]> Sergey Matveev's repositories - vors.git/blob - cmd/server/main.go
Tarballs
[vors.git] / cmd / server / main.go
1 // VoRS -- Vo(IP) Really Simple
2 // Copyright (C) 2024 Sergey Matveev <stargrave@stargrave.org>
3 //
4 // This program is free software: you can redistribute it and/or modify
5 // it under the terms of the GNU Affero General Public License as
6 // published by the Free Software Foundation, version 3 of the License.
7 //
8 // This program is distributed in the hope that it will be useful,
9 // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
11 // GNU Affero General Public License for more details.
12 //
13 // You should have received a copy of the GNU Affero General Public License
14 // along with this program.  If not, see <http://www.gnu.org/licenses/>.
15
16 package main
17
18 import (
19         "crypto/rand"
20         "crypto/subtle"
21         "crypto/tls"
22         "encoding/base64"
23         "encoding/hex"
24         "flag"
25         "fmt"
26         "io"
27         "log"
28         "log/slog"
29         "net"
30         "net/netip"
31         "os"
32         "strconv"
33         "strings"
34         "time"
35
36         "github.com/flynn/noise"
37         "github.com/jroimartin/gocui"
38         vors "go.stargrave.org/vors/internal"
39         "golang.org/x/crypto/blake2s"
40         "golang.org/x/crypto/chacha20"
41         "golang.org/x/crypto/poly1305"
42 )
43
44 var (
45         TLSCfg = &tls.Config{
46                 MinVersion:       tls.VersionTLS13,
47                 CurvePreferences: []tls.CurveID{tls.X25519},
48         }
49         Prv, Pub []byte
50         Cookies  = map[vors.Cookie]chan *net.UDPAddr{}
51 )
52
53 func newPeer(conn *net.TCPConn) {
54         logger := slog.With("remote", conn.RemoteAddr().String())
55         logger.Info("connected")
56         defer conn.Close()
57         err := conn.SetNoDelay(true)
58         if err != nil {
59                 log.Fatalln("nodelay:", err)
60         }
61         buf := make([]byte, len(vors.NoisePrologue))
62
63         if _, err = io.ReadFull(conn, buf); err != nil {
64                 logger.Error("handshake: read prologue", "err", err)
65                 return
66         }
67         if string(buf) != vors.NoisePrologue {
68                 logger.Error("handshake: wrong prologue", "err", err)
69                 return
70         }
71
72         hs, err := noise.NewHandshakeState(noise.Config{
73                 CipherSuite:   vors.NoiseCipherSuite,
74                 Pattern:       noise.HandshakeNK,
75                 Initiator:     false,
76                 StaticKeypair: noise.DHKey{Private: Prv, Public: Pub},
77                 Prologue:      []byte(vors.NoisePrologue),
78         })
79         if err != nil {
80                 log.Fatalln("noise.NewHandshakeState:", err)
81         }
82         buf, err = vors.PktRead(conn)
83         if err != nil {
84                 logger.Error("read handshake", "err", err)
85                 return
86         }
87         peer := &Peer{
88                 logger: logger,
89                 conn:   conn,
90                 stats:  &Stats{},
91                 rx:     make(chan []byte),
92                 tx:     make(chan []byte, 10),
93                 alive:  make(chan struct{}),
94         }
95         var room *Room
96         {
97                 nameAndRoom, _, _, err := hs.ReadMessage(nil, buf)
98                 if err != nil {
99                         logger.Error("handshake: decrypt", "err", err)
100                         return
101                 }
102                 cols := strings.SplitN(string(nameAndRoom), " ", 3)
103                 roomName := "/"
104                 if len(cols) > 1 {
105                         roomName = cols[1]
106                 }
107                 var key string
108                 if len(cols) > 2 {
109                         key = cols[2]
110                 }
111                 peer.name = string(cols[0])
112                 logger = logger.With("name", peer.name, "room", roomName)
113                 RoomsM.Lock()
114                 room = Rooms[roomName]
115                 if room == nil {
116                         room = &Room{
117                                 name:  roomName,
118                                 key:   key,
119                                 peers: make(map[byte]*Peer),
120                                 alive: make(chan struct{}),
121                         }
122                         Rooms[roomName] = room
123                         go func() {
124                                 if *NoGUI {
125                                         return
126                                 }
127                                 tick := time.Tick(vors.ScreenRefresh)
128                                 var now time.Time
129                                 var v *gocui.View
130                                 for {
131                                         select {
132                                         case <-room.alive:
133                                                 GUI.DeleteView(room.name)
134                                                 return
135                                         case now = <-tick:
136                                                 v, err = GUI.View(room.name)
137                                                 if err == nil {
138                                                         v.Clear()
139                                                         v.Write([]byte(strings.Join(room.Stats(now), "\n")))
140                                                 }
141                                         }
142                                 }
143                         }()
144                 }
145                 RoomsM.Unlock()
146                 if room.key != key {
147                         logger.Error("wrong password")
148                         buf, _, _, err = hs.WriteMessage(nil, []byte("wrong password"))
149                         if err != nil {
150                                 log.Fatal(err)
151                         }
152                         vors.PktWrite(conn, buf)
153                         return
154                 }
155         }
156         peer.room = room
157
158         for _, p := range room.peers {
159                 if p.name != peer.name {
160                         continue
161                 }
162                 logger.Error("name already taken")
163                 buf, _, _, err = hs.WriteMessage(nil, []byte("name already taken"))
164                 if err != nil {
165                         log.Fatal(err)
166                 }
167                 vors.PktWrite(conn, buf)
168                 return
169         }
170
171         {
172                 var i byte
173                 var ok bool
174                 var found bool
175                 PeersM.Lock()
176                 for i = 0; i <= (1<<8)-1; i++ {
177                         if _, ok = Peers[i]; !ok {
178                                 peer.sid = i
179                                 found = true
180                                 break
181                         }
182                 }
183                 if found {
184                         Peers[peer.sid] = peer
185                         go peer.Tx()
186                 }
187                 PeersM.Unlock()
188                 if !found {
189                         buf, _, _, err = hs.WriteMessage(nil, []byte("too many users"))
190                         if err != nil {
191                                 log.Fatal(err)
192                         }
193                         vors.PktWrite(conn, buf)
194                         return
195                 }
196         }
197         logger = logger.With("sid", peer.sid)
198         room.peers[peer.sid] = peer
199         logger.Info("logged in")
200
201         defer func() {
202                 logger.Info("removing")
203                 PeersM.Lock()
204                 delete(Peers, peer.sid)
205                 delete(room.peers, peer.sid)
206                 PeersM.Unlock()
207                 s := []byte(fmt.Sprintf("%s %d", vors.CmdDel, peer.sid))
208                 for _, p := range room.peers {
209                         go func(tx chan []byte) { tx <- s }(p.tx)
210                 }
211         }()
212
213         {
214                 var cookie vors.Cookie
215                 if _, err = io.ReadFull(rand.Reader, cookie[:]); err != nil {
216                         log.Fatalln("cookie:", err)
217                 }
218                 gotCookie := make(chan *net.UDPAddr)
219                 Cookies[cookie] = gotCookie
220
221                 var txCS, rxCS *noise.CipherState
222                 buf, txCS, rxCS, err := hs.WriteMessage(nil,
223                         []byte(fmt.Sprintf("OK %s", hex.EncodeToString(cookie[:]))))
224                 if err != nil {
225                         log.Fatalln("hs.WriteMessage:", err)
226                 }
227                 if err = vors.PktWrite(conn, buf); err != nil {
228                         logger.Error("handshake write", "err", err)
229                         delete(Cookies, cookie)
230                         return
231                 }
232                 peer.rxCS, peer.txCS = txCS, rxCS
233
234                 timeout := time.NewTimer(vors.PingTime)
235                 select {
236                 case peer.addr = <-gotCookie:
237                 case <-timeout.C:
238                         logger.Error("cookie timeout")
239                         delete(Cookies, cookie)
240                         return
241                 }
242                 delete(Cookies, cookie)
243                 logger.Info("got cookie", "addr", peer.addr)
244                 if !timeout.Stop() {
245                         <-timeout.C
246                 }
247         }
248         go peer.Rx()
249         peer.tx <- []byte(fmt.Sprintf("SID %d", peer.sid))
250
251         for _, p := range room.peers {
252                 if p.sid == peer.sid {
253                         continue
254                 }
255                 peer.tx <- []byte(fmt.Sprintf("%s %d %s %s",
256                         vors.CmdAdd, p.sid, p.name, hex.EncodeToString(p.key)))
257         }
258
259         {
260                 h, err := blake2s.New256(hs.ChannelBinding())
261                 if err != nil {
262                         log.Fatalln(err)
263                 }
264                 h.Write([]byte(vors.NoisePrologue))
265                 peer.key = h.Sum(nil)
266         }
267
268         {
269                 s := []byte(fmt.Sprintf("%s %d %s %s",
270                         vors.CmdAdd, peer.sid, peer.name, hex.EncodeToString(peer.key)))
271                 for _, p := range room.peers {
272                         if p.sid != peer.sid {
273                                 p.tx <- s
274                         }
275                 }
276         }
277
278         seen := time.Now()
279         go func(seen *time.Time) {
280                 ticker := time.Tick(vors.PingTime)
281                 var now time.Time
282                 for {
283                         select {
284                         case now = <-ticker:
285                                 if seen.Add(2 * vors.PingTime).Before(now) {
286                                         logger.Error("timeout:", "seen", seen)
287                                         peer.Close()
288                                         return
289                                 }
290                         case <-peer.alive:
291                                 return
292                         }
293                 }
294         }(&seen)
295
296         for buf := range peer.rx {
297                 if string(buf) == vors.CmdPing {
298                         seen = time.Now()
299                         peer.tx <- []byte(vors.CmdPong)
300                 }
301         }
302 }
303
304 func main() {
305         bind := flag.String("bind", "[::1]:"+strconv.Itoa(vors.DefaultPort),
306                 "host:TCP/UDP port to listen on")
307         kpFile := flag.String("key", "key", "path to keypair file")
308         version := flag.Bool("version", false, "print version")
309         warranty := flag.Bool("warranty", false, "print warranty information")
310         flag.Parse()
311         log.SetFlags(log.Lmicroseconds | log.Lshortfile)
312
313         if *warranty {
314                 fmt.Println(vors.Warranty)
315                 return
316         }
317         if *version {
318                 fmt.Println(vors.GetVersion())
319                 return
320         }
321
322         {
323                 data, err := os.ReadFile(*kpFile)
324                 if err != nil {
325                         log.Fatal(err)
326                 }
327                 Prv, Pub = data[:len(data)/2], data[len(data)/2:]
328         }
329
330         lnTCP, err := net.ListenTCP("tcp",
331                 net.TCPAddrFromAddrPort(netip.MustParseAddrPort(*bind)))
332         if err != nil {
333                 log.Fatal(err)
334         }
335         lnUDP, err := net.ListenUDP("udp",
336                 net.UDPAddrFromAddrPort(netip.MustParseAddrPort(*bind)))
337         if err != nil {
338                 log.Fatal(err)
339         }
340
341         LoggerReady := make(chan struct{})
342         if *NoGUI {
343                 close(GUIReadyC)
344                 slog.SetDefault(slog.New(slog.NewTextHandler(os.Stderr, nil)))
345                 close(LoggerReady)
346         } else {
347                 GUI, err = gocui.NewGui(gocui.OutputNormal)
348                 if err != nil {
349                         log.Fatal(err)
350                 }
351                 defer GUI.Close()
352                 GUI.SetManagerFunc(guiLayout)
353                 if err := GUI.SetKeybinding("", gocui.KeyF10, gocui.ModNone, guiQuit); err != nil {
354                         log.Fatal(err)
355                 }
356
357                 go func() {
358                         <-GUIReadyC
359                         v, err := GUI.View("logs")
360                         if err != nil {
361                                 log.Fatal(err)
362                         }
363                         slog.SetDefault(slog.New(slog.NewTextHandler(v, nil)))
364                         close(LoggerReady)
365                         for {
366                                 time.Sleep(vors.ScreenRefresh)
367                                 GUI.Update(func(gui *gocui.Gui) error {
368                                         return nil
369                                 })
370                         }
371                 }()
372         }
373
374         go func() {
375                 <-LoggerReady
376                 buf := make([]byte, 2*vors.FrameLen)
377                 var n int
378                 var from *net.UDPAddr
379                 var err error
380                 var sid byte
381                 var peer *Peer
382                 var ciph *chacha20.Cipher
383                 var macKey [32]byte
384                 var mac *poly1305.MAC
385                 tag := make([]byte, poly1305.TagSize)
386                 nonce := make([]byte, 12)
387                 for {
388                         n, from, err = lnUDP.ReadFromUDP(buf)
389                         if err != nil {
390                                 log.Fatalln("recvfrom:", err)
391                         }
392
393                         if n == vors.CookieLen {
394                                 var cookie vors.Cookie
395                                 copy(cookie[:], buf)
396                                 if c, ok := Cookies[cookie]; ok {
397                                         c <- from
398                                         close(c)
399                                 } else {
400                                         slog.Info("unknown cookie", "cookie", cookie)
401                                 }
402                                 continue
403                         }
404
405                         sid = buf[0]
406                         peer = Peers[sid]
407                         if peer == nil {
408                                 slog.Info("unknown", "sid", sid, "from", from)
409                                 continue
410                         }
411
412                         if from.Port != peer.addr.Port || !from.IP.Equal(peer.addr.IP) {
413                                 slog.Info("wrong addr",
414                                         "peer", peer.name,
415                                         "our", peer.addr,
416                                         "got", from)
417                                 continue
418                         }
419
420                         peer.stats.pktsRx++
421                         peer.stats.bytesRx += vors.IPHdrLen(from.IP) + 8 + uint64(n)
422                         if n == 1 {
423                                 continue
424                         }
425                         if n <= 4+vors.TagLen {
426                                 peer.stats.bads++
427                                 continue
428                         }
429
430                         copy(nonce[len(nonce)-4:], buf)
431                         ciph, err = chacha20.NewUnauthenticatedCipher(peer.key, nonce)
432                         if err != nil {
433                                 log.Fatal(err)
434                         }
435                         clear(macKey[:])
436                         ciph.XORKeyStream(macKey[:], macKey[:])
437                         ciph.SetCounter(1)
438                         mac = poly1305.New(&macKey)
439                         if _, err = mac.Write(buf[4 : n-vors.TagLen]); err != nil {
440                                 log.Fatal(err)
441                         }
442                         mac.Sum(tag[:0])
443                         if subtle.ConstantTimeCompare(
444                                 tag[:vors.TagLen],
445                                 buf[n-vors.TagLen:n],
446                         ) != 1 {
447                                 peer.stats.bads++
448                                 continue
449                         }
450
451                         peer.stats.last = time.Now()
452                         for _, p := range peer.room.peers {
453                                 if p.sid == sid {
454                                         continue
455                                 }
456                                 p.stats.pktsTx++
457                                 p.stats.bytesTx += vors.IPHdrLen(p.addr.IP) + 8 + uint64(n)
458                                 if _, err = lnUDP.WriteToUDP(buf[:n], p.addr); err != nil {
459                                         slog.Warn("sendto", "peer", peer.name, "err", err)
460                                 }
461                         }
462                 }
463         }()
464
465         go func() {
466                 <-LoggerReady
467                 slog.Info("listening",
468                         "bind", *bind,
469                         "pub", base64.RawURLEncoding.EncodeToString(Pub))
470                 for {
471                         conn, err := lnTCP.AcceptTCP()
472                         if err != nil {
473                                 log.Fatalln("accept:", err)
474                         }
475                         go newPeer(conn)
476                 }
477         }()
478
479         if *NoGUI {
480                 <-make(chan struct{})
481         }
482         err = GUI.MainLoop()
483         if err != nil && err != gocui.ErrQuit {
484                 log.Fatal(err)
485         }
486 }