2021-11-11 15:37:29 -07:00
|
|
|
package overlay
|
2021-11-08 11:36:31 -07:00
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"io"
|
|
|
|
"net"
|
|
|
|
"os/exec"
|
|
|
|
"strconv"
|
|
|
|
|
2021-11-12 10:19:28 -07:00
|
|
|
"github.com/slackhq/nebula/cidr"
|
|
|
|
"github.com/slackhq/nebula/iputil"
|
2021-11-08 11:36:31 -07:00
|
|
|
"github.com/songgao/water"
|
|
|
|
)
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
type waterTun struct {
|
2021-11-12 10:19:28 -07:00
|
|
|
Device string
|
|
|
|
Cidr *net.IPNet
|
|
|
|
MTU int
|
|
|
|
Routes []Route
|
|
|
|
cidrTree *cidr.Tree4
|
2021-11-08 11:36:31 -07:00
|
|
|
|
|
|
|
*water.Interface
|
|
|
|
}
|
|
|
|
|
2021-11-12 10:19:28 -07:00
|
|
|
func newWaterTun(cidr *net.IPNet, defaultMTU int, routes []Route) (*waterTun, error) {
|
|
|
|
cidrTree, err := makeCidrTree(routes, false)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2021-11-08 11:36:31 -07:00
|
|
|
// NOTE: You cannot set the deviceName under Windows, so you must check tun.Device after calling .Activate()
|
2021-11-12 09:47:36 -07:00
|
|
|
return &waterTun{
|
2021-11-12 10:19:28 -07:00
|
|
|
Cidr: cidr,
|
|
|
|
MTU: defaultMTU,
|
|
|
|
Routes: routes,
|
|
|
|
cidrTree: cidrTree,
|
2021-11-08 11:36:31 -07:00
|
|
|
}, nil
|
|
|
|
}
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
func (t *waterTun) Activate() error {
|
2021-11-08 11:36:31 -07:00
|
|
|
var err error
|
2021-11-12 09:47:36 -07:00
|
|
|
t.Interface, err = water.New(water.Config{
|
2021-11-08 11:36:31 -07:00
|
|
|
DeviceType: water.TUN,
|
|
|
|
PlatformSpecificParams: water.PlatformSpecificParams{
|
|
|
|
ComponentID: "tap0901",
|
2021-11-12 09:47:36 -07:00
|
|
|
Network: t.Cidr.String(),
|
2021-11-08 11:36:31 -07:00
|
|
|
},
|
|
|
|
})
|
|
|
|
if err != nil {
|
2021-11-12 09:47:36 -07:00
|
|
|
return fmt.Errorf("activate failed: %v", err)
|
2021-11-08 11:36:31 -07:00
|
|
|
}
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
t.Device = t.Interface.Name()
|
2021-11-08 11:36:31 -07:00
|
|
|
|
|
|
|
// TODO use syscalls instead of exec.Command
|
|
|
|
err = exec.Command(
|
|
|
|
`C:\Windows\System32\netsh.exe`, "interface", "ipv4", "set", "address",
|
2021-11-12 09:47:36 -07:00
|
|
|
fmt.Sprintf("name=%s", t.Device),
|
2021-11-08 11:36:31 -07:00
|
|
|
"source=static",
|
2021-11-12 09:47:36 -07:00
|
|
|
fmt.Sprintf("addr=%s", t.Cidr.IP),
|
|
|
|
fmt.Sprintf("mask=%s", net.IP(t.Cidr.Mask)),
|
2021-11-08 11:36:31 -07:00
|
|
|
"gateway=none",
|
|
|
|
).Run()
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("failed to run 'netsh' to set address: %s", err)
|
|
|
|
}
|
|
|
|
err = exec.Command(
|
|
|
|
`C:\Windows\System32\netsh.exe`, "interface", "ipv4", "set", "interface",
|
2021-11-12 09:47:36 -07:00
|
|
|
t.Device,
|
|
|
|
fmt.Sprintf("mtu=%d", t.MTU),
|
2021-11-08 11:36:31 -07:00
|
|
|
).Run()
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("failed to run 'netsh' to set MTU: %s", err)
|
|
|
|
}
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
iface, err := net.InterfaceByName(t.Device)
|
2021-11-08 11:36:31 -07:00
|
|
|
if err != nil {
|
2021-11-12 09:47:36 -07:00
|
|
|
return fmt.Errorf("failed to find interface named %s: %v", t.Device, err)
|
2021-11-08 11:36:31 -07:00
|
|
|
}
|
|
|
|
|
2021-11-12 10:19:28 -07:00
|
|
|
for _, r := range t.Routes {
|
|
|
|
if r.Via == nil {
|
|
|
|
// We don't allow route MTUs so only install routes with a via
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
2021-11-08 11:36:31 -07:00
|
|
|
err = exec.Command(
|
2021-11-11 15:37:29 -07:00
|
|
|
"C:\\Windows\\System32\\route.exe", "add", r.Cidr.String(), r.Via.String(), "IF", strconv.Itoa(iface.Index), "METRIC", strconv.Itoa(r.Metric),
|
2021-11-08 11:36:31 -07:00
|
|
|
).Run()
|
|
|
|
if err != nil {
|
2021-11-11 15:37:29 -07:00
|
|
|
return fmt.Errorf("failed to add the unsafe_route %s: %v", r.Cidr.String(), err)
|
2021-11-08 11:36:31 -07:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2021-11-12 10:19:28 -07:00
|
|
|
func (t *waterTun) RouteFor(ip iputil.VpnIp) iputil.VpnIp {
|
|
|
|
r := t.cidrTree.MostSpecificContains(ip)
|
|
|
|
if r != nil {
|
|
|
|
return r.(iputil.VpnIp)
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0
|
|
|
|
}
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
func (t *waterTun) CidrNet() *net.IPNet {
|
|
|
|
return t.Cidr
|
2021-11-08 11:36:31 -07:00
|
|
|
}
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
func (t *waterTun) DeviceName() string {
|
|
|
|
return t.Device
|
2021-11-08 11:36:31 -07:00
|
|
|
}
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
func (t *waterTun) WriteRaw(b []byte) error {
|
|
|
|
_, err := t.Write(b)
|
2021-11-08 11:36:31 -07:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
func (t *waterTun) Close() error {
|
|
|
|
if t.Interface == nil {
|
2021-11-08 11:36:31 -07:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
return t.Interface.Close()
|
2021-11-08 11:36:31 -07:00
|
|
|
}
|
|
|
|
|
2021-11-12 09:47:36 -07:00
|
|
|
func (t *waterTun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
2021-11-08 11:36:31 -07:00
|
|
|
return nil, fmt.Errorf("TODO: multiqueue not implemented for windows")
|
|
|
|
}
|