connection.cpp 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652
  1. /*
  2. * connection.cpp
  3. *
  4. * Created on: Sep 23, 2017
  5. * Author: root
  6. */
  7. #include "connection.h"
  8. #include "encrypt.h"
  9. #include "fd_manager.h"
  10. int disable_anti_replay=0;//if anti_replay windows is diabled
  11. const int disable_conn_clear=0;//a raw connection is called conn.
  12. conn_manager_t conn_manager;
  13. anti_replay_seq_t anti_replay_t::get_new_seq_for_send()
  14. {
  15. return anti_replay_seq++;
  16. }
  17. anti_replay_t::anti_replay_t()
  18. {
  19. max_packet_received=0;
  20. anti_replay_seq=get_true_random_number_64()/10;//random first seq
  21. //memset(window,0,sizeof(window)); //not necessary
  22. }
  23. void anti_replay_t::re_init()
  24. {
  25. max_packet_received=0;
  26. //memset(window,0,sizeof(window));
  27. }
  28. int anti_replay_t::is_vaild(u64_t seq)
  29. {
  30. if(disable_anti_replay) return 1;
  31. //if(disabled) return 0;
  32. if(seq==max_packet_received) return 0;
  33. else if(seq>max_packet_received)
  34. {
  35. if(seq-max_packet_received>=anti_replay_window_size)
  36. {
  37. memset(window,0,sizeof(window));
  38. window[seq%anti_replay_window_size]=1;
  39. }
  40. else
  41. {
  42. for (u64_t i=max_packet_received+1;i<seq;i++)
  43. window[i%anti_replay_window_size]=0;
  44. window[seq%anti_replay_window_size]=1;
  45. }
  46. max_packet_received=seq;
  47. return 1;
  48. }
  49. else if(seq<max_packet_received)
  50. {
  51. if(max_packet_received-seq>=anti_replay_window_size) return 0;
  52. else
  53. {
  54. if (window[seq%anti_replay_window_size]==1) return 0;
  55. else
  56. {
  57. window[seq%anti_replay_window_size]=1;
  58. return 1;
  59. }
  60. }
  61. }
  62. return 0; //for complier check
  63. }
  64. void conn_info_t::recover(const conn_info_t &conn_info)
  65. {
  66. raw_info=conn_info.raw_info;
  67. raw_info.rst_received=0;
  68. raw_info.disabled=0;
  69. last_state_time=conn_info.last_state_time;
  70. last_hb_recv_time=conn_info.last_hb_recv_time;
  71. last_hb_sent_time=conn_info.last_hb_sent_time;
  72. my_id=conn_info.my_id;
  73. oppsite_id=conn_info.oppsite_id;
  74. blob->anti_replay.re_init();
  75. my_roller=0;//no need to set,but for easier debug,set it to zero
  76. oppsite_roller=0;//same as above
  77. last_oppsite_roller_time=0;
  78. }
  79. void conn_info_t::re_init()
  80. {
  81. //send_packet_info.protocol=g_packet_info_send.protocol;
  82. if(program_mode==server_mode)
  83. state.server_current_state=server_idle;
  84. else
  85. state.client_current_state=client_idle;
  86. last_state_time=0;
  87. oppsite_const_id=0;
  88. timer_fd64=0;
  89. my_roller=0;
  90. oppsite_roller=0;
  91. last_oppsite_roller_time=0;
  92. }
  93. conn_info_t::conn_info_t()
  94. {
  95. blob=0;
  96. re_init();
  97. }
  98. void conn_info_t::prepare()
  99. {
  100. assert(blob==0);
  101. blob=new blob_t;
  102. blob->conv_manager.s.additional_clear_function=server_clear_function;
  103. }
  104. conn_info_t::conn_info_t(const conn_info_t&b)
  105. {
  106. assert(0==1);
  107. //mylog(log_error,"called!!!!!!!!!!!!!\n");
  108. *this=b;
  109. if(blob!=0)
  110. {
  111. blob=new blob_t(*b.blob);
  112. }
  113. }
  114. conn_info_t& conn_info_t::operator=(const conn_info_t& b)
  115. {
  116. mylog(log_fatal,"not allowed\n");
  117. myexit(-1);
  118. return *this;
  119. }
  120. conn_info_t::~conn_info_t()
  121. {
  122. if(program_mode==server_mode)
  123. {
  124. if(state.server_current_state==server_ready)
  125. {
  126. assert(blob!=0);
  127. assert(oppsite_const_id!=0);
  128. //assert(conn_manager.const_id_mp.find(oppsite_const_id)!=conn_manager.const_id_mp.end()); // conn_manager 's deconstuction function erases it
  129. }
  130. else
  131. {
  132. assert(blob==0);
  133. assert(oppsite_const_id==0);
  134. }
  135. }
  136. assert(timer_fd64==0);
  137. //if(oppsite_const_id!=0) //do this at conn_manager 's deconstuction function
  138. //conn_manager.const_id_mp.erase(oppsite_const_id);
  139. if(blob!=0)
  140. delete blob;
  141. //send_packet_info.protocol=g_packet_info_send.protocol;
  142. }
  143. conn_manager_t::conn_manager_t()
  144. {
  145. ready_num=0;
  146. mp.reserve(10007);
  147. //clear_it=mp.begin();
  148. // timer_fd_mp.reserve(10007);
  149. const_id_mp.reserve(10007);
  150. // udp_fd_mp.reserve(100007);
  151. last_clear_time=0;
  152. //current_ready_ip=0;
  153. // current_ready_port=0;
  154. }
  155. int conn_manager_t::exist(address_t addr)
  156. {
  157. //u64_t u64=0;
  158. //u64=ip;
  159. //u64<<=32u;
  160. //u64|=port;
  161. if(mp.find(addr)!=mp.end())
  162. {
  163. return 1;
  164. }
  165. return 0;
  166. }
  167. /*
  168. int insert(uint32_t ip,uint16_t port)
  169. {
  170. uint64_t u64=0;
  171. u64=ip;
  172. u64<<=32u;
  173. u64|=port;
  174. mp[u64];
  175. return 0;
  176. }*/
  177. conn_info_t *& conn_manager_t::find_insert_p(address_t addr) //be aware,the adress may change after rehash
  178. {
  179. // u64_t u64=0;
  180. //u64=ip;
  181. //u64<<=32u;
  182. //u64|=port;
  183. unordered_map<address_t,conn_info_t*>::iterator it=mp.find(addr);
  184. if(it==mp.end())
  185. {
  186. mp[addr]=new conn_info_t;
  187. //lru.new_key(addr);
  188. }
  189. else
  190. {
  191. //lru.update(addr);
  192. }
  193. return mp[addr];
  194. }
  195. conn_info_t & conn_manager_t::find_insert(address_t addr) //be aware,the adress may change after rehash
  196. {
  197. //u64_t u64=0;
  198. //u64=ip;
  199. //u64<<=32u;
  200. //u64|=port;
  201. unordered_map<address_t,conn_info_t*>::iterator it=mp.find(addr);
  202. if(it==mp.end())
  203. {
  204. mp[addr]=new conn_info_t;
  205. //lru.new_key(addr);
  206. }
  207. else
  208. {
  209. //lru.update(addr);
  210. }
  211. return *mp[addr];
  212. }
  213. int conn_manager_t::erase(unordered_map<address_t,conn_info_t*>::iterator erase_it)
  214. {
  215. if(erase_it->second->state.server_current_state==server_ready)
  216. {
  217. ready_num--;
  218. assert(i32_t(ready_num)!=-1);
  219. assert(erase_it->second!=0);
  220. assert(erase_it->second->timer_fd64 !=0);
  221. assert(fd_manager.exist(erase_it->second->timer_fd64));
  222. assert(erase_it->second->oppsite_const_id!=0);
  223. assert(const_id_mp.find(erase_it->second->oppsite_const_id)!=const_id_mp.end());
  224. //assert(timer_fd_mp.find(erase_it->second->timer_fd)!=timer_fd_mp.end());
  225. const_id_mp.erase(erase_it->second->oppsite_const_id);
  226. fd_manager.fd64_close(erase_it->second->timer_fd64);
  227. erase_it->second->timer_fd64=0;
  228. //timer_fd_mp.erase(erase_it->second->timer_fd);
  229. //close(erase_it->second->timer_fd);// close will auto delte it from epoll
  230. delete(erase_it->second);
  231. mp.erase(erase_it->first);
  232. }
  233. else
  234. {
  235. assert(erase_it->second->blob==0);
  236. assert(erase_it->second->timer_fd64 ==0);
  237. assert(erase_it->second->oppsite_const_id==0);
  238. delete(erase_it->second);
  239. mp.erase(erase_it->first);
  240. }
  241. return 0;
  242. }
  243. int conn_manager_t::clear_inactive()
  244. {
  245. if(get_current_time()-last_clear_time>conn_clear_interval)
  246. {
  247. last_clear_time=get_current_time();
  248. return clear_inactive0();
  249. }
  250. return 0;
  251. }
  252. int conn_manager_t::clear_inactive0()
  253. {
  254. unordered_map<address_t,conn_info_t*>::iterator it;
  255. unordered_map<address_t,conn_info_t*>::iterator old_it;
  256. if(disable_conn_clear) return 0;
  257. //map<uint32_t,uint64_t>::iterator it;
  258. int cnt=0;
  259. it=clear_it;
  260. int size=mp.size();
  261. int num_to_clean=size/conn_clear_ratio+conn_clear_min; //clear 1/10 each time,to avoid latency glitch
  262. mylog(log_trace,"mp.size() %d\n", size);
  263. num_to_clean=min(num_to_clean,(int)mp.size());
  264. u64_t current_time=get_current_time();
  265. for(;;)
  266. {
  267. if(cnt>=num_to_clean) break;
  268. if(mp.begin()==mp.end()) break;
  269. if(it==mp.end())
  270. {
  271. it=mp.begin();
  272. }
  273. if(it->second->state.server_current_state==server_ready &&current_time - it->second->last_hb_recv_time <=server_conn_timeout)
  274. {
  275. it++;
  276. }
  277. else if(it->second->state.server_current_state!=server_ready&& current_time - it->second->last_state_time <=server_handshake_timeout )
  278. {
  279. it++;
  280. }
  281. else if(it->second->blob!=0&&it->second->blob->conv_manager.s.get_size() >0)
  282. {
  283. assert(it->second->state.server_current_state==server_ready);
  284. it++;
  285. }
  286. else
  287. {
  288. mylog(log_info,"[%s:%d]inactive conn cleared \n",it->second->raw_info.recv_info.new_src_ip.get_str1(),it->second->raw_info.recv_info.src_port);
  289. old_it=it;
  290. it++;
  291. erase(old_it);
  292. }
  293. cnt++;
  294. }
  295. clear_it=it;
  296. return 0;
  297. }
  298. int send_bare(raw_info_t &raw_info,const char* data,int len)//send function with encryption but no anti replay,this is used when client and server verifys each other
  299. //you have to design the protocol carefully, so that you wont be affect by relay attack
  300. {
  301. if(len<0)
  302. {
  303. mylog(log_debug,"input_len <0\n");
  304. return -1;
  305. }
  306. packet_info_t &send_info=raw_info.send_info;
  307. packet_info_t &recv_info=raw_info.recv_info;
  308. char send_data_buf[buf_len]; //buf for send data and send hb
  309. char send_data_buf2[buf_len];
  310. //static send_bare[buf_len];
  311. iv_t iv=get_true_random_number_64();
  312. padding_t padding=get_true_random_number_64();
  313. memcpy(send_data_buf,&iv,sizeof(iv));
  314. memcpy(send_data_buf+sizeof(iv),&padding,sizeof(padding));
  315. send_data_buf[sizeof(iv)+sizeof(padding)]='b';
  316. memcpy(send_data_buf+sizeof(iv)+sizeof(padding)+1,data,len);
  317. int new_len=len+sizeof(iv)+sizeof(padding)+1;
  318. if(my_encrypt(send_data_buf,send_data_buf2,new_len)!=0)
  319. {
  320. return -1;
  321. }
  322. send_raw0(raw_info,send_data_buf2,new_len);
  323. return 0;
  324. }
  325. int reserved_parse_bare(const char *input,int input_len,char* & data,int & len) // a sub function used in recv_bare
  326. {
  327. static char recv_data_buf[buf_len];
  328. if(input_len<0)
  329. {
  330. mylog(log_debug,"input_len <0\n");
  331. return -1;
  332. }
  333. if(my_decrypt(input,recv_data_buf,input_len)!=0)
  334. {
  335. mylog(log_debug,"decrypt_fail in recv bare\n");
  336. return -1;
  337. }
  338. if(recv_data_buf[sizeof(iv_t)+sizeof(padding_t)]!='b')
  339. {
  340. mylog(log_debug,"not a bare packet\n");
  341. return -1;
  342. }
  343. len=input_len;
  344. data=recv_data_buf+sizeof(iv_t)+sizeof(padding_t)+1;
  345. len-=sizeof(iv_t)+sizeof(padding_t)+1;
  346. if(len<0)
  347. {
  348. mylog(log_debug,"len <0\n");
  349. return -1;
  350. }
  351. return 0;
  352. }
  353. int recv_bare(raw_info_t &raw_info,char* & data,int & len)//recv function with encryption but no anti replay,this is used when client and server verifys each other
  354. //you have to design the protocol carefully, so that you wont be affect by relay attack
  355. {
  356. packet_info_t &send_info=raw_info.send_info;
  357. packet_info_t &recv_info=raw_info.recv_info;
  358. if(recv_raw0(raw_info,data,len)<0)
  359. {
  360. //printf("recv_raw_fail in recv bare\n");
  361. return -1;
  362. }
  363. if ((raw_mode == mode_faketcp && (recv_info.syn == 1 || recv_info.ack != 1)))
  364. {
  365. mylog(log_debug,"unexpect packet type recv_info.syn=%d recv_info.ack=%d \n",recv_info.syn,recv_info.ack);
  366. return -1;
  367. }
  368. return reserved_parse_bare(data,len,data,len);
  369. }
  370. int send_handshake(raw_info_t &raw_info,my_id_t id1,my_id_t id2,my_id_t id3)// a warp for send_bare for sending handshake(this is not tcp handshake) easily
  371. {
  372. packet_info_t &send_info=raw_info.send_info;
  373. packet_info_t &recv_info=raw_info.recv_info;
  374. char * data;int len;
  375. //len=sizeof(id_t)*3;
  376. if(numbers_to_char(id1,id2,id3,data,len)!=0) return -1;
  377. if(send_bare(raw_info,data,len)!=0) {mylog(log_warn,"send bare fail\n");return -1;}
  378. return 0;
  379. }
  380. /*
  381. int recv_handshake(packet_info_t &info,id_t &id1,id_t &id2,id_t &id3)
  382. {
  383. char * data;int len;
  384. if(recv_bare(info,data,len)!=0) return -1;
  385. if(char_to_numbers(data,len,id1,id2,id3)!=0) return -1;
  386. return 0;
  387. }*/
  388. int send_safer(conn_info_t &conn_info,char type,const char* data,int len) //safer transfer function with anti-replay,when mutually verification is done.
  389. {
  390. packet_info_t &send_info=conn_info.raw_info.send_info;
  391. packet_info_t &recv_info=conn_info.raw_info.recv_info;
  392. if(type!='h'&&type!='d')
  393. {
  394. mylog(log_warn,"first byte is not h or d ,%x\n",type);
  395. return -1;
  396. }
  397. char send_data_buf[buf_len]; //buf for send data and send hb
  398. char send_data_buf2[buf_len];
  399. my_id_t n_tmp_id=htonl(conn_info.my_id);
  400. memcpy(send_data_buf,&n_tmp_id,sizeof(n_tmp_id));
  401. n_tmp_id=htonl(conn_info.oppsite_id);
  402. memcpy(send_data_buf+sizeof(n_tmp_id),&n_tmp_id,sizeof(n_tmp_id));
  403. anti_replay_seq_t n_seq=hton64(conn_info.blob->anti_replay.get_new_seq_for_send());
  404. memcpy(send_data_buf+sizeof(n_tmp_id)*2,&n_seq,sizeof(n_seq));
  405. send_data_buf[sizeof(n_tmp_id)*2+sizeof(n_seq)]=type;
  406. send_data_buf[sizeof(n_tmp_id)*2+sizeof(n_seq)+1]=conn_info.my_roller;
  407. memcpy(send_data_buf+2+sizeof(n_tmp_id)*2+sizeof(n_seq),data,len);//data;
  408. int new_len=len+sizeof(n_seq)+sizeof(n_tmp_id)*2+2;
  409. if(my_encrypt(send_data_buf,send_data_buf2,new_len)!=0)
  410. {
  411. return -1;
  412. }
  413. if(send_raw0(conn_info.raw_info,send_data_buf2,new_len)!=0) return -1;
  414. if(after_send_raw0(conn_info.raw_info)!=0) return -1;
  415. return 0;
  416. }
  417. int send_data_safer(conn_info_t &conn_info,const char* data,int len,u32_t conv_num)//a wrap for send_safer for transfer data.
  418. {
  419. packet_info_t &send_info=conn_info.raw_info.send_info;
  420. packet_info_t &recv_info=conn_info.raw_info.recv_info;
  421. char send_data_buf[buf_len];
  422. //send_data_buf[0]='d';
  423. u32_t n_conv_num=htonl(conv_num);
  424. memcpy(send_data_buf,&n_conv_num,sizeof(n_conv_num));
  425. memcpy(send_data_buf+sizeof(n_conv_num),data,len);
  426. int new_len=len+sizeof(n_conv_num);
  427. send_safer(conn_info,'d',send_data_buf,new_len);
  428. return 0;
  429. }
  430. int reserved_parse_safer(conn_info_t &conn_info,const char * input,int input_len,char &type,char* &data,int &len)//subfunction for recv_safer,allow overlap
  431. {
  432. static char recv_data_buf[buf_len];
  433. // char *recv_data_buf=recv_data_buf0; //fix strict alias warning
  434. if(my_decrypt(input,recv_data_buf,input_len)!=0)
  435. {
  436. //printf("decrypt fail\n");
  437. return -1;
  438. }
  439. //char *a=recv_data_buf;
  440. //id_t h_oppiste_id= ntohl ( *((id_t * )(recv_data_buf)) );
  441. my_id_t h_oppsite_id;
  442. memcpy(&h_oppsite_id,recv_data_buf,sizeof(h_oppsite_id));
  443. h_oppsite_id=ntohl(h_oppsite_id);
  444. //id_t h_my_id= ntohl ( *((id_t * )(recv_data_buf+sizeof(id_t))) );
  445. my_id_t h_my_id;
  446. memcpy(&h_my_id,recv_data_buf+sizeof(my_id_t),sizeof(h_my_id));
  447. h_my_id=ntohl(h_my_id);
  448. //anti_replay_seq_t h_seq= ntoh64 ( *((anti_replay_seq_t * )(recv_data_buf +sizeof(id_t) *2 )) );
  449. anti_replay_seq_t h_seq;
  450. memcpy(&h_seq,recv_data_buf +sizeof(my_id_t) *2 ,sizeof(h_seq));
  451. h_seq=ntoh64(h_seq);
  452. if(h_oppsite_id!=conn_info.oppsite_id||h_my_id!=conn_info.my_id)
  453. {
  454. mylog(log_debug,"id and oppsite_id verification failed %x %x %x %x \n",h_oppsite_id,conn_info.oppsite_id,h_my_id,conn_info.my_id);
  455. return -1;
  456. }
  457. if (conn_info.blob->anti_replay.is_vaild(h_seq) != 1) {
  458. mylog(log_debug,"dropped replay packet\n");
  459. return -1;
  460. }
  461. //printf("recv _len %d\n ",recv_len);
  462. data=recv_data_buf+sizeof(anti_replay_seq_t)+sizeof(my_id_t)*2;
  463. len=input_len-(sizeof(anti_replay_seq_t)+sizeof(my_id_t)*2 );
  464. if(data[0]!='h'&&data[0]!='d')
  465. {
  466. mylog(log_debug,"first byte is not h or d ,%x\n",data[0]);
  467. return -1;
  468. }
  469. uint8_t roller=data[1];
  470. type=data[0];
  471. data+=2;
  472. len-=2;
  473. if(len<0)
  474. {
  475. mylog(log_debug,"len <0 ,%d\n",len);
  476. return -1;
  477. }
  478. if(roller!=conn_info.oppsite_roller)
  479. {
  480. conn_info.oppsite_roller=roller;
  481. conn_info.last_oppsite_roller_time=get_current_time();
  482. }
  483. if(hb_mode==0)
  484. conn_info.my_roller++;//increase on a successful recv
  485. else if(hb_mode==1)
  486. {
  487. if(type=='h')
  488. conn_info.my_roller++;
  489. }
  490. else
  491. {
  492. assert(0==1);
  493. }
  494. if(after_recv_raw0(conn_info.raw_info)!=0) return -1;
  495. return 0;
  496. }
  497. int recv_safer(conn_info_t &conn_info,char &type,char* &data,int &len)///safer transfer function with anti-replay,when mutually verification is done.
  498. {
  499. packet_info_t &send_info=conn_info.raw_info.send_info;
  500. packet_info_t &recv_info=conn_info.raw_info.recv_info;
  501. char * recv_data;int recv_len;
  502. static char recv_data_buf[buf_len];
  503. if(recv_raw0(conn_info.raw_info,recv_data,recv_len)!=0) return -1;
  504. return reserved_parse_safer(conn_info,recv_data,recv_len,type,data,len);
  505. }
  506. void server_clear_function(u64_t u64)//used in conv_manager in server mode.for server we have to use one udp fd for one conv(udp connection),
  507. //so we have to close the fd when conv expires
  508. {
  509. //int fd=int(u64);
  510. // int ret;
  511. //assert(fd!=0);
  512. /*
  513. epoll_event ev;
  514. ev.events = EPOLLIN;
  515. ev.data.u64 = u64;
  516. ret = epoll_ctl(epollfd, EPOLL_CTL_DEL, fd, &ev);
  517. if (ret!=0)
  518. {
  519. mylog(log_fatal,"fd:%d epoll delete failed!!!!\n",fd);
  520. myexit(-1); //this shouldnt happen
  521. }*/ //no need
  522. /*ret= close(fd); //closed fd should be auto removed from epoll
  523. if (ret!=0)
  524. {
  525. mylog(log_fatal,"close fd %d failed !!!!\n",fd);
  526. myexit(-1); //this shouldnt happen
  527. }*/
  528. //mylog(log_fatal,"size:%d !!!!\n",conn_manager.udp_fd_mp.size());
  529. fd64_t fd64=u64;
  530. assert(fd_manager.exist(fd64));
  531. fd_manager.fd64_close(fd64);
  532. //assert(conn_manager.udp_fd_mp.find(fd)!=conn_manager.udp_fd_mp.end());
  533. //conn_manager.udp_fd_mp.erase(fd);
  534. }