Line data Source code
1 : #include "fd_quic_common.h"
2 : #include "fd_quic_retry_private.h"
3 : #include "crypto/fd_quic_crypto_suites.h"
4 : #include "fd_quic_conn_id.h"
5 : #include "fd_quic_enum.h"
6 : #include "fd_quic_private.h"
7 : #include "../../ballet/aes/fd_aes_gcm.h"
8 :
9 : FD_STATIC_ASSERT( FD_QUIC_RETRY_LOCAL_SZ==
10 : FD_QUIC_MAX_FOOTPRINT(retry_hdr) +
11 : sizeof(fd_quic_retry_token_t) +
12 : FD_QUIC_CRYPTO_TAG_SZ,
13 : layout );
14 :
15 : ulong
16 : fd_quic_retry_pseudo(
17 : uchar out[ FD_QUIC_RETRY_MAX_PSEUDO_SZ ],
18 : void const * retry_pkt,
19 : ulong retry_pkt_sz,
20 6002763 : fd_quic_conn_id_t const * orig_dst_conn_id ) {
21 :
22 6002763 : if( FD_UNLIKELY( retry_pkt_sz <= FD_QUIC_CRYPTO_TAG_SZ ||
23 6002763 : retry_pkt_sz > FD_QUIC_RETRY_MAX_SZ ) ) {
24 0 : return FD_QUIC_PARSE_FAIL;
25 0 : }
26 :
27 : /* Retry Pseudo-Packet {
28 : ODCID Length (8),
29 : Original Destination Connection ID (0..160),
30 : Header Form (1) = 1,
31 : Fixed Bit (1) = 1,
32 : Long Packet Type (2) = 3,
33 : Unused (4),
34 : Version (32),
35 : DCID Len (8),
36 : Destination Connection ID (0..160),
37 : SCID Len (8),
38 : Source Connection ID (0..160),
39 : Retry Token (..),
40 : } */
41 :
42 6002763 : uchar * cur_ptr = out;
43 :
44 6002763 : cur_ptr[0] = (uchar)orig_dst_conn_id->sz;
45 6002763 : cur_ptr += 1;
46 :
47 6002763 : memcpy( cur_ptr, orig_dst_conn_id->conn_id, FD_QUIC_MAX_CONN_ID_SZ ); /* oversz is safe */
48 6002763 : cur_ptr += orig_dst_conn_id->sz;
49 :
50 6002763 : ulong stripped_retry_sz = retry_pkt_sz - FD_QUIC_CRYPTO_TAG_SZ; /* >0 */
51 6002763 : fd_memcpy( cur_ptr, retry_pkt, stripped_retry_sz );
52 6002763 : cur_ptr += stripped_retry_sz;
53 :
54 6002763 : return (ulong)cur_ptr - (ulong)out;
55 6002763 : }
56 :
57 : ulong
58 : fd_quic_retry_create(
59 : uchar retry[FD_QUIC_RETRY_LOCAL_SZ], /* out */
60 : fd_quic_pkt_t const * pkt,
61 : ulong nonce0,
62 : ulong nonce1,
63 : uchar const retry_secret[ FD_QUIC_RETRY_SECRET_SZ ],
64 : uchar const retry_iv[ FD_QUIC_RETRY_IV_SZ ],
65 : fd_quic_conn_id_t const * orig_dst_conn_id,
66 : fd_quic_conn_id_t const * src_conn_id,
67 : ulong new_conn_id,
68 : long expire_at
69 3000021 : ) {
70 :
71 3000021 : uchar * out_ptr = retry;
72 3000021 : ulong out_free = FD_QUIC_RETRY_LOCAL_SZ;
73 :
74 : /* Craft a new Retry packet */
75 :
76 3000021 : fd_quic_retry_hdr_t retry_hdr[1] = {{
77 3000021 : .h0 = 0xf0,
78 3000021 : .version = 1,
79 3000021 : .dst_conn_id_len = src_conn_id->sz,
80 : // .dst_conn_id (initialized below)
81 3000021 : .src_conn_id_len = FD_QUIC_CONN_ID_SZ,
82 : // .src_conn_id (initialized below)
83 3000021 : }};
84 3000021 : memcpy( retry_hdr->dst_conn_id, src_conn_id->conn_id, FD_QUIC_MAX_CONN_ID_SZ );
85 3000021 : FD_STORE( ulong, retry_hdr->src_conn_id, new_conn_id );
86 3000021 : ulong rc = fd_quic_encode_retry_hdr( retry, FD_QUIC_RETRY_LOCAL_SZ, retry_hdr );
87 3000021 : if( FD_UNLIKELY( rc==FD_QUIC_PARSE_FAIL ) ) FD_LOG_CRIT(( "fd_quic_encode_retry_hdr failed" ));
88 3000021 : out_ptr += rc;
89 3000021 : out_free -= rc;
90 :
91 : /* Craft a new retry token */
92 :
93 3000021 : fd_quic_retry_token_t * retry_token = fd_type_pun( out_ptr );
94 3000021 : FD_DCHECK_CRIT( out_free >= sizeof(fd_quic_retry_token_t), "insufficient space for retry token" );
95 :
96 3000021 : uint src_ip4_addr = pkt->ip4->saddr; /* net order */
97 3000021 : ushort src_udp_port = (ushort)fd_ushort_bswap( (ushort)pkt->udp->net_sport );
98 :
99 3000021 : fd_quic_retry_data_new( &retry_token->data, nonce0, nonce1 );
100 3000021 : fd_quic_retry_data_set_ip4( &retry_token->data, src_ip4_addr );
101 3000021 : retry_token->data.udp_port = (ushort)src_udp_port;
102 3000021 : retry_token->data.expire_comp = (ulong)( expire_at >> FD_QUIC_RETRY_EXPIRE_SHIFT );
103 :
104 3000021 : retry_token->data.rscid = new_conn_id;
105 3000021 : retry_token->data.odcid_sz = orig_dst_conn_id->sz;
106 3000021 : memcpy( retry_token->data.odcid, orig_dst_conn_id->conn_id, FD_QUIC_MAX_CONN_ID_SZ ); /* oversz copy ok */
107 :
108 : /* Create the inner integrity tag (non-standard) */
109 :
110 3000021 : fd_aes_gcm_t aes_gcm[1];
111 3000021 : fd_quic_retry_token_sign( retry_token, aes_gcm, retry_secret, retry_iv );
112 3000021 : memset( aes_gcm, 0, sizeof(fd_aes_gcm_t) );
113 :
114 3000021 : out_ptr += sizeof(fd_quic_retry_token_t);
115 3000021 : out_free -= sizeof(fd_quic_retry_token_t);
116 :
117 : # if FD_QUIC_DISABLE_CRYPTO
118 :
119 : memset( out_ptr, 0, FD_QUIC_CRYPTO_TAG_SZ );
120 : out_ptr += FD_QUIC_CRYPTO_TAG_SZ;
121 : out_free -= FD_QUIC_CRYPTO_TAG_SZ;
122 :
123 : # else
124 :
125 : /* Create the outer integrity tag (standard) */
126 :
127 3000021 : ulong retry_unsigned_sz = (ulong)out_ptr - (ulong)retry;
128 :
129 3000021 : uchar retry_pseudo_buf[ FD_QUIC_RETRY_MAX_PSEUDO_SZ ];
130 3000021 : ulong retry_pseudo_sz = fd_quic_retry_pseudo( retry_pseudo_buf, retry, retry_unsigned_sz + FD_QUIC_CRYPTO_TAG_SZ, orig_dst_conn_id );
131 3000021 : if( FD_UNLIKELY( retry_pseudo_sz==FD_QUIC_PARSE_FAIL ) ) FD_LOG_ERR(( "fd_quic_retry_pseudo_hdr failed" ));
132 3000021 : fd_quic_retry_integrity_tag_sign( aes_gcm, retry_pseudo_buf, retry_pseudo_sz, out_ptr );
133 3000021 : out_ptr += FD_QUIC_CRYPTO_TAG_SZ;
134 3000021 : out_free -= FD_QUIC_CRYPTO_TAG_SZ;
135 :
136 3000021 : # endif /* FD_QUIC_DISABLE_CRYPTO */
137 :
138 3000021 : FD_DCHECK_CRIT( (ulong)out_ptr - (ulong)retry <= FD_QUIC_RETRY_LOCAL_SZ, "retry packet overflow" );
139 3000021 : ulong retry_sz = (ulong)out_ptr - (ulong)retry;
140 3000021 : return retry_sz;
141 3000021 : }
142 :
143 : int
144 : fd_quic_retry_server_verify(
145 : fd_quic_pkt_t const * pkt,
146 : fd_quic_initial_t const * initial,
147 : fd_quic_conn_id_t * orig_dst_conn_id, /* out */
148 : ulong * retry_src_conn_id, /* out */
149 : uchar const retry_secret[ FD_QUIC_RETRY_SECRET_SZ ],
150 : uchar const retry_iv[ FD_QUIC_RETRY_IV_SZ ],
151 : long now,
152 : long ttl
153 3002067 : ) {
154 :
155 : /* We told the client to retry with a DCID chosen by us, and we
156 : always use conn IDs of the same size */
157 3002067 : if( FD_UNLIKELY( initial->dst_conn_id_len != FD_QUIC_CONN_ID_SZ ) ) {
158 0 : FD_DEBUG( FD_LOG_DEBUG(( "Retry with weird dst conn ID sz, rejecting" )); )
159 0 : return FD_QUIC_FAILED;
160 0 : }
161 :
162 : /* fd_quic always uses retry tokens of the same size */
163 3002067 : if( FD_UNLIKELY( initial->token_len != sizeof(fd_quic_retry_token_t) ) ) {
164 0 : FD_DEBUG( FD_LOG_DEBUG(( "Retry with weird token sz, rejecting" )); )
165 0 : return FD_QUIC_FAILED;
166 0 : }
167 :
168 3002067 : fd_quic_retry_token_t const * retry_token = fd_type_pun_const( initial->token );
169 3002067 : if( FD_UNLIKELY( retry_token->data.odcid_sz > FD_QUIC_MAX_CONN_ID_SZ ) ) {
170 0 : FD_DEBUG( FD_LOG_DEBUG(( "Retry token with invalid ODCID or RSCID, rejecting" )); )
171 0 : return FD_QUIC_FAILED;
172 0 : }
173 :
174 3002067 : fd_aes_gcm_t aes_gcm[1];
175 3002067 : int vfy_res = fd_quic_retry_token_verify( retry_token, aes_gcm, retry_secret, retry_iv );
176 3002067 : memset( aes_gcm, 0, sizeof(fd_aes_gcm_t) );
177 :
178 3002067 : uint pkt_ip4 = pkt->ip4->saddr;
179 3002067 : uint retry_ip4 = FD_LOAD( uint, retry_token->data.ip6_addr + 12 );
180 3002067 : int is_ip4 = 0==memcmp( retry_token->data.ip6_addr, "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xff\xff", 12 );
181 3002067 : uint pkt_port = fd_ushort_bswap( (ushort)pkt->udp->net_sport );
182 3002067 : uint retry_port = retry_token->data.udp_port;
183 3002067 : long expire_at = (long)retry_token->data.expire_comp << FD_QUIC_RETRY_EXPIRE_SHIFT;
184 3002067 : long expire_before = now + ttl;
185 :
186 3002067 : int is_match =
187 3002067 : vfy_res == FD_QUIC_SUCCESS &&
188 3002067 : is_ip4 &&
189 3002067 : pkt_ip4 == retry_ip4 &&
190 3002067 : pkt_port == retry_port &&
191 3002067 : now < expire_at &&
192 3002067 : expire_at < expire_before; /* token was issued in the future */
193 :
194 3002067 : FD_DEBUG(
195 3002067 : if( vfy_res!=FD_QUIC_SUCCESS ) FD_LOG_DEBUG(( "Invalid Retry Token" ));
196 3002067 : else if( now >= expire_at ) FD_LOG_DEBUG(( "Expired Retry Token" ));
197 3002067 : else if( expire_at >= expire_before ) FD_LOG_WARNING(( "Retry Token issued in the future" ));
198 3002067 : else if( !is_match ) FD_LOG_DEBUG(( "Foreign Retry Token" ));
199 3002067 : )
200 :
201 3002067 : orig_dst_conn_id->sz = (uchar)retry_token->data.odcid_sz;
202 3002067 : memcpy( orig_dst_conn_id->conn_id, retry_token->data.odcid, FD_QUIC_MAX_CONN_ID_SZ ); /* oversz copy ok */
203 3002067 : *retry_src_conn_id = retry_token->data.rscid;
204 :
205 3002067 : return is_match ? FD_QUIC_SUCCESS : FD_QUIC_FAILED;
206 3002067 : }
207 :
208 : int
209 : fd_quic_retry_client_verify( uchar const * const retry_ptr,
210 : ulong const retry_sz,
211 : fd_quic_conn_id_t const * orig_dst_conn_id,
212 : fd_quic_conn_id_t * src_conn_id, /* out */
213 : uchar const ** token,
214 3002778 : ulong * token_sz ) {
215 :
216 3002778 : uchar const * cur_ptr = retry_ptr;
217 3002778 : ulong cur_sz = retry_sz;
218 :
219 : /* Consume retry header */
220 :
221 3002778 : fd_quic_retry_hdr_t retry_hdr[1] = {{0}};
222 3002778 : ulong decode_rc = fd_quic_decode_retry_hdr( retry_hdr, cur_ptr, cur_sz );
223 3002778 : if( FD_UNLIKELY( decode_rc == FD_QUIC_PARSE_FAIL ) ) {
224 24 : FD_DEBUG( FD_LOG_DEBUG(( "fd_quic_decode_retry failed" )); )
225 24 : return FD_QUIC_FAILED;
226 24 : }
227 3002754 : cur_ptr += decode_rc;
228 3002754 : cur_sz -= decode_rc;
229 :
230 3002754 : if( FD_UNLIKELY( retry_hdr->src_conn_id_len == 0 ) ) {
231 : /* something is horribly broken or some attack - ignore packet */
232 15 : FD_DEBUG( FD_LOG_DEBUG(( "Missing source conn ID" )); )
233 15 : return FD_QUIC_FAILED;
234 15 : }
235 :
236 : /* Consume retry token
237 : > A client MUST discard a Retry packet with a zero-length Retry Token field. */
238 :
239 3002739 : if( FD_UNLIKELY( cur_sz <= FD_QUIC_CRYPTO_TAG_SZ ) ) {
240 0 : FD_DEBUG( FD_LOG_DEBUG(( "Retry packet is too small" )); )
241 0 : return FD_QUIC_FAILED;
242 0 : }
243 3002739 : uchar const * retry_token = cur_ptr;
244 3002739 : ulong retry_token_sz = cur_sz - FD_QUIC_CRYPTO_TAG_SZ;
245 3002739 : if( FD_UNLIKELY( retry_token_sz > FD_QUIC_RETRY_MAX_TOKEN_SZ ) ) {
246 0 : FD_DEBUG( FD_LOG_DEBUG(( "Retry token is too long (%lu bytes)", retry_token_sz )); )
247 0 : return FD_QUIC_FAILED;
248 0 : }
249 :
250 3002739 : cur_ptr += retry_token_sz;
251 3002739 : cur_sz -= retry_token_sz;
252 :
253 : /* Consume retry integrity tag */
254 :
255 3002739 : uchar const * retry_tag = cur_ptr;
256 3002739 : FD_DCHECK_CRIT( cur_sz==FD_QUIC_CRYPTO_TAG_SZ, "invalid retry tag size" );
257 3002739 : cur_ptr += FD_QUIC_CRYPTO_TAG_SZ;
258 3002739 : cur_sz -= FD_QUIC_CRYPTO_TAG_SZ;
259 :
260 : /* Construct Retry Pseudo Header required to validate Retry Integrity
261 : Tag. TODO This could be made more efficient using streaming
262 : AES-GCM. */
263 :
264 3002739 : uchar retry_pseudo_buf[ FD_QUIC_RETRY_MAX_PSEUDO_SZ ];
265 3002739 : ulong retry_pseudo_sz = fd_quic_retry_pseudo( retry_pseudo_buf, retry_ptr, retry_sz, orig_dst_conn_id );
266 3002739 : if( FD_UNLIKELY( retry_pseudo_sz==FD_QUIC_PARSE_FAIL ) ) FD_LOG_ERR(( "fd_quic_retry_pseudo_hdr failed" ));
267 :
268 : # if FD_QUIC_DISABLE_CRYPTO
269 :
270 : (void)retry_tag; /* skip verification */
271 :
272 : # else
273 :
274 : /* Validate the retry integrity tag
275 :
276 : Retry packets (see Section 17.2.5 of [QUIC-TRANSPORT]) carry a Retry Integrity Tag that
277 : provides two properties: it allows the discarding of packets that have accidentally been
278 : corrupted by the network, and only an entity that observes an Initial packet can send a valid
279 : Retry packet.*/
280 3002739 : fd_aes_gcm_t aes_gcm[1];
281 3002739 : int rc = fd_quic_retry_integrity_tag_verify( aes_gcm, retry_pseudo_buf, retry_pseudo_sz, retry_tag );
282 3002739 : if( FD_UNLIKELY( rc == FD_QUIC_FAILED ) ) {
283 : /* Clients MUST discard Retry packets that have a Retry Integrity Tag that
284 : cannot be validated */
285 2721 : FD_DEBUG( FD_LOG_DEBUG(( "Invalid retry integrity tag" )); )
286 2721 : return FD_QUIC_FAILED;
287 2721 : }
288 :
289 3000018 : # endif
290 :
291 : /* Set out params */
292 :
293 3000018 : src_conn_id[0].sz = retry_hdr->src_conn_id_len;
294 3000018 : memcpy( src_conn_id[0].conn_id, retry_hdr->src_conn_id, FD_QUIC_MAX_CONN_ID_SZ ); /* oversz copy ok */
295 :
296 3000018 : *token = retry_token;
297 3000018 : *token_sz = retry_token_sz;
298 :
299 3000018 : return FD_QUIC_SUCCESS;
300 3002739 : }
|