Files
krata/network/src/proxynat/icmp.rs

201 lines
7.7 KiB
Rust
Raw Normal View History

2024-02-10 21:13:47 +00:00
use std::{net::IpAddr, time::Duration};
2024-02-10 15:18:12 +00:00
use anyhow::{anyhow, Result};
use async_trait::async_trait;
2024-02-10 21:13:47 +00:00
use etherparse::{
Icmpv4Header, Icmpv4Type, Icmpv6Header, Icmpv6Type, IpNumber, NetSlice, PacketBuilder,
SlicedPacket,
};
2024-02-10 15:18:12 +00:00
use log::{debug, warn};
use smoltcp::wire::IpAddress;
use tokio::{
select,
sync::mpsc::{Receiver, Sender},
};
2024-02-10 21:13:47 +00:00
use crate::{
icmp::{IcmpClient, IcmpProtocol, IcmpReply},
nat::{NatHandler, NatKey},
};
2024-02-10 15:18:12 +00:00
const ICMP_PING_TIMEOUT_SECS: u64 = 20;
const ICMP_TIMEOUT_SECS: u64 = 30;
pub struct ProxyIcmpHandler {
key: NatKey,
rx_sender: Sender<Vec<u8>>,
}
#[async_trait]
impl NatHandler for ProxyIcmpHandler {
async fn receive(&self, data: &[u8]) -> Result<()> {
self.rx_sender.try_send(data.to_vec())?;
Ok(())
}
}
enum ProxyIcmpSelect {
Internal(Vec<u8>),
Close,
}
impl ProxyIcmpHandler {
pub fn new(key: NatKey, rx_sender: Sender<Vec<u8>>) -> Self {
ProxyIcmpHandler { key, rx_sender }
}
pub async fn spawn(
&mut self,
rx_receiver: Receiver<Vec<u8>>,
tx_sender: Sender<Vec<u8>>,
reclaim_sender: Sender<NatKey>,
) -> Result<()> {
2024-02-10 21:13:47 +00:00
let client = IcmpClient::new(IcmpProtocol::Icmp4)?;
2024-02-10 15:18:12 +00:00
let key = self.key;
tokio::spawn(async move {
if let Err(error) =
ProxyIcmpHandler::process(client, key, rx_receiver, tx_sender, reclaim_sender).await
{
warn!("processing of icmp proxy failed: {}", error);
}
});
Ok(())
}
async fn process(
2024-02-10 21:13:47 +00:00
client: IcmpClient,
2024-02-10 15:18:12 +00:00
key: NatKey,
mut rx_receiver: Receiver<Vec<u8>>,
tx_sender: Sender<Vec<u8>>,
reclaim_sender: Sender<NatKey>,
) -> Result<()> {
loop {
let deadline = tokio::time::sleep(Duration::from_secs(ICMP_TIMEOUT_SECS));
let selection = select! {
x = rx_receiver.recv() => if let Some(data) = x {
ProxyIcmpSelect::Internal(data)
} else {
ProxyIcmpSelect::Close
},
_ = deadline => ProxyIcmpSelect::Close,
};
match selection {
ProxyIcmpSelect::Internal(data) => {
let packet = SlicedPacket::from_ethernet(&data)?;
let Some(ref net) = packet.net else {
continue;
};
2024-02-10 21:13:47 +00:00
match net {
NetSlice::Ipv4(ipv4) => {
if ipv4.header().protocol() != IpNumber::ICMP {
continue;
}
2024-02-10 15:18:12 +00:00
2024-02-10 21:13:47 +00:00
let (header, payload) =
Icmpv4Header::from_slice(ipv4.payload().payload)?;
if let Icmpv4Type::EchoRequest(echo) = header.icmp_type {
let IpAddr::V4(external_ipv4) = key.external_ip.addr.into() else {
continue;
};
let Some(IcmpReply::Icmp4 {
header: _,
echo,
payload,
}) = client
.ping4(
external_ipv4,
echo.id,
echo.seq,
payload,
Duration::from_secs(ICMP_PING_TIMEOUT_SECS),
)
.await?
else {
continue;
};
let packet =
PacketBuilder::ethernet2(key.local_mac.0, key.client_mac.0);
let packet = match (key.external_ip.addr, key.client_ip.addr) {
(
IpAddress::Ipv4(external_addr),
IpAddress::Ipv4(client_addr),
) => packet.ipv4(external_addr.0, client_addr.0, 20),
_ => {
return Err(anyhow!("IP endpoint mismatch"));
2024-02-10 15:18:12 +00:00
}
2024-02-10 21:13:47 +00:00
};
let packet = packet.icmpv4_echo_reply(echo.id, echo.seq);
let mut buffer: Vec<u8> = Vec::new();
packet.write(&mut buffer, &payload)?;
if let Err(error) = tx_sender.try_send(buffer) {
debug!("failed to transmit icmp packet: {}", error);
2024-02-10 15:18:12 +00:00
}
2024-02-10 21:13:47 +00:00
}
}
2024-02-10 15:18:12 +00:00
2024-02-10 21:13:47 +00:00
NetSlice::Ipv6(ipv6) => {
if ipv6.header().next_header() != IpNumber::ICMP {
continue;
}
2024-02-10 15:18:12 +00:00
2024-02-10 21:13:47 +00:00
let (header, payload) =
Icmpv6Header::from_slice(ipv6.payload().payload)?;
if let Icmpv6Type::EchoRequest(echo) = header.icmp_type {
let IpAddr::V6(external_ipv6) = key.external_ip.addr.into() else {
continue;
};
let Some(IcmpReply::Icmp6 {
header: _,
echo,
payload,
}) = client
.ping6(
external_ipv6,
echo.id,
echo.seq,
payload,
Duration::from_secs(ICMP_PING_TIMEOUT_SECS),
)
.await?
else {
continue;
};
let packet =
PacketBuilder::ethernet2(key.local_mac.0, key.client_mac.0);
let packet = match (key.external_ip.addr, key.client_ip.addr) {
(
IpAddress::Ipv6(external_addr),
IpAddress::Ipv6(client_addr),
) => packet.ipv6(external_addr.0, client_addr.0, 20),
_ => {
return Err(anyhow!("IP endpoint mismatch"));
}
};
let packet = packet.icmpv6_echo_reply(echo.id, echo.seq);
let mut buffer: Vec<u8> = Vec::new();
packet.write(&mut buffer, &payload)?;
if let Err(error) = tx_sender.try_send(buffer) {
debug!("failed to transmit icmp packet: {}", error);
}
2024-02-10 15:18:12 +00:00
}
}
}
}
ProxyIcmpSelect::Close => {
reclaim_sender.send(key).await?;
break;
}
}
}
Ok(())
}
}