Line | Count | Source |
1 | | // Copyright (c) 2009-2010 Satoshi Nakamoto |
2 | | // Copyright (c) 2009-present The Bitcoin Core developers |
3 | | // Distributed under the MIT software license, see the accompanying |
4 | | // file COPYING or http://www.opensource.org/licenses/mit-license.php. |
5 | | |
6 | | #include <bitcoin-build-config.h> // IWYU pragma: keep |
7 | | |
8 | | #include <net.h> |
9 | | |
10 | | #include <addrdb.h> |
11 | | #include <addrman.h> |
12 | | #include <banman.h> |
13 | | #include <clientversion.h> |
14 | | #include <common/args.h> |
15 | | #include <common/netif.h> |
16 | | #include <compat/compat.h> |
17 | | #include <consensus/consensus.h> |
18 | | #include <crypto/sha256.h> |
19 | | #include <i2p.h> |
20 | | #include <key.h> |
21 | | #include <logging.h> |
22 | | #include <memusage.h> |
23 | | #include <net_permissions.h> |
24 | | #include <netaddress.h> |
25 | | #include <netbase.h> |
26 | | #include <node/eviction.h> |
27 | | #include <node/interface_ui.h> |
28 | | #include <protocol.h> |
29 | | #include <random.h> |
30 | | #include <scheduler.h> |
31 | | #include <util/fs.h> |
32 | | #include <util/overflow.h> |
33 | | #include <util/sock.h> |
34 | | #include <util/strencodings.h> |
35 | | #include <util/thread.h> |
36 | | #include <util/threadinterrupt.h> |
37 | | #include <util/trace.h> |
38 | | #include <util/translation.h> |
39 | | #include <util/vector.h> |
40 | | |
41 | | #include <algorithm> |
42 | | #include <array> |
43 | | #include <cmath> |
44 | | #include <cstdint> |
45 | | #include <cstring> |
46 | | #include <functional> |
47 | | #include <optional> |
48 | | #include <string_view> |
49 | | #include <unordered_map> |
50 | | |
51 | | TRACEPOINT_SEMAPHORE(net, closed_connection); |
52 | | TRACEPOINT_SEMAPHORE(net, evicted_inbound_connection); |
53 | | TRACEPOINT_SEMAPHORE(net, inbound_connection); |
54 | | TRACEPOINT_SEMAPHORE(net, outbound_connection); |
55 | | TRACEPOINT_SEMAPHORE(net, outbound_message); |
56 | | |
57 | | /** Maximum number of block-relay-only anchor connections */ |
58 | | static constexpr size_t MAX_BLOCK_RELAY_ONLY_ANCHORS = 2; |
59 | | static_assert (MAX_BLOCK_RELAY_ONLY_ANCHORS <= static_cast<size_t>(MAX_BLOCK_RELAY_ONLY_CONNECTIONS), "MAX_BLOCK_RELAY_ONLY_ANCHORS must not exceed MAX_BLOCK_RELAY_ONLY_CONNECTIONS."); |
60 | | /** Anchor IP address database file name */ |
61 | | const char* const ANCHORS_DATABASE_FILENAME = "anchors.dat"; |
62 | | |
63 | | // How often to dump addresses to peers.dat |
64 | | static constexpr std::chrono::minutes DUMP_PEERS_INTERVAL{15}; |
65 | | |
66 | | /** Number of DNS seeds to query when the number of connections is low. */ |
67 | | static constexpr int DNSSEEDS_TO_QUERY_AT_ONCE = 3; |
68 | | |
69 | | /** Minimum number of outbound connections under which we will keep fetching our address seeds. */ |
70 | | static constexpr int SEED_OUTBOUND_CONNECTION_THRESHOLD = 2; |
71 | | |
72 | | /** How long to delay before querying DNS seeds |
73 | | * |
74 | | * If we have more than THRESHOLD entries in addrman, then it's likely |
75 | | * that we got those addresses from having previously connected to the P2P |
76 | | * network, and that we'll be able to successfully reconnect to the P2P |
77 | | * network via contacting one of them. So if that's the case, spend a |
78 | | * little longer trying to connect to known peers before querying the |
79 | | * DNS seeds. |
80 | | */ |
81 | | static constexpr std::chrono::seconds DNSSEEDS_DELAY_FEW_PEERS{11}; |
82 | | static constexpr std::chrono::minutes DNSSEEDS_DELAY_MANY_PEERS{5}; |
83 | | static constexpr int DNSSEEDS_DELAY_PEER_THRESHOLD = 1000; // "many" vs "few" peers |
84 | | |
85 | | /** The default timeframe for -maxuploadtarget. 1 day. */ |
86 | | static constexpr std::chrono::seconds MAX_UPLOAD_TIMEFRAME{60 * 60 * 24}; |
87 | | |
88 | | // A random time period (0 to 1 seconds) is added to feeler connections to prevent synchronization. |
89 | | static constexpr auto FEELER_SLEEP_WINDOW{1s}; |
90 | | |
91 | | /** Frequency to attempt extra connections to reachable networks we're not connected to yet **/ |
92 | | static constexpr auto EXTRA_NETWORK_PEER_INTERVAL{5min}; |
93 | | |
94 | | /** Used to pass flags to the Bind() function */ |
95 | | enum BindFlags { |
96 | | BF_NONE = 0, |
97 | | BF_REPORT_ERROR = (1U << 0), |
98 | | /** |
99 | | * Do not call AddLocal() for our special addresses, e.g., for incoming |
100 | | * Tor connections, to prevent gossiping them over the network. |
101 | | */ |
102 | | BF_DONT_ADVERTISE = (1U << 1), |
103 | | }; |
104 | | |
105 | | // The set of sockets cannot be modified while waiting |
106 | | // The sleep time needs to be small to avoid new sockets stalling |
107 | | static const uint64_t SELECT_TIMEOUT_MILLISECONDS = 50; |
108 | | |
109 | | const std::string NET_MESSAGE_TYPE_OTHER = "*other*"; |
110 | | |
111 | | static const uint64_t RANDOMIZER_ID_NETGROUP = 0x6c0edd8036ef4036ULL; // SHA256("netgroup")[0:8] |
112 | | static const uint64_t RANDOMIZER_ID_LOCALHOSTNONCE = 0xd93e69e2bbfa5735ULL; // SHA256("localhostnonce")[0:8] |
113 | | static const uint64_t RANDOMIZER_ID_NETWORKKEY = 0x0e8a2b136c592a7dULL; // SHA256("networkkey")[0:8] |
114 | | // |
115 | | // Global state variables |
116 | | // |
117 | | bool fDiscover = true; |
118 | | bool fListen = true; |
119 | | GlobalMutex g_maplocalhost_mutex; |
120 | | std::map<CNetAddr, LocalServiceInfo> mapLocalHost GUARDED_BY(g_maplocalhost_mutex); |
121 | | std::string strSubVersion; |
122 | | |
123 | | size_t CSerializedNetMsg::GetMemoryUsage() const noexcept |
124 | 661k | { |
125 | 661k | return sizeof(*this) + memusage::DynamicUsage(m_type) + memusage::DynamicUsage(data); |
126 | 661k | } |
127 | | |
128 | | size_t CNetMessage::GetMemoryUsage() const noexcept |
129 | 321k | { |
130 | 321k | return sizeof(*this) + memusage::DynamicUsage(m_type) + m_recv.GetMemoryUsage(); |
131 | 321k | } |
132 | | |
133 | | void CConnman::AddAddrFetch(const std::string& strDest) |
134 | 11 | { |
135 | 11 | LOCK(m_addr_fetches_mutex); |
136 | 11 | m_addr_fetches.push_back(strDest); |
137 | 11 | } |
138 | | |
139 | | uint16_t GetListenPort() |
140 | 1.65k | { |
141 | | // If -bind= is provided with ":port" part, use that (first one if multiple are provided). |
142 | 1.67k | for (const std::string& bind_arg : gArgs.GetArgs("-bind")) { |
143 | 1.67k | constexpr uint16_t dummy_port = 0; |
144 | | |
145 | 1.67k | const std::optional<CService> bind_addr{Lookup(bind_arg, dummy_port, /*fAllowLookup=*/false)}; |
146 | 1.67k | if (bind_addr.has_value() && bind_addr->GetPort() != dummy_port) return bind_addr->GetPort(); |
147 | 1.67k | } |
148 | | |
149 | | // Otherwise, if -whitebind= without NetPermissionFlags::NoBan is provided, use that |
150 | | // (-whitebind= is required to have ":port"). |
151 | 1.63k | for (const std::string& whitebind_arg : gArgs.GetArgs("-whitebind")) { |
152 | 5 | NetWhitebindPermissions whitebind; |
153 | 5 | bilingual_str error; |
154 | 5 | if (NetWhitebindPermissions::TryParse(whitebind_arg, whitebind, error)) { |
155 | 5 | if (!NetPermissions::HasFlag(whitebind.m_flags, NetPermissionFlags::NoBan)) { |
156 | 5 | return whitebind.m_service.GetPort(); |
157 | 5 | } |
158 | 5 | } |
159 | 5 | } |
160 | | |
161 | | // Otherwise, if -port= is provided, use that. Otherwise use the default port. |
162 | 1.63k | return static_cast<uint16_t>(gArgs.GetIntArg("-port", Params().GetDefaultPort())); |
163 | 1.63k | } |
164 | | |
165 | | // Determine the "best" local address for a particular peer. |
166 | | [[nodiscard]] static std::optional<CService> GetLocal(const CNode& peer) |
167 | 1.61k | { |
168 | 1.61k | if (!fListen) return std::nullopt; |
169 | | |
170 | 1.61k | std::optional<CService> addr; |
171 | 1.61k | int nBestScore = -1; |
172 | 1.61k | int nBestReachability = -1; |
173 | 1.61k | { |
174 | 1.61k | LOCK(g_maplocalhost_mutex); |
175 | 1.61k | for (const auto& [local_addr, local_service_info] : mapLocalHost) { |
176 | | // For privacy reasons, don't advertise our privacy-network address |
177 | | // to other networks and don't advertise our other-network address |
178 | | // to privacy networks. |
179 | 95 | if (local_addr.GetNetwork() != peer.ConnectedThroughNetwork() |
180 | 95 | && (local_addr.IsPrivacyNet() || peer.IsConnectedThroughPrivacyNet())) { |
181 | 36 | continue; |
182 | 36 | } |
183 | 59 | const int nScore{local_service_info.nScore}; |
184 | 59 | const int nReachability{local_addr.GetReachabilityFrom(peer.addr)}; |
185 | 59 | if (nReachability > nBestReachability || (nReachability == nBestReachability && nScore > nBestScore)) { |
186 | 42 | addr.emplace(CService{local_addr, local_service_info.nPort}); |
187 | 42 | nBestReachability = nReachability; |
188 | 42 | nBestScore = nScore; |
189 | 42 | } |
190 | 59 | } |
191 | 1.61k | } |
192 | 1.61k | return addr; |
193 | 1.61k | } |
194 | | |
195 | | //! Convert the serialized seeds into usable address objects. |
196 | | static std::vector<CAddress> ConvertSeeds(const std::vector<uint8_t> &vSeedsIn) |
197 | 3 | { |
198 | | // It'll only connect to one or two seed nodes because once it connects, |
199 | | // it'll get a pile of addresses with newer timestamps. |
200 | | // Seed nodes are given a random 'last seen time' of between one and two |
201 | | // weeks ago. |
202 | 3 | const auto one_week{7 * 24h}; |
203 | 3 | std::vector<CAddress> vSeedsOut; |
204 | 3 | FastRandomContext rng; |
205 | 3 | ParamsStream s{SpanReader{vSeedsIn}, CAddress::V2_NETWORK}; |
206 | 3 | while (!s.empty()) { |
207 | 0 | CService endpoint; |
208 | 0 | s >> endpoint; |
209 | 0 | CAddress addr{endpoint, SeedsServiceFlags()}; |
210 | 0 | addr.nTime = rng.rand_uniform_delay(Now<NodeSeconds>() - one_week, -one_week); |
211 | 0 | LogDebug(BCLog::NET, "Added hardcoded seed: %s\n", addr.ToStringAddrPort()); |
212 | 0 | vSeedsOut.push_back(addr); |
213 | 0 | } |
214 | 3 | return vSeedsOut; |
215 | 3 | } |
216 | | |
217 | | // Determine the "best" local address for a particular peer. |
218 | | // If none, return the unroutable 0.0.0.0 but filled in with |
219 | | // the normal parameters, since the IP may be changed to a useful |
220 | | // one by discovery. |
221 | | CService GetLocalAddress(const CNode& peer) |
222 | 1.61k | { |
223 | 1.61k | return GetLocal(peer).value_or(CService{CNetAddr(), GetListenPort()}); |
224 | 1.61k | } |
225 | | |
226 | | static int GetnScore(const CService& addr) |
227 | 0 | { |
228 | 0 | LOCK(g_maplocalhost_mutex); |
229 | 0 | const auto it = mapLocalHost.find(addr); |
230 | 0 | return (it != mapLocalHost.end()) ? it->second.nScore : 0; |
231 | 0 | } |
232 | | |
233 | | // Is our peer's addrLocal potentially useful as an external IP source? |
234 | | [[nodiscard]] static bool IsPeerAddrLocalGood(CNode *pnode) |
235 | 1.59k | { |
236 | 1.59k | CService addrLocal = pnode->GetAddrLocal(); |
237 | 1.59k | return fDiscover && pnode->addr.IsRoutable() && addrLocal.IsRoutable() && |
238 | 1.59k | g_reachable_nets.Contains(addrLocal); |
239 | 1.59k | } |
240 | | |
241 | | std::optional<CService> GetLocalAddrForPeer(CNode& node) |
242 | 1.59k | { |
243 | 1.59k | CService addrLocal{GetLocalAddress(node)}; |
244 | | // If discovery is enabled, sometimes give our peer the address it |
245 | | // tells us that it sees us as in case it has a better idea of our |
246 | | // address than we do. |
247 | 1.59k | FastRandomContext rng; |
248 | 1.59k | if (IsPeerAddrLocalGood(&node) && (!addrLocal.IsRoutable() || |
249 | 4 | rng.randbits((GetnScore(addrLocal) > LOCAL_MANUAL) ? 3 : 1) == 0)) |
250 | 4 | { |
251 | 4 | if (node.IsInboundConn()) { |
252 | | // For inbound connections, assume both the address and the port |
253 | | // as seen from the peer. |
254 | 1 | addrLocal = CService{node.GetAddrLocal()}; |
255 | 3 | } else { |
256 | | // For outbound connections, assume just the address as seen from |
257 | | // the peer and leave the port in `addrLocal` as returned by |
258 | | // `GetLocalAddress()` above. The peer has no way to observe our |
259 | | // listening port when we have initiated the connection. |
260 | 3 | addrLocal.SetIP(node.GetAddrLocal()); |
261 | 3 | } |
262 | 4 | } |
263 | 1.59k | if (addrLocal.IsRoutable()) { |
264 | 28 | LogDebug(BCLog::NET, "Advertising address %s to peer=%d\n", addrLocal.ToStringAddrPort(), node.GetId()); |
265 | 28 | return addrLocal; |
266 | 28 | } |
267 | | // Address is unroutable. Don't advertise. |
268 | 1.56k | return std::nullopt; |
269 | 1.59k | } |
270 | | |
271 | | void ClearLocal() |
272 | 682 | { |
273 | 682 | LOCK(g_maplocalhost_mutex); |
274 | 682 | return mapLocalHost.clear(); |
275 | 682 | } |
276 | | |
277 | | // learn a new local address |
278 | | bool AddLocal(const CService& addr_, int nScore) |
279 | 46 | { |
280 | 46 | CService addr{MaybeFlipIPv6toCJDNS(addr_)}; |
281 | | |
282 | 46 | if (!addr.IsRoutable()) |
283 | 20 | return false; |
284 | | |
285 | 26 | if (!fDiscover && nScore < LOCAL_MANUAL) |
286 | 0 | return false; |
287 | | |
288 | 26 | if (!g_reachable_nets.Contains(addr)) |
289 | 0 | return false; |
290 | | |
291 | 26 | if (fLogIPs) { |
292 | 0 | LogInfo("AddLocal(%s,%i)\n", addr.ToStringAddrPort(), nScore); |
293 | 0 | } |
294 | | |
295 | 26 | { |
296 | 26 | LOCK(g_maplocalhost_mutex); |
297 | 26 | const auto [it, is_newly_added] = mapLocalHost.emplace(addr, LocalServiceInfo()); |
298 | 26 | LocalServiceInfo &info = it->second; |
299 | 26 | if (is_newly_added || nScore >= info.nScore) { |
300 | 26 | info.nScore = SaturatingAdd(nScore, is_newly_added ? 0 : 1); |
301 | 26 | info.nPort = addr.GetPort(); |
302 | 26 | } |
303 | 26 | } |
304 | | |
305 | 26 | return true; |
306 | 26 | } |
307 | | |
308 | | bool AddLocal(const CNetAddr &addr, int nScore) |
309 | 18 | { |
310 | 18 | return AddLocal(CService(addr, GetListenPort()), nScore); |
311 | 18 | } |
312 | | |
313 | | void RemoveLocal(const CService& addr) |
314 | 12 | { |
315 | 12 | LOCK(g_maplocalhost_mutex); |
316 | 12 | if (fLogIPs) { |
317 | 0 | LogInfo("RemoveLocal(%s)\n", addr.ToStringAddrPort()); |
318 | 0 | } |
319 | | |
320 | 12 | mapLocalHost.erase(addr); |
321 | 12 | } |
322 | | |
323 | | /** vote for a local address */ |
324 | | bool SeenLocal(const CService& addr) |
325 | 2 | { |
326 | 2 | LOCK(g_maplocalhost_mutex); |
327 | 2 | const auto it = mapLocalHost.find(addr); |
328 | 2 | if (it == mapLocalHost.end()) return false; |
329 | 2 | it->second.nScore = SaturatingAdd(it->second.nScore, 1); |
330 | 2 | return true; |
331 | 2 | } |
332 | | |
333 | | |
334 | | /** check whether a given address is potentially local */ |
335 | | bool IsLocal(const CService& addr) |
336 | 189 | { |
337 | 189 | LOCK(g_maplocalhost_mutex); |
338 | 189 | return mapLocalHost.contains(addr); |
339 | 189 | } |
340 | | |
341 | | bool CConnman::AlreadyConnectedToHost(std::string_view host) const |
342 | 603 | { |
343 | 603 | LOCK(m_nodes_mutex); |
344 | 741 | return std::ranges::any_of(m_nodes, [&host](CNode* node) { return node->m_addr_name == host; }); |
345 | 603 | } |
346 | | |
347 | | bool CConnman::AlreadyConnectedToAddressPort(const CService& addr_port) const |
348 | 646 | { |
349 | 646 | LOCK(m_nodes_mutex); |
350 | 946 | return std::ranges::any_of(m_nodes, [&addr_port](CNode* node) { return node->addr == addr_port; }); |
351 | 646 | } |
352 | | |
353 | | bool CConnman::AlreadyConnectedToAddress(const CNetAddr& addr) const |
354 | 76 | { |
355 | 76 | LOCK(m_nodes_mutex); |
356 | 375 | return std::ranges::any_of(m_nodes, [&addr](CNode* node) { return node->addr == addr; }); |
357 | 76 | } |
358 | | |
359 | | bool CConnman::CheckIncomingNonce(uint64_t nonce) |
360 | 1.02k | { |
361 | 1.02k | LOCK(m_nodes_mutex); |
362 | 4.88k | for (const CNode* pnode : m_nodes) { |
363 | | // Omit private broadcast connections from this check to prevent this privacy attack: |
364 | | // - We connect to a peer in an attempt to privately broadcast a transaction. From our |
365 | | // VERSION message the peer deducts that this is a short-lived connection for |
366 | | // broadcasting a transaction, takes our nonce and delays their VERACK. |
367 | | // - The peer starts connecting to (clearnet) nodes and sends them a VERSION message |
368 | | // which contains our nonce. If the peer manages to connect to us we would disconnect. |
369 | | // - Upon a disconnect, the peer knows our clearnet address. They go back to the short |
370 | | // lived privacy broadcast connection and continue with VERACK. |
371 | 4.88k | if (!pnode->fSuccessfullyConnected && !pnode->IsInboundConn() && !pnode->IsPrivateBroadcastConn() && |
372 | 4.88k | pnode->GetLocalNonce() == nonce) |
373 | 2 | return false; |
374 | 4.88k | } |
375 | 1.02k | return true; |
376 | 1.02k | } |
377 | | |
378 | | CNode* CConnman::ConnectNode(CAddress addrConnect, |
379 | | const char* pszDest, |
380 | | bool fCountFailure, |
381 | | ConnectionType conn_type, |
382 | | bool use_v2transport, |
383 | | const std::optional<Proxy>& proxy_override) |
384 | 662 | { |
385 | 662 | AssertLockNotHeld(m_nodes_mutex); |
386 | 662 | AssertLockNotHeld(m_unused_i2p_sessions_mutex); |
387 | 662 | assert(conn_type != ConnectionType::INBOUND); |
388 | | |
389 | 662 | if (pszDest == nullptr) { |
390 | 49 | if (IsLocal(addrConnect)) |
391 | 0 | return nullptr; |
392 | | |
393 | | // Look for an existing connection |
394 | 49 | if (AlreadyConnectedToAddressPort(addrConnect)) { |
395 | 0 | LogInfo("Failed to open new connection to %s, already connected", addrConnect.ToStringAddrPort()); |
396 | 0 | return nullptr; |
397 | 0 | } |
398 | 49 | } |
399 | | |
400 | 662 | LogDebug(BCLog::NET, "trying %s connection (%s) to %s, lastseen=%.1fhrs\n", |
401 | 662 | use_v2transport ? "v2" : "v1", |
402 | 662 | ConnectionTypeAsString(conn_type), |
403 | 662 | pszDest ? pszDest : addrConnect.ToStringAddrPort(), |
404 | 662 | Ticks<HoursDouble>(pszDest ? 0h : Now<NodeSeconds>() - addrConnect.nTime)); |
405 | | |
406 | | // Resolve |
407 | 662 | const uint16_t default_port{pszDest != nullptr ? GetDefaultPort(pszDest) : |
408 | 662 | m_params.GetDefaultPort()}; |
409 | | |
410 | | // Collection of addresses to try to connect to: either all dns resolved addresses if a domain name (pszDest) is provided, or addrConnect otherwise. |
411 | 662 | std::vector<CAddress> connect_to{}; |
412 | 662 | if (pszDest) { |
413 | 613 | std::vector<CService> resolved{Lookup(pszDest, default_port, fNameLookup && !HaveNameProxy(), 256)}; |
414 | 613 | if (!resolved.empty()) { |
415 | 599 | std::shuffle(resolved.begin(), resolved.end(), FastRandomContext()); |
416 | | // If the connection is made by name, it can be the case that the name resolves to more than one address. |
417 | | // We don't want to connect any more of them if we are already connected to one |
418 | 599 | for (const auto& r : resolved) { |
419 | 599 | addrConnect = CAddress{MaybeFlipIPv6toCJDNS(r), NODE_NONE}; |
420 | 599 | if (!addrConnect.IsValid()) { |
421 | 2 | LogDebug(BCLog::NET, "Resolver returned invalid address %s for %s\n", addrConnect.ToStringAddrPort(), pszDest); |
422 | 2 | return nullptr; |
423 | 2 | } |
424 | | // It is possible that we already have a connection to the IP/port pszDest resolved to. |
425 | | // In that case, drop the connection that was just created. |
426 | 597 | if (AlreadyConnectedToAddressPort(addrConnect)) { |
427 | 10 | LogInfo("Not opening a connection to %s, already connected to %s\n", pszDest, addrConnect.ToStringAddrPort()); |
428 | 10 | return nullptr; |
429 | 10 | } |
430 | | // Add the address to the resolved addresses vector so we can try to connect to it later on |
431 | 587 | connect_to.push_back(addrConnect); |
432 | 587 | } |
433 | 599 | } else { |
434 | | // For resolution via proxy |
435 | 14 | connect_to.push_back(addrConnect); |
436 | 14 | } |
437 | 613 | } else { |
438 | | // Connect via addrConnect directly |
439 | 49 | connect_to.push_back(addrConnect); |
440 | 49 | } |
441 | | |
442 | | // Connect |
443 | 650 | std::unique_ptr<Sock> sock; |
444 | 650 | CService addr_bind; |
445 | 650 | assert(!addr_bind.IsValid()); |
446 | 650 | std::unique_ptr<i2p::sam::Session> i2p_transient_session; |
447 | | |
448 | 650 | for (auto& target_addr : connect_to) { |
449 | 650 | if (target_addr.IsValid()) { |
450 | 636 | const std::optional<Proxy> use_proxy{ |
451 | 636 | proxy_override.has_value() ? proxy_override : GetProxy(target_addr.GetNetwork()), |
452 | 636 | }; |
453 | 636 | bool proxyConnectionFailed = false; |
454 | | |
455 | 636 | if (target_addr.IsI2P() && use_proxy) { |
456 | 11 | i2p::Connection conn; |
457 | 11 | bool connected{false}; |
458 | | |
459 | | // If an I2P SAM session already exists, normally we would re-use it. But in the case of |
460 | | // private broadcast we force a new transient session. A Connect() using m_i2p_sam_session |
461 | | // would use our permanent I2P address as a source address. |
462 | 11 | if (m_i2p_sam_session && conn_type != ConnectionType::PRIVATE_BROADCAST) { |
463 | 3 | connected = m_i2p_sam_session->Connect(target_addr, conn, proxyConnectionFailed); |
464 | 8 | } else { |
465 | 8 | { |
466 | 8 | LOCK(m_unused_i2p_sessions_mutex); |
467 | 8 | if (m_unused_i2p_sessions.empty()) { |
468 | 2 | i2p_transient_session = |
469 | 2 | std::make_unique<i2p::sam::Session>(*use_proxy, m_interrupt_net); |
470 | 6 | } else { |
471 | 6 | i2p_transient_session.swap(m_unused_i2p_sessions.front()); |
472 | 6 | m_unused_i2p_sessions.pop(); |
473 | 6 | } |
474 | 8 | } |
475 | 8 | connected = i2p_transient_session->Connect(target_addr, conn, proxyConnectionFailed); |
476 | 8 | if (!connected) { |
477 | 8 | LOCK(m_unused_i2p_sessions_mutex); |
478 | 8 | if (m_unused_i2p_sessions.size() < MAX_UNUSED_I2P_SESSIONS_SIZE) { |
479 | 8 | m_unused_i2p_sessions.emplace(i2p_transient_session.release()); |
480 | 8 | } |
481 | 8 | } |
482 | 8 | } |
483 | | |
484 | 11 | if (connected) { |
485 | 0 | sock = std::move(conn.sock); |
486 | 0 | addr_bind = conn.me; |
487 | 0 | } |
488 | 625 | } else if (use_proxy) { |
489 | 86 | LogDebug(BCLog::PROXY, "Using proxy: %s to connect to %s\n", use_proxy->ToString(), target_addr.ToStringAddrPort()); |
490 | 86 | sock = ConnectThroughProxy(*use_proxy, target_addr.ToStringAddr(), target_addr.GetPort(), proxyConnectionFailed); |
491 | 539 | } else { |
492 | | // No proxy needed (none set for target network). Private broadcast connections |
493 | | // must always use a proxy, otherwise they would leak the originator's IP address. |
494 | 539 | if (Assume(conn_type != ConnectionType::PRIVATE_BROADCAST)) { |
495 | 539 | sock = ConnectDirectly(target_addr, conn_type == ConnectionType::MANUAL); |
496 | 539 | } |
497 | 539 | } |
498 | 636 | if (!proxyConnectionFailed) { |
499 | | // If a connection to the node was attempted, and failure (if any) is not caused by a problem connecting to |
500 | | // the proxy, mark this as an attempt. |
501 | 620 | addrman.get().Attempt(target_addr, fCountFailure); |
502 | 620 | } |
503 | 636 | } else if (pszDest) { |
504 | 14 | if (const auto name_proxy = GetNameProxy()) { |
505 | 14 | std::string host; |
506 | 14 | uint16_t port{default_port}; |
507 | 14 | SplitHostPort(pszDest, port, host); |
508 | 14 | bool proxyConnectionFailed; |
509 | 14 | sock = ConnectThroughProxy(*name_proxy, host, port, proxyConnectionFailed); |
510 | 14 | } |
511 | 14 | } |
512 | | // Check any other resolved address (if any) if we fail to connect |
513 | 650 | if (!sock) { |
514 | 26 | continue; |
515 | 26 | } |
516 | | |
517 | 624 | NetPermissionFlags permission_flags = NetPermissionFlags::None; |
518 | 624 | std::vector<NetWhitelistPermissions> whitelist_permissions = conn_type == ConnectionType::MANUAL ? vWhitelistedRangeOutgoing : std::vector<NetWhitelistPermissions>{}; |
519 | 624 | AddWhitelistPermissionFlags(permission_flags, target_addr, whitelist_permissions); |
520 | | |
521 | | // Add node |
522 | 624 | NodeId id = GetNewNodeId(); |
523 | 624 | uint64_t nonce = GetDeterministicRandomizer(RANDOMIZER_ID_LOCALHOSTNONCE).Write(id).Finalize(); |
524 | 624 | if (!addr_bind.IsValid()) { |
525 | 624 | addr_bind = GetBindAddress(*sock); |
526 | 624 | } |
527 | 624 | uint64_t network_id = GetDeterministicRandomizer(RANDOMIZER_ID_NETWORKKEY) |
528 | 624 | .Write(target_addr.GetNetClass()) |
529 | 624 | .Write(addr_bind.GetAddrBytes()) |
530 | | // For outbound connections, the port of the bound address is randomly |
531 | | // assigned by the OS and would therefore not be useful for seeding. |
532 | 624 | .Write(0) |
533 | 624 | .Finalize(); |
534 | 624 | CNode* pnode = new CNode(id, |
535 | 624 | std::move(sock), |
536 | 624 | target_addr, |
537 | 624 | CalculateKeyedNetGroup(target_addr), |
538 | 624 | nonce, |
539 | 624 | addr_bind, |
540 | 624 | pszDest ? pszDest : "", |
541 | 624 | conn_type, |
542 | 624 | /*inbound_onion=*/false, |
543 | 624 | network_id, |
544 | 624 | CNodeOptions{ |
545 | 624 | .permission_flags = permission_flags, |
546 | 624 | .proxy_override = proxy_override, |
547 | 624 | .i2p_sam_session = std::move(i2p_transient_session), |
548 | 624 | .recv_flood_size = nReceiveFloodSize, |
549 | 624 | .use_v2transport = use_v2transport, |
550 | 624 | }); |
551 | 624 | pnode->AddRef(); |
552 | | |
553 | | // We're making a new connection, harvest entropy from the time (and our peer count) |
554 | 624 | RandAddEvent((uint32_t)id); |
555 | | |
556 | 624 | return pnode; |
557 | 650 | } |
558 | | |
559 | 26 | return nullptr; |
560 | 650 | } |
561 | | |
562 | | void CNode::CloseSocketDisconnect() |
563 | 2.25k | { |
564 | 2.25k | fDisconnect = true; |
565 | 2.25k | LOCK(m_sock_mutex); |
566 | 2.25k | if (m_sock) { |
567 | 1.66k | LogDebug(BCLog::NET, "Resetting socket for %s", LogPeer()); |
568 | 1.66k | m_sock.reset(); |
569 | | |
570 | 1.66k | TRACEPOINT(net, closed_connection, |
571 | 1.66k | GetId(), |
572 | 1.66k | m_addr_name.c_str(), |
573 | 1.66k | ConnectionTypeAsString().c_str(), |
574 | 1.66k | ConnectedThroughNetwork(), |
575 | 1.66k | TicksSinceEpoch<std::chrono::seconds>(m_connected)); |
576 | 1.66k | } |
577 | 2.25k | m_i2p_sam_session.reset(); |
578 | 2.25k | } |
579 | | |
580 | 1.67k | void CConnman::AddWhitelistPermissionFlags(NetPermissionFlags& flags, std::optional<CNetAddr> addr, const std::vector<NetWhitelistPermissions>& ranges) const { |
581 | 1.67k | for (const auto& subnet : ranges) { |
582 | 289 | if (addr.has_value() && subnet.m_subnet.Match(addr.value())) { |
583 | 289 | NetPermissions::AddFlag(flags, subnet.m_flags); |
584 | 289 | } |
585 | 289 | } |
586 | 1.67k | if (NetPermissions::HasFlag(flags, NetPermissionFlags::Implicit)) { |
587 | 5 | NetPermissions::ClearFlag(flags, NetPermissionFlags::Implicit); |
588 | 5 | if (whitelist_forcerelay) NetPermissions::AddFlag(flags, NetPermissionFlags::ForceRelay); |
589 | 5 | if (whitelist_relay) NetPermissions::AddFlag(flags, NetPermissionFlags::Relay); |
590 | 5 | NetPermissions::AddFlag(flags, NetPermissionFlags::Mempool); |
591 | 5 | NetPermissions::AddFlag(flags, NetPermissionFlags::NoBan); |
592 | 5 | } |
593 | 1.67k | } |
594 | | |
595 | | CService CNode::GetAddrLocal() const |
596 | 15.8k | { |
597 | 15.8k | AssertLockNotHeld(m_addr_local_mutex); |
598 | 15.8k | LOCK(m_addr_local_mutex); |
599 | 15.8k | return m_addr_local; |
600 | 15.8k | } |
601 | | |
602 | 1.57k | void CNode::SetAddrLocal(const CService& addrLocalIn) { |
603 | 1.57k | AssertLockNotHeld(m_addr_local_mutex); |
604 | 1.57k | LOCK(m_addr_local_mutex); |
605 | 1.57k | if (Assume(!m_addr_local.IsValid())) { // Addr local can only be set once during version msg processing |
606 | 1.57k | m_addr_local = addrLocalIn; |
607 | 1.57k | } |
608 | 1.57k | } |
609 | | |
610 | | Network CNode::ConnectedThroughNetwork() const |
611 | 14.3k | { |
612 | 14.3k | return m_inbound_onion ? NET_ONION : addr.GetNetClass(); |
613 | 14.3k | } |
614 | | |
615 | | bool CNode::IsConnectedThroughPrivacyNet() const |
616 | 57 | { |
617 | 57 | return m_inbound_onion || addr.IsPrivacyNet(); |
618 | 57 | } |
619 | | |
620 | | #undef X |
621 | 285k | #define X(name) stats.name = name |
622 | | void CNode::CopyStats(CNodeStats& stats) |
623 | 14.2k | { |
624 | 14.2k | stats.nodeid = this->GetId(); |
625 | 14.2k | X(addr); |
626 | 14.2k | X(addrBind); |
627 | 14.2k | stats.m_network = ConnectedThroughNetwork(); |
628 | 14.2k | X(m_last_send); |
629 | 14.2k | X(m_last_recv); |
630 | 14.2k | X(m_last_tx_time); |
631 | 14.2k | X(m_last_block_time); |
632 | 14.2k | X(m_connected); |
633 | 14.2k | X(m_addr_name); |
634 | 14.2k | X(nVersion); |
635 | 14.2k | { |
636 | 14.2k | LOCK(m_subver_mutex); |
637 | 14.2k | X(cleanSubVer); |
638 | 14.2k | } |
639 | 14.2k | stats.fInbound = IsInboundConn(); |
640 | 14.2k | X(m_bip152_highbandwidth_to); |
641 | 14.2k | X(m_bip152_highbandwidth_from); |
642 | 14.2k | { |
643 | 14.2k | LOCK(cs_vSend); |
644 | 14.2k | X(mapSendBytesPerMsgType); |
645 | 14.2k | X(nSendBytes); |
646 | 14.2k | } |
647 | 14.2k | { |
648 | 14.2k | LOCK(cs_vRecv); |
649 | 14.2k | X(mapRecvBytesPerMsgType); |
650 | 14.2k | X(nRecvBytes); |
651 | 14.2k | Transport::Info info = m_transport->GetInfo(); |
652 | 14.2k | stats.m_transport_type = info.transport_type; |
653 | 14.2k | if (info.session_id) stats.m_session_id = HexStr(*info.session_id); |
654 | 14.2k | } |
655 | 14.2k | X(m_permission_flags); |
656 | | |
657 | 14.2k | X(m_last_ping_time); |
658 | 14.2k | X(m_min_ping_time); |
659 | | |
660 | | // Leave string empty if addrLocal invalid (not filled in yet) |
661 | 14.2k | CService addrLocalUnlocked = GetAddrLocal(); |
662 | 14.2k | stats.addrLocal = addrLocalUnlocked.IsValid() ? addrLocalUnlocked.ToStringAddrPort() : ""; |
663 | | |
664 | 14.2k | X(m_conn_type); |
665 | 14.2k | } |
666 | | #undef X |
667 | | |
668 | | bool CNode::ReceiveMsgBytes(std::span<const uint8_t> msg_bytes, bool& complete) |
669 | 158k | { |
670 | 158k | complete = false; |
671 | 158k | const auto time{NodeClock::now()}; |
672 | 158k | LOCK(cs_vRecv); |
673 | 158k | m_last_recv = time; |
674 | 158k | nRecvBytes += msg_bytes.size(); |
675 | 491k | while (msg_bytes.size() > 0) { |
676 | | // absorb network data |
677 | 332k | if (!m_transport->ReceivedBytes(msg_bytes)) { |
678 | | // Serious transport problem, disconnect from the peer. |
679 | 10 | return false; |
680 | 10 | } |
681 | | |
682 | 332k | if (m_transport->ReceivedMessageComplete()) { |
683 | | // decompose a transport agnostic CNetMessage from the deserializer |
684 | 160k | bool reject_message{false}; |
685 | 160k | CNetMessage msg = m_transport->GetReceivedMessage(time, reject_message); |
686 | 160k | if (reject_message) { |
687 | | // Message deserialization failed. Drop the message but don't disconnect the peer. |
688 | | // store the size of the corrupt message |
689 | 82 | mapRecvBytesPerMsgType.at(NET_MESSAGE_TYPE_OTHER) += msg.m_raw_message_size; |
690 | 82 | continue; |
691 | 82 | } |
692 | | |
693 | | // Store received bytes per message type. |
694 | | // To prevent a memory DOS, only allow known message types. |
695 | 160k | auto i = mapRecvBytesPerMsgType.find(msg.m_type); |
696 | 160k | if (i == mapRecvBytesPerMsgType.end()) { |
697 | 6 | i = mapRecvBytesPerMsgType.find(NET_MESSAGE_TYPE_OTHER); |
698 | 6 | } |
699 | 160k | assert(i != mapRecvBytesPerMsgType.end()); |
700 | 160k | i->second += msg.m_raw_message_size; |
701 | | |
702 | | // push the message to the process queue, |
703 | 160k | vRecvMsg.push_back(std::move(msg)); |
704 | | |
705 | 160k | complete = true; |
706 | 160k | } |
707 | 332k | } |
708 | | |
709 | 158k | return true; |
710 | 158k | } |
711 | | |
712 | | std::string CNode::LogPeer() const |
713 | 25.8k | { |
714 | 25.8k | auto peer_info{strprintf("peer=%d", GetId())}; |
715 | 25.8k | if (fLogIPs) { |
716 | 20 | return strprintf("%s, peeraddr=%s", peer_info, addr.ToStringAddrPort()); |
717 | 25.8k | } else { |
718 | 25.8k | return peer_info; |
719 | 25.8k | } |
720 | 25.8k | } |
721 | | |
722 | | std::string CNode::DisconnectMsg() const |
723 | 1.56k | { |
724 | 1.56k | return strprintf("disconnecting %s", LogPeer()); |
725 | 1.56k | } |
726 | | |
727 | | V1Transport::V1Transport(const NodeId node_id) noexcept |
728 | 1.78k | : m_magic_bytes{Params().MessageStart()}, m_node_id{node_id} |
729 | 1.78k | { |
730 | 1.78k | LOCK(m_recv_mutex); |
731 | 1.78k | Reset(); |
732 | 1.78k | } |
733 | | |
734 | | Transport::Info V1Transport::GetInfo() const noexcept |
735 | 13.2k | { |
736 | 13.2k | return {.transport_type = TransportProtocolType::V1, .session_id = {}}; |
737 | 13.2k | } |
738 | | |
739 | | int V1Transport::readHeader(std::span<const uint8_t> msg_bytes) |
740 | 153k | { |
741 | 153k | AssertLockHeld(m_recv_mutex); |
742 | | // copy data to temporary parsing buffer |
743 | 153k | unsigned int nRemaining = CMessageHeader::HEADER_SIZE - nHdrPos; |
744 | 153k | unsigned int nCopy = std::min<unsigned int>(nRemaining, msg_bytes.size()); |
745 | | |
746 | 153k | memcpy(&hdrbuf[nHdrPos], msg_bytes.data(), nCopy); |
747 | 153k | nHdrPos += nCopy; |
748 | | |
749 | | // if header incomplete, exit |
750 | 153k | if (nHdrPos < CMessageHeader::HEADER_SIZE) |
751 | 7 | return nCopy; |
752 | | |
753 | | // deserialize to CMessageHeader |
754 | 153k | try { |
755 | 153k | hdrbuf >> hdr; |
756 | 153k | } |
757 | 153k | catch (const std::exception&) { |
758 | 0 | LogDebug(BCLog::NET, "Header error: Unable to deserialize, peer=%d\n", m_node_id); |
759 | 0 | return -1; |
760 | 0 | } |
761 | | |
762 | | // Check start string, network magic |
763 | 153k | if (hdr.pchMessageStart != m_magic_bytes) { |
764 | 2 | LogDebug(BCLog::NET, "Header error: Wrong MessageStart %s received, peer=%d\n", HexStr(hdr.pchMessageStart), m_node_id); |
765 | 2 | return -1; |
766 | 2 | } |
767 | | |
768 | | // reject messages larger than MAX_SIZE or MAX_PROTOCOL_MESSAGE_LENGTH |
769 | | // NOTE: failing to perform this check previously allowed a malicious peer to make us allocate 32MiB of memory per |
770 | | // connection. See https://bitcoincore.org/en/2024/07/03/disclose_receive_buffer_oom. |
771 | 153k | if (hdr.nMessageSize > MAX_SIZE || hdr.nMessageSize > MAX_PROTOCOL_MESSAGE_LENGTH) { |
772 | 3 | LogDebug(BCLog::NET, "Header error: Size too large (%s, %u bytes), peer=%d\n", SanitizeString(hdr.GetMessageType()), hdr.nMessageSize, m_node_id); |
773 | 3 | return -1; |
774 | 3 | } |
775 | | |
776 | | // switch state to reading message data |
777 | 153k | in_data = true; |
778 | | |
779 | 153k | return nCopy; |
780 | 153k | } |
781 | | |
782 | | int V1Transport::readData(std::span<const uint8_t> msg_bytes) |
783 | 171k | { |
784 | 171k | AssertLockHeld(m_recv_mutex); |
785 | 171k | unsigned int nRemaining = hdr.nMessageSize - nDataPos; |
786 | 171k | unsigned int nCopy = std::min<unsigned int>(nRemaining, msg_bytes.size()); |
787 | | |
788 | 171k | if (vRecv.size() < nDataPos + nCopy) { |
789 | | // Allocate up to 256 KiB ahead, but never more than the total message size. |
790 | 152k | vRecv.resize(std::min(hdr.nMessageSize, nDataPos + nCopy + 256 * 1024)); |
791 | 152k | } |
792 | | |
793 | 171k | hasher.Write(msg_bytes.first(nCopy)); |
794 | 171k | memcpy(&vRecv[nDataPos], msg_bytes.data(), nCopy); |
795 | 171k | nDataPos += nCopy; |
796 | | |
797 | 171k | return nCopy; |
798 | 171k | } |
799 | | |
800 | | const uint256& V1Transport::GetMessageHash() const |
801 | 153k | { |
802 | 153k | AssertLockHeld(m_recv_mutex); |
803 | 153k | assert(CompleteInternal()); |
804 | 153k | if (data_hash.IsNull()) |
805 | 153k | hasher.Finalize(data_hash); |
806 | 153k | return data_hash; |
807 | 153k | } |
808 | | |
809 | | CNetMessage V1Transport::GetReceivedMessage(NodeClock::time_point time, bool& reject_message) |
810 | 153k | { |
811 | 153k | AssertLockNotHeld(m_recv_mutex); |
812 | | // Initialize out parameter |
813 | 153k | reject_message = false; |
814 | | // decompose a single CNetMessage from the TransportDeserializer |
815 | 153k | LOCK(m_recv_mutex); |
816 | 153k | CNetMessage msg(std::move(vRecv)); |
817 | | |
818 | | // store message type string, time, and sizes |
819 | 153k | msg.m_type = hdr.GetMessageType(); |
820 | 153k | msg.m_time = time; |
821 | 153k | msg.m_message_size = hdr.nMessageSize; |
822 | 153k | msg.m_raw_message_size = hdr.nMessageSize + CMessageHeader::HEADER_SIZE; |
823 | | |
824 | 153k | uint256 hash = GetMessageHash(); |
825 | | |
826 | | // We just received a message off the wire, harvest entropy from the time (and the message checksum) |
827 | 153k | RandAddEvent(ReadLE32(hash.begin())); |
828 | | |
829 | | // Check checksum and header message type string |
830 | 153k | if (memcmp(hash.begin(), hdr.pchChecksum, CMessageHeader::CHECKSUM_SIZE) != 0) { |
831 | 1 | LogDebug(BCLog::NET, "Header error: Wrong checksum (%s, %u bytes), expected %s was %s, peer=%d\n", |
832 | 1 | SanitizeString(msg.m_type), msg.m_message_size, |
833 | 1 | HexStr(std::span{hash}.first(CMessageHeader::CHECKSUM_SIZE)), |
834 | 1 | HexStr(hdr.pchChecksum), |
835 | 1 | m_node_id); |
836 | 1 | reject_message = true; |
837 | 153k | } else if (!hdr.IsMessageTypeValid()) { |
838 | 81 | LogDebug(BCLog::NET, "Header error: Invalid message type (%s, %u bytes), peer=%d\n", |
839 | 81 | SanitizeString(hdr.GetMessageType()), msg.m_message_size, m_node_id); |
840 | 81 | reject_message = true; |
841 | 81 | } |
842 | | |
843 | | // Always reset the network deserializer (prepare for the next message) |
844 | 153k | Reset(); |
845 | 153k | return msg; |
846 | 153k | } |
847 | | |
848 | | bool V1Transport::SetMessageToSend(CSerializedNetMsg& msg) noexcept |
849 | 161k | { |
850 | 161k | AssertLockNotHeld(m_send_mutex); |
851 | | // Determine whether a new message can be set. |
852 | 161k | LOCK(m_send_mutex); |
853 | 161k | if (m_sending_header || m_bytes_sent < m_message_to_send.data.size()) return false; |
854 | | |
855 | | // create dbl-sha256 checksum |
856 | 161k | uint256 hash = Hash(msg.data); |
857 | | |
858 | | // create header |
859 | 161k | CMessageHeader hdr(m_magic_bytes, msg.m_type.c_str(), msg.data.size()); |
860 | 161k | memcpy(hdr.pchChecksum, hash.begin(), CMessageHeader::CHECKSUM_SIZE); |
861 | | |
862 | | // serialize header |
863 | 161k | m_header_to_send.clear(); |
864 | 161k | VectorWriter{m_header_to_send, 0, hdr}; |
865 | | |
866 | | // update state |
867 | 161k | m_message_to_send = std::move(msg); |
868 | 161k | m_sending_header = true; |
869 | 161k | m_bytes_sent = 0; |
870 | 161k | return true; |
871 | 161k | } |
872 | | |
873 | | Transport::BytesToSend V1Transport::GetBytesToSend(bool have_next_message) const noexcept |
874 | 1.12M | { |
875 | 1.12M | AssertLockNotHeld(m_send_mutex); |
876 | 1.12M | LOCK(m_send_mutex); |
877 | 1.12M | if (m_sending_header) { |
878 | 161k | return {std::span{m_header_to_send}.subspan(m_bytes_sent), |
879 | | // We have more to send after the header if the message has payload, or if there |
880 | | // is a next message after that. |
881 | 161k | have_next_message || !m_message_to_send.data.empty(), |
882 | 161k | m_message_to_send.m_type |
883 | 161k | }; |
884 | 959k | } else { |
885 | 959k | return {std::span{m_message_to_send.data}.subspan(m_bytes_sent), |
886 | | // We only have more to send after this message's payload if there is another |
887 | | // message. |
888 | 959k | have_next_message, |
889 | 959k | m_message_to_send.m_type |
890 | 959k | }; |
891 | 959k | } |
892 | 1.12M | } |
893 | | |
894 | | void V1Transport::MarkBytesSent(size_t bytes_sent) noexcept |
895 | 316k | { |
896 | 316k | AssertLockNotHeld(m_send_mutex); |
897 | 316k | LOCK(m_send_mutex); |
898 | 316k | m_bytes_sent += bytes_sent; |
899 | 316k | if (m_sending_header && m_bytes_sent == m_header_to_send.size()) { |
900 | | // We're done sending a message's header. Switch to sending its data bytes. |
901 | 161k | m_sending_header = false; |
902 | 161k | m_bytes_sent = 0; |
903 | 161k | } else if (!m_sending_header && m_bytes_sent == m_message_to_send.data.size()) { |
904 | | // We're done sending a message's data. Wipe the data vector to reduce memory consumption. |
905 | 155k | ClearShrink(m_message_to_send.data); |
906 | 155k | m_bytes_sent = 0; |
907 | 155k | } |
908 | 316k | } |
909 | | |
910 | | size_t V1Transport::GetSendMemoryUsage() const noexcept |
911 | 322k | { |
912 | 322k | AssertLockNotHeld(m_send_mutex); |
913 | 322k | LOCK(m_send_mutex); |
914 | | // Don't count sending-side fields besides m_message_to_send, as they're all small and bounded. |
915 | 322k | return m_message_to_send.GetMemoryUsage(); |
916 | 322k | } |
917 | | |
918 | | namespace { |
919 | | |
920 | | /** List of short messages as defined in BIP324, in order. |
921 | | * |
922 | | * Only message types that are actually implemented in this codebase need to be listed, as other |
923 | | * messages get ignored anyway - whether we know how to decode them or not. |
924 | | */ |
925 | | const std::array<std::string, BIP324_SHORTIDS_IMPLEMENTED> V2_MESSAGE_IDS = { |
926 | | "", // 12 bytes follow encoding the message type like in V1 |
927 | | NetMsgType::ADDR, |
928 | | NetMsgType::BLOCK, |
929 | | NetMsgType::BLOCKTXN, |
930 | | NetMsgType::CMPCTBLOCK, |
931 | | NetMsgType::FEEFILTER, |
932 | | NetMsgType::FILTERADD, |
933 | | NetMsgType::FILTERCLEAR, |
934 | | NetMsgType::FILTERLOAD, |
935 | | NetMsgType::GETBLOCKS, |
936 | | NetMsgType::GETBLOCKTXN, |
937 | | NetMsgType::GETDATA, |
938 | | NetMsgType::GETHEADERS, |
939 | | NetMsgType::HEADERS, |
940 | | NetMsgType::INV, |
941 | | NetMsgType::MEMPOOL, |
942 | | NetMsgType::MERKLEBLOCK, |
943 | | NetMsgType::NOTFOUND, |
944 | | NetMsgType::PING, |
945 | | NetMsgType::PONG, |
946 | | NetMsgType::SENDCMPCT, |
947 | | NetMsgType::TX, |
948 | | NetMsgType::GETCFILTERS, |
949 | | NetMsgType::CFILTER, |
950 | | NetMsgType::GETCFHEADERS, |
951 | | NetMsgType::CFHEADERS, |
952 | | NetMsgType::GETCFCHECKPT, |
953 | | NetMsgType::CFCHECKPT, |
954 | | NetMsgType::ADDRV2, |
955 | | "", "", "", // Unimplemented message types 29-31 |
956 | | "", "", "", "", // Unimplemented message types 32-35 |
957 | | "", // Unimplemented message type 36 |
958 | | NetMsgType::FEATURE, |
959 | | }; |
960 | | |
961 | | class V2MessageMap |
962 | | { |
963 | | std::unordered_map<std::string, uint8_t> m_map; |
964 | | |
965 | | public: |
966 | | V2MessageMap() noexcept |
967 | 1.35k | { |
968 | 51.5k | for (size_t i = 1; i < std::size(V2_MESSAGE_IDS); ++i) { |
969 | 50.1k | m_map.emplace(V2_MESSAGE_IDS[i], i); |
970 | 50.1k | } |
971 | 1.35k | } |
972 | | |
973 | | std::optional<uint8_t> operator()(const std::string& message_name) const noexcept |
974 | 8.64k | { |
975 | 8.64k | auto it = m_map.find(message_name); |
976 | 8.64k | if (it == m_map.end()) return std::nullopt; |
977 | 7.76k | return it->second; |
978 | 8.64k | } |
979 | | }; |
980 | | |
981 | | const V2MessageMap V2_MESSAGE_MAP; |
982 | | |
983 | | std::vector<uint8_t> GenerateRandomGarbage() noexcept |
984 | 283 | { |
985 | 283 | std::vector<uint8_t> ret; |
986 | 283 | FastRandomContext rng; |
987 | 283 | ret.resize(rng.randrange(V2Transport::MAX_GARBAGE_LEN + 1)); |
988 | 283 | rng.fillrand(MakeWritableByteSpan(ret)); |
989 | 283 | return ret; |
990 | 283 | } |
991 | | |
992 | | } // namespace |
993 | | |
994 | | void V2Transport::StartSendingHandshake() noexcept |
995 | 277 | { |
996 | 277 | AssertLockHeld(m_send_mutex); |
997 | 277 | Assume(m_send_state == SendState::AWAITING_KEY); |
998 | 277 | Assume(m_send_buffer.empty()); |
999 | | // Initialize the send buffer with ellswift pubkey + provided garbage. |
1000 | 277 | m_send_buffer.resize(EllSwiftPubKey::size() + m_send_garbage.size()); |
1001 | 277 | std::copy(std::begin(m_cipher.GetOurPubKey()), std::end(m_cipher.GetOurPubKey()), MakeWritableByteSpan(m_send_buffer).begin()); |
1002 | 277 | std::copy(m_send_garbage.begin(), m_send_garbage.end(), m_send_buffer.begin() + EllSwiftPubKey::size()); |
1003 | | // We cannot wipe m_send_garbage as it will still be used as AAD later in the handshake. |
1004 | 277 | } |
1005 | | |
1006 | | V2Transport::V2Transport(NodeId nodeid, bool initiating, const CKey& key, std::span<const std::byte> ent32, std::vector<uint8_t> garbage) noexcept |
1007 | 283 | : m_cipher{key, ent32}, |
1008 | 283 | m_initiating{initiating}, |
1009 | 283 | m_nodeid{nodeid}, |
1010 | 283 | m_v1_fallback{nodeid}, |
1011 | 283 | m_recv_state{initiating ? RecvState::KEY : RecvState::KEY_MAYBE_V1}, |
1012 | 283 | m_send_garbage{std::move(garbage)}, |
1013 | 283 | m_send_state{initiating ? SendState::AWAITING_KEY : SendState::MAYBE_V1} |
1014 | 283 | { |
1015 | 283 | Assume(m_send_garbage.size() <= MAX_GARBAGE_LEN); |
1016 | | // Start sending immediately if we're the initiator of the connection. |
1017 | 283 | if (initiating) { |
1018 | 133 | LOCK(m_send_mutex); |
1019 | 133 | StartSendingHandshake(); |
1020 | 133 | } |
1021 | 283 | } |
1022 | | |
1023 | | V2Transport::V2Transport(NodeId nodeid, bool initiating) noexcept |
1024 | 283 | : V2Transport{nodeid, initiating, GenerateRandomKey(), |
1025 | 283 | MakeByteSpan(GetRandHash()), GenerateRandomGarbage()} {} |
1026 | | |
1027 | | void V2Transport::SetReceiveState(RecvState recv_state) noexcept |
1028 | 17.0k | { |
1029 | 17.0k | AssertLockHeld(m_recv_mutex); |
1030 | | // Enforce allowed state transitions. |
1031 | 17.0k | switch (m_recv_state) { |
1032 | 150 | case RecvState::KEY_MAYBE_V1: |
1033 | 150 | Assume(recv_state == RecvState::KEY || recv_state == RecvState::V1); |
1034 | 150 | break; |
1035 | 263 | case RecvState::KEY: |
1036 | 263 | Assume(recv_state == RecvState::GARB_GARBTERM); |
1037 | 263 | break; |
1038 | 257 | case RecvState::GARB_GARBTERM: |
1039 | 257 | Assume(recv_state == RecvState::VERSION); |
1040 | 257 | break; |
1041 | 255 | case RecvState::VERSION: |
1042 | 255 | Assume(recv_state == RecvState::APP); |
1043 | 255 | break; |
1044 | 8.04k | case RecvState::APP: |
1045 | 8.04k | Assume(recv_state == RecvState::APP_READY); |
1046 | 8.04k | break; |
1047 | 8.04k | case RecvState::APP_READY: |
1048 | 8.04k | Assume(recv_state == RecvState::APP); |
1049 | 8.04k | break; |
1050 | 0 | case RecvState::V1: |
1051 | 0 | Assume(false); // V1 state cannot be left |
1052 | 0 | break; |
1053 | 17.0k | } |
1054 | | // Change state. |
1055 | 17.0k | m_recv_state = recv_state; |
1056 | 17.0k | } |
1057 | | |
1058 | | void V2Transport::SetSendState(SendState send_state) noexcept |
1059 | 413 | { |
1060 | 413 | AssertLockHeld(m_send_mutex); |
1061 | | // Enforce allowed state transitions. |
1062 | 413 | switch (m_send_state) { |
1063 | 150 | case SendState::MAYBE_V1: |
1064 | 150 | Assume(send_state == SendState::V1 || send_state == SendState::AWAITING_KEY); |
1065 | 150 | break; |
1066 | 263 | case SendState::AWAITING_KEY: |
1067 | 263 | Assume(send_state == SendState::READY); |
1068 | 263 | break; |
1069 | 0 | case SendState::READY: |
1070 | 0 | case SendState::V1: |
1071 | 0 | Assume(false); // Final states |
1072 | 0 | break; |
1073 | 413 | } |
1074 | | // Change state. |
1075 | 413 | m_send_state = send_state; |
1076 | 413 | } |
1077 | | |
1078 | | bool V2Transport::ReceivedMessageComplete() const noexcept |
1079 | 11.7k | { |
1080 | 11.7k | AssertLockNotHeld(m_recv_mutex); |
1081 | 11.7k | LOCK(m_recv_mutex); |
1082 | 11.7k | if (m_recv_state == RecvState::V1) return m_v1_fallback.ReceivedMessageComplete(); |
1083 | | |
1084 | 11.3k | return m_recv_state == RecvState::APP_READY; |
1085 | 11.7k | } |
1086 | | |
1087 | | void V2Transport::ProcessReceivedMaybeV1Bytes() noexcept |
1088 | 152 | { |
1089 | 152 | AssertLockHeld(m_recv_mutex); |
1090 | 152 | AssertLockNotHeld(m_send_mutex); |
1091 | 152 | Assume(m_recv_state == RecvState::KEY_MAYBE_V1); |
1092 | | // We still have to determine if this is a v1 or v2 connection. The bytes being received could |
1093 | | // be the beginning of either a v1 packet (network magic + "version\x00\x00\x00\x00\x00"), or |
1094 | | // of a v2 public key. BIP324 specifies that a mismatch with this 16-byte string should trigger |
1095 | | // sending of the key. |
1096 | 152 | std::array<uint8_t, V1_PREFIX_LEN> v1_prefix = {0, 0, 0, 0, 'v', 'e', 'r', 's', 'i', 'o', 'n', 0, 0, 0, 0, 0}; |
1097 | 152 | std::copy(std::begin(Params().MessageStart()), std::end(Params().MessageStart()), v1_prefix.begin()); |
1098 | 152 | Assume(m_recv_buffer.size() <= v1_prefix.size()); |
1099 | 152 | if (!std::equal(m_recv_buffer.begin(), m_recv_buffer.end(), v1_prefix.begin())) { |
1100 | | // Mismatch with v1 prefix, so we can assume a v2 connection. |
1101 | 144 | SetReceiveState(RecvState::KEY); // Convert to KEY state, leaving received bytes around. |
1102 | | // Transition the sender to AWAITING_KEY state and start sending. |
1103 | 144 | LOCK(m_send_mutex); |
1104 | 144 | SetSendState(SendState::AWAITING_KEY); |
1105 | 144 | StartSendingHandshake(); |
1106 | 144 | } else if (m_recv_buffer.size() == v1_prefix.size()) { |
1107 | | // Full match with the v1 prefix, so fall back to v1 behavior. |
1108 | 6 | LOCK(m_send_mutex); |
1109 | 6 | std::span<const uint8_t> feedback{m_recv_buffer}; |
1110 | | // Feed already received bytes to v1 transport. It should always accept these, because it's |
1111 | | // less than the size of a v1 header, and these are the first bytes fed to m_v1_fallback. |
1112 | 6 | bool ret = m_v1_fallback.ReceivedBytes(feedback); |
1113 | 6 | Assume(feedback.empty()); |
1114 | 6 | Assume(ret); |
1115 | 6 | SetReceiveState(RecvState::V1); |
1116 | 6 | SetSendState(SendState::V1); |
1117 | | // Reset v2 transport buffers to save memory. |
1118 | 6 | ClearShrink(m_recv_buffer); |
1119 | 6 | ClearShrink(m_send_buffer); |
1120 | 6 | } else { |
1121 | | // We have not received enough to distinguish v1 from v2 yet. Wait until more bytes come. |
1122 | 2 | } |
1123 | 152 | } |
1124 | | |
1125 | | bool V2Transport::ProcessReceivedKeyBytes() noexcept |
1126 | 342 | { |
1127 | 342 | AssertLockHeld(m_recv_mutex); |
1128 | 342 | AssertLockNotHeld(m_send_mutex); |
1129 | 342 | Assume(m_recv_state == RecvState::KEY); |
1130 | 342 | Assume(m_recv_buffer.size() <= EllSwiftPubKey::size()); |
1131 | | |
1132 | | // As a special exception, if bytes 4-16 of the key on a responder connection match the |
1133 | | // corresponding bytes of a V1 version message, but bytes 0-4 don't match the network magic |
1134 | | // (if they did, we'd have switched to V1 state already), assume this is a peer from |
1135 | | // another network, and disconnect them. They will almost certainly disconnect us too when |
1136 | | // they receive our uniformly random key and garbage, but detecting this case specially |
1137 | | // means we can log it. |
1138 | 342 | static constexpr std::array<uint8_t, 12> MATCH = {'v', 'e', 'r', 's', 'i', 'o', 'n', 0, 0, 0, 0, 0}; |
1139 | 342 | static constexpr size_t OFFSET = std::tuple_size_v<MessageStartChars>; |
1140 | 342 | if (!m_initiating && m_recv_buffer.size() >= OFFSET + MATCH.size()) { |
1141 | 189 | if (std::equal(MATCH.begin(), MATCH.end(), m_recv_buffer.begin() + OFFSET)) { |
1142 | 2 | LogDebug(BCLog::NET, "V2 transport error: V1 peer with wrong MessageStart %s\n", |
1143 | 2 | HexStr(std::span(m_recv_buffer).first(OFFSET))); |
1144 | 2 | return false; |
1145 | 2 | } |
1146 | 189 | } |
1147 | | |
1148 | 340 | if (m_recv_buffer.size() == EllSwiftPubKey::size()) { |
1149 | | // Other side's key has been fully received, and can now be Diffie-Hellman combined with |
1150 | | // our key to initialize the encryption ciphers. |
1151 | | |
1152 | | // Initialize the ciphers. |
1153 | 263 | EllSwiftPubKey ellswift(MakeByteSpan(m_recv_buffer)); |
1154 | 263 | LOCK(m_send_mutex); |
1155 | 263 | m_cipher.Initialize(ellswift, m_initiating); |
1156 | | |
1157 | | // Switch receiver state to GARB_GARBTERM. |
1158 | 263 | SetReceiveState(RecvState::GARB_GARBTERM); |
1159 | 263 | m_recv_buffer.clear(); |
1160 | | |
1161 | | // Switch sender state to READY. |
1162 | 263 | SetSendState(SendState::READY); |
1163 | | |
1164 | | // Append the garbage terminator to the send buffer. |
1165 | 263 | m_send_buffer.resize(m_send_buffer.size() + BIP324Cipher::GARBAGE_TERMINATOR_LEN); |
1166 | 263 | std::copy(m_cipher.GetSendGarbageTerminator().begin(), |
1167 | 263 | m_cipher.GetSendGarbageTerminator().end(), |
1168 | 263 | MakeWritableByteSpan(m_send_buffer).last(BIP324Cipher::GARBAGE_TERMINATOR_LEN).begin()); |
1169 | | |
1170 | | // Construct version packet in the send buffer, with the sent garbage data as AAD. |
1171 | 263 | m_send_buffer.resize(m_send_buffer.size() + BIP324Cipher::EXPANSION + VERSION_CONTENTS.size()); |
1172 | 263 | m_cipher.Encrypt( |
1173 | 263 | /*contents=*/VERSION_CONTENTS, |
1174 | 263 | /*aad=*/MakeByteSpan(m_send_garbage), |
1175 | 263 | /*ignore=*/false, |
1176 | 263 | /*output=*/MakeWritableByteSpan(m_send_buffer).last(BIP324Cipher::EXPANSION + VERSION_CONTENTS.size())); |
1177 | | // We no longer need the garbage. |
1178 | 263 | ClearShrink(m_send_garbage); |
1179 | 263 | } else { |
1180 | | // We still have to receive more key bytes. |
1181 | 77 | } |
1182 | 340 | return true; |
1183 | 342 | } |
1184 | | |
1185 | | bool V2Transport::ProcessReceivedGarbageBytes() noexcept |
1186 | 545k | { |
1187 | 545k | AssertLockHeld(m_recv_mutex); |
1188 | 545k | Assume(m_recv_state == RecvState::GARB_GARBTERM); |
1189 | 545k | Assume(m_recv_buffer.size() <= MAX_GARBAGE_LEN + BIP324Cipher::GARBAGE_TERMINATOR_LEN); |
1190 | 545k | if (m_recv_buffer.size() >= BIP324Cipher::GARBAGE_TERMINATOR_LEN) { |
1191 | 541k | if (std::ranges::equal(MakeByteSpan(m_recv_buffer).last(BIP324Cipher::GARBAGE_TERMINATOR_LEN), m_cipher.GetReceiveGarbageTerminator())) { |
1192 | | // Garbage terminator received. Store garbage to authenticate it as AAD later. |
1193 | 257 | m_recv_aad = std::move(m_recv_buffer); |
1194 | 257 | m_recv_aad.resize(m_recv_aad.size() - BIP324Cipher::GARBAGE_TERMINATOR_LEN); |
1195 | 257 | m_recv_buffer.clear(); |
1196 | 257 | SetReceiveState(RecvState::VERSION); |
1197 | 541k | } else if (m_recv_buffer.size() == MAX_GARBAGE_LEN + BIP324Cipher::GARBAGE_TERMINATOR_LEN) { |
1198 | | // We've reached the maximum length for garbage + garbage terminator, and the |
1199 | | // terminator still does not match. Abort. |
1200 | 4 | LogDebug(BCLog::NET, "V2 transport error: missing garbage terminator, peer=%d\n", m_nodeid); |
1201 | 4 | return false; |
1202 | 541k | } else { |
1203 | | // We still need to receive more garbage and/or garbage terminator bytes. |
1204 | 541k | } |
1205 | 541k | } else { |
1206 | | // We have less than GARBAGE_TERMINATOR_LEN (16) bytes, so we certainly need to receive |
1207 | | // more first. |
1208 | 3.94k | } |
1209 | 545k | return true; |
1210 | 545k | } |
1211 | | |
1212 | | bool V2Transport::ProcessReceivedPacketBytes() noexcept |
1213 | 110k | { |
1214 | 110k | AssertLockHeld(m_recv_mutex); |
1215 | 110k | Assume(m_recv_state == RecvState::VERSION || m_recv_state == RecvState::APP); |
1216 | | |
1217 | | // The maximum permitted contents length for a packet, consisting of: |
1218 | | // - 0x00 byte: indicating long message type encoding |
1219 | | // - 12 bytes of message type |
1220 | | // - payload |
1221 | 110k | static constexpr size_t MAX_CONTENTS_LEN = |
1222 | 110k | 1 + CMessageHeader::MESSAGE_TYPE_SIZE + |
1223 | 110k | std::min<size_t>(MAX_SIZE, MAX_PROTOCOL_MESSAGE_LENGTH); |
1224 | | |
1225 | 110k | if (m_recv_buffer.size() == BIP324Cipher::LENGTH_LEN) { |
1226 | | // Length descriptor received. |
1227 | 54.3k | m_recv_len = m_cipher.DecryptLength(MakeByteSpan(m_recv_buffer)); |
1228 | 54.3k | if (m_recv_len > MAX_CONTENTS_LEN) { |
1229 | 10 | LogDebug(BCLog::NET, "V2 transport error: packet too large (%u bytes), peer=%d\n", m_recv_len, m_nodeid); |
1230 | 10 | return false; |
1231 | 10 | } |
1232 | 55.8k | } else if (m_recv_buffer.size() > BIP324Cipher::LENGTH_LEN && m_recv_buffer.size() == m_recv_len + BIP324Cipher::EXPANSION) { |
1233 | | // Ciphertext received, decrypt it into m_recv_decode_buffer. |
1234 | | // Note that it is impossible to reach this branch without hitting the branch above first, |
1235 | | // as GetMaxBytesToProcess only allows up to LENGTH_LEN into the buffer before that point. |
1236 | 54.3k | m_recv_decode_buffer.resize(m_recv_len); |
1237 | 54.3k | bool ignore{false}; |
1238 | 54.3k | bool ret = m_cipher.Decrypt( |
1239 | 54.3k | /*input=*/MakeByteSpan(m_recv_buffer).subspan(BIP324Cipher::LENGTH_LEN), |
1240 | 54.3k | /*aad=*/MakeByteSpan(m_recv_aad), |
1241 | 54.3k | /*ignore=*/ignore, |
1242 | 54.3k | /*contents=*/MakeWritableByteSpan(m_recv_decode_buffer)); |
1243 | 54.3k | if (!ret) { |
1244 | 12 | LogDebug(BCLog::NET, "V2 transport error: packet decryption failure (%u bytes), peer=%d\n", m_recv_len, m_nodeid); |
1245 | 12 | return false; |
1246 | 12 | } |
1247 | | // We have decrypted a valid packet with the AAD we expected, so clear the expected AAD. |
1248 | 54.3k | ClearShrink(m_recv_aad); |
1249 | | // Feed the last 4 bytes of the Poly1305 authentication tag (and its timing) into our RNG. |
1250 | 54.3k | RandAddEvent(ReadLE32(m_recv_buffer.data() + m_recv_buffer.size() - 4)); |
1251 | | |
1252 | | // At this point we have a valid packet decrypted into m_recv_decode_buffer. If it's not a |
1253 | | // decoy, which we simply ignore, use the current state to decide what to do with it. |
1254 | 54.3k | if (!ignore) { |
1255 | 8.30k | switch (m_recv_state) { |
1256 | 255 | case RecvState::VERSION: |
1257 | | // Version message received; transition to application phase. The contents is |
1258 | | // ignored, but can be used for future extensions. |
1259 | 255 | SetReceiveState(RecvState::APP); |
1260 | 255 | break; |
1261 | 8.04k | case RecvState::APP: |
1262 | | // Application message decrypted correctly. It can be extracted using GetMessage(). |
1263 | 8.04k | SetReceiveState(RecvState::APP_READY); |
1264 | 8.04k | break; |
1265 | 0 | default: |
1266 | | // Any other state is invalid (this function should not have been called). |
1267 | 0 | Assume(false); |
1268 | 8.30k | } |
1269 | 8.30k | } |
1270 | | // Wipe the receive buffer where the next packet will be received into. |
1271 | 54.3k | ClearShrink(m_recv_buffer); |
1272 | | // In all but APP_READY state, we can wipe the decoded contents. |
1273 | 54.3k | if (m_recv_state != RecvState::APP_READY) ClearShrink(m_recv_decode_buffer); |
1274 | 54.3k | } else { |
1275 | | // We either have less than 3 bytes, so we don't know the packet's length yet, or more |
1276 | | // than 3 bytes but less than the packet's full ciphertext. Wait until those arrive. |
1277 | 1.51k | } |
1278 | 110k | return true; |
1279 | 110k | } |
1280 | | |
1281 | | size_t V2Transport::GetMaxBytesToProcess() noexcept |
1282 | 657k | { |
1283 | 657k | AssertLockHeld(m_recv_mutex); |
1284 | 657k | switch (m_recv_state) { |
1285 | 152 | case RecvState::KEY_MAYBE_V1: |
1286 | | // During the KEY_MAYBE_V1 state we do not allow more than the length of v1 prefix into the |
1287 | | // receive buffer. |
1288 | 152 | Assume(m_recv_buffer.size() <= V1_PREFIX_LEN); |
1289 | | // As long as we're not sure if this is a v1 or v2 connection, don't receive more than what |
1290 | | // is strictly necessary to distinguish the two (16 bytes). If we permitted more than |
1291 | | // the v1 header size (24 bytes), we may not be able to feed the already-received bytes |
1292 | | // back into the m_v1_fallback V1 transport. |
1293 | 152 | return V1_PREFIX_LEN - m_recv_buffer.size(); |
1294 | 342 | case RecvState::KEY: |
1295 | | // During the KEY state, we only allow the 64-byte key into the receive buffer. |
1296 | 342 | Assume(m_recv_buffer.size() <= EllSwiftPubKey::size()); |
1297 | | // As long as we have not received the other side's public key, don't receive more than |
1298 | | // that (64 bytes), as garbage follows, and locating the garbage terminator requires the |
1299 | | // key exchange first. |
1300 | 342 | return EllSwiftPubKey::size() - m_recv_buffer.size(); |
1301 | 545k | case RecvState::GARB_GARBTERM: |
1302 | | // Process garbage bytes one by one (because terminator may appear anywhere). |
1303 | 545k | return 1; |
1304 | 2.14k | case RecvState::VERSION: |
1305 | 110k | case RecvState::APP: |
1306 | | // These three states all involve decoding a packet. Process the length descriptor first, |
1307 | | // so that we know where the current packet ends (and we don't process bytes from the next |
1308 | | // packet or decoy yet). Then, process the ciphertext bytes of the current packet. |
1309 | 110k | if (m_recv_buffer.size() < BIP324Cipher::LENGTH_LEN) { |
1310 | 54.4k | return BIP324Cipher::LENGTH_LEN - m_recv_buffer.size(); |
1311 | 55.8k | } else { |
1312 | | // Note that BIP324Cipher::EXPANSION is the total difference between contents size |
1313 | | // and encoded packet size, which includes the 3 bytes due to the packet length. |
1314 | | // When transitioning from receiving the packet length to receiving its ciphertext, |
1315 | | // the encrypted packet length is left in the receive buffer. |
1316 | 55.8k | return BIP324Cipher::EXPANSION + m_recv_len - m_recv_buffer.size(); |
1317 | 55.8k | } |
1318 | 1.56k | case RecvState::APP_READY: |
1319 | | // No bytes can be processed until GetMessage() is called. |
1320 | 1.56k | return 0; |
1321 | 0 | case RecvState::V1: |
1322 | | // Not allowed (must be dealt with by the caller). |
1323 | 0 | Assume(false); |
1324 | 0 | return 0; |
1325 | 657k | } |
1326 | 0 | Assume(false); // unreachable |
1327 | 0 | return 0; |
1328 | 657k | } |
1329 | | |
1330 | | bool V2Transport::ReceivedBytes(std::span<const uint8_t>& msg_bytes) noexcept |
1331 | 11.0k | { |
1332 | 11.0k | AssertLockNotHeld(m_recv_mutex); |
1333 | | /** How many bytes to allocate in the receive buffer at most above what is received so far. */ |
1334 | 11.0k | static constexpr size_t MAX_RESERVE_AHEAD = 256 * 1024; |
1335 | | |
1336 | 11.0k | LOCK(m_recv_mutex); |
1337 | 11.0k | if (m_recv_state == RecvState::V1) return m_v1_fallback.ReceivedBytes(msg_bytes); |
1338 | | |
1339 | | // Process the provided bytes in msg_bytes in a loop. In each iteration a nonzero number of |
1340 | | // bytes (decided by GetMaxBytesToProcess) are taken from the beginning om msg_bytes, and |
1341 | | // appended to m_recv_buffer. Then, depending on the receiver state, one of the |
1342 | | // ProcessReceived*Bytes functions is called to process the bytes in that buffer. |
1343 | 666k | while (!msg_bytes.empty()) { |
1344 | | // Decide how many bytes to copy from msg_bytes to m_recv_buffer. |
1345 | 657k | size_t max_read = GetMaxBytesToProcess(); |
1346 | | |
1347 | | // Reserve space in the buffer if there is not enough. |
1348 | 657k | if (m_recv_buffer.size() + std::min(msg_bytes.size(), max_read) > m_recv_buffer.capacity()) { |
1349 | 109k | switch (m_recv_state) { |
1350 | 150 | case RecvState::KEY_MAYBE_V1: |
1351 | 271 | case RecvState::KEY: |
1352 | 271 | case RecvState::GARB_GARBTERM: |
1353 | | // During the initial states (key/garbage), allocate once to fit the maximum (4111 |
1354 | | // bytes). |
1355 | 271 | m_recv_buffer.reserve(MAX_GARBAGE_LEN + BIP324Cipher::GARBAGE_TERMINATOR_LEN); |
1356 | 271 | break; |
1357 | 1.75k | case RecvState::VERSION: |
1358 | 108k | case RecvState::APP: { |
1359 | | // During states where a packet is being received, as much as is expected but never |
1360 | | // more than MAX_RESERVE_AHEAD bytes in addition to what is received so far. |
1361 | | // This means attackers that want to cause us to waste allocated memory are limited |
1362 | | // to MAX_RESERVE_AHEAD above the largest allowed message contents size, and to |
1363 | | // MAX_RESERVE_AHEAD more than they've actually sent us. |
1364 | 108k | size_t alloc_add = std::min(max_read, msg_bytes.size() + MAX_RESERVE_AHEAD); |
1365 | 108k | m_recv_buffer.reserve(m_recv_buffer.size() + alloc_add); |
1366 | 108k | break; |
1367 | 1.75k | } |
1368 | 0 | case RecvState::APP_READY: |
1369 | | // The buffer is empty in this state. |
1370 | 0 | Assume(m_recv_buffer.empty()); |
1371 | 0 | break; |
1372 | 0 | case RecvState::V1: |
1373 | | // Should have bailed out above. |
1374 | 0 | Assume(false); |
1375 | 0 | break; |
1376 | 109k | } |
1377 | 109k | } |
1378 | | |
1379 | | // Can't read more than provided input. |
1380 | 657k | max_read = std::min(msg_bytes.size(), max_read); |
1381 | | // Copy data to buffer. |
1382 | 657k | m_recv_buffer.insert(m_recv_buffer.end(), UCharCast(msg_bytes.data()), UCharCast(msg_bytes.data() + max_read)); |
1383 | 657k | msg_bytes = msg_bytes.subspan(max_read); |
1384 | | |
1385 | | // Process data in the buffer. |
1386 | 657k | switch (m_recv_state) { |
1387 | 152 | case RecvState::KEY_MAYBE_V1: |
1388 | 152 | ProcessReceivedMaybeV1Bytes(); |
1389 | 152 | if (m_recv_state == RecvState::V1) return true; |
1390 | 146 | break; |
1391 | | |
1392 | 342 | case RecvState::KEY: |
1393 | 342 | if (!ProcessReceivedKeyBytes()) return false; |
1394 | 340 | break; |
1395 | | |
1396 | 545k | case RecvState::GARB_GARBTERM: |
1397 | 545k | if (!ProcessReceivedGarbageBytes()) return false; |
1398 | 545k | break; |
1399 | | |
1400 | 545k | case RecvState::VERSION: |
1401 | 110k | case RecvState::APP: |
1402 | 110k | if (!ProcessReceivedPacketBytes()) return false; |
1403 | 110k | break; |
1404 | | |
1405 | 110k | case RecvState::APP_READY: |
1406 | 1.56k | return true; |
1407 | | |
1408 | 0 | case RecvState::V1: |
1409 | | // We should have bailed out before. |
1410 | 0 | Assume(false); |
1411 | 0 | break; |
1412 | 657k | } |
1413 | | // Make sure we have made progress before continuing. |
1414 | 656k | Assume(max_read > 0); |
1415 | 656k | } |
1416 | | |
1417 | 9.07k | return true; |
1418 | 10.6k | } |
1419 | | |
1420 | | std::optional<std::string> V2Transport::GetMessageType(std::span<const uint8_t>& contents) noexcept |
1421 | 8.04k | { |
1422 | 8.04k | if (contents.size() == 0) return std::nullopt; // Empty contents |
1423 | 8.04k | uint8_t first_byte = contents[0]; |
1424 | 8.04k | contents = contents.subspan(1); // Strip first byte. |
1425 | | |
1426 | 8.04k | if (first_byte != 0) { |
1427 | | // Short (1 byte) encoding. |
1428 | 7.14k | if (first_byte < std::size(V2_MESSAGE_IDS)) { |
1429 | | // Valid short message id. |
1430 | 7.14k | return V2_MESSAGE_IDS[first_byte]; |
1431 | 7.14k | } else { |
1432 | | // Unknown short message id. |
1433 | 1 | return std::nullopt; |
1434 | 1 | } |
1435 | 7.14k | } |
1436 | | |
1437 | 903 | if (contents.size() < CMessageHeader::MESSAGE_TYPE_SIZE) { |
1438 | 10 | return std::nullopt; // Long encoding needs 12 message type bytes. |
1439 | 10 | } |
1440 | | |
1441 | 893 | size_t msg_type_len{0}; |
1442 | 8.08k | while (msg_type_len < CMessageHeader::MESSAGE_TYPE_SIZE && contents[msg_type_len] != 0) { |
1443 | | // Verify that message type bytes before the first 0x00 are in range. |
1444 | 7.19k | if (contents[msg_type_len] < ' ' || contents[msg_type_len] > 0x7F) { |
1445 | 0 | return {}; |
1446 | 0 | } |
1447 | 7.19k | ++msg_type_len; |
1448 | 7.19k | } |
1449 | 893 | std::string ret{reinterpret_cast<const char*>(contents.data()), msg_type_len}; |
1450 | 4.31k | while (msg_type_len < CMessageHeader::MESSAGE_TYPE_SIZE) { |
1451 | | // Verify that message type bytes after the first 0x00 are also 0x00. |
1452 | 3.47k | if (contents[msg_type_len] != 0) return {}; |
1453 | 3.42k | ++msg_type_len; |
1454 | 3.42k | } |
1455 | | // Strip message type bytes of contents. |
1456 | 843 | contents = contents.subspan(CMessageHeader::MESSAGE_TYPE_SIZE); |
1457 | 843 | return ret; |
1458 | 893 | } |
1459 | | |
1460 | | CNetMessage V2Transport::GetReceivedMessage(NodeClock::time_point time, bool& reject_message) noexcept |
1461 | 8.27k | { |
1462 | 8.27k | AssertLockNotHeld(m_recv_mutex); |
1463 | 8.27k | LOCK(m_recv_mutex); |
1464 | 8.27k | if (m_recv_state == RecvState::V1) return m_v1_fallback.GetReceivedMessage(time, reject_message); |
1465 | | |
1466 | 8.04k | Assume(m_recv_state == RecvState::APP_READY); |
1467 | 8.04k | std::span<const uint8_t> contents{m_recv_decode_buffer}; |
1468 | 8.04k | auto msg_type = GetMessageType(contents); |
1469 | 8.04k | CNetMessage msg{DataStream{}}; |
1470 | | // Note that BIP324Cipher::EXPANSION also includes the length descriptor size. |
1471 | 8.04k | msg.m_raw_message_size = m_recv_decode_buffer.size() + BIP324Cipher::EXPANSION; |
1472 | 8.04k | if (msg_type) { |
1473 | 7.98k | reject_message = false; |
1474 | 7.98k | msg.m_type = std::move(*msg_type); |
1475 | 7.98k | msg.m_time = time; |
1476 | 7.98k | msg.m_message_size = contents.size(); |
1477 | 7.98k | msg.m_recv.resize(contents.size()); |
1478 | 7.98k | std::copy(contents.begin(), contents.end(), UCharCast(msg.m_recv.data())); |
1479 | 7.98k | } else { |
1480 | 61 | LogDebug(BCLog::NET, "V2 transport error: invalid message type (%u bytes contents), peer=%d\n", m_recv_decode_buffer.size(), m_nodeid); |
1481 | 61 | reject_message = true; |
1482 | 61 | } |
1483 | 8.04k | ClearShrink(m_recv_decode_buffer); |
1484 | 8.04k | SetReceiveState(RecvState::APP); |
1485 | | |
1486 | 8.04k | return msg; |
1487 | 8.27k | } |
1488 | | |
1489 | | bool V2Transport::SetMessageToSend(CSerializedNetMsg& msg) noexcept |
1490 | 9.10k | { |
1491 | 9.10k | AssertLockNotHeld(m_send_mutex); |
1492 | 9.10k | LOCK(m_send_mutex); |
1493 | 9.10k | if (m_send_state == SendState::V1) return m_v1_fallback.SetMessageToSend(msg); |
1494 | | // We only allow adding a new message to be sent when in the READY state (so the packet cipher |
1495 | | // is available) and the send buffer is empty. This limits the number of messages in the send |
1496 | | // buffer to just one, and leaves the responsibility for queueing them up to the caller. |
1497 | 8.72k | if (!(m_send_state == SendState::READY && m_send_buffer.empty())) return false; |
1498 | | // Construct contents (encoding message type + payload). |
1499 | 8.64k | std::vector<uint8_t> contents; |
1500 | 8.64k | auto short_message_id = V2_MESSAGE_MAP(msg.m_type); |
1501 | 8.64k | if (short_message_id) { |
1502 | 7.76k | contents.resize(1 + msg.data.size()); |
1503 | 7.76k | contents[0] = *short_message_id; |
1504 | 7.76k | std::copy(msg.data.begin(), msg.data.end(), contents.begin() + 1); |
1505 | 7.76k | } else { |
1506 | | // Initialize with zeroes, and then write the message type string starting at offset 1. |
1507 | | // This means contents[0] and the unused positions in contents[1..13] remain 0x00. |
1508 | 883 | contents.resize(1 + CMessageHeader::MESSAGE_TYPE_SIZE + msg.data.size(), 0); |
1509 | 883 | std::copy(msg.m_type.begin(), msg.m_type.end(), contents.data() + 1); |
1510 | 883 | std::copy(msg.data.begin(), msg.data.end(), contents.begin() + 1 + CMessageHeader::MESSAGE_TYPE_SIZE); |
1511 | 883 | } |
1512 | | // Construct ciphertext in send buffer. |
1513 | 8.64k | m_send_buffer.resize(contents.size() + BIP324Cipher::EXPANSION); |
1514 | 8.64k | m_cipher.Encrypt(MakeByteSpan(contents), {}, false, MakeWritableByteSpan(m_send_buffer)); |
1515 | 8.64k | m_send_type = msg.m_type; |
1516 | | // Release memory |
1517 | 8.64k | ClearShrink(msg.data); |
1518 | 8.64k | return true; |
1519 | 8.72k | } |
1520 | | |
1521 | | Transport::BytesToSend V2Transport::GetBytesToSend(bool have_next_message) const noexcept |
1522 | 65.4k | { |
1523 | 65.4k | AssertLockNotHeld(m_send_mutex); |
1524 | 65.4k | LOCK(m_send_mutex); |
1525 | 65.4k | if (m_send_state == SendState::V1) return m_v1_fallback.GetBytesToSend(have_next_message); |
1526 | | |
1527 | 62.3k | if (m_send_state == SendState::MAYBE_V1) Assume(m_send_buffer.empty()); |
1528 | 62.3k | Assume(m_send_pos <= m_send_buffer.size()); |
1529 | 62.3k | return { |
1530 | 62.3k | std::span{m_send_buffer}.subspan(m_send_pos), |
1531 | | // We only have more to send after the current m_send_buffer if there is a (next) |
1532 | | // message to be sent, and we're capable of sending packets. */ |
1533 | 62.3k | have_next_message && m_send_state == SendState::READY, |
1534 | 62.3k | m_send_type |
1535 | 62.3k | }; |
1536 | 65.4k | } |
1537 | | |
1538 | | void V2Transport::MarkBytesSent(size_t bytes_sent) noexcept |
1539 | 10.5k | { |
1540 | 10.5k | AssertLockNotHeld(m_send_mutex); |
1541 | 10.5k | LOCK(m_send_mutex); |
1542 | 10.5k | if (m_send_state == SendState::V1) return m_v1_fallback.MarkBytesSent(bytes_sent); |
1543 | | |
1544 | 9.78k | if (m_send_state == SendState::AWAITING_KEY && m_send_pos == 0 && bytes_sent > 0) { |
1545 | 136 | LogDebug(BCLog::NET, "start sending v2 handshake to peer=%d\n", m_nodeid); |
1546 | 136 | } |
1547 | | |
1548 | 9.78k | m_send_pos += bytes_sent; |
1549 | 9.78k | Assume(m_send_pos <= m_send_buffer.size()); |
1550 | 9.78k | if (m_send_pos >= CMessageHeader::HEADER_SIZE) { |
1551 | 9.65k | m_sent_v1_header_worth = true; |
1552 | 9.65k | } |
1553 | | // Wipe the buffer when everything is sent. |
1554 | 9.78k | if (m_send_pos == m_send_buffer.size()) { |
1555 | 9.03k | m_send_pos = 0; |
1556 | 9.03k | ClearShrink(m_send_buffer); |
1557 | 9.03k | } |
1558 | 9.78k | } |
1559 | | |
1560 | | bool V2Transport::ShouldReconnectV1() const noexcept |
1561 | 151 | { |
1562 | 151 | AssertLockNotHeld(m_send_mutex); |
1563 | 151 | AssertLockNotHeld(m_recv_mutex); |
1564 | | // Only outgoing connections need reconnection. |
1565 | 151 | if (!m_initiating) return false; |
1566 | | |
1567 | 74 | LOCK(m_recv_mutex); |
1568 | | // We only reconnect in the very first state and when the receive buffer is empty. Together |
1569 | | // these conditions imply nothing has been received so far. |
1570 | 74 | if (m_recv_state != RecvState::KEY) return false; |
1571 | 11 | if (!m_recv_buffer.empty()) return false; |
1572 | | // Check if we've sent enough for the other side to disconnect us (if it was V1). |
1573 | 11 | LOCK(m_send_mutex); |
1574 | 11 | return m_sent_v1_header_worth; |
1575 | 11 | } |
1576 | | |
1577 | | size_t V2Transport::GetSendMemoryUsage() const noexcept |
1578 | 18.2k | { |
1579 | 18.2k | AssertLockNotHeld(m_send_mutex); |
1580 | 18.2k | LOCK(m_send_mutex); |
1581 | 18.2k | if (m_send_state == SendState::V1) return m_v1_fallback.GetSendMemoryUsage(); |
1582 | | |
1583 | 17.4k | return sizeof(m_send_buffer) + memusage::DynamicUsage(m_send_buffer); |
1584 | 18.2k | } |
1585 | | |
1586 | | Transport::Info V2Transport::GetInfo() const noexcept |
1587 | 2.67k | { |
1588 | 2.67k | AssertLockNotHeld(m_recv_mutex); |
1589 | 2.67k | LOCK(m_recv_mutex); |
1590 | 2.67k | if (m_recv_state == RecvState::V1) return m_v1_fallback.GetInfo(); |
1591 | | |
1592 | 2.63k | Transport::Info info; |
1593 | | |
1594 | | // Do not report v2 and session ID until the version packet has been received |
1595 | | // and verified (confirming that the other side very likely has the same keys as us). |
1596 | 2.63k | if (m_recv_state != RecvState::KEY_MAYBE_V1 && m_recv_state != RecvState::KEY && |
1597 | 2.63k | m_recv_state != RecvState::GARB_GARBTERM && m_recv_state != RecvState::VERSION) { |
1598 | 2.55k | info.transport_type = TransportProtocolType::V2; |
1599 | 2.55k | info.session_id = uint256(MakeUCharSpan(m_cipher.GetSessionID())); |
1600 | 2.55k | } else { |
1601 | 74 | info.transport_type = TransportProtocolType::DETECTING; |
1602 | 74 | } |
1603 | | |
1604 | 2.63k | return info; |
1605 | 2.67k | } |
1606 | | |
1607 | | std::pair<size_t, bool> CConnman::SocketSendData(CNode& node) const |
1608 | 169k | { |
1609 | 169k | auto it = node.vSendMsg.begin(); |
1610 | 169k | size_t nSentSize = 0; |
1611 | 169k | bool data_left{false}; //!< second return value (whether unsent data remains) |
1612 | 169k | std::optional<bool> expected_more; |
1613 | | |
1614 | 495k | while (true) { |
1615 | 495k | if (it != node.vSendMsg.end()) { |
1616 | | // If possible, move one message from the send queue to the transport. This fails when |
1617 | | // there is an existing message still being sent, or (for v2 transports) when the |
1618 | | // handshake has not yet completed. |
1619 | 169k | size_t memusage = it->GetMemoryUsage(); |
1620 | 169k | if (node.m_transport->SetMessageToSend(*it)) { |
1621 | | // Update memory usage of send buffer (as *it will be deleted). |
1622 | 169k | node.m_send_memusage -= memusage; |
1623 | 169k | ++it; |
1624 | 169k | } |
1625 | 169k | } |
1626 | 495k | const auto& [data, more, msg_type] = node.m_transport->GetBytesToSend(it != node.vSendMsg.end()); |
1627 | | // We rely on the 'more' value returned by GetBytesToSend to correctly predict whether more |
1628 | | // bytes are still to be sent, to correctly set the MSG_MORE flag. As a sanity check, |
1629 | | // verify that the previously returned 'more' was correct. |
1630 | 495k | if (expected_more.has_value()) Assume(!data.empty() == *expected_more); |
1631 | 495k | expected_more = more; |
1632 | 495k | data_left = !data.empty(); // will be overwritten on next loop if all of data gets sent |
1633 | 495k | int nBytes = 0; |
1634 | 495k | if (!data.empty()) { |
1635 | 325k | LOCK(node.m_sock_mutex); |
1636 | | // There is no socket in case we've already disconnected, or in test cases without |
1637 | | // real connections. In these cases, we bail out immediately and just leave things |
1638 | | // in the send queue and transport. |
1639 | 325k | if (!node.m_sock) { |
1640 | 12 | break; |
1641 | 12 | } |
1642 | 325k | int flags = MSG_NOSIGNAL | MSG_DONTWAIT; |
1643 | 325k | #ifdef MSG_MORE |
1644 | 325k | if (more) { |
1645 | 155k | flags |= MSG_MORE; |
1646 | 155k | } |
1647 | 325k | #endif |
1648 | 325k | nBytes = node.m_sock->Send(data.data(), data.size(), flags); |
1649 | 325k | } |
1650 | 495k | if (nBytes > 0) { |
1651 | 325k | node.m_last_send = NodeClock::now(); |
1652 | 325k | node.nSendBytes += nBytes; |
1653 | | // Notify transport that bytes have been processed. |
1654 | 325k | node.m_transport->MarkBytesSent(nBytes); |
1655 | | // Update statistics per message type. |
1656 | 325k | if (!msg_type.empty()) { // don't report v2 handshake bytes for now |
1657 | 325k | node.AccountForSentBytes(msg_type, nBytes); |
1658 | 325k | } |
1659 | 325k | nSentSize += nBytes; |
1660 | 325k | if ((size_t)nBytes != data.size()) { |
1661 | | // could not send full message; stop sending more |
1662 | 7 | break; |
1663 | 7 | } |
1664 | 325k | } else { |
1665 | 169k | if (nBytes < 0) { |
1666 | | // error |
1667 | 2 | int nErr = WSAGetLastError(); |
1668 | 2 | if (nErr != WSAEWOULDBLOCK && nErr != WSAEMSGSIZE && nErr != WSAEINTR && nErr != WSAEINPROGRESS) { |
1669 | 2 | LogDebug(BCLog::NET, "socket send error, %s: %s", node.DisconnectMsg(), NetworkErrorString(nErr)); |
1670 | 2 | node.CloseSocketDisconnect(); |
1671 | 2 | } |
1672 | 2 | } |
1673 | 169k | break; |
1674 | 169k | } |
1675 | 495k | } |
1676 | | |
1677 | 169k | node.fPauseSend = node.m_send_memusage + node.m_transport->GetSendMemoryUsage() > nSendBufferMaxSize; |
1678 | | |
1679 | 169k | if (it == node.vSendMsg.end()) { |
1680 | 169k | assert(node.m_send_memusage == 0); |
1681 | 169k | } |
1682 | 169k | node.vSendMsg.erase(node.vSendMsg.begin(), it); |
1683 | 169k | return {nSentSize, data_left}; |
1684 | 169k | } |
1685 | | |
1686 | | /** Try to find a connection to evict when the node is full. |
1687 | | * Extreme care must be taken to avoid opening the node to attacker |
1688 | | * triggered network partitioning. |
1689 | | * The strategy used here is to protect a small number of peers |
1690 | | * for each of several distinct characteristics which are difficult |
1691 | | * to forge. In order to partition a node the attacker must be |
1692 | | * simultaneously better at all of them than honest peers. |
1693 | | */ |
1694 | | bool CConnman::AttemptToEvictConnection() |
1695 | 1 | { |
1696 | 1 | AssertLockNotHeld(m_nodes_mutex); |
1697 | | |
1698 | 1 | std::vector<NodeEvictionCandidate> vEvictionCandidates; |
1699 | 1 | { |
1700 | | |
1701 | 1 | LOCK(m_nodes_mutex); |
1702 | 21 | for (const CNode* node : m_nodes) { |
1703 | 21 | if (node->fDisconnect) |
1704 | 0 | continue; |
1705 | 21 | NodeEvictionCandidate candidate{ |
1706 | 21 | .id = node->GetId(), |
1707 | 21 | .m_connected = node->m_connected, |
1708 | 21 | .m_min_ping_time = node->m_min_ping_time, |
1709 | 21 | .m_last_block_time = node->m_last_block_time, |
1710 | 21 | .m_last_tx_time = node->m_last_tx_time, |
1711 | 21 | .fRelevantServices = node->m_has_all_wanted_services, |
1712 | 21 | .m_relay_txs = node->m_relays_txs.load(), |
1713 | 21 | .fBloomFilter = node->m_bloom_filter_loaded.load(), |
1714 | 21 | .nKeyedNetGroup = node->nKeyedNetGroup, |
1715 | 21 | .prefer_evict = node->m_prefer_evict, |
1716 | 21 | .m_is_local = node->addr.IsLocal(), |
1717 | 21 | .m_network = node->ConnectedThroughNetwork(), |
1718 | 21 | .m_noban = node->HasPermission(NetPermissionFlags::NoBan), |
1719 | 21 | .m_conn_type = node->m_conn_type, |
1720 | 21 | }; |
1721 | 21 | vEvictionCandidates.push_back(candidate); |
1722 | 21 | } |
1723 | 1 | } |
1724 | 1 | const std::optional<NodeId> node_id_to_evict = SelectNodeToEvict(std::move(vEvictionCandidates)); |
1725 | 1 | if (!node_id_to_evict) { |
1726 | 0 | return false; |
1727 | 0 | } |
1728 | 1 | LOCK(m_nodes_mutex); |
1729 | 9 | for (CNode* pnode : m_nodes) { |
1730 | 9 | if (pnode->GetId() == *node_id_to_evict) { |
1731 | 1 | LogDebug(BCLog::NET, "selected %s connection for eviction, %s", pnode->ConnectionTypeAsString(), pnode->DisconnectMsg()); |
1732 | 1 | TRACEPOINT(net, evicted_inbound_connection, |
1733 | 1 | pnode->GetId(), |
1734 | 1 | pnode->m_addr_name.c_str(), |
1735 | 1 | pnode->ConnectionTypeAsString().c_str(), |
1736 | 1 | pnode->ConnectedThroughNetwork(), |
1737 | 1 | TicksSinceEpoch<std::chrono::seconds>(pnode->m_connected)); |
1738 | 1 | pnode->fDisconnect = true; |
1739 | 1 | return true; |
1740 | 1 | } |
1741 | 9 | } |
1742 | 0 | return false; |
1743 | 1 | } |
1744 | | |
1745 | 1.04k | void CConnman::AcceptConnection(const ListenSocket& hListenSocket) { |
1746 | 1.04k | AssertLockNotHeld(m_nodes_mutex); |
1747 | | |
1748 | 1.04k | struct sockaddr_storage sockaddr; |
1749 | 1.04k | socklen_t len = sizeof(sockaddr); |
1750 | 1.04k | auto sock = hListenSocket.sock->Accept((struct sockaddr*)&sockaddr, &len); |
1751 | | |
1752 | 1.04k | if (!sock) { |
1753 | 0 | const int nErr = WSAGetLastError(); |
1754 | 0 | if (nErr != WSAEWOULDBLOCK) { |
1755 | 0 | LogInfo("socket error accept failed: %s\n", NetworkErrorString(nErr)); |
1756 | 0 | } |
1757 | 0 | return; |
1758 | 0 | } |
1759 | | |
1760 | 1.04k | CService addr; |
1761 | 1.04k | if (!addr.SetSockAddr((const struct sockaddr*)&sockaddr, len)) { |
1762 | 0 | LogWarning("Unknown socket family\n"); |
1763 | 1.04k | } else { |
1764 | 1.04k | addr = MaybeFlipIPv6toCJDNS(addr); |
1765 | 1.04k | } |
1766 | | |
1767 | 1.04k | const CService addr_bind{MaybeFlipIPv6toCJDNS(GetBindAddress(*sock))}; |
1768 | | |
1769 | 1.04k | NetPermissionFlags permission_flags = NetPermissionFlags::None; |
1770 | 1.04k | hListenSocket.AddSocketPermissionFlags(permission_flags); |
1771 | | |
1772 | 1.04k | CreateNodeFromAcceptedSocket(std::move(sock), permission_flags, addr_bind, addr); |
1773 | 1.04k | } |
1774 | | |
1775 | | void CConnman::CreateNodeFromAcceptedSocket(std::unique_ptr<Sock>&& sock, |
1776 | | NetPermissionFlags permission_flags, |
1777 | | const CService& addr_bind, |
1778 | | const CService& addr) |
1779 | 1.04k | { |
1780 | 1.04k | AssertLockNotHeld(m_nodes_mutex); |
1781 | | |
1782 | 1.04k | int nInbound = 0; |
1783 | | |
1784 | 1.04k | const bool inbound_onion = std::find(m_onion_binds.begin(), m_onion_binds.end(), addr_bind) != m_onion_binds.end(); |
1785 | | |
1786 | | // Tor inbound connections do not reveal the peer's actual network address. |
1787 | | // Therefore do not apply address-based whitelist permissions to them. |
1788 | 1.04k | AddWhitelistPermissionFlags(permission_flags, inbound_onion ? std::optional<CNetAddr>{} : addr, vWhitelistedRangeIncoming); |
1789 | | |
1790 | 1.04k | { |
1791 | 1.04k | LOCK(m_nodes_mutex); |
1792 | 3.89k | for (const CNode* pnode : m_nodes) { |
1793 | 3.89k | if (pnode->IsInboundConn()) nInbound++; |
1794 | 3.89k | } |
1795 | 1.04k | } |
1796 | | |
1797 | 1.04k | if (!fNetworkActive) { |
1798 | 0 | LogDebug(BCLog::NET, "connection from %s dropped: not accepting new connections\n", addr.ToStringAddrPort()); |
1799 | 0 | return; |
1800 | 0 | } |
1801 | | |
1802 | 1.04k | if (!sock->IsSelectable()) { |
1803 | 0 | LogInfo("connection from %s dropped: non-selectable socket\n", addr.ToStringAddrPort()); |
1804 | 0 | return; |
1805 | 0 | } |
1806 | | |
1807 | | // According to the internet TCP_NODELAY is not carried into accepted sockets |
1808 | | // on all platforms. Set it again here just to be sure. |
1809 | 1.04k | const int on{1}; |
1810 | 1.04k | if (sock->SetSockOpt(IPPROTO_TCP, TCP_NODELAY, &on, sizeof(on)) == SOCKET_ERROR) { |
1811 | 0 | LogDebug(BCLog::NET, "connection from %s: unable to set TCP_NODELAY, continuing anyway\n", |
1812 | 0 | addr.ToStringAddrPort()); |
1813 | 0 | } |
1814 | | |
1815 | | // Don't accept connections from banned peers. |
1816 | 1.04k | bool banned = m_banman && m_banman->IsBanned(addr); |
1817 | 1.04k | if (!NetPermissions::HasFlag(permission_flags, NetPermissionFlags::NoBan) && banned) |
1818 | 3 | { |
1819 | 3 | LogDebug(BCLog::NET, "connection from %s dropped (banned)\n", addr.ToStringAddrPort()); |
1820 | 3 | return; |
1821 | 3 | } |
1822 | | |
1823 | | // Only accept connections from discouraged peers if our inbound slots aren't (almost) full. |
1824 | 1.04k | bool discouraged = m_banman && m_banman->IsDiscouraged(addr); |
1825 | 1.04k | if (!NetPermissions::HasFlag(permission_flags, NetPermissionFlags::NoBan) && nInbound + 1 >= m_max_inbound && discouraged) |
1826 | 0 | { |
1827 | 0 | LogDebug(BCLog::NET, "connection from %s dropped (discouraged)\n", addr.ToStringAddrPort()); |
1828 | 0 | return; |
1829 | 0 | } |
1830 | | |
1831 | 1.04k | if (nInbound >= m_max_inbound) |
1832 | 1 | { |
1833 | 1 | if (!AttemptToEvictConnection()) { |
1834 | | // No connection to evict, disconnect the new connection |
1835 | 0 | LogDebug(BCLog::NET, "failed to find an eviction candidate - connection dropped (full)\n"); |
1836 | 0 | return; |
1837 | 0 | } |
1838 | 1 | } |
1839 | | |
1840 | 1.04k | NodeId id = GetNewNodeId(); |
1841 | 1.04k | uint64_t nonce = GetDeterministicRandomizer(RANDOMIZER_ID_LOCALHOSTNONCE).Write(id).Finalize(); |
1842 | | |
1843 | | // The V2Transport transparently falls back to V1 behavior when an incoming V1 connection is |
1844 | | // detected, so use it whenever we signal NODE_P2P_V2. |
1845 | 1.04k | ServiceFlags local_services = GetLocalServices(); |
1846 | 1.04k | const bool use_v2transport(local_services & NODE_P2P_V2); |
1847 | | |
1848 | 1.04k | uint64_t network_id = GetDeterministicRandomizer(RANDOMIZER_ID_NETWORKKEY) |
1849 | 1.04k | .Write(inbound_onion ? NET_ONION : addr.GetNetClass()) |
1850 | 1.04k | .Write(addr_bind.GetAddrBytes()) |
1851 | 1.04k | .Write(addr_bind.GetPort()) // inbound connections use bind port |
1852 | 1.04k | .Finalize(); |
1853 | 1.04k | CNode* pnode = new CNode(id, |
1854 | 1.04k | std::move(sock), |
1855 | 1.04k | CAddress{addr, NODE_NONE}, |
1856 | 1.04k | CalculateKeyedNetGroup(addr), |
1857 | 1.04k | nonce, |
1858 | 1.04k | addr_bind, |
1859 | 1.04k | /*addrNameIn=*/"", |
1860 | 1.04k | ConnectionType::INBOUND, |
1861 | 1.04k | inbound_onion, |
1862 | 1.04k | network_id, |
1863 | 1.04k | CNodeOptions{ |
1864 | 1.04k | .permission_flags = permission_flags, |
1865 | 1.04k | .prefer_evict = discouraged, |
1866 | 1.04k | .recv_flood_size = nReceiveFloodSize, |
1867 | 1.04k | .use_v2transport = use_v2transport, |
1868 | 1.04k | }); |
1869 | 1.04k | pnode->AddRef(); |
1870 | 1.04k | m_msgproc->InitializeNode(*pnode, local_services); |
1871 | 1.04k | { |
1872 | 1.04k | LOCK(m_nodes_mutex); |
1873 | 1.04k | m_nodes.push_back(pnode); |
1874 | 1.04k | } |
1875 | 1.04k | LogDebug(BCLog::NET, "connection from %s accepted\n", addr.ToStringAddrPort()); |
1876 | 1.04k | TRACEPOINT(net, inbound_connection, |
1877 | 1.04k | pnode->GetId(), |
1878 | 1.04k | pnode->m_addr_name.c_str(), |
1879 | 1.04k | pnode->ConnectionTypeAsString().c_str(), |
1880 | 1.04k | pnode->ConnectedThroughNetwork(), |
1881 | 1.04k | GetNodeCount(ConnectionDirection::In)); |
1882 | | |
1883 | | // We received a new connection, harvest entropy from the time (and our peer count) |
1884 | 1.04k | RandAddEvent((uint32_t)id); |
1885 | 1.04k | } |
1886 | | |
1887 | | bool CConnman::AddConnection(const std::string& address, ConnectionType conn_type, bool use_v2transport = false) |
1888 | 150 | { |
1889 | 150 | AssertLockNotHeld(m_nodes_mutex); |
1890 | 150 | AssertLockNotHeld(m_unused_i2p_sessions_mutex); |
1891 | 150 | std::optional<int> max_connections; |
1892 | 150 | switch (conn_type) { |
1893 | 0 | case ConnectionType::INBOUND: |
1894 | 0 | case ConnectionType::MANUAL: |
1895 | 0 | case ConnectionType::PRIVATE_BROADCAST: |
1896 | 0 | return false; |
1897 | 96 | case ConnectionType::OUTBOUND_FULL_RELAY: |
1898 | 96 | max_connections = m_max_outbound_full_relay; |
1899 | 96 | break; |
1900 | 35 | case ConnectionType::BLOCK_RELAY: |
1901 | 35 | max_connections = m_max_outbound_block_relay; |
1902 | 35 | break; |
1903 | | // no limit for ADDR_FETCH because -seednode has no limit either |
1904 | 15 | case ConnectionType::ADDR_FETCH: |
1905 | 15 | break; |
1906 | | // no limit for FEELER connections since they're short-lived |
1907 | 4 | case ConnectionType::FEELER: |
1908 | 4 | break; |
1909 | 150 | } // no default case, so the compiler can warn about missing cases |
1910 | | |
1911 | | // Count existing connections |
1912 | 150 | int existing_connections = WITH_LOCK(m_nodes_mutex, |
1913 | 150 | return std::count_if(m_nodes.begin(), m_nodes.end(), [conn_type](CNode* node) { return node->m_conn_type == conn_type; });); |
1914 | | |
1915 | | // Max connections of specified type already exist |
1916 | 150 | if (max_connections != std::nullopt && existing_connections >= max_connections) return false; |
1917 | | |
1918 | | // Max total outbound connections already exist |
1919 | 150 | CountingSemaphoreGrant<> grant(*semOutbound, true); |
1920 | 150 | if (!grant) return false; |
1921 | | |
1922 | 150 | OpenNetworkConnection(/*addrConnect=*/CAddress{}, |
1923 | 150 | /*fCountFailure=*/false, |
1924 | 150 | /*grant_outbound=*/std::move(grant), |
1925 | 150 | /*pszDest=*/address.c_str(), |
1926 | 150 | /*conn_type=*/conn_type, |
1927 | 150 | /*use_v2transport=*/use_v2transport, |
1928 | 150 | /*proxy_override=*/std::nullopt); |
1929 | 150 | return true; |
1930 | 150 | } |
1931 | | |
1932 | | void CConnman::DisconnectNodes() |
1933 | 327k | { |
1934 | 327k | AssertLockNotHeld(m_nodes_mutex); |
1935 | 327k | AssertLockNotHeld(m_reconnections_mutex); |
1936 | | |
1937 | | // Use a temporary variable to accumulate desired reconnections, so we don't need |
1938 | | // m_reconnections_mutex while holding m_nodes_mutex. |
1939 | 327k | decltype(m_reconnections) reconnections_to_add; |
1940 | | |
1941 | 327k | { |
1942 | 327k | LOCK(m_nodes_mutex); |
1943 | | |
1944 | 327k | const bool network_active{fNetworkActive}; |
1945 | 327k | if (!network_active) { |
1946 | | // Disconnect any connected nodes |
1947 | 168 | for (CNode* pnode : m_nodes) { |
1948 | 7 | if (!pnode->fDisconnect) { |
1949 | 7 | LogDebug(BCLog::NET, "Network not active, %s", pnode->DisconnectMsg()); |
1950 | 7 | pnode->fDisconnect = true; |
1951 | 7 | } |
1952 | 7 | } |
1953 | 168 | } |
1954 | | |
1955 | | // Disconnect unused nodes |
1956 | 327k | std::vector<CNode*> nodes_copy = m_nodes; |
1957 | 327k | for (CNode* pnode : nodes_copy) |
1958 | 515k | { |
1959 | 515k | if (pnode->fDisconnect) |
1960 | 907 | { |
1961 | | // remove from m_nodes |
1962 | 907 | m_nodes.erase(remove(m_nodes.begin(), m_nodes.end(), pnode), m_nodes.end()); |
1963 | | |
1964 | | // Add to reconnection list if appropriate. We don't reconnect right here, because |
1965 | | // the creation of a connection is a blocking operation (up to several seconds), |
1966 | | // and we don't want to hold up the socket handler thread for that long. |
1967 | 907 | if (network_active && pnode->m_transport->ShouldReconnectV1()) { |
1968 | 11 | reconnections_to_add.push_back({ |
1969 | 11 | .proxy_override = pnode->m_proxy_override, |
1970 | 11 | .addr_connect = pnode->addr, |
1971 | 11 | .grant = std::move(pnode->grantOutbound), |
1972 | 11 | .destination = pnode->m_dest, |
1973 | 11 | .conn_type = pnode->m_conn_type, |
1974 | 11 | .use_v2transport = false}); |
1975 | 11 | LogDebug(BCLog::NET, "retrying with v1 transport protocol for peer=%d\n", pnode->GetId()); |
1976 | 11 | } |
1977 | | |
1978 | | // release outbound grant (if any) |
1979 | 907 | pnode->grantOutbound.Release(); |
1980 | | |
1981 | | // close socket and cleanup |
1982 | 907 | pnode->CloseSocketDisconnect(); |
1983 | | |
1984 | | // update connection count by network |
1985 | 907 | if (pnode->IsManualOrFullOutboundConn()) --m_network_conn_counts[pnode->addr.GetNetwork()]; |
1986 | | |
1987 | | // hold in disconnected pool until all refs are released |
1988 | 907 | pnode->Release(); |
1989 | 907 | m_nodes_disconnected.push_back(pnode); |
1990 | 907 | } |
1991 | 515k | } |
1992 | 327k | } |
1993 | 327k | { |
1994 | | // Delete disconnected nodes |
1995 | 327k | std::list<CNode*> nodes_disconnected_copy = m_nodes_disconnected; |
1996 | 327k | for (CNode* pnode : nodes_disconnected_copy) |
1997 | 914 | { |
1998 | | // Destroy the object only after other threads have stopped using it. |
1999 | 914 | if (pnode->GetRefCount() <= 0) { |
2000 | 907 | m_nodes_disconnected.remove(pnode); |
2001 | 907 | DeleteNode(pnode); |
2002 | 907 | } |
2003 | 914 | } |
2004 | 327k | } |
2005 | 327k | { |
2006 | | // Move entries from reconnections_to_add to m_reconnections. |
2007 | 327k | LOCK(m_reconnections_mutex); |
2008 | 327k | m_reconnections.splice(m_reconnections.end(), std::move(reconnections_to_add)); |
2009 | 327k | } |
2010 | 327k | } |
2011 | | |
2012 | | void CConnman::NotifyNumConnectionsChanged() |
2013 | 327k | { |
2014 | 327k | AssertLockNotHeld(m_nodes_mutex); |
2015 | | |
2016 | 327k | size_t nodes_size; |
2017 | 327k | { |
2018 | 327k | LOCK(m_nodes_mutex); |
2019 | 327k | nodes_size = m_nodes.size(); |
2020 | 327k | } |
2021 | 327k | if(nodes_size != nPrevNodeCount) { |
2022 | 2.32k | nPrevNodeCount = nodes_size; |
2023 | 2.32k | if (m_client_interface) { |
2024 | 2.32k | m_client_interface->NotifyNumConnectionsChanged(nodes_size); |
2025 | 2.32k | } |
2026 | 2.32k | } |
2027 | 327k | } |
2028 | | |
2029 | | bool CConnman::ShouldRunInactivityChecks(const CNode& node, NodeClock::time_point now) const |
2030 | 892k | { |
2031 | 892k | return node.m_connected + m_peer_connect_timeout < now; |
2032 | 892k | } |
2033 | | |
2034 | | bool CConnman::InactivityCheck(const CNode& node, NodeClock::time_point now) const |
2035 | 514k | { |
2036 | | // Tests that see disconnects after using mocktime can start nodes with a |
2037 | | // large timeout. For example, -peertimeout=999999999. |
2038 | 514k | const auto last_send{node.m_last_send.load()}; |
2039 | 514k | const auto last_recv{node.m_last_recv.load()}; |
2040 | | |
2041 | 514k | if (!ShouldRunInactivityChecks(node, now)) return false; |
2042 | | |
2043 | 85 | bool has_received{last_recv > NodeClock::epoch}; |
2044 | 85 | bool has_sent{last_send > NodeClock::epoch}; |
2045 | | |
2046 | 85 | if (!has_received || !has_sent) { |
2047 | 3 | std::string has_never; |
2048 | 3 | if (!has_received) has_never += ", never received from peer"; |
2049 | 3 | if (!has_sent) has_never += ", never sent to peer"; |
2050 | 3 | LogDebug(BCLog::NET, |
2051 | 3 | "socket no message in first %i seconds%s, %s", |
2052 | 3 | count_seconds(m_peer_connect_timeout), |
2053 | 3 | has_never, |
2054 | 3 | node.DisconnectMsg() |
2055 | 3 | ); |
2056 | 3 | return true; |
2057 | 3 | } |
2058 | | |
2059 | 82 | if (now > last_send + TIMEOUT_INTERVAL) { |
2060 | 0 | LogDebug(BCLog::NET, |
2061 | 0 | "socket sending timeout: %is, %s", Ticks<std::chrono::seconds>(now - last_send), |
2062 | 0 | node.DisconnectMsg() |
2063 | 0 | ); |
2064 | 0 | return true; |
2065 | 0 | } |
2066 | | |
2067 | 82 | if (now > last_recv + TIMEOUT_INTERVAL) { |
2068 | 0 | LogDebug(BCLog::NET, |
2069 | 0 | "socket receive timeout: %is, %s", Ticks<std::chrono::seconds>(now - last_recv), |
2070 | 0 | node.DisconnectMsg() |
2071 | 0 | ); |
2072 | 0 | return true; |
2073 | 0 | } |
2074 | | |
2075 | 82 | if (!node.fSuccessfullyConnected) { |
2076 | 8 | if (node.m_transport->GetInfo().transport_type == TransportProtocolType::DETECTING) { |
2077 | 2 | LogDebug(BCLog::NET, "V2 handshake timeout, %s", node.DisconnectMsg()); |
2078 | 6 | } else { |
2079 | 6 | LogDebug(BCLog::NET, "version handshake timeout, %s", node.DisconnectMsg()); |
2080 | 6 | } |
2081 | 8 | return true; |
2082 | 8 | } |
2083 | | |
2084 | 74 | return false; |
2085 | 82 | } |
2086 | | |
2087 | | Sock::EventsPerSock CConnman::GenerateWaitSockets(std::span<CNode* const> nodes) |
2088 | 327k | { |
2089 | 327k | Sock::EventsPerSock events_per_sock; |
2090 | | |
2091 | 328k | for (const ListenSocket& hListenSocket : vhListenSocket) { |
2092 | 328k | events_per_sock.emplace(hListenSocket.sock, Sock::Events{Sock::RECV}); |
2093 | 328k | } |
2094 | | |
2095 | 515k | for (CNode* pnode : nodes) { |
2096 | 515k | bool select_recv = !pnode->fPauseRecv; |
2097 | 515k | bool select_send; |
2098 | 515k | { |
2099 | 515k | LOCK(pnode->cs_vSend); |
2100 | | // Sending is possible if either there are bytes to send right now, or if there will be |
2101 | | // once a potential message from vSendMsg is handed to the transport. GetBytesToSend |
2102 | | // determines both of these in a single call. |
2103 | 515k | const auto& [to_send, more, _msg_type] = pnode->m_transport->GetBytesToSend(!pnode->vSendMsg.empty()); |
2104 | 515k | select_send = !to_send.empty() || more; |
2105 | 515k | } |
2106 | 515k | if (!select_recv && !select_send) continue; |
2107 | | |
2108 | 514k | LOCK(pnode->m_sock_mutex); |
2109 | 514k | if (pnode->m_sock) { |
2110 | 514k | Sock::Event event = (select_send ? Sock::SEND : 0) | (select_recv ? Sock::RECV : 0); |
2111 | 514k | events_per_sock.emplace(pnode->m_sock, Sock::Events{event}); |
2112 | 514k | } |
2113 | 514k | } |
2114 | | |
2115 | 327k | return events_per_sock; |
2116 | 327k | } |
2117 | | |
2118 | | void CConnman::SocketHandler() |
2119 | 327k | { |
2120 | 327k | AssertLockNotHeld(m_nodes_mutex); |
2121 | 327k | AssertLockNotHeld(m_total_bytes_sent_mutex); |
2122 | | |
2123 | 327k | Sock::EventsPerSock events_per_sock; |
2124 | | |
2125 | 327k | { |
2126 | 327k | const NodesSnapshot snap{*this, /*shuffle=*/false}; |
2127 | | |
2128 | 327k | const auto timeout = std::chrono::milliseconds(SELECT_TIMEOUT_MILLISECONDS); |
2129 | | |
2130 | | // Check for the readiness of the already connected sockets and the |
2131 | | // listening sockets in one call ("readiness" as in poll(2) or |
2132 | | // select(2)). If none are ready, wait for a short while and return |
2133 | | // empty sets. |
2134 | 327k | events_per_sock = GenerateWaitSockets(snap.Nodes()); |
2135 | 327k | if (events_per_sock.empty() || !events_per_sock.begin()->first->WaitMany(timeout, events_per_sock)) { |
2136 | 32 | m_interrupt_net->sleep_for(timeout); |
2137 | 32 | } |
2138 | | |
2139 | | // Service (send/receive) each of the already connected nodes. |
2140 | 327k | SocketHandlerConnected(snap.Nodes(), events_per_sock); |
2141 | 327k | } |
2142 | | |
2143 | | // Accept new connections from listening sockets. |
2144 | 327k | SocketHandlerListening(events_per_sock); |
2145 | 327k | } |
2146 | | |
2147 | | void CConnman::SocketHandlerConnected(const std::vector<CNode*>& nodes, |
2148 | | const Sock::EventsPerSock& events_per_sock) |
2149 | 327k | { |
2150 | 327k | AssertLockNotHeld(m_total_bytes_sent_mutex); |
2151 | | |
2152 | 327k | const auto now{NodeClock::now()}; |
2153 | | |
2154 | 514k | for (CNode* pnode : nodes) { |
2155 | 514k | if (m_interrupt_net->interrupted()) { |
2156 | 400 | return; |
2157 | 400 | } |
2158 | | |
2159 | | // |
2160 | | // Receive |
2161 | | // |
2162 | 514k | bool recvSet = false; |
2163 | 514k | bool sendSet = false; |
2164 | 514k | bool errorSet = false; |
2165 | 514k | { |
2166 | 514k | LOCK(pnode->m_sock_mutex); |
2167 | 514k | if (!pnode->m_sock) { |
2168 | 0 | continue; |
2169 | 0 | } |
2170 | 514k | const auto it = events_per_sock.find(pnode->m_sock); |
2171 | 514k | if (it != events_per_sock.end()) { |
2172 | 514k | recvSet = it->second.occurred & Sock::RECV; |
2173 | 514k | sendSet = it->second.occurred & Sock::SEND; |
2174 | 514k | errorSet = it->second.occurred & Sock::ERR; |
2175 | 514k | } |
2176 | 514k | } |
2177 | | |
2178 | 514k | if (sendSet) { |
2179 | | // Send data |
2180 | 291 | auto [bytes_sent, data_left] = WITH_LOCK(pnode->cs_vSend, return SocketSendData(*pnode)); |
2181 | 291 | if (bytes_sent) { |
2182 | 289 | RecordBytesSent(bytes_sent); |
2183 | | |
2184 | | // If both receiving and (non-optimistic) sending were possible, we first attempt |
2185 | | // sending. If that succeeds, but does not fully drain the send queue, do not |
2186 | | // attempt to receive. This avoids needlessly queueing data if the remote peer |
2187 | | // is slow at receiving data, by means of TCP flow control. We only do this when |
2188 | | // sending actually succeeded to make sure progress is always made; otherwise a |
2189 | | // deadlock would be possible when both sides have data to send, but neither is |
2190 | | // receiving. |
2191 | 289 | if (data_left) recvSet = false; |
2192 | 289 | } |
2193 | 291 | } |
2194 | | |
2195 | 514k | if (recvSet || errorSet) |
2196 | 159k | { |
2197 | | // typical socket buffer is 8K-64K |
2198 | 159k | uint8_t pchBuf[0x10000]; |
2199 | 159k | int nBytes = 0; |
2200 | 159k | { |
2201 | 159k | LOCK(pnode->m_sock_mutex); |
2202 | 159k | if (!pnode->m_sock) { |
2203 | 2 | continue; |
2204 | 2 | } |
2205 | 159k | nBytes = pnode->m_sock->Recv(pchBuf, sizeof(pchBuf), MSG_DONTWAIT); |
2206 | 159k | } |
2207 | 159k | if (nBytes > 0) |
2208 | 158k | { |
2209 | 158k | bool notify = false; |
2210 | 158k | if (!pnode->ReceiveMsgBytes({pchBuf, (size_t)nBytes}, notify)) { |
2211 | 10 | LogDebug(BCLog::NET, |
2212 | 10 | "receiving message bytes failed, %s", |
2213 | 10 | pnode->DisconnectMsg() |
2214 | 10 | ); |
2215 | 10 | pnode->CloseSocketDisconnect(); |
2216 | 10 | } |
2217 | 158k | RecordBytesRecv(nBytes); |
2218 | 158k | if (notify) { |
2219 | 136k | pnode->MarkReceivedMsgsForProcessing(); |
2220 | 136k | WakeMessageHandler(); |
2221 | 136k | } |
2222 | 158k | } |
2223 | 576 | else if (nBytes == 0) |
2224 | 573 | { |
2225 | | // socket closed gracefully |
2226 | 573 | if (!pnode->fDisconnect) { |
2227 | 573 | LogDebug(BCLog::NET, "socket closed, %s", pnode->DisconnectMsg()); |
2228 | 573 | } |
2229 | 573 | pnode->CloseSocketDisconnect(); |
2230 | 573 | } |
2231 | 3 | else if (nBytes < 0) |
2232 | 3 | { |
2233 | | // error |
2234 | 3 | int nErr = WSAGetLastError(); |
2235 | 3 | if (nErr != WSAEWOULDBLOCK && nErr != WSAEMSGSIZE && nErr != WSAEINTR && nErr != WSAEINPROGRESS) |
2236 | 3 | { |
2237 | 3 | if (!pnode->fDisconnect) { |
2238 | 3 | LogDebug(BCLog::NET, "socket recv error, %s: %s", pnode->DisconnectMsg(), NetworkErrorString(nErr)); |
2239 | 3 | } |
2240 | 3 | pnode->CloseSocketDisconnect(); |
2241 | 3 | } |
2242 | 3 | } |
2243 | 159k | } |
2244 | | |
2245 | 514k | if (InactivityCheck(*pnode, now)) pnode->fDisconnect = true; |
2246 | 514k | } |
2247 | 327k | } |
2248 | | |
2249 | | void CConnman::SocketHandlerListening(const Sock::EventsPerSock& events_per_sock) |
2250 | 327k | { |
2251 | 327k | AssertLockNotHeld(m_nodes_mutex); |
2252 | | |
2253 | 328k | for (const ListenSocket& listen_socket : vhListenSocket) { |
2254 | 328k | if (m_interrupt_net->interrupted()) { |
2255 | 971 | return; |
2256 | 971 | } |
2257 | 327k | const auto it = events_per_sock.find(listen_socket.sock); |
2258 | 327k | if (it != events_per_sock.end() && it->second.occurred & Sock::RECV) { |
2259 | 1.04k | AcceptConnection(listen_socket); |
2260 | 1.04k | } |
2261 | 327k | } |
2262 | 327k | } |
2263 | | |
2264 | | void CConnman::ThreadSocketHandler() |
2265 | 994 | { |
2266 | 994 | AssertLockNotHeld(m_total_bytes_sent_mutex); |
2267 | | |
2268 | 328k | while (!m_interrupt_net->interrupted()) { |
2269 | 327k | DisconnectNodes(); |
2270 | 327k | NotifyNumConnectionsChanged(); |
2271 | 327k | SocketHandler(); |
2272 | 327k | } |
2273 | 994 | } |
2274 | | |
2275 | | void CConnman::WakeMessageHandler() |
2276 | 208k | { |
2277 | 208k | { |
2278 | 208k | LOCK(mutexMsgProc); |
2279 | 208k | fMsgProcWake = true; |
2280 | 208k | } |
2281 | 208k | condMsgProc.notify_one(); |
2282 | 208k | } |
2283 | | |
2284 | | void CConnman::ThreadDNSAddressSeed() |
2285 | 13 | { |
2286 | 13 | int outbound_connection_count = 0; |
2287 | | |
2288 | 13 | if (!gArgs.GetArgs("-seednode").empty()) { |
2289 | 0 | auto start = NodeClock::now(); |
2290 | 0 | constexpr std::chrono::seconds SEEDNODE_TIMEOUT = 30s; |
2291 | 0 | LogInfo("-seednode enabled. Trying the provided seeds for %d seconds before defaulting to the dnsseeds.\n", SEEDNODE_TIMEOUT.count()); |
2292 | 0 | while (!m_interrupt_net->interrupted()) { |
2293 | 0 | if (!m_interrupt_net->sleep_for(500ms)) { |
2294 | 0 | return; |
2295 | 0 | } |
2296 | | |
2297 | | // Abort if we have spent enough time without reaching our target. |
2298 | | // Giving seed nodes 30 seconds so this does not become a race against fixedseeds (which triggers after 1 min) |
2299 | 0 | if (NodeClock::now() > start + SEEDNODE_TIMEOUT) { |
2300 | 0 | LogInfo("Couldn't connect to enough peers via seed nodes. Handing fetch logic to the DNS seeds.\n"); |
2301 | 0 | break; |
2302 | 0 | } |
2303 | | |
2304 | 0 | outbound_connection_count = GetFullOutboundConnCount(); |
2305 | 0 | if (outbound_connection_count >= SEED_OUTBOUND_CONNECTION_THRESHOLD) { |
2306 | 0 | LogInfo("P2P peers available. Finished fetching data from seed nodes.\n"); |
2307 | 0 | break; |
2308 | 0 | } |
2309 | 0 | } |
2310 | 0 | } |
2311 | | |
2312 | 13 | FastRandomContext rng; |
2313 | 13 | std::vector<std::string> seeds = m_params.DNSSeeds(); |
2314 | 13 | std::shuffle(seeds.begin(), seeds.end(), rng); |
2315 | 13 | int seeds_right_now = 0; // Number of seeds left before testing if we have enough connections |
2316 | | |
2317 | 13 | if (gArgs.GetBoolArg("-forcednsseed", DEFAULT_FORCEDNSSEED)) { |
2318 | | // When -forcednsseed is provided, query all. |
2319 | 1 | seeds_right_now = seeds.size(); |
2320 | 12 | } else if (addrman.get().Size() == 0) { |
2321 | | // If we have no known peers, query all. |
2322 | | // This will occur on the first run, or if peers.dat has been |
2323 | | // deleted. |
2324 | 7 | seeds_right_now = seeds.size(); |
2325 | 7 | } |
2326 | | |
2327 | | // Proceed with dnsseeds if seednodes hasn't reached the target or if forcednsseed is set |
2328 | 13 | if (outbound_connection_count < SEED_OUTBOUND_CONNECTION_THRESHOLD || seeds_right_now) { |
2329 | | // goal: only query DNS seed if address need is acute |
2330 | | // * If we have a reasonable number of peers in addrman, spend |
2331 | | // some time trying them first. This improves user privacy by |
2332 | | // creating fewer identifying DNS requests, reduces trust by |
2333 | | // giving seeds less influence on the network topology, and |
2334 | | // reduces traffic to the seeds. |
2335 | | // * When querying DNS seeds query a few at once, this ensures |
2336 | | // that we don't give DNS seeds the ability to eclipse nodes |
2337 | | // that query them. |
2338 | | // * If we continue having problems, eventually query all the |
2339 | | // DNS seeds, and if that fails too, also try the fixed seeds. |
2340 | | // (done in ThreadOpenConnections) |
2341 | 13 | int found = 0; |
2342 | 13 | const std::chrono::seconds seeds_wait_time = (addrman.get().Size() >= DNSSEEDS_DELAY_PEER_THRESHOLD ? DNSSEEDS_DELAY_MANY_PEERS : DNSSEEDS_DELAY_FEW_PEERS); |
2343 | | |
2344 | 13 | for (const std::string& seed : seeds) { |
2345 | 13 | if (seeds_right_now == 0) { |
2346 | 5 | seeds_right_now += DNSSEEDS_TO_QUERY_AT_ONCE; |
2347 | | |
2348 | 5 | if (addrman.get().Size() > 0) { |
2349 | 5 | LogInfo("Waiting %d seconds before querying DNS seeds.\n", seeds_wait_time.count()); |
2350 | 5 | std::chrono::seconds to_wait = seeds_wait_time; |
2351 | 6 | while (to_wait.count() > 0) { |
2352 | | // if sleeping for the MANY_PEERS interval, wake up |
2353 | | // early to see if we have enough peers and can stop |
2354 | | // this thread entirely freeing up its resources |
2355 | 5 | std::chrono::seconds w = std::min(DNSSEEDS_DELAY_FEW_PEERS, to_wait); |
2356 | 5 | if (!m_interrupt_net->sleep_for(w)) return; |
2357 | 2 | to_wait -= w; |
2358 | | |
2359 | 2 | if (GetFullOutboundConnCount() >= SEED_OUTBOUND_CONNECTION_THRESHOLD) { |
2360 | 1 | if (found > 0) { |
2361 | 0 | LogInfo("%d addresses found from DNS seeds\n", found); |
2362 | 0 | LogInfo("P2P peers available. Finished DNS seeding.\n"); |
2363 | 1 | } else { |
2364 | 1 | LogInfo("P2P peers available. Skipped DNS seeding.\n"); |
2365 | 1 | } |
2366 | 1 | return; |
2367 | 1 | } |
2368 | 2 | } |
2369 | 5 | } |
2370 | 5 | } |
2371 | | |
2372 | 9 | if (m_interrupt_net->interrupted()) return; |
2373 | | |
2374 | | // hold off on querying seeds if P2P network deactivated |
2375 | 9 | if (!fNetworkActive) { |
2376 | 0 | LogInfo("Waiting for network to be reactivated before querying DNS seeds.\n"); |
2377 | 0 | do { |
2378 | 0 | if (!m_interrupt_net->sleep_for(1s)) return; |
2379 | 0 | } while (!fNetworkActive); |
2380 | 0 | } |
2381 | | |
2382 | 9 | LogInfo("Loading addresses from DNS seed %s\n", seed); |
2383 | | // If -proxy is in use, we make an ADDR_FETCH connection to the DNS resolved peer address |
2384 | | // for the base dns seed domain in chainparams |
2385 | 9 | if (HaveNameProxy()) { |
2386 | 9 | AddAddrFetch(seed); |
2387 | 9 | } else { |
2388 | 0 | std::vector<CAddress> vAdd; |
2389 | 0 | constexpr ServiceFlags requiredServiceBits{SeedsServiceFlags()}; |
2390 | 0 | std::string host = strprintf("x%x.%s", requiredServiceBits, seed); |
2391 | 0 | CNetAddr resolveSource; |
2392 | 0 | if (!resolveSource.SetInternal(host)) { |
2393 | 0 | continue; |
2394 | 0 | } |
2395 | | // Limit number of IPs learned from a single DNS seed. This limit exists to prevent the results from |
2396 | | // one DNS seed from dominating AddrMan. Note that the number of results from a UDP DNS query is |
2397 | | // bounded to 33 already, but it is possible for it to use TCP where a larger number of results can be |
2398 | | // returned. |
2399 | 0 | unsigned int nMaxIPs = 32; |
2400 | 0 | const auto addresses{LookupHost(host, nMaxIPs, true)}; |
2401 | 0 | if (!addresses.empty()) { |
2402 | 0 | for (const CNetAddr& ip : addresses) { |
2403 | 0 | CAddress addr = CAddress(CService(ip, m_params.GetDefaultPort()), requiredServiceBits); |
2404 | 0 | addr.nTime = rng.rand_uniform_delay(Now<NodeSeconds>() - 3 * 24h, -4 * 24h); // use a random age between 3 and 7 days old |
2405 | 0 | vAdd.push_back(addr); |
2406 | 0 | found++; |
2407 | 0 | } |
2408 | 0 | addrman.get().Add(vAdd, resolveSource); |
2409 | 0 | } else { |
2410 | | // If the seed does not support a subdomain with our desired service bits, |
2411 | | // we make an ADDR_FETCH connection to the DNS resolved peer address for the |
2412 | | // base dns seed domain in chainparams |
2413 | 0 | AddAddrFetch(seed); |
2414 | 0 | } |
2415 | 0 | } |
2416 | 9 | --seeds_right_now; |
2417 | 9 | } |
2418 | 9 | LogInfo("%d addresses found from DNS seeds\n", found); |
2419 | 9 | } else { |
2420 | 0 | LogInfo("Skipping DNS seeds. Enough peers have been found\n"); |
2421 | 0 | } |
2422 | 13 | } |
2423 | | |
2424 | | void CConnman::DumpAddresses() |
2425 | 1.00k | { |
2426 | 1.00k | const auto start{SteadyClock::now()}; |
2427 | | |
2428 | 1.00k | DumpPeerAddresses(::gArgs, addrman); |
2429 | | |
2430 | 1.00k | LogDebug(BCLog::NET, "Flushed %d addresses to peers.dat %dms", |
2431 | 1.00k | addrman.get().Size(), Ticks<std::chrono::milliseconds>(SteadyClock::now() - start)); |
2432 | 1.00k | } |
2433 | | |
2434 | | void CConnman::ProcessAddrFetch() |
2435 | 69 | { |
2436 | 69 | AssertLockNotHeld(m_nodes_mutex); |
2437 | 69 | AssertLockNotHeld(m_unused_i2p_sessions_mutex); |
2438 | 69 | std::string strDest; |
2439 | 69 | { |
2440 | 69 | LOCK(m_addr_fetches_mutex); |
2441 | 69 | if (m_addr_fetches.empty()) |
2442 | 66 | return; |
2443 | 3 | strDest = m_addr_fetches.front(); |
2444 | 3 | m_addr_fetches.pop_front(); |
2445 | 3 | } |
2446 | | // Attempt v2 connection if we support v2 - we'll reconnect with v1 if our |
2447 | | // peer doesn't support it or immediately disconnects us for another reason. |
2448 | 0 | const bool use_v2transport(GetLocalServices() & NODE_P2P_V2); |
2449 | 3 | CAddress addr; |
2450 | 3 | CountingSemaphoreGrant<> grant(*semOutbound, /*fTry=*/true); |
2451 | 3 | if (grant) { |
2452 | 3 | OpenNetworkConnection(/*addrConnect=*/addr, |
2453 | 3 | /*fCountFailure=*/false, |
2454 | 3 | /*grant_outbound=*/std::move(grant), |
2455 | 3 | /*pszDest=*/strDest.c_str(), |
2456 | 3 | /*conn_type=*/ConnectionType::ADDR_FETCH, |
2457 | 3 | /*use_v2transport=*/use_v2transport, |
2458 | 3 | /*proxy_override=*/std::nullopt); |
2459 | 3 | } |
2460 | 3 | } |
2461 | | |
2462 | | bool CConnman::GetTryNewOutboundPeer() const |
2463 | 73 | { |
2464 | 73 | return m_try_another_outbound_peer; |
2465 | 73 | } |
2466 | | |
2467 | | void CConnman::SetTryNewOutboundPeer(bool flag) |
2468 | 1.23k | { |
2469 | 1.23k | m_try_another_outbound_peer = flag; |
2470 | 1.23k | LogDebug(BCLog::NET, "setting try another outbound peer=%s\n", flag ? "true" : "false"); |
2471 | 1.23k | } |
2472 | | |
2473 | | void CConnman::StartExtraBlockRelayPeers() |
2474 | 47 | { |
2475 | 47 | LogDebug(BCLog::NET, "enabling extra block-relay-only peers\n"); |
2476 | 47 | m_start_extra_block_relay_peers = true; |
2477 | 47 | } |
2478 | | |
2479 | | // Return the number of outbound connections that are full relay (not blocks only) |
2480 | | int CConnman::GetFullOutboundConnCount() const |
2481 | 2 | { |
2482 | 2 | AssertLockNotHeld(m_nodes_mutex); |
2483 | | |
2484 | 2 | int nRelevant = 0; |
2485 | 2 | { |
2486 | 2 | LOCK(m_nodes_mutex); |
2487 | 4 | for (const CNode* pnode : m_nodes) { |
2488 | 4 | if (pnode->fSuccessfullyConnected && pnode->IsFullOutboundConn()) ++nRelevant; |
2489 | 4 | } |
2490 | 2 | } |
2491 | 2 | return nRelevant; |
2492 | 2 | } |
2493 | | |
2494 | | // Return the number of peers we have over our outbound connection limit |
2495 | | // Exclude peers that are marked for disconnect, or are going to be |
2496 | | // disconnected soon (eg ADDR_FETCH and FEELER) |
2497 | | // Also exclude peers that haven't finished initial connection handshake yet |
2498 | | // (so that we don't decide we're over our desired connection limit, and then |
2499 | | // evict some peer that has finished the handshake) |
2500 | | int CConnman::GetExtraFullOutboundCount() const |
2501 | 135 | { |
2502 | 135 | AssertLockNotHeld(m_nodes_mutex); |
2503 | | |
2504 | 135 | int full_outbound_peers = 0; |
2505 | 135 | { |
2506 | 135 | LOCK(m_nodes_mutex); |
2507 | 268 | for (const CNode* pnode : m_nodes) { |
2508 | 268 | if (pnode->fSuccessfullyConnected && !pnode->fDisconnect && pnode->IsFullOutboundConn()) { |
2509 | 64 | ++full_outbound_peers; |
2510 | 64 | } |
2511 | 268 | } |
2512 | 135 | } |
2513 | 135 | return std::max(full_outbound_peers - m_max_outbound_full_relay, 0); |
2514 | 135 | } |
2515 | | |
2516 | | int CConnman::GetExtraBlockRelayCount() const |
2517 | 135 | { |
2518 | 135 | AssertLockNotHeld(m_nodes_mutex); |
2519 | | |
2520 | 135 | int block_relay_peers = 0; |
2521 | 135 | { |
2522 | 135 | LOCK(m_nodes_mutex); |
2523 | 268 | for (const CNode* pnode : m_nodes) { |
2524 | 268 | if (pnode->fSuccessfullyConnected && !pnode->fDisconnect && pnode->IsBlockOnlyConn()) { |
2525 | 13 | ++block_relay_peers; |
2526 | 13 | } |
2527 | 268 | } |
2528 | 135 | } |
2529 | 135 | return std::max(block_relay_peers - m_max_outbound_block_relay, 0); |
2530 | 135 | } |
2531 | | |
2532 | | std::unordered_set<Network> CConnman::GetReachableEmptyNetworks() const |
2533 | 39 | { |
2534 | 39 | std::unordered_set<Network> networks{}; |
2535 | 312 | for (int n = 0; n < NET_MAX; n++) { |
2536 | 273 | enum Network net = (enum Network)n; |
2537 | 273 | if (net == NET_UNROUTABLE || net == NET_INTERNAL) continue; |
2538 | 195 | if (g_reachable_nets.Contains(net) && addrman.get().Size(net, std::nullopt) == 0) { |
2539 | 31 | networks.insert(net); |
2540 | 31 | } |
2541 | 195 | } |
2542 | 39 | return networks; |
2543 | 39 | } |
2544 | | |
2545 | | bool CConnman::MultipleManualOrFullOutboundConns(Network net) const |
2546 | 38 | { |
2547 | 38 | AssertLockHeld(m_nodes_mutex); |
2548 | 38 | return m_network_conn_counts[net] > 1; |
2549 | 38 | } |
2550 | | |
2551 | | bool CConnman::MaybePickPreferredNetwork(std::optional<Network>& network) |
2552 | 0 | { |
2553 | 0 | AssertLockNotHeld(m_nodes_mutex); |
2554 | |
|
2555 | 0 | std::array<Network, 5> nets{NET_IPV4, NET_IPV6, NET_ONION, NET_I2P, NET_CJDNS}; |
2556 | 0 | std::shuffle(nets.begin(), nets.end(), FastRandomContext()); |
2557 | |
|
2558 | 0 | LOCK(m_nodes_mutex); |
2559 | 0 | for (const auto net : nets) { |
2560 | 0 | if (g_reachable_nets.Contains(net) && m_network_conn_counts[net] == 0 && addrman.get().Size(net) != 0) { |
2561 | 0 | network = net; |
2562 | 0 | return true; |
2563 | 0 | } |
2564 | 0 | } |
2565 | | |
2566 | 0 | return false; |
2567 | 0 | } |
2568 | | |
2569 | | void CConnman::ThreadOpenConnections(const std::vector<std::string> connect, std::span<const std::string> seed_nodes) |
2570 | 38 | { |
2571 | 38 | AssertLockNotHeld(m_nodes_mutex); |
2572 | 38 | AssertLockNotHeld(m_reconnections_mutex); |
2573 | 38 | AssertLockNotHeld(m_unused_i2p_sessions_mutex); |
2574 | | |
2575 | 38 | FastRandomContext rng; |
2576 | | // Connect to specific addresses |
2577 | 38 | if (!connect.empty()) |
2578 | 5 | { |
2579 | | // Attempt v2 connection if we support v2 - we'll reconnect with v1 if our |
2580 | | // peer doesn't support it or immediately disconnects us for another reason. |
2581 | 5 | const bool use_v2transport(GetLocalServices() & NODE_P2P_V2); |
2582 | 5 | for (int64_t nLoop = 0;; nLoop++) |
2583 | 5 | { |
2584 | 5 | for (const std::string& strAddr : connect) |
2585 | 7 | { |
2586 | 7 | OpenNetworkConnection(/*addrConnect=*/CAddress{CService{}, NODE_NONE}, |
2587 | 7 | /*fCountFailure=*/false, |
2588 | 7 | /*grant_outbound=*/{}, |
2589 | 7 | /*pszDest=*/strAddr.c_str(), |
2590 | 7 | /*conn_type=*/ConnectionType::MANUAL, |
2591 | 7 | /*use_v2transport=*/use_v2transport, |
2592 | 7 | /*proxy_override=*/std::nullopt); |
2593 | 7 | for (int i = 0; i < 10 && i < nLoop; i++) |
2594 | 0 | { |
2595 | 0 | if (!m_interrupt_net->sleep_for(500ms)) { |
2596 | 0 | return; |
2597 | 0 | } |
2598 | 0 | } |
2599 | 7 | } |
2600 | 5 | if (!m_interrupt_net->sleep_for(500ms)) { |
2601 | 5 | return; |
2602 | 5 | } |
2603 | 0 | PerformReconnections(); |
2604 | 0 | } |
2605 | 5 | } |
2606 | | |
2607 | | // Initiate network connections |
2608 | 33 | auto start = GetTime<std::chrono::microseconds>(); |
2609 | | |
2610 | | // Minimum time before next feeler connection (in microseconds). |
2611 | 33 | auto next_feeler = start + rng.rand_exp_duration(FEELER_INTERVAL); |
2612 | 33 | auto next_extra_block_relay = start + rng.rand_exp_duration(EXTRA_BLOCK_RELAY_ONLY_PEER_INTERVAL); |
2613 | 33 | auto next_extra_network_peer{start + rng.rand_exp_duration(EXTRA_NETWORK_PEER_INTERVAL)}; |
2614 | 33 | const bool dnsseed = gArgs.GetBoolArg("-dnsseed", DEFAULT_DNSSEED); |
2615 | 33 | bool add_fixed_seeds = gArgs.GetBoolArg("-fixedseeds", DEFAULT_FIXEDSEEDS); |
2616 | 33 | const bool use_seednodes{!gArgs.GetArgs("-seednode").empty()}; |
2617 | | |
2618 | 33 | auto seed_node_timer = NodeClock::now(); |
2619 | 33 | bool add_addr_fetch{addrman.get().Size() == 0 && !seed_nodes.empty()}; |
2620 | 33 | constexpr std::chrono::seconds ADD_NEXT_SEEDNODE = 10s; |
2621 | | |
2622 | 33 | if (!add_fixed_seeds) { |
2623 | 29 | LogInfo("Fixed seeds are disabled\n"); |
2624 | 29 | } |
2625 | | |
2626 | 71 | while (!m_interrupt_net->interrupted()) { |
2627 | 69 | if (add_addr_fetch) { |
2628 | 2 | add_addr_fetch = false; |
2629 | 2 | const auto& seed{SpanPopBack(seed_nodes)}; |
2630 | 2 | AddAddrFetch(seed); |
2631 | | |
2632 | 2 | if (addrman.get().Size() == 0) { |
2633 | 1 | LogInfo("Empty addrman, adding seednode (%s) to addrfetch\n", seed); |
2634 | 1 | } else { |
2635 | 1 | LogInfo("Couldn't connect to peers from addrman after %d seconds. Adding seednode (%s) to addrfetch\n", ADD_NEXT_SEEDNODE.count(), seed); |
2636 | 1 | } |
2637 | 2 | } |
2638 | | |
2639 | 69 | ProcessAddrFetch(); |
2640 | | |
2641 | 69 | if (!m_interrupt_net->sleep_for(500ms)) { |
2642 | 30 | return; |
2643 | 30 | } |
2644 | | |
2645 | 39 | PerformReconnections(); |
2646 | | |
2647 | 39 | CountingSemaphoreGrant<> grant(*semOutbound); |
2648 | 39 | if (m_interrupt_net->interrupted()) { |
2649 | 0 | return; |
2650 | 0 | } |
2651 | | |
2652 | 39 | const std::unordered_set<Network> fixed_seed_networks{GetReachableEmptyNetworks()}; |
2653 | 39 | if (add_fixed_seeds && !fixed_seed_networks.empty()) { |
2654 | | // When the node starts with an empty peers.dat, there are a few other sources of peers before |
2655 | | // we fallback on to fixed seeds: -dnsseed, -seednode, -addnode |
2656 | | // If none of those are available, we fallback on to fixed seeds immediately, else we allow |
2657 | | // 60 seconds for any of those sources to populate addrman. |
2658 | 3 | bool add_fixed_seeds_now = false; |
2659 | | // It is cheapest to check if enough time has passed first. |
2660 | 3 | if (GetTime<std::chrono::seconds>() > start + std::chrono::minutes{1}) { |
2661 | 2 | add_fixed_seeds_now = true; |
2662 | 2 | LogInfo("Adding fixed seeds as 60 seconds have passed and addrman is empty for at least one reachable network\n"); |
2663 | 2 | } |
2664 | | |
2665 | | // Perform cheap checks before locking a mutex. |
2666 | 1 | else if (!dnsseed && !use_seednodes) { |
2667 | 1 | LOCK(m_added_nodes_mutex); |
2668 | 1 | if (m_added_node_params.empty()) { |
2669 | 1 | add_fixed_seeds_now = true; |
2670 | 1 | LogInfo("Adding fixed seeds as -dnsseed=0 (or IPv4/IPv6 connections are disabled via -onlynet) and neither -addnode nor -seednode are provided\n"); |
2671 | 1 | } |
2672 | 1 | } |
2673 | | |
2674 | 3 | if (add_fixed_seeds_now) { |
2675 | 3 | std::vector<CAddress> seed_addrs{ConvertSeeds(m_params.FixedSeeds())}; |
2676 | | // We will not make outgoing connections to peers that are unreachable |
2677 | | // (e.g. because of -onlynet configuration). |
2678 | | // Therefore, we do not add them to addrman in the first place. |
2679 | | // In case previously unreachable networks become reachable |
2680 | | // (e.g. in case of -onlynet changes by the user), fixed seeds will |
2681 | | // be loaded only for networks for which we have no addresses. |
2682 | 3 | seed_addrs.erase(std::remove_if(seed_addrs.begin(), seed_addrs.end(), |
2683 | 3 | [&fixed_seed_networks](const CAddress& addr) { return !fixed_seed_networks.contains(addr.GetNetwork()); }), |
2684 | 3 | seed_addrs.end()); |
2685 | 3 | CNetAddr local; |
2686 | 3 | local.SetInternal("fixedseeds"); |
2687 | 3 | addrman.get().Add(seed_addrs, local); |
2688 | 3 | add_fixed_seeds = false; |
2689 | 3 | LogInfo("Added %d fixed seeds from reachable networks.\n", seed_addrs.size()); |
2690 | 3 | } |
2691 | 3 | } |
2692 | | |
2693 | | // |
2694 | | // Choose an address to connect to based on most recently seen |
2695 | | // |
2696 | 39 | CAddress addrConnect; |
2697 | | |
2698 | | // Only connect out to one peer per ipv4/ipv6 network group (/16 for IPv4). |
2699 | 39 | int nOutboundFullRelay = 0; |
2700 | 39 | int nOutboundBlockRelay = 0; |
2701 | 39 | int outbound_privacy_network_peers = 0; |
2702 | 39 | std::set<std::vector<unsigned char>> outbound_ipv46_peer_netgroups; |
2703 | | |
2704 | 39 | { |
2705 | 39 | LOCK(m_nodes_mutex); |
2706 | 225 | for (const CNode* pnode : m_nodes) { |
2707 | 225 | if (pnode->IsFullOutboundConn()) nOutboundFullRelay++; |
2708 | 225 | if (pnode->IsBlockOnlyConn()) nOutboundBlockRelay++; |
2709 | | |
2710 | | // Make sure our persistent outbound slots to ipv4/ipv6 peers belong to different netgroups. |
2711 | 225 | switch (pnode->m_conn_type) { |
2712 | | // We currently don't take inbound connections into account. Since they are |
2713 | | // free to make, an attacker could make them to prevent us from connecting to |
2714 | | // certain peers. |
2715 | 2 | case ConnectionType::INBOUND: |
2716 | | // Short-lived outbound connections should not affect how we select outbound |
2717 | | // peers from addrman. |
2718 | 2 | case ConnectionType::ADDR_FETCH: |
2719 | 2 | case ConnectionType::FEELER: |
2720 | 15 | case ConnectionType::PRIVATE_BROADCAST: |
2721 | 15 | break; |
2722 | 7 | case ConnectionType::MANUAL: |
2723 | 177 | case ConnectionType::OUTBOUND_FULL_RELAY: |
2724 | 210 | case ConnectionType::BLOCK_RELAY: |
2725 | 210 | const CAddress address{pnode->addr}; |
2726 | 210 | if (address.IsTor() || address.IsI2P() || address.IsCJDNS()) { |
2727 | | // Since our addrman-groups for these networks are |
2728 | | // random, without relation to the route we |
2729 | | // take to connect to these peers or to the |
2730 | | // difficulty in obtaining addresses with diverse |
2731 | | // groups, we don't worry about diversity with |
2732 | | // respect to our addrman groups when connecting to |
2733 | | // these networks. |
2734 | 27 | ++outbound_privacy_network_peers; |
2735 | 183 | } else { |
2736 | 183 | outbound_ipv46_peer_netgroups.insert(m_netgroupman.GetGroup(address)); |
2737 | 183 | } |
2738 | 225 | } // no default case, so the compiler can warn about missing cases |
2739 | 225 | } |
2740 | 39 | } |
2741 | | |
2742 | 39 | if (!seed_nodes.empty() && nOutboundFullRelay < SEED_OUTBOUND_CONNECTION_THRESHOLD) { |
2743 | 2 | if (NodeClock::now() > seed_node_timer + ADD_NEXT_SEEDNODE) { |
2744 | 1 | seed_node_timer = NodeClock::now(); |
2745 | 1 | add_addr_fetch = true; |
2746 | 1 | } |
2747 | 2 | } |
2748 | | |
2749 | 39 | ConnectionType conn_type = ConnectionType::OUTBOUND_FULL_RELAY; |
2750 | 39 | auto now = GetTime<std::chrono::microseconds>(); |
2751 | 39 | bool anchor = false; |
2752 | 39 | bool fFeeler = false; |
2753 | 39 | std::optional<Network> preferred_net; |
2754 | | |
2755 | | // Determine what type of connection to open. Opening |
2756 | | // BLOCK_RELAY connections to addresses from anchors.dat gets the highest |
2757 | | // priority. Then we open OUTBOUND_FULL_RELAY priority until we |
2758 | | // meet our full-relay capacity. Then we open BLOCK_RELAY connection |
2759 | | // until we hit our block-relay-only peer limit. |
2760 | | // GetTryNewOutboundPeer() gets set when a stale tip is detected, so we |
2761 | | // try opening an additional OUTBOUND_FULL_RELAY connection. If none of |
2762 | | // these conditions are met, check to see if it's time to try an extra |
2763 | | // block-relay-only peer (to confirm our tip is current, see below) or the next_feeler |
2764 | | // timer to decide if we should open a FEELER. |
2765 | | |
2766 | 39 | if (!m_anchors.empty() && (nOutboundBlockRelay < m_max_outbound_block_relay)) { |
2767 | 1 | conn_type = ConnectionType::BLOCK_RELAY; |
2768 | 1 | anchor = true; |
2769 | 38 | } else if (nOutboundFullRelay < m_max_outbound_full_relay) { |
2770 | | // OUTBOUND_FULL_RELAY |
2771 | 21 | } else if (nOutboundBlockRelay < m_max_outbound_block_relay) { |
2772 | 2 | conn_type = ConnectionType::BLOCK_RELAY; |
2773 | 15 | } else if (GetTryNewOutboundPeer()) { |
2774 | | // OUTBOUND_FULL_RELAY |
2775 | 15 | } else if (now > next_extra_block_relay && m_start_extra_block_relay_peers) { |
2776 | | // Periodically connect to a peer (using regular outbound selection |
2777 | | // methodology from addrman) and stay connected long enough to sync |
2778 | | // headers, but not much else. |
2779 | | // |
2780 | | // Then disconnect the peer, if we haven't learned anything new. |
2781 | | // |
2782 | | // The idea is to make eclipse attacks very difficult to pull off, |
2783 | | // because every few minutes we're finding a new peer to learn headers |
2784 | | // from. |
2785 | | // |
2786 | | // This is similar to the logic for trying extra outbound (full-relay) |
2787 | | // peers, except: |
2788 | | // - we do this all the time on an exponential timer, rather than just when |
2789 | | // our tip is stale |
2790 | | // - we potentially disconnect our next-youngest block-relay-only peer, if our |
2791 | | // newest block-relay-only peer delivers a block more recently. |
2792 | | // See the eviction logic in net_processing.cpp. |
2793 | | // |
2794 | | // Because we can promote these connections to block-relay-only |
2795 | | // connections, they do not get their own ConnectionType enum |
2796 | | // (similar to how we deal with extra outbound peers). |
2797 | 1 | next_extra_block_relay = now + rng.rand_exp_duration(EXTRA_BLOCK_RELAY_ONLY_PEER_INTERVAL); |
2798 | 1 | conn_type = ConnectionType::BLOCK_RELAY; |
2799 | 14 | } else if (now > next_feeler) { |
2800 | 1 | next_feeler = now + rng.rand_exp_duration(FEELER_INTERVAL); |
2801 | 1 | conn_type = ConnectionType::FEELER; |
2802 | 1 | fFeeler = true; |
2803 | 13 | } else if (nOutboundFullRelay == m_max_outbound_full_relay && |
2804 | 13 | m_max_outbound_full_relay == MAX_OUTBOUND_FULL_RELAY_CONNECTIONS && |
2805 | 13 | now > next_extra_network_peer && |
2806 | 13 | MaybePickPreferredNetwork(preferred_net)) { |
2807 | | // Full outbound connection management: Attempt to get at least one |
2808 | | // outbound peer from each reachable network by making extra connections |
2809 | | // and then protecting "only" peers from a network during outbound eviction. |
2810 | | // This is not attempted if the user changed -maxconnections to a value |
2811 | | // so low that less than MAX_OUTBOUND_FULL_RELAY_CONNECTIONS are made, |
2812 | | // to prevent interactions with otherwise protected outbound peers. |
2813 | 0 | next_extra_network_peer = now + rng.rand_exp_duration(EXTRA_NETWORK_PEER_INTERVAL); |
2814 | 13 | } else { |
2815 | | // skip to next iteration of while loop |
2816 | 13 | continue; |
2817 | 13 | } |
2818 | | |
2819 | 26 | addrman.get().ResolveCollisions(); |
2820 | | |
2821 | 26 | const auto current_time{NodeClock::now()}; |
2822 | 26 | int nTries = 0; |
2823 | 26 | const auto reachable_nets{g_reachable_nets.All()}; |
2824 | | |
2825 | 139 | while (!m_interrupt_net->interrupted()) { |
2826 | 139 | if (anchor && !m_anchors.empty()) { |
2827 | 1 | const CAddress addr = m_anchors.back(); |
2828 | 1 | m_anchors.pop_back(); |
2829 | 1 | if (!addr.IsValid() || IsLocal(addr) || !g_reachable_nets.Contains(addr) || |
2830 | 1 | !m_msgproc->HasAllDesirableServiceFlags(addr.nServices) || |
2831 | 1 | outbound_ipv46_peer_netgroups.contains(m_netgroupman.GetGroup(addr))) continue; |
2832 | 1 | addrConnect = addr; |
2833 | 1 | LogDebug(BCLog::NET, "Trying to make an anchor connection to %s\n", addrConnect.ToStringAddrPort()); |
2834 | 1 | break; |
2835 | 1 | } |
2836 | | |
2837 | | // If we didn't find an appropriate destination after trying 100 addresses fetched from addrman, |
2838 | | // stop this loop, and let the outer loop run again (which sleeps, adds seed nodes, recalculates |
2839 | | // already-connected network ranges, ...) before trying new addrman addresses. |
2840 | 138 | nTries++; |
2841 | 138 | if (nTries > 100) |
2842 | 1 | break; |
2843 | | |
2844 | 137 | CAddress addr; |
2845 | 137 | NodeSeconds addr_last_try{0s}; |
2846 | | |
2847 | 137 | if (fFeeler) { |
2848 | | // First, try to get a tried table collision address. This returns |
2849 | | // an empty (invalid) address if there are no collisions to try. |
2850 | 1 | std::tie(addr, addr_last_try) = addrman.get().SelectTriedCollision(); |
2851 | | |
2852 | 1 | if (!addr.IsValid()) { |
2853 | | // No tried table collisions. Select a new table address |
2854 | | // for our feeler. |
2855 | 1 | std::tie(addr, addr_last_try) = addrman.get().Select(true, reachable_nets); |
2856 | 1 | } else if (AlreadyConnectedToAddress(addr)) { |
2857 | | // If test-before-evict logic would have us connect to a |
2858 | | // peer that we're already connected to, just mark that |
2859 | | // address as Good(). We won't be able to initiate the |
2860 | | // connection anyway, so this avoids inadvertently evicting |
2861 | | // a currently-connected peer. |
2862 | 0 | addrman.get().Good(addr); |
2863 | | // Select a new table address for our feeler instead. |
2864 | 0 | std::tie(addr, addr_last_try) = addrman.get().Select(true, reachable_nets); |
2865 | 0 | } |
2866 | 136 | } else { |
2867 | | // Not a feeler |
2868 | | // If preferred_net has a value set, pick an extra outbound |
2869 | | // peer from that network. The eviction logic in net_processing |
2870 | | // ensures that a peer from another network will be evicted. |
2871 | 136 | std::tie(addr, addr_last_try) = preferred_net.has_value() |
2872 | 136 | ? addrman.get().Select(false, {*preferred_net}) |
2873 | 136 | : addrman.get().Select(false, reachable_nets); |
2874 | 136 | } |
2875 | | |
2876 | | // Require outbound IPv4/IPv6 connections, other than feelers, to be to distinct network groups |
2877 | 137 | if (!fFeeler && outbound_ipv46_peer_netgroups.contains(m_netgroupman.GetGroup(addr))) { |
2878 | 113 | continue; |
2879 | 113 | } |
2880 | | |
2881 | | // if we selected an invalid or local address, restart |
2882 | 24 | if (!addr.IsValid() || IsLocal(addr)) { |
2883 | 3 | break; |
2884 | 3 | } |
2885 | | |
2886 | 21 | if (!g_reachable_nets.Contains(addr)) { |
2887 | 0 | continue; |
2888 | 0 | } |
2889 | | |
2890 | | // only consider very recently tried nodes after 30 failed attempts |
2891 | 21 | if (current_time - addr_last_try < 10min && nTries < 30) { |
2892 | 0 | continue; |
2893 | 0 | } |
2894 | | |
2895 | | // for non-feelers, require all the services we'll want, |
2896 | | // for feelers, only require they be a full node (only because most |
2897 | | // SPV clients don't have a good address DB available) |
2898 | 21 | if (!fFeeler && !m_msgproc->HasAllDesirableServiceFlags(addr.nServices)) { |
2899 | 0 | continue; |
2900 | 21 | } else if (fFeeler && !MayHaveUsefulAddressDB(addr.nServices)) { |
2901 | 0 | continue; |
2902 | 0 | } |
2903 | | |
2904 | | // Do not connect to bad ports, unless 50 invalid addresses have been selected already. |
2905 | 21 | if (nTries < 50 && (addr.IsIPv4() || addr.IsIPv6()) && IsBadPort(addr.GetPort())) { |
2906 | 0 | continue; |
2907 | 0 | } |
2908 | | |
2909 | | // Do not make automatic outbound connections to addnode peers, to |
2910 | | // not use our limited outbound slots for them and to ensure |
2911 | | // addnode connections benefit from their intended protections. |
2912 | 21 | if (AddedNodesContain(addr)) { |
2913 | 0 | LogDebug(BCLog::NET, "Not making automatic %s%s connection to %s peer selected for manual (addnode) connection%s\n", |
2914 | 0 | preferred_net.has_value() ? "network-specific " : "", |
2915 | 0 | ConnectionTypeAsString(conn_type), GetNetworkName(addr.GetNetwork()), |
2916 | 0 | fLogIPs ? strprintf(": %s", addr.ToStringAddrPort()) : ""); |
2917 | 0 | continue; |
2918 | 0 | } |
2919 | | |
2920 | 21 | addrConnect = addr; |
2921 | 21 | break; |
2922 | 21 | } |
2923 | | |
2924 | 26 | if (addrConnect.IsValid()) { |
2925 | 22 | if (fFeeler) { |
2926 | | // Add small amount of random noise before connection to avoid synchronization. |
2927 | 1 | if (!m_interrupt_net->sleep_for(rng.rand_uniform_duration<CThreadInterrupt::Clock>(FEELER_SLEEP_WINDOW))) { |
2928 | 1 | return; |
2929 | 1 | } |
2930 | 0 | LogDebug(BCLog::NET, "Making feeler connection to %s\n", addrConnect.ToStringAddrPort()); |
2931 | 0 | } |
2932 | | |
2933 | 21 | if (preferred_net != std::nullopt) LogDebug(BCLog::NET, "Making network specific connection to %s on %s.\n", addrConnect.ToStringAddrPort(), GetNetworkName(preferred_net.value())); |
2934 | | |
2935 | | // Record addrman failure attempts when node has at least 2 persistent outbound connections to peers with |
2936 | | // different netgroups in ipv4/ipv6 networks + all peers in Tor/I2P/CJDNS networks. |
2937 | | // Don't record addrman failure attempts when node is offline. This can be identified since all local |
2938 | | // network connections (if any) belong in the same netgroup, and the size of `outbound_ipv46_peer_netgroups` would only be 1. |
2939 | 21 | const bool count_failures{((int)outbound_ipv46_peer_netgroups.size() + outbound_privacy_network_peers) >= std::min(m_max_automatic_connections - 1, 2)}; |
2940 | | // Use BIP324 transport when both us and them have NODE_V2_P2P set. |
2941 | 21 | const bool use_v2transport(addrConnect.nServices & GetLocalServices() & NODE_P2P_V2); |
2942 | 21 | OpenNetworkConnection(/*addrConnect=*/addrConnect, |
2943 | 21 | /*fCountFailure=*/count_failures, |
2944 | 21 | /*grant_outbound=*/std::move(grant), |
2945 | 21 | /*pszDest=*/nullptr, |
2946 | 21 | /*conn_type=*/conn_type, |
2947 | 21 | /*use_v2transport=*/use_v2transport, |
2948 | 21 | /*proxy_override=*/std::nullopt); |
2949 | 21 | } |
2950 | 26 | } |
2951 | 33 | } |
2952 | | |
2953 | | std::vector<CAddress> CConnman::GetCurrentBlockRelayOnlyConns() const |
2954 | 33 | { |
2955 | 33 | AssertLockNotHeld(m_nodes_mutex); |
2956 | 33 | std::vector<CAddress> ret; |
2957 | 33 | LOCK(m_nodes_mutex); |
2958 | 39 | for (const CNode* pnode : m_nodes) { |
2959 | 39 | if (pnode->IsBlockOnlyConn()) { |
2960 | 5 | ret.push_back(pnode->addr); |
2961 | 5 | } |
2962 | 39 | } |
2963 | | |
2964 | 33 | return ret; |
2965 | 33 | } |
2966 | | |
2967 | | std::vector<AddedNodeInfo> CConnman::GetAddedNodeInfo(bool include_connected) const |
2968 | 5.59k | { |
2969 | 5.59k | AssertLockNotHeld(m_nodes_mutex); |
2970 | | |
2971 | 5.59k | std::vector<AddedNodeInfo> ret; |
2972 | | |
2973 | 5.59k | std::list<AddedNodeParams> lAddresses(0); |
2974 | 5.59k | { |
2975 | 5.59k | LOCK(m_added_nodes_mutex); |
2976 | 5.59k | ret.reserve(m_added_node_params.size()); |
2977 | 5.59k | std::copy(m_added_node_params.cbegin(), m_added_node_params.cend(), std::back_inserter(lAddresses)); |
2978 | 5.59k | } |
2979 | | |
2980 | | |
2981 | | // Build a map of all already connected addresses (by IP:port and by name) to inbound/outbound and resolved CService |
2982 | 5.59k | std::map<CService, bool> mapConnected; |
2983 | 5.59k | std::map<std::string, std::pair<bool, CService>> mapConnectedByName; |
2984 | 5.59k | { |
2985 | 5.59k | LOCK(m_nodes_mutex); |
2986 | 6.08k | for (const CNode* pnode : m_nodes) { |
2987 | 6.08k | if (pnode->addr.IsValid()) { |
2988 | 6.08k | mapConnected[pnode->addr] = pnode->IsInboundConn(); |
2989 | 6.08k | } |
2990 | 6.08k | std::string addrName{pnode->m_addr_name}; |
2991 | 6.08k | if (!addrName.empty()) { |
2992 | 6.08k | mapConnectedByName[std::move(addrName)] = std::make_pair(pnode->IsInboundConn(), static_cast<const CService&>(pnode->addr)); |
2993 | 6.08k | } |
2994 | 6.08k | } |
2995 | 5.59k | } |
2996 | | |
2997 | 5.59k | for (const auto& addr : lAddresses) { |
2998 | 33 | CService service{MaybeFlipIPv6toCJDNS(LookupNumeric(addr.m_added_node, GetDefaultPort(addr.m_added_node)))}; |
2999 | 33 | AddedNodeInfo addedNode{addr, CService(), false, false}; |
3000 | 33 | if (service.IsValid()) { |
3001 | | // strAddNode is an IP:port |
3002 | 31 | auto it = mapConnected.find(service); |
3003 | 31 | if (it != mapConnected.end()) { |
3004 | 15 | if (!include_connected) { |
3005 | 5 | continue; |
3006 | 5 | } |
3007 | 10 | addedNode.resolvedAddress = service; |
3008 | 10 | addedNode.fConnected = true; |
3009 | 10 | addedNode.fInbound = it->second; |
3010 | 10 | } |
3011 | 31 | } else { |
3012 | | // strAddNode is a name |
3013 | 2 | auto it = mapConnectedByName.find(addr.m_added_node); |
3014 | 2 | if (it != mapConnectedByName.end()) { |
3015 | 0 | if (!include_connected) { |
3016 | 0 | continue; |
3017 | 0 | } |
3018 | 0 | addedNode.resolvedAddress = it->second.second; |
3019 | 0 | addedNode.fConnected = true; |
3020 | 0 | addedNode.fInbound = it->second.first; |
3021 | 0 | } |
3022 | 2 | } |
3023 | 28 | ret.emplace_back(std::move(addedNode)); |
3024 | 28 | } |
3025 | | |
3026 | 5.59k | return ret; |
3027 | 5.59k | } |
3028 | | |
3029 | | void CConnman::ThreadOpenAddedConnections() |
3030 | 994 | { |
3031 | 994 | AssertLockNotHeld(m_nodes_mutex); |
3032 | 994 | AssertLockNotHeld(m_reconnections_mutex); |
3033 | 994 | AssertLockNotHeld(m_unused_i2p_sessions_mutex); |
3034 | | |
3035 | 5.57k | while (true) |
3036 | 5.57k | { |
3037 | 5.57k | CountingSemaphoreGrant<> grant(*semAddnode); |
3038 | 5.57k | std::vector<AddedNodeInfo> vInfo = GetAddedNodeInfo(/*include_connected=*/false); |
3039 | 5.57k | bool tried = false; |
3040 | 5.57k | for (const AddedNodeInfo& info : vInfo) { |
3041 | 4 | if (!grant) { |
3042 | | // If we've used up our semaphore and need a new one, let's not wait here since while we are waiting |
3043 | | // the addednodeinfo state might change. |
3044 | 0 | break; |
3045 | 0 | } |
3046 | 4 | tried = true; |
3047 | 4 | OpenNetworkConnection(/*addrConnect=*/CAddress{CService{}, NODE_NONE}, |
3048 | 4 | /*fCountFailure=*/false, |
3049 | 4 | /*grant_outbound=*/std::move(grant), |
3050 | 4 | /*pszDest=*/info.m_params.m_added_node.c_str(), |
3051 | 4 | /*conn_type=*/ConnectionType::MANUAL, |
3052 | 4 | /*use_v2transport=*/info.m_params.m_use_v2transport, |
3053 | 4 | /*proxy_override=*/std::nullopt); |
3054 | 4 | if (!m_interrupt_net->sleep_for(500ms)) return; |
3055 | 3 | grant = CountingSemaphoreGrant<>(*semAddnode, /*fTry=*/true); |
3056 | 3 | } |
3057 | | // See if any reconnections are desired. |
3058 | 5.57k | PerformReconnections(); |
3059 | | // Retry every 60 seconds if a connection was attempted, otherwise two seconds |
3060 | 5.57k | if (!m_interrupt_net->sleep_for(tried ? 60s : 2s)) { |
3061 | 993 | return; |
3062 | 993 | } |
3063 | 5.57k | } |
3064 | 994 | } |
3065 | | |
3066 | | // if successful, this moves the passed grant to the constructed node |
3067 | | bool CConnman::OpenNetworkConnection(const CAddress& addrConnect, |
3068 | | bool fCountFailure, |
3069 | | CountingSemaphoreGrant<>&& grant_outbound, |
3070 | | const char* pszDest, |
3071 | | ConnectionType conn_type, |
3072 | | bool use_v2transport, |
3073 | | const std::optional<Proxy>& proxy_override) |
3074 | 674 | { |
3075 | 674 | AssertLockNotHeld(m_nodes_mutex); |
3076 | 674 | AssertLockNotHeld(m_unused_i2p_sessions_mutex); |
3077 | 674 | assert(conn_type != ConnectionType::INBOUND); |
3078 | | |
3079 | | // |
3080 | | // Initiate outbound network connection |
3081 | | // |
3082 | 674 | if (m_interrupt_net->interrupted()) { |
3083 | 1 | return false; |
3084 | 1 | } |
3085 | 673 | if (!fNetworkActive) { |
3086 | 0 | return false; |
3087 | 0 | } |
3088 | 673 | if (!pszDest) { |
3089 | 70 | bool banned_or_discouraged = m_banman && (m_banman->IsDiscouraged(addrConnect) || m_banman->IsBanned(addrConnect)); |
3090 | 70 | if (IsLocal(addrConnect) || banned_or_discouraged || AlreadyConnectedToAddress(addrConnect)) { |
3091 | 21 | return false; |
3092 | 21 | } |
3093 | 603 | } else if (AlreadyConnectedToHost(pszDest)) { |
3094 | 0 | return false; |
3095 | 0 | } |
3096 | | |
3097 | 652 | CNode* pnode = ConnectNode(addrConnect, pszDest, fCountFailure, conn_type, use_v2transport, proxy_override); |
3098 | | |
3099 | 652 | if (!pnode) |
3100 | 28 | return false; |
3101 | 624 | pnode->grantOutbound = std::move(grant_outbound); |
3102 | | |
3103 | 624 | m_msgproc->InitializeNode(*pnode, m_local_services); |
3104 | 624 | { |
3105 | 624 | LOCK(m_nodes_mutex); |
3106 | 624 | m_nodes.push_back(pnode); |
3107 | | |
3108 | | // update connection count by network |
3109 | 624 | if (pnode->IsManualOrFullOutboundConn()) ++m_network_conn_counts[pnode->addr.GetNetwork()]; |
3110 | 624 | } |
3111 | | |
3112 | 624 | TRACEPOINT(net, outbound_connection, |
3113 | 624 | pnode->GetId(), |
3114 | 624 | pnode->m_addr_name.c_str(), |
3115 | 624 | pnode->ConnectionTypeAsString().c_str(), |
3116 | 624 | pnode->ConnectedThroughNetwork(), |
3117 | 624 | GetNodeCount(ConnectionDirection::Out)); |
3118 | | |
3119 | 624 | return true; |
3120 | 652 | } |
3121 | | |
3122 | | std::optional<Network> CConnman::PrivateBroadcast::PickNetwork(std::optional<Proxy>& proxy) const |
3123 | 156 | { |
3124 | 156 | prevector<4, Network> nets; |
3125 | 156 | std::optional<Proxy> clearnet_proxy; |
3126 | 156 | proxy.reset(); |
3127 | 156 | if (g_reachable_nets.Contains(NET_ONION)) { |
3128 | 156 | nets.push_back(NET_ONION); |
3129 | | |
3130 | 156 | clearnet_proxy = ProxyForIPv4or6(); |
3131 | 156 | if (clearnet_proxy.has_value()) { |
3132 | 53 | if (g_reachable_nets.Contains(NET_IPV4)) { |
3133 | 53 | nets.push_back(NET_IPV4); |
3134 | 53 | } |
3135 | 53 | if (g_reachable_nets.Contains(NET_IPV6)) { |
3136 | 53 | nets.push_back(NET_IPV6); |
3137 | 53 | } |
3138 | 53 | } |
3139 | 156 | } |
3140 | 156 | if (g_reachable_nets.Contains(NET_I2P)) { |
3141 | 38 | nets.push_back(NET_I2P); |
3142 | 38 | } |
3143 | | |
3144 | 156 | if (nets.empty()) { |
3145 | 0 | return std::nullopt; |
3146 | 0 | } |
3147 | | |
3148 | 156 | const Network net{nets[FastRandomContext{}.randrange(nets.size())]}; |
3149 | 156 | if (net == NET_IPV4 || net == NET_IPV6) { |
3150 | 32 | proxy = clearnet_proxy; |
3151 | 32 | } |
3152 | 156 | return net; |
3153 | 156 | } |
3154 | | |
3155 | | size_t CConnman::PrivateBroadcast::NumToOpen() const |
3156 | 28 | { |
3157 | 28 | return m_num_to_open; |
3158 | 28 | } |
3159 | | |
3160 | | void CConnman::PrivateBroadcast::NumToOpenAdd(size_t n) |
3161 | 2.31k | { |
3162 | 2.31k | m_num_to_open += n; |
3163 | 2.31k | m_num_to_open.notify_all(); |
3164 | 2.31k | } |
3165 | | |
3166 | | size_t CConnman::PrivateBroadcast::NumToOpenSub(size_t n) |
3167 | 17 | { |
3168 | 17 | size_t current_value{m_num_to_open.load()}; |
3169 | 17 | size_t new_value; |
3170 | 17 | do { |
3171 | 17 | new_value = current_value > n ? current_value - n : 0; |
3172 | 17 | } while (!m_num_to_open.compare_exchange_strong(current_value, new_value)); |
3173 | 17 | return new_value; |
3174 | 17 | } |
3175 | | |
3176 | | void CConnman::PrivateBroadcast::NumToOpenWait() const |
3177 | 160 | { |
3178 | 160 | m_num_to_open.wait(0); |
3179 | 160 | } |
3180 | | |
3181 | | std::optional<Proxy> CConnman::PrivateBroadcast::ProxyForIPv4or6() const |
3182 | 156 | { |
3183 | 156 | if (m_outbound_tor_ok_at_least_once.load()) { |
3184 | 53 | if (const auto tor_proxy = GetProxy(NET_ONION)) { |
3185 | 53 | return tor_proxy; |
3186 | 53 | } |
3187 | 53 | } |
3188 | 103 | return std::nullopt; |
3189 | 156 | } |
3190 | | |
3191 | | Mutex NetEventsInterface::g_msgproc_mutex; |
3192 | | |
3193 | | void CConnman::ThreadMessageHandler() |
3194 | 994 | { |
3195 | 994 | AssertLockNotHeld(m_nodes_mutex); |
3196 | | |
3197 | 994 | LOCK(NetEventsInterface::g_msgproc_mutex); |
3198 | | |
3199 | 250k | while (!flagInterruptMsgProc) |
3200 | 249k | { |
3201 | 249k | bool fMoreWork = false; |
3202 | | |
3203 | 249k | { |
3204 | | // Randomize the order in which we process messages from/to our peers. |
3205 | | // This prevents attacks in which an attacker exploits having multiple |
3206 | | // consecutive connections in the m_nodes list. |
3207 | 249k | const NodesSnapshot snap{*this, /*shuffle=*/true}; |
3208 | | |
3209 | 383k | for (CNode* pnode : snap.Nodes()) { |
3210 | 383k | if (pnode->fDisconnect) |
3211 | 58 | continue; |
3212 | | |
3213 | | // Receive messages |
3214 | 383k | bool fMoreNodeWork{m_msgproc->ProcessMessages(*pnode, flagInterruptMsgProc)}; |
3215 | 383k | fMoreWork |= (fMoreNodeWork && !pnode->fPauseSend); |
3216 | 383k | if (flagInterruptMsgProc) |
3217 | 7 | return; |
3218 | | // Send messages |
3219 | 383k | m_msgproc->SendMessages(*pnode); |
3220 | | |
3221 | 383k | if (flagInterruptMsgProc) |
3222 | 4 | return; |
3223 | 383k | } |
3224 | 249k | } |
3225 | | |
3226 | 249k | WAIT_LOCK(mutexMsgProc, lock); |
3227 | 249k | if (!fMoreWork) { |
3228 | 338k | condMsgProc.wait_until(lock, std::chrono::steady_clock::now() + std::chrono::milliseconds(100), [this]() EXCLUSIVE_LOCKS_REQUIRED(mutexMsgProc) { return fMsgProcWake; }); |
3229 | 174k | } |
3230 | 249k | fMsgProcWake = false; |
3231 | 249k | } |
3232 | 994 | } |
3233 | | |
3234 | | void CConnman::ThreadI2PAcceptIncoming() |
3235 | 4 | { |
3236 | 4 | AssertLockNotHeld(m_nodes_mutex); |
3237 | | |
3238 | 4 | static constexpr auto err_wait_begin = 1s; |
3239 | 4 | static constexpr auto err_wait_cap = 5min; |
3240 | 4 | auto err_wait = err_wait_begin; |
3241 | | |
3242 | 4 | bool advertising_listen_addr = false; |
3243 | 4 | i2p::Connection conn; |
3244 | | |
3245 | 8 | auto SleepOnFailure = [&]() { |
3246 | 8 | m_interrupt_net->sleep_for(err_wait); |
3247 | 8 | if (err_wait < err_wait_cap) { |
3248 | 8 | err_wait += 1s; |
3249 | 8 | } |
3250 | 8 | }; |
3251 | | |
3252 | 12 | while (!m_interrupt_net->interrupted()) { |
3253 | | |
3254 | 8 | if (!m_i2p_sam_session->Listen(conn)) { |
3255 | 8 | if (advertising_listen_addr && conn.me.IsValid()) { |
3256 | 0 | RemoveLocal(conn.me); |
3257 | 0 | advertising_listen_addr = false; |
3258 | 0 | } |
3259 | 8 | SleepOnFailure(); |
3260 | 8 | continue; |
3261 | 8 | } |
3262 | | |
3263 | 0 | if (!advertising_listen_addr) { |
3264 | 0 | AddLocal(conn.me, LOCAL_MANUAL); |
3265 | 0 | advertising_listen_addr = true; |
3266 | 0 | } |
3267 | |
|
3268 | 0 | if (!m_i2p_sam_session->Accept(conn)) { |
3269 | 0 | SleepOnFailure(); |
3270 | 0 | continue; |
3271 | 0 | } |
3272 | | |
3273 | 0 | CreateNodeFromAcceptedSocket(std::move(conn.sock), NetPermissionFlags::None, conn.me, conn.peer); |
3274 | |
|
3275 | 0 | err_wait = err_wait_begin; |
3276 | 0 | } |
3277 | 4 | } |
3278 | | |
3279 | | void CConnman::ThreadPrivateBroadcast() |
3280 | 5 | { |
3281 | 5 | AssertLockNotHeld(m_nodes_mutex); |
3282 | 5 | AssertLockNotHeld(m_unused_i2p_sessions_mutex); |
3283 | | |
3284 | 5 | size_t addrman_num_bad_addresses{0}; |
3285 | 161 | while (!m_interrupt_net->interrupted()) { |
3286 | | |
3287 | 160 | if (!fNetworkActive) { |
3288 | 0 | m_interrupt_net->sleep_for(5s); |
3289 | 0 | continue; |
3290 | 0 | } |
3291 | | |
3292 | 160 | CountingSemaphoreGrant<> conn_max_grant{m_private_broadcast.m_sem_conn_max}; // Would block if too many are opened. |
3293 | | |
3294 | 160 | m_private_broadcast.NumToOpenWait(); |
3295 | | |
3296 | 160 | if (m_interrupt_net->interrupted()) { |
3297 | 4 | break; |
3298 | 4 | } |
3299 | | |
3300 | 156 | std::optional<Proxy> proxy; |
3301 | 156 | const std::optional<Network> net{m_private_broadcast.PickNetwork(proxy)}; |
3302 | 156 | if (!net.has_value()) { |
3303 | 0 | LogWarning("Unable to open -privatebroadcast connections: neither Tor nor I2P is reachable"); |
3304 | 0 | m_interrupt_net->sleep_for(5s); |
3305 | 0 | continue; |
3306 | 0 | } |
3307 | | |
3308 | 156 | const auto [addr, _] = addrman.get().Select(/*new_only=*/false, {net.value()}); |
3309 | | |
3310 | 156 | if (!addr.IsValid() || IsLocal(addr)) { |
3311 | 113 | ++addrman_num_bad_addresses; |
3312 | 113 | if (addrman_num_bad_addresses > 100) { |
3313 | 6 | LogDebug(BCLog::PRIVBROADCAST, "Connections needed but addrman keeps returning bad addresses, will retry"); |
3314 | 6 | m_interrupt_net->sleep_for(500ms); |
3315 | 6 | } |
3316 | 113 | continue; |
3317 | 113 | } |
3318 | 43 | addrman_num_bad_addresses = 0; |
3319 | | |
3320 | 43 | auto target_str{addr.ToStringAddrPort()}; |
3321 | 43 | if (proxy.has_value()) { |
3322 | 23 | target_str += " through the proxy at " + proxy->ToString(); |
3323 | 23 | } |
3324 | | |
3325 | 43 | const bool use_v2transport(addr.nServices & GetLocalServices() & NODE_P2P_V2); |
3326 | | |
3327 | 43 | if (OpenNetworkConnection(addr, |
3328 | 43 | /*fCountFailure=*/true, |
3329 | 43 | std::move(conn_max_grant), |
3330 | 43 | /*pszDest=*/nullptr, |
3331 | 43 | ConnectionType::PRIVATE_BROADCAST, |
3332 | 43 | use_v2transport, |
3333 | 43 | proxy)) { |
3334 | 15 | const size_t remaining{m_private_broadcast.NumToOpenSub(1)}; |
3335 | 15 | LogDebug(BCLog::PRIVBROADCAST, "Socket connected to %s; remaining connections to open: %d", target_str, remaining); |
3336 | 28 | } else { |
3337 | 28 | const size_t remaining{m_private_broadcast.NumToOpen()}; |
3338 | 28 | if (remaining == 0) { |
3339 | 0 | LogDebug(BCLog::PRIVBROADCAST, "Failed to connect to %s, will not retry, no more connections needed", target_str); |
3340 | 28 | } else { |
3341 | 28 | LogDebug(BCLog::PRIVBROADCAST, "Failed to connect to %s, will retry to a different address; remaining connections to open: %d", target_str, remaining); |
3342 | 28 | m_interrupt_net->sleep_for(100ms); // Prevent busy loop if OpenNetworkConnection() fails fast repeatedly. |
3343 | 28 | } |
3344 | 28 | } |
3345 | 43 | } |
3346 | 5 | } |
3347 | | |
3348 | | bool CConnman::BindListenPort(const CService& addrBind, bilingual_str& strError, NetPermissionFlags permissions) |
3349 | 1.00k | { |
3350 | 1.00k | int nOne = 1; |
3351 | | |
3352 | | // Create socket for listening for incoming connections |
3353 | 1.00k | struct sockaddr_storage sockaddr; |
3354 | 1.00k | socklen_t len = sizeof(sockaddr); |
3355 | 1.00k | if (!addrBind.GetSockAddr((struct sockaddr*)&sockaddr, &len)) |
3356 | 0 | { |
3357 | 0 | strError = Untranslated(strprintf("Bind address family for %s not supported", addrBind.ToStringAddrPort())); |
3358 | 0 | LogError("%s\n", strError.original); |
3359 | 0 | return false; |
3360 | 0 | } |
3361 | | |
3362 | 1.00k | std::unique_ptr<Sock> sock = CreateSock(addrBind.GetSAFamily(), SOCK_STREAM, IPPROTO_TCP); |
3363 | 1.00k | if (!sock) { |
3364 | 0 | strError = Untranslated(strprintf("Couldn't open socket for incoming connections (socket returned error %s)", NetworkErrorString(WSAGetLastError()))); |
3365 | 0 | LogError("%s\n", strError.original); |
3366 | 0 | return false; |
3367 | 0 | } |
3368 | | |
3369 | | // Allow binding if the port is still in TIME_WAIT state after |
3370 | | // the program was closed and restarted. |
3371 | 1.00k | if (sock->SetSockOpt(SOL_SOCKET, SO_REUSEADDR, &nOne, sizeof(int)) == SOCKET_ERROR) { |
3372 | 0 | strError = Untranslated(strprintf("Error setting SO_REUSEADDR on socket: %s, continuing anyway", NetworkErrorString(WSAGetLastError()))); |
3373 | 0 | LogInfo("%s\n", strError.original); |
3374 | 0 | } |
3375 | | |
3376 | | // some systems don't have IPV6_V6ONLY but are always v6only; others do have the option |
3377 | | // and enable it by default or not. Try to enable it, if possible. |
3378 | 1.00k | if (addrBind.IsIPv6()) { |
3379 | 3 | #ifdef IPV6_V6ONLY |
3380 | 3 | if (sock->SetSockOpt(IPPROTO_IPV6, IPV6_V6ONLY, &nOne, sizeof(int)) == SOCKET_ERROR) { |
3381 | 0 | strError = Untranslated(strprintf("Error setting IPV6_V6ONLY on socket: %s, continuing anyway", NetworkErrorString(WSAGetLastError()))); |
3382 | 0 | LogInfo("%s\n", strError.original); |
3383 | 0 | } |
3384 | 3 | #endif |
3385 | | #ifdef WIN32 |
3386 | | int nProtLevel = PROTECTION_LEVEL_UNRESTRICTED; |
3387 | | if (sock->SetSockOpt(IPPROTO_IPV6, IPV6_PROTECTION_LEVEL, &nProtLevel, sizeof(int)) == SOCKET_ERROR) { |
3388 | | strError = Untranslated(strprintf("Error setting IPV6_PROTECTION_LEVEL on socket: %s, continuing anyway", NetworkErrorString(WSAGetLastError()))); |
3389 | | LogInfo("%s\n", strError.original); |
3390 | | } |
3391 | | #endif |
3392 | 3 | } |
3393 | | |
3394 | 1.00k | if (sock->Bind(reinterpret_cast<struct sockaddr*>(&sockaddr), len) == SOCKET_ERROR) { |
3395 | 11 | int nErr = WSAGetLastError(); |
3396 | 11 | if (nErr == WSAEADDRINUSE) |
3397 | 0 | strError = strprintf(_("Unable to bind to %s on this computer. %s is probably already running."), addrBind.ToStringAddrPort(), CLIENT_NAME); |
3398 | 11 | else |
3399 | 11 | strError = strprintf(_("Unable to bind to %s on this computer (bind returned error %s)"), addrBind.ToStringAddrPort(), NetworkErrorString(nErr)); |
3400 | 11 | LogError("%s\n", strError.original); |
3401 | 11 | return false; |
3402 | 11 | } |
3403 | 996 | LogInfo("Bound to %s\n", addrBind.ToStringAddrPort()); |
3404 | | |
3405 | | // Listen for incoming connections |
3406 | 996 | if (sock->Listen(SOMAXCONN) == SOCKET_ERROR) |
3407 | 0 | { |
3408 | 0 | strError = strprintf(_("Listening for incoming connections failed (listen returned error %s)"), NetworkErrorString(WSAGetLastError())); |
3409 | 0 | LogError("%s\n", strError.original); |
3410 | 0 | return false; |
3411 | 0 | } |
3412 | | |
3413 | 996 | vhListenSocket.emplace_back(std::move(sock), permissions); |
3414 | 996 | return true; |
3415 | 996 | } |
3416 | | |
3417 | | void Discover() |
3418 | 36 | { |
3419 | 36 | if (!fDiscover) |
3420 | 30 | return; |
3421 | | |
3422 | 18 | for (const CNetAddr &addr: GetLocalAddresses()) { |
3423 | 18 | if (AddLocal(addr, LOCAL_IF) && fLogIPs) { |
3424 | 0 | LogInfo("%s: %s\n", __func__, addr.ToStringAddr()); |
3425 | 0 | } |
3426 | 18 | } |
3427 | 6 | } |
3428 | | |
3429 | | void CConnman::SetNetworkActive(bool active) |
3430 | 1.24k | { |
3431 | 1.24k | LogInfo("%s: %s\n", __func__, active); |
3432 | | |
3433 | 1.24k | if (fNetworkActive == active) { |
3434 | 1.22k | return; |
3435 | 1.22k | } |
3436 | | |
3437 | 14 | fNetworkActive = active; |
3438 | | |
3439 | 14 | if (m_client_interface) { |
3440 | 9 | m_client_interface->NotifyNetworkActiveChanged(fNetworkActive); |
3441 | 9 | } |
3442 | 14 | } |
3443 | | |
3444 | | CConnman::CConnman(uint64_t nSeed0In, |
3445 | | uint64_t nSeed1In, |
3446 | | AddrMan& addrman_in, |
3447 | | const NetGroupManager& netgroupman, |
3448 | | const CChainParams& params, |
3449 | | bool network_active, |
3450 | | std::shared_ptr<CThreadInterrupt> interrupt_net) |
3451 | 1.23k | : addrman(addrman_in) |
3452 | 1.23k | , m_netgroupman{netgroupman} |
3453 | 1.23k | , nSeed0(nSeed0In) |
3454 | 1.23k | , nSeed1(nSeed1In) |
3455 | 1.23k | , m_interrupt_net{interrupt_net} |
3456 | 1.23k | , m_params(params) |
3457 | 1.23k | { |
3458 | 1.23k | SetTryNewOutboundPeer(false); |
3459 | | |
3460 | 1.23k | Options connOptions; |
3461 | 1.23k | Init(connOptions); |
3462 | 1.23k | SetNetworkActive(network_active); |
3463 | 1.23k | } |
3464 | | |
3465 | | NodeId CConnman::GetNewNodeId() |
3466 | 1.66k | { |
3467 | 1.66k | return nLastNodeId.fetch_add(1, std::memory_order_relaxed); |
3468 | 1.66k | } |
3469 | | |
3470 | | uint16_t CConnman::GetDefaultPort(Network net) const |
3471 | 2 | { |
3472 | 2 | return net == NET_I2P ? I2P_SAM31_PORT : m_params.GetDefaultPort(); |
3473 | 2 | } |
3474 | | |
3475 | | uint16_t CConnman::GetDefaultPort(const std::string& addr) const |
3476 | 677 | { |
3477 | 677 | CNetAddr a; |
3478 | 677 | return a.SetSpecial(addr) ? GetDefaultPort(a.GetNetwork()) : m_params.GetDefaultPort(); |
3479 | 677 | } |
3480 | | |
3481 | | bool CConnman::Bind(const CService& addr_, unsigned int flags, NetPermissionFlags permissions) |
3482 | 1.00k | { |
3483 | 1.00k | const CService addr{MaybeFlipIPv6toCJDNS(addr_)}; |
3484 | | |
3485 | 1.00k | bilingual_str strError; |
3486 | 1.00k | if (!BindListenPort(addr, strError, permissions)) { |
3487 | 11 | if ((flags & BF_REPORT_ERROR) && m_client_interface) { |
3488 | 11 | m_client_interface->ThreadSafeMessageBox(strError, CClientUIInterface::MSG_ERROR); |
3489 | 11 | } |
3490 | 11 | return false; |
3491 | 11 | } |
3492 | | |
3493 | 996 | if (addr.IsRoutable() && fDiscover && !(flags & BF_DONT_ADVERTISE) && !NetPermissions::HasFlag(permissions, NetPermissionFlags::NoBan)) { |
3494 | 0 | AddLocal(addr, LOCAL_BIND); |
3495 | 0 | } |
3496 | | |
3497 | 996 | return true; |
3498 | 1.00k | } |
3499 | | |
3500 | | bool CConnman::InitBinds(const Options& options) |
3501 | 986 | { |
3502 | 986 | for (const auto& addrBind : options.vBinds) { |
3503 | 978 | if (!Bind(addrBind, BF_REPORT_ERROR, NetPermissionFlags::None)) { |
3504 | 10 | return false; |
3505 | 10 | } |
3506 | 978 | } |
3507 | 976 | for (const auto& addrBind : options.vWhiteBinds) { |
3508 | 3 | if (!Bind(addrBind.m_service, BF_REPORT_ERROR, addrBind.m_flags)) { |
3509 | 1 | return false; |
3510 | 1 | } |
3511 | 3 | } |
3512 | 975 | for (const auto& addr_bind : options.onion_binds) { |
3513 | 20 | if (!Bind(addr_bind, BF_REPORT_ERROR | BF_DONT_ADVERTISE, NetPermissionFlags::None)) { |
3514 | 0 | return false; |
3515 | 0 | } |
3516 | 20 | } |
3517 | 975 | if (options.bind_on_any) { |
3518 | | // Don't consider errors to bind on IPv6 "::" fatal because the host OS |
3519 | | // may not have IPv6 support and the user did not explicitly ask us to |
3520 | | // bind on that. |
3521 | 3 | const CService ipv6_any{in6_addr(COMPAT_IN6ADDR_ANY_INIT), GetListenPort()}; // :: |
3522 | 3 | Bind(ipv6_any, BF_NONE, NetPermissionFlags::None); |
3523 | | |
3524 | 3 | struct in_addr inaddr_any; |
3525 | 3 | inaddr_any.s_addr = htonl(INADDR_ANY); |
3526 | 3 | const CService ipv4_any{inaddr_any, GetListenPort()}; // 0.0.0.0 |
3527 | 3 | if (!Bind(ipv4_any, BF_REPORT_ERROR, NetPermissionFlags::None)) { |
3528 | 0 | return false; |
3529 | 0 | } |
3530 | 3 | } |
3531 | 975 | return true; |
3532 | 975 | } |
3533 | | |
3534 | | bool CConnman::Start(CScheduler& scheduler, const Options& connOptions) |
3535 | 1.00k | { |
3536 | 1.00k | AssertLockNotHeld(m_total_bytes_sent_mutex); |
3537 | 1.00k | Init(connOptions); |
3538 | | |
3539 | 1.00k | if (fListen && !InitBinds(connOptions)) { |
3540 | 11 | if (m_client_interface) { |
3541 | 11 | m_client_interface->ThreadSafeMessageBox( |
3542 | 11 | _("Failed to listen on any port. Use -listen=0 if you want this."), |
3543 | 11 | CClientUIInterface::MSG_ERROR); |
3544 | 11 | } |
3545 | 11 | return false; |
3546 | 11 | } |
3547 | | |
3548 | 994 | if (connOptions.m_i2p_accept_incoming) { |
3549 | 974 | if (const auto i2p_sam = GetProxy(NET_I2P)) { |
3550 | 4 | m_i2p_sam_session = std::make_unique<i2p::sam::Session>(gArgs.GetDataDirNet() / "i2p_private_key", |
3551 | 4 | *i2p_sam, m_interrupt_net); |
3552 | 4 | } |
3553 | 974 | } |
3554 | | |
3555 | | // Randomize the order in which we may query seednode to potentially prevent connecting to the same one every restart (and signal that we have restarted) |
3556 | 994 | std::vector<std::string> seed_nodes = connOptions.vSeedNodes; |
3557 | 994 | if (!seed_nodes.empty()) { |
3558 | 5 | std::shuffle(seed_nodes.begin(), seed_nodes.end(), FastRandomContext{}); |
3559 | 5 | } |
3560 | | |
3561 | 994 | if (m_use_addrman_outgoing) { |
3562 | | // Load addresses from anchors.dat |
3563 | 33 | m_anchors = ReadAnchors(gArgs.GetDataDirNet() / ANCHORS_DATABASE_FILENAME); |
3564 | 33 | if (m_anchors.size() > MAX_BLOCK_RELAY_ONLY_ANCHORS) { |
3565 | 0 | m_anchors.resize(MAX_BLOCK_RELAY_ONLY_ANCHORS); |
3566 | 0 | } |
3567 | 33 | LogInfo("%i block-relay-only anchors will be tried for connections.\n", m_anchors.size()); |
3568 | 33 | } |
3569 | | |
3570 | 994 | if (m_client_interface) { |
3571 | 994 | m_client_interface->InitMessage(_("Starting network threads…")); |
3572 | 994 | } |
3573 | | |
3574 | 994 | fAddressesInitialized = true; |
3575 | | |
3576 | 994 | if (semOutbound == nullptr) { |
3577 | | // initialize semaphore |
3578 | 994 | semOutbound = std::make_unique<std::counting_semaphore<>>(std::min(m_max_automatic_outbound, m_max_automatic_connections)); |
3579 | 994 | } |
3580 | 994 | if (semAddnode == nullptr) { |
3581 | | // initialize semaphore |
3582 | 994 | semAddnode = std::make_unique<std::counting_semaphore<>>(m_max_addnode); |
3583 | 994 | } |
3584 | | |
3585 | | // |
3586 | | // Start threads |
3587 | | // |
3588 | 994 | assert(m_msgproc); |
3589 | 994 | m_interrupt_net->reset(); |
3590 | 994 | flagInterruptMsgProc = false; |
3591 | | |
3592 | 994 | { |
3593 | 994 | LOCK(mutexMsgProc); |
3594 | 994 | fMsgProcWake = false; |
3595 | 994 | } |
3596 | | |
3597 | | // Send and receive from sockets, accept connections |
3598 | 994 | threadSocketHandler = std::thread(&util::TraceThread, "net", [this] { ThreadSocketHandler(); }); |
3599 | | |
3600 | 994 | if (!gArgs.GetBoolArg("-dnsseed", DEFAULT_DNSSEED)) |
3601 | 994 | LogInfo("DNS seeding disabled\n"); |
3602 | 13 | else |
3603 | 13 | threadDNSAddressSeed = std::thread(&util::TraceThread, "dnsseed", [this] { ThreadDNSAddressSeed(); }); |
3604 | | |
3605 | | // Initiate manual connections |
3606 | 994 | threadOpenAddedConnections = std::thread(&util::TraceThread, "addcon", [this] { ThreadOpenAddedConnections(); }); |
3607 | | |
3608 | 994 | if (connOptions.m_use_addrman_outgoing && !connOptions.m_specified_outgoing.empty()) { |
3609 | 0 | if (m_client_interface) { |
3610 | 0 | m_client_interface->ThreadSafeMessageBox( |
3611 | 0 | _("Cannot provide specific connections and have addrman find outgoing connections at the same time."), |
3612 | 0 | CClientUIInterface::MSG_ERROR); |
3613 | 0 | } |
3614 | 0 | return false; |
3615 | 0 | } |
3616 | 994 | if (connOptions.m_use_addrman_outgoing || !connOptions.m_specified_outgoing.empty()) { |
3617 | 38 | threadOpenConnections = std::thread( |
3618 | 38 | &util::TraceThread, "opencon", |
3619 | 38 | [this, connect = connOptions.m_specified_outgoing, seed_nodes = std::move(seed_nodes)] { ThreadOpenConnections(connect, seed_nodes); }); |
3620 | 38 | } |
3621 | | |
3622 | | // Process messages |
3623 | 994 | threadMessageHandler = std::thread(&util::TraceThread, "msghand", [this] { ThreadMessageHandler(); }); |
3624 | | |
3625 | 994 | if (m_i2p_sam_session) { |
3626 | 4 | threadI2PAcceptIncoming = |
3627 | 4 | std::thread(&util::TraceThread, "i2paccept", [this] { ThreadI2PAcceptIncoming(); }); |
3628 | 4 | } |
3629 | | |
3630 | 994 | if (gArgs.GetBoolArg("-privatebroadcast", DEFAULT_PRIVATE_BROADCAST)) { |
3631 | 5 | threadPrivateBroadcast = |
3632 | 5 | std::thread(&util::TraceThread, "privbcast", [this] { ThreadPrivateBroadcast(); }); |
3633 | 5 | } |
3634 | | |
3635 | | // Dump network addresses |
3636 | 994 | scheduler.scheduleEvery([this] { DumpAddresses(); }, DUMP_PEERS_INTERVAL); |
3637 | | |
3638 | | // Run the ASMap Health check once and then schedule it to run every 24h. |
3639 | 994 | if (m_netgroupman.UsingASMap()) { |
3640 | 7 | ASMapHealthCheck(); |
3641 | 7 | scheduler.scheduleEvery([this] { ASMapHealthCheck(); }, ASMAP_HEALTH_CHECK_INTERVAL); |
3642 | 7 | } |
3643 | | |
3644 | 994 | return true; |
3645 | 994 | } |
3646 | | |
3647 | | class CNetCleanup |
3648 | | { |
3649 | | public: |
3650 | | CNetCleanup() = default; |
3651 | | |
3652 | | ~CNetCleanup() |
3653 | 0 | { |
3654 | | #ifdef WIN32 |
3655 | | // Shutdown Windows Sockets |
3656 | | WSACleanup(); |
3657 | | #endif |
3658 | 0 | } |
3659 | | }; |
3660 | | static CNetCleanup instance_of_cnetcleanup; |
3661 | | |
3662 | | void CConnman::Interrupt() |
3663 | 2.30k | { |
3664 | 2.30k | { |
3665 | 2.30k | LOCK(mutexMsgProc); |
3666 | 2.30k | flagInterruptMsgProc = true; |
3667 | 2.30k | } |
3668 | 2.30k | condMsgProc.notify_all(); |
3669 | | |
3670 | 2.30k | (*m_interrupt_net)(); |
3671 | 2.30k | g_socks5_interrupt(); |
3672 | | |
3673 | 2.30k | if (semOutbound) { |
3674 | 11.9k | for (int i=0; i<m_max_automatic_outbound; i++) { |
3675 | 10.9k | semOutbound->release(); |
3676 | 10.9k | } |
3677 | 994 | } |
3678 | | |
3679 | 2.30k | if (semAddnode) { |
3680 | 8.94k | for (int i=0; i<m_max_addnode; i++) { |
3681 | 7.95k | semAddnode->release(); |
3682 | 7.95k | } |
3683 | 994 | } |
3684 | | |
3685 | 2.30k | m_private_broadcast.m_sem_conn_max.release(); |
3686 | 2.30k | m_private_broadcast.NumToOpenAdd(1); // Just unblock NumToOpenWait() to be able to continue with shutdown. |
3687 | 2.30k | } |
3688 | | |
3689 | | void CConnman::StopThreads() |
3690 | 2.30k | { |
3691 | 2.30k | if (threadPrivateBroadcast.joinable()) { |
3692 | 5 | threadPrivateBroadcast.join(); |
3693 | 5 | } |
3694 | 2.30k | if (threadI2PAcceptIncoming.joinable()) { |
3695 | 4 | threadI2PAcceptIncoming.join(); |
3696 | 4 | } |
3697 | 2.30k | if (threadMessageHandler.joinable()) |
3698 | 994 | threadMessageHandler.join(); |
3699 | 2.30k | if (threadOpenConnections.joinable()) |
3700 | 38 | threadOpenConnections.join(); |
3701 | 2.30k | if (threadOpenAddedConnections.joinable()) |
3702 | 994 | threadOpenAddedConnections.join(); |
3703 | 2.30k | if (threadDNSAddressSeed.joinable()) |
3704 | 13 | threadDNSAddressSeed.join(); |
3705 | 2.30k | if (threadSocketHandler.joinable()) |
3706 | 994 | threadSocketHandler.join(); |
3707 | 2.30k | } |
3708 | | |
3709 | | void CConnman::StopNodes() |
3710 | 2.30k | { |
3711 | 2.30k | AssertLockNotHeld(m_nodes_mutex); |
3712 | 2.30k | AssertLockNotHeld(m_reconnections_mutex); |
3713 | | |
3714 | 2.30k | if (fAddressesInitialized) { |
3715 | 994 | DumpAddresses(); |
3716 | 994 | fAddressesInitialized = false; |
3717 | | |
3718 | 994 | if (m_use_addrman_outgoing) { |
3719 | | // Anchor connections are only dumped during clean shutdown. |
3720 | 33 | std::vector<CAddress> anchors_to_dump = GetCurrentBlockRelayOnlyConns(); |
3721 | 33 | if (anchors_to_dump.size() > MAX_BLOCK_RELAY_ONLY_ANCHORS) { |
3722 | 0 | anchors_to_dump.resize(MAX_BLOCK_RELAY_ONLY_ANCHORS); |
3723 | 0 | } |
3724 | 33 | DumpAnchors(gArgs.GetDataDirNet() / ANCHORS_DATABASE_FILENAME, anchors_to_dump); |
3725 | 33 | } |
3726 | 994 | } |
3727 | | |
3728 | | // Delete peer connections. |
3729 | 2.30k | std::vector<CNode*> nodes; |
3730 | 2.30k | WITH_LOCK(m_nodes_mutex, nodes.swap(m_nodes)); |
3731 | 2.30k | for (CNode* pnode : nodes) { |
3732 | 760 | LogDebug(BCLog::NET, "Stopping node, %s", pnode->DisconnectMsg()); |
3733 | 760 | pnode->CloseSocketDisconnect(); |
3734 | 760 | DeleteNode(pnode); |
3735 | 760 | } |
3736 | | |
3737 | 2.30k | for (CNode* pnode : m_nodes_disconnected) { |
3738 | 0 | DeleteNode(pnode); |
3739 | 0 | } |
3740 | 2.30k | m_nodes_disconnected.clear(); |
3741 | 2.30k | WITH_LOCK(m_reconnections_mutex, m_reconnections.clear()); |
3742 | 2.30k | vhListenSocket.clear(); |
3743 | 2.30k | semOutbound.reset(); |
3744 | 2.30k | semAddnode.reset(); |
3745 | 2.30k | } |
3746 | | |
3747 | | void CConnman::DeleteNode(CNode* pnode) |
3748 | 1.66k | { |
3749 | 1.66k | assert(pnode); |
3750 | 1.66k | m_msgproc->FinalizeNode(*pnode); |
3751 | 1.66k | delete pnode; |
3752 | 1.66k | } |
3753 | | |
3754 | | CConnman::~CConnman() |
3755 | 1.23k | { |
3756 | 1.23k | Interrupt(); |
3757 | 1.23k | Stop(); |
3758 | 1.23k | } |
3759 | | |
3760 | | std::vector<CAddress> CConnman::GetAddressesUnsafe(size_t max_addresses, size_t max_pct, std::optional<Network> network, const bool filtered) const |
3761 | 470 | { |
3762 | 470 | std::vector<CAddress> addresses = addrman.get().GetAddr(max_addresses, max_pct, network, filtered); |
3763 | 470 | if (m_banman) { |
3764 | 470 | addresses.erase(std::remove_if(addresses.begin(), addresses.end(), |
3765 | 34.4k | [this](const CAddress& addr){return m_banman->IsDiscouraged(addr) || m_banman->IsBanned(addr);}), |
3766 | 470 | addresses.end()); |
3767 | 470 | } |
3768 | 470 | return addresses; |
3769 | 470 | } |
3770 | | |
3771 | | std::vector<CAddress> CConnman::GetAddresses(CNode& requestor, size_t max_addresses, size_t max_pct) |
3772 | 944 | { |
3773 | 944 | uint64_t network_id = requestor.m_network_key; |
3774 | 944 | const auto current_time = GetTime<std::chrono::microseconds>(); |
3775 | 944 | auto r = m_addr_response_caches.emplace(network_id, CachedAddrResponse{}); |
3776 | 944 | CachedAddrResponse& cache_entry = r.first->second; |
3777 | 944 | if (cache_entry.m_cache_entry_expiration < current_time) { // If emplace() added new one it has expiration 0. |
3778 | 383 | cache_entry.m_addrs_response_cache = GetAddressesUnsafe(max_addresses, max_pct, /*network=*/std::nullopt); |
3779 | | // Choosing a proper cache lifetime is a trade-off between the privacy leak minimization |
3780 | | // and the usefulness of ADDR responses to honest users. |
3781 | | // |
3782 | | // Longer cache lifetime makes it more difficult for an attacker to scrape |
3783 | | // enough AddrMan data to maliciously infer something useful. |
3784 | | // By the time an attacker scraped enough AddrMan records, most of |
3785 | | // the records should be old enough to not leak topology info by |
3786 | | // e.g. analyzing real-time changes in timestamps. |
3787 | | // |
3788 | | // It takes only several hundred requests to scrape everything from an AddrMan containing 100,000 nodes, |
3789 | | // so ~24 hours of cache lifetime indeed makes the data less inferable by the time |
3790 | | // most of it could be scraped (considering that timestamps are updated via |
3791 | | // ADDR self-announcements and when nodes communicate). |
3792 | | // We also should be robust to those attacks which may not require scraping *full* victim's AddrMan |
3793 | | // (because even several timestamps of the same handful of nodes may leak privacy). |
3794 | | // |
3795 | | // On the other hand, longer cache lifetime makes ADDR responses |
3796 | | // outdated and less useful for an honest requestor, e.g. if most nodes |
3797 | | // in the ADDR response are no longer active. |
3798 | | // |
3799 | | // However, the churn in the network is known to be rather low. Since we consider |
3800 | | // nodes to be "terrible" (see IsTerrible()) if the timestamps are older than 30 days, |
3801 | | // max. 24 hours of "penalty" due to cache shouldn't make any meaningful difference |
3802 | | // in terms of the freshness of the response. |
3803 | 383 | cache_entry.m_cache_entry_expiration = current_time + |
3804 | 383 | 21h + FastRandomContext().randrange<std::chrono::microseconds>(6h); |
3805 | 383 | } |
3806 | 944 | return cache_entry.m_addrs_response_cache; |
3807 | 944 | } |
3808 | | |
3809 | | bool CConnman::AddNode(const AddedNodeParams& add) |
3810 | 15 | { |
3811 | 15 | const CService resolved(LookupNumeric(add.m_added_node, GetDefaultPort(add.m_added_node))); |
3812 | 15 | const bool resolved_is_valid{resolved.IsValid()}; |
3813 | | |
3814 | 15 | LOCK(m_added_nodes_mutex); |
3815 | 18 | for (const auto& it : m_added_node_params) { |
3816 | 18 | if (add.m_added_node == it.m_added_node || (resolved_is_valid && resolved == LookupNumeric(it.m_added_node, GetDefaultPort(it.m_added_node)))) return false; |
3817 | 18 | } |
3818 | | |
3819 | 9 | m_added_node_params.push_back(add); |
3820 | 9 | return true; |
3821 | 15 | } |
3822 | | |
3823 | | bool CConnman::RemoveAddedNode(std::string_view node) |
3824 | 4 | { |
3825 | 4 | LOCK(m_added_nodes_mutex); |
3826 | 6 | for (auto it = m_added_node_params.begin(); it != m_added_node_params.end(); ++it) { |
3827 | 4 | if (node == it->m_added_node) { |
3828 | 2 | m_added_node_params.erase(it); |
3829 | 2 | return true; |
3830 | 2 | } |
3831 | 4 | } |
3832 | 2 | return false; |
3833 | 4 | } |
3834 | | |
3835 | | bool CConnman::AddedNodesContain(const CAddress& addr) const |
3836 | 27 | { |
3837 | 27 | AssertLockNotHeld(m_added_nodes_mutex); |
3838 | 27 | const std::string addr_str{addr.ToStringAddr()}; |
3839 | 27 | const std::string addr_port_str{addr.ToStringAddrPort()}; |
3840 | 27 | LOCK(m_added_nodes_mutex); |
3841 | 27 | return (m_added_node_params.size() < 24 // bound the query to a reasonable limit |
3842 | 27 | && std::any_of(m_added_node_params.cbegin(), m_added_node_params.cend(), |
3843 | 27 | [&](const auto& p) { return p.m_added_node == addr_str || p.m_added_node == addr_port_str; })); |
3844 | 27 | } |
3845 | | |
3846 | | size_t CConnman::GetNodeCount(ConnectionDirection flags) const |
3847 | 2.71k | { |
3848 | 2.71k | LOCK(m_nodes_mutex); |
3849 | 2.71k | if (flags == ConnectionDirection::Both) // Shortcut if we want total |
3850 | 910 | return m_nodes.size(); |
3851 | | |
3852 | 1.80k | int nNum = 0; |
3853 | 1.80k | for (const auto& pnode : m_nodes) { |
3854 | 1.01k | if (flags & (pnode->IsInboundConn() ? ConnectionDirection::In : ConnectionDirection::Out)) { |
3855 | 506 | nNum++; |
3856 | 506 | } |
3857 | 1.01k | } |
3858 | | |
3859 | 1.80k | return nNum; |
3860 | 2.71k | } |
3861 | | |
3862 | | |
3863 | | std::map<CNetAddr, LocalServiceInfo> CConnman::getNetLocalAddresses() const |
3864 | 0 | { |
3865 | 0 | LOCK(g_maplocalhost_mutex); |
3866 | 0 | return mapLocalHost; |
3867 | 0 | } |
3868 | | |
3869 | | uint32_t CConnman::GetMappedAS(const CNetAddr& addr) const |
3870 | 17.4k | { |
3871 | 17.4k | return m_netgroupman.GetMappedAS(addr); |
3872 | 17.4k | } |
3873 | | |
3874 | | void CConnman::GetNodeStats(std::vector<CNodeStats>& vstats) const |
3875 | 7.02k | { |
3876 | 7.02k | AssertLockNotHeld(m_nodes_mutex); |
3877 | | |
3878 | 7.02k | vstats.clear(); |
3879 | 7.02k | LOCK(m_nodes_mutex); |
3880 | 7.02k | vstats.reserve(m_nodes.size()); |
3881 | 14.2k | for (CNode* pnode : m_nodes) { |
3882 | 14.2k | vstats.emplace_back(); |
3883 | 14.2k | pnode->CopyStats(vstats.back()); |
3884 | 14.2k | vstats.back().m_mapped_as = GetMappedAS(pnode->addr); |
3885 | 14.2k | } |
3886 | 7.02k | } |
3887 | | |
3888 | | bool CConnman::DisconnectNode(std::string_view strNode) |
3889 | 4 | { |
3890 | 4 | LOCK(m_nodes_mutex); |
3891 | 6 | auto it = std::ranges::find_if(m_nodes, [&strNode](CNode* node) { return node->m_addr_name == strNode; }); |
3892 | 4 | if (it != m_nodes.end()) { |
3893 | 2 | CNode* node{*it}; |
3894 | 2 | LogDebug(BCLog::NET, "disconnect by address%s match, %s", (fLogIPs ? strprintf("=%s", strNode) : ""), node->DisconnectMsg()); |
3895 | 2 | node->fDisconnect = true; |
3896 | 2 | return true; |
3897 | 2 | } |
3898 | 2 | return false; |
3899 | 4 | } |
3900 | | |
3901 | | bool CConnman::DisconnectNode(const CSubNet& subnet) |
3902 | 33 | { |
3903 | 33 | AssertLockNotHeld(m_nodes_mutex); |
3904 | 33 | bool disconnected = false; |
3905 | 33 | LOCK(m_nodes_mutex); |
3906 | 33 | for (CNode* pnode : m_nodes) { |
3907 | 16 | if (subnet.Match(pnode->addr)) { |
3908 | 11 | LogDebug(BCLog::NET, "disconnect by subnet%s match, %s", (fLogIPs ? strprintf("=%s", subnet.ToString()) : ""), pnode->DisconnectMsg()); |
3909 | 11 | pnode->fDisconnect = true; |
3910 | 11 | disconnected = true; |
3911 | 11 | } |
3912 | 16 | } |
3913 | 33 | return disconnected; |
3914 | 33 | } |
3915 | | |
3916 | | bool CConnman::DisconnectNode(const CNetAddr& addr) |
3917 | 20 | { |
3918 | 20 | AssertLockNotHeld(m_nodes_mutex); |
3919 | 20 | return DisconnectNode(CSubNet(addr)); |
3920 | 20 | } |
3921 | | |
3922 | | bool CConnman::DisconnectNode(NodeId id) |
3923 | 94 | { |
3924 | 94 | LOCK(m_nodes_mutex); |
3925 | 155 | for(CNode* pnode : m_nodes) { |
3926 | 155 | if (id == pnode->GetId()) { |
3927 | 94 | LogDebug(BCLog::NET, "disconnect by id, %s", pnode->DisconnectMsg()); |
3928 | 94 | pnode->fDisconnect = true; |
3929 | 94 | return true; |
3930 | 94 | } |
3931 | 155 | } |
3932 | 0 | return false; |
3933 | 94 | } |
3934 | | |
3935 | | void CConnman::RecordBytesRecv(uint64_t bytes) |
3936 | 158k | { |
3937 | 158k | nTotalBytesRecv += bytes; |
3938 | 158k | } |
3939 | | |
3940 | | void CConnman::RecordBytesSent(uint64_t bytes) |
3941 | 169k | { |
3942 | 169k | AssertLockNotHeld(m_total_bytes_sent_mutex); |
3943 | 169k | LOCK(m_total_bytes_sent_mutex); |
3944 | | |
3945 | 169k | nTotalBytesSent += bytes; |
3946 | | |
3947 | 169k | const auto now = GetTime<std::chrono::seconds>(); |
3948 | 169k | if (nMaxOutboundCycleStartTime + MAX_UPLOAD_TIMEFRAME < now) |
3949 | 535 | { |
3950 | | // timeframe expired, reset cycle |
3951 | 535 | nMaxOutboundCycleStartTime = now; |
3952 | 535 | nMaxOutboundTotalBytesSentInCycle = 0; |
3953 | 535 | } |
3954 | | |
3955 | 169k | nMaxOutboundTotalBytesSentInCycle += bytes; |
3956 | 169k | } |
3957 | | |
3958 | | uint64_t CConnman::GetMaxOutboundTarget() const |
3959 | 17 | { |
3960 | 17 | AssertLockNotHeld(m_total_bytes_sent_mutex); |
3961 | 17 | LOCK(m_total_bytes_sent_mutex); |
3962 | 17 | return nMaxOutboundLimit; |
3963 | 17 | } |
3964 | | |
3965 | | std::chrono::seconds CConnman::GetMaxOutboundTimeframe() const |
3966 | 17 | { |
3967 | 17 | return MAX_UPLOAD_TIMEFRAME; |
3968 | 17 | } |
3969 | | |
3970 | | std::chrono::seconds CConnman::GetMaxOutboundTimeLeftInCycle() const |
3971 | 17 | { |
3972 | 17 | AssertLockNotHeld(m_total_bytes_sent_mutex); |
3973 | 17 | LOCK(m_total_bytes_sent_mutex); |
3974 | 17 | return GetMaxOutboundTimeLeftInCycle_(); |
3975 | 17 | } |
3976 | | |
3977 | | std::chrono::seconds CConnman::GetMaxOutboundTimeLeftInCycle_() const |
3978 | 1.12k | { |
3979 | 1.12k | AssertLockHeld(m_total_bytes_sent_mutex); |
3980 | | |
3981 | 1.12k | if (nMaxOutboundLimit == 0) |
3982 | 11 | return 0s; |
3983 | | |
3984 | 1.11k | if (nMaxOutboundCycleStartTime.count() == 0) |
3985 | 4 | return MAX_UPLOAD_TIMEFRAME; |
3986 | | |
3987 | 1.11k | const std::chrono::seconds cycleEndTime = nMaxOutboundCycleStartTime + MAX_UPLOAD_TIMEFRAME; |
3988 | 1.11k | const auto now = GetTime<std::chrono::seconds>(); |
3989 | 1.11k | return (cycleEndTime < now) ? 0s : cycleEndTime - now; |
3990 | 1.11k | } |
3991 | | |
3992 | | bool CConnman::OutboundTargetReached(bool historicalBlockServingLimit) const |
3993 | 36.5k | { |
3994 | 36.5k | AssertLockNotHeld(m_total_bytes_sent_mutex); |
3995 | 36.5k | LOCK(m_total_bytes_sent_mutex); |
3996 | 36.5k | if (nMaxOutboundLimit == 0) |
3997 | 35.4k | return false; |
3998 | | |
3999 | 1.11k | if (historicalBlockServingLimit) |
4000 | 1.10k | { |
4001 | | // keep a large enough buffer to at least relay each block once |
4002 | 1.10k | const std::chrono::seconds timeLeftInCycle = GetMaxOutboundTimeLeftInCycle_(); |
4003 | 1.10k | const uint64_t buffer = timeLeftInCycle / std::chrono::minutes{10} * MAX_BLOCK_SERIALIZED_SIZE; |
4004 | 1.10k | if (buffer >= nMaxOutboundLimit || nMaxOutboundTotalBytesSentInCycle >= nMaxOutboundLimit - buffer) |
4005 | 827 | return true; |
4006 | 1.10k | } |
4007 | 8 | else if (nMaxOutboundTotalBytesSentInCycle >= nMaxOutboundLimit) |
4008 | 3 | return true; |
4009 | | |
4010 | 286 | return false; |
4011 | 1.11k | } |
4012 | | |
4013 | | uint64_t CConnman::GetOutboundTargetBytesLeft() const |
4014 | 17 | { |
4015 | 17 | AssertLockNotHeld(m_total_bytes_sent_mutex); |
4016 | 17 | LOCK(m_total_bytes_sent_mutex); |
4017 | 17 | if (nMaxOutboundLimit == 0) |
4018 | 11 | return 0; |
4019 | | |
4020 | 6 | return (nMaxOutboundTotalBytesSentInCycle >= nMaxOutboundLimit) ? 0 : nMaxOutboundLimit - nMaxOutboundTotalBytesSentInCycle; |
4021 | 17 | } |
4022 | | |
4023 | | uint64_t CConnman::GetTotalBytesRecv() const |
4024 | 17 | { |
4025 | 17 | return nTotalBytesRecv; |
4026 | 17 | } |
4027 | | |
4028 | | uint64_t CConnman::GetTotalBytesSent() const |
4029 | 17 | { |
4030 | 17 | AssertLockNotHeld(m_total_bytes_sent_mutex); |
4031 | 17 | LOCK(m_total_bytes_sent_mutex); |
4032 | 17 | return nTotalBytesSent; |
4033 | 17 | } |
4034 | | |
4035 | | ServiceFlags CConnman::GetLocalServices() const |
4036 | 4.88k | { |
4037 | 4.88k | return m_local_services; |
4038 | 4.88k | } |
4039 | | |
4040 | | static std::unique_ptr<Transport> MakeTransport(NodeId id, bool use_v2transport, bool inbound) noexcept |
4041 | 1.70k | { |
4042 | 1.70k | if (use_v2transport) { |
4043 | 208 | return std::make_unique<V2Transport>(id, /*initiating=*/!inbound); |
4044 | 1.50k | } else { |
4045 | 1.50k | return std::make_unique<V1Transport>(id); |
4046 | 1.50k | } |
4047 | 1.70k | } |
4048 | | |
4049 | | CNode::CNode(NodeId idIn, |
4050 | | std::shared_ptr<Sock> sock, |
4051 | | const CAddress& addrIn, |
4052 | | uint64_t nKeyedNetGroupIn, |
4053 | | uint64_t nLocalHostNonceIn, |
4054 | | const CService& addrBindIn, |
4055 | | const std::string& addrNameIn, |
4056 | | ConnectionType conn_type_in, |
4057 | | bool inbound_onion, |
4058 | | uint64_t network_key, |
4059 | | CNodeOptions&& node_opts) |
4060 | 1.70k | : m_transport{MakeTransport(idIn, node_opts.use_v2transport, conn_type_in == ConnectionType::INBOUND)}, |
4061 | 1.70k | m_permission_flags{node_opts.permission_flags}, |
4062 | 1.70k | m_sock{sock}, |
4063 | 1.70k | m_connected{NodeClock::now()}, |
4064 | 1.70k | m_proxy_override{std::move(node_opts.proxy_override)}, |
4065 | 1.70k | addr{addrIn}, |
4066 | 1.70k | addrBind{addrBindIn}, |
4067 | 1.70k | m_addr_name{addrNameIn.empty() ? addr.ToStringAddrPort() : addrNameIn}, |
4068 | 1.70k | m_dest(addrNameIn), |
4069 | 1.70k | m_inbound_onion{inbound_onion}, |
4070 | 1.70k | m_prefer_evict{node_opts.prefer_evict}, |
4071 | 1.70k | nKeyedNetGroup{nKeyedNetGroupIn}, |
4072 | 1.70k | m_network_key{network_key}, |
4073 | 1.70k | m_conn_type{conn_type_in}, |
4074 | 1.70k | id{idIn}, |
4075 | 1.70k | nLocalHostNonce{nLocalHostNonceIn}, |
4076 | 1.70k | m_recv_flood_size{node_opts.recv_flood_size}, |
4077 | 1.70k | m_i2p_sam_session{std::move(node_opts.i2p_sam_session)} |
4078 | 1.70k | { |
4079 | 1.70k | if (inbound_onion) assert(conn_type_in == ConnectionType::INBOUND); |
4080 | | |
4081 | 61.4k | for (const auto& msg : ALL_NET_MESSAGE_TYPES) { |
4082 | 61.4k | mapRecvBytesPerMsgType[msg] = 0; |
4083 | 61.4k | } |
4084 | 1.70k | mapRecvBytesPerMsgType[NET_MESSAGE_TYPE_OTHER] = 0; |
4085 | | |
4086 | 1.70k | if (fLogIPs) { |
4087 | 9 | LogDebug(BCLog::NET, "Added connection to %s peer=%d\n", m_addr_name, id); |
4088 | 1.69k | } else { |
4089 | 1.69k | LogDebug(BCLog::NET, "Added connection peer=%d\n", id); |
4090 | 1.69k | } |
4091 | 1.70k | } |
4092 | | |
4093 | | void CNode::MarkReceivedMsgsForProcessing() |
4094 | 136k | { |
4095 | 136k | AssertLockNotHeld(m_msg_process_queue_mutex); |
4096 | | |
4097 | 136k | size_t nSizeAdded = 0; |
4098 | 160k | for (const auto& msg : vRecvMsg) { |
4099 | | // vRecvMsg contains only completed CNetMessage |
4100 | | // the single possible partially deserialized message are held by TransportDeserializer |
4101 | 160k | nSizeAdded += msg.GetMemoryUsage(); |
4102 | 160k | } |
4103 | | |
4104 | 136k | LOCK(m_msg_process_queue_mutex); |
4105 | 136k | m_msg_process_queue.splice(m_msg_process_queue.end(), vRecvMsg); |
4106 | 136k | m_msg_process_queue_size += nSizeAdded; |
4107 | 136k | fPauseRecv = m_msg_process_queue_size > m_recv_flood_size; |
4108 | 136k | } |
4109 | | |
4110 | | std::optional<std::pair<CNetMessage, bool>> CNode::PollMessage() |
4111 | 381k | { |
4112 | 381k | LOCK(m_msg_process_queue_mutex); |
4113 | 381k | if (m_msg_process_queue.empty()) return std::nullopt; |
4114 | | |
4115 | 160k | std::list<CNetMessage> msgs; |
4116 | | // Just take one message |
4117 | 160k | msgs.splice(msgs.begin(), m_msg_process_queue, m_msg_process_queue.begin()); |
4118 | 160k | m_msg_process_queue_size -= msgs.front().GetMemoryUsage(); |
4119 | 160k | fPauseRecv = m_msg_process_queue_size > m_recv_flood_size; |
4120 | | |
4121 | 160k | return std::make_pair(std::move(msgs.front()), !m_msg_process_queue.empty()); |
4122 | 381k | } |
4123 | | |
4124 | | bool CConnman::NodeFullyConnected(const CNode* pnode) |
4125 | 70.3k | { |
4126 | 70.3k | return pnode && pnode->fSuccessfullyConnected && !pnode->fDisconnect; |
4127 | 70.3k | } |
4128 | | |
4129 | | /// Private broadcast connections only need to send certain message types. |
4130 | | /// Other messages are not needed and may degrade privacy. |
4131 | | static bool IsOutboundMessageAllowedInPrivateBroadcast(std::string_view type) noexcept |
4132 | 68 | { |
4133 | 68 | return type == NetMsgType::VERSION || |
4134 | 68 | type == NetMsgType::VERACK || |
4135 | 68 | type == NetMsgType::INV || |
4136 | 68 | type == NetMsgType::TX || |
4137 | 68 | type == NetMsgType::PING; |
4138 | 68 | } |
4139 | | |
4140 | | void CConnman::PushMessage(CNode* pnode, CSerializedNetMsg&& msg) |
4141 | 169k | { |
4142 | 169k | AssertLockNotHeld(m_total_bytes_sent_mutex); |
4143 | | |
4144 | 169k | if (pnode->IsPrivateBroadcastConn() && !IsOutboundMessageAllowedInPrivateBroadcast(msg.m_type)) { |
4145 | 0 | LogDebug(BCLog::PRIVBROADCAST, "Omitting send of message '%s', %s", msg.m_type, pnode->LogPeer()); |
4146 | 0 | return; |
4147 | 0 | } |
4148 | | |
4149 | 169k | if (!m_private_broadcast.m_outbound_tor_ok_at_least_once.load() && !pnode->IsInboundConn() && |
4150 | 169k | pnode->addr.IsTor() && msg.m_type == NetMsgType::VERACK) { |
4151 | | // If we are sending the peer VERACK that means we successfully sent |
4152 | | // and received another message to/from that peer (VERSION). |
4153 | 2 | m_private_broadcast.m_outbound_tor_ok_at_least_once.store(true); |
4154 | 2 | } |
4155 | | |
4156 | 169k | size_t nMessageSize = msg.data.size(); |
4157 | 169k | LogDebug(BCLog::NET, "sending %s (%d bytes) peer=%d\n", msg.m_type, nMessageSize, pnode->GetId()); |
4158 | 169k | if (m_capture_messages) { |
4159 | 20 | CaptureMessage(pnode->addr, msg.m_type, msg.data, /*is_incoming=*/false); |
4160 | 20 | } |
4161 | | |
4162 | 169k | TRACEPOINT(net, outbound_message, |
4163 | 169k | pnode->GetId(), |
4164 | 169k | pnode->m_addr_name.c_str(), |
4165 | 169k | pnode->ConnectionTypeAsString().c_str(), |
4166 | 169k | msg.m_type.c_str(), |
4167 | 169k | msg.data.size(), |
4168 | 169k | msg.data.data() |
4169 | 169k | ); |
4170 | | |
4171 | 169k | size_t nBytesSent = 0; |
4172 | 169k | { |
4173 | 169k | LOCK(pnode->cs_vSend); |
4174 | | // Check if the transport still has unsent bytes, and indicate to it that we're about to |
4175 | | // give it a message to send. |
4176 | 169k | const auto& [to_send, more, _msg_type] = |
4177 | 169k | pnode->m_transport->GetBytesToSend(/*have_next_message=*/true); |
4178 | 169k | const bool queue_was_empty{to_send.empty() && pnode->vSendMsg.empty()}; |
4179 | | |
4180 | | // Update memory usage of send buffer. |
4181 | 169k | pnode->m_send_memusage += msg.GetMemoryUsage(); |
4182 | 169k | if (pnode->m_send_memusage + pnode->m_transport->GetSendMemoryUsage() > nSendBufferMaxSize) pnode->fPauseSend = true; |
4183 | | // Move message to vSendMsg queue. |
4184 | 169k | pnode->vSendMsg.push_back(std::move(msg)); |
4185 | | |
4186 | | // If there was nothing to send before, and there is now (predicted by the "more" value |
4187 | | // returned by the GetBytesToSend call above), attempt "optimistic write": |
4188 | | // because the poll/select loop may pause for SELECT_TIMEOUT_MILLISECONDS before actually |
4189 | | // doing a send, try sending from the calling thread if the queue was empty before. |
4190 | | // With a V1Transport, more will always be true here, because adding a message always |
4191 | | // results in sendable bytes there, but with V2Transport this is not the case (it may |
4192 | | // still be in the handshake). |
4193 | 169k | if (queue_was_empty && more) { |
4194 | 169k | std::tie(nBytesSent, std::ignore) = SocketSendData(*pnode); |
4195 | 169k | } |
4196 | 169k | } |
4197 | 169k | if (nBytesSent) RecordBytesSent(nBytesSent); |
4198 | 169k | } |
4199 | | |
4200 | | bool CConnman::ForNode(NodeId id, std::function<bool(CNode* pnode)> func) |
4201 | 381 | { |
4202 | 381 | AssertLockNotHeld(m_nodes_mutex); |
4203 | | |
4204 | 381 | CNode* found = nullptr; |
4205 | 381 | LOCK(m_nodes_mutex); |
4206 | 608 | for (auto&& pnode : m_nodes) { |
4207 | 608 | if(pnode->GetId() == id) { |
4208 | 350 | found = pnode; |
4209 | 350 | break; |
4210 | 350 | } |
4211 | 608 | } |
4212 | 381 | return found != nullptr && NodeFullyConnected(found) && func(found); |
4213 | 381 | } |
4214 | | |
4215 | | CSipHasher CConnman::GetDeterministicRandomizer(uint64_t id) const |
4216 | 5.05k | { |
4217 | 5.05k | return CSipHasher(nSeed0, nSeed1).Write(id); |
4218 | 5.05k | } |
4219 | | |
4220 | | uint64_t CConnman::CalculateKeyedNetGroup(const CNetAddr& address) const |
4221 | 1.66k | { |
4222 | 1.66k | std::vector<unsigned char> vchNetGroup(m_netgroupman.GetGroup(address)); |
4223 | | |
4224 | 1.66k | return GetDeterministicRandomizer(RANDOMIZER_ID_NETGROUP).Write(vchNetGroup).Finalize(); |
4225 | 1.66k | } |
4226 | | |
4227 | | void CConnman::PerformReconnections() |
4228 | 5.61k | { |
4229 | 5.61k | AssertLockNotHeld(m_nodes_mutex); |
4230 | 5.61k | AssertLockNotHeld(m_reconnections_mutex); |
4231 | 5.61k | AssertLockNotHeld(m_unused_i2p_sessions_mutex); |
4232 | 5.62k | while (true) { |
4233 | | // Move first element of m_reconnections to todo (avoiding an allocation inside the lock). |
4234 | 5.62k | decltype(m_reconnections) todo; |
4235 | 5.62k | { |
4236 | 5.62k | LOCK(m_reconnections_mutex); |
4237 | 5.62k | if (m_reconnections.empty()) break; |
4238 | 10 | todo.splice(todo.end(), m_reconnections, m_reconnections.begin()); |
4239 | 10 | } |
4240 | | |
4241 | 0 | auto& item = *todo.begin(); |
4242 | 10 | OpenNetworkConnection(item.addr_connect, |
4243 | | // We only reconnect if the first attempt to connect succeeded at |
4244 | | // connection time, but then failed after the CNode object was |
4245 | | // created. Since we already know connecting is possible, do not |
4246 | | // count failure to reconnect. |
4247 | 10 | /*fCountFailure=*/false, |
4248 | 10 | std::move(item.grant), |
4249 | 10 | item.destination.empty() ? nullptr : item.destination.c_str(), |
4250 | 10 | item.conn_type, |
4251 | 10 | item.use_v2transport, |
4252 | 10 | item.proxy_override); |
4253 | 10 | } |
4254 | 5.61k | } |
4255 | | |
4256 | | void CConnman::ASMapHealthCheck() |
4257 | 7 | { |
4258 | 7 | const std::vector<CAddress> v4_addrs{GetAddressesUnsafe(/*max_addresses=*/0, /*max_pct=*/0, Network::NET_IPV4, /*filtered=*/false)}; |
4259 | 7 | const std::vector<CAddress> v6_addrs{GetAddressesUnsafe(/*max_addresses=*/0, /*max_pct=*/0, Network::NET_IPV6, /*filtered=*/false)}; |
4260 | 7 | std::vector<CNetAddr> clearnet_addrs; |
4261 | 7 | clearnet_addrs.reserve(v4_addrs.size() + v6_addrs.size()); |
4262 | 7 | std::transform(v4_addrs.begin(), v4_addrs.end(), std::back_inserter(clearnet_addrs), |
4263 | 8 | [](const CAddress& addr) { return static_cast<CNetAddr>(addr); }); |
4264 | 7 | std::transform(v6_addrs.begin(), v6_addrs.end(), std::back_inserter(clearnet_addrs), |
4265 | 7 | [](const CAddress& addr) { return static_cast<CNetAddr>(addr); }); |
4266 | 7 | m_netgroupman.ASMapHealthCheck(clearnet_addrs); |
4267 | 7 | } |
4268 | | |
4269 | | // Dump binary message to file, with timestamp. |
4270 | | static void CaptureMessageToFile(const CAddress& addr, |
4271 | | const std::string& msg_type, |
4272 | | std::span<const unsigned char> data, |
4273 | | bool is_incoming) |
4274 | 23 | { |
4275 | | // Note: This function captures the message at the time of processing, |
4276 | | // not at socket receive/send time. |
4277 | | // This ensures that the messages are always in order from an application |
4278 | | // layer (processing) perspective. |
4279 | 23 | auto now = GetTime<std::chrono::microseconds>(); |
4280 | | |
4281 | | // Windows folder names cannot include a colon |
4282 | 23 | std::string clean_addr = addr.ToStringAddrPort(); |
4283 | 23 | std::replace(clean_addr.begin(), clean_addr.end(), ':', '_'); |
4284 | | |
4285 | 23 | fs::path base_path = gArgs.GetDataDirNet() / "message_capture" / fs::u8path(clean_addr); |
4286 | 23 | fs::create_directories(base_path); |
4287 | | |
4288 | 23 | fs::path path = base_path / (is_incoming ? "msgs_recv.dat" : "msgs_sent.dat"); |
4289 | 23 | AutoFile f{fsbridge::fopen(path, "ab")}; |
4290 | | |
4291 | 23 | ser_writedata64(f, now.count()); |
4292 | 23 | f << std::span{msg_type}; |
4293 | 135 | for (auto i = msg_type.length(); i < CMessageHeader::MESSAGE_TYPE_SIZE; ++i) { |
4294 | 112 | f << uint8_t{'\0'}; |
4295 | 112 | } |
4296 | 23 | uint32_t size = data.size(); |
4297 | 23 | ser_writedata32(f, size); |
4298 | 23 | f << data; |
4299 | | |
4300 | 23 | if (f.fclose() != 0) { |
4301 | 0 | throw std::ios_base::failure( |
4302 | 0 | strprintf("Error closing %s after write, file contents are likely incomplete", fs::PathToString(path))); |
4303 | 0 | } |
4304 | 23 | } |
4305 | | |
4306 | | std::function<void(const CAddress& addr, |
4307 | | const std::string& msg_type, |
4308 | | std::span<const unsigned char> data, |
4309 | | bool is_incoming)> |
4310 | | CaptureMessage = CaptureMessageToFile; |