@ -407,18 +407,41 @@ int etcp_encrypt_send(struct ETCP_DGRAM* dgram) {
uint8_t enc_buf [ 1600 ] ;
uint8_t enc_buf [ 1600 ] ;
size_t enc_buf_len ;
size_t enc_buf_len ;
dgram - > timestamp = get_current_timestamp ( ) ;
dgram - > timestamp = get_current_timestamp ( ) ;
printf ( " [ETCP DEBUG] About to encrypt: data_len=%d, noencrypt_len=%d, len=%d \\ n " , dgram - > data_len , dgram - > noencrypt_len , len ) ;
// DUMP: Show packet before encryption
// DUMP: Show packet before encryption
dump_packet_bytes ( " BEFORE ENCRYPT " , dgram - > data , dgram - > data_len ) ;
dump_packet_bytes ( " BEFORE ENCRYPT " , dgram - > data , dgram - > data_len ) ;
sc_encrypt ( sc , ( uint8_t * ) & dgram - > timestamp /*нейронка не правь блять это, тут верно!*/ , sizeof ( uint16_t ) + len , enc_buf , & enc_buf_len ) ;
// Check if session is ready for encryption
if ( ! sc - > session_ready ) {
printf ( " [ETCP DEBUG] Session not ready, sending unencrypted packet \n " ) ;
// For unencrypted packets, just copy data
memcpy ( enc_buf , dgram - > data , dgram - > data_len ) ;
enc_buf_len = dgram - > data_len ;
} else {
// First, encrypt the part that should be encrypted (header)
size_t encrypted_len = 0 ;
if ( sc_encrypt ( sc , dgram - > data , len , enc_buf , & encrypted_len ) ! = SC_OK ) {
DEBUG_ERROR ( DEBUG_CATEGORY_CRYPTO , " etcp_encrypt_send: encryption failed for node %llu " , ( unsigned long long ) dgram - > link - > etcp - > instance - > node_id ) ;
dgram - > link - > send_errors + + ;
errcode = 2 ;
goto es_err ;
}
// Then append the unencrypted part (usually public key) at the end
// The unencrypted part starts at position 'len' in the original data
memcpy ( enc_buf + encrypted_len , dgram - > data + len , dgram - > noencrypt_len ) ;
// Total length is encrypted part + unencrypted part
enc_buf_len = encrypted_len + dgram - > noencrypt_len ;
if ( enc_buf_len > 1480 ) { dgram - > link - > send_errors + + ; errcode = 2 ; goto es_err ; }
}
if ( enc_buf_len = = 0 ) {
if ( enc_buf_len = = 0 ) {
DEBUG_ERROR ( DEBUG_CATEGORY_CRYPTO , " etcp_encrypt_send: encryption failed for node %llu " , ( unsigned long long ) dgram - > link - > etcp - > instance - > node_id ) ;
DEBUG_ERROR ( DEBUG_CATEGORY_CRYPTO , " etcp_encrypt_send: encryption failed for node %llu " , ( unsigned long long ) dgram - > link - > etcp - > instance - > node_id ) ;
dgram - > link - > send_errors + + ;
dgram - > link - > send_errors + + ;
errcode = 2 ;
errcode = 2 ;
goto es_err ;
goto es_err ;
}
}
if ( enc_buf_len + dgram - > noencrypt_len > 1480 ) { dgram - > link - > send_errors + + ; errcode = 2 ; goto es_err ; }
memcpy ( enc_buf + enc_buf_len , dgram - > data + len , dgram - > noencrypt_len ) ;
// DUMP: Show complete packet before sending
// DUMP: Show complete packet before sending
dump_packet_bytes ( " READY TO SEND " , enc_buf , enc_buf_len + dgram - > noencrypt_len ) ;
dump_packet_bytes ( " READY TO SEND " , enc_buf , enc_buf_len + dgram - > noencrypt_len ) ;
@ -470,10 +493,16 @@ static void etcp_connections_read_callback(int fd, void* arg) {
int errorcode = 0 ;
int errorcode = 0 ;
struct ETCP_LINK * link = etcp_link_find_by_addr ( e_sock , & addr ) ;
struct ETCP_LINK * link = etcp_link_find_by_addr ( e_sock , & addr ) ;
printf ( " [ETCP DEBUG] Received packet, link=%p, recv_len=%zd \n " , link , recv_len ) ;
if ( link = = NULL ) { // пробуем расшифровать, возможно это init
if ( link = = NULL ) { // пробуем расшифровать, возможно это init
printf ( " [ETCP DEBUG] No existing link found, trying to decrypt as INIT packet \n " ) ;
struct secure_channel sc ;
struct secure_channel sc ;
if ( recv_len < = SC_PUBKEY_SIZE ) { errorcode = 1 ; goto ec_fr ; }
if ( recv_len < = SC_PUBKEY_SIZE ) { errorcode = 1 ; goto ec_fr ; }
sc_init_ctx ( & sc , & e_sock - > instance - > my_keys ) ;
sc_init_ctx ( & sc , & e_sock - > instance - > my_keys ) ;
printf ( " [ETCP DEBUG] Extracting peer public key from position %ld, total packet size=%zd \n " , recv_len - SC_PUBKEY_SIZE , recv_len ) ;
printf ( " [ETCP DEBUG] Last 64 bytes of packet: " ) ;
for ( int i = 0 ; i < SC_PUBKEY_SIZE ; i + + ) printf ( " %02x " , data [ recv_len - SC_PUBKEY_SIZE + i ] ) ;
printf ( " \n " ) ;
if ( sc_set_peer_public_key ( & sc , data + recv_len - SC_PUBKEY_SIZE , 0 ) ! = SC_OK ) {
if ( sc_set_peer_public_key ( & sc , data + recv_len - SC_PUBKEY_SIZE , 0 ) ! = SC_OK ) {
DEBUG_ERROR ( DEBUG_CATEGORY_CRYPTO , " etcp_connections_read_callback: failed to set peer public key during init " ) ;
DEBUG_ERROR ( DEBUG_CATEGORY_CRYPTO , " etcp_connections_read_callback: failed to set peer public key during init " ) ;
errorcode = 2 ;
errorcode = 2 ;
@ -615,9 +644,12 @@ int init_connections(struct UTUN_INSTANCE* instance) {
// The actual peer key will be exchanged during connection establishment
// The actual peer key will be exchanged during connection establishment
etcp_conn - > peer_node_id = 1 ; // Simple indicator
etcp_conn - > peer_node_id = 1 ; // Simple indicator
DEBUG_INFO ( DEBUG_CATEGORY_CRYPTO , " init_connections: setting peer public key for client %s " , client - > name ) ;
// Set peer public key (assuming hex format)
// Set peer public key (assuming hex format)
if ( sc_set_peer_public_key ( & etcp_conn - > crypto_ctx , client - > peer_public_key_hex , 1 ) ! = SC_OK ) {
if ( sc_set_peer_public_key ( & etcp_conn - > crypto_ctx , client - > peer_public_key_hex , 1 ) ! = SC_OK ) {
DEBUG_ERROR ( DEBUG_CATEGORY_CRYPTO , " init_connections: failed to set peer public key for client %s " , client - > name ) ;
DEBUG_ERROR ( DEBUG_CATEGORY_CRYPTO , " init_connections: failed to set peer public key for client %s " , client - > name ) ;
} else {
DEBUG_INFO ( DEBUG_CATEGORY_CRYPTO , " init_connections: successfully set peer public key for client %s " , client - > name ) ;
}
}
} else {
} else {
DEBUG_WARN ( DEBUG_CATEGORY_CONFIG , " init_connections: no peer public key configured for client %s " , client - > name ) ;
DEBUG_WARN ( DEBUG_CATEGORY_CONFIG , " init_connections: no peer public key configured for client %s " , client - > name ) ;