Browse Source

crypto: migrate ECDH(secp256r1) to X25519, drop TinyCrypt

- SC_PUBKEY_SIZE: 64 -> 32 bytes, SC_PUBKEY_ENC_SIZE: 72 -> 40
- sc_set_peer_public_key uses EVP_PKEY_derive with X25519
- sc_generate_keypair via EVP_PKEY_keygen(EVP_PKEY_X25519)
- sc_compute_public_key_from_private via EVP_PKEY_new_raw_private_key
- sc_validate_key: check non-zero (X25519 has no invalid keys)
- sc_obfuscate_pubkey: XOR now 32 bytes
- Remove all TinyCrypt code (~860 lines), always use OpenSSL
- Remove TinyCrypt from build system, drop test_crypto/test_ecc_encrypt
- Update all test keys (128 hex -> 64 hex)
- Fix bbr_integration.c split-line pubkeys
feature/x25519-migration
Evgeny 4 months ago
parent
commit
73f707ef9b
  1. 12
      AGENTS.md
  2. 97
      src/Makefile.am
  3. 2
      src/config_parser.h
  4. 6
      src/config_updater.c
  5. 762
      src/secure_channel.c
  6. 18
      src/secure_channel.h
  7. 131
      tests/Makefile.am
  8. 12
      tests/bbr_integration/test_bbr_integration.c
  9. 6
      tests/tcp_proxy_full/client.conf
  10. 4
      tests/tcp_proxy_full/exit.conf
  11. 4
      tests/test_config_debug.c
  12. 10
      tests/test_etcp_100_packets.c
  13. 10
      tests/test_etcp_api.c
  14. 8
      tests/test_etcp_congestion.c
  15. 8
      tests/test_etcp_dummynet.c
  16. 10
      tests/test_etcp_ping.c
  17. 10
      tests/test_etcp_reconnect.c
  18. 12
      tests/test_etcp_reinit_inflight.c
  19. 10
      tests/test_etcp_router.c
  20. 10
      tests/test_etcp_simple_traffic.c
  21. 10
      tests/test_etcp_two_instances.c
  22. 10
      tests/test_icmp_proxy.c
  23. 10
      tests/test_ipv6_sockets.c
  24. 10
      tests/test_pkt_normalizer_etcp.c
  25. 10
      tests/test_tcp_proxy_remote.c
  26. 10
      tests/test_udp_proxy.c
  27. 14
      utun.md

12
AGENTS.md

@ -15,7 +15,7 @@ This file contains essential information for AI coding agents working in the uTu
**Repository:** uTun - Secure VPN tunnel with ETCP protocol
**Language:** C (C99)
**Build System:** GNU Autotools (autoconf/automake)
**Cryptography:** TinyCrypt + OpenSSL (AES-CCM, ECC, SHA256)
**Cryptography:** OpenSSL (AES-CCM, X25519, SHA256)
## Build Commands
@ -142,14 +142,14 @@ gcc -I../src -I../lib -I../tinycrypt/lib/include \
### Key Sizes
| Constant | Value | Description |
|----------|-------|-------------|
| `SC_PRIVKEY_SIZE` | 32 | ECC private key |
| `SC_PUBKEY_SIZE` | 64 | ECC public key |
| `SC_PRIVKEY_SIZE` | 32 | X25519 private key |
| `SC_PUBKEY_SIZE` | 32 | X25519 public key |
| `SC_NONCE_SIZE` | 13 | CCM nonce (exactly 13 bytes) |
| `SC_SESSION_KEY_SIZE` | 16 | AES-128 session key |
| `SC_TAG_SIZE` | 16 | CCM auth tag |
| `SC_CRC32_SIZE` | 4 | CRC32 checksum |
| `SC_PUBKEY_ENC_SALT_SIZE` | 8 | Salt for pubkey obfuscation |
| `SC_PUBKEY_ENC_SIZE` | 72 | Total pubkey+salt block sent unencrypted |
| `SC_PUBKEY_ENC_SIZE` | 40 | Total pubkey+salt block sent unencrypted |
### Using Secure Channel (secure_channel.h)
```c
@ -246,7 +246,7 @@ SOCKET=14, CONTROL=15, DUMP=16, TRAFFIC=17, DEBUG=18, GENERAL=19, NAT=20
- `route_node.c/h` - Route node (peer) management
**Crypto (src/)**
- `secure_channel.c/h` - AES-CCM encryption with ECC key exchange, pubkey obfuscation
- `secure_channel.c/h` - AES-CCM encryption with X25519 key exchange, pubkey obfuscation
- `crc32.c/h` - CRC32 checksums
**NAT (src/)**
@ -285,7 +285,7 @@ SOCKET=14, CONTROL=15, DUMP=16, TRAFFIC=17, DEBUG=18, GENERAL=19, NAT=20
- **LL_QUEUE:** Lock-free queue with auto-callback, hash index lookup, threshold waiter
- **Memory Pool:** Fast allocation for hot-path objects (packets, inflight entries, fragments)
- **ETCP:** TCP-like reliable protocol with encryption, multi-link, load balancing
- **Secure Channel:** AES-CCM + ECC key exchange, nonce-based encryption, pubkey obfuscation
- **Secure Channel:** AES-CCM + X25519 key exchange, nonce-based encryption, pubkey obfuscation
## Queue Usage Rules

97
src/Makefile.am

@ -51,109 +51,22 @@ utun_CORE_SOURCES = \
# Platform-specific TUN libs (Windows only)
utun_TUN_LIBS = @TUN_LIBS@
# TinyCrypt sources (only used without OpenSSL)
utun_TINYCRYPT_SOURCES = \
$(top_srcdir)/tinycrypt/lib/source/aes_encrypt.c \
$(top_srcdir)/tinycrypt/lib/source/aes_decrypt.c \
$(top_srcdir)/tinycrypt/lib/source/cbc_mode.c \
$(top_srcdir)/tinycrypt/lib/source/ccm_mode.c \
$(top_srcdir)/tinycrypt/lib/source/cmac_mode.c \
$(top_srcdir)/tinycrypt/lib/source/ctr_mode.c \
$(top_srcdir)/tinycrypt/lib/source/ecc.c \
$(top_srcdir)/tinycrypt/lib/source/ecc_dh.c \
$(top_srcdir)/tinycrypt/lib/source/ecc_dsa.c \
$(top_srcdir)/tinycrypt/lib/source/ecc_platform_specific.c \
$(top_srcdir)/tinycrypt/lib/source/hmac.c \
$(top_srcdir)/tinycrypt/lib/source/sha256.c \
$(top_srcdir)/tinycrypt/lib/source/utils.c
# Combine sources based on OpenSSL usage
if USE_OPENSSL
utun_SOURCES = $(utun_CORE_SOURCES) $(utun_TUN_SOURCES)
else
utun_SOURCES = $(utun_CORE_SOURCES) $(utun_TINYCRYPT_SOURCES) $(utun_TUN_SOURCES)
endif
# Include paths
utun_CORE_CFLAGS = \
utun_CFLAGS = \
-I$(top_srcdir)/lib \
-I$(top_srcdir)/src/uip \
-I$(top_srcdir)/tinycrypt/lib/include \
-I$(top_srcdir)/tinycrypt/lib/source \
-g \
$(DEBUG_FLAGS)
utun_CFLAGS = $(utun_CORE_CFLAGS)
# Libraries
utun_CORE_LDADD = \
utun_LDADD = \
$(top_builddir)/lib/libuasync.a \
-lpthread \
-lm
if USE_OPENSSL
utun_LDADD = $(utun_CORE_LDADD) -lcrypto $(utun_TUN_LIBS)
else
utun_LDADD = $(utun_CORE_LDADD) $(utun_TUN_LIBS)
endif
# TinyCrypt object files (for tests that need them)
TINYCRYPT_SRCDIR = $(top_srcdir)/tinycrypt/lib/source
TINYCRYPT_OBJS = \
utun-aes_encrypt.o \
utun-aes_decrypt.o \
utun-ccm_mode.o \
utun-cmac_mode.o \
utun-ctr_mode.o \
utun-ecc.o \
utun-ecc_dh.o \
utun-ecc_dsa.o \
utun-sha256.o \
utun-ecc_platform_specific.o \
utun-utils.o
# Rules to build TinyCrypt objects (for tests)
TINYCRYPT_CFLAGS = -g -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
utun-aes_encrypt.o: $(TINYCRYPT_SRCDIR)/aes_encrypt.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
utun-aes_decrypt.o: $(TINYCRYPT_SRCDIR)/aes_decrypt.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
utun-ccm_mode.o: $(TINYCRYPT_SRCDIR)/ccm_mode.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
utun-cmac_mode.o: $(TINYCRYPT_SRCDIR)/cmac_mode.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
utun-ctr_mode.o: $(TINYCRYPT_SRCDIR)/ctr_mode.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
utun-ecc.o: $(TINYCRYPT_SRCDIR)/ecc.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
utun-ecc_dh.o: $(TINYCRYPT_SRCDIR)/ecc_dh.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
utun-ecc_dsa.o: $(TINYCRYPT_SRCDIR)/ecc_dsa.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
utun-sha256.o: $(TINYCRYPT_SRCDIR)/sha256.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
# Force rebuild of ecc_platform_specific.o to pick up platform changes
utun-ecc_platform_specific.o: $(TINYCRYPT_SRCDIR)/ecc_platform_specific.c FORCE
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
FORCE:
utun-utils.o: $(TINYCRYPT_SRCDIR)/utils.c
$(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $<
# Build TinyCrypt objects for tests (convenience target)
tinycrypt-objects: $(TINYCRYPT_OBJS)
-lm \
-lcrypto \
$(utun_TUN_LIBS)
# Copy binary to project root after building
all-local: copy-to-root

2
src/config_parser.h

@ -79,7 +79,7 @@ struct CFG_CONTROL_ALLOW {
};
struct CFG_ALLOWED_KEY {
uint8_t key_bin[SC_PUBKEY_SIZE]; // public key in binary (64 bytes)
uint8_t key_bin[SC_PUBKEY_SIZE]; // public key in binary (32 bytes, X25519)
struct CFG_ALLOWED_KEY *next;
};

6
src/config_updater.c

@ -15,7 +15,7 @@
#include "../lib/mem.h"
#define PRIV_HEXKEY_LEN 65 // 32 bytes * 2 hex chars + null
#define PUB_HEXKEY_LEN 129 // 64 bytes * 2 hex chars + null
#define PUB_HEXKEY_LEN 65 // 32 bytes * 2 hex chars + null
#define HEXNODEID_LEN 17 // 8 bytes * 2 hex chars + null
#define MAX_LINE_LEN 1024
@ -41,8 +41,8 @@ static int is_valid_priv_key(const char *key) {
}
static int is_valid_pub_key(const char *key) {
if (!key || strlen(key) != 128) return 0;
for (int i = 0; i < 128; i++) {
if (!key || strlen(key) != 64) return 0;
for (int i = 0; i < 64; i++) {
if (!isxdigit((unsigned char)key[i])) return 0;
}
return 1;

762
src/secure_channel.c

@ -1,4 +1,4 @@
/* secure_channel.c - Secure Channel library implementation using TinyCrypt or OpenSSL */
/* secure_channel.c - Secure Channel library using X25519 + AES-128-CCM (OpenSSL) */
#ifdef HAVE_CONFIG_H
#include <config.h>
@ -19,27 +19,9 @@
#include "crc32.h"
#include "../lib/sha256.h"
// To switch between implementations, define USE_OPENSSL before including/compiling.
// If USE_OPENSSL is defined, use OpenSSL; otherwise, use TinyCrypt (original logic).
// The core logic (e.g., nonce building, CRC, session key derivation as memcpy, counters, etc.) remains unchanged.
#ifdef USE_OPENSSL
#include <openssl/bn.h>
#include <openssl/evp.h>
#include <openssl/ec.h>
#include <openssl/rand.h>
#include <openssl/sha.h>
#include <openssl/err.h>
#else
#include "../tinycrypt/lib/include/tinycrypt/ecc.h"
#include "../tinycrypt/lib/include/tinycrypt/ecc_dh.h"
#include "../tinycrypt/lib/include/tinycrypt/aes.h"
#include "../tinycrypt/lib/include/tinycrypt/ccm_mode.h"
#include "../tinycrypt/lib/include/tinycrypt/ctr_mode.h"
#include "../tinycrypt/lib/include/tinycrypt/constants.h"
#include "../tinycrypt/lib/include/tinycrypt/ecc_platform_specific.h"
#include "../tinycrypt/lib/include/tinycrypt/sha256.h"
#endif
#include "../lib/platform_compat.h"
static uint8_t sc_urandom_seed[8] = {0};
@ -52,10 +34,9 @@ static void sc_init_random_seed(void)
}
}
// Конвертация hex строки в бинарный формат (common)
// Конвертация hex строки в бинарный формат
static int hex_to_binary(const char *hex_str, uint8_t *binary, size_t binary_len) {
if (!hex_str || !binary || strlen(hex_str) != binary_len * 2) return -1;
for (size_t i = 0; i < binary_len; i++) {
unsigned int byte;
if (sscanf(hex_str + i * 2, "%2x", &byte) != 1) return -1;
@ -76,33 +57,21 @@ sc_status_t sc_init_ctx(sc_context_t *ctx, struct SC_MYKEYS *mykeys) {
// Common helper functions for input validation and CRC handling
static sc_status_t validate_encrypt_inputs(sc_context_t *ctx, const uint8_t *plaintext,
static sc_status_t validate_encrypt_inputs(sc_context_t *ctx, const uint8_t *plaintext,
const uint8_t *ciphertext, const size_t *ciphertext_len,
size_t plaintext_len) {
if (!ctx || !plaintext || !ciphertext || !ciphertext_len) {
return SC_ERR_INVALID_ARG;
}
if (!ctx->session_ready) {
return SC_ERR_NOT_INITIALIZED;
}
if (plaintext_len == 0) {
return SC_ERR_INVALID_ARG;
}
if (!ctx || !plaintext || !ciphertext || !ciphertext_len) return SC_ERR_INVALID_ARG;
if (!ctx->session_ready) return SC_ERR_NOT_INITIALIZED;
if (plaintext_len == 0) return SC_ERR_INVALID_ARG;
return SC_OK;
}
static sc_status_t validate_decrypt_inputs(sc_context_t *ctx, const uint8_t *ciphertext,
const uint8_t *plaintext, const size_t *plaintext_len,
size_t ciphertext_len) {
if (!ctx || !ciphertext || !plaintext || !plaintext_len) {
return SC_ERR_INVALID_ARG;
}
if (!ctx->session_ready) {
return SC_ERR_NOT_INITIALIZED;
}
if (ciphertext_len < SC_NONCE_SIZE + SC_TAG_SIZE + SC_CRC32_SIZE) {
return SC_ERR_INVALID_ARG;
}
if (!ctx || !ciphertext || !plaintext || !plaintext_len) return SC_ERR_INVALID_ARG;
if (!ctx->session_ready) return SC_ERR_NOT_INITIALIZED;
if (ciphertext_len < SC_NONCE_SIZE + SC_TAG_SIZE + SC_CRC32_SIZE) return SC_ERR_INVALID_ARG;
return SC_OK;
}
@ -123,9 +92,7 @@ static sc_status_t verify_and_strip_crc32(uint8_t *plaintext_with_crc, size_t to
((uint32_t)plaintext_with_crc[data_len + 2] << 16) |
((uint32_t)plaintext_with_crc[data_len + 3] << 24);
uint32_t calc_crc = crc32_calc(plaintext_with_crc, data_len);
if (received_crc != calc_crc) {
return SC_ERR_CRC_FAILED;
}
if (received_crc != calc_crc) return SC_ERR_CRC_FAILED;
memcpy(plaintext, plaintext_with_crc, data_len);
*plaintext_len = data_len;
return SC_OK;
@ -134,12 +101,10 @@ static sc_status_t verify_and_strip_crc32(uint8_t *plaintext_with_crc, size_t to
static void sc_derive_session_key(const uint8_t *shared_secret, uint8_t *session_key) {
SC_SHA256_CTX sha_ctx;
uint8_t hash[SC_HASH_SIZE];
sc_sha256_init(&sha_ctx);
sc_sha256_update(&sha_ctx, shared_secret, SC_SHARED_SECRET_SIZE);
sc_sha256_update(&sha_ctx, (const uint8_t *)"uTun-v3-session", 15);
sc_sha256_final(&sha_ctx, hash);
memcpy(session_key, hash, SC_SESSION_KEY_SIZE);
}
@ -160,94 +125,38 @@ static void sc_stream_derive_nonce(const uint8_t *session_key, uint32_t stream_i
memcpy(nonce_out, hash, SC_STREAM_NONCE_SIZE);
}
#ifdef USE_OPENSSL
// OpenSSL-specific implementations
static int sc_rng(uint8_t *dest, unsigned size) {
if (random_bytes(dest, size) != 0) {
return 0;
}
/* Mix in PID and microtime for additional entropy */
#ifdef _WIN32
DWORD pid = GetCurrentProcessId();
#else
pid_t pid = getpid();
#endif
struct timeval tv;
utun_gettimeofday(&tv, NULL);
for (unsigned i = 0; i < size; i++) {
dest[i] ^= ((pid >> (i % (sizeof(pid) * 8))) & 0xFF);
dest[i] ^= ((tv.tv_sec >> (i % (sizeof(tv.tv_sec) * 8))) & 0xFF);
dest[i] ^= ((tv.tv_usec >> (i % (sizeof(tv.tv_usec) * 8))) & 0xFF);
}
return 1;
}
// X25519: any non-zero 32-byte value is a valid public key
static int sc_validate_key(const uint8_t *public_key) {
EC_GROUP *group = EC_GROUP_new_by_curve_name(NID_X9_62_prime256v1);
if (!group) return -1;
EC_POINT *point = EC_POINT_new(group);
if (!point) {
EC_GROUP_free(group);
uint8_t zero[SC_PUBKEY_SIZE] = {0};
if (memcmp(public_key, zero, SC_PUBKEY_SIZE) == 0) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_validate_key: all-zero public key");
return -1;
}
BIGNUM *x = BN_bin2bn(public_key, 32, NULL);
BIGNUM *y = BN_bin2bn(public_key + 32, 32, NULL);
if (!x || !y || EC_POINT_set_affine_coordinates(group, point, x, y, NULL) != 1) {
BN_free(x);
BN_free(y);
EC_POINT_free(point);
EC_GROUP_free(group);
return -1;
}
int result = EC_POINT_is_on_curve(group, point, NULL);
BN_free(x);
BN_free(y);
EC_POINT_free(point);
EC_GROUP_free(group);
// To match TinyCrypt return convention in the provided code (0 valid, !=0 invalid)
return (result == 1) ? 0 : -1;
return 0;
}
sc_status_t sc_generate_keypair(struct SC_MYKEYS *pk) {
if (!pk) {
return SC_ERR_INVALID_ARG;
}
EC_GROUP *group = EC_GROUP_new_by_curve_name(NID_X9_62_prime256v1);
if (!group) return SC_ERR_CRYPTO;
EC_KEY *key = EC_KEY_new();
if (!key) {
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
if (EC_KEY_set_group(key, group) != 1) {
EC_KEY_free(key);
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
// Use custom RNG if needed, but OpenSSL RAND is fine; for consistency, seed if necessary
if (EC_KEY_generate_key(key) != 1) {
EC_KEY_free(key);
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
const BIGNUM *priv = EC_KEY_get0_private_key(key);
if (BN_bn2binpad(priv, pk->private_key, SC_PRIVKEY_SIZE) != SC_PRIVKEY_SIZE) {
EC_KEY_free(key);
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
const EC_POINT *pub_point = EC_KEY_get0_public_key(key);
uint8_t pub_buf[65];
if (EC_POINT_point2oct(group, pub_point, POINT_CONVERSION_UNCOMPRESSED, pub_buf, 65, NULL) != 65) {
EC_KEY_free(key);
EC_GROUP_free(group);
if (!pk) return SC_ERR_INVALID_ARG;
EVP_PKEY_CTX *ctx = EVP_PKEY_CTX_new_id(EVP_PKEY_X25519, NULL);
if (!ctx) return SC_ERR_CRYPTO;
if (EVP_PKEY_keygen_init(ctx) <= 0) { EVP_PKEY_CTX_free(ctx); return SC_ERR_CRYPTO; }
EVP_PKEY *pkey = NULL;
if (EVP_PKEY_keygen(ctx, &pkey) <= 0) { EVP_PKEY_CTX_free(ctx); return SC_ERR_CRYPTO; }
EVP_PKEY_CTX_free(ctx);
size_t priv_len = SC_PRIVKEY_SIZE, pub_len = SC_PUBKEY_SIZE;
if (EVP_PKEY_get_raw_private_key(pkey, pk->private_key, &priv_len) <= 0
|| priv_len != SC_PRIVKEY_SIZE
|| EVP_PKEY_get_raw_public_key(pkey, pk->public_key, &pub_len) <= 0
|| pub_len != SC_PUBKEY_SIZE) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: failed to extract raw keys");
EVP_PKEY_free(pkey);
return SC_ERR_CRYPTO;
}
memcpy(pk->public_key, pub_buf + 1, SC_PUBKEY_SIZE); // Skip 0x04 prefix
EC_KEY_free(key);
EC_GROUP_free(group);
EVP_PKEY_free(pkey);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: generated valid X25519 keypair");
return SC_OK;
}
@ -256,7 +165,7 @@ sc_status_t sc_init_local_keys(struct SC_MYKEYS *mykeys, const char *public_key,
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: invalid arguments");
return SC_ERR_INVALID_ARG;
}
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: public_key len=%zu, private_key len=%zu",
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: public_key len=%zu, private_key len=%zu",
strlen(public_key), strlen(private_key));
if (hex_to_binary(public_key, mykeys->public_key, SC_PUBKEY_SIZE)) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: failed to convert public key from hex");
@ -284,81 +193,46 @@ sc_status_t sc_set_peer_public_key(sc_context_t *ctx, const uint8_t *peer_public
} else {
memcpy(peer_public_key, peer_public_key_h, SC_PUBKEY_SIZE);
}
if (!ctx) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid ctx");
return SC_ERR_INVALID_ARG;
}
if (!ctx->initialized) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: ctx not initialized");
return SC_ERR_NOT_INITIALIZED;
}
if (sc_validate_key(peer_public_key) != 0) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid key");
return SC_ERR_INVALID_ARG;
}
if (!ctx->pk) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: no private key");
return SC_ERR_NOT_INITIALIZED;
}
EC_GROUP *group = EC_GROUP_new_by_curve_name(NID_X9_62_prime256v1);
if (!group) return SC_ERR_CRYPTO;
EC_KEY *my_key = EC_KEY_new();
if (!my_key) {
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
if (EC_KEY_set_group(my_key, group) != 1) {
EC_KEY_free(my_key);
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
BIGNUM *my_priv = BN_bin2bn(ctx->pk->private_key, SC_PRIVKEY_SIZE, NULL);
if (!my_priv || EC_KEY_set_private_key(my_key, my_priv) != 1) {
BN_free(my_priv);
EC_KEY_free(my_key);
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
EC_POINT *peer_point = EC_POINT_new(group);
if (!peer_point) {
BN_free(my_priv);
EC_KEY_free(my_key);
EC_GROUP_free(group);
if (!ctx) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid ctx"); return SC_ERR_INVALID_ARG; }
if (!ctx->initialized) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: ctx not initialized"); return SC_ERR_NOT_INITIALIZED; }
if (sc_validate_key(peer_public_key) != 0) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid key"); return SC_ERR_INVALID_ARG; }
if (!ctx->pk) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: no private key"); return SC_ERR_NOT_INITIALIZED; }
EVP_PKEY *my_pkey = EVP_PKEY_new_raw_private_key(EVP_PKEY_X25519, NULL, ctx->pk->private_key, SC_PRIVKEY_SIZE);
if (!my_pkey) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: EVP_PKEY_new_raw_private_key failed"); return SC_ERR_CRYPTO; }
EVP_PKEY *peer_pkey = EVP_PKEY_new_raw_public_key(EVP_PKEY_X25519, NULL, peer_public_key, SC_PUBKEY_SIZE);
if (!peer_pkey) { EVP_PKEY_free(my_pkey); DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: EVP_PKEY_new_raw_public_key failed"); return SC_ERR_CRYPTO; }
EVP_PKEY_CTX *derive_ctx = EVP_PKEY_CTX_new(my_pkey, NULL);
if (!derive_ctx) { EVP_PKEY_free(my_pkey); EVP_PKEY_free(peer_pkey); return SC_ERR_CRYPTO; }
if (EVP_PKEY_derive_init(derive_ctx) <= 0) {
EVP_PKEY_CTX_free(derive_ctx); EVP_PKEY_free(my_pkey); EVP_PKEY_free(peer_pkey);
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: EVP_PKEY_derive_init failed");
return SC_ERR_CRYPTO;
}
BIGNUM *x = BN_bin2bn(peer_public_key, 32, NULL);
BIGNUM *y = BN_bin2bn(peer_public_key + 32, 32, NULL);
if (!x || !y || EC_POINT_set_affine_coordinates(group, peer_point, x, y, NULL) != 1) {
BN_free(x);
BN_free(y);
BN_free(my_priv);
EC_POINT_free(peer_point);
EC_KEY_free(my_key);
EC_GROUP_free(group);
if (EVP_PKEY_derive_set_peer(derive_ctx, peer_pkey) <= 0) {
EVP_PKEY_CTX_free(derive_ctx); EVP_PKEY_free(my_pkey); EVP_PKEY_free(peer_pkey);
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: EVP_PKEY_derive_set_peer failed");
return SC_ERR_CRYPTO;
}
uint8_t shared_secret[SC_SHARED_SECRET_SIZE];
int len = ECDH_compute_key(shared_secret, SC_SHARED_SECRET_SIZE, peer_point, my_key, NULL);
if (len != SC_SHARED_SECRET_SIZE) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: shared secret error");
BN_free(x);
BN_free(y);
BN_free(my_priv);
EC_POINT_free(peer_point);
EC_KEY_free(my_key);
EC_GROUP_free(group);
size_t secret_len = SC_SHARED_SECRET_SIZE;
if (EVP_PKEY_derive(derive_ctx, shared_secret, &secret_len) <= 0 || secret_len != SC_SHARED_SECRET_SIZE) {
EVP_PKEY_CTX_free(derive_ctx); EVP_PKEY_free(my_pkey); EVP_PKEY_free(peer_pkey);
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: X25519 derive failed secret_len=%zu", secret_len);
return SC_ERR_CRYPTO;
}
sc_derive_session_key(shared_secret, ctx->session_key);
memcpy(ctx->peer_public_key, peer_public_key, SC_PUBKEY_SIZE);
ctx->peer_key_set = 1;
ctx->session_ready = 1;
BN_free(x);
BN_free(y);
BN_free(my_priv);
EC_POINT_free(peer_point);
EC_KEY_free(my_key);
EC_GROUP_free(group);
EVP_PKEY_CTX_free(derive_ctx);
EVP_PKEY_free(my_pkey);
EVP_PKEY_free(peer_pkey);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: X25519 key exchange complete");
return SC_OK;
}
@ -367,27 +241,17 @@ static void sc_build_nonce(uint64_t counter, uint8_t *nonce_out) {
uint8_t hash[32];
struct timeval tv;
uint8_t data[24];
if (!sc_urandom_initialized) {
sc_init_random_seed();
}
if (!sc_urandom_initialized) sc_init_random_seed();
utun_gettimeofday(&tv, NULL);
memcpy(data, sc_urandom_seed, 8);
data[8] = (counter >> 0) & 0xFF;
data[9] = (counter >> 8) & 0xFF;
data[10] = (counter >> 16) & 0xFF;
data[11] = (counter >> 24) & 0xFF;
data[12] = (counter >> 32) & 0xFF;
data[13] = (counter >> 40) & 0xFF;
data[14] = (counter >> 48) & 0xFF;
data[15] = (counter >> 56) & 0xFF;
data[16] = (tv.tv_sec >> 0) & 0xFF;
data[17] = (tv.tv_sec >> 8) & 0xFF;
data[18] = (tv.tv_sec >> 16) & 0xFF;
data[19] = (tv.tv_sec >> 24) & 0xFF;
data[20] = (tv.tv_usec >> 0) & 0xFF;
data[21] = (tv.tv_usec >> 8) & 0xFF;
data[22] = (tv.tv_usec >> 16) & 0xFF;
data[23] = (tv.tv_usec >> 24) & 0xFF;
data[8] = (counter >> 0) & 0xFF; data[9] = (counter >> 8) & 0xFF;
data[10] = (counter >> 16) & 0xFF; data[11] = (counter >> 24) & 0xFF;
data[12] = (counter >> 32) & 0xFF; data[13] = (counter >> 40) & 0xFF;
data[14] = (counter >> 48) & 0xFF; data[15] = (counter >> 56) & 0xFF;
data[16] = (tv.tv_sec >> 0) & 0xFF; data[17] = (tv.tv_sec >> 8) & 0xFF;
data[18] = (tv.tv_sec >> 16) & 0xFF; data[19] = (tv.tv_sec >> 24) & 0xFF;
data[20] = (tv.tv_usec >> 0) & 0xFF; data[21] = (tv.tv_usec >> 8) & 0xFF;
data[22] = (tv.tv_usec >> 16) & 0xFF; data[23] = (tv.tv_usec >> 24) & 0xFF;
SHA256_Init(&sha_ctx);
SHA256_Update(&sha_ctx, data, 24);
SHA256_Final(hash, &sha_ctx);
@ -405,39 +269,22 @@ sc_status_t sc_encrypt(sc_context_t *ctx, const uint8_t *plaintext, size_t plain
sc_build_nonce(ctx->tx_counter, nonce);
EVP_CIPHER_CTX *ectx = EVP_CIPHER_CTX_new();
if (!ectx) return SC_ERR_CRYPTO;
if (EVP_EncryptInit_ex(ectx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1) {
EVP_CIPHER_CTX_free(ectx);
return SC_ERR_CRYPTO;
}
if (EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_IVLEN, SC_NONCE_SIZE, NULL) != 1) {
EVP_CIPHER_CTX_free(ectx);
return SC_ERR_CRYPTO;
}
if (EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_TAG, SC_TAG_SIZE, NULL) != 1) {
EVP_CIPHER_CTX_free(ectx);
return SC_ERR_CRYPTO;
}
if (EVP_EncryptInit_ex(ectx, NULL, NULL, ctx->session_key, nonce) != 1) {
EVP_CIPHER_CTX_free(ectx);
return SC_ERR_CRYPTO;
if (EVP_EncryptInit_ex(ectx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1
|| EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_IVLEN, SC_NONCE_SIZE, NULL) != 1
|| EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_TAG, SC_TAG_SIZE, NULL) != 1
|| EVP_EncryptInit_ex(ectx, NULL, NULL, ctx->session_key, nonce) != 1) {
EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO;
}
int outlen;
uint8_t outbuf[total_plaintext_len];
if (EVP_EncryptUpdate(ectx, outbuf, &outlen, plaintext_with_crc, total_plaintext_len) != 1 ||
outlen != (int)total_plaintext_len) {
EVP_CIPHER_CTX_free(ectx);
return SC_ERR_CRYPTO;
if (EVP_EncryptUpdate(ectx, outbuf, &outlen, plaintext_with_crc, total_plaintext_len) != 1
|| outlen != (int)total_plaintext_len) {
EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO;
}
int tmp;
if (EVP_EncryptFinal_ex(ectx, outbuf + outlen, &tmp) != 1) {
EVP_CIPHER_CTX_free(ectx);
return SC_ERR_CRYPTO;
}
if (EVP_EncryptFinal_ex(ectx, outbuf + outlen, &tmp) != 1) { EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO; }
uint8_t tag[SC_TAG_SIZE];
if (EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_GET_TAG, SC_TAG_SIZE, tag) != 1) {
EVP_CIPHER_CTX_free(ectx);
return SC_ERR_CRYPTO;
}
if (EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_GET_TAG, SC_TAG_SIZE, tag) != 1) { EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO; }
memcpy(ciphertext, nonce, SC_NONCE_SIZE);
memcpy(ciphertext + SC_NONCE_SIZE, outbuf, total_plaintext_len);
memcpy(ciphertext + SC_NONCE_SIZE + total_plaintext_len, tag, SC_TAG_SIZE);
@ -459,79 +306,39 @@ sc_status_t sc_decrypt(sc_context_t *ctx, const uint8_t *ciphertext, size_t ciph
uint8_t plaintext_with_crc[total_plaintext_len];
EVP_CIPHER_CTX *dctx = EVP_CIPHER_CTX_new();
if (!dctx) return SC_ERR_CRYPTO;
if (EVP_DecryptInit_ex(dctx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1) {
EVP_CIPHER_CTX_free(dctx);
return SC_ERR_CRYPTO;
}
if (EVP_CIPHER_CTX_ctrl(dctx, EVP_CTRL_AEAD_SET_IVLEN, SC_NONCE_SIZE, NULL) != 1) {
EVP_CIPHER_CTX_free(dctx);
return SC_ERR_CRYPTO;
}
if (EVP_CIPHER_CTX_ctrl(dctx, EVP_CTRL_AEAD_SET_TAG, SC_TAG_SIZE, (void *)(encrypted_data + total_plaintext_len)) != 1) {
EVP_CIPHER_CTX_free(dctx);
return SC_ERR_CRYPTO;
}
if (EVP_DecryptInit_ex(dctx, NULL, NULL, ctx->session_key, nonce) != 1) {
EVP_CIPHER_CTX_free(dctx);
return SC_ERR_CRYPTO;
if (EVP_DecryptInit_ex(dctx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1
|| EVP_CIPHER_CTX_ctrl(dctx, EVP_CTRL_AEAD_SET_IVLEN, SC_NONCE_SIZE, NULL) != 1
|| EVP_CIPHER_CTX_ctrl(dctx, EVP_CTRL_AEAD_SET_TAG, SC_TAG_SIZE, (void *)(encrypted_data + total_plaintext_len)) != 1
|| EVP_DecryptInit_ex(dctx, NULL, NULL, ctx->session_key, nonce) != 1) {
EVP_CIPHER_CTX_free(dctx); return SC_ERR_CRYPTO;
}
int outlen;
if (EVP_DecryptUpdate(dctx, plaintext_with_crc, &outlen, encrypted_data, total_plaintext_len) != 1 ||
outlen != (int)total_plaintext_len) {
EVP_CIPHER_CTX_free(dctx);
return SC_ERR_AUTH_FAILED;
if (EVP_DecryptUpdate(dctx, plaintext_with_crc, &outlen, encrypted_data, total_plaintext_len) != 1
|| outlen != (int)total_plaintext_len) {
EVP_CIPHER_CTX_free(dctx); return SC_ERR_AUTH_FAILED;
}
int tmp;
if (EVP_DecryptFinal_ex(dctx, plaintext_with_crc + outlen, &tmp) != 1) {
EVP_CIPHER_CTX_free(dctx);
return SC_ERR_AUTH_FAILED;
}
if (EVP_DecryptFinal_ex(dctx, plaintext_with_crc + outlen, &tmp) != 1) { EVP_CIPHER_CTX_free(dctx); return SC_ERR_AUTH_FAILED; }
EVP_CIPHER_CTX_free(dctx);
sc_status_t result = verify_and_strip_crc32(plaintext_with_crc, total_plaintext_len, plaintext, plaintext_len);
if (result == SC_OK) {
ctx->rx_counter++;
}
if (result == SC_OK) ctx->rx_counter++;
return result;
}
sc_status_t sc_compute_public_key_from_private(const uint8_t *private_key, uint8_t *public_key) {
if (!private_key || !public_key) {
return SC_ERR_INVALID_ARG;
}
EC_GROUP *group = EC_GROUP_new_by_curve_name(NID_X9_62_prime256v1);
if (!group) return SC_ERR_CRYPTO;
BIGNUM *priv = BN_bin2bn(private_key, SC_PRIVKEY_SIZE, NULL);
if (!priv) {
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
EC_POINT *pub_point = EC_POINT_new(group);
if (!pub_point) {
BN_free(priv);
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
if (EC_POINT_mul(group, pub_point, priv, NULL, NULL, NULL) != 1) {
EC_POINT_free(pub_point);
BN_free(priv);
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
uint8_t pub_buf[65];
if (EC_POINT_point2oct(group, pub_point, POINT_CONVERSION_UNCOMPRESSED, pub_buf, 65, NULL) != 65) {
EC_POINT_free(pub_point);
BN_free(priv);
EC_GROUP_free(group);
return SC_ERR_CRYPTO;
}
memcpy(public_key, pub_buf + 1, SC_PUBKEY_SIZE);
EC_POINT_free(pub_point);
BN_free(priv);
EC_GROUP_free(group);
if (!private_key || !public_key) return SC_ERR_INVALID_ARG;
EVP_PKEY *pkey = EVP_PKEY_new_raw_private_key(EVP_PKEY_X25519, NULL, private_key, SC_PRIVKEY_SIZE);
if (!pkey) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_compute_public_key_from_private: EVP_PKEY_new_raw_private_key failed"); return SC_ERR_CRYPTO; }
size_t pub_len = SC_PUBKEY_SIZE;
if (EVP_PKEY_get_raw_public_key(pkey, public_key, &pub_len) <= 0 || pub_len != SC_PUBKEY_SIZE) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_compute_public_key_from_private: EVP_PKEY_get_raw_public_key failed");
EVP_PKEY_free(pkey); return SC_ERR_CRYPTO;
}
EVP_PKEY_free(pkey);
return SC_OK;
}
// --- OpenSSL streaming cipher (AES-128-CTR) ---
// --- Streaming cipher (AES-128-CTR) ---
sc_status_t sc_stream_init(sc_context_t *ctx, struct sc_stream_state *state, uint32_t stream_id) {
if (!ctx || !state) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: invalid args"); return SC_ERR_INVALID_ARG; }
@ -545,8 +352,7 @@ sc_status_t sc_stream_init(sc_context_t *ctx, struct sc_stream_state *state, uin
if (!ectx) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: EVP_CIPHER_CTX_new failed"); return SC_ERR_CRYPTO; }
if (EVP_EncryptInit_ex(ectx, EVP_aes_128_ctr(), NULL, ctx->session_key, iv) != 1) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: EVP_EncryptInit_ex failed");
EVP_CIPHER_CTX_free(ectx);
return SC_ERR_CRYPTO;
EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO;
}
state->ectx = ectx;
state->initialized = 1;
@ -575,385 +381,31 @@ void sc_stream_cleanup(struct sc_stream_state *state) {
state->initialized = 0;
}
#else
// Original TinyCrypt implementations (unchanged logic)
static const struct uECC_Curve_t *curve = NULL;
static int sc_rng(uint8_t *dest, unsigned size)
{
if (random_bytes(dest, size) != 0) {
return 0;
}
/* Mix in PID and microtime for additional entropy */
#ifdef _WIN32
DWORD pid = GetCurrentProcessId();
#else
pid_t pid = getpid();
#endif
struct timeval tv;
utun_gettimeofday(&tv, NULL);
for (unsigned i = 0; i < size; i++) {
dest[i] ^= ((pid >> (i % (sizeof(pid) * 8))) & 0xFF);
dest[i] ^= ((tv.tv_sec >> (i % (sizeof(tv.tv_sec) * 8))) & 0xFF);
dest[i] ^= ((tv.tv_usec >> (i % (sizeof(tv.tv_usec) * 8))) & 0xFF);
}
return 1;
}
static int sc_validate_key(const uint8_t *public_key)
{
if (!curve) {
curve = uECC_secp256r1();
}
int result = uECC_valid_public_key(public_key, curve);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_validate_key: uECC_valid_public_key returned %d", result);
return result;
}
sc_status_t sc_generate_keypair(struct SC_MYKEYS *pk)
{
if (!pk) {
return SC_ERR_INVALID_ARG;
}
if (!curve) {
curve = uECC_secp256r1();
}
/* Set custom RNG function */
uECC_set_rng(sc_rng);
/* Try to generate valid key pair (max 10 attempts) */
for (int attempt = 0; attempt < 10; attempt++) {
if (!uECC_make_key(pk->public_key, pk->private_key, curve)) {
continue;
}
/* Validate generated public key immediately */
if (sc_validate_key(pk->public_key) == 0) {
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: generated valid keypair on attempt %d", attempt + 1);
return SC_OK;
}
DEBUG_WARN(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: generated invalid key on attempt %d, retrying...", attempt + 1);
}
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: failed to generate valid keypair after 10 attempts");
return SC_ERR_CRYPTO;
}
sc_status_t sc_init_local_keys(struct SC_MYKEYS *mykeys, const char *public_key, const char *private_key) {
if (!mykeys || !public_key || !private_key) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: invalid arguments");
return SC_ERR_INVALID_ARG;
}
if (!curve) {
curve = uECC_secp256r1();
}
/* Set RNG function for TinyCrypt - must be done before any ECC operations */
uECC_set_rng(sc_rng);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: public_key len=%zu, private_key len=%zu",
strlen(public_key), strlen(private_key));
/* Convert hex to binary first */
if (hex_to_binary(public_key, mykeys->public_key, SC_PUBKEY_SIZE)) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: failed to convert public key from hex");
return SC_ERR_INVALID_ARG;
}
if (hex_to_binary(private_key, mykeys->private_key, SC_PRIVKEY_SIZE)) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: failed to convert private key from hex");
return SC_ERR_INVALID_ARG;
}
/* Validate the converted binary public key */
if (sc_validate_key(mykeys->public_key) != 0) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: public key validation failed");
return SC_ERR_INVALID_ARG;
}
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: keys initialized successfully");
return SC_OK;
}
sc_status_t sc_set_peer_public_key(sc_context_t *ctx, const uint8_t *peer_public_key_h, int mode) {
uint8_t shared_secret[SC_SHARED_SECRET_SIZE];
uint8_t peer_public_key[SC_PUBKEY_SIZE];
if (mode) {
if (hex_to_binary((const char*)peer_public_key_h, peer_public_key, SC_PUBKEY_SIZE)) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid hex key format");
return SC_ERR_INVALID_ARG;
}
}
else memcpy(peer_public_key, peer_public_key_h, SC_PUBKEY_SIZE);
if (!ctx) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid ctx");
return SC_ERR_INVALID_ARG;
}
if (!ctx->initialized) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: ctx not initialized");
return SC_ERR_NOT_INITIALIZED;
}
if (!curve) {
curve = uECC_secp256r1();
}
/* Validate peer public key */
if (sc_validate_key(peer_public_key) != 0) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid key");
return SC_ERR_INVALID_ARG;
}
/* Compute shared secret using ECDH */
if (!ctx->pk) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: no private key");
return SC_ERR_NOT_INITIALIZED;
}
if (!uECC_shared_secret(peer_public_key, ctx->pk->private_key,
shared_secret, curve)) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: shared secret error");
return SC_ERR_CRYPTO;
}
sc_derive_session_key(shared_secret, ctx->session_key);
/* Store peer public key */
memcpy(ctx->peer_public_key, peer_public_key, SC_PUBKEY_SIZE);
ctx->peer_key_set = 1;
ctx->session_ready = 1;
return SC_OK;
}
static void sc_build_nonce(uint64_t counter, uint8_t *nonce_out)
{
struct tc_sha256_state_struct sha_ctx;
uint8_t hash[32];
struct timeval tv;
uint8_t data[8 + 8 + 8];
if (!sc_urandom_initialized) {
sc_init_random_seed();
}
utun_gettimeofday(&tv, NULL);
memcpy(data, sc_urandom_seed, 8);
data[8] = (counter >> 0) & 0xFF;
data[9] = (counter >> 8) & 0xFF;
data[10] = (counter >> 16) & 0xFF;
data[11] = (counter >> 24) & 0xFF;
data[12] = (counter >> 32) & 0xFF;
data[13] = (counter >> 40) & 0xFF;
data[14] = (counter >> 48) & 0xFF;
data[15] = (counter >> 56) & 0xFF;
data[16] = (tv.tv_sec >> 0) & 0xFF;
data[17] = (tv.tv_sec >> 8) & 0xFF;
data[18] = (tv.tv_sec >> 16) & 0xFF;
data[19] = (tv.tv_sec >> 24) & 0xFF;
data[20] = (tv.tv_usec >> 0) & 0xFF;
data[21] = (tv.tv_usec >> 8) & 0xFF;
data[22] = (tv.tv_usec >> 16) & 0xFF;
data[23] = (tv.tv_usec >> 24) & 0xFF;
tc_sha256_init(&sha_ctx);
tc_sha256_update(&sha_ctx, data, 24);
tc_sha256_final(hash, &sha_ctx);
memcpy(nonce_out, hash, SC_NONCE_SIZE);
}
sc_status_t sc_encrypt(sc_context_t *ctx, const uint8_t *plaintext, size_t plaintext_len, uint8_t *ciphertext, size_t *ciphertext_len) {
sc_status_t status = validate_encrypt_inputs(ctx, plaintext, ciphertext, ciphertext_len, plaintext_len);
if (status != SC_OK) return status;
uint8_t nonce[SC_NONCE_SIZE];
uint8_t plaintext_with_crc[plaintext_len + SC_CRC32_SIZE];
size_t total_plaintext_len = plaintext_len + SC_CRC32_SIZE;
uint8_t combined_output[total_plaintext_len + SC_TAG_SIZE];
struct tc_aes_key_sched_struct sched;
struct tc_ccm_mode_struct ccm_state;
/* Добавляем CRC32 к данным */
append_crc32(plaintext, plaintext_len, plaintext_with_crc);
/* Генерируем nonce с таймером */
sc_build_nonce(ctx->tx_counter, nonce);
/* Initialize AES key schedule */
if (tc_aes128_set_encrypt_key(&sched, ctx->session_key) != TC_CRYPTO_SUCCESS) {
return SC_ERR_CRYPTO;
}
/* Configure CCM mode */
if (tc_ccm_config(&ccm_state, &sched, nonce, SC_NONCE_SIZE, SC_TAG_SIZE) != TC_CRYPTO_SUCCESS) {
return SC_ERR_CRYPTO;
}
/* Encrypt and generate tag */
if (tc_ccm_generation_encryption(combined_output, sizeof(combined_output),
NULL, 0, /* no associated data */
plaintext_with_crc, total_plaintext_len,
&ccm_state) != TC_CRYPTO_SUCCESS) {
return SC_ERR_CRYPTO;
}
/* Copy nonce + ciphertext + tag to output buffer */
memcpy(ciphertext, nonce, SC_NONCE_SIZE);
memcpy(ciphertext + SC_NONCE_SIZE, combined_output, total_plaintext_len + SC_TAG_SIZE);
*ciphertext_len = SC_NONCE_SIZE + total_plaintext_len + SC_TAG_SIZE;
ctx->tx_counter++;
return SC_OK;
}
sc_status_t sc_decrypt(sc_context_t *ctx,
const uint8_t *ciphertext,
size_t ciphertext_len,
uint8_t *plaintext,
size_t *plaintext_len)
{
sc_status_t status = validate_decrypt_inputs(ctx, ciphertext, plaintext, plaintext_len, ciphertext_len);
if (status != SC_OK) return status;
uint8_t nonce[SC_NONCE_SIZE];
struct tc_aes_key_sched_struct sched;
struct tc_ccm_mode_struct ccm_state;
size_t total_plaintext_len = ciphertext_len - SC_NONCE_SIZE - SC_TAG_SIZE;
uint8_t plaintext_with_crc[total_plaintext_len];
/* Извлекаем nonce из начала ciphertext */
memcpy(nonce, ciphertext, SC_NONCE_SIZE);
/* Ciphertext для расшифровки начинается после nonce */
const uint8_t *encrypted_data = ciphertext + SC_NONCE_SIZE;
size_t encrypted_len = ciphertext_len - SC_NONCE_SIZE;
/* Initialize AES key schedule */
if (tc_aes128_set_encrypt_key(&sched, ctx->session_key) != TC_CRYPTO_SUCCESS) {
return SC_ERR_CRYPTO;
}
/* Configure CCM mode с извлечённым nonce */
if (tc_ccm_config(&ccm_state, &sched, nonce, SC_NONCE_SIZE, SC_TAG_SIZE) != TC_CRYPTO_SUCCESS) {
return SC_ERR_CRYPTO;
}
/* Decrypt and verify tag */
if (tc_ccm_decryption_verification(plaintext_with_crc, total_plaintext_len,
NULL, 0, /* no associated data */
encrypted_data, encrypted_len,
&ccm_state) != TC_CRYPTO_SUCCESS) {
return SC_ERR_AUTH_FAILED;
}
/* Проверяем CRC32 используя helper-функцию */
sc_status_t result = verify_and_strip_crc32(plaintext_with_crc, total_plaintext_len, plaintext, plaintext_len);
if (result == SC_OK) {
ctx->rx_counter++;
}
return result;
}
sc_status_t sc_compute_public_key_from_private(const uint8_t *private_key, uint8_t *public_key) {
if (!private_key || !public_key) {
return SC_ERR_INVALID_ARG;
}
if (!curve) {
curve = uECC_secp256r1();
}
if (!uECC_compute_public_key(private_key, public_key, curve)) {
return SC_ERR_CRYPTO;
}
return SC_OK;
}
// --- TinyCrypt streaming cipher (AES-128-CTR) ---
sc_status_t sc_stream_init(sc_context_t *ctx, struct sc_stream_state *state, uint32_t stream_id) {
if (!ctx || !state) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: invalid args"); return SC_ERR_INVALID_ARG; }
if (!ctx->session_ready) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: session not ready"); return SC_ERR_NOT_INITIALIZED; }
uint8_t nonce[SC_STREAM_NONCE_SIZE];
sc_stream_derive_nonce(ctx->session_key, stream_id, nonce);
memcpy(state->ctr_block, nonce, SC_STREAM_NONCE_SIZE);
memset(state->ctr_block + SC_STREAM_NONCE_SIZE, 0, 4);
if (tc_aes128_set_encrypt_key((TCAesKeySched_t)state->sched_buf, ctx->session_key) != TC_CRYPTO_SUCCESS) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: tc_aes128_set_encrypt_key failed");
return SC_ERR_CRYPTO;
}
state->initialized = 1;
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: stream_id=%u nonce=%02x%02x%02x%02x...",
stream_id, nonce[0], nonce[1], nonce[2], nonce[3]);
return SC_OK;
}
sc_status_t sc_stream_xor(struct sc_stream_state *state, uint8_t *data, size_t data_len) {
if (data_len == 0) return SC_OK;
if (!state || !data) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_xor: invalid args"); return SC_ERR_INVALID_ARG; }
if (!state->initialized) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_xor: not initialized"); return SC_ERR_NOT_INITIALIZED; }
if (tc_ctr_mode(data, (unsigned int)data_len, data, (unsigned int)data_len,
state->ctr_block, (TCAesKeySched_t)state->sched_buf) != TC_CRYPTO_SUCCESS) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_xor: tc_ctr_mode failed len=%zu", data_len);
return SC_ERR_CRYPTO;
}
return SC_OK;
}
void sc_stream_cleanup(struct sc_stream_state *state) {
if (!state) return;
memset(state->sched_buf, 0, sizeof(state->sched_buf));
memset(state->ctr_block, 0, sizeof(state->ctr_block));
state->initialized = 0;
}
#endif
// --- Common crypto utilities ---
sc_status_t sc_sha_transcode(const uint8_t *key, size_t key_len, uint8_t *data, size_t data_len) {
if (!key || !data || key_len == 0 || data_len == 0) {
return SC_ERR_INVALID_ARG;
}
if (!key || !data || key_len == 0 || data_len == 0) return SC_ERR_INVALID_ARG;
uint8_t sha_hash[SC_HASH_SIZE];
SC_SHA256_CTX ctx;
sc_sha256_init(&ctx);
sc_sha256_update(&ctx, key, key_len);
sc_sha256_final(&ctx, sha_hash);
for (size_t i = 0; i < data_len; i++) {
data[i] ^= sha_hash[i % SC_HASH_SIZE];
}
for (size_t i = 0; i < data_len; i++) data[i] ^= sha_hash[i % SC_HASH_SIZE];
return SC_OK;
}
sc_status_t sc_obfuscate_pubkey(const uint8_t *salt, const uint8_t *peer_pubkey, const uint8_t *pubkey, uint8_t *output) {
if (!salt || !peer_pubkey || !pubkey || !output) return SC_ERR_INVALID_ARG;
uint8_t sha[SC_HASH_SIZE*2];
SC_SHA256_CTX ctx;
sc_sha256_init(&ctx);
sc_sha256_update(&ctx, salt, SC_PUBKEY_ENC_SALT_SIZE);
sc_sha256_update(&ctx, peer_pubkey, SC_PUBKEY_SIZE);
sc_sha256_final(&ctx, sha);
sc_sha256_init(&ctx);
sc_sha256_update(&ctx, peer_pubkey, SC_PUBKEY_SIZE);
sc_sha256_update(&ctx, salt, SC_PUBKEY_ENC_SALT_SIZE);
sc_sha256_final(&ctx, sha+SC_HASH_SIZE);
for (size_t i = 0; i < SC_PUBKEY_SIZE; i++) output[i] = pubkey[i] ^ sha[i];
return SC_OK;
}

18
src/secure_channel.h

@ -7,7 +7,7 @@
// Размеры ключей
#define SC_PRIVKEY_SIZE 32
#define SC_PUBKEY_SIZE 64
#define SC_PUBKEY_SIZE 32
#define SC_HASH_SIZE 32
#define SC_NONCE_SIZE 13 // CCM requires exactly 13 bytes
#define SC_SHARED_SECRET_SIZE SC_HASH_SIZE
@ -15,7 +15,7 @@
#define SC_TAG_SIZE 16
#define SC_CRC32_SIZE 4
// Шифрование pubkey при передаче (salt + double SHA256 XOR)
// Обфускация pubkey при передаче (salt + double SHA256 XOR)
#define SC_PUBKEY_ENC_SALT_SIZE 8
#define SC_PUBKEY_ENC_SIZE (SC_PUBKEY_SIZE + SC_PUBKEY_ENC_SALT_SIZE)
@ -43,14 +43,10 @@ struct SC_MYKEYS {
// Контекст защищенного канала
struct secure_channel {
struct SC_MYKEYS* pk;
/* Ключи пира (после key exchange) */
/* Ключ пира (после key exchange) */
uint8_t peer_public_key[SC_PUBKEY_SIZE];
uint8_t session_key[SC_SESSION_KEY_SIZE]; /* Derived session key */
/* Nonces для отправки и приема (теперь генерируются динамически, не используются counters для nonce) */
uint8_t send_nonce[SC_NONCE_SIZE];
uint8_t recv_nonce[SC_NONCE_SIZE];
uint8_t initialized;
uint8_t peer_key_set;
uint8_t session_ready;
@ -78,15 +74,9 @@ sc_status_t sc_obfuscate_pubkey(const uint8_t *salt, const uint8_t *peer_pubkey,
// --- Streaming cipher (AES-128-CTR, confidentiality only) ---
#define SC_STREAM_NONCE_SIZE 12
#define SC_STREAM_AES_SCHED_SIZE 176 // sizeof(struct tc_aes_key_sched_struct) = Nb*(Nr+1)*4 = 4*11*4
struct sc_stream_state {
#ifdef USE_OPENSSL
void *ectx; // EVP_CIPHER_CTX* (opaque, created/destroyed in .c)
#else
uint8_t sched_buf[SC_STREAM_AES_SCHED_SIZE]; // AES-128 key schedule
uint8_t ctr_block[16]; // nonce(12) + counter(4, BE)
#endif
void *ectx; // EVP_CIPHER_CTX*
uint8_t initialized;
};

131
tests/Makefile.am

@ -49,36 +49,11 @@ check_PROGRAMS = \
bench_timeout_heap \
bench_uasync_timeouts
# Долгие тесты: запускаются только вручную, не включаются в make check
# test_etcp_congestion — DISABLED: старый congestion control удалён, ждёт новых BBR тестов
# test_tcp_proxy_remote — 2-node TCP через etcp, требует fix tcp_proxy_client singleton
# Долгие тесты: запускаются только вручную
noinst_PROGRAMS =
# test_crypto and test_ecc_encrypt only needed for TinyCrypt (not when using OpenSSL)
if USE_OPENSSL
else
check_PROGRAMS += test_crypto test_ecc_encrypt
endif
# Basic includes
AM_CFLAGS = -g -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
# TinyCrypt source files
TINYCRYPT_SRCDIR = $(top_srcdir)/tinycrypt/lib/source
# TinyCrypt object files (built by src/Makefile.am with utun- prefix)
TINYCRYPT_OBJS = \
$(top_builddir)/src/utun-aes_encrypt.o \
$(top_builddir)/src/utun-aes_decrypt.o \
$(top_builddir)/src/utun-ccm_mode.o \
$(top_builddir)/src/utun-cmac_mode.o \
$(top_builddir)/src/utun-ctr_mode.o \
$(top_builddir)/src/utun-ecc.o \
$(top_builddir)/src/utun-ecc_dh.o \
$(top_builddir)/src/utun-ecc_dsa.o \
$(top_builddir)/src/utun-sha256.o \
$(top_builddir)/src/utun-ecc_platform_specific.o \
$(top_builddir)/src/utun-utils.o
AM_CFLAGS = -g -I$(top_srcdir)/src -I$(top_srcdir)/lib
# Secure channel and CRC objects (built in src directory)
SECURE_CHANNEL_OBJS = $(top_builddir)/src/utun-secure_channel.o $(top_builddir)/src/utun-crc32.o
@ -139,41 +114,18 @@ ETCP_FULL_OBJS = \
$(STCP_LINK_OBJS) \
$(ETCP_CORE_OBJS)
# Windows-specific libraries (advapi32 for CryptGenRandom, ws2_32 for sockets)
# Windows-specific libraries
if OS_WINDOWS
WIN_LIBS = -lws2_32 -liphlpapi -ladvapi32 -lbcrypt -ldbghelp
else
WIN_LIBS =
endif
# Common libraries (libuasync.a from lib directory)
# Common libraries
COMMON_LIBS = $(top_builddir)/lib/libuasync.a -lpthread $(WIN_LIBS)
# Crypto libraries (conditional)
if USE_OPENSSL
# Crypto always uses OpenSSL
CRYPTO_LIBS = -lcrypto
TINYCRYPT_BUILT =
else
CRYPTO_LIBS = $(TINYCRYPT_OBJS)
TINYCRYPT_BUILT = tinycrypt-objects
endif
# Tests run via check-local (with timing and colored output), not TESTS
# Build TinyCrypt objects as a group (only when not using OpenSSL)
if USE_OPENSSL
else
tinycrypt-objects: $(TINYCRYPT_OBJS)
endif
# Ensure TinyCrypt objects are built before tests that need them
if USE_OPENSSL
BUILT_SOURCES =
else
BUILT_SOURCES = $(TINYCRYPT_OBJS)
$(TINYCRYPT_OBJS): $(top_builddir)/src/utun
@$(MAKE) -C $(top_builddir)/src tinycrypt-objects
endif
# Test definitions
test_etcp_bbr_SOURCES = test_etcp_bbr.c
@ -181,54 +133,37 @@ test_etcp_bbr_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_etcp_bbr_LDADD = $(top_builddir)/src/utun-etcp_bbr.o $(COMMON_LIBS)
test_etcp_crypto_SOURCES = test_etcp_crypto.c
test_etcp_crypto_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_etcp_crypto_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_etcp_crypto_LDADD = $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_stream_cipher_SOURCES = test_stream_cipher.c
test_stream_cipher_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_stream_cipher_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_stream_cipher_LDADD = $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_transport_SOURCES = test_stcp_link.c
test_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_transport_LDADD = $(STCP_LINK_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_etcp_transport_SOURCES = test_etcp_stcp.c
test_etcp_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_etcp_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_etcp_transport_LDADD = $(STCP_LINK_OBJS) $(top_builddir)/src/utun-etcp_api.o $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_stcp_SOURCES = test_stcp.c
test_stcp_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_stcp_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_stcp_LDADD = $(top_builddir)/src/utun-stcp.o $(top_builddir)/src/utun-stcp_server.o $(top_builddir)/src/utun-stcp_client.o $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
if USE_OPENSSL
else
test_crypto_SOURCES = test_crypto.c
test_crypto_CFLAGS = -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source -I$(top_srcdir)/lib
test_crypto_LDADD = $(TINYCRYPT_OBJS) $(COMMON_LIBS)
endif
test_etcp_two_instances_SOURCES = test_etcp_two_instances.c
test_etcp_two_instances_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_etcp_two_instances_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_etcp_two_instances_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_etcp_simple_traffic_SOURCES = test_etcp_simple_traffic.c
test_etcp_simple_traffic_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_etcp_simple_traffic_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_etcp_simple_traffic_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_ipv6_sockets_SOURCES = test_ipv6_sockets.c
test_ipv6_sockets_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_ipv6_sockets_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_ipv6_sockets_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
# test_etcp_congestion — отключён (старый congestion control удалён)
#test_etcp_congestion_SOURCES = test_etcp_congestion.c
#test_etcp_congestion_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
#test_etcp_congestion_LDADD = $(top_builddir)/src/utun-dummynet.o $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
# test_etcp_reinit_inflight — отключён (старый congestion control удалён)
#test_etcp_reinit_inflight_SOURCES = test_etcp_reinit_inflight.c
#test_etcp_reinit_inflight_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
#test_etcp_reinit_inflight_LDADD = $(top_builddir)/src/utun-dummynet.o $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_tcp_proxy_client_SOURCES = test_tcp_proxy_client.c
test_tcp_proxy_client_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
@ -271,35 +206,35 @@ test_route6_lib_LDADD = $(top_builddir)/src/utun-route6_lib.o \
test_etcp_minimal_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_etcp_100_packets_SOURCES = test_etcp_100_packets.c
test_etcp_100_packets_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_etcp_100_packets_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_etcp_100_packets_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_etcp_reconnect_SOURCES = test_etcp_reconnect.c
test_etcp_reconnect_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_etcp_reconnect_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_etcp_reconnect_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_pkt_normalizer_etcp_SOURCES = test_pkt_normalizer_etcp.c
test_pkt_normalizer_etcp_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_pkt_normalizer_etcp_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_pkt_normalizer_etcp_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_pkt_normalizer_standalone_SOURCES = test_pkt_normalizer_standalone.c
test_pkt_normalizer_standalone_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_pkt_normalizer_standalone_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_pkt_normalizer_standalone_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_etcp_api_SOURCES = test_etcp_api.c
test_etcp_api_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_etcp_api_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_etcp_api_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_etcp_ping_SOURCES = test_etcp_ping.c
test_etcp_ping_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_etcp_ping_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_etcp_ping_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_route_ping_SOURCES = test_route_ping.c
test_route_ping_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_route_ping_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_route_ping_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_nat_detection_SOURCES = test_nat_detection.c
test_nat_detection_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_nat_detection_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_nat_detection_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_nat_engine_SOURCES = test_nat_engine.c
@ -307,7 +242,7 @@ test_nat_engine_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_nat_engine_LDADD = $(top_builddir)/src/utun-eim_nat.o $(top_builddir)/src/utun-config_parser.o $(COMMON_LIBS)
test_nat_transport_SOURCES = test_nat_transport.c
test_nat_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_nat_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_nat_transport_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
test_nat_stress_SOURCES = test_nat_stress.c
@ -322,13 +257,6 @@ test_serialize_SOURCES = test_serialize.c
test_serialize_CFLAGS = -I$(top_srcdir)/lib
test_serialize_LDADD = $(COMMON_LIBS)
if USE_OPENSSL
else
test_ecc_encrypt_SOURCES = test_ecc_encrypt.c
test_ecc_encrypt_CFLAGS = -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source -I$(top_srcdir)/lib
test_ecc_encrypt_LDADD = $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) -lcrypto
endif
test_intensive_memory_pool_SOURCES = test_intensive_memory_pool.c
test_intensive_memory_pool_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_intensive_memory_pool_LDADD = $(COMMON_LIBS)
@ -366,21 +294,15 @@ test_config_debug_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_config_debug_LDADD = $(top_builddir)/src/utun-config_parser.o $(COMMON_LIBS)
test_route_lib_SOURCES = test_route_lib.c
test_route_lib_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/src -I$(top_srcdir)/tinycrypt/lib/include
test_route_lib_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_route_lib_LDADD = $(top_builddir)/src/utun-route_lib.o $(top_builddir)/src/utun-route_node.o $(top_builddir)/src/utun-etcp_debug.o $(COMMON_LIBS)
test_bgp_route_exchange_SOURCES = test_bgp_route_exchange.c
test_bgp_route_exchange_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_bgp_route_exchange_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_bgp_route_exchange_LDADD = $(top_builddir)/src/utun-dummynet.o $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
# test_dummynet временно исключен (медленный)
# test_dummynet_SOURCES = test_dummynet.c
# test_dummynet_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
# test_dummynet_LDADD = $(top_builddir)/src/utun-dummynet.o $(COMMON_LIBS)
test_bbr_integration_SOURCES = bbr_integration/test_bbr_integration.c
test_bbr_integration_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source
test_bbr_integration_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib
test_bbr_integration_LDADD = $(top_builddir)/src/utun-dummynet.o $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS)
bench_timeout_heap_SOURCES = bench_timeout_heap.c
@ -391,9 +313,6 @@ bench_uasync_timeouts_SOURCES = bench_uasync_timeouts.c
bench_uasync_timeouts_CFLAGS = -I$(top_srcdir)/lib
bench_uasync_timeouts_LDADD = $(COMMON_LIBS)
# Build tinycrypt objects before tests that need them
BUILT_SOURCES = $(TINYCRYPT_BUILT)
# Copy test configs to build directory (tests run from build/tests/)
all-local: copy-test-configs

12
tests/bbr_integration/test_bbr_integration.c

@ -334,15 +334,11 @@ int main(void) {
if (!ctx.ua) { printf("ERROR: uasync_create failed\n"); return 1; }
const char* s_priv =
"67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb";
const char* s_pub =
"1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17"
"c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9";
"38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68";
const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a";
const char* c_priv =
"4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2";
const char* c_pub =
"c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3"
"c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71";
"704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f";
const char* c_pub = "b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01";
printf("Creating instances...\n");
ctx.sender = create_instance(ctx.ua, 0x1111111111111111ULL, c_priv, c_pub);

6
tests/tcp_proxy_full/client.conf

@ -1,7 +1,7 @@
[global]
my_node_id=0xAAAA000000000002
my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2
my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71
my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f
my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01
tun_ip=10.200.20.1/24
tun_ifname=tun_test_cli
debug_level=error
@ -13,7 +13,7 @@ type=public
[client: c1]
keepalive=1
link=s1:127.0.0.1:15001
peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9
peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a
[tcp_proxy_client]
enabled=yes

4
tests/tcp_proxy_full/exit.conf

@ -1,7 +1,7 @@
[global]
my_node_id=0xAAAA000000000001
my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb
my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9
my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68
my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a
tun_ip=10.200.10.1/24
tun_ifname=tun_test_exit
debug_level=error

4
tests/test_config_debug.c

@ -26,8 +26,8 @@ static char config_path[256];
static const char* config_content =
"[global]\n"
"my_node_id=0x1111111111111111\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"# Debug and logging configuration\n"

10
tests/test_etcp_100_packets.c

@ -41,8 +41,8 @@ static char client_config_path[256];
static const char* server_config_content =
"[global]\n"
"my_node_id=0x1111111111111111\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"\n"
@ -57,8 +57,8 @@ static const char* server_config_content =
static const char* client_config_content =
"[global]\n"
"my_node_id=0x2222222222222222\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"\n"
@ -68,7 +68,7 @@ static const char* client_config_content =
"\n"
"[client: test_client]\n"
"keepalive=1\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"link=test:127.0.0.1:9021\n";
// Create temp config files

10
tests/test_etcp_api.c

@ -48,8 +48,8 @@ static char client_config_path[256];
static const char* server_config_content =
"[global]\n"
"my_node_id=0x1111111111111111\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"\n"
@ -64,8 +64,8 @@ static const char* server_config_content =
static const char* client_config_content =
"[global]\n"
"my_node_id=0x2222222222222222\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"\n"
@ -75,7 +75,7 @@ static const char* client_config_content =
"\n"
"[client: test_client]\n"
"keepalive=1\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"link=test:127.0.0.1:9031\n";
// Create temp config files

8
tests/test_etcp_congestion.c

@ -298,10 +298,10 @@ int main(void) {
if (!ctx.ua) { printf("uasync failed\n"); return 1; }
/* Ключи */
const char* s_priv = "67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb";
const char* s_pub = "1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9";
const char* c_priv = "4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2";
const char* c_pub = "c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71";
const char* s_priv = "38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68";
const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a";
const char* c_priv = "704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f";
const char* c_pub = "b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01";
printf("Creating instances...\n");
ctx.sender = create_instance(ctx.ua, 0x1111111111111111ULL, c_priv, c_pub);

8
tests/test_etcp_dummynet.c

@ -186,10 +186,10 @@ int main(void) {
printf("Using fixed keys...\n");
/* These keys are copied from test_etcp_two_instances.c and are known to work */
const char* s_priv = "67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb";
const char* s_pub = "1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9";
const char* c_priv = "4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2";
const char* c_pub = "c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71";
const char* s_priv = "38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68";
const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a";
const char* c_priv = "704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f";
const char* c_pub = "b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01";
printf("Creating instances...\n");
server = create_instance(ua, 0x1111111111111111ULL, s_priv, s_pub);

10
tests/test_etcp_ping.c

@ -32,8 +32,8 @@ static int pong_received = 0;
static const char* server_config_content =
"[global]\n"
"my_node_id=0x1111111111111111\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"\n"
@ -47,8 +47,8 @@ static const char* server_config_content =
static const char* client_config_content =
"[global]\n"
"my_node_id=0x2222222222222222\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"\n"
@ -58,7 +58,7 @@ static const char* client_config_content =
"\n"
"[client:test_client]\n"
"keepalive=1\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"link=test:127.0.0.1:9011\n";
static int create_temp_configs(void) {

10
tests/test_etcp_reconnect.c

@ -70,8 +70,8 @@ static int create_temp_configs(void) {
fprintf(f,
"[global]\n"
"my_node_id=0x1111111111111111\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"\n"
@ -89,8 +89,8 @@ static int create_temp_configs(void) {
fprintf(f,
"[global]\n"
"my_node_id=0x2222222222222222\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"\n"
@ -100,7 +100,7 @@ static int create_temp_configs(void) {
"\n"
"[client: test_client]\n"
"keepalive=1\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"link=test:127.0.0.1:%d\n",
client_port, server_port);
fclose(f);

12
tests/test_etcp_reinit_inflight.c

@ -203,8 +203,8 @@ static void monitor(void* arg) {
utun_instance_destroy(ctx->receiver);
ctx->receiver = NULL;
{
const char* s_priv = "67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb";
const char* s_pub = "1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9";
const char* s_priv = "38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68";
const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a";
ctx->receiver = create_instance(ctx->ua, 0x2222222222222222ULL, s_priv, s_pub);
add_server(ctx->receiver, "srv1", SRV_PORT);
utun_instance_init(ctx->receiver);
@ -274,10 +274,10 @@ int main(void) {
ctx.ua = uasync_create();
if (!ctx.ua) { printf("uasync_create failed\n"); return 1; }
const char* s_priv = "67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb";
const char* s_pub = "1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9";
const char* c_priv = "4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2";
const char* c_pub = "c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71";
const char* s_priv = "38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68";
const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a";
const char* c_priv = "704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f";
const char* c_pub = "b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01";
ctx.sender = create_instance(ctx.ua, 0x1111111111111111ULL, c_priv, c_pub);
ctx.receiver = create_instance(ctx.ua, 0x2222222222222222ULL, s_priv, s_pub);

10
tests/test_etcp_router.c

@ -49,8 +49,8 @@ static void* g_mon_id = NULL;
static const char* srv_cfg =
"[global]\n"
"my_node_id=0x1111111111111111\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"[server: s1]\n"
@ -63,8 +63,8 @@ static const char* srv_cfg =
static const char* cli_cfg =
"[global]\n"
"my_node_id=0x2222222222222222\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"[server: s1]\n"
@ -72,7 +72,7 @@ static const char* cli_cfg =
"type=public\n"
"[client: c1]\n"
"keepalive=1\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"link=s1:127.0.0.1:9041\n";
// ======================== Test state ========================

10
tests/test_etcp_simple_traffic.c

@ -63,8 +63,8 @@ static int create_temp_configs(void) {
fprintf(f,
"[global]\n"
"my_node_id=0x1111111111111111\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"\n"
@ -82,8 +82,8 @@ static int create_temp_configs(void) {
fprintf(f,
"[global]\n"
"my_node_id=0x2222222222222222\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"\n"
@ -93,7 +93,7 @@ static int create_temp_configs(void) {
"\n"
"[client: test_client]\n"
"keepalive=1\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"link=test:127.0.0.1:%d\n",
client_port, server_port);
fclose(f);

10
tests/test_etcp_two_instances.c

@ -41,8 +41,8 @@ static char client_config_path[256];
static const char* server_config_content =
"[global]\n"
"my_node_id=0x1111111111111111\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"\n"
@ -57,8 +57,8 @@ static const char* server_config_content =
static const char* client_config_content =
"[global]\n"
"my_node_id=0x2222222222222222\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"\n"
@ -68,7 +68,7 @@ static const char* client_config_content =
"\n"
"[client: test_client]\n"
"keepalive=1\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"link=test:127.0.0.1:9011\n";
// Create temp config files

10
tests/test_icmp_proxy.c

@ -41,13 +41,13 @@ static const char* cfg_node_client(void) {
snprintf(buf, sizeof(buf),
"[global]\n"
"my_node_id=0xEEEE000000000001\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"[server: s1]\naddr=127.0.0.1:9081\ntype=public\n"
"[client: c1]\nkeepalive=1\nlink=s1:127.0.0.1:9082\n"
"peer_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"peer_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"[tcp_proxy_client]\n"
"enabled=yes\n"
"tun_name=tun_tcp\n"
@ -61,8 +61,8 @@ static const char* cfg_node_exit(void) {
snprintf(buf, sizeof(buf),
"[global]\n"
"my_node_id=0xEEEE000000000002\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"[server: s1]\naddr=127.0.0.1:9082\ntype=public\n"

10
tests/test_ipv6_sockets.c

@ -56,8 +56,8 @@ static const char* server_config =
"[global]\n"
"my_node_name=server_v6\n"
"my_node_id=0xAAAA000000000001\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"tun_test_mode=1\n"
@ -76,8 +76,8 @@ static const char* client_config =
"[global]\n"
"my_node_name=client_v6\n"
"my_node_id=0xBBBB000000000002\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"tun_test_mode=1\n"
@ -88,7 +88,7 @@ static const char* client_config =
"\n"
"[client: v6client]\n"
"keepalive=1\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"link=v6srv:[::1]:40111\n";
static int create_temp_configs(void) {

10
tests/test_pkt_normalizer_etcp.c

@ -40,8 +40,8 @@ static char client_config_path[256];
static const char* server_config_content =
"[global]\n"
"my_node_id=0x1111111111111111\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"\n"
@ -55,8 +55,8 @@ static const char* server_config_content =
static const char* client_config_content =
"[global]\n"
"my_node_id=0x2222222222222222\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"\n"
@ -66,7 +66,7 @@ static const char* client_config_content =
"\n"
"[client: test_client]\n"
"keepalive=1\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"link=test:127.0.0.1:9041\n";
static struct UTUN_INSTANCE* server_instance = NULL;

10
tests/test_tcp_proxy_remote.c

@ -135,18 +135,18 @@ static void test_timeout(void* arg) {
static const char* cfg_exit(int srv_port) { static char b[1024]; snprintf(b,sizeof(b),
"[global]\nmy_node_id=0xCCCC000000000001\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\ntun_ifname=tun99\n"
"[server:s1]\naddr=127.0.0.1:%d\ntype=public\n[allowed_keys]\nallow_all=1\n[tcp_proxy_server]\nenabled=yes\n", srv_port); return b; }
static const char* cfg_b(int srv_port, int cli_port) { static char b[1024]; snprintf(b,sizeof(b),
"[global]\nmy_node_id=0xCCCC000000000002\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\ntun_ifname=tun98\n"
"[server:s1]\naddr=127.0.0.1:%d\ntype=public\n[client:c1]\nkeepalive=1\nlink=s1:127.0.0.1:%d\n"
"peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"[tcp_proxy_server]\nenabled=yes\n", srv_port, cli_port); return b; }
int main(void) {

10
tests/test_udp_proxy.c

@ -40,13 +40,13 @@ static const char* cfg_node_client(void) {
snprintf(buf, sizeof(buf),
"[global]\n"
"my_node_id=0xDDDD000000000001\n"
"my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n"
"my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n"
"my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n"
"my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n"
"tun_ip=10.99.0.1/24\n"
"tun_ifname=tun99\n"
"[server: s1]\naddr=127.0.0.1:9071\ntype=public\n"
"[client: c1]\nkeepalive=1\nlink=s1:127.0.0.1:9072\n"
"peer_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"peer_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"[tcp_proxy_client]\n"
"enabled=yes\n"
"tun_name=tun_tcp\n"
@ -60,8 +60,8 @@ static const char* cfg_node_exit(void) {
snprintf(buf, sizeof(buf),
"[global]\n"
"my_node_id=0xDDDD000000000002\n"
"my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n"
"my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n"
"my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n"
"my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n"
"tun_ip=10.99.0.2/24\n"
"tun_ifname=tun98\n"
"[server: s1]\naddr=127.0.0.1:9072\ntype=public\n"

14
utun.md

@ -6,7 +6,7 @@ uTun создаёт виртуальный TUN-интерфейс и маршр
| Возможность | Описание |
|---|---|
| **Шифрование** | ECC (secp256r1) обмен ключами + AES-128-CCM с аутентификацией |
| **Шифрование** | X25519 обмен ключами + AES-128-CCM с аутентификацией |
| **Целостность** | CRC32 внутри зашифрованного payload |
| **Multi-link** | Одно подключение через несколько UDP-каналов одновременно |
| **Балансировка** | Выбор канала с минимальным inflight + round-robin при равенстве |
@ -20,7 +20,7 @@ uTun создаёт виртуальный TUN-интерфейс и маршр
| **Файрвол** | Белый список IP:port для трафика через туннель |
| **Control server** | TCP-сервер для мониторинга метрик в реальном времени (GUI-клиент) |
| **Горячая перезагрузка** | SIGHUP — выборочное обновление конфига (сравнение сокетов/клиентов/линков) |
| **Авто-ключи** | При первом запуске генерирует ECC-пару и node_id, записывает в конфиг |
| **Авто-ключи** | При первом запуске генерирует X25519-пару и node_id, записывает в конфиг |
| **Демонизация** | fork/setsid на Linux; foreground-режим `-f` для отладки |
| **Кроссплатформенность** | Linux (epoll), Windows (wintun), FreeBSD |
| **Эмуляция потерь** | `loss_rate=N` в конфиге сокета — для тестирования |
@ -67,8 +67,8 @@ utun -c utun.conf [-p /var/run/utun.pid] [-l utun.log] [-f] [-d "etcp:debug"]
|---|---|---|
| `my_node_name` | Имя узла (до 15 символов) | — |
| `my_node_id` | 64-битный ID узла (hex, 16 символов) | авто |
| `my_private_key` | Приватный ключ ECC (64 hex символа) | авто |
| `my_public_key` | Публичный ключ ECC (128 hex символов) | авто |
| `my_private_key` | Приватный ключ X25519 (64 hex символа) | авто |
| `my_public_key` | Публичный ключ X25519 (64 hex символа) | авто |
| `tun_ifname` | Имя TUN-интерфейса | `tun0` |
| `tun_ip` | IP-адрес TUN-интерфейса | — |
| `mtu` | MTU для всех подключений | `1500` |
@ -121,7 +121,7 @@ type=public
| Ключ | Значение | По умолчанию |
|---|---|---|
| `link` | `сервер:удалённый_IP:порт` (можно несколько) | **обязателен** |
| `peer_public_key` | Публичный ключ пира (128 hex) | **обязателен** |
| `peer_public_key` | Публичный ключ пира (64 hex) | **обязателен** |
| `keepalive` | 1 — включить keepalive | `1` |
Пример:
@ -184,7 +184,7 @@ control_allow=192.168.0.0/16
| Ключ | Значение | По умолчанию |
|---|---|---|
| `allow_all` | 1 — разрешить все ключи | — |
| `key` | Публичный ключ (128 hex, можно несколько) | — |
| `key` | Публичный ключ (64 hex, можно несколько) | — |
Поведение:
- Секция отсутствует: разрешить все (совместимость)
@ -205,7 +205,7 @@ key=04c1cae041a8e6bfba5245f6669c73f0793d7f9929300a2ba2e123ca55260d6e4748...
tun_ip=10.23.1.1
my_node_name=vmL1
my_node_id=5f75c7445af88e1f
my_private_key=b0e8b68679db468979906894fe36239dbda910e06435361d696c7f5a8e2009c4
my_private_key=d065b784a8386f9b37f07b4c16c3ab83ddce5885e78f79c5d2a6d1f9954fe441
my_public_key=c6c8a8a9616ffa6cf44d4757e2bc9f7bd78a1d3cbbe75cffaf3cab8885ad48e7677b...
[server: lan1]

Loading…
Cancel
Save