|
|
|
|
@ -28,6 +28,17 @@ struct reality_io {
|
|
|
|
|
void (*ready)(struct stcp_conn *); |
|
|
|
|
}; |
|
|
|
|
|
|
|
|
|
const char* reality_io_state_name(const struct stcp_conn *c) { |
|
|
|
|
if (!c->reality_io) return "none"; |
|
|
|
|
switch (c->reality_io->phase) { |
|
|
|
|
case WAIT_HELLO: return c->is_server ? "waiting-ClientHello" : "waiting-ServerHello"; |
|
|
|
|
case WAIT_SERVER_FLIGHT: return "waiting-server-authentication"; |
|
|
|
|
case WAIT_CLIENT_FINISHED: return "waiting-client-Finished"; |
|
|
|
|
case RECORD_DATA: return "protected-data"; |
|
|
|
|
} |
|
|
|
|
return "unknown"; |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
static int replay_accept(struct reality_owner *owner, const uint8_t *ch, size_t len, uint32_t now, |
|
|
|
|
uint32_t timestamp, int64_t window) { |
|
|
|
|
if (!owner->replay) owner->replay = u_calloc(1, sizeof(*owner->replay)); |
|
|
|
|
@ -259,7 +270,8 @@ static int hello_process(struct stcp_conn *c) {
|
|
|
|
|
} |
|
|
|
|
return 0; |
|
|
|
|
reject: |
|
|
|
|
DEBUG_WARN(DEBUG_CATEGORY_REALITY, "Hello rejected: buffered=%zu handshake=%zu", io->wire_len, io->handshake_len); |
|
|
|
|
DEBUG_WARN(DEBUG_CATEGORY_REALITY, "REALITY Hello rejected: buffered=%zu handshake=%zu %s", |
|
|
|
|
io->wire_len, io->handshake_len, stcp_conn_describe(c).text); |
|
|
|
|
return fallback(c); |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
@ -286,7 +298,8 @@ static int handshake_process(struct stcp_conn *c, const uint8_t *data, size_t le
|
|
|
|
|
if (io->phase == WAIT_SERVER_FLIGHT && send_finished(c)) return -1; |
|
|
|
|
io->phase = RECORD_DATA; |
|
|
|
|
reality_session_handshake_done(&io->session); |
|
|
|
|
DEBUG_INFO(DEBUG_CATEGORY_REALITY, "Finished verified: role=%s; protected STCP enabled", io->session.is_server ? "server" : "client"); |
|
|
|
|
DEBUG_TRACE(DEBUG_CATEGORY_REALITY, "REALITY Finished verified; starting protected STCP handshake: %s", |
|
|
|
|
stcp_conn_describe(c).text); |
|
|
|
|
io->ready(c); |
|
|
|
|
if (!c->reality_io || c->state == STCP_STATE_CLOSED || c->state == STCP_STATE_ERROR) return -1; |
|
|
|
|
} else { |
|
|
|
|
@ -300,8 +313,8 @@ static int handshake_process(struct stcp_conn *c, const uint8_t *data, size_t le
|
|
|
|
|
} |
|
|
|
|
return 0; |
|
|
|
|
reject: |
|
|
|
|
DEBUG_WARN(DEBUG_CATEGORY_REALITY, "protected handshake rejected: phase=%d step=%u type=%u size=%zu", io->phase, |
|
|
|
|
io->flight_step, io->handshake[0], io->handshake_len); |
|
|
|
|
DEBUG_WARN(DEBUG_CATEGORY_REALITY, "REALITY protected handshake rejected: step=%u message_type=%u buffered=%zu %s", |
|
|
|
|
io->flight_step, io->handshake[0], io->handshake_len, stcp_conn_describe(c).text); |
|
|
|
|
return -1; |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
|