mirror of https://github.com/tailscale/tailscale/
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
279 lines
7.7 KiB
Go
279 lines
7.7 KiB
Go
2 years ago
|
// Copyright (c) Tailscale Inc & AUTHORS
|
||
|
// SPDX-License-Identifier: BSD-3-Clause
|
||
4 years ago
|
|
||
7 months ago
|
package netmon
|
||
4 years ago
|
|
||
|
import (
|
||
4 years ago
|
"log"
|
||
2 years ago
|
"net/netip"
|
||
4 years ago
|
"net/url"
|
||
3 years ago
|
"strings"
|
||
4 years ago
|
"syscall"
|
||
4 years ago
|
"unsafe"
|
||
4 years ago
|
|
||
4 years ago
|
"golang.org/x/sys/windows"
|
||
4 years ago
|
"golang.zx2c4.com/wireguard/windows/tunnel/winipcfg"
|
||
4 years ago
|
"tailscale.com/tsconst"
|
||
4 years ago
|
)
|
||
|
|
||
|
const (
|
||
|
fallbackInterfaceMetric = uint32(0) // Used if we cannot get the actual interface metric
|
||
4 years ago
|
)
|
||
|
|
||
|
func init() {
|
||
|
likelyHomeRouterIP = likelyHomeRouterIPWindows
|
||
4 years ago
|
getPAC = getPACWindows
|
||
4 years ago
|
}
|
||
|
|
||
11 months ago
|
func likelyHomeRouterIPWindows() (ret netip.Addr, _ netip.Addr, ok bool) {
|
||
4 years ago
|
rs, err := winipcfg.GetIPForwardTable2(windows.AF_INET)
|
||
4 years ago
|
if err != nil {
|
||
4 years ago
|
log.Printf("routerIP/GetIPForwardTable2 error: %v", err)
|
||
4 years ago
|
return
|
||
|
}
|
||
4 years ago
|
|
||
|
var ifaceMetricCache map[winipcfg.LUID]uint32
|
||
|
|
||
|
getIfaceMetric := func(luid winipcfg.LUID) (metric uint32) {
|
||
|
if ifaceMetricCache == nil {
|
||
|
ifaceMetricCache = make(map[winipcfg.LUID]uint32)
|
||
|
} else if m, ok := ifaceMetricCache[luid]; ok {
|
||
|
return m
|
||
|
}
|
||
|
|
||
|
if iface, err := luid.IPInterface(windows.AF_INET); err == nil {
|
||
|
metric = iface.Metric
|
||
|
} else {
|
||
|
log.Printf("routerIP/luid.IPInterface error: %v", err)
|
||
|
metric = fallbackInterfaceMetric
|
||
|
}
|
||
|
|
||
|
ifaceMetricCache[luid] = metric
|
||
4 years ago
|
return
|
||
|
}
|
||
|
|
||
2 years ago
|
v4unspec := netip.IPv4Unspecified()
|
||
4 years ago
|
var best *winipcfg.MibIPforwardRow2 // best (lowest metric) found so far, or nil
|
||
|
|
||
|
for i := range rs {
|
||
|
r := &rs[i]
|
||
2 years ago
|
if r.Loopback || r.DestinationPrefix.PrefixLength != 0 || r.DestinationPrefix.Prefix().Addr().Unmap() != v4unspec {
|
||
4 years ago
|
// Not a default route, so skip
|
||
|
continue
|
||
|
}
|
||
|
|
||
2 years ago
|
ip := r.NextHop.Addr().Unmap()
|
||
|
if !ip.IsValid() {
|
||
4 years ago
|
// Not a valid gateway, so skip (won't happen though)
|
||
|
continue
|
||
4 years ago
|
}
|
||
4 years ago
|
|
||
|
if best == nil {
|
||
|
best = r
|
||
|
ret = ip
|
||
|
continue
|
||
|
}
|
||
|
|
||
|
// We can get here only if there are multiple default gateways defined (rare case),
|
||
|
// in which case we need to calculate the effective metric.
|
||
|
// Effective metric is sum of interface metric and route metric offset
|
||
|
if ifaceMetricCache == nil {
|
||
|
// If we're here it means that previous route still isn't updated, so update it
|
||
|
best.Metric += getIfaceMetric(best.InterfaceLUID)
|
||
4 years ago
|
}
|
||
4 years ago
|
r.Metric += getIfaceMetric(r.InterfaceLUID)
|
||
|
|
||
|
if best.Metric > r.Metric || best.Metric == r.Metric && ret.Compare(ip) > 0 {
|
||
|
// Pick the route with lower metric, or lower IP if metrics are equal
|
||
|
best = r
|
||
4 years ago
|
ret = ip
|
||
|
}
|
||
4 years ago
|
}
|
||
|
|
||
2 years ago
|
if ret.IsValid() && !ret.IsPrivate() {
|
||
4 years ago
|
// Default route has a non-private gateway
|
||
11 months ago
|
return netip.Addr{}, netip.Addr{}, false
|
||
4 years ago
|
}
|
||
|
|
||
11 months ago
|
return ret, netip.Addr{}, ret.IsValid()
|
||
4 years ago
|
}
|
||
4 years ago
|
|
||
|
// NonTailscaleMTUs returns a map of interface LUID to interface MTU,
|
||
|
// for all interfaces except Tailscale tunnels.
|
||
4 years ago
|
func NonTailscaleMTUs() (map[winipcfg.LUID]uint32, error) {
|
||
|
mtus := map[winipcfg.LUID]uint32{}
|
||
4 years ago
|
ifs, err := NonTailscaleInterfaces()
|
||
|
for luid, iface := range ifs {
|
||
4 years ago
|
mtus[luid] = iface.MTU
|
||
4 years ago
|
}
|
||
|
return mtus, err
|
||
|
}
|
||
|
|
||
3 years ago
|
func notTailscaleInterface(iface *winipcfg.IPAdapterAddresses) bool {
|
||
|
// TODO(bradfitz): do this without the Description method's
|
||
|
// utf16-to-string allocation. But at least we only do it for
|
||
|
// the virtual interfaces, for which there won't be many.
|
||
3 years ago
|
if iface.IfType != winipcfg.IfTypePropVirtual {
|
||
|
return true
|
||
|
}
|
||
|
desc := iface.Description()
|
||
|
return !(strings.Contains(desc, tsconst.WintunInterfaceDesc) ||
|
||
|
strings.Contains(desc, tsconst.WintunInterfaceDesc0_14))
|
||
3 years ago
|
}
|
||
|
|
||
4 years ago
|
// NonTailscaleInterfaces returns a map of interface LUID to interface
|
||
|
// for all interfaces except Tailscale tunnels.
|
||
4 years ago
|
func NonTailscaleInterfaces() (map[winipcfg.LUID]*winipcfg.IPAdapterAddresses, error) {
|
||
3 years ago
|
return getInterfaces(windows.AF_UNSPEC, winipcfg.GAAFlagIncludeAllInterfaces, notTailscaleInterface)
|
||
|
}
|
||
|
|
||
|
// getInterfaces returns a map of interfaces keyed by their LUID for
|
||
|
// all interfaces matching the provided match predicate.
|
||
|
//
|
||
|
// The family (AF_UNSPEC, AF_INET, or AF_INET6) and flags are passed
|
||
|
// to winipcfg.GetAdaptersAddresses.
|
||
|
func getInterfaces(family winipcfg.AddressFamily, flags winipcfg.GAAFlags, match func(*winipcfg.IPAdapterAddresses) bool) (map[winipcfg.LUID]*winipcfg.IPAdapterAddresses, error) {
|
||
|
ifs, err := winipcfg.GetAdaptersAddresses(family, flags)
|
||
4 years ago
|
if err != nil {
|
||
|
return nil, err
|
||
|
}
|
||
4 years ago
|
ret := map[winipcfg.LUID]*winipcfg.IPAdapterAddresses{}
|
||
4 years ago
|
for _, iface := range ifs {
|
||
3 years ago
|
if match(iface) {
|
||
|
ret[iface.LUID] = iface
|
||
4 years ago
|
}
|
||
|
}
|
||
|
return ret, nil
|
||
|
}
|
||
4 years ago
|
|
||
|
// GetWindowsDefault returns the interface that has the non-Tailscale
|
||
|
// default route for the given address family.
|
||
|
//
|
||
|
// It returns (nil, nil) if no interface is found.
|
||
3 years ago
|
//
|
||
|
// The family must be one of AF_INET or AF_INET6.
|
||
4 years ago
|
func GetWindowsDefault(family winipcfg.AddressFamily) (*winipcfg.IPAdapterAddresses, error) {
|
||
3 years ago
|
ifs, err := getInterfaces(family, winipcfg.GAAFlagIncludeAllInterfaces, func(iface *winipcfg.IPAdapterAddresses) bool {
|
||
|
switch iface.IfType {
|
||
|
case winipcfg.IfTypeSoftwareLoopback:
|
||
|
return false
|
||
|
}
|
||
|
switch family {
|
||
|
case windows.AF_INET:
|
||
|
if iface.Flags&winipcfg.IPAAFlagIpv4Enabled == 0 {
|
||
|
return false
|
||
|
}
|
||
|
case windows.AF_INET6:
|
||
|
if iface.Flags&winipcfg.IPAAFlagIpv6Enabled == 0 {
|
||
|
return false
|
||
|
}
|
||
|
}
|
||
|
return iface.OperStatus == winipcfg.IfOperStatusUp && notTailscaleInterface(iface)
|
||
|
})
|
||
4 years ago
|
if err != nil {
|
||
|
return nil, err
|
||
|
}
|
||
|
|
||
4 years ago
|
routes, err := winipcfg.GetIPForwardTable2(family)
|
||
4 years ago
|
if err != nil {
|
||
|
return nil, err
|
||
|
}
|
||
|
|
||
|
bestMetric := ^uint32(0)
|
||
4 years ago
|
var bestIface *winipcfg.IPAdapterAddresses
|
||
4 years ago
|
for _, route := range routes {
|
||
3 years ago
|
if route.DestinationPrefix.PrefixLength != 0 {
|
||
|
// Not a default route.
|
||
|
continue
|
||
|
}
|
||
4 years ago
|
iface := ifs[route.InterfaceLUID]
|
||
3 years ago
|
if iface == nil {
|
||
4 years ago
|
continue
|
||
|
}
|
||
3 years ago
|
|
||
|
// Microsoft docs say:
|
||
|
//
|
||
|
// "The actual route metric used to compute the route
|
||
|
// preferences for IPv4 is the summation of the route
|
||
|
// metric offset specified in the Metric member of the
|
||
|
// MIB_IPFORWARD_ROW2 structure and the interface
|
||
|
// metric specified in this member for IPv4"
|
||
|
metric := route.Metric
|
||
|
switch family {
|
||
|
case windows.AF_INET:
|
||
|
metric += iface.Ipv4Metric
|
||
|
case windows.AF_INET6:
|
||
|
metric += iface.Ipv6Metric
|
||
|
}
|
||
|
if metric < bestMetric {
|
||
|
bestMetric = metric
|
||
4 years ago
|
bestIface = iface
|
||
|
}
|
||
|
}
|
||
|
|
||
|
return bestIface, nil
|
||
|
}
|
||
|
|
||
3 years ago
|
func defaultRoute() (d DefaultRouteDetails, err error) {
|
||
3 years ago
|
// We always return the IPv4 default route.
|
||
|
// TODO(bradfitz): adjust API if/when anything cares. They could in theory differ, though,
|
||
|
// in which case we might send traffic to the wrong interface.
|
||
4 years ago
|
iface, err := GetWindowsDefault(windows.AF_INET)
|
||
4 years ago
|
if err != nil {
|
||
3 years ago
|
return d, err
|
||
4 years ago
|
}
|
||
3 years ago
|
if iface != nil {
|
||
|
d.InterfaceName = iface.FriendlyName()
|
||
|
d.InterfaceDesc = iface.Description()
|
||
|
d.InterfaceIndex = int(iface.IfIndex)
|
||
4 years ago
|
}
|
||
3 years ago
|
return d, nil
|
||
4 years ago
|
}
|
||
4 years ago
|
|
||
|
var (
|
||
|
winHTTP = windows.NewLazySystemDLL("winhttp.dll")
|
||
|
detectAutoProxyConfigURL = winHTTP.NewProc("WinHttpDetectAutoProxyConfigUrl")
|
||
|
|
||
|
kernel32 = windows.NewLazySystemDLL("kernel32.dll")
|
||
|
globalFree = kernel32.NewProc("GlobalFree")
|
||
|
)
|
||
|
|
||
|
const (
|
||
|
winHTTP_AUTO_DETECT_TYPE_DHCP = 0x00000001
|
||
|
winHTTP_AUTO_DETECT_TYPE_DNS_A = 0x00000002
|
||
|
)
|
||
|
|
||
|
func getPACWindows() string {
|
||
|
var res *uint16
|
||
4 years ago
|
r, _, e := detectAutoProxyConfigURL.Call(
|
||
4 years ago
|
winHTTP_AUTO_DETECT_TYPE_DHCP|winHTTP_AUTO_DETECT_TYPE_DNS_A,
|
||
|
uintptr(unsafe.Pointer(&res)),
|
||
|
)
|
||
4 years ago
|
if r == 1 {
|
||
|
if res == nil {
|
||
|
log.Printf("getPACWindows: unexpected success with nil result")
|
||
|
return ""
|
||
|
}
|
||
|
defer globalFree.Call(uintptr(unsafe.Pointer(res)))
|
||
4 years ago
|
s := windows.UTF16PtrToString(res)
|
||
3 years ago
|
s = strings.TrimSpace(s)
|
||
|
if s == "" {
|
||
|
return "" // Issue 2357: invalid URL "\n" from winhttp; ignoring
|
||
|
}
|
||
4 years ago
|
if _, err := url.Parse(s); err != nil {
|
||
|
log.Printf("getPACWindows: invalid URL %q from winhttp; ignoring", s)
|
||
|
return ""
|
||
|
}
|
||
|
return s
|
||
4 years ago
|
}
|
||
|
const (
|
||
|
ERROR_WINHTTP_AUTODETECTION_FAILED = 12180
|
||
|
)
|
||
|
if e == syscall.Errno(ERROR_WINHTTP_AUTODETECTION_FAILED) {
|
||
|
// Common case on networks without advertised PAC.
|
||
|
return ""
|
||
4 years ago
|
}
|
||
4 years ago
|
log.Printf("getPACWindows: %T=%v", e, e) // syscall.Errno=0x....
|
||
|
return ""
|
||
4 years ago
|
}
|