mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-09 03:42:01 -04:00
feature/conn25: unmap addresses in TransitIPRequest
Unmap both transit and destination IPs in TransitIPRequest to prevent unpredictable mappings. Fixes https://github.com/tailscale/corp/issues/48781 Change-Id: I5aea2bf4e5ff5240c66f20c71cfa1ceba1722622 Signed-off-by: Mazdak Nasab <mazdak.nasab@gmail.com>
This commit is contained in:
1 parent
8a119e1ec0
commit
ecedffff5b
2 files changed
+24
No files matched your search
@@ -588,6 +588,12 @@ func (c *Conn25) handleConnectorTransitIPRequest(n tailcfg.NodeView, peerCaps ta
|
||||
|
||||
seen := map[netip.Addr]bool{}
|
||||
for _, each := range ctipr.TransitIPs {
|
||||
// Canonicalize IPv4-in-IPv6 addresses, so that duplicate detection and
|
||||
// the keys we store in the connector's map match the unmapped form the
|
||||
// datapath produces when it parses packets.
|
||||
each.TransitIP = each.TransitIP.Unmap()
|
||||
each.DestinationIP = each.DestinationIP.Unmap()
|
||||
|
||||
if seen[each.TransitIP] {
|
||||
resp.TransitIPs = append(resp.TransitIPs, TransitIPResponse{
|
||||
Code: DuplicateTransitIP,
|
||||
|
||||
@@ -78,6 +78,9 @@ func TestHandleConnectorTransitIPRequest(t *testing.T) {
|
||||
tipV4Outside := netip.MustParseAddr("192.0.2.1")
|
||||
tipV6Outside := netip.MustParseAddr("2001:db8::1")
|
||||
|
||||
// tipV4_1 written in its IPv4-in-IPv6 form; the same address as tipV4_1.
|
||||
tipV4_1In6 := netip.MustParseAddr("::ffff:169.254.0.1")
|
||||
|
||||
// Destination IPs
|
||||
dipV4_1 := netip.MustParseAddr("10.0.0.1")
|
||||
dipV4_2 := netip.MustParseAddr("10.0.0.2")
|
||||
@@ -429,6 +432,21 @@ func TestHandleConnectorTransitIPRequest(t *testing.T) {
|
||||
{{pipV4_2, tipV4Outside, netip.Addr{}}, {pipV4_2, tipV4_2, dipV4_2}},
|
||||
},
|
||||
},
|
||||
// Single peer, a transit IP in its IPv4-in-IPv6 form is canonicalized
|
||||
// and stored unmapped.
|
||||
{
|
||||
name: "one-peer-tip-4in6",
|
||||
ctipReqPeers: []tailcfg.NodeView{peerV4Only},
|
||||
ctipReqs: []ConnectorTransitIPRequest{
|
||||
{TransitIPs: []TransitIPRequest{{TransitIP: tipV4_1In6, DestinationIP: dipV4_1, App: appName}}},
|
||||
},
|
||||
wants: []ConnectorTransitIPResponse{
|
||||
{TransitIPs: []TransitIPResponse{{Code: OK, Message: ""}}},
|
||||
},
|
||||
wantLookups: [][][]netip.Addr{
|
||||
{{pipV4_2, tipV4_1, dipV4_1}, {pipV4_2, tipV4_1In6, netip.Addr{}}},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
|
||||
Reference in new issue
Block a user