diff --git a/common/protocol/quic/cipher_suite.go b/common/protocol/quic/cipher_suite.go new file mode 100644 index 000000000..798a03af9 --- /dev/null +++ b/common/protocol/quic/cipher_suite.go @@ -0,0 +1,23 @@ +package quic + +import ( + "crypto" + "crypto/cipher" + _ "crypto/tls" + _ "unsafe" +) + +// copied from github.com/quic-go/quic-go/internal/qtls/cipher_suite_go121.go + +type cipherSuiteTLS13 struct { + ID uint16 + KeyLen int + AEAD func(key, fixedNonce []byte) cipher.AEAD + Hash crypto.Hash +} + +// github.com/quic-go/quic-go/internal/handshake/cipher_suite.go describes these cipher suite implementations are copied from the standard library crypto/tls package. +// So we can user go:linkname to implement the same feature. + +//go:linkname aeadAESGCMTLS13 crypto/tls.aeadAESGCMTLS13 +func aeadAESGCMTLS13(key, nonceMask []byte) cipher.AEAD diff --git a/common/protocol/quic/qtls_go119.go b/common/protocol/quic/qtls_go119.go deleted file mode 100644 index 4ab25af86..000000000 --- a/common/protocol/quic/qtls_go119.go +++ /dev/null @@ -1,18 +0,0 @@ -//go:build go1.19 && !go1.20 - -package quic - -import ( - "crypto/cipher" - - "github.com/quic-go/qtls-go1-19" -) - -type ( - // A CipherSuiteTLS13 is a cipher suite for TLS 1.3 - CipherSuiteTLS13 = qtls.CipherSuiteTLS13 -) - -func AEADAESGCMTLS13(key, fixedNonce []byte) cipher.AEAD { - return qtls.AEADAESGCMTLS13(key, fixedNonce) -} diff --git a/common/protocol/quic/qtls_go120.go b/common/protocol/quic/qtls_go120.go deleted file mode 100644 index e182c75b1..000000000 --- a/common/protocol/quic/qtls_go120.go +++ /dev/null @@ -1,18 +0,0 @@ -//go:build go1.20 - -package quic - -import ( - "crypto/cipher" - - "github.com/quic-go/qtls-go1-20" -) - -type ( - // A CipherSuiteTLS13 is a cipher suite for TLS 1.3 - CipherSuiteTLS13 = qtls.CipherSuiteTLS13 -) - -func AEADAESGCMTLS13(key, fixedNonce []byte) cipher.AEAD { - return qtls.AEADAESGCMTLS13(key, fixedNonce) -} diff --git a/common/protocol/quic/sniff.go b/common/protocol/quic/sniff.go index d88c2945c..f8fcd0ba1 100644 --- a/common/protocol/quic/sniff.go +++ b/common/protocol/quic/sniff.go @@ -37,10 +37,10 @@ const ( var ( quicSaltOld = []byte{0xaf, 0xbf, 0xec, 0x28, 0x99, 0x93, 0xd2, 0x4c, 0x9e, 0x97, 0x86, 0xf1, 0x9c, 0x61, 0x11, 0xe0, 0x43, 0x90, 0xa8, 0x99} quicSalt = []byte{0x38, 0x76, 0x2c, 0xf7, 0xf5, 0x59, 0x34, 0xb3, 0x4d, 0x17, 0x9a, 0xe6, 0xa4, 0xc8, 0x0c, 0xad, 0xcc, 0xbb, 0x7f, 0x0a} - initialSuite = &CipherSuiteTLS13{ + initialSuite = &cipherSuiteTLS13{ ID: tls.TLS_AES_128_GCM_SHA256, KeyLen: 16, - AEAD: AEADAESGCMTLS13, + AEAD: aeadAESGCMTLS13, Hash: crypto.SHA256, } errNotQuic = errors.New("not quic") @@ -153,7 +153,7 @@ func SniffQUIC(b []byte) (*SniffHeader, error) { key := hkdfExpandLabel(crypto.SHA256, secret, []byte{}, "quic key", 16) iv := hkdfExpandLabel(crypto.SHA256, secret, []byte{}, "quic iv", 12) - cipher := AEADAESGCMTLS13(key, iv) + cipher := aeadAESGCMTLS13(key, iv) nonce := cache.Extend(int32(cipher.NonceSize())) binary.BigEndian.PutUint64(nonce[len(nonce)-8:], uint64(packetNumber)) decrypted, err := cipher.Open(b[extHdrLen:extHdrLen], nonce, data, b[:extHdrLen]) diff --git a/go.mod b/go.mod index c4dd1a11a..7c7531964 100644 --- a/go.mod +++ b/go.mod @@ -16,8 +16,6 @@ require ( github.com/mustafaturan/bus v1.0.2 github.com/pelletier/go-toml v1.9.5 github.com/pires/go-proxyproto v0.7.0 - github.com/quic-go/qtls-go1-19 v0.3.2 - github.com/quic-go/qtls-go1-20 v0.3.0 github.com/quic-go/quic-go v0.36.2 github.com/refraction-networking/utls v1.3.2 github.com/seiflotfy/cuckoofilter v0.0.0-20220411075957-e3b120b3f5fb @@ -67,6 +65,8 @@ require ( github.com/pion/sctp v1.8.7 // indirect github.com/pion/transport/v2 v2.2.1 // indirect github.com/pmezard/go-difflib v1.0.0 // indirect + github.com/quic-go/qtls-go1-19 v0.3.2 // indirect + github.com/quic-go/qtls-go1-20 v0.2.2 // indirect github.com/riobard/go-bloom v0.0.0-20200614022211-cdc8013cb5b3 // indirect github.com/secure-io/siv-go v0.0.0-20180922214919-5ff40651e2c4 // indirect github.com/xtaci/smux v1.5.24 // indirect diff --git a/go.sum b/go.sum index fe5cee803..5a02ecb3a 100644 --- a/go.sum +++ b/go.sum @@ -262,6 +262,8 @@ github.com/prometheus/procfs v0.0.0-20190507164030-5867b95ac084/go.mod h1:TjEm7z github.com/prometheus/tsdb v0.7.1/go.mod h1:qhTCs0VvXwvX/y3TZrWD7rabWM+ijKTux40TwIPHuXU= github.com/quic-go/qtls-go1-19 v0.3.2 h1:tFxjCFcTQzK+oMxG6Zcvp4Dq8dx4yD3dDiIiyc86Z5U= github.com/quic-go/qtls-go1-19 v0.3.2/go.mod h1:ySOI96ew8lnoKPtSqx2BlI5wCpUVPT05RMAlajtnyOI= +github.com/quic-go/qtls-go1-20 v0.2.2 h1:WLOPx6OY/hxtTxKV1Zrq20FtXtDEkeY00CGQm8GEa3E= +github.com/quic-go/qtls-go1-20 v0.2.2/go.mod h1:JKtK6mjbAVcUTN/9jZpvLbGxvdWIKS8uT7EiStoU1SM= github.com/quic-go/qtls-go1-20 v0.3.0 h1:NrCXmDl8BddZwO67vlvEpBTwT89bJfKYygxv4HQvuDk= github.com/quic-go/qtls-go1-20 v0.3.0/go.mod h1:X9Nh97ZL80Z+bX/gUXMbipO6OxdiDi58b/fMC9mAL+k= github.com/quic-go/quic-go v0.36.2 h1:ZX/UNQ4gvpCv2RmwdbA6lrRjF6EBm5yZ7TMoT4NQVrA=