Restructure modules (#1572)
* Move portbase into monorepo * Add new simple module mgr * [WIP] Switch to new simple module mgr * Add StateMgr and more worker variants * [WIP] Switch more modules * [WIP] Switch more modules * [WIP] swtich more modules * [WIP] switch all SPN modules * [WIP] switch all service modules * [WIP] Convert all workers to the new module system * [WIP] add new task system to module manager * [WIP] Add second take for scheduling workers * [WIP] Add FIXME for bugs in new scheduler * [WIP] Add minor improvements to scheduler * [WIP] Add new worker scheduler * [WIP] Fix more bug related to new module system * [WIP] Fix start handing of the new module system * [WIP] Improve startup process * [WIP] Fix minor issues * [WIP] Fix missing subsystem in settings * [WIP] Initialize managers in constructor * [WIP] Move module event initialization to constrictors * [WIP] Fix setting for enabling and disabling the SPN module * [WIP] Move API registeration into module construction * [WIP] Update states mgr for all modules * [WIP] Add CmdLine operation support * Add state helper methods to module group and instance * Add notification and module status handling to status package * Fix starting issues * Remove pilot widget and update security lock to new status data * Remove debug logs * Improve http server shutdown * Add workaround for cleanly shutting down firewall+netquery * Improve logging * Add syncing states with notifications for new module system * Improve starting, stopping, shutdown; resolve FIXMEs/TODOs * [WIP] Fix most unit tests * Review new module system and fix minor issues * Push shutdown and restart events again via API * Set sleep mode via interface * Update example/template module * [WIP] Fix spn/cabin unit test * Remove deprecated UI elements * Make log output more similar for the logging transition phase * Switch spn hub and observer cmds to new module system * Fix log sources * Make worker mgr less error prone * Fix tests and minor issues * Fix observation hub * Improve shutdown and restart handling * Split up big connection.go source file * Move varint and dsd packages to structures repo * Improve expansion test * Fix linter warnings * Fix interception module on windows * Fix linter errors --------- Co-authored-by: Vladimir Stoilov <vladimir@safing.io>
This commit is contained in:
114
base/rng/rng.go
Normal file
114
base/rng/rng.go
Normal file
@@ -0,0 +1,114 @@
|
||||
package rng
|
||||
|
||||
import (
|
||||
"crypto/aes"
|
||||
"crypto/cipher"
|
||||
"crypto/rand"
|
||||
"errors"
|
||||
"fmt"
|
||||
"sync"
|
||||
"sync/atomic"
|
||||
|
||||
"github.com/aead/serpent"
|
||||
"github.com/seehuhn/fortuna"
|
||||
|
||||
"github.com/safing/portmaster/service/mgr"
|
||||
)
|
||||
|
||||
// Rng is a random number generator.
|
||||
type Rng struct {
|
||||
mgr *mgr.Manager
|
||||
|
||||
instance instance
|
||||
}
|
||||
|
||||
var (
|
||||
rng *fortuna.Generator
|
||||
rngLock sync.Mutex
|
||||
rngReady = false
|
||||
|
||||
rngCipher = "aes"
|
||||
// Possible values: "aes", "serpent".
|
||||
)
|
||||
|
||||
func newCipher(key []byte) (cipher.Block, error) {
|
||||
switch rngCipher {
|
||||
case "aes":
|
||||
return aes.NewCipher(key)
|
||||
case "serpent":
|
||||
return serpent.NewCipher(key)
|
||||
default:
|
||||
return nil, fmt.Errorf("unknown or unsupported cipher: %s", rngCipher)
|
||||
}
|
||||
}
|
||||
|
||||
// Manager returns the module manager.
|
||||
func (r *Rng) Manager() *mgr.Manager {
|
||||
return r.mgr
|
||||
}
|
||||
|
||||
// Start starts the module.
|
||||
func (r *Rng) Start() error {
|
||||
rngLock.Lock()
|
||||
defer rngLock.Unlock()
|
||||
|
||||
rng = fortuna.NewGenerator(newCipher)
|
||||
if rng == nil {
|
||||
return errors.New("failed to initialize rng")
|
||||
}
|
||||
|
||||
// add another (async) OS rng seed
|
||||
r.mgr.Go("initial rng feed", func(_ *mgr.WorkerCtx) error {
|
||||
// get entropy from OS
|
||||
osEntropy := make([]byte, minFeedEntropy/8)
|
||||
_, err := rand.Read(osEntropy)
|
||||
if err != nil {
|
||||
return fmt.Errorf("could not read entropy from os: %w", err)
|
||||
}
|
||||
// feed
|
||||
rngLock.Lock()
|
||||
rng.Reseed(osEntropy)
|
||||
rngLock.Unlock()
|
||||
return nil
|
||||
})
|
||||
|
||||
// mark as ready
|
||||
rngReady = true
|
||||
|
||||
// random source: OS
|
||||
r.mgr.Go("os rng feeder", osFeeder)
|
||||
|
||||
// random source: goroutine ticks
|
||||
r.mgr.Go("tick rng feeder", tickFeeder)
|
||||
|
||||
// full feeder
|
||||
r.mgr.Go("full feeder", fullFeeder)
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// Stop stops the module.
|
||||
func (r *Rng) Stop() error {
|
||||
return nil
|
||||
}
|
||||
|
||||
var (
|
||||
module *Rng
|
||||
shimLoaded atomic.Bool
|
||||
)
|
||||
|
||||
// New returns a new rng.
|
||||
func New(instance instance) (*Rng, error) {
|
||||
if !shimLoaded.CompareAndSwap(false, true) {
|
||||
return nil, errors.New("only one instance allowed")
|
||||
}
|
||||
m := mgr.New("Rng")
|
||||
module = &Rng{
|
||||
mgr: m,
|
||||
instance: instance,
|
||||
}
|
||||
|
||||
return module, nil
|
||||
}
|
||||
|
||||
type instance interface{}
|
||||
Reference in New Issue
Block a user