1 // Copyright (c) 2009-2010 Satoshi Nakamoto
2 // Copyright (c) 2009-present The Bitcoin Core developers
3 // Distributed under the MIT software license, see the accompanying
4 // file COPYING or http://www.opensource.org/licenses/mit-license.php.
5 6 #ifndef BITCOIN_NET_H
7 #define BITCOIN_NET_H
8 9 #include <bip324.h>
10 #include <chainparams.h>
11 #include <common/bloom.h>
12 #include <compat/compat.h>
13 #include <consensus/amount.h>
14 #include <crypto/siphash.h>
15 #include <hash.h>
16 #include <i2p.h>
17 #include <kernel/messagestartchars.h>
18 #include <net_permissions.h>
19 #include <netaddress.h>
20 #include <netbase.h>
21 #include <netgroup.h>
22 #include <node/connection_types.h>
23 #include <node/protocol_version.h>
24 #include <policy/feerate.h>
25 #include <protocol.h>
26 #include <random.h>
27 #include <semaphore_grant.h>
28 #include <span.h>
29 #include <streams.h>
30 #include <sync.h>
31 #include <uint256.h>
32 #include <util/check.h>
33 #include <util/sock.h>
34 #include <util/threadinterrupt.h>
35 36 #include <atomic>
37 #include <condition_variable>
38 #include <cstdint>
39 #include <deque>
40 #include <functional>
41 #include <list>
42 #include <map>
43 #include <memory>
44 #include <optional>
45 #include <queue>
46 #include <string_view>
47 #include <thread>
48 #include <unordered_set>
49 #include <vector>
50 51 class AddrMan;
52 class BanMan;
53 class CChainParams;
54 class CNode;
55 class CScheduler;
56 struct bilingual_str;
57 58 /** Time after which to disconnect, after waiting for a ping response (or inactivity). */
59 static constexpr std::chrono::minutes TIMEOUT_INTERVAL{20};
60 /** Run the feeler connection loop once every 2 minutes. **/
61 static constexpr auto FEELER_INTERVAL = 2min;
62 /** Run the extra block-relay-only connection loop once every 5 minutes. **/
63 static constexpr auto EXTRA_BLOCK_RELAY_ONLY_PEER_INTERVAL = 5min;
64 /** Maximum length of incoming protocol messages (no message over 4 MB is currently acceptable). */
65 static const unsigned int MAX_PROTOCOL_MESSAGE_LENGTH = 4 * 1000 * 1000;
66 /** Maximum length of the user agent string in `version` message */
67 static const unsigned int MAX_SUBVERSION_LENGTH = 256;
68 /** Maximum number of automatic outgoing nodes over which we'll relay everything (blocks, tx, addrs, etc) */
69 static const int MAX_OUTBOUND_FULL_RELAY_CONNECTIONS = 8;
70 /** Maximum number of addnode outgoing nodes */
71 static const int MAX_ADDNODE_CONNECTIONS = 8;
72 /** Maximum number of block-relay-only outgoing connections */
73 static const int MAX_BLOCK_RELAY_ONLY_CONNECTIONS = 2;
74 /** Maximum number of feeler connections */
75 static const int MAX_FEELER_CONNECTIONS = 1;
76 /** Maximum number of private broadcast connections */
77 static constexpr size_t MAX_PRIVATE_BROADCAST_CONNECTIONS{64};
78 /** -listen default */
79 static const bool DEFAULT_LISTEN = true;
80 /** The maximum number of peer connections to maintain. */
81 static const unsigned int DEFAULT_MAX_PEER_CONNECTIONS = 125;
82 /** The default for -maxuploadtarget. 0 = Unlimited */
83 static const std::string DEFAULT_MAX_UPLOAD_TARGET{"0M"};
84 /** Default for blocks only*/
85 static const bool DEFAULT_BLOCKSONLY = false;
86 /** -peertimeout default */
87 static const int64_t DEFAULT_PEER_CONNECT_TIMEOUT = 60;
88 /** Default for -privatebroadcast. */
89 static constexpr bool DEFAULT_PRIVATE_BROADCAST{false};
90 /** Number of file descriptors required for message capture **/
91 static const int NUM_FDS_MESSAGE_CAPTURE = 1;
92 /** Interval for ASMap Health Check **/
93 static constexpr std::chrono::hours ASMAP_HEALTH_CHECK_INTERVAL{24};
94 95 static constexpr bool DEFAULT_FORCEDNSSEED{false};
96 static constexpr bool DEFAULT_DNSSEED{true};
97 static constexpr bool DEFAULT_FIXEDSEEDS{true};
98 static const size_t DEFAULT_MAXRECEIVEBUFFER = 5 * 1000;
99 static const size_t DEFAULT_MAXSENDBUFFER = 1 * 1000;
100 101 static constexpr bool DEFAULT_V2_TRANSPORT{true};
102 103 typedef int64_t NodeId;
104 105 struct AddedNodeParams {
106 std::string m_added_node;
107 bool m_use_v2transport;
108 };
109 110 struct AddedNodeInfo {
111 AddedNodeParams m_params;
112 CService resolvedAddress;
113 bool fConnected;
114 bool fInbound;
115 };
116 117 class CNodeStats;
118 class CClientUIInterface;
119 120 struct CSerializedNetMsg {
121 CSerializedNetMsg() = default;
122 CSerializedNetMsg(CSerializedNetMsg&&) = default;
123 CSerializedNetMsg& operator=(CSerializedNetMsg&&) = default;
124 // No implicit copying, only moves.
125 CSerializedNetMsg(const CSerializedNetMsg& msg) = delete;
126 CSerializedNetMsg& operator=(const CSerializedNetMsg&) = delete;
127 128 CSerializedNetMsg Copy() const
129 {
130 CSerializedNetMsg copy;
131 copy.data = data;
132 copy.m_type = m_type;
133 return copy;
134 }
135 136 std::vector<unsigned char> data;
137 std::string m_type;
138 139 /** Compute total memory usage of this object (own memory + any dynamic memory). */
140 size_t GetMemoryUsage() const noexcept;
141 };
142 143 /**
144 * Look up IP addresses from all interfaces on the machine and add them to the
145 * list of local addresses to self-advertise.
146 * The loopback interface is skipped.
147 */
148 void Discover();
149 150 uint16_t GetListenPort();
151 152 enum
153 {
154 LOCAL_NONE, // unknown
155 LOCAL_IF, // address a local interface listens on
156 LOCAL_BIND, // address explicit bound to
157 LOCAL_MAPPED, // address reported by PCP
158 LOCAL_MANUAL, // address explicitly specified (-externalip=)
159 160 LOCAL_MAX
161 };
162 163 /** Returns a local address that we should advertise to this peer. */
164 std::optional<CService> GetLocalAddrForPeer(CNode& node);
165 166 void ClearLocal();
167 bool AddLocal(const CService& addr, int nScore = LOCAL_NONE);
168 bool AddLocal(const CNetAddr& addr, int nScore = LOCAL_NONE);
169 void RemoveLocal(const CService& addr);
170 bool SeenLocal(const CService& addr);
171 bool IsLocal(const CService& addr);
172 CService GetLocalAddress(const CNode& peer);
173 174 extern bool fDiscover;
175 extern bool fListen;
176 177 /** Subversion as sent to the P2P network in `version` messages */
178 extern std::string strSubVersion;
179 180 struct LocalServiceInfo {
181 int nScore;
182 uint16_t nPort;
183 };
184 185 extern GlobalMutex g_maplocalhost_mutex;
186 extern std::map<CNetAddr, LocalServiceInfo> mapLocalHost GUARDED_BY(g_maplocalhost_mutex);
187 188 extern const std::string NET_MESSAGE_TYPE_OTHER;
189 using mapMsgTypeSize = std::map</* message type */ std::string, /* total bytes */ uint64_t>;
190 191 class CNodeStats
192 {
193 public:
194 NodeId nodeid;
195 NodeClock::time_point m_last_send;
196 NodeClock::time_point m_last_recv;
197 std::chrono::seconds m_last_tx_time;
198 std::chrono::seconds m_last_block_time;
199 NodeClock::time_point m_connected;
200 std::string m_addr_name;
201 int nVersion;
202 std::string cleanSubVer;
203 bool fInbound;
204 // We requested high bandwidth connection to peer
205 bool m_bip152_highbandwidth_to;
206 // Peer requested high bandwidth connection
207 bool m_bip152_highbandwidth_from;
208 uint64_t nSendBytes;
209 mapMsgTypeSize mapSendBytesPerMsgType;
210 uint64_t nRecvBytes;
211 mapMsgTypeSize mapRecvBytesPerMsgType;
212 NetPermissionFlags m_permission_flags;
213 NodeClock::duration m_last_ping_time;
214 NodeClock::duration m_min_ping_time;
215 // Our address, as reported by the peer
216 std::string addrLocal;
217 // Address of this peer
218 CAddress addr;
219 // Bind address of our side of the connection
220 CService addrBind;
221 // Network the peer connected through
222 Network m_network;
223 uint32_t m_mapped_as;
224 ConnectionType m_conn_type;
225 /** Transport protocol type. */
226 TransportProtocolType m_transport_type;
227 /** BIP324 session id string in hex, if any. */
228 std::string m_session_id;
229 };
230 231 232 /** Transport protocol agnostic message container.
233 * Ideally it should only contain receive time, payload,
234 * type and size.
235 */
236 class CNetMessage
237 {
238 public:
239 DataStream m_recv; //!< received message data
240 /// time of message receipt
241 NodeClock::time_point m_time{NodeClock::epoch};
242 uint32_t m_message_size{0}; //!< size of the payload
243 uint32_t m_raw_message_size{0}; //!< used wire size of the message (including header/checksum)
244 std::string m_type;
245 246 explicit CNetMessage(DataStream&& recv_in) : m_recv(std::move(recv_in)) {}
247 // Only one CNetMessage object will exist for the same message on either
248 // the receive or processing queue. For performance reasons we therefore
249 // delete the copy constructor and assignment operator to avoid the
250 // possibility of copying CNetMessage objects.
251 CNetMessage(CNetMessage&&) = default;
252 CNetMessage(const CNetMessage&) = delete;
253 CNetMessage& operator=(CNetMessage&&) = default;
254 CNetMessage& operator=(const CNetMessage&) = delete;
255 256 /** Compute total memory usage of this object (own memory + any dynamic memory). */
257 size_t GetMemoryUsage() const noexcept;
258 };
259 260 /** The Transport converts one connection's sent messages to wire bytes, and received bytes back. */
261 class Transport {
262 public:
263 virtual ~Transport() = default;
264 265 struct Info
266 {
267 TransportProtocolType transport_type;
268 std::optional<uint256> session_id;
269 };
270 271 /** Retrieve information about this transport. */
272 virtual Info GetInfo() const noexcept = 0;
273 274 // 1. Receiver side functions, for decoding bytes received on the wire into transport protocol
275 // agnostic CNetMessage (message type & payload) objects.
276 277 /** Returns true if the current message is complete (so GetReceivedMessage can be called). */
278 virtual bool ReceivedMessageComplete() const = 0;
279 280 /** Feed wire bytes to the transport.
281 *
282 * @return false if some bytes were invalid, in which case the transport can't be used anymore.
283 *
284 * Consumed bytes are chopped off the front of msg_bytes.
285 */
286 virtual bool ReceivedBytes(std::span<const uint8_t>& msg_bytes) = 0;
287 288 /** Retrieve a completed message from transport.
289 *
290 * This can only be called when ReceivedMessageComplete() is true.
291 *
292 * If reject_message=true is returned the message itself is invalid, but (other than false
293 * returned by ReceivedBytes) the transport is not in an inconsistent state.
294 */
295 virtual CNetMessage GetReceivedMessage(NodeClock::time_point time, bool& reject_message) = 0;
296 297 // 2. Sending side functions, for converting messages into bytes to be sent over the wire.
298 299 /** Set the next message to send.
300 *
301 * If no message can currently be set (perhaps because the previous one is not yet done being
302 * sent), returns false, and msg will be unmodified. Otherwise msg is enqueued (and
303 * possibly moved-from) and true is returned.
304 */
305 virtual bool SetMessageToSend(CSerializedNetMsg& msg) noexcept = 0;
306 307 /** Return type for GetBytesToSend, consisting of:
308 * - std::span<const uint8_t> to_send: span of bytes to be sent over the wire (possibly empty).
309 * - bool more: whether there will be more bytes to be sent after the ones in to_send are
310 * all sent (as signaled by MarkBytesSent()).
311 * - const std::string& m_type: message type on behalf of which this is being sent
312 * ("" for bytes that are not on behalf of any message).
313 */
314 using BytesToSend = std::tuple<
315 std::span<const uint8_t> /*to_send*/,
316 bool /*more*/,
317 const std::string& /*m_type*/
318 >;
319 320 /** Get bytes to send on the wire, if any, along with other information about it.
321 *
322 * As a const function, it does not modify the transport's observable state, and is thus safe
323 * to be called multiple times.
324 *
325 * @param[in] have_next_message If true, the "more" return value reports whether more will
326 * be sendable after a SetMessageToSend call. It is set by the caller when they know
327 * they have another message ready to send, and only care about what happens
328 * after that. The have_next_message argument only affects this "more" return value
329 * and nothing else.
330 *
331 * Effectively, there are three possible outcomes about whether there are more bytes
332 * to send:
333 * - Yes: the transport itself has more bytes to send later. For example, for
334 * V1Transport this happens during the sending of the header of a
335 * message, when there is a non-empty payload that follows.
336 * - No: the transport itself has no more bytes to send, but will have bytes to
337 * send if handed a message through SetMessageToSend. In V1Transport this
338 * happens when sending the payload of a message.
339 * - Blocked: the transport itself has no more bytes to send, and is also incapable
340 * of sending anything more at all now, if it were handed another
341 * message to send. This occurs in V2Transport before the handshake is
342 * complete, as the encryption ciphers are not set up for sending
343 * messages before that point.
344 *
345 * The boolean 'more' is true for Yes, false for Blocked, and have_next_message
346 * controls what is returned for No.
347 *
348 * @return a BytesToSend object. The to_send member returned acts as a stream which is only
349 * ever appended to. This means that with the exception of MarkBytesSent (which pops
350 * bytes off the front of later to_sends), operations on the transport can only append
351 * to what is being returned. Also note that m_type and to_send refer to data that is
352 * internal to the transport, and calling any non-const function on this object may
353 * invalidate them.
354 */
355 virtual BytesToSend GetBytesToSend(bool have_next_message) const noexcept = 0;
356 357 /** Report how many bytes returned by the last GetBytesToSend() have been sent.
358 *
359 * bytes_sent cannot exceed to_send.size() of the last GetBytesToSend() result.
360 *
361 * If bytes_sent=0, this call has no effect.
362 */
363 virtual void MarkBytesSent(size_t bytes_sent) noexcept = 0;
364 365 /** Return the memory usage of this transport attributable to buffered data to send. */
366 virtual size_t GetSendMemoryUsage() const noexcept = 0;
367 368 // 3. Miscellaneous functions.
369 370 /** Whether upon disconnections, a reconnect with V1 is warranted. */
371 virtual bool ShouldReconnectV1() const noexcept = 0;
372 };
373 374 class V1Transport final : public Transport
375 {
376 private:
377 const MessageStartChars m_magic_bytes;
378 const NodeId m_node_id; // Only for logging
379 mutable Mutex m_recv_mutex; //!< Lock for receive state
380 mutable CHash256 hasher GUARDED_BY(m_recv_mutex);
381 mutable uint256 data_hash GUARDED_BY(m_recv_mutex);
382 bool in_data GUARDED_BY(m_recv_mutex); // parsing header (false) or data (true)
383 DataStream hdrbuf GUARDED_BY(m_recv_mutex){}; // partially received header
384 CMessageHeader hdr GUARDED_BY(m_recv_mutex); // complete header
385 DataStream vRecv GUARDED_BY(m_recv_mutex){}; // received message data
386 unsigned int nHdrPos GUARDED_BY(m_recv_mutex);
387 unsigned int nDataPos GUARDED_BY(m_recv_mutex);
388 389 const uint256& GetMessageHash() const EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex);
390 int readHeader(std::span<const uint8_t> msg_bytes) EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex);
391 int readData(std::span<const uint8_t> msg_bytes) EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex);
392 393 void Reset() EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex) {
394 AssertLockHeld(m_recv_mutex);
395 vRecv.clear();
396 hdrbuf.clear();
397 hdrbuf.resize(24);
398 in_data = false;
399 nHdrPos = 0;
400 nDataPos = 0;
401 data_hash.SetNull();
402 hasher.Reset();
403 }
404 405 bool CompleteInternal() const noexcept EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex)
406 {
407 AssertLockHeld(m_recv_mutex);
408 if (!in_data) return false;
409 return hdr.nMessageSize == nDataPos;
410 }
411 412 /** Lock for sending state. */
413 mutable Mutex m_send_mutex;
414 /** The header of the message currently being sent. */
415 std::vector<uint8_t> m_header_to_send GUARDED_BY(m_send_mutex);
416 /** The data of the message currently being sent. */
417 CSerializedNetMsg m_message_to_send GUARDED_BY(m_send_mutex);
418 /** Whether we're currently sending header bytes or message bytes. */
419 bool m_sending_header GUARDED_BY(m_send_mutex) {false};
420 /** How many bytes have been sent so far (from m_header_to_send, or from m_message_to_send.data). */
421 size_t m_bytes_sent GUARDED_BY(m_send_mutex) {0};
422 423 public:
424 explicit V1Transport(NodeId node_id) noexcept;
425 426 bool ReceivedMessageComplete() const override EXCLUSIVE_LOCKS_REQUIRED(!m_recv_mutex)
427 {
428 AssertLockNotHeld(m_recv_mutex);
429 return WITH_LOCK(m_recv_mutex, return CompleteInternal());
430 }
431 432 Info GetInfo() const noexcept override;
433 434 bool ReceivedBytes(std::span<const uint8_t>& msg_bytes) override EXCLUSIVE_LOCKS_REQUIRED(!m_recv_mutex)
435 {
436 AssertLockNotHeld(m_recv_mutex);
437 LOCK(m_recv_mutex);
438 int ret = in_data ? readData(msg_bytes) : readHeader(msg_bytes);
439 if (ret < 0) {
440 Reset();
441 } else {
442 msg_bytes = msg_bytes.subspan(ret);
443 }
444 return ret >= 0;
445 }
446 447 CNetMessage GetReceivedMessage(NodeClock::time_point time, bool& reject_message) override EXCLUSIVE_LOCKS_REQUIRED(!m_recv_mutex);
448 449 bool SetMessageToSend(CSerializedNetMsg& msg) noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_send_mutex);
450 BytesToSend GetBytesToSend(bool have_next_message) const noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_send_mutex);
451 void MarkBytesSent(size_t bytes_sent) noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_send_mutex);
452 size_t GetSendMemoryUsage() const noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_send_mutex);
453 bool ShouldReconnectV1() const noexcept override { return false; }
454 };
455 456 class V2Transport final : public Transport
457 {
458 private:
459 /** Contents of the version packet to send. BIP324 stipulates that senders should leave this
460 * empty, and receivers should ignore it. Future extensions can change what is sent as long as
461 * an empty version packet contents is interpreted as no extensions supported. */
462 static constexpr std::array<std::byte, 0> VERSION_CONTENTS = {};
463 464 /** The length of the V1 prefix to match bytes initially received by responders with to
465 * determine if their peer is speaking V1 or V2. */
466 static constexpr size_t V1_PREFIX_LEN = 16;
467 468 // The sender side and receiver side of V2Transport are state machines that are transitioned
469 // through, based on what has been received. The receive state corresponds to the contents of,
470 // and bytes received to, the receive buffer. The send state controls what can be appended to
471 // the send buffer and what can be sent from it.
472 473 /** State type that defines the current contents of the receive buffer and/or how the next
474 * received bytes added to it will be interpreted.
475 *
476 * Diagram:
477 *
478 * start(responder)
479 * |
480 * | start(initiator) /---------\
481 * | | | |
482 * v v v |
483 * KEY_MAYBE_V1 -> KEY -> GARB_GARBTERM -> VERSION -> APP -> APP_READY
484 * |
485 * \-------> V1
486 */
487 enum class RecvState : uint8_t {
488 /** (Responder only) either v2 public key or v1 header.
489 *
490 * This is the initial state for responders, before data has been received to distinguish
491 * v1 from v2 connections. When that happens, the state becomes either KEY (for v2) or V1
492 * (for v1). */
493 KEY_MAYBE_V1,
494 495 /** Public key.
496 *
497 * This is the initial state for initiators, during which the other side's public key is
498 * received. When that information arrives, the ciphers get initialized and the state
499 * becomes GARB_GARBTERM. */
500 KEY,
501 502 /** Garbage and garbage terminator.
503 *
504 * Whenever a byte is received, the last 16 bytes are compared with the expected garbage
505 * terminator. When that happens, the state becomes VERSION. If no matching terminator is
506 * received in 4111 bytes (4095 for the maximum garbage length, and 16 bytes for the
507 * terminator), the connection aborts. */
508 GARB_GARBTERM,
509 510 /** Version packet.
511 *
512 * A packet is received, and decrypted/verified. If that fails, the connection aborts. The
513 * first received packet in this state (whether it's a decoy or not) is expected to
514 * authenticate the garbage received during the GARB_GARBTERM state as associated
515 * authenticated data (AAD). The first non-decoy packet in this state is interpreted as
516 * version negotiation (currently, that means ignoring the contents, but it can be used for
517 * negotiating future extensions), and afterwards the state becomes APP. */
518 VERSION,
519 520 /** Application packet.
521 *
522 * A packet is received, and decrypted/verified. If that succeeds, the state becomes
523 * APP_READY and the decrypted contents is kept in m_recv_decode_buffer until it is
524 * retrieved as a message by GetMessage(). */
525 APP,
526 527 /** Nothing (an application packet is available for GetMessage()).
528 *
529 * Nothing can be received in this state. When the message is retrieved by GetMessage,
530 * the state becomes APP again. */
531 APP_READY,
532 533 /** Nothing (this transport is using v1 fallback).
534 *
535 * All receive operations are redirected to m_v1_fallback. */
536 V1,
537 };
538 539 /** State type that controls the sender side.
540 *
541 * Diagram:
542 *
543 * start(responder)
544 * |
545 * | start(initiator)
546 * | |
547 * v v
548 * MAYBE_V1 -> AWAITING_KEY -> READY
549 * |
550 * \-----> V1
551 */
552 enum class SendState : uint8_t {
553 /** (Responder only) Not sending until v1 or v2 is detected.
554 *
555 * This is the initial state for responders. The send buffer is empty.
556 * When the receiver determines whether this
557 * is a V1 or V2 connection, the sender state becomes AWAITING_KEY (for v2) or V1 (for v1).
558 */
559 MAYBE_V1,
560 561 /** Waiting for the other side's public key.
562 *
563 * This is the initial state for initiators. The public key and garbage is sent out. When
564 * the receiver receives the other side's public key and transitions to GARB_GARBTERM, the
565 * sender state becomes READY. */
566 AWAITING_KEY,
567 568 /** Normal sending state.
569 *
570 * In this state, the ciphers are initialized, so packets can be sent. When this state is
571 * entered, the garbage terminator and version packet are appended to the send buffer (in
572 * addition to the key and garbage which may still be there). In this state a message can be
573 * provided if the send buffer is empty. */
574 READY,
575 576 /** This transport is using v1 fallback.
577 *
578 * All send operations are redirected to m_v1_fallback. */
579 V1,
580 };
581 582 /** Cipher state. */
583 BIP324Cipher m_cipher;
584 /** Whether we are the initiator side. */
585 const bool m_initiating;
586 /** NodeId (for debug logging). */
587 const NodeId m_nodeid;
588 /** Encapsulate a V1Transport to fall back to. */
589 V1Transport m_v1_fallback;
590 591 /** Lock for receiver-side fields. */
592 mutable Mutex m_recv_mutex ACQUIRED_BEFORE(m_send_mutex);
593 /** In {VERSION, APP}, the decrypted packet length, if m_recv_buffer.size() >=
594 * BIP324Cipher::LENGTH_LEN. Unspecified otherwise. */
595 uint32_t m_recv_len GUARDED_BY(m_recv_mutex) {0};
596 /** Receive buffer; meaning is determined by m_recv_state. */
597 std::vector<uint8_t> m_recv_buffer GUARDED_BY(m_recv_mutex);
598 /** AAD expected in next received packet (currently used only for garbage). */
599 std::vector<uint8_t> m_recv_aad GUARDED_BY(m_recv_mutex);
600 /** Buffer to put decrypted contents in, for converting to CNetMessage. */
601 std::vector<uint8_t> m_recv_decode_buffer GUARDED_BY(m_recv_mutex);
602 /** Current receiver state. */
603 RecvState m_recv_state GUARDED_BY(m_recv_mutex);
604 605 /** Lock for sending-side fields. If both sending and receiving fields are accessed,
606 * m_recv_mutex must be acquired before m_send_mutex. */
607 mutable Mutex m_send_mutex ACQUIRED_AFTER(m_recv_mutex);
608 /** The send buffer; meaning is determined by m_send_state. */
609 std::vector<uint8_t> m_send_buffer GUARDED_BY(m_send_mutex);
610 /** How many bytes from the send buffer have been sent so far. */
611 uint32_t m_send_pos GUARDED_BY(m_send_mutex) {0};
612 /** The garbage sent, or to be sent (MAYBE_V1 and AWAITING_KEY state only). */
613 std::vector<uint8_t> m_send_garbage GUARDED_BY(m_send_mutex);
614 /** Type of the message being sent. */
615 std::string m_send_type GUARDED_BY(m_send_mutex);
616 /** Current sender state. */
617 SendState m_send_state GUARDED_BY(m_send_mutex);
618 /** Whether we've sent at least 24 bytes (which would trigger disconnect for V1 peers). */
619 bool m_sent_v1_header_worth GUARDED_BY(m_send_mutex) {false};
620 621 /** Change the receive state. */
622 void SetReceiveState(RecvState recv_state) noexcept EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex);
623 /** Change the send state. */
624 void SetSendState(SendState send_state) noexcept EXCLUSIVE_LOCKS_REQUIRED(m_send_mutex);
625 /** Given a packet's contents, find the message type (if valid), and strip it from contents. */
626 static std::optional<std::string> GetMessageType(std::span<const uint8_t>& contents) noexcept;
627 /** Determine how many received bytes can be processed in one go (not allowed in V1 state). */
628 size_t GetMaxBytesToProcess() noexcept EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex);
629 /** Put our public key + garbage in the send buffer. */
630 void StartSendingHandshake() noexcept EXCLUSIVE_LOCKS_REQUIRED(m_send_mutex);
631 /** Process bytes in m_recv_buffer, while in KEY_MAYBE_V1 state. */
632 void ProcessReceivedMaybeV1Bytes() noexcept EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex, !m_send_mutex);
633 /** Process bytes in m_recv_buffer, while in KEY state. */
634 bool ProcessReceivedKeyBytes() noexcept EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex, !m_send_mutex);
635 /** Process bytes in m_recv_buffer, while in GARB_GARBTERM state. */
636 bool ProcessReceivedGarbageBytes() noexcept EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex);
637 /** Process bytes in m_recv_buffer, while in VERSION/APP state. */
638 bool ProcessReceivedPacketBytes() noexcept EXCLUSIVE_LOCKS_REQUIRED(m_recv_mutex);
639 640 public:
641 static constexpr uint32_t MAX_GARBAGE_LEN = 4095;
642 643 /** Construct a V2 transport with securely generated random keys.
644 *
645 * @param[in] nodeid the node's NodeId (only for debug log output).
646 * @param[in] initiating whether we are the initiator side.
647 */
648 V2Transport(NodeId nodeid, bool initiating) noexcept;
649 650 /** Construct a V2 transport with specified keys and garbage (test use only). */
651 V2Transport(NodeId nodeid, bool initiating, const CKey& key, std::span<const std::byte> ent32, std::vector<uint8_t> garbage) noexcept;
652 653 // Receive side functions.
654 bool ReceivedMessageComplete() const noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_recv_mutex);
655 bool ReceivedBytes(std::span<const uint8_t>& msg_bytes) noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_recv_mutex, !m_send_mutex);
656 CNetMessage GetReceivedMessage(NodeClock::time_point time, bool& reject_message) noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_recv_mutex);
657 658 // Send side functions.
659 bool SetMessageToSend(CSerializedNetMsg& msg) noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_send_mutex);
660 BytesToSend GetBytesToSend(bool have_next_message) const noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_send_mutex);
661 void MarkBytesSent(size_t bytes_sent) noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_send_mutex);
662 size_t GetSendMemoryUsage() const noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_send_mutex);
663 664 // Miscellaneous functions.
665 bool ShouldReconnectV1() const noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_recv_mutex, !m_send_mutex);
666 Info GetInfo() const noexcept override EXCLUSIVE_LOCKS_REQUIRED(!m_recv_mutex);
667 };
668 669 struct CNodeOptions
670 {
671 NetPermissionFlags permission_flags = NetPermissionFlags::None;
672 std::optional<Proxy> proxy_override = {};
673 std::unique_ptr<i2p::sam::Session> i2p_sam_session = nullptr;
674 bool prefer_evict = false;
675 size_t recv_flood_size{DEFAULT_MAXRECEIVEBUFFER * 1000};
676 bool use_v2transport = false;
677 };
678 679 /** Information about a peer */
680 class CNode
681 {
682 public:
683 /** Transport serializer/deserializer. The receive side functions are only called under cs_vRecv, while
684 * the sending side functions are only called under cs_vSend. */
685 const std::unique_ptr<Transport> m_transport;
686 687 const NetPermissionFlags m_permission_flags;
688 689 /**
690 * Socket used for communication with the node.
691 * May not own a Sock object (after `CloseSocketDisconnect()` or during tests).
692 * `shared_ptr` (instead of `unique_ptr`) is used to avoid premature close of
693 * the underlying file descriptor by one thread while another thread is
694 * poll(2)-ing it for activity.
695 * @see https://github.com/bitcoin/bitcoin/issues/21744 for details.
696 */
697 std::shared_ptr<Sock> m_sock GUARDED_BY(m_sock_mutex);
698 699 /** Sum of GetMemoryUsage of all vSendMsg entries. */
700 size_t m_send_memusage GUARDED_BY(cs_vSend){0};
701 /** Total number of bytes sent on the wire to this peer. */
702 uint64_t nSendBytes GUARDED_BY(cs_vSend){0};
703 /** Messages still to be fed to m_transport->SetMessageToSend. */
704 std::deque<CSerializedNetMsg> vSendMsg GUARDED_BY(cs_vSend);
705 Mutex cs_vSend;
706 Mutex m_sock_mutex;
707 Mutex cs_vRecv;
708 709 uint64_t nRecvBytes GUARDED_BY(cs_vRecv){0};
710 711 std::atomic<NodeClock::time_point> m_last_send{NodeClock::epoch};
712 std::atomic<NodeClock::time_point> m_last_recv{NodeClock::epoch};
713 //! Unix epoch time at peer connection
714 const NodeClock::time_point m_connected;
715 716 //! Proxy to use regardless of global proxy settings if reconnecting to this node.
717 const std::optional<Proxy> m_proxy_override;
718 719 // Address of this peer
720 const CAddress addr;
721 // Bind address of our side of the connection
722 const CService addrBind;
723 const std::string m_addr_name;
724 /** The pszDest argument provided to ConnectNode(). Only used for reconnections. */
725 const std::string m_dest;
726 //! Whether this peer is an inbound onion, i.e. connected via our Tor onion service.
727 const bool m_inbound_onion;
728 std::atomic<int> nVersion{0};
729 Mutex m_subver_mutex;
730 /**
731 * cleanSubVer is a sanitized string of the user agent byte array we read
732 * from the wire. This cleaned string can safely be logged or displayed.
733 */
734 std::string cleanSubVer GUARDED_BY(m_subver_mutex){};
735 const bool m_prefer_evict{false}; // This peer is preferred for eviction.
736 bool HasPermission(NetPermissionFlags permission) const {
737 return NetPermissions::HasFlag(m_permission_flags, permission);
738 }
739 /** fSuccessfullyConnected is set to true on receiving VERACK from the peer. */
740 std::atomic_bool fSuccessfullyConnected{false};
741 // Setting fDisconnect to true will cause the node to be disconnected the
742 // next time DisconnectNodes() runs
743 std::atomic_bool fDisconnect{false};
744 CountingSemaphoreGrant<> grantOutbound;
745 std::atomic<int> nRefCount{0};
746 747 const uint64_t nKeyedNetGroup;
748 std::atomic_bool fPauseRecv{false};
749 std::atomic_bool fPauseSend{false};
750 751 /** Network key used to prevent fingerprinting our node across networks.
752 * Influenced by the network and the bind address (+ bind port for inbounds) */
753 const uint64_t m_network_key;
754 755 const ConnectionType m_conn_type;
756 757 /** Move all messages from the received queue to the processing queue. */
758 void MarkReceivedMsgsForProcessing()
759 EXCLUSIVE_LOCKS_REQUIRED(!m_msg_process_queue_mutex);
760 761 /** Poll the next message from the processing queue of this connection.
762 *
763 * Returns std::nullopt if the processing queue is empty, or a pair
764 * consisting of the message and a bool that indicates if the processing
765 * queue has more entries. */
766 std::optional<std::pair<CNetMessage, bool>> PollMessage()
767 EXCLUSIVE_LOCKS_REQUIRED(!m_msg_process_queue_mutex);
768 769 /** Account for the total size of a sent message in the per msg type connection stats. */
770 void AccountForSentBytes(const std::string& msg_type, size_t sent_bytes)
771 EXCLUSIVE_LOCKS_REQUIRED(cs_vSend)
772 {
773 mapSendBytesPerMsgType[msg_type] += sent_bytes;
774 }
775 776 bool IsOutboundOrBlockRelayConn() const {
777 switch (m_conn_type) {
778 case ConnectionType::OUTBOUND_FULL_RELAY:
779 case ConnectionType::BLOCK_RELAY:
780 return true;
781 case ConnectionType::INBOUND:
782 case ConnectionType::MANUAL:
783 case ConnectionType::ADDR_FETCH:
784 case ConnectionType::FEELER:
785 case ConnectionType::PRIVATE_BROADCAST:
786 return false;
787 } // no default case, so the compiler can warn about missing cases
788 789 assert(false);
790 }
791 792 bool IsFullOutboundConn() const {
793 return m_conn_type == ConnectionType::OUTBOUND_FULL_RELAY;
794 }
795 796 bool IsManualConn() const {
797 return m_conn_type == ConnectionType::MANUAL;
798 }
799 800 bool IsManualOrFullOutboundConn() const
801 {
802 switch (m_conn_type) {
803 case ConnectionType::INBOUND:
804 case ConnectionType::FEELER:
805 case ConnectionType::BLOCK_RELAY:
806 case ConnectionType::ADDR_FETCH:
807 case ConnectionType::PRIVATE_BROADCAST:
808 return false;
809 case ConnectionType::OUTBOUND_FULL_RELAY:
810 case ConnectionType::MANUAL:
811 return true;
812 } // no default case, so the compiler can warn about missing cases
813 814 assert(false);
815 }
816 817 bool IsBlockOnlyConn() const {
818 return m_conn_type == ConnectionType::BLOCK_RELAY;
819 }
820 821 bool IsFeelerConn() const {
822 return m_conn_type == ConnectionType::FEELER;
823 }
824 825 bool IsAddrFetchConn() const {
826 return m_conn_type == ConnectionType::ADDR_FETCH;
827 }
828 829 bool IsPrivateBroadcastConn() const
830 {
831 return m_conn_type == ConnectionType::PRIVATE_BROADCAST;
832 }
833 834 /** Protocol version advertised in our VERSION message.
835 * Private broadcast connections use a fixed version to maximise anonymity. */
836 int AdvertisedVersion() const
837 {
838 return IsPrivateBroadcastConn() ? WTXID_RELAY_VERSION : PROTOCOL_VERSION;
839 }
840 841 bool IsInboundConn() const {
842 return m_conn_type == ConnectionType::INBOUND;
843 }
844 845 bool ExpectServicesFromConn() const {
846 switch (m_conn_type) {
847 case ConnectionType::INBOUND:
848 case ConnectionType::MANUAL:
849 case ConnectionType::FEELER:
850 return false;
851 case ConnectionType::OUTBOUND_FULL_RELAY:
852 case ConnectionType::BLOCK_RELAY:
853 case ConnectionType::ADDR_FETCH:
854 case ConnectionType::PRIVATE_BROADCAST:
855 return true;
856 } // no default case, so the compiler can warn about missing cases
857 858 assert(false);
859 }
860 861 /**
862 * Get network the peer connected through.
863 *
864 * Returns Network::NET_ONION for *inbound* onion connections,
865 * and CNetAddr::GetNetClass() otherwise. The latter cannot be used directly
866 * because it doesn't detect the former, and it's not the responsibility of
867 * the CNetAddr class to know the actual network a peer is connected through.
868 *
869 * @return network the peer connected through.
870 */
871 Network ConnectedThroughNetwork() const;
872 873 /** Whether this peer connected through a privacy network. */
874 [[nodiscard]] bool IsConnectedThroughPrivacyNet() const;
875 876 // We selected peer as (compact blocks) high-bandwidth peer (BIP152)
877 std::atomic<bool> m_bip152_highbandwidth_to{false};
878 // Peer selected us as (compact blocks) high-bandwidth peer (BIP152)
879 std::atomic<bool> m_bip152_highbandwidth_from{false};
880 881 /** Whether this peer provides all services that we want. Used for eviction decisions */
882 std::atomic_bool m_has_all_wanted_services{false};
883 884 /** Whether we should relay transactions to this peer. This only changes
885 * from false to true. It will never change back to false. */
886 std::atomic_bool m_relays_txs{false};
887 888 /** Whether this peer has loaded a bloom filter. Used only in inbound
889 * eviction logic. */
890 std::atomic_bool m_bloom_filter_loaded{false};
891 892 /// UNIX epoch time of the last block received from this peer that we had
893 /// not yet seen (e.g. not already received from another peer), that passed
894 /// preliminary validity checks and was saved to disk, even if we don't
895 /// connect the block or it eventually fails to connect. Used as an inbound
896 /// peer eviction criterion in CConnman::AttemptToEvictConnection.
897 std::atomic<std::chrono::seconds> m_last_block_time{0s};
898 899 /// UNIX epoch time of the last transaction received from this peer that we
900 /// had not yet seen (e.g. not already received from another peer) and that
901 /// was accepted into our mempool. Used as an inbound peer eviction criterion
902 /// in CConnman::AttemptToEvictConnection.
903 std::atomic<std::chrono::seconds> m_last_tx_time{0s};
904 905 /// Last measured round-trip duration. Used only for stats.
906 std::atomic<NodeClock::duration> m_last_ping_time{0us};
907 908 /// Lowest measured round-trip duration. Used as an inbound peer eviction
909 /// criterion in CConnman::AttemptToEvictConnection.
910 std::atomic<NodeClock::duration> m_min_ping_time{NodeClock::duration::max()};
911 912 CNode(NodeId id,
913 std::shared_ptr<Sock> sock,
914 const CAddress& addrIn,
915 uint64_t nKeyedNetGroupIn,
916 uint64_t nLocalHostNonceIn,
917 const CService& addrBindIn,
918 const std::string& addrNameIn,
919 ConnectionType conn_type_in,
920 bool inbound_onion,
921 uint64_t network_key,
922 CNodeOptions&& node_opts = {});
923 CNode(const CNode&) = delete;
924 CNode& operator=(const CNode&) = delete;
925 926 NodeId GetId() const {
927 return id;
928 }
929 930 uint64_t GetLocalNonce() const {
931 return nLocalHostNonce;
932 }
933 934 int GetRefCount() const
935 {
936 assert(nRefCount >= 0);
937 return nRefCount;
938 }
939 940 /**
941 * Receive bytes from the buffer and deserialize them into messages.
942 *
943 * @param[in] msg_bytes The raw data
944 * @param[out] complete Set True if at least one message has been
945 * deserialized and is ready to be processed
946 * @return True if the peer should stay connected,
947 * False if the peer should be disconnected from.
948 */
949 bool ReceiveMsgBytes(std::span<const uint8_t> msg_bytes, bool& complete) EXCLUSIVE_LOCKS_REQUIRED(!cs_vRecv);
950 951 void SetCommonVersion(int greatest_common_version)
952 {
953 Assume(m_greatest_common_version == INIT_PROTO_VERSION);
954 m_greatest_common_version = greatest_common_version;
955 }
956 int GetCommonVersion() const
957 {
958 return m_greatest_common_version;
959 }
960 961 CService GetAddrLocal() const EXCLUSIVE_LOCKS_REQUIRED(!m_addr_local_mutex);
962 //! May not be called more than once
963 void SetAddrLocal(const CService& addrLocalIn) EXCLUSIVE_LOCKS_REQUIRED(!m_addr_local_mutex);
964 965 CNode* AddRef()
966 {
967 nRefCount++;
968 return this;
969 }
970 971 void Release()
972 {
973 nRefCount--;
974 }
975 976 void CloseSocketDisconnect() EXCLUSIVE_LOCKS_REQUIRED(!m_sock_mutex);
977 978 void CopyStats(CNodeStats& stats) EXCLUSIVE_LOCKS_REQUIRED(!m_subver_mutex, !m_addr_local_mutex, !cs_vSend, !cs_vRecv);
979 980 std::string ConnectionTypeAsString() const { return ::ConnectionTypeAsString(m_conn_type); }
981 982 /**
983 * Helper function to log the peer id, optionally including IP address.
984 *
985 * @return "peer=..." and optionally ", peeraddr=..."
986 */
987 std::string LogPeer() const;
988 989 /**
990 * Helper function to log disconnects.
991 *
992 * @return "disconnecting peer=..." and optionally ", peeraddr=..."
993 */
994 std::string DisconnectMsg() const;
995 996 /// A ping-pong round trip has completed successfully. Update latest and minimum ping durations.
997 void PongReceived(NodeClock::duration ping_time)
998 {
999 m_last_ping_time = ping_time;
1000 m_min_ping_time = std::min(m_min_ping_time.load(), ping_time);
1001 }
1002 1003 private:
1004 const NodeId id;
1005 const uint64_t nLocalHostNonce;
1006 std::atomic<int> m_greatest_common_version{INIT_PROTO_VERSION};
1007 1008 const size_t m_recv_flood_size;
1009 std::list<CNetMessage> vRecvMsg; // Used only by SocketHandler thread
1010 1011 Mutex m_msg_process_queue_mutex;
1012 std::list<CNetMessage> m_msg_process_queue GUARDED_BY(m_msg_process_queue_mutex);
1013 size_t m_msg_process_queue_size GUARDED_BY(m_msg_process_queue_mutex){0};
1014 1015 // Our address, as reported by the peer
1016 CService m_addr_local GUARDED_BY(m_addr_local_mutex);
1017 mutable Mutex m_addr_local_mutex;
1018 1019 mapMsgTypeSize mapSendBytesPerMsgType GUARDED_BY(cs_vSend);
1020 mapMsgTypeSize mapRecvBytesPerMsgType GUARDED_BY(cs_vRecv);
1021 1022 /**
1023 * If an I2P session is created per connection (for outbound transient I2P
1024 * connections) then it is stored here so that it can be destroyed when the
1025 * socket is closed. I2P sessions involve a data/transport socket (in `m_sock`)
1026 * and a control socket (in `m_i2p_sam_session`). For transient sessions, once
1027 * the data socket is closed, the control socket is not going to be used anymore
1028 * and is just taking up resources. So better close it as soon as `m_sock` is
1029 * closed.
1030 * Otherwise this unique_ptr is empty.
1031 */
1032 std::unique_ptr<i2p::sam::Session> m_i2p_sam_session GUARDED_BY(m_sock_mutex);
1033 };
1034 1035 /**
1036 * Interface for message handling
1037 */
1038 class NetEventsInterface
1039 {
1040 public:
1041 /** Mutex for anything that is only accessed via the msg processing thread */
1042 static Mutex g_msgproc_mutex;
1043 1044 /** Initialize a peer (setup state) */
1045 virtual void InitializeNode(const CNode& node, ServiceFlags our_services) = 0;
1046 1047 /** Handle removal of a peer (clear state) */
1048 virtual void FinalizeNode(const CNode& node) = 0;
1049 1050 /**
1051 * Callback to determine whether the given set of service flags are sufficient
1052 * for a peer to be "relevant".
1053 */
1054 virtual bool HasAllDesirableServiceFlags(ServiceFlags services) const = 0;
1055 1056 /**
1057 * Process protocol messages received from a given node
1058 *
1059 * @param[in] node The node which we have received messages from.
1060 * @param[in] interrupt Interrupt condition for processing threads
1061 * @return True if there is more work to be done
1062 */
1063 virtual bool ProcessMessages(CNode& node, std::atomic<bool>& interrupt) EXCLUSIVE_LOCKS_REQUIRED(g_msgproc_mutex) = 0;
1064 1065 /**
1066 * Send queued protocol messages to a given node.
1067 *
1068 * @param[in] node The node which we are sending messages to.
1069 * @return True if there is more work to be done
1070 */
1071 virtual bool SendMessages(CNode& node) EXCLUSIVE_LOCKS_REQUIRED(g_msgproc_mutex) = 0;
1072 1073 1074 protected:
1075 /**
1076 * Protected destructor so that instances can only be deleted by derived classes.
1077 * If that restriction is no longer desired, this should be made public and virtual.
1078 */
1079 ~NetEventsInterface() = default;
1080 };
1081 1082 class CConnman
1083 {
1084 public:
1085 1086 struct Options
1087 {
1088 ServiceFlags m_local_services = NODE_NONE;
1089 int m_max_automatic_connections = 0;
1090 CClientUIInterface* uiInterface = nullptr;
1091 NetEventsInterface* m_msgproc = nullptr;
1092 BanMan* m_banman = nullptr;
1093 unsigned int nSendBufferMaxSize = 0;
1094 unsigned int nReceiveFloodSize = 0;
1095 uint64_t nMaxOutboundLimit = 0;
1096 int64_t m_peer_connect_timeout = DEFAULT_PEER_CONNECT_TIMEOUT;
1097 std::vector<std::string> vSeedNodes;
1098 std::vector<NetWhitelistPermissions> vWhitelistedRangeIncoming;
1099 std::vector<NetWhitelistPermissions> vWhitelistedRangeOutgoing;
1100 std::vector<NetWhitebindPermissions> vWhiteBinds;
1101 std::vector<CService> vBinds;
1102 std::vector<CService> onion_binds;
1103 /// True if the user did not specify -bind= or -whitebind= and thus
1104 /// we should bind on `0.0.0.0` (IPv4) and `::` (IPv6).
1105 bool bind_on_any;
1106 bool m_use_addrman_outgoing = true;
1107 std::vector<std::string> m_specified_outgoing;
1108 std::vector<std::string> m_added_nodes;
1109 bool m_i2p_accept_incoming;
1110 bool whitelist_forcerelay = DEFAULT_WHITELISTFORCERELAY;
1111 bool whitelist_relay = DEFAULT_WHITELISTRELAY;
1112 bool m_capture_messages = false;
1113 };
1114 1115 void Init(const Options& connOptions) EXCLUSIVE_LOCKS_REQUIRED(!m_added_nodes_mutex, !m_total_bytes_sent_mutex)
1116 {
1117 AssertLockNotHeld(m_total_bytes_sent_mutex);
1118 1119 m_local_services = connOptions.m_local_services;
1120 m_max_automatic_connections = connOptions.m_max_automatic_connections;
1121 m_max_outbound_full_relay = std::min(MAX_OUTBOUND_FULL_RELAY_CONNECTIONS, m_max_automatic_connections);
1122 m_max_outbound_block_relay = std::min(MAX_BLOCK_RELAY_ONLY_CONNECTIONS, m_max_automatic_connections - m_max_outbound_full_relay);
1123 m_max_automatic_outbound = m_max_outbound_full_relay + m_max_outbound_block_relay + m_max_feeler;
1124 m_max_inbound = std::max(0, m_max_automatic_connections - m_max_automatic_outbound);
1125 m_use_addrman_outgoing = connOptions.m_use_addrman_outgoing;
1126 m_client_interface = connOptions.uiInterface;
1127 m_banman = connOptions.m_banman;
1128 m_msgproc = connOptions.m_msgproc;
1129 nSendBufferMaxSize = connOptions.nSendBufferMaxSize;
1130 nReceiveFloodSize = connOptions.nReceiveFloodSize;
1131 m_peer_connect_timeout = std::chrono::seconds{connOptions.m_peer_connect_timeout};
1132 {
1133 LOCK(m_total_bytes_sent_mutex);
1134 nMaxOutboundLimit = connOptions.nMaxOutboundLimit;
1135 }
1136 vWhitelistedRangeIncoming = connOptions.vWhitelistedRangeIncoming;
1137 vWhitelistedRangeOutgoing = connOptions.vWhitelistedRangeOutgoing;
1138 {
1139 LOCK(m_added_nodes_mutex);
1140 // Attempt v2 connection if we support v2 - we'll reconnect with v1 if our
1141 // peer doesn't support it or immediately disconnects us for another reason.
1142 const bool use_v2transport(GetLocalServices() & NODE_P2P_V2);
1143 for (const std::string& added_node : connOptions.m_added_nodes) {
1144 m_added_node_params.push_back({added_node, use_v2transport});
1145 }
1146 }
1147 m_onion_binds = connOptions.onion_binds;
1148 whitelist_forcerelay = connOptions.whitelist_forcerelay;
1149 whitelist_relay = connOptions.whitelist_relay;
1150 m_capture_messages = connOptions.m_capture_messages;
1151 }
1152 1153 // test only
1154 void SetCaptureMessages(bool cap) { m_capture_messages = cap; }
1155 1156 CConnman(uint64_t seed0,
1157 uint64_t seed1,
1158 AddrMan& addrman,
1159 const NetGroupManager& netgroupman,
1160 const CChainParams& params,
1161 bool network_active = true,
1162 std::shared_ptr<CThreadInterrupt> interrupt_net = std::make_shared<CThreadInterrupt>());
1163 1164 ~CConnman();
1165 1166 bool Start(CScheduler& scheduler, const Options& options) EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex, !m_added_nodes_mutex, !m_addr_fetches_mutex, !mutexMsgProc);
1167 1168 void StopThreads();
1169 void StopNodes() EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex, !m_reconnections_mutex);
1170 void Stop() EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex, !m_reconnections_mutex)
1171 {
1172 AssertLockNotHeld(m_nodes_mutex);
1173 AssertLockNotHeld(m_reconnections_mutex);
1174 StopThreads();
1175 StopNodes();
1176 };
1177 1178 void Interrupt() EXCLUSIVE_LOCKS_REQUIRED(!mutexMsgProc);
1179 bool GetNetworkActive() const { return fNetworkActive; };
1180 bool GetUseAddrmanOutgoing() const { return m_use_addrman_outgoing; };
1181 void SetNetworkActive(bool active);
1182 1183 /**
1184 * Open a new P2P connection and initialize it with the PeerManager at `m_msgproc`.
1185 * @param[in] addrConnect Address to connect to, if `pszDest` is `nullptr`.
1186 * @param[in] fCountFailure Increment the number of connection attempts to this address in Addrman.
1187 * @param[in] grant_outbound Take ownership of this grant, to be released later when the connection is closed.
1188 * @param[in] pszDest Address to resolve and connect to.
1189 * @param[in] conn_type Type of the connection to open, must not be `ConnectionType::INBOUND`.
1190 * @param[in] use_v2transport Use P2P encryption, (aka V2 transport, BIP324).
1191 * @param[in] proxy_override Optional proxy to use and override normal proxy selection.
1192 * @retval true The connection was opened successfully.
1193 * @retval false The connection attempt failed.
1194 */
1195 bool OpenNetworkConnection(const CAddress& addrConnect,
1196 bool fCountFailure,
1197 CountingSemaphoreGrant<>&& grant_outbound,
1198 const char* pszDest,
1199 ConnectionType conn_type,
1200 bool use_v2transport,
1201 const std::optional<Proxy>& proxy_override)
1202 EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex, !m_unused_i2p_sessions_mutex);
1203 1204 /// Group of private broadcast related members.
1205 class PrivateBroadcast
1206 {
1207 public:
1208 /**
1209 * Remember if we ever established at least one outbound connection to a
1210 * Tor peer, including sending and receiving P2P messages. If this is
1211 * true then the Tor proxy indeed works and is a proxy to the Tor network,
1212 * not a misconfigured ordinary SOCKS5 proxy as -proxy or -onion. If that
1213 * is the case, then we assume that connecting to an IPv4 or IPv6 address
1214 * via that proxy will be done through the Tor network and a Tor exit node.
1215 */
1216 std::atomic_bool m_outbound_tor_ok_at_least_once{false};
1217 1218 /**
1219 * Semaphore used to guard against opening too many connections.
1220 * Opening private broadcast connections will be paused if this is equal to 0.
1221 */
1222 std::counting_semaphore<> m_sem_conn_max{MAX_PRIVATE_BROADCAST_CONNECTIONS};
1223 1224 /**
1225 * Choose a network to open a connection to.
1226 * @param[out] proxy Optional proxy to override the normal proxy selection.
1227 * Will be set if !std::nullopt is returned. Could be set to `std::nullopt`
1228 * if there is no need to override the proxy that would be used for connecting
1229 * to the returned network.
1230 * @retval std::nullopt No network could be selected.
1231 * @retval !std::nullopt The network was selected and `proxy` is set (maybe to `std::nullopt`).
1232 */
1233 std::optional<Network> PickNetwork(std::optional<Proxy>& proxy) const;
1234 1235 /// Get the pending number of connections to open.
1236 size_t NumToOpen() const;
1237 1238 /**
1239 * Increment the number of new connections of type `ConnectionType::PRIVATE_BROADCAST`
1240 * to be opened by `CConnman::ThreadPrivateBroadcast()`.
1241 * @param[in] n Increment by this number.
1242 */
1243 void NumToOpenAdd(size_t n);
1244 1245 /**
1246 * Decrement the number of new connections of type `ConnectionType::PRIVATE_BROADCAST`
1247 * to be opened by `CConnman::ThreadPrivateBroadcast()`.
1248 * @param[in] n Decrement by this number.
1249 * @return The number of connections that remain to be opened after the operation.
1250 */
1251 size_t NumToOpenSub(size_t n);
1252 1253 /// Wait for the number of needed connections to become greater than 0.
1254 void NumToOpenWait() const;
1255 1256 protected:
1257 /**
1258 * Check if private broadcast can be done to IPv4 or IPv6 peers and if so via which proxy.
1259 * If private broadcast connections should not be opened to IPv4 or IPv6, then this will
1260 * return an empty optional.
1261 */
1262 std::optional<Proxy> ProxyForIPv4or6() const;
1263 1264 /// Number of `ConnectionType::PRIVATE_BROADCAST` connections to open.
1265 std::atomic_size_t m_num_to_open{0};
1266 1267 friend struct ConnmanTestMsg;
1268 } m_private_broadcast;
1269 1270 bool CheckIncomingNonce(uint64_t nonce) EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1271 void ASMapHealthCheck();
1272 1273 // alias for thread safety annotations only, not defined
1274 Mutex& GetNodesMutex() const LOCK_RETURNED(m_nodes_mutex);
1275 1276 bool ForNode(NodeId id, std::function<bool(CNode* pnode)> func) EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1277 1278 void PushMessage(CNode* pnode, CSerializedNetMsg&& msg) EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex);
1279 1280 using NodeFn = std::function<void(CNode*)>;
1281 void ForEachNode(const NodeFn& func) EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex)
1282 {
1283 LOCK(m_nodes_mutex);
1284 for (auto&& node : m_nodes) {
1285 if (NodeFullyConnected(node))
1286 func(node);
1287 }
1288 };
1289 1290 void ForEachNode(const NodeFn& func) const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex)
1291 {
1292 LOCK(m_nodes_mutex);
1293 for (auto&& node : m_nodes) {
1294 if (NodeFullyConnected(node))
1295 func(node);
1296 }
1297 };
1298 1299 // Addrman functions
1300 /**
1301 * Return randomly selected addresses. This function does not use the address response cache and
1302 * should only be used in trusted contexts.
1303 *
1304 * An untrusted caller (e.g. from p2p) should instead use @ref GetAddresses to use the cache.
1305 *
1306 * @param[in] max_addresses Maximum number of addresses to return (0 = all).
1307 * @param[in] max_pct Maximum percentage of addresses to return (0 = all). Value must be from 0 to 100.
1308 * @param[in] network Select only addresses of this network (nullopt = all).
1309 * @param[in] filtered Select only addresses that are considered high quality (false = all).
1310 */
1311 std::vector<CAddress> GetAddressesUnsafe(size_t max_addresses, size_t max_pct, std::optional<Network> network, bool filtered = true) const;
1312 /**
1313 * Return addresses from the per-requestor cache. If no cache entry exists, it is populated with
1314 * randomly selected addresses. This function can be used in untrusted contexts.
1315 *
1316 * A trusted caller (e.g. from RPC or a peer with addr permission) can use
1317 * @ref GetAddressesUnsafe to avoid using the cache.
1318 *
1319 * @param[in] requestor The requesting peer. Used to key the cache to prevent privacy leaks.
1320 * @param[in] max_addresses Maximum number of addresses to return (0 = all). Ignored when cache
1321 * already contains an entry for requestor.
1322 * @param[in] max_pct Maximum percentage of addresses to return (0 = all). Value must be
1323 * from 0 to 100. Ignored when cache already contains an entry for
1324 * requestor.
1325 */
1326 std::vector<CAddress> GetAddresses(CNode& requestor, size_t max_addresses, size_t max_pct);
1327 1328 // This allows temporarily exceeding m_max_outbound_full_relay, with the goal of finding
1329 // a peer that is better than all our current peers.
1330 void SetTryNewOutboundPeer(bool flag);
1331 bool GetTryNewOutboundPeer() const;
1332 1333 void StartExtraBlockRelayPeers();
1334 1335 // Count the number of full-relay peer we have.
1336 int GetFullOutboundConnCount() const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1337 // Return the number of outbound peers we have in excess of our target (eg,
1338 // if we previously called SetTryNewOutboundPeer(true), and have since set
1339 // to false, we may have extra peers that we wish to disconnect). This may
1340 // return a value less than (num_outbound_connections - num_outbound_slots)
1341 // in cases where some outbound connections are not yet fully connected, or
1342 // not yet fully disconnected.
1343 int GetExtraFullOutboundCount() const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1344 // Count the number of block-relay-only peers we have over our limit.
1345 int GetExtraBlockRelayCount() const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1346 1347 bool AddNode(const AddedNodeParams& add) EXCLUSIVE_LOCKS_REQUIRED(!m_added_nodes_mutex);
1348 bool RemoveAddedNode(std::string_view node) EXCLUSIVE_LOCKS_REQUIRED(!m_added_nodes_mutex);
1349 bool AddedNodesContain(const CAddress& addr) const EXCLUSIVE_LOCKS_REQUIRED(!m_added_nodes_mutex);
1350 std::vector<AddedNodeInfo> GetAddedNodeInfo(bool include_connected) const
1351 EXCLUSIVE_LOCKS_REQUIRED(!m_added_nodes_mutex, !m_nodes_mutex);
1352 1353 /**
1354 * Attempts to open a connection. Currently only used from tests.
1355 *
1356 * @param[in] address Address of node to try connecting to
1357 * @param[in] conn_type ConnectionType::OUTBOUND, ConnectionType::BLOCK_RELAY,
1358 * ConnectionType::ADDR_FETCH or ConnectionType::FEELER
1359 * @param[in] use_v2transport Set to true if node attempts to connect using BIP 324 v2 transport protocol.
1360 * @return bool Returns false if there are no available
1361 * slots for this connection:
1362 * - conn_type not a supported ConnectionType
1363 * - Max total outbound connection capacity filled
1364 * - Max connection capacity for type is filled
1365 */
1366 bool AddConnection(const std::string& address, ConnectionType conn_type, bool use_v2transport)
1367 EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex, !m_unused_i2p_sessions_mutex);
1368 1369 size_t GetNodeCount(ConnectionDirection) const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1370 std::map<CNetAddr, LocalServiceInfo> getNetLocalAddresses() const;
1371 uint32_t GetMappedAS(const CNetAddr& addr) const;
1372 void GetNodeStats(std::vector<CNodeStats>& vstats) const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1373 bool DisconnectNode(std::string_view node) EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1374 bool DisconnectNode(const CSubNet& subnet) EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1375 bool DisconnectNode(const CNetAddr& addr) EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1376 bool DisconnectNode(NodeId id) EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1377 1378 //! Used to convey which local services we are offering peers during node
1379 //! connection.
1380 //!
1381 //! The data returned by this is used in CNode construction,
1382 //! which is used to advertise which services we are offering
1383 //! that peer during `net_processing.cpp:PushNodeVersion()`.
1384 ServiceFlags GetLocalServices() const;
1385 1386 //! Updates the local services that this node advertises to other peers
1387 //! during connection handshake.
1388 void AddLocalServices(ServiceFlags services) { m_local_services = ServiceFlags(m_local_services | services); };
1389 void RemoveLocalServices(ServiceFlags services) { m_local_services = ServiceFlags(m_local_services & ~services); }
1390 1391 uint64_t GetMaxOutboundTarget() const EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex);
1392 std::chrono::seconds GetMaxOutboundTimeframe() const;
1393 1394 //! check if the outbound target is reached
1395 //! if param historicalBlockServingLimit is set true, the function will
1396 //! response true if the limit for serving historical blocks has been reached
1397 bool OutboundTargetReached(bool historicalBlockServingLimit) const EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex);
1398 1399 //! response the bytes left in the current max outbound cycle
1400 //! in case of no limit, it will always response 0
1401 uint64_t GetOutboundTargetBytesLeft() const EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex);
1402 1403 std::chrono::seconds GetMaxOutboundTimeLeftInCycle() const EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex);
1404 1405 uint64_t GetTotalBytesRecv() const;
1406 uint64_t GetTotalBytesSent() const EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex);
1407 1408 /** Get a unique deterministic randomizer. */
1409 CSipHasher GetDeterministicRandomizer(uint64_t id) const;
1410 1411 void WakeMessageHandler() EXCLUSIVE_LOCKS_REQUIRED(!mutexMsgProc);
1412 1413 /** Return true if we should disconnect the peer for failing an inactivity check. */
1414 bool ShouldRunInactivityChecks(const CNode& node, NodeClock::time_point now) const;
1415 1416 bool MultipleManualOrFullOutboundConns(Network net) const EXCLUSIVE_LOCKS_REQUIRED(m_nodes_mutex);
1417 1418 private:
1419 struct ListenSocket {
1420 public:
1421 std::shared_ptr<Sock> sock;
1422 inline void AddSocketPermissionFlags(NetPermissionFlags& flags) const { NetPermissions::AddFlag(flags, m_permissions); }
1423 ListenSocket(std::shared_ptr<Sock> sock_, NetPermissionFlags permissions_)
1424 : sock{sock_}, m_permissions{permissions_}
1425 {
1426 }
1427 1428 private:
1429 NetPermissionFlags m_permissions;
1430 };
1431 1432 //! returns the time left in the current max outbound cycle
1433 //! in case of no limit, it will always return 0
1434 std::chrono::seconds GetMaxOutboundTimeLeftInCycle_() const EXCLUSIVE_LOCKS_REQUIRED(m_total_bytes_sent_mutex);
1435 1436 bool BindListenPort(const CService& bindAddr, bilingual_str& strError, NetPermissionFlags permissions);
1437 bool Bind(const CService& addr, unsigned int flags, NetPermissionFlags permissions);
1438 bool InitBinds(const Options& options);
1439 1440 /// \anchor addcon
1441 void ThreadOpenAddedConnections() EXCLUSIVE_LOCKS_REQUIRED(!m_added_nodes_mutex,
1442 !m_nodes_mutex,
1443 !m_reconnections_mutex,
1444 !m_unused_i2p_sessions_mutex);
1445 1446 void AddAddrFetch(const std::string& strDest) EXCLUSIVE_LOCKS_REQUIRED(!m_addr_fetches_mutex);
1447 1448 void ProcessAddrFetch() EXCLUSIVE_LOCKS_REQUIRED(!m_addr_fetches_mutex,
1449 !m_nodes_mutex,
1450 !m_unused_i2p_sessions_mutex);
1451 1452 /// \anchor opencon
1453 void ThreadOpenConnections(std::vector<std::string> connect, std::span<const std::string> seed_nodes)
1454 EXCLUSIVE_LOCKS_REQUIRED(!m_added_nodes_mutex,
1455 !m_addr_fetches_mutex,
1456 !m_nodes_mutex,
1457 !m_reconnections_mutex,
1458 !m_unused_i2p_sessions_mutex);
1459 1460 /// \anchor msghand
1461 void ThreadMessageHandler() EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex, !mutexMsgProc);
1462 /// \anchor i2paccept
1463 void ThreadI2PAcceptIncoming() EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1464 void ThreadPrivateBroadcast() EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex, !m_unused_i2p_sessions_mutex);
1465 void AcceptConnection(const ListenSocket& hListenSocket) EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1466 1467 /**
1468 * Create a `CNode` object from a socket that has just been accepted and add the node to
1469 * the `m_nodes` member.
1470 * @param[in] sock Connected socket to communicate with the peer.
1471 * @param[in] permission_flags The peer's permissions.
1472 * @param[in] addr_bind The address and port at our side of the connection.
1473 * @param[in] addr The address and port at the peer's side of the connection.
1474 */
1475 void CreateNodeFromAcceptedSocket(std::unique_ptr<Sock>&& sock,
1476 NetPermissionFlags permission_flags,
1477 const CService& addr_bind,
1478 const CService& addr)
1479 EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1480 1481 void DisconnectNodes() EXCLUSIVE_LOCKS_REQUIRED(!m_reconnections_mutex, !m_nodes_mutex);
1482 void NotifyNumConnectionsChanged() EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1483 /** Return true if the peer is inactive and should be disconnected. */
1484 bool InactivityCheck(const CNode& node, NodeClock::time_point now) const;
1485 1486 /**
1487 * Generate a collection of sockets to check for IO readiness.
1488 * @param[in] nodes Select from these nodes' sockets.
1489 * @return sockets to check for readiness
1490 */
1491 Sock::EventsPerSock GenerateWaitSockets(std::span<CNode* const> nodes);
1492 1493 /**
1494 * Check connected and listening sockets for IO readiness and process them accordingly.
1495 */
1496 void SocketHandler() EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex, !m_total_bytes_sent_mutex, !mutexMsgProc);
1497 1498 /**
1499 * Do the read/write for connected sockets that are ready for IO.
1500 * @param[in] nodes Nodes to process. The socket of each node is checked against `what`.
1501 * @param[in] events_per_sock Sockets that are ready for IO.
1502 */
1503 void SocketHandlerConnected(const std::vector<CNode*>& nodes,
1504 const Sock::EventsPerSock& events_per_sock)
1505 EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex, !mutexMsgProc);
1506 1507 /**
1508 * Accept incoming connections, one from each read-ready listening socket.
1509 * @param[in] events_per_sock Sockets that are ready for IO.
1510 */
1511 void SocketHandlerListening(const Sock::EventsPerSock& events_per_sock)
1512 EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1513 1514 /// \anchor net
1515 void ThreadSocketHandler() EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex, !mutexMsgProc, !m_nodes_mutex, !m_reconnections_mutex);
1516 /// \anchor dnsseed
1517 void ThreadDNSAddressSeed() EXCLUSIVE_LOCKS_REQUIRED(!m_addr_fetches_mutex, !m_nodes_mutex);
1518 1519 uint64_t CalculateKeyedNetGroup(const CNetAddr& ad) const;
1520 1521 /**
1522 * Determine whether we're already connected to a given "host:port".
1523 * Note that for inbound connections, the peer is likely using a random outbound
1524 * port on their side, so this will likely not match any inbound connections.
1525 * @param[in] host String of the form "host[:port]", e.g. "localhost" or "localhost:8333" or "1.2.3.4:8333".
1526 * @return true if connected to `host`.
1527 */
1528 bool AlreadyConnectedToHost(std::string_view host) const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1529 1530 /**
1531 * Determine whether we're already connected to a given address:port.
1532 * Note that for inbound connections, the peer is likely using a random outbound
1533 * port on their side, so this will likely not match any inbound connections.
1534 * @param[in] addr_port Address and port to check.
1535 * @return true if connected to addr_port.
1536 */
1537 bool AlreadyConnectedToAddressPort(const CService& addr_port) const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1538 1539 /**
1540 * Determine whether we're already connected to a given address.
1541 */
1542 bool AlreadyConnectedToAddress(const CNetAddr& addr) const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1543 1544 bool AttemptToEvictConnection() EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1545 1546 /**
1547 * Open a new P2P connection.
1548 * @param[in] addrConnect Address to connect to, if `pszDest` is `nullptr`.
1549 * @param[in] pszDest Address to resolve and connect to.
1550 * @param[in] fCountFailure Increment the number of connection attempts to this address in Addrman.
1551 * @param[in] conn_type Type of the connection to open, must not be `ConnectionType::INBOUND`.
1552 * @param[in] use_v2transport Use P2P encryption, (aka V2 transport, BIP324).
1553 * @param[in] proxy_override Optional proxy to use and override normal proxy selection.
1554 * @return Newly created CNode object or nullptr if the connection failed.
1555 */
1556 CNode* ConnectNode(CAddress addrConnect,
1557 const char* pszDest,
1558 bool fCountFailure,
1559 ConnectionType conn_type,
1560 bool use_v2transport,
1561 const std::optional<Proxy>& proxy_override)
1562 EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex, !m_unused_i2p_sessions_mutex);
1563 1564 void AddWhitelistPermissionFlags(NetPermissionFlags& flags, std::optional<CNetAddr> addr, const std::vector<NetWhitelistPermissions>& ranges) const;
1565 1566 void DeleteNode(CNode* pnode);
1567 1568 NodeId GetNewNodeId();
1569 1570 /** (Try to) send data from node's vSendMsg. Returns (bytes_sent, data_left). */
1571 std::pair<size_t, bool> SocketSendData(CNode& node) const EXCLUSIVE_LOCKS_REQUIRED(node.cs_vSend);
1572 1573 void DumpAddresses();
1574 1575 // Network stats
1576 void RecordBytesRecv(uint64_t bytes);
1577 void RecordBytesSent(uint64_t bytes) EXCLUSIVE_LOCKS_REQUIRED(!m_total_bytes_sent_mutex);
1578 1579 /**
1580 Return reachable networks for which we have no addresses in addrman and therefore
1581 may require loading fixed seeds.
1582 */
1583 std::unordered_set<Network> GetReachableEmptyNetworks() const;
1584 1585 /**
1586 * Return vector of current BLOCK_RELAY peers.
1587 */
1588 std::vector<CAddress> GetCurrentBlockRelayOnlyConns() const EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1589 1590 /**
1591 * Search for a "preferred" network, a reachable network to which we
1592 * currently don't have any OUTBOUND_FULL_RELAY or MANUAL connections.
1593 * There needs to be at least one address in AddrMan for a preferred
1594 * network to be picked.
1595 *
1596 * @param[out] network Preferred network, if found.
1597 *
1598 * @return bool Whether a preferred network was found.
1599 */
1600 bool MaybePickPreferredNetwork(std::optional<Network>& network) EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex);
1601 1602 // Whether the node should be passed out in ForEach* callbacks
1603 static bool NodeFullyConnected(const CNode* pnode);
1604 1605 uint16_t GetDefaultPort(Network net) const;
1606 uint16_t GetDefaultPort(const std::string& addr) const;
1607 1608 // Network usage totals
1609 mutable Mutex m_total_bytes_sent_mutex;
1610 std::atomic<uint64_t> nTotalBytesRecv{0};
1611 uint64_t nTotalBytesSent GUARDED_BY(m_total_bytes_sent_mutex) {0};
1612 1613 // outbound limit & stats
1614 uint64_t nMaxOutboundTotalBytesSentInCycle GUARDED_BY(m_total_bytes_sent_mutex) {0};
1615 std::chrono::seconds nMaxOutboundCycleStartTime GUARDED_BY(m_total_bytes_sent_mutex) {0};
1616 uint64_t nMaxOutboundLimit GUARDED_BY(m_total_bytes_sent_mutex);
1617 1618 // P2P timeout in seconds
1619 std::chrono::seconds m_peer_connect_timeout;
1620 1621 // Whitelisted ranges. Any node connecting from these is automatically
1622 // whitelisted (as well as those connecting to whitelisted binds).
1623 std::vector<NetWhitelistPermissions> vWhitelistedRangeIncoming;
1624 // Whitelisted ranges for outgoing connections.
1625 std::vector<NetWhitelistPermissions> vWhitelistedRangeOutgoing;
1626 1627 unsigned int nSendBufferMaxSize{0};
1628 unsigned int nReceiveFloodSize{0};
1629 1630 std::vector<ListenSocket> vhListenSocket;
1631 std::atomic<bool> fNetworkActive{true};
1632 bool fAddressesInitialized{false};
1633 std::reference_wrapper<AddrMan> addrman;
1634 const NetGroupManager& m_netgroupman;
1635 std::deque<std::string> m_addr_fetches GUARDED_BY(m_addr_fetches_mutex);
1636 Mutex m_addr_fetches_mutex;
1637 1638 // connection string and whether to use v2 p2p
1639 std::vector<AddedNodeParams> m_added_node_params GUARDED_BY(m_added_nodes_mutex);
1640 1641 mutable Mutex m_added_nodes_mutex;
1642 std::vector<CNode*> m_nodes GUARDED_BY(m_nodes_mutex);
1643 std::list<CNode*> m_nodes_disconnected;
1644 mutable Mutex m_nodes_mutex;
1645 std::atomic<NodeId> nLastNodeId{0};
1646 unsigned int nPrevNodeCount{0};
1647 1648 // Stores number of full-tx connections (outbound and manual) per network
1649 std::array<unsigned int, Network::NET_MAX> m_network_conn_counts GUARDED_BY(m_nodes_mutex) = {};
1650 1651 /**
1652 * Cache responses to addr requests to minimize privacy leak.
1653 * Attack example: scraping addrs in real-time may allow an attacker
1654 * to infer new connections of the victim by detecting new records
1655 * with fresh timestamps (per self-announcement).
1656 */
1657 struct CachedAddrResponse {
1658 std::vector<CAddress> m_addrs_response_cache;
1659 std::chrono::microseconds m_cache_entry_expiration{0};
1660 };
1661 1662 /**
1663 * Addr responses stored in different caches
1664 * per (network, local socket) prevent cross-network node identification.
1665 * If a node for example is multi-homed under Tor and IPv6,
1666 * a single cache (or no cache at all) would let an attacker
1667 * to easily detect that it is the same node by comparing responses.
1668 * Indexing by local socket prevents leakage when a node has multiple
1669 * listening addresses on the same network.
1670 *
1671 * The used memory equals to 1000 CAddress records (or around 40 bytes) per
1672 * distinct Network (up to 5) we have/had an inbound peer from,
1673 * resulting in at most ~196 KB. Every separate local socket may
1674 * add up to ~196 KB extra.
1675 */
1676 std::map<uint64_t, CachedAddrResponse> m_addr_response_caches;
1677 1678 /**
1679 * Services this node offers.
1680 *
1681 * This data is replicated in each Peer instance we create.
1682 *
1683 * This data is not marked const, but after being set it should not
1684 * change. Unless AssumeUTXO is started, in which case, the peer
1685 * will be limited until the background chain sync finishes.
1686 *
1687 * \sa Peer::our_services
1688 */
1689 std::atomic<ServiceFlags> m_local_services;
1690 1691 std::unique_ptr<std::counting_semaphore<>> semOutbound;
1692 std::unique_ptr<std::counting_semaphore<>> semAddnode;
1693 1694 /**
1695 * Maximum number of automatic connections permitted, excluding manual
1696 * connections but including inbounds. May be changed by the user and is
1697 * potentially limited by the operating system (number of file descriptors).
1698 */
1699 int m_max_automatic_connections;
1700 1701 /*
1702 * Maximum number of peers by connection type. Might vary from defaults
1703 * based on -maxconnections init value.
1704 */
1705 1706 // How many full-relay (tx, block, addr) outbound peers we want
1707 int m_max_outbound_full_relay;
1708 1709 // How many block-relay only outbound peers we want
1710 // We do not relay tx or addr messages with these peers
1711 int m_max_outbound_block_relay;
1712 1713 int m_max_addnode{MAX_ADDNODE_CONNECTIONS};
1714 int m_max_feeler{MAX_FEELER_CONNECTIONS};
1715 int m_max_automatic_outbound;
1716 int m_max_inbound;
1717 1718 bool m_use_addrman_outgoing;
1719 CClientUIInterface* m_client_interface;
1720 NetEventsInterface* m_msgproc;
1721 /** Pointer to this node's banman. May be nullptr - check existence before dereferencing. */
1722 BanMan* m_banman;
1723 1724 /**
1725 * Addresses that were saved during the previous clean shutdown. We'll
1726 * attempt to make block-relay-only connections to them.
1727 */
1728 std::vector<CAddress> m_anchors;
1729 1730 /** SipHasher seeds for deterministic randomness */
1731 const uint64_t nSeed0, nSeed1;
1732 1733 /** flag for waking the message processor. */
1734 bool fMsgProcWake GUARDED_BY(mutexMsgProc);
1735 1736 std::condition_variable condMsgProc;
1737 Mutex mutexMsgProc;
1738 std::atomic<bool> flagInterruptMsgProc{false};
1739 1740 /**
1741 * This is signaled when network activity should cease.
1742 * A copy of this is saved in `m_i2p_sam_session`.
1743 */
1744 const std::shared_ptr<CThreadInterrupt> m_interrupt_net;
1745 1746 /**
1747 * I2P SAM session.
1748 * Used to accept incoming and make outgoing I2P connections from a persistent
1749 * address.
1750 */
1751 std::unique_ptr<i2p::sam::Session> m_i2p_sam_session;
1752 1753 std::thread threadDNSAddressSeed;
1754 std::thread threadSocketHandler;
1755 std::thread threadOpenAddedConnections;
1756 std::thread threadOpenConnections;
1757 std::thread threadMessageHandler;
1758 std::thread threadI2PAcceptIncoming;
1759 std::thread threadPrivateBroadcast;
1760 1761 /** flag for deciding to connect to an extra outbound peer,
1762 * in excess of m_max_outbound_full_relay
1763 * This takes the place of a feeler connection */
1764 std::atomic_bool m_try_another_outbound_peer;
1765 1766 /** flag for initiating extra block-relay-only peer connections.
1767 * this should only be enabled after initial chain sync has occurred,
1768 * as these connections are intended to be short-lived and low-bandwidth.
1769 */
1770 std::atomic_bool m_start_extra_block_relay_peers{false};
1771 1772 /**
1773 * A vector of -bind=<address>:<port>=onion arguments each of which is
1774 * an address and port that are designated for incoming Tor connections.
1775 */
1776 std::vector<CService> m_onion_binds;
1777 1778 /**
1779 * flag for adding 'forcerelay' permission to whitelisted inbound
1780 * and manual peers with default permissions.
1781 */
1782 bool whitelist_forcerelay;
1783 1784 /**
1785 * flag for adding 'relay' permission to whitelisted inbound
1786 * and manual peers with default permissions.
1787 */
1788 bool whitelist_relay;
1789 1790 /**
1791 * flag for whether messages are captured
1792 */
1793 bool m_capture_messages{false};
1794 1795 /**
1796 * Mutex protecting m_i2p_sam_sessions.
1797 */
1798 Mutex m_unused_i2p_sessions_mutex;
1799 1800 /**
1801 * A pool of created I2P SAM transient sessions that should be used instead
1802 * of creating new ones in order to reduce the load on the I2P network.
1803 * Creating a session in I2P is not cheap, thus if this is not empty, then
1804 * pick an entry from it instead of creating a new session. If connecting to
1805 * a host fails, then the created session is put to this pool for reuse.
1806 */
1807 std::queue<std::unique_ptr<i2p::sam::Session>> m_unused_i2p_sessions GUARDED_BY(m_unused_i2p_sessions_mutex);
1808 1809 /**
1810 * Mutex protecting m_reconnections.
1811 */
1812 Mutex m_reconnections_mutex;
1813 1814 /** Struct for entries in m_reconnections. */
1815 struct ReconnectionInfo
1816 {
1817 std::optional<Proxy> proxy_override;
1818 CAddress addr_connect;
1819 CountingSemaphoreGrant<> grant;
1820 std::string destination;
1821 ConnectionType conn_type;
1822 bool use_v2transport;
1823 };
1824 1825 /**
1826 * List of reconnections we have to make.
1827 */
1828 std::list<ReconnectionInfo> m_reconnections GUARDED_BY(m_reconnections_mutex);
1829 1830 /** Attempt reconnections, if m_reconnections non-empty. */
1831 void PerformReconnections()
1832 EXCLUSIVE_LOCKS_REQUIRED(!m_nodes_mutex, !m_reconnections_mutex, !m_unused_i2p_sessions_mutex);
1833 1834 /**
1835 * Cap on the size of `m_unused_i2p_sessions`, to ensure it does not
1836 * unexpectedly use too much memory.
1837 */
1838 static constexpr size_t MAX_UNUSED_I2P_SESSIONS_SIZE{10};
1839 1840 /**
1841 * RAII helper to atomically create a copy of `m_nodes` and add a reference
1842 * to each of the nodes. The nodes are released when this object is destroyed.
1843 */
1844 class NodesSnapshot
1845 {
1846 public:
1847 explicit NodesSnapshot(const CConnman& connman, bool shuffle)
1848 EXCLUSIVE_LOCKS_REQUIRED(!connman.m_nodes_mutex)
1849 {
1850 {
1851 LOCK(connman.m_nodes_mutex);
1852 m_nodes_copy = connman.m_nodes;
1853 for (auto& node : m_nodes_copy) {
1854 node->AddRef();
1855 }
1856 }
1857 if (shuffle) {
1858 std::shuffle(m_nodes_copy.begin(), m_nodes_copy.end(), FastRandomContext{});
1859 }
1860 }
1861 1862 ~NodesSnapshot()
1863 {
1864 for (auto& node : m_nodes_copy) {
1865 node->Release();
1866 }
1867 }
1868 1869 const std::vector<CNode*>& Nodes() const
1870 {
1871 return m_nodes_copy;
1872 }
1873 1874 private:
1875 std::vector<CNode*> m_nodes_copy;
1876 };
1877 1878 const CChainParams& m_params;
1879 1880 friend struct ConnmanTestMsg;
1881 };
1882 1883 /** Defaults to `CaptureMessageToFile()`, but can be overridden by unit tests. */
1884 extern std::function<void(const CAddress& addr,
1885 const std::string& msg_type,
1886 std::span<const unsigned char> data,
1887 bool is_incoming)>
1888 CaptureMessage;
1889 1890 #endif // BITCOIN_NET_H
1891