Compare commits

...
Author SHA1 Message Date
mrambossekandClaude Opus 5 d5e15816b5 server: fix egress-MTU probe — connect the socket before reading IP_MTU
server-release / image (push) Successful in 15s
server-test / test (push) Successful in 27s
server-release / release (push) Successful in 27s
IP_MTU getsockopt returns ENOTCONN on an unconnected socket; the v0.3.4
probe set IP_MTU_DISCOVER and Sendto but never Connect'd, so every probe
errored. UDP-connect (no handshake) pins the route so IP_MTU reflects the
path; switched to Write (two return values). Sysctl audit already flagged
the four real fmr issues in v0.3.4; this makes the MTU proof report.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-31 20:46:47 +02:00
mrambossekandClaude Opus 5 4ae744aae5 server: self-test — sysctl audit + egress-MTU self-proof ("server proven good")
server-release / image (push) Successful in 15s
server-test / test (push) Successful in 27s
server-release / release (push) Successful in 28s
A measurement server must prove its own host isn't distorting results:
- sysctl audit (/proc/sys): flags accept_ra on a static host, ICMP
  redirects, ICMP rate-limiting of the server's own errors, and disabled
  TCP options — each a measurement-fidelity hazard, with the "why".
- egress-MTU self-proof: DF PMTUD probe (IP_MTU_DISCOVER + getsockopt
  IP_MTU, no root — Linux-only, stub elsewhere) to external anchors. If the
  server's own uplink is below 1500, client MTU tests measure THIS server,
  so we say so.
Exposed at GET /admin/selftest (full report) and as server_selftest
{mtu_ok, sysctl_ok} in the profile so clients can trust or skip MTU tests.
Recommended deploy/99-echolot-sysctl.conf + README section.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-31 20:44:38 +02:00
8 changed files with 368 additions and 4 deletions
+20
View File
@@ -53,6 +53,26 @@ All configurable via `ECHOLOT_*_LISTEN`. Plus:
Deliberately out of scope here: an echo listener on 443 (to detect port-based egress filtering) Deliberately out of scope here: an echo listener on 443 (to detect port-based egress filtering)
— that genuinely needs 443 and belongs on a dedicated IP, not on a host running a reverse proxy. — that genuinely needs 443 and belongs on a dedicated IP, not on a host running a reverse proxy.
## Host tuning (measurement fidelity)
A measurement server must not let the kernel distort what clients observe. Apply the
recommended sysctls and the daemon will confirm the host is clean:
```sh
sudo cp deploy/99-echolot-sysctl.conf /etc/sysctl.d/ && sudo sysctl --system
```
The daemon **self-tests at startup and via `GET /admin/selftest`** (localhost):
- **sysctl audit** — flags settings that would distort results (RA acceptance on a static host,
ICMP redirects, ICMP rate-limiting of the server's own errors, disabled TCP options).
- **egress-MTU self-proof** — DF-probes external anchors (`ECHOLOT_MTU_PROBE_TARGETS`,
default 1.1.1.1 + a v6 anchor) and reads the discovered path MTU. If the server's *own* uplink
can't carry 1500, client MTU results would measure this server, not the client — so the profile
exposes `server_selftest.mtu_ok` and the log warns loudly.
Both signals ride in `GET /v1/profile` as `server_selftest` so a client can trust — or skip —
MTU testing accordingly.
## Run in Docker (config via env) ## Run in Docker (config via env)
```sh ```sh
+34
View File
@@ -18,6 +18,7 @@ import (
"crypto/tls" "crypto/tls"
"crypto/x509" "crypto/x509"
"crypto/x509/pkix" "crypto/x509/pkix"
"encoding/json"
"encoding/pem" "encoding/pem"
"errors" "errors"
"fmt" "fmt"
@@ -30,6 +31,7 @@ import (
"os/signal" "os/signal"
"path/filepath" "path/filepath"
"strconv" "strconv"
"sync/atomic"
"syscall" "syscall"
"time" "time"
@@ -37,6 +39,7 @@ import (
"echo-lot.app/server/internal/config" "echo-lot.app/server/internal/config"
"echo-lot.app/server/internal/control" "echo-lot.app/server/internal/control"
"echo-lot.app/server/internal/dataplane" "echo-lot.app/server/internal/dataplane"
"echo-lot.app/server/internal/selftest"
"echo-lot.app/server/internal/selfupdate" "echo-lot.app/server/internal/selfupdate"
"echo-lot.app/server/internal/session" "echo-lot.app/server/internal/session"
"echo-lot.app/server/internal/store" "echo-lot.app/server/internal/store"
@@ -138,11 +141,42 @@ func serve(cfg *config.Config) error {
}(addr, ln) }(addr, ln)
} }
// Self-test: prove the host is a clean measurement target. Sysctl audit is
// instant; the egress-MTU proof does network round trips, so publish the
// sysctl-only report immediately and swap in the full one when it lands.
var selftestPtr atomic.Pointer[selftest.Report]
initial := selftest.Report{Sysctls: selftest.Sysctls()}
selftestPtr.Store(&initial)
for _, c := range initial.Sysctls {
if c.Severity == selftest.Warn {
slog.Warn("sysctl not measurement-clean", "sysctl", c.Name, "got", c.Got, "want", c.Want, "why", c.Why)
}
}
go func() {
r := selftest.Run(config.Addrs(cfg.MTUProbeTargets))
selftestPtr.Store(&r)
for _, m := range r.EgressMTU {
if !m.FullMTU {
slog.Warn("egress MTU below 1500 — client MTU results measure THIS server, not the client",
"target", m.Target, "discovered_mtu", m.DiscoveredMTU, "err", m.Err)
}
}
slog.Info("self-test complete", "sysctl_ok", r.SysctlOK, "mtu_ok", r.MTUOK)
}()
ctl.ProvenGood = func() (mtuOK, sysctlOK bool) {
r := selftestPtr.Load()
return r.MTUOK, r.SysctlOK
}
// Admin/health (plain HTTP, localhost by default; spec §7) // Admin/health (plain HTTP, localhost by default; spec §7)
admin := http.NewServeMux() admin := http.NewServeMux()
admin.HandleFunc("GET /healthz", func(w http.ResponseWriter, _ *http.Request) { admin.HandleFunc("GET /healthz", func(w http.ResponseWriter, _ *http.Request) {
fmt.Fprintf(w, `{"ok":true,"version":%q}`, Version) fmt.Fprintf(w, `{"ok":true,"version":%q}`, Version)
}) })
admin.HandleFunc("GET /admin/selftest", func(w http.ResponseWriter, _ *http.Request) {
w.Header().Set("Content-Type", "application/json")
_ = json.NewEncoder(w).Encode(selftestPtr.Load())
})
// TODO(spec §7): enrollment token management + device list. Until the // TODO(spec §7): enrollment token management + device list. Until the
// admin UI exists, mint tokens with: echolot-admin (or curl on this // admin UI exists, mint tokens with: echolot-admin (or curl on this
// listener once the endpoint lands). // listener once the endpoint lands).
+40
View File
@@ -0,0 +1,40 @@
# SPDX-FileCopyrightText: 2026 Echolot contributors
# SPDX-License-Identifier: GPL-3.0-or-later
#
# Recommended sysctls for an Echolot probe-server host: keep the kernel from
# silently altering what clients measure. Install with:
# sudo cp 99-echolot-sysctl.conf /etc/sysctl.d/
# sudo sysctl --system
# The daemon audits these at startup and via GET /admin/selftest; anything not
# set here shows up as a "not measurement-clean" warning.
# Static-addressed host: never let a Router Advertisement mutate our routing.
# (Echolot's whole job is detecting broken RAs — the server must be immune.)
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
# Don't let ICMP redirects rewrite our routing mid-measurement, and don't
# emit redirects (we're an endpoint, not a router).
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
# Don't throttle the server's own ICMP errors (dest-unreachable/frag-needed/
# time-exceeded) — throttling produces false loss/black-hole readings when
# clients probe toward this server.
net.ipv4.icmp_ratelimit = 0
# These are usually already correct; pinned so the server can honestly
# negotiate/reflect them (a missing option in a client's evidence is then the
# path's fault, not ours).
net.ipv4.tcp_sack = 1
net.ipv4.tcp_timestamps = 1
net.ipv4.tcp_window_scaling = 1
net.ipv4.ip_no_pmtu_disc = 0
net.ipv4.icmp_echo_ignore_all = 0
# Loose reverse-path filtering suits a multi-IP measurement host (strict mode
# can drop alt-address / asymmetric replies used by STUN 5780).
net.ipv4.conf.all.rp_filter = 2
+3
View File
@@ -32,6 +32,8 @@ type Config struct {
// Optional cleartext HTTP-echo listener (spec §4 plaintext-path test). // Optional cleartext HTTP-echo listener (spec §4 plaintext-path test).
// Default empty = off; it exposes only POST /v1/echo, no auth, no secrets. // Default empty = off; it exposes only POST /v1/echo, no auth, no secrets.
HTTPEchoListen string // ECHOLOT_HTTP_ECHO_LISTEN / --http-echo-listen HTTPEchoListen string // ECHOLOT_HTTP_ECHO_LISTEN / --http-echo-listen
// Comma-separated anchors for the egress-MTU self-proof (host or ip).
MTUProbeTargets string // ECHOLOT_MTU_PROBE_TARGETS / --mtu-probe-targets
// Admin UI / health listener (spec §7: localhost-only by default) // Admin UI / health listener (spec §7: localhost-only by default)
AdminListen string // ECHOLOT_ADMIN_LISTEN / --admin-listen AdminListen string // ECHOLOT_ADMIN_LISTEN / --admin-listen
@@ -75,6 +77,7 @@ func Load(args []string) (*Config, *Actions, error) {
fs.StringVar(&c.DNSListen, "dns-listen", envOr("DNS_LISTEN", ""), "canary-DNS listen address(es) udp+tcp/53, comma-separated; empty disables (spec §6.1)") fs.StringVar(&c.DNSListen, "dns-listen", envOr("DNS_LISTEN", ""), "canary-DNS listen address(es) udp+tcp/53, comma-separated; empty disables (spec §6.1)")
fs.StringVar(&c.CanaryZone, "canary-zone", envOr("CANARY_ZONE", ""), "authoritative canary zone, e.g. c.echo-lot.app") fs.StringVar(&c.CanaryZone, "canary-zone", envOr("CANARY_ZONE", ""), "authoritative canary zone, e.g. c.echo-lot.app")
fs.StringVar(&c.HTTPEchoListen, "http-echo-listen", envOr("HTTP_ECHO_LISTEN", ""), "optional CLEARTEXT http-echo listen address(es); empty disables (spec §4)") fs.StringVar(&c.HTTPEchoListen, "http-echo-listen", envOr("HTTP_ECHO_LISTEN", ""), "optional CLEARTEXT http-echo listen address(es); empty disables (spec §4)")
fs.StringVar(&c.MTUProbeTargets, "mtu-probe-targets", envOr("MTU_PROBE_TARGETS", "1.1.1.1,2606:4700:4700::1111"), "egress-MTU self-proof anchors, comma-separated")
fs.StringVar(&c.AdminListen, "admin-listen", envOr("ADMIN_LISTEN", "127.0.0.1:8444"), "admin/health listen address (keep localhost)") fs.StringVar(&c.AdminListen, "admin-listen", envOr("ADMIN_LISTEN", "127.0.0.1:8444"), "admin/health listen address (keep localhost)")
fs.StringVar(&c.StateDir, "state-dir", envOr("STATE_DIR", defaultStateDir()), "state directory (device store, generated TLS)") fs.StringVar(&c.StateDir, "state-dir", envOr("STATE_DIR", defaultStateDir()), "state directory (device store, generated TLS)")
fs.StringVar(&c.Name, "name", envOr("NAME", "echolot"), "server profile name") fs.StringVar(&c.Name, "name", envOr("NAME", "echolot"), "server profile name")
+16
View File
@@ -53,6 +53,11 @@ type Server struct {
CanaryQueries func(sessionPrefix string) any CanaryQueries func(sessionPrefix string) any
// CanaryZone is surfaced in the profile so the app knows what to query. // CanaryZone is surfaced in the profile so the app knows what to query.
CanaryZone string CanaryZone string
// ProvenGood reports the server's self-test signal (may be nil). Surfaced
// in the profile so a client can trust — or skip — MTU tests: if the
// server's own egress isn't full-MTU, client MTU results measure the
// server, not the client.
ProvenGood func() (mtuOK, sysctlOK bool)
} }
func (s *Server) Handler() http.Handler { func (s *Server) Handler() http.Handler {
@@ -78,6 +83,16 @@ func (s *Server) EchoHandler() http.Handler {
return mux return mux
} }
// selftestSignal is the compact "server proven good" object for the profile.
// mtu_ok=false tells a client its MTU results would measure this server.
func selftestSignal(f func() (bool, bool)) map[string]any {
if f == nil {
return map[string]any{"mtu_ok": nil, "sysctl_ok": nil}
}
mtuOK, sysctlOK := f()
return map[string]any{"mtu_ok": mtuOK, "sysctl_ok": sysctlOK}
}
// sessionAuth resolves {id} and requires the bearer to be the owning device. // sessionAuth resolves {id} and requires the bearer to be the owning device.
func (s *Server) sessionAuth(w http.ResponseWriter, r *http.Request) *session.Session { func (s *Server) sessionAuth(w http.ResponseWriter, r *http.Request) *session.Session {
dev := s.Store.DeviceByCredential(bearer(r)) dev := s.Store.DeviceByCredential(bearer(r))
@@ -267,6 +282,7 @@ func (s *Server) profile(w http.ResponseWriter, r *http.Request) {
"pins": []string{"pin-sha256:" + s.PinB64}, "pins": []string{"pin-sha256:" + s.PinB64},
"next_pins": []string{}, "next_pins": []string{},
"canary_zone": s.CanaryZone, "canary_zone": s.CanaryZone,
"server_selftest": selftestSignal(s.ProvenGood),
"limits": map[string]any{"max_kbps": 50000, "max_session_s": 900}, "limits": map[string]any{"max_kbps": 50000, "max_session_s": 900},
}) })
} }
+112
View File
@@ -0,0 +1,112 @@
// SPDX-FileCopyrightText: 2026 Echolot contributors
// SPDX-License-Identifier: GPL-3.0-or-later
//go:build linux
package selftest
import (
"net"
"net/netip"
"syscall"
"time"
)
// Linux IP-level constants for PMTU discovery. Not all are exported by the
// stdlib syscall package across versions, so they are pinned here (stable
// kernel ABI) — same rationale as the prober's OsAbi.
const (
ipMTUDiscover = 10 // IP_MTU_DISCOVER
ipMTU = 14 // IP_MTU
ipPMTUDiscDo = 2 // IP_PMTUDISC_DO (set DF, honor PMTU)
ipv6MTUDiscover = 23 // IPV6_MTU_DISCOVER
ipv6MTU = 24 // IPV6_MTU
ipv6PMTUDiscDo = 2 // IPV6_PMTUDISC_DO
)
// probeEgressMTU sends a DF-flagged full-size UDP datagram toward target and
// reads back the kernel's discovered path MTU. A reduction below 1500 means
// the SERVER's own uplink can't carry full-size packets — so client MTU
// results would measure the server, not the client. No root, no raw socket:
// IP_MTU_DISCOVER + a getsockopt on IP_MTU, mirroring the prober's approach.
func probeEgressMTU(target string) MTUResult {
res := MTUResult{Target: target}
addr, err := netip.ParseAddr(target)
if err != nil {
// allow "host" that resolves
ips, e := net.LookupIP(target)
if e != nil || len(ips) == 0 {
res.Err = "resolve: " + errStr(err)
return res
}
addr, _ = netip.AddrFromSlice(ips[0])
}
addr = addr.Unmap()
is4 := addr.Is4()
fam := syscall.AF_INET6
if is4 {
fam = syscall.AF_INET
}
fd, err := syscall.Socket(fam, syscall.SOCK_DGRAM, 0)
if err != nil {
res.Err = "socket: " + errStr(err)
return res
}
defer syscall.Close(fd)
if is4 {
_ = syscall.SetsockoptInt(fd, syscall.IPPROTO_IP, ipMTUDiscover, ipPMTUDiscDo)
} else {
_ = syscall.SetsockoptInt(fd, syscall.IPPROTO_IPV6, ipv6MTUDiscover, ipv6PMTUDiscDo)
}
// IP_MTU reflects the CONNECTED path's MTU, so the socket must be connected
// (an unconnected socket returns ENOTCONN). No handshake — UDP connect just
// pins the destination and resolves the route.
sa := sockaddr(addr, 33434)
if err := syscall.Connect(fd, sa); err != nil {
res.Err = "connect: " + errStr(err)
return res
}
// Full-size probe: 1500 total IP/UDP headers (28 v4, 48 v6). A DF send
// larger than the local MTU fails immediately with EMSGSIZE; a path
// reduction updates IP_MTU after the ICMP frag-needed returns, so we send,
// briefly wait, and read the discovered MTU.
payload := 1472
if !is4 {
payload = 1452
}
probe := make([]byte, payload)
_, _ = syscall.Write(fd, probe)
time.Sleep(700 * time.Millisecond)
_, _ = syscall.Write(fd, probe) // second send observes any reduction
level, opt := syscall.IPPROTO_IP, ipMTU
if !is4 {
level, opt = syscall.IPPROTO_IPV6, ipv6MTU
}
mtu, err := syscall.GetsockoptInt(fd, level, opt)
if err != nil || mtu <= 0 {
res.Err = "getsockopt IP_MTU: " + errStr(err)
return res
}
res.DiscoveredMTU = mtu
res.FullMTU = mtu >= 1500
return res
}
func sockaddr(a netip.Addr, port int) syscall.Sockaddr {
if a.Is4() {
return &syscall.SockaddrInet4{Port: port, Addr: a.As4()}
}
return &syscall.SockaddrInet6{Port: port, Addr: a.As16()}
}
func errStr(err error) string {
if err == nil {
return "nil"
}
return err.Error()
}
+13
View File
@@ -0,0 +1,13 @@
// SPDX-FileCopyrightText: 2026 Echolot contributors
// SPDX-License-Identifier: GPL-3.0-or-later
//go:build !linux
package selftest
// probeEgressMTU: PMTUD via IP_MTU_DISCOVER is Linux-specific. Off-Linux the
// self-test reports MTU as unproven rather than guessing (the daemon runs on
// Linux in production; this keeps dev builds compiling).
func probeEgressMTU(target string) MTUResult {
return MTUResult{Target: target, Err: "egress MTU probe is Linux-only"}
}
+126
View File
@@ -0,0 +1,126 @@
// SPDX-FileCopyrightText: 2026 Echolot contributors
// SPDX-License-Identifier: GPL-3.0-or-later
// Package selftest lets the daemon prove its own host is a clean measurement
// target: the kernel isn't silently altering what clients measure, and the
// server's own egress reaches full MTU. If the server side is already broken,
// client-side results (especially MTU/PMTUD) measure the server, not the
// client — so the daemon says so.
package selftest
import (
"os"
"strconv"
"strings"
)
// Severity of a check result.
type Severity string
const (
OK Severity = "ok"
Warn Severity = "warn"
)
// Check is one sysctl (or derived) assertion.
type Check struct {
Name string `json:"name"`
Got string `json:"got"`
Want string `json:"want"`
Severity Severity `json:"severity"`
Why string `json:"why"`
}
// MTUResult is one egress path-MTU probe outcome.
type MTUResult struct {
Target string `json:"target"`
DiscoveredMTU int `json:"discovered_mtu"`
FullMTU bool `json:"full_mtu"` // >= 1500
Err string `json:"err,omitempty"`
}
// Report is the whole self-test.
type Report struct {
Sysctls []Check `json:"sysctls"`
EgressMTU []MTUResult `json:"egress_mtu"`
// SysctlOK / MTUOK are the compact "server proven good" signals; the
// profile surfaces these so a client can skip MTU tests the server can't
// support honestly.
SysctlOK bool `json:"sysctl_ok"`
MTUOK bool `json:"mtu_ok"`
}
// readSysctl reads /proc/sys/<dotted.name>. Empty string if unavailable.
func readSysctl(name string) string {
p := "/proc/sys/" + strings.ReplaceAll(name, ".", "/")
b, err := os.ReadFile(p)
if err != nil {
return ""
}
return strings.TrimSpace(string(b))
}
// sysctlChecks are the measurement-fidelity assertions. Each closure returns
// OK/Warn given the read value; a missing value (non-Linux / restricted) is
// reported as Warn "unreadable" but never fatal.
var sysctlChecks = []struct {
name string
want string
why string
ok func(v string) bool
}{
{"net.ipv6.conf.all.accept_ra", "0", "static v6 host must not let RAs mutate routing (the very thing Echolot detects)", eq("0")},
{"net.ipv4.conf.all.accept_redirects", "0", "ICMP redirects could alter routing mid-measurement", eq("0")},
{"net.ipv4.conf.all.send_redirects", "0", "an endpoint should not emit ICMP redirects", eq("0")},
{"net.ipv4.icmp_echo_ignore_all", "0", "server must answer ping so clients can measure to it", eq("0")},
{"net.ipv4.ip_no_pmtu_disc", "0", "server must honor path MTU on its own sends", eq("0")},
{"net.ipv4.tcp_sack", "1", "so a missing SACK in mss_observed is the path's fault, not the server's", eq("1")},
{"net.ipv4.tcp_timestamps", "1", "so TCP-timestamp absence reflects the path, not the server", eq("1")},
{"net.ipv4.tcp_window_scaling", "1", "so wscale absence reflects the path, not the server", eq("1")},
{"net.ipv4.icmp_ratelimit", "0", "nonzero throttles the server's ICMP errors → false loss/black-hole readings", eq("0")},
}
func eq(want string) func(string) bool { return func(v string) bool { return v == want } }
// Sysctls runs the sysctl audit.
func Sysctls() []Check {
out := make([]Check, 0, len(sysctlChecks))
for _, c := range sysctlChecks {
got := readSysctl(c.name)
sev := Warn
switch {
case got == "":
got = "(unreadable)"
case c.ok(got):
sev = OK
}
out = append(out, Check{Name: c.name, Got: got, Want: c.want, Severity: sev, Why: c.why})
}
return out
}
// Run performs the full self-test: sysctl audit + egress MTU probes to the
// given targets (each "host" — port is irrelevant for PMTUD).
func Run(mtuTargets []string) Report {
r := Report{Sysctls: Sysctls()}
r.SysctlOK = true
for _, c := range r.Sysctls {
if c.Severity == Warn {
r.SysctlOK = false
}
}
r.MTUOK = true
for _, t := range mtuTargets {
res := probeEgressMTU(t)
r.EgressMTU = append(r.EgressMTU, res)
if !res.FullMTU {
r.MTUOK = false
}
}
if len(r.EgressMTU) == 0 {
r.MTUOK = false // couldn't prove it
}
return r
}
var _ = strconv.Atoi