1
0
mirror of https://github.com/golang/go synced 2024-11-22 13:04:44 -07:00
go/src
Roland Shoemaker 9eeb627f60 crypto/tls: add ech client support
This CL adds a (very opinionated) client-side ECH implementation.

In particular, if a user configures a ECHConfigList, by setting the
Config.EncryptedClientHelloConfigList, but we determine that none of
the configs are appropriate, we will not fallback to plaintext SNI, and
will instead return an error. It is then up to the user to decide if
they wish to fallback to plaintext themselves (by removing the config
list).

Additionally if Config.EncryptedClientHelloConfigList is provided, we
will not offer TLS support lower than 1.3, since negotiating any other
version, while offering ECH, is a hard error anyway. Similarly, if a
user wishes to fallback to plaintext SNI by using 1.2, they may do so
by removing the config list.

With regard to PSK GREASE, we match the boringssl  behavior, which does
not include PSK identities/binders in the outer hello when doing ECH.

If the server rejects ECH, we will return a ECHRejectionError error,
which, if provided by the server, will contain a ECHConfigList in the
RetryConfigList field containing configs that should be used if the user
wishes to retry. It is up to the user to replace their existing
Config.EncryptedClientHelloConfigList with the retry config list.

Fixes #63369

Cq-Include-Trybots: luci.golang.try:gotip-linux-amd64-longtest
Change-Id: I9bc373c044064221a647a388ac61624efd6bbdbf
Reviewed-on: https://go-review.googlesource.com/c/go/+/578575
Reviewed-by: Ian Lance Taylor <iant@google.com>
Reviewed-by: Filippo Valsorda <filippo@golang.org>
Reviewed-by: Than McIntosh <thanm@google.com>
Reviewed-by: Dmitri Shuralyov <dmitshur@golang.org>
Auto-Submit: Roland Shoemaker <roland@golang.org>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
2024-05-23 03:10:12 +00:00
..
archive all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
arena
bufio
builtin
bytes all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
cmd go/types, types2: factor out check for updated type arguments (cleanup) 2024-05-23 03:04:07 +00:00
cmp
compress
container
context
crypto crypto/tls: add ech client support 2024-05-23 03:10:12 +00:00
database/sql all: document legacy //go:linkname for modules with ≥500 dependents 2024-05-23 01:16:53 +00:00
debug
embed
encoding all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
errors
expvar
flag
fmt all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
go go/types, types2: factor out check for updated type arguments (cleanup) 2024-05-23 03:04:07 +00:00
hash
html
image
index/suffixarray all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
internal go/types, types2: instantiate generic alias types 2024-05-23 03:01:18 +00:00
io all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
iter
log
maps
math all: document legacy //go:linkname for modules with ≥5,000 dependents 2024-05-23 01:15:13 +00:00
mime all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
net all: document legacy //go:linkname for modules with ≥200 dependents 2024-05-23 01:17:26 +00:00
os all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
path all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
plugin
reflect all: document legacy //go:linkname for modules with ≥2,000 dependents 2024-05-23 01:16:47 +00:00
regexp
runtime runtime: move exit hooks into internal/runtime/exithook 2024-05-23 02:32:19 +00:00
slices
sort
strconv
strings
structs
sync all: document legacy //go:linkname for modules with ≥500 dependents 2024-05-23 01:16:53 +00:00
syscall all: document legacy //go:linkname for modules with ≥1,000 dependents 2024-05-23 01:16:50 +00:00
testdata
testing all: change from sort functions to slices functions where feasible 2024-05-23 01:00:11 +00:00
text
time all: document legacy //go:linkname for modules with ≥200 dependents 2024-05-23 01:17:26 +00:00
unicode
unique
unsafe
vendor
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod
go.sum
make.bash
make.bat
Make.dist
make.rc
race.bash
race.bat
README.vendor
run.bash
run.bat
run.rc

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

There are two modules, std and cmd, defined in src/go.mod and
src/cmd/go.mod. When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure that GO111MODULE is not set in the environment, or that it is
set to 'on' or 'auto', and if you use a go.work file, set GOWORK=off.

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src  # or src/cmd
    go get golang.org/x/net@master
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.