2022-07-01 18:19:57 +00:00
|
|
|
# Nim-LibP2P
|
2024-03-05 07:06:27 +00:00
|
|
|
# Copyright (c) 2023-2024 Status Research & Development GmbH
|
2022-07-01 18:19:57 +00:00
|
|
|
# Licensed under either of
|
|
|
|
# * Apache License, version 2.0, ([LICENSE-APACHE](LICENSE-APACHE))
|
|
|
|
# * MIT license ([LICENSE-MIT](LICENSE-MIT))
|
|
|
|
# at your option.
|
|
|
|
# This file may not be copied, modified, or distributed except according to
|
|
|
|
# those terms.
|
2019-09-06 06:51:46 +00:00
|
|
|
|
2022-10-29 21:26:44 +00:00
|
|
|
{.push gcsafe.}
|
2023-06-07 11:12:49 +00:00
|
|
|
{.push raises: [].}
|
2021-05-21 16:27:01 +00:00
|
|
|
|
2022-05-24 13:10:57 +00:00
|
|
|
import std/[strformat]
|
2022-09-22 19:55:59 +00:00
|
|
|
import stew/results
|
2022-06-16 08:08:52 +00:00
|
|
|
import chronos, chronicles
|
2020-03-09 17:27:57 +00:00
|
|
|
import
|
|
|
|
../protocol,
|
2020-05-07 20:37:46 +00:00
|
|
|
../../stream/streamseq,
|
2020-06-19 17:29:43 +00:00
|
|
|
../../stream/connection,
|
2020-06-24 15:08:44 +00:00
|
|
|
../../multiaddress,
|
2020-11-24 00:22:15 +00:00
|
|
|
../../peerinfo,
|
|
|
|
../../errors
|
2019-09-06 06:51:46 +00:00
|
|
|
|
2022-09-22 19:55:59 +00:00
|
|
|
export protocol, results
|
2020-09-21 09:16:29 +00:00
|
|
|
|
2020-06-20 10:56:55 +00:00
|
|
|
logScope:
|
2020-12-01 17:34:27 +00:00
|
|
|
topics = "libp2p secure"
|
2020-06-20 10:56:55 +00:00
|
|
|
|
2020-11-05 03:52:54 +00:00
|
|
|
const SecureConnTrackerName* = "SecureConn"
|
|
|
|
|
2019-09-06 06:51:46 +00:00
|
|
|
type
|
|
|
|
Secure* = ref object of LPProtocol # base type for secure managers
|
2020-04-03 20:36:51 +00:00
|
|
|
|
2020-03-09 17:27:57 +00:00
|
|
|
SecureConn* = ref object of Connection
|
2020-06-19 17:29:43 +00:00
|
|
|
stream*: Connection
|
2020-05-07 20:37:46 +00:00
|
|
|
buf: StreamSeq
|
2020-03-09 17:27:57 +00:00
|
|
|
|
2020-09-06 08:31:47 +00:00
|
|
|
func shortLog*(conn: SecureConn): auto =
|
2021-05-21 16:27:01 +00:00
|
|
|
try:
|
2024-03-05 07:06:27 +00:00
|
|
|
if conn == nil:
|
|
|
|
"SecureConn(nil)"
|
2021-09-08 09:07:46 +00:00
|
|
|
else:
|
|
|
|
&"{shortLog(conn.peerId)}:{conn.oid}"
|
2021-05-21 16:27:01 +00:00
|
|
|
except ValueError as exc:
|
2024-03-05 07:06:27 +00:00
|
|
|
raiseAssert(exc.msg)
|
2021-05-21 16:27:01 +00:00
|
|
|
|
2020-09-06 08:31:47 +00:00
|
|
|
chronicles.formatIt(SecureConn):
|
|
|
|
shortLog(it)
|
|
|
|
|
2024-03-05 07:06:27 +00:00
|
|
|
proc new*(
|
|
|
|
T: type SecureConn,
|
|
|
|
conn: Connection,
|
|
|
|
peerId: PeerId,
|
|
|
|
observedAddr: Opt[MultiAddress],
|
|
|
|
timeout: Duration = DefaultConnectionTimeout,
|
|
|
|
): T =
|
2020-09-06 08:31:47 +00:00
|
|
|
result = T(
|
|
|
|
stream: conn,
|
2021-09-08 09:07:46 +00:00
|
|
|
peerId: peerId,
|
2020-06-24 15:08:44 +00:00
|
|
|
observedAddr: observedAddr,
|
2020-08-10 22:17:11 +00:00
|
|
|
closeEvent: conn.closeEvent,
|
2020-11-01 22:23:26 +00:00
|
|
|
timeout: timeout,
|
|
|
|
dir: conn.dir,
|
|
|
|
)
|
2020-06-24 15:08:44 +00:00
|
|
|
result.initStream()
|
|
|
|
|
2020-06-19 17:29:43 +00:00
|
|
|
method initStream*(s: SecureConn) =
|
|
|
|
if s.objName.len == 0:
|
2021-06-14 08:26:11 +00:00
|
|
|
s.objName = SecureConnTrackerName
|
2020-06-19 17:29:43 +00:00
|
|
|
|
|
|
|
procCall Connection(s).initStream()
|
|
|
|
|
2024-03-05 07:06:27 +00:00
|
|
|
method closeImpl*(s: SecureConn) {.async: (raises: []).} =
|
2020-11-01 22:23:26 +00:00
|
|
|
trace "Closing secure conn", s, dir = s.dir
|
2024-03-05 07:06:27 +00:00
|
|
|
if s.stream != nil:
|
2020-06-19 17:29:43 +00:00
|
|
|
await s.stream.close()
|
|
|
|
|
2020-12-09 14:56:40 +00:00
|
|
|
await procCall Connection(s).closeImpl()
|
2020-07-09 20:21:47 +00:00
|
|
|
|
2024-03-05 07:06:27 +00:00
|
|
|
method readMessage*(
|
|
|
|
c: SecureConn
|
|
|
|
): Future[seq[byte]] {.
|
|
|
|
async: (raises: [CancelledError, LPStreamError], raw: true), base
|
|
|
|
.} =
|
|
|
|
raiseAssert("Not implemented!")
|
2020-03-09 17:27:57 +00:00
|
|
|
|
2022-08-01 12:31:22 +00:00
|
|
|
method getWrapped*(s: SecureConn): Connection =
|
|
|
|
s.stream
|
|
|
|
|
2024-03-07 11:22:22 +00:00
|
|
|
method handshake*(
|
|
|
|
s: Secure, conn: Connection, initiator: bool, peerId: Opt[PeerId]
|
|
|
|
): Future[SecureConn] {.
|
|
|
|
async: (raises: [CancelledError, LPStreamError], raw: true), base
|
|
|
|
.} =
|
2024-03-05 07:06:27 +00:00
|
|
|
raiseAssert("Not implemented!")
|
2020-02-25 05:06:57 +00:00
|
|
|
|
2024-03-07 11:22:22 +00:00
|
|
|
proc handleConn(
|
|
|
|
s: Secure, conn: Connection, initiator: bool, peerId: Opt[PeerId]
|
|
|
|
): Future[Connection] {.async: (raises: [CancelledError, LPStreamError]).} =
|
2022-09-05 12:31:14 +00:00
|
|
|
var sconn = await s.handshake(conn, initiator, peerId)
|
2021-03-02 23:23:40 +00:00
|
|
|
# mark connection bottom level transport direction
|
|
|
|
# this is the safest place to do this
|
|
|
|
# we require this information in for example gossipsub
|
|
|
|
sconn.transportDir = if initiator: Direction.Out else: Direction.In
|
2020-09-04 16:30:45 +00:00
|
|
|
|
2024-03-01 17:06:26 +00:00
|
|
|
proc cleanup() {.async: (raises: []).} =
|
2020-09-04 16:30:45 +00:00
|
|
|
try:
|
2024-03-01 17:06:26 +00:00
|
|
|
block:
|
|
|
|
let
|
|
|
|
fut1 = conn.join()
|
|
|
|
fut2 = sconn.join()
|
2024-03-03 23:06:32 +00:00
|
|
|
try: # https://github.com/status-im/nim-chronos/issues/516
|
|
|
|
discard await race(fut1, fut2)
|
|
|
|
except ValueError:
|
|
|
|
raiseAssert("Futures list is not empty")
|
|
|
|
# at least one join() completed, cancel pending one, if any
|
2024-03-01 17:06:26 +00:00
|
|
|
if not fut1.finished:
|
|
|
|
await fut1.cancelAndWait()
|
|
|
|
if not fut2.finished:
|
|
|
|
await fut2.cancelAndWait()
|
|
|
|
block:
|
|
|
|
let
|
|
|
|
fut1 = sconn.close()
|
|
|
|
fut2 = conn.close()
|
|
|
|
await allFutures(fut1, fut2)
|
2024-03-07 11:22:22 +00:00
|
|
|
static:
|
|
|
|
doAssert typeof(fut1).E is void
|
|
|
|
# Cannot fail
|
|
|
|
static:
|
|
|
|
doAssert typeof(fut2).E is void
|
|
|
|
# Cannot fail
|
2020-11-01 20:49:25 +00:00
|
|
|
except CancelledError:
|
|
|
|
# This is top-level procedure which will work as separate task, so it
|
2020-11-01 22:23:26 +00:00
|
|
|
# do not need to propagate CancelledError.
|
2020-11-01 20:49:25 +00:00
|
|
|
discard
|
2020-09-04 16:30:45 +00:00
|
|
|
|
2024-03-05 07:06:27 +00:00
|
|
|
if sconn != nil:
|
2020-09-04 16:30:45 +00:00
|
|
|
# All the errors are handled inside `cleanup()` procedure.
|
|
|
|
asyncSpawn cleanup()
|
2020-02-25 05:06:57 +00:00
|
|
|
|
2024-03-07 11:22:22 +00:00
|
|
|
sconn
|
2020-02-25 05:06:57 +00:00
|
|
|
|
2020-12-09 14:56:40 +00:00
|
|
|
method init*(s: Secure) =
|
2020-07-07 11:14:11 +00:00
|
|
|
procCall LPProtocol(s).init()
|
|
|
|
|
2020-12-09 14:56:40 +00:00
|
|
|
proc handle(conn: Connection, proto: string) {.async.} =
|
2020-09-06 08:31:47 +00:00
|
|
|
trace "handling connection upgrade", proto, conn
|
2020-02-25 05:06:57 +00:00
|
|
|
try:
|
2020-07-08 00:33:05 +00:00
|
|
|
# We don't need the result but we
|
|
|
|
# definitely need to await the handshake
|
2022-09-05 12:31:14 +00:00
|
|
|
discard await s.handleConn(conn, false, Opt.none(PeerId))
|
2020-09-06 08:31:47 +00:00
|
|
|
trace "connection secured", conn
|
2020-06-29 15:15:31 +00:00
|
|
|
except CancelledError as exc:
|
2020-09-06 08:31:47 +00:00
|
|
|
warn "securing connection canceled", conn
|
2020-06-29 15:15:31 +00:00
|
|
|
await conn.close()
|
2020-08-06 18:14:40 +00:00
|
|
|
raise exc
|
2024-03-07 11:22:22 +00:00
|
|
|
except LPStreamError as exc:
|
2024-08-14 15:19:54 +00:00
|
|
|
warn "securing connection failed", description = exc.msg, conn
|
2020-05-23 16:51:54 +00:00
|
|
|
await conn.close()
|
2020-02-25 05:06:57 +00:00
|
|
|
|
|
|
|
s.handler = handle
|
|
|
|
|
2024-03-07 11:22:22 +00:00
|
|
|
method secure*(
|
|
|
|
s: Secure, conn: Connection, peerId: Opt[PeerId]
|
|
|
|
): Future[Connection] {.
|
|
|
|
async: (raises: [CancelledError, LPStreamError], raw: true), base
|
|
|
|
.} =
|
2023-11-29 16:38:47 +00:00
|
|
|
s.handleConn(conn, conn.dir == Direction.Out, peerId)
|
2020-05-07 20:37:46 +00:00
|
|
|
|
2024-03-05 07:06:27 +00:00
|
|
|
method readOnce*(
|
|
|
|
s: SecureConn, pbytes: pointer, nbytes: int
|
|
|
|
): Future[int] {.async: (raises: [CancelledError, LPStreamError]).} =
|
2020-09-16 09:55:25 +00:00
|
|
|
doAssert(nbytes > 0, "nbytes must be positive integer")
|
2020-06-29 15:15:31 +00:00
|
|
|
|
2020-12-09 14:56:40 +00:00
|
|
|
if s.isEof:
|
|
|
|
raise newLPStreamEOFError()
|
|
|
|
|
2020-06-29 15:15:31 +00:00
|
|
|
if s.buf.data().len() == 0:
|
2020-12-09 14:56:40 +00:00
|
|
|
try:
|
|
|
|
let buf = await s.readMessage() # Always returns >0 bytes or raises
|
|
|
|
s.activity = true
|
|
|
|
s.buf.add(buf)
|
|
|
|
except LPStreamEOFError as err:
|
|
|
|
s.isEof = true
|
|
|
|
await s.close()
|
|
|
|
raise err
|
2022-06-24 09:11:23 +00:00
|
|
|
except CancelledError as exc:
|
|
|
|
raise exc
|
2024-03-05 07:06:27 +00:00
|
|
|
except LPStreamError as err:
|
2020-12-09 14:56:40 +00:00
|
|
|
debug "Error while reading message from secure connection, closing.",
|
|
|
|
error = err.name, message = err.msg, connection = s
|
2020-10-19 05:13:14 +00:00
|
|
|
await s.close()
|
|
|
|
raise err
|
2020-06-29 15:15:31 +00:00
|
|
|
|
|
|
|
var p = cast[ptr UncheckedArray[byte]](pbytes)
|
|
|
|
return s.buf.consumeTo(toOpenArray(p, 0, nbytes - 1))
|