2019-09-06 00:51:46 -06:00
|
|
|
## Nim-LibP2P
|
2019-09-24 11:48:23 -06:00
|
|
|
## Copyright (c) 2019 Status Research & Development GmbH
|
2019-09-06 00:51:46 -06:00
|
|
|
## Licensed under either of
|
|
|
|
## * Apache License, version 2.0, ([LICENSE-APACHE](LICENSE-APACHE))
|
|
|
|
## * MIT license ([LICENSE-MIT](LICENSE-MIT))
|
|
|
|
## at your option.
|
|
|
|
## This file may not be copied, modified, or distributed except according to
|
|
|
|
## those terms.
|
|
|
|
|
2020-09-06 10:31:47 +02:00
|
|
|
import std/[options, strformat]
|
2020-07-07 13:14:11 +02:00
|
|
|
import chronos, chronicles, bearssl
|
2020-03-09 11:27:57 -06:00
|
|
|
import ../protocol,
|
2020-05-07 22:37:46 +02:00
|
|
|
../../stream/streamseq,
|
2020-06-19 11:29:43 -06:00
|
|
|
../../stream/connection,
|
2020-06-24 09:08:44 -06:00
|
|
|
../../multiaddress,
|
2020-11-23 18:22:15 -06:00
|
|
|
../../peerinfo,
|
|
|
|
../../errors
|
2019-09-06 00:51:46 -06:00
|
|
|
|
2020-09-21 18:16:29 +09:00
|
|
|
export protocol
|
|
|
|
|
2020-06-20 19:56:55 +09:00
|
|
|
logScope:
|
|
|
|
topics = "secure"
|
|
|
|
|
2020-11-04 21:52:54 -06:00
|
|
|
const
|
|
|
|
SecureConnTrackerName* = "SecureConn"
|
|
|
|
|
2019-09-06 00:51:46 -06:00
|
|
|
type
|
|
|
|
Secure* = ref object of LPProtocol # base type for secure managers
|
2020-04-03 14:36:51 -06:00
|
|
|
|
2020-03-09 11:27:57 -06:00
|
|
|
SecureConn* = ref object of Connection
|
2020-06-19 11:29:43 -06:00
|
|
|
stream*: Connection
|
2020-05-07 22:37:46 +02:00
|
|
|
buf: StreamSeq
|
2020-03-09 11:27:57 -06:00
|
|
|
|
2020-09-06 10:31:47 +02:00
|
|
|
func shortLog*(conn: SecureConn): auto =
|
|
|
|
if conn.isNil: "SecureConn(nil)"
|
|
|
|
elif conn.peerInfo.isNil: $conn.oid
|
|
|
|
else: &"{shortLog(conn.peerInfo.peerId)}:{conn.oid}"
|
|
|
|
chronicles.formatIt(SecureConn): shortLog(it)
|
|
|
|
|
|
|
|
proc init*(T: type SecureConn,
|
|
|
|
conn: Connection,
|
|
|
|
peerInfo: PeerInfo,
|
|
|
|
observedAddr: Multiaddress,
|
|
|
|
timeout: Duration = DefaultConnectionTimeout): T =
|
|
|
|
result = T(stream: conn,
|
2020-06-24 09:08:44 -06:00
|
|
|
peerInfo: peerInfo,
|
|
|
|
observedAddr: observedAddr,
|
2020-08-10 16:17:11 -06:00
|
|
|
closeEvent: conn.closeEvent,
|
2020-11-01 16:23:26 -06:00
|
|
|
timeout: timeout,
|
|
|
|
dir: conn.dir)
|
2020-06-24 09:08:44 -06:00
|
|
|
result.initStream()
|
|
|
|
|
2020-06-19 11:29:43 -06:00
|
|
|
method initStream*(s: SecureConn) =
|
|
|
|
if s.objName.len == 0:
|
|
|
|
s.objName = "SecureConn"
|
|
|
|
|
|
|
|
procCall Connection(s).initStream()
|
|
|
|
|
|
|
|
method close*(s: SecureConn) {.async.} =
|
2020-11-01 16:23:26 -06:00
|
|
|
trace "Closing secure conn", s, dir = s.dir
|
2020-06-19 11:29:43 -06:00
|
|
|
if not(isNil(s.stream)):
|
|
|
|
await s.stream.close()
|
|
|
|
|
2020-07-09 14:21:47 -06:00
|
|
|
await procCall Connection(s).close()
|
|
|
|
|
2020-03-09 11:27:57 -06:00
|
|
|
method readMessage*(c: SecureConn): Future[seq[byte]] {.async, base.} =
|
|
|
|
doAssert(false, "Not implemented!")
|
|
|
|
|
2020-03-04 21:45:14 +02:00
|
|
|
method handshake(s: Secure,
|
|
|
|
conn: Connection,
|
2020-04-23 10:27:29 +09:00
|
|
|
initiator: bool): Future[SecureConn] {.async, base.} =
|
2020-02-24 23:06:57 -06:00
|
|
|
doAssert(false, "Not implemented!")
|
|
|
|
|
2020-07-07 18:33:05 -06:00
|
|
|
proc handleConn*(s: Secure,
|
|
|
|
conn: Connection,
|
|
|
|
initiator: bool): Future[Connection] {.async, gcsafe.} =
|
2020-03-08 04:14:56 +01:00
|
|
|
var sconn = await s.handshake(conn, initiator)
|
2020-09-04 19:30:45 +03:00
|
|
|
|
|
|
|
proc cleanup() {.async.} =
|
|
|
|
try:
|
2020-11-25 07:35:25 -06:00
|
|
|
let futs = @[conn.join(), sconn.join()]
|
|
|
|
await futs[0] or futs[1]
|
|
|
|
for f in futs:
|
2020-11-28 09:48:06 -06:00
|
|
|
if not f.finished: await f.cancelAndWait() # cancel outstanding join()
|
2020-11-25 07:35:25 -06:00
|
|
|
|
|
|
|
await allFuturesThrowing(
|
|
|
|
sconn.close(), conn.close())
|
2020-11-01 21:49:25 +01:00
|
|
|
except CancelledError:
|
|
|
|
# This is top-level procedure which will work as separate task, so it
|
2020-11-01 16:23:26 -06:00
|
|
|
# do not need to propagate CancelledError.
|
2020-11-01 21:49:25 +01:00
|
|
|
discard
|
2020-09-04 19:30:45 +03:00
|
|
|
except CatchableError as exc:
|
2020-09-06 10:31:47 +02:00
|
|
|
trace "error cleaning up secure connection", err = exc.msg, sconn
|
2020-09-04 19:30:45 +03:00
|
|
|
|
2020-07-09 10:53:19 +02:00
|
|
|
if not isNil(sconn):
|
2020-09-04 19:30:45 +03:00
|
|
|
# All the errors are handled inside `cleanup()` procedure.
|
|
|
|
asyncSpawn cleanup()
|
2020-02-24 23:06:57 -06:00
|
|
|
|
2020-06-24 09:08:44 -06:00
|
|
|
return sconn
|
2020-02-24 23:06:57 -06:00
|
|
|
|
|
|
|
method init*(s: Secure) {.gcsafe.} =
|
2020-07-07 13:14:11 +02:00
|
|
|
procCall LPProtocol(s).init()
|
|
|
|
|
2020-02-24 23:06:57 -06:00
|
|
|
proc handle(conn: Connection, proto: string) {.async, gcsafe.} =
|
2020-09-06 10:31:47 +02:00
|
|
|
trace "handling connection upgrade", proto, conn
|
2020-02-24 23:06:57 -06:00
|
|
|
try:
|
2020-07-07 18:33:05 -06:00
|
|
|
# We don't need the result but we
|
|
|
|
# definitely need to await the handshake
|
2020-03-24 15:34:02 +09:00
|
|
|
discard await s.handleConn(conn, false)
|
2020-09-06 10:31:47 +02:00
|
|
|
trace "connection secured", conn
|
2020-06-29 09:15:31 -06:00
|
|
|
except CancelledError as exc:
|
2020-09-06 10:31:47 +02:00
|
|
|
warn "securing connection canceled", conn
|
2020-06-29 09:15:31 -06:00
|
|
|
await conn.close()
|
2020-08-06 20:14:40 +02:00
|
|
|
raise exc
|
2020-02-24 23:06:57 -06:00
|
|
|
except CatchableError as exc:
|
2020-09-06 10:31:47 +02:00
|
|
|
warn "securing connection failed", err = exc.msg, conn
|
2020-05-23 10:51:54 -06:00
|
|
|
await conn.close()
|
2020-02-24 23:06:57 -06:00
|
|
|
|
|
|
|
s.handler = handle
|
|
|
|
|
2020-07-07 18:33:05 -06:00
|
|
|
method secure*(s: Secure,
|
|
|
|
conn: Connection,
|
|
|
|
initiator: bool):
|
2020-09-16 11:55:25 +02:00
|
|
|
Future[Connection] {.base, gcsafe.} =
|
|
|
|
s.handleConn(conn, initiator)
|
2020-05-07 22:37:46 +02:00
|
|
|
|
|
|
|
method readOnce*(s: SecureConn,
|
|
|
|
pbytes: pointer,
|
|
|
|
nbytes: int):
|
|
|
|
Future[int] {.async, gcsafe.} =
|
2020-09-16 11:55:25 +02:00
|
|
|
doAssert(nbytes > 0, "nbytes must be positive integer")
|
2020-06-29 09:15:31 -06:00
|
|
|
|
|
|
|
if s.buf.data().len() == 0:
|
2020-10-19 14:13:14 +09:00
|
|
|
let (buf, err) = try:
|
|
|
|
(await s.readMessage(), nil)
|
|
|
|
except CatchableError as exc:
|
|
|
|
(@[], exc)
|
|
|
|
|
|
|
|
if not isNil(err):
|
2020-10-21 10:08:24 +09:00
|
|
|
if not (err of LPStreamEOFError):
|
2020-11-24 12:07:27 -06:00
|
|
|
debug "Error while reading message from secure connection, closing.",
|
2020-11-01 16:23:26 -06:00
|
|
|
error=err.name,
|
|
|
|
message=err.msg,
|
2020-10-21 10:08:24 +09:00
|
|
|
connection=s
|
2020-10-19 14:13:14 +09:00
|
|
|
await s.close()
|
|
|
|
raise err
|
2020-11-01 16:23:26 -06:00
|
|
|
|
2020-08-15 07:36:15 +02:00
|
|
|
s.activity = true
|
2020-10-19 14:13:14 +09:00
|
|
|
|
2020-06-29 09:15:31 -06:00
|
|
|
if buf.len == 0:
|
|
|
|
raise newLPStreamIncompleteError()
|
2020-11-01 16:23:26 -06:00
|
|
|
|
2020-06-29 09:15:31 -06:00
|
|
|
s.buf.add(buf)
|
|
|
|
|
|
|
|
var p = cast[ptr UncheckedArray[byte]](pbytes)
|
|
|
|
return s.buf.consumeTo(toOpenArray(p, 0, nbytes - 1))
|