blob: f39730fdc078ebee41bd63afe92bf6fcea5f28d3 [file] [log] [blame]
Andreea Costinas942284d2020-01-28 16:28:40 +01001// Copyright 2020 The Chromium OS Authors. All rights reserved.
2// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4#ifndef SYSTEM_PROXY_SYSTEM_PROXY_ADAPTOR_H_
5#define SYSTEM_PROXY_SYSTEM_PROXY_ADAPTOR_H_
6
7#include <memory>
Andreea Costinasc7d5ad02020-03-09 09:41:51 +01008#include <string>
Andreea Costinas942284d2020-01-28 16:28:40 +01009#include <vector>
10
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010011#include <base/memory/weak_ptr.h>
Andreea Costinas942284d2020-01-28 16:28:40 +010012#include <brillo/dbus/async_event_sequencer.h>
Andreea Costinas5862b102020-03-19 14:45:36 +010013#include <brillo/http/http_proxy.h>
Andreea Costinas41e06442020-03-09 09:41:51 +010014#include <gtest/gtest_prod.h> // for FRIEND_TEST
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010015#include <patchpanel/proto_bindings/patchpanel_service.pb.h>
Andreea Costinas942284d2020-01-28 16:28:40 +010016
Andreea Costinasdb2cbee2020-06-15 11:43:44 +020017#include "bindings/worker_common.pb.h"
Andreea Costinas942284d2020-01-28 16:28:40 +010018#include "system_proxy/org.chromium.SystemProxy.h"
Andreea Costinasfc3dc7d2020-07-20 18:54:38 +020019#include "system_proxy/proto_bindings/system_proxy_service.pb.h"
Andreea Costinas942284d2020-01-28 16:28:40 +010020
21namespace brillo {
22namespace dbus_utils {
23class DBusObject;
24}
25
26} // namespace brillo
27
28namespace system_proxy {
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010029
Andreea Costinas922fbaf2020-05-28 11:55:22 +020030class KerberosClient;
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010031class SandboxedWorker;
32
Andreea Costinas942284d2020-01-28 16:28:40 +010033// Implementation of the SystemProxy D-Bus interface.
34class SystemProxyAdaptor : public org::chromium::SystemProxyAdaptor,
35 public org::chromium::SystemProxyInterface {
36 public:
37 explicit SystemProxyAdaptor(
38 std::unique_ptr<brillo::dbus_utils::DBusObject> dbus_object);
39 SystemProxyAdaptor(const SystemProxyAdaptor&) = delete;
40 SystemProxyAdaptor& operator=(const SystemProxyAdaptor&) = delete;
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010041 virtual ~SystemProxyAdaptor();
Andreea Costinas942284d2020-01-28 16:28:40 +010042
43 // Registers the D-Bus object and interfaces.
44 void RegisterAsync(
45 const brillo::dbus_utils::AsyncEventSequencer::CompletionAction&
46 completion_callback);
47
48 // org::chromium::SystemProxyInterface: (see org.chromium.SystemProxy.xml).
Andreea Costinas77b180e2020-05-12 15:17:32 +020049 std::vector<uint8_t> SetAuthenticationDetails(
50 const std::vector<uint8_t>& request_blob) override;
Andreea Costinas942284d2020-01-28 16:28:40 +010051 std::vector<uint8_t> ShutDown() override;
Andreea Costinase9c73592020-07-17 15:27:54 +020052 std::vector<uint8_t> ClearUserCredentials(
53 const std::vector<uint8_t>& request_blob) override;
Andreea Costinasfc3dc7d2020-07-20 18:54:38 +020054 std::vector<uint8_t> ShutDownProcess(
55 const std::vector<uint8_t>& request_blob) override;
Andreea Costinas942284d2020-01-28 16:28:40 +010056
Andreea Costinas5862b102020-03-19 14:45:36 +010057 void GetChromeProxyServersAsync(
58 const std::string& target_url,
59 const brillo::http::GetChromeProxyServersCallback& callback);
60
Andreea Costinasdb2cbee2020-06-15 11:43:44 +020061 void RequestAuthenticationCredentials(
62 const worker::ProtectionSpace& protection_space);
63
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010064 protected:
65 virtual std::unique_ptr<SandboxedWorker> CreateWorker();
Andreea Costinas91f75352020-07-08 14:47:47 +020066 virtual void ConnectNamespace(SandboxedWorker* worker, bool user_traffic);
Andreea Costinasa89309d2020-05-08 15:51:12 +020067 // Triggers the |WorkerActive| signal.
68 void OnNamespaceConnected(SandboxedWorker* worker, bool user_traffic);
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010069
Andreea Costinas942284d2020-01-28 16:28:40 +010070 private:
Andreea Costinas41e06442020-03-09 09:41:51 +010071 friend class SystemProxyAdaptorTest;
Andreea Costinas77b180e2020-05-12 15:17:32 +020072 FRIEND_TEST(SystemProxyAdaptorTest, SetAuthenticationDetails);
Andreea Costinas922fbaf2020-05-28 11:55:22 +020073 FRIEND_TEST(SystemProxyAdaptorTest, KerberosEnabled);
Andreea Costinas41e06442020-03-09 09:41:51 +010074 FRIEND_TEST(SystemProxyAdaptorTest, ShutDown);
Andreea Costinasa89309d2020-05-08 15:51:12 +020075 FRIEND_TEST(SystemProxyAdaptorTest, ConnectNamespace);
76 FRIEND_TEST(SystemProxyAdaptorTest, ProxyResolutionFilter);
Andreea Costinasdb2cbee2020-06-15 11:43:44 +020077 FRIEND_TEST(SystemProxyAdaptorTest, ProtectionSpaceAuthenticationRequired);
78 FRIEND_TEST(SystemProxyAdaptorTest, ProtectionSpaceNoCredentials);
Andreea Costinase9c73592020-07-17 15:27:54 +020079 FRIEND_TEST(SystemProxyAdaptorTest, ClearUserCredentials);
80 FRIEND_TEST(SystemProxyAdaptorTest, ClearUserCredentialsRestartService);
Andreea Costinas41e06442020-03-09 09:41:51 +010081
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010082 void SetCredentialsTask(SandboxedWorker* worker,
Andreea Costinasdb2cbee2020-06-15 11:43:44 +020083 const worker::Credentials& credentials);
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010084
Andreea Costinas922fbaf2020-05-28 11:55:22 +020085 void SetKerberosEnabledTask(SandboxedWorker* worker,
86 bool kerberos_enabled,
87 const std::string& principal_name);
88
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010089 void ShutDownTask();
90
Andreea Costinas91f75352020-07-08 14:47:47 +020091 void ConnectNamespaceTask(SandboxedWorker* worker, bool user_traffic);
92
Andreea Costinasedb7c8e2020-04-22 10:58:04 +020093 bool StartWorker(SandboxedWorker* worker, bool user_traffic);
Andreea Costinasc7d5ad02020-03-09 09:41:51 +010094
Andreea Costinase9c73592020-07-17 15:27:54 +020095 // Terminates the worker process for traffic indicated by |user_traffic| and
96 // frees the SandboxedWorker associated with it.
97 bool ResetWorker(bool user_traffic);
98
99 // Returns a pointer to the worker process associated with |user_traffic|. Can
100 // return nullptr.
101 SandboxedWorker* GetWorker(bool user_traffic);
102
Andreea Costinasfc3dc7d2020-07-20 18:54:38 +0200103 // Return true if |traffic_origin| represents the traffic originating from
104 // system services or if it includes all traffic.
105 bool IncludesSystemTraffic(TrafficOrigin traffic_origin);
106 // Return true if |traffic_origin| represents the traffic originating from ARC
107 // or if it includes all traffic.
108 bool IncludesUserTraffic(TrafficOrigin traffic_origin);
109
Andreea Costinas77b180e2020-05-12 15:17:32 +0200110 // Checks if a worker process exists and if not creates one and sends a
111 // request to patchpanel to setup the network namespace for it. Returns true
112 // if the worker exists or was created successfully, false otherwise.
113 bool CreateWorkerIfNeeded(bool user_traffic);
114
Andreea Costinase9c73592020-07-17 15:27:54 +0200115 // Sends a request to the worker process associated with |user_traffic| to
116 // clear the cached user credentials. If sending the request fails, the worker
117 // will be restarted.
118 void ClearUserCredentials(bool user_traffic, std::string* error_message);
119
Andreea Costinasa89309d2020-05-08 15:51:12 +0200120 // Called when the patchpanel D-Bus service becomes available.
Andreea Costinasedb7c8e2020-04-22 10:58:04 +0200121 void OnPatchpanelServiceAvailable(bool is_available);
Andreea Costinasc7d5ad02020-03-09 09:41:51 +0100122
Andreea Costinas5862b102020-03-19 14:45:36 +0100123 // The callback of |GetChromeProxyServersAsync|.
124 void OnGetProxyServers(bool success, const std::vector<std::string>& servers);
125
Andreea Costinas91f75352020-07-08 14:47:47 +0200126 // The number of tries left for setting up the network namespace of the
127 // System-proxy worker for system traffic. TODO(acostinas, b/160736881) Remove
128 // when patchpaneld creates the veth pair directly across the host and worker
129 // network namespaces.
130 int netns_reconnect_attempts_available_;
131
Andreea Costinasc7d5ad02020-03-09 09:41:51 +0100132 // Worker that authenticates and forwards to a remote web proxy traffic
133 // coming form Chrome OS system services.
134 std::unique_ptr<SandboxedWorker> system_services_worker_;
135 // Worker that authenticates and forwards to a remote web proxy traffic
136 // coming form ARC++ apps.
137 std::unique_ptr<SandboxedWorker> arc_worker_;
Andreea Costinas922fbaf2020-05-28 11:55:22 +0200138 std::unique_ptr<KerberosClient> kerberos_client_;
139
Andreea Costinas942284d2020-01-28 16:28:40 +0100140 std::unique_ptr<brillo::dbus_utils::DBusObject> dbus_object_;
Andreea Costinasc7d5ad02020-03-09 09:41:51 +0100141 base::WeakPtrFactory<SystemProxyAdaptor> weak_ptr_factory_;
Andreea Costinas942284d2020-01-28 16:28:40 +0100142};
143
144} // namespace system_proxy
145#endif // SYSTEM_PROXY_SYSTEM_PROXY_ADAPTOR_H_