Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 1 | // Copyright 2020 The Chromium OS Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
| 5 | #include "system-proxy/server_proxy.h" |
| 6 | |
| 7 | #include <iostream> |
| 8 | #include <string> |
| 9 | #include <utility> |
| 10 | #include <vector> |
| 11 | |
| 12 | #include <base/bind.h> |
| 13 | #include <base/bind_helpers.h> |
| 14 | #include <base/callback_helpers.h> |
| 15 | #include <base/posix/eintr_wrapper.h> |
| 16 | #include <base/files/file_util.h> |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 17 | #include <base/strings/string_util.h> |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 18 | #include <base/threading/thread.h> |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 19 | #include <base/threading/thread_task_runner_handle.h> |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 20 | #include <brillo/data_encoding.h> |
| 21 | #include <brillo/http/http_transport.h> |
Garrick Evans | cd8c297 | 2020-04-14 14:35:52 +0900 | [diff] [blame] | 22 | #include <chromeos/patchpanel/socket.h> |
| 23 | #include <chromeos/patchpanel/socket_forwarder.h> |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 24 | |
| 25 | #include "bindings/worker_common.pb.h" |
| 26 | #include "system-proxy/protobuf_util.h" |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 27 | #include "system-proxy/proxy_connect_job.h" |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 28 | |
| 29 | namespace system_proxy { |
| 30 | |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 31 | namespace { |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 32 | |
| 33 | constexpr int kMaxConn = 100; |
Andreea Costinas | 922fbaf | 2020-05-28 11:55:22 +0200 | [diff] [blame] | 34 | // Name of the environment variable that points to the location of the kerberos |
| 35 | // credentials (ticket) cache. |
| 36 | constexpr char kKrb5CCEnvKey[] = "KRB5CCNAME"; |
| 37 | // Name of the environment variable that points to the kerberos configuration |
| 38 | // file which contains information regarding the locations of KDCs and admin |
| 39 | // servers for the Kerberos realms of interest, defaults for the current realm |
| 40 | // and for Kerberos applications, and mappings of hostnames onto Kerberos |
| 41 | // realms. |
| 42 | constexpr char kKrb5ConfEnvKey[] = "KRB5_CONFIG"; |
Andreea Costinas | bb2aa02 | 2020-06-13 00:03:23 +0200 | [diff] [blame^] | 43 | constexpr char kCredentialsColonSeparator[] = ":"; |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 44 | |
| 45 | // Returns the URL encoded value of |text|. It also verifies if the string was |
| 46 | // already encoded and, if true it returns it unmodified. |
| 47 | std::string UrlEncode(const std::string& text) { |
| 48 | if (text == brillo::data_encoding::UrlDecode(text.c_str())) |
| 49 | return brillo::data_encoding::UrlEncode(text.c_str(), false); |
| 50 | return text; |
| 51 | } |
| 52 | |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 53 | } // namespace |
| 54 | |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 55 | ServerProxy::ServerProxy(base::OnceClosure quit_closure) |
Andreea Costinas | bb2aa02 | 2020-06-13 00:03:23 +0200 | [diff] [blame^] | 56 | : system_credentials_(kCredentialsColonSeparator), |
| 57 | quit_closure_(std::move(quit_closure)), |
| 58 | weak_ptr_factory_(this) {} |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 59 | ServerProxy::~ServerProxy() = default; |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 60 | |
| 61 | void ServerProxy::Init() { |
| 62 | // Start listening for input. |
| 63 | stdin_watcher_ = base::FileDescriptorWatcher::WatchReadable( |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 64 | GetStdinPipe(), base::Bind(&ServerProxy::HandleStdinReadable, |
| 65 | weak_ptr_factory_.GetWeakPtr())); |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 66 | |
| 67 | // Handle termination signals. |
| 68 | signal_handler_.Init(); |
| 69 | for (int signal : {SIGINT, SIGTERM, SIGHUP, SIGQUIT}) { |
| 70 | signal_handler_.RegisterHandler( |
| 71 | signal, base::BindRepeating(&ServerProxy::HandleSignal, |
| 72 | base::Unretained(this))); |
| 73 | } |
| 74 | } |
| 75 | |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 76 | void ServerProxy::ResolveProxy(const std::string& target_url, |
| 77 | OnProxyResolvedCallback callback) { |
Andreea Costinas | 5862b10 | 2020-03-19 14:45:36 +0100 | [diff] [blame] | 78 | auto it = pending_proxy_resolution_requests_.find(target_url); |
| 79 | if (it != pending_proxy_resolution_requests_.end()) { |
| 80 | it->second.push_back(std::move(callback)); |
| 81 | return; |
| 82 | } |
Andreea Costinas | aae9738 | 2020-05-05 13:31:58 +0200 | [diff] [blame] | 83 | worker::ProxyResolutionRequest proxy_request; |
Andreea Costinas | 5862b10 | 2020-03-19 14:45:36 +0100 | [diff] [blame] | 84 | proxy_request.set_target_url(target_url); |
Andreea Costinas | aae9738 | 2020-05-05 13:31:58 +0200 | [diff] [blame] | 85 | worker::WorkerRequest request; |
Andreea Costinas | 5862b10 | 2020-03-19 14:45:36 +0100 | [diff] [blame] | 86 | *request.mutable_proxy_resolution_request() = proxy_request; |
| 87 | if (!WriteProtobuf(GetStdoutPipe(), request)) { |
| 88 | LOG(ERROR) << "Failed to send proxy resolution request for url: " |
| 89 | << target_url; |
| 90 | std::move(callback).Run({brillo::http::kDirectProxy}); |
| 91 | return; |
| 92 | } |
| 93 | pending_proxy_resolution_requests_[target_url].push_back(std::move(callback)); |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 94 | } |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 95 | |
Andreea Costinas | bb2aa02 | 2020-06-13 00:03:23 +0200 | [diff] [blame^] | 96 | void ServerProxy::AuthenticationRequired(const std::string& proxy_url, |
| 97 | const std::string& scheme, |
| 98 | const std::string& realm, |
| 99 | OnAuthAcquiredCallback callback) { |
| 100 | // TODO(acostinas): Request the credentials from the main process. |
| 101 | std::move(callback).Run(std::string()); |
| 102 | } |
| 103 | |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 104 | void ServerProxy::HandleStdinReadable() { |
Andreea Costinas | aae9738 | 2020-05-05 13:31:58 +0200 | [diff] [blame] | 105 | worker::WorkerConfigs config; |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 106 | if (!ReadProtobuf(GetStdinPipe(), &config)) { |
| 107 | LOG(ERROR) << "Error decoding protobuf configurations." << std::endl; |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 108 | return; |
| 109 | } |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 110 | |
| 111 | if (config.has_credentials()) { |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 112 | const std::string username = UrlEncode(config.credentials().username()); |
| 113 | const std::string password = UrlEncode(config.credentials().password()); |
Andreea Costinas | bb2aa02 | 2020-06-13 00:03:23 +0200 | [diff] [blame^] | 114 | system_credentials_ = base::JoinString({username.c_str(), password.c_str()}, |
| 115 | kCredentialsColonSeparator); |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 116 | } |
| 117 | |
| 118 | if (config.has_listening_address()) { |
| 119 | if (listening_addr_ != 0) { |
| 120 | LOG(ERROR) |
| 121 | << "Failure to set configurations: listening port was already set." |
| 122 | << std::endl; |
| 123 | return; |
| 124 | } |
| 125 | listening_addr_ = config.listening_address().addr(); |
| 126 | listening_port_ = config.listening_address().port(); |
| 127 | CreateListeningSocket(); |
| 128 | } |
Andreea Costinas | 5862b10 | 2020-03-19 14:45:36 +0100 | [diff] [blame] | 129 | |
| 130 | if (config.has_proxy_resolution_reply()) { |
| 131 | std::list<std::string> proxies; |
Andreea Costinas | aae9738 | 2020-05-05 13:31:58 +0200 | [diff] [blame] | 132 | const worker::ProxyResolutionReply& reply = config.proxy_resolution_reply(); |
Andreea Costinas | 5862b10 | 2020-03-19 14:45:36 +0100 | [diff] [blame] | 133 | for (auto const& proxy : reply.proxy_servers()) |
| 134 | proxies.push_back(proxy); |
| 135 | |
| 136 | OnProxyResolved(reply.target_url(), proxies); |
| 137 | } |
Andreea Costinas | 922fbaf | 2020-05-28 11:55:22 +0200 | [diff] [blame] | 138 | |
| 139 | if (config.has_kerberos_config()) { |
| 140 | if (config.kerberos_config().enabled()) { |
| 141 | // Set the environment variables that allow libcurl to use the existing |
| 142 | // kerberos ticket for proxy authentication. The files to which the env |
| 143 | // variables point to are maintained by the parent process. |
| 144 | setenv(kKrb5ConfEnvKey, config.kerberos_config().krb5conf_path().c_str(), |
| 145 | /* overwrite = */ 1); |
| 146 | setenv(kKrb5CCEnvKey, config.kerberos_config().krb5cc_path().c_str(), |
| 147 | /* overwrite = */ 1); |
| 148 | } else { |
| 149 | unsetenv(kKrb5ConfEnvKey); |
| 150 | unsetenv(kKrb5CCEnvKey); |
| 151 | } |
| 152 | } |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 153 | } |
| 154 | |
| 155 | bool ServerProxy::HandleSignal(const struct signalfd_siginfo& siginfo) { |
| 156 | base::ThreadTaskRunnerHandle::Get()->PostTask(FROM_HERE, |
| 157 | std::move(quit_closure_)); |
| 158 | return true; |
| 159 | } |
| 160 | |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 161 | int ServerProxy::GetStdinPipe() { |
| 162 | return STDIN_FILENO; |
| 163 | } |
| 164 | |
Andreea Costinas | 5862b10 | 2020-03-19 14:45:36 +0100 | [diff] [blame] | 165 | int ServerProxy::GetStdoutPipe() { |
| 166 | return STDOUT_FILENO; |
| 167 | } |
| 168 | |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 169 | void ServerProxy::CreateListeningSocket() { |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 170 | listening_fd_ = std::make_unique<patchpanel::Socket>( |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 171 | AF_INET, SOCK_STREAM | SOCK_NONBLOCK); |
| 172 | |
| 173 | struct sockaddr_in addr = {0}; |
| 174 | addr.sin_family = AF_INET; |
| 175 | addr.sin_port = htons(listening_port_); |
| 176 | addr.sin_addr.s_addr = listening_addr_; |
| 177 | if (!listening_fd_->Bind((const struct sockaddr*)&addr, sizeof(addr))) { |
| 178 | LOG(ERROR) << "Cannot bind source socket" << std::endl; |
| 179 | return; |
| 180 | } |
| 181 | |
| 182 | if (!listening_fd_->Listen(kMaxConn)) { |
| 183 | LOG(ERROR) << "Cannot listen on source socket." << std::endl; |
| 184 | return; |
| 185 | } |
| 186 | |
| 187 | fd_watcher_ = base::FileDescriptorWatcher::WatchReadable( |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 188 | listening_fd_->fd(), base::BindRepeating(&ServerProxy::OnConnectionAccept, |
| 189 | weak_ptr_factory_.GetWeakPtr())); |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 190 | } |
| 191 | |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 192 | void ServerProxy::OnConnectionAccept() { |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 193 | struct sockaddr_storage client_src = {}; |
| 194 | socklen_t sockaddr_len = sizeof(client_src); |
| 195 | if (auto client_conn = |
| 196 | listening_fd_->Accept((struct sockaddr*)&client_src, &sockaddr_len)) { |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 197 | auto connect_job = std::make_unique<ProxyConnectJob>( |
Andreea Costinas | bb2aa02 | 2020-06-13 00:03:23 +0200 | [diff] [blame^] | 198 | std::move(client_conn), system_credentials_, |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 199 | base::BindOnce(&ServerProxy::ResolveProxy, base::Unretained(this)), |
Andreea Costinas | bb2aa02 | 2020-06-13 00:03:23 +0200 | [diff] [blame^] | 200 | base::BindOnce(&ServerProxy::AuthenticationRequired, |
| 201 | base::Unretained(this)), |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 202 | base::BindOnce(&ServerProxy::OnConnectionSetupFinished, |
| 203 | base::Unretained(this))); |
| 204 | if (connect_job->Start()) |
| 205 | pending_connect_jobs_[connect_job.get()] = std::move(connect_job); |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 206 | } |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 207 | // Cleanup any defunct forwarders. |
| 208 | // TODO(acostinas, chromium:1064536) Monitor the client and server sockets |
| 209 | // and remove the corresponding SocketForwarder when a socket closes. |
| 210 | for (auto it = forwarders_.begin(); it != forwarders_.end(); ++it) { |
| 211 | if (!(*it)->IsRunning() && (*it)->HasBeenStarted()) |
| 212 | it = forwarders_.erase(it); |
| 213 | } |
| 214 | } |
| 215 | |
Andreea Costinas | 5862b10 | 2020-03-19 14:45:36 +0100 | [diff] [blame] | 216 | void ServerProxy::OnProxyResolved(const std::string& target_url, |
| 217 | const std::list<std::string>& proxy_servers) { |
| 218 | auto callbacks = std::move(pending_proxy_resolution_requests_[target_url]); |
| 219 | pending_proxy_resolution_requests_.erase(target_url); |
| 220 | |
| 221 | for (auto& callback : callbacks) |
| 222 | std::move(callback).Run(proxy_servers); |
| 223 | } |
| 224 | |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 225 | void ServerProxy::OnConnectionSetupFinished( |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 226 | std::unique_ptr<patchpanel::SocketForwarder> fwd, |
Andreea Costinas | e45d54b | 2020-03-10 09:21:14 +0100 | [diff] [blame] | 227 | ProxyConnectJob* connect_job) { |
| 228 | if (fwd) { |
| 229 | // The connection was set up successfully. |
| 230 | forwarders_.emplace_back(std::move(fwd)); |
| 231 | } |
| 232 | pending_connect_jobs_.erase(connect_job); |
Andreea Costinas | 44cefa2 | 2020-03-09 09:07:39 +0100 | [diff] [blame] | 233 | } |
| 234 | |
Andreea Costinas | 41e0644 | 2020-03-09 09:41:51 +0100 | [diff] [blame] | 235 | } // namespace system_proxy |