blob: 7308cd529a059aadfb481ac2739332b9389bafd2 [file] [log] [blame]
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +00001/*
2 * Copyright 2012 The WebRTC Project Authors. All rights reserved.
3 *
4 * Use of this source code is governed by a BSD-style license
5 * that can be found in the LICENSE file in the root of the source
6 * tree. An additional intellectual property rights grant can be found
7 * in the file PATENTS. All contributing project authors may
8 * be found in the AUTHORS file in the root of the source tree.
9 */
10
Steve Anton10542f22019-01-11 09:11:00 -080011#ifndef P2P_BASE_TURN_SERVER_H_
12#define P2P_BASE_TURN_SERVER_H_
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000013
14#include <list>
15#include <map>
kwiberg3ec46792016-04-27 07:22:53 -070016#include <memory>
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000017#include <set>
18#include <string>
Steve Anton6c38cc72017-11-29 10:25:58 -080019#include <utility>
deadbeef824f5862016-08-24 15:06:53 -070020#include <vector>
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000021
Steve Anton10542f22019-01-11 09:11:00 -080022#include "p2p/base/port_interface.h"
23#include "rtc_base/async_invoker.h"
24#include "rtc_base/async_packet_socket.h"
25#include "rtc_base/message_queue.h"
26#include "rtc_base/socket_address.h"
Artem Titove41c4332018-07-25 15:04:28 +020027#include "rtc_base/third_party/sigslot/sigslot.h"
Seth Hampsonaed71642018-06-11 07:41:32 -070028#include "rtc_base/thread_checker.h"
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000029
30namespace rtc {
jbauchf1f87202016-03-30 06:43:37 -070031class ByteBufferWriter;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000032class PacketSocketFactory;
33class Thread;
Jonas Olssona4d87372019-07-05 19:08:33 +020034} // namespace rtc
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000035
36namespace cricket {
37
38class StunMessage;
39class TurnMessage;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +000040class TurnServer;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000041
42// The default server port for TURN, as specified in RFC5766.
43const int TURN_SERVER_PORT = 3478;
44
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +000045// Encapsulates the client's connection to the server.
46class TurnServerConnection {
47 public:
48 TurnServerConnection() : proto_(PROTO_UDP), socket_(NULL) {}
49 TurnServerConnection(const rtc::SocketAddress& src,
50 ProtocolType proto,
51 rtc::AsyncPacketSocket* socket);
52 const rtc::SocketAddress& src() const { return src_; }
53 rtc::AsyncPacketSocket* socket() { return socket_; }
54 bool operator==(const TurnServerConnection& t) const;
55 bool operator<(const TurnServerConnection& t) const;
56 std::string ToString() const;
57
58 private:
59 rtc::SocketAddress src_;
60 rtc::SocketAddress dst_;
61 cricket::ProtocolType proto_;
62 rtc::AsyncPacketSocket* socket_;
63};
64
65// Encapsulates a TURN allocation.
66// The object is created when an allocation request is received, and then
67// handles TURN messages (via HandleTurnMessage) and channel data messages
68// (via HandleChannelData) for this allocation when received by the server.
69// The object self-deletes and informs the server if its lifetime timer expires.
70class TurnServerAllocation : public rtc::MessageHandler,
71 public sigslot::has_slots<> {
72 public:
73 TurnServerAllocation(TurnServer* server_,
74 rtc::Thread* thread,
75 const TurnServerConnection& conn,
76 rtc::AsyncPacketSocket* server_socket,
77 const std::string& key);
Steve Antonf2737d22017-10-31 16:27:34 -070078 ~TurnServerAllocation() override;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +000079
80 TurnServerConnection* conn() { return &conn_; }
81 const std::string& key() const { return key_; }
82 const std::string& transaction_id() const { return transaction_id_; }
83 const std::string& username() const { return username_; }
84 const std::string& origin() const { return origin_; }
85 const std::string& last_nonce() const { return last_nonce_; }
86 void set_last_nonce(const std::string& nonce) { last_nonce_ = nonce; }
87
88 std::string ToString() const;
89
90 void HandleTurnMessage(const TurnMessage* msg);
91 void HandleChannelData(const char* data, size_t size);
92
93 sigslot::signal1<TurnServerAllocation*> SignalDestroyed;
94
95 private:
96 class Channel;
97 class Permission;
98 typedef std::list<Permission*> PermissionList;
99 typedef std::list<Channel*> ChannelList;
100
101 void HandleAllocateRequest(const TurnMessage* msg);
102 void HandleRefreshRequest(const TurnMessage* msg);
103 void HandleSendIndication(const TurnMessage* msg);
104 void HandleCreatePermissionRequest(const TurnMessage* msg);
105 void HandleChannelBindRequest(const TurnMessage* msg);
106
107 void OnExternalPacket(rtc::AsyncPacketSocket* socket,
Niels Möllere6933812018-11-05 13:01:41 +0100108 const char* data,
109 size_t size,
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000110 const rtc::SocketAddress& addr,
Niels Möllere6933812018-11-05 13:01:41 +0100111 const int64_t& packet_time_us);
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000112
113 static int ComputeLifetime(const TurnMessage* msg);
114 bool HasPermission(const rtc::IPAddress& addr);
115 void AddPermission(const rtc::IPAddress& addr);
116 Permission* FindPermission(const rtc::IPAddress& addr) const;
117 Channel* FindChannel(int channel_id) const;
118 Channel* FindChannel(const rtc::SocketAddress& addr) const;
119
120 void SendResponse(TurnMessage* msg);
121 void SendBadRequestResponse(const TurnMessage* req);
Jonas Olssona4d87372019-07-05 19:08:33 +0200122 void SendErrorResponse(const TurnMessage* req,
123 int code,
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000124 const std::string& reason);
Jonas Olssona4d87372019-07-05 19:08:33 +0200125 void SendExternal(const void* data,
126 size_t size,
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000127 const rtc::SocketAddress& peer);
128
129 void OnPermissionDestroyed(Permission* perm);
130 void OnChannelDestroyed(Channel* channel);
Steve Antonf2737d22017-10-31 16:27:34 -0700131 void OnMessage(rtc::Message* msg) override;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000132
133 TurnServer* server_;
134 rtc::Thread* thread_;
135 TurnServerConnection conn_;
kwiberg3ec46792016-04-27 07:22:53 -0700136 std::unique_ptr<rtc::AsyncPacketSocket> external_socket_;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000137 std::string key_;
138 std::string transaction_id_;
139 std::string username_;
140 std::string origin_;
141 std::string last_nonce_;
142 PermissionList perms_;
143 ChannelList channels_;
144};
145
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000146// An interface through which the MD5 credential hash can be retrieved.
147class TurnAuthInterface {
148 public:
149 // Gets HA1 for the specified user and realm.
150 // HA1 = MD5(A1) = MD5(username:realm:password).
151 // Return true if the given username and realm are valid, or false if not.
Jonas Olssona4d87372019-07-05 19:08:33 +0200152 virtual bool GetKey(const std::string& username,
153 const std::string& realm,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000154 std::string* key) = 0;
Henrik Kjellander3fe372d2016-05-12 08:10:52 +0200155 virtual ~TurnAuthInterface() = default;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000156};
157
158// An interface enables Turn Server to control redirection behavior.
159class TurnRedirectInterface {
160 public:
161 virtual bool ShouldRedirect(const rtc::SocketAddress& address,
162 rtc::SocketAddress* out) = 0;
163 virtual ~TurnRedirectInterface() {}
164};
165
Jonas Orelandbdcee282017-10-10 14:01:40 +0200166class StunMessageObserver {
167 public:
168 virtual void ReceivedMessage(const TurnMessage* msg) = 0;
169 virtual void ReceivedChannelData(const char* data, size_t size) = 0;
170 virtual ~StunMessageObserver() {}
171};
172
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000173// The core TURN server class. Give it a socket to listen on via
174// AddInternalServerSocket, and a factory to create external sockets via
175// SetExternalSocketFactory, and it's ready to go.
176// Not yet wired up: TCP support.
177class TurnServer : public sigslot::has_slots<> {
178 public:
deadbeef97943662016-07-12 11:04:50 -0700179 typedef std::map<TurnServerConnection, std::unique_ptr<TurnServerAllocation>>
180 AllocationMap;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000181
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000182 explicit TurnServer(rtc::Thread* thread);
Steve Antonf2737d22017-10-31 16:27:34 -0700183 ~TurnServer() override;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000184
185 // Gets/sets the realm value to use for the server.
Seth Hampsonaed71642018-06-11 07:41:32 -0700186 const std::string& realm() const {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200187 RTC_DCHECK(thread_checker_.IsCurrent());
Seth Hampsonaed71642018-06-11 07:41:32 -0700188 return realm_;
189 }
190 void set_realm(const std::string& realm) {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200191 RTC_DCHECK(thread_checker_.IsCurrent());
Seth Hampsonaed71642018-06-11 07:41:32 -0700192 realm_ = realm;
193 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000194
195 // Gets/sets the value for the SOFTWARE attribute for TURN messages.
Seth Hampsonaed71642018-06-11 07:41:32 -0700196 const std::string& software() const {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200197 RTC_DCHECK(thread_checker_.IsCurrent());
Seth Hampsonaed71642018-06-11 07:41:32 -0700198 return software_;
199 }
200 void set_software(const std::string& software) {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200201 RTC_DCHECK(thread_checker_.IsCurrent());
Seth Hampsonaed71642018-06-11 07:41:32 -0700202 software_ = software;
203 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000204
Seth Hampsonaed71642018-06-11 07:41:32 -0700205 const AllocationMap& allocations() const {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200206 RTC_DCHECK(thread_checker_.IsCurrent());
Seth Hampsonaed71642018-06-11 07:41:32 -0700207 return allocations_;
208 }
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000209
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000210 // Sets the authentication callback; does not take ownership.
Seth Hampsonaed71642018-06-11 07:41:32 -0700211 void set_auth_hook(TurnAuthInterface* auth_hook) {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200212 RTC_DCHECK(thread_checker_.IsCurrent());
Seth Hampsonaed71642018-06-11 07:41:32 -0700213 auth_hook_ = auth_hook;
214 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000215
216 void set_redirect_hook(TurnRedirectInterface* redirect_hook) {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200217 RTC_DCHECK(thread_checker_.IsCurrent());
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000218 redirect_hook_ = redirect_hook;
219 }
220
Seth Hampsonaed71642018-06-11 07:41:32 -0700221 void set_enable_otu_nonce(bool enable) {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200222 RTC_DCHECK(thread_checker_.IsCurrent());
Seth Hampsonaed71642018-06-11 07:41:32 -0700223 enable_otu_nonce_ = enable;
224 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000225
deadbeef376e1232015-11-25 09:00:08 -0800226 // If set to true, reject CreatePermission requests to RFC1918 addresses.
227 void set_reject_private_addresses(bool filter) {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200228 RTC_DCHECK(thread_checker_.IsCurrent());
deadbeef376e1232015-11-25 09:00:08 -0800229 reject_private_addresses_ = filter;
230 }
231
Taylor Brandstetteref184702016-06-23 17:35:47 -0700232 void set_enable_permission_checks(bool enable) {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200233 RTC_DCHECK(thread_checker_.IsCurrent());
Taylor Brandstetteref184702016-06-23 17:35:47 -0700234 enable_permission_checks_ = enable;
235 }
236
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000237 // Starts listening for packets from internal clients.
Jonas Olssona4d87372019-07-05 19:08:33 +0200238 void AddInternalSocket(rtc::AsyncPacketSocket* socket, ProtocolType proto);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000239 // Starts listening for the connections on this socket. When someone tries
240 // to connect, the connection will be accepted and a new internal socket
241 // will be added.
Jonas Olssona4d87372019-07-05 19:08:33 +0200242 void AddInternalServerSocket(rtc::AsyncSocket* socket, ProtocolType proto);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000243 // Specifies the factory to use for creating external sockets.
244 void SetExternalSocketFactory(rtc::PacketSocketFactory* factory,
245 const rtc::SocketAddress& address);
honghaizc463e202016-02-01 15:19:08 -0800246 // For testing only.
honghaiz34b11eb2016-03-16 08:55:44 -0700247 std::string SetTimestampForNextNonce(int64_t timestamp) {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200248 RTC_DCHECK(thread_checker_.IsCurrent());
honghaizc463e202016-02-01 15:19:08 -0800249 ts_for_next_nonce_ = timestamp;
250 return GenerateNonce(timestamp);
251 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000252
Jonas Olssona4d87372019-07-05 19:08:33 +0200253 void SetStunMessageObserver(std::unique_ptr<StunMessageObserver> observer) {
Sebastian Janssonc01367d2019-04-08 15:20:44 +0200254 RTC_DCHECK(thread_checker_.IsCurrent());
Jonas Orelandbdcee282017-10-10 14:01:40 +0200255 stun_message_observer_ = std::move(observer);
256 }
257
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000258 private:
honghaiz34b11eb2016-03-16 08:55:44 -0700259 std::string GenerateNonce(int64_t now) const;
Niels Möllere6933812018-11-05 13:01:41 +0100260 void OnInternalPacket(rtc::AsyncPacketSocket* socket,
261 const char* data,
262 size_t size,
263 const rtc::SocketAddress& address,
264 const int64_t& packet_time_us);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000265
266 void OnNewInternalConnection(rtc::AsyncSocket* socket);
267
268 // Accept connections on this server socket.
269 void AcceptConnection(rtc::AsyncSocket* server_socket);
270 void OnInternalSocketClose(rtc::AsyncPacketSocket* socket, int err);
271
Jonas Olssona4d87372019-07-05 19:08:33 +0200272 void HandleStunMessage(TurnServerConnection* conn,
273 const char* data,
274 size_t size);
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000275 void HandleBindingRequest(TurnServerConnection* conn, const StunMessage* msg);
Jonas Olssona4d87372019-07-05 19:08:33 +0200276 void HandleAllocateRequest(TurnServerConnection* conn,
277 const TurnMessage* msg,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000278 const std::string& key);
279
280 bool GetKey(const StunMessage* msg, std::string* key);
Jonas Olssona4d87372019-07-05 19:08:33 +0200281 bool CheckAuthorization(TurnServerConnection* conn,
282 const StunMessage* msg,
283 const char* data,
284 size_t size,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000285 const std::string& key);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000286 bool ValidateNonce(const std::string& nonce) const;
287
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000288 TurnServerAllocation* FindAllocation(TurnServerConnection* conn);
Jonas Olssona4d87372019-07-05 19:08:33 +0200289 TurnServerAllocation* CreateAllocation(TurnServerConnection* conn,
290 int proto,
291 const std::string& key);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000292
Jonas Olssona4d87372019-07-05 19:08:33 +0200293 void SendErrorResponse(TurnServerConnection* conn,
294 const StunMessage* req,
295 int code,
296 const std::string& reason);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000297
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000298 void SendErrorResponseWithRealmAndNonce(TurnServerConnection* conn,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000299 const StunMessage* req,
300 int code,
301 const std::string& reason);
302
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000303 void SendErrorResponseWithAlternateServer(TurnServerConnection* conn,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000304 const StunMessage* req,
305 const rtc::SocketAddress& addr);
306
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000307 void SendStun(TurnServerConnection* conn, StunMessage* msg);
jbauchf1f87202016-03-30 06:43:37 -0700308 void Send(TurnServerConnection* conn, const rtc::ByteBufferWriter& buf);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000309
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000310 void OnAllocationDestroyed(TurnServerAllocation* allocation);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000311 void DestroyInternalSocket(rtc::AsyncPacketSocket* socket);
312
deadbeef824f5862016-08-24 15:06:53 -0700313 // Just clears |sockets_to_delete_|; called asynchronously.
314 void FreeSockets();
315
Jonas Olssona4d87372019-07-05 19:08:33 +0200316 typedef std::map<rtc::AsyncPacketSocket*, ProtocolType> InternalSocketMap;
317 typedef std::map<rtc::AsyncSocket*, ProtocolType> ServerSocketMap;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000318
319 rtc::Thread* thread_;
Seth Hampsonaed71642018-06-11 07:41:32 -0700320 rtc::ThreadChecker thread_checker_;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000321 std::string nonce_key_;
322 std::string realm_;
323 std::string software_;
324 TurnAuthInterface* auth_hook_;
325 TurnRedirectInterface* redirect_hook_;
326 // otu - one-time-use. Server will respond with 438 if it's
327 // sees the same nonce in next transaction.
328 bool enable_otu_nonce_;
deadbeef376e1232015-11-25 09:00:08 -0800329 bool reject_private_addresses_ = false;
Taylor Brandstetteref184702016-06-23 17:35:47 -0700330 // Check for permission when receiving an external packet.
331 bool enable_permission_checks_ = true;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000332
333 InternalSocketMap server_sockets_;
334 ServerSocketMap server_listen_sockets_;
deadbeef824f5862016-08-24 15:06:53 -0700335 // Used when we need to delete a socket asynchronously.
336 std::vector<std::unique_ptr<rtc::AsyncPacketSocket>> sockets_to_delete_;
kwiberg3ec46792016-04-27 07:22:53 -0700337 std::unique_ptr<rtc::PacketSocketFactory> external_socket_factory_;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000338 rtc::SocketAddress external_addr_;
339
340 AllocationMap allocations_;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000341
deadbeef824f5862016-08-24 15:06:53 -0700342 rtc::AsyncInvoker invoker_;
343
honghaizc463e202016-02-01 15:19:08 -0800344 // For testing only. If this is non-zero, the next NONCE will be generated
345 // from this value, and it will be reset to 0 after generating the NONCE.
honghaiz34b11eb2016-03-16 08:55:44 -0700346 int64_t ts_for_next_nonce_ = 0;
honghaizc463e202016-02-01 15:19:08 -0800347
Jonas Orelandbdcee282017-10-10 14:01:40 +0200348 // For testing only. Used to observe STUN messages received.
349 std::unique_ptr<StunMessageObserver> stun_message_observer_;
350
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000351 friend class TurnServerAllocation;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000352};
353
354} // namespace cricket
355
Steve Anton10542f22019-01-11 09:11:00 -0800356#endif // P2P_BASE_TURN_SERVER_H_