blob: 8052cd809a557643ee685eb438be110a8bdd2bff [file] [log] [blame]
deadbeef1dcb1642017-03-29 21:08:16 -07001/*
2 * Copyright 2017 The WebRTC project authors. All Rights Reserved.
3 *
4 * Use of this source code is governed by a BSD-style license
5 * that can be found in the LICENSE file in the root of the source
6 * tree. An additional intellectual property rights grant can be found
7 * in the file PATENTS. All contributing project authors may
8 * be found in the AUTHORS file in the root of the source tree.
9 */
10
Steve Anton10542f22019-01-11 09:11:00 -080011#include "pc/ice_server_parsing.h"
deadbeef1dcb1642017-03-29 21:08:16 -070012
Yves Gerey3e707812018-11-28 16:47:49 +010013#include <stddef.h>
Jonas Olssona4d87372019-07-05 19:08:33 +020014
deadbeef1dcb1642017-03-29 21:08:16 -070015#include <cctype> // For std::isdigit.
16#include <string>
Niels Möller6d122622022-06-03 13:51:21 +020017#include <tuple>
deadbeef1dcb1642017-03-29 21:08:16 -070018
Steve Anton10542f22019-01-11 09:11:00 -080019#include "p2p/base/port_interface.h"
Mirko Bonadei92ea95e2017-09-15 06:47:31 +020020#include "rtc_base/arraysize.h"
Yves Gerey3e707812018-11-28 16:47:49 +010021#include "rtc_base/checks.h"
Steve Anton10542f22019-01-11 09:11:00 -080022#include "rtc_base/ip_address.h"
Yves Gerey3e707812018-11-28 16:47:49 +010023#include "rtc_base/logging.h"
Steve Anton10542f22019-01-11 09:11:00 -080024#include "rtc_base/socket_address.h"
Harald Alvestrand5761e7b2021-01-29 14:45:08 +000025#include "rtc_base/string_encode.h"
Niels Möller6d122622022-06-03 13:51:21 +020026#include "rtc_base/string_to_number.h"
deadbeef1dcb1642017-03-29 21:08:16 -070027
28namespace webrtc {
29
Niels Möller6d122622022-06-03 13:51:21 +020030namespace {
deadbeef1dcb1642017-03-29 21:08:16 -070031// Number of tokens must be preset when TURN uri has transport param.
Niels Möller6d122622022-06-03 13:51:21 +020032const size_t kTurnTransportTokensNum = 2;
deadbeef1dcb1642017-03-29 21:08:16 -070033// The default stun port.
Niels Möller6d122622022-06-03 13:51:21 +020034const int kDefaultStunPort = 3478;
35const int kDefaultStunTlsPort = 5349;
36const char kTransport[] = "transport";
deadbeef1dcb1642017-03-29 21:08:16 -070037
Harald Alvestranda3dd7722020-11-27 08:05:42 +000038// Allowed characters in hostname per RFC 3986 Appendix A "reg-name"
Niels Möller6d122622022-06-03 13:51:21 +020039const char kRegNameCharacters[] =
Harald Alvestranda3dd7722020-11-27 08:05:42 +000040 "abcdefghijklmnopqrstuvwxyz"
41 "ABCDEFGHIJKLMNOPQRSTUVWXYZ"
42 "0123456789"
43 "-._~" // unreserved
44 "%" // pct-encoded
45 "!$&'()*+,;="; // sub-delims
46
deadbeef1dcb1642017-03-29 21:08:16 -070047// NOTE: Must be in the same order as the ServiceType enum.
Niels Möller6d122622022-06-03 13:51:21 +020048const char* kValidIceServiceTypes[] = {"stun", "stuns", "turn", "turns"};
deadbeef1dcb1642017-03-29 21:08:16 -070049
50// NOTE: A loop below assumes that the first value of this enum is 0 and all
51// other values are incremental.
Niels Möller6d122622022-06-03 13:51:21 +020052enum class ServiceType {
deadbeef1dcb1642017-03-29 21:08:16 -070053 STUN = 0, // Indicates a STUN server.
54 STUNS, // Indicates a STUN server used with a TLS session.
55 TURN, // Indicates a TURN server
56 TURNS, // Indicates a TURN server used with a TLS session.
57 INVALID, // Unknown.
58};
Niels Möller6d122622022-06-03 13:51:21 +020059static_assert(static_cast<size_t>(ServiceType::INVALID) ==
60 arraysize(kValidIceServiceTypes),
deadbeef1dcb1642017-03-29 21:08:16 -070061 "kValidIceServiceTypes must have as many strings as ServiceType "
62 "has values.");
63
Artem Titov880fa812021-07-30 22:30:23 +020064// `in_str` should follow of RFC 7064/7065 syntax, but with an optional
Niels Möllerdb4def92019-03-18 16:53:59 +010065// "?transport=" already stripped. I.e.,
66// stunURI = scheme ":" host [ ":" port ]
67// scheme = "stun" / "stuns" / "turn" / "turns"
68// host = IP-literal / IPv4address / reg-name
69// port = *DIGIT
Niels Möller6d122622022-06-03 13:51:21 +020070
71// Return tuple is service_type, host, with service_type == ServiceType::INVALID
72// on failure.
73std::tuple<ServiceType, absl::string_view> GetServiceTypeAndHostnameFromUri(
74 absl::string_view in_str) {
75 const auto colonpos = in_str.find(':');
76 if (colonpos == absl::string_view::npos) {
Mirko Bonadei675513b2017-11-09 11:09:25 +010077 RTC_LOG(LS_WARNING) << "Missing ':' in ICE URI: " << in_str;
Niels Möller6d122622022-06-03 13:51:21 +020078 return {ServiceType::INVALID, ""};
deadbeef1dcb1642017-03-29 21:08:16 -070079 }
80 if ((colonpos + 1) == in_str.length()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +010081 RTC_LOG(LS_WARNING) << "Empty hostname in ICE URI: " << in_str;
Niels Möller6d122622022-06-03 13:51:21 +020082 return {ServiceType::INVALID, ""};
deadbeef1dcb1642017-03-29 21:08:16 -070083 }
deadbeef1dcb1642017-03-29 21:08:16 -070084 for (size_t i = 0; i < arraysize(kValidIceServiceTypes); ++i) {
85 if (in_str.compare(0, colonpos, kValidIceServiceTypes[i]) == 0) {
Niels Möller6d122622022-06-03 13:51:21 +020086 return {static_cast<ServiceType>(i), in_str.substr(colonpos + 1)};
deadbeef1dcb1642017-03-29 21:08:16 -070087 }
88 }
Niels Möller6d122622022-06-03 13:51:21 +020089 return {ServiceType::INVALID, ""};
deadbeef1dcb1642017-03-29 21:08:16 -070090}
91
Niels Möller6d122622022-06-03 13:51:21 +020092absl::optional<int> ParsePort(absl::string_view in_str) {
93 // Make sure port only contains digits. StringToNumber doesn't check this.
deadbeef1dcb1642017-03-29 21:08:16 -070094 for (const char& c : in_str) {
Niels Möllere66b83f2022-05-30 12:57:41 +020095 if (!std::isdigit(static_cast<unsigned char>(c))) {
deadbeef1dcb1642017-03-29 21:08:16 -070096 return false;
97 }
98 }
Niels Möller6d122622022-06-03 13:51:21 +020099 return rtc::StringToNumber<int>(in_str);
deadbeef1dcb1642017-03-29 21:08:16 -0700100}
101
102// This method parses IPv6 and IPv4 literal strings, along with hostnames in
103// standard hostname:port format.
104// Consider following formats as correct.
Artem Titovcfea2182021-08-10 01:22:31 +0200105// `hostname:port`, |[IPV6 address]:port|, |IPv4 address|:port,
Artem Titov880fa812021-07-30 22:30:23 +0200106// `hostname`, |[IPv6 address]|, |IPv4 address|.
Niels Möller6d122622022-06-03 13:51:21 +0200107
108// Return tuple is success, host, port.
109std::tuple<bool, absl::string_view, int> ParseHostnameAndPortFromString(
110 absl::string_view in_str,
111 int default_port) {
112 if (in_str.empty()) {
113 return {false, "", 0};
114 }
115 absl::string_view host;
116 int port = default_port;
117
deadbeef1dcb1642017-03-29 21:08:16 -0700118 if (in_str.at(0) == '[') {
Harald Alvestranda3dd7722020-11-27 08:05:42 +0000119 // IP_literal syntax
Niels Möller6d122622022-06-03 13:51:21 +0200120 auto closebracket = in_str.rfind(']');
121 if (closebracket == absl::string_view::npos) {
122 return {false, "", 0};
deadbeef1dcb1642017-03-29 21:08:16 -0700123 }
Niels Möller6d122622022-06-03 13:51:21 +0200124 auto colonpos = in_str.find(':', closebracket);
125 if (absl::string_view::npos != colonpos) {
126 if (absl::optional<int> opt_port =
127 ParsePort(in_str.substr(closebracket + 2))) {
128 port = *opt_port;
129 } else {
130 return {false, "", 0};
131 }
132 }
133 host = in_str.substr(1, closebracket - 1);
deadbeef1dcb1642017-03-29 21:08:16 -0700134 } else {
Harald Alvestranda3dd7722020-11-27 08:05:42 +0000135 // IPv4address or reg-name syntax
Niels Möller6d122622022-06-03 13:51:21 +0200136 auto colonpos = in_str.find(':');
137 if (absl::string_view::npos != colonpos) {
138 if (absl::optional<int> opt_port =
139 ParsePort(in_str.substr(colonpos + 1))) {
140 port = *opt_port;
141 } else {
142 return {false, "", 0};
deadbeef1dcb1642017-03-29 21:08:16 -0700143 }
Niels Möller6d122622022-06-03 13:51:21 +0200144 host = in_str.substr(0, colonpos);
deadbeef1dcb1642017-03-29 21:08:16 -0700145 } else {
Niels Möller6d122622022-06-03 13:51:21 +0200146 host = in_str;
deadbeef1dcb1642017-03-29 21:08:16 -0700147 }
Harald Alvestranda3dd7722020-11-27 08:05:42 +0000148 // RFC 3986 section 3.2.2 and Appendix A - "reg-name" syntax
Niels Möller6d122622022-06-03 13:51:21 +0200149 if (host.find_first_not_of(kRegNameCharacters) != absl::string_view::npos) {
150 return {false, "", 0};
Harald Alvestranda3dd7722020-11-27 08:05:42 +0000151 }
deadbeef1dcb1642017-03-29 21:08:16 -0700152 }
Niels Möller6d122622022-06-03 13:51:21 +0200153 return {!host.empty(), host, port};
deadbeef1dcb1642017-03-29 21:08:16 -0700154}
155
156// Adds a STUN or TURN server to the appropriate list,
Artem Titov880fa812021-07-30 22:30:23 +0200157// by parsing `url` and using the username/password in `server`.
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000158RTCErrorType ParseIceServerUrl(
deadbeef1dcb1642017-03-29 21:08:16 -0700159 const PeerConnectionInterface::IceServer& server,
Niels Möller6d122622022-06-03 13:51:21 +0200160 absl::string_view url,
deadbeef1dcb1642017-03-29 21:08:16 -0700161 cricket::ServerAddresses* stun_servers,
162 std::vector<cricket::RelayServerConfig>* turn_servers) {
Niels Möllerdb4def92019-03-18 16:53:59 +0100163 // RFC 7064
164 // stunURI = scheme ":" host [ ":" port ]
deadbeef1dcb1642017-03-29 21:08:16 -0700165 // scheme = "stun" / "stuns"
deadbeef1dcb1642017-03-29 21:08:16 -0700166
Niels Möllerdb4def92019-03-18 16:53:59 +0100167 // RFC 7065
168 // turnURI = scheme ":" host [ ":" port ]
deadbeef1dcb1642017-03-29 21:08:16 -0700169 // [ "?transport=" transport ]
170 // scheme = "turn" / "turns"
171 // transport = "udp" / "tcp" / transport-ext
172 // transport-ext = 1*unreserved
Niels Möllerdb4def92019-03-18 16:53:59 +0100173
174 // RFC 3986
175 // host = IP-literal / IPv4address / reg-name
176 // port = *DIGIT
177
deadbeef1dcb1642017-03-29 21:08:16 -0700178 RTC_DCHECK(stun_servers != nullptr);
179 RTC_DCHECK(turn_servers != nullptr);
deadbeef1dcb1642017-03-29 21:08:16 -0700180 cricket::ProtocolType turn_transport_type = cricket::PROTO_UDP;
181 RTC_DCHECK(!url.empty());
Niels Möller6d122622022-06-03 13:51:21 +0200182 std::vector<absl::string_view> tokens = rtc::split(url, '?');
183 absl::string_view uri_without_transport = tokens[0];
deadbeef1dcb1642017-03-29 21:08:16 -0700184 // Let's look into transport= param, if it exists.
185 if (tokens.size() == kTurnTransportTokensNum) { // ?transport= is present.
Niels Möller6d122622022-06-03 13:51:21 +0200186 std::vector<absl::string_view> transport_tokens =
187 rtc::split(tokens[1], '=');
188 if (transport_tokens[0] != kTransport) {
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000189 RTC_LOG(LS_WARNING) << "Invalid transport parameter key.";
190 return RTCErrorType::SYNTAX_ERROR;
deadbeef1dcb1642017-03-29 21:08:16 -0700191 }
Niels Möller6d122622022-06-03 13:51:21 +0200192 if (transport_tokens.size() < 2) {
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000193 RTC_LOG(LS_WARNING) << "Transport parameter missing value.";
194 return RTCErrorType::SYNTAX_ERROR;
deadbeef1dcb1642017-03-29 21:08:16 -0700195 }
Niels Möller4662f532022-05-20 15:44:37 +0200196
197 absl::optional<cricket::ProtocolType> proto =
Niels Möller6d122622022-06-03 13:51:21 +0200198 cricket::StringToProto(transport_tokens[1]);
Niels Möller4662f532022-05-20 15:44:37 +0200199 if (!proto ||
200 (*proto != cricket::PROTO_UDP && *proto != cricket::PROTO_TCP)) {
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000201 RTC_LOG(LS_WARNING) << "Transport parameter should always be udp or tcp.";
202 return RTCErrorType::SYNTAX_ERROR;
deadbeef1dcb1642017-03-29 21:08:16 -0700203 }
Niels Möller4662f532022-05-20 15:44:37 +0200204 turn_transport_type = *proto;
deadbeef1dcb1642017-03-29 21:08:16 -0700205 }
206
Niels Möller6d122622022-06-03 13:51:21 +0200207 auto [service_type, hoststring] =
208 GetServiceTypeAndHostnameFromUri(uri_without_transport);
209 if (service_type == ServiceType::INVALID) {
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000210 RTC_LOG(LS_WARNING) << "Invalid transport parameter in ICE URI: " << url;
211 return RTCErrorType::SYNTAX_ERROR;
deadbeef1dcb1642017-03-29 21:08:16 -0700212 }
213
214 // GetServiceTypeAndHostnameFromUri should never give an empty hoststring
215 RTC_DCHECK(!hoststring.empty());
216
Niels Möller6d122622022-06-03 13:51:21 +0200217 int default_port = kDefaultStunPort;
218 if (service_type == ServiceType::TURNS) {
219 default_port = kDefaultStunTlsPort;
deadbeef1dcb1642017-03-29 21:08:16 -0700220 turn_transport_type = cricket::PROTO_TLS;
221 }
222
Niels Möller6d122622022-06-03 13:51:21 +0200223 if (hoststring.find('@') != absl::string_view::npos) {
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000224 RTC_LOG(LS_WARNING) << "Invalid url: " << uri_without_transport;
225 RTC_LOG(LS_WARNING)
226 << "Note that user-info@ in turn:-urls is long-deprecated.";
227 return RTCErrorType::SYNTAX_ERROR;
Niels Möllerdb4def92019-03-18 16:53:59 +0100228 }
Niels Möller6d122622022-06-03 13:51:21 +0200229
230 auto [success, address, port] =
231 ParseHostnameAndPortFromString(hoststring, default_port);
232 if (!success) {
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000233 RTC_LOG(LS_WARNING) << "Invalid hostname format: " << uri_without_transport;
234 return RTCErrorType::SYNTAX_ERROR;
deadbeef1dcb1642017-03-29 21:08:16 -0700235 }
236
237 if (port <= 0 || port > 0xffff) {
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000238 RTC_LOG(LS_WARNING) << "Invalid port: " << port;
239 return RTCErrorType::SYNTAX_ERROR;
deadbeef1dcb1642017-03-29 21:08:16 -0700240 }
241
242 switch (service_type) {
Niels Möller6d122622022-06-03 13:51:21 +0200243 case ServiceType::STUN:
244 case ServiceType::STUNS:
deadbeef1dcb1642017-03-29 21:08:16 -0700245 stun_servers->insert(rtc::SocketAddress(address, port));
246 break;
Niels Möller6d122622022-06-03 13:51:21 +0200247 case ServiceType::TURN:
248 case ServiceType::TURNS: {
Niels Möllerdb4def92019-03-18 16:53:59 +0100249 if (server.username.empty() || server.password.empty()) {
deadbeef1dcb1642017-03-29 21:08:16 -0700250 // The WebRTC spec requires throwing an InvalidAccessError when username
251 // or credential are ommitted; this is the native equivalent.
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000252 RTC_LOG(LS_WARNING) << "TURN server with empty username or password";
253 return RTCErrorType::INVALID_PARAMETER;
deadbeef1dcb1642017-03-29 21:08:16 -0700254 }
Emad Omaradab1d2d2017-06-16 15:43:11 -0700255 // If the hostname field is not empty, then the server address must be
256 // the resolved IP for that host, the hostname is needed later for TLS
257 // handshake (SNI and Certificate verification).
Niels Möller6d122622022-06-03 13:51:21 +0200258 absl::string_view hostname =
Emad Omaradab1d2d2017-06-16 15:43:11 -0700259 server.hostname.empty() ? address : server.hostname;
260 rtc::SocketAddress socket_address(hostname, port);
261 if (!server.hostname.empty()) {
262 rtc::IPAddress ip;
263 if (!IPFromString(address, &ip)) {
264 // When hostname is set, the server address must be a
265 // resolved ip address.
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000266 RTC_LOG(LS_WARNING)
267 << "IceServer has hostname field set, but URI does not "
268 "contain an IP address.";
269 return RTCErrorType::INVALID_PARAMETER;
Emad Omaradab1d2d2017-06-16 15:43:11 -0700270 }
271 socket_address.SetResolvedIP(ip);
272 }
Niels Möllerdb4def92019-03-18 16:53:59 +0100273 cricket::RelayServerConfig config =
274 cricket::RelayServerConfig(socket_address, server.username,
275 server.password, turn_transport_type);
deadbeef1dcb1642017-03-29 21:08:16 -0700276 if (server.tls_cert_policy ==
277 PeerConnectionInterface::kTlsCertPolicyInsecureNoCheck) {
Sergey Silkin9c147dd2018-09-12 10:45:38 +0000278 config.tls_cert_policy =
279 cricket::TlsCertPolicy::TLS_CERT_POLICY_INSECURE_NO_CHECK;
deadbeef1dcb1642017-03-29 21:08:16 -0700280 }
Sergey Silkin9c147dd2018-09-12 10:45:38 +0000281 config.tls_alpn_protocols = server.tls_alpn_protocols;
282 config.tls_elliptic_curves = server.tls_elliptic_curves;
Diogo Real1dca9d52017-08-29 12:18:32 -0700283
deadbeef1dcb1642017-03-29 21:08:16 -0700284 turn_servers->push_back(config);
285 break;
286 }
287 default:
288 // We shouldn't get to this point with an invalid service_type, we should
289 // have returned an error already.
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000290 RTC_DCHECK_NOTREACHED() << "Unexpected service type";
291 return RTCErrorType::INTERNAL_ERROR;
deadbeef1dcb1642017-03-29 21:08:16 -0700292 }
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000293 return RTCErrorType::NONE;
deadbeef1dcb1642017-03-29 21:08:16 -0700294}
295
Niels Möller6d122622022-06-03 13:51:21 +0200296} // namespace
297
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000298RTCErrorType ParseIceServers(
deadbeef1dcb1642017-03-29 21:08:16 -0700299 const PeerConnectionInterface::IceServers& servers,
300 cricket::ServerAddresses* stun_servers,
301 std::vector<cricket::RelayServerConfig>* turn_servers) {
302 for (const PeerConnectionInterface::IceServer& server : servers) {
303 if (!server.urls.empty()) {
304 for (const std::string& url : server.urls) {
305 if (url.empty()) {
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000306 RTC_LOG(LS_WARNING) << "Empty uri.";
307 return RTCErrorType::SYNTAX_ERROR;
deadbeef1dcb1642017-03-29 21:08:16 -0700308 }
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000309 RTCErrorType err =
deadbeef1dcb1642017-03-29 21:08:16 -0700310 ParseIceServerUrl(server, url, stun_servers, turn_servers);
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000311 if (err != RTCErrorType::NONE) {
deadbeef1dcb1642017-03-29 21:08:16 -0700312 return err;
313 }
314 }
315 } else if (!server.uri.empty()) {
316 // Fallback to old .uri if new .urls isn't present.
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000317 RTCErrorType err =
deadbeef1dcb1642017-03-29 21:08:16 -0700318 ParseIceServerUrl(server, server.uri, stun_servers, turn_servers);
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000319 if (err != RTCErrorType::NONE) {
deadbeef1dcb1642017-03-29 21:08:16 -0700320 return err;
321 }
322 } else {
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000323 RTC_LOG(LS_WARNING) << "Empty uri.";
324 return RTCErrorType::SYNTAX_ERROR;
deadbeef1dcb1642017-03-29 21:08:16 -0700325 }
326 }
327 // Candidates must have unique priorities, so that connectivity checks
328 // are performed in a well-defined order.
329 int priority = static_cast<int>(turn_servers->size() - 1);
330 for (cricket::RelayServerConfig& turn_server : *turn_servers) {
331 // First in the list gets highest priority.
332 turn_server.priority = priority--;
333 }
Mirko Bonadei4d47e0b2022-10-12 06:51:54 +0000334 return RTCErrorType::NONE;
deadbeef1dcb1642017-03-29 21:08:16 -0700335}
336
337} // namespace webrtc