server_test.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505
  1. /*
  2. * Copyright (c) 2016, Psiphon Inc.
  3. * All rights reserved.
  4. *
  5. * This program is free software: you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation, either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. *
  18. */
  19. package server
  20. import (
  21. "encoding/json"
  22. "flag"
  23. "fmt"
  24. "io/ioutil"
  25. "net"
  26. "net/http"
  27. "net/url"
  28. "os"
  29. "sync"
  30. "syscall"
  31. "testing"
  32. "time"
  33. "github.com/Psiphon-Labs/psiphon-tunnel-core/psiphon"
  34. "github.com/Psiphon-Labs/psiphon-tunnel-core/psiphon/common"
  35. "golang.org/x/net/proxy"
  36. )
  37. func TestMain(m *testing.M) {
  38. flag.Parse()
  39. os.Remove(psiphon.DATA_STORE_FILENAME)
  40. psiphon.SetEmitDiagnosticNotices(true)
  41. os.Exit(m.Run())
  42. }
  43. // Note: not testing fronting meek protocols, which client is
  44. // hard-wired to except running on privileged ports 80 and 443.
  45. func TestSSH(t *testing.T) {
  46. runServer(t,
  47. &runServerConfig{
  48. tunnelProtocol: "SSH",
  49. enableSSHAPIRequests: true,
  50. doHotReload: false,
  51. })
  52. }
  53. func TestOSSH(t *testing.T) {
  54. runServer(t,
  55. &runServerConfig{
  56. tunnelProtocol: "OSSH",
  57. enableSSHAPIRequests: true,
  58. doHotReload: false,
  59. })
  60. }
  61. func TestUnfrontedMeek(t *testing.T) {
  62. runServer(t,
  63. &runServerConfig{
  64. tunnelProtocol: "UNFRONTED-MEEK-OSSH",
  65. enableSSHAPIRequests: true,
  66. doHotReload: false,
  67. })
  68. }
  69. func TestUnfrontedMeekHTTPS(t *testing.T) {
  70. runServer(t,
  71. &runServerConfig{
  72. tunnelProtocol: "UNFRONTED-MEEK-HTTPS-OSSH",
  73. enableSSHAPIRequests: true,
  74. doHotReload: false,
  75. })
  76. }
  77. func TestWebTransportAPIRequests(t *testing.T) {
  78. runServer(t,
  79. &runServerConfig{
  80. tunnelProtocol: "OSSH",
  81. enableSSHAPIRequests: false,
  82. doHotReload: false,
  83. })
  84. }
  85. func TestHotReload(t *testing.T) {
  86. runServer(t,
  87. &runServerConfig{
  88. tunnelProtocol: "OSSH",
  89. enableSSHAPIRequests: true,
  90. doHotReload: true,
  91. })
  92. }
  93. type runServerConfig struct {
  94. tunnelProtocol string
  95. enableSSHAPIRequests bool
  96. doHotReload bool
  97. }
  98. func sendNotificationReceived(c chan<- struct{}) {
  99. select {
  100. case c <- *new(struct{}):
  101. default:
  102. }
  103. }
  104. func waitOnNotification(t *testing.T, c, timeoutSignal <-chan struct{}, timeoutMessage string) {
  105. select {
  106. case <-c:
  107. case <-timeoutSignal:
  108. t.Fatalf(timeoutMessage)
  109. }
  110. }
  111. const dummyClientVerificationPayload = `
  112. {
  113. "status": 0,
  114. "payload": ""
  115. }`
  116. func runServer(t *testing.T, runConfig *runServerConfig) {
  117. // create a server
  118. var err error
  119. serverIPaddress := ""
  120. for _, interfaceName := range []string{"eth0", "en0"} {
  121. serverIPaddress, err = psiphon.GetInterfaceIPAddress(interfaceName)
  122. if err == nil {
  123. break
  124. }
  125. }
  126. if err != nil {
  127. t.Fatalf("error getting server IP address: %s", err)
  128. }
  129. serverConfigJSON, _, encodedServerEntry, err := GenerateConfig(
  130. &GenerateConfigParams{
  131. ServerIPAddress: serverIPaddress,
  132. EnableSSHAPIRequests: runConfig.enableSSHAPIRequests,
  133. WebServerPort: 8000,
  134. TunnelProtocolPorts: map[string]int{runConfig.tunnelProtocol: 4000},
  135. })
  136. if err != nil {
  137. t.Fatalf("error generating server config: %s", err)
  138. }
  139. // customize server config
  140. // Pave psinet with random values to test handshake homepages.
  141. psinetFilename := "psinet.json"
  142. sponsorID, expectedHomepageURL := pavePsinetDatabaseFile(t, psinetFilename)
  143. var serverConfig interface{}
  144. json.Unmarshal(serverConfigJSON, &serverConfig)
  145. serverConfig.(map[string]interface{})["GeoIPDatabaseFilename"] = ""
  146. serverConfig.(map[string]interface{})["PsinetDatabaseFilename"] = psinetFilename
  147. serverConfig.(map[string]interface{})["TrafficRulesFilename"] = ""
  148. serverConfig.(map[string]interface{})["LogLevel"] = "debug"
  149. // 1 second is the minimum period; should be small enough to emit a log during the
  150. // test run, but not guaranteed
  151. serverConfig.(map[string]interface{})["LoadMonitorPeriodSeconds"] = 1
  152. serverConfigJSON, _ = json.Marshal(serverConfig)
  153. // run server
  154. serverWaitGroup := new(sync.WaitGroup)
  155. serverWaitGroup.Add(1)
  156. go func() {
  157. defer serverWaitGroup.Done()
  158. err := RunServices(serverConfigJSON)
  159. if err != nil {
  160. // TODO: wrong goroutine for t.FatalNow()
  161. t.Fatalf("error running server: %s", err)
  162. }
  163. }()
  164. defer func() {
  165. // Test: orderly server shutdown
  166. p, _ := os.FindProcess(os.Getpid())
  167. p.Signal(os.Interrupt)
  168. shutdownTimeout := time.NewTimer(5 * time.Second)
  169. shutdownOk := make(chan struct{}, 1)
  170. go func() {
  171. serverWaitGroup.Wait()
  172. shutdownOk <- *new(struct{})
  173. }()
  174. select {
  175. case <-shutdownOk:
  176. case <-shutdownTimeout.C:
  177. t.Fatalf("server shutdown timeout exceeded")
  178. }
  179. }()
  180. // Test: hot reload (of psinet)
  181. if runConfig.doHotReload {
  182. // TODO: monitor logs for more robust wait-until-loaded
  183. time.Sleep(1 * time.Second)
  184. // Pave a new psinet with different random values.
  185. sponsorID, expectedHomepageURL = pavePsinetDatabaseFile(t, psinetFilename)
  186. p, _ := os.FindProcess(os.Getpid())
  187. p.Signal(syscall.SIGUSR1)
  188. // TODO: monitor logs for more robust wait-until-reloaded
  189. time.Sleep(1 * time.Second)
  190. // After reloading psinet, the new sponsorID/expectedHomepageURL
  191. // should be active, as tested in the client "Homepage" notice
  192. // handler below.
  193. }
  194. // connect to server with client
  195. // TODO: currently, TargetServerEntry only works with one tunnel
  196. numTunnels := 1
  197. localSOCKSProxyPort := 1081
  198. localHTTPProxyPort := 8081
  199. establishTunnelPausePeriodSeconds := 1
  200. // Note: calling LoadConfig ensures all *int config fields are initialized
  201. clientConfigJSON := `
  202. {
  203. "ClientPlatform" : "Android",
  204. "ClientVersion" : "0",
  205. "SponsorId" : "0",
  206. "PropagationChannelId" : "0"
  207. }`
  208. clientConfig, _ := psiphon.LoadConfig([]byte(clientConfigJSON))
  209. clientConfig.SponsorId = sponsorID
  210. clientConfig.ConnectionWorkerPoolSize = numTunnels
  211. clientConfig.TunnelPoolSize = numTunnels
  212. clientConfig.DisableRemoteServerListFetcher = true
  213. clientConfig.EstablishTunnelPausePeriodSeconds = &establishTunnelPausePeriodSeconds
  214. clientConfig.TargetServerEntry = string(encodedServerEntry)
  215. clientConfig.TunnelProtocol = runConfig.tunnelProtocol
  216. clientConfig.LocalSocksProxyPort = localSOCKSProxyPort
  217. clientConfig.LocalHttpProxyPort = localHTTPProxyPort
  218. err = psiphon.InitDataStore(clientConfig)
  219. if err != nil {
  220. t.Fatalf("error initializing client datastore: %s", err)
  221. }
  222. controller, err := psiphon.NewController(clientConfig)
  223. if err != nil {
  224. t.Fatalf("error creating client controller: %s", err)
  225. }
  226. tunnelsEstablished := make(chan struct{}, 1)
  227. homepageReceived := make(chan struct{}, 1)
  228. verificationRequired := make(chan struct{}, 1)
  229. verificationCompleted := make(chan struct{}, 1)
  230. psiphon.SetNoticeOutput(psiphon.NewNoticeReceiver(
  231. func(notice []byte) {
  232. //fmt.Printf("%s\n", string(notice))
  233. noticeType, payload, err := psiphon.GetNotice(notice)
  234. if err != nil {
  235. return
  236. }
  237. switch noticeType {
  238. case "Tunnels":
  239. // Do not set verification payload until tunnel is
  240. // established. Otherwise will silently take no action.
  241. controller.SetClientVerificationPayloadForActiveTunnels("")
  242. count := int(payload["count"].(float64))
  243. if count >= numTunnels {
  244. sendNotificationReceived(tunnelsEstablished)
  245. }
  246. case "Homepage":
  247. homepageURL := payload["url"].(string)
  248. if homepageURL != expectedHomepageURL {
  249. // TODO: wrong goroutine for t.FatalNow()
  250. t.Fatalf("unexpected homepage: %s", homepageURL)
  251. }
  252. sendNotificationReceived(homepageReceived)
  253. case "ClientVerificationRequired":
  254. sendNotificationReceived(verificationRequired)
  255. controller.SetClientVerificationPayloadForActiveTunnels(dummyClientVerificationPayload)
  256. case "NoticeClientVerificationRequestCompleted":
  257. sendNotificationReceived(verificationCompleted)
  258. }
  259. }))
  260. controllerShutdownBroadcast := make(chan struct{})
  261. controllerWaitGroup := new(sync.WaitGroup)
  262. controllerWaitGroup.Add(1)
  263. go func() {
  264. defer controllerWaitGroup.Done()
  265. controller.Run(controllerShutdownBroadcast)
  266. }()
  267. defer func() {
  268. close(controllerShutdownBroadcast)
  269. shutdownTimeout := time.NewTimer(20 * time.Second)
  270. shutdownOk := make(chan struct{}, 1)
  271. go func() {
  272. controllerWaitGroup.Wait()
  273. shutdownOk <- *new(struct{})
  274. }()
  275. select {
  276. case <-shutdownOk:
  277. case <-shutdownTimeout.C:
  278. t.Fatalf("controller shutdown timeout exceeded")
  279. }
  280. }()
  281. // Test: tunnels must be established, and correct homepage
  282. // must be received, within 30 seconds
  283. timeoutSignal := make(chan struct{})
  284. go func() {
  285. timer := time.NewTimer(30 * time.Second)
  286. <-timer.C
  287. close(timeoutSignal)
  288. }()
  289. waitOnNotification(t, tunnelsEstablished, timeoutSignal, "tunnel establish timeout exceeded")
  290. waitOnNotification(t, homepageReceived, timeoutSignal, "homepage received timeout exceeded")
  291. waitOnNotification(t, verificationRequired, timeoutSignal, "verification required timeout exceeded")
  292. waitOnNotification(t, verificationCompleted, timeoutSignal, "verification completed timeout exceeded")
  293. // Test: tunneled web site fetch
  294. makeTunneledWebRequest(t, localHTTPProxyPort)
  295. // Test: tunneled UDP packet
  296. udpgwServerAddress := serverConfig.(map[string]interface{})["UDPInterceptUdpgwServerAddress"].(string)
  297. makeTunneledDNSRequest(t, localSOCKSProxyPort, udpgwServerAddress)
  298. }
  299. func makeTunneledWebRequest(t *testing.T, localHTTPProxyPort int) {
  300. testUrl := "https://psiphon.ca"
  301. roundTripTimeout := 30 * time.Second
  302. proxyUrl, err := url.Parse(fmt.Sprintf("http://127.0.0.1:%d", localHTTPProxyPort))
  303. if err != nil {
  304. t.Fatalf("error initializing proxied HTTP request: %s", err)
  305. }
  306. httpClient := &http.Client{
  307. Transport: &http.Transport{
  308. Proxy: http.ProxyURL(proxyUrl),
  309. },
  310. Timeout: roundTripTimeout,
  311. }
  312. response, err := httpClient.Get(testUrl)
  313. if err != nil {
  314. t.Fatalf("error sending proxied HTTP request: %s", err)
  315. }
  316. _, err = ioutil.ReadAll(response.Body)
  317. if err != nil {
  318. t.Fatalf("error reading proxied HTTP response: %s", err)
  319. }
  320. response.Body.Close()
  321. }
  322. func makeTunneledDNSRequest(t *testing.T, localSOCKSProxyPort int, udpgwServerAddress string) {
  323. testHostname := "psiphon.ca"
  324. timeout := 10 * time.Second
  325. localUDPProxyAddress, err := net.ResolveUDPAddr("udp", "127.0.0.1:7301")
  326. if err != nil {
  327. t.Fatalf("ResolveUDPAddr failed: %s", err)
  328. }
  329. go func() {
  330. serverUDPConn, err := net.ListenUDP("udp", localUDPProxyAddress)
  331. if err != nil {
  332. t.Fatalf("ListenUDP failed: %s", err)
  333. }
  334. defer serverUDPConn.Close()
  335. udpgwPreambleSize := 11 // see writeUdpgwPreamble
  336. buffer := make([]byte, udpgwProtocolMaxMessageSize)
  337. packetSize, clientAddr, err := serverUDPConn.ReadFromUDP(
  338. buffer[udpgwPreambleSize:len(buffer)])
  339. if err != nil {
  340. t.Fatalf("serverUDPConn.Read failed: %s", err)
  341. }
  342. socksProxyAddress := fmt.Sprintf("127.0.0.1:%d", localSOCKSProxyPort)
  343. dialer, err := proxy.SOCKS5("tcp", socksProxyAddress, nil, proxy.Direct)
  344. if err != nil {
  345. t.Fatalf("proxy.SOCKS5 failed: %s", err)
  346. }
  347. socksTCPConn, err := dialer.Dial("tcp", udpgwServerAddress)
  348. if err != nil {
  349. t.Fatalf("dialer.Dial failed: %s", err)
  350. }
  351. defer socksTCPConn.Close()
  352. err = writeUdpgwPreamble(
  353. udpgwPreambleSize,
  354. udpgwProtocolFlagDNS,
  355. 0,
  356. make([]byte, 4), // ignored due to transparent DNS forwarding
  357. 53,
  358. uint16(packetSize),
  359. buffer)
  360. if err != nil {
  361. t.Fatalf("writeUdpgwPreamble failed: %s", err)
  362. }
  363. _, err = socksTCPConn.Write(buffer[0 : udpgwPreambleSize+packetSize])
  364. if err != nil {
  365. t.Fatalf("socksTCPConn.Write failed: %s", err)
  366. }
  367. updgwProtocolMessage, err := readUdpgwMessage(socksTCPConn, buffer)
  368. if err != nil {
  369. t.Fatalf("readUdpgwMessage failed: %s", err)
  370. }
  371. _, err = serverUDPConn.WriteToUDP(updgwProtocolMessage.packet, clientAddr)
  372. if err != nil {
  373. t.Fatalf("serverUDPConn.Write failed: %s", err)
  374. }
  375. }()
  376. // TODO: properly synchronize with server startup
  377. time.Sleep(1 * time.Second)
  378. clientUDPConn, err := net.DialUDP("udp", nil, localUDPProxyAddress)
  379. if err != nil {
  380. t.Fatalf("DialUDP failed: %s", err)
  381. }
  382. defer clientUDPConn.Close()
  383. clientUDPConn.SetReadDeadline(time.Now().Add(timeout))
  384. clientUDPConn.SetWriteDeadline(time.Now().Add(timeout))
  385. _, _, err = psiphon.ResolveIP(testHostname, clientUDPConn)
  386. if err != nil {
  387. t.Fatalf("ResolveIP failed: %s", err)
  388. }
  389. }
  390. func pavePsinetDatabaseFile(t *testing.T, psinetFilename string) (string, string) {
  391. sponsorID, _ := common.MakeRandomStringHex(8)
  392. fakeDomain, _ := common.MakeRandomStringHex(4)
  393. fakePath, _ := common.MakeRandomStringHex(4)
  394. expectedHomepageURL := fmt.Sprintf("https://%s.com/%s", fakeDomain, fakePath)
  395. psinetJSONFormat := `
  396. {
  397. "sponsors": {
  398. "%s": {
  399. "home_pages": {
  400. "None": [
  401. {
  402. "region": null,
  403. "url": "%s"
  404. }
  405. ]
  406. }
  407. }
  408. }
  409. }
  410. `
  411. psinetJSON := fmt.Sprintf(psinetJSONFormat, sponsorID, expectedHomepageURL)
  412. err := ioutil.WriteFile(psinetFilename, []byte(psinetJSON), 0600)
  413. if err != nil {
  414. t.Fatalf("error paving psinet database: %s", err)
  415. }
  416. return sponsorID, expectedHomepageURL
  417. }