server_test.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501
  1. /*
  2. * Copyright (c) 2016, Psiphon Inc.
  3. * All rights reserved.
  4. *
  5. * This program is free software: you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation, either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. *
  18. */
  19. package server
  20. import (
  21. "encoding/json"
  22. "flag"
  23. "fmt"
  24. "io/ioutil"
  25. "net"
  26. "net/http"
  27. "net/url"
  28. "os"
  29. "sync"
  30. "syscall"
  31. "testing"
  32. "time"
  33. "github.com/Psiphon-Labs/psiphon-tunnel-core/psiphon"
  34. "github.com/Psiphon-Labs/psiphon-tunnel-core/psiphon/common"
  35. "golang.org/x/net/proxy"
  36. )
  37. func TestMain(m *testing.M) {
  38. flag.Parse()
  39. os.Remove(psiphon.DATA_STORE_FILENAME)
  40. psiphon.SetEmitDiagnosticNotices(true)
  41. os.Exit(m.Run())
  42. }
  43. // Note: not testing fronting meek protocols, which client is
  44. // hard-wired to except running on privileged ports 80 and 443.
  45. func TestSSH(t *testing.T) {
  46. runServer(t,
  47. &runServerConfig{
  48. tunnelProtocol: "SSH",
  49. enableSSHAPIRequests: true,
  50. doHotReload: false,
  51. })
  52. }
  53. func TestOSSH(t *testing.T) {
  54. runServer(t,
  55. &runServerConfig{
  56. tunnelProtocol: "OSSH",
  57. enableSSHAPIRequests: true,
  58. doHotReload: false,
  59. })
  60. }
  61. func TestUnfrontedMeek(t *testing.T) {
  62. runServer(t,
  63. &runServerConfig{
  64. tunnelProtocol: "UNFRONTED-MEEK-OSSH",
  65. enableSSHAPIRequests: true,
  66. doHotReload: false,
  67. })
  68. }
  69. func TestUnfrontedMeekHTTPS(t *testing.T) {
  70. runServer(t,
  71. &runServerConfig{
  72. tunnelProtocol: "UNFRONTED-MEEK-HTTPS-OSSH",
  73. enableSSHAPIRequests: true,
  74. doHotReload: false,
  75. })
  76. }
  77. func TestWebTransportAPIRequests(t *testing.T) {
  78. runServer(t,
  79. &runServerConfig{
  80. tunnelProtocol: "OSSH",
  81. enableSSHAPIRequests: false,
  82. doHotReload: false,
  83. })
  84. }
  85. func TestHotReload(t *testing.T) {
  86. runServer(t,
  87. &runServerConfig{
  88. tunnelProtocol: "OSSH",
  89. enableSSHAPIRequests: true,
  90. doHotReload: true,
  91. })
  92. }
  93. type runServerConfig struct {
  94. tunnelProtocol string
  95. enableSSHAPIRequests bool
  96. doHotReload bool
  97. }
  98. func sendNotificationReceived(c chan<- struct{}) {
  99. select {
  100. case c <- *new(struct{}):
  101. default:
  102. }
  103. }
  104. func waitOnNotification(t *testing.T, c, timeoutSignal <-chan struct{}, timeoutMessage string) {
  105. select {
  106. case <-c:
  107. case <-timeoutSignal:
  108. t.Fatalf(timeoutMessage)
  109. }
  110. }
  111. const dummyClientVerificationPayload = `
  112. {
  113. "status": 0,
  114. "payload": ""
  115. }`
  116. func runServer(t *testing.T, runConfig *runServerConfig) {
  117. // create a server
  118. var err error
  119. serverIPaddress := ""
  120. for _, interfaceName := range []string{"eth0", "en0"} {
  121. serverIPaddress, err = psiphon.GetInterfaceIPAddress(interfaceName)
  122. if err == nil {
  123. break
  124. }
  125. }
  126. if err != nil {
  127. t.Fatalf("error getting server IP address: %s", err)
  128. }
  129. serverConfigJSON, _, encodedServerEntry, err := GenerateConfig(
  130. &GenerateConfigParams{
  131. ServerIPAddress: serverIPaddress,
  132. EnableSSHAPIRequests: runConfig.enableSSHAPIRequests,
  133. WebServerPort: 8000,
  134. TunnelProtocolPorts: map[string]int{runConfig.tunnelProtocol: 4000},
  135. })
  136. if err != nil {
  137. t.Fatalf("error generating server config: %s", err)
  138. }
  139. // customize server config
  140. // Pave psinet with random values to test handshake homepages.
  141. psinetFilename := "psinet.json"
  142. sponsorID, expectedHomepageURL := pavePsinetDatabaseFile(t, psinetFilename)
  143. var serverConfig interface{}
  144. json.Unmarshal(serverConfigJSON, &serverConfig)
  145. serverConfig.(map[string]interface{})["GeoIPDatabaseFilename"] = ""
  146. serverConfig.(map[string]interface{})["PsinetDatabaseFilename"] = psinetFilename
  147. serverConfig.(map[string]interface{})["TrafficRulesFilename"] = ""
  148. serverConfig.(map[string]interface{})["LogLevel"] = "debug"
  149. serverConfigJSON, _ = json.Marshal(serverConfig)
  150. // run server
  151. serverWaitGroup := new(sync.WaitGroup)
  152. serverWaitGroup.Add(1)
  153. go func() {
  154. defer serverWaitGroup.Done()
  155. err := RunServices(serverConfigJSON)
  156. if err != nil {
  157. // TODO: wrong goroutine for t.FatalNow()
  158. t.Fatalf("error running server: %s", err)
  159. }
  160. }()
  161. defer func() {
  162. // Test: orderly server shutdown
  163. p, _ := os.FindProcess(os.Getpid())
  164. p.Signal(os.Interrupt)
  165. shutdownTimeout := time.NewTimer(5 * time.Second)
  166. shutdownOk := make(chan struct{}, 1)
  167. go func() {
  168. serverWaitGroup.Wait()
  169. shutdownOk <- *new(struct{})
  170. }()
  171. select {
  172. case <-shutdownOk:
  173. case <-shutdownTimeout.C:
  174. t.Fatalf("server shutdown timeout exceeded")
  175. }
  176. }()
  177. // Test: hot reload (of psinet)
  178. if runConfig.doHotReload {
  179. // TODO: monitor logs for more robust wait-until-loaded
  180. time.Sleep(1 * time.Second)
  181. // Pave a new psinet with different random values.
  182. sponsorID, expectedHomepageURL = pavePsinetDatabaseFile(t, psinetFilename)
  183. p, _ := os.FindProcess(os.Getpid())
  184. p.Signal(syscall.SIGUSR1)
  185. // TODO: monitor logs for more robust wait-until-reloaded
  186. time.Sleep(1 * time.Second)
  187. // After reloading psinet, the new sponsorID/expectedHomepageURL
  188. // should be active, as tested in the client "Homepage" notice
  189. // handler below.
  190. }
  191. // connect to server with client
  192. // TODO: currently, TargetServerEntry only works with one tunnel
  193. numTunnels := 1
  194. localSOCKSProxyPort := 1081
  195. localHTTPProxyPort := 8081
  196. establishTunnelPausePeriodSeconds := 1
  197. // Note: calling LoadConfig ensures all *int config fields are initialized
  198. clientConfigJSON := `
  199. {
  200. "ClientPlatform" : "Android",
  201. "ClientVersion" : "0",
  202. "SponsorId" : "0",
  203. "PropagationChannelId" : "0"
  204. }`
  205. clientConfig, _ := psiphon.LoadConfig([]byte(clientConfigJSON))
  206. clientConfig.SponsorId = sponsorID
  207. clientConfig.ConnectionWorkerPoolSize = numTunnels
  208. clientConfig.TunnelPoolSize = numTunnels
  209. clientConfig.DisableRemoteServerListFetcher = true
  210. clientConfig.EstablishTunnelPausePeriodSeconds = &establishTunnelPausePeriodSeconds
  211. clientConfig.TargetServerEntry = string(encodedServerEntry)
  212. clientConfig.TunnelProtocol = runConfig.tunnelProtocol
  213. clientConfig.LocalSocksProxyPort = localSOCKSProxyPort
  214. clientConfig.LocalHttpProxyPort = localHTTPProxyPort
  215. err = psiphon.InitDataStore(clientConfig)
  216. if err != nil {
  217. t.Fatalf("error initializing client datastore: %s", err)
  218. }
  219. controller, err := psiphon.NewController(clientConfig)
  220. if err != nil {
  221. t.Fatalf("error creating client controller: %s", err)
  222. }
  223. tunnelsEstablished := make(chan struct{}, 1)
  224. homepageReceived := make(chan struct{}, 1)
  225. verificationRequired := make(chan struct{}, 1)
  226. verificationCompleted := make(chan struct{}, 1)
  227. psiphon.SetNoticeOutput(psiphon.NewNoticeReceiver(
  228. func(notice []byte) {
  229. //fmt.Printf("%s\n", string(notice))
  230. noticeType, payload, err := psiphon.GetNotice(notice)
  231. if err != nil {
  232. return
  233. }
  234. switch noticeType {
  235. case "Tunnels":
  236. // Do not set verification payload until tunnel is
  237. // established. Otherwise will silently take no action.
  238. controller.SetClientVerificationPayloadForActiveTunnels("")
  239. count := int(payload["count"].(float64))
  240. if count >= numTunnels {
  241. sendNotificationReceived(tunnelsEstablished)
  242. }
  243. case "Homepage":
  244. homepageURL := payload["url"].(string)
  245. if homepageURL != expectedHomepageURL {
  246. // TODO: wrong goroutine for t.FatalNow()
  247. t.Fatalf("unexpected homepage: %s", homepageURL)
  248. }
  249. sendNotificationReceived(homepageReceived)
  250. case "ClientVerificationRequired":
  251. sendNotificationReceived(verificationRequired)
  252. controller.SetClientVerificationPayloadForActiveTunnels(dummyClientVerificationPayload)
  253. case "NoticeClientVerificationRequestCompleted":
  254. sendNotificationReceived(verificationCompleted)
  255. }
  256. }))
  257. controllerShutdownBroadcast := make(chan struct{})
  258. controllerWaitGroup := new(sync.WaitGroup)
  259. controllerWaitGroup.Add(1)
  260. go func() {
  261. defer controllerWaitGroup.Done()
  262. controller.Run(controllerShutdownBroadcast)
  263. }()
  264. defer func() {
  265. close(controllerShutdownBroadcast)
  266. shutdownTimeout := time.NewTimer(20 * time.Second)
  267. shutdownOk := make(chan struct{}, 1)
  268. go func() {
  269. controllerWaitGroup.Wait()
  270. shutdownOk <- *new(struct{})
  271. }()
  272. select {
  273. case <-shutdownOk:
  274. case <-shutdownTimeout.C:
  275. t.Fatalf("controller shutdown timeout exceeded")
  276. }
  277. }()
  278. // Test: tunnels must be established, and correct homepage
  279. // must be received, within 30 seconds
  280. timeoutSignal := make(chan struct{})
  281. go func() {
  282. timer := time.NewTimer(30 * time.Second)
  283. <-timer.C
  284. close(timeoutSignal)
  285. }()
  286. waitOnNotification(t, tunnelsEstablished, timeoutSignal, "tunnel establish timeout exceeded")
  287. waitOnNotification(t, homepageReceived, timeoutSignal, "homepage received timeout exceeded")
  288. waitOnNotification(t, verificationRequired, timeoutSignal, "verification required timeout exceeded")
  289. waitOnNotification(t, verificationCompleted, timeoutSignal, "verification completed timeout exceeded")
  290. // Test: tunneled web site fetch
  291. makeTunneledWebRequest(t, localHTTPProxyPort)
  292. // Test: tunneled UDP packet
  293. udpgwServerAddress := serverConfig.(map[string]interface{})["UDPInterceptUdpgwServerAddress"].(string)
  294. makeTunneledDNSRequest(t, localSOCKSProxyPort, udpgwServerAddress)
  295. }
  296. func makeTunneledWebRequest(t *testing.T, localHTTPProxyPort int) {
  297. testUrl := "https://psiphon.ca"
  298. roundTripTimeout := 30 * time.Second
  299. proxyUrl, err := url.Parse(fmt.Sprintf("http://127.0.0.1:%d", localHTTPProxyPort))
  300. if err != nil {
  301. t.Fatalf("error initializing proxied HTTP request: %s", err)
  302. }
  303. httpClient := &http.Client{
  304. Transport: &http.Transport{
  305. Proxy: http.ProxyURL(proxyUrl),
  306. },
  307. Timeout: roundTripTimeout,
  308. }
  309. response, err := httpClient.Get(testUrl)
  310. if err != nil {
  311. t.Fatalf("error sending proxied HTTP request: %s", err)
  312. }
  313. _, err = ioutil.ReadAll(response.Body)
  314. if err != nil {
  315. t.Fatalf("error reading proxied HTTP response: %s", err)
  316. }
  317. response.Body.Close()
  318. }
  319. func makeTunneledDNSRequest(t *testing.T, localSOCKSProxyPort int, udpgwServerAddress string) {
  320. testHostname := "psiphon.ca"
  321. timeout := 10 * time.Second
  322. localUDPProxyAddress, err := net.ResolveUDPAddr("udp", "127.0.0.1:7301")
  323. if err != nil {
  324. t.Fatalf("ResolveUDPAddr failed: %s", err)
  325. }
  326. go func() {
  327. serverUDPConn, err := net.ListenUDP("udp", localUDPProxyAddress)
  328. if err != nil {
  329. t.Fatalf("ListenUDP failed: %s", err)
  330. }
  331. defer serverUDPConn.Close()
  332. udpgwPreambleSize := 11 // see writeUdpgwPreamble
  333. buffer := make([]byte, udpgwProtocolMaxMessageSize)
  334. packetSize, clientAddr, err := serverUDPConn.ReadFromUDP(
  335. buffer[udpgwPreambleSize:len(buffer)])
  336. if err != nil {
  337. t.Fatalf("serverUDPConn.Read failed: %s", err)
  338. }
  339. socksProxyAddress := fmt.Sprintf("127.0.0.1:%d", localSOCKSProxyPort)
  340. dialer, err := proxy.SOCKS5("tcp", socksProxyAddress, nil, proxy.Direct)
  341. if err != nil {
  342. t.Fatalf("proxy.SOCKS5 failed: %s", err)
  343. }
  344. socksTCPConn, err := dialer.Dial("tcp", udpgwServerAddress)
  345. if err != nil {
  346. t.Fatalf("dialer.Dial failed: %s", err)
  347. }
  348. defer socksTCPConn.Close()
  349. err = writeUdpgwPreamble(
  350. udpgwPreambleSize,
  351. udpgwProtocolFlagDNS,
  352. 0,
  353. make([]byte, 4), // ignored due to transparent DNS forwarding
  354. 53,
  355. uint16(packetSize),
  356. buffer)
  357. if err != nil {
  358. t.Fatalf("writeUdpgwPreamble failed: %s", err)
  359. }
  360. _, err = socksTCPConn.Write(buffer[0 : udpgwPreambleSize+packetSize])
  361. if err != nil {
  362. t.Fatalf("socksTCPConn.Write failed: %s", err)
  363. }
  364. updgwProtocolMessage, err := readUdpgwMessage(socksTCPConn, buffer)
  365. if err != nil {
  366. t.Fatalf("readUdpgwMessage failed: %s", err)
  367. }
  368. _, err = serverUDPConn.WriteToUDP(updgwProtocolMessage.packet, clientAddr)
  369. if err != nil {
  370. t.Fatalf("serverUDPConn.Write failed: %s", err)
  371. }
  372. }()
  373. // TODO: properly synchronize with server startup
  374. time.Sleep(1 * time.Second)
  375. clientUDPConn, err := net.DialUDP("udp", nil, localUDPProxyAddress)
  376. if err != nil {
  377. t.Fatalf("DialUDP failed: %s", err)
  378. }
  379. defer clientUDPConn.Close()
  380. clientUDPConn.SetReadDeadline(time.Now().Add(timeout))
  381. clientUDPConn.SetWriteDeadline(time.Now().Add(timeout))
  382. _, _, err = psiphon.ResolveIP(testHostname, clientUDPConn)
  383. if err != nil {
  384. t.Fatalf("ResolveIP failed: %s", err)
  385. }
  386. }
  387. func pavePsinetDatabaseFile(t *testing.T, psinetFilename string) (string, string) {
  388. sponsorID, _ := common.MakeRandomStringHex(8)
  389. fakeDomain, _ := common.MakeRandomStringHex(4)
  390. fakePath, _ := common.MakeRandomStringHex(4)
  391. expectedHomepageURL := fmt.Sprintf("https://%s.com/%s", fakeDomain, fakePath)
  392. psinetJSONFormat := `
  393. {
  394. "sponsors": {
  395. "%s": {
  396. "home_pages": {
  397. "None": [
  398. {
  399. "region": null,
  400. "url": "%s"
  401. }
  402. ]
  403. }
  404. }
  405. }
  406. }
  407. `
  408. psinetJSON := fmt.Sprintf(psinetJSONFormat, sponsorID, expectedHomepageURL)
  409. err := ioutil.WriteFile(psinetFilename, []byte(psinetJSON), 0600)
  410. if err != nil {
  411. t.Fatalf("error paving psinet database: %s", err)
  412. }
  413. return sponsorID, expectedHomepageURL
  414. }