]> git.ipfire.org Git - thirdparty/openssl.git/blob - ssl/quic/quic_tserver.c
a3359c21c022fd72857a9ad59544ef70418d9822
[thirdparty/openssl.git] / ssl / quic / quic_tserver.c
1 /*
2 * Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.
3 *
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
8 */
9
10 #include "internal/quic_tserver.h"
11 #include "internal/quic_channel.h"
12 #include "internal/quic_statm.h"
13 #include "internal/common.h"
14 #include "internal/time.h"
15 #include "quic_local.h"
16
17 /*
18 * QUIC Test Server Module
19 * =======================
20 */
21 struct quic_tserver_st {
22 QUIC_TSERVER_ARGS args;
23
24 /* Dummy SSL object for this QUIC connection for use by msg_callback */
25 SSL *ssl;
26
27 /*
28 * The QUIC channel providing the core QUIC connection implementation.
29 */
30 QUIC_CHANNEL *ch;
31
32 /* The mutex we give to the QUIC channel. */
33 CRYPTO_MUTEX *mutex;
34
35 /* SSL_CTX for creating the underlying TLS connection */
36 SSL_CTX *ctx;
37
38 /* SSL for the underlying TLS connection */
39 SSL *tls;
40
41 /* The current peer L4 address. AF_UNSPEC if we do not have a peer yet. */
42 BIO_ADDR cur_peer_addr;
43
44 /* Are we connected to a peer? */
45 unsigned int connected : 1;
46 };
47
48 static int alpn_select_cb(SSL *ssl, const unsigned char **out,
49 unsigned char *outlen, const unsigned char *in,
50 unsigned int inlen, void *arg)
51 {
52 QUIC_TSERVER *srv = arg;
53 static const unsigned char alpndeflt[] = {
54 8, 'o', 's', 's', 'l', 't', 'e', 's', 't'
55 };
56 static const unsigned char *alpn;
57 size_t alpnlen;
58
59 if (srv->args.alpn == NULL) {
60 alpn = alpndeflt;
61 alpnlen = sizeof(alpn);
62 } else {
63 alpn = srv->args.alpn;
64 alpnlen = srv->args.alpnlen;
65 }
66
67 if (SSL_select_next_proto((unsigned char **)out, outlen, alpn, alpnlen,
68 in, inlen) != OPENSSL_NPN_NEGOTIATED)
69 return SSL_TLSEXT_ERR_ALERT_FATAL;
70
71 return SSL_TLSEXT_ERR_OK;
72 }
73
74 QUIC_TSERVER *ossl_quic_tserver_new(const QUIC_TSERVER_ARGS *args,
75 const char *certfile, const char *keyfile)
76 {
77 QUIC_TSERVER *srv = NULL;
78 QUIC_CHANNEL_ARGS ch_args = {0};
79 QUIC_CONNECTION *qc = NULL;
80
81 if (args->net_rbio == NULL || args->net_wbio == NULL)
82 goto err;
83
84 if ((srv = OPENSSL_zalloc(sizeof(*srv))) == NULL)
85 goto err;
86
87 srv->args = *args;
88
89 #if defined(OPENSSL_THREADS)
90 if ((srv->mutex = ossl_crypto_mutex_new()) == NULL)
91 goto err;
92 #endif
93
94 if (args->ctx != NULL)
95 srv->ctx = args->ctx;
96 else
97 srv->ctx = SSL_CTX_new_ex(srv->args.libctx, srv->args.propq,
98 TLS_method());
99 if (srv->ctx == NULL)
100 goto err;
101
102 if (SSL_CTX_use_certificate_file(srv->ctx, certfile, SSL_FILETYPE_PEM) <= 0)
103 goto err;
104
105 if (SSL_CTX_use_PrivateKey_file(srv->ctx, keyfile, SSL_FILETYPE_PEM) <= 0)
106 goto err;
107
108 SSL_CTX_set_alpn_select_cb(srv->ctx, alpn_select_cb, srv);
109
110 srv->tls = SSL_new(srv->ctx);
111 if (srv->tls == NULL)
112 goto err;
113
114 ch_args.libctx = srv->args.libctx;
115 ch_args.propq = srv->args.propq;
116 ch_args.tls = srv->tls;
117 ch_args.mutex = srv->mutex;
118 ch_args.is_server = 1;
119 ch_args.now_cb = srv->args.now_cb;
120 ch_args.now_cb_arg = srv->args.now_cb_arg;
121
122 if ((srv->ch = ossl_quic_channel_new(&ch_args)) == NULL)
123 goto err;
124
125 if (!ossl_quic_channel_set_net_rbio(srv->ch, srv->args.net_rbio)
126 || !ossl_quic_channel_set_net_wbio(srv->ch, srv->args.net_wbio))
127 goto err;
128
129 qc = OPENSSL_zalloc(sizeof(*qc));
130 if (qc == NULL)
131 goto err;
132 srv->ssl = (SSL *)qc;
133 qc->ch = srv->ch;
134 srv->ssl->type = SSL_TYPE_QUIC_CONNECTION;
135
136 return srv;
137
138 err:
139 if (srv != NULL) {
140 if (args->ctx == NULL)
141 SSL_CTX_free(srv->ctx);
142 SSL_free(srv->tls);
143 ossl_quic_channel_free(srv->ch);
144 #if defined(OPENSSL_THREADS)
145 ossl_crypto_mutex_free(&srv->mutex);
146 #endif
147 OPENSSL_free(qc);
148 }
149
150 OPENSSL_free(srv);
151 return NULL;
152 }
153
154 void ossl_quic_tserver_free(QUIC_TSERVER *srv)
155 {
156 if (srv == NULL)
157 return;
158
159 ossl_quic_channel_free(srv->ch);
160 BIO_free(srv->args.net_rbio);
161 BIO_free(srv->args.net_wbio);
162 OPENSSL_free(srv->ssl);
163 SSL_free(srv->tls);
164 SSL_CTX_free(srv->ctx);
165 #if defined(OPENSSL_THREADS)
166 ossl_crypto_mutex_free(&srv->mutex);
167 #endif
168 OPENSSL_free(srv);
169 }
170
171 /* Set mutator callbacks for test framework support */
172 int ossl_quic_tserver_set_plain_packet_mutator(QUIC_TSERVER *srv,
173 ossl_mutate_packet_cb mutatecb,
174 ossl_finish_mutate_cb finishmutatecb,
175 void *mutatearg)
176 {
177 return ossl_quic_channel_set_mutator(srv->ch, mutatecb, finishmutatecb,
178 mutatearg);
179 }
180
181 int ossl_quic_tserver_set_handshake_mutator(QUIC_TSERVER *srv,
182 ossl_statem_mutate_handshake_cb mutate_handshake_cb,
183 ossl_statem_finish_mutate_handshake_cb finish_mutate_handshake_cb,
184 void *mutatearg)
185 {
186 return ossl_statem_set_mutator(ossl_quic_channel_get0_ssl(srv->ch),
187 mutate_handshake_cb,
188 finish_mutate_handshake_cb,
189 mutatearg);
190 }
191
192 int ossl_quic_tserver_tick(QUIC_TSERVER *srv)
193 {
194 ossl_quic_reactor_tick(ossl_quic_channel_get_reactor(srv->ch), 0);
195
196 if (ossl_quic_channel_is_active(srv->ch))
197 srv->connected = 1;
198
199 return 1;
200 }
201
202 int ossl_quic_tserver_is_connected(QUIC_TSERVER *srv)
203 {
204 return ossl_quic_channel_is_active(srv->ch);
205 }
206
207 /* Returns 1 if the server is in any terminating or terminated state */
208 int ossl_quic_tserver_is_term_any(const QUIC_TSERVER *srv)
209 {
210 return ossl_quic_channel_is_term_any(srv->ch);
211 }
212
213 const QUIC_TERMINATE_CAUSE *
214 ossl_quic_tserver_get_terminate_cause(const QUIC_TSERVER *srv)
215 {
216 return ossl_quic_channel_get_terminate_cause(srv->ch);
217 }
218
219 /* Returns 1 if the server is in a terminated state */
220 int ossl_quic_tserver_is_terminated(const QUIC_TSERVER *srv)
221 {
222 return ossl_quic_channel_is_terminated(srv->ch);
223 }
224
225 int ossl_quic_tserver_is_handshake_confirmed(const QUIC_TSERVER *srv)
226 {
227 return ossl_quic_channel_is_handshake_confirmed(srv->ch);
228 }
229
230 int ossl_quic_tserver_read(QUIC_TSERVER *srv,
231 uint64_t stream_id,
232 unsigned char *buf,
233 size_t buf_len,
234 size_t *bytes_read)
235 {
236 int is_fin = 0;
237 QUIC_STREAM *qs;
238
239 qs = ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv->ch),
240 stream_id);
241 if (qs == NULL) {
242 int is_client_init
243 = ((stream_id & QUIC_STREAM_INITIATOR_MASK)
244 == QUIC_STREAM_INITIATOR_CLIENT);
245
246 /*
247 * A client-initiated stream might spontaneously come into existence, so
248 * allow trying to read on a client-initiated stream before it exists,
249 * assuming the connection is still active.
250 * Otherwise, fail.
251 */
252 if (!is_client_init || !ossl_quic_channel_is_active(srv->ch))
253 return 0;
254
255 *bytes_read = 0;
256 return 1;
257 }
258
259 if (qs->recv_state == QUIC_RSTREAM_STATE_DATA_READ
260 || !ossl_quic_stream_has_recv_buffer(qs))
261 return 0;
262
263 if (!ossl_quic_rstream_read(qs->rstream, buf, buf_len,
264 bytes_read, &is_fin))
265 return 0;
266
267 if (*bytes_read > 0) {
268 /*
269 * We have read at least one byte from the stream. Inform stream-level
270 * RXFC of the retirement of controlled bytes. Update the active stream
271 * status (the RXFC may now want to emit a frame granting more credit to
272 * the peer).
273 */
274 OSSL_RTT_INFO rtt_info;
275
276 ossl_statm_get_rtt_info(ossl_quic_channel_get_statm(srv->ch), &rtt_info);
277
278 if (!ossl_quic_rxfc_on_retire(&qs->rxfc, *bytes_read,
279 rtt_info.smoothed_rtt))
280 return 0;
281 }
282
283 if (is_fin)
284 ossl_quic_stream_map_notify_totally_read(ossl_quic_channel_get_qsm(srv->ch),
285 qs);
286
287 if (*bytes_read > 0)
288 ossl_quic_stream_map_update_state(ossl_quic_channel_get_qsm(srv->ch), qs);
289
290 return 1;
291 }
292
293 int ossl_quic_tserver_has_read_ended(QUIC_TSERVER *srv, uint64_t stream_id)
294 {
295 QUIC_STREAM *qs;
296 unsigned char buf[1];
297 size_t bytes_read = 0;
298 int is_fin = 0;
299
300 qs = ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv->ch),
301 stream_id);
302
303 if (qs == NULL)
304 return 0;
305
306 if (qs->recv_state == QUIC_RSTREAM_STATE_DATA_READ)
307 return 1;
308
309 if (!ossl_quic_stream_has_recv_buffer(qs))
310 return 0;
311
312 /*
313 * If we do not have the DATA_READ, it is possible we should still return 1
314 * if there is a lone FIN (but no more data) remaining to be retired from
315 * the RSTREAM, for example because ossl_quic_tserver_read() has not been
316 * called since the FIN was received.
317 */
318 if (!ossl_quic_rstream_peek(qs->rstream, buf, sizeof(buf),
319 &bytes_read, &is_fin))
320 return 0;
321
322 if (is_fin && bytes_read == 0) {
323 /* If we have a FIN awaiting retirement and no data before it... */
324 /* Let RSTREAM know we've consumed this FIN. */
325 if (!ossl_quic_rstream_read(qs->rstream, buf, sizeof(buf),
326 &bytes_read, &is_fin))
327 return 0;
328
329 assert(is_fin && bytes_read == 0);
330 assert(qs->recv_state == QUIC_RSTREAM_STATE_DATA_RECVD);
331
332 ossl_quic_stream_map_notify_totally_read(ossl_quic_channel_get_qsm(srv->ch),
333 qs);
334 ossl_quic_stream_map_update_state(ossl_quic_channel_get_qsm(srv->ch), qs);
335 return 1;
336 }
337
338 return 0;
339 }
340
341 int ossl_quic_tserver_write(QUIC_TSERVER *srv,
342 uint64_t stream_id,
343 const unsigned char *buf,
344 size_t buf_len,
345 size_t *bytes_written)
346 {
347 QUIC_STREAM *qs;
348
349 if (!ossl_quic_channel_is_active(srv->ch))
350 return 0;
351
352 qs = ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv->ch),
353 stream_id);
354 if (qs == NULL || !ossl_quic_stream_has_send_buffer(qs))
355 return 0;
356
357 if (!ossl_quic_sstream_append(qs->sstream,
358 buf, buf_len, bytes_written))
359 return 0;
360
361 if (*bytes_written > 0)
362 /*
363 * We have appended at least one byte to the stream. Potentially mark
364 * the stream as active, depending on FC.
365 */
366 ossl_quic_stream_map_update_state(ossl_quic_channel_get_qsm(srv->ch), qs);
367
368 /* Try and send. */
369 ossl_quic_tserver_tick(srv);
370 return 1;
371 }
372
373 int ossl_quic_tserver_conclude(QUIC_TSERVER *srv, uint64_t stream_id)
374 {
375 QUIC_STREAM *qs;
376
377 if (!ossl_quic_channel_is_active(srv->ch))
378 return 0;
379
380 qs = ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv->ch),
381 stream_id);
382 if (qs == NULL || !ossl_quic_stream_has_send_buffer(qs))
383 return 0;
384
385 if (!ossl_quic_sstream_get_final_size(qs->sstream, NULL)) {
386 ossl_quic_sstream_fin(qs->sstream);
387 ossl_quic_stream_map_update_state(ossl_quic_channel_get_qsm(srv->ch), qs);
388 }
389
390 ossl_quic_tserver_tick(srv);
391 return 1;
392 }
393
394 int ossl_quic_tserver_stream_new(QUIC_TSERVER *srv,
395 int is_uni,
396 uint64_t *stream_id)
397 {
398 QUIC_STREAM *qs;
399
400 if (!ossl_quic_channel_is_active(srv->ch))
401 return 0;
402
403 if ((qs = ossl_quic_channel_new_stream_local(srv->ch, is_uni)) == NULL)
404 return 0;
405
406 *stream_id = qs->id;
407 return 1;
408 }
409
410 BIO *ossl_quic_tserver_get0_rbio(QUIC_TSERVER *srv)
411 {
412 return srv->args.net_rbio;
413 }
414
415 SSL_CTX *ossl_quic_tserver_get0_ssl_ctx(QUIC_TSERVER *srv)
416 {
417 return srv->ctx;
418 }
419
420 int ossl_quic_tserver_stream_has_peer_stop_sending(QUIC_TSERVER *srv,
421 uint64_t stream_id,
422 uint64_t *app_error_code)
423 {
424 QUIC_STREAM *qs;
425
426 qs = ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv->ch),
427 stream_id);
428 if (qs == NULL)
429 return 0;
430
431 if (qs->peer_stop_sending && app_error_code != NULL)
432 *app_error_code = qs->peer_stop_sending_aec;
433
434 return qs->peer_stop_sending;
435 }
436
437 int ossl_quic_tserver_stream_has_peer_reset_stream(QUIC_TSERVER *srv,
438 uint64_t stream_id,
439 uint64_t *app_error_code)
440 {
441 QUIC_STREAM *qs;
442
443 qs = ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv->ch),
444 stream_id);
445 if (qs == NULL)
446 return 0;
447
448 if (ossl_quic_stream_recv_is_reset(qs) && app_error_code != NULL)
449 *app_error_code = qs->peer_reset_stream_aec;
450
451 return ossl_quic_stream_recv_is_reset(qs);
452 }
453
454 int ossl_quic_tserver_set_new_local_cid(QUIC_TSERVER *srv,
455 const QUIC_CONN_ID *conn_id)
456 {
457 /* Replace existing local connection ID in the QUIC_CHANNEL */
458 return ossl_quic_channel_replace_local_cid(srv->ch, conn_id);
459 }
460
461 uint64_t ossl_quic_tserver_pop_incoming_stream(QUIC_TSERVER *srv)
462 {
463 QUIC_STREAM_MAP *qsm = ossl_quic_channel_get_qsm(srv->ch);
464 QUIC_STREAM *qs = ossl_quic_stream_map_peek_accept_queue(qsm);
465
466 if (qs == NULL)
467 return UINT64_MAX;
468
469 ossl_quic_stream_map_remove_from_accept_queue(qsm, qs, ossl_time_zero());
470
471 return qs->id;
472 }
473
474 int ossl_quic_tserver_is_stream_totally_acked(QUIC_TSERVER *srv,
475 uint64_t stream_id)
476 {
477 QUIC_STREAM *qs;
478
479 qs = ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv->ch),
480 stream_id);
481 if (qs == NULL)
482 return 1;
483
484 return ossl_quic_sstream_is_totally_acked(qs->sstream);
485 }
486
487 int ossl_quic_tserver_get_net_read_desired(QUIC_TSERVER *srv)
488 {
489 return ossl_quic_reactor_net_read_desired(
490 ossl_quic_channel_get_reactor(srv->ch));
491 }
492
493 int ossl_quic_tserver_get_net_write_desired(QUIC_TSERVER *srv)
494 {
495 return ossl_quic_reactor_net_write_desired(
496 ossl_quic_channel_get_reactor(srv->ch));
497 }
498
499 OSSL_TIME ossl_quic_tserver_get_deadline(QUIC_TSERVER *srv)
500 {
501 return ossl_quic_reactor_get_tick_deadline(
502 ossl_quic_channel_get_reactor(srv->ch));
503 }
504
505 int ossl_quic_tserver_shutdown(QUIC_TSERVER *srv, uint64_t app_error_code)
506 {
507 ossl_quic_channel_local_close(srv->ch, app_error_code, NULL);
508
509 /* TODO(QUIC): !SSL_SHUTDOWN_FLAG_NO_STREAM_FLUSH */
510
511 if (ossl_quic_channel_is_terminated(srv->ch))
512 return 1;
513
514 ossl_quic_reactor_tick(ossl_quic_channel_get_reactor(srv->ch), 0);
515
516 return ossl_quic_channel_is_terminated(srv->ch);
517 }
518
519 int ossl_quic_tserver_ping(QUIC_TSERVER *srv)
520 {
521 if (ossl_quic_channel_is_terminated(srv->ch))
522 return 0;
523
524 if (!ossl_quic_channel_ping(srv->ch))
525 return 0;
526
527 ossl_quic_reactor_tick(ossl_quic_channel_get_reactor(srv->ch), 0);
528 return 1;
529 }
530
531 QUIC_CHANNEL *ossl_quic_tserver_get_channel(QUIC_TSERVER *srv)
532 {
533 return srv->ch;
534 }
535
536 void ossl_quic_tserver_set_msg_callback(QUIC_TSERVER *srv,
537 void (*f)(int write_p, int version,
538 int content_type,
539 const void *buf, size_t len,
540 SSL *ssl, void *arg),
541 void *arg)
542 {
543 ossl_quic_channel_set_msg_callback(srv->ch, f, srv->ssl);
544 ossl_quic_channel_set_msg_callback_arg(srv->ch, arg);
545 SSL_set_msg_callback(srv->tls, f);
546 SSL_set_msg_callback_arg(srv->tls, arg);
547 }
548
549 int ossl_quic_tserver_new_ticket(QUIC_TSERVER *srv)
550 {
551 return SSL_new_session_ticket(srv->tls);
552 }
553
554 int ossl_quic_tserver_set_max_early_data(QUIC_TSERVER *srv,
555 uint32_t max_early_data)
556 {
557 return SSL_set_max_early_data(srv->tls, max_early_data);
558 }