2 * Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
10 #include "internal/quic_tserver.h"
11 #include "internal/quic_channel.h"
12 #include "internal/quic_statm.h"
13 #include "internal/common.h"
14 #include "internal/time.h"
15 #include "quic_local.h"
18 * QUIC Test Server Module
19 * =======================
21 struct quic_tserver_st
{
22 QUIC_TSERVER_ARGS args
;
24 /* Dummy SSL object for this QUIC connection for use by msg_callback */
28 * The QUIC channel providing the core QUIC connection implementation.
32 /* The mutex we give to the QUIC channel. */
35 /* SSL_CTX for creating the underlying TLS connection */
38 /* SSL for the underlying TLS connection */
41 /* The current peer L4 address. AF_UNSPEC if we do not have a peer yet. */
42 BIO_ADDR cur_peer_addr
;
44 /* Are we connected to a peer? */
45 unsigned int connected
: 1;
48 static int alpn_select_cb(SSL
*ssl
, const unsigned char **out
,
49 unsigned char *outlen
, const unsigned char *in
,
50 unsigned int inlen
, void *arg
)
52 QUIC_TSERVER
*srv
= arg
;
53 static const unsigned char alpndeflt
[] = {
54 8, 'o', 's', 's', 'l', 't', 'e', 's', 't'
56 static const unsigned char *alpn
;
59 if (srv
->args
.alpn
== NULL
) {
61 alpnlen
= sizeof(alpn
);
63 alpn
= srv
->args
.alpn
;
64 alpnlen
= srv
->args
.alpnlen
;
67 if (SSL_select_next_proto((unsigned char **)out
, outlen
, alpn
, alpnlen
,
68 in
, inlen
) != OPENSSL_NPN_NEGOTIATED
)
69 return SSL_TLSEXT_ERR_ALERT_FATAL
;
71 return SSL_TLSEXT_ERR_OK
;
74 QUIC_TSERVER
*ossl_quic_tserver_new(const QUIC_TSERVER_ARGS
*args
,
75 const char *certfile
, const char *keyfile
)
77 QUIC_TSERVER
*srv
= NULL
;
78 QUIC_CHANNEL_ARGS ch_args
= {0};
79 QUIC_CONNECTION
*qc
= NULL
;
81 if (args
->net_rbio
== NULL
|| args
->net_wbio
== NULL
)
84 if ((srv
= OPENSSL_zalloc(sizeof(*srv
))) == NULL
)
89 #if defined(OPENSSL_THREADS)
90 if ((srv
->mutex
= ossl_crypto_mutex_new()) == NULL
)
94 if (args
->ctx
!= NULL
)
97 srv
->ctx
= SSL_CTX_new_ex(srv
->args
.libctx
, srv
->args
.propq
,
102 if (SSL_CTX_use_certificate_file(srv
->ctx
, certfile
, SSL_FILETYPE_PEM
) <= 0)
105 if (SSL_CTX_use_PrivateKey_file(srv
->ctx
, keyfile
, SSL_FILETYPE_PEM
) <= 0)
108 SSL_CTX_set_alpn_select_cb(srv
->ctx
, alpn_select_cb
, srv
);
110 srv
->tls
= SSL_new(srv
->ctx
);
111 if (srv
->tls
== NULL
)
114 ch_args
.libctx
= srv
->args
.libctx
;
115 ch_args
.propq
= srv
->args
.propq
;
116 ch_args
.tls
= srv
->tls
;
117 ch_args
.mutex
= srv
->mutex
;
118 ch_args
.is_server
= 1;
119 ch_args
.now_cb
= srv
->args
.now_cb
;
120 ch_args
.now_cb_arg
= srv
->args
.now_cb_arg
;
122 if ((srv
->ch
= ossl_quic_channel_new(&ch_args
)) == NULL
)
125 if (!ossl_quic_channel_set_net_rbio(srv
->ch
, srv
->args
.net_rbio
)
126 || !ossl_quic_channel_set_net_wbio(srv
->ch
, srv
->args
.net_wbio
))
129 qc
= OPENSSL_zalloc(sizeof(*qc
));
132 srv
->ssl
= (SSL
*)qc
;
134 srv
->ssl
->type
= SSL_TYPE_QUIC_CONNECTION
;
140 if (args
->ctx
== NULL
)
141 SSL_CTX_free(srv
->ctx
);
143 ossl_quic_channel_free(srv
->ch
);
144 #if defined(OPENSSL_THREADS)
145 ossl_crypto_mutex_free(&srv
->mutex
);
154 void ossl_quic_tserver_free(QUIC_TSERVER
*srv
)
159 ossl_quic_channel_free(srv
->ch
);
160 BIO_free(srv
->args
.net_rbio
);
161 BIO_free(srv
->args
.net_wbio
);
162 OPENSSL_free(srv
->ssl
);
164 SSL_CTX_free(srv
->ctx
);
165 #if defined(OPENSSL_THREADS)
166 ossl_crypto_mutex_free(&srv
->mutex
);
171 /* Set mutator callbacks for test framework support */
172 int ossl_quic_tserver_set_plain_packet_mutator(QUIC_TSERVER
*srv
,
173 ossl_mutate_packet_cb mutatecb
,
174 ossl_finish_mutate_cb finishmutatecb
,
177 return ossl_quic_channel_set_mutator(srv
->ch
, mutatecb
, finishmutatecb
,
181 int ossl_quic_tserver_set_handshake_mutator(QUIC_TSERVER
*srv
,
182 ossl_statem_mutate_handshake_cb mutate_handshake_cb
,
183 ossl_statem_finish_mutate_handshake_cb finish_mutate_handshake_cb
,
186 return ossl_statem_set_mutator(ossl_quic_channel_get0_ssl(srv
->ch
),
188 finish_mutate_handshake_cb
,
192 int ossl_quic_tserver_tick(QUIC_TSERVER
*srv
)
194 ossl_quic_reactor_tick(ossl_quic_channel_get_reactor(srv
->ch
), 0);
196 if (ossl_quic_channel_is_active(srv
->ch
))
202 int ossl_quic_tserver_is_connected(QUIC_TSERVER
*srv
)
204 return ossl_quic_channel_is_active(srv
->ch
);
207 /* Returns 1 if the server is in any terminating or terminated state */
208 int ossl_quic_tserver_is_term_any(const QUIC_TSERVER
*srv
)
210 return ossl_quic_channel_is_term_any(srv
->ch
);
213 const QUIC_TERMINATE_CAUSE
*
214 ossl_quic_tserver_get_terminate_cause(const QUIC_TSERVER
*srv
)
216 return ossl_quic_channel_get_terminate_cause(srv
->ch
);
219 /* Returns 1 if the server is in a terminated state */
220 int ossl_quic_tserver_is_terminated(const QUIC_TSERVER
*srv
)
222 return ossl_quic_channel_is_terminated(srv
->ch
);
225 int ossl_quic_tserver_is_handshake_confirmed(const QUIC_TSERVER
*srv
)
227 return ossl_quic_channel_is_handshake_confirmed(srv
->ch
);
230 int ossl_quic_tserver_read(QUIC_TSERVER
*srv
,
239 qs
= ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv
->ch
),
243 = ((stream_id
& QUIC_STREAM_INITIATOR_MASK
)
244 == QUIC_STREAM_INITIATOR_CLIENT
);
247 * A client-initiated stream might spontaneously come into existence, so
248 * allow trying to read on a client-initiated stream before it exists,
249 * assuming the connection is still active.
252 if (!is_client_init
|| !ossl_quic_channel_is_active(srv
->ch
))
259 if (qs
->recv_state
== QUIC_RSTREAM_STATE_DATA_READ
260 || !ossl_quic_stream_has_recv_buffer(qs
))
263 if (!ossl_quic_rstream_read(qs
->rstream
, buf
, buf_len
,
264 bytes_read
, &is_fin
))
267 if (*bytes_read
> 0) {
269 * We have read at least one byte from the stream. Inform stream-level
270 * RXFC of the retirement of controlled bytes. Update the active stream
271 * status (the RXFC may now want to emit a frame granting more credit to
274 OSSL_RTT_INFO rtt_info
;
276 ossl_statm_get_rtt_info(ossl_quic_channel_get_statm(srv
->ch
), &rtt_info
);
278 if (!ossl_quic_rxfc_on_retire(&qs
->rxfc
, *bytes_read
,
279 rtt_info
.smoothed_rtt
))
284 ossl_quic_stream_map_notify_totally_read(ossl_quic_channel_get_qsm(srv
->ch
),
288 ossl_quic_stream_map_update_state(ossl_quic_channel_get_qsm(srv
->ch
), qs
);
293 int ossl_quic_tserver_has_read_ended(QUIC_TSERVER
*srv
, uint64_t stream_id
)
296 unsigned char buf
[1];
297 size_t bytes_read
= 0;
300 qs
= ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv
->ch
),
306 if (qs
->recv_state
== QUIC_RSTREAM_STATE_DATA_READ
)
309 if (!ossl_quic_stream_has_recv_buffer(qs
))
313 * If we do not have the DATA_READ, it is possible we should still return 1
314 * if there is a lone FIN (but no more data) remaining to be retired from
315 * the RSTREAM, for example because ossl_quic_tserver_read() has not been
316 * called since the FIN was received.
318 if (!ossl_quic_rstream_peek(qs
->rstream
, buf
, sizeof(buf
),
319 &bytes_read
, &is_fin
))
322 if (is_fin
&& bytes_read
== 0) {
323 /* If we have a FIN awaiting retirement and no data before it... */
324 /* Let RSTREAM know we've consumed this FIN. */
325 if (!ossl_quic_rstream_read(qs
->rstream
, buf
, sizeof(buf
),
326 &bytes_read
, &is_fin
))
329 assert(is_fin
&& bytes_read
== 0);
330 assert(qs
->recv_state
== QUIC_RSTREAM_STATE_DATA_RECVD
);
332 ossl_quic_stream_map_notify_totally_read(ossl_quic_channel_get_qsm(srv
->ch
),
334 ossl_quic_stream_map_update_state(ossl_quic_channel_get_qsm(srv
->ch
), qs
);
341 int ossl_quic_tserver_write(QUIC_TSERVER
*srv
,
343 const unsigned char *buf
,
345 size_t *bytes_written
)
349 if (!ossl_quic_channel_is_active(srv
->ch
))
352 qs
= ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv
->ch
),
354 if (qs
== NULL
|| !ossl_quic_stream_has_send_buffer(qs
))
357 if (!ossl_quic_sstream_append(qs
->sstream
,
358 buf
, buf_len
, bytes_written
))
361 if (*bytes_written
> 0)
363 * We have appended at least one byte to the stream. Potentially mark
364 * the stream as active, depending on FC.
366 ossl_quic_stream_map_update_state(ossl_quic_channel_get_qsm(srv
->ch
), qs
);
369 ossl_quic_tserver_tick(srv
);
373 int ossl_quic_tserver_conclude(QUIC_TSERVER
*srv
, uint64_t stream_id
)
377 if (!ossl_quic_channel_is_active(srv
->ch
))
380 qs
= ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv
->ch
),
382 if (qs
== NULL
|| !ossl_quic_stream_has_send_buffer(qs
))
385 if (!ossl_quic_sstream_get_final_size(qs
->sstream
, NULL
)) {
386 ossl_quic_sstream_fin(qs
->sstream
);
387 ossl_quic_stream_map_update_state(ossl_quic_channel_get_qsm(srv
->ch
), qs
);
390 ossl_quic_tserver_tick(srv
);
394 int ossl_quic_tserver_stream_new(QUIC_TSERVER
*srv
,
400 if (!ossl_quic_channel_is_active(srv
->ch
))
403 if ((qs
= ossl_quic_channel_new_stream_local(srv
->ch
, is_uni
)) == NULL
)
410 BIO
*ossl_quic_tserver_get0_rbio(QUIC_TSERVER
*srv
)
412 return srv
->args
.net_rbio
;
415 SSL_CTX
*ossl_quic_tserver_get0_ssl_ctx(QUIC_TSERVER
*srv
)
420 int ossl_quic_tserver_stream_has_peer_stop_sending(QUIC_TSERVER
*srv
,
422 uint64_t *app_error_code
)
426 qs
= ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv
->ch
),
431 if (qs
->peer_stop_sending
&& app_error_code
!= NULL
)
432 *app_error_code
= qs
->peer_stop_sending_aec
;
434 return qs
->peer_stop_sending
;
437 int ossl_quic_tserver_stream_has_peer_reset_stream(QUIC_TSERVER
*srv
,
439 uint64_t *app_error_code
)
443 qs
= ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv
->ch
),
448 if (ossl_quic_stream_recv_is_reset(qs
) && app_error_code
!= NULL
)
449 *app_error_code
= qs
->peer_reset_stream_aec
;
451 return ossl_quic_stream_recv_is_reset(qs
);
454 int ossl_quic_tserver_set_new_local_cid(QUIC_TSERVER
*srv
,
455 const QUIC_CONN_ID
*conn_id
)
457 /* Replace existing local connection ID in the QUIC_CHANNEL */
458 return ossl_quic_channel_replace_local_cid(srv
->ch
, conn_id
);
461 uint64_t ossl_quic_tserver_pop_incoming_stream(QUIC_TSERVER
*srv
)
463 QUIC_STREAM_MAP
*qsm
= ossl_quic_channel_get_qsm(srv
->ch
);
464 QUIC_STREAM
*qs
= ossl_quic_stream_map_peek_accept_queue(qsm
);
469 ossl_quic_stream_map_remove_from_accept_queue(qsm
, qs
, ossl_time_zero());
474 int ossl_quic_tserver_is_stream_totally_acked(QUIC_TSERVER
*srv
,
479 qs
= ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(srv
->ch
),
484 return ossl_quic_sstream_is_totally_acked(qs
->sstream
);
487 int ossl_quic_tserver_get_net_read_desired(QUIC_TSERVER
*srv
)
489 return ossl_quic_reactor_net_read_desired(
490 ossl_quic_channel_get_reactor(srv
->ch
));
493 int ossl_quic_tserver_get_net_write_desired(QUIC_TSERVER
*srv
)
495 return ossl_quic_reactor_net_write_desired(
496 ossl_quic_channel_get_reactor(srv
->ch
));
499 OSSL_TIME
ossl_quic_tserver_get_deadline(QUIC_TSERVER
*srv
)
501 return ossl_quic_reactor_get_tick_deadline(
502 ossl_quic_channel_get_reactor(srv
->ch
));
505 int ossl_quic_tserver_shutdown(QUIC_TSERVER
*srv
, uint64_t app_error_code
)
507 ossl_quic_channel_local_close(srv
->ch
, app_error_code
, NULL
);
509 /* TODO(QUIC): !SSL_SHUTDOWN_FLAG_NO_STREAM_FLUSH */
511 if (ossl_quic_channel_is_terminated(srv
->ch
))
514 ossl_quic_reactor_tick(ossl_quic_channel_get_reactor(srv
->ch
), 0);
516 return ossl_quic_channel_is_terminated(srv
->ch
);
519 int ossl_quic_tserver_ping(QUIC_TSERVER
*srv
)
521 if (ossl_quic_channel_is_terminated(srv
->ch
))
524 if (!ossl_quic_channel_ping(srv
->ch
))
527 ossl_quic_reactor_tick(ossl_quic_channel_get_reactor(srv
->ch
), 0);
531 QUIC_CHANNEL
*ossl_quic_tserver_get_channel(QUIC_TSERVER
*srv
)
536 void ossl_quic_tserver_set_msg_callback(QUIC_TSERVER
*srv
,
537 void (*f
)(int write_p
, int version
,
539 const void *buf
, size_t len
,
540 SSL
*ssl
, void *arg
),
543 ossl_quic_channel_set_msg_callback(srv
->ch
, f
, srv
->ssl
);
544 ossl_quic_channel_set_msg_callback_arg(srv
->ch
, arg
);
545 SSL_set_msg_callback(srv
->tls
, f
);
546 SSL_set_msg_callback_arg(srv
->tls
, arg
);
549 int ossl_quic_tserver_new_ticket(QUIC_TSERVER
*srv
)
551 return SSL_new_session_ticket(srv
->tls
);
554 int ossl_quic_tserver_set_max_early_data(QUIC_TSERVER
*srv
,
555 uint32_t max_early_data
)
557 return SSL_set_max_early_data(srv
->tls
, max_early_data
);