tls.rs 9.6 KB
Newer Older
R
Ry Dahl 已提交
1
// Copyright 2018-2020 the Deno authors. All rights reserved. MIT license.
J
Jonathon Orsi 已提交
2
use super::dispatch_json::{Deserialize, JsonOp, Value};
3
use super::io::{StreamResource, StreamResourceHolder};
4
use crate::op_error::OpError;
J
Jonathon Orsi 已提交
5
use crate::resolve_addr::resolve_addr;
6
use crate::state::State;
7
use deno_core::*;
8
use futures::future::poll_fn;
B
Bartek Iwańczuk 已提交
9
use futures::future::FutureExt;
J
Jonathon Orsi 已提交
10
use std::convert::From;
B
Bartek Iwańczuk 已提交
11 12
use std::fs::File;
use std::io::BufReader;
13
use std::net::SocketAddr;
14
use std::path::Path;
J
Jonathon Orsi 已提交
15
use std::sync::Arc;
B
Bartek Iwańczuk 已提交
16 17
use std::task::Context;
use std::task::Poll;
B
Bartek Iwańczuk 已提交
18
use tokio::net::TcpListener;
J
Jonathon Orsi 已提交
19 20
use tokio::net::TcpStream;
use tokio_rustls::{rustls::ClientConfig, TlsConnector};
B
Bartek Iwańczuk 已提交
21 22 23 24 25 26 27
use tokio_rustls::{
  rustls::{
    internal::pemfile::{certs, pkcs8_private_keys, rsa_private_keys},
    Certificate, NoClientAuth, PrivateKey, ServerConfig,
  },
  TlsAcceptor,
};
J
Jonathon Orsi 已提交
28 29
use webpki::DNSNameRef;

30
pub fn init(i: &mut Isolate, s: &State) {
R
Ryan Dahl 已提交
31 32 33
  i.register_op("op_connect_tls", s.stateful_json_op(op_connect_tls));
  i.register_op("op_listen_tls", s.stateful_json_op(op_listen_tls));
  i.register_op("op_accept_tls", s.stateful_json_op(op_accept_tls));
B
Bartek Iwańczuk 已提交
34 35
}

J
Jonathon Orsi 已提交
36
#[derive(Deserialize)]
B
Bartek Iwańczuk 已提交
37
#[serde(rename_all = "camelCase")]
38
struct ConnectTLSArgs {
B
Bartek Iwańczuk 已提交
39
  transport: String,
J
Jonathon Orsi 已提交
40 41
  hostname: String,
  port: u16,
B
Bartek Iwańczuk 已提交
42
  cert_file: Option<String>,
43
}
J
Jonathon Orsi 已提交
44

45
pub fn op_connect_tls(
46
  state: &State,
J
Jonathon Orsi 已提交
47
  args: Value,
R
Ryan Dahl 已提交
48
  _zero_copy: Option<ZeroCopyBuf>,
49
) -> Result<JsonOp, OpError> {
50
  let args: ConnectTLSArgs = serde_json::from_value(args)?;
B
Bartek Iwańczuk 已提交
51
  let cert_file = args.cert_file.clone();
52
  let state_ = state.clone();
53
  state.check_net(&args.hostname, args.port)?;
B
Bartek Iwańczuk 已提交
54
  if let Some(path) = cert_file.clone() {
55
    state.check_read(Path::new(&path))?;
B
Bartek Iwańczuk 已提交
56
  }
J
Jonathon Orsi 已提交
57

58
  let mut domain = args.hostname.clone();
J
Jonathon Orsi 已提交
59 60 61 62
  if domain.is_empty() {
    domain.push_str("localhost");
  }

B
Bartek Iwańczuk 已提交
63
  let op = async move {
64
    let addr = resolve_addr(&args.hostname, args.port)?;
B
Bartek Iwańczuk 已提交
65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80
    let tcp_stream = TcpStream::connect(&addr).await?;
    let local_addr = tcp_stream.local_addr()?;
    let remote_addr = tcp_stream.peer_addr()?;
    let mut config = ClientConfig::new();
    config
      .root_store
      .add_server_trust_anchors(&webpki_roots::TLS_SERVER_ROOTS);
    if let Some(path) = cert_file {
      let key_file = File::open(path)?;
      let reader = &mut BufReader::new(key_file);
      config.root_store.add_pem_file(reader).unwrap();
    }
    let tls_connector = TlsConnector::from(Arc::new(config));
    let dnsname =
      DNSNameRef::try_from_ascii_str(&domain).expect("Invalid DNS lookup");
    let tls_stream = tls_connector.connect(dnsname, tcp_stream).await?;
81 82
    let mut state = state_.borrow_mut();
    let rid = state.resource_table.add(
B
Bartek Iwańczuk 已提交
83
      "clientTlsStream",
84 85 86
      Box::new(StreamResourceHolder::new(StreamResource::ClientTlsStream(
        Box::new(tls_stream),
      ))),
B
Bartek Iwańczuk 已提交
87 88 89
    );
    Ok(json!({
        "rid": rid,
B
Bartek Iwańczuk 已提交
90 91 92 93 94 95 96 97 98 99
        "localAddr": {
          "hostname": local_addr.ip().to_string(),
          "port": local_addr.port(),
          "transport": args.transport,
        },
        "remoteAddr": {
          "hostname": remote_addr.ip().to_string(),
          "port": remote_addr.port(),
          "transport": args.transport,
        }
B
Bartek Iwańczuk 已提交
100 101
    }))
  };
J
Jonathon Orsi 已提交
102

103
  Ok(JsonOp::Async(op.boxed_local()))
J
Jonathon Orsi 已提交
104
}
B
Bartek Iwańczuk 已提交
105

106
fn load_certs(path: &str) -> Result<Vec<Certificate>, OpError> {
B
Bartek Iwańczuk 已提交
107 108 109
  let cert_file = File::open(path)?;
  let reader = &mut BufReader::new(cert_file);

110 111
  let certs = certs(reader)
    .map_err(|_| OpError::other("Unable to decode certificate".to_string()))?;
B
Bartek Iwańczuk 已提交
112 113

  if certs.is_empty() {
114 115
    let e = OpError::other("No certificates found in cert file".to_string());
    return Err(e);
B
Bartek Iwańczuk 已提交
116 117 118 119 120
  }

  Ok(certs)
}

121 122
fn key_decode_err() -> OpError {
  OpError::other("Unable to decode key".to_string())
B
Bartek Iwańczuk 已提交
123 124
}

125 126
fn key_not_found_err() -> OpError {
  OpError::other("No keys found in key file".to_string())
B
Bartek Iwańczuk 已提交
127 128 129
}

/// Starts with -----BEGIN RSA PRIVATE KEY-----
130
fn load_rsa_keys(path: &str) -> Result<Vec<PrivateKey>, OpError> {
B
Bartek Iwańczuk 已提交
131 132 133 134 135 136 137
  let key_file = File::open(path)?;
  let reader = &mut BufReader::new(key_file);
  let keys = rsa_private_keys(reader).map_err(|_| key_decode_err())?;
  Ok(keys)
}

/// Starts with -----BEGIN PRIVATE KEY-----
138
fn load_pkcs8_keys(path: &str) -> Result<Vec<PrivateKey>, OpError> {
B
Bartek Iwańczuk 已提交
139 140 141 142 143 144
  let key_file = File::open(path)?;
  let reader = &mut BufReader::new(key_file);
  let keys = pkcs8_private_keys(reader).map_err(|_| key_decode_err())?;
  Ok(keys)
}

145
fn load_keys(path: &str) -> Result<Vec<PrivateKey>, OpError> {
B
Bartek Iwańczuk 已提交
146 147 148 149 150 151 152 153
  let path = path.to_string();
  let mut keys = load_rsa_keys(&path)?;

  if keys.is_empty() {
    keys = load_pkcs8_keys(&path)?;
  }

  if keys.is_empty() {
154
    return Err(key_not_found_err());
B
Bartek Iwańczuk 已提交
155 156 157 158 159
  }

  Ok(keys)
}

160 161
#[allow(dead_code)]
pub struct TlsListenerResource {
B
Bartek Iwańczuk 已提交
162
  listener: TcpListener,
163
  tls_acceptor: TlsAcceptor,
B
Bartek Iwańczuk 已提交
164
  waker: Option<futures::task::AtomicWaker>,
165 166 167 168 169
  local_addr: SocketAddr,
}

impl Drop for TlsListenerResource {
  fn drop(&mut self) {
B
Bartek Iwańczuk 已提交
170
    self.wake_task();
171 172 173 174 175 176 177 178
  }
}

impl TlsListenerResource {
  /// Track the current task so future awaiting for connection
  /// can be notified when listener is closed.
  ///
  /// Throws an error if another task is already tracked.
179
  pub fn track_task(&mut self, cx: &Context) -> Result<(), OpError> {
180 181 182 183
    // Currently, we only allow tracking a single accept task for a listener.
    // This might be changed in the future with multiple workers.
    // Caveat: TcpListener by itself also only tracks an accept task at a time.
    // See https://github.com/tokio-rs/tokio/issues/846#issuecomment-454208883
B
Bartek Iwańczuk 已提交
184
    if self.waker.is_some() {
185
      return Err(OpError::other("Another accept task is ongoing".to_string()));
186 187
    }

B
Bartek Iwańczuk 已提交
188 189 190
    let waker = futures::task::AtomicWaker::new();
    waker.register(cx.waker());
    self.waker.replace(waker);
191 192 193 194
    Ok(())
  }

  /// Notifies a task when listener is closed so accept future can resolve.
B
Bartek Iwańczuk 已提交
195 196 197
  pub fn wake_task(&mut self) {
    if let Some(waker) = self.waker.as_ref() {
      waker.wake();
198 199 200 201 202 203
    }
  }

  /// Stop tracking a task.
  /// Happens when the task is done and thus no further tracking is needed.
  pub fn untrack_task(&mut self) {
B
Bartek Iwańczuk 已提交
204 205
    if self.waker.is_some() {
      self.waker.take();
206 207 208 209
    }
  }
}

B
Bartek Iwańczuk 已提交
210 211 212 213 214 215 216 217 218 219 220
#[derive(Deserialize)]
#[serde(rename_all = "camelCase")]
struct ListenTlsArgs {
  transport: String,
  hostname: String,
  port: u16,
  cert_file: String,
  key_file: String,
}

fn op_listen_tls(
221
  state: &State,
B
Bartek Iwańczuk 已提交
222
  args: Value,
R
Ryan Dahl 已提交
223
  _zero_copy: Option<ZeroCopyBuf>,
224
) -> Result<JsonOp, OpError> {
B
Bartek Iwańczuk 已提交
225 226 227 228 229 230
  let args: ListenTlsArgs = serde_json::from_value(args)?;
  assert_eq!(args.transport, "tcp");

  let cert_file = args.cert_file;
  let key_file = args.key_file;

231
  state.check_net(&args.hostname, args.port)?;
232 233
  state.check_read(Path::new(&cert_file))?;
  state.check_read(Path::new(&key_file))?;
B
Bartek Iwańczuk 已提交
234 235 236 237 238

  let mut config = ServerConfig::new(NoClientAuth::new());
  config
    .set_single_cert(load_certs(&cert_file)?, load_keys(&key_file)?.remove(0))
    .expect("invalid key or certificate");
239
  let tls_acceptor = TlsAcceptor::from(Arc::new(config));
240
  let addr = resolve_addr(&args.hostname, args.port)?;
B
Bartek Iwańczuk 已提交
241
  let listener = futures::executor::block_on(TcpListener::bind(&addr))?;
B
Bartek Iwańczuk 已提交
242
  let local_addr = listener.local_addr()?;
243
  let tls_listener_resource = TlsListenerResource {
B
Bartek Iwańczuk 已提交
244
    listener,
245
    tls_acceptor,
B
Bartek Iwańczuk 已提交
246
    waker: None,
247 248
    local_addr,
  };
249 250 251 252
  let mut state = state.borrow_mut();
  let rid = state
    .resource_table
    .add("tlsListener", Box::new(tls_listener_resource));
B
Bartek Iwańczuk 已提交
253 254

  Ok(JsonOp::Sync(json!({
255
    "rid": rid,
B
Bartek Iwańczuk 已提交
256 257 258 259 260
    "localAddr": {
      "hostname": local_addr.ip().to_string(),
      "port": local_addr.port(),
      "transport": args.transport,
    },
B
Bartek Iwańczuk 已提交
261 262 263 264 265 266 267 268 269
  })))
}

#[derive(Deserialize)]
struct AcceptTlsArgs {
  rid: i32,
}

fn op_accept_tls(
270
  state: &State,
B
Bartek Iwańczuk 已提交
271
  args: Value,
R
Ryan Dahl 已提交
272
  _zero_copy: Option<ZeroCopyBuf>,
273
) -> Result<JsonOp, OpError> {
B
Bartek Iwańczuk 已提交
274
  let args: AcceptTlsArgs = serde_json::from_value(args)?;
275
  let rid = args.rid as u32;
B
Bartek Iwańczuk 已提交
276 277
  let state = state.clone();
  let op = async move {
278 279 280 281 282
    let accept_fut = poll_fn(|cx| {
      let resource_table = &mut state.borrow_mut().resource_table;
      let listener_resource = resource_table
        .get_mut::<TlsListenerResource>(rid)
        .ok_or_else(|| {
283
          OpError::bad_resource("Listener has been closed".to_string())
284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300
        })?;
      let listener = &mut listener_resource.listener;
      match listener.poll_accept(cx).map_err(OpError::from) {
        Poll::Ready(Ok((stream, addr))) => {
          listener_resource.untrack_task();
          Poll::Ready(Ok((stream, addr)))
        }
        Poll::Pending => {
          listener_resource.track_task(cx)?;
          Poll::Pending
        }
        Poll::Ready(Err(e)) => {
          listener_resource.untrack_task();
          Poll::Ready(Err(e))
        }
      }
    });
R
Ryan Dahl 已提交
301
    let (tcp_stream, _socket_addr) = accept_fut.await?;
B
Bartek Iwańczuk 已提交
302 303 304
    let local_addr = tcp_stream.local_addr()?;
    let remote_addr = tcp_stream.peer_addr()?;
    let tls_acceptor = {
305 306 307
      let state = state.borrow();
      let resource = state
        .resource_table
308
        .get::<TlsListenerResource>(rid)
309
        .ok_or_else(OpError::bad_resource_id)
310
        .expect("Can't find tls listener");
B
Bartek Iwańczuk 已提交
311 312 313 314
      resource.tls_acceptor.clone()
    };
    let tls_stream = tls_acceptor.accept(tcp_stream).await?;
    let rid = {
315 316
      let mut state = state.borrow_mut();
      state.resource_table.add(
B
Bartek Iwańczuk 已提交
317
        "serverTlsStream",
318 319 320
        Box::new(StreamResourceHolder::new(StreamResource::ServerTlsStream(
          Box::new(tls_stream),
        ))),
B
Bartek Iwańczuk 已提交
321
      )
B
Bartek Iwańczuk 已提交
322 323 324
    };
    Ok(json!({
      "rid": rid,
B
Bartek Iwańczuk 已提交
325 326 327 328 329 330 331 332 333 334
      "localAddr": {
        "transport": "tcp",
        "hostname": local_addr.ip().to_string(),
        "port": local_addr.port()
      },
      "remoteAddr": {
        "transport": "tcp",
        "hostname": remote_addr.ip().to_string(),
        "port": remote_addr.port()
      }
B
Bartek Iwańczuk 已提交
335 336
    }))
  };
B
Bartek Iwańczuk 已提交
337

338
  Ok(JsonOp::Async(op.boxed_local()))
B
Bartek Iwańczuk 已提交
339
}