chiark / gitweb /
replace plaintext secret transmission with time-limited hmac-based bearer tokens
[hippotat.git] / hippotat
1 #!/usr/bin/python3
2 #
3 # Hippotat - Asinine IP Over HTTP program
4 # ./hippotat - client main program
5 #
6 # Copyright 2017 Ian Jackson
7 #
8 # GPLv3+
9 #
10 #    This program is free software: you can redistribute it and/or modify
11 #    it under the terms of the GNU General Public License as published by
12 #    the Free Software Foundation, either version 3 of the License, or
13 #    (at your option) any later version.
14 #
15 #    This program is distributed in the hope that it will be useful,
16 #    but WITHOUT ANY WARRANTY; without even the implied warranty of
17 #    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
18 #    GNU General Public License for more details.
19 #
20 #    You should have received a copy of the GNU General Public License
21 #    along with this program, in the file GPLv3.  If not,
22 #    see <http://www.gnu.org/licenses/>.
23
24 #@ import sys; sys.path.append('@PYBUILD_INSTALL_DIR@')
25 from hippotatlib import *
26
27 import twisted.web
28 import twisted.web.client
29
30 import io
31
32 class GeneralResponseConsumer(twisted.internet.protocol.Protocol):
33   def __init__(self, cl, req, desc):
34     self._cl = cl
35     self._req = req
36     self._desc = desc
37
38   def _log(self, dflag, msg, **kwargs):
39     self._cl.log(dflag, '%s: %s' % (self._desc, msg), idof=self._req, **kwargs)
40
41   def connectionMade(self):
42     self._log(DBG.HTTP_CTRL, 'connectionMade')
43
44 class ResponseConsumer(GeneralResponseConsumer):
45   def __init__(self, cl, req):
46     super().__init__(cl, req, 'RC')
47     ssddesc = '[%s] %s' % (id(req), self._desc)
48     self._ssd = SlipStreamDecoder(ssddesc, partial(queue_inbound, cl.ipif))
49     self._log(DBG.HTTP_CTRL, '__init__')
50
51   def dataReceived(self, data):
52     self._log(DBG.HTTP, 'dataReceived', d=data)
53     try:
54       self._ssd.inputdata(data)
55     except Exception as e:
56       self._handleexception()
57
58   def connectionLost(self, reason):
59     self._log(DBG.HTTP_CTRL, 'connectionLost ' + str(reason))
60     if not reason.check(twisted.web.client.ResponseDone):
61       self.latefailure()
62       return
63     try:
64       self._log(DBG.HTTP, 'ResponseDone')
65       self._ssd.flush()
66       self._cl.req_fin(self._req)
67     except Exception as e:
68       self._handleexception()
69     self._cl.report_running()
70
71   def _handleexception(self):
72     self._latefailure(traceback.format_exc())
73
74   def _latefailure(self, reason):
75     self._log(DBG.HTTP_CTRL, '_latefailure ' + str(reason))
76     self._cl.req_err(self._req, reason)
77
78 class ErrorResponseConsumer(GeneralResponseConsumer):
79   def __init__(self, cl, req, resp):
80     super().__init__(cl, req, 'ERROR-RC')
81     self._resp = resp
82     self._m = b''
83     try:
84       self._phrase = resp.phrase.decode('utf-8')
85     except Exception:
86       self._phrase = repr(resp.phrase)
87     self._log(DBG.HTTP_CTRL, '__init__ %d %s' % (resp.code, self._phrase))
88
89   def dataReceived(self, data):
90     self._log(DBG.HTTP_CTRL, 'dataReceived ' + repr(data))
91     self._m += data
92
93   def connectionLost(self, reason):
94     try:
95       mbody = self._m.decode('utf-8')
96     except Exception:
97       mbody = repr(self._m)
98     if not reason.check(twisted.web.client.ResponseDone):
99       mbody += ' || ' + str(reason)
100     self._cl.req_err(self._req,
101             "FAILED %d %s | %s"
102             % (self._resp.code, self._phrase, mbody))
103
104 class Client():
105   def __init__(cl, c,ss,cs):
106     cl.c = c
107     cl.outstanding = { }
108     cl.desc = '[%s %s] ' % (ss,cs)
109     cl.running_reported = False
110     cl.log_info('setting up')
111
112   def log_info(cl, msg):
113     log.info(cl.desc + msg, dflag=False)
114
115   def report_running(cl):
116     if not cl.running_reported:
117       cl.log_info('running OK')
118       cl.running_reported = True
119
120   def log(cl, dflag, msg, **kwargs):
121     log_debug(dflag, cl.desc + msg, **kwargs)
122
123   def log_outstanding(cl):
124     cl.log(DBG.CTRL_DUMP, 'OS %s' % cl.outstanding)
125
126   def start(cl):
127     cl.queue = PacketQueue('up', cl.c.max_queue_time)
128     cl.agent = twisted.web.client.Agent(
129       reactor, connectTimeout = cl.c.http_timeout)
130
131   def outbound(cl, packet, saddr, daddr):
132     #print('OUT ', saddr, daddr, repr(packet))
133     cl.queue.append(packet)
134     cl.check_outbound()
135
136   def req_ok(cl, req, resp):
137     cl.log(DBG.HTTP_CTRL,
138             'req_ok %d %s %s' % (resp.code, repr(resp.phrase), str(resp)),
139             idof=req)
140     if resp.code == 200:
141       rc = ResponseConsumer(cl, req)
142     else:
143       rc = ErrorResponseConsumer(cl, req, resp)
144
145     resp.deliverBody(rc)
146     # now rc is responsible for calling req_fin
147
148   def req_err(cl, req, err):
149     # called when the Deferred fails, or (if it completes),
150     # later, by ResponsConsumer or ErrorResponsConsumer
151     try:
152       cl.log(DBG.HTTP_CTRL, 'req_err ' + str(err), idof=req)
153       if isinstance(err, twisted.python.failure.Failure):
154         err = err.getTraceback()
155       print('%s[%#x] %s' % (cl.desc, id(req), err.strip('\n').replace('\n',' / ')),
156             file=sys.stderr)
157       if not isinstance(cl.outstanding[req], int):
158         raise RuntimeError('[%#x] previously %s' %
159                            (id(req), cl.outstanding[req]))
160       cl.outstanding[req] = err
161       cl.log_outstanding()
162       reactor.callLater(cl.c.http_retry, partial(cl.req_fin, req))
163     except Exception as e:
164       crash(traceback.format_exc() + '\n----- handling -----\n' + err)
165
166   def req_fin(cl, req):
167     del cl.outstanding[req]
168     cl.log(DBG.HTTP_CTRL, 'req_fin OS=%d' % len(cl.outstanding), idof=req)
169     cl.check_outbound()
170
171   def check_outbound(cl):
172     while True:
173       if len(cl.outstanding) >= cl.c.max_outstanding:
174         break
175
176       if (not cl.queue.nonempty() and
177           len(cl.outstanding) >= cl.c.target_requests_outstanding):
178         break
179
180       d = b''
181       def moredata(s): nonlocal d; d += s
182       cl.queue.process((lambda: len(d)),
183                     moredata,
184                     cl.c.max_batch_up)
185
186       d = mime_translate(d)
187
188       token = authtoken_make(cl.c.secret)
189
190       crlf = b'\r\n'
191       lf   =   b'\n'
192       mime = (b'--b'                                        + crlf +
193               b'Content-Type: text/plain; charset="utf-8"'  + crlf +
194               b'Content-Disposition: form-data; name="m"'   + crlf + crlf +
195               str(cl.c.client)            .encode('ascii')  + crlf +
196               token                                         + crlf +
197               str(cl.c.target_requests_outstanding)
198                                           .encode('ascii')  + crlf +
199               str(cl.c.http_timeout)      .encode('ascii')  + crlf +
200             ((
201               b'--b'                                        + crlf +
202               b'Content-Type: application/octet-stream'     + crlf +
203               b'Content-Disposition: form-data; name="d"'   + crlf + crlf +
204               d                                             + crlf
205              ) if len(d) else b'')                               +
206               b'--b--'                                      + crlf)
207
208       #df = open('data.dump.dbg', mode='wb')
209       #df.write(mime)
210       #df.close()
211       # POST -use -c 'multipart/form-data; boundary="b"' http://localhost:8099/ <data.dump.dbg
212
213       cl.log(DBG.HTTP_FULL, 'requesting: ' + str(mime))
214
215       hh = { 'User-Agent': ['hippotat'],
216              'Content-Type': ['multipart/form-data; boundary="b"'],
217              'Content-Length': [str(len(mime))] }
218
219       bytesreader = io.BytesIO(mime)
220       producer = twisted.web.client.FileBodyProducer(bytesreader)
221
222       req = cl.agent.request(b'POST',
223                           cl.c.url,
224                           twisted.web.client.Headers(hh),
225                           producer)
226
227       cl.outstanding[req] = len(d)
228       cl.log(DBG.HTTP_CTRL,
229              'request OS=%d' % len(cl.outstanding),
230              idof=req, d=d)
231       req.addTimeout(cl.c.http_timeout, reactor)
232       req.addCallback(partial(cl.req_ok, req))
233       req.addErrback(partial(cl.req_err, req))
234
235     cl.log_outstanding()
236
237 clients = [ ]
238
239 def process_cfg(_opts, putative_servers, putative_clients):
240   global clients
241
242   for ss in putative_servers.values():
243     for (ci,cs) in putative_clients.items():
244       c = ConfigResults()
245
246       sections = cfg_process_client_common(c,ss,cs,ci)
247       if not sections: continue
248
249       log_debug_config('processing client [%s %s]' % (ss, cs))
250
251       def srch(getter,key): return cfg_search(getter,key,sections)
252
253       c.http_timeout   += srch(cfg.getint, 'http_timeout_grace')
254       c.max_outstanding = srch(cfg.getint, 'max_requests_outstanding')
255       c.max_batch_up    = srch(cfg.getint, 'max_batch_up')
256       c.http_retry      = srch(cfg.getint, 'http_retry')
257       c.max_queue_time  = srch(cfg.getint, 'max_queue_time')
258       c.vroutes         = srch(cfg.get,    'vroutes')
259
260       try: c.ifname     = srch(cfg_get_raw, 'ifname_client')
261       except NoOptionError: pass
262
263       try: c.url = srch(cfg.get,'url')
264       except NoOptionError:
265         cfg_process_saddrs(c, ss)
266         c.url = c.saddrs[0].url()
267
268       c.client = ci
269
270       cfg_process_vaddr(c,ss)
271
272       cfg_process_ipif(c,
273                        sections,
274                        (('local','client'),
275                         ('peer', 'vaddr'),
276                         ('rnets','vroutes')))
277
278       clients.append(Client(c,ss,cs))
279
280 common_startup(process_cfg)
281
282 for cl in clients:
283   cl.start()
284   cl.ipif = start_ipif(cl.c.ipif_command, cl.outbound)
285   cl.check_outbound()
286
287 common_run()