2 This file is part of GNUnet
3 Copyright (C) 2007, 2009, 2011, 2012 Christian Grothoff
5 GNUnet is free software: you can redistribute it and/or modify it
6 under the terms of the GNU Affero General Public License as published
7 by the Free Software Foundation, either version 3 of the License,
8 or (at your option) any later version.
10 GNUnet is distributed in the hope that it will be useful, but
11 WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 Affero General Public License for more details.
15 You should have received a copy of the GNU Affero General Public License
16 along with this program. If not, see <http://www.gnu.org/licenses/>.
18 SPDX-License-Identifier: AGPL3.0-or-later
22 * @file test_gns_proxy.c
23 * @brief testcase for accessing SOCKS5 GNS proxy
24 * @author Martin Schanzenbach
28 #include <curl/curl.h>
29 #elif HAVE_GNURL_CURL_H
30 #include <gnurl/curl.h>
32 #include <microhttpd.h>
33 #include "gnunet_util_lib.h"
34 #include "gnutls/x509.h"
37 * Largest allowed size for a PEM certificate.
39 #define MAX_PEM_SIZE (10 * 1024)
41 #define TEST_DOMAIN "www.test"
43 #define TIMEOUT GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_SECONDS, 300)
46 * Return value for 'main'.
48 static int global_ret;
51 static struct MHD_Daemon *mhd;
53 static struct GNUNET_SCHEDULER_Task *mhd_task_id;
55 static struct GNUNET_SCHEDULER_Task *curl_task_id;
63 static struct GNUNET_OS_Process *proxy_proc;
65 static char* cafile_opt;
67 static char* cafile_srv;
71 static gnutls_x509_crt_t proxy_cert;
73 static gnutls_x509_privkey_t proxy_key;
81 static struct CBC cbc;
84 * Read file in filename
86 * @param filename file to read
87 * @param size pointer where filesize is stored
88 * @return NULL on error
91 load_file (const char* filename,
98 GNUNET_DISK_file_size (filename,
103 if (fsize > MAX_PEM_SIZE)
105 *size = (unsigned int) fsize;
106 buffer = GNUNET_malloc (*size);
108 GNUNET_DISK_fn_read (filename,
112 GNUNET_free (buffer);
119 * Load PEM key from file
121 * @param key where to store the data
122 * @param keyfile path to the PEM file
123 * @return #GNUNET_OK on success
126 load_key_from_file (gnutls_x509_privkey_t key,
129 gnutls_datum_t key_data;
132 key_data.data = load_file (keyfile,
134 if (NULL == key_data.data)
135 return GNUNET_SYSERR;
136 ret = gnutls_x509_privkey_import (key, &key_data,
137 GNUTLS_X509_FMT_PEM);
138 if (GNUTLS_E_SUCCESS != ret)
140 GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
141 _("Unable to import private key from file `%s'\n"),
144 GNUNET_free_non_null (key_data.data);
145 return (GNUTLS_E_SUCCESS != ret) ? GNUNET_SYSERR : GNUNET_OK;
149 * Load cert from file
151 * @param crt struct to store data in
152 * @param certfile path to pem file
153 * @return #GNUNET_OK on success
156 load_cert_from_file (gnutls_x509_crt_t crt,
157 const char* certfile)
159 gnutls_datum_t cert_data;
162 cert_data.data = load_file (certfile,
164 if (NULL == cert_data.data)
165 return GNUNET_SYSERR;
166 ret = gnutls_x509_crt_import (crt,
168 GNUTLS_X509_FMT_PEM);
169 if (GNUTLS_E_SUCCESS != ret)
171 GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
172 _("Unable to import certificate from `%s'\n"),
175 GNUNET_free_non_null (cert_data.data);
176 return (GNUTLS_E_SUCCESS != ret) ? GNUNET_SYSERR : GNUNET_OK;
180 copy_buffer (void *ptr, size_t size, size_t nmemb, void *ctx)
182 struct CBC *cbc = ctx;
184 if (cbc->pos + size * nmemb > sizeof(cbc->buf))
185 return 0; /* overflow */
186 GNUNET_memcpy (&cbc->buf[cbc->pos], ptr, size * nmemb);
187 cbc->pos += size * nmemb;
194 struct MHD_Connection *connection,
198 const char *upload_data, size_t *upload_data_size,
202 struct MHD_Response *response;
205 if (0 != strcmp ("GET", method))
206 return MHD_NO; /* unexpected method */
213 GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "MHD sends respose for request to URL `%s'\n", url);
214 response = MHD_create_response_from_buffer (strlen (url),
216 MHD_RESPMEM_MUST_COPY);
217 ret = MHD_queue_response (connection, MHD_HTTP_OK, response);
218 MHD_destroy_response (response);
231 if (mhd_task_id != NULL)
233 GNUNET_SCHEDULER_cancel (mhd_task_id);
236 if (curl_task_id != NULL)
238 GNUNET_SCHEDULER_cancel (curl_task_id);
243 MHD_stop_daemon (mhd);
246 GNUNET_free_non_null (url);
248 if (NULL != proxy_proc)
250 (void) GNUNET_OS_process_kill (proxy_proc, SIGKILL);
251 GNUNET_assert (GNUNET_OK == GNUNET_OS_process_wait (proxy_proc));
252 GNUNET_OS_process_destroy (proxy_proc);
256 GNUNET_SCHEDULER_shutdown ();
261 * Function to run the HTTP client.
268 curl_task (void *cls)
282 struct GNUNET_NETWORK_FDSet nrs;
283 struct GNUNET_NETWORK_FDSet nws;
284 struct GNUNET_TIME_Relative delay;
293 curl_multi_perform (multi, &running);
296 GNUNET_assert (NULL != (msg = curl_multi_info_read (multi, &running)));
297 if (msg->msg == CURLMSG_DONE)
299 if (msg->data.result != CURLE_OK)
302 "%s failed at %s:%d: `%s'\n",
303 "curl_multi_perform",
305 __LINE__, curl_easy_strerror (msg->data.result));
309 curl_multi_remove_handle (multi, curl);
310 curl_multi_cleanup (multi);
311 curl_easy_cleanup (curl);
314 if (cbc.pos != strlen ("/hello_world"))
319 if (0 != strncmp ("/hello_world", cbc.buf, strlen ("/hello_world")))
324 GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "Download complete, shutting down!\n");
328 GNUNET_assert (CURLM_OK == curl_multi_fdset (multi, &rs, &ws, &es, &max));
329 if ( (CURLM_OK != curl_multi_timeout (multi, &timeout)) ||
331 delay = GNUNET_TIME_UNIT_SECONDS;
333 delay = GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_MILLISECONDS, (unsigned int) timeout);
334 GNUNET_NETWORK_fdset_copy_native (&nrs,
337 GNUNET_NETWORK_fdset_copy_native (&nws,
340 curl_task_id = GNUNET_SCHEDULER_add_select (GNUNET_SCHEDULER_PRIORITY_DEFAULT,
350 start_curl (void *cls)
353 GNUNET_asprintf (&url,
354 "https://%s:%d/hello_world",
356 curl = curl_easy_init ();
357 curl_easy_setopt (curl, CURLOPT_URL, url);
358 //curl_easy_setopt (curl, CURLOPT_URL, "https://127.0.0.1:8443/hello_world");
359 curl_easy_setopt (curl, CURLOPT_WRITEFUNCTION, ©_buffer);
360 curl_easy_setopt (curl, CURLOPT_WRITEDATA, &cbc);
361 curl_easy_setopt (curl, CURLOPT_FAILONERROR, 1);
362 curl_easy_setopt (curl, CURLOPT_TIMEOUT, 150L);
363 curl_easy_setopt (curl, CURLOPT_CONNECTTIMEOUT, 15L);
364 curl_easy_setopt (curl, CURLOPT_NOSIGNAL, 1);
365 curl_easy_setopt (curl, CURLOPT_CAINFO, cafile_opt);
366 //curl_easy_setopt (curl, CURLOPT_SSL_VERIFYPEER, 0L);
367 //curl_easy_setopt (curl, CURLOPT_SSL_VERIFYHOST, 0L);
368 curl_easy_setopt (curl, CURLOPT_PROXY, "socks5h://127.0.0.1:7777");
370 multi = curl_multi_init ();
371 GNUNET_assert (multi != NULL);
372 GNUNET_assert (CURLM_OK == curl_multi_add_handle (multi, curl));
373 GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
374 "Beginning HTTP download from `%s'\n",
381 * Callback invoked from the namestore service once record is
385 * @param af address family, AF_INET or AF_INET6; AF_UNSPEC on error;
386 * will match 'result_af' from the request
387 * @param address IP address (struct in_addr or struct in_addr6, depending on 'af')
388 * that the VPN allocated for the redirection;
389 * traffic to this IP will now be redirected to the
390 * specified target peer; NULL on error
393 commence_testing (void *cls)
396 GNUNET_SCHEDULER_add_delayed (GNUNET_TIME_UNIT_SECONDS,
403 * Function to keep the HTTP server running.
421 struct GNUNET_NETWORK_FDSet nrs;
422 struct GNUNET_NETWORK_FDSet nws;
427 unsigned MHD_LONG_LONG timeout;
428 struct GNUNET_TIME_Relative delay;
430 GNUNET_assert (NULL == mhd_task_id);
435 GNUNET_assert (MHD_YES ==
436 MHD_get_fdset (mhd, &rs, &ws, &es, &max_fd));
437 if (MHD_YES == MHD_get_timeout (mhd, &timeout))
438 delay = GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_MILLISECONDS,
439 (unsigned int) timeout);
441 delay = GNUNET_TIME_UNIT_FOREVER_REL;
442 GNUNET_NETWORK_fdset_copy_native (&nrs,
445 GNUNET_NETWORK_fdset_copy_native (&nws,
448 mhd_task_id = GNUNET_SCHEDULER_add_select (GNUNET_SCHEDULER_PRIORITY_DEFAULT,
458 * Main function that will be run
461 * @param args remaining command-line arguments
462 * @param cfgfile name of the configuration file used (for saving, can be NULL!)
463 * @param c configuration
469 const struct GNUNET_CONFIGURATION_Handle *c)
471 GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
472 "Using `%s' as CA\n",
474 char cert[MAX_PEM_SIZE];
475 char key[MAX_PEM_SIZE];
477 size_t cert_buf_size;
479 gnutls_global_init ();
480 gnutls_x509_crt_init (&proxy_cert);
481 gnutls_x509_privkey_init (&proxy_key);
484 load_cert_from_file (proxy_cert,
487 load_key_from_file (proxy_key,
490 GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
491 _("Failed to load X.509 key and certificate from `%s'\n"),
493 gnutls_x509_crt_deinit (proxy_cert);
494 gnutls_x509_privkey_deinit (proxy_key);
495 gnutls_global_deinit ();
498 GNUNET_SCHEDULER_add_shutdown (&do_shutdown,
500 key_buf_size = sizeof (key);
501 cert_buf_size = sizeof (cert);
502 gnutls_x509_crt_export (proxy_cert,
506 gnutls_x509_privkey_export (proxy_key,
510 mhd = MHD_start_daemon (MHD_USE_DEBUG | MHD_USE_SSL | MHD_ALLOW_SUSPEND_RESUME, port,
513 MHD_OPTION_HTTPS_MEM_KEY, key,
514 MHD_OPTION_HTTPS_MEM_CERT, cert,
516 GNUNET_assert (NULL != mhd);
519 GNUNET_SCHEDULER_add_now (&commence_testing,
524 main (int argc, char *const *argv)
526 struct GNUNET_GETOPT_CommandLineOption options[] = {
527 GNUNET_GETOPT_option_uint16 ('p',
530 gettext_noop ("listen on specified port (default: 7777)"),
532 GNUNET_GETOPT_option_string ('A',
535 gettext_noop ("pem file to use as CA"),
537 GNUNET_GETOPT_option_string ('S',
540 gettext_noop ("pem file to use for the server"),
543 GNUNET_GETOPT_OPTION_END
546 if (0 != curl_global_init (CURL_GLOBAL_WIN32))
548 fprintf (stderr, "failed to initialize curl\n");
552 GNUNET_STRINGS_get_utf8_args (argc, argv,
555 GNUNET_log_setup ("gnunet-gns-proxy-test",
558 if (GNUNET_OK != GNUNET_PROGRAM_run (argc, argv,
559 "gnunet-gns-proxy-test",
560 _("GNUnet GNS proxy test"),
564 GNUNET_free_non_null ((char *) argv);
568 /* end of test_gns_proxy.c */