test_entryconn.c 29 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856
  1. /* Copyright (c) 2014-2017, The Tor Project, Inc. */
  2. /* See LICENSE for licensing information */
  3. #include "orconfig.h"
  4. #define CONNECTION_PRIVATE
  5. #define CONNECTION_EDGE_PRIVATE
  6. #include "or.h"
  7. #include "test.h"
  8. #include "addressmap.h"
  9. #include "config.h"
  10. #include "confparse.h"
  11. #include "connection.h"
  12. #include "connection_edge.h"
  13. #include "nodelist.h"
  14. #include "hs_cache.h"
  15. #include "rendcache.h"
  16. static void *
  17. entryconn_rewrite_setup(const struct testcase_t *tc)
  18. {
  19. (void)tc;
  20. entry_connection_t *ec = entry_connection_new(CONN_TYPE_AP, AF_INET);
  21. addressmap_init();
  22. return ec;
  23. }
  24. static int
  25. entryconn_rewrite_teardown(const struct testcase_t *tc, void *arg)
  26. {
  27. (void)tc;
  28. entry_connection_t *ec = arg;
  29. if (ec)
  30. connection_free_(ENTRY_TO_CONN(ec));
  31. addressmap_free_all();
  32. return 1;
  33. }
  34. static struct testcase_setup_t test_rewrite_setup = {
  35. entryconn_rewrite_setup, entryconn_rewrite_teardown
  36. };
  37. /* Simple rewrite: no changes needed */
  38. static void
  39. test_entryconn_rewrite_basic(void *arg)
  40. {
  41. entry_connection_t *ec = arg;
  42. rewrite_result_t rr;
  43. tt_assert(ec->socks_request);
  44. strlcpy(ec->socks_request->address, "www.TORproject.org",
  45. sizeof(ec->socks_request->address));
  46. ec->socks_request->command = SOCKS_COMMAND_CONNECT;
  47. connection_ap_handshake_rewrite(ec, &rr);
  48. tt_int_op(rr.should_close, OP_EQ, 0);
  49. tt_int_op(rr.end_reason, OP_EQ, 0);
  50. tt_int_op(rr.automap, OP_EQ, 0);
  51. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  52. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  53. tt_str_op(rr.orig_address, OP_EQ, "www.torproject.org");
  54. tt_str_op(ec->socks_request->address, OP_EQ, "www.torproject.org");
  55. tt_str_op(ec->original_dest_address, OP_EQ, "www.torproject.org");
  56. done:
  57. ;
  58. }
  59. /* Rewrite but reject because of disallowed .exit */
  60. static void
  61. test_entryconn_rewrite_bad_dotexit(void *arg)
  62. {
  63. entry_connection_t *ec = arg;
  64. rewrite_result_t rr;
  65. get_options_mutable()->AllowDotExit = 0;
  66. tt_assert(ec->socks_request);
  67. strlcpy(ec->socks_request->address, "www.TORproject.org.foo.exit",
  68. sizeof(ec->socks_request->address));
  69. ec->socks_request->command = SOCKS_COMMAND_CONNECT;
  70. connection_ap_handshake_rewrite(ec, &rr);
  71. tt_int_op(rr.should_close, OP_EQ, 1);
  72. tt_int_op(rr.end_reason, OP_EQ, END_STREAM_REASON_TORPROTOCOL);
  73. done:
  74. ;
  75. }
  76. /* Automap on resolve, connect to automapped address, resolve again and get
  77. * same answer. (IPv4) */
  78. static void
  79. test_entryconn_rewrite_automap_ipv4(void *arg)
  80. {
  81. entry_connection_t *ec = arg;
  82. entry_connection_t *ec2=NULL, *ec3=NULL;
  83. rewrite_result_t rr;
  84. char *msg = NULL;
  85. ec2 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  86. ec3 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  87. get_options_mutable()->AutomapHostsOnResolve = 1;
  88. smartlist_add_strdup(get_options_mutable()->AutomapHostsSuffixes, ".");
  89. parse_virtual_addr_network("127.202.0.0/16", AF_INET, 0, &msg);
  90. /* Automap this on resolve. */
  91. strlcpy(ec->socks_request->address, "WWW.MIT.EDU",
  92. sizeof(ec->socks_request->address));
  93. ec->socks_request->command = SOCKS_COMMAND_RESOLVE;
  94. connection_ap_handshake_rewrite(ec, &rr);
  95. tt_int_op(rr.automap, OP_EQ, 1);
  96. tt_int_op(rr.should_close, OP_EQ, 0);
  97. tt_int_op(rr.end_reason, OP_EQ, 0);
  98. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  99. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  100. tt_str_op(rr.orig_address, OP_EQ, "www.mit.edu");
  101. tt_str_op(ec->original_dest_address, OP_EQ, "www.mit.edu");
  102. tt_assert(!strcmpstart(ec->socks_request->address,"127.202."));
  103. /* Connect to it and make sure we get the original address back. */
  104. strlcpy(ec2->socks_request->address, ec->socks_request->address,
  105. sizeof(ec2->socks_request->address));
  106. ec2->socks_request->command = SOCKS_COMMAND_CONNECT;
  107. connection_ap_handshake_rewrite(ec2, &rr);
  108. tt_int_op(rr.automap, OP_EQ, 0);
  109. tt_int_op(rr.should_close, OP_EQ, 0);
  110. tt_int_op(rr.end_reason, OP_EQ, 0);
  111. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  112. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  113. tt_str_op(rr.orig_address, OP_EQ, ec->socks_request->address);
  114. tt_str_op(ec2->original_dest_address, OP_EQ, ec->socks_request->address);
  115. tt_str_op(ec2->socks_request->address, OP_EQ, "www.mit.edu");
  116. /* Resolve it again, make sure the answer is the same. */
  117. strlcpy(ec3->socks_request->address, "www.MIT.EDU",
  118. sizeof(ec3->socks_request->address));
  119. ec3->socks_request->command = SOCKS_COMMAND_RESOLVE;
  120. connection_ap_handshake_rewrite(ec3, &rr);
  121. tt_int_op(rr.automap, OP_EQ, 1);
  122. tt_int_op(rr.should_close, OP_EQ, 0);
  123. tt_int_op(rr.end_reason, OP_EQ, 0);
  124. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  125. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  126. tt_str_op(rr.orig_address, OP_EQ, "www.mit.edu");
  127. tt_str_op(ec3->original_dest_address, OP_EQ, "www.mit.edu");
  128. tt_str_op(ec3->socks_request->address, OP_EQ,
  129. ec->socks_request->address);
  130. done:
  131. connection_free_(ENTRY_TO_CONN(ec2));
  132. connection_free_(ENTRY_TO_CONN(ec3));
  133. }
  134. /* Automap on resolve, connect to automapped address, resolve again and get
  135. * same answer. (IPv6) */
  136. static void
  137. test_entryconn_rewrite_automap_ipv6(void *arg)
  138. {
  139. (void)arg;
  140. entry_connection_t *ec =NULL;
  141. entry_connection_t *ec2=NULL, *ec3=NULL;
  142. rewrite_result_t rr;
  143. char *msg = NULL;
  144. ec = entry_connection_new(CONN_TYPE_AP, AF_INET6);
  145. ec2 = entry_connection_new(CONN_TYPE_AP, AF_INET6);
  146. ec3 = entry_connection_new(CONN_TYPE_AP, AF_INET6);
  147. get_options_mutable()->AutomapHostsOnResolve = 1;
  148. smartlist_add_strdup(get_options_mutable()->AutomapHostsSuffixes, ".");
  149. parse_virtual_addr_network("FE80::/32", AF_INET6, 0, &msg);
  150. /* Automap this on resolve. */
  151. strlcpy(ec->socks_request->address, "WWW.MIT.EDU",
  152. sizeof(ec->socks_request->address));
  153. ec->socks_request->command = SOCKS_COMMAND_RESOLVE;
  154. connection_ap_handshake_rewrite(ec, &rr);
  155. tt_int_op(rr.automap, OP_EQ, 1);
  156. tt_int_op(rr.should_close, OP_EQ, 0);
  157. tt_int_op(rr.end_reason, OP_EQ, 0);
  158. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  159. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  160. tt_str_op(rr.orig_address, OP_EQ, "www.mit.edu");
  161. tt_str_op(ec->original_dest_address, OP_EQ, "www.mit.edu");
  162. /* Yes, this [ should be here. */
  163. tt_assert(!strcmpstart(ec->socks_request->address,"[fe80:"));
  164. /* Connect to it and make sure we get the original address back. */
  165. strlcpy(ec2->socks_request->address, ec->socks_request->address,
  166. sizeof(ec2->socks_request->address));
  167. ec2->socks_request->command = SOCKS_COMMAND_CONNECT;
  168. connection_ap_handshake_rewrite(ec2, &rr);
  169. tt_int_op(rr.automap, OP_EQ, 0);
  170. tt_int_op(rr.should_close, OP_EQ, 0);
  171. tt_int_op(rr.end_reason, OP_EQ, 0);
  172. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  173. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  174. tt_str_op(rr.orig_address, OP_EQ, ec->socks_request->address);
  175. tt_str_op(ec2->original_dest_address, OP_EQ, ec->socks_request->address);
  176. tt_str_op(ec2->socks_request->address, OP_EQ, "www.mit.edu");
  177. /* Resolve it again, make sure the answer is the same. */
  178. strlcpy(ec3->socks_request->address, "www.MIT.EDU",
  179. sizeof(ec3->socks_request->address));
  180. ec3->socks_request->command = SOCKS_COMMAND_RESOLVE;
  181. connection_ap_handshake_rewrite(ec3, &rr);
  182. tt_int_op(rr.automap, OP_EQ, 1);
  183. tt_int_op(rr.should_close, OP_EQ, 0);
  184. tt_int_op(rr.end_reason, OP_EQ, 0);
  185. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  186. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  187. tt_str_op(rr.orig_address, OP_EQ, "www.mit.edu");
  188. tt_str_op(ec3->original_dest_address, OP_EQ, "www.mit.edu");
  189. tt_str_op(ec3->socks_request->address, OP_EQ,
  190. ec->socks_request->address);
  191. done:
  192. connection_free_(ENTRY_TO_CONN(ec));
  193. connection_free_(ENTRY_TO_CONN(ec2));
  194. connection_free_(ENTRY_TO_CONN(ec3));
  195. }
  196. #if 0
  197. /* FFFF not actually supported. */
  198. /* automap on resolve, reverse lookup. */
  199. static void
  200. test_entryconn_rewrite_automap_reverse(void *arg)
  201. {
  202. entry_connection_t *ec = arg;
  203. entry_connection_t *ec2=NULL;
  204. rewrite_result_t rr;
  205. char *msg = NULL;
  206. ec2 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  207. get_options_mutable()->AutomapHostsOnResolve = 1;
  208. get_options_mutable()->SafeLogging_ = SAFELOG_SCRUB_NONE;
  209. smartlist_add(get_options_mutable()->AutomapHostsSuffixes,
  210. tor_strdup(".bloom"));
  211. parse_virtual_addr_network("127.80.0.0/16", AF_INET, 0, &msg);
  212. /* Automap this on resolve. */
  213. strlcpy(ec->socks_request->address, "www.poldy.BLOOM",
  214. sizeof(ec->socks_request->address));
  215. ec->socks_request->command = SOCKS_COMMAND_RESOLVE;
  216. connection_ap_handshake_rewrite(ec, &rr);
  217. tt_int_op(rr.automap, OP_EQ, 1);
  218. tt_int_op(rr.should_close, OP_EQ, 0);
  219. tt_int_op(rr.end_reason, OP_EQ, 0);
  220. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  221. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  222. tt_str_op(rr.orig_address, OP_EQ, "www.poldy.bloom");
  223. tt_str_op(ec->original_dest_address, OP_EQ, "www.poldy.bloom");
  224. tt_assert(!strcmpstart(ec->socks_request->address,"127.80."));
  225. strlcpy(ec2->socks_request->address, ec->socks_request->address,
  226. sizeof(ec2->socks_request->address));
  227. ec2->socks_request->command = SOCKS_COMMAND_RESOLVE_PTR;
  228. connection_ap_handshake_rewrite(ec2, &rr);
  229. tt_int_op(rr.automap, OP_EQ, 0);
  230. tt_int_op(rr.should_close, OP_EQ, 1);
  231. tt_int_op(rr.end_reason, OP_EQ,
  232. END_STREAM_REASON_DONE|END_STREAM_REASON_FLAG_ALREADY_SOCKS_REPLIED);
  233. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  234. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  235. done:
  236. connection_free_(ENTRY_TO_CONN(ec2));
  237. }
  238. #endif
  239. /* Rewrite because of cached DNS entry. */
  240. static void
  241. test_entryconn_rewrite_cached_dns_ipv4(void *arg)
  242. {
  243. entry_connection_t *ec = arg;
  244. rewrite_result_t rr;
  245. time_t expires = time(NULL) + 3600;
  246. entry_connection_t *ec2=NULL;
  247. ec2 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  248. addressmap_register("www.friendly.example.com",
  249. tor_strdup("240.240.241.241"),
  250. expires,
  251. ADDRMAPSRC_DNS,
  252. 0, 0);
  253. strlcpy(ec->socks_request->address, "www.friendly.example.com",
  254. sizeof(ec->socks_request->address));
  255. strlcpy(ec2->socks_request->address, "www.friendly.example.com",
  256. sizeof(ec2->socks_request->address));
  257. ec->socks_request->command = SOCKS_COMMAND_CONNECT;
  258. ec2->socks_request->command = SOCKS_COMMAND_CONNECT;
  259. ec2->entry_cfg.use_cached_ipv4_answers = 1; /* only ec2 gets this flag */
  260. connection_ap_handshake_rewrite(ec, &rr);
  261. tt_int_op(rr.automap, OP_EQ, 0);
  262. tt_int_op(rr.should_close, OP_EQ, 0);
  263. tt_int_op(rr.end_reason, OP_EQ, 0);
  264. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  265. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  266. tt_str_op(rr.orig_address, OP_EQ, "www.friendly.example.com");
  267. tt_str_op(ec->socks_request->address, OP_EQ, "www.friendly.example.com");
  268. connection_ap_handshake_rewrite(ec2, &rr);
  269. tt_int_op(rr.automap, OP_EQ, 0);
  270. tt_int_op(rr.should_close, OP_EQ, 0);
  271. tt_int_op(rr.end_reason, OP_EQ, 0);
  272. tt_i64_op(rr.map_expires, OP_EQ, expires);
  273. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  274. tt_str_op(rr.orig_address, OP_EQ, "www.friendly.example.com");
  275. tt_str_op(ec2->socks_request->address, OP_EQ, "240.240.241.241");
  276. done:
  277. connection_free_(ENTRY_TO_CONN(ec2));
  278. }
  279. /* Rewrite because of cached DNS entry. */
  280. static void
  281. test_entryconn_rewrite_cached_dns_ipv6(void *arg)
  282. {
  283. entry_connection_t *ec = NULL;
  284. rewrite_result_t rr;
  285. time_t expires = time(NULL) + 3600;
  286. entry_connection_t *ec2=NULL;
  287. (void)arg;
  288. ec = entry_connection_new(CONN_TYPE_AP, AF_INET6);
  289. ec2 = entry_connection_new(CONN_TYPE_AP, AF_INET6);
  290. addressmap_register("www.friendly.example.com",
  291. tor_strdup("[::f00f]"),
  292. expires,
  293. ADDRMAPSRC_DNS,
  294. 0, 0);
  295. strlcpy(ec->socks_request->address, "www.friendly.example.com",
  296. sizeof(ec->socks_request->address));
  297. strlcpy(ec2->socks_request->address, "www.friendly.example.com",
  298. sizeof(ec2->socks_request->address));
  299. ec->socks_request->command = SOCKS_COMMAND_CONNECT;
  300. ec2->socks_request->command = SOCKS_COMMAND_CONNECT;
  301. ec2->entry_cfg.use_cached_ipv6_answers = 1; /* only ec2 gets this flag */
  302. connection_ap_handshake_rewrite(ec, &rr);
  303. tt_int_op(rr.automap, OP_EQ, 0);
  304. tt_int_op(rr.should_close, OP_EQ, 0);
  305. tt_int_op(rr.end_reason, OP_EQ, 0);
  306. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  307. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  308. tt_str_op(rr.orig_address, OP_EQ, "www.friendly.example.com");
  309. tt_str_op(ec->socks_request->address, OP_EQ, "www.friendly.example.com");
  310. connection_ap_handshake_rewrite(ec2, &rr);
  311. tt_int_op(rr.automap, OP_EQ, 0);
  312. tt_int_op(rr.should_close, OP_EQ, 0);
  313. tt_int_op(rr.end_reason, OP_EQ, 0);
  314. tt_i64_op(rr.map_expires, OP_EQ, expires);
  315. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  316. tt_str_op(rr.orig_address, OP_EQ, "www.friendly.example.com");
  317. tt_str_op(ec2->socks_request->address, OP_EQ, "[::f00f]");
  318. done:
  319. connection_free_(ENTRY_TO_CONN(ec));
  320. connection_free_(ENTRY_TO_CONN(ec2));
  321. }
  322. /* Fail to connect to unmapped address in virtual range. */
  323. static void
  324. test_entryconn_rewrite_unmapped_virtual(void *arg)
  325. {
  326. entry_connection_t *ec = arg;
  327. rewrite_result_t rr;
  328. entry_connection_t *ec2 = NULL;
  329. char *msg = NULL;
  330. ec2 = entry_connection_new(CONN_TYPE_AP, AF_INET6);
  331. parse_virtual_addr_network("18.202.0.0/16", AF_INET, 0, &msg);
  332. parse_virtual_addr_network("[ABCD::]/16", AF_INET6, 0, &msg);
  333. strlcpy(ec->socks_request->address, "18.202.5.5",
  334. sizeof(ec->socks_request->address));
  335. ec->socks_request->command = SOCKS_COMMAND_CONNECT;
  336. connection_ap_handshake_rewrite(ec, &rr);
  337. tt_int_op(rr.should_close, OP_EQ, 1);
  338. tt_int_op(rr.end_reason, OP_EQ, END_STREAM_REASON_INTERNAL);
  339. tt_int_op(rr.automap, OP_EQ, 0);
  340. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  341. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  342. strlcpy(ec2->socks_request->address, "[ABCD:9::5314:9543]",
  343. sizeof(ec2->socks_request->address));
  344. ec2->socks_request->command = SOCKS_COMMAND_CONNECT;
  345. connection_ap_handshake_rewrite(ec2, &rr);
  346. tt_int_op(rr.should_close, OP_EQ, 1);
  347. tt_int_op(rr.end_reason, OP_EQ, END_STREAM_REASON_INTERNAL);
  348. tt_int_op(rr.automap, OP_EQ, 0);
  349. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  350. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  351. done:
  352. connection_free_(ENTRY_TO_CONN(ec2));
  353. }
  354. /* Rewrite because of mapaddress option */
  355. static void
  356. test_entryconn_rewrite_mapaddress(void *arg)
  357. {
  358. entry_connection_t *ec = arg;
  359. rewrite_result_t rr;
  360. config_line_append(&get_options_mutable()->AddressMap,
  361. "MapAddress", "meta metaobjects.example");
  362. config_register_addressmaps(get_options());
  363. strlcpy(ec->socks_request->address, "meta",
  364. sizeof(ec->socks_request->address));
  365. ec->socks_request->command = SOCKS_COMMAND_CONNECT;
  366. connection_ap_handshake_rewrite(ec, &rr);
  367. tt_int_op(rr.should_close, OP_EQ, 0);
  368. tt_int_op(rr.end_reason, OP_EQ, 0);
  369. tt_int_op(rr.automap, OP_EQ, 0);
  370. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  371. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  372. tt_str_op(ec->socks_request->address, OP_EQ, "metaobjects.example");
  373. done:
  374. ;
  375. }
  376. /* Reject reverse lookups of internal address. */
  377. static void
  378. test_entryconn_rewrite_reject_internal_reverse(void *arg)
  379. {
  380. entry_connection_t *ec = arg;
  381. rewrite_result_t rr;
  382. strlcpy(ec->socks_request->address, "10.0.0.1",
  383. sizeof(ec->socks_request->address));
  384. ec->socks_request->command = SOCKS_COMMAND_RESOLVE_PTR;
  385. connection_ap_handshake_rewrite(ec, &rr);
  386. tt_int_op(rr.should_close, OP_EQ, 1);
  387. tt_int_op(rr.end_reason, OP_EQ, END_STREAM_REASON_SOCKSPROTOCOL |
  388. END_STREAM_REASON_FLAG_ALREADY_SOCKS_REPLIED);
  389. tt_int_op(rr.automap, OP_EQ, 0);
  390. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  391. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  392. done:
  393. ;
  394. }
  395. /* Rewrite into .exit because of virtual address mapping */
  396. static void
  397. test_entryconn_rewrite_automap_exit(void *arg)
  398. {
  399. entry_connection_t *ec = arg;
  400. entry_connection_t *ec2=NULL;
  401. rewrite_result_t rr;
  402. char *msg = NULL;
  403. ec2 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  404. get_options_mutable()->AutomapHostsOnResolve = 1;
  405. get_options_mutable()->AllowDotExit = 1;
  406. smartlist_add_strdup(get_options_mutable()->AutomapHostsSuffixes,
  407. ".EXIT");
  408. parse_virtual_addr_network("127.1.0.0/16", AF_INET, 0, &msg);
  409. /* Automap this on resolve. */
  410. strlcpy(ec->socks_request->address, "website.example.exit",
  411. sizeof(ec->socks_request->address));
  412. ec->socks_request->command = SOCKS_COMMAND_RESOLVE;
  413. connection_ap_handshake_rewrite(ec, &rr);
  414. tt_int_op(rr.automap, OP_EQ, 1);
  415. tt_int_op(rr.should_close, OP_EQ, 0);
  416. tt_int_op(rr.end_reason, OP_EQ, 0);
  417. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  418. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  419. tt_str_op(rr.orig_address, OP_EQ, "website.example.exit");
  420. tt_str_op(ec->original_dest_address, OP_EQ, "website.example.exit");
  421. tt_assert(!strcmpstart(ec->socks_request->address,"127.1."));
  422. /* Connect to it and make sure we get the original address back. */
  423. strlcpy(ec2->socks_request->address, ec->socks_request->address,
  424. sizeof(ec2->socks_request->address));
  425. ec2->socks_request->command = SOCKS_COMMAND_CONNECT;
  426. connection_ap_handshake_rewrite(ec2, &rr);
  427. tt_int_op(rr.automap, OP_EQ, 0);
  428. tt_int_op(rr.should_close, OP_EQ, 0);
  429. tt_int_op(rr.end_reason, OP_EQ, 0);
  430. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  431. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_AUTOMAP);
  432. tt_str_op(rr.orig_address, OP_EQ, ec->socks_request->address);
  433. tt_str_op(ec2->original_dest_address, OP_EQ, ec->socks_request->address);
  434. tt_str_op(ec2->socks_request->address, OP_EQ, "website.example.exit");
  435. done:
  436. connection_free_(ENTRY_TO_CONN(ec2));
  437. }
  438. /* Rewrite into .exit because of mapaddress */
  439. static void
  440. test_entryconn_rewrite_mapaddress_exit(void *arg)
  441. {
  442. entry_connection_t *ec = arg;
  443. rewrite_result_t rr;
  444. config_line_append(&get_options_mutable()->AddressMap,
  445. "MapAddress", "*.example.com *.example.com.abc.exit");
  446. config_register_addressmaps(get_options());
  447. /* Automap this on resolve. */
  448. strlcpy(ec->socks_request->address, "abc.example.com",
  449. sizeof(ec->socks_request->address));
  450. ec->socks_request->command = SOCKS_COMMAND_CONNECT;
  451. connection_ap_handshake_rewrite(ec, &rr);
  452. tt_int_op(rr.automap, OP_EQ, 0);
  453. tt_int_op(rr.should_close, OP_EQ, 0);
  454. tt_int_op(rr.end_reason, OP_EQ, 0);
  455. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  456. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_TORRC);
  457. tt_str_op(rr.orig_address, OP_EQ, "abc.example.com");
  458. tt_str_op(ec->socks_request->address, OP_EQ, "abc.example.com.abc.exit");
  459. done:
  460. ;
  461. }
  462. /* Map foo.onion to longthing.onion, and also automap. */
  463. static void
  464. test_entryconn_rewrite_mapaddress_automap_onion(void *arg)
  465. {
  466. entry_connection_t *ec = arg;
  467. entry_connection_t *ec2 = NULL;
  468. entry_connection_t *ec3 = NULL;
  469. entry_connection_t *ec4 = NULL;
  470. rewrite_result_t rr;
  471. char *msg = NULL;
  472. ec2 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  473. ec3 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  474. ec4 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  475. get_options_mutable()->AutomapHostsOnResolve = 1;
  476. get_options_mutable()->AllowDotExit = 1;
  477. smartlist_add_strdup(get_options_mutable()->AutomapHostsSuffixes,
  478. ".onion");
  479. parse_virtual_addr_network("192.168.0.0/16", AF_INET, 0, &msg);
  480. config_line_append(&get_options_mutable()->AddressMap,
  481. "MapAddress", "foo.onion abcdefghijklmnop.onion");
  482. config_register_addressmaps(get_options());
  483. /* Connect to foo.onion. */
  484. strlcpy(ec->socks_request->address, "foo.onion",
  485. sizeof(ec->socks_request->address));
  486. ec->socks_request->command = SOCKS_COMMAND_CONNECT;
  487. connection_ap_handshake_rewrite(ec, &rr);
  488. tt_int_op(rr.automap, OP_EQ, 0);
  489. tt_int_op(rr.should_close, OP_EQ, 0);
  490. tt_int_op(rr.end_reason, OP_EQ, 0);
  491. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  492. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  493. tt_str_op(rr.orig_address, OP_EQ, "foo.onion");
  494. tt_str_op(ec->socks_request->address, OP_EQ, "abcdefghijklmnop.onion");
  495. /* Okay, resolve foo.onion */
  496. strlcpy(ec2->socks_request->address, "foo.onion",
  497. sizeof(ec2->socks_request->address));
  498. ec2->socks_request->command = SOCKS_COMMAND_RESOLVE;
  499. connection_ap_handshake_rewrite(ec2, &rr);
  500. tt_int_op(rr.automap, OP_EQ, 1);
  501. tt_int_op(rr.should_close, OP_EQ, 0);
  502. tt_int_op(rr.end_reason, OP_EQ, 0);
  503. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  504. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  505. tt_str_op(rr.orig_address, OP_EQ, "foo.onion");
  506. tt_assert(!strcmpstart(ec2->socks_request->address, "192.168."));
  507. /* Now connect */
  508. strlcpy(ec3->socks_request->address, ec2->socks_request->address,
  509. sizeof(ec3->socks_request->address));
  510. ec3->socks_request->command = SOCKS_COMMAND_CONNECT;
  511. connection_ap_handshake_rewrite(ec3, &rr);
  512. tt_int_op(rr.automap, OP_EQ, 0);
  513. tt_int_op(rr.should_close, OP_EQ, 0);
  514. tt_int_op(rr.end_reason, OP_EQ, 0);
  515. tt_assert(!strcmpstart(ec3->socks_request->address,
  516. "abcdefghijklmnop.onion"));
  517. /* Now resolve abcefghijklmnop.onion. */
  518. strlcpy(ec4->socks_request->address, "abcdefghijklmnop.onion",
  519. sizeof(ec4->socks_request->address));
  520. ec4->socks_request->command = SOCKS_COMMAND_RESOLVE;
  521. connection_ap_handshake_rewrite(ec4, &rr);
  522. tt_int_op(rr.automap, OP_EQ, 1);
  523. tt_int_op(rr.should_close, OP_EQ, 0);
  524. tt_int_op(rr.end_reason, OP_EQ, 0);
  525. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  526. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  527. tt_str_op(rr.orig_address, OP_EQ, "abcdefghijklmnop.onion");
  528. tt_assert(!strcmpstart(ec4->socks_request->address, "192.168."));
  529. /* XXXX doesn't work
  530. tt_str_op(ec4->socks_request->address, OP_EQ, ec2->socks_request->address);
  531. */
  532. done:
  533. connection_free_(ENTRY_TO_CONN(ec2));
  534. connection_free_(ENTRY_TO_CONN(ec3));
  535. connection_free_(ENTRY_TO_CONN(ec4));
  536. }
  537. static void
  538. test_entryconn_rewrite_mapaddress_automap_onion_common(entry_connection_t *ec,
  539. int map_to_onion,
  540. int map_to_address)
  541. {
  542. entry_connection_t *ec2 = NULL;
  543. entry_connection_t *ec3 = NULL;
  544. rewrite_result_t rr;
  545. ec2 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  546. ec3 = entry_connection_new(CONN_TYPE_AP, AF_INET);
  547. /* Connect to irc.example.com */
  548. strlcpy(ec->socks_request->address, "irc.example.com",
  549. sizeof(ec->socks_request->address));
  550. ec->socks_request->command = SOCKS_COMMAND_CONNECT;
  551. connection_ap_handshake_rewrite(ec, &rr);
  552. tt_int_op(rr.automap, OP_EQ, 0);
  553. tt_int_op(rr.should_close, OP_EQ, 0);
  554. tt_int_op(rr.end_reason, OP_EQ, 0);
  555. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  556. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  557. tt_str_op(rr.orig_address, OP_EQ, "irc.example.com");
  558. tt_str_op(ec->socks_request->address, OP_EQ,
  559. map_to_onion ? "abcdefghijklmnop.onion" : "irc.example.com");
  560. /* Okay, resolve irc.example.com */
  561. strlcpy(ec2->socks_request->address, "irc.example.com",
  562. sizeof(ec2->socks_request->address));
  563. ec2->socks_request->command = SOCKS_COMMAND_RESOLVE;
  564. connection_ap_handshake_rewrite(ec2, &rr);
  565. tt_int_op(rr.automap, OP_EQ, map_to_onion && map_to_address);
  566. tt_int_op(rr.should_close, OP_EQ, 0);
  567. tt_int_op(rr.end_reason, OP_EQ, 0);
  568. tt_i64_op(rr.map_expires, OP_EQ, TIME_MAX);
  569. tt_int_op(rr.exit_source, OP_EQ, ADDRMAPSRC_NONE);
  570. tt_str_op(rr.orig_address, OP_EQ, "irc.example.com");
  571. if (map_to_onion && map_to_address)
  572. tt_assert(!strcmpstart(ec2->socks_request->address, "192.168."));
  573. /* Now connect */
  574. strlcpy(ec3->socks_request->address, ec2->socks_request->address,
  575. sizeof(ec3->socks_request->address));
  576. ec3->socks_request->command = SOCKS_COMMAND_CONNECT;
  577. connection_ap_handshake_rewrite(ec3, &rr);
  578. tt_int_op(rr.automap, OP_EQ, 0);
  579. tt_int_op(rr.should_close, OP_EQ, 0);
  580. tt_int_op(rr.end_reason, OP_EQ, 0);
  581. if (map_to_onion)
  582. tt_assert(!strcmpstart(ec3->socks_request->address,
  583. "abcdefghijklmnop.onion"));
  584. done:
  585. connection_free_(ENTRY_TO_CONN(ec2));
  586. connection_free_(ENTRY_TO_CONN(ec3));
  587. }
  588. /* This time is the same, but we start with a mapping from a non-onion
  589. * address. */
  590. static void
  591. test_entryconn_rewrite_mapaddress_automap_onion2(void *arg)
  592. {
  593. char *msg = NULL;
  594. get_options_mutable()->AutomapHostsOnResolve = 1;
  595. smartlist_add_strdup(get_options_mutable()->AutomapHostsSuffixes,
  596. ".onion");
  597. parse_virtual_addr_network("192.168.0.0/16", AF_INET, 0, &msg);
  598. config_line_append(&get_options_mutable()->AddressMap,
  599. "MapAddress", "irc.example.com abcdefghijklmnop.onion");
  600. config_register_addressmaps(get_options());
  601. test_entryconn_rewrite_mapaddress_automap_onion_common(arg, 1, 1);
  602. }
  603. /* Same as above, with automapped turned off */
  604. static void
  605. test_entryconn_rewrite_mapaddress_automap_onion3(void *arg)
  606. {
  607. config_line_append(&get_options_mutable()->AddressMap,
  608. "MapAddress", "irc.example.com abcdefghijklmnop.onion");
  609. config_register_addressmaps(get_options());
  610. test_entryconn_rewrite_mapaddress_automap_onion_common(arg, 1, 0);
  611. }
  612. /* As above, with no mapping. */
  613. static void
  614. test_entryconn_rewrite_mapaddress_automap_onion4(void *arg)
  615. {
  616. char *msg = NULL;
  617. get_options_mutable()->AutomapHostsOnResolve = 1;
  618. smartlist_add_strdup(get_options_mutable()->AutomapHostsSuffixes,
  619. ".onion");
  620. parse_virtual_addr_network("192.168.0.0/16", AF_INET, 0, &msg);
  621. test_entryconn_rewrite_mapaddress_automap_onion_common(arg, 0, 1);
  622. }
  623. /** Test that rewrite functions can handle v2 addresses */
  624. static void
  625. test_entryconn_rewrite_onion_v2(void *arg)
  626. {
  627. int retval;
  628. entry_connection_t *conn = arg;
  629. (void) arg;
  630. rend_cache_init();
  631. /* Make a SOCKS request */
  632. conn->socks_request->command = SOCKS_COMMAND_CONNECT;
  633. strlcpy(conn->socks_request->address,
  634. "pqeed46efnwmfuid.onion",
  635. sizeof(conn->socks_request->address));
  636. /* Make an onion connection using the SOCKS request */
  637. conn->entry_cfg.onion_traffic = 1;
  638. ENTRY_TO_CONN(conn)->state = AP_CONN_STATE_SOCKS_WAIT;
  639. tt_assert(!ENTRY_TO_EDGE_CONN(conn)->rend_data);
  640. /* Handle SOCKS and rewrite! */
  641. retval = connection_ap_handshake_rewrite_and_attach(conn, NULL, NULL);
  642. tt_int_op(retval, OP_EQ, 0);
  643. /* Check connection state after rewrite */
  644. tt_int_op(ENTRY_TO_CONN(conn)->state, OP_EQ, AP_CONN_STATE_RENDDESC_WAIT);
  645. /* check that the address got rewritten */
  646. tt_str_op(conn->socks_request->address, OP_EQ,
  647. "pqeed46efnwmfuid");
  648. /* check that HS information got attached to the connection */
  649. tt_assert(ENTRY_TO_EDGE_CONN(conn)->rend_data);
  650. tt_assert(!ENTRY_TO_EDGE_CONN(conn)->hs_ident);
  651. done:
  652. rend_cache_free_all();
  653. /* 'conn' is cleaned by handler */
  654. }
  655. /** Test that rewrite functions can handle v3 onion addresses */
  656. static void
  657. test_entryconn_rewrite_onion_v3(void *arg)
  658. {
  659. int retval;
  660. entry_connection_t *conn = arg;
  661. (void) arg;
  662. hs_cache_init();
  663. /* Make a SOCKS request */
  664. conn->socks_request->command = SOCKS_COMMAND_CONNECT;
  665. strlcpy(conn->socks_request->address,
  666. "git.25njqamcweflpvkl73j4szahhihoc4xt3ktcgjnpaingr5yhkenl5sid.onion",
  667. sizeof(conn->socks_request->address));
  668. /* Make an onion connection using the SOCKS request */
  669. conn->entry_cfg.onion_traffic = 1;
  670. ENTRY_TO_CONN(conn)->state = AP_CONN_STATE_SOCKS_WAIT;
  671. tt_assert(!ENTRY_TO_EDGE_CONN(conn)->rend_data);
  672. tt_assert(!ENTRY_TO_EDGE_CONN(conn)->hs_ident);
  673. /* Handle SOCKS and rewrite! */
  674. retval = connection_ap_handshake_rewrite_and_attach(conn, NULL, NULL);
  675. tt_int_op(retval, OP_EQ, 0);
  676. /* Check connection state after rewrite */
  677. tt_int_op(ENTRY_TO_CONN(conn)->state, OP_EQ, AP_CONN_STATE_CIRCUIT_WAIT);
  678. /* check that the address got rewritten */
  679. tt_str_op(conn->socks_request->address, OP_EQ,
  680. "25njqamcweflpvkl73j4szahhihoc4xt3ktcgjnpaingr5yhkenl5sid");
  681. /* check that HS information got attached to the connection */
  682. tt_assert(ENTRY_TO_EDGE_CONN(conn)->hs_ident);
  683. tt_assert(!ENTRY_TO_EDGE_CONN(conn)->rend_data);
  684. done:
  685. hs_free_all();
  686. /* 'conn' is cleaned by handler */
  687. }
  688. #define REWRITE(name) \
  689. { #name, test_entryconn_##name, TT_FORK, &test_rewrite_setup, NULL }
  690. struct testcase_t entryconn_tests[] = {
  691. REWRITE(rewrite_basic),
  692. REWRITE(rewrite_bad_dotexit),
  693. REWRITE(rewrite_automap_ipv4),
  694. REWRITE(rewrite_automap_ipv6),
  695. // REWRITE(rewrite_automap_reverse),
  696. REWRITE(rewrite_cached_dns_ipv4),
  697. REWRITE(rewrite_cached_dns_ipv6),
  698. REWRITE(rewrite_unmapped_virtual),
  699. REWRITE(rewrite_mapaddress),
  700. REWRITE(rewrite_reject_internal_reverse),
  701. REWRITE(rewrite_automap_exit),
  702. REWRITE(rewrite_mapaddress_exit),
  703. REWRITE(rewrite_mapaddress_automap_onion),
  704. REWRITE(rewrite_mapaddress_automap_onion2),
  705. REWRITE(rewrite_mapaddress_automap_onion3),
  706. REWRITE(rewrite_mapaddress_automap_onion4),
  707. REWRITE(rewrite_onion_v2),
  708. REWRITE(rewrite_onion_v3),
  709. END_OF_TESTCASES
  710. };