v2ray-core/testing/scenarios/tls_test.go

667 lines
17 KiB
Go
Raw Normal View History

2016-12-16 20:39:00 +00:00
package scenarios
import (
2017-02-08 16:57:21 +00:00
"crypto/rand"
"crypto/x509"
"runtime"
2018-03-01 20:42:42 +00:00
"sync"
2016-12-30 22:12:00 +00:00
"testing"
"time"
2016-12-16 20:39:00 +00:00
"v2ray.com/core"
"v2ray.com/core/app/proxyman"
2018-08-16 10:05:33 +00:00
"v2ray.com/core/common"
"v2ray.com/core/common/net"
2016-12-30 22:12:00 +00:00
"v2ray.com/core/common/protocol"
"v2ray.com/core/common/protocol/tls/cert"
2016-12-30 22:12:00 +00:00
"v2ray.com/core/common/serial"
"v2ray.com/core/common/uuid"
"v2ray.com/core/proxy/dokodemo"
"v2ray.com/core/proxy/freedom"
"v2ray.com/core/proxy/vmess"
"v2ray.com/core/proxy/vmess/inbound"
"v2ray.com/core/proxy/vmess/outbound"
"v2ray.com/core/testing/servers/tcp"
2017-11-14 22:45:07 +00:00
"v2ray.com/core/testing/servers/udp"
2016-12-30 22:12:00 +00:00
"v2ray.com/core/transport/internet"
2018-03-01 20:22:53 +00:00
"v2ray.com/core/transport/internet/http"
2016-12-30 22:12:00 +00:00
"v2ray.com/core/transport/internet/tls"
2017-02-08 16:57:21 +00:00
"v2ray.com/core/transport/internet/websocket"
2017-10-26 19:44:22 +00:00
. "v2ray.com/ext/assert"
2016-12-16 20:39:00 +00:00
)
2016-12-30 22:12:00 +00:00
func TestSimpleTLSConnection(t *testing.T) {
2017-10-24 14:15:35 +00:00
assert := With(t)
2016-12-30 22:12:00 +00:00
tcpServer := tcp.Server{
MsgProcessor: xor,
}
dest, err := tcpServer.Start()
2018-08-16 10:05:33 +00:00
common.Must(err)
defer tcpServer.Close()
2016-12-30 22:12:00 +00:00
userID := protocol.NewID(uuid.New())
2018-03-01 10:53:39 +00:00
serverPort := tcp.PickPort()
2016-12-30 22:12:00 +00:00
serverConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
2016-12-30 22:12:00 +00:00
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(serverPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
StreamSettings: &internet.StreamConfig{
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
Certificate: []*tls.Certificate{tls.ParseCertificate(cert.MustGenerate(nil))},
}),
},
},
}),
ProxySettings: serial.ToTypedMessage(&inbound.Config{
2016-12-30 22:12:00 +00:00
User: []*protocol.User{
{
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
},
},
}),
2017-01-12 15:10:03 +00:00
},
},
Outbound: []*core.OutboundHandlerConfig{
2017-01-12 15:10:03 +00:00
{
ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
2017-01-12 15:10:03 +00:00
},
},
}
2018-03-01 10:53:39 +00:00
clientPort := tcp.PickPort()
2017-01-12 15:10:03 +00:00
clientConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
2017-01-12 15:10:03 +00:00
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(clientPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
}),
ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
Address: net.NewIPOrDomain(dest.Address),
2017-01-12 15:10:03 +00:00
Port: uint32(dest.Port),
NetworkList: &net.NetworkList{
Network: []net.Network{net.Network_TCP},
2017-01-12 15:10:03 +00:00
},
}),
},
},
Outbound: []*core.OutboundHandlerConfig{
2017-01-12 15:10:03 +00:00
{
ProxySettings: serial.ToTypedMessage(&outbound.Config{
2017-01-12 15:10:03 +00:00
Receiver: []*protocol.ServerEndpoint{
{
Address: net.NewIPOrDomain(net.LocalHostIP),
2017-01-12 15:10:03 +00:00
Port: uint32(serverPort),
User: []*protocol.User{
2016-12-30 22:12:00 +00:00
{
2017-01-12 15:10:03 +00:00
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
2016-12-30 22:12:00 +00:00
},
},
2017-01-12 15:10:03 +00:00
},
},
}),
SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
StreamSettings: &internet.StreamConfig{
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
AllowInsecure: true,
}),
},
2017-01-12 15:10:03 +00:00
},
}),
2017-01-12 15:10:03 +00:00
},
},
}
2017-05-17 22:39:30 +00:00
servers, err := InitializeServerConfigs(serverConfig, clientConfig)
2018-08-16 10:05:33 +00:00
common.Must(err)
defer CloseAllServers(servers)
{
conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
IP: []byte{127, 0, 0, 1},
Port: int(clientPort),
})
assert(err, IsNil)
payload := "dokodemo request."
nBytes, err := conn.Write([]byte(payload))
assert(err, IsNil)
assert(nBytes, Equals, len(payload))
response := readFrom(conn, time.Second*2, len(payload))
assert(response, Equals, xor([]byte(payload)))
assert(conn.Close(), IsNil)
}
2017-01-12 15:10:03 +00:00
}
func TestAutoIssuingCertificate(t *testing.T) {
if runtime.GOOS == "windows" {
// Not supported on Windows yet.
return
}
2018-08-09 14:30:05 +00:00
if runtime.GOARCH == "arm64" {
return
}
assert := With(t)
tcpServer := tcp.Server{
MsgProcessor: xor,
}
dest, err := tcpServer.Start()
assert(err, IsNil)
defer tcpServer.Close()
caCert, err := cert.Generate(nil, cert.Authority(true), cert.KeyUsage(x509.KeyUsageDigitalSignature|x509.KeyUsageKeyEncipherment|x509.KeyUsageCertSign))
assert(err, IsNil)
certPEM, keyPEM := caCert.ToPEM()
userID := protocol.NewID(uuid.New())
serverPort := tcp.PickPort()
serverConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(serverPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
StreamSettings: &internet.StreamConfig{
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
Certificate: []*tls.Certificate{{
Certificate: certPEM,
Key: keyPEM,
Usage: tls.Certificate_AUTHORITY_ISSUE,
}},
}),
},
},
}),
ProxySettings: serial.ToTypedMessage(&inbound.Config{
User: []*protocol.User{
{
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
},
},
}),
},
},
Outbound: []*core.OutboundHandlerConfig{
{
ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
},
},
}
clientPort := tcp.PickPort()
clientConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(clientPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
}),
ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
Address: net.NewIPOrDomain(dest.Address),
Port: uint32(dest.Port),
NetworkList: &net.NetworkList{
Network: []net.Network{net.Network_TCP},
},
}),
},
},
Outbound: []*core.OutboundHandlerConfig{
{
ProxySettings: serial.ToTypedMessage(&outbound.Config{
Receiver: []*protocol.ServerEndpoint{
{
Address: net.NewIPOrDomain(net.LocalHostIP),
Port: uint32(serverPort),
User: []*protocol.User{
{
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
},
},
},
},
}),
SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
StreamSettings: &internet.StreamConfig{
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
ServerName: "v2ray.com",
Certificate: []*tls.Certificate{{
Certificate: certPEM,
Usage: tls.Certificate_AUTHORITY_VERIFY,
}},
}),
},
},
}),
},
},
}
servers, err := InitializeServerConfigs(serverConfig, clientConfig)
assert(err, IsNil)
2018-08-09 21:02:31 +00:00
for i := 0; i < 10; i++ {
conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
IP: []byte{127, 0, 0, 1},
Port: int(clientPort),
})
assert(err, IsNil)
2018-08-09 21:02:31 +00:00
payload := "dokodemo request."
nBytes, err := conn.Write([]byte(payload))
assert(err, IsNil)
assert(nBytes, Equals, len(payload))
2018-08-09 21:02:31 +00:00
response := readFrom(conn, time.Second*2, len(payload))
assert(response, Equals, xor([]byte(payload)))
assert(conn.Close(), IsNil)
}
CloseAllServers(servers)
}
2017-01-12 15:10:03 +00:00
func TestTLSOverKCP(t *testing.T) {
2017-10-24 14:15:35 +00:00
assert := With(t)
2017-01-12 15:10:03 +00:00
tcpServer := tcp.Server{
MsgProcessor: xor,
}
dest, err := tcpServer.Start()
2017-10-24 14:15:35 +00:00
assert(err, IsNil)
2017-01-12 15:10:03 +00:00
defer tcpServer.Close()
userID := protocol.NewID(uuid.New())
2017-11-14 22:45:07 +00:00
serverPort := udp.PickPort()
2017-01-12 15:10:03 +00:00
serverConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
2017-01-12 15:10:03 +00:00
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(serverPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
StreamSettings: &internet.StreamConfig{
Protocol: internet.TransportProtocol_MKCP,
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
Certificate: []*tls.Certificate{tls.ParseCertificate(cert.MustGenerate(nil))},
}),
},
},
}),
ProxySettings: serial.ToTypedMessage(&inbound.Config{
2017-01-12 15:10:03 +00:00
User: []*protocol.User{
{
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
},
},
}),
2016-12-30 22:12:00 +00:00
},
2016-12-16 20:39:00 +00:00
},
Outbound: []*core.OutboundHandlerConfig{
2016-12-30 22:12:00 +00:00
{
ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
2016-12-30 22:12:00 +00:00
},
},
}
2018-03-01 10:53:39 +00:00
clientPort := tcp.PickPort()
2016-12-30 22:12:00 +00:00
clientConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
2016-12-30 22:12:00 +00:00
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(clientPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
}),
ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
Address: net.NewIPOrDomain(dest.Address),
2016-12-30 22:12:00 +00:00
Port: uint32(dest.Port),
NetworkList: &net.NetworkList{
Network: []net.Network{net.Network_TCP},
2016-12-30 22:12:00 +00:00
},
}),
},
},
Outbound: []*core.OutboundHandlerConfig{
2016-12-30 22:12:00 +00:00
{
ProxySettings: serial.ToTypedMessage(&outbound.Config{
2016-12-30 22:12:00 +00:00
Receiver: []*protocol.ServerEndpoint{
{
Address: net.NewIPOrDomain(net.LocalHostIP),
2016-12-30 22:12:00 +00:00
Port: uint32(serverPort),
User: []*protocol.User{
{
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
},
},
},
},
}),
SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
StreamSettings: &internet.StreamConfig{
Protocol: internet.TransportProtocol_MKCP,
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
AllowInsecure: true,
}),
},
2016-12-30 22:12:00 +00:00
},
}),
2016-12-30 22:12:00 +00:00
},
},
}
2017-05-17 22:39:30 +00:00
servers, err := InitializeServerConfigs(serverConfig, clientConfig)
2017-10-24 14:15:35 +00:00
assert(err, IsNil)
2016-12-30 22:12:00 +00:00
conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
IP: []byte{127, 0, 0, 1},
Port: int(clientPort),
})
2017-10-24 14:15:35 +00:00
assert(err, IsNil)
2016-12-30 22:12:00 +00:00
payload := "dokodemo request."
nBytes, err := conn.Write([]byte(payload))
2017-10-24 14:15:35 +00:00
assert(err, IsNil)
assert(nBytes, Equals, len(payload))
2016-12-30 22:12:00 +00:00
2017-01-04 14:42:06 +00:00
response := readFrom(conn, time.Second*2, len(payload))
2017-10-24 14:15:35 +00:00
assert(response, Equals, xor([]byte(payload)))
assert(conn.Close(), IsNil)
2017-01-04 14:42:06 +00:00
2017-05-17 22:39:30 +00:00
CloseAllServers(servers)
2017-01-04 14:42:06 +00:00
}
2017-02-08 16:57:21 +00:00
func TestTLSOverWebSocket(t *testing.T) {
2017-10-24 14:15:35 +00:00
assert := With(t)
2017-02-08 16:57:21 +00:00
tcpServer := tcp.Server{
MsgProcessor: xor,
}
dest, err := tcpServer.Start()
2017-10-24 14:15:35 +00:00
assert(err, IsNil)
2017-02-08 16:57:21 +00:00
defer tcpServer.Close()
userID := protocol.NewID(uuid.New())
2018-03-01 10:53:39 +00:00
serverPort := tcp.PickPort()
2017-02-08 16:57:21 +00:00
serverConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
2017-02-08 16:57:21 +00:00
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(serverPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
2017-02-08 16:57:21 +00:00
StreamSettings: &internet.StreamConfig{
Protocol: internet.TransportProtocol_WebSocket,
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
Certificate: []*tls.Certificate{tls.ParseCertificate(cert.MustGenerate(nil))},
2017-02-08 16:57:21 +00:00
}),
},
},
}),
ProxySettings: serial.ToTypedMessage(&inbound.Config{
User: []*protocol.User{
{
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
},
},
}),
},
},
Outbound: []*core.OutboundHandlerConfig{
2017-02-08 16:57:21 +00:00
{
ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
},
},
}
2018-03-01 10:53:39 +00:00
clientPort := tcp.PickPort()
2017-02-08 16:57:21 +00:00
clientConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
2017-02-08 16:57:21 +00:00
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(clientPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
2017-02-08 16:57:21 +00:00
}),
ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
Address: net.NewIPOrDomain(dest.Address),
2017-02-08 16:57:21 +00:00
Port: uint32(dest.Port),
NetworkList: &net.NetworkList{
Network: []net.Network{net.Network_TCP},
2017-02-08 16:57:21 +00:00
},
}),
},
},
Outbound: []*core.OutboundHandlerConfig{
2017-02-08 16:57:21 +00:00
{
ProxySettings: serial.ToTypedMessage(&outbound.Config{
Receiver: []*protocol.ServerEndpoint{
{
Address: net.NewIPOrDomain(net.LocalHostIP),
2017-02-08 16:57:21 +00:00
Port: uint32(serverPort),
User: []*protocol.User{
{
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
},
},
},
},
}),
SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
StreamSettings: &internet.StreamConfig{
Protocol: internet.TransportProtocol_WebSocket,
TransportSettings: []*internet.TransportConfig{
{
Protocol: internet.TransportProtocol_WebSocket,
Settings: serial.ToTypedMessage(&websocket.Config{}),
2017-02-08 16:57:21 +00:00
},
},
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
AllowInsecure: true,
}),
},
},
}),
},
},
}
2017-05-17 22:39:30 +00:00
servers, err := InitializeServerConfigs(serverConfig, clientConfig)
2017-10-24 14:15:35 +00:00
assert(err, IsNil)
2017-02-08 16:57:21 +00:00
conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
IP: []byte{127, 0, 0, 1},
Port: int(clientPort),
})
2017-10-24 14:15:35 +00:00
assert(err, IsNil)
2017-02-08 16:57:21 +00:00
payload := make([]byte, 10240*1024)
rand.Read(payload)
nBytes, err := conn.Write([]byte(payload))
2017-10-24 14:15:35 +00:00
assert(err, IsNil)
assert(nBytes, Equals, len(payload))
2017-02-08 16:57:21 +00:00
2017-04-16 19:31:33 +00:00
response := readFrom(conn, time.Second*20, len(payload))
2017-10-24 14:15:35 +00:00
assert(response, Equals, xor([]byte(payload)))
assert(conn.Close(), IsNil)
2017-02-08 16:57:21 +00:00
2017-05-17 22:39:30 +00:00
CloseAllServers(servers)
2017-02-08 16:57:21 +00:00
}
2018-03-01 20:22:53 +00:00
func TestHTTP2(t *testing.T) {
assert := With(t)
tcpServer := tcp.Server{
MsgProcessor: xor,
}
dest, err := tcpServer.Start()
assert(err, IsNil)
defer tcpServer.Close()
userID := protocol.NewID(uuid.New())
serverPort := tcp.PickPort()
serverConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(serverPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
StreamSettings: &internet.StreamConfig{
Protocol: internet.TransportProtocol_HTTP,
TransportSettings: []*internet.TransportConfig{
{
Protocol: internet.TransportProtocol_HTTP,
Settings: serial.ToTypedMessage(&http.Config{
Host: []string{"v2ray.com"},
Path: "/testpath",
}),
},
},
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
Certificate: []*tls.Certificate{tls.ParseCertificate(cert.MustGenerate(nil))},
2018-03-01 20:22:53 +00:00
}),
},
},
}),
ProxySettings: serial.ToTypedMessage(&inbound.Config{
User: []*protocol.User{
{
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
},
},
}),
},
},
Outbound: []*core.OutboundHandlerConfig{
{
ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
},
},
}
clientPort := tcp.PickPort()
clientConfig := &core.Config{
Inbound: []*core.InboundHandlerConfig{
{
ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
PortRange: net.SinglePortRange(clientPort),
Listen: net.NewIPOrDomain(net.LocalHostIP),
}),
ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
Address: net.NewIPOrDomain(dest.Address),
Port: uint32(dest.Port),
NetworkList: &net.NetworkList{
Network: []net.Network{net.Network_TCP},
},
}),
},
},
Outbound: []*core.OutboundHandlerConfig{
{
ProxySettings: serial.ToTypedMessage(&outbound.Config{
Receiver: []*protocol.ServerEndpoint{
{
Address: net.NewIPOrDomain(net.LocalHostIP),
Port: uint32(serverPort),
User: []*protocol.User{
{
Account: serial.ToTypedMessage(&vmess.Account{
Id: userID.String(),
}),
},
},
},
},
}),
SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
StreamSettings: &internet.StreamConfig{
Protocol: internet.TransportProtocol_HTTP,
TransportSettings: []*internet.TransportConfig{
{
Protocol: internet.TransportProtocol_HTTP,
Settings: serial.ToTypedMessage(&http.Config{
Host: []string{"v2ray.com"},
Path: "/testpath",
}),
},
},
SecurityType: serial.GetMessageType(&tls.Config{}),
SecuritySettings: []*serial.TypedMessage{
serial.ToTypedMessage(&tls.Config{
AllowInsecure: true,
}),
},
},
}),
},
},
}
servers, err := InitializeServerConfigs(serverConfig, clientConfig)
assert(err, IsNil)
2018-03-01 20:42:42 +00:00
var wg sync.WaitGroup
for i := 0; i < 10; i++ {
wg.Add(1)
go func() {
defer wg.Done()
conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
IP: []byte{127, 0, 0, 1},
Port: int(clientPort),
})
assert(err, IsNil)
payload := make([]byte, 10240*1024)
rand.Read(payload)
nBytes, err := conn.Write([]byte(payload))
assert(err, IsNil)
assert(nBytes, Equals, len(payload))
response := readFrom(conn, time.Second*20, len(payload))
assert(response, Equals, xor([]byte(payload)))
assert(conn.Close(), IsNil)
}()
}
wg.Wait()
2018-03-01 20:22:53 +00:00
CloseAllServers(servers)
}