tlstransport.cpp 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747
  1. /**
  2. * Copyright (c) 2020 Paul-Louis Ageneau
  3. *
  4. * This Source Code Form is subject to the terms of the Mozilla Public
  5. * License, v. 2.0. If a copy of the MPL was not distributed with this
  6. * file, You can obtain one at https://mozilla.org/MPL/2.0/.
  7. */
  8. #include "tlstransport.hpp"
  9. #include "httpproxytransport.hpp"
  10. #include "tcptransport.hpp"
  11. #include "threadpool.hpp"
  12. #if RTC_ENABLE_WEBSOCKET
  13. #include <algorithm>
  14. #include <chrono>
  15. #include <cstring>
  16. #include <exception>
  17. using namespace std::chrono;
  18. namespace rtc::impl {
  19. void TlsTransport::enqueueRecv() {
  20. if (mPendingRecvCount > 0)
  21. return;
  22. if (auto shared_this = weak_from_this().lock()) {
  23. ++mPendingRecvCount;
  24. ThreadPool::Instance().enqueue(&TlsTransport::doRecv, std::move(shared_this));
  25. }
  26. }
  27. #if USE_GNUTLS
  28. namespace {
  29. gnutls_certificate_credentials_t default_certificate_credentials() {
  30. static std::mutex mutex;
  31. static shared_ptr<gnutls_certificate_credentials_t> creds;
  32. std::lock_guard lock(mutex);
  33. if (!creds) {
  34. creds = shared_ptr<gnutls_certificate_credentials_t>(gnutls::new_credentials(),
  35. gnutls::free_credentials);
  36. gnutls::check(gnutls_certificate_set_x509_system_trust(*creds));
  37. }
  38. return *creds;
  39. }
  40. } // namespace
  41. void TlsTransport::Init() {
  42. // Nothing to do
  43. }
  44. void TlsTransport::Cleanup() {
  45. // Nothing to do
  46. }
  47. TlsTransport::TlsTransport(variant<shared_ptr<TcpTransport>, shared_ptr<HttpProxyTransport>> lower,
  48. optional<string> host, certificate_ptr certificate,
  49. state_callback callback)
  50. : Transport(std::visit([](auto l) { return std::static_pointer_cast<Transport>(l); }, lower),
  51. std::move(callback)),
  52. mHost(std::move(host)), mIsClient(std::visit([](auto l) { return l->isActive(); }, lower)),
  53. mIncomingQueue(RECV_QUEUE_LIMIT, message_size_func) {
  54. PLOG_DEBUG << "Initializing TLS transport (GnuTLS)";
  55. unsigned int flags = GNUTLS_NONBLOCK | (mIsClient ? GNUTLS_CLIENT : GNUTLS_SERVER);
  56. gnutls::check(gnutls_init(&mSession, flags));
  57. try {
  58. const char *priorities = "SECURE128:-VERS-SSL3.0:-ARCFOUR-128";
  59. const char *err_pos = NULL;
  60. gnutls::check(gnutls_priority_set_direct(mSession, priorities, &err_pos),
  61. "Failed to set TLS priorities");
  62. gnutls::check(gnutls_credentials_set(mSession, GNUTLS_CRD_CERTIFICATE,
  63. certificate ? certificate->credentials()
  64. : default_certificate_credentials()));
  65. if (mIsClient && mHost) {
  66. PLOG_VERBOSE << "Server Name Indication: " << *mHost;
  67. gnutls_server_name_set(mSession, GNUTLS_NAME_DNS, mHost->data(), mHost->size());
  68. }
  69. gnutls_session_set_ptr(mSession, this);
  70. gnutls_transport_set_ptr(mSession, this);
  71. gnutls_transport_set_push_function(mSession, WriteCallback);
  72. gnutls_transport_set_pull_function(mSession, ReadCallback);
  73. gnutls_transport_set_pull_timeout_function(mSession, TimeoutCallback);
  74. } catch (...) {
  75. gnutls_deinit(mSession);
  76. throw;
  77. }
  78. }
  79. TlsTransport::~TlsTransport() {
  80. stop();
  81. gnutls_deinit(mSession);
  82. }
  83. void TlsTransport::start() {
  84. PLOG_DEBUG << "Starting TLS transport";
  85. registerIncoming();
  86. changeState(State::Connecting);
  87. enqueueRecv(); // to initiate the handshake
  88. }
  89. void TlsTransport::stop() {
  90. PLOG_DEBUG << "Stopping TLS transport";
  91. unregisterIncoming();
  92. mIncomingQueue.stop();
  93. enqueueRecv();
  94. }
  95. bool TlsTransport::send(message_ptr message) {
  96. if (state() != State::Connected)
  97. throw std::runtime_error("TLS is not open");
  98. if (!message || message->size() == 0)
  99. return outgoing(message); // pass through
  100. PLOG_VERBOSE << "Send size=" << message->size();
  101. ssize_t ret;
  102. do {
  103. ret = gnutls_record_send(mSession, message->data(), message->size());
  104. } while (ret == GNUTLS_E_INTERRUPTED || ret == GNUTLS_E_AGAIN);
  105. if (!gnutls::check(ret))
  106. throw std::runtime_error("TLS send failed");
  107. return mOutgoingResult;
  108. }
  109. void TlsTransport::incoming(message_ptr message) {
  110. if (!message) {
  111. mIncomingQueue.stop();
  112. enqueueRecv();
  113. return;
  114. }
  115. PLOG_VERBOSE << "Incoming size=" << message->size();
  116. mIncomingQueue.push(message);
  117. enqueueRecv();
  118. }
  119. bool TlsTransport::outgoing(message_ptr message) {
  120. bool result = Transport::outgoing(std::move(message));
  121. mOutgoingResult = result;
  122. return result;
  123. }
  124. void TlsTransport::postHandshake() {
  125. // Dummy
  126. }
  127. void TlsTransport::doRecv() {
  128. std::lock_guard lock(mRecvMutex);
  129. --mPendingRecvCount;
  130. const size_t bufferSize = 4096;
  131. char buffer[bufferSize];
  132. try {
  133. // Handle handshake if connecting
  134. if (state() == State::Connecting) {
  135. int ret;
  136. do {
  137. ret = gnutls_handshake(mSession);
  138. if (ret == GNUTLS_E_AGAIN)
  139. return;
  140. } while (!gnutls::check(ret, "TLS handshake failed")); // Re-call on non-fatal error
  141. PLOG_INFO << "TLS handshake finished";
  142. changeState(State::Connected);
  143. postHandshake();
  144. }
  145. if (state() == State::Connected) {
  146. while (true) {
  147. ssize_t ret = gnutls_record_recv(mSession, buffer, bufferSize);
  148. if (ret == GNUTLS_E_AGAIN)
  149. return;
  150. // Consider premature termination as remote closing
  151. if (ret == GNUTLS_E_PREMATURE_TERMINATION) {
  152. PLOG_DEBUG << "TLS connection terminated";
  153. break;
  154. }
  155. if (gnutls::check(ret)) {
  156. if (ret == 0) {
  157. // Closed
  158. PLOG_DEBUG << "TLS connection cleanly closed";
  159. break;
  160. }
  161. auto *b = reinterpret_cast<byte *>(buffer);
  162. recv(make_message(b, b + ret));
  163. }
  164. }
  165. }
  166. } catch (const std::exception &e) {
  167. PLOG_ERROR << "TLS recv: " << e.what();
  168. }
  169. gnutls_bye(mSession, GNUTLS_SHUT_WR);
  170. PLOG_INFO << "TLS closed";
  171. changeState(State::Disconnected);
  172. recv(nullptr);
  173. }
  174. ssize_t TlsTransport::WriteCallback(gnutls_transport_ptr_t ptr, const void *data, size_t len) {
  175. TlsTransport *t = static_cast<TlsTransport *>(ptr);
  176. try {
  177. if (len > 0) {
  178. auto b = reinterpret_cast<const byte *>(data);
  179. t->outgoing(make_message(b, b + len));
  180. }
  181. gnutls_transport_set_errno(t->mSession, 0);
  182. return ssize_t(len);
  183. } catch (const std::exception &e) {
  184. PLOG_WARNING << e.what();
  185. gnutls_transport_set_errno(t->mSession, ECONNRESET);
  186. return -1;
  187. }
  188. }
  189. ssize_t TlsTransport::ReadCallback(gnutls_transport_ptr_t ptr, void *data, size_t maxlen) {
  190. TlsTransport *t = static_cast<TlsTransport *>(ptr);
  191. try {
  192. message_ptr &message = t->mIncomingMessage;
  193. size_t &position = t->mIncomingMessagePosition;
  194. if (message && position >= message->size())
  195. message.reset();
  196. if (!message) {
  197. position = 0;
  198. while (auto next = t->mIncomingQueue.pop()) {
  199. message = *next;
  200. if (message->size() > 0)
  201. break;
  202. else
  203. t->recv(message); // Pass zero-sized messages through
  204. }
  205. }
  206. if (message) {
  207. size_t available = message->size() - position;
  208. ssize_t len = std::min(maxlen, available);
  209. std::memcpy(data, message->data() + position, len);
  210. position += len;
  211. gnutls_transport_set_errno(t->mSession, 0);
  212. return len;
  213. } else if (t->mIncomingQueue.running()) {
  214. gnutls_transport_set_errno(t->mSession, EAGAIN);
  215. return -1;
  216. } else {
  217. // Closed
  218. gnutls_transport_set_errno(t->mSession, 0);
  219. return 0;
  220. }
  221. } catch (const std::exception &e) {
  222. PLOG_WARNING << e.what();
  223. gnutls_transport_set_errno(t->mSession, ECONNRESET);
  224. return -1;
  225. }
  226. }
  227. int TlsTransport::TimeoutCallback(gnutls_transport_ptr_t ptr, unsigned int /* ms */) {
  228. TlsTransport *t = static_cast<TlsTransport *>(ptr);
  229. try {
  230. message_ptr &message = t->mIncomingMessage;
  231. size_t &position = t->mIncomingMessagePosition;
  232. if (message && position < message->size())
  233. return 1;
  234. return !t->mIncomingQueue.empty() ? 1 : 0;
  235. } catch (const std::exception &e) {
  236. PLOG_WARNING << e.what();
  237. return 1;
  238. }
  239. }
  240. #elif USE_MBEDTLS
  241. void TlsTransport::Init() {
  242. // Nothing to do
  243. }
  244. void TlsTransport::Cleanup() {
  245. // Nothing to do
  246. }
  247. TlsTransport::TlsTransport(variant<shared_ptr<TcpTransport>, shared_ptr<HttpProxyTransport>> lower,
  248. optional<string> host, certificate_ptr certificate,
  249. state_callback callback)
  250. : Transport(std::visit([](auto l) { return std::static_pointer_cast<Transport>(l); }, lower),
  251. std::move(callback)),
  252. mHost(std::move(host)), mIsClient(std::visit([](auto l) { return l->isActive(); }, lower)),
  253. mIncomingQueue(RECV_QUEUE_LIMIT, message_size_func) {
  254. PLOG_DEBUG << "Initializing TLS transport (MbedTLS)";
  255. mbedtls_entropy_init(&mEntropy);
  256. mbedtls_ctr_drbg_init(&mDrbg);
  257. mbedtls_ssl_init(&mSsl);
  258. mbedtls_ssl_config_init(&mConf);
  259. mbedtls_ctr_drbg_set_prediction_resistance(&mDrbg, MBEDTLS_CTR_DRBG_PR_ON);
  260. try {
  261. mbedtls::check(mbedtls_ctr_drbg_seed(&mDrbg, mbedtls_entropy_func, &mEntropy, NULL, 0));
  262. mbedtls::check(mbedtls_ssl_config_defaults(
  263. &mConf, mIsClient ? MBEDTLS_SSL_IS_CLIENT : MBEDTLS_SSL_IS_SERVER,
  264. MBEDTLS_SSL_TRANSPORT_STREAM, MBEDTLS_SSL_PRESET_DEFAULT));
  265. mbedtls_ssl_conf_authmode(&mConf, MBEDTLS_SSL_VERIFY_OPTIONAL);
  266. mbedtls_ssl_conf_rng(&mConf, mbedtls_ctr_drbg_random, &mDrbg);
  267. if (certificate) {
  268. auto [crt, pk] = certificate->credentials();
  269. mbedtls::check(mbedtls_ssl_conf_own_cert(&mConf, crt.get(), pk.get()));
  270. }
  271. mbedtls::check(mbedtls_ssl_setup(&mSsl, &mConf));
  272. mbedtls_ssl_set_bio(&mSsl, static_cast<void *>(this), WriteCallback, ReadCallback, NULL);
  273. } catch (...) {
  274. mbedtls_entropy_free(&mEntropy);
  275. mbedtls_ctr_drbg_free(&mDrbg);
  276. mbedtls_ssl_free(&mSsl);
  277. mbedtls_ssl_config_free(&mConf);
  278. throw;
  279. }
  280. }
  281. TlsTransport::~TlsTransport() {}
  282. void TlsTransport::start() {
  283. PLOG_DEBUG << "Starting TLS transport";
  284. registerIncoming();
  285. changeState(State::Connecting);
  286. enqueueRecv(); // to initiate the handshake
  287. }
  288. void TlsTransport::stop() {
  289. PLOG_DEBUG << "Stopping TLS transport";
  290. unregisterIncoming();
  291. mIncomingQueue.stop();
  292. enqueueRecv();
  293. }
  294. bool TlsTransport::send(message_ptr message) {
  295. if (state() != State::Connected)
  296. throw std::runtime_error("TLS is not open");
  297. if (!message || message->size() == 0)
  298. return outgoing(message); // pass through
  299. PLOG_VERBOSE << "Send size=" << message->size();
  300. mbedtls::check(mbedtls_ssl_write(
  301. &mSsl, reinterpret_cast<const unsigned char *>(message->data()), int(message->size())));
  302. return mOutgoingResult;
  303. }
  304. void TlsTransport::incoming(message_ptr message) {
  305. if (!message) {
  306. mIncomingQueue.stop();
  307. enqueueRecv();
  308. return;
  309. }
  310. PLOG_VERBOSE << "Incoming size=" << message->size();
  311. mIncomingQueue.push(message);
  312. enqueueRecv();
  313. }
  314. bool TlsTransport::outgoing(message_ptr message) {
  315. bool result = Transport::outgoing(std::move(message));
  316. mOutgoingResult = result;
  317. return result;
  318. }
  319. void TlsTransport::postHandshake() {
  320. // Dummy
  321. }
  322. void TlsTransport::doRecv() {
  323. std::lock_guard lock(mRecvMutex);
  324. --mPendingRecvCount;
  325. if (state() != State::Connecting && state() != State::Connected)
  326. return;
  327. try {
  328. const size_t bufferSize = 4096;
  329. char buffer[bufferSize];
  330. // Handle handshake if connecting
  331. if (state() == State::Connecting) {
  332. while (true) {
  333. auto ret = mbedtls_ssl_handshake(&mSsl);
  334. if (ret == MBEDTLS_ERR_SSL_WANT_READ || ret == MBEDTLS_ERR_SSL_WANT_WRITE) {
  335. return;
  336. } else if ( ret == MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS || ret == MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS) {
  337. continue;
  338. }
  339. mbedtls::check(ret);
  340. PLOG_INFO << "TLS handshake finished";
  341. changeState(State::Connected);
  342. postHandshake();
  343. break;
  344. }
  345. }
  346. if (state() == State::Connected) {
  347. while (true) {
  348. auto ret =
  349. mbedtls_ssl_read(&mSsl, reinterpret_cast<unsigned char *>(buffer), bufferSize);
  350. if (ret == 0 || ret == MBEDTLS_ERR_SSL_PEER_CLOSE_NOTIFY) {
  351. // Closed
  352. PLOG_DEBUG << "TLS connection cleanly closed";
  353. break;
  354. }
  355. if (ret == MBEDTLS_ERR_SSL_WANT_READ || ret == MBEDTLS_ERR_SSL_WANT_WRITE) {
  356. return;
  357. } else if ( ret == MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS || ret == MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS) {
  358. continue;
  359. }
  360. mbedtls::check(ret);
  361. auto *b = reinterpret_cast<byte *>(buffer);
  362. recv(make_message(b, b + ret));
  363. }
  364. }
  365. } catch (const std::exception &e) {
  366. PLOG_ERROR << "TLS recv: " << e.what();
  367. }
  368. PLOG_INFO << "TLS closed";
  369. changeState(State::Disconnected);
  370. recv(nullptr);
  371. }
  372. int TlsTransport::WriteCallback(void *ctx, const unsigned char *buf, size_t len) {
  373. auto *t = static_cast<TlsTransport *>(ctx);
  374. auto *b = reinterpret_cast<const byte *>(buf);
  375. t->outgoing(make_message(b, b + len));
  376. return int(len);
  377. }
  378. int TlsTransport::ReadCallback(void *ctx, unsigned char *buf, size_t len) {
  379. TlsTransport *t = static_cast<TlsTransport *>(ctx);
  380. try {
  381. message_ptr &message = t->mIncomingMessage;
  382. size_t &position = t->mIncomingMessagePosition;
  383. if (message && position >= message->size())
  384. message.reset();
  385. if (!message) {
  386. position = 0;
  387. while (auto next = t->mIncomingQueue.pop()) {
  388. message = *next;
  389. if (message->size() > 0)
  390. break;
  391. else
  392. t->recv(message); // Pass zero-sized messages through
  393. }
  394. }
  395. if (message) {
  396. size_t available = message->size() - position;
  397. size_t writeLen = std::min(len, available);
  398. std::memcpy(buf, message->data() + position, writeLen);
  399. position += writeLen;
  400. return int(writeLen);
  401. } else if (t->mIncomingQueue.running()) {
  402. return MBEDTLS_ERR_SSL_WANT_READ;
  403. } else {
  404. return MBEDTLS_ERR_SSL_CONN_EOF;
  405. }
  406. } catch (const std::exception &e) {
  407. PLOG_WARNING << e.what();
  408. return MBEDTLS_ERR_SSL_INTERNAL_ERROR;
  409. }
  410. }
  411. #else
  412. int TlsTransport::TransportExIndex = -1;
  413. void TlsTransport::Init() {
  414. openssl::init();
  415. if (TransportExIndex < 0) {
  416. TransportExIndex = SSL_get_ex_new_index(0, NULL, NULL, NULL, NULL);
  417. }
  418. }
  419. void TlsTransport::Cleanup() {
  420. // Nothing to do
  421. }
  422. TlsTransport::TlsTransport(variant<shared_ptr<TcpTransport>, shared_ptr<HttpProxyTransport>> lower,
  423. optional<string> host, certificate_ptr certificate,
  424. state_callback callback)
  425. : Transport(std::visit([](auto l) { return std::static_pointer_cast<Transport>(l); }, lower),
  426. std::move(callback)),
  427. mHost(std::move(host)), mIsClient(std::visit([](auto l) { return l->isActive(); }, lower)),
  428. mIncomingQueue(RECV_QUEUE_LIMIT, message_size_func) {
  429. PLOG_DEBUG << "Initializing TLS transport (OpenSSL)";
  430. try {
  431. if (!(mCtx = SSL_CTX_new(SSLv23_method()))) // version-flexible
  432. throw std::runtime_error("Failed to create SSL context");
  433. openssl::check(SSL_CTX_set_cipher_list(mCtx, "ALL:!LOW:!EXP:!RC4:!MD5:@STRENGTH"),
  434. "Failed to set SSL priorities");
  435. if (certificate) {
  436. auto [x509, pkey] = certificate->credentials();
  437. SSL_CTX_use_certificate(mCtx, x509);
  438. SSL_CTX_use_PrivateKey(mCtx, pkey);
  439. } else {
  440. if (!SSL_CTX_set_default_verify_paths(mCtx)) {
  441. PLOG_WARNING << "SSL root CA certificates unavailable";
  442. }
  443. }
  444. SSL_CTX_set_options(mCtx, SSL_OP_NO_SSLv3);
  445. SSL_CTX_set_min_proto_version(mCtx, TLS1_VERSION);
  446. SSL_CTX_set_read_ahead(mCtx, 1);
  447. SSL_CTX_set_quiet_shutdown(mCtx, 1);
  448. SSL_CTX_set_info_callback(mCtx, InfoCallback);
  449. SSL_CTX_set_verify(mCtx, SSL_VERIFY_NONE, NULL);
  450. if (!(mSsl = SSL_new(mCtx)))
  451. throw std::runtime_error("Failed to create SSL instance");
  452. SSL_set_ex_data(mSsl, TransportExIndex, this);
  453. if (mIsClient && mHost) {
  454. SSL_set_hostflags(mSsl, 0);
  455. openssl::check(SSL_set1_host(mSsl, mHost->c_str()), "Failed to set SSL host");
  456. PLOG_VERBOSE << "Server Name Indication: " << *mHost;
  457. SSL_set_tlsext_host_name(mSsl, mHost->c_str());
  458. }
  459. if (mIsClient)
  460. SSL_set_connect_state(mSsl);
  461. else
  462. SSL_set_accept_state(mSsl);
  463. if (!(mInBio = BIO_new(BIO_s_mem())) || !(mOutBio = BIO_new(BIO_s_mem())))
  464. throw std::runtime_error("Failed to create BIO");
  465. BIO_set_mem_eof_return(mInBio, BIO_EOF);
  466. BIO_set_mem_eof_return(mOutBio, BIO_EOF);
  467. SSL_set_bio(mSsl, mInBio, mOutBio);
  468. auto ecdh = unique_ptr<EC_KEY, decltype(&EC_KEY_free)>(
  469. EC_KEY_new_by_curve_name(NID_X9_62_prime256v1), EC_KEY_free);
  470. SSL_set_options(mSsl, SSL_OP_SINGLE_ECDH_USE);
  471. SSL_set_tmp_ecdh(mSsl, ecdh.get());
  472. } catch (...) {
  473. if (mSsl)
  474. SSL_free(mSsl);
  475. if (mCtx)
  476. SSL_CTX_free(mCtx);
  477. throw;
  478. }
  479. }
  480. TlsTransport::~TlsTransport() {
  481. stop();
  482. SSL_free(mSsl);
  483. SSL_CTX_free(mCtx);
  484. }
  485. void TlsTransport::start() {
  486. PLOG_DEBUG << "Starting TLS transport";
  487. registerIncoming();
  488. changeState(State::Connecting);
  489. // Initiate the handshake
  490. int ret = SSL_do_handshake(mSsl);
  491. openssl::check(mSsl, ret, "Handshake initiation failed");
  492. flushOutput();
  493. }
  494. void TlsTransport::stop() {
  495. PLOG_DEBUG << "Stopping TLS transport";
  496. unregisterIncoming();
  497. mIncomingQueue.stop();
  498. enqueueRecv();
  499. }
  500. bool TlsTransport::send(message_ptr message) {
  501. if (state() != State::Connected)
  502. throw std::runtime_error("TLS is not open");
  503. if (!message || message->size() == 0)
  504. return outgoing(message); // pass through
  505. PLOG_VERBOSE << "Send size=" << message->size();
  506. int ret = SSL_write(mSsl, message->data(), int(message->size()));
  507. if (!openssl::check(mSsl, ret))
  508. throw std::runtime_error("TLS send failed");
  509. return flushOutput();
  510. }
  511. void TlsTransport::incoming(message_ptr message) {
  512. if (!message) {
  513. mIncomingQueue.stop();
  514. enqueueRecv();
  515. return;
  516. }
  517. PLOG_VERBOSE << "Incoming size=" << message->size();
  518. mIncomingQueue.push(message);
  519. enqueueRecv();
  520. }
  521. bool TlsTransport::outgoing(message_ptr message) { return Transport::outgoing(std::move(message)); }
  522. void TlsTransport::postHandshake() {
  523. // Dummy
  524. }
  525. void TlsTransport::doRecv() {
  526. std::lock_guard lock(mRecvMutex);
  527. --mPendingRecvCount;
  528. if (state() != State::Connecting && state() != State::Connected)
  529. return;
  530. try {
  531. const size_t bufferSize = 4096;
  532. byte buffer[bufferSize];
  533. // Process incoming messages
  534. while (mIncomingQueue.running()) {
  535. auto next = mIncomingQueue.pop();
  536. if (!next)
  537. return;
  538. message_ptr message = std::move(*next);
  539. if (message->size() > 0)
  540. BIO_write(mInBio, message->data(), int(message->size())); // Input
  541. else
  542. recv(message); // Pass zero-sized messages through
  543. if (state() == State::Connecting) {
  544. // Continue the handshake
  545. int ret = SSL_do_handshake(mSsl);
  546. if (!openssl::check(mSsl, ret, "Handshake failed"))
  547. break;
  548. flushOutput();
  549. if (SSL_is_init_finished(mSsl)) {
  550. PLOG_INFO << "TLS handshake finished";
  551. changeState(State::Connected);
  552. postHandshake();
  553. }
  554. }
  555. if (state() == State::Connected) {
  556. int ret;
  557. while ((ret = SSL_read(mSsl, buffer, bufferSize)) > 0)
  558. recv(make_message(buffer, buffer + ret));
  559. if (!openssl::check(mSsl, ret))
  560. break;
  561. }
  562. }
  563. } catch (const std::exception &e) {
  564. PLOG_ERROR << "TLS recv: " << e.what();
  565. }
  566. SSL_shutdown(mSsl);
  567. if (state() == State::Connected) {
  568. PLOG_INFO << "TLS closed";
  569. recv(nullptr);
  570. } else {
  571. PLOG_ERROR << "TLS handshake failed";
  572. }
  573. }
  574. bool TlsTransport::flushOutput() {
  575. const size_t bufferSize = 4096;
  576. byte buffer[bufferSize];
  577. int ret;
  578. bool result = true;
  579. while ((ret = BIO_read(mOutBio, buffer, bufferSize)) > 0)
  580. result = outgoing(make_message(buffer, buffer + ret));
  581. return result;
  582. }
  583. void TlsTransport::InfoCallback(const SSL *ssl, int where, int ret) {
  584. TlsTransport *t =
  585. static_cast<TlsTransport *>(SSL_get_ex_data(ssl, TlsTransport::TransportExIndex));
  586. if (where & SSL_CB_ALERT) {
  587. if (ret != 256) { // Close Notify
  588. PLOG_ERROR << "TLS alert: " << SSL_alert_desc_string_long(ret);
  589. }
  590. t->mIncomingQueue.stop(); // Close the connection
  591. }
  592. }
  593. #endif
  594. } // namespace rtc::impl
  595. #endif