yahns Ruby server user/dev discussion
 help / color / mirror / Atom feed
7909094ec5106bb262831521d1c9e079379186c3 blob 6624 bytes (raw)

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
 
# Copyright (C) 2013-2016 all contributors <yahns-public@yhbt.net>
# License: GPL-3.0+ (https://www.gnu.org/licenses/gpl-3.0.txt)
# frozen_string_literal: true
require_relative 'server_helper'
require 'openssl'
class TestSSL < Testcase
  ENV["N"].to_i > 1 and parallelize_me!
  include ServerHelper

  r, w = IO.pipe
  FAST_NB = begin
    :wait_readable == r.read_nonblock(1, exception: false)
  rescue
    false
  end
  r.close
  w.close

  # copied from test/openssl/utils.rb in Ruby:

  TEST_KEY_DH1024 = OpenSSL::PKey::DH.new <<-_end_of_pem_
-----BEGIN DH PARAMETERS-----
MIGHAoGBAKnKQ8MNK6nYZzLrrcuTsLxuiJGXoOO5gT+tljOTbHBuiktdMTITzIY0
pFxIvjG05D7HoBZQfrR0c92NGWPkAiCkhQKB8JCbPVzwNLDy6DZ0pmofDKrEsYHG
AQjjxMXhwULlmuR/K+WwlaZPiLIBYalLAZQ7ZbOPeVkJ8ePao0eLAgEC
-----END DH PARAMETERS-----
  _end_of_pem_

  def setup
    unless FAST_NB
      skip "missing exception-free non-blocking IO in " \
           "#{RUBY_ENGINE} #{RUBY_VERSION}"
    end
    server_helper_setup
  end

  def teardown
    server_helper_teardown
  end

  def ssl_client(host, port)
    ctx = OpenSSL::SSL::SSLContext.new
    ctx.ciphers = "ADH"
    ctx.security_level = 0
    s = TCPSocket.new(host, port)
    ssl = OpenSSL::SSL::SSLSocket.new(s, ctx)
    ssl.connect
    ssl.sync_close = true
    ssl
  end

  def srv_ctx
    ctx = OpenSSL::SSL::SSLContext.new
    ctx.ciphers = "ADH"
    ctx.security_level = 0
    ctx.tmp_dh_callback = proc { TEST_KEY_DH1024 }
    ctx
  end

  def test_ssl_basic
    err, cfg, host, port = @err, Yahns::Config.new, @srv.addr[3], @srv.addr[1]
    insecure = TCPServer.new(ENV["TEST_HOST"] || "127.0.0.1", 0)
    ctx = srv_ctx
    raw = File.read(__FILE__)
    pid = mkserver(cfg) do
      ENV["YAHNS_FD"] += ",#{insecure.fileno.to_s}"
      cfg.instance_eval do
        ru = lambda do |env|
          case path_info = env['PATH_INFO']
          when '/rack.url_scheme', '/HTTPS', '/SERVER_PORT'
            s = env[path_info[1..-1]] # remove leading slash
            s = s.inspect if s.nil?
            [ 200, {
                'Content-Length' => s.bytesize.to_s,
                'Content-Type'=>'text/plain',
              }, [ s ] ]
          when '/static'
            f = File.open(__FILE__)
            [ 200, {
                'Content-Length' => f.size.to_s,
                'Content-Type'=>'text/plain',
              },
              f ]
          else
            [ 200, {'Content-Length'=>'2'}, ['HI'] ]
          end
        end
        app(:rack, ru) {
          listen "#{host}:#{port}", ssl_ctx: ctx
          listen "#{insecure.addr[3]}:#{insecure.addr[1]}"
        }
        logger(Logger.new(err.path))
      end
    end
    client = ssl_client(host, port)
    buf = ''.dup
    { '/' => 'HI',
      '/rack.url_scheme' => 'https',
      '/HTTPS' => 'on',
      '/SERVER_PORT' => '443',
    }.each do |path, exp|
      client.write("GET #{path} HTTP/1.1\r\nHost: example.com\r\n\r\n")
      buf.clear
      re = /#{Regexp.escape(exp)}\z/
      Timeout.timeout(60) do
        buf << client.readpartial(111) until buf =~ re
      end
      head, body = buf.split("\r\n\r\n", 2)
      assert_equal exp, body
      assert_match %r{\AHTTP/1\.\d 200 OK\r\n}, head
    end

    # use port in Host: header (implemented by unicorn_http parser)
    exp = '666'
    client.write("GET /SERVER_PORT HTTP/1.1\r\nHost: example.com:#{exp}\r\n\r\n")
    re = /#{Regexp.escape(exp)}\z/
    buf.clear
    Timeout.timeout(60) do
      buf << client.readpartial(111) until buf =~ re
    end
    head, body = buf.split("\r\n\r\n", 2)
    assert_equal exp, body
    assert_match %r{\AHTTP/1\.\d 200 OK\r\n}, head

    Net::HTTP.start(insecure.addr[3], insecure.addr[1]) do |h|
      res = h.get('/rack.url_scheme')
      assert_equal 'http', res.body
      res = h.get('/HTTPS')
      assert_equal 'nil', res.body
      res = h.get('/SERVER_PORT')
      assert_equal insecure.addr[1].to_s, res.body
    end

    # read static file
    client.write("GET /static HTTP/1.1\r\nHost: example.com\r\n\r\n")
    buf.clear
    Timeout.timeout(60) do
      buf << client.readpartial(8192) until buf.include?(raw)
    end
    head, body = buf.split("\r\n\r\n", 2)
    assert_match %r{\AHTTP/1\.\d 200 OK\r\n}, head
    assert_equal raw, body

    client.write("GET / HTTP/1.0\r\n\r\n")
    head, body = client.read.split("\r\n\r\n", 2)
    assert_equal "HI", body
    assert_match %r{\AHTTP/1\.\d 200 OK\r\n}, head
  ensure
    insecure.close if insecure
    client.close if client
    quit_wait(pid)
  end

  def test_ssl_hijack
    err, cfg, host, port = @err, Yahns::Config.new, @srv.addr[3], @srv.addr[1]
    ctx = srv_ctx
    pid = mkserver(cfg) do
      cfg.instance_eval do
        ru = lambda do |env|
          io = env['rack.hijack'].call
          Thread.new(io) do |s|
            s.write "HTTP/1.1 201 Switching Protocols\r\n\r\n"
            case req = s.gets
            when "inspect\n"
              s.puts(s.instance_variable_get(:@ssl).inspect)
            when "remote_address\n"
              s.puts(s.remote_address.inspect)
            when "each\n"
              line = ''.dup
              s.each do |l|
                l.strip!
                line << l
                break if l == 'd'
              end
              s.puts line
            when "missing\n"
              begin
                s.any_old_invalid_test_method
                s.puts "FAIL"
              rescue => e
                s.puts "#{e.class}: #{e.message}"
              end
            when nil
              s.close
            else
              p [ :ERR, req ]
            end until s.closed?
          end
          [ 200, DieIfUsed.new, DieIfUsed.new ]
        end
        app(:rack, ru) { listen "#{host}:#{port}", ssl_ctx: ctx }
        logger(Logger.new(err.path))
        stderr_path err.path
      end
    end
    client = ssl_client(host, port)
    client.write("GET / HTTP/1.0\r\n\r\n")

    Timeout.timeout(60) do
      assert_equal "HTTP/1.1 201 Switching Protocols\r\n", client.gets
      assert_equal "\r\n", client.gets
      client.puts "inspect"
      assert_match %r{SSLSocket}, client.gets
      client.puts "remote_address"
      assert_equal client.to_io.local_address.inspect, client.gets.strip
      client.puts "missing"
      assert_match %r{NoMethodError}, client.gets

      client.puts "each"
      %w(a b c d).each { |x| client.puts(x) }
      assert_equal "abcd", client.gets.strip
    end
    errs = File.readlines(err.path).grep(/DieIfUsed/)
    assert_equal([ "INFO #{pid} closed DieIfUsed 1\n" ], errs)
  ensure
    client.close if client
    quit_wait(pid)
  end
end if defined?(OpenSSL)
debug log:

solving 7909094 ...
found 7909094 in https://yhbt.net/yahns.git

yahns Ruby server user/dev discussion

This inbox may be cloned and mirrored by anyone:

	git clone --mirror https://yhbt.net/yahns-public
	git clone --mirror http://ou63pmih66umazou.onion/yahns-public

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V1 yahns-public yahns-public/ https://yhbt.net/yahns-public \
		yahns-public@yhbt.net yahns-public@rubyforge.org
	public-inbox-index yahns-public

Example config snippet for mirrors.
Newsgroups are available over NNTP:
	nntp://news.public-inbox.org/inbox.comp.lang.ruby.yahns
	nntp://ou63pmih66umazou.onion/inbox.comp.lang.ruby.yahns
 note: .onion URLs require Tor: https://www.torproject.org/

code repositories for the project(s) associated with this inbox:

	../../../yahns.git

AGPL code for this site: git clone http://ou63pmih66umazou.onion/public-inbox.git