yahns.git  about / heads / tags
sleepy, multi-threaded, non-blocking application server for Ruby
blob e89a89d94c117d767b108b1e38b8ff4e220514b5 6920 bytes (raw)
$ git show maint:test/test_ssl.rb	# shows this blob on the CLI

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
 
# Copyright (C) 2013-2016 all contributors <yahns-public@yhbt.net>
# License: GPL-3.0+ (https://www.gnu.org/licenses/gpl-3.0.txt)
# frozen_string_literal: true
require_relative 'server_helper'
require 'openssl'
class TestSSL < Testcase
  ENV["N"].to_i > 1 and parallelize_me!
  include ServerHelper

  r, w = IO.pipe
  FAST_NB = begin
    :wait_readable == r.read_nonblock(1, exception: false)
  rescue
    false
  end
  r.close
  w.close

  # copied from test/openssl/utils.rb in Ruby:

  TEST_KEY_DH1024 = OpenSSL::PKey::DH.new <<-_end_of_pem_
-----BEGIN DH PARAMETERS-----
MIGHAoGBAKnKQ8MNK6nYZzLrrcuTsLxuiJGXoOO5gT+tljOTbHBuiktdMTITzIY0
pFxIvjG05D7HoBZQfrR0c92NGWPkAiCkhQKB8JCbPVzwNLDy6DZ0pmofDKrEsYHG
AQjjxMXhwULlmuR/K+WwlaZPiLIBYalLAZQ7ZbOPeVkJ8ePao0eLAgEC
-----END DH PARAMETERS-----
  _end_of_pem_

  TEST_KEY_DH1024.priv_key = OpenSSL::BN.new("48561834C67E65FFD2A9B47F41" \
     "E5E78FDC95C387428FDB1E4B0188B64D1643C3A8D3455B945B7E8C4D166010C7C2" \
     "CE23BFB9BEF43D0348FE7FA5284B0225E7FE1537546D114E3D8A4411B9B9351AB4" \
     "51E1A358F50ED61B1F00DA29336EEBBD649980AC86D76AF8BBB065298C2052672E" \
     "EF3EF13AB47A15275FC2836F3AC74CEA", 16)

  def setup
    unless FAST_NB
      skip "missing exception-free non-blocking IO in " \
           "#{RUBY_ENGINE} #{RUBY_VERSION}"
    end
    server_helper_setup
  end

  def teardown
    server_helper_teardown
  end

  def ssl_client(host, port)
    ctx = OpenSSL::SSL::SSLContext.new
    ctx.ciphers = "ADH"
    s = TCPSocket.new(host, port)
    ssl = OpenSSL::SSL::SSLSocket.new(s, ctx)
    ssl.connect
    ssl.sync_close = true
    ssl
  end

  def srv_ctx
    ctx = OpenSSL::SSL::SSLContext.new
    ctx.ciphers = "ADH"
    ctx.tmp_dh_callback = proc { TEST_KEY_DH1024 }
    ctx
  end

  def test_ssl_basic
    err, cfg, host, port = @err, Yahns::Config.new, @srv.addr[3], @srv.addr[1]
    insecure = TCPServer.new(ENV["TEST_HOST"] || "127.0.0.1", 0)
    ctx = srv_ctx
    raw = File.read(__FILE__)
    pid = mkserver(cfg) do
      ENV["YAHNS_FD"] += ",#{insecure.fileno.to_s}"
      cfg.instance_eval do
        ru = lambda do |env|
          case path_info = env['PATH_INFO']
          when '/rack.url_scheme', '/HTTPS', '/SERVER_PORT'
            s = env[path_info[1..-1]] # remove leading slash
            s = s.inspect if s.nil?
            [ 200, {
                'Content-Length' => s.bytesize.to_s,
                'Content-Type'=>'text/plain',
              }, [ s ] ]
          when '/static'
            f = File.open(__FILE__)
            [ 200, {
                'Content-Length' => f.size.to_s,
                'Content-Type'=>'text/plain',
              },
              f ]
          else
            [ 200, {'Content-Length'=>'2'}, ['HI'] ]
          end
        end
        app(:rack, ru) {
          listen "#{host}:#{port}", ssl_ctx: ctx
          listen "#{insecure.addr[3]}:#{insecure.addr[1]}"
        }
        logger(Logger.new(err.path))
      end
    end
    client = ssl_client(host, port)
    buf = ''.dup
    { '/' => 'HI',
      '/rack.url_scheme' => 'https',
      '/HTTPS' => 'on',
      '/SERVER_PORT' => '443',
    }.each do |path, exp|
      client.write("GET #{path} HTTP/1.1\r\nHost: example.com\r\n\r\n")
      buf.clear
      re = /#{Regexp.escape(exp)}\z/
      Timeout.timeout(60) do
        buf << client.readpartial(111) until buf =~ re
      end
      head, body = buf.split("\r\n\r\n", 2)
      assert_equal exp, body
      assert_match %r{\AHTTP/1\.\d 200 OK\r\n}, head
    end

    # use port in Host: header (implemented by unicorn_http parser)
    exp = '666'
    client.write("GET /SERVER_PORT HTTP/1.1\r\nHost: example.com:#{exp}\r\n\r\n")
    re = /#{Regexp.escape(exp)}\z/
    buf.clear
    Timeout.timeout(60) do
      buf << client.readpartial(111) until buf =~ re
    end
    head, body = buf.split("\r\n\r\n", 2)
    assert_equal exp, body
    assert_match %r{\AHTTP/1\.\d 200 OK\r\n}, head

    Net::HTTP.start(insecure.addr[3], insecure.addr[1]) do |h|
      res = h.get('/rack.url_scheme')
      assert_equal 'http', res.body
      res = h.get('/HTTPS')
      assert_equal 'nil', res.body
      res = h.get('/SERVER_PORT')
      assert_equal insecure.addr[1].to_s, res.body
    end

    # read static file
    client.write("GET /static HTTP/1.1\r\nHost: example.com\r\n\r\n")
    buf.clear
    Timeout.timeout(60) do
      buf << client.readpartial(8192) until buf.include?(raw)
    end
    head, body = buf.split("\r\n\r\n", 2)
    assert_match %r{\AHTTP/1\.\d 200 OK\r\n}, head
    assert_equal raw, body

    client.write("GET / HTTP/1.0\r\n\r\n")
    head, body = client.read.split("\r\n\r\n", 2)
    assert_equal "HI", body
    assert_match %r{\AHTTP/1\.\d 200 OK\r\n}, head
  ensure
    insecure.close if insecure
    client.close if client
    quit_wait(pid)
  end

  def test_ssl_hijack
    err, cfg, host, port = @err, Yahns::Config.new, @srv.addr[3], @srv.addr[1]
    ctx = srv_ctx
    pid = mkserver(cfg) do
      cfg.instance_eval do
        ru = lambda do |env|
          io = env['rack.hijack'].call
          Thread.new(io) do |s|
            s.write "HTTP/1.1 201 Switching Protocols\r\n\r\n"
            case req = s.gets
            when "inspect\n"
              s.puts(s.instance_variable_get(:@ssl).inspect)
            when "remote_address\n"
              s.puts(s.remote_address.inspect)
            when "each\n"
              line = ''.dup
              s.each do |l|
                l.strip!
                line << l
                break if l == 'd'
              end
              s.puts line
            when "missing\n"
              begin
                s.any_old_invalid_test_method
                s.puts "FAIL"
              rescue => e
                s.puts "#{e.class}: #{e.message}"
              end
            when nil
              s.close
            else
              p [ :ERR, req ]
            end until s.closed?
          end
          [ 200, DieIfUsed.new, DieIfUsed.new ]
        end
        app(:rack, ru) { listen "#{host}:#{port}", ssl_ctx: ctx }
        logger(Logger.new(err.path))
        stderr_path err.path
      end
    end
    client = ssl_client(host, port)
    client.write("GET / HTTP/1.0\r\n\r\n")

    Timeout.timeout(60) do
      assert_equal "HTTP/1.1 201 Switching Protocols\r\n", client.gets
      assert_equal "\r\n", client.gets
      client.puts "inspect"
      assert_match %r{SSLSocket}, client.gets
      client.puts "remote_address"
      assert_equal client.to_io.local_address.inspect, client.gets.strip
      client.puts "missing"
      assert_match %r{NoMethodError}, client.gets

      client.puts "each"
      %w(a b c d).each { |x| client.puts(x) }
      assert_equal "abcd", client.gets.strip
    end
    errs = File.readlines(err.path).grep(/DieIfUsed/)
    assert_equal([ "INFO #{pid} closed DieIfUsed 1\n" ], errs)
  ensure
    client.close if client
    quit_wait(pid)
  end
end if defined?(OpenSSL)

git clone git://yhbt.net/yahns.git
git clone https://yhbt.net/yahns.git