1 // Copyright 2012 The Chromium Authors
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
4
5 #include "net/socket/socks_client_socket.h"
6
7 #include <memory>
8 #include <utility>
9
10 #include "base/containers/span.h"
11 #include "base/memory/raw_ptr.h"
12 #include "build/build_config.h"
13 #include "net/base/address_list.h"
14 #include "net/base/test_completion_callback.h"
15 #include "net/base/winsock_init.h"
16 #include "net/dns/host_resolver.h"
17 #include "net/dns/mock_host_resolver.h"
18 #include "net/dns/public/secure_dns_policy.h"
19 #include "net/log/net_log_event_type.h"
20 #include "net/log/test_net_log.h"
21 #include "net/log/test_net_log_util.h"
22 #include "net/socket/client_socket_factory.h"
23 #include "net/socket/socket_test_util.h"
24 #include "net/socket/tcp_client_socket.h"
25 #include "net/test/gtest_util.h"
26 #include "net/test/test_with_task_environment.h"
27 #include "net/traffic_annotation/network_traffic_annotation_test_helper.h"
28 #include "testing/gmock/include/gmock/gmock.h"
29 #include "testing/gtest/include/gtest/gtest.h"
30 #include "testing/platform_test.h"
31
32 using net::test::IsError;
33 using net::test::IsOk;
34
35 //-----------------------------------------------------------------------------
36
37 namespace net {
38
39 class NetLog;
40
41 class SOCKSClientSocketTest : public PlatformTest, public WithTaskEnvironment {
42 public:
43 SOCKSClientSocketTest();
44 // Create a SOCKSClientSocket on top of a MockSocket.
45 std::unique_ptr<SOCKSClientSocket> BuildMockSocket(
46 base::span<const MockRead> reads,
47 base::span<const MockWrite> writes,
48 HostResolver* host_resolver,
49 const std::string& hostname,
50 int port,
51 NetLog* net_log);
52 void SetUp() override;
53
54 protected:
55 std::unique_ptr<SOCKSClientSocket> user_sock_;
56 AddressList address_list_;
57 // Filled in by BuildMockSocket() and owned by its return value
58 // (which |user_sock| is set to).
59 raw_ptr<StreamSocket> tcp_sock_;
60 TestCompletionCallback callback_;
61 std::unique_ptr<MockHostResolver> host_resolver_;
62 std::unique_ptr<SocketDataProvider> data_;
63 };
64
SOCKSClientSocketTest()65 SOCKSClientSocketTest::SOCKSClientSocketTest()
66 : host_resolver_(std::make_unique<MockHostResolver>()) {}
67
68 // Set up platform before every test case
SetUp()69 void SOCKSClientSocketTest::SetUp() {
70 PlatformTest::SetUp();
71 }
72
BuildMockSocket(base::span<const MockRead> reads,base::span<const MockWrite> writes,HostResolver * host_resolver,const std::string & hostname,int port,NetLog * net_log)73 std::unique_ptr<SOCKSClientSocket> SOCKSClientSocketTest::BuildMockSocket(
74 base::span<const MockRead> reads,
75 base::span<const MockWrite> writes,
76 HostResolver* host_resolver,
77 const std::string& hostname,
78 int port,
79 NetLog* net_log) {
80 TestCompletionCallback callback;
81 data_ = std::make_unique<StaticSocketDataProvider>(reads, writes);
82 auto socket = std::make_unique<MockTCPClientSocket>(address_list_, net_log,
83 data_.get());
84 socket->set_enable_read_if_ready(true);
85
86 int rv = socket->Connect(callback.callback());
87 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
88 rv = callback.WaitForResult();
89 EXPECT_THAT(rv, IsOk());
90 EXPECT_TRUE(socket->IsConnected());
91
92 // The SOCKSClientSocket takes ownership of |socket|, but |tcp_sock_| keeps a
93 // non-owning pointer to it.
94 tcp_sock_ = socket.get();
95 return std::make_unique<SOCKSClientSocket>(
96 std::move(socket), HostPortPair(hostname, port),
97 NetworkAnonymizationKey(), DEFAULT_PRIORITY, host_resolver,
98 SecureDnsPolicy::kAllow, TRAFFIC_ANNOTATION_FOR_TESTS);
99 }
100
101 // Tests a complete handshake and the disconnection.
TEST_F(SOCKSClientSocketTest,CompleteHandshake)102 TEST_F(SOCKSClientSocketTest, CompleteHandshake) {
103 // Run the test twice. Once with ReadIfReady() and once with Read().
104 for (bool use_read_if_ready : {true, false}) {
105 const std::string payload_write = "random data";
106 const std::string payload_read = "moar random data";
107
108 MockWrite data_writes[] = {
109 MockWrite(ASYNC, kSOCKS4OkRequestLocalHostPort80,
110 kSOCKS4OkRequestLocalHostPort80Length),
111 MockWrite(ASYNC, payload_write.data(), payload_write.size())};
112 MockRead data_reads[] = {
113 MockRead(ASYNC, kSOCKS4OkReply, kSOCKS4OkReplyLength),
114 MockRead(ASYNC, payload_read.data(), payload_read.size())};
115 RecordingNetLogObserver log_observer;
116
117 user_sock_ = BuildMockSocket(data_reads, data_writes, host_resolver_.get(),
118 "localhost", 80, NetLog::Get());
119
120 // At this state the TCP connection is completed but not the SOCKS
121 // handshake.
122 EXPECT_TRUE(tcp_sock_->IsConnected());
123 EXPECT_FALSE(user_sock_->IsConnected());
124
125 int rv = user_sock_->Connect(callback_.callback());
126 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
127
128 auto entries = log_observer.GetEntries();
129 EXPECT_TRUE(
130 LogContainsBeginEvent(entries, 0, NetLogEventType::SOCKS_CONNECT));
131 EXPECT_FALSE(user_sock_->IsConnected());
132
133 rv = callback_.WaitForResult();
134 EXPECT_THAT(rv, IsOk());
135 EXPECT_TRUE(user_sock_->IsConnected());
136 entries = log_observer.GetEntries();
137 EXPECT_TRUE(
138 LogContainsEndEvent(entries, -1, NetLogEventType::SOCKS_CONNECT));
139
140 scoped_refptr<IOBuffer> buffer =
141 base::MakeRefCounted<IOBuffer>(payload_write.size());
142 memcpy(buffer->data(), payload_write.data(), payload_write.size());
143 rv = user_sock_->Write(buffer.get(), payload_write.size(),
144 callback_.callback(), TRAFFIC_ANNOTATION_FOR_TESTS);
145 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
146 rv = callback_.WaitForResult();
147 EXPECT_EQ(static_cast<int>(payload_write.size()), rv);
148
149 buffer = base::MakeRefCounted<IOBuffer>(payload_read.size());
150 if (use_read_if_ready) {
151 rv = user_sock_->ReadIfReady(buffer.get(), payload_read.size(),
152 callback_.callback());
153 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
154 rv = callback_.WaitForResult();
155 EXPECT_EQ(net::OK, rv);
156 rv = user_sock_->ReadIfReady(buffer.get(), payload_read.size(),
157 callback_.callback());
158 } else {
159 rv = user_sock_->Read(buffer.get(), payload_read.size(),
160 callback_.callback());
161 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
162 rv = callback_.WaitForResult();
163 }
164 EXPECT_EQ(static_cast<int>(payload_read.size()), rv);
165 EXPECT_EQ(payload_read, std::string(buffer->data(), payload_read.size()));
166
167 user_sock_->Disconnect();
168 EXPECT_FALSE(tcp_sock_->IsConnected());
169 EXPECT_FALSE(user_sock_->IsConnected());
170 }
171 }
172
TEST_F(SOCKSClientSocketTest,CancelPendingReadIfReady)173 TEST_F(SOCKSClientSocketTest, CancelPendingReadIfReady) {
174 const std::string payload_read = "random data";
175
176 MockWrite data_writes[] = {MockWrite(ASYNC, kSOCKS4OkRequestLocalHostPort80,
177 kSOCKS4OkRequestLocalHostPort80Length)};
178 MockRead data_reads[] = {
179 MockRead(ASYNC, kSOCKS4OkReply, kSOCKS4OkReplyLength),
180 MockRead(ASYNC, payload_read.data(), payload_read.size())};
181 user_sock_ = BuildMockSocket(data_reads, data_writes, host_resolver_.get(),
182 "localhost", 80, nullptr);
183
184 // At this state the TCP connection is completed but not the SOCKS
185 // handshake.
186 EXPECT_TRUE(tcp_sock_->IsConnected());
187 EXPECT_FALSE(user_sock_->IsConnected());
188
189 int rv = user_sock_->Connect(callback_.callback());
190 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
191 rv = callback_.WaitForResult();
192 EXPECT_THAT(rv, IsOk());
193 EXPECT_TRUE(user_sock_->IsConnected());
194
195 auto buffer = base::MakeRefCounted<IOBuffer>(payload_read.size());
196 rv = user_sock_->ReadIfReady(buffer.get(), payload_read.size(),
197 callback_.callback());
198 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
199 rv = user_sock_->CancelReadIfReady();
200 EXPECT_EQ(net::OK, rv);
201
202 user_sock_->Disconnect();
203 EXPECT_FALSE(tcp_sock_->IsConnected());
204 EXPECT_FALSE(user_sock_->IsConnected());
205 }
206
207 // List of responses from the socks server and the errors they should
208 // throw up are tested here.
TEST_F(SOCKSClientSocketTest,HandshakeFailures)209 TEST_F(SOCKSClientSocketTest, HandshakeFailures) {
210 const struct {
211 const char fail_reply[8];
212 Error fail_code;
213 } tests[] = {
214 // Failure of the server response code
215 {
216 { 0x01, 0x5A, 0x00, 0x00, 0, 0, 0, 0 },
217 ERR_SOCKS_CONNECTION_FAILED,
218 },
219 // Failure of the null byte
220 {
221 { 0x00, 0x5B, 0x00, 0x00, 0, 0, 0, 0 },
222 ERR_SOCKS_CONNECTION_FAILED,
223 },
224 };
225
226 //---------------------------------------
227 host_resolver_->rules()->AddRule("socks.test", "127.0.0.1");
228 for (const auto& test : tests) {
229 MockWrite data_writes[] = {
230 MockWrite(SYNCHRONOUS, kSOCKS4OkRequestLocalHostPort80,
231 kSOCKS4OkRequestLocalHostPort80Length)};
232 MockRead data_reads[] = {
233 MockRead(SYNCHRONOUS, test.fail_reply, std::size(test.fail_reply))};
234 RecordingNetLogObserver log_observer;
235
236 user_sock_ = BuildMockSocket(data_reads, data_writes, host_resolver_.get(),
237 "socks.test", 80, NetLog::Get());
238
239 int rv = user_sock_->Connect(callback_.callback());
240 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
241
242 auto entries = log_observer.GetEntries();
243 EXPECT_TRUE(
244 LogContainsBeginEvent(entries, 0, NetLogEventType::SOCKS_CONNECT));
245
246 rv = callback_.WaitForResult();
247 EXPECT_EQ(test.fail_code, rv);
248 EXPECT_FALSE(user_sock_->IsConnected());
249 EXPECT_TRUE(tcp_sock_->IsConnected());
250 entries = log_observer.GetEntries();
251 EXPECT_TRUE(
252 LogContainsEndEvent(entries, -1, NetLogEventType::SOCKS_CONNECT));
253 }
254 }
255
256 // Tests scenario when the server sends the handshake response in
257 // more than one packet.
TEST_F(SOCKSClientSocketTest,PartialServerReads)258 TEST_F(SOCKSClientSocketTest, PartialServerReads) {
259 const char kSOCKSPartialReply1[] = { 0x00 };
260 const char kSOCKSPartialReply2[] = { 0x5A, 0x00, 0x00, 0, 0, 0, 0 };
261
262 MockWrite data_writes[] = {MockWrite(ASYNC, kSOCKS4OkRequestLocalHostPort80,
263 kSOCKS4OkRequestLocalHostPort80Length)};
264 MockRead data_reads[] = {
265 MockRead(ASYNC, kSOCKSPartialReply1, std::size(kSOCKSPartialReply1)),
266 MockRead(ASYNC, kSOCKSPartialReply2, std::size(kSOCKSPartialReply2))};
267 RecordingNetLogObserver log_observer;
268
269 user_sock_ = BuildMockSocket(data_reads, data_writes, host_resolver_.get(),
270 "localhost", 80, NetLog::Get());
271
272 int rv = user_sock_->Connect(callback_.callback());
273 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
274 auto entries = log_observer.GetEntries();
275 EXPECT_TRUE(
276 LogContainsBeginEvent(entries, 0, NetLogEventType::SOCKS_CONNECT));
277
278 rv = callback_.WaitForResult();
279 EXPECT_THAT(rv, IsOk());
280 EXPECT_TRUE(user_sock_->IsConnected());
281 entries = log_observer.GetEntries();
282 EXPECT_TRUE(LogContainsEndEvent(entries, -1, NetLogEventType::SOCKS_CONNECT));
283 }
284
285 // Tests scenario when the client sends the handshake request in
286 // more than one packet.
TEST_F(SOCKSClientSocketTest,PartialClientWrites)287 TEST_F(SOCKSClientSocketTest, PartialClientWrites) {
288 const char kSOCKSPartialRequest1[] = { 0x04, 0x01 };
289 const char kSOCKSPartialRequest2[] = { 0x00, 0x50, 127, 0, 0, 1, 0 };
290
291 MockWrite data_writes[] = {
292 MockWrite(ASYNC, kSOCKSPartialRequest1, std::size(kSOCKSPartialRequest1)),
293 // simulate some empty writes
294 MockWrite(ASYNC, 0),
295 MockWrite(ASYNC, 0),
296 MockWrite(ASYNC, kSOCKSPartialRequest2, std::size(kSOCKSPartialRequest2)),
297 };
298 MockRead data_reads[] = {
299 MockRead(ASYNC, kSOCKS4OkReply, kSOCKS4OkReplyLength)};
300 RecordingNetLogObserver log_observer;
301
302 user_sock_ = BuildMockSocket(data_reads, data_writes, host_resolver_.get(),
303 "localhost", 80, NetLog::Get());
304
305 int rv = user_sock_->Connect(callback_.callback());
306 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
307 auto entries = log_observer.GetEntries();
308 EXPECT_TRUE(
309 LogContainsBeginEvent(entries, 0, NetLogEventType::SOCKS_CONNECT));
310
311 rv = callback_.WaitForResult();
312 EXPECT_THAT(rv, IsOk());
313 EXPECT_TRUE(user_sock_->IsConnected());
314 entries = log_observer.GetEntries();
315 EXPECT_TRUE(LogContainsEndEvent(entries, -1, NetLogEventType::SOCKS_CONNECT));
316 }
317
318 // Tests the case when the server sends a smaller sized handshake data
319 // and closes the connection.
TEST_F(SOCKSClientSocketTest,FailedSocketRead)320 TEST_F(SOCKSClientSocketTest, FailedSocketRead) {
321 MockWrite data_writes[] = {MockWrite(ASYNC, kSOCKS4OkRequestLocalHostPort80,
322 kSOCKS4OkRequestLocalHostPort80Length)};
323 MockRead data_reads[] = {
324 MockRead(ASYNC, kSOCKS4OkReply, kSOCKS4OkReplyLength - 2),
325 // close connection unexpectedly
326 MockRead(SYNCHRONOUS, 0)};
327 RecordingNetLogObserver log_observer;
328
329 user_sock_ = BuildMockSocket(data_reads, data_writes, host_resolver_.get(),
330 "localhost", 80, NetLog::Get());
331
332 int rv = user_sock_->Connect(callback_.callback());
333 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
334 auto entries = log_observer.GetEntries();
335 EXPECT_TRUE(
336 LogContainsBeginEvent(entries, 0, NetLogEventType::SOCKS_CONNECT));
337
338 rv = callback_.WaitForResult();
339 EXPECT_THAT(rv, IsError(ERR_CONNECTION_CLOSED));
340 EXPECT_FALSE(user_sock_->IsConnected());
341 entries = log_observer.GetEntries();
342 EXPECT_TRUE(LogContainsEndEvent(entries, -1, NetLogEventType::SOCKS_CONNECT));
343 }
344
345 // Tries to connect to an unknown hostname. Should fail rather than
346 // falling back to SOCKS4a.
TEST_F(SOCKSClientSocketTest,FailedDNS)347 TEST_F(SOCKSClientSocketTest, FailedDNS) {
348 const char hostname[] = "unresolved.ipv4.address";
349
350 host_resolver_->rules()->AddSimulatedTimeoutFailure(hostname);
351
352 RecordingNetLogObserver log_observer;
353
354 user_sock_ =
355 BuildMockSocket(base::span<MockRead>(), base::span<MockWrite>(),
356 host_resolver_.get(), hostname, 80, NetLog::Get());
357
358 int rv = user_sock_->Connect(callback_.callback());
359 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
360 auto entries = log_observer.GetEntries();
361 EXPECT_TRUE(
362 LogContainsBeginEvent(entries, 0, NetLogEventType::SOCKS_CONNECT));
363
364 rv = callback_.WaitForResult();
365 EXPECT_THAT(rv, IsError(ERR_NAME_NOT_RESOLVED));
366 EXPECT_THAT(user_sock_->GetResolveErrorInfo().error,
367 IsError(ERR_DNS_TIMED_OUT));
368 EXPECT_FALSE(user_sock_->IsConnected());
369 entries = log_observer.GetEntries();
370 EXPECT_TRUE(LogContainsEndEvent(entries, -1, NetLogEventType::SOCKS_CONNECT));
371 }
372
373 // Calls Disconnect() while a host resolve is in progress. The outstanding host
374 // resolve should be cancelled.
TEST_F(SOCKSClientSocketTest,DisconnectWhileHostResolveInProgress)375 TEST_F(SOCKSClientSocketTest, DisconnectWhileHostResolveInProgress) {
376 auto hanging_resolver = std::make_unique<HangingHostResolver>();
377
378 // Doesn't matter what the socket data is, we will never use it -- garbage.
379 MockWrite data_writes[] = { MockWrite(SYNCHRONOUS, "", 0) };
380 MockRead data_reads[] = { MockRead(SYNCHRONOUS, "", 0) };
381
382 user_sock_ = BuildMockSocket(data_reads, data_writes, hanging_resolver.get(),
383 "foo", 80, nullptr);
384
385 // Start connecting (will get stuck waiting for the host to resolve).
386 int rv = user_sock_->Connect(callback_.callback());
387 EXPECT_THAT(rv, IsError(ERR_IO_PENDING));
388
389 EXPECT_FALSE(user_sock_->IsConnected());
390 EXPECT_FALSE(user_sock_->IsConnectedAndIdle());
391
392 // Disconnect the SOCKS socket -- this should cancel the outstanding resolve.
393 ASSERT_EQ(0, hanging_resolver->num_cancellations());
394 user_sock_->Disconnect();
395 EXPECT_EQ(1, hanging_resolver->num_cancellations());
396
397 EXPECT_FALSE(user_sock_->IsConnected());
398 EXPECT_FALSE(user_sock_->IsConnectedAndIdle());
399 }
400
401 // Tries to connect to an IPv6 IP. Should fail, as SOCKS4 does not support
402 // IPv6.
TEST_F(SOCKSClientSocketTest,NoIPv6)403 TEST_F(SOCKSClientSocketTest, NoIPv6) {
404 const char kHostName[] = "::1";
405
406 user_sock_ = BuildMockSocket(base::span<MockRead>(), base::span<MockWrite>(),
407 host_resolver_.get(), kHostName, 80, nullptr);
408
409 EXPECT_EQ(ERR_NAME_NOT_RESOLVED,
410 callback_.GetResult(user_sock_->Connect(callback_.callback())));
411 }
412
413 // Same as above, but with a real resolver, to protect against regressions.
TEST_F(SOCKSClientSocketTest,NoIPv6RealResolver)414 TEST_F(SOCKSClientSocketTest, NoIPv6RealResolver) {
415 const char kHostName[] = "::1";
416
417 std::unique_ptr<HostResolver> host_resolver(
418 HostResolver::CreateStandaloneResolver(nullptr));
419
420 user_sock_ = BuildMockSocket(base::span<MockRead>(), base::span<MockWrite>(),
421 host_resolver.get(), kHostName, 80, nullptr);
422
423 EXPECT_EQ(ERR_NAME_NOT_RESOLVED,
424 callback_.GetResult(user_sock_->Connect(callback_.callback())));
425 }
426
TEST_F(SOCKSClientSocketTest,Tag)427 TEST_F(SOCKSClientSocketTest, Tag) {
428 StaticSocketDataProvider data;
429 auto tagging_sock = std::make_unique<MockTaggingStreamSocket>(
430 std::make_unique<MockTCPClientSocket>(address_list_, NetLog::Get(),
431 &data));
432 auto* tagging_sock_ptr = tagging_sock.get();
433
434 auto connection = std::make_unique<ClientSocketHandle>();
435 // |connection| takes ownership of |tagging_sock|, but keep a
436 // non-owning pointer to it.
437 MockHostResolver host_resolver;
438 SOCKSClientSocket socket(
439 std::move(tagging_sock), HostPortPair("localhost", 80),
440 NetworkAnonymizationKey(), DEFAULT_PRIORITY, &host_resolver,
441 SecureDnsPolicy::kAllow, TRAFFIC_ANNOTATION_FOR_TESTS);
442
443 EXPECT_EQ(tagging_sock_ptr->tag(), SocketTag());
444 #if BUILDFLAG(IS_ANDROID)
445 SocketTag tag(0x12345678, 0x87654321);
446 socket.ApplySocketTag(tag);
447 EXPECT_EQ(tagging_sock_ptr->tag(), tag);
448 #endif // BUILDFLAG(IS_ANDROID)
449 }
450
TEST_F(SOCKSClientSocketTest,SetSecureDnsPolicy)451 TEST_F(SOCKSClientSocketTest, SetSecureDnsPolicy) {
452 for (auto secure_dns_policy :
453 {SecureDnsPolicy::kAllow, SecureDnsPolicy::kDisable}) {
454 StaticSocketDataProvider data;
455 MockHostResolver host_resolver;
456 host_resolver.rules()->AddRule("doh.test", "127.0.0.1");
457 SOCKSClientSocket socket(std::make_unique<MockTCPClientSocket>(
458 address_list_, NetLog::Get(), &data),
459 HostPortPair("doh.test", 80),
460 NetworkAnonymizationKey(), DEFAULT_PRIORITY,
461 &host_resolver, secure_dns_policy,
462 TRAFFIC_ANNOTATION_FOR_TESTS);
463
464 EXPECT_EQ(ERR_IO_PENDING, socket.Connect(callback_.callback()));
465 EXPECT_EQ(secure_dns_policy, host_resolver.last_secure_dns_policy());
466 }
467 }
468
469 } // namespace net
470