ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/AnyEvent-MP/MP/Transport.pm
(Generate patch)

Comparing AnyEvent-MP/MP/Transport.pm (file contents):
Revision 1.11 by root, Mon Aug 3 15:40:53 2009 UTC vs.
Revision 1.22 by root, Wed Aug 5 19:55:58 2009 UTC

1=head1 NAME 1=head1 NAME
2 2
3AnyEvent::MP::Transport - actual transport protocol 3AnyEvent::MP::Transport - actual transport protocol handler
4 4
5=head1 SYNOPSIS 5=head1 SYNOPSIS
6 6
7 use AnyEvent::MP::Transport; 7 use AnyEvent::MP::Transport;
8 8
9=head1 DESCRIPTION 9=head1 DESCRIPTION
10 10
11This is the superclass for MP transports, most of which is considered an 11This implements the actual transport protocol for MP (it represents a
12implementation detail. 12single link), most of which is considered an implementation detail.
13 13
14See the "PROTOCOL" section below if you want to write another client for 14See the "PROTOCOL" section below if you want to write another client for
15this protocol. 15this protocol.
16 16
17=head1 FUNCTIONS/METHODS 17=head1 FUNCTIONS/METHODS
26 26
27use Scalar::Util; 27use Scalar::Util;
28use MIME::Base64 (); 28use MIME::Base64 ();
29use Storable (); 29use Storable ();
30use JSON::XS (); 30use JSON::XS ();
31
32use Digest::MD6 ();
33use Digest::HMAC_MD6 ();
31 34
32use AE (); 35use AE ();
33use AnyEvent::Socket (); 36use AnyEvent::Socket ();
34use AnyEvent::Handle (); 37use AnyEvent::Handle ();
35 38
111 114
112=cut 115=cut
113 116
114our @FRAMINGS = qw(json storable); # the framing types we accept and send, in order of preference 117our @FRAMINGS = qw(json storable); # the framing types we accept and send, in order of preference
115our @AUTH_SND = qw(hmac_md6_64_256); # auth types we send 118our @AUTH_SND = qw(hmac_md6_64_256); # auth types we send
116our @AUTH_RCV = (@AUTH_SND, qw(hex_secret)); # auth types we accept 119our @AUTH_RCV = (@AUTH_SND, qw(cleartext)); # auth types we accept
117 120
118#AnyEvent::Handle::register_write_type mp_record => sub { 121#AnyEvent::Handle::register_write_type mp_record => sub {
119#}; 122#};
120 123
121sub new { 124sub new {
126 $self->{queue} = []; 129 $self->{queue} = [];
127 130
128 { 131 {
129 Scalar::Util::weaken (my $self = $self); 132 Scalar::Util::weaken (my $self = $self);
130 133
131 $arg{tls_ctx_disabled} ||= {
132 sslv2 => 0,
133 sslv3 => 0,
134 tlsv1 => 1,
135 verify => 1,
136 cert_file => "secret.pem",
137 ca_file => "secret.pem",
138 verify_require_client_cert => 1,
139 };
140
141 $arg{secret} = AnyEvent::MP::Base::default_secret () 134 $arg{secret} = AnyEvent::MP::Base::default_secret ()
142 unless exists $arg{secret}; 135 unless exists $arg{secret};
143 136
137 my $secret = $arg{secret};
138
139 if ($secret =~ /-----BEGIN RSA PRIVATE KEY-----.*-----END RSA PRIVATE KEY-----.*-----BEGIN CERTIFICATE-----.*-----END CERTIFICATE-----/s) {
140 # assume TLS mode
141 $arg{tls_ctx} = {
142 sslv2 => 0,
143 sslv3 => 0,
144 tlsv1 => 1,
145 verify => 1,
146 cert => $secret,
147 ca_cert => $secret,
148 verify_require_client_cert => 1,
149 };
150 }
151
144 $self->{hdl} = new AnyEvent::Handle 152 $self->{hdl} = new AnyEvent::Handle
145 fh => delete $arg{fh}, 153 fh => delete $arg{fh},
146 rbuf_max => 64 * 1024,
147 autocork => 1, 154 autocork => 1,
148 no_delay => 1, 155 no_delay => 1,
149 on_error => sub { 156 on_error => sub {
150 $self->error ($_[2]); 157 $self->error ($_[2]);
151 }, 158 },
152 peername => delete $arg{peername}, 159 peername => delete $arg{peername},
153 ; 160 ;
154 161
155 my $secret = $arg{secret};
156 my $greeting_kv = $self->{greeting} ||= {}; 162 my $greeting_kv = $self->{greeting} ||= {};
157 $greeting_kv->{"tls"} = "1.0" 163 $greeting_kv->{"tls"} = "1.0"
158 if $arg{tls_ctx}; 164 if $arg{tls_ctx};
159 $greeting_kv->{provider} = "AE-$VERSION"; 165 $greeting_kv->{provider} = "AE-$VERSION";
160 $greeting_kv->{peeraddr} = AnyEvent::Socket::format_hostport $self->{peerhost}, $self->{peerport}; 166 $greeting_kv->{peeraddr} = AnyEvent::Socket::format_hostport $self->{peerhost}, $self->{peerport};
161 167
162 # send greeting 168 # send greeting
163 my $lgreeting1 = "aemp;$PROTOCOL_VERSION;$PROTOCOL_VERSION" # version, min 169 my $lgreeting1 = "aemp;$PROTOCOL_VERSION"
164 . ";$AnyEvent::MP::Base::UNIQ" 170 . ";$AnyEvent::MP::Base::UNIQ"
165 . ";$AnyEvent::MP::Base::NODE" 171 . ";$AnyEvent::MP::Base::NODE"
166 . ";" . (join ",", @AUTH_RCV) 172 . ";" . (join ",", @AUTH_RCV)
167 . ";" . (join ",", @FRAMINGS) 173 . ";" . (join ",", @FRAMINGS)
168 . (join "", map ";$_=$greeting_kv->{$_}", keys %$greeting_kv); 174 . (join "", map ";$_=$greeting_kv->{$_}", keys %$greeting_kv);
175
169 my $lgreeting2 = MIME::Base64::encode_base64 AnyEvent::MP::Base::nonce (33), ""; 176 my $lgreeting2 = MIME::Base64::encode_base64 AnyEvent::MP::Base::nonce (33), "";
170 177
171 $self->{hdl}->push_write ("$lgreeting1\012$lgreeting2\012"); 178 $self->{hdl}->push_write ("$lgreeting1\012$lgreeting2\012");
172 179
173 # expect greeting 180 # expect greeting
181 $self->{hdl}->rbuf_max (4 * 1024);
174 $self->{hdl}->push_read (line => sub { 182 $self->{hdl}->push_read (line => sub {
175 my $rgreeting1 = $_[1]; 183 my $rgreeting1 = $_[1];
176 184
177 my ($aemp, $version, $version_min, $uniq, $rnode, $auths, $framings, @kv) = split /;/, $rgreeting1; 185 my ($aemp, $version, $uniq, $rnode, $auths, $framings, @kv) = split /;/, $rgreeting1;
178 186
179 if ($aemp ne "aemp") { 187 if ($aemp ne "aemp") {
180 return $self->error ("unparsable greeting"); 188 return $self->error ("unparsable greeting");
181 } elsif ($version_min > $PROTOCOL_VERSION) { 189 } elsif ($version != $PROTOCOL_VERSION) {
182 return $self->error ("version mismatch (we: $PROTOCOL_VERSION, they: $version_min .. $version)"); 190 return $self->error ("version mismatch (we: $PROTOCOL_VERSION, they: $version)");
183 } 191 }
184 192
185 my $s_auth; 193 my $s_auth;
186 for my $auth_ (split /,/, $auths) { 194 for my $auth_ (split /,/, $auths) {
187 if (grep $auth_ eq $_, @AUTH_SND) { 195 if (grep $auth_ eq $_, @AUTH_SND) {
216 224
217 # read nonce 225 # read nonce
218 $self->{hdl}->push_read (line => sub { 226 $self->{hdl}->push_read (line => sub {
219 my $rgreeting2 = $_[1]; 227 my $rgreeting2 = $_[1];
220 228
229 "$lgreeting1\012$lgreeting2" ne "$rgreeting1\012$rgreeting2" # echo attack?
230 or return $self->error ("authentication error, echo attack?");
231
232 my $key = Digest::MD6::md6 $secret;
233 my $lauth;
234
221 if ($self->{tls_ctx} and 1 == int $self->{remote_greeting}{tls}) { 235 if ($self->{tls_ctx} and 1 == int $self->{remote_greeting}{tls}) {
222 $self->{tls} = $lgreeting2 lt $rgreeting2 ? "connect" : "accept"; 236 $self->{tls} = $lgreeting2 lt $rgreeting2 ? "connect" : "accept";
223 $self->{hdl}->starttls ($self->{tls}, $self->{tls_ctx}); 237 $self->{hdl}->starttls ($self->{tls}, $self->{tls_ctx});
238 $s_auth = "tls";
239 $lauth = "";
240 } else {
241 # we currently only support hmac_md6_64_256
242 $lauth = Digest::HMAC_MD6::hmac_md6_hex $key, "$lgreeting1\012$lgreeting2\012$rgreeting1\012$rgreeting2\012", 64, 256;
224 } 243 }
225
226 # auth
227 require Digest::MD6;
228 require Digest::HMAC_MD6;
229
230 my $key = Digest::MD6::md6 ($secret);
231 my $lauth = Digest::HMAC_MD6::hmac_md6_base64 ($key, "$lgreeting1\012$lgreeting2\012$rgreeting1\012$rgreeting2\012", 64, 256);
232
233 my $rauth =
234 $s_auth eq "hmac_md6_64_256" ? Digest::HMAC_MD6::hmac_md6_base64 ($key, "$rgreeting1\012$rgreeting2\012$lgreeting1\012$lgreeting2\012", 64, 256)
235 : $s_auth eq "hex_secret" ? unpack "H*", $secret
236 : die;
237
238 $lauth ne $rauth # echo attack?
239 or return $self->error ("authentication error");
240 244
241 $self->{hdl}->push_write ("$s_auth;$lauth;$s_framing\012"); 245 $self->{hdl}->push_write ("$s_auth;$lauth;$s_framing\012");
242 246
243 $self->{hdl}->rbuf_max (64); # enough for 44 reply bytes or so 247 # read the authentication response
244 $self->{hdl}->push_read (line => sub { 248 $self->{hdl}->push_read (line => sub {
245 my ($hdl, $rline) = @_; 249 my ($hdl, $rline) = @_;
246 250
247 my ($auth_method, $rauth2, $r_framing) = split /;/, $rline; 251 my ($auth_method, $rauth2, $r_framing) = split /;/, $rline;
252
253 my $rauth =
254 $auth_method eq "hmac_md6_64_256" ? Digest::HMAC_MD6::hmac_md6_hex $key, "$rgreeting1\012$rgreeting2\012$lgreeting1\012$lgreeting2\012", 64, 256
255 : $auth_method eq "cleartext" ? unpack "H*", $secret
256 : $auth_method eq "tls" ? ($self->{tls} ? "" : "\012\012") # \012\012 never matches
257 : return $self->error ("$auth_method: fatal, selected unsupported auth method");
248 258
249 if ($rauth2 ne $rauth) { 259 if ($rauth2 ne $rauth) {
250 return $self->error ("authentication failure/shared secret mismatch"); 260 return $self->error ("authentication failure/shared secret mismatch");
251 } 261 }
252 262
255 $hdl->rbuf_max (undef); 265 $hdl->rbuf_max (undef);
256 my $queue = delete $self->{queue}; # we are connected 266 my $queue = delete $self->{queue}; # we are connected
257 267
258 $self->connected; 268 $self->connected;
259 269
270 my $src_node = $self->{node};
271
260 $hdl->push_write ($self->{s_framing} => $_) 272 $hdl->push_write ($self->{s_framing} => $_)
261 for @$queue; 273 for @$queue;
262 274
263 my $rmsg; $rmsg = sub { 275 my $rmsg; $rmsg = sub {
264 $_[0]->push_read ($r_framing => $rmsg); 276 $_[0]->push_read ($r_framing => $rmsg);
265 277
278 local $AnyEvent::MP::Base::SRCNODE = $src_node;
266 AnyEvent::MP::Base::_inject ($_[1]); 279 AnyEvent::MP::Base::_inject (@{ $_[1] });
267 }; 280 };
268 $hdl->push_read ($r_framing => $rmsg); 281 $hdl->push_read ($r_framing => $rmsg);
269 }); 282 });
270 }); 283 });
271 }); 284 });
276 289
277sub error { 290sub error {
278 my ($self, $msg) = @_; 291 my ($self, $msg) = @_;
279 292
280 if ($self->{node} && $self->{node}{transport} == $self) { 293 if ($self->{node} && $self->{node}{transport} == $self) {
294 #TODO: store error, but do not instantly fail
295 $self->{node}->fail (transport_error => $self->{node}{noderef}, $msg);
281 $self->{node}->clr_transport; 296 $self->{node}->clr_transport;
282 } 297 }
283 $AnyEvent::MP::Base::WARN->("$self->{peerhost}:$self->{peerport}: $msg"); 298 $AnyEvent::MP::Base::WARN->("$self->{peerhost}:$self->{peerport}: $msg");
284 $self->destroy; 299 $self->destroy;
285} 300}
322The greeting consists of two text lines that are ended by either an ASCII 337The greeting consists of two text lines that are ended by either an ASCII
323CR LF pair, or a single ASCII LF (recommended). 338CR LF pair, or a single ASCII LF (recommended).
324 339
325=head2 GREETING 340=head2 GREETING
326 341
342All the lines until after authentication must not exceed 4kb in length,
343including delimiter. Afterwards there is no limit on the packet size that
344can be received.
345
346=head3 First Greeting Line
347
348Example:
349
350 aemp;0;fec.4a7720fc;127.0.0.1:1235,[::1]:1235;hmac_md6_64_256;json,storable;provider=AE-0.0
351
327The first line contains strings separated (not ended) by C<;> 352The first line contains strings separated (not ended) by C<;>
328characters. The first seven strings are fixed by the protocol, the 353characters. The first even ixtrings are fixed by the protocol, the
329remaining strings are C<KEY=VALUE> pairs. None of them may contain C<;> 354remaining strings are C<KEY=VALUE> pairs. None of them may contain C<;>
330characters themselves. 355characters themselves.
331 356
332The seven fixed strings are: 357The fixed strings are:
333 358
334=over 4 359=over 4
335 360
336=item C<aemp> 361=item protocol identification
337 362
338The constant C<aemp> to identify the protocol. 363The constant C<aemp> to identify the protocol.
339 364
340=item protocol version 365=item protocol version
341 366
342The (maximum) protocol version supported by this end, currently C<0>.
343
344=item minimum protocol version
345
346The minimum protocol version supported by this end, currently C<0>. 367The protocol version supported by this end, currently C<0>. If the
368versions don't match then no communication is possible. Minor extensions
369are supposed to be handled through additional key-value pairs.
347 370
348=item a token uniquely identifying the current node instance 371=item a token uniquely identifying the current node instance
349 372
350This is a string that must change between restarts. It usually contains 373This is a string that must change between restarts. It usually contains
351things like the current time, the (OS) process id or similar values, but 374things like the current time, the (OS) process id or similar values, but
392 415
393Indicates that the other side supports TLS (version should be 1.0) and 416Indicates that the other side supports TLS (version should be 1.0) and
394wishes to do a TLS handshake. 417wishes to do a TLS handshake.
395 418
396=back 419=back
420
421=head3 Second Greeting Line
397 422
398After this greeting line there will be a second line containing a 423After this greeting line there will be a second line containing a
399cryptographic nonce, i.e. random data of high quality. To keep the 424cryptographic nonce, i.e. random data of high quality. To keep the
400protocol text-only, these are usually 32 base64-encoded octets, but 425protocol text-only, these are usually 32 base64-encoded octets, but
401it could be anything that doesn't contain any ASCII CR or ASCII LF 426it could be anything that doesn't contain any ASCII CR or ASCII LF
402characters. 427characters.
403 428
404Example of the two lines of greeting: 429I<< The two nonces B<must> be different, and an aemp implementation
430B<must> check and fail when they are identical >>.
405 431
406 aemp;0;0;e7d.4a76f48f;10.0.0.1:4040;hmac_md6_64_256,hex_secret;json,storable;provider=AE-0.0;peeraddr=127.0.0.1:1235 432Example of a nonce line:
407 XntegV2Guvss0qNn7phCPnoU87xqxV+4Mqm/5y4iQm6a 433
434 p/I122ql7kJR8lumW3lXlXCeBnyDAvz8NQo3x5IFowE4
408 435
409=head2 TLS handshake 436=head2 TLS handshake
410 437
411If, after the handshake, both sides indicate interest in TLS, then the 438I<< If, after the handshake, both sides indicate interest in TLS, then the
412connection I<must> use TLS, or fail. 439connection B<must> use TLS, or fail. >>
413 440
414Both sides compare their nonces, and the side who sent the lower nonce 441Both sides compare their nonces, and the side who sent the lower nonce
415value ("string" comparison on the raw octet values) becomes the client, 442value ("string" comparison on the raw octet values) becomes the client,
416and the one with the higher nonce the server. 443and the one with the higher nonce the server.
417 444
428 455
429=item the authentication method chosen 456=item the authentication method chosen
430 457
431This must be one of the methods offered by the other side in the greeting. 458This must be one of the methods offered by the other side in the greeting.
432 459
460The currently supported authentication methods are:
461
462=over 4
463
464=item cleartext
465
466This is simply the shared secret, lowercase-hex-encoded. This method is of
467course very insecure, unless TLS is used, which is why this module will
468accept, but not generate, cleartext auth replies.
469
470=item hmac_md6_64_256
471
472This method uses an MD6 HMAC with 64 bit blocksize and 256 bit hash. First, the shared secret
473is hashed with MD6:
474
475 key = MD6 (secret)
476
477This secret is then used to generate the "local auth reply", by taking
478the two local greeting lines and the two remote greeting lines (without
479line endings), appending \012 to all of them, concatenating them and
480calculating the MD6 HMAC with the key.
481
482 lauth = HMAC_MD6 key, "lgreeting1\012lgreeting2\012rgreeting1\012rgreeting2\012"
483
484This authentication token is then lowercase-hex-encoded and sent to the
485other side.
486
487Then the remote auth reply is generated using the same method, but local
488and remote greeting lines swapped:
489
490 rauth = HMAC_MD6 key, "rgreeting1\012rgreeting2\012lgreeting1\012lgreeting2\012"
491
492This is the token that is expected from the other side.
493
494=item tls
495
496This type is only valid iff TLS was enabled and the TLS handshake
497was successful. It has no authentication data, as the server/client
498certificate was successfully verified.
499
500Implementations supporting TLS I<must> accept this authentication type.
501
502=back
503
433=item the authentication data 504=item the authentication data
434 505
435The authentication data itself, usually base64 or hex-encoded data. 506The authentication data itself, usually base64 or hex-encoded data, see
507above.
436 508
437=item the framing protocol chosen 509=item the framing protocol chosen
438 510
439This must be one of the framing protocols offered by the other side in the 511This must be one of the framing protocols offered by the other side in the
440greeting. Each side must accept the choice of the other side. 512greeting. Each side must accept the choice of the other side.
441 513
442=back 514=back
443 515
444Example (the actual reply matching the previous example): 516Example of an authentication reply:
445 517
446 hmac_md6_64_256;wIlLedBY956UCGSISG9mBZRDTG8xUi73/sVse2DSQp0;json 518 hmac_md6_64_256;363d5175df38bd9eaddd3f6ca18aa1c0c4aa22f0da245ac638d048398c26b8d3;json
447 519
448=head2 DATA PHASE 520=head2 DATA PHASE
449 521
450After this, packets get exchanged using the chosen framing protocol. It is 522After this, packets get exchanged using the chosen framing protocol. It is
451quite possible that both sides use a different framing protocol. 523quite possible that both sides use a different framing protocol.
452 524
525=head2 FULL EXAMPLE
526
527This is an actual protocol dump of a handshake, followed by a single data
528packet. The greater than/less than lines indicate the direction of the
529transfer only.
530
531 > aemp;0;nndKd+gn;10.0.0.1:4040;hmac_md6_64_256,cleartext;json,storable;provider=AE-0.0;peeraddr=127.0.0.1:1235
532 > sRG8bbc4TDbkpvH8FTP4HBs87OhepH6VuApoZqXXskuG
533 < aemp;0;nmpKd+gh;127.0.0.1:1235,[::1]:1235;hmac_md6_64_256,cleartext;json,storable;provider=AE-0.0;peeraddr=127.0.0.1:58760
534 < dCEUcL/LJVSTJcx8byEsOzrwhzJYOq+L3YcopA5T6EAo
535 > hmac_md6_64_256;9513d4b258975accfcb2ab7532b83690e9c119a502c612203332a591c7237788;json
536 < hmac_md6_64_256;0298d6ba2240faabb2b2e881cf86b97d70a113ca74a87dc006f9f1e9d3010f90;json
537 > ["","lookup","pinger","10.0.0.1:4040#nndKd+gn.a","resolved"]
538
453=head1 SEE ALSO 539=head1 SEE ALSO
454 540
455L<AnyEvent>. 541L<AnyEvent>.
456 542
457=head1 AUTHOR 543=head1 AUTHOR

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines