2022-06-21 17:20:08 -04:00
|
|
|
"""
|
2022-06-30 14:21:21 -04:00
|
|
|
Support for listening with both HTTPS and Foolscap on the same port.
|
|
|
|
|
|
|
|
The goal is to make the transition from Foolscap to HTTPS-based protocols as
|
|
|
|
simple as possible, with no extra configuration needed. Listening on the same
|
|
|
|
port means a user upgrading Tahoe-LAFS will automatically get HTTPS working
|
|
|
|
with no additional changes.
|
2022-06-21 17:20:08 -04:00
|
|
|
|
2022-06-30 14:21:21 -04:00
|
|
|
Use ``create_foolscap_or_http_class()`` to create a new subclass per ``Tub``,
|
|
|
|
and then ``update_foolscap_or_http_class()`` to add the relevant information to
|
|
|
|
the subclass once it becomes available later in the configuration process.
|
|
|
|
"""
|
2022-06-21 17:20:08 -04:00
|
|
|
|
|
|
|
from twisted.internet.protocol import Protocol
|
2022-06-23 12:47:33 -04:00
|
|
|
from twisted.internet.interfaces import IDelayedCall
|
2022-06-23 12:41:47 -04:00
|
|
|
from twisted.internet.ssl import CertificateOptions, PrivateCertificate
|
2022-06-22 14:19:29 -04:00
|
|
|
from twisted.web.server import Site
|
|
|
|
from twisted.protocols.tls import TLSMemoryBIOFactory
|
2022-06-23 12:47:33 -04:00
|
|
|
from twisted.internet import reactor
|
2022-06-21 17:20:08 -04:00
|
|
|
|
|
|
|
from foolscap.negotiate import Negotiation
|
|
|
|
|
2022-06-22 14:19:29 -04:00
|
|
|
from .storage.http_server import HTTPServer
|
2022-06-23 07:59:43 -04:00
|
|
|
from .storage.server import StorageServer
|
2022-06-22 14:19:29 -04:00
|
|
|
|
2022-06-22 10:23:23 -04:00
|
|
|
|
2022-06-30 14:21:21 -04:00
|
|
|
class _PretendToBeNegotiation(type):
|
|
|
|
"""
|
|
|
|
Metaclass that allows ``_FoolscapOrHttps`` to pretend to be a ``Negotiation``
|
|
|
|
instance, since Foolscap has some ``assert isinstance(protocol,
|
|
|
|
Negotiation`` checks.
|
|
|
|
"""
|
2022-06-21 17:20:08 -04:00
|
|
|
|
|
|
|
def __instancecheck__(self, instance):
|
|
|
|
return (instance.__class__ == self) or isinstance(instance, Negotiation)
|
|
|
|
|
|
|
|
|
2022-06-30 14:21:21 -04:00
|
|
|
class _FoolscapOrHttps(Protocol, metaclass=_PretendToBeNegotiation):
|
2022-06-21 17:20:08 -04:00
|
|
|
"""
|
|
|
|
Based on initial query, decide whether we're talking Foolscap or HTTP.
|
|
|
|
|
2022-06-30 14:21:21 -04:00
|
|
|
Additionally, pretends to be a ``foolscap.negotiate.Negotiation`` instance,
|
|
|
|
since these are created by Foolscap's ``Tub``, by setting this to be the
|
|
|
|
tub's ``negotiationClass``.
|
|
|
|
|
|
|
|
Do not use directly; this needs to be subclassed per ``Tub``.
|
2022-06-21 17:20:08 -04:00
|
|
|
"""
|
2022-06-22 10:23:23 -04:00
|
|
|
|
2022-06-23 12:43:46 -04:00
|
|
|
# These three will be set by a subclass in update_foolscap_or_http_class()
|
|
|
|
# below.
|
2022-06-23 07:59:43 -04:00
|
|
|
swissnum: bytes
|
2022-06-23 12:41:47 -04:00
|
|
|
certificate: PrivateCertificate
|
2022-06-23 07:59:43 -04:00
|
|
|
storage_server: StorageServer
|
|
|
|
|
2022-06-23 12:47:33 -04:00
|
|
|
_timeout: IDelayedCall
|
|
|
|
|
2022-06-21 17:20:08 -04:00
|
|
|
def __init__(self, *args, **kwargs):
|
2022-06-23 12:41:01 -04:00
|
|
|
self._foolscap: Negotiation = Negotiation(*args, **kwargs)
|
|
|
|
self._buffer: bytes = b""
|
2022-06-21 17:20:08 -04:00
|
|
|
|
|
|
|
def __setattr__(self, name, value):
|
2022-06-23 12:49:07 -04:00
|
|
|
if name in {"_foolscap", "_buffer", "transport", "__class__", "_timeout"}:
|
2022-06-21 17:20:08 -04:00
|
|
|
object.__setattr__(self, name, value)
|
|
|
|
else:
|
|
|
|
setattr(self._foolscap, name, value)
|
|
|
|
|
|
|
|
def __getattr__(self, name):
|
|
|
|
return getattr(self._foolscap, name)
|
|
|
|
|
2022-06-23 12:43:46 -04:00
|
|
|
def _convert_to_negotiation(self):
|
|
|
|
"""
|
2022-06-23 12:44:17 -04:00
|
|
|
Convert self to a ``Negotiation`` instance.
|
2022-06-23 12:43:46 -04:00
|
|
|
"""
|
2022-06-23 12:32:43 -04:00
|
|
|
self.__class__ = Negotiation # type: ignore
|
|
|
|
self.__dict__ = self._foolscap.__dict__
|
2022-06-21 17:20:08 -04:00
|
|
|
|
|
|
|
def initClient(self, *args, **kwargs):
|
2022-06-22 10:23:23 -04:00
|
|
|
# After creation, a Negotiation instance either has initClient() or
|
2022-06-23 12:43:46 -04:00
|
|
|
# initServer() called. Since this is a client, we're never going to do
|
|
|
|
# HTTP, so we can immediately become a Negotiation instance.
|
2022-06-21 17:20:08 -04:00
|
|
|
assert not self._buffer
|
2022-06-23 12:32:43 -04:00
|
|
|
self._convert_to_negotiation()
|
2022-06-22 10:23:23 -04:00
|
|
|
return self.initClient(*args, **kwargs)
|
2022-06-21 17:20:08 -04:00
|
|
|
|
2022-06-23 12:47:33 -04:00
|
|
|
def connectionMade(self):
|
|
|
|
self._timeout = reactor.callLater(30, self.transport.abortConnection)
|
|
|
|
|
2022-06-21 17:20:08 -04:00
|
|
|
def dataReceived(self, data: bytes) -> None:
|
2022-06-23 12:41:01 -04:00
|
|
|
"""Handle incoming data.
|
2022-06-21 17:20:08 -04:00
|
|
|
|
2022-06-23 12:41:01 -04:00
|
|
|
Once we've decided which protocol we are, update self.__class__, at
|
|
|
|
which point all methods will be called on the new class.
|
|
|
|
"""
|
2022-06-21 17:20:08 -04:00
|
|
|
self._buffer += data
|
|
|
|
if len(self._buffer) < 8:
|
|
|
|
return
|
|
|
|
|
2022-06-22 10:23:23 -04:00
|
|
|
# Check if it looks like a Foolscap request. If so, it can handle this
|
2022-06-23 12:47:33 -04:00
|
|
|
# and later data, otherwise assume HTTPS.
|
|
|
|
self._timeout.cancel()
|
2022-06-21 17:20:08 -04:00
|
|
|
if self._buffer.startswith(b"GET /id/"):
|
2022-06-23 12:51:07 -04:00
|
|
|
# We're a Foolscap Negotiation server protocol instance:
|
2022-06-23 12:43:46 -04:00
|
|
|
transport = self.transport
|
|
|
|
buf = self._buffer
|
|
|
|
self._convert_to_negotiation()
|
2022-06-23 12:32:43 -04:00
|
|
|
self.makeConnection(transport)
|
|
|
|
self.dataReceived(buf)
|
|
|
|
return
|
2022-06-21 17:20:08 -04:00
|
|
|
else:
|
2022-06-23 12:51:07 -04:00
|
|
|
# We're a HTTPS protocol instance, serving the storage protocol:
|
2022-06-22 14:19:29 -04:00
|
|
|
certificate_options = CertificateOptions(
|
|
|
|
privateKey=self.certificate.privateKey.original,
|
|
|
|
certificate=self.certificate.original,
|
|
|
|
)
|
|
|
|
http_server = HTTPServer(self.storage_server, self.swissnum)
|
|
|
|
factory = TLSMemoryBIOFactory(
|
|
|
|
certificate_options, False, Site(http_server.get_resource())
|
|
|
|
)
|
2022-06-23 12:41:47 -04:00
|
|
|
assert self.transport is not None
|
2022-06-22 14:19:29 -04:00
|
|
|
protocol = factory.buildProtocol(self.transport.getPeer())
|
|
|
|
protocol.makeConnection(self.transport)
|
|
|
|
protocol.dataReceived(self._buffer)
|
2022-06-23 12:41:01 -04:00
|
|
|
self.__class__ = protocol.__class__
|
|
|
|
self.__dict__ = protocol.__dict__
|
2022-06-21 17:20:08 -04:00
|
|
|
|
2022-06-23 07:59:43 -04:00
|
|
|
|
|
|
|
def create_foolscap_or_http_class():
|
2022-06-30 14:21:21 -04:00
|
|
|
"""
|
|
|
|
Create a new Foolscap-or-HTTPS protocol class for a specific ``Tub``
|
|
|
|
instance.
|
|
|
|
"""
|
|
|
|
|
|
|
|
class FoolscapOrHttpWithCert(_FoolscapOrHttps):
|
2022-06-23 07:59:43 -04:00
|
|
|
pass
|
|
|
|
|
|
|
|
return FoolscapOrHttpWithCert
|
|
|
|
|
|
|
|
|
|
|
|
def update_foolscap_or_http_class(cls, certificate, storage_server, swissnum):
|
2022-06-30 14:21:21 -04:00
|
|
|
"""
|
|
|
|
Add the various parameters needed by a ``Tub``-specific
|
|
|
|
``_FoolscapOrHttps`` subclass.
|
|
|
|
"""
|
2022-06-23 07:59:43 -04:00
|
|
|
cls.certificate = certificate
|
|
|
|
cls.storage_server = storage_server
|
|
|
|
cls.swissnum = swissnum
|