tls_test.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515
  1. package scenarios
  2. import (
  3. "crypto/rand"
  4. "testing"
  5. "time"
  6. "v2ray.com/core"
  7. "v2ray.com/core/app/proxyman"
  8. "v2ray.com/core/common/net"
  9. "v2ray.com/core/common/protocol"
  10. "v2ray.com/core/common/serial"
  11. "v2ray.com/core/common/uuid"
  12. "v2ray.com/core/proxy/dokodemo"
  13. "v2ray.com/core/proxy/freedom"
  14. "v2ray.com/core/proxy/vmess"
  15. "v2ray.com/core/proxy/vmess/inbound"
  16. "v2ray.com/core/proxy/vmess/outbound"
  17. "v2ray.com/core/testing/servers/tcp"
  18. "v2ray.com/core/testing/servers/udp"
  19. tlsgen "v2ray.com/core/testing/tls"
  20. "v2ray.com/core/transport/internet"
  21. "v2ray.com/core/transport/internet/http"
  22. "v2ray.com/core/transport/internet/tls"
  23. "v2ray.com/core/transport/internet/websocket"
  24. . "v2ray.com/ext/assert"
  25. )
  26. func TestSimpleTLSConnection(t *testing.T) {
  27. assert := With(t)
  28. tcpServer := tcp.Server{
  29. MsgProcessor: xor,
  30. }
  31. dest, err := tcpServer.Start()
  32. assert(err, IsNil)
  33. defer tcpServer.Close()
  34. userID := protocol.NewID(uuid.New())
  35. serverPort := tcp.PickPort()
  36. serverConfig := &core.Config{
  37. Inbound: []*core.InboundHandlerConfig{
  38. {
  39. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  40. PortRange: net.SinglePortRange(serverPort),
  41. Listen: net.NewIPOrDomain(net.LocalHostIP),
  42. StreamSettings: &internet.StreamConfig{
  43. SecurityType: serial.GetMessageType(&tls.Config{}),
  44. SecuritySettings: []*serial.TypedMessage{
  45. serial.ToTypedMessage(&tls.Config{
  46. Certificate: []*tls.Certificate{tlsgen.GenerateCertificateForTest()},
  47. }),
  48. },
  49. },
  50. }),
  51. ProxySettings: serial.ToTypedMessage(&inbound.Config{
  52. User: []*protocol.User{
  53. {
  54. Account: serial.ToTypedMessage(&vmess.Account{
  55. Id: userID.String(),
  56. }),
  57. },
  58. },
  59. }),
  60. },
  61. },
  62. Outbound: []*core.OutboundHandlerConfig{
  63. {
  64. ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
  65. },
  66. },
  67. }
  68. clientPort := tcp.PickPort()
  69. clientConfig := &core.Config{
  70. Inbound: []*core.InboundHandlerConfig{
  71. {
  72. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  73. PortRange: net.SinglePortRange(clientPort),
  74. Listen: net.NewIPOrDomain(net.LocalHostIP),
  75. }),
  76. ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
  77. Address: net.NewIPOrDomain(dest.Address),
  78. Port: uint32(dest.Port),
  79. NetworkList: &net.NetworkList{
  80. Network: []net.Network{net.Network_TCP},
  81. },
  82. }),
  83. },
  84. },
  85. Outbound: []*core.OutboundHandlerConfig{
  86. {
  87. ProxySettings: serial.ToTypedMessage(&outbound.Config{
  88. Receiver: []*protocol.ServerEndpoint{
  89. {
  90. Address: net.NewIPOrDomain(net.LocalHostIP),
  91. Port: uint32(serverPort),
  92. User: []*protocol.User{
  93. {
  94. Account: serial.ToTypedMessage(&vmess.Account{
  95. Id: userID.String(),
  96. }),
  97. },
  98. },
  99. },
  100. },
  101. }),
  102. SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
  103. StreamSettings: &internet.StreamConfig{
  104. SecurityType: serial.GetMessageType(&tls.Config{}),
  105. SecuritySettings: []*serial.TypedMessage{
  106. serial.ToTypedMessage(&tls.Config{
  107. AllowInsecure: true,
  108. }),
  109. },
  110. },
  111. }),
  112. },
  113. },
  114. }
  115. servers, err := InitializeServerConfigs(serverConfig, clientConfig)
  116. assert(err, IsNil)
  117. conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
  118. IP: []byte{127, 0, 0, 1},
  119. Port: int(clientPort),
  120. })
  121. assert(err, IsNil)
  122. payload := "dokodemo request."
  123. nBytes, err := conn.Write([]byte(payload))
  124. assert(err, IsNil)
  125. assert(nBytes, Equals, len(payload))
  126. response := readFrom(conn, time.Second*2, len(payload))
  127. assert(response, Equals, xor([]byte(payload)))
  128. assert(conn.Close(), IsNil)
  129. CloseAllServers(servers)
  130. }
  131. func TestTLSOverKCP(t *testing.T) {
  132. assert := With(t)
  133. tcpServer := tcp.Server{
  134. MsgProcessor: xor,
  135. }
  136. dest, err := tcpServer.Start()
  137. assert(err, IsNil)
  138. defer tcpServer.Close()
  139. userID := protocol.NewID(uuid.New())
  140. serverPort := udp.PickPort()
  141. serverConfig := &core.Config{
  142. Inbound: []*core.InboundHandlerConfig{
  143. {
  144. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  145. PortRange: net.SinglePortRange(serverPort),
  146. Listen: net.NewIPOrDomain(net.LocalHostIP),
  147. StreamSettings: &internet.StreamConfig{
  148. Protocol: internet.TransportProtocol_MKCP,
  149. SecurityType: serial.GetMessageType(&tls.Config{}),
  150. SecuritySettings: []*serial.TypedMessage{
  151. serial.ToTypedMessage(&tls.Config{
  152. Certificate: []*tls.Certificate{tlsgen.GenerateCertificateForTest()},
  153. }),
  154. },
  155. },
  156. }),
  157. ProxySettings: serial.ToTypedMessage(&inbound.Config{
  158. User: []*protocol.User{
  159. {
  160. Account: serial.ToTypedMessage(&vmess.Account{
  161. Id: userID.String(),
  162. }),
  163. },
  164. },
  165. }),
  166. },
  167. },
  168. Outbound: []*core.OutboundHandlerConfig{
  169. {
  170. ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
  171. },
  172. },
  173. }
  174. clientPort := tcp.PickPort()
  175. clientConfig := &core.Config{
  176. Inbound: []*core.InboundHandlerConfig{
  177. {
  178. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  179. PortRange: net.SinglePortRange(clientPort),
  180. Listen: net.NewIPOrDomain(net.LocalHostIP),
  181. }),
  182. ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
  183. Address: net.NewIPOrDomain(dest.Address),
  184. Port: uint32(dest.Port),
  185. NetworkList: &net.NetworkList{
  186. Network: []net.Network{net.Network_TCP},
  187. },
  188. }),
  189. },
  190. },
  191. Outbound: []*core.OutboundHandlerConfig{
  192. {
  193. ProxySettings: serial.ToTypedMessage(&outbound.Config{
  194. Receiver: []*protocol.ServerEndpoint{
  195. {
  196. Address: net.NewIPOrDomain(net.LocalHostIP),
  197. Port: uint32(serverPort),
  198. User: []*protocol.User{
  199. {
  200. Account: serial.ToTypedMessage(&vmess.Account{
  201. Id: userID.String(),
  202. }),
  203. },
  204. },
  205. },
  206. },
  207. }),
  208. SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
  209. StreamSettings: &internet.StreamConfig{
  210. Protocol: internet.TransportProtocol_MKCP,
  211. SecurityType: serial.GetMessageType(&tls.Config{}),
  212. SecuritySettings: []*serial.TypedMessage{
  213. serial.ToTypedMessage(&tls.Config{
  214. AllowInsecure: true,
  215. }),
  216. },
  217. },
  218. }),
  219. },
  220. },
  221. }
  222. servers, err := InitializeServerConfigs(serverConfig, clientConfig)
  223. assert(err, IsNil)
  224. conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
  225. IP: []byte{127, 0, 0, 1},
  226. Port: int(clientPort),
  227. })
  228. assert(err, IsNil)
  229. payload := "dokodemo request."
  230. nBytes, err := conn.Write([]byte(payload))
  231. assert(err, IsNil)
  232. assert(nBytes, Equals, len(payload))
  233. response := readFrom(conn, time.Second*2, len(payload))
  234. assert(response, Equals, xor([]byte(payload)))
  235. assert(conn.Close(), IsNil)
  236. CloseAllServers(servers)
  237. }
  238. func TestTLSOverWebSocket(t *testing.T) {
  239. assert := With(t)
  240. tcpServer := tcp.Server{
  241. MsgProcessor: xor,
  242. }
  243. dest, err := tcpServer.Start()
  244. assert(err, IsNil)
  245. defer tcpServer.Close()
  246. userID := protocol.NewID(uuid.New())
  247. serverPort := tcp.PickPort()
  248. serverConfig := &core.Config{
  249. Inbound: []*core.InboundHandlerConfig{
  250. {
  251. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  252. PortRange: net.SinglePortRange(serverPort),
  253. Listen: net.NewIPOrDomain(net.LocalHostIP),
  254. StreamSettings: &internet.StreamConfig{
  255. Protocol: internet.TransportProtocol_WebSocket,
  256. SecurityType: serial.GetMessageType(&tls.Config{}),
  257. SecuritySettings: []*serial.TypedMessage{
  258. serial.ToTypedMessage(&tls.Config{
  259. Certificate: []*tls.Certificate{tlsgen.GenerateCertificateForTest()},
  260. }),
  261. },
  262. },
  263. }),
  264. ProxySettings: serial.ToTypedMessage(&inbound.Config{
  265. User: []*protocol.User{
  266. {
  267. Account: serial.ToTypedMessage(&vmess.Account{
  268. Id: userID.String(),
  269. }),
  270. },
  271. },
  272. }),
  273. },
  274. },
  275. Outbound: []*core.OutboundHandlerConfig{
  276. {
  277. ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
  278. },
  279. },
  280. }
  281. clientPort := tcp.PickPort()
  282. clientConfig := &core.Config{
  283. Inbound: []*core.InboundHandlerConfig{
  284. {
  285. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  286. PortRange: net.SinglePortRange(clientPort),
  287. Listen: net.NewIPOrDomain(net.LocalHostIP),
  288. }),
  289. ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
  290. Address: net.NewIPOrDomain(dest.Address),
  291. Port: uint32(dest.Port),
  292. NetworkList: &net.NetworkList{
  293. Network: []net.Network{net.Network_TCP},
  294. },
  295. }),
  296. },
  297. },
  298. Outbound: []*core.OutboundHandlerConfig{
  299. {
  300. ProxySettings: serial.ToTypedMessage(&outbound.Config{
  301. Receiver: []*protocol.ServerEndpoint{
  302. {
  303. Address: net.NewIPOrDomain(net.LocalHostIP),
  304. Port: uint32(serverPort),
  305. User: []*protocol.User{
  306. {
  307. Account: serial.ToTypedMessage(&vmess.Account{
  308. Id: userID.String(),
  309. }),
  310. },
  311. },
  312. },
  313. },
  314. }),
  315. SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
  316. StreamSettings: &internet.StreamConfig{
  317. Protocol: internet.TransportProtocol_WebSocket,
  318. TransportSettings: []*internet.TransportConfig{
  319. {
  320. Protocol: internet.TransportProtocol_WebSocket,
  321. Settings: serial.ToTypedMessage(&websocket.Config{}),
  322. },
  323. },
  324. SecurityType: serial.GetMessageType(&tls.Config{}),
  325. SecuritySettings: []*serial.TypedMessage{
  326. serial.ToTypedMessage(&tls.Config{
  327. AllowInsecure: true,
  328. }),
  329. },
  330. },
  331. }),
  332. },
  333. },
  334. }
  335. servers, err := InitializeServerConfigs(serverConfig, clientConfig)
  336. assert(err, IsNil)
  337. conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
  338. IP: []byte{127, 0, 0, 1},
  339. Port: int(clientPort),
  340. })
  341. assert(err, IsNil)
  342. payload := make([]byte, 10240*1024)
  343. rand.Read(payload)
  344. nBytes, err := conn.Write([]byte(payload))
  345. assert(err, IsNil)
  346. assert(nBytes, Equals, len(payload))
  347. response := readFrom(conn, time.Second*20, len(payload))
  348. assert(response, Equals, xor([]byte(payload)))
  349. assert(conn.Close(), IsNil)
  350. CloseAllServers(servers)
  351. }
  352. func TestHTTP2(t *testing.T) {
  353. assert := With(t)
  354. tcpServer := tcp.Server{
  355. MsgProcessor: xor,
  356. }
  357. dest, err := tcpServer.Start()
  358. assert(err, IsNil)
  359. defer tcpServer.Close()
  360. userID := protocol.NewID(uuid.New())
  361. serverPort := tcp.PickPort()
  362. serverConfig := &core.Config{
  363. Inbound: []*core.InboundHandlerConfig{
  364. {
  365. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  366. PortRange: net.SinglePortRange(serverPort),
  367. Listen: net.NewIPOrDomain(net.LocalHostIP),
  368. StreamSettings: &internet.StreamConfig{
  369. Protocol: internet.TransportProtocol_HTTP,
  370. TransportSettings: []*internet.TransportConfig{
  371. {
  372. Protocol: internet.TransportProtocol_HTTP,
  373. Settings: serial.ToTypedMessage(&http.Config{
  374. Host: []string{"v2ray.com"},
  375. Path: "/testpath",
  376. }),
  377. },
  378. },
  379. SecurityType: serial.GetMessageType(&tls.Config{}),
  380. SecuritySettings: []*serial.TypedMessage{
  381. serial.ToTypedMessage(&tls.Config{
  382. Certificate: []*tls.Certificate{tlsgen.GenerateCertificateForTest()},
  383. }),
  384. },
  385. },
  386. }),
  387. ProxySettings: serial.ToTypedMessage(&inbound.Config{
  388. User: []*protocol.User{
  389. {
  390. Account: serial.ToTypedMessage(&vmess.Account{
  391. Id: userID.String(),
  392. }),
  393. },
  394. },
  395. }),
  396. },
  397. },
  398. Outbound: []*core.OutboundHandlerConfig{
  399. {
  400. ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
  401. },
  402. },
  403. }
  404. clientPort := tcp.PickPort()
  405. clientConfig := &core.Config{
  406. Inbound: []*core.InboundHandlerConfig{
  407. {
  408. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  409. PortRange: net.SinglePortRange(clientPort),
  410. Listen: net.NewIPOrDomain(net.LocalHostIP),
  411. }),
  412. ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
  413. Address: net.NewIPOrDomain(dest.Address),
  414. Port: uint32(dest.Port),
  415. NetworkList: &net.NetworkList{
  416. Network: []net.Network{net.Network_TCP},
  417. },
  418. }),
  419. },
  420. },
  421. Outbound: []*core.OutboundHandlerConfig{
  422. {
  423. ProxySettings: serial.ToTypedMessage(&outbound.Config{
  424. Receiver: []*protocol.ServerEndpoint{
  425. {
  426. Address: net.NewIPOrDomain(net.LocalHostIP),
  427. Port: uint32(serverPort),
  428. User: []*protocol.User{
  429. {
  430. Account: serial.ToTypedMessage(&vmess.Account{
  431. Id: userID.String(),
  432. }),
  433. },
  434. },
  435. },
  436. },
  437. }),
  438. SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
  439. StreamSettings: &internet.StreamConfig{
  440. Protocol: internet.TransportProtocol_HTTP,
  441. TransportSettings: []*internet.TransportConfig{
  442. {
  443. Protocol: internet.TransportProtocol_HTTP,
  444. Settings: serial.ToTypedMessage(&http.Config{
  445. Host: []string{"v2ray.com"},
  446. Path: "/testpath",
  447. }),
  448. },
  449. },
  450. SecurityType: serial.GetMessageType(&tls.Config{}),
  451. SecuritySettings: []*serial.TypedMessage{
  452. serial.ToTypedMessage(&tls.Config{
  453. AllowInsecure: true,
  454. }),
  455. },
  456. },
  457. }),
  458. },
  459. },
  460. }
  461. servers, err := InitializeServerConfigs(serverConfig, clientConfig)
  462. assert(err, IsNil)
  463. conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
  464. IP: []byte{127, 0, 0, 1},
  465. Port: int(clientPort),
  466. })
  467. assert(err, IsNil)
  468. payload := make([]byte, 10240*1024)
  469. rand.Read(payload)
  470. nBytes, err := conn.Write([]byte(payload))
  471. assert(err, IsNil)
  472. assert(nBytes, Equals, len(payload))
  473. response := readFrom(conn, time.Second*20, len(payload))
  474. assert(response, Equals, xor([]byte(payload)))
  475. assert(conn.Close(), IsNil)
  476. CloseAllServers(servers)
  477. }