tls_test.go 17 KB


  1. package scenarios
  2. import (
  3. "crypto/rand"
  4. "crypto/x509"
  5. "runtime"
  6. "sync"
  7. "testing"
  8. "time"
  9. "v2ray.com/core"
  10. "v2ray.com/core/app/proxyman"
  11. "v2ray.com/core/common"
  12. "v2ray.com/core/common/net"
  13. "v2ray.com/core/common/protocol"
  14. "v2ray.com/core/common/protocol/tls/cert"
  15. "v2ray.com/core/common/serial"
  16. "v2ray.com/core/common/uuid"
  17. "v2ray.com/core/proxy/dokodemo"
  18. "v2ray.com/core/proxy/freedom"
  19. "v2ray.com/core/proxy/vmess"
  20. "v2ray.com/core/proxy/vmess/inbound"
  21. "v2ray.com/core/proxy/vmess/outbound"
  22. "v2ray.com/core/testing/servers/tcp"
  23. "v2ray.com/core/testing/servers/udp"
  24. "v2ray.com/core/transport/internet"
  25. "v2ray.com/core/transport/internet/http"
  26. "v2ray.com/core/transport/internet/tls"
  27. "v2ray.com/core/transport/internet/websocket"
  28. . "v2ray.com/ext/assert"
  29. )
  30. func TestSimpleTLSConnection(t *testing.T) {
  31. assert := With(t)
  32. tcpServer := tcp.Server{
  33. MsgProcessor: xor,
  34. }
  35. dest, err := tcpServer.Start()
  36. common.Must(err)
  37. defer tcpServer.Close()
  38. userID := protocol.NewID(uuid.New())
  39. serverPort := tcp.PickPort()
  40. serverConfig := &core.Config{
  41. Inbound: []*core.InboundHandlerConfig{
  42. {
  43. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  44. PortRange: net.SinglePortRange(serverPort),
  45. Listen: net.NewIPOrDomain(net.LocalHostIP),
  46. StreamSettings: &internet.StreamConfig{
  47. SecurityType: serial.GetMessageType(&tls.Config{}),
  48. SecuritySettings: []*serial.TypedMessage{
  49. serial.ToTypedMessage(&tls.Config{
  50. Certificate: []*tls.Certificate{tls.ParseCertificate(cert.MustGenerate(nil))},
  51. }),
  52. },
  53. },
  54. }),
  55. ProxySettings: serial.ToTypedMessage(&inbound.Config{
  56. User: []*protocol.User{
  57. {
  58. Account: serial.ToTypedMessage(&vmess.Account{
  59. Id: userID.String(),
  60. }),
  61. },
  62. },
  63. }),
  64. },
  65. },
  66. Outbound: []*core.OutboundHandlerConfig{
  67. {
  68. ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
  69. },
  70. },
  71. }
  72. clientPort := tcp.PickPort()
  73. clientConfig := &core.Config{
  74. Inbound: []*core.InboundHandlerConfig{
  75. {
  76. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  77. PortRange: net.SinglePortRange(clientPort),
  78. Listen: net.NewIPOrDomain(net.LocalHostIP),
  79. }),
  80. ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
  81. Address: net.NewIPOrDomain(dest.Address),
  82. Port: uint32(dest.Port),
  83. NetworkList: &net.NetworkList{
  84. Network: []net.Network{net.Network_TCP},
  85. },
  86. }),
  87. },
  88. },
  89. Outbound: []*core.OutboundHandlerConfig{
  90. {
  91. ProxySettings: serial.ToTypedMessage(&outbound.Config{
  92. Receiver: []*protocol.ServerEndpoint{
  93. {
  94. Address: net.NewIPOrDomain(net.LocalHostIP),
  95. Port: uint32(serverPort),
  96. User: []*protocol.User{
  97. {
  98. Account: serial.ToTypedMessage(&vmess.Account{
  99. Id: userID.String(),
  100. }),
  101. },
  102. },
  103. },
  104. },
  105. }),
  106. SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
  107. StreamSettings: &internet.StreamConfig{
  108. SecurityType: serial.GetMessageType(&tls.Config{}),
  109. SecuritySettings: []*serial.TypedMessage{
  110. serial.ToTypedMessage(&tls.Config{
  111. AllowInsecure: true,
  112. }),
  113. },
  114. },
  115. }),
  116. },
  117. },
  118. }
  119. servers, err := InitializeServerConfigs(serverConfig, clientConfig)
  120. common.Must(err)
  121. defer CloseAllServers(servers)
  122. {
  123. conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
  124. IP: []byte{127, 0, 0, 1},
  125. Port: int(clientPort),
  126. })
  127. assert(err, IsNil)
  128. payload := "dokodemo request."
  129. nBytes, err := conn.Write([]byte(payload))
  130. assert(err, IsNil)
  131. assert(nBytes, Equals, len(payload))
  132. response := readFrom(conn, time.Second*2, len(payload))
  133. assert(response, Equals, xor([]byte(payload)))
  134. assert(conn.Close(), IsNil)
  135. }
  136. }
  137. func TestAutoIssuingCertificate(t *testing.T) {
  138. if runtime.GOOS == "windows" {
  139. // Not supported on Windows yet.
  140. return
  141. }
  142. if runtime.GOARCH == "arm64" {
  143. return
  144. }
  145. assert := With(t)
  146. tcpServer := tcp.Server{
  147. MsgProcessor: xor,
  148. }
  149. dest, err := tcpServer.Start()
  150. assert(err, IsNil)
  151. defer tcpServer.Close()
  152. caCert, err := cert.Generate(nil, cert.Authority(true), cert.KeyUsage(x509.KeyUsageDigitalSignature|x509.KeyUsageKeyEncipherment|x509.KeyUsageCertSign))
  153. assert(err, IsNil)
  154. certPEM, keyPEM := caCert.ToPEM()
  155. userID := protocol.NewID(uuid.New())
  156. serverPort := tcp.PickPort()
  157. serverConfig := &core.Config{
  158. Inbound: []*core.InboundHandlerConfig{
  159. {
  160. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  161. PortRange: net.SinglePortRange(serverPort),
  162. Listen: net.NewIPOrDomain(net.LocalHostIP),
  163. StreamSettings: &internet.StreamConfig{
  164. SecurityType: serial.GetMessageType(&tls.Config{}),
  165. SecuritySettings: []*serial.TypedMessage{
  166. serial.ToTypedMessage(&tls.Config{
  167. Certificate: []*tls.Certificate{{
  168. Certificate: certPEM,
  169. Key: keyPEM,
  170. Usage: tls.Certificate_AUTHORITY_ISSUE,
  171. }},
  172. }),
  173. },
  174. },
  175. }),
  176. ProxySettings: serial.ToTypedMessage(&inbound.Config{
  177. User: []*protocol.User{
  178. {
  179. Account: serial.ToTypedMessage(&vmess.Account{
  180. Id: userID.String(),
  181. }),
  182. },
  183. },
  184. }),
  185. },
  186. },
  187. Outbound: []*core.OutboundHandlerConfig{
  188. {
  189. ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
  190. },
  191. },
  192. }
  193. clientPort := tcp.PickPort()
  194. clientConfig := &core.Config{
  195. Inbound: []*core.InboundHandlerConfig{
  196. {
  197. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  198. PortRange: net.SinglePortRange(clientPort),
  199. Listen: net.NewIPOrDomain(net.LocalHostIP),
  200. }),
  201. ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
  202. Address: net.NewIPOrDomain(dest.Address),
  203. Port: uint32(dest.Port),
  204. NetworkList: &net.NetworkList{
  205. Network: []net.Network{net.Network_TCP},
  206. },
  207. }),
  208. },
  209. },
  210. Outbound: []*core.OutboundHandlerConfig{
  211. {
  212. ProxySettings: serial.ToTypedMessage(&outbound.Config{
  213. Receiver: []*protocol.ServerEndpoint{
  214. {
  215. Address: net.NewIPOrDomain(net.LocalHostIP),
  216. Port: uint32(serverPort),
  217. User: []*protocol.User{
  218. {
  219. Account: serial.ToTypedMessage(&vmess.Account{
  220. Id: userID.String(),
  221. }),
  222. },
  223. },
  224. },
  225. },
  226. }),
  227. SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
  228. StreamSettings: &internet.StreamConfig{
  229. SecurityType: serial.GetMessageType(&tls.Config{}),
  230. SecuritySettings: []*serial.TypedMessage{
  231. serial.ToTypedMessage(&tls.Config{
  232. ServerName: "v2ray.com",
  233. Certificate: []*tls.Certificate{{
  234. Certificate: certPEM,
  235. Usage: tls.Certificate_AUTHORITY_VERIFY,
  236. }},
  237. }),
  238. },
  239. },
  240. }),
  241. },
  242. },
  243. }
  244. servers, err := InitializeServerConfigs(serverConfig, clientConfig)
  245. assert(err, IsNil)
  246. for i := 0; i < 10; i++ {
  247. conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
  248. IP: []byte{127, 0, 0, 1},
  249. Port: int(clientPort),
  250. })
  251. assert(err, IsNil)
  252. payload := "dokodemo request."
  253. nBytes, err := conn.Write([]byte(payload))
  254. assert(err, IsNil)
  255. assert(nBytes, Equals, len(payload))
  256. response := readFrom(conn, time.Second*2, len(payload))
  257. assert(response, Equals, xor([]byte(payload)))
  258. assert(conn.Close(), IsNil)
  259. }
  260. CloseAllServers(servers)
  261. }
  262. func TestTLSOverKCP(t *testing.T) {
  263. assert := With(t)
  264. tcpServer := tcp.Server{
  265. MsgProcessor: xor,
  266. }
  267. dest, err := tcpServer.Start()
  268. assert(err, IsNil)
  269. defer tcpServer.Close()
  270. userID := protocol.NewID(uuid.New())
  271. serverPort := udp.PickPort()
  272. serverConfig := &core.Config{
  273. Inbound: []*core.InboundHandlerConfig{
  274. {
  275. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  276. PortRange: net.SinglePortRange(serverPort),
  277. Listen: net.NewIPOrDomain(net.LocalHostIP),
  278. StreamSettings: &internet.StreamConfig{
  279. Protocol: internet.TransportProtocol_MKCP,
  280. SecurityType: serial.GetMessageType(&tls.Config{}),
  281. SecuritySettings: []*serial.TypedMessage{
  282. serial.ToTypedMessage(&tls.Config{
  283. Certificate: []*tls.Certificate{tls.ParseCertificate(cert.MustGenerate(nil))},
  284. }),
  285. },
  286. },
  287. }),
  288. ProxySettings: serial.ToTypedMessage(&inbound.Config{
  289. User: []*protocol.User{
  290. {
  291. Account: serial.ToTypedMessage(&vmess.Account{
  292. Id: userID.String(),
  293. }),
  294. },
  295. },
  296. }),
  297. },
  298. },
  299. Outbound: []*core.OutboundHandlerConfig{
  300. {
  301. ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
  302. },
  303. },
  304. }
  305. clientPort := tcp.PickPort()
  306. clientConfig := &core.Config{
  307. Inbound: []*core.InboundHandlerConfig{
  308. {
  309. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  310. PortRange: net.SinglePortRange(clientPort),
  311. Listen: net.NewIPOrDomain(net.LocalHostIP),
  312. }),
  313. ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
  314. Address: net.NewIPOrDomain(dest.Address),
  315. Port: uint32(dest.Port),
  316. NetworkList: &net.NetworkList{
  317. Network: []net.Network{net.Network_TCP},
  318. },
  319. }),
  320. },
  321. },
  322. Outbound: []*core.OutboundHandlerConfig{
  323. {
  324. ProxySettings: serial.ToTypedMessage(&outbound.Config{
  325. Receiver: []*protocol.ServerEndpoint{
  326. {
  327. Address: net.NewIPOrDomain(net.LocalHostIP),
  328. Port: uint32(serverPort),
  329. User: []*protocol.User{
  330. {
  331. Account: serial.ToTypedMessage(&vmess.Account{
  332. Id: userID.String(),
  333. }),
  334. },
  335. },
  336. },
  337. },
  338. }),
  339. SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
  340. StreamSettings: &internet.StreamConfig{
  341. Protocol: internet.TransportProtocol_MKCP,
  342. SecurityType: serial.GetMessageType(&tls.Config{}),
  343. SecuritySettings: []*serial.TypedMessage{
  344. serial.ToTypedMessage(&tls.Config{
  345. AllowInsecure: true,
  346. }),
  347. },
  348. },
  349. }),
  350. },
  351. },
  352. }
  353. servers, err := InitializeServerConfigs(serverConfig, clientConfig)
  354. assert(err, IsNil)
  355. conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
  356. IP: []byte{127, 0, 0, 1},
  357. Port: int(clientPort),
  358. })
  359. assert(err, IsNil)
  360. payload := "dokodemo request."
  361. nBytes, err := conn.Write([]byte(payload))
  362. assert(err, IsNil)
  363. assert(nBytes, Equals, len(payload))
  364. response := readFrom(conn, time.Second*2, len(payload))
  365. assert(response, Equals, xor([]byte(payload)))
  366. assert(conn.Close(), IsNil)
  367. CloseAllServers(servers)
  368. }
  369. func TestTLSOverWebSocket(t *testing.T) {
  370. assert := With(t)
  371. tcpServer := tcp.Server{
  372. MsgProcessor: xor,
  373. }
  374. dest, err := tcpServer.Start()
  375. assert(err, IsNil)
  376. defer tcpServer.Close()
  377. userID := protocol.NewID(uuid.New())
  378. serverPort := tcp.PickPort()
  379. serverConfig := &core.Config{
  380. Inbound: []*core.InboundHandlerConfig{
  381. {
  382. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  383. PortRange: net.SinglePortRange(serverPort),
  384. Listen: net.NewIPOrDomain(net.LocalHostIP),
  385. StreamSettings: &internet.StreamConfig{
  386. Protocol: internet.TransportProtocol_WebSocket,
  387. SecurityType: serial.GetMessageType(&tls.Config{}),
  388. SecuritySettings: []*serial.TypedMessage{
  389. serial.ToTypedMessage(&tls.Config{
  390. Certificate: []*tls.Certificate{tls.ParseCertificate(cert.MustGenerate(nil))},
  391. }),
  392. },
  393. },
  394. }),
  395. ProxySettings: serial.ToTypedMessage(&inbound.Config{
  396. User: []*protocol.User{
  397. {
  398. Account: serial.ToTypedMessage(&vmess.Account{
  399. Id: userID.String(),
  400. }),
  401. },
  402. },
  403. }),
  404. },
  405. },
  406. Outbound: []*core.OutboundHandlerConfig{
  407. {
  408. ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
  409. },
  410. },
  411. }
  412. clientPort := tcp.PickPort()
  413. clientConfig := &core.Config{
  414. Inbound: []*core.InboundHandlerConfig{
  415. {
  416. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  417. PortRange: net.SinglePortRange(clientPort),
  418. Listen: net.NewIPOrDomain(net.LocalHostIP),
  419. }),
  420. ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
  421. Address: net.NewIPOrDomain(dest.Address),
  422. Port: uint32(dest.Port),
  423. NetworkList: &net.NetworkList{
  424. Network: []net.Network{net.Network_TCP},
  425. },
  426. }),
  427. },
  428. },
  429. Outbound: []*core.OutboundHandlerConfig{
  430. {
  431. ProxySettings: serial.ToTypedMessage(&outbound.Config{
  432. Receiver: []*protocol.ServerEndpoint{
  433. {
  434. Address: net.NewIPOrDomain(net.LocalHostIP),
  435. Port: uint32(serverPort),
  436. User: []*protocol.User{
  437. {
  438. Account: serial.ToTypedMessage(&vmess.Account{
  439. Id: userID.String(),
  440. }),
  441. },
  442. },
  443. },
  444. },
  445. }),
  446. SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
  447. StreamSettings: &internet.StreamConfig{
  448. Protocol: internet.TransportProtocol_WebSocket,
  449. TransportSettings: []*internet.TransportConfig{
  450. {
  451. Protocol: internet.TransportProtocol_WebSocket,
  452. Settings: serial.ToTypedMessage(&websocket.Config{}),
  453. },
  454. },
  455. SecurityType: serial.GetMessageType(&tls.Config{}),
  456. SecuritySettings: []*serial.TypedMessage{
  457. serial.ToTypedMessage(&tls.Config{
  458. AllowInsecure: true,
  459. }),
  460. },
  461. },
  462. }),
  463. },
  464. },
  465. }
  466. servers, err := InitializeServerConfigs(serverConfig, clientConfig)
  467. assert(err, IsNil)
  468. conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
  469. IP: []byte{127, 0, 0, 1},
  470. Port: int(clientPort),
  471. })
  472. assert(err, IsNil)
  473. payload := make([]byte, 10240*1024)
  474. rand.Read(payload)
  475. nBytes, err := conn.Write([]byte(payload))
  476. assert(err, IsNil)
  477. assert(nBytes, Equals, len(payload))
  478. response := readFrom(conn, time.Second*20, len(payload))
  479. assert(response, Equals, xor([]byte(payload)))
  480. assert(conn.Close(), IsNil)
  481. CloseAllServers(servers)
  482. }
  483. func TestHTTP2(t *testing.T) {
  484. assert := With(t)
  485. tcpServer := tcp.Server{
  486. MsgProcessor: xor,
  487. }
  488. dest, err := tcpServer.Start()
  489. assert(err, IsNil)
  490. defer tcpServer.Close()
  491. userID := protocol.NewID(uuid.New())
  492. serverPort := tcp.PickPort()
  493. serverConfig := &core.Config{
  494. Inbound: []*core.InboundHandlerConfig{
  495. {
  496. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  497. PortRange: net.SinglePortRange(serverPort),
  498. Listen: net.NewIPOrDomain(net.LocalHostIP),
  499. StreamSettings: &internet.StreamConfig{
  500. Protocol: internet.TransportProtocol_HTTP,
  501. TransportSettings: []*internet.TransportConfig{
  502. {
  503. Protocol: internet.TransportProtocol_HTTP,
  504. Settings: serial.ToTypedMessage(&http.Config{
  505. Host: []string{"v2ray.com"},
  506. Path: "/testpath",
  507. }),
  508. },
  509. },
  510. SecurityType: serial.GetMessageType(&tls.Config{}),
  511. SecuritySettings: []*serial.TypedMessage{
  512. serial.ToTypedMessage(&tls.Config{
  513. Certificate: []*tls.Certificate{tls.ParseCertificate(cert.MustGenerate(nil))},
  514. }),
  515. },
  516. },
  517. }),
  518. ProxySettings: serial.ToTypedMessage(&inbound.Config{
  519. User: []*protocol.User{
  520. {
  521. Account: serial.ToTypedMessage(&vmess.Account{
  522. Id: userID.String(),
  523. }),
  524. },
  525. },
  526. }),
  527. },
  528. },
  529. Outbound: []*core.OutboundHandlerConfig{
  530. {
  531. ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
  532. },
  533. },
  534. }
  535. clientPort := tcp.PickPort()
  536. clientConfig := &core.Config{
  537. Inbound: []*core.InboundHandlerConfig{
  538. {
  539. ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
  540. PortRange: net.SinglePortRange(clientPort),
  541. Listen: net.NewIPOrDomain(net.LocalHostIP),
  542. }),
  543. ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
  544. Address: net.NewIPOrDomain(dest.Address),
  545. Port: uint32(dest.Port),
  546. NetworkList: &net.NetworkList{
  547. Network: []net.Network{net.Network_TCP},
  548. },
  549. }),
  550. },
  551. },
  552. Outbound: []*core.OutboundHandlerConfig{
  553. {
  554. ProxySettings: serial.ToTypedMessage(&outbound.Config{
  555. Receiver: []*protocol.ServerEndpoint{
  556. {
  557. Address: net.NewIPOrDomain(net.LocalHostIP),
  558. Port: uint32(serverPort),
  559. User: []*protocol.User{
  560. {
  561. Account: serial.ToTypedMessage(&vmess.Account{
  562. Id: userID.String(),
  563. }),
  564. },
  565. },
  566. },
  567. },
  568. }),
  569. SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
  570. StreamSettings: &internet.StreamConfig{
  571. Protocol: internet.TransportProtocol_HTTP,
  572. TransportSettings: []*internet.TransportConfig{
  573. {
  574. Protocol: internet.TransportProtocol_HTTP,
  575. Settings: serial.ToTypedMessage(&http.Config{
  576. Host: []string{"v2ray.com"},
  577. Path: "/testpath",
  578. }),
  579. },
  580. },
  581. SecurityType: serial.GetMessageType(&tls.Config{}),
  582. SecuritySettings: []*serial.TypedMessage{
  583. serial.ToTypedMessage(&tls.Config{
  584. AllowInsecure: true,
  585. }),
  586. },
  587. },
  588. }),
  589. },
  590. },
  591. }
  592. servers, err := InitializeServerConfigs(serverConfig, clientConfig)
  593. assert(err, IsNil)
  594. var wg sync.WaitGroup
  595. for i := 0; i < 10; i++ {
  596. wg.Add(1)
  597. go func() {
  598. defer wg.Done()
  599. conn, err := net.DialTCP("tcp", nil, &net.TCPAddr{
  600. IP: []byte{127, 0, 0, 1},
  601. Port: int(clientPort),
  602. })
  603. assert(err, IsNil)
  604. payload := make([]byte, 10240*1024)
  605. rand.Read(payload)
  606. nBytes, err := conn.Write([]byte(payload))
  607. assert(err, IsNil)
  608. assert(nBytes, Equals, len(payload))
  609. response := readFrom(conn, time.Second*20, len(payload))
  610. assert(response, Equals, xor([]byte(payload)))
  611. assert(conn.Close(), IsNil)
  612. }()
  613. }
  614. wg.Wait()
  615. CloseAllServers(servers)
  616. }