summaryrefslogtreecommitdiffstats
path: root/blimp
diff options
context:
space:
mode:
Diffstat (limited to 'blimp')
-rw-r--r--blimp/client/BUILD.gn22
-rw-r--r--blimp/client/DEPS3
-rw-r--r--blimp/client/app/android/blimp_jni_registrar.cc2
-rw-r--r--blimp/client/app/blimp_client_switches.cc12
-rw-r--r--blimp/client/app/blimp_client_switches.h20
-rw-r--r--blimp/client/session/assignment_source.cc239
-rw-r--r--blimp/client/session/assignment_source.h57
-rw-r--r--blimp/client/session/assignment_source_unittest.cc270
-rw-r--r--blimp/client/session/blimp_client_session.cc22
-rw-r--r--blimp/client/session/test_selfsigned_cert.pem11
-rw-r--r--blimp/docs/running.md13
-rw-r--r--blimp/engine/BUILD.gn2
-rw-r--r--blimp/net/BUILD.gn5
-rw-r--r--blimp/net/DEPS3
-rw-r--r--blimp/net/blimp_transport.h2
-rw-r--r--blimp/net/exact_match_cert_verifier.cc56
-rw-r--r--blimp/net/exact_match_cert_verifier.h50
-rw-r--r--blimp/net/ssl_client_transport.cc91
-rw-r--r--blimp/net/ssl_client_transport.h64
-rw-r--r--blimp/net/ssl_client_transport_unittest.cc162
-rw-r--r--blimp/net/tcp_client_transport.cc46
-rw-r--r--blimp/net/tcp_client_transport.h32
-rw-r--r--blimp/net/tcp_engine_transport.cc2
-rw-r--r--blimp/net/tcp_engine_transport.h2
-rw-r--r--blimp/net/tcp_transport_unittest.cc14
-rw-r--r--blimp/net/test_common.cc2
-rw-r--r--blimp/net/test_common.h2
27 files changed, 923 insertions, 283 deletions
diff --git a/blimp/client/BUILD.gn b/blimp/client/BUILD.gn
index d2ddc2b..465adb7 100644
--- a/blimp/client/BUILD.gn
+++ b/blimp/client/BUILD.gn
@@ -27,6 +27,7 @@ source_set("blimp_client") {
defines = [ "BLIMP_CLIENT_IMPLEMENTATION=1" ]
public_deps = [
+ "//components/safe_json",
"//ui/events",
]
@@ -49,12 +50,6 @@ source_set("blimp_client_unit_tests") {
sources = []
- # TODO(dtrainor): Fix the test harness to allow this to run on Android.
- # See crbug.com/588240.
- if (is_linux) {
- sources += [ "session/assignment_source_unittest.cc" ]
- }
-
deps = [
":blimp_client",
"//base",
@@ -63,6 +58,19 @@ source_set("blimp_client_unit_tests") {
"//testing/gmock",
"//testing/gtest",
]
+
+ data = []
+
+ # TODO(dtrainor): Fix the test harness to allow this to run on Android.
+ # See crbug.com/588240.
+ if (is_linux) {
+ sources += [ "session/assignment_source_unittest.cc" ]
+ deps += [
+ "//components/safe_json:test_support",
+ "//net:test_support",
+ ]
+ data += [ "session/test_selfsigned_cert.pem" ]
+ }
}
source_set("app_unit_tests") {
@@ -342,6 +350,7 @@ if (is_android) {
"//base",
"//blimp/common/proto",
"//blimp/net:blimp_net",
+ "//components/safe_json/android:safe_json_jni_headers",
"//skia",
"//ui/gfx/geometry",
"//ui/gl",
@@ -375,6 +384,7 @@ if (is_android) {
":blimp_java",
":blimp_java_resources",
"//base:base_java",
+ "//components/safe_json/android:safe_json_java",
"//net/android:net_java",
google_play_services_resources,
]
diff --git a/blimp/client/DEPS b/blimp/client/DEPS
index 62e4870..e1fa29a 100644
--- a/blimp/client/DEPS
+++ b/blimp/client/DEPS
@@ -2,7 +2,8 @@ include_rules = [
"+base",
"+cc",
"-cc/blink",
- "-chrome"
+ "-chrome",
+ "+components/safe_json",
"-content",
"+gpu",
"+jni",
diff --git a/blimp/client/app/android/blimp_jni_registrar.cc b/blimp/client/app/android/blimp_jni_registrar.cc
index 0ad0bcb..2f6ad4d 100644
--- a/blimp/client/app/android/blimp_jni_registrar.cc
+++ b/blimp/client/app/android/blimp_jni_registrar.cc
@@ -10,6 +10,7 @@
#include "blimp/client/app/android/blimp_view.h"
#include "blimp/client/app/android/tab_control_feature_android.h"
#include "blimp/client/app/android/toolbar.h"
+#include "components/safe_json/android/component_jni_registrar.h"
namespace blimp {
namespace client {
@@ -20,6 +21,7 @@ base::android::RegistrationMethod kBlimpRegistrationMethods[] = {
{"Toolbar", Toolbar::RegisterJni},
{"BlimpView", BlimpView::RegisterJni},
{"BlimpClientSessionAndroid", BlimpClientSessionAndroid::RegisterJni},
+ {"SafeJson", safe_json::android::RegisterSafeJsonJni},
{"TabControlFeatureAndroid", TabControlFeatureAndroid::RegisterJni},
};
diff --git a/blimp/client/app/blimp_client_switches.cc b/blimp/client/app/blimp_client_switches.cc
index cfcf2a0..da7dcda 100644
--- a/blimp/client/app/blimp_client_switches.cc
+++ b/blimp/client/app/blimp_client_switches.cc
@@ -7,11 +7,13 @@
namespace blimp {
namespace switches {
-// Specifies the blimplet scheme, IP-address and port to connect to, e.g.:
-// --blimplet-host="tcp:127.0.0.1:25467". Valid schemes are "ssl",
-// "tcp", and "quic".
-// TODO(nyquist): Add support for DNS-lookup. See http://crbug.com/576857.
-const char kBlimpletEndpoint[] = "blimplet-endpoint";
+const char kEngineCertPath[] = "engine-cert-path";
+
+const char kEngineIP[] = "engine-ip";
+
+const char kEnginePort[] = "engine-port";
+
+const char kEngineTransport[] = "engine-transport";
} // namespace switches
} // namespace blimp
diff --git a/blimp/client/app/blimp_client_switches.h b/blimp/client/app/blimp_client_switches.h
index 19b91dd..b06958f 100644
--- a/blimp/client/app/blimp_client_switches.h
+++ b/blimp/client/app/blimp_client_switches.h
@@ -10,7 +10,25 @@
namespace blimp {
namespace switches {
-extern const char kBlimpletEndpoint[];
+// The path to the engine's PEM-encoded X509 certificate.
+// If specified, SSL connected Engines must supply this certificate
+// for the connection to be valid.
+// e.g.:
+// --engine-cert-path=/home/blimp/certs/cert.pem
+extern const char kEngineCertPath[];
+
+// Specifies the engine's IP address. Must be used in conjunction with
+// --engine-port and --engine-transport.
+extern const char kEngineIP[];
+
+// Specifies the engine's listening port (1-65535).
+// Must be used in conjunction with --engine-ip and --engine-transport.
+extern const char kEnginePort[];
+
+// Specifies the transport used to communicate with the engine.
+// Can be "tcp" or "ssl".
+// Must be used in conjunction with --engine-ip and --engine-port.
+extern const char kEngineTransport[];
} // namespace switches
} // namespace blimp
diff --git a/blimp/client/session/assignment_source.cc b/blimp/client/session/assignment_source.cc
index 242d783..bbd8d1a 100644
--- a/blimp/client/session/assignment_source.cc
+++ b/blimp/client/session/assignment_source.cc
@@ -7,19 +7,22 @@
#include "base/bind.h"
#include "base/callback_helpers.h"
#include "base/command_line.h"
+#include "base/files/file_util.h"
#include "base/json/json_reader.h"
#include "base/json/json_writer.h"
#include "base/location.h"
+#include "base/memory/ref_counted.h"
#include "base/numerics/safe_conversions.h"
#include "base/strings/string_number_conversions.h"
+#include "base/task_runner_util.h"
#include "base/values.h"
#include "blimp/client/app/blimp_client_switches.h"
#include "blimp/common/protocol_version.h"
+#include "components/safe_json/safe_json_parser.h"
#include "net/base/ip_address.h"
#include "net/base/ip_endpoint.h"
#include "net/base/load_flags.h"
#include "net/base/net_errors.h"
-#include "net/base/url_util.h"
#include "net/http/http_status_code.h"
#include "net/proxy/proxy_config_service.h"
#include "net/proxy/proxy_service.h"
@@ -40,55 +43,11 @@ const char kProtocolVersionKey[] = "protocol_version";
const char kClientTokenKey[] = "clientToken";
const char kHostKey[] = "host";
const char kPortKey[] = "port";
-const char kCertificateFingerprintKey[] = "certificateFingerprint";
const char kCertificateKey[] = "certificate";
-// URL scheme constants for custom assignments. See the '--blimplet-endpoint'
-// documentation in blimp_client_switches.cc for details.
-const char kCustomSSLScheme[] = "ssl";
-const char kCustomTCPScheme[] = "tcp";
-const char kCustomQUICScheme[] = "quic";
-
-Assignment GetCustomBlimpletAssignment() {
- GURL url(base::CommandLine::ForCurrentProcess()->GetSwitchValueASCII(
- switches::kBlimpletEndpoint));
-
- std::string host;
- int port;
- if (url.is_empty() || !url.is_valid() || !url.has_scheme() ||
- !net::ParseHostAndPort(url.path(), &host, &port)) {
- return Assignment();
- }
-
- net::IPAddress ip_address;
- if (!ip_address.AssignFromIPLiteral(host)) {
- CHECK(false) << "Invalid BlimpletAssignment host " << host;
- }
-
- if (!base::IsValueInRangeForNumericType<uint16_t>(port)) {
- CHECK(false) << "Invalid BlimpletAssignment port " << port;
- }
-
- Assignment::TransportProtocol protocol =
- Assignment::TransportProtocol::UNKNOWN;
- if (url.has_scheme()) {
- if (url.SchemeIs(kCustomSSLScheme)) {
- protocol = Assignment::TransportProtocol::SSL;
- } else if (url.SchemeIs(kCustomTCPScheme)) {
- protocol = Assignment::TransportProtocol::TCP;
- } else if (url.SchemeIs(kCustomQUICScheme)) {
- protocol = Assignment::TransportProtocol::QUIC;
- } else {
- CHECK(false) << "Invalid BlimpletAssignment scheme " << url.scheme();
- }
- }
-
- Assignment assignment;
- assignment.transport_protocol = protocol;
- assignment.ip_endpoint = net::IPEndPoint(ip_address, port);
- assignment.client_token = kDummyClientToken;
- return assignment;
-}
+// Possible arguments for the "--engine-transport" command line parameter.
+const char kSSLTransportValue[] = "ssl";
+const char kTCPTransportValue[] = "tcp";
GURL GetBlimpAssignerURL() {
// TODO(dtrainor): Add a way to specify another assigner.
@@ -98,8 +57,8 @@ GURL GetBlimpAssignerURL() {
class SimpleURLRequestContextGetter : public net::URLRequestContextGetter {
public:
SimpleURLRequestContextGetter(
- const scoped_refptr<base::SingleThreadTaskRunner>& io_loop_task_runner)
- : io_loop_task_runner_(io_loop_task_runner),
+ scoped_refptr<base::SingleThreadTaskRunner> io_loop_task_runner)
+ : io_loop_task_runner_(std::move(io_loop_task_runner)),
proxy_config_service_(net::ProxyService::CreateSystemProxyConfigService(
io_loop_task_runner_,
io_loop_task_runner_)) {}
@@ -136,45 +95,142 @@ class SimpleURLRequestContextGetter : public net::URLRequestContextGetter {
DISALLOW_COPY_AND_ASSIGN(SimpleURLRequestContextGetter);
};
+bool IsValidIpPortNumber(unsigned port) {
+ return port > 0 && port <= 65535;
+}
+
+// Populates an Assignment using command-line parameters, if provided.
+// Returns a null Assignment if no parameters were set.
+// Must be called on a thread suitable for file IO.
+Assignment GetAssignmentFromCommandLine() {
+ Assignment assignment;
+ assignment.client_token = kDummyClientToken;
+
+ unsigned port_parsed = 0;
+ if (!base::StringToUint(
+ base::CommandLine::ForCurrentProcess()->GetSwitchValueASCII(
+ switches::kEnginePort),
+ &port_parsed) ||
+ !IsValidIpPortNumber(port_parsed)) {
+ DLOG(FATAL) << "--engine-port must be a value between 1 and 65535.";
+ return Assignment();
+ }
+
+ net::IPAddress ip_address;
+ std::string ip_str =
+ base::CommandLine::ForCurrentProcess()->GetSwitchValueASCII(
+ switches::kEngineIP);
+ if (!ip_address.AssignFromIPLiteral(ip_str)) {
+ DLOG(FATAL) << "Invalid engine IP " << ip_str;
+ return Assignment();
+ }
+ assignment.engine_endpoint =
+ net::IPEndPoint(ip_address, base::checked_cast<uint16_t>(port_parsed));
+
+ std::string transport_str =
+ base::CommandLine::ForCurrentProcess()->GetSwitchValueASCII(
+ switches::kEngineTransport);
+ if (transport_str == kSSLTransportValue) {
+ assignment.transport_protocol = Assignment::TransportProtocol::SSL;
+ } else if (transport_str == kTCPTransportValue) {
+ assignment.transport_protocol = Assignment::TransportProtocol::TCP;
+ } else {
+ DLOG(FATAL) << "Invalid engine transport " << transport_str;
+ return Assignment();
+ }
+
+ scoped_refptr<net::X509Certificate> cert;
+ if (assignment.transport_protocol == Assignment::TransportProtocol::SSL) {
+ base::FilePath cert_path =
+ base::CommandLine::ForCurrentProcess()->GetSwitchValuePath(
+ switches::kEngineCertPath);
+ if (cert_path.empty()) {
+ DLOG(FATAL) << "Missing required parameter --"
+ << switches::kEngineCertPath << ".";
+ return Assignment();
+ }
+ std::string cert_str;
+ if (!base::ReadFileToString(cert_path, &cert_str)) {
+ DLOG(FATAL) << "Couldn't read from file: "
+ << cert_path.LossyDisplayName();
+ return Assignment();
+ }
+ net::CertificateList cert_list =
+ net::X509Certificate::CreateCertificateListFromBytes(
+ cert_str.data(), cert_str.size(),
+ net::X509Certificate::FORMAT_PEM_CERT_SEQUENCE);
+ DLOG_IF(FATAL, (cert_list.size() != 1u))
+ << "Only one cert is allowed in PEM cert list.";
+ assignment.cert = std::move(cert_list[0]);
+ }
+
+ if (!assignment.IsValid()) {
+ DLOG(FATAL) << "Invalid command-line assignment.";
+ return Assignment();
+ }
+
+ return assignment;
+}
+
} // namespace
Assignment::Assignment() : transport_protocol(TransportProtocol::UNKNOWN) {}
Assignment::~Assignment() {}
-bool Assignment::is_null() const {
- return ip_endpoint.address().empty() || ip_endpoint.port() == 0 ||
- transport_protocol == TransportProtocol::UNKNOWN;
+bool Assignment::IsValid() const {
+ if (engine_endpoint.address().empty() || engine_endpoint.port() == 0 ||
+ transport_protocol == TransportProtocol::UNKNOWN) {
+ return false;
+ }
+ if (transport_protocol == TransportProtocol::SSL && !cert) {
+ return false;
+ }
+ return true;
}
AssignmentSource::AssignmentSource(
- const scoped_refptr<base::SingleThreadTaskRunner>& main_task_runner,
- const scoped_refptr<base::SingleThreadTaskRunner>& io_task_runner)
- : main_task_runner_(main_task_runner),
- url_request_context_(new SimpleURLRequestContextGetter(io_task_runner)) {}
+ const scoped_refptr<base::SingleThreadTaskRunner>& network_task_runner,
+ const scoped_refptr<base::SingleThreadTaskRunner>& file_task_runner)
+ : file_task_runner_(std::move(file_task_runner)),
+ url_request_context_(
+ new SimpleURLRequestContextGetter(network_task_runner)),
+ weak_factory_(this) {}
AssignmentSource::~AssignmentSource() {}
void AssignmentSource::GetAssignment(const std::string& client_auth_token,
const AssignmentCallback& callback) {
- DCHECK(main_task_runner_->BelongsToCurrentThread());
+ DCHECK(callback_.is_null());
+ callback_ = AssignmentCallback(callback);
- // Cancel any outstanding callback.
- if (!callback_.is_null()) {
- base::ResetAndReturn(&callback_)
- .Run(AssignmentSource::Result::RESULT_SERVER_INTERRUPTED, Assignment());
+ if (base::CommandLine::ForCurrentProcess()->HasSwitch(switches::kEngineIP)) {
+ base::PostTaskAndReplyWithResult(
+ file_task_runner_.get(), FROM_HERE,
+ base::Bind(&GetAssignmentFromCommandLine),
+ base::Bind(&AssignmentSource::OnGetAssignmentFromCommandLineDone,
+ weak_factory_.GetWeakPtr(), client_auth_token));
+ } else {
+ QueryAssigner(client_auth_token);
}
- callback_ = AssignmentCallback(callback);
+}
- Assignment assignment = GetCustomBlimpletAssignment();
- if (!assignment.is_null()) {
- // Post the result so that the behavior of this function is consistent.
- main_task_runner_->PostTask(
- FROM_HERE, base::Bind(base::ResetAndReturn(&callback_),
- AssignmentSource::Result::RESULT_OK, assignment));
+void AssignmentSource::OnGetAssignmentFromCommandLineDone(
+ const std::string& client_auth_token,
+ Assignment parsed_assignment) {
+ // If GetAssignmentFromCommandLine succeeded, then return its output.
+ if (parsed_assignment.IsValid()) {
+ base::ResetAndReturn(&callback_)
+ .Run(AssignmentSource::RESULT_OK, parsed_assignment);
return;
}
+ // If no assignment was passed via the command line, then fall back on
+ // querying the Assigner service.
+ QueryAssigner(client_auth_token);
+}
+
+void AssignmentSource::QueryAssigner(const std::string& client_auth_token) {
// Call out to the network for a real assignment. Build the network request
// to hit the assigner.
url_fetcher_ = net::URLFetcher::Create(GetBlimpAssignerURL(),
@@ -191,12 +247,10 @@ void AssignmentSource::GetAssignment(const std::string& client_auth_token,
std::string json;
base::JSONWriter::Write(dictionary, &json);
url_fetcher_->SetUploadData("application/json", json);
-
url_fetcher_->Start();
}
void AssignmentSource::OnURLFetchComplete(const net::URLFetcher* source) {
- DCHECK(main_task_runner_->BelongsToCurrentThread());
DCHECK(!callback_.is_null());
DCHECK_EQ(url_fetcher_.get(), source);
@@ -253,14 +307,14 @@ void AssignmentSource::ParseAssignerResponse() {
return;
}
- // Attempt to interpret the response as JSON and treat it as a dictionary.
- scoped_ptr<base::Value> json = base::JSONReader::Read(response);
- if (!json) {
- base::ResetAndReturn(&callback_)
- .Run(AssignmentSource::Result::RESULT_BAD_RESPONSE, Assignment());
- return;
- }
+ safe_json::SafeJsonParser::Parse(
+ response,
+ base::Bind(&AssignmentSource::OnJsonParsed, weak_factory_.GetWeakPtr()),
+ base::Bind(&AssignmentSource::OnJsonParseError,
+ weak_factory_.GetWeakPtr()));
+}
+void AssignmentSource::OnJsonParsed(scoped_ptr<base::Value> json) {
const base::DictionaryValue* dict;
if (!json->GetAsDictionary(&dict)) {
base::ResetAndReturn(&callback_)
@@ -272,12 +326,10 @@ void AssignmentSource::ParseAssignerResponse() {
std::string client_token;
std::string host;
int port;
- std::string cert_fingerprint;
- std::string cert;
+ std::string cert_str;
if (!(dict->GetString(kClientTokenKey, &client_token) &&
dict->GetString(kHostKey, &host) && dict->GetInteger(kPortKey, &port) &&
- dict->GetString(kCertificateFingerprintKey, &cert_fingerprint) &&
- dict->GetString(kCertificateKey, &cert))) {
+ dict->GetString(kCertificateKey, &cert_str))) {
base::ResetAndReturn(&callback_)
.Run(AssignmentSource::Result::RESULT_BAD_RESPONSE, Assignment());
return;
@@ -296,18 +348,33 @@ void AssignmentSource::ParseAssignerResponse() {
return;
}
- Assignment assignment;
+ net::CertificateList cert_list =
+ net::X509Certificate::CreateCertificateListFromBytes(
+ cert_str.data(), cert_str.size(),
+ net::X509Certificate::FORMAT_PEM_CERT_SEQUENCE);
+ if (cert_list.size() != 1) {
+ base::ResetAndReturn(&callback_)
+ .Run(AssignmentSource::Result::RESULT_INVALID_CERT, Assignment());
+ return;
+ }
+
// The assigner assumes SSL-only and all engines it assigns only communicate
// over SSL.
+ Assignment assignment;
assignment.transport_protocol = Assignment::TransportProtocol::SSL;
- assignment.ip_endpoint = net::IPEndPoint(ip_address, port);
+ assignment.engine_endpoint = net::IPEndPoint(ip_address, port);
assignment.client_token = client_token;
- assignment.certificate = cert;
- assignment.certificate_fingerprint = cert_fingerprint;
+ assignment.cert = std::move(cert_list[0]);
base::ResetAndReturn(&callback_)
.Run(AssignmentSource::Result::RESULT_OK, assignment);
}
+void AssignmentSource::OnJsonParseError(const std::string& error) {
+ DLOG(ERROR) << "Error while parsing assigner JSON: " << error;
+ base::ResetAndReturn(&callback_)
+ .Run(AssignmentSource::Result::RESULT_BAD_RESPONSE, Assignment());
+}
+
} // namespace client
} // namespace blimp
diff --git a/blimp/client/session/assignment_source.h b/blimp/client/session/assignment_source.h
index dabe72c..bafd021 100644
--- a/blimp/client/session/assignment_source.h
+++ b/blimp/client/session/assignment_source.h
@@ -8,17 +8,21 @@
#include <string>
#include "base/callback.h"
+#include "base/memory/weak_ptr.h"
#include "blimp/client/blimp_client_export.h"
#include "net/base/ip_endpoint.h"
#include "net/url_request/url_fetcher_delegate.h"
namespace base {
+class FilePath;
class SingleThreadTaskRunner;
+class Value;
}
namespace net {
class URLFetcher;
class URLRequestContextGetter;
+class X509Certificate;
}
namespace blimp {
@@ -38,21 +42,26 @@ struct BLIMP_CLIENT_EXPORT Assignment {
UNKNOWN = 0,
SSL = 1,
TCP = 2,
- QUIC = 3,
};
Assignment();
~Assignment();
+ // Returns true if the net::IPEndPoint has an unspecified IP, port, or
+ // transport protocol.
+ bool IsValid() const;
+
+ // Specifies the transport to use to connect to the engine.
TransportProtocol transport_protocol;
- net::IPEndPoint ip_endpoint;
+
+ // Specifies the IP address and port on which to reach the engine.
+ net::IPEndPoint engine_endpoint;
+
+ // Used to authenticate to the specified engine.
std::string client_token;
- std::string certificate;
- std::string certificate_fingerprint;
- // Returns true if the net::IPEndPoint has an unspecified IP, port, or
- // transport protocol.
- bool is_null() const;
+ // Specifies the X.509 certificate that the engine must report.
+ scoped_refptr<net::X509Certificate> cert;
};
// AssignmentSource provides functionality to find out how a client should
@@ -72,18 +81,21 @@ class BLIMP_CLIENT_EXPORT AssignmentSource : public net::URLFetcherDelegate {
RESULT_OUT_OF_VMS = 7,
RESULT_SERVER_ERROR = 8,
RESULT_SERVER_INTERRUPTED = 9,
- RESULT_NETWORK_FAILURE = 10
+ RESULT_NETWORK_FAILURE = 10,
+ RESULT_INVALID_CERT = 11,
};
typedef base::Callback<void(AssignmentSource::Result, const Assignment&)>
AssignmentCallback;
- // The |main_task_runner| should be the task runner for the UI thread because
- // this will in some cases be used to trigger user interaction on the UI
- // thread.
+ // |network_task_runner|: The task runner to use for querying the Assigner API
+ // over the network.
+ // |file_task_runner|: The task runner to use for reading cert files from disk
+ // (specified on the command line.)
AssignmentSource(
- const scoped_refptr<base::SingleThreadTaskRunner>& main_task_runner,
- const scoped_refptr<base::SingleThreadTaskRunner>& io_task_runner);
+ const scoped_refptr<base::SingleThreadTaskRunner>& network_task_runner,
+ const scoped_refptr<base::SingleThreadTaskRunner>& file_task_runner);
+
~AssignmentSource() override;
// Retrieves a valid assignment for the client and posts the result to the
@@ -94,20 +106,25 @@ class BLIMP_CLIENT_EXPORT AssignmentSource : public net::URLFetcherDelegate {
void GetAssignment(const std::string& client_auth_token,
const AssignmentCallback& callback);
- // net::URLFetcherDelegate implementation:
- void OnURLFetchComplete(const net::URLFetcher* source) override;
-
private:
+ void OnGetAssignmentFromCommandLineDone(const std::string& client_auth_token,
+ Assignment parsed_assignment);
+ void QueryAssigner(const std::string& client_auth_token);
void ParseAssignerResponse();
+ void OnJsonParsed(scoped_ptr<base::Value> json);
+ void OnJsonParseError(const std::string& error);
+
+ // net::URLFetcherDelegate implementation:
+ void OnURLFetchComplete(const net::URLFetcher* source) override;
- scoped_refptr<base::SingleThreadTaskRunner> main_task_runner_;
+ // GetAssignment() callback, invoked after URLFetcher completion.
+ AssignmentCallback callback_;
+ scoped_refptr<base::SingleThreadTaskRunner> file_task_runner_;
scoped_refptr<net::URLRequestContextGetter> url_request_context_;
scoped_ptr<net::URLFetcher> url_fetcher_;
- // This callback is set during a call to GetAssignment() and is cleared after
- // the request has completed (whether it be a success or failure).
- AssignmentCallback callback_;
+ base::WeakPtrFactory<AssignmentSource> weak_factory_;
DISALLOW_COPY_AND_ASSIGN(AssignmentSource);
};
diff --git a/blimp/client/session/assignment_source_unittest.cc b/blimp/client/session/assignment_source_unittest.cc
index d893ae3..54f3e44 100644
--- a/blimp/client/session/assignment_source_unittest.cc
+++ b/blimp/client/session/assignment_source_unittest.cc
@@ -5,68 +5,80 @@
#include "blimp/client/session/assignment_source.h"
#include "base/command_line.h"
+#include "base/files/file_path.h"
+#include "base/files/file_util.h"
#include "base/json/json_reader.h"
#include "base/json/json_writer.h"
+#include "base/message_loop/message_loop.h"
+#include "base/path_service.h"
+#include "base/run_loop.h"
#include "base/test/test_simple_task_runner.h"
#include "base/thread_task_runner_handle.h"
#include "base/values.h"
#include "blimp/client/app/blimp_client_switches.h"
#include "blimp/common/protocol_version.h"
+#include "components/safe_json/testing_json_parser.h"
+#include "net/base/test_data_directory.h"
#include "net/url_request/test_url_fetcher_factory.h"
#include "testing/gmock/include/gmock/gmock.h"
#include "testing/gtest/include/gtest/gtest.h"
using testing::_;
+using testing::DoAll;
using testing::InSequence;
+using testing::NotNull;
+using testing::Return;
+using testing::SetArgPointee;
namespace blimp {
namespace client {
namespace {
+const uint8_t kTestIpAddress[] = {127, 0, 0, 1};
+const uint16_t kTestPort = 8086;
+const char kTestIpAddressString[] = "127.0.0.1";
+const char kTcpTransportName[] = "tcp";
+const char kSslTransportName[] = "ssl";
+const char kCertRelativePath[] =
+ "blimp/client/session/test_selfsigned_cert.pem";
+const char kTestClientToken[] = "secrett0ken";
+const char kTestAuthToken[] = "UserAuthT0kenz";
+
MATCHER_P(AssignmentEquals, assignment, "") {
return arg.transport_protocol == assignment.transport_protocol &&
- arg.ip_endpoint == assignment.ip_endpoint &&
+ arg.engine_endpoint == assignment.engine_endpoint &&
arg.client_token == assignment.client_token &&
- arg.certificate == assignment.certificate &&
- arg.certificate_fingerprint == assignment.certificate_fingerprint;
-}
-
-net::IPEndPoint BuildIPEndPoint(const std::string& ip, int port) {
- net::IPAddress ip_address;
- EXPECT_TRUE(ip_address.AssignFromIPLiteral(ip));
-
- return net::IPEndPoint(ip_address, port);
-}
-
-Assignment BuildValidAssignment() {
- Assignment assignment;
- assignment.transport_protocol = Assignment::TransportProtocol::SSL;
- assignment.ip_endpoint = BuildIPEndPoint("100.150.200.250", 500);
- assignment.client_token = "SecretT0kenz";
- assignment.certificate_fingerprint = "WhaleWhaleWhale";
- assignment.certificate = "whaaaaaaaaaaaaale";
- return assignment;
+ ((!assignment.cert && !arg.cert) ||
+ (arg.cert && assignment.cert &&
+ arg.cert->Equals(assignment.cert.get())));
}
-std::string BuildResponseFromAssignment(const Assignment& assignment) {
- base::DictionaryValue dict;
- dict.SetString("clientToken", assignment.client_token);
- dict.SetString("host", assignment.ip_endpoint.address().ToString());
- dict.SetInteger("port", assignment.ip_endpoint.port());
- dict.SetString("certificateFingerprint", assignment.certificate_fingerprint);
- dict.SetString("certificate", assignment.certificate);
-
+// Converts |value| to a JSON string.
+std::string ValueToString(const base::Value& value) {
std::string json;
- base::JSONWriter::Write(dict, &json);
+ base::JSONWriter::Write(value, &json);
return json;
}
class AssignmentSourceTest : public testing::Test {
public:
AssignmentSourceTest()
- : task_runner_(new base::TestSimpleTaskRunner),
- task_runner_handle_(task_runner_),
- source_(task_runner_, task_runner_) {}
+ : source_(message_loop_.task_runner(), message_loop_.task_runner()) {}
+
+ void SetUp() override {
+ base::FilePath src_root;
+ PathService::Get(base::DIR_SOURCE_ROOT, &src_root);
+ ASSERT_FALSE(src_root.empty());
+ cert_path_ = src_root.Append(kCertRelativePath);
+ ASSERT_TRUE(base::ReadFileToString(cert_path_, &cert_pem_));
+ net::CertificateList cert_list =
+ net::X509Certificate::CreateCertificateListFromBytes(
+ cert_pem_.data(), cert_pem_.size(),
+ net::X509Certificate::FORMAT_PEM_CERT_SEQUENCE);
+ ASSERT_FALSE(cert_list.empty());
+ cert_ = std::move(cert_list[0]);
+ ASSERT_TRUE(cert_);
+ }
// This expects the AssignmentSource::GetAssignment to return a custom
// endpoint without having to hit the network. This will typically be used
@@ -77,7 +89,7 @@ class AssignmentSourceTest : public testing::Test {
base::Bind(&AssignmentSourceTest::AssignmentResponse,
base::Unretained(this)));
EXPECT_EQ(nullptr, factory_.GetFetcherByID(0));
- task_runner_->RunUntilIdle();
+ base::RunLoop().RunUntilIdle();
}
// See net/base/net_errors.h for possible status errors.
@@ -90,11 +102,10 @@ class AssignmentSourceTest : public testing::Test {
source_.GetAssignment(client_auth_token,
base::Bind(&AssignmentSourceTest::AssignmentResponse,
base::Unretained(this)));
+ base::RunLoop().RunUntilIdle();
net::TestURLFetcher* fetcher = factory_.GetFetcherByID(0);
- task_runner_->RunUntilIdle();
-
EXPECT_NE(nullptr, fetcher);
EXPECT_EQ(kDefaultAssignerURL, fetcher->GetOriginalURL().spec());
@@ -125,30 +136,74 @@ class AssignmentSourceTest : public testing::Test {
fetcher->SetResponseString(response);
fetcher->delegate()->OnURLFetchComplete(fetcher);
- task_runner_->RunUntilIdle();
+ base::RunLoop().RunUntilIdle();
}
MOCK_METHOD2(AssignmentResponse,
void(AssignmentSource::Result, const Assignment&));
protected:
+ Assignment BuildSslAssignment();
+
+ // Builds simulated JSON response from the Assigner service.
+ scoped_ptr<base::DictionaryValue> BuildAssignerResponse();
+
// Used to drive all AssignmentSource tasks.
- scoped_refptr<base::TestSimpleTaskRunner> task_runner_;
- base::ThreadTaskRunnerHandle task_runner_handle_;
+ // MessageLoop is required by TestingJsonParser's self-deletion logic.
+ // TODO(bauerb): Replace this with a TestSimpleTaskRunner once
+ // TestingJsonParser no longer requires having a MessageLoop.
+ base::MessageLoop message_loop_;
net::TestURLFetcherFactory factory_;
+ // Path to the PEM-encoded certificate chain.
+ base::FilePath cert_path_;
+
+ // Payload of PEM certificate chain at |cert_path_|.
+ std::string cert_pem_;
+
+ // X509 certificate decoded from |cert_path_|.
+ scoped_refptr<net::X509Certificate> cert_;
+
AssignmentSource source_;
+
+ // Allows safe_json to parse JSON in-process, instead of depending on a
+ // utility proces.
+ safe_json::TestingJsonParser::ScopedFactoryOverride json_parsing_factory_;
};
+Assignment AssignmentSourceTest::BuildSslAssignment() {
+ Assignment assignment;
+ assignment.transport_protocol = Assignment::TransportProtocol::SSL;
+ assignment.engine_endpoint = net::IPEndPoint(kTestIpAddress, kTestPort);
+ assignment.client_token = kTestClientToken;
+ assignment.cert = cert_;
+ return assignment;
+}
+
+scoped_ptr<base::DictionaryValue>
+AssignmentSourceTest::BuildAssignerResponse() {
+ scoped_ptr<base::DictionaryValue> dict(new base::DictionaryValue);
+ dict->SetString("clientToken", kTestClientToken);
+ dict->SetString("host", kTestIpAddressString);
+ dict->SetInteger("port", kTestPort);
+ dict->SetString("certificate", cert_pem_);
+ return dict;
+}
+
TEST_F(AssignmentSourceTest, TestTCPAlternateEndpointSuccess) {
Assignment assignment;
assignment.transport_protocol = Assignment::TransportProtocol::TCP;
- assignment.ip_endpoint = BuildIPEndPoint("100.150.200.250", 500);
+ assignment.engine_endpoint = net::IPEndPoint(kTestIpAddress, kTestPort);
assignment.client_token = kDummyClientToken;
+ assignment.cert = scoped_refptr<net::X509Certificate>(nullptr);
base::CommandLine::ForCurrentProcess()->AppendSwitchASCII(
- switches::kBlimpletEndpoint, "tcp:100.150.200.250:500");
+ switches::kEngineIP, kTestIpAddressString);
+ base::CommandLine::ForCurrentProcess()->AppendSwitchASCII(
+ switches::kEnginePort, std::to_string(kTestPort));
+ base::CommandLine::ForCurrentProcess()->AppendSwitchASCII(
+ switches::kEngineTransport, kTcpTransportName);
EXPECT_CALL(*this, AssignmentResponse(AssignmentSource::Result::RESULT_OK,
AssignmentEquals(assignment)))
@@ -160,27 +215,18 @@ TEST_F(AssignmentSourceTest, TestTCPAlternateEndpointSuccess) {
TEST_F(AssignmentSourceTest, TestSSLAlternateEndpointSuccess) {
Assignment assignment;
assignment.transport_protocol = Assignment::TransportProtocol::SSL;
- assignment.ip_endpoint = BuildIPEndPoint("100.150.200.250", 500);
+ assignment.engine_endpoint = net::IPEndPoint(kTestIpAddress, kTestPort);
assignment.client_token = kDummyClientToken;
+ assignment.cert = cert_;
base::CommandLine::ForCurrentProcess()->AppendSwitchASCII(
- switches::kBlimpletEndpoint, "ssl:100.150.200.250:500");
-
- EXPECT_CALL(*this, AssignmentResponse(AssignmentSource::Result::RESULT_OK,
- AssignmentEquals(assignment)))
- .Times(1);
-
- GetAlternateAssignment();
-}
-
-TEST_F(AssignmentSourceTest, TestQUICAlternateEndpointSuccess) {
- Assignment assignment;
- assignment.transport_protocol = Assignment::TransportProtocol::QUIC;
- assignment.ip_endpoint = BuildIPEndPoint("100.150.200.250", 500);
- assignment.client_token = kDummyClientToken;
-
+ switches::kEngineIP, kTestIpAddressString);
+ base::CommandLine::ForCurrentProcess()->AppendSwitchASCII(
+ switches::kEnginePort, std::to_string(kTestPort));
base::CommandLine::ForCurrentProcess()->AppendSwitchASCII(
- switches::kBlimpletEndpoint, "quic:100.150.200.250:500");
+ switches::kEngineTransport, kSslTransportName);
+ base::CommandLine::ForCurrentProcess()->AppendSwitchASCII(
+ switches::kEngineCertPath, cert_path_.value());
EXPECT_CALL(*this, AssignmentResponse(AssignmentSource::Result::RESULT_OK,
AssignmentEquals(assignment)))
@@ -190,44 +236,20 @@ TEST_F(AssignmentSourceTest, TestQUICAlternateEndpointSuccess) {
}
TEST_F(AssignmentSourceTest, TestSuccess) {
- Assignment assignment = BuildValidAssignment();
+ Assignment assignment = BuildSslAssignment();
EXPECT_CALL(*this, AssignmentResponse(AssignmentSource::Result::RESULT_OK,
AssignmentEquals(assignment)))
.Times(1);
GetNetworkAssignmentAndWaitForResponse(
- net::HTTP_OK, net::Error::OK, BuildResponseFromAssignment(assignment),
- "UserAuthT0kenz", kEngineVersion);
-}
-
-TEST_F(AssignmentSourceTest, TestSecondRequestInterruptsFirst) {
- InSequence sequence;
- Assignment assignment = BuildValidAssignment();
-
- source_.GetAssignment("",
- base::Bind(&AssignmentSourceTest::AssignmentResponse,
- base::Unretained(this)));
-
- EXPECT_CALL(*this, AssignmentResponse(
- AssignmentSource::Result::RESULT_SERVER_INTERRUPTED,
- AssignmentEquals(Assignment())))
- .Times(1)
- .RetiresOnSaturation();
-
- EXPECT_CALL(*this, AssignmentResponse(AssignmentSource::Result::RESULT_OK,
- AssignmentEquals(assignment)))
- .Times(1)
- .RetiresOnSaturation();
-
- GetNetworkAssignmentAndWaitForResponse(
- net::HTTP_OK, net::Error::OK, BuildResponseFromAssignment(assignment),
- "UserAuthT0kenz", kEngineVersion);
+ net::HTTP_OK, net::Error::OK, ValueToString(*BuildAssignerResponse()),
+ kTestAuthToken, kEngineVersion);
}
TEST_F(AssignmentSourceTest, TestValidAfterError) {
InSequence sequence;
- Assignment assignment = BuildValidAssignment();
+ Assignment assignment = BuildSslAssignment();
EXPECT_CALL(*this, AssignmentResponse(
AssignmentSource::Result::RESULT_NETWORK_FAILURE, _))
@@ -241,11 +263,11 @@ TEST_F(AssignmentSourceTest, TestValidAfterError) {
GetNetworkAssignmentAndWaitForResponse(net::HTTP_OK,
net::Error::ERR_INSUFFICIENT_RESOURCES,
- "", "UserAuthT0kenz", kEngineVersion);
+ "", kTestAuthToken, kEngineVersion);
GetNetworkAssignmentAndWaitForResponse(
- net::HTTP_OK, net::Error::OK, BuildResponseFromAssignment(assignment),
- "UserAuthT0kenz", kEngineVersion);
+ net::HTTP_OK, net::Error::OK, ValueToString(*BuildAssignerResponse()),
+ kTestAuthToken, kEngineVersion);
}
TEST_F(AssignmentSourceTest, TestNetworkFailure) {
@@ -253,14 +275,14 @@ TEST_F(AssignmentSourceTest, TestNetworkFailure) {
AssignmentSource::Result::RESULT_NETWORK_FAILURE, _));
GetNetworkAssignmentAndWaitForResponse(net::HTTP_OK,
net::Error::ERR_INSUFFICIENT_RESOURCES,
- "", "UserAuthT0kenz", kEngineVersion);
+ "", kTestAuthToken, kEngineVersion);
}
TEST_F(AssignmentSourceTest, TestBadRequest) {
EXPECT_CALL(*this, AssignmentResponse(
AssignmentSource::Result::RESULT_BAD_REQUEST, _));
GetNetworkAssignmentAndWaitForResponse(net::HTTP_BAD_REQUEST, net::Error::OK,
- "", "UserAuthT0kenz", kEngineVersion);
+ "", kTestAuthToken, kEngineVersion);
}
TEST_F(AssignmentSourceTest, TestUnauthorized) {
@@ -268,21 +290,21 @@ TEST_F(AssignmentSourceTest, TestUnauthorized) {
AssignmentResponse(
AssignmentSource::Result::RESULT_EXPIRED_ACCESS_TOKEN, _));
GetNetworkAssignmentAndWaitForResponse(net::HTTP_UNAUTHORIZED, net::Error::OK,
- "", "UserAuthT0kenz", kEngineVersion);
+ "", kTestAuthToken, kEngineVersion);
}
TEST_F(AssignmentSourceTest, TestForbidden) {
EXPECT_CALL(*this, AssignmentResponse(
AssignmentSource::Result::RESULT_USER_INVALID, _));
GetNetworkAssignmentAndWaitForResponse(net::HTTP_FORBIDDEN, net::Error::OK,
- "", "UserAuthT0kenz", kEngineVersion);
+ "", kTestAuthToken, kEngineVersion);
}
TEST_F(AssignmentSourceTest, TestTooManyRequests) {
EXPECT_CALL(*this, AssignmentResponse(
AssignmentSource::Result::RESULT_OUT_OF_VMS, _));
GetNetworkAssignmentAndWaitForResponse(static_cast<net::HttpStatusCode>(429),
- net::Error::OK, "", "UserAuthT0kenz",
+ net::Error::OK, "", kTestAuthToken,
kEngineVersion);
}
@@ -290,7 +312,7 @@ TEST_F(AssignmentSourceTest, TestInternalServerError) {
EXPECT_CALL(*this, AssignmentResponse(
AssignmentSource::Result::RESULT_SERVER_ERROR, _));
GetNetworkAssignmentAndWaitForResponse(net::HTTP_INTERNAL_SERVER_ERROR,
- net::Error::OK, "", "UserAuthT0kenz",
+ net::Error::OK, "", kTestAuthToken,
kEngineVersion);
}
@@ -298,56 +320,62 @@ TEST_F(AssignmentSourceTest, TestUnexpectedNetCodeFallback) {
EXPECT_CALL(*this, AssignmentResponse(
AssignmentSource::Result::RESULT_BAD_RESPONSE, _));
GetNetworkAssignmentAndWaitForResponse(net::HTTP_NOT_IMPLEMENTED,
- net::Error::OK, "", "UserAuthT0kenz",
+ net::Error::OK, "", kTestAuthToken,
kEngineVersion);
}
TEST_F(AssignmentSourceTest, TestInvalidJsonResponse) {
- Assignment assignment = BuildValidAssignment();
+ Assignment assignment = BuildSslAssignment();
// Remove half the response.
- std::string response = BuildResponseFromAssignment(assignment);
+ std::string response = ValueToString(*BuildAssignerResponse());
response = response.substr(response.size() / 2);
EXPECT_CALL(*this, AssignmentResponse(
AssignmentSource::Result::RESULT_BAD_RESPONSE, _));
GetNetworkAssignmentAndWaitForResponse(net::HTTP_OK, net::Error::OK, response,
- "UserAuthT0kenz", kEngineVersion);
+ kTestAuthToken, kEngineVersion);
}
TEST_F(AssignmentSourceTest, TestMissingResponsePort) {
- // Purposely do not add the 'port' field to the response.
- base::DictionaryValue dict;
- dict.SetString("clientToken", "SecretT0kenz");
- dict.SetString("host", "happywhales");
- dict.SetString("certificateFingerprint", "WhaleWhaleWhale");
- dict.SetString("certificate", "whaaaaaaaaaaaaale");
-
- std::string response;
- base::JSONWriter::Write(dict, &response);
-
+ scoped_ptr<base::DictionaryValue> response = BuildAssignerResponse();
+ response->Remove("port", nullptr);
EXPECT_CALL(*this, AssignmentResponse(
AssignmentSource::Result::RESULT_BAD_RESPONSE, _));
- GetNetworkAssignmentAndWaitForResponse(net::HTTP_OK, net::Error::OK, response,
- "UserAuthT0kenz", kEngineVersion);
+ GetNetworkAssignmentAndWaitForResponse(net::HTTP_OK, net::Error::OK,
+ ValueToString(*response),
+ kTestAuthToken, kEngineVersion);
}
TEST_F(AssignmentSourceTest, TestInvalidIPAddress) {
- // Purposely add an invalid IP field to the response.
- base::DictionaryValue dict;
- dict.SetString("clientToken", "SecretT0kenz");
- dict.SetString("host", "happywhales");
- dict.SetInteger("port", 500);
- dict.SetString("certificateFingerprint", "WhaleWhaleWhale");
- dict.SetString("certificate", "whaaaaaaaaaaaaale");
+ scoped_ptr<base::DictionaryValue> response = BuildAssignerResponse();
+ response->SetString("host", "happywhales.test");
- std::string response;
- base::JSONWriter::Write(dict, &response);
+ EXPECT_CALL(*this, AssignmentResponse(
+ AssignmentSource::Result::RESULT_BAD_RESPONSE, _));
+ GetNetworkAssignmentAndWaitForResponse(net::HTTP_OK, net::Error::OK,
+ ValueToString(*response),
+ kTestAuthToken, kEngineVersion);
+}
+TEST_F(AssignmentSourceTest, TestMissingCert) {
+ scoped_ptr<base::DictionaryValue> response = BuildAssignerResponse();
+ response->Remove("certificate", nullptr);
EXPECT_CALL(*this, AssignmentResponse(
AssignmentSource::Result::RESULT_BAD_RESPONSE, _));
- GetNetworkAssignmentAndWaitForResponse(net::HTTP_OK, net::Error::OK, response,
- "UserAuthT0kenz", kEngineVersion);
+ GetNetworkAssignmentAndWaitForResponse(net::HTTP_OK, net::Error::OK,
+ ValueToString(*response),
+ kTestAuthToken, kEngineVersion);
+}
+
+TEST_F(AssignmentSourceTest, TestInvalidCert) {
+ scoped_ptr<base::DictionaryValue> response = BuildAssignerResponse();
+ response->SetString("certificate", "h4x0rz!");
+ EXPECT_CALL(*this, AssignmentResponse(
+ AssignmentSource::Result::RESULT_INVALID_CERT, _));
+ GetNetworkAssignmentAndWaitForResponse(net::HTTP_OK, net::Error::OK,
+ ValueToString(*response),
+ kTestAuthToken, kEngineVersion);
}
} // namespace
diff --git a/blimp/client/session/blimp_client_session.cc b/blimp/client/session/blimp_client_session.cc
index 29c0b32..7846d59 100644
--- a/blimp/client/session/blimp_client_session.cc
+++ b/blimp/client/session/blimp_client_session.cc
@@ -22,6 +22,7 @@
#include "blimp/net/client_connection_manager.h"
#include "blimp/net/common.h"
#include "blimp/net/null_blimp_message_processor.h"
+#include "blimp/net/ssl_client_transport.h"
#include "blimp/net/tcp_client_transport.h"
#include "net/base/address_list.h"
#include "net/base/ip_address.h"
@@ -66,7 +67,6 @@ class ClientNetworkComponents {
// they are used from the UI thread.
std::vector<scoped_ptr<BlimpMessageThreadPipe>> outgoing_pipes_;
std::vector<scoped_ptr<BlimpMessageProcessor>> outgoing_message_processors_;
-
DISALLOW_COPY_AND_ASSIGN(ClientNetworkComponents);
};
@@ -81,8 +81,20 @@ void ClientNetworkComponents::ConnectWithAssignment(
DCHECK(connection_manager_);
connection_manager_->set_client_token(assignment.client_token);
- connection_manager_->AddTransport(make_scoped_ptr(new TCPClientTransport(
- net::AddressList(assignment.ip_endpoint), nullptr)));
+ switch (assignment.transport_protocol) {
+ case Assignment::SSL:
+ DCHECK(assignment.cert);
+ connection_manager_->AddTransport(make_scoped_ptr(new SSLClientTransport(
+ assignment.engine_endpoint, std::move(assignment.cert), nullptr)));
+ break;
+ case Assignment::TCP:
+ connection_manager_->AddTransport(make_scoped_ptr(
+ new TCPClientTransport(assignment.engine_endpoint, nullptr)));
+ break;
+ case Assignment::UNKNOWN:
+ DLOG(FATAL) << "Uknown transport type.";
+ break;
+ }
connection_manager_->Connect();
}
@@ -118,8 +130,8 @@ BlimpClientSession::BlimpClientSession()
options.message_loop_type = base::MessageLoop::TYPE_IO;
io_thread_.StartWithOptions(options);
- assignment_source_.reset(new AssignmentSource(
- base::ThreadTaskRunnerHandle::Get(), io_thread_.task_runner()));
+ assignment_source_.reset(
+ new AssignmentSource(io_thread_.task_runner(), io_thread_.task_runner()));
// Register features' message senders and receivers.
tab_control_feature_->set_outgoing_message_processor(
diff --git a/blimp/client/session/test_selfsigned_cert.pem b/blimp/client/session/test_selfsigned_cert.pem
new file mode 100644
index 0000000..de0e79f
--- /dev/null
+++ b/blimp/client/session/test_selfsigned_cert.pem
@@ -0,0 +1,11 @@
+-----BEGIN CERTIFICATE-----
+MIIBmjCCAQOgAwIBAgIBATANBgkqhkiG9w0BAQUFADATMREwDwYDVQQDEwh1bml0
+dGVzdDAeFw0xMDEyMjMwMjI5NDhaFw0xMDEyMjQwMjI5NDhaMBMxETAPBgNVBAMT
+CHVuaXR0ZXN0MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDUrDNORwXwkey6
+1BtbawRswIkKE81+eZhlIOpMyKayUhi4qB5qaAg0Mt0Of7SwXYA/Nk0ADzcbI+jn
+bl8y1gSaHN33I/OO9bEEwBtL2c+iF0Z9tI4iQ1lU2LQ2qiW8nfdQ21HUFbcnkk31
+vE8wNzh3c332RgVzvo5nzypVkamLgQIDAQABMA0GCSqGSIb3DQEBBQUAA4GBABu5
+toCzcK6zKviZe+Uj5EVRUMwDywwCA7FadW7JmgCVt6yQ9YXgkqZelk0aodKZs+eS
+WHuyx0EKVuZzaIiI2b/PKnfGVIvAu5Svzdqc8mlwEy4cBYoVFnFOIMzN93p9uUER
+Y8o1fBKQE2LhRv3v86PYez5EI7xbUc/5ai+9LkXe
+-----END CERTIFICATE-----
diff --git a/blimp/docs/running.md b/blimp/docs/running.md
index a32b436..8accd3e 100644
--- a/blimp/docs/running.md
+++ b/blimp/docs/running.md
@@ -21,10 +21,15 @@ Set up any command line flags with:
./build/android/adb_blimp_command_line --your-flag-here
```
-To have the client connect to a custom engine use the `--blimplet-endpoint`
-flag. This takes values in the form of scheme:ip:port. The possible valid
-schemes are 'tcp', 'quic', and 'ssl'. An example valid endpoint would be
-`--blimplet-endpoint=tcp:127.0.0.1:25467`.
+To have the client connect to a custom engine use the `--engine-ip`,
+`--engine-port`, and `--engine-transport` flags. The possible valid
+values for `--engine-transport` are 'tcp' and 'ssl'.
+An example valid endpoint would be
+`--engine-ip=127.0.0.1 --engine-port=1234 --engine-transport=tcp`.
+
+SSL-encrypted connections take an additional flag
+`--engine-cert-path` which specifies a path to a PEM-encoded certificate
+file (e.g. `--engine-cert-path=/path/to/file.pem`.)
To see your current command line, run `adb_blimp_command_line` without any
arguments.
diff --git a/blimp/engine/BUILD.gn b/blimp/engine/BUILD.gn
index b91730f..5bd4c21 100644
--- a/blimp/engine/BUILD.gn
+++ b/blimp/engine/BUILD.gn
@@ -244,7 +244,7 @@ if (is_linux) {
# Detail the target & "source"-file dependencies, and output, for GN.
deps = [
- "//blimp/engine:blimp_engine",
+ "//blimp/engine:blimp_engine_app",
]
sources = [
_rebased_dockerfile,
diff --git a/blimp/net/BUILD.gn b/blimp/net/BUILD.gn
index aeafbae..28c00cd 100644
--- a/blimp/net/BUILD.gn
+++ b/blimp/net/BUILD.gn
@@ -34,12 +34,16 @@ component("blimp_net") {
"engine_authentication_handler.h",
"engine_connection_manager.cc",
"engine_connection_manager.h",
+ "exact_match_cert_verifier.cc",
+ "exact_match_cert_verifier.h",
"input_message_converter.cc",
"input_message_converter.h",
"input_message_generator.cc",
"input_message_generator.h",
"null_blimp_message_processor.cc",
"null_blimp_message_processor.h",
+ "ssl_client_transport.cc",
+ "ssl_client_transport.h",
"stream_packet_reader.cc",
"stream_packet_reader.h",
"stream_packet_writer.cc",
@@ -94,6 +98,7 @@ source_set("unit_tests") {
"engine_authentication_handler_unittest.cc",
"engine_connection_manager_unittest.cc",
"input_message_unittest.cc",
+ "ssl_client_transport_unittest.cc",
"stream_packet_reader_unittest.cc",
"stream_packet_writer_unittest.cc",
"tcp_transport_unittest.cc",
diff --git a/blimp/net/DEPS b/blimp/net/DEPS
index 9891086..211c82c 100644
--- a/blimp/net/DEPS
+++ b/blimp/net/DEPS
@@ -1,6 +1,5 @@
include_rules = [
- "+net/base",
- "+net/socket",
+ "+net",
"+third_party/WebKit/public/platform/WebGestureDevice.h",
"+third_party/WebKit/public/web/WebInputEvent.h",
]
diff --git a/blimp/net/blimp_transport.h b/blimp/net/blimp_transport.h
index 8336912..8deabd5 100644
--- a/blimp/net/blimp_transport.h
+++ b/blimp/net/blimp_transport.h
@@ -35,7 +35,7 @@ class BlimpTransport {
virtual scoped_ptr<BlimpConnection> TakeConnection() = 0;
// Gets transport name, e.g. "TCP", "SSL", "mock", etc.
- virtual const std::string GetName() const = 0;
+ virtual const char* GetName() const = 0;
};
} // namespace blimp
diff --git a/blimp/net/exact_match_cert_verifier.cc b/blimp/net/exact_match_cert_verifier.cc
new file mode 100644
index 0000000..c140c36
--- /dev/null
+++ b/blimp/net/exact_match_cert_verifier.cc
@@ -0,0 +1,56 @@
+// Copyright 2016 The Chromium Authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+#include "blimp/net/exact_match_cert_verifier.h"
+
+#include "base/callback.h"
+#include "base/macros.h"
+#include "base/memory/scoped_ptr.h"
+#include "net/base/net_errors.h"
+#include "net/cert/cert_verifier.h"
+#include "net/cert/cert_verify_result.h"
+#include "net/cert/x509_certificate.h"
+
+namespace blimp {
+
+ExactMatchCertVerifier::ExactMatchCertVerifier(
+ scoped_refptr<net::X509Certificate> engine_cert)
+ : engine_cert_(std::move(engine_cert)) {
+ DCHECK(engine_cert);
+
+ net::SHA1HashValue sha1_hash;
+ sha1_hash = net::X509Certificate::CalculateFingerprint(
+ engine_cert_->os_cert_handle());
+ engine_cert_hashes_.push_back(net::HashValue(sha1_hash));
+
+ net::SHA256HashValue sha256_hash;
+ sha256_hash = net::X509Certificate::CalculateFingerprint256(
+ engine_cert_->os_cert_handle());
+ engine_cert_hashes_.push_back(net::HashValue(sha256_hash));
+}
+
+ExactMatchCertVerifier::~ExactMatchCertVerifier() {}
+
+int ExactMatchCertVerifier::Verify(net::X509Certificate* cert,
+ const std::string& hostname,
+ const std::string& ocsp_response,
+ int flags,
+ net::CRLSet* crl_set,
+ net::CertVerifyResult* verify_result,
+ const net::CompletionCallback& callback,
+ scoped_ptr<Request>* out_req,
+ const net::BoundNetLog& net_log) {
+ verify_result->Reset();
+ verify_result->verified_cert = engine_cert_;
+
+ if (!cert->Equals(engine_cert_.get())) {
+ verify_result->cert_status = net::CERT_STATUS_INVALID;
+ return net::ERR_CERT_INVALID;
+ }
+
+ verify_result->public_key_hashes = engine_cert_hashes_;
+ return net::OK;
+}
+
+} // namespace blimp
diff --git a/blimp/net/exact_match_cert_verifier.h b/blimp/net/exact_match_cert_verifier.h
new file mode 100644
index 0000000..d26d57a
--- /dev/null
+++ b/blimp/net/exact_match_cert_verifier.h
@@ -0,0 +1,50 @@
+// Copyright 2016 The Chromium Authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+#ifndef BLIMP_NET_EXACT_MATCH_CERT_VERIFIER_H_
+#define BLIMP_NET_EXACT_MATCH_CERT_VERIFIER_H_
+
+#include <string>
+#include <vector>
+
+#include "blimp/net/blimp_net_export.h"
+#include "net/cert/cert_verifier.h"
+
+namespace net {
+class HashValue;
+} // namespace net
+
+namespace blimp {
+
+// Checks if the peer certificate is an exact match to the X.509 certificate
+// |engine_cert|, which is specified at class construction time.
+class BLIMP_NET_EXPORT ExactMatchCertVerifier : public net::CertVerifier {
+ public:
+ // |engine_cert|: The single allowable certificate.
+ explicit ExactMatchCertVerifier(
+ scoped_refptr<net::X509Certificate> engine_cert);
+
+ ~ExactMatchCertVerifier() override;
+
+ // net::CertVerifier implementation.
+ int Verify(net::X509Certificate* cert,
+ const std::string& hostname,
+ const std::string& ocsp_response,
+ int flags,
+ net::CRLSet* crl_set,
+ net::CertVerifyResult* verify_result,
+ const net::CompletionCallback& callback,
+ scoped_ptr<Request>* out_req,
+ const net::BoundNetLog& net_log) override;
+
+ private:
+ scoped_refptr<net::X509Certificate> engine_cert_;
+ std::vector<net::HashValue> engine_cert_hashes_;
+
+ DISALLOW_COPY_AND_ASSIGN(ExactMatchCertVerifier);
+};
+
+} // namespace blimp
+
+#endif // BLIMP_NET_EXACT_MATCH_CERT_VERIFIER_H_
diff --git a/blimp/net/ssl_client_transport.cc b/blimp/net/ssl_client_transport.cc
new file mode 100644
index 0000000..3364093
--- /dev/null
+++ b/blimp/net/ssl_client_transport.cc
@@ -0,0 +1,91 @@
+// Copyright 2016 The Chromium Authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+#include "blimp/net/ssl_client_transport.h"
+
+#include "base/callback.h"
+#include "base/callback_helpers.h"
+#include "blimp/net/exact_match_cert_verifier.h"
+#include "blimp/net/stream_socket_connection.h"
+#include "net/base/host_port_pair.h"
+#include "net/cert/x509_certificate.h"
+#include "net/socket/client_socket_factory.h"
+#include "net/socket/client_socket_handle.h"
+#include "net/socket/ssl_client_socket.h"
+#include "net/socket/stream_socket.h"
+#include "net/socket/tcp_client_socket.h"
+#include "net/ssl/ssl_config.h"
+
+namespace blimp {
+
+SSLClientTransport::SSLClientTransport(const net::IPEndPoint& ip_endpoint,
+ scoped_refptr<net::X509Certificate> cert,
+ net::NetLog* net_log)
+ : TCPClientTransport(ip_endpoint, net_log), ip_endpoint_(ip_endpoint) {
+ // Test code may pass in a null value for |cert|. Only spin up a CertVerifier
+ // if there is a cert present.
+ if (cert) {
+ cert_verifier_.reset(new ExactMatchCertVerifier(std::move(cert)));
+ }
+}
+
+SSLClientTransport::~SSLClientTransport() {}
+
+const char* SSLClientTransport::GetName() const {
+ return "SSL";
+}
+
+void SSLClientTransport::OnTCPConnectComplete(int result) {
+ DCHECK_NE(net::ERR_IO_PENDING, result);
+
+ scoped_ptr<net::StreamSocket> tcp_socket = TCPClientTransport::TakeSocket();
+
+ DVLOG(1) << "TCP connection result=" << result;
+ if (result != net::OK) {
+ OnConnectComplete(result);
+ return;
+ }
+
+ // Construct arguments to use for the SSL socket factory.
+ scoped_ptr<net::ClientSocketHandle> socket_handle(
+ new net::ClientSocketHandle);
+ socket_handle->SetSocket(std::move(tcp_socket));
+
+ net::HostPortPair host_port_pair =
+ net::HostPortPair::FromIPEndPoint(ip_endpoint_);
+
+ net::SSLClientSocketContext create_context;
+ create_context.cert_verifier = cert_verifier_.get();
+ create_context.transport_security_state = &transport_security_state_;
+
+ scoped_ptr<net::StreamSocket> ssl_socket(
+ socket_factory()->CreateSSLClientSocket(std::move(socket_handle),
+ host_port_pair, net::SSLConfig(),
+ create_context));
+
+ if (!ssl_socket) {
+ OnConnectComplete(net::ERR_SSL_PROTOCOL_ERROR);
+ return;
+ }
+
+ result = ssl_socket->Connect(base::Bind(
+ &SSLClientTransport::OnSSLConnectComplete, base::Unretained(this)));
+ SetSocket(std::move(ssl_socket));
+
+ if (result == net::ERR_IO_PENDING) {
+ // SSL connection will complete asynchronously.
+ return;
+ }
+
+ OnSSLConnectComplete(result);
+}
+
+void SSLClientTransport::OnSSLConnectComplete(int result) {
+ DCHECK_NE(net::ERR_IO_PENDING, result);
+ DVLOG(1) << "SSL connection result=" << result;
+
+ OnConnectComplete(result);
+}
+
+} // namespace blimp
diff --git a/blimp/net/ssl_client_transport.h b/blimp/net/ssl_client_transport.h
new file mode 100644
index 0000000..0f0a1f4
--- /dev/null
+++ b/blimp/net/ssl_client_transport.h
@@ -0,0 +1,64 @@
+// Copyright 2016 The Chromium Authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+#ifndef BLIMP_NET_SSL_CLIENT_TRANSPORT_H_
+#define BLIMP_NET_SSL_CLIENT_TRANSPORT_H_
+
+#include <string>
+#include "base/callback_forward.h"
+#include "base/macros.h"
+#include "base/memory/scoped_ptr.h"
+#include "blimp/net/blimp_net_export.h"
+#include "blimp/net/blimp_transport.h"
+#include "blimp/net/exact_match_cert_verifier.h"
+#include "blimp/net/tcp_client_transport.h"
+#include "net/base/address_list.h"
+#include "net/base/net_errors.h"
+#include "net/http/transport_security_state.h"
+
+namespace net {
+class ClientSocketFactory;
+class NetLog;
+class StreamSocket;
+class TCPClientSocket;
+class TransportSecurityState;
+} // namespace net
+
+namespace blimp {
+
+class BlimpConnection;
+
+// Creates and connects SSL socket connections to an Engine.
+class BLIMP_NET_EXPORT SSLClientTransport : public TCPClientTransport {
+ public:
+ // |ip_endpoint|: the address to connect to.
+ // |cert|: the certificate required from the remote peer.
+ // SSL connections that use different certificates are rejected.
+ // |net_log|: the socket event log (optional).
+ SSLClientTransport(const net::IPEndPoint& ip_endpoint,
+ scoped_refptr<net::X509Certificate> cert,
+ net::NetLog* net_log);
+
+ ~SSLClientTransport() override;
+
+ // BlimpTransport implementation.
+ const char* GetName() const override;
+
+ private:
+ // Method called after TCPClientSocket::Connect finishes.
+ void OnTCPConnectComplete(int result) override;
+
+ // Method called after SSLClientSocket::Connect finishes.
+ void OnSSLConnectComplete(int result);
+
+ net::IPEndPoint ip_endpoint_;
+ scoped_ptr<ExactMatchCertVerifier> cert_verifier_;
+ net::TransportSecurityState transport_security_state_;
+
+ DISALLOW_COPY_AND_ASSIGN(SSLClientTransport);
+};
+
+} // namespace blimp
+
+#endif // BLIMP_NET_SSL_CLIENT_TRANSPORT_H_
diff --git a/blimp/net/ssl_client_transport_unittest.cc b/blimp/net/ssl_client_transport_unittest.cc
new file mode 100644
index 0000000..47724ce
--- /dev/null
+++ b/blimp/net/ssl_client_transport_unittest.cc
@@ -0,0 +1,162 @@
+// Copyright 2016 The Chromium Authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+#include "base/bind.h"
+#include "base/message_loop/message_loop.h"
+#include "base/run_loop.h"
+#include "blimp/net/blimp_connection.h"
+#include "blimp/net/ssl_client_transport.h"
+#include "net/base/address_list.h"
+#include "net/base/ip_address.h"
+#include "net/base/net_errors.h"
+#include "net/socket/socket_test_util.h"
+#include "testing/gmock/include/gmock/gmock.h"
+#include "testing/gtest/include/gtest/gtest.h"
+
+namespace blimp {
+namespace {
+
+const uint8_t kIPV4Address[] = {127, 0, 0, 1};
+const uint16_t kPort = 6667;
+
+} // namespace
+
+class SSLClientTransportTest : public testing::Test {
+ public:
+ SSLClientTransportTest() {}
+
+ ~SSLClientTransportTest() override {}
+
+ void TearDown() override { base::RunLoop().RunUntilIdle(); }
+
+ MOCK_METHOD1(ConnectComplete, void(int));
+
+ protected:
+ // Methods for provisioning simulated connection outcomes.
+ void SetupTCPSyncSocketConnect(net::IPEndPoint endpoint, int result) {
+ tcp_connect_.set_connect_data(
+ net::MockConnect(net::SYNCHRONOUS, result, endpoint));
+ socket_factory_.AddSocketDataProvider(&tcp_connect_);
+ }
+
+ void SetupTCPAsyncSocketConnect(net::IPEndPoint endpoint, int result) {
+ tcp_connect_.set_connect_data(
+ net::MockConnect(net::ASYNC, result, endpoint));
+ socket_factory_.AddSocketDataProvider(&tcp_connect_);
+ }
+
+ void SetupSSLSyncSocketConnect(int result) {
+ ssl_connect_.reset(
+ new net::SSLSocketDataProvider(net::SYNCHRONOUS, result));
+ socket_factory_.AddSSLSocketDataProvider(ssl_connect_.get());
+ }
+
+ void SetupSSLAsyncSocketConnect(int result) {
+ ssl_connect_.reset(new net::SSLSocketDataProvider(net::ASYNC, result));
+ socket_factory_.AddSSLSocketDataProvider(ssl_connect_.get());
+ }
+
+ void ConfigureTransport(const net::IPEndPoint& ip_endpoint) {
+ // The mock does not interact with the cert directly, so just leave it null.
+ scoped_refptr<net::X509Certificate> cert;
+ transport_.reset(new SSLClientTransport(ip_endpoint, cert, &net_log_));
+ transport_->SetClientSocketFactoryForTest(&socket_factory_);
+ }
+
+ base::MessageLoop message_loop;
+ net::NetLog net_log_;
+ net::StaticSocketDataProvider tcp_connect_;
+ scoped_ptr<net::SSLSocketDataProvider> ssl_connect_;
+ net::MockClientSocketFactory socket_factory_;
+ scoped_ptr<SSLClientTransport> transport_;
+};
+
+TEST_F(SSLClientTransportTest, ConnectSyncOK) {
+ net::IPEndPoint endpoint(kIPV4Address, kPort);
+ ConfigureTransport(endpoint);
+ for (int i = 0; i < 5; ++i) {
+ EXPECT_CALL(*this, ConnectComplete(net::OK));
+ SetupTCPSyncSocketConnect(endpoint, net::OK);
+ SetupSSLSyncSocketConnect(net::OK);
+ transport_->Connect(base::Bind(&SSLClientTransportTest::ConnectComplete,
+ base::Unretained(this)));
+ EXPECT_NE(nullptr, transport_->TakeConnection().get());
+ base::RunLoop().RunUntilIdle();
+ }
+}
+
+TEST_F(SSLClientTransportTest, ConnectAsyncOK) {
+ net::IPEndPoint endpoint(kIPV4Address, kPort);
+ ConfigureTransport(endpoint);
+ for (int i = 0; i < 5; ++i) {
+ EXPECT_CALL(*this, ConnectComplete(net::OK));
+ SetupTCPAsyncSocketConnect(endpoint, net::OK);
+ SetupSSLAsyncSocketConnect(net::OK);
+ transport_->Connect(base::Bind(&SSLClientTransportTest::ConnectComplete,
+ base::Unretained(this)));
+ base::RunLoop().RunUntilIdle();
+ EXPECT_NE(nullptr, transport_->TakeConnection().get());
+ }
+}
+
+TEST_F(SSLClientTransportTest, ConnectSyncTCPError) {
+ net::IPEndPoint endpoint(kIPV4Address, kPort);
+ ConfigureTransport(endpoint);
+ EXPECT_CALL(*this, ConnectComplete(net::ERR_FAILED));
+ SetupTCPSyncSocketConnect(endpoint, net::ERR_FAILED);
+ transport_->Connect(base::Bind(&SSLClientTransportTest::ConnectComplete,
+ base::Unretained(this)));
+}
+
+TEST_F(SSLClientTransportTest, ConnectAsyncTCPError) {
+ net::IPEndPoint endpoint(kIPV4Address, kPort);
+ ConfigureTransport(endpoint);
+ EXPECT_CALL(*this, ConnectComplete(net::ERR_FAILED));
+ SetupTCPAsyncSocketConnect(endpoint, net::ERR_FAILED);
+ transport_->Connect(base::Bind(&SSLClientTransportTest::ConnectComplete,
+ base::Unretained(this)));
+}
+
+TEST_F(SSLClientTransportTest, ConnectSyncSSLError) {
+ net::IPEndPoint endpoint(kIPV4Address, kPort);
+ ConfigureTransport(endpoint);
+ EXPECT_CALL(*this, ConnectComplete(net::ERR_FAILED));
+ SetupTCPSyncSocketConnect(endpoint, net::OK);
+ SetupSSLSyncSocketConnect(net::ERR_FAILED);
+ transport_->Connect(base::Bind(&SSLClientTransportTest::ConnectComplete,
+ base::Unretained(this)));
+}
+
+TEST_F(SSLClientTransportTest, ConnectAsyncSSLError) {
+ net::IPEndPoint endpoint(kIPV4Address, kPort);
+ ConfigureTransport(endpoint);
+ EXPECT_CALL(*this, ConnectComplete(net::ERR_FAILED));
+ SetupTCPAsyncSocketConnect(endpoint, net::OK);
+ SetupSSLAsyncSocketConnect(net::ERR_FAILED);
+ transport_->Connect(base::Bind(&SSLClientTransportTest::ConnectComplete,
+ base::Unretained(this)));
+}
+
+TEST_F(SSLClientTransportTest, ConnectAfterError) {
+ net::IPEndPoint endpoint(kIPV4Address, kPort);
+ ConfigureTransport(endpoint);
+
+ // TCP connection fails.
+ EXPECT_CALL(*this, ConnectComplete(net::ERR_FAILED));
+ SetupTCPSyncSocketConnect(endpoint, net::ERR_FAILED);
+ transport_->Connect(base::Bind(&SSLClientTransportTest::ConnectComplete,
+ base::Unretained(this)));
+ base::RunLoop().RunUntilIdle();
+
+ // Subsequent TCP+SSL connections succeed.
+ EXPECT_CALL(*this, ConnectComplete(net::OK));
+ SetupTCPSyncSocketConnect(endpoint, net::OK);
+ SetupSSLSyncSocketConnect(net::OK);
+ transport_->Connect(base::Bind(&SSLClientTransportTest::ConnectComplete,
+ base::Unretained(this)));
+ EXPECT_NE(nullptr, transport_->TakeConnection().get());
+ base::RunLoop().RunUntilIdle();
+}
+
+} // namespace blimp
diff --git a/blimp/net/tcp_client_transport.cc b/blimp/net/tcp_client_transport.cc
index 9dbb8803..6a6cc50 100644
--- a/blimp/net/tcp_client_transport.cc
+++ b/blimp/net/tcp_client_transport.cc
@@ -9,38 +9,42 @@
#include "base/memory/scoped_ptr.h"
#include "base/message_loop/message_loop.h"
#include "blimp/net/stream_socket_connection.h"
+#include "net/socket/client_socket_factory.h"
#include "net/socket/stream_socket.h"
#include "net/socket/tcp_client_socket.h"
namespace blimp {
-TCPClientTransport::TCPClientTransport(const net::AddressList& addresses,
+TCPClientTransport::TCPClientTransport(const net::IPEndPoint& ip_endpoint,
net::NetLog* net_log)
- : addresses_(addresses), net_log_(net_log) {}
+ : ip_endpoint_(ip_endpoint),
+ net_log_(net_log),
+ socket_factory_(net::ClientSocketFactory::GetDefaultFactory()) {}
TCPClientTransport::~TCPClientTransport() {}
+void TCPClientTransport::SetClientSocketFactoryForTest(
+ net::ClientSocketFactory* factory) {
+ DCHECK(factory);
+ socket_factory_ = factory;
+}
+
void TCPClientTransport::Connect(const net::CompletionCallback& callback) {
DCHECK(!socket_);
DCHECK(!callback.is_null());
- socket_.reset(
- new net::TCPClientSocket(addresses_, net_log_, net::NetLog::Source()));
+ connect_callback_ = callback;
+ socket_ = socket_factory_->CreateTransportClientSocket(
+ net::AddressList(ip_endpoint_), net_log_, net::NetLog::Source());
net::CompletionCallback completion_callback = base::Bind(
&TCPClientTransport::OnTCPConnectComplete, base::Unretained(this));
int result = socket_->Connect(completion_callback);
if (result == net::ERR_IO_PENDING) {
- connect_callback_ = callback;
return;
}
- if (result != net::OK) {
- socket_ = nullptr;
- }
-
- base::MessageLoop::current()->PostTask(FROM_HERE,
- base::Bind(callback, result));
+ OnTCPConnectComplete(result);
}
scoped_ptr<BlimpConnection> TCPClientTransport::TakeConnection() {
@@ -49,17 +53,33 @@ scoped_ptr<BlimpConnection> TCPClientTransport::TakeConnection() {
return make_scoped_ptr(new StreamSocketConnection(std::move(socket_)));
}
-const std::string TCPClientTransport::GetName() const {
+const char* TCPClientTransport::GetName() const {
return "TCP";
}
void TCPClientTransport::OnTCPConnectComplete(int result) {
DCHECK_NE(net::ERR_IO_PENDING, result);
- DCHECK(socket_);
+ OnConnectComplete(result);
+}
+
+void TCPClientTransport::OnConnectComplete(int result) {
if (result != net::OK) {
socket_ = nullptr;
}
base::ResetAndReturn(&connect_callback_).Run(result);
}
+scoped_ptr<net::StreamSocket> TCPClientTransport::TakeSocket() {
+ return std::move(socket_);
+}
+
+void TCPClientTransport::SetSocket(scoped_ptr<net::StreamSocket> socket) {
+ DCHECK(socket);
+ socket_ = std::move(socket);
+}
+
+net::ClientSocketFactory* TCPClientTransport::socket_factory() const {
+ return socket_factory_;
+}
+
} // namespace blimp
diff --git a/blimp/net/tcp_client_transport.h b/blimp/net/tcp_client_transport.h
index 3242883..6a879fe 100644
--- a/blimp/net/tcp_client_transport.h
+++ b/blimp/net/tcp_client_transport.h
@@ -5,6 +5,8 @@
#ifndef BLIMP_NET_TCP_CLIENT_TRANSPORT_H_
#define BLIMP_NET_TCP_CLIENT_TRANSPORT_H_
+#include <string>
+
#include "base/callback.h"
#include "base/macros.h"
#include "base/memory/scoped_ptr.h"
@@ -14,6 +16,7 @@
#include "net/base/net_errors.h"
namespace net {
+class ClientSocketFactory;
class NetLog;
class StreamSocket;
} // namespace net
@@ -26,21 +29,38 @@ class BlimpConnection;
// |addresses| on each call to Connect().
class BLIMP_NET_EXPORT TCPClientTransport : public BlimpTransport {
public:
- TCPClientTransport(const net::AddressList& addresses, net::NetLog* net_log);
+ TCPClientTransport(const net::IPEndPoint& ip_endpoint, net::NetLog* net_log);
~TCPClientTransport() override;
+ void SetClientSocketFactoryForTest(net::ClientSocketFactory* factory);
+
// BlimpTransport implementation.
void Connect(const net::CompletionCallback& callback) override;
scoped_ptr<BlimpConnection> TakeConnection() override;
- const std::string GetName() const override;
+ const char* GetName() const override;
- private:
- void OnTCPConnectComplete(int result);
+ protected:
+ // Called when the TCP connection completed.
+ virtual void OnTCPConnectComplete(int result);
+
+ // Called when the connection attempt completed or failed.
+ // Resets |socket_| if |result| indicates a failure (!= net::OK).
+ void OnConnectComplete(int result);
+
+ // Methods for taking and setting |socket_|. Can be used by subclasses to
+ // swap out a socket for an upgraded one, e.g. adding SSL encryption.
+ scoped_ptr<net::StreamSocket> TakeSocket();
+ void SetSocket(scoped_ptr<net::StreamSocket> socket);
- net::AddressList addresses_;
+ // Gets the socket factory instance.
+ net::ClientSocketFactory* socket_factory() const;
+
+ private:
+ net::IPEndPoint ip_endpoint_;
net::NetLog* net_log_;
- scoped_ptr<net::StreamSocket> socket_;
net::CompletionCallback connect_callback_;
+ net::ClientSocketFactory* socket_factory_ = nullptr;
+ scoped_ptr<net::StreamSocket> socket_;
DISALLOW_COPY_AND_ASSIGN(TCPClientTransport);
};
diff --git a/blimp/net/tcp_engine_transport.cc b/blimp/net/tcp_engine_transport.cc
index 473a1bb..4606caf 100644
--- a/blimp/net/tcp_engine_transport.cc
+++ b/blimp/net/tcp_engine_transport.cc
@@ -61,7 +61,7 @@ scoped_ptr<BlimpConnection> TCPEngineTransport::TakeConnection() {
new StreamSocketConnection(std::move(accepted_socket_)));
}
-const std::string TCPEngineTransport::GetName() const {
+const char* TCPEngineTransport::GetName() const {
return "TCP";
}
diff --git a/blimp/net/tcp_engine_transport.h b/blimp/net/tcp_engine_transport.h
index bf8b7cf..ace223e 100644
--- a/blimp/net/tcp_engine_transport.h
+++ b/blimp/net/tcp_engine_transport.h
@@ -33,7 +33,7 @@ class BLIMP_NET_EXPORT TCPEngineTransport : public BlimpTransport {
// BlimpTransport implementation.
void Connect(const net::CompletionCallback& callback) override;
scoped_ptr<BlimpConnection> TakeConnection() override;
- const std::string GetName() const override;
+ const char* GetName() const override;
int GetLocalAddressForTesting(net::IPEndPoint* address) const;
diff --git a/blimp/net/tcp_transport_unittest.cc b/blimp/net/tcp_transport_unittest.cc
index cef15d3..8f1525a 100644
--- a/blimp/net/tcp_transport_unittest.cc
+++ b/blimp/net/tcp_transport_unittest.cc
@@ -35,10 +35,10 @@ class TCPTransportTest : public testing::Test {
engine_.reset(new TCPEngineTransport(local_address, nullptr));
}
- net::AddressList GetLocalAddressList() const {
+ net::IPEndPoint GetLocalEndpoint() const {
net::IPEndPoint local_address;
- engine_->GetLocalAddressForTesting(&local_address);
- return net::AddressList(local_address);
+ CHECK_EQ(net::OK, engine_->GetLocalAddressForTesting(&local_address));
+ return local_address;
}
base::MessageLoopForIO message_loop_;
@@ -50,7 +50,7 @@ TEST_F(TCPTransportTest, Connect) {
engine_->Connect(accept_callback.callback());
net::TestCompletionCallback connect_callback;
- TCPClientTransport client(GetLocalAddressList(), nullptr);
+ TCPClientTransport client(GetLocalEndpoint(), nullptr);
client.Connect(connect_callback.callback());
EXPECT_EQ(net::OK, connect_callback.WaitForResult());
@@ -63,11 +63,11 @@ TEST_F(TCPTransportTest, TwoClientConnections) {
engine_->Connect(accept_callback1.callback());
net::TestCompletionCallback connect_callback1;
- TCPClientTransport client1(GetLocalAddressList(), nullptr);
+ TCPClientTransport client1(GetLocalEndpoint(), nullptr);
client1.Connect(connect_callback1.callback());
net::TestCompletionCallback connect_callback2;
- TCPClientTransport client2(GetLocalAddressList(), nullptr);
+ TCPClientTransport client2(GetLocalEndpoint(), nullptr);
client2.Connect(connect_callback2.callback());
EXPECT_EQ(net::OK, connect_callback1.WaitForResult());
@@ -86,7 +86,7 @@ TEST_F(TCPTransportTest, ExchangeMessages) {
net::TestCompletionCallback accept_callback;
engine_->Connect(accept_callback.callback());
net::TestCompletionCallback client_connect_callback;
- TCPClientTransport client(GetLocalAddressList(), nullptr /* NetLog */);
+ TCPClientTransport client(GetLocalEndpoint(), nullptr /* NetLog */);
client.Connect(client_connect_callback.callback());
EXPECT_EQ(net::OK, client_connect_callback.WaitForResult());
EXPECT_EQ(net::OK, accept_callback.WaitForResult());
diff --git a/blimp/net/test_common.cc b/blimp/net/test_common.cc
index e6cd956..92a951d 100644
--- a/blimp/net/test_common.cc
+++ b/blimp/net/test_common.cc
@@ -26,7 +26,7 @@ scoped_ptr<BlimpConnection> MockTransport::TakeConnection() {
return make_scoped_ptr(TakeConnectionPtr());
}
-const std::string MockTransport::GetName() const {
+const char* MockTransport::GetName() const {
return "mock";
}
diff --git a/blimp/net/test_common.h b/blimp/net/test_common.h
index 302060a..380465e 100644
--- a/blimp/net/test_common.h
+++ b/blimp/net/test_common.h
@@ -137,7 +137,7 @@ class MockTransport : public BlimpTransport {
MOCK_METHOD0(TakeConnectionPtr, BlimpConnection*());
scoped_ptr<BlimpConnection> TakeConnection() override;
- const std::string GetName() const override;
+ const char* GetName() const override;
};
class MockConnectionHandler : public ConnectionHandler {