blob: 690d6a9c95a86447bcbdbdb1d593f4f16d726b75 [file] [log] [blame]
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +00001/*
2 * Copyright 2012 The WebRTC Project Authors. All rights reserved.
3 *
4 * Use of this source code is governed by a BSD-style license
5 * that can be found in the LICENSE file in the root of the source
6 * tree. An additional intellectual property rights grant can be found
7 * in the file PATENTS. All contributing project authors may
8 * be found in the AUTHORS file in the root of the source tree.
9 */
10
Steve Anton10542f22019-01-11 09:11:00 -080011#ifndef P2P_BASE_TURN_SERVER_H_
12#define P2P_BASE_TURN_SERVER_H_
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000013
14#include <list>
15#include <map>
kwiberg3ec46792016-04-27 07:22:53 -070016#include <memory>
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000017#include <set>
18#include <string>
Steve Anton6c38cc72017-11-29 10:25:58 -080019#include <utility>
deadbeef824f5862016-08-24 15:06:53 -070020#include <vector>
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000021
Steve Anton10542f22019-01-11 09:11:00 -080022#include "p2p/base/port_interface.h"
23#include "rtc_base/async_invoker.h"
24#include "rtc_base/async_packet_socket.h"
25#include "rtc_base/message_queue.h"
26#include "rtc_base/socket_address.h"
Artem Titove41c4332018-07-25 15:04:28 +020027#include "rtc_base/third_party/sigslot/sigslot.h"
Seth Hampsonaed71642018-06-11 07:41:32 -070028#include "rtc_base/thread_checker.h"
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000029
30namespace rtc {
jbauchf1f87202016-03-30 06:43:37 -070031class ByteBufferWriter;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000032class PacketSocketFactory;
33class Thread;
34}
35
36namespace cricket {
37
38class StunMessage;
39class TurnMessage;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +000040class TurnServer;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +000041
42// The default server port for TURN, as specified in RFC5766.
43const int TURN_SERVER_PORT = 3478;
44
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +000045// Encapsulates the client's connection to the server.
46class TurnServerConnection {
47 public:
48 TurnServerConnection() : proto_(PROTO_UDP), socket_(NULL) {}
49 TurnServerConnection(const rtc::SocketAddress& src,
50 ProtocolType proto,
51 rtc::AsyncPacketSocket* socket);
52 const rtc::SocketAddress& src() const { return src_; }
53 rtc::AsyncPacketSocket* socket() { return socket_; }
54 bool operator==(const TurnServerConnection& t) const;
55 bool operator<(const TurnServerConnection& t) const;
56 std::string ToString() const;
57
58 private:
59 rtc::SocketAddress src_;
60 rtc::SocketAddress dst_;
61 cricket::ProtocolType proto_;
62 rtc::AsyncPacketSocket* socket_;
63};
64
65// Encapsulates a TURN allocation.
66// The object is created when an allocation request is received, and then
67// handles TURN messages (via HandleTurnMessage) and channel data messages
68// (via HandleChannelData) for this allocation when received by the server.
69// The object self-deletes and informs the server if its lifetime timer expires.
70class TurnServerAllocation : public rtc::MessageHandler,
71 public sigslot::has_slots<> {
72 public:
73 TurnServerAllocation(TurnServer* server_,
74 rtc::Thread* thread,
75 const TurnServerConnection& conn,
76 rtc::AsyncPacketSocket* server_socket,
77 const std::string& key);
Steve Antonf2737d22017-10-31 16:27:34 -070078 ~TurnServerAllocation() override;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +000079
80 TurnServerConnection* conn() { return &conn_; }
81 const std::string& key() const { return key_; }
82 const std::string& transaction_id() const { return transaction_id_; }
83 const std::string& username() const { return username_; }
84 const std::string& origin() const { return origin_; }
85 const std::string& last_nonce() const { return last_nonce_; }
86 void set_last_nonce(const std::string& nonce) { last_nonce_ = nonce; }
87
88 std::string ToString() const;
89
90 void HandleTurnMessage(const TurnMessage* msg);
91 void HandleChannelData(const char* data, size_t size);
92
93 sigslot::signal1<TurnServerAllocation*> SignalDestroyed;
94
95 private:
96 class Channel;
97 class Permission;
98 typedef std::list<Permission*> PermissionList;
99 typedef std::list<Channel*> ChannelList;
100
101 void HandleAllocateRequest(const TurnMessage* msg);
102 void HandleRefreshRequest(const TurnMessage* msg);
103 void HandleSendIndication(const TurnMessage* msg);
104 void HandleCreatePermissionRequest(const TurnMessage* msg);
105 void HandleChannelBindRequest(const TurnMessage* msg);
106
107 void OnExternalPacket(rtc::AsyncPacketSocket* socket,
Niels Möllere6933812018-11-05 13:01:41 +0100108 const char* data,
109 size_t size,
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000110 const rtc::SocketAddress& addr,
Niels Möllere6933812018-11-05 13:01:41 +0100111 const int64_t& packet_time_us);
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000112
113 static int ComputeLifetime(const TurnMessage* msg);
114 bool HasPermission(const rtc::IPAddress& addr);
115 void AddPermission(const rtc::IPAddress& addr);
116 Permission* FindPermission(const rtc::IPAddress& addr) const;
117 Channel* FindChannel(int channel_id) const;
118 Channel* FindChannel(const rtc::SocketAddress& addr) const;
119
120 void SendResponse(TurnMessage* msg);
121 void SendBadRequestResponse(const TurnMessage* req);
122 void SendErrorResponse(const TurnMessage* req, int code,
123 const std::string& reason);
124 void SendExternal(const void* data, size_t size,
125 const rtc::SocketAddress& peer);
126
127 void OnPermissionDestroyed(Permission* perm);
128 void OnChannelDestroyed(Channel* channel);
Steve Antonf2737d22017-10-31 16:27:34 -0700129 void OnMessage(rtc::Message* msg) override;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000130
131 TurnServer* server_;
132 rtc::Thread* thread_;
133 TurnServerConnection conn_;
kwiberg3ec46792016-04-27 07:22:53 -0700134 std::unique_ptr<rtc::AsyncPacketSocket> external_socket_;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000135 std::string key_;
136 std::string transaction_id_;
137 std::string username_;
138 std::string origin_;
139 std::string last_nonce_;
140 PermissionList perms_;
141 ChannelList channels_;
142};
143
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000144// An interface through which the MD5 credential hash can be retrieved.
145class TurnAuthInterface {
146 public:
147 // Gets HA1 for the specified user and realm.
148 // HA1 = MD5(A1) = MD5(username:realm:password).
149 // Return true if the given username and realm are valid, or false if not.
150 virtual bool GetKey(const std::string& username, const std::string& realm,
151 std::string* key) = 0;
Henrik Kjellander3fe372d2016-05-12 08:10:52 +0200152 virtual ~TurnAuthInterface() = default;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000153};
154
155// An interface enables Turn Server to control redirection behavior.
156class TurnRedirectInterface {
157 public:
158 virtual bool ShouldRedirect(const rtc::SocketAddress& address,
159 rtc::SocketAddress* out) = 0;
160 virtual ~TurnRedirectInterface() {}
161};
162
Jonas Orelandbdcee282017-10-10 14:01:40 +0200163class StunMessageObserver {
164 public:
165 virtual void ReceivedMessage(const TurnMessage* msg) = 0;
166 virtual void ReceivedChannelData(const char* data, size_t size) = 0;
167 virtual ~StunMessageObserver() {}
168};
169
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000170// The core TURN server class. Give it a socket to listen on via
171// AddInternalServerSocket, and a factory to create external sockets via
172// SetExternalSocketFactory, and it's ready to go.
173// Not yet wired up: TCP support.
174class TurnServer : public sigslot::has_slots<> {
175 public:
deadbeef97943662016-07-12 11:04:50 -0700176 typedef std::map<TurnServerConnection, std::unique_ptr<TurnServerAllocation>>
177 AllocationMap;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000178
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000179 explicit TurnServer(rtc::Thread* thread);
Steve Antonf2737d22017-10-31 16:27:34 -0700180 ~TurnServer() override;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000181
182 // Gets/sets the realm value to use for the server.
Seth Hampsonaed71642018-06-11 07:41:32 -0700183 const std::string& realm() const {
184 RTC_DCHECK(thread_checker_.CalledOnValidThread());
185 return realm_;
186 }
187 void set_realm(const std::string& realm) {
188 RTC_DCHECK(thread_checker_.CalledOnValidThread());
189 realm_ = realm;
190 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000191
192 // Gets/sets the value for the SOFTWARE attribute for TURN messages.
Seth Hampsonaed71642018-06-11 07:41:32 -0700193 const std::string& software() const {
194 RTC_DCHECK(thread_checker_.CalledOnValidThread());
195 return software_;
196 }
197 void set_software(const std::string& software) {
198 RTC_DCHECK(thread_checker_.CalledOnValidThread());
199 software_ = software;
200 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000201
Seth Hampsonaed71642018-06-11 07:41:32 -0700202 const AllocationMap& allocations() const {
203 RTC_DCHECK(thread_checker_.CalledOnValidThread());
204 return allocations_;
205 }
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000206
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000207 // Sets the authentication callback; does not take ownership.
Seth Hampsonaed71642018-06-11 07:41:32 -0700208 void set_auth_hook(TurnAuthInterface* auth_hook) {
209 RTC_DCHECK(thread_checker_.CalledOnValidThread());
210 auth_hook_ = auth_hook;
211 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000212
213 void set_redirect_hook(TurnRedirectInterface* redirect_hook) {
Seth Hampsonaed71642018-06-11 07:41:32 -0700214 RTC_DCHECK(thread_checker_.CalledOnValidThread());
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000215 redirect_hook_ = redirect_hook;
216 }
217
Seth Hampsonaed71642018-06-11 07:41:32 -0700218 void set_enable_otu_nonce(bool enable) {
219 RTC_DCHECK(thread_checker_.CalledOnValidThread());
220 enable_otu_nonce_ = enable;
221 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000222
deadbeef376e1232015-11-25 09:00:08 -0800223 // If set to true, reject CreatePermission requests to RFC1918 addresses.
224 void set_reject_private_addresses(bool filter) {
Seth Hampsonaed71642018-06-11 07:41:32 -0700225 RTC_DCHECK(thread_checker_.CalledOnValidThread());
deadbeef376e1232015-11-25 09:00:08 -0800226 reject_private_addresses_ = filter;
227 }
228
Taylor Brandstetteref184702016-06-23 17:35:47 -0700229 void set_enable_permission_checks(bool enable) {
Seth Hampsonaed71642018-06-11 07:41:32 -0700230 RTC_DCHECK(thread_checker_.CalledOnValidThread());
Taylor Brandstetteref184702016-06-23 17:35:47 -0700231 enable_permission_checks_ = enable;
232 }
233
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000234 // Starts listening for packets from internal clients.
235 void AddInternalSocket(rtc::AsyncPacketSocket* socket,
236 ProtocolType proto);
237 // Starts listening for the connections on this socket. When someone tries
238 // to connect, the connection will be accepted and a new internal socket
239 // will be added.
240 void AddInternalServerSocket(rtc::AsyncSocket* socket,
241 ProtocolType proto);
242 // Specifies the factory to use for creating external sockets.
243 void SetExternalSocketFactory(rtc::PacketSocketFactory* factory,
244 const rtc::SocketAddress& address);
honghaizc463e202016-02-01 15:19:08 -0800245 // For testing only.
honghaiz34b11eb2016-03-16 08:55:44 -0700246 std::string SetTimestampForNextNonce(int64_t timestamp) {
Seth Hampsonaed71642018-06-11 07:41:32 -0700247 RTC_DCHECK(thread_checker_.CalledOnValidThread());
honghaizc463e202016-02-01 15:19:08 -0800248 ts_for_next_nonce_ = timestamp;
249 return GenerateNonce(timestamp);
250 }
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000251
Jonas Orelandbdcee282017-10-10 14:01:40 +0200252 void SetStunMessageObserver(
253 std::unique_ptr<StunMessageObserver> observer) {
Seth Hampsonaed71642018-06-11 07:41:32 -0700254 RTC_DCHECK(thread_checker_.CalledOnValidThread());
Jonas Orelandbdcee282017-10-10 14:01:40 +0200255 stun_message_observer_ = std::move(observer);
256 }
257
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000258 private:
honghaiz34b11eb2016-03-16 08:55:44 -0700259 std::string GenerateNonce(int64_t now) const;
Niels Möllere6933812018-11-05 13:01:41 +0100260 void OnInternalPacket(rtc::AsyncPacketSocket* socket,
261 const char* data,
262 size_t size,
263 const rtc::SocketAddress& address,
264 const int64_t& packet_time_us);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000265
266 void OnNewInternalConnection(rtc::AsyncSocket* socket);
267
268 // Accept connections on this server socket.
269 void AcceptConnection(rtc::AsyncSocket* server_socket);
270 void OnInternalSocketClose(rtc::AsyncPacketSocket* socket, int err);
271
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000272 void HandleStunMessage(
273 TurnServerConnection* conn, const char* data, size_t size);
274 void HandleBindingRequest(TurnServerConnection* conn, const StunMessage* msg);
275 void HandleAllocateRequest(TurnServerConnection* conn, const TurnMessage* msg,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000276 const std::string& key);
277
278 bool GetKey(const StunMessage* msg, std::string* key);
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000279 bool CheckAuthorization(TurnServerConnection* conn, const StunMessage* msg,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000280 const char* data, size_t size,
281 const std::string& key);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000282 bool ValidateNonce(const std::string& nonce) const;
283
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000284 TurnServerAllocation* FindAllocation(TurnServerConnection* conn);
285 TurnServerAllocation* CreateAllocation(
286 TurnServerConnection* conn, int proto, const std::string& key);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000287
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000288 void SendErrorResponse(TurnServerConnection* conn, const StunMessage* req,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000289 int code, const std::string& reason);
290
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000291 void SendErrorResponseWithRealmAndNonce(TurnServerConnection* conn,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000292 const StunMessage* req,
293 int code,
294 const std::string& reason);
295
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000296 void SendErrorResponseWithAlternateServer(TurnServerConnection* conn,
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000297 const StunMessage* req,
298 const rtc::SocketAddress& addr);
299
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000300 void SendStun(TurnServerConnection* conn, StunMessage* msg);
jbauchf1f87202016-03-30 06:43:37 -0700301 void Send(TurnServerConnection* conn, const rtc::ByteBufferWriter& buf);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000302
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000303 void OnAllocationDestroyed(TurnServerAllocation* allocation);
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000304 void DestroyInternalSocket(rtc::AsyncPacketSocket* socket);
305
deadbeef824f5862016-08-24 15:06:53 -0700306 // Just clears |sockets_to_delete_|; called asynchronously.
307 void FreeSockets();
308
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000309 typedef std::map<rtc::AsyncPacketSocket*,
310 ProtocolType> InternalSocketMap;
311 typedef std::map<rtc::AsyncSocket*,
312 ProtocolType> ServerSocketMap;
313
314 rtc::Thread* thread_;
Seth Hampsonaed71642018-06-11 07:41:32 -0700315 rtc::ThreadChecker thread_checker_;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000316 std::string nonce_key_;
317 std::string realm_;
318 std::string software_;
319 TurnAuthInterface* auth_hook_;
320 TurnRedirectInterface* redirect_hook_;
321 // otu - one-time-use. Server will respond with 438 if it's
322 // sees the same nonce in next transaction.
323 bool enable_otu_nonce_;
deadbeef376e1232015-11-25 09:00:08 -0800324 bool reject_private_addresses_ = false;
Taylor Brandstetteref184702016-06-23 17:35:47 -0700325 // Check for permission when receiving an external packet.
326 bool enable_permission_checks_ = true;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000327
328 InternalSocketMap server_sockets_;
329 ServerSocketMap server_listen_sockets_;
deadbeef824f5862016-08-24 15:06:53 -0700330 // Used when we need to delete a socket asynchronously.
331 std::vector<std::unique_ptr<rtc::AsyncPacketSocket>> sockets_to_delete_;
kwiberg3ec46792016-04-27 07:22:53 -0700332 std::unique_ptr<rtc::PacketSocketFactory> external_socket_factory_;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000333 rtc::SocketAddress external_addr_;
334
335 AllocationMap allocations_;
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000336
deadbeef824f5862016-08-24 15:06:53 -0700337 rtc::AsyncInvoker invoker_;
338
honghaizc463e202016-02-01 15:19:08 -0800339 // For testing only. If this is non-zero, the next NONCE will be generated
340 // from this value, and it will be reset to 0 after generating the NONCE.
honghaiz34b11eb2016-03-16 08:55:44 -0700341 int64_t ts_for_next_nonce_ = 0;
honghaizc463e202016-02-01 15:19:08 -0800342
Jonas Orelandbdcee282017-10-10 14:01:40 +0200343 // For testing only. Used to observe STUN messages received.
344 std::unique_ptr<StunMessageObserver> stun_message_observer_;
345
pthatcher@webrtc.org0ba15332015-01-10 00:47:02 +0000346 friend class TurnServerAllocation;
henrike@webrtc.org269fb4b2014-10-28 22:20:11 +0000347};
348
349} // namespace cricket
350
Steve Anton10542f22019-01-11 09:11:00 -0800351#endif // P2P_BASE_TURN_SERVER_H_