dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 1 | // Copyright 2014 The Chromium Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
| 5 | #include "net/server/web_socket_encoder.h" |
| 6 | |
davidben | 411d3f7 | 2016-01-22 01:41:41 | [diff] [blame] | 7 | #include <limits> |
dcheng | c7eeda42 | 2015-12-26 03:56:48 | [diff] [blame] | 8 | #include <utility> |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 9 | #include <vector> |
| 10 | |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 11 | #include "base/logging.h" |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 12 | #include "base/memory/ptr_util.h" |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 13 | #include "base/strings/string_number_conversions.h" |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 14 | #include "net/base/io_buffer.h" |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 15 | #include "net/websockets/websocket_deflate_parameters.h" |
| 16 | #include "net/websockets/websocket_extension.h" |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 17 | #include "net/websockets/websocket_extension_parser.h" |
| 18 | |
| 19 | namespace net { |
| 20 | |
| 21 | const char WebSocketEncoder::kClientExtensions[] = |
Eugene Ostroukhov | dea9637 | 2017-11-22 23:16:02 | [diff] [blame] | 22 | "permessage-deflate; client_max_window_bits"; |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 23 | |
| 24 | namespace { |
| 25 | |
| 26 | const int kInflaterChunkSize = 16 * 1024; |
| 27 | |
| 28 | // Constants for hybi-10 frame format. |
| 29 | |
| 30 | typedef int OpCode; |
| 31 | |
| 32 | const OpCode kOpCodeContinuation = 0x0; |
| 33 | const OpCode kOpCodeText = 0x1; |
| 34 | const OpCode kOpCodeBinary = 0x2; |
| 35 | const OpCode kOpCodeClose = 0x8; |
| 36 | const OpCode kOpCodePing = 0x9; |
| 37 | const OpCode kOpCodePong = 0xA; |
| 38 | |
| 39 | const unsigned char kFinalBit = 0x80; |
| 40 | const unsigned char kReserved1Bit = 0x40; |
| 41 | const unsigned char kReserved2Bit = 0x20; |
| 42 | const unsigned char kReserved3Bit = 0x10; |
| 43 | const unsigned char kOpCodeMask = 0xF; |
| 44 | const unsigned char kMaskBit = 0x80; |
| 45 | const unsigned char kPayloadLengthMask = 0x7F; |
| 46 | |
| 47 | const size_t kMaxSingleBytePayloadLength = 125; |
| 48 | const size_t kTwoBytePayloadLengthField = 126; |
| 49 | const size_t kEightBytePayloadLengthField = 127; |
| 50 | const size_t kMaskingKeyWidthInBytes = 4; |
| 51 | |
| 52 | WebSocket::ParseResult DecodeFrameHybi17(const base::StringPiece& frame, |
| 53 | bool client_frame, |
| 54 | int* bytes_consumed, |
| 55 | std::string* output, |
| 56 | bool* compressed) { |
| 57 | size_t data_length = frame.length(); |
| 58 | if (data_length < 2) |
| 59 | return WebSocket::FRAME_INCOMPLETE; |
| 60 | |
| 61 | const char* buffer_begin = const_cast<char*>(frame.data()); |
| 62 | const char* p = buffer_begin; |
| 63 | const char* buffer_end = p + data_length; |
| 64 | |
| 65 | unsigned char first_byte = *p++; |
| 66 | unsigned char second_byte = *p++; |
| 67 | |
| 68 | bool final = (first_byte & kFinalBit) != 0; |
| 69 | bool reserved1 = (first_byte & kReserved1Bit) != 0; |
| 70 | bool reserved2 = (first_byte & kReserved2Bit) != 0; |
| 71 | bool reserved3 = (first_byte & kReserved3Bit) != 0; |
| 72 | int op_code = first_byte & kOpCodeMask; |
| 73 | bool masked = (second_byte & kMaskBit) != 0; |
| 74 | *compressed = reserved1; |
| 75 | if (!final || reserved2 || reserved3) |
| 76 | return WebSocket::FRAME_ERROR; // Only compression extension is supported. |
| 77 | |
| 78 | bool closed = false; |
| 79 | switch (op_code) { |
| 80 | case kOpCodeClose: |
| 81 | closed = true; |
| 82 | break; |
| 83 | case kOpCodeText: |
| 84 | break; |
| 85 | case kOpCodeBinary: // We don't support binary frames yet. |
| 86 | case kOpCodeContinuation: // We don't support binary frames yet. |
| 87 | case kOpCodePing: // We don't support binary frames yet. |
| 88 | case kOpCodePong: // We don't support binary frames yet. |
| 89 | default: |
| 90 | return WebSocket::FRAME_ERROR; |
| 91 | } |
| 92 | |
ellyjones | c7a5c50 | 2015-06-26 18:55:20 | [diff] [blame] | 93 | if (client_frame && !masked) // In Hybi-17 spec client MUST mask its frame. |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 94 | return WebSocket::FRAME_ERROR; |
| 95 | |
Avi Drissman | 13fc893 | 2015-12-20 04:40:46 | [diff] [blame] | 96 | uint64_t payload_length64 = second_byte & kPayloadLengthMask; |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 97 | if (payload_length64 > kMaxSingleBytePayloadLength) { |
| 98 | int extended_payload_length_size; |
thestig | cf72977 | 2016-11-19 04:35:07 | [diff] [blame] | 99 | if (payload_length64 == kTwoBytePayloadLengthField) { |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 100 | extended_payload_length_size = 2; |
thestig | cf72977 | 2016-11-19 04:35:07 | [diff] [blame] | 101 | } else { |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 102 | DCHECK(payload_length64 == kEightBytePayloadLengthField); |
| 103 | extended_payload_length_size = 8; |
| 104 | } |
| 105 | if (buffer_end - p < extended_payload_length_size) |
| 106 | return WebSocket::FRAME_INCOMPLETE; |
| 107 | payload_length64 = 0; |
| 108 | for (int i = 0; i < extended_payload_length_size; ++i) { |
| 109 | payload_length64 <<= 8; |
| 110 | payload_length64 |= static_cast<unsigned char>(*p++); |
| 111 | } |
| 112 | } |
| 113 | |
| 114 | size_t actual_masking_key_length = masked ? kMaskingKeyWidthInBytes : 0; |
Avi Drissman | 13fc893 | 2015-12-20 04:40:46 | [diff] [blame] | 115 | static const uint64_t max_payload_length = 0x7FFFFFFFFFFFFFFFull; |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 116 | static size_t max_length = std::numeric_limits<size_t>::max(); |
| 117 | if (payload_length64 > max_payload_length || |
| 118 | payload_length64 + actual_masking_key_length > max_length) { |
| 119 | // WebSocket frame length too large. |
| 120 | return WebSocket::FRAME_ERROR; |
| 121 | } |
| 122 | size_t payload_length = static_cast<size_t>(payload_length64); |
| 123 | |
| 124 | size_t total_length = actual_masking_key_length + payload_length; |
| 125 | if (static_cast<size_t>(buffer_end - p) < total_length) |
| 126 | return WebSocket::FRAME_INCOMPLETE; |
| 127 | |
| 128 | if (masked) { |
| 129 | output->resize(payload_length); |
| 130 | const char* masking_key = p; |
| 131 | char* payload = const_cast<char*>(p + kMaskingKeyWidthInBytes); |
| 132 | for (size_t i = 0; i < payload_length; ++i) // Unmask the payload. |
| 133 | (*output)[i] = payload[i] ^ masking_key[i % kMaskingKeyWidthInBytes]; |
| 134 | } else { |
| 135 | output->assign(p, p + payload_length); |
| 136 | } |
| 137 | |
| 138 | size_t pos = p + actual_masking_key_length + payload_length - buffer_begin; |
| 139 | *bytes_consumed = pos; |
| 140 | return closed ? WebSocket::FRAME_CLOSE : WebSocket::FRAME_OK; |
| 141 | } |
| 142 | |
Johannes Henkel | da8b9d3 | 2019-03-15 16:15:33 | [diff] [blame^] | 143 | void EncodeFrameHybi17(base::StringPiece message, |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 144 | int masking_key, |
| 145 | bool compressed, |
| 146 | std::string* output) { |
| 147 | std::vector<char> frame; |
| 148 | OpCode op_code = kOpCodeText; |
| 149 | size_t data_length = message.length(); |
| 150 | |
| 151 | int reserved1 = compressed ? kReserved1Bit : 0; |
| 152 | frame.push_back(kFinalBit | op_code | reserved1); |
| 153 | char mask_key_bit = masking_key != 0 ? kMaskBit : 0; |
brucedawson | ef12824 | 2015-12-01 04:26:36 | [diff] [blame] | 154 | if (data_length <= kMaxSingleBytePayloadLength) { |
| 155 | frame.push_back(static_cast<char>(data_length) | mask_key_bit); |
| 156 | } else if (data_length <= 0xFFFF) { |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 157 | frame.push_back(kTwoBytePayloadLengthField | mask_key_bit); |
| 158 | frame.push_back((data_length & 0xFF00) >> 8); |
| 159 | frame.push_back(data_length & 0xFF); |
| 160 | } else { |
| 161 | frame.push_back(kEightBytePayloadLengthField | mask_key_bit); |
| 162 | char extended_payload_length[8]; |
| 163 | size_t remaining = data_length; |
| 164 | // Fill the length into extended_payload_length in the network byte order. |
| 165 | for (int i = 0; i < 8; ++i) { |
| 166 | extended_payload_length[7 - i] = remaining & 0xFF; |
| 167 | remaining >>= 8; |
| 168 | } |
| 169 | frame.insert(frame.end(), extended_payload_length, |
| 170 | extended_payload_length + 8); |
| 171 | DCHECK(!remaining); |
| 172 | } |
| 173 | |
| 174 | const char* data = const_cast<char*>(message.data()); |
| 175 | if (masking_key != 0) { |
| 176 | const char* mask_bytes = reinterpret_cast<char*>(&masking_key); |
| 177 | frame.insert(frame.end(), mask_bytes, mask_bytes + 4); |
| 178 | for (size_t i = 0; i < data_length; ++i) // Mask the payload. |
| 179 | frame.push_back(data[i] ^ mask_bytes[i % kMaskingKeyWidthInBytes]); |
| 180 | } else { |
| 181 | frame.insert(frame.end(), data, data + data_length); |
| 182 | } |
| 183 | *output = std::string(&frame[0], frame.size()); |
| 184 | } |
| 185 | |
| 186 | } // anonymous namespace |
| 187 | |
| 188 | // static |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 189 | std::unique_ptr<WebSocketEncoder> WebSocketEncoder::CreateServer() { |
| 190 | return base::WrapUnique(new WebSocketEncoder(FOR_SERVER, nullptr, nullptr)); |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 191 | } |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 192 | |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 193 | // static |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 194 | std::unique_ptr<WebSocketEncoder> WebSocketEncoder::CreateServer( |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 195 | const std::string& extensions, |
| 196 | WebSocketDeflateParameters* deflate_parameters) { |
| 197 | WebSocketExtensionParser parser; |
| 198 | if (!parser.Parse(extensions)) { |
| 199 | // Failed to parse Sec-WebSocket-Extensions header. We MUST fail the |
| 200 | // connection. |
| 201 | return nullptr; |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 202 | } |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 203 | |
| 204 | for (const auto& extension : parser.extensions()) { |
| 205 | std::string failure_message; |
| 206 | WebSocketDeflateParameters offer; |
| 207 | if (!offer.Initialize(extension, &failure_message) || |
| 208 | !offer.IsValidAsRequest(&failure_message)) { |
| 209 | // We decline unknown / malformed extensions. |
| 210 | continue; |
| 211 | } |
| 212 | |
| 213 | WebSocketDeflateParameters response = offer; |
| 214 | if (offer.is_client_max_window_bits_specified() && |
| 215 | !offer.has_client_max_window_bits_value()) { |
| 216 | // We need to choose one value for the response. |
| 217 | response.SetClientMaxWindowBits(15); |
| 218 | } |
| 219 | DCHECK(response.IsValidAsResponse()); |
| 220 | DCHECK(offer.IsCompatibleWith(response)); |
Jeremy Roman | 0579ed6 | 2017-08-29 15:56:19 | [diff] [blame] | 221 | auto deflater = std::make_unique<WebSocketDeflater>( |
ricea | 2deef68 | 2016-09-09 08:04:07 | [diff] [blame] | 222 | response.server_context_take_over_mode()); |
Jeremy Roman | 0579ed6 | 2017-08-29 15:56:19 | [diff] [blame] | 223 | auto inflater = std::make_unique<WebSocketInflater>(kInflaterChunkSize, |
ricea | 2deef68 | 2016-09-09 08:04:07 | [diff] [blame] | 224 | kInflaterChunkSize); |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 225 | if (!deflater->Initialize(response.PermissiveServerMaxWindowBits()) || |
| 226 | !inflater->Initialize(response.PermissiveClientMaxWindowBits())) { |
| 227 | // For some reason we cannot accept the parameters. |
| 228 | continue; |
| 229 | } |
| 230 | *deflate_parameters = response; |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 231 | return base::WrapUnique(new WebSocketEncoder( |
| 232 | FOR_SERVER, std::move(deflater), std::move(inflater))); |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 233 | } |
| 234 | |
| 235 | // We cannot find an acceptable offer. |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 236 | return base::WrapUnique(new WebSocketEncoder(FOR_SERVER, nullptr, nullptr)); |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 237 | } |
| 238 | |
| 239 | // static |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 240 | std::unique_ptr<WebSocketEncoder> WebSocketEncoder::CreateClient( |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 241 | const std::string& response_extensions) { |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 242 | // TODO(yhirano): Add a way to return an error. |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 243 | |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 244 | WebSocketExtensionParser parser; |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 245 | if (!parser.Parse(response_extensions)) { |
| 246 | // Parse error. Note that there are two cases here. |
| 247 | // 1) There is no Sec-WebSocket-Extensions header. |
| 248 | // 2) There is a malformed Sec-WebSocketExtensions header. |
| 249 | // We should return a deflate-disabled encoder for the former case and |
| 250 | // fail the connection for the latter case. |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 251 | return base::WrapUnique(new WebSocketEncoder(FOR_CLIENT, nullptr, nullptr)); |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 252 | } |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 253 | if (parser.extensions().size() != 1) { |
| 254 | // Only permessage-deflate extension is supported. |
| 255 | // TODO (yhirano): Fail the connection. |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 256 | return base::WrapUnique(new WebSocketEncoder(FOR_CLIENT, nullptr, nullptr)); |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 257 | } |
| 258 | const auto& extension = parser.extensions()[0]; |
| 259 | WebSocketDeflateParameters params; |
| 260 | std::string failure_message; |
| 261 | if (!params.Initialize(extension, &failure_message) || |
| 262 | !params.IsValidAsResponse(&failure_message)) { |
| 263 | // TODO (yhirano): Fail the connection. |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 264 | return base::WrapUnique(new WebSocketEncoder(FOR_CLIENT, nullptr, nullptr)); |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 265 | } |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 266 | |
Jeremy Roman | 0579ed6 | 2017-08-29 15:56:19 | [diff] [blame] | 267 | auto deflater = std::make_unique<WebSocketDeflater>( |
ricea | 2deef68 | 2016-09-09 08:04:07 | [diff] [blame] | 268 | params.client_context_take_over_mode()); |
Jeremy Roman | 0579ed6 | 2017-08-29 15:56:19 | [diff] [blame] | 269 | auto inflater = std::make_unique<WebSocketInflater>(kInflaterChunkSize, |
ricea | 2deef68 | 2016-09-09 08:04:07 | [diff] [blame] | 270 | kInflaterChunkSize); |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 271 | if (!deflater->Initialize(params.PermissiveClientMaxWindowBits()) || |
| 272 | !inflater->Initialize(params.PermissiveServerMaxWindowBits())) { |
| 273 | // TODO (yhirano): Fail the connection. |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 274 | return base::WrapUnique(new WebSocketEncoder(FOR_CLIENT, nullptr, nullptr)); |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 275 | } |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 276 | |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 277 | return base::WrapUnique(new WebSocketEncoder(FOR_CLIENT, std::move(deflater), |
| 278 | std::move(inflater))); |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 279 | } |
| 280 | |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 281 | WebSocketEncoder::WebSocketEncoder(Type type, |
danakj | a9850e1 | 2016-04-18 22:28:08 | [diff] [blame] | 282 | std::unique_ptr<WebSocketDeflater> deflater, |
| 283 | std::unique_ptr<WebSocketInflater> inflater) |
dcheng | c7eeda42 | 2015-12-26 03:56:48 | [diff] [blame] | 284 | : type_(type), |
| 285 | deflater_(std::move(deflater)), |
| 286 | inflater_(std::move(inflater)) {} |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 287 | |
Chris Watkins | 7a41d355 | 2017-12-01 02:13:27 | [diff] [blame] | 288 | WebSocketEncoder::~WebSocketEncoder() = default; |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 289 | |
| 290 | WebSocket::ParseResult WebSocketEncoder::DecodeFrame( |
| 291 | const base::StringPiece& frame, |
| 292 | int* bytes_consumed, |
| 293 | std::string* output) { |
| 294 | bool compressed; |
yhirano | a10dd4e | 2015-09-28 09:06:34 | [diff] [blame] | 295 | WebSocket::ParseResult result = DecodeFrameHybi17( |
| 296 | frame, type_ == FOR_SERVER, bytes_consumed, output, &compressed); |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 297 | if (result == WebSocket::FRAME_OK && compressed) { |
| 298 | if (!Inflate(output)) |
| 299 | result = WebSocket::FRAME_ERROR; |
| 300 | } |
| 301 | return result; |
| 302 | } |
| 303 | |
Johannes Henkel | da8b9d3 | 2019-03-15 16:15:33 | [diff] [blame^] | 304 | void WebSocketEncoder::EncodeFrame(base::StringPiece frame, |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 305 | int masking_key, |
| 306 | std::string* output) { |
| 307 | std::string compressed; |
| 308 | if (Deflate(frame, &compressed)) |
| 309 | EncodeFrameHybi17(compressed, masking_key, true, output); |
| 310 | else |
| 311 | EncodeFrameHybi17(frame, masking_key, false, output); |
| 312 | } |
| 313 | |
| 314 | bool WebSocketEncoder::Inflate(std::string* message) { |
| 315 | if (!inflater_) |
| 316 | return false; |
| 317 | if (!inflater_->AddBytes(message->data(), message->length())) |
| 318 | return false; |
| 319 | if (!inflater_->Finish()) |
| 320 | return false; |
| 321 | |
| 322 | std::vector<char> output; |
| 323 | while (inflater_->CurrentOutputSize() > 0) { |
| 324 | scoped_refptr<IOBufferWithSize> chunk = |
| 325 | inflater_->GetOutput(inflater_->CurrentOutputSize()); |
| 326 | if (!chunk.get()) |
| 327 | return false; |
| 328 | output.insert(output.end(), chunk->data(), chunk->data() + chunk->size()); |
| 329 | } |
| 330 | |
| 331 | *message = |
| 332 | output.size() ? std::string(&output[0], output.size()) : std::string(); |
| 333 | return true; |
| 334 | } |
| 335 | |
Johannes Henkel | da8b9d3 | 2019-03-15 16:15:33 | [diff] [blame^] | 336 | bool WebSocketEncoder::Deflate(base::StringPiece message, std::string* output) { |
dgozman | a6e7009 | 2014-12-12 14:46:21 | [diff] [blame] | 337 | if (!deflater_) |
| 338 | return false; |
| 339 | if (!deflater_->AddBytes(message.data(), message.length())) { |
| 340 | deflater_->Finish(); |
| 341 | return false; |
| 342 | } |
| 343 | if (!deflater_->Finish()) |
| 344 | return false; |
| 345 | scoped_refptr<IOBufferWithSize> buffer = |
| 346 | deflater_->GetOutput(deflater_->CurrentOutputSize()); |
| 347 | if (!buffer.get()) |
| 348 | return false; |
| 349 | *output = std::string(buffer->data(), buffer->size()); |
| 350 | return true; |
| 351 | } |
| 352 | |
| 353 | } // namespace net |