Add Transparent Proxy and PROXY v2 support and help page
This commit is contained in:
@@ -144,6 +144,60 @@ sleep 2
|
||||
r=$(on target "sqlite3 /etc/patchbay/patchbay.db \"SELECT COUNT(*) FROM interfaces WHERE (client_id = 0 AND name = 'tun7') OR (client_id = 1 AND name = 'tun8')\"")
|
||||
[ "$r" = 2 ] && ok "tun interfaces reported" || bad "interfaces: $r rows"
|
||||
|
||||
# Origin address: PROXY v2 headers (services print the first 28 bytes as hex,
|
||||
# an IPv4 header is exactly 28) and transparent source spoofing (services
|
||||
# print the peer address they see).
|
||||
HEXDUMP="head -c 28 | od -An -tx1 | tr -dc 0-9a-f" # no quotes or colons: socat parses these
|
||||
on client1 "(socat TCP-LISTEN:9400,fork,reuseaddr SYSTEM:'$HEXDUMP' >/dev/null 2>&1 &) &&
|
||||
(socat UDP-RECVFROM:9401,bind=127.0.0.1,fork SYSTEM:'$HEXDUMP' >/dev/null 2>&1 &) &&
|
||||
(socat TCP-LISTEN:9410,fork,reuseaddr SYSTEM:'echo \$SOCAT_PEERADDR' >/dev/null 2>&1 &) &&
|
||||
(socat UDP-RECVFROM:9411,bind=127.0.0.1,fork SYSTEM:'echo \$SOCAT_PEERADDR' >/dev/null 2>&1 &)"
|
||||
on target "(ip netns exec peer socat TCP-LISTEN:9402,fork,reuseaddr SYSTEM:'$HEXDUMP' >/dev/null 2>&1 &)"
|
||||
on target "sqlite3 /etc/patchbay/patchbay.db \"
|
||||
INSERT INTO nodes (id, type, client_id, host, port, proto, iface, origin) VALUES
|
||||
(40, 'client_source', 1, '127.0.0.1', 9400, 'tcp', '', ''),
|
||||
(41, 'splitter', NULL, '', 0, 'tcp', '', ''),
|
||||
(42, 'public_sink', NULL, '0.0.0.0', 2220, 'tcp', '', 'proxy_v2'),
|
||||
(43, 'client_sink', 2, '127.0.0.1', 7400, 'tcp', '', 'proxy_v2'),
|
||||
(44, 'client_source', 1, '127.0.0.1', 9401, 'udp', '', ''),
|
||||
(45, 'public_sink', NULL, '0.0.0.0', 2221, 'udp', '', 'proxy_v2'),
|
||||
(46, 'tunnel_source', NULL, '10.77.0.2', 9402, 'tcp', 'tun7', ''),
|
||||
(47, 'public_sink', NULL, '0.0.0.0', 2224, 'tcp', '', 'proxy_v2'),
|
||||
(48, 'client_source', 1, '127.0.0.1', 9410, 'tcp', '', ''),
|
||||
(49, 'public_sink', NULL, '0.0.0.0', 2230, 'tcp', '', 'transparent'),
|
||||
(50, 'client_source', 1, '127.0.0.1', 9411, 'udp', '', ''),
|
||||
(51, 'public_sink', NULL, '0.0.0.0', 2231, 'udp', '', 'transparent'),
|
||||
(52, 'tunnel_source', NULL, '10.77.0.2', 9402, 'tcp', 'tun7', ''),
|
||||
(53, 'public_sink', NULL, '0.0.0.0', 2232, 'tcp', '', 'transparent');
|
||||
INSERT INTO links (from_node, to_node) VALUES (40, 41), (41, 42), (41, 43), (44, 45), (46, 47), (48, 49),
|
||||
(50, 51), (52, 53);\""
|
||||
on target 'echo RELOAD | socat - UNIX-CONNECT:/run/patchbay/api.sock' >/dev/null
|
||||
sleep 3
|
||||
c2ip=$(on target 'getent ahostsv4 client2 | head -1 | cut -d" " -f1')
|
||||
c2hex=$(printf '%02x' $(echo "$c2ip" | tr . ' '))
|
||||
sig=0d0a0d0a000d0a515549540a
|
||||
|
||||
r=$(on client2 'echo x | socat -t3 - TCP:target:2220')
|
||||
[ "${r:0:32}" = "${sig}2111000c" ] && [ "${r:32:8}" = "$c2hex" ] && ok "PROXY v2 via public sink (TCP)" || bad "PROXY v2 public TCP: got '$r', want src $c2hex"
|
||||
|
||||
r=$(on client2 'echo x | socat -t3 - TCP:127.0.0.1:7400')
|
||||
[ "${r:0:32}" = "${sig}2111000c" ] && [ "${r:32:8}" = 7f000001 ] && ok "PROXY v2 via client sink" || bad "PROXY v2 client sink: got '$r'"
|
||||
|
||||
r=$(on client2 'echo x | socat -T3 - UDP:target:2221')
|
||||
[ "${r:0:32}" = "${sig}2112000c" ] && [ "${r:32:8}" = "$c2hex" ] && ok "PROXY v2 via public sink (UDP)" || bad "PROXY v2 public UDP: got '$r'"
|
||||
|
||||
r=$(on client2 'echo x | socat -t3 - TCP:target:2224')
|
||||
[ "${r:0:32}" = "${sig}2111000c" ] && [ "${r:32:8}" = "$c2hex" ] && ok "PROXY v2 from target tunnel source" || bad "PROXY v2 target source: got '$r'"
|
||||
|
||||
r=$(on client2 'echo x | socat -t3 - TCP:target:2230')
|
||||
[ "${r%%:*}" = "$c2ip" ] && ok "transparent spoofing (TCP): service sees $r" || bad "spoofing TCP: service saw '$r', want $c2ip"
|
||||
|
||||
r=$(on client2 'echo x | socat -T3 - UDP:target:2231')
|
||||
[ "${r%%:*}" = "$c2ip" ] && ok "transparent spoofing (UDP): service sees $r" || bad "spoofing UDP: service saw '$r', want $c2ip"
|
||||
|
||||
r=$(on target 'echo STATUS | socat - UNIX-CONNECT:/run/patchbay/api.sock')
|
||||
echo "$r" | grep -q '"53":{"ok":false,[^}]*needs a source on a client' && ok "spoofing refused for a target source" || bad "spoofing on target source: $r"
|
||||
|
||||
# Web login over HTTPS with the emailed (logged) code.
|
||||
r=$(on target 'set -e
|
||||
J=/tmp/jar; rm -f $J; U=https://127.0.0.1:8443
|
||||
|
||||
Reference in New Issue
Block a user