a72cc7151c
* tls_handshakes: add IP addresses * tls_handshakes: extract ip from tcp-connect * tls_handshake: switched to trace event * saver.go: get remoteAddr before handshake Not sure whether this is strictly necessary, but I'd rather take the remoteAddr before calling Handshake, just in case a future version of the handshake closes the `conn`. In such a case, `conn.RemoteAddr` would return `nil` and we would crash here. This occurred to me while reading once again the diff before merging. Co-authored-by: decfox <decfox> Co-authored-by: Simone Basso <bassosimone@gmail.com>
53 lines
1.5 KiB
Go
53 lines
1.5 KiB
Go
package tlsdialer
|
|
|
|
import (
|
|
"context"
|
|
"crypto/tls"
|
|
"net"
|
|
"time"
|
|
|
|
"github.com/ooni/probe-cli/v3/internal/engine/netx/trace"
|
|
"github.com/ooni/probe-cli/v3/internal/model"
|
|
"github.com/ooni/probe-cli/v3/internal/netxlite"
|
|
)
|
|
|
|
// SaverTLSHandshaker saves events occurring during the handshake
|
|
type SaverTLSHandshaker struct {
|
|
model.TLSHandshaker
|
|
Saver *trace.Saver
|
|
}
|
|
|
|
// Handshake implements TLSHandshaker.Handshake
|
|
func (h SaverTLSHandshaker) Handshake(
|
|
ctx context.Context, conn net.Conn, config *tls.Config,
|
|
) (net.Conn, tls.ConnectionState, error) {
|
|
start := time.Now()
|
|
h.Saver.Write(trace.Event{
|
|
Name: "tls_handshake_start",
|
|
NoTLSVerify: config.InsecureSkipVerify,
|
|
TLSNextProtos: config.NextProtos,
|
|
TLSServerName: config.ServerName,
|
|
Time: start,
|
|
})
|
|
remoteAddr := conn.RemoteAddr().String()
|
|
tlsconn, state, err := h.TLSHandshaker.Handshake(ctx, conn, config)
|
|
stop := time.Now()
|
|
h.Saver.Write(trace.Event{
|
|
Address: remoteAddr,
|
|
Duration: stop.Sub(start),
|
|
Err: err,
|
|
Name: "tls_handshake_done",
|
|
NoTLSVerify: config.InsecureSkipVerify,
|
|
TLSCipherSuite: netxlite.TLSCipherSuiteString(state.CipherSuite),
|
|
TLSNegotiatedProto: state.NegotiatedProtocol,
|
|
TLSNextProtos: config.NextProtos,
|
|
TLSPeerCerts: trace.PeerCerts(state, err),
|
|
TLSServerName: config.ServerName,
|
|
TLSVersion: netxlite.TLSVersionString(state.Version),
|
|
Time: stop,
|
|
})
|
|
return tlsconn, state, err
|
|
}
|
|
|
|
var _ model.TLSHandshaker = SaverTLSHandshaker{}
|