0fdc9cafb5
* fix(all): introduce and use iox.ReadAllContext This improvement over the ioutil.ReadAll utility returns early if the context expires. This enables us to unblock stuck code in case there's censorship confounding the TCP stack. See https://github.com/ooni/probe/issues/1417. Compared to the functionality postulated in the above mentioned issue, I choose to be more generic and separate limiting the maximum body size (not implemented here) from using the context to return early when reading a body (or any other reader). After implementing iox.ReadAllContext, I made sure we always use it everywhere in the tree instead of ioutil.ReadAll. This includes many parts of the codebase where in theory we don't need iox.ReadAllContext. Though, changing all the places makes checking whether we're not using ioutil.ReadAll where we should not be using it easy: `git grep` should return no lines. * Update internal/iox/iox_test.go * fix(ndt7): treat context errors as non-errors The rationale is explained by the comment documenting reduceErr. * Update internal/engine/experiment/ndt7/download.go
87 lines
1.7 KiB
Go
87 lines
1.7 KiB
Go
// +build ignore
|
|
|
|
// This Source Code Form is subject to the terms of the Mozilla Public
|
|
// License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
// file, You can obtain one at https://mozilla.org/MPL/2.0/.
|
|
//
|
|
// Forked from github.com/certifi/gocertifi <https://git.io/JJjmG>.
|
|
//
|
|
// This script should not be invoked directly, rather it should be
|
|
// executed by running go generate ./... from toplevel dir.
|
|
|
|
package main
|
|
|
|
import (
|
|
"context"
|
|
"crypto/x509"
|
|
"log"
|
|
"net/http"
|
|
"os"
|
|
"strings"
|
|
"text/template"
|
|
"time"
|
|
|
|
"github.com/ooni/probe-cli/v3/internal/iox"
|
|
)
|
|
|
|
var tmpl = template.Must(template.New("").Parse(`// Code generated by go generate; DO NOT EDIT.
|
|
// {{ .Timestamp }}
|
|
// {{ .URL }}
|
|
|
|
package tlsx
|
|
|
|
//go:generate go run generate.go "{{ .URL }}"
|
|
|
|
const pemcerts string = ` + "`" + `
|
|
{{ .Bundle }}
|
|
` + "`" + `
|
|
`))
|
|
|
|
func main() {
|
|
if len(os.Args) != 2 || !strings.HasPrefix(os.Args[1], "https://") {
|
|
log.Fatal("usage: go run generate.go <url>")
|
|
}
|
|
url := os.Args[1]
|
|
|
|
resp, err := http.Get(url)
|
|
if err != nil {
|
|
log.Fatal(err)
|
|
}
|
|
if resp.StatusCode != 200 {
|
|
log.Fatal("expected 200, got", resp.StatusCode)
|
|
}
|
|
defer resp.Body.Close()
|
|
|
|
bundle, err := iox.ReadAllContext(context.Background(), resp.Body)
|
|
if err != nil {
|
|
log.Fatal(err)
|
|
}
|
|
|
|
pool := x509.NewCertPool()
|
|
if !pool.AppendCertsFromPEM(bundle) {
|
|
log.Fatalf("can't parse certificates from %s", url)
|
|
}
|
|
|
|
fp, err := os.Create("certifi.go")
|
|
if err != nil {
|
|
log.Fatal(err)
|
|
}
|
|
|
|
err = tmpl.Execute(fp, struct {
|
|
Timestamp time.Time
|
|
URL string
|
|
Bundle string
|
|
}{
|
|
Timestamp: time.Now(),
|
|
URL: url,
|
|
Bundle: string(bundle),
|
|
})
|
|
if err != nil {
|
|
log.Fatal(err)
|
|
}
|
|
|
|
if err := fp.Close(); err != nil {
|
|
log.Fatal(err)
|
|
}
|
|
}
|