conn.go 8.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340
  1. // Copyright 2011 The Go Authors. All rights reserved.
  2. // Use of this source code is governed by a BSD-style
  3. // license that can be found in the LICENSE file.
  4. package ldap
  5. import (
  6. "crypto/tls"
  7. "errors"
  8. "log"
  9. "net"
  10. "sync"
  11. "time"
  12. "github.com/nmcclain/asn1-ber"
  13. )
  14. const (
  15. MessageQuit = 0
  16. MessageRequest = 1
  17. MessageResponse = 2
  18. MessageFinish = 3
  19. )
  20. type messagePacket struct {
  21. Op int
  22. MessageID uint64
  23. Packet *ber.Packet
  24. Channel chan *ber.Packet
  25. }
  26. // Conn represents an LDAP Connection
  27. type Conn struct {
  28. conn net.Conn
  29. isTLS bool
  30. Debug debugging
  31. chanConfirm chan bool
  32. chanResults map[uint64]chan *ber.Packet
  33. chanMessage chan *messagePacket
  34. chanMessageID chan uint64
  35. wgSender sync.WaitGroup
  36. chanDone chan struct{}
  37. once sync.Once
  38. }
  39. // Dial connects to the given address on the given network using net.Dial
  40. // and then returns a new Conn for the connection.
  41. func Dial(network, addr string) (*Conn, error) {
  42. c, err := net.Dial(network, addr)
  43. if err != nil {
  44. return nil, NewError(ErrorNetwork, err)
  45. }
  46. conn := NewConn(c)
  47. conn.start()
  48. return conn, nil
  49. }
  50. // DialTimeout connects to the given address on the given network using net.DialTimeout
  51. // and then returns a new Conn for the connection. Acts like Dial but takes a timeout.
  52. func DialTimeout(network, addr string, timeout time.Duration) (*Conn, error) {
  53. c, err := net.DialTimeout(network, addr, timeout)
  54. if err != nil {
  55. return nil, NewError(ErrorNetwork, err)
  56. }
  57. conn := NewConn(c)
  58. conn.start()
  59. return conn, nil
  60. }
  61. // DialTLS connects to the given address on the given network using tls.Dial
  62. // and then returns a new Conn for the connection.
  63. func DialTLS(network, addr string, config *tls.Config) (*Conn, error) {
  64. c, err := tls.Dial(network, addr, config)
  65. if err != nil {
  66. return nil, NewError(ErrorNetwork, err)
  67. }
  68. conn := NewConn(c)
  69. conn.isTLS = true
  70. conn.start()
  71. return conn, nil
  72. }
  73. // DialTLSDialer connects to the given address on the given network using tls.DialWithDialer
  74. // and then returns a new Conn for the connection.
  75. func DialTLSDialer(network, addr string, config *tls.Config, dialer *net.Dialer) (*Conn, error) {
  76. c, err := tls.DialWithDialer(dialer, network, addr, config)
  77. if err != nil {
  78. return nil, NewError(ErrorNetwork, err)
  79. }
  80. conn := NewConn(c)
  81. conn.isTLS = true
  82. conn.start()
  83. return conn, nil
  84. }
  85. // NewConn returns a new Conn using conn for network I/O.
  86. func NewConn(conn net.Conn) *Conn {
  87. return &Conn{
  88. conn: conn,
  89. chanConfirm: make(chan bool),
  90. chanMessageID: make(chan uint64),
  91. chanMessage: make(chan *messagePacket, 10),
  92. chanResults: map[uint64]chan *ber.Packet{},
  93. chanDone: make(chan struct{}),
  94. }
  95. }
  96. func (l *Conn) start() {
  97. go l.reader()
  98. go l.processMessages()
  99. }
  100. // Close closes the connection.
  101. func (l *Conn) Close() {
  102. l.once.Do(func() {
  103. close(l.chanDone)
  104. l.wgSender.Wait()
  105. l.Debug.Printf("Sending quit message and waiting for confirmation")
  106. l.chanMessage <- &messagePacket{Op: MessageQuit}
  107. <-l.chanConfirm
  108. close(l.chanMessage)
  109. l.Debug.Printf("Closing network connection")
  110. if err := l.conn.Close(); err != nil {
  111. log.Print(err)
  112. }
  113. })
  114. <-l.chanDone
  115. }
  116. // Returns the next available messageID
  117. func (l *Conn) nextMessageID() uint64 {
  118. if l.chanMessageID != nil {
  119. if messageID, ok := <-l.chanMessageID; ok {
  120. return messageID
  121. }
  122. }
  123. return 0
  124. }
  125. // StartTLS sends the command to start a TLS session and then creates a new TLS Client
  126. func (l *Conn) StartTLS(config *tls.Config) error {
  127. messageID := l.nextMessageID()
  128. if l.isTLS {
  129. return NewError(ErrorNetwork, errors.New("ldap: already encrypted"))
  130. }
  131. packet := ber.Encode(ber.ClassUniversal, ber.TypeConstructed, ber.TagSequence, nil, "LDAP Request")
  132. packet.AppendChild(ber.NewInteger(ber.ClassUniversal, ber.TypePrimitive, ber.TagInteger, messageID, "MessageID"))
  133. request := ber.Encode(ber.ClassApplication, ber.TypeConstructed, ApplicationExtendedRequest, nil, "Start TLS")
  134. request.AppendChild(ber.NewString(ber.ClassContext, ber.TypePrimitive, 0, "1.3.6.1.4.1.1466.20037", "TLS Extended Command"))
  135. packet.AppendChild(request)
  136. l.Debug.PrintPacket(packet)
  137. _, err := l.conn.Write(packet.Bytes())
  138. if err != nil {
  139. return NewError(ErrorNetwork, err)
  140. }
  141. packet, err = ber.ReadPacket(l.conn)
  142. if err != nil {
  143. return NewError(ErrorNetwork, err)
  144. }
  145. if l.Debug {
  146. if err := addLDAPDescriptions(packet); err != nil {
  147. return err
  148. }
  149. ber.PrintPacket(packet)
  150. }
  151. if packet.Children[1].Children[0].Value.(uint64) == 0 {
  152. conn := tls.Client(l.conn, config)
  153. l.isTLS = true
  154. l.conn = conn
  155. }
  156. return nil
  157. }
  158. func (l *Conn) closing() bool {
  159. select {
  160. case <-l.chanDone:
  161. return true
  162. default:
  163. return false
  164. }
  165. }
  166. func (l *Conn) sendMessage(packet *ber.Packet) (chan *ber.Packet, error) {
  167. if l.closing() {
  168. return nil, NewError(ErrorNetwork, errors.New("ldap: connection closed"))
  169. }
  170. out := make(chan *ber.Packet)
  171. message := &messagePacket{
  172. Op: MessageRequest,
  173. MessageID: packet.Children[0].Value.(uint64),
  174. Packet: packet,
  175. Channel: out,
  176. }
  177. l.sendProcessMessage(message)
  178. return out, nil
  179. }
  180. func (l *Conn) finishMessage(messageID uint64) {
  181. if l.closing() {
  182. return
  183. }
  184. message := &messagePacket{
  185. Op: MessageFinish,
  186. MessageID: messageID,
  187. }
  188. l.sendProcessMessage(message)
  189. }
  190. func (l *Conn) sendProcessMessage(message *messagePacket) bool {
  191. l.wgSender.Add(1)
  192. defer l.wgSender.Done()
  193. if l.closing() {
  194. return false
  195. }
  196. l.chanMessage <- message
  197. return true
  198. }
  199. func (l *Conn) processMessages() {
  200. defer func() {
  201. for messageID, channel := range l.chanResults {
  202. l.Debug.Printf("Closing channel for MessageID %d", messageID)
  203. close(channel)
  204. delete(l.chanResults, messageID)
  205. }
  206. close(l.chanMessageID)
  207. l.chanConfirm <- true
  208. close(l.chanConfirm)
  209. }()
  210. var messageID uint64 = 1
  211. for {
  212. select {
  213. case l.chanMessageID <- messageID:
  214. messageID++
  215. case messagePacket, ok := <-l.chanMessage:
  216. if !ok {
  217. l.Debug.Printf("Shutting down - message channel is closed")
  218. return
  219. }
  220. switch messagePacket.Op {
  221. case MessageQuit:
  222. l.Debug.Printf("Shutting down - quit message received")
  223. return
  224. case MessageRequest:
  225. // Add to message list and write to network
  226. l.Debug.Printf("Sending message %d", messagePacket.MessageID)
  227. l.chanResults[messagePacket.MessageID] = messagePacket.Channel
  228. // go routine
  229. buf := messagePacket.Packet.Bytes()
  230. _, err := l.conn.Write(buf)
  231. if err != nil {
  232. l.Debug.Printf("Error Sending Message: %s", err.Error())
  233. break
  234. }
  235. case MessageResponse:
  236. l.Debug.Printf("Receiving message %d", messagePacket.MessageID)
  237. if chanResult, ok := l.chanResults[messagePacket.MessageID]; ok {
  238. chanResult <- messagePacket.Packet
  239. } else {
  240. log.Printf("Received unexpected message %d", messagePacket.MessageID)
  241. ber.PrintPacket(messagePacket.Packet)
  242. }
  243. case MessageFinish:
  244. // Remove from message list
  245. l.Debug.Printf("Finished message %d", messagePacket.MessageID)
  246. close(l.chanResults[messagePacket.MessageID])
  247. delete(l.chanResults, messagePacket.MessageID)
  248. }
  249. }
  250. }
  251. }
  252. func (l *Conn) reader() {
  253. defer func() {
  254. l.Close()
  255. }()
  256. for {
  257. packet, err := ber.ReadPacket(l.conn)
  258. if err != nil {
  259. l.Debug.Printf("reader: %s", err.Error())
  260. return
  261. }
  262. addLDAPDescriptions(packet)
  263. message := &messagePacket{
  264. Op: MessageResponse,
  265. MessageID: packet.Children[0].Value.(uint64),
  266. Packet: packet,
  267. }
  268. if !l.sendProcessMessage(message) {
  269. return
  270. }
  271. }
  272. }
  273. // Use Abandon operation to perform connection keepalives
  274. func (l *Conn) Ping() error {
  275. messageID := l.nextMessageID()
  276. packet := ber.Encode(ber.ClassUniversal, ber.TypeConstructed, ber.TagSequence, nil, "LDAP Request")
  277. packet.AppendChild(ber.NewInteger(ber.ClassUniversal, ber.TypePrimitive, ber.TagInteger, messageID, "MessageID"))
  278. abandonRequest := ber.Encode(ber.ClassApplication, ber.TypePrimitive, ApplicationAbandonRequest, nil, "Abandon Request")
  279. packet.AppendChild(abandonRequest)
  280. if l.Debug {
  281. ber.PrintPacket(packet)
  282. }
  283. channel, err := l.sendMessage(packet)
  284. if err != nil {
  285. return err
  286. }
  287. if channel == nil {
  288. return NewError(ErrorNetwork, errors.New("ldap: could not send message"))
  289. }
  290. defer l.finishMessage(messageID)
  291. if l.Debug {
  292. if err := addLDAPDescriptions(packet); err != nil {
  293. return err
  294. }
  295. ber.PrintPacket(packet)
  296. }
  297. return nil
  298. }