2011-01-25 02:02:48 +00:00
|
|
|
"""
|
|
|
|
This module provides more sophisticated flow tracking. These match requests
|
|
|
|
with their responses, and provide filtering and interception facilities.
|
|
|
|
"""
|
2011-02-20 19:47:19 +00:00
|
|
|
import subprocess, base64, sys, json, hashlib
|
2011-02-16 01:33:04 +00:00
|
|
|
import proxy, threading, netstring
|
2011-02-16 03:03:22 +00:00
|
|
|
import controller
|
2011-01-25 02:02:48 +00:00
|
|
|
|
2011-02-01 22:44:28 +00:00
|
|
|
class RunException(Exception):
|
|
|
|
def __init__(self, msg, returncode, errout):
|
|
|
|
Exception.__init__(self, msg)
|
|
|
|
self.returncode = returncode
|
|
|
|
self.errout = errout
|
|
|
|
|
2011-01-31 00:26:56 +00:00
|
|
|
|
2011-01-27 01:19:48 +00:00
|
|
|
# begin nocover
|
2011-02-20 19:47:19 +00:00
|
|
|
class RequestReplayThread(threading.Thread):
|
2011-01-25 02:02:48 +00:00
|
|
|
def __init__(self, flow, masterq):
|
|
|
|
self.flow, self.masterq = flow, masterq
|
|
|
|
threading.Thread.__init__(self)
|
|
|
|
|
|
|
|
def run(self):
|
|
|
|
try:
|
|
|
|
server = proxy.ServerConnection(self.flow.request)
|
2011-02-16 06:37:40 +00:00
|
|
|
server.send_request(self.flow.request)
|
2011-01-25 02:02:48 +00:00
|
|
|
response = server.read_response()
|
|
|
|
response.send(self.masterq)
|
|
|
|
except proxy.ProxyError, v:
|
2011-02-03 01:51:32 +00:00
|
|
|
err = proxy.Error(self.flow.client_conn, v.msg)
|
2011-01-25 02:02:48 +00:00
|
|
|
err.send(self.masterq)
|
2011-01-27 01:19:48 +00:00
|
|
|
# end nocover
|
2011-01-25 02:02:48 +00:00
|
|
|
|
|
|
|
|
2011-02-20 19:47:19 +00:00
|
|
|
class ServerPlaybackState:
|
|
|
|
def __init__(self):
|
|
|
|
self.fmap = {}
|
|
|
|
|
2011-02-20 22:40:49 +00:00
|
|
|
def count(self):
|
2011-02-20 19:47:19 +00:00
|
|
|
return sum([len(i) for i in self.fmap.values()])
|
|
|
|
|
|
|
|
def load(self, flows):
|
|
|
|
"""
|
|
|
|
Load a sequence of flows. We assume that the sequence is in
|
|
|
|
chronological order.
|
|
|
|
"""
|
|
|
|
for i in flows:
|
2011-02-20 22:08:35 +00:00
|
|
|
if i.response:
|
|
|
|
h = self._hash(i)
|
|
|
|
l = self.fmap.setdefault(self._hash(i), [])
|
|
|
|
l.append(i)
|
2011-02-20 19:47:19 +00:00
|
|
|
|
|
|
|
def _hash(self, flow):
|
|
|
|
"""
|
|
|
|
Calculates a loose hash of the flow request.
|
|
|
|
"""
|
|
|
|
r = flow.request
|
|
|
|
key = [
|
|
|
|
str(r.host),
|
|
|
|
str(r.port),
|
|
|
|
str(r.scheme),
|
|
|
|
str(r.method),
|
|
|
|
str(r.path),
|
|
|
|
str(r.content),
|
|
|
|
]
|
|
|
|
return hashlib.sha256(repr(key)).digest()
|
|
|
|
|
|
|
|
def next_flow(self, request):
|
|
|
|
"""
|
|
|
|
Returns the next flow object, or None if no matching flow was
|
|
|
|
found.
|
|
|
|
"""
|
|
|
|
l = self.fmap.get(self._hash(request))
|
|
|
|
if not l:
|
|
|
|
return None
|
|
|
|
return l.pop(0)
|
|
|
|
|
|
|
|
|
2011-01-25 02:02:48 +00:00
|
|
|
class Flow:
|
2011-02-19 04:00:24 +00:00
|
|
|
def __init__(self, request):
|
|
|
|
self.request = request
|
|
|
|
self.response, self.error = None, None
|
2011-01-25 02:02:48 +00:00
|
|
|
self.intercepting = False
|
|
|
|
self._backup = None
|
|
|
|
|
2011-01-31 00:26:56 +00:00
|
|
|
def script_serialize(self):
|
|
|
|
data = self.get_state()
|
2011-02-16 02:10:00 +00:00
|
|
|
return json.dumps(data)
|
2011-01-31 00:26:56 +00:00
|
|
|
|
|
|
|
@classmethod
|
|
|
|
def script_deserialize(klass, data):
|
|
|
|
try:
|
2011-02-16 02:10:00 +00:00
|
|
|
data = json.loads(data)
|
2011-01-31 00:26:56 +00:00
|
|
|
except Exception:
|
|
|
|
return None
|
|
|
|
return klass.from_state(data)
|
|
|
|
|
|
|
|
def run_script(self, path):
|
2011-01-30 22:44:52 +00:00
|
|
|
"""
|
2011-02-01 21:08:24 +00:00
|
|
|
Run a script on a flow.
|
2011-01-31 00:26:56 +00:00
|
|
|
|
2011-02-01 21:08:24 +00:00
|
|
|
Returns a (flow, stderr output) tuple, or raises RunException if
|
|
|
|
there's an error.
|
2011-01-30 22:44:52 +00:00
|
|
|
"""
|
2011-02-01 22:44:28 +00:00
|
|
|
self.backup()
|
2011-01-31 00:26:56 +00:00
|
|
|
data = self.script_serialize()
|
|
|
|
try:
|
2011-02-01 21:08:24 +00:00
|
|
|
p = subprocess.Popen(
|
|
|
|
[path],
|
|
|
|
stdout=subprocess.PIPE,
|
|
|
|
stdin=subprocess.PIPE,
|
|
|
|
stderr=subprocess.PIPE,
|
|
|
|
)
|
2011-01-31 00:26:56 +00:00
|
|
|
except OSError, e:
|
2011-02-01 22:44:28 +00:00
|
|
|
raise RunException(e.args[1], None, None)
|
2011-01-31 00:26:56 +00:00
|
|
|
so, se = p.communicate(data)
|
|
|
|
if p.returncode:
|
2011-02-01 22:44:28 +00:00
|
|
|
raise RunException(
|
|
|
|
"Script returned error code %s"%p.returncode,
|
|
|
|
p.returncode,
|
|
|
|
se
|
|
|
|
)
|
2011-01-31 00:26:56 +00:00
|
|
|
f = Flow.script_deserialize(so)
|
|
|
|
if not f:
|
2011-02-01 22:44:28 +00:00
|
|
|
raise RunException(
|
|
|
|
"Invalid response from script.",
|
|
|
|
p.returncode,
|
|
|
|
se
|
|
|
|
)
|
2011-02-17 23:40:45 +00:00
|
|
|
self.load_state(f.get_state())
|
|
|
|
return se
|
2011-01-30 22:44:52 +00:00
|
|
|
|
2011-02-05 21:28:43 +00:00
|
|
|
def get_state(self, nobackup=False):
|
|
|
|
d = dict(
|
2011-01-26 01:52:03 +00:00
|
|
|
request = self.request.get_state() if self.request else None,
|
|
|
|
response = self.response.get_state() if self.response else None,
|
|
|
|
error = self.error.get_state() if self.error else None,
|
|
|
|
)
|
2011-02-05 21:28:43 +00:00
|
|
|
if nobackup:
|
|
|
|
d["backup"] = None
|
|
|
|
else:
|
|
|
|
d["backup"] = self._backup
|
|
|
|
return d
|
2011-01-26 01:52:03 +00:00
|
|
|
|
2011-01-31 00:26:56 +00:00
|
|
|
def load_state(self, state):
|
2011-02-05 21:28:43 +00:00
|
|
|
self._backup = state["backup"]
|
2011-02-19 20:36:13 +00:00
|
|
|
if self.request:
|
|
|
|
self.request.load_state(state["request"])
|
|
|
|
else:
|
|
|
|
self.request = proxy.Request.from_state(state["request"])
|
|
|
|
|
2011-01-26 01:52:03 +00:00
|
|
|
if state["response"]:
|
2011-02-19 20:36:13 +00:00
|
|
|
if self.response:
|
|
|
|
self.response.load_state(state["response"])
|
|
|
|
else:
|
|
|
|
self.response = proxy.Response.from_state(self.request, state["response"])
|
|
|
|
else:
|
|
|
|
self.response = None
|
|
|
|
|
2011-01-26 01:52:03 +00:00
|
|
|
if state["error"]:
|
2011-02-19 20:36:13 +00:00
|
|
|
if self.error:
|
|
|
|
self.error.load_state(state["error"])
|
|
|
|
else:
|
|
|
|
self.error = proxy.Error.from_state(state["error"])
|
|
|
|
else:
|
|
|
|
self.error = None
|
2011-01-31 00:26:56 +00:00
|
|
|
|
|
|
|
@classmethod
|
|
|
|
def from_state(klass, state):
|
|
|
|
f = klass(None)
|
|
|
|
f.load_state(state)
|
2011-01-26 01:52:03 +00:00
|
|
|
return f
|
|
|
|
|
|
|
|
def __eq__(self, other):
|
|
|
|
return self.get_state() == other.get_state()
|
|
|
|
|
2011-02-01 22:44:28 +00:00
|
|
|
def modified(self):
|
|
|
|
# FIXME: Save a serialization in backup, compare current with
|
|
|
|
# backup to detect if flow has _really_ been modified.
|
|
|
|
if self._backup:
|
|
|
|
return True
|
|
|
|
else:
|
|
|
|
return False
|
|
|
|
|
2011-01-25 02:02:48 +00:00
|
|
|
def backup(self):
|
2011-02-05 21:28:43 +00:00
|
|
|
self._backup = self.get_state(nobackup=True)
|
2011-01-25 02:02:48 +00:00
|
|
|
|
|
|
|
def revert(self):
|
|
|
|
if self._backup:
|
2011-02-05 21:28:43 +00:00
|
|
|
self.load_state(self._backup)
|
2011-02-01 22:44:28 +00:00
|
|
|
self._backup = None
|
2011-01-25 02:02:48 +00:00
|
|
|
|
|
|
|
def match(self, pattern):
|
|
|
|
if pattern:
|
|
|
|
if self.response:
|
|
|
|
return pattern(self.response)
|
|
|
|
elif self.request:
|
|
|
|
return pattern(self.request)
|
|
|
|
return False
|
|
|
|
|
|
|
|
def kill(self):
|
2011-01-27 00:32:24 +00:00
|
|
|
if self.request and not self.request.acked:
|
2011-02-03 22:39:28 +00:00
|
|
|
self.request.ack(None)
|
2011-01-27 00:32:24 +00:00
|
|
|
elif self.response and not self.response.acked:
|
2011-02-03 22:39:28 +00:00
|
|
|
self.response.ack(None)
|
2011-01-27 00:32:24 +00:00
|
|
|
self.intercepting = False
|
2011-01-25 02:02:48 +00:00
|
|
|
|
|
|
|
def intercept(self):
|
|
|
|
self.intercepting = True
|
|
|
|
|
|
|
|
def accept_intercept(self):
|
|
|
|
if self.request:
|
|
|
|
if not self.request.acked:
|
|
|
|
self.request.ack()
|
|
|
|
elif self.response and not self.response.acked:
|
|
|
|
self.response.ack()
|
|
|
|
self.intercepting = False
|
|
|
|
|
|
|
|
|
|
|
|
class State:
|
|
|
|
def __init__(self):
|
2011-02-19 04:00:24 +00:00
|
|
|
self.client_connections = []
|
2011-01-25 02:02:48 +00:00
|
|
|
self.flow_map = {}
|
|
|
|
self.flow_list = []
|
2011-02-19 04:00:24 +00:00
|
|
|
|
2011-01-25 02:02:48 +00:00
|
|
|
# These are compiled filt expressions:
|
|
|
|
self.limit = None
|
|
|
|
self.intercept = None
|
|
|
|
|
2011-02-19 04:00:24 +00:00
|
|
|
def clientconnect(self, cc):
|
|
|
|
self.client_connections.append(cc)
|
|
|
|
|
|
|
|
def clientdisconnect(self, dc):
|
2011-01-25 02:02:48 +00:00
|
|
|
"""
|
|
|
|
Start a browser connection.
|
|
|
|
"""
|
2011-02-19 04:00:24 +00:00
|
|
|
self.client_connections.remove(dc.client_conn)
|
2011-01-25 02:02:48 +00:00
|
|
|
|
|
|
|
def add_request(self, req):
|
|
|
|
"""
|
|
|
|
Add a request to the state. Returns the matching flow.
|
|
|
|
"""
|
2011-02-19 04:00:24 +00:00
|
|
|
f = Flow(req)
|
|
|
|
self.flow_list.insert(0, f)
|
|
|
|
self.flow_map[req] = f
|
2011-01-25 02:02:48 +00:00
|
|
|
return f
|
|
|
|
|
|
|
|
def add_response(self, resp):
|
|
|
|
"""
|
|
|
|
Add a response to the state. Returns the matching flow.
|
|
|
|
"""
|
2011-02-19 04:00:24 +00:00
|
|
|
f = self.flow_map.get(resp.request)
|
2011-01-25 02:02:48 +00:00
|
|
|
if not f:
|
|
|
|
return False
|
|
|
|
f.response = resp
|
|
|
|
return f
|
|
|
|
|
|
|
|
def add_error(self, err):
|
|
|
|
"""
|
|
|
|
Add an error response to the state. Returns the matching flow, or
|
|
|
|
None if there isn't one.
|
|
|
|
"""
|
2011-02-20 00:29:41 +00:00
|
|
|
f = self.flow_map.get(err.request) if err.request else None
|
2011-01-25 02:02:48 +00:00
|
|
|
if not f:
|
|
|
|
return None
|
|
|
|
f.error = err
|
|
|
|
return f
|
|
|
|
|
2011-02-16 02:10:00 +00:00
|
|
|
def load_flows(self, flows):
|
|
|
|
self.flow_list.extend(flows)
|
|
|
|
for i in flows:
|
2011-02-19 04:00:24 +00:00
|
|
|
self.flow_map[i.request] = i
|
2011-01-26 03:50:17 +00:00
|
|
|
|
2011-01-25 02:02:48 +00:00
|
|
|
def set_limit(self, limit):
|
|
|
|
"""
|
|
|
|
Limit is a compiled filter expression, or None.
|
|
|
|
"""
|
|
|
|
self.limit = limit
|
|
|
|
|
2011-01-26 03:50:17 +00:00
|
|
|
@property
|
|
|
|
def view(self):
|
|
|
|
if self.limit:
|
|
|
|
return tuple([i for i in self.flow_list if i.match(self.limit)])
|
|
|
|
else:
|
|
|
|
return tuple(self.flow_list[:])
|
|
|
|
|
2011-01-25 02:02:48 +00:00
|
|
|
def delete_flow(self, f):
|
|
|
|
if not f.intercepting:
|
2011-02-19 04:00:24 +00:00
|
|
|
if f.request in self.flow_map:
|
|
|
|
del self.flow_map[f.request]
|
2011-01-25 02:02:48 +00:00
|
|
|
self.flow_list.remove(f)
|
|
|
|
return True
|
|
|
|
return False
|
|
|
|
|
|
|
|
def clear(self):
|
|
|
|
for i in self.flow_list[:]:
|
|
|
|
self.delete_flow(i)
|
|
|
|
|
|
|
|
def accept_all(self):
|
|
|
|
for i in self.flow_list[:]:
|
|
|
|
i.accept_intercept()
|
|
|
|
|
|
|
|
def kill_flow(self, f):
|
|
|
|
f.kill()
|
|
|
|
self.delete_flow(f)
|
|
|
|
|
|
|
|
def revert(self, f):
|
|
|
|
f.revert()
|
|
|
|
|
2011-02-20 19:47:19 +00:00
|
|
|
def replay_request(self, f, masterq):
|
2011-01-25 02:02:48 +00:00
|
|
|
"""
|
|
|
|
Returns None if successful, or error message if not.
|
|
|
|
"""
|
|
|
|
#begin nocover
|
|
|
|
if f.intercepting:
|
|
|
|
return "Can't replay while intercepting..."
|
|
|
|
if f.request:
|
|
|
|
f.backup()
|
2011-02-19 04:00:24 +00:00
|
|
|
f.request.set_replay()
|
2011-01-25 02:02:48 +00:00
|
|
|
if f.request.content:
|
|
|
|
f.request.headers["content-length"] = [str(len(f.request.content))]
|
|
|
|
f.response = None
|
|
|
|
f.error = None
|
2011-02-20 19:47:19 +00:00
|
|
|
rt = RequestReplayThread(f, masterq)
|
2011-01-25 02:02:48 +00:00
|
|
|
rt.start()
|
|
|
|
#end nocover
|
2011-02-16 01:33:04 +00:00
|
|
|
|
|
|
|
|
2011-02-16 03:03:22 +00:00
|
|
|
class FlowMaster(controller.Master):
|
|
|
|
def __init__(self, server, state):
|
|
|
|
controller.Master.__init__(self, server)
|
|
|
|
self.state = state
|
2011-02-20 22:40:49 +00:00
|
|
|
self.playback = None
|
|
|
|
self.scripts = {}
|
|
|
|
self.kill_nonreplay = False
|
2011-02-20 20:54:39 +00:00
|
|
|
|
2011-02-20 22:40:49 +00:00
|
|
|
def _runscript(self, f, script):
|
|
|
|
return f.run_script(script)
|
2011-02-20 20:54:39 +00:00
|
|
|
|
2011-02-20 22:40:49 +00:00
|
|
|
def set_response_script(self, s):
|
|
|
|
self.scripts["response"] = s
|
|
|
|
|
|
|
|
def set_request_script(self, s):
|
|
|
|
self.scripts["request"] = s
|
|
|
|
|
|
|
|
def start_playback(self, flows, kill):
|
|
|
|
"""
|
|
|
|
flows: A list of flows.
|
|
|
|
kill: Boolean, should we kill requests not part of the replay?
|
|
|
|
"""
|
|
|
|
self.playback = ServerPlaybackState()
|
|
|
|
self.playback.load(flows)
|
|
|
|
self.kill_nonreplay = kill
|
|
|
|
|
|
|
|
def do_playback(self, flow):
|
2011-02-20 20:54:39 +00:00
|
|
|
"""
|
|
|
|
This method should be called by child classes in the handle_request
|
|
|
|
handler. Returns True if playback has taken place, None if not.
|
|
|
|
"""
|
2011-02-20 22:40:49 +00:00
|
|
|
if self.playback:
|
|
|
|
rflow = self.playback.next_flow(flow)
|
2011-02-20 20:54:39 +00:00
|
|
|
if not rflow:
|
|
|
|
return None
|
|
|
|
response = proxy.Response.from_state(flow.request, rflow.response.get_state())
|
|
|
|
response.set_replay()
|
|
|
|
flow.response = response
|
|
|
|
flow.request.ack(response)
|
|
|
|
return True
|
|
|
|
return None
|
2011-02-16 03:03:22 +00:00
|
|
|
|
2011-02-19 04:00:24 +00:00
|
|
|
def handle_clientconnect(self, r):
|
|
|
|
self.state.clientconnect(r)
|
|
|
|
r.ack()
|
|
|
|
|
|
|
|
def handle_clientdisconnect(self, r):
|
|
|
|
self.state.clientdisconnect(r)
|
2011-02-16 03:03:22 +00:00
|
|
|
r.ack()
|
|
|
|
|
|
|
|
def handle_error(self, r):
|
|
|
|
f = self.state.add_error(r)
|
2011-02-19 04:21:08 +00:00
|
|
|
r.ack()
|
2011-02-16 03:03:22 +00:00
|
|
|
return f
|
|
|
|
|
|
|
|
def handle_request(self, r):
|
2011-02-20 22:40:49 +00:00
|
|
|
f = self.state.add_request(r)
|
|
|
|
if "request" in self.scripts:
|
|
|
|
self._runscript(f, self.scripts["request"])
|
|
|
|
if self.playback:
|
|
|
|
pb = self.do_playback(f)
|
|
|
|
if not pb:
|
|
|
|
if self.kill_nonreplay:
|
|
|
|
self.state.kill_flow(f)
|
|
|
|
else:
|
|
|
|
r.ack()
|
|
|
|
return f
|
2011-02-16 03:03:22 +00:00
|
|
|
|
|
|
|
def handle_response(self, r):
|
|
|
|
f = self.state.add_response(r)
|
|
|
|
if not f:
|
|
|
|
r.ack()
|
2011-02-20 22:40:49 +00:00
|
|
|
if "response" in self.scripts:
|
|
|
|
self._runscript(f, self.scripts["response"])
|
2011-02-16 03:43:35 +00:00
|
|
|
return f
|
2011-02-16 03:03:22 +00:00
|
|
|
|
2011-02-16 01:33:04 +00:00
|
|
|
|
|
|
|
class FlowWriter:
|
|
|
|
def __init__(self, fo):
|
|
|
|
self.fo = fo
|
|
|
|
self.ns = netstring.FileEncoder(fo)
|
|
|
|
|
|
|
|
def add(self, flow):
|
|
|
|
d = flow.get_state()
|
|
|
|
s = json.dumps(d)
|
|
|
|
self.ns.write(s)
|
|
|
|
|
|
|
|
|
|
|
|
class FlowReader:
|
|
|
|
def __init__(self, fo):
|
|
|
|
self.fo = fo
|
|
|
|
self.ns = netstring.decode_file(fo)
|
|
|
|
|
|
|
|
def stream(self):
|
|
|
|
"""
|
|
|
|
Yields Flow objects from the dump.
|
|
|
|
"""
|
|
|
|
for i in self.ns:
|
|
|
|
data = json.loads(i)
|
|
|
|
yield Flow.from_state(data)
|
|
|
|
|