consider IP address protected only if it is used for the chosen host

This commit is contained in:
Evgeny @ SimpleX Chat
2026-09-29 19:52:51 +00:00
parent 551a79d99b
commit 0ac5b1808d
3 changed files with 36 additions and 10 deletions
+3 -2
View File
@@ -1261,9 +1261,10 @@ sendOrProxySMPCommand c nm userId destSrv@ProtocolServer {host = destHosts} conn
Left e -> throwE e
ipAddressProtected :: NetworkConfig -> ProtocolServer p -> Bool
ipAddressProtected NetworkConfig {socksProxy, hostMode} (ProtocolServer _ hosts _ _) = do
isJust socksProxy || (hostMode == HMOnion && any isOnionHost hosts)
ipAddressProtected cfg@NetworkConfig {socksProxy, hostMode} (ProtocolServer _ hosts _ _) =
either (const $ isJust socksProxy) protected $ chooseTransportHost cfg hosts
where
protected h = isJust (useSocksProxy cfg h) || (hostMode == HMOnion && isOnionHost h)
isOnionHost = \case THOnionHost _ -> True; _ -> False
withNtfClient :: AgentClient -> NetworkRequestMode -> NtfServer -> EntityId -> ByteString -> (NtfClient -> ExceptT NtfClientError IO a) -> AM a
+12 -7
View File
@@ -102,6 +102,7 @@ module Simplex.Messaging.Client
defaultSMPClientConfig,
defaultNetworkConfig,
transportClientConfig,
useSocksProxy,
clientSocksCredentials,
chooseTransportHost,
temporaryClientError,
@@ -170,7 +171,7 @@ import Simplex.Messaging.SimplexName (SimplexDomain, fullDomainName)
import Simplex.Messaging.TMap (TMap)
import qualified Simplex.Messaging.TMap as TM
import Simplex.Messaging.Transport
import Simplex.Messaging.Transport.Client (SocksAuth (..), SocksProxyWithAuth (..), TransportClientConfig (..), TransportHost (..), defaultSMPPort, runTransportClient)
import Simplex.Messaging.Transport.Client (SocksAuth (..), SocksProxy, SocksProxyWithAuth (..), TransportClientConfig (..), TransportHost (..), defaultSMPPort, runTransportClient)
import Simplex.Messaging.Transport.HTTP2 (httpALPN11)
import Simplex.Messaging.Transport.KeepAlive
import Simplex.Messaging.Transport.Shared (ChainCertificates (..), chainIdCaCerts, x509validate)
@@ -439,15 +440,19 @@ defaultNetworkConfig =
}
transportClientConfig :: NetworkConfig -> NetworkRequestMode -> TransportHost -> Bool -> Maybe [ALPN] -> TransportClientConfig
transportClientConfig NetworkConfig {socksProxy, socksMode, tcpConnectTimeout, tcpKeepAlive, logTLSErrors} nm host useSNI clientALPN =
TransportClientConfig {socksProxy = useSocksProxy socksMode, tcpConnectTimeout = tOut, tcpKeepAlive, logTLSErrors, clientCredentials = Nothing, clientALPN, useSNI}
transportClientConfig cfg@NetworkConfig {tcpConnectTimeout, tcpKeepAlive, logTLSErrors} nm host useSNI clientALPN =
TransportClientConfig {socksProxy = useSocksProxy cfg host, tcpConnectTimeout = tOut, tcpKeepAlive, logTLSErrors, clientCredentials = Nothing, clientALPN, useSNI}
where
tOut = netTimeoutInt tcpConnectTimeout nm
useSocksProxy :: NetworkConfig -> TransportHost -> Maybe SocksProxy
useSocksProxy NetworkConfig {socksProxy, socksMode} host = case socksMode of
SMAlways -> socksProxy'
SMOnion -> case host of
THOnionHost _ -> socksProxy'
_ -> Nothing
where
socksProxy' = (\(SocksProxyWithAuth _ proxy) -> proxy) <$> socksProxy
useSocksProxy SMAlways = socksProxy'
useSocksProxy SMOnion = case host of
THOnionHost _ -> socksProxy'
_ -> Nothing
clientSocksCredentials :: ProtocolTypeI (ProtoType msg) => NetworkConfig -> UTCTime -> TransportSession msg -> Maybe SocksCredentials
clientSocksCredentials NetworkConfig {socksProxy, sessionMode} proxySessTs (userId, srv, entityId_) = case socksProxy of
+21 -1
View File
@@ -2,15 +2,18 @@
{-# LANGUAGE NamedFieldPuns #-}
{-# LANGUAGE OverloadedLists #-}
{-# LANGUAGE OverloadedStrings #-}
{-# LANGUAGE PatternSynonyms #-}
{-# LANGUAGE TypeApplications #-}
{-# OPTIONS_GHC -fno-warn-ambiguous-fields #-}
module CoreTests.SOCKSSettings where
import Network.Socket (SockAddr (..), tupleToHostAddress)
import Simplex.Messaging.Agent.Client (ipAddressProtected)
import Simplex.Messaging.Client
import qualified Simplex.Messaging.Crypto as C
import Simplex.Messaging.Encoding.String
import Simplex.Messaging.Protocol (ErrorType)
import Simplex.Messaging.Protocol (ErrorType, pattern SMPServer)
import Simplex.Messaging.Transport.Client
import Test.Hspec hiding (fit, it)
import Util
@@ -19,6 +22,7 @@ socksSettingsTests :: Spec
socksSettingsTests = do
describe "hostMode and requiredHostMode settings" testHostMode
describe "socksMode setting, independent of hostMode setting" testSocksMode
describe "ipAddressProtected, consistent with chosen host and socksMode" testIPAddressProtected
describe "socks proxy address encoding" testSocksProxyEncoding
testPublicHost :: TransportHost
@@ -94,6 +98,22 @@ testSocksMode = do
let TransportClientConfig {socksProxy} = transportClientConfig cfg NRMInteractive host False Nothing
in socksProxy
testIPAddressProtected :: Spec
testIPAddressProtected = do
it "should be protected if SOCKS proxy is used for the chosen host" $ do
protected SMAlways HMOnionViaSocks [testPublicHost] `shouldBe` True
protected SMOnion HMOnionViaSocks [testPublicHost, testOnionHost] `shouldBe` True
protected SMOnion HMPublic [testOnionHost] `shouldBe` True
it "should not be protected if SOCKS proxy is not used for the chosen host" $ do
protected SMOnion HMOnionViaSocks [testPublicHost] `shouldBe` False
protected SMOnion HMPublic [testPublicHost, testOnionHost] `shouldBe` False
it "should be protected if SOCKS proxy is specified and required host is not available" $ do
protectedCfg defaultNetworkConfig {requiredHostMode = True} SMOnion HMOnionViaSocks [testPublicHost] `shouldBe` True
where
protected = protectedCfg defaultNetworkConfig
protectedCfg cfg socksMode hostMode hosts =
ipAddressProtected cfg {socksProxy = Just defaultSocksProxyWithAuth, socksMode, hostMode} (SMPServer hosts "" (C.KeyHash ""))
testSocksProxyEncoding :: Spec
testSocksProxyEncoding = do
it "should decode SOCKS proxy with isolate-by-auth mode" $ do