From e11dfb985dc725c91c4ef47cfe74d5078f08c989 Mon Sep 17 00:00:00 2001 From: Evgeny Date: Sat, 3 Oct 2026 22:45:44 +0100 Subject: [PATCH] consider IP address protected only if it is used for the chosen host (#1895) * consider IP address protected only if it is used for the chosen host * simplify * simplify * simplify --------- Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com> --- src/Simplex/Messaging/Agent/Client.hs | 7 +++++-- tests/CoreTests/SOCKSSettings.hs | 19 ++++++++++++++++++- 2 files changed, 23 insertions(+), 3 deletions(-) diff --git a/src/Simplex/Messaging/Agent/Client.hs b/src/Simplex/Messaging/Agent/Client.hs index 8cbb4c17b..453acf106 100644 --- a/src/Simplex/Messaging/Agent/Client.hs +++ b/src/Simplex/Messaging/Agent/Client.hs @@ -1261,9 +1261,12 @@ sendOrProxySMPCommand c nm userId destSrv@ProtocolServer {host = destHosts} conn Left e -> throwE e ipAddressProtected :: NetworkConfig -> ProtocolServer p -> Bool -ipAddressProtected NetworkConfig {socksProxy, hostMode} (ProtocolServer _ hosts _ _) = do - isJust socksProxy || (hostMode == HMOnion && any isOnionHost hosts) +ipAddressProtected NetworkConfig {socksProxy, socksMode, hostMode} (ProtocolServer _ hosts _ _) + | isJust socksProxy = socksMode == SMAlways || if hostMode == HMPublic then allOnion else anyOnion + | otherwise = hostMode == HMOnion && anyOnion where + anyOnion = any isOnionHost hosts + allOnion = all isOnionHost hosts isOnionHost = \case THOnionHost _ -> True; _ -> False withNtfClient :: AgentClient -> NetworkRequestMode -> NtfServer -> EntityId -> ByteString -> (NtfClient -> ExceptT NtfClientError IO a) -> AM a diff --git a/tests/CoreTests/SOCKSSettings.hs b/tests/CoreTests/SOCKSSettings.hs index 3dbf5e5e7..a56be966e 100644 --- a/tests/CoreTests/SOCKSSettings.hs +++ b/tests/CoreTests/SOCKSSettings.hs @@ -2,15 +2,18 @@ {-# LANGUAGE NamedFieldPuns #-} {-# LANGUAGE OverloadedLists #-} {-# LANGUAGE OverloadedStrings #-} +{-# LANGUAGE PatternSynonyms #-} {-# LANGUAGE TypeApplications #-} {-# OPTIONS_GHC -fno-warn-ambiguous-fields #-} module CoreTests.SOCKSSettings where import Network.Socket (SockAddr (..), tupleToHostAddress) +import Simplex.Messaging.Agent.Client (ipAddressProtected) import Simplex.Messaging.Client +import qualified Simplex.Messaging.Crypto as C import Simplex.Messaging.Encoding.String -import Simplex.Messaging.Protocol (ErrorType) +import Simplex.Messaging.Protocol (ErrorType, pattern SMPServer) import Simplex.Messaging.Transport.Client import Test.Hspec hiding (fit, it) import Util @@ -19,6 +22,7 @@ socksSettingsTests :: Spec socksSettingsTests = do describe "hostMode and requiredHostMode settings" testHostMode describe "socksMode setting, independent of hostMode setting" testSocksMode + describe "ipAddressProtected, consistent with chosen host and socksMode" testIPAddressProtected describe "socks proxy address encoding" testSocksProxyEncoding testPublicHost :: TransportHost @@ -94,6 +98,19 @@ testSocksMode = do let TransportClientConfig {socksProxy} = transportClientConfig cfg NRMInteractive host False Nothing in socksProxy +testIPAddressProtected :: Spec +testIPAddressProtected = do + it "should be protected if SOCKS proxy is used for the chosen host" $ do + protected SMAlways HMOnionViaSocks [testPublicHost] `shouldBe` True + protected SMOnion HMOnionViaSocks [testPublicHost, testOnionHost] `shouldBe` True + protected SMOnion HMPublic [testOnionHost] `shouldBe` True + it "should not be protected if SOCKS proxy is not used for the chosen host" $ do + protected SMOnion HMOnionViaSocks [testPublicHost] `shouldBe` False + protected SMOnion HMPublic [testPublicHost, testOnionHost] `shouldBe` False + where + protected socksMode hostMode hosts = + ipAddressProtected defaultNetworkConfig {socksProxy = Just defaultSocksProxyWithAuth, socksMode, hostMode} (SMPServer hosts "" (C.KeyHash "")) + testSocksProxyEncoding :: Spec testSocksProxyEncoding = do it "should decode SOCKS proxy with isolate-by-auth mode" $ do