root / lib / http / __init__.py @ 29b8eaee
History | View | Annotate | Download (27.8 kB)
1 | a43f68dc | Michael Hanselmann | #
|
---|---|---|---|
2 | a43f68dc | Michael Hanselmann | #
|
3 | 4ce6007f | Michael Hanselmann | |
4 | db4e138b | Manuel Franceschini | # Copyright (C) 2007, 2008, 2010 Google Inc.
|
5 | 4ce6007f | Michael Hanselmann | #
|
6 | a43f68dc | Michael Hanselmann | # This program is free software; you can redistribute it and/or modify
|
7 | a43f68dc | Michael Hanselmann | # it under the terms of the GNU General Public License as published by
|
8 | a43f68dc | Michael Hanselmann | # the Free Software Foundation; either version 2 of the License, or
|
9 | a43f68dc | Michael Hanselmann | # (at your option) any later version.
|
10 | a43f68dc | Michael Hanselmann | #
|
11 | a43f68dc | Michael Hanselmann | # This program is distributed in the hope that it will be useful, but
|
12 | a43f68dc | Michael Hanselmann | # WITHOUT ANY WARRANTY; without even the implied warranty of
|
13 | a43f68dc | Michael Hanselmann | # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
14 | a43f68dc | Michael Hanselmann | # General Public License for more details.
|
15 | a43f68dc | Michael Hanselmann | #
|
16 | a43f68dc | Michael Hanselmann | # You should have received a copy of the GNU General Public License
|
17 | a43f68dc | Michael Hanselmann | # along with this program; if not, write to the Free Software
|
18 | a43f68dc | Michael Hanselmann | # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
19 | a43f68dc | Michael Hanselmann | # 02110-1301, USA.
|
20 | a43f68dc | Michael Hanselmann | |
21 | 02cab3e7 | Michael Hanselmann | """HTTP module.
|
22 | a43f68dc | Michael Hanselmann |
|
23 | a43f68dc | Michael Hanselmann | """
|
24 | a43f68dc | Michael Hanselmann | |
25 | 42242313 | Michael Hanselmann | import logging |
26 | 42242313 | Michael Hanselmann | import mimetools |
27 | a43f68dc | Michael Hanselmann | import OpenSSL |
28 | 42242313 | Michael Hanselmann | import select |
29 | 42242313 | Michael Hanselmann | import socket |
30 | 8a0b06d2 | Michael Hanselmann | import errno |
31 | 8a0b06d2 | Michael Hanselmann | |
32 | 8a0b06d2 | Michael Hanselmann | from cStringIO import StringIO |
33 | a43f68dc | Michael Hanselmann | |
34 | 42242313 | Michael Hanselmann | from ganeti import constants |
35 | f2a6fc9e | Michael Hanselmann | from ganeti import utils |
36 | a43f68dc | Michael Hanselmann | |
37 | a43f68dc | Michael Hanselmann | |
38 | 8a9f9060 | Michael Hanselmann | HTTP_GANETI_VERSION = "Ganeti %s" % constants.RELEASE_VERSION
|
39 | 8a9f9060 | Michael Hanselmann | |
40 | 42242313 | Michael Hanselmann | HTTP_OK = 200
|
41 | 42242313 | Michael Hanselmann | HTTP_NO_CONTENT = 204
|
42 | 42242313 | Michael Hanselmann | HTTP_NOT_MODIFIED = 304
|
43 | 42242313 | Michael Hanselmann | |
44 | 42242313 | Michael Hanselmann | HTTP_0_9 = "HTTP/0.9"
|
45 | 42242313 | Michael Hanselmann | HTTP_1_0 = "HTTP/1.0"
|
46 | 42242313 | Michael Hanselmann | HTTP_1_1 = "HTTP/1.1"
|
47 | 42242313 | Michael Hanselmann | |
48 | 42242313 | Michael Hanselmann | HTTP_GET = "GET"
|
49 | 42242313 | Michael Hanselmann | HTTP_HEAD = "HEAD"
|
50 | 8a9f9060 | Michael Hanselmann | HTTP_POST = "POST"
|
51 | 8a9f9060 | Michael Hanselmann | HTTP_PUT = "PUT"
|
52 | 99b5ef90 | Michael Hanselmann | HTTP_DELETE = "DELETE"
|
53 | 8a9f9060 | Michael Hanselmann | |
54 | 713faea6 | Oleksiy Mishchenko | HTTP_ETAG = "ETag"
|
55 | 8a9f9060 | Michael Hanselmann | HTTP_HOST = "Host"
|
56 | 8a9f9060 | Michael Hanselmann | HTTP_SERVER = "Server"
|
57 | 8a9f9060 | Michael Hanselmann | HTTP_DATE = "Date"
|
58 | 8a9f9060 | Michael Hanselmann | HTTP_USER_AGENT = "User-Agent"
|
59 | 8a9f9060 | Michael Hanselmann | HTTP_CONTENT_TYPE = "Content-Type"
|
60 | 8a9f9060 | Michael Hanselmann | HTTP_CONTENT_LENGTH = "Content-Length"
|
61 | 8a9f9060 | Michael Hanselmann | HTTP_CONNECTION = "Connection"
|
62 | 8a9f9060 | Michael Hanselmann | HTTP_KEEP_ALIVE = "Keep-Alive"
|
63 | b3660886 | Michael Hanselmann | HTTP_WWW_AUTHENTICATE = "WWW-Authenticate"
|
64 | b3660886 | Michael Hanselmann | HTTP_AUTHORIZATION = "Authorization"
|
65 | b3660886 | Michael Hanselmann | HTTP_AUTHENTICATION_INFO = "Authentication-Info"
|
66 | b3660886 | Michael Hanselmann | HTTP_ALLOW = "Allow"
|
67 | 42242313 | Michael Hanselmann | |
68 | 580558a3 | Michael Hanselmann | HTTP_APP_OCTET_STREAM = "application/octet-stream"
|
69 | 16b037a9 | Michael Hanselmann | HTTP_APP_JSON = "application/json"
|
70 | 580558a3 | Michael Hanselmann | |
71 | d7bace1b | Michael Hanselmann | _SSL_UNEXPECTED_EOF = "Unexpected EOF"
|
72 | d7bace1b | Michael Hanselmann | |
73 | 73a59d9e | Michael Hanselmann | # Socket operations
|
74 | 73a59d9e | Michael Hanselmann | (SOCKOP_SEND, |
75 | 73a59d9e | Michael Hanselmann | SOCKOP_RECV, |
76 | d7fa9982 | Michael Hanselmann | SOCKOP_SHUTDOWN, |
77 | d7fa9982 | Michael Hanselmann | SOCKOP_HANDSHAKE) = range(4) |
78 | 73a59d9e | Michael Hanselmann | |
79 | b18dd019 | Iustin Pop | # send/receive quantum
|
80 | b18dd019 | Iustin Pop | SOCK_BUF_SIZE = 32768
|
81 | 42242313 | Michael Hanselmann | |
82 | 13b63666 | Michael Hanselmann | |
83 | 02cab3e7 | Michael Hanselmann | class HttpError(Exception): |
84 | 02cab3e7 | Michael Hanselmann | """Internal exception for HTTP errors.
|
85 | 02cab3e7 | Michael Hanselmann |
|
86 | 02cab3e7 | Michael Hanselmann | This should only be used for internal error reporting.
|
87 | 02cab3e7 | Michael Hanselmann |
|
88 | 02cab3e7 | Michael Hanselmann | """
|
89 | 02cab3e7 | Michael Hanselmann | |
90 | 02cab3e7 | Michael Hanselmann | |
91 | 39cfc25b | Michael Hanselmann | class HttpConnectionClosed(Exception): |
92 | 39cfc25b | Michael Hanselmann | """Internal exception for a closed connection.
|
93 | 39cfc25b | Michael Hanselmann |
|
94 | 39cfc25b | Michael Hanselmann | This should only be used for internal error reporting. Only use
|
95 | 39cfc25b | Michael Hanselmann | it if there's no other way to report this condition.
|
96 | 39cfc25b | Michael Hanselmann |
|
97 | 39cfc25b | Michael Hanselmann | """
|
98 | 39cfc25b | Michael Hanselmann | |
99 | 39cfc25b | Michael Hanselmann | |
100 | d7fa9982 | Michael Hanselmann | class HttpSessionHandshakeUnexpectedEOF(HttpError): |
101 | d7fa9982 | Michael Hanselmann | """Internal exception for errors during SSL handshake.
|
102 | d7fa9982 | Michael Hanselmann |
|
103 | d7fa9982 | Michael Hanselmann | This should only be used for internal error reporting.
|
104 | d7fa9982 | Michael Hanselmann |
|
105 | d7fa9982 | Michael Hanselmann | """
|
106 | d7fa9982 | Michael Hanselmann | |
107 | d7fa9982 | Michael Hanselmann | |
108 | c9d0fa8a | Michael Hanselmann | class HttpSocketTimeout(Exception): |
109 | 73a59d9e | Michael Hanselmann | """Internal exception for socket timeouts.
|
110 | 73a59d9e | Michael Hanselmann |
|
111 | 73a59d9e | Michael Hanselmann | This should only be used for internal error reporting.
|
112 | 73a59d9e | Michael Hanselmann |
|
113 | 73a59d9e | Michael Hanselmann | """
|
114 | 8a0b06d2 | Michael Hanselmann | |
115 | 8a0b06d2 | Michael Hanselmann | |
116 | 84f2756e | Michael Hanselmann | class HttpException(Exception): |
117 | a43f68dc | Michael Hanselmann | code = None
|
118 | a43f68dc | Michael Hanselmann | message = None
|
119 | a43f68dc | Michael Hanselmann | |
120 | a8e01e9f | Michael Hanselmann | def __init__(self, message=None, headers=None): |
121 | 42242313 | Michael Hanselmann | Exception.__init__(self) |
122 | a8e01e9f | Michael Hanselmann | self.message = message
|
123 | a8e01e9f | Michael Hanselmann | self.headers = headers
|
124 | a43f68dc | Michael Hanselmann | |
125 | a43f68dc | Michael Hanselmann | |
126 | 84f2756e | Michael Hanselmann | class HttpBadRequest(HttpException): |
127 | b3660886 | Michael Hanselmann | """400 Bad Request
|
128 | b3660886 | Michael Hanselmann |
|
129 | 25e7b43f | Iustin Pop | RFC2616, 10.4.1: The request could not be understood by the server
|
130 | 25e7b43f | Iustin Pop | due to malformed syntax. The client SHOULD NOT repeat the request
|
131 | 25e7b43f | Iustin Pop | without modifications.
|
132 | b3660886 | Michael Hanselmann |
|
133 | b3660886 | Michael Hanselmann | """
|
134 | a43f68dc | Michael Hanselmann | code = 400
|
135 | a43f68dc | Michael Hanselmann | |
136 | a43f68dc | Michael Hanselmann | |
137 | b3660886 | Michael Hanselmann | class HttpUnauthorized(HttpException): |
138 | b3660886 | Michael Hanselmann | """401 Unauthorized
|
139 | b3660886 | Michael Hanselmann |
|
140 | 25e7b43f | Iustin Pop | RFC2616, section 10.4.2: The request requires user
|
141 | 25e7b43f | Iustin Pop | authentication. The response MUST include a WWW-Authenticate header
|
142 | 25e7b43f | Iustin Pop | field (section 14.47) containing a challenge applicable to the
|
143 | 25e7b43f | Iustin Pop | requested resource.
|
144 | b3660886 | Michael Hanselmann |
|
145 | b3660886 | Michael Hanselmann | """
|
146 | b3660886 | Michael Hanselmann | code = 401
|
147 | b3660886 | Michael Hanselmann | |
148 | b3660886 | Michael Hanselmann | |
149 | 84f2756e | Michael Hanselmann | class HttpForbidden(HttpException): |
150 | b3660886 | Michael Hanselmann | """403 Forbidden
|
151 | b3660886 | Michael Hanselmann |
|
152 | 25e7b43f | Iustin Pop | RFC2616, 10.4.4: The server understood the request, but is refusing
|
153 | 25e7b43f | Iustin Pop | to fulfill it. Authorization will not help and the request SHOULD
|
154 | 25e7b43f | Iustin Pop | NOT be repeated.
|
155 | b3660886 | Michael Hanselmann |
|
156 | b3660886 | Michael Hanselmann | """
|
157 | a43f68dc | Michael Hanselmann | code = 403
|
158 | a43f68dc | Michael Hanselmann | |
159 | a43f68dc | Michael Hanselmann | |
160 | 84f2756e | Michael Hanselmann | class HttpNotFound(HttpException): |
161 | b3660886 | Michael Hanselmann | """404 Not Found
|
162 | b3660886 | Michael Hanselmann |
|
163 | 25e7b43f | Iustin Pop | RFC2616, 10.4.5: The server has not found anything matching the
|
164 | 25e7b43f | Iustin Pop | Request-URI. No indication is given of whether the condition is
|
165 | 25e7b43f | Iustin Pop | temporary or permanent.
|
166 | b3660886 | Michael Hanselmann |
|
167 | b3660886 | Michael Hanselmann | """
|
168 | a43f68dc | Michael Hanselmann | code = 404
|
169 | a43f68dc | Michael Hanselmann | |
170 | a43f68dc | Michael Hanselmann | |
171 | b3660886 | Michael Hanselmann | class HttpMethodNotAllowed(HttpException): |
172 | b3660886 | Michael Hanselmann | """405 Method Not Allowed
|
173 | b3660886 | Michael Hanselmann |
|
174 | 25e7b43f | Iustin Pop | RFC2616, 10.4.6: The method specified in the Request-Line is not
|
175 | 25e7b43f | Iustin Pop | allowed for the resource identified by the Request-URI. The response
|
176 | 25e7b43f | Iustin Pop | MUST include an Allow header containing a list of valid methods for
|
177 | 25e7b43f | Iustin Pop | the requested resource.
|
178 | b3660886 | Michael Hanselmann |
|
179 | b3660886 | Michael Hanselmann | """
|
180 | b3660886 | Michael Hanselmann | code = 405
|
181 | b3660886 | Michael Hanselmann | |
182 | b3660886 | Michael Hanselmann | |
183 | 580558a3 | Michael Hanselmann | class HttpNotAcceptable(HttpException): |
184 | 580558a3 | Michael Hanselmann | """406 Not Acceptable
|
185 | 580558a3 | Michael Hanselmann |
|
186 | 580558a3 | Michael Hanselmann | RFC2616, 10.4.7: The resource identified by the request is only capable of
|
187 | 580558a3 | Michael Hanselmann | generating response entities which have content characteristics not
|
188 | 580558a3 | Michael Hanselmann | acceptable according to the accept headers sent in the request.
|
189 | 580558a3 | Michael Hanselmann |
|
190 | 580558a3 | Michael Hanselmann | """
|
191 | 580558a3 | Michael Hanselmann | code = 406
|
192 | 580558a3 | Michael Hanselmann | |
193 | 580558a3 | Michael Hanselmann | |
194 | b3660886 | Michael Hanselmann | class HttpRequestTimeout(HttpException): |
195 | b3660886 | Michael Hanselmann | """408 Request Timeout
|
196 | b3660886 | Michael Hanselmann |
|
197 | 25e7b43f | Iustin Pop | RFC2616, 10.4.9: The client did not produce a request within the
|
198 | 25e7b43f | Iustin Pop | time that the server was prepared to wait. The client MAY repeat the
|
199 | 25e7b43f | Iustin Pop | request without modifications at any later time.
|
200 | b3660886 | Michael Hanselmann |
|
201 | b3660886 | Michael Hanselmann | """
|
202 | b3660886 | Michael Hanselmann | code = 408
|
203 | b3660886 | Michael Hanselmann | |
204 | b3660886 | Michael Hanselmann | |
205 | b3660886 | Michael Hanselmann | class HttpConflict(HttpException): |
206 | b3660886 | Michael Hanselmann | """409 Conflict
|
207 | b3660886 | Michael Hanselmann |
|
208 | 25e7b43f | Iustin Pop | RFC2616, 10.4.10: The request could not be completed due to a
|
209 | 25e7b43f | Iustin Pop | conflict with the current state of the resource. This code is only
|
210 | 25e7b43f | Iustin Pop | allowed in situations where it is expected that the user might be
|
211 | 25e7b43f | Iustin Pop | able to resolve the conflict and resubmit the request.
|
212 | b3660886 | Michael Hanselmann |
|
213 | b3660886 | Michael Hanselmann | """
|
214 | b3660886 | Michael Hanselmann | code = 409
|
215 | b3660886 | Michael Hanselmann | |
216 | b3660886 | Michael Hanselmann | |
217 | 84f2756e | Michael Hanselmann | class HttpGone(HttpException): |
218 | b3660886 | Michael Hanselmann | """410 Gone
|
219 | b3660886 | Michael Hanselmann |
|
220 | 25e7b43f | Iustin Pop | RFC2616, 10.4.11: The requested resource is no longer available at
|
221 | 25e7b43f | Iustin Pop | the server and no forwarding address is known. This condition is
|
222 | 25e7b43f | Iustin Pop | expected to be considered permanent.
|
223 | b3660886 | Michael Hanselmann |
|
224 | b3660886 | Michael Hanselmann | """
|
225 | a43f68dc | Michael Hanselmann | code = 410
|
226 | a43f68dc | Michael Hanselmann | |
227 | a43f68dc | Michael Hanselmann | |
228 | 84f2756e | Michael Hanselmann | class HttpLengthRequired(HttpException): |
229 | b3660886 | Michael Hanselmann | """411 Length Required
|
230 | b3660886 | Michael Hanselmann |
|
231 | 25e7b43f | Iustin Pop | RFC2616, 10.4.12: The server refuses to accept the request without a
|
232 | 25e7b43f | Iustin Pop | defined Content-Length. The client MAY repeat the request if it adds
|
233 | 25e7b43f | Iustin Pop | a valid Content-Length header field containing the length of the
|
234 | 25e7b43f | Iustin Pop | message-body in the request message.
|
235 | b3660886 | Michael Hanselmann |
|
236 | b3660886 | Michael Hanselmann | """
|
237 | a43f68dc | Michael Hanselmann | code = 411
|
238 | a43f68dc | Michael Hanselmann | |
239 | a43f68dc | Michael Hanselmann | |
240 | b3660886 | Michael Hanselmann | class HttpPreconditionFailed(HttpException): |
241 | b3660886 | Michael Hanselmann | """412 Precondition Failed
|
242 | b3660886 | Michael Hanselmann |
|
243 | 25e7b43f | Iustin Pop | RFC2616, 10.4.13: The precondition given in one or more of the
|
244 | 25e7b43f | Iustin Pop | request-header fields evaluated to false when it was tested on the
|
245 | 25e7b43f | Iustin Pop | server.
|
246 | b3660886 | Michael Hanselmann |
|
247 | b3660886 | Michael Hanselmann | """
|
248 | b3660886 | Michael Hanselmann | code = 412
|
249 | b3660886 | Michael Hanselmann | |
250 | b3660886 | Michael Hanselmann | |
251 | 580558a3 | Michael Hanselmann | class HttpUnsupportedMediaType(HttpException): |
252 | 580558a3 | Michael Hanselmann | """415 Unsupported Media Type
|
253 | 580558a3 | Michael Hanselmann |
|
254 | 580558a3 | Michael Hanselmann | RFC2616, 10.4.16: The server is refusing to service the request because the
|
255 | 580558a3 | Michael Hanselmann | entity of the request is in a format not supported by the requested resource
|
256 | 580558a3 | Michael Hanselmann | for the requested method.
|
257 | 580558a3 | Michael Hanselmann |
|
258 | 580558a3 | Michael Hanselmann | """
|
259 | 580558a3 | Michael Hanselmann | code = 415
|
260 | 580558a3 | Michael Hanselmann | |
261 | 580558a3 | Michael Hanselmann | |
262 | 79589f25 | Michael Hanselmann | class HttpInternalServerError(HttpException): |
263 | b3660886 | Michael Hanselmann | """500 Internal Server Error
|
264 | b3660886 | Michael Hanselmann |
|
265 | 25e7b43f | Iustin Pop | RFC2616, 10.5.1: The server encountered an unexpected condition
|
266 | 25e7b43f | Iustin Pop | which prevented it from fulfilling the request.
|
267 | b3660886 | Michael Hanselmann |
|
268 | b3660886 | Michael Hanselmann | """
|
269 | a43f68dc | Michael Hanselmann | code = 500
|
270 | a43f68dc | Michael Hanselmann | |
271 | a43f68dc | Michael Hanselmann | |
272 | 84f2756e | Michael Hanselmann | class HttpNotImplemented(HttpException): |
273 | b3660886 | Michael Hanselmann | """501 Not Implemented
|
274 | b3660886 | Michael Hanselmann |
|
275 | 25e7b43f | Iustin Pop | RFC2616, 10.5.2: The server does not support the functionality
|
276 | 25e7b43f | Iustin Pop | required to fulfill the request.
|
277 | b3660886 | Michael Hanselmann |
|
278 | b3660886 | Michael Hanselmann | """
|
279 | a43f68dc | Michael Hanselmann | code = 501
|
280 | a43f68dc | Michael Hanselmann | |
281 | a43f68dc | Michael Hanselmann | |
282 | 77e1d753 | Iustin Pop | class HttpBadGateway(HttpException): |
283 | 77e1d753 | Iustin Pop | """502 Bad Gateway
|
284 | 77e1d753 | Iustin Pop |
|
285 | 77e1d753 | Iustin Pop | RFC2616, 10.5.3: The server, while acting as a gateway or proxy,
|
286 | 77e1d753 | Iustin Pop | received an invalid response from the upstream server it accessed in
|
287 | 77e1d753 | Iustin Pop | attempting to fulfill the request.
|
288 | 77e1d753 | Iustin Pop |
|
289 | 77e1d753 | Iustin Pop | """
|
290 | 77e1d753 | Iustin Pop | code = 502
|
291 | 77e1d753 | Iustin Pop | |
292 | 77e1d753 | Iustin Pop | |
293 | 84f2756e | Michael Hanselmann | class HttpServiceUnavailable(HttpException): |
294 | b3660886 | Michael Hanselmann | """503 Service Unavailable
|
295 | b3660886 | Michael Hanselmann |
|
296 | 25e7b43f | Iustin Pop | RFC2616, 10.5.4: The server is currently unable to handle the
|
297 | 25e7b43f | Iustin Pop | request due to a temporary overloading or maintenance of the server.
|
298 | b3660886 | Michael Hanselmann |
|
299 | b3660886 | Michael Hanselmann | """
|
300 | a43f68dc | Michael Hanselmann | code = 503
|
301 | a43f68dc | Michael Hanselmann | |
302 | a43f68dc | Michael Hanselmann | |
303 | 77e1d753 | Iustin Pop | class HttpGatewayTimeout(HttpException): |
304 | 77e1d753 | Iustin Pop | """504 Gateway Timeout
|
305 | 77e1d753 | Iustin Pop |
|
306 | 77e1d753 | Iustin Pop | RFC2616, 10.5.5: The server, while acting as a gateway or proxy, did
|
307 | 77e1d753 | Iustin Pop | not receive a timely response from the upstream server specified by
|
308 | 77e1d753 | Iustin Pop | the URI (e.g. HTTP, FTP, LDAP) or some other auxiliary server
|
309 | 77e1d753 | Iustin Pop | (e.g. DNS) it needed to access in attempting to complete the
|
310 | 77e1d753 | Iustin Pop | request.
|
311 | 77e1d753 | Iustin Pop |
|
312 | 77e1d753 | Iustin Pop | """
|
313 | 77e1d753 | Iustin Pop | code = 504
|
314 | 77e1d753 | Iustin Pop | |
315 | 77e1d753 | Iustin Pop | |
316 | 84f2756e | Michael Hanselmann | class HttpVersionNotSupported(HttpException): |
317 | b3660886 | Michael Hanselmann | """505 HTTP Version Not Supported
|
318 | b3660886 | Michael Hanselmann |
|
319 | 25e7b43f | Iustin Pop | RFC2616, 10.5.6: The server does not support, or refuses to support,
|
320 | 25e7b43f | Iustin Pop | the HTTP protocol version that was used in the request message.
|
321 | b3660886 | Michael Hanselmann |
|
322 | b3660886 | Michael Hanselmann | """
|
323 | 42242313 | Michael Hanselmann | code = 505
|
324 | 42242313 | Michael Hanselmann | |
325 | 42242313 | Michael Hanselmann | |
326 | aea0ed67 | Michael Hanselmann | def SocketOperation(sock, op, arg1, timeout): |
327 | 73a59d9e | Michael Hanselmann | """Wrapper around socket functions.
|
328 | 73a59d9e | Michael Hanselmann |
|
329 | 73a59d9e | Michael Hanselmann | This function abstracts error handling for socket operations, especially
|
330 | 73a59d9e | Michael Hanselmann | for the complicated interaction with OpenSSL.
|
331 | 73a59d9e | Michael Hanselmann |
|
332 | 73a59d9e | Michael Hanselmann | @type sock: socket
|
333 | 358a8811 | Michael Hanselmann | @param sock: Socket for the operation
|
334 | 73a59d9e | Michael Hanselmann | @type op: int
|
335 | 73a59d9e | Michael Hanselmann | @param op: Operation to execute (SOCKOP_* constants)
|
336 | 73a59d9e | Michael Hanselmann | @type arg1: any
|
337 | 73a59d9e | Michael Hanselmann | @param arg1: Parameter for function (if needed)
|
338 | 73a59d9e | Michael Hanselmann | @type timeout: None or float
|
339 | 73a59d9e | Michael Hanselmann | @param timeout: Timeout in seconds or None
|
340 | 358a8811 | Michael Hanselmann | @return: Return value of socket function
|
341 | 73a59d9e | Michael Hanselmann |
|
342 | 73a59d9e | Michael Hanselmann | """
|
343 | 73a59d9e | Michael Hanselmann | # TODO: event_poll/event_check/override
|
344 | d7fa9982 | Michael Hanselmann | if op in (SOCKOP_SEND, SOCKOP_HANDSHAKE): |
345 | 73a59d9e | Michael Hanselmann | event_poll = select.POLLOUT |
346 | 73a59d9e | Michael Hanselmann | |
347 | 73a59d9e | Michael Hanselmann | elif op == SOCKOP_RECV:
|
348 | 73a59d9e | Michael Hanselmann | event_poll = select.POLLIN |
349 | 73a59d9e | Michael Hanselmann | |
350 | 73a59d9e | Michael Hanselmann | elif op == SOCKOP_SHUTDOWN:
|
351 | 73a59d9e | Michael Hanselmann | event_poll = None
|
352 | 73a59d9e | Michael Hanselmann | |
353 | 73a59d9e | Michael Hanselmann | # The timeout is only used when OpenSSL requests polling for a condition.
|
354 | 73a59d9e | Michael Hanselmann | # It is not advisable to have no timeout for shutdown.
|
355 | 73a59d9e | Michael Hanselmann | assert timeout
|
356 | 73a59d9e | Michael Hanselmann | |
357 | 73a59d9e | Michael Hanselmann | else:
|
358 | 73a59d9e | Michael Hanselmann | raise AssertionError("Invalid socket operation") |
359 | 73a59d9e | Michael Hanselmann | |
360 | d7fa9982 | Michael Hanselmann | # Handshake is only supported by SSL sockets
|
361 | d7fa9982 | Michael Hanselmann | if (op == SOCKOP_HANDSHAKE and |
362 | d7fa9982 | Michael Hanselmann | not isinstance(sock, OpenSSL.SSL.ConnectionType)): |
363 | d7fa9982 | Michael Hanselmann | return
|
364 | d7fa9982 | Michael Hanselmann | |
365 | 73a59d9e | Michael Hanselmann | # No override by default
|
366 | 73a59d9e | Michael Hanselmann | event_override = 0
|
367 | 73a59d9e | Michael Hanselmann | |
368 | 73a59d9e | Michael Hanselmann | while True: |
369 | 73a59d9e | Michael Hanselmann | # Poll only for certain operations and when asked for by an override
|
370 | d7fa9982 | Michael Hanselmann | if event_override or op in (SOCKOP_SEND, SOCKOP_RECV, SOCKOP_HANDSHAKE): |
371 | 73a59d9e | Michael Hanselmann | if event_override:
|
372 | 73a59d9e | Michael Hanselmann | wait_for_event = event_override |
373 | 73a59d9e | Michael Hanselmann | else:
|
374 | 73a59d9e | Michael Hanselmann | wait_for_event = event_poll |
375 | 73a59d9e | Michael Hanselmann | |
376 | dfdc4060 | Guido Trotter | event = utils.WaitForFdCondition(sock, wait_for_event, timeout) |
377 | 73a59d9e | Michael Hanselmann | if event is None: |
378 | c9d0fa8a | Michael Hanselmann | raise HttpSocketTimeout()
|
379 | 73a59d9e | Michael Hanselmann | |
380 | 0be13136 | Michael Hanselmann | if event & (select.POLLNVAL | select.POLLHUP | select.POLLERR):
|
381 | 0be13136 | Michael Hanselmann | # Let the socket functions handle these
|
382 | 0be13136 | Michael Hanselmann | break
|
383 | 73a59d9e | Michael Hanselmann | |
384 | 73a59d9e | Michael Hanselmann | if not event & wait_for_event: |
385 | 73a59d9e | Michael Hanselmann | continue
|
386 | 73a59d9e | Michael Hanselmann | |
387 | 73a59d9e | Michael Hanselmann | # Reset override
|
388 | 73a59d9e | Michael Hanselmann | event_override = 0
|
389 | 73a59d9e | Michael Hanselmann | |
390 | 73a59d9e | Michael Hanselmann | try:
|
391 | 73a59d9e | Michael Hanselmann | try:
|
392 | 73a59d9e | Michael Hanselmann | if op == SOCKOP_SEND:
|
393 | 73a59d9e | Michael Hanselmann | return sock.send(arg1)
|
394 | 73a59d9e | Michael Hanselmann | |
395 | 73a59d9e | Michael Hanselmann | elif op == SOCKOP_RECV:
|
396 | 73a59d9e | Michael Hanselmann | return sock.recv(arg1)
|
397 | 73a59d9e | Michael Hanselmann | |
398 | 73a59d9e | Michael Hanselmann | elif op == SOCKOP_SHUTDOWN:
|
399 | 73a59d9e | Michael Hanselmann | if isinstance(sock, OpenSSL.SSL.ConnectionType): |
400 | 73a59d9e | Michael Hanselmann | # PyOpenSSL's shutdown() doesn't take arguments
|
401 | 73a59d9e | Michael Hanselmann | return sock.shutdown()
|
402 | 73a59d9e | Michael Hanselmann | else:
|
403 | 73a59d9e | Michael Hanselmann | return sock.shutdown(arg1)
|
404 | 73a59d9e | Michael Hanselmann | |
405 | d7fa9982 | Michael Hanselmann | elif op == SOCKOP_HANDSHAKE:
|
406 | d7fa9982 | Michael Hanselmann | return sock.do_handshake()
|
407 | d7fa9982 | Michael Hanselmann | |
408 | 73a59d9e | Michael Hanselmann | except OpenSSL.SSL.WantWriteError:
|
409 | 73a59d9e | Michael Hanselmann | # OpenSSL wants to write, poll for POLLOUT
|
410 | 73a59d9e | Michael Hanselmann | event_override = select.POLLOUT |
411 | 73a59d9e | Michael Hanselmann | continue
|
412 | 73a59d9e | Michael Hanselmann | |
413 | 73a59d9e | Michael Hanselmann | except OpenSSL.SSL.WantReadError:
|
414 | 73a59d9e | Michael Hanselmann | # OpenSSL wants to read, poll for POLLIN
|
415 | 73a59d9e | Michael Hanselmann | event_override = select.POLLIN | select.POLLPRI |
416 | 73a59d9e | Michael Hanselmann | continue
|
417 | 73a59d9e | Michael Hanselmann | |
418 | 73a59d9e | Michael Hanselmann | except OpenSSL.SSL.WantX509LookupError:
|
419 | 73a59d9e | Michael Hanselmann | continue
|
420 | 73a59d9e | Michael Hanselmann | |
421 | 39cfc25b | Michael Hanselmann | except OpenSSL.SSL.ZeroReturnError, err:
|
422 | 39cfc25b | Michael Hanselmann | # SSL Connection has been closed. In SSL 3.0 and TLS 1.0, this only
|
423 | 39cfc25b | Michael Hanselmann | # occurs if a closure alert has occurred in the protocol, i.e. the
|
424 | 39cfc25b | Michael Hanselmann | # connection has been closed cleanly. Note that this does not
|
425 | 39cfc25b | Michael Hanselmann | # necessarily mean that the transport layer (e.g. a socket) has been
|
426 | 39cfc25b | Michael Hanselmann | # closed.
|
427 | 39cfc25b | Michael Hanselmann | if op == SOCKOP_SEND:
|
428 | 39cfc25b | Michael Hanselmann | # Can happen during a renegotiation
|
429 | 39cfc25b | Michael Hanselmann | raise HttpConnectionClosed(err.args)
|
430 | 39cfc25b | Michael Hanselmann | elif op == SOCKOP_RECV:
|
431 | 39cfc25b | Michael Hanselmann | return "" |
432 | 39cfc25b | Michael Hanselmann | |
433 | 39cfc25b | Michael Hanselmann | # SSL_shutdown shouldn't return SSL_ERROR_ZERO_RETURN
|
434 | 39cfc25b | Michael Hanselmann | raise socket.error(err.args)
|
435 | 39cfc25b | Michael Hanselmann | |
436 | 73a59d9e | Michael Hanselmann | except OpenSSL.SSL.SysCallError, err:
|
437 | 73a59d9e | Michael Hanselmann | if op == SOCKOP_SEND:
|
438 | 73a59d9e | Michael Hanselmann | # arg1 is the data when writing
|
439 | 73a59d9e | Michael Hanselmann | if err.args and err.args[0] == -1 and arg1 == "": |
440 | 73a59d9e | Michael Hanselmann | # errors when writing empty strings are expected
|
441 | 73a59d9e | Michael Hanselmann | # and can be ignored
|
442 | 73a59d9e | Michael Hanselmann | return 0 |
443 | 73a59d9e | Michael Hanselmann | |
444 | d7fa9982 | Michael Hanselmann | if err.args == (-1, _SSL_UNEXPECTED_EOF): |
445 | d7fa9982 | Michael Hanselmann | if op == SOCKOP_RECV:
|
446 | 73a59d9e | Michael Hanselmann | return "" |
447 | d7fa9982 | Michael Hanselmann | elif op == SOCKOP_HANDSHAKE:
|
448 | d7fa9982 | Michael Hanselmann | # Can happen if peer disconnects directly after the connection is
|
449 | d7fa9982 | Michael Hanselmann | # opened.
|
450 | d7fa9982 | Michael Hanselmann | raise HttpSessionHandshakeUnexpectedEOF(err.args)
|
451 | 73a59d9e | Michael Hanselmann | |
452 | 73a59d9e | Michael Hanselmann | raise socket.error(err.args)
|
453 | 73a59d9e | Michael Hanselmann | |
454 | 73a59d9e | Michael Hanselmann | except OpenSSL.SSL.Error, err:
|
455 | 73a59d9e | Michael Hanselmann | raise socket.error(err.args)
|
456 | 73a59d9e | Michael Hanselmann | |
457 | 73a59d9e | Michael Hanselmann | except socket.error, err:
|
458 | 73a59d9e | Michael Hanselmann | if err.args and err.args[0] == errno.EAGAIN: |
459 | 73a59d9e | Michael Hanselmann | # Ignore EAGAIN
|
460 | 73a59d9e | Michael Hanselmann | continue
|
461 | 73a59d9e | Michael Hanselmann | |
462 | 73a59d9e | Michael Hanselmann | raise
|
463 | 73a59d9e | Michael Hanselmann | |
464 | 73a59d9e | Michael Hanselmann | |
465 | aea0ed67 | Michael Hanselmann | def ShutdownConnection(sock, close_timeout, write_timeout, msgreader, force): |
466 | 02cab3e7 | Michael Hanselmann | """Closes the connection.
|
467 | 02cab3e7 | Michael Hanselmann |
|
468 | 358a8811 | Michael Hanselmann | @type sock: socket
|
469 | 358a8811 | Michael Hanselmann | @param sock: Socket to be shut down
|
470 | 358a8811 | Michael Hanselmann | @type close_timeout: float
|
471 | 25e7b43f | Iustin Pop | @param close_timeout: How long to wait for the peer to close
|
472 | 25e7b43f | Iustin Pop | the connection
|
473 | 358a8811 | Michael Hanselmann | @type write_timeout: float
|
474 | 358a8811 | Michael Hanselmann | @param write_timeout: Write timeout for shutdown
|
475 | 358a8811 | Michael Hanselmann | @type msgreader: http.HttpMessageReader
|
476 | 25e7b43f | Iustin Pop | @param msgreader: Request message reader, used to determine whether
|
477 | 25e7b43f | Iustin Pop | peer should close connection
|
478 | 358a8811 | Michael Hanselmann | @type force: bool
|
479 | 25e7b43f | Iustin Pop | @param force: Whether to forcibly close the connection without
|
480 | 25e7b43f | Iustin Pop | waiting for peer
|
481 | 358a8811 | Michael Hanselmann |
|
482 | 02cab3e7 | Michael Hanselmann | """
|
483 | 02cab3e7 | Michael Hanselmann | #print msgreader.peer_will_close, force
|
484 | 02cab3e7 | Michael Hanselmann | if msgreader and msgreader.peer_will_close and not force: |
485 | 02cab3e7 | Michael Hanselmann | # Wait for peer to close
|
486 | 02cab3e7 | Michael Hanselmann | try:
|
487 | 02cab3e7 | Michael Hanselmann | # Check whether it's actually closed
|
488 | aea0ed67 | Michael Hanselmann | if not SocketOperation(sock, SOCKOP_RECV, 1, close_timeout): |
489 | 02cab3e7 | Michael Hanselmann | return
|
490 | 02cab3e7 | Michael Hanselmann | except (socket.error, HttpError, HttpSocketTimeout):
|
491 | 02cab3e7 | Michael Hanselmann | # Ignore errors at this stage
|
492 | 02cab3e7 | Michael Hanselmann | pass
|
493 | 02cab3e7 | Michael Hanselmann | |
494 | 02cab3e7 | Michael Hanselmann | # Close the connection from our side
|
495 | 02cab3e7 | Michael Hanselmann | try:
|
496 | 39cfc25b | Michael Hanselmann | # We don't care about the return value, see NOTES in SSL_shutdown(3).
|
497 | aea0ed67 | Michael Hanselmann | SocketOperation(sock, SOCKOP_SHUTDOWN, socket.SHUT_RDWR, |
498 | 02cab3e7 | Michael Hanselmann | write_timeout) |
499 | 02cab3e7 | Michael Hanselmann | except HttpSocketTimeout:
|
500 | 02cab3e7 | Michael Hanselmann | raise HttpError("Timeout while shutting down connection") |
501 | 02cab3e7 | Michael Hanselmann | except socket.error, err:
|
502 | 45eac583 | Michael Hanselmann | # Ignore ENOTCONN
|
503 | 45eac583 | Michael Hanselmann | if not (err.args and err.args[0] == errno.ENOTCONN): |
504 | 45eac583 | Michael Hanselmann | raise HttpError("Error while shutting down connection: %s" % err) |
505 | 02cab3e7 | Michael Hanselmann | |
506 | 02cab3e7 | Michael Hanselmann | |
507 | aea0ed67 | Michael Hanselmann | def Handshake(sock, write_timeout): |
508 | d7fa9982 | Michael Hanselmann | """Shakes peer's hands.
|
509 | d7fa9982 | Michael Hanselmann |
|
510 | d7fa9982 | Michael Hanselmann | @type sock: socket
|
511 | d7fa9982 | Michael Hanselmann | @param sock: Socket to be shut down
|
512 | d7fa9982 | Michael Hanselmann | @type write_timeout: float
|
513 | d7fa9982 | Michael Hanselmann | @param write_timeout: Write timeout for handshake
|
514 | d7fa9982 | Michael Hanselmann |
|
515 | d7fa9982 | Michael Hanselmann | """
|
516 | d7fa9982 | Michael Hanselmann | try:
|
517 | aea0ed67 | Michael Hanselmann | return SocketOperation(sock, SOCKOP_HANDSHAKE, None, write_timeout) |
518 | d7fa9982 | Michael Hanselmann | except HttpSocketTimeout:
|
519 | d7fa9982 | Michael Hanselmann | raise HttpError("Timeout during SSL handshake") |
520 | d7fa9982 | Michael Hanselmann | except socket.error, err:
|
521 | d7fa9982 | Michael Hanselmann | raise HttpError("Error in SSL handshake: %s" % err) |
522 | d7fa9982 | Michael Hanselmann | |
523 | d7fa9982 | Michael Hanselmann | |
524 | 8d0a4f99 | Michael Hanselmann | def InitSsl(): |
525 | 8d0a4f99 | Michael Hanselmann | """Initializes the SSL infrastructure.
|
526 | 8d0a4f99 | Michael Hanselmann |
|
527 | 8d0a4f99 | Michael Hanselmann | This function is idempotent.
|
528 | 8d0a4f99 | Michael Hanselmann |
|
529 | 8d0a4f99 | Michael Hanselmann | """
|
530 | 8d0a4f99 | Michael Hanselmann | if not OpenSSL.rand.status(): |
531 | 8d0a4f99 | Michael Hanselmann | raise EnvironmentError("OpenSSL could not collect enough entropy" |
532 | 8d0a4f99 | Michael Hanselmann | " for the PRNG")
|
533 | 8d0a4f99 | Michael Hanselmann | |
534 | 8d0a4f99 | Michael Hanselmann | # TODO: Maybe add some additional seeding for OpenSSL's PRNG
|
535 | 8d0a4f99 | Michael Hanselmann | |
536 | 8d0a4f99 | Michael Hanselmann | |
537 | f20cbea2 | Michael Hanselmann | class HttpSslParams(object): |
538 | f20cbea2 | Michael Hanselmann | """Data class for SSL key and certificate.
|
539 | f20cbea2 | Michael Hanselmann |
|
540 | f20cbea2 | Michael Hanselmann | """
|
541 | f20cbea2 | Michael Hanselmann | def __init__(self, ssl_key_path, ssl_cert_path): |
542 | f20cbea2 | Michael Hanselmann | """Initializes this class.
|
543 | f20cbea2 | Michael Hanselmann |
|
544 | f20cbea2 | Michael Hanselmann | @type ssl_key_path: string
|
545 | f20cbea2 | Michael Hanselmann | @param ssl_key_path: Path to file containing SSL key in PEM format
|
546 | f20cbea2 | Michael Hanselmann | @type ssl_cert_path: string
|
547 | 25e7b43f | Iustin Pop | @param ssl_cert_path: Path to file containing SSL certificate
|
548 | 25e7b43f | Iustin Pop | in PEM format
|
549 | f20cbea2 | Michael Hanselmann |
|
550 | f20cbea2 | Michael Hanselmann | """
|
551 | 65c6b8e0 | Michael Hanselmann | self.ssl_key_pem = utils.ReadFile(ssl_key_path)
|
552 | 65c6b8e0 | Michael Hanselmann | self.ssl_cert_pem = utils.ReadFile(ssl_cert_path)
|
553 | 2d93a6a7 | Apollon Oikonomopoulos | self.ssl_cert_path = ssl_cert_path
|
554 | f20cbea2 | Michael Hanselmann | |
555 | 65c6b8e0 | Michael Hanselmann | def GetKey(self): |
556 | 65c6b8e0 | Michael Hanselmann | return OpenSSL.crypto.load_privatekey(OpenSSL.crypto.FILETYPE_PEM,
|
557 | 65c6b8e0 | Michael Hanselmann | self.ssl_key_pem)
|
558 | 65c6b8e0 | Michael Hanselmann | |
559 | 65c6b8e0 | Michael Hanselmann | def GetCertificate(self): |
560 | 65c6b8e0 | Michael Hanselmann | return OpenSSL.crypto.load_certificate(OpenSSL.crypto.FILETYPE_PEM,
|
561 | 65c6b8e0 | Michael Hanselmann | self.ssl_cert_pem)
|
562 | f20cbea2 | Michael Hanselmann | |
563 | f20cbea2 | Michael Hanselmann | |
564 | f4322a1e | Michael Hanselmann | class HttpBase(object): |
565 | b14f759e | Michael Hanselmann | """Base class for HTTP server and client.
|
566 | b14f759e | Michael Hanselmann |
|
567 | b14f759e | Michael Hanselmann | """
|
568 | b14f759e | Michael Hanselmann | def __init__(self): |
569 | 22692e48 | Michael Hanselmann | self.using_ssl = None |
570 | f20cbea2 | Michael Hanselmann | self._ssl_params = None |
571 | 65c6b8e0 | Michael Hanselmann | self._ssl_key = None |
572 | 65c6b8e0 | Michael Hanselmann | self._ssl_cert = None |
573 | b14f759e | Michael Hanselmann | |
574 | db4e138b | Manuel Franceschini | def _CreateSocket(self, ssl_params, ssl_verify_peer, family): |
575 | b14f759e | Michael Hanselmann | """Creates a TCP socket and initializes SSL if needed.
|
576 | b14f759e | Michael Hanselmann |
|
577 | f20cbea2 | Michael Hanselmann | @type ssl_params: HttpSslParams
|
578 | f20cbea2 | Michael Hanselmann | @param ssl_params: SSL key and certificate
|
579 | b14f759e | Michael Hanselmann | @type ssl_verify_peer: bool
|
580 | 25e7b43f | Iustin Pop | @param ssl_verify_peer: Whether to require client certificate
|
581 | 25e7b43f | Iustin Pop | and compare it with our certificate
|
582 | db4e138b | Manuel Franceschini | @type family: int
|
583 | db4e138b | Manuel Franceschini | @param family: socket.AF_INET | socket.AF_INET6
|
584 | b14f759e | Michael Hanselmann |
|
585 | b14f759e | Michael Hanselmann | """
|
586 | db4e138b | Manuel Franceschini | assert family in (socket.AF_INET, socket.AF_INET6) |
587 | f20cbea2 | Michael Hanselmann | |
588 | db4e138b | Manuel Franceschini | self._ssl_params = ssl_params
|
589 | db4e138b | Manuel Franceschini | sock = socket.socket(family, socket.SOCK_STREAM) |
590 | b14f759e | Michael Hanselmann | |
591 | b14f759e | Michael Hanselmann | # Should we enable SSL?
|
592 | 22692e48 | Michael Hanselmann | self.using_ssl = ssl_params is not None |
593 | b14f759e | Michael Hanselmann | |
594 | 22692e48 | Michael Hanselmann | if not self.using_ssl: |
595 | b14f759e | Michael Hanselmann | return sock
|
596 | b14f759e | Michael Hanselmann | |
597 | 65c6b8e0 | Michael Hanselmann | self._ssl_key = ssl_params.GetKey()
|
598 | 65c6b8e0 | Michael Hanselmann | self._ssl_cert = ssl_params.GetCertificate()
|
599 | 65c6b8e0 | Michael Hanselmann | |
600 | b14f759e | Michael Hanselmann | ctx = OpenSSL.SSL.Context(OpenSSL.SSL.SSLv23_METHOD) |
601 | b14f759e | Michael Hanselmann | ctx.set_options(OpenSSL.SSL.OP_NO_SSLv2) |
602 | 91c69613 | Michael Hanselmann | |
603 | 91c69613 | Michael Hanselmann | ciphers = self.GetSslCiphers()
|
604 | 91c69613 | Michael Hanselmann | logging.debug("Setting SSL cipher string %s", ciphers)
|
605 | 91c69613 | Michael Hanselmann | ctx.set_cipher_list(ciphers) |
606 | b14f759e | Michael Hanselmann | |
607 | 65c6b8e0 | Michael Hanselmann | ctx.use_privatekey(self._ssl_key)
|
608 | 65c6b8e0 | Michael Hanselmann | ctx.use_certificate(self._ssl_cert)
|
609 | b14f759e | Michael Hanselmann | ctx.check_privatekey() |
610 | b14f759e | Michael Hanselmann | |
611 | b14f759e | Michael Hanselmann | if ssl_verify_peer:
|
612 | b14f759e | Michael Hanselmann | ctx.set_verify(OpenSSL.SSL.VERIFY_PEER | |
613 | b14f759e | Michael Hanselmann | OpenSSL.SSL.VERIFY_FAIL_IF_NO_PEER_CERT, |
614 | b14f759e | Michael Hanselmann | self._SSLVerifyCallback)
|
615 | b14f759e | Michael Hanselmann | |
616 | 2d93a6a7 | Apollon Oikonomopoulos | # Also add our certificate as a trusted CA to be sent to the client.
|
617 | 2d93a6a7 | Apollon Oikonomopoulos | # This is required at least for GnuTLS clients to work.
|
618 | 2d93a6a7 | Apollon Oikonomopoulos | try:
|
619 | 2d93a6a7 | Apollon Oikonomopoulos | # This will fail for PyOpenssl versions before 0.10
|
620 | 2d93a6a7 | Apollon Oikonomopoulos | ctx.add_client_ca(self._ssl_cert)
|
621 | 2d93a6a7 | Apollon Oikonomopoulos | except AttributeError: |
622 | 2d93a6a7 | Apollon Oikonomopoulos | # Fall back to letting OpenSSL read the certificate file directly.
|
623 | 2d93a6a7 | Apollon Oikonomopoulos | ctx.load_client_ca(ssl_params.ssl_cert_path) |
624 | 2d93a6a7 | Apollon Oikonomopoulos | |
625 | b14f759e | Michael Hanselmann | return OpenSSL.SSL.Connection(ctx, sock)
|
626 | b14f759e | Michael Hanselmann | |
627 | 5117f822 | Michael Hanselmann | def GetSslCiphers(self): # pylint: disable-msg=R0201 |
628 | 91c69613 | Michael Hanselmann | """Returns the ciphers string for SSL.
|
629 | 91c69613 | Michael Hanselmann |
|
630 | 91c69613 | Michael Hanselmann | """
|
631 | 91c69613 | Michael Hanselmann | return constants.OPENSSL_CIPHERS
|
632 | 91c69613 | Michael Hanselmann | |
633 | b14f759e | Michael Hanselmann | def _SSLVerifyCallback(self, conn, cert, errnum, errdepth, ok): |
634 | b14f759e | Michael Hanselmann | """Verify the certificate provided by the peer
|
635 | b14f759e | Michael Hanselmann |
|
636 | b14f759e | Michael Hanselmann | We only compare fingerprints. The client must use the same certificate as
|
637 | b14f759e | Michael Hanselmann | we do on our side.
|
638 | b14f759e | Michael Hanselmann |
|
639 | b14f759e | Michael Hanselmann | """
|
640 | 2d54e29c | Iustin Pop | # some parameters are unused, but this is the API
|
641 | 2d54e29c | Iustin Pop | # pylint: disable-msg=W0613
|
642 | f20cbea2 | Michael Hanselmann | assert self._ssl_params, "SSL not initialized" |
643 | b14f759e | Michael Hanselmann | |
644 | 65c6b8e0 | Michael Hanselmann | return (self._ssl_cert.digest("sha1") == cert.digest("sha1") and |
645 | 65c6b8e0 | Michael Hanselmann | self._ssl_cert.digest("md5") == cert.digest("md5")) |
646 | b14f759e | Michael Hanselmann | |
647 | b14f759e | Michael Hanselmann | |
648 | 02cab3e7 | Michael Hanselmann | class HttpMessage(object): |
649 | 02cab3e7 | Michael Hanselmann | """Data structure for HTTP message.
|
650 | 02cab3e7 | Michael Hanselmann |
|
651 | 02cab3e7 | Michael Hanselmann | """
|
652 | 02cab3e7 | Michael Hanselmann | def __init__(self): |
653 | 02cab3e7 | Michael Hanselmann | self.start_line = None |
654 | 02cab3e7 | Michael Hanselmann | self.headers = None |
655 | 02cab3e7 | Michael Hanselmann | self.body = None |
656 | 02cab3e7 | Michael Hanselmann | |
657 | 02cab3e7 | Michael Hanselmann | |
658 | 02cab3e7 | Michael Hanselmann | class HttpClientToServerStartLine(object): |
659 | 02cab3e7 | Michael Hanselmann | """Data structure for HTTP request start line.
|
660 | 02cab3e7 | Michael Hanselmann |
|
661 | 02cab3e7 | Michael Hanselmann | """
|
662 | 02cab3e7 | Michael Hanselmann | def __init__(self, method, path, version): |
663 | 02cab3e7 | Michael Hanselmann | self.method = method
|
664 | 02cab3e7 | Michael Hanselmann | self.path = path
|
665 | 02cab3e7 | Michael Hanselmann | self.version = version
|
666 | 02cab3e7 | Michael Hanselmann | |
667 | 02cab3e7 | Michael Hanselmann | def __str__(self): |
668 | 02cab3e7 | Michael Hanselmann | return "%s %s %s" % (self.method, self.path, self.version) |
669 | 02cab3e7 | Michael Hanselmann | |
670 | 02cab3e7 | Michael Hanselmann | |
671 | 02cab3e7 | Michael Hanselmann | class HttpServerToClientStartLine(object): |
672 | 02cab3e7 | Michael Hanselmann | """Data structure for HTTP response start line.
|
673 | 02cab3e7 | Michael Hanselmann |
|
674 | 02cab3e7 | Michael Hanselmann | """
|
675 | 02cab3e7 | Michael Hanselmann | def __init__(self, version, code, reason): |
676 | 02cab3e7 | Michael Hanselmann | self.version = version
|
677 | 02cab3e7 | Michael Hanselmann | self.code = code
|
678 | 02cab3e7 | Michael Hanselmann | self.reason = reason
|
679 | 02cab3e7 | Michael Hanselmann | |
680 | 02cab3e7 | Michael Hanselmann | def __str__(self): |
681 | 02cab3e7 | Michael Hanselmann | return "%s %s %s" % (self.version, self.code, self.reason) |
682 | 02cab3e7 | Michael Hanselmann | |
683 | 02cab3e7 | Michael Hanselmann | |
684 | 02cab3e7 | Michael Hanselmann | class HttpMessageWriter(object): |
685 | 02cab3e7 | Michael Hanselmann | """Writes an HTTP message to a socket.
|
686 | 02cab3e7 | Michael Hanselmann |
|
687 | 02cab3e7 | Michael Hanselmann | """
|
688 | 02cab3e7 | Michael Hanselmann | def __init__(self, sock, msg, write_timeout): |
689 | 358a8811 | Michael Hanselmann | """Initializes this class and writes an HTTP message to a socket.
|
690 | 358a8811 | Michael Hanselmann |
|
691 | 358a8811 | Michael Hanselmann | @type sock: socket
|
692 | 358a8811 | Michael Hanselmann | @param sock: Socket to be written to
|
693 | 358a8811 | Michael Hanselmann | @type msg: http.HttpMessage
|
694 | 358a8811 | Michael Hanselmann | @param msg: HTTP message to be written
|
695 | 358a8811 | Michael Hanselmann | @type write_timeout: float
|
696 | 358a8811 | Michael Hanselmann | @param write_timeout: Write timeout for socket
|
697 | 358a8811 | Michael Hanselmann |
|
698 | 358a8811 | Michael Hanselmann | """
|
699 | 02cab3e7 | Michael Hanselmann | self._msg = msg
|
700 | 02cab3e7 | Michael Hanselmann | |
701 | 02cab3e7 | Michael Hanselmann | self._PrepareMessage()
|
702 | 02cab3e7 | Michael Hanselmann | |
703 | 02cab3e7 | Michael Hanselmann | buf = self._FormatMessage()
|
704 | 02cab3e7 | Michael Hanselmann | |
705 | b18dd019 | Iustin Pop | pos = 0
|
706 | b18dd019 | Iustin Pop | end = len(buf)
|
707 | b18dd019 | Iustin Pop | while pos < end:
|
708 | b18dd019 | Iustin Pop | # Send only SOCK_BUF_SIZE bytes at a time
|
709 | 358a8811 | Michael Hanselmann | data = buf[pos:(pos + SOCK_BUF_SIZE)] |
710 | 02cab3e7 | Michael Hanselmann | |
711 | aea0ed67 | Michael Hanselmann | sent = SocketOperation(sock, SOCKOP_SEND, data, write_timeout) |
712 | 02cab3e7 | Michael Hanselmann | |
713 | 02cab3e7 | Michael Hanselmann | # Remove sent bytes
|
714 | b18dd019 | Iustin Pop | pos += sent |
715 | 02cab3e7 | Michael Hanselmann | |
716 | b18dd019 | Iustin Pop | assert pos == end, "Message wasn't sent completely" |
717 | 02cab3e7 | Michael Hanselmann | |
718 | 02cab3e7 | Michael Hanselmann | def _PrepareMessage(self): |
719 | 02cab3e7 | Michael Hanselmann | """Prepares the HTTP message by setting mandatory headers.
|
720 | 02cab3e7 | Michael Hanselmann |
|
721 | 02cab3e7 | Michael Hanselmann | """
|
722 | 02cab3e7 | Michael Hanselmann | # RFC2616, section 4.3: "The presence of a message-body in a request is
|
723 | 02cab3e7 | Michael Hanselmann | # signaled by the inclusion of a Content-Length or Transfer-Encoding header
|
724 | 02cab3e7 | Michael Hanselmann | # field in the request's message-headers."
|
725 | 02cab3e7 | Michael Hanselmann | if self._msg.body: |
726 | 02cab3e7 | Michael Hanselmann | self._msg.headers[HTTP_CONTENT_LENGTH] = len(self._msg.body) |
727 | 02cab3e7 | Michael Hanselmann | |
728 | 02cab3e7 | Michael Hanselmann | def _FormatMessage(self): |
729 | 02cab3e7 | Michael Hanselmann | """Serializes the HTTP message into a string.
|
730 | 02cab3e7 | Michael Hanselmann |
|
731 | 02cab3e7 | Michael Hanselmann | """
|
732 | 02cab3e7 | Michael Hanselmann | buf = StringIO() |
733 | 02cab3e7 | Michael Hanselmann | |
734 | 02cab3e7 | Michael Hanselmann | # Add start line
|
735 | 02cab3e7 | Michael Hanselmann | buf.write(str(self._msg.start_line)) |
736 | 02cab3e7 | Michael Hanselmann | buf.write("\r\n")
|
737 | 02cab3e7 | Michael Hanselmann | |
738 | 02cab3e7 | Michael Hanselmann | # Add headers
|
739 | 02cab3e7 | Michael Hanselmann | if self._msg.start_line.version != HTTP_0_9: |
740 | 02cab3e7 | Michael Hanselmann | for name, value in self._msg.headers.iteritems(): |
741 | 02cab3e7 | Michael Hanselmann | buf.write("%s: %s\r\n" % (name, value))
|
742 | 02cab3e7 | Michael Hanselmann | |
743 | 02cab3e7 | Michael Hanselmann | buf.write("\r\n")
|
744 | 02cab3e7 | Michael Hanselmann | |
745 | 02cab3e7 | Michael Hanselmann | # Add message body if needed
|
746 | 02cab3e7 | Michael Hanselmann | if self.HasMessageBody(): |
747 | 02cab3e7 | Michael Hanselmann | buf.write(self._msg.body)
|
748 | 02cab3e7 | Michael Hanselmann | |
749 | 02cab3e7 | Michael Hanselmann | elif self._msg.body: |
750 | 02cab3e7 | Michael Hanselmann | logging.warning("Ignoring message body")
|
751 | 02cab3e7 | Michael Hanselmann | |
752 | 02cab3e7 | Michael Hanselmann | return buf.getvalue()
|
753 | 02cab3e7 | Michael Hanselmann | |
754 | 02cab3e7 | Michael Hanselmann | def HasMessageBody(self): |
755 | 02cab3e7 | Michael Hanselmann | """Checks whether the HTTP message contains a body.
|
756 | 02cab3e7 | Michael Hanselmann |
|
757 | 5bbd3f7f | Michael Hanselmann | Can be overridden by subclasses.
|
758 | 02cab3e7 | Michael Hanselmann |
|
759 | 02cab3e7 | Michael Hanselmann | """
|
760 | 02cab3e7 | Michael Hanselmann | return bool(self._msg.body) |
761 | 02cab3e7 | Michael Hanselmann | |
762 | 02cab3e7 | Michael Hanselmann | |
763 | 02cab3e7 | Michael Hanselmann | class HttpMessageReader(object): |
764 | 02cab3e7 | Michael Hanselmann | """Reads HTTP message from socket.
|
765 | 02cab3e7 | Michael Hanselmann |
|
766 | 02cab3e7 | Michael Hanselmann | """
|
767 | 02cab3e7 | Michael Hanselmann | # Length limits
|
768 | 02cab3e7 | Michael Hanselmann | START_LINE_LENGTH_MAX = None
|
769 | 02cab3e7 | Michael Hanselmann | HEADER_LENGTH_MAX = None
|
770 | 02cab3e7 | Michael Hanselmann | |
771 | 02cab3e7 | Michael Hanselmann | # Parser state machine
|
772 | 02cab3e7 | Michael Hanselmann | PS_START_LINE = "start-line"
|
773 | 02cab3e7 | Michael Hanselmann | PS_HEADERS = "headers"
|
774 | 02cab3e7 | Michael Hanselmann | PS_BODY = "entity-body"
|
775 | 02cab3e7 | Michael Hanselmann | PS_COMPLETE = "complete"
|
776 | 02cab3e7 | Michael Hanselmann | |
777 | 02cab3e7 | Michael Hanselmann | def __init__(self, sock, msg, read_timeout): |
778 | 358a8811 | Michael Hanselmann | """Reads an HTTP message from a socket.
|
779 | 358a8811 | Michael Hanselmann |
|
780 | 358a8811 | Michael Hanselmann | @type sock: socket
|
781 | 358a8811 | Michael Hanselmann | @param sock: Socket to be read from
|
782 | 358a8811 | Michael Hanselmann | @type msg: http.HttpMessage
|
783 | 358a8811 | Michael Hanselmann | @param msg: Object for the read message
|
784 | 358a8811 | Michael Hanselmann | @type read_timeout: float
|
785 | 358a8811 | Michael Hanselmann | @param read_timeout: Read timeout for socket
|
786 | 358a8811 | Michael Hanselmann |
|
787 | 358a8811 | Michael Hanselmann | """
|
788 | 02cab3e7 | Michael Hanselmann | self.sock = sock
|
789 | 02cab3e7 | Michael Hanselmann | self.msg = msg
|
790 | 02cab3e7 | Michael Hanselmann | |
791 | 02cab3e7 | Michael Hanselmann | self.start_line_buffer = None |
792 | 02cab3e7 | Michael Hanselmann | self.header_buffer = StringIO()
|
793 | 02cab3e7 | Michael Hanselmann | self.body_buffer = StringIO()
|
794 | 02cab3e7 | Michael Hanselmann | self.parser_status = self.PS_START_LINE |
795 | 02cab3e7 | Michael Hanselmann | self.content_length = None |
796 | 02cab3e7 | Michael Hanselmann | self.peer_will_close = None |
797 | 02cab3e7 | Michael Hanselmann | |
798 | 02cab3e7 | Michael Hanselmann | buf = ""
|
799 | 02cab3e7 | Michael Hanselmann | eof = False
|
800 | 02cab3e7 | Michael Hanselmann | while self.parser_status != self.PS_COMPLETE: |
801 | f088165d | Michael Hanselmann | # TODO: Don't read more than necessary (Content-Length), otherwise
|
802 | f088165d | Michael Hanselmann | # data might be lost and/or an error could occur
|
803 | aea0ed67 | Michael Hanselmann | data = SocketOperation(sock, SOCKOP_RECV, SOCK_BUF_SIZE, read_timeout) |
804 | 02cab3e7 | Michael Hanselmann | |
805 | 02cab3e7 | Michael Hanselmann | if data:
|
806 | 02cab3e7 | Michael Hanselmann | buf += data |
807 | 02cab3e7 | Michael Hanselmann | else:
|
808 | 02cab3e7 | Michael Hanselmann | eof = True
|
809 | 02cab3e7 | Michael Hanselmann | |
810 | 02cab3e7 | Michael Hanselmann | # Do some parsing and error checking while more data arrives
|
811 | 02cab3e7 | Michael Hanselmann | buf = self._ContinueParsing(buf, eof)
|
812 | 02cab3e7 | Michael Hanselmann | |
813 | 02cab3e7 | Michael Hanselmann | # Must be done only after the buffer has been evaluated
|
814 | 231db3a5 | Michael Hanselmann | # TODO: Content-Length < len(data read) and connection closed
|
815 | 02cab3e7 | Michael Hanselmann | if (eof and |
816 | 02cab3e7 | Michael Hanselmann | self.parser_status in (self.PS_START_LINE, |
817 | 02cab3e7 | Michael Hanselmann | self.PS_HEADERS)):
|
818 | 02cab3e7 | Michael Hanselmann | raise HttpError("Connection closed prematurely") |
819 | 02cab3e7 | Michael Hanselmann | |
820 | 02cab3e7 | Michael Hanselmann | # Parse rest
|
821 | 02cab3e7 | Michael Hanselmann | buf = self._ContinueParsing(buf, True) |
822 | 02cab3e7 | Michael Hanselmann | |
823 | 02cab3e7 | Michael Hanselmann | assert self.parser_status == self.PS_COMPLETE |
824 | 02cab3e7 | Michael Hanselmann | assert not buf, "Parser didn't read full response" |
825 | 02cab3e7 | Michael Hanselmann | |
826 | ab221ddf | Michael Hanselmann | # Body is complete
|
827 | 02cab3e7 | Michael Hanselmann | msg.body = self.body_buffer.getvalue()
|
828 | 02cab3e7 | Michael Hanselmann | |
829 | 02cab3e7 | Michael Hanselmann | def _ContinueParsing(self, buf, eof): |
830 | 02cab3e7 | Michael Hanselmann | """Main function for HTTP message state machine.
|
831 | 02cab3e7 | Michael Hanselmann |
|
832 | 02cab3e7 | Michael Hanselmann | @type buf: string
|
833 | 02cab3e7 | Michael Hanselmann | @param buf: Receive buffer
|
834 | 02cab3e7 | Michael Hanselmann | @type eof: bool
|
835 | 02cab3e7 | Michael Hanselmann | @param eof: Whether we've reached EOF on the socket
|
836 | 02cab3e7 | Michael Hanselmann | @rtype: string
|
837 | 02cab3e7 | Michael Hanselmann | @return: Updated receive buffer
|
838 | 02cab3e7 | Michael Hanselmann |
|
839 | 02cab3e7 | Michael Hanselmann | """
|
840 | f088165d | Michael Hanselmann | # TODO: Use offset instead of slicing when possible
|
841 | 02cab3e7 | Michael Hanselmann | if self.parser_status == self.PS_START_LINE: |
842 | 02cab3e7 | Michael Hanselmann | # Expect start line
|
843 | 02cab3e7 | Michael Hanselmann | while True: |
844 | 02cab3e7 | Michael Hanselmann | idx = buf.find("\r\n")
|
845 | 02cab3e7 | Michael Hanselmann | |
846 | 02cab3e7 | Michael Hanselmann | # RFC2616, section 4.1: "In the interest of robustness, servers SHOULD
|
847 | 02cab3e7 | Michael Hanselmann | # ignore any empty line(s) received where a Request-Line is expected.
|
848 | 02cab3e7 | Michael Hanselmann | # In other words, if the server is reading the protocol stream at the
|
849 | 02cab3e7 | Michael Hanselmann | # beginning of a message and receives a CRLF first, it should ignore
|
850 | 02cab3e7 | Michael Hanselmann | # the CRLF."
|
851 | 02cab3e7 | Michael Hanselmann | if idx == 0: |
852 | 358a8811 | Michael Hanselmann | # TODO: Limit number of CRLFs/empty lines for safety?
|
853 | 0be13136 | Michael Hanselmann | buf = buf[2:]
|
854 | 02cab3e7 | Michael Hanselmann | continue
|
855 | 02cab3e7 | Michael Hanselmann | |
856 | 02cab3e7 | Michael Hanselmann | if idx > 0: |
857 | 02cab3e7 | Michael Hanselmann | self.start_line_buffer = buf[:idx]
|
858 | 02cab3e7 | Michael Hanselmann | |
859 | 02cab3e7 | Michael Hanselmann | self._CheckStartLineLength(len(self.start_line_buffer)) |
860 | 02cab3e7 | Michael Hanselmann | |
861 | 02cab3e7 | Michael Hanselmann | # Remove status line, including CRLF
|
862 | 02cab3e7 | Michael Hanselmann | buf = buf[idx + 2:]
|
863 | 02cab3e7 | Michael Hanselmann | |
864 | 02cab3e7 | Michael Hanselmann | self.msg.start_line = self.ParseStartLine(self.start_line_buffer) |
865 | 02cab3e7 | Michael Hanselmann | |
866 | 02cab3e7 | Michael Hanselmann | self.parser_status = self.PS_HEADERS |
867 | 02cab3e7 | Michael Hanselmann | else:
|
868 | 02cab3e7 | Michael Hanselmann | # Check whether incoming data is getting too large, otherwise we just
|
869 | 02cab3e7 | Michael Hanselmann | # fill our read buffer.
|
870 | 02cab3e7 | Michael Hanselmann | self._CheckStartLineLength(len(buf)) |
871 | 02cab3e7 | Michael Hanselmann | |
872 | 02cab3e7 | Michael Hanselmann | break
|
873 | 02cab3e7 | Michael Hanselmann | |
874 | 02cab3e7 | Michael Hanselmann | # TODO: Handle messages without headers
|
875 | 02cab3e7 | Michael Hanselmann | if self.parser_status == self.PS_HEADERS: |
876 | 02cab3e7 | Michael Hanselmann | # Wait for header end
|
877 | 02cab3e7 | Michael Hanselmann | idx = buf.find("\r\n\r\n")
|
878 | 02cab3e7 | Michael Hanselmann | if idx >= 0: |
879 | 02cab3e7 | Michael Hanselmann | self.header_buffer.write(buf[:idx + 2]) |
880 | 02cab3e7 | Michael Hanselmann | |
881 | 02cab3e7 | Michael Hanselmann | self._CheckHeaderLength(self.header_buffer.tell()) |
882 | 02cab3e7 | Michael Hanselmann | |
883 | 02cab3e7 | Michael Hanselmann | # Remove headers, including CRLF
|
884 | 02cab3e7 | Michael Hanselmann | buf = buf[idx + 4:]
|
885 | 02cab3e7 | Michael Hanselmann | |
886 | 02cab3e7 | Michael Hanselmann | self._ParseHeaders()
|
887 | 02cab3e7 | Michael Hanselmann | |
888 | 02cab3e7 | Michael Hanselmann | self.parser_status = self.PS_BODY |
889 | 02cab3e7 | Michael Hanselmann | else:
|
890 | 02cab3e7 | Michael Hanselmann | # Check whether incoming data is getting too large, otherwise we just
|
891 | 02cab3e7 | Michael Hanselmann | # fill our read buffer.
|
892 | 02cab3e7 | Michael Hanselmann | self._CheckHeaderLength(len(buf)) |
893 | 02cab3e7 | Michael Hanselmann | |
894 | 02cab3e7 | Michael Hanselmann | if self.parser_status == self.PS_BODY: |
895 | 02cab3e7 | Michael Hanselmann | # TODO: Implement max size for body_buffer
|
896 | 02cab3e7 | Michael Hanselmann | self.body_buffer.write(buf)
|
897 | 02cab3e7 | Michael Hanselmann | buf = ""
|
898 | 02cab3e7 | Michael Hanselmann | |
899 | 02cab3e7 | Michael Hanselmann | # Check whether we've read everything
|
900 | 02cab3e7 | Michael Hanselmann | #
|
901 | 02cab3e7 | Michael Hanselmann | # RFC2616, section 4.4: "When a message-body is included with a message,
|
902 | 02cab3e7 | Michael Hanselmann | # the transfer-length of that body is determined by one of the following
|
903 | 02cab3e7 | Michael Hanselmann | # [...] 5. By the server closing the connection. (Closing the connection
|
904 | 02cab3e7 | Michael Hanselmann | # cannot be used to indicate the end of a request body, since that would
|
905 | 02cab3e7 | Michael Hanselmann | # leave no possibility for the server to send back a response.)"
|
906 | f088165d | Michael Hanselmann | #
|
907 | f088165d | Michael Hanselmann | # TODO: Error when buffer length > Content-Length header
|
908 | 02cab3e7 | Michael Hanselmann | if (eof or |
909 | 02cab3e7 | Michael Hanselmann | self.content_length is None or |
910 | 02cab3e7 | Michael Hanselmann | (self.content_length is not None and |
911 | 02cab3e7 | Michael Hanselmann | self.body_buffer.tell() >= self.content_length)): |
912 | 02cab3e7 | Michael Hanselmann | self.parser_status = self.PS_COMPLETE |
913 | 02cab3e7 | Michael Hanselmann | |
914 | 02cab3e7 | Michael Hanselmann | return buf
|
915 | 02cab3e7 | Michael Hanselmann | |
916 | 02cab3e7 | Michael Hanselmann | def _CheckStartLineLength(self, length): |
917 | 02cab3e7 | Michael Hanselmann | """Limits the start line buffer size.
|
918 | 02cab3e7 | Michael Hanselmann |
|
919 | 02cab3e7 | Michael Hanselmann | @type length: int
|
920 | 02cab3e7 | Michael Hanselmann | @param length: Buffer size
|
921 | 02cab3e7 | Michael Hanselmann |
|
922 | 02cab3e7 | Michael Hanselmann | """
|
923 | 02cab3e7 | Michael Hanselmann | if (self.START_LINE_LENGTH_MAX is not None and |
924 | 02cab3e7 | Michael Hanselmann | length > self.START_LINE_LENGTH_MAX):
|
925 | 02cab3e7 | Michael Hanselmann | raise HttpError("Start line longer than %d chars" % |
926 | 02cab3e7 | Michael Hanselmann | self.START_LINE_LENGTH_MAX)
|
927 | 02cab3e7 | Michael Hanselmann | |
928 | 02cab3e7 | Michael Hanselmann | def _CheckHeaderLength(self, length): |
929 | 02cab3e7 | Michael Hanselmann | """Limits the header buffer size.
|
930 | 02cab3e7 | Michael Hanselmann |
|
931 | 02cab3e7 | Michael Hanselmann | @type length: int
|
932 | 02cab3e7 | Michael Hanselmann | @param length: Buffer size
|
933 | 02cab3e7 | Michael Hanselmann |
|
934 | 02cab3e7 | Michael Hanselmann | """
|
935 | 02cab3e7 | Michael Hanselmann | if (self.HEADER_LENGTH_MAX is not None and |
936 | 02cab3e7 | Michael Hanselmann | length > self.HEADER_LENGTH_MAX):
|
937 | 02cab3e7 | Michael Hanselmann | raise HttpError("Headers longer than %d chars" % self.HEADER_LENGTH_MAX) |
938 | 02cab3e7 | Michael Hanselmann | |
939 | 02cab3e7 | Michael Hanselmann | def ParseStartLine(self, start_line): |
940 | 02cab3e7 | Michael Hanselmann | """Parses the start line of a message.
|
941 | 02cab3e7 | Michael Hanselmann |
|
942 | 5bbd3f7f | Michael Hanselmann | Must be overridden by subclass.
|
943 | 02cab3e7 | Michael Hanselmann |
|
944 | 02cab3e7 | Michael Hanselmann | @type start_line: string
|
945 | 02cab3e7 | Michael Hanselmann | @param start_line: Start line string
|
946 | 02cab3e7 | Michael Hanselmann |
|
947 | 02cab3e7 | Michael Hanselmann | """
|
948 | 02cab3e7 | Michael Hanselmann | raise NotImplementedError() |
949 | 02cab3e7 | Michael Hanselmann | |
950 | 02cab3e7 | Michael Hanselmann | def _WillPeerCloseConnection(self): |
951 | 02cab3e7 | Michael Hanselmann | """Evaluate whether peer will close the connection.
|
952 | 02cab3e7 | Michael Hanselmann |
|
953 | 02cab3e7 | Michael Hanselmann | @rtype: bool
|
954 | 02cab3e7 | Michael Hanselmann | @return: Whether peer will close the connection
|
955 | 02cab3e7 | Michael Hanselmann |
|
956 | 02cab3e7 | Michael Hanselmann | """
|
957 | 02cab3e7 | Michael Hanselmann | # RFC2616, section 14.10: "HTTP/1.1 defines the "close" connection option
|
958 | 02cab3e7 | Michael Hanselmann | # for the sender to signal that the connection will be closed after
|
959 | 02cab3e7 | Michael Hanselmann | # completion of the response. For example,
|
960 | 02cab3e7 | Michael Hanselmann | #
|
961 | 02cab3e7 | Michael Hanselmann | # Connection: close
|
962 | 02cab3e7 | Michael Hanselmann | #
|
963 | 02cab3e7 | Michael Hanselmann | # in either the request or the response header fields indicates that the
|
964 | 02cab3e7 | Michael Hanselmann | # connection SHOULD NOT be considered `persistent' (section 8.1) after the
|
965 | 02cab3e7 | Michael Hanselmann | # current request/response is complete."
|
966 | 02cab3e7 | Michael Hanselmann | |
967 | 02cab3e7 | Michael Hanselmann | hdr_connection = self.msg.headers.get(HTTP_CONNECTION, None) |
968 | 02cab3e7 | Michael Hanselmann | if hdr_connection:
|
969 | 02cab3e7 | Michael Hanselmann | hdr_connection = hdr_connection.lower() |
970 | 02cab3e7 | Michael Hanselmann | |
971 | 02cab3e7 | Michael Hanselmann | # An HTTP/1.1 server is assumed to stay open unless explicitly closed.
|
972 | 02cab3e7 | Michael Hanselmann | if self.msg.start_line.version == HTTP_1_1: |
973 | 02cab3e7 | Michael Hanselmann | return (hdr_connection and "close" in hdr_connection) |
974 | 02cab3e7 | Michael Hanselmann | |
975 | 02cab3e7 | Michael Hanselmann | # Some HTTP/1.0 implementations have support for persistent connections,
|
976 | 02cab3e7 | Michael Hanselmann | # using rules different than HTTP/1.1.
|
977 | 02cab3e7 | Michael Hanselmann | |
978 | 02cab3e7 | Michael Hanselmann | # For older HTTP, Keep-Alive indicates persistent connection.
|
979 | 02cab3e7 | Michael Hanselmann | if self.msg.headers.get(HTTP_KEEP_ALIVE): |
980 | 02cab3e7 | Michael Hanselmann | return False |
981 | 02cab3e7 | Michael Hanselmann | |
982 | 02cab3e7 | Michael Hanselmann | # At least Akamai returns a "Connection: Keep-Alive" header, which was
|
983 | 02cab3e7 | Michael Hanselmann | # supposed to be sent by the client.
|
984 | 02cab3e7 | Michael Hanselmann | if hdr_connection and "keep-alive" in hdr_connection: |
985 | 02cab3e7 | Michael Hanselmann | return False |
986 | 02cab3e7 | Michael Hanselmann | |
987 | 02cab3e7 | Michael Hanselmann | return True |
988 | 02cab3e7 | Michael Hanselmann | |
989 | 02cab3e7 | Michael Hanselmann | def _ParseHeaders(self): |
990 | 02cab3e7 | Michael Hanselmann | """Parses the headers.
|
991 | 02cab3e7 | Michael Hanselmann |
|
992 | 02cab3e7 | Michael Hanselmann | This function also adjusts internal variables based on header values.
|
993 | 02cab3e7 | Michael Hanselmann |
|
994 | 25e7b43f | Iustin Pop | RFC2616, section 4.3: The presence of a message-body in a request is
|
995 | 02cab3e7 | Michael Hanselmann | signaled by the inclusion of a Content-Length or Transfer-Encoding header
|
996 | 25e7b43f | Iustin Pop | field in the request's message-headers.
|
997 | 02cab3e7 | Michael Hanselmann |
|
998 | 02cab3e7 | Michael Hanselmann | """
|
999 | 02cab3e7 | Michael Hanselmann | # Parse headers
|
1000 | 02cab3e7 | Michael Hanselmann | self.header_buffer.seek(0, 0) |
1001 | 02cab3e7 | Michael Hanselmann | self.msg.headers = mimetools.Message(self.header_buffer, 0) |
1002 | 02cab3e7 | Michael Hanselmann | |
1003 | 02cab3e7 | Michael Hanselmann | self.peer_will_close = self._WillPeerCloseConnection() |
1004 | 02cab3e7 | Michael Hanselmann | |
1005 | 02cab3e7 | Michael Hanselmann | # Do we have a Content-Length header?
|
1006 | 02cab3e7 | Michael Hanselmann | hdr_content_length = self.msg.headers.get(HTTP_CONTENT_LENGTH, None) |
1007 | 02cab3e7 | Michael Hanselmann | if hdr_content_length:
|
1008 | 02cab3e7 | Michael Hanselmann | try:
|
1009 | 02cab3e7 | Michael Hanselmann | self.content_length = int(hdr_content_length) |
1010 | 691744c4 | Iustin Pop | except (TypeError, ValueError): |
1011 | 02cab3e7 | Michael Hanselmann | self.content_length = None |
1012 | 02cab3e7 | Michael Hanselmann | if self.content_length is not None and self.content_length < 0: |
1013 | 02cab3e7 | Michael Hanselmann | self.content_length = None |
1014 | 02cab3e7 | Michael Hanselmann | |
1015 | 02cab3e7 | Michael Hanselmann | # if the connection remains open and a content-length was not provided,
|
1016 | 02cab3e7 | Michael Hanselmann | # then assume that the connection WILL close.
|
1017 | 02cab3e7 | Michael Hanselmann | if self.content_length is None: |
1018 | 02cab3e7 | Michael Hanselmann | self.peer_will_close = True |