Conversation
…oxies Only an http:// HTTPS_PROXY or HTTP_PROXY was used. An https://, socks5:// or socks5h:// value was ignored with a warning and allowed hosts were dialled directly, so a machine whose only route out is such a proxy reached nothing. An https:// proxy is now reached over TLS, verified against the system roots with the proxy's host as server name, and then gets the same CONNECT request and Proxy-Authorization header as an http:// one. socks5:// and socks5h:// use a small RFC 1928 client with RFC 1929 login from the URL's userinfo. socks5h:// sends the name. socks5:// sends the addresses nvx resolved and vetted, trying each in turn as dialVetted does, and a refused login is not repeated for the next address. The allowlist decision is unchanged and still happens before any upstream dial. Other schemes keep the warning and direct dial. No new dependency. vettedOrResolve is split out of dialVetted so the socks5:// path re-resolves an empty answer through the same link-local check.
…-upstream-proxy # Conflicts: # CHANGELOG.md
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes
Only an
http://value inHTTPS_PROXY/HTTP_PROXYwas used. Anhttps://,socks5://orsocks5h://value was ignored with a warning, and allowed hosts were dialled directly. A machine whose only route out is such a proxy reached nothing from a contained install.https://. TLS to the proxy, verified against the system roots with the proxy's host as server name (TLS 1.2 minimum). Then the same CONNECT andProxy-Authorizationashttp://. A proxy whose certificate fails verification never receives the CONNECT or the credential. Default port 443.socks5h://. Minimal RFC 1928 CONNECT with the destination name. Default port 1080.socks5://. Same client, sending the addresses nvx resolved and vetted (each in turn, asdialVetteddoes). An empty answer is re-resolved through the same link-local check viavettedOrResolve, split out ofdialVetted.socks4://, unknown) keep the warning and the direct dial.go.sumstays empty.Tests
internal/nvx/egress_upstream_tls_socks_test.go, with in-process fake upstreams:TestAllowedConnectGoesThroughAnHTTPSUpstreamProxy. httptest TLS proxy with its CA handed in throughupstreamProxy.rootCAs. Checks the CONNECT target andProxy-Authorization, the echoed tunnel bytes, and that a refused host gets 403 with no second connection to the proxy.TestHTTPSUpstreamProxyWithABadCertificateIsRefused. Untrusted CA, and a trusted certificate that does not name the host. Both give 502, the proxy was dialled, and no CONNECT reached it.TestAllowedConnectGoesThroughASOCKS5hUpstreamProxy. Exact greeting and domain-type request bytes, the tunnel, refusal before dial.TestAllowedConnectGoesThroughASOCKS5UpstreamProxyWithLogin. Exact greeting, RFC 1929 login and IPv4 request bytes for the vetted address, the tunnel, refusal before dial.TestSOCKS5UpstreamLoginIsTriedOnce. Two resolved addresses with a wrong password give one login attempt and a 502.TestUpstreamProxySchemes. Accepted schemes and default ports.All six fail against main's
egress_upstream.goandegress_resolve.go. Disabling the allowlist check inhandleHTTPConnfails the three refusal assertions. Removing the login-retry guard failsTestSOCKS5UpstreamLoginIsTriedOnce.Local, Windows:
gofmt -l internal cmdempty,go vet ./...and withGOOS=linux/GOOS=darwinclean,go test ./internal/nvx -count=1ok.site/is not touched here.limitations.mdandpolicy.mdstill describe the http-only behaviour.