websocket.py 8.6 KB


  1. #!/usr/bin/python
  2. '''
  3. Python WebSocket library with support for "wss://" encryption.
  4. Copyright 2010 Joel Martin
  5. Licensed under LGPL version 3 (see docs/LICENSE.LGPL-3)
  6. You can make a cert/key with openssl using:
  7. openssl req -new -x509 -days 365 -nodes -out self.pem -keyout self.pem
  8. as taken from http://docs.python.org/dev/library/ssl.html#certificates
  9. '''
  10. import sys, socket, ssl, struct, traceback
  11. import os, resource, errno, signal # daemonizing
  12. from SimpleHTTPServer import SimpleHTTPRequestHandler
  13. from cStringIO import StringIO
  14. from base64 import b64encode, b64decode
  15. try:
  16. from hashlib import md5
  17. except:
  18. from md5 import md5 # Support python 2.4
  19. from urlparse import urlsplit
  20. from cgi import parse_qsl
  21. settings = {
  22. 'verbose' : False,
  23. 'listen_host' : '',
  24. 'listen_port' : None,
  25. 'handler' : None,
  26. 'handler_id' : 1,
  27. 'cert' : None,
  28. 'key' : None,
  29. 'ssl_only' : False,
  30. 'daemon' : True,
  31. 'record' : None,
  32. 'web' : False, }
  33. server_handshake = """HTTP/1.1 101 Web Socket Protocol Handshake\r
  34. Upgrade: WebSocket\r
  35. Connection: Upgrade\r
  36. %sWebSocket-Origin: %s\r
  37. %sWebSocket-Location: %s://%s%s\r
  38. %sWebSocket-Protocol: sample\r
  39. \r
  40. %s"""
  41. policy_response = """<cross-domain-policy><allow-access-from domain="*" to-ports="*" /></cross-domain-policy>\n"""
  42. class EClose(Exception):
  43. pass
  44. # HTTP handler with request from a string and response to a socket
  45. class SplitHTTPHandler(SimpleHTTPRequestHandler):
  46. def __init__(self, req, resp, addr):
  47. # Save the response socket
  48. self.response = resp
  49. SimpleHTTPRequestHandler.__init__(self, req, addr, object())
  50. def setup(self):
  51. self.connection = self.response
  52. # Duck type request string to file object
  53. self.rfile = StringIO(self.request)
  54. self.wfile = self.connection.makefile('wb', self.wbufsize)
  55. def send_response(self, code, message=None):
  56. # Save the status code
  57. self.last_code = code
  58. SimpleHTTPRequestHandler.send_response(self, code, message)
  59. def log_message(self, f, *args):
  60. # Save instead of printing
  61. self.last_message = f % args
  62. def traffic(token="."):
  63. if settings['verbose'] and not settings['daemon']:
  64. sys.stdout.write(token)
  65. sys.stdout.flush()
  66. def handler_msg(msg):
  67. if not settings['daemon']:
  68. print "% 3d: %s" % (settings['handler_id'], msg)
  69. def handler_vmsg(msg):
  70. if settings['verbose']: handler_msg(msg)
  71. def encode(buf):
  72. buf = b64encode(buf)
  73. return "\x00%s\xff" % buf
  74. def decode(buf):
  75. """ Parse out WebSocket packets. """
  76. if buf.count('\xff') > 1:
  77. return [b64decode(d[1:]) for d in buf.split('\xff')]
  78. else:
  79. return [b64decode(buf[1:-1])]
  80. def parse_handshake(handshake):
  81. ret = {}
  82. req_lines = handshake.split("\r\n")
  83. if not req_lines[0].startswith("GET "):
  84. raise Exception("Invalid handshake: no GET request line")
  85. ret['path'] = req_lines[0].split(" ")[1]
  86. for line in req_lines[1:]:
  87. if line == "": break
  88. var, val = line.split(": ")
  89. ret[var] = val
  90. if req_lines[-2] == "":
  91. ret['key3'] = req_lines[-1]
  92. return ret
  93. def gen_md5(keys):
  94. key1 = keys['Sec-WebSocket-Key1']
  95. key2 = keys['Sec-WebSocket-Key2']
  96. key3 = keys['key3']
  97. spaces1 = key1.count(" ")
  98. spaces2 = key2.count(" ")
  99. num1 = int("".join([c for c in key1 if c.isdigit()])) / spaces1
  100. num2 = int("".join([c for c in key2 if c.isdigit()])) / spaces2
  101. return md5(struct.pack('>II8s', num1, num2, key3)).digest()
  102. def do_handshake(sock, address):
  103. stype = ""
  104. # Peek, but don't read the data
  105. handshake = sock.recv(1024, socket.MSG_PEEK)
  106. #handler_msg("Handshake [%s]" % repr(handshake))
  107. if handshake == "":
  108. raise EClose("ignoring empty handshake")
  109. elif handshake.startswith("<policy-file-request/>"):
  110. handshake = sock.recv(1024)
  111. sock.send(policy_response)
  112. raise EClose("Sending flash policy response")
  113. elif handshake[0] in ("\x16", "\x80"):
  114. if not os.path.exists(settings['cert']):
  115. raise EClose("SSL connection but '%s' not found"
  116. % settings['cert'])
  117. try:
  118. retsock = ssl.wrap_socket(
  119. sock,
  120. server_side=True,
  121. certfile=settings['cert'],
  122. keyfile=settings['key'])
  123. except ssl.SSLError, x:
  124. if x.args[0] == ssl.SSL_ERROR_EOF:
  125. raise EClose("")
  126. else:
  127. raise
  128. scheme = "wss"
  129. stype = "SSL/TLS (wss://)"
  130. elif settings['ssl_only']:
  131. raise EClose("non-SSL connection received but disallowed")
  132. else:
  133. retsock = sock
  134. scheme = "ws"
  135. stype = "Plain non-SSL (ws://)"
  136. # Now get the data from the socket
  137. handshake = retsock.recv(4096)
  138. #handler_msg("handshake: " + repr(handshake))
  139. if len(handshake) == 0:
  140. raise EClose("Client closed during handshake")
  141. # Handle normal web requests
  142. if handshake.startswith('GET ') and \
  143. handshake.find('Upgrade: WebSocket\r\n') == -1:
  144. if not settings['web']:
  145. raise EClose("Normal web request received but disallowed")
  146. sh = SplitHTTPHandler(handshake, retsock, address)
  147. if sh.last_code < 200 or sh.last_code >= 300:
  148. raise EClose(sh.last_message)
  149. elif settings['verbose']:
  150. raise EClose(sh.last_message)
  151. else:
  152. raise EClose("")
  153. # Do WebSockets handshake and return the socket
  154. h = parse_handshake(handshake)
  155. if h.get('key3'):
  156. trailer = gen_md5(h)
  157. pre = "Sec-"
  158. ver = 76
  159. else:
  160. trailer = ""
  161. pre = ""
  162. ver = 75
  163. handler_msg("%s WebSocket connection (version %s) from %s"
  164. % (stype, ver, address[0]))
  165. response = server_handshake % (pre, h['Origin'], pre, scheme,
  166. h['Host'], h['path'], pre, trailer)
  167. #handler_msg("sending response:", repr(response))
  168. retsock.send(response)
  169. return retsock
  170. def daemonize(keepfd=None):
  171. os.umask(0)
  172. os.chdir('/')
  173. os.setgid(os.getgid()) # relinquish elevations
  174. os.setuid(os.getuid()) # relinquish elevations
  175. # Double fork to daemonize
  176. if os.fork() > 0: os._exit(0) # Parent exits
  177. os.setsid() # Obtain new process group
  178. if os.fork() > 0: os._exit(0) # Parent exits
  179. # Signal handling
  180. def terminate(a,b): os._exit(0)
  181. signal.signal(signal.SIGTERM, terminate)
  182. signal.signal(signal.SIGINT, signal.SIG_IGN)
  183. # Close open files
  184. maxfd = resource.getrlimit(resource.RLIMIT_NOFILE)[1]
  185. if maxfd == resource.RLIM_INFINITY: maxfd = 256
  186. for fd in reversed(range(maxfd)):
  187. try:
  188. if fd != keepfd:
  189. os.close(fd)
  190. else:
  191. handler_vmsg("Keeping fd: %d" % fd)
  192. except OSError, exc:
  193. if exc.errno != errno.EBADF: raise
  194. # Redirect I/O to /dev/null
  195. os.dup2(os.open(os.devnull, os.O_RDWR), sys.stdin.fileno())
  196. os.dup2(os.open(os.devnull, os.O_RDWR), sys.stdout.fileno())
  197. os.dup2(os.open(os.devnull, os.O_RDWR), sys.stderr.fileno())
  198. def start_server():
  199. lsock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
  200. lsock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  201. lsock.bind((settings['listen_host'], settings['listen_port']))
  202. lsock.listen(100)
  203. if settings['daemon']:
  204. daemonize(keepfd=lsock.fileno())
  205. # Reep zombies
  206. signal.signal(signal.SIGCHLD, signal.SIG_IGN)
  207. print 'Waiting for connections on %s:%s' % (
  208. settings['listen_host'], settings['listen_port'])
  209. while True:
  210. try:
  211. csock = startsock = None
  212. pid = 0
  213. startsock, address = lsock.accept()
  214. handler_vmsg('%s: forking handler' % address[0])
  215. pid = os.fork()
  216. if pid == 0: # handler process
  217. csock = do_handshake(startsock, address)
  218. settings['handler'](csock)
  219. else: # parent process
  220. settings['handler_id'] += 1
  221. except EClose, exc:
  222. if csock and csock != startsock:
  223. csock.close()
  224. startsock.close()
  225. if exc.args[0]:
  226. handler_msg("%s: %s" % (address[0], exc.args[0]))
  227. except Exception, exc:
  228. handler_msg("handler exception: %s" % str(exc))
  229. if settings['verbose']:
  230. handler_msg(traceback.format_exc())
  231. if pid == 0:
  232. if csock: csock.close()
  233. if startsock and startsock != csock: startsock.close()
  234. break # Child process exits