BlockingSSL.java
/*
** Module : BlockingSSL.java
** Abstract : Implements SSL support over the blocking SocketChannel.
**
** Copyright (c) 2016-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ---------------------------------------Description---------------------------------------
** 001 IAS 20160805 Initial version
** 002 IAS 20200729 Improve logging
** 003 IAS 20210827 Fixed sporadic SSL failures
** 004 GBB 20230512 Logging methods replaced by CentralLogger/ConversionStatus.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
** Under Section 7 of the GNU Affero GPL version 3, the following additional
** terms apply to the works covered under the License. These additional terms
** are non-permissive additional terms allowed under Section 7 of the GNU
** Affero GPL version 3 and may not be removed by you.
**
** 0. Attribution Requirement.
**
** You must preserve all legal notices or author attributions in the covered
** work or Appropriate Legal Notices displayed by works containing the covered
** work. You may not remove from the covered work any author or developer
** credit already included within the covered work.
**
** 1. No License To Use Trademarks.
**
** This license does not grant any license or rights to use the trademarks
** Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
** of Golden Code Development Corporation. You are not authorized to use the
** name Golden Code, FWD, or the names of any author or contributor, for
** publicity purposes without written authorization.
**
** 2. No Misrepresentation of Affiliation.
**
** You may not represent yourself as Golden Code Development Corporation or FWD.
**
** You may not represent yourself for publicity purposes as associated with
** Golden Code Development Corporation, FWD, or any author or contributor to
** the covered work, without written authorization.
**
** 3. No Misrepresentation of Source or Origin.
**
** You may not represent the covered work as solely your work. All modified
** versions of the covered work must be marked in a reasonable way to make it
** clear that the modified work is not originating from Golden Code Development
** Corporation or FWD. All modified versions must contain the notices of
** attribution required in this license.
*/
package com.goldencode.p2j.net;
import java.io.*;
import java.nio.*;
import java.nio.channels.*;
import java.util.concurrent.*;
import java.util.logging.*;
import javax.net.ssl.*;
import com.goldencode.p2j.util.logging.CentralLogger;
/**
* Implements SSL support over the SocketChannel.
*/
public abstract class BlockingSSL
extends SSL
{
/** Logger */
protected static final CentralLogger LOG = CentralLogger.get(BlockingSSL.class.getName(), true, true);
/** Underlying SocketChannel */
protected final SocketChannel channel;
/** Input buffer */
protected final ByteBuffer buffer = ByteBuffer.allocateDirect(16 * 1024);
/**
* Constructor
*
* @param channel
* underlying SocketChannel
* @param engine
* the SSLEngine instance
* @param fsmWorkers
* ExecutorService for internal tasks' execution
*/
public BlockingSSL(SocketChannel channel, SSLEngine engine, ExecutorService fsmWorkers)
{
super(engine, fsmWorkers);
this.channel = channel;
}
/**
* Check if more input is available for processing
*/
@Override
public void checkInput() throws IOException
{
if (!processInput())
{
throw new EOFException();
}
}
/**
* Process the next portion of the encrypted output
*
* @param encrypted
* the next portion of the encrypted output
*/
@Override
public void onOutput(ByteBuffer encrypted)
{
int len = encrypted.limit();
log("About to send %d bytes", len);
try
{
while (encrypted.hasRemaining())
{
channel.write(encrypted);
log("%d/%d bytes sent", encrypted.position(), len);
}
}
catch (IOException exc)
{
throw new IllegalStateException(exc);
}
log("%d bytes sent OK", len);
}
/**
* Called on the SSL session close
*/
@Override
public void onClosed()
{
System.out.println("ssl session closed");
fsmWorkers.shutdownNow();
}
/**
* Process the next portion of the output
*
* @param data
* the next portion of the output
*/
@Override
public void send(final ByteBuffer data)
{
super.send(data);
}
/**
* Report the handshake failure
*
* @param ex
* The exception which caused the failure
*/
@Override
public void onFailure(Exception ex)
{
if (done.compareAndSet(false, true))
{
LOG.log(Level.WARNING, "handshake failure", ex);
LOG.log(Level.FINE, "done");
}
else
{
LOG.log(Level.WARNING, "SSL operation failure", ex);
try
{
channel.close();
}
catch (IOException e)
{
LOG.log(Level.WARNING, "Failed to close channel", ex);
}
}
}
/**
* Try to get new portion of the input
*
* @return <code>true</code> if more input is available
*/
private boolean processInput()
{
buffer.clear();
int bytes;
try
{
bytes = channel.read(buffer);
}
catch(AsynchronousCloseException e)
{
LOG.log(Level.FINE, "Connection closed");
bytes = -1;
}
catch (IOException ex)
{
LOG.log(Level.WARNING, "Network I/O failed", ex);
bytes = -1;
}
if (bytes == -1)
{
return false;
}
if (bytes == 0)
{
return true;
}
if (LOG.isLoggable(Level.FINE))
{
LOG.log(Level.FINE, String.format( "%d bytes read", bytes));
}
buffer.flip();
ByteBuffer copy = ByteBuffer.allocate(bytes);
copy.put(buffer);
copy.flip();
this.notify(copy);
return true;
}
}