fune/toolkit/components/extensions/test/xpcshell/test_ext_dns.js
Manuel Bucher 5205854e55 Bug 1741375 - Proxy DNS by default when using SOCKS v5 r=necko-reviewers,extension-reviewers,kershaw,perftest-reviewers,robwu,sparky
Initially reported and discussed in Bug 610896.

The simple solution of just flipping the pref `network.proxy.socks_remote_dns`
is risky due to potentially breaking SOCKS4 proxy users.  Proxying
DNS on SOCKS4 isn't supported.  Therefore we speak the incompatible
SOCKS4a protocol when `socks_remote_dns` is enabled, potentially
breaking users setup.

To keep backwards compatibility on SOCKS4 proxy users, that don't have
SOCKS4a support, the pref `network.proxy.socks_remote_dns` is split into
two prefs:

* `network.proxy.socks_remote_dns`: remote DNS for SOCKS4
* `network.proxy.socks5_remote_dns`: remote DNS for SOCKS5.

This way we proxy DNS by default on SOCKS5 while keeping user settings
on SOCKS4.  This is a similar approach to the one described in
[Bug 610896 comment 17].

Proxying DNS in SOCKS4 by default is desireable (See [Bug 610896 comment 11]),
but out of scope for this patch.  [Telemetry] on proxy usage by socks
version indicated that changing the default for SOCKS4 is likely break
some users setup and needs to be taken with more care.

The default values of [proxyDNS] now defaults to true for SOCKS5 proxies.
When creating nsIProxyInfo objects of SOCKS4 proxies, the default value
false is kept.  Setting proxyDNS affects both SOCKS4 and SOCKS5 proxy by
modifying both `socks_remote_dns` and `socks5_remote_dns`.  Therefore no
extension breakage is expected.

The enterprise policy can also modify the new pref
`network.proxy.socks5_remote_dns`.

Follow up bugs filed while implementing:

* Bug 1890542 - Also disable Prefetch non-manual configurations of socks
                proxy
* Bug 1890554 - Use `ProxyInfo::TRANSPARENT_PROXY_RESOLVES_HOST` flag in
                `nsHttpChannel::GetProxyDNSStrategy`
* Bug 1890549 - nsHttpChannel implementation DNS resolve strategy for
                proxies incomplete
* Bug 1893670 - Proxy DNS by default for SOCK4 proxies. Defaulting to
                SOCKS4a

[Bug 610896 comment 17]: https://bugzilla.mozilla.org/show_bug.cgi?id=610896#c17
[Bug 610896 comment 11]: https://bugzilla.mozilla.org/show_bug.cgi?id=610896#c11
[Telemetry]: https://bugzilla.mozilla.org/show_bug.cgi?id=1741375#c27
[proxyDNS]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/API/proxy/settings#proxydns

Differential Revision: https://phabricator.services.mozilla.com/D207532
2024-05-21 11:55:26 +00:00

181 lines
4.5 KiB
JavaScript

"use strict";
// Some test machines and android are not returning ipv6, turn it
// off to get consistent test results.
Services.prefs.setBoolPref("network.dns.disableIPv6", true);
AddonTestUtils.init(this);
AddonTestUtils.overrideCertDB();
AddonTestUtils.createAppInfo(
"xpcshell@tests.mozilla.org",
"XPCShell",
"1",
"42"
);
function getExtension() {
let manifest = {
permissions: ["dns", "proxy"],
};
return ExtensionTestUtils.loadExtension({
manifest,
background() {
browser.test.onMessage.addListener(async (msg, data) => {
if (msg == "proxy") {
await browser.proxy.settings.set({ value: data });
browser.test.sendMessage("proxied");
return;
}
browser.test.log(`=== dns resolve test ${JSON.stringify(data)}`);
browser.dns
.resolve(data.hostname, data.flags)
.then(result => {
browser.test.log(
`=== dns resolve result ${JSON.stringify(result)}`
);
browser.test.sendMessage("resolved", result);
})
.catch(e => {
browser.test.log(`=== dns resolve error ${e.message}`);
browser.test.sendMessage("resolved", { message: e.message });
});
});
browser.test.sendMessage("ready");
},
incognitoOverride: "spanning",
useAddonManager: "temporary",
});
}
const tests = [
{
request: {
hostname: "localhost",
},
expect: {
addresses: ["127.0.0.1"], // ipv6 disabled , "::1"
},
},
{
request: {
hostname: "localhost",
flags: ["offline"],
},
expect: {
addresses: ["127.0.0.1"], // ipv6 disabled , "::1"
},
},
{
request: {
hostname: "test.example",
},
expect: {
// android will error with offline
error: /NS_ERROR_UNKNOWN_HOST|NS_ERROR_OFFLINE/,
},
},
{
request: {
hostname: "127.0.0.1",
flags: ["canonical_name"],
},
expect: {
canonicalName: "127.0.0.1",
addresses: ["127.0.0.1"],
},
},
{
request: {
hostname: "localhost",
flags: ["disable_ipv6"],
},
expect: {
addresses: ["127.0.0.1"],
},
},
];
add_setup(async function startup() {
await AddonTestUtils.promiseStartupManager();
});
add_task(async function test_dns_resolve() {
let extension = getExtension();
await extension.startup();
await extension.awaitMessage("ready");
for (let test of tests) {
extension.sendMessage("resolve", test.request);
let result = await extension.awaitMessage("resolved");
if (test.expect.error) {
ok(
test.expect.error.test(result.message),
`expected error ${result.message}`
);
} else {
equal(
result.canonicalName,
test.expect.canonicalName,
"canonicalName match"
);
// It seems there are platform differences happening that make this
// testing difficult. We're going to rely on other existing dns tests to validate
// the dns service itself works and only validate that we're getting generally
// expected results in the webext api.
Assert.greaterOrEqual(
result.addresses.length,
test.expect.addresses.length,
"expected number of addresses returned"
);
if (test.expect.addresses.length && result.addresses.length) {
ok(
result.addresses.includes(test.expect.addresses[0]),
"got expected ip address"
);
}
}
}
await extension.unload();
});
add_task(async function test_dns_resolve_socks() {
let extension = getExtension();
await extension.startup();
await extension.awaitMessage("ready");
extension.sendMessage("proxy", {
proxyType: "manual",
socks: "127.0.0.1",
socksVersion: 5,
proxyDNS: true,
});
await extension.awaitMessage("proxied");
equal(
Services.prefs.getIntPref("network.proxy.type"),
1 /* PROXYCONFIG_MANUAL */,
"manual proxy"
);
equal(
Services.prefs.getStringPref("network.proxy.socks"),
"127.0.0.1",
"socks proxy"
);
ok(
Services.prefs.getBoolPref("network.proxy.socks_remote_dns"),
"socks4 remote dns"
);
ok(
Services.prefs.getBoolPref("network.proxy.socks5_remote_dns"),
"socks5 remote dns"
);
extension.sendMessage("resolve", {
hostname: "mozilla.org",
});
let result = await extension.awaitMessage("resolved");
ok(
/NS_ERROR_UNKNOWN_PROXY_HOST/.test(result.message),
`expected error ${result.message}`
);
await extension.unload();
});