diff --git a/CHANGELOG.md b/CHANGELOG.md index 3a8811d..adac210 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,9 @@ # Changelog +## 0.6.0 +- **Updated**: Slightly changed API of the framework. +- **Fixed**: Reading packets issue affecting on connection when network interface is changed. + ## 0.5.0 - **Added**: Swift Package Manager support; - **Updated**: openvpn3 library – 3.5.4 version; diff --git a/OpenVPNAdapter.podspec b/OpenVPNAdapter.podspec index 37bb028..3cc20df 100644 --- a/OpenVPNAdapter.podspec +++ b/OpenVPNAdapter.podspec @@ -3,7 +3,7 @@ Pod::Spec.new do |s| # ――― Spec Metadata ―――――――――――――――――――――――――――――――――――――――――――――――――――――――――― # s.name = "OpenVPNAdapter" - s.version = "0.5.1" + s.version = "0.6.0" s.summary = "Objective-C wrapper for OpenVPN library. Compatible with iOS and macOS." s.description = <<-DESC OpenVPNAdapter is an Objective-C framework that allows to easily configure and establish VPN connection using OpenVPN protocol. diff --git a/OpenVPNAdapter.xcodeproj/project.pbxproj b/OpenVPNAdapter.xcodeproj/project.pbxproj index 6134291..31292a3 100644 --- a/OpenVPNAdapter.xcodeproj/project.pbxproj +++ b/OpenVPNAdapter.xcodeproj/project.pbxproj @@ -1524,7 +1524,7 @@ "$(inherited)", "$(TOOLCHAIN_DIR)/usr/lib/swift/macosx", ); - MARKETING_VERSION = 0.5.1; + MARKETING_VERSION = 0.6.0; OTHER_SWIFT_FLAGS = "$(inherited)"; PRODUCT_BUNDLE_IDENTIFIER = OpenVPNAdapter; PRODUCT_MODULE_NAME = "$(TARGET_NAME:c99extidentifier)"; @@ -1553,7 +1553,7 @@ "$(inherited)", "$(TOOLCHAIN_DIR)/usr/lib/swift/macosx", ); - MARKETING_VERSION = 0.5.1; + MARKETING_VERSION = 0.6.0; OTHER_SWIFT_FLAGS = "$(inherited)"; PRODUCT_BUNDLE_IDENTIFIER = OpenVPNAdapter; PRODUCT_MODULE_NAME = "$(TARGET_NAME:c99extidentifier)"; diff --git a/README.md b/README.md index c2f243e..428e4ea 100644 --- a/README.md +++ b/README.md @@ -141,6 +141,11 @@ Packet Tunnel Provider extension uses [`NEPacketTunnelProvider`](https://develop import NetworkExtension import OpenVPNAdapter +// Extend NEPacketTunnelFlow to adopt OpenVPNAdapterPacketFlow protocol so that +// `self.packetFlow` could be sent to `completionHandler` callback of OpenVPNAdapterDelegate +// method openVPNAdapter(openVPNAdapter:configureTunnelWithNetworkSettings:completionHandler). +extension NEPacketTunnelFlow: OpenVPNAdapterPacketFlow {} + class PacketTunnelProvider: NEPacketTunnelProvider { lazy var vpnAdapter: OpenVPNAdapter = { @@ -182,8 +187,8 @@ class PacketTunnelProvider: NEPacketTunnelProvider { // Additional parameters as key:value pairs may be provided here ] - // Add this line if you want to keep TUN interface active during pauses or reconnections - configuration.tunPersist = true + // Uncomment this line if you want to keep TUN interface active during pauses or reconnections + // configuration.tunPersist = true // Apply OpenVPN configuration let properties: OpenVPNProperties @@ -226,13 +231,13 @@ class PacketTunnelProvider: NEPacketTunnelProvider { // WiFi the adapter still uses cellular data. Changing reachability forces // reconnection so the adapter will use actual connection. vpnReachability.startTracking { [weak self] status in - guard status != .notReachable else { return } + guard status == .reachableViaWiFi else { return } self?.vpnAdapter.reconnect(interval: 5) } // Establish connection and wait for .connected event startHandler = completionHandler - vpnAdapter.connect() + vpnAdapter.connect(using: packetFlow) } override func stopTunnel(with reason: NEProviderStopReason, completionHandler: @escaping () -> Void) { @@ -255,15 +260,13 @@ extension PacketTunnelProvider: OpenVPNAdapterDelegate { // `OpenVPNAdapterPacketFlow` method signatures are similar to `NEPacketTunnelFlow` so // you can just extend that class to adopt `OpenVPNAdapterPacketFlow` protocol and // send `self.packetFlow` to `completionHandler` callback. - func openVPNAdapter(_ openVPNAdapter: OpenVPNAdapter, configureTunnelWithNetworkSettings networkSettings: NEPacketTunnelNetworkSettings?, completionHandler: @escaping (OpenVPNAdapterPacketFlow?) -> Void) { + func openVPNAdapter(_ openVPNAdapter: OpenVPNAdapter, configureTunnelWithNetworkSettings networkSettings: NEPacketTunnelNetworkSettings?, completionHandler: @escaping (Error?) -> Void) { // In order to direct all DNS queries first to the VPN DNS servers before the primary DNS servers // send empty string to NEDNSSettings.matchDomains networkSettings?.dnsSettings?.matchDomains = [""] - // Specify the network settings for the current tunneling session. - setTunnelNetworkSettings(settings) { (error) in - completionHandler(error == nil ? self.packetFlow : nil) - } + // Set the network settings for the current tunneling session. + setTunnelNetworkSettings(networkSettings, completionHandler: completionHandler) } // Process events returned by the OpenVPN library @@ -322,11 +325,6 @@ extension PacketTunnelProvider: OpenVPNAdapterDelegate { } } - -// Extend NEPacketTunnelFlow to adopt OpenVPNAdapterPacketFlow protocol so that -// `self.packetFlow` could be sent to `completionHandler` callback of OpenVPNAdapterDelegate -// method openVPNAdapter(openVPNAdapter:configureTunnelWithNetworkSettings:completionHandler). -extension NEPacketTunnelFlow: OpenVPNAdapterPacketFlow {} ``` ## Contributing diff --git a/Sources/OpenVPNAdapter/library/OpenVPNAdapter.h b/Sources/OpenVPNAdapter/library/OpenVPNAdapter.h index 3105daa..70b007b 100644 --- a/Sources/OpenVPNAdapter/library/OpenVPNAdapter.h +++ b/Sources/OpenVPNAdapter/library/OpenVPNAdapter.h @@ -39,7 +39,7 @@ typedef NS_ENUM(NSInteger, OpenVPNAdapterEvent); */ - (void)openVPNAdapter:(OpenVPNAdapter *)openVPNAdapter configureTunnelWithNetworkSettings:(nullable NEPacketTunnelNetworkSettings *)networkSettings - completionHandler:(void (^)(id _Nullable packetFlow))completionHandler + completionHandler:(void (^)(NSError * _Nullable error))completionHandler NS_SWIFT_NAME(openVPNAdapter(_:configureTunnelWithNetworkSettings:completionHandler:)); /** @@ -149,8 +149,10 @@ NS_SWIFT_NAME(apply(configuration:)); /** Starts the tunnel. + + @param packetFlow The object implementing OpenVPNAdapterPacketFlow protocol. */ -- (void)connect; +- (void)connectUsingPacketFlow:(id)packetFlow NS_SWIFT_NAME(connect(using:)); /** Pauses the tunnel. diff --git a/Sources/OpenVPNAdapter/library/OpenVPNAdapter.mm b/Sources/OpenVPNAdapter/library/OpenVPNAdapter.mm index 5064fb4..44bc498 100644 --- a/Sources/OpenVPNAdapter/library/OpenVPNAdapter.mm +++ b/Sources/OpenVPNAdapter/library/OpenVPNAdapter.mm @@ -43,6 +43,7 @@ - (instancetype)init { if (self = [super init]) { _vpnClient = new OpenVPNClient(self); + _packetFlowBridge = [[OpenVPNPacketFlowBridge alloc] init]; } return self; } @@ -56,7 +57,7 @@ if (error) { NSString *message = [NSString stringWithUTF8String:eval.message.c_str()]; *error = [NSError ovpn_errorObjectForAdapterError:OpenVPNAdapterErrorConfigurationFailure - description:@"Failed to apply OpenVPN configuration" + description:@"Failed to apply OpenVPN configuration." message:message fatal:YES]; } @@ -74,7 +75,7 @@ if (error) { NSString *message = [NSString stringWithUTF8String:status.message.c_str()]; *error = [NSError ovpn_errorObjectForAdapterError:OpenVPNAdapterErrorCredentialsFailure - description:@"Failed to provide OpenVPN credentials" + description:@"Failed to provide OpenVPN credentials." message:message fatal:YES]; } @@ -85,9 +86,13 @@ return YES; } -- (void)connect { +- (void)connectUsingPacketFlow:(id)packetFlow { + NSAssert(self.delegate != nil, @"delegate property shouldn't be nil, set it before trying to establish connection."); + + self.packetFlowBridge.packetFlow = packetFlow; + dispatch_queue_attr_t attributes = dispatch_queue_attr_make_with_qos_class(DISPATCH_QUEUE_SERIAL, QOS_CLASS_UTILITY, 0); - dispatch_queue_t connectQueue = dispatch_queue_create("me.ss-abramchuk.openvpn-adapter.connection", attributes); + dispatch_queue_t connectQueue = dispatch_queue_create("me.ss-abramchuk.openvpn-adapter.connection.", attributes); dispatch_async(connectQueue, ^{ OpenVPNClient::init_process(); @@ -123,7 +128,7 @@ NSString *message = [NSString stringWithUTF8String:status.message.c_str()]; NSError *error = [NSError ovpn_errorObjectForAdapterError:adapterError - description:@"Failed to establish connection with OpenVPN server" + description:@"Failed to establish connection with OpenVPN server." message:message fatal:YES]; @@ -315,23 +320,35 @@ dispatch_semaphore_t semaphore = dispatch_semaphore_create(0); - __weak typeof(self) weakSelf = self; - void (^completionHandler)(id _Nullable) = ^(id flow) { - __strong typeof(self) self = weakSelf; - - if (flow) { - self.packetFlowBridge = [[OpenVPNPacketFlowBridge alloc] initWithPacketFlow:flow]; - } - + __block NSError *configurationError; + void (^completionHandler)(NSError *error) = ^(NSError *error) { + configurationError = error; dispatch_semaphore_signal(semaphore); }; [self.delegate openVPNAdapter:self configureTunnelWithNetworkSettings:networkSettings completionHandler:completionHandler]; - dispatch_semaphore_wait(semaphore, dispatch_time(DISPATCH_TIME_NOW, TUNNEL_CONFIGURATION_TIMEOUT * NSEC_PER_SEC)); + long timeout = dispatch_semaphore_wait(semaphore, dispatch_time(DISPATCH_TIME_NOW, TUNNEL_CONFIGURATION_TIMEOUT * NSEC_PER_SEC)); + if (timeout) { return NO; } + + if (configurationError) { + NSDictionary *userInfo = @{ + NSLocalizedDescriptionKey: @"Failed to configure tunnel using provided settings. Check underlying error for more details.", + NSUnderlyingErrorKey: configurationError, + OpenVPNAdapterErrorFatalKey: @(YES) + }; + + NSError *error = [NSError errorWithDomain:OpenVPNAdapterErrorDomain + code:OpenVPNAdapterErrorTUNSetupFailed + userInfo:userInfo]; + + [self.delegate openVPNAdapter:self handleError:error]; + + return NO; + } NSError *socketError; - if (self.packetFlowBridge && [self.packetFlowBridge configureSocketsWithError:&socketError]) { + if ([self.packetFlowBridge configureSocketsWithError:&socketError]) { [self.packetFlowBridge startReading]; return YES; } else { @@ -403,17 +420,33 @@ } - (void)resetTun { - _packetFlowBridge = nil; + [_packetFlowBridge invalidateSocketsIfNeeded]; dispatch_semaphore_t semaphore = dispatch_semaphore_create(0); - void (^completionHandler)(id _Nullable) = ^(id flow) { + __block NSError *configurationError; + void (^completionHandler)(NSError *error) = ^(NSError *error) { + configurationError = error; dispatch_semaphore_signal(semaphore); }; [self.delegate openVPNAdapter:self configureTunnelWithNetworkSettings:nil completionHandler:completionHandler]; dispatch_semaphore_wait(semaphore, dispatch_time(DISPATCH_TIME_NOW, TUNNEL_CONFIGURATION_TIMEOUT * NSEC_PER_SEC)); + + if (configurationError) { + NSDictionary *userInfo = @{ + NSLocalizedDescriptionKey: @"Failed to reset tunnel. Check underlying error for more details.", + NSUnderlyingErrorKey: configurationError, + OpenVPNAdapterErrorFatalKey: @(YES) + }; + + NSError *error = [NSError errorWithDomain:OpenVPNAdapterErrorDomain + code:OpenVPNAdapterErrorTUNSetupFailed + userInfo:userInfo]; + + [self.delegate openVPNAdapter:self handleError:error]; + } } #pragma mark - diff --git a/Sources/OpenVPNAdapter/library/OpenVPNPacketFlowBridge.h b/Sources/OpenVPNAdapter/library/OpenVPNPacketFlowBridge.h index 7f77b42..f99258f 100644 --- a/Sources/OpenVPNAdapter/library/OpenVPNPacketFlowBridge.h +++ b/Sources/OpenVPNAdapter/library/OpenVPNPacketFlowBridge.h @@ -14,13 +14,14 @@ NS_ASSUME_NONNULL_BEGIN @interface OpenVPNPacketFlowBridge: NSObject +@property (nonatomic, weak) id packetFlow; + @property (nonatomic, readonly) CFSocketRef openVPNSocket; @property (nonatomic, readonly) CFSocketRef packetFlowSocket; -- (instancetype)init NS_UNAVAILABLE; -- (instancetype)initWithPacketFlow:(id)packetFlow NS_DESIGNATED_INITIALIZER; - - (BOOL)configureSocketsWithError:(NSError **)error; +- (void)invalidateSocketsIfNeeded; + - (void)startReading; @end diff --git a/Sources/OpenVPNAdapter/library/OpenVPNPacketFlowBridge.mm b/Sources/OpenVPNAdapter/library/OpenVPNPacketFlowBridge.mm index 5b64e26..72e73c0 100644 --- a/Sources/OpenVPNAdapter/library/OpenVPNPacketFlowBridge.mm +++ b/Sources/OpenVPNAdapter/library/OpenVPNPacketFlowBridge.mm @@ -15,21 +15,8 @@ #import "OpenVPNPacket.h" #import "OpenVPNAdapterPacketFlow.h" -@interface OpenVPNPacketFlowBridge () - -@property (nonatomic) id packetFlow; - -@end - @implementation OpenVPNPacketFlowBridge -- (instancetype)initWithPacketFlow:(id)packetFlow { - if (self = [super init]) { - _packetFlow = packetFlow; - } - return self; -} - #pragma mark - Sockets Configuration static void SocketCallback(CFSocketRef socket, CFSocketCallBackType type, CFDataRef address, const void *data, void *obj) { @@ -46,7 +33,7 @@ static void SocketCallback(CFSocketRef socket, CFSocketCallBackType type, CFData if (socketpair(PF_LOCAL, SOCK_DGRAM, IPPROTO_IP, sockets) == -1) { if (error) { NSDictionary *userInfo = @{ - NSLocalizedDescriptionKey: @"Failed to create a pair of connected sockets", + NSLocalizedDescriptionKey: @"Failed to create a pair of connected sockets.", NSLocalizedFailureReasonErrorKey: [NSString stringWithUTF8String:strerror(errno)], OpenVPNAdapterErrorFatalKey: @(YES) }; @@ -68,7 +55,7 @@ static void SocketCallback(CFSocketRef socket, CFSocketCallBackType type, CFData if (!(_packetFlowSocket && _openVPNSocket)) { if (error) { NSDictionary *userInfo = @{ - NSLocalizedDescriptionKey: @"Failed to create core foundation sockets from native sockets", + NSLocalizedDescriptionKey: @"Failed to create core foundation sockets from native sockets.", OpenVPNAdapterErrorFatalKey: @(YES) }; @@ -99,7 +86,7 @@ static void SocketCallback(CFSocketRef socket, CFSocketCallBackType type, CFData if (setsockopt(socketHandle, SOL_SOCKET, SO_RCVBUF, &buf_value, buf_len) == -1) { if (error) { NSDictionary *userInfo = @{ - NSLocalizedDescriptionKey: @"Failed to setup buffer size for input", + NSLocalizedDescriptionKey: @"Failed to setup buffer size for input.", NSLocalizedFailureReasonErrorKey: [NSString stringWithUTF8String:strerror(errno)], OpenVPNAdapterErrorFatalKey: @(YES) }; @@ -115,7 +102,7 @@ static void SocketCallback(CFSocketRef socket, CFSocketCallBackType type, CFData if (setsockopt(socketHandle, SOL_SOCKET, SO_SNDBUF, &buf_value, buf_len) == -1) { if (error) { NSDictionary *userInfo = @{ - NSLocalizedDescriptionKey: @"Failed to setup buffer size for output", + NSLocalizedDescriptionKey: @"Failed to setup buffer size for output.", NSLocalizedFailureReasonErrorKey: [NSString stringWithUTF8String:strerror(errno)], OpenVPNAdapterErrorFatalKey: @(YES) }; @@ -131,7 +118,25 @@ static void SocketCallback(CFSocketRef socket, CFSocketCallBackType type, CFData return YES; } +- (void)invalidateSocketsIfNeeded { + if (_openVPNSocket) { + CFSocketInvalidate(_openVPNSocket); + CFRelease(_openVPNSocket); + + _openVPNSocket = NULL; + } + + if (_packetFlowSocket) { + CFSocketInvalidate(_packetFlowSocket); + CFRelease(_packetFlowSocket); + + _packetFlowSocket = NULL; + } +} + - (void)startReading { + NSAssert(self.packetFlow != nil, @"packetFlow property shouldn't be nil, set it before start reading packets."); + __weak typeof(self) weakSelf = self; [self.packetFlow readPacketsWithCompletionHandler:^(NSArray *packets, NSArray *protocols) { @@ -145,6 +150,8 @@ static void SocketCallback(CFSocketRef socket, CFSocketCallBackType type, CFData #pragma mark - TUN -> VPN - (void)writePackets:(NSArray *)packets protocols:(NSArray *)protocols toSocket:(CFSocketRef)socket { + if (socket == NULL) { return; } + [packets enumerateObjectsUsingBlock:^(NSData *data, NSUInteger idx, BOOL *stop) { NSNumber *protocolFamily = protocols[idx]; OpenVPNPacket *packet = [[OpenVPNPacket alloc] initWithPacketFlowData:data protocolFamily:protocolFamily]; @@ -156,6 +163,8 @@ static void SocketCallback(CFSocketRef socket, CFSocketCallBackType type, CFData #pragma mark - VPN -> TUN - (void)writePackets:(NSArray *)packets toPacketFlow:(id)packetFlow { + NSAssert(packetFlow != nil, @"packetFlow shouldn't be nil, check provided parameter before start writing packets."); + NSMutableArray *flowPackets = [[NSMutableArray alloc] init]; NSMutableArray *protocols = [[NSMutableArray alloc] init]; @@ -170,11 +179,7 @@ static void SocketCallback(CFSocketRef socket, CFSocketCallBackType type, CFData #pragma mark - - (void)dealloc { - CFSocketInvalidate(_openVPNSocket); - CFRelease(_openVPNSocket); - - CFSocketInvalidate(_packetFlowSocket); - CFRelease(_packetFlowSocket); + [self invalidateSocketsIfNeeded]; } @end diff --git a/Tests/OpenVPNAdapter/OpenVPNAdapterTests.swift b/Tests/OpenVPNAdapter/OpenVPNAdapterTests.swift index 11b7ec0..52d5e94 100644 --- a/Tests/OpenVPNAdapter/OpenVPNAdapterTests.swift +++ b/Tests/OpenVPNAdapter/OpenVPNAdapterTests.swift @@ -100,7 +100,7 @@ class OpenVPNAdapterTests: XCTestCase { expectations[.connection] = expectation(description: "me.ss-abramchuk.openvpn-adapter.connection") adapter.delegate = self - adapter.connect() + adapter.connect(using: customFlow) waitForExpectations(timeout: 30.0) { (error) in adapter.disconnect() @@ -110,9 +110,8 @@ class OpenVPNAdapterTests: XCTestCase { } extension OpenVPNAdapterTests: OpenVPNAdapterDelegate { - - func openVPNAdapter(_ openVPNAdapter: OpenVPNAdapter, configureTunnelWithNetworkSettings networkSettings: NEPacketTunnelNetworkSettings?, completionHandler: @escaping (OpenVPNAdapterPacketFlow?) -> Void) { - completionHandler(customFlow) + func openVPNAdapter(_ openVPNAdapter: OpenVPNAdapter, configureTunnelWithNetworkSettings networkSettings: NEPacketTunnelNetworkSettings?, completionHandler: @escaping (Error?) -> Void) { + completionHandler(nil) } func openVPNAdapter(_ openVPNAdapter: OpenVPNAdapter, handleEvent event: OpenVPNAdapterEvent, message: String?) {