1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
use std::{
    io::{self, Read, Write},
    net::TcpStream,
    sync::{Arc, Mutex},
};

use native_tls::TlsStream;

pub use native_tls::{Certificate, Identity, Protocol, TlsConnector, TlsConnectorBuilder};

/// Returns a new TLS configuration object for use
/// with `ConnectionOptions::set_tls_connector`.
///
/// # Examples
/// ```no_run
/// # fn main() -> Result<(), Box<dyn std::error::Error>> {
/// let tls_connector = nats::tls::builder()
///     .identity(nats::tls::Identity::from_pkcs12(b"der_bytes", "my_password")?)
///     .add_root_certificate(nats::tls::Certificate::from_pem(b"my_pem_bytes")?)
///     .build()?;
///
/// let nc = nats::ConnectionOptions::new()
///     .tls_connector(tls_connector)
///     .connect("tls://demo.nats.io:4443")?;
/// # Ok(())
/// # }
/// ```
pub fn builder() -> TlsConnectorBuilder {
    TlsConnector::builder()
}

pub(crate) fn split_tls(tls: TlsStream<TcpStream>) -> (TlsReader, TlsWriter) {
    let tls_reader = TlsReader {
        raw_socket: tls.get_ref().try_clone().unwrap(),
        tls: Arc::new(Mutex::new(tls)),
    };

    let tls_writer = TlsWriter {
        tls: tls_reader.tls.clone(),
    };

    (tls_reader, tls_writer)
}

#[derive(Debug)]
pub(crate) struct TlsReader {
    tls: Arc<Mutex<TlsStream<TcpStream>>>,
    raw_socket: TcpStream,
}

impl TlsReader {
    fn wait_for_readable(&self) -> io::Result<()> {
        let mut peek_buf = [0];
        self.raw_socket.peek(&mut peek_buf)?;
        Ok(())
    }
}

impl Read for TlsReader {
    fn read(&mut self, buf: &mut [u8]) -> io::Result<usize> {
        self.wait_for_readable()?;

        let mut tls = self.tls.lock().unwrap();

        tls.read(buf)
    }
}

#[derive(Debug)]
pub(crate) struct TlsWriter {
    tls: Arc<Mutex<TlsStream<TcpStream>>>,
}

impl Write for TlsWriter {
    fn write(&mut self, buf: &[u8]) -> io::Result<usize> {
        let mut tls = self.tls.lock().unwrap();
        tls.write(buf)
    }

    fn flush(&mut self) -> io::Result<()> {
        let mut tls = self.tls.lock().unwrap();
        tls.flush()
    }
}

impl TlsWriter {
    pub(crate) fn shutdown(&mut self) -> io::Result<()> {
        let mut tls = self.tls.lock().unwrap();
        tls.shutdown()
    }
}