HTTP/3: add proxy CONNECT and MASQUE CONNECT-UDP support (ngtcp2 QUIC)

This patch adds two major proxy capabilities to curl (ngtcp2 QUIC):
- HTTP/3 Proxy CONNECT: Tunnel HTTP/1.1 or HTTP/2 traffic through an
  HTTPS proxy that speaks HTTP/3 (QUIC) using the standard CONNECT
  method over an HTTP/3 connection.
- MASQUE CONNECT-UDP: Tunnel HTTP/3 (QUIC) traffic through an HTTP
  proxy (speaking HTTP/1.1, HTTP/2, or HTTP/3) using the extended
  CONNECT method with the CONNECT-UDP protocol (RFC9297 & RFC9298).

Public API additions:
- `CURLPROXY_HTTPS3`: new proxy type constant for HTTP/3 proxy
- `--proxy-http3`: new CLI flag to negotiate HTTP/3 with HTTPS proxy

The implementation adds two new filters:
- `H3-PROXY` - enables negotiating HTTP/3 (QUIC) to the proxy and
  running CONNECT/CONNECT-UDP through that proxy transport.
- `CAPSULE` - dedicated filter inserted between QUIC transport and
  HTTP-PROXY to handle datagram capsule encapsulation/decapsulation.

Here is how the curl filter chaining looks in different scenarios:
- HTTP/3 Proxy CONNECT (tunneling TCP protocols over QUIC proxy):
  conn -> HTTP/1.1 or HTTP/2  -> SSL -> HTTP-PROXY ->
                                 H3-PROXY -> HAPPY-EYEBALLS -> UDP
- MASQUE CONNECT-UDP (tunneling QUIC over any proxy):
  conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H3-PROXY ->
                               HAPPY-EYEBALLS -> UDP
  conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H1-PROXY or H2-PROXY ->
                               SSL -> HAPPY-EYEBALLS -> TCP

- Both features currently require the ngtcp2 QUIC backend.
- Both features are experimental (disabled by default). Enable with
  `--enable-proxy-http3`(autotools) or `-DUSE_PROXY_HTTP3=ON`(CMake).

Tests:
- tests/unit/unit3400.c: Unit tests for capsule protocol encode/decode
- tests/http/test_60_h3_proxy.py: Comprehensive pytest integration suite
- tests/http/testenv/h2o.py: Managing h2o instances with HTTP/1.1, HTTP/2,
  and HTTP/3 (QUIC) listeners, proxy.connect and proxy.connect-udp enabled.

References:
  RFC 9297 - HTTP Datagrams and the Capsule Protocol
  RFC 9298 - Proxying UDP in HTTP
  RFC 9000 §16 — Variable-Length Integer Encoding

Signed-off-by: Aritra Basu <aritrbas+gh@cisco.com>

Closes #21153
This commit is contained in:
Aritra Basu 2026-04-27 19:35:38 -04:00 committed by Daniel Stenberg
parent efc3f2309e
commit e78b1b3ecc
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
66 changed files with 7401 additions and 473 deletions

View file

@ -54,6 +54,30 @@ CURL_CHECK_OPTION_RT
CURL_CHECK_OPTION_HTTPSRR
CURL_CHECK_OPTION_ECH
CURL_CHECK_OPTION_SSLS_EXPORT
AC_MSG_CHECKING([whether to enable HTTP/3 proxy support])
OPT_PROXY_HTTP3="default"
AC_ARG_ENABLE(proxy-http3,
AS_HELP_STRING([--enable-proxy-http3],[Enable experimental HTTP/3 proxy support])
AS_HELP_STRING([--disable-proxy-http3],[Disable experimental HTTP/3 proxy support]),
OPT_PROXY_HTTP3=$enableval)
case "$OPT_PROXY_HTTP3" in
no)
want_proxy_http3="no"
curl_proxy_http3_msg="no (--enable-proxy-http3)"
AC_MSG_RESULT([no])
;;
default)
want_proxy_http3="no"
curl_proxy_http3_msg="no (--enable-proxy-http3)"
AC_MSG_RESULT([no])
;;
*)
want_proxy_http3="yes"
curl_proxy_http3_msg="enabled (--disable-proxy-http3)"
AC_MSG_RESULT([yes])
;;
esac
USE_PROXY_HTTP3=0
XC_CHECK_PATH_SEPARATOR
@ -318,6 +342,22 @@ AS_HELP_STRING([--with-test-caddy=PATH],[where to find caddy for testing]),
)
AC_SUBST(CADDY)
if test -x /usr/local/bin/h2o; then
H2O=/usr/local/bin/h2o
elif test -x /usr/bin/h2o; then
H2O=/usr/bin/h2o
elif test -x "`brew --prefix 2>/dev/null`/bin/h2o"; then
H2O=`brew --prefix`/bin/h2o
fi
AC_ARG_WITH(test-h2o,dnl
AS_HELP_STRING([--with-test-h2o=PATH],[where to find h2o for testing]),
H2O=$withval
if test "x$H2O" = "xno"; then
H2O=""
fi
)
AC_SUBST(H2O)
if test -x /usr/sbin/vsftpd; then
VSFTPD=/usr/sbin/vsftpd
elif test -x /usr/local/sbin/vsftpd; then
@ -5028,6 +5068,28 @@ if test "$want_ssls_export" != "no"; then
fi
fi
dnl *************************************************************
dnl check whether experimental HTTP/3 proxy support is enabled
dnl
if test "$want_proxy_http3" = "yes"; then
AC_MSG_CHECKING([whether HTTP/3 proxy support is available])
if test "$CURL_DISABLE_PROXY" = "1"; then
AC_MSG_ERROR([--enable-proxy-http3 requires proxy support])
elif test "$CURL_DISABLE_HTTP" = "1"; then
AC_MSG_ERROR([--enable-proxy-http3 requires HTTP support])
elif test "$USE_NGTCP2_H3" != "1"; then
AC_MSG_ERROR([--enable-proxy-http3 requires ngtcp2 + nghttp3])
elif test "x$OPENSSL_ENABLED" != "x1"; then
AC_MSG_ERROR([--enable-proxy-http3 currently requires OpenSSL])
else
AC_DEFINE(USE_PROXY_HTTP3, 1, [if HTTP/3 proxy support is available])
USE_PROXY_HTTP3=1
AC_MSG_RESULT([yes])
experimental="$experimental PROXY-HTTP3"
fi
fi
dnl ************************************************************
dnl hiding of library internal symbols
dnl
@ -5141,6 +5203,10 @@ if test "$curl_psl_msg" = "enabled"; then
SUPPORT_FEATURES="$SUPPORT_FEATURES PSL"
fi
if test "$USE_PROXY_HTTP3" = "1"; then
SUPPORT_FEATURES="$SUPPORT_FEATURES PROXY-HTTP3"
fi
if test "$curl_gsasl_msg" = "enabled"; then
SUPPORT_FEATURES="$SUPPORT_FEATURES gsasl"
fi
@ -5485,6 +5551,7 @@ AC_MSG_NOTICE([Configured to build curl/libcurl:
HTTP1: ${curl_h1_msg}
HTTP2: ${curl_h2_msg}
HTTP3: ${curl_h3_msg}
Proxy-HTTP3: ${curl_proxy_http3_msg}
ECH: ${curl_ech_msg}
HTTPS RR: ${curl_httpsrr_msg}
SSLS-EXPORT: ${curl_ssls_export_msg}