mirror of
https://github.com/curl/curl.git
synced 2026-07-24 12:27:16 +03:00
HTTP/3: add proxy CONNECT and MASQUE CONNECT-UDP support (ngtcp2 QUIC)
This patch adds two major proxy capabilities to curl (ngtcp2 QUIC):
- HTTP/3 Proxy CONNECT: Tunnel HTTP/1.1 or HTTP/2 traffic through an
HTTPS proxy that speaks HTTP/3 (QUIC) using the standard CONNECT
method over an HTTP/3 connection.
- MASQUE CONNECT-UDP: Tunnel HTTP/3 (QUIC) traffic through an HTTP
proxy (speaking HTTP/1.1, HTTP/2, or HTTP/3) using the extended
CONNECT method with the CONNECT-UDP protocol (RFC9297 & RFC9298).
Public API additions:
- `CURLPROXY_HTTPS3`: new proxy type constant for HTTP/3 proxy
- `--proxy-http3`: new CLI flag to negotiate HTTP/3 with HTTPS proxy
The implementation adds two new filters:
- `H3-PROXY` - enables negotiating HTTP/3 (QUIC) to the proxy and
running CONNECT/CONNECT-UDP through that proxy transport.
- `CAPSULE` - dedicated filter inserted between QUIC transport and
HTTP-PROXY to handle datagram capsule encapsulation/decapsulation.
Here is how the curl filter chaining looks in different scenarios:
- HTTP/3 Proxy CONNECT (tunneling TCP protocols over QUIC proxy):
conn -> HTTP/1.1 or HTTP/2 -> SSL -> HTTP-PROXY ->
H3-PROXY -> HAPPY-EYEBALLS -> UDP
- MASQUE CONNECT-UDP (tunneling QUIC over any proxy):
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H3-PROXY ->
HAPPY-EYEBALLS -> UDP
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H1-PROXY or H2-PROXY ->
SSL -> HAPPY-EYEBALLS -> TCP
- Both features currently require the ngtcp2 QUIC backend.
- Both features are experimental (disabled by default). Enable with
`--enable-proxy-http3`(autotools) or `-DUSE_PROXY_HTTP3=ON`(CMake).
Tests:
- tests/unit/unit3400.c: Unit tests for capsule protocol encode/decode
- tests/http/test_60_h3_proxy.py: Comprehensive pytest integration suite
- tests/http/testenv/h2o.py: Managing h2o instances with HTTP/1.1, HTTP/2,
and HTTP/3 (QUIC) listeners, proxy.connect and proxy.connect-udp enabled.
References:
RFC 9297 - HTTP Datagrams and the Capsule Protocol
RFC 9298 - Proxying UDP in HTTP
RFC 9000 §16 — Variable-Length Integer Encoding
Signed-off-by: Aritra Basu <aritrbas+gh@cisco.com>
Closes #21153
This commit is contained in:
parent
efc3f2309e
commit
e78b1b3ecc
66 changed files with 7401 additions and 473 deletions
|
|
@ -32,14 +32,47 @@
|
|||
enum Curl_proxy_use {
|
||||
HEADER_SERVER, /* direct to server */
|
||||
HEADER_PROXY, /* regular request to proxy */
|
||||
HEADER_CONNECT /* sending CONNECT to a proxy */
|
||||
HEADER_CONNECT, /* sending CONNECT to a proxy */
|
||||
HEADER_CONNECT_UDP /* sending CONNECT-UDP to a proxy */
|
||||
};
|
||||
|
||||
/* HTTP version for proxy tunnel request creation */
|
||||
typedef enum {
|
||||
PROXY_HTTP_V1 = 1,
|
||||
PROXY_HTTP_V2 = 2,
|
||||
PROXY_HTTP_V3 = 3
|
||||
} proxy_http_ver;
|
||||
|
||||
/* Result from inspecting a proxy tunnel response */
|
||||
typedef enum {
|
||||
PROXY_INSPECT_OK, /* Tunnel established */
|
||||
PROXY_INSPECT_FAILED, /* Tunnel failed */
|
||||
PROXY_INSPECT_AUTH_RETRY /* Retry with auth */
|
||||
} proxy_inspect_result;
|
||||
|
||||
CURLcode Curl_http_proxy_create_CONNECT(struct httpreq **preq,
|
||||
struct Curl_cfilter *cf,
|
||||
struct Curl_easy *data,
|
||||
struct Curl_peer *dest,
|
||||
int httpversion);
|
||||
proxy_http_ver ver);
|
||||
CURLcode Curl_http_proxy_create_CONNECTUDP(struct httpreq **preq,
|
||||
struct Curl_cfilter *cf,
|
||||
struct Curl_easy *data,
|
||||
struct Curl_peer *dest,
|
||||
proxy_http_ver ver);
|
||||
|
||||
/* Create CONNECT or CONNECT-UDP request */
|
||||
CURLcode Curl_http_proxy_create_tunnel_request(
|
||||
struct httpreq **preq, struct Curl_cfilter *cf,
|
||||
struct Curl_easy *data, struct Curl_peer *dest,
|
||||
proxy_http_ver ver, bool udp_tunnel);
|
||||
|
||||
/* Inspect tunnel response for H2/H3 proxy (capsule-protocol, auth) */
|
||||
struct http_resp;
|
||||
CURLcode Curl_http_proxy_inspect_tunnel_response(
|
||||
struct Curl_cfilter *cf, struct Curl_easy *data,
|
||||
struct http_resp *resp, bool udp_tunnel,
|
||||
proxy_inspect_result *presult);
|
||||
|
||||
/* Default proxy timeout in milliseconds */
|
||||
#define PROXY_TIMEOUT (3600 * 1000)
|
||||
|
|
@ -47,13 +80,17 @@ CURLcode Curl_http_proxy_create_CONNECT(struct httpreq **preq,
|
|||
CURLcode Curl_cf_http_proxy_insert_after(struct Curl_cfilter *cf_at,
|
||||
struct Curl_easy *data,
|
||||
struct Curl_peer *dest,
|
||||
uint8_t proxytype);
|
||||
uint8_t proxytype,
|
||||
bool udp_tunnel);
|
||||
|
||||
extern struct Curl_cftype Curl_cft_http_proxy;
|
||||
|
||||
#endif /* !CURL_DISABLE_PROXY && !CURL_DISABLE_HTTP */
|
||||
|
||||
#define IS_HTTPS_PROXY(t) (((t) == CURLPROXY_HTTPS) || \
|
||||
((t) == CURLPROXY_HTTPS2))
|
||||
((t) == CURLPROXY_HTTPS2) || \
|
||||
((t) == CURLPROXY_HTTPS3))
|
||||
|
||||
#define IS_QUIC_PROXY(t) ((t) == CURLPROXY_HTTPS3)
|
||||
|
||||
#endif /* HEADER_CURL_HTTP_PROXY_H */
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue