mirror of
https://github.com/curl/curl.git
synced 2026-08-11 23:20:53 +03:00
HTTP/3: add proxy CONNECT and MASQUE CONNECT-UDP support (ngtcp2 QUIC)
This patch adds two major proxy capabilities to curl (ngtcp2 QUIC):
- HTTP/3 Proxy CONNECT: Tunnel HTTP/1.1 or HTTP/2 traffic through an
HTTPS proxy that speaks HTTP/3 (QUIC) using the standard CONNECT
method over an HTTP/3 connection.
- MASQUE CONNECT-UDP: Tunnel HTTP/3 (QUIC) traffic through an HTTP
proxy (speaking HTTP/1.1, HTTP/2, or HTTP/3) using the extended
CONNECT method with the CONNECT-UDP protocol (RFC9297 & RFC9298).
Public API additions:
- `CURLPROXY_HTTPS3`: new proxy type constant for HTTP/3 proxy
- `--proxy-http3`: new CLI flag to negotiate HTTP/3 with HTTPS proxy
The implementation adds two new filters:
- `H3-PROXY` - enables negotiating HTTP/3 (QUIC) to the proxy and
running CONNECT/CONNECT-UDP through that proxy transport.
- `CAPSULE` - dedicated filter inserted between QUIC transport and
HTTP-PROXY to handle datagram capsule encapsulation/decapsulation.
Here is how the curl filter chaining looks in different scenarios:
- HTTP/3 Proxy CONNECT (tunneling TCP protocols over QUIC proxy):
conn -> HTTP/1.1 or HTTP/2 -> SSL -> HTTP-PROXY ->
H3-PROXY -> HAPPY-EYEBALLS -> UDP
- MASQUE CONNECT-UDP (tunneling QUIC over any proxy):
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H3-PROXY ->
HAPPY-EYEBALLS -> UDP
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H1-PROXY or H2-PROXY ->
SSL -> HAPPY-EYEBALLS -> TCP
- Both features currently require the ngtcp2 QUIC backend.
- Both features are experimental (disabled by default). Enable with
`--enable-proxy-http3`(autotools) or `-DUSE_PROXY_HTTP3=ON`(CMake).
Tests:
- tests/unit/unit3400.c: Unit tests for capsule protocol encode/decode
- tests/http/test_60_h3_proxy.py: Comprehensive pytest integration suite
- tests/http/testenv/h2o.py: Managing h2o instances with HTTP/1.1, HTTP/2,
and HTTP/3 (QUIC) listeners, proxy.connect and proxy.connect-udp enabled.
References:
RFC 9297 - HTTP Datagrams and the Capsule Protocol
RFC 9298 - Proxying UDP in HTTP
RFC 9000 §16 — Variable-Length Integer Encoding
Signed-off-by: Aritra Basu <aritrbas+gh@cisco.com>
Closes #21153
This commit is contained in:
parent
efc3f2309e
commit
e78b1b3ecc
66 changed files with 7401 additions and 473 deletions
27
lib/url.c
27
lib/url.c
|
|
@ -99,6 +99,7 @@
|
|||
#include "headers.h"
|
||||
#include "curlx/strerr.h"
|
||||
#include "curlx/strparse.h"
|
||||
#include "peer.h"
|
||||
|
||||
/* Now for the protocols */
|
||||
#include "ftp.h"
|
||||
|
|
@ -1316,7 +1317,12 @@ static struct connectdata *allocate_conn(struct Curl_easy *data)
|
|||
#endif
|
||||
conn->ip_version = data->set.ipver;
|
||||
conn->bits.connect_only = (bool)data->set.connect_only;
|
||||
conn->transport_wanted = TRNSPRT_TCP; /* most of them are TCP streams */
|
||||
#ifndef CURL_DISABLE_PROXY
|
||||
if(conn->http_proxy.proxytype == CURLPROXY_HTTPS3)
|
||||
conn->transport_wanted = TRNSPRT_QUIC;
|
||||
else
|
||||
#endif
|
||||
conn->transport_wanted = TRNSPRT_TCP; /* most of them are TCP streams */
|
||||
|
||||
/* Store the local bind parameters that will be used for this connection */
|
||||
if(data->set.str[STRING_DEVICE]) {
|
||||
|
|
@ -1793,6 +1799,7 @@ static CURLcode parse_proxy(struct Curl_easy *data,
|
|||
{
|
||||
char *proxyuser = NULL;
|
||||
char *proxypasswd = NULL;
|
||||
char *scheme = NULL;
|
||||
CURLcode result = CURLE_OK;
|
||||
/* Set the start proxy type for url scheme guessing */
|
||||
uint8_t proxytype = for_pre_proxy ? CURLPROXY_SOCKS4 : data->set.proxytype;
|
||||
|
|
@ -1807,7 +1814,21 @@ static CURLcode parse_proxy(struct Curl_easy *data,
|
|||
these made up ones for proxies. Guess scheme for URLs without it. */
|
||||
uc = curl_url_set(uhp, CURLUPART_URL, proxy,
|
||||
CURLU_NON_SUPPORT_SCHEME | CURLU_GUESS_SCHEME);
|
||||
if(uc) {
|
||||
if(!uc) {
|
||||
/* parsed okay as a URL - only update proxytype when scheme was explicit */
|
||||
uc = curl_url_get(uhp, CURLUPART_SCHEME, &scheme, CURLU_NO_GUESS_SCHEME);
|
||||
if(!uc) {
|
||||
result = Curl_scheme_to_proxytype(data, scheme, &proxytype, proxy);
|
||||
if(result)
|
||||
goto error;
|
||||
}
|
||||
else if(uc != CURLUE_NO_SCHEME) {
|
||||
result = CURLE_OUT_OF_MEMORY;
|
||||
goto error;
|
||||
}
|
||||
/* else: no explicit scheme, keep the configured proxytype */
|
||||
}
|
||||
else {
|
||||
failf(data, "Unsupported proxy syntax in \'%s\': %s", proxy,
|
||||
curl_url_strerror(uc));
|
||||
result = CURLE_COULDNT_RESOLVE_PROXY;
|
||||
|
|
@ -1824,6 +1845,7 @@ static CURLcode parse_proxy(struct Curl_easy *data,
|
|||
case CURLPROXY_HTTP_1_0:
|
||||
case CURLPROXY_HTTPS:
|
||||
case CURLPROXY_HTTPS2:
|
||||
case CURLPROXY_HTTPS3:
|
||||
if(for_pre_proxy) {
|
||||
failf(data, "Unsupported pre-proxy type for \'%s\'", proxy);
|
||||
result = CURLE_COULDNT_RESOLVE_PROXY;
|
||||
|
|
@ -1878,6 +1900,7 @@ static CURLcode parse_proxy(struct Curl_easy *data,
|
|||
proxyinfo->proxytype = proxytype;
|
||||
|
||||
error:
|
||||
curlx_free(scheme);
|
||||
curlx_free(proxyuser);
|
||||
curlx_free(proxypasswd);
|
||||
curl_url_cleanup(uhp);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue