mirror of
https://github.com/curl/curl.git
synced 2026-06-02 19:54:35 +03:00
This patch adds two major proxy capabilities to curl (ngtcp2 QUIC):
- HTTP/3 Proxy CONNECT: Tunnel HTTP/1.1 or HTTP/2 traffic through an
HTTPS proxy that speaks HTTP/3 (QUIC) using the standard CONNECT
method over an HTTP/3 connection.
- MASQUE CONNECT-UDP: Tunnel HTTP/3 (QUIC) traffic through an HTTP
proxy (speaking HTTP/1.1, HTTP/2, or HTTP/3) using the extended
CONNECT method with the CONNECT-UDP protocol (RFC9297 & RFC9298).
Public API additions:
- `CURLPROXY_HTTPS3`: new proxy type constant for HTTP/3 proxy
- `--proxy-http3`: new CLI flag to negotiate HTTP/3 with HTTPS proxy
The implementation adds two new filters:
- `H3-PROXY` - enables negotiating HTTP/3 (QUIC) to the proxy and
running CONNECT/CONNECT-UDP through that proxy transport.
- `CAPSULE` - dedicated filter inserted between QUIC transport and
HTTP-PROXY to handle datagram capsule encapsulation/decapsulation.
Here is how the curl filter chaining looks in different scenarios:
- HTTP/3 Proxy CONNECT (tunneling TCP protocols over QUIC proxy):
conn -> HTTP/1.1 or HTTP/2 -> SSL -> HTTP-PROXY ->
H3-PROXY -> HAPPY-EYEBALLS -> UDP
- MASQUE CONNECT-UDP (tunneling QUIC over any proxy):
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H3-PROXY ->
HAPPY-EYEBALLS -> UDP
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H1-PROXY or H2-PROXY ->
SSL -> HAPPY-EYEBALLS -> TCP
- Both features currently require the ngtcp2 QUIC backend.
- Both features are experimental (disabled by default). Enable with
`--enable-proxy-http3`(autotools) or `-DUSE_PROXY_HTTP3=ON`(CMake).
Tests:
- tests/unit/unit3400.c: Unit tests for capsule protocol encode/decode
- tests/http/test_60_h3_proxy.py: Comprehensive pytest integration suite
- tests/http/testenv/h2o.py: Managing h2o instances with HTTP/1.1, HTTP/2,
and HTTP/3 (QUIC) listeners, proxy.connect and proxy.connect-udp enabled.
References:
RFC 9297 - HTTP Datagrams and the Capsule Protocol
RFC 9298 - Proxying UDP in HTTP
RFC 9000 §16 — Variable-Length Integer Encoding
Signed-off-by: Aritra Basu <aritrbas+gh@cisco.com>
Closes #21153
|
||
|---|---|---|
| .. | ||
| opts | ||
| .gitignore | ||
| ABI.md | ||
| CMakeLists.txt | ||
| curl_easy_cleanup.md | ||
| curl_easy_duphandle.md | ||
| curl_easy_escape.md | ||
| curl_easy_getinfo.md | ||
| curl_easy_header.md | ||
| curl_easy_init.md | ||
| curl_easy_nextheader.md | ||
| curl_easy_option_by_id.md | ||
| curl_easy_option_by_name.md | ||
| curl_easy_option_next.md | ||
| curl_easy_pause.md | ||
| curl_easy_perform.md | ||
| curl_easy_recv.md | ||
| curl_easy_reset.md | ||
| curl_easy_send.md | ||
| curl_easy_setopt.md | ||
| curl_easy_ssls_export.md | ||
| curl_easy_ssls_import.md | ||
| curl_easy_strerror.md | ||
| curl_easy_unescape.md | ||
| curl_easy_upkeep.md | ||
| curl_escape.md | ||
| curl_formadd.md | ||
| curl_formfree.md | ||
| curl_formget.md | ||
| curl_free.md | ||
| curl_getdate.md | ||
| curl_getenv.md | ||
| curl_global_cleanup.md | ||
| curl_global_init.md | ||
| curl_global_init_mem.md | ||
| curl_global_sslset.md | ||
| curl_global_trace.md | ||
| curl_mime_addpart.md | ||
| curl_mime_data.md | ||
| curl_mime_data_cb.md | ||
| curl_mime_encoder.md | ||
| curl_mime_filedata.md | ||
| curl_mime_filename.md | ||
| curl_mime_free.md | ||
| curl_mime_headers.md | ||
| curl_mime_init.md | ||
| curl_mime_name.md | ||
| curl_mime_subparts.md | ||
| curl_mime_type.md | ||
| curl_mprintf.md | ||
| curl_multi_add_handle.md | ||
| curl_multi_assign.md | ||
| curl_multi_cleanup.md | ||
| curl_multi_fdset.md | ||
| curl_multi_get_handles.md | ||
| curl_multi_get_offt.md | ||
| curl_multi_info_read.md | ||
| curl_multi_init.md | ||
| curl_multi_notify_disable.md | ||
| curl_multi_notify_enable.md | ||
| curl_multi_perform.md | ||
| curl_multi_poll.md | ||
| curl_multi_remove_handle.md | ||
| curl_multi_setopt.md | ||
| curl_multi_socket.md | ||
| curl_multi_socket_action.md | ||
| curl_multi_socket_all.md | ||
| curl_multi_strerror.md | ||
| curl_multi_timeout.md | ||
| curl_multi_wait.md | ||
| curl_multi_waitfds.md | ||
| curl_multi_wakeup.md | ||
| curl_pushheader_byname.md | ||
| curl_pushheader_bynum.md | ||
| curl_share_cleanup.md | ||
| curl_share_init.md | ||
| curl_share_setopt.md | ||
| curl_share_strerror.md | ||
| curl_slist_append.md | ||
| curl_slist_free_all.md | ||
| curl_strequal.md | ||
| curl_strnequal.md | ||
| curl_unescape.md | ||
| curl_url.md | ||
| curl_url_cleanup.md | ||
| curl_url_dup.md | ||
| curl_url_get.md | ||
| curl_url_set.md | ||
| curl_url_strerror.md | ||
| curl_version.md | ||
| curl_version_info.md | ||
| curl_ws_meta.md | ||
| curl_ws_recv.md | ||
| curl_ws_send.md | ||
| curl_ws_start_frame.md | ||
| libcurl-easy.md | ||
| libcurl-env-dbg.md | ||
| libcurl-env.md | ||
| libcurl-errors.md | ||
| libcurl-multi.md | ||
| libcurl-security.md | ||
| libcurl-share.md | ||
| libcurl-thread.md | ||
| libcurl-tutorial.md | ||
| libcurl-url.md | ||
| libcurl-ws.md | ||
| libcurl.m4 | ||
| libcurl.md | ||
| Makefile.am | ||
| Makefile.inc | ||
| mksymbolsmanpage.pl | ||
| symbols-in-versions | ||
| symbols.pl | ||