mirror of
https://github.com/curl/curl.git
synced 2026-06-02 15:54:17 +03:00
This patch adds two major proxy capabilities to curl (ngtcp2 QUIC):
- HTTP/3 Proxy CONNECT: Tunnel HTTP/1.1 or HTTP/2 traffic through an
HTTPS proxy that speaks HTTP/3 (QUIC) using the standard CONNECT
method over an HTTP/3 connection.
- MASQUE CONNECT-UDP: Tunnel HTTP/3 (QUIC) traffic through an HTTP
proxy (speaking HTTP/1.1, HTTP/2, or HTTP/3) using the extended
CONNECT method with the CONNECT-UDP protocol (RFC9297 & RFC9298).
Public API additions:
- `CURLPROXY_HTTPS3`: new proxy type constant for HTTP/3 proxy
- `--proxy-http3`: new CLI flag to negotiate HTTP/3 with HTTPS proxy
The implementation adds two new filters:
- `H3-PROXY` - enables negotiating HTTP/3 (QUIC) to the proxy and
running CONNECT/CONNECT-UDP through that proxy transport.
- `CAPSULE` - dedicated filter inserted between QUIC transport and
HTTP-PROXY to handle datagram capsule encapsulation/decapsulation.
Here is how the curl filter chaining looks in different scenarios:
- HTTP/3 Proxy CONNECT (tunneling TCP protocols over QUIC proxy):
conn -> HTTP/1.1 or HTTP/2 -> SSL -> HTTP-PROXY ->
H3-PROXY -> HAPPY-EYEBALLS -> UDP
- MASQUE CONNECT-UDP (tunneling QUIC over any proxy):
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H3-PROXY ->
HAPPY-EYEBALLS -> UDP
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H1-PROXY or H2-PROXY ->
SSL -> HAPPY-EYEBALLS -> TCP
- Both features currently require the ngtcp2 QUIC backend.
- Both features are experimental (disabled by default). Enable with
`--enable-proxy-http3`(autotools) or `-DUSE_PROXY_HTTP3=ON`(CMake).
Tests:
- tests/unit/unit3400.c: Unit tests for capsule protocol encode/decode
- tests/http/test_60_h3_proxy.py: Comprehensive pytest integration suite
- tests/http/testenv/h2o.py: Managing h2o instances with HTTP/1.1, HTTP/2,
and HTTP/3 (QUIC) listeners, proxy.connect and proxy.connect-udp enabled.
References:
RFC 9297 - HTTP Datagrams and the Capsule Protocol
RFC 9298 - Proxying UDP in HTTP
RFC 9000 §16 — Variable-Length Integer Encoding
Signed-off-by: Aritra Basu <aritrbas+gh@cisco.com>
Closes #21153
86 lines
2.7 KiB
Makefile
86 lines
2.7 KiB
Makefile
#***************************************************************************
|
|
# _ _ ____ _
|
|
# Project ___| | | | _ \| |
|
|
# / __| | | | |_) | |
|
|
# | (__| |_| | _ <| |___
|
|
# \___|\___/|_| \_\_____|
|
|
#
|
|
# Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
|
|
#
|
|
# This software is licensed as described in the file COPYING, which
|
|
# you should have received as part of this distribution. The terms
|
|
# are also available at https://curl.se/docs/copyright.html.
|
|
#
|
|
# You may opt to use, copy, modify, merge, publish, distribute and/or sell
|
|
# copies of the Software, and permit persons to whom the Software is
|
|
# furnished to do so, under the terms of the COPYING file.
|
|
#
|
|
# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
|
|
# KIND, either express or implied.
|
|
#
|
|
# SPDX-License-Identifier: curl
|
|
#
|
|
###########################################################################
|
|
|
|
TESTENV = \
|
|
testenv/__init__.py \
|
|
testenv/caddy.py \
|
|
testenv/certs.py \
|
|
testenv/client.py \
|
|
testenv/curl.py \
|
|
testenv/dnsd.py \
|
|
testenv/dante.py \
|
|
testenv/env.py \
|
|
testenv/h2o.py \
|
|
testenv/httpd.py \
|
|
testenv/mod_curltest/mod_curltest.c \
|
|
testenv/nghttpx.py \
|
|
testenv/ports.py \
|
|
testenv/sshd.py \
|
|
testenv/vsftpd.py \
|
|
testenv/ws_echo_server.py
|
|
|
|
EXTRA_DIST = \
|
|
CMakeLists.txt \
|
|
conftest.py \
|
|
requirements.txt \
|
|
scorecard.py \
|
|
test_01_basic.py \
|
|
test_02_download.py \
|
|
test_03_goaway.py \
|
|
test_04_stuttered.py \
|
|
test_05_errors.py \
|
|
test_06_eyeballs.py \
|
|
test_07_upload.py \
|
|
test_08_caddy.py \
|
|
test_09_push.py \
|
|
test_10_proxy.py \
|
|
test_11_unix.py \
|
|
test_12_reuse.py \
|
|
test_13_proxy_auth.py \
|
|
test_14_auth.py \
|
|
test_15_tracing.py \
|
|
test_16_info.py \
|
|
test_17_ssl_use.py \
|
|
test_18_methods.py \
|
|
test_19_shutdown.py \
|
|
test_20_websockets.py \
|
|
test_21_resolve.py \
|
|
test_22_httpsrr.py \
|
|
test_30_vsftpd.py \
|
|
test_31_vsftpds.py \
|
|
test_32_ftps_vsftpd.py \
|
|
test_40_socks.py \
|
|
test_50_scp.py \
|
|
test_51_sftp.py \
|
|
test_60_h3_proxy.py \
|
|
$(TESTENV)
|
|
|
|
clean-local:
|
|
rm -rf *.pyc __pycache__
|
|
rm -rf gen
|
|
|
|
check: libtests
|
|
|
|
libtests:
|
|
@(cd ../libtest && $(MAKE) check)
|