mirror of
https://github.com/curl/curl.git
synced 2026-06-02 12:04:31 +03:00
This patch adds two major proxy capabilities to curl (ngtcp2 QUIC):
- HTTP/3 Proxy CONNECT: Tunnel HTTP/1.1 or HTTP/2 traffic through an
HTTPS proxy that speaks HTTP/3 (QUIC) using the standard CONNECT
method over an HTTP/3 connection.
- MASQUE CONNECT-UDP: Tunnel HTTP/3 (QUIC) traffic through an HTTP
proxy (speaking HTTP/1.1, HTTP/2, or HTTP/3) using the extended
CONNECT method with the CONNECT-UDP protocol (RFC9297 & RFC9298).
Public API additions:
- `CURLPROXY_HTTPS3`: new proxy type constant for HTTP/3 proxy
- `--proxy-http3`: new CLI flag to negotiate HTTP/3 with HTTPS proxy
The implementation adds two new filters:
- `H3-PROXY` - enables negotiating HTTP/3 (QUIC) to the proxy and
running CONNECT/CONNECT-UDP through that proxy transport.
- `CAPSULE` - dedicated filter inserted between QUIC transport and
HTTP-PROXY to handle datagram capsule encapsulation/decapsulation.
Here is how the curl filter chaining looks in different scenarios:
- HTTP/3 Proxy CONNECT (tunneling TCP protocols over QUIC proxy):
conn -> HTTP/1.1 or HTTP/2 -> SSL -> HTTP-PROXY ->
H3-PROXY -> HAPPY-EYEBALLS -> UDP
- MASQUE CONNECT-UDP (tunneling QUIC over any proxy):
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H3-PROXY ->
HAPPY-EYEBALLS -> UDP
conn -> HTTP/3 -> CAPSULE -> HTTP-PROXY -> H1-PROXY or H2-PROXY ->
SSL -> HAPPY-EYEBALLS -> TCP
- Both features currently require the ngtcp2 QUIC backend.
- Both features are experimental (disabled by default). Enable with
`--enable-proxy-http3`(autotools) or `-DUSE_PROXY_HTTP3=ON`(CMake).
Tests:
- tests/unit/unit3400.c: Unit tests for capsule protocol encode/decode
- tests/http/test_60_h3_proxy.py: Comprehensive pytest integration suite
- tests/http/testenv/h2o.py: Managing h2o instances with HTTP/1.1, HTTP/2,
and HTTP/3 (QUIC) listeners, proxy.connect and proxy.connect-udp enabled.
References:
RFC 9297 - HTTP Datagrams and the Capsule Protocol
RFC 9298 - Proxying UDP in HTTP
RFC 9000 §16 — Variable-Length Integer Encoding
Signed-off-by: Aritra Basu <aritrbas+gh@cisco.com>
Closes #21153
110 lines
4.5 KiB
C
110 lines
4.5 KiB
C
#ifndef HEADER_CURL_PEER_H
|
|
#define HEADER_CURL_PEER_H
|
|
/***************************************************************************
|
|
* _ _ ____ _
|
|
* Project ___| | | | _ \| |
|
|
* / __| | | | |_) | |
|
|
* | (__| |_| | _ <| |___
|
|
* \___|\___/|_| \_\_____|
|
|
*
|
|
* Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
|
|
*
|
|
* This software is licensed as described in the file COPYING, which
|
|
* you should have received as part of this distribution. The terms
|
|
* are also available at https://curl.se/docs/copyright.html.
|
|
*
|
|
* You may opt to use, copy, modify, merge, publish, distribute and/or sell
|
|
* copies of the Software, and permit persons to whom the Software is
|
|
* furnished to do so, under the terms of the COPYING file.
|
|
*
|
|
* This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
|
|
* KIND, either express or implied.
|
|
*
|
|
* SPDX-License-Identifier: curl
|
|
*
|
|
***************************************************************************/
|
|
|
|
struct Curl_scheme;
|
|
struct urlpieces;
|
|
|
|
/* if peer hostname starts with this, the peer is a unix domain socket
|
|
* path, e.g. the remainder after 'localhost'. */
|
|
#define CURL_PEER_UDS_PREFIX "localhost/"
|
|
|
|
struct Curl_peer {
|
|
const struct Curl_scheme *scheme; /* url scheme */
|
|
char *hostname; /* normalized hostname (IDN decoded when supported) */
|
|
char *zoneid; /* NULL or ipv6 zone identifier */
|
|
uint32_t refcount; /* created with 1, freed when dropping to 0 */
|
|
uint32_t scopeid; /* != 0, ipv6 scope to use */
|
|
uint16_t port;
|
|
BIT(unix_socket); /* hostname is a UDS path without the prefix */
|
|
BIT(abstract_uds); /* only TRUE when `unix_socket` also TRUE */
|
|
BIT(ipv6); /* hostname is an IPv6 address stripped of '[]' */
|
|
char user_hostname[1]; /* hostname supplied by user/url */
|
|
};
|
|
|
|
/* Create a new peer:
|
|
* - `peer->user_hostname` is the passed `hostname`
|
|
* - `peer->hostname` is the normalized `hostname` via
|
|
* + IDN conversion if it has non-ASCII characters
|
|
* + stripping of surrounding '[]' for URL formatted ipv6 addresses
|
|
* + the path alone in case of a unix domain socket, e.g. hostname
|
|
* starts with CURL_PEER_UDS_PREFIX and is longer
|
|
* Will scam for IPv6 addresses even without surrounding '[]'.
|
|
* - `zoneid` ipv6 zone identifier or NULL
|
|
* - `scopeid` ipv6 scopeid of zoneid, when known.
|
|
*/
|
|
CURLcode Curl_peer_create(struct Curl_easy *data,
|
|
const struct Curl_scheme *scheme,
|
|
const char *hostname,
|
|
uint16_t port,
|
|
struct Curl_peer **ppeer);
|
|
|
|
#ifdef USE_UNIX_SOCKETS
|
|
CURLcode Curl_peer_uds_create(const struct Curl_scheme *scheme,
|
|
const char *path,
|
|
bool abstract_unix_socket,
|
|
struct Curl_peer **ppeer);
|
|
#endif
|
|
|
|
/* Unlink any peer in `*pdest`, assign src, increase src
|
|
* refcount when not NULL. */
|
|
void Curl_peer_link(struct Curl_peer **pdest, struct Curl_peer *src);
|
|
|
|
/* Drop a reference, peer may be passed as NULL */
|
|
void Curl_peer_unlink(struct Curl_peer **ppeer);
|
|
|
|
/* TRUE if both peers are NULL or have completely same properties. */
|
|
bool Curl_peer_equal(struct Curl_peer *p1, struct Curl_peer *p2);
|
|
|
|
/* TRUE if both peers are NULL or have properties except the scheme. */
|
|
bool Curl_peer_same_destination(struct Curl_peer *p1, struct Curl_peer *p2);
|
|
|
|
CURLcode Curl_peer_from_url(CURLU *uh, struct Curl_easy *data,
|
|
uint16_t port_override,
|
|
uint32_t scopeid_override,
|
|
struct urlpieces *up,
|
|
struct Curl_peer **ppeer);
|
|
|
|
CURLcode Curl_peer_from_connect_to(struct Curl_easy *data,
|
|
const struct Curl_peer *dest,
|
|
const char *connect_to,
|
|
struct Curl_peer **ppeer);
|
|
|
|
#ifndef CURL_DISABLE_PROXY
|
|
|
|
CURLcode Curl_scheme_to_proxytype(struct Curl_easy *data,
|
|
const char *scheme,
|
|
uint8_t *proxytype,
|
|
const char *url);
|
|
|
|
CURLcode Curl_peer_from_proxy_url(CURLU *uh,
|
|
struct Curl_easy *data,
|
|
const char *url,
|
|
uint8_t proxytype,
|
|
struct Curl_peer **ppeer,
|
|
uint8_t *pproxytype);
|
|
#endif /* !CURL_DISABLE_PROXY */
|
|
|
|
#endif /* HEADER_CURL_PEER_H */
|