Mercurial > hg > nginx-quic
annotate src/stream/ngx_stream_proxy_module.c @ 6183:4dcffe43a7ea
Stream: the "proxy_bind" directive.
author | Vladimir Homutov <vl@nginx.com> |
---|---|
date | Tue, 16 Jun 2015 09:02:45 +0300 |
parents | 68c106e6fa0a |
children | fa663739e115 |
rev | line source |
---|---|
6115 | 1 |
2 /* | |
3 * Copyright (C) Roman Arutyunyan | |
4 * Copyright (C) Nginx, Inc. | |
5 */ | |
6 | |
7 | |
8 #include <ngx_config.h> | |
9 #include <ngx_core.h> | |
10 #include <ngx_stream.h> | |
11 | |
12 | |
13 typedef void (*ngx_stream_proxy_handler_pt)(ngx_stream_session_t *s); | |
14 | |
15 | |
16 typedef struct { | |
17 ngx_msec_t connect_timeout; | |
18 ngx_msec_t timeout; | |
19 ngx_msec_t next_upstream_timeout; | |
20 size_t downstream_buf_size; | |
21 size_t upstream_buf_size; | |
22 ngx_uint_t next_upstream_tries; | |
23 ngx_flag_t next_upstream; | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
24 ngx_addr_t *local; |
6115 | 25 |
26 #if (NGX_STREAM_SSL) | |
27 ngx_flag_t ssl_enable; | |
28 ngx_flag_t ssl_session_reuse; | |
29 ngx_uint_t ssl_protocols; | |
30 ngx_str_t ssl_ciphers; | |
31 ngx_str_t ssl_name; | |
32 ngx_flag_t ssl_server_name; | |
33 | |
34 ngx_flag_t ssl_verify; | |
35 ngx_uint_t ssl_verify_depth; | |
36 ngx_str_t ssl_trusted_certificate; | |
37 ngx_str_t ssl_crl; | |
38 ngx_str_t ssl_certificate; | |
39 ngx_str_t ssl_certificate_key; | |
40 ngx_array_t *ssl_passwords; | |
41 | |
42 ngx_ssl_t *ssl; | |
43 #endif | |
44 | |
45 ngx_stream_upstream_srv_conf_t *upstream; | |
46 } ngx_stream_proxy_srv_conf_t; | |
47 | |
48 | |
49 static void ngx_stream_proxy_handler(ngx_stream_session_t *s); | |
50 static void ngx_stream_proxy_connect(ngx_stream_session_t *s); | |
51 static void ngx_stream_proxy_init_upstream(ngx_stream_session_t *s); | |
52 static void ngx_stream_proxy_upstream_handler(ngx_event_t *ev); | |
53 static void ngx_stream_proxy_downstream_handler(ngx_event_t *ev); | |
54 static void ngx_stream_proxy_connect_handler(ngx_event_t *ev); | |
55 static ngx_int_t ngx_stream_proxy_test_connect(ngx_connection_t *c); | |
56 static ngx_int_t ngx_stream_proxy_process(ngx_stream_session_t *s, | |
57 ngx_uint_t from_upstream, ngx_uint_t do_write); | |
58 static void ngx_stream_proxy_next_upstream(ngx_stream_session_t *s); | |
59 static void ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc); | |
60 static u_char *ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, | |
61 size_t len); | |
62 | |
63 static void *ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf); | |
64 static char *ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, | |
65 void *child); | |
66 static char *ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, | |
67 void *conf); | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
68 static char *ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
69 void *conf); |
6115 | 70 |
71 #if (NGX_STREAM_SSL) | |
72 | |
73 static char *ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, | |
74 ngx_command_t *cmd, void *conf); | |
75 static void ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s); | |
76 static void ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc); | |
77 static ngx_int_t ngx_stream_proxy_ssl_name(ngx_stream_session_t *s); | |
78 static ngx_int_t ngx_stream_proxy_set_ssl(ngx_conf_t *cf, | |
79 ngx_stream_proxy_srv_conf_t *pscf); | |
80 | |
81 | |
82 static ngx_conf_bitmask_t ngx_stream_proxy_ssl_protocols[] = { | |
83 { ngx_string("SSLv2"), NGX_SSL_SSLv2 }, | |
84 { ngx_string("SSLv3"), NGX_SSL_SSLv3 }, | |
85 { ngx_string("TLSv1"), NGX_SSL_TLSv1 }, | |
86 { ngx_string("TLSv1.1"), NGX_SSL_TLSv1_1 }, | |
87 { ngx_string("TLSv1.2"), NGX_SSL_TLSv1_2 }, | |
88 { ngx_null_string, 0 } | |
89 }; | |
90 | |
91 #endif | |
92 | |
93 | |
94 static ngx_command_t ngx_stream_proxy_commands[] = { | |
95 | |
96 { ngx_string("proxy_pass"), | |
97 NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
98 ngx_stream_proxy_pass, | |
99 NGX_STREAM_SRV_CONF_OFFSET, | |
100 0, | |
101 NULL }, | |
102 | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
103 { ngx_string("proxy_bind"), |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
104 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
105 ngx_stream_proxy_bind, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
106 NGX_STREAM_SRV_CONF_OFFSET, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
107 0, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
108 NULL }, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
109 |
6115 | 110 { ngx_string("proxy_connect_timeout"), |
111 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
112 ngx_conf_set_msec_slot, | |
113 NGX_STREAM_SRV_CONF_OFFSET, | |
114 offsetof(ngx_stream_proxy_srv_conf_t, connect_timeout), | |
115 NULL }, | |
116 | |
117 { ngx_string("proxy_timeout"), | |
118 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
119 ngx_conf_set_msec_slot, | |
120 NGX_STREAM_SRV_CONF_OFFSET, | |
121 offsetof(ngx_stream_proxy_srv_conf_t, timeout), | |
122 NULL }, | |
123 | |
124 { ngx_string("proxy_downstream_buffer"), | |
125 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
126 ngx_conf_set_size_slot, | |
127 NGX_STREAM_SRV_CONF_OFFSET, | |
128 offsetof(ngx_stream_proxy_srv_conf_t, downstream_buf_size), | |
129 NULL }, | |
130 | |
131 { ngx_string("proxy_upstream_buffer"), | |
132 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
133 ngx_conf_set_size_slot, | |
134 NGX_STREAM_SRV_CONF_OFFSET, | |
135 offsetof(ngx_stream_proxy_srv_conf_t, upstream_buf_size), | |
136 NULL }, | |
137 | |
138 { ngx_string("proxy_next_upstream"), | |
139 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
140 ngx_conf_set_flag_slot, | |
141 NGX_STREAM_SRV_CONF_OFFSET, | |
142 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream), | |
143 NULL }, | |
144 | |
145 { ngx_string("proxy_next_upstream_tries"), | |
146 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
147 ngx_conf_set_num_slot, | |
148 NGX_STREAM_SRV_CONF_OFFSET, | |
149 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_tries), | |
150 NULL }, | |
151 | |
152 { ngx_string("proxy_next_upstream_timeout"), | |
153 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
154 ngx_conf_set_msec_slot, | |
155 NGX_STREAM_SRV_CONF_OFFSET, | |
156 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_timeout), | |
157 NULL }, | |
158 | |
159 #if (NGX_STREAM_SSL) | |
160 | |
161 { ngx_string("proxy_ssl"), | |
162 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
163 ngx_conf_set_flag_slot, | |
164 NGX_STREAM_SRV_CONF_OFFSET, | |
165 offsetof(ngx_stream_proxy_srv_conf_t, ssl_enable), | |
166 NULL }, | |
167 | |
168 { ngx_string("proxy_ssl_session_reuse"), | |
169 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
170 ngx_conf_set_flag_slot, | |
171 NGX_STREAM_SRV_CONF_OFFSET, | |
172 offsetof(ngx_stream_proxy_srv_conf_t, ssl_session_reuse), | |
173 NULL }, | |
174 | |
175 { ngx_string("proxy_ssl_protocols"), | |
176 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_1MORE, | |
177 ngx_conf_set_bitmask_slot, | |
178 NGX_STREAM_SRV_CONF_OFFSET, | |
179 offsetof(ngx_stream_proxy_srv_conf_t, ssl_protocols), | |
180 &ngx_stream_proxy_ssl_protocols }, | |
181 | |
182 { ngx_string("proxy_ssl_ciphers"), | |
183 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
184 ngx_conf_set_str_slot, | |
185 NGX_STREAM_SRV_CONF_OFFSET, | |
186 offsetof(ngx_stream_proxy_srv_conf_t, ssl_ciphers), | |
187 NULL }, | |
188 | |
189 { ngx_string("proxy_ssl_name"), | |
190 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
191 ngx_conf_set_str_slot, | |
192 NGX_STREAM_SRV_CONF_OFFSET, | |
193 offsetof(ngx_stream_proxy_srv_conf_t, ssl_name), | |
194 NULL }, | |
195 | |
196 { ngx_string("proxy_ssl_server_name"), | |
197 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
198 ngx_conf_set_flag_slot, | |
199 NGX_STREAM_SRV_CONF_OFFSET, | |
200 offsetof(ngx_stream_proxy_srv_conf_t, ssl_server_name), | |
201 NULL }, | |
202 | |
203 { ngx_string("proxy_ssl_verify"), | |
204 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
205 ngx_conf_set_flag_slot, | |
206 NGX_STREAM_SRV_CONF_OFFSET, | |
207 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify), | |
208 NULL }, | |
209 | |
210 { ngx_string("proxy_ssl_verify_depth"), | |
211 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
212 ngx_conf_set_num_slot, | |
213 NGX_STREAM_SRV_CONF_OFFSET, | |
214 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify_depth), | |
215 NULL }, | |
216 | |
217 { ngx_string("proxy_ssl_trusted_certificate"), | |
218 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
219 ngx_conf_set_str_slot, | |
220 NGX_STREAM_SRV_CONF_OFFSET, | |
221 offsetof(ngx_stream_proxy_srv_conf_t, ssl_trusted_certificate), | |
222 NULL }, | |
223 | |
224 { ngx_string("proxy_ssl_crl"), | |
225 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
226 ngx_conf_set_str_slot, | |
227 NGX_STREAM_SRV_CONF_OFFSET, | |
228 offsetof(ngx_stream_proxy_srv_conf_t, ssl_crl), | |
229 NULL }, | |
230 | |
231 { ngx_string("proxy_ssl_certificate"), | |
232 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
233 ngx_conf_set_str_slot, | |
234 NGX_STREAM_SRV_CONF_OFFSET, | |
235 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate), | |
236 NULL }, | |
237 | |
238 { ngx_string("proxy_ssl_certificate_key"), | |
239 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
240 ngx_conf_set_str_slot, | |
241 NGX_STREAM_SRV_CONF_OFFSET, | |
242 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate_key), | |
243 NULL }, | |
244 | |
245 { ngx_string("proxy_ssl_password_file"), | |
246 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
247 ngx_stream_proxy_ssl_password_file, | |
248 NGX_STREAM_SRV_CONF_OFFSET, | |
249 0, | |
250 NULL }, | |
251 | |
252 #endif | |
253 | |
254 ngx_null_command | |
255 }; | |
256 | |
257 | |
258 static ngx_stream_module_t ngx_stream_proxy_module_ctx = { | |
6174
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
259 NULL, /* postconfiguration */ |
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
260 |
6115 | 261 NULL, /* create main configuration */ |
262 NULL, /* init main configuration */ | |
263 | |
264 ngx_stream_proxy_create_srv_conf, /* create server configuration */ | |
265 ngx_stream_proxy_merge_srv_conf /* merge server configuration */ | |
266 }; | |
267 | |
268 | |
269 ngx_module_t ngx_stream_proxy_module = { | |
270 NGX_MODULE_V1, | |
271 &ngx_stream_proxy_module_ctx, /* module context */ | |
272 ngx_stream_proxy_commands, /* module directives */ | |
273 NGX_STREAM_MODULE, /* module type */ | |
274 NULL, /* init master */ | |
275 NULL, /* init module */ | |
276 NULL, /* init process */ | |
277 NULL, /* init thread */ | |
278 NULL, /* exit thread */ | |
279 NULL, /* exit process */ | |
280 NULL, /* exit master */ | |
281 NGX_MODULE_V1_PADDING | |
282 }; | |
283 | |
284 | |
285 static void | |
286 ngx_stream_proxy_handler(ngx_stream_session_t *s) | |
287 { | |
288 u_char *p; | |
289 ngx_connection_t *c; | |
290 ngx_stream_upstream_t *u; | |
291 ngx_stream_proxy_srv_conf_t *pscf; | |
292 ngx_stream_upstream_srv_conf_t *uscf; | |
293 | |
294 c = s->connection; | |
295 | |
296 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
297 | |
298 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
299 "proxy connection handler"); | |
300 | |
301 u = ngx_pcalloc(c->pool, sizeof(ngx_stream_upstream_t)); | |
302 if (u == NULL) { | |
303 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
304 return; | |
305 } | |
306 | |
307 s->upstream = u; | |
308 | |
309 s->log_handler = ngx_stream_proxy_log_error; | |
310 | |
311 u->peer.log = c->log; | |
312 u->peer.log_error = NGX_ERROR_ERR; | |
313 | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
314 u->peer.local = pscf->local; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
315 |
6115 | 316 uscf = pscf->upstream; |
317 | |
318 if (uscf->peer.init(s, uscf) != NGX_OK) { | |
319 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
320 return; | |
321 } | |
322 | |
323 u->peer.start_time = ngx_current_msec; | |
324 | |
325 if (pscf->next_upstream_tries | |
326 && u->peer.tries > pscf->next_upstream_tries) | |
327 { | |
328 u->peer.tries = pscf->next_upstream_tries; | |
329 } | |
330 | |
331 p = ngx_pnalloc(c->pool, pscf->downstream_buf_size); | |
332 if (p == NULL) { | |
333 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
334 return; | |
335 } | |
336 | |
337 u->downstream_buf.start = p; | |
338 u->downstream_buf.end = p + pscf->downstream_buf_size; | |
339 u->downstream_buf.pos = p; | |
340 u->downstream_buf.last = p; | |
341 | |
342 c->write->handler = ngx_stream_proxy_downstream_handler; | |
343 c->read->handler = ngx_stream_proxy_downstream_handler; | |
344 | |
345 if (ngx_stream_proxy_process(s, 0, 0) != NGX_OK) { | |
346 return; | |
347 } | |
348 | |
349 ngx_stream_proxy_connect(s); | |
350 } | |
351 | |
352 | |
353 static void | |
354 ngx_stream_proxy_connect(ngx_stream_session_t *s) | |
355 { | |
356 ngx_int_t rc; | |
357 ngx_connection_t *c, *pc; | |
358 ngx_stream_upstream_t *u; | |
359 ngx_stream_proxy_srv_conf_t *pscf; | |
360 | |
361 c = s->connection; | |
362 | |
363 c->log->action = "connecting to upstream"; | |
364 | |
365 u = s->upstream; | |
366 | |
367 rc = ngx_event_connect_peer(&u->peer); | |
368 | |
369 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, c->log, 0, "proxy connect: %i", rc); | |
370 | |
371 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
372 | |
373 if (rc == NGX_ERROR) { | |
374 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
375 return; | |
376 } | |
377 | |
378 if (rc == NGX_BUSY) { | |
379 ngx_log_error(NGX_LOG_ERR, c->log, 0, "no live upstreams"); | |
380 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
381 return; | |
382 } | |
383 | |
384 if (rc == NGX_DECLINED) { | |
385 ngx_stream_proxy_next_upstream(s); | |
386 return; | |
387 } | |
388 | |
389 /* rc == NGX_OK || rc == NGX_AGAIN || rc == NGX_DONE */ | |
390 | |
391 pc = u->peer.connection; | |
392 | |
393 pc->data = s; | |
394 pc->log = c->log; | |
395 pc->pool = c->pool; | |
396 pc->read->log = c->log; | |
397 pc->write->log = c->log; | |
398 | |
399 if (rc != NGX_AGAIN) { | |
400 ngx_stream_proxy_init_upstream(s); | |
401 return; | |
402 } | |
403 | |
404 pc->read->handler = ngx_stream_proxy_connect_handler; | |
405 pc->write->handler = ngx_stream_proxy_connect_handler; | |
406 | |
407 ngx_add_timer(pc->write, pscf->connect_timeout); | |
408 } | |
409 | |
410 | |
411 static void | |
412 ngx_stream_proxy_init_upstream(ngx_stream_session_t *s) | |
413 { | |
414 u_char *p; | |
415 ngx_connection_t *c, *pc; | |
416 ngx_log_handler_pt handler; | |
417 ngx_stream_upstream_t *u; | |
418 ngx_stream_proxy_srv_conf_t *pscf; | |
419 | |
420 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
421 | |
422 u = s->upstream; | |
423 | |
424 pc = u->peer.connection; | |
425 | |
426 #if (NGX_STREAM_SSL) | |
427 if (pscf->ssl && pc->ssl == NULL) { | |
428 ngx_stream_proxy_ssl_init_connection(s); | |
429 return; | |
430 } | |
431 #endif | |
432 | |
433 c = s->connection; | |
434 | |
435 if (c->log->log_level >= NGX_LOG_INFO) { | |
436 ngx_str_t s; | |
437 u_char addr[NGX_SOCKADDR_STRLEN]; | |
438 | |
439 s.len = NGX_SOCKADDR_STRLEN; | |
440 s.data = addr; | |
441 | |
442 if (ngx_connection_local_sockaddr(pc, &s, 1) == NGX_OK) { | |
443 handler = c->log->handler; | |
444 c->log->handler = NULL; | |
445 | |
446 ngx_log_error(NGX_LOG_INFO, c->log, 0, "proxy %V connected to %V", | |
447 &s, u->peer.name); | |
448 | |
449 c->log->handler = handler; | |
450 } | |
451 } | |
452 | |
453 c->log->action = "proxying connection"; | |
454 | |
455 p = ngx_pnalloc(c->pool, pscf->upstream_buf_size); | |
456 if (p == NULL) { | |
457 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
458 return; | |
459 } | |
460 | |
461 u->upstream_buf.start = p; | |
462 u->upstream_buf.end = p + pscf->upstream_buf_size; | |
463 u->upstream_buf.pos = p; | |
464 u->upstream_buf.last = p; | |
465 | |
466 pc->read->handler = ngx_stream_proxy_upstream_handler; | |
467 pc->write->handler = ngx_stream_proxy_upstream_handler; | |
468 | |
469 if (ngx_stream_proxy_process(s, 1, 0) != NGX_OK) { | |
470 return; | |
471 } | |
472 | |
473 ngx_stream_proxy_process(s, 0, 1); | |
474 } | |
475 | |
476 | |
477 #if (NGX_STREAM_SSL) | |
478 | |
479 static char * | |
480 ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, ngx_command_t *cmd, | |
481 void *conf) | |
482 { | |
483 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
484 | |
485 ngx_str_t *value; | |
486 | |
487 if (pscf->ssl_passwords != NGX_CONF_UNSET_PTR) { | |
488 return "is duplicate"; | |
489 } | |
490 | |
491 value = cf->args->elts; | |
492 | |
493 pscf->ssl_passwords = ngx_ssl_read_password_file(cf, &value[1]); | |
494 | |
495 if (pscf->ssl_passwords == NULL) { | |
496 return NGX_CONF_ERROR; | |
497 } | |
498 | |
499 return NGX_CONF_OK; | |
500 } | |
501 | |
502 | |
503 static void | |
504 ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s) | |
505 { | |
506 ngx_int_t rc; | |
507 ngx_connection_t *pc; | |
508 ngx_stream_upstream_t *u; | |
509 ngx_stream_proxy_srv_conf_t *pscf; | |
510 | |
511 u = s->upstream; | |
512 | |
513 pc = u->peer.connection; | |
514 | |
515 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
516 | |
517 if (ngx_ssl_create_connection(pscf->ssl, pc, NGX_SSL_BUFFER|NGX_SSL_CLIENT) | |
518 != NGX_OK) | |
519 { | |
520 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
521 return; | |
522 } | |
523 | |
524 if (pscf->ssl_server_name || pscf->ssl_verify) { | |
525 if (ngx_stream_proxy_ssl_name(s) != NGX_OK) { | |
526 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
527 return; | |
528 } | |
529 } | |
530 | |
531 if (pscf->ssl_session_reuse) { | |
532 if (u->peer.set_session(&u->peer, u->peer.data) != NGX_OK) { | |
533 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
534 return; | |
535 } | |
536 } | |
537 | |
538 s->connection->log->action = "SSL handshaking to upstream"; | |
539 | |
540 rc = ngx_ssl_handshake(pc); | |
541 | |
542 if (rc == NGX_AGAIN) { | |
543 | |
544 if (!pc->write->timer_set) { | |
545 ngx_add_timer(pc->write, pscf->connect_timeout); | |
546 } | |
547 | |
548 pc->ssl->handler = ngx_stream_proxy_ssl_handshake; | |
549 return; | |
550 } | |
551 | |
552 ngx_stream_proxy_ssl_handshake(pc); | |
553 } | |
554 | |
555 | |
556 static void | |
557 ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc) | |
558 { | |
559 long rc; | |
560 ngx_stream_session_t *s; | |
561 ngx_stream_upstream_t *u; | |
562 ngx_stream_proxy_srv_conf_t *pscf; | |
563 | |
564 s = pc->data; | |
565 | |
566 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
567 | |
568 if (pc->ssl->handshaked) { | |
569 | |
570 if (pscf->ssl_verify) { | |
571 rc = SSL_get_verify_result(pc->ssl->connection); | |
572 | |
573 if (rc != X509_V_OK) { | |
574 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
575 "upstream SSL certificate verify error: (%l:%s)", | |
576 rc, X509_verify_cert_error_string(rc)); | |
577 goto failed; | |
578 } | |
579 | |
580 u = s->upstream; | |
581 | |
582 if (ngx_ssl_check_host(pc, &u->ssl_name) != NGX_OK) { | |
583 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
584 "upstream SSL certificate does not match \"%V\"", | |
585 &u->ssl_name); | |
586 goto failed; | |
587 } | |
588 } | |
589 | |
590 if (pscf->ssl_session_reuse) { | |
591 u = s->upstream; | |
592 u->peer.save_session(&u->peer, u->peer.data); | |
593 } | |
594 | |
595 ngx_stream_proxy_init_upstream(s); | |
596 | |
597 return; | |
598 } | |
599 | |
600 failed: | |
601 | |
602 ngx_stream_proxy_next_upstream(s); | |
603 } | |
604 | |
605 | |
606 static ngx_int_t | |
607 ngx_stream_proxy_ssl_name(ngx_stream_session_t *s) | |
608 { | |
609 u_char *p, *last; | |
610 ngx_str_t name; | |
611 ngx_stream_upstream_t *u; | |
612 ngx_stream_proxy_srv_conf_t *pscf; | |
613 | |
614 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
615 | |
616 u = s->upstream; | |
617 | |
618 name = pscf->ssl_name; | |
619 | |
620 if (name.len == 0) { | |
621 name = pscf->upstream->host; | |
622 } | |
623 | |
624 if (name.len == 0) { | |
625 goto done; | |
626 } | |
627 | |
628 /* | |
629 * ssl name here may contain port, strip it for compatibility | |
630 * with the http module | |
631 */ | |
632 | |
633 p = name.data; | |
634 last = name.data + name.len; | |
635 | |
636 if (*p == '[') { | |
637 p = ngx_strlchr(p, last, ']'); | |
638 | |
639 if (p == NULL) { | |
640 p = name.data; | |
641 } | |
642 } | |
643 | |
644 p = ngx_strlchr(p, last, ':'); | |
645 | |
646 if (p != NULL) { | |
647 name.len = p - name.data; | |
648 } | |
649 | |
650 if (!pscf->ssl_server_name) { | |
651 goto done; | |
652 } | |
653 | |
654 #ifdef SSL_CTRL_SET_TLSEXT_HOSTNAME | |
655 | |
656 /* as per RFC 6066, literal IPv4 and IPv6 addresses are not permitted */ | |
657 | |
658 if (name.len == 0 || *name.data == '[') { | |
659 goto done; | |
660 } | |
661 | |
662 if (ngx_inet_addr(name.data, name.len) != INADDR_NONE) { | |
663 goto done; | |
664 } | |
665 | |
666 /* | |
667 * SSL_set_tlsext_host_name() needs a null-terminated string, | |
668 * hence we explicitly null-terminate name here | |
669 */ | |
670 | |
671 p = ngx_pnalloc(s->connection->pool, name.len + 1); | |
672 if (p == NULL) { | |
673 return NGX_ERROR; | |
674 } | |
675 | |
676 (void) ngx_cpystrn(p, name.data, name.len + 1); | |
677 | |
678 name.data = p; | |
679 | |
680 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
681 "upstream SSL server name: \"%s\"", name.data); | |
682 | |
683 if (SSL_set_tlsext_host_name(u->peer.connection->ssl->connection, name.data) | |
684 == 0) | |
685 { | |
686 ngx_ssl_error(NGX_LOG_ERR, s->connection->log, 0, | |
687 "SSL_set_tlsext_host_name(\"%s\") failed", name.data); | |
688 return NGX_ERROR; | |
689 } | |
690 | |
691 #endif | |
692 | |
693 done: | |
694 | |
695 u->ssl_name = name; | |
696 | |
697 return NGX_OK; | |
698 } | |
699 | |
700 #endif | |
701 | |
702 | |
703 static void | |
704 ngx_stream_proxy_downstream_handler(ngx_event_t *ev) | |
705 { | |
706 ngx_connection_t *c; | |
707 ngx_stream_session_t *s; | |
708 ngx_stream_upstream_t *u; | |
709 | |
710 c = ev->data; | |
711 s = c->data; | |
712 | |
713 if (ev->timedout) { | |
714 ngx_connection_error(c, NGX_ETIMEDOUT, "connection timed out"); | |
715 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
716 return; | |
717 } | |
718 | |
719 u = s->upstream; | |
720 | |
721 if (!ev->write) { | |
722 ngx_stream_proxy_process(s, 0, 0); | |
723 | |
724 } else if (u->upstream_buf.start) { | |
725 ngx_stream_proxy_process(s, 1, 1); | |
726 } | |
727 } | |
728 | |
729 | |
730 static void | |
731 ngx_stream_proxy_upstream_handler(ngx_event_t *ev) | |
732 { | |
733 ngx_connection_t *c; | |
734 ngx_stream_session_t *s; | |
735 ngx_stream_upstream_t *u; | |
736 | |
737 c = ev->data; | |
738 s = c->data; | |
739 | |
740 u = s->upstream; | |
741 | |
742 if (ev->write) { | |
743 ngx_stream_proxy_process(s, 0, 1); | |
744 | |
745 } else if (u->upstream_buf.start) { | |
746 ngx_stream_proxy_process(s, 1, 0); | |
747 } | |
748 } | |
749 | |
750 | |
751 static void | |
752 ngx_stream_proxy_connect_handler(ngx_event_t *ev) | |
753 { | |
754 ngx_connection_t *c; | |
755 ngx_stream_session_t *s; | |
756 | |
757 c = ev->data; | |
758 s = c->data; | |
759 | |
760 if (ev->timedout) { | |
761 ngx_log_error(NGX_LOG_ERR, c->log, NGX_ETIMEDOUT, "upstream timed out"); | |
762 ngx_stream_proxy_next_upstream(s); | |
763 return; | |
764 } | |
765 | |
766 ngx_del_timer(c->write); | |
767 | |
768 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
769 "stream proxy connect upstream"); | |
770 | |
771 if (ngx_stream_proxy_test_connect(c) != NGX_OK) { | |
772 ngx_stream_proxy_next_upstream(s); | |
773 return; | |
774 } | |
775 | |
776 ngx_stream_proxy_init_upstream(s); | |
777 } | |
778 | |
779 | |
780 static ngx_int_t | |
781 ngx_stream_proxy_test_connect(ngx_connection_t *c) | |
782 { | |
783 int err; | |
784 socklen_t len; | |
785 | |
786 #if (NGX_HAVE_KQUEUE) | |
787 | |
788 if (ngx_event_flags & NGX_USE_KQUEUE_EVENT) { | |
789 err = c->write->kq_errno ? c->write->kq_errno : c->read->kq_errno; | |
790 | |
791 if (err) { | |
792 (void) ngx_connection_error(c, err, | |
793 "kevent() reported that connect() failed"); | |
794 return NGX_ERROR; | |
795 } | |
796 | |
797 } else | |
798 #endif | |
799 { | |
800 err = 0; | |
801 len = sizeof(int); | |
802 | |
803 /* | |
804 * BSDs and Linux return 0 and set a pending error in err | |
805 * Solaris returns -1 and sets errno | |
806 */ | |
807 | |
808 if (getsockopt(c->fd, SOL_SOCKET, SO_ERROR, (void *) &err, &len) | |
809 == -1) | |
810 { | |
811 err = ngx_socket_errno; | |
812 } | |
813 | |
814 if (err) { | |
815 (void) ngx_connection_error(c, err, "connect() failed"); | |
816 return NGX_ERROR; | |
817 } | |
818 } | |
819 | |
820 return NGX_OK; | |
821 } | |
822 | |
823 | |
824 static ngx_int_t | |
825 ngx_stream_proxy_process(ngx_stream_session_t *s, ngx_uint_t from_upstream, | |
826 ngx_uint_t do_write) | |
827 { | |
828 size_t size; | |
829 ssize_t n; | |
830 ngx_buf_t *b; | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
831 ngx_uint_t flags; |
6115 | 832 ngx_connection_t *c, *pc, *src, *dst; |
833 ngx_log_handler_pt handler; | |
834 ngx_stream_upstream_t *u; | |
835 ngx_stream_proxy_srv_conf_t *pscf; | |
836 | |
837 u = s->upstream; | |
838 | |
839 c = s->connection; | |
840 pc = u->upstream_buf.start ? u->peer.connection : NULL; | |
841 | |
842 if (from_upstream) { | |
843 src = pc; | |
844 dst = c; | |
845 b = &u->upstream_buf; | |
846 | |
847 } else { | |
848 src = c; | |
849 dst = pc; | |
850 b = &u->downstream_buf; | |
851 } | |
852 | |
853 for ( ;; ) { | |
854 | |
855 if (do_write) { | |
856 | |
857 size = b->last - b->pos; | |
858 | |
859 if (size && dst && dst->write->ready) { | |
860 | |
861 n = dst->send(dst, b->pos, size); | |
862 | |
863 if (n == NGX_ERROR) { | |
864 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
865 return NGX_ERROR; | |
866 } | |
867 | |
868 if (n > 0) { | |
869 b->pos += n; | |
870 | |
871 if (b->pos == b->last) { | |
872 b->pos = b->start; | |
873 b->last = b->start; | |
874 } | |
875 } | |
876 } | |
877 } | |
878 | |
879 size = b->end - b->last; | |
880 | |
881 if (size && src->read->ready) { | |
882 | |
883 n = src->recv(src, b->last, size); | |
884 | |
885 if (n == NGX_AGAIN || n == 0) { | |
886 break; | |
887 } | |
888 | |
889 if (n > 0) { | |
890 if (from_upstream) { | |
891 u->received += n; | |
892 | |
893 } else { | |
894 s->received += n; | |
895 } | |
896 | |
897 do_write = 1; | |
898 b->last += n; | |
899 continue; | |
900 } | |
901 | |
902 if (n == NGX_ERROR) { | |
903 src->read->eof = 1; | |
904 } | |
905 } | |
906 | |
907 break; | |
908 } | |
909 | |
910 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
911 | |
912 if (src->read->eof && (b->pos == b->last || (dst && dst->read->eof))) { | |
913 handler = c->log->handler; | |
914 c->log->handler = NULL; | |
915 | |
916 ngx_log_error(NGX_LOG_INFO, c->log, 0, | |
917 "%s disconnected" | |
918 ", bytes from/to client:%O/%O" | |
919 ", bytes from/to upstream:%O/%O", | |
920 from_upstream ? "upstream" : "client", | |
921 s->received, c->sent, u->received, pc ? pc->sent : 0); | |
922 | |
923 c->log->handler = handler; | |
924 | |
925 ngx_stream_proxy_finalize(s, NGX_OK); | |
926 return NGX_DONE; | |
927 } | |
928 | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
929 flags = src->read->eof ? NGX_CLOSE_EVENT : 0; |
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
930 |
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
931 if (ngx_handle_read_event(src->read, flags) != NGX_OK) { |
6115 | 932 ngx_stream_proxy_finalize(s, NGX_ERROR); |
933 return NGX_ERROR; | |
934 } | |
935 | |
936 if (dst) { | |
937 if (ngx_handle_write_event(dst->write, 0) != NGX_OK) { | |
938 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
939 return NGX_ERROR; | |
940 } | |
941 | |
942 ngx_add_timer(c->read, pscf->timeout); | |
943 } | |
944 | |
945 return NGX_OK; | |
946 } | |
947 | |
948 | |
949 static void | |
950 ngx_stream_proxy_next_upstream(ngx_stream_session_t *s) | |
951 { | |
952 ngx_msec_t timeout; | |
953 ngx_connection_t *pc; | |
954 ngx_stream_upstream_t *u; | |
955 ngx_stream_proxy_srv_conf_t *pscf; | |
956 | |
957 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
958 "stream proxy next upstream"); | |
959 | |
960 u = s->upstream; | |
961 | |
962 if (u->peer.sockaddr) { | |
963 u->peer.free(&u->peer, u->peer.data, NGX_PEER_FAILED); | |
964 u->peer.sockaddr = NULL; | |
965 } | |
966 | |
967 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
968 | |
969 timeout = pscf->next_upstream_timeout; | |
970 | |
971 if (u->peer.tries == 0 | |
972 || !pscf->next_upstream | |
973 || (timeout && ngx_current_msec - u->peer.start_time >= timeout)) | |
974 { | |
975 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
976 return; | |
977 } | |
978 | |
979 pc = u->peer.connection; | |
980 | |
981 if (pc) { | |
982 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
983 "close proxy upstream connection: %d", pc->fd); | |
984 | |
985 #if (NGX_STREAM_SSL) | |
986 if (pc->ssl) { | |
987 pc->ssl->no_wait_shutdown = 1; | |
988 pc->ssl->no_send_shutdown = 1; | |
989 | |
990 (void) ngx_ssl_shutdown(pc); | |
991 } | |
992 #endif | |
993 | |
994 ngx_close_connection(pc); | |
995 u->peer.connection = NULL; | |
996 } | |
997 | |
998 ngx_stream_proxy_connect(s); | |
999 } | |
1000 | |
1001 | |
1002 static void | |
1003 ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc) | |
1004 { | |
1005 ngx_connection_t *pc; | |
1006 ngx_stream_upstream_t *u; | |
1007 | |
1008 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1009 "finalize stream proxy: %i", rc); | |
1010 | |
1011 u = s->upstream; | |
1012 | |
1013 if (u == NULL) { | |
1014 goto noupstream; | |
1015 } | |
1016 | |
1017 if (u->peer.free && u->peer.sockaddr) { | |
1018 u->peer.free(&u->peer, u->peer.data, 0); | |
1019 u->peer.sockaddr = NULL; | |
1020 } | |
1021 | |
1022 pc = u->peer.connection; | |
1023 | |
1024 if (pc) { | |
1025 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1026 "close stream proxy upstream connection: %d", pc->fd); | |
1027 | |
1028 #if (NGX_STREAM_SSL) | |
1029 if (pc->ssl) { | |
1030 pc->ssl->no_wait_shutdown = 1; | |
1031 (void) ngx_ssl_shutdown(pc); | |
1032 } | |
1033 #endif | |
1034 | |
1035 ngx_close_connection(pc); | |
1036 u->peer.connection = NULL; | |
1037 } | |
1038 | |
1039 noupstream: | |
1040 | |
1041 ngx_stream_close_connection(s->connection); | |
1042 } | |
1043 | |
1044 | |
1045 static u_char * | |
1046 ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, size_t len) | |
1047 { | |
1048 u_char *p; | |
1049 ngx_connection_t *pc; | |
1050 ngx_stream_session_t *s; | |
1051 ngx_stream_upstream_t *u; | |
1052 | |
1053 s = log->data; | |
1054 | |
1055 u = s->upstream; | |
1056 | |
1057 p = buf; | |
1058 | |
1059 if (u->peer.name) { | |
1060 p = ngx_snprintf(p, len, ", upstream: \"%V\"", u->peer.name); | |
1061 len -= p - buf; | |
1062 } | |
1063 | |
1064 pc = u->peer.connection; | |
1065 | |
1066 p = ngx_snprintf(p, len, | |
1067 ", bytes from/to client:%O/%O" | |
1068 ", bytes from/to upstream:%O/%O", | |
1069 s->received, s->connection->sent, | |
1070 u->received, pc ? pc->sent : 0); | |
1071 | |
1072 return p; | |
1073 } | |
1074 | |
1075 | |
1076 static void * | |
1077 ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf) | |
1078 { | |
1079 ngx_stream_proxy_srv_conf_t *conf; | |
1080 | |
1081 conf = ngx_pcalloc(cf->pool, sizeof(ngx_stream_proxy_srv_conf_t)); | |
1082 if (conf == NULL) { | |
1083 return NULL; | |
1084 } | |
1085 | |
1086 /* | |
1087 * set by ngx_pcalloc(): | |
1088 * | |
1089 * conf->ssl_protocols = 0; | |
1090 * conf->ssl_ciphers = { 0, NULL }; | |
1091 * conf->ssl_name = { 0, NULL }; | |
1092 * conf->ssl_trusted_certificate = { 0, NULL }; | |
1093 * conf->ssl_crl = { 0, NULL }; | |
1094 * conf->ssl_certificate = { 0, NULL }; | |
1095 * conf->ssl_certificate_key = { 0, NULL }; | |
1096 * | |
1097 * conf->ssl = NULL; | |
1098 * conf->upstream = NULL; | |
1099 */ | |
1100 | |
1101 conf->connect_timeout = NGX_CONF_UNSET_MSEC; | |
1102 conf->timeout = NGX_CONF_UNSET_MSEC; | |
1103 conf->next_upstream_timeout = NGX_CONF_UNSET_MSEC; | |
1104 conf->downstream_buf_size = NGX_CONF_UNSET_SIZE; | |
1105 conf->upstream_buf_size = NGX_CONF_UNSET_SIZE; | |
1106 conf->next_upstream_tries = NGX_CONF_UNSET_UINT; | |
1107 conf->next_upstream = NGX_CONF_UNSET; | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1108 conf->local = NGX_CONF_UNSET_PTR; |
6115 | 1109 |
1110 #if (NGX_STREAM_SSL) | |
1111 conf->ssl_enable = NGX_CONF_UNSET; | |
1112 conf->ssl_session_reuse = NGX_CONF_UNSET; | |
1113 conf->ssl_server_name = NGX_CONF_UNSET; | |
1114 conf->ssl_verify = NGX_CONF_UNSET; | |
1115 conf->ssl_verify_depth = NGX_CONF_UNSET_UINT; | |
1116 conf->ssl_passwords = NGX_CONF_UNSET_PTR; | |
1117 #endif | |
1118 | |
1119 return conf; | |
1120 } | |
1121 | |
1122 | |
1123 static char * | |
1124 ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, void *child) | |
1125 { | |
1126 ngx_stream_proxy_srv_conf_t *prev = parent; | |
1127 ngx_stream_proxy_srv_conf_t *conf = child; | |
1128 | |
1129 ngx_conf_merge_msec_value(conf->connect_timeout, | |
1130 prev->connect_timeout, 60000); | |
1131 | |
1132 ngx_conf_merge_msec_value(conf->timeout, | |
1133 prev->timeout, 10 * 60000); | |
1134 | |
1135 ngx_conf_merge_msec_value(conf->next_upstream_timeout, | |
1136 prev->next_upstream_timeout, 0); | |
1137 | |
1138 ngx_conf_merge_size_value(conf->downstream_buf_size, | |
1139 prev->downstream_buf_size, 16384); | |
1140 | |
1141 ngx_conf_merge_size_value(conf->upstream_buf_size, | |
1142 prev->upstream_buf_size, 16384); | |
1143 | |
1144 ngx_conf_merge_uint_value(conf->next_upstream_tries, | |
1145 prev->next_upstream_tries, 0); | |
1146 | |
1147 ngx_conf_merge_value(conf->next_upstream, prev->next_upstream, 1); | |
1148 | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1149 ngx_conf_merge_ptr_value(conf->local, prev->local, NULL); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1150 |
6115 | 1151 #if (NGX_STREAM_SSL) |
1152 | |
1153 ngx_conf_merge_value(conf->ssl_enable, prev->ssl_enable, 0); | |
1154 | |
1155 ngx_conf_merge_value(conf->ssl_session_reuse, | |
1156 prev->ssl_session_reuse, 1); | |
1157 | |
1158 ngx_conf_merge_bitmask_value(conf->ssl_protocols, prev->ssl_protocols, | |
6157
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1159 (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1 |
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1160 |NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2)); |
6115 | 1161 |
1162 ngx_conf_merge_str_value(conf->ssl_ciphers, prev->ssl_ciphers, "DEFAULT"); | |
1163 | |
1164 ngx_conf_merge_str_value(conf->ssl_name, prev->ssl_name, ""); | |
1165 | |
1166 ngx_conf_merge_value(conf->ssl_server_name, prev->ssl_server_name, 0); | |
1167 | |
1168 ngx_conf_merge_value(conf->ssl_verify, prev->ssl_verify, 0); | |
1169 | |
1170 ngx_conf_merge_uint_value(conf->ssl_verify_depth, | |
1171 prev->ssl_verify_depth, 1); | |
1172 | |
1173 ngx_conf_merge_str_value(conf->ssl_trusted_certificate, | |
1174 prev->ssl_trusted_certificate, ""); | |
1175 | |
1176 ngx_conf_merge_str_value(conf->ssl_crl, prev->ssl_crl, ""); | |
1177 | |
1178 ngx_conf_merge_str_value(conf->ssl_certificate, | |
1179 prev->ssl_certificate, ""); | |
1180 | |
1181 ngx_conf_merge_str_value(conf->ssl_certificate_key, | |
1182 prev->ssl_certificate_key, ""); | |
1183 | |
1184 ngx_conf_merge_ptr_value(conf->ssl_passwords, prev->ssl_passwords, NULL); | |
1185 | |
1186 if (conf->ssl_enable && ngx_stream_proxy_set_ssl(cf, conf) != NGX_OK) { | |
1187 return NGX_CONF_ERROR; | |
1188 } | |
1189 | |
1190 #endif | |
1191 | |
1192 return NGX_CONF_OK; | |
1193 } | |
1194 | |
1195 | |
1196 #if (NGX_STREAM_SSL) | |
1197 | |
1198 static ngx_int_t | |
1199 ngx_stream_proxy_set_ssl(ngx_conf_t *cf, ngx_stream_proxy_srv_conf_t *pscf) | |
1200 { | |
1201 ngx_pool_cleanup_t *cln; | |
1202 | |
1203 pscf->ssl = ngx_pcalloc(cf->pool, sizeof(ngx_ssl_t)); | |
1204 if (pscf->ssl == NULL) { | |
1205 return NGX_ERROR; | |
1206 } | |
1207 | |
1208 pscf->ssl->log = cf->log; | |
1209 | |
1210 if (ngx_ssl_create(pscf->ssl, pscf->ssl_protocols, NULL) != NGX_OK) { | |
1211 return NGX_ERROR; | |
1212 } | |
1213 | |
1214 cln = ngx_pool_cleanup_add(cf->pool, 0); | |
1215 if (cln == NULL) { | |
1216 return NGX_ERROR; | |
1217 } | |
1218 | |
1219 cln->handler = ngx_ssl_cleanup_ctx; | |
1220 cln->data = pscf->ssl; | |
1221 | |
1222 if (pscf->ssl_certificate.len) { | |
1223 | |
1224 if (pscf->ssl_certificate_key.len == 0) { | |
1225 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1226 "no \"proxy_ssl_certificate_key\" is defined " | |
1227 "for certificate \"%V\"", &pscf->ssl_certificate); | |
1228 return NGX_ERROR; | |
1229 } | |
1230 | |
1231 if (ngx_ssl_certificate(cf, pscf->ssl, &pscf->ssl_certificate, | |
1232 &pscf->ssl_certificate_key, pscf->ssl_passwords) | |
1233 != NGX_OK) | |
1234 { | |
1235 return NGX_ERROR; | |
1236 } | |
1237 } | |
1238 | |
1239 if (SSL_CTX_set_cipher_list(pscf->ssl->ctx, | |
1240 (const char *) pscf->ssl_ciphers.data) | |
1241 == 0) | |
1242 { | |
1243 ngx_ssl_error(NGX_LOG_EMERG, cf->log, 0, | |
1244 "SSL_CTX_set_cipher_list(\"%V\") failed", | |
1245 &pscf->ssl_ciphers); | |
1246 return NGX_ERROR; | |
1247 } | |
1248 | |
1249 if (pscf->ssl_verify) { | |
1250 if (pscf->ssl_trusted_certificate.len == 0) { | |
1251 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1252 "no proxy_ssl_trusted_certificate for proxy_ssl_verify"); | |
1253 return NGX_ERROR; | |
1254 } | |
1255 | |
1256 if (ngx_ssl_trusted_certificate(cf, pscf->ssl, | |
1257 &pscf->ssl_trusted_certificate, | |
1258 pscf->ssl_verify_depth) | |
1259 != NGX_OK) | |
1260 { | |
1261 return NGX_ERROR; | |
1262 } | |
1263 | |
1264 if (ngx_ssl_crl(cf, pscf->ssl, &pscf->ssl_crl) != NGX_OK) { | |
1265 return NGX_ERROR; | |
1266 } | |
1267 } | |
1268 | |
1269 return NGX_OK; | |
1270 } | |
1271 | |
1272 #endif | |
1273 | |
1274 | |
1275 static char * | |
1276 ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) | |
1277 { | |
1278 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
1279 | |
1280 ngx_url_t u; | |
1281 ngx_str_t *value, *url; | |
1282 ngx_stream_core_srv_conf_t *cscf; | |
1283 | |
1284 if (pscf->upstream) { | |
1285 return "is duplicate"; | |
1286 } | |
1287 | |
1288 cscf = ngx_stream_conf_get_module_srv_conf(cf, ngx_stream_core_module); | |
1289 | |
1290 cscf->handler = ngx_stream_proxy_handler; | |
1291 | |
1292 value = cf->args->elts; | |
1293 | |
1294 url = &value[1]; | |
1295 | |
1296 ngx_memzero(&u, sizeof(ngx_url_t)); | |
1297 | |
1298 u.url = *url; | |
1299 u.no_resolve = 1; | |
1300 | |
1301 pscf->upstream = ngx_stream_upstream_add(cf, &u, 0); | |
1302 if (pscf->upstream == NULL) { | |
1303 return NGX_CONF_ERROR; | |
1304 } | |
1305 | |
1306 return NGX_CONF_OK; | |
1307 } | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1308 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1309 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1310 static char * |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1311 ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1312 { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1313 ngx_stream_proxy_srv_conf_t *pscf = conf; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1314 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1315 ngx_int_t rc; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1316 ngx_str_t *value; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1317 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1318 if (pscf->local != NGX_CONF_UNSET_PTR) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1319 return "is duplicate"; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1320 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1321 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1322 value = cf->args->elts; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1323 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1324 if (ngx_strcmp(value[1].data, "off") == 0) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1325 pscf->local = NULL; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1326 return NGX_CONF_OK; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1327 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1328 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1329 pscf->local = ngx_palloc(cf->pool, sizeof(ngx_addr_t)); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1330 if (pscf->local == NULL) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1331 return NGX_CONF_ERROR; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1332 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1333 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1334 rc = ngx_parse_addr(cf->pool, pscf->local, value[1].data, value[1].len); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1335 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1336 switch (rc) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1337 case NGX_OK: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1338 pscf->local->name = value[1]; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1339 return NGX_CONF_OK; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1340 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1341 case NGX_DECLINED: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1342 ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1343 "invalid address \"%V\"", &value[1]); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1344 /* fall through */ |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1345 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1346 default: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1347 return NGX_CONF_ERROR; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1348 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1349 } |