Mercurial > hg > nginx
annotate src/stream/ngx_stream_proxy_module.c @ 6200:abee77018d3a
Stream: common handler for upstream and downstream.
author | Roman Arutyunyan <arut@nginx.com> |
---|---|
date | Tue, 23 Jun 2015 20:17:47 +0300 |
parents | fa663739e115 |
children | 24488e6db782 |
rev | line source |
---|---|
6115 | 1 |
2 /* | |
3 * Copyright (C) Roman Arutyunyan | |
4 * Copyright (C) Nginx, Inc. | |
5 */ | |
6 | |
7 | |
8 #include <ngx_config.h> | |
9 #include <ngx_core.h> | |
10 #include <ngx_stream.h> | |
11 | |
12 | |
13 typedef void (*ngx_stream_proxy_handler_pt)(ngx_stream_session_t *s); | |
14 | |
15 | |
16 typedef struct { | |
17 ngx_msec_t connect_timeout; | |
18 ngx_msec_t timeout; | |
19 ngx_msec_t next_upstream_timeout; | |
20 size_t downstream_buf_size; | |
21 size_t upstream_buf_size; | |
22 ngx_uint_t next_upstream_tries; | |
23 ngx_flag_t next_upstream; | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
24 ngx_flag_t proxy_protocol; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
25 ngx_addr_t *local; |
6115 | 26 |
27 #if (NGX_STREAM_SSL) | |
28 ngx_flag_t ssl_enable; | |
29 ngx_flag_t ssl_session_reuse; | |
30 ngx_uint_t ssl_protocols; | |
31 ngx_str_t ssl_ciphers; | |
32 ngx_str_t ssl_name; | |
33 ngx_flag_t ssl_server_name; | |
34 | |
35 ngx_flag_t ssl_verify; | |
36 ngx_uint_t ssl_verify_depth; | |
37 ngx_str_t ssl_trusted_certificate; | |
38 ngx_str_t ssl_crl; | |
39 ngx_str_t ssl_certificate; | |
40 ngx_str_t ssl_certificate_key; | |
41 ngx_array_t *ssl_passwords; | |
42 | |
43 ngx_ssl_t *ssl; | |
44 #endif | |
45 | |
46 ngx_stream_upstream_srv_conf_t *upstream; | |
47 } ngx_stream_proxy_srv_conf_t; | |
48 | |
49 | |
50 static void ngx_stream_proxy_handler(ngx_stream_session_t *s); | |
51 static void ngx_stream_proxy_connect(ngx_stream_session_t *s); | |
52 static void ngx_stream_proxy_init_upstream(ngx_stream_session_t *s); | |
53 static void ngx_stream_proxy_upstream_handler(ngx_event_t *ev); | |
54 static void ngx_stream_proxy_downstream_handler(ngx_event_t *ev); | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
55 static void ngx_stream_proxy_process_connection(ngx_event_t *ev, |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
56 ngx_uint_t from_upstream); |
6115 | 57 static void ngx_stream_proxy_connect_handler(ngx_event_t *ev); |
58 static ngx_int_t ngx_stream_proxy_test_connect(ngx_connection_t *c); | |
59 static ngx_int_t ngx_stream_proxy_process(ngx_stream_session_t *s, | |
60 ngx_uint_t from_upstream, ngx_uint_t do_write); | |
61 static void ngx_stream_proxy_next_upstream(ngx_stream_session_t *s); | |
62 static void ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc); | |
63 static u_char *ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, | |
64 size_t len); | |
65 | |
66 static void *ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf); | |
67 static char *ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, | |
68 void *child); | |
69 static char *ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, | |
70 void *conf); | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
71 static char *ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
72 void *conf); |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
73 static ngx_int_t ngx_stream_proxy_send_proxy_protocol(ngx_stream_session_t *s); |
6115 | 74 |
75 #if (NGX_STREAM_SSL) | |
76 | |
77 static char *ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, | |
78 ngx_command_t *cmd, void *conf); | |
79 static void ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s); | |
80 static void ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc); | |
81 static ngx_int_t ngx_stream_proxy_ssl_name(ngx_stream_session_t *s); | |
82 static ngx_int_t ngx_stream_proxy_set_ssl(ngx_conf_t *cf, | |
83 ngx_stream_proxy_srv_conf_t *pscf); | |
84 | |
85 | |
86 static ngx_conf_bitmask_t ngx_stream_proxy_ssl_protocols[] = { | |
87 { ngx_string("SSLv2"), NGX_SSL_SSLv2 }, | |
88 { ngx_string("SSLv3"), NGX_SSL_SSLv3 }, | |
89 { ngx_string("TLSv1"), NGX_SSL_TLSv1 }, | |
90 { ngx_string("TLSv1.1"), NGX_SSL_TLSv1_1 }, | |
91 { ngx_string("TLSv1.2"), NGX_SSL_TLSv1_2 }, | |
92 { ngx_null_string, 0 } | |
93 }; | |
94 | |
95 #endif | |
96 | |
97 | |
98 static ngx_command_t ngx_stream_proxy_commands[] = { | |
99 | |
100 { ngx_string("proxy_pass"), | |
101 NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
102 ngx_stream_proxy_pass, | |
103 NGX_STREAM_SRV_CONF_OFFSET, | |
104 0, | |
105 NULL }, | |
106 | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
107 { ngx_string("proxy_bind"), |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
108 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
109 ngx_stream_proxy_bind, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
110 NGX_STREAM_SRV_CONF_OFFSET, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
111 0, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
112 NULL }, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
113 |
6115 | 114 { ngx_string("proxy_connect_timeout"), |
115 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
116 ngx_conf_set_msec_slot, | |
117 NGX_STREAM_SRV_CONF_OFFSET, | |
118 offsetof(ngx_stream_proxy_srv_conf_t, connect_timeout), | |
119 NULL }, | |
120 | |
121 { ngx_string("proxy_timeout"), | |
122 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
123 ngx_conf_set_msec_slot, | |
124 NGX_STREAM_SRV_CONF_OFFSET, | |
125 offsetof(ngx_stream_proxy_srv_conf_t, timeout), | |
126 NULL }, | |
127 | |
128 { ngx_string("proxy_downstream_buffer"), | |
129 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
130 ngx_conf_set_size_slot, | |
131 NGX_STREAM_SRV_CONF_OFFSET, | |
132 offsetof(ngx_stream_proxy_srv_conf_t, downstream_buf_size), | |
133 NULL }, | |
134 | |
135 { ngx_string("proxy_upstream_buffer"), | |
136 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
137 ngx_conf_set_size_slot, | |
138 NGX_STREAM_SRV_CONF_OFFSET, | |
139 offsetof(ngx_stream_proxy_srv_conf_t, upstream_buf_size), | |
140 NULL }, | |
141 | |
142 { ngx_string("proxy_next_upstream"), | |
143 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
144 ngx_conf_set_flag_slot, | |
145 NGX_STREAM_SRV_CONF_OFFSET, | |
146 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream), | |
147 NULL }, | |
148 | |
149 { ngx_string("proxy_next_upstream_tries"), | |
150 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
151 ngx_conf_set_num_slot, | |
152 NGX_STREAM_SRV_CONF_OFFSET, | |
153 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_tries), | |
154 NULL }, | |
155 | |
156 { ngx_string("proxy_next_upstream_timeout"), | |
157 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
158 ngx_conf_set_msec_slot, | |
159 NGX_STREAM_SRV_CONF_OFFSET, | |
160 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_timeout), | |
161 NULL }, | |
162 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
163 { ngx_string("proxy_protocol"), |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
164 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
165 ngx_conf_set_flag_slot, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
166 NGX_STREAM_SRV_CONF_OFFSET, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
167 offsetof(ngx_stream_proxy_srv_conf_t, proxy_protocol), |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
168 NULL }, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
169 |
6115 | 170 #if (NGX_STREAM_SSL) |
171 | |
172 { ngx_string("proxy_ssl"), | |
173 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
174 ngx_conf_set_flag_slot, | |
175 NGX_STREAM_SRV_CONF_OFFSET, | |
176 offsetof(ngx_stream_proxy_srv_conf_t, ssl_enable), | |
177 NULL }, | |
178 | |
179 { ngx_string("proxy_ssl_session_reuse"), | |
180 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
181 ngx_conf_set_flag_slot, | |
182 NGX_STREAM_SRV_CONF_OFFSET, | |
183 offsetof(ngx_stream_proxy_srv_conf_t, ssl_session_reuse), | |
184 NULL }, | |
185 | |
186 { ngx_string("proxy_ssl_protocols"), | |
187 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_1MORE, | |
188 ngx_conf_set_bitmask_slot, | |
189 NGX_STREAM_SRV_CONF_OFFSET, | |
190 offsetof(ngx_stream_proxy_srv_conf_t, ssl_protocols), | |
191 &ngx_stream_proxy_ssl_protocols }, | |
192 | |
193 { ngx_string("proxy_ssl_ciphers"), | |
194 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
195 ngx_conf_set_str_slot, | |
196 NGX_STREAM_SRV_CONF_OFFSET, | |
197 offsetof(ngx_stream_proxy_srv_conf_t, ssl_ciphers), | |
198 NULL }, | |
199 | |
200 { ngx_string("proxy_ssl_name"), | |
201 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
202 ngx_conf_set_str_slot, | |
203 NGX_STREAM_SRV_CONF_OFFSET, | |
204 offsetof(ngx_stream_proxy_srv_conf_t, ssl_name), | |
205 NULL }, | |
206 | |
207 { ngx_string("proxy_ssl_server_name"), | |
208 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
209 ngx_conf_set_flag_slot, | |
210 NGX_STREAM_SRV_CONF_OFFSET, | |
211 offsetof(ngx_stream_proxy_srv_conf_t, ssl_server_name), | |
212 NULL }, | |
213 | |
214 { ngx_string("proxy_ssl_verify"), | |
215 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
216 ngx_conf_set_flag_slot, | |
217 NGX_STREAM_SRV_CONF_OFFSET, | |
218 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify), | |
219 NULL }, | |
220 | |
221 { ngx_string("proxy_ssl_verify_depth"), | |
222 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
223 ngx_conf_set_num_slot, | |
224 NGX_STREAM_SRV_CONF_OFFSET, | |
225 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify_depth), | |
226 NULL }, | |
227 | |
228 { ngx_string("proxy_ssl_trusted_certificate"), | |
229 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
230 ngx_conf_set_str_slot, | |
231 NGX_STREAM_SRV_CONF_OFFSET, | |
232 offsetof(ngx_stream_proxy_srv_conf_t, ssl_trusted_certificate), | |
233 NULL }, | |
234 | |
235 { ngx_string("proxy_ssl_crl"), | |
236 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
237 ngx_conf_set_str_slot, | |
238 NGX_STREAM_SRV_CONF_OFFSET, | |
239 offsetof(ngx_stream_proxy_srv_conf_t, ssl_crl), | |
240 NULL }, | |
241 | |
242 { ngx_string("proxy_ssl_certificate"), | |
243 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
244 ngx_conf_set_str_slot, | |
245 NGX_STREAM_SRV_CONF_OFFSET, | |
246 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate), | |
247 NULL }, | |
248 | |
249 { ngx_string("proxy_ssl_certificate_key"), | |
250 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
251 ngx_conf_set_str_slot, | |
252 NGX_STREAM_SRV_CONF_OFFSET, | |
253 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate_key), | |
254 NULL }, | |
255 | |
256 { ngx_string("proxy_ssl_password_file"), | |
257 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
258 ngx_stream_proxy_ssl_password_file, | |
259 NGX_STREAM_SRV_CONF_OFFSET, | |
260 0, | |
261 NULL }, | |
262 | |
263 #endif | |
264 | |
265 ngx_null_command | |
266 }; | |
267 | |
268 | |
269 static ngx_stream_module_t ngx_stream_proxy_module_ctx = { | |
6174
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
270 NULL, /* postconfiguration */ |
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
271 |
6115 | 272 NULL, /* create main configuration */ |
273 NULL, /* init main configuration */ | |
274 | |
275 ngx_stream_proxy_create_srv_conf, /* create server configuration */ | |
276 ngx_stream_proxy_merge_srv_conf /* merge server configuration */ | |
277 }; | |
278 | |
279 | |
280 ngx_module_t ngx_stream_proxy_module = { | |
281 NGX_MODULE_V1, | |
282 &ngx_stream_proxy_module_ctx, /* module context */ | |
283 ngx_stream_proxy_commands, /* module directives */ | |
284 NGX_STREAM_MODULE, /* module type */ | |
285 NULL, /* init master */ | |
286 NULL, /* init module */ | |
287 NULL, /* init process */ | |
288 NULL, /* init thread */ | |
289 NULL, /* exit thread */ | |
290 NULL, /* exit process */ | |
291 NULL, /* exit master */ | |
292 NGX_MODULE_V1_PADDING | |
293 }; | |
294 | |
295 | |
296 static void | |
297 ngx_stream_proxy_handler(ngx_stream_session_t *s) | |
298 { | |
299 u_char *p; | |
300 ngx_connection_t *c; | |
301 ngx_stream_upstream_t *u; | |
302 ngx_stream_proxy_srv_conf_t *pscf; | |
303 ngx_stream_upstream_srv_conf_t *uscf; | |
304 | |
305 c = s->connection; | |
306 | |
307 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
308 | |
309 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
310 "proxy connection handler"); | |
311 | |
312 u = ngx_pcalloc(c->pool, sizeof(ngx_stream_upstream_t)); | |
313 if (u == NULL) { | |
314 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
315 return; | |
316 } | |
317 | |
318 s->upstream = u; | |
319 | |
320 s->log_handler = ngx_stream_proxy_log_error; | |
321 | |
322 u->peer.log = c->log; | |
323 u->peer.log_error = NGX_ERROR_ERR; | |
324 | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
325 u->peer.local = pscf->local; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
326 |
6115 | 327 uscf = pscf->upstream; |
328 | |
329 if (uscf->peer.init(s, uscf) != NGX_OK) { | |
330 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
331 return; | |
332 } | |
333 | |
334 u->peer.start_time = ngx_current_msec; | |
335 | |
336 if (pscf->next_upstream_tries | |
337 && u->peer.tries > pscf->next_upstream_tries) | |
338 { | |
339 u->peer.tries = pscf->next_upstream_tries; | |
340 } | |
341 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
342 u->proxy_protocol = pscf->proxy_protocol; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
343 |
6115 | 344 p = ngx_pnalloc(c->pool, pscf->downstream_buf_size); |
345 if (p == NULL) { | |
346 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
347 return; | |
348 } | |
349 | |
350 u->downstream_buf.start = p; | |
351 u->downstream_buf.end = p + pscf->downstream_buf_size; | |
352 u->downstream_buf.pos = p; | |
353 u->downstream_buf.last = p; | |
354 | |
355 c->write->handler = ngx_stream_proxy_downstream_handler; | |
356 c->read->handler = ngx_stream_proxy_downstream_handler; | |
357 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
358 if (u->proxy_protocol |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
359 #if (NGX_STREAM_SSL) |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
360 && pscf->ssl == NULL |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
361 #endif |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
362 && pscf->downstream_buf_size >= NGX_PROXY_PROTOCOL_MAX_HEADER |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
363 ) |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
364 { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
365 /* optimization for a typical case */ |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
366 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
367 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
368 "stream proxy send PROXY protocol header"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
369 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
370 p = ngx_proxy_protocol_write(c, u->downstream_buf.last, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
371 u->downstream_buf.end); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
372 if (p == NULL) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
373 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
374 return; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
375 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
376 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
377 u->downstream_buf.last = p; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
378 u->proxy_protocol = 0; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
379 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
380 |
6115 | 381 if (ngx_stream_proxy_process(s, 0, 0) != NGX_OK) { |
382 return; | |
383 } | |
384 | |
385 ngx_stream_proxy_connect(s); | |
386 } | |
387 | |
388 | |
389 static void | |
390 ngx_stream_proxy_connect(ngx_stream_session_t *s) | |
391 { | |
392 ngx_int_t rc; | |
393 ngx_connection_t *c, *pc; | |
394 ngx_stream_upstream_t *u; | |
395 ngx_stream_proxy_srv_conf_t *pscf; | |
396 | |
397 c = s->connection; | |
398 | |
399 c->log->action = "connecting to upstream"; | |
400 | |
401 u = s->upstream; | |
402 | |
403 rc = ngx_event_connect_peer(&u->peer); | |
404 | |
405 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, c->log, 0, "proxy connect: %i", rc); | |
406 | |
407 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
408 | |
409 if (rc == NGX_ERROR) { | |
410 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
411 return; | |
412 } | |
413 | |
414 if (rc == NGX_BUSY) { | |
415 ngx_log_error(NGX_LOG_ERR, c->log, 0, "no live upstreams"); | |
416 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
417 return; | |
418 } | |
419 | |
420 if (rc == NGX_DECLINED) { | |
421 ngx_stream_proxy_next_upstream(s); | |
422 return; | |
423 } | |
424 | |
425 /* rc == NGX_OK || rc == NGX_AGAIN || rc == NGX_DONE */ | |
426 | |
427 pc = u->peer.connection; | |
428 | |
429 pc->data = s; | |
430 pc->log = c->log; | |
431 pc->pool = c->pool; | |
432 pc->read->log = c->log; | |
433 pc->write->log = c->log; | |
434 | |
435 if (rc != NGX_AGAIN) { | |
436 ngx_stream_proxy_init_upstream(s); | |
437 return; | |
438 } | |
439 | |
440 pc->read->handler = ngx_stream_proxy_connect_handler; | |
441 pc->write->handler = ngx_stream_proxy_connect_handler; | |
442 | |
443 ngx_add_timer(pc->write, pscf->connect_timeout); | |
444 } | |
445 | |
446 | |
447 static void | |
448 ngx_stream_proxy_init_upstream(ngx_stream_session_t *s) | |
449 { | |
450 u_char *p; | |
451 ngx_connection_t *c, *pc; | |
452 ngx_log_handler_pt handler; | |
453 ngx_stream_upstream_t *u; | |
454 ngx_stream_proxy_srv_conf_t *pscf; | |
455 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
456 u = s->upstream; |
6115 | 457 |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
458 if (u->proxy_protocol) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
459 if (ngx_stream_proxy_send_proxy_protocol(s) != NGX_OK) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
460 return; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
461 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
462 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
463 u->proxy_protocol = 0; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
464 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
465 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
466 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
6115 | 467 |
468 pc = u->peer.connection; | |
469 | |
470 #if (NGX_STREAM_SSL) | |
471 if (pscf->ssl && pc->ssl == NULL) { | |
472 ngx_stream_proxy_ssl_init_connection(s); | |
473 return; | |
474 } | |
475 #endif | |
476 | |
477 c = s->connection; | |
478 | |
479 if (c->log->log_level >= NGX_LOG_INFO) { | |
480 ngx_str_t s; | |
481 u_char addr[NGX_SOCKADDR_STRLEN]; | |
482 | |
483 s.len = NGX_SOCKADDR_STRLEN; | |
484 s.data = addr; | |
485 | |
486 if (ngx_connection_local_sockaddr(pc, &s, 1) == NGX_OK) { | |
487 handler = c->log->handler; | |
488 c->log->handler = NULL; | |
489 | |
490 ngx_log_error(NGX_LOG_INFO, c->log, 0, "proxy %V connected to %V", | |
491 &s, u->peer.name); | |
492 | |
493 c->log->handler = handler; | |
494 } | |
495 } | |
496 | |
497 c->log->action = "proxying connection"; | |
498 | |
499 p = ngx_pnalloc(c->pool, pscf->upstream_buf_size); | |
500 if (p == NULL) { | |
501 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
502 return; | |
503 } | |
504 | |
505 u->upstream_buf.start = p; | |
506 u->upstream_buf.end = p + pscf->upstream_buf_size; | |
507 u->upstream_buf.pos = p; | |
508 u->upstream_buf.last = p; | |
509 | |
510 pc->read->handler = ngx_stream_proxy_upstream_handler; | |
511 pc->write->handler = ngx_stream_proxy_upstream_handler; | |
512 | |
513 if (ngx_stream_proxy_process(s, 1, 0) != NGX_OK) { | |
514 return; | |
515 } | |
516 | |
517 ngx_stream_proxy_process(s, 0, 1); | |
518 } | |
519 | |
520 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
521 static ngx_int_t |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
522 ngx_stream_proxy_send_proxy_protocol(ngx_stream_session_t *s) |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
523 { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
524 u_char *p; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
525 ssize_t n, size; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
526 ngx_connection_t *c, *pc; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
527 ngx_stream_upstream_t *u; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
528 ngx_stream_proxy_srv_conf_t *pscf; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
529 u_char buf[NGX_PROXY_PROTOCOL_MAX_HEADER]; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
530 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
531 c = s->connection; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
532 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
533 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
534 "stream proxy send PROXY protocol header"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
535 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
536 p = ngx_proxy_protocol_write(c, buf, buf + NGX_PROXY_PROTOCOL_MAX_HEADER); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
537 if (p == NULL) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
538 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
539 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
540 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
541 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
542 u = s->upstream; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
543 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
544 pc = u->peer.connection; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
545 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
546 size = p - buf; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
547 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
548 n = pc->send(pc, buf, size); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
549 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
550 if (n == NGX_AGAIN) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
551 if (ngx_handle_write_event(pc->write, 0) != NGX_OK) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
552 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
553 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
554 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
555 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
556 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
557 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
558 ngx_add_timer(pc->write, pscf->timeout); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
559 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
560 pc->write->handler = ngx_stream_proxy_connect_handler; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
561 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
562 return NGX_AGAIN; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
563 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
564 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
565 if (n == NGX_ERROR) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
566 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
567 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
568 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
569 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
570 if (n != size) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
571 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
572 /* |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
573 * PROXY protocol specification: |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
574 * The sender must always ensure that the header |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
575 * is sent at once, so that the transport layer |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
576 * maintains atomicity along the path to the receiver. |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
577 */ |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
578 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
579 ngx_log_error(NGX_LOG_ERR, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
580 "could not send PROXY protocol header at once"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
581 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
582 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
583 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
584 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
585 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
586 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
587 return NGX_OK; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
588 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
589 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
590 |
6115 | 591 #if (NGX_STREAM_SSL) |
592 | |
593 static char * | |
594 ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, ngx_command_t *cmd, | |
595 void *conf) | |
596 { | |
597 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
598 | |
599 ngx_str_t *value; | |
600 | |
601 if (pscf->ssl_passwords != NGX_CONF_UNSET_PTR) { | |
602 return "is duplicate"; | |
603 } | |
604 | |
605 value = cf->args->elts; | |
606 | |
607 pscf->ssl_passwords = ngx_ssl_read_password_file(cf, &value[1]); | |
608 | |
609 if (pscf->ssl_passwords == NULL) { | |
610 return NGX_CONF_ERROR; | |
611 } | |
612 | |
613 return NGX_CONF_OK; | |
614 } | |
615 | |
616 | |
617 static void | |
618 ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s) | |
619 { | |
620 ngx_int_t rc; | |
621 ngx_connection_t *pc; | |
622 ngx_stream_upstream_t *u; | |
623 ngx_stream_proxy_srv_conf_t *pscf; | |
624 | |
625 u = s->upstream; | |
626 | |
627 pc = u->peer.connection; | |
628 | |
629 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
630 | |
631 if (ngx_ssl_create_connection(pscf->ssl, pc, NGX_SSL_BUFFER|NGX_SSL_CLIENT) | |
632 != NGX_OK) | |
633 { | |
634 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
635 return; | |
636 } | |
637 | |
638 if (pscf->ssl_server_name || pscf->ssl_verify) { | |
639 if (ngx_stream_proxy_ssl_name(s) != NGX_OK) { | |
640 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
641 return; | |
642 } | |
643 } | |
644 | |
645 if (pscf->ssl_session_reuse) { | |
646 if (u->peer.set_session(&u->peer, u->peer.data) != NGX_OK) { | |
647 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
648 return; | |
649 } | |
650 } | |
651 | |
652 s->connection->log->action = "SSL handshaking to upstream"; | |
653 | |
654 rc = ngx_ssl_handshake(pc); | |
655 | |
656 if (rc == NGX_AGAIN) { | |
657 | |
658 if (!pc->write->timer_set) { | |
659 ngx_add_timer(pc->write, pscf->connect_timeout); | |
660 } | |
661 | |
662 pc->ssl->handler = ngx_stream_proxy_ssl_handshake; | |
663 return; | |
664 } | |
665 | |
666 ngx_stream_proxy_ssl_handshake(pc); | |
667 } | |
668 | |
669 | |
670 static void | |
671 ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc) | |
672 { | |
673 long rc; | |
674 ngx_stream_session_t *s; | |
675 ngx_stream_upstream_t *u; | |
676 ngx_stream_proxy_srv_conf_t *pscf; | |
677 | |
678 s = pc->data; | |
679 | |
680 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
681 | |
682 if (pc->ssl->handshaked) { | |
683 | |
684 if (pscf->ssl_verify) { | |
685 rc = SSL_get_verify_result(pc->ssl->connection); | |
686 | |
687 if (rc != X509_V_OK) { | |
688 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
689 "upstream SSL certificate verify error: (%l:%s)", | |
690 rc, X509_verify_cert_error_string(rc)); | |
691 goto failed; | |
692 } | |
693 | |
694 u = s->upstream; | |
695 | |
696 if (ngx_ssl_check_host(pc, &u->ssl_name) != NGX_OK) { | |
697 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
698 "upstream SSL certificate does not match \"%V\"", | |
699 &u->ssl_name); | |
700 goto failed; | |
701 } | |
702 } | |
703 | |
704 if (pscf->ssl_session_reuse) { | |
705 u = s->upstream; | |
706 u->peer.save_session(&u->peer, u->peer.data); | |
707 } | |
708 | |
709 ngx_stream_proxy_init_upstream(s); | |
710 | |
711 return; | |
712 } | |
713 | |
714 failed: | |
715 | |
716 ngx_stream_proxy_next_upstream(s); | |
717 } | |
718 | |
719 | |
720 static ngx_int_t | |
721 ngx_stream_proxy_ssl_name(ngx_stream_session_t *s) | |
722 { | |
723 u_char *p, *last; | |
724 ngx_str_t name; | |
725 ngx_stream_upstream_t *u; | |
726 ngx_stream_proxy_srv_conf_t *pscf; | |
727 | |
728 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
729 | |
730 u = s->upstream; | |
731 | |
732 name = pscf->ssl_name; | |
733 | |
734 if (name.len == 0) { | |
735 name = pscf->upstream->host; | |
736 } | |
737 | |
738 if (name.len == 0) { | |
739 goto done; | |
740 } | |
741 | |
742 /* | |
743 * ssl name here may contain port, strip it for compatibility | |
744 * with the http module | |
745 */ | |
746 | |
747 p = name.data; | |
748 last = name.data + name.len; | |
749 | |
750 if (*p == '[') { | |
751 p = ngx_strlchr(p, last, ']'); | |
752 | |
753 if (p == NULL) { | |
754 p = name.data; | |
755 } | |
756 } | |
757 | |
758 p = ngx_strlchr(p, last, ':'); | |
759 | |
760 if (p != NULL) { | |
761 name.len = p - name.data; | |
762 } | |
763 | |
764 if (!pscf->ssl_server_name) { | |
765 goto done; | |
766 } | |
767 | |
768 #ifdef SSL_CTRL_SET_TLSEXT_HOSTNAME | |
769 | |
770 /* as per RFC 6066, literal IPv4 and IPv6 addresses are not permitted */ | |
771 | |
772 if (name.len == 0 || *name.data == '[') { | |
773 goto done; | |
774 } | |
775 | |
776 if (ngx_inet_addr(name.data, name.len) != INADDR_NONE) { | |
777 goto done; | |
778 } | |
779 | |
780 /* | |
781 * SSL_set_tlsext_host_name() needs a null-terminated string, | |
782 * hence we explicitly null-terminate name here | |
783 */ | |
784 | |
785 p = ngx_pnalloc(s->connection->pool, name.len + 1); | |
786 if (p == NULL) { | |
787 return NGX_ERROR; | |
788 } | |
789 | |
790 (void) ngx_cpystrn(p, name.data, name.len + 1); | |
791 | |
792 name.data = p; | |
793 | |
794 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
795 "upstream SSL server name: \"%s\"", name.data); | |
796 | |
797 if (SSL_set_tlsext_host_name(u->peer.connection->ssl->connection, name.data) | |
798 == 0) | |
799 { | |
800 ngx_ssl_error(NGX_LOG_ERR, s->connection->log, 0, | |
801 "SSL_set_tlsext_host_name(\"%s\") failed", name.data); | |
802 return NGX_ERROR; | |
803 } | |
804 | |
805 #endif | |
806 | |
807 done: | |
808 | |
809 u->ssl_name = name; | |
810 | |
811 return NGX_OK; | |
812 } | |
813 | |
814 #endif | |
815 | |
816 | |
817 static void | |
818 ngx_stream_proxy_downstream_handler(ngx_event_t *ev) | |
819 { | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
820 ngx_stream_proxy_process_connection(ev, ev->write); |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
821 } |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
822 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
823 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
824 static void |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
825 ngx_stream_proxy_upstream_handler(ngx_event_t *ev) |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
826 { |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
827 ngx_stream_proxy_process_connection(ev, !ev->write); |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
828 } |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
829 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
830 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
831 static void |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
832 ngx_stream_proxy_process_connection(ngx_event_t *ev, ngx_uint_t from_upstream) |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
833 { |
6115 | 834 ngx_connection_t *c; |
835 ngx_stream_session_t *s; | |
836 ngx_stream_upstream_t *u; | |
837 | |
838 c = ev->data; | |
839 s = c->data; | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
840 u = s->upstream; |
6115 | 841 |
842 if (ev->timedout) { | |
843 ngx_connection_error(c, NGX_ETIMEDOUT, "connection timed out"); | |
844 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
845 return; | |
846 } | |
847 | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
848 if (from_upstream && u->upstream_buf.start == NULL) { |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
849 return; |
6115 | 850 } |
851 | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
852 ngx_stream_proxy_process(s, from_upstream, ev->write); |
6115 | 853 } |
854 | |
855 | |
856 static void | |
857 ngx_stream_proxy_connect_handler(ngx_event_t *ev) | |
858 { | |
859 ngx_connection_t *c; | |
860 ngx_stream_session_t *s; | |
861 | |
862 c = ev->data; | |
863 s = c->data; | |
864 | |
865 if (ev->timedout) { | |
866 ngx_log_error(NGX_LOG_ERR, c->log, NGX_ETIMEDOUT, "upstream timed out"); | |
867 ngx_stream_proxy_next_upstream(s); | |
868 return; | |
869 } | |
870 | |
871 ngx_del_timer(c->write); | |
872 | |
873 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
874 "stream proxy connect upstream"); | |
875 | |
876 if (ngx_stream_proxy_test_connect(c) != NGX_OK) { | |
877 ngx_stream_proxy_next_upstream(s); | |
878 return; | |
879 } | |
880 | |
881 ngx_stream_proxy_init_upstream(s); | |
882 } | |
883 | |
884 | |
885 static ngx_int_t | |
886 ngx_stream_proxy_test_connect(ngx_connection_t *c) | |
887 { | |
888 int err; | |
889 socklen_t len; | |
890 | |
891 #if (NGX_HAVE_KQUEUE) | |
892 | |
893 if (ngx_event_flags & NGX_USE_KQUEUE_EVENT) { | |
894 err = c->write->kq_errno ? c->write->kq_errno : c->read->kq_errno; | |
895 | |
896 if (err) { | |
897 (void) ngx_connection_error(c, err, | |
898 "kevent() reported that connect() failed"); | |
899 return NGX_ERROR; | |
900 } | |
901 | |
902 } else | |
903 #endif | |
904 { | |
905 err = 0; | |
906 len = sizeof(int); | |
907 | |
908 /* | |
909 * BSDs and Linux return 0 and set a pending error in err | |
910 * Solaris returns -1 and sets errno | |
911 */ | |
912 | |
913 if (getsockopt(c->fd, SOL_SOCKET, SO_ERROR, (void *) &err, &len) | |
914 == -1) | |
915 { | |
916 err = ngx_socket_errno; | |
917 } | |
918 | |
919 if (err) { | |
920 (void) ngx_connection_error(c, err, "connect() failed"); | |
921 return NGX_ERROR; | |
922 } | |
923 } | |
924 | |
925 return NGX_OK; | |
926 } | |
927 | |
928 | |
929 static ngx_int_t | |
930 ngx_stream_proxy_process(ngx_stream_session_t *s, ngx_uint_t from_upstream, | |
931 ngx_uint_t do_write) | |
932 { | |
933 size_t size; | |
934 ssize_t n; | |
935 ngx_buf_t *b; | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
936 ngx_uint_t flags; |
6115 | 937 ngx_connection_t *c, *pc, *src, *dst; |
938 ngx_log_handler_pt handler; | |
939 ngx_stream_upstream_t *u; | |
940 ngx_stream_proxy_srv_conf_t *pscf; | |
941 | |
942 u = s->upstream; | |
943 | |
944 c = s->connection; | |
945 pc = u->upstream_buf.start ? u->peer.connection : NULL; | |
946 | |
947 if (from_upstream) { | |
948 src = pc; | |
949 dst = c; | |
950 b = &u->upstream_buf; | |
951 | |
952 } else { | |
953 src = c; | |
954 dst = pc; | |
955 b = &u->downstream_buf; | |
956 } | |
957 | |
958 for ( ;; ) { | |
959 | |
960 if (do_write) { | |
961 | |
962 size = b->last - b->pos; | |
963 | |
964 if (size && dst && dst->write->ready) { | |
965 | |
966 n = dst->send(dst, b->pos, size); | |
967 | |
968 if (n == NGX_ERROR) { | |
969 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
970 return NGX_ERROR; | |
971 } | |
972 | |
973 if (n > 0) { | |
974 b->pos += n; | |
975 | |
976 if (b->pos == b->last) { | |
977 b->pos = b->start; | |
978 b->last = b->start; | |
979 } | |
980 } | |
981 } | |
982 } | |
983 | |
984 size = b->end - b->last; | |
985 | |
986 if (size && src->read->ready) { | |
987 | |
988 n = src->recv(src, b->last, size); | |
989 | |
990 if (n == NGX_AGAIN || n == 0) { | |
991 break; | |
992 } | |
993 | |
994 if (n > 0) { | |
995 if (from_upstream) { | |
996 u->received += n; | |
997 | |
998 } else { | |
999 s->received += n; | |
1000 } | |
1001 | |
1002 do_write = 1; | |
1003 b->last += n; | |
1004 continue; | |
1005 } | |
1006 | |
1007 if (n == NGX_ERROR) { | |
1008 src->read->eof = 1; | |
1009 } | |
1010 } | |
1011 | |
1012 break; | |
1013 } | |
1014 | |
1015 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
1016 | |
1017 if (src->read->eof && (b->pos == b->last || (dst && dst->read->eof))) { | |
1018 handler = c->log->handler; | |
1019 c->log->handler = NULL; | |
1020 | |
1021 ngx_log_error(NGX_LOG_INFO, c->log, 0, | |
1022 "%s disconnected" | |
1023 ", bytes from/to client:%O/%O" | |
1024 ", bytes from/to upstream:%O/%O", | |
1025 from_upstream ? "upstream" : "client", | |
1026 s->received, c->sent, u->received, pc ? pc->sent : 0); | |
1027 | |
1028 c->log->handler = handler; | |
1029 | |
1030 ngx_stream_proxy_finalize(s, NGX_OK); | |
1031 return NGX_DONE; | |
1032 } | |
1033 | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1034 flags = src->read->eof ? NGX_CLOSE_EVENT : 0; |
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1035 |
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1036 if (ngx_handle_read_event(src->read, flags) != NGX_OK) { |
6115 | 1037 ngx_stream_proxy_finalize(s, NGX_ERROR); |
1038 return NGX_ERROR; | |
1039 } | |
1040 | |
1041 if (dst) { | |
1042 if (ngx_handle_write_event(dst->write, 0) != NGX_OK) { | |
1043 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
1044 return NGX_ERROR; | |
1045 } | |
1046 | |
1047 ngx_add_timer(c->read, pscf->timeout); | |
1048 } | |
1049 | |
1050 return NGX_OK; | |
1051 } | |
1052 | |
1053 | |
1054 static void | |
1055 ngx_stream_proxy_next_upstream(ngx_stream_session_t *s) | |
1056 { | |
1057 ngx_msec_t timeout; | |
1058 ngx_connection_t *pc; | |
1059 ngx_stream_upstream_t *u; | |
1060 ngx_stream_proxy_srv_conf_t *pscf; | |
1061 | |
1062 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1063 "stream proxy next upstream"); | |
1064 | |
1065 u = s->upstream; | |
1066 | |
1067 if (u->peer.sockaddr) { | |
1068 u->peer.free(&u->peer, u->peer.data, NGX_PEER_FAILED); | |
1069 u->peer.sockaddr = NULL; | |
1070 } | |
1071 | |
1072 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
1073 | |
1074 timeout = pscf->next_upstream_timeout; | |
1075 | |
1076 if (u->peer.tries == 0 | |
1077 || !pscf->next_upstream | |
1078 || (timeout && ngx_current_msec - u->peer.start_time >= timeout)) | |
1079 { | |
1080 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
1081 return; | |
1082 } | |
1083 | |
1084 pc = u->peer.connection; | |
1085 | |
1086 if (pc) { | |
1087 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1088 "close proxy upstream connection: %d", pc->fd); | |
1089 | |
1090 #if (NGX_STREAM_SSL) | |
1091 if (pc->ssl) { | |
1092 pc->ssl->no_wait_shutdown = 1; | |
1093 pc->ssl->no_send_shutdown = 1; | |
1094 | |
1095 (void) ngx_ssl_shutdown(pc); | |
1096 } | |
1097 #endif | |
1098 | |
1099 ngx_close_connection(pc); | |
1100 u->peer.connection = NULL; | |
1101 } | |
1102 | |
1103 ngx_stream_proxy_connect(s); | |
1104 } | |
1105 | |
1106 | |
1107 static void | |
1108 ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc) | |
1109 { | |
1110 ngx_connection_t *pc; | |
1111 ngx_stream_upstream_t *u; | |
1112 | |
1113 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1114 "finalize stream proxy: %i", rc); | |
1115 | |
1116 u = s->upstream; | |
1117 | |
1118 if (u == NULL) { | |
1119 goto noupstream; | |
1120 } | |
1121 | |
1122 if (u->peer.free && u->peer.sockaddr) { | |
1123 u->peer.free(&u->peer, u->peer.data, 0); | |
1124 u->peer.sockaddr = NULL; | |
1125 } | |
1126 | |
1127 pc = u->peer.connection; | |
1128 | |
1129 if (pc) { | |
1130 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1131 "close stream proxy upstream connection: %d", pc->fd); | |
1132 | |
1133 #if (NGX_STREAM_SSL) | |
1134 if (pc->ssl) { | |
1135 pc->ssl->no_wait_shutdown = 1; | |
1136 (void) ngx_ssl_shutdown(pc); | |
1137 } | |
1138 #endif | |
1139 | |
1140 ngx_close_connection(pc); | |
1141 u->peer.connection = NULL; | |
1142 } | |
1143 | |
1144 noupstream: | |
1145 | |
1146 ngx_stream_close_connection(s->connection); | |
1147 } | |
1148 | |
1149 | |
1150 static u_char * | |
1151 ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, size_t len) | |
1152 { | |
1153 u_char *p; | |
1154 ngx_connection_t *pc; | |
1155 ngx_stream_session_t *s; | |
1156 ngx_stream_upstream_t *u; | |
1157 | |
1158 s = log->data; | |
1159 | |
1160 u = s->upstream; | |
1161 | |
1162 p = buf; | |
1163 | |
1164 if (u->peer.name) { | |
1165 p = ngx_snprintf(p, len, ", upstream: \"%V\"", u->peer.name); | |
1166 len -= p - buf; | |
1167 } | |
1168 | |
1169 pc = u->peer.connection; | |
1170 | |
1171 p = ngx_snprintf(p, len, | |
1172 ", bytes from/to client:%O/%O" | |
1173 ", bytes from/to upstream:%O/%O", | |
1174 s->received, s->connection->sent, | |
1175 u->received, pc ? pc->sent : 0); | |
1176 | |
1177 return p; | |
1178 } | |
1179 | |
1180 | |
1181 static void * | |
1182 ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf) | |
1183 { | |
1184 ngx_stream_proxy_srv_conf_t *conf; | |
1185 | |
1186 conf = ngx_pcalloc(cf->pool, sizeof(ngx_stream_proxy_srv_conf_t)); | |
1187 if (conf == NULL) { | |
1188 return NULL; | |
1189 } | |
1190 | |
1191 /* | |
1192 * set by ngx_pcalloc(): | |
1193 * | |
1194 * conf->ssl_protocols = 0; | |
1195 * conf->ssl_ciphers = { 0, NULL }; | |
1196 * conf->ssl_name = { 0, NULL }; | |
1197 * conf->ssl_trusted_certificate = { 0, NULL }; | |
1198 * conf->ssl_crl = { 0, NULL }; | |
1199 * conf->ssl_certificate = { 0, NULL }; | |
1200 * conf->ssl_certificate_key = { 0, NULL }; | |
1201 * | |
1202 * conf->ssl = NULL; | |
1203 * conf->upstream = NULL; | |
1204 */ | |
1205 | |
1206 conf->connect_timeout = NGX_CONF_UNSET_MSEC; | |
1207 conf->timeout = NGX_CONF_UNSET_MSEC; | |
1208 conf->next_upstream_timeout = NGX_CONF_UNSET_MSEC; | |
1209 conf->downstream_buf_size = NGX_CONF_UNSET_SIZE; | |
1210 conf->upstream_buf_size = NGX_CONF_UNSET_SIZE; | |
1211 conf->next_upstream_tries = NGX_CONF_UNSET_UINT; | |
1212 conf->next_upstream = NGX_CONF_UNSET; | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1213 conf->proxy_protocol = NGX_CONF_UNSET; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1214 conf->local = NGX_CONF_UNSET_PTR; |
6115 | 1215 |
1216 #if (NGX_STREAM_SSL) | |
1217 conf->ssl_enable = NGX_CONF_UNSET; | |
1218 conf->ssl_session_reuse = NGX_CONF_UNSET; | |
1219 conf->ssl_server_name = NGX_CONF_UNSET; | |
1220 conf->ssl_verify = NGX_CONF_UNSET; | |
1221 conf->ssl_verify_depth = NGX_CONF_UNSET_UINT; | |
1222 conf->ssl_passwords = NGX_CONF_UNSET_PTR; | |
1223 #endif | |
1224 | |
1225 return conf; | |
1226 } | |
1227 | |
1228 | |
1229 static char * | |
1230 ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, void *child) | |
1231 { | |
1232 ngx_stream_proxy_srv_conf_t *prev = parent; | |
1233 ngx_stream_proxy_srv_conf_t *conf = child; | |
1234 | |
1235 ngx_conf_merge_msec_value(conf->connect_timeout, | |
1236 prev->connect_timeout, 60000); | |
1237 | |
1238 ngx_conf_merge_msec_value(conf->timeout, | |
1239 prev->timeout, 10 * 60000); | |
1240 | |
1241 ngx_conf_merge_msec_value(conf->next_upstream_timeout, | |
1242 prev->next_upstream_timeout, 0); | |
1243 | |
1244 ngx_conf_merge_size_value(conf->downstream_buf_size, | |
1245 prev->downstream_buf_size, 16384); | |
1246 | |
1247 ngx_conf_merge_size_value(conf->upstream_buf_size, | |
1248 prev->upstream_buf_size, 16384); | |
1249 | |
1250 ngx_conf_merge_uint_value(conf->next_upstream_tries, | |
1251 prev->next_upstream_tries, 0); | |
1252 | |
1253 ngx_conf_merge_value(conf->next_upstream, prev->next_upstream, 1); | |
1254 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1255 ngx_conf_merge_value(conf->proxy_protocol, prev->proxy_protocol, 0); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1256 |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1257 ngx_conf_merge_ptr_value(conf->local, prev->local, NULL); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1258 |
6115 | 1259 #if (NGX_STREAM_SSL) |
1260 | |
1261 ngx_conf_merge_value(conf->ssl_enable, prev->ssl_enable, 0); | |
1262 | |
1263 ngx_conf_merge_value(conf->ssl_session_reuse, | |
1264 prev->ssl_session_reuse, 1); | |
1265 | |
1266 ngx_conf_merge_bitmask_value(conf->ssl_protocols, prev->ssl_protocols, | |
6157
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1267 (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1 |
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1268 |NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2)); |
6115 | 1269 |
1270 ngx_conf_merge_str_value(conf->ssl_ciphers, prev->ssl_ciphers, "DEFAULT"); | |
1271 | |
1272 ngx_conf_merge_str_value(conf->ssl_name, prev->ssl_name, ""); | |
1273 | |
1274 ngx_conf_merge_value(conf->ssl_server_name, prev->ssl_server_name, 0); | |
1275 | |
1276 ngx_conf_merge_value(conf->ssl_verify, prev->ssl_verify, 0); | |
1277 | |
1278 ngx_conf_merge_uint_value(conf->ssl_verify_depth, | |
1279 prev->ssl_verify_depth, 1); | |
1280 | |
1281 ngx_conf_merge_str_value(conf->ssl_trusted_certificate, | |
1282 prev->ssl_trusted_certificate, ""); | |
1283 | |
1284 ngx_conf_merge_str_value(conf->ssl_crl, prev->ssl_crl, ""); | |
1285 | |
1286 ngx_conf_merge_str_value(conf->ssl_certificate, | |
1287 prev->ssl_certificate, ""); | |
1288 | |
1289 ngx_conf_merge_str_value(conf->ssl_certificate_key, | |
1290 prev->ssl_certificate_key, ""); | |
1291 | |
1292 ngx_conf_merge_ptr_value(conf->ssl_passwords, prev->ssl_passwords, NULL); | |
1293 | |
1294 if (conf->ssl_enable && ngx_stream_proxy_set_ssl(cf, conf) != NGX_OK) { | |
1295 return NGX_CONF_ERROR; | |
1296 } | |
1297 | |
1298 #endif | |
1299 | |
1300 return NGX_CONF_OK; | |
1301 } | |
1302 | |
1303 | |
1304 #if (NGX_STREAM_SSL) | |
1305 | |
1306 static ngx_int_t | |
1307 ngx_stream_proxy_set_ssl(ngx_conf_t *cf, ngx_stream_proxy_srv_conf_t *pscf) | |
1308 { | |
1309 ngx_pool_cleanup_t *cln; | |
1310 | |
1311 pscf->ssl = ngx_pcalloc(cf->pool, sizeof(ngx_ssl_t)); | |
1312 if (pscf->ssl == NULL) { | |
1313 return NGX_ERROR; | |
1314 } | |
1315 | |
1316 pscf->ssl->log = cf->log; | |
1317 | |
1318 if (ngx_ssl_create(pscf->ssl, pscf->ssl_protocols, NULL) != NGX_OK) { | |
1319 return NGX_ERROR; | |
1320 } | |
1321 | |
1322 cln = ngx_pool_cleanup_add(cf->pool, 0); | |
1323 if (cln == NULL) { | |
1324 return NGX_ERROR; | |
1325 } | |
1326 | |
1327 cln->handler = ngx_ssl_cleanup_ctx; | |
1328 cln->data = pscf->ssl; | |
1329 | |
1330 if (pscf->ssl_certificate.len) { | |
1331 | |
1332 if (pscf->ssl_certificate_key.len == 0) { | |
1333 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1334 "no \"proxy_ssl_certificate_key\" is defined " | |
1335 "for certificate \"%V\"", &pscf->ssl_certificate); | |
1336 return NGX_ERROR; | |
1337 } | |
1338 | |
1339 if (ngx_ssl_certificate(cf, pscf->ssl, &pscf->ssl_certificate, | |
1340 &pscf->ssl_certificate_key, pscf->ssl_passwords) | |
1341 != NGX_OK) | |
1342 { | |
1343 return NGX_ERROR; | |
1344 } | |
1345 } | |
1346 | |
1347 if (SSL_CTX_set_cipher_list(pscf->ssl->ctx, | |
1348 (const char *) pscf->ssl_ciphers.data) | |
1349 == 0) | |
1350 { | |
1351 ngx_ssl_error(NGX_LOG_EMERG, cf->log, 0, | |
1352 "SSL_CTX_set_cipher_list(\"%V\") failed", | |
1353 &pscf->ssl_ciphers); | |
1354 return NGX_ERROR; | |
1355 } | |
1356 | |
1357 if (pscf->ssl_verify) { | |
1358 if (pscf->ssl_trusted_certificate.len == 0) { | |
1359 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1360 "no proxy_ssl_trusted_certificate for proxy_ssl_verify"); | |
1361 return NGX_ERROR; | |
1362 } | |
1363 | |
1364 if (ngx_ssl_trusted_certificate(cf, pscf->ssl, | |
1365 &pscf->ssl_trusted_certificate, | |
1366 pscf->ssl_verify_depth) | |
1367 != NGX_OK) | |
1368 { | |
1369 return NGX_ERROR; | |
1370 } | |
1371 | |
1372 if (ngx_ssl_crl(cf, pscf->ssl, &pscf->ssl_crl) != NGX_OK) { | |
1373 return NGX_ERROR; | |
1374 } | |
1375 } | |
1376 | |
1377 return NGX_OK; | |
1378 } | |
1379 | |
1380 #endif | |
1381 | |
1382 | |
1383 static char * | |
1384 ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) | |
1385 { | |
1386 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
1387 | |
1388 ngx_url_t u; | |
1389 ngx_str_t *value, *url; | |
1390 ngx_stream_core_srv_conf_t *cscf; | |
1391 | |
1392 if (pscf->upstream) { | |
1393 return "is duplicate"; | |
1394 } | |
1395 | |
1396 cscf = ngx_stream_conf_get_module_srv_conf(cf, ngx_stream_core_module); | |
1397 | |
1398 cscf->handler = ngx_stream_proxy_handler; | |
1399 | |
1400 value = cf->args->elts; | |
1401 | |
1402 url = &value[1]; | |
1403 | |
1404 ngx_memzero(&u, sizeof(ngx_url_t)); | |
1405 | |
1406 u.url = *url; | |
1407 u.no_resolve = 1; | |
1408 | |
1409 pscf->upstream = ngx_stream_upstream_add(cf, &u, 0); | |
1410 if (pscf->upstream == NULL) { | |
1411 return NGX_CONF_ERROR; | |
1412 } | |
1413 | |
1414 return NGX_CONF_OK; | |
1415 } | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1416 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1417 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1418 static char * |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1419 ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1420 { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1421 ngx_stream_proxy_srv_conf_t *pscf = conf; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1422 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1423 ngx_int_t rc; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1424 ngx_str_t *value; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1425 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1426 if (pscf->local != NGX_CONF_UNSET_PTR) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1427 return "is duplicate"; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1428 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1429 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1430 value = cf->args->elts; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1431 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1432 if (ngx_strcmp(value[1].data, "off") == 0) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1433 pscf->local = NULL; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1434 return NGX_CONF_OK; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1435 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1436 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1437 pscf->local = ngx_palloc(cf->pool, sizeof(ngx_addr_t)); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1438 if (pscf->local == NULL) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1439 return NGX_CONF_ERROR; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1440 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1441 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1442 rc = ngx_parse_addr(cf->pool, pscf->local, value[1].data, value[1].len); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1443 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1444 switch (rc) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1445 case NGX_OK: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1446 pscf->local->name = value[1]; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1447 return NGX_CONF_OK; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1448 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1449 case NGX_DECLINED: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1450 ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1451 "invalid address \"%V\"", &value[1]); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1452 /* fall through */ |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1453 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1454 default: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1455 return NGX_CONF_ERROR; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1456 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1457 } |