Mercurial > hg > nginx
annotate src/stream/ngx_stream_proxy_module.c @ 6217:b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
The directive proxy_buffer_size should be used instead.
author | Roman Arutyunyan <arut@nginx.com> |
---|---|
date | Thu, 30 Jul 2015 16:43:48 -0700 |
parents | 543f10fe34d2 |
children | 7565e056fad6 |
rev | line source |
---|---|
6115 | 1 |
2 /* | |
3 * Copyright (C) Roman Arutyunyan | |
4 * Copyright (C) Nginx, Inc. | |
5 */ | |
6 | |
7 | |
8 #include <ngx_config.h> | |
9 #include <ngx_core.h> | |
10 #include <ngx_stream.h> | |
11 | |
12 | |
13 typedef void (*ngx_stream_proxy_handler_pt)(ngx_stream_session_t *s); | |
14 | |
15 | |
16 typedef struct { | |
17 ngx_msec_t connect_timeout; | |
18 ngx_msec_t timeout; | |
19 ngx_msec_t next_upstream_timeout; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
20 size_t buffer_size; |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
21 size_t upload_rate; |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
22 size_t download_rate; |
6115 | 23 ngx_uint_t next_upstream_tries; |
24 ngx_flag_t next_upstream; | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
25 ngx_flag_t proxy_protocol; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
26 ngx_addr_t *local; |
6115 | 27 |
28 #if (NGX_STREAM_SSL) | |
29 ngx_flag_t ssl_enable; | |
30 ngx_flag_t ssl_session_reuse; | |
31 ngx_uint_t ssl_protocols; | |
32 ngx_str_t ssl_ciphers; | |
33 ngx_str_t ssl_name; | |
34 ngx_flag_t ssl_server_name; | |
35 | |
36 ngx_flag_t ssl_verify; | |
37 ngx_uint_t ssl_verify_depth; | |
38 ngx_str_t ssl_trusted_certificate; | |
39 ngx_str_t ssl_crl; | |
40 ngx_str_t ssl_certificate; | |
41 ngx_str_t ssl_certificate_key; | |
42 ngx_array_t *ssl_passwords; | |
43 | |
44 ngx_ssl_t *ssl; | |
45 #endif | |
46 | |
47 ngx_stream_upstream_srv_conf_t *upstream; | |
48 } ngx_stream_proxy_srv_conf_t; | |
49 | |
50 | |
51 static void ngx_stream_proxy_handler(ngx_stream_session_t *s); | |
52 static void ngx_stream_proxy_connect(ngx_stream_session_t *s); | |
53 static void ngx_stream_proxy_init_upstream(ngx_stream_session_t *s); | |
54 static void ngx_stream_proxy_upstream_handler(ngx_event_t *ev); | |
55 static void ngx_stream_proxy_downstream_handler(ngx_event_t *ev); | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
56 static void ngx_stream_proxy_process_connection(ngx_event_t *ev, |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
57 ngx_uint_t from_upstream); |
6115 | 58 static void ngx_stream_proxy_connect_handler(ngx_event_t *ev); |
59 static ngx_int_t ngx_stream_proxy_test_connect(ngx_connection_t *c); | |
60 static ngx_int_t ngx_stream_proxy_process(ngx_stream_session_t *s, | |
61 ngx_uint_t from_upstream, ngx_uint_t do_write); | |
62 static void ngx_stream_proxy_next_upstream(ngx_stream_session_t *s); | |
63 static void ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc); | |
64 static u_char *ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, | |
65 size_t len); | |
66 | |
67 static void *ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf); | |
68 static char *ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, | |
69 void *child); | |
70 static char *ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, | |
71 void *conf); | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
72 static char *ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
73 void *conf); |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
74 static ngx_int_t ngx_stream_proxy_send_proxy_protocol(ngx_stream_session_t *s); |
6115 | 75 |
76 #if (NGX_STREAM_SSL) | |
77 | |
78 static char *ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, | |
79 ngx_command_t *cmd, void *conf); | |
80 static void ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s); | |
81 static void ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc); | |
82 static ngx_int_t ngx_stream_proxy_ssl_name(ngx_stream_session_t *s); | |
83 static ngx_int_t ngx_stream_proxy_set_ssl(ngx_conf_t *cf, | |
84 ngx_stream_proxy_srv_conf_t *pscf); | |
85 | |
86 | |
87 static ngx_conf_bitmask_t ngx_stream_proxy_ssl_protocols[] = { | |
88 { ngx_string("SSLv2"), NGX_SSL_SSLv2 }, | |
89 { ngx_string("SSLv3"), NGX_SSL_SSLv3 }, | |
90 { ngx_string("TLSv1"), NGX_SSL_TLSv1 }, | |
91 { ngx_string("TLSv1.1"), NGX_SSL_TLSv1_1 }, | |
92 { ngx_string("TLSv1.2"), NGX_SSL_TLSv1_2 }, | |
93 { ngx_null_string, 0 } | |
94 }; | |
95 | |
96 #endif | |
97 | |
98 | |
6217
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
99 static ngx_conf_deprecated_t ngx_conf_deprecated_proxy_downstream_buffer = { |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
100 ngx_conf_deprecated, "proxy_downstream_buffer", "proxy_buffer_size" |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
101 }; |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
102 |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
103 static ngx_conf_deprecated_t ngx_conf_deprecated_proxy_upstream_buffer = { |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
104 ngx_conf_deprecated, "proxy_upstream_buffer", "proxy_buffer_size" |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
105 }; |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
106 |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
107 |
6115 | 108 static ngx_command_t ngx_stream_proxy_commands[] = { |
109 | |
110 { ngx_string("proxy_pass"), | |
111 NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
112 ngx_stream_proxy_pass, | |
113 NGX_STREAM_SRV_CONF_OFFSET, | |
114 0, | |
115 NULL }, | |
116 | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
117 { ngx_string("proxy_bind"), |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
118 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
119 ngx_stream_proxy_bind, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
120 NGX_STREAM_SRV_CONF_OFFSET, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
121 0, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
122 NULL }, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
123 |
6115 | 124 { ngx_string("proxy_connect_timeout"), |
125 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
126 ngx_conf_set_msec_slot, | |
127 NGX_STREAM_SRV_CONF_OFFSET, | |
128 offsetof(ngx_stream_proxy_srv_conf_t, connect_timeout), | |
129 NULL }, | |
130 | |
131 { ngx_string("proxy_timeout"), | |
132 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
133 ngx_conf_set_msec_slot, | |
134 NGX_STREAM_SRV_CONF_OFFSET, | |
135 offsetof(ngx_stream_proxy_srv_conf_t, timeout), | |
136 NULL }, | |
137 | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
138 { ngx_string("proxy_buffer_size"), |
6115 | 139 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
140 ngx_conf_set_size_slot, | |
141 NGX_STREAM_SRV_CONF_OFFSET, | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
142 offsetof(ngx_stream_proxy_srv_conf_t, buffer_size), |
6115 | 143 NULL }, |
144 | |
6217
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
145 { ngx_string("proxy_downstream_buffer"), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
146 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
147 ngx_conf_set_size_slot, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
148 NGX_STREAM_SRV_CONF_OFFSET, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
149 offsetof(ngx_stream_proxy_srv_conf_t, buffer_size), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
150 &ngx_conf_deprecated_proxy_downstream_buffer }, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
151 |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
152 { ngx_string("proxy_upstream_buffer"), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
153 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
154 ngx_conf_set_size_slot, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
155 NGX_STREAM_SRV_CONF_OFFSET, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
156 offsetof(ngx_stream_proxy_srv_conf_t, buffer_size), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
157 &ngx_conf_deprecated_proxy_upstream_buffer }, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
158 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
159 { ngx_string("proxy_upload_rate"), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
160 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
161 ngx_conf_set_size_slot, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
162 NGX_STREAM_SRV_CONF_OFFSET, |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
163 offsetof(ngx_stream_proxy_srv_conf_t, upload_rate), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
164 NULL }, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
165 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
166 { ngx_string("proxy_download_rate"), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
167 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
168 ngx_conf_set_size_slot, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
169 NGX_STREAM_SRV_CONF_OFFSET, |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
170 offsetof(ngx_stream_proxy_srv_conf_t, download_rate), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
171 NULL }, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
172 |
6115 | 173 { ngx_string("proxy_next_upstream"), |
174 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
175 ngx_conf_set_flag_slot, | |
176 NGX_STREAM_SRV_CONF_OFFSET, | |
177 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream), | |
178 NULL }, | |
179 | |
180 { ngx_string("proxy_next_upstream_tries"), | |
181 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
182 ngx_conf_set_num_slot, | |
183 NGX_STREAM_SRV_CONF_OFFSET, | |
184 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_tries), | |
185 NULL }, | |
186 | |
187 { ngx_string("proxy_next_upstream_timeout"), | |
188 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
189 ngx_conf_set_msec_slot, | |
190 NGX_STREAM_SRV_CONF_OFFSET, | |
191 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_timeout), | |
192 NULL }, | |
193 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
194 { ngx_string("proxy_protocol"), |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
195 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
196 ngx_conf_set_flag_slot, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
197 NGX_STREAM_SRV_CONF_OFFSET, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
198 offsetof(ngx_stream_proxy_srv_conf_t, proxy_protocol), |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
199 NULL }, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
200 |
6115 | 201 #if (NGX_STREAM_SSL) |
202 | |
203 { ngx_string("proxy_ssl"), | |
204 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
205 ngx_conf_set_flag_slot, | |
206 NGX_STREAM_SRV_CONF_OFFSET, | |
207 offsetof(ngx_stream_proxy_srv_conf_t, ssl_enable), | |
208 NULL }, | |
209 | |
210 { ngx_string("proxy_ssl_session_reuse"), | |
211 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
212 ngx_conf_set_flag_slot, | |
213 NGX_STREAM_SRV_CONF_OFFSET, | |
214 offsetof(ngx_stream_proxy_srv_conf_t, ssl_session_reuse), | |
215 NULL }, | |
216 | |
217 { ngx_string("proxy_ssl_protocols"), | |
218 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_1MORE, | |
219 ngx_conf_set_bitmask_slot, | |
220 NGX_STREAM_SRV_CONF_OFFSET, | |
221 offsetof(ngx_stream_proxy_srv_conf_t, ssl_protocols), | |
222 &ngx_stream_proxy_ssl_protocols }, | |
223 | |
224 { ngx_string("proxy_ssl_ciphers"), | |
225 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
226 ngx_conf_set_str_slot, | |
227 NGX_STREAM_SRV_CONF_OFFSET, | |
228 offsetof(ngx_stream_proxy_srv_conf_t, ssl_ciphers), | |
229 NULL }, | |
230 | |
231 { ngx_string("proxy_ssl_name"), | |
232 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
233 ngx_conf_set_str_slot, | |
234 NGX_STREAM_SRV_CONF_OFFSET, | |
235 offsetof(ngx_stream_proxy_srv_conf_t, ssl_name), | |
236 NULL }, | |
237 | |
238 { ngx_string("proxy_ssl_server_name"), | |
239 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
240 ngx_conf_set_flag_slot, | |
241 NGX_STREAM_SRV_CONF_OFFSET, | |
242 offsetof(ngx_stream_proxy_srv_conf_t, ssl_server_name), | |
243 NULL }, | |
244 | |
245 { ngx_string("proxy_ssl_verify"), | |
246 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
247 ngx_conf_set_flag_slot, | |
248 NGX_STREAM_SRV_CONF_OFFSET, | |
249 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify), | |
250 NULL }, | |
251 | |
252 { ngx_string("proxy_ssl_verify_depth"), | |
253 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
254 ngx_conf_set_num_slot, | |
255 NGX_STREAM_SRV_CONF_OFFSET, | |
256 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify_depth), | |
257 NULL }, | |
258 | |
259 { ngx_string("proxy_ssl_trusted_certificate"), | |
260 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
261 ngx_conf_set_str_slot, | |
262 NGX_STREAM_SRV_CONF_OFFSET, | |
263 offsetof(ngx_stream_proxy_srv_conf_t, ssl_trusted_certificate), | |
264 NULL }, | |
265 | |
266 { ngx_string("proxy_ssl_crl"), | |
267 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
268 ngx_conf_set_str_slot, | |
269 NGX_STREAM_SRV_CONF_OFFSET, | |
270 offsetof(ngx_stream_proxy_srv_conf_t, ssl_crl), | |
271 NULL }, | |
272 | |
273 { ngx_string("proxy_ssl_certificate"), | |
274 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
275 ngx_conf_set_str_slot, | |
276 NGX_STREAM_SRV_CONF_OFFSET, | |
277 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate), | |
278 NULL }, | |
279 | |
280 { ngx_string("proxy_ssl_certificate_key"), | |
281 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
282 ngx_conf_set_str_slot, | |
283 NGX_STREAM_SRV_CONF_OFFSET, | |
284 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate_key), | |
285 NULL }, | |
286 | |
287 { ngx_string("proxy_ssl_password_file"), | |
288 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
289 ngx_stream_proxy_ssl_password_file, | |
290 NGX_STREAM_SRV_CONF_OFFSET, | |
291 0, | |
292 NULL }, | |
293 | |
294 #endif | |
295 | |
296 ngx_null_command | |
297 }; | |
298 | |
299 | |
300 static ngx_stream_module_t ngx_stream_proxy_module_ctx = { | |
6174
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
301 NULL, /* postconfiguration */ |
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
302 |
6115 | 303 NULL, /* create main configuration */ |
304 NULL, /* init main configuration */ | |
305 | |
306 ngx_stream_proxy_create_srv_conf, /* create server configuration */ | |
307 ngx_stream_proxy_merge_srv_conf /* merge server configuration */ | |
308 }; | |
309 | |
310 | |
311 ngx_module_t ngx_stream_proxy_module = { | |
312 NGX_MODULE_V1, | |
313 &ngx_stream_proxy_module_ctx, /* module context */ | |
314 ngx_stream_proxy_commands, /* module directives */ | |
315 NGX_STREAM_MODULE, /* module type */ | |
316 NULL, /* init master */ | |
317 NULL, /* init module */ | |
318 NULL, /* init process */ | |
319 NULL, /* init thread */ | |
320 NULL, /* exit thread */ | |
321 NULL, /* exit process */ | |
322 NULL, /* exit master */ | |
323 NGX_MODULE_V1_PADDING | |
324 }; | |
325 | |
326 | |
327 static void | |
328 ngx_stream_proxy_handler(ngx_stream_session_t *s) | |
329 { | |
330 u_char *p; | |
331 ngx_connection_t *c; | |
332 ngx_stream_upstream_t *u; | |
333 ngx_stream_proxy_srv_conf_t *pscf; | |
334 ngx_stream_upstream_srv_conf_t *uscf; | |
335 | |
336 c = s->connection; | |
337 | |
338 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
339 | |
340 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
341 "proxy connection handler"); | |
342 | |
343 u = ngx_pcalloc(c->pool, sizeof(ngx_stream_upstream_t)); | |
344 if (u == NULL) { | |
345 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
346 return; | |
347 } | |
348 | |
349 s->upstream = u; | |
350 | |
351 s->log_handler = ngx_stream_proxy_log_error; | |
352 | |
353 u->peer.log = c->log; | |
354 u->peer.log_error = NGX_ERROR_ERR; | |
355 | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
356 u->peer.local = pscf->local; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
357 |
6115 | 358 uscf = pscf->upstream; |
359 | |
360 if (uscf->peer.init(s, uscf) != NGX_OK) { | |
361 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
362 return; | |
363 } | |
364 | |
365 u->peer.start_time = ngx_current_msec; | |
366 | |
367 if (pscf->next_upstream_tries | |
368 && u->peer.tries > pscf->next_upstream_tries) | |
369 { | |
370 u->peer.tries = pscf->next_upstream_tries; | |
371 } | |
372 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
373 u->proxy_protocol = pscf->proxy_protocol; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
374 u->start_sec = ngx_time(); |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
375 |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
376 p = ngx_pnalloc(c->pool, pscf->buffer_size); |
6115 | 377 if (p == NULL) { |
378 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
379 return; | |
380 } | |
381 | |
382 u->downstream_buf.start = p; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
383 u->downstream_buf.end = p + pscf->buffer_size; |
6115 | 384 u->downstream_buf.pos = p; |
385 u->downstream_buf.last = p; | |
386 | |
387 c->write->handler = ngx_stream_proxy_downstream_handler; | |
388 c->read->handler = ngx_stream_proxy_downstream_handler; | |
389 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
390 if (u->proxy_protocol |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
391 #if (NGX_STREAM_SSL) |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
392 && pscf->ssl == NULL |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
393 #endif |
6216 | 394 && pscf->buffer_size >= NGX_PROXY_PROTOCOL_MAX_HEADER) |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
395 { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
396 /* optimization for a typical case */ |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
397 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
398 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
399 "stream proxy send PROXY protocol header"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
400 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
401 p = ngx_proxy_protocol_write(c, u->downstream_buf.last, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
402 u->downstream_buf.end); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
403 if (p == NULL) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
404 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
405 return; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
406 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
407 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
408 u->downstream_buf.last = p; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
409 u->proxy_protocol = 0; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
410 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
411 |
6115 | 412 if (ngx_stream_proxy_process(s, 0, 0) != NGX_OK) { |
413 return; | |
414 } | |
415 | |
416 ngx_stream_proxy_connect(s); | |
417 } | |
418 | |
419 | |
420 static void | |
421 ngx_stream_proxy_connect(ngx_stream_session_t *s) | |
422 { | |
423 ngx_int_t rc; | |
424 ngx_connection_t *c, *pc; | |
425 ngx_stream_upstream_t *u; | |
426 ngx_stream_proxy_srv_conf_t *pscf; | |
427 | |
428 c = s->connection; | |
429 | |
430 c->log->action = "connecting to upstream"; | |
431 | |
432 u = s->upstream; | |
433 | |
434 rc = ngx_event_connect_peer(&u->peer); | |
435 | |
436 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, c->log, 0, "proxy connect: %i", rc); | |
437 | |
438 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
439 | |
440 if (rc == NGX_ERROR) { | |
441 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
442 return; | |
443 } | |
444 | |
445 if (rc == NGX_BUSY) { | |
446 ngx_log_error(NGX_LOG_ERR, c->log, 0, "no live upstreams"); | |
447 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
448 return; | |
449 } | |
450 | |
451 if (rc == NGX_DECLINED) { | |
452 ngx_stream_proxy_next_upstream(s); | |
453 return; | |
454 } | |
455 | |
456 /* rc == NGX_OK || rc == NGX_AGAIN || rc == NGX_DONE */ | |
457 | |
458 pc = u->peer.connection; | |
459 | |
460 pc->data = s; | |
461 pc->log = c->log; | |
462 pc->pool = c->pool; | |
463 pc->read->log = c->log; | |
464 pc->write->log = c->log; | |
465 | |
466 if (rc != NGX_AGAIN) { | |
467 ngx_stream_proxy_init_upstream(s); | |
468 return; | |
469 } | |
470 | |
471 pc->read->handler = ngx_stream_proxy_connect_handler; | |
472 pc->write->handler = ngx_stream_proxy_connect_handler; | |
473 | |
474 ngx_add_timer(pc->write, pscf->connect_timeout); | |
475 } | |
476 | |
477 | |
478 static void | |
479 ngx_stream_proxy_init_upstream(ngx_stream_session_t *s) | |
480 { | |
481 u_char *p; | |
482 ngx_connection_t *c, *pc; | |
483 ngx_log_handler_pt handler; | |
484 ngx_stream_upstream_t *u; | |
485 ngx_stream_proxy_srv_conf_t *pscf; | |
486 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
487 u = s->upstream; |
6115 | 488 |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
489 if (u->proxy_protocol) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
490 if (ngx_stream_proxy_send_proxy_protocol(s) != NGX_OK) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
491 return; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
492 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
493 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
494 u->proxy_protocol = 0; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
495 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
496 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
497 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
6115 | 498 |
499 pc = u->peer.connection; | |
500 | |
501 #if (NGX_STREAM_SSL) | |
502 if (pscf->ssl && pc->ssl == NULL) { | |
503 ngx_stream_proxy_ssl_init_connection(s); | |
504 return; | |
505 } | |
506 #endif | |
507 | |
508 c = s->connection; | |
509 | |
510 if (c->log->log_level >= NGX_LOG_INFO) { | |
511 ngx_str_t s; | |
512 u_char addr[NGX_SOCKADDR_STRLEN]; | |
513 | |
514 s.len = NGX_SOCKADDR_STRLEN; | |
515 s.data = addr; | |
516 | |
517 if (ngx_connection_local_sockaddr(pc, &s, 1) == NGX_OK) { | |
518 handler = c->log->handler; | |
519 c->log->handler = NULL; | |
520 | |
521 ngx_log_error(NGX_LOG_INFO, c->log, 0, "proxy %V connected to %V", | |
522 &s, u->peer.name); | |
523 | |
524 c->log->handler = handler; | |
525 } | |
526 } | |
527 | |
528 c->log->action = "proxying connection"; | |
529 | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
530 p = ngx_pnalloc(c->pool, pscf->buffer_size); |
6115 | 531 if (p == NULL) { |
532 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
533 return; | |
534 } | |
535 | |
536 u->upstream_buf.start = p; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
537 u->upstream_buf.end = p + pscf->buffer_size; |
6115 | 538 u->upstream_buf.pos = p; |
539 u->upstream_buf.last = p; | |
540 | |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
541 u->connected = 1; |
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
542 |
6115 | 543 pc->read->handler = ngx_stream_proxy_upstream_handler; |
544 pc->write->handler = ngx_stream_proxy_upstream_handler; | |
545 | |
546 if (ngx_stream_proxy_process(s, 1, 0) != NGX_OK) { | |
547 return; | |
548 } | |
549 | |
550 ngx_stream_proxy_process(s, 0, 1); | |
551 } | |
552 | |
553 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
554 static ngx_int_t |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
555 ngx_stream_proxy_send_proxy_protocol(ngx_stream_session_t *s) |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
556 { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
557 u_char *p; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
558 ssize_t n, size; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
559 ngx_connection_t *c, *pc; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
560 ngx_stream_upstream_t *u; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
561 ngx_stream_proxy_srv_conf_t *pscf; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
562 u_char buf[NGX_PROXY_PROTOCOL_MAX_HEADER]; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
563 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
564 c = s->connection; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
565 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
566 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
567 "stream proxy send PROXY protocol header"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
568 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
569 p = ngx_proxy_protocol_write(c, buf, buf + NGX_PROXY_PROTOCOL_MAX_HEADER); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
570 if (p == NULL) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
571 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
572 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
573 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
574 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
575 u = s->upstream; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
576 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
577 pc = u->peer.connection; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
578 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
579 size = p - buf; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
580 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
581 n = pc->send(pc, buf, size); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
582 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
583 if (n == NGX_AGAIN) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
584 if (ngx_handle_write_event(pc->write, 0) != NGX_OK) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
585 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
586 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
587 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
588 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
589 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
590 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
591 ngx_add_timer(pc->write, pscf->timeout); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
592 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
593 pc->write->handler = ngx_stream_proxy_connect_handler; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
594 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
595 return NGX_AGAIN; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
596 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
597 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
598 if (n == NGX_ERROR) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
599 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
600 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
601 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
602 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
603 if (n != size) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
604 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
605 /* |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
606 * PROXY protocol specification: |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
607 * The sender must always ensure that the header |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
608 * is sent at once, so that the transport layer |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
609 * maintains atomicity along the path to the receiver. |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
610 */ |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
611 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
612 ngx_log_error(NGX_LOG_ERR, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
613 "could not send PROXY protocol header at once"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
614 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
615 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
616 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
617 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
618 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
619 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
620 return NGX_OK; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
621 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
622 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
623 |
6115 | 624 #if (NGX_STREAM_SSL) |
625 | |
626 static char * | |
627 ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, ngx_command_t *cmd, | |
628 void *conf) | |
629 { | |
630 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
631 | |
632 ngx_str_t *value; | |
633 | |
634 if (pscf->ssl_passwords != NGX_CONF_UNSET_PTR) { | |
635 return "is duplicate"; | |
636 } | |
637 | |
638 value = cf->args->elts; | |
639 | |
640 pscf->ssl_passwords = ngx_ssl_read_password_file(cf, &value[1]); | |
641 | |
642 if (pscf->ssl_passwords == NULL) { | |
643 return NGX_CONF_ERROR; | |
644 } | |
645 | |
646 return NGX_CONF_OK; | |
647 } | |
648 | |
649 | |
650 static void | |
651 ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s) | |
652 { | |
653 ngx_int_t rc; | |
654 ngx_connection_t *pc; | |
655 ngx_stream_upstream_t *u; | |
656 ngx_stream_proxy_srv_conf_t *pscf; | |
657 | |
658 u = s->upstream; | |
659 | |
660 pc = u->peer.connection; | |
661 | |
662 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
663 | |
664 if (ngx_ssl_create_connection(pscf->ssl, pc, NGX_SSL_BUFFER|NGX_SSL_CLIENT) | |
665 != NGX_OK) | |
666 { | |
667 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
668 return; | |
669 } | |
670 | |
671 if (pscf->ssl_server_name || pscf->ssl_verify) { | |
672 if (ngx_stream_proxy_ssl_name(s) != NGX_OK) { | |
673 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
674 return; | |
675 } | |
676 } | |
677 | |
678 if (pscf->ssl_session_reuse) { | |
679 if (u->peer.set_session(&u->peer, u->peer.data) != NGX_OK) { | |
680 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
681 return; | |
682 } | |
683 } | |
684 | |
685 s->connection->log->action = "SSL handshaking to upstream"; | |
686 | |
687 rc = ngx_ssl_handshake(pc); | |
688 | |
689 if (rc == NGX_AGAIN) { | |
690 | |
691 if (!pc->write->timer_set) { | |
692 ngx_add_timer(pc->write, pscf->connect_timeout); | |
693 } | |
694 | |
695 pc->ssl->handler = ngx_stream_proxy_ssl_handshake; | |
696 return; | |
697 } | |
698 | |
699 ngx_stream_proxy_ssl_handshake(pc); | |
700 } | |
701 | |
702 | |
703 static void | |
704 ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc) | |
705 { | |
706 long rc; | |
707 ngx_stream_session_t *s; | |
708 ngx_stream_upstream_t *u; | |
709 ngx_stream_proxy_srv_conf_t *pscf; | |
710 | |
711 s = pc->data; | |
712 | |
713 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
714 | |
715 if (pc->ssl->handshaked) { | |
716 | |
717 if (pscf->ssl_verify) { | |
718 rc = SSL_get_verify_result(pc->ssl->connection); | |
719 | |
720 if (rc != X509_V_OK) { | |
721 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
722 "upstream SSL certificate verify error: (%l:%s)", | |
723 rc, X509_verify_cert_error_string(rc)); | |
724 goto failed; | |
725 } | |
726 | |
727 u = s->upstream; | |
728 | |
729 if (ngx_ssl_check_host(pc, &u->ssl_name) != NGX_OK) { | |
730 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
731 "upstream SSL certificate does not match \"%V\"", | |
732 &u->ssl_name); | |
733 goto failed; | |
734 } | |
735 } | |
736 | |
737 if (pscf->ssl_session_reuse) { | |
738 u = s->upstream; | |
739 u->peer.save_session(&u->peer, u->peer.data); | |
740 } | |
741 | |
742 ngx_stream_proxy_init_upstream(s); | |
743 | |
744 return; | |
745 } | |
746 | |
747 failed: | |
748 | |
749 ngx_stream_proxy_next_upstream(s); | |
750 } | |
751 | |
752 | |
753 static ngx_int_t | |
754 ngx_stream_proxy_ssl_name(ngx_stream_session_t *s) | |
755 { | |
756 u_char *p, *last; | |
757 ngx_str_t name; | |
758 ngx_stream_upstream_t *u; | |
759 ngx_stream_proxy_srv_conf_t *pscf; | |
760 | |
761 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
762 | |
763 u = s->upstream; | |
764 | |
765 name = pscf->ssl_name; | |
766 | |
767 if (name.len == 0) { | |
768 name = pscf->upstream->host; | |
769 } | |
770 | |
771 if (name.len == 0) { | |
772 goto done; | |
773 } | |
774 | |
775 /* | |
776 * ssl name here may contain port, strip it for compatibility | |
777 * with the http module | |
778 */ | |
779 | |
780 p = name.data; | |
781 last = name.data + name.len; | |
782 | |
783 if (*p == '[') { | |
784 p = ngx_strlchr(p, last, ']'); | |
785 | |
786 if (p == NULL) { | |
787 p = name.data; | |
788 } | |
789 } | |
790 | |
791 p = ngx_strlchr(p, last, ':'); | |
792 | |
793 if (p != NULL) { | |
794 name.len = p - name.data; | |
795 } | |
796 | |
797 if (!pscf->ssl_server_name) { | |
798 goto done; | |
799 } | |
800 | |
801 #ifdef SSL_CTRL_SET_TLSEXT_HOSTNAME | |
802 | |
803 /* as per RFC 6066, literal IPv4 and IPv6 addresses are not permitted */ | |
804 | |
805 if (name.len == 0 || *name.data == '[') { | |
806 goto done; | |
807 } | |
808 | |
809 if (ngx_inet_addr(name.data, name.len) != INADDR_NONE) { | |
810 goto done; | |
811 } | |
812 | |
813 /* | |
814 * SSL_set_tlsext_host_name() needs a null-terminated string, | |
815 * hence we explicitly null-terminate name here | |
816 */ | |
817 | |
818 p = ngx_pnalloc(s->connection->pool, name.len + 1); | |
819 if (p == NULL) { | |
820 return NGX_ERROR; | |
821 } | |
822 | |
823 (void) ngx_cpystrn(p, name.data, name.len + 1); | |
824 | |
825 name.data = p; | |
826 | |
827 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
828 "upstream SSL server name: \"%s\"", name.data); | |
829 | |
830 if (SSL_set_tlsext_host_name(u->peer.connection->ssl->connection, name.data) | |
831 == 0) | |
832 { | |
833 ngx_ssl_error(NGX_LOG_ERR, s->connection->log, 0, | |
834 "SSL_set_tlsext_host_name(\"%s\") failed", name.data); | |
835 return NGX_ERROR; | |
836 } | |
837 | |
838 #endif | |
839 | |
840 done: | |
841 | |
842 u->ssl_name = name; | |
843 | |
844 return NGX_OK; | |
845 } | |
846 | |
847 #endif | |
848 | |
849 | |
850 static void | |
851 ngx_stream_proxy_downstream_handler(ngx_event_t *ev) | |
852 { | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
853 ngx_stream_proxy_process_connection(ev, ev->write); |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
854 } |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
855 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
856 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
857 static void |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
858 ngx_stream_proxy_upstream_handler(ngx_event_t *ev) |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
859 { |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
860 ngx_stream_proxy_process_connection(ev, !ev->write); |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
861 } |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
862 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
863 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
864 static void |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
865 ngx_stream_proxy_process_connection(ngx_event_t *ev, ngx_uint_t from_upstream) |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
866 { |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
867 ngx_connection_t *c, *pc; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
868 ngx_stream_session_t *s; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
869 ngx_stream_upstream_t *u; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
870 ngx_stream_proxy_srv_conf_t *pscf; |
6115 | 871 |
872 c = ev->data; | |
873 s = c->data; | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
874 u = s->upstream; |
6115 | 875 |
876 if (ev->timedout) { | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
877 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
878 if (ev->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
879 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
880 ev->timedout = 0; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
881 ev->delayed = 0; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
882 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
883 if (!ev->ready) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
884 if (ngx_handle_read_event(ev, 0) != NGX_OK) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
885 ngx_stream_proxy_finalize(s, NGX_ERROR); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
886 return; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
887 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
888 |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
889 if (u->connected) { |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
890 pc = u->peer.connection; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
891 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
892 if (!c->read->delayed && !pc->read->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
893 pscf = ngx_stream_get_module_srv_conf(s, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
894 ngx_stream_proxy_module); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
895 ngx_add_timer(c->write, pscf->timeout); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
896 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
897 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
898 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
899 return; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
900 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
901 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
902 } else { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
903 ngx_connection_error(c, NGX_ETIMEDOUT, "connection timed out"); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
904 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
905 return; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
906 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
907 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
908 } else if (ev->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
909 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
910 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
911 "stream connection delayed"); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
912 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
913 if (ngx_handle_read_event(ev, 0) != NGX_OK) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
914 ngx_stream_proxy_finalize(s, NGX_ERROR); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
915 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
916 |
6115 | 917 return; |
918 } | |
919 | |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
920 if (from_upstream && !u->connected) { |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
921 return; |
6115 | 922 } |
923 | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
924 ngx_stream_proxy_process(s, from_upstream, ev->write); |
6115 | 925 } |
926 | |
927 | |
928 static void | |
929 ngx_stream_proxy_connect_handler(ngx_event_t *ev) | |
930 { | |
931 ngx_connection_t *c; | |
932 ngx_stream_session_t *s; | |
933 | |
934 c = ev->data; | |
935 s = c->data; | |
936 | |
937 if (ev->timedout) { | |
938 ngx_log_error(NGX_LOG_ERR, c->log, NGX_ETIMEDOUT, "upstream timed out"); | |
939 ngx_stream_proxy_next_upstream(s); | |
940 return; | |
941 } | |
942 | |
943 ngx_del_timer(c->write); | |
944 | |
945 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
946 "stream proxy connect upstream"); | |
947 | |
948 if (ngx_stream_proxy_test_connect(c) != NGX_OK) { | |
949 ngx_stream_proxy_next_upstream(s); | |
950 return; | |
951 } | |
952 | |
953 ngx_stream_proxy_init_upstream(s); | |
954 } | |
955 | |
956 | |
957 static ngx_int_t | |
958 ngx_stream_proxy_test_connect(ngx_connection_t *c) | |
959 { | |
960 int err; | |
961 socklen_t len; | |
962 | |
963 #if (NGX_HAVE_KQUEUE) | |
964 | |
965 if (ngx_event_flags & NGX_USE_KQUEUE_EVENT) { | |
966 err = c->write->kq_errno ? c->write->kq_errno : c->read->kq_errno; | |
967 | |
968 if (err) { | |
969 (void) ngx_connection_error(c, err, | |
970 "kevent() reported that connect() failed"); | |
971 return NGX_ERROR; | |
972 } | |
973 | |
974 } else | |
975 #endif | |
976 { | |
977 err = 0; | |
978 len = sizeof(int); | |
979 | |
980 /* | |
981 * BSDs and Linux return 0 and set a pending error in err | |
982 * Solaris returns -1 and sets errno | |
983 */ | |
984 | |
985 if (getsockopt(c->fd, SOL_SOCKET, SO_ERROR, (void *) &err, &len) | |
986 == -1) | |
987 { | |
988 err = ngx_socket_errno; | |
989 } | |
990 | |
991 if (err) { | |
992 (void) ngx_connection_error(c, err, "connect() failed"); | |
993 return NGX_ERROR; | |
994 } | |
995 } | |
996 | |
997 return NGX_OK; | |
998 } | |
999 | |
1000 | |
1001 static ngx_int_t | |
1002 ngx_stream_proxy_process(ngx_stream_session_t *s, ngx_uint_t from_upstream, | |
1003 ngx_uint_t do_write) | |
1004 { | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1005 off_t *received, limit; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1006 size_t size, limit_rate; |
6115 | 1007 ssize_t n; |
1008 ngx_buf_t *b; | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1009 ngx_uint_t flags; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1010 ngx_msec_t delay; |
6115 | 1011 ngx_connection_t *c, *pc, *src, *dst; |
1012 ngx_log_handler_pt handler; | |
1013 ngx_stream_upstream_t *u; | |
1014 ngx_stream_proxy_srv_conf_t *pscf; | |
1015 | |
1016 u = s->upstream; | |
1017 | |
1018 c = s->connection; | |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
1019 pc = u->connected ? u->peer.connection : NULL; |
6115 | 1020 |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1021 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1022 |
6115 | 1023 if (from_upstream) { |
1024 src = pc; | |
1025 dst = c; | |
1026 b = &u->upstream_buf; | |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1027 limit_rate = pscf->download_rate; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1028 received = &u->received; |
6115 | 1029 |
1030 } else { | |
1031 src = c; | |
1032 dst = pc; | |
1033 b = &u->downstream_buf; | |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1034 limit_rate = pscf->upload_rate; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1035 received = &s->received; |
6115 | 1036 } |
1037 | |
1038 for ( ;; ) { | |
1039 | |
1040 if (do_write) { | |
1041 | |
1042 size = b->last - b->pos; | |
1043 | |
1044 if (size && dst && dst->write->ready) { | |
1045 | |
1046 n = dst->send(dst, b->pos, size); | |
1047 | |
1048 if (n == NGX_ERROR) { | |
1049 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
1050 return NGX_ERROR; | |
1051 } | |
1052 | |
1053 if (n > 0) { | |
1054 b->pos += n; | |
1055 | |
1056 if (b->pos == b->last) { | |
1057 b->pos = b->start; | |
1058 b->last = b->start; | |
1059 } | |
1060 } | |
1061 } | |
1062 } | |
1063 | |
1064 size = b->end - b->last; | |
1065 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1066 if (size && src->read->ready && !src->read->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1067 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1068 if (limit_rate) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1069 limit = (off_t) limit_rate * (ngx_time() - u->start_sec + 1) |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1070 - *received; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1071 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1072 if (limit <= 0) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1073 src->read->delayed = 1; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1074 delay = (ngx_msec_t) (- limit * 1000 / limit_rate + 1); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1075 ngx_add_timer(src->read, delay); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1076 break; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1077 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1078 |
6204
114d1f8cdcab
Stream: fixed possible integer overflow in rate limiting.
Valentin Bartenev <vbart@nginx.com>
parents:
6203
diff
changeset
|
1079 if ((off_t) size > limit) { |
6203
fdfdcad62875
Stream: fixed MSVC compilation warning.
Roman Arutyunyan <arut@nginx.com>
parents:
6202
diff
changeset
|
1080 size = (size_t) limit; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1081 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1082 } |
6115 | 1083 |
1084 n = src->recv(src, b->last, size); | |
1085 | |
1086 if (n == NGX_AGAIN || n == 0) { | |
1087 break; | |
1088 } | |
1089 | |
1090 if (n > 0) { | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1091 if (limit_rate) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1092 delay = (ngx_msec_t) (n * 1000 / limit_rate); |
6115 | 1093 |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1094 if (delay > 0) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1095 src->read->delayed = 1; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1096 ngx_add_timer(src->read, delay); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1097 } |
6115 | 1098 } |
1099 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1100 *received += n; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1101 b->last += n; |
6115 | 1102 do_write = 1; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1103 |
6115 | 1104 continue; |
1105 } | |
1106 | |
1107 if (n == NGX_ERROR) { | |
1108 src->read->eof = 1; | |
1109 } | |
1110 } | |
1111 | |
1112 break; | |
1113 } | |
1114 | |
1115 if (src->read->eof && (b->pos == b->last || (dst && dst->read->eof))) { | |
1116 handler = c->log->handler; | |
1117 c->log->handler = NULL; | |
1118 | |
1119 ngx_log_error(NGX_LOG_INFO, c->log, 0, | |
1120 "%s disconnected" | |
1121 ", bytes from/to client:%O/%O" | |
1122 ", bytes from/to upstream:%O/%O", | |
1123 from_upstream ? "upstream" : "client", | |
1124 s->received, c->sent, u->received, pc ? pc->sent : 0); | |
1125 | |
1126 c->log->handler = handler; | |
1127 | |
1128 ngx_stream_proxy_finalize(s, NGX_OK); | |
1129 return NGX_DONE; | |
1130 } | |
1131 | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1132 flags = src->read->eof ? NGX_CLOSE_EVENT : 0; |
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1133 |
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1134 if (ngx_handle_read_event(src->read, flags) != NGX_OK) { |
6115 | 1135 ngx_stream_proxy_finalize(s, NGX_ERROR); |
1136 return NGX_ERROR; | |
1137 } | |
1138 | |
1139 if (dst) { | |
1140 if (ngx_handle_write_event(dst->write, 0) != NGX_OK) { | |
1141 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
1142 return NGX_ERROR; | |
1143 } | |
1144 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1145 if (!c->read->delayed && !pc->read->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1146 ngx_add_timer(c->write, pscf->timeout); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1147 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1148 } else if (c->write->timer_set) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1149 ngx_del_timer(c->write); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1150 } |
6115 | 1151 } |
1152 | |
1153 return NGX_OK; | |
1154 } | |
1155 | |
1156 | |
1157 static void | |
1158 ngx_stream_proxy_next_upstream(ngx_stream_session_t *s) | |
1159 { | |
1160 ngx_msec_t timeout; | |
1161 ngx_connection_t *pc; | |
1162 ngx_stream_upstream_t *u; | |
1163 ngx_stream_proxy_srv_conf_t *pscf; | |
1164 | |
1165 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1166 "stream proxy next upstream"); | |
1167 | |
1168 u = s->upstream; | |
1169 | |
1170 if (u->peer.sockaddr) { | |
1171 u->peer.free(&u->peer, u->peer.data, NGX_PEER_FAILED); | |
1172 u->peer.sockaddr = NULL; | |
1173 } | |
1174 | |
1175 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
1176 | |
1177 timeout = pscf->next_upstream_timeout; | |
1178 | |
1179 if (u->peer.tries == 0 | |
1180 || !pscf->next_upstream | |
1181 || (timeout && ngx_current_msec - u->peer.start_time >= timeout)) | |
1182 { | |
1183 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
1184 return; | |
1185 } | |
1186 | |
1187 pc = u->peer.connection; | |
1188 | |
1189 if (pc) { | |
1190 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1191 "close proxy upstream connection: %d", pc->fd); | |
1192 | |
1193 #if (NGX_STREAM_SSL) | |
1194 if (pc->ssl) { | |
1195 pc->ssl->no_wait_shutdown = 1; | |
1196 pc->ssl->no_send_shutdown = 1; | |
1197 | |
1198 (void) ngx_ssl_shutdown(pc); | |
1199 } | |
1200 #endif | |
1201 | |
1202 ngx_close_connection(pc); | |
1203 u->peer.connection = NULL; | |
1204 } | |
1205 | |
1206 ngx_stream_proxy_connect(s); | |
1207 } | |
1208 | |
1209 | |
1210 static void | |
1211 ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc) | |
1212 { | |
1213 ngx_connection_t *pc; | |
1214 ngx_stream_upstream_t *u; | |
1215 | |
1216 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1217 "finalize stream proxy: %i", rc); | |
1218 | |
1219 u = s->upstream; | |
1220 | |
1221 if (u == NULL) { | |
1222 goto noupstream; | |
1223 } | |
1224 | |
1225 if (u->peer.free && u->peer.sockaddr) { | |
1226 u->peer.free(&u->peer, u->peer.data, 0); | |
1227 u->peer.sockaddr = NULL; | |
1228 } | |
1229 | |
1230 pc = u->peer.connection; | |
1231 | |
1232 if (pc) { | |
1233 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1234 "close stream proxy upstream connection: %d", pc->fd); | |
1235 | |
1236 #if (NGX_STREAM_SSL) | |
1237 if (pc->ssl) { | |
1238 pc->ssl->no_wait_shutdown = 1; | |
1239 (void) ngx_ssl_shutdown(pc); | |
1240 } | |
1241 #endif | |
1242 | |
1243 ngx_close_connection(pc); | |
1244 u->peer.connection = NULL; | |
1245 } | |
1246 | |
1247 noupstream: | |
1248 | |
1249 ngx_stream_close_connection(s->connection); | |
1250 } | |
1251 | |
1252 | |
1253 static u_char * | |
1254 ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, size_t len) | |
1255 { | |
1256 u_char *p; | |
1257 ngx_connection_t *pc; | |
1258 ngx_stream_session_t *s; | |
1259 ngx_stream_upstream_t *u; | |
1260 | |
1261 s = log->data; | |
1262 | |
1263 u = s->upstream; | |
1264 | |
1265 p = buf; | |
1266 | |
1267 if (u->peer.name) { | |
1268 p = ngx_snprintf(p, len, ", upstream: \"%V\"", u->peer.name); | |
1269 len -= p - buf; | |
1270 } | |
1271 | |
1272 pc = u->peer.connection; | |
1273 | |
1274 p = ngx_snprintf(p, len, | |
1275 ", bytes from/to client:%O/%O" | |
1276 ", bytes from/to upstream:%O/%O", | |
1277 s->received, s->connection->sent, | |
1278 u->received, pc ? pc->sent : 0); | |
1279 | |
1280 return p; | |
1281 } | |
1282 | |
1283 | |
1284 static void * | |
1285 ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf) | |
1286 { | |
1287 ngx_stream_proxy_srv_conf_t *conf; | |
1288 | |
1289 conf = ngx_pcalloc(cf->pool, sizeof(ngx_stream_proxy_srv_conf_t)); | |
1290 if (conf == NULL) { | |
1291 return NULL; | |
1292 } | |
1293 | |
1294 /* | |
1295 * set by ngx_pcalloc(): | |
1296 * | |
1297 * conf->ssl_protocols = 0; | |
1298 * conf->ssl_ciphers = { 0, NULL }; | |
1299 * conf->ssl_name = { 0, NULL }; | |
1300 * conf->ssl_trusted_certificate = { 0, NULL }; | |
1301 * conf->ssl_crl = { 0, NULL }; | |
1302 * conf->ssl_certificate = { 0, NULL }; | |
1303 * conf->ssl_certificate_key = { 0, NULL }; | |
1304 * | |
1305 * conf->ssl = NULL; | |
1306 * conf->upstream = NULL; | |
1307 */ | |
1308 | |
1309 conf->connect_timeout = NGX_CONF_UNSET_MSEC; | |
1310 conf->timeout = NGX_CONF_UNSET_MSEC; | |
1311 conf->next_upstream_timeout = NGX_CONF_UNSET_MSEC; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
1312 conf->buffer_size = NGX_CONF_UNSET_SIZE; |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1313 conf->upload_rate = NGX_CONF_UNSET_SIZE; |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1314 conf->download_rate = NGX_CONF_UNSET_SIZE; |
6115 | 1315 conf->next_upstream_tries = NGX_CONF_UNSET_UINT; |
1316 conf->next_upstream = NGX_CONF_UNSET; | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1317 conf->proxy_protocol = NGX_CONF_UNSET; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1318 conf->local = NGX_CONF_UNSET_PTR; |
6115 | 1319 |
1320 #if (NGX_STREAM_SSL) | |
1321 conf->ssl_enable = NGX_CONF_UNSET; | |
1322 conf->ssl_session_reuse = NGX_CONF_UNSET; | |
1323 conf->ssl_server_name = NGX_CONF_UNSET; | |
1324 conf->ssl_verify = NGX_CONF_UNSET; | |
1325 conf->ssl_verify_depth = NGX_CONF_UNSET_UINT; | |
1326 conf->ssl_passwords = NGX_CONF_UNSET_PTR; | |
1327 #endif | |
1328 | |
1329 return conf; | |
1330 } | |
1331 | |
1332 | |
1333 static char * | |
1334 ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, void *child) | |
1335 { | |
1336 ngx_stream_proxy_srv_conf_t *prev = parent; | |
1337 ngx_stream_proxy_srv_conf_t *conf = child; | |
1338 | |
1339 ngx_conf_merge_msec_value(conf->connect_timeout, | |
1340 prev->connect_timeout, 60000); | |
1341 | |
1342 ngx_conf_merge_msec_value(conf->timeout, | |
1343 prev->timeout, 10 * 60000); | |
1344 | |
1345 ngx_conf_merge_msec_value(conf->next_upstream_timeout, | |
1346 prev->next_upstream_timeout, 0); | |
1347 | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
1348 ngx_conf_merge_size_value(conf->buffer_size, |
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
1349 prev->buffer_size, 16384); |
6115 | 1350 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1351 ngx_conf_merge_size_value(conf->upload_rate, |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1352 prev->upload_rate, 0); |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1353 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1354 ngx_conf_merge_size_value(conf->download_rate, |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1355 prev->download_rate, 0); |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1356 |
6115 | 1357 ngx_conf_merge_uint_value(conf->next_upstream_tries, |
1358 prev->next_upstream_tries, 0); | |
1359 | |
1360 ngx_conf_merge_value(conf->next_upstream, prev->next_upstream, 1); | |
1361 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1362 ngx_conf_merge_value(conf->proxy_protocol, prev->proxy_protocol, 0); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1363 |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1364 ngx_conf_merge_ptr_value(conf->local, prev->local, NULL); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1365 |
6115 | 1366 #if (NGX_STREAM_SSL) |
1367 | |
1368 ngx_conf_merge_value(conf->ssl_enable, prev->ssl_enable, 0); | |
1369 | |
1370 ngx_conf_merge_value(conf->ssl_session_reuse, | |
1371 prev->ssl_session_reuse, 1); | |
1372 | |
1373 ngx_conf_merge_bitmask_value(conf->ssl_protocols, prev->ssl_protocols, | |
6157
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1374 (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1 |
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1375 |NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2)); |
6115 | 1376 |
1377 ngx_conf_merge_str_value(conf->ssl_ciphers, prev->ssl_ciphers, "DEFAULT"); | |
1378 | |
1379 ngx_conf_merge_str_value(conf->ssl_name, prev->ssl_name, ""); | |
1380 | |
1381 ngx_conf_merge_value(conf->ssl_server_name, prev->ssl_server_name, 0); | |
1382 | |
1383 ngx_conf_merge_value(conf->ssl_verify, prev->ssl_verify, 0); | |
1384 | |
1385 ngx_conf_merge_uint_value(conf->ssl_verify_depth, | |
1386 prev->ssl_verify_depth, 1); | |
1387 | |
1388 ngx_conf_merge_str_value(conf->ssl_trusted_certificate, | |
1389 prev->ssl_trusted_certificate, ""); | |
1390 | |
1391 ngx_conf_merge_str_value(conf->ssl_crl, prev->ssl_crl, ""); | |
1392 | |
1393 ngx_conf_merge_str_value(conf->ssl_certificate, | |
1394 prev->ssl_certificate, ""); | |
1395 | |
1396 ngx_conf_merge_str_value(conf->ssl_certificate_key, | |
1397 prev->ssl_certificate_key, ""); | |
1398 | |
1399 ngx_conf_merge_ptr_value(conf->ssl_passwords, prev->ssl_passwords, NULL); | |
1400 | |
1401 if (conf->ssl_enable && ngx_stream_proxy_set_ssl(cf, conf) != NGX_OK) { | |
1402 return NGX_CONF_ERROR; | |
1403 } | |
1404 | |
1405 #endif | |
1406 | |
1407 return NGX_CONF_OK; | |
1408 } | |
1409 | |
1410 | |
1411 #if (NGX_STREAM_SSL) | |
1412 | |
1413 static ngx_int_t | |
1414 ngx_stream_proxy_set_ssl(ngx_conf_t *cf, ngx_stream_proxy_srv_conf_t *pscf) | |
1415 { | |
1416 ngx_pool_cleanup_t *cln; | |
1417 | |
1418 pscf->ssl = ngx_pcalloc(cf->pool, sizeof(ngx_ssl_t)); | |
1419 if (pscf->ssl == NULL) { | |
1420 return NGX_ERROR; | |
1421 } | |
1422 | |
1423 pscf->ssl->log = cf->log; | |
1424 | |
1425 if (ngx_ssl_create(pscf->ssl, pscf->ssl_protocols, NULL) != NGX_OK) { | |
1426 return NGX_ERROR; | |
1427 } | |
1428 | |
1429 cln = ngx_pool_cleanup_add(cf->pool, 0); | |
1430 if (cln == NULL) { | |
1431 return NGX_ERROR; | |
1432 } | |
1433 | |
1434 cln->handler = ngx_ssl_cleanup_ctx; | |
1435 cln->data = pscf->ssl; | |
1436 | |
1437 if (pscf->ssl_certificate.len) { | |
1438 | |
1439 if (pscf->ssl_certificate_key.len == 0) { | |
1440 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1441 "no \"proxy_ssl_certificate_key\" is defined " | |
1442 "for certificate \"%V\"", &pscf->ssl_certificate); | |
1443 return NGX_ERROR; | |
1444 } | |
1445 | |
1446 if (ngx_ssl_certificate(cf, pscf->ssl, &pscf->ssl_certificate, | |
1447 &pscf->ssl_certificate_key, pscf->ssl_passwords) | |
1448 != NGX_OK) | |
1449 { | |
1450 return NGX_ERROR; | |
1451 } | |
1452 } | |
1453 | |
1454 if (SSL_CTX_set_cipher_list(pscf->ssl->ctx, | |
1455 (const char *) pscf->ssl_ciphers.data) | |
1456 == 0) | |
1457 { | |
1458 ngx_ssl_error(NGX_LOG_EMERG, cf->log, 0, | |
1459 "SSL_CTX_set_cipher_list(\"%V\") failed", | |
1460 &pscf->ssl_ciphers); | |
1461 return NGX_ERROR; | |
1462 } | |
1463 | |
1464 if (pscf->ssl_verify) { | |
1465 if (pscf->ssl_trusted_certificate.len == 0) { | |
1466 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1467 "no proxy_ssl_trusted_certificate for proxy_ssl_verify"); | |
1468 return NGX_ERROR; | |
1469 } | |
1470 | |
1471 if (ngx_ssl_trusted_certificate(cf, pscf->ssl, | |
1472 &pscf->ssl_trusted_certificate, | |
1473 pscf->ssl_verify_depth) | |
1474 != NGX_OK) | |
1475 { | |
1476 return NGX_ERROR; | |
1477 } | |
1478 | |
1479 if (ngx_ssl_crl(cf, pscf->ssl, &pscf->ssl_crl) != NGX_OK) { | |
1480 return NGX_ERROR; | |
1481 } | |
1482 } | |
1483 | |
1484 return NGX_OK; | |
1485 } | |
1486 | |
1487 #endif | |
1488 | |
1489 | |
1490 static char * | |
1491 ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) | |
1492 { | |
1493 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
1494 | |
1495 ngx_url_t u; | |
1496 ngx_str_t *value, *url; | |
1497 ngx_stream_core_srv_conf_t *cscf; | |
1498 | |
1499 if (pscf->upstream) { | |
1500 return "is duplicate"; | |
1501 } | |
1502 | |
1503 cscf = ngx_stream_conf_get_module_srv_conf(cf, ngx_stream_core_module); | |
1504 | |
1505 cscf->handler = ngx_stream_proxy_handler; | |
1506 | |
1507 value = cf->args->elts; | |
1508 | |
1509 url = &value[1]; | |
1510 | |
1511 ngx_memzero(&u, sizeof(ngx_url_t)); | |
1512 | |
1513 u.url = *url; | |
1514 u.no_resolve = 1; | |
1515 | |
1516 pscf->upstream = ngx_stream_upstream_add(cf, &u, 0); | |
1517 if (pscf->upstream == NULL) { | |
1518 return NGX_CONF_ERROR; | |
1519 } | |
1520 | |
1521 return NGX_CONF_OK; | |
1522 } | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1523 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1524 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1525 static char * |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1526 ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1527 { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1528 ngx_stream_proxy_srv_conf_t *pscf = conf; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1529 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1530 ngx_int_t rc; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1531 ngx_str_t *value; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1532 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1533 if (pscf->local != NGX_CONF_UNSET_PTR) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1534 return "is duplicate"; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1535 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1536 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1537 value = cf->args->elts; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1538 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1539 if (ngx_strcmp(value[1].data, "off") == 0) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1540 pscf->local = NULL; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1541 return NGX_CONF_OK; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1542 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1543 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1544 pscf->local = ngx_palloc(cf->pool, sizeof(ngx_addr_t)); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1545 if (pscf->local == NULL) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1546 return NGX_CONF_ERROR; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1547 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1548 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1549 rc = ngx_parse_addr(cf->pool, pscf->local, value[1].data, value[1].len); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1550 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1551 switch (rc) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1552 case NGX_OK: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1553 pscf->local->name = value[1]; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1554 return NGX_CONF_OK; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1555 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1556 case NGX_DECLINED: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1557 ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1558 "invalid address \"%V\"", &value[1]); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1559 /* fall through */ |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1560 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1561 default: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1562 return NGX_CONF_ERROR; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1563 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1564 } |