Mercurial > hg > nginx
annotate src/stream/ngx_stream_proxy_module.c @ 6529:cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
author | Roman Arutyunyan <arut@nginx.com> |
---|---|
date | Wed, 13 Apr 2016 15:42:47 +0300 |
parents | a01e315b3a78 |
children | 1d0e03db9f8e |
rev | line source |
---|---|
6115 | 1 |
2 /* | |
3 * Copyright (C) Roman Arutyunyan | |
4 * Copyright (C) Nginx, Inc. | |
5 */ | |
6 | |
7 | |
8 #include <ngx_config.h> | |
9 #include <ngx_core.h> | |
10 #include <ngx_stream.h> | |
11 | |
12 | |
13 typedef struct { | |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
14 ngx_addr_t *addr; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
15 } ngx_stream_upstream_local_t; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
16 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
17 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
18 typedef struct { |
6115 | 19 ngx_msec_t connect_timeout; |
20 ngx_msec_t timeout; | |
21 ngx_msec_t next_upstream_timeout; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
22 size_t buffer_size; |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
23 size_t upload_rate; |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
24 size_t download_rate; |
6436 | 25 ngx_uint_t responses; |
6115 | 26 ngx_uint_t next_upstream_tries; |
27 ngx_flag_t next_upstream; | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
28 ngx_flag_t proxy_protocol; |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
29 ngx_stream_upstream_local_t *local; |
6115 | 30 |
31 #if (NGX_STREAM_SSL) | |
32 ngx_flag_t ssl_enable; | |
33 ngx_flag_t ssl_session_reuse; | |
34 ngx_uint_t ssl_protocols; | |
35 ngx_str_t ssl_ciphers; | |
36 ngx_str_t ssl_name; | |
37 ngx_flag_t ssl_server_name; | |
38 | |
39 ngx_flag_t ssl_verify; | |
40 ngx_uint_t ssl_verify_depth; | |
41 ngx_str_t ssl_trusted_certificate; | |
42 ngx_str_t ssl_crl; | |
43 ngx_str_t ssl_certificate; | |
44 ngx_str_t ssl_certificate_key; | |
45 ngx_array_t *ssl_passwords; | |
46 | |
47 ngx_ssl_t *ssl; | |
48 #endif | |
49 | |
50 ngx_stream_upstream_srv_conf_t *upstream; | |
51 } ngx_stream_proxy_srv_conf_t; | |
52 | |
53 | |
54 static void ngx_stream_proxy_handler(ngx_stream_session_t *s); | |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
55 static ngx_int_t ngx_stream_proxy_set_local(ngx_stream_session_t *s, |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
56 ngx_stream_upstream_t *u, ngx_stream_upstream_local_t *local); |
6115 | 57 static void ngx_stream_proxy_connect(ngx_stream_session_t *s); |
58 static void ngx_stream_proxy_init_upstream(ngx_stream_session_t *s); | |
59 static void ngx_stream_proxy_upstream_handler(ngx_event_t *ev); | |
60 static void ngx_stream_proxy_downstream_handler(ngx_event_t *ev); | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
61 static void ngx_stream_proxy_process_connection(ngx_event_t *ev, |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
62 ngx_uint_t from_upstream); |
6115 | 63 static void ngx_stream_proxy_connect_handler(ngx_event_t *ev); |
64 static ngx_int_t ngx_stream_proxy_test_connect(ngx_connection_t *c); | |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
65 static void ngx_stream_proxy_process(ngx_stream_session_t *s, |
6115 | 66 ngx_uint_t from_upstream, ngx_uint_t do_write); |
67 static void ngx_stream_proxy_next_upstream(ngx_stream_session_t *s); | |
68 static void ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc); | |
69 static u_char *ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, | |
70 size_t len); | |
71 | |
72 static void *ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf); | |
73 static char *ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, | |
74 void *child); | |
75 static char *ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, | |
76 void *conf); | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
77 static char *ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
78 void *conf); |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
79 static ngx_int_t ngx_stream_proxy_send_proxy_protocol(ngx_stream_session_t *s); |
6115 | 80 |
81 #if (NGX_STREAM_SSL) | |
82 | |
83 static char *ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, | |
84 ngx_command_t *cmd, void *conf); | |
85 static void ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s); | |
86 static void ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc); | |
87 static ngx_int_t ngx_stream_proxy_ssl_name(ngx_stream_session_t *s); | |
88 static ngx_int_t ngx_stream_proxy_set_ssl(ngx_conf_t *cf, | |
89 ngx_stream_proxy_srv_conf_t *pscf); | |
90 | |
91 | |
92 static ngx_conf_bitmask_t ngx_stream_proxy_ssl_protocols[] = { | |
93 { ngx_string("SSLv2"), NGX_SSL_SSLv2 }, | |
94 { ngx_string("SSLv3"), NGX_SSL_SSLv3 }, | |
95 { ngx_string("TLSv1"), NGX_SSL_TLSv1 }, | |
96 { ngx_string("TLSv1.1"), NGX_SSL_TLSv1_1 }, | |
97 { ngx_string("TLSv1.2"), NGX_SSL_TLSv1_2 }, | |
98 { ngx_null_string, 0 } | |
99 }; | |
100 | |
101 #endif | |
102 | |
103 | |
6217
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
104 static ngx_conf_deprecated_t ngx_conf_deprecated_proxy_downstream_buffer = { |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
105 ngx_conf_deprecated, "proxy_downstream_buffer", "proxy_buffer_size" |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
106 }; |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
107 |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
108 static ngx_conf_deprecated_t ngx_conf_deprecated_proxy_upstream_buffer = { |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
109 ngx_conf_deprecated, "proxy_upstream_buffer", "proxy_buffer_size" |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
110 }; |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
111 |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
112 |
6115 | 113 static ngx_command_t ngx_stream_proxy_commands[] = { |
114 | |
115 { ngx_string("proxy_pass"), | |
116 NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
117 ngx_stream_proxy_pass, | |
118 NGX_STREAM_SRV_CONF_OFFSET, | |
119 0, | |
120 NULL }, | |
121 | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
122 { ngx_string("proxy_bind"), |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
123 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
124 ngx_stream_proxy_bind, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
125 NGX_STREAM_SRV_CONF_OFFSET, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
126 0, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
127 NULL }, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
128 |
6115 | 129 { ngx_string("proxy_connect_timeout"), |
130 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
131 ngx_conf_set_msec_slot, | |
132 NGX_STREAM_SRV_CONF_OFFSET, | |
133 offsetof(ngx_stream_proxy_srv_conf_t, connect_timeout), | |
134 NULL }, | |
135 | |
136 { ngx_string("proxy_timeout"), | |
137 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
138 ngx_conf_set_msec_slot, | |
139 NGX_STREAM_SRV_CONF_OFFSET, | |
140 offsetof(ngx_stream_proxy_srv_conf_t, timeout), | |
141 NULL }, | |
142 | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
143 { ngx_string("proxy_buffer_size"), |
6115 | 144 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
145 ngx_conf_set_size_slot, | |
146 NGX_STREAM_SRV_CONF_OFFSET, | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
147 offsetof(ngx_stream_proxy_srv_conf_t, buffer_size), |
6115 | 148 NULL }, |
149 | |
6217
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
150 { ngx_string("proxy_downstream_buffer"), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
151 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
152 ngx_conf_set_size_slot, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
153 NGX_STREAM_SRV_CONF_OFFSET, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
154 offsetof(ngx_stream_proxy_srv_conf_t, buffer_size), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
155 &ngx_conf_deprecated_proxy_downstream_buffer }, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
156 |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
157 { ngx_string("proxy_upstream_buffer"), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
158 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
159 ngx_conf_set_size_slot, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
160 NGX_STREAM_SRV_CONF_OFFSET, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
161 offsetof(ngx_stream_proxy_srv_conf_t, buffer_size), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
162 &ngx_conf_deprecated_proxy_upstream_buffer }, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
163 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
164 { ngx_string("proxy_upload_rate"), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
165 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
166 ngx_conf_set_size_slot, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
167 NGX_STREAM_SRV_CONF_OFFSET, |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
168 offsetof(ngx_stream_proxy_srv_conf_t, upload_rate), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
169 NULL }, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
170 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
171 { ngx_string("proxy_download_rate"), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
172 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
173 ngx_conf_set_size_slot, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
174 NGX_STREAM_SRV_CONF_OFFSET, |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
175 offsetof(ngx_stream_proxy_srv_conf_t, download_rate), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
176 NULL }, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
177 |
6436 | 178 { ngx_string("proxy_responses"), |
179 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
180 ngx_conf_set_num_slot, | |
181 NGX_STREAM_SRV_CONF_OFFSET, | |
182 offsetof(ngx_stream_proxy_srv_conf_t, responses), | |
183 NULL }, | |
184 | |
6115 | 185 { ngx_string("proxy_next_upstream"), |
186 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
187 ngx_conf_set_flag_slot, | |
188 NGX_STREAM_SRV_CONF_OFFSET, | |
189 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream), | |
190 NULL }, | |
191 | |
192 { ngx_string("proxy_next_upstream_tries"), | |
193 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
194 ngx_conf_set_num_slot, | |
195 NGX_STREAM_SRV_CONF_OFFSET, | |
196 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_tries), | |
197 NULL }, | |
198 | |
199 { ngx_string("proxy_next_upstream_timeout"), | |
200 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
201 ngx_conf_set_msec_slot, | |
202 NGX_STREAM_SRV_CONF_OFFSET, | |
203 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_timeout), | |
204 NULL }, | |
205 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
206 { ngx_string("proxy_protocol"), |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
207 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
208 ngx_conf_set_flag_slot, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
209 NGX_STREAM_SRV_CONF_OFFSET, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
210 offsetof(ngx_stream_proxy_srv_conf_t, proxy_protocol), |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
211 NULL }, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
212 |
6115 | 213 #if (NGX_STREAM_SSL) |
214 | |
215 { ngx_string("proxy_ssl"), | |
216 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
217 ngx_conf_set_flag_slot, | |
218 NGX_STREAM_SRV_CONF_OFFSET, | |
219 offsetof(ngx_stream_proxy_srv_conf_t, ssl_enable), | |
220 NULL }, | |
221 | |
222 { ngx_string("proxy_ssl_session_reuse"), | |
223 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
224 ngx_conf_set_flag_slot, | |
225 NGX_STREAM_SRV_CONF_OFFSET, | |
226 offsetof(ngx_stream_proxy_srv_conf_t, ssl_session_reuse), | |
227 NULL }, | |
228 | |
229 { ngx_string("proxy_ssl_protocols"), | |
230 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_1MORE, | |
231 ngx_conf_set_bitmask_slot, | |
232 NGX_STREAM_SRV_CONF_OFFSET, | |
233 offsetof(ngx_stream_proxy_srv_conf_t, ssl_protocols), | |
234 &ngx_stream_proxy_ssl_protocols }, | |
235 | |
236 { ngx_string("proxy_ssl_ciphers"), | |
237 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
238 ngx_conf_set_str_slot, | |
239 NGX_STREAM_SRV_CONF_OFFSET, | |
240 offsetof(ngx_stream_proxy_srv_conf_t, ssl_ciphers), | |
241 NULL }, | |
242 | |
243 { ngx_string("proxy_ssl_name"), | |
244 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
245 ngx_conf_set_str_slot, | |
246 NGX_STREAM_SRV_CONF_OFFSET, | |
247 offsetof(ngx_stream_proxy_srv_conf_t, ssl_name), | |
248 NULL }, | |
249 | |
250 { ngx_string("proxy_ssl_server_name"), | |
251 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
252 ngx_conf_set_flag_slot, | |
253 NGX_STREAM_SRV_CONF_OFFSET, | |
254 offsetof(ngx_stream_proxy_srv_conf_t, ssl_server_name), | |
255 NULL }, | |
256 | |
257 { ngx_string("proxy_ssl_verify"), | |
258 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
259 ngx_conf_set_flag_slot, | |
260 NGX_STREAM_SRV_CONF_OFFSET, | |
261 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify), | |
262 NULL }, | |
263 | |
264 { ngx_string("proxy_ssl_verify_depth"), | |
265 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
266 ngx_conf_set_num_slot, | |
267 NGX_STREAM_SRV_CONF_OFFSET, | |
268 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify_depth), | |
269 NULL }, | |
270 | |
271 { ngx_string("proxy_ssl_trusted_certificate"), | |
272 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
273 ngx_conf_set_str_slot, | |
274 NGX_STREAM_SRV_CONF_OFFSET, | |
275 offsetof(ngx_stream_proxy_srv_conf_t, ssl_trusted_certificate), | |
276 NULL }, | |
277 | |
278 { ngx_string("proxy_ssl_crl"), | |
279 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
280 ngx_conf_set_str_slot, | |
281 NGX_STREAM_SRV_CONF_OFFSET, | |
282 offsetof(ngx_stream_proxy_srv_conf_t, ssl_crl), | |
283 NULL }, | |
284 | |
285 { ngx_string("proxy_ssl_certificate"), | |
286 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
287 ngx_conf_set_str_slot, | |
288 NGX_STREAM_SRV_CONF_OFFSET, | |
289 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate), | |
290 NULL }, | |
291 | |
292 { ngx_string("proxy_ssl_certificate_key"), | |
293 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
294 ngx_conf_set_str_slot, | |
295 NGX_STREAM_SRV_CONF_OFFSET, | |
296 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate_key), | |
297 NULL }, | |
298 | |
299 { ngx_string("proxy_ssl_password_file"), | |
300 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
301 ngx_stream_proxy_ssl_password_file, | |
302 NGX_STREAM_SRV_CONF_OFFSET, | |
303 0, | |
304 NULL }, | |
305 | |
306 #endif | |
307 | |
308 ngx_null_command | |
309 }; | |
310 | |
311 | |
312 static ngx_stream_module_t ngx_stream_proxy_module_ctx = { | |
6174
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
313 NULL, /* postconfiguration */ |
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
314 |
6115 | 315 NULL, /* create main configuration */ |
316 NULL, /* init main configuration */ | |
317 | |
318 ngx_stream_proxy_create_srv_conf, /* create server configuration */ | |
319 ngx_stream_proxy_merge_srv_conf /* merge server configuration */ | |
320 }; | |
321 | |
322 | |
323 ngx_module_t ngx_stream_proxy_module = { | |
324 NGX_MODULE_V1, | |
325 &ngx_stream_proxy_module_ctx, /* module context */ | |
326 ngx_stream_proxy_commands, /* module directives */ | |
327 NGX_STREAM_MODULE, /* module type */ | |
328 NULL, /* init master */ | |
329 NULL, /* init module */ | |
330 NULL, /* init process */ | |
331 NULL, /* init thread */ | |
332 NULL, /* exit thread */ | |
333 NULL, /* exit process */ | |
334 NULL, /* exit master */ | |
335 NGX_MODULE_V1_PADDING | |
336 }; | |
337 | |
338 | |
339 static void | |
340 ngx_stream_proxy_handler(ngx_stream_session_t *s) | |
341 { | |
342 u_char *p; | |
343 ngx_connection_t *c; | |
344 ngx_stream_upstream_t *u; | |
345 ngx_stream_proxy_srv_conf_t *pscf; | |
346 ngx_stream_upstream_srv_conf_t *uscf; | |
347 | |
348 c = s->connection; | |
349 | |
350 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
351 | |
352 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
353 "proxy connection handler"); | |
354 | |
355 u = ngx_pcalloc(c->pool, sizeof(ngx_stream_upstream_t)); | |
356 if (u == NULL) { | |
357 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
358 return; | |
359 } | |
360 | |
361 s->upstream = u; | |
362 | |
363 s->log_handler = ngx_stream_proxy_log_error; | |
364 | |
365 u->peer.log = c->log; | |
366 u->peer.log_error = NGX_ERROR_ERR; | |
367 | |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
368 if (ngx_stream_proxy_set_local(s, u, pscf->local) != NGX_OK) { |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
369 ngx_stream_proxy_finalize(s, NGX_ERROR); |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
370 return; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
371 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
372 |
6436 | 373 u->peer.type = c->type; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
374 |
6115 | 375 uscf = pscf->upstream; |
376 | |
377 if (uscf->peer.init(s, uscf) != NGX_OK) { | |
378 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
379 return; | |
380 } | |
381 | |
382 u->peer.start_time = ngx_current_msec; | |
383 | |
384 if (pscf->next_upstream_tries | |
385 && u->peer.tries > pscf->next_upstream_tries) | |
386 { | |
387 u->peer.tries = pscf->next_upstream_tries; | |
388 } | |
389 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
390 u->proxy_protocol = pscf->proxy_protocol; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
391 u->start_sec = ngx_time(); |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
392 |
6436 | 393 c->write->handler = ngx_stream_proxy_downstream_handler; |
394 c->read->handler = ngx_stream_proxy_downstream_handler; | |
395 | |
396 if (c->type == SOCK_DGRAM) { | |
397 ngx_stream_proxy_connect(s); | |
398 return; | |
399 } | |
400 | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
401 p = ngx_pnalloc(c->pool, pscf->buffer_size); |
6115 | 402 if (p == NULL) { |
403 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
404 return; | |
405 } | |
406 | |
407 u->downstream_buf.start = p; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
408 u->downstream_buf.end = p + pscf->buffer_size; |
6115 | 409 u->downstream_buf.pos = p; |
410 u->downstream_buf.last = p; | |
411 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
412 if (u->proxy_protocol |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
413 #if (NGX_STREAM_SSL) |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
414 && pscf->ssl == NULL |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
415 #endif |
6216 | 416 && pscf->buffer_size >= NGX_PROXY_PROTOCOL_MAX_HEADER) |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
417 { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
418 /* optimization for a typical case */ |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
419 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
420 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
421 "stream proxy send PROXY protocol header"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
422 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
423 p = ngx_proxy_protocol_write(c, u->downstream_buf.last, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
424 u->downstream_buf.end); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
425 if (p == NULL) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
426 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
427 return; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
428 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
429 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
430 u->downstream_buf.last = p; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
431 u->proxy_protocol = 0; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
432 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
433 |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
434 if (c->read->ready) { |
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
435 ngx_post_event(c->read, &ngx_posted_events); |
6115 | 436 } |
437 | |
438 ngx_stream_proxy_connect(s); | |
439 } | |
440 | |
441 | |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
442 static ngx_int_t |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
443 ngx_stream_proxy_set_local(ngx_stream_session_t *s, ngx_stream_upstream_t *u, |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
444 ngx_stream_upstream_local_t *local) |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
445 { |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
446 if (local == NULL) { |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
447 u->peer.local = NULL; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
448 return NGX_OK; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
449 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
450 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
451 if (local->addr) { |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
452 u->peer.local = local->addr; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
453 return NGX_OK; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
454 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
455 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
456 return NGX_OK; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
457 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
458 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
459 |
6115 | 460 static void |
461 ngx_stream_proxy_connect(ngx_stream_session_t *s) | |
462 { | |
463 ngx_int_t rc; | |
464 ngx_connection_t *c, *pc; | |
465 ngx_stream_upstream_t *u; | |
466 ngx_stream_proxy_srv_conf_t *pscf; | |
467 | |
468 c = s->connection; | |
469 | |
470 c->log->action = "connecting to upstream"; | |
471 | |
472 u = s->upstream; | |
473 | |
474 rc = ngx_event_connect_peer(&u->peer); | |
475 | |
476 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, c->log, 0, "proxy connect: %i", rc); | |
477 | |
478 if (rc == NGX_ERROR) { | |
479 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
480 return; | |
481 } | |
482 | |
483 if (rc == NGX_BUSY) { | |
484 ngx_log_error(NGX_LOG_ERR, c->log, 0, "no live upstreams"); | |
485 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
486 return; | |
487 } | |
488 | |
489 if (rc == NGX_DECLINED) { | |
490 ngx_stream_proxy_next_upstream(s); | |
491 return; | |
492 } | |
493 | |
494 /* rc == NGX_OK || rc == NGX_AGAIN || rc == NGX_DONE */ | |
495 | |
496 pc = u->peer.connection; | |
497 | |
498 pc->data = s; | |
499 pc->log = c->log; | |
500 pc->pool = c->pool; | |
501 pc->read->log = c->log; | |
502 pc->write->log = c->log; | |
503 | |
504 if (rc != NGX_AGAIN) { | |
505 ngx_stream_proxy_init_upstream(s); | |
506 return; | |
507 } | |
508 | |
509 pc->read->handler = ngx_stream_proxy_connect_handler; | |
510 pc->write->handler = ngx_stream_proxy_connect_handler; | |
511 | |
6393
70e6e1f12dee
Stream: initialize variable right before using it.
Roman Arutyunyan <arut@nginx.com>
parents:
6392
diff
changeset
|
512 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
70e6e1f12dee
Stream: initialize variable right before using it.
Roman Arutyunyan <arut@nginx.com>
parents:
6392
diff
changeset
|
513 |
6115 | 514 ngx_add_timer(pc->write, pscf->connect_timeout); |
515 } | |
516 | |
517 | |
518 static void | |
519 ngx_stream_proxy_init_upstream(ngx_stream_session_t *s) | |
520 { | |
6222 | 521 int tcp_nodelay; |
6115 | 522 u_char *p; |
523 ngx_connection_t *c, *pc; | |
524 ngx_log_handler_pt handler; | |
525 ngx_stream_upstream_t *u; | |
6221
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
526 ngx_stream_core_srv_conf_t *cscf; |
6115 | 527 ngx_stream_proxy_srv_conf_t *pscf; |
528 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
529 u = s->upstream; |
6221
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
530 pc = u->peer.connection; |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
531 |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
532 cscf = ngx_stream_get_module_srv_conf(s, ngx_stream_core_module); |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
533 |
6436 | 534 if (pc->type == SOCK_STREAM |
535 && cscf->tcp_nodelay | |
536 && pc->tcp_nodelay == NGX_TCP_NODELAY_UNSET) | |
537 { | |
6221
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
538 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, pc->log, 0, "tcp_nodelay"); |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
539 |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
540 tcp_nodelay = 1; |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
541 |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
542 if (setsockopt(pc->fd, IPPROTO_TCP, TCP_NODELAY, |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
543 (const void *) &tcp_nodelay, sizeof(int)) == -1) |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
544 { |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
545 ngx_connection_error(pc, ngx_socket_errno, |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
546 "setsockopt(TCP_NODELAY) failed"); |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
547 ngx_stream_proxy_next_upstream(s); |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
548 return; |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
549 } |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
550 |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
551 pc->tcp_nodelay = NGX_TCP_NODELAY_SET; |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
552 } |
6115 | 553 |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
554 if (u->proxy_protocol) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
555 if (ngx_stream_proxy_send_proxy_protocol(s) != NGX_OK) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
556 return; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
557 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
558 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
559 u->proxy_protocol = 0; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
560 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
561 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
562 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
6115 | 563 |
564 #if (NGX_STREAM_SSL) | |
6436 | 565 if (pc->type == SOCK_STREAM && pscf->ssl && pc->ssl == NULL) { |
6115 | 566 ngx_stream_proxy_ssl_init_connection(s); |
567 return; | |
568 } | |
569 #endif | |
570 | |
571 c = s->connection; | |
572 | |
573 if (c->log->log_level >= NGX_LOG_INFO) { | |
6230
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
574 ngx_str_t str; |
6115 | 575 u_char addr[NGX_SOCKADDR_STRLEN]; |
576 | |
6230
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
577 str.len = NGX_SOCKADDR_STRLEN; |
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
578 str.data = addr; |
6115 | 579 |
6230
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
580 if (ngx_connection_local_sockaddr(pc, &str, 1) == NGX_OK) { |
6115 | 581 handler = c->log->handler; |
582 c->log->handler = NULL; | |
583 | |
6461
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
584 ngx_log_error(NGX_LOG_INFO, c->log, 0, |
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
585 "%sproxy %V connected to %V", |
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
586 pc->type == SOCK_DGRAM ? "udp " : "", |
6230
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
587 &str, u->peer.name); |
6115 | 588 |
589 c->log->handler = handler; | |
590 } | |
591 } | |
592 | |
593 c->log->action = "proxying connection"; | |
594 | |
6436 | 595 if (u->upstream_buf.start == NULL) { |
596 p = ngx_pnalloc(c->pool, pscf->buffer_size); | |
597 if (p == NULL) { | |
598 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
599 return; | |
600 } | |
601 | |
602 u->upstream_buf.start = p; | |
603 u->upstream_buf.end = p + pscf->buffer_size; | |
604 u->upstream_buf.pos = p; | |
605 u->upstream_buf.last = p; | |
6115 | 606 } |
607 | |
6436 | 608 if (c->type == SOCK_DGRAM) { |
609 s->received = c->buffer->last - c->buffer->pos; | |
610 u->downstream_buf = *c->buffer; | |
611 | |
612 if (pscf->responses == 0) { | |
613 pc->read->ready = 0; | |
614 pc->read->eof = 1; | |
615 } | |
616 } | |
6115 | 617 |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
618 u->connected = 1; |
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
619 |
6115 | 620 pc->read->handler = ngx_stream_proxy_upstream_handler; |
621 pc->write->handler = ngx_stream_proxy_upstream_handler; | |
622 | |
6436 | 623 if (pc->read->ready || pc->read->eof) { |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
624 ngx_post_event(pc->read, &ngx_posted_events); |
6115 | 625 } |
626 | |
627 ngx_stream_proxy_process(s, 0, 1); | |
628 } | |
629 | |
630 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
631 static ngx_int_t |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
632 ngx_stream_proxy_send_proxy_protocol(ngx_stream_session_t *s) |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
633 { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
634 u_char *p; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
635 ssize_t n, size; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
636 ngx_connection_t *c, *pc; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
637 ngx_stream_upstream_t *u; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
638 ngx_stream_proxy_srv_conf_t *pscf; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
639 u_char buf[NGX_PROXY_PROTOCOL_MAX_HEADER]; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
640 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
641 c = s->connection; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
642 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
643 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
644 "stream proxy send PROXY protocol header"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
645 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
646 p = ngx_proxy_protocol_write(c, buf, buf + NGX_PROXY_PROTOCOL_MAX_HEADER); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
647 if (p == NULL) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
648 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
649 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
650 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
651 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
652 u = s->upstream; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
653 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
654 pc = u->peer.connection; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
655 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
656 size = p - buf; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
657 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
658 n = pc->send(pc, buf, size); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
659 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
660 if (n == NGX_AGAIN) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
661 if (ngx_handle_write_event(pc->write, 0) != NGX_OK) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
662 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
663 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
664 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
665 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
666 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
667 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
668 ngx_add_timer(pc->write, pscf->timeout); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
669 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
670 pc->write->handler = ngx_stream_proxy_connect_handler; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
671 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
672 return NGX_AGAIN; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
673 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
674 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
675 if (n == NGX_ERROR) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
676 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
677 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
678 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
679 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
680 if (n != size) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
681 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
682 /* |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
683 * PROXY protocol specification: |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
684 * The sender must always ensure that the header |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
685 * is sent at once, so that the transport layer |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
686 * maintains atomicity along the path to the receiver. |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
687 */ |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
688 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
689 ngx_log_error(NGX_LOG_ERR, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
690 "could not send PROXY protocol header at once"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
691 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
692 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
693 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
694 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
695 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
696 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
697 return NGX_OK; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
698 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
699 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
700 |
6115 | 701 #if (NGX_STREAM_SSL) |
702 | |
703 static char * | |
704 ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, ngx_command_t *cmd, | |
705 void *conf) | |
706 { | |
707 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
708 | |
709 ngx_str_t *value; | |
710 | |
711 if (pscf->ssl_passwords != NGX_CONF_UNSET_PTR) { | |
712 return "is duplicate"; | |
713 } | |
714 | |
715 value = cf->args->elts; | |
716 | |
717 pscf->ssl_passwords = ngx_ssl_read_password_file(cf, &value[1]); | |
718 | |
719 if (pscf->ssl_passwords == NULL) { | |
720 return NGX_CONF_ERROR; | |
721 } | |
722 | |
723 return NGX_CONF_OK; | |
724 } | |
725 | |
726 | |
727 static void | |
728 ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s) | |
729 { | |
730 ngx_int_t rc; | |
731 ngx_connection_t *pc; | |
732 ngx_stream_upstream_t *u; | |
733 ngx_stream_proxy_srv_conf_t *pscf; | |
734 | |
735 u = s->upstream; | |
736 | |
737 pc = u->peer.connection; | |
738 | |
739 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
740 | |
741 if (ngx_ssl_create_connection(pscf->ssl, pc, NGX_SSL_BUFFER|NGX_SSL_CLIENT) | |
742 != NGX_OK) | |
743 { | |
744 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
745 return; | |
746 } | |
747 | |
748 if (pscf->ssl_server_name || pscf->ssl_verify) { | |
749 if (ngx_stream_proxy_ssl_name(s) != NGX_OK) { | |
750 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
751 return; | |
752 } | |
753 } | |
754 | |
755 if (pscf->ssl_session_reuse) { | |
756 if (u->peer.set_session(&u->peer, u->peer.data) != NGX_OK) { | |
757 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
758 return; | |
759 } | |
760 } | |
761 | |
762 s->connection->log->action = "SSL handshaking to upstream"; | |
763 | |
764 rc = ngx_ssl_handshake(pc); | |
765 | |
766 if (rc == NGX_AGAIN) { | |
767 | |
768 if (!pc->write->timer_set) { | |
769 ngx_add_timer(pc->write, pscf->connect_timeout); | |
770 } | |
771 | |
772 pc->ssl->handler = ngx_stream_proxy_ssl_handshake; | |
773 return; | |
774 } | |
775 | |
776 ngx_stream_proxy_ssl_handshake(pc); | |
777 } | |
778 | |
779 | |
780 static void | |
781 ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc) | |
782 { | |
783 long rc; | |
784 ngx_stream_session_t *s; | |
785 ngx_stream_upstream_t *u; | |
786 ngx_stream_proxy_srv_conf_t *pscf; | |
787 | |
788 s = pc->data; | |
789 | |
790 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
791 | |
792 if (pc->ssl->handshaked) { | |
793 | |
794 if (pscf->ssl_verify) { | |
795 rc = SSL_get_verify_result(pc->ssl->connection); | |
796 | |
797 if (rc != X509_V_OK) { | |
798 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
799 "upstream SSL certificate verify error: (%l:%s)", | |
800 rc, X509_verify_cert_error_string(rc)); | |
801 goto failed; | |
802 } | |
803 | |
804 u = s->upstream; | |
805 | |
806 if (ngx_ssl_check_host(pc, &u->ssl_name) != NGX_OK) { | |
807 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
808 "upstream SSL certificate does not match \"%V\"", | |
809 &u->ssl_name); | |
810 goto failed; | |
811 } | |
812 } | |
813 | |
814 if (pscf->ssl_session_reuse) { | |
815 u = s->upstream; | |
816 u->peer.save_session(&u->peer, u->peer.data); | |
817 } | |
818 | |
6258
4b4aee40c508
Stream: delete proxy connection timer after SSL handshake.
Ruslan Ermilov <ru@nginx.com>
parents:
6230
diff
changeset
|
819 if (pc->write->timer_set) { |
4b4aee40c508
Stream: delete proxy connection timer after SSL handshake.
Ruslan Ermilov <ru@nginx.com>
parents:
6230
diff
changeset
|
820 ngx_del_timer(pc->write); |
4b4aee40c508
Stream: delete proxy connection timer after SSL handshake.
Ruslan Ermilov <ru@nginx.com>
parents:
6230
diff
changeset
|
821 } |
4b4aee40c508
Stream: delete proxy connection timer after SSL handshake.
Ruslan Ermilov <ru@nginx.com>
parents:
6230
diff
changeset
|
822 |
6115 | 823 ngx_stream_proxy_init_upstream(s); |
824 | |
825 return; | |
826 } | |
827 | |
828 failed: | |
829 | |
830 ngx_stream_proxy_next_upstream(s); | |
831 } | |
832 | |
833 | |
834 static ngx_int_t | |
835 ngx_stream_proxy_ssl_name(ngx_stream_session_t *s) | |
836 { | |
837 u_char *p, *last; | |
838 ngx_str_t name; | |
839 ngx_stream_upstream_t *u; | |
840 ngx_stream_proxy_srv_conf_t *pscf; | |
841 | |
842 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
843 | |
844 u = s->upstream; | |
845 | |
846 name = pscf->ssl_name; | |
847 | |
848 if (name.len == 0) { | |
849 name = pscf->upstream->host; | |
850 } | |
851 | |
852 if (name.len == 0) { | |
853 goto done; | |
854 } | |
855 | |
856 /* | |
857 * ssl name here may contain port, strip it for compatibility | |
858 * with the http module | |
859 */ | |
860 | |
861 p = name.data; | |
862 last = name.data + name.len; | |
863 | |
864 if (*p == '[') { | |
865 p = ngx_strlchr(p, last, ']'); | |
866 | |
867 if (p == NULL) { | |
868 p = name.data; | |
869 } | |
870 } | |
871 | |
872 p = ngx_strlchr(p, last, ':'); | |
873 | |
874 if (p != NULL) { | |
875 name.len = p - name.data; | |
876 } | |
877 | |
878 if (!pscf->ssl_server_name) { | |
879 goto done; | |
880 } | |
881 | |
882 #ifdef SSL_CTRL_SET_TLSEXT_HOSTNAME | |
883 | |
884 /* as per RFC 6066, literal IPv4 and IPv6 addresses are not permitted */ | |
885 | |
886 if (name.len == 0 || *name.data == '[') { | |
887 goto done; | |
888 } | |
889 | |
890 if (ngx_inet_addr(name.data, name.len) != INADDR_NONE) { | |
891 goto done; | |
892 } | |
893 | |
894 /* | |
895 * SSL_set_tlsext_host_name() needs a null-terminated string, | |
896 * hence we explicitly null-terminate name here | |
897 */ | |
898 | |
899 p = ngx_pnalloc(s->connection->pool, name.len + 1); | |
900 if (p == NULL) { | |
901 return NGX_ERROR; | |
902 } | |
903 | |
904 (void) ngx_cpystrn(p, name.data, name.len + 1); | |
905 | |
906 name.data = p; | |
907 | |
908 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
909 "upstream SSL server name: \"%s\"", name.data); | |
910 | |
911 if (SSL_set_tlsext_host_name(u->peer.connection->ssl->connection, name.data) | |
912 == 0) | |
913 { | |
914 ngx_ssl_error(NGX_LOG_ERR, s->connection->log, 0, | |
915 "SSL_set_tlsext_host_name(\"%s\") failed", name.data); | |
916 return NGX_ERROR; | |
917 } | |
918 | |
919 #endif | |
920 | |
921 done: | |
922 | |
923 u->ssl_name = name; | |
924 | |
925 return NGX_OK; | |
926 } | |
927 | |
928 #endif | |
929 | |
930 | |
931 static void | |
932 ngx_stream_proxy_downstream_handler(ngx_event_t *ev) | |
933 { | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
934 ngx_stream_proxy_process_connection(ev, ev->write); |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
935 } |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
936 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
937 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
938 static void |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
939 ngx_stream_proxy_upstream_handler(ngx_event_t *ev) |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
940 { |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
941 ngx_stream_proxy_process_connection(ev, !ev->write); |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
942 } |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
943 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
944 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
945 static void |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
946 ngx_stream_proxy_process_connection(ngx_event_t *ev, ngx_uint_t from_upstream) |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
947 { |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
948 ngx_connection_t *c, *pc; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
949 ngx_stream_session_t *s; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
950 ngx_stream_upstream_t *u; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
951 ngx_stream_proxy_srv_conf_t *pscf; |
6115 | 952 |
953 c = ev->data; | |
954 s = c->data; | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
955 u = s->upstream; |
6115 | 956 |
6436 | 957 c = s->connection; |
958 pc = u->peer.connection; | |
959 | |
960 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
961 | |
6115 | 962 if (ev->timedout) { |
6436 | 963 ev->timedout = 0; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
964 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
965 if (ev->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
966 ev->delayed = 0; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
967 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
968 if (!ev->ready) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
969 if (ngx_handle_read_event(ev, 0) != NGX_OK) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
970 ngx_stream_proxy_finalize(s, NGX_ERROR); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
971 return; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
972 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
973 |
6436 | 974 if (u->connected && !c->read->delayed && !pc->read->delayed) { |
975 ngx_add_timer(c->write, pscf->timeout); | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
976 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
977 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
978 return; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
979 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
980 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
981 } else { |
6436 | 982 if (s->connection->type == SOCK_DGRAM) { |
983 if (pscf->responses == NGX_MAX_INT32_VALUE) { | |
984 | |
985 /* | |
986 * successfully terminate timed out UDP session | |
987 * with unspecified number of responses | |
988 */ | |
989 | |
990 pc->read->ready = 0; | |
991 pc->read->eof = 1; | |
992 | |
993 ngx_stream_proxy_process(s, 1, 0); | |
994 return; | |
995 } | |
996 | |
997 if (u->received == 0) { | |
998 ngx_stream_proxy_next_upstream(s); | |
999 return; | |
1000 } | |
1001 } | |
1002 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1003 ngx_connection_error(c, NGX_ETIMEDOUT, "connection timed out"); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1004 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1005 return; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1006 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1007 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1008 } else if (ev->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1009 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1010 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1011 "stream connection delayed"); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1012 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1013 if (ngx_handle_read_event(ev, 0) != NGX_OK) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1014 ngx_stream_proxy_finalize(s, NGX_ERROR); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1015 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1016 |
6115 | 1017 return; |
1018 } | |
1019 | |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
1020 if (from_upstream && !u->connected) { |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
1021 return; |
6115 | 1022 } |
1023 | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
1024 ngx_stream_proxy_process(s, from_upstream, ev->write); |
6115 | 1025 } |
1026 | |
1027 | |
1028 static void | |
1029 ngx_stream_proxy_connect_handler(ngx_event_t *ev) | |
1030 { | |
1031 ngx_connection_t *c; | |
1032 ngx_stream_session_t *s; | |
1033 | |
1034 c = ev->data; | |
1035 s = c->data; | |
1036 | |
1037 if (ev->timedout) { | |
1038 ngx_log_error(NGX_LOG_ERR, c->log, NGX_ETIMEDOUT, "upstream timed out"); | |
1039 ngx_stream_proxy_next_upstream(s); | |
1040 return; | |
1041 } | |
1042 | |
1043 ngx_del_timer(c->write); | |
1044 | |
1045 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
1046 "stream proxy connect upstream"); | |
1047 | |
1048 if (ngx_stream_proxy_test_connect(c) != NGX_OK) { | |
1049 ngx_stream_proxy_next_upstream(s); | |
1050 return; | |
1051 } | |
1052 | |
1053 ngx_stream_proxy_init_upstream(s); | |
1054 } | |
1055 | |
1056 | |
1057 static ngx_int_t | |
1058 ngx_stream_proxy_test_connect(ngx_connection_t *c) | |
1059 { | |
1060 int err; | |
1061 socklen_t len; | |
1062 | |
1063 #if (NGX_HAVE_KQUEUE) | |
1064 | |
1065 if (ngx_event_flags & NGX_USE_KQUEUE_EVENT) { | |
1066 err = c->write->kq_errno ? c->write->kq_errno : c->read->kq_errno; | |
1067 | |
1068 if (err) { | |
1069 (void) ngx_connection_error(c, err, | |
1070 "kevent() reported that connect() failed"); | |
1071 return NGX_ERROR; | |
1072 } | |
1073 | |
1074 } else | |
1075 #endif | |
1076 { | |
1077 err = 0; | |
1078 len = sizeof(int); | |
1079 | |
1080 /* | |
1081 * BSDs and Linux return 0 and set a pending error in err | |
1082 * Solaris returns -1 and sets errno | |
1083 */ | |
1084 | |
1085 if (getsockopt(c->fd, SOL_SOCKET, SO_ERROR, (void *) &err, &len) | |
1086 == -1) | |
1087 { | |
1088 err = ngx_socket_errno; | |
1089 } | |
1090 | |
1091 if (err) { | |
1092 (void) ngx_connection_error(c, err, "connect() failed"); | |
1093 return NGX_ERROR; | |
1094 } | |
1095 } | |
1096 | |
1097 return NGX_OK; | |
1098 } | |
1099 | |
1100 | |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1101 static void |
6115 | 1102 ngx_stream_proxy_process(ngx_stream_session_t *s, ngx_uint_t from_upstream, |
1103 ngx_uint_t do_write) | |
1104 { | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1105 off_t *received, limit; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1106 size_t size, limit_rate; |
6115 | 1107 ssize_t n; |
1108 ngx_buf_t *b; | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1109 ngx_uint_t flags; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1110 ngx_msec_t delay; |
6115 | 1111 ngx_connection_t *c, *pc, *src, *dst; |
1112 ngx_log_handler_pt handler; | |
1113 ngx_stream_upstream_t *u; | |
1114 ngx_stream_proxy_srv_conf_t *pscf; | |
1115 | |
1116 u = s->upstream; | |
1117 | |
1118 c = s->connection; | |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
1119 pc = u->connected ? u->peer.connection : NULL; |
6115 | 1120 |
6436 | 1121 if (c->type == SOCK_DGRAM && (ngx_terminate || ngx_exiting)) { |
1122 | |
1123 /* socket is already closed on worker shutdown */ | |
1124 | |
1125 handler = c->log->handler; | |
1126 c->log->handler = NULL; | |
1127 | |
1128 ngx_log_error(NGX_LOG_INFO, c->log, 0, "disconnected on shutdown"); | |
1129 | |
1130 c->log->handler = handler; | |
1131 | |
1132 ngx_stream_proxy_finalize(s, NGX_OK); | |
1133 return; | |
1134 } | |
1135 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1136 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1137 |
6115 | 1138 if (from_upstream) { |
1139 src = pc; | |
1140 dst = c; | |
1141 b = &u->upstream_buf; | |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1142 limit_rate = pscf->download_rate; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1143 received = &u->received; |
6115 | 1144 |
1145 } else { | |
1146 src = c; | |
1147 dst = pc; | |
1148 b = &u->downstream_buf; | |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1149 limit_rate = pscf->upload_rate; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1150 received = &s->received; |
6115 | 1151 } |
1152 | |
1153 for ( ;; ) { | |
1154 | |
1155 if (do_write) { | |
1156 | |
1157 size = b->last - b->pos; | |
1158 | |
1159 if (size && dst && dst->write->ready) { | |
1160 | |
1161 n = dst->send(dst, b->pos, size); | |
1162 | |
6436 | 1163 if (n == NGX_AGAIN && dst->shared) { |
1164 /* cannot wait on a shared socket */ | |
1165 n = NGX_ERROR; | |
1166 } | |
1167 | |
6115 | 1168 if (n == NGX_ERROR) { |
6436 | 1169 if (c->type == SOCK_DGRAM && !from_upstream) { |
1170 ngx_stream_proxy_next_upstream(s); | |
1171 return; | |
1172 } | |
1173 | |
6115 | 1174 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1175 return; |
6115 | 1176 } |
1177 | |
1178 if (n > 0) { | |
1179 b->pos += n; | |
1180 | |
1181 if (b->pos == b->last) { | |
1182 b->pos = b->start; | |
1183 b->last = b->start; | |
1184 } | |
1185 } | |
1186 } | |
1187 } | |
1188 | |
1189 size = b->end - b->last; | |
1190 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1191 if (size && src->read->ready && !src->read->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1192 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1193 if (limit_rate) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1194 limit = (off_t) limit_rate * (ngx_time() - u->start_sec + 1) |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1195 - *received; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1196 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1197 if (limit <= 0) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1198 src->read->delayed = 1; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1199 delay = (ngx_msec_t) (- limit * 1000 / limit_rate + 1); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1200 ngx_add_timer(src->read, delay); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1201 break; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1202 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1203 |
6204
114d1f8cdcab
Stream: fixed possible integer overflow in rate limiting.
Valentin Bartenev <vbart@nginx.com>
parents:
6203
diff
changeset
|
1204 if ((off_t) size > limit) { |
6203
fdfdcad62875
Stream: fixed MSVC compilation warning.
Roman Arutyunyan <arut@nginx.com>
parents:
6202
diff
changeset
|
1205 size = (size_t) limit; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1206 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1207 } |
6115 | 1208 |
1209 n = src->recv(src, b->last, size); | |
1210 | |
1211 if (n == NGX_AGAIN || n == 0) { | |
1212 break; | |
1213 } | |
1214 | |
1215 if (n > 0) { | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1216 if (limit_rate) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1217 delay = (ngx_msec_t) (n * 1000 / limit_rate); |
6115 | 1218 |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1219 if (delay > 0) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1220 src->read->delayed = 1; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1221 ngx_add_timer(src->read, delay); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1222 } |
6115 | 1223 } |
1224 | |
6436 | 1225 if (c->type == SOCK_DGRAM && ++u->responses == pscf->responses) |
1226 { | |
1227 src->read->ready = 0; | |
1228 src->read->eof = 1; | |
1229 } | |
1230 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1231 *received += n; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1232 b->last += n; |
6115 | 1233 do_write = 1; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1234 |
6115 | 1235 continue; |
1236 } | |
1237 | |
1238 if (n == NGX_ERROR) { | |
6436 | 1239 if (c->type == SOCK_DGRAM && u->received == 0) { |
1240 ngx_stream_proxy_next_upstream(s); | |
1241 return; | |
1242 } | |
1243 | |
6115 | 1244 src->read->eof = 1; |
1245 } | |
1246 } | |
1247 | |
1248 break; | |
1249 } | |
1250 | |
1251 if (src->read->eof && (b->pos == b->last || (dst && dst->read->eof))) { | |
1252 handler = c->log->handler; | |
1253 c->log->handler = NULL; | |
1254 | |
1255 ngx_log_error(NGX_LOG_INFO, c->log, 0, | |
6461
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
1256 "%s%s disconnected" |
6115 | 1257 ", bytes from/to client:%O/%O" |
1258 ", bytes from/to upstream:%O/%O", | |
6461
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
1259 src->type == SOCK_DGRAM ? "udp " : "", |
6115 | 1260 from_upstream ? "upstream" : "client", |
1261 s->received, c->sent, u->received, pc ? pc->sent : 0); | |
1262 | |
1263 c->log->handler = handler; | |
1264 | |
1265 ngx_stream_proxy_finalize(s, NGX_OK); | |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1266 return; |
6115 | 1267 } |
1268 | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1269 flags = src->read->eof ? NGX_CLOSE_EVENT : 0; |
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1270 |
6436 | 1271 if (!src->shared && ngx_handle_read_event(src->read, flags) != NGX_OK) { |
6115 | 1272 ngx_stream_proxy_finalize(s, NGX_ERROR); |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1273 return; |
6115 | 1274 } |
1275 | |
1276 if (dst) { | |
6436 | 1277 if (!dst->shared && ngx_handle_write_event(dst->write, 0) != NGX_OK) { |
6115 | 1278 ngx_stream_proxy_finalize(s, NGX_ERROR); |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1279 return; |
6115 | 1280 } |
1281 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1282 if (!c->read->delayed && !pc->read->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1283 ngx_add_timer(c->write, pscf->timeout); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1284 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1285 } else if (c->write->timer_set) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1286 ngx_del_timer(c->write); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1287 } |
6115 | 1288 } |
1289 } | |
1290 | |
1291 | |
1292 static void | |
1293 ngx_stream_proxy_next_upstream(ngx_stream_session_t *s) | |
1294 { | |
1295 ngx_msec_t timeout; | |
1296 ngx_connection_t *pc; | |
1297 ngx_stream_upstream_t *u; | |
1298 ngx_stream_proxy_srv_conf_t *pscf; | |
1299 | |
1300 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1301 "stream proxy next upstream"); | |
1302 | |
1303 u = s->upstream; | |
1304 | |
1305 if (u->peer.sockaddr) { | |
1306 u->peer.free(&u->peer, u->peer.data, NGX_PEER_FAILED); | |
1307 u->peer.sockaddr = NULL; | |
1308 } | |
1309 | |
1310 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
1311 | |
1312 timeout = pscf->next_upstream_timeout; | |
1313 | |
1314 if (u->peer.tries == 0 | |
1315 || !pscf->next_upstream | |
1316 || (timeout && ngx_current_msec - u->peer.start_time >= timeout)) | |
1317 { | |
1318 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
1319 return; | |
1320 } | |
1321 | |
1322 pc = u->peer.connection; | |
1323 | |
1324 if (pc) { | |
1325 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1326 "close proxy upstream connection: %d", pc->fd); | |
1327 | |
1328 #if (NGX_STREAM_SSL) | |
1329 if (pc->ssl) { | |
1330 pc->ssl->no_wait_shutdown = 1; | |
1331 pc->ssl->no_send_shutdown = 1; | |
1332 | |
1333 (void) ngx_ssl_shutdown(pc); | |
1334 } | |
1335 #endif | |
1336 | |
1337 ngx_close_connection(pc); | |
1338 u->peer.connection = NULL; | |
1339 } | |
1340 | |
1341 ngx_stream_proxy_connect(s); | |
1342 } | |
1343 | |
1344 | |
1345 static void | |
1346 ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc) | |
1347 { | |
1348 ngx_connection_t *pc; | |
1349 ngx_stream_upstream_t *u; | |
1350 | |
1351 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1352 "finalize stream proxy: %i", rc); | |
1353 | |
1354 u = s->upstream; | |
1355 | |
1356 if (u == NULL) { | |
1357 goto noupstream; | |
1358 } | |
1359 | |
1360 if (u->peer.free && u->peer.sockaddr) { | |
1361 u->peer.free(&u->peer, u->peer.data, 0); | |
1362 u->peer.sockaddr = NULL; | |
1363 } | |
1364 | |
1365 pc = u->peer.connection; | |
1366 | |
1367 if (pc) { | |
1368 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1369 "close stream proxy upstream connection: %d", pc->fd); | |
1370 | |
1371 #if (NGX_STREAM_SSL) | |
1372 if (pc->ssl) { | |
1373 pc->ssl->no_wait_shutdown = 1; | |
1374 (void) ngx_ssl_shutdown(pc); | |
1375 } | |
1376 #endif | |
1377 | |
1378 ngx_close_connection(pc); | |
1379 u->peer.connection = NULL; | |
1380 } | |
1381 | |
1382 noupstream: | |
1383 | |
1384 ngx_stream_close_connection(s->connection); | |
1385 } | |
1386 | |
1387 | |
1388 static u_char * | |
1389 ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, size_t len) | |
1390 { | |
1391 u_char *p; | |
1392 ngx_connection_t *pc; | |
1393 ngx_stream_session_t *s; | |
1394 ngx_stream_upstream_t *u; | |
1395 | |
1396 s = log->data; | |
1397 | |
1398 u = s->upstream; | |
1399 | |
1400 p = buf; | |
1401 | |
1402 if (u->peer.name) { | |
1403 p = ngx_snprintf(p, len, ", upstream: \"%V\"", u->peer.name); | |
1404 len -= p - buf; | |
1405 } | |
1406 | |
1407 pc = u->peer.connection; | |
1408 | |
1409 p = ngx_snprintf(p, len, | |
1410 ", bytes from/to client:%O/%O" | |
1411 ", bytes from/to upstream:%O/%O", | |
1412 s->received, s->connection->sent, | |
1413 u->received, pc ? pc->sent : 0); | |
1414 | |
1415 return p; | |
1416 } | |
1417 | |
1418 | |
1419 static void * | |
1420 ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf) | |
1421 { | |
1422 ngx_stream_proxy_srv_conf_t *conf; | |
1423 | |
1424 conf = ngx_pcalloc(cf->pool, sizeof(ngx_stream_proxy_srv_conf_t)); | |
1425 if (conf == NULL) { | |
1426 return NULL; | |
1427 } | |
1428 | |
1429 /* | |
1430 * set by ngx_pcalloc(): | |
1431 * | |
1432 * conf->ssl_protocols = 0; | |
1433 * conf->ssl_ciphers = { 0, NULL }; | |
1434 * conf->ssl_name = { 0, NULL }; | |
1435 * conf->ssl_trusted_certificate = { 0, NULL }; | |
1436 * conf->ssl_crl = { 0, NULL }; | |
1437 * conf->ssl_certificate = { 0, NULL }; | |
1438 * conf->ssl_certificate_key = { 0, NULL }; | |
1439 * | |
1440 * conf->ssl = NULL; | |
1441 * conf->upstream = NULL; | |
1442 */ | |
1443 | |
1444 conf->connect_timeout = NGX_CONF_UNSET_MSEC; | |
1445 conf->timeout = NGX_CONF_UNSET_MSEC; | |
1446 conf->next_upstream_timeout = NGX_CONF_UNSET_MSEC; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
1447 conf->buffer_size = NGX_CONF_UNSET_SIZE; |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1448 conf->upload_rate = NGX_CONF_UNSET_SIZE; |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1449 conf->download_rate = NGX_CONF_UNSET_SIZE; |
6436 | 1450 conf->responses = NGX_CONF_UNSET_UINT; |
6115 | 1451 conf->next_upstream_tries = NGX_CONF_UNSET_UINT; |
1452 conf->next_upstream = NGX_CONF_UNSET; | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1453 conf->proxy_protocol = NGX_CONF_UNSET; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1454 conf->local = NGX_CONF_UNSET_PTR; |
6115 | 1455 |
1456 #if (NGX_STREAM_SSL) | |
1457 conf->ssl_enable = NGX_CONF_UNSET; | |
1458 conf->ssl_session_reuse = NGX_CONF_UNSET; | |
1459 conf->ssl_server_name = NGX_CONF_UNSET; | |
1460 conf->ssl_verify = NGX_CONF_UNSET; | |
1461 conf->ssl_verify_depth = NGX_CONF_UNSET_UINT; | |
1462 conf->ssl_passwords = NGX_CONF_UNSET_PTR; | |
1463 #endif | |
1464 | |
1465 return conf; | |
1466 } | |
1467 | |
1468 | |
1469 static char * | |
1470 ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, void *child) | |
1471 { | |
1472 ngx_stream_proxy_srv_conf_t *prev = parent; | |
1473 ngx_stream_proxy_srv_conf_t *conf = child; | |
1474 | |
1475 ngx_conf_merge_msec_value(conf->connect_timeout, | |
1476 prev->connect_timeout, 60000); | |
1477 | |
1478 ngx_conf_merge_msec_value(conf->timeout, | |
1479 prev->timeout, 10 * 60000); | |
1480 | |
1481 ngx_conf_merge_msec_value(conf->next_upstream_timeout, | |
1482 prev->next_upstream_timeout, 0); | |
1483 | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
1484 ngx_conf_merge_size_value(conf->buffer_size, |
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
1485 prev->buffer_size, 16384); |
6115 | 1486 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1487 ngx_conf_merge_size_value(conf->upload_rate, |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1488 prev->upload_rate, 0); |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1489 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1490 ngx_conf_merge_size_value(conf->download_rate, |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1491 prev->download_rate, 0); |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1492 |
6436 | 1493 ngx_conf_merge_uint_value(conf->responses, |
1494 prev->responses, NGX_MAX_INT32_VALUE); | |
1495 | |
6115 | 1496 ngx_conf_merge_uint_value(conf->next_upstream_tries, |
1497 prev->next_upstream_tries, 0); | |
1498 | |
1499 ngx_conf_merge_value(conf->next_upstream, prev->next_upstream, 1); | |
1500 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1501 ngx_conf_merge_value(conf->proxy_protocol, prev->proxy_protocol, 0); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1502 |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1503 ngx_conf_merge_ptr_value(conf->local, prev->local, NULL); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1504 |
6115 | 1505 #if (NGX_STREAM_SSL) |
1506 | |
1507 ngx_conf_merge_value(conf->ssl_enable, prev->ssl_enable, 0); | |
1508 | |
1509 ngx_conf_merge_value(conf->ssl_session_reuse, | |
1510 prev->ssl_session_reuse, 1); | |
1511 | |
1512 ngx_conf_merge_bitmask_value(conf->ssl_protocols, prev->ssl_protocols, | |
6157
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1513 (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1 |
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1514 |NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2)); |
6115 | 1515 |
1516 ngx_conf_merge_str_value(conf->ssl_ciphers, prev->ssl_ciphers, "DEFAULT"); | |
1517 | |
1518 ngx_conf_merge_str_value(conf->ssl_name, prev->ssl_name, ""); | |
1519 | |
1520 ngx_conf_merge_value(conf->ssl_server_name, prev->ssl_server_name, 0); | |
1521 | |
1522 ngx_conf_merge_value(conf->ssl_verify, prev->ssl_verify, 0); | |
1523 | |
1524 ngx_conf_merge_uint_value(conf->ssl_verify_depth, | |
1525 prev->ssl_verify_depth, 1); | |
1526 | |
1527 ngx_conf_merge_str_value(conf->ssl_trusted_certificate, | |
1528 prev->ssl_trusted_certificate, ""); | |
1529 | |
1530 ngx_conf_merge_str_value(conf->ssl_crl, prev->ssl_crl, ""); | |
1531 | |
1532 ngx_conf_merge_str_value(conf->ssl_certificate, | |
1533 prev->ssl_certificate, ""); | |
1534 | |
1535 ngx_conf_merge_str_value(conf->ssl_certificate_key, | |
1536 prev->ssl_certificate_key, ""); | |
1537 | |
1538 ngx_conf_merge_ptr_value(conf->ssl_passwords, prev->ssl_passwords, NULL); | |
1539 | |
1540 if (conf->ssl_enable && ngx_stream_proxy_set_ssl(cf, conf) != NGX_OK) { | |
1541 return NGX_CONF_ERROR; | |
1542 } | |
1543 | |
1544 #endif | |
1545 | |
1546 return NGX_CONF_OK; | |
1547 } | |
1548 | |
1549 | |
1550 #if (NGX_STREAM_SSL) | |
1551 | |
1552 static ngx_int_t | |
1553 ngx_stream_proxy_set_ssl(ngx_conf_t *cf, ngx_stream_proxy_srv_conf_t *pscf) | |
1554 { | |
1555 ngx_pool_cleanup_t *cln; | |
1556 | |
1557 pscf->ssl = ngx_pcalloc(cf->pool, sizeof(ngx_ssl_t)); | |
1558 if (pscf->ssl == NULL) { | |
1559 return NGX_ERROR; | |
1560 } | |
1561 | |
1562 pscf->ssl->log = cf->log; | |
1563 | |
1564 if (ngx_ssl_create(pscf->ssl, pscf->ssl_protocols, NULL) != NGX_OK) { | |
1565 return NGX_ERROR; | |
1566 } | |
1567 | |
1568 cln = ngx_pool_cleanup_add(cf->pool, 0); | |
1569 if (cln == NULL) { | |
1570 return NGX_ERROR; | |
1571 } | |
1572 | |
1573 cln->handler = ngx_ssl_cleanup_ctx; | |
1574 cln->data = pscf->ssl; | |
1575 | |
1576 if (pscf->ssl_certificate.len) { | |
1577 | |
1578 if (pscf->ssl_certificate_key.len == 0) { | |
1579 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1580 "no \"proxy_ssl_certificate_key\" is defined " | |
1581 "for certificate \"%V\"", &pscf->ssl_certificate); | |
1582 return NGX_ERROR; | |
1583 } | |
1584 | |
1585 if (ngx_ssl_certificate(cf, pscf->ssl, &pscf->ssl_certificate, | |
1586 &pscf->ssl_certificate_key, pscf->ssl_passwords) | |
1587 != NGX_OK) | |
1588 { | |
1589 return NGX_ERROR; | |
1590 } | |
1591 } | |
1592 | |
1593 if (SSL_CTX_set_cipher_list(pscf->ssl->ctx, | |
1594 (const char *) pscf->ssl_ciphers.data) | |
1595 == 0) | |
1596 { | |
1597 ngx_ssl_error(NGX_LOG_EMERG, cf->log, 0, | |
1598 "SSL_CTX_set_cipher_list(\"%V\") failed", | |
1599 &pscf->ssl_ciphers); | |
1600 return NGX_ERROR; | |
1601 } | |
1602 | |
1603 if (pscf->ssl_verify) { | |
1604 if (pscf->ssl_trusted_certificate.len == 0) { | |
1605 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1606 "no proxy_ssl_trusted_certificate for proxy_ssl_verify"); | |
1607 return NGX_ERROR; | |
1608 } | |
1609 | |
1610 if (ngx_ssl_trusted_certificate(cf, pscf->ssl, | |
1611 &pscf->ssl_trusted_certificate, | |
1612 pscf->ssl_verify_depth) | |
1613 != NGX_OK) | |
1614 { | |
1615 return NGX_ERROR; | |
1616 } | |
1617 | |
1618 if (ngx_ssl_crl(cf, pscf->ssl, &pscf->ssl_crl) != NGX_OK) { | |
1619 return NGX_ERROR; | |
1620 } | |
1621 } | |
1622 | |
1623 return NGX_OK; | |
1624 } | |
1625 | |
1626 #endif | |
1627 | |
1628 | |
1629 static char * | |
1630 ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) | |
1631 { | |
1632 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
1633 | |
1634 ngx_url_t u; | |
1635 ngx_str_t *value, *url; | |
1636 ngx_stream_core_srv_conf_t *cscf; | |
1637 | |
1638 if (pscf->upstream) { | |
1639 return "is duplicate"; | |
1640 } | |
1641 | |
1642 cscf = ngx_stream_conf_get_module_srv_conf(cf, ngx_stream_core_module); | |
1643 | |
1644 cscf->handler = ngx_stream_proxy_handler; | |
1645 | |
1646 value = cf->args->elts; | |
1647 | |
1648 url = &value[1]; | |
1649 | |
1650 ngx_memzero(&u, sizeof(ngx_url_t)); | |
1651 | |
1652 u.url = *url; | |
1653 u.no_resolve = 1; | |
1654 | |
1655 pscf->upstream = ngx_stream_upstream_add(cf, &u, 0); | |
1656 if (pscf->upstream == NULL) { | |
1657 return NGX_CONF_ERROR; | |
1658 } | |
1659 | |
1660 return NGX_CONF_OK; | |
1661 } | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1662 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1663 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1664 static char * |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1665 ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1666 { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1667 ngx_stream_proxy_srv_conf_t *pscf = conf; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1668 |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1669 ngx_int_t rc; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1670 ngx_str_t *value; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1671 ngx_stream_upstream_local_t *local; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1672 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1673 if (pscf->local != NGX_CONF_UNSET_PTR) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1674 return "is duplicate"; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1675 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1676 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1677 value = cf->args->elts; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1678 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1679 if (ngx_strcmp(value[1].data, "off") == 0) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1680 pscf->local = NULL; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1681 return NGX_CONF_OK; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1682 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1683 |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1684 local = ngx_palloc(cf->pool, sizeof(ngx_stream_upstream_local_t)); |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1685 if (local == NULL) { |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1686 return NGX_CONF_ERROR; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1687 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1688 |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1689 pscf->local = local; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1690 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1691 local->addr = ngx_palloc(cf->pool, sizeof(ngx_addr_t)); |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1692 if (local->addr == NULL) { |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1693 return NGX_CONF_ERROR; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1694 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1695 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1696 rc = ngx_parse_addr(cf->pool, local->addr, value[1].data, value[1].len); |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1697 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1698 switch (rc) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1699 case NGX_OK: |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1700 local->addr->name = value[1]; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1701 break; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1702 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1703 case NGX_DECLINED: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1704 ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1705 "invalid address \"%V\"", &value[1]); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1706 /* fall through */ |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1707 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1708 default: |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1709 return NGX_CONF_ERROR; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1710 } |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1711 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1712 return NGX_CONF_OK; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1713 } |