Mercurial > hg > nginx
annotate src/stream/ngx_stream_proxy_module.c @ 6610:d5b5866c06c4
Stream: got rid of pseudo variables.
Stream limit_conn, upstream_hash and proxy modules now use complex values.
author | Vladimir Homutov <vl@nginx.com> |
---|---|
date | Wed, 29 Jun 2016 12:46:12 +0300 |
parents | 2f41d383c9c7 |
children | 9757cffc1e2f |
rev | line source |
---|---|
6115 | 1 |
2 /* | |
3 * Copyright (C) Roman Arutyunyan | |
4 * Copyright (C) Nginx, Inc. | |
5 */ | |
6 | |
7 | |
8 #include <ngx_config.h> | |
9 #include <ngx_core.h> | |
10 #include <ngx_stream.h> | |
11 | |
12 | |
13 typedef struct { | |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
14 ngx_addr_t *addr; |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
15 ngx_stream_complex_value_t *value; |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
16 #if (NGX_HAVE_TRANSPARENT_PROXY) |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
17 ngx_uint_t transparent; /* unsigned transparent:1; */ |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
18 #endif |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
19 } ngx_stream_upstream_local_t; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
20 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
21 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
22 typedef struct { |
6115 | 23 ngx_msec_t connect_timeout; |
24 ngx_msec_t timeout; | |
25 ngx_msec_t next_upstream_timeout; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
26 size_t buffer_size; |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
27 size_t upload_rate; |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
28 size_t download_rate; |
6436 | 29 ngx_uint_t responses; |
6115 | 30 ngx_uint_t next_upstream_tries; |
31 ngx_flag_t next_upstream; | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
32 ngx_flag_t proxy_protocol; |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
33 ngx_stream_upstream_local_t *local; |
6115 | 34 |
35 #if (NGX_STREAM_SSL) | |
36 ngx_flag_t ssl_enable; | |
37 ngx_flag_t ssl_session_reuse; | |
38 ngx_uint_t ssl_protocols; | |
39 ngx_str_t ssl_ciphers; | |
40 ngx_str_t ssl_name; | |
41 ngx_flag_t ssl_server_name; | |
42 | |
43 ngx_flag_t ssl_verify; | |
44 ngx_uint_t ssl_verify_depth; | |
45 ngx_str_t ssl_trusted_certificate; | |
46 ngx_str_t ssl_crl; | |
47 ngx_str_t ssl_certificate; | |
48 ngx_str_t ssl_certificate_key; | |
49 ngx_array_t *ssl_passwords; | |
50 | |
51 ngx_ssl_t *ssl; | |
52 #endif | |
53 | |
54 ngx_stream_upstream_srv_conf_t *upstream; | |
55 } ngx_stream_proxy_srv_conf_t; | |
56 | |
57 | |
58 static void ngx_stream_proxy_handler(ngx_stream_session_t *s); | |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
59 static ngx_int_t ngx_stream_proxy_set_local(ngx_stream_session_t *s, |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
60 ngx_stream_upstream_t *u, ngx_stream_upstream_local_t *local); |
6115 | 61 static void ngx_stream_proxy_connect(ngx_stream_session_t *s); |
62 static void ngx_stream_proxy_init_upstream(ngx_stream_session_t *s); | |
63 static void ngx_stream_proxy_upstream_handler(ngx_event_t *ev); | |
64 static void ngx_stream_proxy_downstream_handler(ngx_event_t *ev); | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
65 static void ngx_stream_proxy_process_connection(ngx_event_t *ev, |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
66 ngx_uint_t from_upstream); |
6115 | 67 static void ngx_stream_proxy_connect_handler(ngx_event_t *ev); |
68 static ngx_int_t ngx_stream_proxy_test_connect(ngx_connection_t *c); | |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
69 static void ngx_stream_proxy_process(ngx_stream_session_t *s, |
6115 | 70 ngx_uint_t from_upstream, ngx_uint_t do_write); |
71 static void ngx_stream_proxy_next_upstream(ngx_stream_session_t *s); | |
72 static void ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc); | |
73 static u_char *ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, | |
74 size_t len); | |
75 | |
76 static void *ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf); | |
77 static char *ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, | |
78 void *child); | |
79 static char *ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, | |
80 void *conf); | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
81 static char *ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
82 void *conf); |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
83 static ngx_int_t ngx_stream_proxy_send_proxy_protocol(ngx_stream_session_t *s); |
6115 | 84 |
85 #if (NGX_STREAM_SSL) | |
86 | |
87 static char *ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, | |
88 ngx_command_t *cmd, void *conf); | |
89 static void ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s); | |
90 static void ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc); | |
91 static ngx_int_t ngx_stream_proxy_ssl_name(ngx_stream_session_t *s); | |
92 static ngx_int_t ngx_stream_proxy_set_ssl(ngx_conf_t *cf, | |
93 ngx_stream_proxy_srv_conf_t *pscf); | |
94 | |
95 | |
96 static ngx_conf_bitmask_t ngx_stream_proxy_ssl_protocols[] = { | |
97 { ngx_string("SSLv2"), NGX_SSL_SSLv2 }, | |
98 { ngx_string("SSLv3"), NGX_SSL_SSLv3 }, | |
99 { ngx_string("TLSv1"), NGX_SSL_TLSv1 }, | |
100 { ngx_string("TLSv1.1"), NGX_SSL_TLSv1_1 }, | |
101 { ngx_string("TLSv1.2"), NGX_SSL_TLSv1_2 }, | |
102 { ngx_null_string, 0 } | |
103 }; | |
104 | |
105 #endif | |
106 | |
107 | |
6217
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
108 static ngx_conf_deprecated_t ngx_conf_deprecated_proxy_downstream_buffer = { |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
109 ngx_conf_deprecated, "proxy_downstream_buffer", "proxy_buffer_size" |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
110 }; |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
111 |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
112 static ngx_conf_deprecated_t ngx_conf_deprecated_proxy_upstream_buffer = { |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
113 ngx_conf_deprecated, "proxy_upstream_buffer", "proxy_buffer_size" |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
114 }; |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
115 |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
116 |
6115 | 117 static ngx_command_t ngx_stream_proxy_commands[] = { |
118 | |
119 { ngx_string("proxy_pass"), | |
120 NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
121 ngx_stream_proxy_pass, | |
122 NGX_STREAM_SRV_CONF_OFFSET, | |
123 0, | |
124 NULL }, | |
125 | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
126 { ngx_string("proxy_bind"), |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
127 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE12, |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
128 ngx_stream_proxy_bind, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
129 NGX_STREAM_SRV_CONF_OFFSET, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
130 0, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
131 NULL }, |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
132 |
6115 | 133 { ngx_string("proxy_connect_timeout"), |
134 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
135 ngx_conf_set_msec_slot, | |
136 NGX_STREAM_SRV_CONF_OFFSET, | |
137 offsetof(ngx_stream_proxy_srv_conf_t, connect_timeout), | |
138 NULL }, | |
139 | |
140 { ngx_string("proxy_timeout"), | |
141 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
142 ngx_conf_set_msec_slot, | |
143 NGX_STREAM_SRV_CONF_OFFSET, | |
144 offsetof(ngx_stream_proxy_srv_conf_t, timeout), | |
145 NULL }, | |
146 | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
147 { ngx_string("proxy_buffer_size"), |
6115 | 148 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
149 ngx_conf_set_size_slot, | |
150 NGX_STREAM_SRV_CONF_OFFSET, | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
151 offsetof(ngx_stream_proxy_srv_conf_t, buffer_size), |
6115 | 152 NULL }, |
153 | |
6217
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
154 { ngx_string("proxy_downstream_buffer"), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
155 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
156 ngx_conf_set_size_slot, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
157 NGX_STREAM_SRV_CONF_OFFSET, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
158 offsetof(ngx_stream_proxy_srv_conf_t, buffer_size), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
159 &ngx_conf_deprecated_proxy_downstream_buffer }, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
160 |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
161 { ngx_string("proxy_upstream_buffer"), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
162 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
163 ngx_conf_set_size_slot, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
164 NGX_STREAM_SRV_CONF_OFFSET, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
165 offsetof(ngx_stream_proxy_srv_conf_t, buffer_size), |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
166 &ngx_conf_deprecated_proxy_upstream_buffer }, |
b544f8e0d921
Stream: deprecated proxy_downstream_buffer, proxy_upstream_buffer.
Roman Arutyunyan <arut@nginx.com>
parents:
6216
diff
changeset
|
167 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
168 { ngx_string("proxy_upload_rate"), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
169 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
170 ngx_conf_set_size_slot, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
171 NGX_STREAM_SRV_CONF_OFFSET, |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
172 offsetof(ngx_stream_proxy_srv_conf_t, upload_rate), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
173 NULL }, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
174 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
175 { ngx_string("proxy_download_rate"), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
176 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
177 ngx_conf_set_size_slot, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
178 NGX_STREAM_SRV_CONF_OFFSET, |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
179 offsetof(ngx_stream_proxy_srv_conf_t, download_rate), |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
180 NULL }, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
181 |
6436 | 182 { ngx_string("proxy_responses"), |
183 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
184 ngx_conf_set_num_slot, | |
185 NGX_STREAM_SRV_CONF_OFFSET, | |
186 offsetof(ngx_stream_proxy_srv_conf_t, responses), | |
187 NULL }, | |
188 | |
6115 | 189 { ngx_string("proxy_next_upstream"), |
190 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
191 ngx_conf_set_flag_slot, | |
192 NGX_STREAM_SRV_CONF_OFFSET, | |
193 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream), | |
194 NULL }, | |
195 | |
196 { ngx_string("proxy_next_upstream_tries"), | |
197 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
198 ngx_conf_set_num_slot, | |
199 NGX_STREAM_SRV_CONF_OFFSET, | |
200 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_tries), | |
201 NULL }, | |
202 | |
203 { ngx_string("proxy_next_upstream_timeout"), | |
204 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
205 ngx_conf_set_msec_slot, | |
206 NGX_STREAM_SRV_CONF_OFFSET, | |
207 offsetof(ngx_stream_proxy_srv_conf_t, next_upstream_timeout), | |
208 NULL }, | |
209 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
210 { ngx_string("proxy_protocol"), |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
211 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
212 ngx_conf_set_flag_slot, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
213 NGX_STREAM_SRV_CONF_OFFSET, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
214 offsetof(ngx_stream_proxy_srv_conf_t, proxy_protocol), |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
215 NULL }, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
216 |
6115 | 217 #if (NGX_STREAM_SSL) |
218 | |
219 { ngx_string("proxy_ssl"), | |
220 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
221 ngx_conf_set_flag_slot, | |
222 NGX_STREAM_SRV_CONF_OFFSET, | |
223 offsetof(ngx_stream_proxy_srv_conf_t, ssl_enable), | |
224 NULL }, | |
225 | |
226 { ngx_string("proxy_ssl_session_reuse"), | |
227 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
228 ngx_conf_set_flag_slot, | |
229 NGX_STREAM_SRV_CONF_OFFSET, | |
230 offsetof(ngx_stream_proxy_srv_conf_t, ssl_session_reuse), | |
231 NULL }, | |
232 | |
233 { ngx_string("proxy_ssl_protocols"), | |
234 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_1MORE, | |
235 ngx_conf_set_bitmask_slot, | |
236 NGX_STREAM_SRV_CONF_OFFSET, | |
237 offsetof(ngx_stream_proxy_srv_conf_t, ssl_protocols), | |
238 &ngx_stream_proxy_ssl_protocols }, | |
239 | |
240 { ngx_string("proxy_ssl_ciphers"), | |
241 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
242 ngx_conf_set_str_slot, | |
243 NGX_STREAM_SRV_CONF_OFFSET, | |
244 offsetof(ngx_stream_proxy_srv_conf_t, ssl_ciphers), | |
245 NULL }, | |
246 | |
247 { ngx_string("proxy_ssl_name"), | |
248 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
249 ngx_conf_set_str_slot, | |
250 NGX_STREAM_SRV_CONF_OFFSET, | |
251 offsetof(ngx_stream_proxy_srv_conf_t, ssl_name), | |
252 NULL }, | |
253 | |
254 { ngx_string("proxy_ssl_server_name"), | |
255 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
256 ngx_conf_set_flag_slot, | |
257 NGX_STREAM_SRV_CONF_OFFSET, | |
258 offsetof(ngx_stream_proxy_srv_conf_t, ssl_server_name), | |
259 NULL }, | |
260 | |
261 { ngx_string("proxy_ssl_verify"), | |
262 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG, | |
263 ngx_conf_set_flag_slot, | |
264 NGX_STREAM_SRV_CONF_OFFSET, | |
265 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify), | |
266 NULL }, | |
267 | |
268 { ngx_string("proxy_ssl_verify_depth"), | |
269 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
270 ngx_conf_set_num_slot, | |
271 NGX_STREAM_SRV_CONF_OFFSET, | |
272 offsetof(ngx_stream_proxy_srv_conf_t, ssl_verify_depth), | |
273 NULL }, | |
274 | |
275 { ngx_string("proxy_ssl_trusted_certificate"), | |
276 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
277 ngx_conf_set_str_slot, | |
278 NGX_STREAM_SRV_CONF_OFFSET, | |
279 offsetof(ngx_stream_proxy_srv_conf_t, ssl_trusted_certificate), | |
280 NULL }, | |
281 | |
282 { ngx_string("proxy_ssl_crl"), | |
283 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
284 ngx_conf_set_str_slot, | |
285 NGX_STREAM_SRV_CONF_OFFSET, | |
286 offsetof(ngx_stream_proxy_srv_conf_t, ssl_crl), | |
287 NULL }, | |
288 | |
289 { ngx_string("proxy_ssl_certificate"), | |
290 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
291 ngx_conf_set_str_slot, | |
292 NGX_STREAM_SRV_CONF_OFFSET, | |
293 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate), | |
294 NULL }, | |
295 | |
296 { ngx_string("proxy_ssl_certificate_key"), | |
297 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
298 ngx_conf_set_str_slot, | |
299 NGX_STREAM_SRV_CONF_OFFSET, | |
300 offsetof(ngx_stream_proxy_srv_conf_t, ssl_certificate_key), | |
301 NULL }, | |
302 | |
303 { ngx_string("proxy_ssl_password_file"), | |
304 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1, | |
305 ngx_stream_proxy_ssl_password_file, | |
306 NGX_STREAM_SRV_CONF_OFFSET, | |
307 0, | |
308 NULL }, | |
309 | |
310 #endif | |
311 | |
312 ngx_null_command | |
313 }; | |
314 | |
315 | |
316 static ngx_stream_module_t ngx_stream_proxy_module_ctx = { | |
6606
2f41d383c9c7
Stream: added preconfiguration step.
Vladimir Homutov <vl@nginx.com>
parents:
6599
diff
changeset
|
317 NULL, /* preconfiguration */ |
6174
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
318 NULL, /* postconfiguration */ |
68c106e6fa0a
Stream: added postconfiguration method to stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
6157
diff
changeset
|
319 |
6115 | 320 NULL, /* create main configuration */ |
321 NULL, /* init main configuration */ | |
322 | |
323 ngx_stream_proxy_create_srv_conf, /* create server configuration */ | |
324 ngx_stream_proxy_merge_srv_conf /* merge server configuration */ | |
325 }; | |
326 | |
327 | |
328 ngx_module_t ngx_stream_proxy_module = { | |
329 NGX_MODULE_V1, | |
330 &ngx_stream_proxy_module_ctx, /* module context */ | |
331 ngx_stream_proxy_commands, /* module directives */ | |
332 NGX_STREAM_MODULE, /* module type */ | |
333 NULL, /* init master */ | |
334 NULL, /* init module */ | |
335 NULL, /* init process */ | |
336 NULL, /* init thread */ | |
337 NULL, /* exit thread */ | |
338 NULL, /* exit process */ | |
339 NULL, /* exit master */ | |
340 NGX_MODULE_V1_PADDING | |
341 }; | |
342 | |
343 | |
344 static void | |
345 ngx_stream_proxy_handler(ngx_stream_session_t *s) | |
346 { | |
347 u_char *p; | |
348 ngx_connection_t *c; | |
349 ngx_stream_upstream_t *u; | |
350 ngx_stream_proxy_srv_conf_t *pscf; | |
351 ngx_stream_upstream_srv_conf_t *uscf; | |
352 | |
353 c = s->connection; | |
354 | |
355 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
356 | |
357 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
358 "proxy connection handler"); | |
359 | |
360 u = ngx_pcalloc(c->pool, sizeof(ngx_stream_upstream_t)); | |
361 if (u == NULL) { | |
362 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
363 return; | |
364 } | |
365 | |
366 s->upstream = u; | |
367 | |
368 s->log_handler = ngx_stream_proxy_log_error; | |
369 | |
370 u->peer.log = c->log; | |
371 u->peer.log_error = NGX_ERROR_ERR; | |
372 | |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
373 if (ngx_stream_proxy_set_local(s, u, pscf->local) != NGX_OK) { |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
374 ngx_stream_proxy_finalize(s, NGX_ERROR); |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
375 return; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
376 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
377 |
6436 | 378 u->peer.type = c->type; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
379 |
6115 | 380 uscf = pscf->upstream; |
381 | |
382 if (uscf->peer.init(s, uscf) != NGX_OK) { | |
383 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
384 return; | |
385 } | |
386 | |
387 u->peer.start_time = ngx_current_msec; | |
388 | |
389 if (pscf->next_upstream_tries | |
390 && u->peer.tries > pscf->next_upstream_tries) | |
391 { | |
392 u->peer.tries = pscf->next_upstream_tries; | |
393 } | |
394 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
395 u->proxy_protocol = pscf->proxy_protocol; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
396 u->start_sec = ngx_time(); |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
397 |
6436 | 398 c->write->handler = ngx_stream_proxy_downstream_handler; |
399 c->read->handler = ngx_stream_proxy_downstream_handler; | |
400 | |
401 if (c->type == SOCK_DGRAM) { | |
402 ngx_stream_proxy_connect(s); | |
403 return; | |
404 } | |
405 | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
406 p = ngx_pnalloc(c->pool, pscf->buffer_size); |
6115 | 407 if (p == NULL) { |
408 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
409 return; | |
410 } | |
411 | |
412 u->downstream_buf.start = p; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
413 u->downstream_buf.end = p + pscf->buffer_size; |
6115 | 414 u->downstream_buf.pos = p; |
415 u->downstream_buf.last = p; | |
416 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
417 if (u->proxy_protocol |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
418 #if (NGX_STREAM_SSL) |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
419 && pscf->ssl == NULL |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
420 #endif |
6216 | 421 && pscf->buffer_size >= NGX_PROXY_PROTOCOL_MAX_HEADER) |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
422 { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
423 /* optimization for a typical case */ |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
424 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
425 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
426 "stream proxy send PROXY protocol header"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
427 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
428 p = ngx_proxy_protocol_write(c, u->downstream_buf.last, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
429 u->downstream_buf.end); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
430 if (p == NULL) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
431 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
432 return; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
433 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
434 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
435 u->downstream_buf.last = p; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
436 u->proxy_protocol = 0; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
437 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
438 |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
439 if (c->read->ready) { |
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
440 ngx_post_event(c->read, &ngx_posted_events); |
6115 | 441 } |
442 | |
443 ngx_stream_proxy_connect(s); | |
444 } | |
445 | |
446 | |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
447 static ngx_int_t |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
448 ngx_stream_proxy_set_local(ngx_stream_session_t *s, ngx_stream_upstream_t *u, |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
449 ngx_stream_upstream_local_t *local) |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
450 { |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
451 ngx_int_t rc; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
452 ngx_str_t val; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
453 ngx_addr_t *addr; |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
454 |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
455 if (local == NULL) { |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
456 u->peer.local = NULL; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
457 return NGX_OK; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
458 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
459 |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
460 #if (NGX_HAVE_TRANSPARENT_PROXY) |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
461 u->peer.transparent = local->transparent; |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
462 #endif |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
463 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
464 if (local->value == NULL) { |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
465 u->peer.local = local->addr; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
466 return NGX_OK; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
467 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
468 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
469 if (ngx_stream_complex_value(s, local->value, &val) != NGX_OK) { |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
470 return NGX_ERROR; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
471 } |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
472 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
473 if (val.len == 0) { |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
474 return NGX_OK; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
475 } |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
476 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
477 addr = ngx_palloc(s->connection->pool, sizeof(ngx_addr_t)); |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
478 if (addr == NULL) { |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
479 return NGX_ERROR; |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
480 } |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
481 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
482 rc = ngx_parse_addr_port(s->connection->pool, addr, val.data, val.len); |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
483 if (rc == NGX_ERROR) { |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
484 return NGX_ERROR; |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
485 } |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
486 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
487 if (rc != NGX_OK) { |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
488 ngx_log_error(NGX_LOG_ERR, s->connection->log, 0, |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
489 "invalid local address \"%V\"", &val); |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
490 return NGX_OK; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
491 } |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
492 |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
493 addr->name = val; |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
494 u->peer.local = addr; |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
495 |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
496 return NGX_OK; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
497 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
498 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
499 |
6115 | 500 static void |
501 ngx_stream_proxy_connect(ngx_stream_session_t *s) | |
502 { | |
503 ngx_int_t rc; | |
504 ngx_connection_t *c, *pc; | |
505 ngx_stream_upstream_t *u; | |
506 ngx_stream_proxy_srv_conf_t *pscf; | |
507 | |
508 c = s->connection; | |
509 | |
510 c->log->action = "connecting to upstream"; | |
511 | |
512 u = s->upstream; | |
513 | |
514 rc = ngx_event_connect_peer(&u->peer); | |
515 | |
516 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, c->log, 0, "proxy connect: %i", rc); | |
517 | |
518 if (rc == NGX_ERROR) { | |
519 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
520 return; | |
521 } | |
522 | |
523 if (rc == NGX_BUSY) { | |
524 ngx_log_error(NGX_LOG_ERR, c->log, 0, "no live upstreams"); | |
525 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
526 return; | |
527 } | |
528 | |
529 if (rc == NGX_DECLINED) { | |
530 ngx_stream_proxy_next_upstream(s); | |
531 return; | |
532 } | |
533 | |
534 /* rc == NGX_OK || rc == NGX_AGAIN || rc == NGX_DONE */ | |
535 | |
536 pc = u->peer.connection; | |
537 | |
538 pc->data = s; | |
539 pc->log = c->log; | |
540 pc->pool = c->pool; | |
541 pc->read->log = c->log; | |
542 pc->write->log = c->log; | |
543 | |
544 if (rc != NGX_AGAIN) { | |
545 ngx_stream_proxy_init_upstream(s); | |
546 return; | |
547 } | |
548 | |
549 pc->read->handler = ngx_stream_proxy_connect_handler; | |
550 pc->write->handler = ngx_stream_proxy_connect_handler; | |
551 | |
6393
70e6e1f12dee
Stream: initialize variable right before using it.
Roman Arutyunyan <arut@nginx.com>
parents:
6392
diff
changeset
|
552 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
70e6e1f12dee
Stream: initialize variable right before using it.
Roman Arutyunyan <arut@nginx.com>
parents:
6392
diff
changeset
|
553 |
6115 | 554 ngx_add_timer(pc->write, pscf->connect_timeout); |
555 } | |
556 | |
557 | |
558 static void | |
559 ngx_stream_proxy_init_upstream(ngx_stream_session_t *s) | |
560 { | |
6222 | 561 int tcp_nodelay; |
6115 | 562 u_char *p; |
563 ngx_connection_t *c, *pc; | |
564 ngx_log_handler_pt handler; | |
565 ngx_stream_upstream_t *u; | |
6221
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
566 ngx_stream_core_srv_conf_t *cscf; |
6115 | 567 ngx_stream_proxy_srv_conf_t *pscf; |
568 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
569 u = s->upstream; |
6221
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
570 pc = u->peer.connection; |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
571 |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
572 cscf = ngx_stream_get_module_srv_conf(s, ngx_stream_core_module); |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
573 |
6436 | 574 if (pc->type == SOCK_STREAM |
575 && cscf->tcp_nodelay | |
576 && pc->tcp_nodelay == NGX_TCP_NODELAY_UNSET) | |
577 { | |
6221
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
578 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, pc->log, 0, "tcp_nodelay"); |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
579 |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
580 tcp_nodelay = 1; |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
581 |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
582 if (setsockopt(pc->fd, IPPROTO_TCP, TCP_NODELAY, |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
583 (const void *) &tcp_nodelay, sizeof(int)) == -1) |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
584 { |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
585 ngx_connection_error(pc, ngx_socket_errno, |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
586 "setsockopt(TCP_NODELAY) failed"); |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
587 ngx_stream_proxy_next_upstream(s); |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
588 return; |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
589 } |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
590 |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
591 pc->tcp_nodelay = NGX_TCP_NODELAY_SET; |
7565e056fad6
Stream: the "tcp_nodelay" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6217
diff
changeset
|
592 } |
6115 | 593 |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
594 if (u->proxy_protocol) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
595 if (ngx_stream_proxy_send_proxy_protocol(s) != NGX_OK) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
596 return; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
597 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
598 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
599 u->proxy_protocol = 0; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
600 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
601 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
602 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
6115 | 603 |
604 #if (NGX_STREAM_SSL) | |
6436 | 605 if (pc->type == SOCK_STREAM && pscf->ssl && pc->ssl == NULL) { |
6115 | 606 ngx_stream_proxy_ssl_init_connection(s); |
607 return; | |
608 } | |
609 #endif | |
610 | |
611 c = s->connection; | |
612 | |
613 if (c->log->log_level >= NGX_LOG_INFO) { | |
6230
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
614 ngx_str_t str; |
6115 | 615 u_char addr[NGX_SOCKADDR_STRLEN]; |
616 | |
6230
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
617 str.len = NGX_SOCKADDR_STRLEN; |
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
618 str.data = addr; |
6115 | 619 |
6230
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
620 if (ngx_connection_local_sockaddr(pc, &str, 1) == NGX_OK) { |
6115 | 621 handler = c->log->handler; |
622 c->log->handler = NULL; | |
623 | |
6461
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
624 ngx_log_error(NGX_LOG_INFO, c->log, 0, |
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
625 "%sproxy %V connected to %V", |
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
626 pc->type == SOCK_DGRAM ? "udp " : "", |
6230
2a621245f4cf
Win32: MSVC 2015 compatibility.
Maxim Dounin <mdounin@mdounin.ru>
parents:
6222
diff
changeset
|
627 &str, u->peer.name); |
6115 | 628 |
629 c->log->handler = handler; | |
630 } | |
631 } | |
632 | |
633 c->log->action = "proxying connection"; | |
634 | |
6436 | 635 if (u->upstream_buf.start == NULL) { |
636 p = ngx_pnalloc(c->pool, pscf->buffer_size); | |
637 if (p == NULL) { | |
638 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
639 return; | |
640 } | |
641 | |
642 u->upstream_buf.start = p; | |
643 u->upstream_buf.end = p + pscf->buffer_size; | |
644 u->upstream_buf.pos = p; | |
645 u->upstream_buf.last = p; | |
6115 | 646 } |
647 | |
6436 | 648 if (c->type == SOCK_DGRAM) { |
649 s->received = c->buffer->last - c->buffer->pos; | |
650 u->downstream_buf = *c->buffer; | |
651 | |
652 if (pscf->responses == 0) { | |
653 pc->read->ready = 0; | |
654 pc->read->eof = 1; | |
655 } | |
656 } | |
6115 | 657 |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
658 u->connected = 1; |
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
659 |
6115 | 660 pc->read->handler = ngx_stream_proxy_upstream_handler; |
661 pc->write->handler = ngx_stream_proxy_upstream_handler; | |
662 | |
6436 | 663 if (pc->read->ready || pc->read->eof) { |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
664 ngx_post_event(pc->read, &ngx_posted_events); |
6115 | 665 } |
666 | |
667 ngx_stream_proxy_process(s, 0, 1); | |
668 } | |
669 | |
670 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
671 static ngx_int_t |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
672 ngx_stream_proxy_send_proxy_protocol(ngx_stream_session_t *s) |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
673 { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
674 u_char *p; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
675 ssize_t n, size; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
676 ngx_connection_t *c, *pc; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
677 ngx_stream_upstream_t *u; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
678 ngx_stream_proxy_srv_conf_t *pscf; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
679 u_char buf[NGX_PROXY_PROTOCOL_MAX_HEADER]; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
680 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
681 c = s->connection; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
682 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
683 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
684 "stream proxy send PROXY protocol header"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
685 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
686 p = ngx_proxy_protocol_write(c, buf, buf + NGX_PROXY_PROTOCOL_MAX_HEADER); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
687 if (p == NULL) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
688 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
689 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
690 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
691 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
692 u = s->upstream; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
693 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
694 pc = u->peer.connection; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
695 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
696 size = p - buf; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
697 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
698 n = pc->send(pc, buf, size); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
699 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
700 if (n == NGX_AGAIN) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
701 if (ngx_handle_write_event(pc->write, 0) != NGX_OK) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
702 ngx_stream_proxy_finalize(s, NGX_ERROR); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
703 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
704 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
705 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
706 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
707 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
708 ngx_add_timer(pc->write, pscf->timeout); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
709 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
710 pc->write->handler = ngx_stream_proxy_connect_handler; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
711 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
712 return NGX_AGAIN; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
713 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
714 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
715 if (n == NGX_ERROR) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
716 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
717 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
718 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
719 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
720 if (n != size) { |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
721 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
722 /* |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
723 * PROXY protocol specification: |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
724 * The sender must always ensure that the header |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
725 * is sent at once, so that the transport layer |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
726 * maintains atomicity along the path to the receiver. |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
727 */ |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
728 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
729 ngx_log_error(NGX_LOG_ERR, c->log, 0, |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
730 "could not send PROXY protocol header at once"); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
731 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
732 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
733 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
734 return NGX_ERROR; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
735 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
736 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
737 return NGX_OK; |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
738 } |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
739 |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
740 |
6115 | 741 #if (NGX_STREAM_SSL) |
742 | |
743 static char * | |
744 ngx_stream_proxy_ssl_password_file(ngx_conf_t *cf, ngx_command_t *cmd, | |
745 void *conf) | |
746 { | |
747 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
748 | |
749 ngx_str_t *value; | |
750 | |
751 if (pscf->ssl_passwords != NGX_CONF_UNSET_PTR) { | |
752 return "is duplicate"; | |
753 } | |
754 | |
755 value = cf->args->elts; | |
756 | |
757 pscf->ssl_passwords = ngx_ssl_read_password_file(cf, &value[1]); | |
758 | |
759 if (pscf->ssl_passwords == NULL) { | |
760 return NGX_CONF_ERROR; | |
761 } | |
762 | |
763 return NGX_CONF_OK; | |
764 } | |
765 | |
766 | |
767 static void | |
768 ngx_stream_proxy_ssl_init_connection(ngx_stream_session_t *s) | |
769 { | |
770 ngx_int_t rc; | |
771 ngx_connection_t *pc; | |
772 ngx_stream_upstream_t *u; | |
773 ngx_stream_proxy_srv_conf_t *pscf; | |
774 | |
775 u = s->upstream; | |
776 | |
777 pc = u->peer.connection; | |
778 | |
779 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
780 | |
781 if (ngx_ssl_create_connection(pscf->ssl, pc, NGX_SSL_BUFFER|NGX_SSL_CLIENT) | |
782 != NGX_OK) | |
783 { | |
784 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
785 return; | |
786 } | |
787 | |
788 if (pscf->ssl_server_name || pscf->ssl_verify) { | |
789 if (ngx_stream_proxy_ssl_name(s) != NGX_OK) { | |
790 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
791 return; | |
792 } | |
793 } | |
794 | |
795 if (pscf->ssl_session_reuse) { | |
796 if (u->peer.set_session(&u->peer, u->peer.data) != NGX_OK) { | |
797 ngx_stream_proxy_finalize(s, NGX_ERROR); | |
798 return; | |
799 } | |
800 } | |
801 | |
802 s->connection->log->action = "SSL handshaking to upstream"; | |
803 | |
804 rc = ngx_ssl_handshake(pc); | |
805 | |
806 if (rc == NGX_AGAIN) { | |
807 | |
808 if (!pc->write->timer_set) { | |
809 ngx_add_timer(pc->write, pscf->connect_timeout); | |
810 } | |
811 | |
812 pc->ssl->handler = ngx_stream_proxy_ssl_handshake; | |
813 return; | |
814 } | |
815 | |
816 ngx_stream_proxy_ssl_handshake(pc); | |
817 } | |
818 | |
819 | |
820 static void | |
821 ngx_stream_proxy_ssl_handshake(ngx_connection_t *pc) | |
822 { | |
823 long rc; | |
824 ngx_stream_session_t *s; | |
825 ngx_stream_upstream_t *u; | |
826 ngx_stream_proxy_srv_conf_t *pscf; | |
827 | |
828 s = pc->data; | |
829 | |
830 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
831 | |
832 if (pc->ssl->handshaked) { | |
833 | |
834 if (pscf->ssl_verify) { | |
835 rc = SSL_get_verify_result(pc->ssl->connection); | |
836 | |
837 if (rc != X509_V_OK) { | |
838 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
839 "upstream SSL certificate verify error: (%l:%s)", | |
840 rc, X509_verify_cert_error_string(rc)); | |
841 goto failed; | |
842 } | |
843 | |
844 u = s->upstream; | |
845 | |
846 if (ngx_ssl_check_host(pc, &u->ssl_name) != NGX_OK) { | |
847 ngx_log_error(NGX_LOG_ERR, pc->log, 0, | |
848 "upstream SSL certificate does not match \"%V\"", | |
849 &u->ssl_name); | |
850 goto failed; | |
851 } | |
852 } | |
853 | |
854 if (pscf->ssl_session_reuse) { | |
855 u = s->upstream; | |
856 u->peer.save_session(&u->peer, u->peer.data); | |
857 } | |
858 | |
6258
4b4aee40c508
Stream: delete proxy connection timer after SSL handshake.
Ruslan Ermilov <ru@nginx.com>
parents:
6230
diff
changeset
|
859 if (pc->write->timer_set) { |
4b4aee40c508
Stream: delete proxy connection timer after SSL handshake.
Ruslan Ermilov <ru@nginx.com>
parents:
6230
diff
changeset
|
860 ngx_del_timer(pc->write); |
4b4aee40c508
Stream: delete proxy connection timer after SSL handshake.
Ruslan Ermilov <ru@nginx.com>
parents:
6230
diff
changeset
|
861 } |
4b4aee40c508
Stream: delete proxy connection timer after SSL handshake.
Ruslan Ermilov <ru@nginx.com>
parents:
6230
diff
changeset
|
862 |
6115 | 863 ngx_stream_proxy_init_upstream(s); |
864 | |
865 return; | |
866 } | |
867 | |
868 failed: | |
869 | |
870 ngx_stream_proxy_next_upstream(s); | |
871 } | |
872 | |
873 | |
874 static ngx_int_t | |
875 ngx_stream_proxy_ssl_name(ngx_stream_session_t *s) | |
876 { | |
877 u_char *p, *last; | |
878 ngx_str_t name; | |
879 ngx_stream_upstream_t *u; | |
880 ngx_stream_proxy_srv_conf_t *pscf; | |
881 | |
882 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
883 | |
884 u = s->upstream; | |
885 | |
886 name = pscf->ssl_name; | |
887 | |
888 if (name.len == 0) { | |
889 name = pscf->upstream->host; | |
890 } | |
891 | |
892 if (name.len == 0) { | |
893 goto done; | |
894 } | |
895 | |
896 /* | |
897 * ssl name here may contain port, strip it for compatibility | |
898 * with the http module | |
899 */ | |
900 | |
901 p = name.data; | |
902 last = name.data + name.len; | |
903 | |
904 if (*p == '[') { | |
905 p = ngx_strlchr(p, last, ']'); | |
906 | |
907 if (p == NULL) { | |
908 p = name.data; | |
909 } | |
910 } | |
911 | |
912 p = ngx_strlchr(p, last, ':'); | |
913 | |
914 if (p != NULL) { | |
915 name.len = p - name.data; | |
916 } | |
917 | |
918 if (!pscf->ssl_server_name) { | |
919 goto done; | |
920 } | |
921 | |
922 #ifdef SSL_CTRL_SET_TLSEXT_HOSTNAME | |
923 | |
924 /* as per RFC 6066, literal IPv4 and IPv6 addresses are not permitted */ | |
925 | |
926 if (name.len == 0 || *name.data == '[') { | |
927 goto done; | |
928 } | |
929 | |
930 if (ngx_inet_addr(name.data, name.len) != INADDR_NONE) { | |
931 goto done; | |
932 } | |
933 | |
934 /* | |
935 * SSL_set_tlsext_host_name() needs a null-terminated string, | |
936 * hence we explicitly null-terminate name here | |
937 */ | |
938 | |
939 p = ngx_pnalloc(s->connection->pool, name.len + 1); | |
940 if (p == NULL) { | |
941 return NGX_ERROR; | |
942 } | |
943 | |
944 (void) ngx_cpystrn(p, name.data, name.len + 1); | |
945 | |
946 name.data = p; | |
947 | |
948 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
949 "upstream SSL server name: \"%s\"", name.data); | |
950 | |
951 if (SSL_set_tlsext_host_name(u->peer.connection->ssl->connection, name.data) | |
952 == 0) | |
953 { | |
954 ngx_ssl_error(NGX_LOG_ERR, s->connection->log, 0, | |
955 "SSL_set_tlsext_host_name(\"%s\") failed", name.data); | |
956 return NGX_ERROR; | |
957 } | |
958 | |
959 #endif | |
960 | |
961 done: | |
962 | |
963 u->ssl_name = name; | |
964 | |
965 return NGX_OK; | |
966 } | |
967 | |
968 #endif | |
969 | |
970 | |
971 static void | |
972 ngx_stream_proxy_downstream_handler(ngx_event_t *ev) | |
973 { | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
974 ngx_stream_proxy_process_connection(ev, ev->write); |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
975 } |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
976 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
977 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
978 static void |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
979 ngx_stream_proxy_upstream_handler(ngx_event_t *ev) |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
980 { |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
981 ngx_stream_proxy_process_connection(ev, !ev->write); |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
982 } |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
983 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
984 |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
985 static void |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
986 ngx_stream_proxy_process_connection(ngx_event_t *ev, ngx_uint_t from_upstream) |
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
987 { |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
988 ngx_connection_t *c, *pc; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
989 ngx_stream_session_t *s; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
990 ngx_stream_upstream_t *u; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
991 ngx_stream_proxy_srv_conf_t *pscf; |
6115 | 992 |
993 c = ev->data; | |
994 s = c->data; | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
995 u = s->upstream; |
6115 | 996 |
6436 | 997 c = s->connection; |
998 pc = u->peer.connection; | |
999 | |
1000 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
1001 | |
6115 | 1002 if (ev->timedout) { |
6436 | 1003 ev->timedout = 0; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1004 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1005 if (ev->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1006 ev->delayed = 0; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1007 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1008 if (!ev->ready) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1009 if (ngx_handle_read_event(ev, 0) != NGX_OK) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1010 ngx_stream_proxy_finalize(s, NGX_ERROR); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1011 return; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1012 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1013 |
6436 | 1014 if (u->connected && !c->read->delayed && !pc->read->delayed) { |
1015 ngx_add_timer(c->write, pscf->timeout); | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1016 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1017 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1018 return; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1019 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1020 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1021 } else { |
6436 | 1022 if (s->connection->type == SOCK_DGRAM) { |
1023 if (pscf->responses == NGX_MAX_INT32_VALUE) { | |
1024 | |
1025 /* | |
1026 * successfully terminate timed out UDP session | |
1027 * with unspecified number of responses | |
1028 */ | |
1029 | |
1030 pc->read->ready = 0; | |
1031 pc->read->eof = 1; | |
1032 | |
1033 ngx_stream_proxy_process(s, 1, 0); | |
1034 return; | |
1035 } | |
1036 | |
1037 if (u->received == 0) { | |
1038 ngx_stream_proxy_next_upstream(s); | |
1039 return; | |
1040 } | |
1041 } | |
1042 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1043 ngx_connection_error(c, NGX_ETIMEDOUT, "connection timed out"); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1044 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1045 return; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1046 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1047 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1048 } else if (ev->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1049 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1050 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1051 "stream connection delayed"); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1052 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1053 if (ngx_handle_read_event(ev, 0) != NGX_OK) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1054 ngx_stream_proxy_finalize(s, NGX_ERROR); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1055 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1056 |
6115 | 1057 return; |
1058 } | |
1059 | |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
1060 if (from_upstream && !u->connected) { |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
1061 return; |
6115 | 1062 } |
1063 | |
6200
abee77018d3a
Stream: common handler for upstream and downstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6184
diff
changeset
|
1064 ngx_stream_proxy_process(s, from_upstream, ev->write); |
6115 | 1065 } |
1066 | |
1067 | |
1068 static void | |
1069 ngx_stream_proxy_connect_handler(ngx_event_t *ev) | |
1070 { | |
1071 ngx_connection_t *c; | |
1072 ngx_stream_session_t *s; | |
1073 | |
1074 c = ev->data; | |
1075 s = c->data; | |
1076 | |
1077 if (ev->timedout) { | |
1078 ngx_log_error(NGX_LOG_ERR, c->log, NGX_ETIMEDOUT, "upstream timed out"); | |
1079 ngx_stream_proxy_next_upstream(s); | |
1080 return; | |
1081 } | |
1082 | |
1083 ngx_del_timer(c->write); | |
1084 | |
1085 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, c->log, 0, | |
1086 "stream proxy connect upstream"); | |
1087 | |
1088 if (ngx_stream_proxy_test_connect(c) != NGX_OK) { | |
1089 ngx_stream_proxy_next_upstream(s); | |
1090 return; | |
1091 } | |
1092 | |
1093 ngx_stream_proxy_init_upstream(s); | |
1094 } | |
1095 | |
1096 | |
1097 static ngx_int_t | |
1098 ngx_stream_proxy_test_connect(ngx_connection_t *c) | |
1099 { | |
1100 int err; | |
1101 socklen_t len; | |
1102 | |
1103 #if (NGX_HAVE_KQUEUE) | |
1104 | |
1105 if (ngx_event_flags & NGX_USE_KQUEUE_EVENT) { | |
1106 err = c->write->kq_errno ? c->write->kq_errno : c->read->kq_errno; | |
1107 | |
1108 if (err) { | |
1109 (void) ngx_connection_error(c, err, | |
1110 "kevent() reported that connect() failed"); | |
1111 return NGX_ERROR; | |
1112 } | |
1113 | |
1114 } else | |
1115 #endif | |
1116 { | |
1117 err = 0; | |
1118 len = sizeof(int); | |
1119 | |
1120 /* | |
1121 * BSDs and Linux return 0 and set a pending error in err | |
1122 * Solaris returns -1 and sets errno | |
1123 */ | |
1124 | |
1125 if (getsockopt(c->fd, SOL_SOCKET, SO_ERROR, (void *) &err, &len) | |
1126 == -1) | |
1127 { | |
1128 err = ngx_socket_errno; | |
1129 } | |
1130 | |
1131 if (err) { | |
1132 (void) ngx_connection_error(c, err, "connect() failed"); | |
1133 return NGX_ERROR; | |
1134 } | |
1135 } | |
1136 | |
1137 return NGX_OK; | |
1138 } | |
1139 | |
1140 | |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1141 static void |
6115 | 1142 ngx_stream_proxy_process(ngx_stream_session_t *s, ngx_uint_t from_upstream, |
1143 ngx_uint_t do_write) | |
1144 { | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1145 off_t *received, limit; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1146 size_t size, limit_rate; |
6115 | 1147 ssize_t n; |
1148 ngx_buf_t *b; | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1149 ngx_uint_t flags; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1150 ngx_msec_t delay; |
6115 | 1151 ngx_connection_t *c, *pc, *src, *dst; |
1152 ngx_log_handler_pt handler; | |
1153 ngx_stream_upstream_t *u; | |
1154 ngx_stream_proxy_srv_conf_t *pscf; | |
1155 | |
1156 u = s->upstream; | |
1157 | |
1158 c = s->connection; | |
6202
6345822f0abb
Stream: upstream "connected" flag.
Roman Arutyunyan <arut@nginx.com>
parents:
6201
diff
changeset
|
1159 pc = u->connected ? u->peer.connection : NULL; |
6115 | 1160 |
6436 | 1161 if (c->type == SOCK_DGRAM && (ngx_terminate || ngx_exiting)) { |
1162 | |
1163 /* socket is already closed on worker shutdown */ | |
1164 | |
1165 handler = c->log->handler; | |
1166 c->log->handler = NULL; | |
1167 | |
1168 ngx_log_error(NGX_LOG_INFO, c->log, 0, "disconnected on shutdown"); | |
1169 | |
1170 c->log->handler = handler; | |
1171 | |
1172 ngx_stream_proxy_finalize(s, NGX_OK); | |
1173 return; | |
1174 } | |
1175 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1176 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1177 |
6115 | 1178 if (from_upstream) { |
1179 src = pc; | |
1180 dst = c; | |
1181 b = &u->upstream_buf; | |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1182 limit_rate = pscf->download_rate; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1183 received = &u->received; |
6115 | 1184 |
1185 } else { | |
1186 src = c; | |
1187 dst = pc; | |
1188 b = &u->downstream_buf; | |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1189 limit_rate = pscf->upload_rate; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1190 received = &s->received; |
6115 | 1191 } |
1192 | |
1193 for ( ;; ) { | |
1194 | |
1195 if (do_write) { | |
1196 | |
1197 size = b->last - b->pos; | |
1198 | |
1199 if (size && dst && dst->write->ready) { | |
1200 | |
1201 n = dst->send(dst, b->pos, size); | |
1202 | |
6436 | 1203 if (n == NGX_AGAIN && dst->shared) { |
1204 /* cannot wait on a shared socket */ | |
1205 n = NGX_ERROR; | |
1206 } | |
1207 | |
6115 | 1208 if (n == NGX_ERROR) { |
6436 | 1209 if (c->type == SOCK_DGRAM && !from_upstream) { |
1210 ngx_stream_proxy_next_upstream(s); | |
1211 return; | |
1212 } | |
1213 | |
6115 | 1214 ngx_stream_proxy_finalize(s, NGX_DECLINED); |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1215 return; |
6115 | 1216 } |
1217 | |
1218 if (n > 0) { | |
1219 b->pos += n; | |
1220 | |
1221 if (b->pos == b->last) { | |
1222 b->pos = b->start; | |
1223 b->last = b->start; | |
1224 } | |
1225 } | |
1226 } | |
1227 } | |
1228 | |
1229 size = b->end - b->last; | |
1230 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1231 if (size && src->read->ready && !src->read->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1232 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1233 if (limit_rate) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1234 limit = (off_t) limit_rate * (ngx_time() - u->start_sec + 1) |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1235 - *received; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1236 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1237 if (limit <= 0) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1238 src->read->delayed = 1; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1239 delay = (ngx_msec_t) (- limit * 1000 / limit_rate + 1); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1240 ngx_add_timer(src->read, delay); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1241 break; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1242 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1243 |
6204
114d1f8cdcab
Stream: fixed possible integer overflow in rate limiting.
Valentin Bartenev <vbart@nginx.com>
parents:
6203
diff
changeset
|
1244 if ((off_t) size > limit) { |
6203
fdfdcad62875
Stream: fixed MSVC compilation warning.
Roman Arutyunyan <arut@nginx.com>
parents:
6202
diff
changeset
|
1245 size = (size_t) limit; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1246 } |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1247 } |
6115 | 1248 |
1249 n = src->recv(src, b->last, size); | |
1250 | |
1251 if (n == NGX_AGAIN || n == 0) { | |
1252 break; | |
1253 } | |
1254 | |
1255 if (n > 0) { | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1256 if (limit_rate) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1257 delay = (ngx_msec_t) (n * 1000 / limit_rate); |
6115 | 1258 |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1259 if (delay > 0) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1260 src->read->delayed = 1; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1261 ngx_add_timer(src->read, delay); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1262 } |
6115 | 1263 } |
1264 | |
6436 | 1265 if (c->type == SOCK_DGRAM && ++u->responses == pscf->responses) |
1266 { | |
1267 src->read->ready = 0; | |
1268 src->read->eof = 1; | |
1269 } | |
1270 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1271 *received += n; |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1272 b->last += n; |
6115 | 1273 do_write = 1; |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1274 |
6115 | 1275 continue; |
1276 } | |
1277 | |
1278 if (n == NGX_ERROR) { | |
6436 | 1279 if (c->type == SOCK_DGRAM && u->received == 0) { |
1280 ngx_stream_proxy_next_upstream(s); | |
1281 return; | |
1282 } | |
1283 | |
6115 | 1284 src->read->eof = 1; |
1285 } | |
1286 } | |
1287 | |
1288 break; | |
1289 } | |
1290 | |
1291 if (src->read->eof && (b->pos == b->last || (dst && dst->read->eof))) { | |
1292 handler = c->log->handler; | |
1293 c->log->handler = NULL; | |
1294 | |
1295 ngx_log_error(NGX_LOG_INFO, c->log, 0, | |
6461
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
1296 "%s%s disconnected" |
6115 | 1297 ", bytes from/to client:%O/%O" |
1298 ", bytes from/to upstream:%O/%O", | |
6461
a01e315b3a78
Stream: additional logging for UDP.
Vladimir Homutov <vl@nginx.com>
parents:
6436
diff
changeset
|
1299 src->type == SOCK_DGRAM ? "udp " : "", |
6115 | 1300 from_upstream ? "upstream" : "client", |
1301 s->received, c->sent, u->received, pc ? pc->sent : 0); | |
1302 | |
1303 c->log->handler = handler; | |
1304 | |
1305 ngx_stream_proxy_finalize(s, NGX_OK); | |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1306 return; |
6115 | 1307 } |
1308 | |
6124
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1309 flags = src->read->eof ? NGX_CLOSE_EVENT : 0; |
f1f222db290b
Stream: prevent repeated event notifications after eof.
Roman Arutyunyan <arut@nginx.com>
parents:
6115
diff
changeset
|
1310 |
6436 | 1311 if (!src->shared && ngx_handle_read_event(src->read, flags) != NGX_OK) { |
6115 | 1312 ngx_stream_proxy_finalize(s, NGX_ERROR); |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1313 return; |
6115 | 1314 } |
1315 | |
1316 if (dst) { | |
6436 | 1317 if (!dst->shared && ngx_handle_write_event(dst->write, 0) != NGX_OK) { |
6115 | 1318 ngx_stream_proxy_finalize(s, NGX_ERROR); |
6435
d1c791479bbb
Stream: post first read events from client and upstream.
Roman Arutyunyan <arut@nginx.com>
parents:
6393
diff
changeset
|
1319 return; |
6115 | 1320 } |
1321 | |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1322 if (!c->read->delayed && !pc->read->delayed) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1323 ngx_add_timer(c->write, pscf->timeout); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1324 |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1325 } else if (c->write->timer_set) { |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1326 ngx_del_timer(c->write); |
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1327 } |
6115 | 1328 } |
1329 } | |
1330 | |
1331 | |
1332 static void | |
1333 ngx_stream_proxy_next_upstream(ngx_stream_session_t *s) | |
1334 { | |
1335 ngx_msec_t timeout; | |
1336 ngx_connection_t *pc; | |
1337 ngx_stream_upstream_t *u; | |
1338 ngx_stream_proxy_srv_conf_t *pscf; | |
1339 | |
1340 ngx_log_debug0(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1341 "stream proxy next upstream"); | |
1342 | |
1343 u = s->upstream; | |
1344 | |
1345 if (u->peer.sockaddr) { | |
1346 u->peer.free(&u->peer, u->peer.data, NGX_PEER_FAILED); | |
1347 u->peer.sockaddr = NULL; | |
1348 } | |
1349 | |
1350 pscf = ngx_stream_get_module_srv_conf(s, ngx_stream_proxy_module); | |
1351 | |
1352 timeout = pscf->next_upstream_timeout; | |
1353 | |
1354 if (u->peer.tries == 0 | |
1355 || !pscf->next_upstream | |
1356 || (timeout && ngx_current_msec - u->peer.start_time >= timeout)) | |
1357 { | |
1358 ngx_stream_proxy_finalize(s, NGX_DECLINED); | |
1359 return; | |
1360 } | |
1361 | |
1362 pc = u->peer.connection; | |
1363 | |
1364 if (pc) { | |
1365 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1366 "close proxy upstream connection: %d", pc->fd); | |
1367 | |
1368 #if (NGX_STREAM_SSL) | |
1369 if (pc->ssl) { | |
1370 pc->ssl->no_wait_shutdown = 1; | |
1371 pc->ssl->no_send_shutdown = 1; | |
1372 | |
1373 (void) ngx_ssl_shutdown(pc); | |
1374 } | |
1375 #endif | |
1376 | |
1377 ngx_close_connection(pc); | |
1378 u->peer.connection = NULL; | |
1379 } | |
1380 | |
1381 ngx_stream_proxy_connect(s); | |
1382 } | |
1383 | |
1384 | |
1385 static void | |
1386 ngx_stream_proxy_finalize(ngx_stream_session_t *s, ngx_int_t rc) | |
1387 { | |
1388 ngx_connection_t *pc; | |
1389 ngx_stream_upstream_t *u; | |
1390 | |
1391 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1392 "finalize stream proxy: %i", rc); | |
1393 | |
1394 u = s->upstream; | |
1395 | |
1396 if (u == NULL) { | |
1397 goto noupstream; | |
1398 } | |
1399 | |
1400 if (u->peer.free && u->peer.sockaddr) { | |
1401 u->peer.free(&u->peer, u->peer.data, 0); | |
1402 u->peer.sockaddr = NULL; | |
1403 } | |
1404 | |
1405 pc = u->peer.connection; | |
1406 | |
1407 if (pc) { | |
1408 ngx_log_debug1(NGX_LOG_DEBUG_STREAM, s->connection->log, 0, | |
1409 "close stream proxy upstream connection: %d", pc->fd); | |
1410 | |
1411 #if (NGX_STREAM_SSL) | |
1412 if (pc->ssl) { | |
1413 pc->ssl->no_wait_shutdown = 1; | |
1414 (void) ngx_ssl_shutdown(pc); | |
1415 } | |
1416 #endif | |
1417 | |
1418 ngx_close_connection(pc); | |
1419 u->peer.connection = NULL; | |
1420 } | |
1421 | |
1422 noupstream: | |
1423 | |
1424 ngx_stream_close_connection(s->connection); | |
1425 } | |
1426 | |
1427 | |
1428 static u_char * | |
1429 ngx_stream_proxy_log_error(ngx_log_t *log, u_char *buf, size_t len) | |
1430 { | |
1431 u_char *p; | |
1432 ngx_connection_t *pc; | |
1433 ngx_stream_session_t *s; | |
1434 ngx_stream_upstream_t *u; | |
1435 | |
1436 s = log->data; | |
1437 | |
1438 u = s->upstream; | |
1439 | |
1440 p = buf; | |
1441 | |
1442 if (u->peer.name) { | |
1443 p = ngx_snprintf(p, len, ", upstream: \"%V\"", u->peer.name); | |
1444 len -= p - buf; | |
1445 } | |
1446 | |
1447 pc = u->peer.connection; | |
1448 | |
1449 p = ngx_snprintf(p, len, | |
1450 ", bytes from/to client:%O/%O" | |
1451 ", bytes from/to upstream:%O/%O", | |
1452 s->received, s->connection->sent, | |
1453 u->received, pc ? pc->sent : 0); | |
1454 | |
1455 return p; | |
1456 } | |
1457 | |
1458 | |
1459 static void * | |
1460 ngx_stream_proxy_create_srv_conf(ngx_conf_t *cf) | |
1461 { | |
1462 ngx_stream_proxy_srv_conf_t *conf; | |
1463 | |
1464 conf = ngx_pcalloc(cf->pool, sizeof(ngx_stream_proxy_srv_conf_t)); | |
1465 if (conf == NULL) { | |
1466 return NULL; | |
1467 } | |
1468 | |
1469 /* | |
1470 * set by ngx_pcalloc(): | |
1471 * | |
1472 * conf->ssl_protocols = 0; | |
1473 * conf->ssl_ciphers = { 0, NULL }; | |
1474 * conf->ssl_name = { 0, NULL }; | |
1475 * conf->ssl_trusted_certificate = { 0, NULL }; | |
1476 * conf->ssl_crl = { 0, NULL }; | |
1477 * conf->ssl_certificate = { 0, NULL }; | |
1478 * conf->ssl_certificate_key = { 0, NULL }; | |
1479 * | |
1480 * conf->ssl = NULL; | |
1481 * conf->upstream = NULL; | |
1482 */ | |
1483 | |
1484 conf->connect_timeout = NGX_CONF_UNSET_MSEC; | |
1485 conf->timeout = NGX_CONF_UNSET_MSEC; | |
1486 conf->next_upstream_timeout = NGX_CONF_UNSET_MSEC; | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
1487 conf->buffer_size = NGX_CONF_UNSET_SIZE; |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1488 conf->upload_rate = NGX_CONF_UNSET_SIZE; |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1489 conf->download_rate = NGX_CONF_UNSET_SIZE; |
6436 | 1490 conf->responses = NGX_CONF_UNSET_UINT; |
6115 | 1491 conf->next_upstream_tries = NGX_CONF_UNSET_UINT; |
1492 conf->next_upstream = NGX_CONF_UNSET; | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1493 conf->proxy_protocol = NGX_CONF_UNSET; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1494 conf->local = NGX_CONF_UNSET_PTR; |
6115 | 1495 |
1496 #if (NGX_STREAM_SSL) | |
1497 conf->ssl_enable = NGX_CONF_UNSET; | |
1498 conf->ssl_session_reuse = NGX_CONF_UNSET; | |
1499 conf->ssl_server_name = NGX_CONF_UNSET; | |
1500 conf->ssl_verify = NGX_CONF_UNSET; | |
1501 conf->ssl_verify_depth = NGX_CONF_UNSET_UINT; | |
1502 conf->ssl_passwords = NGX_CONF_UNSET_PTR; | |
1503 #endif | |
1504 | |
1505 return conf; | |
1506 } | |
1507 | |
1508 | |
1509 static char * | |
1510 ngx_stream_proxy_merge_srv_conf(ngx_conf_t *cf, void *parent, void *child) | |
1511 { | |
1512 ngx_stream_proxy_srv_conf_t *prev = parent; | |
1513 ngx_stream_proxy_srv_conf_t *conf = child; | |
1514 | |
1515 ngx_conf_merge_msec_value(conf->connect_timeout, | |
1516 prev->connect_timeout, 60000); | |
1517 | |
1518 ngx_conf_merge_msec_value(conf->timeout, | |
1519 prev->timeout, 10 * 60000); | |
1520 | |
1521 ngx_conf_merge_msec_value(conf->next_upstream_timeout, | |
1522 prev->next_upstream_timeout, 0); | |
1523 | |
6215
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
1524 ngx_conf_merge_size_value(conf->buffer_size, |
8ee6a08ea3eb
Stream: added proxy_buffer_size to set the size of data buffers.
Roman Arutyunyan <arut@nginx.com>
parents:
6208
diff
changeset
|
1525 prev->buffer_size, 16384); |
6115 | 1526 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1527 ngx_conf_merge_size_value(conf->upload_rate, |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1528 prev->upload_rate, 0); |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1529 |
6208
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1530 ngx_conf_merge_size_value(conf->download_rate, |
7a14a0d754ad
Stream: renamed rate limiting directives.
Roman Arutyunyan <arut@nginx.com>
parents:
6204
diff
changeset
|
1531 prev->download_rate, 0); |
6201
24488e6db782
Stream: upstream and downstream limit rates.
Roman Arutyunyan <arut@nginx.com>
parents:
6200
diff
changeset
|
1532 |
6436 | 1533 ngx_conf_merge_uint_value(conf->responses, |
1534 prev->responses, NGX_MAX_INT32_VALUE); | |
1535 | |
6115 | 1536 ngx_conf_merge_uint_value(conf->next_upstream_tries, |
1537 prev->next_upstream_tries, 0); | |
1538 | |
1539 ngx_conf_merge_value(conf->next_upstream, prev->next_upstream, 1); | |
1540 | |
6184
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1541 ngx_conf_merge_value(conf->proxy_protocol, prev->proxy_protocol, 0); |
fa663739e115
Stream: client-side PROXY protocol.
Roman Arutyunyan <arut@nginx.com>
parents:
6183
diff
changeset
|
1542 |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1543 ngx_conf_merge_ptr_value(conf->local, prev->local, NULL); |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1544 |
6115 | 1545 #if (NGX_STREAM_SSL) |
1546 | |
1547 ngx_conf_merge_value(conf->ssl_enable, prev->ssl_enable, 0); | |
1548 | |
1549 ngx_conf_merge_value(conf->ssl_session_reuse, | |
1550 prev->ssl_session_reuse, 1); | |
1551 | |
1552 ngx_conf_merge_bitmask_value(conf->ssl_protocols, prev->ssl_protocols, | |
6157
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1553 (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1 |
b2899e7d0ef8
Disabled SSLv3 by default (ticket #653).
Maxim Dounin <mdounin@mdounin.ru>
parents:
6124
diff
changeset
|
1554 |NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2)); |
6115 | 1555 |
1556 ngx_conf_merge_str_value(conf->ssl_ciphers, prev->ssl_ciphers, "DEFAULT"); | |
1557 | |
1558 ngx_conf_merge_str_value(conf->ssl_name, prev->ssl_name, ""); | |
1559 | |
1560 ngx_conf_merge_value(conf->ssl_server_name, prev->ssl_server_name, 0); | |
1561 | |
1562 ngx_conf_merge_value(conf->ssl_verify, prev->ssl_verify, 0); | |
1563 | |
1564 ngx_conf_merge_uint_value(conf->ssl_verify_depth, | |
1565 prev->ssl_verify_depth, 1); | |
1566 | |
1567 ngx_conf_merge_str_value(conf->ssl_trusted_certificate, | |
1568 prev->ssl_trusted_certificate, ""); | |
1569 | |
1570 ngx_conf_merge_str_value(conf->ssl_crl, prev->ssl_crl, ""); | |
1571 | |
1572 ngx_conf_merge_str_value(conf->ssl_certificate, | |
1573 prev->ssl_certificate, ""); | |
1574 | |
1575 ngx_conf_merge_str_value(conf->ssl_certificate_key, | |
1576 prev->ssl_certificate_key, ""); | |
1577 | |
1578 ngx_conf_merge_ptr_value(conf->ssl_passwords, prev->ssl_passwords, NULL); | |
1579 | |
1580 if (conf->ssl_enable && ngx_stream_proxy_set_ssl(cf, conf) != NGX_OK) { | |
1581 return NGX_CONF_ERROR; | |
1582 } | |
1583 | |
1584 #endif | |
1585 | |
1586 return NGX_CONF_OK; | |
1587 } | |
1588 | |
1589 | |
1590 #if (NGX_STREAM_SSL) | |
1591 | |
1592 static ngx_int_t | |
1593 ngx_stream_proxy_set_ssl(ngx_conf_t *cf, ngx_stream_proxy_srv_conf_t *pscf) | |
1594 { | |
1595 ngx_pool_cleanup_t *cln; | |
1596 | |
1597 pscf->ssl = ngx_pcalloc(cf->pool, sizeof(ngx_ssl_t)); | |
1598 if (pscf->ssl == NULL) { | |
1599 return NGX_ERROR; | |
1600 } | |
1601 | |
1602 pscf->ssl->log = cf->log; | |
1603 | |
1604 if (ngx_ssl_create(pscf->ssl, pscf->ssl_protocols, NULL) != NGX_OK) { | |
1605 return NGX_ERROR; | |
1606 } | |
1607 | |
1608 cln = ngx_pool_cleanup_add(cf->pool, 0); | |
1609 if (cln == NULL) { | |
1610 return NGX_ERROR; | |
1611 } | |
1612 | |
1613 cln->handler = ngx_ssl_cleanup_ctx; | |
1614 cln->data = pscf->ssl; | |
1615 | |
1616 if (pscf->ssl_certificate.len) { | |
1617 | |
1618 if (pscf->ssl_certificate_key.len == 0) { | |
1619 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1620 "no \"proxy_ssl_certificate_key\" is defined " | |
1621 "for certificate \"%V\"", &pscf->ssl_certificate); | |
1622 return NGX_ERROR; | |
1623 } | |
1624 | |
1625 if (ngx_ssl_certificate(cf, pscf->ssl, &pscf->ssl_certificate, | |
1626 &pscf->ssl_certificate_key, pscf->ssl_passwords) | |
1627 != NGX_OK) | |
1628 { | |
1629 return NGX_ERROR; | |
1630 } | |
1631 } | |
1632 | |
6591
04d8d1f85649
SSL: ngx_ssl_ciphers() to set list of ciphers.
Tim Taubert <tim@timtaubert.de>
parents:
6530
diff
changeset
|
1633 if (ngx_ssl_ciphers(cf, pscf->ssl, &pscf->ssl_ciphers, 0) != NGX_OK) { |
6115 | 1634 return NGX_ERROR; |
1635 } | |
1636 | |
1637 if (pscf->ssl_verify) { | |
1638 if (pscf->ssl_trusted_certificate.len == 0) { | |
1639 ngx_log_error(NGX_LOG_EMERG, cf->log, 0, | |
1640 "no proxy_ssl_trusted_certificate for proxy_ssl_verify"); | |
1641 return NGX_ERROR; | |
1642 } | |
1643 | |
1644 if (ngx_ssl_trusted_certificate(cf, pscf->ssl, | |
1645 &pscf->ssl_trusted_certificate, | |
1646 pscf->ssl_verify_depth) | |
1647 != NGX_OK) | |
1648 { | |
1649 return NGX_ERROR; | |
1650 } | |
1651 | |
1652 if (ngx_ssl_crl(cf, pscf->ssl, &pscf->ssl_crl) != NGX_OK) { | |
1653 return NGX_ERROR; | |
1654 } | |
1655 } | |
1656 | |
1657 return NGX_OK; | |
1658 } | |
1659 | |
1660 #endif | |
1661 | |
1662 | |
1663 static char * | |
1664 ngx_stream_proxy_pass(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) | |
1665 { | |
1666 ngx_stream_proxy_srv_conf_t *pscf = conf; | |
1667 | |
1668 ngx_url_t u; | |
1669 ngx_str_t *value, *url; | |
1670 ngx_stream_core_srv_conf_t *cscf; | |
1671 | |
1672 if (pscf->upstream) { | |
1673 return "is duplicate"; | |
1674 } | |
1675 | |
1676 cscf = ngx_stream_conf_get_module_srv_conf(cf, ngx_stream_core_module); | |
1677 | |
1678 cscf->handler = ngx_stream_proxy_handler; | |
1679 | |
1680 value = cf->args->elts; | |
1681 | |
1682 url = &value[1]; | |
1683 | |
1684 ngx_memzero(&u, sizeof(ngx_url_t)); | |
1685 | |
1686 u.url = *url; | |
1687 u.no_resolve = 1; | |
1688 | |
1689 pscf->upstream = ngx_stream_upstream_add(cf, &u, 0); | |
1690 if (pscf->upstream == NULL) { | |
1691 return NGX_CONF_ERROR; | |
1692 } | |
1693 | |
1694 return NGX_CONF_OK; | |
1695 } | |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1696 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1697 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1698 static char * |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1699 ngx_stream_proxy_bind(ngx_conf_t *cf, ngx_command_t *cmd, void *conf) |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1700 { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1701 ngx_stream_proxy_srv_conf_t *pscf = conf; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1702 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1703 ngx_int_t rc; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1704 ngx_str_t *value; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1705 ngx_stream_complex_value_t cv; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1706 ngx_stream_upstream_local_t *local; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1707 ngx_stream_compile_complex_value_t ccv; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1708 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1709 if (pscf->local != NGX_CONF_UNSET_PTR) { |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1710 return "is duplicate"; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1711 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1712 |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1713 value = cf->args->elts; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1714 |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1715 if (cf->args->nelts == 2 && ngx_strcmp(value[1].data, "off") == 0) { |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1716 pscf->local = NULL; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1717 return NGX_CONF_OK; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1718 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1719 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1720 ngx_memzero(&ccv, sizeof(ngx_stream_compile_complex_value_t)); |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1721 |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1722 ccv.cf = cf; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1723 ccv.value = &value[1]; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1724 ccv.complex_value = &cv; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1725 |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1726 if (ngx_stream_compile_complex_value(&ccv) != NGX_OK) { |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1727 return NGX_CONF_ERROR; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1728 } |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1729 |
6598
4a724d6006ee
Stream: use ngx_pcalloc() in ngx_stream_proxy_bind().
Roman Arutyunyan <arut@nginx.com>
parents:
6595
diff
changeset
|
1730 local = ngx_pcalloc(cf->pool, sizeof(ngx_stream_upstream_local_t)); |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1731 if (local == NULL) { |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1732 return NGX_CONF_ERROR; |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1733 } |
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1734 |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1735 pscf->local = local; |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1736 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1737 if (cv.lengths) { |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1738 local->value = ngx_palloc(cf->pool, sizeof(ngx_stream_complex_value_t)); |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1739 if (local->value == NULL) { |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1740 return NGX_CONF_ERROR; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1741 } |
6595
0c98c4092440
Stream: support for $remote_port in proxy_bind.
Roman Arutyunyan <arut@nginx.com>
parents:
6594
diff
changeset
|
1742 |
6610
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1743 *local->value = cv; |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1744 |
d5b5866c06c4
Stream: got rid of pseudo variables.
Vladimir Homutov <vl@nginx.com>
parents:
6606
diff
changeset
|
1745 } else { |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1746 local->addr = ngx_palloc(cf->pool, sizeof(ngx_addr_t)); |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1747 if (local->addr == NULL) { |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1748 return NGX_CONF_ERROR; |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1749 } |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1750 |
6594
3c87b82b17d4
Upstream: support for port in proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6593
diff
changeset
|
1751 rc = ngx_parse_addr_port(cf->pool, local->addr, value[1].data, |
3c87b82b17d4
Upstream: support for port in proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6593
diff
changeset
|
1752 value[1].len); |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1753 |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1754 switch (rc) { |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1755 case NGX_OK: |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1756 local->addr->name = value[1]; |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1757 break; |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1758 |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1759 case NGX_DECLINED: |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1760 ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1761 "invalid address \"%V\"", &value[1]); |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1762 /* fall through */ |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1763 |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1764 default: |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1765 return NGX_CONF_ERROR; |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1766 } |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1767 } |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1768 |
6530
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1769 if (cf->args->nelts > 2) { |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1770 if (ngx_strcmp(value[2].data, "transparent") == 0) { |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1771 #if (NGX_HAVE_TRANSPARENT_PROXY) |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1772 local->transparent = 1; |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1773 #else |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1774 ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1775 "transparent proxying is not supported " |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1776 "on this platform, ignored"); |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1777 #endif |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1778 } else { |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1779 ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1780 "invalid parameter \"%V\"", &value[2]); |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1781 return NGX_CONF_ERROR; |
1d0e03db9f8e
Upstream: the "transparent" parameter of proxy_bind and friends.
Roman Arutyunyan <arut@nginx.com>
parents:
6529
diff
changeset
|
1782 } |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1783 } |
6529
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1784 |
cb8177ca0990
Stream: prepared proxy_bind to accept parameters.
Roman Arutyunyan <arut@nginx.com>
parents:
6461
diff
changeset
|
1785 return NGX_CONF_OK; |
6183
4dcffe43a7ea
Stream: the "proxy_bind" directive.
Vladimir Homutov <vl@nginx.com>
parents:
6174
diff
changeset
|
1786 } |