mirror of
https://github.com/curl/curl
synced 2026-08-25 12:32:35 -04:00
Use separate dns cache entries for addresses (A+AAAA) and HTTPS-RR results. That makes also "negative" results independent of each other. Dns cache entries, once in use, can no longer be modified safely, as concurrent use would require each access then to be done under lock. By using separate entries, we can update a HTTPS entry without needing to duplicate an existing address entry for the same host+port. Connection filters can now ask for DNS resolves. This works at any time during connection setup and while connect is going on. `Curl_conn_dns_add_addr_resolve()` and `Curl_conn_dns_add_https_resolve()` are used for that. They check if the resolve is already ongoing, can be added to a resolve not started yet or, as last resort, create a new filter instance and add it to the connection (it's easier to add more filters than making the same filter handle multiple resolves. Since DNS filters are removed once the connection is established, there is no later penalty). HTTPS-RR queries are added by the `HTTPS-CONNECT`, `SSL` and `QUIC` filters. The latter will only do that when ECH is configured and supported. That means we trigger HTTPS-RR queries only when the results matter. Add test_22_06 for ALPN influenced via HTTPS-RR when tunneling through a proxy. This did not work before. Adjust test2100 to use https: as the previous http: URL no longer triggers HTTPS-RR resolves. Closes #22216
97 lines
3.2 KiB
C
97 lines
3.2 KiB
C
#ifndef HEADER_CURL_HTTPSRR_H
|
|
#define HEADER_CURL_HTTPSRR_H
|
|
/***************************************************************************
|
|
* _ _ ____ _
|
|
* Project ___| | | | _ \| |
|
|
* / __| | | | |_) | |
|
|
* | (__| |_| | _ <| |___
|
|
* \___|\___/|_| \_\_____|
|
|
*
|
|
* Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
|
|
*
|
|
* This software is licensed as described in the file COPYING, which
|
|
* you should have received as part of this distribution. The terms
|
|
* are also available at https://curl.se/docs/copyright.html.
|
|
*
|
|
* You may opt to use, copy, modify, merge, publish, distribute and/or sell
|
|
* copies of the Software, and permit persons to whom the Software is
|
|
* furnished to do so, under the terms of the COPYING file.
|
|
*
|
|
* This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
|
|
* KIND, either express or implied.
|
|
*
|
|
* SPDX-License-Identifier: curl
|
|
*
|
|
***************************************************************************/
|
|
#include "curl_setup.h"
|
|
|
|
#ifdef USE_ARES
|
|
#include <ares.h>
|
|
#endif
|
|
|
|
#ifdef USE_HTTPSRR
|
|
|
|
#define CURL_MAXLEN_HOST_NAME 253
|
|
#define MAX_HTTPSRR_ALPNS 4
|
|
|
|
struct Curl_easy;
|
|
struct dynbuf;
|
|
|
|
struct Curl_https_rrinfo {
|
|
/*
|
|
* Fields from HTTPS RR. The only mandatory fields are priority and target.
|
|
* See https://datatracker.ietf.org/doc/html/rfc9460#section-14.3.2
|
|
*/
|
|
char *target;
|
|
unsigned char *ipv4hints; /* keytag = 4 */
|
|
size_t ipv4hints_len;
|
|
unsigned char *echconfiglist; /* keytag = 5 */
|
|
size_t echconfiglist_len;
|
|
unsigned char *ipv6hints; /* keytag = 6 */
|
|
size_t ipv6hints_len;
|
|
unsigned char alpns[MAX_HTTPSRR_ALPNS]; /* keytag = 1 */
|
|
/* store parsed alpnid entries in the array, end with ALPN_none */
|
|
uint16_t port;
|
|
uint16_t priority;
|
|
BIT(no_def_alpn); /* keytag = 2 */
|
|
BIT(mandatory); /* keytag = 0 */
|
|
BIT(port_set); /* port value has been assigned */
|
|
};
|
|
|
|
CURLcode Curl_httpsrr_set(struct Curl_https_rrinfo *rr,
|
|
uint16_t rrkey, const uint8_t *val, size_t vlen);
|
|
|
|
void Curl_httpsrr_destroy(struct Curl_https_rrinfo *rrinfo);
|
|
|
|
/* TRUE if the record is applicable to the transfer and its connection. */
|
|
bool Curl_httpsrr_applicable(struct Curl_easy *data,
|
|
const struct Curl_https_rrinfo *rr);
|
|
|
|
/*
|
|
* Code points for DNS wire format SvcParams as per RFC 9460
|
|
*/
|
|
#define HTTPS_RR_CODE_MANDATORY 0x00
|
|
#define HTTPS_RR_CODE_ALPN 0x01
|
|
#define HTTPS_RR_CODE_NO_DEF_ALPN 0x02
|
|
#define HTTPS_RR_CODE_PORT 0x03
|
|
#define HTTPS_RR_CODE_IPV4 0x04
|
|
#define HTTPS_RR_CODE_ECH 0x05
|
|
#define HTTPS_RR_CODE_IPV6 0x06
|
|
|
|
#ifdef USE_ARES
|
|
CURLcode Curl_httpsrr_from_ares(const ares_dns_record_t *dnsrec,
|
|
struct Curl_https_rrinfo **phinfo);
|
|
#endif /* USE_ARES */
|
|
|
|
#ifdef CURLVERBOSE
|
|
CURLcode Curl_httpsrr_print(struct dynbuf *tmp,
|
|
struct Curl_https_rrinfo *rr);
|
|
void Curl_httpsrr_trace(struct Curl_easy *data,
|
|
struct Curl_https_rrinfo *rr);
|
|
#else
|
|
#define Curl_httpsrr_trace(a, b) Curl_nop_stmt
|
|
#endif
|
|
|
|
#endif /* USE_HTTPSRR */
|
|
|
|
#endif /* HEADER_CURL_HTTPSRR_H */
|