http2.c 86 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794
  1. /***************************************************************************
  2. * _ _ ____ _
  3. * Project ___| | | | _ \| |
  4. * / __| | | | |_) | |
  5. * | (__| |_| | _ <| |___
  6. * \___|\___/|_| \_\_____|
  7. *
  8. * Copyright (C) Daniel Stenberg, <[email protected]>, et al.
  9. *
  10. * This software is licensed as described in the file COPYING, which
  11. * you should have received as part of this distribution. The terms
  12. * are also available at https://curl.se/docs/copyright.html.
  13. *
  14. * You may opt to use, copy, modify, merge, publish, distribute and/or sell
  15. * copies of the Software, and permit persons to whom the Software is
  16. * furnished to do so, under the terms of the COPYING file.
  17. *
  18. * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
  19. * KIND, either express or implied.
  20. *
  21. * SPDX-License-Identifier: curl
  22. *
  23. ***************************************************************************/
  24. #include "curl_setup.h"
  25. #ifdef USE_NGHTTP2
  26. #include <stdint.h>
  27. #include <nghttp2/nghttp2.h>
  28. #include "urldata.h"
  29. #include "bufq.h"
  30. #include "http1.h"
  31. #include "http2.h"
  32. #include "http.h"
  33. #include "sendf.h"
  34. #include "select.h"
  35. #include "curl_base64.h"
  36. #include "strcase.h"
  37. #include "multiif.h"
  38. #include "url.h"
  39. #include "urlapi-int.h"
  40. #include "cfilters.h"
  41. #include "connect.h"
  42. #include "rand.h"
  43. #include "strtoofft.h"
  44. #include "strdup.h"
  45. #include "transfer.h"
  46. #include "dynbuf.h"
  47. #include "headers.h"
  48. /* The last 3 #include files should be in this order */
  49. #include "curl_printf.h"
  50. #include "curl_memory.h"
  51. #include "memdebug.h"
  52. #if (NGHTTP2_VERSION_NUM < 0x010c00)
  53. #error too old nghttp2 version, upgrade!
  54. #endif
  55. #ifdef CURL_DISABLE_VERBOSE_STRINGS
  56. #define nghttp2_session_callbacks_set_error_callback(x,y)
  57. #endif
  58. #if (NGHTTP2_VERSION_NUM >= 0x010c00)
  59. #define NGHTTP2_HAS_SET_LOCAL_WINDOW_SIZE 1
  60. #endif
  61. /* buffer dimensioning:
  62. * use 16K as chunk size, as that fits H2 DATA frames well */
  63. #define H2_CHUNK_SIZE (16 * 1024)
  64. /* this is how much we want "in flight" for a stream */
  65. #define H2_STREAM_WINDOW_SIZE (10 * 1024 * 1024)
  66. /* on receiving from TLS, we prep for holding a full stream window */
  67. #define H2_NW_RECV_CHUNKS (H2_STREAM_WINDOW_SIZE / H2_CHUNK_SIZE)
  68. /* on send into TLS, we just want to accumulate small frames */
  69. #define H2_NW_SEND_CHUNKS 1
  70. /* stream recv/send chunks are a result of window / chunk sizes */
  71. #define H2_STREAM_RECV_CHUNKS (H2_STREAM_WINDOW_SIZE / H2_CHUNK_SIZE)
  72. /* keep smaller stream upload buffer (default h2 window size) to have
  73. * our progress bars and "upload done" reporting closer to reality */
  74. #define H2_STREAM_SEND_CHUNKS ((64 * 1024) / H2_CHUNK_SIZE)
  75. /* spare chunks we keep for a full window */
  76. #define H2_STREAM_POOL_SPARES (H2_STREAM_WINDOW_SIZE / H2_CHUNK_SIZE)
  77. /* We need to accommodate the max number of streams with their window
  78. * sizes on the overall connection. Streams might become PAUSED which
  79. * will block their received QUOTA in the connection window. And if we
  80. * run out of space, the server is blocked from sending us any data.
  81. * See #10988 for an issue with this. */
  82. #define HTTP2_HUGE_WINDOW_SIZE (100 * H2_STREAM_WINDOW_SIZE)
  83. #define H2_SETTINGS_IV_LEN 3
  84. #define H2_BINSETTINGS_LEN 80
  85. static int populate_settings(nghttp2_settings_entry *iv,
  86. struct Curl_easy *data)
  87. {
  88. iv[0].settings_id = NGHTTP2_SETTINGS_MAX_CONCURRENT_STREAMS;
  89. iv[0].value = Curl_multi_max_concurrent_streams(data->multi);
  90. iv[1].settings_id = NGHTTP2_SETTINGS_INITIAL_WINDOW_SIZE;
  91. iv[1].value = H2_STREAM_WINDOW_SIZE;
  92. iv[2].settings_id = NGHTTP2_SETTINGS_ENABLE_PUSH;
  93. iv[2].value = data->multi->push_cb != NULL;
  94. return 3;
  95. }
  96. static ssize_t populate_binsettings(uint8_t *binsettings,
  97. struct Curl_easy *data)
  98. {
  99. nghttp2_settings_entry iv[H2_SETTINGS_IV_LEN];
  100. int ivlen;
  101. ivlen = populate_settings(iv, data);
  102. /* this returns number of bytes it wrote or a negative number on error. */
  103. return nghttp2_pack_settings_payload(binsettings, H2_BINSETTINGS_LEN,
  104. iv, ivlen);
  105. }
  106. struct cf_h2_ctx {
  107. nghttp2_session *h2;
  108. /* The easy handle used in the current filter call, cleared at return */
  109. struct cf_call_data call_data;
  110. struct bufq inbufq; /* network input */
  111. struct bufq outbufq; /* network output */
  112. struct bufc_pool stream_bufcp; /* spares for stream buffers */
  113. size_t drain_total; /* sum of all stream's UrlState drain */
  114. uint32_t max_concurrent_streams;
  115. int32_t goaway_error;
  116. int32_t last_stream_id;
  117. BIT(conn_closed);
  118. BIT(goaway);
  119. BIT(enable_push);
  120. BIT(nw_out_blocked);
  121. };
  122. /* How to access `call_data` from a cf_h2 filter */
  123. #undef CF_CTX_CALL_DATA
  124. #define CF_CTX_CALL_DATA(cf) \
  125. ((struct cf_h2_ctx *)(cf)->ctx)->call_data
  126. static void cf_h2_ctx_clear(struct cf_h2_ctx *ctx)
  127. {
  128. struct cf_call_data save = ctx->call_data;
  129. if(ctx->h2) {
  130. nghttp2_session_del(ctx->h2);
  131. }
  132. Curl_bufq_free(&ctx->inbufq);
  133. Curl_bufq_free(&ctx->outbufq);
  134. Curl_bufcp_free(&ctx->stream_bufcp);
  135. memset(ctx, 0, sizeof(*ctx));
  136. ctx->call_data = save;
  137. }
  138. static void cf_h2_ctx_free(struct cf_h2_ctx *ctx)
  139. {
  140. if(ctx) {
  141. cf_h2_ctx_clear(ctx);
  142. free(ctx);
  143. }
  144. }
  145. static CURLcode h2_progress_egress(struct Curl_cfilter *cf,
  146. struct Curl_easy *data);
  147. /**
  148. * All about the H2 internals of a stream
  149. */
  150. struct h2_stream_ctx {
  151. struct bufq recvbuf; /* response buffer */
  152. struct bufq sendbuf; /* request buffer */
  153. struct h1_req_parser h1; /* parsing the request */
  154. struct dynhds resp_trailers; /* response trailer fields */
  155. size_t resp_hds_len; /* amount of response header bytes in recvbuf */
  156. size_t upload_blocked_len;
  157. curl_off_t upload_left; /* number of request bytes left to upload */
  158. curl_off_t nrcvd_data; /* number of DATA bytes received */
  159. char **push_headers; /* allocated array */
  160. size_t push_headers_used; /* number of entries filled in */
  161. size_t push_headers_alloc; /* number of entries allocated */
  162. int status_code; /* HTTP response status code */
  163. uint32_t error; /* stream error code */
  164. uint32_t local_window_size; /* the local recv window size */
  165. int32_t id; /* HTTP/2 protocol identifier for stream */
  166. BIT(resp_hds_complete); /* we have a complete, final response */
  167. BIT(closed); /* TRUE on stream close */
  168. BIT(reset); /* TRUE on stream reset */
  169. BIT(close_handled); /* TRUE if stream closure is handled by libcurl */
  170. BIT(bodystarted);
  171. BIT(send_closed); /* transfer is done sending, we might have still
  172. buffered data in stream->sendbuf to upload. */
  173. };
  174. #define H2_STREAM_CTX(d) ((struct h2_stream_ctx *)(((d) && \
  175. (d)->req.p.http)? \
  176. ((struct HTTP *)(d)->req.p.http)->h2_ctx \
  177. : NULL))
  178. #define H2_STREAM_LCTX(d) ((struct HTTP *)(d)->req.p.http)->h2_ctx
  179. #define H2_STREAM_ID(d) (H2_STREAM_CTX(d)? \
  180. H2_STREAM_CTX(d)->id : -2)
  181. /*
  182. * Mark this transfer to get "drained".
  183. */
  184. static void drain_stream(struct Curl_cfilter *cf,
  185. struct Curl_easy *data,
  186. struct h2_stream_ctx *stream)
  187. {
  188. unsigned char bits;
  189. (void)cf;
  190. bits = CURL_CSELECT_IN;
  191. if(!stream->send_closed &&
  192. (stream->upload_left || stream->upload_blocked_len))
  193. bits |= CURL_CSELECT_OUT;
  194. if(data->state.select_bits != bits) {
  195. CURL_TRC_CF(data, cf, "[%d] DRAIN select_bits=%x",
  196. stream->id, bits);
  197. data->state.select_bits = bits;
  198. Curl_expire(data, 0, EXPIRE_RUN_NOW);
  199. }
  200. }
  201. static CURLcode http2_data_setup(struct Curl_cfilter *cf,
  202. struct Curl_easy *data,
  203. struct h2_stream_ctx **pstream)
  204. {
  205. struct cf_h2_ctx *ctx = cf->ctx;
  206. struct h2_stream_ctx *stream;
  207. (void)cf;
  208. DEBUGASSERT(data);
  209. if(!data->req.p.http) {
  210. failf(data, "initialization failure, transfer not http initialized");
  211. return CURLE_FAILED_INIT;
  212. }
  213. stream = H2_STREAM_CTX(data);
  214. if(stream) {
  215. *pstream = stream;
  216. return CURLE_OK;
  217. }
  218. stream = calloc(1, sizeof(*stream));
  219. if(!stream)
  220. return CURLE_OUT_OF_MEMORY;
  221. stream->id = -1;
  222. Curl_bufq_initp(&stream->sendbuf, &ctx->stream_bufcp,
  223. H2_STREAM_SEND_CHUNKS, BUFQ_OPT_NONE);
  224. Curl_h1_req_parse_init(&stream->h1, H1_PARSE_DEFAULT_MAX_LINE_LEN);
  225. Curl_dynhds_init(&stream->resp_trailers, 0, DYN_HTTP_REQUEST);
  226. stream->resp_hds_len = 0;
  227. stream->bodystarted = FALSE;
  228. stream->status_code = -1;
  229. stream->closed = FALSE;
  230. stream->close_handled = FALSE;
  231. stream->error = NGHTTP2_NO_ERROR;
  232. stream->local_window_size = H2_STREAM_WINDOW_SIZE;
  233. stream->upload_left = 0;
  234. stream->nrcvd_data = 0;
  235. H2_STREAM_LCTX(data) = stream;
  236. *pstream = stream;
  237. return CURLE_OK;
  238. }
  239. static void free_push_headers(struct h2_stream_ctx *stream)
  240. {
  241. size_t i;
  242. for(i = 0; i<stream->push_headers_used; i++)
  243. free(stream->push_headers[i]);
  244. Curl_safefree(stream->push_headers);
  245. stream->push_headers_used = 0;
  246. }
  247. static void http2_data_done(struct Curl_cfilter *cf, struct Curl_easy *data)
  248. {
  249. struct cf_h2_ctx *ctx = cf->ctx;
  250. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  251. DEBUGASSERT(ctx);
  252. if(!stream)
  253. return;
  254. if(ctx->h2) {
  255. bool flush_egress = FALSE;
  256. /* returns error if stream not known, which is fine here */
  257. (void)nghttp2_session_set_stream_user_data(ctx->h2, stream->id, NULL);
  258. if(!stream->closed && stream->id > 0) {
  259. /* RST_STREAM */
  260. CURL_TRC_CF(data, cf, "[%d] premature DATA_DONE, RST stream",
  261. stream->id);
  262. stream->closed = TRUE;
  263. stream->reset = TRUE;
  264. stream->send_closed = TRUE;
  265. nghttp2_submit_rst_stream(ctx->h2, NGHTTP2_FLAG_NONE,
  266. stream->id, NGHTTP2_STREAM_CLOSED);
  267. flush_egress = TRUE;
  268. }
  269. if(flush_egress)
  270. nghttp2_session_send(ctx->h2);
  271. }
  272. Curl_bufq_free(&stream->sendbuf);
  273. Curl_h1_req_parse_free(&stream->h1);
  274. Curl_dynhds_free(&stream->resp_trailers);
  275. free_push_headers(stream);
  276. free(stream);
  277. H2_STREAM_LCTX(data) = NULL;
  278. }
  279. static int h2_client_new(struct Curl_cfilter *cf,
  280. nghttp2_session_callbacks *cbs)
  281. {
  282. struct cf_h2_ctx *ctx = cf->ctx;
  283. nghttp2_option *o;
  284. int rc = nghttp2_option_new(&o);
  285. if(rc)
  286. return rc;
  287. /* We handle window updates ourself to enforce buffer limits */
  288. nghttp2_option_set_no_auto_window_update(o, 1);
  289. #if NGHTTP2_VERSION_NUM >= 0x013200
  290. /* with 1.50.0 */
  291. /* turn off RFC 9113 leading and trailing white spaces validation against
  292. HTTP field value. */
  293. nghttp2_option_set_no_rfc9113_leading_and_trailing_ws_validation(o, 1);
  294. #endif
  295. rc = nghttp2_session_client_new2(&ctx->h2, cbs, cf, o);
  296. nghttp2_option_del(o);
  297. return rc;
  298. }
  299. static ssize_t nw_in_reader(void *reader_ctx,
  300. unsigned char *buf, size_t buflen,
  301. CURLcode *err)
  302. {
  303. struct Curl_cfilter *cf = reader_ctx;
  304. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  305. return Curl_conn_cf_recv(cf->next, data, (char *)buf, buflen, err);
  306. }
  307. static ssize_t nw_out_writer(void *writer_ctx,
  308. const unsigned char *buf, size_t buflen,
  309. CURLcode *err)
  310. {
  311. struct Curl_cfilter *cf = writer_ctx;
  312. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  313. if(data) {
  314. ssize_t nwritten = Curl_conn_cf_send(cf->next, data,
  315. (const char *)buf, buflen, err);
  316. if(nwritten > 0)
  317. CURL_TRC_CF(data, cf, "[0] egress: wrote %zd bytes", nwritten);
  318. return nwritten;
  319. }
  320. return 0;
  321. }
  322. static ssize_t send_callback(nghttp2_session *h2,
  323. const uint8_t *mem, size_t length, int flags,
  324. void *userp);
  325. static int on_frame_recv(nghttp2_session *session, const nghttp2_frame *frame,
  326. void *userp);
  327. #ifndef CURL_DISABLE_VERBOSE_STRINGS
  328. static int on_frame_send(nghttp2_session *session, const nghttp2_frame *frame,
  329. void *userp);
  330. #endif
  331. static int on_data_chunk_recv(nghttp2_session *session, uint8_t flags,
  332. int32_t stream_id,
  333. const uint8_t *mem, size_t len, void *userp);
  334. static int on_stream_close(nghttp2_session *session, int32_t stream_id,
  335. uint32_t error_code, void *userp);
  336. static int on_begin_headers(nghttp2_session *session,
  337. const nghttp2_frame *frame, void *userp);
  338. static int on_header(nghttp2_session *session, const nghttp2_frame *frame,
  339. const uint8_t *name, size_t namelen,
  340. const uint8_t *value, size_t valuelen,
  341. uint8_t flags,
  342. void *userp);
  343. static int error_callback(nghttp2_session *session, const char *msg,
  344. size_t len, void *userp);
  345. /*
  346. * Initialize the cfilter context
  347. */
  348. static CURLcode cf_h2_ctx_init(struct Curl_cfilter *cf,
  349. struct Curl_easy *data,
  350. bool via_h1_upgrade)
  351. {
  352. struct cf_h2_ctx *ctx = cf->ctx;
  353. struct h2_stream_ctx *stream;
  354. CURLcode result = CURLE_OUT_OF_MEMORY;
  355. int rc;
  356. nghttp2_session_callbacks *cbs = NULL;
  357. DEBUGASSERT(!ctx->h2);
  358. Curl_bufcp_init(&ctx->stream_bufcp, H2_CHUNK_SIZE, H2_STREAM_POOL_SPARES);
  359. Curl_bufq_initp(&ctx->inbufq, &ctx->stream_bufcp, H2_NW_RECV_CHUNKS, 0);
  360. Curl_bufq_initp(&ctx->outbufq, &ctx->stream_bufcp, H2_NW_SEND_CHUNKS, 0);
  361. ctx->last_stream_id = 2147483647;
  362. rc = nghttp2_session_callbacks_new(&cbs);
  363. if(rc) {
  364. failf(data, "Couldn't initialize nghttp2 callbacks");
  365. goto out;
  366. }
  367. nghttp2_session_callbacks_set_send_callback(cbs, send_callback);
  368. nghttp2_session_callbacks_set_on_frame_recv_callback(cbs, on_frame_recv);
  369. #ifndef CURL_DISABLE_VERBOSE_STRINGS
  370. nghttp2_session_callbacks_set_on_frame_send_callback(cbs, on_frame_send);
  371. #endif
  372. nghttp2_session_callbacks_set_on_data_chunk_recv_callback(
  373. cbs, on_data_chunk_recv);
  374. nghttp2_session_callbacks_set_on_stream_close_callback(cbs, on_stream_close);
  375. nghttp2_session_callbacks_set_on_begin_headers_callback(
  376. cbs, on_begin_headers);
  377. nghttp2_session_callbacks_set_on_header_callback(cbs, on_header);
  378. nghttp2_session_callbacks_set_error_callback(cbs, error_callback);
  379. /* The nghttp2 session is not yet setup, do it */
  380. rc = h2_client_new(cf, cbs);
  381. if(rc) {
  382. failf(data, "Couldn't initialize nghttp2");
  383. goto out;
  384. }
  385. ctx->max_concurrent_streams = DEFAULT_MAX_CONCURRENT_STREAMS;
  386. if(via_h1_upgrade) {
  387. /* HTTP/1.1 Upgrade issued. H2 Settings have already been submitted
  388. * in the H1 request and we upgrade from there. This stream
  389. * is opened implicitly as #1. */
  390. uint8_t binsettings[H2_BINSETTINGS_LEN];
  391. ssize_t binlen; /* length of the binsettings data */
  392. binlen = populate_binsettings(binsettings, data);
  393. if(binlen <= 0) {
  394. failf(data, "nghttp2 unexpectedly failed on pack_settings_payload");
  395. result = CURLE_FAILED_INIT;
  396. goto out;
  397. }
  398. result = http2_data_setup(cf, data, &stream);
  399. if(result)
  400. goto out;
  401. DEBUGASSERT(stream);
  402. stream->id = 1;
  403. /* queue SETTINGS frame (again) */
  404. rc = nghttp2_session_upgrade2(ctx->h2, binsettings, binlen,
  405. data->state.httpreq == HTTPREQ_HEAD,
  406. NULL);
  407. if(rc) {
  408. failf(data, "nghttp2_session_upgrade2() failed: %s(%d)",
  409. nghttp2_strerror(rc), rc);
  410. result = CURLE_HTTP2;
  411. goto out;
  412. }
  413. rc = nghttp2_session_set_stream_user_data(ctx->h2, stream->id,
  414. data);
  415. if(rc) {
  416. infof(data, "http/2: failed to set user_data for stream %u",
  417. stream->id);
  418. DEBUGASSERT(0);
  419. }
  420. CURL_TRC_CF(data, cf, "created session via Upgrade");
  421. }
  422. else {
  423. nghttp2_settings_entry iv[H2_SETTINGS_IV_LEN];
  424. int ivlen;
  425. ivlen = populate_settings(iv, data);
  426. rc = nghttp2_submit_settings(ctx->h2, NGHTTP2_FLAG_NONE,
  427. iv, ivlen);
  428. if(rc) {
  429. failf(data, "nghttp2_submit_settings() failed: %s(%d)",
  430. nghttp2_strerror(rc), rc);
  431. result = CURLE_HTTP2;
  432. goto out;
  433. }
  434. }
  435. rc = nghttp2_session_set_local_window_size(ctx->h2, NGHTTP2_FLAG_NONE, 0,
  436. HTTP2_HUGE_WINDOW_SIZE);
  437. if(rc) {
  438. failf(data, "nghttp2_session_set_local_window_size() failed: %s(%d)",
  439. nghttp2_strerror(rc), rc);
  440. result = CURLE_HTTP2;
  441. goto out;
  442. }
  443. /* all set, traffic will be send on connect */
  444. result = CURLE_OK;
  445. CURL_TRC_CF(data, cf, "[0] created h2 session%s",
  446. via_h1_upgrade? " (via h1 upgrade)" : "");
  447. out:
  448. if(cbs)
  449. nghttp2_session_callbacks_del(cbs);
  450. return result;
  451. }
  452. /*
  453. * Returns nonzero if current HTTP/2 session should be closed.
  454. */
  455. static int should_close_session(struct cf_h2_ctx *ctx)
  456. {
  457. return ctx->drain_total == 0 && !nghttp2_session_want_read(ctx->h2) &&
  458. !nghttp2_session_want_write(ctx->h2);
  459. }
  460. /*
  461. * Processes pending input left in network input buffer.
  462. * This function returns 0 if it succeeds, or -1 and error code will
  463. * be assigned to *err.
  464. */
  465. static int h2_process_pending_input(struct Curl_cfilter *cf,
  466. struct Curl_easy *data,
  467. CURLcode *err)
  468. {
  469. struct cf_h2_ctx *ctx = cf->ctx;
  470. const unsigned char *buf;
  471. size_t blen;
  472. ssize_t rv;
  473. while(Curl_bufq_peek(&ctx->inbufq, &buf, &blen)) {
  474. rv = nghttp2_session_mem_recv(ctx->h2, (const uint8_t *)buf, blen);
  475. if(rv < 0) {
  476. failf(data,
  477. "process_pending_input: nghttp2_session_mem_recv() returned "
  478. "%zd:%s", rv, nghttp2_strerror((int)rv));
  479. *err = CURLE_RECV_ERROR;
  480. return -1;
  481. }
  482. Curl_bufq_skip(&ctx->inbufq, (size_t)rv);
  483. if(Curl_bufq_is_empty(&ctx->inbufq)) {
  484. break;
  485. }
  486. else {
  487. CURL_TRC_CF(data, cf, "process_pending_input: %zu bytes left "
  488. "in connection buffer", Curl_bufq_len(&ctx->inbufq));
  489. }
  490. }
  491. if(nghttp2_session_check_request_allowed(ctx->h2) == 0) {
  492. /* No more requests are allowed in the current session, so
  493. the connection may not be reused. This is set when a
  494. GOAWAY frame has been received or when the limit of stream
  495. identifiers has been reached. */
  496. connclose(cf->conn, "http/2: No new requests allowed");
  497. }
  498. return 0;
  499. }
  500. /*
  501. * The server may send us data at any point (e.g. PING frames). Therefore,
  502. * we cannot assume that an HTTP/2 socket is dead just because it is readable.
  503. *
  504. * Check the lower filters first and, if successful, peek at the socket
  505. * and distinguish between closed and data.
  506. */
  507. static bool http2_connisalive(struct Curl_cfilter *cf, struct Curl_easy *data,
  508. bool *input_pending)
  509. {
  510. struct cf_h2_ctx *ctx = cf->ctx;
  511. bool alive = TRUE;
  512. *input_pending = FALSE;
  513. if(!cf->next || !cf->next->cft->is_alive(cf->next, data, input_pending))
  514. return FALSE;
  515. if(*input_pending) {
  516. /* This happens before we've sent off a request and the connection is
  517. not in use by any other transfer, there shouldn't be any data here,
  518. only "protocol frames" */
  519. CURLcode result;
  520. ssize_t nread = -1;
  521. *input_pending = FALSE;
  522. nread = Curl_bufq_slurp(&ctx->inbufq, nw_in_reader, cf, &result);
  523. if(nread != -1) {
  524. CURL_TRC_CF(data, cf, "%zd bytes stray data read before trying "
  525. "h2 connection", nread);
  526. if(h2_process_pending_input(cf, data, &result) < 0)
  527. /* immediate error, considered dead */
  528. alive = FALSE;
  529. else {
  530. alive = !should_close_session(ctx);
  531. }
  532. }
  533. else if(result != CURLE_AGAIN) {
  534. /* the read failed so let's say this is dead anyway */
  535. alive = FALSE;
  536. }
  537. }
  538. return alive;
  539. }
  540. static CURLcode http2_send_ping(struct Curl_cfilter *cf,
  541. struct Curl_easy *data)
  542. {
  543. struct cf_h2_ctx *ctx = cf->ctx;
  544. int rc;
  545. rc = nghttp2_submit_ping(ctx->h2, 0, ZERO_NULL);
  546. if(rc) {
  547. failf(data, "nghttp2_submit_ping() failed: %s(%d)",
  548. nghttp2_strerror(rc), rc);
  549. return CURLE_HTTP2;
  550. }
  551. rc = nghttp2_session_send(ctx->h2);
  552. if(rc) {
  553. failf(data, "nghttp2_session_send() failed: %s(%d)",
  554. nghttp2_strerror(rc), rc);
  555. return CURLE_SEND_ERROR;
  556. }
  557. return CURLE_OK;
  558. }
  559. /*
  560. * Store nghttp2 version info in this buffer.
  561. */
  562. void Curl_http2_ver(char *p, size_t len)
  563. {
  564. nghttp2_info *h2 = nghttp2_version(0);
  565. (void)msnprintf(p, len, "nghttp2/%s", h2->version_str);
  566. }
  567. static CURLcode nw_out_flush(struct Curl_cfilter *cf,
  568. struct Curl_easy *data)
  569. {
  570. struct cf_h2_ctx *ctx = cf->ctx;
  571. ssize_t nwritten;
  572. CURLcode result;
  573. (void)data;
  574. if(Curl_bufq_is_empty(&ctx->outbufq))
  575. return CURLE_OK;
  576. nwritten = Curl_bufq_pass(&ctx->outbufq, nw_out_writer, cf, &result);
  577. if(nwritten < 0) {
  578. if(result == CURLE_AGAIN) {
  579. CURL_TRC_CF(data, cf, "flush nw send buffer(%zu) -> EAGAIN",
  580. Curl_bufq_len(&ctx->outbufq));
  581. ctx->nw_out_blocked = 1;
  582. }
  583. return result;
  584. }
  585. return Curl_bufq_is_empty(&ctx->outbufq)? CURLE_OK: CURLE_AGAIN;
  586. }
  587. /*
  588. * The implementation of nghttp2_send_callback type. Here we write |data| with
  589. * size |length| to the network and return the number of bytes actually
  590. * written. See the documentation of nghttp2_send_callback for the details.
  591. */
  592. static ssize_t send_callback(nghttp2_session *h2,
  593. const uint8_t *buf, size_t blen, int flags,
  594. void *userp)
  595. {
  596. struct Curl_cfilter *cf = userp;
  597. struct cf_h2_ctx *ctx = cf->ctx;
  598. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  599. ssize_t nwritten;
  600. CURLcode result = CURLE_OK;
  601. (void)h2;
  602. (void)flags;
  603. DEBUGASSERT(data);
  604. nwritten = Curl_bufq_write_pass(&ctx->outbufq, buf, blen,
  605. nw_out_writer, cf, &result);
  606. if(nwritten < 0) {
  607. if(result == CURLE_AGAIN) {
  608. ctx->nw_out_blocked = 1;
  609. return NGHTTP2_ERR_WOULDBLOCK;
  610. }
  611. failf(data, "Failed sending HTTP2 data");
  612. return NGHTTP2_ERR_CALLBACK_FAILURE;
  613. }
  614. if(!nwritten) {
  615. ctx->nw_out_blocked = 1;
  616. return NGHTTP2_ERR_WOULDBLOCK;
  617. }
  618. return nwritten;
  619. }
  620. /* We pass a pointer to this struct in the push callback, but the contents of
  621. the struct are hidden from the user. */
  622. struct curl_pushheaders {
  623. struct Curl_easy *data;
  624. const nghttp2_push_promise *frame;
  625. };
  626. /*
  627. * push header access function. Only to be used from within the push callback
  628. */
  629. char *curl_pushheader_bynum(struct curl_pushheaders *h, size_t num)
  630. {
  631. /* Verify that we got a good easy handle in the push header struct, mostly to
  632. detect rubbish input fast(er). */
  633. if(!h || !GOOD_EASY_HANDLE(h->data))
  634. return NULL;
  635. else {
  636. struct h2_stream_ctx *stream = H2_STREAM_CTX(h->data);
  637. if(stream && num < stream->push_headers_used)
  638. return stream->push_headers[num];
  639. }
  640. return NULL;
  641. }
  642. /*
  643. * push header access function. Only to be used from within the push callback
  644. */
  645. char *curl_pushheader_byname(struct curl_pushheaders *h, const char *header)
  646. {
  647. struct h2_stream_ctx *stream;
  648. size_t len;
  649. size_t i;
  650. /* Verify that we got a good easy handle in the push header struct,
  651. mostly to detect rubbish input fast(er). Also empty header name
  652. is just a rubbish too. We have to allow ":" at the beginning of
  653. the header, but header == ":" must be rejected. If we have ':' in
  654. the middle of header, it could be matched in middle of the value,
  655. this is because we do prefix match.*/
  656. if(!h || !GOOD_EASY_HANDLE(h->data) || !header || !header[0] ||
  657. !strcmp(header, ":") || strchr(header + 1, ':'))
  658. return NULL;
  659. stream = H2_STREAM_CTX(h->data);
  660. if(!stream)
  661. return NULL;
  662. len = strlen(header);
  663. for(i = 0; i<stream->push_headers_used; i++) {
  664. if(!strncmp(header, stream->push_headers[i], len)) {
  665. /* sub-match, make sure that it is followed by a colon */
  666. if(stream->push_headers[i][len] != ':')
  667. continue;
  668. return &stream->push_headers[i][len + 1];
  669. }
  670. }
  671. return NULL;
  672. }
  673. static struct Curl_easy *h2_duphandle(struct Curl_cfilter *cf,
  674. struct Curl_easy *data)
  675. {
  676. struct Curl_easy *second = curl_easy_duphandle(data);
  677. if(second) {
  678. /* setup the request struct */
  679. struct HTTP *http = calloc(1, sizeof(struct HTTP));
  680. if(!http) {
  681. (void)Curl_close(&second);
  682. }
  683. else {
  684. struct h2_stream_ctx *second_stream;
  685. second->req.p.http = http;
  686. http2_data_setup(cf, second, &second_stream);
  687. second->state.priority.weight = data->state.priority.weight;
  688. }
  689. }
  690. return second;
  691. }
  692. static int set_transfer_url(struct Curl_easy *data,
  693. struct curl_pushheaders *hp)
  694. {
  695. const char *v;
  696. CURLUcode uc;
  697. char *url = NULL;
  698. int rc = 0;
  699. CURLU *u = curl_url();
  700. if(!u)
  701. return 5;
  702. v = curl_pushheader_byname(hp, HTTP_PSEUDO_SCHEME);
  703. if(v) {
  704. uc = curl_url_set(u, CURLUPART_SCHEME, v, 0);
  705. if(uc) {
  706. rc = 1;
  707. goto fail;
  708. }
  709. }
  710. v = curl_pushheader_byname(hp, HTTP_PSEUDO_AUTHORITY);
  711. if(v) {
  712. uc = Curl_url_set_authority(u, v, CURLU_DISALLOW_USER);
  713. if(uc) {
  714. rc = 2;
  715. goto fail;
  716. }
  717. }
  718. v = curl_pushheader_byname(hp, HTTP_PSEUDO_PATH);
  719. if(v) {
  720. uc = curl_url_set(u, CURLUPART_PATH, v, 0);
  721. if(uc) {
  722. rc = 3;
  723. goto fail;
  724. }
  725. }
  726. uc = curl_url_get(u, CURLUPART_URL, &url, 0);
  727. if(uc)
  728. rc = 4;
  729. fail:
  730. curl_url_cleanup(u);
  731. if(rc)
  732. return rc;
  733. if(data->state.url_alloc)
  734. free(data->state.url);
  735. data->state.url_alloc = TRUE;
  736. data->state.url = url;
  737. return 0;
  738. }
  739. static void discard_newhandle(struct Curl_cfilter *cf,
  740. struct Curl_easy *newhandle)
  741. {
  742. if(newhandle->req.p.http) {
  743. http2_data_done(cf, newhandle);
  744. }
  745. (void)Curl_close(&newhandle);
  746. }
  747. static int push_promise(struct Curl_cfilter *cf,
  748. struct Curl_easy *data,
  749. const nghttp2_push_promise *frame)
  750. {
  751. struct cf_h2_ctx *ctx = cf->ctx;
  752. int rv; /* one of the CURL_PUSH_* defines */
  753. CURL_TRC_CF(data, cf, "[%d] PUSH_PROMISE received",
  754. frame->promised_stream_id);
  755. if(data->multi->push_cb) {
  756. struct h2_stream_ctx *stream;
  757. struct h2_stream_ctx *newstream;
  758. struct curl_pushheaders heads;
  759. CURLMcode rc;
  760. CURLcode result;
  761. /* clone the parent */
  762. struct Curl_easy *newhandle = h2_duphandle(cf, data);
  763. if(!newhandle) {
  764. infof(data, "failed to duplicate handle");
  765. rv = CURL_PUSH_DENY; /* FAIL HARD */
  766. goto fail;
  767. }
  768. heads.data = data;
  769. heads.frame = frame;
  770. /* ask the application */
  771. CURL_TRC_CF(data, cf, "Got PUSH_PROMISE, ask application");
  772. stream = H2_STREAM_CTX(data);
  773. if(!stream) {
  774. failf(data, "Internal NULL stream");
  775. discard_newhandle(cf, newhandle);
  776. rv = CURL_PUSH_DENY;
  777. goto fail;
  778. }
  779. rv = set_transfer_url(newhandle, &heads);
  780. if(rv) {
  781. discard_newhandle(cf, newhandle);
  782. rv = CURL_PUSH_DENY;
  783. goto fail;
  784. }
  785. result = http2_data_setup(cf, newhandle, &newstream);
  786. if(result) {
  787. failf(data, "error setting up stream: %d", result);
  788. discard_newhandle(cf, newhandle);
  789. rv = CURL_PUSH_DENY;
  790. goto fail;
  791. }
  792. DEBUGASSERT(stream);
  793. Curl_set_in_callback(data, true);
  794. rv = data->multi->push_cb(data, newhandle,
  795. stream->push_headers_used, &heads,
  796. data->multi->push_userp);
  797. Curl_set_in_callback(data, false);
  798. /* free the headers again */
  799. free_push_headers(stream);
  800. if(rv) {
  801. DEBUGASSERT((rv > CURL_PUSH_OK) && (rv <= CURL_PUSH_ERROROUT));
  802. /* denied, kill off the new handle again */
  803. discard_newhandle(cf, newhandle);
  804. goto fail;
  805. }
  806. newstream->id = frame->promised_stream_id;
  807. newhandle->req.maxdownload = -1;
  808. newhandle->req.size = -1;
  809. /* approved, add to the multi handle and immediately switch to PERFORM
  810. state with the given connection !*/
  811. rc = Curl_multi_add_perform(data->multi, newhandle, cf->conn);
  812. if(rc) {
  813. infof(data, "failed to add handle to multi");
  814. discard_newhandle(cf, newhandle);
  815. rv = CURL_PUSH_DENY;
  816. goto fail;
  817. }
  818. rv = nghttp2_session_set_stream_user_data(ctx->h2,
  819. newstream->id,
  820. newhandle);
  821. if(rv) {
  822. infof(data, "failed to set user_data for stream %u",
  823. newstream->id);
  824. DEBUGASSERT(0);
  825. rv = CURL_PUSH_DENY;
  826. goto fail;
  827. }
  828. }
  829. else {
  830. CURL_TRC_CF(data, cf, "Got PUSH_PROMISE, ignore it");
  831. rv = CURL_PUSH_DENY;
  832. }
  833. fail:
  834. return rv;
  835. }
  836. static CURLcode recvbuf_write_hds(struct Curl_cfilter *cf,
  837. struct Curl_easy *data,
  838. const char *buf, size_t blen)
  839. {
  840. (void)cf;
  841. return Curl_xfer_write_resp(data, (char *)buf, blen, FALSE);
  842. }
  843. static CURLcode on_stream_frame(struct Curl_cfilter *cf,
  844. struct Curl_easy *data,
  845. const nghttp2_frame *frame)
  846. {
  847. struct cf_h2_ctx *ctx = cf->ctx;
  848. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  849. int32_t stream_id = frame->hd.stream_id;
  850. CURLcode result;
  851. int rv;
  852. if(!stream) {
  853. CURL_TRC_CF(data, cf, "[%d] No stream_ctx set", stream_id);
  854. return CURLE_FAILED_INIT;
  855. }
  856. switch(frame->hd.type) {
  857. case NGHTTP2_DATA:
  858. CURL_TRC_CF(data, cf, "[%d] DATA, window=%d/%d",
  859. stream_id,
  860. nghttp2_session_get_stream_effective_recv_data_length(
  861. ctx->h2, stream->id),
  862. nghttp2_session_get_stream_effective_local_window_size(
  863. ctx->h2, stream->id));
  864. /* If !body started on this stream, then receiving DATA is illegal. */
  865. if(!stream->bodystarted) {
  866. rv = nghttp2_submit_rst_stream(ctx->h2, NGHTTP2_FLAG_NONE,
  867. stream_id, NGHTTP2_PROTOCOL_ERROR);
  868. if(nghttp2_is_fatal(rv)) {
  869. return CURLE_RECV_ERROR;
  870. }
  871. }
  872. if(frame->hd.flags & NGHTTP2_FLAG_END_STREAM) {
  873. drain_stream(cf, data, stream);
  874. }
  875. break;
  876. case NGHTTP2_HEADERS:
  877. if(stream->bodystarted) {
  878. /* Only valid HEADERS after body started is trailer HEADERS. We
  879. buffer them in on_header callback. */
  880. break;
  881. }
  882. /* nghttp2 guarantees that :status is received, and we store it to
  883. stream->status_code. Fuzzing has proven this can still be reached
  884. without status code having been set. */
  885. if(stream->status_code == -1)
  886. return CURLE_RECV_ERROR;
  887. /* Only final status code signals the end of header */
  888. if(stream->status_code / 100 != 1) {
  889. stream->bodystarted = TRUE;
  890. stream->status_code = -1;
  891. }
  892. result = recvbuf_write_hds(cf, data, STRCONST("\r\n"));
  893. if(result)
  894. return result;
  895. if(stream->status_code / 100 != 1) {
  896. stream->resp_hds_complete = TRUE;
  897. }
  898. drain_stream(cf, data, stream);
  899. break;
  900. case NGHTTP2_PUSH_PROMISE:
  901. rv = push_promise(cf, data, &frame->push_promise);
  902. if(rv) { /* deny! */
  903. DEBUGASSERT((rv > CURL_PUSH_OK) && (rv <= CURL_PUSH_ERROROUT));
  904. rv = nghttp2_submit_rst_stream(ctx->h2, NGHTTP2_FLAG_NONE,
  905. frame->push_promise.promised_stream_id,
  906. NGHTTP2_CANCEL);
  907. if(nghttp2_is_fatal(rv))
  908. return CURLE_SEND_ERROR;
  909. else if(rv == CURL_PUSH_ERROROUT) {
  910. CURL_TRC_CF(data, cf, "[%d] fail in PUSH_PROMISE received",
  911. stream_id);
  912. return CURLE_RECV_ERROR;
  913. }
  914. }
  915. break;
  916. case NGHTTP2_RST_STREAM:
  917. stream->closed = TRUE;
  918. if(frame->rst_stream.error_code) {
  919. stream->reset = TRUE;
  920. }
  921. stream->send_closed = TRUE;
  922. drain_stream(cf, data, stream);
  923. break;
  924. case NGHTTP2_WINDOW_UPDATE:
  925. if(CURL_WANT_SEND(data)) {
  926. drain_stream(cf, data, stream);
  927. }
  928. break;
  929. default:
  930. break;
  931. }
  932. return CURLE_OK;
  933. }
  934. #ifndef CURL_DISABLE_VERBOSE_STRINGS
  935. static int fr_print(const nghttp2_frame *frame, char *buffer, size_t blen)
  936. {
  937. switch(frame->hd.type) {
  938. case NGHTTP2_DATA: {
  939. return msnprintf(buffer, blen,
  940. "FRAME[DATA, len=%d, eos=%d, padlen=%d]",
  941. (int)frame->hd.length,
  942. !!(frame->hd.flags & NGHTTP2_FLAG_END_STREAM),
  943. (int)frame->data.padlen);
  944. }
  945. case NGHTTP2_HEADERS: {
  946. return msnprintf(buffer, blen,
  947. "FRAME[HEADERS, len=%d, hend=%d, eos=%d]",
  948. (int)frame->hd.length,
  949. !!(frame->hd.flags & NGHTTP2_FLAG_END_HEADERS),
  950. !!(frame->hd.flags & NGHTTP2_FLAG_END_STREAM));
  951. }
  952. case NGHTTP2_PRIORITY: {
  953. return msnprintf(buffer, blen,
  954. "FRAME[PRIORITY, len=%d, flags=%d]",
  955. (int)frame->hd.length, frame->hd.flags);
  956. }
  957. case NGHTTP2_RST_STREAM: {
  958. return msnprintf(buffer, blen,
  959. "FRAME[RST_STREAM, len=%d, flags=%d, error=%u]",
  960. (int)frame->hd.length, frame->hd.flags,
  961. frame->rst_stream.error_code);
  962. }
  963. case NGHTTP2_SETTINGS: {
  964. if(frame->hd.flags & NGHTTP2_FLAG_ACK) {
  965. return msnprintf(buffer, blen, "FRAME[SETTINGS, ack=1]");
  966. }
  967. return msnprintf(buffer, blen,
  968. "FRAME[SETTINGS, len=%d]", (int)frame->hd.length);
  969. }
  970. case NGHTTP2_PUSH_PROMISE: {
  971. return msnprintf(buffer, blen,
  972. "FRAME[PUSH_PROMISE, len=%d, hend=%d]",
  973. (int)frame->hd.length,
  974. !!(frame->hd.flags & NGHTTP2_FLAG_END_HEADERS));
  975. }
  976. case NGHTTP2_PING: {
  977. return msnprintf(buffer, blen,
  978. "FRAME[PING, len=%d, ack=%d]",
  979. (int)frame->hd.length,
  980. frame->hd.flags&NGHTTP2_FLAG_ACK);
  981. }
  982. case NGHTTP2_GOAWAY: {
  983. char scratch[128];
  984. size_t s_len = sizeof(scratch)/sizeof(scratch[0]);
  985. size_t len = (frame->goaway.opaque_data_len < s_len)?
  986. frame->goaway.opaque_data_len : s_len-1;
  987. if(len)
  988. memcpy(scratch, frame->goaway.opaque_data, len);
  989. scratch[len] = '\0';
  990. return msnprintf(buffer, blen, "FRAME[GOAWAY, error=%d, reason='%s', "
  991. "last_stream=%d]", frame->goaway.error_code,
  992. scratch, frame->goaway.last_stream_id);
  993. }
  994. case NGHTTP2_WINDOW_UPDATE: {
  995. return msnprintf(buffer, blen,
  996. "FRAME[WINDOW_UPDATE, incr=%d]",
  997. frame->window_update.window_size_increment);
  998. }
  999. default:
  1000. return msnprintf(buffer, blen, "FRAME[%d, len=%d, flags=%d]",
  1001. frame->hd.type, (int)frame->hd.length,
  1002. frame->hd.flags);
  1003. }
  1004. }
  1005. static int on_frame_send(nghttp2_session *session, const nghttp2_frame *frame,
  1006. void *userp)
  1007. {
  1008. struct Curl_cfilter *cf = userp;
  1009. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  1010. (void)session;
  1011. DEBUGASSERT(data);
  1012. if(data && Curl_trc_cf_is_verbose(cf, data)) {
  1013. char buffer[256];
  1014. int len;
  1015. len = fr_print(frame, buffer, sizeof(buffer)-1);
  1016. buffer[len] = 0;
  1017. CURL_TRC_CF(data, cf, "[%d] -> %s", frame->hd.stream_id, buffer);
  1018. }
  1019. return 0;
  1020. }
  1021. #endif /* !CURL_DISABLE_VERBOSE_STRINGS */
  1022. static int on_frame_recv(nghttp2_session *session, const nghttp2_frame *frame,
  1023. void *userp)
  1024. {
  1025. struct Curl_cfilter *cf = userp;
  1026. struct cf_h2_ctx *ctx = cf->ctx;
  1027. struct Curl_easy *data = CF_DATA_CURRENT(cf), *data_s;
  1028. int32_t stream_id = frame->hd.stream_id;
  1029. DEBUGASSERT(data);
  1030. #ifndef CURL_DISABLE_VERBOSE_STRINGS
  1031. if(Curl_trc_cf_is_verbose(cf, data)) {
  1032. char buffer[256];
  1033. int len;
  1034. len = fr_print(frame, buffer, sizeof(buffer)-1);
  1035. buffer[len] = 0;
  1036. CURL_TRC_CF(data, cf, "[%d] <- %s",frame->hd.stream_id, buffer);
  1037. }
  1038. #endif /* !CURL_DISABLE_VERBOSE_STRINGS */
  1039. if(!stream_id) {
  1040. /* stream ID zero is for connection-oriented stuff */
  1041. DEBUGASSERT(data);
  1042. switch(frame->hd.type) {
  1043. case NGHTTP2_SETTINGS: {
  1044. if(!(frame->hd.flags & NGHTTP2_FLAG_ACK)) {
  1045. uint32_t max_conn = ctx->max_concurrent_streams;
  1046. ctx->max_concurrent_streams = nghttp2_session_get_remote_settings(
  1047. session, NGHTTP2_SETTINGS_MAX_CONCURRENT_STREAMS);
  1048. ctx->enable_push = nghttp2_session_get_remote_settings(
  1049. session, NGHTTP2_SETTINGS_ENABLE_PUSH) != 0;
  1050. CURL_TRC_CF(data, cf, "[0] MAX_CONCURRENT_STREAMS: %d",
  1051. ctx->max_concurrent_streams);
  1052. CURL_TRC_CF(data, cf, "[0] ENABLE_PUSH: %s",
  1053. ctx->enable_push ? "TRUE" : "false");
  1054. if(data && max_conn != ctx->max_concurrent_streams) {
  1055. /* only signal change if the value actually changed */
  1056. CURL_TRC_CF(data, cf, "[0] notify MAX_CONCURRENT_STREAMS: %u",
  1057. ctx->max_concurrent_streams);
  1058. Curl_multi_connchanged(data->multi);
  1059. }
  1060. /* Since the initial stream window is 64K, a request might be on HOLD,
  1061. * due to exhaustion. The (initial) SETTINGS may announce a much larger
  1062. * window and *assume* that we treat this like a WINDOW_UPDATE. Some
  1063. * servers send an explicit WINDOW_UPDATE, but not all seem to do that.
  1064. * To be safe, we UNHOLD a stream in order not to stall. */
  1065. if(CURL_WANT_SEND(data)) {
  1066. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1067. if(stream)
  1068. drain_stream(cf, data, stream);
  1069. }
  1070. }
  1071. break;
  1072. }
  1073. case NGHTTP2_GOAWAY:
  1074. ctx->goaway = TRUE;
  1075. ctx->goaway_error = frame->goaway.error_code;
  1076. ctx->last_stream_id = frame->goaway.last_stream_id;
  1077. if(data) {
  1078. infof(data, "received GOAWAY, error=%d, last_stream=%u",
  1079. ctx->goaway_error, ctx->last_stream_id);
  1080. Curl_multi_connchanged(data->multi);
  1081. }
  1082. break;
  1083. default:
  1084. break;
  1085. }
  1086. return 0;
  1087. }
  1088. data_s = nghttp2_session_get_stream_user_data(session, stream_id);
  1089. if(!data_s) {
  1090. CURL_TRC_CF(data, cf, "[%d] No Curl_easy associated", stream_id);
  1091. return 0;
  1092. }
  1093. return on_stream_frame(cf, data_s, frame)? NGHTTP2_ERR_CALLBACK_FAILURE : 0;
  1094. }
  1095. static int on_data_chunk_recv(nghttp2_session *session, uint8_t flags,
  1096. int32_t stream_id,
  1097. const uint8_t *mem, size_t len, void *userp)
  1098. {
  1099. struct Curl_cfilter *cf = userp;
  1100. struct cf_h2_ctx *ctx = cf->ctx;
  1101. struct h2_stream_ctx *stream;
  1102. struct Curl_easy *data_s;
  1103. CURLcode result;
  1104. (void)flags;
  1105. DEBUGASSERT(stream_id); /* should never be a zero stream ID here */
  1106. DEBUGASSERT(CF_DATA_CURRENT(cf));
  1107. /* get the stream from the hash based on Stream ID */
  1108. data_s = nghttp2_session_get_stream_user_data(session, stream_id);
  1109. if(!data_s) {
  1110. /* Receiving a Stream ID not in the hash should not happen - unless
  1111. we have aborted a transfer artificially and there were more data
  1112. in the pipeline. Silently ignore. */
  1113. CURL_TRC_CF(CF_DATA_CURRENT(cf), cf, "[%d] Data for unknown",
  1114. stream_id);
  1115. /* consumed explicitly as no one will read it */
  1116. nghttp2_session_consume(session, stream_id, len);
  1117. return 0;
  1118. }
  1119. stream = H2_STREAM_CTX(data_s);
  1120. if(!stream)
  1121. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1122. result = Curl_xfer_write_resp(data_s, (char *)mem, len, FALSE);
  1123. if(result && result != CURLE_AGAIN)
  1124. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1125. nghttp2_session_consume(ctx->h2, stream_id, len);
  1126. stream->nrcvd_data += (curl_off_t)len;
  1127. /* if we receive data for another handle, wake that up */
  1128. drain_stream(cf, data_s, stream);
  1129. return 0;
  1130. }
  1131. static int on_stream_close(nghttp2_session *session, int32_t stream_id,
  1132. uint32_t error_code, void *userp)
  1133. {
  1134. struct Curl_cfilter *cf = userp;
  1135. struct Curl_easy *data_s, *call_data = CF_DATA_CURRENT(cf);
  1136. struct h2_stream_ctx *stream;
  1137. int rv;
  1138. (void)session;
  1139. DEBUGASSERT(call_data);
  1140. /* get the stream from the hash based on Stream ID, stream ID zero is for
  1141. connection-oriented stuff */
  1142. data_s = stream_id?
  1143. nghttp2_session_get_stream_user_data(session, stream_id) : NULL;
  1144. if(!data_s) {
  1145. CURL_TRC_CF(call_data, cf,
  1146. "[%d] on_stream_close, no easy set on stream", stream_id);
  1147. return 0;
  1148. }
  1149. if(!GOOD_EASY_HANDLE(data_s)) {
  1150. /* nghttp2 still has an easy registered for the stream which has
  1151. * been freed be libcurl. This points to a code path that does not
  1152. * trigger DONE or DETACH events as it must. */
  1153. CURL_TRC_CF(call_data, cf,
  1154. "[%d] on_stream_close, not a GOOD easy on stream", stream_id);
  1155. (void)nghttp2_session_set_stream_user_data(session, stream_id, 0);
  1156. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1157. }
  1158. stream = H2_STREAM_CTX(data_s);
  1159. if(!stream) {
  1160. CURL_TRC_CF(data_s, cf,
  1161. "[%d] on_stream_close, GOOD easy but no stream", stream_id);
  1162. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1163. }
  1164. stream->closed = TRUE;
  1165. stream->error = error_code;
  1166. if(stream->error) {
  1167. stream->reset = TRUE;
  1168. stream->send_closed = TRUE;
  1169. }
  1170. if(stream->error)
  1171. CURL_TRC_CF(data_s, cf, "[%d] RESET: %s (err %d)",
  1172. stream_id, nghttp2_http2_strerror(error_code), error_code);
  1173. else
  1174. CURL_TRC_CF(data_s, cf, "[%d] CLOSED", stream_id);
  1175. drain_stream(cf, data_s, stream);
  1176. /* remove `data_s` from the nghttp2 stream */
  1177. rv = nghttp2_session_set_stream_user_data(session, stream_id, 0);
  1178. if(rv) {
  1179. infof(data_s, "http/2: failed to clear user_data for stream %u",
  1180. stream_id);
  1181. DEBUGASSERT(0);
  1182. }
  1183. return 0;
  1184. }
  1185. static int on_begin_headers(nghttp2_session *session,
  1186. const nghttp2_frame *frame, void *userp)
  1187. {
  1188. struct Curl_cfilter *cf = userp;
  1189. struct h2_stream_ctx *stream;
  1190. struct Curl_easy *data_s = NULL;
  1191. (void)cf;
  1192. data_s = nghttp2_session_get_stream_user_data(session, frame->hd.stream_id);
  1193. if(!data_s) {
  1194. return 0;
  1195. }
  1196. if(frame->hd.type != NGHTTP2_HEADERS) {
  1197. return 0;
  1198. }
  1199. stream = H2_STREAM_CTX(data_s);
  1200. if(!stream || !stream->bodystarted) {
  1201. return 0;
  1202. }
  1203. return 0;
  1204. }
  1205. /* frame->hd.type is either NGHTTP2_HEADERS or NGHTTP2_PUSH_PROMISE */
  1206. static int on_header(nghttp2_session *session, const nghttp2_frame *frame,
  1207. const uint8_t *name, size_t namelen,
  1208. const uint8_t *value, size_t valuelen,
  1209. uint8_t flags,
  1210. void *userp)
  1211. {
  1212. struct Curl_cfilter *cf = userp;
  1213. struct h2_stream_ctx *stream;
  1214. struct Curl_easy *data_s;
  1215. int32_t stream_id = frame->hd.stream_id;
  1216. CURLcode result;
  1217. (void)flags;
  1218. DEBUGASSERT(stream_id); /* should never be a zero stream ID here */
  1219. /* get the stream from the hash based on Stream ID */
  1220. data_s = nghttp2_session_get_stream_user_data(session, stream_id);
  1221. if(!data_s)
  1222. /* Receiving a Stream ID not in the hash should not happen, this is an
  1223. internal error more than anything else! */
  1224. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1225. stream = H2_STREAM_CTX(data_s);
  1226. if(!stream) {
  1227. failf(data_s, "Internal NULL stream");
  1228. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1229. }
  1230. /* Store received PUSH_PROMISE headers to be used when the subsequent
  1231. PUSH_PROMISE callback comes */
  1232. if(frame->hd.type == NGHTTP2_PUSH_PROMISE) {
  1233. char *h;
  1234. if(!strcmp(HTTP_PSEUDO_AUTHORITY, (const char *)name)) {
  1235. /* pseudo headers are lower case */
  1236. int rc = 0;
  1237. char *check = aprintf("%s:%d", cf->conn->host.name,
  1238. cf->conn->remote_port);
  1239. if(!check)
  1240. /* no memory */
  1241. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1242. if(!strcasecompare(check, (const char *)value) &&
  1243. ((cf->conn->remote_port != cf->conn->given->defport) ||
  1244. !strcasecompare(cf->conn->host.name, (const char *)value))) {
  1245. /* This is push is not for the same authority that was asked for in
  1246. * the URL. RFC 7540 section 8.2 says: "A client MUST treat a
  1247. * PUSH_PROMISE for which the server is not authoritative as a stream
  1248. * error of type PROTOCOL_ERROR."
  1249. */
  1250. (void)nghttp2_submit_rst_stream(session, NGHTTP2_FLAG_NONE,
  1251. stream_id, NGHTTP2_PROTOCOL_ERROR);
  1252. rc = NGHTTP2_ERR_CALLBACK_FAILURE;
  1253. }
  1254. free(check);
  1255. if(rc)
  1256. return rc;
  1257. }
  1258. if(!stream->push_headers) {
  1259. stream->push_headers_alloc = 10;
  1260. stream->push_headers = malloc(stream->push_headers_alloc *
  1261. sizeof(char *));
  1262. if(!stream->push_headers)
  1263. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1264. stream->push_headers_used = 0;
  1265. }
  1266. else if(stream->push_headers_used ==
  1267. stream->push_headers_alloc) {
  1268. char **headp;
  1269. if(stream->push_headers_alloc > 1000) {
  1270. /* this is beyond crazy many headers, bail out */
  1271. failf(data_s, "Too many PUSH_PROMISE headers");
  1272. free_push_headers(stream);
  1273. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1274. }
  1275. stream->push_headers_alloc *= 2;
  1276. headp = realloc(stream->push_headers,
  1277. stream->push_headers_alloc * sizeof(char *));
  1278. if(!headp) {
  1279. free_push_headers(stream);
  1280. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1281. }
  1282. stream->push_headers = headp;
  1283. }
  1284. h = aprintf("%s:%s", name, value);
  1285. if(h)
  1286. stream->push_headers[stream->push_headers_used++] = h;
  1287. return 0;
  1288. }
  1289. if(stream->bodystarted) {
  1290. /* This is a trailer */
  1291. CURL_TRC_CF(data_s, cf, "[%d] trailer: %.*s: %.*s",
  1292. stream->id, (int)namelen, name, (int)valuelen, value);
  1293. result = Curl_dynhds_add(&stream->resp_trailers,
  1294. (const char *)name, namelen,
  1295. (const char *)value, valuelen);
  1296. if(result)
  1297. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1298. return 0;
  1299. }
  1300. if(namelen == sizeof(HTTP_PSEUDO_STATUS) - 1 &&
  1301. memcmp(HTTP_PSEUDO_STATUS, name, namelen) == 0) {
  1302. /* nghttp2 guarantees :status is received first and only once. */
  1303. char buffer[32];
  1304. result = Curl_http_decode_status(&stream->status_code,
  1305. (const char *)value, valuelen);
  1306. if(result)
  1307. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1308. msnprintf(buffer, sizeof(buffer), HTTP_PSEUDO_STATUS ":%u\r",
  1309. stream->status_code);
  1310. result = Curl_headers_push(data_s, buffer, CURLH_PSEUDO);
  1311. if(result)
  1312. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1313. result = recvbuf_write_hds(cf, data_s, STRCONST("HTTP/2 "));
  1314. if(result)
  1315. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1316. result = recvbuf_write_hds(cf, data_s, (const char *)value, valuelen);
  1317. if(result)
  1318. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1319. /* the space character after the status code is mandatory */
  1320. result = recvbuf_write_hds(cf, data_s, STRCONST(" \r\n"));
  1321. if(result)
  1322. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1323. /* if we receive data for another handle, wake that up */
  1324. if(CF_DATA_CURRENT(cf) != data_s)
  1325. Curl_expire(data_s, 0, EXPIRE_RUN_NOW);
  1326. CURL_TRC_CF(data_s, cf, "[%d] status: HTTP/2 %03d",
  1327. stream->id, stream->status_code);
  1328. return 0;
  1329. }
  1330. /* nghttp2 guarantees that namelen > 0, and :status was already
  1331. received, and this is not pseudo-header field . */
  1332. /* convert to an HTTP1-style header */
  1333. result = recvbuf_write_hds(cf, data_s, (const char *)name, namelen);
  1334. if(result)
  1335. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1336. result = recvbuf_write_hds(cf, data_s, STRCONST(": "));
  1337. if(result)
  1338. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1339. result = recvbuf_write_hds(cf, data_s, (const char *)value, valuelen);
  1340. if(result)
  1341. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1342. result = recvbuf_write_hds(cf, data_s, STRCONST("\r\n"));
  1343. if(result)
  1344. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1345. /* if we receive data for another handle, wake that up */
  1346. if(CF_DATA_CURRENT(cf) != data_s)
  1347. Curl_expire(data_s, 0, EXPIRE_RUN_NOW);
  1348. CURL_TRC_CF(data_s, cf, "[%d] header: %.*s: %.*s",
  1349. stream->id, (int)namelen, name, (int)valuelen, value);
  1350. return 0; /* 0 is successful */
  1351. }
  1352. static ssize_t req_body_read_callback(nghttp2_session *session,
  1353. int32_t stream_id,
  1354. uint8_t *buf, size_t length,
  1355. uint32_t *data_flags,
  1356. nghttp2_data_source *source,
  1357. void *userp)
  1358. {
  1359. struct Curl_cfilter *cf = userp;
  1360. struct Curl_easy *data_s;
  1361. struct h2_stream_ctx *stream = NULL;
  1362. CURLcode result;
  1363. ssize_t nread;
  1364. (void)source;
  1365. (void)cf;
  1366. if(stream_id) {
  1367. /* get the stream from the hash based on Stream ID, stream ID zero is for
  1368. connection-oriented stuff */
  1369. data_s = nghttp2_session_get_stream_user_data(session, stream_id);
  1370. if(!data_s)
  1371. /* Receiving a Stream ID not in the hash should not happen, this is an
  1372. internal error more than anything else! */
  1373. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1374. stream = H2_STREAM_CTX(data_s);
  1375. if(!stream)
  1376. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1377. }
  1378. else
  1379. return NGHTTP2_ERR_INVALID_ARGUMENT;
  1380. nread = Curl_bufq_read(&stream->sendbuf, buf, length, &result);
  1381. if(nread < 0) {
  1382. if(result != CURLE_AGAIN)
  1383. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1384. nread = 0;
  1385. }
  1386. if(nread > 0 && stream->upload_left != -1)
  1387. stream->upload_left -= nread;
  1388. CURL_TRC_CF(data_s, cf, "[%d] req_body_read(len=%zu) left=%"
  1389. CURL_FORMAT_CURL_OFF_T " -> %zd, %d",
  1390. stream_id, length, stream->upload_left, nread, result);
  1391. if(stream->upload_left == 0)
  1392. *data_flags = NGHTTP2_DATA_FLAG_EOF;
  1393. else if(nread == 0)
  1394. return NGHTTP2_ERR_DEFERRED;
  1395. return nread;
  1396. }
  1397. #if !defined(CURL_DISABLE_VERBOSE_STRINGS)
  1398. static int error_callback(nghttp2_session *session,
  1399. const char *msg,
  1400. size_t len,
  1401. void *userp)
  1402. {
  1403. struct Curl_cfilter *cf = userp;
  1404. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  1405. (void)session;
  1406. failf(data, "%.*s", (int)len, msg);
  1407. return 0;
  1408. }
  1409. #endif
  1410. /*
  1411. * Append headers to ask for an HTTP1.1 to HTTP2 upgrade.
  1412. */
  1413. CURLcode Curl_http2_request_upgrade(struct dynbuf *req,
  1414. struct Curl_easy *data)
  1415. {
  1416. CURLcode result;
  1417. char *base64;
  1418. size_t blen;
  1419. struct SingleRequest *k = &data->req;
  1420. uint8_t binsettings[H2_BINSETTINGS_LEN];
  1421. ssize_t binlen; /* length of the binsettings data */
  1422. binlen = populate_binsettings(binsettings, data);
  1423. if(binlen <= 0) {
  1424. failf(data, "nghttp2 unexpectedly failed on pack_settings_payload");
  1425. Curl_dyn_free(req);
  1426. return CURLE_FAILED_INIT;
  1427. }
  1428. result = Curl_base64url_encode((const char *)binsettings, binlen,
  1429. &base64, &blen);
  1430. if(result) {
  1431. Curl_dyn_free(req);
  1432. return result;
  1433. }
  1434. result = Curl_dyn_addf(req,
  1435. "Connection: Upgrade, HTTP2-Settings\r\n"
  1436. "Upgrade: %s\r\n"
  1437. "HTTP2-Settings: %s\r\n",
  1438. NGHTTP2_CLEARTEXT_PROTO_VERSION_ID, base64);
  1439. free(base64);
  1440. k->upgr101 = UPGR101_H2;
  1441. return result;
  1442. }
  1443. static CURLcode http2_data_done_send(struct Curl_cfilter *cf,
  1444. struct Curl_easy *data)
  1445. {
  1446. struct cf_h2_ctx *ctx = cf->ctx;
  1447. CURLcode result = CURLE_OK;
  1448. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1449. if(!ctx || !ctx->h2 || !stream)
  1450. goto out;
  1451. CURL_TRC_CF(data, cf, "[%d] data done send", stream->id);
  1452. if(!stream->send_closed) {
  1453. stream->send_closed = TRUE;
  1454. if(stream->upload_left) {
  1455. /* we now know that everything that is buffered is all there is. */
  1456. stream->upload_left = Curl_bufq_len(&stream->sendbuf);
  1457. /* resume sending here to trigger the callback to get called again so
  1458. that it can signal EOF to nghttp2 */
  1459. (void)nghttp2_session_resume_data(ctx->h2, stream->id);
  1460. drain_stream(cf, data, stream);
  1461. }
  1462. }
  1463. out:
  1464. return result;
  1465. }
  1466. static ssize_t http2_handle_stream_close(struct Curl_cfilter *cf,
  1467. struct Curl_easy *data,
  1468. struct h2_stream_ctx *stream,
  1469. CURLcode *err)
  1470. {
  1471. ssize_t rv = 0;
  1472. if(stream->error == NGHTTP2_REFUSED_STREAM) {
  1473. CURL_TRC_CF(data, cf, "[%d] REFUSED_STREAM, try again on a new "
  1474. "connection", stream->id);
  1475. connclose(cf->conn, "REFUSED_STREAM"); /* don't use this anymore */
  1476. data->state.refused_stream = TRUE;
  1477. *err = CURLE_RECV_ERROR; /* trigger Curl_retry_request() later */
  1478. return -1;
  1479. }
  1480. else if(stream->error != NGHTTP2_NO_ERROR) {
  1481. failf(data, "HTTP/2 stream %u was not closed cleanly: %s (err %u)",
  1482. stream->id, nghttp2_http2_strerror(stream->error),
  1483. stream->error);
  1484. *err = CURLE_HTTP2_STREAM;
  1485. return -1;
  1486. }
  1487. else if(stream->reset) {
  1488. failf(data, "HTTP/2 stream %u was reset", stream->id);
  1489. *err = data->req.bytecount? CURLE_PARTIAL_FILE : CURLE_HTTP2;
  1490. return -1;
  1491. }
  1492. if(!stream->bodystarted) {
  1493. failf(data, "HTTP/2 stream %u was closed cleanly, but before getting "
  1494. " all response header fields, treated as error",
  1495. stream->id);
  1496. *err = CURLE_HTTP2_STREAM;
  1497. return -1;
  1498. }
  1499. if(Curl_dynhds_count(&stream->resp_trailers)) {
  1500. struct dynhds_entry *e;
  1501. struct dynbuf dbuf;
  1502. size_t i;
  1503. *err = CURLE_OK;
  1504. Curl_dyn_init(&dbuf, DYN_TRAILERS);
  1505. for(i = 0; i < Curl_dynhds_count(&stream->resp_trailers); ++i) {
  1506. e = Curl_dynhds_getn(&stream->resp_trailers, i);
  1507. if(!e)
  1508. break;
  1509. Curl_dyn_reset(&dbuf);
  1510. *err = Curl_dyn_addf(&dbuf, "%.*s: %.*s\x0d\x0a",
  1511. (int)e->namelen, e->name,
  1512. (int)e->valuelen, e->value);
  1513. if(*err)
  1514. break;
  1515. Curl_debug(data, CURLINFO_HEADER_IN, Curl_dyn_ptr(&dbuf),
  1516. Curl_dyn_len(&dbuf));
  1517. *err = Curl_client_write(data, CLIENTWRITE_HEADER|CLIENTWRITE_TRAILER,
  1518. Curl_dyn_ptr(&dbuf), Curl_dyn_len(&dbuf));
  1519. if(*err)
  1520. break;
  1521. }
  1522. Curl_dyn_free(&dbuf);
  1523. if(*err)
  1524. goto out;
  1525. }
  1526. stream->close_handled = TRUE;
  1527. *err = CURLE_OK;
  1528. rv = 0;
  1529. out:
  1530. CURL_TRC_CF(data, cf, "handle_stream_close -> %zd, %d", rv, *err);
  1531. return rv;
  1532. }
  1533. static int sweight_wanted(const struct Curl_easy *data)
  1534. {
  1535. /* 0 weight is not set by user and we take the nghttp2 default one */
  1536. return data->set.priority.weight?
  1537. data->set.priority.weight : NGHTTP2_DEFAULT_WEIGHT;
  1538. }
  1539. static int sweight_in_effect(const struct Curl_easy *data)
  1540. {
  1541. /* 0 weight is not set by user and we take the nghttp2 default one */
  1542. return data->state.priority.weight?
  1543. data->state.priority.weight : NGHTTP2_DEFAULT_WEIGHT;
  1544. }
  1545. /*
  1546. * h2_pri_spec() fills in the pri_spec struct, used by nghttp2 to send weight
  1547. * and dependency to the peer. It also stores the updated values in the state
  1548. * struct.
  1549. */
  1550. static void h2_pri_spec(struct Curl_easy *data,
  1551. nghttp2_priority_spec *pri_spec)
  1552. {
  1553. struct Curl_data_priority *prio = &data->set.priority;
  1554. struct h2_stream_ctx *depstream = H2_STREAM_CTX(prio->parent);
  1555. int32_t depstream_id = depstream? depstream->id:0;
  1556. nghttp2_priority_spec_init(pri_spec, depstream_id,
  1557. sweight_wanted(data),
  1558. data->set.priority.exclusive);
  1559. data->state.priority = *prio;
  1560. }
  1561. /*
  1562. * Check if there's been an update in the priority /
  1563. * dependency settings and if so it submits a PRIORITY frame with the updated
  1564. * info.
  1565. * Flush any out data pending in the network buffer.
  1566. */
  1567. static CURLcode h2_progress_egress(struct Curl_cfilter *cf,
  1568. struct Curl_easy *data)
  1569. {
  1570. struct cf_h2_ctx *ctx = cf->ctx;
  1571. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1572. int rv = 0;
  1573. if(stream && stream->id > 0 &&
  1574. ((sweight_wanted(data) != sweight_in_effect(data)) ||
  1575. (data->set.priority.exclusive != data->state.priority.exclusive) ||
  1576. (data->set.priority.parent != data->state.priority.parent)) ) {
  1577. /* send new weight and/or dependency */
  1578. nghttp2_priority_spec pri_spec;
  1579. h2_pri_spec(data, &pri_spec);
  1580. CURL_TRC_CF(data, cf, "[%d] Queuing PRIORITY", stream->id);
  1581. DEBUGASSERT(stream->id != -1);
  1582. rv = nghttp2_submit_priority(ctx->h2, NGHTTP2_FLAG_NONE,
  1583. stream->id, &pri_spec);
  1584. if(rv)
  1585. goto out;
  1586. }
  1587. ctx->nw_out_blocked = 0;
  1588. while(!rv && !ctx->nw_out_blocked && nghttp2_session_want_write(ctx->h2))
  1589. rv = nghttp2_session_send(ctx->h2);
  1590. out:
  1591. if(nghttp2_is_fatal(rv)) {
  1592. CURL_TRC_CF(data, cf, "nghttp2_session_send error (%s)%d",
  1593. nghttp2_strerror(rv), rv);
  1594. return CURLE_SEND_ERROR;
  1595. }
  1596. return nw_out_flush(cf, data);
  1597. }
  1598. static ssize_t stream_recv(struct Curl_cfilter *cf, struct Curl_easy *data,
  1599. struct h2_stream_ctx *stream,
  1600. char *buf, size_t len, CURLcode *err)
  1601. {
  1602. struct cf_h2_ctx *ctx = cf->ctx;
  1603. ssize_t nread = -1;
  1604. (void)buf;
  1605. *err = CURLE_AGAIN;
  1606. if(stream->closed) {
  1607. CURL_TRC_CF(data, cf, "[%d] returning CLOSE", stream->id);
  1608. nread = http2_handle_stream_close(cf, data, stream, err);
  1609. }
  1610. else if(stream->reset ||
  1611. (ctx->conn_closed && Curl_bufq_is_empty(&ctx->inbufq)) ||
  1612. (ctx->goaway && ctx->last_stream_id < stream->id)) {
  1613. CURL_TRC_CF(data, cf, "[%d] returning ERR", stream->id);
  1614. *err = data->req.bytecount? CURLE_PARTIAL_FILE : CURLE_HTTP2;
  1615. nread = -1;
  1616. }
  1617. if(nread < 0 && *err != CURLE_AGAIN)
  1618. CURL_TRC_CF(data, cf, "[%d] stream_recv(len=%zu) -> %zd, %d",
  1619. stream->id, len, nread, *err);
  1620. return nread;
  1621. }
  1622. static CURLcode h2_progress_ingress(struct Curl_cfilter *cf,
  1623. struct Curl_easy *data,
  1624. size_t data_max_bytes)
  1625. {
  1626. struct cf_h2_ctx *ctx = cf->ctx;
  1627. struct h2_stream_ctx *stream;
  1628. CURLcode result = CURLE_OK;
  1629. ssize_t nread;
  1630. /* Process network input buffer fist */
  1631. if(!Curl_bufq_is_empty(&ctx->inbufq)) {
  1632. CURL_TRC_CF(data, cf, "Process %zu bytes in connection buffer",
  1633. Curl_bufq_len(&ctx->inbufq));
  1634. if(h2_process_pending_input(cf, data, &result) < 0)
  1635. return result;
  1636. }
  1637. /* Receive data from the "lower" filters, e.g. network until
  1638. * it is time to stop due to connection close or us not processing
  1639. * all network input */
  1640. while(!ctx->conn_closed && Curl_bufq_is_empty(&ctx->inbufq)) {
  1641. stream = H2_STREAM_CTX(data);
  1642. if(stream && (stream->closed || !data_max_bytes)) {
  1643. /* We would like to abort here and stop processing, so that
  1644. * the transfer loop can handle the data/close here. However,
  1645. * this may leave data in underlying buffers that will not
  1646. * be consumed. */
  1647. if(!cf->next || !cf->next->cft->has_data_pending(cf->next, data))
  1648. drain_stream(cf, data, stream);
  1649. break;
  1650. }
  1651. nread = Curl_bufq_sipn(&ctx->inbufq, 0, nw_in_reader, cf, &result);
  1652. if(nread < 0) {
  1653. if(result != CURLE_AGAIN) {
  1654. failf(data, "Failed receiving HTTP2 data: %d(%s)", result,
  1655. curl_easy_strerror(result));
  1656. return result;
  1657. }
  1658. break;
  1659. }
  1660. else if(nread == 0) {
  1661. CURL_TRC_CF(data, cf, "[0] ingress: connection closed");
  1662. ctx->conn_closed = TRUE;
  1663. break;
  1664. }
  1665. else {
  1666. CURL_TRC_CF(data, cf, "[0] ingress: read %zd bytes", nread);
  1667. data_max_bytes = (data_max_bytes > (size_t)nread)?
  1668. (data_max_bytes - (size_t)nread) : 0;
  1669. }
  1670. if(h2_process_pending_input(cf, data, &result))
  1671. return result;
  1672. }
  1673. if(ctx->conn_closed && Curl_bufq_is_empty(&ctx->inbufq)) {
  1674. connclose(cf->conn, "GOAWAY received");
  1675. }
  1676. return CURLE_OK;
  1677. }
  1678. static ssize_t cf_h2_recv(struct Curl_cfilter *cf, struct Curl_easy *data,
  1679. char *buf, size_t len, CURLcode *err)
  1680. {
  1681. struct cf_h2_ctx *ctx = cf->ctx;
  1682. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1683. ssize_t nread = -1;
  1684. CURLcode result;
  1685. struct cf_call_data save;
  1686. if(!stream) {
  1687. /* Abnormal call sequence: either this transfer has never opened a stream
  1688. * (unlikely) or the transfer has been done, cleaned up its resources, but
  1689. * a read() is called anyway. It is not clear what the calling sequence
  1690. * is for such a case. */
  1691. failf(data, "[%zd-%zd], http/2 recv on a transfer never opened "
  1692. "or already cleared", (ssize_t)data->id,
  1693. (ssize_t)cf->conn->connection_id);
  1694. *err = CURLE_HTTP2;
  1695. return -1;
  1696. }
  1697. CF_DATA_SAVE(save, cf, data);
  1698. nread = stream_recv(cf, data, stream, buf, len, err);
  1699. if(nread < 0 && *err != CURLE_AGAIN)
  1700. goto out;
  1701. if(nread < 0) {
  1702. *err = h2_progress_ingress(cf, data, len);
  1703. if(*err)
  1704. goto out;
  1705. nread = stream_recv(cf, data, stream, buf, len, err);
  1706. }
  1707. if(nread > 0) {
  1708. size_t data_consumed = (size_t)nread;
  1709. /* Now that we transferred this to the upper layer, we report
  1710. * the actual amount of DATA consumed to the H2 session, so
  1711. * that it adjusts stream flow control */
  1712. if(stream->resp_hds_len >= data_consumed) {
  1713. stream->resp_hds_len -= data_consumed; /* no DATA */
  1714. }
  1715. else {
  1716. if(stream->resp_hds_len) {
  1717. data_consumed -= stream->resp_hds_len;
  1718. stream->resp_hds_len = 0;
  1719. }
  1720. if(data_consumed) {
  1721. nghttp2_session_consume(ctx->h2, stream->id, data_consumed);
  1722. }
  1723. }
  1724. if(stream->closed) {
  1725. CURL_TRC_CF(data, cf, "[%d] DRAIN closed stream", stream->id);
  1726. drain_stream(cf, data, stream);
  1727. }
  1728. }
  1729. out:
  1730. result = h2_progress_egress(cf, data);
  1731. if(result == CURLE_AGAIN) {
  1732. /* pending data to send, need to be called again. Ideally, we'd
  1733. * monitor the socket for POLLOUT, but we might not be in SENDING
  1734. * transfer state any longer and are unable to make this happen.
  1735. */
  1736. drain_stream(cf, data, stream);
  1737. }
  1738. else if(result) {
  1739. *err = result;
  1740. nread = -1;
  1741. }
  1742. CURL_TRC_CF(data, cf, "[%d] cf_recv(len=%zu) -> %zd %d, "
  1743. "window=%d/%d, connection %d/%d",
  1744. stream->id, len, nread, *err,
  1745. nghttp2_session_get_stream_effective_recv_data_length(
  1746. ctx->h2, stream->id),
  1747. nghttp2_session_get_stream_effective_local_window_size(
  1748. ctx->h2, stream->id),
  1749. nghttp2_session_get_local_window_size(ctx->h2),
  1750. HTTP2_HUGE_WINDOW_SIZE);
  1751. CF_DATA_RESTORE(cf, save);
  1752. return nread;
  1753. }
  1754. static ssize_t h2_submit(struct h2_stream_ctx **pstream,
  1755. struct Curl_cfilter *cf, struct Curl_easy *data,
  1756. const void *buf, size_t len,
  1757. size_t *phdslen, CURLcode *err)
  1758. {
  1759. struct cf_h2_ctx *ctx = cf->ctx;
  1760. struct h2_stream_ctx *stream = NULL;
  1761. struct dynhds h2_headers;
  1762. nghttp2_nv *nva = NULL;
  1763. const void *body = NULL;
  1764. size_t nheader, bodylen, i;
  1765. nghttp2_data_provider data_prd;
  1766. int32_t stream_id;
  1767. nghttp2_priority_spec pri_spec;
  1768. ssize_t nwritten;
  1769. *phdslen = 0;
  1770. Curl_dynhds_init(&h2_headers, 0, DYN_HTTP_REQUEST);
  1771. *err = http2_data_setup(cf, data, &stream);
  1772. if(*err) {
  1773. nwritten = -1;
  1774. goto out;
  1775. }
  1776. nwritten = Curl_h1_req_parse_read(&stream->h1, buf, len, NULL, 0, err);
  1777. if(nwritten < 0)
  1778. goto out;
  1779. *phdslen = (size_t)nwritten;
  1780. if(!stream->h1.done) {
  1781. /* need more data */
  1782. goto out;
  1783. }
  1784. DEBUGASSERT(stream->h1.req);
  1785. *err = Curl_http_req_to_h2(&h2_headers, stream->h1.req, data);
  1786. if(*err) {
  1787. nwritten = -1;
  1788. goto out;
  1789. }
  1790. /* no longer needed */
  1791. Curl_h1_req_parse_free(&stream->h1);
  1792. nva = Curl_dynhds_to_nva(&h2_headers, &nheader);
  1793. if(!nva) {
  1794. *err = CURLE_OUT_OF_MEMORY;
  1795. nwritten = -1;
  1796. goto out;
  1797. }
  1798. h2_pri_spec(data, &pri_spec);
  1799. if(!nghttp2_session_check_request_allowed(ctx->h2))
  1800. CURL_TRC_CF(data, cf, "send request NOT allowed (via nghttp2)");
  1801. switch(data->state.httpreq) {
  1802. case HTTPREQ_POST:
  1803. case HTTPREQ_POST_FORM:
  1804. case HTTPREQ_POST_MIME:
  1805. case HTTPREQ_PUT:
  1806. if(data->state.infilesize != -1)
  1807. stream->upload_left = data->state.infilesize;
  1808. else
  1809. /* data sending without specifying the data amount up front */
  1810. stream->upload_left = -1; /* unknown */
  1811. data_prd.read_callback = req_body_read_callback;
  1812. data_prd.source.ptr = NULL;
  1813. stream_id = nghttp2_submit_request(ctx->h2, &pri_spec, nva, nheader,
  1814. &data_prd, data);
  1815. break;
  1816. default:
  1817. stream->upload_left = 0; /* no request body */
  1818. stream_id = nghttp2_submit_request(ctx->h2, &pri_spec, nva, nheader,
  1819. NULL, data);
  1820. }
  1821. if(stream_id < 0) {
  1822. CURL_TRC_CF(data, cf, "send: nghttp2_submit_request error (%s)%u",
  1823. nghttp2_strerror(stream_id), stream_id);
  1824. *err = CURLE_SEND_ERROR;
  1825. nwritten = -1;
  1826. goto out;
  1827. }
  1828. #define MAX_ACC 60000 /* <64KB to account for some overhead */
  1829. if(Curl_trc_is_verbose(data)) {
  1830. size_t acc = 0;
  1831. infof(data, "[HTTP/2] [%d] OPENED stream for %s",
  1832. stream_id, data->state.url);
  1833. for(i = 0; i < nheader; ++i) {
  1834. acc += nva[i].namelen + nva[i].valuelen;
  1835. infof(data, "[HTTP/2] [%d] [%.*s: %.*s]", stream_id,
  1836. (int)nva[i].namelen, nva[i].name,
  1837. (int)nva[i].valuelen, nva[i].value);
  1838. }
  1839. if(acc > MAX_ACC) {
  1840. infof(data, "[HTTP/2] Warning: The cumulative length of all "
  1841. "headers exceeds %d bytes and that could cause the "
  1842. "stream to be rejected.", MAX_ACC);
  1843. }
  1844. }
  1845. stream->id = stream_id;
  1846. stream->local_window_size = H2_STREAM_WINDOW_SIZE;
  1847. if(data->set.max_recv_speed) {
  1848. /* We are asked to only receive `max_recv_speed` bytes per second.
  1849. * Let's limit our stream window size around that, otherwise the server
  1850. * will send in large bursts only. We make the window 50% larger to
  1851. * allow for data in flight and avoid stalling. */
  1852. curl_off_t n = (((data->set.max_recv_speed - 1) / H2_CHUNK_SIZE) + 1);
  1853. n += CURLMAX((n/2), 1);
  1854. if(n < (H2_STREAM_WINDOW_SIZE / H2_CHUNK_SIZE) &&
  1855. n < (UINT_MAX / H2_CHUNK_SIZE)) {
  1856. stream->local_window_size = (uint32_t)n * H2_CHUNK_SIZE;
  1857. }
  1858. }
  1859. body = (const char *)buf + nwritten;
  1860. bodylen = len - nwritten;
  1861. if(bodylen) {
  1862. /* We have request body to send in DATA frame */
  1863. ssize_t n = Curl_bufq_write(&stream->sendbuf, body, bodylen, err);
  1864. if(n < 0) {
  1865. *err = CURLE_SEND_ERROR;
  1866. nwritten = -1;
  1867. goto out;
  1868. }
  1869. nwritten += n;
  1870. }
  1871. out:
  1872. CURL_TRC_CF(data, cf, "[%d] submit -> %zd, %d",
  1873. stream? stream->id : -1, nwritten, *err);
  1874. Curl_safefree(nva);
  1875. *pstream = stream;
  1876. Curl_dynhds_free(&h2_headers);
  1877. return nwritten;
  1878. }
  1879. static ssize_t cf_h2_send(struct Curl_cfilter *cf, struct Curl_easy *data,
  1880. const void *buf, size_t len, CURLcode *err)
  1881. {
  1882. struct cf_h2_ctx *ctx = cf->ctx;
  1883. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1884. struct cf_call_data save;
  1885. int rv;
  1886. ssize_t nwritten;
  1887. size_t hdslen = 0;
  1888. CURLcode result;
  1889. int blocked = 0, was_blocked = 0;
  1890. CF_DATA_SAVE(save, cf, data);
  1891. if(stream && stream->id != -1) {
  1892. if(stream->upload_blocked_len) {
  1893. /* the data in `buf` has already been submitted or added to the
  1894. * buffers, but have been EAGAINed on the last invocation. */
  1895. /* TODO: this assertion triggers in OSSFuzz runs and it is not
  1896. * clear why. Disable for now to let OSSFuzz continue its tests. */
  1897. DEBUGASSERT(len >= stream->upload_blocked_len);
  1898. if(len < stream->upload_blocked_len) {
  1899. /* Did we get called again with a smaller `len`? This should not
  1900. * happen. We are not prepared to handle that. */
  1901. failf(data, "HTTP/2 send again with decreased length (%zd vs %zd)",
  1902. len, stream->upload_blocked_len);
  1903. *err = CURLE_HTTP2;
  1904. nwritten = -1;
  1905. goto out;
  1906. }
  1907. nwritten = (ssize_t)stream->upload_blocked_len;
  1908. stream->upload_blocked_len = 0;
  1909. was_blocked = 1;
  1910. }
  1911. else if(stream->closed) {
  1912. if(stream->resp_hds_complete) {
  1913. /* Server decided to close the stream after having sent us a findl
  1914. * response. This is valid if it is not interested in the request
  1915. * body. This happens on 30x or 40x responses.
  1916. * We silently discard the data sent, since this is not a transport
  1917. * error situation. */
  1918. CURL_TRC_CF(data, cf, "[%d] discarding data"
  1919. "on closed stream with response", stream->id);
  1920. *err = CURLE_OK;
  1921. nwritten = (ssize_t)len;
  1922. goto out;
  1923. }
  1924. infof(data, "stream %u closed", stream->id);
  1925. *err = CURLE_SEND_ERROR;
  1926. nwritten = -1;
  1927. goto out;
  1928. }
  1929. else {
  1930. /* If stream_id != -1, we have dispatched request HEADERS and
  1931. * optionally request body, and now are going to send or sending
  1932. * more request body in DATA frame */
  1933. nwritten = Curl_bufq_write(&stream->sendbuf, buf, len, err);
  1934. if(nwritten < 0 && *err != CURLE_AGAIN)
  1935. goto out;
  1936. }
  1937. if(!Curl_bufq_is_empty(&stream->sendbuf)) {
  1938. /* req body data is buffered, resume the potentially suspended stream */
  1939. rv = nghttp2_session_resume_data(ctx->h2, stream->id);
  1940. if(nghttp2_is_fatal(rv)) {
  1941. *err = CURLE_SEND_ERROR;
  1942. nwritten = -1;
  1943. goto out;
  1944. }
  1945. }
  1946. }
  1947. else {
  1948. nwritten = h2_submit(&stream, cf, data, buf, len, &hdslen, err);
  1949. if(nwritten < 0) {
  1950. goto out;
  1951. }
  1952. DEBUGASSERT(stream);
  1953. DEBUGASSERT(hdslen <= (size_t)nwritten);
  1954. }
  1955. /* Call the nghttp2 send loop and flush to write ALL buffered data,
  1956. * headers and/or request body completely out to the network */
  1957. result = h2_progress_egress(cf, data);
  1958. /* if the stream has been closed in egress handling (nghttp2 does that
  1959. * when it does not like the headers, for example */
  1960. if(stream && stream->closed && !was_blocked) {
  1961. infof(data, "stream %u closed", stream->id);
  1962. *err = CURLE_SEND_ERROR;
  1963. nwritten = -1;
  1964. goto out;
  1965. }
  1966. else if(result == CURLE_AGAIN) {
  1967. blocked = 1;
  1968. }
  1969. else if(result) {
  1970. *err = result;
  1971. nwritten = -1;
  1972. goto out;
  1973. }
  1974. else if(stream && !Curl_bufq_is_empty(&stream->sendbuf)) {
  1975. /* although we wrote everything that nghttp2 wants to send now,
  1976. * there is data left in our stream send buffer unwritten. This may
  1977. * be due to the stream's HTTP/2 flow window being exhausted. */
  1978. blocked = 1;
  1979. }
  1980. if(stream && blocked && nwritten > 0) {
  1981. /* Unable to send all data, due to connection blocked or H2 window
  1982. * exhaustion. Data is left in our stream buffer, or nghttp2's internal
  1983. * frame buffer or our network out buffer. */
  1984. size_t rwin = nghttp2_session_get_stream_remote_window_size(ctx->h2,
  1985. stream->id);
  1986. /* At the start of a stream, we are called with request headers
  1987. * and, possibly, parts of the body. Later, only body data.
  1988. * If we cannot send pure body data, we EAGAIN. If there had been
  1989. * header, we return that *they* have been written and remember the
  1990. * block on the data length only. */
  1991. stream->upload_blocked_len = ((size_t)nwritten) - hdslen;
  1992. CURL_TRC_CF(data, cf, "[%d] cf_send(len=%zu) BLOCK: win %u/%zu "
  1993. "hds_len=%zu blocked_len=%zu",
  1994. stream->id, len,
  1995. nghttp2_session_get_remote_window_size(ctx->h2), rwin,
  1996. hdslen, stream->upload_blocked_len);
  1997. if(hdslen) {
  1998. *err = CURLE_OK;
  1999. nwritten = hdslen;
  2000. }
  2001. else {
  2002. *err = CURLE_AGAIN;
  2003. nwritten = -1;
  2004. goto out;
  2005. }
  2006. }
  2007. else if(should_close_session(ctx)) {
  2008. /* nghttp2 thinks this session is done. If the stream has not been
  2009. * closed, this is an error state for out transfer */
  2010. if(stream->closed) {
  2011. nwritten = http2_handle_stream_close(cf, data, stream, err);
  2012. }
  2013. else {
  2014. CURL_TRC_CF(data, cf, "send: nothing to do in this session");
  2015. *err = CURLE_HTTP2;
  2016. nwritten = -1;
  2017. }
  2018. }
  2019. out:
  2020. if(stream) {
  2021. CURL_TRC_CF(data, cf, "[%d] cf_send(len=%zu) -> %zd, %d, "
  2022. "upload_left=%" CURL_FORMAT_CURL_OFF_T ", "
  2023. "h2 windows %d-%d (stream-conn), "
  2024. "buffers %zu-%zu (stream-conn)",
  2025. stream->id, len, nwritten, *err,
  2026. stream->upload_left,
  2027. nghttp2_session_get_stream_remote_window_size(
  2028. ctx->h2, stream->id),
  2029. nghttp2_session_get_remote_window_size(ctx->h2),
  2030. Curl_bufq_len(&stream->sendbuf),
  2031. Curl_bufq_len(&ctx->outbufq));
  2032. }
  2033. else {
  2034. CURL_TRC_CF(data, cf, "cf_send(len=%zu) -> %zd, %d, "
  2035. "connection-window=%d, nw_send_buffer(%zu)",
  2036. len, nwritten, *err,
  2037. nghttp2_session_get_remote_window_size(ctx->h2),
  2038. Curl_bufq_len(&ctx->outbufq));
  2039. }
  2040. CF_DATA_RESTORE(cf, save);
  2041. return nwritten;
  2042. }
  2043. static void cf_h2_adjust_pollset(struct Curl_cfilter *cf,
  2044. struct Curl_easy *data,
  2045. struct easy_pollset *ps)
  2046. {
  2047. struct cf_h2_ctx *ctx = cf->ctx;
  2048. curl_socket_t sock;
  2049. bool want_recv, want_send;
  2050. if(!ctx->h2)
  2051. return;
  2052. sock = Curl_conn_cf_get_socket(cf, data);
  2053. Curl_pollset_check(data, ps, sock, &want_recv, &want_send);
  2054. if(want_recv || want_send) {
  2055. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  2056. struct cf_call_data save;
  2057. bool c_exhaust, s_exhaust;
  2058. CF_DATA_SAVE(save, cf, data);
  2059. c_exhaust = want_send && !nghttp2_session_get_remote_window_size(ctx->h2);
  2060. s_exhaust = want_send && stream && stream->id >= 0 &&
  2061. !nghttp2_session_get_stream_remote_window_size(ctx->h2,
  2062. stream->id);
  2063. want_recv = (want_recv || c_exhaust || s_exhaust);
  2064. want_send = (!s_exhaust && want_send) ||
  2065. (!c_exhaust && nghttp2_session_want_write(ctx->h2));
  2066. Curl_pollset_set(data, ps, sock, want_recv, want_send);
  2067. CF_DATA_RESTORE(cf, save);
  2068. }
  2069. }
  2070. static CURLcode cf_h2_connect(struct Curl_cfilter *cf,
  2071. struct Curl_easy *data,
  2072. bool blocking, bool *done)
  2073. {
  2074. struct cf_h2_ctx *ctx = cf->ctx;
  2075. CURLcode result = CURLE_OK;
  2076. struct cf_call_data save;
  2077. if(cf->connected) {
  2078. *done = TRUE;
  2079. return CURLE_OK;
  2080. }
  2081. /* Connect the lower filters first */
  2082. if(!cf->next->connected) {
  2083. result = Curl_conn_cf_connect(cf->next, data, blocking, done);
  2084. if(result || !*done)
  2085. return result;
  2086. }
  2087. *done = FALSE;
  2088. CF_DATA_SAVE(save, cf, data);
  2089. if(!ctx->h2) {
  2090. result = cf_h2_ctx_init(cf, data, FALSE);
  2091. if(result)
  2092. goto out;
  2093. }
  2094. result = h2_progress_ingress(cf, data, H2_CHUNK_SIZE);
  2095. if(result)
  2096. goto out;
  2097. /* Send out our SETTINGS and ACKs and such. If that blocks, we
  2098. * have it buffered and can count this filter as being connected */
  2099. result = h2_progress_egress(cf, data);
  2100. if(result == CURLE_AGAIN)
  2101. result = CURLE_OK;
  2102. else if(result)
  2103. goto out;
  2104. *done = TRUE;
  2105. cf->connected = TRUE;
  2106. result = CURLE_OK;
  2107. out:
  2108. CURL_TRC_CF(data, cf, "cf_connect() -> %d, %d, ", result, *done);
  2109. CF_DATA_RESTORE(cf, save);
  2110. return result;
  2111. }
  2112. static void cf_h2_close(struct Curl_cfilter *cf, struct Curl_easy *data)
  2113. {
  2114. struct cf_h2_ctx *ctx = cf->ctx;
  2115. if(ctx) {
  2116. struct cf_call_data save;
  2117. CF_DATA_SAVE(save, cf, data);
  2118. cf_h2_ctx_clear(ctx);
  2119. CF_DATA_RESTORE(cf, save);
  2120. }
  2121. if(cf->next)
  2122. cf->next->cft->do_close(cf->next, data);
  2123. }
  2124. static void cf_h2_destroy(struct Curl_cfilter *cf, struct Curl_easy *data)
  2125. {
  2126. struct cf_h2_ctx *ctx = cf->ctx;
  2127. (void)data;
  2128. if(ctx) {
  2129. cf_h2_ctx_free(ctx);
  2130. cf->ctx = NULL;
  2131. }
  2132. }
  2133. static CURLcode http2_data_pause(struct Curl_cfilter *cf,
  2134. struct Curl_easy *data,
  2135. bool pause)
  2136. {
  2137. #ifdef NGHTTP2_HAS_SET_LOCAL_WINDOW_SIZE
  2138. struct cf_h2_ctx *ctx = cf->ctx;
  2139. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  2140. DEBUGASSERT(data);
  2141. if(ctx && ctx->h2 && stream) {
  2142. uint32_t window = pause? 0 : stream->local_window_size;
  2143. int rv = nghttp2_session_set_local_window_size(ctx->h2,
  2144. NGHTTP2_FLAG_NONE,
  2145. stream->id,
  2146. window);
  2147. if(rv) {
  2148. failf(data, "nghttp2_session_set_local_window_size() failed: %s(%d)",
  2149. nghttp2_strerror(rv), rv);
  2150. return CURLE_HTTP2;
  2151. }
  2152. if(!pause)
  2153. drain_stream(cf, data, stream);
  2154. /* attempt to send the window update */
  2155. (void)h2_progress_egress(cf, data);
  2156. if(!pause) {
  2157. /* Unpausing a h2 transfer, requires it to be run again. The server
  2158. * may send new DATA on us increasing the flow window, and it may
  2159. * not. We may have already buffered and exhausted the new window
  2160. * by operating on things in flight during the handling of other
  2161. * transfers. */
  2162. drain_stream(cf, data, stream);
  2163. Curl_expire(data, 0, EXPIRE_RUN_NOW);
  2164. }
  2165. DEBUGF(infof(data, "Set HTTP/2 window size to %u for stream %u",
  2166. window, stream->id));
  2167. #ifdef DEBUGBUILD
  2168. {
  2169. /* read out the stream local window again */
  2170. uint32_t window2 =
  2171. nghttp2_session_get_stream_local_window_size(ctx->h2,
  2172. stream->id);
  2173. DEBUGF(infof(data, "HTTP/2 window size is now %u for stream %u",
  2174. window2, stream->id));
  2175. }
  2176. #endif
  2177. }
  2178. #endif
  2179. return CURLE_OK;
  2180. }
  2181. static CURLcode cf_h2_cntrl(struct Curl_cfilter *cf,
  2182. struct Curl_easy *data,
  2183. int event, int arg1, void *arg2)
  2184. {
  2185. CURLcode result = CURLE_OK;
  2186. struct cf_call_data save;
  2187. (void)arg2;
  2188. CF_DATA_SAVE(save, cf, data);
  2189. switch(event) {
  2190. case CF_CTRL_DATA_SETUP:
  2191. break;
  2192. case CF_CTRL_DATA_PAUSE:
  2193. result = http2_data_pause(cf, data, (arg1 != 0));
  2194. break;
  2195. case CF_CTRL_DATA_DONE_SEND:
  2196. result = http2_data_done_send(cf, data);
  2197. break;
  2198. case CF_CTRL_DATA_DETACH:
  2199. http2_data_done(cf, data);
  2200. break;
  2201. case CF_CTRL_DATA_DONE:
  2202. http2_data_done(cf, data);
  2203. break;
  2204. default:
  2205. break;
  2206. }
  2207. CF_DATA_RESTORE(cf, save);
  2208. return result;
  2209. }
  2210. static bool cf_h2_data_pending(struct Curl_cfilter *cf,
  2211. const struct Curl_easy *data)
  2212. {
  2213. struct cf_h2_ctx *ctx = cf->ctx;
  2214. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  2215. if(ctx && (!Curl_bufq_is_empty(&ctx->inbufq)
  2216. || (stream && !Curl_bufq_is_empty(&stream->sendbuf))))
  2217. return TRUE;
  2218. return cf->next? cf->next->cft->has_data_pending(cf->next, data) : FALSE;
  2219. }
  2220. static bool cf_h2_is_alive(struct Curl_cfilter *cf,
  2221. struct Curl_easy *data,
  2222. bool *input_pending)
  2223. {
  2224. struct cf_h2_ctx *ctx = cf->ctx;
  2225. CURLcode result;
  2226. struct cf_call_data save;
  2227. CF_DATA_SAVE(save, cf, data);
  2228. result = (ctx && ctx->h2 && http2_connisalive(cf, data, input_pending));
  2229. CURL_TRC_CF(data, cf, "conn alive -> %d, input_pending=%d",
  2230. result, *input_pending);
  2231. CF_DATA_RESTORE(cf, save);
  2232. return result;
  2233. }
  2234. static CURLcode cf_h2_keep_alive(struct Curl_cfilter *cf,
  2235. struct Curl_easy *data)
  2236. {
  2237. CURLcode result;
  2238. struct cf_call_data save;
  2239. CF_DATA_SAVE(save, cf, data);
  2240. result = http2_send_ping(cf, data);
  2241. CF_DATA_RESTORE(cf, save);
  2242. return result;
  2243. }
  2244. static CURLcode cf_h2_query(struct Curl_cfilter *cf,
  2245. struct Curl_easy *data,
  2246. int query, int *pres1, void *pres2)
  2247. {
  2248. struct cf_h2_ctx *ctx = cf->ctx;
  2249. struct cf_call_data save;
  2250. size_t effective_max;
  2251. switch(query) {
  2252. case CF_QUERY_MAX_CONCURRENT:
  2253. DEBUGASSERT(pres1);
  2254. CF_DATA_SAVE(save, cf, data);
  2255. if(nghttp2_session_check_request_allowed(ctx->h2) == 0) {
  2256. /* the limit is what we have in use right now */
  2257. effective_max = CONN_INUSE(cf->conn);
  2258. }
  2259. else {
  2260. effective_max = ctx->max_concurrent_streams;
  2261. }
  2262. *pres1 = (effective_max > INT_MAX)? INT_MAX : (int)effective_max;
  2263. CF_DATA_RESTORE(cf, save);
  2264. return CURLE_OK;
  2265. default:
  2266. break;
  2267. }
  2268. return cf->next?
  2269. cf->next->cft->query(cf->next, data, query, pres1, pres2) :
  2270. CURLE_UNKNOWN_OPTION;
  2271. }
  2272. struct Curl_cftype Curl_cft_nghttp2 = {
  2273. "HTTP/2",
  2274. CF_TYPE_MULTIPLEX,
  2275. CURL_LOG_LVL_NONE,
  2276. cf_h2_destroy,
  2277. cf_h2_connect,
  2278. cf_h2_close,
  2279. Curl_cf_def_get_host,
  2280. cf_h2_adjust_pollset,
  2281. cf_h2_data_pending,
  2282. cf_h2_send,
  2283. cf_h2_recv,
  2284. cf_h2_cntrl,
  2285. cf_h2_is_alive,
  2286. cf_h2_keep_alive,
  2287. cf_h2_query,
  2288. };
  2289. static CURLcode http2_cfilter_add(struct Curl_cfilter **pcf,
  2290. struct Curl_easy *data,
  2291. struct connectdata *conn,
  2292. int sockindex,
  2293. bool via_h1_upgrade)
  2294. {
  2295. struct Curl_cfilter *cf = NULL;
  2296. struct cf_h2_ctx *ctx;
  2297. CURLcode result = CURLE_OUT_OF_MEMORY;
  2298. DEBUGASSERT(data->conn);
  2299. ctx = calloc(1, sizeof(*ctx));
  2300. if(!ctx)
  2301. goto out;
  2302. result = Curl_cf_create(&cf, &Curl_cft_nghttp2, ctx);
  2303. if(result)
  2304. goto out;
  2305. ctx = NULL;
  2306. Curl_conn_cf_add(data, conn, sockindex, cf);
  2307. result = cf_h2_ctx_init(cf, data, via_h1_upgrade);
  2308. out:
  2309. if(result)
  2310. cf_h2_ctx_free(ctx);
  2311. *pcf = result? NULL : cf;
  2312. return result;
  2313. }
  2314. static CURLcode http2_cfilter_insert_after(struct Curl_cfilter *cf,
  2315. struct Curl_easy *data,
  2316. bool via_h1_upgrade)
  2317. {
  2318. struct Curl_cfilter *cf_h2 = NULL;
  2319. struct cf_h2_ctx *ctx;
  2320. CURLcode result = CURLE_OUT_OF_MEMORY;
  2321. (void)data;
  2322. ctx = calloc(1, sizeof(*ctx));
  2323. if(!ctx)
  2324. goto out;
  2325. result = Curl_cf_create(&cf_h2, &Curl_cft_nghttp2, ctx);
  2326. if(result)
  2327. goto out;
  2328. ctx = NULL;
  2329. Curl_conn_cf_insert_after(cf, cf_h2);
  2330. result = cf_h2_ctx_init(cf_h2, data, via_h1_upgrade);
  2331. out:
  2332. if(result)
  2333. cf_h2_ctx_free(ctx);
  2334. return result;
  2335. }
  2336. static bool Curl_cf_is_http2(struct Curl_cfilter *cf,
  2337. const struct Curl_easy *data)
  2338. {
  2339. (void)data;
  2340. for(; cf; cf = cf->next) {
  2341. if(cf->cft == &Curl_cft_nghttp2)
  2342. return TRUE;
  2343. if(cf->cft->flags & CF_TYPE_IP_CONNECT)
  2344. return FALSE;
  2345. }
  2346. return FALSE;
  2347. }
  2348. bool Curl_conn_is_http2(const struct Curl_easy *data,
  2349. const struct connectdata *conn,
  2350. int sockindex)
  2351. {
  2352. return conn? Curl_cf_is_http2(conn->cfilter[sockindex], data) : FALSE;
  2353. }
  2354. bool Curl_http2_may_switch(struct Curl_easy *data,
  2355. struct connectdata *conn,
  2356. int sockindex)
  2357. {
  2358. (void)sockindex;
  2359. if(!Curl_conn_is_http2(data, conn, sockindex) &&
  2360. data->state.httpwant == CURL_HTTP_VERSION_2_PRIOR_KNOWLEDGE) {
  2361. #ifndef CURL_DISABLE_PROXY
  2362. if(conn->bits.httpproxy && !conn->bits.tunnel_proxy) {
  2363. /* We don't support HTTP/2 proxies yet. Also it's debatable
  2364. whether or not this setting should apply to HTTP/2 proxies. */
  2365. infof(data, "Ignoring HTTP/2 prior knowledge due to proxy");
  2366. return FALSE;
  2367. }
  2368. #endif
  2369. return TRUE;
  2370. }
  2371. return FALSE;
  2372. }
  2373. CURLcode Curl_http2_switch(struct Curl_easy *data,
  2374. struct connectdata *conn, int sockindex)
  2375. {
  2376. struct Curl_cfilter *cf;
  2377. CURLcode result;
  2378. DEBUGASSERT(!Curl_conn_is_http2(data, conn, sockindex));
  2379. DEBUGF(infof(data, "switching to HTTP/2"));
  2380. result = http2_cfilter_add(&cf, data, conn, sockindex, FALSE);
  2381. if(result)
  2382. return result;
  2383. conn->httpversion = 20; /* we know we're on HTTP/2 now */
  2384. conn->bits.multiplex = TRUE; /* at least potentially multiplexed */
  2385. conn->bundle->multiuse = BUNDLE_MULTIPLEX;
  2386. Curl_multi_connchanged(data->multi);
  2387. if(cf->next) {
  2388. bool done;
  2389. return Curl_conn_cf_connect(cf, data, FALSE, &done);
  2390. }
  2391. return CURLE_OK;
  2392. }
  2393. CURLcode Curl_http2_switch_at(struct Curl_cfilter *cf, struct Curl_easy *data)
  2394. {
  2395. struct Curl_cfilter *cf_h2;
  2396. CURLcode result;
  2397. DEBUGASSERT(!Curl_cf_is_http2(cf, data));
  2398. result = http2_cfilter_insert_after(cf, data, FALSE);
  2399. if(result)
  2400. return result;
  2401. cf_h2 = cf->next;
  2402. cf->conn->httpversion = 20; /* we know we're on HTTP/2 now */
  2403. cf->conn->bits.multiplex = TRUE; /* at least potentially multiplexed */
  2404. cf->conn->bundle->multiuse = BUNDLE_MULTIPLEX;
  2405. Curl_multi_connchanged(data->multi);
  2406. if(cf_h2->next) {
  2407. bool done;
  2408. return Curl_conn_cf_connect(cf_h2, data, FALSE, &done);
  2409. }
  2410. return CURLE_OK;
  2411. }
  2412. CURLcode Curl_http2_upgrade(struct Curl_easy *data,
  2413. struct connectdata *conn, int sockindex,
  2414. const char *mem, size_t nread)
  2415. {
  2416. struct Curl_cfilter *cf;
  2417. struct cf_h2_ctx *ctx;
  2418. CURLcode result;
  2419. DEBUGASSERT(!Curl_conn_is_http2(data, conn, sockindex));
  2420. DEBUGF(infof(data, "upgrading to HTTP/2"));
  2421. DEBUGASSERT(data->req.upgr101 == UPGR101_RECEIVED);
  2422. result = http2_cfilter_add(&cf, data, conn, sockindex, TRUE);
  2423. if(result)
  2424. return result;
  2425. DEBUGASSERT(cf->cft == &Curl_cft_nghttp2);
  2426. ctx = cf->ctx;
  2427. if(nread > 0) {
  2428. /* Remaining data from the protocol switch reply is already using
  2429. * the switched protocol, ie. HTTP/2. We add that to the network
  2430. * inbufq. */
  2431. ssize_t copied;
  2432. copied = Curl_bufq_write(&ctx->inbufq,
  2433. (const unsigned char *)mem, nread, &result);
  2434. if(copied < 0) {
  2435. failf(data, "error on copying HTTP Upgrade response: %d", result);
  2436. return CURLE_RECV_ERROR;
  2437. }
  2438. if((size_t)copied < nread) {
  2439. failf(data, "connection buffer size could not take all data "
  2440. "from HTTP Upgrade response header: copied=%zd, datalen=%zu",
  2441. copied, nread);
  2442. return CURLE_HTTP2;
  2443. }
  2444. infof(data, "Copied HTTP/2 data in stream buffer to connection buffer"
  2445. " after upgrade: len=%zu", nread);
  2446. }
  2447. conn->httpversion = 20; /* we know we're on HTTP/2 now */
  2448. conn->bits.multiplex = TRUE; /* at least potentially multiplexed */
  2449. conn->bundle->multiuse = BUNDLE_MULTIPLEX;
  2450. Curl_multi_connchanged(data->multi);
  2451. if(cf->next) {
  2452. bool done;
  2453. return Curl_conn_cf_connect(cf, data, FALSE, &done);
  2454. }
  2455. return CURLE_OK;
  2456. }
  2457. /* Only call this function for a transfer that already got an HTTP/2
  2458. CURLE_HTTP2_STREAM error! */
  2459. bool Curl_h2_http_1_1_error(struct Curl_easy *data)
  2460. {
  2461. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  2462. return (stream && stream->error == NGHTTP2_HTTP_1_1_REQUIRED);
  2463. }
  2464. #else /* !USE_NGHTTP2 */
  2465. /* Satisfy external references even if http2 is not compiled in. */
  2466. #include <curl/curl.h>
  2467. char *curl_pushheader_bynum(struct curl_pushheaders *h, size_t num)
  2468. {
  2469. (void) h;
  2470. (void) num;
  2471. return NULL;
  2472. }
  2473. char *curl_pushheader_byname(struct curl_pushheaders *h, const char *header)
  2474. {
  2475. (void) h;
  2476. (void) header;
  2477. return NULL;
  2478. }
  2479. #endif /* USE_NGHTTP2 */