http2.c 86 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786
  1. /***************************************************************************
  2. * _ _ ____ _
  3. * Project ___| | | | _ \| |
  4. * / __| | | | |_) | |
  5. * | (__| |_| | _ <| |___
  6. * \___|\___/|_| \_\_____|
  7. *
  8. * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
  9. *
  10. * This software is licensed as described in the file COPYING, which
  11. * you should have received as part of this distribution. The terms
  12. * are also available at https://curl.se/docs/copyright.html.
  13. *
  14. * You may opt to use, copy, modify, merge, publish, distribute and/or sell
  15. * copies of the Software, and permit persons to whom the Software is
  16. * furnished to do so, under the terms of the COPYING file.
  17. *
  18. * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
  19. * KIND, either express or implied.
  20. *
  21. * SPDX-License-Identifier: curl
  22. *
  23. ***************************************************************************/
  24. #include "curl_setup.h"
  25. #ifdef USE_NGHTTP2
  26. #include <stdint.h>
  27. #include <nghttp2/nghttp2.h>
  28. #include "urldata.h"
  29. #include "bufq.h"
  30. #include "http1.h"
  31. #include "http2.h"
  32. #include "http.h"
  33. #include "sendf.h"
  34. #include "select.h"
  35. #include "curl_base64.h"
  36. #include "strcase.h"
  37. #include "multiif.h"
  38. #include "url.h"
  39. #include "urlapi-int.h"
  40. #include "cfilters.h"
  41. #include "connect.h"
  42. #include "rand.h"
  43. #include "strtoofft.h"
  44. #include "strdup.h"
  45. #include "transfer.h"
  46. #include "dynbuf.h"
  47. #include "headers.h"
  48. /* The last 3 #include files should be in this order */
  49. #include "curl_printf.h"
  50. #include "curl_memory.h"
  51. #include "memdebug.h"
  52. #if (NGHTTP2_VERSION_NUM < 0x010c00)
  53. #error too old nghttp2 version, upgrade!
  54. #endif
  55. #ifdef CURL_DISABLE_VERBOSE_STRINGS
  56. #define nghttp2_session_callbacks_set_error_callback(x,y)
  57. #endif
  58. #if (NGHTTP2_VERSION_NUM >= 0x010c00)
  59. #define NGHTTP2_HAS_SET_LOCAL_WINDOW_SIZE 1
  60. #endif
  61. /* buffer dimensioning:
  62. * use 16K as chunk size, as that fits H2 DATA frames well */
  63. #define H2_CHUNK_SIZE (16 * 1024)
  64. /* this is how much we want "in flight" for a stream */
  65. #define H2_STREAM_WINDOW_SIZE (10 * 1024 * 1024)
  66. /* on receiving from TLS, we prep for holding a full stream window */
  67. #define H2_NW_RECV_CHUNKS (H2_STREAM_WINDOW_SIZE / H2_CHUNK_SIZE)
  68. /* on send into TLS, we just want to accumulate small frames */
  69. #define H2_NW_SEND_CHUNKS 1
  70. /* stream recv/send chunks are a result of window / chunk sizes */
  71. #define H2_STREAM_RECV_CHUNKS (H2_STREAM_WINDOW_SIZE / H2_CHUNK_SIZE)
  72. /* keep smaller stream upload buffer (default h2 window size) to have
  73. * our progress bars and "upload done" reporting closer to reality */
  74. #define H2_STREAM_SEND_CHUNKS ((64 * 1024) / H2_CHUNK_SIZE)
  75. /* spare chunks we keep for a full window */
  76. #define H2_STREAM_POOL_SPARES (H2_STREAM_WINDOW_SIZE / H2_CHUNK_SIZE)
  77. /* We need to accommodate the max number of streams with their window
  78. * sizes on the overall connection. Streams might become PAUSED which
  79. * will block their received QUOTA in the connection window. And if we
  80. * run out of space, the server is blocked from sending us any data.
  81. * See #10988 for an issue with this. */
  82. #define HTTP2_HUGE_WINDOW_SIZE (100 * H2_STREAM_WINDOW_SIZE)
  83. #define H2_SETTINGS_IV_LEN 3
  84. #define H2_BINSETTINGS_LEN 80
  85. static int populate_settings(nghttp2_settings_entry *iv,
  86. struct Curl_easy *data)
  87. {
  88. iv[0].settings_id = NGHTTP2_SETTINGS_MAX_CONCURRENT_STREAMS;
  89. iv[0].value = Curl_multi_max_concurrent_streams(data->multi);
  90. iv[1].settings_id = NGHTTP2_SETTINGS_INITIAL_WINDOW_SIZE;
  91. iv[1].value = H2_STREAM_WINDOW_SIZE;
  92. iv[2].settings_id = NGHTTP2_SETTINGS_ENABLE_PUSH;
  93. iv[2].value = data->multi->push_cb != NULL;
  94. return 3;
  95. }
  96. static ssize_t populate_binsettings(uint8_t *binsettings,
  97. struct Curl_easy *data)
  98. {
  99. nghttp2_settings_entry iv[H2_SETTINGS_IV_LEN];
  100. int ivlen;
  101. ivlen = populate_settings(iv, data);
  102. /* this returns number of bytes it wrote or a negative number on error. */
  103. return nghttp2_pack_settings_payload(binsettings, H2_BINSETTINGS_LEN,
  104. iv, ivlen);
  105. }
  106. struct cf_h2_ctx {
  107. nghttp2_session *h2;
  108. /* The easy handle used in the current filter call, cleared at return */
  109. struct cf_call_data call_data;
  110. struct bufq inbufq; /* network input */
  111. struct bufq outbufq; /* network output */
  112. struct bufc_pool stream_bufcp; /* spares for stream buffers */
  113. size_t drain_total; /* sum of all stream's UrlState drain */
  114. uint32_t max_concurrent_streams;
  115. int32_t goaway_error;
  116. int32_t last_stream_id;
  117. BIT(conn_closed);
  118. BIT(goaway);
  119. BIT(enable_push);
  120. BIT(nw_out_blocked);
  121. };
  122. /* How to access `call_data` from a cf_h2 filter */
  123. #undef CF_CTX_CALL_DATA
  124. #define CF_CTX_CALL_DATA(cf) \
  125. ((struct cf_h2_ctx *)(cf)->ctx)->call_data
  126. static void cf_h2_ctx_clear(struct cf_h2_ctx *ctx)
  127. {
  128. struct cf_call_data save = ctx->call_data;
  129. if(ctx->h2) {
  130. nghttp2_session_del(ctx->h2);
  131. }
  132. Curl_bufq_free(&ctx->inbufq);
  133. Curl_bufq_free(&ctx->outbufq);
  134. Curl_bufcp_free(&ctx->stream_bufcp);
  135. memset(ctx, 0, sizeof(*ctx));
  136. ctx->call_data = save;
  137. }
  138. static void cf_h2_ctx_free(struct cf_h2_ctx *ctx)
  139. {
  140. if(ctx) {
  141. cf_h2_ctx_clear(ctx);
  142. free(ctx);
  143. }
  144. }
  145. static CURLcode h2_progress_egress(struct Curl_cfilter *cf,
  146. struct Curl_easy *data);
  147. /**
  148. * All about the H2 internals of a stream
  149. */
  150. struct h2_stream_ctx {
  151. struct bufq recvbuf; /* response buffer */
  152. struct bufq sendbuf; /* request buffer */
  153. struct h1_req_parser h1; /* parsing the request */
  154. struct dynhds resp_trailers; /* response trailer fields */
  155. size_t resp_hds_len; /* amount of response header bytes in recvbuf */
  156. size_t upload_blocked_len;
  157. curl_off_t upload_left; /* number of request bytes left to upload */
  158. curl_off_t nrcvd_data; /* number of DATA bytes received */
  159. char **push_headers; /* allocated array */
  160. size_t push_headers_used; /* number of entries filled in */
  161. size_t push_headers_alloc; /* number of entries allocated */
  162. int status_code; /* HTTP response status code */
  163. uint32_t error; /* stream error code */
  164. uint32_t local_window_size; /* the local recv window size */
  165. int32_t id; /* HTTP/2 protocol identifier for stream */
  166. BIT(resp_hds_complete); /* we have a complete, final response */
  167. BIT(closed); /* TRUE on stream close */
  168. BIT(reset); /* TRUE on stream reset */
  169. BIT(close_handled); /* TRUE if stream closure is handled by libcurl */
  170. BIT(bodystarted);
  171. BIT(send_closed); /* transfer is done sending, we might have still
  172. buffered data in stream->sendbuf to upload. */
  173. };
  174. #define H2_STREAM_CTX(d) ((struct h2_stream_ctx *)(((d) && \
  175. (d)->req.p.http)? \
  176. ((struct HTTP *)(d)->req.p.http)->h2_ctx \
  177. : NULL))
  178. #define H2_STREAM_LCTX(d) ((struct HTTP *)(d)->req.p.http)->h2_ctx
  179. #define H2_STREAM_ID(d) (H2_STREAM_CTX(d)? \
  180. H2_STREAM_CTX(d)->id : -2)
  181. /*
  182. * Mark this transfer to get "drained".
  183. */
  184. static void drain_stream(struct Curl_cfilter *cf,
  185. struct Curl_easy *data,
  186. struct h2_stream_ctx *stream)
  187. {
  188. unsigned char bits;
  189. (void)cf;
  190. bits = CURL_CSELECT_IN;
  191. if(!stream->send_closed &&
  192. (stream->upload_left || stream->upload_blocked_len))
  193. bits |= CURL_CSELECT_OUT;
  194. if(data->state.select_bits != bits) {
  195. CURL_TRC_CF(data, cf, "[%d] DRAIN select_bits=%x",
  196. stream->id, bits);
  197. data->state.select_bits = bits;
  198. Curl_expire(data, 0, EXPIRE_RUN_NOW);
  199. }
  200. }
  201. static CURLcode http2_data_setup(struct Curl_cfilter *cf,
  202. struct Curl_easy *data,
  203. struct h2_stream_ctx **pstream)
  204. {
  205. struct cf_h2_ctx *ctx = cf->ctx;
  206. struct h2_stream_ctx *stream;
  207. (void)cf;
  208. DEBUGASSERT(data);
  209. if(!data->req.p.http) {
  210. failf(data, "initialization failure, transfer not http initialized");
  211. return CURLE_FAILED_INIT;
  212. }
  213. stream = H2_STREAM_CTX(data);
  214. if(stream) {
  215. *pstream = stream;
  216. return CURLE_OK;
  217. }
  218. stream = calloc(1, sizeof(*stream));
  219. if(!stream)
  220. return CURLE_OUT_OF_MEMORY;
  221. stream->id = -1;
  222. Curl_bufq_initp(&stream->sendbuf, &ctx->stream_bufcp,
  223. H2_STREAM_SEND_CHUNKS, BUFQ_OPT_NONE);
  224. Curl_h1_req_parse_init(&stream->h1, H1_PARSE_DEFAULT_MAX_LINE_LEN);
  225. Curl_dynhds_init(&stream->resp_trailers, 0, DYN_HTTP_REQUEST);
  226. stream->resp_hds_len = 0;
  227. stream->bodystarted = FALSE;
  228. stream->status_code = -1;
  229. stream->closed = FALSE;
  230. stream->close_handled = FALSE;
  231. stream->error = NGHTTP2_NO_ERROR;
  232. stream->local_window_size = H2_STREAM_WINDOW_SIZE;
  233. stream->upload_left = 0;
  234. stream->nrcvd_data = 0;
  235. H2_STREAM_LCTX(data) = stream;
  236. *pstream = stream;
  237. return CURLE_OK;
  238. }
  239. static void free_push_headers(struct h2_stream_ctx *stream)
  240. {
  241. size_t i;
  242. for(i = 0; i<stream->push_headers_used; i++)
  243. free(stream->push_headers[i]);
  244. Curl_safefree(stream->push_headers);
  245. stream->push_headers_used = 0;
  246. }
  247. static void http2_data_done(struct Curl_cfilter *cf,
  248. struct Curl_easy *data, bool premature)
  249. {
  250. struct cf_h2_ctx *ctx = cf->ctx;
  251. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  252. DEBUGASSERT(ctx);
  253. (void)premature;
  254. if(!stream)
  255. return;
  256. if(ctx->h2) {
  257. bool flush_egress = FALSE;
  258. /* returns error if stream not known, which is fine here */
  259. (void)nghttp2_session_set_stream_user_data(ctx->h2, stream->id, NULL);
  260. if(!stream->closed && stream->id > 0) {
  261. /* RST_STREAM */
  262. CURL_TRC_CF(data, cf, "[%d] premature DATA_DONE, RST stream",
  263. stream->id);
  264. stream->closed = TRUE;
  265. stream->reset = TRUE;
  266. stream->send_closed = TRUE;
  267. nghttp2_submit_rst_stream(ctx->h2, NGHTTP2_FLAG_NONE,
  268. stream->id, NGHTTP2_STREAM_CLOSED);
  269. flush_egress = TRUE;
  270. }
  271. if(flush_egress)
  272. nghttp2_session_send(ctx->h2);
  273. }
  274. Curl_bufq_free(&stream->sendbuf);
  275. Curl_h1_req_parse_free(&stream->h1);
  276. Curl_dynhds_free(&stream->resp_trailers);
  277. free_push_headers(stream);
  278. free(stream);
  279. H2_STREAM_LCTX(data) = NULL;
  280. }
  281. static int h2_client_new(struct Curl_cfilter *cf,
  282. nghttp2_session_callbacks *cbs)
  283. {
  284. struct cf_h2_ctx *ctx = cf->ctx;
  285. nghttp2_option *o;
  286. int rc = nghttp2_option_new(&o);
  287. if(rc)
  288. return rc;
  289. /* We handle window updates ourself to enforce buffer limits */
  290. nghttp2_option_set_no_auto_window_update(o, 1);
  291. #if NGHTTP2_VERSION_NUM >= 0x013200
  292. /* with 1.50.0 */
  293. /* turn off RFC 9113 leading and trailing white spaces validation against
  294. HTTP field value. */
  295. nghttp2_option_set_no_rfc9113_leading_and_trailing_ws_validation(o, 1);
  296. #endif
  297. rc = nghttp2_session_client_new2(&ctx->h2, cbs, cf, o);
  298. nghttp2_option_del(o);
  299. return rc;
  300. }
  301. static ssize_t nw_in_reader(void *reader_ctx,
  302. unsigned char *buf, size_t buflen,
  303. CURLcode *err)
  304. {
  305. struct Curl_cfilter *cf = reader_ctx;
  306. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  307. return Curl_conn_cf_recv(cf->next, data, (char *)buf, buflen, err);
  308. }
  309. static ssize_t nw_out_writer(void *writer_ctx,
  310. const unsigned char *buf, size_t buflen,
  311. CURLcode *err)
  312. {
  313. struct Curl_cfilter *cf = writer_ctx;
  314. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  315. if(data) {
  316. ssize_t nwritten = Curl_conn_cf_send(cf->next, data,
  317. (const char *)buf, buflen, err);
  318. if(nwritten > 0)
  319. CURL_TRC_CF(data, cf, "[0] egress: wrote %zd bytes", nwritten);
  320. return nwritten;
  321. }
  322. return 0;
  323. }
  324. static ssize_t send_callback(nghttp2_session *h2,
  325. const uint8_t *mem, size_t length, int flags,
  326. void *userp);
  327. static int on_frame_recv(nghttp2_session *session, const nghttp2_frame *frame,
  328. void *userp);
  329. #ifndef CURL_DISABLE_VERBOSE_STRINGS
  330. static int on_frame_send(nghttp2_session *session, const nghttp2_frame *frame,
  331. void *userp);
  332. #endif
  333. static int on_data_chunk_recv(nghttp2_session *session, uint8_t flags,
  334. int32_t stream_id,
  335. const uint8_t *mem, size_t len, void *userp);
  336. static int on_stream_close(nghttp2_session *session, int32_t stream_id,
  337. uint32_t error_code, void *userp);
  338. static int on_begin_headers(nghttp2_session *session,
  339. const nghttp2_frame *frame, void *userp);
  340. static int on_header(nghttp2_session *session, const nghttp2_frame *frame,
  341. const uint8_t *name, size_t namelen,
  342. const uint8_t *value, size_t valuelen,
  343. uint8_t flags,
  344. void *userp);
  345. static int error_callback(nghttp2_session *session, const char *msg,
  346. size_t len, void *userp);
  347. /*
  348. * Initialize the cfilter context
  349. */
  350. static CURLcode cf_h2_ctx_init(struct Curl_cfilter *cf,
  351. struct Curl_easy *data,
  352. bool via_h1_upgrade)
  353. {
  354. struct cf_h2_ctx *ctx = cf->ctx;
  355. struct h2_stream_ctx *stream;
  356. CURLcode result = CURLE_OUT_OF_MEMORY;
  357. int rc;
  358. nghttp2_session_callbacks *cbs = NULL;
  359. DEBUGASSERT(!ctx->h2);
  360. Curl_bufcp_init(&ctx->stream_bufcp, H2_CHUNK_SIZE, H2_STREAM_POOL_SPARES);
  361. Curl_bufq_initp(&ctx->inbufq, &ctx->stream_bufcp, H2_NW_RECV_CHUNKS, 0);
  362. Curl_bufq_initp(&ctx->outbufq, &ctx->stream_bufcp, H2_NW_SEND_CHUNKS, 0);
  363. ctx->last_stream_id = 2147483647;
  364. rc = nghttp2_session_callbacks_new(&cbs);
  365. if(rc) {
  366. failf(data, "Couldn't initialize nghttp2 callbacks");
  367. goto out;
  368. }
  369. nghttp2_session_callbacks_set_send_callback(cbs, send_callback);
  370. nghttp2_session_callbacks_set_on_frame_recv_callback(cbs, on_frame_recv);
  371. #ifndef CURL_DISABLE_VERBOSE_STRINGS
  372. nghttp2_session_callbacks_set_on_frame_send_callback(cbs, on_frame_send);
  373. #endif
  374. nghttp2_session_callbacks_set_on_data_chunk_recv_callback(
  375. cbs, on_data_chunk_recv);
  376. nghttp2_session_callbacks_set_on_stream_close_callback(cbs, on_stream_close);
  377. nghttp2_session_callbacks_set_on_begin_headers_callback(
  378. cbs, on_begin_headers);
  379. nghttp2_session_callbacks_set_on_header_callback(cbs, on_header);
  380. nghttp2_session_callbacks_set_error_callback(cbs, error_callback);
  381. /* The nghttp2 session is not yet setup, do it */
  382. rc = h2_client_new(cf, cbs);
  383. if(rc) {
  384. failf(data, "Couldn't initialize nghttp2");
  385. goto out;
  386. }
  387. ctx->max_concurrent_streams = DEFAULT_MAX_CONCURRENT_STREAMS;
  388. if(via_h1_upgrade) {
  389. /* HTTP/1.1 Upgrade issued. H2 Settings have already been submitted
  390. * in the H1 request and we upgrade from there. This stream
  391. * is opened implicitly as #1. */
  392. uint8_t binsettings[H2_BINSETTINGS_LEN];
  393. ssize_t binlen; /* length of the binsettings data */
  394. binlen = populate_binsettings(binsettings, data);
  395. if(binlen <= 0) {
  396. failf(data, "nghttp2 unexpectedly failed on pack_settings_payload");
  397. result = CURLE_FAILED_INIT;
  398. goto out;
  399. }
  400. result = http2_data_setup(cf, data, &stream);
  401. if(result)
  402. goto out;
  403. DEBUGASSERT(stream);
  404. stream->id = 1;
  405. /* queue SETTINGS frame (again) */
  406. rc = nghttp2_session_upgrade2(ctx->h2, binsettings, binlen,
  407. data->state.httpreq == HTTPREQ_HEAD,
  408. NULL);
  409. if(rc) {
  410. failf(data, "nghttp2_session_upgrade2() failed: %s(%d)",
  411. nghttp2_strerror(rc), rc);
  412. result = CURLE_HTTP2;
  413. goto out;
  414. }
  415. rc = nghttp2_session_set_stream_user_data(ctx->h2, stream->id,
  416. data);
  417. if(rc) {
  418. infof(data, "http/2: failed to set user_data for stream %u",
  419. stream->id);
  420. DEBUGASSERT(0);
  421. }
  422. CURL_TRC_CF(data, cf, "created session via Upgrade");
  423. }
  424. else {
  425. nghttp2_settings_entry iv[H2_SETTINGS_IV_LEN];
  426. int ivlen;
  427. ivlen = populate_settings(iv, data);
  428. rc = nghttp2_submit_settings(ctx->h2, NGHTTP2_FLAG_NONE,
  429. iv, ivlen);
  430. if(rc) {
  431. failf(data, "nghttp2_submit_settings() failed: %s(%d)",
  432. nghttp2_strerror(rc), rc);
  433. result = CURLE_HTTP2;
  434. goto out;
  435. }
  436. }
  437. rc = nghttp2_session_set_local_window_size(ctx->h2, NGHTTP2_FLAG_NONE, 0,
  438. HTTP2_HUGE_WINDOW_SIZE);
  439. if(rc) {
  440. failf(data, "nghttp2_session_set_local_window_size() failed: %s(%d)",
  441. nghttp2_strerror(rc), rc);
  442. result = CURLE_HTTP2;
  443. goto out;
  444. }
  445. /* all set, traffic will be send on connect */
  446. result = CURLE_OK;
  447. CURL_TRC_CF(data, cf, "[0] created h2 session%s",
  448. via_h1_upgrade? " (via h1 upgrade)" : "");
  449. out:
  450. if(cbs)
  451. nghttp2_session_callbacks_del(cbs);
  452. return result;
  453. }
  454. /*
  455. * Returns nonzero if current HTTP/2 session should be closed.
  456. */
  457. static int should_close_session(struct cf_h2_ctx *ctx)
  458. {
  459. return ctx->drain_total == 0 && !nghttp2_session_want_read(ctx->h2) &&
  460. !nghttp2_session_want_write(ctx->h2);
  461. }
  462. /*
  463. * Processes pending input left in network input buffer.
  464. * This function returns 0 if it succeeds, or -1 and error code will
  465. * be assigned to *err.
  466. */
  467. static int h2_process_pending_input(struct Curl_cfilter *cf,
  468. struct Curl_easy *data,
  469. CURLcode *err)
  470. {
  471. struct cf_h2_ctx *ctx = cf->ctx;
  472. const unsigned char *buf;
  473. size_t blen;
  474. ssize_t rv;
  475. while(Curl_bufq_peek(&ctx->inbufq, &buf, &blen)) {
  476. rv = nghttp2_session_mem_recv(ctx->h2, (const uint8_t *)buf, blen);
  477. if(rv < 0) {
  478. failf(data,
  479. "process_pending_input: nghttp2_session_mem_recv() returned "
  480. "%zd:%s", rv, nghttp2_strerror((int)rv));
  481. *err = CURLE_RECV_ERROR;
  482. return -1;
  483. }
  484. Curl_bufq_skip(&ctx->inbufq, (size_t)rv);
  485. if(Curl_bufq_is_empty(&ctx->inbufq)) {
  486. break;
  487. }
  488. else {
  489. CURL_TRC_CF(data, cf, "process_pending_input: %zu bytes left "
  490. "in connection buffer", Curl_bufq_len(&ctx->inbufq));
  491. }
  492. }
  493. if(nghttp2_session_check_request_allowed(ctx->h2) == 0) {
  494. /* No more requests are allowed in the current session, so
  495. the connection may not be reused. This is set when a
  496. GOAWAY frame has been received or when the limit of stream
  497. identifiers has been reached. */
  498. connclose(cf->conn, "http/2: No new requests allowed");
  499. }
  500. return 0;
  501. }
  502. /*
  503. * The server may send us data at any point (e.g. PING frames). Therefore,
  504. * we cannot assume that an HTTP/2 socket is dead just because it is readable.
  505. *
  506. * Check the lower filters first and, if successful, peek at the socket
  507. * and distinguish between closed and data.
  508. */
  509. static bool http2_connisalive(struct Curl_cfilter *cf, struct Curl_easy *data,
  510. bool *input_pending)
  511. {
  512. struct cf_h2_ctx *ctx = cf->ctx;
  513. bool alive = TRUE;
  514. *input_pending = FALSE;
  515. if(!cf->next || !cf->next->cft->is_alive(cf->next, data, input_pending))
  516. return FALSE;
  517. if(*input_pending) {
  518. /* This happens before we've sent off a request and the connection is
  519. not in use by any other transfer, there shouldn't be any data here,
  520. only "protocol frames" */
  521. CURLcode result;
  522. ssize_t nread = -1;
  523. *input_pending = FALSE;
  524. nread = Curl_bufq_slurp(&ctx->inbufq, nw_in_reader, cf, &result);
  525. if(nread != -1) {
  526. CURL_TRC_CF(data, cf, "%zd bytes stray data read before trying "
  527. "h2 connection", nread);
  528. if(h2_process_pending_input(cf, data, &result) < 0)
  529. /* immediate error, considered dead */
  530. alive = FALSE;
  531. else {
  532. alive = !should_close_session(ctx);
  533. }
  534. }
  535. else if(result != CURLE_AGAIN) {
  536. /* the read failed so let's say this is dead anyway */
  537. alive = FALSE;
  538. }
  539. }
  540. return alive;
  541. }
  542. static CURLcode http2_send_ping(struct Curl_cfilter *cf,
  543. struct Curl_easy *data)
  544. {
  545. struct cf_h2_ctx *ctx = cf->ctx;
  546. int rc;
  547. rc = nghttp2_submit_ping(ctx->h2, 0, ZERO_NULL);
  548. if(rc) {
  549. failf(data, "nghttp2_submit_ping() failed: %s(%d)",
  550. nghttp2_strerror(rc), rc);
  551. return CURLE_HTTP2;
  552. }
  553. rc = nghttp2_session_send(ctx->h2);
  554. if(rc) {
  555. failf(data, "nghttp2_session_send() failed: %s(%d)",
  556. nghttp2_strerror(rc), rc);
  557. return CURLE_SEND_ERROR;
  558. }
  559. return CURLE_OK;
  560. }
  561. /*
  562. * Store nghttp2 version info in this buffer.
  563. */
  564. void Curl_http2_ver(char *p, size_t len)
  565. {
  566. nghttp2_info *h2 = nghttp2_version(0);
  567. (void)msnprintf(p, len, "nghttp2/%s", h2->version_str);
  568. }
  569. static CURLcode nw_out_flush(struct Curl_cfilter *cf,
  570. struct Curl_easy *data)
  571. {
  572. struct cf_h2_ctx *ctx = cf->ctx;
  573. ssize_t nwritten;
  574. CURLcode result;
  575. (void)data;
  576. if(Curl_bufq_is_empty(&ctx->outbufq))
  577. return CURLE_OK;
  578. nwritten = Curl_bufq_pass(&ctx->outbufq, nw_out_writer, cf, &result);
  579. if(nwritten < 0) {
  580. if(result == CURLE_AGAIN) {
  581. CURL_TRC_CF(data, cf, "flush nw send buffer(%zu) -> EAGAIN",
  582. Curl_bufq_len(&ctx->outbufq));
  583. ctx->nw_out_blocked = 1;
  584. }
  585. return result;
  586. }
  587. return Curl_bufq_is_empty(&ctx->outbufq)? CURLE_OK: CURLE_AGAIN;
  588. }
  589. /*
  590. * The implementation of nghttp2_send_callback type. Here we write |data| with
  591. * size |length| to the network and return the number of bytes actually
  592. * written. See the documentation of nghttp2_send_callback for the details.
  593. */
  594. static ssize_t send_callback(nghttp2_session *h2,
  595. const uint8_t *buf, size_t blen, int flags,
  596. void *userp)
  597. {
  598. struct Curl_cfilter *cf = userp;
  599. struct cf_h2_ctx *ctx = cf->ctx;
  600. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  601. ssize_t nwritten;
  602. CURLcode result = CURLE_OK;
  603. (void)h2;
  604. (void)flags;
  605. DEBUGASSERT(data);
  606. nwritten = Curl_bufq_write_pass(&ctx->outbufq, buf, blen,
  607. nw_out_writer, cf, &result);
  608. if(nwritten < 0) {
  609. if(result == CURLE_AGAIN) {
  610. ctx->nw_out_blocked = 1;
  611. return NGHTTP2_ERR_WOULDBLOCK;
  612. }
  613. failf(data, "Failed sending HTTP2 data");
  614. return NGHTTP2_ERR_CALLBACK_FAILURE;
  615. }
  616. if(!nwritten) {
  617. ctx->nw_out_blocked = 1;
  618. return NGHTTP2_ERR_WOULDBLOCK;
  619. }
  620. return nwritten;
  621. }
  622. /* We pass a pointer to this struct in the push callback, but the contents of
  623. the struct are hidden from the user. */
  624. struct curl_pushheaders {
  625. struct Curl_easy *data;
  626. const nghttp2_push_promise *frame;
  627. };
  628. /*
  629. * push header access function. Only to be used from within the push callback
  630. */
  631. char *curl_pushheader_bynum(struct curl_pushheaders *h, size_t num)
  632. {
  633. /* Verify that we got a good easy handle in the push header struct, mostly to
  634. detect rubbish input fast(er). */
  635. if(!h || !GOOD_EASY_HANDLE(h->data))
  636. return NULL;
  637. else {
  638. struct h2_stream_ctx *stream = H2_STREAM_CTX(h->data);
  639. if(stream && num < stream->push_headers_used)
  640. return stream->push_headers[num];
  641. }
  642. return NULL;
  643. }
  644. /*
  645. * push header access function. Only to be used from within the push callback
  646. */
  647. char *curl_pushheader_byname(struct curl_pushheaders *h, const char *header)
  648. {
  649. struct h2_stream_ctx *stream;
  650. size_t len;
  651. size_t i;
  652. /* Verify that we got a good easy handle in the push header struct,
  653. mostly to detect rubbish input fast(er). Also empty header name
  654. is just a rubbish too. We have to allow ":" at the beginning of
  655. the header, but header == ":" must be rejected. If we have ':' in
  656. the middle of header, it could be matched in middle of the value,
  657. this is because we do prefix match.*/
  658. if(!h || !GOOD_EASY_HANDLE(h->data) || !header || !header[0] ||
  659. !strcmp(header, ":") || strchr(header + 1, ':'))
  660. return NULL;
  661. stream = H2_STREAM_CTX(h->data);
  662. if(!stream)
  663. return NULL;
  664. len = strlen(header);
  665. for(i = 0; i<stream->push_headers_used; i++) {
  666. if(!strncmp(header, stream->push_headers[i], len)) {
  667. /* sub-match, make sure that it is followed by a colon */
  668. if(stream->push_headers[i][len] != ':')
  669. continue;
  670. return &stream->push_headers[i][len + 1];
  671. }
  672. }
  673. return NULL;
  674. }
  675. static struct Curl_easy *h2_duphandle(struct Curl_cfilter *cf,
  676. struct Curl_easy *data)
  677. {
  678. struct Curl_easy *second = curl_easy_duphandle(data);
  679. if(second) {
  680. /* setup the request struct */
  681. struct HTTP *http = calloc(1, sizeof(struct HTTP));
  682. if(!http) {
  683. (void)Curl_close(&second);
  684. }
  685. else {
  686. struct h2_stream_ctx *second_stream;
  687. second->req.p.http = http;
  688. http2_data_setup(cf, second, &second_stream);
  689. second->state.priority.weight = data->state.priority.weight;
  690. }
  691. }
  692. return second;
  693. }
  694. static int set_transfer_url(struct Curl_easy *data,
  695. struct curl_pushheaders *hp)
  696. {
  697. const char *v;
  698. CURLUcode uc;
  699. char *url = NULL;
  700. int rc = 0;
  701. CURLU *u = curl_url();
  702. if(!u)
  703. return 5;
  704. v = curl_pushheader_byname(hp, HTTP_PSEUDO_SCHEME);
  705. if(v) {
  706. uc = curl_url_set(u, CURLUPART_SCHEME, v, 0);
  707. if(uc) {
  708. rc = 1;
  709. goto fail;
  710. }
  711. }
  712. v = curl_pushheader_byname(hp, HTTP_PSEUDO_AUTHORITY);
  713. if(v) {
  714. uc = Curl_url_set_authority(u, v, CURLU_DISALLOW_USER);
  715. if(uc) {
  716. rc = 2;
  717. goto fail;
  718. }
  719. }
  720. v = curl_pushheader_byname(hp, HTTP_PSEUDO_PATH);
  721. if(v) {
  722. uc = curl_url_set(u, CURLUPART_PATH, v, 0);
  723. if(uc) {
  724. rc = 3;
  725. goto fail;
  726. }
  727. }
  728. uc = curl_url_get(u, CURLUPART_URL, &url, 0);
  729. if(uc)
  730. rc = 4;
  731. fail:
  732. curl_url_cleanup(u);
  733. if(rc)
  734. return rc;
  735. if(data->state.url_alloc)
  736. free(data->state.url);
  737. data->state.url_alloc = TRUE;
  738. data->state.url = url;
  739. return 0;
  740. }
  741. static void discard_newhandle(struct Curl_cfilter *cf,
  742. struct Curl_easy *newhandle)
  743. {
  744. if(newhandle->req.p.http) {
  745. http2_data_done(cf, newhandle, TRUE);
  746. }
  747. (void)Curl_close(&newhandle);
  748. }
  749. static int push_promise(struct Curl_cfilter *cf,
  750. struct Curl_easy *data,
  751. const nghttp2_push_promise *frame)
  752. {
  753. struct cf_h2_ctx *ctx = cf->ctx;
  754. int rv; /* one of the CURL_PUSH_* defines */
  755. CURL_TRC_CF(data, cf, "[%d] PUSH_PROMISE received",
  756. frame->promised_stream_id);
  757. if(data->multi->push_cb) {
  758. struct h2_stream_ctx *stream;
  759. struct h2_stream_ctx *newstream;
  760. struct curl_pushheaders heads;
  761. CURLMcode rc;
  762. CURLcode result;
  763. /* clone the parent */
  764. struct Curl_easy *newhandle = h2_duphandle(cf, data);
  765. if(!newhandle) {
  766. infof(data, "failed to duplicate handle");
  767. rv = CURL_PUSH_DENY; /* FAIL HARD */
  768. goto fail;
  769. }
  770. heads.data = data;
  771. heads.frame = frame;
  772. /* ask the application */
  773. CURL_TRC_CF(data, cf, "Got PUSH_PROMISE, ask application");
  774. stream = H2_STREAM_CTX(data);
  775. if(!stream) {
  776. failf(data, "Internal NULL stream");
  777. discard_newhandle(cf, newhandle);
  778. rv = CURL_PUSH_DENY;
  779. goto fail;
  780. }
  781. rv = set_transfer_url(newhandle, &heads);
  782. if(rv) {
  783. discard_newhandle(cf, newhandle);
  784. rv = CURL_PUSH_DENY;
  785. goto fail;
  786. }
  787. result = http2_data_setup(cf, newhandle, &newstream);
  788. if(result) {
  789. failf(data, "error setting up stream: %d", result);
  790. discard_newhandle(cf, newhandle);
  791. rv = CURL_PUSH_DENY;
  792. goto fail;
  793. }
  794. DEBUGASSERT(stream);
  795. Curl_set_in_callback(data, true);
  796. rv = data->multi->push_cb(data, newhandle,
  797. stream->push_headers_used, &heads,
  798. data->multi->push_userp);
  799. Curl_set_in_callback(data, false);
  800. /* free the headers again */
  801. free_push_headers(stream);
  802. if(rv) {
  803. DEBUGASSERT((rv > CURL_PUSH_OK) && (rv <= CURL_PUSH_ERROROUT));
  804. /* denied, kill off the new handle again */
  805. discard_newhandle(cf, newhandle);
  806. goto fail;
  807. }
  808. newstream->id = frame->promised_stream_id;
  809. newhandle->req.maxdownload = -1;
  810. newhandle->req.size = -1;
  811. /* approved, add to the multi handle and immediately switch to PERFORM
  812. state with the given connection !*/
  813. rc = Curl_multi_add_perform(data->multi, newhandle, cf->conn);
  814. if(rc) {
  815. infof(data, "failed to add handle to multi");
  816. discard_newhandle(cf, newhandle);
  817. rv = CURL_PUSH_DENY;
  818. goto fail;
  819. }
  820. rv = nghttp2_session_set_stream_user_data(ctx->h2,
  821. newstream->id,
  822. newhandle);
  823. if(rv) {
  824. infof(data, "failed to set user_data for stream %u",
  825. newstream->id);
  826. DEBUGASSERT(0);
  827. rv = CURL_PUSH_DENY;
  828. goto fail;
  829. }
  830. }
  831. else {
  832. CURL_TRC_CF(data, cf, "Got PUSH_PROMISE, ignore it");
  833. rv = CURL_PUSH_DENY;
  834. }
  835. fail:
  836. return rv;
  837. }
  838. static CURLcode recvbuf_write_hds(struct Curl_cfilter *cf,
  839. struct Curl_easy *data,
  840. const char *buf, size_t blen)
  841. {
  842. bool done;
  843. (void)cf;
  844. return Curl_xfer_write_resp(data, (char *)buf, blen, FALSE, &done);
  845. }
  846. static CURLcode on_stream_frame(struct Curl_cfilter *cf,
  847. struct Curl_easy *data,
  848. const nghttp2_frame *frame)
  849. {
  850. struct cf_h2_ctx *ctx = cf->ctx;
  851. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  852. int32_t stream_id = frame->hd.stream_id;
  853. CURLcode result;
  854. int rv;
  855. if(!stream) {
  856. CURL_TRC_CF(data, cf, "[%d] No stream_ctx set", stream_id);
  857. return CURLE_FAILED_INIT;
  858. }
  859. switch(frame->hd.type) {
  860. case NGHTTP2_DATA:
  861. CURL_TRC_CF(data, cf, "[%d] DATA, window=%d/%d",
  862. stream_id,
  863. nghttp2_session_get_stream_effective_recv_data_length(
  864. ctx->h2, stream->id),
  865. nghttp2_session_get_stream_effective_local_window_size(
  866. ctx->h2, stream->id));
  867. /* If !body started on this stream, then receiving DATA is illegal. */
  868. if(!stream->bodystarted) {
  869. rv = nghttp2_submit_rst_stream(ctx->h2, NGHTTP2_FLAG_NONE,
  870. stream_id, NGHTTP2_PROTOCOL_ERROR);
  871. if(nghttp2_is_fatal(rv)) {
  872. return CURLE_RECV_ERROR;
  873. }
  874. }
  875. if(frame->hd.flags & NGHTTP2_FLAG_END_STREAM) {
  876. drain_stream(cf, data, stream);
  877. }
  878. break;
  879. case NGHTTP2_HEADERS:
  880. if(stream->bodystarted) {
  881. /* Only valid HEADERS after body started is trailer HEADERS. We
  882. buffer them in on_header callback. */
  883. break;
  884. }
  885. /* nghttp2 guarantees that :status is received, and we store it to
  886. stream->status_code. Fuzzing has proven this can still be reached
  887. without status code having been set. */
  888. if(stream->status_code == -1)
  889. return CURLE_RECV_ERROR;
  890. /* Only final status code signals the end of header */
  891. if(stream->status_code / 100 != 1) {
  892. stream->bodystarted = TRUE;
  893. stream->status_code = -1;
  894. }
  895. result = recvbuf_write_hds(cf, data, STRCONST("\r\n"));
  896. if(result)
  897. return result;
  898. if(stream->status_code / 100 != 1) {
  899. stream->resp_hds_complete = TRUE;
  900. }
  901. drain_stream(cf, data, stream);
  902. break;
  903. case NGHTTP2_PUSH_PROMISE:
  904. rv = push_promise(cf, data, &frame->push_promise);
  905. if(rv) { /* deny! */
  906. DEBUGASSERT((rv > CURL_PUSH_OK) && (rv <= CURL_PUSH_ERROROUT));
  907. rv = nghttp2_submit_rst_stream(ctx->h2, NGHTTP2_FLAG_NONE,
  908. frame->push_promise.promised_stream_id,
  909. NGHTTP2_CANCEL);
  910. if(nghttp2_is_fatal(rv))
  911. return CURLE_SEND_ERROR;
  912. else if(rv == CURL_PUSH_ERROROUT) {
  913. CURL_TRC_CF(data, cf, "[%d] fail in PUSH_PROMISE received",
  914. stream_id);
  915. return CURLE_RECV_ERROR;
  916. }
  917. }
  918. break;
  919. case NGHTTP2_RST_STREAM:
  920. stream->closed = TRUE;
  921. if(frame->rst_stream.error_code) {
  922. stream->reset = TRUE;
  923. }
  924. stream->send_closed = TRUE;
  925. drain_stream(cf, data, stream);
  926. break;
  927. case NGHTTP2_WINDOW_UPDATE:
  928. if(CURL_WANT_SEND(data)) {
  929. drain_stream(cf, data, stream);
  930. }
  931. break;
  932. default:
  933. break;
  934. }
  935. return CURLE_OK;
  936. }
  937. #ifndef CURL_DISABLE_VERBOSE_STRINGS
  938. static int fr_print(const nghttp2_frame *frame, char *buffer, size_t blen)
  939. {
  940. switch(frame->hd.type) {
  941. case NGHTTP2_DATA: {
  942. return msnprintf(buffer, blen,
  943. "FRAME[DATA, len=%d, eos=%d, padlen=%d]",
  944. (int)frame->hd.length,
  945. !!(frame->hd.flags & NGHTTP2_FLAG_END_STREAM),
  946. (int)frame->data.padlen);
  947. }
  948. case NGHTTP2_HEADERS: {
  949. return msnprintf(buffer, blen,
  950. "FRAME[HEADERS, len=%d, hend=%d, eos=%d]",
  951. (int)frame->hd.length,
  952. !!(frame->hd.flags & NGHTTP2_FLAG_END_HEADERS),
  953. !!(frame->hd.flags & NGHTTP2_FLAG_END_STREAM));
  954. }
  955. case NGHTTP2_PRIORITY: {
  956. return msnprintf(buffer, blen,
  957. "FRAME[PRIORITY, len=%d, flags=%d]",
  958. (int)frame->hd.length, frame->hd.flags);
  959. }
  960. case NGHTTP2_RST_STREAM: {
  961. return msnprintf(buffer, blen,
  962. "FRAME[RST_STREAM, len=%d, flags=%d, error=%u]",
  963. (int)frame->hd.length, frame->hd.flags,
  964. frame->rst_stream.error_code);
  965. }
  966. case NGHTTP2_SETTINGS: {
  967. if(frame->hd.flags & NGHTTP2_FLAG_ACK) {
  968. return msnprintf(buffer, blen, "FRAME[SETTINGS, ack=1]");
  969. }
  970. return msnprintf(buffer, blen,
  971. "FRAME[SETTINGS, len=%d]", (int)frame->hd.length);
  972. }
  973. case NGHTTP2_PUSH_PROMISE: {
  974. return msnprintf(buffer, blen,
  975. "FRAME[PUSH_PROMISE, len=%d, hend=%d]",
  976. (int)frame->hd.length,
  977. !!(frame->hd.flags & NGHTTP2_FLAG_END_HEADERS));
  978. }
  979. case NGHTTP2_PING: {
  980. return msnprintf(buffer, blen,
  981. "FRAME[PING, len=%d, ack=%d]",
  982. (int)frame->hd.length,
  983. frame->hd.flags&NGHTTP2_FLAG_ACK);
  984. }
  985. case NGHTTP2_GOAWAY: {
  986. char scratch[128];
  987. size_t s_len = sizeof(scratch)/sizeof(scratch[0]);
  988. size_t len = (frame->goaway.opaque_data_len < s_len)?
  989. frame->goaway.opaque_data_len : s_len-1;
  990. if(len)
  991. memcpy(scratch, frame->goaway.opaque_data, len);
  992. scratch[len] = '\0';
  993. return msnprintf(buffer, blen, "FRAME[GOAWAY, error=%d, reason='%s', "
  994. "last_stream=%d]", frame->goaway.error_code,
  995. scratch, frame->goaway.last_stream_id);
  996. }
  997. case NGHTTP2_WINDOW_UPDATE: {
  998. return msnprintf(buffer, blen,
  999. "FRAME[WINDOW_UPDATE, incr=%d]",
  1000. frame->window_update.window_size_increment);
  1001. }
  1002. default:
  1003. return msnprintf(buffer, blen, "FRAME[%d, len=%d, flags=%d]",
  1004. frame->hd.type, (int)frame->hd.length,
  1005. frame->hd.flags);
  1006. }
  1007. }
  1008. static int on_frame_send(nghttp2_session *session, const nghttp2_frame *frame,
  1009. void *userp)
  1010. {
  1011. struct Curl_cfilter *cf = userp;
  1012. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  1013. (void)session;
  1014. DEBUGASSERT(data);
  1015. if(data && Curl_trc_cf_is_verbose(cf, data)) {
  1016. char buffer[256];
  1017. int len;
  1018. len = fr_print(frame, buffer, sizeof(buffer)-1);
  1019. buffer[len] = 0;
  1020. CURL_TRC_CF(data, cf, "[%d] -> %s", frame->hd.stream_id, buffer);
  1021. }
  1022. return 0;
  1023. }
  1024. #endif /* !CURL_DISABLE_VERBOSE_STRINGS */
  1025. static int on_frame_recv(nghttp2_session *session, const nghttp2_frame *frame,
  1026. void *userp)
  1027. {
  1028. struct Curl_cfilter *cf = userp;
  1029. struct cf_h2_ctx *ctx = cf->ctx;
  1030. struct Curl_easy *data = CF_DATA_CURRENT(cf), *data_s;
  1031. int32_t stream_id = frame->hd.stream_id;
  1032. DEBUGASSERT(data);
  1033. #ifndef CURL_DISABLE_VERBOSE_STRINGS
  1034. if(Curl_trc_cf_is_verbose(cf, data)) {
  1035. char buffer[256];
  1036. int len;
  1037. len = fr_print(frame, buffer, sizeof(buffer)-1);
  1038. buffer[len] = 0;
  1039. CURL_TRC_CF(data, cf, "[%d] <- %s",frame->hd.stream_id, buffer);
  1040. }
  1041. #endif /* !CURL_DISABLE_VERBOSE_STRINGS */
  1042. if(!stream_id) {
  1043. /* stream ID zero is for connection-oriented stuff */
  1044. DEBUGASSERT(data);
  1045. switch(frame->hd.type) {
  1046. case NGHTTP2_SETTINGS: {
  1047. if(!(frame->hd.flags & NGHTTP2_FLAG_ACK)) {
  1048. uint32_t max_conn = ctx->max_concurrent_streams;
  1049. ctx->max_concurrent_streams = nghttp2_session_get_remote_settings(
  1050. session, NGHTTP2_SETTINGS_MAX_CONCURRENT_STREAMS);
  1051. ctx->enable_push = nghttp2_session_get_remote_settings(
  1052. session, NGHTTP2_SETTINGS_ENABLE_PUSH) != 0;
  1053. CURL_TRC_CF(data, cf, "[0] MAX_CONCURRENT_STREAMS: %d",
  1054. ctx->max_concurrent_streams);
  1055. CURL_TRC_CF(data, cf, "[0] ENABLE_PUSH: %s",
  1056. ctx->enable_push ? "TRUE" : "false");
  1057. if(data && max_conn != ctx->max_concurrent_streams) {
  1058. /* only signal change if the value actually changed */
  1059. CURL_TRC_CF(data, cf, "[0] notify MAX_CONCURRENT_STREAMS: %u",
  1060. ctx->max_concurrent_streams);
  1061. Curl_multi_connchanged(data->multi);
  1062. }
  1063. /* Since the initial stream window is 64K, a request might be on HOLD,
  1064. * due to exhaustion. The (initial) SETTINGS may announce a much larger
  1065. * window and *assume* that we treat this like a WINDOW_UPDATE. Some
  1066. * servers send an explicit WINDOW_UPDATE, but not all seem to do that.
  1067. * To be safe, we UNHOLD a stream in order not to stall. */
  1068. if(CURL_WANT_SEND(data)) {
  1069. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1070. if(stream)
  1071. drain_stream(cf, data, stream);
  1072. }
  1073. }
  1074. break;
  1075. }
  1076. case NGHTTP2_GOAWAY:
  1077. ctx->goaway = TRUE;
  1078. ctx->goaway_error = frame->goaway.error_code;
  1079. ctx->last_stream_id = frame->goaway.last_stream_id;
  1080. if(data) {
  1081. infof(data, "received GOAWAY, error=%d, last_stream=%u",
  1082. ctx->goaway_error, ctx->last_stream_id);
  1083. Curl_multi_connchanged(data->multi);
  1084. }
  1085. break;
  1086. default:
  1087. break;
  1088. }
  1089. return 0;
  1090. }
  1091. data_s = nghttp2_session_get_stream_user_data(session, stream_id);
  1092. if(!data_s) {
  1093. CURL_TRC_CF(data, cf, "[%d] No Curl_easy associated", stream_id);
  1094. return 0;
  1095. }
  1096. return on_stream_frame(cf, data_s, frame)? NGHTTP2_ERR_CALLBACK_FAILURE : 0;
  1097. }
  1098. static int on_data_chunk_recv(nghttp2_session *session, uint8_t flags,
  1099. int32_t stream_id,
  1100. const uint8_t *mem, size_t len, void *userp)
  1101. {
  1102. struct Curl_cfilter *cf = userp;
  1103. struct cf_h2_ctx *ctx = cf->ctx;
  1104. struct h2_stream_ctx *stream;
  1105. struct Curl_easy *data_s;
  1106. CURLcode result;
  1107. bool done;
  1108. (void)flags;
  1109. DEBUGASSERT(stream_id); /* should never be a zero stream ID here */
  1110. DEBUGASSERT(CF_DATA_CURRENT(cf));
  1111. /* get the stream from the hash based on Stream ID */
  1112. data_s = nghttp2_session_get_stream_user_data(session, stream_id);
  1113. if(!data_s) {
  1114. /* Receiving a Stream ID not in the hash should not happen - unless
  1115. we have aborted a transfer artificially and there were more data
  1116. in the pipeline. Silently ignore. */
  1117. CURL_TRC_CF(CF_DATA_CURRENT(cf), cf, "[%d] Data for unknown",
  1118. stream_id);
  1119. /* consumed explicitly as no one will read it */
  1120. nghttp2_session_consume(session, stream_id, len);
  1121. return 0;
  1122. }
  1123. stream = H2_STREAM_CTX(data_s);
  1124. if(!stream)
  1125. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1126. result = Curl_xfer_write_resp(data_s, (char *)mem, len, FALSE, &done);
  1127. if(result && result != CURLE_AGAIN)
  1128. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1129. nghttp2_session_consume(ctx->h2, stream_id, len);
  1130. stream->nrcvd_data += (curl_off_t)len;
  1131. /* if we receive data for another handle, wake that up */
  1132. drain_stream(cf, data_s, stream);
  1133. return 0;
  1134. }
  1135. static int on_stream_close(nghttp2_session *session, int32_t stream_id,
  1136. uint32_t error_code, void *userp)
  1137. {
  1138. struct Curl_cfilter *cf = userp;
  1139. struct Curl_easy *data_s, *call_data = CF_DATA_CURRENT(cf);
  1140. struct h2_stream_ctx *stream;
  1141. int rv;
  1142. (void)session;
  1143. DEBUGASSERT(call_data);
  1144. /* get the stream from the hash based on Stream ID, stream ID zero is for
  1145. connection-oriented stuff */
  1146. data_s = stream_id?
  1147. nghttp2_session_get_stream_user_data(session, stream_id) : NULL;
  1148. if(!data_s) {
  1149. CURL_TRC_CF(call_data, cf,
  1150. "[%d] on_stream_close, no easy set on stream", stream_id);
  1151. return 0;
  1152. }
  1153. if(!GOOD_EASY_HANDLE(data_s)) {
  1154. /* nghttp2 still has an easy registered for the stream which has
  1155. * been freed be libcurl. This points to a code path that does not
  1156. * trigger DONE or DETACH events as it must. */
  1157. CURL_TRC_CF(call_data, cf,
  1158. "[%d] on_stream_close, not a GOOD easy on stream", stream_id);
  1159. (void)nghttp2_session_set_stream_user_data(session, stream_id, 0);
  1160. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1161. }
  1162. stream = H2_STREAM_CTX(data_s);
  1163. if(!stream) {
  1164. CURL_TRC_CF(data_s, cf,
  1165. "[%d] on_stream_close, GOOD easy but no stream", stream_id);
  1166. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1167. }
  1168. stream->closed = TRUE;
  1169. stream->error = error_code;
  1170. if(stream->error) {
  1171. stream->reset = TRUE;
  1172. stream->send_closed = TRUE;
  1173. }
  1174. if(stream->error)
  1175. CURL_TRC_CF(data_s, cf, "[%d] RESET: %s (err %d)",
  1176. stream_id, nghttp2_http2_strerror(error_code), error_code);
  1177. else
  1178. CURL_TRC_CF(data_s, cf, "[%d] CLOSED", stream_id);
  1179. drain_stream(cf, data_s, stream);
  1180. /* remove `data_s` from the nghttp2 stream */
  1181. rv = nghttp2_session_set_stream_user_data(session, stream_id, 0);
  1182. if(rv) {
  1183. infof(data_s, "http/2: failed to clear user_data for stream %u",
  1184. stream_id);
  1185. DEBUGASSERT(0);
  1186. }
  1187. return 0;
  1188. }
  1189. static int on_begin_headers(nghttp2_session *session,
  1190. const nghttp2_frame *frame, void *userp)
  1191. {
  1192. struct Curl_cfilter *cf = userp;
  1193. struct h2_stream_ctx *stream;
  1194. struct Curl_easy *data_s = NULL;
  1195. (void)cf;
  1196. data_s = nghttp2_session_get_stream_user_data(session, frame->hd.stream_id);
  1197. if(!data_s) {
  1198. return 0;
  1199. }
  1200. if(frame->hd.type != NGHTTP2_HEADERS) {
  1201. return 0;
  1202. }
  1203. stream = H2_STREAM_CTX(data_s);
  1204. if(!stream || !stream->bodystarted) {
  1205. return 0;
  1206. }
  1207. return 0;
  1208. }
  1209. /* frame->hd.type is either NGHTTP2_HEADERS or NGHTTP2_PUSH_PROMISE */
  1210. static int on_header(nghttp2_session *session, const nghttp2_frame *frame,
  1211. const uint8_t *name, size_t namelen,
  1212. const uint8_t *value, size_t valuelen,
  1213. uint8_t flags,
  1214. void *userp)
  1215. {
  1216. struct Curl_cfilter *cf = userp;
  1217. struct h2_stream_ctx *stream;
  1218. struct Curl_easy *data_s;
  1219. int32_t stream_id = frame->hd.stream_id;
  1220. CURLcode result;
  1221. (void)flags;
  1222. DEBUGASSERT(stream_id); /* should never be a zero stream ID here */
  1223. /* get the stream from the hash based on Stream ID */
  1224. data_s = nghttp2_session_get_stream_user_data(session, stream_id);
  1225. if(!data_s)
  1226. /* Receiving a Stream ID not in the hash should not happen, this is an
  1227. internal error more than anything else! */
  1228. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1229. stream = H2_STREAM_CTX(data_s);
  1230. if(!stream) {
  1231. failf(data_s, "Internal NULL stream");
  1232. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1233. }
  1234. /* Store received PUSH_PROMISE headers to be used when the subsequent
  1235. PUSH_PROMISE callback comes */
  1236. if(frame->hd.type == NGHTTP2_PUSH_PROMISE) {
  1237. char *h;
  1238. if(!strcmp(HTTP_PSEUDO_AUTHORITY, (const char *)name)) {
  1239. /* pseudo headers are lower case */
  1240. int rc = 0;
  1241. char *check = aprintf("%s:%d", cf->conn->host.name,
  1242. cf->conn->remote_port);
  1243. if(!check)
  1244. /* no memory */
  1245. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1246. if(!strcasecompare(check, (const char *)value) &&
  1247. ((cf->conn->remote_port != cf->conn->given->defport) ||
  1248. !strcasecompare(cf->conn->host.name, (const char *)value))) {
  1249. /* This is push is not for the same authority that was asked for in
  1250. * the URL. RFC 7540 section 8.2 says: "A client MUST treat a
  1251. * PUSH_PROMISE for which the server is not authoritative as a stream
  1252. * error of type PROTOCOL_ERROR."
  1253. */
  1254. (void)nghttp2_submit_rst_stream(session, NGHTTP2_FLAG_NONE,
  1255. stream_id, NGHTTP2_PROTOCOL_ERROR);
  1256. rc = NGHTTP2_ERR_CALLBACK_FAILURE;
  1257. }
  1258. free(check);
  1259. if(rc)
  1260. return rc;
  1261. }
  1262. if(!stream->push_headers) {
  1263. stream->push_headers_alloc = 10;
  1264. stream->push_headers = malloc(stream->push_headers_alloc *
  1265. sizeof(char *));
  1266. if(!stream->push_headers)
  1267. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1268. stream->push_headers_used = 0;
  1269. }
  1270. else if(stream->push_headers_used ==
  1271. stream->push_headers_alloc) {
  1272. char **headp;
  1273. if(stream->push_headers_alloc > 1000) {
  1274. /* this is beyond crazy many headers, bail out */
  1275. failf(data_s, "Too many PUSH_PROMISE headers");
  1276. free_push_headers(stream);
  1277. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1278. }
  1279. stream->push_headers_alloc *= 2;
  1280. headp = realloc(stream->push_headers,
  1281. stream->push_headers_alloc * sizeof(char *));
  1282. if(!headp) {
  1283. free_push_headers(stream);
  1284. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1285. }
  1286. stream->push_headers = headp;
  1287. }
  1288. h = aprintf("%s:%s", name, value);
  1289. if(h)
  1290. stream->push_headers[stream->push_headers_used++] = h;
  1291. return 0;
  1292. }
  1293. if(stream->bodystarted) {
  1294. /* This is a trailer */
  1295. CURL_TRC_CF(data_s, cf, "[%d] trailer: %.*s: %.*s",
  1296. stream->id, (int)namelen, name, (int)valuelen, value);
  1297. result = Curl_dynhds_add(&stream->resp_trailers,
  1298. (const char *)name, namelen,
  1299. (const char *)value, valuelen);
  1300. if(result)
  1301. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1302. return 0;
  1303. }
  1304. if(namelen == sizeof(HTTP_PSEUDO_STATUS) - 1 &&
  1305. memcmp(HTTP_PSEUDO_STATUS, name, namelen) == 0) {
  1306. /* nghttp2 guarantees :status is received first and only once. */
  1307. char buffer[32];
  1308. result = Curl_http_decode_status(&stream->status_code,
  1309. (const char *)value, valuelen);
  1310. if(result)
  1311. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1312. msnprintf(buffer, sizeof(buffer), HTTP_PSEUDO_STATUS ":%u\r",
  1313. stream->status_code);
  1314. result = Curl_headers_push(data_s, buffer, CURLH_PSEUDO);
  1315. if(result)
  1316. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1317. result = recvbuf_write_hds(cf, data_s, STRCONST("HTTP/2 "));
  1318. if(result)
  1319. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1320. result = recvbuf_write_hds(cf, data_s, (const char *)value, valuelen);
  1321. if(result)
  1322. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1323. /* the space character after the status code is mandatory */
  1324. result = recvbuf_write_hds(cf, data_s, STRCONST(" \r\n"));
  1325. if(result)
  1326. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1327. /* if we receive data for another handle, wake that up */
  1328. if(CF_DATA_CURRENT(cf) != data_s)
  1329. Curl_expire(data_s, 0, EXPIRE_RUN_NOW);
  1330. CURL_TRC_CF(data_s, cf, "[%d] status: HTTP/2 %03d",
  1331. stream->id, stream->status_code);
  1332. return 0;
  1333. }
  1334. /* nghttp2 guarantees that namelen > 0, and :status was already
  1335. received, and this is not pseudo-header field . */
  1336. /* convert to an HTTP1-style header */
  1337. result = recvbuf_write_hds(cf, data_s, (const char *)name, namelen);
  1338. if(result)
  1339. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1340. result = recvbuf_write_hds(cf, data_s, STRCONST(": "));
  1341. if(result)
  1342. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1343. result = recvbuf_write_hds(cf, data_s, (const char *)value, valuelen);
  1344. if(result)
  1345. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1346. result = recvbuf_write_hds(cf, data_s, STRCONST("\r\n"));
  1347. if(result)
  1348. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1349. /* if we receive data for another handle, wake that up */
  1350. if(CF_DATA_CURRENT(cf) != data_s)
  1351. Curl_expire(data_s, 0, EXPIRE_RUN_NOW);
  1352. CURL_TRC_CF(data_s, cf, "[%d] header: %.*s: %.*s",
  1353. stream->id, (int)namelen, name, (int)valuelen, value);
  1354. return 0; /* 0 is successful */
  1355. }
  1356. static ssize_t req_body_read_callback(nghttp2_session *session,
  1357. int32_t stream_id,
  1358. uint8_t *buf, size_t length,
  1359. uint32_t *data_flags,
  1360. nghttp2_data_source *source,
  1361. void *userp)
  1362. {
  1363. struct Curl_cfilter *cf = userp;
  1364. struct Curl_easy *data_s;
  1365. struct h2_stream_ctx *stream = NULL;
  1366. CURLcode result;
  1367. ssize_t nread;
  1368. (void)source;
  1369. (void)cf;
  1370. if(stream_id) {
  1371. /* get the stream from the hash based on Stream ID, stream ID zero is for
  1372. connection-oriented stuff */
  1373. data_s = nghttp2_session_get_stream_user_data(session, stream_id);
  1374. if(!data_s)
  1375. /* Receiving a Stream ID not in the hash should not happen, this is an
  1376. internal error more than anything else! */
  1377. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1378. stream = H2_STREAM_CTX(data_s);
  1379. if(!stream)
  1380. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1381. }
  1382. else
  1383. return NGHTTP2_ERR_INVALID_ARGUMENT;
  1384. nread = Curl_bufq_read(&stream->sendbuf, buf, length, &result);
  1385. if(nread < 0) {
  1386. if(result != CURLE_AGAIN)
  1387. return NGHTTP2_ERR_CALLBACK_FAILURE;
  1388. nread = 0;
  1389. }
  1390. if(nread > 0 && stream->upload_left != -1)
  1391. stream->upload_left -= nread;
  1392. CURL_TRC_CF(data_s, cf, "[%d] req_body_read(len=%zu) left=%"
  1393. CURL_FORMAT_CURL_OFF_T " -> %zd, %d",
  1394. stream_id, length, stream->upload_left, nread, result);
  1395. if(stream->upload_left == 0)
  1396. *data_flags = NGHTTP2_DATA_FLAG_EOF;
  1397. else if(nread == 0)
  1398. return NGHTTP2_ERR_DEFERRED;
  1399. return nread;
  1400. }
  1401. #if !defined(CURL_DISABLE_VERBOSE_STRINGS)
  1402. static int error_callback(nghttp2_session *session,
  1403. const char *msg,
  1404. size_t len,
  1405. void *userp)
  1406. {
  1407. struct Curl_cfilter *cf = userp;
  1408. struct Curl_easy *data = CF_DATA_CURRENT(cf);
  1409. (void)session;
  1410. failf(data, "%.*s", (int)len, msg);
  1411. return 0;
  1412. }
  1413. #endif
  1414. /*
  1415. * Append headers to ask for an HTTP1.1 to HTTP2 upgrade.
  1416. */
  1417. CURLcode Curl_http2_request_upgrade(struct dynbuf *req,
  1418. struct Curl_easy *data)
  1419. {
  1420. CURLcode result;
  1421. char *base64;
  1422. size_t blen;
  1423. struct SingleRequest *k = &data->req;
  1424. uint8_t binsettings[H2_BINSETTINGS_LEN];
  1425. ssize_t binlen; /* length of the binsettings data */
  1426. binlen = populate_binsettings(binsettings, data);
  1427. if(binlen <= 0) {
  1428. failf(data, "nghttp2 unexpectedly failed on pack_settings_payload");
  1429. Curl_dyn_free(req);
  1430. return CURLE_FAILED_INIT;
  1431. }
  1432. result = Curl_base64url_encode((const char *)binsettings, binlen,
  1433. &base64, &blen);
  1434. if(result) {
  1435. Curl_dyn_free(req);
  1436. return result;
  1437. }
  1438. result = Curl_dyn_addf(req,
  1439. "Connection: Upgrade, HTTP2-Settings\r\n"
  1440. "Upgrade: %s\r\n"
  1441. "HTTP2-Settings: %s\r\n",
  1442. NGHTTP2_CLEARTEXT_PROTO_VERSION_ID, base64);
  1443. free(base64);
  1444. k->upgr101 = UPGR101_H2;
  1445. return result;
  1446. }
  1447. static CURLcode http2_data_done_send(struct Curl_cfilter *cf,
  1448. struct Curl_easy *data)
  1449. {
  1450. struct cf_h2_ctx *ctx = cf->ctx;
  1451. CURLcode result = CURLE_OK;
  1452. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1453. if(!ctx || !ctx->h2 || !stream)
  1454. goto out;
  1455. CURL_TRC_CF(data, cf, "[%d] data done send", stream->id);
  1456. if(!stream->send_closed) {
  1457. stream->send_closed = TRUE;
  1458. if(stream->upload_left) {
  1459. /* we now know that everything that is buffered is all there is. */
  1460. stream->upload_left = Curl_bufq_len(&stream->sendbuf);
  1461. /* resume sending here to trigger the callback to get called again so
  1462. that it can signal EOF to nghttp2 */
  1463. (void)nghttp2_session_resume_data(ctx->h2, stream->id);
  1464. drain_stream(cf, data, stream);
  1465. }
  1466. }
  1467. out:
  1468. return result;
  1469. }
  1470. static ssize_t http2_handle_stream_close(struct Curl_cfilter *cf,
  1471. struct Curl_easy *data,
  1472. struct h2_stream_ctx *stream,
  1473. CURLcode *err)
  1474. {
  1475. ssize_t rv = 0;
  1476. if(stream->error == NGHTTP2_REFUSED_STREAM) {
  1477. CURL_TRC_CF(data, cf, "[%d] REFUSED_STREAM, try again on a new "
  1478. "connection", stream->id);
  1479. connclose(cf->conn, "REFUSED_STREAM"); /* don't use this anymore */
  1480. data->state.refused_stream = TRUE;
  1481. *err = CURLE_RECV_ERROR; /* trigger Curl_retry_request() later */
  1482. return -1;
  1483. }
  1484. else if(stream->error != NGHTTP2_NO_ERROR) {
  1485. failf(data, "HTTP/2 stream %u was not closed cleanly: %s (err %u)",
  1486. stream->id, nghttp2_http2_strerror(stream->error),
  1487. stream->error);
  1488. *err = CURLE_HTTP2_STREAM;
  1489. return -1;
  1490. }
  1491. else if(stream->reset) {
  1492. failf(data, "HTTP/2 stream %u was reset", stream->id);
  1493. *err = stream->bodystarted? CURLE_PARTIAL_FILE : CURLE_RECV_ERROR;
  1494. return -1;
  1495. }
  1496. if(!stream->bodystarted) {
  1497. failf(data, "HTTP/2 stream %u was closed cleanly, but before getting "
  1498. " all response header fields, treated as error",
  1499. stream->id);
  1500. *err = CURLE_HTTP2_STREAM;
  1501. return -1;
  1502. }
  1503. if(Curl_dynhds_count(&stream->resp_trailers)) {
  1504. struct dynhds_entry *e;
  1505. struct dynbuf dbuf;
  1506. size_t i;
  1507. *err = CURLE_OK;
  1508. Curl_dyn_init(&dbuf, DYN_TRAILERS);
  1509. for(i = 0; i < Curl_dynhds_count(&stream->resp_trailers); ++i) {
  1510. e = Curl_dynhds_getn(&stream->resp_trailers, i);
  1511. if(!e)
  1512. break;
  1513. Curl_dyn_reset(&dbuf);
  1514. *err = Curl_dyn_addf(&dbuf, "%.*s: %.*s\x0d\x0a",
  1515. (int)e->namelen, e->name,
  1516. (int)e->valuelen, e->value);
  1517. if(*err)
  1518. break;
  1519. Curl_debug(data, CURLINFO_HEADER_IN, Curl_dyn_ptr(&dbuf),
  1520. Curl_dyn_len(&dbuf));
  1521. *err = Curl_client_write(data, CLIENTWRITE_HEADER|CLIENTWRITE_TRAILER,
  1522. Curl_dyn_ptr(&dbuf), Curl_dyn_len(&dbuf));
  1523. if(*err)
  1524. break;
  1525. }
  1526. Curl_dyn_free(&dbuf);
  1527. if(*err)
  1528. goto out;
  1529. }
  1530. stream->close_handled = TRUE;
  1531. *err = CURLE_OK;
  1532. rv = 0;
  1533. out:
  1534. CURL_TRC_CF(data, cf, "handle_stream_close -> %zd, %d", rv, *err);
  1535. return rv;
  1536. }
  1537. static int sweight_wanted(const struct Curl_easy *data)
  1538. {
  1539. /* 0 weight is not set by user and we take the nghttp2 default one */
  1540. return data->set.priority.weight?
  1541. data->set.priority.weight : NGHTTP2_DEFAULT_WEIGHT;
  1542. }
  1543. static int sweight_in_effect(const struct Curl_easy *data)
  1544. {
  1545. /* 0 weight is not set by user and we take the nghttp2 default one */
  1546. return data->state.priority.weight?
  1547. data->state.priority.weight : NGHTTP2_DEFAULT_WEIGHT;
  1548. }
  1549. /*
  1550. * h2_pri_spec() fills in the pri_spec struct, used by nghttp2 to send weight
  1551. * and dependency to the peer. It also stores the updated values in the state
  1552. * struct.
  1553. */
  1554. static void h2_pri_spec(struct Curl_easy *data,
  1555. nghttp2_priority_spec *pri_spec)
  1556. {
  1557. struct Curl_data_priority *prio = &data->set.priority;
  1558. struct h2_stream_ctx *depstream = H2_STREAM_CTX(prio->parent);
  1559. int32_t depstream_id = depstream? depstream->id:0;
  1560. nghttp2_priority_spec_init(pri_spec, depstream_id,
  1561. sweight_wanted(data),
  1562. data->set.priority.exclusive);
  1563. data->state.priority = *prio;
  1564. }
  1565. /*
  1566. * Check if there's been an update in the priority /
  1567. * dependency settings and if so it submits a PRIORITY frame with the updated
  1568. * info.
  1569. * Flush any out data pending in the network buffer.
  1570. */
  1571. static CURLcode h2_progress_egress(struct Curl_cfilter *cf,
  1572. struct Curl_easy *data)
  1573. {
  1574. struct cf_h2_ctx *ctx = cf->ctx;
  1575. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1576. int rv = 0;
  1577. if(stream && stream->id > 0 &&
  1578. ((sweight_wanted(data) != sweight_in_effect(data)) ||
  1579. (data->set.priority.exclusive != data->state.priority.exclusive) ||
  1580. (data->set.priority.parent != data->state.priority.parent)) ) {
  1581. /* send new weight and/or dependency */
  1582. nghttp2_priority_spec pri_spec;
  1583. h2_pri_spec(data, &pri_spec);
  1584. CURL_TRC_CF(data, cf, "[%d] Queuing PRIORITY", stream->id);
  1585. DEBUGASSERT(stream->id != -1);
  1586. rv = nghttp2_submit_priority(ctx->h2, NGHTTP2_FLAG_NONE,
  1587. stream->id, &pri_spec);
  1588. if(rv)
  1589. goto out;
  1590. }
  1591. ctx->nw_out_blocked = 0;
  1592. while(!rv && !ctx->nw_out_blocked && nghttp2_session_want_write(ctx->h2))
  1593. rv = nghttp2_session_send(ctx->h2);
  1594. out:
  1595. if(nghttp2_is_fatal(rv)) {
  1596. CURL_TRC_CF(data, cf, "nghttp2_session_send error (%s)%d",
  1597. nghttp2_strerror(rv), rv);
  1598. return CURLE_SEND_ERROR;
  1599. }
  1600. return nw_out_flush(cf, data);
  1601. }
  1602. static ssize_t stream_recv(struct Curl_cfilter *cf, struct Curl_easy *data,
  1603. struct h2_stream_ctx *stream,
  1604. char *buf, size_t len, CURLcode *err)
  1605. {
  1606. struct cf_h2_ctx *ctx = cf->ctx;
  1607. ssize_t nread = -1;
  1608. (void)buf;
  1609. *err = CURLE_AGAIN;
  1610. if(stream->closed) {
  1611. CURL_TRC_CF(data, cf, "[%d] returning CLOSE", stream->id);
  1612. nread = http2_handle_stream_close(cf, data, stream, err);
  1613. }
  1614. else if(stream->reset ||
  1615. (ctx->conn_closed && Curl_bufq_is_empty(&ctx->inbufq)) ||
  1616. (ctx->goaway && ctx->last_stream_id < stream->id)) {
  1617. CURL_TRC_CF(data, cf, "[%d] returning ERR", stream->id);
  1618. *err = stream->bodystarted? CURLE_PARTIAL_FILE : CURLE_RECV_ERROR;
  1619. nread = -1;
  1620. }
  1621. if(nread < 0 && *err != CURLE_AGAIN)
  1622. CURL_TRC_CF(data, cf, "[%d] stream_recv(len=%zu) -> %zd, %d",
  1623. stream->id, len, nread, *err);
  1624. return nread;
  1625. }
  1626. static CURLcode h2_progress_ingress(struct Curl_cfilter *cf,
  1627. struct Curl_easy *data,
  1628. size_t data_max_bytes)
  1629. {
  1630. struct cf_h2_ctx *ctx = cf->ctx;
  1631. struct h2_stream_ctx *stream;
  1632. CURLcode result = CURLE_OK;
  1633. ssize_t nread;
  1634. /* Process network input buffer fist */
  1635. if(!Curl_bufq_is_empty(&ctx->inbufq)) {
  1636. CURL_TRC_CF(data, cf, "Process %zu bytes in connection buffer",
  1637. Curl_bufq_len(&ctx->inbufq));
  1638. if(h2_process_pending_input(cf, data, &result) < 0)
  1639. return result;
  1640. }
  1641. /* Receive data from the "lower" filters, e.g. network until
  1642. * it is time to stop due to connection close or us not processing
  1643. * all network input */
  1644. while(!ctx->conn_closed && Curl_bufq_is_empty(&ctx->inbufq)) {
  1645. stream = H2_STREAM_CTX(data);
  1646. if(stream && (stream->closed || !data_max_bytes)) {
  1647. /* We would like to abort here and stop processing, so that
  1648. * the transfer loop can handle the data/close here. However,
  1649. * this may leave data in underlying buffers that will not
  1650. * be consumed. */
  1651. if(!cf->next || !cf->next->cft->has_data_pending(cf->next, data))
  1652. drain_stream(cf, data, stream);
  1653. break;
  1654. }
  1655. nread = Curl_bufq_sipn(&ctx->inbufq, 0, nw_in_reader, cf, &result);
  1656. if(nread < 0) {
  1657. if(result != CURLE_AGAIN) {
  1658. failf(data, "Failed receiving HTTP2 data: %d(%s)", result,
  1659. curl_easy_strerror(result));
  1660. return result;
  1661. }
  1662. break;
  1663. }
  1664. else if(nread == 0) {
  1665. CURL_TRC_CF(data, cf, "[0] ingress: connection closed");
  1666. ctx->conn_closed = TRUE;
  1667. break;
  1668. }
  1669. else {
  1670. CURL_TRC_CF(data, cf, "[0] ingress: read %zd bytes", nread);
  1671. data_max_bytes = (data_max_bytes > (size_t)nread)?
  1672. (data_max_bytes - (size_t)nread) : 0;
  1673. }
  1674. if(h2_process_pending_input(cf, data, &result))
  1675. return result;
  1676. }
  1677. if(ctx->conn_closed && Curl_bufq_is_empty(&ctx->inbufq)) {
  1678. connclose(cf->conn, "GOAWAY received");
  1679. }
  1680. return CURLE_OK;
  1681. }
  1682. static ssize_t cf_h2_recv(struct Curl_cfilter *cf, struct Curl_easy *data,
  1683. char *buf, size_t len, CURLcode *err)
  1684. {
  1685. struct cf_h2_ctx *ctx = cf->ctx;
  1686. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1687. ssize_t nread = -1;
  1688. CURLcode result;
  1689. struct cf_call_data save;
  1690. if(!stream) {
  1691. /* Abnormal call sequence: either this transfer has never opened a stream
  1692. * (unlikely) or the transfer has been done, cleaned up its resources, but
  1693. * a read() is called anyway. It is not clear what the calling sequence
  1694. * is for such a case. */
  1695. failf(data, "[%zd-%zd], http/2 recv on a transfer never opened "
  1696. "or already cleared", (ssize_t)data->id,
  1697. (ssize_t)cf->conn->connection_id);
  1698. *err = CURLE_HTTP2;
  1699. return -1;
  1700. }
  1701. CF_DATA_SAVE(save, cf, data);
  1702. nread = stream_recv(cf, data, stream, buf, len, err);
  1703. if(nread < 0 && *err != CURLE_AGAIN)
  1704. goto out;
  1705. if(nread < 0) {
  1706. *err = h2_progress_ingress(cf, data, len);
  1707. if(*err)
  1708. goto out;
  1709. nread = stream_recv(cf, data, stream, buf, len, err);
  1710. }
  1711. if(nread > 0) {
  1712. size_t data_consumed = (size_t)nread;
  1713. /* Now that we transferred this to the upper layer, we report
  1714. * the actual amount of DATA consumed to the H2 session, so
  1715. * that it adjusts stream flow control */
  1716. if(stream->resp_hds_len >= data_consumed) {
  1717. stream->resp_hds_len -= data_consumed; /* no DATA */
  1718. }
  1719. else {
  1720. if(stream->resp_hds_len) {
  1721. data_consumed -= stream->resp_hds_len;
  1722. stream->resp_hds_len = 0;
  1723. }
  1724. if(data_consumed) {
  1725. nghttp2_session_consume(ctx->h2, stream->id, data_consumed);
  1726. }
  1727. }
  1728. if(stream->closed) {
  1729. CURL_TRC_CF(data, cf, "[%d] DRAIN closed stream", stream->id);
  1730. drain_stream(cf, data, stream);
  1731. }
  1732. }
  1733. out:
  1734. result = h2_progress_egress(cf, data);
  1735. if(result == CURLE_AGAIN) {
  1736. /* pending data to send, need to be called again. Ideally, we'd
  1737. * monitor the socket for POLLOUT, but we might not be in SENDING
  1738. * transfer state any longer and are unable to make this happen.
  1739. */
  1740. drain_stream(cf, data, stream);
  1741. }
  1742. else if(result) {
  1743. *err = result;
  1744. nread = -1;
  1745. }
  1746. CURL_TRC_CF(data, cf, "[%d] cf_recv(len=%zu) -> %zd %d, "
  1747. "window=%d/%d, connection %d/%d",
  1748. stream->id, len, nread, *err,
  1749. nghttp2_session_get_stream_effective_recv_data_length(
  1750. ctx->h2, stream->id),
  1751. nghttp2_session_get_stream_effective_local_window_size(
  1752. ctx->h2, stream->id),
  1753. nghttp2_session_get_local_window_size(ctx->h2),
  1754. HTTP2_HUGE_WINDOW_SIZE);
  1755. CF_DATA_RESTORE(cf, save);
  1756. return nread;
  1757. }
  1758. static ssize_t h2_submit(struct h2_stream_ctx **pstream,
  1759. struct Curl_cfilter *cf, struct Curl_easy *data,
  1760. const void *buf, size_t len, CURLcode *err)
  1761. {
  1762. struct cf_h2_ctx *ctx = cf->ctx;
  1763. struct h2_stream_ctx *stream = NULL;
  1764. struct dynhds h2_headers;
  1765. nghttp2_nv *nva = NULL;
  1766. const void *body = NULL;
  1767. size_t nheader, bodylen, i;
  1768. nghttp2_data_provider data_prd;
  1769. int32_t stream_id;
  1770. nghttp2_priority_spec pri_spec;
  1771. ssize_t nwritten;
  1772. Curl_dynhds_init(&h2_headers, 0, DYN_HTTP_REQUEST);
  1773. *err = http2_data_setup(cf, data, &stream);
  1774. if(*err) {
  1775. nwritten = -1;
  1776. goto out;
  1777. }
  1778. nwritten = Curl_h1_req_parse_read(&stream->h1, buf, len, NULL, 0, err);
  1779. if(nwritten < 0)
  1780. goto out;
  1781. if(!stream->h1.done) {
  1782. /* need more data */
  1783. goto out;
  1784. }
  1785. DEBUGASSERT(stream->h1.req);
  1786. *err = Curl_http_req_to_h2(&h2_headers, stream->h1.req, data);
  1787. if(*err) {
  1788. nwritten = -1;
  1789. goto out;
  1790. }
  1791. /* no longer needed */
  1792. Curl_h1_req_parse_free(&stream->h1);
  1793. nva = Curl_dynhds_to_nva(&h2_headers, &nheader);
  1794. if(!nva) {
  1795. *err = CURLE_OUT_OF_MEMORY;
  1796. nwritten = -1;
  1797. goto out;
  1798. }
  1799. h2_pri_spec(data, &pri_spec);
  1800. if(!nghttp2_session_check_request_allowed(ctx->h2))
  1801. CURL_TRC_CF(data, cf, "send request NOT allowed (via nghttp2)");
  1802. switch(data->state.httpreq) {
  1803. case HTTPREQ_POST:
  1804. case HTTPREQ_POST_FORM:
  1805. case HTTPREQ_POST_MIME:
  1806. case HTTPREQ_PUT:
  1807. if(data->state.infilesize != -1)
  1808. stream->upload_left = data->state.infilesize;
  1809. else
  1810. /* data sending without specifying the data amount up front */
  1811. stream->upload_left = -1; /* unknown */
  1812. data_prd.read_callback = req_body_read_callback;
  1813. data_prd.source.ptr = NULL;
  1814. stream_id = nghttp2_submit_request(ctx->h2, &pri_spec, nva, nheader,
  1815. &data_prd, data);
  1816. break;
  1817. default:
  1818. stream->upload_left = 0; /* no request body */
  1819. stream_id = nghttp2_submit_request(ctx->h2, &pri_spec, nva, nheader,
  1820. NULL, data);
  1821. }
  1822. if(stream_id < 0) {
  1823. CURL_TRC_CF(data, cf, "send: nghttp2_submit_request error (%s)%u",
  1824. nghttp2_strerror(stream_id), stream_id);
  1825. *err = CURLE_SEND_ERROR;
  1826. nwritten = -1;
  1827. goto out;
  1828. }
  1829. #define MAX_ACC 60000 /* <64KB to account for some overhead */
  1830. if(Curl_trc_is_verbose(data)) {
  1831. size_t acc = 0;
  1832. infof(data, "[HTTP/2] [%d] OPENED stream for %s",
  1833. stream_id, data->state.url);
  1834. for(i = 0; i < nheader; ++i) {
  1835. acc += nva[i].namelen + nva[i].valuelen;
  1836. infof(data, "[HTTP/2] [%d] [%.*s: %.*s]", stream_id,
  1837. (int)nva[i].namelen, nva[i].name,
  1838. (int)nva[i].valuelen, nva[i].value);
  1839. }
  1840. if(acc > MAX_ACC) {
  1841. infof(data, "[HTTP/2] Warning: The cumulative length of all "
  1842. "headers exceeds %d bytes and that could cause the "
  1843. "stream to be rejected.", MAX_ACC);
  1844. }
  1845. }
  1846. stream->id = stream_id;
  1847. stream->local_window_size = H2_STREAM_WINDOW_SIZE;
  1848. if(data->set.max_recv_speed) {
  1849. /* We are asked to only receive `max_recv_speed` bytes per second.
  1850. * Let's limit our stream window size around that, otherwise the server
  1851. * will send in large bursts only. We make the window 50% larger to
  1852. * allow for data in flight and avoid stalling. */
  1853. curl_off_t n = (((data->set.max_recv_speed - 1) / H2_CHUNK_SIZE) + 1);
  1854. n += CURLMAX((n/2), 1);
  1855. if(n < (H2_STREAM_WINDOW_SIZE / H2_CHUNK_SIZE) &&
  1856. n < (UINT_MAX / H2_CHUNK_SIZE)) {
  1857. stream->local_window_size = (uint32_t)n * H2_CHUNK_SIZE;
  1858. }
  1859. }
  1860. body = (const char *)buf + nwritten;
  1861. bodylen = len - nwritten;
  1862. if(bodylen) {
  1863. /* We have request body to send in DATA frame */
  1864. ssize_t n = Curl_bufq_write(&stream->sendbuf, body, bodylen, err);
  1865. if(n < 0) {
  1866. *err = CURLE_SEND_ERROR;
  1867. nwritten = -1;
  1868. goto out;
  1869. }
  1870. nwritten += n;
  1871. }
  1872. out:
  1873. CURL_TRC_CF(data, cf, "[%d] submit -> %zd, %d",
  1874. stream? stream->id : -1, nwritten, *err);
  1875. Curl_safefree(nva);
  1876. *pstream = stream;
  1877. Curl_dynhds_free(&h2_headers);
  1878. return nwritten;
  1879. }
  1880. static ssize_t cf_h2_send(struct Curl_cfilter *cf, struct Curl_easy *data,
  1881. const void *buf, size_t len, CURLcode *err)
  1882. {
  1883. struct cf_h2_ctx *ctx = cf->ctx;
  1884. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  1885. struct cf_call_data save;
  1886. int rv;
  1887. ssize_t nwritten;
  1888. CURLcode result;
  1889. int blocked = 0, was_blocked = 0;
  1890. CF_DATA_SAVE(save, cf, data);
  1891. if(stream && stream->id != -1) {
  1892. if(stream->upload_blocked_len) {
  1893. /* the data in `buf` has already been submitted or added to the
  1894. * buffers, but have been EAGAINed on the last invocation. */
  1895. /* TODO: this assertion triggers in OSSFuzz runs and it is not
  1896. * clear why. Disable for now to let OSSFuzz continue its tests. */
  1897. DEBUGASSERT(len >= stream->upload_blocked_len);
  1898. if(len < stream->upload_blocked_len) {
  1899. /* Did we get called again with a smaller `len`? This should not
  1900. * happen. We are not prepared to handle that. */
  1901. failf(data, "HTTP/2 send again with decreased length (%zd vs %zd)",
  1902. len, stream->upload_blocked_len);
  1903. *err = CURLE_HTTP2;
  1904. nwritten = -1;
  1905. goto out;
  1906. }
  1907. nwritten = (ssize_t)stream->upload_blocked_len;
  1908. stream->upload_blocked_len = 0;
  1909. was_blocked = 1;
  1910. }
  1911. else if(stream->closed) {
  1912. if(stream->resp_hds_complete) {
  1913. /* Server decided to close the stream after having sent us a findl
  1914. * response. This is valid if it is not interested in the request
  1915. * body. This happens on 30x or 40x responses.
  1916. * We silently discard the data sent, since this is not a transport
  1917. * error situation. */
  1918. CURL_TRC_CF(data, cf, "[%d] discarding data"
  1919. "on closed stream with response", stream->id);
  1920. *err = CURLE_OK;
  1921. nwritten = (ssize_t)len;
  1922. goto out;
  1923. }
  1924. infof(data, "stream %u closed", stream->id);
  1925. *err = CURLE_SEND_ERROR;
  1926. nwritten = -1;
  1927. goto out;
  1928. }
  1929. else {
  1930. /* If stream_id != -1, we have dispatched request HEADERS and
  1931. * optionally request body, and now are going to send or sending
  1932. * more request body in DATA frame */
  1933. nwritten = Curl_bufq_write(&stream->sendbuf, buf, len, err);
  1934. if(nwritten < 0 && *err != CURLE_AGAIN)
  1935. goto out;
  1936. }
  1937. if(!Curl_bufq_is_empty(&stream->sendbuf)) {
  1938. /* req body data is buffered, resume the potentially suspended stream */
  1939. rv = nghttp2_session_resume_data(ctx->h2, stream->id);
  1940. if(nghttp2_is_fatal(rv)) {
  1941. *err = CURLE_SEND_ERROR;
  1942. nwritten = -1;
  1943. goto out;
  1944. }
  1945. }
  1946. }
  1947. else {
  1948. nwritten = h2_submit(&stream, cf, data, buf, len, err);
  1949. if(nwritten < 0) {
  1950. goto out;
  1951. }
  1952. DEBUGASSERT(stream);
  1953. }
  1954. /* Call the nghttp2 send loop and flush to write ALL buffered data,
  1955. * headers and/or request body completely out to the network */
  1956. result = h2_progress_egress(cf, data);
  1957. /* if the stream has been closed in egress handling (nghttp2 does that
  1958. * when it does not like the headers, for example */
  1959. if(stream && stream->closed && !was_blocked) {
  1960. infof(data, "stream %u closed", stream->id);
  1961. *err = CURLE_SEND_ERROR;
  1962. nwritten = -1;
  1963. goto out;
  1964. }
  1965. else if(result == CURLE_AGAIN) {
  1966. blocked = 1;
  1967. }
  1968. else if(result) {
  1969. *err = result;
  1970. nwritten = -1;
  1971. goto out;
  1972. }
  1973. else if(stream && !Curl_bufq_is_empty(&stream->sendbuf)) {
  1974. /* although we wrote everything that nghttp2 wants to send now,
  1975. * there is data left in our stream send buffer unwritten. This may
  1976. * be due to the stream's HTTP/2 flow window being exhausted. */
  1977. blocked = 1;
  1978. }
  1979. if(stream && blocked && nwritten > 0) {
  1980. /* Unable to send all data, due to connection blocked or H2 window
  1981. * exhaustion. Data is left in our stream buffer, or nghttp2's internal
  1982. * frame buffer or our network out buffer. */
  1983. size_t rwin = nghttp2_session_get_stream_remote_window_size(ctx->h2,
  1984. stream->id);
  1985. /* Whatever the cause, we need to return CURL_EAGAIN for this call.
  1986. * We have unwritten state that needs us being invoked again and EAGAIN
  1987. * is the only way to ensure that. */
  1988. stream->upload_blocked_len = nwritten;
  1989. CURL_TRC_CF(data, cf, "[%d] cf_send(len=%zu) BLOCK: win %u/%zu "
  1990. "blocked_len=%zu",
  1991. stream->id, len,
  1992. nghttp2_session_get_remote_window_size(ctx->h2), rwin,
  1993. nwritten);
  1994. *err = CURLE_AGAIN;
  1995. nwritten = -1;
  1996. goto out;
  1997. }
  1998. else if(should_close_session(ctx)) {
  1999. /* nghttp2 thinks this session is done. If the stream has not been
  2000. * closed, this is an error state for out transfer */
  2001. if(stream->closed) {
  2002. nwritten = http2_handle_stream_close(cf, data, stream, err);
  2003. }
  2004. else {
  2005. CURL_TRC_CF(data, cf, "send: nothing to do in this session");
  2006. *err = CURLE_HTTP2;
  2007. nwritten = -1;
  2008. }
  2009. }
  2010. out:
  2011. if(stream) {
  2012. CURL_TRC_CF(data, cf, "[%d] cf_send(len=%zu) -> %zd, %d, "
  2013. "upload_left=%" CURL_FORMAT_CURL_OFF_T ", "
  2014. "h2 windows %d-%d (stream-conn), "
  2015. "buffers %zu-%zu (stream-conn)",
  2016. stream->id, len, nwritten, *err,
  2017. stream->upload_left,
  2018. nghttp2_session_get_stream_remote_window_size(
  2019. ctx->h2, stream->id),
  2020. nghttp2_session_get_remote_window_size(ctx->h2),
  2021. Curl_bufq_len(&stream->sendbuf),
  2022. Curl_bufq_len(&ctx->outbufq));
  2023. }
  2024. else {
  2025. CURL_TRC_CF(data, cf, "cf_send(len=%zu) -> %zd, %d, "
  2026. "connection-window=%d, nw_send_buffer(%zu)",
  2027. len, nwritten, *err,
  2028. nghttp2_session_get_remote_window_size(ctx->h2),
  2029. Curl_bufq_len(&ctx->outbufq));
  2030. }
  2031. CF_DATA_RESTORE(cf, save);
  2032. return nwritten;
  2033. }
  2034. static void cf_h2_adjust_pollset(struct Curl_cfilter *cf,
  2035. struct Curl_easy *data,
  2036. struct easy_pollset *ps)
  2037. {
  2038. struct cf_h2_ctx *ctx = cf->ctx;
  2039. curl_socket_t sock;
  2040. bool want_recv, want_send;
  2041. if(!ctx->h2)
  2042. return;
  2043. sock = Curl_conn_cf_get_socket(cf, data);
  2044. Curl_pollset_check(data, ps, sock, &want_recv, &want_send);
  2045. if(want_recv || want_send) {
  2046. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  2047. struct cf_call_data save;
  2048. bool c_exhaust, s_exhaust;
  2049. CF_DATA_SAVE(save, cf, data);
  2050. c_exhaust = want_send && !nghttp2_session_get_remote_window_size(ctx->h2);
  2051. s_exhaust = want_send && stream && stream->id >= 0 &&
  2052. !nghttp2_session_get_stream_remote_window_size(ctx->h2,
  2053. stream->id);
  2054. want_recv = (want_recv || c_exhaust || s_exhaust);
  2055. want_send = (!s_exhaust && want_send) ||
  2056. (!c_exhaust && nghttp2_session_want_write(ctx->h2));
  2057. Curl_pollset_set(data, ps, sock, want_recv, want_send);
  2058. CF_DATA_RESTORE(cf, save);
  2059. }
  2060. }
  2061. static CURLcode cf_h2_connect(struct Curl_cfilter *cf,
  2062. struct Curl_easy *data,
  2063. bool blocking, bool *done)
  2064. {
  2065. struct cf_h2_ctx *ctx = cf->ctx;
  2066. CURLcode result = CURLE_OK;
  2067. struct cf_call_data save;
  2068. if(cf->connected) {
  2069. *done = TRUE;
  2070. return CURLE_OK;
  2071. }
  2072. /* Connect the lower filters first */
  2073. if(!cf->next->connected) {
  2074. result = Curl_conn_cf_connect(cf->next, data, blocking, done);
  2075. if(result || !*done)
  2076. return result;
  2077. }
  2078. *done = FALSE;
  2079. CF_DATA_SAVE(save, cf, data);
  2080. if(!ctx->h2) {
  2081. result = cf_h2_ctx_init(cf, data, FALSE);
  2082. if(result)
  2083. goto out;
  2084. }
  2085. result = h2_progress_ingress(cf, data, H2_CHUNK_SIZE);
  2086. if(result)
  2087. goto out;
  2088. /* Send out our SETTINGS and ACKs and such. If that blocks, we
  2089. * have it buffered and can count this filter as being connected */
  2090. result = h2_progress_egress(cf, data);
  2091. if(result == CURLE_AGAIN)
  2092. result = CURLE_OK;
  2093. else if(result)
  2094. goto out;
  2095. *done = TRUE;
  2096. cf->connected = TRUE;
  2097. result = CURLE_OK;
  2098. out:
  2099. CURL_TRC_CF(data, cf, "cf_connect() -> %d, %d, ", result, *done);
  2100. CF_DATA_RESTORE(cf, save);
  2101. return result;
  2102. }
  2103. static void cf_h2_close(struct Curl_cfilter *cf, struct Curl_easy *data)
  2104. {
  2105. struct cf_h2_ctx *ctx = cf->ctx;
  2106. if(ctx) {
  2107. struct cf_call_data save;
  2108. CF_DATA_SAVE(save, cf, data);
  2109. cf_h2_ctx_clear(ctx);
  2110. CF_DATA_RESTORE(cf, save);
  2111. }
  2112. if(cf->next)
  2113. cf->next->cft->do_close(cf->next, data);
  2114. }
  2115. static void cf_h2_destroy(struct Curl_cfilter *cf, struct Curl_easy *data)
  2116. {
  2117. struct cf_h2_ctx *ctx = cf->ctx;
  2118. (void)data;
  2119. if(ctx) {
  2120. cf_h2_ctx_free(ctx);
  2121. cf->ctx = NULL;
  2122. }
  2123. }
  2124. static CURLcode http2_data_pause(struct Curl_cfilter *cf,
  2125. struct Curl_easy *data,
  2126. bool pause)
  2127. {
  2128. #ifdef NGHTTP2_HAS_SET_LOCAL_WINDOW_SIZE
  2129. struct cf_h2_ctx *ctx = cf->ctx;
  2130. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  2131. DEBUGASSERT(data);
  2132. if(ctx && ctx->h2 && stream) {
  2133. uint32_t window = pause? 0 : stream->local_window_size;
  2134. int rv = nghttp2_session_set_local_window_size(ctx->h2,
  2135. NGHTTP2_FLAG_NONE,
  2136. stream->id,
  2137. window);
  2138. if(rv) {
  2139. failf(data, "nghttp2_session_set_local_window_size() failed: %s(%d)",
  2140. nghttp2_strerror(rv), rv);
  2141. return CURLE_HTTP2;
  2142. }
  2143. if(!pause)
  2144. drain_stream(cf, data, stream);
  2145. /* attempt to send the window update */
  2146. (void)h2_progress_egress(cf, data);
  2147. if(!pause) {
  2148. /* Unpausing a h2 transfer, requires it to be run again. The server
  2149. * may send new DATA on us increasing the flow window, and it may
  2150. * not. We may have already buffered and exhausted the new window
  2151. * by operating on things in flight during the handling of other
  2152. * transfers. */
  2153. drain_stream(cf, data, stream);
  2154. Curl_expire(data, 0, EXPIRE_RUN_NOW);
  2155. }
  2156. DEBUGF(infof(data, "Set HTTP/2 window size to %u for stream %u",
  2157. window, stream->id));
  2158. #ifdef DEBUGBUILD
  2159. {
  2160. /* read out the stream local window again */
  2161. uint32_t window2 =
  2162. nghttp2_session_get_stream_local_window_size(ctx->h2,
  2163. stream->id);
  2164. DEBUGF(infof(data, "HTTP/2 window size is now %u for stream %u",
  2165. window2, stream->id));
  2166. }
  2167. #endif
  2168. }
  2169. #endif
  2170. return CURLE_OK;
  2171. }
  2172. static CURLcode cf_h2_cntrl(struct Curl_cfilter *cf,
  2173. struct Curl_easy *data,
  2174. int event, int arg1, void *arg2)
  2175. {
  2176. CURLcode result = CURLE_OK;
  2177. struct cf_call_data save;
  2178. (void)arg2;
  2179. CF_DATA_SAVE(save, cf, data);
  2180. switch(event) {
  2181. case CF_CTRL_DATA_SETUP:
  2182. break;
  2183. case CF_CTRL_DATA_PAUSE:
  2184. result = http2_data_pause(cf, data, (arg1 != 0));
  2185. break;
  2186. case CF_CTRL_DATA_DONE_SEND:
  2187. result = http2_data_done_send(cf, data);
  2188. break;
  2189. case CF_CTRL_DATA_DETACH:
  2190. http2_data_done(cf, data, TRUE);
  2191. break;
  2192. case CF_CTRL_DATA_DONE:
  2193. http2_data_done(cf, data, arg1 != 0);
  2194. break;
  2195. default:
  2196. break;
  2197. }
  2198. CF_DATA_RESTORE(cf, save);
  2199. return result;
  2200. }
  2201. static bool cf_h2_data_pending(struct Curl_cfilter *cf,
  2202. const struct Curl_easy *data)
  2203. {
  2204. struct cf_h2_ctx *ctx = cf->ctx;
  2205. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  2206. if(ctx && (!Curl_bufq_is_empty(&ctx->inbufq)
  2207. || (stream && !Curl_bufq_is_empty(&stream->sendbuf))))
  2208. return TRUE;
  2209. return cf->next? cf->next->cft->has_data_pending(cf->next, data) : FALSE;
  2210. }
  2211. static bool cf_h2_is_alive(struct Curl_cfilter *cf,
  2212. struct Curl_easy *data,
  2213. bool *input_pending)
  2214. {
  2215. struct cf_h2_ctx *ctx = cf->ctx;
  2216. CURLcode result;
  2217. struct cf_call_data save;
  2218. CF_DATA_SAVE(save, cf, data);
  2219. result = (ctx && ctx->h2 && http2_connisalive(cf, data, input_pending));
  2220. CURL_TRC_CF(data, cf, "conn alive -> %d, input_pending=%d",
  2221. result, *input_pending);
  2222. CF_DATA_RESTORE(cf, save);
  2223. return result;
  2224. }
  2225. static CURLcode cf_h2_keep_alive(struct Curl_cfilter *cf,
  2226. struct Curl_easy *data)
  2227. {
  2228. CURLcode result;
  2229. struct cf_call_data save;
  2230. CF_DATA_SAVE(save, cf, data);
  2231. result = http2_send_ping(cf, data);
  2232. CF_DATA_RESTORE(cf, save);
  2233. return result;
  2234. }
  2235. static CURLcode cf_h2_query(struct Curl_cfilter *cf,
  2236. struct Curl_easy *data,
  2237. int query, int *pres1, void *pres2)
  2238. {
  2239. struct cf_h2_ctx *ctx = cf->ctx;
  2240. struct cf_call_data save;
  2241. size_t effective_max;
  2242. switch(query) {
  2243. case CF_QUERY_MAX_CONCURRENT:
  2244. DEBUGASSERT(pres1);
  2245. CF_DATA_SAVE(save, cf, data);
  2246. if(nghttp2_session_check_request_allowed(ctx->h2) == 0) {
  2247. /* the limit is what we have in use right now */
  2248. effective_max = CONN_INUSE(cf->conn);
  2249. }
  2250. else {
  2251. effective_max = ctx->max_concurrent_streams;
  2252. }
  2253. *pres1 = (effective_max > INT_MAX)? INT_MAX : (int)effective_max;
  2254. CF_DATA_RESTORE(cf, save);
  2255. return CURLE_OK;
  2256. default:
  2257. break;
  2258. }
  2259. return cf->next?
  2260. cf->next->cft->query(cf->next, data, query, pres1, pres2) :
  2261. CURLE_UNKNOWN_OPTION;
  2262. }
  2263. struct Curl_cftype Curl_cft_nghttp2 = {
  2264. "HTTP/2",
  2265. CF_TYPE_MULTIPLEX,
  2266. CURL_LOG_LVL_NONE,
  2267. cf_h2_destroy,
  2268. cf_h2_connect,
  2269. cf_h2_close,
  2270. Curl_cf_def_get_host,
  2271. cf_h2_adjust_pollset,
  2272. cf_h2_data_pending,
  2273. cf_h2_send,
  2274. cf_h2_recv,
  2275. cf_h2_cntrl,
  2276. cf_h2_is_alive,
  2277. cf_h2_keep_alive,
  2278. cf_h2_query,
  2279. };
  2280. static CURLcode http2_cfilter_add(struct Curl_cfilter **pcf,
  2281. struct Curl_easy *data,
  2282. struct connectdata *conn,
  2283. int sockindex,
  2284. bool via_h1_upgrade)
  2285. {
  2286. struct Curl_cfilter *cf = NULL;
  2287. struct cf_h2_ctx *ctx;
  2288. CURLcode result = CURLE_OUT_OF_MEMORY;
  2289. DEBUGASSERT(data->conn);
  2290. ctx = calloc(1, sizeof(*ctx));
  2291. if(!ctx)
  2292. goto out;
  2293. result = Curl_cf_create(&cf, &Curl_cft_nghttp2, ctx);
  2294. if(result)
  2295. goto out;
  2296. ctx = NULL;
  2297. Curl_conn_cf_add(data, conn, sockindex, cf);
  2298. result = cf_h2_ctx_init(cf, data, via_h1_upgrade);
  2299. out:
  2300. if(result)
  2301. cf_h2_ctx_free(ctx);
  2302. *pcf = result? NULL : cf;
  2303. return result;
  2304. }
  2305. static CURLcode http2_cfilter_insert_after(struct Curl_cfilter *cf,
  2306. struct Curl_easy *data,
  2307. bool via_h1_upgrade)
  2308. {
  2309. struct Curl_cfilter *cf_h2 = NULL;
  2310. struct cf_h2_ctx *ctx;
  2311. CURLcode result = CURLE_OUT_OF_MEMORY;
  2312. (void)data;
  2313. ctx = calloc(1, sizeof(*ctx));
  2314. if(!ctx)
  2315. goto out;
  2316. result = Curl_cf_create(&cf_h2, &Curl_cft_nghttp2, ctx);
  2317. if(result)
  2318. goto out;
  2319. ctx = NULL;
  2320. Curl_conn_cf_insert_after(cf, cf_h2);
  2321. result = cf_h2_ctx_init(cf_h2, data, via_h1_upgrade);
  2322. out:
  2323. if(result)
  2324. cf_h2_ctx_free(ctx);
  2325. return result;
  2326. }
  2327. static bool Curl_cf_is_http2(struct Curl_cfilter *cf,
  2328. const struct Curl_easy *data)
  2329. {
  2330. (void)data;
  2331. for(; cf; cf = cf->next) {
  2332. if(cf->cft == &Curl_cft_nghttp2)
  2333. return TRUE;
  2334. if(cf->cft->flags & CF_TYPE_IP_CONNECT)
  2335. return FALSE;
  2336. }
  2337. return FALSE;
  2338. }
  2339. bool Curl_conn_is_http2(const struct Curl_easy *data,
  2340. const struct connectdata *conn,
  2341. int sockindex)
  2342. {
  2343. return conn? Curl_cf_is_http2(conn->cfilter[sockindex], data) : FALSE;
  2344. }
  2345. bool Curl_http2_may_switch(struct Curl_easy *data,
  2346. struct connectdata *conn,
  2347. int sockindex)
  2348. {
  2349. (void)sockindex;
  2350. if(!Curl_conn_is_http2(data, conn, sockindex) &&
  2351. data->state.httpwant == CURL_HTTP_VERSION_2_PRIOR_KNOWLEDGE) {
  2352. #ifndef CURL_DISABLE_PROXY
  2353. if(conn->bits.httpproxy && !conn->bits.tunnel_proxy) {
  2354. /* We don't support HTTP/2 proxies yet. Also it's debatable
  2355. whether or not this setting should apply to HTTP/2 proxies. */
  2356. infof(data, "Ignoring HTTP/2 prior knowledge due to proxy");
  2357. return FALSE;
  2358. }
  2359. #endif
  2360. return TRUE;
  2361. }
  2362. return FALSE;
  2363. }
  2364. CURLcode Curl_http2_switch(struct Curl_easy *data,
  2365. struct connectdata *conn, int sockindex)
  2366. {
  2367. struct Curl_cfilter *cf;
  2368. CURLcode result;
  2369. DEBUGASSERT(!Curl_conn_is_http2(data, conn, sockindex));
  2370. DEBUGF(infof(data, "switching to HTTP/2"));
  2371. result = http2_cfilter_add(&cf, data, conn, sockindex, FALSE);
  2372. if(result)
  2373. return result;
  2374. conn->httpversion = 20; /* we know we're on HTTP/2 now */
  2375. conn->bits.multiplex = TRUE; /* at least potentially multiplexed */
  2376. conn->bundle->multiuse = BUNDLE_MULTIPLEX;
  2377. Curl_multi_connchanged(data->multi);
  2378. if(cf->next) {
  2379. bool done;
  2380. return Curl_conn_cf_connect(cf, data, FALSE, &done);
  2381. }
  2382. return CURLE_OK;
  2383. }
  2384. CURLcode Curl_http2_switch_at(struct Curl_cfilter *cf, struct Curl_easy *data)
  2385. {
  2386. struct Curl_cfilter *cf_h2;
  2387. CURLcode result;
  2388. DEBUGASSERT(!Curl_cf_is_http2(cf, data));
  2389. result = http2_cfilter_insert_after(cf, data, FALSE);
  2390. if(result)
  2391. return result;
  2392. cf_h2 = cf->next;
  2393. cf->conn->httpversion = 20; /* we know we're on HTTP/2 now */
  2394. cf->conn->bits.multiplex = TRUE; /* at least potentially multiplexed */
  2395. cf->conn->bundle->multiuse = BUNDLE_MULTIPLEX;
  2396. Curl_multi_connchanged(data->multi);
  2397. if(cf_h2->next) {
  2398. bool done;
  2399. return Curl_conn_cf_connect(cf_h2, data, FALSE, &done);
  2400. }
  2401. return CURLE_OK;
  2402. }
  2403. CURLcode Curl_http2_upgrade(struct Curl_easy *data,
  2404. struct connectdata *conn, int sockindex,
  2405. const char *mem, size_t nread)
  2406. {
  2407. struct Curl_cfilter *cf;
  2408. struct cf_h2_ctx *ctx;
  2409. CURLcode result;
  2410. DEBUGASSERT(!Curl_conn_is_http2(data, conn, sockindex));
  2411. DEBUGF(infof(data, "upgrading to HTTP/2"));
  2412. DEBUGASSERT(data->req.upgr101 == UPGR101_RECEIVED);
  2413. result = http2_cfilter_add(&cf, data, conn, sockindex, TRUE);
  2414. if(result)
  2415. return result;
  2416. DEBUGASSERT(cf->cft == &Curl_cft_nghttp2);
  2417. ctx = cf->ctx;
  2418. if(nread > 0) {
  2419. /* Remaining data from the protocol switch reply is already using
  2420. * the switched protocol, ie. HTTP/2. We add that to the network
  2421. * inbufq. */
  2422. ssize_t copied;
  2423. copied = Curl_bufq_write(&ctx->inbufq,
  2424. (const unsigned char *)mem, nread, &result);
  2425. if(copied < 0) {
  2426. failf(data, "error on copying HTTP Upgrade response: %d", result);
  2427. return CURLE_RECV_ERROR;
  2428. }
  2429. if((size_t)copied < nread) {
  2430. failf(data, "connection buffer size could not take all data "
  2431. "from HTTP Upgrade response header: copied=%zd, datalen=%zu",
  2432. copied, nread);
  2433. return CURLE_HTTP2;
  2434. }
  2435. infof(data, "Copied HTTP/2 data in stream buffer to connection buffer"
  2436. " after upgrade: len=%zu", nread);
  2437. }
  2438. conn->httpversion = 20; /* we know we're on HTTP/2 now */
  2439. conn->bits.multiplex = TRUE; /* at least potentially multiplexed */
  2440. conn->bundle->multiuse = BUNDLE_MULTIPLEX;
  2441. Curl_multi_connchanged(data->multi);
  2442. if(cf->next) {
  2443. bool done;
  2444. return Curl_conn_cf_connect(cf, data, FALSE, &done);
  2445. }
  2446. return CURLE_OK;
  2447. }
  2448. /* Only call this function for a transfer that already got an HTTP/2
  2449. CURLE_HTTP2_STREAM error! */
  2450. bool Curl_h2_http_1_1_error(struct Curl_easy *data)
  2451. {
  2452. struct h2_stream_ctx *stream = H2_STREAM_CTX(data);
  2453. return (stream && stream->error == NGHTTP2_HTTP_1_1_REQUIRED);
  2454. }
  2455. #else /* !USE_NGHTTP2 */
  2456. /* Satisfy external references even if http2 is not compiled in. */
  2457. #include <curl/curl.h>
  2458. char *curl_pushheader_bynum(struct curl_pushheaders *h, size_t num)
  2459. {
  2460. (void) h;
  2461. (void) num;
  2462. return NULL;
  2463. }
  2464. char *curl_pushheader_byname(struct curl_pushheaders *h, const char *header)
  2465. {
  2466. (void) h;
  2467. (void) header;
  2468. return NULL;
  2469. }
  2470. #endif /* USE_NGHTTP2 */