blob: b3610e49b3405cb90b306a8c065262c3244f557f [file] [log] [blame]
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001/*
2 * HTTP/3 protocol processing
3 *
4 * This library is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU Lesser General Public
6 * License as published by the Free Software Foundation, version 2.1
7 * exclusively.
8 *
9 * This library is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
12 * Lesser General Public License for more details.
13 *
14 * You should have received a copy of the GNU Lesser General Public
15 * License along with this library; if not, write to the Free Software
16 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
17 */
18
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +020019#include <import/ist.h>
20
21#include <haproxy/api.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010022#include <haproxy/buf.h>
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +020023#include <haproxy/chunk.h>
Amaury Denoyelle99043552021-08-24 15:36:02 +020024#include <haproxy/connection.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010025#include <haproxy/dynbuf.h>
26#include <haproxy/h3.h>
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +020027#include <haproxy/h3_stats.h>
Amaury Denoyelleb49fa1a2021-08-24 15:30:12 +020028#include <haproxy/http.h>
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +020029#include <haproxy/http-hdr-t.h>
Amaury Denoyelle115ccce2022-08-17 18:02:47 +020030#include <haproxy/http_htx.h>
Amaury Denoyelleb49fa1a2021-08-24 15:30:12 +020031#include <haproxy/htx.h>
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +020032#include <haproxy/intops.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010033#include <haproxy/istbuf.h>
Amaury Denoyelle846cc042022-04-04 16:13:44 +020034#include <haproxy/mux_quic.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010035#include <haproxy/pool.h>
Amaury Denoyelle381d8132023-02-17 09:51:20 +010036#include <haproxy/qmux_http.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010037#include <haproxy/qpack-dec.h>
Amaury Denoyelle15b09612021-08-24 16:20:27 +020038#include <haproxy/qpack-enc.h>
Amaury Denoyelle92fa63f2022-09-30 18:11:13 +020039#include <haproxy/quic_conn-t.h>
Amaury Denoyelle15b09612021-08-24 16:20:27 +020040#include <haproxy/quic_enc.h>
Amaury Denoyelle51f116d2023-05-04 15:49:02 +020041#include <haproxy/quic_frame.h>
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +020042#include <haproxy/stats-t.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010043#include <haproxy/tools.h>
Amaury Denoyelle016aa932022-05-30 15:49:36 +020044#include <haproxy/trace.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010045
Amaury Denoyelle016aa932022-05-30 15:49:36 +020046/* trace source and events */
47static void h3_trace(enum trace_level level, uint64_t mask,
48 const struct trace_source *src,
49 const struct ist where, const struct ist func,
50 const void *a1, const void *a2, const void *a3, const void *a4);
51
52static const struct trace_event h3_trace_events[] = {
Amaury Denoyelle494512d2022-05-30 15:50:34 +020053#define H3_EV_RX_FRAME (1ULL << 0)
54 { .mask = H3_EV_RX_FRAME, .name = "rx_frame", .desc = "receipt of any H3 frame" },
55#define H3_EV_RX_DATA (1ULL << 1)
56 { .mask = H3_EV_RX_DATA, .name = "rx_data", .desc = "receipt of H3 DATA frame" },
57#define H3_EV_RX_HDR (1ULL << 2)
58 { .mask = H3_EV_RX_HDR, .name = "rx_hdr", .desc = "receipt of H3 HEADERS frame" },
59#define H3_EV_RX_SETTINGS (1ULL << 3)
60 { .mask = H3_EV_RX_SETTINGS, .name = "rx_settings", .desc = "receipt of H3 SETTINGS frame" },
Amaury Denoyellea717eb72022-05-30 15:51:01 +020061#define H3_EV_TX_DATA (1ULL << 4)
62 { .mask = H3_EV_TX_DATA, .name = "tx_data", .desc = "transmission of H3 DATA frame" },
63#define H3_EV_TX_HDR (1ULL << 5)
64 { .mask = H3_EV_TX_HDR, .name = "tx_hdr", .desc = "transmission of H3 HEADERS frame" },
65#define H3_EV_TX_SETTINGS (1ULL << 6)
66 { .mask = H3_EV_TX_SETTINGS, .name = "tx_settings", .desc = "transmission of H3 SETTINGS frame" },
Amaury Denoyelled5581d52022-05-30 15:51:31 +020067#define H3_EV_H3S_NEW (1ULL << 7)
68 { .mask = H3_EV_H3S_NEW, .name = "h3s_new", .desc = "new H3 stream" },
69#define H3_EV_H3S_END (1ULL << 8)
70 { .mask = H3_EV_H3S_END, .name = "h3s_end", .desc = "H3 stream terminated" },
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +010071#define H3_EV_H3C_END (1ULL << 9)
72 { .mask = H3_EV_H3C_END, .name = "h3c_end", .desc = "H3 connection terminated" },
Amaury Denoyelle44083ac2024-01-29 15:15:27 +010073#define H3_EV_STRM_SEND (1ULL << 12)
74 { .mask = H3_EV_STRM_SEND, .name = "strm_send", .desc = "sending data for stream" },
Amaury Denoyelle016aa932022-05-30 15:49:36 +020075 { }
76};
77
78static const struct name_desc h3_trace_lockon_args[4] = {
79 /* arg1 */ { /* already used by the connection */ },
80 /* arg2 */ { .name="qcs", .desc="QUIC stream" },
81 /* arg3 */ { },
82 /* arg4 */ { }
83};
84
85static const struct name_desc h3_trace_decoding[] = {
86#define H3_VERB_CLEAN 1
87 { .name="clean", .desc="only user-friendly stuff, generally suitable for level \"user\"" },
88#define H3_VERB_MINIMAL 2
89 { .name="minimal", .desc="report only qcc/qcs state and flags, no real decoding" },
90 { /* end */ }
91};
92
93struct trace_source trace_h3 = {
94 .name = IST("h3"),
95 .desc = "HTTP/3 transcoder",
96 .arg_def = TRC_ARG1_CONN, /* TRACE()'s first argument is always a connection */
97 .default_cb = h3_trace,
98 .known_events = h3_trace_events,
99 .lockon_args = h3_trace_lockon_args,
100 .decoding = h3_trace_decoding,
101 .report_events = ~0, /* report everything by default */
102};
103
104#define TRACE_SOURCE &trace_h3
105INITCALL1(STG_REGISTER, trace_register_source, TRACE_SOURCE);
106
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100107#if defined(DEBUG_H3)
108#define h3_debug_printf fprintf
109#define h3_debug_hexdump debug_hexdump
110#else
111#define h3_debug_printf(...) do { } while (0)
112#define h3_debug_hexdump(...) do { } while (0)
113#endif
114
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200115#define H3_CF_SETTINGS_SENT 0x00000001 /* SETTINGS frame already sent on local control stream */
116#define H3_CF_SETTINGS_RECV 0x00000002 /* SETTINGS frame already received on remote control stream */
117#define H3_CF_UNI_CTRL_SET 0x00000004 /* Remote H3 Control stream opened */
118#define H3_CF_UNI_QPACK_DEC_SET 0x00000008 /* Remote QPACK decoder stream opened */
119#define H3_CF_UNI_QPACK_ENC_SET 0x00000010 /* Remote QPACK encoder stream opened */
Amaury Denoyelle3d550842023-01-24 17:42:21 +0100120#define H3_CF_GOAWAY_SENT 0x00000020 /* GOAWAY sent on local control stream */
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100121
122/* Default settings */
Amaury Denoyelle33949392021-08-24 15:16:58 +0200123static uint64_t h3_settings_qpack_max_table_capacity = 0;
124static uint64_t h3_settings_qpack_blocked_streams = 4096;
125static uint64_t h3_settings_max_field_section_size = QUIC_VARINT_8_BYTE_MAX; /* Unlimited */
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100126
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +0200127struct h3c {
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100128 struct qcc *qcc;
Amaury Denoyelled7010392022-07-13 15:17:29 +0200129 struct qcs *ctrl_strm; /* Control stream */
Amaury Denoyellec3c4d1b2024-05-13 16:01:08 +0200130 int err;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100131 uint32_t flags;
Amaury Denoyelle9cc47512022-05-24 16:27:41 +0200132
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100133 /* Settings */
134 uint64_t qpack_max_table_capacity;
135 uint64_t qpack_blocked_streams;
136 uint64_t max_field_section_size;
Amaury Denoyelle9cc47512022-05-24 16:27:41 +0200137
Amaury Denoyelle114c9c82022-03-28 14:53:45 +0200138 uint64_t id_goaway; /* stream ID used for a GOAWAY frame */
139
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100140 struct buffer_wait buf_wait; /* wait list for buffer allocations */
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +0200141 /* Stats counters */
142 struct h3_counters *prx_counters;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100143};
144
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +0200145DECLARE_STATIC_POOL(pool_head_h3c, "h3c", sizeof(struct h3c));
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100146
Amaury Denoyelle35550642022-05-24 15:14:53 +0200147#define H3_SF_UNI_INIT 0x00000001 /* stream type not parsed for unidirectional stream */
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200148#define H3_SF_UNI_NO_H3 0x00000002 /* unidirectional stream does not carry H3 frames */
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100149#define H3_SF_HAVE_CLEN 0x00000004 /* content-length header is present */
Amaury Denoyelle35550642022-05-24 15:14:53 +0200150
Amaury Denoyelle67e92d32022-04-27 18:04:01 +0200151struct h3s {
Amaury Denoyellec0156792022-06-03 15:29:07 +0200152 struct h3c *h3c;
153
Amaury Denoyelle3236a8e2022-05-24 15:24:03 +0200154 enum h3s_t type;
Amaury Denoyelle8d818c62022-08-02 11:32:45 +0200155 enum h3s_st_req st_req; /* only used for request streams */
Amaury Denoyelle35d90532023-01-26 16:03:45 +0100156 uint64_t demux_frame_len;
157 uint64_t demux_frame_type;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200158
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100159 unsigned long long body_len; /* known request body length from content-length header if present */
160 unsigned long long data_len; /* total length of all parsed DATA */
161
Amaury Denoyelle35550642022-05-24 15:14:53 +0200162 int flags;
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100163 int err; /* used for stream reset */
Amaury Denoyelle67e92d32022-04-27 18:04:01 +0200164};
165
166DECLARE_STATIC_POOL(pool_head_h3s, "h3s", sizeof(struct h3s));
167
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200168/* Initialize an uni-stream <qcs> by reading its type from <b>.
Amaury Denoyelle35550642022-05-24 15:14:53 +0200169 *
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200170 * Returns the count of consumed bytes or a negative error code.
Amaury Denoyelle35550642022-05-24 15:14:53 +0200171 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200172static ssize_t h3_init_uni_stream(struct h3c *h3c, struct qcs *qcs,
173 struct buffer *b)
Amaury Denoyelle35550642022-05-24 15:14:53 +0200174{
175 /* decode unidirectional stream type */
176 struct h3s *h3s = qcs->ctx;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200177 uint64_t type;
178 size_t len = 0, ret;
179
Amaury Denoyelled5581d52022-05-30 15:51:31 +0200180 TRACE_ENTER(H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
181
Amaury Denoyelle8d6d2462023-05-11 16:55:30 +0200182 /* Function reserved to uni streams. Must be called only once per stream instance. */
183 BUG_ON(!quic_stream_is_uni(qcs->id) || h3s->flags & H3_SF_UNI_INIT);
Amaury Denoyelle35550642022-05-24 15:14:53 +0200184
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200185 ret = b_quic_dec_int(&type, b, &len);
Amaury Denoyelle35550642022-05-24 15:14:53 +0200186 if (!ret) {
Amaury Denoyelle5aa21c12023-03-09 11:12:32 +0100187 /* not enough data to decode uni stream type, retry later */
188 TRACE_DATA("cannot decode uni stream type due to incomplete data", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
189 goto out;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200190 }
191
192 switch (type) {
193 case H3_UNI_S_T_CTRL:
194 if (h3c->flags & H3_CF_UNI_CTRL_SET) {
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100195 TRACE_ERROR("duplicated control stream", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +0200196 qcc_set_error(qcs->qcc, H3_STREAM_CREATION_ERROR, 1);
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100197 goto err;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200198 }
199 h3c->flags |= H3_CF_UNI_CTRL_SET;
200 h3s->type = H3S_T_CTRL;
201 break;
202
203 case H3_UNI_S_T_PUSH:
204 /* TODO not supported for the moment */
205 h3s->type = H3S_T_PUSH;
206 break;
207
208 case H3_UNI_S_T_QPACK_DEC:
209 if (h3c->flags & H3_CF_UNI_QPACK_DEC_SET) {
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100210 TRACE_ERROR("duplicated qpack decoder stream", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +0200211 qcc_set_error(qcs->qcc, H3_STREAM_CREATION_ERROR, 1);
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100212 goto err;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200213 }
214 h3c->flags |= H3_CF_UNI_QPACK_DEC_SET;
215 h3s->type = H3S_T_QPACK_DEC;
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200216 h3s->flags |= H3_SF_UNI_NO_H3;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200217 break;
218
219 case H3_UNI_S_T_QPACK_ENC:
220 if (h3c->flags & H3_CF_UNI_QPACK_ENC_SET) {
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100221 TRACE_ERROR("duplicated qpack encoder stream", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +0200222 qcc_set_error(qcs->qcc, H3_STREAM_CREATION_ERROR, 1);
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100223 goto err;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200224 }
225 h3c->flags |= H3_CF_UNI_QPACK_ENC_SET;
226 h3s->type = H3S_T_QPACK_ENC;
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200227 h3s->flags |= H3_SF_UNI_NO_H3;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200228 break;
229
230 default:
Amaury Denoyelle849b24f2022-05-24 17:22:07 +0200231 /* draft-ietf-quic-http34 9. Extensions to HTTP/3
232 *
233 * Implementations MUST [...] abort reading on unidirectional
234 * streams that have unknown or unsupported types.
235 */
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100236 TRACE_STATE("abort reading on unknown uni stream type", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle663e8722022-12-09 14:58:28 +0100237 qcc_abort_stream_read(qcs);
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100238 goto err;
239 }
Amaury Denoyelle35550642022-05-24 15:14:53 +0200240
241 h3s->flags |= H3_SF_UNI_INIT;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200242
Amaury Denoyelle5aa21c12023-03-09 11:12:32 +0100243 out:
Amaury Denoyelled5581d52022-05-30 15:51:31 +0200244 TRACE_LEAVE(H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200245 return len;
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100246
247 err:
248 TRACE_DEVEL("leaving on error", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
249 return -1;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200250}
251
Amaury Denoyelle26aa3992022-08-16 17:42:47 +0200252/* Parse a buffer <b> for a <qcs> uni-stream which does not contains H3 frames.
253 * This may be used for QPACK encoder/decoder streams for example. <fin> is set
254 * if this is the last frame of the stream.
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200255 *
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200256 * Returns the number of consumed bytes or a negative error code.
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200257 */
Amaury Denoyelle26aa3992022-08-16 17:42:47 +0200258static ssize_t h3_parse_uni_stream_no_h3(struct qcs *qcs, struct buffer *b, int fin)
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200259{
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200260 struct h3s *h3s = qcs->ctx;
261
Amaury Denoyelle8d6d2462023-05-11 16:55:30 +0200262 /* Function reserved to non-HTTP/3 unidirectional streams. */
263 BUG_ON(!quic_stream_is_uni(qcs->id) || !(h3s->flags & H3_SF_UNI_NO_H3));
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200264
265 switch (h3s->type) {
266 case H3S_T_QPACK_DEC:
Amaury Denoyelle26aa3992022-08-16 17:42:47 +0200267 if (qpack_decode_dec(b, fin, qcs))
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200268 return -1;
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200269 break;
270 case H3S_T_QPACK_ENC:
Amaury Denoyelle26aa3992022-08-16 17:42:47 +0200271 if (qpack_decode_enc(b, fin, qcs))
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200272 return -1;
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200273 break;
Amaury Denoyelle849b24f2022-05-24 17:22:07 +0200274 case H3S_T_UNKNOWN:
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200275 default:
Amaury Denoyelle849b24f2022-05-24 17:22:07 +0200276 /* Unknown stream should be flagged with QC_SF_READ_ABORTED. */
277 ABORT_NOW();
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200278 }
279
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200280 /* TODO adjust return code */
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200281 return 0;
282}
283
Amaury Denoyelle88d5dd12022-05-31 11:44:52 +0200284/* Decode a H3 frame header from <rxbuf> buffer. The frame type is stored in
285 * <ftype> and length in <flen>.
286 *
287 * Returns the size of the H3 frame header. Note that the input buffer is not
288 * consumed.
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100289 */
290static inline size_t h3_decode_frm_header(uint64_t *ftype, uint64_t *flen,
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200291 struct buffer *b)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100292{
293 size_t hlen;
294
295 hlen = 0;
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200296 if (!b_quic_dec_int(ftype, b, &hlen) ||
297 !b_quic_dec_int(flen, b, &hlen)) {
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100298 return 0;
Amaury Denoyelle88d5dd12022-05-31 11:44:52 +0200299 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100300
301 return hlen;
302}
303
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200304/* Check if H3 frame of type <ftype> is valid when received on stream <qcs>.
305 *
306 * Returns a boolean. If false, a connection error H3_FRAME_UNEXPECTED should
307 * be reported.
308 */
309static int h3_is_frame_valid(struct h3c *h3c, struct qcs *qcs, uint64_t ftype)
310{
311 struct h3s *h3s = qcs->ctx;
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200312
Amaury Denoyelle8d6d2462023-05-11 16:55:30 +0200313 /* Stream type must be known to ensure frame is valid for this stream. */
314 BUG_ON(h3s->type == H3S_T_UNKNOWN);
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200315
316 switch (ftype) {
317 case H3_FT_DATA:
Amaury Denoyelle8d818c62022-08-02 11:32:45 +0200318 return h3s->type != H3S_T_CTRL && (h3s->st_req == H3S_ST_REQ_HEADERS ||
319 h3s->st_req == H3S_ST_REQ_DATA);
320
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200321 case H3_FT_HEADERS:
Amaury Denoyelle8d818c62022-08-02 11:32:45 +0200322 return h3s->type != H3S_T_CTRL && h3s->st_req != H3S_ST_REQ_TRAILERS;
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200323
324 case H3_FT_CANCEL_PUSH:
325 case H3_FT_GOAWAY:
326 case H3_FT_MAX_PUSH_ID:
327 /* Only allowed for control stream. First frame of control
328 * stream MUST be SETTINGS.
329 */
330 return h3s->type == H3S_T_CTRL &&
331 (h3c->flags & H3_CF_SETTINGS_RECV);
332
333 case H3_FT_SETTINGS:
334 /* draft-ietf-quic-http34 7.2.4. SETTINGS
335 *
336 * If an endpoint receives a second SETTINGS frame on the control
337 * stream, the endpoint MUST respond with a connection error of type
338 * H3_FRAME_UNEXPECTED.
339 */
340 return h3s->type == H3S_T_CTRL &&
341 !(h3c->flags & H3_CF_SETTINGS_RECV);
342
343 case H3_FT_PUSH_PROMISE:
Amaury Denoyelle68bf6c82023-11-28 12:00:40 +0100344 /* RFC 9114 7.2.5. PUSH_PROMISE
345 * A client MUST NOT send a PUSH_PROMISE frame. A server MUST treat the
346 * receipt of a PUSH_PROMISE frame as a connection error of type
347 * H3_FRAME_UNEXPECTED.
348 */
349
350 /* TODO server-side only. */
351 return 0;
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200352
353 default:
354 /* draft-ietf-quic-http34 9. Extensions to HTTP/3
355 *
356 * Implementations MUST discard frames [...] that have unknown
357 * or unsupported types.
358 */
359 return h3s->type != H3S_T_CTRL || (h3c->flags & H3_CF_SETTINGS_RECV);
360 }
361}
362
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100363/* Check from stream <qcs> that length of all DATA frames does not exceed with
364 * a previously parsed content-length header. <fin> must be set for the last
365 * data of the stream so that length of DATA frames must be equal to the
366 * content-length.
367 *
368 * This must only be called for a stream with H3_SF_HAVE_CLEN flag.
369 *
370 * Return 0 on valid else non-zero.
371 */
372static int h3_check_body_size(struct qcs *qcs, int fin)
373{
374 struct h3s *h3s = qcs->ctx;
375 int ret = 0;
376 TRACE_ENTER(H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
377
378 /* Reserved for streams with a previously parsed content-length header. */
379 BUG_ON(!(h3s->flags & H3_SF_HAVE_CLEN));
380
381 /* RFC 9114 4.1.2. Malformed Requests and Responses
382 *
383 * A request or response that is defined as having content when it
384 * contains a Content-Length header field (Section 8.6 of [HTTP]) is
385 * malformed if the value of the Content-Length header field does not
386 * equal the sum of the DATA frame lengths received.
387 *
388 * TODO for backend support
389 * A response that is
390 * defined as never having content, even when a Content-Length is
391 * present, can have a non-zero Content-Length header field even though
392 * no content is included in DATA frames.
393 */
394 if (h3s->data_len > h3s->body_len ||
395 (fin && h3s->data_len < h3s->body_len)) {
396 TRACE_ERROR("Content-length does not match DATA frame size", H3_EV_RX_FRAME|H3_EV_RX_DATA, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100397 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100398 ret = -1;
399 }
400
401 TRACE_LEAVE(H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
402 return ret;
403}
404
Amaury Denoyellea514a112023-10-09 16:14:44 +0200405/* Set <auth> authority header to the new value <value> for <qcs> stream. This
406 * ensures that value is conformant to the specification. If <auth> is a
407 * non-null length string, it ensures that <value> is identical to it.
408 *
409 * Returns 0 on success else non-zero.
410 */
411static int h3_set_authority(struct qcs *qcs, struct ist *auth, const struct ist value)
412{
413 /* RFC 9114 4.3.1. Request Pseudo-Header Fields
414 *
415 * If the :scheme pseudo-header field identifies a scheme that has a
416 * mandatory authority component (including "http" and "https"), the
417 * request MUST contain either an :authority pseudo-header field or a
418 * Host header field. If these fields are present, they MUST NOT be
419 * empty. If both fields are present, they MUST contain the same value.
420 */
421
422 /* Check that if a previous value is set the new value is identical. */
423 if (isttest(*auth) && !isteq(*auth, value)) {
424 TRACE_ERROR("difference between :authority and host headers", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
425 return 1;
426 }
427
428 /* Check that value is not empty. */
429 if (!istlen(value)) {
430 TRACE_ERROR("empty :authority/host header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
431 return 1;
432 }
433
434 *auth = value;
435 return 0;
436}
437
Amaury Denoyellec3c4d1b2024-05-13 16:01:08 +0200438/* Return <value> as is or H3_INTERNAL_ERROR if negative. Useful to prepare a standard error code. */
439static int h3_err(const int value)
440{
441 return value >= 0 ? value : H3_INTERNAL_ERROR;
442}
443
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100444/* Parse from buffer <buf> a H3 HEADERS frame of length <len>. Data are copied
Willy Tarreau4596fe22022-05-17 19:07:51 +0200445 * in a local HTX buffer and transfer to the stream connector layer. <fin> must be
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100446 * set if this is the last data to transfer from this stream.
447 *
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100448 * Returns the number of consumed bytes or a negative error code. On error
449 * either the connection should be closed or the stream reset using codes
450 * provided in h3c.err / h3s.err.
Amaury Denoyelleb9ce14e2021-11-08 09:13:42 +0100451 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200452static ssize_t h3_headers_to_htx(struct qcs *qcs, const struct buffer *buf,
453 uint64_t len, char fin)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100454{
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200455 struct h3s *h3s = qcs->ctx;
456 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100457 struct buffer htx_buf = BUF_NULL;
458 struct buffer *tmp = get_trash_chunk();
Amaury Denoyelle7059ebc2021-12-08 15:51:04 +0100459 struct htx *htx = NULL;
Amaury Denoyelleb49fa1a2021-08-24 15:30:12 +0200460 struct htx_sl *sl;
Amaury Denoyellefd7cdc32021-08-24 15:13:20 +0200461 struct http_hdr list[global.tune.max_http_hdr];
Amaury Denoyelleb49fa1a2021-08-24 15:30:12 +0200462 unsigned int flags = HTX_SL_F_NONE;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100463 struct ist meth = IST_NULL, path = IST_NULL;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100464 struct ist scheme = IST_NULL, authority = IST_NULL;
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200465 int hdr_idx, ret;
Amaury Denoyelled6fb7a02022-12-07 14:31:42 +0100466 int cookie = -1, last_cookie = -1, i;
Willy Tarreau0404bf12023-08-08 17:18:27 +0200467 const char *ctl;
Willy Tarreau96dfea82023-08-08 17:54:26 +0200468 int relaxed = !!(h3c->qcc->proxy->options2 & PR_O2_REQBUG_OK);
Amaury Denoyelled6fb7a02022-12-07 14:31:42 +0100469
470 /* RFC 9114 4.1.2. Malformed Requests and Responses
471 *
472 * A malformed request or response is one that is an otherwise valid
473 * sequence of frames but is invalid due to:
474 * - the presence of prohibited fields or pseudo-header fields,
475 * - the absence of mandatory pseudo-header fields,
476 * - invalid values for pseudo-header fields,
477 * - pseudo-header fields after fields,
478 * - an invalid sequence of HTTP messages,
479 * - the inclusion of uppercase field names, or
480 * - the inclusion of invalid characters in field names or values.
481 *
482 * [...]
483 *
484 * Intermediaries that process HTTP requests or responses (i.e., any
485 * intermediary not acting as a tunnel) MUST NOT forward a malformed
486 * request or response. Malformed requests or responses that are
487 * detected MUST be treated as a stream error of type H3_MESSAGE_ERROR.
488 */
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100489
Amaury Denoyelle494512d2022-05-30 15:50:34 +0200490 TRACE_ENTER(H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
491
Amaury Denoyelle8d818c62022-08-02 11:32:45 +0200492 /* TODO support trailer parsing in this function */
493
Amaury Denoyelle30f23f52022-04-27 14:41:53 +0200494 /* TODO support buffer wrapping */
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200495 BUG_ON(b_head(buf) + len >= b_wrap(buf));
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200496 ret = qpack_decode_fs((const unsigned char *)b_head(buf), len, tmp,
497 list, sizeof(list) / sizeof(list[0]));
498 if (ret < 0) {
499 TRACE_ERROR("QPACK decoding error", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyellec3c4d1b2024-05-13 16:01:08 +0200500 h3c->err = h3_err(qpack_err_decode(ret));
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100501 len = -1;
502 goto out;
Amaury Denoyelle60ef19f2022-06-14 17:38:36 +0200503 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100504
Amaury Denoyelled68f8b52023-05-30 15:04:46 +0200505 if (!qcs_get_buf(qcs, &htx_buf)) {
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +0200506 TRACE_ERROR("HTX buffer alloc failure", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
507 h3c->err = H3_INTERNAL_ERROR;
508 len = -1;
509 goto out;
510 }
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100511 BUG_ON(!b_size(&htx_buf)); /* TODO */
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100512 htx = htx_from_buf(&htx_buf);
513
514 /* first treat pseudo-header to build the start line */
515 hdr_idx = 0;
516 while (1) {
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100517 /* RFC 9114 4.3. HTTP Control Data
518 *
519 * Endpoints MUST treat a request or response that contains
520 * undefined or invalid pseudo-header fields as malformed.
521 *
522 * All pseudo-header fields MUST appear in the header section before
523 * regular header fields. Any request or response that contains a
524 * pseudo-header field that appears in a header section after a regular
525 * header field MUST be treated as malformed.
526 */
527
528 /* Stop at first non pseudo-header. */
529 if (!istmatch(list[hdr_idx].n, ist(":")))
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100530 break;
531
Willy Tarreau0404bf12023-08-08 17:18:27 +0200532 /* RFC 9114 10.3 Intermediary-Encapsulation Attacks
533 *
534 * While most values that can be encoded will not alter field
535 * parsing, carriage return (ASCII 0x0d), line feed (ASCII 0x0a),
536 * and the null character (ASCII 0x00) might be exploited by an
537 * attacker if they are translated verbatim. Any request or
538 * response that contains a character not permitted in a field
539 * value MUST be treated as malformed
540 */
541
542 /* look for forbidden control characters in the pseudo-header value */
543 ctl = ist_find_ctl(list[hdr_idx].v);
544 if (unlikely(ctl) && http_header_has_forbidden_char(list[hdr_idx].v, ctl)) {
545 TRACE_ERROR("control character present in pseudo-header value", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
546 h3s->err = H3_MESSAGE_ERROR;
547 len = -1;
548 goto out;
549 }
550
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100551 /* pseudo-header. Malformed name with uppercase character or
552 * invalid token will be rejected in the else clause.
553 */
554 if (isteq(list[hdr_idx].n, ist(":method"))) {
555 if (isttest(meth)) {
556 TRACE_ERROR("duplicated method pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100557 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100558 len = -1;
559 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100560 }
561 meth = list[hdr_idx].v;
562 }
563 else if (isteq(list[hdr_idx].n, ist(":path"))) {
564 if (isttest(path)) {
565 TRACE_ERROR("duplicated path pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100566 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100567 len = -1;
568 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100569 }
Willy Tarreau96dfea82023-08-08 17:54:26 +0200570
571 if (!relaxed) {
572 /* we need to reject any control chars or '#' from the path,
573 * unless option accept-invalid-http-request is set.
574 */
575 ctl = ist_find_range(list[hdr_idx].v, 0, '#');
576 if (unlikely(ctl) && http_path_has_forbidden_char(list[hdr_idx].v, ctl)) {
577 TRACE_ERROR("forbidden character in ':path' pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
578 h3s->err = H3_MESSAGE_ERROR;
579 len = -1;
580 goto out;
581 }
582 }
583
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100584 path = list[hdr_idx].v;
585 }
586 else if (isteq(list[hdr_idx].n, ist(":scheme"))) {
587 if (isttest(scheme)) {
588 /* duplicated pseudo-header */
589 TRACE_ERROR("duplicated scheme pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100590 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100591 len = -1;
592 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100593 }
594 scheme = list[hdr_idx].v;
595 }
596 else if (isteq(list[hdr_idx].n, ist(":authority"))) {
597 if (isttest(authority)) {
598 TRACE_ERROR("duplicated authority pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100599 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100600 len = -1;
601 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100602 }
Amaury Denoyellea514a112023-10-09 16:14:44 +0200603
604 if (h3_set_authority(qcs, &authority, list[hdr_idx].v)) {
605 h3s->err = H3_MESSAGE_ERROR;
606 len = -1;
607 goto out;
608 }
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100609 }
610 else {
611 TRACE_ERROR("unknown pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100612 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100613 len = -1;
614 goto out;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100615 }
616
617 ++hdr_idx;
618 }
619
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100620 if (!istmatch(meth, ist("CONNECT"))) {
621 /* RFC 9114 4.3.1. Request Pseudo-Header Fields
622 *
623 * All HTTP/3 requests MUST include exactly one value for the :method,
624 * :scheme, and :path pseudo-header fields, unless the request is a
625 * CONNECT request; see Section 4.4.
626 */
627 if (!isttest(meth) || !isttest(scheme) || !isttest(path)) {
628 TRACE_ERROR("missing mandatory pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100629 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100630 len = -1;
631 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100632 }
633 }
634
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100635 flags |= HTX_SL_F_VER_11;
Amaury Denoyelle0fa14a62022-04-26 16:24:39 +0200636 flags |= HTX_SL_F_XFER_LEN;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100637
638 sl = htx_add_stline(htx, HTX_BLK_REQ_SL, flags, meth, path, ist("HTTP/3.0"));
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200639 if (!sl) {
640 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100641 len = -1;
642 goto out;
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200643 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100644
645 if (fin)
646 sl->flags |= HTX_SL_F_BODYLESS;
647
648 sl->info.req.meth = find_http_meth(meth.ptr, meth.len);
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100649
Amaury Denoyellec4913f62022-12-15 10:58:05 +0100650 if (isttest(authority)) {
651 if (!htx_add_header(htx, ist("host"), authority)) {
652 h3c->err = H3_INTERNAL_ERROR;
653 len = -1;
654 goto out;
655 }
656 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100657
658 /* now treat standard headers */
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100659 while (1) {
660 if (isteq(list[hdr_idx].n, ist("")))
661 break;
662
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100663 if (istmatch(list[hdr_idx].n, ist(":"))) {
664 TRACE_ERROR("pseudo-header field after fields", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100665 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100666 len = -1;
667 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100668 }
669
Amaury Denoyelled6fb7a02022-12-07 14:31:42 +0100670 for (i = 0; i < list[hdr_idx].n.len; ++i) {
671 const char c = list[hdr_idx].n.ptr[i];
672 if ((uint8_t)(c - 'A') < 'Z' - 'A' || !HTTP_IS_TOKEN(c)) {
673 TRACE_ERROR("invalid characters in field name", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100674 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100675 len = -1;
676 goto out;
Amaury Denoyelled6fb7a02022-12-07 14:31:42 +0100677 }
678 }
679
Willy Tarreau0404bf12023-08-08 17:18:27 +0200680
681 /* RFC 9114 10.3 Intermediary-Encapsulation Attacks
682 *
683 * While most values that can be encoded will not alter field
684 * parsing, carriage return (ASCII 0x0d), line feed (ASCII 0x0a),
685 * and the null character (ASCII 0x00) might be exploited by an
686 * attacker if they are translated verbatim. Any request or
687 * response that contains a character not permitted in a field
688 * value MUST be treated as malformed
689 */
690
691 /* look for forbidden control characters in the header value */
692 ctl = ist_find_ctl(list[hdr_idx].v);
693 if (unlikely(ctl) && http_header_has_forbidden_char(list[hdr_idx].v, ctl)) {
694 TRACE_ERROR("control character present in header value", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
695 h3s->err = H3_MESSAGE_ERROR;
696 len = -1;
697 goto out;
698 }
699
Amaury Denoyellea514a112023-10-09 16:14:44 +0200700 if (isteq(list[hdr_idx].n, ist("host"))) {
701 if (h3_set_authority(qcs, &authority, list[hdr_idx].v)) {
702 h3s->err = H3_MESSAGE_ERROR;
703 len = -1;
704 goto out;
705 }
706 }
707 else if (isteq(list[hdr_idx].n, ist("cookie"))) {
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200708 http_cookie_register(list, hdr_idx, &cookie, &last_cookie);
Amaury Denoyelle19942e32022-12-15 09:18:25 +0100709 ++hdr_idx;
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200710 continue;
711 }
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100712 else if (isteq(list[hdr_idx].n, ist("content-length"))) {
713 ret = http_parse_cont_len_header(&list[hdr_idx].v,
714 &h3s->body_len,
715 h3s->flags & H3_SF_HAVE_CLEN);
716 if (ret < 0) {
717 TRACE_ERROR("invalid content-length", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100718 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100719 len = -1;
720 goto out;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100721 }
722 else if (!ret) {
723 /* Skip duplicated value. */
724 ++hdr_idx;
725 continue;
726 }
727
728 h3s->flags |= H3_SF_HAVE_CLEN;
Christopher Faulet87230d32023-07-24 11:37:10 +0200729 sl->flags |= HTX_SL_F_CLEN;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100730 /* This will fail if current frame is the last one and
731 * content-length is not null.
732 */
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100733 if (h3_check_body_size(qcs, fin)) {
734 len = -1;
735 goto out;
736 }
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100737 }
Amaury Denoyelle8ad26692023-01-17 17:47:06 +0100738 else if (isteq(list[hdr_idx].n, ist("connection")) ||
739 isteq(list[hdr_idx].n, ist("proxy-connection")) ||
740 isteq(list[hdr_idx].n, ist("keep-alive")) ||
741 isteq(list[hdr_idx].n, ist("transfer-encoding"))) {
742 /* RFC 9114 4.2. HTTP Fields
743 *
744 * HTTP/3 does not use the Connection header field to indicate
745 * connection-specific fields; in this protocol, connection-
746 * specific metadata is conveyed by other means. An endpoint
747 * MUST NOT generate an HTTP/3 field section containing
748 * connection-specific fields; any message containing
749 * connection-specific fields MUST be treated as malformed.
750 */
751 TRACE_ERROR("invalid connection header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
752 h3s->err = H3_MESSAGE_ERROR;
753 len = -1;
754 goto out;
755 }
756 else if (isteq(list[hdr_idx].n, ist("te")) &&
757 !isteq(list[hdr_idx].v, ist("trailers"))) {
758 /* RFC 9114 4.2. HTTP Fields
759 *
760 * The only exception to this is the TE header field, which MAY
761 * be present in an HTTP/3 request header; when it is, it MUST
762 * NOT contain any value other than "trailers".
763 */
764 TRACE_ERROR("invalid te header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
765 h3s->err = H3_MESSAGE_ERROR;
766 len = -1;
767 goto out;
768 }
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200769
Amaury Denoyellec4913f62022-12-15 10:58:05 +0100770 if (!htx_add_header(htx, list[hdr_idx].n, list[hdr_idx].v)) {
771 h3c->err = H3_INTERNAL_ERROR;
772 len = -1;
773 goto out;
774 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100775 ++hdr_idx;
776 }
777
Amaury Denoyellea514a112023-10-09 16:14:44 +0200778 /* RFC 9114 4.3.1. Request Pseudo-Header Fields
779 *
780 * If the :scheme pseudo-header field identifies a scheme that has a
781 * mandatory authority component (including "http" and "https"), the
782 * request MUST contain either an :authority pseudo-header field or a
783 * Host header field.
784 */
785 if (!isttest(authority)) {
786 TRACE_ERROR("missing mandatory pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
787 h3s->err = H3_MESSAGE_ERROR;
788 len = -1;
789 goto out;
790 }
791
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200792 if (cookie >= 0) {
793 if (http_cookie_merge(htx, list, cookie)) {
794 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100795 len = -1;
796 goto out;
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200797 }
798 }
799
Amaury Denoyellec4913f62022-12-15 10:58:05 +0100800 if (!htx_add_endof(htx, HTX_BLK_EOH)) {
801 h3c->err = H3_INTERNAL_ERROR;
802 len = -1;
803 goto out;
804 }
805
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100806 if (fin)
807 htx->flags |= HTX_FL_EOM;
808
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100809 htx_to_buf(htx, &htx_buf);
810 htx = NULL;
811
Amaury Denoyelled68f8b52023-05-30 15:04:46 +0200812 if (!qcs_attach_sc(qcs, &htx_buf, fin)) {
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200813 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100814 len = -1;
815 goto out;
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200816 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100817
Amaury Denoyelle114c9c82022-03-28 14:53:45 +0200818 /* RFC 9114 5.2. Connection Shutdown
819 *
820 * The GOAWAY frame contains an identifier that
821 * indicates to the receiver the range of requests or pushes that were
822 * or might be processed in this connection. The server sends a client-
823 * initiated bidirectional stream ID; the client sends a push ID.
824 * Requests or pushes with the indicated identifier or greater are
825 * rejected (Section 4.1.1) by the sender of the GOAWAY. This
826 * identifier MAY be zero if no requests or pushes were processed.
827 */
828 if (qcs->id >= h3c->id_goaway)
829 h3c->id_goaway = qcs->id + 4;
830
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100831 out:
832 /* HTX may be non NULL if error before previous htx_to_buf(). */
833 if (htx)
834 htx_to_buf(htx, &htx_buf);
835
Willy Tarreau4596fe22022-05-17 19:07:51 +0200836 /* buffer is transferred to the stream connector and set to NULL
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100837 * except on stream creation error.
838 */
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100839 if (b_size(&htx_buf)) {
840 b_free(&htx_buf);
841 offer_buffers(NULL, 1);
842 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100843
Amaury Denoyelle494512d2022-05-30 15:50:34 +0200844 TRACE_LEAVE(H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle314578a2022-04-27 14:52:52 +0200845 return len;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100846}
847
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100848/* Parse from buffer <buf> a H3 HEADERS frame of length <len> used as trailers.
849 * Data are copied in a local HTX buffer and transfer to the stream connector
850 * layer. <fin> must be set if this is the last data to transfer from this
851 * stream.
852 *
853 * Returns the number of consumed bytes or a negative error code. On error
854 * either the connection should be closed or the stream reset using codes
855 * provided in h3c.err / h3s.err.
856 */
857static ssize_t h3_trailers_to_htx(struct qcs *qcs, const struct buffer *buf,
858 uint64_t len, char fin)
859{
860 struct h3s *h3s = qcs->ctx;
861 struct h3c *h3c = h3s->h3c;
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100862 struct buffer *tmp = get_trash_chunk();
Amaury Denoyelle29058f72023-11-28 15:59:38 +0100863 struct buffer *appbuf = NULL;
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100864 struct htx *htx = NULL;
865 struct htx_sl *sl;
866 struct http_hdr list[global.tune.max_http_hdr];
867 int hdr_idx, ret;
Willy Tarreau0404bf12023-08-08 17:18:27 +0200868 const char *ctl;
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100869 int i;
870
871 TRACE_ENTER(H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
872
873 /* TODO support buffer wrapping */
874 BUG_ON(b_head(buf) + len >= b_wrap(buf));
875 ret = qpack_decode_fs((const unsigned char *)b_head(buf), len, tmp,
876 list, sizeof(list) / sizeof(list[0]));
877 if (ret < 0) {
878 TRACE_ERROR("QPACK decoding error", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyellec3c4d1b2024-05-13 16:01:08 +0200879 h3c->err = h3_err(qpack_err_decode(ret));
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100880 len = -1;
881 goto out;
882 }
883
Amaury Denoyelle29058f72023-11-28 15:59:38 +0100884 if (!(appbuf = qcs_get_buf(qcs, &qcs->rx.app_buf))) {
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +0200885 TRACE_ERROR("HTX buffer alloc failure", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
886 h3c->err = H3_INTERNAL_ERROR;
887 len = -1;
888 goto out;
889 }
Amaury Denoyelle29058f72023-11-28 15:59:38 +0100890 BUG_ON(!b_size(appbuf)); /* TODO */
891 htx = htx_from_buf(appbuf);
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100892
893 if (!h3s->data_len) {
894 /* Notify that no body is present. This can only happens if
895 * there is H3 HEADERS as trailers without or empty H3 DATA
896 * frame. So this is probably not realistice ?
897 *
898 * TODO if sl is NULL because already consumed there is no way
899 * to notify about missing body.
900 */
901 sl = http_get_stline(htx);
902 if (sl)
903 sl->flags |= HTX_SL_F_BODYLESS;
904 else
905 TRACE_ERROR("cannot notify missing body after trailers", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
906 }
907
908 hdr_idx = 0;
909 while (1) {
910 if (isteq(list[hdr_idx].n, ist("")))
911 break;
912
913 /* RFC 9114 4.3. HTTP Control Data
914 *
915 * Pseudo-header
916 * fields MUST NOT appear in trailer sections.
917 */
918 if (istmatch(list[hdr_idx].n, ist(":"))) {
919 TRACE_ERROR("pseudo-header field in trailers", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
920 h3s->err = H3_MESSAGE_ERROR;
921 len = -1;
922 goto out;
923 }
924
925 for (i = 0; i < list[hdr_idx].n.len; ++i) {
926 const char c = list[hdr_idx].n.ptr[i];
927 if ((uint8_t)(c - 'A') < 'Z' - 'A' || !HTTP_IS_TOKEN(c)) {
928 TRACE_ERROR("invalid characters in field name", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
929 h3s->err = H3_MESSAGE_ERROR;
930 len = -1;
931 goto out;
932 }
933 }
934
935 /* forbidden HTTP/3 headers, cf h3_headers_to_htx() */
936 if (isteq(list[hdr_idx].n, ist("host")) ||
937 isteq(list[hdr_idx].n, ist("content-length")) ||
938 isteq(list[hdr_idx].n, ist("connection")) ||
939 isteq(list[hdr_idx].n, ist("proxy-connection")) ||
940 isteq(list[hdr_idx].n, ist("keep-alive")) ||
941 isteq(list[hdr_idx].n, ist("te")) ||
942 isteq(list[hdr_idx].n, ist("transfer-encoding"))) {
943 TRACE_ERROR("forbidden HTTP/3 headers", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
944 h3s->err = H3_MESSAGE_ERROR;
945 len = -1;
946 goto out;
947 }
948
Willy Tarreau0404bf12023-08-08 17:18:27 +0200949 /* RFC 9114 10.3 Intermediary-Encapsulation Attacks
950 *
951 * While most values that can be encoded will not alter field
952 * parsing, carriage return (ASCII 0x0d), line feed (ASCII 0x0a),
953 * and the null character (ASCII 0x00) might be exploited by an
954 * attacker if they are translated verbatim. Any request or
955 * response that contains a character not permitted in a field
956 * value MUST be treated as malformed
957 */
958
959 /* look for forbidden control characters in the trailer value */
960 ctl = ist_find_ctl(list[hdr_idx].v);
961 if (unlikely(ctl) && http_header_has_forbidden_char(list[hdr_idx].v, ctl)) {
962 TRACE_ERROR("control character present in trailer value", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
963 h3s->err = H3_MESSAGE_ERROR;
964 len = -1;
965 goto out;
966 }
967
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100968 if (!htx_add_trailer(htx, list[hdr_idx].n, list[hdr_idx].v)) {
969 TRACE_ERROR("cannot add trailer", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
970 h3c->err = H3_INTERNAL_ERROR;
971 len = -1;
972 goto out;
973 }
974
975 ++hdr_idx;
976 }
977
978 if (!htx_add_endof(htx, HTX_BLK_EOT)) {
979 TRACE_ERROR("cannot add trailer", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
980 h3c->err = H3_INTERNAL_ERROR;
981 len = -1;
982 goto out;
983 }
984
985 if (fin)
986 htx->flags |= HTX_FL_EOM;
987
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100988 out:
989 /* HTX may be non NULL if error before previous htx_to_buf(). */
Amaury Denoyelle29058f72023-11-28 15:59:38 +0100990 if (appbuf)
991 htx_to_buf(htx, appbuf);
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100992
993 TRACE_LEAVE(H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
994 return len;
995}
996
Amaury Denoyelle91379f72022-02-14 17:14:59 +0100997/* Copy from buffer <buf> a H3 DATA frame of length <len> in QUIC stream <qcs>
998 * HTX buffer. <fin> must be set if this is the last data to transfer from this
999 * stream.
1000 *
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001001 * Returns the number of consumed bytes or a negative error code.
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001002 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001003static ssize_t h3_data_to_htx(struct qcs *qcs, const struct buffer *buf,
1004 uint64_t len, char fin)
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001005{
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +02001006 struct h3s *h3s = qcs->ctx;
1007 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001008 struct buffer *appbuf;
1009 struct htx *htx = NULL;
Amaury Denoyelle1290f1e2022-05-13 14:49:05 +02001010 size_t htx_sent = 0;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001011 int htx_space;
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001012 char *head;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001013
Amaury Denoyelle494512d2022-05-30 15:50:34 +02001014 TRACE_ENTER(H3_EV_RX_FRAME|H3_EV_RX_DATA, qcs->qcc->conn, qcs);
1015
Amaury Denoyelled68f8b52023-05-30 15:04:46 +02001016 if (!(appbuf = qcs_get_buf(qcs, &qcs->rx.app_buf))) {
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +02001017 TRACE_ERROR("data buffer alloc failure", H3_EV_RX_FRAME|H3_EV_RX_DATA, qcs->qcc->conn, qcs);
1018 h3c->err = H3_INTERNAL_ERROR;
1019 len = -1;
1020 goto out;
1021 }
1022
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001023 htx = htx_from_buf(appbuf);
1024
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001025 if (len > b_data(buf)) {
1026 len = b_data(buf);
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001027 fin = 0;
1028 }
1029
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001030 head = b_head(buf);
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001031 retry:
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001032 htx_space = htx_free_data_space(htx);
Amaury Denoyellef1fc0b32022-05-02 11:07:06 +02001033 if (!htx_space) {
1034 qcs->flags |= QC_SF_DEM_FULL;
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001035 goto out;
Amaury Denoyellef1fc0b32022-05-02 11:07:06 +02001036 }
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001037
1038 if (len > htx_space) {
1039 len = htx_space;
1040 fin = 0;
Amaury Denoyelleff191de2022-02-21 18:38:29 +01001041 }
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001042
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001043 if (head + len > b_wrap(buf)) {
1044 size_t contig = b_wrap(buf) - head;
1045 htx_sent = htx_add_data(htx, ist2(b_head(buf), contig));
Amaury Denoyelle73d6ffe2022-05-16 13:54:31 +02001046 if (htx_sent < contig) {
1047 qcs->flags |= QC_SF_DEM_FULL;
1048 goto out;
1049 }
1050
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001051 len -= contig;
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001052 head = b_orig(buf);
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001053 goto retry;
Amaury Denoyelleff191de2022-02-21 18:38:29 +01001054 }
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001055
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001056 htx_sent += htx_add_data(htx, ist2(head, len));
Amaury Denoyelle73d6ffe2022-05-16 13:54:31 +02001057 if (htx_sent < len) {
1058 qcs->flags |= QC_SF_DEM_FULL;
1059 goto out;
1060 }
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001061
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001062 if (fin && len == htx_sent)
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001063 htx->flags |= HTX_FL_EOM;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001064
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001065 out:
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +02001066 if (appbuf)
1067 htx_to_buf(htx, appbuf);
Amaury Denoyelle494512d2022-05-30 15:50:34 +02001068
1069 TRACE_LEAVE(H3_EV_RX_FRAME|H3_EV_RX_DATA, qcs->qcc->conn, qcs);
Amaury Denoyelle314578a2022-04-27 14:52:52 +02001070 return htx_sent;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001071}
1072
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001073/* Parse a SETTINGS frame of length <len> of payload <buf>.
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001074 *
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001075 * Returns the number of consumed bytes or a negative error code.
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001076 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001077static ssize_t h3_parse_settings_frm(struct h3c *h3c, const struct buffer *buf,
1078 size_t len)
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001079{
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001080 struct buffer b;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001081 uint64_t id, value;
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001082 size_t ret = 0;
1083 long mask = 0; /* used to detect duplicated settings identifier */
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001084
Amaury Denoyelle494512d2022-05-30 15:50:34 +02001085 TRACE_ENTER(H3_EV_RX_FRAME|H3_EV_RX_SETTINGS, h3c->qcc->conn);
1086
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001087 /* Work on a copy of <buf>. */
Amaury Denoyelle3a2fcfd2022-06-09 11:54:38 +02001088 b = b_make(b_orig(buf), b_size(buf), b_head_ofs(buf), len);
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001089
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001090 while (b_data(&b)) {
1091 if (!b_quic_dec_int(&id, &b, &ret) || !b_quic_dec_int(&value, &b, &ret)) {
1092 h3c->err = H3_FRAME_ERROR;
1093 return -1;
1094 }
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001095
1096 h3_debug_printf(stderr, "%s id: %llu value: %llu\n",
1097 __func__, (unsigned long long)id, (unsigned long long)value);
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001098
1099 /* draft-ietf-quic-http34 7.2.4. SETTINGS
1100 *
1101 * The same setting identifier MUST NOT occur more than once in the
1102 * SETTINGS frame. A receiver MAY treat the presence of duplicate
1103 * setting identifiers as a connection error of type H3_SETTINGS_ERROR.
1104 */
1105
1106 /* Ignore duplicate check for ID too big used for GREASE. */
1107 if (id < sizeof(mask)) {
1108 if (ha_bit_test(id, &mask)) {
1109 h3c->err = H3_SETTINGS_ERROR;
1110 return -1;
1111 }
1112 ha_bit_set(id, &mask);
1113 }
1114
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001115 switch (id) {
1116 case H3_SETTINGS_QPACK_MAX_TABLE_CAPACITY:
1117 h3c->qpack_max_table_capacity = value;
1118 break;
1119 case H3_SETTINGS_MAX_FIELD_SECTION_SIZE:
1120 h3c->max_field_section_size = value;
1121 break;
1122 case H3_SETTINGS_QPACK_BLOCKED_STREAMS:
1123 h3c->qpack_blocked_streams = value;
1124 break;
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001125
1126 case H3_SETTINGS_RESERVED_0:
1127 case H3_SETTINGS_RESERVED_2:
1128 case H3_SETTINGS_RESERVED_3:
1129 case H3_SETTINGS_RESERVED_4:
1130 case H3_SETTINGS_RESERVED_5:
1131 /* draft-ietf-quic-http34 7.2.4.1. Defined SETTINGS Parameters
1132 *
1133 * Setting identifiers which were defined in [HTTP2] where there is no
1134 * corresponding HTTP/3 setting have also been reserved
1135 * (Section 11.2.2). These reserved settings MUST NOT be sent, and
1136 * their receipt MUST be treated as a connection error of type
1137 * H3_SETTINGS_ERROR.
1138 */
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001139 h3c->err = H3_SETTINGS_ERROR;
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001140 return -1;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001141 default:
1142 /* MUST be ignored */
1143 break;
1144 }
1145 }
1146
Frédéric Lécaillebefcf702022-09-08 16:04:55 +02001147 TRACE_LEAVE(H3_EV_RX_FRAME|H3_EV_RX_SETTINGS, h3c->qcc->conn);
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001148 return ret;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001149}
1150
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +01001151/* Decode <qcs> remotely initiated bidi-stream. <fin> must be set to indicate
1152 * that we received the last data of the stream.
Amaury Denoyelle0ffd6e72022-05-24 11:07:28 +02001153 *
1154 * Returns 0 on success else non-zero.
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +01001155 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001156static ssize_t h3_decode_qcs(struct qcs *qcs, struct buffer *b, int fin)
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +01001157{
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001158 struct h3s *h3s = qcs->ctx;
Amaury Denoyellec0156792022-06-03 15:29:07 +02001159 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001160 ssize_t total = 0, ret;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +01001161
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001162 TRACE_ENTER(H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001163
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001164 if (quic_stream_is_uni(qcs->id) && !(h3s->flags & H3_SF_UNI_INIT)) {
Amaury Denoyelle5aa21c12023-03-09 11:12:32 +01001165 ret = h3_init_uni_stream(h3c, qcs, b);
1166 if (ret < 0) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001167 TRACE_ERROR("cannot initialize uni stream", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1168 goto err;
1169 }
Amaury Denoyelle5aa21c12023-03-09 11:12:32 +01001170 else if (!ret) {
1171 /* not enough data to initialize uni stream, retry later */
1172 goto done;
1173 }
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001174
1175 total += ret;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001176 }
1177
1178 if (quic_stream_is_uni(qcs->id) && (h3s->flags & H3_SF_UNI_NO_H3)) {
1179 /* For non-h3 STREAM, parse it and return immediately. */
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001180 if ((ret = h3_parse_uni_stream_no_h3(qcs, b, fin)) < 0) {
1181 TRACE_ERROR("error when parsing non-HTTP3 uni stream", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1182 goto err;
1183 }
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001184
1185 total += ret;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001186 goto done;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001187 }
1188
Amaury Denoyelle6b02c6b2022-08-16 17:16:47 +02001189 /* RFC 9114 6.2.1. Control Streams
1190 *
1191 * The sender MUST NOT close the control stream, and the receiver MUST NOT
1192 * request that the sender close the control stream. If either control
1193 * stream is closed at any point, this MUST be treated as a connection
1194 * error of type H3_CLOSED_CRITICAL_STREAM.
1195 */
1196 if (h3s->type == H3S_T_CTRL && fin) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001197 TRACE_ERROR("control stream closed by remote peer", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001198 qcc_set_error(qcs->qcc, H3_CLOSED_CRITICAL_STREAM, 1);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001199 goto err;
Amaury Denoyelle6b02c6b2022-08-16 17:16:47 +02001200 }
1201
Amaury Denoyelle381d8132023-02-17 09:51:20 +01001202 if (!b_data(b) && fin && quic_stream_is_bidi(qcs->id)) {
Amaury Denoyelle93dd23c2023-05-11 16:49:28 +02001203 struct buffer *appbuf;
1204 struct htx *htx;
1205
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001206 TRACE_PROTO("received FIN without data", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelled68f8b52023-05-30 15:04:46 +02001207 if (!(appbuf = qcs_get_buf(qcs, &qcs->rx.app_buf))) {
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +02001208 TRACE_ERROR("data buffer alloc failure", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1209 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle6133aba2023-05-15 09:35:59 +02001210 goto err;
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +02001211 }
Amaury Denoyelle93dd23c2023-05-11 16:49:28 +02001212
1213 htx = htx_from_buf(appbuf);
1214 if (!htx_set_eom(htx)) {
1215 TRACE_ERROR("cannot set EOM", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1216 h3c->err = H3_INTERNAL_ERROR;
1217 }
1218 htx_to_buf(htx, appbuf);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001219 goto done;
Amaury Denoyelle381d8132023-02-17 09:51:20 +01001220 }
1221
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001222 while (b_data(b) && !(qcs->flags & QC_SF_DEM_FULL) && !h3c->err && !h3s->err) {
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001223 uint64_t ftype, flen;
Amaury Denoyelle95b93a32022-02-14 15:49:53 +01001224 char last_stream_frame = 0;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001225
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001226 if (!h3s->demux_frame_len) {
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001227 /* Switch to a new frame. */
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001228 size_t hlen = h3_decode_frm_header(&ftype, &flen, b);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001229 if (!hlen) {
1230 TRACE_PROTO("pause parsing on incomplete frame header", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001231 break;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001232 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001233
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001234 h3s->demux_frame_type = ftype;
1235 h3s->demux_frame_len = flen;
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001236 total += hlen;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001237 TRACE_PROTO("parsing a new frame", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle417c7c02022-05-31 14:18:33 +02001238
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001239 /* Check that content-length is not exceeded on a new DATA frame. */
1240 if (ftype == H3_FT_DATA) {
1241 h3s->data_len += flen;
Christopher Faulet3809fe92023-07-28 09:33:29 +02001242 if (h3s->flags & H3_SF_HAVE_CLEN && h3_check_body_size(qcs, (fin && flen == b_data(b))))
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001243 break;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001244 }
1245
Amaury Denoyelle417c7c02022-05-31 14:18:33 +02001246 if (!h3_is_frame_valid(h3c, qcs, ftype)) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001247 TRACE_ERROR("received an invalid frame", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001248 qcc_set_error(qcs->qcc, H3_FRAME_UNEXPECTED, 1);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001249 goto err;
Amaury Denoyelle417c7c02022-05-31 14:18:33 +02001250 }
1251
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001252 if (!b_data(b))
Amaury Denoyelle417c7c02022-05-31 14:18:33 +02001253 break;
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001254 }
Amaury Denoyelle0484f922022-02-15 16:59:39 +01001255
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001256 flen = h3s->demux_frame_len;
1257 ftype = h3s->demux_frame_type;
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001258
1259 /* Do not demux incomplete frames except H3 DATA which can be
1260 * fragmented in multiple HTX blocks.
1261 */
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001262 if (flen > b_data(b) && ftype != H3_FT_DATA) {
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001263 /* Reject frames bigger than bufsize.
1264 *
1265 * TODO HEADERS should in complement be limited with H3
1266 * SETTINGS_MAX_FIELD_SECTION_SIZE parameter to prevent
1267 * excessive decompressed size.
1268 */
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001269 if (flen > QC_S_RX_BUF_SZ) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001270 TRACE_ERROR("received a too big frame", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001271 qcc_set_error(qcs->qcc, H3_EXCESSIVE_LOAD, 1);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001272 goto err;
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001273 }
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001274 break;
Amaury Denoyelleb5454d42022-05-12 16:56:16 +02001275 }
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001276
Christopher Faulet3809fe92023-07-28 09:33:29 +02001277 last_stream_frame = (fin && flen == b_data(b));
1278
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001279 /* Check content-length equality with DATA frames length on the last frame. */
Christopher Faulet3809fe92023-07-28 09:33:29 +02001280 if (last_stream_frame && h3s->flags & H3_SF_HAVE_CLEN && h3_check_body_size(qcs, last_stream_frame))
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001281 break;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001282
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02001283 h3_inc_frame_type_cnt(h3c->prx_counters, ftype);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001284 switch (ftype) {
1285 case H3_FT_DATA:
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001286 ret = h3_data_to_htx(qcs, b, flen, last_stream_frame);
Amaury Denoyelle8d818c62022-08-02 11:32:45 +02001287 h3s->st_req = H3S_ST_REQ_DATA;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001288 break;
1289 case H3_FT_HEADERS:
Amaury Denoyelleedfcb552023-01-13 16:40:31 +01001290 if (h3s->st_req == H3S_ST_REQ_BEFORE) {
1291 ret = h3_headers_to_htx(qcs, b, flen, last_stream_frame);
1292 h3s->st_req = H3S_ST_REQ_HEADERS;
1293 }
1294 else {
1295 ret = h3_trailers_to_htx(qcs, b, flen, last_stream_frame);
1296 h3s->st_req = H3S_ST_REQ_TRAILERS;
1297 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001298 break;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001299 case H3_FT_CANCEL_PUSH:
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001300 case H3_FT_PUSH_PROMISE:
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001301 case H3_FT_MAX_PUSH_ID:
1302 case H3_FT_GOAWAY:
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001303 /* Not supported */
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001304 ret = flen;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001305 break;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001306 case H3_FT_SETTINGS:
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001307 ret = h3_parse_settings_frm(qcs->qcc->ctx, b, flen);
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001308 if (ret < 0) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001309 TRACE_ERROR("error on SETTINGS parsing", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001310 qcc_set_error(qcs->qcc, h3c->err, 1);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001311 goto err;
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001312 }
1313 h3c->flags |= H3_CF_SETTINGS_RECV;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001314 break;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001315 default:
Amaury Denoyelled1acaf92021-11-15 15:52:55 +01001316 /* draft-ietf-quic-http34 9. Extensions to HTTP/3
Amaury Denoyelle302ecd42022-05-24 15:24:32 +02001317 *
1318 * Implementations MUST discard frames [...] that have unknown
1319 * or unsupported types.
Amaury Denoyelled1acaf92021-11-15 15:52:55 +01001320 */
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001321 ret = flen;
1322 break;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001323 }
Amaury Denoyelle314578a2022-04-27 14:52:52 +02001324
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001325 if (ret > 0) {
Amaury Denoyelle291ee252022-05-02 10:35:39 +02001326 BUG_ON(h3s->demux_frame_len < ret);
1327 h3s->demux_frame_len -= ret;
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001328 b_del(b, ret);
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001329 total += ret;
Amaury Denoyelle291ee252022-05-02 10:35:39 +02001330 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001331 }
1332
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001333 /* Reset demux frame type for traces. */
1334 if (!h3s->demux_frame_len)
1335 h3s->demux_frame_type = H3_FT_UNINIT;
1336
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001337 /* Interrupt decoding on stream/connection error detected. */
1338 if (h3s->err) {
1339 qcc_abort_stream_read(qcs);
1340 qcc_reset_stream(qcs, h3s->err);
1341 return b_data(b);
1342 }
1343 else if (h3c->err) {
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001344 qcc_set_error(qcs->qcc, h3c->err, 1);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001345 return b_data(b);
1346 }
1347
Amaury Denoyelle03cc62c2022-04-27 16:53:16 +02001348 /* TODO may be useful to wakeup the MUX if blocked due to full buffer.
1349 * However, currently, io-cb of MUX does not handle Rx.
1350 */
1351
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001352 done:
1353 TRACE_LEAVE(H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001354 return total;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001355
1356 err:
1357 TRACE_DEVEL("leaving on error", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1358 return -1;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001359}
1360
Amaury Denoyellea5871362021-10-07 16:26:12 +02001361/* Returns buffer for data sending.
1362 * May be NULL if the allocation failed.
1363 */
1364static struct buffer *mux_get_buf(struct qcs *qcs)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001365{
Amaury Denoyellea5871362021-10-07 16:26:12 +02001366 if (!b_size(&qcs->tx.buf))
1367 b_alloc(&qcs->tx.buf);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001368
Amaury Denoyellea5871362021-10-07 16:26:12 +02001369 return &qcs->tx.buf;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001370}
1371
Amaury Denoyelleddc1ef12023-12-15 17:32:06 +01001372/* Function used to emit stream data from <qcs> control uni-stream.
1373 *
1374 * On success return the number of sent bytes. A negative code is used on
1375 * error.
1376 */
Amaury Denoyelle6b923942022-05-23 14:25:53 +02001377static int h3_control_send(struct qcs *qcs, void *ctx)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001378{
1379 int ret;
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02001380 struct h3c *h3c = ctx;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001381 unsigned char data[(2 + 3) * 2 * QUIC_VARINT_MAX_SIZE]; /* enough for 3 settings */
Amaury Denoyellea5871362021-10-07 16:26:12 +02001382 struct buffer pos, *res;
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001383 size_t frm_len;
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001384
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001385 TRACE_ENTER(H3_EV_TX_SETTINGS, qcs->qcc->conn, qcs);
1386
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001387 BUG_ON_HOT(h3c->flags & H3_CF_SETTINGS_SENT);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001388
1389 ret = 0;
Amaury Denoyellea5871362021-10-07 16:26:12 +02001390 pos = b_make((char *)data, sizeof(data), 0, 0);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001391
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001392 frm_len = quic_int_getsize(H3_SETTINGS_QPACK_MAX_TABLE_CAPACITY) +
1393 quic_int_getsize(h3_settings_qpack_max_table_capacity) +
1394 quic_int_getsize(H3_SETTINGS_QPACK_BLOCKED_STREAMS) +
1395 quic_int_getsize(h3_settings_qpack_blocked_streams);
1396 if (h3_settings_max_field_section_size) {
1397 frm_len += quic_int_getsize(H3_SETTINGS_MAX_FIELD_SECTION_SIZE) +
1398 quic_int_getsize(h3_settings_max_field_section_size);
1399 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001400
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001401 b_quic_enc_int(&pos, H3_UNI_S_T_CTRL, 0);
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001402 /* Build a SETTINGS frame */
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001403 b_quic_enc_int(&pos, H3_FT_SETTINGS, 0);
1404 b_quic_enc_int(&pos, frm_len, 0);
1405 b_quic_enc_int(&pos, H3_SETTINGS_QPACK_MAX_TABLE_CAPACITY, 0);
1406 b_quic_enc_int(&pos, h3_settings_qpack_max_table_capacity, 0);
1407 b_quic_enc_int(&pos, H3_SETTINGS_QPACK_BLOCKED_STREAMS, 0);
1408 b_quic_enc_int(&pos, h3_settings_qpack_blocked_streams, 0);
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001409 if (h3_settings_max_field_section_size) {
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001410 b_quic_enc_int(&pos, H3_SETTINGS_MAX_FIELD_SECTION_SIZE, 0);
1411 b_quic_enc_int(&pos, h3_settings_max_field_section_size, 0);
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001412 }
Amaury Denoyellea5871362021-10-07 16:26:12 +02001413
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001414 res = mux_get_buf(qcs);
Amaury Denoyelled70f1332024-01-29 14:39:19 +01001415 if (b_is_null(res)) {
Amaury Denoyelleddc1ef12023-12-15 17:32:06 +01001416 TRACE_ERROR("cannot allocate Tx buffer", H3_EV_TX_SETTINGS, qcs->qcc->conn, qcs);
1417 goto err;
1418 }
1419
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001420 if (b_room(res) < b_data(&pos)) {
1421 // TODO the mux should be put in blocked state, with
1422 // the stream in state waiting for settings to be sent
1423 ABORT_NOW();
1424 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001425
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001426 ret = b_force_xfer(res, &pos, b_data(&pos));
Amaury Denoyelle20f2a422023-01-03 14:39:24 +01001427 if (ret > 0) {
1428 /* Register qcs for sending before other streams. */
Amaury Denoyellef9b03262023-01-09 10:34:25 +01001429 qcc_send_stream(qcs, 1);
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001430 h3c->flags |= H3_CF_SETTINGS_SENT;
Amaury Denoyelle20f2a422023-01-03 14:39:24 +01001431 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001432
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001433 TRACE_LEAVE(H3_EV_TX_SETTINGS, qcs->qcc->conn, qcs);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001434 return ret;
Amaury Denoyelleddc1ef12023-12-15 17:32:06 +01001435
1436 err:
1437 TRACE_DEVEL("leaving on error", H3_EV_TX_SETTINGS, qcs->qcc->conn, qcs);
1438 return -1;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001439}
1440
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001441static int h3_resp_headers_send(struct qcs *qcs, struct htx *htx)
1442{
Amaury Denoyellea7554392023-12-21 17:42:43 +01001443 struct h3s *h3s = qcs->ctx;
1444 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001445 struct buffer outbuf;
1446 struct buffer headers_buf = BUF_NULL;
1447 struct buffer *res;
1448 struct http_hdr list[global.tune.max_http_hdr];
1449 struct htx_sl *sl;
1450 struct htx_blk *blk;
1451 enum htx_blk_type type;
1452 int frame_length_size; /* size in bytes of frame length varint field */
1453 int ret = 0;
1454 int hdr;
1455 int status = 0;
1456
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001457 TRACE_ENTER(H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1458
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001459 sl = NULL;
1460 hdr = 0;
1461 for (blk = htx_get_head_blk(htx); blk; blk = htx_get_next_blk(htx, blk)) {
1462 type = htx_get_blk_type(blk);
1463
1464 if (type == HTX_BLK_UNUSED)
1465 continue;
1466
1467 if (type == HTX_BLK_EOH)
1468 break;
1469
1470 if (type == HTX_BLK_RES_SL) {
1471 /* start-line -> HEADERS h3 frame */
1472 BUG_ON(sl);
1473 sl = htx_get_blk_ptr(htx, blk);
1474 /* TODO should be on h3 layer */
1475 status = sl->info.res.status;
1476 }
1477 else if (type == HTX_BLK_HDR) {
Amaury Denoyellea7554392023-12-21 17:42:43 +01001478 if (unlikely(hdr >= sizeof(list) / sizeof(list[0]) - 1)) {
Amaury Denoyelleddc1ef12023-12-15 17:32:06 +01001479 TRACE_ERROR("too many headers", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyellea7554392023-12-21 17:42:43 +01001480 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyellefa7fadc2022-06-15 15:52:27 +02001481 goto err;
Amaury Denoyellea7554392023-12-21 17:42:43 +01001482 }
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001483 list[hdr].n = htx_get_blk_name(htx, blk);
1484 list[hdr].v = htx_get_blk_value(htx, blk);
1485 hdr++;
1486 }
1487 else {
1488 ABORT_NOW();
1489 goto err;
1490 }
1491 }
1492
1493 BUG_ON(!sl);
1494
1495 list[hdr].n = ist("");
1496
Amaury Denoyelled3d97c62021-10-05 11:45:58 +02001497 res = mux_get_buf(qcs);
Amaury Denoyelled70f1332024-01-29 14:39:19 +01001498 if (b_is_null(res)) {
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001499 TRACE_ERROR("cannot allocate Tx buffer", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1500 h3c->err = H3_INTERNAL_ERROR;
1501 goto err;
1502 }
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001503
1504 /* At least 5 bytes to store frame type + length as a varint max size */
1505 if (b_room(res) < 5)
1506 ABORT_NOW();
1507
1508 b_reset(&outbuf);
1509 outbuf = b_make(b_tail(res), b_contig_space(res), 0, 0);
1510 /* Start the headers after frame type + length */
1511 headers_buf = b_make(b_head(res) + 5, b_size(res) - 5, 0, 0);
1512
1513 if (qpack_encode_field_section_line(&headers_buf))
1514 ABORT_NOW();
Amaury Denoyelleed968652024-01-29 13:47:44 +01001515 if (qpack_encode_int_status(&headers_buf, status)) {
1516 TRACE_ERROR("invalid status code", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1517 h3c->err = H3_INTERNAL_ERROR;
1518 goto err;
1519 }
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001520
1521 for (hdr = 0; hdr < sizeof(list) / sizeof(list[0]); ++hdr) {
1522 if (isteq(list[hdr].n, ist("")))
1523 break;
1524
Amaury Denoyelle8ad26692023-01-17 17:47:06 +01001525 /* RFC 9114 4.2. HTTP Fields
1526 *
1527 * An intermediary transforming an HTTP/1.x message to HTTP/3
1528 * MUST remove connection-specific header fields as discussed in
1529 * Section 7.6.1 of [HTTP], or their messages will be treated by
1530 * other HTTP/3 endpoints as malformed.
Amaury Denoyelleffafb3d2022-02-15 16:10:42 +01001531 */
Amaury Denoyelle8ad26692023-01-17 17:47:06 +01001532 if (isteq(list[hdr].n, ist("connection")) ||
1533 isteq(list[hdr].n, ist("proxy-connection")) ||
1534 isteq(list[hdr].n, ist("keep-alive")) ||
1535 isteq(list[hdr].n, ist("transfer-encoding"))) {
Amaury Denoyelleffafb3d2022-02-15 16:10:42 +01001536 continue;
Amaury Denoyelle8ad26692023-01-17 17:47:06 +01001537 }
1538 else if (isteq(list[hdr].n, ist("te"))) {
1539 /* "te" may only be sent with "trailers" if this value
1540 * is present, otherwise it must be deleted.
1541 */
1542 const struct ist v = istist(list[hdr].v, ist("trailers"));
1543 if (!isttest(v) || (v.len > 8 && v.ptr[8] != ','))
1544 continue;
1545 list[hdr].v = ist("trailers");
1546 }
Amaury Denoyelleffafb3d2022-02-15 16:10:42 +01001547
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001548 if (qpack_encode_header(&headers_buf, list[hdr].n, list[hdr].v))
1549 ABORT_NOW();
1550 }
1551
1552 /* Now that all headers are encoded, we are certain that res buffer is
1553 * big enough
1554 */
1555 frame_length_size = quic_int_getsize(b_data(&headers_buf));
1556 res->head += 4 - frame_length_size;
1557 b_putchr(res, 0x01); /* h3 HEADERS frame type */
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001558 if (!b_quic_enc_int(res, b_data(&headers_buf), 0))
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001559 ABORT_NOW();
1560 b_add(res, b_data(&headers_buf));
1561
1562 ret = 0;
1563 blk = htx_get_head_blk(htx);
1564 while (blk) {
1565 type = htx_get_blk_type(blk);
1566 ret += htx_get_blksz(blk);
1567 blk = htx_remove_blk(htx, blk);
1568 if (type == HTX_BLK_EOH)
1569 break;
1570 }
1571
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001572 TRACE_LEAVE(H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001573 return ret;
1574
1575 err:
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001576 TRACE_DEVEL("leaving on error", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001577 return -1;
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001578}
1579
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001580/* Convert a series of HTX trailer blocks from <htx> buffer into <qcs> buffer
1581 * as a H3 HEADERS frame. H3 forbidden trailers are skipped. HTX trailer blocks
1582 * are removed from <htx> until EOT is found and itself removed.
1583 *
1584 * If only a EOT HTX block is present without trailer, no H3 frame is produced.
1585 * Caller is responsible to emit an empty QUIC STREAM frame to signal the end
1586 * of the stream.
1587 *
1588 * Returns the size of HTX blocks removed.
1589 */
1590static int h3_resp_trailers_send(struct qcs *qcs, struct htx *htx)
1591{
Amaury Denoyellea7554392023-12-21 17:42:43 +01001592 struct h3s *h3s = qcs->ctx;
1593 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001594 struct buffer headers_buf = BUF_NULL;
1595 struct buffer *res;
1596 struct http_hdr list[global.tune.max_http_hdr];
1597 struct htx_blk *blk;
1598 enum htx_blk_type type;
1599 char *tail;
1600 int ret = 0;
1601 int hdr;
1602
1603 TRACE_ENTER(H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1604
1605 hdr = 0;
1606 for (blk = htx_get_head_blk(htx); blk; blk = htx_get_next_blk(htx, blk)) {
1607 type = htx_get_blk_type(blk);
1608
1609 if (type == HTX_BLK_UNUSED)
1610 continue;
1611
1612 if (type == HTX_BLK_EOT)
1613 break;
1614
1615 if (type == HTX_BLK_TLR) {
Amaury Denoyellea7554392023-12-21 17:42:43 +01001616 if (unlikely(hdr >= sizeof(list) / sizeof(list[0]) - 1)) {
Amaury Denoyelleddc1ef12023-12-15 17:32:06 +01001617 TRACE_ERROR("too many headers", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyellea7554392023-12-21 17:42:43 +01001618 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001619 goto err;
Amaury Denoyellea7554392023-12-21 17:42:43 +01001620 }
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001621 list[hdr].n = htx_get_blk_name(htx, blk);
1622 list[hdr].v = htx_get_blk_value(htx, blk);
1623 hdr++;
1624 }
1625 else {
1626 TRACE_ERROR("unexpected HTX block", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyellea7554392023-12-21 17:42:43 +01001627 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001628 goto err;
1629 }
1630 }
1631
Amaury Denoyelle4be54352023-01-26 17:49:21 +01001632 if (!hdr) {
1633 /* No headers encoded here so no need to generate a H3 HEADERS
1634 * frame. Mux will send an empty QUIC STREAM frame with FIN.
1635 */
1636 TRACE_DATA("skipping trailer", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1637 goto end;
1638 }
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001639 list[hdr].n = ist("");
1640
1641 res = mux_get_buf(qcs);
Amaury Denoyelled70f1332024-01-29 14:39:19 +01001642 if (b_is_null(res)) {
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001643 TRACE_ERROR("cannot allocate Tx buffer", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1644 h3c->err = H3_INTERNAL_ERROR;
1645 goto err;
1646 }
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001647
1648 /* At least 9 bytes to store frame type + length as a varint max size */
1649 if (b_room(res) < 9) {
1650 qcs->flags |= QC_SF_BLK_MROOM;
1651 goto err;
1652 }
1653
1654 /* Force buffer realignment as size required to encode headers is unknown. */
1655 if (b_space_wraps(res))
1656 b_slow_realign(res, trash.area, b_data(res));
1657 /* Start the headers after frame type + length */
1658 headers_buf = b_make(b_peek(res, b_data(res) + 9), b_contig_space(res) - 9, 0, 0);
1659
Amaury Denoyelle224ba5c2023-01-26 17:41:58 +01001660 if (qpack_encode_field_section_line(&headers_buf)) {
1661 qcs->flags |= QC_SF_BLK_MROOM;
1662 goto err;
1663 }
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001664
1665 tail = b_tail(&headers_buf);
1666 for (hdr = 0; hdr < sizeof(list) / sizeof(list[0]); ++hdr) {
1667 if (isteq(list[hdr].n, ist("")))
1668 break;
1669
1670 /* forbidden HTTP/3 headers, cf h3_resp_headers_send() */
1671 if (isteq(list[hdr].n, ist("host")) ||
1672 isteq(list[hdr].n, ist("content-length")) ||
1673 isteq(list[hdr].n, ist("connection")) ||
1674 isteq(list[hdr].n, ist("proxy-connection")) ||
1675 isteq(list[hdr].n, ist("keep-alive")) ||
1676 isteq(list[hdr].n, ist("te")) ||
1677 isteq(list[hdr].n, ist("transfer-encoding"))) {
1678 continue;
1679 }
1680
Amaury Denoyelle224ba5c2023-01-26 17:41:58 +01001681 if (qpack_encode_header(&headers_buf, list[hdr].n, list[hdr].v)) {
1682 qcs->flags |= QC_SF_BLK_MROOM;
1683 goto err;
1684 }
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001685 }
1686
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001687 /* Check that at least one header was encoded in buffer. */
Amaury Denoyelle4be54352023-01-26 17:49:21 +01001688 if (b_tail(&headers_buf) == tail) {
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001689 /* No headers encoded here so no need to generate a H3 HEADERS
1690 * frame. Mux will send an empty QUIC STREAM frame with FIN.
1691 */
1692 TRACE_DATA("skipping trailer", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle4be54352023-01-26 17:49:21 +01001693 goto end;
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001694 }
1695
Amaury Denoyelle4be54352023-01-26 17:49:21 +01001696 /* Now that all headers are encoded, we are certain that res buffer is
1697 * big enough.
1698 */
1699 b_putchr(res, 0x01); /* h3 HEADERS frame type */
1700 if (!b_quic_enc_int(res, b_data(&headers_buf), 8))
1701 ABORT_NOW();
1702 b_add(res, b_data(&headers_buf));
1703
1704 end:
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001705 ret = 0;
1706 blk = htx_get_head_blk(htx);
1707 while (blk) {
1708 type = htx_get_blk_type(blk);
1709 ret += htx_get_blksz(blk);
1710 blk = htx_remove_blk(htx, blk);
1711 if (type == HTX_BLK_EOT)
1712 break;
1713 }
1714
1715 TRACE_LEAVE(H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1716 return ret;
1717
1718 err:
1719 TRACE_DEVEL("leaving on error", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001720 return -1;
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001721}
1722
Amaury Denoyelle3d5b5332024-01-04 11:33:33 +01001723/* Returns the total of bytes sent. This corresponds to the
1724 * total bytes of HTX block removed. A negative error code is returned in case
1725 * of a fatal error which should caused a connection closure.
1726 */
Amaury Denoyelle9534e592022-09-19 17:14:27 +02001727static int h3_resp_data_send(struct qcs *qcs, struct htx *htx, size_t count)
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001728{
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001729 struct h3s *h3s = qcs->ctx;
1730 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001731 struct buffer outbuf;
1732 struct buffer *res;
1733 size_t total = 0;
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001734 int bsize, fsize, hsize;
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001735 struct htx_blk *blk;
1736 enum htx_blk_type type;
1737
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001738 TRACE_ENTER(H3_EV_TX_DATA, qcs->qcc->conn, qcs);
1739
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001740 new_frame:
1741 if (!count || htx_is_empty(htx))
1742 goto end;
1743
1744 blk = htx_get_head_blk(htx);
1745 type = htx_get_blk_type(blk);
1746 fsize = bsize = htx_get_blksz(blk);
1747
1748 if (type != HTX_BLK_DATA)
1749 goto end;
1750
Amaury Denoyelled3d97c62021-10-05 11:45:58 +02001751 res = mux_get_buf(qcs);
Amaury Denoyelled70f1332024-01-29 14:39:19 +01001752 if (b_is_null(res)) {
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001753 TRACE_ERROR("cannot allocate Tx buffer", H3_EV_TX_DATA, qcs->qcc->conn, qcs);
1754 h3c->err = H3_INTERNAL_ERROR;
1755 goto err;
1756 }
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001757
1758 if (fsize > count)
1759 fsize = count;
1760
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001761 /* h3 DATA headers : 1-byte frame type + varint frame length */
1762 hsize = 1 + QUIC_VARINT_MAX_SIZE;
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001763
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001764 while (1) {
1765 b_reset(&outbuf);
1766 outbuf = b_make(b_tail(res), b_contig_space(res), 0, 0);
1767 if (b_size(&outbuf) > hsize || !b_space_wraps(res))
1768 break;
1769 b_slow_realign(res, trash.area, b_data(res));
1770 }
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001771
Amaury Denoyelle84ea8dc2021-12-03 14:40:01 +01001772 /* Not enough room for headers and at least one data byte, block the
Willy Tarreau4596fe22022-05-17 19:07:51 +02001773 * stream. It is expected that the stream connector layer will subscribe
1774 * on SEND.
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001775 */
Amaury Denoyelle84ea8dc2021-12-03 14:40:01 +01001776 if (b_size(&outbuf) <= hsize) {
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001777 TRACE_STATE("not enough room for data frame", H3_EV_TX_DATA, qcs->qcc->conn, qcs);
Amaury Denoyelle84ea8dc2021-12-03 14:40:01 +01001778 qcs->flags |= QC_SF_BLK_MROOM;
Amaury Denoyelle3d5b5332024-01-04 11:33:33 +01001779 goto end;
Amaury Denoyelle84ea8dc2021-12-03 14:40:01 +01001780 }
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001781
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001782 if (b_size(&outbuf) < hsize + fsize)
1783 fsize = b_size(&outbuf) - hsize;
1784 BUG_ON(fsize <= 0);
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001785
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001786 b_putchr(&outbuf, 0x00); /* h3 frame type = DATA */
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001787 b_quic_enc_int(&outbuf, fsize, 0); /* h3 frame length */
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001788
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001789 b_putblk(&outbuf, htx_get_blk_ptr(htx, blk), fsize);
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001790 total += fsize;
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001791 count -= fsize;
1792
1793 if (fsize == bsize)
1794 htx_remove_blk(htx, blk);
1795 else
1796 htx_cut_data_blk(htx, blk, fsize);
1797
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001798 /* commit the buffer */
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001799 b_add(res, b_data(&outbuf));
1800 goto new_frame;
1801
1802 end:
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001803 TRACE_LEAVE(H3_EV_TX_DATA, qcs->qcc->conn, qcs);
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001804 return total;
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001805
1806 err:
Amaury Denoyelle3d5b5332024-01-04 11:33:33 +01001807 BUG_ON(total); /* Must return HTX removed size if at least on frame encoded. */
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001808 TRACE_DEVEL("leaving on error", H3_EV_TX_DATA, qcs->qcc->conn, qcs);
1809 return -1;
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001810}
1811
Amaury Denoyelle9534e592022-09-19 17:14:27 +02001812static size_t h3_snd_buf(struct qcs *qcs, struct htx *htx, size_t count)
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001813{
Amaury Denoyelledf0ea3f2023-12-22 11:45:54 +01001814 struct h3s *h3s = qcs->ctx;
1815 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001816 size_t total = 0;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001817 enum htx_blk_type btype;
1818 struct htx_blk *blk;
1819 uint32_t bsize;
1820 int32_t idx;
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001821 int ret = 0;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001822
Amaury Denoyelle44083ac2024-01-29 15:15:27 +01001823 TRACE_ENTER(H3_EV_STRM_SEND, qcs->qcc->conn, qcs);
Amaury Denoyelledeed7772021-12-03 11:36:46 +01001824
Amaury Denoyelledf0ea3f2023-12-22 11:45:54 +01001825 while (count && !htx_is_empty(htx) &&
1826 !(qcs->flags & QC_SF_BLK_MROOM) && !h3c->err) {
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001827 idx = htx_get_head(htx);
1828 blk = htx_get_blk(htx, idx);
1829 btype = htx_get_blk_type(blk);
1830 bsize = htx_get_blksz(blk);
1831
1832 /* Not implemented : QUIC on backend side */
1833 BUG_ON(btype == HTX_BLK_REQ_SL);
1834
1835 switch (btype) {
1836 case HTX_BLK_RES_SL:
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001837 /* start-line -> HEADERS h3 frame */
1838 ret = h3_resp_headers_send(qcs, htx);
1839 if (ret > 0) {
1840 total += ret;
1841 count -= ret;
1842 if (ret < bsize)
1843 goto out;
1844 }
1845 break;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001846
1847 case HTX_BLK_DATA:
Amaury Denoyelle9534e592022-09-19 17:14:27 +02001848 ret = h3_resp_data_send(qcs, htx, count);
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001849 if (ret > 0) {
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001850 total += ret;
1851 count -= ret;
1852 if (ret < bsize)
1853 goto out;
1854 }
1855 break;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001856
1857 case HTX_BLK_TLR:
1858 case HTX_BLK_EOT:
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001859 ret = h3_resp_trailers_send(qcs, htx);
1860 if (ret > 0) {
1861 total += ret;
1862 count -= ret;
1863 if (ret < bsize)
1864 goto out;
1865 }
1866 break;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001867
1868 default:
1869 htx_remove_blk(htx, blk);
1870 total += bsize;
1871 count -= bsize;
1872 break;
1873 }
Amaury Denoyelle40ca0722023-12-22 09:00:13 +01001874
1875 /* If an error occured, either buffer space or connection error
1876 * must be set to break current loop.
1877 */
1878 BUG_ON(ret < 0 && !(qcs->flags & QC_SF_BLK_MROOM) && !h3c->err);
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001879 }
1880
Amaury Denoyelledf0ea3f2023-12-22 11:45:54 +01001881 /* Interrupt sending on connection error. */
1882 if (unlikely(h3c->err)) {
1883 qcc_set_error(qcs->qcc, h3c->err, 1);
1884 goto out;
1885 }
1886
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001887 out:
Amaury Denoyelle44083ac2024-01-29 15:15:27 +01001888 TRACE_LEAVE(H3_EV_STRM_SEND, qcs->qcc->conn, qcs);
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001889 return total;
Amaury Denoyellef52151d2021-08-24 16:11:18 +02001890}
1891
Amaury Denoyelle1e340ba2023-01-30 12:12:11 +01001892/* Notify about a closure on <qcs> stream requested by the remote peer.
1893 *
1894 * Stream channel <side> is explained relative to our endpoint : WR for
1895 * STOP_SENDING or RD for RESET_STREAM reception. Callback decode_qcs() is used
1896 * instead for closure performed using a STREAM frame with FIN bit.
1897 *
1898 * The main objective of this function is to check if closure is valid
1899 * according to HTTP/3 specification.
1900 *
1901 * Returns 0 on success else non-zero. A CONNECTION_CLOSE is generated on
1902 * error.
1903 */
1904static int h3_close(struct qcs *qcs, enum qcc_app_ops_close_side side)
1905{
Amaury Denoyelle87f87662023-01-30 12:12:43 +01001906 struct h3s *h3s = qcs->ctx;
1907 struct h3c *h3c = h3s->h3c;;
1908
1909 /* RFC 9114 6.2.1. Control Streams
1910 *
1911 * The sender
1912 * MUST NOT close the control stream, and the receiver MUST NOT
1913 * request that the sender close the control stream. If either
1914 * control stream is closed at any point, this MUST be treated
1915 * as a connection error of type H3_CLOSED_CRITICAL_STREAM.
1916 */
Amaury Denoyellee269aeb2023-01-30 12:13:22 +01001917 if (qcs == h3c->ctrl_strm || h3s->type == H3S_T_CTRL) {
Amaury Denoyellee31867b2023-01-31 16:01:22 +01001918 TRACE_ERROR("closure detected on control stream", H3_EV_H3S_END, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001919 qcc_set_error(qcs->qcc, H3_CLOSED_CRITICAL_STREAM, 1);
Amaury Denoyelle87f87662023-01-30 12:12:43 +01001920 return 1;
1921 }
1922
Amaury Denoyelle1e340ba2023-01-30 12:12:11 +01001923 return 0;
1924}
1925
Amaury Denoyelle583895a2024-06-21 14:45:04 +02001926/* Allocates HTTP/3 stream context relative to <qcs>. If the operation cannot
1927 * be performed, an error is returned and <qcs> context is unchanged.
1928 *
1929 * Returns 0 on success else non-zero.
1930 */
Amaury Denoyellec0156792022-06-03 15:29:07 +02001931static int h3_attach(struct qcs *qcs, void *conn_ctx)
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001932{
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001933 struct h3c *h3c = conn_ctx;
1934 struct h3s *h3s = NULL;
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001935
Amaury Denoyelled5581d52022-05-30 15:51:31 +02001936 TRACE_ENTER(H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
1937
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001938 h3s = pool_alloc(pool_head_h3s);
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001939 if (!h3s) {
1940 TRACE_ERROR("h3s allocation failure", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001941 goto err;
1942 }
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001943
1944 qcs->ctx = h3s;
Amaury Denoyellec0156792022-06-03 15:29:07 +02001945 h3s->h3c = conn_ctx;
1946
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001947 h3s->demux_frame_len = 0;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001948 h3s->demux_frame_type = H3_FT_UNINIT;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001949 h3s->body_len = 0;
1950 h3s->data_len = 0;
Amaury Denoyelle35550642022-05-24 15:14:53 +02001951 h3s->flags = 0;
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001952 h3s->err = 0;
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001953
Amaury Denoyelle3236a8e2022-05-24 15:24:03 +02001954 if (quic_stream_is_bidi(qcs->id)) {
1955 h3s->type = H3S_T_REQ;
Amaury Denoyelle8d818c62022-08-02 11:32:45 +02001956 h3s->st_req = H3S_ST_REQ_BEFORE;
Amaury Denoyelle30e260e2022-08-03 11:17:57 +02001957 qcs_wait_http_req(qcs);
Amaury Denoyelle3236a8e2022-05-24 15:24:03 +02001958 }
1959 else {
1960 /* stream type must be decoded for unidirectional streams */
1961 h3s->type = H3S_T_UNKNOWN;
1962 }
1963
Amaury Denoyelle583895a2024-06-21 14:45:04 +02001964 /* RFC 9114 5.2. Connection Shutdown
1965 *
1966 * Upon sending
1967 * a GOAWAY frame, the endpoint SHOULD explicitly cancel (see
1968 * Sections 4.1.1 and 7.2.3) any requests or pushes that have
1969 * identifiers greater than or equal to the one indicated, in
1970 * order to clean up transport state for the affected streams.
1971 * The endpoint SHOULD continue to do so as more requests or
1972 * pushes arrive.
1973 */
1974 if (h3c->flags & H3_CF_GOAWAY_SENT && qcs->id >= h3c->id_goaway &&
1975 quic_stream_is_bidi(qcs->id)) {
1976 TRACE_STATE("close stream outside of goaway range", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
1977 qcc_abort_stream_read(qcs);
1978 qcc_reset_stream(qcs, H3_REQUEST_REJECTED);
1979 }
1980
1981 /* TODO support push uni-stream rejection. */
1982
Amaury Denoyelled5581d52022-05-30 15:51:31 +02001983 TRACE_LEAVE(H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001984 return 0;
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001985
1986 err:
1987 TRACE_DEVEL("leaving in error", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
1988 return 1;
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001989}
1990
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001991static void h3_detach(struct qcs *qcs)
1992{
1993 struct h3s *h3s = qcs->ctx;
Amaury Denoyelled5581d52022-05-30 15:51:31 +02001994
1995 TRACE_ENTER(H3_EV_H3S_END, qcs->qcc->conn, qcs);
1996
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001997 pool_free(pool_head_h3s, h3s);
1998 qcs->ctx = NULL;
Amaury Denoyelled5581d52022-05-30 15:51:31 +02001999
2000 TRACE_LEAVE(H3_EV_H3S_END, qcs->qcc->conn, qcs);
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02002001}
2002
Amaury Denoyelle71fd0362023-01-24 17:35:37 +01002003/* Initialize H3 control stream and prepare SETTINGS emission.
2004 *
2005 * Returns 0 on success else non-zero.
2006 */
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002007static int h3_finalize(void *ctx)
2008{
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002009 struct h3c *h3c = ctx;
Amaury Denoyelle9cc47512022-05-24 16:27:41 +02002010 struct qcs *qcs;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002011
Amaury Denoyelleb1437232022-07-08 11:53:22 +02002012 qcs = qcc_init_stream_local(h3c->qcc, 0);
Amaury Denoyelle9cc47512022-05-24 16:27:41 +02002013 if (!qcs)
Amaury Denoyelle71fd0362023-01-24 17:35:37 +01002014 return 1;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002015
Amaury Denoyelled7010392022-07-13 15:17:29 +02002016 h3c->ctrl_strm = qcs;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002017
Amaury Denoyelleddc1ef12023-12-15 17:32:06 +01002018 if (h3_control_send(qcs, h3c) < 0)
2019 return 1;
2020
Amaury Denoyelle71fd0362023-01-24 17:35:37 +01002021 return 0;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002022}
2023
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002024/* Generate a GOAWAY frame for <h3c> connection on the control stream.
2025 *
2026 * Returns 0 on success else non-zero.
2027 */
2028static int h3_send_goaway(struct h3c *h3c)
2029{
2030 struct qcs *qcs = h3c->ctrl_strm;
2031 struct buffer pos, *res;
2032 unsigned char data[3 * QUIC_VARINT_MAX_SIZE];
2033 size_t frm_len = quic_int_getsize(h3c->id_goaway);
2034
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002035 TRACE_ENTER(H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002036
2037 if (!qcs) {
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002038 TRACE_ERROR("control stream not initialized", H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002039 goto err;
2040 }
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002041
2042 pos = b_make((char *)data, sizeof(data), 0, 0);
2043
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01002044 b_quic_enc_int(&pos, H3_FT_GOAWAY, 0);
2045 b_quic_enc_int(&pos, frm_len, 0);
2046 b_quic_enc_int(&pos, h3c->id_goaway, 0);
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002047
2048 res = mux_get_buf(qcs);
Amaury Denoyelled70f1332024-01-29 14:39:19 +01002049 if (b_is_null(res) || b_room(res) < b_data(&pos)) {
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002050 /* Do not try forcefully to emit GOAWAY if no space left. */
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002051 TRACE_ERROR("cannot send GOAWAY", H3_EV_H3C_END, h3c->qcc->conn, qcs);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002052 goto err;
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002053 }
2054
2055 b_force_xfer(res, &pos, b_data(&pos));
Amaury Denoyelle19adeb52023-01-25 10:50:03 +01002056 qcc_send_stream(qcs, 1);
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002057
Amaury Denoyelle3d550842023-01-24 17:42:21 +01002058 h3c->flags |= H3_CF_GOAWAY_SENT;
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002059 TRACE_LEAVE(H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002060 return 0;
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002061
2062 err:
Amaury Denoyelle3d550842023-01-24 17:42:21 +01002063 /* Consider GOAWAY as sent even if not really the case. This will
2064 * block future stream opening using H3_REQUEST_REJECTED reset.
2065 */
2066 h3c->flags |= H3_CF_GOAWAY_SENT;
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002067 TRACE_DEVEL("leaving in error", H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002068 return 1;
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002069}
2070
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002071/* Initialize the HTTP/3 context for <qcc> mux.
2072 * Return 1 if succeeded, 0 if not.
2073 */
2074static int h3_init(struct qcc *qcc)
2075{
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002076 struct h3c *h3c;
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02002077 struct quic_conn *qc = qcc->conn->handle.qc;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002078
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002079 h3c = pool_alloc(pool_head_h3c);
2080 if (!h3c)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002081 goto fail_no_h3;
2082
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002083 h3c->qcc = qcc;
Amaury Denoyelled7010392022-07-13 15:17:29 +02002084 h3c->ctrl_strm = NULL;
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01002085 h3c->err = 0;
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002086 h3c->flags = 0;
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002087 h3c->id_goaway = 0;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002088
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002089 qcc->ctx = h3c;
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +02002090 /* TODO cleanup only ref to quic_conn */
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02002091 h3c->prx_counters =
2092 EXTRA_COUNTERS_GET(qc->li->bind_conf->frontend->extra_counters_fe,
2093 &h3_stats_module);
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002094 LIST_INIT(&h3c->buf_wait.list);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002095
2096 return 1;
2097
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002098 fail_no_h3:
2099 return 0;
2100}
2101
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002102/* Send a HTTP/3 GOAWAY followed by a CONNECTION_CLOSE_APP. */
2103static void h3_shutdown(void *ctx)
Amaury Denoyelle8347f272022-03-29 14:46:55 +02002104{
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002105 struct h3c *h3c = ctx;
Amaury Denoyelle069288b2022-07-15 10:58:25 +02002106
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002107 TRACE_ENTER(H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002108
Amaury Denoyelle069288b2022-07-15 10:58:25 +02002109 /* RFC 9114 5.2. Connection Shutdown
2110 *
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002111 * Even when a connection is not idle, either endpoint can decide to
2112 * stop using the connection and initiate a graceful connection close.
2113 * Endpoints initiate the graceful shutdown of an HTTP/3 connection by
2114 * sending a GOAWAY frame.
2115 */
2116 h3_send_goaway(h3c);
2117
2118 /* RFC 9114 5.2. Connection Shutdown
2119 *
Amaury Denoyelle069288b2022-07-15 10:58:25 +02002120 * An endpoint that completes a
2121 * graceful shutdown SHOULD use the H3_NO_ERROR error code when closing
2122 * the connection.
2123 */
Amaury Denoyelle51f116d2023-05-04 15:49:02 +02002124 h3c->qcc->err = quic_err_app(H3_NO_ERROR);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002125
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002126 TRACE_LEAVE(H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002127}
Amaury Denoyelle069288b2022-07-15 10:58:25 +02002128
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002129static void h3_release(void *ctx)
2130{
2131 struct h3c *h3c = ctx;
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002132 pool_free(pool_head_h3c, h3c);
Amaury Denoyelle8347f272022-03-29 14:46:55 +02002133}
2134
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02002135/* Increment the h3 error code counters for <error_code> value */
2136static void h3_stats_inc_err_cnt(void *ctx, int err_code)
2137{
2138 struct h3c *h3c = ctx;
2139
2140 h3_inc_err_cnt(h3c->prx_counters, err_code);
2141}
2142
Amaury Denoyelle35d90532023-01-26 16:03:45 +01002143static inline const char *h3_ft_str(uint64_t type)
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01002144{
2145 switch (type) {
2146 case H3_FT_DATA: return "DATA";
2147 case H3_FT_HEADERS: return "HEADERS";
2148 case H3_FT_SETTINGS: return "SETTINGS";
2149 case H3_FT_PUSH_PROMISE: return "PUSH_PROMISE";
2150 case H3_FT_MAX_PUSH_ID: return "MAX_PUSH_ID";
2151 case H3_FT_CANCEL_PUSH: return "CANCEL_PUSH";
2152 case H3_FT_GOAWAY: return "GOAWAY";
2153 default: return "_UNKNOWN_";
2154 }
2155}
2156
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002157/* h3 trace handler */
2158static void h3_trace(enum trace_level level, uint64_t mask,
2159 const struct trace_source *src,
2160 const struct ist where, const struct ist func,
2161 const void *a1, const void *a2, const void *a3, const void *a4)
2162{
2163 const struct connection *conn = a1;
2164 const struct qcc *qcc = conn ? conn->ctx : NULL;
2165 const struct qcs *qcs = a2;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01002166 const struct h3s *h3s = qcs ? qcs->ctx : NULL;
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002167
Frédéric Lécaille1c725aa2022-09-08 15:49:37 +02002168 if (!qcc)
2169 return;
2170
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002171 if (src->verbosity > H3_VERB_CLEAN) {
2172 chunk_appendf(&trace_buf, " : qcc=%p(F)", qcc);
Frédéric Lécaille2eb5faa2022-09-08 16:03:13 +02002173 if (qcc->conn->handle.qc)
2174 chunk_appendf(&trace_buf, " qc=%p", qcc->conn->handle.qc);
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002175
2176 if (qcs)
Frédéric Lécaille628e89c2022-06-24 12:13:53 +02002177 chunk_appendf(&trace_buf, " qcs=%p(%llu)", qcs, (ull)qcs->id);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01002178
2179 if (h3s && h3s->demux_frame_type != H3_FT_UNINIT) {
Amaury Denoyelle35d90532023-01-26 16:03:45 +01002180 chunk_appendf(&trace_buf, " h3s.dem=%s/%llu",
2181 h3_ft_str(h3s->demux_frame_type), (ull)h3s->demux_frame_len);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01002182 }
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002183 }
2184}
2185
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002186/* HTTP/3 application layer operations */
2187const struct qcc_app_ops h3_ops = {
2188 .init = h3_init,
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02002189 .attach = h3_attach,
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002190 .decode_qcs = h3_decode_qcs,
Amaury Denoyelleabbe91e2021-11-12 16:09:29 +01002191 .snd_buf = h3_snd_buf,
Amaury Denoyelle1e340ba2023-01-30 12:12:11 +01002192 .close = h3_close,
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02002193 .detach = h3_detach,
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002194 .finalize = h3_finalize,
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002195 .shutdown = h3_shutdown,
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02002196 .inc_err_cnt = h3_stats_inc_err_cnt,
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002197 .release = h3_release,
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002198};