blob: a8a3574186ea1952ae050412822f5e6ad75436f3 [file] [log] [blame]
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001/*
2 * HTTP/3 protocol processing
3 *
4 * This library is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU Lesser General Public
6 * License as published by the Free Software Foundation, version 2.1
7 * exclusively.
8 *
9 * This library is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
12 * Lesser General Public License for more details.
13 *
14 * You should have received a copy of the GNU Lesser General Public
15 * License along with this library; if not, write to the Free Software
16 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
17 */
18
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +020019#include <import/ist.h>
20
21#include <haproxy/api.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010022#include <haproxy/buf.h>
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +020023#include <haproxy/chunk.h>
Amaury Denoyelle99043552021-08-24 15:36:02 +020024#include <haproxy/connection.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010025#include <haproxy/dynbuf.h>
26#include <haproxy/h3.h>
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +020027#include <haproxy/h3_stats.h>
Amaury Denoyelleb49fa1a2021-08-24 15:30:12 +020028#include <haproxy/http.h>
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +020029#include <haproxy/http-hdr-t.h>
Amaury Denoyelle115ccce2022-08-17 18:02:47 +020030#include <haproxy/http_htx.h>
Amaury Denoyelleb49fa1a2021-08-24 15:30:12 +020031#include <haproxy/htx.h>
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +020032#include <haproxy/intops.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010033#include <haproxy/istbuf.h>
Amaury Denoyelle846cc042022-04-04 16:13:44 +020034#include <haproxy/mux_quic.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010035#include <haproxy/pool.h>
Amaury Denoyelle381d8132023-02-17 09:51:20 +010036#include <haproxy/qmux_http.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010037#include <haproxy/qpack-dec.h>
Amaury Denoyelle15b09612021-08-24 16:20:27 +020038#include <haproxy/qpack-enc.h>
Amaury Denoyelle92fa63f2022-09-30 18:11:13 +020039#include <haproxy/quic_conn-t.h>
Amaury Denoyelle15b09612021-08-24 16:20:27 +020040#include <haproxy/quic_enc.h>
Amaury Denoyelle51f116d2023-05-04 15:49:02 +020041#include <haproxy/quic_frame.h>
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +020042#include <haproxy/stats-t.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010043#include <haproxy/tools.h>
Amaury Denoyelle016aa932022-05-30 15:49:36 +020044#include <haproxy/trace.h>
Frédéric Lécailleccac11f2021-03-03 16:09:02 +010045
Amaury Denoyelle016aa932022-05-30 15:49:36 +020046/* trace source and events */
47static void h3_trace(enum trace_level level, uint64_t mask,
48 const struct trace_source *src,
49 const struct ist where, const struct ist func,
50 const void *a1, const void *a2, const void *a3, const void *a4);
51
52static const struct trace_event h3_trace_events[] = {
Amaury Denoyelle494512d2022-05-30 15:50:34 +020053#define H3_EV_RX_FRAME (1ULL << 0)
54 { .mask = H3_EV_RX_FRAME, .name = "rx_frame", .desc = "receipt of any H3 frame" },
55#define H3_EV_RX_DATA (1ULL << 1)
56 { .mask = H3_EV_RX_DATA, .name = "rx_data", .desc = "receipt of H3 DATA frame" },
57#define H3_EV_RX_HDR (1ULL << 2)
58 { .mask = H3_EV_RX_HDR, .name = "rx_hdr", .desc = "receipt of H3 HEADERS frame" },
59#define H3_EV_RX_SETTINGS (1ULL << 3)
60 { .mask = H3_EV_RX_SETTINGS, .name = "rx_settings", .desc = "receipt of H3 SETTINGS frame" },
Amaury Denoyellea717eb72022-05-30 15:51:01 +020061#define H3_EV_TX_DATA (1ULL << 4)
62 { .mask = H3_EV_TX_DATA, .name = "tx_data", .desc = "transmission of H3 DATA frame" },
63#define H3_EV_TX_HDR (1ULL << 5)
64 { .mask = H3_EV_TX_HDR, .name = "tx_hdr", .desc = "transmission of H3 HEADERS frame" },
65#define H3_EV_TX_SETTINGS (1ULL << 6)
66 { .mask = H3_EV_TX_SETTINGS, .name = "tx_settings", .desc = "transmission of H3 SETTINGS frame" },
Amaury Denoyelled5581d52022-05-30 15:51:31 +020067#define H3_EV_H3S_NEW (1ULL << 7)
68 { .mask = H3_EV_H3S_NEW, .name = "h3s_new", .desc = "new H3 stream" },
69#define H3_EV_H3S_END (1ULL << 8)
70 { .mask = H3_EV_H3S_END, .name = "h3s_end", .desc = "H3 stream terminated" },
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +010071#define H3_EV_H3C_END (1ULL << 9)
72 { .mask = H3_EV_H3C_END, .name = "h3c_end", .desc = "H3 connection terminated" },
Amaury Denoyelle016aa932022-05-30 15:49:36 +020073 { }
74};
75
76static const struct name_desc h3_trace_lockon_args[4] = {
77 /* arg1 */ { /* already used by the connection */ },
78 /* arg2 */ { .name="qcs", .desc="QUIC stream" },
79 /* arg3 */ { },
80 /* arg4 */ { }
81};
82
83static const struct name_desc h3_trace_decoding[] = {
84#define H3_VERB_CLEAN 1
85 { .name="clean", .desc="only user-friendly stuff, generally suitable for level \"user\"" },
86#define H3_VERB_MINIMAL 2
87 { .name="minimal", .desc="report only qcc/qcs state and flags, no real decoding" },
88 { /* end */ }
89};
90
91struct trace_source trace_h3 = {
92 .name = IST("h3"),
93 .desc = "HTTP/3 transcoder",
94 .arg_def = TRC_ARG1_CONN, /* TRACE()'s first argument is always a connection */
95 .default_cb = h3_trace,
96 .known_events = h3_trace_events,
97 .lockon_args = h3_trace_lockon_args,
98 .decoding = h3_trace_decoding,
99 .report_events = ~0, /* report everything by default */
100};
101
102#define TRACE_SOURCE &trace_h3
103INITCALL1(STG_REGISTER, trace_register_source, TRACE_SOURCE);
104
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100105#if defined(DEBUG_H3)
106#define h3_debug_printf fprintf
107#define h3_debug_hexdump debug_hexdump
108#else
109#define h3_debug_printf(...) do { } while (0)
110#define h3_debug_hexdump(...) do { } while (0)
111#endif
112
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200113#define H3_CF_SETTINGS_SENT 0x00000001 /* SETTINGS frame already sent on local control stream */
114#define H3_CF_SETTINGS_RECV 0x00000002 /* SETTINGS frame already received on remote control stream */
115#define H3_CF_UNI_CTRL_SET 0x00000004 /* Remote H3 Control stream opened */
116#define H3_CF_UNI_QPACK_DEC_SET 0x00000008 /* Remote QPACK decoder stream opened */
117#define H3_CF_UNI_QPACK_ENC_SET 0x00000010 /* Remote QPACK encoder stream opened */
Amaury Denoyelle3d550842023-01-24 17:42:21 +0100118#define H3_CF_GOAWAY_SENT 0x00000020 /* GOAWAY sent on local control stream */
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100119
120/* Default settings */
Amaury Denoyelle33949392021-08-24 15:16:58 +0200121static uint64_t h3_settings_qpack_max_table_capacity = 0;
122static uint64_t h3_settings_qpack_blocked_streams = 4096;
123static uint64_t h3_settings_max_field_section_size = QUIC_VARINT_8_BYTE_MAX; /* Unlimited */
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100124
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +0200125struct h3c {
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100126 struct qcc *qcc;
Amaury Denoyelled7010392022-07-13 15:17:29 +0200127 struct qcs *ctrl_strm; /* Control stream */
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100128 enum h3_err err;
129 uint32_t flags;
Amaury Denoyelle9cc47512022-05-24 16:27:41 +0200130
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100131 /* Settings */
132 uint64_t qpack_max_table_capacity;
133 uint64_t qpack_blocked_streams;
134 uint64_t max_field_section_size;
Amaury Denoyelle9cc47512022-05-24 16:27:41 +0200135
Amaury Denoyelle114c9c82022-03-28 14:53:45 +0200136 uint64_t id_goaway; /* stream ID used for a GOAWAY frame */
137
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100138 struct buffer_wait buf_wait; /* wait list for buffer allocations */
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +0200139 /* Stats counters */
140 struct h3_counters *prx_counters;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100141};
142
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +0200143DECLARE_STATIC_POOL(pool_head_h3c, "h3c", sizeof(struct h3c));
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100144
Amaury Denoyelle35550642022-05-24 15:14:53 +0200145#define H3_SF_UNI_INIT 0x00000001 /* stream type not parsed for unidirectional stream */
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200146#define H3_SF_UNI_NO_H3 0x00000002 /* unidirectional stream does not carry H3 frames */
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100147#define H3_SF_HAVE_CLEN 0x00000004 /* content-length header is present */
Amaury Denoyelle35550642022-05-24 15:14:53 +0200148
Amaury Denoyelle67e92d32022-04-27 18:04:01 +0200149struct h3s {
Amaury Denoyellec0156792022-06-03 15:29:07 +0200150 struct h3c *h3c;
151
Amaury Denoyelle3236a8e2022-05-24 15:24:03 +0200152 enum h3s_t type;
Amaury Denoyelle8d818c62022-08-02 11:32:45 +0200153 enum h3s_st_req st_req; /* only used for request streams */
Amaury Denoyelle35d90532023-01-26 16:03:45 +0100154 uint64_t demux_frame_len;
155 uint64_t demux_frame_type;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200156
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100157 unsigned long long body_len; /* known request body length from content-length header if present */
158 unsigned long long data_len; /* total length of all parsed DATA */
159
Amaury Denoyelle35550642022-05-24 15:14:53 +0200160 int flags;
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100161 int err; /* used for stream reset */
Amaury Denoyelle67e92d32022-04-27 18:04:01 +0200162};
163
164DECLARE_STATIC_POOL(pool_head_h3s, "h3s", sizeof(struct h3s));
165
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200166/* Initialize an uni-stream <qcs> by reading its type from <b>.
Amaury Denoyelle35550642022-05-24 15:14:53 +0200167 *
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200168 * Returns the count of consumed bytes or a negative error code.
Amaury Denoyelle35550642022-05-24 15:14:53 +0200169 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200170static ssize_t h3_init_uni_stream(struct h3c *h3c, struct qcs *qcs,
171 struct buffer *b)
Amaury Denoyelle35550642022-05-24 15:14:53 +0200172{
173 /* decode unidirectional stream type */
174 struct h3s *h3s = qcs->ctx;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200175 uint64_t type;
176 size_t len = 0, ret;
177
Amaury Denoyelled5581d52022-05-30 15:51:31 +0200178 TRACE_ENTER(H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
179
Amaury Denoyelle8d6d2462023-05-11 16:55:30 +0200180 /* Function reserved to uni streams. Must be called only once per stream instance. */
181 BUG_ON(!quic_stream_is_uni(qcs->id) || h3s->flags & H3_SF_UNI_INIT);
Amaury Denoyelle35550642022-05-24 15:14:53 +0200182
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200183 ret = b_quic_dec_int(&type, b, &len);
Amaury Denoyelle35550642022-05-24 15:14:53 +0200184 if (!ret) {
Amaury Denoyelle5aa21c12023-03-09 11:12:32 +0100185 /* not enough data to decode uni stream type, retry later */
186 TRACE_DATA("cannot decode uni stream type due to incomplete data", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
187 goto out;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200188 }
189
190 switch (type) {
191 case H3_UNI_S_T_CTRL:
192 if (h3c->flags & H3_CF_UNI_CTRL_SET) {
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100193 TRACE_ERROR("duplicated control stream", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +0200194 qcc_set_error(qcs->qcc, H3_STREAM_CREATION_ERROR, 1);
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100195 goto err;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200196 }
197 h3c->flags |= H3_CF_UNI_CTRL_SET;
198 h3s->type = H3S_T_CTRL;
199 break;
200
201 case H3_UNI_S_T_PUSH:
202 /* TODO not supported for the moment */
203 h3s->type = H3S_T_PUSH;
204 break;
205
206 case H3_UNI_S_T_QPACK_DEC:
207 if (h3c->flags & H3_CF_UNI_QPACK_DEC_SET) {
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100208 TRACE_ERROR("duplicated qpack decoder stream", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +0200209 qcc_set_error(qcs->qcc, H3_STREAM_CREATION_ERROR, 1);
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100210 goto err;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200211 }
212 h3c->flags |= H3_CF_UNI_QPACK_DEC_SET;
213 h3s->type = H3S_T_QPACK_DEC;
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200214 h3s->flags |= H3_SF_UNI_NO_H3;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200215 break;
216
217 case H3_UNI_S_T_QPACK_ENC:
218 if (h3c->flags & H3_CF_UNI_QPACK_ENC_SET) {
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100219 TRACE_ERROR("duplicated qpack encoder stream", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +0200220 qcc_set_error(qcs->qcc, H3_STREAM_CREATION_ERROR, 1);
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100221 goto err;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200222 }
223 h3c->flags |= H3_CF_UNI_QPACK_ENC_SET;
224 h3s->type = H3S_T_QPACK_ENC;
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200225 h3s->flags |= H3_SF_UNI_NO_H3;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200226 break;
227
228 default:
Amaury Denoyelle849b24f2022-05-24 17:22:07 +0200229 /* draft-ietf-quic-http34 9. Extensions to HTTP/3
230 *
231 * Implementations MUST [...] abort reading on unidirectional
232 * streams that have unknown or unsupported types.
233 */
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100234 TRACE_STATE("abort reading on unknown uni stream type", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle663e8722022-12-09 14:58:28 +0100235 qcc_abort_stream_read(qcs);
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100236 goto err;
237 }
Amaury Denoyelle35550642022-05-24 15:14:53 +0200238
239 h3s->flags |= H3_SF_UNI_INIT;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200240
Amaury Denoyelle5aa21c12023-03-09 11:12:32 +0100241 out:
Amaury Denoyelled5581d52022-05-30 15:51:31 +0200242 TRACE_LEAVE(H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200243 return len;
Amaury Denoyelle815c8ce2023-03-08 10:25:39 +0100244
245 err:
246 TRACE_DEVEL("leaving on error", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
247 return -1;
Amaury Denoyelle35550642022-05-24 15:14:53 +0200248}
249
Amaury Denoyelle26aa3992022-08-16 17:42:47 +0200250/* Parse a buffer <b> for a <qcs> uni-stream which does not contains H3 frames.
251 * This may be used for QPACK encoder/decoder streams for example. <fin> is set
252 * if this is the last frame of the stream.
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200253 *
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200254 * Returns the number of consumed bytes or a negative error code.
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200255 */
Amaury Denoyelle26aa3992022-08-16 17:42:47 +0200256static ssize_t h3_parse_uni_stream_no_h3(struct qcs *qcs, struct buffer *b, int fin)
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200257{
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200258 struct h3s *h3s = qcs->ctx;
259
Amaury Denoyelle8d6d2462023-05-11 16:55:30 +0200260 /* Function reserved to non-HTTP/3 unidirectional streams. */
261 BUG_ON(!quic_stream_is_uni(qcs->id) || !(h3s->flags & H3_SF_UNI_NO_H3));
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200262
263 switch (h3s->type) {
264 case H3S_T_QPACK_DEC:
Amaury Denoyelle26aa3992022-08-16 17:42:47 +0200265 if (qpack_decode_dec(b, fin, qcs))
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200266 return -1;
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200267 break;
268 case H3S_T_QPACK_ENC:
Amaury Denoyelle26aa3992022-08-16 17:42:47 +0200269 if (qpack_decode_enc(b, fin, qcs))
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200270 return -1;
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200271 break;
Amaury Denoyelle849b24f2022-05-24 17:22:07 +0200272 case H3S_T_UNKNOWN:
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200273 default:
Amaury Denoyelle849b24f2022-05-24 17:22:07 +0200274 /* Unknown stream should be flagged with QC_SF_READ_ABORTED. */
275 ABORT_NOW();
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200276 }
277
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200278 /* TODO adjust return code */
Amaury Denoyellefc99a692022-05-24 15:25:19 +0200279 return 0;
280}
281
Amaury Denoyelle88d5dd12022-05-31 11:44:52 +0200282/* Decode a H3 frame header from <rxbuf> buffer. The frame type is stored in
283 * <ftype> and length in <flen>.
284 *
285 * Returns the size of the H3 frame header. Note that the input buffer is not
286 * consumed.
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100287 */
288static inline size_t h3_decode_frm_header(uint64_t *ftype, uint64_t *flen,
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200289 struct buffer *b)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100290{
291 size_t hlen;
292
293 hlen = 0;
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200294 if (!b_quic_dec_int(ftype, b, &hlen) ||
295 !b_quic_dec_int(flen, b, &hlen)) {
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100296 return 0;
Amaury Denoyelle88d5dd12022-05-31 11:44:52 +0200297 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100298
299 return hlen;
300}
301
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200302/* Check if H3 frame of type <ftype> is valid when received on stream <qcs>.
303 *
304 * Returns a boolean. If false, a connection error H3_FRAME_UNEXPECTED should
305 * be reported.
306 */
307static int h3_is_frame_valid(struct h3c *h3c, struct qcs *qcs, uint64_t ftype)
308{
309 struct h3s *h3s = qcs->ctx;
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200310
Amaury Denoyelle8d6d2462023-05-11 16:55:30 +0200311 /* Stream type must be known to ensure frame is valid for this stream. */
312 BUG_ON(h3s->type == H3S_T_UNKNOWN);
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200313
314 switch (ftype) {
315 case H3_FT_DATA:
Amaury Denoyelle8d818c62022-08-02 11:32:45 +0200316 return h3s->type != H3S_T_CTRL && (h3s->st_req == H3S_ST_REQ_HEADERS ||
317 h3s->st_req == H3S_ST_REQ_DATA);
318
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200319 case H3_FT_HEADERS:
Amaury Denoyelle8d818c62022-08-02 11:32:45 +0200320 return h3s->type != H3S_T_CTRL && h3s->st_req != H3S_ST_REQ_TRAILERS;
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200321
322 case H3_FT_CANCEL_PUSH:
323 case H3_FT_GOAWAY:
324 case H3_FT_MAX_PUSH_ID:
325 /* Only allowed for control stream. First frame of control
326 * stream MUST be SETTINGS.
327 */
328 return h3s->type == H3S_T_CTRL &&
329 (h3c->flags & H3_CF_SETTINGS_RECV);
330
331 case H3_FT_SETTINGS:
332 /* draft-ietf-quic-http34 7.2.4. SETTINGS
333 *
334 * If an endpoint receives a second SETTINGS frame on the control
335 * stream, the endpoint MUST respond with a connection error of type
336 * H3_FRAME_UNEXPECTED.
337 */
338 return h3s->type == H3S_T_CTRL &&
339 !(h3c->flags & H3_CF_SETTINGS_RECV);
340
341 case H3_FT_PUSH_PROMISE:
Amaury Denoyelle68bf6c82023-11-28 12:00:40 +0100342 /* RFC 9114 7.2.5. PUSH_PROMISE
343 * A client MUST NOT send a PUSH_PROMISE frame. A server MUST treat the
344 * receipt of a PUSH_PROMISE frame as a connection error of type
345 * H3_FRAME_UNEXPECTED.
346 */
347
348 /* TODO server-side only. */
349 return 0;
Amaury Denoyelle302ecd42022-05-24 15:24:32 +0200350
351 default:
352 /* draft-ietf-quic-http34 9. Extensions to HTTP/3
353 *
354 * Implementations MUST discard frames [...] that have unknown
355 * or unsupported types.
356 */
357 return h3s->type != H3S_T_CTRL || (h3c->flags & H3_CF_SETTINGS_RECV);
358 }
359}
360
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100361/* Check from stream <qcs> that length of all DATA frames does not exceed with
362 * a previously parsed content-length header. <fin> must be set for the last
363 * data of the stream so that length of DATA frames must be equal to the
364 * content-length.
365 *
366 * This must only be called for a stream with H3_SF_HAVE_CLEN flag.
367 *
368 * Return 0 on valid else non-zero.
369 */
370static int h3_check_body_size(struct qcs *qcs, int fin)
371{
372 struct h3s *h3s = qcs->ctx;
373 int ret = 0;
374 TRACE_ENTER(H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
375
376 /* Reserved for streams with a previously parsed content-length header. */
377 BUG_ON(!(h3s->flags & H3_SF_HAVE_CLEN));
378
379 /* RFC 9114 4.1.2. Malformed Requests and Responses
380 *
381 * A request or response that is defined as having content when it
382 * contains a Content-Length header field (Section 8.6 of [HTTP]) is
383 * malformed if the value of the Content-Length header field does not
384 * equal the sum of the DATA frame lengths received.
385 *
386 * TODO for backend support
387 * A response that is
388 * defined as never having content, even when a Content-Length is
389 * present, can have a non-zero Content-Length header field even though
390 * no content is included in DATA frames.
391 */
392 if (h3s->data_len > h3s->body_len ||
393 (fin && h3s->data_len < h3s->body_len)) {
394 TRACE_ERROR("Content-length does not match DATA frame size", H3_EV_RX_FRAME|H3_EV_RX_DATA, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100395 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100396 ret = -1;
397 }
398
399 TRACE_LEAVE(H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
400 return ret;
401}
402
Amaury Denoyellea514a112023-10-09 16:14:44 +0200403/* Set <auth> authority header to the new value <value> for <qcs> stream. This
404 * ensures that value is conformant to the specification. If <auth> is a
405 * non-null length string, it ensures that <value> is identical to it.
406 *
407 * Returns 0 on success else non-zero.
408 */
409static int h3_set_authority(struct qcs *qcs, struct ist *auth, const struct ist value)
410{
411 /* RFC 9114 4.3.1. Request Pseudo-Header Fields
412 *
413 * If the :scheme pseudo-header field identifies a scheme that has a
414 * mandatory authority component (including "http" and "https"), the
415 * request MUST contain either an :authority pseudo-header field or a
416 * Host header field. If these fields are present, they MUST NOT be
417 * empty. If both fields are present, they MUST contain the same value.
418 */
419
420 /* Check that if a previous value is set the new value is identical. */
421 if (isttest(*auth) && !isteq(*auth, value)) {
422 TRACE_ERROR("difference between :authority and host headers", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
423 return 1;
424 }
425
426 /* Check that value is not empty. */
427 if (!istlen(value)) {
428 TRACE_ERROR("empty :authority/host header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
429 return 1;
430 }
431
432 *auth = value;
433 return 0;
434}
435
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100436/* Parse from buffer <buf> a H3 HEADERS frame of length <len>. Data are copied
Willy Tarreau4596fe22022-05-17 19:07:51 +0200437 * in a local HTX buffer and transfer to the stream connector layer. <fin> must be
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100438 * set if this is the last data to transfer from this stream.
439 *
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100440 * Returns the number of consumed bytes or a negative error code. On error
441 * either the connection should be closed or the stream reset using codes
442 * provided in h3c.err / h3s.err.
Amaury Denoyelleb9ce14e2021-11-08 09:13:42 +0100443 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200444static ssize_t h3_headers_to_htx(struct qcs *qcs, const struct buffer *buf,
445 uint64_t len, char fin)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100446{
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200447 struct h3s *h3s = qcs->ctx;
448 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100449 struct buffer htx_buf = BUF_NULL;
450 struct buffer *tmp = get_trash_chunk();
Amaury Denoyelle7059ebc2021-12-08 15:51:04 +0100451 struct htx *htx = NULL;
Amaury Denoyelleb49fa1a2021-08-24 15:30:12 +0200452 struct htx_sl *sl;
Amaury Denoyellefd7cdc32021-08-24 15:13:20 +0200453 struct http_hdr list[global.tune.max_http_hdr];
Amaury Denoyelleb49fa1a2021-08-24 15:30:12 +0200454 unsigned int flags = HTX_SL_F_NONE;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100455 struct ist meth = IST_NULL, path = IST_NULL;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100456 struct ist scheme = IST_NULL, authority = IST_NULL;
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200457 int hdr_idx, ret;
Amaury Denoyelled6fb7a02022-12-07 14:31:42 +0100458 int cookie = -1, last_cookie = -1, i;
Willy Tarreau0404bf12023-08-08 17:18:27 +0200459 const char *ctl;
Willy Tarreau96dfea82023-08-08 17:54:26 +0200460 int relaxed = !!(h3c->qcc->proxy->options2 & PR_O2_REQBUG_OK);
Amaury Denoyelled6fb7a02022-12-07 14:31:42 +0100461
462 /* RFC 9114 4.1.2. Malformed Requests and Responses
463 *
464 * A malformed request or response is one that is an otherwise valid
465 * sequence of frames but is invalid due to:
466 * - the presence of prohibited fields or pseudo-header fields,
467 * - the absence of mandatory pseudo-header fields,
468 * - invalid values for pseudo-header fields,
469 * - pseudo-header fields after fields,
470 * - an invalid sequence of HTTP messages,
471 * - the inclusion of uppercase field names, or
472 * - the inclusion of invalid characters in field names or values.
473 *
474 * [...]
475 *
476 * Intermediaries that process HTTP requests or responses (i.e., any
477 * intermediary not acting as a tunnel) MUST NOT forward a malformed
478 * request or response. Malformed requests or responses that are
479 * detected MUST be treated as a stream error of type H3_MESSAGE_ERROR.
480 */
Frédéric Lécailleccac11f2021-03-03 16:09:02 +0100481
Amaury Denoyelle494512d2022-05-30 15:50:34 +0200482 TRACE_ENTER(H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
483
Amaury Denoyelle8d818c62022-08-02 11:32:45 +0200484 /* TODO support trailer parsing in this function */
485
Amaury Denoyelle30f23f52022-04-27 14:41:53 +0200486 /* TODO support buffer wrapping */
Amaury Denoyelle62eef852022-06-03 16:40:34 +0200487 BUG_ON(b_head(buf) + len >= b_wrap(buf));
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200488 ret = qpack_decode_fs((const unsigned char *)b_head(buf), len, tmp,
489 list, sizeof(list) / sizeof(list[0]));
490 if (ret < 0) {
491 TRACE_ERROR("QPACK decoding error", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
492 h3c->err = -ret;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100493 len = -1;
494 goto out;
Amaury Denoyelle60ef19f2022-06-14 17:38:36 +0200495 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100496
Amaury Denoyelled68f8b52023-05-30 15:04:46 +0200497 if (!qcs_get_buf(qcs, &htx_buf)) {
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +0200498 TRACE_ERROR("HTX buffer alloc failure", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
499 h3c->err = H3_INTERNAL_ERROR;
500 len = -1;
501 goto out;
502 }
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100503 BUG_ON(!b_size(&htx_buf)); /* TODO */
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100504 htx = htx_from_buf(&htx_buf);
505
506 /* first treat pseudo-header to build the start line */
507 hdr_idx = 0;
508 while (1) {
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100509 /* RFC 9114 4.3. HTTP Control Data
510 *
511 * Endpoints MUST treat a request or response that contains
512 * undefined or invalid pseudo-header fields as malformed.
513 *
514 * All pseudo-header fields MUST appear in the header section before
515 * regular header fields. Any request or response that contains a
516 * pseudo-header field that appears in a header section after a regular
517 * header field MUST be treated as malformed.
518 */
519
520 /* Stop at first non pseudo-header. */
521 if (!istmatch(list[hdr_idx].n, ist(":")))
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100522 break;
523
Willy Tarreau0404bf12023-08-08 17:18:27 +0200524 /* RFC 9114 10.3 Intermediary-Encapsulation Attacks
525 *
526 * While most values that can be encoded will not alter field
527 * parsing, carriage return (ASCII 0x0d), line feed (ASCII 0x0a),
528 * and the null character (ASCII 0x00) might be exploited by an
529 * attacker if they are translated verbatim. Any request or
530 * response that contains a character not permitted in a field
531 * value MUST be treated as malformed
532 */
533
534 /* look for forbidden control characters in the pseudo-header value */
535 ctl = ist_find_ctl(list[hdr_idx].v);
536 if (unlikely(ctl) && http_header_has_forbidden_char(list[hdr_idx].v, ctl)) {
537 TRACE_ERROR("control character present in pseudo-header value", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
538 h3s->err = H3_MESSAGE_ERROR;
539 len = -1;
540 goto out;
541 }
542
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100543 /* pseudo-header. Malformed name with uppercase character or
544 * invalid token will be rejected in the else clause.
545 */
546 if (isteq(list[hdr_idx].n, ist(":method"))) {
547 if (isttest(meth)) {
548 TRACE_ERROR("duplicated method pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100549 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100550 len = -1;
551 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100552 }
553 meth = list[hdr_idx].v;
554 }
555 else if (isteq(list[hdr_idx].n, ist(":path"))) {
556 if (isttest(path)) {
557 TRACE_ERROR("duplicated path pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100558 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100559 len = -1;
560 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100561 }
Willy Tarreau96dfea82023-08-08 17:54:26 +0200562
563 if (!relaxed) {
564 /* we need to reject any control chars or '#' from the path,
565 * unless option accept-invalid-http-request is set.
566 */
567 ctl = ist_find_range(list[hdr_idx].v, 0, '#');
568 if (unlikely(ctl) && http_path_has_forbidden_char(list[hdr_idx].v, ctl)) {
569 TRACE_ERROR("forbidden character in ':path' pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
570 h3s->err = H3_MESSAGE_ERROR;
571 len = -1;
572 goto out;
573 }
574 }
575
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100576 path = list[hdr_idx].v;
577 }
578 else if (isteq(list[hdr_idx].n, ist(":scheme"))) {
579 if (isttest(scheme)) {
580 /* duplicated pseudo-header */
581 TRACE_ERROR("duplicated scheme pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100582 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100583 len = -1;
584 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100585 }
586 scheme = list[hdr_idx].v;
587 }
588 else if (isteq(list[hdr_idx].n, ist(":authority"))) {
589 if (isttest(authority)) {
590 TRACE_ERROR("duplicated authority pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100591 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100592 len = -1;
593 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100594 }
Amaury Denoyellea514a112023-10-09 16:14:44 +0200595
596 if (h3_set_authority(qcs, &authority, list[hdr_idx].v)) {
597 h3s->err = H3_MESSAGE_ERROR;
598 len = -1;
599 goto out;
600 }
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100601 }
602 else {
603 TRACE_ERROR("unknown pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100604 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100605 len = -1;
606 goto out;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100607 }
608
609 ++hdr_idx;
610 }
611
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100612 if (!istmatch(meth, ist("CONNECT"))) {
613 /* RFC 9114 4.3.1. Request Pseudo-Header Fields
614 *
615 * All HTTP/3 requests MUST include exactly one value for the :method,
616 * :scheme, and :path pseudo-header fields, unless the request is a
617 * CONNECT request; see Section 4.4.
618 */
619 if (!isttest(meth) || !isttest(scheme) || !isttest(path)) {
620 TRACE_ERROR("missing mandatory pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100621 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100622 len = -1;
623 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100624 }
625 }
626
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100627 flags |= HTX_SL_F_VER_11;
Amaury Denoyelle0fa14a62022-04-26 16:24:39 +0200628 flags |= HTX_SL_F_XFER_LEN;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100629
630 sl = htx_add_stline(htx, HTX_BLK_REQ_SL, flags, meth, path, ist("HTTP/3.0"));
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200631 if (!sl) {
632 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100633 len = -1;
634 goto out;
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200635 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100636
637 if (fin)
638 sl->flags |= HTX_SL_F_BODYLESS;
639
640 sl->info.req.meth = find_http_meth(meth.ptr, meth.len);
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100641
Amaury Denoyellec4913f62022-12-15 10:58:05 +0100642 if (isttest(authority)) {
643 if (!htx_add_header(htx, ist("host"), authority)) {
644 h3c->err = H3_INTERNAL_ERROR;
645 len = -1;
646 goto out;
647 }
648 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100649
650 /* now treat standard headers */
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100651 while (1) {
652 if (isteq(list[hdr_idx].n, ist("")))
653 break;
654
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100655 if (istmatch(list[hdr_idx].n, ist(":"))) {
656 TRACE_ERROR("pseudo-header field after fields", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100657 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100658 len = -1;
659 goto out;
Amaury Denoyelle7b5a6712022-12-07 14:33:26 +0100660 }
661
Amaury Denoyelled6fb7a02022-12-07 14:31:42 +0100662 for (i = 0; i < list[hdr_idx].n.len; ++i) {
663 const char c = list[hdr_idx].n.ptr[i];
664 if ((uint8_t)(c - 'A') < 'Z' - 'A' || !HTTP_IS_TOKEN(c)) {
665 TRACE_ERROR("invalid characters in field name", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100666 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100667 len = -1;
668 goto out;
Amaury Denoyelled6fb7a02022-12-07 14:31:42 +0100669 }
670 }
671
Willy Tarreau0404bf12023-08-08 17:18:27 +0200672
673 /* RFC 9114 10.3 Intermediary-Encapsulation Attacks
674 *
675 * While most values that can be encoded will not alter field
676 * parsing, carriage return (ASCII 0x0d), line feed (ASCII 0x0a),
677 * and the null character (ASCII 0x00) might be exploited by an
678 * attacker if they are translated verbatim. Any request or
679 * response that contains a character not permitted in a field
680 * value MUST be treated as malformed
681 */
682
683 /* look for forbidden control characters in the header value */
684 ctl = ist_find_ctl(list[hdr_idx].v);
685 if (unlikely(ctl) && http_header_has_forbidden_char(list[hdr_idx].v, ctl)) {
686 TRACE_ERROR("control character present in header value", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
687 h3s->err = H3_MESSAGE_ERROR;
688 len = -1;
689 goto out;
690 }
691
Amaury Denoyellea514a112023-10-09 16:14:44 +0200692 if (isteq(list[hdr_idx].n, ist("host"))) {
693 if (h3_set_authority(qcs, &authority, list[hdr_idx].v)) {
694 h3s->err = H3_MESSAGE_ERROR;
695 len = -1;
696 goto out;
697 }
698 }
699 else if (isteq(list[hdr_idx].n, ist("cookie"))) {
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200700 http_cookie_register(list, hdr_idx, &cookie, &last_cookie);
Amaury Denoyelle19942e32022-12-15 09:18:25 +0100701 ++hdr_idx;
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200702 continue;
703 }
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100704 else if (isteq(list[hdr_idx].n, ist("content-length"))) {
705 ret = http_parse_cont_len_header(&list[hdr_idx].v,
706 &h3s->body_len,
707 h3s->flags & H3_SF_HAVE_CLEN);
708 if (ret < 0) {
709 TRACE_ERROR("invalid content-length", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +0100710 h3s->err = H3_MESSAGE_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100711 len = -1;
712 goto out;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100713 }
714 else if (!ret) {
715 /* Skip duplicated value. */
716 ++hdr_idx;
717 continue;
718 }
719
720 h3s->flags |= H3_SF_HAVE_CLEN;
Christopher Faulet87230d32023-07-24 11:37:10 +0200721 sl->flags |= HTX_SL_F_CLEN;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100722 /* This will fail if current frame is the last one and
723 * content-length is not null.
724 */
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100725 if (h3_check_body_size(qcs, fin)) {
726 len = -1;
727 goto out;
728 }
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +0100729 }
Amaury Denoyelle8ad26692023-01-17 17:47:06 +0100730 else if (isteq(list[hdr_idx].n, ist("connection")) ||
731 isteq(list[hdr_idx].n, ist("proxy-connection")) ||
732 isteq(list[hdr_idx].n, ist("keep-alive")) ||
733 isteq(list[hdr_idx].n, ist("transfer-encoding"))) {
734 /* RFC 9114 4.2. HTTP Fields
735 *
736 * HTTP/3 does not use the Connection header field to indicate
737 * connection-specific fields; in this protocol, connection-
738 * specific metadata is conveyed by other means. An endpoint
739 * MUST NOT generate an HTTP/3 field section containing
740 * connection-specific fields; any message containing
741 * connection-specific fields MUST be treated as malformed.
742 */
743 TRACE_ERROR("invalid connection header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
744 h3s->err = H3_MESSAGE_ERROR;
745 len = -1;
746 goto out;
747 }
748 else if (isteq(list[hdr_idx].n, ist("te")) &&
749 !isteq(list[hdr_idx].v, ist("trailers"))) {
750 /* RFC 9114 4.2. HTTP Fields
751 *
752 * The only exception to this is the TE header field, which MAY
753 * be present in an HTTP/3 request header; when it is, it MUST
754 * NOT contain any value other than "trailers".
755 */
756 TRACE_ERROR("invalid te header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
757 h3s->err = H3_MESSAGE_ERROR;
758 len = -1;
759 goto out;
760 }
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200761
Amaury Denoyellec4913f62022-12-15 10:58:05 +0100762 if (!htx_add_header(htx, list[hdr_idx].n, list[hdr_idx].v)) {
763 h3c->err = H3_INTERNAL_ERROR;
764 len = -1;
765 goto out;
766 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100767 ++hdr_idx;
768 }
769
Amaury Denoyellea514a112023-10-09 16:14:44 +0200770 /* RFC 9114 4.3.1. Request Pseudo-Header Fields
771 *
772 * If the :scheme pseudo-header field identifies a scheme that has a
773 * mandatory authority component (including "http" and "https"), the
774 * request MUST contain either an :authority pseudo-header field or a
775 * Host header field.
776 */
777 if (!isttest(authority)) {
778 TRACE_ERROR("missing mandatory pseudo-header", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
779 h3s->err = H3_MESSAGE_ERROR;
780 len = -1;
781 goto out;
782 }
783
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200784 if (cookie >= 0) {
785 if (http_cookie_merge(htx, list, cookie)) {
786 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100787 len = -1;
788 goto out;
Amaury Denoyelle115ccce2022-08-17 18:02:47 +0200789 }
790 }
791
Amaury Denoyellec4913f62022-12-15 10:58:05 +0100792 if (!htx_add_endof(htx, HTX_BLK_EOH)) {
793 h3c->err = H3_INTERNAL_ERROR;
794 len = -1;
795 goto out;
796 }
797
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100798 if (fin)
799 htx->flags |= HTX_FL_EOM;
800
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100801 htx_to_buf(htx, &htx_buf);
802 htx = NULL;
803
Amaury Denoyelled68f8b52023-05-30 15:04:46 +0200804 if (!qcs_attach_sc(qcs, &htx_buf, fin)) {
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200805 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100806 len = -1;
807 goto out;
Amaury Denoyelle2bc47862022-06-30 10:04:42 +0200808 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100809
Amaury Denoyelle114c9c82022-03-28 14:53:45 +0200810 /* RFC 9114 5.2. Connection Shutdown
811 *
812 * The GOAWAY frame contains an identifier that
813 * indicates to the receiver the range of requests or pushes that were
814 * or might be processed in this connection. The server sends a client-
815 * initiated bidirectional stream ID; the client sends a push ID.
816 * Requests or pushes with the indicated identifier or greater are
817 * rejected (Section 4.1.1) by the sender of the GOAWAY. This
818 * identifier MAY be zero if no requests or pushes were processed.
819 */
820 if (qcs->id >= h3c->id_goaway)
821 h3c->id_goaway = qcs->id + 4;
822
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100823 out:
824 /* HTX may be non NULL if error before previous htx_to_buf(). */
825 if (htx)
826 htx_to_buf(htx, &htx_buf);
827
Willy Tarreau4596fe22022-05-17 19:07:51 +0200828 /* buffer is transferred to the stream connector and set to NULL
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100829 * except on stream creation error.
830 */
Amaury Denoyelle788fc052022-12-15 10:53:55 +0100831 if (b_size(&htx_buf)) {
832 b_free(&htx_buf);
833 offer_buffers(NULL, 1);
834 }
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100835
Amaury Denoyelle494512d2022-05-30 15:50:34 +0200836 TRACE_LEAVE(H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle314578a2022-04-27 14:52:52 +0200837 return len;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +0100838}
839
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100840/* Parse from buffer <buf> a H3 HEADERS frame of length <len> used as trailers.
841 * Data are copied in a local HTX buffer and transfer to the stream connector
842 * layer. <fin> must be set if this is the last data to transfer from this
843 * stream.
844 *
845 * Returns the number of consumed bytes or a negative error code. On error
846 * either the connection should be closed or the stream reset using codes
847 * provided in h3c.err / h3s.err.
848 */
849static ssize_t h3_trailers_to_htx(struct qcs *qcs, const struct buffer *buf,
850 uint64_t len, char fin)
851{
852 struct h3s *h3s = qcs->ctx;
853 struct h3c *h3c = h3s->h3c;
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100854 struct buffer *tmp = get_trash_chunk();
Amaury Denoyelle29058f72023-11-28 15:59:38 +0100855 struct buffer *appbuf = NULL;
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100856 struct htx *htx = NULL;
857 struct htx_sl *sl;
858 struct http_hdr list[global.tune.max_http_hdr];
859 int hdr_idx, ret;
Willy Tarreau0404bf12023-08-08 17:18:27 +0200860 const char *ctl;
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100861 int i;
862
863 TRACE_ENTER(H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
864
865 /* TODO support buffer wrapping */
866 BUG_ON(b_head(buf) + len >= b_wrap(buf));
867 ret = qpack_decode_fs((const unsigned char *)b_head(buf), len, tmp,
868 list, sizeof(list) / sizeof(list[0]));
869 if (ret < 0) {
870 TRACE_ERROR("QPACK decoding error", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
871 h3c->err = -ret;
872 len = -1;
873 goto out;
874 }
875
Amaury Denoyelle29058f72023-11-28 15:59:38 +0100876 if (!(appbuf = qcs_get_buf(qcs, &qcs->rx.app_buf))) {
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +0200877 TRACE_ERROR("HTX buffer alloc failure", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
878 h3c->err = H3_INTERNAL_ERROR;
879 len = -1;
880 goto out;
881 }
Amaury Denoyelle29058f72023-11-28 15:59:38 +0100882 BUG_ON(!b_size(appbuf)); /* TODO */
883 htx = htx_from_buf(appbuf);
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100884
885 if (!h3s->data_len) {
886 /* Notify that no body is present. This can only happens if
887 * there is H3 HEADERS as trailers without or empty H3 DATA
888 * frame. So this is probably not realistice ?
889 *
890 * TODO if sl is NULL because already consumed there is no way
891 * to notify about missing body.
892 */
893 sl = http_get_stline(htx);
894 if (sl)
895 sl->flags |= HTX_SL_F_BODYLESS;
896 else
897 TRACE_ERROR("cannot notify missing body after trailers", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
898 }
899
900 hdr_idx = 0;
901 while (1) {
902 if (isteq(list[hdr_idx].n, ist("")))
903 break;
904
905 /* RFC 9114 4.3. HTTP Control Data
906 *
907 * Pseudo-header
908 * fields MUST NOT appear in trailer sections.
909 */
910 if (istmatch(list[hdr_idx].n, ist(":"))) {
911 TRACE_ERROR("pseudo-header field in trailers", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
912 h3s->err = H3_MESSAGE_ERROR;
913 len = -1;
914 goto out;
915 }
916
917 for (i = 0; i < list[hdr_idx].n.len; ++i) {
918 const char c = list[hdr_idx].n.ptr[i];
919 if ((uint8_t)(c - 'A') < 'Z' - 'A' || !HTTP_IS_TOKEN(c)) {
920 TRACE_ERROR("invalid characters in field name", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
921 h3s->err = H3_MESSAGE_ERROR;
922 len = -1;
923 goto out;
924 }
925 }
926
927 /* forbidden HTTP/3 headers, cf h3_headers_to_htx() */
928 if (isteq(list[hdr_idx].n, ist("host")) ||
929 isteq(list[hdr_idx].n, ist("content-length")) ||
930 isteq(list[hdr_idx].n, ist("connection")) ||
931 isteq(list[hdr_idx].n, ist("proxy-connection")) ||
932 isteq(list[hdr_idx].n, ist("keep-alive")) ||
933 isteq(list[hdr_idx].n, ist("te")) ||
934 isteq(list[hdr_idx].n, ist("transfer-encoding"))) {
935 TRACE_ERROR("forbidden HTTP/3 headers", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
936 h3s->err = H3_MESSAGE_ERROR;
937 len = -1;
938 goto out;
939 }
940
Willy Tarreau0404bf12023-08-08 17:18:27 +0200941 /* RFC 9114 10.3 Intermediary-Encapsulation Attacks
942 *
943 * While most values that can be encoded will not alter field
944 * parsing, carriage return (ASCII 0x0d), line feed (ASCII 0x0a),
945 * and the null character (ASCII 0x00) might be exploited by an
946 * attacker if they are translated verbatim. Any request or
947 * response that contains a character not permitted in a field
948 * value MUST be treated as malformed
949 */
950
951 /* look for forbidden control characters in the trailer value */
952 ctl = ist_find_ctl(list[hdr_idx].v);
953 if (unlikely(ctl) && http_header_has_forbidden_char(list[hdr_idx].v, ctl)) {
954 TRACE_ERROR("control character present in trailer value", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
955 h3s->err = H3_MESSAGE_ERROR;
956 len = -1;
957 goto out;
958 }
959
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100960 if (!htx_add_trailer(htx, list[hdr_idx].n, list[hdr_idx].v)) {
961 TRACE_ERROR("cannot add trailer", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
962 h3c->err = H3_INTERNAL_ERROR;
963 len = -1;
964 goto out;
965 }
966
967 ++hdr_idx;
968 }
969
970 if (!htx_add_endof(htx, HTX_BLK_EOT)) {
971 TRACE_ERROR("cannot add trailer", H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
972 h3c->err = H3_INTERNAL_ERROR;
973 len = -1;
974 goto out;
975 }
976
977 if (fin)
978 htx->flags |= HTX_FL_EOM;
979
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100980 out:
981 /* HTX may be non NULL if error before previous htx_to_buf(). */
Amaury Denoyelle29058f72023-11-28 15:59:38 +0100982 if (appbuf)
983 htx_to_buf(htx, appbuf);
Amaury Denoyelleedfcb552023-01-13 16:40:31 +0100984
985 TRACE_LEAVE(H3_EV_RX_FRAME|H3_EV_RX_HDR, qcs->qcc->conn, qcs);
986 return len;
987}
988
Amaury Denoyelle91379f72022-02-14 17:14:59 +0100989/* Copy from buffer <buf> a H3 DATA frame of length <len> in QUIC stream <qcs>
990 * HTX buffer. <fin> must be set if this is the last data to transfer from this
991 * stream.
992 *
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200993 * Returns the number of consumed bytes or a negative error code.
Amaury Denoyelle91379f72022-02-14 17:14:59 +0100994 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +0200995static ssize_t h3_data_to_htx(struct qcs *qcs, const struct buffer *buf,
996 uint64_t len, char fin)
Amaury Denoyelle91379f72022-02-14 17:14:59 +0100997{
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +0200998 struct h3s *h3s = qcs->ctx;
999 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001000 struct buffer *appbuf;
1001 struct htx *htx = NULL;
Amaury Denoyelle1290f1e2022-05-13 14:49:05 +02001002 size_t htx_sent = 0;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001003 int htx_space;
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001004 char *head;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001005
Amaury Denoyelle494512d2022-05-30 15:50:34 +02001006 TRACE_ENTER(H3_EV_RX_FRAME|H3_EV_RX_DATA, qcs->qcc->conn, qcs);
1007
Amaury Denoyelled68f8b52023-05-30 15:04:46 +02001008 if (!(appbuf = qcs_get_buf(qcs, &qcs->rx.app_buf))) {
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +02001009 TRACE_ERROR("data buffer alloc failure", H3_EV_RX_FRAME|H3_EV_RX_DATA, qcs->qcc->conn, qcs);
1010 h3c->err = H3_INTERNAL_ERROR;
1011 len = -1;
1012 goto out;
1013 }
1014
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001015 htx = htx_from_buf(appbuf);
1016
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001017 if (len > b_data(buf)) {
1018 len = b_data(buf);
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001019 fin = 0;
1020 }
1021
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001022 head = b_head(buf);
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001023 retry:
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001024 htx_space = htx_free_data_space(htx);
Amaury Denoyellef1fc0b32022-05-02 11:07:06 +02001025 if (!htx_space) {
1026 qcs->flags |= QC_SF_DEM_FULL;
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001027 goto out;
Amaury Denoyellef1fc0b32022-05-02 11:07:06 +02001028 }
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001029
1030 if (len > htx_space) {
1031 len = htx_space;
1032 fin = 0;
Amaury Denoyelleff191de2022-02-21 18:38:29 +01001033 }
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001034
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001035 if (head + len > b_wrap(buf)) {
1036 size_t contig = b_wrap(buf) - head;
1037 htx_sent = htx_add_data(htx, ist2(b_head(buf), contig));
Amaury Denoyelle73d6ffe2022-05-16 13:54:31 +02001038 if (htx_sent < contig) {
1039 qcs->flags |= QC_SF_DEM_FULL;
1040 goto out;
1041 }
1042
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001043 len -= contig;
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001044 head = b_orig(buf);
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001045 goto retry;
Amaury Denoyelleff191de2022-02-21 18:38:29 +01001046 }
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001047
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001048 htx_sent += htx_add_data(htx, ist2(head, len));
Amaury Denoyelle73d6ffe2022-05-16 13:54:31 +02001049 if (htx_sent < len) {
1050 qcs->flags |= QC_SF_DEM_FULL;
1051 goto out;
1052 }
Amaury Denoyelle30f23f52022-04-27 14:41:53 +02001053
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001054 if (fin && len == htx_sent)
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001055 htx->flags |= HTX_FL_EOM;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001056
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001057 out:
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +02001058 if (appbuf)
1059 htx_to_buf(htx, appbuf);
Amaury Denoyelle494512d2022-05-30 15:50:34 +02001060
1061 TRACE_LEAVE(H3_EV_RX_FRAME|H3_EV_RX_DATA, qcs->qcc->conn, qcs);
Amaury Denoyelle314578a2022-04-27 14:52:52 +02001062 return htx_sent;
Amaury Denoyelle91379f72022-02-14 17:14:59 +01001063}
1064
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001065/* Parse a SETTINGS frame of length <len> of payload <buf>.
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001066 *
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001067 * Returns the number of consumed bytes or a negative error code.
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001068 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001069static ssize_t h3_parse_settings_frm(struct h3c *h3c, const struct buffer *buf,
1070 size_t len)
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001071{
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001072 struct buffer b;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001073 uint64_t id, value;
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001074 size_t ret = 0;
1075 long mask = 0; /* used to detect duplicated settings identifier */
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001076
Amaury Denoyelle494512d2022-05-30 15:50:34 +02001077 TRACE_ENTER(H3_EV_RX_FRAME|H3_EV_RX_SETTINGS, h3c->qcc->conn);
1078
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001079 /* Work on a copy of <buf>. */
Amaury Denoyelle3a2fcfd2022-06-09 11:54:38 +02001080 b = b_make(b_orig(buf), b_size(buf), b_head_ofs(buf), len);
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001081
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001082 while (b_data(&b)) {
1083 if (!b_quic_dec_int(&id, &b, &ret) || !b_quic_dec_int(&value, &b, &ret)) {
1084 h3c->err = H3_FRAME_ERROR;
1085 return -1;
1086 }
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001087
1088 h3_debug_printf(stderr, "%s id: %llu value: %llu\n",
1089 __func__, (unsigned long long)id, (unsigned long long)value);
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001090
1091 /* draft-ietf-quic-http34 7.2.4. SETTINGS
1092 *
1093 * The same setting identifier MUST NOT occur more than once in the
1094 * SETTINGS frame. A receiver MAY treat the presence of duplicate
1095 * setting identifiers as a connection error of type H3_SETTINGS_ERROR.
1096 */
1097
1098 /* Ignore duplicate check for ID too big used for GREASE. */
1099 if (id < sizeof(mask)) {
1100 if (ha_bit_test(id, &mask)) {
1101 h3c->err = H3_SETTINGS_ERROR;
1102 return -1;
1103 }
1104 ha_bit_set(id, &mask);
1105 }
1106
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001107 switch (id) {
1108 case H3_SETTINGS_QPACK_MAX_TABLE_CAPACITY:
1109 h3c->qpack_max_table_capacity = value;
1110 break;
1111 case H3_SETTINGS_MAX_FIELD_SECTION_SIZE:
1112 h3c->max_field_section_size = value;
1113 break;
1114 case H3_SETTINGS_QPACK_BLOCKED_STREAMS:
1115 h3c->qpack_blocked_streams = value;
1116 break;
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001117
1118 case H3_SETTINGS_RESERVED_0:
1119 case H3_SETTINGS_RESERVED_2:
1120 case H3_SETTINGS_RESERVED_3:
1121 case H3_SETTINGS_RESERVED_4:
1122 case H3_SETTINGS_RESERVED_5:
1123 /* draft-ietf-quic-http34 7.2.4.1. Defined SETTINGS Parameters
1124 *
1125 * Setting identifiers which were defined in [HTTP2] where there is no
1126 * corresponding HTTP/3 setting have also been reserved
1127 * (Section 11.2.2). These reserved settings MUST NOT be sent, and
1128 * their receipt MUST be treated as a connection error of type
1129 * H3_SETTINGS_ERROR.
1130 */
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001131 h3c->err = H3_SETTINGS_ERROR;
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001132 return -1;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001133 default:
1134 /* MUST be ignored */
1135 break;
1136 }
1137 }
1138
Frédéric Lécaillebefcf702022-09-08 16:04:55 +02001139 TRACE_LEAVE(H3_EV_RX_FRAME|H3_EV_RX_SETTINGS, h3c->qcc->conn);
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001140 return ret;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001141}
1142
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +01001143/* Decode <qcs> remotely initiated bidi-stream. <fin> must be set to indicate
1144 * that we received the last data of the stream.
Amaury Denoyelle0ffd6e72022-05-24 11:07:28 +02001145 *
1146 * Returns 0 on success else non-zero.
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +01001147 */
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001148static ssize_t h3_decode_qcs(struct qcs *qcs, struct buffer *b, int fin)
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +01001149{
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001150 struct h3s *h3s = qcs->ctx;
Amaury Denoyellec0156792022-06-03 15:29:07 +02001151 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001152 ssize_t total = 0, ret;
Amaury Denoyelle7b0f1222022-02-14 17:13:55 +01001153
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001154 TRACE_ENTER(H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001155
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001156 if (quic_stream_is_uni(qcs->id) && !(h3s->flags & H3_SF_UNI_INIT)) {
Amaury Denoyelle5aa21c12023-03-09 11:12:32 +01001157 ret = h3_init_uni_stream(h3c, qcs, b);
1158 if (ret < 0) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001159 TRACE_ERROR("cannot initialize uni stream", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1160 goto err;
1161 }
Amaury Denoyelle5aa21c12023-03-09 11:12:32 +01001162 else if (!ret) {
1163 /* not enough data to initialize uni stream, retry later */
1164 goto done;
1165 }
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001166
1167 total += ret;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001168 }
1169
1170 if (quic_stream_is_uni(qcs->id) && (h3s->flags & H3_SF_UNI_NO_H3)) {
1171 /* For non-h3 STREAM, parse it and return immediately. */
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001172 if ((ret = h3_parse_uni_stream_no_h3(qcs, b, fin)) < 0) {
1173 TRACE_ERROR("error when parsing non-HTTP3 uni stream", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1174 goto err;
1175 }
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001176
1177 total += ret;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001178 goto done;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001179 }
1180
Amaury Denoyelle6b02c6b2022-08-16 17:16:47 +02001181 /* RFC 9114 6.2.1. Control Streams
1182 *
1183 * The sender MUST NOT close the control stream, and the receiver MUST NOT
1184 * request that the sender close the control stream. If either control
1185 * stream is closed at any point, this MUST be treated as a connection
1186 * error of type H3_CLOSED_CRITICAL_STREAM.
1187 */
1188 if (h3s->type == H3S_T_CTRL && fin) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001189 TRACE_ERROR("control stream closed by remote peer", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001190 qcc_set_error(qcs->qcc, H3_CLOSED_CRITICAL_STREAM, 1);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001191 goto err;
Amaury Denoyelle6b02c6b2022-08-16 17:16:47 +02001192 }
1193
Amaury Denoyelle381d8132023-02-17 09:51:20 +01001194 if (!b_data(b) && fin && quic_stream_is_bidi(qcs->id)) {
Amaury Denoyelle93dd23c2023-05-11 16:49:28 +02001195 struct buffer *appbuf;
1196 struct htx *htx;
1197
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001198 TRACE_PROTO("received FIN without data", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelled68f8b52023-05-30 15:04:46 +02001199 if (!(appbuf = qcs_get_buf(qcs, &qcs->rx.app_buf))) {
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +02001200 TRACE_ERROR("data buffer alloc failure", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1201 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle6133aba2023-05-15 09:35:59 +02001202 goto err;
Amaury Denoyelle0abde9d2023-05-11 16:52:17 +02001203 }
Amaury Denoyelle93dd23c2023-05-11 16:49:28 +02001204
1205 htx = htx_from_buf(appbuf);
1206 if (!htx_set_eom(htx)) {
1207 TRACE_ERROR("cannot set EOM", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1208 h3c->err = H3_INTERNAL_ERROR;
1209 }
1210 htx_to_buf(htx, appbuf);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001211 goto done;
Amaury Denoyelle381d8132023-02-17 09:51:20 +01001212 }
1213
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001214 while (b_data(b) && !(qcs->flags & QC_SF_DEM_FULL) && !h3c->err && !h3s->err) {
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001215 uint64_t ftype, flen;
Amaury Denoyelle95b93a32022-02-14 15:49:53 +01001216 char last_stream_frame = 0;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001217
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001218 if (!h3s->demux_frame_len) {
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001219 /* Switch to a new frame. */
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001220 size_t hlen = h3_decode_frm_header(&ftype, &flen, b);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001221 if (!hlen) {
1222 TRACE_PROTO("pause parsing on incomplete frame header", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001223 break;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001224 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001225
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001226 h3s->demux_frame_type = ftype;
1227 h3s->demux_frame_len = flen;
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001228 total += hlen;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001229 TRACE_PROTO("parsing a new frame", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle417c7c02022-05-31 14:18:33 +02001230
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001231 /* Check that content-length is not exceeded on a new DATA frame. */
1232 if (ftype == H3_FT_DATA) {
1233 h3s->data_len += flen;
Christopher Faulet3809fe92023-07-28 09:33:29 +02001234 if (h3s->flags & H3_SF_HAVE_CLEN && h3_check_body_size(qcs, (fin && flen == b_data(b))))
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001235 break;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001236 }
1237
Amaury Denoyelle417c7c02022-05-31 14:18:33 +02001238 if (!h3_is_frame_valid(h3c, qcs, ftype)) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001239 TRACE_ERROR("received an invalid frame", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001240 qcc_set_error(qcs->qcc, H3_FRAME_UNEXPECTED, 1);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001241 goto err;
Amaury Denoyelle417c7c02022-05-31 14:18:33 +02001242 }
1243
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001244 if (!b_data(b))
Amaury Denoyelle417c7c02022-05-31 14:18:33 +02001245 break;
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001246 }
Amaury Denoyelle0484f922022-02-15 16:59:39 +01001247
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001248 flen = h3s->demux_frame_len;
1249 ftype = h3s->demux_frame_type;
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001250
1251 /* Do not demux incomplete frames except H3 DATA which can be
1252 * fragmented in multiple HTX blocks.
1253 */
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001254 if (flen > b_data(b) && ftype != H3_FT_DATA) {
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001255 /* Reject frames bigger than bufsize.
1256 *
1257 * TODO HEADERS should in complement be limited with H3
1258 * SETTINGS_MAX_FIELD_SECTION_SIZE parameter to prevent
1259 * excessive decompressed size.
1260 */
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001261 if (flen > QC_S_RX_BUF_SZ) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001262 TRACE_ERROR("received a too big frame", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001263 qcc_set_error(qcs->qcc, H3_EXCESSIVE_LOAD, 1);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001264 goto err;
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001265 }
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001266 break;
Amaury Denoyelleb5454d42022-05-12 16:56:16 +02001267 }
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001268
Christopher Faulet3809fe92023-07-28 09:33:29 +02001269 last_stream_frame = (fin && flen == b_data(b));
1270
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001271 /* Check content-length equality with DATA frames length on the last frame. */
Christopher Faulet3809fe92023-07-28 09:33:29 +02001272 if (last_stream_frame && h3s->flags & H3_SF_HAVE_CLEN && h3_check_body_size(qcs, last_stream_frame))
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001273 break;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001274
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02001275 h3_inc_frame_type_cnt(h3c->prx_counters, ftype);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001276 switch (ftype) {
1277 case H3_FT_DATA:
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001278 ret = h3_data_to_htx(qcs, b, flen, last_stream_frame);
Amaury Denoyelle8d818c62022-08-02 11:32:45 +02001279 h3s->st_req = H3S_ST_REQ_DATA;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001280 break;
1281 case H3_FT_HEADERS:
Amaury Denoyelleedfcb552023-01-13 16:40:31 +01001282 if (h3s->st_req == H3S_ST_REQ_BEFORE) {
1283 ret = h3_headers_to_htx(qcs, b, flen, last_stream_frame);
1284 h3s->st_req = H3S_ST_REQ_HEADERS;
1285 }
1286 else {
1287 ret = h3_trailers_to_htx(qcs, b, flen, last_stream_frame);
1288 h3s->st_req = H3S_ST_REQ_TRAILERS;
1289 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001290 break;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001291 case H3_FT_CANCEL_PUSH:
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001292 case H3_FT_PUSH_PROMISE:
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001293 case H3_FT_MAX_PUSH_ID:
1294 case H3_FT_GOAWAY:
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001295 /* Not supported */
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001296 ret = flen;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001297 break;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001298 case H3_FT_SETTINGS:
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001299 ret = h3_parse_settings_frm(qcs->qcc->ctx, b, flen);
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001300 if (ret < 0) {
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001301 TRACE_ERROR("error on SETTINGS parsing", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001302 qcc_set_error(qcs->qcc, h3c->err, 1);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001303 goto err;
Amaury Denoyelle8c6176b2022-05-24 18:16:49 +02001304 }
1305 h3c->flags |= H3_CF_SETTINGS_RECV;
Amaury Denoyellef8db5aa2022-05-24 15:26:07 +02001306 break;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001307 default:
Amaury Denoyelled1acaf92021-11-15 15:52:55 +01001308 /* draft-ietf-quic-http34 9. Extensions to HTTP/3
Amaury Denoyelle302ecd42022-05-24 15:24:32 +02001309 *
1310 * Implementations MUST discard frames [...] that have unknown
1311 * or unsupported types.
Amaury Denoyelled1acaf92021-11-15 15:52:55 +01001312 */
Amaury Denoyelle80097cc2022-05-24 11:13:46 +02001313 ret = flen;
1314 break;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001315 }
Amaury Denoyelle314578a2022-04-27 14:52:52 +02001316
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001317 if (ret > 0) {
Amaury Denoyelle291ee252022-05-02 10:35:39 +02001318 BUG_ON(h3s->demux_frame_len < ret);
1319 h3s->demux_frame_len -= ret;
Amaury Denoyelle62eef852022-06-03 16:40:34 +02001320 b_del(b, ret);
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001321 total += ret;
Amaury Denoyelle291ee252022-05-02 10:35:39 +02001322 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001323 }
1324
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001325 /* Reset demux frame type for traces. */
1326 if (!h3s->demux_frame_len)
1327 h3s->demux_frame_type = H3_FT_UNINIT;
1328
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001329 /* Interrupt decoding on stream/connection error detected. */
1330 if (h3s->err) {
1331 qcc_abort_stream_read(qcs);
1332 qcc_reset_stream(qcs, h3s->err);
1333 return b_data(b);
1334 }
1335 else if (h3c->err) {
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001336 qcc_set_error(qcs->qcc, h3c->err, 1);
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001337 return b_data(b);
1338 }
1339
Amaury Denoyelle03cc62c2022-04-27 16:53:16 +02001340 /* TODO may be useful to wakeup the MUX if blocked due to full buffer.
1341 * However, currently, io-cb of MUX does not handle Rx.
1342 */
1343
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001344 done:
1345 TRACE_LEAVE(H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
Amaury Denoyelle1f21ebd2022-06-07 17:30:55 +02001346 return total;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001347
1348 err:
1349 TRACE_DEVEL("leaving on error", H3_EV_RX_FRAME, qcs->qcc->conn, qcs);
1350 return -1;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001351}
1352
Amaury Denoyellea5871362021-10-07 16:26:12 +02001353/* Returns buffer for data sending.
1354 * May be NULL if the allocation failed.
1355 */
1356static struct buffer *mux_get_buf(struct qcs *qcs)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001357{
Amaury Denoyellea5871362021-10-07 16:26:12 +02001358 if (!b_size(&qcs->tx.buf))
1359 b_alloc(&qcs->tx.buf);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001360
Amaury Denoyellea5871362021-10-07 16:26:12 +02001361 return &qcs->tx.buf;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001362}
1363
Amaury Denoyelle6b923942022-05-23 14:25:53 +02001364/* Function used to emit stream data from <qcs> control uni-stream */
1365static int h3_control_send(struct qcs *qcs, void *ctx)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001366{
1367 int ret;
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02001368 struct h3c *h3c = ctx;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001369 unsigned char data[(2 + 3) * 2 * QUIC_VARINT_MAX_SIZE]; /* enough for 3 settings */
Amaury Denoyellea5871362021-10-07 16:26:12 +02001370 struct buffer pos, *res;
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001371 size_t frm_len;
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001372
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001373 TRACE_ENTER(H3_EV_TX_SETTINGS, qcs->qcc->conn, qcs);
1374
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001375 BUG_ON_HOT(h3c->flags & H3_CF_SETTINGS_SENT);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001376
1377 ret = 0;
Amaury Denoyellea5871362021-10-07 16:26:12 +02001378 pos = b_make((char *)data, sizeof(data), 0, 0);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001379
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001380 frm_len = quic_int_getsize(H3_SETTINGS_QPACK_MAX_TABLE_CAPACITY) +
1381 quic_int_getsize(h3_settings_qpack_max_table_capacity) +
1382 quic_int_getsize(H3_SETTINGS_QPACK_BLOCKED_STREAMS) +
1383 quic_int_getsize(h3_settings_qpack_blocked_streams);
1384 if (h3_settings_max_field_section_size) {
1385 frm_len += quic_int_getsize(H3_SETTINGS_MAX_FIELD_SECTION_SIZE) +
1386 quic_int_getsize(h3_settings_max_field_section_size);
1387 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001388
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001389 b_quic_enc_int(&pos, H3_UNI_S_T_CTRL, 0);
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001390 /* Build a SETTINGS frame */
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001391 b_quic_enc_int(&pos, H3_FT_SETTINGS, 0);
1392 b_quic_enc_int(&pos, frm_len, 0);
1393 b_quic_enc_int(&pos, H3_SETTINGS_QPACK_MAX_TABLE_CAPACITY, 0);
1394 b_quic_enc_int(&pos, h3_settings_qpack_max_table_capacity, 0);
1395 b_quic_enc_int(&pos, H3_SETTINGS_QPACK_BLOCKED_STREAMS, 0);
1396 b_quic_enc_int(&pos, h3_settings_qpack_blocked_streams, 0);
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001397 if (h3_settings_max_field_section_size) {
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001398 b_quic_enc_int(&pos, H3_SETTINGS_MAX_FIELD_SECTION_SIZE, 0);
1399 b_quic_enc_int(&pos, h3_settings_max_field_section_size, 0);
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001400 }
Amaury Denoyellea5871362021-10-07 16:26:12 +02001401
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001402 res = mux_get_buf(qcs);
1403 if (b_room(res) < b_data(&pos)) {
1404 // TODO the mux should be put in blocked state, with
1405 // the stream in state waiting for settings to be sent
1406 ABORT_NOW();
1407 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001408
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001409 ret = b_force_xfer(res, &pos, b_data(&pos));
Amaury Denoyelle20f2a422023-01-03 14:39:24 +01001410 if (ret > 0) {
1411 /* Register qcs for sending before other streams. */
Amaury Denoyellef9b03262023-01-09 10:34:25 +01001412 qcc_send_stream(qcs, 1);
Amaury Denoyelle65df3ad2022-05-24 15:06:10 +02001413 h3c->flags |= H3_CF_SETTINGS_SENT;
Amaury Denoyelle20f2a422023-01-03 14:39:24 +01001414 }
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001415
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001416 TRACE_LEAVE(H3_EV_TX_SETTINGS, qcs->qcc->conn, qcs);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001417 return ret;
1418}
1419
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001420static int h3_resp_headers_send(struct qcs *qcs, struct htx *htx)
1421{
Amaury Denoyellea7554392023-12-21 17:42:43 +01001422 struct h3s *h3s = qcs->ctx;
1423 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001424 struct buffer outbuf;
1425 struct buffer headers_buf = BUF_NULL;
1426 struct buffer *res;
1427 struct http_hdr list[global.tune.max_http_hdr];
1428 struct htx_sl *sl;
1429 struct htx_blk *blk;
1430 enum htx_blk_type type;
1431 int frame_length_size; /* size in bytes of frame length varint field */
1432 int ret = 0;
1433 int hdr;
1434 int status = 0;
1435
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001436 TRACE_ENTER(H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1437
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001438 sl = NULL;
1439 hdr = 0;
1440 for (blk = htx_get_head_blk(htx); blk; blk = htx_get_next_blk(htx, blk)) {
1441 type = htx_get_blk_type(blk);
1442
1443 if (type == HTX_BLK_UNUSED)
1444 continue;
1445
1446 if (type == HTX_BLK_EOH)
1447 break;
1448
1449 if (type == HTX_BLK_RES_SL) {
1450 /* start-line -> HEADERS h3 frame */
1451 BUG_ON(sl);
1452 sl = htx_get_blk_ptr(htx, blk);
1453 /* TODO should be on h3 layer */
1454 status = sl->info.res.status;
1455 }
1456 else if (type == HTX_BLK_HDR) {
Amaury Denoyellea7554392023-12-21 17:42:43 +01001457 if (unlikely(hdr >= sizeof(list) / sizeof(list[0]) - 1)) {
1458 TRACE_ERROR("too many headers", H3_EV_TX_FRAME|H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1459 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyellefa7fadc2022-06-15 15:52:27 +02001460 goto err;
Amaury Denoyellea7554392023-12-21 17:42:43 +01001461 }
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001462 list[hdr].n = htx_get_blk_name(htx, blk);
1463 list[hdr].v = htx_get_blk_value(htx, blk);
1464 hdr++;
1465 }
1466 else {
1467 ABORT_NOW();
1468 goto err;
1469 }
1470 }
1471
1472 BUG_ON(!sl);
1473
1474 list[hdr].n = ist("");
1475
Amaury Denoyelled3d97c62021-10-05 11:45:58 +02001476 res = mux_get_buf(qcs);
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001477
1478 /* At least 5 bytes to store frame type + length as a varint max size */
1479 if (b_room(res) < 5)
1480 ABORT_NOW();
1481
1482 b_reset(&outbuf);
1483 outbuf = b_make(b_tail(res), b_contig_space(res), 0, 0);
1484 /* Start the headers after frame type + length */
1485 headers_buf = b_make(b_head(res) + 5, b_size(res) - 5, 0, 0);
1486
1487 if (qpack_encode_field_section_line(&headers_buf))
1488 ABORT_NOW();
1489 if (qpack_encode_int_status(&headers_buf, status))
1490 ABORT_NOW();
1491
1492 for (hdr = 0; hdr < sizeof(list) / sizeof(list[0]); ++hdr) {
1493 if (isteq(list[hdr].n, ist("")))
1494 break;
1495
Amaury Denoyelle8ad26692023-01-17 17:47:06 +01001496 /* RFC 9114 4.2. HTTP Fields
1497 *
1498 * An intermediary transforming an HTTP/1.x message to HTTP/3
1499 * MUST remove connection-specific header fields as discussed in
1500 * Section 7.6.1 of [HTTP], or their messages will be treated by
1501 * other HTTP/3 endpoints as malformed.
Amaury Denoyelleffafb3d2022-02-15 16:10:42 +01001502 */
Amaury Denoyelle8ad26692023-01-17 17:47:06 +01001503 if (isteq(list[hdr].n, ist("connection")) ||
1504 isteq(list[hdr].n, ist("proxy-connection")) ||
1505 isteq(list[hdr].n, ist("keep-alive")) ||
1506 isteq(list[hdr].n, ist("transfer-encoding"))) {
Amaury Denoyelleffafb3d2022-02-15 16:10:42 +01001507 continue;
Amaury Denoyelle8ad26692023-01-17 17:47:06 +01001508 }
1509 else if (isteq(list[hdr].n, ist("te"))) {
1510 /* "te" may only be sent with "trailers" if this value
1511 * is present, otherwise it must be deleted.
1512 */
1513 const struct ist v = istist(list[hdr].v, ist("trailers"));
1514 if (!isttest(v) || (v.len > 8 && v.ptr[8] != ','))
1515 continue;
1516 list[hdr].v = ist("trailers");
1517 }
Amaury Denoyelleffafb3d2022-02-15 16:10:42 +01001518
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001519 if (qpack_encode_header(&headers_buf, list[hdr].n, list[hdr].v))
1520 ABORT_NOW();
1521 }
1522
1523 /* Now that all headers are encoded, we are certain that res buffer is
1524 * big enough
1525 */
1526 frame_length_size = quic_int_getsize(b_data(&headers_buf));
1527 res->head += 4 - frame_length_size;
1528 b_putchr(res, 0x01); /* h3 HEADERS frame type */
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001529 if (!b_quic_enc_int(res, b_data(&headers_buf), 0))
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001530 ABORT_NOW();
1531 b_add(res, b_data(&headers_buf));
1532
1533 ret = 0;
1534 blk = htx_get_head_blk(htx);
1535 while (blk) {
1536 type = htx_get_blk_type(blk);
1537 ret += htx_get_blksz(blk);
1538 blk = htx_remove_blk(htx, blk);
1539 if (type == HTX_BLK_EOH)
1540 break;
1541 }
1542
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001543 TRACE_LEAVE(H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001544 return ret;
1545
1546 err:
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001547 TRACE_DEVEL("leaving on error", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001548 return 0;
1549}
1550
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001551/* Convert a series of HTX trailer blocks from <htx> buffer into <qcs> buffer
1552 * as a H3 HEADERS frame. H3 forbidden trailers are skipped. HTX trailer blocks
1553 * are removed from <htx> until EOT is found and itself removed.
1554 *
1555 * If only a EOT HTX block is present without trailer, no H3 frame is produced.
1556 * Caller is responsible to emit an empty QUIC STREAM frame to signal the end
1557 * of the stream.
1558 *
1559 * Returns the size of HTX blocks removed.
1560 */
1561static int h3_resp_trailers_send(struct qcs *qcs, struct htx *htx)
1562{
Amaury Denoyellea7554392023-12-21 17:42:43 +01001563 struct h3s *h3s = qcs->ctx;
1564 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001565 struct buffer headers_buf = BUF_NULL;
1566 struct buffer *res;
1567 struct http_hdr list[global.tune.max_http_hdr];
1568 struct htx_blk *blk;
1569 enum htx_blk_type type;
1570 char *tail;
1571 int ret = 0;
1572 int hdr;
1573
1574 TRACE_ENTER(H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1575
1576 hdr = 0;
1577 for (blk = htx_get_head_blk(htx); blk; blk = htx_get_next_blk(htx, blk)) {
1578 type = htx_get_blk_type(blk);
1579
1580 if (type == HTX_BLK_UNUSED)
1581 continue;
1582
1583 if (type == HTX_BLK_EOT)
1584 break;
1585
1586 if (type == HTX_BLK_TLR) {
Amaury Denoyellea7554392023-12-21 17:42:43 +01001587 if (unlikely(hdr >= sizeof(list) / sizeof(list[0]) - 1)) {
1588 TRACE_ERROR("too many headers", H3_EV_TX_FRAME|H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1589 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001590 goto err;
Amaury Denoyellea7554392023-12-21 17:42:43 +01001591 }
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001592 list[hdr].n = htx_get_blk_name(htx, blk);
1593 list[hdr].v = htx_get_blk_value(htx, blk);
1594 hdr++;
1595 }
1596 else {
1597 TRACE_ERROR("unexpected HTX block", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyellea7554392023-12-21 17:42:43 +01001598 h3c->err = H3_INTERNAL_ERROR;
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001599 goto err;
1600 }
1601 }
1602
Amaury Denoyelle4be54352023-01-26 17:49:21 +01001603 if (!hdr) {
1604 /* No headers encoded here so no need to generate a H3 HEADERS
1605 * frame. Mux will send an empty QUIC STREAM frame with FIN.
1606 */
1607 TRACE_DATA("skipping trailer", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1608 goto end;
1609 }
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001610 list[hdr].n = ist("");
1611
1612 res = mux_get_buf(qcs);
1613
1614 /* At least 9 bytes to store frame type + length as a varint max size */
1615 if (b_room(res) < 9) {
1616 qcs->flags |= QC_SF_BLK_MROOM;
1617 goto err;
1618 }
1619
1620 /* Force buffer realignment as size required to encode headers is unknown. */
1621 if (b_space_wraps(res))
1622 b_slow_realign(res, trash.area, b_data(res));
1623 /* Start the headers after frame type + length */
1624 headers_buf = b_make(b_peek(res, b_data(res) + 9), b_contig_space(res) - 9, 0, 0);
1625
Amaury Denoyelle224ba5c2023-01-26 17:41:58 +01001626 if (qpack_encode_field_section_line(&headers_buf)) {
1627 qcs->flags |= QC_SF_BLK_MROOM;
1628 goto err;
1629 }
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001630
1631 tail = b_tail(&headers_buf);
1632 for (hdr = 0; hdr < sizeof(list) / sizeof(list[0]); ++hdr) {
1633 if (isteq(list[hdr].n, ist("")))
1634 break;
1635
1636 /* forbidden HTTP/3 headers, cf h3_resp_headers_send() */
1637 if (isteq(list[hdr].n, ist("host")) ||
1638 isteq(list[hdr].n, ist("content-length")) ||
1639 isteq(list[hdr].n, ist("connection")) ||
1640 isteq(list[hdr].n, ist("proxy-connection")) ||
1641 isteq(list[hdr].n, ist("keep-alive")) ||
1642 isteq(list[hdr].n, ist("te")) ||
1643 isteq(list[hdr].n, ist("transfer-encoding"))) {
1644 continue;
1645 }
1646
Amaury Denoyelle224ba5c2023-01-26 17:41:58 +01001647 if (qpack_encode_header(&headers_buf, list[hdr].n, list[hdr].v)) {
1648 qcs->flags |= QC_SF_BLK_MROOM;
1649 goto err;
1650 }
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001651 }
1652
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001653 /* Check that at least one header was encoded in buffer. */
Amaury Denoyelle4be54352023-01-26 17:49:21 +01001654 if (b_tail(&headers_buf) == tail) {
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001655 /* No headers encoded here so no need to generate a H3 HEADERS
1656 * frame. Mux will send an empty QUIC STREAM frame with FIN.
1657 */
1658 TRACE_DATA("skipping trailer", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
Amaury Denoyelle4be54352023-01-26 17:49:21 +01001659 goto end;
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001660 }
1661
Amaury Denoyelle4be54352023-01-26 17:49:21 +01001662 /* Now that all headers are encoded, we are certain that res buffer is
1663 * big enough.
1664 */
1665 b_putchr(res, 0x01); /* h3 HEADERS frame type */
1666 if (!b_quic_enc_int(res, b_data(&headers_buf), 8))
1667 ABORT_NOW();
1668 b_add(res, b_data(&headers_buf));
1669
1670 end:
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001671 ret = 0;
1672 blk = htx_get_head_blk(htx);
1673 while (blk) {
1674 type = htx_get_blk_type(blk);
1675 ret += htx_get_blksz(blk);
1676 blk = htx_remove_blk(htx, blk);
1677 if (type == HTX_BLK_EOT)
1678 break;
1679 }
1680
1681 TRACE_LEAVE(H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1682 return ret;
1683
1684 err:
1685 TRACE_DEVEL("leaving on error", H3_EV_TX_HDR, qcs->qcc->conn, qcs);
1686 return 0;
1687}
1688
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001689/* Returns the total of bytes sent. */
Amaury Denoyelle9534e592022-09-19 17:14:27 +02001690static int h3_resp_data_send(struct qcs *qcs, struct htx *htx, size_t count)
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001691{
1692 struct buffer outbuf;
1693 struct buffer *res;
1694 size_t total = 0;
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001695 int bsize, fsize, hsize;
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001696 struct htx_blk *blk;
1697 enum htx_blk_type type;
1698
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001699 TRACE_ENTER(H3_EV_TX_DATA, qcs->qcc->conn, qcs);
1700
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001701 new_frame:
1702 if (!count || htx_is_empty(htx))
1703 goto end;
1704
1705 blk = htx_get_head_blk(htx);
1706 type = htx_get_blk_type(blk);
1707 fsize = bsize = htx_get_blksz(blk);
1708
1709 if (type != HTX_BLK_DATA)
1710 goto end;
1711
Amaury Denoyelled3d97c62021-10-05 11:45:58 +02001712 res = mux_get_buf(qcs);
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001713
1714 if (fsize > count)
1715 fsize = count;
1716
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001717 /* h3 DATA headers : 1-byte frame type + varint frame length */
1718 hsize = 1 + QUIC_VARINT_MAX_SIZE;
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001719
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001720 while (1) {
1721 b_reset(&outbuf);
1722 outbuf = b_make(b_tail(res), b_contig_space(res), 0, 0);
1723 if (b_size(&outbuf) > hsize || !b_space_wraps(res))
1724 break;
1725 b_slow_realign(res, trash.area, b_data(res));
1726 }
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001727
Amaury Denoyelle84ea8dc2021-12-03 14:40:01 +01001728 /* Not enough room for headers and at least one data byte, block the
Willy Tarreau4596fe22022-05-17 19:07:51 +02001729 * stream. It is expected that the stream connector layer will subscribe
1730 * on SEND.
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001731 */
Amaury Denoyelle84ea8dc2021-12-03 14:40:01 +01001732 if (b_size(&outbuf) <= hsize) {
1733 qcs->flags |= QC_SF_BLK_MROOM;
1734 goto end;
1735 }
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001736
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001737 if (b_size(&outbuf) < hsize + fsize)
1738 fsize = b_size(&outbuf) - hsize;
1739 BUG_ON(fsize <= 0);
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001740
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001741 b_putchr(&outbuf, 0x00); /* h3 frame type = DATA */
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001742 b_quic_enc_int(&outbuf, fsize, 0); /* h3 frame length */
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001743
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001744 b_putblk(&outbuf, htx_get_blk_ptr(htx, blk), fsize);
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001745 total += fsize;
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001746 count -= fsize;
1747
1748 if (fsize == bsize)
1749 htx_remove_blk(htx, blk);
1750 else
1751 htx_cut_data_blk(htx, blk, fsize);
1752
Amaury Denoyellea543eb12021-10-06 14:53:13 +02001753 /* commit the buffer */
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001754 b_add(res, b_data(&outbuf));
1755 goto new_frame;
1756
1757 end:
Amaury Denoyellea717eb72022-05-30 15:51:01 +02001758 TRACE_LEAVE(H3_EV_TX_DATA, qcs->qcc->conn, qcs);
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001759 return total;
1760}
1761
Amaury Denoyelle9534e592022-09-19 17:14:27 +02001762static size_t h3_snd_buf(struct qcs *qcs, struct htx *htx, size_t count)
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001763{
Amaury Denoyelledf0ea3f2023-12-22 11:45:54 +01001764 struct h3s *h3s = qcs->ctx;
1765 struct h3c *h3c = h3s->h3c;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001766 size_t total = 0;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001767 enum htx_blk_type btype;
1768 struct htx_blk *blk;
1769 uint32_t bsize;
1770 int32_t idx;
1771 int ret;
1772
Amaury Denoyelled8769d12022-03-25 15:28:33 +01001773 h3_debug_printf(stderr, "%s\n", __func__);
Amaury Denoyelledeed7772021-12-03 11:36:46 +01001774
Amaury Denoyelledf0ea3f2023-12-22 11:45:54 +01001775 while (count && !htx_is_empty(htx) &&
1776 !(qcs->flags & QC_SF_BLK_MROOM) && !h3c->err) {
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001777 idx = htx_get_head(htx);
1778 blk = htx_get_blk(htx, idx);
1779 btype = htx_get_blk_type(blk);
1780 bsize = htx_get_blksz(blk);
1781
1782 /* Not implemented : QUIC on backend side */
1783 BUG_ON(btype == HTX_BLK_REQ_SL);
1784
1785 switch (btype) {
1786 case HTX_BLK_RES_SL:
Amaury Denoyelle15b09612021-08-24 16:20:27 +02001787 /* start-line -> HEADERS h3 frame */
1788 ret = h3_resp_headers_send(qcs, htx);
1789 if (ret > 0) {
1790 total += ret;
1791 count -= ret;
1792 if (ret < bsize)
1793 goto out;
1794 }
1795 break;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001796
1797 case HTX_BLK_DATA:
Amaury Denoyelle9534e592022-09-19 17:14:27 +02001798 ret = h3_resp_data_send(qcs, htx, count);
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001799 if (ret > 0) {
Amaury Denoyelle8e2a9982021-08-24 16:24:37 +02001800 total += ret;
1801 count -= ret;
1802 if (ret < bsize)
1803 goto out;
1804 }
1805 break;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001806
1807 case HTX_BLK_TLR:
1808 case HTX_BLK_EOT:
Amaury Denoyelle4e520102023-01-12 14:53:43 +01001809 ret = h3_resp_trailers_send(qcs, htx);
1810 if (ret > 0) {
1811 total += ret;
1812 count -= ret;
1813 if (ret < bsize)
1814 goto out;
1815 }
1816 break;
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001817
1818 default:
1819 htx_remove_blk(htx, blk);
1820 total += bsize;
1821 count -= bsize;
1822 break;
1823 }
1824 }
1825
Amaury Denoyelledf0ea3f2023-12-22 11:45:54 +01001826 /* Interrupt sending on connection error. */
1827 if (unlikely(h3c->err)) {
1828 qcc_set_error(qcs->qcc, h3c->err, 1);
1829 goto out;
1830 }
1831
Amaury Denoyelle26dfd902021-08-24 16:33:53 +02001832 out:
1833 return total;
Amaury Denoyellef52151d2021-08-24 16:11:18 +02001834}
1835
Amaury Denoyelle1e340ba2023-01-30 12:12:11 +01001836/* Notify about a closure on <qcs> stream requested by the remote peer.
1837 *
1838 * Stream channel <side> is explained relative to our endpoint : WR for
1839 * STOP_SENDING or RD for RESET_STREAM reception. Callback decode_qcs() is used
1840 * instead for closure performed using a STREAM frame with FIN bit.
1841 *
1842 * The main objective of this function is to check if closure is valid
1843 * according to HTTP/3 specification.
1844 *
1845 * Returns 0 on success else non-zero. A CONNECTION_CLOSE is generated on
1846 * error.
1847 */
1848static int h3_close(struct qcs *qcs, enum qcc_app_ops_close_side side)
1849{
Amaury Denoyelle87f87662023-01-30 12:12:43 +01001850 struct h3s *h3s = qcs->ctx;
1851 struct h3c *h3c = h3s->h3c;;
1852
1853 /* RFC 9114 6.2.1. Control Streams
1854 *
1855 * The sender
1856 * MUST NOT close the control stream, and the receiver MUST NOT
1857 * request that the sender close the control stream. If either
1858 * control stream is closed at any point, this MUST be treated
1859 * as a connection error of type H3_CLOSED_CRITICAL_STREAM.
1860 */
Amaury Denoyellee269aeb2023-01-30 12:13:22 +01001861 if (qcs == h3c->ctrl_strm || h3s->type == H3S_T_CTRL) {
Amaury Denoyellee31867b2023-01-31 16:01:22 +01001862 TRACE_ERROR("closure detected on control stream", H3_EV_H3S_END, qcs->qcc->conn, qcs);
Amaury Denoyelle58721f22023-05-09 18:01:09 +02001863 qcc_set_error(qcs->qcc, H3_CLOSED_CRITICAL_STREAM, 1);
Amaury Denoyelle87f87662023-01-30 12:12:43 +01001864 return 1;
1865 }
1866
Amaury Denoyelle1e340ba2023-01-30 12:12:11 +01001867 return 0;
1868}
1869
Amaury Denoyellec0156792022-06-03 15:29:07 +02001870static int h3_attach(struct qcs *qcs, void *conn_ctx)
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001871{
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001872 struct h3c *h3c = conn_ctx;
1873 struct h3s *h3s = NULL;
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001874
Amaury Denoyelled5581d52022-05-30 15:51:31 +02001875 TRACE_ENTER(H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
1876
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001877 /* RFC 9114 5.2. Connection Shutdown
1878 *
1879 * Upon sending
1880 * a GOAWAY frame, the endpoint SHOULD explicitly cancel (see
1881 * Sections 4.1.1 and 7.2.3) any requests or pushes that have
1882 * identifiers greater than or equal to the one indicated, in
1883 * order to clean up transport state for the affected streams.
1884 * The endpoint SHOULD continue to do so as more requests or
1885 * pushes arrive.
1886 */
1887 if (h3c->flags & H3_CF_GOAWAY_SENT && qcs->id >= h3c->id_goaway &&
1888 quic_stream_is_bidi(qcs->id)) {
1889 /* Reject request and do not allocate a h3s context.
1890 * TODO support push uni-stream rejection.
1891 */
1892 TRACE_STATE("reject stream higher than goaway", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
1893 qcc_abort_stream_read(qcs);
1894 qcc_reset_stream(qcs, H3_REQUEST_REJECTED);
1895 goto done;
1896 }
1897
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001898 h3s = pool_alloc(pool_head_h3s);
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001899 if (!h3s) {
1900 TRACE_ERROR("h3s allocation failure", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001901 goto err;
1902 }
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001903
1904 qcs->ctx = h3s;
Amaury Denoyellec0156792022-06-03 15:29:07 +02001905 h3s->h3c = conn_ctx;
1906
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001907 h3s->demux_frame_len = 0;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01001908 h3s->demux_frame_type = H3_FT_UNINIT;
Amaury Denoyelled2c5ee62022-12-08 16:54:42 +01001909 h3s->body_len = 0;
1910 h3s->data_len = 0;
Amaury Denoyelle35550642022-05-24 15:14:53 +02001911 h3s->flags = 0;
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01001912 h3s->err = 0;
Amaury Denoyelle48f01bd2022-04-27 15:37:20 +02001913
Amaury Denoyelle3236a8e2022-05-24 15:24:03 +02001914 if (quic_stream_is_bidi(qcs->id)) {
1915 h3s->type = H3S_T_REQ;
Amaury Denoyelle8d818c62022-08-02 11:32:45 +02001916 h3s->st_req = H3S_ST_REQ_BEFORE;
Amaury Denoyelle30e260e2022-08-03 11:17:57 +02001917 qcs_wait_http_req(qcs);
Amaury Denoyelle3236a8e2022-05-24 15:24:03 +02001918 }
1919 else {
1920 /* stream type must be decoded for unidirectional streams */
1921 h3s->type = H3S_T_UNKNOWN;
1922 }
1923
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001924 done:
Amaury Denoyelled5581d52022-05-30 15:51:31 +02001925 TRACE_LEAVE(H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001926 return 0;
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001927
1928 err:
1929 TRACE_DEVEL("leaving in error", H3_EV_H3S_NEW, qcs->qcc->conn, qcs);
1930 return 1;
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001931}
1932
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001933static void h3_detach(struct qcs *qcs)
1934{
1935 struct h3s *h3s = qcs->ctx;
Amaury Denoyelled5581d52022-05-30 15:51:31 +02001936
1937 TRACE_ENTER(H3_EV_H3S_END, qcs->qcc->conn, qcs);
1938
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001939 pool_free(pool_head_h3s, h3s);
1940 qcs->ctx = NULL;
Amaury Denoyelled5581d52022-05-30 15:51:31 +02001941
1942 TRACE_LEAVE(H3_EV_H3S_END, qcs->qcc->conn, qcs);
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02001943}
1944
Amaury Denoyelle71fd0362023-01-24 17:35:37 +01001945/* Initialize H3 control stream and prepare SETTINGS emission.
1946 *
1947 * Returns 0 on success else non-zero.
1948 */
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001949static int h3_finalize(void *ctx)
1950{
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02001951 struct h3c *h3c = ctx;
Amaury Denoyelle9cc47512022-05-24 16:27:41 +02001952 struct qcs *qcs;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001953
Amaury Denoyelleb1437232022-07-08 11:53:22 +02001954 qcs = qcc_init_stream_local(h3c->qcc, 0);
Amaury Denoyelle9cc47512022-05-24 16:27:41 +02001955 if (!qcs)
Amaury Denoyelle71fd0362023-01-24 17:35:37 +01001956 return 1;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001957
Amaury Denoyelle9cc47512022-05-24 16:27:41 +02001958 h3_control_send(qcs, h3c);
Amaury Denoyelled7010392022-07-13 15:17:29 +02001959 h3c->ctrl_strm = qcs;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001960
Amaury Denoyelle71fd0362023-01-24 17:35:37 +01001961 return 0;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01001962}
1963
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02001964/* Generate a GOAWAY frame for <h3c> connection on the control stream.
1965 *
1966 * Returns 0 on success else non-zero.
1967 */
1968static int h3_send_goaway(struct h3c *h3c)
1969{
1970 struct qcs *qcs = h3c->ctrl_strm;
1971 struct buffer pos, *res;
1972 unsigned char data[3 * QUIC_VARINT_MAX_SIZE];
1973 size_t frm_len = quic_int_getsize(h3c->id_goaway);
1974
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01001975 TRACE_ENTER(H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01001976
1977 if (!qcs) {
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01001978 TRACE_ERROR("control stream not initialized", H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01001979 goto err;
1980 }
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02001981
1982 pos = b_make((char *)data, sizeof(data), 0, 0);
1983
Amaury Denoyelle7d78eff2023-01-17 15:21:16 +01001984 b_quic_enc_int(&pos, H3_FT_GOAWAY, 0);
1985 b_quic_enc_int(&pos, frm_len, 0);
1986 b_quic_enc_int(&pos, h3c->id_goaway, 0);
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02001987
1988 res = mux_get_buf(qcs);
1989 if (!res || b_room(res) < b_data(&pos)) {
1990 /* Do not try forcefully to emit GOAWAY if no space left. */
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01001991 TRACE_ERROR("cannot send GOAWAY", H3_EV_H3C_END, h3c->qcc->conn, qcs);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01001992 goto err;
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02001993 }
1994
1995 b_force_xfer(res, &pos, b_data(&pos));
Amaury Denoyelle19adeb52023-01-25 10:50:03 +01001996 qcc_send_stream(qcs, 1);
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02001997
Amaury Denoyelle3d550842023-01-24 17:42:21 +01001998 h3c->flags |= H3_CF_GOAWAY_SENT;
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01001999 TRACE_LEAVE(H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002000 return 0;
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002001
2002 err:
Amaury Denoyelle3d550842023-01-24 17:42:21 +01002003 /* Consider GOAWAY as sent even if not really the case. This will
2004 * block future stream opening using H3_REQUEST_REJECTED reset.
2005 */
2006 h3c->flags |= H3_CF_GOAWAY_SENT;
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002007 TRACE_DEVEL("leaving in error", H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002008 return 1;
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002009}
2010
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002011/* Initialize the HTTP/3 context for <qcc> mux.
2012 * Return 1 if succeeded, 0 if not.
2013 */
2014static int h3_init(struct qcc *qcc)
2015{
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002016 struct h3c *h3c;
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02002017 struct quic_conn *qc = qcc->conn->handle.qc;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002018
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002019 h3c = pool_alloc(pool_head_h3c);
2020 if (!h3c)
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002021 goto fail_no_h3;
2022
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002023 h3c->qcc = qcc;
Amaury Denoyelled7010392022-07-13 15:17:29 +02002024 h3c->ctrl_strm = NULL;
Amaury Denoyelle2fe93ab2022-12-09 15:01:31 +01002025 h3c->err = 0;
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002026 h3c->flags = 0;
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002027 h3c->id_goaway = 0;
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002028
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002029 qcc->ctx = h3c;
Amaury Denoyelle5c25dc52022-09-30 17:44:15 +02002030 /* TODO cleanup only ref to quic_conn */
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02002031 h3c->prx_counters =
2032 EXTRA_COUNTERS_GET(qc->li->bind_conf->frontend->extra_counters_fe,
2033 &h3_stats_module);
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002034 LIST_INIT(&h3c->buf_wait.list);
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002035
2036 return 1;
2037
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002038 fail_no_h3:
2039 return 0;
2040}
2041
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002042/* Send a HTTP/3 GOAWAY followed by a CONNECTION_CLOSE_APP. */
2043static void h3_shutdown(void *ctx)
Amaury Denoyelle8347f272022-03-29 14:46:55 +02002044{
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002045 struct h3c *h3c = ctx;
Amaury Denoyelle069288b2022-07-15 10:58:25 +02002046
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002047 TRACE_ENTER(H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002048
Amaury Denoyelle069288b2022-07-15 10:58:25 +02002049 /* RFC 9114 5.2. Connection Shutdown
2050 *
Amaury Denoyelle114c9c82022-03-28 14:53:45 +02002051 * Even when a connection is not idle, either endpoint can decide to
2052 * stop using the connection and initiate a graceful connection close.
2053 * Endpoints initiate the graceful shutdown of an HTTP/3 connection by
2054 * sending a GOAWAY frame.
2055 */
2056 h3_send_goaway(h3c);
2057
2058 /* RFC 9114 5.2. Connection Shutdown
2059 *
Amaury Denoyelle069288b2022-07-15 10:58:25 +02002060 * An endpoint that completes a
2061 * graceful shutdown SHOULD use the H3_NO_ERROR error code when closing
2062 * the connection.
2063 */
Amaury Denoyelle51f116d2023-05-04 15:49:02 +02002064 h3c->qcc->err = quic_err_app(H3_NO_ERROR);
Amaury Denoyelle56a86dd2023-01-30 15:36:51 +01002065
Amaury Denoyelle78adb4b2023-01-31 15:50:16 +01002066 TRACE_LEAVE(H3_EV_H3C_END, h3c->qcc->conn);
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002067}
Amaury Denoyelle069288b2022-07-15 10:58:25 +02002068
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002069static void h3_release(void *ctx)
2070{
2071 struct h3c *h3c = ctx;
Amaury Denoyelle8d1ecac2022-05-24 14:55:43 +02002072 pool_free(pool_head_h3c, h3c);
Amaury Denoyelle8347f272022-03-29 14:46:55 +02002073}
2074
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02002075/* Increment the h3 error code counters for <error_code> value */
2076static void h3_stats_inc_err_cnt(void *ctx, int err_code)
2077{
2078 struct h3c *h3c = ctx;
2079
2080 h3_inc_err_cnt(h3c->prx_counters, err_code);
2081}
2082
Amaury Denoyelle35d90532023-01-26 16:03:45 +01002083static inline const char *h3_ft_str(uint64_t type)
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01002084{
2085 switch (type) {
2086 case H3_FT_DATA: return "DATA";
2087 case H3_FT_HEADERS: return "HEADERS";
2088 case H3_FT_SETTINGS: return "SETTINGS";
2089 case H3_FT_PUSH_PROMISE: return "PUSH_PROMISE";
2090 case H3_FT_MAX_PUSH_ID: return "MAX_PUSH_ID";
2091 case H3_FT_CANCEL_PUSH: return "CANCEL_PUSH";
2092 case H3_FT_GOAWAY: return "GOAWAY";
2093 default: return "_UNKNOWN_";
2094 }
2095}
2096
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002097/* h3 trace handler */
2098static void h3_trace(enum trace_level level, uint64_t mask,
2099 const struct trace_source *src,
2100 const struct ist where, const struct ist func,
2101 const void *a1, const void *a2, const void *a3, const void *a4)
2102{
2103 const struct connection *conn = a1;
2104 const struct qcc *qcc = conn ? conn->ctx : NULL;
2105 const struct qcs *qcs = a2;
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01002106 const struct h3s *h3s = qcs ? qcs->ctx : NULL;
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002107
Frédéric Lécaille1c725aa2022-09-08 15:49:37 +02002108 if (!qcc)
2109 return;
2110
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002111 if (src->verbosity > H3_VERB_CLEAN) {
2112 chunk_appendf(&trace_buf, " : qcc=%p(F)", qcc);
Frédéric Lécaille2eb5faa2022-09-08 16:03:13 +02002113 if (qcc->conn->handle.qc)
2114 chunk_appendf(&trace_buf, " qc=%p", qcc->conn->handle.qc);
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002115
2116 if (qcs)
Frédéric Lécaille628e89c2022-06-24 12:13:53 +02002117 chunk_appendf(&trace_buf, " qcs=%p(%llu)", qcs, (ull)qcs->id);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01002118
2119 if (h3s && h3s->demux_frame_type != H3_FT_UNINIT) {
Amaury Denoyelle35d90532023-01-26 16:03:45 +01002120 chunk_appendf(&trace_buf, " h3s.dem=%s/%llu",
2121 h3_ft_str(h3s->demux_frame_type), (ull)h3s->demux_frame_len);
Amaury Denoyelle14037bf2023-02-17 15:56:06 +01002122 }
Amaury Denoyelle016aa932022-05-30 15:49:36 +02002123 }
2124}
2125
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002126/* HTTP/3 application layer operations */
2127const struct qcc_app_ops h3_ops = {
2128 .init = h3_init,
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02002129 .attach = h3_attach,
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002130 .decode_qcs = h3_decode_qcs,
Amaury Denoyelleabbe91e2021-11-12 16:09:29 +01002131 .snd_buf = h3_snd_buf,
Amaury Denoyelle1e340ba2023-01-30 12:12:11 +01002132 .close = h3_close,
Amaury Denoyelle67e92d32022-04-27 18:04:01 +02002133 .detach = h3_detach,
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002134 .finalize = h3_finalize,
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002135 .shutdown = h3_shutdown,
Frédéric Lécaille6f7607e2022-05-25 22:25:37 +02002136 .inc_err_cnt = h3_stats_inc_err_cnt,
Amaury Denoyellef8aaf8b2022-09-14 16:23:47 +02002137 .release = h3_release,
Frédéric Lécailleccac11f2021-03-03 16:09:02 +01002138};