blob: 73802553d21e2f05b17290bf581c9865c4c9cb11 [file] [log] [blame]
Willy Tarreaubaaee002006-06-26 02:48:02 +02001/*
Willy Tarreau03fa5df2010-05-24 21:02:37 +02002 * Frontend variables and functions.
Willy Tarreaubaaee002006-06-26 02:48:02 +02003 *
Willy Tarreaua73fcaf2011-03-20 10:15:22 +01004 * Copyright 2000-2011 Willy Tarreau <w@1wt.eu>
Willy Tarreaubaaee002006-06-26 02:48:02 +02005 *
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public License
8 * as published by the Free Software Foundation; either version
9 * 2 of the License, or (at your option) any later version.
10 *
11 */
12
13#include <errno.h>
14#include <fcntl.h>
15#include <stdio.h>
16#include <stdlib.h>
Willy Tarreau2dd0d472006-06-29 17:53:05 +020017#include <string.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020018
19#include <sys/socket.h>
20#include <sys/stat.h>
21#include <sys/types.h>
22
Willy Tarreau48a7e722010-12-24 15:26:39 +010023#include <netinet/tcp.h>
24
Willy Tarreauc7e42382012-08-24 19:22:53 +020025#include <common/chunk.h>
Willy Tarreau2dd0d472006-06-29 17:53:05 +020026#include <common/compat.h>
Willy Tarreaue3ba5f02006-06-29 18:54:54 +020027#include <common/config.h>
Willy Tarreau8b0cbf92010-10-15 23:23:19 +020028#include <common/debug.h>
29#include <common/standard.h>
Willy Tarreau2dd0d472006-06-29 17:53:05 +020030#include <common/time.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020031
Willy Tarreaubaaee002006-06-26 02:48:02 +020032#include <types/global.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020033
Willy Tarreau8797c062007-05-07 00:55:35 +020034#include <proto/acl.h>
Willy Tarreau61612d42012-04-19 18:42:05 +020035#include <proto/arg.h>
Willy Tarreauc7e42382012-08-24 19:22:53 +020036#include <proto/channel.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020037#include <proto/fd.h>
Willy Tarreau03fa5df2010-05-24 21:02:37 +020038#include <proto/frontend.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020039#include <proto/log.h>
Willy Tarreaue5f20dc2006-12-03 15:21:35 +010040#include <proto/hdr_idx.h>
Willy Tarreau9650f372009-08-16 14:02:45 +020041#include <proto/proto_tcp.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020042#include <proto/proto_http.h>
Willy Tarreau7f062c42009-03-05 18:43:00 +010043#include <proto/proxy.h>
Willy Tarreauc6ca1a02007-05-13 19:43:47 +020044#include <proto/session.h>
Willy Tarreaudded32d2008-11-30 19:48:07 +010045#include <proto/stream_interface.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020046#include <proto/task.h>
47
Willy Tarreau81f9aa32010-06-01 17:45:26 +020048/* Finish a session accept() for a proxy (TCP or HTTP). It returns a negative
Willy Tarreauabe8ea52010-11-11 10:56:04 +010049 * value in case of a critical failure which must cause the listener to be
50 * disabled, a positive value in case of success, or zero if it is a success
51 * but the session must be closed ASAP (eg: monitoring).
Willy Tarreaubaaee002006-06-26 02:48:02 +020052 */
Willy Tarreau81f9aa32010-06-01 17:45:26 +020053int frontend_accept(struct session *s)
Willy Tarreaueb472682010-05-28 18:46:57 +020054{
Willy Tarreaufb7508a2012-05-21 16:47:54 +020055 int cfd = si_fd(&s->si[0]);
Emeric Brunb982a3d2010-01-04 15:45:53 +010056
Willy Tarreaueb472682010-05-28 18:46:57 +020057 tv_zero(&s->logs.tv_request);
58 s->logs.t_queue = -1;
59 s->logs.t_connect = -1;
60 s->logs.t_data = -1;
61 s->logs.t_close = 0;
62 s->logs.bytes_in = s->logs.bytes_out = 0;
63 s->logs.prx_queue_size = 0; /* we get the number of pending conns before us */
64 s->logs.srv_queue_size = 0; /* we will get this number soon */
Willy Tarreaubaaee002006-06-26 02:48:02 +020065
Willy Tarreau35a09942010-06-01 17:12:40 +020066 /* FIXME: the logs are horribly complicated now, because they are
67 * defined in <p>, <p>, and later <be> and <be>.
Willy Tarreaueb472682010-05-28 18:46:57 +020068 */
William Lallemandbddd4fd2012-02-27 11:23:10 +010069 s->do_log = sess_log;
Willy Tarreau35a09942010-06-01 17:12:40 +020070
71 /* default error reporting function, may be changed by analysers */
72 s->srv_error = default_srv_error;
Willy Tarreaubaaee002006-06-26 02:48:02 +020073
Willy Tarreauf67c9782010-05-23 22:59:00 +020074 /* Adjust some socket options */
Willy Tarreau9c3bc222010-12-24 14:49:37 +010075 if (s->listener->addr.ss_family == AF_INET || s->listener->addr.ss_family == AF_INET6) {
76 if (setsockopt(cfd, IPPROTO_TCP, TCP_NODELAY,
77 (char *) &one, sizeof(one)) == -1)
78 goto out_return;
Willy Tarreauf67c9782010-05-23 22:59:00 +020079
Willy Tarreau9c3bc222010-12-24 14:49:37 +010080 if (s->fe->options & PR_O_TCP_CLI_KA)
81 setsockopt(cfd, SOL_SOCKET, SO_KEEPALIVE,
82 (char *) &one, sizeof(one));
Willy Tarreauf67c9782010-05-23 22:59:00 +020083
Willy Tarreau9c3bc222010-12-24 14:49:37 +010084 if (s->fe->options & PR_O_TCP_NOLING)
85 setsockopt(cfd, SOL_SOCKET, SO_LINGER,
86 (struct linger *) &nolinger, sizeof(struct linger));
Willy Tarreau48a7e722010-12-24 15:26:39 +010087#if defined(TCP_MAXSEG)
88 if (s->listener->maxseg < 0) {
89 /* we just want to reduce the current MSS by that value */
90 int mss;
Willy Tarreau7d286a02011-01-05 15:42:54 +010091 socklen_t mss_len = sizeof(mss);
Willy Tarreau48a7e722010-12-24 15:26:39 +010092 if (getsockopt(cfd, IPPROTO_TCP, TCP_MAXSEG, &mss, &mss_len) == 0) {
93 mss += s->listener->maxseg; /* remember, it's < 0 */
94 setsockopt(cfd, IPPROTO_TCP, TCP_MAXSEG, &mss, sizeof(mss));
95 }
96 }
97#endif
Willy Tarreau9c3bc222010-12-24 14:49:37 +010098 }
Willy Tarreauf67c9782010-05-23 22:59:00 +020099
100 if (global.tune.client_sndbuf)
101 setsockopt(cfd, SOL_SOCKET, SO_SNDBUF, &global.tune.client_sndbuf, sizeof(global.tune.client_sndbuf));
102
103 if (global.tune.client_rcvbuf)
104 setsockopt(cfd, SOL_SOCKET, SO_RCVBUF, &global.tune.client_rcvbuf, sizeof(global.tune.client_rcvbuf));
105
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200106 if (s->fe->mode == PR_MODE_HTTP) {
Willy Tarreaueb472682010-05-28 18:46:57 +0200107 /* the captures are only used in HTTP frontends */
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200108 if (unlikely(s->fe->nb_req_cap > 0 &&
109 (s->txn.req.cap = pool_alloc2(s->fe->req_cap_pool)) == NULL))
Willy Tarreauabe8ea52010-11-11 10:56:04 +0100110 goto out_return; /* no memory */
Willy Tarreaubaaee002006-06-26 02:48:02 +0200111
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200112 if (unlikely(s->fe->nb_rsp_cap > 0 &&
113 (s->txn.rsp.cap = pool_alloc2(s->fe->rsp_cap_pool)) == NULL))
Willy Tarreau35a09942010-06-01 17:12:40 +0200114 goto out_free_reqcap; /* no memory */
Willy Tarreaueb472682010-05-28 18:46:57 +0200115 }
Willy Tarreaubaaee002006-06-26 02:48:02 +0200116
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200117 if (s->fe->acl_requires & ACL_USE_L7_ANY) {
Willy Tarreaueb472682010-05-28 18:46:57 +0200118 /* we have to allocate header indexes only if we know
119 * that we may make use of them. This of course includes
120 * (mode == PR_MODE_HTTP).
Willy Tarreau042cc792007-03-19 16:20:06 +0100121 */
Willy Tarreauac1932d2011-10-24 19:14:41 +0200122 s->txn.hdr_idx.size = global.tune.max_http_hdr;
Willy Tarreau45e73e32006-12-17 00:05:15 +0100123
Willy Tarreau34eb6712011-10-24 18:15:04 +0200124 if (unlikely((s->txn.hdr_idx.v = pool_alloc2(pool2_hdr_idx)) == NULL))
Willy Tarreau35a09942010-06-01 17:12:40 +0200125 goto out_free_rspcap; /* no memory */
Willy Tarreau45e73e32006-12-17 00:05:15 +0100126
Willy Tarreaueb472682010-05-28 18:46:57 +0200127 /* and now initialize the HTTP transaction state */
128 http_init_txn(s);
129 }
Willy Tarreaue5f20dc2006-12-03 15:21:35 +0100130
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200131 if ((s->fe->mode == PR_MODE_TCP || s->fe->mode == PR_MODE_HTTP)
William Lallemand0f99e342011-10-12 17:50:54 +0200132 && (!LIST_ISEMPTY(&s->fe->logsrvs))) {
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200133 if (likely(s->fe->to_log)) {
Willy Tarreaueb472682010-05-28 18:46:57 +0200134 /* we have the client ip */
135 if (s->logs.logwait & LW_CLIP)
136 if (!(s->logs.logwait &= ~LW_CLIP))
137 s->do_log(s);
Willy Tarreaua3445fc2010-05-20 16:17:07 +0200138 }
Willy Tarreau631f01c2011-09-05 00:36:48 +0200139 else {
Willy Tarreaueb472682010-05-28 18:46:57 +0200140 char pn[INET6_ADDRSTRLEN], sn[INET6_ADDRSTRLEN];
Willy Tarreau14c8aac2007-05-08 19:46:30 +0200141
Willy Tarreau986a9d22012-08-30 21:11:38 +0200142 conn_get_from_addr(&s->req->prod->conn);
143 conn_get_to_addr(&s->req->prod->conn);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200144
Willy Tarreau986a9d22012-08-30 21:11:38 +0200145 switch (addr_to_str(&s->req->prod->conn.addr.from, pn, sizeof(pn))) {
Willy Tarreau631f01c2011-09-05 00:36:48 +0200146 case AF_INET:
147 case AF_INET6:
Willy Tarreau986a9d22012-08-30 21:11:38 +0200148 addr_to_str(&s->req->prod->conn.addr.to, sn, sizeof(sn));
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200149 send_log(s->fe, LOG_INFO, "Connect from %s:%d to %s:%d (%s/%s)\n",
Willy Tarreau986a9d22012-08-30 21:11:38 +0200150 pn, get_host_port(&s->req->prod->conn.addr.from),
151 sn, get_host_port(&s->req->prod->conn.addr.to),
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200152 s->fe->id, (s->fe->mode == PR_MODE_HTTP) ? "HTTP" : "TCP");
Willy Tarreau631f01c2011-09-05 00:36:48 +0200153 break;
154 case AF_UNIX:
155 /* UNIX socket, only the destination is known */
156 send_log(s->fe, LOG_INFO, "Connect to unix:%d (%s/%s)\n",
157 s->listener->luid,
158 s->fe->id, (s->fe->mode == PR_MODE_HTTP) ? "HTTP" : "TCP");
159 break;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200160 }
Willy Tarreaueb472682010-05-28 18:46:57 +0200161 }
162 }
Willy Tarreaubaaee002006-06-26 02:48:02 +0200163
Willy Tarreau2281b7f2010-05-28 19:29:49 +0200164 if (unlikely((global.mode & MODE_DEBUG) && (!(global.mode & MODE_QUIET) || (global.mode & MODE_VERBOSE)))) {
Willy Tarreau631f01c2011-09-05 00:36:48 +0200165 char pn[INET6_ADDRSTRLEN];
Willy Tarreaub0f75322011-09-09 11:21:06 +0200166 int len = 0;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200167
Willy Tarreau986a9d22012-08-30 21:11:38 +0200168 conn_get_from_addr(&s->req->prod->conn);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200169
Willy Tarreau986a9d22012-08-30 21:11:38 +0200170 switch (addr_to_str(&s->req->prod->conn.addr.from, pn, sizeof(pn))) {
Willy Tarreau631f01c2011-09-05 00:36:48 +0200171 case AF_INET:
172 case AF_INET6:
Willy Tarreaueb472682010-05-28 18:46:57 +0200173 len = sprintf(trash, "%08x:%s.accept(%04x)=%04x from [%s:%d]\n",
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200174 s->uniq_id, s->fe->id, (unsigned short)s->listener->fd, (unsigned short)cfd,
Willy Tarreau986a9d22012-08-30 21:11:38 +0200175 pn, get_host_port(&s->req->prod->conn.addr.from));
Willy Tarreau631f01c2011-09-05 00:36:48 +0200176 break;
177 case AF_UNIX:
178 /* UNIX socket, only the destination is known */
Emeric Brunab844ea2010-10-22 16:33:18 +0200179 len = sprintf(trash, "%08x:%s.accept(%04x)=%04x from [unix:%d]\n",
180 s->uniq_id, s->fe->id, (unsigned short)s->listener->fd, (unsigned short)cfd,
181 s->listener->luid);
Willy Tarreau631f01c2011-09-05 00:36:48 +0200182 break;
Emeric Brunab844ea2010-10-22 16:33:18 +0200183 }
Willy Tarreau9a2d1542008-08-30 12:31:07 +0200184
Willy Tarreau21337822012-04-29 14:11:38 +0200185 if (write(1, trash, len) < 0) /* shut gcc warning */;
Willy Tarreaueb472682010-05-28 18:46:57 +0200186 }
Willy Tarreaubaaee002006-06-26 02:48:02 +0200187
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200188 if (s->fe->mode == PR_MODE_HTTP)
Willy Tarreau03cdb7c2012-08-27 23:14:58 +0200189 s->req->flags |= CF_READ_DONTWAIT; /* one read is usually enough */
Willy Tarreaubaaee002006-06-26 02:48:02 +0200190
Willy Tarreaueb472682010-05-28 18:46:57 +0200191 /* note: this should not happen anymore since there's always at least the switching rules */
192 if (!s->req->analysers) {
Willy Tarreau8263d2b2012-08-28 00:06:31 +0200193 channel_auto_connect(s->req); /* don't wait to establish connection */
194 channel_auto_close(s->req); /* let the producer forward close requests */
Willy Tarreaueb472682010-05-28 18:46:57 +0200195 }
Willy Tarreaud7971282006-07-29 18:36:34 +0200196
Willy Tarreaueb472682010-05-28 18:46:57 +0200197 s->req->rto = s->fe->timeout.client;
Willy Tarreaueb472682010-05-28 18:46:57 +0200198 s->rep->wto = s->fe->timeout.client;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200199
Willy Tarreaueb472682010-05-28 18:46:57 +0200200 fdtab[cfd].flags = FD_FL_TCP | FD_FL_TCP_NODELAY;
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200201 if (s->fe->options & PR_O_TCP_NOLING)
Willy Tarreaueb472682010-05-28 18:46:57 +0200202 fdtab[cfd].flags |= FD_FL_TCP_NOLING;
Willy Tarreau6e6fb2b2009-08-16 18:20:44 +0200203
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200204 if (unlikely((s->fe->mode == PR_MODE_HTTP && (s->flags & SN_MONITOR)) ||
Willy Tarreau1620ec32011-08-06 17:05:02 +0200205 (s->fe->mode == PR_MODE_HEALTH && ((s->fe->options2 & PR_O2_CHK_ANY) == PR_O2_HTTP_CHK)))) {
Willy Tarreaueb472682010-05-28 18:46:57 +0200206 /* Either we got a request from a monitoring system on an HTTP instance,
207 * or we're in health check mode with the 'httpchk' option enabled. In
208 * both cases, we return a fake "HTTP/1.0 200 OK" response and we exit.
209 */
210 struct chunk msg;
211 chunk_initstr(&msg, "HTTP/1.0 200 OK\r\n\r\n");
212 stream_int_retnclose(&s->si[0], &msg); /* forge a 200 response */
213 s->req->analysers = 0;
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200214 s->task->expire = s->rep->wex;
Willy Tarreau49b046d2012-08-09 12:11:58 +0200215 fd_stop_recv(cfd);
Willy Tarreaueb472682010-05-28 18:46:57 +0200216 }
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200217 else if (unlikely(s->fe->mode == PR_MODE_HEALTH)) { /* health check mode, no client reading */
Willy Tarreaueb472682010-05-28 18:46:57 +0200218 struct chunk msg;
219 chunk_initstr(&msg, "OK\n");
220 stream_int_retnclose(&s->si[0], &msg); /* forge an "OK" response */
221 s->req->analysers = 0;
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200222 s->task->expire = s->rep->wex;
Willy Tarreau49b046d2012-08-09 12:11:58 +0200223 fd_stop_recv(cfd);
Willy Tarreaueb472682010-05-28 18:46:57 +0200224 }
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200225 /* everything's OK, let's go on */
Willy Tarreaueb472682010-05-28 18:46:57 +0200226 return 1;
Willy Tarreau8ced9a42007-11-04 17:51:50 +0100227
228 /* Error unrolling */
Willy Tarreau35a09942010-06-01 17:12:40 +0200229 out_free_rspcap:
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200230 pool_free2(s->fe->rsp_cap_pool, s->txn.rsp.cap);
Willy Tarreau35a09942010-06-01 17:12:40 +0200231 out_free_reqcap:
Willy Tarreau81f9aa32010-06-01 17:45:26 +0200232 pool_free2(s->fe->req_cap_pool, s->txn.req.cap);
Willy Tarreauabe8ea52010-11-11 10:56:04 +0100233 out_return:
Willy Tarreaueb472682010-05-28 18:46:57 +0200234 return -1;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200235}
236
Willy Tarreau22cda212012-08-31 17:43:29 +0200237/* This handshake handler waits a PROXY protocol header at the beginning of the
238 * raw data stream. The header looks like this :
239 *
240 * "PROXY" <SP> PROTO <SP> SRC3 <SP> DST3 <SP> SRC4 <SP> <DST4> "\r\n"
241 *
242 * There must be exactly one space between each field. Fields are :
243 * - PROTO : layer 4 protocol, which must be "TCP4" or "TCP6".
244 * - SRC3 : layer 3 (eg: IP) source address in standard text form
245 * - DST3 : layer 3 (eg: IP) destination address in standard text form
246 * - SRC4 : layer 4 (eg: TCP port) source address in standard text form
247 * - DST4 : layer 4 (eg: TCP port) destination address in standard text form
248 *
249 * This line MUST be at the beginning of the buffer and MUST NOT wrap.
250 *
251 * The header line is small and in all cases smaller than the smallest normal
252 * TCP MSS. So it MUST always be delivered as one segment, which ensures we
253 * can safely use MSG_PEEK and avoid buffering.
254 *
255 * Once the data is fetched, the values are set in the connection's address
256 * fields, and data are removed from the socket's buffer. The function returns
257 * zero if it needs to wait for more data or if it fails, or 1 if it completed
258 * and removed itself.
259 */
260int conn_recv_proxy(struct connection *conn, int flag)
261{
262 char *line, *end;
263 int len;
264
265 /* we might have been called just after an asynchronous shutr */
266 if (conn->flags & CO_FL_SOCK_RD_SH)
267 goto fail;
268
269 do {
270 len = recv(conn->t.sock.fd, trash, trashlen, MSG_PEEK);
271 if (len < 0) {
272 if (errno == EINTR)
273 continue;
274 if (errno == EAGAIN) {
275 conn_sock_poll_recv(conn);
276 return 0;
277 }
278 goto fail;
279 }
280 } while (0);
281
282 if (len < 6)
283 goto missing;
284
285 line = trash;
286 end = trash + len;
287
288 /* Decode a possible proxy request, fail early if it does not match */
289 if (strncmp(line, "PROXY ", 6) != 0)
290 goto fail;
291
292 line += 6;
293 if (len < 18) /* shortest possible line */
294 goto missing;
295
296 if (!memcmp(line, "TCP4 ", 5) != 0) {
297 u32 src3, dst3, sport, dport;
298
299 line += 5;
300
301 src3 = inetaddr_host_lim_ret(line, end, &line);
302 if (line == end)
303 goto missing;
304 if (*line++ != ' ')
305 goto fail;
306
307 dst3 = inetaddr_host_lim_ret(line, end, &line);
308 if (line == end)
309 goto missing;
310 if (*line++ != ' ')
311 goto fail;
312
313 sport = read_uint((const char **)&line, end);
314 if (line == end)
315 goto missing;
316 if (*line++ != ' ')
317 goto fail;
318
319 dport = read_uint((const char **)&line, end);
320 if (line > end - 2)
321 goto missing;
322 if (*line++ != '\r')
323 goto fail;
324 if (*line++ != '\n')
325 goto fail;
326
327 /* update the session's addresses and mark them set */
328 ((struct sockaddr_in *)&conn->addr.from)->sin_family = AF_INET;
329 ((struct sockaddr_in *)&conn->addr.from)->sin_addr.s_addr = htonl(src3);
330 ((struct sockaddr_in *)&conn->addr.from)->sin_port = htons(sport);
331
332 ((struct sockaddr_in *)&conn->addr.to)->sin_family = AF_INET;
333 ((struct sockaddr_in *)&conn->addr.to)->sin_addr.s_addr = htonl(dst3);
334 ((struct sockaddr_in *)&conn->addr.to)->sin_port = htons(dport);
335 conn->flags |= CO_FL_ADDR_FROM_SET | CO_FL_ADDR_TO_SET;
336 }
337 else if (!memcmp(line, "TCP6 ", 5) != 0) {
338 u32 sport, dport;
339 char *src_s;
340 char *dst_s, *sport_s, *dport_s;
341 struct in6_addr src3, dst3;
342
343 line += 5;
344
345 src_s = line;
346 dst_s = sport_s = dport_s = NULL;
347 while (1) {
348 if (line > end - 2) {
349 goto missing;
350 }
351 else if (*line == '\r') {
352 *line = 0;
353 line++;
354 if (*line++ != '\n')
355 goto fail;
356 break;
357 }
358
359 if (*line == ' ') {
360 *line = 0;
361 if (!dst_s)
362 dst_s = line + 1;
363 else if (!sport_s)
364 sport_s = line + 1;
365 else if (!dport_s)
366 dport_s = line + 1;
367 }
368 line++;
369 }
370
371 if (!dst_s || !sport_s || !dport_s)
372 goto fail;
373
374 sport = read_uint((const char **)&sport_s,dport_s - 1);
375 if (*sport_s != 0)
376 goto fail;
377
378 dport = read_uint((const char **)&dport_s,line - 2);
379 if (*dport_s != 0)
380 goto fail;
381
382 if (inet_pton(AF_INET6, src_s, (void *)&src3) != 1)
383 goto fail;
384
385 if (inet_pton(AF_INET6, dst_s, (void *)&dst3) != 1)
386 goto fail;
387
388 /* update the session's addresses and mark them set */
389 ((struct sockaddr_in6 *)&conn->addr.from)->sin6_family = AF_INET6;
390 memcpy(&((struct sockaddr_in6 *)&conn->addr.from)->sin6_addr, &src3, sizeof(struct in6_addr));
391 ((struct sockaddr_in6 *)&conn->addr.from)->sin6_port = htons(sport);
392
393 ((struct sockaddr_in6 *)&conn->addr.to)->sin6_family = AF_INET6;
394 memcpy(&((struct sockaddr_in6 *)&conn->addr.to)->sin6_addr, &dst3, sizeof(struct in6_addr));
395 ((struct sockaddr_in6 *)&conn->addr.to)->sin6_port = htons(dport);
396 conn->flags |= CO_FL_ADDR_FROM_SET | CO_FL_ADDR_TO_SET;
397 }
398 else {
399 goto fail;
400 }
401
402 /* remove the PROXY line from the request. For this we re-read the
403 * exact line at once. If we don't get the exact same result, we
404 * fail.
405 */
406 len = line - trash;
407 do {
408 int len2 = recv(conn->t.sock.fd, trash, len, 0);
409 if (len2 < 0 && errno == EINTR)
410 continue;
411 if (len2 != len)
412 goto fail;
413 } while (0);
414
415 conn->flags &= ~flag;
416 return 1;
417
418 missing:
419 /* Missing data. Since we're using MSG_PEEK, we can only poll again if
420 * we have not read anything. Otherwise we need to fail because we won't
421 * be able to poll anymore.
422 */
423 fail:
424 conn_sock_stop_both(conn);
425 conn->flags |= CO_FL_ERROR;
426 conn->flags &= ~flag;
427 return 0;
428}
429
Willy Tarreaua73fcaf2011-03-20 10:15:22 +0100430/* Makes a PROXY protocol line from the two addresses. The output is sent to
431 * buffer <buf> for a maximum size of <buf_len> (including the trailing zero).
432 * It returns the number of bytes composing this line (including the trailing
433 * LF), or zero in case of failure (eg: not enough space). It supports TCP4,
434 * TCP6 and "UNKNOWN" formats.
435 */
436int make_proxy_line(char *buf, int buf_len, struct sockaddr_storage *src, struct sockaddr_storage *dst)
437{
438 int ret = 0;
439
440 if (src->ss_family == dst->ss_family && src->ss_family == AF_INET) {
441 ret = snprintf(buf + ret, buf_len - ret, "PROXY TCP4 ");
442 if (ret >= buf_len)
443 return 0;
444
445 /* IPv4 src */
446 if (!inet_ntop(src->ss_family, &((struct sockaddr_in *)src)->sin_addr, buf + ret, buf_len - ret))
447 return 0;
448
449 ret += strlen(buf + ret);
450 if (ret >= buf_len)
451 return 0;
452
453 buf[ret++] = ' ';
454
455 /* IPv4 dst */
456 if (!inet_ntop(dst->ss_family, &((struct sockaddr_in *)dst)->sin_addr, buf + ret, buf_len - ret))
457 return 0;
458
459 ret += strlen(buf + ret);
460 if (ret >= buf_len)
461 return 0;
462
463 /* source and destination ports */
464 ret += snprintf(buf + ret, buf_len - ret, " %u %u\r\n",
465 ntohs(((struct sockaddr_in *)src)->sin_port),
466 ntohs(((struct sockaddr_in *)dst)->sin_port));
467 if (ret >= buf_len)
468 return 0;
469 }
470 else if (src->ss_family == dst->ss_family && src->ss_family == AF_INET6) {
471 ret = snprintf(buf + ret, buf_len - ret, "PROXY TCP6 ");
472 if (ret >= buf_len)
473 return 0;
474
475 /* IPv6 src */
476 if (!inet_ntop(src->ss_family, &((struct sockaddr_in6 *)src)->sin6_addr, buf + ret, buf_len - ret))
477 return 0;
478
479 ret += strlen(buf + ret);
480 if (ret >= buf_len)
481 return 0;
482
483 buf[ret++] = ' ';
484
485 /* IPv6 dst */
486 if (!inet_ntop(dst->ss_family, &((struct sockaddr_in6 *)dst)->sin6_addr, buf + ret, buf_len - ret))
487 return 0;
488
489 ret += strlen(buf + ret);
490 if (ret >= buf_len)
491 return 0;
492
493 /* source and destination ports */
494 ret += snprintf(buf + ret, buf_len - ret, " %u %u\r\n",
495 ntohs(((struct sockaddr_in6 *)src)->sin6_port),
496 ntohs(((struct sockaddr_in6 *)dst)->sin6_port));
497 if (ret >= buf_len)
498 return 0;
499 }
500 else {
501 /* unknown family combination */
502 ret = snprintf(buf, buf_len, "PROXY UNKNOWN\r\n");
503 if (ret >= buf_len)
504 return 0;
505 }
506 return ret;
507}
508
Willy Tarreaua5e37562011-12-16 17:06:15 +0100509/* set temp integer to the id of the frontend */
Willy Tarreaud41f8d82007-06-10 10:06:18 +0200510static int
Willy Tarreau32a6f2e2012-04-25 10:13:36 +0200511acl_fetch_fe_id(struct proxy *px, struct session *l4, void *l7, unsigned int opt,
Willy Tarreau24e32d82012-04-23 23:55:44 +0200512 const struct arg *args, struct sample *smp)
Willy Tarreau37406352012-04-23 16:16:37 +0200513{
Willy Tarreauf853c462012-04-23 18:53:56 +0200514 smp->flags = SMP_F_VOL_SESS;
515 smp->type = SMP_T_UINT;
516 smp->data.uint = l4->fe->uuid;
Emeric Brun5d16eda2010-01-04 15:47:45 +0100517 return 1;
518}
519
Willy Tarreau34db1082012-04-19 17:16:54 +0200520/* set temp integer to the number of connections per second reaching the frontend.
Willy Tarreau0146c2e2012-04-20 11:37:56 +0200521 * Accepts exactly 1 argument. Argument is a frontend, other types will cause
Willy Tarreau34db1082012-04-19 17:16:54 +0200522 * an undefined behaviour.
523 */
Willy Tarreaud41f8d82007-06-10 10:06:18 +0200524static int
Willy Tarreau32a6f2e2012-04-25 10:13:36 +0200525acl_fetch_fe_sess_rate(struct proxy *px, struct session *l4, void *l7, unsigned int opt,
Willy Tarreau24e32d82012-04-23 23:55:44 +0200526 const struct arg *args, struct sample *smp)
Willy Tarreau662b2d82007-05-08 19:56:15 +0200527{
Willy Tarreau37406352012-04-23 16:16:37 +0200528 smp->flags = SMP_F_VOL_TEST;
Willy Tarreauf853c462012-04-23 18:53:56 +0200529 smp->type = SMP_T_UINT;
Willy Tarreau24e32d82012-04-23 23:55:44 +0200530 smp->data.uint = read_freq_ctr(&args->data.prx->fe_sess_per_sec);
Emeric Brun5d16eda2010-01-04 15:47:45 +0100531 return 1;
532}
Alexandre Cassen5eb1a902007-11-29 15:43:32 +0100533
Willy Tarreau34db1082012-04-19 17:16:54 +0200534/* set temp integer to the number of concurrent connections on the frontend
Willy Tarreau0146c2e2012-04-20 11:37:56 +0200535 * Accepts exactly 1 argument. Argument is a frontend, other types will cause
Willy Tarreau34db1082012-04-19 17:16:54 +0200536 * an undefined behaviour.
537 */
Willy Tarreaud41f8d82007-06-10 10:06:18 +0200538static int
Willy Tarreau32a6f2e2012-04-25 10:13:36 +0200539acl_fetch_fe_conn(struct proxy *px, struct session *l4, void *l7, unsigned int opt,
Willy Tarreau24e32d82012-04-23 23:55:44 +0200540 const struct arg *args, struct sample *smp)
Willy Tarreau8797c062007-05-07 00:55:35 +0200541{
Willy Tarreau37406352012-04-23 16:16:37 +0200542 smp->flags = SMP_F_VOL_TEST;
Willy Tarreauf853c462012-04-23 18:53:56 +0200543 smp->type = SMP_T_UINT;
Willy Tarreau24e32d82012-04-23 23:55:44 +0200544 smp->data.uint = args->data.prx->feconn;
Krzysztof Piotr Oledzki346f76d2010-01-12 21:59:30 +0100545 return 1;
546}
547
Willy Tarreau8797c062007-05-07 00:55:35 +0200548
Willy Tarreau61612d42012-04-19 18:42:05 +0200549/* Note: must not be declared <const> as its list will be overwritten.
550 * Please take care of keeping this list alphabetically sorted.
551 */
Willy Tarreau8797c062007-05-07 00:55:35 +0200552static struct acl_kw_list acl_kws = {{ },{
Willy Tarreaufc2c1fd2012-04-19 23:35:54 +0200553 { "fe_conn", acl_parse_int, acl_fetch_fe_conn, acl_match_int, ACL_USE_NOTHING, ARG1(1,FE) },
Willy Tarreau61612d42012-04-19 18:42:05 +0200554 { "fe_id", acl_parse_int, acl_fetch_fe_id, acl_match_int, ACL_USE_NOTHING, 0 },
Willy Tarreaufc2c1fd2012-04-19 23:35:54 +0200555 { "fe_sess_rate", acl_parse_int, acl_fetch_fe_sess_rate, acl_match_int, ACL_USE_NOTHING, ARG1(1,FE) },
Willy Tarreau8797c062007-05-07 00:55:35 +0200556 { NULL, NULL, NULL, NULL },
557}};
558
559
560__attribute__((constructor))
Willy Tarreau03fa5df2010-05-24 21:02:37 +0200561static void __frontend_init(void)
Willy Tarreau8797c062007-05-07 00:55:35 +0200562{
563 acl_register_keywords(&acl_kws);
564}
565
566
Willy Tarreaubaaee002006-06-26 02:48:02 +0200567/*
568 * Local variables:
569 * c-indent-level: 8
570 * c-basic-offset: 8
571 * End:
572 */