Repository navigation
Expand file tree
/
Copy pathaihttps.h
More file actions
154 lines (125 loc) · 4.4 KB
/
Copy pathaihttps.h
File metadata and controls
154 lines (125 loc) · 4.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
/*
* This program is free software; you can redistribute it and/or
* modify it under the terms of the GNU General Public License
* as published by the Free Software Foundation; either version 2
* of the License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* For more ,please contact QQ/wechat:4108863 mail:4108863@qq.com
*/
#ifndef AIHTTPS_H_INCLUDED
#define AIHTTPS_H_INCLUDED
#include "config.h"
#include <arpa/inet.h>
#include "ev.h"
#include <stdio.h>
#include <syslog.h>
#include <sys/types.h>
#include <sys/ioctl.h>
#include <openssl/asn1.h>
#include <openssl/engine.h>
#include <openssl/evp.h>
#include <openssl/err.h>
#include <openssl/ssl.h>
#include <openssl/ocsp.h>
#include <openssl/x509.h>
#include <openssl/x509v3.h>
#include "asn_gentm.h"
#include "configuration.h"
#include "ringbuffer.h"
#include "foreign/miniobj.h"
#include "foreign/vas.h"
#include "foreign/vsb.h"
#include "waf/httpx.h"
#include "waf/mqtt.h"
typedef struct sslstaple_s sslstaple;
struct sni_name_s;
VTAILQ_HEAD(sni_name_head, sni_name_s);
/* SSL contexts. */
struct sslctx_s {
unsigned magic;
#define SSLCTX_MAGIC 0xcd1ce5ff
char *filename;
SSL_CTX *ctx;
double mtim;
sslstaple *staple;
int staple_vfy;
char *staple_fn;
X509 *x509;
ev_stat *ev_staple;
struct sni_name_head sni_list;
UT_hash_handle hh;
};
typedef struct sslctx_s sslctx;
#ifndef OPENSSL_NO_TLSEXT
struct sslstaple_s {
unsigned magic;
#define SSLSTAPLE_MAGIC 0x20fe53fd
unsigned char *staple;
double mtim;
double nextupd;
int len;
};
/* SNI lookup objects */
typedef struct sni_name_s {
unsigned magic;
#define SNI_NAME_MAGIC 0xb0626581
char *servername;
sslctx *sctx;
int is_wildcard;
VTAILQ_ENTRY(sni_name_s) list;
UT_hash_handle hh;
} sni_name;
sni_name *sni_names;
#endif /* OPENSSL_NO_TLSEXT */
struct backend;
/*
* Proxied State
*
* All state associated with one proxied connection
*/
typedef struct proxystate {
unsigned magic;
#define PROXYSTATE_MAGIC 0xcf877ed9
ringbuffer ring_ssl2clear; /* Pushing bytes from
* secure to clear
* stream */
ringbuffer ring_clear2ssl; /* Pushing bytes from
* clear to secure
* stream */
ev_io ev_r_ssl; /* Secure stream write event */
ev_io ev_w_ssl; /* Secure stream read event */
ev_io ev_r_handshake; /* Secure stream handshake
* write event */
ev_io ev_w_handshake; /* Secure stream handshake
* read event */
ev_timer ev_t_handshake; /* handshake timer */
ev_io ev_w_connect; /* Backend connect event */
ev_timer ev_t_connect; /* backend connect timer */
ev_io ev_r_clear; /* Clear stream write event */
ev_io ev_w_clear; /* Clear stream read event */
ev_io ev_proxy; /* proxy read event */
int fd_up; /* Upstream (client) socket */
int fd_down; /* Downstream (backend)
* socket */
struct backend *backend;
int want_shutdown:1; /* Connection is
* half-shutdown */
int handshaked:1; /* Initial handshake happened */
int clear_connected:1; /* Clear stream is
* connected */
int renegotiation:1; /* Renegotation is
* occuring */
int npn_alpn_tried:1;/* NPN or ALPN was tried */
SSL *ssl; /* OpenSSL SSL state */
http_waf_msg *req;
struct sockaddr_storage remote_ip; /* Remote ip returned
* from `accept` */
int connect_port; /* local port for connection */
} proxystate;
X509 * Find_issuer(X509 *subj, STACK_OF(X509) *chain);
#endif /* AIHTTPS_H_INCLUDED */