cjson
.github
workflows CI.yml ci-fuzz.yml
CONTRIBUTING.md
fuzzing
inputs test1 test10 test11 test2 test3 test3.bu test3.uf test3.uu test4 test5 test6 test7 test8 test9
.gitignore CMakeLists.txt afl-prepare-linux.sh afl.c afl.sh cjson_read_fuzzer.c fuzz_main.c json.dict ossfuzz.sh
library_config cJSONConfig.cmake.in cJSONConfigVersion.cmake.in libcjson.pc.in libcjson_utils.pc.in uninstall.cmake
tests
inputs test1 test1.expected test10 test10.expected test11 test11.expected test2 test2.expected test3 test3.expected test4 test4.expected test5 test5.expected test6 test7 test7.expected test8 test8.expected test9 test9.expected
json-patch-tests .editorconfig .gitignore .npmignore README.md cjson-utils-tests.json package.json spec_tests.json tests.json
unity
auto colour_prompt.rb colour_reporter.rb generate_config.yml generate_module.rb generate_test_runner.rb parse_output.rb stylize_as_junit.rb test_file_filter.rb type_sanitizer.rb unity_test_summary.py unity_test_summary.rb unity_to_junit.py
docs ThrowTheSwitchCodingStandard.md UnityAssertionsCheatSheetSuitableforPrintingandPossiblyFraming.pdf UnityAssertionsReference.md UnityConfigurationGuide.md UnityGettingStartedGuide.md UnityHelperScriptsGuide.md license.txt
examples
example_1
src ProductionCode.c ProductionCode.h ProductionCode2.c ProductionCode2.h
makefile readme.txt
example_2
src ProductionCode.c ProductionCode.h ProductionCode2.c ProductionCode2.h
makefile readme.txt
example_3
helper UnityHelper.c UnityHelper.h
src ProductionCode.c ProductionCode.h ProductionCode2.c ProductionCode2.h
rakefile.rb rakefile_helper.rb readme.txt target_gcc_32.yml
unity_config.h
extras
eclipse error_parsers.txt
fixture
src unity_fixture.c unity_fixture.h unity_fixture_internals.h unity_fixture_malloc_overrides.h
rakefile.rb rakefile_helper.rb readme.txt
release build.info version.info
src unity.c unity.h unity_internals.h
.gitattributes .gitignore .travis.yml README.md
CMakeLists.txt cjson_add.c common.h compare_tests.c json_patch_tests.c minify_tests.c misc_tests.c misc_utils_tests.c old_utils_tests.c parse_array.c parse_examples.c parse_hex4.c parse_number.c parse_object.c parse_string.c parse_value.c parse_with_opts.c print_array.c print_number.c print_object.c print_string.c print_value.c readme_examples.c unity_setup.c
.editorconfig .gitattributes .gitignore .travis.yml CHANGELOG.md CMakeLists.txt CONTRIBUTORS.md LICENSE Makefile README.md SECURITY.md appveyor.yml cJSON.c cJSON.h cJSON_Utils.c cJSON_Utils.h test.c valgrind.supp
curl
.circleci config.yml
.github
ISSUE_TEMPLATE bug_report.yml config.yml docs.yml
scripts cleancmd.pl cmp-config.pl cmp-pkg-config.sh codespell-ignore.words codespell.sh distfiles.sh pyspelling.words pyspelling.yaml randcurl.pl requirements-docs.txt requirements-proselint.txt requirements.txt shellcheck-ci.sh shellcheck.sh spellcheck.curl trimmarkdownheader.pl typos.sh typos.toml verify-examples.pl verify-synopsis.pl yamlcheck.sh yamlcheck.yaml
workflows appveyor-status.yml checkdocs.yml checksrc.yml checkurls.yml codeql.yml configure-vs-cmake.yml curl-for-win.yml distcheck.yml fuzz.yml http3-linux.yml label.yml linux-old.yml linux.yml macos.yml non-native.yml windows.yml
CODEOWNERS CONTRIBUTING.md FUNDING.yml dependabot.yml labeler.yml lock.yml stale.yml
CMake CurlSymbolHiding.cmake CurlTests.c FindBrotli.cmake FindCares.cmake FindGSS.cmake FindGnuTLS.cmake FindLDAP.cmake FindLibbacktrace.cmake FindLibgsasl.cmake FindLibidn2.cmake FindLibpsl.cmake FindLibssh.cmake FindLibssh2.cmake FindLibuv.cmake FindMbedTLS.cmake FindNGHTTP2.cmake FindNGHTTP3.cmake FindNGTCP2.cmake FindNettle.cmake FindQuiche.cmake FindRustls.cmake FindWolfSSL.cmake FindZstd.cmake Macros.cmake OtherTests.cmake PickyWarnings.cmake Utilities.cmake cmake_uninstall.in.cmake curl-config.in.cmake unix-cache.cmake win32-cache.cmake
LICENSES BSD-4-Clause-UC.txt ISC.txt curl.txt
docs
cmdline-opts .gitignore CMakeLists.txt MANPAGE.md Makefile.am Makefile.inc _AUTHORS.md _BUGS.md _DESCRIPTION.md _ENVIRONMENT.md _EXITCODES.md _FILES.md _GLOBBING.md _NAME.md _OPTIONS.md _OUTPUT.md _PROGRESS.md _PROTOCOLS.md _PROXYPREFIX.md _SEEALSO.md _SYNOPSIS.md _URL.md _VARIABLES.md _VERSION.md _WWW.md abstract-unix-socket.md alt-svc.md anyauth.md append.md aws-sigv4.md basic.md ca-native.md cacert.md capath.md cert-status.md cert-type.md cert.md ciphers.md compressed-ssh.md compressed.md config.md connect-timeout.md connect-to.md continue-at.md cookie-jar.md cookie.md create-dirs.md create-file-mode.md crlf.md crlfile.md curves.md data-ascii.md data-binary.md data-raw.md data-urlencode.md data.md delegation.md digest.md disable-eprt.md disable-epsv.md disable.md disallow-username-in-url.md dns-interface.md dns-ipv4-addr.md dns-ipv6-addr.md dns-servers.md doh-cert-status.md doh-insecure.md doh-url.md dump-ca-embed.md dump-header.md ech.md egd-file.md engine.md etag-compare.md etag-save.md expect100-timeout.md fail-early.md fail-with-body.md fail.md false-start.md follow.md form-escape.md form-string.md form.md ftp-account.md ftp-alternative-to-user.md ftp-create-dirs.md ftp-method.md ftp-pasv.md ftp-port.md ftp-pret.md ftp-skip-pasv-ip.md ftp-ssl-ccc-mode.md ftp-ssl-ccc.md ftp-ssl-control.md get.md globoff.md happy-eyeballs-timeout-ms.md haproxy-clientip.md haproxy-protocol.md head.md header.md help.md hostpubmd5.md hostpubsha256.md hsts.md http0.9.md http1.0.md http1.1.md http2-prior-knowledge.md http2.md http3-only.md http3.md ignore-content-length.md insecure.md interface.md ip-tos.md ipfs-gateway.md ipv4.md ipv6.md json.md junk-session-cookies.md keepalive-cnt.md keepalive-time.md key-type.md key.md knownhosts.md krb.md libcurl.md limit-rate.md list-only.md local-port.md location-trusted.md location.md login-options.md mail-auth.md mail-from.md mail-rcpt-allowfails.md mail-rcpt.md mainpage.idx manual.md max-filesize.md max-redirs.md max-time.md metalink.md mptcp.md negotiate.md netrc-file.md netrc-optional.md netrc.md next.md no-alpn.md no-buffer.md no-clobber.md no-keepalive.md no-npn.md no-progress-meter.md no-sessionid.md noproxy.md ntlm-wb.md ntlm.md oauth2-bearer.md out-null.md output-dir.md output.md parallel-immediate.md parallel-max-host.md parallel-max.md parallel.md pass.md path-as-is.md pinnedpubkey.md post301.md post302.md post303.md preproxy.md progress-bar.md proto-default.md proto-redir.md proto.md proxy-anyauth.md proxy-basic.md proxy-ca-native.md proxy-cacert.md proxy-capath.md proxy-cert-type.md proxy-cert.md proxy-ciphers.md proxy-crlfile.md proxy-digest.md proxy-header.md proxy-http2.md proxy-insecure.md proxy-key-type.md proxy-key.md proxy-negotiate.md proxy-ntlm.md proxy-pass.md proxy-pinnedpubkey.md proxy-service-name.md proxy-ssl-allow-beast.md proxy-ssl-auto-client-cert.md proxy-tls13-ciphers.md proxy-tlsauthtype.md proxy-tlspassword.md proxy-tlsuser.md proxy-tlsv1.md proxy-user.md proxy.md proxy1.0.md proxytunnel.md pubkey.md quote.md random-file.md range.md rate.md raw.md referer.md remote-header-name.md remote-name-all.md remote-name.md remote-time.md remove-on-error.md request-target.md request.md resolve.md retry-all-errors.md retry-connrefused.md retry-delay.md retry-max-time.md retry.md sasl-authzid.md sasl-ir.md service-name.md show-error.md show-headers.md sigalgs.md silent.md skip-existing.md socks4.md socks4a.md socks5-basic.md socks5-gssapi-nec.md socks5-gssapi-service.md socks5-gssapi.md socks5-hostname.md socks5.md speed-limit.md speed-time.md ssl-allow-beast.md ssl-auto-client-cert.md ssl-no-revoke.md ssl-reqd.md ssl-revoke-best-effort.md ssl-sessions.md ssl.md sslv2.md sslv3.md stderr.md styled-output.md suppress-connect-headers.md tcp-fastopen.md tcp-nodelay.md telnet-option.md tftp-blksize.md tftp-no-options.md time-cond.md tls-earlydata.md tls-max.md tls13-ciphers.md tlsauthtype.md tlspassword.md tlsuser.md tlsv1.0.md tlsv1.1.md tlsv1.2.md tlsv1.3.md tlsv1.md tr-encoding.md trace-ascii.md trace-config.md trace-ids.md trace-time.md trace.md unix-socket.md upload-file.md upload-flags.md url-query.md url.md use-ascii.md user-agent.md user.md variable.md verbose.md version.md vlan-priority.md write-out.md xattr.md
examples .checksrc .gitignore 10-at-a-time.c CMakeLists.txt Makefile.am Makefile.example Makefile.inc README.md adddocsref.pl address-scope.c altsvc.c anyauthput.c block_ip.c cacertinmem.c certinfo.c chkspeed.c connect-to.c cookie_interface.c crawler.c debug.c default-scheme.c ephiperfifo.c evhiperfifo.c externalsocket.c fileupload.c ftp-delete.c ftp-wildcard.c ftpget.c ftpgetinfo.c ftpgetresp.c ftpsget.c ftpupload.c ftpuploadfrommem.c ftpuploadresume.c getinfo.c getinmemory.c getredirect.c getreferrer.c ghiper.c headerapi.c hiperfifo.c hsts-preload.c htmltidy.c htmltitle.cpp http-options.c http-post.c http2-download.c http2-pushinmemory.c http2-serverpush.c http2-upload.c http3-present.c http3.c httpcustomheader.c httpput-postfields.c httpput.c https.c imap-append.c imap-authzid.c imap-copy.c imap-create.c imap-delete.c imap-examine.c imap-fetch.c imap-list.c imap-lsub.c imap-multi.c imap-noop.c imap-search.c imap-ssl.c imap-store.c imap-tls.c interface.c ipv6.c keepalive.c localport.c log_failed_transfers.c maxconnects.c multi-app.c multi-debugcallback.c multi-double.c multi-event.c multi-formadd.c multi-legacy.c multi-post.c multi-single.c multi-uv.c netrc.c parseurl.c persistent.c pop3-authzid.c pop3-dele.c pop3-list.c pop3-multi.c pop3-noop.c pop3-retr.c pop3-ssl.c pop3-stat.c pop3-tls.c pop3-top.c pop3-uidl.c post-callback.c postinmemory.c postit2-formadd.c postit2.c progressfunc.c protofeats.c range.c resolve.c rtsp-options.c sendrecv.c sepheaders.c sessioninfo.c sftpget.c sftpuploadresume.c shared-connection-cache.c simple.c simplepost.c simplessl.c smooth-gtk-thread.c smtp-authzid.c smtp-expn.c smtp-mail.c smtp-mime.c smtp-multi.c smtp-ssl.c smtp-tls.c smtp-vrfy.c sslbackend.c synctime.c threaded.c unixsocket.c url2file.c urlapi.c usercertinmem.c version-check.pl websocket-cb.c websocket-updown.c websocket.c xmlstream.c
internals BUFQ.md BUFREF.md CHECKSRC.md CLIENT-READERS.md CLIENT-WRITERS.md CODE_STYLE.md CONNECTION-FILTERS.md CREDENTIALS.md CURLX.md DYNBUF.md HASH.md LLIST.md MID.md MQTT.md MULTI-EV.md NEW-PROTOCOL.md PEERS.md PORTING.md RATELIMITS.md README.md SCORECARD.md SPLAY.md STRPARSE.md THRDPOOL-AND-QUEUE.md TIME-KEEPING.md TLS-SESSIONS.md UINT_SETS.md WEBSOCKET.md
libcurl
opts CMakeLists.txt CURLINFO_ACTIVESOCKET.md CURLINFO_APPCONNECT_TIME.md CURLINFO_APPCONNECT_TIME_T.md CURLINFO_CAINFO.md CURLINFO_CAPATH.md CURLINFO_CERTINFO.md CURLINFO_CONDITION_UNMET.md CURLINFO_CONNECT_TIME.md CURLINFO_CONNECT_TIME_T.md CURLINFO_CONN_ID.md CURLINFO_CONTENT_LENGTH_DOWNLOAD.md CURLINFO_CONTENT_LENGTH_DOWNLOAD_T.md CURLINFO_CONTENT_LENGTH_UPLOAD.md CURLINFO_CONTENT_LENGTH_UPLOAD_T.md CURLINFO_CONTENT_TYPE.md CURLINFO_COOKIELIST.md CURLINFO_EARLYDATA_SENT_T.md CURLINFO_EFFECTIVE_METHOD.md CURLINFO_EFFECTIVE_URL.md CURLINFO_FILETIME.md CURLINFO_FILETIME_T.md CURLINFO_FTP_ENTRY_PATH.md CURLINFO_HEADER_SIZE.md CURLINFO_HTTPAUTH_AVAIL.md CURLINFO_HTTPAUTH_USED.md CURLINFO_HTTP_CONNECTCODE.md CURLINFO_HTTP_VERSION.md CURLINFO_LASTSOCKET.md CURLINFO_LOCAL_IP.md CURLINFO_LOCAL_PORT.md CURLINFO_NAMELOOKUP_TIME.md CURLINFO_NAMELOOKUP_TIME_T.md CURLINFO_NUM_CONNECTS.md CURLINFO_OS_ERRNO.md CURLINFO_POSTTRANSFER_TIME_T.md CURLINFO_PRETRANSFER_TIME.md CURLINFO_PRETRANSFER_TIME_T.md CURLINFO_PRIMARY_IP.md CURLINFO_PRIMARY_PORT.md CURLINFO_PRIVATE.md CURLINFO_PROTOCOL.md CURLINFO_PROXYAUTH_AVAIL.md CURLINFO_PROXYAUTH_USED.md CURLINFO_PROXY_ERROR.md CURLINFO_PROXY_SSL_VERIFYRESULT.md CURLINFO_QUEUE_TIME_T.md CURLINFO_REDIRECT_COUNT.md CURLINFO_REDIRECT_TIME.md CURLINFO_REDIRECT_TIME_T.md CURLINFO_REDIRECT_URL.md CURLINFO_REFERER.md CURLINFO_REQUEST_SIZE.md CURLINFO_RESPONSE_CODE.md CURLINFO_RETRY_AFTER.md CURLINFO_RTSP_CLIENT_CSEQ.md CURLINFO_RTSP_CSEQ_RECV.md CURLINFO_RTSP_SERVER_CSEQ.md CURLINFO_RTSP_SESSION_ID.md CURLINFO_SCHEME.md CURLINFO_SIZE_DELIVERED.md CURLINFO_SIZE_DOWNLOAD.md CURLINFO_SIZE_DOWNLOAD_T.md CURLINFO_SIZE_UPLOAD.md CURLINFO_SIZE_UPLOAD_T.md CURLINFO_SPEED_DOWNLOAD.md CURLINFO_SPEED_DOWNLOAD_T.md CURLINFO_SPEED_UPLOAD.md CURLINFO_SPEED_UPLOAD_T.md CURLINFO_SSL_ENGINES.md CURLINFO_SSL_VERIFYRESULT.md CURLINFO_STARTTRANSFER_TIME.md CURLINFO_STARTTRANSFER_TIME_T.md CURLINFO_TLS_SESSION.md CURLINFO_TLS_SSL_PTR.md CURLINFO_TOTAL_TIME.md CURLINFO_TOTAL_TIME_T.md CURLINFO_USED_PROXY.md CURLINFO_XFER_ID.md CURLMINFO_XFERS_ADDED.md CURLMINFO_XFERS_CURRENT.md CURLMINFO_XFERS_DONE.md CURLMINFO_XFERS_PENDING.md CURLMINFO_XFERS_RUNNING.md CURLMOPT_CHUNK_LENGTH_PENALTY_SIZE.md CURLMOPT_CONTENT_LENGTH_PENALTY_SIZE.md CURLMOPT_MAXCONNECTS.md CURLMOPT_MAX_CONCURRENT_STREAMS.md CURLMOPT_MAX_HOST_CONNECTIONS.md CURLMOPT_MAX_PIPELINE_LENGTH.md CURLMOPT_MAX_TOTAL_CONNECTIONS.md CURLMOPT_NETWORK_CHANGED.md CURLMOPT_NOTIFYDATA.md CURLMOPT_NOTIFYFUNCTION.md CURLMOPT_PIPELINING.md CURLMOPT_PIPELINING_SERVER_BL.md CURLMOPT_PIPELINING_SITE_BL.md CURLMOPT_PUSHDATA.md CURLMOPT_PUSHFUNCTION.md CURLMOPT_QUICK_EXIT.md CURLMOPT_RESOLVE_THREADS_MAX.md CURLMOPT_SOCKETDATA.md CURLMOPT_SOCKETFUNCTION.md CURLMOPT_TIMERDATA.md CURLMOPT_TIMERFUNCTION.md CURLOPT_ABSTRACT_UNIX_SOCKET.md CURLOPT_ACCEPTTIMEOUT_MS.md CURLOPT_ACCEPT_ENCODING.md CURLOPT_ADDRESS_SCOPE.md CURLOPT_ALTSVC.md CURLOPT_ALTSVC_CTRL.md CURLOPT_APPEND.md CURLOPT_AUTOREFERER.md CURLOPT_AWS_SIGV4.md CURLOPT_BUFFERSIZE.md CURLOPT_CAINFO.md CURLOPT_CAINFO_BLOB.md CURLOPT_CAPATH.md CURLOPT_CA_CACHE_TIMEOUT.md CURLOPT_CERTINFO.md CURLOPT_CHUNK_BGN_FUNCTION.md CURLOPT_CHUNK_DATA.md CURLOPT_CHUNK_END_FUNCTION.md CURLOPT_CLOSESOCKETDATA.md CURLOPT_CLOSESOCKETFUNCTION.md CURLOPT_CONNECTTIMEOUT.md CURLOPT_CONNECTTIMEOUT_MS.md CURLOPT_CONNECT_ONLY.md CURLOPT_CONNECT_TO.md CURLOPT_CONV_FROM_NETWORK_FUNCTION.md CURLOPT_CONV_FROM_UTF8_FUNCTION.md CURLOPT_CONV_TO_NETWORK_FUNCTION.md CURLOPT_COOKIE.md CURLOPT_COOKIEFILE.md CURLOPT_COOKIEJAR.md CURLOPT_COOKIELIST.md CURLOPT_COOKIESESSION.md CURLOPT_COPYPOSTFIELDS.md CURLOPT_CRLF.md CURLOPT_CRLFILE.md CURLOPT_CURLU.md CURLOPT_CUSTOMREQUEST.md CURLOPT_DEBUGDATA.md CURLOPT_DEBUGFUNCTION.md CURLOPT_DEFAULT_PROTOCOL.md CURLOPT_DIRLISTONLY.md CURLOPT_DISALLOW_USERNAME_IN_URL.md CURLOPT_DNS_CACHE_TIMEOUT.md CURLOPT_DNS_INTERFACE.md CURLOPT_DNS_LOCAL_IP4.md CURLOPT_DNS_LOCAL_IP6.md CURLOPT_DNS_SERVERS.md CURLOPT_DNS_SHUFFLE_ADDRESSES.md CURLOPT_DNS_USE_GLOBAL_CACHE.md CURLOPT_DOH_SSL_VERIFYHOST.md CURLOPT_DOH_SSL_VERIFYPEER.md CURLOPT_DOH_SSL_VERIFYSTATUS.md CURLOPT_DOH_URL.md CURLOPT_ECH.md CURLOPT_EGDSOCKET.md CURLOPT_ERRORBUFFER.md CURLOPT_EXPECT_100_TIMEOUT_MS.md CURLOPT_FAILONERROR.md CURLOPT_FILETIME.md CURLOPT_FNMATCH_DATA.md CURLOPT_FNMATCH_FUNCTION.md CURLOPT_FOLLOWLOCATION.md CURLOPT_FORBID_REUSE.md CURLOPT_FRESH_CONNECT.md CURLOPT_FTPPORT.md CURLOPT_FTPSSLAUTH.md CURLOPT_FTP_ACCOUNT.md CURLOPT_FTP_ALTERNATIVE_TO_USER.md CURLOPT_FTP_CREATE_MISSING_DIRS.md CURLOPT_FTP_FILEMETHOD.md CURLOPT_FTP_SKIP_PASV_IP.md CURLOPT_FTP_SSL_CCC.md CURLOPT_FTP_USE_EPRT.md CURLOPT_FTP_USE_EPSV.md CURLOPT_FTP_USE_PRET.md CURLOPT_GSSAPI_DELEGATION.md CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS.md CURLOPT_HAPROXYPROTOCOL.md CURLOPT_HAPROXY_CLIENT_IP.md CURLOPT_HEADER.md CURLOPT_HEADERDATA.md CURLOPT_HEADERFUNCTION.md CURLOPT_HEADEROPT.md CURLOPT_HSTS.md CURLOPT_HSTSREADDATA.md CURLOPT_HSTSREADFUNCTION.md CURLOPT_HSTSWRITEDATA.md CURLOPT_HSTSWRITEFUNCTION.md CURLOPT_HSTS_CTRL.md CURLOPT_HTTP09_ALLOWED.md CURLOPT_HTTP200ALIASES.md CURLOPT_HTTPAUTH.md CURLOPT_HTTPGET.md CURLOPT_HTTPHEADER.md CURLOPT_HTTPPOST.md CURLOPT_HTTPPROXYTUNNEL.md CURLOPT_HTTP_CONTENT_DECODING.md CURLOPT_HTTP_TRANSFER_DECODING.md CURLOPT_HTTP_VERSION.md CURLOPT_IGNORE_CONTENT_LENGTH.md CURLOPT_INFILESIZE.md CURLOPT_INFILESIZE_LARGE.md CURLOPT_INTERFACE.md CURLOPT_INTERLEAVEDATA.md CURLOPT_INTERLEAVEFUNCTION.md CURLOPT_IOCTLDATA.md CURLOPT_IOCTLFUNCTION.md CURLOPT_IPRESOLVE.md CURLOPT_ISSUERCERT.md CURLOPT_ISSUERCERT_BLOB.md CURLOPT_KEEP_SENDING_ON_ERROR.md CURLOPT_KEYPASSWD.md CURLOPT_KRBLEVEL.md CURLOPT_LOCALPORT.md CURLOPT_LOCALPORTRANGE.md CURLOPT_LOGIN_OPTIONS.md CURLOPT_LOW_SPEED_LIMIT.md CURLOPT_LOW_SPEED_TIME.md CURLOPT_MAIL_AUTH.md CURLOPT_MAIL_FROM.md CURLOPT_MAIL_RCPT.md CURLOPT_MAIL_RCPT_ALLOWFAILS.md CURLOPT_MAXAGE_CONN.md CURLOPT_MAXCONNECTS.md CURLOPT_MAXFILESIZE.md CURLOPT_MAXFILESIZE_LARGE.md CURLOPT_MAXLIFETIME_CONN.md CURLOPT_MAXREDIRS.md CURLOPT_MAX_RECV_SPEED_LARGE.md CURLOPT_MAX_SEND_SPEED_LARGE.md CURLOPT_MIMEPOST.md CURLOPT_MIME_OPTIONS.md CURLOPT_NETRC.md CURLOPT_NETRC_FILE.md CURLOPT_NEW_DIRECTORY_PERMS.md CURLOPT_NEW_FILE_PERMS.md CURLOPT_NOBODY.md CURLOPT_NOPROGRESS.md CURLOPT_NOPROXY.md CURLOPT_NOSIGNAL.md CURLOPT_OPENSOCKETDATA.md CURLOPT_OPENSOCKETFUNCTION.md CURLOPT_PASSWORD.md CURLOPT_PATH_AS_IS.md CURLOPT_PINNEDPUBLICKEY.md CURLOPT_PIPEWAIT.md CURLOPT_PORT.md CURLOPT_POST.md CURLOPT_POSTFIELDS.md CURLOPT_POSTFIELDSIZE.md CURLOPT_POSTFIELDSIZE_LARGE.md CURLOPT_POSTQUOTE.md CURLOPT_POSTREDIR.md CURLOPT_PREQUOTE.md CURLOPT_PREREQDATA.md CURLOPT_PREREQFUNCTION.md CURLOPT_PRE_PROXY.md CURLOPT_PRIVATE.md CURLOPT_PROGRESSDATA.md CURLOPT_PROGRESSFUNCTION.md CURLOPT_PROTOCOLS.md CURLOPT_PROTOCOLS_STR.md CURLOPT_PROXY.md CURLOPT_PROXYAUTH.md CURLOPT_PROXYHEADER.md CURLOPT_PROXYPASSWORD.md CURLOPT_PROXYPORT.md CURLOPT_PROXYTYPE.md CURLOPT_PROXYUSERNAME.md CURLOPT_PROXYUSERPWD.md CURLOPT_PROXY_CAINFO.md CURLOPT_PROXY_CAINFO_BLOB.md CURLOPT_PROXY_CAPATH.md CURLOPT_PROXY_CRLFILE.md CURLOPT_PROXY_ISSUERCERT.md CURLOPT_PROXY_ISSUERCERT_BLOB.md CURLOPT_PROXY_KEYPASSWD.md CURLOPT_PROXY_PINNEDPUBLICKEY.md CURLOPT_PROXY_SERVICE_NAME.md CURLOPT_PROXY_SSLCERT.md CURLOPT_PROXY_SSLCERTTYPE.md CURLOPT_PROXY_SSLCERT_BLOB.md CURLOPT_PROXY_SSLKEY.md CURLOPT_PROXY_SSLKEYTYPE.md CURLOPT_PROXY_SSLKEY_BLOB.md CURLOPT_PROXY_SSLVERSION.md CURLOPT_PROXY_SSL_CIPHER_LIST.md CURLOPT_PROXY_SSL_OPTIONS.md CURLOPT_PROXY_SSL_VERIFYHOST.md CURLOPT_PROXY_SSL_VERIFYPEER.md CURLOPT_PROXY_TLS13_CIPHERS.md CURLOPT_PROXY_TLSAUTH_PASSWORD.md CURLOPT_PROXY_TLSAUTH_TYPE.md CURLOPT_PROXY_TLSAUTH_USERNAME.md CURLOPT_PROXY_TRANSFER_MODE.md CURLOPT_PUT.md CURLOPT_QUICK_EXIT.md CURLOPT_QUOTE.md CURLOPT_RANDOM_FILE.md CURLOPT_RANGE.md CURLOPT_READDATA.md CURLOPT_READFUNCTION.md CURLOPT_REDIR_PROTOCOLS.md CURLOPT_REDIR_PROTOCOLS_STR.md CURLOPT_REFERER.md CURLOPT_REQUEST_TARGET.md CURLOPT_RESOLVE.md CURLOPT_RESOLVER_START_DATA.md CURLOPT_RESOLVER_START_FUNCTION.md CURLOPT_RESUME_FROM.md CURLOPT_RESUME_FROM_LARGE.md CURLOPT_RTSP_CLIENT_CSEQ.md CURLOPT_RTSP_REQUEST.md CURLOPT_RTSP_SERVER_CSEQ.md CURLOPT_RTSP_SESSION_ID.md CURLOPT_RTSP_STREAM_URI.md CURLOPT_RTSP_TRANSPORT.md CURLOPT_SASL_AUTHZID.md CURLOPT_SASL_IR.md CURLOPT_SEEKDATA.md CURLOPT_SEEKFUNCTION.md CURLOPT_SERVER_RESPONSE_TIMEOUT.md CURLOPT_SERVER_RESPONSE_TIMEOUT_MS.md CURLOPT_SERVICE_NAME.md CURLOPT_SHARE.md CURLOPT_SOCKOPTDATA.md CURLOPT_SOCKOPTFUNCTION.md CURLOPT_SOCKS5_AUTH.md CURLOPT_SOCKS5_GSSAPI_NEC.md CURLOPT_SOCKS5_GSSAPI_SERVICE.md CURLOPT_SSH_AUTH_TYPES.md CURLOPT_SSH_COMPRESSION.md CURLOPT_SSH_HOSTKEYDATA.md CURLOPT_SSH_HOSTKEYFUNCTION.md CURLOPT_SSH_HOST_PUBLIC_KEY_MD5.md CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256.md CURLOPT_SSH_KEYDATA.md CURLOPT_SSH_KEYFUNCTION.md CURLOPT_SSH_KNOWNHOSTS.md CURLOPT_SSH_PRIVATE_KEYFILE.md CURLOPT_SSH_PUBLIC_KEYFILE.md CURLOPT_SSLCERT.md CURLOPT_SSLCERTTYPE.md CURLOPT_SSLCERT_BLOB.md CURLOPT_SSLENGINE.md CURLOPT_SSLENGINE_DEFAULT.md CURLOPT_SSLKEY.md CURLOPT_SSLKEYTYPE.md CURLOPT_SSLKEY_BLOB.md CURLOPT_SSLVERSION.md CURLOPT_SSL_CIPHER_LIST.md CURLOPT_SSL_CTX_DATA.md CURLOPT_SSL_CTX_FUNCTION.md CURLOPT_SSL_EC_CURVES.md CURLOPT_SSL_ENABLE_ALPN.md CURLOPT_SSL_ENABLE_NPN.md CURLOPT_SSL_FALSESTART.md CURLOPT_SSL_OPTIONS.md CURLOPT_SSL_SESSIONID_CACHE.md CURLOPT_SSL_SIGNATURE_ALGORITHMS.md CURLOPT_SSL_VERIFYHOST.md CURLOPT_SSL_VERIFYPEER.md CURLOPT_SSL_VERIFYSTATUS.md CURLOPT_STDERR.md CURLOPT_STREAM_DEPENDS.md CURLOPT_STREAM_DEPENDS_E.md CURLOPT_STREAM_WEIGHT.md CURLOPT_SUPPRESS_CONNECT_HEADERS.md CURLOPT_TCP_FASTOPEN.md CURLOPT_TCP_KEEPALIVE.md CURLOPT_TCP_KEEPCNT.md CURLOPT_TCP_KEEPIDLE.md CURLOPT_TCP_KEEPINTVL.md CURLOPT_TCP_NODELAY.md CURLOPT_TELNETOPTIONS.md CURLOPT_TFTP_BLKSIZE.md CURLOPT_TFTP_NO_OPTIONS.md CURLOPT_TIMECONDITION.md CURLOPT_TIMEOUT.md CURLOPT_TIMEOUT_MS.md CURLOPT_TIMEVALUE.md CURLOPT_TIMEVALUE_LARGE.md CURLOPT_TLS13_CIPHERS.md CURLOPT_TLSAUTH_PASSWORD.md CURLOPT_TLSAUTH_TYPE.md CURLOPT_TLSAUTH_USERNAME.md CURLOPT_TRAILERDATA.md CURLOPT_TRAILERFUNCTION.md CURLOPT_TRANSFERTEXT.md CURLOPT_TRANSFER_ENCODING.md CURLOPT_UNIX_SOCKET_PATH.md CURLOPT_UNRESTRICTED_AUTH.md CURLOPT_UPKEEP_INTERVAL_MS.md CURLOPT_UPLOAD.md CURLOPT_UPLOAD_BUFFERSIZE.md CURLOPT_UPLOAD_FLAGS.md CURLOPT_URL.md CURLOPT_USERAGENT.md CURLOPT_USERNAME.md CURLOPT_USERPWD.md CURLOPT_USE_SSL.md CURLOPT_VERBOSE.md CURLOPT_WILDCARDMATCH.md CURLOPT_WRITEDATA.md CURLOPT_WRITEFUNCTION.md CURLOPT_WS_OPTIONS.md CURLOPT_XFERINFODATA.md CURLOPT_XFERINFOFUNCTION.md CURLOPT_XOAUTH2_BEARER.md CURLSHOPT_LOCKFUNC.md CURLSHOPT_SHARE.md CURLSHOPT_UNLOCKFUNC.md CURLSHOPT_UNSHARE.md CURLSHOPT_USERDATA.md Makefile.am Makefile.inc
.gitignore ABI.md CMakeLists.txt Makefile.am Makefile.inc curl_easy_cleanup.md curl_easy_duphandle.md curl_easy_escape.md curl_easy_getinfo.md curl_easy_header.md curl_easy_init.md curl_easy_nextheader.md curl_easy_option_by_id.md curl_easy_option_by_name.md curl_easy_option_next.md curl_easy_pause.md curl_easy_perform.md curl_easy_recv.md curl_easy_reset.md curl_easy_send.md curl_easy_setopt.md curl_easy_ssls_export.md curl_easy_ssls_import.md curl_easy_strerror.md curl_easy_unescape.md curl_easy_upkeep.md curl_escape.md curl_formadd.md curl_formfree.md curl_formget.md curl_free.md curl_getdate.md curl_getenv.md curl_global_cleanup.md curl_global_init.md curl_global_init_mem.md curl_global_sslset.md curl_global_trace.md curl_mime_addpart.md curl_mime_data.md curl_mime_data_cb.md curl_mime_encoder.md curl_mime_filedata.md curl_mime_filename.md curl_mime_free.md curl_mime_headers.md curl_mime_init.md curl_mime_name.md curl_mime_subparts.md curl_mime_type.md curl_mprintf.md curl_multi_add_handle.md curl_multi_assign.md curl_multi_cleanup.md curl_multi_fdset.md curl_multi_get_handles.md curl_multi_get_offt.md curl_multi_info_read.md curl_multi_init.md curl_multi_notify_disable.md curl_multi_notify_enable.md curl_multi_perform.md curl_multi_poll.md curl_multi_remove_handle.md curl_multi_setopt.md curl_multi_socket.md curl_multi_socket_action.md curl_multi_socket_all.md curl_multi_strerror.md curl_multi_timeout.md curl_multi_wait.md curl_multi_waitfds.md curl_multi_wakeup.md curl_pushheader_byname.md curl_pushheader_bynum.md curl_share_cleanup.md curl_share_init.md curl_share_setopt.md curl_share_strerror.md curl_slist_append.md curl_slist_free_all.md curl_strequal.md curl_strnequal.md curl_unescape.md curl_url.md curl_url_cleanup.md curl_url_dup.md curl_url_get.md curl_url_set.md curl_url_strerror.md curl_version.md curl_version_info.md curl_ws_meta.md curl_ws_recv.md curl_ws_send.md curl_ws_start_frame.md libcurl-easy.md libcurl-env-dbg.md libcurl-env.md libcurl-errors.md libcurl-multi.md libcurl-security.md libcurl-share.md libcurl-thread.md libcurl-tutorial.md libcurl-url.md libcurl-ws.md libcurl.m4 libcurl.md mksymbolsmanpage.pl symbols-in-versions symbols.pl
tests CI.md FILEFORMAT.md HTTP.md TEST-SUITE.md
.gitignore ALTSVC.md BINDINGS.md BUG-BOUNTY.md BUGS.md CIPHERS-TLS12.md CIPHERS.md CMakeLists.txt CODE_OF_CONDUCT.md CODE_REVIEW.md CONTRIBUTE.md CURL-DISABLE.md CURLDOWN.md DEPRECATE.md DISTROS.md EARLY-RELEASE.md ECH.md EXPERIMENTAL.md FAQ.md FEATURES.md GOVERNANCE.md HELP-US.md HISTORY.md HSTS.md HTTP-COOKIES.md HTTP3.md HTTPSRR.md INFRASTRUCTURE.md INSTALL-CMAKE.md INSTALL.md INTERNALS.md IPFS.md KNOWN_BUGS.md KNOWN_RISKS.md MAIL-ETIQUETTE.md MANUAL.md Makefile.am README.md RELEASE-PROCEDURE.md ROADMAP.md RUSTLS.md SECURITY-ADVISORY.md SPONSORS.md SSL-PROBLEMS.md SSLCERTS.md THANKS THANKS-filter TODO.md TheArtOfHttpScripting.md URL-SYNTAX.md VERIFY.md VERSIONS.md VULN-DISCLOSURE-POLICY.md curl-config.md mk-ca-bundle.md options-in-versions runtests.md testcurl.md wcurl.md
include
curl Makefile.am curl.h curlver.h easy.h header.h mprintf.h multi.h options.h stdcheaders.h system.h typecheck-gcc.h urlapi.h websockets.h
Makefile.am README.md
lib
curlx base64.c base64.h basename.c basename.h dynbuf.c dynbuf.h fopen.c fopen.h inet_ntop.c inet_ntop.h inet_pton.c inet_pton.h multibyte.c multibyte.h nonblock.c nonblock.h snprintf.c snprintf.h strcopy.c strcopy.h strdup.c strdup.h strerr.c strerr.h strparse.c strparse.h timediff.c timediff.h timeval.c timeval.h version_win32.c version_win32.h wait.c wait.h warnless.c warnless.h winapi.c winapi.h
vauth cleartext.c cram.c digest.c digest.h digest_sspi.c gsasl.c krb5_gssapi.c krb5_sspi.c ntlm.c ntlm_sspi.c oauth2.c spnego_gssapi.c spnego_sspi.c vauth.c vauth.h
vquic curl_ngtcp2.c curl_ngtcp2.h curl_quiche.c curl_quiche.h vquic-tls.c vquic-tls.h vquic.c vquic.h vquic_int.h
vssh libssh.c libssh2.c ssh.h vssh.c vssh.h
vtls apple.c apple.h cipher_suite.c cipher_suite.h gtls.c gtls.h hostcheck.c hostcheck.h keylog.c keylog.h mbedtls.c mbedtls.h openssl.c openssl.h rustls.c rustls.h schannel.c schannel.h schannel_int.h schannel_verify.c vtls.c vtls.h vtls_int.h vtls_scache.c vtls_scache.h vtls_spack.c vtls_spack.h wolfssl.c wolfssl.h x509asn1.c x509asn1.h
.gitignore CMakeLists.txt Makefile.am Makefile.inc Makefile.soname altsvc.c altsvc.h amigaos.c amigaos.h arpa_telnet.h asyn-ares.c asyn-base.c asyn-thrdd.c asyn.h bufq.c bufq.h bufref.c bufref.h cf-dns.c cf-dns.h cf-h1-proxy.c cf-h1-proxy.h cf-h2-proxy.c cf-h2-proxy.h cf-haproxy.c cf-haproxy.h cf-https-connect.c cf-https-connect.h cf-ip-happy.c cf-ip-happy.h cf-socket.c cf-socket.h cfilters.c cfilters.h config-mac.h config-os400.h config-riscos.h config-win32.h conncache.c conncache.h connect.c connect.h content_encoding.c content_encoding.h cookie.c cookie.h creds.c creds.h cshutdn.c cshutdn.h curl_addrinfo.c curl_addrinfo.h curl_config-cmake.h.in curl_ctype.h curl_endian.c curl_endian.h curl_fnmatch.c curl_fnmatch.h curl_fopen.c curl_fopen.h curl_get_line.c curl_get_line.h curl_gethostname.c curl_gethostname.h curl_gssapi.c curl_gssapi.h curl_hmac.h curl_ldap.h curl_md4.h curl_md5.h curl_memrchr.c curl_memrchr.h curl_ntlm_core.c curl_ntlm_core.h curl_printf.h curl_range.c curl_range.h curl_sasl.c curl_sasl.h curl_setup.h curl_sha256.h curl_sha512_256.c curl_sha512_256.h curl_share.c curl_share.h curl_sspi.c curl_sspi.h curl_threads.c curl_threads.h curl_trc.c curl_trc.h cw-out.c cw-out.h cw-pause.c cw-pause.h dict.c dict.h dllmain.c dnscache.c dnscache.h doh.c doh.h dynhds.c dynhds.h easy.c easy_lock.h easygetopt.c easyif.h easyoptions.c easyoptions.h escape.c escape.h fake_addrinfo.c fake_addrinfo.h file.c file.h fileinfo.c fileinfo.h formdata.c formdata.h ftp-int.h ftp.c ftp.h ftplistparser.c ftplistparser.h functypes.h getenv.c getinfo.c getinfo.h gopher.c gopher.h hash.c hash.h headers.c headers.h hmac.c hostip.c hostip.h hostip4.c hostip6.c hsts.c hsts.h http.c http.h http1.c http1.h http2.c http2.h http_aws_sigv4.c http_aws_sigv4.h http_chunks.c http_chunks.h http_digest.c http_digest.h http_negotiate.c http_negotiate.h http_ntlm.c http_ntlm.h http_proxy.c http_proxy.h httpsrr.c httpsrr.h idn.c idn.h if2ip.c if2ip.h imap.c imap.h ldap.c libcurl.def libcurl.rc libcurl.vers.in llist.c llist.h macos.c macos.h md4.c md5.c memdebug.c mime.c mime.h mprintf.c mqtt.c mqtt.h multi.c multi_ev.c multi_ev.h multi_ntfy.c multi_ntfy.h multihandle.h multiif.h netrc.c netrc.h noproxy.c noproxy.h openldap.c optiontable.pl parsedate.c parsedate.h peer.c peer.h pingpong.c pingpong.h pop3.c pop3.h progress.c progress.h protocol.c protocol.h psl.c psl.h rand.c rand.h ratelimit.c ratelimit.h request.c request.h rtsp.c rtsp.h select.c select.h sendf.c sendf.h setopt.c setopt.h setup-os400.h setup-vms.h setup-win32.h sha256.c sigpipe.h slist.c slist.h smb.c smb.h smtp.c smtp.h sockaddr.h socketpair.c socketpair.h socks.c socks.h socks_gssapi.c socks_sspi.c splay.c splay.h strcase.c strcase.h strequal.c strerror.c strerror.h system_win32.c system_win32.h telnet.c telnet.h tftp.c tftp.h thrdpool.c thrdpool.h thrdqueue.c thrdqueue.h transfer.c transfer.h uint-bset.c uint-bset.h uint-hash.c uint-hash.h uint-spbset.c uint-spbset.h uint-table.c uint-table.h url.c url.h urlapi-int.h urlapi.c urldata.h version.c ws.c ws.h
m4 .gitignore curl-amissl.m4 curl-apple-sectrust.m4 curl-compilers.m4 curl-confopts.m4 curl-functions.m4 curl-gnutls.m4 curl-mbedtls.m4 curl-openssl.m4 curl-override.m4 curl-reentrant.m4 curl-rustls.m4 curl-schannel.m4 curl-sysconfig.m4 curl-wolfssl.m4 xc-am-iface.m4 xc-cc-check.m4 xc-lt-iface.m4 xc-val-flgs.m4 zz40-xc-ovr.m4 zz50-xc-ovr.m4
projects
OS400
rpg-examples HEADERAPI HTTPPOST INMEMORY SIMPLE1 SIMPLE2 SMTPSRCMBR
.checksrc README.OS400 ccsidcurl.c ccsidcurl.h config400.default curl.cmd curl.inc.in curlcl.c curlmain.c initscript.sh make-docs.sh make-include.sh make-lib.sh make-src.sh make-tests.sh makefile.sh os400sys.c os400sys.h
Windows
tmpl .gitattributes README.txt curl-all.sln curl.sln curl.vcxproj curl.vcxproj.filters libcurl.sln libcurl.vcxproj libcurl.vcxproj.filters
.gitignore README.md generate.bat
vms Makefile.am backup_gnv_curl_src.com build_curl-config_script.com build_gnv_curl.com build_gnv_curl_pcsi_desc.com build_gnv_curl_pcsi_text.com build_gnv_curl_release_notes.com build_libcurl_pc.com build_vms.com clean_gnv_curl.com compare_curl_source.com config_h.com curl_crtl_init.c curl_gnv_build_steps.txt curl_release_note_start.txt curl_startup.com curlmsg.h curlmsg.msg curlmsg.sdl curlmsg_vms.h generate_config_vms_h_curl.com generate_vax_transfer.com gnv_conftest.c_first gnv_curl_configure.sh gnv_libcurl_symbols.opt gnv_link_curl.com macro32_exactcase.patch make_gnv_curl_install.sh make_pcsi_curl_kit_name.com pcsi_gnv_curl_file_list.txt pcsi_product_gnv_curl.com readme report_openssl_version.c setup_gnv_curl_build.com stage_curl_install.com vms_eco_level.h
Makefile.am README.md
scripts .checksrc CMakeLists.txt Makefile.am badwords badwords-all badwords.txt cd2cd cd2nroff cdall checksrc-all.pl checksrc.pl cmakelint.sh completion.pl contributors.sh contrithanks.sh coverage.sh delta dmaketgz extract-unit-protos firefox-db2pem.sh installcheck.sh maketgz managen mdlinkcheck mk-ca-bundle.pl mk-unity.pl nroff2cd perlcheck.sh pythonlint.sh randdisable release-notes.pl release-tools.sh schemetable.c singleuse.pl spacecheck.pl top-complexity top-length verify-release wcurl
src
toolx tool_time.c tool_time.h
.checksrc .gitignore CMakeLists.txt Makefile.am Makefile.inc config2setopts.c config2setopts.h curl.rc curlinfo.c mk-file-embed.pl mkhelp.pl slist_wc.c slist_wc.h terminal.c terminal.h tool_cb_dbg.c tool_cb_dbg.h tool_cb_hdr.c tool_cb_hdr.h tool_cb_prg.c tool_cb_prg.h tool_cb_rea.c tool_cb_rea.h tool_cb_see.c tool_cb_see.h tool_cb_soc.c tool_cb_soc.h tool_cb_wrt.c tool_cb_wrt.h tool_cfgable.c tool_cfgable.h tool_dirhie.c tool_dirhie.h tool_doswin.c tool_doswin.h tool_easysrc.c tool_easysrc.h tool_filetime.c tool_filetime.h tool_findfile.c tool_findfile.h tool_formparse.c tool_formparse.h tool_getparam.c tool_getparam.h tool_getpass.c tool_getpass.h tool_help.c tool_help.h tool_helpers.c tool_helpers.h tool_hugehelp.h tool_ipfs.c tool_ipfs.h tool_libinfo.c tool_libinfo.h tool_listhelp.c tool_main.c tool_main.h tool_msgs.c tool_msgs.h tool_operate.c tool_operate.h tool_operhlp.c tool_operhlp.h tool_paramhlp.c tool_paramhlp.h tool_parsecfg.c tool_parsecfg.h tool_progress.c tool_progress.h tool_sdecls.h tool_setopt.c tool_setopt.h tool_setup.h tool_ssls.c tool_ssls.h tool_stderr.c tool_stderr.h tool_urlglob.c tool_urlglob.h tool_util.c tool_util.h tool_version.h tool_vms.c tool_vms.h tool_writeout.c tool_writeout.h tool_writeout_json.c tool_writeout_json.h tool_xattr.c tool_xattr.h var.c var.h
tests
certs .gitignore CMakeLists.txt Makefile.am Makefile.inc genserv.pl srp-verifier-conf srp-verifier-db test-ca.cnf test-ca.prm test-client-cert.prm test-client-eku-only.prm test-localhost-san-first.prm test-localhost-san-last.prm test-localhost.nn.prm test-localhost.prm test-localhost0h.prm
cmake CMakeLists.txt test.c test.cpp test.sh
data .gitignore DISABLED Makefile.am data-xml1 data1400.c data1401.c data1402.c data1403.c data1404.c data1405.c data1406.c data1407.c data1420.c data1461.txt data1463.txt data1465.c data1481.c data1705-1.md data1705-2.md data1705-3.md data1705-4.md data1705-stdout.1 data1706-1.md data1706-2.md data1706-3.md data1706-4.md data1706-stdout.txt data320.html test1 test10 test100 test1000 test1001 test1002 test1003 test1004 test1005 test1006 test1007 test1008 test1009 test101 test1010 test1011 test1012 test1013 test1014 test1015 test1016 test1017 test1018 test1019 test102 test1020 test1021 test1022 test1023 test1024 test1025 test1026 test1027 test1028 test1029 test103 test1030 test1031 test1032 test1033 test1034 test1035 test1036 test1037 test1038 test1039 test104 test1040 test1041 test1042 test1043 test1044 test1045 test1046 test1047 test1048 test1049 test105 test1050 test1051 test1052 test1053 test1054 test1055 test1056 test1057 test1058 test1059 test106 test1060 test1061 test1062 test1063 test1064 test1065 test1066 test1067 test1068 test1069 test107 test1070 test1071 test1072 test1073 test1074 test1075 test1076 test1077 test1078 test1079 test108 test1080 test1081 test1082 test1083 test1084 test1085 test1086 test1087 test1088 test1089 test109 test1090 test1091 test1092 test1093 test1094 test1095 test1096 test1097 test1098 test1099 test11 test110 test1100 test1101 test1102 test1103 test1104 test1105 test1106 test1107 test1108 test1109 test111 test1110 test1111 test1112 test1113 test1114 test1115 test1116 test1117 test1118 test1119 test112 test1120 test1121 test1122 test1123 test1124 test1125 test1126 test1127 test1128 test1129 test113 test1130 test1131 test1132 test1133 test1134 test1135 test1136 test1137 test1138 test1139 test114 test1140 test1141 test1142 test1143 test1144 test1145 test1146 test1147 test1148 test1149 test115 test1150 test1151 test1152 test1153 test1154 test1155 test1156 test1157 test1158 test1159 test116 test1160 test1161 test1162 test1163 test1164 test1165 test1166 test1167 test1168 test1169 test117 test1170 test1171 test1172 test1173 test1174 test1175 test1176 test1177 test1178 test1179 test118 test1180 test1181 test1182 test1183 test1184 test1185 test1186 test1187 test1188 test1189 test119 test1190 test1191 test1192 test1193 test1194 test1195 test1196 test1197 test1198 test1199 test12 test120 test1200 test1201 test1202 test1203 test1204 test1205 test1206 test1207 test1208 test1209 test121 test1210 test1211 test1212 test1213 test1214 test1215 test1216 test1217 test1218 test1219 test122 test1220 test1221 test1222 test1223 test1224 test1225 test1226 test1227 test1228 test1229 test123 test1230 test1231 test1232 test1233 test1234 test1235 test1236 test1237 test1238 test1239 test124 test1240 test1241 test1242 test1243 test1244 test1245 test1246 test1247 test1248 test1249 test125 test1250 test1251 test1252 test1253 test1254 test1255 test1256 test1257 test1258 test1259 test126 test1260 test1261 test1262 test1263 test1264 test1265 test1266 test1267 test1268 test1269 test127 test1270 test1271 test1272 test1273 test1274 test1275 test1276 test1277 test1278 test1279 test128 test1280 test1281 test1282 test1283 test1284 test1285 test1286 test1287 test1288 test1289 test129 test1290 test1291 test1292 test1293 test1294 test1295 test1296 test1297 test1298 test1299 test13 test130 test1300 test1301 test1302 test1303 test1304 test1305 test1306 test1307 test1308 test1309 test131 test1310 test1311 test1312 test1313 test1314 test1315 test1316 test1317 test1318 test1319 test132 test1320 test1321 test1322 test1323 test1324 test1325 test1326 test1327 test1328 test1329 test133 test1330 test1331 test1332 test1333 test1334 test1335 test1336 test1337 test1338 test1339 test134 test1340 test1341 test1342 test1343 test1344 test1345 test1346 test1347 test1348 test1349 test135 test1350 test1351 test1352 test1353 test1354 test1355 test1356 test1357 test1358 test1359 test136 test1360 test1361 test1362 test1363 test1364 test1365 test1366 test1367 test1368 test1369 test137 test1370 test1371 test1372 test1373 test1374 test1375 test1376 test1377 test1378 test1379 test138 test1380 test1381 test1382 test1383 test1384 test1385 test1386 test1387 test1388 test1389 test139 test1390 test1391 test1392 test1393 test1394 test1395 test1396 test1397 test1398 test1399 test14 test140 test1400 test1401 test1402 test1403 test1404 test1405 test1406 test1407 test1408 test1409 test141 test1410 test1411 test1412 test1413 test1414 test1415 test1416 test1417 test1418 test1419 test142 test1420 test1421 test1422 test1423 test1424 test1425 test1426 test1427 test1428 test1429 test143 test1430 test1431 test1432 test1433 test1434 test1435 test1436 test1437 test1438 test1439 test144 test1440 test1441 test1442 test1443 test1444 test1445 test1446 test1447 test1448 test1449 test145 test1450 test1451 test1452 test1453 test1454 test1455 test1456 test1457 test1458 test1459 test146 test1460 test1461 test1462 test1463 test1464 test1465 test1466 test1467 test1468 test1469 test147 test1470 test1471 test1472 test1473 test1474 test1475 test1476 test1477 test1478 test1479 test148 test1480 test1481 test1482 test1483 test1484 test1485 test1486 test1487 test1488 test1489 test149 test1490 test1491 test1492 test1493 test1494 test1495 test1496 test1497 test1498 test1499 test15 test150 test1500 test1501 test1502 test1503 test1504 test1505 test1506 test1507 test1508 test1509 test151 test1510 test1511 test1512 test1513 test1514 test1515 test1516 test1517 test1518 test1519 test152 test1520 test1521 test1522 test1523 test1524 test1525 test1526 test1527 test1528 test1529 test153 test1530 test1531 test1532 test1533 test1534 test1535 test1536 test1537 test1538 test1539 test154 test1540 test1541 test1542 test1543 test1544 test1545 test1546 test1547 test1548 test1549 test155 test1550 test1551 test1552 test1553 test1554 test1555 test1556 test1557 test1558 test1559 test156 test1560 test1561 test1562 test1563 test1564 test1565 test1566 test1567 test1568 test1569 test157 test1570 test1571 test1572 test1573 test1574 test1575 test1576 test1577 test1578 test1579 test158 test1580 test1581 test1582 test1583 test1584 test1585 test1586 test1587 test1588 test1589 test159 test1590 test1591 test1592 test1593 test1594 test1595 test1596 test1597 test1598 test1599 test16 test160 test1600 test1601 test1602 test1603 test1604 test1605 test1606 test1607 test1608 test1609 test161 test1610 test1611 test1612 test1613 test1614 test1615 test1616 test1617 test1618 test1619 test162 test1620 test1621 test1622 test1623 test1624 test1625 test1626 test1627 test1628 test1629 test163 test1630 test1631 test1632 test1633 test1634 test1635 test1636 test1637 test1638 test1639 test164 test1640 test1641 test1642 test1643 test1644 test1645 test165 test1650 test1651 test1652 test1653 test1654 test1655 test1656 test1657 test1658 test1659 test166 test1660 test1661 test1662 test1663 test1664 test1665 test1666 test1667 test1668 test1669 test167 test1670 test1671 test1672 test1673 test1674 test1675 test1676 test168 test1680 test1681 test1682 test1683 test1684 test1685 test169 test17 test170 test1700 test1701 test1702 test1703 test1704 test1705 test1706 test1707 test1708 test1709 test171 test1710 test1711 test1712 test1713 test1714 test1715 test172 test1720 test1721 test173 test174 test175 test176 test177 test178 test179 test18 test180 test1800 test1801 test1802 test181 test182 test183 test184 test1847 test1848 test1849 test185 test1850 test1851 test186 test187 test188 test189 test19 test190 test1900 test1901 test1902 test1903 test1904 test1905 test1906 test1907 test1908 test1909 test191 test1910 test1911 test1912 test1913 test1914 test1915 test1916 test1917 test1918 test1919 test192 test1920 test1921 test193 test1933 test1934 test1935 test1936 test1937 test1938 test1939 test194 test1940 test1941 test1942 test1943 test1944 test1945 test1946 test1947 test1948 test195 test1955 test1956 test1957 test1958 test1959 test196 test1960 test1964 test1965 test1966 test197 test1970 test1971 test1972 test1973 test1974 test1975 test1976 test1977 test1978 test1979 test198 test1980 test1981 test1982 test1983 test1984 test199 test2 test20 test200 test2000 test2001 test2002 test2003 test2004 test2005 test2006 test2007 test2008 test2009 test201 test2010 test2011 test2012 test2013 test2014 test202 test2023 test2024 test2025 test2026 test2027 test2028 test2029 test203 test2030 test2031 test2032 test2033 test2034 test2035 test2037 test2038 test2039 test204 test2040 test2041 test2042 test2043 test2044 test2045 test2046 test2047 test2048 test2049 test205 test2050 test2051 test2052 test2053 test2054 test2055 test2056 test2057 test2058 test2059 test206 test2060 test2061 test2062 test2063 test2064 test2065 test2066 test2067 test2068 test2069 test207 test2070 test2071 test2072 test2073 test2074 test2075 test2076 test2077 test2078 test2079 test208 test2080 test2081 test2082 test2083 test2084 test2085 test2086 test2087 test2088 test2089 test209 test2090 test2091 test2092 test21 test210 test2100 test2101 test2102 test2103 test2104 test211 test212 test213 test214 test215 test216 test217 test218 test219 test22 test220 test2200 test2201 test2202 test2203 test2204 test2205 test2206 test2207 test221 test222 test223 test224 test225 test226 test227 test228 test229 test23 test230 test2300 test2301 test2302 test2303 test2304 test2306 test2307 test2308 test2309 test231 test232 test233 test234 test235 test236 test237 test238 test239 test24 test240 test2400 test2401 test2402 test2403 test2404 test2405 test2406 test2407 test2408 test2409 test241 test2410 test2411 test242 test243 test244 test245 test246 test247 test248 test249 test25 test250 test2500 test2501 test2502 test2503 test2504 test2505 test2506 test251 test252 test253 test254 test255 test256 test257 test258 test259 test26 test260 test2600 test2601 test2602 test2603 test2604 test2605 test261 test262 test263 test264 test265 test266 test267 test268 test269 test27 test270 test2700 test2701 test2702 test2703 test2704 test2705 test2706 test2707 test2708 test2709 test271 test2710 test2711 test2712 test2713 test2714 test2715 test2716 test2717 test2718 test2719 test272 test2720 test2721 test2722 test2723 test273 test274 test275 test276 test277 test278 test279 test28 test280 test281 test282 test283 test284 test285 test286 test287 test288 test289 test29 test290 test291 test292 test293 test294 test295 test296 test297 test298 test299 test3 test30 test300 test3000 test3001 test3002 test3003 test3004 test3005 test3006 test3007 test3008 test3009 test301 test3010 test3011 test3012 test3013 test3014 test3015 test3016 test3017 test3018 test3019 test302 test3020 test3021 test3022 test3023 test3024 test3025 test3026 test3027 test3028 test3029 test303 test3030 test3031 test3032 test3033 test3034 test3035 test3036 test304 test305 test306 test307 test308 test309 test31 test310 test3100 test3101 test3102 test3103 test3104 test3105 test3106 test311 test312 test313 test314 test315 test316 test317 test318 test319 test32 test320 test3200 test3201 test3202 test3203 test3204 test3205 test3206 test3207 test3208 test3209 test321 test3210 test3211 test3212 test3213 test3214 test3215 test3216 test3217 test3218 test3219 test322 test3220 test323 test324 test325 test326 test327 test328 test329 test33 test330 test3300 test3301 test3302 test331 test332 test333 test334 test335 test336 test337 test338 test339 test34 test340 test341 test342 test343 test344 test345 test346 test347 test348 test349 test35 test350 test351 test352 test353 test354 test355 test356 test357 test358 test359 test36 test360 test361 test362 test363 test364 test365 test366 test367 test368 test369 test37 test370 test371 test372 test373 test374 test375 test376 test378 test379 test38 test380 test381 test383 test384 test385 test386 test387 test388 test389 test39 test390 test391 test392 test393 test394 test395 test396 test397 test398 test399 test4 test40 test400 test4000 test4001 test401 test402 test403 test404 test405 test406 test407 test408 test409 test41 test410 test411 test412 test413 test414 test415 test416 test417 test418 test419 test42 test420 test421 test422 test423 test424 test425 test426 test427 test428 test429 test43 test430 test431 test432 test433 test434 test435 test436 test437 test438 test439 test44 test440 test441 test442 test443 test444 test445 test446 test447 test448 test449 test45 test450 test451 test452 test453 test454 test455 test456 test457 test458 test459 test46 test460 test461 test462 test463 test467 test468 test469 test47 test470 test471 test472 test473 test474 test475 test476 test477 test478 test479 test48 test480 test481 test482 test483 test484 test485 test486 test487 test488 test489 test49 test490 test491 test492 test493 test494 test495 test496 test497 test498 test499 test5 test50 test500 test501 test502 test503 test504 test505 test506 test507 test508 test509 test51 test510 test511 test512 test513 test514 test515 test516 test517 test518 test519 test52 test520 test521 test522 test523 test524 test525 test526 test527 test528 test529 test53 test530 test531 test532 test533 test534 test535 test536 test537 test538 test539 test54 test540 test541 test542 test543 test544 test545 test546 test547 test548 test549 test55 test550 test551 test552 test553 test554 test555 test556 test557 test558 test559 test56 test560 test561 test562 test563 test564 test565 test566 test567 test568 test569 test57 test570 test571 test572 test573 test574 test575 test576 test577 test578 test579 test58 test580 test581 test582 test583 test584 test585 test586 test587 test588 test589 test59 test590 test591 test592 test593 test594 test595 test596 test597 test598 test599 test6 test60 test600 test601 test602 test603 test604 test605 test606 test607 test608 test609 test61 test610 test611 test612 test613 test614 test615 test616 test617 test618 test619 test62 test620 test621 test622 test623 test624 test625 test626 test627 test628 test629 test63 test630 test631 test632 test633 test634 test635 test636 test637 test638 test639 test64 test640 test641 test642 test643 test644 test645 test646 test647 test648 test649 test65 test650 test651 test652 test653 test654 test655 test656 test658 test659 test66 test660 test661 test662 test663 test664 test665 test666 test667 test668 test669 test67 test670 test671 test672 test673 test674 test675 test676 test677 test678 test679 test68 test680 test681 test682 test683 test684 test685 test686 test687 test688 test689 test69 test690 test691 test692 test693 test694 test695 test696 test697 test698 test699 test7 test70 test700 test701 test702 test703 test704 test705 test706 test707 test708 test709 test71 test710 test711 test712 test713 test714 test715 test716 test717 test718 test719 test72 test720 test721 test722 test723 test724 test725 test726 test727 test728 test729 test73 test730 test731 test732 test733 test734 test735 test736 test737 test738 test739 test74 test740 test741 test742 test743 test744 test745 test746 test747 test748 test749 test75 test750 test751 test752 test753 test754 test755 test756 test757 test758 test759 test76 test760 test761 test762 test763 test764 test765 test766 test767 test768 test769 test77 test770 test771 test772 test773 test774 test775 test776 test777 test778 test779 test78 test780 test781 test782 test783 test784 test785 test786 test787 test788 test789 test79 test790 test791 test792 test793 test794 test795 test796 test797 test798 test799 test8 test80 test800 test801 test802 test803 test804 test805 test806 test807 test808 test809 test81 test810 test811 test812 test813 test814 test815 test816 test817 test818 test819 test82 test820 test821 test822 test823 test824 test825 test826 test827 test828 test829 test83 test830 test831 test832 test833 test834 test835 test836 test837 test838 test839 test84 test840 test841 test842 test843 test844 test845 test846 test847 test848 test849 test85 test850 test851 test852 test853 test854 test855 test856 test857 test858 test859 test86 test860 test861 test862 test863 test864 test865 test866 test867 test868 test869 test87 test870 test871 test872 test873 test874 test875 test876 test877 test878 test879 test88 test880 test881 test882 test883 test884 test885 test886 test887 test888 test889 test89 test890 test891 test892 test893 test894 test895 test896 test897 test898 test899 test9 test90 test900 test901 test902 test903 test904 test905 test906 test907 test908 test909 test91 test910 test911 test912 test913 test914 test915 test916 test917 test918 test919 test92 test920 test921 test922 test923 test924 test925 test926 test927 test928 test929 test93 test930 test931 test932 test933 test934 test935 test936 test937 test938 test939 test94 test940 test941 test942 test943 test944 test945 test946 test947 test948 test949 test95 test950 test951 test952 test953 test954 test955 test956 test957 test958 test959 test96 test960 test961 test962 test963 test964 test965 test966 test967 test968 test969 test97 test970 test971 test972 test973 test974 test975 test976 test977 test978 test979 test98 test980 test981 test982 test983 test984 test985 test986 test987 test988 test989 test99 test990 test991 test992 test993 test994 test995 test996 test997 test998 test999
http
testenv
mod_curltest .gitignore mod_curltest.c
__init__.py caddy.py certs.py client.py curl.py dante.py dnsd.py env.py httpd.py nghttpx.py ports.py sshd.py vsftpd.py ws_echo_server.py
.gitignore CMakeLists.txt Makefile.am config.ini.in conftest.py requirements.txt scorecard.py test_01_basic.py test_02_download.py test_03_goaway.py test_04_stuttered.py test_05_errors.py test_06_eyeballs.py test_07_upload.py test_08_caddy.py test_09_push.py test_10_proxy.py test_11_unix.py test_12_reuse.py test_13_proxy_auth.py test_14_auth.py test_15_tracing.py test_16_info.py test_17_ssl_use.py test_18_methods.py test_19_shutdown.py test_20_websockets.py test_21_resolve.py test_22_httpsrr.py test_30_vsftpd.py test_31_vsftpds.py test_32_ftps_vsftpd.py test_40_socks.py test_50_scp.py test_51_sftp.py
libtest .gitignore CMakeLists.txt Makefile.am Makefile.inc cli_ftp_upload.c cli_h2_pausing.c cli_h2_serverpush.c cli_h2_upgrade_extreme.c cli_hx_download.c cli_hx_upload.c cli_tls_session_reuse.c cli_upload_pausing.c cli_ws_data.c cli_ws_pingpong.c first.c first.h lib1156.c lib1301.c lib1308.c lib1485.c lib1500.c lib1501.c lib1502.c lib1506.c lib1507.c lib1508.c lib1509.c lib1510.c lib1511.c lib1512.c lib1513.c lib1514.c lib1515.c lib1517.c lib1518.c lib1520.c lib1522.c lib1523.c lib1525.c lib1526.c lib1527.c lib1528.c lib1529.c lib1530.c lib1531.c lib1532.c lib1533.c lib1534.c lib1535.c lib1536.c lib1537.c lib1538.c lib1540.c lib1541.c lib1542.c lib1545.c lib1549.c lib1550.c lib1551.c lib1552.c lib1553.c lib1554.c lib1555.c lib1556.c lib1557.c lib1558.c lib1559.c lib1560.c lib1564.c lib1565.c lib1567.c lib1568.c lib1569.c lib1571.c lib1576.c lib1582.c lib1587.c lib1588.c lib1589.c lib1591.c lib1592.c lib1593.c lib1594.c lib1597.c lib1598.c lib1599.c lib1662.c lib1900.c lib1901.c lib1902.c lib1903.c lib1905.c lib1906.c lib1907.c lib1908.c lib1910.c lib1911.c lib1912.c lib1913.c lib1915.c lib1916.c lib1918.c lib1919.c lib1920.c lib1921.c lib1933.c lib1934.c lib1935.c lib1936.c lib1937.c lib1938.c lib1939.c lib1940.c lib1945.c lib1947.c lib1948.c lib1955.c lib1956.c lib1957.c lib1958.c lib1959.c lib1960.c lib1964.c lib1965.c lib1970.c lib1971.c lib1972.c lib1973.c lib1974.c lib1975.c lib1977.c lib1978.c lib2023.c lib2032.c lib2082.c lib2301.c lib2302.c lib2304.c lib2306.c lib2308.c lib2309.c lib2402.c lib2404.c lib2405.c lib2502.c lib2504.c lib2505.c lib2506.c lib2700.c lib3010.c lib3025.c lib3026.c lib3027.c lib3033.c lib3034.c lib3100.c lib3101.c lib3102.c lib3103.c lib3104.c lib3105.c lib3207.c lib3208.c lib500.c lib501.c lib502.c lib503.c lib504.c lib505.c lib506.c lib507.c lib508.c lib509.c lib510.c lib511.c lib512.c lib513.c lib514.c lib515.c lib516.c lib517.c lib518.c lib519.c lib520.c lib521.c lib523.c lib524.c lib525.c lib526.c lib530.c lib533.c lib536.c lib537.c lib539.c lib540.c lib541.c lib542.c lib543.c lib544.c lib547.c lib549.c lib552.c lib553.c lib554.c lib555.c lib556.c lib557.c lib558.c lib559.c lib560.c lib562.c lib564.c lib566.c lib567.c lib568.c lib569.c lib570.c lib571.c lib572.c lib573.c lib574.c lib575.c lib576.c lib578.c lib579.c lib582.c lib583.c lib586.c lib589.c lib590.c lib591.c lib597.c lib598.c lib599.c lib643.c lib650.c lib651.c lib652.c lib653.c lib654.c lib655.c lib658.c lib659.c lib661.c lib666.c lib667.c lib668.c lib670.c lib674.c lib676.c lib677.c lib678.c lib694.c lib695.c lib751.c lib753.c lib757.c lib758.c lib766.c memptr.c mk-lib1521.pl test1013.pl test1022.pl test307.pl test610.pl test613.pl testtrace.c testtrace.h testutil.c testutil.h unitcheck.h
server .checksrc .gitignore CMakeLists.txt Makefile.am Makefile.inc dnsd.c first.c first.h getpart.c mqttd.c resolve.c rtspd.c sockfilt.c socksd.c sws.c tftpd.c util.c
tunit .gitignore CMakeLists.txt Makefile.am Makefile.inc README.md tool1394.c tool1604.c tool1621.c tool1622.c tool1623.c tool1720.c
unit .gitignore CMakeLists.txt Makefile.am Makefile.inc README.md unit1300.c unit1302.c unit1303.c unit1304.c unit1305.c unit1307.c unit1309.c unit1323.c unit1330.c unit1395.c unit1396.c unit1397.c unit1398.c unit1399.c unit1600.c unit1601.c unit1602.c unit1603.c unit1605.c unit1606.c unit1607.c unit1608.c unit1609.c unit1610.c unit1611.c unit1612.c unit1614.c unit1615.c unit1616.c unit1620.c unit1625.c unit1626.c unit1627.c unit1636.c unit1650.c unit1651.c unit1652.c unit1653.c unit1654.c unit1655.c unit1656.c unit1657.c unit1658.c unit1660.c unit1661.c unit1663.c unit1664.c unit1666.c unit1667.c unit1668.c unit1669.c unit1674.c unit1675.c unit1676.c unit1979.c unit1980.c unit2600.c unit2601.c unit2602.c unit2603.c unit2604.c unit2605.c unit3200.c unit3205.c unit3211.c unit3212.c unit3213.c unit3214.c unit3216.c unit3219.c unit3300.c unit3301.c unit3302.c
.gitignore CMakeLists.txt Makefile.am allversions.pm appveyor.pm azure.pm config.in configurehelp.pm.in devtest.pl dictserver.py directories.pm ech_combos.py ech_tests.sh ftpserver.pl getpart.pm globalconfig.pm http-server.pl http2-server.pl http3-server.pl memanalyze.pl memanalyzer.pm negtelnetserver.py nghttpx.conf pathhelp.pm processhelp.pm requirements.txt rtspserver.pl runner.pm runtests.pl secureserver.pl serverhelp.pm servers.pm smbserver.py sshhelp.pm sshserver.pl test1119.pl test1135.pl test1139.pl test1140.pl test1165.pl test1167.pl test1173.pl test1175.pl test1177.pl test1222.pl test1275.pl test1276.pl test1477.pl test1486.pl test1488.pl test1544.pl test1707.pl test745.pl test971.pl testcurl.pl testutil.pm tftpserver.pl util.py valgrind.pm valgrind.supp
.clang-tidy.yml .dir-locals.el .editorconfig .git-blame-ignore-revs .gitattributes .gitignore .mailmap CHANGES.md CMakeLists.txt COPYING Dockerfile GIT-INFO.md Makefile.am README README.md RELEASE-NOTES REUSE.toml SECURITY.md acinclude.m4 appveyor.sh appveyor.yml configure.ac curl-config.in libcurl.pc.in renovate.json
examples .env config.ini crypto_test.lua env_test.lua fs_example.lua http_server.lua https_test.lua ini_example.lua json.lua log.lua path_fs_example.lua process_example.lua request_download.lua request_test.lua run_all.lua sqlite_example.lua sqlite_http_template.lua stash_test.lua template_test.lua timer.lua websocket.lua
iniparser
.github
ISSUE_TEMPLATE config.yml
workflows disable-pull-requests.yml trigger-gitlab-ci.yml
cmake JoinPaths.cmake config.cmake.in pc.in
example iniexample.c iniwrite.c parse.c twisted-errors.ini twisted-genhuge.py twisted-ofkey.ini twisted-ofval.ini twisted.ini
src dictionary.c dictionary.h iniparser.c iniparser.h
test
ressources
bad_ini ends_well.ini twisted-errors.ini twisted-ofkey.ini twisted-ofval.ini
good_ini empty.ini spaced.ini spaced2.ini twisted.ini
gruezi.ini old.ini quotes.ini utf8.ini
CMakeLists.txt test_dictionary.c test_iniparser.c unity-config.yml unity_config.h
.cmake-format.py .gitignore .gitlab-ci.yml .gitmessage .travis.yml AUTHORS CMakeLists.txt FAQ-en.md FAQ-zhcn.md INSTALL LICENSE README.md compile_commands.json
jinjac
example CMakeLists.txt example.c
jinjac_test_app CMakeLists.txt jinjac_test_app.c
libjinjac
include jinjac.h
src CMakeLists.txt ast.c ast.h block_statement.c block_statement.h buffer.c buffer.h buildin.c buildin.h common.h convert.c convert.h flex_decl.h jfunction.c jfunction.h jinja_expression.l jinja_expression.y jinjac_parse.c jinjac_parse.h jinjac_stream.c jinjac_stream.h jlist.c jlist.h jobject.c jobject.h parameter.c parameter.h str_obj.c str_obj.h trace.c trace.h
CMakeLists.txt
test .gitignore CMakeLists.txt autotest.rb test_01.expected test_01.jinja test_01b.expected test_01b.jinja test_01c.expected test_01c.jinja test_01d.expected test_01d.jinja test_02.expected test_02.jinja test_03.expected test_03.jinja test_04.expected test_04.jinja test_05.expected test_05.jinja test_06.expected test_06.jinja test_07.expected test_07.jinja test_08.expected test_08.jinja test_08b.expected test_08b.jinja test_09.expected test_09.jinja test_10.expected test_10.jinja test_11.expected test_11.jinja test_12.expected test_12.jinja test_13.expected test_13.jinja test_14.expected test_14.jinja test_15.expected test_15.jinja test_16.expected test_16.jinja test_17.expected test_17.jinja test_18.expected test_18.jinja test_18b.expected test_18b.jinja test_18c.expected test_18c.jinja test_19.expected test_19.jinja test_19b.expected test_19b.jinja test_19c.expected test_19c.jinja test_19d.expected test_19d.jinja test_19e.expected test_19e.jinja test_19f.expected test_19f.jinja test_20.expected test_20.jinja test_21.expected test_21.jinja test_22.expected test_22.jinja test_22a.expected test_22a.jinja test_22b.expected test_22b.jinja test_23.expected test_23.jinja test_24.expected test_24.jinja
.gitignore CMakeLists.txt LICENSE.txt README.md build_coverage.sh build_debug.sh build_release.sh cppcheck_analysis.sh
libev Changes LICENSE Makefile Makefile.am Makefile.in README Symbols.ev Symbols.event aclocal.m4 autogen.sh compile config.guess config.h config.h.in config.status config.sub configure configure.ac depcomp ev++.h ev.3 ev.c ev.h ev.pod ev_epoll.c ev_kqueue.c ev_poll.c ev_port.c ev_select.c ev_vars.h ev_win32.c ev_wrap.h event.c event.h install-sh libev.m4 libtool ltmain.sh missing mkinstalldirs stamp-h1
luajit
doc
img contact.png
bluequad-print.css bluequad.css contact.html ext_buffer.html ext_c_api.html ext_ffi.html ext_ffi_api.html ext_ffi_semantics.html ext_ffi_tutorial.html ext_jit.html ext_profiler.html extensions.html install.html luajit.html running.html
dynasm dasm_arm.h dasm_arm.lua dasm_arm64.h dasm_arm64.lua dasm_mips.h dasm_mips.lua dasm_mips64.lua dasm_ppc.h dasm_ppc.lua dasm_proto.h dasm_x64.lua dasm_x86.h dasm_x86.lua dynasm.lua
etc luajit.1 luajit.pc
src
host .gitignore README buildvm.c buildvm.h buildvm_asm.c buildvm_fold.c buildvm_lib.c buildvm_libbc.h buildvm_peobj.c genlibbc.lua genminilua.lua genversion.lua minilua.c
jit .gitignore bc.lua bcsave.lua dis_arm.lua dis_arm64.lua dis_arm64be.lua dis_mips.lua dis_mips64.lua dis_mips64el.lua dis_mips64r6.lua dis_mips64r6el.lua dis_mipsel.lua dis_ppc.lua dis_x64.lua dis_x86.lua dump.lua p.lua v.lua zone.lua
.gitignore Makefile Makefile.dep lauxlib.h lib_aux.c lib_base.c lib_bit.c lib_buffer.c lib_debug.c lib_ffi.c lib_init.c lib_io.c lib_jit.c lib_math.c lib_os.c lib_package.c lib_string.c lib_table.c lj_alloc.c lj_alloc.h lj_api.c lj_arch.h lj_asm.c lj_asm.h lj_asm_arm.h lj_asm_arm64.h lj_asm_mips.h lj_asm_ppc.h lj_asm_x86.h lj_assert.c lj_bc.c lj_bc.h lj_bcdump.h lj_bcread.c lj_bcwrite.c lj_buf.c lj_buf.h lj_carith.c lj_carith.h lj_ccall.c lj_ccall.h lj_ccallback.c lj_ccallback.h lj_cconv.c lj_cconv.h lj_cdata.c lj_cdata.h lj_char.c lj_char.h lj_clib.c lj_clib.h lj_cparse.c lj_cparse.h lj_crecord.c lj_crecord.h lj_ctype.c lj_ctype.h lj_debug.c lj_debug.h lj_def.h lj_dispatch.c lj_dispatch.h lj_emit_arm.h lj_emit_arm64.h lj_emit_mips.h lj_emit_ppc.h lj_emit_x86.h lj_err.c lj_err.h lj_errmsg.h lj_ff.h lj_ffrecord.c lj_ffrecord.h lj_frame.h lj_func.c lj_func.h lj_gc.c lj_gc.h lj_gdbjit.c lj_gdbjit.h lj_ir.c lj_ir.h lj_ircall.h lj_iropt.h lj_jit.h lj_lex.c lj_lex.h lj_lib.c lj_lib.h lj_load.c lj_mcode.c lj_mcode.h lj_meta.c lj_meta.h lj_obj.c lj_obj.h lj_opt_dce.c lj_opt_fold.c lj_opt_loop.c lj_opt_mem.c lj_opt_narrow.c lj_opt_sink.c lj_opt_split.c lj_parse.c lj_parse.h lj_prng.c lj_prng.h lj_profile.c lj_profile.h lj_record.c lj_record.h lj_serialize.c lj_serialize.h lj_snap.c lj_snap.h lj_state.c lj_state.h lj_str.c lj_str.h lj_strfmt.c lj_strfmt.h lj_strfmt_num.c lj_strscan.c lj_strscan.h lj_tab.c lj_tab.h lj_target.h lj_target_arm.h lj_target_arm64.h lj_target_mips.h lj_target_ppc.h lj_target_x86.h lj_trace.c lj_trace.h lj_traceerr.h lj_udata.c lj_udata.h lj_vm.h lj_vmevent.c lj_vmevent.h lj_vmmath.c ljamalg.c lua.h lua.hpp luaconf.h luajit.c luajit_rolling.h lualib.h msvcbuild.bat nxbuild.bat ps4build.bat ps5build.bat psvitabuild.bat vm_arm.dasc vm_arm64.dasc vm_mips.dasc vm_mips64.dasc vm_ppc.dasc vm_x64.dasc vm_x86.dasc xb1build.bat xedkbuild.bat
.gitattributes .gitignore .relver COPYRIGHT Makefile README
sqlite shell.c sqlite3.c sqlite3.h sqlite3ext.h
wolfssl
.github
ISSUE_TEMPLATE bug_report.yaml other.yaml
actions
install-apt-deps action.yml
scripts
zephyr-4.x external_libc.conf zephyr-test.sh
openssl-ech.sh tls-anvil-test.sh
workflows
disabled haproxy.yml hitch.yml hostap.yml
hostap-files
configs
07c9f183ea744ac04585fb6dd10220c75a5e2e74 hostapd.config tests wpa_supplicant.config
b607d2723e927a3446d89aed813f1aa6068186bb hostapd.config tests wpa_supplicant.config
hostap_2_10 extra.patch hostapd.config tests wpa_supplicant.config
Makefile README dbus-wpa_supplicant.conf
ada.yml arduino.yml async-examples.yml async.yml atecc608-sim.yml bind.yml cmake-autoconf.yml cmake.yml codespell.yml coverity-scan-fixes.yml cryptocb-only.yml curl.yml cyrus-sasl.yml disable-pk-algs.yml docker-Espressif.yml docker-OpenWrt.yml emnet-nonblock.yml fil-c.yml freertos-mem-track.yml gencertbuf.yml grpc.yml haproxy.yml hostap-vm.yml intelasm-c-fallback.yml ipmitool.yml jwt-cpp.yml krb5.yml libspdm.yml libssh2.yml libvncserver.yml linuxkm.yml macos-apple-native-cert-validation.yml mbedtls.sh mbedtls.yml membrowse-comment.yml membrowse-onboard.yml membrowse-report.yml memcached.sh memcached.yml mono.yml mosquitto.yml msmtp.yml msys2.yml multi-arch.yml multi-compiler.yml net-snmp.yml nginx.yml no-malloc.yml no-tls.yml nss.sh nss.yml ntp.yml ocsp.yml openldap.yml openssh.yml openssl-ech.yml opensslcoexist.yml openvpn.yml os-check.yml packaging.yml pam-ipmi.yml pq-all.yml pr-commit-check.yml psk.yml puf.yml python.yml rng-tools.yml rust-wrapper.yml se050-sim.yml smallStackSize.yml socat.yml softhsm.yml sssd.yml stm32-sim.yml stsafe-a120-sim.yml stunnel.yml symbol-prefixes.yml threadx.yml tls-anvil.yml trackmemory.yml watcomc.yml win-csharp-test.yml wolfCrypt-Wconversion.yml wolfboot-integration.yml wolfsm.yml xcode.yml zephyr-4.x.yml zephyr.yml
PULL_REQUEST_TEMPLATE.md SECURITY.md membrowse-targets.json
Docker
OpenWrt Dockerfile README.md runTests.sh
packaging
debian Dockerfile
fedora Dockerfile
wolfCLU Dockerfile README.md
yocto Dockerfile buildAndPush.sh
Dockerfile Dockerfile.cross-compiler README.md buildAndPush.sh include.am run.sh
IDE
ARDUINO
sketches
wolfssl_client README.md
wolfssl_server README.md
wolfssl_version README.md
README.md
Arduino_README_prepend.md README.md include.am keywords.txt library.properties.template wolfssl-arduino.cpp wolfssl-arduino.sh wolfssl.h
AURIX Cpu0_Main.c README.md include.am user_settings.h wolf_main.c
Android Android.bp README.md include.am user_settings.h
CRYPTOCELL README.md include.am main.c user_settings.h
CSBENCH include.am user_settings.h
ECLIPSE
DEOS
deos_wolfssl .options
README.md deos_malloc.c include.am tls_wolfssl.c tls_wolfssl.h user_settings.h
MICRIUM README.md client_wolfssl.c client_wolfssl.h include.am server_wolfssl.c server_wolfssl.h user_settings.h wolfsslRunTests.c
RTTHREAD README.md include.am user_settings.h wolfssl_test.c
SIFIVE README.md include.am
Espressif
ESP-IDF
examples
template
VisualGDB wolfssl_template_IDF_v5.1_ESP32.vgdbproj
components
wolfssl
include user_settings.h
CMakeLists.txt Kconfig README.md component.mk
main
include main.h
CMakeLists.txt Kconfig.projbuild component.mk main.c
CMakeLists.txt Makefile README.md partitions_singleapp_large.csv sdkconfig.defaults sdkconfig.defaults.esp8266
wolfssl_benchmark
VisualGDB wolfssl_benchmark_IDF_v4.4_ESP32.sln wolfssl_benchmark_IDF_v4.4_ESP32.vgdbproj wolfssl_benchmark_IDF_v5_ESP32.sln wolfssl_benchmark_IDF_v5_ESP32.vgdbproj wolfssl_benchmark_IDF_v5_ESP32C3.sln wolfssl_benchmark_IDF_v5_ESP32C3.vgdbproj wolfssl_benchmark_IDF_v5_ESP32S3.sln wolfssl_benchmark_IDF_v5_ESP32S3.vgdbproj
components
wolfssl
include user_settings.h
CMakeLists.txt Kconfig README.md component.mk
main
include main.h
CMakeLists.txt Kconfig.projbuild component.mk main.c
CMakeLists.txt Makefile README.md partitions_singleapp_large.csv sdkconfig.defaults sdkconfig.defaults.esp8266
wolfssl_client
VisualGDB README.md wolfssl_client_IDF_v5_ESP32.sln wolfssl_client_IDF_v5_ESP32.vgdbproj
components
wolfssl
include user_settings.h
CMakeLists.txt Kconfig README.md component.mk
main
include client-tls.h main.h time_helper.h wifi_connect.h
CMakeLists.txt Kconfig.projbuild client-tls.c component.mk main.c time_helper.c wifi_connect.c
CMakeLists.txt Makefile README.md README_server_sm.md partitions_singleapp_large.csv sdkconfig.defaults sdkconfig.defaults.esp32c2 sdkconfig.defaults.esp8266 wolfssl_client_ESP8266.vgdbproj
wolfssl_server
VisualGDB README.md wolfssl_server_IDF_v5_ESP32.sln wolfssl_server_IDF_v5_ESP32.vgdbproj
components
wolfssl
include user_settings.h
CMakeLists.txt Kconfig README.md component.mk
main
include main.h server-tls.h time_helper.h wifi_connect.h
CMakeLists.txt Kconfig.projbuild component.mk main.c server-tls.c time_helper.c wifi_connect.c
CMakeLists.txt Makefile README.md README_server_sm.md partitions_singleapp_large.csv sdkconfig.defaults sdkconfig.defaults.esp32c2 sdkconfig.defaults.esp8266 wolfssl_server_ESP8266.vgdbproj
wolfssl_test
VisualGDB wolfssl_test-IDF_v5_ESP32.sln wolfssl_test-IDF_v5_ESP32.vgdbproj wolfssl_test-IDF_v5_ESP32C3.sln wolfssl_test-IDF_v5_ESP32C3.vgdbproj wolfssl_test-IDF_v5_ESP32C6.sln wolfssl_test-IDF_v5_ESP32C6.vgdbproj wolfssl_test_IDF_v5_ESP32S3.sln wolfssl_test_IDF_v5_ESP32S3.vgdbproj
components
wolfssl
include user_settings.h
CMakeLists.txt Kconfig README.md component.mk
main
include main.h
CMakeLists.txt Kconfig.projbuild component.mk main.c
CMakeLists.txt Makefile README.md partitions_singleapp_large.csv sdkconfig.defaults sdkconfig.defaults.esp32 sdkconfig.defaults.esp32c3 sdkconfig.defaults.esp32c6 sdkconfig.defaults.esp32h2 sdkconfig.defaults.esp32s2 sdkconfig.defaults.esp32s3 sdkconfig.defaults.esp8266 testAll.sh testMonitor.sh wolfssl_test_ESP8266.sln wolfssl_test_ESP8266.vgdbproj
wolfssl_test_idf
VisualGDB VisualGDB_wolfssl_test_idf.sln VisualGDB_wolfssl_test_idf.vgdbproj
main CMakeLists.txt Kconfig.projbuild component.mk main.c main_wip.c.ex time_helper.c time_helper.h
CMakeLists.txt Kconfig.projbuild README.md component.mk sdkconfig.defaults
README.md
libs CMakeLists.txt README.md component.mk tigard.cfg
test CMakeLists.txt README.md component.mk test_wolfssl.c
README.md README_32se.md UPDATE.md compileAllExamples.sh dummy_config_h dummy_test_paths.h setup.sh setup_win.bat user_settings.h
README.md include.am
GCC-ARM
Header user_settings.h
Source armtarget.c benchmark_main.c test_main.c tls_client.c tls_server.c wolf_main.c
Makefile Makefile.bench Makefile.client Makefile.common Makefile.server Makefile.static Makefile.test README.md include.am linker.ld linker_fips.ld
Gaisler-BCC README.md include.am
HEXAGON
DSP Makefile wolfssl_dsp.idl
Makefile README.md build.sh ecc-verify-benchmark.c ecc-verify.c include.am user_settings.h
HEXIWEAR
wolfSSL_HW .cwGeneratedFileSetLog user_settings.h
IAR-EWARM
Projects
benchmark benchmark-main.c current_time.c wolfCrypt-benchmark.ewd wolfCrypt-benchmark.ewp
common minimum-startup.c wolfssl.icf
lib wolfSSL-Lib.ewd wolfSSL-Lib.ewp
test test-main.c wolfCrypt-test.ewd wolfCrypt-test.ewp
user_settings.h wolfssl.eww
embOS
SAMV71_XULT
embOS_SAMV71_XULT_Linker_Script samv71q21_wolfssl.icf
embOS_SAMV71_XULT_user_settings user_settings.h user_settings_simple_example.h user_settings_verbose_example.h
embOS_wolfcrypt_benchmark_SAMV71_XULT
Application runBenchmarks.c
README_wolfcrypt_benchmark wolfcrypt_benchmark.ewd wolfcrypt_benchmark.ewp
embOS_wolfcrypt_lib_SAMV71_XULT README_wolfcrypt_lib wolfcrypt_lib.ewd wolfcrypt_lib.ewp
embOS_wolfcrypt_test_SAMV71_XULT
Application runWolfcryptTests.c
README_wolfcrypt_test wolfcrypt_test.ewd wolfcrypt_test.ewp
README_SAMV71
custom_port
custom_port_Linker_Script samv71q21_wolfssl.icf
custom_port_user_settings user_settings.h
wolfcrypt_benchmark_custom_port
Application runBenchmarks.c
wolfcrypt_test_custom_port
Application runWolfcryptTests.c
README_custom_port
extract_trial_here README_extract_trial_here
README
.gitignore README
IAR-MSP430 Makefile README.md include.am main.c user_settings.h
INTIME-RTOS Makefile README.md include.am libwolfssl.c libwolfssl.vcxproj user_settings.h wolfExamples.c wolfExamples.h wolfExamples.sln wolfExamples.vcxproj wolfssl-lib.sln wolfssl-lib.vcxproj
Infineon README.md include.am user_settings.h
KDS
config user_settings.h
include.am
LINUX-SGX README.md build.sh clean.sh include.am sgx_t_static.mk
LPCXPRESSO
lib_wolfssl lpc_18xx_port.c user_settings.h
wolf_example
src lpc_18xx_startup.c wolfssl_example.c
readme.txt
README.md
M68K
benchmark Makefile main.cpp
testwolfcrypt Makefile main.cpp
Makefile README.md include.am user_settings.h
MCUEXPRESSO
RT1170 fsl_caam_c.patch fsl_caam_h.patch user_settings.h
benchmark
source run_benchmark.c
wolfssl liblinks.xml
README.md include.am user_settings.h wolfcrypt_test.c
MDK-ARM
LPC43xx time-LCP43xx.c
MDK-ARM
wolfSSL Retarget.c cert_data.c cert_data.h config-BARE-METAL.h config-FS.h config-RTX-TCP-FS.h config-WOLFLIB.h main.c shell.c time-CortexM3-4.c time-dummy.c wolfssl_MDK_ARM.c wolfssl_MDK_ARM.h
STM32F2xx_StdPeriph_Lib time-STM32F2xx.c
MDK5-ARM
Conf user_settings.h
Inc wolfssl_MDK_ARM.h
Projects
CryptBenchmark Abstract.txt CryptBenchmark.sct CryptBenchmark.uvoptx CryptBenchmark.uvprojx main.c
CryptTest Abstract.txt CryptTest.sct CryptTest.uvoptx CryptTest.uvprojx main.c
EchoClient Abstract.txt EchoClient.uvoptx EchoClient.uvprojx main.c wolfssl-link.sct
EchoServer Abstract.txt EchoServer.uvoptx EchoServer.uvprojx main.c wolfssl-link.sct
SimpleClient Abstract.txt SimpleClient.uvoptx SimpleClient.uvprojx main.c wolfssl-link.sct
SimpleServer Abstract.txt SimpleServer.uvoptx SimpleServer.uvprojx main.c wolfssl-link.sct
wolfSSL-Full Abstract.txt main.c shell.c time-CortexM3-4.c wolfsslFull.uvoptx wolfsslFull.uvprojx
wolfSSL-Lib Abstract.txt wolfSSL-Lib.uvoptx wolfSSL-Lib.uvprojx
Src ssl-dummy.c
README.md include.am
MPLABX16
wolfcrypt_test.X
nbproject
private configurations.xml private.xml
configurations.xml include.am project.xml
Makefile
wolfssl.X
nbproject configurations.xml include.am project.xml
Makefile
README.md include.am main.c user_settings.h
MQX Makefile README-jp.md README.md client-tls.c include.am server-tls.c user_config.h user_settings.h
MSVS-2019-AZSPHERE
client client.c client.h
server server.c server.h
shared util.h
wolfssl_new_azsphere
HardwareDefinitions
avnet_mt3620_sk
inc
hw template_appliance.h
template_appliance.json
mt3620_rdb
inc
hw template_appliance.h
template_appliance.json
seeed_mt3620_mdb
inc
hw template_appliance.h
template_appliance.json
.gitignore CMakeLists.txt CMakeSettings.json app_manifest.json applibs_versions.h launch.vs.json main.c
README.md include.am user_settings.h
MYSQL CMakeLists_wolfCrypt.txt CMakeLists_wolfSSL.txt do.sh
NDS README.md
NETOS Makefile.wolfcrypt.inc README.md include.am user_settings.h user_settings.h-cert2425 user_settings.h-cert3389 wolfssl_netos_custom.c
OPENSTM32 README.md
PlatformIO
examples
wolfssl_benchmark
include README main.h
lib README
src CMakeLists.txt main.c
test README
CMakeLists.txt README.md platformio.ini sdkconfig.defaults wolfssl_benchmark.code-workspace
wolfssl_test
include README main.h
lib README
src CMakeLists.txt main.c
test README
CMakeLists.txt README.md platformio.ini sdkconfig.defaults wolfssl_test.code-workspace
README.md wolfssl_platformio.code-workspace
README.md include.am
QNX
CAAM-DRIVER Makefile
example-client Makefile client-tls.c
example-cmac Makefile cmac-test.c
example-server Makefile server-tls.c
testwolfcrypt Makefile
wolfssl Makefile user_settings.h
README.md include.am
RISCV
SIFIVE-HIFIVE1 Makefile README.md include.am main.c user_settings.h
SIFIVE-UNLEASHED README.md include.am
include.am
ROWLEY-CROSSWORKS-ARM Kinetis_FlashPlacement.xml README.md arm_startup.c benchmark_main.c hw.h include.am kinetis_hw.c retarget.c test_main.c user_settings.h wolfssl.hzp wolfssl_ltc.hzp
Renesas
cs+
Projects
common strings.h unistd.h user_settings.h wolfssl_dummy.c
t4_demo README_en.txt README_jp.txt t4_demo.mtpj wolf_client.c wolf_demo.h wolf_main.c wolf_server.c
test test.mtpj test_main.c
wolfssl_lib wolfssl_lib.mtpj
README include.am
e2studio
DK-S7G2
benchmark-template
src app_entry.c
example_server-template
src app_entry.c
wolfcrypttest-template
src app_entry.c
wolfssl-template-project configuration.xml
README.md include.am user_settings.h
Projects
common strings.h unistd.h user_settings.h wolfssl_dummy.c
test
src key_data.c key_data.h test_main.c wolf_client.c wolf_server.c wolfssl_demo.h
tools generate_rsa_keypair.sh genhexbuf.pl rsa_pss_sign.sh
wolfssl
src .gitkeep
wolfcrypt
src .gitkeep
README include.am
RA6M3
benchmark-wolfcrypt
common .gitkeep
script .gitkeep
src wolfssl_thread_entry.c
client-wolfssl
common
src .gitkeep
script .gitkeep
src wolfssl_thread_entry.c
wolfssl_thread_entry.h
common
ra6m3g README.md
src freertos_tcp_port.c
user_settings.h util.h
server-wolfssl
common
src .gitkeep
script .gitkeep
src wolfssl_thread_entry.c
wolfssl_thread_entry.h
test-wolfcrypt
common .gitkeep
script .gitkeep
src wolfssl_thread_entry.c
wolfssl
src .gitkeep
wolfcrypt .gitkeep
README.md README_APRA6M_en.md README_APRA6M_jp.md include.am
RA6M3G README.md
RA6M4
common user_settings.h wolfssl_demo.h
test
key_data key_data.h key_data_sce.c
src
SEGGER_RTT myprint.c
common .gitignore
test_main.c wolf_client.c wolfssl_sce_unit_test.c
test_RA6M4Debug.launch
tools
example_keys generate_SignedCA.sh rsa_private.pem rsa_public.pem
README.md
README.md include.am
RX65N
GR-ROSE
common strings.h unistd.h user_settings.h wolfssl_dummy.c
smc smc.scfg
test
src key_data.c key_data.h test_main.c wolf_client.c wolf_server.c wolfssl_demo.h
test.rcpc test_HardwareDebug.launch
tools
example_keys generate_SignedCA.sh rsa_private.pem rsa_public.pem
README.md
wolfssl wolfssl.rcpc
README_EN.md README_JP.md include.am
RSK
resource section.esi
wolfssl wolfssl.rcpc
wolfssl_demo key_data.c key_data.h user_settings.h wolfssl_demo.c wolfssl_demo.h
InstructionManualForExample_RSK+RX65N-2MB_EN.pdf InstructionManualForExample_RSK+RX65N-2MB_JP.pdf README_EN.md README_JP.md include.am
RX72N
EnvisionKit
Simple
common sectioninfo.esi wolfssl_dummy.c
test
src
client simple_tcp_client.c simple_tls_tsip_client.c
server simple_tcp_server.c simple_tls_server.c
test_main.c wolfssl_simple_demo.h
test.rcpc test.scfg test_HardwareDebug.launch
wolfssl wolfssl.rcpc
README_EN.md README_JP.md
resource section.esi
tools
example_keys generate_SignedCA.sh rsa_private.pem rsa_public.pem
README.md
wolfssl wolfssl.rcpc
wolfssl_demo key_data.c key_data.h user_settings.h wolfssl_demo.c wolfssl_demo.h wolfssl_tsip_unit_test.c
InstructionManualForExample_RX72N_EnvisonKit_EN.pdf InstructionManualForExample_RX72N_EnvisonKit_JP.pdf README_EN.md README_JP.md include.am
RZN2L
common user_settings.h wolfssl_demo.h
test
src
serial_io app_print.c
test wolf_client.c wolf_server.c wolfssl_rsip_unit_test.c
wolfCrypt .gitignore
wolfSSL .gitignore
local_system_init.c rzn2l_tst_thread_entry.c wolfssl_dummy.c
README.md include.am
SK-S7G2
common user_settings.h
wolfssl_lib configuration.xml
.gitignore README.md include.am
STARCORE README.txt include.am starcore_test.c user_settings.h
STM32Cube README.md STM32_Benchmarks.md default_conf.ftl include.am main.c wolfssl_example.c wolfssl_example.h
SimplicityStudio README.md include.am test_wolf.c user_settings.h
TRUESTUDIO
wolfssl user_settings.h
README include.am
VS-ARM README.md include.am user_settings.h wolfssl.sln wolfssl.vcxproj
VS-AZURE-SPHERE
client app_manifest.json client.c client.h client.vcxproj
server app_manifest.json server.c server.h server.vcxproj
shared util.h
wolfcrypt_test app_manifest.json wolfcrypt_test.vcxproj
README.md include.am user_settings.h wolfssl.sln wolfssl.vcxproj
VisualDSP include.am user_settings.h wolf_tasks.c
WICED-STUDIO README include.am user_settings.h
WIN README.txt include.am test.vcxproj user_settings.h user_settings_dtls.h wolfssl-fips.sln wolfssl-fips.vcxproj
WIN-SGX ReadMe.txt include.am wolfSSL_SGX.edl wolfSSL_SGX.sln wolfSSL_SGX.vcxproj
WIN-SRTP-KDF-140-3 README.txt include.am resource.h test.vcxproj user_settings.h wolfssl-fips.rc wolfssl-fips.sln wolfssl-fips.vcxproj
WIN10 README.txt include.am resource.h test.vcxproj user_settings.h wolfssl-fips.rc wolfssl-fips.sln wolfssl-fips.vcxproj
WINCE README.md include.am user_settings.h user_settings.h.140-2-deprecated
WORKBENCH README.md include.am
XCODE
Benchmark
wolfBench
Assets.xcassets
AppIcon.appiconset Contents.json
Base.lproj LaunchScreen.storyboard Main.storyboard
AppDelegate.h AppDelegate.m Info.plist ViewController.h ViewController.m main.m
wolfBench.xcodeproj project.pbxproj
include.am
wolfssl-FIPS.xcodeproj project.pbxproj
wolfssl.xcodeproj project.pbxproj
wolfssl_testsuite.xcodeproj project.pbxproj
README.md build-for-i386.sh include.am user_settings.h
XCODE-FIPSv2
macOS-C++
Intel user_settings.h
M1 user_settings.h
include.am user_settings.h
XCODE-FIPSv5 README include.am user_settings.h
XCODE-FIPSv6 README include.am user_settings.h
XilinxSDK
2018_2 lscript.ld
2019_2
wolfCrypt_example
src lscript.ld
wolfCrypt_example_system wolfCrypt_example_system.sprj
2022_1
wolfCrypt_FreeRTOS_example wolfCrypt_FreeRTOS_example.prj
wolfCrypt_FreeRTOS_example_system wolfCrypt_FreeRTOS_example_system.sprj
wolfCrypt_example wolfCrypt_example.prj
wolfCrypt_example_system wolfCrypt_example_system.sprj
.gitignore
README.md bench.sh combine.sh eclipse_formatter_profile.xml graph.sh include.am user_settings.h wolfssl_example.c
apple-universal
wolfssl-multiplatform
wolfssl-multiplatform
Assets.xcassets
AccentColor.colorset Contents.json
AppIcon.appiconset Contents.json
Contents.json
ContentView.swift simple_client_example.c simple_client_example.h wolfssl-multiplatform-Bridging-Header.h wolfssl_multiplatform.entitlements wolfssl_multiplatformApp.swift wolfssl_test_driver.c wolfssl_test_driver.h
wolfssl-multiplatform.xcodeproj project.pbxproj
.gitignore README.md build-wolfssl-framework.sh include.am
iotsafe Makefile README.md ca-cert.c devices.c devices.h include.am main.c memory-tls.c startup.c target.ld user_settings.h
iotsafe-raspberrypi Makefile README.md client-tls13.c include.am main.c
mynewt README.md apps.wolfcrypttest.pkg.yml crypto.wolfssl.pkg.yml crypto.wolfssl.syscfg.yml include.am setup.sh
zephyr README.md include.am
include.am
RTOS
nuttx
wolfssl .gitignore Kconfig Make.defs Makefile README.md setup-wolfssl.sh user_settings.h
include.am
bsdkm Makefile README.md bsdkm_wc_port.h include.am wolfkmod.c wolfkmod_aes.c x86_vecreg.c
certs
1024 ca-cert.der ca-cert.pem ca-key.der ca-key.pem client-cert.der client-cert.pem client-key.der client-key.pem client-keyPub.der dh1024.der dh1024.pem dsa-pub-1024.pem dsa1024.der dsa1024.pem include.am rsa1024.der server-cert.der server-cert.pem server-key.der server-key.pem
3072 client-cert.der client-cert.pem client-key.der client-key.pem client-keyPub.der include.am
4096 client-cert.der client-cert.pem client-key.der client-key.pem client-keyPub.der include.am
acert
rsa_pss acert.pem acert_ietf.pem acert_ietf_pubkey.pem acert_pubkey.pem
acert.pem acert_ietf.pem acert_ietf_pubkey.pem acert_pubkey.pem include.am
aia ca-issuers-cert.pem multi-aia-cert.pem overflow-aia-cert.pem
crl
extra-crls ca-int-cert-revoked.pem claim-root.pem crl_critical_entry.pem crlnum_57oct.pem crlnum_64oct.pem general-server-crl.pem large_crlnum.pem large_crlnum2.pem
hash_der 0fdb2da4.r0
hash_pem 0fdb2da4.r0
bad_time_fmt.pem ca-int-ecc.pem ca-int.pem ca-int2-ecc.pem ca-int2.pem caEcc384Crl.pem caEccCrl.der caEccCrl.pem cliCrl.pem client-int-ecc.pem client-int.pem crl.der crl.pem crl.revoked crl2.der crl2.pem crl_reason.pem crl_rsapss.pem eccCliCRL.pem eccSrvCRL.pem gencrls.sh include.am server-goodaltCrl.pem server-goodaltwildCrl.pem server-goodcnCrl.pem server-goodcnwildCrl.pem server-int-ecc.pem server-int.pem wolfssl.cnf
dilithium bench_dilithium_level2_key.der bench_dilithium_level3_key.der bench_dilithium_level5_key.der include.am
ecc bp256r1-key.der bp256r1-key.pem ca-secp256k1-cert.pem ca-secp256k1-key.pem client-bp256r1-cert.der client-bp256r1-cert.pem client-secp256k1-cert.der client-secp256k1-cert.pem genecc.sh include.am secp256k1-key.der secp256k1-key.pem secp256k1-param.pem secp256k1-privkey.der secp256k1-privkey.pem server-bp256r1-cert.der server-bp256r1-cert.pem server-secp256k1-cert.der server-secp256k1-cert.pem server2-secp256k1-cert.der server2-secp256k1-cert.pem wolfssl.cnf wolfssl_384.cnf
ed25519 ca-ed25519-key.der ca-ed25519-key.pem ca-ed25519-priv.der ca-ed25519-priv.pem ca-ed25519.der ca-ed25519.pem client-ed25519-key.der client-ed25519-key.pem client-ed25519-priv.der client-ed25519-priv.pem client-ed25519.der client-ed25519.pem eddsa-ed25519.der eddsa-ed25519.pem gen-ed25519-certs.sh gen-ed25519-keys.sh gen-ed25519.sh include.am root-ed25519-key.der root-ed25519-key.pem root-ed25519-priv.der root-ed25519-priv.pem root-ed25519.der root-ed25519.pem server-ed25519-cert.pem server-ed25519-key.der server-ed25519-key.pem server-ed25519-priv.der server-ed25519-priv.pem server-ed25519.der server-ed25519.pem
ed448 ca-ed448-key.der ca-ed448-key.pem ca-ed448-priv.der ca-ed448-priv.pem ca-ed448.der ca-ed448.pem client-ed448-key.der client-ed448-key.pem client-ed448-priv.der client-ed448-priv.pem client-ed448.der client-ed448.pem gen-ed448-certs.sh gen-ed448-keys.sh include.am root-ed448-key.der root-ed448-key.pem root-ed448-priv.der root-ed448-priv.pem root-ed448.der root-ed448.pem server-ed448-cert.pem server-ed448-key.der server-ed448-key.pem server-ed448-priv.der server-ed448-priv.pem server-ed448.der server-ed448.pem
external DigiCertGlobalRootCA.pem README.txt ca-digicert-ev.pem ca-globalsign-root.pem ca-google-root.pem ca_collection.pem include.am
falcon bench_falcon_level1_key.der bench_falcon_level5_key.der include.am
intermediate
ca_false_intermediate gentestcert.sh int_ca.key server.key test_ca.key test_ca.pem test_int_not_cacert.pem test_sign_bynoca_srv.pem wolfssl_base.conf wolfssl_srv.conf
ca-ecc-bad-aki.der ca-ecc-bad-aki.pem ca-int-cert.der ca-int-cert.pem ca-int-ecc-cert.der ca-int-ecc-cert.pem ca-int-ecc-key.der ca-int-ecc-key.pem ca-int-key.der ca-int-key.pem ca-int2-cert.der ca-int2-cert.pem ca-int2-ecc-cert.der ca-int2-ecc-cert.pem ca-int2-ecc-key.der ca-int2-ecc-key.pem ca-int2-key.der ca-int2-key.pem client-chain-alt-ecc.pem client-chain-alt.pem client-chain-ecc.der client-chain-ecc.pem client-chain.der client-chain.pem client-int-cert.der client-int-cert.pem client-int-ecc-cert.der client-int-ecc-cert.pem genintcerts.sh include.am server-chain-alt-ecc.pem server-chain-alt.pem server-chain-ecc.der server-chain-ecc.pem server-chain-short.pem server-chain.der server-chain.pem server-int-cert.der server-int-cert.pem server-int-ecc-cert.der server-int-ecc-cert.pem
lms bc_hss_L2_H5_W8_root.der bc_hss_L3_H5_W4_root.der bc_lms_chain_ca.der bc_lms_chain_leaf.der bc_lms_native_bc_root.der bc_lms_sha256_h10_w8_root.der bc_lms_sha256_h5_w4_root.der include.am
mldsa README.txt include.am mldsa44-cert.der mldsa44-cert.pem mldsa44-key.pem mldsa44_bare-priv.der mldsa44_bare-seed.der mldsa44_oqskeypair.der mldsa44_priv-only.der mldsa44_pub-spki.der mldsa44_seed-only.der mldsa44_seed-priv.der mldsa65-cert.der mldsa65-cert.pem mldsa65-key.pem mldsa65_bare-priv.der mldsa65_bare-seed.der mldsa65_oqskeypair.der mldsa65_priv-only.der mldsa65_pub-spki.der mldsa65_seed-only.der mldsa65_seed-priv.der mldsa87-cert.der mldsa87-cert.pem mldsa87-key.pem mldsa87_bare-priv.der mldsa87_bare-seed.der mldsa87_oqskeypair.der mldsa87_priv-only.der mldsa87_pub-spki.der mldsa87_seed-only.der mldsa87_seed-priv.der
ocsp imposter-root-ca-cert.der imposter-root-ca-cert.pem imposter-root-ca-key.der imposter-root-ca-key.pem include.am index-ca-and-intermediate-cas.txt index-ca-and-intermediate-cas.txt.attr index-intermediate1-ca-issued-certs.txt index-intermediate1-ca-issued-certs.txt.attr index-intermediate2-ca-issued-certs.txt index-intermediate2-ca-issued-certs.txt.attr index-intermediate3-ca-issued-certs.txt index-intermediate3-ca-issued-certs.txt.attr intermediate1-ca-cert.der intermediate1-ca-cert.pem intermediate1-ca-key.der intermediate1-ca-key.pem intermediate2-ca-cert.der intermediate2-ca-cert.pem intermediate2-ca-key.der intermediate2-ca-key.pem intermediate3-ca-cert.der intermediate3-ca-cert.pem intermediate3-ca-key.der intermediate3-ca-key.pem ocsp-responder-cert.der ocsp-responder-cert.pem ocsp-responder-key.der ocsp-responder-key.pem openssl.cnf renewcerts-for-test.sh renewcerts.sh root-ca-cert.der root-ca-cert.pem root-ca-crl.pem root-ca-key.der root-ca-key.pem server1-cert.der server1-cert.pem server1-chain-noroot.pem server1-key.der server1-key.pem server2-cert.der server2-cert.pem server2-key.der server2-key.pem server3-cert.der server3-cert.pem server3-key.der server3-key.pem server4-cert.der server4-cert.pem server4-key.der server4-key.pem server5-cert.der server5-cert.pem server5-key.der server5-key.pem test-leaf-response.der test-multi-response.der test-response-nointern.der test-response-rsapss.der test-response.der
p521 ca-p521-key.der ca-p521-key.pem ca-p521-priv.der ca-p521-priv.pem ca-p521.der ca-p521.pem client-p521-key.der client-p521-key.pem client-p521-priv.der client-p521-priv.pem client-p521.der client-p521.pem gen-p521-certs.sh gen-p521-keys.sh include.am root-p521-key.der root-p521-key.pem root-p521-priv.der root-p521-priv.pem root-p521.der root-p521.pem server-p521-cert.pem server-p521-key.der server-p521-key.pem server-p521-priv.der server-p521-priv.pem server-p521.der server-p521.pem
renewcerts wolfssl.cnf
rpk client-cert-rpk.der client-ecc-cert-rpk.der include.am server-cert-rpk.der server-ecc-cert-rpk.der
rsapss ca-3072-rsapss-key.der ca-3072-rsapss-key.pem ca-3072-rsapss-priv.der ca-3072-rsapss-priv.pem ca-3072-rsapss.der ca-3072-rsapss.pem ca-rsapss-key.der ca-rsapss-key.pem ca-rsapss-priv.der ca-rsapss-priv.pem ca-rsapss.der ca-rsapss.pem client-3072-rsapss-key.der client-3072-rsapss-key.pem client-3072-rsapss-priv.der client-3072-rsapss-priv.pem client-3072-rsapss.der client-3072-rsapss.pem client-rsapss-key.der client-rsapss-key.pem client-rsapss-priv.der client-rsapss-priv.pem client-rsapss.der client-rsapss.pem gen-rsapss-keys.sh include.am renew-rsapss-certs.sh root-3072-rsapss-key.der root-3072-rsapss-key.pem root-3072-rsapss-priv.der root-3072-rsapss-priv.pem root-3072-rsapss.der root-3072-rsapss.pem root-rsapss-key.der root-rsapss-key.pem root-rsapss-priv.der root-rsapss-priv.pem root-rsapss.der root-rsapss.pem server-3072-rsapss-cert.pem server-3072-rsapss-key.der server-3072-rsapss-key.pem server-3072-rsapss-priv.der server-3072-rsapss-priv.pem server-3072-rsapss.der server-3072-rsapss.pem server-mix-rsapss-cert.pem server-rsapss-cert.pem server-rsapss-key.der server-rsapss-key.pem server-rsapss-priv.der server-rsapss-priv.pem server-rsapss.der server-rsapss.pem
sia timestamping-sia-cert.pem
slhdsa bench_slhdsa_sha2_128f_key.der bench_slhdsa_sha2_128s_key.der bench_slhdsa_sha2_192f_key.der bench_slhdsa_sha2_192s_key.der bench_slhdsa_sha2_256f_key.der bench_slhdsa_sha2_256s_key.der bench_slhdsa_shake128f_key.der bench_slhdsa_shake128s_key.der bench_slhdsa_shake192f_key.der bench_slhdsa_shake192s_key.der bench_slhdsa_shake256f_key.der bench_slhdsa_shake256s_key.der client-mldsa44-priv.pem client-mldsa44-sha2.der client-mldsa44-sha2.pem client-mldsa44-shake.der client-mldsa44-shake.pem gen-slhdsa-mldsa-certs.sh include.am root-slhdsa-sha2-128s-priv.der root-slhdsa-sha2-128s-priv.pem root-slhdsa-sha2-128s.der root-slhdsa-sha2-128s.pem root-slhdsa-shake-128s-priv.der root-slhdsa-shake-128s-priv.pem root-slhdsa-shake-128s.der root-slhdsa-shake-128s.pem server-mldsa44-priv.pem server-mldsa44-sha2.der server-mldsa44-sha2.pem server-mldsa44-shake.der server-mldsa44-shake.pem
sm2 ca-sm2-key.der ca-sm2-key.pem ca-sm2-priv.der ca-sm2-priv.pem ca-sm2.der ca-sm2.pem client-sm2-key.der client-sm2-key.pem client-sm2-priv.der client-sm2-priv.pem client-sm2.der client-sm2.pem fix_sm2_spki.py gen-sm2-certs.sh gen-sm2-keys.sh include.am root-sm2-key.der root-sm2-key.pem root-sm2-priv.der root-sm2-priv.pem root-sm2.der root-sm2.pem self-sm2-cert.pem self-sm2-key.pem self-sm2-priv.pem server-sm2-cert.der server-sm2-cert.pem server-sm2-key.der server-sm2-key.pem server-sm2-priv.der server-sm2-priv.pem server-sm2.der server-sm2.pem
statickeys dh-ffdhe2048-params.pem dh-ffdhe2048-pub.der dh-ffdhe2048-pub.pem dh-ffdhe2048.der dh-ffdhe2048.pem ecc-secp256r1.der ecc-secp256r1.pem gen-static.sh include.am x25519-pub.der x25519-pub.pem x25519.der x25519.pem
test
expired expired-ca.der expired-ca.pem expired-cert.der expired-cert.pem
catalog.txt cert-bad-neg-int.der cert-bad-oid.der cert-bad-utf8.der cert-ext-ia.cfg cert-ext-ia.der cert-ext-ia.pem cert-ext-joi.cfg cert-ext-joi.der cert-ext-joi.pem cert-ext-mnc.der cert-ext-multiple.cfg cert-ext-multiple.der cert-ext-multiple.pem cert-ext-nc-combined.der cert-ext-nc-combined.pem cert-ext-nc.cfg cert-ext-nc.der cert-ext-nc.pem cert-ext-ncdns.der cert-ext-ncdns.pem cert-ext-ncip.der cert-ext-ncip.pem cert-ext-ncmixed.der cert-ext-ncmulti.der cert-ext-ncmulti.pem cert-ext-ncrid.der cert-ext-ncrid.pem cert-ext-nct.cfg cert-ext-nct.der cert-ext-nct.pem cert-ext-ndir-exc.cfg cert-ext-ndir-exc.der cert-ext-ndir-exc.pem cert-ext-ndir.cfg cert-ext-ndir.der cert-ext-ndir.pem cert-ext-ns.der cert-over-max-altnames.cfg cert-over-max-altnames.der cert-over-max-altnames.pem cert-over-max-nc.cfg cert-over-max-nc.der cert-over-max-nc.pem client-ecc-cert-ski.hex cn-ip-literal.der cn-ip-wildcard.der crit-cert.pem crit-key.pem dh1024.der dh1024.pem dh512.der dh512.pem digsigku.pem encrypteddata.msg gen-badsig.sh gen-ext-certs.sh gen-testcerts.sh include.am kari-keyid-cms.msg ktri-keyid-cms.msg ossl-trusted-cert.pem server-badaltname.der server-badaltname.pem server-badaltnull.der server-badaltnull.pem server-badcn.der server-badcn.pem server-badcnnull.der server-badcnnull.pem server-cert-ecc-badsig.der server-cert-ecc-badsig.pem server-cert-rsa-badsig.der server-cert-rsa-badsig.pem server-duplicate-policy.pem server-garbage.der server-garbage.pem server-goodalt.der server-goodalt.pem server-goodaltwild.der server-goodaltwild.pem server-goodcn.der server-goodcn.pem server-goodcnwild.der server-goodcnwild.pem server-localhost.der server-localhost.pem smime-test-canon.p7s smime-test-multipart-badsig.p7s smime-test-multipart.p7s smime-test.p7s
test-pathlen assemble-chains.sh chainA-ICA1-key.pem chainA-ICA1-pathlen0.pem chainA-assembled.pem chainA-entity-key.pem chainA-entity.pem chainB-ICA1-key.pem chainB-ICA1-pathlen0.pem chainB-ICA2-key.pem chainB-ICA2-pathlen1.pem chainB-assembled.pem chainB-entity-key.pem chainB-entity.pem chainC-ICA1-key.pem chainC-ICA1-pathlen1.pem chainC-assembled.pem chainC-entity-key.pem chainC-entity.pem chainD-ICA1-key.pem chainD-ICA1-pathlen127.pem chainD-assembled.pem chainD-entity-key.pem chainD-entity.pem chainE-ICA1-key.pem chainE-ICA1-pathlen128.pem chainE-assembled.pem chainE-entity-key.pem chainE-entity.pem chainF-ICA1-key.pem chainF-ICA1-pathlen1.pem chainF-ICA2-key.pem chainF-ICA2-pathlen0.pem chainF-assembled.pem chainF-entity-key.pem chainF-entity.pem chainG-ICA1-key.pem chainG-ICA1-pathlen0.pem chainG-ICA2-key.pem chainG-ICA2-pathlen1.pem chainG-ICA3-key.pem chainG-ICA3-pathlen99.pem chainG-ICA4-key.pem chainG-ICA4-pathlen5.pem chainG-ICA5-key.pem chainG-ICA5-pathlen20.pem chainG-ICA6-key.pem chainG-ICA6-pathlen10.pem chainG-ICA7-key.pem chainG-ICA7-pathlen100.pem chainG-assembled.pem chainG-entity-key.pem chainG-entity.pem chainH-ICA1-key.pem chainH-ICA1-pathlen0.pem chainH-ICA2-key.pem chainH-ICA2-pathlen2.pem chainH-ICA3-key.pem chainH-ICA3-pathlen2.pem chainH-ICA4-key.pem chainH-ICA4-pathlen2.pem chainH-assembled.pem chainH-entity-key.pem chainH-entity.pem chainI-ICA1-key.pem chainI-ICA1-no_pathlen.pem chainI-ICA2-key.pem chainI-ICA2-no_pathlen.pem chainI-ICA3-key.pem chainI-ICA3-pathlen2.pem chainI-assembled.pem chainI-entity-key.pem chainI-entity.pem chainJ-ICA1-key.pem chainJ-ICA1-no_pathlen.pem chainJ-ICA2-key.pem chainJ-ICA2-no_pathlen.pem chainJ-ICA3-key.pem chainJ-ICA3-no_pathlen.pem chainJ-ICA4-key.pem chainJ-ICA4-pathlen2.pem chainJ-assembled.pem chainJ-entity-key.pem chainJ-entity.pem include.am refreshkeys.sh
test-serial0 ee_normal.pem ee_serial0.pem generate_certs.sh include.am intermediate_serial0.pem root_serial0.pem root_serial0_key.pem selfsigned_nonca_serial0.pem
xmss bc_xmss_chain_ca.der bc_xmss_chain_leaf.der bc_xmss_sha2_10_256_root.der bc_xmss_sha2_16_256_root.der bc_xmssmt_sha2_20_2_256_root.der bc_xmssmt_sha2_20_4_256_root.der bc_xmssmt_sha2_40_8_256_root.der include.am
ca-cert-chain.der ca-cert.der ca-cert.pem ca-ecc-cert.der ca-ecc-cert.pem ca-ecc-key.der ca-ecc-key.pem ca-ecc384-cert.der ca-ecc384-cert.pem ca-ecc384-key.der ca-ecc384-key.pem ca-key-pkcs8-attribute.der ca-key.der ca-key.pem check_dates.sh client-absolute-urn.pem client-ca-cert.der client-ca-cert.pem client-ca.pem client-cert-ext.der client-cert-ext.pem client-cert.der client-cert.pem client-crl-dist.der client-crl-dist.pem client-ecc-ca-cert.der client-ecc-ca-cert.pem client-ecc-cert.der client-ecc-cert.pem client-ecc384-cert.der client-ecc384-cert.pem client-ecc384-key.der client-ecc384-key.pem client-key.der client-key.pem client-keyEnc.pem client-keyPub.der client-keyPub.pem client-relative-uri.pem client-uri-cert.pem csr.attr.der csr.dsa.der csr.dsa.pem csr.ext.der csr.signed.der dh-priv-2048.der dh-priv-2048.pem dh-pub-2048.der dh-pub-2048.pem dh-pubkey-2048.der dh2048.der dh2048.pem dh3072.der dh3072.pem dh4096.der dh4096.pem dsa-pubkey-2048.der dsa2048.der dsa2048.pem dsa3072.der dsaparams.der dsaparams.pem ecc-client-key.der ecc-client-key.pem ecc-client-keyPub.der ecc-client-keyPub.pem ecc-key-comp.pem ecc-keyPkcs8.der ecc-keyPkcs8.pem ecc-keyPkcs8Enc.der ecc-keyPkcs8Enc.pem ecc-keyPub.der ecc-keyPub.pem ecc-params.der ecc-params.pem ecc-privOnlyCert.pem ecc-privOnlyKey.pem ecc-privkey.der ecc-privkey.pem ecc-privkeyPkcs8.der ecc-privkeyPkcs8.pem ecc-rsa-server.p12 empty-issuer-cert.pem entity-no-ca-bool-cert.pem entity-no-ca-bool-key.pem fpki-cert.der fpki-certpol-cert.der gen_revoked.sh include.am renewcerts.sh rid-cert.der rsa-pub-2048.pem rsa2048.der rsa3072.der server-cert-chain.der server-cert.der server-cert.pem server-ecc-comp.der server-ecc-comp.pem server-ecc-rsa.der server-ecc-rsa.pem server-ecc-self.der server-ecc-self.pem server-ecc.der server-ecc.pem server-ecc384-cert.der server-ecc384-cert.pem server-ecc384-key.der server-ecc384-key.pem server-key.der server-key.pem server-keyEnc.pem server-keyPkcs8.der server-keyPkcs8.pem server-keyPkcs8Enc.der server-keyPkcs8Enc.pem server-keyPkcs8Enc12.pem server-keyPkcs8Enc2.pem server-keyPub.der server-keyPub.pem server-revoked-cert.pem server-revoked-key.pem taoCert.txt test-ber-exp02-05-2022.p7b test-degenerate.p7b test-multiple-recipients.p7b test-servercert-rc2.p12 test-servercert.p12 test-stream-dec.p7b test-stream-sign.p7b wolfssl-website-ca.pem x942dh2048.der x942dh2048.pem
cmake
consumer CMakeLists.txt README.md main.c
modules FindARIA.cmake FindOQS.cmake
Config.cmake.in README.md config.in functions.cmake include.am options.h.in wolfssl-config-version.cmake.in wolfssl-targets.cmake.in
debian
source format
changelog.in control.in copyright include.am libwolfssl-dev.install libwolfssl.install rules.in
doc
dox_comments
header_files aes.h arc4.h ascon.h asn.h asn_public.h blake2.h bn.h camellia.h chacha.h chacha20_poly1305.h cmac.h coding.h compress.h cryptocb.h curve25519.h curve448.h des3.h dh.h doxygen_groups.h doxygen_pages.h dsa.h ecc.h eccsi.h ed25519.h ed448.h error-crypt.h evp.h hash.h hmac.h iotsafe.h kdf.h logging.h md2.h md4.h md5.h memory.h ocsp.h pem.h pkcs11.h pkcs7.h poly1305.h psa.h puf.h pwdbased.h quic.h random.h ripemd.h rsa.h sakke.h sha.h sha256.h sha3.h sha512.h signature.h siphash.h srp.h ssl.h tfm.h types.h wc_encrypt.h wc_port.h wc_she.h wc_slhdsa.h wolfio.h
header_files-ja aes.h arc4.h ascon.h asn.h asn_public.h blake2.h bn.h camellia.h chacha.h chacha20_poly1305.h cmac.h coding.h compress.h cryptocb.h curve25519.h curve448.h des3.h dh.h doxygen_groups.h doxygen_pages.h dsa.h ecc.h eccsi.h ed25519.h ed448.h error-crypt.h evp.h hash.h hmac.h iotsafe.h kdf.h logging.h md2.h md4.h md5.h memory.h ocsp.h pem.h pkcs11.h pkcs7.h poly1305.h psa.h pwdbased.h quic.h random.h ripemd.h rsa.h sakke.h sha.h sha256.h sha3.h sha512.h signature.h siphash.h srp.h ssl.h tfm.h types.h wc_encrypt.h wc_port.h wolfio.h
formats
html
html_changes
search search.css search.js
customdoxygen.css doxygen.css menu.js menudata.js tabs.css
Doxyfile footer.html header.html mainpage.dox
pdf Doxyfile header.tex
images wolfssl_logo.png
QUIC.md README.txt README_DOXYGEN check_api.sh generate_documentation.sh include.am
examples
asn1 asn1.c dumpasn1.cfg gen_oid_names.rb include.am oid_names.h
async Makefile README.md async_client.c async_server.c async_tls.c async_tls.h include.am user_settings.h
benchmark include.am tls_bench.c tls_bench.h
client client.c client.h client.sln client.vcproj client.vcxproj include.am
configs README.md include.am user_settings_EBSnet.h user_settings_all.h user_settings_arduino.h user_settings_baremetal.h user_settings_ca.h user_settings_curve25519nonblock.h user_settings_dtls13.h user_settings_eccnonblock.h user_settings_espressif.h user_settings_fipsv2.h user_settings_fipsv5.h user_settings_min_ecc.h user_settings_openssl_compat.h user_settings_pkcs7.h user_settings_platformio.h user_settings_pq.h user_settings_rsa_only.h user_settings_stm32.h user_settings_template.h user_settings_tls12.h user_settings_tls13.h user_settings_wolfboot_keytools.h user_settings_wolfssh.h user_settings_wolftpm.h
crypto_policies
default wolfssl.txt
future wolfssl.txt
legacy wolfssl.txt
echoclient echoclient.c echoclient.h echoclient.sln echoclient.vcproj echoclient.vcxproj include.am quit
echoserver echoserver.c echoserver.h echoserver.sln echoserver.vcproj echoserver.vcxproj include.am
ocsp_responder include.am ocsp_responder.c ocsp_responder.h
pem include.am pem.c
sctp include.am sctp-client-dtls.c sctp-client.c sctp-server-dtls.c sctp-server.c
server include.am server.c server.h server.sln server.vcproj server.vcxproj
README.md include.am
linuxkm
patches
5.10.17 WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-5v10v17.patch
5.10.236 WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-5v10v236.patch
5.14.0-570.58.1.el9_6 WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-5v14-570v58v1-el9_6.patch
5.15 WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-5v15.patch
5.17 WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-5v17.patch
5.17-ubuntu-jammy-tegra WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-5v17-ubuntu-jammy-tegra.patch
6.1.73 WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-6v1v73.patch
6.12 WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-6v12.patch
6.15 WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-6v15.patch
7.0 WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS-7v0.patch
regen-patches.sh
Kbuild Makefile README.md get_thread_size.c include.am linuxkm-fips-hash-wrapper.sh linuxkm-fips-hash.c linuxkm_memory.c linuxkm_memory.h linuxkm_wc_port.h lkcapi_aes_glue.c lkcapi_dh_glue.c lkcapi_ecdh_glue.c lkcapi_ecdsa_glue.c lkcapi_glue.c lkcapi_rsa_glue.c lkcapi_sha_glue.c module_exports.c.template module_hooks.c pie_redirect_table.c wolfcrypt.lds x86_vector_register_glue.c
m4 ax_add_am_macro.m4 ax_am_jobserver.m4 ax_am_macros.m4 ax_append_compile_flags.m4 ax_append_flag.m4 ax_append_link_flags.m4 ax_append_to_file.m4 ax_atomic.m4 ax_bsdkm.m4 ax_check_compile_flag.m4 ax_check_link_flag.m4 ax_compiler_version.m4 ax_count_cpus.m4 ax_create_generic_config.m4 ax_debug.m4 ax_file_escapes.m4 ax_harden_compiler_flags.m4 ax_linuxkm.m4 ax_print_to_file.m4 ax_pthread.m4 ax_require_defined.m4 ax_tls.m4 ax_vcs_checkout.m4 hexversion.m4 lib_socket_nsl.m4 visibility.m4
mcapi
wolfcrypt_mcapi.X
nbproject configurations.xml include.am project.xml
Makefile
wolfcrypt_test.X
nbproject configurations.xml include.am project.xml
Makefile
wolfssl.X
nbproject configurations.xml include.am project.xml
Makefile
zlib.X
nbproject configurations.xml include.am project.xml
Makefile
PIC32MZ-serial.h README crypto.c crypto.h include.am mcapi_test.c user_settings.h
mplabx
wolfcrypt_benchmark.X
nbproject configurations.xml include.am project.xml
Makefile
wolfcrypt_test.X
nbproject configurations.xml include.am project.xml
Makefile
wolfssl.X
nbproject configurations.xml include.am project.xml
Makefile
PIC32MZ-serial.h README benchmark_main.c include.am test_main.c user_settings.h
mqx
util_lib
Sources include.am util.c util.h
wolfcrypt_benchmark
Debugger K70FN1M0.mem init_kinetis.tcl mass_erase_kinetis.tcl
Sources include.am main.c main.h
ReferencedRSESystems.xml wolfcrypt_benchmark_twrk70f120m_Int_Flash_DDRData_Debug_PnE_U-MultiLink.launch wolfcrypt_benchmark_twrk70f120m_Int_Flash_DDRData_Release_PnE_U-MultiLink.launch wolfcrypt_benchmark_twrk70f120m_Int_Flash_SramData_Debug_JTrace.jlink wolfcrypt_benchmark_twrk70f120m_Int_Flash_SramData_Debug_JTrace.launch wolfcrypt_benchmark_twrk70f120m_Int_Flash_SramData_Debug_PnE_U-MultiLink.launch wolfcrypt_benchmark_twrk70f120m_Int_Flash_SramData_Release_PnE_U-MultiLink.launch
wolfcrypt_test
Debugger K70FN1M0.mem init_kinetis.tcl mass_erase_kinetis.tcl
Sources include.am main.c main.h
ReferencedRSESystems.xml wolfcrypt_test_twrk70f120m_Int_Flash_DDRData_Debug_PnE_U-MultiLink.launch wolfcrypt_test_twrk70f120m_Int_Flash_DDRData_Release_PnE_U-MultiLink.launch wolfcrypt_test_twrk70f120m_Int_Flash_SramData_Debug_JTrace.jlink wolfcrypt_test_twrk70f120m_Int_Flash_SramData_Debug_JTrace.launch wolfcrypt_test_twrk70f120m_Int_Flash_SramData_Debug_PnE_U-MultiLink.launch wolfcrypt_test_twrk70f120m_Int_Flash_SramData_Release_PnE_U-MultiLink.launch
wolfssl include.am
wolfssl_client
Debugger K70FN1M0.mem init_kinetis.tcl mass_erase_kinetis.tcl
Sources include.am main.c main.h
ReferencedRSESystems.xml wolfssl_client_twrk70f120m_Int_Flash_DDRData_Debug_PnE_U-MultiLink.launch wolfssl_client_twrk70f120m_Int_Flash_DDRData_Release_PnE_U-MultiLink.launch wolfssl_client_twrk70f120m_Int_Flash_SramData_Debug_JTrace.jlink wolfssl_client_twrk70f120m_Int_Flash_SramData_Debug_JTrace.launch wolfssl_client_twrk70f120m_Int_Flash_SramData_Debug_PnE_U-MultiLink.launch wolfssl_client_twrk70f120m_Int_Flash_SramData_Release_PnE_U-MultiLink.launch
README
rpm include.am spec.in
scripts
bench bench_functions.sh
aria-cmake-build-test.sh asn1_oid_sum.pl benchmark.test benchmark_compare.sh cleanup_testfiles.sh crl-gen-openssl.test crl-revoked.test dertoc.pl dtls.test dtlscid.test external.test google.test include.am makedistsmall.sh memtest.sh ocsp-responder-openssl-interop.test ocsp-stapling-with-ca-as-responder.test ocsp-stapling-with-wolfssl-responder.test ocsp-stapling.test ocsp-stapling2.test ocsp-stapling_tls13multi.test ocsp.test openssl.test openssl_srtp.test pem.test ping.test pkcallbacks.test psk.test resume.test rsapss.test sniffer-gen.sh sniffer-ipv6.pcap sniffer-static-rsa.pcap sniffer-testsuite.test sniffer-tls12-keylog.out sniffer-tls12-keylog.pcap sniffer-tls12-keylog.sslkeylog sniffer-tls13-dh-resume.pcap sniffer-tls13-dh.pcap sniffer-tls13-ecc-resume.pcap sniffer-tls13-ecc.pcap sniffer-tls13-hrr.pcap sniffer-tls13-keylog.out sniffer-tls13-keylog.pcap sniffer-tls13-keylog.sslkeylog sniffer-tls13-x25519-resume.pcap sniffer-tls13-x25519.pcap stm32l4-v4_0_1_build.sh tls13.test trusted_peer.test unit.test.in user_settings_asm.sh
src bio.c conf.c crl.c dtls.c dtls13.c include.am internal.c keys.c ocsp.c pk.c pk_ec.c pk_rsa.c quic.c sniffer.c ssl.c ssl_api_cert.c ssl_api_crl_ocsp.c ssl_api_pk.c ssl_asn1.c ssl_bn.c ssl_certman.c ssl_crypto.c ssl_ech.c ssl_load.c ssl_misc.c ssl_p7p12.c ssl_sess.c ssl_sk.c tls.c tls13.c wolfio.c x509.c x509_str.c
sslSniffer
sslSnifferTest README_WIN.md include.am snifftest.c sslSniffTest.vcproj sslSniffTest.vcxproj
README.md sslSniffer.vcproj sslSniffer.vcxproj
support gen-debug-trace-error-codes.sh include.am wolfssl.pc.in
tests
api api.h api_decl.h create_ocsp_test_blobs.py include.am test_aes.c test_aes.h test_arc4.c test_arc4.h test_ascon.c test_ascon.h test_ascon_kats.h test_asn.c test_asn.h test_blake2.c test_blake2.h test_camellia.c test_camellia.h test_certman.c test_certman.h test_chacha.c test_chacha.h test_chacha20_poly1305.c test_chacha20_poly1305.h test_cmac.c test_cmac.h test_curve25519.c test_curve25519.h test_curve448.c test_curve448.h test_des3.c test_des3.h test_dh.c test_dh.h test_digest.h test_dsa.c test_dsa.h test_dtls.c test_dtls.h test_ecc.c test_ecc.h test_ed25519.c test_ed25519.h test_ed448.c test_ed448.h test_evp.c test_evp.h test_evp_cipher.c test_evp_cipher.h test_evp_digest.c test_evp_digest.h test_evp_pkey.c test_evp_pkey.h test_hash.c test_hash.h test_hmac.c test_hmac.h test_md2.c test_md2.h test_md4.c test_md4.h test_md5.c test_md5.h test_mldsa.c test_mldsa.h test_mlkem.c test_mlkem.h test_ocsp.c test_ocsp.h test_ocsp_test_blobs.h test_ossl_asn1.c test_ossl_asn1.h test_ossl_bio.c test_ossl_bio.h test_ossl_bn.c test_ossl_bn.h test_ossl_cipher.c test_ossl_cipher.h test_ossl_dgst.c test_ossl_dgst.h test_ossl_dh.c test_ossl_dh.h test_ossl_dsa.c test_ossl_dsa.h test_ossl_ec.c test_ossl_ec.h test_ossl_ecx.c test_ossl_ecx.h test_ossl_mac.c test_ossl_mac.h test_ossl_obj.c test_ossl_obj.h test_ossl_p7p12.c test_ossl_p7p12.h test_ossl_pem.c test_ossl_pem.h test_ossl_rand.c test_ossl_rand.h test_ossl_rsa.c test_ossl_rsa.h test_ossl_sk.c test_ossl_sk.h test_ossl_x509.c test_ossl_x509.h test_ossl_x509_acert.c test_ossl_x509_acert.h test_ossl_x509_crypto.c test_ossl_x509_crypto.h test_ossl_x509_ext.c test_ossl_x509_ext.h test_ossl_x509_info.c test_ossl_x509_info.h test_ossl_x509_io.c test_ossl_x509_io.h test_ossl_x509_lu.c test_ossl_x509_lu.h test_ossl_x509_name.c test_ossl_x509_name.h test_ossl_x509_pk.c test_ossl_x509_pk.h test_ossl_x509_str.c test_ossl_x509_str.h test_ossl_x509_vp.c test_ossl_x509_vp.h test_pkcs12.c test_pkcs12.h test_pkcs7.c test_pkcs7.h test_poly1305.c test_poly1305.h test_random.c test_random.h test_rc2.c test_rc2.h test_ripemd.c test_ripemd.h test_rsa.c test_rsa.h test_sha.c test_sha.h test_sha256.c test_sha256.h test_sha3.c test_sha3.h test_sha512.c test_sha512.h test_she.c test_she.h test_signature.c test_signature.h test_slhdsa.c test_slhdsa.h test_sm2.c test_sm2.h test_sm3.c test_sm3.h test_sm4.c test_sm4.h test_tls.c test_tls.h test_tls13.c test_tls13.h test_tls_ext.c test_tls_ext.h test_wc_encrypt.c test_wc_encrypt.h test_wolfmath.c test_wolfmath.h test_x509.c test_x509.h
emnet
IP IP.h
Makefile emnet_nonblock_test.c emnet_shim.c
freertos-mem-track-repro FreeRTOS.h repro.c run.sh semphr.h task.h user_settings.h
swdev .gitignore Makefile README.md swdev.c swdev.h swdev_loader.c swdev_loader.h user_settings.h
CONF_FILES_README.md NCONF_test.cnf README TXT_DB.txt api.c include.am quic.c srp.c suites.c test-altchains.conf test-chains.conf test-dhprime.conf test-dtls-downgrade.conf test-dtls-fails-cipher.conf test-dtls-fails.conf test-dtls-group.conf test-dtls-mtu.conf test-dtls-reneg-client.conf test-dtls-reneg-server.conf test-dtls-resume.conf test-dtls-sha2.conf test-dtls-srtp-fails.conf test-dtls-srtp.conf test-dtls.conf test-dtls13-cid.conf test-dtls13-downgrade-fails.conf test-dtls13-downgrade.conf test-dtls13-pq-hybrid-extra-frag.conf test-dtls13-pq-hybrid-extra.conf test-dtls13-pq-hybrid-frag.conf test-dtls13-pq-standalone-frag.conf test-dtls13-pq-standalone.conf test-dtls13-psk.conf test-dtls13.conf test-ecc-cust-curves.conf test-ed25519.conf test-ed448.conf test-enckeys.conf test-fails.conf test-maxfrag-dtls.conf test-maxfrag.conf test-p521.conf test-psk-no-id-sha2.conf test-psk-no-id.conf test-psk.conf test-rsapss.conf test-sctp-sha2.conf test-sctp.conf test-sha2.conf test-sig.conf test-sm2.conf test-tls-downgrade.conf test-tls13-down.conf test-tls13-ecc.conf test-tls13-pq-hybrid-extra.conf test-tls13-pq-hybrid.conf test-tls13-pq-standalone.conf test-tls13-psk-certs.conf test-tls13-psk.conf test-tls13-slhdsa-fail.conf test-tls13-slhdsa-sha2.conf test-tls13-slhdsa-shake.conf test-tls13.conf test-trustpeer.conf test.conf unit.c unit.h utils.c utils.h w64wrapper.c
testsuite include.am testsuite.c testsuite.sln testsuite.vcproj testsuite.vcxproj utils.c utils.h
tirtos
packages
ti
net
wolfssl
tests
EK_TM4C1294XL
wolfcrypt
benchmark TM4C1294NC.icf benchmark.cfg main.c package.bld.hide package.xdc
test TM4C1294NC.icf main.c package.bld.hide package.xdc test.cfg
package.bld package.xdc package.xs
.gitignore README include.am products.mak wolfssl.bld wolfssl.mak
wolfcrypt
benchmark README.md benchmark-VS2022.sln benchmark-VS2022.vcxproj benchmark-VS2022.vcxproj.user benchmark.c benchmark.h benchmark.sln benchmark.vcproj benchmark.vcxproj include.am
src
port
Espressif
esp_crt_bundle README.md cacrt_all.pem cacrt_deprecated.pem cacrt_local.pem esp_crt_bundle.c gen_crt_bundle.py pio_install_cryptography.py
README.md esp32_aes.c esp32_mp.c esp32_sha.c esp32_util.c esp_sdk_mem_lib.c esp_sdk_time_lib.c esp_sdk_wifi_lib.c
Renesas README.md renesas_common.c renesas_fspsm_aes.c renesas_fspsm_rsa.c renesas_fspsm_sha.c renesas_fspsm_util.c renesas_rx64_hw_sha.c renesas_rx64_hw_util.c renesas_tsip_aes.c renesas_tsip_rsa.c renesas_tsip_sha.c renesas_tsip_util.c
af_alg afalg_aes.c afalg_hash.c wc_afalg.c
aria aria-crypt.c aria-cryptocb.c
arm armv8-32-aes-asm.S armv8-32-aes-asm_c.c armv8-32-chacha-asm.S armv8-32-chacha-asm_c.c armv8-32-curve25519.S armv8-32-curve25519_c.c armv8-32-mlkem-asm.S armv8-32-mlkem-asm_c.c armv8-32-poly1305-asm.S armv8-32-poly1305-asm_c.c armv8-32-sha256-asm.S armv8-32-sha256-asm_c.c armv8-32-sha3-asm.S armv8-32-sha3-asm_c.c armv8-32-sha512-asm.S armv8-32-sha512-asm_c.c armv8-aes-asm.S armv8-aes-asm_c.c armv8-aes.c armv8-chacha-asm.S armv8-chacha-asm_c.c armv8-curve25519.S armv8-curve25519_c.c armv8-mlkem-asm.S armv8-mlkem-asm_c.c armv8-poly1305-asm.S armv8-poly1305-asm_c.c armv8-sha256-asm.S armv8-sha256-asm_c.c armv8-sha256.c armv8-sha3-asm.S armv8-sha3-asm_c.c armv8-sha512-asm.S armv8-sha512-asm_c.c armv8-sha512.c cryptoCell.c cryptoCellHash.c thumb2-aes-asm.S thumb2-aes-asm_c.c thumb2-chacha-asm.S thumb2-chacha-asm_c.c thumb2-curve25519.S thumb2-curve25519_c.c thumb2-mlkem-asm.S thumb2-mlkem-asm_c.c thumb2-poly1305-asm.S thumb2-poly1305-asm_c.c thumb2-sha256-asm.S thumb2-sha256-asm_c.c thumb2-sha3-asm.S thumb2-sha3-asm_c.c thumb2-sha512-asm.S thumb2-sha512-asm_c.c
atmel README.md atmel.c
autosar README.md cryif.c crypto.c csm.c include.am test.c
caam README.md caam_aes.c caam_doc.pdf caam_driver.c caam_error.c caam_integrity.c caam_qnx.c caam_sha.c wolfcaam_aes.c wolfcaam_cmac.c wolfcaam_ecdsa.c wolfcaam_fsl_nxp.c wolfcaam_hash.c wolfcaam_hmac.c wolfcaam_init.c wolfcaam_qnx.c wolfcaam_rsa.c wolfcaam_seco.c wolfcaam_x25519.c
cavium README.md README_Octeon.md cavium_nitrox.c cavium_octeon_sync.c
cuda README.md aes-cuda.cu
cypress README.md psoc6_crypto.c
devcrypto README.md devcrypto_aes.c devcrypto_ecdsa.c devcrypto_hash.c devcrypto_hmac.c devcrypto_rsa.c devcrypto_x25519.c wc_devcrypto.c
intel README.md quickassist.c quickassist_mem.c quickassist_sync.c
iotsafe iotsafe.c
kcapi README.md kcapi_aes.c kcapi_dh.c kcapi_ecc.c kcapi_hash.c kcapi_hmac.c kcapi_rsa.c
liboqs liboqs.c
maxim README.md max3266x.c maxq10xx.c
mynewt mynewt_port.c
nxp README.md README_SE050.md casper_port.c dcp_port.c hashcrypt_port.c ksdk_port.c se050_port.c
pic32 pic32mz-crypt.c
ppc32 ppc32-sha256-asm.S ppc32-sha256-asm_c.c ppc32-sha256-asm_cr.c
psa README.md psa.c psa_aes.c psa_hash.c psa_pkcbs.c
riscv riscv-64-aes.c riscv-64-chacha.c riscv-64-poly1305.c riscv-64-sha256.c riscv-64-sha3.c riscv-64-sha512.c
rpi_pico README.md pico.c
silabs README.md silabs_aes.c silabs_ecc.c silabs_hash.c silabs_random.c
st README.md STM32MP13.md STM32MP25.md stm32.c stsafe.c
ti ti-aes.c ti-ccm.c ti-des3.c ti-hash.c
tropicsquare README.md tropic01.c
xilinx xil-aesgcm.c xil-sha3.c xil-versal-glue.c xil-versal-trng.c
nrf51.c
ASN_TEMPLATE.md aes.c aes_asm.S aes_asm.asm aes_gcm_asm.S aes_gcm_asm.asm aes_gcm_x86_asm.S aes_xts_asm.S aes_xts_asm.asm arc4.c ascon.c asm.c asn.c asn_orig.c async.c blake2b.c blake2s.c camellia.c chacha.c chacha20_poly1305.c chacha_asm.S chacha_asm.asm cmac.c coding.c compress.c cpuid.c cryptocb.c curve25519.c curve448.c des3.c dh.c dilithium.c dsa.c ecc.c ecc_fp.c eccsi.c ed25519.c ed448.c error.c evp.c evp_pk.c falcon.c fe_448.c fe_low_mem.c fe_operations.c fe_x25519_128.h fe_x25519_asm.S fp_mont_small.i fp_mul_comba_12.i fp_mul_comba_17.i fp_mul_comba_20.i fp_mul_comba_24.i fp_mul_comba_28.i fp_mul_comba_3.i fp_mul_comba_32.i fp_mul_comba_4.i fp_mul_comba_48.i fp_mul_comba_6.i fp_mul_comba_64.i fp_mul_comba_7.i fp_mul_comba_8.i fp_mul_comba_9.i fp_mul_comba_small_set.i fp_sqr_comba_12.i fp_sqr_comba_17.i fp_sqr_comba_20.i fp_sqr_comba_24.i fp_sqr_comba_28.i fp_sqr_comba_3.i fp_sqr_comba_32.i fp_sqr_comba_4.i fp_sqr_comba_48.i fp_sqr_comba_6.i fp_sqr_comba_64.i fp_sqr_comba_7.i fp_sqr_comba_8.i fp_sqr_comba_9.i fp_sqr_comba_small_set.i ge_448.c ge_low_mem.c ge_operations.c hash.c hmac.c hpke.c include.am integer.c kdf.c logging.c md2.c md4.c md5.c memory.c misc.c pkcs12.c pkcs7.c poly1305.c poly1305_asm.S poly1305_asm.asm puf.c pwdbased.c random.c rc2.c ripemd.c rng_bank.c rsa.c sakke.c sha.c sha256.c sha256_asm.S sha3.c sha3_asm.S sha512.c sha512_asm.S signature.c siphash.c sm2.c sm3.c sm3_asm.S sm4.c sp_arm32.c sp_arm64.c sp_armthumb.c sp_c32.c sp_c64.c sp_cortexm.c sp_dsp32.c sp_int.c sp_sm2_arm32.c sp_sm2_arm64.c sp_sm2_armthumb.c sp_sm2_c32.c sp_sm2_c64.c sp_sm2_cortexm.c sp_sm2_x86_64.c sp_sm2_x86_64_asm.S sp_x86_64.c sp_x86_64_asm.S sp_x86_64_asm.asm srp.c tfm.c wc_dsp.c wc_encrypt.c wc_lms.c wc_lms_impl.c wc_mldsa_asm.S wc_mlkem.c wc_mlkem_asm.S wc_mlkem_poly.c wc_pkcs11.c wc_port.c wc_she.c wc_slhdsa.c wc_xmss.c wc_xmss_impl.c wolfentropy.c wolfevent.c wolfmath.c
test README.md include.am test-VS2022.sln test-VS2022.vcxproj test-VS2022.vcxproj.user test.c test.h test.sln test.vcproj test_paths.h.in
wolfssl
openssl aes.h asn1.h asn1t.h bio.h bn.h buffer.h camellia.h cmac.h cms.h compat_types.h conf.h crypto.h des.h dh.h dsa.h ec.h ec25519.h ec448.h ecdh.h ecdsa.h ed25519.h ed448.h engine.h err.h evp.h fips_rand.h hmac.h include.am kdf.h lhash.h md4.h md5.h modes.h obj_mac.h objects.h ocsp.h opensslconf.h opensslv.h ossl_typ.h pem.h pkcs12.h pkcs7.h rand.h rc4.h ripemd.h rsa.h safestack.h sha.h sha3.h srp.h ssl.h ssl23.h stack.h tls1.h txt_db.h ui.h x509.h x509_vfy.h x509v3.h
wolfcrypt
port
Espressif esp-sdk-lib.h esp32-crypt.h esp_crt_bundle.h
Renesas renesas-fspsm-crypt.h renesas-fspsm-types.h renesas-rx64-hw-crypt.h renesas-tsip-crypt.h renesas_cmn.h renesas_fspsm_internal.h renesas_sync.h renesas_tsip_internal.h renesas_tsip_types.h
af_alg afalg_hash.h wc_afalg.h
aria aria-crypt.h aria-cryptocb.h
arm cryptoCell.h
atmel atmel.h
autosar CryIf.h Crypto.h Csm.h StandardTypes.h
caam caam_driver.h caam_error.h caam_qnx.h wolfcaam.h wolfcaam_aes.h wolfcaam_cmac.h wolfcaam_ecdsa.h wolfcaam_fsl_nxp.h wolfcaam_hash.h wolfcaam_qnx.h wolfcaam_rsa.h wolfcaam_seco.h wolfcaam_sha.h wolfcaam_x25519.h
cavium cavium_nitrox.h cavium_octeon_sync.h
cypress psoc6_crypto.h
devcrypto wc_devcrypto.h
intel quickassist.h quickassist_mem.h quickassist_sync.h
iotsafe iotsafe.h
kcapi kcapi_dh.h kcapi_ecc.h kcapi_hash.h kcapi_hmac.h kcapi_rsa.h wc_kcapi.h
liboqs liboqs.h
maxim max3266x-cryptocb.h max3266x.h maxq10xx.h
nxp casper_port.h dcp_port.h hashcrypt_port.h ksdk_port.h se050_port.h
pic32 pic32mz-crypt.h
psa psa.h
riscv riscv-64-asm.h
rpi_pico pico.h
silabs silabs_aes.h silabs_ecc.h silabs_hash.h silabs_random.h
st stm32.h stsafe.h
ti ti-ccm.h ti-hash.h
tropicsquare tropic01.h
xilinx xil-sha3.h xil-versal-glue.h xil-versal-trng.h
nrf51.h
aes.h arc4.h ascon.h asn.h asn_public.h async.h blake2-impl.h blake2-int.h blake2.h camellia.h chacha.h chacha20_poly1305.h cmac.h coding.h compress.h cpuid.h cryptocb.h curve25519.h curve448.h des3.h dh.h dilithium.h dsa.h ecc.h eccsi.h ed25519.h ed448.h error-crypt.h falcon.h fe_448.h fe_operations.h fips_test.h ge_448.h ge_operations.h hash.h hmac.h hpke.h include.am integer.h kdf.h libwolfssl_sources.h libwolfssl_sources_asm.h logging.h md2.h md4.h md5.h mem_track.h memory.h misc.h mpi_class.h mpi_superclass.h oid_sum.h pkcs11.h pkcs12.h pkcs7.h poly1305.h puf.h pwdbased.h random.h rc2.h ripemd.h rng_bank.h rsa.h sakke.h selftest.h settings.h sha.h sha256.h sha3.h sha512.h signature.h siphash.h sm2.h sm3.h sm4.h sp.h sp_int.h srp.h tfm.h types.h visibility.h wc_encrypt.h wc_lms.h wc_mlkem.h wc_pkcs11.h wc_port.h wc_she.h wc_slhdsa.h wc_xmss.h wolfentropy.h wolfevent.h wolfmath.h
callbacks.h certs_test.h certs_test_sm.h crl.h error-ssl.h include.am internal.h ocsp.h options.h.in quic.h sniffer.h sniffer_error.h sniffer_error.rc ssl.h test.h version.h version.h.in wolfio.h
wrapper
Ada
examples
src aes_verify_main.adb rsa_verify_main.adb sha256_main.adb spark_sockets.adb spark_sockets.ads spark_terminal.adb spark_terminal.ads tls_client.adb tls_client.ads tls_client_main.adb tls_server.adb tls_server.ads tls_server_main.adb
.gitignore alire.toml examples.gpr
tests
src
support test_support.adb test_support.ads tests_root_suite.adb tests_root_suite.ads
aes_bindings_tests.adb aes_bindings_tests.ads rsa_verify_bindings_tests.adb rsa_verify_bindings_tests.ads sha256_bindings_tests.adb sha256_bindings_tests.ads tests.adb
.gitignore README.md alire.toml tests.gpr valgrind.supp
.gitignore README.md ada_binding.c alire.toml default.gpr include.am restricted.adc user_settings.h wolfssl-full_runtime.adb wolfssl-full_runtime.ads wolfssl.adb wolfssl.ads wolfssl.gpr
CSharp
wolfCrypt-Test
Properties AssemblyInfo.cs
App.config wolfCrypt-Test.cs wolfCrypt-Test.csproj
wolfSSL-DTLS-PSK-Server
Properties AssemblyInfo.cs
App.config wolfSSL-DTLS-PSK-Server.cs wolfSSL-DTLS-PSK-Server.csproj
wolfSSL-DTLS-Server
Properties AssemblyInfo.cs
App.config wolfSSL-DTLS-Server.cs wolfSSL-DTLS-Server.csproj
wolfSSL-Example-IOCallbacks
Properties AssemblyInfo.cs
App.config wolfSSL-Example-IOCallbacks.cs wolfSSL-Example-IOCallbacks.csproj
wolfSSL-TLS-Client
Properties AssemblyInfo.cs
App.config wolfSSL-TLS-Client.cs wolfSSL-TLS-Client.csproj
wolfSSL-TLS-PSK-Client
Properties AssemblyInfo.cs
App.config wolfSSL-TLS-PSK-Client.cs wolfSSL-TLS-PSK-Client.csproj
wolfSSL-TLS-PSK-Server
Properties AssemblyInfo.cs
App.config wolfSSL-TLS-PSK-Server.cs wolfSSL-TLS-PSK-Server.csproj
wolfSSL-TLS-Server
Properties AssemblyInfo.cs
App.config wolfSSL-TLS-Server.cs wolfSSL-TLS-Server.csproj
wolfSSL-TLS-ServerThreaded
Properties AssemblyInfo.cs
App.config wolfSSL-TLS-ServerThreaded.cs wolfSSL-TLS-ServerThreaded.csproj
wolfSSL_CSharp
Properties AssemblyInfo.cs Resources.Designer.cs Resources.resx
X509.cs wolfCrypt.cs wolfSSL.cs wolfSSL_CSharp.csproj
README.md include.am user_settings.h wolfSSL_CSharp.sln wolfssl.vcxproj
python README.md
rust
wolfssl-wolfcrypt
src aes.rs blake2.rs chacha20_poly1305.rs cmac.rs cmac_mac.rs curve25519.rs dh.rs dilithium.rs ecc.rs ecdsa.rs ed25519.rs ed448.rs fips.rs hkdf.rs hmac.rs hmac_mac.rs kdf.rs lib.rs lms.rs mlkem.rs mlkem_kem.rs pbkdf2_password_hash.rs prf.rs random.rs rsa.rs rsa_pkcs1v15.rs sha.rs sha_digest.rs sys.rs
tests
common mod.rs
test_aes.rs test_blake2.rs test_chacha20_poly1305.rs test_cmac.rs test_cmac_mac.rs test_curve25519.rs test_dh.rs test_dilithium.rs test_ecc.rs test_ecdsa.rs test_ed25519.rs test_ed448.rs test_hkdf.rs test_hmac.rs test_hmac_mac.rs test_kdf.rs test_lms.rs test_mlkem.rs test_mlkem_kem.rs test_pbkdf2_password_hash.rs test_prf.rs test_random.rs test_rsa.rs test_rsa_pkcs1v15.rs test_sha.rs test_sha_digest.rs test_wolfcrypt.rs
CHANGELOG.md Cargo.lock Cargo.toml Makefile README.md build.rs headers.h
Makefile README.md include.am
include.am
zephyr
samples
wolfssl_benchmark
boards native_sim.conf nrf5340dk_nrf5340_cpuapp.conf nrf5340dk_nrf5340_cpuapp_ns.conf
CMakeLists.txt README install_test.sh prj.conf sample.yaml zephyr_legacy.conf zephyr_v4.1.conf
wolfssl_test
boards native_sim.conf nrf5340dk_nrf5340_cpuapp.conf nrf5340dk_nrf5340_cpuapp_ns.conf
CMakeLists.txt README install_test.sh prj-no-malloc.conf prj.conf sample.yaml zephyr_legacy.conf zephyr_v4.1.conf
wolfssl_tls_sock
boards native_sim.conf
src tls_sock.c
CMakeLists.txt README install_sample.sh prj-no-malloc.conf prj.conf sample.yaml zephyr_legacy.conf zephyr_v4.1.conf
wolfssl_tls_thread
boards native_sim.conf nrf5340dk_nrf5340_cpuapp.conf nrf5340dk_nrf5340_cpuapp_ns.conf
src tls_threaded.c
CMakeLists.txt README install_sample.sh prj.conf sample.yaml zephyr_legacy.conf zephyr_v4.1.conf
wolfssl options.h
CMakeLists.txt Kconfig Kconfig.tls-generic README.md include.am module.yml user_settings-no-malloc.h user_settings.h zephyr_init.c
.codespellexcludelines .cyignore .editorconfig .gitignore .wolfssl_known_macro_extras AUTHORS CMakeLists.txt CMakePresets.json CMakeSettings.json COPYING ChangeLog.md INSTALL LICENSING LPCExpresso.cproject LPCExpresso.project Makefile.am README README-async.md README.md SCRIPTS-LIST SECURITY-POLICY.md SECURITY-REPORT-TEMPLATE.md Vagrantfile autogen.sh commit-tests.sh configure.ac fips-check.sh fips-hash.sh gencertbuf.pl input pull_to_vagrant.sh quit resource.h stamp-h.in valgrind-bash.supp valgrind-error.sh wnr-example.conf wolfssl-VS2022.vcxproj wolfssl.rc wolfssl.vcproj wolfssl.vcxproj wolfssl64.sln
.clangd .gitignore DOCS.md Makefile README.md assert.c core.c crypto.c env.c fs.c http.c ini.c json.c log.c luna.h main.c makext.mk path.c process.c request.c sqlite.c stash.c template.c util.c
curl/lib/vquic/curl_ngtcp2.c raw
   1/***************************************************************************
   2 *                                  _   _ ____  _
   3 *  Project                     ___| | | |  _ \| |
   4 *                             / __| | | | |_) | |
   5 *                            | (__| |_| |  _ <| |___
   6 *                             \___|\___/|_| \_\_____|
   7 *
   8 * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
   9 *
  10 * This software is licensed as described in the file COPYING, which
  11 * you should have received as part of this distribution. The terms
  12 * are also available at https://curl.se/docs/copyright.html.
  13 *
  14 * You may opt to use, copy, modify, merge, publish, distribute and/or sell
  15 * copies of the Software, and permit persons to whom the Software is
  16 * furnished to do so, under the terms of the COPYING file.
  17 *
  18 * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
  19 * KIND, either express or implied.
  20 *
  21 * SPDX-License-Identifier: curl
  22 *
  23 ***************************************************************************/
  24#include "curl_setup.h"
  25
  26#if !defined(CURL_DISABLE_HTTP) && defined(USE_NGTCP2) && defined(USE_NGHTTP3)
  27#include <ngtcp2/ngtcp2.h>
  28#include <nghttp3/nghttp3.h>
  29
  30#ifdef USE_OPENSSL
  31#include <openssl/err.h>
  32#if defined(OPENSSL_IS_AWSLC) || defined(OPENSSL_IS_BORINGSSL)
  33#include <ngtcp2/ngtcp2_crypto_boringssl.h>
  34#elif defined(OPENSSL_QUIC_API2)
  35#include <ngtcp2/ngtcp2_crypto_ossl.h>
  36#else
  37#include <ngtcp2/ngtcp2_crypto_quictls.h>
  38#endif
  39#include "vtls/openssl.h"
  40#elif defined(USE_GNUTLS)
  41#include <ngtcp2/ngtcp2_crypto_gnutls.h>
  42#include "vtls/gtls.h"
  43#elif defined(USE_WOLFSSL)
  44#include <ngtcp2/ngtcp2_crypto_wolfssl.h>
  45#include "vtls/wolfssl.h"
  46#endif
  47
  48#include "urldata.h"
  49#include "url.h"
  50#include "uint-hash.h"
  51#include "curl_trc.h"
  52#include "rand.h"
  53#include "multiif.h"
  54#include "cfilters.h"
  55#include "cf-dns.h"
  56#include "cf-socket.h"
  57#include "connect.h"
  58#include "progress.h"
  59#include "curlx/fopen.h"
  60#include "curlx/dynbuf.h"
  61#include "http1.h"
  62#include "select.h"
  63#include "transfer.h"
  64#include "bufref.h"
  65#include "vquic/vquic.h"
  66#include "vquic/vquic_int.h"
  67#include "vquic/vquic-tls.h"
  68#include "vtls/vtls.h"
  69#include "vtls/vtls_scache.h"
  70#include "vquic/curl_ngtcp2.h"
  71
  72
  73#define QUIC_MAX_STREAMS       (256 * 1024)
  74#define QUIC_HANDSHAKE_TIMEOUT (10 * NGTCP2_SECONDS)
  75
  76/* We announce a small window size in transport param to the server,
  77 * and grow that immediately to max when no rate limit is in place.
  78 * We need to start small as we are not able to decrease it. */
  79#define H3_STREAM_WINDOW_SIZE_INITIAL (32 * 1024)
  80#define H3_STREAM_WINDOW_SIZE_MAX     (10 * 1024 * 1024)
  81#define H3_CONN_WINDOW_SIZE_MAX       (100 * H3_STREAM_WINDOW_SIZE_MAX)
  82
  83#define H3_STREAM_CHUNK_SIZE  (64 * 1024)
  84#if H3_STREAM_CHUNK_SIZE < NGTCP2_MAX_UDP_PAYLOAD_SIZE
  85#error H3_STREAM_CHUNK_SIZE smaller than NGTCP2_MAX_UDP_PAYLOAD_SIZE
  86#endif
  87
  88/* The pool keeps spares around and half of a full stream windows
  89 * seems good. More does not seem to improve performance.
  90 * The benefit of the pool is that stream buffer to not keep
  91 * spares. Memory consumption goes down when streams run empty,
  92 * have a large upload done, etc. */
  93#define H3_STREAM_POOL_SPARES      2
  94/* The max amount of un-acked upload data we keep around per stream */
  95#define H3_STREAM_SEND_BUFFER_MAX      (10 * 1024 * 1024)
  96#define H3_STREAM_SEND_CHUNKS \
  97  (H3_STREAM_SEND_BUFFER_MAX / H3_STREAM_CHUNK_SIZE)
  98
  99/*
 100 * Store ngtcp2 version info in this buffer.
 101 */
 102void Curl_ngtcp2_ver(char *p, size_t len)
 103{
 104  const ngtcp2_info *ng2 = ngtcp2_version(0);
 105  const nghttp3_info *ht3 = nghttp3_version(0);
 106  (void)curl_msnprintf(p, len, "ngtcp2/%s nghttp3/%s",
 107                       ng2->version_str, ht3->version_str);
 108}
 109
 110struct cf_ngtcp2_ctx {
 111  struct cf_quic_ctx q;
 112  struct ssl_peer peer;
 113  struct curl_tls_ctx tls;
 114#ifdef OPENSSL_QUIC_API2
 115  ngtcp2_crypto_ossl_ctx *ossl_ctx;
 116#endif
 117  ngtcp2_path connected_path;
 118  ngtcp2_conn *qconn;
 119  ngtcp2_cid dcid;
 120  ngtcp2_cid scid;
 121  uint32_t version;
 122  ngtcp2_settings settings;
 123  ngtcp2_transport_params transport_params;
 124  ngtcp2_ccerr last_error;
 125  ngtcp2_crypto_conn_ref conn_ref;
 126  struct cf_call_data call_data;
 127  nghttp3_conn *h3conn;
 128  nghttp3_settings h3settings;
 129  struct curltime started_at;        /* time the current attempt started */
 130  struct curltime handshake_at;      /* time connect handshake finished */
 131  struct bufc_pool stream_bufcp;     /* chunk pool for streams */
 132  struct dynbuf scratch;             /* temp buffer for header construction */
 133  struct uint_hash streams;          /* hash `data->mid` to `h3_stream_ctx` */
 134  uint64_t used_bidi_streams;        /* bidi streams we have opened */
 135  uint64_t max_bidi_streams;         /* max bidi streams we can open */
 136  size_t earlydata_max;              /* max amount of early data supported by
 137                                        server on session reuse */
 138  size_t earlydata_skip;             /* sending bytes to skip when earlydata
 139                                        is accepted by peer */
 140  CURLcode tls_vrfy_result;          /* result of TLS peer verification */
 141  int qlogfd;
 142  BIT(initialized);
 143  BIT(tls_handshake_complete);       /* TLS handshake is done */
 144  BIT(use_earlydata);                /* Using 0RTT data */
 145  BIT(earlydata_accepted);           /* 0RTT was accepted by server */
 146  BIT(shutdown_started);             /* queued shutdown packets */
 147};
 148
 149/* How to access `call_data` from a cf_ngtcp2 filter */
 150#undef CF_CTX_CALL_DATA
 151#define CF_CTX_CALL_DATA(cf) ((struct cf_ngtcp2_ctx *)(cf)->ctx)->call_data
 152
 153static void h3_stream_hash_free(unsigned int id, void *stream);
 154
 155static void cf_ngtcp2_ctx_init(struct cf_ngtcp2_ctx *ctx)
 156{
 157  DEBUGASSERT(!ctx->initialized);
 158  ctx->qlogfd = -1;
 159  ctx->version = NGTCP2_PROTO_VER_MAX;
 160  Curl_bufcp_init(&ctx->stream_bufcp, H3_STREAM_CHUNK_SIZE,
 161                  H3_STREAM_POOL_SPARES);
 162  curlx_dyn_init(&ctx->scratch, CURL_MAX_HTTP_HEADER);
 163  Curl_uint32_hash_init(&ctx->streams, 63, h3_stream_hash_free);
 164  ctx->initialized = TRUE;
 165}
 166
 167static void cf_ngtcp2_ctx_free(struct cf_ngtcp2_ctx *ctx)
 168{
 169  if(ctx && ctx->initialized) {
 170    Curl_vquic_tls_cleanup(&ctx->tls);
 171    vquic_ctx_free(&ctx->q);
 172    Curl_bufcp_free(&ctx->stream_bufcp);
 173    curlx_dyn_free(&ctx->scratch);
 174    Curl_uint32_hash_destroy(&ctx->streams);
 175    Curl_ssl_peer_cleanup(&ctx->peer);
 176  }
 177  curlx_free(ctx);
 178}
 179
 180static void cf_ngtcp2_setup_keep_alive(struct Curl_cfilter *cf,
 181                                       struct Curl_easy *data)
 182{
 183  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 184  const ngtcp2_transport_params *rp;
 185  /* Peer should have sent us its transport parameters. If it
 186   * announces a positive `max_idle_timeout` it closes the
 187   * connection when it does not hear from us for that time.
 188   *
 189   * Some servers use this as a keep-alive timer at a rather low
 190   * value. We are doing HTTP/3 here and waiting for the response
 191   * to a request may take a considerable amount of time. We need
 192   * to prevent the peer's QUIC stack from closing in this case.
 193   */
 194  if(!ctx->qconn)
 195    return;
 196
 197  rp = ngtcp2_conn_get_remote_transport_params(ctx->qconn);
 198  if(!rp || !rp->max_idle_timeout) {
 199    ngtcp2_conn_set_keep_alive_timeout(ctx->qconn, UINT64_MAX);
 200    CURL_TRC_CF(data, cf, "no peer idle timeout, unset keep-alive");
 201  }
 202  else if(!Curl_uint32_hash_count(&ctx->streams)) {
 203    ngtcp2_conn_set_keep_alive_timeout(ctx->qconn, UINT64_MAX);
 204    CURL_TRC_CF(data, cf, "no active streams, unset keep-alive");
 205  }
 206  else {
 207    ngtcp2_duration keep_ns;
 208    keep_ns = (rp->max_idle_timeout > 1) ? (rp->max_idle_timeout / 2) : 1;
 209    ngtcp2_conn_set_keep_alive_timeout(ctx->qconn, keep_ns);
 210    CURL_TRC_CF(data, cf, "peer idle timeout is %" PRIu64 "ms, "
 211                "set keep-alive to %" PRIu64 " ms.",
 212                (rp->max_idle_timeout / NGTCP2_MILLISECONDS),
 213                (keep_ns / NGTCP2_MILLISECONDS));
 214  }
 215}
 216
 217struct pkt_io_ctx;
 218static CURLcode cf_progress_ingress(struct Curl_cfilter *cf,
 219                                    struct Curl_easy *data,
 220                                    struct pkt_io_ctx *pktx);
 221static CURLcode cf_progress_egress(struct Curl_cfilter *cf,
 222                                   struct Curl_easy *data,
 223                                   struct pkt_io_ctx *pktx);
 224
 225/**
 226 * All about the H3 internals of a stream
 227 */
 228struct h3_stream_ctx {
 229  int64_t id;                   /* HTTP/3 protocol identifier */
 230  struct bufq sendbuf;          /* h3 request body */
 231  struct h1_req_parser h1;      /* h1 request parsing */
 232  size_t sendbuf_len_in_flight; /* sendbuf amount "in flight" */
 233  uint64_t error3;              /* HTTP/3 stream error code */
 234  curl_off_t upload_left;       /* number of request bytes left to upload */
 235  uint64_t rx_offset;           /* current receive offset */
 236  uint64_t rx_offset_max;       /* allowed receive offset */
 237  uint64_t window_size_max;     /* max flow control window set for stream */
 238  int status_code;              /* HTTP status code */
 239  CURLcode xfer_result;         /* result from xfer_resp_write(_hd) */
 240  BIT(resp_hds_complete);       /* we have a complete, final response */
 241  BIT(closed);                  /* TRUE on stream close */
 242  BIT(reset);                   /* TRUE on stream reset */
 243  BIT(send_closed);             /* stream is local closed */
 244  BIT(quic_flow_blocked);       /* stream is blocked by QUIC flow control */
 245};
 246
 247static void h3_stream_ctx_free(struct h3_stream_ctx *stream)
 248{
 249  Curl_bufq_free(&stream->sendbuf);
 250  Curl_h1_req_parse_free(&stream->h1);
 251  curlx_free(stream);
 252}
 253
 254static void h3_stream_hash_free(unsigned int id, void *stream)
 255{
 256  (void)id;
 257  DEBUGASSERT(stream);
 258  h3_stream_ctx_free((struct h3_stream_ctx *)stream);
 259}
 260
 261static CURLcode h3_data_setup(struct Curl_cfilter *cf,
 262                              struct Curl_easy *data)
 263{
 264  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 265  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
 266
 267  if(!data)
 268    return CURLE_FAILED_INIT;
 269
 270  if(stream)
 271    return CURLE_OK;
 272
 273  stream = curlx_calloc(1, sizeof(*stream));
 274  if(!stream)
 275    return CURLE_OUT_OF_MEMORY;
 276
 277  stream->id = -1;
 278  stream->rx_offset = 0;
 279  stream->rx_offset_max = H3_STREAM_WINDOW_SIZE_INITIAL;
 280
 281  /* on send, we control how much we put into the buffer */
 282  Curl_bufq_initp(&stream->sendbuf, &ctx->stream_bufcp,
 283                  H3_STREAM_SEND_CHUNKS, BUFQ_OPT_NONE);
 284  stream->sendbuf_len_in_flight = 0;
 285  stream->window_size_max = H3_STREAM_WINDOW_SIZE_INITIAL;
 286  Curl_h1_req_parse_init(&stream->h1, H1_PARSE_DEFAULT_MAX_LINE_LEN);
 287
 288  if(!Curl_uint32_hash_set(&ctx->streams, data->mid, stream)) {
 289    h3_stream_ctx_free(stream);
 290    return CURLE_OUT_OF_MEMORY;
 291  }
 292
 293  if(Curl_uint32_hash_count(&ctx->streams) == 1)
 294    cf_ngtcp2_setup_keep_alive(cf, data);
 295
 296  return CURLE_OK;
 297}
 298
 299#if NGTCP2_VERSION_NUM < 0x011100
 300struct cf_ngtcp2_sfind_ctx {
 301  int64_t stream_id;
 302  struct h3_stream_ctx *stream;
 303  uint32_t mid;
 304};
 305
 306static bool cf_ngtcp2_sfind(uint32_t mid, void *value, void *user_data)
 307{
 308  struct cf_ngtcp2_sfind_ctx *fctx = user_data;
 309  struct h3_stream_ctx *stream = value;
 310
 311  if(fctx->stream_id == stream->id) {
 312    fctx->mid = mid;
 313    fctx->stream = stream;
 314    return FALSE;
 315  }
 316  return TRUE; /* continue */
 317}
 318
 319static struct h3_stream_ctx *cf_ngtcp2_get_stream(struct cf_ngtcp2_ctx *ctx,
 320                                                  int64_t stream_id)
 321{
 322  struct cf_ngtcp2_sfind_ctx fctx;
 323  fctx.stream_id = stream_id;
 324  fctx.stream = NULL;
 325  Curl_uint32_hash_visit(&ctx->streams, cf_ngtcp2_sfind, &fctx);
 326  return fctx.stream;
 327}
 328#else
 329static struct h3_stream_ctx *cf_ngtcp2_get_stream(struct cf_ngtcp2_ctx *ctx,
 330                                                  int64_t stream_id)
 331{
 332  struct Curl_easy *data =
 333    ngtcp2_conn_get_stream_user_data(ctx->qconn, stream_id);
 334
 335  if(!data) {
 336    return NULL;
 337  }
 338
 339  return H3_STREAM_CTX(ctx, data);
 340}
 341#endif
 342
 343static void cf_ngtcp2_stream_close(struct Curl_cfilter *cf,
 344                                   struct Curl_easy *data,
 345                                   struct h3_stream_ctx *stream)
 346{
 347  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 348  DEBUGASSERT(data);
 349  DEBUGASSERT(stream);
 350  if(!stream->closed && ctx->qconn && ctx->h3conn) {
 351    CURLcode result;
 352
 353    nghttp3_conn_set_stream_user_data(ctx->h3conn, stream->id, NULL);
 354    ngtcp2_conn_set_stream_user_data(ctx->qconn, stream->id, NULL);
 355    stream->closed = TRUE;
 356    (void)ngtcp2_conn_shutdown_stream(ctx->qconn, 0, stream->id,
 357                                      NGHTTP3_H3_REQUEST_CANCELLED);
 358    result = cf_progress_egress(cf, data, NULL);
 359    if(result)
 360      CURL_TRC_CF(data, cf, "[%" PRId64 "] cancel stream -> %d",
 361                  stream->id, result);
 362  }
 363}
 364
 365static void h3_data_done(struct Curl_cfilter *cf, struct Curl_easy *data)
 366{
 367  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 368  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
 369  (void)cf;
 370  if(stream) {
 371    CURL_TRC_CF(data, cf, "[%" PRId64 "] easy handle is done", stream->id);
 372    cf_ngtcp2_stream_close(cf, data, stream);
 373    Curl_uint32_hash_remove(&ctx->streams, data->mid);
 374    if(!Curl_uint32_hash_count(&ctx->streams))
 375      cf_ngtcp2_setup_keep_alive(cf, data);
 376  }
 377}
 378
 379struct pkt_io_ctx {
 380  struct Curl_cfilter *cf;
 381  struct Curl_easy *data;
 382  ngtcp2_tstamp ts;
 383  ngtcp2_path_storage ps;
 384};
 385
 386static void pktx_update_time(struct Curl_easy *data,
 387                             struct pkt_io_ctx *pktx,
 388                             struct Curl_cfilter *cf)
 389{
 390  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 391  const struct curltime *pnow = Curl_pgrs_now(data);
 392
 393  vquic_ctx_update_time(&ctx->q, pnow);
 394  pktx->ts = ((ngtcp2_tstamp)pnow->tv_sec * NGTCP2_SECONDS) +
 395             ((ngtcp2_tstamp)pnow->tv_usec * NGTCP2_MICROSECONDS);
 396}
 397
 398static void pktx_init(struct pkt_io_ctx *pktx,
 399                      struct Curl_cfilter *cf,
 400                      struct Curl_easy *data)
 401{
 402  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 403  const struct curltime *pnow = Curl_pgrs_now(data);
 404
 405  pktx->cf = cf;
 406  pktx->data = data;
 407  ngtcp2_path_storage_zero(&pktx->ps);
 408  vquic_ctx_set_time(&ctx->q, pnow);
 409  pktx->ts = ((ngtcp2_tstamp)pnow->tv_sec * NGTCP2_SECONDS) +
 410             ((ngtcp2_tstamp)pnow->tv_usec * NGTCP2_MICROSECONDS);
 411}
 412
 413static int cb_h3_acked_req_body(nghttp3_conn *conn, int64_t stream_id,
 414                                uint64_t datalen, void *user_data,
 415                                void *stream_user_data);
 416
 417static ngtcp2_conn *get_conn(ngtcp2_crypto_conn_ref *conn_ref)
 418{
 419  struct Curl_cfilter *cf = conn_ref->user_data;
 420  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 421  return ctx->qconn;
 422}
 423
 424#ifdef DEBUG_NGTCP2
 425static void quic_printf(void *user_data, const char *fmt, ...)
 426{
 427  struct Curl_cfilter *cf = user_data;
 428  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 429
 430  (void)ctx;  /* need an easy handle to infof() message */
 431  va_list ap;
 432  va_start(ap, fmt);
 433  curl_mvfprintf(stderr, fmt, ap);
 434  va_end(ap);
 435  curl_mfprintf(stderr, "\n");
 436}
 437#endif
 438
 439static void qlog_callback(void *user_data, uint32_t flags,
 440                          const void *data, size_t datalen)
 441{
 442  struct Curl_cfilter *cf = user_data;
 443  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 444  (void)flags;
 445  if(ctx->qlogfd != -1) {
 446    ssize_t rc = write(ctx->qlogfd, data, datalen);
 447    if(rc == -1) {
 448      /* on write error, stop further write attempts */
 449      curlx_close(ctx->qlogfd);
 450      ctx->qlogfd = -1;
 451    }
 452  }
 453}
 454
 455static void quic_settings(struct cf_ngtcp2_ctx *ctx,
 456                          struct Curl_easy *data,
 457                          struct pkt_io_ctx *pktx)
 458{
 459  ngtcp2_settings *s = &ctx->settings;
 460  ngtcp2_transport_params *t = &ctx->transport_params;
 461
 462  ngtcp2_settings_default(s);
 463  ngtcp2_transport_params_default(t);
 464#ifdef DEBUG_NGTCP2
 465  s->log_printf = quic_printf;
 466#else
 467  s->log_printf = NULL;
 468#endif
 469
 470  s->initial_ts = pktx->ts;
 471  s->handshake_timeout = (data->set.connecttimeout > 0) ?
 472    data->set.connecttimeout * NGTCP2_MILLISECONDS : QUIC_HANDSHAKE_TIMEOUT;
 473  s->max_window = H3_CONN_WINDOW_SIZE_MAX;
 474  s->max_stream_window = 0; /* disable ngtcp2 auto-tuning of window */
 475  s->no_pmtud = FALSE;
 476#ifdef NGTCP2_SETTINGS_V3
 477  /* try ten times the ngtcp2 defaults here for problems with Caddy */
 478  s->glitch_ratelim_burst = 1000 * 10;
 479  s->glitch_ratelim_rate = 33 * 10;
 480#endif
 481  t->initial_max_data = s->max_window;
 482  t->initial_max_stream_data_bidi_local = H3_STREAM_WINDOW_SIZE_INITIAL;
 483  t->initial_max_stream_data_bidi_remote = H3_STREAM_WINDOW_SIZE_INITIAL;
 484  t->initial_max_stream_data_uni = t->initial_max_data;
 485  t->initial_max_streams_bidi = QUIC_MAX_STREAMS;
 486  t->initial_max_streams_uni = QUIC_MAX_STREAMS;
 487  t->max_idle_timeout = 0; /* no idle timeout from our side */
 488  if(ctx->qlogfd != -1) {
 489    s->qlog_write = qlog_callback;
 490  }
 491}
 492
 493static CURLcode init_ngh3_conn(struct Curl_cfilter *cf,
 494                               struct Curl_easy *data);
 495
 496static int cf_ngtcp2_handshake_completed(ngtcp2_conn *tconn, void *user_data)
 497{
 498  struct Curl_cfilter *cf = user_data;
 499  struct cf_ngtcp2_ctx *ctx = cf ? cf->ctx : NULL;
 500  struct Curl_easy *data;
 501
 502  (void)tconn;
 503  DEBUGASSERT(ctx);
 504  data = CF_DATA_CURRENT(cf);
 505  DEBUGASSERT(data);
 506  if(!ctx || !data)
 507    return NGHTTP3_ERR_CALLBACK_FAILURE;
 508
 509  ctx->handshake_at = *Curl_pgrs_now(data);
 510  ctx->tls_handshake_complete = TRUE;
 511  Curl_vquic_report_handshake(&ctx->tls, cf, data);
 512
 513  ctx->tls_vrfy_result = Curl_vquic_tls_verify_peer(&ctx->tls, cf,
 514                                                    data, &ctx->peer);
 515#ifdef CURLVERBOSE
 516  if(Curl_trc_is_verbose(data)) {
 517    const ngtcp2_transport_params *rp;
 518    rp = ngtcp2_conn_get_remote_transport_params(ctx->qconn);
 519    CURL_TRC_CF(data, cf, "handshake complete after %" FMT_TIMEDIFF_T
 520                "ms, remote transport[max_udp_payload=%" PRIu64
 521                ", initial_max_data=%" PRIu64
 522                "]",
 523               curlx_ptimediff_ms(&ctx->handshake_at, &ctx->started_at),
 524               rp->max_udp_payload_size, rp->initial_max_data);
 525  }
 526#endif
 527
 528  /* In case of earlydata, where we simulate being connected, update
 529   * the handshake time when we really did connect */
 530  if(ctx->use_earlydata)
 531    Curl_pgrsTimeWas(data, TIMER_APPCONNECT, ctx->handshake_at);
 532  if(ctx->use_earlydata) {
 533#if defined(USE_OPENSSL) && defined(HAVE_OPENSSL_EARLYDATA)
 534    ctx->earlydata_accepted =
 535      (SSL_get_early_data_status(ctx->tls.ossl.ssl) !=
 536       SSL_EARLY_DATA_REJECTED);
 537#endif
 538#ifdef USE_GNUTLS
 539    int flags = gnutls_session_get_flags(ctx->tls.gtls.session);
 540    ctx->earlydata_accepted = !!(flags & GNUTLS_SFLAGS_EARLY_DATA);
 541#endif
 542#ifdef USE_WOLFSSL
 543#ifdef WOLFSSL_EARLY_DATA
 544    ctx->earlydata_accepted =
 545      (wolfSSL_get_early_data_status(ctx->tls.wssl.ssl) !=
 546       WOLFSSL_EARLY_DATA_REJECTED);
 547#else
 548    DEBUGASSERT(0); /* should not come here if ED is disabled. */
 549    ctx->earlydata_accepted = FALSE;
 550#endif /* WOLFSSL_EARLY_DATA */
 551#endif
 552    CURL_TRC_CF(data, cf, "server did%s accept %zu bytes of early data",
 553                ctx->earlydata_accepted ? "" : " not", ctx->earlydata_skip);
 554    Curl_pgrsEarlyData(data, ctx->earlydata_accepted ?
 555                              (curl_off_t)ctx->earlydata_skip :
 556                             -(curl_off_t)ctx->earlydata_skip);
 557  }
 558  return 0;
 559}
 560
 561static void cf_ngtcp2_conn_close(struct Curl_cfilter *cf,
 562                                 struct Curl_easy *data);
 563
 564static bool cf_ngtcp2_err_is_fatal(int code)
 565{
 566  return (NGTCP2_ERR_FATAL >= code) ||
 567         (NGTCP2_ERR_DROP_CONN == code) ||
 568         (NGTCP2_ERR_IDLE_CLOSE == code);
 569}
 570
 571static void cf_ngtcp2_err_set(struct Curl_cfilter *cf,
 572                              struct Curl_easy *data, int code)
 573{
 574  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 575  if(!ctx->last_error.error_code) {
 576    if(NGTCP2_ERR_CRYPTO == code) {
 577      ngtcp2_ccerr_set_tls_alert(&ctx->last_error,
 578                                 ngtcp2_conn_get_tls_alert(ctx->qconn),
 579                                 NULL, 0);
 580    }
 581    else {
 582      ngtcp2_ccerr_set_liberr(&ctx->last_error, code, NULL, 0);
 583    }
 584  }
 585  if(cf_ngtcp2_err_is_fatal(code))
 586    cf_ngtcp2_conn_close(cf, data);
 587}
 588
 589static bool cf_ngtcp2_h3_err_is_fatal(int code)
 590{
 591  return (NGHTTP3_ERR_FATAL >= code) ||
 592         (NGHTTP3_ERR_H3_CLOSED_CRITICAL_STREAM == code);
 593}
 594
 595static void cf_ngtcp2_h3_err_set(struct Curl_cfilter *cf,
 596                                 struct Curl_easy *data, int code)
 597{
 598  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 599  if(!ctx->last_error.error_code) {
 600    ngtcp2_ccerr_set_application_error(&ctx->last_error,
 601      nghttp3_err_infer_quic_app_error_code(code), NULL, 0);
 602  }
 603  if(cf_ngtcp2_h3_err_is_fatal(code))
 604    cf_ngtcp2_conn_close(cf, data);
 605}
 606
 607static int cb_recv_stream_data(ngtcp2_conn *tconn, uint32_t flags,
 608                               int64_t stream_id, uint64_t offset,
 609                               const uint8_t *buf, size_t buflen,
 610                               void *user_data, void *stream_user_data)
 611{
 612  struct Curl_cfilter *cf = user_data;
 613  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 614  nghttp3_ssize rc;
 615  uint64_t nconsumed;
 616  int fin = (flags & NGTCP2_STREAM_DATA_FLAG_FIN) ? 1 : 0;
 617  struct Curl_easy *data = stream_user_data;
 618  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
 619  (void)offset;
 620
 621  rc = nghttp3_conn_read_stream(ctx->h3conn, stream_id, buf, buflen, fin);
 622  if(rc < 0) {
 623    if(data && stream) {
 624      CURL_TRC_CF(data, cf, "[%" PRId64 "] error on known stream, "
 625                  "reset=%d, closed=%d",
 626                  stream_id, stream->reset, stream->closed);
 627    }
 628    return NGTCP2_ERR_CALLBACK_FAILURE;
 629  }
 630  nconsumed = (uint64_t)rc;
 631  if(nconsumed) {
 632    /* number of bytes inside buflen which consists of framing overhead
 633     * including QPACK HEADERS. In other words, it does not consume payload of
 634     * DATA frame. */
 635    ngtcp2_conn_extend_max_stream_offset(tconn, stream_id, nconsumed);
 636    ngtcp2_conn_extend_max_offset(tconn, nconsumed);
 637    if(stream) {
 638      stream->rx_offset += nconsumed;
 639      stream->rx_offset_max += nconsumed;
 640    }
 641  }
 642  return 0;
 643}
 644
 645static int cb_acked_stream_data_offset(ngtcp2_conn *tconn, int64_t stream_id,
 646                                       uint64_t offset, uint64_t datalen,
 647                                       void *user_data, void *stream_user_data)
 648{
 649  struct Curl_cfilter *cf = user_data;
 650  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 651  int rv;
 652  (void)stream_id;
 653  (void)tconn;
 654  (void)offset;
 655  (void)datalen;
 656  (void)stream_user_data;
 657
 658  rv = nghttp3_conn_add_ack_offset(ctx->h3conn, stream_id, datalen);
 659  if(rv && rv != NGHTTP3_ERR_STREAM_NOT_FOUND) {
 660    return NGTCP2_ERR_CALLBACK_FAILURE;
 661  }
 662
 663  return 0;
 664}
 665
 666static int cb_stream_close(ngtcp2_conn *tconn, uint32_t flags,
 667                           int64_t stream_id, uint64_t app_error_code,
 668                           void *user_data, void *stream_user_data)
 669{
 670  struct Curl_cfilter *cf = user_data;
 671  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 672  struct Curl_easy *data = stream_user_data;
 673  int rv;
 674
 675  (void)tconn;
 676  /* stream is closed... */
 677  if(!data)
 678    data = CF_DATA_CURRENT(cf);
 679  if(!data)
 680    return NGTCP2_ERR_CALLBACK_FAILURE;
 681
 682  if(!(flags & NGTCP2_STREAM_CLOSE_FLAG_APP_ERROR_CODE_SET)) {
 683    app_error_code = NGHTTP3_H3_NO_ERROR;
 684  }
 685
 686  rv = nghttp3_conn_close_stream(ctx->h3conn, stream_id, app_error_code);
 687  CURL_TRC_CF(data, cf, "[%" PRId64 "] quic close(app_error=%"
 688              PRIu64 ") -> %d", stream_id, app_error_code, rv);
 689  if(rv && rv != NGHTTP3_ERR_STREAM_NOT_FOUND) {
 690    cf_ngtcp2_h3_err_set(cf, data, rv);
 691    return NGTCP2_ERR_CALLBACK_FAILURE;
 692  }
 693
 694  return 0;
 695}
 696
 697static int cb_stream_reset(ngtcp2_conn *tconn, int64_t stream_id,
 698                           uint64_t final_size, uint64_t app_error_code,
 699                           void *user_data, void *stream_user_data)
 700{
 701  struct Curl_cfilter *cf = user_data;
 702  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 703  struct Curl_easy *data = stream_user_data;
 704  int rv;
 705  (void)tconn;
 706  (void)final_size;
 707  (void)app_error_code;
 708
 709  rv = nghttp3_conn_shutdown_stream_read(ctx->h3conn, stream_id);
 710  CURL_TRC_CF(data, cf, "[%" PRId64 "] reset -> %d", stream_id, rv);
 711  if(rv && rv != NGHTTP3_ERR_STREAM_NOT_FOUND) {
 712    return NGTCP2_ERR_CALLBACK_FAILURE;
 713  }
 714
 715  return 0;
 716}
 717
 718static int cb_stream_stop_sending(ngtcp2_conn *tconn, int64_t stream_id,
 719                                  uint64_t app_error_code, void *user_data,
 720                                  void *stream_user_data)
 721{
 722  struct Curl_cfilter *cf = user_data;
 723  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 724  int rv;
 725  (void)tconn;
 726  (void)app_error_code;
 727  (void)stream_user_data;
 728
 729  rv = nghttp3_conn_shutdown_stream_read(ctx->h3conn, stream_id);
 730  if(rv && rv != NGHTTP3_ERR_STREAM_NOT_FOUND) {
 731    return NGTCP2_ERR_CALLBACK_FAILURE;
 732  }
 733
 734  return 0;
 735}
 736
 737static int cb_extend_max_local_streams_bidi(ngtcp2_conn *tconn,
 738                                            uint64_t max_streams,
 739                                            void *user_data)
 740{
 741  struct Curl_cfilter *cf = user_data;
 742  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 743  struct Curl_easy *data = CF_DATA_CURRENT(cf);
 744
 745  (void)tconn;
 746  ctx->max_bidi_streams = max_streams;
 747  if(data)
 748    CURL_TRC_CF(data, cf, "max bidi streams now %" PRIu64 ", used %" PRIu64,
 749                ctx->max_bidi_streams, ctx->used_bidi_streams);
 750  return 0;
 751}
 752
 753static int cb_extend_max_stream_data(ngtcp2_conn *tconn, int64_t stream_id,
 754                                     uint64_t max_data, void *user_data,
 755                                     void *stream_user_data)
 756{
 757  struct Curl_cfilter *cf = user_data;
 758  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 759  struct Curl_easy *s_data = stream_user_data;
 760  struct h3_stream_ctx *stream;
 761  int rv;
 762  (void)tconn;
 763  (void)max_data;
 764
 765  rv = nghttp3_conn_unblock_stream(ctx->h3conn, stream_id);
 766  if(rv && rv != NGHTTP3_ERR_STREAM_NOT_FOUND) {
 767    return NGTCP2_ERR_CALLBACK_FAILURE;
 768  }
 769  stream = H3_STREAM_CTX(ctx, s_data);
 770  if(stream && stream->quic_flow_blocked) {
 771    CURL_TRC_CF(s_data, cf, "[%" PRId64 "] unblock quic flow", stream_id);
 772    stream->quic_flow_blocked = FALSE;
 773    Curl_multi_mark_dirty(s_data);
 774  }
 775  return 0;
 776}
 777
 778static void cb_rand(uint8_t *dest, size_t destlen,
 779                    const ngtcp2_rand_ctx *rand_ctx)
 780{
 781  CURLcode result;
 782  (void)rand_ctx;
 783
 784  result = Curl_rand(NULL, dest, destlen);
 785  if(result) {
 786    /* cb_rand is only used for non-cryptographic context. If Curl_rand
 787       failed, fill 0 and call it *random*. */
 788    memset(dest, 0, destlen);
 789  }
 790}
 791
 792/* for ngtcp2 <v1.22.0 */
 793static int cb_get_new_connection_id(ngtcp2_conn *tconn, ngtcp2_cid *cid,
 794                                    uint8_t *token, size_t cidlen,
 795                                    void *user_data)
 796{
 797  CURLcode result;
 798  (void)tconn;
 799  (void)user_data;
 800
 801  result = Curl_rand(NULL, cid->data, cidlen);
 802  if(result)
 803    return NGTCP2_ERR_CALLBACK_FAILURE;
 804  cid->datalen = cidlen;
 805
 806  result = Curl_rand(NULL, token, NGTCP2_STATELESS_RESET_TOKENLEN);
 807  if(result)
 808    return NGTCP2_ERR_CALLBACK_FAILURE;
 809
 810  return 0;
 811}
 812
 813#ifdef NGTCP2_CALLBACKS_V3  /* ngtcp2 v1.22.0+ */
 814static int cb_get_new_connection_id2(ngtcp2_conn *tconn, ngtcp2_cid *cid,
 815  struct ngtcp2_stateless_reset_token *token, size_t cidlen, void *user_data)
 816{
 817  CURLcode result;
 818  (void)tconn;
 819  (void)user_data;
 820
 821  result = Curl_rand(NULL, cid->data, cidlen);
 822  if(result)
 823    return NGTCP2_ERR_CALLBACK_FAILURE;
 824  cid->datalen = cidlen;
 825
 826  result = Curl_rand(NULL, token->data, sizeof(token->data));
 827  if(result)
 828    return NGTCP2_ERR_CALLBACK_FAILURE;
 829
 830  return 0;
 831}
 832#endif
 833
 834static int cb_recv_rx_key(ngtcp2_conn *tconn, ngtcp2_encryption_level level,
 835                          void *user_data)
 836{
 837  struct Curl_cfilter *cf = user_data;
 838  struct cf_ngtcp2_ctx *ctx = cf ? cf->ctx : NULL;
 839  struct Curl_easy *data = CF_DATA_CURRENT(cf);
 840  (void)tconn;
 841
 842  if(level != NGTCP2_ENCRYPTION_LEVEL_1RTT)
 843    return 0;
 844
 845  DEBUGASSERT(ctx);
 846  DEBUGASSERT(data);
 847  if(ctx && data && !ctx->h3conn) {
 848    if(init_ngh3_conn(cf, data))
 849      return NGTCP2_ERR_CALLBACK_FAILURE;
 850  }
 851  return 0;
 852}
 853
 854#if defined(_MSC_VER) && defined(_DLL)
 855#pragma warning(push)
 856#pragma warning(disable:4232) /* MSVC extension, dllimport identity */
 857#endif
 858
 859static ngtcp2_callbacks ng_callbacks = {
 860  ngtcp2_crypto_client_initial_cb,
 861  NULL, /* recv_client_initial */
 862  ngtcp2_crypto_recv_crypto_data_cb,
 863  cf_ngtcp2_handshake_completed,
 864  NULL, /* recv_version_negotiation */
 865  ngtcp2_crypto_encrypt_cb,
 866  ngtcp2_crypto_decrypt_cb,
 867  ngtcp2_crypto_hp_mask_cb,
 868  cb_recv_stream_data,
 869  cb_acked_stream_data_offset,
 870  NULL, /* stream_open */
 871  cb_stream_close,
 872  NULL, /* recv_stateless_reset */
 873  ngtcp2_crypto_recv_retry_cb,
 874  cb_extend_max_local_streams_bidi,
 875  NULL, /* extend_max_local_streams_uni */
 876  cb_rand,
 877  cb_get_new_connection_id, /* for ngtcp2 <v1.22.0 */
 878  NULL, /* remove_connection_id */
 879  ngtcp2_crypto_update_key_cb, /* update_key */
 880  NULL, /* path_validation */
 881  NULL, /* select_preferred_addr */
 882  cb_stream_reset,
 883  NULL, /* extend_max_remote_streams_bidi */
 884  NULL, /* extend_max_remote_streams_uni */
 885  cb_extend_max_stream_data,
 886  NULL, /* dcid_status */
 887  NULL, /* handshake_confirmed */
 888  NULL, /* recv_new_token */
 889  ngtcp2_crypto_delete_crypto_aead_ctx_cb,
 890  ngtcp2_crypto_delete_crypto_cipher_ctx_cb,
 891  NULL, /* recv_datagram */
 892  NULL, /* ack_datagram */
 893  NULL, /* lost_datagram */
 894  ngtcp2_crypto_get_path_challenge_data_cb,
 895  cb_stream_stop_sending,
 896  NULL, /* version_negotiation */
 897  cb_recv_rx_key,
 898  NULL, /* recv_tx_key */
 899  NULL, /* early_data_rejected */
 900#ifdef NGTCP2_CALLBACKS_V2  /* ngtcp2 v1.14.0+ */
 901  NULL, /* begin_path_validation */
 902#endif
 903#ifdef NGTCP2_CALLBACKS_V3  /* ngtcp2 v1.22.0+ */
 904  NULL, /* recv_stateless_reset2 */
 905  cb_get_new_connection_id2, /* get_new_connection_id2 */
 906  NULL, /* dcid_status2 */
 907  ngtcp2_crypto_get_path_challenge_data2_cb, /* get_path_challenge_data2 */
 908#endif
 909};
 910
 911#if defined(_MSC_VER) && defined(_DLL)
 912#pragma warning(pop)
 913#endif
 914
 915/**
 916 * Connection maintenance like timeouts on packet ACKs etc. are done by us, not
 917 * the OS like for TCP. POLL events on the socket therefore are not
 918 * sufficient.
 919 * ngtcp2 tells us when it wants to be invoked again. We handle that via
 920 * the `Curl_expire()` mechanisms.
 921 */
 922static CURLcode check_and_set_expiry(struct Curl_cfilter *cf,
 923                                     struct Curl_easy *data,
 924                                     struct pkt_io_ctx *pktx)
 925{
 926  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 927  struct pkt_io_ctx local_pktx;
 928  ngtcp2_tstamp expiry;
 929
 930  if(!pktx) {
 931    pktx_init(&local_pktx, cf, data);
 932    pktx = &local_pktx;
 933  }
 934  else {
 935    pktx_update_time(data, pktx, cf);
 936  }
 937
 938  expiry = ngtcp2_conn_get_expiry(ctx->qconn);
 939  if(expiry != UINT64_MAX) {
 940    if(expiry <= pktx->ts) {
 941      CURLcode result;
 942      int rv = ngtcp2_conn_handle_expiry(ctx->qconn, pktx->ts);
 943      if(rv) {
 944        failf(data, "ngtcp2_conn_handle_expiry returned error: %s",
 945              ngtcp2_strerror(rv));
 946        cf_ngtcp2_err_set(cf, data, rv);
 947        return CURLE_SEND_ERROR;
 948      }
 949      result = cf_progress_ingress(cf, data, pktx);
 950      if(result)
 951        return result;
 952      result = cf_progress_egress(cf, data, pktx);
 953      if(result)
 954        return result;
 955      /* ask again, things might have changed */
 956      expiry = ngtcp2_conn_get_expiry(ctx->qconn);
 957    }
 958
 959    if(expiry > pktx->ts) {
 960      ngtcp2_duration timeout = expiry - pktx->ts;
 961      if(timeout % NGTCP2_MILLISECONDS) {
 962        timeout += NGTCP2_MILLISECONDS;
 963      }
 964      Curl_expire(data, (timediff_t)(timeout / NGTCP2_MILLISECONDS),
 965                  EXPIRE_QUIC);
 966    }
 967  }
 968  return CURLE_OK;
 969}
 970
 971static CURLcode cf_ngtcp2_adjust_pollset(struct Curl_cfilter *cf,
 972                                         struct Curl_easy *data,
 973                                         struct easy_pollset *ps)
 974{
 975  struct cf_ngtcp2_ctx *ctx = cf->ctx;
 976  bool want_recv, want_send;
 977  CURLcode result = CURLE_OK;
 978
 979  if(!ctx->qconn)
 980    return CURLE_OK;
 981
 982  Curl_pollset_check(data, ps, ctx->q.sockfd, &want_recv, &want_send);
 983  if(!want_send && !Curl_bufq_is_empty(&ctx->q.sendbuf))
 984    want_send = TRUE;
 985
 986  if(want_recv || want_send) {
 987    struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
 988    struct cf_call_data save;
 989    bool c_exhaust, s_exhaust;
 990
 991    CF_DATA_SAVE(save, cf, data);
 992    c_exhaust = want_send && (!ngtcp2_conn_get_cwnd_left(ctx->qconn) ||
 993                              !ngtcp2_conn_get_max_data_left(ctx->qconn));
 994    s_exhaust = want_send && stream && stream->id >= 0 &&
 995                stream->quic_flow_blocked;
 996    want_recv = (want_recv || c_exhaust || s_exhaust);
 997    want_send = (!s_exhaust && want_send) ||
 998                 !Curl_bufq_is_empty(&ctx->q.sendbuf);
 999
1000    result = Curl_pollset_set(data, ps, ctx->q.sockfd, want_recv, want_send);
1001    CF_DATA_RESTORE(cf, save);
1002  }
1003  return result;
1004}
1005
1006static int cb_h3_stream_close(nghttp3_conn *conn, int64_t stream_id,
1007                              uint64_t app_error_code, void *user_data,
1008                              void *stream_user_data)
1009{
1010  struct Curl_cfilter *cf = user_data;
1011  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1012  struct Curl_easy *data = stream_user_data;
1013  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
1014  (void)conn;
1015  (void)stream_id;
1016
1017  /* we might be called by nghttp3 after we already cleaned up */
1018  if(!stream)
1019    return 0;
1020
1021  stream->closed = TRUE;
1022  stream->error3 = app_error_code;
1023  if(stream->error3 != NGHTTP3_H3_NO_ERROR) {
1024    stream->reset = TRUE;
1025    stream->send_closed = TRUE;
1026    CURL_TRC_CF(data, cf, "[%" PRId64 "] RESET: error %" PRIu64,
1027                stream->id, stream->error3);
1028  }
1029  else {
1030    CURL_TRC_CF(data, cf, "[%" PRId64 "] CLOSED", stream->id);
1031  }
1032  Curl_multi_mark_dirty(data);
1033  return 0;
1034}
1035
1036static void h3_xfer_write_resp_hd(struct Curl_cfilter *cf,
1037                                  struct Curl_easy *data,
1038                                  struct h3_stream_ctx *stream,
1039                                  const char *buf, size_t blen, bool eos)
1040{
1041  /* This function returns no error intentionally, but records
1042   * the result at the stream, skipping further writes once the
1043   * `result` of the transfer is known.
1044   * The stream is subsequently cancelled "higher up" in the filter's
1045   * send/recv callbacks. Closing the stream here leads to SEND/RECV
1046   * errors in other places that then overwrite the transfer's result. */
1047  if(!stream->xfer_result) {
1048    stream->xfer_result = Curl_xfer_write_resp_hd(data, buf, blen, eos);
1049    if(stream->xfer_result)
1050      CURL_TRC_CF(data, cf, "[%" PRId64 "] error %d writing %zu "
1051                  "bytes of headers", stream->id, stream->xfer_result, blen);
1052  }
1053}
1054
1055static void h3_xfer_write_resp(struct Curl_cfilter *cf,
1056                               struct Curl_easy *data,
1057                               struct h3_stream_ctx *stream,
1058                               const char *buf, size_t blen, bool eos)
1059{
1060  /* This function returns no error intentionally, but records
1061   * the result at the stream, skipping further writes once the
1062   * `result` of the transfer is known.
1063   * The stream is subsequently cancelled "higher up" in the filter's
1064   * send/recv callbacks. Closing the stream here leads to SEND/RECV
1065   * errors in other places that then overwrite the transfer's result. */
1066  if(!stream->xfer_result) {
1067    stream->xfer_result = Curl_xfer_write_resp(data, buf, blen, eos);
1068    /* If the transfer write is errored, we do not want any more data */
1069    if(stream->xfer_result) {
1070      CURL_TRC_CF(data, cf, "[%" PRId64 "] error %d writing %zu bytes of data",
1071                  stream->id, stream->xfer_result, blen);
1072    }
1073  }
1074}
1075
1076static void cf_ngtcp2_upd_rx_win(struct Curl_cfilter *cf,
1077                                 struct Curl_easy *data,
1078                                 struct h3_stream_ctx *stream)
1079{
1080  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1081  uint64_t cur_win, wanted_win = H3_STREAM_WINDOW_SIZE_MAX;
1082
1083  /* how much does rate limiting allow us to acknowledge? */
1084  if(Curl_rlimit_active(&data->progress.dl.rlimit)) {
1085    int64_t avail;
1086
1087    /* start rate limit updates only after first bytes arrived */
1088    if(!stream->rx_offset)
1089      return;
1090
1091    avail = Curl_rlimit_avail(&data->progress.dl.rlimit,
1092                              Curl_pgrs_now(data));
1093    if(avail <= 0) {
1094      /* nothing available, do not extend the rx offset */
1095      CURL_TRC_CF(data, cf, "[%" PRId64 "] dl rate limit exhausted (%" PRId64
1096                  " tokens)", stream->id, avail);
1097      return;
1098    }
1099    wanted_win = CURLMIN((uint64_t)avail, H3_STREAM_WINDOW_SIZE_MAX);
1100  }
1101
1102  if(stream->rx_offset_max < stream->rx_offset) {
1103    DEBUGASSERT(0);
1104    return;
1105  }
1106  cur_win = stream->rx_offset_max - stream->rx_offset;
1107
1108  if(wanted_win > cur_win) {
1109    uint64_t delta = wanted_win - cur_win;
1110
1111    if(UINT64_MAX - delta < stream->rx_offset_max)
1112      delta = UINT64_MAX - stream->rx_offset_max;
1113    if(delta) {
1114      CURL_TRC_CF(data, cf, "[%" PRId64 "] rx window, extend by %" PRIu64
1115                  " bytes", stream->id, delta);
1116      stream->rx_offset_max += delta;
1117      ngtcp2_conn_extend_max_stream_offset(ctx->qconn, stream->id, delta);
1118    }
1119  }
1120}
1121
1122static int cb_h3_recv_data(nghttp3_conn *conn, int64_t stream3_id,
1123                           const uint8_t *buf, size_t blen,
1124                           void *user_data, void *stream_user_data)
1125{
1126  struct Curl_cfilter *cf = user_data;
1127  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1128  struct Curl_easy *data = stream_user_data;
1129  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
1130
1131  (void)conn;
1132  (void)stream3_id;
1133
1134  if(!stream)
1135    return NGHTTP3_ERR_CALLBACK_FAILURE;
1136
1137  h3_xfer_write_resp(cf, data, stream, (const char *)buf, blen, FALSE);
1138
1139  ngtcp2_conn_extend_max_offset(ctx->qconn, blen);
1140  stream->rx_offset += blen;
1141  if(stream->rx_offset_max < stream->rx_offset)
1142    stream->rx_offset_max = stream->rx_offset;
1143
1144  CURL_TRC_CF(data, cf, "[%" PRId64 "] DATA len=%zu, rx win=%" PRIu64,
1145              stream->id, blen, stream->rx_offset_max - stream->rx_offset);
1146  cf_ngtcp2_upd_rx_win(cf, data, stream);
1147  return 0;
1148}
1149
1150static int cb_h3_deferred_consume(nghttp3_conn *conn, int64_t stream3_id,
1151                                  size_t consumed, void *user_data,
1152                                  void *stream_user_data)
1153{
1154  struct Curl_cfilter *cf = user_data;
1155  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1156  struct Curl_easy *data = stream_user_data;
1157  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
1158  (void)conn;
1159
1160  /* nghttp3 has consumed bytes on the QUIC stream and we need to
1161   * tell the QUIC connection to increase its flow control */
1162  ngtcp2_conn_extend_max_stream_offset(ctx->qconn, stream3_id, consumed);
1163  ngtcp2_conn_extend_max_offset(ctx->qconn, consumed);
1164  if(stream) {
1165    stream->rx_offset += consumed;
1166    stream->rx_offset_max += consumed;
1167  }
1168  return 0;
1169}
1170
1171static int cb_h3_end_headers(nghttp3_conn *conn, int64_t stream_id,
1172                             int fin, void *user_data, void *stream_user_data)
1173{
1174  struct Curl_cfilter *cf = user_data;
1175  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1176  struct Curl_easy *data = stream_user_data;
1177  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
1178  (void)conn;
1179  (void)stream_id;
1180  (void)fin;
1181  (void)cf;
1182
1183  if(!stream)
1184    return 0;
1185  /* add a CRLF only if we have received some headers */
1186  h3_xfer_write_resp_hd(cf, data, stream, STRCONST("\r\n"),
1187                        (bool)stream->closed);
1188
1189  CURL_TRC_CF(data, cf, "[%" PRId64 "] end_headers, status=%d",
1190              stream_id, stream->status_code);
1191  if(stream->status_code / 100 != 1) {
1192    stream->resp_hds_complete = TRUE;
1193  }
1194  Curl_multi_mark_dirty(data);
1195  return 0;
1196}
1197
1198static int cb_h3_recv_header(nghttp3_conn *conn, int64_t stream_id,
1199                             int32_t token, nghttp3_rcbuf *name,
1200                             nghttp3_rcbuf *value, uint8_t flags,
1201                             void *user_data, void *stream_user_data)
1202{
1203  struct Curl_cfilter *cf = user_data;
1204  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1205  nghttp3_vec h3name = nghttp3_rcbuf_get_buf(name);
1206  nghttp3_vec h3val = nghttp3_rcbuf_get_buf(value);
1207  struct Curl_easy *data = stream_user_data;
1208  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
1209  CURLcode result = CURLE_OK;
1210  (void)conn;
1211  (void)stream_id;
1212  (void)token;
1213  (void)flags;
1214  (void)cf;
1215
1216  /* we might have cleaned up this transfer already */
1217  if(!stream)
1218    return 0;
1219
1220  if(token == NGHTTP3_QPACK_TOKEN__STATUS) {
1221
1222    result = Curl_http_decode_status(&stream->status_code,
1223                                     (const char *)h3val.base, h3val.len);
1224    if(result)
1225      return NGHTTP3_ERR_CALLBACK_FAILURE;
1226    curlx_dyn_reset(&ctx->scratch);
1227    result = curlx_dyn_addn(&ctx->scratch, STRCONST("HTTP/3 "));
1228    if(!result)
1229      result = curlx_dyn_addn(&ctx->scratch,
1230                              (const char *)h3val.base, h3val.len);
1231    if(!result)
1232      result = curlx_dyn_addn(&ctx->scratch, STRCONST(" \r\n"));
1233    if(!result)
1234      h3_xfer_write_resp_hd(cf, data, stream, curlx_dyn_ptr(&ctx->scratch),
1235                            curlx_dyn_len(&ctx->scratch), FALSE);
1236    CURL_TRC_CF(data, cf, "[%" PRId64 "] status: %s",
1237                stream_id, curlx_dyn_ptr(&ctx->scratch));
1238    if(result) {
1239      return NGHTTP3_ERR_CALLBACK_FAILURE;
1240    }
1241  }
1242  else {
1243    /* store as an HTTP1-style header */
1244    CURL_TRC_CF(data, cf, "[%" PRId64 "] header: %.*s: %.*s",
1245                stream_id, (int)h3name.len, h3name.base,
1246                (int)h3val.len, h3val.base);
1247    curlx_dyn_reset(&ctx->scratch);
1248    result = curlx_dyn_addn(&ctx->scratch,
1249                            (const char *)h3name.base, h3name.len);
1250    if(!result)
1251      result = curlx_dyn_addn(&ctx->scratch, STRCONST(": "));
1252    if(!result)
1253      result = curlx_dyn_addn(&ctx->scratch,
1254                              (const char *)h3val.base, h3val.len);
1255    if(!result)
1256      result = curlx_dyn_addn(&ctx->scratch, STRCONST("\r\n"));
1257    if(!result)
1258      h3_xfer_write_resp_hd(cf, data, stream, curlx_dyn_ptr(&ctx->scratch),
1259                            curlx_dyn_len(&ctx->scratch), FALSE);
1260  }
1261  return 0;
1262}
1263
1264static int cb_h3_stop_sending(nghttp3_conn *conn, int64_t stream_id,
1265                              uint64_t app_error_code, void *user_data,
1266                              void *stream_user_data)
1267{
1268  struct Curl_cfilter *cf = user_data;
1269  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1270  int rv;
1271  (void)conn;
1272  (void)stream_user_data;
1273
1274  rv = ngtcp2_conn_shutdown_stream_read(ctx->qconn, 0, stream_id,
1275                                        app_error_code);
1276  if(rv && rv != NGTCP2_ERR_STREAM_NOT_FOUND) {
1277    return NGHTTP3_ERR_CALLBACK_FAILURE;
1278  }
1279
1280  return 0;
1281}
1282
1283static int cb_h3_reset_stream(nghttp3_conn *conn, int64_t stream_id,
1284                              uint64_t app_error_code, void *user_data,
1285                              void *stream_user_data)
1286{
1287  struct Curl_cfilter *cf = user_data;
1288  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1289  struct Curl_easy *data = stream_user_data;
1290  int rv;
1291  (void)conn;
1292
1293  rv = ngtcp2_conn_shutdown_stream_write(ctx->qconn, 0, stream_id,
1294                                         app_error_code);
1295  CURL_TRC_CF(data, cf, "[%" PRId64 "] reset -> %d", stream_id, rv);
1296  if(rv && rv != NGTCP2_ERR_STREAM_NOT_FOUND) {
1297    return NGHTTP3_ERR_CALLBACK_FAILURE;
1298  }
1299
1300  return 0;
1301}
1302
1303static nghttp3_callbacks ngh3_callbacks = {
1304  cb_h3_acked_req_body, /* acked_stream_data */
1305  cb_h3_stream_close,
1306  cb_h3_recv_data,
1307  cb_h3_deferred_consume,
1308  NULL, /* begin_headers */
1309  cb_h3_recv_header,
1310  cb_h3_end_headers,
1311  NULL, /* begin_trailers */
1312  cb_h3_recv_header,
1313  NULL, /* end_trailers */
1314  cb_h3_stop_sending,
1315  NULL, /* end_stream */
1316  cb_h3_reset_stream,
1317  NULL, /* shutdown */
1318  NULL, /* recv_settings (deprecated) */
1319#ifdef NGHTTP3_CALLBACKS_V2  /* nghttp3 v1.11.0+ */
1320  NULL, /* recv_origin */
1321  NULL, /* end_origin */
1322  NULL, /* rand */
1323#endif
1324#ifdef NGHTTP3_CALLBACKS_V3  /* nghttp3 v1.14.0+ */
1325  NULL, /* recv_settings2 */
1326#endif
1327};
1328
1329static CURLcode init_ngh3_conn(struct Curl_cfilter *cf,
1330                               struct Curl_easy *data)
1331{
1332  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1333  int64_t ctrl_stream_id, qpack_enc_stream_id, qpack_dec_stream_id;
1334  int rc;
1335
1336  if(ngtcp2_conn_get_streams_uni_left(ctx->qconn) < 3) {
1337    failf(data, "QUIC connection lacks 3 uni streams to run HTTP/3");
1338    return CURLE_QUIC_CONNECT_ERROR;
1339  }
1340
1341  nghttp3_settings_default(&ctx->h3settings);
1342
1343  rc = nghttp3_conn_client_new(&ctx->h3conn,
1344                               &ngh3_callbacks,
1345                               &ctx->h3settings,
1346                               Curl_nghttp3_mem(),
1347                               cf);
1348  if(rc) {
1349    failf(data, "error creating nghttp3 connection instance");
1350    return CURLE_OUT_OF_MEMORY;
1351  }
1352
1353  rc = ngtcp2_conn_open_uni_stream(ctx->qconn, &ctrl_stream_id, NULL);
1354  if(rc) {
1355    failf(data, "error creating HTTP/3 control stream: %s",
1356          ngtcp2_strerror(rc));
1357    return CURLE_QUIC_CONNECT_ERROR;
1358  }
1359
1360  rc = nghttp3_conn_bind_control_stream(ctx->h3conn, ctrl_stream_id);
1361  if(rc) {
1362    failf(data, "error binding HTTP/3 control stream: %s",
1363          ngtcp2_strerror(rc));
1364    return CURLE_QUIC_CONNECT_ERROR;
1365  }
1366
1367  rc = ngtcp2_conn_open_uni_stream(ctx->qconn, &qpack_enc_stream_id, NULL);
1368  if(rc) {
1369    failf(data, "error creating HTTP/3 qpack encoding stream: %s",
1370          ngtcp2_strerror(rc));
1371    return CURLE_QUIC_CONNECT_ERROR;
1372  }
1373
1374  rc = ngtcp2_conn_open_uni_stream(ctx->qconn, &qpack_dec_stream_id, NULL);
1375  if(rc) {
1376    failf(data, "error creating HTTP/3 qpack decoding stream: %s",
1377          ngtcp2_strerror(rc));
1378    return CURLE_QUIC_CONNECT_ERROR;
1379  }
1380
1381  rc = nghttp3_conn_bind_qpack_streams(ctx->h3conn, qpack_enc_stream_id,
1382                                       qpack_dec_stream_id);
1383  if(rc) {
1384    failf(data, "error binding HTTP/3 qpack streams: %s",
1385          ngtcp2_strerror(rc));
1386    return CURLE_QUIC_CONNECT_ERROR;
1387  }
1388
1389  return CURLE_OK;
1390}
1391
1392static CURLcode recv_closed_stream(struct Curl_cfilter *cf,
1393                                   struct Curl_easy *data,
1394                                   struct h3_stream_ctx *stream,
1395                                   size_t *pnread)
1396{
1397  (void)cf;
1398  *pnread = 0;
1399  if(stream->reset) {
1400    if(stream->error3 == CURL_H3_ERR_REQUEST_REJECTED) {
1401      infof(data, "HTTP/3 stream %" PRId64 " refused by server, try again "
1402            "on a new connection", stream->id);
1403      connclose(cf->conn, "REFUSED_STREAM"); /* do not use this anymore */
1404      data->state.refused_stream = TRUE;
1405      return CURLE_RECV_ERROR; /* trigger Curl_retry_request() later */
1406    }
1407    else if(stream->resp_hds_complete && data->req.no_body) {
1408        CURL_TRC_CF(data, cf, "[%" PRId64 "] error after response headers, "
1409                    "but we did not want a body anyway, ignore error 0x%"
1410                    PRIx64 " %s", stream->id, stream->error3,
1411                    vquic_h3_err_str(stream->error3));
1412        return CURLE_OK;
1413    }
1414    failf(data, "HTTP/3 stream %" PRId64 " reset by server (error 0x%" PRIx64
1415          " %s)", stream->id, stream->error3,
1416          vquic_h3_err_str(stream->error3));
1417    return data->req.bytecount ? CURLE_PARTIAL_FILE : CURLE_HTTP3;
1418  }
1419  else if(!stream->resp_hds_complete) {
1420    failf(data,
1421          "HTTP/3 stream %" PRId64 " was closed cleanly, but before "
1422          "getting all response header fields, treated as error",
1423          stream->id);
1424    return CURLE_HTTP3;
1425  }
1426  return CURLE_OK;
1427}
1428
1429/* incoming data frames on the h3 stream */
1430static CURLcode cf_ngtcp2_recv(struct Curl_cfilter *cf, struct Curl_easy *data,
1431                               char *buf, size_t blen, size_t *pnread)
1432{
1433  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1434  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
1435  struct cf_call_data save;
1436  struct pkt_io_ctx pktx;
1437  CURLcode result = CURLE_OK;
1438  int i;
1439
1440  (void)ctx;
1441  (void)buf;
1442  NOVERBOSE((void)blen);
1443
1444  CF_DATA_SAVE(save, cf, data);
1445  DEBUGASSERT(cf->connected);
1446  DEBUGASSERT(ctx);
1447  DEBUGASSERT(ctx->qconn);
1448  DEBUGASSERT(ctx->h3conn);
1449  *pnread = 0;
1450
1451  /* handshake verification failed in callback, do not recv anything */
1452  if(ctx->tls_vrfy_result) {
1453    result = ctx->tls_vrfy_result;
1454    goto denied;
1455  }
1456
1457  pktx_init(&pktx, cf, data);
1458
1459  if(!stream || ctx->shutdown_started) {
1460    result = CURLE_RECV_ERROR;
1461    goto out;
1462  }
1463
1464  cf_ngtcp2_upd_rx_win(cf, data, stream);
1465
1466  /* first check for results/closed already known without touching
1467   * the connection. For an already failed/closed stream, errors on
1468   * the connection do not count.
1469   * Then handle incoming data and check for failed/closed again.
1470   */
1471  for(i = 0; i < 2; ++i) {
1472    if(stream->xfer_result) {
1473      CURL_TRC_CF(data, cf, "[%" PRId64 "] xfer write failed", stream->id);
1474      cf_ngtcp2_stream_close(cf, data, stream);
1475      result = stream->xfer_result;
1476      goto out;
1477    }
1478    else if(stream->closed) {
1479      result = recv_closed_stream(cf, data, stream, pnread);
1480      goto out;
1481    }
1482
1483    if(!i && cf_progress_ingress(cf, data, &pktx)) {
1484      result = CURLE_RECV_ERROR;
1485      goto out;
1486    }
1487  }
1488
1489  result = CURLE_AGAIN;
1490
1491out:
1492  result = Curl_1st_fatal(result, cf_progress_egress(cf, data, &pktx));
1493  result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx));
1494denied:
1495  CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_recv(blen=%zu) -> %d, %zu",
1496              stream ? stream->id : -1, blen, result, *pnread);
1497  CF_DATA_RESTORE(cf, save);
1498  return result;
1499}
1500
1501static int cb_h3_acked_req_body(nghttp3_conn *conn, int64_t stream_id,
1502                                uint64_t datalen, void *user_data,
1503                                void *stream_user_data)
1504{
1505  struct Curl_cfilter *cf = user_data;
1506  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1507  struct Curl_easy *data = stream_user_data;
1508  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
1509  size_t skiplen;
1510
1511  (void)cf;
1512  if(!stream)
1513    return 0;
1514  /* The server acknowledged `datalen` of bytes from our request body.
1515   * This is a delta. We have kept this data in `sendbuf` for
1516   * re-transmissions and can free it now. */
1517  if(datalen >= (uint64_t)stream->sendbuf_len_in_flight)
1518    skiplen = stream->sendbuf_len_in_flight;
1519  else
1520    skiplen = (size_t)datalen;
1521  Curl_bufq_skip(&stream->sendbuf, skiplen);
1522  stream->sendbuf_len_in_flight -= skiplen;
1523
1524  /* Resume upload processing if we have more data to send */
1525  if(stream->sendbuf_len_in_flight < Curl_bufq_len(&stream->sendbuf)) {
1526    int rv = nghttp3_conn_resume_stream(conn, stream_id);
1527    if(rv && rv != NGHTTP3_ERR_STREAM_NOT_FOUND) {
1528      return NGHTTP3_ERR_CALLBACK_FAILURE;
1529    }
1530  }
1531  return 0;
1532}
1533
1534static nghttp3_ssize cb_h3_read_req_body(nghttp3_conn *conn, int64_t stream_id,
1535                                         nghttp3_vec *vec, size_t veccnt,
1536                                         uint32_t *pflags, void *user_data,
1537                                         void *stream_user_data)
1538{
1539  struct Curl_cfilter *cf = user_data;
1540  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1541  struct Curl_easy *data = stream_user_data;
1542  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
1543  ssize_t nwritten = 0;
1544  size_t nvecs = 0;
1545  (void)cf;
1546  (void)conn;
1547  (void)stream_id;
1548  (void)user_data;
1549  (void)veccnt;
1550
1551  if(!stream)
1552    return NGHTTP3_ERR_CALLBACK_FAILURE;
1553  /* nghttp3 keeps references to the sendbuf data until it is ACKed
1554   * by the server (see `cb_h3_acked_req_body()` for updates).
1555   * `sendbuf_len_in_flight` is the amount of bytes in `sendbuf`
1556   * that we have already passed to nghttp3, but which have not been
1557   * ACKed yet.
1558   * Any amount beyond `sendbuf_len_in_flight` we need still to pass
1559   * to nghttp3. Do that now, if we can. */
1560  if(stream->sendbuf_len_in_flight < Curl_bufq_len(&stream->sendbuf)) {
1561    nvecs = 0;
1562    while(nvecs < veccnt &&
1563          Curl_bufq_peek_at(&stream->sendbuf,
1564                            stream->sendbuf_len_in_flight,
1565                            CURL_UNCONST(&vec[nvecs].base),
1566                            &vec[nvecs].len)) {
1567      stream->sendbuf_len_in_flight += vec[nvecs].len;
1568      nwritten += vec[nvecs].len;
1569      ++nvecs;
1570    }
1571    DEBUGASSERT(nvecs > 0); /* we SHOULD have been be able to peek */
1572  }
1573
1574  if(nwritten > 0 && stream->upload_left != -1)
1575    stream->upload_left -= nwritten;
1576
1577  /* When we stopped sending and everything in `sendbuf` is "in flight",
1578   * we are at the end of the request body. */
1579  if(stream->upload_left == 0) {
1580    *pflags = NGHTTP3_DATA_FLAG_EOF;
1581    stream->send_closed = TRUE;
1582  }
1583  else if(!nwritten) {
1584    /* Not EOF, and nothing to give, we signal WOULDBLOCK. */
1585    CURL_TRC_CF(data, cf, "[%" PRId64 "] read req body -> AGAIN", stream->id);
1586    return NGHTTP3_ERR_WOULDBLOCK;
1587  }
1588
1589  CURL_TRC_CF(data, cf, "[%" PRId64 "] read req body -> "
1590              "%d vecs%s with %zd (buffered=%zu, left=%" FMT_OFF_T ")",
1591              stream->id, (int)nvecs,
1592              *pflags == NGHTTP3_DATA_FLAG_EOF ? " EOF" : "",
1593              nwritten, Curl_bufq_len(&stream->sendbuf),
1594              stream->upload_left);
1595  return (nghttp3_ssize)nvecs;
1596}
1597
1598static CURLcode h3_stream_open(struct Curl_cfilter *cf,
1599                               struct Curl_easy *data,
1600                               const uint8_t *buf, size_t len,
1601                               size_t *pnwritten)
1602{
1603  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1604  struct h3_stream_ctx *stream = NULL;
1605  int64_t sid;
1606  struct dynhds h2_headers;
1607  size_t nheader;
1608  nghttp3_nv *nva = NULL;
1609  int rc = 0;
1610  unsigned int i;
1611  nghttp3_data_reader reader;
1612  nghttp3_data_reader *preader = NULL;
1613  CURLcode result;
1614
1615  *pnwritten = 0;
1616  Curl_dynhds_init(&h2_headers, 0, DYN_HTTP_REQUEST);
1617
1618  result = h3_data_setup(cf, data);
1619  if(result)
1620    goto out;
1621  stream = H3_STREAM_CTX(ctx, data);
1622  DEBUGASSERT(stream);
1623  if(!stream) {
1624    result = CURLE_FAILED_INIT;
1625    goto out;
1626  }
1627
1628  result = Curl_h1_req_parse_read(&stream->h1, buf, len, NULL,
1629                                  !data->state.http_ignorecustom ?
1630                                  data->set.str[STRING_CUSTOMREQUEST] : NULL,
1631                                  0, pnwritten);
1632  if(result)
1633    goto out;
1634  if(!stream->h1.done) {
1635    /* need more data */
1636    goto out;
1637  }
1638  DEBUGASSERT(stream->h1.req);
1639
1640  result = Curl_http_req_to_h2(&h2_headers, stream->h1.req, data);
1641  if(result)
1642    goto out;
1643
1644  /* no longer needed */
1645  Curl_h1_req_parse_free(&stream->h1);
1646
1647  nheader = Curl_dynhds_count(&h2_headers);
1648  nva = curlx_malloc(sizeof(nghttp3_nv) * nheader);
1649  if(!nva) {
1650    result = CURLE_OUT_OF_MEMORY;
1651    goto out;
1652  }
1653
1654  for(i = 0; i < nheader; ++i) {
1655    struct dynhds_entry *e = Curl_dynhds_getn(&h2_headers, i);
1656    nva[i].name = (unsigned char *)e->name;
1657    nva[i].namelen = e->namelen;
1658    nva[i].value = (unsigned char *)e->value;
1659    nva[i].valuelen = e->valuelen;
1660    nva[i].flags = NGHTTP3_NV_FLAG_NONE;
1661  }
1662
1663  rc = ngtcp2_conn_open_bidi_stream(ctx->qconn, &sid, data);
1664  if(rc) {
1665    failf(data, "can get bidi streams");
1666    result = CURLE_SEND_ERROR;
1667    goto out;
1668  }
1669  stream->id = sid;
1670  ++ctx->used_bidi_streams;
1671
1672  switch(data->state.httpreq) {
1673  case HTTPREQ_POST:
1674  case HTTPREQ_POST_FORM:
1675  case HTTPREQ_POST_MIME:
1676  case HTTPREQ_PUT:
1677    /* known request body size or -1 */
1678    if(data->state.infilesize != -1)
1679      stream->upload_left = data->state.infilesize;
1680    else
1681      /* data sending without specifying the data amount up front */
1682      stream->upload_left = -1; /* unknown */
1683    break;
1684  default:
1685    /* there is not request body */
1686    stream->upload_left = 0; /* no request body */
1687    break;
1688  }
1689
1690  stream->send_closed = (stream->upload_left == 0);
1691  if(!stream->send_closed) {
1692    reader.read_data = cb_h3_read_req_body;
1693    preader = &reader;
1694  }
1695
1696  rc = nghttp3_conn_submit_request(ctx->h3conn, stream->id,
1697                                   nva, nheader, preader, data);
1698  if(rc) {
1699    switch(rc) {
1700    case NGHTTP3_ERR_CONN_CLOSING:
1701      CURL_TRC_CF(data, cf, "h3sid[%" PRId64 "] failed to send, "
1702                  "connection is closing", stream->id);
1703      break;
1704    default:
1705      CURL_TRC_CF(data, cf, "h3sid[%" PRId64 "] failed to send -> "
1706                  "%d (%s)", stream->id, rc, nghttp3_strerror(rc));
1707      break;
1708    }
1709    cf_ngtcp2_stream_close(cf, data, stream);
1710    result = CURLE_SEND_ERROR;
1711    goto out;
1712  }
1713
1714  cf_ngtcp2_upd_rx_win(cf, data, stream);
1715
1716  if(Curl_trc_is_verbose(data)) {
1717    infof(data, "[HTTP/3] [%" PRId64 "] OPENED stream for %s",
1718          stream->id, Curl_bufref_ptr(&data->state.url));
1719    for(i = 0; i < nheader; ++i) {
1720      infof(data, "[HTTP/3] [%" PRId64 "] [%.*s: %.*s]", stream->id,
1721            (int)nva[i].namelen, nva[i].name,
1722            (int)nva[i].valuelen, nva[i].value);
1723    }
1724  }
1725
1726out:
1727  curlx_free(nva);
1728  Curl_dynhds_free(&h2_headers);
1729  return result;
1730}
1731
1732static CURLcode cf_ngtcp2_send(struct Curl_cfilter *cf, struct Curl_easy *data,
1733                               const uint8_t *buf, size_t len, bool eos,
1734                               size_t *pnwritten)
1735{
1736  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1737  struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
1738  struct cf_call_data save;
1739  struct pkt_io_ctx pktx;
1740  CURLcode result = CURLE_OK;
1741
1742  CF_DATA_SAVE(save, cf, data);
1743  DEBUGASSERT(cf->connected);
1744  DEBUGASSERT(ctx->qconn);
1745  DEBUGASSERT(ctx->h3conn);
1746  pktx_init(&pktx, cf, data);
1747  *pnwritten = 0;
1748
1749  /* handshake verification failed in callback, do not send anything */
1750  if(ctx->tls_vrfy_result) {
1751    result = ctx->tls_vrfy_result;
1752    goto denied;
1753  }
1754
1755  (void)eos; /* use for stream EOF and block handling */
1756  result = cf_progress_ingress(cf, data, &pktx);
1757  if(result)
1758    goto out;
1759
1760  if(!stream || stream->id < 0) {
1761    if(ctx->shutdown_started) {
1762      CURL_TRC_CF(data, cf, "cannot open stream on closed connection");
1763      result = CURLE_SEND_ERROR;
1764      goto out;
1765    }
1766    result = h3_stream_open(cf, data, buf, len, pnwritten);
1767    if(result) {
1768      CURL_TRC_CF(data, cf, "failed to open stream -> %d", result);
1769      goto out;
1770    }
1771    VERBOSE(stream = H3_STREAM_CTX(ctx, data));
1772  }
1773  else if(stream->xfer_result) {
1774    CURL_TRC_CF(data, cf, "[%" PRId64 "] xfer write failed", stream->id);
1775    cf_ngtcp2_stream_close(cf, data, stream);
1776    result = stream->xfer_result;
1777    goto out;
1778  }
1779  else if(stream->closed) {
1780    if(stream->resp_hds_complete) {
1781      /* Server decided to close the stream after having sent us a final
1782       * response. This is valid if it is not interested in the request
1783       * body. This happens on 30x or 40x responses.
1784       * We silently discard the data sent, since this is not a transport
1785       * error situation. */
1786      CURL_TRC_CF(data, cf, "[%" PRId64 "] discarding data"
1787                  "on closed stream with response", stream->id);
1788      result = CURLE_OK;
1789      *pnwritten = len;
1790      goto out;
1791    }
1792    CURL_TRC_CF(data, cf, "[%" PRId64 "] send_body(len=%zu) "
1793                "-> stream closed", stream->id, len);
1794    result = CURLE_HTTP3;
1795    goto out;
1796  }
1797  else if(ctx->shutdown_started) {
1798    CURL_TRC_CF(data, cf, "cannot send on closed connection");
1799    result = CURLE_SEND_ERROR;
1800    goto out;
1801  }
1802  else {
1803    result = Curl_bufq_write(&stream->sendbuf, buf, len, pnwritten);
1804    CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_send, add to "
1805                "sendbuf(len=%zu) -> %d, %zu",
1806                stream->id, len, result, *pnwritten);
1807    if(result)
1808      goto out;
1809    (void)nghttp3_conn_resume_stream(ctx->h3conn, stream->id);
1810  }
1811
1812  if(*pnwritten > 0 && !ctx->tls_handshake_complete && ctx->use_earlydata)
1813    ctx->earlydata_skip += *pnwritten;
1814
1815  DEBUGASSERT(!result);
1816  result = cf_progress_egress(cf, data, &pktx);
1817
1818out:
1819  result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx));
1820denied:
1821  CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_send(len=%zu) -> %d, %zu",
1822              stream ? stream->id : -1, len, result, *pnwritten);
1823  CF_DATA_RESTORE(cf, save);
1824  return result;
1825}
1826
1827struct cf_ngtcp2_recv_ctx {
1828  struct pkt_io_ctx *pktx;
1829  size_t pkt_count;
1830};
1831
1832static CURLcode cf_ngtcp2_recv_pkts(const unsigned char *buf, size_t buflen,
1833                                    size_t gso_size,
1834                                    struct sockaddr_storage *remote_addr,
1835                                    socklen_t remote_addrlen, int ecn,
1836                                    void *userp)
1837{
1838  struct cf_ngtcp2_recv_ctx *rctx = userp;
1839  struct pkt_io_ctx *pktx = rctx->pktx;
1840  struct cf_ngtcp2_ctx *ctx = pktx->cf->ctx;
1841  ngtcp2_pkt_info pi;
1842  ngtcp2_path path;
1843  size_t offset, pktlen;
1844  int rv;
1845
1846  if(!rctx->pkt_count) {
1847    pktx_update_time(pktx->data, pktx, pktx->cf);
1848    ngtcp2_path_storage_zero(&pktx->ps);
1849  }
1850
1851  if(ecn)
1852    CURL_TRC_CF(pktx->data, pktx->cf, "vquic_recv(len=%zu, gso=%zu, ecn=%x)",
1853                buflen, gso_size, ecn);
1854  ngtcp2_addr_init(&path.local, (struct sockaddr *)&ctx->q.local_addr,
1855                   ctx->q.local_addrlen);
1856  ngtcp2_addr_init(&path.remote, (struct sockaddr *)remote_addr,
1857                   remote_addrlen);
1858  pi.ecn = (uint8_t)ecn;
1859
1860  for(offset = 0; offset < buflen; offset += gso_size) {
1861    rctx->pkt_count++;
1862    pktlen = ((offset + gso_size) <= buflen) ? gso_size : (buflen - offset);
1863    rv = ngtcp2_conn_read_pkt(ctx->qconn, &path, &pi,
1864                              buf + offset, pktlen, pktx->ts);
1865    if(rv) {
1866      CURL_TRC_CF(pktx->data, pktx->cf, "ingress, read_pkt -> %s (%d)",
1867                  ngtcp2_strerror(rv), rv);
1868      cf_ngtcp2_err_set(pktx->cf, pktx->data, rv);
1869
1870      if(rv == NGTCP2_ERR_CRYPTO)
1871        /* this is a "TLS problem", but a failed certificate verification
1872           is a common reason for this */
1873        return CURLE_PEER_FAILED_VERIFICATION;
1874      return CURLE_RECV_ERROR;
1875    }
1876  }
1877  return CURLE_OK;
1878}
1879
1880static CURLcode cf_progress_ingress(struct Curl_cfilter *cf,
1881                                    struct Curl_easy *data,
1882                                    struct pkt_io_ctx *pktx)
1883{
1884  struct cf_ngtcp2_ctx *ctx = cf->ctx;
1885  struct pkt_io_ctx local_pktx;
1886  struct cf_ngtcp2_recv_ctx rctx;
1887  CURLcode result = CURLE_OK;
1888
1889  if(!pktx) {
1890    pktx_init(&local_pktx, cf, data);
1891    pktx = &local_pktx;
1892  }
1893
1894  result = Curl_vquic_tls_before_recv(&ctx->tls, cf, data);
1895  if(result)
1896    return result;
1897
1898  rctx.pktx = pktx;
1899  rctx.pkt_count = 0;
1900  return vquic_recv_packets(cf, data, &ctx->q, 1000,
1901                            cf_ngtcp2_recv_pkts, &rctx);
1902}
1903
1904/**
1905 * Read a network packet to send from ngtcp2 into `buf`.
1906 * Return number of bytes written or -1 with *err set.
1907 */
1908static CURLcode read_pkt_to_send(void *userp,
1909                                 unsigned char *buf, size_t buflen,
1910                                 size_t *pnread)
1911{
1912  struct pkt_io_ctx *x = userp;
1913  struct cf_ngtcp2_ctx *ctx = x->cf->ctx;
1914  nghttp3_vec vec[16];
1915  nghttp3_ssize veccnt;
1916  ngtcp2_ssize ndatalen;
1917  uint32_t flags;
1918  int64_t stream_id;
1919  int fin;
1920  ssize_t n;
1921
1922  *pnread = 0;
1923  veccnt = 0;
1924  stream_id = -1;
1925  fin = 0;
1926
1927  /* ngtcp2 may want to put several frames from different streams into
1928   * this packet. `NGTCP2_WRITE_STREAM_FLAG_MORE` tells it to do so.
1929   * When `NGTCP2_ERR_WRITE_MORE` is returned, we *need* to make
1930   * another iteration.
1931   * When ngtcp2 is happy (because it has no other frame that would fit
1932   * or it has nothing more to send), it returns the total length
1933   * of the assembled packet. This may be 0 if there was nothing to send. */
1934  for(;;) {
1935
1936    if(ctx->h3conn && ngtcp2_conn_get_max_data_left(ctx->qconn)) {
1937      veccnt = nghttp3_conn_writev_stream(ctx->h3conn, &stream_id, &fin, vec,
1938                                          CURL_ARRAYSIZE(vec));
1939      if(veccnt < 0) {
1940        failf(x->data, "nghttp3_conn_writev_stream returned error: %s",
1941              nghttp3_strerror((int)veccnt));
1942        cf_ngtcp2_h3_err_set(x->cf, x->data, (int)veccnt);
1943        return CURLE_SEND_ERROR;
1944      }
1945    }
1946
1947    flags = NGTCP2_WRITE_STREAM_FLAG_MORE |
1948            (fin ? NGTCP2_WRITE_STREAM_FLAG_FIN : 0);
1949    n = ngtcp2_conn_writev_stream(ctx->qconn, &x->ps.path,
1950                                  NULL, buf, buflen,
1951                                  &ndatalen, flags, stream_id,
1952                                  (const ngtcp2_vec *)vec, veccnt, x->ts);
1953    if(n == 0) {
1954      /* nothing to send */
1955      return CURLE_AGAIN;
1956    }
1957    else if(n < 0) {
1958      switch(n) {
1959      case NGTCP2_ERR_STREAM_DATA_BLOCKED: {
1960        struct h3_stream_ctx *stream;
1961        DEBUGASSERT(ndatalen == -1);
1962        nghttp3_conn_block_stream(ctx->h3conn, stream_id);
1963        CURL_TRC_CF(x->data, x->cf, "[%" PRId64 "] block quic flow",
1964                    stream_id);
1965        stream = cf_ngtcp2_get_stream(ctx, stream_id);
1966        if(stream) /* it might be not one of our h3 streams? */
1967          stream->quic_flow_blocked = TRUE;
1968        n = 0;
1969        break;
1970      }
1971      case NGTCP2_ERR_STREAM_SHUT_WR:
1972        DEBUGASSERT(ndatalen == -1);
1973        nghttp3_conn_shutdown_stream_write(ctx->h3conn, stream_id);
1974        n = 0;
1975        break;
1976      case NGTCP2_ERR_WRITE_MORE:
1977        /* ngtcp2 wants to send more. update the flow of the stream whose data
1978         * is in the buffer and continue */
1979        DEBUGASSERT(ndatalen >= 0);
1980        n = 0;
1981        break;
1982      default:
1983        DEBUGASSERT(ndatalen == -1);
1984        failf(x->data, "ngtcp2_conn_writev_stream returned error: %s",
1985              ngtcp2_strerror((int)n));
1986        cf_ngtcp2_err_set(x->cf, x->data, (int)n);
1987        return CURLE_SEND_ERROR;
1988      }
1989    }
1990
1991    if(ndatalen >= 0) {
1992      /* we add the amount of data bytes to the flow windows */
1993      int rv = nghttp3_conn_add_write_offset(ctx->h3conn, stream_id, ndatalen);
1994      if(rv) {
1995        failf(x->data, "nghttp3_conn_add_write_offset returned error: %s",
1996              nghttp3_strerror(rv));
1997        return CURLE_SEND_ERROR;
1998      }
1999    }
2000
2001    if(n > 0) {
2002      /* packet assembled, leave */
2003      *pnread = (size_t)n;
2004      return CURLE_OK;
2005    }
2006  }
2007}
2008
2009static CURLcode cf_progress_egress(struct Curl_cfilter *cf,
2010                                   struct Curl_easy *data,
2011                                   struct pkt_io_ctx *pktx)
2012{
2013  struct cf_ngtcp2_ctx *ctx = cf->ctx;
2014  size_t nread;
2015  size_t max_payload_size, path_max_payload_size;
2016  size_t pktcnt = 0;
2017  size_t gsolen = 0;  /* this disables gso until we have a clue */
2018  size_t send_quantum;
2019  CURLcode curlcode;
2020  struct pkt_io_ctx local_pktx;
2021
2022  if(!pktx) {
2023    pktx_init(&local_pktx, cf, data);
2024    pktx = &local_pktx;
2025  }
2026  else {
2027    pktx_update_time(data, pktx, cf);
2028    ngtcp2_path_storage_zero(&pktx->ps);
2029  }
2030
2031  curlcode = vquic_flush(cf, data, &ctx->q);
2032  if(curlcode) {
2033    if(curlcode == CURLE_AGAIN) {
2034      Curl_expire(data, 1, EXPIRE_QUIC);
2035      return CURLE_OK;
2036    }
2037    return curlcode;
2038  }
2039
2040  /* In UDP, there is a maximum theoretical packet payload length and
2041   * a minimum payload length that is "guaranteed" to work.
2042   * To detect if this minimum payload can be increased, ngtcp2 sends
2043   * now and then a packet payload larger than the minimum. It that
2044   * is ACKed by the peer, both parties know that it works and
2045   * the subsequent packets can use a larger one.
2046   * This is called PMTUD (Path Maximum Transmission Unit Discovery).
2047   * Since a PMTUD might be rejected right on send, we do not want it
2048   * be followed by other packets of lesser size. Because those would
2049   * also fail then. If we detect a PMTUD while buffering, we flush.
2050   */
2051  max_payload_size = ngtcp2_conn_get_max_tx_udp_payload_size(ctx->qconn);
2052  path_max_payload_size =
2053    ngtcp2_conn_get_path_max_tx_udp_payload_size(ctx->qconn);
2054  send_quantum = ngtcp2_conn_get_send_quantum(ctx->qconn);
2055  CURL_TRC_CF(data, cf, "egress, collect and send packets, quantum=%zu",
2056              send_quantum);
2057  for(;;) {
2058    /* add the next packet to send, if any, to our buffer */
2059    curlcode = Curl_bufq_sipn(&ctx->q.sendbuf, max_payload_size,
2060                              read_pkt_to_send, pktx, &nread);
2061    if(curlcode == CURLE_AGAIN)
2062      break;
2063    else if(curlcode)
2064      return curlcode;
2065    else {
2066      size_t buflen = Curl_bufq_len(&ctx->q.sendbuf);
2067      if((buflen >= send_quantum) ||
2068         ((buflen + gsolen) >= ctx->q.sendbuf.chunk_size))
2069        break;
2070      DEBUGASSERT(nread > 0);
2071      ++pktcnt;
2072      if(pktcnt == 1) {
2073        /* first packet in buffer. This is either of a known, "good"
2074         * payload size or it is a PMTUD. We shall see. */
2075        gsolen = nread;
2076      }
2077      else if(nread > gsolen ||
2078              (gsolen > path_max_payload_size && nread != gsolen)) {
2079        /* The added packet is a PMTUD *or* the one(s) before the
2080         * added were PMTUD and the last one is smaller.
2081         * Flush the buffer before the last add. */
2082        curlcode = vquic_send_tail_split(cf, data, &ctx->q,
2083                                         gsolen, nread, nread);
2084        if(curlcode) {
2085          if(curlcode == CURLE_AGAIN) {
2086            Curl_expire(data, 1, EXPIRE_QUIC);
2087            return CURLE_OK;
2088          }
2089          return curlcode;
2090        }
2091        pktcnt = 0;
2092      }
2093      else if(nread < gsolen) {
2094        /* Reached capacity of our buffer *or*
2095         * last add was shorter than the previous ones, flush */
2096        break;
2097      }
2098    }
2099  }
2100
2101  if(!Curl_bufq_is_empty(&ctx->q.sendbuf)) {
2102    /* time to send */
2103    CURL_TRC_CF(data, cf, "egress, send collected %zu packets in %zu bytes",
2104                pktcnt, Curl_bufq_len(&ctx->q.sendbuf));
2105    curlcode = vquic_send(cf, data, &ctx->q, gsolen);
2106    if(curlcode) {
2107      if(curlcode == CURLE_AGAIN) {
2108        Curl_expire(data, 1, EXPIRE_QUIC);
2109        return CURLE_OK;
2110      }
2111      return curlcode;
2112    }
2113    pktx_update_time(data, pktx, cf);
2114    ngtcp2_conn_update_pkt_tx_time(ctx->qconn, pktx->ts);
2115  }
2116  return CURLE_OK;
2117}
2118
2119static CURLcode h3_data_pause(struct Curl_cfilter *cf,
2120                              struct Curl_easy *data,
2121                              bool pause)
2122{
2123  /* There seems to exist no API in ngtcp2 to shrink/enlarge the streams
2124   * windows. As we do in HTTP/2. */
2125  (void)cf;
2126  if(!pause)
2127    Curl_multi_mark_dirty(data);
2128  return CURLE_OK;
2129}
2130
2131static CURLcode cf_ngtcp2_cntrl(struct Curl_cfilter *cf,
2132                                struct Curl_easy *data,
2133                                int event, int arg1, void *arg2)
2134{
2135  struct cf_ngtcp2_ctx *ctx = cf->ctx;
2136  CURLcode result = CURLE_OK;
2137  struct cf_call_data save;
2138
2139  CF_DATA_SAVE(save, cf, data);
2140  (void)arg1;
2141  (void)arg2;
2142  switch(event) {
2143  case CF_CTRL_DATA_SETUP:
2144    break;
2145  case CF_CTRL_DATA_PAUSE:
2146    result = h3_data_pause(cf, data, (arg1 != 0));
2147    break;
2148  case CF_CTRL_DATA_DONE:
2149    h3_data_done(cf, data);
2150    break;
2151  case CF_CTRL_DATA_DONE_SEND: {
2152    struct h3_stream_ctx *stream = H3_STREAM_CTX(ctx, data);
2153    if(stream && !stream->send_closed) {
2154      stream->send_closed = TRUE;
2155      stream->upload_left = Curl_bufq_len(&stream->sendbuf) -
2156        stream->sendbuf_len_in_flight;
2157      (void)nghttp3_conn_resume_stream(ctx->h3conn, stream->id);
2158    }
2159    break;
2160  }
2161  case CF_CTRL_CONN_INFO_UPDATE:
2162    if(!cf->sockindex && cf->connected) {
2163      cf->conn->httpversion_seen = 30;
2164      Curl_conn_set_multiplex(cf->conn);
2165    }
2166    break;
2167  default:
2168    break;
2169  }
2170  CF_DATA_RESTORE(cf, save);
2171  return result;
2172}
2173
2174static void cf_ngtcp2_ctx_close(struct cf_ngtcp2_ctx *ctx)
2175{
2176  struct cf_call_data save = ctx->call_data;
2177
2178  if(!ctx->initialized)
2179    return;
2180  if(ctx->qlogfd != -1) {
2181    curlx_close(ctx->qlogfd);
2182  }
2183  ctx->qlogfd = -1;
2184  Curl_vquic_tls_cleanup(&ctx->tls);
2185  vquic_ctx_free(&ctx->q);
2186  if(ctx->h3conn) {
2187    nghttp3_conn_del(ctx->h3conn);
2188    ctx->h3conn = NULL;
2189  }
2190  if(ctx->qconn) {
2191    ngtcp2_conn_del(ctx->qconn);
2192    ctx->qconn = NULL;
2193  }
2194#ifdef OPENSSL_QUIC_API2
2195  if(ctx->ossl_ctx) {
2196    ngtcp2_crypto_ossl_ctx_del(ctx->ossl_ctx);
2197    ctx->ossl_ctx = NULL;
2198  }
2199#endif
2200  ctx->call_data = save;
2201}
2202
2203static CURLcode cf_ngtcp2_shutdown(struct Curl_cfilter *cf,
2204                                   struct Curl_easy *data, bool *done)
2205{
2206  struct cf_ngtcp2_ctx *ctx = cf->ctx;
2207  struct cf_call_data save;
2208  struct pkt_io_ctx pktx;
2209  CURLcode result = CURLE_OK;
2210
2211  if(cf->shutdown || !ctx->qconn) {
2212    *done = TRUE;
2213    return CURLE_OK;
2214  }
2215
2216  CF_DATA_SAVE(save, cf, data);
2217  *done = FALSE;
2218  pktx_init(&pktx, cf, data);
2219
2220  if(!ctx->shutdown_started) {
2221    char buffer[NGTCP2_MAX_UDP_PAYLOAD_SIZE];
2222    ngtcp2_ssize nwritten;
2223
2224    if(!Curl_bufq_is_empty(&ctx->q.sendbuf)) {
2225      CURL_TRC_CF(data, cf, "shutdown, flushing sendbuf");
2226      result = cf_progress_egress(cf, data, &pktx);
2227      if(!Curl_bufq_is_empty(&ctx->q.sendbuf)) {
2228        CURL_TRC_CF(data, cf, "sending shutdown packets blocked");
2229        result = CURLE_OK;
2230        goto out;
2231      }
2232      else if(result) {
2233        CURL_TRC_CF(data, cf, "shutdown, error %d flushing sendbuf", result);
2234        *done = TRUE;
2235        goto out;
2236      }
2237    }
2238
2239    DEBUGASSERT(Curl_bufq_is_empty(&ctx->q.sendbuf));
2240    ctx->shutdown_started = TRUE;
2241    nwritten = ngtcp2_conn_write_connection_close(
2242      ctx->qconn, NULL, /* path */
2243      NULL, /* pkt_info */
2244      (uint8_t *)buffer, sizeof(buffer),
2245      &ctx->last_error, pktx.ts);
2246    CURL_TRC_CF(data, cf, "start shutdown(err_type=%d, err_code=%"
2247                PRIu64 ") -> %zd", ctx->last_error.type,
2248                ctx->last_error.error_code, (ssize_t)nwritten);
2249    /* there are cases listed in ngtcp2 documentation where this call
2250     * may fail. Since we are doing a connection shutdown as graceful
2251     * as we can, such an error is ignored here. */
2252    if(nwritten > 0) {
2253      /* Ignore amount written. sendbuf was empty and has always room for
2254       * NGTCP2_MAX_UDP_PAYLOAD_SIZE. It can only completely fail, in which
2255       * case `result` is set non zero. */
2256      size_t n;
2257      result = Curl_bufq_write(&ctx->q.sendbuf, (const unsigned char *)buffer,
2258                               (size_t)nwritten, &n);
2259      if(result) {
2260        CURL_TRC_CF(data, cf, "error %d adding shutdown packets to sendbuf, "
2261                    "aborting shutdown", result);
2262        goto out;
2263      }
2264
2265      ctx->q.no_gso = TRUE;
2266      ctx->q.gsolen = (size_t)nwritten;
2267      ctx->q.split_len = 0;
2268    }
2269  }
2270
2271  if(!Curl_bufq_is_empty(&ctx->q.sendbuf)) {
2272    CURL_TRC_CF(data, cf, "shutdown, flushing egress");
2273    result = vquic_flush(cf, data, &ctx->q);
2274    if(result == CURLE_AGAIN) {
2275      CURL_TRC_CF(data, cf, "sending shutdown packets blocked");
2276      result = CURLE_OK;
2277      goto out;
2278    }
2279    else if(result) {
2280      CURL_TRC_CF(data, cf, "shutdown, error %d flushing sendbuf", result);
2281      *done = TRUE;
2282      goto out;
2283    }
2284  }
2285
2286  if(Curl_bufq_is_empty(&ctx->q.sendbuf)) {
2287    /* Sent everything off. ngtcp2 seems to have no support for graceful
2288     * shutdowns. We are done. */
2289    CURL_TRC_CF(data, cf, "shutdown completely sent off, done");
2290    *done = TRUE;
2291    result = CURLE_OK;
2292  }
2293out:
2294  CF_DATA_RESTORE(cf, save);
2295  return result;
2296}
2297
2298static void cf_ngtcp2_conn_close(struct Curl_cfilter *cf,
2299                                 struct Curl_easy *data)
2300{
2301  bool done;
2302  cf_ngtcp2_shutdown(cf, data, &done);
2303}
2304
2305static void cf_ngtcp2_close(struct Curl_cfilter *cf, struct Curl_easy *data)
2306{
2307  struct cf_ngtcp2_ctx *ctx = cf->ctx;
2308  struct cf_call_data save;
2309
2310  CF_DATA_SAVE(save, cf, data);
2311  if(ctx && ctx->qconn) {
2312    cf_ngtcp2_conn_close(cf, data);
2313    cf_ngtcp2_ctx_close(ctx);
2314    CURL_TRC_CF(data, cf, "close");
2315  }
2316  cf->connected = FALSE;
2317  CF_DATA_RESTORE(cf, save);
2318}
2319
2320static void cf_ngtcp2_destroy(struct Curl_cfilter *cf, struct Curl_easy *data)
2321{
2322  CURL_TRC_CF(data, cf, "destroy");
2323  if(cf->ctx) {
2324    cf_ngtcp2_close(cf, data);
2325    cf_ngtcp2_ctx_free(cf->ctx);
2326    cf->ctx = NULL;
2327  }
2328}
2329
2330#ifdef USE_OPENSSL
2331/* The "new session" callback must return zero if the session can be removed
2332 * or non-zero if the session has been put into the session cache.
2333 */
2334static int quic_ossl_new_session_cb(SSL *ssl, SSL_SESSION *ssl_sessionid)
2335{
2336  struct Curl_cfilter *cf;
2337  struct cf_ngtcp2_ctx *ctx;
2338  struct Curl_easy *data;
2339  ngtcp2_crypto_conn_ref *cref;
2340
2341  cref = (ngtcp2_crypto_conn_ref *)SSL_get_app_data(ssl);
2342  cf = cref ? cref->user_data : NULL;
2343  ctx = cf ? cf->ctx : NULL;
2344  data = cf ? CF_DATA_CURRENT(cf) : NULL;
2345  if(cf && data && ctx) {
2346    unsigned char *quic_tp = NULL;
2347    size_t quic_tp_len = 0;
2348#ifdef HAVE_OPENSSL_EARLYDATA
2349    ngtcp2_ssize tplen;
2350    uint8_t tpbuf[256];
2351
2352    tplen = ngtcp2_conn_encode_0rtt_transport_params(ctx->qconn, tpbuf,
2353                                                     sizeof(tpbuf));
2354    if(tplen < 0)
2355      CURL_TRC_CF(data, cf, "error encoding 0RTT transport data: %s",
2356                  ngtcp2_strerror((int)tplen));
2357    else {
2358      quic_tp = (unsigned char *)tpbuf;
2359      quic_tp_len = (size_t)tplen;
2360    }
2361#endif
2362    Curl_ossl_add_session(cf, data, ctx->peer.scache_key, ssl_sessionid,
2363                          SSL_version(ssl), "h3", quic_tp, quic_tp_len);
2364  }
2365  return 0;
2366}
2367#endif /* USE_OPENSSL */
2368
2369#ifdef USE_GNUTLS
2370
2371#ifdef CURLVERBOSE
2372static const char *gtls_hs_msg_name(int mtype)
2373{
2374  switch(mtype) {
2375  case 1:
2376    return "ClientHello";
2377  case 2:
2378    return "ServerHello";
2379  case 4:
2380    return "SessionTicket";
2381  case 8:
2382    return "EncryptedExtensions";
2383  case 11:
2384    return "Certificate";
2385  case 13:
2386    return "CertificateRequest";
2387  case 15:
2388    return "CertificateVerify";
2389  case 20:
2390    return "Finished";
2391  case 24:
2392    return "KeyUpdate";
2393  case 254:
2394    return "MessageHash";
2395  }
2396  return "Unknown";
2397}
2398#endif
2399
2400static int quic_gtls_handshake_cb(gnutls_session_t session, unsigned int htype,
2401                                  unsigned when, unsigned int incoming,
2402                                  const gnutls_datum_t *msg)
2403{
2404  ngtcp2_crypto_conn_ref *conn_ref = gnutls_session_get_ptr(session);
2405  struct Curl_cfilter *cf = conn_ref ? conn_ref->user_data : NULL;
2406  struct cf_ngtcp2_ctx *ctx = cf ? cf->ctx : NULL;
2407
2408  (void)msg;
2409  (void)incoming;
2410  if(when && cf && ctx) { /* after message has been processed */
2411    struct Curl_easy *data = CF_DATA_CURRENT(cf);
2412    DEBUGASSERT(data);
2413    if(!data)
2414      return 0;
2415    CURL_TRC_CF(data, cf, "SSL message: %s %s [%u]",
2416                incoming ? "<-" : "->", gtls_hs_msg_name(htype), htype);
2417    switch(htype) {
2418    case GNUTLS_HANDSHAKE_NEW_SESSION_TICKET: {
2419      ngtcp2_ssize tplen;
2420      uint8_t tpbuf[256];
2421      unsigned char *quic_tp = NULL;
2422      size_t quic_tp_len = 0;
2423
2424      tplen = ngtcp2_conn_encode_0rtt_transport_params(ctx->qconn, tpbuf,
2425                                                       sizeof(tpbuf));
2426      if(tplen < 0)
2427        CURL_TRC_CF(data, cf, "error encoding 0RTT transport data: %s",
2428                    ngtcp2_strerror((int)tplen));
2429      else {
2430        quic_tp = (unsigned char *)tpbuf;
2431        quic_tp_len = (size_t)tplen;
2432      }
2433      (void)Curl_gtls_cache_session(cf, data, ctx->peer.scache_key,
2434                                    session, 0, "h3", quic_tp, quic_tp_len);
2435      break;
2436    }
2437    default:
2438      break;
2439    }
2440  }
2441  return 0;
2442}
2443#endif /* USE_GNUTLS */
2444
2445#ifdef USE_WOLFSSL
2446static int wssl_quic_new_session_cb(WOLFSSL *ssl, WOLFSSL_SESSION *session)
2447{
2448  ngtcp2_crypto_conn_ref *conn_ref = wolfSSL_get_app_data(ssl);
2449  struct Curl_cfilter *cf = conn_ref ? conn_ref->user_data : NULL;
2450
2451  DEBUGASSERT(cf != NULL);
2452  if(cf && session) {
2453    struct cf_ngtcp2_ctx *ctx = cf->ctx;
2454    struct Curl_easy *data = CF_DATA_CURRENT(cf);
2455    DEBUGASSERT(data);
2456    if(data && ctx) {
2457      ngtcp2_ssize tplen;
2458      uint8_t tpbuf[256];
2459      unsigned char *quic_tp = NULL;
2460      size_t quic_tp_len = 0;
2461
2462      tplen = ngtcp2_conn_encode_0rtt_transport_params(ctx->qconn, tpbuf,
2463                                                       sizeof(tpbuf));
2464      if(tplen < 0)
2465        CURL_TRC_CF(data, cf, "error encoding 0RTT transport data: %s",
2466                    ngtcp2_strerror((int)tplen));
2467      else {
2468        quic_tp = (unsigned char *)tpbuf;
2469        quic_tp_len = (size_t)tplen;
2470      }
2471      (void)Curl_wssl_cache_session(cf, data, ctx->peer.scache_key,
2472                                    session, wolfSSL_version(ssl),
2473                                    "h3", quic_tp, quic_tp_len);
2474    }
2475  }
2476  return 0;
2477}
2478#endif /* USE_WOLFSSL */
2479
2480static CURLcode cf_ngtcp2_tls_ctx_setup(struct Curl_cfilter *cf,
2481                                        struct Curl_easy *data,
2482                                        void *user_data)
2483{
2484  struct curl_tls_ctx *ctx = user_data;
2485
2486#ifdef USE_OPENSSL
2487#if defined(OPENSSL_IS_AWSLC) || defined(OPENSSL_IS_BORINGSSL)
2488  if(ngtcp2_crypto_boringssl_configure_client_context(ctx->ossl.ssl_ctx)
2489     != 0) {
2490    failf(data, "ngtcp2_crypto_boringssl_configure_client_context failed");
2491    return CURLE_FAILED_INIT;
2492  }
2493#elif defined(OPENSSL_QUIC_API2)
2494  /* nothing to do */
2495#else
2496  if(ngtcp2_crypto_quictls_configure_client_context(ctx->ossl.ssl_ctx) != 0) {
2497    failf(data, "ngtcp2_crypto_quictls_configure_client_context failed");
2498    return CURLE_FAILED_INIT;
2499  }
2500#endif /* !OPENSSL_IS_AWSLC && !OPENSSL_IS_BORINGSSL */
2501  if(Curl_ssl_scache_use(cf, data)) {
2502    /* Enable the session cache because it is a prerequisite for the
2503     * "new session" callback. Use the "external storage" mode to prevent
2504     * OpenSSL from creating an internal session cache.
2505     */
2506    SSL_CTX_set_session_cache_mode(ctx->ossl.ssl_ctx,
2507                                   SSL_SESS_CACHE_CLIENT |
2508                                   SSL_SESS_CACHE_NO_INTERNAL);
2509    SSL_CTX_sess_set_new_cb(ctx->ossl.ssl_ctx, quic_ossl_new_session_cb);
2510  }
2511
2512#elif defined(USE_GNUTLS)
2513  if(ngtcp2_crypto_gnutls_configure_client_session(ctx->gtls.session) != 0) {
2514    failf(data, "ngtcp2_crypto_gnutls_configure_client_session failed");
2515    return CURLE_FAILED_INIT;
2516  }
2517  if(Curl_ssl_scache_use(cf, data)) {
2518    gnutls_handshake_set_hook_function(ctx->gtls.session,
2519                                       GNUTLS_HANDSHAKE_ANY, GNUTLS_HOOK_POST,
2520                                       quic_gtls_handshake_cb);
2521  }
2522
2523#elif defined(USE_WOLFSSL)
2524  if(ngtcp2_crypto_wolfssl_configure_client_context(ctx->wssl.ssl_ctx) != 0) {
2525    failf(data, "ngtcp2_crypto_wolfssl_configure_client_context failed");
2526    return CURLE_FAILED_INIT;
2527  }
2528  if(Curl_ssl_scache_use(cf, data)) {
2529    /* Register to get notified when a new session is received */
2530    wolfSSL_CTX_sess_set_new_cb(ctx->wssl.ssl_ctx, wssl_quic_new_session_cb);
2531  }
2532#endif
2533  return CURLE_OK;
2534}
2535
2536static CURLcode cf_ngtcp2_on_session_reuse(struct Curl_cfilter *cf,
2537                                           struct Curl_easy *data,
2538                                           struct alpn_spec *alpns,
2539                                           struct Curl_ssl_session *scs,
2540                                           bool *do_early_data)
2541{
2542  struct cf_ngtcp2_ctx *ctx = cf->ctx;
2543  CURLcode result = CURLE_OK;
2544
2545  *do_early_data = FALSE;
2546#if defined(USE_OPENSSL) && defined(HAVE_OPENSSL_EARLYDATA)
2547  ctx->earlydata_max = scs->earlydata_max;
2548#endif
2549#ifdef USE_GNUTLS
2550  ctx->earlydata_max =
2551    gnutls_record_get_max_early_data_size(ctx->tls.gtls.session);
2552#endif
2553#ifdef USE_WOLFSSL
2554#ifdef WOLFSSL_EARLY_DATA
2555  ctx->earlydata_max = scs->earlydata_max;
2556#else
2557  ctx->earlydata_max = 0;
2558#endif /* WOLFSSL_EARLY_DATA */
2559#endif
2560#if defined(USE_GNUTLS) || defined(USE_WOLFSSL) || \
2561  (defined(USE_OPENSSL) && defined(HAVE_OPENSSL_EARLYDATA))
2562  if(!ctx->earlydata_max) {
2563    CURL_TRC_CF(data, cf, "SSL session does not allow earlydata");
2564  }
2565  else if(!Curl_alpn_contains_proto(alpns, scs->alpn)) {
2566    CURL_TRC_CF(data, cf, "SSL session from different ALPN, no early data");
2567  }
2568  else if(!scs->quic_tp || !scs->quic_tp_len) {
2569    CURL_TRC_CF(data, cf, "no 0RTT transport parameters, no early data, ");
2570  }
2571  else {
2572    int rv;
2573    rv = ngtcp2_conn_decode_and_set_0rtt_transport_params(
2574      ctx->qconn, (const uint8_t *)scs->quic_tp, scs->quic_tp_len);
2575    if(rv)
2576      CURL_TRC_CF(data, cf, "no early data, failed to set 0RTT transport "
2577                  "parameters: %s", ngtcp2_strerror(rv));
2578    else {
2579      infof(data, "SSL session allows %zu bytes of early data, "
2580            "reusing ALPN '%s'", ctx->earlydata_max, scs->alpn);
2581      result = init_ngh3_conn(cf, data);
2582      if(!result) {
2583        ctx->use_earlydata = TRUE;
2584        cf->connected = TRUE;
2585        *do_early_data = TRUE;
2586      }
2587    }
2588  }
2589#else /* not supported in the TLS backend */
2590  (void)data;
2591  (void)ctx;
2592  (void)scs;
2593  (void)alpns;
2594#endif
2595  return result;
2596}
2597
2598static bool cf_ngtcp2_need_httpsrr(struct Curl_easy *data)
2599{
2600#ifdef USE_OPENSSL
2601  return Curl_ossl_need_httpsrr(data);
2602#elif defined(USE_WOLFSSL)
2603  return Curl_wssl_need_httpsrr(data);
2604#else
2605  (void)data;
2606  return FALSE;
2607#endif
2608}
2609
2610/*
2611 * Might be called twice for happy eyeballs.
2612 */
2613static CURLcode cf_connect_start(struct Curl_cfilter *cf,
2614                                 struct Curl_easy *data,
2615                                 struct pkt_io_ctx *pktx)
2616{
2617  struct cf_ngtcp2_ctx *ctx = cf->ctx;
2618  int rc;
2619  int rv;
2620  CURLcode result;
2621  const struct Curl_sockaddr_ex *sockaddr = NULL;
2622  int qfd;
2623  static const struct alpn_spec ALPN_SPEC_H3 = { { "h3", "h3-29" }, 2 };
2624
2625  DEBUGASSERT(ctx->initialized);
2626  ctx->dcid.datalen = NGTCP2_MAX_CIDLEN;
2627  result = Curl_rand(data, ctx->dcid.data, NGTCP2_MAX_CIDLEN);
2628  if(result)
2629    return result;
2630
2631  ctx->scid.datalen = NGTCP2_MAX_CIDLEN;
2632  result = Curl_rand(data, ctx->scid.data, NGTCP2_MAX_CIDLEN);
2633  if(result)
2634    return result;
2635
2636  (void)Curl_qlogdir(data, ctx->scid.data, NGTCP2_MAX_CIDLEN, &qfd);
2637  ctx->qlogfd = qfd; /* -1 if failure above */
2638  quic_settings(ctx, data, pktx);
2639
2640  result = vquic_ctx_init(data, &ctx->q);
2641  if(result)
2642    return result;
2643
2644  if(Curl_cf_socket_peek(cf->next, data, &ctx->q.sockfd, &sockaddr, NULL))
2645    return CURLE_QUIC_CONNECT_ERROR;
2646  ctx->q.local_addrlen = sizeof(ctx->q.local_addr);
2647  rv = getsockname(ctx->q.sockfd, (struct sockaddr *)&ctx->q.local_addr,
2648                   &ctx->q.local_addrlen);
2649  if(rv == -1)
2650    return CURLE_QUIC_CONNECT_ERROR;
2651
2652  ngtcp2_addr_init(&ctx->connected_path.local,
2653                   (struct sockaddr *)&ctx->q.local_addr,
2654                   ctx->q.local_addrlen);
2655  ngtcp2_addr_init(&ctx->connected_path.remote,
2656                   &sockaddr->curl_sa_addr, (socklen_t)sockaddr->addrlen);
2657
2658  rc = ngtcp2_conn_client_new(&ctx->qconn, &ctx->dcid, &ctx->scid,
2659                              &ctx->connected_path,
2660                              NGTCP2_PROTO_VER_V1, &ng_callbacks,
2661                              &ctx->settings, &ctx->transport_params,
2662                              Curl_ngtcp2_mem(), cf);
2663  if(rc)
2664    return CURLE_QUIC_CONNECT_ERROR;
2665
2666  ctx->conn_ref.get_conn = get_conn;
2667  ctx->conn_ref.user_data = cf;
2668
2669  result = Curl_vquic_tls_init(&ctx->tls, cf, data, &ctx->peer, &ALPN_SPEC_H3,
2670                               cf_ngtcp2_tls_ctx_setup, &ctx->tls,
2671                               &ctx->conn_ref,
2672                               cf_ngtcp2_on_session_reuse);
2673  if(result)
2674    return result;
2675
2676#if defined(USE_OPENSSL) && defined(OPENSSL_QUIC_API2)
2677  if(ngtcp2_crypto_ossl_ctx_new(&ctx->ossl_ctx, ctx->tls.ossl.ssl) != 0) {
2678    failf(data, "ngtcp2_crypto_ossl_ctx_new failed");
2679    return CURLE_FAILED_INIT;
2680  }
2681  ngtcp2_conn_set_tls_native_handle(ctx->qconn, ctx->ossl_ctx);
2682  if(ngtcp2_crypto_ossl_configure_client_session(ctx->tls.ossl.ssl) != 0) {
2683    failf(data, "ngtcp2_crypto_ossl_configure_client_session failed");
2684    return CURLE_FAILED_INIT;
2685  }
2686#elif defined(USE_OPENSSL)
2687  SSL_set_quic_use_legacy_codepoint(ctx->tls.ossl.ssl, 0);
2688  ngtcp2_conn_set_tls_native_handle(ctx->qconn, ctx->tls.ossl.ssl);
2689#elif defined(USE_GNUTLS)
2690  ngtcp2_conn_set_tls_native_handle(ctx->qconn, ctx->tls.gtls.session);
2691#elif defined(USE_WOLFSSL)
2692  ngtcp2_conn_set_tls_native_handle(ctx->qconn, ctx->tls.wssl.ssl);
2693#else
2694#error "ngtcp2 TLS backend not defined"
2695#endif
2696
2697  ngtcp2_ccerr_default(&ctx->last_error);
2698
2699  return CURLE_OK;
2700}
2701
2702static CURLcode cf_ngtcp2_connect(struct Curl_cfilter *cf,
2703                                  struct Curl_easy *data,
2704                                  bool *done)
2705{
2706  struct cf_ngtcp2_ctx *ctx = cf->ctx;
2707  CURLcode result = CURLE_OK;
2708  struct cf_call_data save;
2709  struct pkt_io_ctx pktx;
2710
2711  if(cf->connected) {
2712    *done = TRUE;
2713    return CURLE_OK;
2714  }
2715
2716  /* Connect the UDP filter first */
2717  if(!cf->next->connected) {
2718    result = Curl_conn_cf_connect(cf->next, data, done);
2719    if(result || !*done)
2720      return result;
2721  }
2722
2723  *done = FALSE;
2724
2725  if(cf_ngtcp2_need_httpsrr(data) &&
2726     !Curl_conn_dns_resolved_https(data, cf->sockindex)) {
2727    CURL_TRC_CF(data, cf, "need HTTPS-RR, delaying connect");
2728    return CURLE_OK;
2729  }
2730
2731  pktx_init(&pktx, cf, data);
2732  CF_DATA_SAVE(save, cf, data);
2733
2734  if(!ctx->qconn) {
2735    ctx->started_at = *Curl_pgrs_now(data);
2736    result = cf_connect_start(cf, data, &pktx);
2737    if(result)
2738      goto out;
2739    if(cf->connected) {
2740      *done = TRUE;
2741      goto out;
2742    }
2743    result = cf_progress_egress(cf, data, &pktx);
2744    /* we do not expect to be able to recv anything yet */
2745    goto out;
2746  }
2747
2748  result = cf_progress_ingress(cf, data, &pktx);
2749  if(result)
2750    goto out;
2751
2752  result = cf_progress_egress(cf, data, &pktx);
2753  if(result)
2754    goto out;
2755
2756  if(ngtcp2_conn_get_handshake_completed(ctx->qconn)) {
2757    result = ctx->tls_vrfy_result;
2758    if(!result) {
2759      CURL_TRC_CF(data, cf, "peer verified");
2760      cf->connected = TRUE;
2761      *done = TRUE;
2762    }
2763  }
2764
2765out:
2766  if(ctx->qconn &&
2767     ((result == CURLE_RECV_ERROR) || (result == CURLE_SEND_ERROR)) &&
2768     ngtcp2_conn_in_draining_period(ctx->qconn)) {
2769    const ngtcp2_ccerr *cerr = ngtcp2_conn_get_ccerr(ctx->qconn);
2770
2771    result = CURLE_COULDNT_CONNECT;
2772    if(cerr) {
2773      CURL_TRC_CF(data, cf, "connect error, type=%d, code=%" PRIu64,
2774                  cerr->type, cerr->error_code);
2775      switch(cerr->type) {
2776      case NGTCP2_CCERR_TYPE_VERSION_NEGOTIATION:
2777        CURL_TRC_CF(data, cf, "error in version negotiation");
2778        break;
2779      default:
2780        if(cerr->error_code >= NGTCP2_CRYPTO_ERROR) {
2781          CURL_TRC_CF(data, cf, "crypto error, tls alert=%u",
2782                      (unsigned int)(cerr->error_code & 0xffU));
2783        }
2784        else if(cerr->error_code == NGTCP2_CONNECTION_REFUSED) {
2785          CURL_TRC_CF(data, cf, "connection refused by server");
2786          /* When a QUIC server instance is shutting down, it may send us a
2787           * CONNECTION_CLOSE with this code right away. We want
2788           * to keep on trying in this case. */
2789          result = CURLE_WEIRD_SERVER_REPLY;
2790        }
2791      }
2792    }
2793  }
2794
2795#ifdef CURLVERBOSE
2796  if(result) {
2797    struct ip_quadruple ip;
2798
2799    if(!Curl_cf_socket_peek(cf->next, data, NULL, NULL, &ip))
2800      infof(data, "QUIC connect to %s port %u failed: %s",
2801            ip.remote_ip, ip.remote_port, curl_easy_strerror(result));
2802  }
2803#endif
2804  if(!result && ctx->qconn) {
2805    result = check_and_set_expiry(cf, data, &pktx);
2806  }
2807  if(result || *done)
2808    CURL_TRC_CF(data, cf, "connect -> %d, done=%d", result, *done);
2809  CF_DATA_RESTORE(cf, save);
2810  return result;
2811}
2812
2813static CURLcode cf_ngtcp2_query(struct Curl_cfilter *cf,
2814                                struct Curl_easy *data,
2815                                int query, int *pres1, void *pres2)
2816{
2817  struct cf_ngtcp2_ctx *ctx = cf->ctx;
2818  struct cf_call_data save;
2819
2820  switch(query) {
2821  case CF_QUERY_MAX_CONCURRENT: {
2822    DEBUGASSERT(pres1);
2823    CF_DATA_SAVE(save, cf, data);
2824    /* Set after transport params arrived and continually updated
2825     * by callback. QUIC counts the number over the lifetime of the
2826     * connection, ever increasing.
2827     * We count the *open* transfers plus the budget for new ones. */
2828    if(!ctx->qconn || ctx->shutdown_started) {
2829      *pres1 = 0;
2830    }
2831    else if(ctx->max_bidi_streams) {
2832      uint64_t avail_bidi_streams = 0;
2833      uint64_t max_streams = cf->conn->attached_xfers;
2834      if(ctx->max_bidi_streams > ctx->used_bidi_streams)
2835        avail_bidi_streams = ctx->max_bidi_streams - ctx->used_bidi_streams;
2836      max_streams += avail_bidi_streams;
2837      *pres1 = (max_streams > INT_MAX) ? INT_MAX : (int)max_streams;
2838    }
2839    else  /* transport params not arrived yet? take our default. */
2840      *pres1 = (int)Curl_multi_max_concurrent_streams(data->multi);
2841    CURL_TRC_CF(data, cf, "query conn[%" FMT_OFF_T "]: "
2842                "MAX_CONCURRENT -> %d (%u in use)",
2843                cf->conn->connection_id, *pres1, cf->conn->attached_xfers);
2844    CF_DATA_RESTORE(cf, save);
2845    return CURLE_OK;
2846  }
2847  case CF_QUERY_CONNECT_REPLY_MS:
2848    if(ctx->q.got_first_byte) {
2849      timediff_t ms = curlx_ptimediff_ms(&ctx->q.first_byte_at,
2850                                         &ctx->started_at);
2851      *pres1 = (ms < INT_MAX) ? (int)ms : INT_MAX;
2852    }
2853    else
2854      *pres1 = -1;
2855    return CURLE_OK;
2856  case CF_QUERY_TIMER_CONNECT: {
2857    struct curltime *when = pres2;
2858    if(ctx->q.got_first_byte)
2859      *when = ctx->q.first_byte_at;
2860    return CURLE_OK;
2861  }
2862  case CF_QUERY_TIMER_APPCONNECT: {
2863    struct curltime *when = pres2;
2864    if(cf->connected)
2865      *when = ctx->handshake_at;
2866    return CURLE_OK;
2867  }
2868  case CF_QUERY_HTTP_VERSION:
2869    *pres1 = 30;
2870    return CURLE_OK;
2871  case CF_QUERY_SSL_INFO:
2872  case CF_QUERY_SSL_CTX_INFO: {
2873    struct curl_tlssessioninfo *info = pres2;
2874    if(Curl_vquic_tls_get_ssl_info(&ctx->tls,
2875                                   (query == CF_QUERY_SSL_CTX_INFO), info))
2876      return CURLE_OK;
2877    break;
2878  }
2879  case CF_QUERY_ALPN_NEGOTIATED: {
2880    const char **palpn = pres2;
2881    DEBUGASSERT(palpn);
2882    *palpn = cf->connected ? "h3" : NULL;
2883    return CURLE_OK;
2884  }
2885  default:
2886    break;
2887  }
2888  return cf->next ?
2889    cf->next->cft->query(cf->next, data, query, pres1, pres2) :
2890    CURLE_UNKNOWN_OPTION;
2891}
2892
2893static bool cf_ngtcp2_conn_is_alive(struct Curl_cfilter *cf,
2894                                    struct Curl_easy *data,
2895                                    bool *input_pending)
2896{
2897  struct cf_ngtcp2_ctx *ctx = cf->ctx;
2898  bool alive = FALSE;
2899  const ngtcp2_transport_params *rp;
2900  struct cf_call_data save;
2901
2902  CF_DATA_SAVE(save, cf, data);
2903  *input_pending = FALSE;
2904  if(!ctx->qconn || ctx->shutdown_started)
2905    goto out;
2906
2907  /* We do not announce a max idle timeout, but when the peer does
2908   * it closes the connection when it expires. */
2909  rp = ngtcp2_conn_get_remote_transport_params(ctx->qconn);
2910  if(rp && rp->max_idle_timeout) {
2911    timediff_t idletime_ms =
2912      curlx_ptimediff_ms(Curl_pgrs_now(data), &ctx->q.last_io);
2913    if(idletime_ms > 0) {
2914      uint64_t max_idle_ms =
2915        (uint64_t)(rp->max_idle_timeout / NGTCP2_MILLISECONDS);
2916      if((uint64_t)idletime_ms > max_idle_ms)
2917        goto out;
2918    }
2919  }
2920
2921  if(!cf->next || !cf->next->cft->is_alive(cf->next, data, input_pending))
2922    goto out;
2923
2924  alive = TRUE;
2925  if(*input_pending) {
2926    CURLcode result;
2927    /* This happens before we have sent off a request and the connection is
2928       not in use by any other transfer, there should not be any data here,
2929       only "protocol frames" */
2930    *input_pending = FALSE;
2931    result = cf_progress_ingress(cf, data, NULL);
2932    CURL_TRC_CF(data, cf, "is_alive, progress ingress -> %d", result);
2933    alive = result ? FALSE : TRUE;
2934  }
2935
2936out:
2937  CF_DATA_RESTORE(cf, save);
2938  return alive;
2939}
2940
2941struct Curl_cftype Curl_cft_http3 = {
2942  "HTTP/3",
2943  CF_TYPE_IP_CONNECT | CF_TYPE_SSL | CF_TYPE_MULTIPLEX | CF_TYPE_HTTP,
2944  0,
2945  cf_ngtcp2_destroy,
2946  cf_ngtcp2_connect,
2947  cf_ngtcp2_close,
2948  cf_ngtcp2_shutdown,
2949  cf_ngtcp2_adjust_pollset,
2950  Curl_cf_def_data_pending,
2951  cf_ngtcp2_send,
2952  cf_ngtcp2_recv,
2953  cf_ngtcp2_cntrl,
2954  cf_ngtcp2_conn_is_alive,
2955  Curl_cf_def_conn_keep_alive,
2956  cf_ngtcp2_query,
2957};
2958
2959CURLcode Curl_cf_ngtcp2_create(struct Curl_cfilter **pcf,
2960                               struct Curl_easy *data,
2961                               struct connectdata *conn,
2962                               struct Curl_sockaddr_ex *addr)
2963{
2964  struct cf_ngtcp2_ctx *ctx = NULL;
2965  struct Curl_cfilter *cf = NULL;
2966  CURLcode result;
2967
2968  ctx = curlx_calloc(1, sizeof(*ctx));
2969  if(!ctx) {
2970    result = CURLE_OUT_OF_MEMORY;
2971    goto out;
2972  }
2973  cf_ngtcp2_ctx_init(ctx);
2974
2975  result = Curl_cf_create(&cf, &Curl_cft_http3, ctx);
2976  if(result)
2977    goto out;
2978  cf->conn = conn;
2979
2980  result = Curl_cf_udp_create(&cf->next, data, conn, addr, TRNSPRT_QUIC);
2981  if(result)
2982    goto out;
2983  cf->next->conn = cf->conn;
2984  cf->next->sockindex = cf->sockindex;
2985
2986out:
2987  *pcf = (!result) ? cf : NULL;
2988  if(result) {
2989    if(cf)
2990      Curl_conn_cf_discard_chain(&cf, data);
2991    else if(ctx)
2992      cf_ngtcp2_ctx_free(ctx);
2993  }
2994  return result;
2995}
2996
2997#endif