summaryrefslogtreecommitdiffhomepage
path: root/src/http/ngx_http.c (unfollow)
AgeCommit message (Collapse)AuthorFilesLines
2021-10-15HTTP/2: removed support for NPN.Vladimir Homutov1-3/+2
NPN was replaced with ALPN, published as RFC 7301 in July 2014. It used to negotiate SPDY (and, in transition, HTTP/2). NPN supported appeared in OpenSSL 1.0.1. It does not work with TLSv1.3 [1]. ALPN is supported since OpenSSL 1.0.2. The NPN support was dropped in Firefox 53 [2] and Chrome 51 [3]. [1] https://github.com/openssl/openssl/issues/3665. [2] https://bugzilla.mozilla.org/show_bug.cgi?id=1248198 [3] https://www.chromestatus.com/feature/5767920709795840
2021-05-24Location header escaping in redirects (ticket #882).Ruslan Ermilov1-0/+37
The header is escaped in redirects based on request URI or location name (auto redirect).
2021-01-19Core: removed post_accept_timeout.Maxim Dounin1-1/+0
Keeping post_accept_timeout in ngx_listening_t is no longer needed since we've switched to 1 second timeout for deferred accept in 5541:fdb67cfc957d. Further, using it in HTTP code can result in client_header_timeout being used from an incorrect server block, notably if address-specific virtual servers are used along with a wildcard listening socket, or if we've switched to a different server block based on SNI in SSL handshake.
2020-06-15Fixed potential leak of temp pool.Eran Kornblau1-2/+2
In case ngx_hash_add_key() fails, need to goto failed instead of returning, so that temp_pool will be destoryed.
2019-03-15Multiple addresses in "listen".Roman Arutyunyan1-16/+18
Previously only one address was used by the listen directive handler even if host name resolved to multiple addresses. Now a separate listening socket is created for each address.
2018-07-12Events: moved sockets cloning to ngx_event_init_conf().Maxim Dounin1-4/+0
Previously, listenings sockets were not cloned if the worker_processes directive was specified after "listen ... reuseport". This also simplifies upcoming configuration check on the number of worker connections, as it needs to know the number of listening sockets before cloning.
2017-07-20Precontent phase.Roman Arutyunyan1-11/+8
The phase is added instead of the try_files phase. Unlike the old phase, the new one supports registering multiple handlers. The try_files implementation is moved to a separate ngx_http_try_files_module, which now registers a precontent phase handler.
2017-07-19Style.Alex Zhang1-1/+1
Signed-off-by: Alex Zhang <zchao1995@gmail.com>
2016-12-13The size of cmcf->phase_engine.handlers explained.Ruslan Ermilov1-1/+4
2016-10-03Modules compatibility: removed unneeded IPV6_V6ONLY checks.Maxim Dounin1-1/+1
The IPV6_V6ONLY macro is now checked only while parsing appropriate flag and when using the macro. The ipv6only field in listen structures is always initialized to 1, even if not supported on a given platform. This is expected to prevent a module compiled without IPV6_V6ONLY from accidentally creating dual sockets if loaded into main binary with proper IPV6_V6ONLY support.
2016-06-20Introduced ngx_inet_get_port() and ngx_inet_set_port() functions.Roman Arutyunyan1-25/+1
2016-05-23Renamed "u" to "sockaddr" in listen options types.Maxim Dounin1-8/+10
2016-05-20Use ngx_cmp_sockaddr() where appropriate.Ruslan Ermilov1-33/+4
2016-02-04Dynamic modules: changed ngx_modules to cycle->modules.Maxim Dounin1-14/+14
2016-02-04Dynamic modules: moved module-related stuff to separate files.Maxim Dounin1-8/+1
2015-12-17Fixed PROXY protocol on IPv6 sockets (ticket #858).Maxim Dounin1-0/+1
2015-09-11The HTTP/2 implementation (RFC 7240, 7241).Valentin Bartenev1-14/+17
The SPDY support is removed, as it's incompatible with the new module.
2015-06-16Disabled duplicate http, mail, and stream blocks.Vladimir Homutov1-0/+4
Such configurations have very limited use, introduce various problems and are not officially supported.
2015-05-20The "reuseport" option of the "listen" directive.Maxim Dounin1-0/+8
When configured, an individual listen socket on a given address is created for each worker process. This allows to reduce in-kernel lock contention on configurations with high accept rates, resulting in better performance. As of now it works on Linux and DragonFly BSD. Note that on Linux incoming connection requests are currently tied up to a specific listen socket, and if some sockets are closed, connection requests will be reset, see https://lwn.net/Articles/542629/. With nginx, this may happen if the number of worker processes is reduced. There is no such problem on DragonFly BSD. Based on previous work by Sepherosa Ziehau and Yingqi Lu.
2015-05-20Simplified ngx_http_init_listening().Maxim Dounin1-7/+1
There is no need to set "i" to 0, as it's expected to be 0 assuming the bindings are properly sorted, and we already rely on this when explicitly set hport->naddrs to 1. Remaining conditional code is replaced with identical "hport->naddrs = i + 1". Identical modifications are done in the mail and stream modules, in the ngx_mail_optimize_servers() and ngx_stream_optimize_servers() functions, respectively. No functional changes.
2015-04-24Merge proxy_protocol setting of listen directives.Roman Arutyunyan1-1/+4
It's now enough to specify proxy_protocol option in one listen directive to enable it in all servers listening on the same address/port. Previously, the setting from the first directive was always used.
2015-03-23Request body: filters support.Maxim Dounin1-2/+3
2014-09-17Avoided to add duplicate hash key in ngx_http_types_slot().Gu Feng1-1/+5
2014-06-26Fixed wrong sizeof() in ngx_http_init_locations().Maxim Dounin1-2/+2
There is no real difference on all known platforms, but it's still wrong. Found by Coverity (CID 400876).
2014-03-17Added server-side support for PROXY protocol v1 (ticket #355).Roman Arutyunyan1-0/+1
Client address specified in the PROXY protocol header is now saved in the $proxy_protocol_addr variable and can be used in the realip module. This is currently not implemented for mail.
2014-01-28SSL: support ALPN (IETF's successor to NPN).Piotr Sikora1-3/+5
Signed-off-by: Piotr Sikora <piotr@cloudflare.com>
2013-12-03Added support for TCP_FASTOPEN supported in Linux >= 3.7.1.Mathew Rodley1-0/+4
--- auto/unix | 12 ++++++++++++ src/core/ngx_connection.c | 32 ++++++++++++++++++++++++++++++++ src/core/ngx_connection.h | 4 ++++ src/http/ngx_http.c | 4 ++++ src/http/ngx_http_core_module.c | 21 +++++++++++++++++++++ src/http/ngx_http_core_module.h | 3 +++ 6 files changed, 76 insertions(+)
2013-09-23Caseless location tree construction (ticket #90).Maxim Dounin1-4/+7
Location tree was always constructed using case-sensitive comparison, even on case-insensitive systems. This resulted in incorrect operation if uppercase letters were used in location directives. Notably, the following config: location /a { ... } location /B { ... } failed to properly map requests to "/B" into "location /B".
2013-03-21Use NGX_DEFAULT_POOL_SIZE macro where appropriate.Ruslan Ermilov1-1/+1
2013-03-20Preliminary experimental support for SPDY draft 2.Valentin Bartenev1-0/+23
2012-07-17Fixed sorting of listen addresses so that wildcard address is always atRuslan Ermilov1-0/+5
the end (closes #187). Failure to do so could result in several listen sockets to be created instead of only one listening on wildcard address. Reported by Roman Odaisky.
2012-04-03Fixed spelling in multiline C comments.Ruslan Ermilov1-1/+1
2012-01-18Copyright updated.Maxim Konovalov1-0/+1
2011-12-05Added the "so_keepalive=" parameter to the "listen" directive.Valentin Bartenev1-0/+7
The "so_keepalive" directive in mail module was deprecated. Thanks to Vsevolod Stakhov for initial work.
2011-09-27Fixed segmentation fault with empty config on Windows.Maxim Dounin1-3/+5
See here for report: http://mailman.nginx.org/pipermail/nginx-ru/2011-September/043288.html
2011-09-23Fixed error message.Ruslan Ermilov1-1/+1
2011-09-19Replaced "can not" with "cannot" and "could not" in a bunch of places.Ruslan Ermilov1-1/+1
Fixed nearby grammar errors.
2010-12-12always run regex in server_name to get captures for IPv6 addresses,Igor Sysoev1-1/+5
the same fix for IPv4 addresses has been made in r2584
2010-12-12test wildcard tail hash existance for IPv6 addresses,Igor Sysoev1-2/+2
the same fix for IPv4 addresses has been made in r2581
2010-12-12style fixIgor Sysoev1-1/+1
2010-09-28nginx uses SSL mode for a listen socket with any option set,Igor Sysoev1-1/+1
the bug has been introduced in r3765
2010-09-27allow duplicate listen ssl optionsIgor Sysoev1-0/+10
2010-08-02ngx_http_conf_get_module_srv_conf() and ngx_http_conf_get_module_loc_conf()Igor Sysoev1-33/+75
may be used at merge phase
2010-07-05listen setfib=XIgor Sysoev1-0/+4
2010-06-18return code textIgor Sysoev1-2/+2
2009-12-22fix building by gcc 4.4 with -O2/3/s:Igor Sysoev1-9/+9
dereferencing pointer 'sin' does break strict-aliasing rules
2009-11-30support "*" in gzip_types, ssi_types, etcIgor Sysoev1-7/+26
2009-10-28style fixIgor Sysoev1-1/+1
2009-10-28fix segfault if http {} block is empty, the bug had been introduced in r3218Igor Sysoev1-0/+4
2009-10-26http listen unix domain socketsIgor Sysoev1-0/+16