|
| 1 | +diff -r 2e8de3d81783 src/event/ngx_event_openssl.c |
| 2 | +--- a/src/event/ngx_event_openssl.c Tue Aug 22 17:36:12 2017 +0300 |
| 3 | ++++ b/src/event/ngx_event_openssl.c Tue Aug 22 20:20:30 2017 +0000 |
| 4 | +@@ -1221,6 +1221,60 @@ |
| 5 | + } |
| 6 | + |
| 7 | + |
| 8 | ++#if OPENSSL_VERSION_NUMBER >= 0x10101000L |
| 9 | ++ |
| 10 | ++int |
| 11 | ++ngx_SSL_early_cb_fn(SSL *s, int *al, void *arg) { |
| 12 | ++ |
| 13 | ++ int got_extensions; |
| 14 | ++ int *ext_out; |
| 15 | ++ size_t ext_len; |
| 16 | ++ ngx_connection_t *c; |
| 17 | ++ |
| 18 | ++ c = arg; |
| 19 | ++ |
| 20 | ++ if (c == NULL) { |
| 21 | ++ return 1; |
| 22 | ++ } |
| 23 | ++ |
| 24 | ++ if (c->ssl == NULL) { |
| 25 | ++ return 1; |
| 26 | ++ } |
| 27 | ++ |
| 28 | ++ c->ssl->client_extensions_size = 0; |
| 29 | ++ c->ssl->client_extensions = NULL; |
| 30 | ++ |
| 31 | ++ got_extensions = SSL_client_hello_get1_extensions_present(s, |
| 32 | ++ &ext_out, |
| 33 | ++ &ext_len); |
| 34 | ++ if (!got_extensions) { |
| 35 | ++ return 1; |
| 36 | ++ } |
| 37 | ++ |
| 38 | ++ if (!ext_out) { |
| 39 | ++ return 1; |
| 40 | ++ } |
| 41 | ++ |
| 42 | ++ if (!ext_len) { |
| 43 | ++ return 1; |
| 44 | ++ } |
| 45 | ++ |
| 46 | ++ c->ssl->client_extensions = ngx_palloc(c->pool, sizeof(int) * ext_len); |
| 47 | ++ if (c->ssl->client_extensions == NULL) { |
| 48 | ++ OPENSSL_free(ext_out); |
| 49 | ++ return 1; |
| 50 | ++ } |
| 51 | ++ |
| 52 | ++ c->ssl->client_extensions_size = ext_len; |
| 53 | ++ ngx_memcpy(c->ssl->client_extensions, ext_out, sizeof(int) * ext_len); |
| 54 | ++ |
| 55 | ++ OPENSSL_free(ext_out); |
| 56 | ++ |
| 57 | ++ return 1; |
| 58 | ++} |
| 59 | ++#endif |
| 60 | ++ |
| 61 | ++ |
| 62 | + ngx_int_t |
| 63 | + ngx_ssl_handshake(ngx_connection_t *c) |
| 64 | + { |
| 65 | +@@ -1229,6 +1283,10 @@ |
| 66 | + |
| 67 | + ngx_ssl_clear_error(c->log); |
| 68 | + |
| 69 | ++#if OPENSSL_VERSION_NUMBER >= 0x10101000L |
| 70 | ++ SSL_CTX_set_client_hello_cb(c->ssl->session_ctx, ngx_SSL_early_cb_fn, c); |
| 71 | ++#endif |
| 72 | ++ |
| 73 | + n = SSL_do_handshake(c->ssl->connection); |
| 74 | + |
| 75 | + ngx_log_debug1(NGX_LOG_DEBUG_EVENT, c->log, 0, "SSL_do_handshake: %d", n); |
| 76 | +diff -r 2e8de3d81783 src/event/ngx_event_openssl.h |
| 77 | +--- a/src/event/ngx_event_openssl.h Tue Aug 22 17:36:12 2017 +0300 |
| 78 | ++++ b/src/event/ngx_event_openssl.h Tue Aug 22 20:20:30 2017 +0000 |
| 79 | +@@ -98,6 +98,11 @@ |
| 80 | + unsigned in_early:1; |
| 81 | + unsigned early_preread:1; |
| 82 | + unsigned write_blocked:1; |
| 83 | ++ |
| 84 | ++#if OPENSSL_VERSION_NUMBER >= 0x10101000L |
| 85 | ++ size_t client_extensions_size; |
| 86 | ++ int *client_extensions; |
| 87 | ++#endif |
| 88 | + }; |
| 89 | + |
| 90 | + |
0 commit comments