Lines Matching +full:hdr +full:- +full:engine

2  * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved.
112 if (ch->qlog != NULL) in ch_get_qlog()
113 return ch->qlog; in ch_get_qlog()
115 if (!ch->use_qlog) in ch_get_qlog()
118 if (ch->is_server && ch->init_dcid.id_len == 0) in ch_get_qlog()
121 qti.odcid = ch->init_dcid; in ch_get_qlog()
122 qti.title = ch->qlog_title; in ch_get_qlog()
125 qti.is_server = ch->is_server; in ch_get_qlog()
128 if ((ch->qlog = ossl_qlog_new_from_env(&qti)) == NULL) { in ch_get_qlog()
129 ch->use_qlog = 0; /* don't try again */ in ch_get_qlog()
133 return ch->qlog; in ch_get_qlog()
169 if (ch->port == NULL || ch->lcidm == NULL || ch->srtm == NULL) in ch_init()
172 rx_short_dcid_len = ossl_quic_port_get_rx_short_dcid_len(ch->port); in ch_init()
173 tx_init_dcid_len = ossl_quic_port_get_tx_init_dcid_len(ch->port); in ch_init()
176 if (!ch->is_server in ch_init()
177 && !ossl_quic_gen_rand_conn_id(ch->port->engine->libctx, tx_init_dcid_len, in ch_init()
178 &ch->init_dcid)) in ch_init()
182 qtx_args.libctx = ch->port->engine->libctx; in ch_init()
186 ch->rx_max_udp_payload_size = qtx_args.mdpl; in ch_init()
188 ch->ping_deadline = ossl_time_infinite(); in ch_init()
190 ch->qtx = ossl_qtx_new(&qtx_args); in ch_init()
191 if (ch->qtx == NULL) in ch_init()
194 ch->txpim = ossl_quic_txpim_new(); in ch_init()
195 if (ch->txpim == NULL) in ch_init()
198 ch->cfq = ossl_quic_cfq_new(); in ch_init()
199 if (ch->cfq == NULL) in ch_init()
202 if (!ossl_quic_txfc_init(&ch->conn_txfc, NULL)) in ch_init()
209 ch->tx_init_max_stream_data_bidi_local = DEFAULT_INIT_STREAM_RXFC_WND; in ch_init()
210 ch->tx_init_max_stream_data_bidi_remote = DEFAULT_INIT_STREAM_RXFC_WND; in ch_init()
211 ch->tx_init_max_stream_data_uni = DEFAULT_INIT_STREAM_RXFC_WND; in ch_init()
213 if (!ossl_quic_rxfc_init(&ch->conn_rxfc, NULL, in ch_init()
221 if (!ossl_quic_rxfc_init_standalone(&ch->crypto_rxfc[pn_space], in ch_init()
226 if (!ossl_quic_rxfc_init_standalone(&ch->max_streams_bidi_rxfc, in ch_init()
231 if (!ossl_quic_rxfc_init_standalone(&ch->max_streams_uni_rxfc, in ch_init()
236 if (!ossl_statm_init(&ch->statm)) in ch_init()
239 ch->have_statm = 1; in ch_init()
240 ch->cc_method = &ossl_cc_newreno_method; in ch_init()
241 if ((ch->cc_data = ch->cc_method->new(get_time, ch)) == NULL) in ch_init()
244 if ((ch->ackm = ossl_ackm_new(get_time, ch, &ch->statm, in ch_init()
245 ch->cc_method, ch->cc_data, in ch_init()
246 ch->is_server)) == NULL) in ch_init()
249 if (!ossl_quic_stream_map_init(&ch->qsm, get_stream_limit, ch, in ch_init()
250 &ch->max_streams_bidi_rxfc, in ch_init()
251 &ch->max_streams_uni_rxfc, in ch_init()
252 ch->is_server)) in ch_init()
255 ch->have_qsm = 1; in ch_init()
257 if (!ch->is_server in ch_init()
258 && !ossl_quic_lcidm_generate_initial(ch->lcidm, ch, &ch->init_scid)) in ch_init()
261 txp_args.cur_scid = ch->init_scid; in ch_init()
262 txp_args.cur_dcid = ch->init_dcid; in ch_init()
264 txp_args.qtx = ch->qtx; in ch_init()
265 txp_args.txpim = ch->txpim; in ch_init()
266 txp_args.cfq = ch->cfq; in ch_init()
267 txp_args.ackm = ch->ackm; in ch_init()
268 txp_args.qsm = &ch->qsm; in ch_init()
269 txp_args.conn_txfc = &ch->conn_txfc; in ch_init()
270 txp_args.conn_rxfc = &ch->conn_rxfc; in ch_init()
271 txp_args.max_streams_bidi_rxfc = &ch->max_streams_bidi_rxfc; in ch_init()
272 txp_args.max_streams_uni_rxfc = &ch->max_streams_uni_rxfc; in ch_init()
273 txp_args.cc_method = ch->cc_method; in ch_init()
274 txp_args.cc_data = ch->cc_data; in ch_init()
282 ch->crypto_send[pn_space] = ossl_quic_sstream_new(INIT_CRYPTO_SEND_BUF_LEN); in ch_init()
283 if (ch->crypto_send[pn_space] == NULL) in ch_init()
286 txp_args.crypto[pn_space] = ch->crypto_send[pn_space]; in ch_init()
289 ch->txp = ossl_quic_tx_packetiser_new(&txp_args); in ch_init()
290 if (ch->txp == NULL) in ch_init()
294 if (!ch->is_server) in ch_init()
295 ossl_quic_tx_packetiser_set_validated(ch->txp); in ch_init()
297 ossl_quic_tx_packetiser_set_ack_tx_cb(ch->txp, ch_on_txp_ack_tx, ch); in ch_init()
309 if (ch->qrx == NULL && ch->is_tserver_ch == 0) { in ch_init()
311 qrx_args.libctx = ch->port->engine->libctx; in ch_init()
312 qrx_args.demux = ch->port->demux; in ch_init()
316 if ((ch->qrx = ossl_qrx_new(&qrx_args)) == NULL) in ch_init()
320 if (ch->qrx != NULL) { in ch_init()
326 if (!ossl_qrx_set_late_validation_cb(ch->qrx, in ch_init()
331 if (!ossl_qrx_set_key_update_cb(ch->qrx, in ch_init()
339 ch->crypto_recv[pn_space] = ossl_quic_rstream_new(NULL, NULL, 0); in ch_init()
340 if (ch->crypto_recv[pn_space] == NULL) in ch_init()
345 tls_args.s = ch->tls; in ch_init()
360 tls_args.is_server = ch->is_server; in ch_init()
363 if ((ch->qtls = ossl_quic_tls_new(&tls_args)) == NULL) in ch_init()
366 ch->tx_max_ack_delay = DEFAULT_MAX_ACK_DELAY; in ch_init()
367 ch->rx_max_ack_delay = QUIC_DEFAULT_MAX_ACK_DELAY; in ch_init()
368 ch->rx_ack_delay_exp = QUIC_DEFAULT_ACK_DELAY_EXP; in ch_init()
369 ch->rx_active_conn_id_limit = QUIC_MIN_ACTIVE_CONN_ID_LIMIT; in ch_init()
370 ch->tx_enc_level = QUIC_ENC_LEVEL_INITIAL; in ch_init()
371 ch->rx_enc_level = QUIC_ENC_LEVEL_INITIAL; in ch_init()
372 ch->txku_threshold_override = UINT64_MAX; in ch_init()
374 ch->max_idle_timeout_local_req = QUIC_DEFAULT_IDLE_TIMEOUT; in ch_init()
375 ch->max_idle_timeout_remote_req = 0; in ch_init()
376 ch->max_idle_timeout = ch->max_idle_timeout_local_req; in ch_init()
378 ossl_ackm_set_tx_max_ack_delay(ch->ackm, ossl_ms2time(ch->tx_max_ack_delay)); in ch_init()
379 ossl_ackm_set_rx_max_ack_delay(ch->ackm, ossl_ms2time(ch->rx_max_ack_delay)); in ch_init()
382 ossl_list_ch_insert_tail(&ch->port->channel_list, ch); in ch_init()
383 ch->on_port_list = 1; in ch_init()
395 if (ch->ackm != NULL) in ch_cleanup()
399 ossl_ackm_on_pkt_space_discarded(ch->ackm, pn_space); in ch_cleanup()
401 ossl_quic_lcidm_cull(ch->lcidm, ch); in ch_cleanup()
402 ossl_quic_srtm_cull(ch->srtm, ch); in ch_cleanup()
403 ossl_quic_tx_packetiser_free(ch->txp); in ch_cleanup()
404 ossl_quic_txpim_free(ch->txpim); in ch_cleanup()
405 ossl_quic_cfq_free(ch->cfq); in ch_cleanup()
406 ossl_qtx_free(ch->qtx); in ch_cleanup()
407 if (ch->cc_data != NULL) in ch_cleanup()
408 ch->cc_method->free(ch->cc_data); in ch_cleanup()
409 if (ch->have_statm) in ch_cleanup()
410 ossl_statm_destroy(&ch->statm); in ch_cleanup()
411 ossl_ackm_free(ch->ackm); in ch_cleanup()
413 if (ch->have_qsm) in ch_cleanup()
414 ossl_quic_stream_map_cleanup(&ch->qsm); in ch_cleanup()
417 ossl_quic_sstream_free(ch->crypto_send[pn_space]); in ch_cleanup()
418 ossl_quic_rstream_free(ch->crypto_recv[pn_space]); in ch_cleanup()
421 ossl_qrx_pkt_release(ch->qrx_pkt); in ch_cleanup()
422 ch->qrx_pkt = NULL; in ch_cleanup()
424 ossl_quic_tls_free(ch->qtls); in ch_cleanup()
425 ossl_qrx_free(ch->qrx); in ch_cleanup()
426 OPENSSL_free(ch->local_transport_params); in ch_cleanup()
427 OPENSSL_free((char *)ch->terminate_cause.reason); in ch_cleanup()
428 OSSL_ERR_STATE_free(ch->err_state); in ch_cleanup()
429 OPENSSL_free(ch->ack_range_scratch); in ch_cleanup()
430 OPENSSL_free(ch->pending_new_token); in ch_cleanup()
432 if (ch->on_port_list) { in ch_cleanup()
433 ossl_list_ch_remove(&ch->port->channel_list, ch); in ch_cleanup()
434 ch->on_port_list = 0; in ch_cleanup()
438 if (ch->qlog != NULL) in ch_cleanup()
439 ossl_qlog_flush(ch->qlog); /* best effort */ in ch_cleanup()
441 OPENSSL_free(ch->qlog_title); in ch_cleanup()
442 ossl_qlog_free(ch->qlog); in ch_cleanup()
453 if (tserver_ch->qrx == NULL && tserver_ch->is_tserver_ch == 1) { in ossl_quic_channel_bind_qrx()
454 tserver_ch->qrx = qrx; in ossl_quic_channel_bind_qrx()
455 ossl_qrx_set_late_validation_cb(tserver_ch->qrx, rx_late_validate, in ossl_quic_channel_bind_qrx()
457 ossl_qrx_set_key_update_cb(tserver_ch->qrx, rxku_detected, in ossl_quic_channel_bind_qrx()
469 ch->port = args->port; in ossl_quic_channel_alloc()
470 ch->is_server = args->is_server; in ossl_quic_channel_alloc()
471 ch->tls = args->tls; in ossl_quic_channel_alloc()
472 ch->lcidm = args->lcidm; in ossl_quic_channel_alloc()
473 ch->srtm = args->srtm; in ossl_quic_channel_alloc()
474 ch->qrx = args->qrx; in ossl_quic_channel_alloc()
475 ch->is_tserver_ch = args->is_tserver_ch; in ossl_quic_channel_alloc()
477 ch->use_qlog = args->use_qlog; in ossl_quic_channel_alloc()
479 if (ch->use_qlog && args->qlog_title != NULL) { in ossl_quic_channel_alloc()
480 if ((ch->qlog_title = OPENSSL_strdup(args->qlog_title)) == NULL) { in ossl_quic_channel_alloc()
505 if (ch->qtx == NULL) in ossl_quic_channel_set_mutator()
508 ossl_qtx_set_mutator(ch->qtx, mutatecb, finishmutatecb, mutatearg); in ossl_quic_channel_set_mutator()
514 if (!ch->addressed_mode) in ossl_quic_channel_get_peer_addr()
517 return BIO_ADDR_copy(peer_addr, &ch->cur_peer_addr); in ossl_quic_channel_get_peer_addr()
522 if (ch->state != QUIC_CHANNEL_STATE_IDLE) in ossl_quic_channel_set_peer_addr()
526 BIO_ADDR_clear(&ch->cur_peer_addr); in ossl_quic_channel_set_peer_addr()
527 ch->addressed_mode = 0; in ossl_quic_channel_set_peer_addr()
531 if (!BIO_ADDR_copy(&ch->cur_peer_addr, peer_addr)) { in ossl_quic_channel_set_peer_addr()
532 ch->addressed_mode = 0; in ossl_quic_channel_set_peer_addr()
535 ch->addressed_mode = 1; in ossl_quic_channel_set_peer_addr()
542 return ossl_quic_port_get0_reactor(ch->port); in ossl_quic_channel_get_reactor()
547 return &ch->qsm; in ossl_quic_channel_get_qsm()
552 return &ch->statm; in ossl_quic_channel_get_statm()
557 return ch->tls; in ossl_quic_channel_get0_tls()
593 cfq_item = ossl_quic_cfq_add_frame(ch->cfq, 1, in ossl_quic_channel_schedule_new_token()
596 (unsigned char *)buf_mem->data, l, in ossl_quic_channel_schedule_new_token()
611 return ossl_quic_port_get_rx_short_dcid_len(ch->port); in ossl_quic_channel_get_short_header_conn_id_len()
617 return ossl_quic_stream_map_get_by_id(&ch->qsm, stream_id); in ossl_quic_channel_get_stream_by_id()
622 return ch != NULL && ch->state == QUIC_CHANNEL_STATE_ACTIVE; in ossl_quic_channel_is_active()
627 return ch->state == QUIC_CHANNEL_STATE_TERMINATING_CLOSING; in ossl_quic_channel_is_closing()
632 return ch->state == QUIC_CHANNEL_STATE_TERMINATING_DRAINING; in ossl_quic_channel_is_draining()
643 return ch->state == QUIC_CHANNEL_STATE_TERMINATED; in ossl_quic_channel_is_terminated()
655 return ossl_quic_channel_is_term_any(ch) ? &ch->terminate_cause : NULL; in ossl_quic_channel_get_terminate_cause()
660 return ch->handshake_complete; in ossl_quic_channel_is_handshake_complete()
665 return ch->handshake_confirmed; in ossl_quic_channel_is_handshake_confirmed()
670 return ch->port->demux; in ossl_quic_channel_get0_demux()
675 return ch->port; in ossl_quic_channel_get0_port()
680 return ossl_quic_port_get0_engine(ch->port); in ossl_quic_channel_get0_engine()
685 return ossl_quic_port_get0_mutex(ch->port); in ossl_quic_channel_get_mutex()
690 return ossl_quic_demux_has_pending(ch->port->demux) in ossl_quic_channel_has_pending()
691 || ossl_qrx_processed_read_pending(ch->qrx); in ossl_quic_channel_has_pending()
704 return ossl_quic_port_get_time(ch->port); in get_time()
712 return uni ? ch->max_local_streams_uni : ch->max_local_streams_bidi; in get_stream_limit()
724 if (!ossl_ackm_is_rx_pn_processable(ch->ackm, pn, pn_space)) in rx_late_validate()
738 = ossl_quic_tx_packetiser_get_next_pn(ch->txp, QUIC_PN_SPACE_APP); in ch_trigger_txku()
741 || !ossl_qtx_trigger_key_update(ch->qtx)) { in ch_trigger_txku()
747 ch->txku_in_progress = 1; in ch_trigger_txku()
748 ch->txku_pn = next_pn; in ch_trigger_txku()
749 ch->rxku_expected = ch->ku_locally_initiated; in ch_trigger_txku()
755 if (ch->txku_in_progress in txku_in_progress()
756 && ossl_ackm_get_largest_acked(ch->ackm, QUIC_PN_SPACE_APP) >= ch->txku_pn) { in txku_in_progress()
757 OSSL_TIME pto = ossl_ackm_get_pto_duration(ch->ackm); in txku_in_progress()
765 * the ack for a TXKU-triggering packet, not when the TXKU is initiated. in txku_in_progress()
768 ch->txku_in_progress = 0; in txku_in_progress()
769 ch->txku_cooldown_deadline = ossl_time_add(get_time(ch), in txku_in_progress()
773 return ch->txku_in_progress; in txku_in_progress()
779 return ch->tx_enc_level == QUIC_ENC_LEVEL_1RTT /* Sanity check. */ in txku_allowed()
781 && ch->handshake_confirmed in txku_allowed()
793 ossl_time_compare(get_time(ch), ch->txku_cooldown_deadline) >= 0 in txku_recommendable()
795 && !ch->rxku_in_progress in txku_recommendable()
796 && !ch->rxku_pending_confirm; in txku_recommendable()
806 cur_pkt_count = ossl_qtx_get_cur_epoch_pkt_count(ch->qtx, enc_level); in txku_desirable()
807 max_pkt_count = ossl_qtx_get_max_epoch_pkt_count(ch->qtx, enc_level); in txku_desirable()
810 if (ch->txku_threshold_override != UINT64_MAX) in txku_desirable()
811 thresh_pkt_count = ch->txku_threshold_override; in txku_desirable()
822 ch->ku_locally_initiated = 1; in ch_maybe_trigger_spontaneous_txku()
844 return ch->handshake_confirmed && !ch->rxku_pending_confirm; in rxku_allowed()
868 assert(!ch->rxku_in_progress); in rxku_detected()
874 else if (ch->ku_locally_initiated) in rxku_detected()
879 * ping-pong of key updates. We still process it as an RXKU. in rxku_detected()
895 pto = ossl_ackm_get_pto_duration(ch->ackm); in rxku_detected()
897 ch->ku_locally_initiated = 0; in rxku_detected()
898 ch->rxku_in_progress = 1; in rxku_detected()
899 ch->rxku_pending_confirm = 1; in rxku_detected()
900 ch->rxku_trigger_pn = pn; in rxku_detected()
901 ch->rxku_update_end_deadline = ossl_time_add(get_time(ch), pto); in rxku_detected()
902 ch->rxku_expected = 0; in rxku_detected()
909 * Ordinarily, we only generate ACK when some ACK-eliciting frame has been in rxku_detected()
914 * (spontaneous or solicited) TXKU has completed - meaning that prior in rxku_detected()
918 * (Basically, we consider a RXKU event something that is 'ACK-eliciting', in rxku_detected()
920 * processing of ACK-eliciting frames as key update is not indicated via a in rxku_detected()
923 ossl_quic_tx_packetiser_schedule_ack(ch->txp, QUIC_PN_SPACE_APP); in rxku_detected()
930 if (!ch->rxku_in_progress in ch_rxku_tick()
931 || ossl_time_compare(get_time(ch), ch->rxku_update_end_deadline) < 0) in ch_rxku_tick()
934 ch->rxku_update_end_deadline = ossl_time_infinite(); in ch_rxku_tick()
935 ch->rxku_in_progress = 0; in ch_rxku_tick()
937 if (!ossl_qrx_key_update_timeout(ch->qrx, /*normal=*/1)) in ch_rxku_tick()
948 if (pn_space != QUIC_PN_SPACE_APP || !ch->rxku_pending_confirm in ch_on_txp_ack_tx()
949 || !ossl_quic_frame_ack_contains_pn(ack, ch->rxku_trigger_pn)) in ch_on_txp_ack_tx()
956 ch->rxku_pending_confirm_done = 1; in ch_on_txp_ack_tx()
968 uint32_t enc_level = ch->tx_enc_level; in ch_on_crypto_send()
970 QUIC_SSTREAM *sstream = ch->crypto_send[pn_space]; in ch_on_crypto_send()
1014 for (i = QUIC_ENC_LEVEL_INITIAL; i < ch->rx_enc_level; ++i) in ch_on_crypto_recv_record()
1016 !crypto_ensure_empty(ch->crypto_recv[ossl_quic_enc_level_to_pn_space(i)])) { in ch_on_crypto_recv_record()
1024 rstream = ch->crypto_recv[ossl_quic_enc_level_to_pn_space(ch->rx_enc_level)]; in ch_on_crypto_recv_record()
1037 uint32_t rx_pn_space = ossl_quic_enc_level_to_pn_space(ch->rx_enc_level); in ch_on_crypto_release_record()
1039 rstream = ch->crypto_recv[rx_pn_space]; in ch_on_crypto_release_record()
1044 if (!ossl_quic_rxfc_on_retire(&ch->crypto_rxfc[rx_pn_space], bytes_read, in ch_on_crypto_release_record()
1086 if (enc_level <= ch->tx_enc_level) in ch_on_handshake_yield_secret()
1093 if (!ossl_qtx_provide_secret(ch->qtx, enc_level, in ch_on_handshake_yield_secret()
1098 ch->tx_enc_level = enc_level; in ch_on_handshake_yield_secret()
1101 if (enc_level <= ch->rx_enc_level) in ch_on_handshake_yield_secret()
1113 if (!crypto_ensure_empty(ch->crypto_recv[ossl_quic_enc_level_to_pn_space(i)])) { in ch_on_handshake_yield_secret()
1121 if (!ossl_qrx_provide_secret(ch->qrx, enc_level, in ch_on_handshake_yield_secret()
1126 ch->have_new_rx_secret = 1; in ch_on_handshake_yield_secret()
1127 ch->rx_enc_level = enc_level; in ch_on_handshake_yield_secret()
1137 if (!ossl_assert(!ch->handshake_complete)) in ch_on_handshake_complete()
1140 if (!ossl_assert(ch->tx_enc_level == QUIC_ENC_LEVEL_1RTT)) in ch_on_handshake_complete()
1148 ossl_quic_tx_packetiser_set_validated(ch->txp); in ch_on_handshake_complete()
1150 if (!ch->got_remote_transport_params) { in ch_on_handshake_complete()
1162 OPENSSL_free(ch->local_transport_params); in ch_on_handshake_complete()
1163 ch->local_transport_params = NULL; in ch_on_handshake_complete()
1165 /* Tell the QRX it can now process 1-RTT packets. */ in ch_on_handshake_complete()
1166 ossl_qrx_allow_1rtt_processing(ch->qrx); in ch_on_handshake_complete()
1169 ossl_quic_tx_packetiser_notify_handshake_complete(ch->txp); in ch_on_handshake_complete()
1171 ch->handshake_complete = 1; in ch_on_handshake_complete()
1173 if (ch->pending_new_token != NULL) { in ch_on_handshake_complete()
1183 ch->pending_new_token, in ch_on_handshake_complete()
1184 ch->pending_new_token_len); in ch_on_handshake_complete()
1185 OPENSSL_free(ch->pending_new_token); in ch_on_handshake_complete()
1186 ch->pending_new_token = NULL; in ch_on_handshake_complete()
1187 ch->pending_new_token_len = 0; in ch_on_handshake_complete()
1190 if (ch->is_server) { in ch_on_handshake_complete()
1196 ossl_quic_tx_packetiser_schedule_handshake_done(ch->txp); in ch_on_handshake_complete()
1199 ch_record_state_transition(ch, ch->state); in ch_on_handshake_complete()
1208 * RFC 9001 s. 4.4: More specifically, servers MUST NOT send post-handshake in ch_on_handshake_alert()
1213 && ch->handshake_complete in ch_on_handshake_alert()
1214 && ossl_quic_tls_is_cert_request(ch->qtls)) in ch_on_handshake_alert()
1218 "Post-handshake TLS " in ch_on_handshake_alert()
1228 && ch->handshake_complete in ch_on_handshake_alert()
1229 && ossl_quic_tls_has_bad_max_early_data(ch->qtls)) in ch_on_handshake_alert()
1274 ossl_quic_txfc_bump_cwm(&s->txfc, *(uint64_t *)arg); in txfc_bump_cwm_bidi()
1283 ossl_quic_txfc_bump_cwm(&s->txfc, *(uint64_t *)arg); in txfc_bump_cwm_uni()
1290 ossl_quic_stream_map_update_state(&ch->qsm, s); in do_update()
1334 SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(ch->tls); in ch_on_transport_params()
1340 if (ch->is_server && sc->hello_retry_request != SSL_HRR_NONE in ch_on_transport_params()
1341 && ch->got_remote_transport_params) { in ch_on_transport_params()
1342 ch->max_local_streams_bidi = 0; in ch_on_transport_params()
1343 ch->max_local_streams_uni = 0; in ch_on_transport_params()
1344 ch->got_local_transport_params = 0; in ch_on_transport_params()
1345 OPENSSL_free(ch->local_transport_params); in ch_on_transport_params()
1346 ch->local_transport_params = NULL; in ch_on_transport_params()
1347 } else if (ch->got_remote_transport_params) { in ch_on_transport_params()
1369 if (ch->is_server) { in ch_on_transport_params()
1381 if (!ossl_quic_conn_id_eq(&ch->init_dcid, &cid)) { in ch_on_transport_params()
1391 if (ch->is_server) { in ch_on_transport_params()
1401 if (!ch->doing_retry) { in ch_on_transport_params()
1412 if (!ossl_quic_conn_id_eq(&ch->retry_scid, &cid)) { in ch_on_transport_params()
1432 if (!ossl_quic_conn_id_eq(&ch->init_scid, &cid)) { in ch_on_transport_params()
1452 ossl_quic_txfc_bump_cwm(&ch->conn_txfc, v); in ch_on_transport_params()
1472 ch->rx_init_max_stream_data_bidi_remote = v; in ch_on_transport_params()
1492 ch->rx_init_max_stream_data_bidi_local = v; in ch_on_transport_params()
1495 ossl_quic_stream_map_visit(&ch->qsm, txfc_bump_cwm_bidi, &v); in ch_on_transport_params()
1511 ch->rx_init_max_stream_data_uni = v; in ch_on_transport_params()
1514 ossl_quic_stream_map_visit(&ch->qsm, txfc_bump_cwm_uni, &v); in ch_on_transport_params()
1531 ch->rx_ack_delay_exp = (unsigned char)v; in ch_on_transport_params()
1548 ch->rx_max_ack_delay = v; in ch_on_transport_params()
1549 ossl_ackm_set_rx_max_ack_delay(ch->ackm, in ch_on_transport_params()
1550 ossl_ms2time(ch->rx_max_ack_delay)); in ch_on_transport_params()
1568 assert(ch->max_local_streams_bidi == 0); in ch_on_transport_params()
1569 ch->max_local_streams_bidi = v; in ch_on_transport_params()
1586 assert(ch->max_local_streams_uni == 0); in ch_on_transport_params()
1587 ch->max_local_streams_uni = v; in ch_on_transport_params()
1603 ch->max_idle_timeout_remote_req = v; in ch_on_transport_params()
1605 ch->max_idle_timeout = min_u64_ignore_0(ch->max_idle_timeout_local_req, in ch_on_transport_params()
1606 ch->max_idle_timeout_remote_req); in ch_on_transport_params()
1627 ch->rx_max_udp_payload_size = v; in ch_on_transport_params()
1644 ch->rx_active_conn_id_limit = v; in ch_on_transport_params()
1658 if (ch->is_server) { in ch_on_transport_params()
1668 if (!ossl_quic_srtm_add(ch->srtm, ch, ch->cur_remote_seq_num, in ch_on_transport_params()
1686 * RFC 9000 s. 18.2: "A server that chooses a zero-length in ch_on_transport_params()
1688 * Similarly, a server MUST NOT include a zero-length connection in ch_on_transport_params()
1693 if (ch->is_server) { in ch_on_transport_params()
1698 if (ch->cur_remote_dcid.id_len == 0) { in ch_on_transport_params()
1699 reason = "PREFERRED_ADDR provided for zero-length CID"; in ch_on_transport_params()
1709 reason = "zero-length CID in PREFERRED_ADDR"; in ch_on_transport_params()
1757 if (!ch->is_server) { in ch_on_transport_params()
1763 if (ch->doing_retry && !got_retry_scid) { in ch_on_transport_params()
1769 ch->got_remote_transport_params = 1; in ch_on_transport_params()
1777 &ch->init_dcid); in ch_on_transport_params()
1780 &ch->init_dcid); in ch_on_transport_params()
1783 &ch->retry_scid); in ch_on_transport_params()
1786 ossl_quic_txfc_get_cwm(&ch->conn_txfc)); in ch_on_transport_params()
1789 ch->rx_init_max_stream_data_bidi_local); in ch_on_transport_params()
1792 ch->rx_init_max_stream_data_bidi_remote); in ch_on_transport_params()
1795 ch->rx_init_max_stream_data_uni); in ch_on_transport_params()
1798 ch->max_local_streams_bidi); in ch_on_transport_params()
1801 ch->max_local_streams_uni); in ch_on_transport_params()
1803 QLOG_U64("ack_delay_exponent", ch->rx_ack_delay_exp); in ch_on_transport_params()
1805 QLOG_U64("max_ack_delay", ch->rx_max_ack_delay); in ch_on_transport_params()
1807 QLOG_U64("max_udp_payload_size", ch->rx_max_udp_payload_size); in ch_on_transport_params()
1811 QLOG_U64("active_connection_id_limit", ch->rx_active_conn_id_limit); in ch_on_transport_params()
1836 ossl_quic_stream_map_visit(&ch->qsm, do_update, ch); in ch_on_transport_params()
1839 if (ch->is_server && !ch_generate_transport_params(ch)) { in ch_on_transport_params()
1876 if (ch->odcid.id_len == 0) in ch_generate_transport_params()
1877 id_to_use = &ch->init_dcid; in ch_generate_transport_params()
1879 id_to_use = &ch->odcid; in ch_generate_transport_params()
1881 if (ch->local_transport_params != NULL || ch->got_local_transport_params) in ch_generate_transport_params()
1896 if (ch->is_server) { in ch_generate_transport_params()
1902 &ch->cur_local_cid)) in ch_generate_transport_params()
1904 if (ch->odcid.id_len != 0) in ch_generate_transport_params()
1907 &ch->init_dcid)) in ch_generate_transport_params()
1911 &ch->init_scid)) in ch_generate_transport_params()
1916 ch->max_idle_timeout_local_req)) in ch_generate_transport_params()
1927 if (ch->tx_max_ack_delay != QUIC_DEFAULT_MAX_ACK_DELAY in ch_generate_transport_params()
1929 ch->tx_max_ack_delay)) in ch_generate_transport_params()
1933 ossl_quic_rxfc_get_cwm(&ch->conn_rxfc))) in ch_generate_transport_params()
1938 ch->tx_init_max_stream_data_bidi_local)) in ch_generate_transport_params()
1942 ch->tx_init_max_stream_data_bidi_remote)) in ch_generate_transport_params()
1946 ch->tx_init_max_stream_data_uni)) in ch_generate_transport_params()
1950 … ossl_quic_rxfc_get_cwm(&ch->max_streams_bidi_rxfc))) in ch_generate_transport_params()
1954 … ossl_quic_rxfc_get_cwm(&ch->max_streams_uni_rxfc))) in ch_generate_transport_params()
1965 ch->local_transport_params = (unsigned char *)buf_mem->data; in ch_generate_transport_params()
1966 buf_mem->data = NULL; in ch_generate_transport_params()
1968 if (!ossl_quic_tls_set_transport_params(ch->qtls, ch->local_transport_params, in ch_generate_transport_params()
1976 if (ch->is_server) { in ch_generate_transport_params()
1977 QLOG_CID("original_destination_connection_id", &ch->init_dcid); in ch_generate_transport_params()
1978 QLOG_CID("initial_source_connection_id", &ch->cur_local_cid); in ch_generate_transport_params()
1982 QLOG_U64("max_idle_timeout", ch->max_idle_timeout); in ch_generate_transport_params()
1985 QLOG_U64("max_ack_delay", ch->tx_max_ack_delay); in ch_generate_transport_params()
1986 QLOG_U64("initial_max_data", ossl_quic_rxfc_get_cwm(&ch->conn_rxfc)); in ch_generate_transport_params()
1988 ch->tx_init_max_stream_data_bidi_local); in ch_generate_transport_params()
1990 ch->tx_init_max_stream_data_bidi_remote); in ch_generate_transport_params()
1992 ch->tx_init_max_stream_data_uni); in ch_generate_transport_params()
1994 ossl_quic_rxfc_get_cwm(&ch->max_streams_bidi_rxfc)); in ch_generate_transport_params()
1996 ossl_quic_rxfc_get_cwm(&ch->max_streams_uni_rxfc)); in ch_generate_transport_params()
2000 ch->got_local_transport_params = 1; in ch_generate_transport_params()
2011 * QUIC Channel: Ticker-Mutator
2017 * at least everything network I/O related. Best effort - not allowed to fail
2032 * - handle any packets the DEMUX has queued up for us; in ossl_quic_channel_subtick()
2033 * - handle any timer events which are due to fire (ACKM, etc.); in ossl_quic_channel_subtick()
2034 * - generate any packets which need to be sent; in ossl_quic_channel_subtick()
2035 * - determine the time at which we should next be ticked. in ossl_quic_channel_subtick()
2042 if (ch->state == QUIC_CHANNEL_STATE_IDLE in ossl_quic_channel_subtick()
2044 res->net_read_desired = 0; in ossl_quic_channel_subtick()
2045 res->net_write_desired = 0; in ossl_quic_channel_subtick()
2046 res->notify_other_threads = 0; in ossl_quic_channel_subtick()
2047 res->tick_deadline = ossl_time_infinite(); in ossl_quic_channel_subtick()
2058 if (ossl_time_compare(now, ch->terminate_deadline) >= 0) { in ossl_quic_channel_subtick()
2060 res->net_read_desired = 0; in ossl_quic_channel_subtick()
2061 res->net_write_desired = 0; in ossl_quic_channel_subtick()
2062 res->notify_other_threads = 1; in ossl_quic_channel_subtick()
2063 res->tick_deadline = ossl_time_infinite(); in ossl_quic_channel_subtick()
2068 if (!ch->port->engine->inhibit_tick) { in ossl_quic_channel_subtick()
2074 ch->did_tls_tick = 0; in ossl_quic_channel_subtick()
2075 ch->have_new_rx_secret = 0; in ossl_quic_channel_subtick()
2082 if (!ch->did_tls_tick) in ossl_quic_channel_subtick()
2092 } while (ch->have_new_rx_secret); in ossl_quic_channel_subtick()
2103 if (ossl_time_compare(now, ch->idle_deadline) >= 0) { in ossl_quic_channel_subtick()
2108 if (!ch->port->engine->inhibit_tick) in ossl_quic_channel_subtick()
2111 res->net_read_desired = 0; in ossl_quic_channel_subtick()
2112 res->net_write_desired = 0; in ossl_quic_channel_subtick()
2113 res->notify_other_threads = 1; in ossl_quic_channel_subtick()
2114 res->tick_deadline = ossl_time_infinite(); in ossl_quic_channel_subtick()
2118 if (!ch->port->engine->inhibit_tick) { in ossl_quic_channel_subtick()
2119 deadline = ossl_ackm_get_loss_detection_deadline(ch->ackm); in ossl_quic_channel_subtick()
2122 ossl_ackm_on_timeout(ch->ackm); in ossl_quic_channel_subtick()
2125 if (ossl_time_compare(now, ch->ping_deadline) >= 0) { in ossl_quic_channel_subtick()
2126 int pn_space = ossl_quic_enc_level_to_pn_space(ch->tx_enc_level); in ossl_quic_channel_subtick()
2128 ossl_quic_tx_packetiser_schedule_ack_eliciting(ch->txp, pn_space); in ossl_quic_channel_subtick()
2134 * busy-loop endlessly as the above deadline comparison condition in ossl_quic_channel_subtick()
2144 ossl_quic_stream_map_gc(&ch->qsm); in ossl_quic_channel_subtick()
2148 res->tick_deadline = ch_determine_next_tick_deadline(ch); in ossl_quic_channel_subtick()
2155 res->net_read_desired = !ossl_quic_channel_is_terminated(ch); in ossl_quic_channel_subtick()
2158 res->net_write_desired in ossl_quic_channel_subtick()
2160 && ossl_qtx_get_queue_len_datagrams(ch->qtx) > 0); in ossl_quic_channel_subtick()
2162 res->notify_other_threads = notify_other_threads; in ossl_quic_channel_subtick()
2174 ch->did_tls_tick = 1; in ch_tick_tls()
2175 ossl_quic_tls_tick(ch->qtls); in ch_tick_tls()
2177 if (ossl_quic_tls_get_error(ch->qtls, &error_code, &error_msg, in ch_tick_tls()
2204 if ((ch->el_discarded & (1U << enc_level)) != 0) in ch_rx_check_forged_pkt_limit()
2207 if (enc_level > ch->rx_enc_level) in ch_rx_check_forged_pkt_limit()
2210 l = ossl_qrx_get_max_forged_pkt_count(ch->qrx, enc_level); in ch_rx_check_forged_pkt_limit()
2215 if (ossl_qrx_get_cur_forged_pkt_count(ch->qrx) < limit) in ch_rx_check_forged_pkt_limit()
2228 if (!ch->is_server && !ch->have_sent_any_pkt) in ch_rx()
2236 assert(ch->qrx_pkt == NULL); in ch_rx()
2238 if (!ossl_qrx_read_pkt(ch->qrx, &ch->qrx_pkt)) in ch_rx()
2244 ch->txp, ch->qrx_pkt->hdr->len); in ch_rx()
2258 ossl_qrx_pkt_release(ch->qrx_pkt); in ch_rx()
2259 ch->qrx_pkt = NULL; in ch_rx()
2261 ch->have_sent_ack_eliciting_since_rx = 0; in ch_rx()
2271 * When in TERMINATING - CLOSING, generate a CONN_CLOSE frame whenever we in ch_rx()
2275 ch->conn_close_queued = 1; in ch_rx()
2287 return !memcmp(&a->s_in.sin_addr, in bio_addr_eq()
2288 &b->s_in.sin_addr, in bio_addr_eq()
2289 sizeof(a->s_in.sin_addr)) in bio_addr_eq()
2290 && a->s_in.sin_port == b->s_in.sin_port; in bio_addr_eq()
2293 return !memcmp(&a->s_in6.sin6_addr, in bio_addr_eq()
2294 &b->s_in6.sin6_addr, in bio_addr_eq()
2295 sizeof(a->s_in6.sin6_addr)) in bio_addr_eq()
2296 && a->s_in6.sin6_port == b->s_in6.sin6_port; in bio_addr_eq()
2305 /* Handles the packet currently in ch->qrx_pkt->hdr. */
2309 int old_have_processed_any_pkt = ch->have_processed_any_pkt; in ch_rx_handle_packet()
2314 assert(ch->qrx_pkt != NULL); in ch_rx_handle_packet()
2324 if (ossl_quic_pkt_type_is_encrypted(ch->qrx_pkt->hdr->type)) { in ch_rx_handle_packet()
2325 if (!ch->have_received_enc_pkt) { in ch_rx_handle_packet()
2326 ch->cur_remote_dcid = ch->init_scid = ch->qrx_pkt->hdr->src_conn_id; in ch_rx_handle_packet()
2327 ch->have_received_enc_pkt = 1; in ch_rx_handle_packet()
2333 ossl_quic_tx_packetiser_set_cur_dcid(ch->txp, &ch->init_scid); in ch_rx_handle_packet()
2336 enc_level = ossl_quic_pkt_type_to_enc_level(ch->qrx_pkt->hdr->type); in ch_rx_handle_packet()
2337 if ((ch->el_discarded & (1U << enc_level)) != 0) in ch_rx_handle_packet()
2352 if (!ch->is_server in ch_rx_handle_packet()
2353 && ch->qrx_pkt->peer != NULL in ch_rx_handle_packet()
2355 BIO_ADDR_family(&ch->cur_peer_addr) == AF_INET in ch_rx_handle_packet()
2357 || BIO_ADDR_family(&ch->cur_peer_addr) == AF_INET6 in ch_rx_handle_packet()
2360 && !bio_addr_eq(ch->qrx_pkt->peer, &ch->cur_peer_addr)) in ch_rx_handle_packet()
2363 if (!ch->is_server in ch_rx_handle_packet()
2364 && ch->have_received_enc_pkt in ch_rx_handle_packet()
2365 && ossl_quic_pkt_type_has_scid(ch->qrx_pkt->hdr->type)) { in ch_rx_handle_packet()
2371 if (!ossl_quic_conn_id_eq(&ch->qrx_pkt->hdr->src_conn_id, in ch_rx_handle_packet()
2372 &ch->init_scid)) in ch_rx_handle_packet()
2376 if (ossl_quic_pkt_type_has_version(ch->qrx_pkt->hdr->type) in ch_rx_handle_packet()
2377 && ch->qrx_pkt->hdr->version != QUIC_VERSION_1) in ch_rx_handle_packet()
2385 if (ch->qrx_pkt->hdr->type == QUIC_PKT_TYPE_VERSION_NEG) { in ch_rx_handle_packet()
2391 if (ch->qrx_pkt->hdr->version != 0) in ch_rx_handle_packet()
2416 ch->have_processed_any_pkt = 1; in ch_rx_handle_packet()
2422 * this array, bounded by the hdr->len field in ch_rx_handle_packet()
2426 if (!PACKET_buf_init(&vpkt, ch->qrx_pkt->hdr->data, in ch_rx_handle_packet()
2427 ch->qrx_pkt->hdr->len)) in ch_rx_handle_packet()
2443 ossl_quic_tx_packetiser_set_protocol_version(ch->txp, QUIC_VERSION_1); in ch_rx_handle_packet()
2465 ch->have_processed_any_pkt = 1; in ch_rx_handle_packet()
2469 * non-zero value for [the reserved bits] after removing both packet and in ch_rx_handle_packet()
2472 if (ossl_quic_pkt_type_is_encrypted(ch->qrx_pkt->hdr->type) in ch_rx_handle_packet()
2473 && ch->qrx_pkt->hdr->reserved != 0) { in ch_rx_handle_packet()
2479 iovec.buf = ch->qrx_pkt->hdr->data; in ch_rx_handle_packet()
2480 iovec.buf_len = ch->qrx_pkt->hdr->len; in ch_rx_handle_packet()
2481 ossl_qlog_event_transport_packet_received(ch_get_qlog(ch), ch->qrx_pkt->hdr, in ch_rx_handle_packet()
2482 ch->qrx_pkt->pn, &iovec, 1, in ch_rx_handle_packet()
2483 ch->qrx_pkt->datagram_id); in ch_rx_handle_packet()
2486 switch (ch->qrx_pkt->hdr->type) { in ch_rx_handle_packet()
2488 if (ch->doing_retry || ch->is_server) in ch_rx_handle_packet()
2500 if (ch->have_received_enc_pkt) in ch_rx_handle_packet()
2503 if (ch->qrx_pkt->hdr->len <= QUIC_RETRY_INTEGRITY_TAG_LEN) in ch_rx_handle_packet()
2504 /* Packets with zero-length Retry Tokens are invalid. */ in ch_rx_handle_packet()
2516 if (!ossl_quic_validate_retry_integrity_tag(ch->port->engine->libctx, in ch_rx_handle_packet()
2517 ch->port->engine->propq, in ch_rx_handle_packet()
2518 ch->qrx_pkt->hdr, in ch_rx_handle_packet()
2519 &ch->init_dcid)) in ch_rx_handle_packet()
2523 if (!ch_retry(ch, ch->qrx_pkt->hdr->data, in ch_rx_handle_packet()
2524 ch->qrx_pkt->hdr->len - QUIC_RETRY_INTEGRITY_TAG_LEN, in ch_rx_handle_packet()
2525 &ch->qrx_pkt->hdr->src_conn_id, old_have_processed_any_pkt)) in ch_rx_handle_packet()
2531 if (!ch->is_server) in ch_rx_handle_packet()
2532 /* Clients should never receive 0-RTT packets. */ in ch_rx_handle_packet()
2536 * TODO(QUIC 0RTT): Implement 0-RTT on the server side. We currently in ch_rx_handle_packet()
2537 * do not need to implement this as a client can only do 0-RTT if we in ch_rx_handle_packet()
2545 if (ch->is_server && ch->qrx_pkt->hdr->type == QUIC_PKT_TYPE_HANDSHAKE) in ch_rx_handle_packet()
2552 if (ch->rxku_in_progress in ch_rx_handle_packet()
2553 && ch->qrx_pkt->hdr->type == QUIC_PKT_TYPE_1RTT in ch_rx_handle_packet()
2554 && ch->qrx_pkt->pn >= ch->rxku_trigger_pn in ch_rx_handle_packet()
2555 && ch->qrx_pkt->key_epoch < ossl_qrx_get_key_epoch(ch->qrx)) { in ch_rx_handle_packet()
2569 if (!ch->is_server in ch_rx_handle_packet()
2570 && ch->qrx_pkt->hdr->type == QUIC_PKT_TYPE_INITIAL in ch_rx_handle_packet()
2571 && ch->qrx_pkt->hdr->token_len > 0) { in ch_rx_handle_packet()
2574 * non-zero Token Length field MUST either discard the packet or in ch_rx_handle_packet()
2595 ossl_quic_handle_frames(ch, ch->qrx_pkt); /* best effort */ in ch_rx_handle_packet()
2597 if (ch->did_crypto_frame) in ch_rx_handle_packet()
2608 ch_rx_handle_version_neg(ch, ch->qrx_pkt); in ch_rx_handle_packet()
2630 if (!PACKET_buf_init(&vpkt, pkt->hdr->data, pkt->hdr->len)) in ch_rx_handle_version_neg()
2687 if (!ch->conn_close_queued) in ch_tx()
2690 ch->conn_close_queued = 0; in ch_tx()
2696 ch->rxku_pending_confirm_done = 0; in ch_tx()
2707 res = ossl_quic_tx_packetiser_generate(ch->txp, &status); in ch_tx()
2709 ch->have_sent_any_pkt = 1; /* Packet(s) were sent */ in ch_tx()
2710 ch->port->have_sent_any_pkt = 1; in ch_tx()
2714 * sending an ack-eliciting packet if no other ack-eliciting packets in ch_tx()
2718 && !ch->have_sent_ack_eliciting_since_rx) { in ch_tx()
2720 ch->have_sent_ack_eliciting_since_rx = 1; in ch_tx()
2723 if (!ch->is_server && status.sent_handshake) in ch_tx()
2730 if (ch->rxku_pending_confirm_done) in ch_tx()
2731 ch->rxku_pending_confirm = 0; in ch_tx()
2738 * One case where TXP can fail is if we reach a TX PN of 2**62 - 1. in ch_tx()
2757 switch (ossl_qtx_flush_net(ch->qtx)) { in ch_tx()
2766 ossl_quic_port_raise_net_error(ch->port, ch); in ch_tx()
2775 if (ossl_qtx_get_queue_len_datagrams(ch->qtx) > 0) in ch_tx()
2790 deadline = ossl_ackm_get_loss_detection_deadline(ch->ackm); in ch_determine_next_tick_deadline()
2799 if (ossl_qtx_is_enc_level_provisioned(ch->qtx, i)) { in ch_determine_next_tick_deadline()
2801 ossl_ackm_get_ack_deadline(ch->ackm, in ch_determine_next_tick_deadline()
2807 * When do we need to send an ACK-eliciting packet to reset the idle in ch_determine_next_tick_deadline()
2810 if (!ossl_time_is_infinite(ch->ping_deadline)) in ch_determine_next_tick_deadline()
2811 deadline = ossl_time_min(deadline, ch->ping_deadline); in ch_determine_next_tick_deadline()
2815 ossl_quic_tx_packetiser_get_deadline(ch->txp)); in ch_determine_next_tick_deadline()
2820 ch->terminate_deadline); in ch_determine_next_tick_deadline()
2821 else if (!ossl_time_is_infinite(ch->idle_deadline)) in ch_determine_next_tick_deadline()
2823 ch->idle_deadline); in ch_determine_next_tick_deadline()
2826 if (ch->rxku_in_progress) in ch_determine_next_tick_deadline()
2827 deadline = ossl_time_min(deadline, ch->rxku_update_end_deadline); in ch_determine_next_tick_deadline()
2838 * Record a state transition. This is not necessarily a change to ch->state but
2843 uint32_t old_state = ch->state; in ch_record_state_transition()
2845 ch->state = new_state; in ch_record_state_transition()
2850 ch->handshake_complete, in ch_record_state_transition()
2851 ch->handshake_confirmed); in ch_record_state_transition()
2864 if (ch->is_server) in ossl_quic_channel_start()
2871 if (ch->state != QUIC_CHANNEL_STATE_IDLE) in ossl_quic_channel_start()
2876 if (!ossl_quic_tx_packetiser_set_peer(ch->txp, &ch->cur_peer_addr)) in ossl_quic_channel_start()
2882 if (!ch->is_server in ossl_quic_channel_start()
2883 && ossl_quic_get_peer_token(ch->port->channel_ctx, in ossl_quic_channel_start()
2884 &ch->cur_peer_addr, in ossl_quic_channel_start()
2886 && !ossl_quic_tx_packetiser_set_initial_token(ch->txp, token->token, in ossl_quic_channel_start()
2887 token->token_len, in ossl_quic_channel_start()
2893 if (!ossl_quic_provide_initial_secret(ch->port->engine->libctx, in ossl_quic_channel_start()
2894 ch->port->engine->propq, in ossl_quic_channel_start()
2895 &ch->init_dcid, in ossl_quic_channel_start()
2896 ch->is_server, in ossl_quic_channel_start()
2897 ch->qrx, ch->qtx)) in ossl_quic_channel_start()
2905 if (!ch->is_server && !ch->got_local_transport_params in ossl_quic_channel_start()
2911 ch->doing_proactive_ver_neg = 0; /* not currently supported */ in ossl_quic_channel_start()
2914 &ch->init_dcid); in ossl_quic_channel_start()
2920 ossl_quic_reactor_tick(ossl_quic_port_get0_reactor(ch->port), 0); /* best effort */ in ossl_quic_channel_start()
2946 * ch_restart - Restarts the QUIC channel by simulating loss of the initial
2960 return ossl_ackm_mark_packet_pseudo_lost(ch->ackm, QUIC_PN_SPACE_INITIAL, in ch_restart()
2978 if (ossl_quic_conn_id_eq(&ch->init_dcid, retry_scid)) in ch_retry()
2982 if (!ossl_quic_tx_packetiser_set_cur_dcid(ch->txp, retry_scid)) in ch_retry()
2992 if (!ossl_quic_tx_packetiser_set_initial_token(ch->txp, buf, in ch_retry()
3005 ch->retry_scid = *retry_scid; in ch_retry()
3006 ch->doing_retry = 1; in ch_retry()
3025 if (!ossl_ackm_mark_packet_pseudo_lost(ch->ackm, QUIC_PN_SPACE_INITIAL, in ch_retry()
3033 if (!ossl_quic_provide_initial_secret(ch->port->engine->libctx, in ch_retry()
3034 ch->port->engine->propq, in ch_retry()
3035 &ch->retry_scid, in ch_retry()
3037 ch->qrx, ch->qtx)) in ch_retry()
3050 if ((ch->el_discarded & (1U << enc_level)) != 0) in ch_discard_el()
3055 ossl_quic_tx_packetiser_discard_enc_level(ch->txp, enc_level); in ch_discard_el()
3056 ossl_qrx_discard_enc_level(ch->qrx, enc_level); in ch_discard_el()
3057 ossl_qtx_discard_enc_level(ch->qtx, enc_level); in ch_discard_el()
3062 ossl_ackm_on_pkt_space_discarded(ch->ackm, pn_space); in ch_discard_el()
3065 if (!ossl_assert(ch->crypto_send[pn_space] != NULL) in ch_discard_el()
3066 || !ossl_assert(ch->crypto_recv[pn_space] != NULL)) in ch_discard_el()
3070 ossl_quic_sstream_free(ch->crypto_send[pn_space]); in ch_discard_el()
3071 ch->crypto_send[pn_space] = NULL; in ch_discard_el()
3073 ossl_quic_rstream_free(ch->crypto_recv[pn_space]); in ch_discard_el()
3074 ch->crypto_recv[pn_space] = NULL; in ch_discard_el()
3077 ch->el_discarded |= (1U << enc_level); in ch_discard_el()
3084 if (ch->handshake_confirmed) in ossl_quic_channel_on_handshake_confirmed()
3087 if (!ch->handshake_complete) { in ossl_quic_channel_on_handshake_confirmed()
3100 ch->handshake_confirmed = 1; in ossl_quic_channel_on_handshake_confirmed()
3101 ch_record_state_transition(ch, ch->state); in ossl_quic_channel_on_handshake_confirmed()
3102 ossl_ackm_on_handshake_confirmed(ch->ackm); in ossl_quic_channel_on_handshake_confirmed()
3109 * - If the connection is still IDLE we can go straight to TERMINATED;
3111 * - If we are already TERMINATED this is a no-op.
3113 * - If we are TERMINATING - CLOSING and we have now got a CONNECTION_CLOSE
3114 * from the peer (tcause->remote == 1), we move to TERMINATING - DRAINING.
3116 * - If we are TERMINATING - DRAINING, we remain here until the terminating
3119 * - Otherwise, we are in ACTIVE and move to TERMINATING - CLOSING.
3124 * TERMINATING - DRAINING.
3154 dst->error_code = src->error_code; in copy_tcause()
3155 dst->frame_type = src->frame_type; in copy_tcause()
3156 dst->app = src->app; in copy_tcause()
3157 dst->remote = src->remote; in copy_tcause()
3159 dst->reason = NULL; in copy_tcause()
3160 dst->reason_len = 0; in copy_tcause()
3162 if (src->reason != NULL && src->reason_len > 0) { in copy_tcause()
3163 size_t l = src->reason_len; in copy_tcause()
3167 --l; in copy_tcause()
3170 * If this fails, dst->reason becomes NULL and we simply do not use a in copy_tcause()
3173 dst->reason = r = OPENSSL_memdup(src->reason, l + 1); in copy_tcause()
3178 dst->reason_len = l; in copy_tcause()
3187 if (!ch->have_sent_any_pkt) in ch_start_terminating()
3190 switch (ch->state) { in ch_start_terminating()
3193 copy_tcause(&ch->terminate_cause, tcause); in ch_start_terminating()
3198 copy_tcause(&ch->terminate_cause, tcause); in ch_start_terminating()
3203 ch_record_state_transition(ch, tcause->remote in ch_start_terminating()
3209 * the current PTO interval as defined in [QUIC-RECOVERY]. in ch_start_terminating()
3211 ch->terminate_deadline in ch_start_terminating()
3213 ossl_time_multiply(ossl_ackm_get_pto_duration(ch->ackm), in ch_start_terminating()
3216 if (!tcause->remote) { in ch_start_terminating()
3220 f.error_code = ch->terminate_cause.error_code; in ch_start_terminating()
3221 f.frame_type = ch->terminate_cause.frame_type; in ch_start_terminating()
3222 f.is_app = ch->terminate_cause.app; in ch_start_terminating()
3223 f.reason = (char *)ch->terminate_cause.reason; in ch_start_terminating()
3224 f.reason_len = ch->terminate_cause.reason_len; in ch_start_terminating()
3225 ossl_quic_tx_packetiser_schedule_conn_close(ch->txp, &f); in ch_start_terminating()
3233 ch->conn_close_queued = 1; in ch_start_terminating()
3243 else if (tcause->remote) in ch_start_terminating()
3256 * Other than in the force-immediate case, we remain here until the in ch_start_terminating()
3265 /* No-op. */ in ch_start_terminating()
3280 tcause.app = f->is_app; in ossl_quic_channel_on_remote_conn_close()
3281 tcause.error_code = f->error_code; in ossl_quic_channel_on_remote_conn_close()
3282 tcause.frame_type = f->frame_type; in ossl_quic_channel_on_remote_conn_close()
3283 tcause.reason = f->reason; in ossl_quic_channel_on_remote_conn_close()
3284 tcause.reason_len = f->reason_len; in ossl_quic_channel_on_remote_conn_close()
3299 ossl_quic_srtm_remove(ch->srtm, ch, seq_num); in ch_enqueue_retire_conn_id()
3316 if (ossl_quic_cfq_add_frame(ch->cfq, 1, QUIC_PN_SPACE_APP, in ch_enqueue_retire_conn_id()
3318 (unsigned char *)buf_mem->data, l, in ch_enqueue_retire_conn_id()
3322 buf_mem->data = NULL; in ch_enqueue_retire_conn_id()
3338 uint64_t new_remote_seq_num = ch->cur_remote_seq_num; in ossl_quic_channel_on_new_conn_id()
3339 uint64_t new_retire_prior_to = ch->cur_retire_prior_to; in ossl_quic_channel_on_new_conn_id()
3345 if (ch->cur_remote_dcid.id_len == 0) { in ossl_quic_channel_on_new_conn_id()
3355 if (f->seq_num > new_remote_seq_num) in ossl_quic_channel_on_new_conn_id()
3356 new_remote_seq_num = f->seq_num; in ossl_quic_channel_on_new_conn_id()
3357 if (f->retire_prior_to > new_retire_prior_to) in ossl_quic_channel_on_new_conn_id()
3358 new_retire_prior_to = f->retire_prior_to; in ossl_quic_channel_on_new_conn_id()
3361 * RFC 9000-5.1.1: An endpoint MUST NOT provide more connection IDs in ossl_quic_channel_on_new_conn_id()
3370 if (new_remote_seq_num - new_retire_prior_to > 1) { in ossl_quic_channel_on_new_conn_id()
3379 * RFC 9000-5.1.1: An endpoint MAY send connection IDs that temporarily in ossl_quic_channel_on_new_conn_id()
3384 * RFC 9000-5.1.2: An endpoint SHOULD allow for sending and tracking in ossl_quic_channel_on_new_conn_id()
3393 if (new_retire_prior_to - ch->cur_retire_prior_to > 10) { in ossl_quic_channel_on_new_conn_id()
3402 if (new_remote_seq_num > ch->cur_remote_seq_num) { in ossl_quic_channel_on_new_conn_id()
3404 if (!ossl_quic_srtm_add(ch->srtm, ch, new_remote_seq_num, in ossl_quic_channel_on_new_conn_id()
3405 &f->stateless_reset)) { in ossl_quic_channel_on_new_conn_id()
3413 ch->cur_remote_seq_num = new_remote_seq_num; in ossl_quic_channel_on_new_conn_id()
3414 ch->cur_remote_dcid = f->conn_id; in ossl_quic_channel_on_new_conn_id()
3415 ossl_quic_tx_packetiser_set_cur_dcid(ch->txp, &ch->cur_remote_dcid); in ossl_quic_channel_on_new_conn_id()
3419 * RFC 9000-5.1.2: Upon receipt of an increased Retire Prior To in ossl_quic_channel_on_new_conn_id()
3438 while (new_retire_prior_to > ch->cur_retire_prior_to) { in ossl_quic_channel_on_new_conn_id()
3439 if (!ch_enqueue_retire_conn_id(ch, ch->cur_retire_prior_to)) in ossl_quic_channel_on_new_conn_id()
3441 ++ch->cur_retire_prior_to; in ossl_quic_channel_on_new_conn_id()
3447 if (ch->err_state == NULL) in ch_save_err_state()
3448 ch->err_state = OSSL_ERR_STATE_new(); in ch_save_err_state()
3450 if (ch->err_state == NULL) in ch_save_err_state()
3453 OSSL_ERR_STATE_save(ch->err_state); in ch_save_err_state()
3458 ossl_qrx_inject_urxe(ch->qrx, e); in ossl_quic_channel_inject()
3463 ossl_qrx_inject_pkt(ch->qrx, qpkt); in ossl_quic_channel_inject_pkt()
3479 if (ch->net_error) in ossl_quic_channel_raise_net_error()
3482 ch->net_error = 1; in ossl_quic_channel_raise_net_error()
3497 return ch->net_error; in ossl_quic_channel_net_error()
3505 if (!ossl_quic_port_is_running(ch->port)) in ossl_quic_channel_restore_err_state()
3506 ossl_quic_port_restore_err_state(ch->port); in ossl_quic_channel_restore_err_state()
3508 OSSL_ERR_STATE_restore(ch->err_state); in ossl_quic_channel_restore_err_state()
3528 if (ch->protocol_error) in ossl_quic_channel_raise_protocol_error_loc()
3579 ch->protocol_error = 1; in ossl_quic_channel_raise_protocol_error_loc()
3601 if (ch->max_idle_timeout == 0) in ch_get_effective_idle_timeout_duration()
3612 pto = ossl_ackm_get_pto_duration(ch->ackm); in ch_get_effective_idle_timeout_duration()
3613 return ossl_time_max(ossl_ms2time(ch->max_idle_timeout), in ch_get_effective_idle_timeout_duration()
3623 ch->idle_deadline = ossl_time_add(get_time(ch), in ch_update_idle()
3629 * we don't have any other ACK-eliciting frames to send.
3637 ch->ping_deadline = ossl_time_infinite(); in ch_update_ping_deadline()
3649 ch->ping_deadline = ossl_time_add(get_time(ch), max_span); in ch_update_ping_deadline()
3660 ch->terminate_cause.app = 0; in ch_on_idle_timeout()
3661 ch->terminate_cause.error_code = OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT; in ch_on_idle_timeout()
3662 ch->terminate_cause.frame_type = 0; in ch_on_idle_timeout()
3677 * @param peer_scid Peer-specified source connection ID.
3678 * @param peer_dcid Peer-specified destination connection ID.
3679 * @param peer_odcid Peer-specified original destination connection ID
3689 if (!BIO_ADDR_copy(&ch->cur_peer_addr, peer)) in ch_on_new_conn_common()
3692 ch->init_dcid = *peer_dcid; in ch_on_new_conn_common()
3693 ch->cur_remote_dcid = *peer_scid; in ch_on_new_conn_common()
3694 ch->odcid.id_len = 0; in ch_on_new_conn_common()
3697 ch->odcid = *peer_odcid; in ch_on_new_conn_common()
3700 if (!ossl_quic_tx_packetiser_set_peer(ch->txp, &ch->cur_peer_addr)) in ch_on_new_conn_common()
3704 if (!ossl_quic_tx_packetiser_set_cur_dcid(ch->txp, &ch->cur_remote_dcid)) in ch_on_new_conn_common()
3707 if (!ossl_quic_tx_packetiser_set_cur_scid(ch->txp, &ch->cur_local_cid)) in ch_on_new_conn_common()
3711 ossl_qtx_set_qlog_cb(ch->qtx, ch_get_qlog_cb, ch); in ch_on_new_conn_common()
3712 ossl_quic_tx_packetiser_set_qlog_cb(ch->txp, ch_get_qlog_cb, ch); in ch_on_new_conn_common()
3718 if (!ossl_quic_provide_initial_secret(ch->port->engine->libctx, in ch_on_new_conn_common()
3719 ch->port->engine->propq, in ch_on_new_conn_common()
3720 &ch->init_dcid, in ch_on_new_conn_common()
3722 NULL, ch->qtx)) in ch_on_new_conn_common()
3726 if (!ossl_quic_lcidm_enrol_odcid(ch->lcidm, ch, peer_odcid == NULL ? in ch_on_new_conn_common()
3727 &ch->init_dcid : in ch_on_new_conn_common()
3733 ch->doing_proactive_ver_neg = 0; /* not currently supported */ in ch_on_new_conn_common()
3742 if (!ossl_assert(ch->state == QUIC_CHANNEL_STATE_IDLE && ch->is_server)) in ossl_quic_channel_on_new_conn()
3746 if (!ossl_quic_lcidm_generate_initial(ch->lcidm, ch, &ch->cur_local_cid)) in ossl_quic_channel_on_new_conn()
3783 if (!ossl_assert(ch->state == QUIC_CHANNEL_STATE_IDLE && ch->is_server)) in ossl_quic_bind_channel()
3786 ch->cur_local_cid = *peer_dcid; in ossl_quic_bind_channel()
3787 if (!ossl_quic_lcidm_bind_channel(ch->lcidm, ch, peer_dcid)) in ossl_quic_bind_channel()
3799 return ch->tls; in ossl_quic_channel_get0_ssl()
3807 int local_init = (ch->is_server == server_init); in ch_init_new_stream()
3811 if ((qs->sstream = ossl_quic_sstream_new(INIT_APP_BUF_LEN)) == NULL) in ch_init_new_stream()
3815 if ((qs->rstream = ossl_quic_rstream_new(NULL, NULL, 0)) == NULL) in ch_init_new_stream()
3819 if (!ossl_quic_txfc_init(&qs->txfc, &ch->conn_txfc)) in ch_init_new_stream()
3822 if (ch->got_remote_transport_params) { in ch_init_new_stream()
3832 cwm = ch->rx_init_max_stream_data_uni; in ch_init_new_stream()
3834 cwm = ch->rx_init_max_stream_data_bidi_local; in ch_init_new_stream()
3836 cwm = ch->rx_init_max_stream_data_bidi_remote; in ch_init_new_stream()
3838 ossl_quic_txfc_bump_cwm(&qs->txfc, cwm); in ch_init_new_stream()
3846 rxfc_wnd = ch->tx_init_max_stream_data_uni; in ch_init_new_stream()
3848 rxfc_wnd = ch->tx_init_max_stream_data_bidi_local; in ch_init_new_stream()
3850 rxfc_wnd = ch->tx_init_max_stream_data_bidi_remote; in ch_init_new_stream()
3852 if (!ossl_quic_rxfc_init(&qs->rxfc, &ch->conn_rxfc, in ch_init_new_stream()
3861 ossl_quic_sstream_free(qs->sstream); in ch_init_new_stream()
3862 qs->sstream = NULL; in ch_init_new_stream()
3863 ossl_quic_rstream_free(qs->rstream); in ch_init_new_stream()
3864 qs->rstream = NULL; in ch_init_new_stream()
3871 return is_uni ? &ch->next_local_stream_ordinal_uni in ch_get_local_stream_next_ordinal_ptr()
3872 : &ch->next_local_stream_ordinal_bidi; in ch_get_local_stream_next_ordinal_ptr()
3878 return is_uni ? &ch->max_local_streams_uni in ch_get_local_stream_max_ptr()
3879 : &ch->max_local_streams_bidi; in ch_get_local_stream_max_ptr()
3885 return is_uni ? &ch->max_streams_uni_rxfc in ch_get_remote_stream_count_rxfc()
3886 : &ch->max_streams_bidi_rxfc; in ch_get_remote_stream_count_rxfc()
3894 return ossl_quic_stream_map_is_local_allowed_by_stream_limit(&ch->qsm, in ossl_quic_channel_is_new_local_stream_admissible()
3908 return *p_max - *p_next_ordinal; in ossl_quic_channel_get_local_stream_count_avail()
3924 type = ch->is_server ? QUIC_STREAM_INITIATOR_SERVER in ossl_quic_channel_new_stream_local()
3939 if ((qs = ossl_quic_stream_map_alloc(&ch->qsm, stream_id, type)) == NULL) in ossl_quic_channel_new_stream_local()
3942 /* Locally-initiated stream, so we always want a send buffer. */ in ossl_quic_channel_new_stream_local()
3950 ossl_quic_stream_map_release(&ch->qsm, qs); in ossl_quic_channel_new_stream_local()
3961 peer_role = ch->is_server in ossl_quic_channel_new_stream_remote()
3970 qs = ossl_quic_stream_map_alloc(&ch->qsm, stream_id, in ossl_quic_channel_new_stream_remote()
3979 if (ch->incoming_stream_auto_reject) in ossl_quic_channel_new_stream_remote()
3982 ossl_quic_stream_map_push_accept_queue(&ch->qsm, qs); in ossl_quic_channel_new_stream_remote()
3987 ossl_quic_stream_map_release(&ch->qsm, qs); in ossl_quic_channel_new_stream_remote()
3995 ch->incoming_stream_auto_reject = (enable != 0); in ossl_quic_channel_set_incoming_stream_auto_reject()
3996 ch->incoming_stream_auto_reject_aec = aec; in ossl_quic_channel_set_incoming_stream_auto_reject()
4001 ossl_quic_stream_map_stop_sending_recv_part(&ch->qsm, qs, in ossl_quic_channel_reject_stream()
4002 ch->incoming_stream_auto_reject_aec); in ossl_quic_channel_reject_stream()
4004 ossl_quic_stream_map_reset_stream_send_part(&ch->qsm, qs, in ossl_quic_channel_reject_stream()
4005 ch->incoming_stream_auto_reject_aec); in ossl_quic_channel_reject_stream()
4006 qs->deleted = 1; in ossl_quic_channel_reject_stream()
4008 ossl_quic_stream_map_update_state(&ch->qsm, qs); in ossl_quic_channel_reject_stream()
4016 if (!ossl_quic_lcidm_debug_remove(ch->lcidm, &ch->cur_local_cid)) in ossl_quic_channel_replace_local_cid()
4018 ch->cur_local_cid = *conn_id; in ossl_quic_channel_replace_local_cid()
4020 if (!ossl_quic_tx_packetiser_set_cur_scid(ch->txp, &ch->cur_local_cid)) in ossl_quic_channel_replace_local_cid()
4023 if (!ossl_quic_lcidm_debug_add(ch->lcidm, ch, &ch->cur_local_cid, in ossl_quic_channel_replace_local_cid()
4033 ch->msg_callback = msg_callback; in ossl_quic_channel_set_msg_callback()
4034 ch->msg_callback_ssl = msg_callback_ssl; in ossl_quic_channel_set_msg_callback()
4035 ossl_qtx_set_msg_callback(ch->qtx, msg_callback, msg_callback_ssl); in ossl_quic_channel_set_msg_callback()
4036 ossl_quic_tx_packetiser_set_msg_callback(ch->txp, msg_callback, in ossl_quic_channel_set_msg_callback()
4042 if (ch->is_tserver_ch == 0) in ossl_quic_channel_set_msg_callback()
4043 ossl_qrx_set_msg_callback(ch->qrx, msg_callback, msg_callback_ssl); in ossl_quic_channel_set_msg_callback()
4049 ch->msg_callback_arg = msg_callback_arg; in ossl_quic_channel_set_msg_callback_arg()
4050 ossl_qtx_set_msg_callback_arg(ch->qtx, msg_callback_arg); in ossl_quic_channel_set_msg_callback_arg()
4051 ossl_quic_tx_packetiser_set_msg_callback_arg(ch->txp, msg_callback_arg); in ossl_quic_channel_set_msg_callback_arg()
4057 if (ch->is_tserver_ch == 0) in ossl_quic_channel_set_msg_callback_arg()
4058 ossl_qrx_set_msg_callback_arg(ch->qrx, msg_callback_arg); in ossl_quic_channel_set_msg_callback_arg()
4064 ch->txku_threshold_override = tx_pkt_threshold; in ossl_quic_channel_set_txku_threshold_override()
4069 return ossl_qtx_get_key_epoch(ch->qtx); in ossl_quic_channel_get_tx_key_epoch()
4074 return ossl_qrx_get_key_epoch(ch->qrx); in ossl_quic_channel_get_rx_key_epoch()
4082 ch->ku_locally_initiated = 1; in ossl_quic_channel_trigger_txku()
4089 int pn_space = ossl_quic_enc_level_to_pn_space(ch->tx_enc_level); in ossl_quic_channel_ping()
4091 ossl_quic_tx_packetiser_schedule_ack_eliciting(ch->txp, pn_space); in ossl_quic_channel_ping()
4098 return ch->diag_num_rx_ack; in ossl_quic_channel_get_diag_num_rx_ack()
4103 *cid = ch->cur_local_cid; in ossl_quic_channel_get_diag_local_cid()
4108 return ch->got_local_transport_params; in ossl_quic_channel_have_generated_transport_params()
4113 ch->max_idle_timeout_local_req = ms; in ossl_quic_channel_set_max_idle_timeout_request()
4117 return ch->max_idle_timeout_local_req; in ossl_quic_channel_get_max_idle_timeout_request()
4122 return ch->max_idle_timeout_remote_req; in ossl_quic_channel_get_max_idle_timeout_peer_request()
4127 return ch->max_idle_timeout; in ossl_quic_channel_get_max_idle_timeout_actual()