Nginx's stream support transparent.

Also support kernel network stack while set
`proxy_kernel_network_stack on`.
This commit is contained in:
fengbojiang 2024-10-15 14:49:21 +08:00
parent da5549fcf6
commit 783fc174b2
1 changed files with 29 additions and 11 deletions

View File

@ -353,10 +353,20 @@ failed:
#if (NGX_HAVE_TRANSPARENT_PROXY) #if (NGX_HAVE_TRANSPARENT_PROXY)
#if (NGX_HAVE_FSTACK)
extern int is_fstack_fd(int sockfd);
#ifndef IP_BINDANY
#define IP_BINDANY 24
#endif
#endif
static ngx_int_t static ngx_int_t
ngx_event_connect_set_transparent(ngx_peer_connection_t *pc, ngx_socket_t s) ngx_event_connect_set_transparent(ngx_peer_connection_t *pc, ngx_socket_t s)
{ {
int value; int value;
#if defined(NGX_HAVE_FSTACK)
int optname;
#endif
value = 1; value = 1;
@ -376,8 +386,26 @@ ngx_event_connect_set_transparent(ngx_peer_connection_t *pc, ngx_socket_t s)
case AF_INET: case AF_INET:
#if defined(IP_TRANSPARENT) #if defined(NGX_HAVE_FSTACK)
/****
FreeBSD define IP_BINDANY in freebsd/netinet/in.h
Fstack should only support IP_BINDANY.
****/
if(is_fstack_fd(s)){
optname = IP_BINDANY;
} else {
optname = IP_TRANSPARENT;
}
if (setsockopt(s, IPPROTO_IP, optname,
(const void *) &value, sizeof(int)) == -1)
{
ngx_log_error(NGX_LOG_ALERT, pc->log, ngx_socket_errno,
"setsockopt(IP_BINDANY/IP_TRANSPARENT) failed");
return NGX_ERROR;
}
#elif defined(IP_TRANSPARENT)
if (setsockopt(s, IPPROTO_IP, IP_TRANSPARENT, if (setsockopt(s, IPPROTO_IP, IP_TRANSPARENT,
(const void *) &value, sizeof(int)) == -1) (const void *) &value, sizeof(int)) == -1)
{ {
@ -386,16 +414,6 @@ ngx_event_connect_set_transparent(ngx_peer_connection_t *pc, ngx_socket_t s)
return NGX_ERROR; return NGX_ERROR;
} }
#elif defined(IP_BINDANY)
if (setsockopt(s, IPPROTO_IP, IP_BINDANY,
(const void *) &value, sizeof(int)) == -1)
{
ngx_log_error(NGX_LOG_ALERT, pc->log, ngx_socket_errno,
"setsockopt(IP_BINDANY) failed");
return NGX_ERROR;
}
#endif #endif
break; break;