curl/lib
Kamil Dudka 68d2830ee9 nss: prevent NSS from crashing on client auth hook failure
Although it is not explicitly stated in the documentation, NSS uses
*pRetCert and *pRetKey even if the client authentication hook returns
a failure.  Namely, if we destroy *pRetCert without clearing *pRetCert
afterwards, NSS destroys the certificate once again, which causes a
double free.

Reported by: Bob Relyea
2012-12-03 13:34:36 +01:00
..
.gitignore Removed libcurl.imp from Makefile.am. 2012-07-11 17:40:09 +02:00
amigaos.c curl tool: use configuration files from lib directory 2012-04-06 23:37:05 +02:00
amigaos.h curl tool: use configuration files from lib directory 2012-04-06 23:37:05 +02:00
arpa_telnet.h TELNET: improved treatment of options 2011-11-25 10:46:49 +01:00
asyn-ares.c asyn-ares: restore working with c-ares < 1.6.1 2012-10-23 23:06:38 +02:00
asyn-thread.c win32-threaded-resolver: stop using a dummy socket 2012-01-04 23:16:30 +01:00
asyn.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
axtls.c SSL: Several SSL-backend related fixes 2012-11-08 22:23:12 +01:00
axtls.h
base64.c fix several compiler warnings 2012-03-22 04:54:04 +01:00
checksrc.pl checksrc: detect "}else" uses as well 2011-09-07 22:45:43 +02:00
CMakeLists.txt
config-amigaos.h curl tool: use configuration files from lib directory 2012-04-06 23:37:05 +02:00
config-dos.h
config-mac.h curl tool: use configuration files from lib directory 2012-04-06 23:37:05 +02:00
config-os400.h build adjustments: CURL_HIDDEN_SYMBOLS no longer defined in config files 2012-04-11 19:33:54 +02:00
config-riscos.h curl tool: use configuration files from lib directory 2012-04-06 23:37:05 +02:00
config-symbian.h nss: unconditionally require PK11_CreateGenericObject() 2012-04-13 12:19:36 +02:00
config-tpf.h configure: Windows cross-compilation fixes 2012-04-09 21:24:16 +02:00
config-vms.h
config-vxworks.h nss: unconditionally require PK11_CreateGenericObject() 2012-04-13 12:19:36 +02:00
config-win32.h Changed Windows 64bit OS define to x86_64. 2011-09-20 12:32:04 +02:00
config-win32ce.h unicode NTLM SSPI: cleanup 2012-07-05 22:18:11 +02:00
connect.c Curl_connecthost: friendlier "couldn't connect" message 2012-11-07 22:55:33 +01:00
connect.h timeleft_accept: ack global timeout, moved to ftp.c 2011-12-20 20:55:54 +01:00
content_encoding.c
content_encoding.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
cookie.c cookie: fixed typo in comment 2012-07-09 15:25:34 +02:00
cookie.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
curl_addrinfo.c
curl_addrinfo.h
curl_base64.h base64: fix Curl_base64_encode and Curl_base64_decode interfaces 2011-08-24 08:10:30 +02:00
curl_config.h.cmake nss: unconditionally require PK11_CreateGenericObject() 2012-04-13 12:19:36 +02:00
curl_darwinssl.c SSL: Several SSL-backend related fixes 2012-11-08 22:23:12 +01:00
curl_darwinssl.h DarwinSSL: allow using NTLM authentication 2012-06-27 11:57:31 +02:00
curl_fnmatch.c
curl_fnmatch.h
curl_gethostname.c curl_gethostname.c: fix signed/unsigned comparison and avoid a double copy 2011-10-13 23:00:24 +02:00
curl_gethostname.h HOSTNAME_MAX: Moved to curl_gethostname.h 2011-09-25 23:58:47 +02:00
curl_gssapi.c
curl_gssapi.h
curl_hmac.h
curl_ldap.h
curl_md4.h
curl_md5.h Fixed compile error with GNUTLS+NETTLE 2012-05-22 16:40:09 +02:00
curl_memory.h
curl_memrchr.c
curl_memrchr.h
curl_multibyte.c unicode NTLM SSPI: cleanup 2012-07-05 22:18:11 +02:00
curl_multibyte.h unicode NTLM SSPI: cleanup 2012-07-05 22:18:11 +02:00
curl_ntlm_core.c DarwinSSL: allow using NTLM authentication 2012-06-27 11:57:31 +02:00
curl_ntlm_core.h NTLM: header inclusion cleanup 2011-08-28 07:15:46 +02:00
curl_ntlm_msgs.c code police: narrow source to < 80 columns 2012-07-06 00:19:41 +02:00
curl_ntlm_msgs.h unicode NTLM SSPI: cleanup 2012-07-05 22:18:11 +02:00
curl_ntlm_wb.c fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
curl_ntlm_wb.h NTLM: header inclusion cleanup 2011-08-28 07:15:46 +02:00
curl_ntlm.c Cleanup handshake after clean NTLM failure 2012-08-03 17:01:54 -04:00
curl_ntlm.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
curl_rand.c
curl_rand.h
curl_rtmp.c krb5/curl_rtmp.c: Hide size_t to int type conversion warning 2012-10-04 19:17:00 +02:00
curl_rtmp.h
curl_sasl.c SSPI related code: Unicode support for WinCE 2012-06-15 18:41:49 +02:00
curl_sasl.h sasl: Re-factored mechanism constants in preparation for APOP work 2012-06-08 19:52:28 +01:00
curl_schannel.c SSL: Several SSL-backend related fixes 2012-11-08 22:23:12 +01:00
curl_schannel.h curl_schannel: Removed buffer limit and optimized buffer strategy 2012-10-06 13:59:28 +02:00
curl_sspi.c SSPI related code: Unicode support for WinCE 2012-06-15 18:41:49 +02:00
curl_sspi.h SSPI related code: Unicode support for WinCE 2012-06-15 18:41:49 +02:00
curl_threads.c stdio.h, stdlib.h, string.h, stdarg.h and ctype.h inclusion done in setup_once.h 2011-07-26 17:23:27 +02:00
curl_threads.h
curlx.h
cyassl.c SSL: Several SSL-backend related fixes 2012-11-08 22:23:12 +01:00
cyassl.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
dict.c mem-include-scan: verify memory #includes 2012-11-17 13:56:38 +01:00
dict.h
easy.c curl tool: use configuration files from lib directory 2012-04-06 23:37:05 +02:00
easyif.h
escape.c URL sanitize: reject URLs containing bad data 2012-01-24 08:54:26 +01:00
escape.h URL sanitize: reject URLs containing bad data 2012-01-24 08:54:26 +01:00
file.c FILE: Make upload-writes unbuffered by not using FILE streams 2012-11-13 22:02:18 +01:00
file.h
fileinfo.c OOM handling/cleanup slight adjustments 2011-10-11 19:41:30 +02:00
fileinfo.h
firefox-db2pem.sh
formdata.c Fix bad failf() and info() usage 2012-06-14 13:32:05 +02:00
formdata.h
ftp.c ftp: EPSV-disable fix over SOCKS 2012-11-12 23:00:27 +01:00
ftp.h timeleft_accept: ack global timeout, moved to ftp.c 2011-12-20 20:55:54 +01:00
ftplistparser.c ftplistparser.c: do not compile if FTP protocol is not enabled 2012-06-18 18:51:30 +02:00
ftplistparser.h ftplistparser.c: do not compile if FTP protocol is not enabled 2012-06-18 18:51:30 +02:00
getenv.c SSPI related code: Unicode support for WinCE 2012-06-15 18:41:49 +02:00
getinfo.c getinfo: use va_end and cut off Curl_ from static funcs 2012-07-13 13:47:34 +02:00
getinfo.h
gopher.c mem-include-scan: verify memory #includes 2012-11-17 13:56:38 +01:00
gopher.h
gtls.c CURLOPT_SSL_VERIFYHOST: stop supporting the 1 value 2012-11-06 19:46:53 +01:00
gtls.h SSL cleanup: use crypto functions through the sslgen layer 2012-06-26 19:40:36 +02:00
hash.c hash.c: fix OOM triggered segfault 2011-12-25 11:35:45 +01:00
hash.h
hmac.c
hostasyn.c
hostcheck.c hostcheck: only build for the actual users 2012-11-08 22:37:53 +01:00
hostcheck.h hostcheck: only build for the actual users 2012-11-08 22:37:53 +01:00
hostip4.c hostip: avoid getaddrinfo when c-ares is used 2012-01-12 23:13:19 +01:00
hostip6.c fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
hostip.c fixed memory leak: CURLOPT_RESOLVE with multi interface 2012-11-18 16:39:31 +01:00
hostip.h fixed memory leak: CURLOPT_RESOLVE with multi interface 2012-11-18 16:39:31 +01:00
hostsyn.c CURLOPT_DNS_SERVERS: set name servers if possible 2011-11-17 22:52:33 +01:00
http_chunks.c fix bool variables checking and assignment 2011-09-05 20:46:09 +02:00
http_chunks.h
http_digest.c Digst: Add microseconds into nounce calculation 2012-11-12 11:46:27 +01:00
http_digest.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
http_negotiate_sspi.c unicode NTLM SSPI: cleanup 2012-07-05 22:18:11 +02:00
http_negotiate.c http_negotiate.c: Fxied warning: unused variable 'rc' 2012-09-14 15:50:24 +02:00
http_negotiate.h
http_proxy.c mem-include-scan: verify memory #includes 2012-11-17 13:56:38 +01:00
http_proxy.h http_proxy.h: fix builds with proxy or http disabled 2012-03-22 17:27:14 +01:00
http.c Remove stray CRLF in chunk-encoded content-free request bodies 2012-11-26 15:28:53 +01:00
http.h
idn_win32.c mem-include-scan: verify memory #includes 2012-11-17 13:56:38 +01:00
if2ip.c if2ip.[ch]: fix compilation with MinGW 2011-12-13 18:37:33 +01:00
if2ip.h if2ip.[ch]: fix compilation with MinGW 2011-12-13 18:37:33 +01:00
imap.c email: Removed duplicated header file 2012-06-05 11:18:07 +01:00
imap.h
inet_ntop.c
inet_ntop.h
inet_pton.c
inet_pton.h
krb4.c add missing semicolons 2011-08-24 13:58:37 +02:00
krb4.h
krb5.c krb5/curl_rtmp.c: Hide size_t to int type conversion warning 2012-10-04 19:17:00 +02:00
ldap.c curl_multi_fdset: correct fdset with FTP PORT use 2011-10-21 23:36:54 +02:00
libcurl.def
libcurl.plist removed trailing whitespace 2011-12-30 03:36:18 +01:00
libcurl.rc
libcurl.vers.in configure: add symbols versioning option 2011-12-19 23:25:36 +01:00
llist.c OOM handling/cleanup slight adjustments 2011-10-11 19:41:30 +02:00
llist.h
Makefile.am libcurl: VERSIONINFO update 2012-11-08 20:26:19 +01:00
makefile.amiga curl tool: use configuration files from lib directory - follow-up I 2012-04-07 00:31:24 +02:00
Makefile.b32 Updated dependency libary versions. 2012-05-22 04:15:37 +02:00
makefile.dj
Makefile.inc SSL: Several SSL-backend related fixes 2012-11-08 22:23:12 +01:00
Makefile.m32 Added .def file to output. 2012-11-08 18:50:48 +01:00
Makefile.netware Added missing dependency to export list. 2012-07-11 16:52:48 +02:00
Makefile.vc6 VC Makefiles: add missing hostcheck 2012-11-21 16:18:57 +01:00
Makefile.vxworks Updated dependency libary versions. 2012-05-22 04:15:37 +02:00
Makefile.Watcom Updated dependency libary versions. 2012-05-22 04:15:37 +02:00
md4.c fix several compiler warnings 2012-03-20 18:28:24 +01:00
md5.c mem-include-scan: verify memory #includes 2012-11-17 13:56:38 +01:00
memdebug.c fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
memdebug.h Make Curl_safefree() macro assign NULL to given pointer when free'd 2011-09-15 17:35:23 +02:00
mk-ca-bundle.pl mk-ca-bundle: detect start of trust section better 2012-09-04 23:21:15 +02:00
mk-ca-bundle.vbs Fix to skip untrusted certs. 2011-11-08 05:46:46 +01:00
mprintf.c MemoryTracking: fix logging of free() calls done where Curl_safefree is called 2011-09-02 19:40:53 +02:00
msvcproj.foot
msvcproj.head
multi.c multi.c: disambiguate precedence of bitwise and relational operation 2012-11-26 16:23:47 +01:00
multiif.h
netrc.c netrc: remove dead code 2012-06-12 22:46:14 +02:00
netrc.h
non-ascii.c mem-include-scan: verify memory #includes 2012-11-17 13:56:38 +01:00
non-ascii.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
nonblock.c lwip: basic checks and macros for compatiblity 2012-03-17 23:02:21 +01:00
nonblock.h
nss.c nss: prevent NSS from crashing on client auth hook failure 2012-12-03 13:34:36 +01:00
nssg.h SSL cleanup: use crypto functions through the sslgen layer 2012-06-26 19:40:36 +02:00
nwlib.c mem-include-scan: verify memory #includes 2012-11-17 13:56:38 +01:00
nwos.c checksrc: Fixed line length and comment indentation 2012-09-14 00:44:16 +02:00
openldap.c openldap: OOM fixes 2012-06-08 20:57:11 +02:00
parsedate.c parsedate.c: fix a numeric overflow 2012-03-22 15:54:34 +01:00
parsedate.h
pingpong.c FTP: prevent the multi interface from blocking 2012-11-04 19:05:39 +01:00
pingpong.h pingpong.c: fix Curl_pp_vsendf() arbitrary restrictions on command length 2011-08-29 14:27:06 +02:00
polarssl.c SSL: Several SSL-backend related fixes 2012-11-08 22:23:12 +01:00
polarssl.h PolarSSL: add support for asynchronous connect 2012-04-05 00:18:34 +02:00
pop3.c pop3: Post apop feature code tidy up 2012-06-09 19:21:44 +01:00
pop3.h pop3: Added support for apop authentication 2012-06-09 13:49:37 +01:00
progress.c Curl_pgrsDone: return int and acknowledge return code 2012-06-10 23:40:35 +02:00
progress.h Curl_pgrsDone: return int and acknowledge return code 2012-06-10 23:40:35 +02:00
qssl.c
qssl.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
rawstr.c
rawstr.h
README.ares
README.curl_off_t
README.curlx
README.encoding
README.hostip
README.httpauth
README.memoryleak
README.multi_socket
README.pingpong
README.pipelining
rtsp.c Curl_rtsp_parseheader: avoid useless malloc/free 2012-06-15 22:51:45 +02:00
rtsp.h
security.c security.c: Aligned internal type to return type 2012-10-04 19:16:59 +02:00
select.c Curl_socket_check: fix timeout return value for select users 2012-08-07 23:30:05 +02:00
select.h WSAPoll: disabled on all windows builds 2012-08-07 20:47:31 +02:00
sendf.c Curl_write: remove unneeded typecast 2012-11-12 10:04:31 +01:00
sendf.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
setup_once.h setup_once.h: tighten requirements for stdbool.h header inclusion 2012-04-14 15:41:38 +02:00
setup-os400.h
setup.h HTTP_ONLY: disable more protocols 2012-09-19 11:03:34 +02:00
share.c curl_share_setopt: use va_end() 2012-06-15 22:37:19 +02:00
share.h ssl session caching: fix compiler warnings 2012-01-18 23:42:39 +01:00
slist.c libcurl: some OOM handling fixes 2011-10-07 20:50:57 +02:00
slist.h
smtp.c SMTP: only send SIZE if supported 2012-09-04 16:54:41 +02:00
smtp.h SMTP: only send SIZE if supported 2012-09-04 16:54:41 +02:00
sockaddr.h sockaddr.h: Fixed dereferencing pointer breakin strict-aliasing 2012-06-26 21:24:29 +02:00
socks_gssapi.c Fix bad failf() and info() usage 2012-06-14 13:32:05 +02:00
socks_sspi.c SOCKS: truly disable it if CURL_DISABLE_PROXY is defined 2012-09-06 20:51:30 +02:00
socks.c lib/socks.c: Merged two size variables into one 2012-10-04 21:27:46 +02:00
socks.h
speedcheck.c Curl_speedcheck: don't mistakenly clear Curl_expire() 2011-09-08 08:39:53 +02:00
speedcheck.h
splay.c
splay.h fix a bunch of MSVC compiler warnings 2011-09-03 16:07:09 +02:00
ssh.c compiler warning fixes 2012-11-20 20:57:18 +01:00
ssh.h SSH: added agent based authentication 2012-08-08 23:03:10 +02:00
sslgen.c sslgen.c: cleanup temporary compile-time SSL-backend check 2012-06-28 12:49:12 +02:00
sslgen.h SSL cleanup: use crypto functions through the sslgen layer 2012-06-26 19:40:36 +02:00
ssluse.c OpenSSL: Disable SSL/TLS compression 2012-11-13 23:01:28 +01:00
ssluse.h SSL cleanup: use crypto functions through the sslgen layer 2012-06-26 19:40:36 +02:00
strdup.c mem-include-scan: verify memory #includes 2012-11-17 13:56:38 +01:00
strdup.h
strequal.c
strequal.h
strerror.c mem-include-scan: verify memory #includes 2012-11-17 13:56:38 +01:00
strerror.h sspi: make Curl_sspi_strerror() libcurl's sspi status code string function 2012-06-12 01:06:48 +02:00
strtok.c
strtok.h
strtoofft.c
strtoofft.h
telnet.c SSPI related code: Unicode support for WinCE 2012-06-15 18:41:49 +02:00
telnet.h
tftp.c tftp_rx: code style cleanup 2012-11-16 22:00:17 +01:00
tftp.h
timeval.c tvdiff_secs(): sub-zero time difference adjustment 2011-11-25 13:51:55 +01:00
timeval.h
transfer.c Curl_readwrite: remove debug output 2012-11-08 10:47:11 +01:00
transfer.h
url.c avoid mixing of enumerated type with another type 2012-11-26 16:23:48 +01:00
url.h non-blocking active FTP: cleanup multi state usage 2011-12-20 20:30:02 +01:00
urldata.h CURLOPT_SSL_VERIFYHOST: stop supporting the 1 value 2012-11-06 19:46:53 +01:00
vc6libcurl.dsw
vc8proj.foot
vc8proj.head
version.c curl_version: fixed Value stored to 'len' is never read 2012-08-08 14:58:09 +02:00
warnless.c fix some compiler warnings 2012-03-25 18:30:16 +02:00
warnless.h fix some compiler warnings 2012-03-25 18:30:16 +02:00
wildcard.c
wildcard.h

HTTP Pipelining with libcurl
============================

Background

Since pipelining implies that one or more requests are sent to a server before
the previous response(s) have been received, we only support it for multi
interface use.

Considerations

When using the multi interface, you create one easy handle for each transfer.
Bascially any number of handles can be created, added and used with the multi
interface - simultaneously. It is an interface designed to allow many
simultaneous transfers while still using a single thread. Pipelining does not
change any of these details.

API

We've added a new option to curl_multi_setopt() called CURLMOPT_PIPELINING
that enables "attempted pipelining" and then all easy handles used on that
handle will attempt to use an existing pipeline.

Details

- A pipeline is only created if a previous connection exists to the same IP
  address that the new request is being made to use.

- Pipelines are only supported for HTTP(S) as no other currently supported
  protocol has features resemembling this, but we still name this feature
  plain 'pipelining' to possibly one day support it for other protocols as
  well.

- HTTP Pipelining is for GET and HEAD requests only.

- When a pipeline is in use, we must take precautions so that when used easy
  handles (i.e those who still wait for a response) are removed from the multi
  handle, we must deal with the outstanding response nicely.

- Explicitly asking for pipelining handle X and handle Y won't be supported.
  It isn't easy for an app to do this association. The lib should probably
  still resolve the second one properly to make sure that they actually _can_
  be considered for pipelining. Also, asking for explicit pipelining on handle
  X may be tricky when handle X get a closed connection.

- We need options to control max pipeline length, and probably how to behave
  if we reach that limit. As was discussed on the list, it can probably be
  made very complicated, so perhaps we can think of a way to pass all
  variables involved to a callback and let the application decide how to act
  in specific situations. Either way, these fancy options are only interesting
  to work on when everything is working and we have working apps to test with.