Coverage Report

Created: 2026-09-14 20:36

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/tmp/bitcoin/src/httpserver.cpp
Line
Count
Source
1
// Copyright (c) 2015-present The Bitcoin Core developers
2
// Distributed under the MIT software license, see the accompanying
3
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4
5
#include <bitcoin-build-config.h> // IWYU pragma: keep
6
7
#include <httpserver.h>
8
9
#include <chainparamsbase.h>
10
#include <common/args.h>
11
#include <common/messages.h>
12
#include <common/url.h>
13
#include <compat/compat.h>
14
#include <logging.h>
15
#include <netbase.h>
16
#include <node/interface_ui.h>
17
#include <rpc/protocol.h>
18
#include <span.h>
19
#include <sync.h>
20
#include <util/check.h>
21
#include <util/signalinterrupt.h>
22
#include <util/sock.h>
23
#include <util/strencodings.h>
24
#include <util/thread.h>
25
#include <util/threadnames.h>
26
#include <util/threadpool.h>
27
#include <util/time.h>
28
#include <util/translation.h>
29
30
#include <condition_variable>
31
#include <cstdio>
32
#include <cstdlib>
33
#include <memory>
34
#include <optional>
35
#include <span>
36
#include <string>
37
#include <string_view>
38
#include <thread>
39
#include <unordered_map>
40
#include <vector>
41
42
#include <sys/types.h>
43
#include <sys/stat.h>
44
45
//! The set of sockets cannot be modified while waiting, so
46
//! the sleep time needs to be small to avoid new sockets stalling.
47
static constexpr auto SELECT_TIMEOUT{50ms};
48
49
//! Explicit alias for setting socket option methods.
50
static constexpr int SOCKET_OPTION_TRUE{1};
51
52
using common::InvalidPortErrMsg;
53
using util::LineReader;
54
using namespace bitcoin_http;
55
56
struct HTTPPathHandler
57
{
58
    HTTPPathHandler(std::string _prefix, bool _exactMatch, HTTPRequestHandler _handler):
59
2.36k
        prefix(_prefix), exactMatch(_exactMatch), handler(_handler)
60
2.36k
    {
61
2.36k
    }
62
    std::string prefix;
63
    bool exactMatch;
64
    HTTPRequestHandler handler;
65
};
66
67
/** HTTP module state */
68
69
static std::unique_ptr<HTTPServer> g_http_server{nullptr};
70
//! Handlers for (sub)paths
71
static GlobalMutex g_httppathhandlers_mutex;
72
static std::vector<HTTPPathHandler> pathHandlers GUARDED_BY(g_httppathhandlers_mutex);
73
/// \anchor http_pool
74
//! Http thread pool - future: encapsulate in HttpContext
75
static ThreadPool g_threadpool_http("http");
76
static int g_max_queue_depth{100};
77
78
/** Check if a network address is allowed to access the HTTP server */
79
bool HTTPServer::ClientAllowed(const CNetAddr& netaddr) const
80
3.52k
{
81
3.52k
    if (!netaddr.IsValid())
82
0
        return false;
83
3.52k
    for(const CSubNet& subnet : m_allow_subnets)
84
3.53k
        if (subnet.Match(netaddr))
85
3.52k
            return true;
86
2
    return false;
87
3.52k
}
88
89
/** Initialize ACL list for HTTP server */
90
bool HTTPServer::InitHTTPAllowList()
91
1.17k
{
92
    // Must be run before StartSocketThreads() because ThreadSocketHandler()
93
    // will check m_allow_subnets from the I/O thread.
94
1.17k
    Assume(!m_thread_socket_handler.joinable());
95
96
1.17k
    m_allow_subnets.clear();
97
1.17k
    m_allow_subnets.emplace_back(LookupHost("127.0.0.1", false).value(), 8);  // always allow IPv4 local subnet
98
1.17k
    m_allow_subnets.emplace_back(LookupHost("::1", false).value());  // always allow IPv6 localhost
99
1.17k
    for (const std::string& strAllow : gArgs.GetArgs("-rpcallowip")) {
100
16
        const CSubNet subnet{LookupSubNet(strAllow)};
101
16
        if (!subnet.IsValid()) {
102
1
            uiInterface.ThreadSafeMessageBox(
103
1
                Untranslated(strprintf("Invalid -rpcallowip subnet specification: %s. Valid values are a single IP (e.g. 1.2.3.4), a network/netmask (e.g. 1.2.3.4/255.255.255.0), a network/CIDR (e.g. 1.2.3.4/24), all ipv4 (0.0.0.0/0), or all ipv6 (::/0). RFC4193 is allowed only if -cjdnsreachable=0.", strAllow)),
104
1
                CClientUIInterface::MSG_ERROR);
105
1
            return false;
106
1
        }
107
15
        m_allow_subnets.push_back(subnet);
108
15
    }
109
1.17k
    std::string strAllowed;
110
1.17k
    for (const CSubNet& subnet : m_allow_subnets)
111
2.35k
        strAllowed += subnet.ToString() + " ";
112
1.17k
    LogDebug(BCLog::HTTP, "Allowing HTTP connections from: %s\n", strAllowed);
113
1.17k
    return true;
114
1.17k
}
115
116
/** HTTP request method as string - use for logging only */
117
std::string_view RequestMethodString(HTTPRequestMethod m)
118
186k
{
119
186k
    switch (m) {
120
0
    using enum HTTPRequestMethod;
121
894
    case GET: return "GET";
122
185k
    case POST: return "POST";
123
0
    case HEAD: return "HEAD";
124
0
    case PUT: return "PUT";
125
5
    case UNKNOWN: return "unknown";
126
186k
    } // no default case, so the compiler can warn about missing cases
127
186k
    assert(false);
128
0
}
129
130
static void WriteNoStoreErrorReply(HTTPRequest& req, HTTPStatusCode status, std::string_view reply = {})
131
905
{
132
905
    req.WriteHeader("Cache-Control", "no-store");
133
905
    req.WriteReply(status, reply);
134
905
}
135
136
static void MaybeDispatchRequestToWorker(std::shared_ptr<HTTPRequest> hreq)
137
186k
{
138
    // Early reject unknown HTTP methods
139
186k
    if (hreq->GetRequestMethod() == HTTPRequestMethod::UNKNOWN) {
140
5
        LogDebug(BCLog::HTTP, "HTTP request from %s rejected: Unknown HTTP request method\n",
141
5
                 hreq->GetPeer().ToStringAddrPort());
142
5
        WriteNoStoreErrorReply(*hreq, HTTP_BAD_METHOD);
143
5
        return;
144
5
    }
145
146
    // Find registered handler for prefix
147
186k
    std::string strURI = hreq->GetURI();
148
186k
    std::string path;
149
186k
    LOCK(g_httppathhandlers_mutex);
150
186k
    std::vector<HTTPPathHandler>::const_iterator i = pathHandlers.begin();
151
186k
    std::vector<HTTPPathHandler>::const_iterator iend = pathHandlers.end();
152
213k
    for (; i != iend; ++i) {
153
213k
        bool match = false;
154
213k
        if (i->exactMatch)
155
186k
            match = (strURI == i->prefix);
156
27.4k
        else
157
27.4k
            match = strURI.starts_with(i->prefix);
158
213k
        if (match) {
159
186k
            path = strURI.substr(i->prefix.size());
160
186k
            break;
161
186k
        }
162
213k
    }
163
164
    // Dispatch to worker thread
165
186k
    if (i != iend) {
166
186k
        if (static_cast<int>(g_threadpool_http.WorkQueueSize()) >= g_max_queue_depth) {
167
871
            LogWarning("Request rejected because http work queue depth exceeded, it can be increased with the -rpcworkqueue= setting");
168
871
            WriteNoStoreErrorReply(*hreq, HTTP_SERVICE_UNAVAILABLE, "Work queue depth exceeded");
169
871
            return;
170
871
        }
171
172
185k
        auto item = [req = hreq, in_path = std::move(path), fn = i->handler]() {
173
185k
            std::string err_msg;
174
185k
            try {
175
185k
                fn(req.get(), in_path);
176
185k
                return;
177
185k
            } catch (const std::exception& e) {
178
0
                LogWarning("Unexpected error while processing request for '%s'. Error msg: '%s'", req->GetURI(), e.what());
179
0
                err_msg = e.what();
180
0
            } catch (...) {
181
0
                LogWarning("Unknown error while processing request for '%s'", req->GetURI());
182
0
                err_msg = "unknown error";
183
0
            }
184
            // Reply so the client doesn't hang waiting for the response.
185
0
            req->WriteHeader("Connection", "close");
186
            // TODO: Implement specific error formatting for the REST and JSON-RPC servers responses.
187
0
            WriteNoStoreErrorReply(*req, HTTP_INTERNAL_SERVER_ERROR, err_msg);
188
0
        };
189
190
185k
        if (auto res = g_threadpool_http.Submit(std::move(item)); !res.has_value()) {
191
0
            Assume(hreq.use_count() == 1); // ensure request will be deleted
192
            // Both SubmitError::Inactive and SubmitError::Interrupted mean shutdown
193
0
            LogWarning("HTTP request rejected during server shutdown: '%s'", SubmitErrorString(res.error()));
194
0
            WriteNoStoreErrorReply(*hreq, HTTP_SERVICE_UNAVAILABLE, "Request rejected during server shutdown");
195
0
            return;
196
0
        }
197
185k
    } else {
198
12
        WriteNoStoreErrorReply(*hreq, HTTP_NOT_FOUND);
199
12
    }
200
186k
}
201
202
static void RejectRequest(std::unique_ptr<HTTPRequest> hreq)
203
0
{
204
0
    LogDebug(BCLog::HTTP, "Rejecting request while shutting down");
205
0
    WriteNoStoreErrorReply(*hreq, HTTP_SERVICE_UNAVAILABLE);
206
0
}
207
208
static std::vector<std::pair<std::string, uint16_t>> GetBindAddresses()
209
1.16k
{
210
1.16k
    uint16_t http_port{static_cast<uint16_t>(gArgs.GetIntArg("-rpcport", BaseParams().RPCPort()))};
211
1.16k
    std::vector<std::pair<std::string, uint16_t>> endpoints;
212
213
    // Determine what addresses to bind to
214
    // To prevent misconfiguration and accidental exposure of the RPC
215
    // interface, require -rpcallowip and -rpcbind to both be specified
216
    // together. If either is missing, ignore both values, bind to localhost
217
    // instead, and log warnings.
218
1.16k
    if (gArgs.GetArgs("-rpcallowip").empty() || gArgs.GetArgs("-rpcbind").empty()) { // Default to loopback if not allowing external IPs
219
1.15k
        endpoints.emplace_back("::1", http_port);
220
1.15k
        endpoints.emplace_back("127.0.0.1", http_port);
221
1.15k
        if (!gArgs.GetArgs("-rpcallowip").empty()) {
222
3
            LogWarning("Option -rpcallowip was specified without -rpcbind; this doesn't usually make sense");
223
3
        }
224
1.15k
        if (!gArgs.GetArgs("-rpcbind").empty()) {
225
0
            LogWarning("Option -rpcbind was ignored because -rpcallowip was not specified, refusing to allow everyone to connect");
226
0
        }
227
1.15k
    } else { // Specific bind addresses
228
14
        for (const std::string& strRPCBind : gArgs.GetArgs("-rpcbind")) {
229
14
            uint16_t port{http_port};
230
14
            std::string host;
231
14
            if (!SplitHostPort(strRPCBind, port, host)) {
232
0
                LogError("%s\n", InvalidPortErrMsg("-rpcbind", strRPCBind).original);
233
0
                return {}; // empty
234
0
            }
235
14
            endpoints.emplace_back(host, port);
236
14
        }
237
9
    }
238
1.16k
    return endpoints;
239
1.16k
}
240
241
void RegisterHTTPHandler(const std::string &prefix, bool exactMatch, const HTTPRequestHandler &handler)
242
2.36k
{
243
2.36k
    LogDebug(BCLog::HTTP, "Registering HTTP handler for %s (exactmatch %d)\n", prefix, exactMatch);
244
2.36k
    LOCK(g_httppathhandlers_mutex);
245
2.36k
    pathHandlers.emplace_back(prefix, exactMatch, handler);
246
2.36k
}
247
248
void UnregisterHTTPHandler(const std::string &prefix, bool exactMatch)
249
19.3k
{
250
19.3k
    LOCK(g_httppathhandlers_mutex);
251
19.3k
    std::vector<HTTPPathHandler>::iterator i = pathHandlers.begin();
252
19.3k
    std::vector<HTTPPathHandler>::iterator iend = pathHandlers.end();
253
19.3k
    for (; i != iend; ++i)
254
2.36k
        if (i->prefix == prefix && i->exactMatch == exactMatch)
255
2.36k
            break;
256
19.3k
    if (i != iend)
257
2.36k
    {
258
2.36k
        LogDebug(BCLog::HTTP, "Unregistering HTTP handler for %s (exactmatch %d)\n", prefix, exactMatch);
259
2.36k
        pathHandlers.erase(i);
260
2.36k
    }
261
19.3k
}
262
263
using util::Split;
264
265
std::optional<std::string> HTTPHeaders::FindFirst(const std::string_view key) const
266
822k
{
267
3.81M
    for (const auto& item : m_headers) {
268
3.81M
        if (CaseInsensitiveEqual(key, item.first)) {
269
371k
            return item.second;
270
371k
        }
271
3.81M
    }
272
451k
    return std::nullopt;
273
822k
}
274
275
std::vector<std::string_view> HTTPHeaders::FindAll(const std::string_view key) const
276
265k
{
277
265k
    std::vector<std::string_view> ret;
278
1.58M
    for (const auto& item : m_headers) {
279
1.58M
        if (CaseInsensitiveEqual(key, item.first)) {
280
264k
            ret.push_back(item.second);
281
264k
        }
282
1.58M
    }
283
265k
    return ret;
284
265k
}
285
286
void HTTPHeaders::Write(std::string&& key, std::string&& value)
287
1.67M
{
288
1.67M
    m_headers.emplace_back(std::move(key), std::move(value));
289
1.67M
}
290
291
void HTTPHeaders::RemoveAll(std::string_view key)
292
1.10k
{
293
3.33k
    auto moved = std::ranges::remove_if(m_headers, [key] (auto& pair) {
294
3.33k
        return CaseInsensitiveEqual(key, pair.first);
295
3.33k
    });
296
1.10k
    m_headers.erase(moved.begin(), moved.end());
297
1.10k
}
298
299
bool HTTPHeaders::Read(util::LineReader& reader, bool write)
300
186k
{
301
    // Headers https://httpwg.org/specs/rfc9110.html#rfc.section.6.3
302
    // A sequence of Field Lines https://httpwg.org/specs/rfc9110.html#rfc.section.5.2
303
186k
    size_t start{reader.Consumed()};
304
1.30M
    while (auto maybe_line = reader.ReadLine()) {
305
1.30M
        if (reader.Consumed() - start + m_consumed > MAX_HEADERS_SIZE) throw std::runtime_error("HTTP headers exceed size limit");
306
307
1.30M
        const std::string_view& line = *maybe_line;
308
309
        // An empty line indicates end of the headers section https://www.rfc-editor.org/rfc/rfc2616#section-4
310
1.30M
        if (line.empty()) {
311
            // Ensure all headers are accounted for in case there is a chunked trailer
312
186k
            m_consumed += reader.Consumed() - start;
313
186k
            return true;
314
186k
        }
315
316
        // "Field values containing CR, LF, or NUL characters are invalid and dangerous"
317
        // https://httpwg.org/specs/rfc9110.html#rfc.section.5.5
318
        // A sender MUST NOT generate a bare CR (a CR character not immediately followed by LF)
319
        // within any protocol elements other than the content.
320
        // A recipient of such a bare CR MUST consider that element to be invalid...
321
        // https://httpwg.org/specs/rfc9112.html#rfc.section.2.2
322
1.11M
        if (line.find_first_of("\r\n\0", 0, 3) != std::string_view::npos) throw std::runtime_error("Header contains invalid character");
323
324
        // Header line must have at least one ":"
325
        // keys are not allowed to have delimiters like ":" but values are
326
        // https://httpwg.org/specs/rfc9110.html#rfc.section.5.6.2
327
1.11M
        const size_t pos{line.find(':')};
328
1.11M
        if (pos == std::string_view::npos) throw std::runtime_error("HTTP header missing colon (:)");
329
330
        // Whitespace is strictly not allowed in the field-name (key)
331
        // https://www.rfc-editor.org/rfc/rfc9110.html#section-5.6.2
332
1.11M
        std::string_view key = line.substr(0, pos);
333
1.11M
        if (key.find_first_of(" \t\n\r\f\v") != std::string_view::npos) throw std::runtime_error("Invalid header field-name contains whitespace");
334
        // Whitespace is optional in the value and can be trimmed
335
1.11M
        std::string value = util::TrimString(std::string_view(line).substr(pos + 1));
336
337
        // Header keys are Field Names: https://httpwg.org/specs/rfc9110.html#fields.names
338
        // which consist of "tokens": https://httpwg.org/specs/rfc9110.html#rfc.section.5.6.2
339
        // that can not be empty.
340
1.11M
        if (key.empty()) throw std::runtime_error("Empty HTTP header name");
341
342
1.11M
        if (write) {
343
1.11M
            Write(std::string(key), std::move(value));
344
1.11M
        }
345
1.11M
    }
346
347
    // We have not received all the request headers yet.
348
    // Keep track of how much data we have already consumed to enforce
349
    // the total limit over multiple read operations.
350
14
    m_consumed += reader.Consumed() - start;
351
352
14
    return false;
353
186k
}
354
355
std::string HTTPHeaders::Stringify() const
356
186k
{
357
186k
    std::string out;
358
561k
    for (const auto& [key, value] : m_headers) {
359
561k
        out += key + ": " + value + "\r\n";
360
561k
    }
361
362
    // Headers are terminated by an empty line
363
186k
    out += "\r\n";
364
365
186k
    return out;
366
186k
}
367
368
std::string HTTPResponse::StringifyHeaders() const
369
186k
{
370
186k
    return strprintf("HTTP/%d.%d %d %s\r\n%s",
371
186k
                     version.major,
372
186k
                     version.minor,
373
186k
                     status,
374
186k
                     HTTPStatusReasonString(status),
375
186k
                     headers.Stringify());
376
186k
}
377
378
bool HTTPRequest::LoadControlData(LineReader& reader)
379
186k
{
380
186k
    auto maybe_line = reader.ReadLine();
381
186k
    if (!maybe_line) return false;
382
186k
    const std::string_view& request_line = *maybe_line;
383
384
    // Request Line aka Control Data https://httpwg.org/specs/rfc9110.html#rfc.section.6.2
385
    // Three words separated by spaces, terminated by \n or \r\n
386
186k
    if (request_line.length() < MIN_REQUEST_LINE_LENGTH) throw std::runtime_error("HTTP request line too short");
387
388
    // NUL is not a valid tchar and would silently truncate
389
    // C-string-based parsers rather than being rejected as malformed.
390
    // tchar: https://www.rfc-editor.org/info/rfc7230/#section-3.2.6
391
186k
    if (request_line.find('\0') != std::string_view::npos) throw std::runtime_error("Invalid request line contains NUL");
392
393
186k
    const std::vector<std::string_view> parts{Split<std::string_view>(request_line, " ")};
394
186k
    if (parts.size() != 3) throw std::runtime_error("HTTP request line malformed");
395
396
186k
    if (parts[0] == "GET") {
397
920
        m_method = HTTPRequestMethod::GET;
398
185k
    } else if (parts[0] == "POST") {
399
185k
        m_method = HTTPRequestMethod::POST;
400
185k
    } else if (parts[0] == "HEAD") {
401
0
        m_method = HTTPRequestMethod::HEAD;
402
7
    } else if (parts[0] == "PUT") {
403
0
        m_method = HTTPRequestMethod::PUT;
404
7
    } else {
405
7
        m_method = HTTPRequestMethod::UNKNOWN;
406
7
    }
407
408
186k
    m_target = parts[1];
409
410
186k
    if (parts[2].rfind("HTTP/") != 0) throw std::runtime_error("HTTP request line malformed");
411
412
    // Version is exactly two decimal digits separated by a decimal point
413
    // https://httpwg.org/specs/rfc9110.html#rfc.section.2.5
414
186k
    const std::vector<std::string_view> version_parts{Split<std::string_view>(parts[2].substr(5), ".")};
415
186k
    if (version_parts.size() != 2) throw std::runtime_error("HTTP request line malformed");
416
186k
    if (version_parts[0].size() != 1 || version_parts[1].size() != 1) throw std::runtime_error("HTTP bad version");
417
186k
    auto major = ToIntegral<uint8_t>(version_parts[0]);
418
186k
    auto minor = ToIntegral<uint8_t>(version_parts[1]);
419
186k
    if (!major || !minor || major != 1 || minor > 9) throw std::runtime_error("HTTP bad version");
420
186k
    m_version.major = major.value();
421
186k
    m_version.minor = minor.value();
422
423
186k
    return true;
424
186k
}
425
426
bool HTTPRequest::LoadHeaders(LineReader& reader)
427
186k
{
428
186k
    return m_headers.Read(reader);
429
186k
}
430
431
bool HTTPRequest::LoadBody(LineReader& reader)
432
265k
{
433
    // https://httpwg.org/specs/rfc9112.html#message.body
434
265k
    auto transfer_encoding_header = m_headers.FindFirst("Transfer-Encoding");
435
265k
    if (transfer_encoding_header && ToLower(transfer_encoding_header.value()) == "chunked") {
436
        // Transfer-Encoding: https://datatracker.ietf.org/doc/html/rfc7230.html#section-3.3.1
437
        // Chunked Transfer Coding: https://datatracker.ietf.org/doc/html/rfc7230.html#section-4.1
438
        // see evhttp_handle_chunked_read() in libevent http.c
439
1.08k
        while (reader.Remaining() > 0) {
440
557
            if (!m_chunk_size) {
441
33
                auto maybe_chunk_size = reader.ReadLine();
442
33
                if (!maybe_chunk_size) return false;
443
444
                // Allow (but ignore) Chunk Extensions
445
                // See https://www.rfc-editor.org/rfc/rfc9112.html#name-chunk-extensions
446
33
                std::string_view chunk_size_noext{maybe_chunk_size.value()};
447
33
                const auto semicolon_pos = chunk_size_noext.find(';');
448
33
                if (semicolon_pos != chunk_size_noext.npos) {
449
3
                    chunk_size_noext.remove_suffix(chunk_size_noext.size() - semicolon_pos);
450
3
                }
451
452
33
                m_chunk_size = ToIntegral<uint64_t>(util::TrimStringView(chunk_size_noext), /*base=*/16);
453
33
                if (!m_chunk_size) throw std::runtime_error("Cannot parse chunk length value");
454
455
32
                if ((m_body.size() > MAX_BODY_SIZE) ||
456
32
                    (*m_chunk_size > MAX_BODY_SIZE - m_body.size()))
457
3
                    throw ContentTooLargeError("Chunk will exceed max body size");
458
32
            }
459
460
            // We either just read the chunk size, or we have it saved
461
            // from a prior I/O loop iteration
462
553
            Assume(m_chunk_size);
463
464
            // Last chunk has size 0
465
553
            if (*m_chunk_size == 0) {
466
                // Validate Chunked Trailer section, which is used for
467
                // additional headers sent at the end of the message.
468
                // Data consumed here is counted towards MAX_HEADERS_SIZE
469
                // along with the headers we read in the beginning of the request.
470
                // At this time we ignore and drop these data after validating.
471
                // See https://httpwg.org/specs/rfc9112.html#rfc.section.7.1.2
472
11
                return m_headers.Read(reader, /*write=*/false);
473
11
            }
474
475
            // We have not read the entire chunk from the buffer yet
476
542
            if (m_chunk_read < *m_chunk_size) {
477
                // Get what we can from the buffer
478
541
                const uint64_t chunk_need{*m_chunk_size - m_chunk_read};
479
541
                const uint64_t buffer_has{std::min(chunk_need, static_cast<uint64_t>(reader.Remaining()))};
480
481
                // Pack [partial] chunk onto body and update state
482
541
                m_body += reader.ReadLength(buffer_has);
483
541
                m_chunk_read += buffer_has;
484
541
            }
485
486
            // Even though every chunk size is explicitly declared,
487
            // they are still terminated by a CRLF we don't need,
488
            // just consume it here.
489
542
            if (m_chunk_read == *m_chunk_size) {
490
23
                auto crlf = reader.ReadLine();
491
23
                if (!crlf) {
492
                    // CRLF not found before end of buffer: it has not been received by our socket yet.
493
1
                    return false;
494
1
                }
495
                // CRLF was found but there was unexpected data after the chunk_sized chunk
496
22
                if (!crlf.value().empty()) throw std::runtime_error("Improperly terminated chunk");
497
498
                // Clear state for next chunk
499
21
                m_chunk_size.reset();
500
21
                m_chunk_read = 0;
501
21
            }
502
542
        }
503
504
        // We read all the chunks but never got the last chunk, wait for client to send more
505
525
        return false;
506
265k
    } else {
507
        // No Content-length or Transfer-Encoding header means no body, see libevent evhttp_get_body()
508
265k
        auto content_length_values{m_headers.FindAll("Content-Length")};
509
265k
        if (content_length_values.empty()) return true;
510
511
        // Duplicate Content-Length headers are allowed only if they all have the same value
512
        // https://www.rfc-editor.org/rfc/rfc7230#section-3.3.3
513
264k
        const auto& first_content_length_value{content_length_values[0]};
514
264k
        for (size_t i = 1; i < content_length_values.size(); ++i) {
515
3
            if (content_length_values[i] != first_content_length_value) throw std::runtime_error("Differing Content-Length values");
516
3
        }
517
518
264k
        const auto content_length{ToIntegral<uint64_t>(first_content_length_value)};
519
264k
        if (!content_length) throw std::runtime_error("Cannot parse Content-Length value");
520
521
264k
        if (*content_length > MAX_BODY_SIZE) throw ContentTooLargeError("Max body size exceeded");
522
523
        // A large body may arrive over multiple I/O loop iterations. Copy
524
        // whatever the buffer has now; m_body's size tracks our progress.
525
264k
        const uint64_t body_need{*content_length - m_body.size()};
526
264k
        const uint64_t buffer_has{std::min(body_need, static_cast<uint64_t>(reader.Remaining()))};
527
528
        // Pack [partial] body on and update state
529
264k
        m_body += reader.ReadLength(buffer_has);
530
531
264k
        return m_body.size() == *content_length;
532
264k
    }
533
265k
}
534
535
void HTTPRequest::WriteReply(HTTPStatusCode status, std::span<const std::byte> reply_body)
536
186k
{
537
186k
    HTTPResponse res;
538
539
    // Some response headers are determined in advance and stored in the request
540
186k
    res.headers = std::move(m_response_headers);
541
542
    // Response version matches request version
543
186k
    res.version = m_version;
544
545
    // Add response code
546
186k
    res.status = status;
547
548
    // See libevent evhttp_response_needs_body()
549
    // Response headers are different if no body is needed
550
186k
    bool needs_body{status != HTTP_NO_CONTENT && (status < 100 || status >= 200)};
551
186k
    bool needs_content_length{false};
552
553
186k
    bool keep_alive{false};
554
555
    // See libevent evhttp_make_header_response()
556
    // Expected response headers depend on protocol version
557
186k
    if (m_version.major == 1) {
558
        // HTTP/1.0
559
186k
        if (m_version.minor == 0) {
560
5
            auto connection_header{m_headers.FindFirst("Connection")};
561
5
            if (connection_header && ToLower(connection_header.value()) == "keep-alive") {
562
0
                res.headers.Write("Connection", "keep-alive");
563
0
                keep_alive = true;
564
                // HTTP/1.0 connections are closed by default so EOF is sufficient
565
                // to indicate end of the body. Adding Content-Length a special case.
566
0
                if (needs_body) needs_content_length = true;
567
0
            }
568
5
        }
569
570
        // HTTP/1.1
571
186k
        if (m_version.minor >= 1) {
572
186k
            const int64_t now_seconds{TicksSinceEpoch<std::chrono::seconds>(NodeClock::now())};
573
186k
            res.headers.Write("Date", FormatRFC1123DateTime(now_seconds));
574
575
            // HTTP/1.1 connections are kept alive by default and always require Content-Length.
576
186k
            if (needs_body) needs_content_length = true;
577
578
            // Default for HTTP/1.1
579
186k
            keep_alive = true;
580
186k
        }
581
186k
    }
582
583
186k
    if (needs_content_length) {
584
186k
        res.headers.Write("Content-Length", util::ToString(reply_body.size()));
585
186k
    }
586
587
186k
    if (needs_body && !res.headers.FindFirst("Content-Type")) {
588
        // Default type from libevent evhttp_new_object()
589
1.04k
        res.headers.Write("Content-Type", "text/html; charset=ISO-8859-1");
590
1.04k
    }
591
592
186k
    auto connection_header{m_headers.FindFirst("Connection")};
593
186k
    if (connection_header && ToLower(connection_header.value()) == "close") {
594
        // Might not exist already but we need to replace it, not append to it
595
1.10k
        res.headers.RemoveAll("Connection");
596
597
1.10k
        res.headers.Write("Connection", "close");
598
1.10k
        keep_alive = false;
599
1.10k
    }
600
601
186k
    if (std::shared_ptr client{m_client.lock()}) {
602
186k
        client->Send(res, reply_body, keep_alive);
603
186k
    }
604
186k
}
605
606
void HTTPRemoteClient::Send(const HTTPResponse& res, std::span<const std::byte> reply_body, bool keep_alive)
607
186k
{
608
186k
    m_keep_alive = keep_alive;
609
610
    // Serialize the response headers
611
186k
    const std::string headers{res.StringifyHeaders()};
612
186k
    const auto headers_bytes{std::as_bytes(std::span{headers})};
613
614
186k
    bool send_buffer_was_empty{false};
615
    // Fill the send buffer with the complete serialized response headers + body
616
186k
    {
617
186k
        LOCK(m_send_mutex);
618
186k
        send_buffer_was_empty = m_send_buffer.empty();
619
186k
        m_send_buffer.insert(m_send_buffer.end(), headers_bytes.begin(), headers_bytes.end());
620
621
        // We've been using std::span up until now but it is finally time to copy
622
        // data. The original data will go out of scope when WriteReply() returns.
623
        // This is analogous to the memcpy() in libevent's evbuffer_add()
624
186k
        m_send_buffer.insert(m_send_buffer.end(), reply_body.begin(), reply_body.end());
625
626
        // If the buffer already held data, the I/O thread is (or soon will be)
627
        // draining it, so flag that there is more data to send. This must happen
628
        // while holding m_send_mutex and while the buffer is known non-empty:
629
        // setting m_send_ready after releasing the lock would race with the I/O
630
        // thread draining the buffer to empty and clearing m_send_ready in
631
        // between, leaving m_send_ready set on an empty buffer. The I/O loop would
632
        // then only ever poll the socket for writeability, never read the client's
633
        // next request, and wedge the connection.
634
186k
        if (!send_buffer_was_empty) m_send_ready = true;
635
186k
    }
636
637
186k
    LogDebug(
638
186k
        BCLog::HTTP,
639
186k
        "HTTPResponse (status code: %d size: %lld) added to send buffer for client %s (id=%llu)",
640
186k
        res.status,
641
186k
        headers_bytes.size() + reply_body.size(),
642
186k
        m_origin,
643
186k
        m_id);
644
645
    // If the send buffer was empty before we wrote this reply, we can try an
646
    // optimistic send akin to CConnman::PushMessage() in which we
647
    // push the data directly out the socket to client right now, instead
648
    // of waiting for the next iteration of the I/O loop.
649
186k
    if (send_buffer_was_empty) {
650
186k
        MaybeSendBytesFromBuffer();
651
186k
    }
652
653
    // Signal to the I/O loop that we are ready to handle the next request.
654
186k
    m_req_busy = false;
655
186k
}
656
657
CService HTTPRequest::GetPeer() const
658
184k
{
659
184k
    if (std::shared_ptr c{m_client.lock()}) {
660
184k
        return c->GetPeer();
661
184k
    } else {
662
2
        return {};
663
2
    }
664
184k
}
665
666
std::optional<std::string> HTTPRequest::GetQueryParameter(const std::string_view key) const
667
93
{
668
93
    return GetQueryParameterFromUri(m_target, key);
669
93
}
670
671
// See libevent http.c evhttp_parse_query_impl()
672
// and https://www.rfc-editor.org/rfc/rfc3986#section-3.4
673
std::optional<std::string> GetQueryParameterFromUri(const std::string_view uri, const std::string_view key)
674
107
{
675
    // find query in URI
676
107
    size_t start = uri.find('?');
677
107
    if (start == std::string::npos) return std::nullopt;
678
97
    size_t end = uri.find('#', start);
679
97
    if (end == std::string::npos) {
680
97
        end = uri.length();
681
97
    }
682
97
    const std::string_view query{uri.data() + start + 1, end - start - 1};
683
    // find requested parameter in query
684
97
    const std::vector<std::string_view> params{Split<std::string_view>(query, "&")};
685
124
    for (const std::string_view& param : params) {
686
124
        size_t delim = param.find('=');
687
124
        if (key == UrlDecode(param.substr(0, delim))) {
688
85
            if (delim == std::string::npos) {
689
0
                return "";
690
85
            } else {
691
85
                return std::string(UrlDecode(param.substr(delim + 1)));
692
85
            }
693
85
        }
694
124
    }
695
12
    return std::nullopt;
696
97
}
697
698
std::optional<std::string> HTTPRequest::GetHeader(const std::string_view hdr) const
699
184k
{
700
184k
    return m_headers.FindFirst(hdr);
701
184k
}
702
703
void HTTPRequest::WriteHeader(std::string&& hdr, std::string&& value)
704
186k
{
705
186k
    m_response_headers.Write(std::move(hdr), std::move(value));
706
186k
}
707
708
util::Expected<void, std::string> HTTPServer::BindAndStartListening(const CService& to)
709
2.33k
{
710
    // Create socket for listening for incoming connections
711
2.33k
    sockaddr_storage storage;
712
2.33k
    auto sa = reinterpret_cast<sockaddr*>(&storage);
713
2.33k
    socklen_t len{sizeof(storage)};
714
2.33k
    if (!to.GetSockAddr(sa, &len)) {
715
1
        return util::Unexpected{strprintf("Bind address family for %s not supported", to.ToStringAddrPort())};
716
1
    }
717
718
2.33k
    std::unique_ptr<Sock> sock{CreateSock(to.GetSAFamily(), SOCK_STREAM, IPPROTO_TCP)};
719
2.33k
    if (!sock) {
720
0
        return util::Unexpected{strprintf("Cannot create %s listen socket: %s",
721
0
                                          to.ToStringAddrPort(),
722
0
                                          NetworkErrorString(WSAGetLastError()))};
723
0
    }
724
725
#ifdef WIN32
726
    // Prevent another application from binding to the same address and port and
727
    // intercepting RPC credentials.
728
    // SO_REUSEADDR on Windows is non-exclusive so another process could bind to
729
    // the same port.
730
    if (sock->SetSockOpt(SOL_SOCKET, SO_EXCLUSIVEADDRUSE, &SOCKET_OPTION_TRUE, sizeof(SOCKET_OPTION_TRUE)) == SOCKET_ERROR) {
731
        return util::Unexpected{strprintf("Cannot set SO_EXCLUSIVEADDRUSE on %s listen socket: %s",
732
                                          to.ToStringAddrPort(),
733
                                          NetworkErrorString(WSAGetLastError()))};
734
    }
735
#else
736
    // Allow binding if the port is still in TIME_WAIT state after
737
    // the program was closed and restarted.
738
2.33k
    if (sock->SetSockOpt(SOL_SOCKET, SO_REUSEADDR, &SOCKET_OPTION_TRUE, sizeof(SOCKET_OPTION_TRUE)) == SOCKET_ERROR) {
739
0
        LogDebug(BCLog::HTTP,
740
0
                 "Cannot set SO_REUSEADDR on %s listen socket: %s, continuing anyway",
741
0
                 to.ToStringAddrPort(),
742
0
                 NetworkErrorString(WSAGetLastError()));
743
0
    }
744
2.33k
#endif
745
746
    // some systems don't have IPV6_V6ONLY but are always v6only; others do have the option
747
    // and enable it by default or not. Try to enable it, if possible.
748
2.33k
    if (to.IsIPv6()) {
749
1.16k
#ifdef IPV6_V6ONLY
750
1.16k
        if (sock->SetSockOpt(IPPROTO_IPV6, IPV6_V6ONLY, &SOCKET_OPTION_TRUE, sizeof(SOCKET_OPTION_TRUE)) == SOCKET_ERROR) {
751
0
            LogDebug(BCLog::HTTP,
752
0
                     "Cannot set IPV6_V6ONLY on %s listen socket: %s, continuing anyway",
753
0
                     to.ToStringAddrPort(),
754
0
                     NetworkErrorString(WSAGetLastError()));
755
0
        }
756
1.16k
#endif
757
#ifdef WIN32
758
        int prot_level{PROTECTION_LEVEL_UNRESTRICTED};
759
        if (sock->SetSockOpt(IPPROTO_IPV6,
760
                             IPV6_PROTECTION_LEVEL,
761
                             &prot_level,
762
                             sizeof(prot_level)) == SOCKET_ERROR) {
763
            LogDebug(BCLog::HTTP,
764
                     "Cannot set IPV6_PROTECTION_LEVEL on %s listen socket: %s, continuing anyway",
765
                     to.ToStringAddrPort(),
766
                     NetworkErrorString(WSAGetLastError()));
767
        }
768
#endif
769
1.16k
    }
770
771
2.33k
    if (sock->Bind(sa, len) == SOCKET_ERROR) {
772
0
        const int err{WSAGetLastError()};
773
0
        if (err == WSAEADDRINUSE) {
774
0
            return util::Unexpected{strprintf("Unable to bind to %s on this computer. %s is probably already running.",
775
0
                                              to.ToStringAddrPort(),
776
0
                                              CLIENT_NAME)};
777
0
        } else {
778
0
            return util::Unexpected{strprintf("Unable to bind to %s on this computer (bind returned error %s)",
779
0
                                              to.ToStringAddrPort(),
780
0
                                              NetworkErrorString(err))};
781
0
        }
782
0
    }
783
784
    // Listen for incoming connections
785
2.33k
    if (sock->Listen(SOMAXCONN) == SOCKET_ERROR) {
786
0
        return util::Unexpected{strprintf("Cannot listen on %s: %s",
787
0
                                          to.ToStringAddrPort(),
788
0
                                          NetworkErrorString(WSAGetLastError()))};
789
0
    }
790
791
2.33k
    m_listen.emplace_back(std::move(sock));
792
793
2.33k
    return {};
794
2.33k
}
795
796
void HTTPServer::StopListening()
797
1.17k
{
798
1.17k
    m_listen.clear();
799
1.17k
}
800
801
void HTTPServer::StartSocketsThreads()
802
1.15k
{
803
    // The socket handler reads m_allow_subnets in ClientAllowed(). InitHTTPAllowList()
804
    // must have populated it first; localhost entries are always added, so an empty
805
    // list means it was never called and every connection is rejected.
806
1.15k
    Assume(!m_allow_subnets.empty());
807
808
1.15k
    m_thread_socket_handler = std::thread(&util::TraceThread,
809
1.15k
                                          "http",
810
1.15k
                                          [this] { ThreadSocketHandler(); });
811
1.15k
}
812
813
void HTTPServer::JoinSocketsThreads()
814
1.17k
{
815
1.17k
    if (m_thread_socket_handler.joinable()) {
816
1.15k
        m_thread_socket_handler.join();
817
1.15k
    }
818
1.17k
}
819
820
std::unique_ptr<Sock> HTTPServer::AcceptConnection(const Sock& listen_sock, CService& addr)
821
6.94k
{
822
    // Make sure we only operate on our own listening sockets
823
6.94k
    Assume(std::ranges::any_of(m_listen, [&](const auto& sock) { return sock.get() == &listen_sock; }));
824
825
6.94k
    sockaddr_storage storage;
826
6.94k
    socklen_t len{sizeof(storage)};
827
6.94k
    auto sa = reinterpret_cast<sockaddr*>(&storage);
828
829
6.94k
    auto sock{listen_sock.Accept(sa, &len)};
830
831
6.94k
    if (!sock) {
832
3.42k
        const int err{WSAGetLastError()};
833
3.42k
        if (err != WSAEWOULDBLOCK) {
834
0
            LogDebug(BCLog::HTTP,
835
0
                     "Cannot accept new connection: %s",
836
0
                     NetworkErrorString(err));
837
0
        }
838
3.42k
        return {};
839
3.42k
    }
840
841
    // The OS handed us a valid socket but we can't determine its source address.
842
3.52k
    if (!addr.SetSockAddr(sa, len)) {
843
0
        LogDebug(BCLog::HTTP,
844
0
                 "Unknown socket family");
845
0
    }
846
847
    // Early address-based allow check
848
3.52k
    if (!ClientAllowed(addr)) {
849
2
        LogDebug(BCLog::HTTP, "Connection from %s rejected: Client network is not allowed HTTP access\n",
850
2
                 addr.ToStringAddrPort());
851
        // Socket destroyed, connection aborted
852
2
        return {};
853
2
    }
854
855
3.52k
    return sock;
856
3.52k
}
857
858
HTTPServer::Id HTTPServer::GetNewId()
859
3.52k
{
860
3.52k
    return m_next_id.fetch_add(1, std::memory_order_relaxed);
861
3.52k
}
862
863
void HTTPServer::NewSockAccepted(std::unique_ptr<Sock>&& sock, const CService& addr)
864
3.52k
{
865
3.52k
    if (!sock->IsSelectable()) {
866
0
        LogDebug(BCLog::HTTP,
867
0
                 "connection from %s dropped: non-selectable socket",
868
0
                 addr.ToStringAddrPort());
869
0
        return;
870
0
    }
871
872
    // According to the internet TCP_NODELAY is not carried into accepted sockets
873
    // on all platforms.  Set it again here just to be sure.
874
3.52k
    if (sock->SetSockOpt(IPPROTO_TCP, TCP_NODELAY, &SOCKET_OPTION_TRUE, sizeof(SOCKET_OPTION_TRUE)) == SOCKET_ERROR) {
875
0
        LogDebug(BCLog::HTTP, "connection from %s: unable to set TCP_NODELAY, continuing anyway",
876
0
                 addr.ToStringAddrPort());
877
0
    }
878
879
3.52k
    const Id id{GetNewId()};
880
881
3.52k
    m_connected.push_back(std::make_shared<HTTPRemoteClient>(id, addr, std::move(sock)));
882
    // Report back to the main thread
883
3.52k
    m_connected_size.fetch_add(1, std::memory_order_relaxed);
884
885
3.52k
    LogDebug(BCLog::HTTP,
886
3.52k
             "HTTP Connection accepted from %s (id=%llu)",
887
3.52k
             addr.ToStringAddrPort(), id);
888
3.52k
}
889
890
void HTTPServer::SocketHandlerConnected(const IOReadiness& io_readiness) const
891
449k
{
892
1.58M
    for (const auto& [sock, events] : io_readiness.events_per_sock) {
893
1.58M
        if (m_interrupt_net) {
894
1.14k
            return;
895
1.14k
        }
896
897
1.58M
        auto it{io_readiness.httpclients_per_sock.find(sock)};
898
1.58M
        if (it == io_readiness.httpclients_per_sock.end()) {
899
895k
            continue;
900
895k
        }
901
691k
        const std::shared_ptr<HTTPRemoteClient>& client{it->second};
902
903
691k
        bool send_ready = events.occurred & Sock::SendEvent;
904
691k
        bool recv_ready = events.occurred & Sock::RecvEvent;
905
691k
        bool err_ready = events.occurred & Sock::ErrorEvent;
906
907
691k
        if (send_ready) {
908
            // Try to send as much data as is ready for this client.
909
            // If there's an error we can skip the receive phase for this client
910
            // because we need to disconnect.
911
31
            if (!client->MaybeSendBytesFromBuffer()) {
912
0
                recv_ready = false;
913
0
            }
914
31
        }
915
916
691k
        if (recv_ready || err_ready) {
917
268k
            client->Receive();
918
268k
        }
919
        // Process as much received data as we can.
920
        // This executes for every client whether or not reading or writing
921
        // took place because it also (might) parse a request we have already
922
        // received and pass it to a worker thread.
923
691k
        if (std::unique_ptr<HTTPRequest> request{HTTPRemoteClient::TryReadRequest(client)})
924
186k
        {
925
186k
            LOCK(m_request_dispatcher_mutex);
926
186k
            m_request_dispatcher(std::move(request));
927
186k
        }
928
691k
    }
929
449k
}
930
931
void HTTPRemoteClient::Receive()
932
268k
{
933
268k
    char buf[0x10000]; // typical socket buffer is 8K-64K
934
935
268k
    const ssize_t nrecv{WITH_LOCK(
936
268k
        m_sock_mutex,
937
268k
        return m_sock->Recv(buf, sizeof(buf), MSG_DONTWAIT);)};
938
939
268k
    if (nrecv < 0) {
940
1
        const int err = WSAGetLastError();
941
1
        if (IOErrorIsPermanent(err)) {
942
1
            LogDebug(
943
1
                BCLog::HTTP,
944
1
                "Permanent read error from %s (id=%llu): %s",
945
1
                m_origin,
946
1
                m_id,
947
1
                NetworkErrorString(err));
948
1
            m_disconnect = true;
949
1
        }
950
268k
    } else if (nrecv == 0) {
951
2.35k
        LogDebug(
952
2.35k
            BCLog::HTTP,
953
2.35k
            "Received EOF from %s (id=%llu)",
954
2.35k
            m_origin,
955
2.35k
            m_id);
956
2.35k
        m_disconnect = true;
957
265k
    } else {
958
        // Reset idle timeout
959
265k
        m_idle_since = Now<SteadySeconds>();
960
961
        // Prevent disconnect until all requests are completely handled.
962
265k
        m_connection_busy = true;
963
964
        // Copy data from socket buffer to client receive buffer
965
265k
        m_recv_buffer.insert(
966
265k
            m_recv_buffer.end(),
967
265k
            buf,
968
265k
            buf + nrecv);
969
265k
    }
970
268k
}
971
972
void HTTPServer::SocketHandlerListening(const Sock::EventsPerSock& events_per_sock)
973
449k
{
974
449k
    if (m_stop_accepting) return;
975
894k
    for (const auto& sock : m_listen) {
976
894k
        if (m_interrupt_net) {
977
3
            return;
978
3
        }
979
894k
        const auto it = events_per_sock.find(sock);
980
894k
        if (it != events_per_sock.end() && it->second.occurred & Sock::RecvEvent) {
981
            // Drain all pending connections from this socket up to the limit.
982
            // Stop early if the kernel queue is empty (AcceptConnection returns null)
983
            // or if accepting the last connection brought us to the limit.
984
6.95k
            while (GetConnectionsCount() < static_cast<size_t>(m_rpcmaxconnections)) {
985
6.94k
                CService addr_accepted;
986
6.94k
                auto sock_accepted{AcceptConnection(*sock, addr_accepted)};
987
6.94k
                if (!sock_accepted) break;
988
3.52k
                NewSockAccepted(std::move(sock_accepted), addr_accepted);
989
3.52k
            }
990
3.43k
        }
991
894k
    }
992
447k
}
993
994
HTTPServer::IOReadiness HTTPServer::GenerateWaitSockets() const
995
449k
{
996
449k
    IOReadiness io_readiness;
997
998
    // If the server is already handling its max connected clients count,
999
    // don't bother checking the listening sockets for new inbound connections.
1000
    // Leave them in the kernel's queue until space in the application opens
1001
    // up (or the client times out on its own).
1002
449k
    if (GetConnectionsCount() < static_cast<size_t>(m_rpcmaxconnections)) {
1003
898k
        for (const auto& sock : m_listen) {
1004
898k
            io_readiness.events_per_sock.emplace(sock, Sock::Events{Sock::RecvEvent});
1005
898k
        }
1006
449k
    }
1007
1008
691k
    for (const auto& http_client : m_connected) {
1009
        // Safely copy the shared pointer to the socket
1010
691k
        std::shared_ptr<Sock> sock{http_client->GetSock()};
1011
1012
        // Event choice:
1013
        //   1. ReadyToSend() (m_send_ready set) -> Send
1014
        //      m_send_ready stays set while the send buffer still has data to
1015
        //      drain, so we keep sending and do not Recv. This is also how the
1016
        //      send-throttle applies backpressure: while the send buffer is
1017
        //      full, TryReadRequest() holds a completed request back from a
1018
        //      worker, so nothing new is read until send has drained.
1019
        //   2. Else, m_req is incomplete and needs more data, or there is no
1020
        //      m_req at all and the recv buffer is empty -> Recv
1021
        //   3. Else (no parse in progress, leftover bytes in m_recv_buffer) -> 0
1022
        //      Stay in the I/O map so TryReadRequest() drains the buffer first.
1023
        //      Extra pipelined data waits in the kernel socket buffer
1024
        //      (TCP backpressure), not in m_recv_buffer.
1025
        //
1026
        // Lock-order safety: the convention established by
1027
        // MaybeSendBytesFromBuffer() is to take m_send_mutex before m_sock_mutex.
1028
        // In this loop GetSock() (above) takes m_sock_mutex and ReadyToSend()
1029
        // (below) takes m_send_mutex; both are scoped, so each lock is released
1030
        // before the next is taken and they stay separate critical sections.
1031
        // Holding m_sock_mutex while acquiring m_send_mutex would invert that
1032
        // order and risk a lock-order-inversion deadlock.
1033
691k
        Sock::Event event{0};
1034
691k
        if (http_client->ReadyToSend()) {
1035
343
            event = Sock::SendEvent;
1036
691k
        } else if (http_client->GetRequest() != nullptr || http_client->ReceiveBufferEmpty()) {
1037
            // Mid-parse (need more bytes) or buffer empty.
1038
679k
            event = Sock::RecvEvent;
1039
679k
        }
1040
1041
691k
        io_readiness.events_per_sock.emplace(sock, Sock::Events{event});
1042
691k
        io_readiness.httpclients_per_sock.emplace(sock, http_client);
1043
691k
    }
1044
1045
449k
    return io_readiness;
1046
449k
}
1047
1048
/// \anchor http
1049
void HTTPServer::ThreadSocketHandler()
1050
1.15k
{
1051
450k
    while (!m_interrupt_net) {
1052
        // Check for the readiness of the already connected sockets and the
1053
        // listening sockets in one call ("readiness" as in poll(2) or
1054
        // select(2)). If none are ready, wait for a short while and return
1055
        // empty sets.
1056
449k
        auto io_readiness{GenerateWaitSockets()};
1057
449k
        if (io_readiness.events_per_sock.empty() ||
1058
            // WaitMany() may as well be a static method, the context of the first Sock in the vector is not relevant.
1059
449k
            !io_readiness.events_per_sock.begin()->first->WaitMany(SELECT_TIMEOUT,
1060
449k
                                                                   io_readiness.events_per_sock)) {
1061
0
            m_interrupt_net.sleep_for(SELECT_TIMEOUT);
1062
0
        }
1063
1064
        // Service (send/receive) each of the already connected sockets.
1065
449k
        SocketHandlerConnected(io_readiness);
1066
1067
        // Accept new connections from listening sockets.
1068
449k
        SocketHandlerListening(io_readiness.events_per_sock);
1069
1070
        // Disconnect any clients that have been flagged.
1071
449k
        DisconnectClients();
1072
449k
    }
1073
1.15k
}
1074
1075
std::unique_ptr<HTTPRequest> HTTPRemoteClient::TryReadRequest(const std::shared_ptr<HTTPRemoteClient>& client)
1076
691k
{
1077
    // If we are already handling a request from
1078
    // this client, do nothing. We'll check again on the next I/O
1079
    // loop iteration.
1080
691k
    if (client->m_req_busy) return nullptr;
1081
1082
523k
    if (!client->m_req) {
1083
189k
        client->m_req = std::make_unique<HTTPRequest>(client);
1084
189k
    }
1085
1086
523k
    try {
1087
        // Read data from the buffer into the current request
1088
523k
        client->ReadRequest(*client->m_req);
1089
523k
    } catch (const ContentTooLargeError& e) {
1090
3
        LogDebug(
1091
3
            BCLog::HTTP,
1092
3
            "HTTP request body too large from client %s (id=%llu): %s",
1093
3
            client->m_origin,
1094
3
            client->m_id,
1095
3
            e.what());
1096
1097
3
        WriteNoStoreErrorReply(*client->m_req, HTTP_CONTENT_TOO_LARGE);
1098
3
        client->m_disconnect = true;
1099
3
        return nullptr;
1100
14
    } catch (const std::runtime_error& e) {
1101
14
        LogDebug(
1102
14
            BCLog::HTTP,
1103
14
            "Error reading HTTP request from client %s (id=%llu): %s",
1104
14
            client->m_origin,
1105
14
            client->m_id,
1106
14
            e.what());
1107
1108
        // We failed to read a complete request from the buffer
1109
14
        WriteNoStoreErrorReply(*client->m_req, HTTP_BAD_REQUEST);
1110
14
        client->m_disconnect = true;
1111
14
        return nullptr;
1112
14
    }
1113
1114
    // If the request is ready, hand it to a worker.
1115
523k
    if (client->m_req->GetState() == HTTPRequest::State::Complete) {
1116
        // Unless this client's send buffer is full: in that case hold the
1117
        // parsed request here instead of moving it to a worker. This prevents
1118
        // the server from reading any more data from this client until they
1119
        // drain their end of the socket, and prevents the server from packing
1120
        // more responses into the send buffer.
1121
186k
        const size_t buffer_used{WITH_LOCK(
1122
186k
            client->m_send_mutex,
1123
186k
            return client->m_send_buffer.size();)};
1124
186k
        if (buffer_used > MAX_BODY_SIZE) return nullptr;
1125
186k
        LogDebug(
1126
186k
            BCLog::HTTP,
1127
186k
            "Received a %s request for %s from %s (id=%llu)",
1128
186k
            RequestMethodString(client->m_req->GetRequestMethod()),
1129
186k
            client->m_req->GetURI(),
1130
186k
            client->m_origin,
1131
186k
            client->m_id);
1132
1133
186k
        client->m_req_busy = true;
1134
186k
        return std::move(client->m_req);
1135
186k
    }
1136
1137
337k
    return nullptr;
1138
523k
}
1139
1140
void HTTPServer::DisconnectClients()
1141
449k
{
1142
449k
    const auto now{Now<SteadySeconds>()};
1143
449k
    size_t erased = std::erase_if(m_connected,
1144
695k
                                  [&](auto& client) {
1145
695k
                                      return client->MaybeDisconnect(now,
1146
695k
                                                                     m_rpcservertimeout,
1147
695k
                                                                     /*disconnect_all=*/m_disconnect_all_clients);
1148
695k
                                  });
1149
449k
    if (erased > 0) {
1150
        // Report back to the main thread
1151
3.30k
        m_connected_size.fetch_sub(erased, std::memory_order_relaxed);
1152
3.30k
    }
1153
449k
}
1154
1155
bool HTTPRemoteClient::MaybeDisconnect(std::chrono::time_point<SteadyClock> now, std::chrono::seconds rpcservertimeout, bool disconnect_all)
1156
695k
{
1157
    // First check for idle timeout. We reset the timer when we send and receive data,
1158
    // but if the server is busy handling a request we should ignore the timeout until
1159
    // the reply is sent. If we did erase the shared_ptr<HTTPRemoteClient> reference in m_connected
1160
    // while the server is busy with a request, it might be prematurely dropped before
1161
    // the response has been sent, or if the HTTPRequest was holding a temporary shared_ptr
1162
    // client on a worker thread - it would keep the socket open even after "disconnecting".
1163
695k
    const bool is_idle{rpcservertimeout.count() > 0 &&
1164
695k
                       now - m_idle_since.load() > rpcservertimeout &&
1165
695k
                       !m_req_busy};
1166
1167
    // Disconnect this client due to error, end of communication, or idle timeout.
1168
    // May drop unsent data if we are closing due to error.
1169
695k
    if (m_disconnect || is_idle) {
1170
2.49k
        if (is_idle) {
1171
5
            LogDebug(BCLog::HTTP,
1172
5
                     "HTTP client idle timeout %s (id=%llu)",
1173
5
                     m_origin,
1174
5
                     m_id);
1175
5
        }
1176
692k
    } else {
1177
        // Disconnect this client because the server is shutting
1178
        // down and we need to disconnect all clients...
1179
692k
        if (disconnect_all) {
1180
            // ...unless we still have data for this client.
1181
1.09k
            if (m_connection_busy) {
1182
                // There is still data for this healthy-connected client.
1183
                // Continue the I/O loop until all data is sent or an error is encountered.
1184
64
                return false;
1185
1.02k
            } else {
1186
                // This is a healthy persistent connection (e.g. keep-alive)
1187
                // but it's time to say goodbye.
1188
1.02k
                ;
1189
1.02k
            }
1190
691k
        } else {
1191
            // No reason to disconnect.
1192
691k
            return false;
1193
691k
        }
1194
692k
    }
1195
    // No reason NOT to disconnect, log and remove.
1196
3.52k
    LogDebug(BCLog::HTTP,
1197
3.52k
             "Disconnecting HTTP client %s (id=%llu)",
1198
3.52k
             m_origin,
1199
3.52k
             m_id);
1200
3.52k
    return true;
1201
695k
}
1202
1203
void HTTPServer::ClearConnectedClients()
1204
1.16k
{
1205
1.16k
    Assume(!m_thread_socket_handler.joinable()); // must be called after JoinSocketsThreads()
1206
1.16k
    if (m_connected.empty()) return;
1207
0
    LogWarning("Force-disconnecting %d HTTP client(s) that did not disconnect gracefully", m_connected.size());
1208
0
    m_connected_size.fetch_sub(m_connected.size(), std::memory_order_relaxed);
1209
0
    m_connected.clear();
1210
0
}
1211
1212
void HTTPRemoteClient::ReadRequest(HTTPRequest& req)
1213
523k
{
1214
523k
    if (m_recv_buffer.empty()) return;
1215
1216
266k
    LineReader reader(m_recv_buffer, MAX_HEADERS_SIZE);
1217
1218
266k
    try {
1219
266k
        switch (req.GetState()) {
1220
186k
        case HTTPRequest::State::Init:
1221
186k
            if (!req.LoadControlData(reader)) break;
1222
186k
            req.SetState(HTTPRequest::State::NeedsHeaders);
1223
186k
            [[fallthrough]];
1224
1225
186k
        case HTTPRequest::State::NeedsHeaders:
1226
186k
            if (!req.LoadHeaders(reader)) break;
1227
186k
            req.SetState(HTTPRequest::State::NeedsBody);
1228
186k
            [[fallthrough]];
1229
1230
265k
        case HTTPRequest::State::NeedsBody:
1231
265k
            if (!req.LoadBody(reader)) break;
1232
186k
            req.SetState(HTTPRequest::State::Complete);
1233
186k
            [[fallthrough]];
1234
1235
186k
        case HTTPRequest::State::Complete:
1236
186k
            break;
1237
1238
1
        case HTTPRequest::State::Error:
1239
1
            break;
1240
266k
        }
1241
266k
    } catch (...) {
1242
        // Don't try to read any more data for this request
1243
17
        req.SetState(HTTPRequest::State::Error);
1244
        // Clear the memory allocated to this client, caller must disconnect
1245
17
        m_recv_buffer.clear();
1246
17
        throw;
1247
17
    }
1248
1249
    // Remove the bytes read out of the buffer.
1250
266k
    m_recv_buffer.erase(
1251
266k
        m_recv_buffer.begin(),
1252
266k
        m_recv_buffer.begin() + reader.Consumed());
1253
266k
}
1254
1255
bool HTTPRemoteClient::MaybeSendBytesFromBuffer()
1256
186k
{
1257
    // Send as much data from this client's buffer as we can
1258
186k
    LOCK(m_send_mutex);
1259
186k
    if (!m_send_buffer.empty()) {
1260
        // Socket flags (See kernel docs for send(2) and tcp(7) for more details).
1261
        // MSG_NOSIGNAL: If the remote end of the connection is closed,
1262
        //               fail with EPIPE (an error) as opposed to triggering
1263
        //               SIGPIPE which terminates the process.
1264
        // MSG_DONTWAIT: Makes the send operation non-blocking regardless of socket blocking mode.
1265
        // MSG_MORE:     We do not set this flag here because http responses are usually
1266
        //               small and we want the kernel to send them right away. Setting MSG_MORE
1267
        //               would "cork" the socket to prevent sending out partial frames.
1268
186k
        int flags{MSG_NOSIGNAL | MSG_DONTWAIT};
1269
1270
        // Try to send bytes through socket
1271
186k
        ssize_t bytes_sent;
1272
186k
        {
1273
186k
            LOCK(m_sock_mutex);
1274
186k
            bytes_sent = m_sock->Send(m_send_buffer.data(),
1275
186k
                                      m_send_buffer.size(),
1276
186k
                                      flags);
1277
186k
        }
1278
1279
186k
        if (bytes_sent < 0) {
1280
            // Something went wrong
1281
2
            const int err{WSAGetLastError()};
1282
2
            if (!IOErrorIsPermanent(err)) {
1283
                // The error can be safely ignored, try the send again on the next I/O loop.
1284
2
                m_send_ready = true;
1285
2
                m_connection_busy = true;
1286
2
                return true;
1287
2
            } else {
1288
                // Unrecoverable error, log and disconnect client.
1289
0
                LogDebug(
1290
0
                    BCLog::HTTP,
1291
0
                    "Error sending HTTP response data to client %s (id=%llu): %s",
1292
0
                    m_origin,
1293
0
                    m_id,
1294
0
                    NetworkErrorString(err));
1295
0
                m_send_ready = false;
1296
0
                m_disconnect = true;
1297
1298
                // Do not attempt to read from this client.
1299
0
                return false;
1300
0
            }
1301
2
        }
1302
1303
        // Successful send, remove sent bytes from our local buffer.
1304
186k
        Assume(static_cast<size_t>(bytes_sent) <= m_send_buffer.size());
1305
186k
        m_send_buffer.erase(m_send_buffer.begin(),
1306
186k
                            m_send_buffer.begin() + bytes_sent);
1307
1308
186k
        LogDebug(
1309
186k
            BCLog::HTTP,
1310
186k
            "Sent %d bytes to client %s (id=%llu)",
1311
186k
            bytes_sent,
1312
186k
            m_origin,
1313
186k
            m_id);
1314
1315
        // This check is inside the if(!empty) block meaning "there was data but now its gone".
1316
        // We wouldn't want to change the flags if MaybeSendBytesFromBuffer() was called
1317
        // on an already-empty m_send_buffer because the connection might have just been opened.
1318
186k
        if (m_send_buffer.empty()) {
1319
186k
            m_send_ready = false;
1320
186k
            m_connection_busy = false;
1321
1322
            // Our work is done here
1323
186k
            if (!m_keep_alive) {
1324
1.11k
                m_disconnect = true;
1325
                // Do not attempt to read from this client.
1326
1.11k
                return false;
1327
1.11k
            }
1328
186k
        } else {
1329
            // The send buffer isn't flushed yet, try to push more on the next loop.
1330
30
            m_send_ready = true;
1331
30
            m_connection_busy = true;
1332
30
        }
1333
1334
        // Finally, reset idle timeout
1335
185k
        m_idle_since = Now<SteadySeconds>();
1336
185k
    }
1337
1338
185k
    return true;
1339
186k
}
1340
1341
bool InitHTTPServer()
1342
1.16k
{
1343
    // Create HTTPServer
1344
1.16k
    g_http_server = std::make_unique<HTTPServer>(MaybeDispatchRequestToWorker);
1345
1346
1.16k
    if (!g_http_server->InitHTTPAllowList()) {
1347
1
        return false;
1348
1
    }
1349
1350
1.16k
    g_http_server->SetServerTimeout(std::chrono::seconds(gArgs.GetIntArg("-rpcservertimeout", DEFAULT_HTTP_SERVER_TIMEOUT)));
1351
1.16k
    g_http_server->SetMaxConnections(std::max(gArgs.GetArg<int>("-rpcmaxconnections", DEFAULT_MAX_HTTP_CONNECTIONS), 1));
1352
1353
    // Bind HTTP server to specified addresses
1354
1.16k
    std::vector<std::pair<std::string, uint16_t>> endpoints{GetBindAddresses()};
1355
1.16k
    bool bind_success{false};
1356
2.33k
    for (const auto& [address_string, port] : endpoints) {
1357
2.33k
        LogInfo("Binding RPC on address %s port %i", address_string, port);
1358
2.33k
        const std::optional<CService> addr{Lookup(address_string, port, false)};
1359
2.33k
        if (addr) {
1360
2.33k
            if (addr->IsBindAny()) {
1361
0
                LogWarning("The RPC server is not safe to expose to untrusted networks such as the public internet");
1362
0
            }
1363
2.33k
            auto result{g_http_server->BindAndStartListening(addr.value())};
1364
2.33k
            if (!result) {
1365
0
                LogWarning("Binding RPC on address %s failed: %s", addr->ToStringAddrPort(), result.error());
1366
2.33k
            } else {
1367
2.33k
                bind_success = true;
1368
2.33k
            }
1369
2.33k
        } else {
1370
0
            LogWarning("Could not bind RPC on address %s port %i: Address lookup failed.", address_string, port);
1371
0
        }
1372
2.33k
    }
1373
1374
1.16k
    if (!bind_success) {
1375
0
        LogError("Unable to bind any endpoint for RPC server");
1376
0
        return false;
1377
0
    }
1378
1379
1.16k
    LogDebug(BCLog::HTTP, "Initialized HTTP server");
1380
1381
1.16k
    g_max_queue_depth = std::max(gArgs.GetArg<int>("-rpcworkqueue", DEFAULT_HTTP_WORKQUEUE), 1);
1382
1.16k
    LogDebug(BCLog::HTTP, "set work queue of depth %d\n", g_max_queue_depth);
1383
1384
1.16k
    return true;
1385
1.16k
}
1386
1387
void StartHTTPServer()
1388
1.15k
{
1389
1.15k
    auto rpcThreads{std::max(gArgs.GetArg<int>("-rpcthreads", DEFAULT_HTTP_THREADS), 1)};
1390
1.15k
    LogInfo("Starting HTTP server with %d worker threads", rpcThreads);
1391
1.15k
    g_threadpool_http.Start(rpcThreads);
1392
1.15k
    g_http_server->StartSocketsThreads();
1393
1.15k
}
1394
1395
void InterruptHTTPServer()
1396
1.21k
{
1397
1.21k
    LogDebug(BCLog::HTTP, "Interrupting HTTP server");
1398
1.21k
    if (g_http_server) {
1399
        // Reject all new requests
1400
1.16k
        g_http_server->SetRequestHandler(RejectRequest);
1401
1.16k
    }
1402
1403
    // Interrupt pool after disabling requests
1404
1.21k
    g_threadpool_http.Interrupt();
1405
1.21k
}
1406
1407
void StopHTTPServer()
1408
1.21k
{
1409
1.21k
    LogDebug(BCLog::HTTP, "Stopping HTTP server");
1410
1411
1.21k
    LogDebug(BCLog::HTTP, "Waiting for HTTP worker threads to exit\n");
1412
1.21k
    g_threadpool_http.Stop();
1413
1414
1.21k
    if (g_http_server) {
1415
        // Must precede DisconnectAllClients(): a connection accepted after
1416
        // GetConnectionsCount() returns 0 would survive into the destructor.
1417
1.16k
        g_http_server->StopAccepting();
1418
        // Disconnect clients as their remaining responses are flushed
1419
1.16k
        g_http_server->DisconnectAllClients();
1420
        // Wait 30 seconds for all disconnections
1421
1.16k
        LogDebug(BCLog::HTTP, "Waiting for HTTP clients to disconnect gracefully");
1422
1.16k
        const auto deadline{NodeClock::now() + 30s};
1423
2.20k
        while (g_http_server->GetConnectionsCount() != 0) {
1424
1.03k
            if (NodeClock::now() > deadline) {
1425
0
                LogWarning("Timeout waiting for HTTP clients to disconnect gracefully, continuing shutdown");
1426
0
                break;
1427
0
            }
1428
1.03k
            std::this_thread::sleep_for(50ms);
1429
1.03k
        }
1430
        // Break HTTPServer I/O loop: stop accepting connections, sending and receiving data
1431
1.16k
        g_http_server->InterruptNet();
1432
        // Wait for HTTPServer I/O thread to exit
1433
1.16k
        g_http_server->JoinSocketsThreads();
1434
        // Force-remove any clients that survived the graceful wait
1435
1.16k
        g_http_server->ClearConnectedClients();
1436
        // Close all listening sockets
1437
1.16k
        g_http_server->StopListening();
1438
1.16k
    }
1439
1.21k
    LogDebug(BCLog::HTTP, "Stopped HTTP server");
1440
1.21k
}