1
0
Fork 0
mirror of https://github.com/klzgrad/naiveproxy.git synced 2025-04-09 12:12:03 +00:00
Commit graph

28 commits

Author SHA1 Message Date
klzgrad
18db8a5d7e net: Allow http proxies in proxy chains 2025-04-04 09:40:47 +08:00
klzgrad
3118cee01b net/socket: Use SO_REUSEPORT for server sockets 2025-04-04 09:40:47 +08:00
klzgrad
94098d6477 net/socket: Force tunneling for all sockets
In the socket system, only WebSocket sockets are allowed to tunnel
through HTTP/1 proxies. "Raw" sockets in the normal socket pool don't
have it, and their CONNECT headers are not sent, instead the raw
payload is sent as-is to the HTTP/1 proxy, breaking the proxying.

The socket system works like this:

- HTTP sockets via HTTP/1 proxies: normal pool, no tunneling.
- HTTPS sockets via HTTP/1 proxies: normal pool, no tunneling,
  but does its own proxy encapsulation.
- WS sockets via HTTP/1 proxies: WS pool, tunneling.

In Naive, we need the normal pool because the WS pool has some extra
restrictions but we also need tunneling to produce a client socket
with proxy tunneling built in.

Therefore force tunneling for all sockets and have them always send
CONNECT headers. This will otherwise break regular HTTP client sockets
via HTTP/1 proxies, but as we don't use this combination, it is ok.
2025-04-04 09:40:47 +08:00
klzgrad
4b7a7d6f9a net/socket: Allow higher limits for proxies
As an intermediary proxy we should not enforce stricter connection
limits in addition to what the user is already enforcing.
2025-04-04 09:40:47 +08:00
klzgrad
bd37b294a0 net/cert: Fix iwyu 2025-04-04 09:40:47 +08:00
klzgrad
652ea88607 net/cert: Handle AIA response in PKCS#7 format 2025-04-04 09:40:47 +08:00
klzgrad
b7a9331b59 net/cert: Use builtin verifier on Android and Linux 2025-04-04 09:40:47 +08:00
klzgrad
ae1b3b76c7 net/cert: Add SystemTrustStoreStaticUnix
It reads CA certificates from:

* The file in environment variable SSL_CERT_FILE
* The first available file of

/etc/ssl/certs/ca-certificates.crt (Debian/Ubuntu/Gentoo etc.)
/etc/pki/tls/certs/ca-bundle.crt (Fedora/RHEL 6)
/etc/ssl/ca-bundle.pem (OpenSUSE)
/etc/pki/tls/cacert.pem (OpenELEC)
/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem (CentOS/RHEL 7)
/etc/ssl/cert.pem (Alpine Linux)

* Files in the directory of environment variable SSL_CERT_DIR
* Files in the first available directory of

/etc/ssl/certs (SLES10/SLES11, https://golang.org/issue/12139)
/etc/pki/tls/certs (Fedora/RHEL)
/system/etc/security/cacerts (Android)
2025-04-04 09:40:47 +08:00
klzgrad
8b2cb3d398 libc++: Fix assertion handler 2025-04-04 09:40:47 +08:00
klzgrad
e0085bb5ab libc++: Disable exceptions and RTTI
Except on Mac, where exceptions are required.
And except on Android, where rtti is required.
2025-04-04 09:40:47 +08:00
klzgrad
a1072f7b27 base: Don't fix Y2038 problem with icu 2025-04-04 09:40:47 +08:00
klzgrad
2271c4d54e net, url: Remove icu 2025-04-04 09:40:47 +08:00
klzgrad
f6c6ee6761 base, crypto, net: Fix trace stubs 2025-04-04 09:40:47 +08:00
klzgrad
5d76af56a1 build: Minimize sysroot creator script 2025-04-04 09:40:47 +08:00
klzgrad
c90a00f739 build: Use thinlto max optimization for everything 2025-04-04 09:40:47 +08:00
klzgrad
293867100e build: Never explicitly link clang_rt.builtins
https://chromium-review.googlesource.com/c/chromium/src/+/5723176
2025-04-04 09:40:47 +08:00
klzgrad
e293a08161 build: Force determinism in official build
Helps build with ccache.
2025-04-04 09:40:47 +08:00
klzgrad
15235657e4 build: Disable build_with_chromium
The argument build_with_chromium mainly enables various tests,
data bundling, infra integration, and AFDO profiles.

AFDO can be added by other arguments.
2025-04-04 09:40:47 +08:00
klzgrad
5f3417b6d4 android: base: Fix build adding extra -latomic
We don't use use_sysroot=true, but without it -latomic is added
to is_android.
2025-04-04 09:40:47 +08:00
klzgrad
f7ac6b5c15 android: build: Disable Android java templates 2025-04-04 09:40:47 +08:00
klzgrad
c2fe4acf55 android: url: Remove Android 2025-04-04 09:40:47 +08:00
klzgrad
171b384382 android: third_party/jni_zero: Remove JNI functions 2025-04-04 09:40:47 +08:00
klzgrad
e1e959e49c android: base: Add Android stubs 2025-04-04 09:40:47 +08:00
klzgrad
6238cf5ff0 android: net: Add Android stubs 2025-04-04 09:40:46 +08:00
klzgrad
1b0a5efb19 base: Remove Rust 2025-04-04 09:40:46 +08:00
klzgrad
4854dc2f37 build: Remove tests and minimize 2025-04-04 09:40:46 +08:00
klzgrad
ed59981830 Add .gitignore 2025-04-04 09:40:46 +08:00
importer
db893af208 Import chromium-135.0.7049.38 2025-04-04 09:40:46 +08:00