From 5d5e35fb9be0d7854febd1f22a45d403209fb966 Mon Sep 17 00:00:00 2001 From: "Alexander J. Semenuk" Date: Mon, 27 Jul 2026 19:19:18 -0400 Subject: [PATCH] fix: Windows toolchain compatibility (curl 8.21 re-vendor, endless reconfigure loop) (#4355) ## Problem Windows builds break with a current local toolchain (Scoop LLVM 22.1.8, CMake 4.4.0, VS 2026), in two independent ways: 1. The build stops at curl's deliberate guard: `#error "no non-blocking method was found/used/set"` in `third-party/curl/lib/nonblock.c`. 2. From the second configure onward, `cmake --build` re-runs CMake in an endless loop (observed 42 consecutive reconfigure cycles in a single build). Likely the same mechanism behind the "endlessly building" VS 2026 note in `docs/setup/dev/vs.md`. ## Root cause 1. `third-party/curl/CMake/CurlTests.c` passes `int *` to `ioctlsocket()`, whose third parameter is `u_long *`. Clang 22 promotes `-Wincompatible-pointer-types` to a hard error in C, so the `HAVE_IOCTLSOCKET_FIONBIO` try_compile silently fails and `curl_config.h` never defines it. Upstream CI does not see this because the windows-2022 runner image ships an older LLVM. GCC 14 promotes the same warning to a hard error, which is very likely the `CurlTests.c.obj` failure reported from MSYS2 in open-goal/jak-project#3551. Upstream curl hit the identical problem with GCC 14 and fixed the probe in curl 8.8.0 (curl/curl#13578). 2. The root CMakeLists copies the build tree's `compile_commands.json` into `/build/` for clangd using `configure_file()`, which registers its input as a configure dependency. CMake rewrites `compile_commands.json` late in every generation, after `CTestTestfile.cmake` and `cmake_install.cmake` (outputs of the same Ninja regen rule), so once the dependency is registered the rule is deterministically dirty and every `ninja` invocation re-runs CMake. A pristine first configure is safe (the file does not exist yet, so the `if(EXISTS ...)` guard skips the copy), which is why the loop looks machine- or IDE-specific. ## Fix 1. Per review, re-vendor `third-party/curl` at the `curl-8_21_0` tag (previously `curl-8_3_0`), which carries the upstream probe fix plus two years of upstream development; `vendor.yaml` updated to match. Adjustments the version jump forced: - curl 8.15 removed the native macOS Secure Transport backend (`CURL_USE_SECTRANSP`), so macOS now builds curl against OpenSSL like Linux. The two macOS workflows install Homebrew `openssl@3` and export `OPENSSL_ROOT_DIR` (keg-only), and the macOS setup docs gained the same two lines. - `CURL_BROTLI` / `CURL_ZSTD` switched to AUTO-detection in curl 8.10; pinned OFF to keep the previous no-compression behavior and avoid silently linking whatever the CI images happen to have. - curl's new top-level `BUILD_EXAMPLES` cache option (default ON) leaked into discord-rpc's identically named option and broke configure at a nonexistent `examples/send-presence` directory; pinned OFF ahead of the third-party subdirectories. The diff is dominated by the mechanical tag-tree swap under `third-party/curl` (linguist-vendored, collapsed in review). The hand-written changes are `CMakeLists.txt`, the two macOS workflows, `docs/setup/system/macos.md`, and `vendor.yaml`. 2. Swap `configure_file()` for `file(COPY ...)`: the same clangd copy with no configure dependency registered. (`file(COPY_FILE ... ONLY_IF_DIFFERENT)` would be cleaner still but requires CMake 3.21, above the declared `cmake_minimum_required(VERSION 3.10)`.) ## Test plan - [x] Fresh `cmake --preset Release-windows-clang` (LLVM 22, no cache seeding) completes and logs `Enabled SSL backends: Schannel`; the FIONBIO probe passes without the previous `#error` - [x] Full Windows Release build from scratch in the branch worktree (all 1422 targets) - [x] goalc-test suite: 1509 passed, 0 failed - [x] Second consecutive configure with `compile_commands.json` present: the regen rule in `build.ninja` has no `compile_commands.json` input; `/build/compile_commands.json` is still refreshed for clangd - [x] Repeated `ninja` invocations after a full build no longer re-run CMake - [x] macOS Intel and ARM CI green (first exercise of the OpenSSL backend switch) --- I work off a self-hosted forge, so this GitHub account is quiet; the configure logs and ninja dirty-node traces from the investigation are available if anyone wants the raw data. (AI-assisted) --- .github/workflows/macos-build-arm.yaml | 6 +- .github/workflows/macos-build.yaml | 6 +- CMakeLists.txt | 19 +- docs/setup/system/macos.md | 6 +- third-party/curl/.azure-pipelines.yml | 315 - third-party/curl/.circleci/config.yml | 424 +- third-party/curl/.cirrus.yml | 85 - third-party/curl/.clang-tidy.yml | 59 + third-party/curl/.dcignore | 7 - third-party/curl/.editorconfig | 18 + third-party/curl/.gitattributes | 6 +- third-party/curl/.github/CONTRIBUTING.md | 27 +- .../.github/ISSUE_TEMPLATE/bug_report.yml | 20 +- .../curl/.github/ISSUE_TEMPLATE/config.yml | 15 +- .../curl/.github/ISSUE_TEMPLATE/docs.yml | 43 + third-party/curl/.github/dependabot.yml | 38 + third-party/curl/.github/labeler.yml | 722 +- .../curl/.github/pull_request_template.md | 8 + third-party/curl/.github/scripts/cleancmd.pl | 130 + .../curl/.github/scripts/cleanspell.pl | 79 - .../curl/.github/scripts/cmp-config.pl | 136 + .../curl/.github/scripts/cmp-pkg-config.sh | 49 + .../.github/scripts/codespell-ignore.words | 21 + third-party/curl/.github/scripts/codespell.sh | 22 + third-party/curl/.github/scripts/distfiles.sh | 54 + .../curl/.github/scripts/pyspelling.words | 1023 +++ .../curl/.github/scripts/pyspelling.yaml | 33 + third-party/curl/.github/scripts/randcurl.pl | 251 + .../.github/scripts/requirements-docs.txt | 5 + .../scripts/requirements-proselint.txt | 5 + .../curl/.github/scripts/requirements.txt | 8 + .../curl/.github/scripts/shellcheck-ci.sh | 30 + .../curl/.github/scripts/shellcheck.sh | 13 + .../curl/.github/scripts/spellcheck.curl | 153 + .../curl/.github/scripts/spellcheck.words | 909 --- .../curl/.github/scripts/spellcheck.yaml | 32 - .../.github/scripts/trimmarkdownheader.pl | 44 + third-party/curl/.github/scripts/typos.sh | 14 + third-party/curl/.github/scripts/typos.toml | 36 + .../curl/.github/scripts/verify-examples.pl | 106 + .../curl/.github/scripts/verify-synopsis.pl | 87 + third-party/curl/.github/scripts/yamlcheck.sh | 15 + .../curl/.github/scripts/yamlcheck.yaml | 17 + third-party/curl/.github/stale.yml | 4 +- .../.github/workflows/appveyor-status.yml | 18 +- third-party/curl/.github/workflows/awslc.yml | 152 - .../curl/.github/workflows/checkdocs.yml | 135 + .../curl/.github/workflows/checksrc.yml | 214 + .../curl/.github/workflows/checkurls.yml | 43 + .../.github/workflows/codeql-analysis.yml | 80 - third-party/curl/.github/workflows/codeql.yml | 142 + .../.github/workflows/configure-vs-cmake.yml | 194 + .../curl/.github/workflows/curl-for-win.yml | 199 + .../curl/.github/workflows/distcheck.yml | 409 + third-party/curl/.github/workflows/fuzz.yml | 58 +- .../workflows/hacktoberfest-accepted.yml | 67 - .../curl/.github/workflows/http3-linux.yml | 894 +++ third-party/curl/.github/workflows/label.yml | 37 +- .../curl/.github/workflows/linkcheck.yml | 36 - .../curl/.github/workflows/linux-old.yml | 185 + third-party/curl/.github/workflows/linux.yml | 1258 +++- .../curl/.github/workflows/linux32.yml | 93 - third-party/curl/.github/workflows/macos.yml | 928 ++- .../curl/.github/workflows/ngtcp2-linux.yml | 279 - .../curl/.github/workflows/non-native.yml | 565 ++ .../curl/.github/workflows/proselint.yml | 68 - .../curl/.github/workflows/quiche-linux.yml | 209 - third-party/curl/.github/workflows/reuse.yml | 29 - .../curl/.github/workflows/spellcheck.yml | 66 - .../curl/.github/workflows/torture.yml | 92 - .../curl/.github/workflows/windows.yml | 1197 +++ .../curl/.github/workflows/wolfssl.yml | 105 - third-party/curl/.gitignore | 11 +- third-party/curl/.mailmap | 27 +- third-party/curl/.reuse/dep5 | 98 - third-party/curl/CHANGES | 7 - third-party/curl/CHANGES.md | 12 + .../curl/CMake/CMakeConfigurableFile.in | 24 - third-party/curl/CMake/CurlSymbolHiding.cmake | 92 +- third-party/curl/CMake/CurlTests.c | 459 +- third-party/curl/CMake/FindBearSSL.cmake | 32 - third-party/curl/CMake/FindBrotli.cmake | 79 +- third-party/curl/CMake/FindCARES.cmake | 123 +- third-party/curl/CMake/FindGSS.cmake | 410 +- third-party/curl/CMake/FindGnuTLS.cmake | 92 + third-party/curl/CMake/FindLDAP.cmake | 115 + third-party/curl/CMake/FindLibPSL.cmake | 79 +- third-party/curl/CMake/FindLibSSH2.cmake | 104 +- third-party/curl/CMake/FindLibbacktrace.cmake | 61 + third-party/curl/CMake/FindLibgsasl.cmake | 91 + third-party/curl/CMake/FindLibidn2.cmake | 92 + third-party/curl/CMake/FindLibssh.cmake | 118 + third-party/curl/CMake/FindLibuv.cmake | 102 + third-party/curl/CMake/FindMSH3.cmake | 70 - third-party/curl/CMake/FindMbedTLS.cmake | 119 +- third-party/curl/CMake/FindNGHTTP2.cmake | 97 +- third-party/curl/CMake/FindNGHTTP3.cmake | 128 +- third-party/curl/CMake/FindNGTCP2.cmake | 224 +- third-party/curl/CMake/FindNettle.cmake | 97 + third-party/curl/CMake/FindQUICHE.cmake | 84 +- third-party/curl/CMake/FindRustls.cmake | 116 + third-party/curl/CMake/FindWolfSSL.cmake | 117 +- third-party/curl/CMake/FindZstd.cmake | 157 +- third-party/curl/CMake/Macros.cmake | 314 +- third-party/curl/CMake/OtherTests.cmake | 194 +- third-party/curl/CMake/PickyWarnings.cmake | 429 +- .../curl/CMake/Platforms/WindowsCache.cmake | 127 - third-party/curl/CMake/Utilities.cmake | 65 +- .../curl/CMake/cmake_uninstall.cmake.in | 49 - .../curl/CMake/cmake_uninstall.in.cmake | 50 + third-party/curl/CMake/curl-config.cmake.in | 38 - third-party/curl/CMake/curl-config.in.cmake | 196 + third-party/curl/CMake/unix-cache.cmake | 332 + third-party/curl/CMake/win32-cache.cmake | 192 + third-party/curl/CMakeLists.txt | 3104 +++++--- third-party/curl/COPYING | 2 +- third-party/curl/Dockerfile | 41 + third-party/curl/GIT-INFO | 44 - third-party/curl/GIT-INFO.md | 33 + third-party/curl/LICENSES/BSD-3-Clause.txt | 11 - third-party/curl/LICENSES/BSD-4-Clause-UC.txt | 32 +- third-party/curl/MacOSX-Framework | 160 - third-party/curl/Makefile.am | 569 +- third-party/curl/Makefile.dist | 92 - third-party/curl/README | 17 +- third-party/curl/README.md | 56 +- third-party/curl/RELEASE-NOTES | 983 ++- third-party/curl/REUSE.toml | 41 + third-party/curl/SECURITY.md | 22 +- third-party/curl/acinclude.m4 | 1625 ++-- third-party/curl/appveyor.sh | 132 + third-party/curl/appveyor.yml | 467 +- third-party/curl/buildconf | 8 - third-party/curl/buildconf.bat | 319 - third-party/curl/configure.ac | 5193 +++++++------ third-party/curl/curl-config.in | 271 +- third-party/curl/docs/.gitignore | 7 +- third-party/curl/docs/ALTSVC.md | 24 +- third-party/curl/docs/BINDINGS.md | 56 +- third-party/curl/docs/BUFQ.md | 141 - third-party/curl/docs/BUG-BOUNTY.md | 84 +- third-party/curl/docs/BUGS.md | 348 +- third-party/curl/docs/CHECKSRC.md | 182 - third-party/curl/docs/CIPHERS-TLS12.md | 336 + third-party/curl/docs/CIPHERS.md | 644 +- third-party/curl/docs/CMakeLists.txt | 31 +- third-party/curl/docs/CODE_OF_CONDUCT.md | 14 +- third-party/curl/docs/CODE_REVIEW.md | 27 +- third-party/curl/docs/CONNECTION-FILTERS.md | 127 - third-party/curl/docs/CONTRIBUTE.md | 335 +- third-party/curl/docs/CURL-DISABLE.md | 43 +- third-party/curl/docs/CURLDOWN.md | 165 + third-party/curl/docs/DEPRECATE.md | 97 +- third-party/curl/docs/DISTROS.md | 304 + third-party/curl/docs/DYNBUF.md | 128 - third-party/curl/docs/EARLY-RELEASE.md | 54 +- third-party/curl/docs/ECH.md | 492 ++ third-party/curl/docs/EXPERIMENTAL.md | 95 +- third-party/curl/docs/FAQ | 1544 ---- third-party/curl/docs/FAQ.md | 1427 ++++ third-party/curl/docs/FEATURES.md | 356 +- third-party/curl/docs/GOVERNANCE.md | 82 +- third-party/curl/docs/HELP-US.md | 35 +- third-party/curl/docs/HISTORY.md | 334 +- third-party/curl/docs/HSTS.md | 27 +- third-party/curl/docs/HTTP-COOKIES.md | 214 +- third-party/curl/docs/HTTP2.md | 102 - third-party/curl/docs/HTTP3.md | 319 +- third-party/curl/docs/HTTPSRR.md | 100 + third-party/curl/docs/HYPER.md | 69 - third-party/curl/docs/INFRASTRUCTURE.md | 201 + third-party/curl/docs/INSTALL-CMAKE.md | 612 ++ third-party/curl/docs/INSTALL.cmake | 89 - third-party/curl/docs/INSTALL.md | 667 +- third-party/curl/docs/INTERNALS.md | 90 +- third-party/curl/docs/IPFS.md | 150 + third-party/curl/docs/KNOWN_BUGS | 625 -- third-party/curl/docs/KNOWN_BUGS.md | 548 ++ third-party/curl/docs/KNOWN_RISKS.md | 149 + third-party/curl/docs/MAIL-ETIQUETTE | 285 - third-party/curl/docs/MAIL-ETIQUETTE.md | 257 + third-party/curl/docs/MANUAL.md | 410 +- third-party/curl/docs/MQTT.md | 27 - third-party/curl/docs/Makefile.am | 210 +- third-party/curl/docs/PARALLEL-TRANSFERS.md | 50 - third-party/curl/docs/README.md | 12 +- third-party/curl/docs/RELEASE-PROCEDURE.md | 90 +- third-party/curl/docs/ROADMAP.md | 25 +- third-party/curl/docs/RUSTLS.md | 83 +- third-party/curl/docs/SECURITY-ADVISORY.md | 52 +- third-party/curl/docs/SECURITY-PROCESS.md | 285 - third-party/curl/docs/SPONSORS.md | 55 + third-party/curl/docs/SSL-PROBLEMS.md | 126 +- third-party/curl/docs/SSLCERTS.md | 242 +- third-party/curl/docs/THANKS | 1457 +++- third-party/curl/docs/THANKS-filter | 29 +- third-party/curl/docs/TODO | 1385 ---- third-party/curl/docs/TODO.md | 1032 +++ .../curl/docs/TheArtOfHttpScripting.md | 840 +-- third-party/curl/docs/URL-SYNTAX.md | 183 +- third-party/curl/docs/VERIFY.md | 168 + third-party/curl/docs/VERSIONS.md | 365 +- .../curl/docs/VULN-DISCLOSURE-POLICY.md | 484 ++ third-party/curl/docs/cmdline-opts/.gitignore | 5 + .../curl/docs/cmdline-opts/CMakeLists.txt | 39 +- third-party/curl/docs/cmdline-opts/MANPAGE.md | 125 +- .../curl/docs/cmdline-opts/Makefile.am | 33 +- .../curl/docs/cmdline-opts/Makefile.inc | 556 +- .../curl/docs/cmdline-opts/_AUTHORS.md | 5 + third-party/curl/docs/cmdline-opts/_BUGS.md | 5 + .../curl/docs/cmdline-opts/_DESCRIPTION.md | 11 + .../curl/docs/cmdline-opts/_ENVIRONMENT.md | 120 + .../curl/docs/cmdline-opts/_EXITCODES.md | 203 + third-party/curl/docs/cmdline-opts/_FILES.md | 6 + .../curl/docs/cmdline-opts/_GLOBBING.md | 55 + third-party/curl/docs/cmdline-opts/_NAME.md | 4 + .../curl/docs/cmdline-opts/_OPTIONS.md | 39 + third-party/curl/docs/cmdline-opts/_OUTPUT.md | 11 + .../curl/docs/cmdline-opts/_PROGRESS.md | 26 + .../curl/docs/cmdline-opts/_PROTOCOLS.md | 50 + .../curl/docs/cmdline-opts/_PROXYPREFIX.md | 22 + .../curl/docs/cmdline-opts/_SEEALSO.md | 5 + .../curl/docs/cmdline-opts/_SYNOPSIS.md | 5 + third-party/curl/docs/cmdline-opts/_URL.md | 24 + .../curl/docs/cmdline-opts/_VARIABLES.md | 43 + .../curl/docs/cmdline-opts/_VERSION.md | 15 + third-party/curl/docs/cmdline-opts/_WWW.md | 4 + .../docs/cmdline-opts/abstract-unix-socket.d | 15 - .../docs/cmdline-opts/abstract-unix-socket.md | 21 + third-party/curl/docs/cmdline-opts/alt-svc.d | 21 - third-party/curl/docs/cmdline-opts/alt-svc.md | 31 + third-party/curl/docs/cmdline-opts/anyauth.d | 22 - third-party/curl/docs/cmdline-opts/anyauth.md | 30 + third-party/curl/docs/cmdline-opts/append.d | 16 - third-party/curl/docs/cmdline-opts/append.md | 23 + .../curl/docs/cmdline-opts/aws-sigv4.d | 22 - .../curl/docs/cmdline-opts/aws-sigv4.md | 30 + third-party/curl/docs/cmdline-opts/basic.d | 17 - third-party/curl/docs/cmdline-opts/basic.md | 23 + .../curl/docs/cmdline-opts/ca-native.d | 21 - .../curl/docs/cmdline-opts/ca-native.md | 44 + third-party/curl/docs/cmdline-opts/cacert.d | 35 - third-party/curl/docs/cmdline-opts/cacert.md | 40 + third-party/curl/docs/cmdline-opts/capath.d | 21 - third-party/curl/docs/cmdline-opts/capath.md | 31 + .../curl/docs/cmdline-opts/cert-status.d | 19 - .../curl/docs/cmdline-opts/cert-status.md | 25 + .../curl/docs/cmdline-opts/cert-type.d | 18 - .../curl/docs/cmdline-opts/cert-type.md | 26 + third-party/curl/docs/cmdline-opts/cert.d | 49 - third-party/curl/docs/cmdline-opts/cert.md | 53 + third-party/curl/docs/cmdline-opts/ciphers.d | 16 - third-party/curl/docs/cmdline-opts/ciphers.md | 25 + .../curl/docs/cmdline-opts/compressed-ssh.d | 13 - .../curl/docs/cmdline-opts/compressed-ssh.md | 20 + .../curl/docs/cmdline-opts/compressed.d | 21 - .../curl/docs/cmdline-opts/compressed.md | 32 + third-party/curl/docs/cmdline-opts/config.d | 77 - third-party/curl/docs/cmdline-opts/config.md | 84 + .../curl/docs/cmdline-opts/connect-timeout.d | 22 - .../curl/docs/cmdline-opts/connect-timeout.md | 28 + .../curl/docs/cmdline-opts/connect-to.d | 24 - .../curl/docs/cmdline-opts/connect-to.md | 40 + .../curl/docs/cmdline-opts/continue-at.d | 20 - .../curl/docs/cmdline-opts/continue-at.md | 37 + .../curl/docs/cmdline-opts/cookie-jar.d | 31 - .../curl/docs/cmdline-opts/cookie-jar.md | 42 + third-party/curl/docs/cmdline-opts/cookie.d | 42 - third-party/curl/docs/cmdline-opts/cookie.md | 63 + .../curl/docs/cmdline-opts/create-dirs.d | 19 - .../curl/docs/cmdline-opts/create-dirs.md | 26 + .../curl/docs/cmdline-opts/create-file-mode.d | 17 - .../docs/cmdline-opts/create-file-mode.md | 23 + third-party/curl/docs/cmdline-opts/crlf.d | 15 - third-party/curl/docs/cmdline-opts/crlf.md | 19 + third-party/curl/docs/cmdline-opts/crlfile.d | 14 - third-party/curl/docs/cmdline-opts/crlfile.md | 21 + third-party/curl/docs/cmdline-opts/curves.d | 22 - third-party/curl/docs/cmdline-opts/curves.md | 28 + .../curl/docs/cmdline-opts/data-ascii.d | 13 - .../curl/docs/cmdline-opts/data-ascii.md | 21 + .../curl/docs/cmdline-opts/data-binary.d | 25 - .../curl/docs/cmdline-opts/data-binary.md | 32 + third-party/curl/docs/cmdline-opts/data-raw.d | 15 - .../curl/docs/cmdline-opts/data-raw.md | 21 + .../curl/docs/cmdline-opts/data-urlencode.d | 42 - .../curl/docs/cmdline-opts/data-urlencode.md | 51 + third-party/curl/docs/cmdline-opts/data.d | 41 - third-party/curl/docs/cmdline-opts/data.md | 49 + .../curl/docs/cmdline-opts/delegation.d | 24 - .../curl/docs/cmdline-opts/delegation.md | 30 + third-party/curl/docs/cmdline-opts/digest.d | 15 - third-party/curl/docs/cmdline-opts/digest.md | 22 + .../curl/docs/cmdline-opts/disable-eprt.d | 25 - .../curl/docs/cmdline-opts/disable-eprt.md | 32 + .../curl/docs/cmdline-opts/disable-epsv.d | 23 - .../curl/docs/cmdline-opts/disable-epsv.md | 30 + third-party/curl/docs/cmdline-opts/disable.d | 17 - third-party/curl/docs/cmdline-opts/disable.md | 20 + .../cmdline-opts/disallow-username-in-url.d | 13 - .../cmdline-opts/disallow-username-in-url.md | 21 + .../curl/docs/cmdline-opts/dns-interface.d | 16 - .../curl/docs/cmdline-opts/dns-interface.md | 23 + .../curl/docs/cmdline-opts/dns-ipv4-addr.d | 16 - .../curl/docs/cmdline-opts/dns-ipv4-addr.md | 23 + .../curl/docs/cmdline-opts/dns-ipv6-addr.d | 16 - .../curl/docs/cmdline-opts/dns-ipv6-addr.md | 23 + .../curl/docs/cmdline-opts/dns-servers.d | 16 - .../curl/docs/cmdline-opts/dns-servers.md | 24 + .../curl/docs/cmdline-opts/doh-cert-status.d | 11 - .../curl/docs/cmdline-opts/doh-cert-status.md | 27 + .../curl/docs/cmdline-opts/doh-insecure.d | 11 - .../curl/docs/cmdline-opts/doh-insecure.md | 28 + third-party/curl/docs/cmdline-opts/doh-url.d | 21 - third-party/curl/docs/cmdline-opts/doh-url.md | 31 + .../curl/docs/cmdline-opts/dump-ca-embed.md | 25 + .../curl/docs/cmdline-opts/dump-header.d | 21 - .../curl/docs/cmdline-opts/dump-header.md | 35 + third-party/curl/docs/cmdline-opts/ech.md | 52 + third-party/curl/docs/cmdline-opts/egd-file.d | 17 - .../curl/docs/cmdline-opts/egd-file.md | 23 + third-party/curl/docs/cmdline-opts/engine.d | 15 - third-party/curl/docs/cmdline-opts/engine.md | 25 + .../curl/docs/cmdline-opts/etag-compare.d | 23 - .../curl/docs/cmdline-opts/etag-compare.md | 30 + .../curl/docs/cmdline-opts/etag-save.d | 16 - .../curl/docs/cmdline-opts/etag-save.md | 30 + .../docs/cmdline-opts/expect100-timeout.d | 19 - .../docs/cmdline-opts/expect100-timeout.md | 25 + .../curl/docs/cmdline-opts/fail-early.d | 25 - .../curl/docs/cmdline-opts/fail-early.md | 32 + .../curl/docs/cmdline-opts/fail-with-body.d | 20 - .../curl/docs/cmdline-opts/fail-with-body.md | 27 + third-party/curl/docs/cmdline-opts/fail.d | 22 - third-party/curl/docs/cmdline-opts/fail.md | 35 + .../curl/docs/cmdline-opts/false-start.d | 18 - .../curl/docs/cmdline-opts/false-start.md | 22 + third-party/curl/docs/cmdline-opts/follow.md | 33 + .../curl/docs/cmdline-opts/form-escape.d | 13 - .../curl/docs/cmdline-opts/form-escape.md | 19 + .../curl/docs/cmdline-opts/form-string.d | 17 - .../curl/docs/cmdline-opts/form-string.md | 23 + third-party/curl/docs/cmdline-opts/form.d | 134 - third-party/curl/docs/cmdline-opts/form.md | 143 + .../curl/docs/cmdline-opts/ftp-account.d | 14 - .../curl/docs/cmdline-opts/ftp-account.md | 20 + .../cmdline-opts/ftp-alternative-to-user.d | 16 - .../cmdline-opts/ftp-alternative-to-user.md | 23 + .../curl/docs/cmdline-opts/ftp-create-dirs.d | 14 - .../curl/docs/cmdline-opts/ftp-create-dirs.md | 20 + .../curl/docs/cmdline-opts/ftp-method.d | 30 - .../curl/docs/cmdline-opts/ftp-method.md | 36 + third-party/curl/docs/cmdline-opts/ftp-pasv.d | 20 - .../curl/docs/cmdline-opts/ftp-pasv.md | 27 + third-party/curl/docs/cmdline-opts/ftp-port.d | 41 - .../curl/docs/cmdline-opts/ftp-port.md | 51 + third-party/curl/docs/cmdline-opts/ftp-pret.d | 14 - .../curl/docs/cmdline-opts/ftp-pret.md | 21 + .../curl/docs/cmdline-opts/ftp-skip-pasv-ip.d | 18 - .../docs/cmdline-opts/ftp-skip-pasv-ip.md | 24 + .../curl/docs/cmdline-opts/ftp-ssl-ccc-mode.d | 16 - .../docs/cmdline-opts/ftp-ssl-ccc-mode.md | 22 + .../curl/docs/cmdline-opts/ftp-ssl-ccc.d | 15 - .../curl/docs/cmdline-opts/ftp-ssl-ccc.md | 22 + .../curl/docs/cmdline-opts/ftp-ssl-control.d | 14 - .../curl/docs/cmdline-opts/ftp-ssl-control.md | 22 + third-party/curl/docs/cmdline-opts/gen.pl | 744 -- third-party/curl/docs/cmdline-opts/get.d | 20 - third-party/curl/docs/cmdline-opts/get.md | 28 + third-party/curl/docs/cmdline-opts/globoff.d | 15 - third-party/curl/docs/cmdline-opts/globoff.md | 25 + .../cmdline-opts/happy-eyeballs-timeout-ms.d | 21 - .../cmdline-opts/happy-eyeballs-timeout-ms.md | 30 + .../curl/docs/cmdline-opts/haproxy-clientip.d | 29 - .../docs/cmdline-opts/haproxy-clientip.md | 33 + .../curl/docs/cmdline-opts/haproxy-protocol.d | 17 - .../docs/cmdline-opts/haproxy-protocol.md | 23 + third-party/curl/docs/cmdline-opts/head.d | 15 - third-party/curl/docs/cmdline-opts/head.md | 23 + third-party/curl/docs/cmdline-opts/header.d | 56 - third-party/curl/docs/cmdline-opts/header.md | 69 + third-party/curl/docs/cmdline-opts/help.d | 21 - third-party/curl/docs/cmdline-opts/help.md | 39 + .../curl/docs/cmdline-opts/hostpubmd5.d | 15 - .../curl/docs/cmdline-opts/hostpubmd5.md | 21 + .../curl/docs/cmdline-opts/hostpubsha256.d | 17 - .../curl/docs/cmdline-opts/hostpubsha256.md | 20 + third-party/curl/docs/cmdline-opts/hsts.d | 26 - third-party/curl/docs/cmdline-opts/hsts.md | 40 + third-party/curl/docs/cmdline-opts/http0.9.d | 19 - third-party/curl/docs/cmdline-opts/http0.9.md | 27 + third-party/curl/docs/cmdline-opts/http1.0.d | 16 - third-party/curl/docs/cmdline-opts/http1.0.md | 22 + third-party/curl/docs/cmdline-opts/http1.1.d | 14 - third-party/curl/docs/cmdline-opts/http1.1.md | 21 + .../docs/cmdline-opts/http2-prior-knowledge.d | 18 - .../cmdline-opts/http2-prior-knowledge.md | 29 + third-party/curl/docs/cmdline-opts/http2.d | 25 - third-party/curl/docs/cmdline-opts/http2.md | 34 + .../curl/docs/cmdline-opts/http3-only.d | 25 - .../curl/docs/cmdline-opts/http3-only.md | 32 + third-party/curl/docs/cmdline-opts/http3.d | 27 - third-party/curl/docs/cmdline-opts/http3.md | 37 + .../docs/cmdline-opts/ignore-content-length.d | 19 - .../cmdline-opts/ignore-content-length.md | 23 + third-party/curl/docs/cmdline-opts/include.d | 19 - third-party/curl/docs/cmdline-opts/insecure.d | 33 - .../curl/docs/cmdline-opts/insecure.md | 41 + .../curl/docs/cmdline-opts/interface.d | 19 - .../curl/docs/cmdline-opts/interface.md | 51 + third-party/curl/docs/cmdline-opts/ip-tos.md | 26 + .../curl/docs/cmdline-opts/ipfs-gateway.md | 40 + third-party/curl/docs/cmdline-opts/ipv4.d | 17 - third-party/curl/docs/cmdline-opts/ipv4.md | 24 + third-party/curl/docs/cmdline-opts/ipv6.d | 17 - third-party/curl/docs/cmdline-opts/ipv6.md | 28 + third-party/curl/docs/cmdline-opts/json.d | 35 - third-party/curl/docs/cmdline-opts/json.md | 42 + .../docs/cmdline-opts/junk-session-cookies.d | 15 - .../docs/cmdline-opts/junk-session-cookies.md | 25 + .../curl/docs/cmdline-opts/keepalive-cnt.md | 27 + .../curl/docs/cmdline-opts/keepalive-time.d | 21 - .../curl/docs/cmdline-opts/keepalive-time.md | 30 + third-party/curl/docs/cmdline-opts/key-type.d | 14 - .../curl/docs/cmdline-opts/key-type.md | 20 + third-party/curl/docs/cmdline-opts/key.d | 27 - third-party/curl/docs/cmdline-opts/key.md | 33 + .../curl/docs/cmdline-opts/knownhosts.md | 31 + third-party/curl/docs/cmdline-opts/krb.d | 16 - third-party/curl/docs/cmdline-opts/krb.md | 25 + third-party/curl/docs/cmdline-opts/libcurl.d | 15 - third-party/curl/docs/cmdline-opts/libcurl.md | 21 + .../curl/docs/cmdline-opts/limit-rate.d | 29 - .../curl/docs/cmdline-opts/limit-rate.md | 42 + .../curl/docs/cmdline-opts/list-only.d | 36 - .../curl/docs/cmdline-opts/list-only.md | 43 + .../curl/docs/cmdline-opts/local-port.d | 15 - .../curl/docs/cmdline-opts/local-port.md | 21 + .../curl/docs/cmdline-opts/location-trusted.d | 15 - .../docs/cmdline-opts/location-trusted.md | 27 + third-party/curl/docs/cmdline-opts/location.d | 33 - .../curl/docs/cmdline-opts/location.md | 48 + .../curl/docs/cmdline-opts/login-options.d | 25 - .../curl/docs/cmdline-opts/login-options.md | 32 + .../curl/docs/cmdline-opts/mail-auth.d | 14 - .../curl/docs/cmdline-opts/mail-auth.md | 21 + .../curl/docs/cmdline-opts/mail-from.d | 13 - .../curl/docs/cmdline-opts/mail-from.md | 20 + .../docs/cmdline-opts/mail-rcpt-allowfails.d | 22 - .../docs/cmdline-opts/mail-rcpt-allowfails.md | 28 + .../curl/docs/cmdline-opts/mail-rcpt.d | 22 - .../curl/docs/cmdline-opts/mail-rcpt.md | 28 + .../curl/docs/cmdline-opts/mainpage.idx | 43 + third-party/curl/docs/cmdline-opts/manual.d | 12 - third-party/curl/docs/cmdline-opts/manual.md | 20 + .../curl/docs/cmdline-opts/max-filesize.d | 23 - .../curl/docs/cmdline-opts/max-filesize.md | 42 + .../curl/docs/cmdline-opts/max-redirs.d | 15 - .../curl/docs/cmdline-opts/max-redirs.md | 23 + third-party/curl/docs/cmdline-opts/max-time.d | 23 - .../curl/docs/cmdline-opts/max-time.md | 30 + third-party/curl/docs/cmdline-opts/metalink.d | 12 - .../curl/docs/cmdline-opts/metalink.md | 18 + third-party/curl/docs/cmdline-opts/mptcp.md | 31 + .../curl/docs/cmdline-opts/negotiate.d | 19 - .../curl/docs/cmdline-opts/negotiate.md | 28 + .../curl/docs/cmdline-opts/netrc-file.d | 17 - .../curl/docs/cmdline-opts/netrc-file.md | 24 + .../curl/docs/cmdline-opts/netrc-optional.d | 13 - .../curl/docs/cmdline-opts/netrc-optional.md | 19 + third-party/curl/docs/cmdline-opts/netrc.d | 27 - third-party/curl/docs/cmdline-opts/netrc.md | 52 + third-party/curl/docs/cmdline-opts/next.d | 27 - third-party/curl/docs/cmdline-opts/next.md | 33 + third-party/curl/docs/cmdline-opts/no-alpn.d | 19 - third-party/curl/docs/cmdline-opts/no-alpn.md | 26 + .../curl/docs/cmdline-opts/no-buffer.d | 18 - .../curl/docs/cmdline-opts/no-buffer.md | 24 + .../curl/docs/cmdline-opts/no-clobber.d | 19 - .../curl/docs/cmdline-opts/no-clobber.md | 28 + .../curl/docs/cmdline-opts/no-keepalive.d | 15 - .../curl/docs/cmdline-opts/no-keepalive.md | 22 + third-party/curl/docs/cmdline-opts/no-npn.d | 19 - third-party/curl/docs/cmdline-opts/no-npn.md | 26 + .../docs/cmdline-opts/no-progress-meter.d | 15 - .../docs/cmdline-opts/no-progress-meter.md | 22 + .../curl/docs/cmdline-opts/no-sessionid.d | 19 - .../curl/docs/cmdline-opts/no-sessionid.md | 25 + third-party/curl/docs/cmdline-opts/noproxy.d | 27 - third-party/curl/docs/cmdline-opts/noproxy.md | 36 + third-party/curl/docs/cmdline-opts/ntlm-wb.d | 13 - third-party/curl/docs/cmdline-opts/ntlm-wb.md | 22 + third-party/curl/docs/cmdline-opts/ntlm.d | 22 - third-party/curl/docs/cmdline-opts/ntlm.md | 27 + .../curl/docs/cmdline-opts/oauth2-bearer.d | 17 - .../curl/docs/cmdline-opts/oauth2-bearer.md | 25 + .../curl/docs/cmdline-opts/out-null.md | 26 + .../curl/docs/cmdline-opts/output-dir.d | 19 - .../curl/docs/cmdline-opts/output-dir.md | 26 + third-party/curl/docs/cmdline-opts/output.d | 49 - third-party/curl/docs/cmdline-opts/output.md | 90 + .../curl/docs/cmdline-opts/page-footer | 322 - .../curl/docs/cmdline-opts/page-header | 258 - .../docs/cmdline-opts/parallel-immediate.d | 15 - .../docs/cmdline-opts/parallel-immediate.md | 25 + .../docs/cmdline-opts/parallel-max-host.md | 28 + .../curl/docs/cmdline-opts/parallel-max.d | 18 - .../curl/docs/cmdline-opts/parallel-max.md | 23 + third-party/curl/docs/cmdline-opts/parallel.d | 14 - .../curl/docs/cmdline-opts/parallel.md | 32 + third-party/curl/docs/cmdline-opts/pass.d | 13 - third-party/curl/docs/cmdline-opts/pass.md | 20 + .../curl/docs/cmdline-opts/path-as-is.d | 13 - .../curl/docs/cmdline-opts/path-as-is.md | 19 + .../curl/docs/cmdline-opts/pinnedpubkey.d | 32 - .../curl/docs/cmdline-opts/pinnedpubkey.md | 43 + third-party/curl/docs/cmdline-opts/post301.d | 16 - third-party/curl/docs/cmdline-opts/post301.md | 24 + third-party/curl/docs/cmdline-opts/post302.d | 16 - third-party/curl/docs/cmdline-opts/post302.md | 24 + third-party/curl/docs/cmdline-opts/post303.d | 15 - third-party/curl/docs/cmdline-opts/post303.md | 22 + third-party/curl/docs/cmdline-opts/preproxy.d | 26 - .../curl/docs/cmdline-opts/preproxy.md | 33 + .../curl/docs/cmdline-opts/progress-bar.d | 20 - .../curl/docs/cmdline-opts/progress-bar.md | 26 + .../curl/docs/cmdline-opts/proto-default.d | 20 - .../curl/docs/cmdline-opts/proto-default.md | 30 + .../curl/docs/cmdline-opts/proto-redir.d | 22 - .../curl/docs/cmdline-opts/proto-redir.md | 28 + third-party/curl/docs/cmdline-opts/proto.d | 48 - third-party/curl/docs/cmdline-opts/proto.md | 48 + .../curl/docs/cmdline-opts/proxy-anyauth.d | 12 - .../curl/docs/cmdline-opts/proxy-anyauth.md | 20 + .../curl/docs/cmdline-opts/proxy-basic.d | 13 - .../curl/docs/cmdline-opts/proxy-basic.md | 21 + .../curl/docs/cmdline-opts/proxy-ca-native.d | 21 - .../curl/docs/cmdline-opts/proxy-ca-native.md | 30 + .../curl/docs/cmdline-opts/proxy-cacert.d | 12 - .../curl/docs/cmdline-opts/proxy-cacert.md | 28 + .../curl/docs/cmdline-opts/proxy-capath.d | 12 - .../curl/docs/cmdline-opts/proxy-capath.md | 31 + .../curl/docs/cmdline-opts/proxy-cert-type.d | 12 - .../curl/docs/cmdline-opts/proxy-cert-type.md | 26 + .../curl/docs/cmdline-opts/proxy-cert.d | 12 - .../curl/docs/cmdline-opts/proxy-cert.md | 25 + .../curl/docs/cmdline-opts/proxy-ciphers.d | 18 - .../curl/docs/cmdline-opts/proxy-ciphers.md | 27 + .../curl/docs/cmdline-opts/proxy-crlfile.d | 12 - .../curl/docs/cmdline-opts/proxy-crlfile.md | 23 + .../curl/docs/cmdline-opts/proxy-digest.d | 12 - .../curl/docs/cmdline-opts/proxy-digest.md | 20 + .../curl/docs/cmdline-opts/proxy-header.d | 32 - .../curl/docs/cmdline-opts/proxy-header.md | 39 + .../curl/docs/cmdline-opts/proxy-http2.d | 18 - .../curl/docs/cmdline-opts/proxy-http2.md | 26 + .../curl/docs/cmdline-opts/proxy-http3.md | 31 + .../curl/docs/cmdline-opts/proxy-insecure.d | 11 - .../curl/docs/cmdline-opts/proxy-insecure.md | 30 + .../curl/docs/cmdline-opts/proxy-key-type.d | 12 - .../curl/docs/cmdline-opts/proxy-key-type.md | 22 + .../curl/docs/cmdline-opts/proxy-key.d | 12 - .../curl/docs/cmdline-opts/proxy-key.md | 21 + .../curl/docs/cmdline-opts/proxy-negotiate.d | 13 - .../curl/docs/cmdline-opts/proxy-negotiate.md | 21 + .../curl/docs/cmdline-opts/proxy-ntlm.d | 12 - .../curl/docs/cmdline-opts/proxy-ntlm.md | 20 + .../curl/docs/cmdline-opts/proxy-pass.d | 12 - .../curl/docs/cmdline-opts/proxy-pass.md | 21 + .../docs/cmdline-opts/proxy-pinnedpubkey.d | 22 - .../docs/cmdline-opts/proxy-pinnedpubkey.md | 31 + .../docs/cmdline-opts/proxy-service-name.d | 12 - .../docs/cmdline-opts/proxy-service-name.md | 20 + .../docs/cmdline-opts/proxy-ssl-allow-beast.d | 11 - .../cmdline-opts/proxy-ssl-allow-beast.md | 29 + .../cmdline-opts/proxy-ssl-auto-client-cert.d | 11 - .../proxy-ssl-auto-client-cert.md | 20 + .../docs/cmdline-opts/proxy-tls13-ciphers.d | 21 - .../docs/cmdline-opts/proxy-tls13-ciphers.md | 33 + .../docs/cmdline-opts/proxy-tlsauthtype.d | 12 - .../docs/cmdline-opts/proxy-tlsauthtype.md | 24 + .../docs/cmdline-opts/proxy-tlspassword.d | 12 - .../docs/cmdline-opts/proxy-tlspassword.md | 25 + .../curl/docs/cmdline-opts/proxy-tlsuser.d | 12 - .../curl/docs/cmdline-opts/proxy-tlsuser.md | 23 + .../curl/docs/cmdline-opts/proxy-tlsv1.d | 11 - .../curl/docs/cmdline-opts/proxy-tlsv1.md | 20 + .../curl/docs/cmdline-opts/proxy-user.d | 23 - .../curl/docs/cmdline-opts/proxy-user.md | 29 + third-party/curl/docs/cmdline-opts/proxy.d | 51 - third-party/curl/docs/cmdline-opts/proxy.md | 61 + third-party/curl/docs/cmdline-opts/proxy1.0.d | 17 - .../curl/docs/cmdline-opts/proxy1.0.md | 25 + .../curl/docs/cmdline-opts/proxytunnel.d | 18 - .../curl/docs/cmdline-opts/proxytunnel.md | 24 + third-party/curl/docs/cmdline-opts/pubkey.d | 19 - third-party/curl/docs/cmdline-opts/pubkey.md | 25 + third-party/curl/docs/cmdline-opts/quote.d | 87 - third-party/curl/docs/cmdline-opts/quote.md | 93 + .../curl/docs/cmdline-opts/random-file.d | 16 - .../curl/docs/cmdline-opts/random-file.md | 22 + third-party/curl/docs/cmdline-opts/range.d | 50 - third-party/curl/docs/cmdline-opts/range.md | 66 + third-party/curl/docs/cmdline-opts/rate.d | 35 - third-party/curl/docs/cmdline-opts/rate.md | 46 + third-party/curl/docs/cmdline-opts/raw.d | 13 - third-party/curl/docs/cmdline-opts/raw.md | 19 + third-party/curl/docs/cmdline-opts/referer.d | 20 - third-party/curl/docs/cmdline-opts/referer.md | 27 + .../docs/cmdline-opts/remote-header-name.d | 34 - .../docs/cmdline-opts/remote-header-name.md | 42 + .../curl/docs/cmdline-opts/remote-name-all.d | 14 - .../curl/docs/cmdline-opts/remote-name-all.md | 20 + .../curl/docs/cmdline-opts/remote-name.d | 28 - .../curl/docs/cmdline-opts/remote-name.md | 42 + .../curl/docs/cmdline-opts/remote-time.d | 14 - .../curl/docs/cmdline-opts/remote-time.md | 21 + .../curl/docs/cmdline-opts/remove-on-error.d | 15 - .../curl/docs/cmdline-opts/remove-on-error.md | 23 + .../curl/docs/cmdline-opts/request-target.d | 16 - .../curl/docs/cmdline-opts/request-target.md | 25 + third-party/curl/docs/cmdline-opts/request.d | 51 - third-party/curl/docs/cmdline-opts/request.md | 58 + third-party/curl/docs/cmdline-opts/resolve.d | 41 - third-party/curl/docs/cmdline-opts/resolve.md | 50 + .../curl/docs/cmdline-opts/retry-all-errors.d | 34 - .../docs/cmdline-opts/retry-all-errors.md | 40 + .../docs/cmdline-opts/retry-connrefused.d | 12 - .../docs/cmdline-opts/retry-connrefused.md | 21 + .../curl/docs/cmdline-opts/retry-delay.d | 15 - .../curl/docs/cmdline-opts/retry-delay.md | 28 + .../curl/docs/cmdline-opts/retry-max-time.d | 17 - .../curl/docs/cmdline-opts/retry-max-time.md | 38 + third-party/curl/docs/cmdline-opts/retry.d | 25 - third-party/curl/docs/cmdline-opts/retry.md | 34 + .../curl/docs/cmdline-opts/sasl-authzid.d | 19 - .../curl/docs/cmdline-opts/sasl-authzid.md | 26 + third-party/curl/docs/cmdline-opts/sasl-ir.d | 11 - third-party/curl/docs/cmdline-opts/sasl-ir.md | 20 + .../curl/docs/cmdline-opts/service-name.d | 12 - .../curl/docs/cmdline-opts/service-name.md | 19 + .../curl/docs/cmdline-opts/show-error.d | 13 - .../curl/docs/cmdline-opts/show-error.md | 19 + .../curl/docs/cmdline-opts/show-headers.md | 39 + third-party/curl/docs/cmdline-opts/sigalgs.md | 33 + third-party/curl/docs/cmdline-opts/silent.d | 17 - third-party/curl/docs/cmdline-opts/silent.md | 25 + .../curl/docs/cmdline-opts/skip-existing.md | 22 + third-party/curl/docs/cmdline-opts/socks4.d | 28 - third-party/curl/docs/cmdline-opts/socks4.md | 38 + third-party/curl/docs/cmdline-opts/socks4a.d | 27 - third-party/curl/docs/cmdline-opts/socks4a.md | 37 + .../curl/docs/cmdline-opts/socks5-basic.d | 13 - .../curl/docs/cmdline-opts/socks5-basic.md | 19 + .../docs/cmdline-opts/socks5-gssapi-nec.d | 14 - .../docs/cmdline-opts/socks5-gssapi-nec.md | 21 + .../docs/cmdline-opts/socks5-gssapi-service.d | 13 - .../cmdline-opts/socks5-gssapi-service.md | 18 + .../curl/docs/cmdline-opts/socks5-gssapi.d | 14 - .../curl/docs/cmdline-opts/socks5-gssapi.md | 21 + .../curl/docs/cmdline-opts/socks5-hostname.d | 27 - .../curl/docs/cmdline-opts/socks5-hostname.md | 36 + third-party/curl/docs/cmdline-opts/socks5.d | 29 - third-party/curl/docs/cmdline-opts/socks5.md | 39 + .../curl/docs/cmdline-opts/speed-limit.d | 15 - .../curl/docs/cmdline-opts/speed-limit.md | 23 + .../curl/docs/cmdline-opts/speed-time.d | 18 - .../curl/docs/cmdline-opts/speed-time.md | 25 + .../curl/docs/cmdline-opts/ssl-allow-beast.d | 17 - .../curl/docs/cmdline-opts/ssl-allow-beast.md | 27 + .../docs/cmdline-opts/ssl-auto-client-cert.d | 14 - .../docs/cmdline-opts/ssl-auto-client-cert.md | 21 + .../curl/docs/cmdline-opts/ssl-no-revoke.d | 13 - .../curl/docs/cmdline-opts/ssl-no-revoke.md | 19 + third-party/curl/docs/cmdline-opts/ssl-reqd.d | 23 - .../curl/docs/cmdline-opts/ssl-reqd.md | 31 + .../cmdline-opts/ssl-revoke-best-effort.d | 13 - .../cmdline-opts/ssl-revoke-best-effort.md | 20 + .../curl/docs/cmdline-opts/ssl-sessions.md | 39 + third-party/curl/docs/cmdline-opts/ssl.d | 26 - third-party/curl/docs/cmdline-opts/ssl.md | 36 + third-party/curl/docs/cmdline-opts/sslv2.d | 17 - third-party/curl/docs/cmdline-opts/sslv2.md | 24 + third-party/curl/docs/cmdline-opts/sslv3.d | 17 - third-party/curl/docs/cmdline-opts/sslv3.md | 24 + third-party/curl/docs/cmdline-opts/stderr.d | 14 - third-party/curl/docs/cmdline-opts/stderr.md | 21 + .../curl/docs/cmdline-opts/styled-output.d | 16 - .../curl/docs/cmdline-opts/styled-output.md | 23 + .../cmdline-opts/suppress-connect-headers.d | 14 - .../cmdline-opts/suppress-connect-headers.md | 23 + .../curl/docs/cmdline-opts/tcp-fastopen.d | 14 - .../curl/docs/cmdline-opts/tcp-fastopen.md | 19 + .../curl/docs/cmdline-opts/tcp-nodelay.d | 15 - .../curl/docs/cmdline-opts/tcp-nodelay.md | 30 + .../curl/docs/cmdline-opts/telnet-option.d | 23 - .../curl/docs/cmdline-opts/telnet-option.md | 29 + .../curl/docs/cmdline-opts/tftp-blksize.d | 15 - .../curl/docs/cmdline-opts/tftp-blksize.md | 21 + .../curl/docs/cmdline-opts/tftp-no-options.d | 16 - .../curl/docs/cmdline-opts/tftp-no-options.md | 20 + .../curl/docs/cmdline-opts/time-cond.d | 27 - .../curl/docs/cmdline-opts/time-cond.md | 34 + .../curl/docs/cmdline-opts/tls-earlydata.md | 46 + third-party/curl/docs/cmdline-opts/tls-max.d | 34 - third-party/curl/docs/cmdline-opts/tls-max.md | 44 + .../curl/docs/cmdline-opts/tls13-ciphers.d | 21 - .../curl/docs/cmdline-opts/tls13-ciphers.md | 31 + .../curl/docs/cmdline-opts/tlsauthtype.d | 16 - .../curl/docs/cmdline-opts/tlsauthtype.md | 23 + .../curl/docs/cmdline-opts/tlspassword.d | 15 - .../curl/docs/cmdline-opts/tlspassword.md | 22 + third-party/curl/docs/cmdline-opts/tlsuser.d | 15 - third-party/curl/docs/cmdline-opts/tlsuser.md | 22 + third-party/curl/docs/cmdline-opts/tlsv1.0.d | 16 - third-party/curl/docs/cmdline-opts/tlsv1.0.md | 22 + third-party/curl/docs/cmdline-opts/tlsv1.1.d | 16 - third-party/curl/docs/cmdline-opts/tlsv1.1.md | 23 + third-party/curl/docs/cmdline-opts/tlsv1.2.d | 16 - third-party/curl/docs/cmdline-opts/tlsv1.2.md | 23 + third-party/curl/docs/cmdline-opts/tlsv1.3.d | 18 - third-party/curl/docs/cmdline-opts/tlsv1.3.md | 25 + third-party/curl/docs/cmdline-opts/tlsv1.d | 17 - third-party/curl/docs/cmdline-opts/tlsv1.md | 24 + .../curl/docs/cmdline-opts/tr-encoding.d | 13 - .../curl/docs/cmdline-opts/tr-encoding.md | 24 + .../curl/docs/cmdline-opts/trace-ascii.d | 24 - .../curl/docs/cmdline-opts/trace-ascii.md | 31 + .../curl/docs/cmdline-opts/trace-config.d | 21 - .../curl/docs/cmdline-opts/trace-config.md | 27 + .../curl/docs/cmdline-opts/trace-ids.d | 12 - .../curl/docs/cmdline-opts/trace-ids.md | 24 + .../curl/docs/cmdline-opts/trace-time.d | 12 - .../curl/docs/cmdline-opts/trace-time.md | 19 + third-party/curl/docs/cmdline-opts/trace.d | 21 - third-party/curl/docs/cmdline-opts/trace.md | 30 + .../curl/docs/cmdline-opts/unix-socket.d | 13 - .../curl/docs/cmdline-opts/unix-socket.md | 22 + .../curl/docs/cmdline-opts/upload-file.d | 37 - .../curl/docs/cmdline-opts/upload-file.md | 63 + .../curl/docs/cmdline-opts/upload-flags.md | 25 + .../curl/docs/cmdline-opts/url-query.d | 25 - .../curl/docs/cmdline-opts/url-query.md | 31 + third-party/curl/docs/cmdline-opts/url.d | 26 - third-party/curl/docs/cmdline-opts/url.md | 49 + .../curl/docs/cmdline-opts/use-ascii.d | 15 - .../curl/docs/cmdline-opts/use-ascii.md | 23 + .../curl/docs/cmdline-opts/user-agent.d | 20 - .../curl/docs/cmdline-opts/user-agent.md | 29 + third-party/curl/docs/cmdline-opts/user.d | 44 - third-party/curl/docs/cmdline-opts/user.md | 50 + third-party/curl/docs/cmdline-opts/variable.d | 55 - .../curl/docs/cmdline-opts/variable.md | 110 + third-party/curl/docs/cmdline-opts/verbose.d | 28 - third-party/curl/docs/cmdline-opts/verbose.md | 81 + third-party/curl/docs/cmdline-opts/version.d | 88 - third-party/curl/docs/cmdline-opts/version.md | 134 + .../curl/docs/cmdline-opts/vlan-priority.md | 22 + .../curl/docs/cmdline-opts/write-out.d | 292 - .../curl/docs/cmdline-opts/write-out.md | 557 ++ third-party/curl/docs/cmdline-opts/xattr.d | 15 - third-party/curl/docs/cmdline-opts/xattr.md | 25 + third-party/curl/docs/curl-config.1 | 105 - third-party/curl/docs/curl-config.md | 124 + third-party/curl/docs/examples/.checksrc | 39 +- third-party/curl/docs/examples/.gitignore | 42 +- third-party/curl/docs/examples/10-at-a-time.c | 195 +- third-party/curl/docs/examples/CMakeLists.txt | 92 + third-party/curl/docs/examples/Makefile.am | 32 +- .../curl/docs/examples/Makefile.example | 37 +- third-party/curl/docs/examples/Makefile.inc | 34 +- third-party/curl/docs/examples/Makefile.mk | 74 - third-party/curl/docs/examples/README.md | 7 +- third-party/curl/docs/examples/adddocsref.pl | 21 +- .../curl/docs/examples/address-scope.c | 69 + third-party/curl/docs/examples/altsvc.c | 21 +- third-party/curl/docs/examples/anyauthput.c | 78 +- third-party/curl/docs/examples/block_ip.c | 351 + third-party/curl/docs/examples/cacertinmem.c | 227 +- third-party/curl/docs/examples/certinfo.c | 22 +- third-party/curl/docs/examples/chkspeed.c | 138 +- third-party/curl/docs/examples/connect-to.c | 34 +- .../curl/docs/examples/cookie_interface.c | 79 +- third-party/curl/docs/examples/crawler.c | 252 +- third-party/curl/docs/examples/debug.c | 58 +- .../curl/docs/examples/default-scheme.c | 18 +- third-party/curl/docs/examples/ephiperfifo.c | 404 +- third-party/curl/docs/examples/evhiperfifo.c | 345 +- .../curl/docs/examples/externalsocket.c | 68 +- third-party/curl/docs/examples/fileupload.c | 51 +- third-party/curl/docs/examples/ftp-delete.c | 84 + third-party/curl/docs/examples/ftp-wildcard.c | 134 +- third-party/curl/docs/examples/ftpget.c | 34 +- third-party/curl/docs/examples/ftpgetinfo.c | 48 +- third-party/curl/docs/examples/ftpgetresp.c | 56 +- third-party/curl/docs/examples/ftpsget.c | 38 +- third-party/curl/docs/examples/ftpupload.c | 103 +- .../curl/docs/examples/ftpuploadfrommem.c | 33 +- .../curl/docs/examples/ftpuploadresume.c | 93 +- third-party/curl/docs/examples/getinfo.c | 19 +- third-party/curl/docs/examples/getinmemory.c | 78 +- third-party/curl/docs/examples/getredirect.c | 31 +- third-party/curl/docs/examples/getreferrer.c | 22 +- third-party/curl/docs/examples/ghiper.c | 323 +- third-party/curl/docs/examples/headerapi.c | 22 +- third-party/curl/docs/examples/hiperfifo.c | 353 +- .../curl/docs/examples/href_extractor.c | 88 - third-party/curl/docs/examples/hsts-preload.c | 46 +- third-party/curl/docs/examples/htmltidy.c | 94 +- third-party/curl/docs/examples/htmltitle.cpp | 153 +- third-party/curl/docs/examples/http-options.c | 17 +- third-party/curl/docs/examples/http-post.c | 22 +- .../curl/docs/examples/http2-download.c | 175 +- .../curl/docs/examples/http2-pushinmemory.c | 72 +- .../curl/docs/examples/http2-serverpush.c | 159 +- third-party/curl/docs/examples/http2-upload.c | 271 +- .../curl/docs/examples/http3-present.c | 5 +- third-party/curl/docs/examples/http3.c | 20 +- .../curl/docs/examples/httpcustomheader.c | 15 +- .../curl/docs/examples/httpput-postfields.c | 30 +- third-party/curl/docs/examples/httpput.c | 61 +- third-party/curl/docs/examples/https.c | 22 +- third-party/curl/docs/examples/imap-append.c | 38 +- third-party/curl/docs/examples/imap-authzid.c | 20 +- third-party/curl/docs/examples/imap-copy.c | 20 +- third-party/curl/docs/examples/imap-create.c | 20 +- third-party/curl/docs/examples/imap-delete.c | 20 +- third-party/curl/docs/examples/imap-examine.c | 20 +- third-party/curl/docs/examples/imap-fetch.c | 20 +- third-party/curl/docs/examples/imap-list.c | 22 +- third-party/curl/docs/examples/imap-lsub.c | 20 +- third-party/curl/docs/examples/imap-multi.c | 61 +- third-party/curl/docs/examples/imap-noop.c | 20 +- third-party/curl/docs/examples/imap-search.c | 20 +- third-party/curl/docs/examples/imap-ssl.c | 30 +- third-party/curl/docs/examples/imap-store.c | 24 +- third-party/curl/docs/examples/imap-tls.c | 32 +- third-party/curl/docs/examples/interface.c | 58 + third-party/curl/docs/examples/ipv6.c | 34 +- third-party/curl/docs/examples/keepalive.c | 64 + third-party/curl/docs/examples/localport.c | 59 + .../curl/docs/examples/log_failed_transfers.c | 337 + third-party/curl/docs/examples/maxconnects.c | 24 +- third-party/curl/docs/examples/multi-app.c | 119 +- .../curl/docs/examples/multi-debugcallback.c | 101 +- third-party/curl/docs/examples/multi-double.c | 96 +- third-party/curl/docs/examples/multi-event.c | 190 +- .../curl/docs/examples/multi-formadd.c | 110 +- third-party/curl/docs/examples/multi-legacy.c | 226 +- third-party/curl/docs/examples/multi-post.c | 102 +- third-party/curl/docs/examples/multi-single.c | 67 +- third-party/curl/docs/examples/multi-uv.c | 193 +- third-party/curl/docs/examples/multithread.c | 96 - third-party/curl/docs/examples/netrc.c | 54 + third-party/curl/docs/examples/parseurl.c | 7 +- third-party/curl/docs/examples/persistent.c | 27 +- third-party/curl/docs/examples/pop3-authzid.c | 20 +- third-party/curl/docs/examples/pop3-dele.c | 18 +- third-party/curl/docs/examples/pop3-list.c | 20 +- third-party/curl/docs/examples/pop3-multi.c | 61 +- third-party/curl/docs/examples/pop3-noop.c | 20 +- third-party/curl/docs/examples/pop3-retr.c | 20 +- third-party/curl/docs/examples/pop3-ssl.c | 30 +- third-party/curl/docs/examples/pop3-stat.c | 20 +- third-party/curl/docs/examples/pop3-tls.c | 32 +- third-party/curl/docs/examples/pop3-top.c | 20 +- third-party/curl/docs/examples/pop3-uidl.c | 20 +- .../curl/docs/examples/post-callback.c | 42 +- third-party/curl/docs/examples/postinmemory.c | 32 +- .../curl/docs/examples/postit2-formadd.c | 77 +- third-party/curl/docs/examples/postit2.c | 35 +- third-party/curl/docs/examples/progressfunc.c | 39 +- third-party/curl/docs/examples/protofeats.c | 9 +- third-party/curl/docs/examples/range.c | 50 + third-party/curl/docs/examples/resolve.c | 19 +- third-party/curl/docs/examples/rtsp-options.c | 60 + third-party/curl/docs/examples/sendrecv.c | 60 +- third-party/curl/docs/examples/sepheaders.c | 101 +- third-party/curl/docs/examples/sessioninfo.c | 40 +- third-party/curl/docs/examples/sftpget.c | 34 +- .../curl/docs/examples/sftpuploadresume.c | 84 +- .../docs/examples/shared-connection-cache.c | 32 +- third-party/curl/docs/examples/simple.c | 17 +- third-party/curl/docs/examples/simplepost.c | 26 +- third-party/curl/docs/examples/simplessl.c | 157 +- .../curl/docs/examples/smooth-gtk-thread.c | 77 +- third-party/curl/docs/examples/smtp-authzid.c | 68 +- third-party/curl/docs/examples/smtp-expn.c | 23 +- third-party/curl/docs/examples/smtp-mail.c | 62 +- third-party/curl/docs/examples/smtp-mime.c | 33 +- third-party/curl/docs/examples/smtp-multi.c | 128 +- third-party/curl/docs/examples/smtp-ssl.c | 70 +- third-party/curl/docs/examples/smtp-tls.c | 72 +- third-party/curl/docs/examples/smtp-vrfy.c | 25 +- third-party/curl/docs/examples/sslbackend.c | 12 +- third-party/curl/docs/examples/synctime.c | 325 +- third-party/curl/docs/examples/threaded-ssl.c | 168 - third-party/curl/docs/examples/threaded.c | 116 + third-party/curl/docs/examples/unixsocket.c | 21 +- third-party/curl/docs/examples/url2file.c | 87 +- third-party/curl/docs/examples/urlapi.c | 24 +- .../curl/docs/examples/usercertinmem.c | 255 +- .../curl/docs/examples/version-check.pl | 22 +- third-party/curl/docs/examples/websocket-cb.c | 28 +- .../curl/docs/examples/websocket-updown.c | 128 + third-party/curl/docs/examples/websocket.c | 139 +- third-party/curl/docs/examples/xmlstream.c | 115 +- third-party/curl/docs/internals/BUFQ.md | 184 + .../curl/docs/{ => internals}/BUFREF.md | 33 +- third-party/curl/docs/internals/CHECKSRC.md | 195 + .../curl/docs/internals/CLIENT-READERS.md | 206 + .../curl/docs/internals/CLIENT-WRITERS.md | 168 + .../curl/docs/{ => internals}/CODE_STYLE.md | 132 +- .../curl/docs/internals/CONNECTION-FILTERS.md | 343 + .../curl/docs/internals/CREDENTIALS.md | 76 + third-party/curl/docs/internals/CURLX.md | 24 + third-party/curl/docs/internals/DYNBUF.md | 145 + third-party/curl/docs/internals/HASH.md | 151 + third-party/curl/docs/internals/LLIST.md | 195 + third-party/curl/docs/internals/MID.md | 72 + third-party/curl/docs/internals/MQTT.md | 61 + third-party/curl/docs/internals/MULTI-EV.md | 127 + .../curl/docs/{ => internals}/NEW-PROTOCOL.md | 44 +- third-party/curl/docs/internals/PEERS.md | 130 + third-party/curl/docs/internals/PORTING.md | 47 + third-party/curl/docs/internals/RATELIMITS.md | 100 + third-party/curl/docs/internals/README.md | 12 + third-party/curl/docs/internals/SCORECARD.md | 90 + third-party/curl/docs/internals/SPLAY.md | 111 + third-party/curl/docs/internals/STRPARSE.md | 230 + .../curl/docs/internals/THRDPOOL-AND-QUEUE.md | 112 + .../curl/docs/internals/TIME-KEEPING.md | 53 + .../curl/docs/internals/TLS-SESSIONS.md | 161 + third-party/curl/docs/internals/UINT_SETS.md | 137 + .../curl/docs/{ => internals}/WEBSOCKET.md | 38 +- third-party/curl/docs/libcurl/.gitignore | 5 +- third-party/curl/docs/libcurl/ABI.md | 75 +- third-party/curl/docs/libcurl/CMakeLists.txt | 85 +- third-party/curl/docs/libcurl/Makefile.am | 56 +- third-party/curl/docs/libcurl/Makefile.inc | 202 +- .../curl/docs/libcurl/curl_easy_cleanup.3 | 75 - .../curl/docs/libcurl/curl_easy_cleanup.md | 79 + .../curl/docs/libcurl/curl_easy_duphandle.3 | 70 - .../curl/docs/libcurl/curl_easy_duphandle.md | 77 + .../curl/docs/libcurl/curl_easy_escape.3 | 75 - .../curl/docs/libcurl/curl_easy_escape.md | 92 + .../curl/docs/libcurl/curl_easy_getinfo.3 | 325 - .../curl/docs/libcurl/curl_easy_getinfo.md | 447 ++ .../curl/docs/libcurl/curl_easy_header.3 | 140 - .../curl/docs/libcurl/curl_easy_header.md | 165 + .../curl/docs/libcurl/curl_easy_init.3 | 76 - .../curl/docs/libcurl/curl_easy_init.md | 76 + .../curl/docs/libcurl/curl_easy_nextheader.3 | 96 - .../curl/docs/libcurl/curl_easy_nextheader.md | 107 + .../docs/libcurl/curl_easy_option_by_id.3 | 55 - .../docs/libcurl/curl_easy_option_by_id.md | 56 + .../docs/libcurl/curl_easy_option_by_name.3 | 54 - .../docs/libcurl/curl_easy_option_by_name.md | 55 + .../curl/docs/libcurl/curl_easy_option_next.3 | 86 - .../docs/libcurl/curl_easy_option_next.md | 92 + .../curl/docs/libcurl/curl_easy_pause.3 | 116 - .../curl/docs/libcurl/curl_easy_pause.md | 142 + .../curl/docs/libcurl/curl_easy_perform.3 | 85 - .../curl/docs/libcurl/curl_easy_perform.md | 88 + .../curl/docs/libcurl/curl_easy_recv.3 | 97 - .../curl/docs/libcurl/curl_easy_recv.md | 106 + .../curl/docs/libcurl/curl_easy_reset.3 | 55 - .../curl/docs/libcurl/curl_easy_reset.md | 59 + .../curl/docs/libcurl/curl_easy_send.3 | 90 - .../curl/docs/libcurl/curl_easy_send.md | 98 + .../curl/docs/libcurl/curl_easy_setopt.3 | 742 -- .../curl/docs/libcurl/curl_easy_setopt.md | 1391 ++++ .../docs/libcurl/curl_easy_ssls_export.md | 175 + .../docs/libcurl/curl_easy_ssls_import.md | 89 + .../curl/docs/libcurl/curl_easy_strerror.3 | 54 - .../curl/docs/libcurl/curl_easy_strerror.md | 62 + .../curl/docs/libcurl/curl_easy_unescape.3 | 75 - .../curl/docs/libcurl/curl_easy_unescape.md | 77 + .../curl/docs/libcurl/curl_easy_upkeep.3 | 81 - .../curl/docs/libcurl/curl_easy_upkeep.md | 90 + third-party/curl/docs/libcurl/curl_escape.3 | 59 - third-party/curl/docs/libcurl/curl_escape.md | 66 + third-party/curl/docs/libcurl/curl_formadd.3 | 268 - third-party/curl/docs/libcurl/curl_formadd.md | 322 + third-party/curl/docs/libcurl/curl_formfree.3 | 70 - .../curl/docs/libcurl/curl_formfree.md | 83 + third-party/curl/docs/libcurl/curl_formget.3 | 73 - third-party/curl/docs/libcurl/curl_formget.md | 75 + third-party/curl/docs/libcurl/curl_free.3 | 53 - third-party/curl/docs/libcurl/curl_free.md | 55 + third-party/curl/docs/libcurl/curl_getdate.3 | 120 - third-party/curl/docs/libcurl/curl_getdate.md | 134 + third-party/curl/docs/libcurl/curl_getenv.3 | 57 - third-party/curl/docs/libcurl/curl_getenv.md | 61 + .../curl/docs/libcurl/curl_global_cleanup.3 | 74 - .../curl/docs/libcurl/curl_global_cleanup.md | 82 + .../curl/docs/libcurl/curl_global_init.3 | 121 - .../curl/docs/libcurl/curl_global_init.md | 138 + .../curl/docs/libcurl/curl_global_init_mem.3 | 79 - .../curl/docs/libcurl/curl_global_init_mem.md | 111 + .../curl/docs/libcurl/curl_global_sslset.3 | 132 - .../curl/docs/libcurl/curl_global_sslset.md | 141 + .../curl/docs/libcurl/curl_global_trace.3 | 118 - .../curl/docs/libcurl/curl_global_trace.md | 212 + .../curl/docs/libcurl/curl_mime_addpart.3 | 69 - .../curl/docs/libcurl/curl_mime_addpart.md | 75 + .../curl/docs/libcurl/curl_mime_data.3 | 75 - .../curl/docs/libcurl/curl_mime_data.md | 86 + .../curl/docs/libcurl/curl_mime_data_cb.3 | 168 - .../curl/docs/libcurl/curl_mime_data_cb.md | 180 + .../curl/docs/libcurl/curl_mime_encoder.3 | 99 - .../curl/docs/libcurl/curl_mime_encoder.md | 110 + .../curl/docs/libcurl/curl_mime_filedata.3 | 87 - .../curl/docs/libcurl/curl_mime_filedata.md | 99 + .../curl/docs/libcurl/curl_mime_filename.3 | 75 - .../curl/docs/libcurl/curl_mime_filename.md | 89 + .../curl/docs/libcurl/curl_mime_free.3 | 63 - .../curl/docs/libcurl/curl_mime_free.md | 70 + .../curl/docs/libcurl/curl_mime_headers.3 | 68 - .../curl/docs/libcurl/curl_mime_headers.md | 88 + .../curl/docs/libcurl/curl_mime_init.3 | 73 - .../curl/docs/libcurl/curl_mime_init.md | 77 + .../curl/docs/libcurl/curl_mime_name.3 | 66 - .../curl/docs/libcurl/curl_mime_name.md | 77 + .../curl/docs/libcurl/curl_mime_subparts.3 | 75 - .../curl/docs/libcurl/curl_mime_subparts.md | 93 + .../curl/docs/libcurl/curl_mime_type.3 | 85 - .../curl/docs/libcurl/curl_mime_type.md | 96 + third-party/curl/docs/libcurl/curl_mprintf.3 | 254 - third-party/curl/docs/libcurl/curl_mprintf.md | 290 + .../curl/docs/libcurl/curl_multi_add_handle.3 | 83 - .../docs/libcurl/curl_multi_add_handle.md | 94 + .../curl/docs/libcurl/curl_multi_assign.3 | 74 - .../curl/docs/libcurl/curl_multi_assign.md | 84 + .../curl/docs/libcurl/curl_multi_cleanup.3 | 62 - .../curl/docs/libcurl/curl_multi_cleanup.md | 76 + .../curl/docs/libcurl/curl_multi_fdset.3 | 102 - .../curl/docs/libcurl/curl_multi_fdset.md | 129 + .../docs/libcurl/curl_multi_get_handles.md | 81 + .../curl/docs/libcurl/curl_multi_get_offt.md | 87 + .../curl/docs/libcurl/curl_multi_info_read.3 | 98 - .../curl/docs/libcurl/curl_multi_info_read.md | 105 + .../curl/docs/libcurl/curl_multi_init.3 | 53 - .../curl/docs/libcurl/curl_multi_init.md | 64 + .../docs/libcurl/curl_multi_notify_disable.md | 66 + .../docs/libcurl/curl_multi_notify_enable.md | 66 + .../curl/docs/libcurl/curl_multi_perform.3 | 99 - .../curl/docs/libcurl/curl_multi_perform.md | 118 + .../curl/docs/libcurl/curl_multi_poll.3 | 119 - .../curl/docs/libcurl/curl_multi_poll.md | 150 + .../docs/libcurl/curl_multi_remove_handle.3 | 71 - .../docs/libcurl/curl_multi_remove_handle.md | 79 + .../curl/docs/libcurl/curl_multi_setopt.3 | 89 - .../curl/docs/libcurl/curl_multi_setopt.md | 154 + .../curl/docs/libcurl/curl_multi_socket.3 | 92 - .../curl/docs/libcurl/curl_multi_socket.md | 89 + .../docs/libcurl/curl_multi_socket_action.3 | 114 - .../docs/libcurl/curl_multi_socket_action.md | 127 + .../curl/docs/libcurl/curl_multi_socket_all.3 | 1 - .../docs/libcurl/curl_multi_socket_all.md | 69 + .../curl/docs/libcurl/curl_multi_strerror.3 | 48 - .../curl/docs/libcurl/curl_multi_strerror.md | 54 + .../curl/docs/libcurl/curl_multi_timeout.3 | 83 - .../curl/docs/libcurl/curl_multi_timeout.md | 95 + .../curl/docs/libcurl/curl_multi_wait.3 | 126 - .../curl/docs/libcurl/curl_multi_wait.md | 128 + .../curl/docs/libcurl/curl_multi_waitfds.md | 112 + .../curl/docs/libcurl/curl_multi_wakeup.3 | 88 - .../curl/docs/libcurl/curl_multi_wakeup.md | 99 + .../docs/libcurl/curl_pushheader_byname.3 | 80 - .../docs/libcurl/curl_pushheader_byname.md | 86 + .../curl/docs/libcurl/curl_pushheader_bynum.3 | 70 - .../docs/libcurl/curl_pushheader_bynum.md | 73 + .../curl/docs/libcurl/curl_share_cleanup.3 | 55 - .../curl/docs/libcurl/curl_share_cleanup.md | 66 + .../curl/docs/libcurl/curl_share_init.3 | 57 - .../curl/docs/libcurl/curl_share_init.md | 59 + .../curl/docs/libcurl/curl_share_setopt.3 | 61 - .../curl/docs/libcurl/curl_share_setopt.md | 74 + .../curl/docs/libcurl/curl_share_strerror.3 | 48 - .../curl/docs/libcurl/curl_share_strerror.md | 53 + .../curl/docs/libcurl/curl_slist_append.3 | 77 - .../curl/docs/libcurl/curl_slist_append.md | 79 + .../curl/docs/libcurl/curl_slist_free_all.3 | 60 - .../curl/docs/libcurl/curl_slist_free_all.md | 64 + third-party/curl/docs/libcurl/curl_strequal.3 | 59 - .../curl/docs/libcurl/curl_strequal.md | 59 + .../curl/docs/libcurl/curl_strnequal.3 | 1 - .../curl/docs/libcurl/curl_strnequal.md | 62 + third-party/curl/docs/libcurl/curl_unescape.3 | 65 - .../curl/docs/libcurl/curl_unescape.md | 73 + third-party/curl/docs/libcurl/curl_url.3 | 62 - third-party/curl/docs/libcurl/curl_url.md | 70 + .../curl/docs/libcurl/curl_url_cleanup.3 | 50 - .../curl/docs/libcurl/curl_url_cleanup.md | 57 + third-party/curl/docs/libcurl/curl_url_dup.3 | 55 - third-party/curl/docs/libcurl/curl_url_dup.md | 59 + third-party/curl/docs/libcurl/curl_url_get.3 | 171 - third-party/curl/docs/libcurl/curl_url_get.md | 249 + third-party/curl/docs/libcurl/curl_url_set.3 | 205 - third-party/curl/docs/libcurl/curl_url_set.md | 280 + .../curl/docs/libcurl/curl_url_strerror.3 | 51 - .../curl/docs/libcurl/curl_url_strerror.md | 56 + third-party/curl/docs/libcurl/curl_version.3 | 49 - third-party/curl/docs/libcurl/curl_version.md | 53 + .../curl/docs/libcurl/curl_version_info.3 | 320 - .../curl/docs/libcurl/curl_version_info.md | 423 ++ third-party/curl/docs/libcurl/curl_ws_meta.3 | 118 - third-party/curl/docs/libcurl/curl_ws_meta.md | 172 + third-party/curl/docs/libcurl/curl_ws_recv.3 | 69 - third-party/curl/docs/libcurl/curl_ws_recv.md | 134 + third-party/curl/docs/libcurl/curl_ws_send.3 | 100 - third-party/curl/docs/libcurl/curl_ws_send.md | 137 + .../curl/docs/libcurl/curl_ws_start_frame.md | 150 + third-party/curl/docs/libcurl/libcurl-easy.3 | 61 - third-party/curl/docs/libcurl/libcurl-easy.md | 54 + .../curl/docs/libcurl/libcurl-env-dbg.md | 206 + third-party/curl/docs/libcurl/libcurl-env.3 | 99 - third-party/curl/docs/libcurl/libcurl-env.md | 93 + .../curl/docs/libcurl/libcurl-errors.3 | 438 -- .../curl/docs/libcurl/libcurl-errors.md | 762 ++ third-party/curl/docs/libcurl/libcurl-multi.3 | 182 - .../curl/docs/libcurl/libcurl-multi.md | 180 + .../curl/docs/libcurl/libcurl-security.3 | 426 -- .../curl/docs/libcurl/libcurl-security.md | 520 ++ third-party/curl/docs/libcurl/libcurl-share.3 | 67 - .../curl/docs/libcurl/libcurl-share.md | 65 + .../curl/docs/libcurl/libcurl-thread.3 | 123 - .../curl/docs/libcurl/libcurl-thread.md | 127 + .../curl/docs/libcurl/libcurl-tutorial.3 | 1394 ---- .../curl/docs/libcurl/libcurl-tutorial.md | 1465 ++++ third-party/curl/docs/libcurl/libcurl-url.3 | 147 - third-party/curl/docs/libcurl/libcurl-url.md | 163 + third-party/curl/docs/libcurl/libcurl-ws.3 | 114 - third-party/curl/docs/libcurl/libcurl-ws.md | 154 + third-party/curl/docs/libcurl/libcurl.3 | 228 - third-party/curl/docs/libcurl/libcurl.m4 | 343 +- third-party/curl/docs/libcurl/libcurl.md | 250 + .../curl/docs/libcurl/mksymbolsmanpage.pl | 295 +- .../curl/docs/libcurl/opts/CMakeLists.txt | 21 +- .../docs/libcurl/opts/CURLINFO_ACTIVESOCKET.3 | 75 - .../libcurl/opts/CURLINFO_ACTIVESOCKET.md | 84 + .../libcurl/opts/CURLINFO_APPCONNECT_TIME.3 | 69 - .../libcurl/opts/CURLINFO_APPCONNECT_TIME.md | 73 + .../libcurl/opts/CURLINFO_APPCONNECT_TIME_T.3 | 71 - .../opts/CURLINFO_APPCONNECT_TIME_T.md | 74 + .../curl/docs/libcurl/opts/CURLINFO_CAINFO.3 | 67 - .../curl/docs/libcurl/opts/CURLINFO_CAINFO.md | 70 + .../curl/docs/libcurl/opts/CURLINFO_CAPATH.3 | 67 - .../curl/docs/libcurl/opts/CURLINFO_CAPATH.md | 73 + .../docs/libcurl/opts/CURLINFO_CERTINFO.3 | 98 - .../docs/libcurl/opts/CURLINFO_CERTINFO.md | 109 + .../libcurl/opts/CURLINFO_CONDITION_UNMET.3 | 76 - .../libcurl/opts/CURLINFO_CONDITION_UNMET.md | 81 + .../docs/libcurl/opts/CURLINFO_CONNECT_TIME.3 | 65 - .../libcurl/opts/CURLINFO_CONNECT_TIME.md | 69 + .../libcurl/opts/CURLINFO_CONNECT_TIME_T.3 | 67 - .../libcurl/opts/CURLINFO_CONNECT_TIME_T.md | 72 + .../curl/docs/libcurl/opts/CURLINFO_CONN_ID.3 | 69 - .../docs/libcurl/opts/CURLINFO_CONN_ID.md | 72 + .../opts/CURLINFO_CONTENT_LENGTH_DOWNLOAD.3 | 69 - .../opts/CURLINFO_CONTENT_LENGTH_DOWNLOAD.md | 76 + .../opts/CURLINFO_CONTENT_LENGTH_DOWNLOAD_T.3 | 66 - .../CURLINFO_CONTENT_LENGTH_DOWNLOAD_T.md | 70 + .../opts/CURLINFO_CONTENT_LENGTH_UPLOAD.3 | 68 - .../opts/CURLINFO_CONTENT_LENGTH_UPLOAD.md | 75 + .../opts/CURLINFO_CONTENT_LENGTH_UPLOAD_T.3 | 65 - .../opts/CURLINFO_CONTENT_LENGTH_UPLOAD_T.md | 73 + .../docs/libcurl/opts/CURLINFO_CONTENT_TYPE.3 | 73 - .../libcurl/opts/CURLINFO_CONTENT_TYPE.md | 77 + .../docs/libcurl/opts/CURLINFO_COOKIELIST.3 | 81 - .../docs/libcurl/opts/CURLINFO_COOKIELIST.md | 84 + .../libcurl/opts/CURLINFO_EARLYDATA_SENT_T.md | 78 + .../libcurl/opts/CURLINFO_EFFECTIVE_METHOD.3 | 70 - .../libcurl/opts/CURLINFO_EFFECTIVE_METHOD.md | 74 + .../libcurl/opts/CURLINFO_EFFECTIVE_URL.3 | 67 - .../libcurl/opts/CURLINFO_EFFECTIVE_URL.md | 70 + .../docs/libcurl/opts/CURLINFO_FILETIME.3 | 73 - .../docs/libcurl/opts/CURLINFO_FILETIME.md | 79 + .../docs/libcurl/opts/CURLINFO_FILETIME_T.3 | 76 - .../docs/libcurl/opts/CURLINFO_FILETIME_T.md | 80 + .../libcurl/opts/CURLINFO_FTP_ENTRY_PATH.3 | 69 - .../libcurl/opts/CURLINFO_FTP_ENTRY_PATH.md | 77 + .../docs/libcurl/opts/CURLINFO_HEADER_SIZE.3 | 65 - .../docs/libcurl/opts/CURLINFO_HEADER_SIZE.md | 71 + .../libcurl/opts/CURLINFO_HTTPAUTH_AVAIL.3 | 74 - .../libcurl/opts/CURLINFO_HTTPAUTH_AVAIL.md | 77 + .../libcurl/opts/CURLINFO_HTTPAUTH_USED.md | 79 + .../libcurl/opts/CURLINFO_HTTP_CONNECTCODE.3 | 65 - .../libcurl/opts/CURLINFO_HTTP_CONNECTCODE.md | 67 + .../docs/libcurl/opts/CURLINFO_HTTP_VERSION.3 | 61 - .../libcurl/opts/CURLINFO_HTTP_VERSION.md | 63 + .../docs/libcurl/opts/CURLINFO_LASTSOCKET.3 | 75 - .../docs/libcurl/opts/CURLINFO_LASTSOCKET.md | 88 + .../docs/libcurl/opts/CURLINFO_LOCAL_IP.3 | 71 - .../docs/libcurl/opts/CURLINFO_LOCAL_IP.md | 75 + .../docs/libcurl/opts/CURLINFO_LOCAL_PORT.3 | 69 - .../docs/libcurl/opts/CURLINFO_LOCAL_PORT.md | 77 + .../libcurl/opts/CURLINFO_NAMELOOKUP_TIME.3 | 66 - .../libcurl/opts/CURLINFO_NAMELOOKUP_TIME.md | 70 + .../libcurl/opts/CURLINFO_NAMELOOKUP_TIME_T.3 | 67 - .../opts/CURLINFO_NAMELOOKUP_TIME_T.md | 72 + .../docs/libcurl/opts/CURLINFO_NUM_CONNECTS.3 | 65 - .../libcurl/opts/CURLINFO_NUM_CONNECTS.md | 67 + .../docs/libcurl/opts/CURLINFO_OS_ERRNO.3 | 62 - .../docs/libcurl/opts/CURLINFO_OS_ERRNO.md | 72 + .../opts/CURLINFO_POSTTRANSFER_TIME_T.md | 73 + .../libcurl/opts/CURLINFO_PRETRANSFER_TIME.3 | 70 - .../libcurl/opts/CURLINFO_PRETRANSFER_TIME.md | 76 + .../opts/CURLINFO_PRETRANSFER_TIME_T.3 | 71 - .../opts/CURLINFO_PRETRANSFER_TIME_T.md | 78 + .../docs/libcurl/opts/CURLINFO_PRIMARY_IP.3 | 71 - .../docs/libcurl/opts/CURLINFO_PRIMARY_IP.md | 75 + .../docs/libcurl/opts/CURLINFO_PRIMARY_PORT.3 | 65 - .../libcurl/opts/CURLINFO_PRIMARY_PORT.md | 74 + .../curl/docs/libcurl/opts/CURLINFO_PRIVATE.3 | 64 - .../docs/libcurl/opts/CURLINFO_PRIVATE.md | 70 + .../docs/libcurl/opts/CURLINFO_PROTOCOL.3 | 72 - .../docs/libcurl/opts/CURLINFO_PROTOCOL.md | 79 + .../libcurl/opts/CURLINFO_PROXYAUTH_AVAIL.3 | 76 - .../libcurl/opts/CURLINFO_PROXYAUTH_AVAIL.md | 78 + .../libcurl/opts/CURLINFO_PROXYAUTH_USED.md | 82 + .../docs/libcurl/opts/CURLINFO_PROXY_ERROR.3 | 104 - .../docs/libcurl/opts/CURLINFO_PROXY_ERROR.md | 107 + .../opts/CURLINFO_PROXY_SSL_VERIFYRESULT.3 | 62 - .../opts/CURLINFO_PROXY_SSL_VERIFYRESULT.md | 80 + .../libcurl/opts/CURLINFO_QUEUE_TIME_T.md | 72 + .../libcurl/opts/CURLINFO_REDIRECT_COUNT.3 | 60 - .../libcurl/opts/CURLINFO_REDIRECT_COUNT.md | 64 + .../libcurl/opts/CURLINFO_REDIRECT_TIME.3 | 66 - .../libcurl/opts/CURLINFO_REDIRECT_TIME.md | 72 + .../libcurl/opts/CURLINFO_REDIRECT_TIME_T.3 | 68 - .../libcurl/opts/CURLINFO_REDIRECT_TIME_T.md | 74 + .../docs/libcurl/opts/CURLINFO_REDIRECT_URL.3 | 66 - .../libcurl/opts/CURLINFO_REDIRECT_URL.md | 71 + .../curl/docs/libcurl/opts/CURLINFO_REFERER.3 | 65 - .../docs/libcurl/opts/CURLINFO_REFERER.md | 69 + .../docs/libcurl/opts/CURLINFO_REQUEST_SIZE.3 | 63 - .../libcurl/opts/CURLINFO_REQUEST_SIZE.md | 65 + .../libcurl/opts/CURLINFO_RESPONSE_CODE.3 | 65 - .../libcurl/opts/CURLINFO_RESPONSE_CODE.md | 74 + .../docs/libcurl/opts/CURLINFO_RETRY_AFTER.3 | 68 - .../docs/libcurl/opts/CURLINFO_RETRY_AFTER.md | 78 + .../libcurl/opts/CURLINFO_RTSP_CLIENT_CSEQ.3 | 59 - .../libcurl/opts/CURLINFO_RTSP_CLIENT_CSEQ.md | 63 + .../libcurl/opts/CURLINFO_RTSP_CSEQ_RECV.3 | 60 - .../libcurl/opts/CURLINFO_RTSP_CSEQ_RECV.md | 63 + .../libcurl/opts/CURLINFO_RTSP_SERVER_CSEQ.3 | 64 - .../libcurl/opts/CURLINFO_RTSP_SERVER_CSEQ.md | 67 + .../libcurl/opts/CURLINFO_RTSP_SESSION_ID.3 | 65 - .../libcurl/opts/CURLINFO_RTSP_SESSION_ID.md | 68 + .../curl/docs/libcurl/opts/CURLINFO_SCHEME.3 | 66 - .../curl/docs/libcurl/opts/CURLINFO_SCHEME.md | 74 + .../libcurl/opts/CURLINFO_SIZE_DELIVERED.md | 78 + .../libcurl/opts/CURLINFO_SIZE_DOWNLOAD.3 | 71 - .../libcurl/opts/CURLINFO_SIZE_DOWNLOAD.md | 79 + .../libcurl/opts/CURLINFO_SIZE_DOWNLOAD_T.3 | 68 - .../libcurl/opts/CURLINFO_SIZE_DOWNLOAD_T.md | 72 + .../docs/libcurl/opts/CURLINFO_SIZE_UPLOAD.3 | 67 - .../docs/libcurl/opts/CURLINFO_SIZE_UPLOAD.md | 75 + .../libcurl/opts/CURLINFO_SIZE_UPLOAD_T.3 | 64 - .../libcurl/opts/CURLINFO_SIZE_UPLOAD_T.md | 68 + .../libcurl/opts/CURLINFO_SPEED_DOWNLOAD.3 | 67 - .../libcurl/opts/CURLINFO_SPEED_DOWNLOAD.md | 75 + .../libcurl/opts/CURLINFO_SPEED_DOWNLOAD_T.3 | 64 - .../libcurl/opts/CURLINFO_SPEED_DOWNLOAD_T.md | 69 + .../docs/libcurl/opts/CURLINFO_SPEED_UPLOAD.3 | 65 - .../libcurl/opts/CURLINFO_SPEED_UPLOAD.md | 73 + .../libcurl/opts/CURLINFO_SPEED_UPLOAD_T.3 | 63 - .../libcurl/opts/CURLINFO_SPEED_UPLOAD_T.md | 67 + .../docs/libcurl/opts/CURLINFO_SSL_ENGINES.3 | 64 - .../docs/libcurl/opts/CURLINFO_SSL_ENGINES.md | 69 + .../libcurl/opts/CURLINFO_SSL_VERIFYRESULT.3 | 62 - .../libcurl/opts/CURLINFO_SSL_VERIFYRESULT.md | 79 + .../opts/CURLINFO_STARTTRANSFER_TIME.3 | 68 - .../opts/CURLINFO_STARTTRANSFER_TIME.md | 73 + .../opts/CURLINFO_STARTTRANSFER_TIME_T.3 | 70 - .../opts/CURLINFO_STARTTRANSFER_TIME_T.md | 75 + .../docs/libcurl/opts/CURLINFO_TLS_SESSION.3 | 72 - .../docs/libcurl/opts/CURLINFO_TLS_SESSION.md | 94 + .../docs/libcurl/opts/CURLINFO_TLS_SSL_PTR.3 | 163 - .../docs/libcurl/opts/CURLINFO_TLS_SSL_PTR.md | 171 + .../docs/libcurl/opts/CURLINFO_TOTAL_TIME.3 | 66 - .../docs/libcurl/opts/CURLINFO_TOTAL_TIME.md | 71 + .../docs/libcurl/opts/CURLINFO_TOTAL_TIME_T.3 | 68 - .../libcurl/opts/CURLINFO_TOTAL_TIME_T.md | 72 + .../docs/libcurl/opts/CURLINFO_USED_PROXY.md | 71 + .../curl/docs/libcurl/opts/CURLINFO_XFER_ID.3 | 70 - .../docs/libcurl/opts/CURLINFO_XFER_ID.md | 72 + .../libcurl/opts/CURLMINFO_XFERS_ADDED.md | 63 + .../libcurl/opts/CURLMINFO_XFERS_CURRENT.md | 62 + .../docs/libcurl/opts/CURLMINFO_XFERS_DONE.md | 58 + .../libcurl/opts/CURLMINFO_XFERS_PENDING.md | 60 + .../libcurl/opts/CURLMINFO_XFERS_RUNNING.md | 58 + .../opts/CURLMOPT_CHUNK_LENGTH_PENALTY_SIZE.3 | 59 - .../CURLMOPT_CHUNK_LENGTH_PENALTY_SIZE.md | 63 + .../CURLMOPT_CONTENT_LENGTH_PENALTY_SIZE.3 | 58 - .../CURLMOPT_CONTENT_LENGTH_PENALTY_SIZE.md | 62 + .../docs/libcurl/opts/CURLMOPT_MAXCONNECTS.3 | 69 - .../docs/libcurl/opts/CURLMOPT_MAXCONNECTS.md | 75 + .../opts/CURLMOPT_MAX_CONCURRENT_STREAMS.3 | 57 - .../opts/CURLMOPT_MAX_CONCURRENT_STREAMS.md | 61 + .../opts/CURLMOPT_MAX_HOST_CONNECTIONS.3 | 70 - .../opts/CURLMOPT_MAX_HOST_CONNECTIONS.md | 80 + .../opts/CURLMOPT_MAX_PIPELINE_LENGTH.3 | 62 - .../opts/CURLMOPT_MAX_PIPELINE_LENGTH.md | 66 + .../opts/CURLMOPT_MAX_TOTAL_CONNECTIONS.3 | 68 - .../opts/CURLMOPT_MAX_TOTAL_CONNECTIONS.md | 77 + .../libcurl/opts/CURLMOPT_NETWORK_CHANGED.md | 83 + .../docs/libcurl/opts/CURLMOPT_NOTIFYDATA.md | 72 + .../libcurl/opts/CURLMOPT_NOTIFYFUNCTION.md | 130 + .../docs/libcurl/opts/CURLMOPT_PIPELINING.3 | 71 - .../docs/libcurl/opts/CURLMOPT_PIPELINING.md | 85 + .../opts/CURLMOPT_PIPELINING_SERVER_BL.3 | 67 - .../opts/CURLMOPT_PIPELINING_SERVER_BL.md | 72 + .../opts/CURLMOPT_PIPELINING_SITE_BL.3 | 63 - .../opts/CURLMOPT_PIPELINING_SITE_BL.md | 68 + .../docs/libcurl/opts/CURLMOPT_PUSHDATA.3 | 81 - .../docs/libcurl/opts/CURLMOPT_PUSHDATA.md | 89 + .../docs/libcurl/opts/CURLMOPT_PUSHFUNCTION.3 | 130 - .../libcurl/opts/CURLMOPT_PUSHFUNCTION.md | 150 + .../docs/libcurl/opts/CURLMOPT_QUICK_EXIT.md | 60 + .../opts/CURLMOPT_RESOLVE_THREADS_MAX.md | 75 + .../docs/libcurl/opts/CURLMOPT_SOCKETDATA.3 | 78 - .../docs/libcurl/opts/CURLMOPT_SOCKETDATA.md | 81 + .../libcurl/opts/CURLMOPT_SOCKETFUNCTION.3 | 121 - .../libcurl/opts/CURLMOPT_SOCKETFUNCTION.md | 156 + .../docs/libcurl/opts/CURLMOPT_TIMERDATA.3 | 84 - .../docs/libcurl/opts/CURLMOPT_TIMERDATA.md | 78 + .../libcurl/opts/CURLMOPT_TIMERFUNCTION.3 | 112 - .../libcurl/opts/CURLMOPT_TIMERFUNCTION.md | 111 + .../opts/CURLOPT_ABSTRACT_UNIX_SOCKET.3 | 64 - .../opts/CURLOPT_ABSTRACT_UNIX_SOCKET.md | 75 + .../libcurl/opts/CURLOPT_ACCEPTTIMEOUT_MS.3 | 58 - .../libcurl/opts/CURLOPT_ACCEPTTIMEOUT_MS.md | 70 + .../libcurl/opts/CURLOPT_ACCEPT_ENCODING.3 | 108 - .../libcurl/opts/CURLOPT_ACCEPT_ENCODING.md | 129 + .../docs/libcurl/opts/CURLOPT_ADDRESS_SCOPE.3 | 59 - .../libcurl/opts/CURLOPT_ADDRESS_SCOPE.md | 65 + .../curl/docs/libcurl/opts/CURLOPT_ALTSVC.3 | 89 - .../curl/docs/libcurl/opts/CURLOPT_ALTSVC.md | 136 + .../docs/libcurl/opts/CURLOPT_ALTSVC_CTRL.3 | 86 - .../docs/libcurl/opts/CURLOPT_ALTSVC_CTRL.md | 108 + .../curl/docs/libcurl/opts/CURLOPT_APPEND.3 | 59 - .../curl/docs/libcurl/opts/CURLOPT_APPEND.md | 69 + .../docs/libcurl/opts/CURLOPT_AUTOREFERER.3 | 68 - .../docs/libcurl/opts/CURLOPT_AUTOREFERER.md | 79 + .../docs/libcurl/opts/CURLOPT_AWS_SIGV4.3 | 105 - .../docs/libcurl/opts/CURLOPT_AWS_SIGV4.md | 131 + .../docs/libcurl/opts/CURLOPT_BUFFERSIZE.3 | 75 - .../docs/libcurl/opts/CURLOPT_BUFFERSIZE.md | 86 + .../curl/docs/libcurl/opts/CURLOPT_CAINFO.3 | 83 - .../curl/docs/libcurl/opts/CURLOPT_CAINFO.md | 92 + .../docs/libcurl/opts/CURLOPT_CAINFO_BLOB.3 | 73 - .../docs/libcurl/opts/CURLOPT_CAINFO_BLOB.md | 93 + .../curl/docs/libcurl/opts/CURLOPT_CAPATH.3 | 76 - .../curl/docs/libcurl/opts/CURLOPT_CAPATH.md | 85 + .../libcurl/opts/CURLOPT_CA_CACHE_TIMEOUT.3 | 78 - .../libcurl/opts/CURLOPT_CA_CACHE_TIMEOUT.md | 92 + .../curl/docs/libcurl/opts/CURLOPT_CERTINFO.3 | 83 - .../docs/libcurl/opts/CURLOPT_CERTINFO.md | 99 + .../libcurl/opts/CURLOPT_CHUNK_BGN_FUNCTION.3 | 143 - .../opts/CURLOPT_CHUNK_BGN_FUNCTION.md | 155 + .../docs/libcurl/opts/CURLOPT_CHUNK_DATA.3 | 94 - .../docs/libcurl/opts/CURLOPT_CHUNK_DATA.md | 104 + .../libcurl/opts/CURLOPT_CHUNK_END_FUNCTION.3 | 73 - .../opts/CURLOPT_CHUNK_END_FUNCTION.md | 85 + .../libcurl/opts/CURLOPT_CLOSESOCKETDATA.3 | 60 - .../libcurl/opts/CURLOPT_CLOSESOCKETDATA.md | 84 + .../opts/CURLOPT_CLOSESOCKETFUNCTION.3 | 71 - .../opts/CURLOPT_CLOSESOCKETFUNCTION.md | 95 + .../libcurl/opts/CURLOPT_CONNECTTIMEOUT.3 | 86 - .../libcurl/opts/CURLOPT_CONNECTTIMEOUT.md | 91 + .../libcurl/opts/CURLOPT_CONNECTTIMEOUT_MS.3 | 62 - .../libcurl/opts/CURLOPT_CONNECTTIMEOUT_MS.md | 92 + .../docs/libcurl/opts/CURLOPT_CONNECT_ONLY.3 | 80 - .../docs/libcurl/opts/CURLOPT_CONNECT_ONLY.md | 89 + .../docs/libcurl/opts/CURLOPT_CONNECT_TO.3 | 113 - .../docs/libcurl/opts/CURLOPT_CONNECT_TO.md | 120 + .../opts/CURLOPT_CONV_FROM_NETWORK_FUNCTION.3 | 105 - .../CURLOPT_CONV_FROM_NETWORK_FUNCTION.md | 120 + .../opts/CURLOPT_CONV_FROM_UTF8_FUNCTION.3 | 103 - .../opts/CURLOPT_CONV_FROM_UTF8_FUNCTION.md | 113 + .../opts/CURLOPT_CONV_TO_NETWORK_FUNCTION.3 | 104 - .../opts/CURLOPT_CONV_TO_NETWORK_FUNCTION.md | 116 + .../curl/docs/libcurl/opts/CURLOPT_COOKIE.3 | 87 - .../curl/docs/libcurl/opts/CURLOPT_COOKIE.md | 97 + .../docs/libcurl/opts/CURLOPT_COOKIEFILE.3 | 95 - .../docs/libcurl/opts/CURLOPT_COOKIEFILE.md | 108 + .../docs/libcurl/opts/CURLOPT_COOKIEJAR.3 | 83 - .../docs/libcurl/opts/CURLOPT_COOKIEJAR.md | 99 + .../docs/libcurl/opts/CURLOPT_COOKIELIST.3 | 123 - .../docs/libcurl/opts/CURLOPT_COOKIELIST.md | 142 + .../docs/libcurl/opts/CURLOPT_COOKIESESSION.3 | 71 - .../libcurl/opts/CURLOPT_COOKIESESSION.md | 77 + .../libcurl/opts/CURLOPT_COPYPOSTFIELDS.3 | 74 - .../libcurl/opts/CURLOPT_COPYPOSTFIELDS.md | 88 + .../curl/docs/libcurl/opts/CURLOPT_CRLF.3 | 60 - .../curl/docs/libcurl/opts/CURLOPT_CRLF.md | 64 + .../curl/docs/libcurl/opts/CURLOPT_CRLFILE.3 | 79 - .../curl/docs/libcurl/opts/CURLOPT_CRLFILE.md | 91 + .../curl/docs/libcurl/opts/CURLOPT_CURLU.3 | 74 - .../curl/docs/libcurl/opts/CURLOPT_CURLU.md | 81 + .../docs/libcurl/opts/CURLOPT_CUSTOMREQUEST.3 | 115 - .../libcurl/opts/CURLOPT_CUSTOMREQUEST.md | 142 + .../docs/libcurl/opts/CURLOPT_DEBUGDATA.3 | 73 - .../docs/libcurl/opts/CURLOPT_DEBUGDATA.md | 89 + .../docs/libcurl/opts/CURLOPT_DEBUGFUNCTION.3 | 194 - .../libcurl/opts/CURLOPT_DEBUGFUNCTION.md | 221 + .../libcurl/opts/CURLOPT_DEFAULT_PROTOCOL.3 | 86 - .../libcurl/opts/CURLOPT_DEFAULT_PROTOCOL.md | 93 + .../docs/libcurl/opts/CURLOPT_DIRLISTONLY.3 | 77 - .../docs/libcurl/opts/CURLOPT_DIRLISTONLY.md | 91 + .../opts/CURLOPT_DISALLOW_USERNAME_IN_URL.3 | 65 - .../opts/CURLOPT_DISALLOW_USERNAME_IN_URL.md | 73 + .../libcurl/opts/CURLOPT_DNS_CACHE_TIMEOUT.3 | 85 - .../libcurl/opts/CURLOPT_DNS_CACHE_TIMEOUT.md | 95 + .../docs/libcurl/opts/CURLOPT_DNS_INTERFACE.3 | 64 - .../libcurl/opts/CURLOPT_DNS_INTERFACE.md | 76 + .../docs/libcurl/opts/CURLOPT_DNS_LOCAL_IP4.3 | 66 - .../libcurl/opts/CURLOPT_DNS_LOCAL_IP4.md | 75 + .../docs/libcurl/opts/CURLOPT_DNS_LOCAL_IP6.3 | 66 - .../libcurl/opts/CURLOPT_DNS_LOCAL_IP6.md | 75 + .../docs/libcurl/opts/CURLOPT_DNS_SERVERS.3 | 71 - .../docs/libcurl/opts/CURLOPT_DNS_SERVERS.md | 80 + .../opts/CURLOPT_DNS_SHUFFLE_ADDRESSES.3 | 73 - .../opts/CURLOPT_DNS_SHUFFLE_ADDRESSES.md | 75 + .../opts/CURLOPT_DNS_USE_GLOBAL_CACHE.3 | 65 - .../opts/CURLOPT_DNS_USE_GLOBAL_CACHE.md | 74 + .../libcurl/opts/CURLOPT_DOH_SSL_VERIFYHOST.3 | 88 - .../opts/CURLOPT_DOH_SSL_VERIFYHOST.md | 94 + .../libcurl/opts/CURLOPT_DOH_SSL_VERIFYPEER.3 | 101 - .../opts/CURLOPT_DOH_SSL_VERIFYPEER.md | 106 + .../opts/CURLOPT_DOH_SSL_VERIFYSTATUS.3 | 74 - .../opts/CURLOPT_DOH_SSL_VERIFYSTATUS.md | 81 + .../curl/docs/libcurl/opts/CURLOPT_DOH_URL.3 | 90 - .../curl/docs/libcurl/opts/CURLOPT_DOH_URL.md | 104 + .../curl/docs/libcurl/opts/CURLOPT_ECH.md | 109 + .../docs/libcurl/opts/CURLOPT_EGDSOCKET.3 | 65 - .../docs/libcurl/opts/CURLOPT_EGDSOCKET.md | 47 + .../docs/libcurl/opts/CURLOPT_ERRORBUFFER.3 | 96 - .../docs/libcurl/opts/CURLOPT_ERRORBUFFER.md | 113 + .../opts/CURLOPT_EXPECT_100_TIMEOUT_MS.3 | 61 - .../opts/CURLOPT_EXPECT_100_TIMEOUT_MS.md | 68 + .../docs/libcurl/opts/CURLOPT_FAILONERROR.3 | 71 - .../docs/libcurl/opts/CURLOPT_FAILONERROR.md | 76 + .../curl/docs/libcurl/opts/CURLOPT_FILETIME.3 | 68 - .../docs/libcurl/opts/CURLOPT_FILETIME.md | 78 + .../docs/libcurl/opts/CURLOPT_FNMATCH_DATA.3 | 66 - .../docs/libcurl/opts/CURLOPT_FNMATCH_DATA.md | 84 + .../libcurl/opts/CURLOPT_FNMATCH_FUNCTION.3 | 76 - .../libcurl/opts/CURLOPT_FNMATCH_FUNCTION.md | 92 + .../libcurl/opts/CURLOPT_FOLLOWLOCATION.3 | 88 - .../libcurl/opts/CURLOPT_FOLLOWLOCATION.md | 160 + .../docs/libcurl/opts/CURLOPT_FORBID_REUSE.3 | 64 - .../docs/libcurl/opts/CURLOPT_FORBID_REUSE.md | 74 + .../docs/libcurl/opts/CURLOPT_FRESH_CONNECT.3 | 63 - .../libcurl/opts/CURLOPT_FRESH_CONNECT.md | 72 + .../curl/docs/libcurl/opts/CURLOPT_FTPPORT.3 | 95 - .../curl/docs/libcurl/opts/CURLOPT_FTPPORT.md | 100 + .../docs/libcurl/opts/CURLOPT_FTPSSLAUTH.3 | 67 - .../docs/libcurl/opts/CURLOPT_FTPSSLAUTH.md | 83 + .../docs/libcurl/opts/CURLOPT_FTP_ACCOUNT.3 | 64 - .../docs/libcurl/opts/CURLOPT_FTP_ACCOUNT.md | 71 + .../opts/CURLOPT_FTP_ALTERNATIVE_TO_USER.3 | 65 - .../opts/CURLOPT_FTP_ALTERNATIVE_TO_USER.md | 71 + .../opts/CURLOPT_FTP_CREATE_MISSING_DIRS.3 | 83 - .../opts/CURLOPT_FTP_CREATE_MISSING_DIRS.md | 91 + .../libcurl/opts/CURLOPT_FTP_FILEMETHOD.3 | 76 - .../libcurl/opts/CURLOPT_FTP_FILEMETHOD.md | 92 + .../libcurl/opts/CURLOPT_FTP_SKIP_PASV_IP.3 | 69 - .../libcurl/opts/CURLOPT_FTP_SKIP_PASV_IP.md | 78 + .../docs/libcurl/opts/CURLOPT_FTP_SSL_CCC.3 | 68 - .../docs/libcurl/opts/CURLOPT_FTP_SSL_CCC.md | 85 + .../docs/libcurl/opts/CURLOPT_FTP_USE_EPRT.3 | 73 - .../docs/libcurl/opts/CURLOPT_FTP_USE_EPRT.md | 77 + .../docs/libcurl/opts/CURLOPT_FTP_USE_EPSV.3 | 70 - .../docs/libcurl/opts/CURLOPT_FTP_USE_EPSV.md | 75 + .../docs/libcurl/opts/CURLOPT_FTP_USE_PRET.3 | 62 - .../docs/libcurl/opts/CURLOPT_FTP_USE_PRET.md | 68 + .../libcurl/opts/CURLOPT_GSSAPI_DELEGATION.3 | 64 - .../libcurl/opts/CURLOPT_GSSAPI_DELEGATION.md | 72 + .../opts/CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS.3 | 69 - .../opts/CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS.md | 130 + .../libcurl/opts/CURLOPT_HAPROXYPROTOCOL.3 | 63 - .../libcurl/opts/CURLOPT_HAPROXYPROTOCOL.md | 70 + .../libcurl/opts/CURLOPT_HAPROXY_CLIENT_IP.3 | 62 - .../libcurl/opts/CURLOPT_HAPROXY_CLIENT_IP.md | 81 + .../curl/docs/libcurl/opts/CURLOPT_HEADER.3 | 75 - .../curl/docs/libcurl/opts/CURLOPT_HEADER.md | 84 + .../docs/libcurl/opts/CURLOPT_HEADERDATA.3 | 86 - .../docs/libcurl/opts/CURLOPT_HEADERDATA.md | 94 + .../libcurl/opts/CURLOPT_HEADERFUNCTION.3 | 128 - .../libcurl/opts/CURLOPT_HEADERFUNCTION.md | 140 + .../docs/libcurl/opts/CURLOPT_HEADEROPT.3 | 79 - .../docs/libcurl/opts/CURLOPT_HEADEROPT.md | 88 + .../curl/docs/libcurl/opts/CURLOPT_HSTS.3 | 78 - .../curl/docs/libcurl/opts/CURLOPT_HSTS.md | 105 + .../docs/libcurl/opts/CURLOPT_HSTSREADDATA.3 | 65 - .../docs/libcurl/opts/CURLOPT_HSTSREADDATA.md | 82 + .../libcurl/opts/CURLOPT_HSTSREADFUNCTION.3 | 88 - .../libcurl/opts/CURLOPT_HSTSREADFUNCTION.md | 110 + .../docs/libcurl/opts/CURLOPT_HSTSWRITEDATA.3 | 65 - .../libcurl/opts/CURLOPT_HSTSWRITEDATA.md | 73 + .../libcurl/opts/CURLOPT_HSTSWRITEFUNCTION.3 | 92 - .../libcurl/opts/CURLOPT_HSTSWRITEFUNCTION.md | 109 + .../docs/libcurl/opts/CURLOPT_HSTS_CTRL.3 | 70 - .../docs/libcurl/opts/CURLOPT_HSTS_CTRL.md | 85 + .../libcurl/opts/CURLOPT_HTTP09_ALLOWED.3 | 62 - .../libcurl/opts/CURLOPT_HTTP09_ALLOWED.md | 70 + .../libcurl/opts/CURLOPT_HTTP200ALIASES.3 | 72 - .../libcurl/opts/CURLOPT_HTTP200ALIASES.md | 85 + .../curl/docs/libcurl/opts/CURLOPT_HTTPAUTH.3 | 138 - .../docs/libcurl/opts/CURLOPT_HTTPAUTH.md | 168 + .../curl/docs/libcurl/opts/CURLOPT_HTTPGET.3 | 68 - .../curl/docs/libcurl/opts/CURLOPT_HTTPGET.md | 75 + .../docs/libcurl/opts/CURLOPT_HTTPHEADER.3 | 162 - .../docs/libcurl/opts/CURLOPT_HTTPHEADER.md | 205 + .../curl/docs/libcurl/opts/CURLOPT_HTTPPOST.3 | 83 - .../docs/libcurl/opts/CURLOPT_HTTPPOST.md | 107 + .../libcurl/opts/CURLOPT_HTTPPROXYTUNNEL.3 | 72 - .../libcurl/opts/CURLOPT_HTTPPROXYTUNNEL.md | 79 + .../opts/CURLOPT_HTTP_CONTENT_DECODING.3 | 59 - .../opts/CURLOPT_HTTP_CONTENT_DECODING.md | 64 + .../opts/CURLOPT_HTTP_TRANSFER_DECODING.3 | 58 - .../opts/CURLOPT_HTTP_TRANSFER_DECODING.md | 62 + .../docs/libcurl/opts/CURLOPT_HTTP_VERSION.3 | 101 - .../docs/libcurl/opts/CURLOPT_HTTP_VERSION.md | 131 + .../opts/CURLOPT_IGNORE_CONTENT_LENGTH.3 | 70 - .../opts/CURLOPT_IGNORE_CONTENT_LENGTH.md | 81 + .../docs/libcurl/opts/CURLOPT_INFILESIZE.3 | 78 - .../docs/libcurl/opts/CURLOPT_INFILESIZE.md | 93 + .../libcurl/opts/CURLOPT_INFILESIZE_LARGE.3 | 74 - .../libcurl/opts/CURLOPT_INFILESIZE_LARGE.md | 89 + .../docs/libcurl/opts/CURLOPT_INTERFACE.3 | 80 - .../docs/libcurl/opts/CURLOPT_INTERFACE.md | 95 + .../libcurl/opts/CURLOPT_INTERLEAVEDATA.3 | 62 - .../libcurl/opts/CURLOPT_INTERLEAVEDATA.md | 76 + .../libcurl/opts/CURLOPT_INTERLEAVEFUNCTION.3 | 92 - .../opts/CURLOPT_INTERLEAVEFUNCTION.md | 104 + .../docs/libcurl/opts/CURLOPT_IOCTLDATA.3 | 64 - .../docs/libcurl/opts/CURLOPT_IOCTLDATA.md | 78 + .../docs/libcurl/opts/CURLOPT_IOCTLFUNCTION.3 | 94 - .../libcurl/opts/CURLOPT_IOCTLFUNCTION.md | 109 + .../docs/libcurl/opts/CURLOPT_IPRESOLVE.3 | 74 - .../docs/libcurl/opts/CURLOPT_IPRESOLVE.md | 90 + .../docs/libcurl/opts/CURLOPT_ISSUERCERT.3 | 73 - .../docs/libcurl/opts/CURLOPT_ISSUERCERT.md | 84 + .../libcurl/opts/CURLOPT_ISSUERCERT_BLOB.3 | 84 - .../libcurl/opts/CURLOPT_ISSUERCERT_BLOB.md | 95 + .../opts/CURLOPT_KEEP_SENDING_ON_ERROR.3 | 65 - .../opts/CURLOPT_KEEP_SENDING_ON_ERROR.md | 70 + .../docs/libcurl/opts/CURLOPT_KEYPASSWD.3 | 65 - .../docs/libcurl/opts/CURLOPT_KEYPASSWD.md | 83 + .../curl/docs/libcurl/opts/CURLOPT_KRBLEVEL.3 | 63 - .../docs/libcurl/opts/CURLOPT_KRBLEVEL.md | 81 + .../docs/libcurl/opts/CURLOPT_LOCALPORT.3 | 60 - .../docs/libcurl/opts/CURLOPT_LOCALPORT.md | 66 + .../libcurl/opts/CURLOPT_LOCALPORTRANGE.3 | 64 - .../libcurl/opts/CURLOPT_LOCALPORTRANGE.md | 69 + .../docs/libcurl/opts/CURLOPT_LOGIN_OPTIONS.3 | 74 - .../libcurl/opts/CURLOPT_LOGIN_OPTIONS.md | 96 + .../libcurl/opts/CURLOPT_LOW_SPEED_LIMIT.3 | 65 - .../libcurl/opts/CURLOPT_LOW_SPEED_LIMIT.md | 72 + .../libcurl/opts/CURLOPT_LOW_SPEED_TIME.3 | 64 - .../libcurl/opts/CURLOPT_LOW_SPEED_TIME.md | 69 + .../docs/libcurl/opts/CURLOPT_MAIL_AUTH.3 | 73 - .../docs/libcurl/opts/CURLOPT_MAIL_AUTH.md | 79 + .../docs/libcurl/opts/CURLOPT_MAIL_FROM.3 | 66 - .../docs/libcurl/opts/CURLOPT_MAIL_FROM.md | 76 + .../docs/libcurl/opts/CURLOPT_MAIL_RCPT.3 | 76 - .../docs/libcurl/opts/CURLOPT_MAIL_RCPT.md | 91 + .../opts/CURLOPT_MAIL_RCPT_ALLOWFAILS.3 | 77 - .../opts/CURLOPT_MAIL_RCPT_ALLOWFAILS.md | 86 + .../docs/libcurl/opts/CURLOPT_MAXAGE_CONN.3 | 68 - .../docs/libcurl/opts/CURLOPT_MAXAGE_CONN.md | 75 + .../docs/libcurl/opts/CURLOPT_MAXCONNECTS.3 | 71 - .../docs/libcurl/opts/CURLOPT_MAXCONNECTS.md | 77 + .../docs/libcurl/opts/CURLOPT_MAXFILESIZE.3 | 64 - .../docs/libcurl/opts/CURLOPT_MAXFILESIZE.md | 79 + .../libcurl/opts/CURLOPT_MAXFILESIZE_LARGE.3 | 64 - .../libcurl/opts/CURLOPT_MAXFILESIZE_LARGE.md | 79 + .../libcurl/opts/CURLOPT_MAXLIFETIME_CONN.3 | 70 - .../libcurl/opts/CURLOPT_MAXLIFETIME_CONN.md | 79 + .../docs/libcurl/opts/CURLOPT_MAXREDIRS.3 | 69 - .../docs/libcurl/opts/CURLOPT_MAXREDIRS.md | 76 + .../opts/CURLOPT_MAX_RECV_SPEED_LARGE.3 | 66 - .../opts/CURLOPT_MAX_RECV_SPEED_LARGE.md | 72 + .../opts/CURLOPT_MAX_SEND_SPEED_LARGE.3 | 69 - .../opts/CURLOPT_MAX_SEND_SPEED_LARGE.md | 74 + .../curl/docs/libcurl/opts/CURLOPT_MIMEPOST.3 | 74 - .../docs/libcurl/opts/CURLOPT_MIMEPOST.md | 84 + .../docs/libcurl/opts/CURLOPT_MIME_OPTIONS.3 | 93 - .../docs/libcurl/opts/CURLOPT_MIME_OPTIONS.md | 107 + .../curl/docs/libcurl/opts/CURLOPT_NETRC.3 | 121 - .../curl/docs/libcurl/opts/CURLOPT_NETRC.md | 159 + .../docs/libcurl/opts/CURLOPT_NETRC_FILE.3 | 63 - .../docs/libcurl/opts/CURLOPT_NETRC_FILE.md | 75 + .../opts/CURLOPT_NEW_DIRECTORY_PERMS.3 | 59 - .../opts/CURLOPT_NEW_DIRECTORY_PERMS.md | 68 + .../libcurl/opts/CURLOPT_NEW_FILE_PERMS.3 | 58 - .../libcurl/opts/CURLOPT_NEW_FILE_PERMS.md | 64 + .../curl/docs/libcurl/opts/CURLOPT_NOBODY.3 | 74 - .../curl/docs/libcurl/opts/CURLOPT_NOBODY.md | 82 + .../docs/libcurl/opts/CURLOPT_NOPROGRESS.3 | 63 - .../docs/libcurl/opts/CURLOPT_NOPROGRESS.md | 69 + .../curl/docs/libcurl/opts/CURLOPT_NOPROXY.3 | 86 - .../curl/docs/libcurl/opts/CURLOPT_NOPROXY.md | 103 + .../curl/docs/libcurl/opts/CURLOPT_NOSIGNAL.3 | 76 - .../docs/libcurl/opts/CURLOPT_NOSIGNAL.md | 78 + .../libcurl/opts/CURLOPT_OPENSOCKETDATA.3 | 86 - .../libcurl/opts/CURLOPT_OPENSOCKETDATA.md | 93 + .../libcurl/opts/CURLOPT_OPENSOCKETFUNCTION.3 | 127 - .../opts/CURLOPT_OPENSOCKETFUNCTION.md | 140 + .../curl/docs/libcurl/opts/CURLOPT_PASSWORD.3 | 67 - .../docs/libcurl/opts/CURLOPT_PASSWORD.md | 75 + .../docs/libcurl/opts/CURLOPT_PATH_AS_IS.3 | 71 - .../docs/libcurl/opts/CURLOPT_PATH_AS_IS.md | 82 + .../libcurl/opts/CURLOPT_PINNEDPUBLICKEY.3 | 131 - .../libcurl/opts/CURLOPT_PINNEDPUBLICKEY.md | 161 + .../curl/docs/libcurl/opts/CURLOPT_PIPEWAIT.3 | 75 - .../docs/libcurl/opts/CURLOPT_PIPEWAIT.md | 80 + .../curl/docs/libcurl/opts/CURLOPT_PORT.3 | 68 - .../curl/docs/libcurl/opts/CURLOPT_PORT.md | 74 + .../curl/docs/libcurl/opts/CURLOPT_POST.3 | 98 - .../curl/docs/libcurl/opts/CURLOPT_POST.md | 104 + .../docs/libcurl/opts/CURLOPT_POSTFIELDS.3 | 121 - .../docs/libcurl/opts/CURLOPT_POSTFIELDS.md | 133 + .../docs/libcurl/opts/CURLOPT_POSTFIELDSIZE.3 | 67 - .../libcurl/opts/CURLOPT_POSTFIELDSIZE.md | 77 + .../opts/CURLOPT_POSTFIELDSIZE_LARGE.3 | 67 - .../opts/CURLOPT_POSTFIELDSIZE_LARGE.md | 78 + .../docs/libcurl/opts/CURLOPT_POSTQUOTE.3 | 69 - .../docs/libcurl/opts/CURLOPT_POSTQUOTE.md | 80 + .../docs/libcurl/opts/CURLOPT_POSTREDIR.3 | 75 - .../docs/libcurl/opts/CURLOPT_POSTREDIR.md | 95 + .../curl/docs/libcurl/opts/CURLOPT_PREQUOTE.3 | 73 - .../docs/libcurl/opts/CURLOPT_PREQUOTE.md | 81 + .../docs/libcurl/opts/CURLOPT_PREREQDATA.3 | 64 - .../docs/libcurl/opts/CURLOPT_PREREQDATA.md | 77 + .../libcurl/opts/CURLOPT_PREREQFUNCTION.3 | 105 - .../libcurl/opts/CURLOPT_PREREQFUNCTION.md | 130 + .../docs/libcurl/opts/CURLOPT_PRE_PROXY.3 | 83 - .../docs/libcurl/opts/CURLOPT_PRE_PROXY.md | 90 + .../curl/docs/libcurl/opts/CURLOPT_PRIVATE.3 | 65 - .../curl/docs/libcurl/opts/CURLOPT_PRIVATE.md | 77 + .../docs/libcurl/opts/CURLOPT_PROGRESSDATA.3 | 73 - .../docs/libcurl/opts/CURLOPT_PROGRESSDATA.md | 84 + .../libcurl/opts/CURLOPT_PROGRESSFUNCTION.3 | 118 - .../libcurl/opts/CURLOPT_PROGRESSFUNCTION.md | 134 + .../docs/libcurl/opts/CURLOPT_PROTOCOLS.3 | 101 - .../docs/libcurl/opts/CURLOPT_PROTOCOLS.md | 120 + .../docs/libcurl/opts/CURLOPT_PROTOCOLS_STR.3 | 84 - .../libcurl/opts/CURLOPT_PROTOCOLS_STR.md | 96 + .../curl/docs/libcurl/opts/CURLOPT_PROXY.3 | 132 - .../curl/docs/libcurl/opts/CURLOPT_PROXY.md | 174 + .../docs/libcurl/opts/CURLOPT_PROXYAUTH.3 | 73 - .../docs/libcurl/opts/CURLOPT_PROXYAUTH.md | 82 + .../docs/libcurl/opts/CURLOPT_PROXYHEADER.3 | 77 - .../docs/libcurl/opts/CURLOPT_PROXYHEADER.md | 88 + .../docs/libcurl/opts/CURLOPT_PROXYPASSWORD.3 | 66 - .../libcurl/opts/CURLOPT_PROXYPASSWORD.md | 74 + .../docs/libcurl/opts/CURLOPT_PROXYPORT.3 | 61 - .../docs/libcurl/opts/CURLOPT_PROXYPORT.md | 74 + .../docs/libcurl/opts/CURLOPT_PROXYTYPE.3 | 84 - .../docs/libcurl/opts/CURLOPT_PROXYTYPE.md | 113 + .../docs/libcurl/opts/CURLOPT_PROXYUSERNAME.3 | 68 - .../libcurl/opts/CURLOPT_PROXYUSERNAME.md | 74 + .../docs/libcurl/opts/CURLOPT_PROXYUSERPWD.3 | 66 - .../docs/libcurl/opts/CURLOPT_PROXYUSERPWD.md | 75 + .../docs/libcurl/opts/CURLOPT_PROXY_CAINFO.3 | 87 - .../docs/libcurl/opts/CURLOPT_PROXY_CAINFO.md | 96 + .../libcurl/opts/CURLOPT_PROXY_CAINFO_BLOB.3 | 80 - .../libcurl/opts/CURLOPT_PROXY_CAINFO_BLOB.md | 94 + .../docs/libcurl/opts/CURLOPT_PROXY_CAPATH.3 | 77 - .../docs/libcurl/opts/CURLOPT_PROXY_CAPATH.md | 85 + .../docs/libcurl/opts/CURLOPT_PROXY_CRLFILE.3 | 79 - .../libcurl/opts/CURLOPT_PROXY_CRLFILE.md | 91 + .../libcurl/opts/CURLOPT_PROXY_ISSUERCERT.3 | 77 - .../libcurl/opts/CURLOPT_PROXY_ISSUERCERT.md | 88 + .../opts/CURLOPT_PROXY_ISSUERCERT_BLOB.3 | 87 - .../opts/CURLOPT_PROXY_ISSUERCERT_BLOB.md | 98 + .../libcurl/opts/CURLOPT_PROXY_KEYPASSWD.3 | 66 - .../libcurl/opts/CURLOPT_PROXY_KEYPASSWD.md | 79 + .../opts/CURLOPT_PROXY_PINNEDPUBLICKEY.3 | 115 - .../opts/CURLOPT_PROXY_PINNEDPUBLICKEY.md | 139 + .../libcurl/opts/CURLOPT_PROXY_SERVICE_NAME.3 | 62 - .../opts/CURLOPT_PROXY_SERVICE_NAME.md | 69 + .../docs/libcurl/opts/CURLOPT_PROXY_SSLCERT.3 | 76 - .../libcurl/opts/CURLOPT_PROXY_SSLCERT.md | 84 + .../libcurl/opts/CURLOPT_PROXY_SSLCERTTYPE.3 | 72 - .../libcurl/opts/CURLOPT_PROXY_SSLCERTTYPE.md | 81 + .../libcurl/opts/CURLOPT_PROXY_SSLCERT_BLOB.3 | 77 - .../opts/CURLOPT_PROXY_SSLCERT_BLOB.md | 88 + .../docs/libcurl/opts/CURLOPT_PROXY_SSLKEY.3 | 72 - .../docs/libcurl/opts/CURLOPT_PROXY_SSLKEY.md | 84 + .../libcurl/opts/CURLOPT_PROXY_SSLKEYTYPE.3 | 65 - .../libcurl/opts/CURLOPT_PROXY_SSLKEYTYPE.md | 74 + .../libcurl/opts/CURLOPT_PROXY_SSLKEY_BLOB.3 | 75 - .../libcurl/opts/CURLOPT_PROXY_SSLKEY_BLOB.md | 89 + .../libcurl/opts/CURLOPT_PROXY_SSLVERSION.3 | 105 - .../libcurl/opts/CURLOPT_PROXY_SSLVERSION.md | 130 + .../opts/CURLOPT_PROXY_SSL_CIPHER_LIST.3 | 87 - .../opts/CURLOPT_PROXY_SSL_CIPHER_LIST.md | 106 + .../libcurl/opts/CURLOPT_PROXY_SSL_OPTIONS.3 | 102 - .../libcurl/opts/CURLOPT_PROXY_SSL_OPTIONS.md | 132 + .../opts/CURLOPT_PROXY_SSL_VERIFYHOST.3 | 91 - .../opts/CURLOPT_PROXY_SSL_VERIFYHOST.md | 96 + .../opts/CURLOPT_PROXY_SSL_VERIFYPEER.3 | 94 - .../opts/CURLOPT_PROXY_SSL_VERIFYPEER.md | 98 + .../opts/CURLOPT_PROXY_TLS13_CIPHERS.3 | 74 - .../opts/CURLOPT_PROXY_TLS13_CIPHERS.md | 101 + .../opts/CURLOPT_PROXY_TLSAUTH_PASSWORD.3 | 67 - .../opts/CURLOPT_PROXY_TLSAUTH_PASSWORD.md | 78 + .../libcurl/opts/CURLOPT_PROXY_TLSAUTH_TYPE.3 | 75 - .../opts/CURLOPT_PROXY_TLSAUTH_TYPE.md | 85 + .../opts/CURLOPT_PROXY_TLSAUTH_USERNAME.3 | 67 - .../opts/CURLOPT_PROXY_TLSAUTH_USERNAME.md | 78 + .../opts/CURLOPT_PROXY_TRANSFER_MODE.3 | 63 - .../opts/CURLOPT_PROXY_TRANSFER_MODE.md | 70 + .../curl/docs/libcurl/opts/CURLOPT_PUT.3 | 73 - .../curl/docs/libcurl/opts/CURLOPT_PUT.md | 101 + .../docs/libcurl/opts/CURLOPT_QUICK_EXIT.3 | 59 - .../docs/libcurl/opts/CURLOPT_QUICK_EXIT.md | 64 + .../curl/docs/libcurl/opts/CURLOPT_QUOTE.3 | 126 - .../curl/docs/libcurl/opts/CURLOPT_QUOTE.md | 176 + .../docs/libcurl/opts/CURLOPT_RANDOM_FILE.3 | 65 - .../docs/libcurl/opts/CURLOPT_RANDOM_FILE.md | 47 + .../curl/docs/libcurl/opts/CURLOPT_RANGE.3 | 80 - .../curl/docs/libcurl/opts/CURLOPT_RANGE.md | 100 + .../curl/docs/libcurl/opts/CURLOPT_READDATA.3 | 69 - .../docs/libcurl/opts/CURLOPT_READDATA.md | 82 + .../docs/libcurl/opts/CURLOPT_READFUNCTION.3 | 119 - .../docs/libcurl/opts/CURLOPT_READFUNCTION.md | 130 + .../libcurl/opts/CURLOPT_REDIR_PROTOCOLS.3 | 111 - .../libcurl/opts/CURLOPT_REDIR_PROTOCOLS.md | 125 + .../opts/CURLOPT_REDIR_PROTOCOLS_STR.3 | 89 - .../opts/CURLOPT_REDIR_PROTOCOLS_STR.md | 98 + .../curl/docs/libcurl/opts/CURLOPT_REFERER.3 | 64 - .../curl/docs/libcurl/opts/CURLOPT_REFERER.md | 73 + .../libcurl/opts/CURLOPT_REQUEST_TARGET.3 | 60 - .../libcurl/opts/CURLOPT_REQUEST_TARGET.md | 77 + .../curl/docs/libcurl/opts/CURLOPT_RESOLVE.3 | 112 - .../curl/docs/libcurl/opts/CURLOPT_RESOLVE.md | 133 + .../opts/CURLOPT_RESOLVER_START_DATA.3 | 68 - .../opts/CURLOPT_RESOLVER_START_DATA.md | 73 + .../opts/CURLOPT_RESOLVER_START_FUNCTION.3 | 85 - .../opts/CURLOPT_RESOLVER_START_FUNCTION.md | 91 + .../docs/libcurl/opts/CURLOPT_RESUME_FROM.3 | 76 - .../docs/libcurl/opts/CURLOPT_RESUME_FROM.md | 84 + .../libcurl/opts/CURLOPT_RESUME_FROM_LARGE.3 | 76 - .../libcurl/opts/CURLOPT_RESUME_FROM_LARGE.md | 83 + .../libcurl/opts/CURLOPT_RTSP_CLIENT_CSEQ.3 | 57 - .../libcurl/opts/CURLOPT_RTSP_CLIENT_CSEQ.md | 64 + .../docs/libcurl/opts/CURLOPT_RTSP_REQUEST.3 | 117 - .../docs/libcurl/opts/CURLOPT_RTSP_REQUEST.md | 146 + .../libcurl/opts/CURLOPT_RTSP_SERVER_CSEQ.3 | 57 - .../libcurl/opts/CURLOPT_RTSP_SERVER_CSEQ.md | 63 + .../libcurl/opts/CURLOPT_RTSP_SESSION_ID.3 | 64 - .../libcurl/opts/CURLOPT_RTSP_SESSION_ID.md | 75 + .../libcurl/opts/CURLOPT_RTSP_STREAM_URI.3 | 70 - .../libcurl/opts/CURLOPT_RTSP_STREAM_URI.md | 76 + .../libcurl/opts/CURLOPT_RTSP_TRANSPORT.3 | 64 - .../libcurl/opts/CURLOPT_RTSP_TRANSPORT.md | 74 + .../docs/libcurl/opts/CURLOPT_SASL_AUTHZID.3 | 68 - .../docs/libcurl/opts/CURLOPT_SASL_AUTHZID.md | 80 + .../curl/docs/libcurl/opts/CURLOPT_SASL_IR.3 | 68 - .../curl/docs/libcurl/opts/CURLOPT_SASL_IR.md | 75 + .../curl/docs/libcurl/opts/CURLOPT_SEEKDATA.3 | 60 - .../docs/libcurl/opts/CURLOPT_SEEKDATA.md | 71 + .../docs/libcurl/opts/CURLOPT_SEEKFUNCTION.3 | 91 - .../docs/libcurl/opts/CURLOPT_SEEKFUNCTION.md | 106 + .../opts/CURLOPT_SERVER_RESPONSE_TIMEOUT.3 | 72 - .../opts/CURLOPT_SERVER_RESPONSE_TIMEOUT.md | 79 + .../CURLOPT_SERVER_RESPONSE_TIMEOUT_MS.md | 80 + .../docs/libcurl/opts/CURLOPT_SERVICE_NAME.3 | 63 - .../docs/libcurl/opts/CURLOPT_SERVICE_NAME.md | 74 + .../curl/docs/libcurl/opts/CURLOPT_SHARE.3 | 85 - .../curl/docs/libcurl/opts/CURLOPT_SHARE.md | 92 + .../docs/libcurl/opts/CURLOPT_SOCKOPTDATA.3 | 71 - .../docs/libcurl/opts/CURLOPT_SOCKOPTDATA.md | 74 + .../libcurl/opts/CURLOPT_SOCKOPTFUNCTION.3 | 125 - .../libcurl/opts/CURLOPT_SOCKOPTFUNCTION.md | 134 + .../docs/libcurl/opts/CURLOPT_SOCKS5_AUTH.3 | 67 - .../docs/libcurl/opts/CURLOPT_SOCKS5_AUTH.md | 86 + .../libcurl/opts/CURLOPT_SOCKS5_GSSAPI_NEC.3 | 60 - .../libcurl/opts/CURLOPT_SOCKS5_GSSAPI_NEC.md | 65 + .../opts/CURLOPT_SOCKS5_GSSAPI_SERVICE.3 | 65 - .../opts/CURLOPT_SOCKS5_GSSAPI_SERVICE.md | 73 + .../libcurl/opts/CURLOPT_SSH_AUTH_TYPES.3 | 63 - .../libcurl/opts/CURLOPT_SSH_AUTH_TYPES.md | 75 + .../libcurl/opts/CURLOPT_SSH_COMPRESSION.3 | 62 - .../libcurl/opts/CURLOPT_SSH_COMPRESSION.md | 68 + .../libcurl/opts/CURLOPT_SSH_HOSTKEYDATA.3 | 65 - .../libcurl/opts/CURLOPT_SSH_HOSTKEYDATA.md | 82 + .../opts/CURLOPT_SSH_HOSTKEYFUNCTION.3 | 87 - .../opts/CURLOPT_SSH_HOSTKEYFUNCTION.md | 110 + .../opts/CURLOPT_SSH_HOST_PUBLIC_KEY_MD5.3 | 66 - .../opts/CURLOPT_SSH_HOST_PUBLIC_KEY_MD5.md | 90 + .../opts/CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256.3 | 61 - .../CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256.md | 83 + .../docs/libcurl/opts/CURLOPT_SSH_KEYDATA.3 | 67 - .../docs/libcurl/opts/CURLOPT_SSH_KEYDATA.md | 80 + .../libcurl/opts/CURLOPT_SSH_KEYFUNCTION.3 | 132 - .../libcurl/opts/CURLOPT_SSH_KEYFUNCTION.md | 157 + .../libcurl/opts/CURLOPT_SSH_KNOWNHOSTS.3 | 65 - .../libcurl/opts/CURLOPT_SSH_KNOWNHOSTS.md | 90 + .../opts/CURLOPT_SSH_PRIVATE_KEYFILE.3 | 67 - .../opts/CURLOPT_SSH_PRIVATE_KEYFILE.md | 78 + .../libcurl/opts/CURLOPT_SSH_PUBLIC_KEYFILE.3 | 67 - .../opts/CURLOPT_SSH_PUBLIC_KEYFILE.md | 77 + .../curl/docs/libcurl/opts/CURLOPT_SSLCERT.3 | 84 - .../curl/docs/libcurl/opts/CURLOPT_SSLCERT.md | 87 + .../docs/libcurl/opts/CURLOPT_SSLCERTTYPE.3 | 68 - .../docs/libcurl/opts/CURLOPT_SSLCERTTYPE.md | 80 + .../docs/libcurl/opts/CURLOPT_SSLCERT_BLOB.3 | 75 - .../docs/libcurl/opts/CURLOPT_SSLCERT_BLOB.md | 87 + .../docs/libcurl/opts/CURLOPT_SSLENGINE.3 | 70 - .../docs/libcurl/opts/CURLOPT_SSLENGINE.md | 83 + .../libcurl/opts/CURLOPT_SSLENGINE_DEFAULT.3 | 67 - .../libcurl/opts/CURLOPT_SSLENGINE_DEFAULT.md | 71 + .../curl/docs/libcurl/opts/CURLOPT_SSLKEY.3 | 67 - .../curl/docs/libcurl/opts/CURLOPT_SSLKEY.md | 81 + .../docs/libcurl/opts/CURLOPT_SSLKEYTYPE.3 | 68 - .../docs/libcurl/opts/CURLOPT_SSLKEYTYPE.md | 85 + .../docs/libcurl/opts/CURLOPT_SSLKEY_BLOB.3 | 77 - .../docs/libcurl/opts/CURLOPT_SSLKEY_BLOB.md | 91 + .../docs/libcurl/opts/CURLOPT_SSLVERSION.3 | 119 - .../docs/libcurl/opts/CURLOPT_SSLVERSION.md | 155 + .../libcurl/opts/CURLOPT_SSL_CIPHER_LIST.3 | 88 - .../libcurl/opts/CURLOPT_SSL_CIPHER_LIST.md | 111 + .../docs/libcurl/opts/CURLOPT_SSL_CTX_DATA.3 | 125 - .../docs/libcurl/opts/CURLOPT_SSL_CTX_DATA.md | 130 + .../libcurl/opts/CURLOPT_SSL_CTX_FUNCTION.3 | 167 - .../libcurl/opts/CURLOPT_SSL_CTX_FUNCTION.md | 184 + .../docs/libcurl/opts/CURLOPT_SSL_EC_CURVES.3 | 58 - .../libcurl/opts/CURLOPT_SSL_EC_CURVES.md | 72 + .../libcurl/opts/CURLOPT_SSL_ENABLE_ALPN.3 | 57 - .../libcurl/opts/CURLOPT_SSL_ENABLE_ALPN.md | 64 + .../libcurl/opts/CURLOPT_SSL_ENABLE_NPN.3 | 59 - .../libcurl/opts/CURLOPT_SSL_ENABLE_NPN.md | 70 + .../libcurl/opts/CURLOPT_SSL_FALSESTART.3 | 61 - .../libcurl/opts/CURLOPT_SSL_FALSESTART.md | 70 + .../docs/libcurl/opts/CURLOPT_SSL_OPTIONS.3 | 99 - .../docs/libcurl/opts/CURLOPT_SSL_OPTIONS.md | 145 + .../opts/CURLOPT_SSL_SESSIONID_CACHE.3 | 60 - .../opts/CURLOPT_SSL_SESSIONID_CACHE.md | 70 + .../opts/CURLOPT_SSL_SIGNATURE_ALGORITHMS.md | 84 + .../libcurl/opts/CURLOPT_SSL_VERIFYHOST.3 | 110 - .../libcurl/opts/CURLOPT_SSL_VERIFYHOST.md | 120 + .../libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 | 97 - .../libcurl/opts/CURLOPT_SSL_VERIFYPEER.md | 104 + .../libcurl/opts/CURLOPT_SSL_VERIFYSTATUS.3 | 66 - .../libcurl/opts/CURLOPT_SSL_VERIFYSTATUS.md | 71 + .../curl/docs/libcurl/opts/CURLOPT_STDERR.3 | 63 - .../curl/docs/libcurl/opts/CURLOPT_STDERR.md | 73 + .../libcurl/opts/CURLOPT_STREAM_DEPENDS.3 | 73 - .../libcurl/opts/CURLOPT_STREAM_DEPENDS.md | 87 + .../libcurl/opts/CURLOPT_STREAM_DEPENDS_E.3 | 76 - .../libcurl/opts/CURLOPT_STREAM_DEPENDS_E.md | 90 + .../docs/libcurl/opts/CURLOPT_STREAM_WEIGHT.3 | 78 - .../libcurl/opts/CURLOPT_STREAM_WEIGHT.md | 82 + .../opts/CURLOPT_SUPPRESS_CONNECT_HEADERS.3 | 97 - .../opts/CURLOPT_SUPPRESS_CONNECT_HEADERS.md | 103 + .../docs/libcurl/opts/CURLOPT_TCP_FASTOPEN.3 | 63 - .../docs/libcurl/opts/CURLOPT_TCP_FASTOPEN.md | 70 + .../docs/libcurl/opts/CURLOPT_TCP_KEEPALIVE.3 | 67 - .../libcurl/opts/CURLOPT_TCP_KEEPALIVE.md | 79 + .../docs/libcurl/opts/CURLOPT_TCP_KEEPCNT.md | 79 + .../docs/libcurl/opts/CURLOPT_TCP_KEEPIDLE.3 | 68 - .../docs/libcurl/opts/CURLOPT_TCP_KEEPIDLE.md | 78 + .../docs/libcurl/opts/CURLOPT_TCP_KEEPINTVL.3 | 67 - .../libcurl/opts/CURLOPT_TCP_KEEPINTVL.md | 77 + .../docs/libcurl/opts/CURLOPT_TCP_NODELAY.3 | 68 - .../docs/libcurl/opts/CURLOPT_TCP_NODELAY.md | 78 + .../docs/libcurl/opts/CURLOPT_TELNETOPTIONS.3 | 63 - .../libcurl/opts/CURLOPT_TELNETOPTIONS.md | 74 + .../docs/libcurl/opts/CURLOPT_TFTP_BLKSIZE.3 | 61 - .../docs/libcurl/opts/CURLOPT_TFTP_BLKSIZE.md | 65 + .../libcurl/opts/CURLOPT_TFTP_NO_OPTIONS.3 | 77 - .../libcurl/opts/CURLOPT_TFTP_NO_OPTIONS.md | 81 + .../docs/libcurl/opts/CURLOPT_TIMECONDITION.3 | 70 - .../libcurl/opts/CURLOPT_TIMECONDITION.md | 82 + .../curl/docs/libcurl/opts/CURLOPT_TIMEOUT.3 | 87 - .../curl/docs/libcurl/opts/CURLOPT_TIMEOUT.md | 93 + .../docs/libcurl/opts/CURLOPT_TIMEOUT_MS.3 | 61 - .../docs/libcurl/opts/CURLOPT_TIMEOUT_MS.md | 68 + .../docs/libcurl/opts/CURLOPT_TIMEVALUE.3 | 67 - .../docs/libcurl/opts/CURLOPT_TIMEVALUE.md | 78 + .../libcurl/opts/CURLOPT_TIMEVALUE_LARGE.3 | 69 - .../libcurl/opts/CURLOPT_TIMEVALUE_LARGE.md | 80 + .../docs/libcurl/opts/CURLOPT_TLS13_CIPHERS.3 | 74 - .../libcurl/opts/CURLOPT_TLS13_CIPHERS.md | 101 + .../libcurl/opts/CURLOPT_TLSAUTH_PASSWORD.3 | 66 - .../libcurl/opts/CURLOPT_TLSAUTH_PASSWORD.md | 77 + .../docs/libcurl/opts/CURLOPT_TLSAUTH_TYPE.3 | 71 - .../docs/libcurl/opts/CURLOPT_TLSAUTH_TYPE.md | 81 + .../libcurl/opts/CURLOPT_TLSAUTH_USERNAME.3 | 66 - .../libcurl/opts/CURLOPT_TLSAUTH_USERNAME.md | 76 + .../docs/libcurl/opts/CURLOPT_TRAILERDATA.3 | 55 - .../docs/libcurl/opts/CURLOPT_TRAILERDATA.md | 61 + .../libcurl/opts/CURLOPT_TRAILERFUNCTION.3 | 108 - .../libcurl/opts/CURLOPT_TRAILERFUNCTION.md | 116 + .../docs/libcurl/opts/CURLOPT_TRANSFERTEXT.3 | 63 - .../docs/libcurl/opts/CURLOPT_TRANSFERTEXT.md | 67 + .../libcurl/opts/CURLOPT_TRANSFER_ENCODING.3 | 66 - .../libcurl/opts/CURLOPT_TRANSFER_ENCODING.md | 72 + .../libcurl/opts/CURLOPT_UNIX_SOCKET_PATH.3 | 83 - .../libcurl/opts/CURLOPT_UNIX_SOCKET_PATH.md | 93 + .../libcurl/opts/CURLOPT_UNRESTRICTED_AUTH.3 | 75 - .../libcurl/opts/CURLOPT_UNRESTRICTED_AUTH.md | 89 + .../libcurl/opts/CURLOPT_UPKEEP_INTERVAL_MS.3 | 82 - .../opts/CURLOPT_UPKEEP_INTERVAL_MS.md | 85 + .../curl/docs/libcurl/opts/CURLOPT_UPLOAD.3 | 82 - .../curl/docs/libcurl/opts/CURLOPT_UPLOAD.md | 101 + .../libcurl/opts/CURLOPT_UPLOAD_BUFFERSIZE.3 | 76 - .../libcurl/opts/CURLOPT_UPLOAD_BUFFERSIZE.md | 82 + .../docs/libcurl/opts/CURLOPT_UPLOAD_FLAGS.md | 129 + .../curl/docs/libcurl/opts/CURLOPT_URL.3 | 138 - .../curl/docs/libcurl/opts/CURLOPT_URL.md | 149 + .../docs/libcurl/opts/CURLOPT_USERAGENT.3 | 62 - .../docs/libcurl/opts/CURLOPT_USERAGENT.md | 72 + .../curl/docs/libcurl/opts/CURLOPT_USERNAME.3 | 87 - .../docs/libcurl/opts/CURLOPT_USERNAME.md | 92 + .../curl/docs/libcurl/opts/CURLOPT_USERPWD.3 | 95 - .../curl/docs/libcurl/opts/CURLOPT_USERPWD.md | 101 + .../curl/docs/libcurl/opts/CURLOPT_USE_SSL.3 | 76 - .../curl/docs/libcurl/opts/CURLOPT_USE_SSL.md | 106 + .../curl/docs/libcurl/opts/CURLOPT_VERBOSE.3 | 69 - .../curl/docs/libcurl/opts/CURLOPT_VERBOSE.md | 78 + .../docs/libcurl/opts/CURLOPT_WILDCARDMATCH.3 | 108 - .../libcurl/opts/CURLOPT_WILDCARDMATCH.md | 113 + .../docs/libcurl/opts/CURLOPT_WRITEDATA.3 | 64 - .../docs/libcurl/opts/CURLOPT_WRITEDATA.md | 66 + .../docs/libcurl/opts/CURLOPT_WRITEFUNCTION.3 | 132 - .../libcurl/opts/CURLOPT_WRITEFUNCTION.md | 140 + .../docs/libcurl/opts/CURLOPT_WS_OPTIONS.3 | 69 - .../docs/libcurl/opts/CURLOPT_WS_OPTIONS.md | 90 + .../docs/libcurl/opts/CURLOPT_XFERINFODATA.3 | 75 - .../docs/libcurl/opts/CURLOPT_XFERINFODATA.md | 82 + .../libcurl/opts/CURLOPT_XFERINFOFUNCTION.3 | 114 - .../libcurl/opts/CURLOPT_XFERINFOFUNCTION.md | 126 + .../libcurl/opts/CURLOPT_XOAUTH2_BEARER.3 | 64 - .../libcurl/opts/CURLOPT_XOAUTH2_BEARER.md | 79 + .../docs/libcurl/opts/CURLSHOPT_LOCKFUNC.3 | 72 - .../docs/libcurl/opts/CURLSHOPT_LOCKFUNC.md | 76 + .../curl/docs/libcurl/opts/CURLSHOPT_SHARE.3 | 103 - .../curl/docs/libcurl/opts/CURLSHOPT_SHARE.md | 119 + .../docs/libcurl/opts/CURLSHOPT_UNLOCKFUNC.3 | 68 - .../docs/libcurl/opts/CURLSHOPT_UNLOCKFUNC.md | 71 + .../docs/libcurl/opts/CURLSHOPT_UNSHARE.3 | 72 - .../docs/libcurl/opts/CURLSHOPT_UNSHARE.md | 83 + .../docs/libcurl/opts/CURLSHOPT_USERDATA.3 | 56 - .../docs/libcurl/opts/CURLSHOPT_USERDATA.md | 61 + .../curl/docs/libcurl/opts/Makefile.am | 46 +- .../curl/docs/libcurl/opts/Makefile.inc | 29 +- third-party/curl/docs/libcurl/opts/template.3 | 40 - .../curl/docs/libcurl/symbols-in-versions | 134 +- third-party/curl/docs/libcurl/symbols.pl | 16 +- third-party/curl/docs/mk-ca-bundle.1 | 120 - third-party/curl/docs/mk-ca-bundle.md | 125 + third-party/curl/docs/options-in-versions | 25 +- third-party/curl/docs/runtests.md | 320 + third-party/curl/docs/testcurl.md | 138 + third-party/curl/docs/tests/CI.md | 92 + third-party/curl/docs/tests/FILEFORMAT.md | 823 ++ third-party/curl/docs/tests/HTTP.md | 206 + third-party/curl/docs/tests/TEST-SUITE.md | 323 + third-party/curl/docs/wcurl.md | 154 + third-party/curl/include/README.md | 2 +- third-party/curl/include/curl/.gitignore | 7 - third-party/curl/include/curl/Makefile.am | 6 +- third-party/curl/include/curl/curl.h | 1080 +-- third-party/curl/include/curl/curlver.h | 17 +- third-party/curl/include/curl/easy.h | 14 +- third-party/curl/include/curl/header.h | 20 +- third-party/curl/include/curl/mprintf.h | 31 +- third-party/curl/include/curl/multi.h | 290 +- third-party/curl/include/curl/options.h | 4 +- third-party/curl/include/curl/system.h | 274 +- third-party/curl/include/curl/typecheck-gcc.h | 1147 +-- third-party/curl/include/curl/urlapi.h | 57 +- third-party/curl/include/curl/websockets.h | 36 +- third-party/curl/lib/.checksrc | 1 - third-party/curl/lib/.gitattributes | 3 - third-party/curl/lib/.gitignore | 13 +- third-party/curl/lib/CMakeLists.txt | 346 +- third-party/curl/lib/Makefile.am | 98 +- third-party/curl/lib/Makefile.inc | 226 +- third-party/curl/lib/Makefile.mk | 421 -- third-party/curl/lib/Makefile.soname | 7 +- third-party/curl/lib/altsvc.c | 711 +- third-party/curl/lib/altsvc.h | 29 +- third-party/curl/lib/amigaos.c | 46 +- third-party/curl/lib/amigaos.h | 2 +- third-party/curl/lib/arpa_telnet.h | 46 +- third-party/curl/lib/asyn-ares.c | 1183 ++- third-party/curl/lib/asyn-base.c | 265 + third-party/curl/lib/asyn-thrdd.c | 838 +++ third-party/curl/lib/asyn-thread.c | 760 -- third-party/curl/lib/asyn.h | 329 +- third-party/curl/lib/base64.c | 292 - third-party/curl/lib/bufq.c | 339 +- third-party/curl/lib/bufq.h | 114 +- third-party/curl/lib/bufref.c | 35 +- third-party/curl/lib/bufref.h | 9 +- third-party/curl/lib/c-hyper.c | 1281 ---- third-party/curl/lib/c-hyper.h | 59 - third-party/curl/lib/cf-dns.c | 596 ++ third-party/curl/lib/cf-dns.h | 79 + third-party/curl/lib/cf-h1-proxy.c | 1235 ++- third-party/curl/lib/cf-h1-proxy.h | 11 +- third-party/curl/lib/cf-h2-proxy.c | 1264 ++-- third-party/curl/lib/cf-h2-proxy.h | 8 +- third-party/curl/lib/cf-haproxy.c | 150 +- third-party/curl/lib/cf-haproxy.h | 4 +- third-party/curl/lib/cf-https-connect.c | 751 +- third-party/curl/lib/cf-https-connect.h | 22 +- third-party/curl/lib/cf-ip-happy.c | 1054 +++ third-party/curl/lib/cf-ip-happy.h | 73 + third-party/curl/lib/cf-recvbuf.c | 157 + third-party/curl/lib/cf-recvbuf.h | 40 + third-party/curl/lib/cf-setup.c | 476 ++ third-party/curl/lib/cf-setup.h | 46 + third-party/curl/lib/cf-socket.c | 2149 +++--- third-party/curl/lib/cf-socket.h | 121 +- third-party/curl/lib/cfilters.c | 977 ++- third-party/curl/lib/cfilters.h | 468 +- third-party/curl/lib/config-amigaos.h | 135 - third-party/curl/lib/config-dos.h | 142 - third-party/curl/lib/config-mac.h | 33 +- third-party/curl/lib/config-os400.h | 532 +- third-party/curl/lib/config-plan9.h | 156 - third-party/curl/lib/config-riscos.h | 164 +- third-party/curl/lib/config-win32.h | 451 +- third-party/curl/lib/config-win32ce.h | 325 - third-party/curl/lib/conncache.c | 1186 +-- third-party/curl/lib/conncache.h | 199 +- third-party/curl/lib/connect.c | 1654 +--- third-party/curl/lib/connect.h | 128 +- third-party/curl/lib/content_encoding.c | 1048 +-- third-party/curl/lib/content_encoding.h | 28 +- third-party/curl/lib/cookie.c | 2131 +++--- third-party/curl/lib/cookie.h | 105 +- third-party/curl/lib/creds.c | 189 + third-party/curl/lib/creds.h | 91 + third-party/curl/lib/cshutdn.c | 534 ++ third-party/curl/lib/cshutdn.h | 106 + third-party/curl/lib/curl_addrinfo.c | 388 +- third-party/curl/lib/curl_addrinfo.h | 60 +- third-party/curl/lib/curl_base64.h | 41 - third-party/curl/lib/curl_config-cmake.h.in | 801 ++ third-party/curl/lib/curl_config.h.cmake | 794 -- third-party/curl/lib/curl_ctype.h | 17 +- third-party/curl/lib/curl_des.c | 69 - third-party/curl/lib/curl_des.h | 40 - third-party/curl/lib/curl_endian.c | 13 +- third-party/curl/lib/curl_fnmatch.c | 75 +- third-party/curl/lib/curl_fnmatch.h | 3 +- third-party/curl/lib/curl_fopen.c | 165 + third-party/curl/lib/curl_fopen.h | 31 + third-party/curl/lib/curl_get_line.c | 75 +- third-party/curl/lib/curl_get_line.h | 6 +- third-party/curl/lib/curl_gethostname.c | 36 +- third-party/curl/lib/curl_gssapi.c | 359 +- third-party/curl/lib/curl_gssapi.h | 41 +- third-party/curl/lib/curl_hmac.h | 50 +- third-party/curl/lib/curl_krb5.h | 52 - third-party/curl/lib/curl_ldap.h | 10 +- third-party/curl/lib/curl_md4.h | 6 +- third-party/curl/lib/curl_md5.h | 36 +- third-party/curl/lib/curl_memory.h | 178 - third-party/curl/lib/curl_memrchr.c | 15 +- third-party/curl/lib/curl_memrchr.h | 8 +- third-party/curl/lib/curl_multibyte.c | 179 - third-party/curl/lib/curl_multibyte.h | 91 - third-party/curl/lib/curl_ntlm_core.c | 451 +- third-party/curl/lib/curl_ntlm_core.h | 32 +- third-party/curl/lib/curl_ntlm_wb.c | 500 -- third-party/curl/lib/curl_ntlm_wb.h | 45 - third-party/curl/lib/curl_path.c | 199 - third-party/curl/lib/curl_path.h | 49 - third-party/curl/lib/curl_printf.h | 30 +- third-party/curl/lib/curl_range.c | 59 +- third-party/curl/lib/curl_range.h | 2 +- third-party/curl/lib/curl_rtmp.c | 338 - third-party/curl/lib/curl_rtmp.h | 35 - third-party/curl/lib/curl_sasl.c | 738 +- third-party/curl/lib/curl_sasl.h | 15 +- third-party/curl/lib/curl_setup.h | 1486 +++- third-party/curl/lib/curl_setup_once.h | 422 -- third-party/curl/lib/curl_sha256.h | 21 +- third-party/curl/lib/curl_sha512_256.c | 847 +++ third-party/curl/lib/curl_sha512_256.h | 43 + third-party/curl/lib/curl_share.c | 472 ++ third-party/curl/lib/curl_share.h | 92 + third-party/curl/lib/curl_sspi.c | 132 +- third-party/curl/lib/curl_sspi.h | 290 +- third-party/curl/lib/curl_threads.c | 187 +- third-party/curl/lib/curl_threads.h | 43 +- third-party/curl/lib/curl_trc.c | 763 +- third-party/curl/lib/curl_trc.h | 340 +- third-party/curl/lib/curlx.h | 118 - third-party/curl/lib/curlx/base64.c | 267 + third-party/curl/lib/curlx/base64.h | 40 + third-party/curl/lib/curlx/basename.c | 74 + third-party/curl/lib/curlx/basename.h | 39 + third-party/curl/lib/curlx/dynbuf.c | 292 + third-party/curl/lib/curlx/dynbuf.h | 83 + third-party/curl/lib/curlx/fopen.c | 508 ++ third-party/curl/lib/curlx/fopen.h | 87 + third-party/curl/lib/curlx/inet_ntop.c | 222 + third-party/curl/lib/curlx/inet_ntop.h | 50 + third-party/curl/lib/curlx/inet_pton.c | 221 + third-party/curl/lib/{ => curlx}/inet_pton.h | 22 +- third-party/curl/lib/curlx/multibyte.c | 78 + third-party/curl/lib/curlx/multibyte.h | 73 + third-party/curl/lib/{ => curlx}/nonblock.c | 38 +- third-party/curl/lib/{ => curlx}/nonblock.h | 2 - third-party/curl/lib/curlx/snprintf.c | 49 + third-party/curl/lib/curlx/snprintf.h | 45 + third-party/curl/lib/curlx/strcopy.c | 50 + third-party/curl/lib/curlx/strcopy.h | 32 + third-party/curl/lib/curlx/strdup.c | 125 + third-party/curl/lib/{ => curlx}/strdup.h | 18 +- third-party/curl/lib/curlx/strerr.c | 329 + third-party/curl/lib/curlx/strerr.h | 29 + third-party/curl/lib/curlx/strparse.c | 317 + third-party/curl/lib/curlx/strparse.h | 114 + third-party/curl/lib/{ => curlx}/timediff.c | 11 +- third-party/curl/lib/{ => curlx}/timediff.h | 5 +- third-party/curl/lib/curlx/timeval.c | 273 + third-party/curl/lib/curlx/timeval.h | 74 + third-party/curl/lib/curlx/version_win32.c | 238 + .../curl/lib/{ => curlx}/version_win32.h | 12 +- third-party/curl/lib/curlx/wait.c | 94 + third-party/curl/lib/curlx/wait.h | 30 + third-party/curl/lib/curlx/warnless.c | 341 + third-party/curl/lib/curlx/warnless.h | 74 + third-party/curl/lib/curlx/winapi.c | 106 + third-party/curl/lib/curlx/winapi.h | 33 + third-party/curl/lib/cw-out.c | 522 ++ third-party/curl/lib/cw-out.h | 52 + third-party/curl/lib/cw-pause.c | 227 + third-party/curl/lib/cw-pause.h | 38 + third-party/curl/lib/dict.c | 157 +- third-party/curl/lib/dict.h | 3 +- third-party/curl/lib/dllmain.c | 64 + third-party/curl/lib/dnscache.c | 859 +++ third-party/curl/lib/dnscache.h | 138 + third-party/curl/lib/doh.c | 1179 ++- third-party/curl/lib/doh.h | 164 +- third-party/curl/lib/dynbuf.c | 275 - third-party/curl/lib/dynbuf.h | 92 - third-party/curl/lib/dynhds.c | 241 +- third-party/curl/lib/dynhds.h | 69 +- third-party/curl/lib/easy.c | 913 +-- third-party/curl/lib/easy_lock.h | 53 +- third-party/curl/lib/easygetopt.c | 27 +- third-party/curl/lib/easyif.h | 7 +- third-party/curl/lib/easyoptions.c | 688 +- third-party/curl/lib/easyoptions.h | 8 +- third-party/curl/lib/escape.c | 161 +- third-party/curl/lib/escape.h | 10 +- third-party/curl/lib/fake_addrinfo.c | 202 + third-party/curl/lib/fake_addrinfo.h | 53 + third-party/curl/lib/file.c | 478 +- third-party/curl/lib/file.h | 14 +- third-party/curl/lib/fileinfo.c | 16 +- third-party/curl/lib/fileinfo.h | 6 +- third-party/curl/lib/fopen.c | 112 - third-party/curl/lib/fopen.h | 30 - third-party/curl/lib/formdata.c | 873 +-- third-party/curl/lib/formdata.h | 32 +- third-party/curl/lib/ftp-int.h | 160 + third-party/curl/lib/ftp.c | 5015 ++++++------ third-party/curl/lib/ftp.h | 129 +- third-party/curl/lib/ftplistparser.c | 1338 ++-- third-party/curl/lib/ftplistparser.h | 10 +- third-party/curl/lib/functypes.h | 15 +- third-party/curl/lib/getenv.c | 32 +- third-party/curl/lib/getinfo.c | 296 +- third-party/curl/lib/getinfo.h | 2 +- third-party/curl/lib/gopher.c | 191 +- third-party/curl/lib/gopher.h | 7 +- third-party/curl/lib/hash.c | 390 +- third-party/curl/lib/hash.h | 77 +- third-party/curl/lib/headers.c | 291 +- third-party/curl/lib/headers.h | 18 +- third-party/curl/lib/hmac.c | 117 +- third-party/curl/lib/hostasyn.c | 123 - third-party/curl/lib/hostip.c | 1765 ++--- third-party/curl/lib/hostip.h | 288 +- third-party/curl/lib/hostip4.c | 116 +- third-party/curl/lib/hostip6.c | 74 +- third-party/curl/lib/hostsyn.c | 104 - third-party/curl/lib/hsts.c | 521 +- third-party/curl/lib/hsts.h | 33 +- third-party/curl/lib/http.c | 6703 +++++++++-------- third-party/curl/lib/http.h | 221 +- third-party/curl/lib/http1.c | 187 +- third-party/curl/lib/http1.h | 16 +- third-party/curl/lib/http2.c | 2861 +++---- third-party/curl/lib/http2.h | 35 +- third-party/curl/lib/http_aws_sigv4.c | 1238 ++- third-party/curl/lib/http_aws_sigv4.h | 7 +- third-party/curl/lib/http_chunks.c | 633 +- third-party/curl/lib/http_chunks.h | 82 +- third-party/curl/lib/http_digest.c | 107 +- third-party/curl/lib/http_negotiate.c | 168 +- third-party/curl/lib/http_negotiate.h | 5 +- third-party/curl/lib/http_ntlm.c | 162 +- third-party/curl/lib/http_ntlm.h | 9 +- third-party/curl/lib/http_proxy.c | 745 +- third-party/curl/lib/http_proxy.h | 54 +- third-party/curl/lib/httpsrr.c | 311 + third-party/curl/lib/httpsrr.h | 102 + third-party/curl/lib/idn.c | 310 +- third-party/curl/lib/idn.h | 17 +- third-party/curl/lib/if2ip.c | 86 +- third-party/curl/lib/if2ip.h | 45 +- third-party/curl/lib/imap.c | 2098 +++--- third-party/curl/lib/imap.h | 72 +- third-party/curl/lib/inet_ntop.c | 205 - third-party/curl/lib/inet_ntop.h | 39 - third-party/curl/lib/inet_pton.c | 242 - third-party/curl/lib/krb5.c | 902 --- third-party/curl/lib/ldap.c | 836 +- third-party/curl/{ => lib}/libcurl.def | 8 + third-party/curl/lib/libcurl.plist.in | 35 - third-party/curl/lib/libcurl.rc | 2 +- third-party/curl/lib/libcurl.vers.in | 10 +- third-party/curl/lib/llist.c | 276 +- third-party/curl/lib/llist.h | 68 +- third-party/curl/lib/macos.c | 31 +- third-party/curl/lib/macos.h | 5 - third-party/curl/lib/md4.c | 467 +- third-party/curl/lib/md5.c | 660 +- third-party/curl/lib/memdebug.c | 389 +- third-party/curl/lib/memdebug.h | 202 - third-party/curl/lib/mime.c | 1127 +-- third-party/curl/lib/mime.h | 35 +- third-party/curl/lib/mprintf.c | 1967 ++--- third-party/curl/lib/mqtt.c | 678 +- third-party/curl/lib/mqtt.h | 36 +- third-party/curl/lib/multi.c | 5661 +++++++------- third-party/curl/lib/multi_ev.c | 646 ++ third-party/curl/lib/multi_ev.h | 80 + third-party/curl/lib/multi_ntfy.c | 207 + third-party/curl/lib/multi_ntfy.h | 60 + third-party/curl/lib/multihandle.h | 171 +- third-party/curl/lib/multiif.h | 161 +- third-party/curl/lib/netrc.c | 885 ++- third-party/curl/lib/netrc.h | 45 +- third-party/curl/lib/noproxy.c | 266 - third-party/curl/lib/noproxy.h | 45 - third-party/curl/lib/openldap.c | 863 ++- third-party/curl/lib/optiontable.pl | 64 +- third-party/curl/lib/parsedate.c | 759 +- third-party/curl/lib/parsedate.h | 7 +- third-party/curl/lib/peer.c | 740 ++ third-party/curl/lib/peer.h | 110 + third-party/curl/lib/pingpong.c | 427 +- third-party/curl/lib/pingpong.h | 68 +- third-party/curl/lib/pop3.c | 1344 ++-- third-party/curl/lib/pop3.h | 73 +- third-party/curl/lib/progress.c | 864 ++- third-party/curl/lib/progress.h | 47 +- third-party/curl/lib/protocol.c | 536 ++ third-party/curl/lib/protocol.h | 296 + third-party/curl/lib/proxy.c | 673 ++ third-party/curl/lib/proxy.h | 59 + third-party/curl/lib/psl.c | 44 +- third-party/curl/lib/psl.h | 6 +- third-party/curl/lib/rand.c | 269 +- third-party/curl/lib/rand.h | 25 +- third-party/curl/lib/ratelimit.c | 295 + third-party/curl/lib/ratelimit.h | 108 + third-party/curl/lib/rename.c | 73 - third-party/curl/lib/rename.h | 29 - third-party/curl/lib/request.c | 503 ++ third-party/curl/lib/request.h | 251 + third-party/curl/lib/rtsp.c | 1195 +-- third-party/curl/lib/rtsp.h | 48 +- third-party/curl/lib/select.c | 590 +- third-party/curl/lib/select.h | 168 +- third-party/curl/lib/sendf.c | 1723 ++++- third-party/curl/lib/sendf.h | 414 +- third-party/curl/lib/setopt.c | 5233 ++++++------- third-party/curl/lib/setopt.h | 14 +- third-party/curl/lib/setup-os400.h | 41 +- third-party/curl/lib/setup-vms.h | 450 +- third-party/curl/lib/setup-win32.h | 113 +- third-party/curl/lib/sha256.c | 404 +- third-party/curl/lib/share.c | 290 - third-party/curl/lib/share.h | 76 - third-party/curl/lib/sigpipe.h | 50 +- third-party/curl/lib/slist.c | 37 +- third-party/curl/lib/slist.h | 2 +- third-party/curl/lib/smb.c | 787 +- third-party/curl/lib/smb.h | 35 +- third-party/curl/lib/smtp.c | 1728 +++-- third-party/curl/lib/smtp.h | 76 +- third-party/curl/lib/sockaddr.h | 21 +- third-party/curl/lib/socketpair.c | 263 +- third-party/curl/lib/socketpair.h | 18 +- third-party/curl/lib/socks.c | 2092 ++--- third-party/curl/lib/socks.h | 38 +- third-party/curl/lib/socks_gssapi.c | 436 +- third-party/curl/lib/socks_sspi.c | 671 +- third-party/curl/lib/speedcheck.c | 79 - third-party/curl/lib/speedcheck.h | 35 - third-party/curl/lib/splay.c | 109 +- third-party/curl/lib/splay.h | 23 +- third-party/curl/lib/strcase.c | 152 +- third-party/curl/lib/strcase.h | 21 +- third-party/curl/lib/strdup.c | 123 - third-party/curl/lib/strequal.c | 95 + third-party/curl/lib/strerror.c | 727 +- third-party/curl/lib/strerror.h | 11 +- third-party/curl/lib/strtok.c | 68 - third-party/curl/lib/strtok.h | 36 - third-party/curl/lib/strtoofft.c | 245 - third-party/curl/lib/strtoofft.h | 54 - third-party/curl/lib/system_win32.c | 165 +- third-party/curl/lib/system_win32.h | 18 +- third-party/curl/lib/telnet.c | 1467 ++-- third-party/curl/lib/telnet.h | 2 +- third-party/curl/lib/tftp.c | 1124 ++- third-party/curl/lib/tftp.h | 5 +- third-party/curl/lib/thrdpool.c | 481 ++ third-party/curl/lib/thrdpool.h | 106 + third-party/curl/lib/thrdqueue.c | 416 + third-party/curl/lib/thrdqueue.h | 119 + third-party/curl/lib/timeval.c | 224 - third-party/curl/lib/timeval.h | 54 - third-party/curl/lib/transfer.c | 2033 ++--- third-party/curl/lib/transfer.h | 143 +- third-party/curl/lib/uint-bset.c | 233 + third-party/curl/lib/uint-bset.h | 109 + third-party/curl/lib/uint-hash.c | 235 + third-party/curl/lib/uint-hash.h | 59 + third-party/curl/lib/uint-spbset.c | 253 + third-party/curl/lib/uint-spbset.h | 91 + third-party/curl/lib/uint-table.c | 202 + third-party/curl/lib/uint-table.h | 96 + third-party/curl/lib/url.c | 5028 +++++-------- third-party/curl/lib/url.h | 68 +- third-party/curl/lib/urlapi-int.h | 41 +- third-party/curl/lib/urlapi.c | 2688 +++---- third-party/curl/lib/urldata.h | 1674 ++-- third-party/curl/lib/vauth/cleartext.c | 89 +- third-party/curl/lib/vauth/cram.c | 30 +- third-party/curl/lib/vauth/digest.c | 788 +- third-party/curl/lib/vauth/digest.h | 3 +- third-party/curl/lib/vauth/digest_sspi.c | 319 +- third-party/curl/lib/vauth/gsasl.c | 34 +- third-party/curl/lib/vauth/krb5_gssapi.c | 66 +- third-party/curl/lib/vauth/krb5_sspi.c | 180 +- third-party/curl/lib/vauth/ntlm.c | 552 +- third-party/curl/lib/vauth/ntlm.h | 143 - third-party/curl/lib/vauth/ntlm_sspi.c | 169 +- third-party/curl/lib/vauth/oauth2.c | 40 +- third-party/curl/lib/vauth/spnego_gssapi.c | 78 +- third-party/curl/lib/vauth/spnego_sspi.c | 161 +- third-party/curl/lib/vauth/vauth.c | 181 +- third-party/curl/lib/vauth/vauth.h | 211 +- third-party/curl/lib/version.c | 335 +- third-party/curl/lib/version_win32.c | 319 - third-party/curl/lib/vquic/capsule.c | 301 + third-party/curl/lib/vquic/capsule.h | 70 + third-party/curl/lib/vquic/cf-capsule.c | 306 + third-party/curl/lib/vquic/cf-capsule.h | 40 + third-party/curl/lib/vquic/cf-ngtcp2-cmn.c | 1969 +++++ third-party/curl/lib/vquic/cf-ngtcp2-cmn.h | 239 + third-party/curl/lib/vquic/cf-ngtcp2-proxy.c | 1316 ++++ third-party/curl/lib/vquic/cf-ngtcp2-proxy.h | 52 + third-party/curl/lib/vquic/cf-ngtcp2.c | 1166 +++ third-party/curl/lib/vquic/cf-ngtcp2.h | 63 + third-party/curl/lib/vquic/cf-quiche.c | 1713 +++++ third-party/curl/lib/vquic/cf-quiche.h | 50 + third-party/curl/lib/vquic/curl_msh3.c | 1087 --- third-party/curl/lib/vquic/curl_msh3.h | 46 - third-party/curl/lib/vquic/curl_ngtcp2.c | 2748 ------- third-party/curl/lib/vquic/curl_ngtcp2.h | 61 - third-party/curl/lib/vquic/curl_quiche.c | 1709 ----- third-party/curl/lib/vquic/curl_quiche.h | 50 - third-party/curl/lib/vquic/vquic-tls.c | 241 + third-party/curl/lib/vquic/vquic-tls.h | 125 + third-party/curl/lib/vquic/vquic.c | 808 +- third-party/curl/lib/vquic/vquic.h | 49 +- third-party/curl/lib/vquic/vquic_int.h | 97 +- third-party/curl/lib/vssh/libssh.c | 5148 +++++++------ third-party/curl/lib/vssh/libssh2.c | 5840 +++++++------- third-party/curl/lib/vssh/ssh.h | 138 +- third-party/curl/lib/vssh/vssh.c | 333 + third-party/curl/lib/vssh/vssh.h | 42 + third-party/curl/lib/vssh/wolfssh.c | 1173 --- third-party/curl/lib/vtls/apple.c | 291 + third-party/curl/lib/vtls/apple.h | 54 + third-party/curl/lib/vtls/bearssl.c | 1230 --- third-party/curl/lib/vtls/bearssl.h | 34 - third-party/curl/lib/vtls/cipher_suite.c | 702 ++ third-party/curl/lib/vtls/cipher_suite.h | 44 + third-party/curl/lib/vtls/gtls.c | 2689 ++++--- third-party/curl/lib/vtls/gtls.h | 87 +- third-party/curl/lib/vtls/hostcheck.c | 27 +- third-party/curl/lib/vtls/hostcheck.h | 9 +- third-party/curl/lib/vtls/keylog.c | 108 +- third-party/curl/lib/vtls/keylog.h | 25 +- third-party/curl/lib/vtls/mbedtls.c | 1943 +++-- .../curl/lib/vtls/mbedtls_threadlock.c | 134 - .../curl/lib/vtls/mbedtls_threadlock.h | 50 - third-party/curl/lib/vtls/openssl.c | 6203 ++++++++------- third-party/curl/lib/vtls/openssl.h | 169 +- third-party/curl/lib/vtls/rustls.c | 1529 +++- third-party/curl/lib/vtls/rustls.h | 8 +- third-party/curl/lib/vtls/schannel.c | 4194 ++++++----- third-party/curl/lib/vtls/schannel.h | 45 +- third-party/curl/lib/vtls/schannel_int.h | 235 +- third-party/curl/lib/vtls/schannel_verify.c | 714 +- third-party/curl/lib/vtls/sectransp.c | 3505 --------- third-party/curl/lib/vtls/sectransp.h | 34 - third-party/curl/lib/vtls/vtls.c | 2006 +++-- third-party/curl/lib/vtls/vtls.h | 221 +- third-party/curl/lib/vtls/vtls_config.c | 423 ++ third-party/curl/lib/vtls/vtls_config.h | 125 + third-party/curl/lib/vtls/vtls_int.h | 225 +- third-party/curl/lib/vtls/vtls_scache.c | 1316 ++++ third-party/curl/lib/vtls/vtls_scache.h | 216 + third-party/curl/lib/vtls/vtls_spack.c | 322 + third-party/curl/lib/vtls/vtls_spack.h | 43 + third-party/curl/lib/vtls/wolfssl.c | 2671 ++++--- third-party/curl/lib/vtls/wolfssl.h | 68 + third-party/curl/lib/vtls/x509asn1.c | 1281 ++-- third-party/curl/lib/vtls/x509asn1.h | 51 +- third-party/curl/lib/warnless.c | 437 -- third-party/curl/lib/warnless.h | 99 - third-party/curl/lib/ws.c | 1945 +++-- third-party/curl/lib/ws.h | 69 +- third-party/curl/libcurl.pc.in | 14 +- third-party/curl/m4/.gitignore | 1 - third-party/curl/m4/curl-amissl.m4 | 15 +- third-party/curl/m4/curl-apple-sectrust.m4 | 61 + third-party/curl/m4/curl-bearssl.m4 | 110 - third-party/curl/m4/curl-compilers.m4 | 764 +- third-party/curl/m4/curl-confopts.m4 | 385 +- third-party/curl/m4/curl-functions.m4 | 3246 +++----- third-party/curl/m4/curl-gnutls.m4 | 272 +- third-party/curl/m4/curl-mbedtls.m4 | 138 +- third-party/curl/m4/curl-openssl.m4 | 504 +- third-party/curl/m4/curl-override.m4 | 23 +- third-party/curl/m4/curl-reentrant.m4 | 180 +- third-party/curl/m4/curl-rustls.m4 | 215 +- third-party/curl/m4/curl-schannel.m4 | 15 +- third-party/curl/m4/curl-sectransp.m4 | 45 - third-party/curl/m4/curl-sysconfig.m4 | 51 +- third-party/curl/m4/curl-wolfssl.m4 | 244 +- third-party/curl/m4/xc-am-iface.m4 | 41 +- third-party/curl/m4/xc-cc-check.m4 | 50 +- third-party/curl/m4/xc-lt-iface.m4 | 228 +- third-party/curl/m4/xc-translit.m4 | 165 - third-party/curl/m4/xc-val-flgs.m4 | 40 +- third-party/curl/m4/zz40-xc-ovr.m4 | 386 +- third-party/curl/m4/zz50-xc-ovr.m4 | 10 +- third-party/curl/m4/zz60-xc-ovr.m4 | 65 - third-party/curl/maketgz | 225 - third-party/curl/packages/Makefile.am | 51 - third-party/curl/packages/OS400/ccsidcurl.c | 1527 ---- third-party/curl/packages/OS400/make-lib.sh | 183 - third-party/curl/packages/OS400/make-src.sh | 99 - third-party/curl/packages/OS400/os400sys.c | 1040 --- third-party/curl/packages/OS400/os400sys.h | 57 - third-party/curl/packages/README.md | 12 - third-party/curl/packages/vms/Makefile.am | 59 - third-party/curl/packages/vms/config_h.com | 2004 ----- .../curl/packages/vms/curl_crtl_init.c | 333 - third-party/curl/packages/vms/curlmsg.h | 143 - third-party/curl/packages/vms/curlmsg.msg | 134 - third-party/curl/packages/vms/curlmsg_vms.h | 143 - .../packages/vms/report_openssl_version.c | 100 - third-party/curl/plan9/README | 55 - third-party/curl/plan9/include/mkfile | 36 - third-party/curl/plan9/lib/mkfile | 41 - third-party/curl/plan9/lib/mkfile.inc | 27 - third-party/curl/plan9/mkfile | 38 - third-party/curl/plan9/mkfile.proto | 32 - third-party/curl/plan9/src/mkfile | 47 - third-party/curl/plan9/src/mkfile.inc | 27 - third-party/curl/projects/Makefile.am | 60 + third-party/curl/projects/OS400/.checksrc | 9 + .../{packages => projects}/OS400/README.OS400 | 52 +- third-party/curl/projects/OS400/ccsidcurl.c | 1471 ++++ .../{packages => projects}/OS400/ccsidcurl.h | 1 - .../OS400/config400.default | 1 + .../{packages => projects}/OS400/curl.cmd | 2 +- .../{packages => projects}/OS400/curl.inc.in | 153 +- .../{packages => projects}/OS400/curlcl.c | 26 +- .../{packages => projects}/OS400/curlmain.c | 20 +- .../OS400/initscript.sh | 94 +- third-party/curl/projects/OS400/make-docs.sh | 65 + .../OS400/make-include.sh | 10 +- third-party/curl/projects/OS400/make-lib.sh | 181 + third-party/curl/projects/OS400/make-src.sh | 118 + .../OS400/make-tests.sh | 45 +- .../{packages => projects}/OS400/makefile.sh | 38 +- third-party/curl/projects/OS400/os400sys.c | 1038 +++ third-party/curl/projects/OS400/os400sys.h | 54 + .../OS400/rpg-examples/HEADERAPI | 4 +- .../OS400/rpg-examples/HTTPPOST | 4 +- .../OS400/rpg-examples/INMEMORY | 4 +- .../OS400/rpg-examples/SIMPLE1 | 4 +- .../OS400/rpg-examples/SIMPLE2 | 4 +- .../OS400/rpg-examples/SMTPSRCMBR | 4 +- third-party/curl/projects/README.md | 158 +- third-party/curl/projects/Windows/.gitignore | 7 +- third-party/curl/projects/Windows/README.md | 148 + .../curl/projects/Windows/VC10/.gitignore | 8 - .../curl/projects/Windows/VC10/curl-all.sln | 298 - .../curl/projects/Windows/VC10/lib/.gitignore | 10 - .../projects/Windows/VC10/lib/libcurl.sln | 181 - .../projects/Windows/VC10/lib/libcurl.tmpl | 2353 ------ .../Windows/VC10/lib/libcurl.vcxproj.filters | 17 - .../curl/projects/Windows/VC10/src/.gitignore | 10 - .../curl/projects/Windows/VC10/src/curl.sln | 181 - .../curl/projects/Windows/VC10/src/curl.tmpl | 2643 ------- .../Windows/VC10/src/curl.vcxproj.filters | 17 - .../curl/projects/Windows/VC11/.gitignore | 8 - .../curl/projects/Windows/VC11/curl-all.sln | 298 - .../curl/projects/Windows/VC11/lib/.gitignore | 10 - .../projects/Windows/VC11/lib/libcurl.sln | 181 - .../projects/Windows/VC11/lib/libcurl.tmpl | 2409 ------ .../Windows/VC11/lib/libcurl.vcxproj.filters | 17 - .../curl/projects/Windows/VC11/src/.gitignore | 10 - .../curl/projects/Windows/VC11/src/curl.sln | 181 - .../curl/projects/Windows/VC11/src/curl.tmpl | 2699 ------- .../Windows/VC11/src/curl.vcxproj.filters | 17 - .../curl/projects/Windows/VC12/.gitignore | 8 - .../curl/projects/Windows/VC12/curl-all.sln | 298 - .../curl/projects/Windows/VC12/lib/.gitignore | 10 - .../projects/Windows/VC12/lib/libcurl.sln | 181 - .../projects/Windows/VC12/lib/libcurl.tmpl | 2409 ------ .../Windows/VC12/lib/libcurl.vcxproj.filters | 17 - .../curl/projects/Windows/VC12/src/.gitignore | 10 - .../curl/projects/Windows/VC12/src/curl.sln | 181 - .../curl/projects/Windows/VC12/src/curl.tmpl | 2699 ------- .../Windows/VC12/src/curl.vcxproj.filters | 17 - .../curl/projects/Windows/VC14.10/.gitignore | 9 - .../projects/Windows/VC14.10/curl-all.sln | 298 - .../projects/Windows/VC14.10/lib/.gitignore | 10 - .../projects/Windows/VC14.10/lib/libcurl.sln | 181 - .../projects/Windows/VC14.10/lib/libcurl.tmpl | 2381 ------ .../VC14.10/lib/libcurl.vcxproj.filters | 17 - .../projects/Windows/VC14.10/src/.gitignore | 10 - .../projects/Windows/VC14.10/src/curl.sln | 181 - .../projects/Windows/VC14.10/src/curl.tmpl | 2671 ------- .../Windows/VC14.10/src/curl.vcxproj.filters | 17 - .../curl/projects/Windows/VC14.30/.gitignore | 9 - .../projects/Windows/VC14.30/curl-all.sln | 298 - .../projects/Windows/VC14.30/lib/.gitignore | 10 - .../projects/Windows/VC14.30/lib/libcurl.sln | 181 - .../projects/Windows/VC14.30/lib/libcurl.tmpl | 2381 ------ .../VC14.30/lib/libcurl.vcxproj.filters | 17 - .../projects/Windows/VC14.30/src/.gitignore | 10 - .../projects/Windows/VC14.30/src/curl.sln | 181 - .../projects/Windows/VC14.30/src/curl.tmpl | 2671 ------- .../Windows/VC14.30/src/curl.vcxproj.filters | 17 - .../curl/projects/Windows/VC14/.gitignore | 9 - .../curl/projects/Windows/VC14/curl-all.sln | 298 - .../curl/projects/Windows/VC14/lib/.gitignore | 10 - .../projects/Windows/VC14/lib/libcurl.sln | 181 - .../projects/Windows/VC14/lib/libcurl.tmpl | 2409 ------ .../Windows/VC14/lib/libcurl.vcxproj.filters | 17 - .../curl/projects/Windows/VC14/src/.gitignore | 10 - .../curl/projects/Windows/VC14/src/curl.sln | 181 - .../curl/projects/Windows/VC14/src/curl.tmpl | 2699 ------- .../Windows/VC14/src/curl.vcxproj.filters | 17 - .../curl/projects/Windows/generate.bat | 355 + .../Windows/{ => tmpl}/.gitattributes | 0 .../curl/projects/Windows/tmpl/README.txt | 6 + .../curl/projects/Windows/tmpl/curl-all.sln | 257 + .../curl/projects/Windows/tmpl/curl.sln | 156 + .../curl/projects/Windows/tmpl/curl.vcxproj | 2314 ++++++ .../Windows/tmpl/curl.vcxproj.filters | 17 + .../curl/projects/Windows/tmpl/libcurl.sln | 156 + .../projects/Windows/tmpl/libcurl.vcxproj | 2055 +++++ .../Windows/tmpl/libcurl.vcxproj.filters | 17 + third-party/curl/projects/build-openssl.bat | 739 -- third-party/curl/projects/build-wolfssl.bat | 429 -- third-party/curl/projects/checksrc.bat | 225 - third-party/curl/projects/generate.bat | 405 - third-party/curl/projects/vms/Makefile.am | 59 + .../vms/backup_gnv_curl_src.com | 0 .../vms/build_curl-config_script.com | 2 +- .../vms/build_gnv_curl.com | 0 .../vms/build_gnv_curl_pcsi_desc.com | 6 +- .../vms/build_gnv_curl_pcsi_text.com | 4 +- .../vms/build_gnv_curl_release_notes.com | 10 +- .../vms/build_libcurl_pc.com | 4 +- .../{packages => projects}/vms/build_vms.com | 46 +- .../vms/clean_gnv_curl.com | 29 +- .../vms/compare_curl_source.com | 6 +- third-party/curl/projects/vms/config_h.com | 1932 +++++ .../curl/projects/vms/curl_crtl_init.c | 323 + .../vms/curl_gnv_build_steps.txt | 14 +- .../vms/curl_release_note_start.txt | 10 +- .../vms/curl_startup.com | 4 +- third-party/curl/projects/vms/curlmsg.h | 143 + third-party/curl/projects/vms/curlmsg.msg | 134 + .../{packages => projects}/vms/curlmsg.sdl | 0 third-party/curl/projects/vms/curlmsg_vms.h | 129 + .../vms/generate_config_vms_h_curl.com | 99 +- .../vms/generate_vax_transfer.com | 0 .../vms/gnv_conftest.c_first | 2 +- .../vms/gnv_curl_configure.sh | 8 +- .../vms/gnv_libcurl_symbols.opt | 0 .../vms/gnv_link_curl.com | 44 +- .../vms/macro32_exactcase.patch | 0 .../vms/make_gnv_curl_install.sh | 4 +- .../vms/make_pcsi_curl_kit_name.com | 2 +- .../vms/pcsi_gnv_curl_file_list.txt | 2 +- .../vms/pcsi_product_gnv_curl.com | 8 +- .../curl/{packages => projects}/vms/readme | 30 +- .../projects/vms/report_openssl_version.c | 98 + .../vms/setup_gnv_curl_build.com | 22 +- .../vms/stage_curl_install.com | 2 +- .../vms/vms_eco_level.h | 0 third-party/curl/projects/wolfssl_options.h | 308 - .../curl/projects/wolfssl_override.props | 40 - third-party/curl/renovate.json | 97 + third-party/curl/scripts/.checksrc | 5 + third-party/curl/scripts/CMakeLists.txt | 80 + third-party/curl/scripts/Makefile.am | 47 +- third-party/curl/scripts/badwords | 336 + third-party/curl/scripts/badwords-all | 14 + third-party/curl/scripts/badwords.txt | 135 + third-party/curl/scripts/cd2cd | 233 + third-party/curl/scripts/cd2nroff | 588 ++ third-party/curl/scripts/cdall | 47 + third-party/curl/scripts/checksrc-all.pl | 48 + third-party/curl/scripts/checksrc.pl | 603 +- third-party/curl/scripts/ciconfig.pl | 185 - third-party/curl/scripts/cijobs.pl | 510 -- third-party/curl/scripts/cmakelint.sh | 79 + third-party/curl/scripts/completion.pl | 94 +- third-party/curl/scripts/contributors.sh | 91 +- third-party/curl/scripts/contrithanks.sh | 106 +- third-party/curl/scripts/copyright.pl | 227 - third-party/curl/scripts/coverage.sh | 2 + third-party/curl/scripts/delta | 135 +- third-party/curl/scripts/dmaketgz | 55 + third-party/curl/scripts/extract-unit-protos | 151 + third-party/curl/scripts/firefox-db2pem.sh | 27 +- third-party/curl/scripts/installcheck.sh | 24 +- third-party/curl/scripts/log2changes.pl | 103 - third-party/curl/scripts/maketgz | 246 + third-party/curl/scripts/managen | 1383 ++++ third-party/curl/scripts/mdlinkcheck | 254 + third-party/curl/scripts/mk-ca-bundle.pl | 911 ++- third-party/curl/scripts/mk-unity.pl | 115 + third-party/curl/scripts/nroff2cd | 197 + third-party/curl/scripts/perlcheck.sh | 48 + third-party/curl/scripts/pythonlint.sh | 37 + third-party/curl/scripts/randdisable | 83 + third-party/curl/scripts/release-notes.pl | 62 +- third-party/curl/scripts/release-tools.sh | 79 + third-party/curl/scripts/schemetable.c | 186 + third-party/curl/scripts/singleuse.pl | 111 +- third-party/curl/scripts/spacecheck.pl | 306 + third-party/curl/scripts/top-complexity | 134 + third-party/curl/scripts/top-length | 133 + third-party/curl/scripts/updatemanpages.pl | 357 - third-party/curl/scripts/verify-release | 121 + third-party/curl/scripts/wcurl | 352 + third-party/curl/src/.checksrc | 5 + third-party/curl/src/.gitignore | 12 +- third-party/curl/src/CMakeLists.txt | 189 +- third-party/curl/src/Makefile.am | 187 +- third-party/curl/src/Makefile.inc | 92 +- third-party/curl/src/Makefile.mk | 111 - third-party/curl/src/config2setopts.c | 1092 +++ third-party/curl/src/config2setopts.h | 32 + third-party/curl/src/curl.rc | 52 +- third-party/curl/src/curlinfo.c | 277 + third-party/curl/src/mk-file-embed.pl | 63 + third-party/curl/src/mkhelp.pl | 236 +- third-party/curl/src/slist_wc.c | 11 +- third-party/curl/src/slist_wc.h | 8 +- third-party/curl/src/terminal.c | 86 + third-party/curl/src/terminal.h | 30 + third-party/curl/src/tool_binmode.c | 53 - third-party/curl/src/tool_binmode.h | 38 - third-party/curl/src/tool_bname.c | 51 - third-party/curl/src/tool_bname.h | 36 - third-party/curl/src/tool_cb_dbg.c | 216 +- third-party/curl/src/tool_cb_hdr.c | 749 +- third-party/curl/src/tool_cb_hdr.h | 4 +- third-party/curl/src/tool_cb_prg.c | 162 +- third-party/curl/src/tool_cb_prg.h | 17 +- third-party/curl/src/tool_cb_rea.c | 134 +- third-party/curl/src/tool_cb_see.c | 88 +- third-party/curl/src/tool_cb_see.h | 13 - third-party/curl/src/tool_cb_soc.c | 58 + third-party/curl/src/tool_cb_soc.h | 36 + third-party/curl/src/tool_cb_wrt.c | 397 +- third-party/curl/src/tool_cfgable.c | 371 +- third-party/curl/src/tool_cfgable.h | 389 +- third-party/curl/src/tool_dirhie.c | 155 +- third-party/curl/src/tool_dirhie.h | 8 +- third-party/curl/src/tool_doswin.c | 900 ++- third-party/curl/src/tool_doswin.h | 46 +- third-party/curl/src/tool_easysrc.c | 120 +- third-party/curl/src/tool_easysrc.h | 8 +- third-party/curl/src/tool_filetime.c | 163 +- third-party/curl/src/tool_filetime.h | 17 +- third-party/curl/src/tool_findfile.c | 43 +- third-party/curl/src/tool_findfile.h | 2 +- third-party/curl/src/tool_formparse.c | 779 +- third-party/curl/src/tool_formparse.h | 8 +- third-party/curl/src/tool_getparam.c | 5169 +++++++------ third-party/curl/src/tool_getparam.h | 354 +- third-party/curl/src/tool_getpass.c | 75 +- third-party/curl/src/tool_getpass.h | 4 +- third-party/curl/src/tool_help.c | 356 +- third-party/curl/src/tool_help.h | 83 +- third-party/curl/src/tool_helpers.c | 45 +- third-party/curl/src/tool_helpers.h | 10 +- third-party/curl/src/tool_hugehelp.c.cvs | 31 - third-party/curl/src/tool_hugehelp.h | 4 +- third-party/curl/src/tool_ipfs.c | 239 + third-party/curl/src/tool_ipfs.h | 34 + third-party/curl/src/tool_libinfo.c | 93 +- third-party/curl/src/tool_libinfo.h | 8 +- third-party/curl/src/tool_listhelp.c | 1611 ++-- third-party/curl/src/tool_main.c | 173 +- third-party/curl/src/tool_main.h | 15 +- third-party/curl/src/tool_msgs.c | 128 +- third-party/curl/src/tool_msgs.h | 9 +- third-party/curl/src/tool_operate.c | 4078 +++++----- third-party/curl/src/tool_operate.h | 52 +- third-party/curl/src/tool_operhlp.c | 158 +- third-party/curl/src/tool_operhlp.h | 7 +- third-party/curl/src/tool_paramhlp.c | 519 +- third-party/curl/src/tool_paramhlp.h | 28 +- third-party/curl/src/tool_parsecfg.c | 613 +- third-party/curl/src/tool_parsecfg.h | 6 +- third-party/curl/src/tool_progress.c | 280 +- third-party/curl/src/tool_progress.h | 10 +- third-party/curl/src/tool_sdecls.h | 70 +- third-party/curl/src/tool_setopt.c | 699 +- third-party/curl/src/tool_setopt.h | 145 +- third-party/curl/src/tool_setup.h | 75 +- third-party/curl/src/tool_sleep.c | 61 - third-party/curl/src/tool_sleep.h | 30 - third-party/curl/src/tool_ssls.c | 213 + third-party/curl/src/tool_ssls.h | 33 + third-party/curl/src/tool_stderr.c | 23 +- third-party/curl/src/tool_stderr.h | 3 +- third-party/curl/src/tool_strdup.c | 44 - third-party/curl/src/tool_strdup.h | 32 - third-party/curl/src/tool_urlglob.c | 847 ++- third-party/curl/src/tool_urlglob.h | 63 +- third-party/curl/src/tool_util.c | 181 +- third-party/curl/src/tool_util.h | 15 +- third-party/curl/src/tool_version.h | 8 +- third-party/curl/src/tool_vms.c | 46 +- third-party/curl/src/tool_vms.h | 10 +- third-party/curl/src/tool_writeout.c | 690 +- third-party/curl/src/tool_writeout.h | 11 +- third-party/curl/src/tool_writeout_json.c | 38 +- third-party/curl/src/tool_writeout_json.h | 5 +- third-party/curl/src/tool_xattr.c | 18 +- third-party/curl/src/tool_xattr.h | 8 +- third-party/curl/src/toolx/tool_time.c | 61 + third-party/curl/src/toolx/tool_time.h | 30 + third-party/curl/src/var.c | 288 +- third-party/curl/src/var.h | 18 +- third-party/curl/tests/.gitignore | 7 +- third-party/curl/tests/CI.md | 117 - third-party/curl/tests/CMakeLists.txt | 139 +- third-party/curl/tests/FILEFORMAT.md | 659 -- third-party/curl/tests/Makefile.am | 139 +- third-party/curl/tests/README.md | 269 - third-party/curl/tests/allversions.pm | 53 + third-party/curl/tests/appveyor.pm | 37 +- third-party/curl/tests/azure.pm | 34 +- third-party/curl/tests/badsymbols.pl | 158 - third-party/curl/tests/certs/.gitignore | 18 +- third-party/curl/tests/certs/CMakeLists.txt | 50 + .../curl/tests/certs/EdelCurlRoot-ca.cacert | 95 - .../curl/tests/certs/EdelCurlRoot-ca.cnf | 11 - .../curl/tests/certs/EdelCurlRoot-ca.crt | 95 - .../curl/tests/certs/EdelCurlRoot-ca.csr | 17 - .../curl/tests/certs/EdelCurlRoot-ca.der | Bin 1080 -> 0 bytes .../curl/tests/certs/EdelCurlRoot-ca.key | 28 - .../curl/tests/certs/EdelCurlRoot-ca.prm | 30 - third-party/curl/tests/certs/Makefile.am | 124 +- third-party/curl/tests/certs/Makefile.inc | 88 + .../certs/Server-localhost-firstSAN-sv.crl | 14 - .../certs/Server-localhost-firstSAN-sv.crt | 100 - .../certs/Server-localhost-firstSAN-sv.csr | 16 - .../certs/Server-localhost-firstSAN-sv.der | Bin 1123 -> 0 bytes .../certs/Server-localhost-firstSAN-sv.dhp | 0 .../certs/Server-localhost-firstSAN-sv.key | 28 - .../certs/Server-localhost-firstSAN-sv.pem | 167 - .../certs/Server-localhost-firstSAN-sv.prm | 39 - .../Server-localhost-firstSAN-sv.pub.der | Bin 294 -> 0 bytes .../Server-localhost-firstSAN-sv.pub.pem | 9 - ...Server-localhost-firstSAN-sv.pubkey-pinned | 1 - .../certs/Server-localhost-lastSAN-sv.crl | 15 - .../certs/Server-localhost-lastSAN-sv.crt | 100 - .../certs/Server-localhost-lastSAN-sv.csr | 16 - .../certs/Server-localhost-lastSAN-sv.der | Bin 1123 -> 0 bytes .../certs/Server-localhost-lastSAN-sv.dhp | 0 .../certs/Server-localhost-lastSAN-sv.key | 28 - .../certs/Server-localhost-lastSAN-sv.pem | 166 - .../certs/Server-localhost-lastSAN-sv.prm | 38 - .../certs/Server-localhost-lastSAN-sv.pub.der | Bin 294 -> 0 bytes .../certs/Server-localhost-lastSAN-sv.pub.pem | 9 - .../Server-localhost-lastSAN-sv.pubkey-pinned | 1 - .../curl/tests/certs/Server-localhost-sv.crl | 12 - .../curl/tests/certs/Server-localhost-sv.crt | 99 - .../curl/tests/certs/Server-localhost-sv.csr | 16 - .../curl/tests/certs/Server-localhost-sv.der | Bin 1096 -> 0 bytes .../curl/tests/certs/Server-localhost-sv.dhp | 0 .../curl/tests/certs/Server-localhost-sv.key | 28 - .../curl/tests/certs/Server-localhost-sv.pem | 165 - .../curl/tests/certs/Server-localhost-sv.prm | 38 - .../tests/certs/Server-localhost-sv.pub.der | Bin 294 -> 0 bytes .../tests/certs/Server-localhost-sv.pub.pem | 9 - .../certs/Server-localhost-sv.pubkey-pinned | 1 - .../tests/certs/Server-localhost.nn-sv.crl | 13 - .../tests/certs/Server-localhost.nn-sv.crt | 99 - .../tests/certs/Server-localhost.nn-sv.csr | 16 - .../tests/certs/Server-localhost.nn-sv.der | Bin 1102 -> 0 bytes .../tests/certs/Server-localhost.nn-sv.dhp | 0 .../tests/certs/Server-localhost.nn-sv.key | 28 - .../tests/certs/Server-localhost.nn-sv.pem | 165 - .../tests/certs/Server-localhost.nn-sv.prm | 38 - .../certs/Server-localhost.nn-sv.pub.der | Bin 294 -> 0 bytes .../certs/Server-localhost.nn-sv.pub.pem | 9 - .../Server-localhost.nn-sv.pubkey-pinned | 1 - .../tests/certs/Server-localhost0h-sv.crl | 14 - .../tests/certs/Server-localhost0h-sv.crt | 99 - .../tests/certs/Server-localhost0h-sv.csr | 16 - .../tests/certs/Server-localhost0h-sv.der | Bin 1098 -> 0 bytes .../tests/certs/Server-localhost0h-sv.dhp | 0 .../tests/certs/Server-localhost0h-sv.key | 28 - .../tests/certs/Server-localhost0h-sv.pem | 166 - .../tests/certs/Server-localhost0h-sv.prm | 39 - .../tests/certs/Server-localhost0h-sv.pub.der | Bin 294 -> 0 bytes .../tests/certs/Server-localhost0h-sv.pub.pem | 9 - .../certs/Server-localhost0h-sv.pubkey-pinned | 1 - third-party/curl/tests/certs/genserv.pl | 146 + .../curl/tests/certs/scripts/Makefile.am | 30 - .../curl/tests/certs/scripts/genroot.sh | 89 - .../curl/tests/certs/scripts/genserv.sh | 143 - third-party/curl/tests/certs/stunnel-sv.crl | 15 - third-party/curl/tests/certs/stunnel-sv.crt | 99 - third-party/curl/tests/certs/stunnel-sv.csr | 16 - third-party/curl/tests/certs/stunnel-sv.der | Bin 1096 -> 0 bytes third-party/curl/tests/certs/stunnel-sv.dhp | 0 third-party/curl/tests/certs/stunnel-sv.key | 28 - third-party/curl/tests/certs/stunnel-sv.pem | 165 - third-party/curl/tests/certs/stunnel-sv.prm | 38 - .../curl/tests/certs/stunnel-sv.pub.der | Bin 294 -> 0 bytes .../curl/tests/certs/stunnel-sv.pub.pem | 9 - .../curl/tests/certs/stunnel-sv.pubkey-pinned | 1 - third-party/curl/tests/certs/test-ca.cnf | 11 + third-party/curl/tests/certs/test-ca.prm | 32 + .../curl/tests/certs/test-client-cert.prm | 34 + .../curl/tests/certs/test-client-eku-only.prm | 34 + .../tests/certs/test-localhost-san-first.prm | 34 + .../tests/certs/test-localhost-san-last.prm | 34 + .../curl/tests/certs/test-localhost.nn.prm | 34 + .../curl/tests/certs/test-localhost.prm | 34 + .../curl/tests/certs/test-localhost0h.prm | 35 + third-party/curl/tests/check-deprecated.pl | 329 - .../curl/tests/check-translatable-options.pl | 147 - third-party/curl/tests/cmake/CMakeLists.txt | 138 + third-party/curl/tests/cmake/test.c | 35 + third-party/curl/tests/cmake/test.cpp | 47 + third-party/curl/tests/cmake/test.sh | 94 + third-party/curl/tests/configurehelp.pm.in | 45 + third-party/curl/tests/conftest.py | 60 - third-party/curl/tests/convsrctest.pl | 263 - third-party/curl/tests/data/.gitattributes | 5 - third-party/curl/tests/data/CMakeLists.txt | 26 - third-party/curl/tests/data/DISABLED | 79 +- third-party/curl/tests/data/Makefile.am | 277 +- third-party/curl/tests/data/Makefile.inc | 261 - third-party/curl/tests/data/data-xml1 | 112 + third-party/curl/tests/data/data1400.c | 46 + third-party/curl/tests/data/data1401.c | 58 + third-party/curl/tests/data/data1402.c | 48 + third-party/curl/tests/data/data1403.c | 46 + third-party/curl/tests/data/data1404.c | 83 + third-party/curl/tests/data/data1405.c | 66 + third-party/curl/tests/data/data1406.c | 56 + third-party/curl/tests/data/data1407.c | 46 + third-party/curl/tests/data/data1420.c | 46 + third-party/curl/tests/data/data1461.txt | 23 + third-party/curl/tests/data/data1463.txt | 5 + third-party/curl/tests/data/data1465.c | 48 + third-party/curl/tests/data/data1481.c | 49 + third-party/curl/tests/data/data1705-1.md | 11 + third-party/curl/tests/data/data1705-2.md | 40 + third-party/curl/tests/data/data1705-3.md | 48 + third-party/curl/tests/data/data1705-4.md | 22 + third-party/curl/tests/data/data1705-stdout.1 | 126 + third-party/curl/tests/data/data1706-1.md | 11 + third-party/curl/tests/data/data1706-2.md | 36 + third-party/curl/tests/data/data1706-3.md | 48 + third-party/curl/tests/data/data1706-4.md | 22 + .../curl/tests/data/data1706-stdout.txt | 116 + third-party/curl/tests/data/data320.html | 19 + third-party/curl/tests/data/test1 | 20 +- third-party/curl/tests/data/test10 | 9 +- third-party/curl/tests/data/test100 | 14 +- third-party/curl/tests/data/test1000 | 12 +- third-party/curl/tests/data/test1001 | 21 +- third-party/curl/tests/data/test1002 | 21 +- third-party/curl/tests/data/test1003 | 11 +- third-party/curl/tests/data/test1004 | 15 +- third-party/curl/tests/data/test1005 | 11 +- third-party/curl/tests/data/test1006 | 13 +- third-party/curl/tests/data/test1007 | 13 +- third-party/curl/tests/data/test1008 | 31 +- third-party/curl/tests/data/test1009 | 10 +- third-party/curl/tests/data/test101 | 15 +- third-party/curl/tests/data/test1010 | 21 +- third-party/curl/tests/data/test1011 | 24 +- third-party/curl/tests/data/test1012 | 24 +- third-party/curl/tests/data/test1013 | 19 +- third-party/curl/tests/data/test1014 | 19 +- third-party/curl/tests/data/test1015 | 24 +- third-party/curl/tests/data/test1016 | 10 +- third-party/curl/tests/data/test1017 | 10 +- third-party/curl/tests/data/test1018 | 10 +- third-party/curl/tests/data/test1019 | 10 +- third-party/curl/tests/data/test102 | 9 +- third-party/curl/tests/data/test1020 | 10 +- third-party/curl/tests/data/test1021 | 41 +- third-party/curl/tests/data/test1022 | 19 +- third-party/curl/tests/data/test1023 | 19 +- third-party/curl/tests/data/test1024 | 17 +- third-party/curl/tests/data/test1025 | 17 +- third-party/curl/tests/data/test1026 | 23 +- third-party/curl/tests/data/test1027 | 23 +- third-party/curl/tests/data/test1028 | 16 +- third-party/curl/tests/data/test1029 | 13 +- third-party/curl/tests/data/test103 | 9 +- third-party/curl/tests/data/test1030 | 18 +- third-party/curl/tests/data/test1031 | 9 +- third-party/curl/tests/data/test1032 | 12 +- third-party/curl/tests/data/test1033 | 13 +- third-party/curl/tests/data/test1034 | 30 +- third-party/curl/tests/data/test1035 | 27 +- third-party/curl/tests/data/test1036 | 9 +- third-party/curl/tests/data/test1037 | 9 +- third-party/curl/tests/data/test1038 | 13 +- third-party/curl/tests/data/test1039 | 13 +- third-party/curl/tests/data/test104 | 9 +- third-party/curl/tests/data/test1040 | 19 +- third-party/curl/tests/data/test1041 | 13 +- third-party/curl/tests/data/test1042 | 22 +- third-party/curl/tests/data/test1043 | 25 +- third-party/curl/tests/data/test1044 | 13 +- third-party/curl/tests/data/test1045 | 14 +- third-party/curl/tests/data/test1046 | 22 +- third-party/curl/tests/data/test1047 | 18 +- third-party/curl/tests/data/test1048 | 26 +- third-party/curl/tests/data/test1049 | 10 +- third-party/curl/tests/data/test105 | 9 +- third-party/curl/tests/data/test1050 | 26 +- third-party/curl/tests/data/test1051 | 15 +- third-party/curl/tests/data/test1052 | 15 +- third-party/curl/tests/data/test1053 | 97 +- third-party/curl/tests/data/test1054 | 18 +- third-party/curl/tests/data/test1055 | 38 +- third-party/curl/tests/data/test1056 | 26 +- third-party/curl/tests/data/test1057 | 9 +- third-party/curl/tests/data/test1058 | 11 +- third-party/curl/tests/data/test1059 | 19 +- third-party/curl/tests/data/test106 | 9 +- third-party/curl/tests/data/test1060 | 833 +- third-party/curl/tests/data/test1061 | 847 +-- third-party/curl/tests/data/test1062 | 11 +- third-party/curl/tests/data/test1063 | 17 +- third-party/curl/tests/data/test1064 | 16 +- third-party/curl/tests/data/test1065 | 16 +- third-party/curl/tests/data/test1066 | 53 +- third-party/curl/tests/data/test1067 | 9 +- third-party/curl/tests/data/test1068 | 27 +- third-party/curl/tests/data/test1069 | 5 +- third-party/curl/tests/data/test107 | 9 +- third-party/curl/tests/data/test1070 | 20 +- third-party/curl/tests/data/test1071 | 16 +- third-party/curl/tests/data/test1072 | 35 +- third-party/curl/tests/data/test1073 | 35 +- third-party/curl/tests/data/test1074 | 15 +- third-party/curl/tests/data/test1075 | 17 +- third-party/curl/tests/data/test1076 | 18 +- third-party/curl/tests/data/test1077 | 16 +- third-party/curl/tests/data/test1078 | 20 +- third-party/curl/tests/data/test1079 | 14 +- third-party/curl/tests/data/test108 | 9 +- third-party/curl/tests/data/test1080 | 13 +- third-party/curl/tests/data/test1081 | 15 +- third-party/curl/tests/data/test1082 | 16 +- third-party/curl/tests/data/test1083 | 18 +- third-party/curl/tests/data/test1084 | 14 +- third-party/curl/tests/data/test1085 | 18 +- third-party/curl/tests/data/test1086 | 71 +- third-party/curl/tests/data/test1087 | 22 +- third-party/curl/tests/data/test1088 | 24 +- third-party/curl/tests/data/test1089 | 18 +- third-party/curl/tests/data/test109 | 9 +- third-party/curl/tests/data/test1090 | 20 +- third-party/curl/tests/data/test1091 | 9 +- third-party/curl/tests/data/test1092 | 12 +- third-party/curl/tests/data/test1093 | 14 +- third-party/curl/tests/data/test1094 | 12 +- third-party/curl/tests/data/test1095 | 16 +- third-party/curl/tests/data/test1096 | 10 +- third-party/curl/tests/data/test1097 | 17 +- third-party/curl/tests/data/test1098 | 16 +- third-party/curl/tests/data/test1099 | 10 +- third-party/curl/tests/data/test11 | 9 +- third-party/curl/tests/data/test110 | 9 +- third-party/curl/tests/data/test1100 | 32 +- third-party/curl/tests/data/test1101 | 17 +- third-party/curl/tests/data/test1102 | 9 +- third-party/curl/tests/data/test1103 | 9 +- third-party/curl/tests/data/test1104 | 9 +- third-party/curl/tests/data/test1105 | 33 +- third-party/curl/tests/data/test1106 | 11 +- third-party/curl/tests/data/test1107 | 9 +- third-party/curl/tests/data/test1108 | 11 +- third-party/curl/tests/data/test1109 | 10 +- third-party/curl/tests/data/test111 | 10 +- third-party/curl/tests/data/test1110 | 10 +- third-party/curl/tests/data/test1111 | 10 +- third-party/curl/tests/data/test1112 | 72 +- third-party/curl/tests/data/test1113 | 7 +- third-party/curl/tests/data/test1114 | 9 +- third-party/curl/tests/data/test1115 | 12 +- third-party/curl/tests/data/test1116 | 24 +- third-party/curl/tests/data/test1117 | 17 +- third-party/curl/tests/data/test1118 | 12 +- third-party/curl/tests/data/test1119 | 12 +- third-party/curl/tests/data/test112 | 13 +- third-party/curl/tests/data/test1120 | 10 +- third-party/curl/tests/data/test1121 | 14 +- third-party/curl/tests/data/test1122 | 35 +- third-party/curl/tests/data/test1123 | 185 +- third-party/curl/tests/data/test1124 | 36 +- third-party/curl/tests/data/test1125 | 37 +- third-party/curl/tests/data/test1126 | 12 +- third-party/curl/tests/data/test1127 | 12 +- third-party/curl/tests/data/test1128 | 12 +- third-party/curl/tests/data/test1129 | 17 +- third-party/curl/tests/data/test113 | 10 +- third-party/curl/tests/data/test1130 | 19 +- third-party/curl/tests/data/test1131 | 19 +- third-party/curl/tests/data/test1132 | 53 +- third-party/curl/tests/data/test1133 | 92 +- third-party/curl/tests/data/test1134 | 16 +- third-party/curl/tests/data/test1135 | 21 +- third-party/curl/tests/data/test1136 | 2 + third-party/curl/tests/data/test1137 | 9 +- third-party/curl/tests/data/test1138 | 24 +- third-party/curl/tests/data/test1139 | 8 +- third-party/curl/tests/data/test114 | 10 +- third-party/curl/tests/data/test1140 | 12 +- third-party/curl/tests/data/test1141 | 9 +- third-party/curl/tests/data/test1142 | 9 +- third-party/curl/tests/data/test1143 | 9 +- third-party/curl/tests/data/test1144 | 18 +- third-party/curl/tests/data/test1145 | 3 + third-party/curl/tests/data/test1146 | 1 + third-party/curl/tests/data/test1147 | 16 +- third-party/curl/tests/data/test1148 | 16 +- third-party/curl/tests/data/test1149 | 18 +- third-party/curl/tests/data/test115 | 10 +- third-party/curl/tests/data/test1150 | 9 +- third-party/curl/tests/data/test1151 | 21 +- third-party/curl/tests/data/test1152 | 42 +- third-party/curl/tests/data/test1153 | 14 +- third-party/curl/tests/data/test1154 | 16 +- third-party/curl/tests/data/test1155 | 11 +- third-party/curl/tests/data/test1156 | 18 +- third-party/curl/tests/data/test1157 | 12 +- third-party/curl/tests/data/test1158 | 76 +- third-party/curl/tests/data/test1159 | 11 +- third-party/curl/tests/data/test116 | 12 +- third-party/curl/tests/data/test1160 | 14 +- third-party/curl/tests/data/test1161 | 11 +- third-party/curl/tests/data/test1162 | 4 +- third-party/curl/tests/data/test1163 | 4 +- third-party/curl/tests/data/test1164 | 25 +- third-party/curl/tests/data/test1165 | 12 +- third-party/curl/tests/data/test1166 | 11 +- third-party/curl/tests/data/test1167 | 12 +- third-party/curl/tests/data/test1168 | 13 +- third-party/curl/tests/data/test1169 | 5 +- third-party/curl/tests/data/test117 | 10 +- third-party/curl/tests/data/test1170 | 37 +- third-party/curl/tests/data/test1171 | 37 +- third-party/curl/tests/data/test1172 | 12 +- third-party/curl/tests/data/test1173 | 12 +- third-party/curl/tests/data/test1174 | 12 +- third-party/curl/tests/data/test1175 | 12 +- third-party/curl/tests/data/test1176 | 16 +- third-party/curl/tests/data/test1177 | 13 +- third-party/curl/tests/data/test1178 | 16 +- third-party/curl/tests/data/test1179 | 7 +- third-party/curl/tests/data/test118 | 10 +- third-party/curl/tests/data/test1180 | 9 +- third-party/curl/tests/data/test1181 | 13 +- third-party/curl/tests/data/test1182 | 12 +- third-party/curl/tests/data/test1183 | 11 +- third-party/curl/tests/data/test1184 | 22 +- third-party/curl/tests/data/test1185 | 125 +- third-party/curl/tests/data/test1186 | 76 +- third-party/curl/tests/data/test1187 | 28 +- third-party/curl/tests/data/test1188 | 9 +- third-party/curl/tests/data/test1189 | 107 +- third-party/curl/tests/data/test119 | 10 +- third-party/curl/tests/data/test1190 | 8 +- third-party/curl/tests/data/test1191 | 5 +- third-party/curl/tests/data/test1192 | 14 +- third-party/curl/tests/data/test1193 | 26 +- third-party/curl/tests/data/test1194 | 10 +- third-party/curl/tests/data/test1195 | 8 +- third-party/curl/tests/data/test1196 | 10 +- third-party/curl/tests/data/test1197 | 18 +- third-party/curl/tests/data/test1198 | 8 +- third-party/curl/tests/data/test1199 | 8 +- third-party/curl/tests/data/test12 | 11 +- third-party/curl/tests/data/test120 | 9 +- third-party/curl/tests/data/test1200 | 13 +- third-party/curl/tests/data/test1201 | 17 +- third-party/curl/tests/data/test1202 | 13 +- third-party/curl/tests/data/test1203 | 15 +- third-party/curl/tests/data/test1204 | 17 +- third-party/curl/tests/data/test1205 | 14 +- third-party/curl/tests/data/test1206 | 12 +- third-party/curl/tests/data/test1207 | 11 +- third-party/curl/tests/data/test1208 | 18 +- third-party/curl/tests/data/test1209 | 14 +- third-party/curl/tests/data/test121 | 9 +- third-party/curl/tests/data/test1210 | 16 +- third-party/curl/tests/data/test1211 | 14 +- third-party/curl/tests/data/test1212 | 9 +- third-party/curl/tests/data/test1213 | 11 +- third-party/curl/tests/data/test1214 | 11 +- third-party/curl/tests/data/test1215 | 5 +- third-party/curl/tests/data/test1216 | 13 +- third-party/curl/tests/data/test1217 | 9 +- third-party/curl/tests/data/test1218 | 13 +- third-party/curl/tests/data/test1219 | 9 +- third-party/curl/tests/data/test122 | 9 +- third-party/curl/tests/data/test1220 | 5 +- third-party/curl/tests/data/test1221 | 26 +- third-party/curl/tests/data/test1222 | 12 +- third-party/curl/tests/data/test1223 | 12 +- third-party/curl/tests/data/test1224 | 9 +- third-party/curl/tests/data/test1225 | 9 +- third-party/curl/tests/data/test1226 | 9 +- third-party/curl/tests/data/test1227 | 9 +- third-party/curl/tests/data/test1228 | 9 +- third-party/curl/tests/data/test1229 | 18 +- third-party/curl/tests/data/test123 | 9 +- third-party/curl/tests/data/test1230 | 20 +- third-party/curl/tests/data/test1231 | 12 +- third-party/curl/tests/data/test1232 | 12 +- third-party/curl/tests/data/test1233 | 13 +- third-party/curl/tests/data/test1234 | 11 +- third-party/curl/tests/data/test1235 | 15 +- third-party/curl/tests/data/test1236 | 11 +- third-party/curl/tests/data/test1237 | 15 +- third-party/curl/tests/data/test1238 | 13 +- third-party/curl/tests/data/test1239 | 12 +- third-party/curl/tests/data/test124 | 9 +- third-party/curl/tests/data/test1240 | 9 +- third-party/curl/tests/data/test1241 | 12 +- third-party/curl/tests/data/test1242 | 10 +- third-party/curl/tests/data/test1243 | 9 +- third-party/curl/tests/data/test1244 | 6 +- third-party/curl/tests/data/test1245 | 8 +- third-party/curl/tests/data/test1246 | 14 +- third-party/curl/tests/data/test1247 | 10 +- third-party/curl/tests/data/test1248 | 7 +- third-party/curl/tests/data/test1249 | 7 +- third-party/curl/tests/data/test125 | 10 +- third-party/curl/tests/data/test1250 | 7 +- third-party/curl/tests/data/test1251 | 7 +- third-party/curl/tests/data/test1252 | 5 +- third-party/curl/tests/data/test1253 | 5 +- third-party/curl/tests/data/test1254 | 5 +- third-party/curl/tests/data/test1255 | 6 +- third-party/curl/tests/data/test1256 | 6 +- third-party/curl/tests/data/test1257 | 6 +- third-party/curl/tests/data/test1258 | 11 +- third-party/curl/tests/data/test1259 | 13 +- third-party/curl/tests/data/test126 | 9 +- third-party/curl/tests/data/test1260 | 10 +- third-party/curl/tests/data/test1261 | 13 +- third-party/curl/tests/data/test1262 | 9 +- third-party/curl/tests/data/test1263 | 10 +- third-party/curl/tests/data/test1264 | 12 +- third-party/curl/tests/data/test1265 | 9 +- third-party/curl/tests/data/test1266 | 16 +- third-party/curl/tests/data/test1267 | 18 +- third-party/curl/tests/data/test1268 | 22 +- third-party/curl/tests/data/test1269 | 13 +- third-party/curl/tests/data/test127 | 9 +- third-party/curl/tests/data/test1270 | 13 +- third-party/curl/tests/data/test1271 | 11 +- third-party/curl/tests/data/test1272 | 13 +- third-party/curl/tests/data/test1273 | 19 +- third-party/curl/tests/data/test1274 | 51 +- third-party/curl/tests/data/test1275 | 8 +- third-party/curl/tests/data/test1276 | 12 +- third-party/curl/tests/data/test1277 | 191 +- third-party/curl/tests/data/test1278 | 6 +- third-party/curl/tests/data/test1279 | 14 +- third-party/curl/tests/data/test128 | 15 +- third-party/curl/tests/data/test1280 | 12 +- third-party/curl/tests/data/test1281 | 13 +- third-party/curl/tests/data/test1282 | 16 +- third-party/curl/tests/data/test1283 | 8 +- third-party/curl/tests/data/test1284 | 15 +- third-party/curl/tests/data/test1285 | 15 +- third-party/curl/tests/data/test1286 | 17 +- third-party/curl/tests/data/test1287 | 17 +- third-party/curl/tests/data/test1288 | 44 +- third-party/curl/tests/data/test1289 | 4 +- third-party/curl/tests/data/test129 | 12 +- third-party/curl/tests/data/test1290 | 4 +- third-party/curl/tests/data/test1291 | 12 +- third-party/curl/tests/data/test1292 | 14 +- third-party/curl/tests/data/test1293 | 18 +- third-party/curl/tests/data/test1294 | 17 +- third-party/curl/tests/data/test1295 | 17 +- third-party/curl/tests/data/test1296 | 6 +- third-party/curl/tests/data/test1297 | 10 +- third-party/curl/tests/data/test1298 | 12 +- third-party/curl/tests/data/test1299 | 12 +- third-party/curl/tests/data/test13 | 11 +- third-party/curl/tests/data/test130 | 19 +- third-party/curl/tests/data/test1300 | 9 +- third-party/curl/tests/data/test1301 | 9 +- third-party/curl/tests/data/test1302 | 9 +- third-party/curl/tests/data/test1303 | 13 +- third-party/curl/tests/data/test1304 | 9 +- third-party/curl/tests/data/test1305 | 9 +- third-party/curl/tests/data/test1306 | 12 +- third-party/curl/tests/data/test1307 | 9 +- third-party/curl/tests/data/test1308 | 16 +- third-party/curl/tests/data/test1309 | 9 +- third-party/curl/tests/data/test131 | 19 +- third-party/curl/tests/data/test1310 | 129 +- third-party/curl/tests/data/test1311 | 16 +- third-party/curl/tests/data/test1312 | 16 +- third-party/curl/tests/data/test1313 | 16 +- third-party/curl/tests/data/test1314 | 9 +- third-party/curl/tests/data/test1315 | 71 +- third-party/curl/tests/data/test1316 | 26 +- third-party/curl/tests/data/test1317 | 6 +- third-party/curl/tests/data/test1318 | 14 +- third-party/curl/tests/data/test1319 | 20 +- third-party/curl/tests/data/test132 | 18 +- third-party/curl/tests/data/test1320 | 24 +- third-party/curl/tests/data/test1321 | 20 +- third-party/curl/tests/data/test1322 | 8 +- third-party/curl/tests/data/test1323 | 7 +- third-party/curl/tests/data/test1324 | 11 +- third-party/curl/tests/data/test1325 | 18 +- third-party/curl/tests/data/test1326 | 14 +- third-party/curl/tests/data/test1327 | 16 +- third-party/curl/tests/data/test1328 | 13 +- third-party/curl/tests/data/test1329 | 9 +- third-party/curl/tests/data/test133 | 18 +- third-party/curl/tests/data/test1330 | 11 +- third-party/curl/tests/data/test1331 | 21 +- third-party/curl/tests/data/test1332 | 18 +- third-party/curl/tests/data/test1333 | 14 +- third-party/curl/tests/data/test1334 | 20 +- third-party/curl/tests/data/test1335 | 20 +- third-party/curl/tests/data/test1336 | 27 +- third-party/curl/tests/data/test1337 | 27 +- third-party/curl/tests/data/test1338 | 20 +- third-party/curl/tests/data/test1339 | 20 +- third-party/curl/tests/data/test134 | 12 +- third-party/curl/tests/data/test1340 | 22 +- third-party/curl/tests/data/test1341 | 22 +- third-party/curl/tests/data/test1342 | 22 +- third-party/curl/tests/data/test1343 | 22 +- third-party/curl/tests/data/test1344 | 29 +- third-party/curl/tests/data/test1345 | 29 +- third-party/curl/tests/data/test1346 | 20 +- third-party/curl/tests/data/test1347 | 26 +- third-party/curl/tests/data/test1348 | 13 +- third-party/curl/tests/data/test1349 | 27 +- third-party/curl/tests/data/test135 | 9 +- third-party/curl/tests/data/test1350 | 27 +- third-party/curl/tests/data/test1351 | 27 +- third-party/curl/tests/data/test1352 | 27 +- third-party/curl/tests/data/test1353 | 27 +- third-party/curl/tests/data/test1354 | 23 +- third-party/curl/tests/data/test1355 | 13 +- third-party/curl/tests/data/test1356 | 24 +- third-party/curl/tests/data/test1357 | 30 +- third-party/curl/tests/data/test1358 | 29 +- third-party/curl/tests/data/test1359 | 29 +- third-party/curl/tests/data/test136 | 11 +- third-party/curl/tests/data/test1360 | 29 +- third-party/curl/tests/data/test1361 | 29 +- third-party/curl/tests/data/test1362 | 29 +- third-party/curl/tests/data/test1363 | 23 +- third-party/curl/tests/data/test1364 | 16 +- third-party/curl/tests/data/test1365 | 16 +- third-party/curl/tests/data/test1366 | 17 +- third-party/curl/tests/data/test1367 | 17 +- third-party/curl/tests/data/test1368 | 16 +- third-party/curl/tests/data/test1369 | 16 +- third-party/curl/tests/data/test137 | 9 +- third-party/curl/tests/data/test1370 | 17 +- third-party/curl/tests/data/test1371 | 17 +- third-party/curl/tests/data/test1372 | 18 +- third-party/curl/tests/data/test1373 | 18 +- third-party/curl/tests/data/test1374 | 19 +- third-party/curl/tests/data/test1375 | 19 +- third-party/curl/tests/data/test1376 | 16 +- third-party/curl/tests/data/test1377 | 17 +- third-party/curl/tests/data/test1378 | 9 +- third-party/curl/tests/data/test1379 | 19 +- third-party/curl/tests/data/test138 | 9 +- third-party/curl/tests/data/test1380 | 19 +- third-party/curl/tests/data/test1381 | 19 +- third-party/curl/tests/data/test1382 | 19 +- third-party/curl/tests/data/test1383 | 19 +- third-party/curl/tests/data/test1384 | 19 +- third-party/curl/tests/data/test1385 | 9 +- third-party/curl/tests/data/test1386 | 14 +- third-party/curl/tests/data/test1387 | 24 +- third-party/curl/tests/data/test1388 | 24 +- third-party/curl/tests/data/test1389 | 26 +- third-party/curl/tests/data/test139 | 9 +- third-party/curl/tests/data/test1390 | 24 +- third-party/curl/tests/data/test1391 | 24 +- third-party/curl/tests/data/test1392 | 24 +- third-party/curl/tests/data/test1393 | 14 +- third-party/curl/tests/data/test1394 | 12 +- third-party/curl/tests/data/test1395 | 9 +- third-party/curl/tests/data/test1396 | 9 +- third-party/curl/tests/data/test1397 | 5 +- third-party/curl/tests/data/test1398 | 9 +- third-party/curl/tests/data/test1399 | 9 +- third-party/curl/tests/data/test14 | 9 +- third-party/curl/tests/data/test140 | 9 +- third-party/curl/tests/data/test1400 | 69 +- third-party/curl/tests/data/test1401 | 81 +- third-party/curl/tests/data/test1402 | 74 +- third-party/curl/tests/data/test1403 | 72 +- third-party/curl/tests/data/test1404 | 180 +- third-party/curl/tests/data/test1405 | 91 +- third-party/curl/tests/data/test1406 | 95 +- third-party/curl/tests/data/test1407 | 74 +- third-party/curl/tests/data/test1408 | 16 +- third-party/curl/tests/data/test1409 | 14 +- third-party/curl/tests/data/test141 | 11 +- third-party/curl/tests/data/test1410 | 14 +- third-party/curl/tests/data/test1411 | 16 +- third-party/curl/tests/data/test1412 | 22 +- third-party/curl/tests/data/test1413 | 18 +- third-party/curl/tests/data/test1414 | 13 +- third-party/curl/tests/data/test1415 | 15 +- third-party/curl/tests/data/test1416 | 28 +- third-party/curl/tests/data/test1417 | 40 +- third-party/curl/tests/data/test1418 | 22 +- third-party/curl/tests/data/test1419 | 15 +- third-party/curl/tests/data/test142 | 13 +- third-party/curl/tests/data/test1420 | 75 +- third-party/curl/tests/data/test1421 | 14 +- third-party/curl/tests/data/test1422 | 17 +- third-party/curl/tests/data/test1423 | 17 +- third-party/curl/tests/data/test1424 | 6 +- third-party/curl/tests/data/test1425 | Bin 1735 -> 1296 bytes third-party/curl/tests/data/test1426 | Bin 1672 -> 1244 bytes third-party/curl/tests/data/test1427 | 12 +- third-party/curl/tests/data/test1428 | 22 +- third-party/curl/tests/data/test1429 | 13 +- third-party/curl/tests/data/test143 | 9 +- third-party/curl/tests/data/test1430 | 11 +- third-party/curl/tests/data/test1431 | 11 +- third-party/curl/tests/data/test1432 | 9 +- third-party/curl/tests/data/test1433 | 9 +- third-party/curl/tests/data/test1434 | 29 +- third-party/curl/tests/data/test1435 | 13 +- third-party/curl/tests/data/test1436 | 13 +- third-party/curl/tests/data/test1437 | 16 +- third-party/curl/tests/data/test1438 | 5 +- third-party/curl/tests/data/test1439 | 3 +- third-party/curl/tests/data/test144 | 9 +- third-party/curl/tests/data/test1440 | 3 +- third-party/curl/tests/data/test1441 | 3 +- third-party/curl/tests/data/test1442 | 3 +- third-party/curl/tests/data/test1443 | 24 +- third-party/curl/tests/data/test1444 | 19 +- third-party/curl/tests/data/test1445 | 16 +- third-party/curl/tests/data/test1446 | 24 +- third-party/curl/tests/data/test1447 | 16 +- third-party/curl/tests/data/test1448 | 29 +- third-party/curl/tests/data/test1449 | 9 +- third-party/curl/tests/data/test145 | 9 +- third-party/curl/tests/data/test1450 | 10 +- third-party/curl/tests/data/test1451 | 7 +- third-party/curl/tests/data/test1452 | 10 +- third-party/curl/tests/data/test1453 | 18 +- third-party/curl/tests/data/test1454 | 10 +- third-party/curl/tests/data/test1455 | 6 +- third-party/curl/tests/data/test1456 | 16 +- third-party/curl/tests/data/test1457 | 3 +- third-party/curl/tests/data/test1458 | 6 +- third-party/curl/tests/data/test1459 | 29 +- third-party/curl/tests/data/test146 | 9 +- third-party/curl/tests/data/test1460 | 25 +- third-party/curl/tests/data/test1461 | 34 +- third-party/curl/tests/data/test1462 | 61 +- third-party/curl/tests/data/test1463 | 19 +- third-party/curl/tests/data/test1464 | 19 +- third-party/curl/tests/data/test1465 | 71 +- third-party/curl/tests/data/test1466 | 9 +- third-party/curl/tests/data/test1467 | 20 +- third-party/curl/tests/data/test1468 | 20 +- third-party/curl/tests/data/test1469 | 11 +- third-party/curl/tests/data/test147 | 9 +- third-party/curl/tests/data/test1470 | 22 +- third-party/curl/tests/data/test1471 | 10 +- third-party/curl/tests/data/test1472 | 10 +- third-party/curl/tests/data/test1473 | 20 +- third-party/curl/tests/data/test1474 | 106 +- third-party/curl/tests/data/test1475 | 84 + third-party/curl/tests/data/test1476 | 60 + third-party/curl/tests/data/test1477 | 26 + third-party/curl/tests/data/test1478 | 28 + third-party/curl/tests/data/test1479 | 59 + third-party/curl/tests/data/test148 | 9 +- third-party/curl/tests/data/test1480 | 51 + third-party/curl/tests/data/test1481 | 69 + third-party/curl/tests/data/test1482 | 79 + third-party/curl/tests/data/test1483 | 82 + third-party/curl/tests/data/test1484 | 51 + third-party/curl/tests/data/test1485 | 52 + third-party/curl/tests/data/test1486 | 28 + third-party/curl/tests/data/test1487 | 52 + third-party/curl/tests/data/test1488 | 27 + third-party/curl/tests/data/test1489 | 64 + third-party/curl/tests/data/test149 | 9 +- third-party/curl/tests/data/test1490 | 44 + third-party/curl/tests/data/test1491 | 38 + third-party/curl/tests/data/test1492 | 61 + third-party/curl/tests/data/test1493 | 76 + third-party/curl/tests/data/test1494 | 48 + third-party/curl/tests/data/test1495 | 51 + third-party/curl/tests/data/test1496 | 51 + third-party/curl/tests/data/test1497 | 59 + third-party/curl/tests/data/test1498 | 60 + third-party/curl/tests/data/test1499 | 74 + third-party/curl/tests/data/test15 | 13 +- third-party/curl/tests/data/test150 | 11 +- third-party/curl/tests/data/test1500 | 9 +- third-party/curl/tests/data/test1501 | 9 +- third-party/curl/tests/data/test1502 | 13 +- third-party/curl/tests/data/test1503 | 15 +- third-party/curl/tests/data/test1504 | 15 +- third-party/curl/tests/data/test1505 | 15 +- third-party/curl/tests/data/test1506 | 33 +- third-party/curl/tests/data/test1507 | 16 +- third-party/curl/tests/data/test1508 | 11 +- third-party/curl/tests/data/test1509 | 19 +- third-party/curl/tests/data/test151 | 13 +- third-party/curl/tests/data/test1510 | 30 +- third-party/curl/tests/data/test1511 | 9 +- third-party/curl/tests/data/test1512 | 21 +- third-party/curl/tests/data/test1513 | 13 +- third-party/curl/tests/data/test1514 | 5 +- third-party/curl/tests/data/test1515 | 4 +- third-party/curl/tests/data/test1516 | 8 +- third-party/curl/tests/data/test1517 | 23 +- third-party/curl/tests/data/test1518 | 14 +- third-party/curl/tests/data/test1519 | 14 +- third-party/curl/tests/data/test152 | 13 +- third-party/curl/tests/data/test1520 | 21 +- third-party/curl/tests/data/test1521 | 16 +- third-party/curl/tests/data/test1522 | 3 +- third-party/curl/tests/data/test1523 | 3 +- third-party/curl/tests/data/test1524 | 18 +- third-party/curl/tests/data/test1525 | 19 +- third-party/curl/tests/data/test1526 | 19 +- third-party/curl/tests/data/test1527 | 21 +- third-party/curl/tests/data/test1528 | 15 +- third-party/curl/tests/data/test1529 | 11 +- third-party/curl/tests/data/test153 | 27 +- third-party/curl/tests/data/test1530 | 8 +- third-party/curl/tests/data/test1531 | Bin 573 -> 632 bytes third-party/curl/tests/data/test1532 | 7 +- third-party/curl/tests/data/test1533 | 9 +- third-party/curl/tests/data/test1534 | 7 +- third-party/curl/tests/data/test1535 | 5 +- third-party/curl/tests/data/test1536 | 5 +- third-party/curl/tests/data/test1537 | 9 +- third-party/curl/tests/data/test1538 | 43 +- third-party/curl/tests/data/test1539 | 5 +- third-party/curl/tests/data/test154 | 16 +- third-party/curl/tests/data/test1540 | 43 +- third-party/curl/tests/data/test1541 | 75 + third-party/curl/tests/data/test1542 | 27 +- third-party/curl/tests/data/test1543 | 10 +- third-party/curl/tests/data/test1544 | 12 +- third-party/curl/tests/data/test1545 | 37 + third-party/curl/tests/data/test1546 | 61 + third-party/curl/tests/data/test1547 | 54 + third-party/curl/tests/data/test1548 | 41 + third-party/curl/tests/data/test1549 | 57 + third-party/curl/tests/data/test155 | 13 +- third-party/curl/tests/data/test1550 | 13 +- third-party/curl/tests/data/test1551 | 9 +- third-party/curl/tests/data/test1552 | 14 +- third-party/curl/tests/data/test1553 | 16 +- third-party/curl/tests/data/test1554 | 105 +- third-party/curl/tests/data/test1555 | 13 +- third-party/curl/tests/data/test1556 | 14 +- third-party/curl/tests/data/test1557 | 9 +- third-party/curl/tests/data/test1558 | 5 +- third-party/curl/tests/data/test1559 | 9 +- third-party/curl/tests/data/test156 | 11 +- third-party/curl/tests/data/test1560 | 17 +- third-party/curl/tests/data/test1561 | 9 +- third-party/curl/tests/data/test1562 | 5 +- third-party/curl/tests/data/test1563 | 3 +- third-party/curl/tests/data/test1564 | 6 +- third-party/curl/tests/data/test1565 | 3 +- third-party/curl/tests/data/test1566 | 8 +- third-party/curl/tests/data/test1567 | 9 +- third-party/curl/tests/data/test1568 | 10 +- third-party/curl/tests/data/test1569 | 7 +- third-party/curl/tests/data/test157 | 13 +- third-party/curl/tests/data/test1570 | 7 +- third-party/curl/tests/data/test1571 | 92 + third-party/curl/tests/data/test1572 | 94 + third-party/curl/tests/data/test1573 | 89 + third-party/curl/tests/data/test1574 | 89 + third-party/curl/tests/data/test1575 | 94 + third-party/curl/tests/data/test1576 | 92 + third-party/curl/tests/data/test1577 | 92 + third-party/curl/tests/data/test1578 | 92 + third-party/curl/tests/data/test1579 | 90 + third-party/curl/tests/data/test158 | 13 +- third-party/curl/tests/data/test1580 | 92 + third-party/curl/tests/data/test1581 | 94 + third-party/curl/tests/data/test1582 | 55 + third-party/curl/tests/data/test1583 | 36 + third-party/curl/tests/data/test1584 | 53 + third-party/curl/tests/data/test1585 | 53 + third-party/curl/tests/data/test1586 | 73 + third-party/curl/tests/data/test1587 | 51 + third-party/curl/tests/data/test1588 | 106 + third-party/curl/tests/data/test1589 | 108 + third-party/curl/tests/data/test159 | 26 +- third-party/curl/tests/data/test1590 | 14 +- third-party/curl/tests/data/test1591 | 7 +- third-party/curl/tests/data/test1592 | 16 +- third-party/curl/tests/data/test1593 | 3 +- third-party/curl/tests/data/test1594 | 3 +- third-party/curl/tests/data/test1595 | 3 +- third-party/curl/tests/data/test1596 | 12 +- third-party/curl/tests/data/test1597 | 7 +- third-party/curl/tests/data/test1598 | 60 + third-party/curl/tests/data/test1599 | 43 + third-party/curl/tests/data/test16 | 15 +- third-party/curl/tests/data/test160 | 15 +- third-party/curl/tests/data/test1600 | 9 +- third-party/curl/tests/data/test1601 | 9 +- third-party/curl/tests/data/test1602 | 9 +- third-party/curl/tests/data/test1603 | 9 +- third-party/curl/tests/data/test1604 | 14 +- third-party/curl/tests/data/test1605 | 9 +- third-party/curl/tests/data/test1606 | 9 +- third-party/curl/tests/data/test1607 | 9 +- third-party/curl/tests/data/test1608 | 9 +- third-party/curl/tests/data/test1609 | 22 - third-party/curl/tests/data/test161 | 14 +- third-party/curl/tests/data/test1610 | 9 +- third-party/curl/tests/data/test1611 | 9 +- third-party/curl/tests/data/test1612 | 9 +- third-party/curl/tests/data/test1613 | 7 +- third-party/curl/tests/data/test1614 | 10 +- third-party/curl/tests/data/test1615 | 20 + third-party/curl/tests/data/test1616 | 19 + third-party/curl/tests/data/test1617 | 73 + third-party/curl/tests/data/test1618 | 68 + third-party/curl/tests/data/test1619 | 45 + third-party/curl/tests/data/test162 | 18 +- third-party/curl/tests/data/test1620 | 9 +- third-party/curl/tests/data/test1621 | 13 +- third-party/curl/tests/data/test1622 | 160 + third-party/curl/tests/data/test1623 | 25 + third-party/curl/tests/data/test1624 | 57 + third-party/curl/tests/data/test1625 | 25 + third-party/curl/tests/data/test1626 | 25 + third-party/curl/tests/data/test1627 | 24 + third-party/curl/tests/data/test1628 | 53 + third-party/curl/tests/data/test1629 | 54 + third-party/curl/tests/data/test163 | 45 +- third-party/curl/tests/data/test1630 | 19 +- third-party/curl/tests/data/test1631 | 27 +- third-party/curl/tests/data/test1632 | 29 +- third-party/curl/tests/data/test1633 | 6 +- third-party/curl/tests/data/test1634 | 8 +- third-party/curl/tests/data/test1635 | 8 +- third-party/curl/tests/data/test1636 | 161 + third-party/curl/tests/data/test1637 | 58 + third-party/curl/tests/data/test1638 | 79 + third-party/curl/tests/data/test1639 | 65 + third-party/curl/tests/data/test164 | 49 +- third-party/curl/tests/data/test1640 | 51 + third-party/curl/tests/data/test1641 | 62 + third-party/curl/tests/data/test1642 | 61 + third-party/curl/tests/data/test1643 | 71 + third-party/curl/tests/data/test1644 | 65 + third-party/curl/tests/data/test1645 | 74 + third-party/curl/tests/data/test1646 | 46 + third-party/curl/tests/data/test1647 | 103 + third-party/curl/tests/data/test1648 | 63 + third-party/curl/tests/data/test1649 | 55 + third-party/curl/tests/data/test165 | 27 +- third-party/curl/tests/data/test1650 | 11 +- third-party/curl/tests/data/test1651 | 16 +- third-party/curl/tests/data/test1652 | 5 +- third-party/curl/tests/data/test1653 | 4 +- third-party/curl/tests/data/test1654 | 28 +- third-party/curl/tests/data/test1655 | 13 +- third-party/curl/tests/data/test1656 | 19 + third-party/curl/tests/data/test1657 | 19 + third-party/curl/tests/data/test1658 | 27 + third-party/curl/tests/data/test1659 | 27 + third-party/curl/tests/data/test166 | 33 +- third-party/curl/tests/data/test1660 | 6 +- third-party/curl/tests/data/test1661 | 9 +- third-party/curl/tests/data/test1662 | 6 +- third-party/curl/tests/data/test1663 | 20 + third-party/curl/tests/data/test1664 | 242 + third-party/curl/tests/data/test1665 | 51 + third-party/curl/tests/data/test1666 | 20 + third-party/curl/tests/data/test1667 | 20 + third-party/curl/tests/data/test1668 | 21 + third-party/curl/tests/data/test1669 | 37 + third-party/curl/tests/data/test167 | 24 +- third-party/curl/tests/data/test1670 | 6 +- third-party/curl/tests/data/test1671 | 6 +- third-party/curl/tests/data/test1672 | 55 + third-party/curl/tests/data/test1673 | 25 + third-party/curl/tests/data/test1674 | 38 + third-party/curl/tests/data/test1675 | 18 + third-party/curl/tests/data/test1676 | 21 + third-party/curl/tests/data/test1677 | 77 + third-party/curl/tests/data/test168 | 22 +- third-party/curl/tests/data/test1680 | 4 +- third-party/curl/tests/data/test1681 | 4 +- third-party/curl/tests/data/test1682 | 4 +- third-party/curl/tests/data/test1683 | 14 +- third-party/curl/tests/data/test1684 | 46 + third-party/curl/tests/data/test1685 | 57 + third-party/curl/tests/data/test1686 | 84 + third-party/curl/tests/data/test169 | 20 +- third-party/curl/tests/data/test17 | 18 +- third-party/curl/tests/data/test170 | 11 +- third-party/curl/tests/data/test1700 | 23 +- third-party/curl/tests/data/test1701 | 19 +- third-party/curl/tests/data/test1702 | 19 +- third-party/curl/tests/data/test1703 | 3 +- third-party/curl/tests/data/test1704 | 64 + third-party/curl/tests/data/test1705 | 57 + third-party/curl/tests/data/test1706 | 58 + third-party/curl/tests/data/test1707 | 24 + third-party/curl/tests/data/test1708 | 24 + third-party/curl/tests/data/test1709 | 29 + third-party/curl/tests/data/test171 | 11 +- third-party/curl/tests/data/test1710 | 24 + third-party/curl/tests/data/test1711 | 49 + third-party/curl/tests/data/test1712 | 61 + third-party/curl/tests/data/test1713 | 36 + third-party/curl/tests/data/test1714 | 56 + third-party/curl/tests/data/test1715 | 54 + third-party/curl/tests/data/test172 | 11 +- third-party/curl/tests/data/test1720 | 24 + third-party/curl/tests/data/test1721 | 45 + third-party/curl/tests/data/test1722 | 61 + third-party/curl/tests/data/test1723 | 61 + third-party/curl/tests/data/test1724 | 53 + third-party/curl/tests/data/test1725 | 29 + third-party/curl/tests/data/test173 | 43 +- third-party/curl/tests/data/test174 | 14 +- third-party/curl/tests/data/test175 | 21 +- third-party/curl/tests/data/test176 | 21 +- third-party/curl/tests/data/test177 | 13 +- third-party/curl/tests/data/test178 | 23 +- third-party/curl/tests/data/test179 | 9 +- third-party/curl/tests/data/test18 | 17 +- third-party/curl/tests/data/test180 | 9 +- third-party/curl/tests/data/test1800 | 13 +- third-party/curl/tests/data/test1801 | 9 +- third-party/curl/tests/data/test1802 | 62 + third-party/curl/tests/data/test181 | 9 +- third-party/curl/tests/data/test182 | 3 +- third-party/curl/tests/data/test183 | 11 +- third-party/curl/tests/data/test184 | 15 +- third-party/curl/tests/data/test1847 | 58 + third-party/curl/tests/data/test1848 | 51 + third-party/curl/tests/data/test1849 | 89 + third-party/curl/tests/data/test185 | 15 +- third-party/curl/tests/data/test1850 | 39 + third-party/curl/tests/data/test1851 | 55 + third-party/curl/tests/data/test186 | 15 +- third-party/curl/tests/data/test187 | 11 +- third-party/curl/tests/data/test188 | 13 +- third-party/curl/tests/data/test189 | 15 +- third-party/curl/tests/data/test19 | 15 +- third-party/curl/tests/data/test190 | 12 +- third-party/curl/tests/data/test1900 | 36 + third-party/curl/tests/data/test1901 | 61 + third-party/curl/tests/data/test1902 | 44 + third-party/curl/tests/data/test1903 | 20 +- third-party/curl/tests/data/test1904 | 20 +- third-party/curl/tests/data/test1905 | 11 +- third-party/curl/tests/data/test1906 | 7 +- third-party/curl/tests/data/test1907 | 7 +- third-party/curl/tests/data/test1908 | 9 +- third-party/curl/tests/data/test1909 | 12 +- third-party/curl/tests/data/test191 | 9 +- third-party/curl/tests/data/test1910 | 7 +- third-party/curl/tests/data/test1911 | 4 +- third-party/curl/tests/data/test1912 | 4 +- third-party/curl/tests/data/test1913 | 3 +- third-party/curl/tests/data/test1914 | 3 +- third-party/curl/tests/data/test1915 | 13 +- third-party/curl/tests/data/test1916 | 8 +- third-party/curl/tests/data/test1917 | 12 +- third-party/curl/tests/data/test1918 | 4 +- third-party/curl/tests/data/test1919 | 5 +- third-party/curl/tests/data/test192 | 12 +- third-party/curl/tests/data/test1920 | 65 + third-party/curl/tests/data/test1921 | 30 + third-party/curl/tests/data/test1922 | 91 + third-party/curl/tests/data/test193 | 12 +- third-party/curl/tests/data/test1933 | 10 +- third-party/curl/tests/data/test1934 | 10 +- third-party/curl/tests/data/test1935 | 10 +- third-party/curl/tests/data/test1936 | 10 +- third-party/curl/tests/data/test1937 | 10 +- third-party/curl/tests/data/test1938 | Bin 1308 -> 1377 bytes third-party/curl/tests/data/test1939 | 1 + third-party/curl/tests/data/test194 | 16 +- third-party/curl/tests/data/test1940 | 13 +- third-party/curl/tests/data/test1941 | 14 +- third-party/curl/tests/data/test1942 | 3 +- third-party/curl/tests/data/test1943 | 31 +- third-party/curl/tests/data/test1944 | 3 +- third-party/curl/tests/data/test1945 | 7 +- third-party/curl/tests/data/test1946 | 5 +- third-party/curl/tests/data/test1947 | 3 +- third-party/curl/tests/data/test1948 | 9 +- third-party/curl/tests/data/test195 | 9 +- third-party/curl/tests/data/test1955 | 15 +- third-party/curl/tests/data/test1956 | 13 +- third-party/curl/tests/data/test1957 | 13 +- third-party/curl/tests/data/test1958 | 16 +- third-party/curl/tests/data/test1959 | 13 +- third-party/curl/tests/data/test196 | 14 +- third-party/curl/tests/data/test1960 | 7 +- third-party/curl/tests/data/test1964 | 9 +- third-party/curl/tests/data/test1965 | 44 + third-party/curl/tests/data/test1966 | 118 + third-party/curl/tests/data/test1967 | 30 + third-party/curl/tests/data/test197 | 12 +- third-party/curl/tests/data/test1970 | 13 +- third-party/curl/tests/data/test1971 | 13 +- third-party/curl/tests/data/test1972 | 18 +- third-party/curl/tests/data/test1973 | 13 +- third-party/curl/tests/data/test1974 | 13 +- third-party/curl/tests/data/test1975 | 13 +- third-party/curl/tests/data/test1976 | 63 + third-party/curl/tests/data/test1977 | 63 + third-party/curl/tests/data/test1978 | 75 + third-party/curl/tests/data/test1979 | 20 + third-party/curl/tests/data/test198 | 12 +- third-party/curl/tests/data/test1980 | 20 + third-party/curl/tests/data/test1981 | 61 + third-party/curl/tests/data/test1982 | 53 + third-party/curl/tests/data/test1983 | 71 + third-party/curl/tests/data/test1984 | 76 + third-party/curl/tests/data/test199 | 18 +- third-party/curl/tests/data/test2 | 20 +- third-party/curl/tests/data/test20 | 15 +- third-party/curl/tests/data/test200 | 5 +- third-party/curl/tests/data/test2000 | 10 +- third-party/curl/tests/data/test2001 | 12 +- third-party/curl/tests/data/test2002 | 36 +- third-party/curl/tests/data/test2003 | 63 +- third-party/curl/tests/data/test2004 | 22 +- third-party/curl/tests/data/test2005 | 53 + third-party/curl/tests/data/test2006 | 98 + third-party/curl/tests/data/test2007 | 32 + third-party/curl/tests/data/test2008 | 50 + third-party/curl/tests/data/test2009 | 70 + third-party/curl/tests/data/test201 | 10 +- third-party/curl/tests/data/test2010 | 71 + third-party/curl/tests/data/test2011 | 70 + third-party/curl/tests/data/test2012 | 90 + third-party/curl/tests/data/test2013 | 85 + third-party/curl/tests/data/test2014 | 97 + third-party/curl/tests/data/test2015 | 92 + third-party/curl/tests/data/test202 | 5 +- third-party/curl/tests/data/test2023 | 42 +- third-party/curl/tests/data/test2024 | 39 +- third-party/curl/tests/data/test2025 | 41 +- third-party/curl/tests/data/test2026 | 45 +- third-party/curl/tests/data/test2027 | 51 +- third-party/curl/tests/data/test2028 | 42 +- third-party/curl/tests/data/test2029 | 37 +- third-party/curl/tests/data/test203 | 5 +- third-party/curl/tests/data/test2030 | 49 +- third-party/curl/tests/data/test2031 | 47 +- third-party/curl/tests/data/test2032 | 22 +- third-party/curl/tests/data/test2033 | 27 +- third-party/curl/tests/data/test2034 | 21 +- third-party/curl/tests/data/test2035 | 19 +- third-party/curl/tests/data/test2036 | 28 +- third-party/curl/tests/data/test2037 | 21 +- third-party/curl/tests/data/test2038 | 19 +- third-party/curl/tests/data/test2039 | 18 +- third-party/curl/tests/data/test204 | 5 +- third-party/curl/tests/data/test2040 | 5 +- third-party/curl/tests/data/test2041 | 21 +- third-party/curl/tests/data/test2042 | 19 +- third-party/curl/tests/data/test2043 | 12 +- third-party/curl/tests/data/test2044 | 9 +- third-party/curl/tests/data/test2045 | 28 +- third-party/curl/tests/data/test2046 | 27 +- third-party/curl/tests/data/test2047 | 27 +- third-party/curl/tests/data/test2048 | 8 +- third-party/curl/tests/data/test2049 | 17 +- third-party/curl/tests/data/test205 | 10 +- third-party/curl/tests/data/test2050 | 25 +- third-party/curl/tests/data/test2051 | 18 +- third-party/curl/tests/data/test2052 | 20 +- third-party/curl/tests/data/test2053 | 17 +- third-party/curl/tests/data/test2054 | 28 +- third-party/curl/tests/data/test2055 | 25 +- third-party/curl/tests/data/test2056 | 9 +- third-party/curl/tests/data/test2057 | 13 +- third-party/curl/tests/data/test2058 | 23 +- third-party/curl/tests/data/test2059 | 23 +- third-party/curl/tests/data/test206 | 31 +- third-party/curl/tests/data/test2060 | 25 +- third-party/curl/tests/data/test2061 | 16 +- third-party/curl/tests/data/test2062 | 18 +- third-party/curl/tests/data/test2063 | 16 +- third-party/curl/tests/data/test2064 | 16 +- third-party/curl/tests/data/test2065 | 20 +- third-party/curl/tests/data/test2066 | 18 +- third-party/curl/tests/data/test2067 | 15 +- third-party/curl/tests/data/test2068 | 19 +- third-party/curl/tests/data/test2069 | 17 +- third-party/curl/tests/data/test207 | 22 +- third-party/curl/tests/data/test2070 | 27 +- third-party/curl/tests/data/test2071 | 5 +- third-party/curl/tests/data/test2072 | 7 +- third-party/curl/tests/data/test2073 | 16 +- third-party/curl/tests/data/test2074 | 14 +- third-party/curl/tests/data/test2075 | 6 +- third-party/curl/tests/data/test2076 | 10 +- third-party/curl/tests/data/test2077 | 3 +- third-party/curl/tests/data/test2078 | 5 +- third-party/curl/tests/data/test2079 | 27 +- third-party/curl/tests/data/test208 | 25 +- third-party/curl/tests/data/test2080 | Bin 20683 -> 518 bytes third-party/curl/tests/data/test2081 | 19 +- third-party/curl/tests/data/test2082 | 3 +- third-party/curl/tests/data/test2083 | 3 +- third-party/curl/tests/data/test2084 | 3 +- third-party/curl/tests/data/test2085 | 3 +- third-party/curl/tests/data/test2086 | 11 +- third-party/curl/tests/data/test2087 | 27 +- third-party/curl/tests/data/test2088 | 51 + third-party/curl/tests/data/test2089 | 51 + third-party/curl/tests/data/test209 | 29 +- third-party/curl/tests/data/test2090 | 59 + third-party/curl/tests/data/test2091 | 98 + third-party/curl/tests/data/test2092 | 28 + third-party/curl/tests/data/test21 | 8 +- third-party/curl/tests/data/test210 | 7 +- third-party/curl/tests/data/test2100 | 47 +- third-party/curl/tests/data/test2101 | 48 + third-party/curl/tests/data/test2102 | 62 + third-party/curl/tests/data/test2103 | 43 + third-party/curl/tests/data/test2104 | 47 + third-party/curl/tests/data/test2105 | 49 + third-party/curl/tests/data/test2106 | 53 + third-party/curl/tests/data/test2107 | 49 + third-party/curl/tests/data/test2108 | 41 + third-party/curl/tests/data/test211 | 9 +- third-party/curl/tests/data/test212 | 15 +- third-party/curl/tests/data/test213 | 29 +- third-party/curl/tests/data/test214 | 10 +- third-party/curl/tests/data/test215 | 15 +- third-party/curl/tests/data/test216 | 9 +- third-party/curl/tests/data/test217 | 17 +- third-party/curl/tests/data/test218 | 42 +- third-party/curl/tests/data/test219 | 14 +- third-party/curl/tests/data/test22 | 15 +- third-party/curl/tests/data/test220 | 37 +- third-party/curl/tests/data/test2200 | 10 +- third-party/curl/tests/data/test2201 | 5 +- third-party/curl/tests/data/test2202 | 6 +- third-party/curl/tests/data/test2203 | 10 +- third-party/curl/tests/data/test2204 | 8 +- third-party/curl/tests/data/test2205 | 13 +- third-party/curl/tests/data/test2206 | 59 + third-party/curl/tests/data/test2207 | 59 + third-party/curl/tests/data/test2208 | 90 + third-party/curl/tests/data/test221 | 33 +- third-party/curl/tests/data/test222 | 173 +- third-party/curl/tests/data/test223 | 57 +- third-party/curl/tests/data/test224 | 69 +- third-party/curl/tests/data/test225 | 8 +- third-party/curl/tests/data/test226 | 8 +- third-party/curl/tests/data/test227 | 9 +- third-party/curl/tests/data/test228 | 10 +- third-party/curl/tests/data/test229 | 10 +- third-party/curl/tests/data/test23 | 10 +- third-party/curl/tests/data/test230 | 174 +- third-party/curl/tests/data/test2300 | 25 +- third-party/curl/tests/data/test2301 | 17 +- third-party/curl/tests/data/test2302 | 27 +- third-party/curl/tests/data/test2303 | 19 +- third-party/curl/tests/data/test2304 | 25 +- third-party/curl/tests/data/test2305 | 59 - third-party/curl/tests/data/test2306 | 15 +- third-party/curl/tests/data/test2307 | 58 + third-party/curl/tests/data/test2308 | 56 + third-party/curl/tests/data/test2309 | 65 + third-party/curl/tests/data/test231 | 5 +- third-party/curl/tests/data/test2310 | 50 + third-party/curl/tests/data/test2311 | 58 + third-party/curl/tests/data/test232 | 173 +- third-party/curl/tests/data/test233 | 18 +- third-party/curl/tests/data/test234 | 22 +- third-party/curl/tests/data/test235 | 14 +- third-party/curl/tests/data/test236 | 9 +- third-party/curl/tests/data/test237 | 11 +- third-party/curl/tests/data/test238 | 11 +- third-party/curl/tests/data/test239 | 11 +- third-party/curl/tests/data/test24 | 11 +- third-party/curl/tests/data/test240 | 14 +- third-party/curl/tests/data/test2400 | 24 +- third-party/curl/tests/data/test2401 | 29 +- third-party/curl/tests/data/test2402 | 35 +- third-party/curl/tests/data/test2403 | 23 +- third-party/curl/tests/data/test2404 | 33 +- third-party/curl/tests/data/test2405 | 52 + third-party/curl/tests/data/test2406 | 63 + third-party/curl/tests/data/test2407 | 53 + third-party/curl/tests/data/test2408 | 92 + third-party/curl/tests/data/test2409 | 92 + third-party/curl/tests/data/test241 | 16 +- third-party/curl/tests/data/test2410 | 34 + third-party/curl/tests/data/test2411 | 37 + third-party/curl/tests/data/test2412 | 50 + third-party/curl/tests/data/test2413 | 19 + third-party/curl/tests/data/test242 | 16 +- third-party/curl/tests/data/test243 | 13 +- third-party/curl/tests/data/test244 | 10 +- third-party/curl/tests/data/test245 | 21 +- third-party/curl/tests/data/test246 | 21 +- third-party/curl/tests/data/test247 | 12 +- third-party/curl/tests/data/test248 | 11 +- third-party/curl/tests/data/test249 | 12 +- third-party/curl/tests/data/test25 | 9 +- third-party/curl/tests/data/test250 | 16 +- third-party/curl/tests/data/test2500 | 26 +- third-party/curl/tests/data/test2501 | 26 +- third-party/curl/tests/data/test2502 | 34 +- third-party/curl/tests/data/test2503 | 23 +- third-party/curl/tests/data/test2504 | 55 + third-party/curl/tests/data/test2505 | 67 + third-party/curl/tests/data/test2506 | 64 + third-party/curl/tests/data/test251 | 15 +- third-party/curl/tests/data/test252 | 20 +- third-party/curl/tests/data/test253 | 24 +- third-party/curl/tests/data/test254 | 20 +- third-party/curl/tests/data/test255 | 22 +- third-party/curl/tests/data/test256 | 12 +- third-party/curl/tests/data/test257 | 13 +- third-party/curl/tests/data/test258 | 112 +- third-party/curl/tests/data/test259 | 116 +- third-party/curl/tests/data/test26 | 9 +- third-party/curl/tests/data/test260 | 14 +- third-party/curl/tests/data/test2600 | 13 +- third-party/curl/tests/data/test2601 | 14 +- third-party/curl/tests/data/test2602 | 9 +- third-party/curl/tests/data/test2603 | 9 +- third-party/curl/tests/data/test2604 | 19 + third-party/curl/tests/data/test2605 | 20 + third-party/curl/tests/data/test261 | 12 +- third-party/curl/tests/data/test262 | Bin 1228 -> 850 bytes third-party/curl/tests/data/test263 | 14 +- third-party/curl/tests/data/test264 | 13 +- third-party/curl/tests/data/test265 | 33 +- third-party/curl/tests/data/test266 | 58 +- third-party/curl/tests/data/test267 | 11 +- third-party/curl/tests/data/test268 | 57 + third-party/curl/tests/data/test269 | 15 +- third-party/curl/tests/data/test27 | 9 +- third-party/curl/tests/data/test270 | 9 +- third-party/curl/tests/data/test2700 | 77 + third-party/curl/tests/data/test2701 | 73 + third-party/curl/tests/data/test2702 | 73 + third-party/curl/tests/data/test2703 | 73 + third-party/curl/tests/data/test2704 | 73 + third-party/curl/tests/data/test2705 | 73 + third-party/curl/tests/data/test2706 | 73 + third-party/curl/tests/data/test2707 | 85 + third-party/curl/tests/data/test2708 | 75 + third-party/curl/tests/data/test2709 | 74 + third-party/curl/tests/data/test271 | 10 +- third-party/curl/tests/data/test2710 | 74 + third-party/curl/tests/data/test2711 | 75 + third-party/curl/tests/data/test2712 | 75 + third-party/curl/tests/data/test2713 | 73 + third-party/curl/tests/data/test2714 | 73 + third-party/curl/tests/data/test2715 | 73 + third-party/curl/tests/data/test2716 | 73 + third-party/curl/tests/data/test2717 | 73 + third-party/curl/tests/data/test2718 | 73 + third-party/curl/tests/data/test2719 | 82 + third-party/curl/tests/data/test272 | 9 +- third-party/curl/tests/data/test2720 | 87 + third-party/curl/tests/data/test2721 | 78 + third-party/curl/tests/data/test2722 | 74 + third-party/curl/tests/data/test2723 | 75 + third-party/curl/tests/data/test273 | 16 +- third-party/curl/tests/data/test274 | 9 +- third-party/curl/tests/data/test275 | 28 +- third-party/curl/tests/data/test276 | 9 +- third-party/curl/tests/data/test277 | 15 +- third-party/curl/tests/data/test278 | 13 +- third-party/curl/tests/data/test279 | 13 +- third-party/curl/tests/data/test28 | 13 +- third-party/curl/tests/data/test280 | 20 +- third-party/curl/tests/data/test281 | 9 +- third-party/curl/tests/data/test282 | 12 +- third-party/curl/tests/data/test283 | 10 +- third-party/curl/tests/data/test284 | 14 +- third-party/curl/tests/data/test285 | 11 +- third-party/curl/tests/data/test286 | 15 +- third-party/curl/tests/data/test287 | 17 +- third-party/curl/tests/data/test288 | 8 +- third-party/curl/tests/data/test289 | 8 +- third-party/curl/tests/data/test29 | 15 +- third-party/curl/tests/data/test290 | 9 +- third-party/curl/tests/data/test291 | 9 +- third-party/curl/tests/data/test292 | 12 +- third-party/curl/tests/data/test293 | 13 +- third-party/curl/tests/data/test294 | 18 +- third-party/curl/tests/data/test295 | 13 +- third-party/curl/tests/data/test296 | 10 +- third-party/curl/tests/data/test297 | 10 +- third-party/curl/tests/data/test298 | 10 +- third-party/curl/tests/data/test299 | 11 +- third-party/curl/tests/data/test3 | 22 +- third-party/curl/tests/data/test30 | 10 +- third-party/curl/tests/data/test300 | 13 +- third-party/curl/tests/data/test3000 | 17 +- third-party/curl/tests/data/test3001 | 17 +- third-party/curl/tests/data/test3002 | 40 +- third-party/curl/tests/data/test3003 | 40 +- third-party/curl/tests/data/test3004 | 40 +- third-party/curl/tests/data/test3005 | 40 +- third-party/curl/tests/data/test3006 | 36 +- third-party/curl/tests/data/test3007 | 24 +- third-party/curl/tests/data/test3008 | 6 +- third-party/curl/tests/data/test3009 | 6 +- third-party/curl/tests/data/test301 | 16 +- third-party/curl/tests/data/test3010 | 1 + third-party/curl/tests/data/test3011 | 6 +- third-party/curl/tests/data/test3012 | 11 +- third-party/curl/tests/data/test3013 | 6 +- third-party/curl/tests/data/test3014 | 7 +- third-party/curl/tests/data/test3015 | 40 +- third-party/curl/tests/data/test3016 | 11 +- third-party/curl/tests/data/test3017 | 10 +- third-party/curl/tests/data/test3018 | 10 +- third-party/curl/tests/data/test3019 | 4 +- third-party/curl/tests/data/test302 | 15 +- third-party/curl/tests/data/test3020 | 4 +- third-party/curl/tests/data/test3021 | 22 +- third-party/curl/tests/data/test3022 | 22 +- third-party/curl/tests/data/test3023 | 19 +- third-party/curl/tests/data/test3024 | 19 +- third-party/curl/tests/data/test3025 | 7 +- third-party/curl/tests/data/test3026 | 10 +- third-party/curl/tests/data/test3027 | 7 +- third-party/curl/tests/data/test3028 | 8 +- third-party/curl/tests/data/test3029 | 6 +- third-party/curl/tests/data/test303 | 14 +- third-party/curl/tests/data/test3030 | 3 +- third-party/curl/tests/data/test3031 | 65 + third-party/curl/tests/data/test3032 | 113 + third-party/curl/tests/data/test3033 | 51 + third-party/curl/tests/data/test3034 | 41 + third-party/curl/tests/data/test3035 | 118 + third-party/curl/tests/data/test3036 | 62 + third-party/curl/tests/data/test304 | 55 +- third-party/curl/tests/data/test305 | 15 +- third-party/curl/tests/data/test306 | 17 +- third-party/curl/tests/data/test307 | 16 +- third-party/curl/tests/data/test308 | 12 +- third-party/curl/tests/data/test309 | 17 +- third-party/curl/tests/data/test31 | 208 +- third-party/curl/tests/data/test310 | 23 +- third-party/curl/tests/data/test3100 | 13 +- third-party/curl/tests/data/test3101 | 11 +- third-party/curl/tests/data/test3102 | 15 +- third-party/curl/tests/data/test3103 | 58 + third-party/curl/tests/data/test3104 | 58 + third-party/curl/tests/data/test3105 | 25 + third-party/curl/tests/data/test3106 | 77 + third-party/curl/tests/data/test311 | 19 +- third-party/curl/tests/data/test312 | 19 +- third-party/curl/tests/data/test313 | 20 +- third-party/curl/tests/data/test314 | 171 +- third-party/curl/tests/data/test315 | 53 +- third-party/curl/tests/data/test316 | 164 +- third-party/curl/tests/data/test317 | 16 +- third-party/curl/tests/data/test318 | 18 +- third-party/curl/tests/data/test319 | 45 +- third-party/curl/tests/data/test32 | 16 +- third-party/curl/tests/data/test320 | 39 +- third-party/curl/tests/data/test3200 | 9 +- third-party/curl/tests/data/test3201 | 10 +- third-party/curl/tests/data/test3202 | 18 +- third-party/curl/tests/data/test3203 | 38 + third-party/curl/tests/data/test3204 | 51 + third-party/curl/tests/data/test3205 | 19 + third-party/curl/tests/data/test3206 | 47 + third-party/curl/tests/data/test3207 | 52 + third-party/curl/tests/data/test3208 | 63 + third-party/curl/tests/data/test3209 | 60 + third-party/curl/tests/data/test321 | 6 +- third-party/curl/tests/data/test3210 | 60 + third-party/curl/tests/data/test3211 | 19 + third-party/curl/tests/data/test3212 | 19 + third-party/curl/tests/data/test3213 | 19 + third-party/curl/tests/data/test3214 | 19 + third-party/curl/tests/data/test3215 | 54 + third-party/curl/tests/data/test3216 | 19 + third-party/curl/tests/data/test3217 | 41 + third-party/curl/tests/data/test3218 | 41 + third-party/curl/tests/data/test3219 | 19 + third-party/curl/tests/data/test322 | 6 +- third-party/curl/tests/data/test3220 | 61 + third-party/curl/tests/data/test3221 | 74 + third-party/curl/tests/data/test3222 | 57 + third-party/curl/tests/data/test323 | 6 +- third-party/curl/tests/data/test324 | 6 +- third-party/curl/tests/data/test325 | 14 +- third-party/curl/tests/data/test326 | 45 +- third-party/curl/tests/data/test327 | 9 +- third-party/curl/tests/data/test328 | 11 +- third-party/curl/tests/data/test329 | 13 +- third-party/curl/tests/data/test33 | 9 +- third-party/curl/tests/data/test330 | 12 +- third-party/curl/tests/data/test3300 | 19 + third-party/curl/tests/data/test3301 | 19 + third-party/curl/tests/data/test3302 | 19 + third-party/curl/tests/data/test3303 | 20 + third-party/curl/tests/data/test3304 | 20 + third-party/curl/tests/data/test3305 | 84 + third-party/curl/tests/data/test331 | 11 +- third-party/curl/tests/data/test332 | 10 +- third-party/curl/tests/data/test333 | 15 +- third-party/curl/tests/data/test334 | 3 +- third-party/curl/tests/data/test335 | 14 +- third-party/curl/tests/data/test336 | 11 +- third-party/curl/tests/data/test337 | 9 +- third-party/curl/tests/data/test338 | 12 +- third-party/curl/tests/data/test339 | 38 +- third-party/curl/tests/data/test34 | 28 +- third-party/curl/tests/data/test340 | 10 +- third-party/curl/tests/data/test3400 | 19 + third-party/curl/tests/data/test3401 | 55 + third-party/curl/tests/data/test341 | 31 +- third-party/curl/tests/data/test342 | 6 +- third-party/curl/tests/data/test343 | 6 +- third-party/curl/tests/data/test344 | 6 +- third-party/curl/tests/data/test345 | 6 +- third-party/curl/tests/data/test346 | 10 +- third-party/curl/tests/data/test347 | 38 +- third-party/curl/tests/data/test348 | 9 +- third-party/curl/tests/data/test349 | 11 +- third-party/curl/tests/data/test35 | Bin 849 -> 920 bytes third-party/curl/tests/data/test350 | 18 +- third-party/curl/tests/data/test351 | 18 +- third-party/curl/tests/data/test352 | 18 +- third-party/curl/tests/data/test353 | 18 +- third-party/curl/tests/data/test354 | 9 +- third-party/curl/tests/data/test355 | 22 +- third-party/curl/tests/data/test356 | 16 +- third-party/curl/tests/data/test357 | 18 +- third-party/curl/tests/data/test358 | 24 +- third-party/curl/tests/data/test359 | 22 +- third-party/curl/tests/data/test36 | 21 +- third-party/curl/tests/data/test360 | 33 +- third-party/curl/tests/data/test361 | 11 +- third-party/curl/tests/data/test362 | 9 +- third-party/curl/tests/data/test363 | 22 +- third-party/curl/tests/data/test364 | 11 +- third-party/curl/tests/data/test365 | 22 +- third-party/curl/tests/data/test366 | 12 +- third-party/curl/tests/data/test367 | 12 +- third-party/curl/tests/data/test368 | 12 +- third-party/curl/tests/data/test369 | 6 +- third-party/curl/tests/data/test37 | 13 +- third-party/curl/tests/data/test370 | 7 +- third-party/curl/tests/data/test371 | 12 +- third-party/curl/tests/data/test372 | 5 +- third-party/curl/tests/data/test373 | 41 +- third-party/curl/tests/data/test374 | 5 +- third-party/curl/tests/data/test375 | 5 +- third-party/curl/tests/data/test376 | 18 +- third-party/curl/tests/data/test378 | 15 +- third-party/curl/tests/data/test379 | 18 +- third-party/curl/tests/data/test38 | 10 +- third-party/curl/tests/data/test380 | 14 +- third-party/curl/tests/data/test381 | 13 +- third-party/curl/tests/data/test383 | 18 +- third-party/curl/tests/data/test384 | 16 +- third-party/curl/tests/data/test385 | 18 +- third-party/curl/tests/data/test386 | 18 +- third-party/curl/tests/data/test387 | 12 +- third-party/curl/tests/data/test388 | 27 +- third-party/curl/tests/data/test389 | 22 +- third-party/curl/tests/data/test39 | 107 +- third-party/curl/tests/data/test390 | 5 +- third-party/curl/tests/data/test391 | 14 +- third-party/curl/tests/data/test392 | 17 +- third-party/curl/tests/data/test393 | 17 +- third-party/curl/tests/data/test394 | 17 +- third-party/curl/tests/data/test395 | 19 +- third-party/curl/tests/data/test396 | 172 +- third-party/curl/tests/data/test397 | 165 +- third-party/curl/tests/data/test398 | 16 +- third-party/curl/tests/data/test399 | 5 +- third-party/curl/tests/data/test4 | 28 +- third-party/curl/tests/data/test40 | 28 +- third-party/curl/tests/data/test400 | 20 +- third-party/curl/tests/data/test4000 | 49 + third-party/curl/tests/data/test4001 | 44 + third-party/curl/tests/data/test401 | 11 +- third-party/curl/tests/data/test402 | 12 +- third-party/curl/tests/data/test403 | 21 +- third-party/curl/tests/data/test404 | 15 +- third-party/curl/tests/data/test405 | 10 +- third-party/curl/tests/data/test406 | 20 +- third-party/curl/tests/data/test407 | 11 +- third-party/curl/tests/data/test408 | 11 +- third-party/curl/tests/data/test409 | 57 - third-party/curl/tests/data/test41 | 8 +- third-party/curl/tests/data/test410 | 16 +- third-party/curl/tests/data/test411 | 13 +- third-party/curl/tests/data/test412 | 18 +- third-party/curl/tests/data/test413 | 18 +- third-party/curl/tests/data/test414 | 8 +- third-party/curl/tests/data/test415 | 32 +- third-party/curl/tests/data/test416 | 9 +- third-party/curl/tests/data/test417 | 34 +- third-party/curl/tests/data/test418 | 10 +- third-party/curl/tests/data/test419 | 11 +- third-party/curl/tests/data/test42 | 26 +- third-party/curl/tests/data/test420 | 22 +- third-party/curl/tests/data/test421 | 12 +- third-party/curl/tests/data/test422 | 7 +- third-party/curl/tests/data/test423 | 12 +- third-party/curl/tests/data/test424 | 21 +- third-party/curl/tests/data/test425 | 14 +- third-party/curl/tests/data/test426 | 5 +- third-party/curl/tests/data/test427 | 10 +- third-party/curl/tests/data/test428 | 7 +- third-party/curl/tests/data/test429 | 12 +- third-party/curl/tests/data/test43 | 9 +- third-party/curl/tests/data/test430 | 12 +- third-party/curl/tests/data/test431 | 12 +- third-party/curl/tests/data/test432 | 12 +- third-party/curl/tests/data/test433 | 32 +- third-party/curl/tests/data/test434 | 6 +- third-party/curl/tests/data/test435 | 10 +- third-party/curl/tests/data/test436 | 13 +- third-party/curl/tests/data/test437 | 17 +- third-party/curl/tests/data/test438 | 20 +- third-party/curl/tests/data/test439 | 17 +- third-party/curl/tests/data/test44 | 49 +- third-party/curl/tests/data/test440 | 18 +- third-party/curl/tests/data/test441 | 14 +- third-party/curl/tests/data/test442 | 11 +- third-party/curl/tests/data/test443 | 50 +- third-party/curl/tests/data/test444 | 109 +- third-party/curl/tests/data/test445 | 18 +- third-party/curl/tests/data/test446 | 12 +- third-party/curl/tests/data/test447 | 8 +- third-party/curl/tests/data/test448 | 7 +- third-party/curl/tests/data/test449 | 7 +- third-party/curl/tests/data/test45 | 15 +- third-party/curl/tests/data/test450 | 7 +- third-party/curl/tests/data/test451 | 6 +- third-party/curl/tests/data/test452 | 4 +- third-party/curl/tests/data/test453 | 3 +- third-party/curl/tests/data/test454 | 4 +- third-party/curl/tests/data/test455 | 10 +- third-party/curl/tests/data/test456 | 3 +- third-party/curl/tests/data/test457 | 67 + third-party/curl/tests/data/test458 | 73 + third-party/curl/tests/data/test459 | 61 + third-party/curl/tests/data/test46 | 28 +- third-party/curl/tests/data/test460 | 25 + third-party/curl/tests/data/test461 | 46 + third-party/curl/tests/data/test462 | 34 + third-party/curl/tests/data/test463 | 51 + third-party/curl/tests/data/test467 | 27 + third-party/curl/tests/data/test468 | 58 + third-party/curl/tests/data/test469 | 50 + third-party/curl/tests/data/test47 | 12 +- third-party/curl/tests/data/test470 | 50 + third-party/curl/tests/data/test471 | 72 + third-party/curl/tests/data/test472 | 58 + third-party/curl/tests/data/test473 | 60 + third-party/curl/tests/data/test474 | 50 + third-party/curl/tests/data/test475 | 47 + third-party/curl/tests/data/test476 | 43 + third-party/curl/tests/data/test477 | 65 + third-party/curl/tests/data/test478 | 72 + third-party/curl/tests/data/test479 | 106 + third-party/curl/tests/data/test48 | 18 +- third-party/curl/tests/data/test480 | 37 + third-party/curl/tests/data/test481 | 47 + third-party/curl/tests/data/test482 | 43 + third-party/curl/tests/data/test483 | 64 + third-party/curl/tests/data/test484 | 39 + third-party/curl/tests/data/test485 | 39 + third-party/curl/tests/data/test486 | 104 + third-party/curl/tests/data/test487 | 50 + third-party/curl/tests/data/test488 | 61 + third-party/curl/tests/data/test489 | 61 + third-party/curl/tests/data/test49 | 12 +- third-party/curl/tests/data/test490 | 12 +- third-party/curl/tests/data/test491 | 12 +- third-party/curl/tests/data/test492 | 12 +- third-party/curl/tests/data/test493 | 12 +- third-party/curl/tests/data/test494 | 12 +- third-party/curl/tests/data/test495 | 8 +- third-party/curl/tests/data/test496 | 9 +- third-party/curl/tests/data/test497 | 17 +- third-party/curl/tests/data/test498 | 48 + third-party/curl/tests/data/test499 | 63 + third-party/curl/tests/data/test5 | 12 +- third-party/curl/tests/data/test50 | 12 +- third-party/curl/tests/data/test500 | 17 +- third-party/curl/tests/data/test501 | 13 +- third-party/curl/tests/data/test502 | 10 +- third-party/curl/tests/data/test503 | 21 +- third-party/curl/tests/data/test504 | 15 +- third-party/curl/tests/data/test505 | 10 +- third-party/curl/tests/data/test506 | 203 +- third-party/curl/tests/data/test507 | 4 +- third-party/curl/tests/data/test508 | 17 +- third-party/curl/tests/data/test509 | 9 +- third-party/curl/tests/data/test51 | 12 +- third-party/curl/tests/data/test510 | 17 +- third-party/curl/tests/data/test511 | 11 +- third-party/curl/tests/data/test512 | 13 +- third-party/curl/tests/data/test513 | 19 +- third-party/curl/tests/data/test514 | 14 +- third-party/curl/tests/data/test515 | 13 +- third-party/curl/tests/data/test516 | 13 +- third-party/curl/tests/data/test517 | 21 +- third-party/curl/tests/data/test518 | 18 +- third-party/curl/tests/data/test519 | 21 +- third-party/curl/tests/data/test52 | 12 +- third-party/curl/tests/data/test520 | 11 +- third-party/curl/tests/data/test521 | 18 +- third-party/curl/tests/data/test522 | 16 +- third-party/curl/tests/data/test523 | 16 +- third-party/curl/tests/data/test524 | 12 +- third-party/curl/tests/data/test525 | 9 +- third-party/curl/tests/data/test526 | 9 +- third-party/curl/tests/data/test527 | 13 +- third-party/curl/tests/data/test528 | 11 +- third-party/curl/tests/data/test529 | 11 +- third-party/curl/tests/data/test53 | 11 +- third-party/curl/tests/data/test530 | 3 +- third-party/curl/tests/data/test531 | 11 +- third-party/curl/tests/data/test532 | 11 +- third-party/curl/tests/data/test533 | 9 +- third-party/curl/tests/data/test534 | 9 +- third-party/curl/tests/data/test535 | 14 +- third-party/curl/tests/data/test536 | 73 + third-party/curl/tests/data/test537 | 18 +- third-party/curl/tests/data/test538 | 14 +- third-party/curl/tests/data/test539 | 35 +- third-party/curl/tests/data/test54 | 11 +- third-party/curl/tests/data/test540 | 18 +- third-party/curl/tests/data/test541 | 10 +- third-party/curl/tests/data/test542 | 14 +- third-party/curl/tests/data/test543 | 15 +- third-party/curl/tests/data/test544 | 13 +- third-party/curl/tests/data/test545 | Bin 822 -> 848 bytes third-party/curl/tests/data/test546 | 9 +- third-party/curl/tests/data/test547 | 13 +- third-party/curl/tests/data/test548 | 15 +- third-party/curl/tests/data/test549 | 14 +- third-party/curl/tests/data/test55 | 9 +- third-party/curl/tests/data/test550 | 14 +- third-party/curl/tests/data/test551 | 22 +- third-party/curl/tests/data/test552 | 44 +- third-party/curl/tests/data/test553 | 11 +- third-party/curl/tests/data/test554 | 133 +- third-party/curl/tests/data/test555 | 15 +- third-party/curl/tests/data/test556 | 13 +- third-party/curl/tests/data/test557 | 10 +- third-party/curl/tests/data/test558 | 13 +- third-party/curl/tests/data/test559 | 7 +- third-party/curl/tests/data/test56 | 21 +- third-party/curl/tests/data/test560 | 14 +- third-party/curl/tests/data/test561 | 14 +- third-party/curl/tests/data/test562 | 14 +- third-party/curl/tests/data/test563 | 13 +- third-party/curl/tests/data/test564 | 7 +- third-party/curl/tests/data/test565 | 24 +- third-party/curl/tests/data/test566 | 13 +- third-party/curl/tests/data/test567 | 8 +- third-party/curl/tests/data/test568 | 33 +- third-party/curl/tests/data/test569 | 5 +- third-party/curl/tests/data/test57 | 11 +- third-party/curl/tests/data/test570 | 11 +- third-party/curl/tests/data/test571 | 17 +- third-party/curl/tests/data/test572 | 15 +- third-party/curl/tests/data/test573 | 12 +- third-party/curl/tests/data/test574 | 12 +- third-party/curl/tests/data/test575 | 15 +- third-party/curl/tests/data/test576 | 9 +- third-party/curl/tests/data/test577 | 7 +- third-party/curl/tests/data/test578 | 11 +- third-party/curl/tests/data/test579 | 28 +- third-party/curl/tests/data/test58 | 7 +- third-party/curl/tests/data/test580 | 22 +- third-party/curl/tests/data/test581 | 11 +- third-party/curl/tests/data/test582 | 16 +- third-party/curl/tests/data/test583 | 20 +- third-party/curl/tests/data/test584 | 23 +- third-party/curl/tests/data/test585 | 27 +- third-party/curl/tests/data/test586 | 14 +- third-party/curl/tests/data/test587 | 28 +- third-party/curl/tests/data/test588 | 19 +- third-party/curl/tests/data/test589 | 13 +- third-party/curl/tests/data/test59 | 14 +- third-party/curl/tests/data/test590 | 13 +- third-party/curl/tests/data/test591 | 15 +- third-party/curl/tests/data/test592 | 15 +- third-party/curl/tests/data/test593 | 15 +- third-party/curl/tests/data/test594 | 16 +- third-party/curl/tests/data/test595 | 15 +- third-party/curl/tests/data/test596 | 17 +- third-party/curl/tests/data/test597 | 8 +- third-party/curl/tests/data/test598 | 15 +- third-party/curl/tests/data/test599 | 35 +- third-party/curl/tests/data/test6 | 11 +- third-party/curl/tests/data/test60 | 31 +- third-party/curl/tests/data/test600 | 15 +- third-party/curl/tests/data/test601 | 15 +- third-party/curl/tests/data/test602 | 15 +- third-party/curl/tests/data/test603 | 15 +- third-party/curl/tests/data/test604 | 15 +- third-party/curl/tests/data/test605 | 15 +- third-party/curl/tests/data/test606 | 15 +- third-party/curl/tests/data/test607 | 15 +- third-party/curl/tests/data/test608 | 23 +- third-party/curl/tests/data/test609 | 16 +- third-party/curl/tests/data/test61 | 20 +- third-party/curl/tests/data/test610 | 23 +- third-party/curl/tests/data/test611 | 25 +- third-party/curl/tests/data/test612 | 24 +- third-party/curl/tests/data/test613 | 28 +- third-party/curl/tests/data/test614 | 28 +- third-party/curl/tests/data/test615 | 23 +- third-party/curl/tests/data/test616 | 15 +- third-party/curl/tests/data/test617 | 15 +- third-party/curl/tests/data/test618 | 16 +- third-party/curl/tests/data/test619 | 16 +- third-party/curl/tests/data/test62 | 16 +- third-party/curl/tests/data/test620 | 15 +- third-party/curl/tests/data/test621 | 15 +- third-party/curl/tests/data/test622 | 16 +- third-party/curl/tests/data/test623 | 16 +- third-party/curl/tests/data/test624 | 21 +- third-party/curl/tests/data/test625 | 24 +- third-party/curl/tests/data/test626 | 16 +- third-party/curl/tests/data/test627 | 23 +- third-party/curl/tests/data/test628 | 15 +- third-party/curl/tests/data/test629 | 15 +- third-party/curl/tests/data/test63 | 14 +- third-party/curl/tests/data/test630 | 15 +- third-party/curl/tests/data/test631 | 15 +- third-party/curl/tests/data/test632 | 15 +- third-party/curl/tests/data/test633 | 15 +- third-party/curl/tests/data/test634 | 15 +- third-party/curl/tests/data/test635 | 15 +- third-party/curl/tests/data/test636 | 15 +- third-party/curl/tests/data/test637 | 17 +- third-party/curl/tests/data/test638 | 23 +- third-party/curl/tests/data/test639 | 25 +- third-party/curl/tests/data/test64 | 24 +- third-party/curl/tests/data/test640 | 15 +- third-party/curl/tests/data/test641 | 15 +- third-party/curl/tests/data/test642 | 17 +- third-party/curl/tests/data/test643 | 129 +- third-party/curl/tests/data/test644 | 9 +- third-party/curl/tests/data/test645 | 263 +- third-party/curl/tests/data/test646 | 114 +- third-party/curl/tests/data/test647 | 84 +- third-party/curl/tests/data/test648 | 32 +- third-party/curl/tests/data/test649 | 42 +- third-party/curl/tests/data/test65 | 16 +- third-party/curl/tests/data/test650 | 313 +- third-party/curl/tests/data/test651 | 21 +- third-party/curl/tests/data/test652 | 22 +- third-party/curl/tests/data/test653 | 23 +- third-party/curl/tests/data/test654 | 115 +- third-party/curl/tests/data/test655 | 13 +- third-party/curl/tests/data/test656 | 15 +- third-party/curl/tests/data/test658 | 7 +- third-party/curl/tests/data/test659 | 7 +- third-party/curl/tests/data/test66 | 13 +- third-party/curl/tests/data/test660 | 8 +- third-party/curl/tests/data/test661 | 11 +- third-party/curl/tests/data/test662 | 18 +- third-party/curl/tests/data/test663 | 20 +- third-party/curl/tests/data/test664 | 15 +- third-party/curl/tests/data/test665 | 15 +- third-party/curl/tests/data/test666 | 44 +- third-party/curl/tests/data/test667 | 27 +- third-party/curl/tests/data/test668 | 87 +- third-party/curl/tests/data/test669 | 15 +- third-party/curl/tests/data/test67 | 11 +- third-party/curl/tests/data/test670 | 21 +- third-party/curl/tests/data/test671 | 23 +- third-party/curl/tests/data/test672 | 23 +- third-party/curl/tests/data/test673 | 23 +- third-party/curl/tests/data/test674 | 7 +- third-party/curl/tests/data/test675 | 13 +- third-party/curl/tests/data/test676 | 15 +- third-party/curl/tests/data/test677 | 10 +- third-party/curl/tests/data/test678 | 18 +- third-party/curl/tests/data/test679 | 18 +- third-party/curl/tests/data/test68 | 11 +- third-party/curl/tests/data/test680 | 13 +- third-party/curl/tests/data/test681 | 6 +- third-party/curl/tests/data/test682 | 12 +- third-party/curl/tests/data/test683 | 12 +- third-party/curl/tests/data/test684 | 12 +- third-party/curl/tests/data/test685 | 18 +- third-party/curl/tests/data/test686 | 13 +- third-party/curl/tests/data/test687 | 9 +- third-party/curl/tests/data/test688 | 11 +- third-party/curl/tests/data/test689 | 52 + third-party/curl/tests/data/test69 | 13 +- third-party/curl/tests/data/test690 | 65 + third-party/curl/tests/data/test691 | 65 + third-party/curl/tests/data/test692 | 54 + third-party/curl/tests/data/test693 | 60 + third-party/curl/tests/data/test694 | 128 + third-party/curl/tests/data/test695 | 79 + third-party/curl/tests/data/test696 | 69 + third-party/curl/tests/data/test697 | 32 + third-party/curl/tests/data/test698 | 55 + third-party/curl/tests/data/test699 | 55 + third-party/curl/tests/data/test7 | 12 +- third-party/curl/tests/data/test70 | 16 +- third-party/curl/tests/data/test700 | 12 +- third-party/curl/tests/data/test701 | 12 +- third-party/curl/tests/data/test702 | 8 +- third-party/curl/tests/data/test703 | 8 +- third-party/curl/tests/data/test704 | 8 +- third-party/curl/tests/data/test705 | 8 +- third-party/curl/tests/data/test706 | 18 +- third-party/curl/tests/data/test707 | 18 +- third-party/curl/tests/data/test708 | 14 +- third-party/curl/tests/data/test709 | 13 +- third-party/curl/tests/data/test71 | 47 +- third-party/curl/tests/data/test710 | 12 +- third-party/curl/tests/data/test711 | 12 +- third-party/curl/tests/data/test712 | 12 +- third-party/curl/tests/data/test713 | 12 +- third-party/curl/tests/data/test714 | 12 +- third-party/curl/tests/data/test715 | 12 +- third-party/curl/tests/data/test716 | 10 +- third-party/curl/tests/data/test717 | 10 +- third-party/curl/tests/data/test718 | 15 +- third-party/curl/tests/data/test719 | 14 +- third-party/curl/tests/data/test72 | 16 +- third-party/curl/tests/data/test720 | 12 +- third-party/curl/tests/data/test721 | 14 +- third-party/curl/tests/data/test722 | 53 + third-party/curl/tests/data/test723 | 36 + third-party/curl/tests/data/test724 | 59 + third-party/curl/tests/data/test725 | 41 + third-party/curl/tests/data/test726 | 40 + third-party/curl/tests/data/test727 | 53 + third-party/curl/tests/data/test728 | 62 + third-party/curl/tests/data/test729 | 39 + third-party/curl/tests/data/test73 | 11 +- third-party/curl/tests/data/test730 | 53 + third-party/curl/tests/data/test731 | 59 + third-party/curl/tests/data/test732 | 53 + third-party/curl/tests/data/test733 | 53 + third-party/curl/tests/data/test734 | 53 + third-party/curl/tests/data/test735 | 53 + third-party/curl/tests/data/test736 | 59 + third-party/curl/tests/data/test737 | 59 + third-party/curl/tests/data/test738 | 38 + third-party/curl/tests/data/test739 | 35 + third-party/curl/tests/data/test74 | 12 +- third-party/curl/tests/data/test740 | 61 + third-party/curl/tests/data/test741 | 43 + third-party/curl/tests/data/test742 | 64 + third-party/curl/tests/data/test743 | 58 + third-party/curl/tests/data/test744 | 77 + third-party/curl/tests/data/test745 | 28 + third-party/curl/tests/data/test746 | 32 + third-party/curl/tests/data/test747 | 57 + third-party/curl/tests/data/test748 | 32 + third-party/curl/tests/data/test749 | 62 + third-party/curl/tests/data/test75 | 16 +- third-party/curl/tests/data/test750 | 58 + third-party/curl/tests/data/test751 | 32 + third-party/curl/tests/data/test752 | 70 + third-party/curl/tests/data/test753 | 46 + third-party/curl/tests/data/test754 | 62 + third-party/curl/tests/data/test755 | 57 + third-party/curl/tests/data/test756 | 74 + third-party/curl/tests/data/test757 | 79 + third-party/curl/tests/data/test758 | 52 + third-party/curl/tests/data/test759 | 26 + third-party/curl/tests/data/test76 | 105 +- third-party/curl/tests/data/test760 | 26 + third-party/curl/tests/data/test761 | 29 + third-party/curl/tests/data/test762 | 54 + third-party/curl/tests/data/test763 | 30 + third-party/curl/tests/data/test764 | 65 + third-party/curl/tests/data/test765 | 65 + third-party/curl/tests/data/test766 | 60 + third-party/curl/tests/data/test767 | 56 + third-party/curl/tests/data/test768 | 55 + third-party/curl/tests/data/test769 | 51 + third-party/curl/tests/data/test77 | 12 +- third-party/curl/tests/data/test770 | 52 + third-party/curl/tests/data/test771 | 55 + third-party/curl/tests/data/test772 | 50 + third-party/curl/tests/data/test773 | 47 + third-party/curl/tests/data/test774 | 26 + third-party/curl/tests/data/test775 | 68 + third-party/curl/tests/data/test776 | 53 + third-party/curl/tests/data/test777 | 46 + third-party/curl/tests/data/test778 | 95 + third-party/curl/tests/data/test779 | 75 + third-party/curl/tests/data/test78 | 12 +- third-party/curl/tests/data/test780 | 86 + third-party/curl/tests/data/test781 | 88 + third-party/curl/tests/data/test782 | 88 + third-party/curl/tests/data/test783 | 88 + third-party/curl/tests/data/test784 | 57 + third-party/curl/tests/data/test785 | 57 + third-party/curl/tests/data/test786 | 57 + third-party/curl/tests/data/test787 | 33 + third-party/curl/tests/data/test788 | 57 + third-party/curl/tests/data/test789 | 56 + third-party/curl/tests/data/test79 | 12 +- third-party/curl/tests/data/test790 | 54 + third-party/curl/tests/data/test791 | 54 + third-party/curl/tests/data/test792 | 47 + third-party/curl/tests/data/test793 | 47 + third-party/curl/tests/data/test794 | 94 + third-party/curl/tests/data/test795 | 73 + third-party/curl/tests/data/test796 | 91 + third-party/curl/tests/data/test797 | 93 + third-party/curl/tests/data/test798 | 64 + third-party/curl/tests/data/test799 | 14 +- third-party/curl/tests/data/test8 | 11 +- third-party/curl/tests/data/test80 | 28 +- third-party/curl/tests/data/test800 | 16 +- third-party/curl/tests/data/test801 | 14 +- third-party/curl/tests/data/test802 | 14 +- third-party/curl/tests/data/test803 | 13 +- third-party/curl/tests/data/test804 | 16 +- third-party/curl/tests/data/test805 | 24 +- third-party/curl/tests/data/test806 | 14 +- third-party/curl/tests/data/test807 | 14 +- third-party/curl/tests/data/test808 | 14 +- third-party/curl/tests/data/test809 | 14 +- third-party/curl/tests/data/test81 | 11 +- third-party/curl/tests/data/test810 | 14 +- third-party/curl/tests/data/test811 | 12 +- third-party/curl/tests/data/test812 | 12 +- third-party/curl/tests/data/test813 | 12 +- third-party/curl/tests/data/test814 | 12 +- third-party/curl/tests/data/test815 | 14 +- third-party/curl/tests/data/test816 | 16 +- third-party/curl/tests/data/test817 | 12 +- third-party/curl/tests/data/test818 | 14 +- third-party/curl/tests/data/test819 | 18 +- third-party/curl/tests/data/test82 | 13 +- third-party/curl/tests/data/test820 | 24 +- third-party/curl/tests/data/test821 | 21 +- third-party/curl/tests/data/test822 | 12 +- third-party/curl/tests/data/test823 | 26 +- third-party/curl/tests/data/test824 | 18 +- third-party/curl/tests/data/test825 | 16 +- third-party/curl/tests/data/test826 | 22 +- third-party/curl/tests/data/test827 | 10 +- third-party/curl/tests/data/test828 | 16 +- third-party/curl/tests/data/test829 | 8 +- third-party/curl/tests/data/test83 | 22 +- third-party/curl/tests/data/test830 | 16 +- third-party/curl/tests/data/test831 | 28 +- third-party/curl/tests/data/test832 | 18 +- third-party/curl/tests/data/test833 | 19 +- third-party/curl/tests/data/test834 | 31 +- third-party/curl/tests/data/test835 | 21 +- third-party/curl/tests/data/test836 | 14 +- third-party/curl/tests/data/test837 | 18 +- third-party/curl/tests/data/test838 | 14 +- third-party/curl/tests/data/test839 | 16 +- third-party/curl/tests/data/test84 | 14 +- third-party/curl/tests/data/test840 | 14 +- third-party/curl/tests/data/test841 | 25 +- third-party/curl/tests/data/test842 | 16 +- third-party/curl/tests/data/test843 | 14 +- third-party/curl/tests/data/test844 | 15 +- third-party/curl/tests/data/test845 | 17 +- third-party/curl/tests/data/test846 | 14 +- third-party/curl/tests/data/test847 | 16 +- third-party/curl/tests/data/test848 | 18 +- third-party/curl/tests/data/test849 | 21 +- third-party/curl/tests/data/test85 | 16 +- third-party/curl/tests/data/test850 | 14 +- third-party/curl/tests/data/test851 | 12 +- third-party/curl/tests/data/test852 | 13 +- third-party/curl/tests/data/test853 | 16 +- third-party/curl/tests/data/test854 | 12 +- third-party/curl/tests/data/test855 | 13 +- third-party/curl/tests/data/test856 | 16 +- third-party/curl/tests/data/test857 | 16 +- third-party/curl/tests/data/test858 | 12 +- third-party/curl/tests/data/test859 | 12 +- third-party/curl/tests/data/test86 | 12 +- third-party/curl/tests/data/test860 | 12 +- third-party/curl/tests/data/test861 | 14 +- third-party/curl/tests/data/test862 | 14 +- third-party/curl/tests/data/test863 | 12 +- third-party/curl/tests/data/test864 | 17 +- third-party/curl/tests/data/test865 | 18 +- third-party/curl/tests/data/test866 | 24 +- third-party/curl/tests/data/test867 | 21 +- third-party/curl/tests/data/test868 | 12 +- third-party/curl/tests/data/test869 | 26 +- third-party/curl/tests/data/test87 | 21 +- third-party/curl/tests/data/test870 | 18 +- third-party/curl/tests/data/test871 | 16 +- third-party/curl/tests/data/test872 | 22 +- third-party/curl/tests/data/test873 | 10 +- third-party/curl/tests/data/test874 | 16 +- third-party/curl/tests/data/test875 | 8 +- third-party/curl/tests/data/test876 | 16 +- third-party/curl/tests/data/test877 | 28 +- third-party/curl/tests/data/test878 | 18 +- third-party/curl/tests/data/test879 | 19 +- third-party/curl/tests/data/test88 | 16 +- third-party/curl/tests/data/test880 | 31 +- third-party/curl/tests/data/test881 | 21 +- third-party/curl/tests/data/test882 | 14 +- third-party/curl/tests/data/test883 | 18 +- third-party/curl/tests/data/test884 | 14 +- third-party/curl/tests/data/test885 | 16 +- third-party/curl/tests/data/test886 | 14 +- third-party/curl/tests/data/test887 | 14 +- third-party/curl/tests/data/test888 | 14 +- third-party/curl/tests/data/test889 | 17 +- third-party/curl/tests/data/test89 | 17 +- third-party/curl/tests/data/test890 | 17 +- third-party/curl/tests/data/test891 | 15 +- third-party/curl/tests/data/test892 | 18 +- third-party/curl/tests/data/test893 | 21 +- third-party/curl/tests/data/test894 | 10 +- third-party/curl/tests/data/test895 | 14 +- third-party/curl/tests/data/test896 | 10 +- third-party/curl/tests/data/test897 | 24 +- third-party/curl/tests/data/test898 | 18 +- third-party/curl/tests/data/test899 | 16 +- third-party/curl/tests/data/test9 | 49 +- third-party/curl/tests/data/test90 | 21 +- third-party/curl/tests/data/test900 | 42 +- third-party/curl/tests/data/test901 | 20 +- third-party/curl/tests/data/test902 | 20 +- third-party/curl/tests/data/test903 | 24 +- third-party/curl/tests/data/test904 | 28 +- third-party/curl/tests/data/test905 | 27 +- third-party/curl/tests/data/test906 | 18 +- third-party/curl/tests/data/test907 | 34 +- third-party/curl/tests/data/test908 | 24 +- third-party/curl/tests/data/test909 | 20 +- third-party/curl/tests/data/test91 | 17 +- third-party/curl/tests/data/test910 | 20 +- third-party/curl/tests/data/test911 | 18 +- third-party/curl/tests/data/test912 | 20 +- third-party/curl/tests/data/test913 | 16 +- third-party/curl/tests/data/test914 | 16 +- third-party/curl/tests/data/test915 | 20 +- third-party/curl/tests/data/test916 | 18 +- third-party/curl/tests/data/test917 | 37 +- third-party/curl/tests/data/test918 | 29 +- third-party/curl/tests/data/test919 | 22 +- third-party/curl/tests/data/test92 | 13 +- third-party/curl/tests/data/test920 | 28 +- third-party/curl/tests/data/test921 | 16 +- third-party/curl/tests/data/test922 | 22 +- third-party/curl/tests/data/test923 | 12 +- third-party/curl/tests/data/test924 | 20 +- third-party/curl/tests/data/test925 | 14 +- third-party/curl/tests/data/test926 | 12 +- third-party/curl/tests/data/test927 | 20 +- third-party/curl/tests/data/test928 | 14 +- third-party/curl/tests/data/test929 | 12 +- third-party/curl/tests/data/test93 | 12 +- third-party/curl/tests/data/test930 | 12 +- third-party/curl/tests/data/test931 | 8 +- third-party/curl/tests/data/test932 | 16 +- third-party/curl/tests/data/test933 | 28 +- third-party/curl/tests/data/test934 | 18 +- third-party/curl/tests/data/test935 | 25 +- third-party/curl/tests/data/test936 | 37 +- third-party/curl/tests/data/test937 | 27 +- third-party/curl/tests/data/test938 | 35 +- third-party/curl/tests/data/test939 | 20 +- third-party/curl/tests/data/test94 | 15 +- third-party/curl/tests/data/test940 | 20 +- third-party/curl/tests/data/test941 | 24 +- third-party/curl/tests/data/test942 | 24 +- third-party/curl/tests/data/test943 | 20 +- third-party/curl/tests/data/test944 | 22 +- third-party/curl/tests/data/test945 | 20 +- third-party/curl/tests/data/test946 | 20 +- third-party/curl/tests/data/test947 | 20 +- third-party/curl/tests/data/test948 | 18 +- third-party/curl/tests/data/test949 | 19 +- third-party/curl/tests/data/test95 | 20 +- third-party/curl/tests/data/test950 | 16 +- third-party/curl/tests/data/test951 | 18 +- third-party/curl/tests/data/test952 | 18 +- third-party/curl/tests/data/test953 | 24 +- third-party/curl/tests/data/test954 | 23 +- third-party/curl/tests/data/test955 | 23 +- third-party/curl/tests/data/test956 | 25 +- third-party/curl/tests/data/test957 | 23 +- third-party/curl/tests/data/test958 | 23 +- third-party/curl/tests/data/test959 | 25 +- third-party/curl/tests/data/test96 | 12 +- third-party/curl/tests/data/test960 | 27 +- third-party/curl/tests/data/test961 | 25 +- third-party/curl/tests/data/test962 | 31 +- third-party/curl/tests/data/test963 | 31 +- third-party/curl/tests/data/test964 | 23 +- third-party/curl/tests/data/test965 | 29 +- third-party/curl/tests/data/test966 | 29 +- third-party/curl/tests/data/test967 | 25 +- third-party/curl/tests/data/test968 | 23 +- third-party/curl/tests/data/test969 | 22 +- third-party/curl/tests/data/test97 | 16 +- third-party/curl/tests/data/test970 | 10 +- third-party/curl/tests/data/test971 | 12 +- third-party/curl/tests/data/test972 | 10 +- third-party/curl/tests/data/test973 | 14 +- third-party/curl/tests/data/test974 | 14 +- third-party/curl/tests/data/test975 | 14 +- third-party/curl/tests/data/test976 | 16 +- third-party/curl/tests/data/test977 | 12 +- third-party/curl/tests/data/test978 | 14 +- third-party/curl/tests/data/test979 | 16 +- third-party/curl/tests/data/test98 | 16 +- third-party/curl/tests/data/test980 | 14 +- third-party/curl/tests/data/test981 | 16 +- third-party/curl/tests/data/test982 | 14 +- third-party/curl/tests/data/test983 | 10 +- third-party/curl/tests/data/test984 | 16 +- third-party/curl/tests/data/test985 | 14 +- third-party/curl/tests/data/test986 | 10 +- third-party/curl/tests/data/test987 | 23 +- third-party/curl/tests/data/test988 | 16 +- third-party/curl/tests/data/test989 | 16 +- third-party/curl/tests/data/test99 | 15 +- third-party/curl/tests/data/test990 | 10 +- third-party/curl/tests/data/test991 | 8 +- third-party/curl/tests/data/test992 | 52 + third-party/curl/tests/data/test993 | 43 + third-party/curl/tests/data/test994 | 40 + third-party/curl/tests/data/test995 | 54 + third-party/curl/tests/data/test996 | 39 + third-party/curl/tests/data/test997 | 45 + third-party/curl/tests/data/test998 | 86 + third-party/curl/tests/data/test999 | 76 + third-party/curl/tests/devtest.pl | 27 +- third-party/curl/tests/dictserver.py | 47 +- third-party/curl/tests/directories.pm | 394 +- third-party/curl/tests/disable-scan.pl | 148 - third-party/curl/tests/ech_combos.py | 98 + third-party/curl/tests/ech_tests.sh | 1102 +++ third-party/curl/tests/error-codes.pl | 82 - third-party/curl/tests/extern-scan.pl | 114 - third-party/curl/tests/ftpserver.pl | 654 +- third-party/curl/tests/getpart.pm | 230 +- third-party/curl/tests/globalconfig.pm | 88 +- third-party/curl/tests/http-server.pl | 13 +- third-party/curl/tests/http/CMakeLists.txt | 80 + third-party/curl/tests/http/Makefile.am | 63 +- third-party/curl/tests/http/README.md | 128 - .../curl/tests/http/clients/.gitignore | 10 - .../curl/tests/http/clients/Makefile.am | 73 - .../curl/tests/http/clients/Makefile.inc | 32 - .../curl/tests/http/clients/h2-download.c | 352 - .../curl/tests/http/clients/h2-serverpush.c | 272 - .../tests/http/clients/h2-upgrade-extreme.c | 249 - .../tests/http/clients/tls-session-reuse.c | 306 - third-party/curl/tests/http/clients/ws-data.c | 263 - .../curl/tests/http/clients/ws-pingpong.c | 158 - third-party/curl/tests/http/config.ini.in | 14 +- third-party/curl/tests/http/conftest.py | 175 +- third-party/curl/tests/http/requirements.txt | 33 +- third-party/curl/tests/http/scorecard.py | 1234 ++- third-party/curl/tests/http/test_01_basic.py | 257 +- .../curl/tests/http/test_02_download.py | 644 +- third-party/curl/tests/http/test_03_goaway.py | 74 +- .../curl/tests/http/test_04_stuttered.py | 57 +- third-party/curl/tests/http/test_05_errors.py | 187 +- .../curl/tests/http/test_06_eyeballs.py | 175 +- third-party/curl/tests/http/test_07_upload.py | 588 +- third-party/curl/tests/http/test_08_caddy.py | 165 +- third-party/curl/tests/http/test_09_push.py | 44 +- third-party/curl/tests/http/test_10_proxy.py | 290 +- third-party/curl/tests/http/test_11_unix.py | 48 +- third-party/curl/tests/http/test_12_reuse.py | 31 +- .../curl/tests/http/test_13_proxy_auth.py | 100 +- third-party/curl/tests/http/test_14_auth.py | 70 +- .../curl/tests/http/test_15_tracing.py | 13 +- third-party/curl/tests/http/test_16_info.py | 122 + .../curl/tests/http/test_17_ssl_use.py | 601 ++ .../curl/tests/http/test_18_methods.py | 65 + .../curl/tests/http/test_19_shutdown.py | 213 + .../curl/tests/http/test_20_websockets.py | 245 +- .../curl/tests/http/test_21_resolve.py | 202 + .../curl/tests/http/test_22_httpsrr.py | 131 + third-party/curl/tests/http/test_30_vsftpd.py | 277 + .../curl/tests/http/test_31_vsftpds.py | 328 + .../curl/tests/http/test_32_ftps_vsftpd.py | 317 + third-party/curl/tests/http/test_40_socks.py | 122 + third-party/curl/tests/http/test_50_scp.py | 214 + third-party/curl/tests/http/test_51_sftp.py | 214 + .../curl/tests/http/test_60_h3_proxy.py | 626 ++ .../curl/tests/http/testenv/__init__.py | 20 +- third-party/curl/tests/http/testenv/caddy.py | 99 +- third-party/curl/tests/http/testenv/certs.py | 105 +- third-party/curl/tests/http/testenv/client.py | 53 +- third-party/curl/tests/http/testenv/curl.py | 850 ++- third-party/curl/tests/http/testenv/dante.py | 179 + third-party/curl/tests/http/testenv/dnsd.py | 175 + third-party/curl/tests/http/testenv/env.py | 796 +- third-party/curl/tests/http/testenv/h2o.py | 448 ++ third-party/curl/tests/http/testenv/httpd.py | 417 +- .../http/testenv/mod_curltest/mod_curltest.c | 639 +- .../curl/tests/http/testenv/nghttpx.py | 214 +- third-party/curl/tests/http/testenv/ports.py | 22 +- third-party/curl/tests/http/testenv/sshd.py | 293 + third-party/curl/tests/http/testenv/vsftpd.py | 231 + .../curl/tests/http/testenv/ws_echo_server.py | 2 +- third-party/curl/tests/http2-server.pl | 24 +- third-party/curl/tests/http3-server.pl | 22 +- third-party/curl/tests/libtest/.checksrc | 2 - third-party/curl/tests/libtest/.gitignore | 8 +- third-party/curl/tests/libtest/CMakeLists.txt | 97 +- third-party/curl/tests/libtest/Makefile.am | 107 +- third-party/curl/tests/libtest/Makefile.inc | 768 +- third-party/curl/tests/libtest/chkhostname.c | 49 - .../curl/tests/libtest/cli_ftp_upload.c | 182 + .../curl/tests/libtest/cli_h2_pausing.c | 316 + .../curl/tests/libtest/cli_h2_serverpush.c | 192 + .../tests/libtest/cli_h2_upgrade_extreme.c | 171 + .../curl/tests/libtest/cli_hx_download.c | 607 ++ .../curl/tests/libtest/cli_hx_upload.c | 548 ++ .../tests/libtest/cli_tls_session_reuse.c | 266 + .../curl/tests/libtest/cli_upload_pausing.c | 215 + third-party/curl/tests/libtest/cli_ws_data.c | 484 ++ .../curl/tests/libtest/cli_ws_pingpong.c | 96 + third-party/curl/tests/libtest/first.c | 274 +- third-party/curl/tests/libtest/first.h | 536 ++ third-party/curl/tests/libtest/lib1156.c | 92 +- third-party/curl/tests/libtest/lib1301.c | 34 +- third-party/curl/tests/libtest/lib1308.c | 99 + third-party/curl/tests/libtest/lib1485.c | 117 + third-party/curl/tests/libtest/lib1500.c | 39 +- third-party/curl/tests/libtest/lib1501.c | 73 +- third-party/curl/tests/libtest/lib1502.c | 111 +- third-party/curl/tests/libtest/lib1506.c | 68 +- third-party/curl/tests/libtest/lib1507.c | 93 +- third-party/curl/tests/libtest/lib1508.c | 20 +- third-party/curl/tests/libtest/lib1509.c | 81 +- third-party/curl/tests/libtest/lib1510.c | 42 +- third-party/curl/tests/libtest/lib1511.c | 26 +- third-party/curl/tests/libtest/lib1512.c | 53 +- third-party/curl/tests/libtest/lib1513.c | 26 +- third-party/curl/tests/libtest/lib1514.c | 45 +- third-party/curl/tests/libtest/lib1515.c | 94 +- third-party/curl/tests/libtest/lib1517.c | 78 +- third-party/curl/tests/libtest/lib1518.c | 78 +- third-party/curl/tests/libtest/lib1520.c | 82 +- third-party/curl/tests/libtest/lib1522.c | 43 +- third-party/curl/tests/libtest/lib1523.c | 58 +- third-party/curl/tests/libtest/lib1525.c | 62 +- third-party/curl/tests/libtest/lib1526.c | 61 +- third-party/curl/tests/libtest/lib1527.c | 60 +- third-party/curl/tests/libtest/lib1528.c | 33 +- third-party/curl/tests/libtest/lib1529.c | 31 +- third-party/curl/tests/libtest/lib1530.c | 25 +- third-party/curl/tests/libtest/lib1531.c | 76 +- third-party/curl/tests/libtest/lib1532.c | 51 +- third-party/curl/tests/libtest/lib1533.c | 102 +- third-party/curl/tests/libtest/lib1534.c | 99 +- third-party/curl/tests/libtest/lib1535.c | 112 +- third-party/curl/tests/libtest/lib1536.c | 102 +- third-party/curl/tests/libtest/lib1537.c | 52 +- third-party/curl/tests/libtest/lib1538.c | 25 +- third-party/curl/tests/libtest/lib1540.c | 71 +- third-party/curl/tests/libtest/lib1541.c | 229 +- third-party/curl/tests/libtest/lib1542.c | 52 +- third-party/curl/tests/libtest/lib1545.c | 52 + third-party/curl/tests/libtest/lib1549.c | 75 + third-party/curl/tests/libtest/lib1550.c | 26 +- third-party/curl/tests/libtest/lib1551.c | 22 +- third-party/curl/tests/libtest/lib1552.c | 43 +- third-party/curl/tests/libtest/lib1553.c | 67 +- third-party/curl/tests/libtest/lib1554.c | 66 +- third-party/curl/tests/libtest/lib1555.c | 42 +- third-party/curl/tests/libtest/lib1556.c | 30 +- third-party/curl/tests/libtest/lib1557.c | 32 +- third-party/curl/tests/libtest/lib1558.c | 34 +- third-party/curl/tests/libtest/lib1559.c | 58 +- third-party/curl/tests/libtest/lib1560.c | 1272 +++- third-party/curl/tests/libtest/lib1564.c | 75 +- third-party/curl/tests/libtest/lib1565.c | 126 +- third-party/curl/tests/libtest/lib1567.c | 29 +- third-party/curl/tests/libtest/lib1568.c | 44 +- third-party/curl/tests/libtest/lib1569.c | 34 +- third-party/curl/tests/libtest/lib1571.c | 70 + third-party/curl/tests/libtest/lib1576.c | 94 + third-party/curl/tests/libtest/lib1582.c | 58 + third-party/curl/tests/libtest/lib1587.c | 98 + third-party/curl/tests/libtest/lib1588.c | 150 + third-party/curl/tests/libtest/lib1589.c | 132 + third-party/curl/tests/libtest/lib1591.c | 49 +- third-party/curl/tests/libtest/lib1592.c | 86 +- third-party/curl/tests/libtest/lib1593.c | 26 +- third-party/curl/tests/libtest/lib1594.c | 26 +- third-party/curl/tests/libtest/lib1597.c | 62 +- third-party/curl/tests/libtest/lib1598.c | 104 + third-party/curl/tests/libtest/lib1599.c | 44 + third-party/curl/tests/libtest/lib1647.c | 120 + third-party/curl/tests/libtest/lib1648.c | 135 + third-party/curl/tests/libtest/lib1649.c | 90 + third-party/curl/tests/libtest/lib1662.c | 66 +- third-party/curl/tests/libtest/lib1686.c | 93 + third-party/curl/tests/libtest/lib1900.c | 51 + third-party/curl/tests/libtest/lib1901.c | 79 + third-party/curl/tests/libtest/lib1902.c | 46 + third-party/curl/tests/libtest/lib1903.c | 41 +- third-party/curl/tests/libtest/lib1905.c | 63 +- third-party/curl/tests/libtest/lib1906.c | 66 +- third-party/curl/tests/libtest/lib1907.c | 26 +- third-party/curl/tests/libtest/lib1908.c | 44 +- third-party/curl/tests/libtest/lib1910.c | 30 +- third-party/curl/tests/libtest/lib1911.c | 64 +- third-party/curl/tests/libtest/lib1912.c | 97 +- third-party/curl/tests/libtest/lib1913.c | 28 +- third-party/curl/tests/libtest/lib1915.c | 147 +- third-party/curl/tests/libtest/lib1916.c | 32 +- third-party/curl/tests/libtest/lib1918.c | 23 +- third-party/curl/tests/libtest/lib1919.c | 43 +- third-party/curl/tests/libtest/lib1920.c | 55 + third-party/curl/tests/libtest/lib1921.c | 52 + third-party/curl/tests/libtest/lib1922.c | 116 + third-party/curl/tests/libtest/lib1933.c | 30 +- third-party/curl/tests/libtest/lib1934.c | 32 +- third-party/curl/tests/libtest/lib1935.c | 32 +- third-party/curl/tests/libtest/lib1936.c | 32 +- third-party/curl/tests/libtest/lib1937.c | 37 +- third-party/curl/tests/libtest/lib1938.c | 41 +- third-party/curl/tests/libtest/lib1939.c | 45 +- third-party/curl/tests/libtest/lib1940.c | 134 +- third-party/curl/tests/libtest/lib1945.c | 73 +- third-party/curl/tests/libtest/lib1947.c | 107 +- third-party/curl/tests/libtest/lib1948.c | 67 +- third-party/curl/tests/libtest/lib1955.c | 32 +- third-party/curl/tests/libtest/lib1956.c | 32 +- third-party/curl/tests/libtest/lib1957.c | 32 +- third-party/curl/tests/libtest/lib1958.c | 32 +- third-party/curl/tests/libtest/lib1959.c | 32 +- third-party/curl/tests/libtest/lib1960.c | 86 +- third-party/curl/tests/libtest/lib1964.c | 18 +- third-party/curl/tests/libtest/lib1965.c | 55 + third-party/curl/tests/libtest/lib1967.c | 42 + third-party/curl/tests/libtest/lib1970.c | 38 +- third-party/curl/tests/libtest/lib1971.c | 49 +- third-party/curl/tests/libtest/lib1972.c | 36 +- third-party/curl/tests/libtest/lib1973.c | 36 +- third-party/curl/tests/libtest/lib1974.c | 32 +- third-party/curl/tests/libtest/lib1975.c | 49 +- third-party/curl/tests/libtest/lib1977.c | 89 + third-party/curl/tests/libtest/lib1978.c | 102 + third-party/curl/tests/libtest/lib2023.c | 148 + third-party/curl/tests/libtest/lib2032.c | 234 + third-party/curl/tests/libtest/lib2082.c | 102 + third-party/curl/tests/libtest/lib2301.c | 116 +- third-party/curl/tests/libtest/lib2302.c | 192 +- third-party/curl/tests/libtest/lib2304.c | 106 +- third-party/curl/tests/libtest/lib2305.c | 109 - third-party/curl/tests/libtest/lib2306.c | 36 +- third-party/curl/tests/libtest/lib2308.c | 50 + third-party/curl/tests/libtest/lib2309.c | 63 + third-party/curl/tests/libtest/lib2402.c | 64 +- third-party/curl/tests/libtest/lib2404.c | 66 +- third-party/curl/tests/libtest/lib2405.c | 392 + third-party/curl/tests/libtest/lib2412.c | 95 + third-party/curl/tests/libtest/lib2502.c | 72 +- third-party/curl/tests/libtest/lib2504.c | 86 + third-party/curl/tests/libtest/lib2505.c | 64 + third-party/curl/tests/libtest/lib2506.c | 64 + third-party/curl/tests/libtest/lib2700.c | 256 + third-party/curl/tests/libtest/lib3010.c | 36 +- third-party/curl/tests/libtest/lib3025.c | 24 +- third-party/curl/tests/libtest/lib3026.c | 128 +- third-party/curl/tests/libtest/lib3027.c | 36 +- third-party/curl/tests/libtest/lib3033.c | 128 + third-party/curl/tests/libtest/lib3034.c | 77 + third-party/curl/tests/libtest/lib3100.c | 39 +- third-party/curl/tests/libtest/lib3101.c | 35 +- third-party/curl/tests/libtest/lib3102.c | 86 +- third-party/curl/tests/libtest/lib3103.c | 64 + third-party/curl/tests/libtest/lib3104.c | 64 + third-party/curl/tests/libtest/lib3105.c | 62 + third-party/curl/tests/libtest/lib3207.c | 214 + third-party/curl/tests/libtest/lib3208.c | 100 + third-party/curl/tests/libtest/lib500.c | 132 +- third-party/curl/tests/libtest/lib501.c | 24 +- third-party/curl/tests/libtest/lib502.c | 36 +- third-party/curl/tests/libtest/lib503.c | 49 +- third-party/curl/tests/libtest/lib504.c | 69 +- third-party/curl/tests/libtest/lib505.c | 106 +- third-party/curl/tests/libtest/lib506.c | 317 +- third-party/curl/tests/libtest/lib507.c | 30 +- third-party/curl/tests/libtest/lib508.c | 63 +- third-party/curl/tests/libtest/lib509.c | 61 +- third-party/curl/tests/libtest/lib510.c | 77 +- third-party/curl/tests/libtest/lib511.c | 24 +- third-party/curl/tests/libtest/lib512.c | 22 +- third-party/curl/tests/libtest/lib513.c | 34 +- third-party/curl/tests/libtest/lib514.c | 32 +- third-party/curl/tests/libtest/lib515.c | 26 +- third-party/curl/tests/libtest/lib516.c | 26 +- third-party/curl/tests/libtest/lib517.c | 355 +- third-party/curl/tests/libtest/lib518.c | 440 +- third-party/curl/tests/libtest/lib519.c | 30 +- third-party/curl/tests/libtest/lib520.c | 22 +- third-party/curl/tests/libtest/lib521.c | 32 +- third-party/curl/tests/libtest/lib523.c | 26 +- third-party/curl/tests/libtest/lib524.c | 22 +- third-party/curl/tests/libtest/lib525.c | 96 +- third-party/curl/tests/libtest/lib526.c | 155 +- third-party/curl/tests/libtest/lib530.c | 288 +- third-party/curl/tests/libtest/lib533.c | 40 +- third-party/curl/tests/libtest/lib536.c | 81 + third-party/curl/tests/libtest/lib537.c | 451 +- third-party/curl/tests/libtest/lib539.c | 105 +- third-party/curl/tests/libtest/lib540.c | 200 +- third-party/curl/tests/libtest/lib541.c | 71 +- third-party/curl/tests/libtest/lib542.c | 30 +- third-party/curl/tests/libtest/lib543.c | 41 +- third-party/curl/tests/libtest/lib544.c | 56 +- third-party/curl/tests/libtest/lib547.c | 98 +- third-party/curl/tests/libtest/lib549.c | 28 +- third-party/curl/tests/libtest/lib552.c | 168 +- third-party/curl/tests/libtest/lib553.c | 44 +- third-party/curl/tests/libtest/lib554.c | 123 +- third-party/curl/tests/libtest/lib555.c | 71 +- third-party/curl/tests/libtest/lib556.c | 100 +- third-party/curl/tests/libtest/lib557.c | 853 +-- third-party/curl/tests/libtest/lib558.c | 22 +- third-party/curl/tests/libtest/lib559.c | 23 +- third-party/curl/tests/libtest/lib560.c | 50 +- third-party/curl/tests/libtest/lib562.c | 43 +- third-party/curl/tests/libtest/lib564.c | 37 +- third-party/curl/tests/libtest/lib566.c | 35 +- third-party/curl/tests/libtest/lib567.c | 31 +- third-party/curl/tests/libtest/lib568.c | 130 +- third-party/curl/tests/libtest/lib569.c | 81 +- third-party/curl/tests/libtest/lib570.c | 79 +- third-party/curl/tests/libtest/lib571.c | 147 +- third-party/curl/tests/libtest/lib572.c | 138 +- third-party/curl/tests/libtest/lib573.c | 57 +- third-party/curl/tests/libtest/lib574.c | 40 +- third-party/curl/tests/libtest/lib575.c | 60 +- third-party/curl/tests/libtest/lib576.c | 97 +- third-party/curl/tests/libtest/lib578.c | 60 +- third-party/curl/tests/libtest/lib579.c | 135 +- third-party/curl/tests/libtest/lib582.c | 212 +- third-party/curl/tests/libtest/lib583.c | 46 +- third-party/curl/tests/libtest/lib586.c | 189 +- third-party/curl/tests/libtest/lib589.c | 48 +- third-party/curl/tests/libtest/lib590.c | 49 +- third-party/curl/tests/libtest/lib591.c | 73 +- third-party/curl/tests/libtest/lib597.c | 47 +- third-party/curl/tests/libtest/lib598.c | 44 +- third-party/curl/tests/libtest/lib599.c | 52 +- third-party/curl/tests/libtest/lib643.c | 212 +- third-party/curl/tests/libtest/lib650.c | 83 +- third-party/curl/tests/libtest/lib651.c | 45 +- third-party/curl/tests/libtest/lib652.c | 78 +- third-party/curl/tests/libtest/lib653.c | 37 +- third-party/curl/tests/libtest/lib654.c | 104 +- third-party/curl/tests/libtest/lib655.c | 73 +- third-party/curl/tests/libtest/lib658.c | 39 +- third-party/curl/tests/libtest/lib659.c | 39 +- third-party/curl/tests/libtest/lib661.c | 230 +- third-party/curl/tests/libtest/lib666.c | 74 +- third-party/curl/tests/libtest/lib667.c | 69 +- third-party/curl/tests/libtest/lib668.c | 67 +- third-party/curl/tests/libtest/lib670.c | 302 +- third-party/curl/tests/libtest/lib674.c | 46 +- third-party/curl/tests/libtest/lib676.c | 38 +- third-party/curl/tests/libtest/lib677.c | 77 +- third-party/curl/tests/libtest/lib678.c | 66 +- third-party/curl/tests/libtest/lib694.c | 75 + third-party/curl/tests/libtest/lib695.c | 104 + third-party/curl/tests/libtest/lib751.c | 86 + third-party/curl/tests/libtest/lib753.c | 183 + third-party/curl/tests/libtest/lib757.c | 125 + third-party/curl/tests/libtest/lib758.c | 505 ++ third-party/curl/tests/libtest/lib766.c | 64 + third-party/curl/tests/libtest/libauthretry.c | 149 - .../curl/tests/libtest/libntlmconnect.c | 238 - third-party/curl/tests/libtest/libprereq.c | 99 - third-party/curl/tests/libtest/memptr.c | 46 + third-party/curl/tests/libtest/mk-lib1521.pl | 483 +- third-party/curl/tests/libtest/notexists.pl | 38 - third-party/curl/tests/libtest/sethostname.c | 43 - third-party/curl/tests/libtest/sethostname.h | 42 - third-party/curl/tests/libtest/stub_gssapi.c | 462 -- third-party/curl/tests/libtest/stub_gssapi.h | 184 - third-party/curl/tests/libtest/test.h | 500 -- third-party/curl/tests/libtest/test1013.pl | 40 +- third-party/curl/tests/libtest/test1022.pl | 24 +- third-party/curl/tests/libtest/test307.pl | 16 +- third-party/curl/tests/libtest/test610.pl | 26 +- third-party/curl/tests/libtest/test613.pl | 86 +- third-party/curl/tests/libtest/testtrace.c | 170 +- third-party/curl/tests/libtest/testtrace.h | 20 +- third-party/curl/tests/libtest/testutil.c | 145 +- third-party/curl/tests/libtest/testutil.h | 35 +- third-party/curl/tests/libtest/unitcheck.h | 124 + third-party/curl/tests/manpage-scan.pl | 305 - third-party/curl/tests/manpage-syntax.pl | 288 - third-party/curl/tests/markdown-uppercase.pl | 100 - third-party/curl/tests/mem-include-scan.pl | 98 - third-party/curl/tests/memanalyze.pl | 406 +- third-party/curl/tests/memanalyzer.pm | 446 ++ third-party/curl/tests/negtelnetserver.py | 67 +- third-party/curl/tests/nroff-scan.pl | 112 - third-party/curl/tests/option-check.pl | 66 - third-party/curl/tests/options-scan.pl | 125 - third-party/curl/tests/pathhelp.pm | 754 +- third-party/curl/tests/processhelp.pm | 233 +- third-party/curl/tests/requirements.txt | 25 +- third-party/curl/tests/rtspserver.pl | 11 +- third-party/curl/tests/runner.pm | 582 +- third-party/curl/tests/runtests.1 | 196 - third-party/curl/tests/runtests.pl | 1511 ++-- third-party/curl/tests/secureserver.pl | 89 +- third-party/curl/tests/server/.checksrc | 19 + third-party/curl/tests/server/.gitignore | 12 +- third-party/curl/tests/server/CMakeLists.txt | 81 +- third-party/curl/tests/server/Makefile.am | 34 +- third-party/curl/tests/server/Makefile.inc | 124 +- third-party/curl/tests/server/base64.pl | 32 - third-party/curl/tests/server/disabled.c | 117 - third-party/curl/tests/server/dnsd.c | 1077 +++ third-party/curl/tests/server/fake_ntlm.c | 286 - third-party/curl/tests/server/first.c | 59 + third-party/curl/tests/server/first.h | 181 + third-party/curl/tests/server/getpart.c | 186 +- third-party/curl/tests/server/getpart.h | 36 - third-party/curl/tests/server/mqttd.c | 674 +- third-party/curl/tests/server/resolve.c | 79 +- third-party/curl/tests/server/rtspd.c | 646 +- third-party/curl/tests/server/server_setup.h | 31 - .../curl/tests/server/server_sockaddr.h | 43 - third-party/curl/tests/server/sockfilt.c | 909 +-- third-party/curl/tests/server/socksd.c | 723 +- third-party/curl/tests/server/sws.c | 1509 ++-- third-party/curl/tests/server/testpart.c | 51 - third-party/curl/tests/server/tftp.h | 63 - third-party/curl/tests/server/tftpd.c | 1717 +++-- third-party/curl/tests/server/util.c | 1016 +-- third-party/curl/tests/server/util.h | 99 - third-party/curl/tests/serverhelp.pm | 134 +- third-party/curl/tests/servers.pm | 1184 +-- third-party/curl/tests/smbserver.py | 149 +- third-party/curl/tests/sshhelp.pm | 55 +- third-party/curl/tests/sshserver.pl | 244 +- third-party/curl/tests/stunnel.pem | 165 - third-party/curl/tests/symbol-scan.pl | 245 - third-party/curl/tests/test1119.pl | 247 + third-party/curl/tests/test1135.pl | 108 + third-party/curl/tests/test1139.pl | 316 + third-party/curl/tests/test1140.pl | 115 + third-party/curl/tests/test1165.pl | 215 + third-party/curl/tests/test1167.pl | 156 + third-party/curl/tests/test1173.pl | 394 + third-party/curl/tests/test1175.pl | 80 + third-party/curl/tests/test1177.pl | 95 + third-party/curl/tests/test1222.pl | 335 + third-party/curl/tests/test1275.pl | 131 + third-party/curl/tests/test1276.pl | 69 + third-party/curl/tests/test1477.pl | 101 + third-party/curl/tests/test1486.pl | 113 + third-party/curl/tests/test1488.pl | 141 + third-party/curl/tests/test1544.pl | 147 + third-party/curl/tests/test1707.pl | 130 + third-party/curl/tests/test745.pl | 92 + third-party/curl/tests/test971.pl | 145 + third-party/curl/tests/testcurl.1 | 126 - third-party/curl/tests/testcurl.pl | 988 ++- third-party/curl/tests/testutil.pm | 137 +- third-party/curl/tests/tftpserver.pl | 12 +- third-party/curl/tests/tunit/.gitignore | 6 + third-party/curl/tests/tunit/CMakeLists.txt | 57 + third-party/curl/tests/tunit/Makefile.am | 82 + third-party/curl/tests/tunit/Makefile.inc | 38 + third-party/curl/tests/tunit/README.md | 11 + third-party/curl/tests/tunit/tool1394.c | 122 + third-party/curl/tests/tunit/tool1604.c | 232 + third-party/curl/tests/tunit/tool1621.c | 84 + third-party/curl/tests/tunit/tool1622.c | 98 + third-party/curl/tests/tunit/tool1623.c | 125 + third-party/curl/tests/tunit/tool1720.c | 79 + third-party/curl/tests/unit/.gitignore | 3 +- third-party/curl/tests/unit/CMakeLists.txt | 51 +- third-party/curl/tests/unit/Makefile.am | 47 +- third-party/curl/tests/unit/Makefile.inc | 131 +- third-party/curl/tests/unit/README.md | 84 +- third-party/curl/tests/unit/curlcheck.h | 113 - third-party/curl/tests/unit/unit1300.c | 219 +- third-party/curl/tests/unit/unit1302.c | 331 +- third-party/curl/tests/unit/unit1303.c | 160 +- third-party/curl/tests/unit/unit1304.c | 216 +- third-party/curl/tests/unit/unit1305.c | 71 +- third-party/curl/tests/unit/unit1307.c | 484 +- third-party/curl/tests/unit/unit1308.c | 98 - third-party/curl/tests/unit/unit1309.c | 81 +- third-party/curl/tests/unit/unit1323.c | 61 +- third-party/curl/tests/unit/unit1330.c | 25 +- third-party/curl/tests/unit/unit1394.c | 133 - third-party/curl/tests/unit/unit1395.c | 148 +- third-party/curl/tests/unit/unit1396.c | 110 +- third-party/curl/tests/unit/unit1397.c | 158 +- third-party/curl/tests/unit/unit1398.c | 241 +- third-party/curl/tests/unit/unit1399.c | 96 +- third-party/curl/tests/unit/unit1600.c | 61 +- third-party/curl/tests/unit/unit1601.c | 36 +- third-party/curl/tests/unit/unit1602.c | 53 +- third-party/curl/tests/unit/unit1603.c | 67 +- third-party/curl/tests/unit/unit1604.c | 358 - third-party/curl/tests/unit/unit1605.c | 31 +- third-party/curl/tests/unit/unit1606.c | 57 +- third-party/curl/tests/unit/unit1607.c | 235 +- third-party/curl/tests/unit/unit1608.c | 47 +- third-party/curl/tests/unit/unit1609.c | 195 +- third-party/curl/tests/unit/unit1610.c | 45 +- third-party/curl/tests/unit/unit1611.c | 38 +- third-party/curl/tests/unit/unit1612.c | 52 +- third-party/curl/tests/unit/unit1614.c | 249 +- third-party/curl/tests/unit/unit1615.c | 147 + third-party/curl/tests/unit/unit1616.c | 85 + third-party/curl/tests/unit/unit1620.c | 119 +- third-party/curl/tests/unit/unit1621.c | 81 - third-party/curl/tests/unit/unit1625.c | 135 + third-party/curl/tests/unit/unit1626.c | 129 + third-party/curl/tests/unit/unit1627.c | 104 + third-party/curl/tests/unit/unit1636.c | 82 + third-party/curl/tests/unit/unit1650.c | 228 +- third-party/curl/tests/unit/unit1651.c | 679 +- third-party/curl/tests/unit/unit1652.c | 159 +- third-party/curl/tests/unit/unit1653.c | 115 +- third-party/curl/tests/unit/unit1654.c | 108 +- third-party/curl/tests/unit/unit1655.c | 274 +- third-party/curl/tests/unit/unit1656.c | 125 + third-party/curl/tests/unit/unit1657.c | 125 + third-party/curl/tests/unit/unit1658.c | 565 ++ third-party/curl/tests/unit/unit1660.c | 181 +- third-party/curl/tests/unit/unit1661.c | 57 +- third-party/curl/tests/unit/unit1663.c | 90 + third-party/curl/tests/unit/unit1664.c | 489 ++ third-party/curl/tests/unit/unit1666.c | 202 + third-party/curl/tests/unit/unit1667.c | 335 + third-party/curl/tests/unit/unit1668.c | 177 + third-party/curl/tests/unit/unit1669.c | 58 + third-party/curl/tests/unit/unit1674.c | 85 + third-party/curl/tests/unit/unit1675.c | 443 ++ third-party/curl/tests/unit/unit1676.c | 119 + third-party/curl/tests/unit/unit1979.c | 142 + third-party/curl/tests/unit/unit1980.c | 117 + third-party/curl/tests/unit/unit2413.c | 112 + third-party/curl/tests/unit/unit2600.c | 311 +- third-party/curl/tests/unit/unit2601.c | 131 +- third-party/curl/tests/unit/unit2602.c | 81 +- third-party/curl/tests/unit/unit2603.c | 202 +- third-party/curl/tests/unit/unit2604.c | 115 + third-party/curl/tests/unit/unit2605.c | 112 + third-party/curl/tests/unit/unit3200.c | 248 +- third-party/curl/tests/unit/unit3205.c | 614 ++ third-party/curl/tests/unit/unit3211.c | 149 + third-party/curl/tests/unit/unit3212.c | 134 + third-party/curl/tests/unit/unit3213.c | 123 + third-party/curl/tests/unit/unit3214.c | 85 + third-party/curl/tests/unit/unit3216.c | 103 + third-party/curl/tests/unit/unit3219.c | 43 + third-party/curl/tests/unit/unit3300.c | 162 + third-party/curl/tests/unit/unit3301.c | 142 + third-party/curl/tests/unit/unit3302.c | 89 + third-party/curl/tests/unit/unit3303.c | 140 + third-party/curl/tests/unit/unit3304.c | 166 + third-party/curl/tests/unit/unit3400.c | 261 + third-party/curl/tests/util.py | 21 +- third-party/curl/tests/valgrind.pm | 3 +- third-party/curl/tests/valgrind.supp | 37 +- third-party/curl/tests/version-scan.pl | 94 - third-party/curl/winbuild/.gitignore | 6 - third-party/curl/winbuild/Makefile.vc | 310 - third-party/curl/winbuild/MakefileBuild.vc | 714 -- third-party/curl/winbuild/README.md | 199 - third-party/curl/winbuild/gen_resp_file.bat | 34 - third-party/curl/winbuild/makedebug.cmd | 36 - vendor.yaml | 2 +- 5480 files changed, 345923 insertions(+), 288294 deletions(-) delete mode 100644 third-party/curl/.azure-pipelines.yml delete mode 100644 third-party/curl/.cirrus.yml create mode 100644 third-party/curl/.clang-tidy.yml delete mode 100644 third-party/curl/.dcignore create mode 100644 third-party/curl/.editorconfig create mode 100644 third-party/curl/.github/ISSUE_TEMPLATE/docs.yml create mode 100644 third-party/curl/.github/dependabot.yml create mode 100644 third-party/curl/.github/pull_request_template.md create mode 100644 third-party/curl/.github/scripts/cleancmd.pl delete mode 100644 third-party/curl/.github/scripts/cleanspell.pl create mode 100644 third-party/curl/.github/scripts/cmp-config.pl create mode 100644 third-party/curl/.github/scripts/cmp-pkg-config.sh create mode 100644 third-party/curl/.github/scripts/codespell-ignore.words create mode 100644 third-party/curl/.github/scripts/codespell.sh create mode 100644 third-party/curl/.github/scripts/distfiles.sh create mode 100644 third-party/curl/.github/scripts/pyspelling.words create mode 100644 third-party/curl/.github/scripts/pyspelling.yaml create mode 100644 third-party/curl/.github/scripts/randcurl.pl create mode 100644 third-party/curl/.github/scripts/requirements-docs.txt create mode 100644 third-party/curl/.github/scripts/requirements-proselint.txt create mode 100644 third-party/curl/.github/scripts/requirements.txt create mode 100644 third-party/curl/.github/scripts/shellcheck-ci.sh create mode 100644 third-party/curl/.github/scripts/shellcheck.sh create mode 100644 third-party/curl/.github/scripts/spellcheck.curl delete mode 100644 third-party/curl/.github/scripts/spellcheck.words delete mode 100644 third-party/curl/.github/scripts/spellcheck.yaml create mode 100644 third-party/curl/.github/scripts/trimmarkdownheader.pl create mode 100644 third-party/curl/.github/scripts/typos.sh create mode 100644 third-party/curl/.github/scripts/typos.toml create mode 100644 third-party/curl/.github/scripts/verify-examples.pl create mode 100644 third-party/curl/.github/scripts/verify-synopsis.pl create mode 100644 third-party/curl/.github/scripts/yamlcheck.sh create mode 100644 third-party/curl/.github/scripts/yamlcheck.yaml delete mode 100644 third-party/curl/.github/workflows/awslc.yml create mode 100644 third-party/curl/.github/workflows/checkdocs.yml create mode 100644 third-party/curl/.github/workflows/checksrc.yml create mode 100644 third-party/curl/.github/workflows/checkurls.yml delete mode 100644 third-party/curl/.github/workflows/codeql-analysis.yml create mode 100644 third-party/curl/.github/workflows/codeql.yml create mode 100644 third-party/curl/.github/workflows/configure-vs-cmake.yml create mode 100644 third-party/curl/.github/workflows/curl-for-win.yml create mode 100644 third-party/curl/.github/workflows/distcheck.yml delete mode 100644 third-party/curl/.github/workflows/hacktoberfest-accepted.yml create mode 100644 third-party/curl/.github/workflows/http3-linux.yml delete mode 100644 third-party/curl/.github/workflows/linkcheck.yml create mode 100644 third-party/curl/.github/workflows/linux-old.yml delete mode 100644 third-party/curl/.github/workflows/linux32.yml delete mode 100644 third-party/curl/.github/workflows/ngtcp2-linux.yml create mode 100644 third-party/curl/.github/workflows/non-native.yml delete mode 100644 third-party/curl/.github/workflows/proselint.yml delete mode 100644 third-party/curl/.github/workflows/quiche-linux.yml delete mode 100644 third-party/curl/.github/workflows/reuse.yml delete mode 100644 third-party/curl/.github/workflows/spellcheck.yml delete mode 100644 third-party/curl/.github/workflows/torture.yml create mode 100644 third-party/curl/.github/workflows/windows.yml delete mode 100644 third-party/curl/.github/workflows/wolfssl.yml delete mode 100644 third-party/curl/.reuse/dep5 delete mode 100644 third-party/curl/CHANGES create mode 100644 third-party/curl/CHANGES.md delete mode 100644 third-party/curl/CMake/CMakeConfigurableFile.in delete mode 100644 third-party/curl/CMake/FindBearSSL.cmake create mode 100644 third-party/curl/CMake/FindGnuTLS.cmake create mode 100644 third-party/curl/CMake/FindLDAP.cmake create mode 100644 third-party/curl/CMake/FindLibbacktrace.cmake create mode 100644 third-party/curl/CMake/FindLibgsasl.cmake create mode 100644 third-party/curl/CMake/FindLibidn2.cmake create mode 100644 third-party/curl/CMake/FindLibssh.cmake create mode 100644 third-party/curl/CMake/FindLibuv.cmake delete mode 100644 third-party/curl/CMake/FindMSH3.cmake create mode 100644 third-party/curl/CMake/FindNettle.cmake create mode 100644 third-party/curl/CMake/FindRustls.cmake delete mode 100644 third-party/curl/CMake/Platforms/WindowsCache.cmake delete mode 100644 third-party/curl/CMake/cmake_uninstall.cmake.in create mode 100644 third-party/curl/CMake/cmake_uninstall.in.cmake delete mode 100644 third-party/curl/CMake/curl-config.cmake.in create mode 100644 third-party/curl/CMake/curl-config.in.cmake create mode 100644 third-party/curl/CMake/unix-cache.cmake create mode 100644 third-party/curl/CMake/win32-cache.cmake create mode 100644 third-party/curl/Dockerfile delete mode 100644 third-party/curl/GIT-INFO create mode 100644 third-party/curl/GIT-INFO.md delete mode 100644 third-party/curl/LICENSES/BSD-3-Clause.txt delete mode 100644 third-party/curl/MacOSX-Framework delete mode 100644 third-party/curl/Makefile.dist create mode 100644 third-party/curl/REUSE.toml create mode 100644 third-party/curl/appveyor.sh delete mode 100644 third-party/curl/buildconf delete mode 100644 third-party/curl/buildconf.bat delete mode 100644 third-party/curl/docs/BUFQ.md delete mode 100644 third-party/curl/docs/CHECKSRC.md create mode 100644 third-party/curl/docs/CIPHERS-TLS12.md delete mode 100644 third-party/curl/docs/CONNECTION-FILTERS.md create mode 100644 third-party/curl/docs/CURLDOWN.md create mode 100644 third-party/curl/docs/DISTROS.md delete mode 100644 third-party/curl/docs/DYNBUF.md create mode 100644 third-party/curl/docs/ECH.md delete mode 100644 third-party/curl/docs/FAQ create mode 100644 third-party/curl/docs/FAQ.md delete mode 100644 third-party/curl/docs/HTTP2.md create mode 100644 third-party/curl/docs/HTTPSRR.md delete mode 100644 third-party/curl/docs/HYPER.md create mode 100644 third-party/curl/docs/INFRASTRUCTURE.md create mode 100644 third-party/curl/docs/INSTALL-CMAKE.md delete mode 100644 third-party/curl/docs/INSTALL.cmake create mode 100644 third-party/curl/docs/IPFS.md delete mode 100644 third-party/curl/docs/KNOWN_BUGS create mode 100644 third-party/curl/docs/KNOWN_BUGS.md create mode 100644 third-party/curl/docs/KNOWN_RISKS.md delete mode 100644 third-party/curl/docs/MAIL-ETIQUETTE create mode 100644 third-party/curl/docs/MAIL-ETIQUETTE.md delete mode 100644 third-party/curl/docs/MQTT.md delete mode 100644 third-party/curl/docs/PARALLEL-TRANSFERS.md delete mode 100644 third-party/curl/docs/SECURITY-PROCESS.md create mode 100644 third-party/curl/docs/SPONSORS.md delete mode 100644 third-party/curl/docs/TODO create mode 100644 third-party/curl/docs/TODO.md create mode 100644 third-party/curl/docs/VERIFY.md create mode 100644 third-party/curl/docs/VULN-DISCLOSURE-POLICY.md create mode 100644 third-party/curl/docs/cmdline-opts/.gitignore create mode 100644 third-party/curl/docs/cmdline-opts/_AUTHORS.md create mode 100644 third-party/curl/docs/cmdline-opts/_BUGS.md create mode 100644 third-party/curl/docs/cmdline-opts/_DESCRIPTION.md create mode 100644 third-party/curl/docs/cmdline-opts/_ENVIRONMENT.md create mode 100644 third-party/curl/docs/cmdline-opts/_EXITCODES.md create mode 100644 third-party/curl/docs/cmdline-opts/_FILES.md create mode 100644 third-party/curl/docs/cmdline-opts/_GLOBBING.md create mode 100644 third-party/curl/docs/cmdline-opts/_NAME.md create mode 100644 third-party/curl/docs/cmdline-opts/_OPTIONS.md create mode 100644 third-party/curl/docs/cmdline-opts/_OUTPUT.md create mode 100644 third-party/curl/docs/cmdline-opts/_PROGRESS.md create mode 100644 third-party/curl/docs/cmdline-opts/_PROTOCOLS.md create mode 100644 third-party/curl/docs/cmdline-opts/_PROXYPREFIX.md create mode 100644 third-party/curl/docs/cmdline-opts/_SEEALSO.md create mode 100644 third-party/curl/docs/cmdline-opts/_SYNOPSIS.md create mode 100644 third-party/curl/docs/cmdline-opts/_URL.md create mode 100644 third-party/curl/docs/cmdline-opts/_VARIABLES.md create mode 100644 third-party/curl/docs/cmdline-opts/_VERSION.md create mode 100644 third-party/curl/docs/cmdline-opts/_WWW.md delete mode 100644 third-party/curl/docs/cmdline-opts/abstract-unix-socket.d create mode 100644 third-party/curl/docs/cmdline-opts/abstract-unix-socket.md delete mode 100644 third-party/curl/docs/cmdline-opts/alt-svc.d create mode 100644 third-party/curl/docs/cmdline-opts/alt-svc.md delete mode 100644 third-party/curl/docs/cmdline-opts/anyauth.d create mode 100644 third-party/curl/docs/cmdline-opts/anyauth.md delete mode 100644 third-party/curl/docs/cmdline-opts/append.d create mode 100644 third-party/curl/docs/cmdline-opts/append.md delete mode 100644 third-party/curl/docs/cmdline-opts/aws-sigv4.d create mode 100644 third-party/curl/docs/cmdline-opts/aws-sigv4.md delete mode 100644 third-party/curl/docs/cmdline-opts/basic.d create mode 100644 third-party/curl/docs/cmdline-opts/basic.md delete mode 100644 third-party/curl/docs/cmdline-opts/ca-native.d create mode 100644 third-party/curl/docs/cmdline-opts/ca-native.md delete mode 100644 third-party/curl/docs/cmdline-opts/cacert.d create mode 100644 third-party/curl/docs/cmdline-opts/cacert.md delete mode 100644 third-party/curl/docs/cmdline-opts/capath.d create mode 100644 third-party/curl/docs/cmdline-opts/capath.md delete mode 100644 third-party/curl/docs/cmdline-opts/cert-status.d create mode 100644 third-party/curl/docs/cmdline-opts/cert-status.md delete mode 100644 third-party/curl/docs/cmdline-opts/cert-type.d create mode 100644 third-party/curl/docs/cmdline-opts/cert-type.md delete mode 100644 third-party/curl/docs/cmdline-opts/cert.d create mode 100644 third-party/curl/docs/cmdline-opts/cert.md delete mode 100644 third-party/curl/docs/cmdline-opts/ciphers.d create mode 100644 third-party/curl/docs/cmdline-opts/ciphers.md delete mode 100644 third-party/curl/docs/cmdline-opts/compressed-ssh.d create mode 100644 third-party/curl/docs/cmdline-opts/compressed-ssh.md delete mode 100644 third-party/curl/docs/cmdline-opts/compressed.d create mode 100644 third-party/curl/docs/cmdline-opts/compressed.md delete mode 100644 third-party/curl/docs/cmdline-opts/config.d create mode 100644 third-party/curl/docs/cmdline-opts/config.md delete mode 100644 third-party/curl/docs/cmdline-opts/connect-timeout.d create mode 100644 third-party/curl/docs/cmdline-opts/connect-timeout.md delete mode 100644 third-party/curl/docs/cmdline-opts/connect-to.d create mode 100644 third-party/curl/docs/cmdline-opts/connect-to.md delete mode 100644 third-party/curl/docs/cmdline-opts/continue-at.d create mode 100644 third-party/curl/docs/cmdline-opts/continue-at.md delete mode 100644 third-party/curl/docs/cmdline-opts/cookie-jar.d create mode 100644 third-party/curl/docs/cmdline-opts/cookie-jar.md delete mode 100644 third-party/curl/docs/cmdline-opts/cookie.d create mode 100644 third-party/curl/docs/cmdline-opts/cookie.md delete mode 100644 third-party/curl/docs/cmdline-opts/create-dirs.d create mode 100644 third-party/curl/docs/cmdline-opts/create-dirs.md delete mode 100644 third-party/curl/docs/cmdline-opts/create-file-mode.d create mode 100644 third-party/curl/docs/cmdline-opts/create-file-mode.md delete mode 100644 third-party/curl/docs/cmdline-opts/crlf.d create mode 100644 third-party/curl/docs/cmdline-opts/crlf.md delete mode 100644 third-party/curl/docs/cmdline-opts/crlfile.d create mode 100644 third-party/curl/docs/cmdline-opts/crlfile.md delete mode 100644 third-party/curl/docs/cmdline-opts/curves.d create mode 100644 third-party/curl/docs/cmdline-opts/curves.md delete mode 100644 third-party/curl/docs/cmdline-opts/data-ascii.d create mode 100644 third-party/curl/docs/cmdline-opts/data-ascii.md delete mode 100644 third-party/curl/docs/cmdline-opts/data-binary.d create mode 100644 third-party/curl/docs/cmdline-opts/data-binary.md delete mode 100644 third-party/curl/docs/cmdline-opts/data-raw.d create mode 100644 third-party/curl/docs/cmdline-opts/data-raw.md delete mode 100644 third-party/curl/docs/cmdline-opts/data-urlencode.d create mode 100644 third-party/curl/docs/cmdline-opts/data-urlencode.md delete mode 100644 third-party/curl/docs/cmdline-opts/data.d create mode 100644 third-party/curl/docs/cmdline-opts/data.md delete mode 100644 third-party/curl/docs/cmdline-opts/delegation.d create mode 100644 third-party/curl/docs/cmdline-opts/delegation.md delete mode 100644 third-party/curl/docs/cmdline-opts/digest.d create mode 100644 third-party/curl/docs/cmdline-opts/digest.md delete mode 100644 third-party/curl/docs/cmdline-opts/disable-eprt.d create mode 100644 third-party/curl/docs/cmdline-opts/disable-eprt.md delete mode 100644 third-party/curl/docs/cmdline-opts/disable-epsv.d create mode 100644 third-party/curl/docs/cmdline-opts/disable-epsv.md delete mode 100644 third-party/curl/docs/cmdline-opts/disable.d create mode 100644 third-party/curl/docs/cmdline-opts/disable.md delete mode 100644 third-party/curl/docs/cmdline-opts/disallow-username-in-url.d create mode 100644 third-party/curl/docs/cmdline-opts/disallow-username-in-url.md delete mode 100644 third-party/curl/docs/cmdline-opts/dns-interface.d create mode 100644 third-party/curl/docs/cmdline-opts/dns-interface.md delete mode 100644 third-party/curl/docs/cmdline-opts/dns-ipv4-addr.d create mode 100644 third-party/curl/docs/cmdline-opts/dns-ipv4-addr.md delete mode 100644 third-party/curl/docs/cmdline-opts/dns-ipv6-addr.d create mode 100644 third-party/curl/docs/cmdline-opts/dns-ipv6-addr.md delete mode 100644 third-party/curl/docs/cmdline-opts/dns-servers.d create mode 100644 third-party/curl/docs/cmdline-opts/dns-servers.md delete mode 100644 third-party/curl/docs/cmdline-opts/doh-cert-status.d create mode 100644 third-party/curl/docs/cmdline-opts/doh-cert-status.md delete mode 100644 third-party/curl/docs/cmdline-opts/doh-insecure.d create mode 100644 third-party/curl/docs/cmdline-opts/doh-insecure.md delete mode 100644 third-party/curl/docs/cmdline-opts/doh-url.d create mode 100644 third-party/curl/docs/cmdline-opts/doh-url.md create mode 100644 third-party/curl/docs/cmdline-opts/dump-ca-embed.md delete mode 100644 third-party/curl/docs/cmdline-opts/dump-header.d create mode 100644 third-party/curl/docs/cmdline-opts/dump-header.md create mode 100644 third-party/curl/docs/cmdline-opts/ech.md delete mode 100644 third-party/curl/docs/cmdline-opts/egd-file.d create mode 100644 third-party/curl/docs/cmdline-opts/egd-file.md delete mode 100644 third-party/curl/docs/cmdline-opts/engine.d create mode 100644 third-party/curl/docs/cmdline-opts/engine.md delete mode 100644 third-party/curl/docs/cmdline-opts/etag-compare.d create mode 100644 third-party/curl/docs/cmdline-opts/etag-compare.md delete mode 100644 third-party/curl/docs/cmdline-opts/etag-save.d create mode 100644 third-party/curl/docs/cmdline-opts/etag-save.md delete mode 100644 third-party/curl/docs/cmdline-opts/expect100-timeout.d create mode 100644 third-party/curl/docs/cmdline-opts/expect100-timeout.md delete mode 100644 third-party/curl/docs/cmdline-opts/fail-early.d create mode 100644 third-party/curl/docs/cmdline-opts/fail-early.md delete mode 100644 third-party/curl/docs/cmdline-opts/fail-with-body.d create mode 100644 third-party/curl/docs/cmdline-opts/fail-with-body.md delete mode 100644 third-party/curl/docs/cmdline-opts/fail.d create mode 100644 third-party/curl/docs/cmdline-opts/fail.md delete mode 100644 third-party/curl/docs/cmdline-opts/false-start.d create mode 100644 third-party/curl/docs/cmdline-opts/false-start.md create mode 100644 third-party/curl/docs/cmdline-opts/follow.md delete mode 100644 third-party/curl/docs/cmdline-opts/form-escape.d create mode 100644 third-party/curl/docs/cmdline-opts/form-escape.md delete mode 100644 third-party/curl/docs/cmdline-opts/form-string.d create mode 100644 third-party/curl/docs/cmdline-opts/form-string.md delete mode 100644 third-party/curl/docs/cmdline-opts/form.d create mode 100644 third-party/curl/docs/cmdline-opts/form.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-account.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-account.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-alternative-to-user.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-alternative-to-user.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-create-dirs.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-create-dirs.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-method.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-method.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-pasv.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-pasv.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-port.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-port.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-pret.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-pret.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-skip-pasv-ip.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-skip-pasv-ip.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-ssl-ccc-mode.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-ssl-ccc-mode.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-ssl-ccc.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-ssl-ccc.md delete mode 100644 third-party/curl/docs/cmdline-opts/ftp-ssl-control.d create mode 100644 third-party/curl/docs/cmdline-opts/ftp-ssl-control.md delete mode 100644 third-party/curl/docs/cmdline-opts/gen.pl delete mode 100644 third-party/curl/docs/cmdline-opts/get.d create mode 100644 third-party/curl/docs/cmdline-opts/get.md delete mode 100644 third-party/curl/docs/cmdline-opts/globoff.d create mode 100644 third-party/curl/docs/cmdline-opts/globoff.md delete mode 100644 third-party/curl/docs/cmdline-opts/happy-eyeballs-timeout-ms.d create mode 100644 third-party/curl/docs/cmdline-opts/happy-eyeballs-timeout-ms.md delete mode 100644 third-party/curl/docs/cmdline-opts/haproxy-clientip.d create mode 100644 third-party/curl/docs/cmdline-opts/haproxy-clientip.md delete mode 100644 third-party/curl/docs/cmdline-opts/haproxy-protocol.d create mode 100644 third-party/curl/docs/cmdline-opts/haproxy-protocol.md delete mode 100644 third-party/curl/docs/cmdline-opts/head.d create mode 100644 third-party/curl/docs/cmdline-opts/head.md delete mode 100644 third-party/curl/docs/cmdline-opts/header.d create mode 100644 third-party/curl/docs/cmdline-opts/header.md delete mode 100644 third-party/curl/docs/cmdline-opts/help.d create mode 100644 third-party/curl/docs/cmdline-opts/help.md delete mode 100644 third-party/curl/docs/cmdline-opts/hostpubmd5.d create mode 100644 third-party/curl/docs/cmdline-opts/hostpubmd5.md delete mode 100644 third-party/curl/docs/cmdline-opts/hostpubsha256.d create mode 100644 third-party/curl/docs/cmdline-opts/hostpubsha256.md delete mode 100644 third-party/curl/docs/cmdline-opts/hsts.d create mode 100644 third-party/curl/docs/cmdline-opts/hsts.md delete mode 100644 third-party/curl/docs/cmdline-opts/http0.9.d create mode 100644 third-party/curl/docs/cmdline-opts/http0.9.md delete mode 100644 third-party/curl/docs/cmdline-opts/http1.0.d create mode 100644 third-party/curl/docs/cmdline-opts/http1.0.md delete mode 100644 third-party/curl/docs/cmdline-opts/http1.1.d create mode 100644 third-party/curl/docs/cmdline-opts/http1.1.md delete mode 100644 third-party/curl/docs/cmdline-opts/http2-prior-knowledge.d create mode 100644 third-party/curl/docs/cmdline-opts/http2-prior-knowledge.md delete mode 100644 third-party/curl/docs/cmdline-opts/http2.d create mode 100644 third-party/curl/docs/cmdline-opts/http2.md delete mode 100644 third-party/curl/docs/cmdline-opts/http3-only.d create mode 100644 third-party/curl/docs/cmdline-opts/http3-only.md delete mode 100644 third-party/curl/docs/cmdline-opts/http3.d create mode 100644 third-party/curl/docs/cmdline-opts/http3.md delete mode 100644 third-party/curl/docs/cmdline-opts/ignore-content-length.d create mode 100644 third-party/curl/docs/cmdline-opts/ignore-content-length.md delete mode 100644 third-party/curl/docs/cmdline-opts/include.d delete mode 100644 third-party/curl/docs/cmdline-opts/insecure.d create mode 100644 third-party/curl/docs/cmdline-opts/insecure.md delete mode 100644 third-party/curl/docs/cmdline-opts/interface.d create mode 100644 third-party/curl/docs/cmdline-opts/interface.md create mode 100644 third-party/curl/docs/cmdline-opts/ip-tos.md create mode 100644 third-party/curl/docs/cmdline-opts/ipfs-gateway.md delete mode 100644 third-party/curl/docs/cmdline-opts/ipv4.d create mode 100644 third-party/curl/docs/cmdline-opts/ipv4.md delete mode 100644 third-party/curl/docs/cmdline-opts/ipv6.d create mode 100644 third-party/curl/docs/cmdline-opts/ipv6.md delete mode 100644 third-party/curl/docs/cmdline-opts/json.d create mode 100644 third-party/curl/docs/cmdline-opts/json.md delete mode 100644 third-party/curl/docs/cmdline-opts/junk-session-cookies.d create mode 100644 third-party/curl/docs/cmdline-opts/junk-session-cookies.md create mode 100644 third-party/curl/docs/cmdline-opts/keepalive-cnt.md delete mode 100644 third-party/curl/docs/cmdline-opts/keepalive-time.d create mode 100644 third-party/curl/docs/cmdline-opts/keepalive-time.md delete mode 100644 third-party/curl/docs/cmdline-opts/key-type.d create mode 100644 third-party/curl/docs/cmdline-opts/key-type.md delete mode 100644 third-party/curl/docs/cmdline-opts/key.d create mode 100644 third-party/curl/docs/cmdline-opts/key.md create mode 100644 third-party/curl/docs/cmdline-opts/knownhosts.md delete mode 100644 third-party/curl/docs/cmdline-opts/krb.d create mode 100644 third-party/curl/docs/cmdline-opts/krb.md delete mode 100644 third-party/curl/docs/cmdline-opts/libcurl.d create mode 100644 third-party/curl/docs/cmdline-opts/libcurl.md delete mode 100644 third-party/curl/docs/cmdline-opts/limit-rate.d create mode 100644 third-party/curl/docs/cmdline-opts/limit-rate.md delete mode 100644 third-party/curl/docs/cmdline-opts/list-only.d create mode 100644 third-party/curl/docs/cmdline-opts/list-only.md delete mode 100644 third-party/curl/docs/cmdline-opts/local-port.d create mode 100644 third-party/curl/docs/cmdline-opts/local-port.md delete mode 100644 third-party/curl/docs/cmdline-opts/location-trusted.d create mode 100644 third-party/curl/docs/cmdline-opts/location-trusted.md delete mode 100644 third-party/curl/docs/cmdline-opts/location.d create mode 100644 third-party/curl/docs/cmdline-opts/location.md delete mode 100644 third-party/curl/docs/cmdline-opts/login-options.d create mode 100644 third-party/curl/docs/cmdline-opts/login-options.md delete mode 100644 third-party/curl/docs/cmdline-opts/mail-auth.d create mode 100644 third-party/curl/docs/cmdline-opts/mail-auth.md delete mode 100644 third-party/curl/docs/cmdline-opts/mail-from.d create mode 100644 third-party/curl/docs/cmdline-opts/mail-from.md delete mode 100644 third-party/curl/docs/cmdline-opts/mail-rcpt-allowfails.d create mode 100644 third-party/curl/docs/cmdline-opts/mail-rcpt-allowfails.md delete mode 100644 third-party/curl/docs/cmdline-opts/mail-rcpt.d create mode 100644 third-party/curl/docs/cmdline-opts/mail-rcpt.md create mode 100644 third-party/curl/docs/cmdline-opts/mainpage.idx delete mode 100644 third-party/curl/docs/cmdline-opts/manual.d create mode 100644 third-party/curl/docs/cmdline-opts/manual.md delete mode 100644 third-party/curl/docs/cmdline-opts/max-filesize.d create mode 100644 third-party/curl/docs/cmdline-opts/max-filesize.md delete mode 100644 third-party/curl/docs/cmdline-opts/max-redirs.d create mode 100644 third-party/curl/docs/cmdline-opts/max-redirs.md delete mode 100644 third-party/curl/docs/cmdline-opts/max-time.d create mode 100644 third-party/curl/docs/cmdline-opts/max-time.md delete mode 100644 third-party/curl/docs/cmdline-opts/metalink.d create mode 100644 third-party/curl/docs/cmdline-opts/metalink.md create mode 100644 third-party/curl/docs/cmdline-opts/mptcp.md delete mode 100644 third-party/curl/docs/cmdline-opts/negotiate.d create mode 100644 third-party/curl/docs/cmdline-opts/negotiate.md delete mode 100644 third-party/curl/docs/cmdline-opts/netrc-file.d create mode 100644 third-party/curl/docs/cmdline-opts/netrc-file.md delete mode 100644 third-party/curl/docs/cmdline-opts/netrc-optional.d create mode 100644 third-party/curl/docs/cmdline-opts/netrc-optional.md delete mode 100644 third-party/curl/docs/cmdline-opts/netrc.d create mode 100644 third-party/curl/docs/cmdline-opts/netrc.md delete mode 100644 third-party/curl/docs/cmdline-opts/next.d create mode 100644 third-party/curl/docs/cmdline-opts/next.md delete mode 100644 third-party/curl/docs/cmdline-opts/no-alpn.d create mode 100644 third-party/curl/docs/cmdline-opts/no-alpn.md delete mode 100644 third-party/curl/docs/cmdline-opts/no-buffer.d create mode 100644 third-party/curl/docs/cmdline-opts/no-buffer.md delete mode 100644 third-party/curl/docs/cmdline-opts/no-clobber.d create mode 100644 third-party/curl/docs/cmdline-opts/no-clobber.md delete mode 100644 third-party/curl/docs/cmdline-opts/no-keepalive.d create mode 100644 third-party/curl/docs/cmdline-opts/no-keepalive.md delete mode 100644 third-party/curl/docs/cmdline-opts/no-npn.d create mode 100644 third-party/curl/docs/cmdline-opts/no-npn.md delete mode 100644 third-party/curl/docs/cmdline-opts/no-progress-meter.d create mode 100644 third-party/curl/docs/cmdline-opts/no-progress-meter.md delete mode 100644 third-party/curl/docs/cmdline-opts/no-sessionid.d create mode 100644 third-party/curl/docs/cmdline-opts/no-sessionid.md delete mode 100644 third-party/curl/docs/cmdline-opts/noproxy.d create mode 100644 third-party/curl/docs/cmdline-opts/noproxy.md delete mode 100644 third-party/curl/docs/cmdline-opts/ntlm-wb.d create mode 100644 third-party/curl/docs/cmdline-opts/ntlm-wb.md delete mode 100644 third-party/curl/docs/cmdline-opts/ntlm.d create mode 100644 third-party/curl/docs/cmdline-opts/ntlm.md delete mode 100644 third-party/curl/docs/cmdline-opts/oauth2-bearer.d create mode 100644 third-party/curl/docs/cmdline-opts/oauth2-bearer.md create mode 100644 third-party/curl/docs/cmdline-opts/out-null.md delete mode 100644 third-party/curl/docs/cmdline-opts/output-dir.d create mode 100644 third-party/curl/docs/cmdline-opts/output-dir.md delete mode 100644 third-party/curl/docs/cmdline-opts/output.d create mode 100644 third-party/curl/docs/cmdline-opts/output.md delete mode 100644 third-party/curl/docs/cmdline-opts/page-footer delete mode 100644 third-party/curl/docs/cmdline-opts/page-header delete mode 100644 third-party/curl/docs/cmdline-opts/parallel-immediate.d create mode 100644 third-party/curl/docs/cmdline-opts/parallel-immediate.md create mode 100644 third-party/curl/docs/cmdline-opts/parallel-max-host.md delete mode 100644 third-party/curl/docs/cmdline-opts/parallel-max.d create mode 100644 third-party/curl/docs/cmdline-opts/parallel-max.md delete mode 100644 third-party/curl/docs/cmdline-opts/parallel.d create mode 100644 third-party/curl/docs/cmdline-opts/parallel.md delete mode 100644 third-party/curl/docs/cmdline-opts/pass.d create mode 100644 third-party/curl/docs/cmdline-opts/pass.md delete mode 100644 third-party/curl/docs/cmdline-opts/path-as-is.d create mode 100644 third-party/curl/docs/cmdline-opts/path-as-is.md delete mode 100644 third-party/curl/docs/cmdline-opts/pinnedpubkey.d create mode 100644 third-party/curl/docs/cmdline-opts/pinnedpubkey.md delete mode 100644 third-party/curl/docs/cmdline-opts/post301.d create mode 100644 third-party/curl/docs/cmdline-opts/post301.md delete mode 100644 third-party/curl/docs/cmdline-opts/post302.d create mode 100644 third-party/curl/docs/cmdline-opts/post302.md delete mode 100644 third-party/curl/docs/cmdline-opts/post303.d create mode 100644 third-party/curl/docs/cmdline-opts/post303.md delete mode 100644 third-party/curl/docs/cmdline-opts/preproxy.d create mode 100644 third-party/curl/docs/cmdline-opts/preproxy.md delete mode 100644 third-party/curl/docs/cmdline-opts/progress-bar.d create mode 100644 third-party/curl/docs/cmdline-opts/progress-bar.md delete mode 100644 third-party/curl/docs/cmdline-opts/proto-default.d create mode 100644 third-party/curl/docs/cmdline-opts/proto-default.md delete mode 100644 third-party/curl/docs/cmdline-opts/proto-redir.d create mode 100644 third-party/curl/docs/cmdline-opts/proto-redir.md delete mode 100644 third-party/curl/docs/cmdline-opts/proto.d create mode 100644 third-party/curl/docs/cmdline-opts/proto.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-anyauth.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-anyauth.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-basic.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-basic.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-ca-native.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-ca-native.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-cacert.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-cacert.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-capath.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-capath.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-cert-type.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-cert-type.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-cert.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-cert.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-ciphers.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-ciphers.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-crlfile.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-crlfile.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-digest.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-digest.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-header.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-header.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-http2.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-http2.md create mode 100644 third-party/curl/docs/cmdline-opts/proxy-http3.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-insecure.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-insecure.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-key-type.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-key-type.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-key.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-key.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-negotiate.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-negotiate.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-ntlm.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-ntlm.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-pass.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-pass.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-pinnedpubkey.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-pinnedpubkey.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-service-name.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-service-name.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-ssl-allow-beast.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-ssl-allow-beast.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-ssl-auto-client-cert.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-ssl-auto-client-cert.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-tls13-ciphers.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-tls13-ciphers.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-tlsauthtype.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-tlsauthtype.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-tlspassword.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-tlspassword.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-tlsuser.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-tlsuser.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-tlsv1.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-tlsv1.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy-user.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy-user.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxy1.0.d create mode 100644 third-party/curl/docs/cmdline-opts/proxy1.0.md delete mode 100644 third-party/curl/docs/cmdline-opts/proxytunnel.d create mode 100644 third-party/curl/docs/cmdline-opts/proxytunnel.md delete mode 100644 third-party/curl/docs/cmdline-opts/pubkey.d create mode 100644 third-party/curl/docs/cmdline-opts/pubkey.md delete mode 100644 third-party/curl/docs/cmdline-opts/quote.d create mode 100644 third-party/curl/docs/cmdline-opts/quote.md delete mode 100644 third-party/curl/docs/cmdline-opts/random-file.d create mode 100644 third-party/curl/docs/cmdline-opts/random-file.md delete mode 100644 third-party/curl/docs/cmdline-opts/range.d create mode 100644 third-party/curl/docs/cmdline-opts/range.md delete mode 100644 third-party/curl/docs/cmdline-opts/rate.d create mode 100644 third-party/curl/docs/cmdline-opts/rate.md delete mode 100644 third-party/curl/docs/cmdline-opts/raw.d create mode 100644 third-party/curl/docs/cmdline-opts/raw.md delete mode 100644 third-party/curl/docs/cmdline-opts/referer.d create mode 100644 third-party/curl/docs/cmdline-opts/referer.md delete mode 100644 third-party/curl/docs/cmdline-opts/remote-header-name.d create mode 100644 third-party/curl/docs/cmdline-opts/remote-header-name.md delete mode 100644 third-party/curl/docs/cmdline-opts/remote-name-all.d create mode 100644 third-party/curl/docs/cmdline-opts/remote-name-all.md delete mode 100644 third-party/curl/docs/cmdline-opts/remote-name.d create mode 100644 third-party/curl/docs/cmdline-opts/remote-name.md delete mode 100644 third-party/curl/docs/cmdline-opts/remote-time.d create mode 100644 third-party/curl/docs/cmdline-opts/remote-time.md delete mode 100644 third-party/curl/docs/cmdline-opts/remove-on-error.d create mode 100644 third-party/curl/docs/cmdline-opts/remove-on-error.md delete mode 100644 third-party/curl/docs/cmdline-opts/request-target.d create mode 100644 third-party/curl/docs/cmdline-opts/request-target.md delete mode 100644 third-party/curl/docs/cmdline-opts/request.d create mode 100644 third-party/curl/docs/cmdline-opts/request.md delete mode 100644 third-party/curl/docs/cmdline-opts/resolve.d create mode 100644 third-party/curl/docs/cmdline-opts/resolve.md delete mode 100644 third-party/curl/docs/cmdline-opts/retry-all-errors.d create mode 100644 third-party/curl/docs/cmdline-opts/retry-all-errors.md delete mode 100644 third-party/curl/docs/cmdline-opts/retry-connrefused.d create mode 100644 third-party/curl/docs/cmdline-opts/retry-connrefused.md delete mode 100644 third-party/curl/docs/cmdline-opts/retry-delay.d create mode 100644 third-party/curl/docs/cmdline-opts/retry-delay.md delete mode 100644 third-party/curl/docs/cmdline-opts/retry-max-time.d create mode 100644 third-party/curl/docs/cmdline-opts/retry-max-time.md delete mode 100644 third-party/curl/docs/cmdline-opts/retry.d create mode 100644 third-party/curl/docs/cmdline-opts/retry.md delete mode 100644 third-party/curl/docs/cmdline-opts/sasl-authzid.d create mode 100644 third-party/curl/docs/cmdline-opts/sasl-authzid.md delete mode 100644 third-party/curl/docs/cmdline-opts/sasl-ir.d create mode 100644 third-party/curl/docs/cmdline-opts/sasl-ir.md delete mode 100644 third-party/curl/docs/cmdline-opts/service-name.d create mode 100644 third-party/curl/docs/cmdline-opts/service-name.md delete mode 100644 third-party/curl/docs/cmdline-opts/show-error.d create mode 100644 third-party/curl/docs/cmdline-opts/show-error.md create mode 100644 third-party/curl/docs/cmdline-opts/show-headers.md create mode 100644 third-party/curl/docs/cmdline-opts/sigalgs.md delete mode 100644 third-party/curl/docs/cmdline-opts/silent.d create mode 100644 third-party/curl/docs/cmdline-opts/silent.md create mode 100644 third-party/curl/docs/cmdline-opts/skip-existing.md delete mode 100644 third-party/curl/docs/cmdline-opts/socks4.d create mode 100644 third-party/curl/docs/cmdline-opts/socks4.md delete mode 100644 third-party/curl/docs/cmdline-opts/socks4a.d create mode 100644 third-party/curl/docs/cmdline-opts/socks4a.md delete mode 100644 third-party/curl/docs/cmdline-opts/socks5-basic.d create mode 100644 third-party/curl/docs/cmdline-opts/socks5-basic.md delete mode 100644 third-party/curl/docs/cmdline-opts/socks5-gssapi-nec.d create mode 100644 third-party/curl/docs/cmdline-opts/socks5-gssapi-nec.md delete mode 100644 third-party/curl/docs/cmdline-opts/socks5-gssapi-service.d create mode 100644 third-party/curl/docs/cmdline-opts/socks5-gssapi-service.md delete mode 100644 third-party/curl/docs/cmdline-opts/socks5-gssapi.d create mode 100644 third-party/curl/docs/cmdline-opts/socks5-gssapi.md delete mode 100644 third-party/curl/docs/cmdline-opts/socks5-hostname.d create mode 100644 third-party/curl/docs/cmdline-opts/socks5-hostname.md delete mode 100644 third-party/curl/docs/cmdline-opts/socks5.d create mode 100644 third-party/curl/docs/cmdline-opts/socks5.md delete mode 100644 third-party/curl/docs/cmdline-opts/speed-limit.d create mode 100644 third-party/curl/docs/cmdline-opts/speed-limit.md delete mode 100644 third-party/curl/docs/cmdline-opts/speed-time.d create mode 100644 third-party/curl/docs/cmdline-opts/speed-time.md delete mode 100644 third-party/curl/docs/cmdline-opts/ssl-allow-beast.d create mode 100644 third-party/curl/docs/cmdline-opts/ssl-allow-beast.md delete mode 100644 third-party/curl/docs/cmdline-opts/ssl-auto-client-cert.d create mode 100644 third-party/curl/docs/cmdline-opts/ssl-auto-client-cert.md delete mode 100644 third-party/curl/docs/cmdline-opts/ssl-no-revoke.d create mode 100644 third-party/curl/docs/cmdline-opts/ssl-no-revoke.md delete mode 100644 third-party/curl/docs/cmdline-opts/ssl-reqd.d create mode 100644 third-party/curl/docs/cmdline-opts/ssl-reqd.md delete mode 100644 third-party/curl/docs/cmdline-opts/ssl-revoke-best-effort.d create mode 100644 third-party/curl/docs/cmdline-opts/ssl-revoke-best-effort.md create mode 100644 third-party/curl/docs/cmdline-opts/ssl-sessions.md delete mode 100644 third-party/curl/docs/cmdline-opts/ssl.d create mode 100644 third-party/curl/docs/cmdline-opts/ssl.md delete mode 100644 third-party/curl/docs/cmdline-opts/sslv2.d create mode 100644 third-party/curl/docs/cmdline-opts/sslv2.md delete mode 100644 third-party/curl/docs/cmdline-opts/sslv3.d create mode 100644 third-party/curl/docs/cmdline-opts/sslv3.md delete mode 100644 third-party/curl/docs/cmdline-opts/stderr.d create mode 100644 third-party/curl/docs/cmdline-opts/stderr.md delete mode 100644 third-party/curl/docs/cmdline-opts/styled-output.d create mode 100644 third-party/curl/docs/cmdline-opts/styled-output.md delete mode 100644 third-party/curl/docs/cmdline-opts/suppress-connect-headers.d create mode 100644 third-party/curl/docs/cmdline-opts/suppress-connect-headers.md delete mode 100644 third-party/curl/docs/cmdline-opts/tcp-fastopen.d create mode 100644 third-party/curl/docs/cmdline-opts/tcp-fastopen.md delete mode 100644 third-party/curl/docs/cmdline-opts/tcp-nodelay.d create mode 100644 third-party/curl/docs/cmdline-opts/tcp-nodelay.md delete mode 100644 third-party/curl/docs/cmdline-opts/telnet-option.d create mode 100644 third-party/curl/docs/cmdline-opts/telnet-option.md delete mode 100644 third-party/curl/docs/cmdline-opts/tftp-blksize.d create mode 100644 third-party/curl/docs/cmdline-opts/tftp-blksize.md delete mode 100644 third-party/curl/docs/cmdline-opts/tftp-no-options.d create mode 100644 third-party/curl/docs/cmdline-opts/tftp-no-options.md delete mode 100644 third-party/curl/docs/cmdline-opts/time-cond.d create mode 100644 third-party/curl/docs/cmdline-opts/time-cond.md create mode 100644 third-party/curl/docs/cmdline-opts/tls-earlydata.md delete mode 100644 third-party/curl/docs/cmdline-opts/tls-max.d create mode 100644 third-party/curl/docs/cmdline-opts/tls-max.md delete mode 100644 third-party/curl/docs/cmdline-opts/tls13-ciphers.d create mode 100644 third-party/curl/docs/cmdline-opts/tls13-ciphers.md delete mode 100644 third-party/curl/docs/cmdline-opts/tlsauthtype.d create mode 100644 third-party/curl/docs/cmdline-opts/tlsauthtype.md delete mode 100644 third-party/curl/docs/cmdline-opts/tlspassword.d create mode 100644 third-party/curl/docs/cmdline-opts/tlspassword.md delete mode 100644 third-party/curl/docs/cmdline-opts/tlsuser.d create mode 100644 third-party/curl/docs/cmdline-opts/tlsuser.md delete mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.0.d create mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.0.md delete mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.1.d create mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.1.md delete mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.2.d create mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.2.md delete mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.3.d create mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.3.md delete mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.d create mode 100644 third-party/curl/docs/cmdline-opts/tlsv1.md delete mode 100644 third-party/curl/docs/cmdline-opts/tr-encoding.d create mode 100644 third-party/curl/docs/cmdline-opts/tr-encoding.md delete mode 100644 third-party/curl/docs/cmdline-opts/trace-ascii.d create mode 100644 third-party/curl/docs/cmdline-opts/trace-ascii.md delete mode 100644 third-party/curl/docs/cmdline-opts/trace-config.d create mode 100644 third-party/curl/docs/cmdline-opts/trace-config.md delete mode 100644 third-party/curl/docs/cmdline-opts/trace-ids.d create mode 100644 third-party/curl/docs/cmdline-opts/trace-ids.md delete mode 100644 third-party/curl/docs/cmdline-opts/trace-time.d create mode 100644 third-party/curl/docs/cmdline-opts/trace-time.md delete mode 100644 third-party/curl/docs/cmdline-opts/trace.d create mode 100644 third-party/curl/docs/cmdline-opts/trace.md delete mode 100644 third-party/curl/docs/cmdline-opts/unix-socket.d create mode 100644 third-party/curl/docs/cmdline-opts/unix-socket.md delete mode 100644 third-party/curl/docs/cmdline-opts/upload-file.d create mode 100644 third-party/curl/docs/cmdline-opts/upload-file.md create mode 100644 third-party/curl/docs/cmdline-opts/upload-flags.md delete mode 100644 third-party/curl/docs/cmdline-opts/url-query.d create mode 100644 third-party/curl/docs/cmdline-opts/url-query.md delete mode 100644 third-party/curl/docs/cmdline-opts/url.d create mode 100644 third-party/curl/docs/cmdline-opts/url.md delete mode 100644 third-party/curl/docs/cmdline-opts/use-ascii.d create mode 100644 third-party/curl/docs/cmdline-opts/use-ascii.md delete mode 100644 third-party/curl/docs/cmdline-opts/user-agent.d create mode 100644 third-party/curl/docs/cmdline-opts/user-agent.md delete mode 100644 third-party/curl/docs/cmdline-opts/user.d create mode 100644 third-party/curl/docs/cmdline-opts/user.md delete mode 100644 third-party/curl/docs/cmdline-opts/variable.d create mode 100644 third-party/curl/docs/cmdline-opts/variable.md delete mode 100644 third-party/curl/docs/cmdline-opts/verbose.d create mode 100644 third-party/curl/docs/cmdline-opts/verbose.md delete mode 100644 third-party/curl/docs/cmdline-opts/version.d create mode 100644 third-party/curl/docs/cmdline-opts/version.md create mode 100644 third-party/curl/docs/cmdline-opts/vlan-priority.md delete mode 100644 third-party/curl/docs/cmdline-opts/write-out.d create mode 100644 third-party/curl/docs/cmdline-opts/write-out.md delete mode 100644 third-party/curl/docs/cmdline-opts/xattr.d create mode 100644 third-party/curl/docs/cmdline-opts/xattr.md delete mode 100644 third-party/curl/docs/curl-config.1 create mode 100644 third-party/curl/docs/curl-config.md create mode 100644 third-party/curl/docs/examples/CMakeLists.txt delete mode 100644 third-party/curl/docs/examples/Makefile.mk create mode 100644 third-party/curl/docs/examples/address-scope.c create mode 100644 third-party/curl/docs/examples/block_ip.c create mode 100644 third-party/curl/docs/examples/ftp-delete.c delete mode 100644 third-party/curl/docs/examples/href_extractor.c create mode 100644 third-party/curl/docs/examples/interface.c create mode 100644 third-party/curl/docs/examples/keepalive.c create mode 100644 third-party/curl/docs/examples/localport.c create mode 100644 third-party/curl/docs/examples/log_failed_transfers.c delete mode 100644 third-party/curl/docs/examples/multithread.c create mode 100644 third-party/curl/docs/examples/netrc.c create mode 100644 third-party/curl/docs/examples/range.c create mode 100644 third-party/curl/docs/examples/rtsp-options.c delete mode 100644 third-party/curl/docs/examples/threaded-ssl.c create mode 100644 third-party/curl/docs/examples/threaded.c create mode 100644 third-party/curl/docs/examples/websocket-updown.c create mode 100644 third-party/curl/docs/internals/BUFQ.md rename third-party/curl/docs/{ => internals}/BUFREF.md (75%) create mode 100644 third-party/curl/docs/internals/CHECKSRC.md create mode 100644 third-party/curl/docs/internals/CLIENT-READERS.md create mode 100644 third-party/curl/docs/internals/CLIENT-WRITERS.md rename third-party/curl/docs/{ => internals}/CODE_STYLE.md (75%) create mode 100644 third-party/curl/docs/internals/CONNECTION-FILTERS.md create mode 100644 third-party/curl/docs/internals/CREDENTIALS.md create mode 100644 third-party/curl/docs/internals/CURLX.md create mode 100644 third-party/curl/docs/internals/DYNBUF.md create mode 100644 third-party/curl/docs/internals/HASH.md create mode 100644 third-party/curl/docs/internals/LLIST.md create mode 100644 third-party/curl/docs/internals/MID.md create mode 100644 third-party/curl/docs/internals/MQTT.md create mode 100644 third-party/curl/docs/internals/MULTI-EV.md rename third-party/curl/docs/{ => internals}/NEW-PROTOCOL.md (75%) create mode 100644 third-party/curl/docs/internals/PEERS.md create mode 100644 third-party/curl/docs/internals/PORTING.md create mode 100644 third-party/curl/docs/internals/RATELIMITS.md create mode 100644 third-party/curl/docs/internals/README.md create mode 100644 third-party/curl/docs/internals/SCORECARD.md create mode 100644 third-party/curl/docs/internals/SPLAY.md create mode 100644 third-party/curl/docs/internals/STRPARSE.md create mode 100644 third-party/curl/docs/internals/THRDPOOL-AND-QUEUE.md create mode 100644 third-party/curl/docs/internals/TIME-KEEPING.md create mode 100644 third-party/curl/docs/internals/TLS-SESSIONS.md create mode 100644 third-party/curl/docs/internals/UINT_SETS.md rename third-party/curl/docs/{ => internals}/WEBSOCKET.md (77%) delete mode 100644 third-party/curl/docs/libcurl/curl_easy_cleanup.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_cleanup.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_duphandle.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_duphandle.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_escape.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_escape.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_getinfo.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_getinfo.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_header.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_header.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_init.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_init.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_nextheader.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_nextheader.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_option_by_id.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_option_by_id.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_option_by_name.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_option_by_name.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_option_next.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_option_next.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_pause.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_pause.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_perform.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_perform.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_recv.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_recv.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_reset.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_reset.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_send.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_send.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_setopt.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_setopt.md create mode 100644 third-party/curl/docs/libcurl/curl_easy_ssls_export.md create mode 100644 third-party/curl/docs/libcurl/curl_easy_ssls_import.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_strerror.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_strerror.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_unescape.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_unescape.md delete mode 100644 third-party/curl/docs/libcurl/curl_easy_upkeep.3 create mode 100644 third-party/curl/docs/libcurl/curl_easy_upkeep.md delete mode 100644 third-party/curl/docs/libcurl/curl_escape.3 create mode 100644 third-party/curl/docs/libcurl/curl_escape.md delete mode 100644 third-party/curl/docs/libcurl/curl_formadd.3 create mode 100644 third-party/curl/docs/libcurl/curl_formadd.md delete mode 100644 third-party/curl/docs/libcurl/curl_formfree.3 create mode 100644 third-party/curl/docs/libcurl/curl_formfree.md delete mode 100644 third-party/curl/docs/libcurl/curl_formget.3 create mode 100644 third-party/curl/docs/libcurl/curl_formget.md delete mode 100644 third-party/curl/docs/libcurl/curl_free.3 create mode 100644 third-party/curl/docs/libcurl/curl_free.md delete mode 100644 third-party/curl/docs/libcurl/curl_getdate.3 create mode 100644 third-party/curl/docs/libcurl/curl_getdate.md delete mode 100644 third-party/curl/docs/libcurl/curl_getenv.3 create mode 100644 third-party/curl/docs/libcurl/curl_getenv.md delete mode 100644 third-party/curl/docs/libcurl/curl_global_cleanup.3 create mode 100644 third-party/curl/docs/libcurl/curl_global_cleanup.md delete mode 100644 third-party/curl/docs/libcurl/curl_global_init.3 create mode 100644 third-party/curl/docs/libcurl/curl_global_init.md delete mode 100644 third-party/curl/docs/libcurl/curl_global_init_mem.3 create mode 100644 third-party/curl/docs/libcurl/curl_global_init_mem.md delete mode 100644 third-party/curl/docs/libcurl/curl_global_sslset.3 create mode 100644 third-party/curl/docs/libcurl/curl_global_sslset.md delete mode 100644 third-party/curl/docs/libcurl/curl_global_trace.3 create mode 100644 third-party/curl/docs/libcurl/curl_global_trace.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_addpart.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_addpart.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_data.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_data.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_data_cb.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_data_cb.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_encoder.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_encoder.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_filedata.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_filedata.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_filename.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_filename.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_free.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_free.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_headers.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_headers.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_init.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_init.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_name.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_name.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_subparts.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_subparts.md delete mode 100644 third-party/curl/docs/libcurl/curl_mime_type.3 create mode 100644 third-party/curl/docs/libcurl/curl_mime_type.md delete mode 100644 third-party/curl/docs/libcurl/curl_mprintf.3 create mode 100644 third-party/curl/docs/libcurl/curl_mprintf.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_add_handle.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_add_handle.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_assign.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_assign.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_cleanup.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_cleanup.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_fdset.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_fdset.md create mode 100644 third-party/curl/docs/libcurl/curl_multi_get_handles.md create mode 100644 third-party/curl/docs/libcurl/curl_multi_get_offt.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_info_read.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_info_read.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_init.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_init.md create mode 100644 third-party/curl/docs/libcurl/curl_multi_notify_disable.md create mode 100644 third-party/curl/docs/libcurl/curl_multi_notify_enable.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_perform.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_perform.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_poll.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_poll.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_remove_handle.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_remove_handle.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_setopt.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_setopt.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_socket.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_socket.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_socket_action.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_socket_action.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_socket_all.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_socket_all.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_strerror.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_strerror.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_timeout.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_timeout.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_wait.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_wait.md create mode 100644 third-party/curl/docs/libcurl/curl_multi_waitfds.md delete mode 100644 third-party/curl/docs/libcurl/curl_multi_wakeup.3 create mode 100644 third-party/curl/docs/libcurl/curl_multi_wakeup.md delete mode 100644 third-party/curl/docs/libcurl/curl_pushheader_byname.3 create mode 100644 third-party/curl/docs/libcurl/curl_pushheader_byname.md delete mode 100644 third-party/curl/docs/libcurl/curl_pushheader_bynum.3 create mode 100644 third-party/curl/docs/libcurl/curl_pushheader_bynum.md delete mode 100644 third-party/curl/docs/libcurl/curl_share_cleanup.3 create mode 100644 third-party/curl/docs/libcurl/curl_share_cleanup.md delete mode 100644 third-party/curl/docs/libcurl/curl_share_init.3 create mode 100644 third-party/curl/docs/libcurl/curl_share_init.md delete mode 100644 third-party/curl/docs/libcurl/curl_share_setopt.3 create mode 100644 third-party/curl/docs/libcurl/curl_share_setopt.md delete mode 100644 third-party/curl/docs/libcurl/curl_share_strerror.3 create mode 100644 third-party/curl/docs/libcurl/curl_share_strerror.md delete mode 100644 third-party/curl/docs/libcurl/curl_slist_append.3 create mode 100644 third-party/curl/docs/libcurl/curl_slist_append.md delete mode 100644 third-party/curl/docs/libcurl/curl_slist_free_all.3 create mode 100644 third-party/curl/docs/libcurl/curl_slist_free_all.md delete mode 100644 third-party/curl/docs/libcurl/curl_strequal.3 create mode 100644 third-party/curl/docs/libcurl/curl_strequal.md delete mode 100644 third-party/curl/docs/libcurl/curl_strnequal.3 create mode 100644 third-party/curl/docs/libcurl/curl_strnequal.md delete mode 100644 third-party/curl/docs/libcurl/curl_unescape.3 create mode 100644 third-party/curl/docs/libcurl/curl_unescape.md delete mode 100644 third-party/curl/docs/libcurl/curl_url.3 create mode 100644 third-party/curl/docs/libcurl/curl_url.md delete mode 100644 third-party/curl/docs/libcurl/curl_url_cleanup.3 create mode 100644 third-party/curl/docs/libcurl/curl_url_cleanup.md delete mode 100644 third-party/curl/docs/libcurl/curl_url_dup.3 create mode 100644 third-party/curl/docs/libcurl/curl_url_dup.md delete mode 100644 third-party/curl/docs/libcurl/curl_url_get.3 create mode 100644 third-party/curl/docs/libcurl/curl_url_get.md delete mode 100644 third-party/curl/docs/libcurl/curl_url_set.3 create mode 100644 third-party/curl/docs/libcurl/curl_url_set.md delete mode 100644 third-party/curl/docs/libcurl/curl_url_strerror.3 create mode 100644 third-party/curl/docs/libcurl/curl_url_strerror.md delete mode 100644 third-party/curl/docs/libcurl/curl_version.3 create mode 100644 third-party/curl/docs/libcurl/curl_version.md delete mode 100644 third-party/curl/docs/libcurl/curl_version_info.3 create mode 100644 third-party/curl/docs/libcurl/curl_version_info.md delete mode 100644 third-party/curl/docs/libcurl/curl_ws_meta.3 create mode 100644 third-party/curl/docs/libcurl/curl_ws_meta.md delete mode 100644 third-party/curl/docs/libcurl/curl_ws_recv.3 create mode 100644 third-party/curl/docs/libcurl/curl_ws_recv.md delete mode 100644 third-party/curl/docs/libcurl/curl_ws_send.3 create mode 100644 third-party/curl/docs/libcurl/curl_ws_send.md create mode 100644 third-party/curl/docs/libcurl/curl_ws_start_frame.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-easy.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-easy.md create mode 100644 third-party/curl/docs/libcurl/libcurl-env-dbg.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-env.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-env.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-errors.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-errors.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-multi.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-multi.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-security.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-security.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-share.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-share.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-thread.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-thread.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-tutorial.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-tutorial.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-url.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-url.md delete mode 100644 third-party/curl/docs/libcurl/libcurl-ws.3 create mode 100644 third-party/curl/docs/libcurl/libcurl-ws.md delete mode 100644 third-party/curl/docs/libcurl/libcurl.3 create mode 100644 third-party/curl/docs/libcurl/libcurl.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_ACTIVESOCKET.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_ACTIVESOCKET.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_APPCONNECT_TIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_APPCONNECT_TIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_APPCONNECT_TIME_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_APPCONNECT_TIME_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CAINFO.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CAINFO.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CAPATH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CAPATH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CERTINFO.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CERTINFO.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONDITION_UNMET.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONDITION_UNMET.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONNECT_TIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONNECT_TIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONNECT_TIME_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONNECT_TIME_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONN_ID.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONN_ID.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_LENGTH_DOWNLOAD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_LENGTH_DOWNLOAD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_LENGTH_DOWNLOAD_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_LENGTH_DOWNLOAD_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_LENGTH_UPLOAD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_LENGTH_UPLOAD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_LENGTH_UPLOAD_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_LENGTH_UPLOAD_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_TYPE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_CONTENT_TYPE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_COOKIELIST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_COOKIELIST.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_EARLYDATA_SENT_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_EFFECTIVE_METHOD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_EFFECTIVE_METHOD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_EFFECTIVE_URL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_EFFECTIVE_URL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_FILETIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_FILETIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_FILETIME_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_FILETIME_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_FTP_ENTRY_PATH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_FTP_ENTRY_PATH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_HEADER_SIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_HEADER_SIZE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_HTTPAUTH_AVAIL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_HTTPAUTH_AVAIL.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_HTTPAUTH_USED.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_HTTP_CONNECTCODE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_HTTP_CONNECTCODE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_HTTP_VERSION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_HTTP_VERSION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_LASTSOCKET.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_LASTSOCKET.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_LOCAL_IP.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_LOCAL_IP.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_LOCAL_PORT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_LOCAL_PORT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_NAMELOOKUP_TIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_NAMELOOKUP_TIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_NAMELOOKUP_TIME_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_NAMELOOKUP_TIME_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_NUM_CONNECTS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_NUM_CONNECTS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_OS_ERRNO.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_OS_ERRNO.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_POSTTRANSFER_TIME_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRETRANSFER_TIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRETRANSFER_TIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRETRANSFER_TIME_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRETRANSFER_TIME_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRIMARY_IP.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRIMARY_IP.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRIMARY_PORT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRIMARY_PORT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRIVATE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PRIVATE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PROTOCOL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PROTOCOL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PROXYAUTH_AVAIL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PROXYAUTH_AVAIL.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PROXYAUTH_USED.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PROXY_ERROR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PROXY_ERROR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PROXY_SSL_VERIFYRESULT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_PROXY_SSL_VERIFYRESULT.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_QUEUE_TIME_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REDIRECT_COUNT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REDIRECT_COUNT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REDIRECT_TIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REDIRECT_TIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REDIRECT_TIME_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REDIRECT_TIME_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REDIRECT_URL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REDIRECT_URL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REFERER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REFERER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REQUEST_SIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_REQUEST_SIZE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RESPONSE_CODE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RESPONSE_CODE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RETRY_AFTER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RETRY_AFTER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RTSP_CLIENT_CSEQ.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RTSP_CLIENT_CSEQ.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RTSP_CSEQ_RECV.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RTSP_CSEQ_RECV.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RTSP_SERVER_CSEQ.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RTSP_SERVER_CSEQ.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RTSP_SESSION_ID.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_RTSP_SESSION_ID.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SCHEME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SCHEME.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SIZE_DELIVERED.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SIZE_DOWNLOAD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SIZE_DOWNLOAD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SIZE_DOWNLOAD_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SIZE_DOWNLOAD_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SIZE_UPLOAD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SIZE_UPLOAD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SIZE_UPLOAD_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SIZE_UPLOAD_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SPEED_DOWNLOAD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SPEED_DOWNLOAD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SPEED_DOWNLOAD_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SPEED_DOWNLOAD_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SPEED_UPLOAD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SPEED_UPLOAD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SPEED_UPLOAD_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SPEED_UPLOAD_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SSL_ENGINES.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SSL_ENGINES.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SSL_VERIFYRESULT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_SSL_VERIFYRESULT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_STARTTRANSFER_TIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_STARTTRANSFER_TIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_STARTTRANSFER_TIME_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_STARTTRANSFER_TIME_T.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_TLS_SESSION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_TLS_SESSION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_TLS_SSL_PTR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_TLS_SSL_PTR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_TOTAL_TIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_TOTAL_TIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_TOTAL_TIME_T.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_TOTAL_TIME_T.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_USED_PROXY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_XFER_ID.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLINFO_XFER_ID.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMINFO_XFERS_ADDED.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMINFO_XFERS_CURRENT.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMINFO_XFERS_DONE.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMINFO_XFERS_PENDING.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMINFO_XFERS_RUNNING.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_CHUNK_LENGTH_PENALTY_SIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_CHUNK_LENGTH_PENALTY_SIZE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_CONTENT_LENGTH_PENALTY_SIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_CONTENT_LENGTH_PENALTY_SIZE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAXCONNECTS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAXCONNECTS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAX_CONCURRENT_STREAMS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAX_CONCURRENT_STREAMS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAX_HOST_CONNECTIONS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAX_HOST_CONNECTIONS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAX_PIPELINE_LENGTH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAX_PIPELINE_LENGTH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAX_TOTAL_CONNECTIONS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_MAX_TOTAL_CONNECTIONS.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_NETWORK_CHANGED.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_NOTIFYDATA.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_NOTIFYFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PIPELINING.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PIPELINING.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PIPELINING_SERVER_BL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PIPELINING_SERVER_BL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PIPELINING_SITE_BL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PIPELINING_SITE_BL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PUSHDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PUSHDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PUSHFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_PUSHFUNCTION.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_QUICK_EXIT.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_RESOLVE_THREADS_MAX.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_SOCKETDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_SOCKETDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_SOCKETFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_SOCKETFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_TIMERDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_TIMERDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_TIMERFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLMOPT_TIMERFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ABSTRACT_UNIX_SOCKET.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ABSTRACT_UNIX_SOCKET.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ACCEPTTIMEOUT_MS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ACCEPTTIMEOUT_MS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ACCEPT_ENCODING.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ACCEPT_ENCODING.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ADDRESS_SCOPE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ADDRESS_SCOPE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ALTSVC.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ALTSVC.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ALTSVC_CTRL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ALTSVC_CTRL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_APPEND.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_APPEND.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_AUTOREFERER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_AUTOREFERER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_AWS_SIGV4.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_AWS_SIGV4.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_BUFFERSIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_BUFFERSIZE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CAINFO.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CAINFO.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CAINFO_BLOB.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CAINFO_BLOB.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CAPATH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CAPATH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CA_CACHE_TIMEOUT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CA_CACHE_TIMEOUT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CERTINFO.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CERTINFO.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CHUNK_BGN_FUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CHUNK_BGN_FUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CHUNK_DATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CHUNK_DATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CHUNK_END_FUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CHUNK_END_FUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CLOSESOCKETDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CLOSESOCKETDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CLOSESOCKETFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CLOSESOCKETFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONNECTTIMEOUT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONNECTTIMEOUT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONNECTTIMEOUT_MS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONNECTTIMEOUT_MS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONNECT_ONLY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONNECT_ONLY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONNECT_TO.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONNECT_TO.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONV_FROM_NETWORK_FUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONV_FROM_NETWORK_FUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONV_FROM_UTF8_FUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONV_FROM_UTF8_FUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONV_TO_NETWORK_FUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CONV_TO_NETWORK_FUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIEFILE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIEFILE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIEJAR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIEJAR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIELIST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIELIST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIESESSION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COOKIESESSION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COPYPOSTFIELDS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_COPYPOSTFIELDS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CRLF.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CRLF.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CRLFILE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CRLFILE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CURLU.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CURLU.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CUSTOMREQUEST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_CUSTOMREQUEST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DEBUGDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DEBUGDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DEBUGFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DEBUGFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DEFAULT_PROTOCOL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DEFAULT_PROTOCOL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DIRLISTONLY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DIRLISTONLY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DISALLOW_USERNAME_IN_URL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DISALLOW_USERNAME_IN_URL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_CACHE_TIMEOUT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_CACHE_TIMEOUT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_INTERFACE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_INTERFACE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_LOCAL_IP4.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_LOCAL_IP4.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_LOCAL_IP6.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_LOCAL_IP6.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_SERVERS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_SERVERS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_SHUFFLE_ADDRESSES.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_SHUFFLE_ADDRESSES.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_USE_GLOBAL_CACHE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DNS_USE_GLOBAL_CACHE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DOH_SSL_VERIFYHOST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DOH_SSL_VERIFYHOST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DOH_SSL_VERIFYPEER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DOH_SSL_VERIFYPEER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DOH_SSL_VERIFYSTATUS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DOH_SSL_VERIFYSTATUS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DOH_URL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_DOH_URL.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ECH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_EGDSOCKET.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_EGDSOCKET.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ERRORBUFFER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ERRORBUFFER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_EXPECT_100_TIMEOUT_MS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_EXPECT_100_TIMEOUT_MS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FAILONERROR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FAILONERROR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FILETIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FILETIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FNMATCH_DATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FNMATCH_DATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FNMATCH_FUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FNMATCH_FUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FOLLOWLOCATION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FOLLOWLOCATION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FORBID_REUSE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FORBID_REUSE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FRESH_CONNECT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FRESH_CONNECT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTPPORT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTPPORT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTPSSLAUTH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTPSSLAUTH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_ACCOUNT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_ACCOUNT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_ALTERNATIVE_TO_USER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_ALTERNATIVE_TO_USER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_CREATE_MISSING_DIRS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_CREATE_MISSING_DIRS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_FILEMETHOD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_FILEMETHOD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_SKIP_PASV_IP.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_SKIP_PASV_IP.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_SSL_CCC.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_SSL_CCC.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_USE_EPRT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_USE_EPRT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_USE_EPSV.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_USE_EPSV.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_USE_PRET.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_FTP_USE_PRET.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_GSSAPI_DELEGATION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_GSSAPI_DELEGATION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HAPROXYPROTOCOL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HAPROXYPROTOCOL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HAPROXY_CLIENT_IP.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HAPROXY_CLIENT_IP.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HEADER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HEADER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HEADERDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HEADERDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HEADERFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HEADERFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HEADEROPT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HEADEROPT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTSREADDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTSREADDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTSREADFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTSREADFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTSWRITEDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTSWRITEDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTSWRITEFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTSWRITEFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTS_CTRL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HSTS_CTRL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP09_ALLOWED.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP09_ALLOWED.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP200ALIASES.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP200ALIASES.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPAUTH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPAUTH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPGET.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPGET.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPHEADER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPHEADER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPPOST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPPOST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPPROXYTUNNEL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTPPROXYTUNNEL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP_CONTENT_DECODING.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP_CONTENT_DECODING.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP_TRANSFER_DECODING.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP_TRANSFER_DECODING.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP_VERSION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_HTTP_VERSION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_IGNORE_CONTENT_LENGTH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_IGNORE_CONTENT_LENGTH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INFILESIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INFILESIZE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INFILESIZE_LARGE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INFILESIZE_LARGE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INTERFACE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INTERFACE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INTERLEAVEDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INTERLEAVEDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INTERLEAVEFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_INTERLEAVEFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_IOCTLDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_IOCTLDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_IOCTLFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_IOCTLFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_IPRESOLVE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_IPRESOLVE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ISSUERCERT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ISSUERCERT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ISSUERCERT_BLOB.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_ISSUERCERT_BLOB.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_KEEP_SENDING_ON_ERROR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_KEEP_SENDING_ON_ERROR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_KEYPASSWD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_KEYPASSWD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_KRBLEVEL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_KRBLEVEL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOCALPORT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOCALPORT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOCALPORTRANGE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOCALPORTRANGE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOGIN_OPTIONS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOGIN_OPTIONS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOW_SPEED_LIMIT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOW_SPEED_LIMIT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOW_SPEED_TIME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_LOW_SPEED_TIME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAIL_AUTH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAIL_AUTH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAIL_FROM.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAIL_FROM.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAIL_RCPT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAIL_RCPT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAIL_RCPT_ALLOWFAILS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAIL_RCPT_ALLOWFAILS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXAGE_CONN.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXAGE_CONN.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXCONNECTS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXCONNECTS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXFILESIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXFILESIZE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXFILESIZE_LARGE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXFILESIZE_LARGE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXLIFETIME_CONN.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXLIFETIME_CONN.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXREDIRS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAXREDIRS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAX_RECV_SPEED_LARGE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAX_RECV_SPEED_LARGE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAX_SEND_SPEED_LARGE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MAX_SEND_SPEED_LARGE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MIMEPOST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MIMEPOST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MIME_OPTIONS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_MIME_OPTIONS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NETRC.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NETRC.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NETRC_FILE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NETRC_FILE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NEW_DIRECTORY_PERMS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NEW_DIRECTORY_PERMS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NEW_FILE_PERMS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NEW_FILE_PERMS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NOBODY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NOBODY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NOPROGRESS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NOPROGRESS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NOPROXY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NOPROXY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NOSIGNAL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_NOSIGNAL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_OPENSOCKETDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_OPENSOCKETDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_OPENSOCKETFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_OPENSOCKETFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PASSWORD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PASSWORD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PATH_AS_IS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PATH_AS_IS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PINNEDPUBLICKEY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PINNEDPUBLICKEY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PIPEWAIT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PIPEWAIT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PORT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PORT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTFIELDS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTFIELDS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTFIELDSIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTFIELDSIZE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTFIELDSIZE_LARGE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTFIELDSIZE_LARGE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTQUOTE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTQUOTE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTREDIR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_POSTREDIR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PREQUOTE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PREQUOTE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PREREQDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PREREQDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PREREQFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PREREQFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PRE_PROXY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PRE_PROXY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PRIVATE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PRIVATE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROGRESSDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROGRESSDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROGRESSFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROGRESSFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROTOCOLS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROTOCOLS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROTOCOLS_STR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROTOCOLS_STR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYAUTH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYAUTH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYHEADER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYHEADER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYPASSWORD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYPASSWORD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYPORT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYPORT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYTYPE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYTYPE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYUSERNAME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYUSERNAME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYUSERPWD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXYUSERPWD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_CAINFO.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_CAINFO.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_CAINFO_BLOB.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_CAINFO_BLOB.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_CAPATH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_CAPATH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_CRLFILE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_CRLFILE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_ISSUERCERT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_ISSUERCERT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_ISSUERCERT_BLOB.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_ISSUERCERT_BLOB.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_KEYPASSWD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_KEYPASSWD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_PINNEDPUBLICKEY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_PINNEDPUBLICKEY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SERVICE_NAME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SERVICE_NAME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLCERT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLCERT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLCERTTYPE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLCERTTYPE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLCERT_BLOB.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLCERT_BLOB.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLKEY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLKEY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLKEYTYPE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLKEYTYPE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLKEY_BLOB.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLKEY_BLOB.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLVERSION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSLVERSION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSL_CIPHER_LIST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSL_CIPHER_LIST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSL_OPTIONS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSL_OPTIONS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSL_VERIFYHOST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSL_VERIFYHOST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSL_VERIFYPEER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_SSL_VERIFYPEER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TLS13_CIPHERS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TLS13_CIPHERS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TLSAUTH_PASSWORD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TLSAUTH_PASSWORD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TLSAUTH_TYPE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TLSAUTH_TYPE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TLSAUTH_USERNAME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TLSAUTH_USERNAME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TRANSFER_MODE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PROXY_TRANSFER_MODE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PUT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_PUT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_QUICK_EXIT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_QUICK_EXIT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_QUOTE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_QUOTE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RANDOM_FILE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RANDOM_FILE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RANGE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RANGE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_READDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_READDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_READFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_READFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_REDIR_PROTOCOLS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_REDIR_PROTOCOLS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_REDIR_PROTOCOLS_STR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_REDIR_PROTOCOLS_STR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_REFERER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_REFERER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_REQUEST_TARGET.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_REQUEST_TARGET.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESOLVE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESOLVE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESOLVER_START_DATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESOLVER_START_DATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESOLVER_START_FUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESOLVER_START_FUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESUME_FROM.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESUME_FROM.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESUME_FROM_LARGE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RESUME_FROM_LARGE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_CLIENT_CSEQ.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_CLIENT_CSEQ.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_REQUEST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_REQUEST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_SERVER_CSEQ.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_SERVER_CSEQ.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_SESSION_ID.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_SESSION_ID.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_STREAM_URI.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_STREAM_URI.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_TRANSPORT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_RTSP_TRANSPORT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SASL_AUTHZID.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SASL_AUTHZID.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SASL_IR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SASL_IR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SEEKDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SEEKDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SEEKFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SEEKFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SERVER_RESPONSE_TIMEOUT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SERVER_RESPONSE_TIMEOUT.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SERVER_RESPONSE_TIMEOUT_MS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SERVICE_NAME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SERVICE_NAME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SHARE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SHARE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKOPTDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKOPTDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKOPTFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKOPTFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKS5_AUTH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKS5_AUTH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKS5_GSSAPI_NEC.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKS5_GSSAPI_NEC.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKS5_GSSAPI_SERVICE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SOCKS5_GSSAPI_SERVICE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_AUTH_TYPES.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_AUTH_TYPES.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_COMPRESSION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_COMPRESSION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_HOSTKEYDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_HOSTKEYDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_HOSTKEYFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_HOSTKEYFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_HOST_PUBLIC_KEY_MD5.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_HOST_PUBLIC_KEY_MD5.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_KEYDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_KEYDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_KEYFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_KEYFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_KNOWNHOSTS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_KNOWNHOSTS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_PRIVATE_KEYFILE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_PRIVATE_KEYFILE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_PUBLIC_KEYFILE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSH_PUBLIC_KEYFILE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLCERT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLCERT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLCERTTYPE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLCERTTYPE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLCERT_BLOB.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLCERT_BLOB.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLENGINE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLENGINE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLENGINE_DEFAULT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLENGINE_DEFAULT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLKEY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLKEY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLKEYTYPE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLKEYTYPE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLKEY_BLOB.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLKEY_BLOB.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLVERSION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSLVERSION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_CIPHER_LIST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_CIPHER_LIST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_CTX_DATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_CTX_DATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_CTX_FUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_CTX_FUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_EC_CURVES.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_EC_CURVES.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_ENABLE_ALPN.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_ENABLE_ALPN.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_ENABLE_NPN.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_ENABLE_NPN.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_FALSESTART.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_FALSESTART.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_OPTIONS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_OPTIONS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_SESSIONID_CACHE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_SESSIONID_CACHE.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_SIGNATURE_ALGORITHMS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_VERIFYHOST.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_VERIFYHOST.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_VERIFYSTATUS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SSL_VERIFYSTATUS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_STDERR.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_STDERR.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_STREAM_DEPENDS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_STREAM_DEPENDS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_STREAM_DEPENDS_E.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_STREAM_DEPENDS_E.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_STREAM_WEIGHT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_STREAM_WEIGHT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SUPPRESS_CONNECT_HEADERS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_SUPPRESS_CONNECT_HEADERS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_FASTOPEN.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_FASTOPEN.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_KEEPALIVE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_KEEPALIVE.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_KEEPCNT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_KEEPIDLE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_KEEPIDLE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_KEEPINTVL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_KEEPINTVL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_NODELAY.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TCP_NODELAY.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TELNETOPTIONS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TELNETOPTIONS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TFTP_BLKSIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TFTP_BLKSIZE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TFTP_NO_OPTIONS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TFTP_NO_OPTIONS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMECONDITION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMECONDITION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMEOUT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMEOUT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMEOUT_MS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMEOUT_MS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMEVALUE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMEVALUE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMEVALUE_LARGE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TIMEVALUE_LARGE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TLS13_CIPHERS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TLS13_CIPHERS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TLSAUTH_PASSWORD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TLSAUTH_PASSWORD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TLSAUTH_TYPE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TLSAUTH_TYPE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TLSAUTH_USERNAME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TLSAUTH_USERNAME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TRAILERDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TRAILERDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TRAILERFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TRAILERFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TRANSFERTEXT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TRANSFERTEXT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TRANSFER_ENCODING.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_TRANSFER_ENCODING.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UNIX_SOCKET_PATH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UNIX_SOCKET_PATH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UNRESTRICTED_AUTH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UNRESTRICTED_AUTH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UPKEEP_INTERVAL_MS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UPKEEP_INTERVAL_MS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UPLOAD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UPLOAD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UPLOAD_BUFFERSIZE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UPLOAD_BUFFERSIZE.md create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_UPLOAD_FLAGS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_URL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_URL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_USERAGENT.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_USERAGENT.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_USERNAME.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_USERNAME.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_USERPWD.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_USERPWD.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_USE_SSL.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_USE_SSL.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_VERBOSE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_VERBOSE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_WILDCARDMATCH.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_WILDCARDMATCH.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_WRITEDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_WRITEDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_WRITEFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_WRITEFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_WS_OPTIONS.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_WS_OPTIONS.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_XFERINFODATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_XFERINFODATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_XFERINFOFUNCTION.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_XFERINFOFUNCTION.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_XOAUTH2_BEARER.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLOPT_XOAUTH2_BEARER.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_LOCKFUNC.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_LOCKFUNC.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_SHARE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_SHARE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_UNLOCKFUNC.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_UNLOCKFUNC.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_UNSHARE.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_UNSHARE.md delete mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_USERDATA.3 create mode 100644 third-party/curl/docs/libcurl/opts/CURLSHOPT_USERDATA.md delete mode 100644 third-party/curl/docs/libcurl/opts/template.3 delete mode 100644 third-party/curl/docs/mk-ca-bundle.1 create mode 100644 third-party/curl/docs/mk-ca-bundle.md create mode 100644 third-party/curl/docs/runtests.md create mode 100644 third-party/curl/docs/testcurl.md create mode 100644 third-party/curl/docs/tests/CI.md create mode 100644 third-party/curl/docs/tests/FILEFORMAT.md create mode 100644 third-party/curl/docs/tests/HTTP.md create mode 100644 third-party/curl/docs/tests/TEST-SUITE.md create mode 100644 third-party/curl/docs/wcurl.md delete mode 100644 third-party/curl/include/curl/.gitignore delete mode 100644 third-party/curl/lib/.checksrc delete mode 100644 third-party/curl/lib/.gitattributes delete mode 100644 third-party/curl/lib/Makefile.mk create mode 100644 third-party/curl/lib/asyn-base.c create mode 100644 third-party/curl/lib/asyn-thrdd.c delete mode 100644 third-party/curl/lib/asyn-thread.c delete mode 100644 third-party/curl/lib/base64.c delete mode 100644 third-party/curl/lib/c-hyper.c delete mode 100644 third-party/curl/lib/c-hyper.h create mode 100644 third-party/curl/lib/cf-dns.c create mode 100644 third-party/curl/lib/cf-dns.h create mode 100644 third-party/curl/lib/cf-ip-happy.c create mode 100644 third-party/curl/lib/cf-ip-happy.h create mode 100644 third-party/curl/lib/cf-recvbuf.c create mode 100644 third-party/curl/lib/cf-recvbuf.h create mode 100644 third-party/curl/lib/cf-setup.c create mode 100644 third-party/curl/lib/cf-setup.h delete mode 100644 third-party/curl/lib/config-amigaos.h delete mode 100644 third-party/curl/lib/config-dos.h delete mode 100644 third-party/curl/lib/config-plan9.h delete mode 100644 third-party/curl/lib/config-win32ce.h create mode 100644 third-party/curl/lib/creds.c create mode 100644 third-party/curl/lib/creds.h create mode 100644 third-party/curl/lib/cshutdn.c create mode 100644 third-party/curl/lib/cshutdn.h delete mode 100644 third-party/curl/lib/curl_base64.h create mode 100644 third-party/curl/lib/curl_config-cmake.h.in delete mode 100644 third-party/curl/lib/curl_config.h.cmake delete mode 100644 third-party/curl/lib/curl_des.c delete mode 100644 third-party/curl/lib/curl_des.h create mode 100644 third-party/curl/lib/curl_fopen.c create mode 100644 third-party/curl/lib/curl_fopen.h delete mode 100644 third-party/curl/lib/curl_krb5.h delete mode 100644 third-party/curl/lib/curl_memory.h delete mode 100644 third-party/curl/lib/curl_multibyte.c delete mode 100644 third-party/curl/lib/curl_multibyte.h delete mode 100644 third-party/curl/lib/curl_ntlm_wb.c delete mode 100644 third-party/curl/lib/curl_ntlm_wb.h delete mode 100644 third-party/curl/lib/curl_path.c delete mode 100644 third-party/curl/lib/curl_path.h delete mode 100644 third-party/curl/lib/curl_rtmp.c delete mode 100644 third-party/curl/lib/curl_rtmp.h delete mode 100644 third-party/curl/lib/curl_setup_once.h create mode 100644 third-party/curl/lib/curl_sha512_256.c create mode 100644 third-party/curl/lib/curl_sha512_256.h create mode 100644 third-party/curl/lib/curl_share.c create mode 100644 third-party/curl/lib/curl_share.h delete mode 100644 third-party/curl/lib/curlx.h create mode 100644 third-party/curl/lib/curlx/base64.c create mode 100644 third-party/curl/lib/curlx/base64.h create mode 100644 third-party/curl/lib/curlx/basename.c create mode 100644 third-party/curl/lib/curlx/basename.h create mode 100644 third-party/curl/lib/curlx/dynbuf.c create mode 100644 third-party/curl/lib/curlx/dynbuf.h create mode 100644 third-party/curl/lib/curlx/fopen.c create mode 100644 third-party/curl/lib/curlx/fopen.h create mode 100644 third-party/curl/lib/curlx/inet_ntop.c create mode 100644 third-party/curl/lib/curlx/inet_ntop.h create mode 100644 third-party/curl/lib/curlx/inet_pton.c rename third-party/curl/lib/{ => curlx}/inet_pton.h (77%) create mode 100644 third-party/curl/lib/curlx/multibyte.c create mode 100644 third-party/curl/lib/curlx/multibyte.h rename third-party/curl/lib/{ => curlx}/nonblock.c (79%) rename third-party/curl/lib/{ => curlx}/nonblock.h (96%) create mode 100644 third-party/curl/lib/curlx/snprintf.c create mode 100644 third-party/curl/lib/curlx/snprintf.h create mode 100644 third-party/curl/lib/curlx/strcopy.c create mode 100644 third-party/curl/lib/curlx/strcopy.h create mode 100644 third-party/curl/lib/curlx/strdup.c rename third-party/curl/lib/{ => curlx}/strdup.h (77%) create mode 100644 third-party/curl/lib/curlx/strerr.c create mode 100644 third-party/curl/lib/curlx/strerr.h create mode 100644 third-party/curl/lib/curlx/strparse.c create mode 100644 third-party/curl/lib/curlx/strparse.h rename third-party/curl/lib/{ => curlx}/timediff.c (91%) rename third-party/curl/lib/{ => curlx}/timediff.h (93%) create mode 100644 third-party/curl/lib/curlx/timeval.c create mode 100644 third-party/curl/lib/curlx/timeval.h create mode 100644 third-party/curl/lib/curlx/version_win32.c rename third-party/curl/lib/{ => curlx}/version_win32.h (89%) create mode 100644 third-party/curl/lib/curlx/wait.c create mode 100644 third-party/curl/lib/curlx/wait.h create mode 100644 third-party/curl/lib/curlx/warnless.c create mode 100644 third-party/curl/lib/curlx/warnless.h create mode 100644 third-party/curl/lib/curlx/winapi.c create mode 100644 third-party/curl/lib/curlx/winapi.h create mode 100644 third-party/curl/lib/cw-out.c create mode 100644 third-party/curl/lib/cw-out.h create mode 100644 third-party/curl/lib/cw-pause.c create mode 100644 third-party/curl/lib/cw-pause.h create mode 100644 third-party/curl/lib/dllmain.c create mode 100644 third-party/curl/lib/dnscache.c create mode 100644 third-party/curl/lib/dnscache.h delete mode 100644 third-party/curl/lib/dynbuf.c delete mode 100644 third-party/curl/lib/dynbuf.h create mode 100644 third-party/curl/lib/fake_addrinfo.c create mode 100644 third-party/curl/lib/fake_addrinfo.h delete mode 100644 third-party/curl/lib/fopen.c delete mode 100644 third-party/curl/lib/fopen.h create mode 100644 third-party/curl/lib/ftp-int.h delete mode 100644 third-party/curl/lib/hostasyn.c delete mode 100644 third-party/curl/lib/hostsyn.c create mode 100644 third-party/curl/lib/httpsrr.c create mode 100644 third-party/curl/lib/httpsrr.h delete mode 100644 third-party/curl/lib/inet_ntop.c delete mode 100644 third-party/curl/lib/inet_ntop.h delete mode 100644 third-party/curl/lib/inet_pton.c delete mode 100644 third-party/curl/lib/krb5.c rename third-party/curl/{ => lib}/libcurl.def (89%) delete mode 100644 third-party/curl/lib/libcurl.plist.in delete mode 100644 third-party/curl/lib/memdebug.h create mode 100644 third-party/curl/lib/multi_ev.c create mode 100644 third-party/curl/lib/multi_ev.h create mode 100644 third-party/curl/lib/multi_ntfy.c create mode 100644 third-party/curl/lib/multi_ntfy.h delete mode 100644 third-party/curl/lib/noproxy.c delete mode 100644 third-party/curl/lib/noproxy.h create mode 100644 third-party/curl/lib/peer.c create mode 100644 third-party/curl/lib/peer.h create mode 100644 third-party/curl/lib/protocol.c create mode 100644 third-party/curl/lib/protocol.h create mode 100644 third-party/curl/lib/proxy.c create mode 100644 third-party/curl/lib/proxy.h create mode 100644 third-party/curl/lib/ratelimit.c create mode 100644 third-party/curl/lib/ratelimit.h delete mode 100644 third-party/curl/lib/rename.c delete mode 100644 third-party/curl/lib/rename.h create mode 100644 third-party/curl/lib/request.c create mode 100644 third-party/curl/lib/request.h delete mode 100644 third-party/curl/lib/share.c delete mode 100644 third-party/curl/lib/share.h delete mode 100644 third-party/curl/lib/speedcheck.c delete mode 100644 third-party/curl/lib/speedcheck.h delete mode 100644 third-party/curl/lib/strdup.c create mode 100644 third-party/curl/lib/strequal.c delete mode 100644 third-party/curl/lib/strtok.c delete mode 100644 third-party/curl/lib/strtok.h delete mode 100644 third-party/curl/lib/strtoofft.c delete mode 100644 third-party/curl/lib/strtoofft.h create mode 100644 third-party/curl/lib/thrdpool.c create mode 100644 third-party/curl/lib/thrdpool.h create mode 100644 third-party/curl/lib/thrdqueue.c create mode 100644 third-party/curl/lib/thrdqueue.h delete mode 100644 third-party/curl/lib/timeval.c delete mode 100644 third-party/curl/lib/timeval.h create mode 100644 third-party/curl/lib/uint-bset.c create mode 100644 third-party/curl/lib/uint-bset.h create mode 100644 third-party/curl/lib/uint-hash.c create mode 100644 third-party/curl/lib/uint-hash.h create mode 100644 third-party/curl/lib/uint-spbset.c create mode 100644 third-party/curl/lib/uint-spbset.h create mode 100644 third-party/curl/lib/uint-table.c create mode 100644 third-party/curl/lib/uint-table.h delete mode 100644 third-party/curl/lib/vauth/ntlm.h delete mode 100644 third-party/curl/lib/version_win32.c create mode 100644 third-party/curl/lib/vquic/capsule.c create mode 100644 third-party/curl/lib/vquic/capsule.h create mode 100644 third-party/curl/lib/vquic/cf-capsule.c create mode 100644 third-party/curl/lib/vquic/cf-capsule.h create mode 100644 third-party/curl/lib/vquic/cf-ngtcp2-cmn.c create mode 100644 third-party/curl/lib/vquic/cf-ngtcp2-cmn.h create mode 100644 third-party/curl/lib/vquic/cf-ngtcp2-proxy.c create mode 100644 third-party/curl/lib/vquic/cf-ngtcp2-proxy.h create mode 100644 third-party/curl/lib/vquic/cf-ngtcp2.c create mode 100644 third-party/curl/lib/vquic/cf-ngtcp2.h create mode 100644 third-party/curl/lib/vquic/cf-quiche.c create mode 100644 third-party/curl/lib/vquic/cf-quiche.h delete mode 100644 third-party/curl/lib/vquic/curl_msh3.c delete mode 100644 third-party/curl/lib/vquic/curl_msh3.h delete mode 100644 third-party/curl/lib/vquic/curl_ngtcp2.c delete mode 100644 third-party/curl/lib/vquic/curl_ngtcp2.h delete mode 100644 third-party/curl/lib/vquic/curl_quiche.c delete mode 100644 third-party/curl/lib/vquic/curl_quiche.h create mode 100644 third-party/curl/lib/vquic/vquic-tls.c create mode 100644 third-party/curl/lib/vquic/vquic-tls.h create mode 100644 third-party/curl/lib/vssh/vssh.c create mode 100644 third-party/curl/lib/vssh/vssh.h delete mode 100644 third-party/curl/lib/vssh/wolfssh.c create mode 100644 third-party/curl/lib/vtls/apple.c create mode 100644 third-party/curl/lib/vtls/apple.h delete mode 100644 third-party/curl/lib/vtls/bearssl.c delete mode 100644 third-party/curl/lib/vtls/bearssl.h create mode 100644 third-party/curl/lib/vtls/cipher_suite.c create mode 100644 third-party/curl/lib/vtls/cipher_suite.h delete mode 100644 third-party/curl/lib/vtls/mbedtls_threadlock.c delete mode 100644 third-party/curl/lib/vtls/mbedtls_threadlock.h delete mode 100644 third-party/curl/lib/vtls/sectransp.c delete mode 100644 third-party/curl/lib/vtls/sectransp.h create mode 100644 third-party/curl/lib/vtls/vtls_config.c create mode 100644 third-party/curl/lib/vtls/vtls_config.h create mode 100644 third-party/curl/lib/vtls/vtls_scache.c create mode 100644 third-party/curl/lib/vtls/vtls_scache.h create mode 100644 third-party/curl/lib/vtls/vtls_spack.c create mode 100644 third-party/curl/lib/vtls/vtls_spack.h delete mode 100644 third-party/curl/lib/warnless.c delete mode 100644 third-party/curl/lib/warnless.h create mode 100644 third-party/curl/m4/curl-apple-sectrust.m4 delete mode 100644 third-party/curl/m4/curl-bearssl.m4 delete mode 100644 third-party/curl/m4/curl-sectransp.m4 delete mode 100644 third-party/curl/m4/xc-translit.m4 delete mode 100644 third-party/curl/m4/zz60-xc-ovr.m4 delete mode 100644 third-party/curl/maketgz delete mode 100644 third-party/curl/packages/Makefile.am delete mode 100644 third-party/curl/packages/OS400/ccsidcurl.c delete mode 100644 third-party/curl/packages/OS400/make-lib.sh delete mode 100644 third-party/curl/packages/OS400/make-src.sh delete mode 100644 third-party/curl/packages/OS400/os400sys.c delete mode 100644 third-party/curl/packages/OS400/os400sys.h delete mode 100644 third-party/curl/packages/README.md delete mode 100644 third-party/curl/packages/vms/Makefile.am delete mode 100644 third-party/curl/packages/vms/config_h.com delete mode 100644 third-party/curl/packages/vms/curl_crtl_init.c delete mode 100644 third-party/curl/packages/vms/curlmsg.h delete mode 100644 third-party/curl/packages/vms/curlmsg.msg delete mode 100644 third-party/curl/packages/vms/curlmsg_vms.h delete mode 100644 third-party/curl/packages/vms/report_openssl_version.c delete mode 100644 third-party/curl/plan9/README delete mode 100644 third-party/curl/plan9/include/mkfile delete mode 100644 third-party/curl/plan9/lib/mkfile delete mode 100644 third-party/curl/plan9/lib/mkfile.inc delete mode 100644 third-party/curl/plan9/mkfile delete mode 100644 third-party/curl/plan9/mkfile.proto delete mode 100644 third-party/curl/plan9/src/mkfile delete mode 100644 third-party/curl/plan9/src/mkfile.inc create mode 100644 third-party/curl/projects/Makefile.am create mode 100644 third-party/curl/projects/OS400/.checksrc rename third-party/curl/{packages => projects}/OS400/README.OS400 (93%) create mode 100644 third-party/curl/projects/OS400/ccsidcurl.c rename third-party/curl/{packages => projects}/OS400/ccsidcurl.h (99%) rename third-party/curl/{packages => projects}/OS400/config400.default (97%) rename third-party/curl/{packages => projects}/OS400/curl.cmd (97%) rename third-party/curl/{packages => projects}/OS400/curl.inc.in (95%) rename third-party/curl/{packages => projects}/OS400/curlcl.c (86%) rename third-party/curl/{packages => projects}/OS400/curlmain.c (89%) rename third-party/curl/{packages => projects}/OS400/initscript.sh (77%) create mode 100644 third-party/curl/projects/OS400/make-docs.sh rename third-party/curl/{packages => projects}/OS400/make-include.sh (92%) create mode 100644 third-party/curl/projects/OS400/make-lib.sh create mode 100644 third-party/curl/projects/OS400/make-src.sh rename third-party/curl/{packages => projects}/OS400/make-tests.sh (78%) rename third-party/curl/{packages => projects}/OS400/makefile.sh (76%) create mode 100644 third-party/curl/projects/OS400/os400sys.c create mode 100644 third-party/curl/projects/OS400/os400sys.h rename third-party/curl/{packages => projects}/OS400/rpg-examples/HEADERAPI (98%) rename third-party/curl/{packages => projects}/OS400/rpg-examples/HTTPPOST (97%) rename third-party/curl/{packages => projects}/OS400/rpg-examples/INMEMORY (98%) rename third-party/curl/{packages => projects}/OS400/rpg-examples/SIMPLE1 (98%) rename third-party/curl/{packages => projects}/OS400/rpg-examples/SIMPLE2 (96%) rename third-party/curl/{packages => projects}/OS400/rpg-examples/SMTPSRCMBR (98%) create mode 100644 third-party/curl/projects/Windows/README.md delete mode 100644 third-party/curl/projects/Windows/VC10/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC10/curl-all.sln delete mode 100644 third-party/curl/projects/Windows/VC10/lib/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC10/lib/libcurl.sln delete mode 100644 third-party/curl/projects/Windows/VC10/lib/libcurl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC10/lib/libcurl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC10/src/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC10/src/curl.sln delete mode 100644 third-party/curl/projects/Windows/VC10/src/curl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC10/src/curl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC11/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC11/curl-all.sln delete mode 100644 third-party/curl/projects/Windows/VC11/lib/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC11/lib/libcurl.sln delete mode 100644 third-party/curl/projects/Windows/VC11/lib/libcurl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC11/lib/libcurl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC11/src/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC11/src/curl.sln delete mode 100644 third-party/curl/projects/Windows/VC11/src/curl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC11/src/curl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC12/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC12/curl-all.sln delete mode 100644 third-party/curl/projects/Windows/VC12/lib/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC12/lib/libcurl.sln delete mode 100644 third-party/curl/projects/Windows/VC12/lib/libcurl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC12/lib/libcurl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC12/src/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC12/src/curl.sln delete mode 100644 third-party/curl/projects/Windows/VC12/src/curl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC12/src/curl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC14.10/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC14.10/curl-all.sln delete mode 100644 third-party/curl/projects/Windows/VC14.10/lib/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC14.10/lib/libcurl.sln delete mode 100644 third-party/curl/projects/Windows/VC14.10/lib/libcurl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC14.10/lib/libcurl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC14.10/src/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC14.10/src/curl.sln delete mode 100644 third-party/curl/projects/Windows/VC14.10/src/curl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC14.10/src/curl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC14.30/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC14.30/curl-all.sln delete mode 100644 third-party/curl/projects/Windows/VC14.30/lib/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC14.30/lib/libcurl.sln delete mode 100644 third-party/curl/projects/Windows/VC14.30/lib/libcurl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC14.30/lib/libcurl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC14.30/src/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC14.30/src/curl.sln delete mode 100644 third-party/curl/projects/Windows/VC14.30/src/curl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC14.30/src/curl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC14/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC14/curl-all.sln delete mode 100644 third-party/curl/projects/Windows/VC14/lib/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC14/lib/libcurl.sln delete mode 100644 third-party/curl/projects/Windows/VC14/lib/libcurl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC14/lib/libcurl.vcxproj.filters delete mode 100644 third-party/curl/projects/Windows/VC14/src/.gitignore delete mode 100644 third-party/curl/projects/Windows/VC14/src/curl.sln delete mode 100644 third-party/curl/projects/Windows/VC14/src/curl.tmpl delete mode 100644 third-party/curl/projects/Windows/VC14/src/curl.vcxproj.filters create mode 100644 third-party/curl/projects/Windows/generate.bat rename third-party/curl/projects/Windows/{ => tmpl}/.gitattributes (100%) create mode 100644 third-party/curl/projects/Windows/tmpl/README.txt create mode 100644 third-party/curl/projects/Windows/tmpl/curl-all.sln create mode 100644 third-party/curl/projects/Windows/tmpl/curl.sln create mode 100644 third-party/curl/projects/Windows/tmpl/curl.vcxproj create mode 100644 third-party/curl/projects/Windows/tmpl/curl.vcxproj.filters create mode 100644 third-party/curl/projects/Windows/tmpl/libcurl.sln create mode 100644 third-party/curl/projects/Windows/tmpl/libcurl.vcxproj create mode 100644 third-party/curl/projects/Windows/tmpl/libcurl.vcxproj.filters delete mode 100644 third-party/curl/projects/build-openssl.bat delete mode 100644 third-party/curl/projects/build-wolfssl.bat delete mode 100644 third-party/curl/projects/checksrc.bat delete mode 100644 third-party/curl/projects/generate.bat create mode 100644 third-party/curl/projects/vms/Makefile.am rename third-party/curl/{packages => projects}/vms/backup_gnv_curl_src.com (100%) rename third-party/curl/{packages => projects}/vms/build_curl-config_script.com (98%) rename third-party/curl/{packages => projects}/vms/build_gnv_curl.com (100%) rename third-party/curl/{packages => projects}/vms/build_gnv_curl_pcsi_desc.com (99%) rename third-party/curl/{packages => projects}/vms/build_gnv_curl_pcsi_text.com (97%) rename third-party/curl/{packages => projects}/vms/build_gnv_curl_release_notes.com (90%) rename third-party/curl/{packages => projects}/vms/build_libcurl_pc.com (97%) rename third-party/curl/{packages => projects}/vms/build_vms.com (96%) rename third-party/curl/{packages => projects}/vms/clean_gnv_curl.com (88%) rename third-party/curl/{packages => projects}/vms/compare_curl_source.com (98%) create mode 100644 third-party/curl/projects/vms/config_h.com create mode 100644 third-party/curl/projects/vms/curl_crtl_init.c rename third-party/curl/{packages => projects}/vms/curl_gnv_build_steps.txt (96%) rename third-party/curl/{packages => projects}/vms/curl_release_note_start.txt (91%) rename third-party/curl/{packages => projects}/vms/curl_startup.com (97%) create mode 100644 third-party/curl/projects/vms/curlmsg.h create mode 100644 third-party/curl/projects/vms/curlmsg.msg rename third-party/curl/{packages => projects}/vms/curlmsg.sdl (100%) create mode 100644 third-party/curl/projects/vms/curlmsg_vms.h rename third-party/curl/{packages => projects}/vms/generate_config_vms_h_curl.com (83%) rename third-party/curl/{packages => projects}/vms/generate_vax_transfer.com (100%) rename third-party/curl/{packages => projects}/vms/gnv_conftest.c_first (97%) rename third-party/curl/{packages => projects}/vms/gnv_curl_configure.sh (85%) rename third-party/curl/{packages => projects}/vms/gnv_libcurl_symbols.opt (100%) rename third-party/curl/{packages => projects}/vms/gnv_link_curl.com (95%) rename third-party/curl/{packages => projects}/vms/macro32_exactcase.patch (100%) rename third-party/curl/{packages => projects}/vms/make_gnv_curl_install.sh (94%) rename third-party/curl/{packages => projects}/vms/make_pcsi_curl_kit_name.com (98%) rename third-party/curl/{packages => projects}/vms/pcsi_gnv_curl_file_list.txt (98%) rename third-party/curl/{packages => projects}/vms/pcsi_product_gnv_curl.com (95%) rename third-party/curl/{packages => projects}/vms/readme (90%) create mode 100644 third-party/curl/projects/vms/report_openssl_version.c rename third-party/curl/{packages => projects}/vms/setup_gnv_curl_build.com (93%) rename third-party/curl/{packages => projects}/vms/stage_curl_install.com (99%) rename third-party/curl/{packages => projects}/vms/vms_eco_level.h (100%) delete mode 100644 third-party/curl/projects/wolfssl_options.h delete mode 100644 third-party/curl/projects/wolfssl_override.props create mode 100644 third-party/curl/renovate.json create mode 100644 third-party/curl/scripts/.checksrc create mode 100644 third-party/curl/scripts/CMakeLists.txt create mode 100644 third-party/curl/scripts/badwords create mode 100644 third-party/curl/scripts/badwords-all create mode 100644 third-party/curl/scripts/badwords.txt create mode 100644 third-party/curl/scripts/cd2cd create mode 100644 third-party/curl/scripts/cd2nroff create mode 100644 third-party/curl/scripts/cdall create mode 100644 third-party/curl/scripts/checksrc-all.pl delete mode 100644 third-party/curl/scripts/ciconfig.pl delete mode 100644 third-party/curl/scripts/cijobs.pl create mode 100644 third-party/curl/scripts/cmakelint.sh delete mode 100644 third-party/curl/scripts/copyright.pl create mode 100644 third-party/curl/scripts/dmaketgz create mode 100644 third-party/curl/scripts/extract-unit-protos delete mode 100644 third-party/curl/scripts/log2changes.pl create mode 100644 third-party/curl/scripts/maketgz create mode 100644 third-party/curl/scripts/managen create mode 100644 third-party/curl/scripts/mdlinkcheck create mode 100644 third-party/curl/scripts/mk-unity.pl create mode 100644 third-party/curl/scripts/nroff2cd create mode 100644 third-party/curl/scripts/perlcheck.sh create mode 100644 third-party/curl/scripts/pythonlint.sh create mode 100644 third-party/curl/scripts/randdisable create mode 100644 third-party/curl/scripts/release-tools.sh create mode 100644 third-party/curl/scripts/schemetable.c create mode 100644 third-party/curl/scripts/spacecheck.pl create mode 100644 third-party/curl/scripts/top-complexity create mode 100644 third-party/curl/scripts/top-length delete mode 100644 third-party/curl/scripts/updatemanpages.pl create mode 100644 third-party/curl/scripts/verify-release create mode 100644 third-party/curl/scripts/wcurl create mode 100644 third-party/curl/src/.checksrc delete mode 100644 third-party/curl/src/Makefile.mk create mode 100644 third-party/curl/src/config2setopts.c create mode 100644 third-party/curl/src/config2setopts.h create mode 100644 third-party/curl/src/curlinfo.c create mode 100644 third-party/curl/src/mk-file-embed.pl create mode 100644 third-party/curl/src/terminal.c create mode 100644 third-party/curl/src/terminal.h delete mode 100644 third-party/curl/src/tool_binmode.c delete mode 100644 third-party/curl/src/tool_binmode.h delete mode 100644 third-party/curl/src/tool_bname.c delete mode 100644 third-party/curl/src/tool_bname.h create mode 100644 third-party/curl/src/tool_cb_soc.c create mode 100644 third-party/curl/src/tool_cb_soc.h delete mode 100644 third-party/curl/src/tool_hugehelp.c.cvs create mode 100644 third-party/curl/src/tool_ipfs.c create mode 100644 third-party/curl/src/tool_ipfs.h delete mode 100644 third-party/curl/src/tool_sleep.c delete mode 100644 third-party/curl/src/tool_sleep.h create mode 100644 third-party/curl/src/tool_ssls.c create mode 100644 third-party/curl/src/tool_ssls.h delete mode 100644 third-party/curl/src/tool_strdup.c delete mode 100644 third-party/curl/src/tool_strdup.h create mode 100644 third-party/curl/src/toolx/tool_time.c create mode 100644 third-party/curl/src/toolx/tool_time.h delete mode 100644 third-party/curl/tests/CI.md delete mode 100644 third-party/curl/tests/FILEFORMAT.md delete mode 100644 third-party/curl/tests/README.md create mode 100644 third-party/curl/tests/allversions.pm delete mode 100644 third-party/curl/tests/badsymbols.pl create mode 100644 third-party/curl/tests/certs/CMakeLists.txt delete mode 100644 third-party/curl/tests/certs/EdelCurlRoot-ca.cacert delete mode 100644 third-party/curl/tests/certs/EdelCurlRoot-ca.cnf delete mode 100644 third-party/curl/tests/certs/EdelCurlRoot-ca.crt delete mode 100644 third-party/curl/tests/certs/EdelCurlRoot-ca.csr delete mode 100644 third-party/curl/tests/certs/EdelCurlRoot-ca.der delete mode 100644 third-party/curl/tests/certs/EdelCurlRoot-ca.key delete mode 100644 third-party/curl/tests/certs/EdelCurlRoot-ca.prm create mode 100644 third-party/curl/tests/certs/Makefile.inc delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.crl delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.crt delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.csr delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.der delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.dhp delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.key delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.prm delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.pub.der delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.pub.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost-firstSAN-sv.pubkey-pinned delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.crl delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.crt delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.csr delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.der delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.dhp delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.key delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.prm delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.pub.der delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.pub.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost-lastSAN-sv.pubkey-pinned delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.crl delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.crt delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.csr delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.der delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.dhp delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.key delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.prm delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.pub.der delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.pub.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost-sv.pubkey-pinned delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.crl delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.crt delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.csr delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.der delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.dhp delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.key delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.prm delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.pub.der delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.pub.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost.nn-sv.pubkey-pinned delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.crl delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.crt delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.csr delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.der delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.dhp delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.key delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.prm delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.pub.der delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.pub.pem delete mode 100644 third-party/curl/tests/certs/Server-localhost0h-sv.pubkey-pinned create mode 100644 third-party/curl/tests/certs/genserv.pl delete mode 100644 third-party/curl/tests/certs/scripts/Makefile.am delete mode 100644 third-party/curl/tests/certs/scripts/genroot.sh delete mode 100644 third-party/curl/tests/certs/scripts/genserv.sh delete mode 100644 third-party/curl/tests/certs/stunnel-sv.crl delete mode 100644 third-party/curl/tests/certs/stunnel-sv.crt delete mode 100644 third-party/curl/tests/certs/stunnel-sv.csr delete mode 100644 third-party/curl/tests/certs/stunnel-sv.der delete mode 100644 third-party/curl/tests/certs/stunnel-sv.dhp delete mode 100644 third-party/curl/tests/certs/stunnel-sv.key delete mode 100644 third-party/curl/tests/certs/stunnel-sv.pem delete mode 100644 third-party/curl/tests/certs/stunnel-sv.prm delete mode 100644 third-party/curl/tests/certs/stunnel-sv.pub.der delete mode 100644 third-party/curl/tests/certs/stunnel-sv.pub.pem delete mode 100644 third-party/curl/tests/certs/stunnel-sv.pubkey-pinned create mode 100644 third-party/curl/tests/certs/test-ca.cnf create mode 100644 third-party/curl/tests/certs/test-ca.prm create mode 100644 third-party/curl/tests/certs/test-client-cert.prm create mode 100644 third-party/curl/tests/certs/test-client-eku-only.prm create mode 100644 third-party/curl/tests/certs/test-localhost-san-first.prm create mode 100644 third-party/curl/tests/certs/test-localhost-san-last.prm create mode 100644 third-party/curl/tests/certs/test-localhost.nn.prm create mode 100644 third-party/curl/tests/certs/test-localhost.prm create mode 100644 third-party/curl/tests/certs/test-localhost0h.prm delete mode 100644 third-party/curl/tests/check-deprecated.pl delete mode 100644 third-party/curl/tests/check-translatable-options.pl create mode 100644 third-party/curl/tests/cmake/CMakeLists.txt create mode 100644 third-party/curl/tests/cmake/test.c create mode 100644 third-party/curl/tests/cmake/test.cpp create mode 100644 third-party/curl/tests/cmake/test.sh create mode 100644 third-party/curl/tests/configurehelp.pm.in delete mode 100644 third-party/curl/tests/conftest.py delete mode 100644 third-party/curl/tests/convsrctest.pl delete mode 100644 third-party/curl/tests/data/.gitattributes delete mode 100644 third-party/curl/tests/data/CMakeLists.txt delete mode 100644 third-party/curl/tests/data/Makefile.inc create mode 100644 third-party/curl/tests/data/data-xml1 create mode 100644 third-party/curl/tests/data/data1400.c create mode 100644 third-party/curl/tests/data/data1401.c create mode 100644 third-party/curl/tests/data/data1402.c create mode 100644 third-party/curl/tests/data/data1403.c create mode 100644 third-party/curl/tests/data/data1404.c create mode 100644 third-party/curl/tests/data/data1405.c create mode 100644 third-party/curl/tests/data/data1406.c create mode 100644 third-party/curl/tests/data/data1407.c create mode 100644 third-party/curl/tests/data/data1420.c create mode 100644 third-party/curl/tests/data/data1461.txt create mode 100644 third-party/curl/tests/data/data1463.txt create mode 100644 third-party/curl/tests/data/data1465.c create mode 100644 third-party/curl/tests/data/data1481.c create mode 100644 third-party/curl/tests/data/data1705-1.md create mode 100644 third-party/curl/tests/data/data1705-2.md create mode 100644 third-party/curl/tests/data/data1705-3.md create mode 100644 third-party/curl/tests/data/data1705-4.md create mode 100644 third-party/curl/tests/data/data1705-stdout.1 create mode 100644 third-party/curl/tests/data/data1706-1.md create mode 100644 third-party/curl/tests/data/data1706-2.md create mode 100644 third-party/curl/tests/data/data1706-3.md create mode 100644 third-party/curl/tests/data/data1706-4.md create mode 100644 third-party/curl/tests/data/data1706-stdout.txt create mode 100644 third-party/curl/tests/data/data320.html create mode 100644 third-party/curl/tests/data/test1475 create mode 100644 third-party/curl/tests/data/test1476 create mode 100644 third-party/curl/tests/data/test1477 create mode 100644 third-party/curl/tests/data/test1478 create mode 100644 third-party/curl/tests/data/test1479 create mode 100644 third-party/curl/tests/data/test1480 create mode 100644 third-party/curl/tests/data/test1481 create mode 100644 third-party/curl/tests/data/test1482 create mode 100644 third-party/curl/tests/data/test1483 create mode 100644 third-party/curl/tests/data/test1484 create mode 100644 third-party/curl/tests/data/test1485 create mode 100644 third-party/curl/tests/data/test1486 create mode 100644 third-party/curl/tests/data/test1487 create mode 100644 third-party/curl/tests/data/test1488 create mode 100644 third-party/curl/tests/data/test1489 create mode 100644 third-party/curl/tests/data/test1490 create mode 100644 third-party/curl/tests/data/test1491 create mode 100644 third-party/curl/tests/data/test1492 create mode 100644 third-party/curl/tests/data/test1493 create mode 100644 third-party/curl/tests/data/test1494 create mode 100644 third-party/curl/tests/data/test1495 create mode 100644 third-party/curl/tests/data/test1496 create mode 100644 third-party/curl/tests/data/test1497 create mode 100644 third-party/curl/tests/data/test1498 create mode 100644 third-party/curl/tests/data/test1499 create mode 100644 third-party/curl/tests/data/test1541 create mode 100644 third-party/curl/tests/data/test1545 create mode 100644 third-party/curl/tests/data/test1546 create mode 100644 third-party/curl/tests/data/test1547 create mode 100644 third-party/curl/tests/data/test1548 create mode 100644 third-party/curl/tests/data/test1549 create mode 100644 third-party/curl/tests/data/test1571 create mode 100644 third-party/curl/tests/data/test1572 create mode 100644 third-party/curl/tests/data/test1573 create mode 100644 third-party/curl/tests/data/test1574 create mode 100644 third-party/curl/tests/data/test1575 create mode 100644 third-party/curl/tests/data/test1576 create mode 100644 third-party/curl/tests/data/test1577 create mode 100644 third-party/curl/tests/data/test1578 create mode 100644 third-party/curl/tests/data/test1579 create mode 100644 third-party/curl/tests/data/test1580 create mode 100644 third-party/curl/tests/data/test1581 create mode 100644 third-party/curl/tests/data/test1582 create mode 100644 third-party/curl/tests/data/test1583 create mode 100644 third-party/curl/tests/data/test1584 create mode 100644 third-party/curl/tests/data/test1585 create mode 100644 third-party/curl/tests/data/test1586 create mode 100644 third-party/curl/tests/data/test1587 create mode 100644 third-party/curl/tests/data/test1588 create mode 100644 third-party/curl/tests/data/test1589 create mode 100644 third-party/curl/tests/data/test1598 create mode 100644 third-party/curl/tests/data/test1599 delete mode 100644 third-party/curl/tests/data/test1609 create mode 100644 third-party/curl/tests/data/test1615 create mode 100644 third-party/curl/tests/data/test1616 create mode 100644 third-party/curl/tests/data/test1617 create mode 100644 third-party/curl/tests/data/test1618 create mode 100644 third-party/curl/tests/data/test1619 create mode 100644 third-party/curl/tests/data/test1622 create mode 100644 third-party/curl/tests/data/test1623 create mode 100644 third-party/curl/tests/data/test1624 create mode 100644 third-party/curl/tests/data/test1625 create mode 100644 third-party/curl/tests/data/test1626 create mode 100644 third-party/curl/tests/data/test1627 create mode 100644 third-party/curl/tests/data/test1628 create mode 100644 third-party/curl/tests/data/test1629 create mode 100644 third-party/curl/tests/data/test1636 create mode 100644 third-party/curl/tests/data/test1637 create mode 100644 third-party/curl/tests/data/test1638 create mode 100644 third-party/curl/tests/data/test1639 create mode 100644 third-party/curl/tests/data/test1640 create mode 100644 third-party/curl/tests/data/test1641 create mode 100644 third-party/curl/tests/data/test1642 create mode 100644 third-party/curl/tests/data/test1643 create mode 100644 third-party/curl/tests/data/test1644 create mode 100644 third-party/curl/tests/data/test1645 create mode 100644 third-party/curl/tests/data/test1646 create mode 100644 third-party/curl/tests/data/test1647 create mode 100644 third-party/curl/tests/data/test1648 create mode 100644 third-party/curl/tests/data/test1649 create mode 100644 third-party/curl/tests/data/test1656 create mode 100644 third-party/curl/tests/data/test1657 create mode 100644 third-party/curl/tests/data/test1658 create mode 100644 third-party/curl/tests/data/test1659 create mode 100644 third-party/curl/tests/data/test1663 create mode 100644 third-party/curl/tests/data/test1664 create mode 100644 third-party/curl/tests/data/test1665 create mode 100644 third-party/curl/tests/data/test1666 create mode 100644 third-party/curl/tests/data/test1667 create mode 100644 third-party/curl/tests/data/test1668 create mode 100644 third-party/curl/tests/data/test1669 create mode 100644 third-party/curl/tests/data/test1672 create mode 100644 third-party/curl/tests/data/test1673 create mode 100644 third-party/curl/tests/data/test1674 create mode 100644 third-party/curl/tests/data/test1675 create mode 100644 third-party/curl/tests/data/test1676 create mode 100644 third-party/curl/tests/data/test1677 create mode 100644 third-party/curl/tests/data/test1684 create mode 100644 third-party/curl/tests/data/test1685 create mode 100644 third-party/curl/tests/data/test1686 create mode 100644 third-party/curl/tests/data/test1704 create mode 100644 third-party/curl/tests/data/test1705 create mode 100644 third-party/curl/tests/data/test1706 create mode 100644 third-party/curl/tests/data/test1707 create mode 100644 third-party/curl/tests/data/test1708 create mode 100644 third-party/curl/tests/data/test1709 create mode 100644 third-party/curl/tests/data/test1710 create mode 100644 third-party/curl/tests/data/test1711 create mode 100644 third-party/curl/tests/data/test1712 create mode 100644 third-party/curl/tests/data/test1713 create mode 100644 third-party/curl/tests/data/test1714 create mode 100644 third-party/curl/tests/data/test1715 create mode 100644 third-party/curl/tests/data/test1720 create mode 100644 third-party/curl/tests/data/test1721 create mode 100644 third-party/curl/tests/data/test1722 create mode 100644 third-party/curl/tests/data/test1723 create mode 100644 third-party/curl/tests/data/test1724 create mode 100644 third-party/curl/tests/data/test1725 create mode 100644 third-party/curl/tests/data/test1802 create mode 100644 third-party/curl/tests/data/test1847 create mode 100644 third-party/curl/tests/data/test1848 create mode 100644 third-party/curl/tests/data/test1849 create mode 100644 third-party/curl/tests/data/test1850 create mode 100644 third-party/curl/tests/data/test1851 create mode 100644 third-party/curl/tests/data/test1900 create mode 100644 third-party/curl/tests/data/test1901 create mode 100644 third-party/curl/tests/data/test1902 create mode 100644 third-party/curl/tests/data/test1920 create mode 100644 third-party/curl/tests/data/test1921 create mode 100644 third-party/curl/tests/data/test1922 create mode 100644 third-party/curl/tests/data/test1965 create mode 100644 third-party/curl/tests/data/test1966 create mode 100644 third-party/curl/tests/data/test1967 create mode 100644 third-party/curl/tests/data/test1976 create mode 100644 third-party/curl/tests/data/test1977 create mode 100644 third-party/curl/tests/data/test1978 create mode 100644 third-party/curl/tests/data/test1979 create mode 100644 third-party/curl/tests/data/test1980 create mode 100644 third-party/curl/tests/data/test1981 create mode 100644 third-party/curl/tests/data/test1982 create mode 100644 third-party/curl/tests/data/test1983 create mode 100644 third-party/curl/tests/data/test1984 create mode 100644 third-party/curl/tests/data/test2005 create mode 100644 third-party/curl/tests/data/test2006 create mode 100644 third-party/curl/tests/data/test2007 create mode 100644 third-party/curl/tests/data/test2008 create mode 100644 third-party/curl/tests/data/test2009 create mode 100644 third-party/curl/tests/data/test2010 create mode 100644 third-party/curl/tests/data/test2011 create mode 100644 third-party/curl/tests/data/test2012 create mode 100644 third-party/curl/tests/data/test2013 create mode 100644 third-party/curl/tests/data/test2014 create mode 100644 third-party/curl/tests/data/test2015 create mode 100644 third-party/curl/tests/data/test2088 create mode 100644 third-party/curl/tests/data/test2089 create mode 100644 third-party/curl/tests/data/test2090 create mode 100644 third-party/curl/tests/data/test2091 create mode 100644 third-party/curl/tests/data/test2092 create mode 100644 third-party/curl/tests/data/test2101 create mode 100644 third-party/curl/tests/data/test2102 create mode 100644 third-party/curl/tests/data/test2103 create mode 100644 third-party/curl/tests/data/test2104 create mode 100644 third-party/curl/tests/data/test2105 create mode 100644 third-party/curl/tests/data/test2106 create mode 100644 third-party/curl/tests/data/test2107 create mode 100644 third-party/curl/tests/data/test2108 create mode 100644 third-party/curl/tests/data/test2206 create mode 100644 third-party/curl/tests/data/test2207 create mode 100644 third-party/curl/tests/data/test2208 delete mode 100644 third-party/curl/tests/data/test2305 create mode 100644 third-party/curl/tests/data/test2307 create mode 100644 third-party/curl/tests/data/test2308 create mode 100644 third-party/curl/tests/data/test2309 create mode 100644 third-party/curl/tests/data/test2310 create mode 100644 third-party/curl/tests/data/test2311 create mode 100644 third-party/curl/tests/data/test2405 create mode 100644 third-party/curl/tests/data/test2406 create mode 100644 third-party/curl/tests/data/test2407 create mode 100644 third-party/curl/tests/data/test2408 create mode 100644 third-party/curl/tests/data/test2409 create mode 100644 third-party/curl/tests/data/test2410 create mode 100644 third-party/curl/tests/data/test2411 create mode 100644 third-party/curl/tests/data/test2412 create mode 100644 third-party/curl/tests/data/test2413 create mode 100644 third-party/curl/tests/data/test2504 create mode 100644 third-party/curl/tests/data/test2505 create mode 100644 third-party/curl/tests/data/test2506 create mode 100644 third-party/curl/tests/data/test2604 create mode 100644 third-party/curl/tests/data/test2605 create mode 100644 third-party/curl/tests/data/test268 create mode 100644 third-party/curl/tests/data/test2700 create mode 100644 third-party/curl/tests/data/test2701 create mode 100644 third-party/curl/tests/data/test2702 create mode 100644 third-party/curl/tests/data/test2703 create mode 100644 third-party/curl/tests/data/test2704 create mode 100644 third-party/curl/tests/data/test2705 create mode 100644 third-party/curl/tests/data/test2706 create mode 100644 third-party/curl/tests/data/test2707 create mode 100644 third-party/curl/tests/data/test2708 create mode 100644 third-party/curl/tests/data/test2709 create mode 100644 third-party/curl/tests/data/test2710 create mode 100644 third-party/curl/tests/data/test2711 create mode 100644 third-party/curl/tests/data/test2712 create mode 100644 third-party/curl/tests/data/test2713 create mode 100644 third-party/curl/tests/data/test2714 create mode 100644 third-party/curl/tests/data/test2715 create mode 100644 third-party/curl/tests/data/test2716 create mode 100644 third-party/curl/tests/data/test2717 create mode 100644 third-party/curl/tests/data/test2718 create mode 100644 third-party/curl/tests/data/test2719 create mode 100644 third-party/curl/tests/data/test2720 create mode 100644 third-party/curl/tests/data/test2721 create mode 100644 third-party/curl/tests/data/test2722 create mode 100644 third-party/curl/tests/data/test2723 create mode 100644 third-party/curl/tests/data/test3031 create mode 100644 third-party/curl/tests/data/test3032 create mode 100644 third-party/curl/tests/data/test3033 create mode 100644 third-party/curl/tests/data/test3034 create mode 100644 third-party/curl/tests/data/test3035 create mode 100644 third-party/curl/tests/data/test3036 create mode 100644 third-party/curl/tests/data/test3103 create mode 100644 third-party/curl/tests/data/test3104 create mode 100644 third-party/curl/tests/data/test3105 create mode 100644 third-party/curl/tests/data/test3106 create mode 100644 third-party/curl/tests/data/test3203 create mode 100644 third-party/curl/tests/data/test3204 create mode 100644 third-party/curl/tests/data/test3205 create mode 100644 third-party/curl/tests/data/test3206 create mode 100644 third-party/curl/tests/data/test3207 create mode 100644 third-party/curl/tests/data/test3208 create mode 100644 third-party/curl/tests/data/test3209 create mode 100644 third-party/curl/tests/data/test3210 create mode 100644 third-party/curl/tests/data/test3211 create mode 100644 third-party/curl/tests/data/test3212 create mode 100644 third-party/curl/tests/data/test3213 create mode 100644 third-party/curl/tests/data/test3214 create mode 100644 third-party/curl/tests/data/test3215 create mode 100644 third-party/curl/tests/data/test3216 create mode 100644 third-party/curl/tests/data/test3217 create mode 100644 third-party/curl/tests/data/test3218 create mode 100644 third-party/curl/tests/data/test3219 create mode 100644 third-party/curl/tests/data/test3220 create mode 100644 third-party/curl/tests/data/test3221 create mode 100644 third-party/curl/tests/data/test3222 create mode 100644 third-party/curl/tests/data/test3300 create mode 100644 third-party/curl/tests/data/test3301 create mode 100644 third-party/curl/tests/data/test3302 create mode 100644 third-party/curl/tests/data/test3303 create mode 100644 third-party/curl/tests/data/test3304 create mode 100644 third-party/curl/tests/data/test3305 create mode 100644 third-party/curl/tests/data/test3400 create mode 100644 third-party/curl/tests/data/test3401 create mode 100644 third-party/curl/tests/data/test4000 create mode 100644 third-party/curl/tests/data/test4001 delete mode 100644 third-party/curl/tests/data/test409 create mode 100644 third-party/curl/tests/data/test457 create mode 100644 third-party/curl/tests/data/test458 create mode 100644 third-party/curl/tests/data/test459 create mode 100644 third-party/curl/tests/data/test460 create mode 100644 third-party/curl/tests/data/test461 create mode 100644 third-party/curl/tests/data/test462 create mode 100644 third-party/curl/tests/data/test463 create mode 100644 third-party/curl/tests/data/test467 create mode 100644 third-party/curl/tests/data/test468 create mode 100644 third-party/curl/tests/data/test469 create mode 100644 third-party/curl/tests/data/test470 create mode 100644 third-party/curl/tests/data/test471 create mode 100644 third-party/curl/tests/data/test472 create mode 100644 third-party/curl/tests/data/test473 create mode 100644 third-party/curl/tests/data/test474 create mode 100644 third-party/curl/tests/data/test475 create mode 100644 third-party/curl/tests/data/test476 create mode 100644 third-party/curl/tests/data/test477 create mode 100644 third-party/curl/tests/data/test478 create mode 100644 third-party/curl/tests/data/test479 create mode 100644 third-party/curl/tests/data/test480 create mode 100644 third-party/curl/tests/data/test481 create mode 100644 third-party/curl/tests/data/test482 create mode 100644 third-party/curl/tests/data/test483 create mode 100644 third-party/curl/tests/data/test484 create mode 100644 third-party/curl/tests/data/test485 create mode 100644 third-party/curl/tests/data/test486 create mode 100644 third-party/curl/tests/data/test487 create mode 100644 third-party/curl/tests/data/test488 create mode 100644 third-party/curl/tests/data/test489 create mode 100644 third-party/curl/tests/data/test498 create mode 100644 third-party/curl/tests/data/test499 create mode 100644 third-party/curl/tests/data/test536 create mode 100644 third-party/curl/tests/data/test689 create mode 100644 third-party/curl/tests/data/test690 create mode 100644 third-party/curl/tests/data/test691 create mode 100644 third-party/curl/tests/data/test692 create mode 100644 third-party/curl/tests/data/test693 create mode 100644 third-party/curl/tests/data/test694 create mode 100644 third-party/curl/tests/data/test695 create mode 100644 third-party/curl/tests/data/test696 create mode 100644 third-party/curl/tests/data/test697 create mode 100644 third-party/curl/tests/data/test698 create mode 100644 third-party/curl/tests/data/test699 create mode 100644 third-party/curl/tests/data/test722 create mode 100644 third-party/curl/tests/data/test723 create mode 100644 third-party/curl/tests/data/test724 create mode 100644 third-party/curl/tests/data/test725 create mode 100644 third-party/curl/tests/data/test726 create mode 100644 third-party/curl/tests/data/test727 create mode 100644 third-party/curl/tests/data/test728 create mode 100644 third-party/curl/tests/data/test729 create mode 100644 third-party/curl/tests/data/test730 create mode 100644 third-party/curl/tests/data/test731 create mode 100644 third-party/curl/tests/data/test732 create mode 100644 third-party/curl/tests/data/test733 create mode 100644 third-party/curl/tests/data/test734 create mode 100644 third-party/curl/tests/data/test735 create mode 100644 third-party/curl/tests/data/test736 create mode 100644 third-party/curl/tests/data/test737 create mode 100644 third-party/curl/tests/data/test738 create mode 100644 third-party/curl/tests/data/test739 create mode 100644 third-party/curl/tests/data/test740 create mode 100644 third-party/curl/tests/data/test741 create mode 100644 third-party/curl/tests/data/test742 create mode 100644 third-party/curl/tests/data/test743 create mode 100644 third-party/curl/tests/data/test744 create mode 100644 third-party/curl/tests/data/test745 create mode 100644 third-party/curl/tests/data/test746 create mode 100644 third-party/curl/tests/data/test747 create mode 100644 third-party/curl/tests/data/test748 create mode 100644 third-party/curl/tests/data/test749 create mode 100644 third-party/curl/tests/data/test750 create mode 100644 third-party/curl/tests/data/test751 create mode 100644 third-party/curl/tests/data/test752 create mode 100644 third-party/curl/tests/data/test753 create mode 100644 third-party/curl/tests/data/test754 create mode 100644 third-party/curl/tests/data/test755 create mode 100644 third-party/curl/tests/data/test756 create mode 100644 third-party/curl/tests/data/test757 create mode 100644 third-party/curl/tests/data/test758 create mode 100644 third-party/curl/tests/data/test759 create mode 100644 third-party/curl/tests/data/test760 create mode 100644 third-party/curl/tests/data/test761 create mode 100644 third-party/curl/tests/data/test762 create mode 100644 third-party/curl/tests/data/test763 create mode 100644 third-party/curl/tests/data/test764 create mode 100644 third-party/curl/tests/data/test765 create mode 100644 third-party/curl/tests/data/test766 create mode 100644 third-party/curl/tests/data/test767 create mode 100644 third-party/curl/tests/data/test768 create mode 100644 third-party/curl/tests/data/test769 create mode 100644 third-party/curl/tests/data/test770 create mode 100644 third-party/curl/tests/data/test771 create mode 100644 third-party/curl/tests/data/test772 create mode 100644 third-party/curl/tests/data/test773 create mode 100644 third-party/curl/tests/data/test774 create mode 100644 third-party/curl/tests/data/test775 create mode 100644 third-party/curl/tests/data/test776 create mode 100644 third-party/curl/tests/data/test777 create mode 100644 third-party/curl/tests/data/test778 create mode 100644 third-party/curl/tests/data/test779 create mode 100644 third-party/curl/tests/data/test780 create mode 100644 third-party/curl/tests/data/test781 create mode 100644 third-party/curl/tests/data/test782 create mode 100644 third-party/curl/tests/data/test783 create mode 100644 third-party/curl/tests/data/test784 create mode 100644 third-party/curl/tests/data/test785 create mode 100644 third-party/curl/tests/data/test786 create mode 100644 third-party/curl/tests/data/test787 create mode 100644 third-party/curl/tests/data/test788 create mode 100644 third-party/curl/tests/data/test789 create mode 100644 third-party/curl/tests/data/test790 create mode 100644 third-party/curl/tests/data/test791 create mode 100644 third-party/curl/tests/data/test792 create mode 100644 third-party/curl/tests/data/test793 create mode 100644 third-party/curl/tests/data/test794 create mode 100644 third-party/curl/tests/data/test795 create mode 100644 third-party/curl/tests/data/test796 create mode 100644 third-party/curl/tests/data/test797 create mode 100644 third-party/curl/tests/data/test798 create mode 100644 third-party/curl/tests/data/test992 create mode 100644 third-party/curl/tests/data/test993 create mode 100644 third-party/curl/tests/data/test994 create mode 100644 third-party/curl/tests/data/test995 create mode 100644 third-party/curl/tests/data/test996 create mode 100644 third-party/curl/tests/data/test997 create mode 100644 third-party/curl/tests/data/test998 create mode 100644 third-party/curl/tests/data/test999 delete mode 100644 third-party/curl/tests/disable-scan.pl create mode 100644 third-party/curl/tests/ech_combos.py create mode 100644 third-party/curl/tests/ech_tests.sh delete mode 100644 third-party/curl/tests/error-codes.pl delete mode 100644 third-party/curl/tests/extern-scan.pl create mode 100644 third-party/curl/tests/http/CMakeLists.txt delete mode 100644 third-party/curl/tests/http/README.md delete mode 100644 third-party/curl/tests/http/clients/.gitignore delete mode 100644 third-party/curl/tests/http/clients/Makefile.am delete mode 100644 third-party/curl/tests/http/clients/Makefile.inc delete mode 100644 third-party/curl/tests/http/clients/h2-download.c delete mode 100644 third-party/curl/tests/http/clients/h2-serverpush.c delete mode 100644 third-party/curl/tests/http/clients/h2-upgrade-extreme.c delete mode 100644 third-party/curl/tests/http/clients/tls-session-reuse.c delete mode 100644 third-party/curl/tests/http/clients/ws-data.c delete mode 100644 third-party/curl/tests/http/clients/ws-pingpong.c create mode 100644 third-party/curl/tests/http/test_16_info.py create mode 100644 third-party/curl/tests/http/test_17_ssl_use.py create mode 100644 third-party/curl/tests/http/test_18_methods.py create mode 100644 third-party/curl/tests/http/test_19_shutdown.py create mode 100644 third-party/curl/tests/http/test_21_resolve.py create mode 100644 third-party/curl/tests/http/test_22_httpsrr.py create mode 100644 third-party/curl/tests/http/test_30_vsftpd.py create mode 100644 third-party/curl/tests/http/test_31_vsftpds.py create mode 100644 third-party/curl/tests/http/test_32_ftps_vsftpd.py create mode 100644 third-party/curl/tests/http/test_40_socks.py create mode 100644 third-party/curl/tests/http/test_50_scp.py create mode 100644 third-party/curl/tests/http/test_51_sftp.py create mode 100644 third-party/curl/tests/http/test_60_h3_proxy.py create mode 100644 third-party/curl/tests/http/testenv/dante.py create mode 100644 third-party/curl/tests/http/testenv/dnsd.py create mode 100644 third-party/curl/tests/http/testenv/h2o.py create mode 100644 third-party/curl/tests/http/testenv/sshd.py create mode 100644 third-party/curl/tests/http/testenv/vsftpd.py delete mode 100644 third-party/curl/tests/libtest/.checksrc delete mode 100644 third-party/curl/tests/libtest/chkhostname.c create mode 100644 third-party/curl/tests/libtest/cli_ftp_upload.c create mode 100644 third-party/curl/tests/libtest/cli_h2_pausing.c create mode 100644 third-party/curl/tests/libtest/cli_h2_serverpush.c create mode 100644 third-party/curl/tests/libtest/cli_h2_upgrade_extreme.c create mode 100644 third-party/curl/tests/libtest/cli_hx_download.c create mode 100644 third-party/curl/tests/libtest/cli_hx_upload.c create mode 100644 third-party/curl/tests/libtest/cli_tls_session_reuse.c create mode 100644 third-party/curl/tests/libtest/cli_upload_pausing.c create mode 100644 third-party/curl/tests/libtest/cli_ws_data.c create mode 100644 third-party/curl/tests/libtest/cli_ws_pingpong.c create mode 100644 third-party/curl/tests/libtest/first.h create mode 100644 third-party/curl/tests/libtest/lib1308.c create mode 100644 third-party/curl/tests/libtest/lib1485.c create mode 100644 third-party/curl/tests/libtest/lib1545.c create mode 100644 third-party/curl/tests/libtest/lib1549.c create mode 100644 third-party/curl/tests/libtest/lib1571.c create mode 100644 third-party/curl/tests/libtest/lib1576.c create mode 100644 third-party/curl/tests/libtest/lib1582.c create mode 100644 third-party/curl/tests/libtest/lib1587.c create mode 100644 third-party/curl/tests/libtest/lib1588.c create mode 100644 third-party/curl/tests/libtest/lib1589.c create mode 100644 third-party/curl/tests/libtest/lib1598.c create mode 100644 third-party/curl/tests/libtest/lib1599.c create mode 100644 third-party/curl/tests/libtest/lib1647.c create mode 100644 third-party/curl/tests/libtest/lib1648.c create mode 100644 third-party/curl/tests/libtest/lib1649.c create mode 100644 third-party/curl/tests/libtest/lib1686.c create mode 100644 third-party/curl/tests/libtest/lib1900.c create mode 100644 third-party/curl/tests/libtest/lib1901.c create mode 100644 third-party/curl/tests/libtest/lib1902.c create mode 100644 third-party/curl/tests/libtest/lib1920.c create mode 100644 third-party/curl/tests/libtest/lib1921.c create mode 100644 third-party/curl/tests/libtest/lib1922.c create mode 100644 third-party/curl/tests/libtest/lib1965.c create mode 100644 third-party/curl/tests/libtest/lib1967.c create mode 100644 third-party/curl/tests/libtest/lib1977.c create mode 100644 third-party/curl/tests/libtest/lib1978.c create mode 100644 third-party/curl/tests/libtest/lib2023.c create mode 100644 third-party/curl/tests/libtest/lib2032.c create mode 100644 third-party/curl/tests/libtest/lib2082.c delete mode 100644 third-party/curl/tests/libtest/lib2305.c create mode 100644 third-party/curl/tests/libtest/lib2308.c create mode 100644 third-party/curl/tests/libtest/lib2309.c create mode 100644 third-party/curl/tests/libtest/lib2405.c create mode 100644 third-party/curl/tests/libtest/lib2412.c create mode 100644 third-party/curl/tests/libtest/lib2504.c create mode 100644 third-party/curl/tests/libtest/lib2505.c create mode 100644 third-party/curl/tests/libtest/lib2506.c create mode 100644 third-party/curl/tests/libtest/lib2700.c create mode 100644 third-party/curl/tests/libtest/lib3033.c create mode 100644 third-party/curl/tests/libtest/lib3034.c create mode 100644 third-party/curl/tests/libtest/lib3103.c create mode 100644 third-party/curl/tests/libtest/lib3104.c create mode 100644 third-party/curl/tests/libtest/lib3105.c create mode 100644 third-party/curl/tests/libtest/lib3207.c create mode 100644 third-party/curl/tests/libtest/lib3208.c create mode 100644 third-party/curl/tests/libtest/lib536.c create mode 100644 third-party/curl/tests/libtest/lib694.c create mode 100644 third-party/curl/tests/libtest/lib695.c create mode 100644 third-party/curl/tests/libtest/lib751.c create mode 100644 third-party/curl/tests/libtest/lib753.c create mode 100644 third-party/curl/tests/libtest/lib757.c create mode 100644 third-party/curl/tests/libtest/lib758.c create mode 100644 third-party/curl/tests/libtest/lib766.c delete mode 100644 third-party/curl/tests/libtest/libauthretry.c delete mode 100644 third-party/curl/tests/libtest/libntlmconnect.c delete mode 100644 third-party/curl/tests/libtest/libprereq.c create mode 100644 third-party/curl/tests/libtest/memptr.c delete mode 100644 third-party/curl/tests/libtest/notexists.pl delete mode 100644 third-party/curl/tests/libtest/sethostname.c delete mode 100644 third-party/curl/tests/libtest/sethostname.h delete mode 100644 third-party/curl/tests/libtest/stub_gssapi.c delete mode 100644 third-party/curl/tests/libtest/stub_gssapi.h delete mode 100644 third-party/curl/tests/libtest/test.h create mode 100644 third-party/curl/tests/libtest/unitcheck.h delete mode 100644 third-party/curl/tests/manpage-scan.pl delete mode 100644 third-party/curl/tests/manpage-syntax.pl delete mode 100644 third-party/curl/tests/markdown-uppercase.pl delete mode 100644 third-party/curl/tests/mem-include-scan.pl create mode 100644 third-party/curl/tests/memanalyzer.pm delete mode 100644 third-party/curl/tests/nroff-scan.pl delete mode 100644 third-party/curl/tests/option-check.pl delete mode 100644 third-party/curl/tests/options-scan.pl delete mode 100644 third-party/curl/tests/runtests.1 create mode 100644 third-party/curl/tests/server/.checksrc delete mode 100644 third-party/curl/tests/server/base64.pl delete mode 100644 third-party/curl/tests/server/disabled.c create mode 100644 third-party/curl/tests/server/dnsd.c delete mode 100644 third-party/curl/tests/server/fake_ntlm.c create mode 100644 third-party/curl/tests/server/first.c create mode 100644 third-party/curl/tests/server/first.h delete mode 100644 third-party/curl/tests/server/getpart.h delete mode 100644 third-party/curl/tests/server/server_setup.h delete mode 100644 third-party/curl/tests/server/server_sockaddr.h delete mode 100644 third-party/curl/tests/server/testpart.c delete mode 100644 third-party/curl/tests/server/tftp.h delete mode 100644 third-party/curl/tests/server/util.h delete mode 100644 third-party/curl/tests/stunnel.pem delete mode 100644 third-party/curl/tests/symbol-scan.pl create mode 100644 third-party/curl/tests/test1119.pl create mode 100644 third-party/curl/tests/test1135.pl create mode 100644 third-party/curl/tests/test1139.pl create mode 100644 third-party/curl/tests/test1140.pl create mode 100644 third-party/curl/tests/test1165.pl create mode 100644 third-party/curl/tests/test1167.pl create mode 100644 third-party/curl/tests/test1173.pl create mode 100644 third-party/curl/tests/test1175.pl create mode 100644 third-party/curl/tests/test1177.pl create mode 100644 third-party/curl/tests/test1222.pl create mode 100644 third-party/curl/tests/test1275.pl create mode 100644 third-party/curl/tests/test1276.pl create mode 100644 third-party/curl/tests/test1477.pl create mode 100644 third-party/curl/tests/test1486.pl create mode 100644 third-party/curl/tests/test1488.pl create mode 100644 third-party/curl/tests/test1544.pl create mode 100644 third-party/curl/tests/test1707.pl create mode 100644 third-party/curl/tests/test745.pl create mode 100644 third-party/curl/tests/test971.pl delete mode 100644 third-party/curl/tests/testcurl.1 create mode 100644 third-party/curl/tests/tunit/.gitignore create mode 100644 third-party/curl/tests/tunit/CMakeLists.txt create mode 100644 third-party/curl/tests/tunit/Makefile.am create mode 100644 third-party/curl/tests/tunit/Makefile.inc create mode 100644 third-party/curl/tests/tunit/README.md create mode 100644 third-party/curl/tests/tunit/tool1394.c create mode 100644 third-party/curl/tests/tunit/tool1604.c create mode 100644 third-party/curl/tests/tunit/tool1621.c create mode 100644 third-party/curl/tests/tunit/tool1622.c create mode 100644 third-party/curl/tests/tunit/tool1623.c create mode 100644 third-party/curl/tests/tunit/tool1720.c delete mode 100644 third-party/curl/tests/unit/curlcheck.h delete mode 100644 third-party/curl/tests/unit/unit1308.c delete mode 100644 third-party/curl/tests/unit/unit1394.c delete mode 100644 third-party/curl/tests/unit/unit1604.c create mode 100644 third-party/curl/tests/unit/unit1615.c create mode 100644 third-party/curl/tests/unit/unit1616.c delete mode 100644 third-party/curl/tests/unit/unit1621.c create mode 100644 third-party/curl/tests/unit/unit1625.c create mode 100644 third-party/curl/tests/unit/unit1626.c create mode 100644 third-party/curl/tests/unit/unit1627.c create mode 100644 third-party/curl/tests/unit/unit1636.c create mode 100644 third-party/curl/tests/unit/unit1656.c create mode 100644 third-party/curl/tests/unit/unit1657.c create mode 100644 third-party/curl/tests/unit/unit1658.c create mode 100644 third-party/curl/tests/unit/unit1663.c create mode 100644 third-party/curl/tests/unit/unit1664.c create mode 100644 third-party/curl/tests/unit/unit1666.c create mode 100644 third-party/curl/tests/unit/unit1667.c create mode 100644 third-party/curl/tests/unit/unit1668.c create mode 100644 third-party/curl/tests/unit/unit1669.c create mode 100644 third-party/curl/tests/unit/unit1674.c create mode 100644 third-party/curl/tests/unit/unit1675.c create mode 100644 third-party/curl/tests/unit/unit1676.c create mode 100644 third-party/curl/tests/unit/unit1979.c create mode 100644 third-party/curl/tests/unit/unit1980.c create mode 100644 third-party/curl/tests/unit/unit2413.c create mode 100644 third-party/curl/tests/unit/unit2604.c create mode 100644 third-party/curl/tests/unit/unit2605.c create mode 100644 third-party/curl/tests/unit/unit3205.c create mode 100644 third-party/curl/tests/unit/unit3211.c create mode 100644 third-party/curl/tests/unit/unit3212.c create mode 100644 third-party/curl/tests/unit/unit3213.c create mode 100644 third-party/curl/tests/unit/unit3214.c create mode 100644 third-party/curl/tests/unit/unit3216.c create mode 100644 third-party/curl/tests/unit/unit3219.c create mode 100644 third-party/curl/tests/unit/unit3300.c create mode 100644 third-party/curl/tests/unit/unit3301.c create mode 100644 third-party/curl/tests/unit/unit3302.c create mode 100644 third-party/curl/tests/unit/unit3303.c create mode 100644 third-party/curl/tests/unit/unit3304.c create mode 100644 third-party/curl/tests/unit/unit3400.c delete mode 100644 third-party/curl/tests/version-scan.pl delete mode 100644 third-party/curl/winbuild/.gitignore delete mode 100644 third-party/curl/winbuild/Makefile.vc delete mode 100644 third-party/curl/winbuild/MakefileBuild.vc delete mode 100644 third-party/curl/winbuild/README.md delete mode 100644 third-party/curl/winbuild/gen_resp_file.bat delete mode 100644 third-party/curl/winbuild/makedebug.cmd diff --git a/.github/workflows/macos-build-arm.yaml b/.github/workflows/macos-build-arm.yaml index 52d89308a7..8ffa196b76 100644 --- a/.github/workflows/macos-build-arm.yaml +++ b/.github/workflows/macos-build-arm.yaml @@ -29,10 +29,12 @@ jobs: HOMEBREW_NO_INSTALL_CLEANUP: 1 HOMEBREW_NO_ANALYTICS: 1 run: | - if ! brew install ninja nasm; then + if ! brew install ninja nasm openssl@3; then brew update - brew install ninja nasm + brew install ninja nasm openssl@3 fi + # keg-only, so give CMake's FindOpenSSL an explicit hint + echo "OPENSSL_ROOT_DIR=$(brew --prefix openssl@3)" >> $GITHUB_ENV - name: Setup sccache uses: hendrikmuhs/ccache-action@v1.2.23 diff --git a/.github/workflows/macos-build.yaml b/.github/workflows/macos-build.yaml index 99f51a7983..d66a378b35 100644 --- a/.github/workflows/macos-build.yaml +++ b/.github/workflows/macos-build.yaml @@ -39,10 +39,12 @@ jobs: HOMEBREW_NO_INSTALL_CLEANUP: 1 HOMEBREW_NO_ANALYTICS: 1 run: | - if ! brew install ninja nasm; then + if ! brew install ninja nasm openssl@3; then brew update - brew install ninja nasm + brew install ninja nasm openssl@3 fi + # keg-only, so give CMake's FindOpenSSL an explicit hint + echo "OPENSSL_ROOT_DIR=$(brew --prefix openssl@3)" >> $GITHUB_ENV - name: Setup sccache uses: hendrikmuhs/ccache-action@v1.2.23 diff --git a/CMakeLists.txt b/CMakeLists.txt index b66598562b..f6ddddf93a 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -26,10 +26,13 @@ else() endif() # For clangd +# file(COPY), not configure_file(): configure_file registers its input as a +# configure dependency, putting the ever-rewritten compile_commands.json into +# the Ninja regen rule and causing an endless reconfigure loop. if (EXISTS "${CMAKE_CURRENT_BINARY_DIR}/compile_commands.json" ) - configure_file( + file(COPY "${CMAKE_CURRENT_BINARY_DIR}/compile_commands.json" - "${PROJECT_SOURCE_DIR}/build/compile_commands.json") + DESTINATION "${PROJECT_SOURCE_DIR}/build") endif() # NOTE - for SDL, i think SDL3 regressed this - https://github.com/libsdl-org/SDL/pull/6455 @@ -213,18 +216,24 @@ set(CURL_USE_LIBSSH2 OFF) # but this is another part of libcurl we probably don't need (multi-threading/parallelism) set(CURL_USE_LIBPSL OFF) set(CURL_ZLIB OFF) +# these default to AUTO since curl 8.10 and would silently pick up system libs +set(CURL_BROTLI OFF) +set(CURL_ZSTD OFF) +# curl's BUILD_EXAMPLES cache option (default ON) would otherwise leak into +# discord-rpc's identically named option and break its examples add_subdirectory +set(BUILD_EXAMPLES OFF) # suddenly became enabled on macOS atleast, only needed for unicode URLs # wasn't being properly statically linked set(USE_LIBIDN2 OFF) if(WIN32) set(CURL_USE_SCHANNEL ON) # native Windows SSL support -elseif(APPLE) - set(CURL_USE_SECTRANSP ON) # native macOS SSL support else() + # curl 8.15 removed the native macOS backend (CURL_USE_SECTRANSP), so macOS + # uses OpenSSL like linux (Homebrew openssl@3, see the macOS build workflows) if(STATICALLY_LINK) set(OPENSSL_USE_STATIC_LIBS TRUE) endif() - set(CURL_USE_OPENSSL ON) # not native, but seems to be the best choice for linux + set(CURL_USE_OPENSSL ON) endif() include_directories(third-party/curl/include) if(STATICALLY_LINK) diff --git a/docs/setup/system/macos.md b/docs/setup/system/macos.md index de3205e5de..36c42e41ce 100644 --- a/docs/setup/system/macos.md +++ b/docs/setup/system/macos.md @@ -17,7 +17,8 @@ softwareupdate --install-rosetta ## Building for x86_64 ```bash -brew install cmake nasm ninja go-task clang-format +brew install cmake nasm ninja go-task clang-format openssl@3 +export OPENSSL_ROOT_DIR=$(brew --prefix openssl@3) cmake -B build --preset=Release-macos-x86_64-clang cmake --build build --parallel $((`sysctl -n hw.logicalcpu`)) ``` @@ -25,7 +26,8 @@ cmake --build build --parallel $((`sysctl -n hw.logicalcpu`)) ## Building for ARM64 (experimental, unsupported) ```bash -brew install cmake ninja go-task clang-format +brew install cmake ninja go-task clang-format openssl@3 +export OPENSSL_ROOT_DIR=$(brew --prefix openssl@3) cmake -B build --preset=Release-macos-arm64-clang cmake --build build --parallel $((`sysctl -n hw.logicalcpu`)) ``` diff --git a/third-party/curl/.azure-pipelines.yml b/third-party/curl/.azure-pipelines.yml deleted file mode 100644 index ec04019339..0000000000 --- a/third-party/curl/.azure-pipelines.yml +++ /dev/null @@ -1,315 +0,0 @@ -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### -# https://dev.azure.com/daniel0244/curl/_build?view=runs -# -# Azure Pipelines configuration: -# https://aka.ms/yaml - -trigger: - branches: - include: - - 'master' - - '*/ci' - paths: - exclude: - - '.circleci/*' - - '.cirrus.yml' - - '.github/*' - - '.github/workflows/*' - - 'appveyor.yml' - - 'packages/*' - - 'plan9/*' - -pr: - branches: - include: - - 'master' - paths: - exclude: - - '.circleci/*' - - '.cirrus.yml' - - '.github/*' - - '.github/workflows/*' - - 'appveyor.yml' - - 'packages/*' - - 'plan9/*' - -stages: - -########################################## -### Linux jobs first -########################################## - -- stage: linux - dependsOn: [] - jobs: - - job: ubuntu - # define defaults to make sure variables are always expanded/replaced - variables: - install: '' - configure: '' - tests: '!433' - timeoutInMinutes: 60 - pool: - vmImage: 'ubuntu-latest' - strategy: - matrix: - default: - name: default - install: - configure: --enable-debug --with-openssl - disable_ipv6: - name: w/o IPv6 - configure: --disable-ipv6 --with-openssl - disable_http_smtp_imap: - name: w/o HTTP/SMTP/IMAP - configure: --disable-http --disable-smtp --disable-imap --without-ssl - disable_thredres: - name: sync resolver - configure: --disable-threaded-resolver --with-openssl - https_only: - name: HTTPS only - configure: --disable-dict --disable-file --disable-ftp --disable-gopher --disable-imap --disable-ldap --disable-pop3 --disable-rtmp --disable-rtsp --disable-scp --disable-sftp --disable-smb --disable-smtp --disable-telnet --disable-tftp --with-openssl - torture: - name: torture - install: libnghttp2-dev - configure: --enable-debug --disable-shared --disable-threaded-resolver --with-openssl - tests: -n -t --shallow=25 !FTP - steps: - - script: sudo apt-get update && sudo apt-get install -y stunnel4 python3-impacket libzstd-dev libbrotli-dev $(install) - displayName: 'apt install' - retryCountOnTaskFailure: 3 - - - script: autoreconf -fi && ./configure --enable-warnings --enable-werror $(configure) - displayName: 'configure $(name)' - - - script: make V=1 && make V=1 examples && cd tests && make V=1 - displayName: 'compile' - env: - MAKEFLAGS: "-j 2" - - - script: make V=1 test-ci - displayName: 'test' - env: - AZURE_ACCESS_TOKEN: "$(System.AccessToken)" - TFLAGS: "-ac /usr/bin/curl -r $(tests)" - -- stage: distcheck - dependsOn: [] - jobs: - - job: ubuntu - timeoutInMinutes: 30 - pool: - vmImage: 'ubuntu-latest' - steps: - - script: autoreconf -fi && ./configure --without-ssl - displayName: 'configure $(name)' - - - script: make && ./maketgz 99.98.97 - displayName: 'make tarball' - - - script: | - tar xf curl-99.98.97.tar.gz - cd curl-99.98.97 - ./configure --prefix=$HOME/temp --without-ssl - make - make TFLAGS=1 test - make install - # basic check of the installed files - cd .. - bash scripts/installcheck.sh $HOME/temp - rm -rf curl-99.98.97 - - displayName: 'verify in-tree configure build' - - - script: | - # verify out-of-tree build - tar xf curl-99.98.97.tar.gz - touch curl-99.98.97/docs/{cmdline-opts,libcurl}/Makefile.inc - mkdir build - cd build - ../curl-99.98.97/configure --without-ssl - make - make TFLAGS='-p 1 1139' test - # verify cmake build - cd .. - rm -rf curl-99.98.97 - - displayName: 'verify out-of-tree configure build' - - - script: | - tar xf curl-99.98.97.tar.gz - cd curl-99.98.97 - mkdir build - cd build - cmake .. - make - - displayName: 'verify out-of-tree cmake build' - -- stage: scanbuild - dependsOn: [] - jobs: - - job: ubuntu - timeoutInMinutes: 30 - pool: - vmImage: 'ubuntu-latest' - steps: - - script: sudo apt-get update && sudo apt-get install -y clang-tools clang libssl-dev libssh2-1-dev libpsl-dev libbrotli-dev libzstd-dev - displayName: 'apt install' - retryCountOnTaskFailure: 3 - - - script: autoreconf -fi - displayName: 'autoreconf' - - - script: scan-build ./configure --enable-debug --enable-werror --with-openssl --with-libssh2 - displayName: 'configure' - env: - CC: "clang" - CCX: "clang++" - - - script: scan-build --status-bugs make - displayName: 'make' - - - script: scan-build --status-bugs make examples - displayName: 'make examples' - -########################################## -### Windows jobs below -########################################## - -- stage: windows - dependsOn: [] - variables: - agent.preferPowerShellOnContainers: true - jobs: - - job: msys - # define defaults to make sure variables are always expanded/replaced - variables: - container_img: '' - container_cmd: '' - configure: '' - tests: '' - timeoutInMinutes: 120 - pool: - vmImage: 'windows-2019' - strategy: - matrix: - v2_mingw32_openssl: - name: 32-bit OpenSSL/libssh2 - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys2-mingw32:ltsc2019 - container_cmd: C:\msys64\usr\bin\sh - prepare: pacman -S --needed --noconfirm --noprogressbar libssh2-devel mingw-w64-i686-libssh2 mingw-w64-i686-python-pip mingw-w64-i686-python-wheel mingw-w64-i686-python-pyopenssl && python3 -m pip install --prefer-binary impacket - configure: --host=i686-w64-mingw32 --build=i686-w64-mingw32 --prefix=/mingw32 --enable-debug --enable-werror --with-libssh2 --with-openssl - tests: "~571" - v2_mingw64_openssl: - name: 64-bit OpenSSL/libssh2 - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys2-mingw64:ltsc2019 - container_cmd: C:\msys64\usr\bin\sh - prepare: pacman -S --needed --noconfirm --noprogressbar libssh2-devel mingw-w64-x86_64-libssh2 mingw-w64-x86_64-python-pip mingw-w64-x86_64-python-wheel mingw-w64-x86_64-python-pyopenssl && python3 -m pip install --prefer-binary impacket - configure: --host=x86_64-w64-mingw32 --build=x86_64-w64-mingw32 --prefix=/mingw64 --enable-debug --enable-werror --with-libssh2 --with-openssl - tests: "~571" - v2_mingw64_libssh: - name: 64-bit OpenSSL/libssh - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys2-mingw64:ltsc2019 - container_cmd: C:\msys64\usr\bin\sh - prepare: pacman -S --needed --noconfirm --noprogressbar libssh-devel mingw-w64-x86_64-libssh - configure: --host=x86_64-w64-mingw32 --build=x86_64-w64-mingw32 --prefix=/mingw64 --enable-debug --enable-werror --with-libssh --with-openssl - tests: "~571 ~614" - v1_mingw: - name: 32-bit (legacy) - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys1-mingw:ltsc2019 - container_cmd: C:\MinGW\msys\1.0\bin\sh - configure: --host=i686-pc-mingw32 --build=i686-pc-mingw32 --prefix=/mingw --enable-debug --without-ssl --with-mingw1-deprecated - tests: "!203 !1143" - v1_mingw32: - name: 32-bit w/o zlib - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys1-mingw32:ltsc2019 - container_cmd: C:\MinGW\msys\1.0\bin\sh - configure: --host=i686-w64-mingw32 --build=i686-w64-mingw32 --prefix=/mingw32 --enable-debug --enable-werror --without-zlib --without-ssl - tests: "!203 !1143" - v1_mingw64: - name: 64-bit w/o zlib - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys1-mingw64:ltsc2019 - container_cmd: C:\MinGW\msys\1.0\bin\sh - configure: --host=x86_64-w64-mingw32 --build=x86_64-w64-mingw32 --prefix=/mingw64 --enable-debug --enable-werror --without-zlib --without-ssl - tests: "!203 !1143" - v2_mingw32_schannel: - name: 32-bit Schannel/SSPI/WinIDN/libssh2 - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys2-mingw32:ltsc2019 - container_cmd: C:\msys64\usr\bin\sh - prepare: pacman -S --needed --noconfirm --noprogressbar libssh2-devel mingw-w64-i686-libssh2 mingw-w64-i686-python-pip mingw-w64-i686-python-wheel mingw-w64-i686-python-pyopenssl && python3 -m pip install --prefer-binary impacket - configure: --host=i686-w64-mingw32 --build=i686-w64-mingw32 --prefix=/mingw32 --enable-debug --enable-werror --enable-sspi --with-schannel --with-winidn --with-libssh2 - tests: "~571" - v2_mingw64_schannel: - name: 64-bit Schannel/SSPI/WinIDN/libssh2 - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys2-mingw64:ltsc2019 - container_cmd: C:\msys64\usr\bin\sh - prepare: pacman -S --needed --noconfirm --noprogressbar libssh2-devel mingw-w64-x86_64-libssh2 mingw-w64-x86_64-python-pip mingw-w64-x86_64-python-wheel mingw-w64-x86_64-python-pyopenssl && python3 -m pip install --prefer-binary impacket - configure: --host=x86_64-w64-mingw32 --build=x86_64-w64-mingw32 --prefix=/mingw64 --enable-debug --enable-werror --enable-sspi --with-schannel --with-winidn --with-libssh2 - tests: "~571" - v1_mingw_schannel: - name: 32-bit Schannel/SSPI/WinIDN (legacy) - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys1-mingw:ltsc2019 - container_cmd: C:\MinGW\msys\1.0\bin\sh - configure: --host=i686-pc-mingw32 --build=i686-pc-mingw32 --prefix=/mingw --enable-debug --enable-sspi --with-schannel --with-winidn --with-mingw1-deprecated - tests: "!203 !305 !311 !312 !313 !404 !1143 !2033 !2035 !2038 !2041 !2042 !2048 !2070 !2079 !2087 !3023 !3024" - v1_mingw32_schannel: - name: 32-bit Schannel/SSPI/WinIDN w/o zlib - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys1-mingw32:ltsc2019 - container_cmd: C:\MinGW\msys\1.0\bin\sh - configure: --host=i686-w64-mingw32 --build=i686-w64-mingw32 --prefix=/mingw32 --enable-debug --enable-werror --enable-sspi --with-schannel --with-winidn --without-zlib - tests: "!203 !1143" - v1_mingw64_schannel: - name: 64-bit Schannel/SSPI/WinIDN w/o zlib - container_img: ghcr.io/mback2k/curl-docker-winbuildenv/msys1-mingw64:ltsc2019 - container_cmd: C:\MinGW\msys\1.0\bin\sh - configure: --host=x86_64-w64-mingw32 --build=x86_64-w64-mingw32 --prefix=/mingw64 --enable-debug --enable-werror --enable-sspi --with-schannel --with-winidn --without-zlib - tests: "!203 !1143" - container: - image: $(container_img) - env: - MSYS2_PATH_TYPE: inherit - steps: - - script: $(container_cmd) -l -c "cd $(echo '%cd%') && $(prepare)" - displayName: 'prepare' - condition: variables.prepare - retryCountOnTaskFailure: 3 - - - script: $(container_cmd) -l -c "cd $(echo '%cd%') && autoreconf -fi && ./configure $(configure)" - displayName: 'configure $(name)' - - - script: $(container_cmd) -l -c "cd $(echo '%cd%') && make V=1 && make V=1 examples && cd tests && make V=1" - displayName: 'compile' - env: - MAKEFLAGS: "-j 2" - - - script: $(container_cmd) -l -c "cd $(echo '%cd%') && make V=1 install && PATH=/usr/bin:/bin find . -type f -path '*/.libs/*.exe' -print -execdir mv -t .. {} \;" - displayName: 'install' - - - script: $(container_cmd) -l -c "cd $(echo '%cd%') && make V=1 test-ci" - displayName: 'test' - env: - AZURE_ACCESS_TOKEN: "$(System.AccessToken)" - TFLAGS: "-ac /usr/bin/curl.exe !IDN !SCP ~612 ~1056 $(tests)" diff --git a/third-party/curl/.circleci/config.yml b/third-party/curl/.circleci/config.yml index 11bb0ef7b2..30eec16e5a 100644 --- a/third-party/curl/.circleci/config.yml +++ b/third-party/curl/.circleci/config.yml @@ -24,115 +24,10 @@ # View these jobs in the browser: https://app.circleci.com/pipelines/github/curl/curl -# Use the latest 2.1 version of CircleCI pipeline process engine. See: https://circleci.com/docs/2.0/configuration-reference +# Use the latest 2.1 version of CircleCI pipeline process engine. See: https://circleci.com/docs/configuration-reference/ version: 2.1 commands: - configure: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-werror --with-openssl - - configure-openssl-no-verbose: - steps: - - run: - command: | - autoreconf -fi - ./configure --disable-verbose --enable-werror --with-openssl - - configure-no-proxy: - steps: - - run: - command: | - autoreconf -fi - ./configure --disable-proxy --enable-werror --with-openssl - - configure-macos-normal: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --without-ssl CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - - configure-macos-debug: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --without-ssl --enable-debug CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - - configure-macos-libssh2: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --without-ssl --with-libssh2=/opt/homebrew/opt/libssh2 --enable-debug CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - - configure-macos-libssh-c-ares: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --with-openssl --with-libssh --enable-ares --enable-debug PKG_CONFIG_PATH="$(brew --prefix openssl)/lib/pkgconfig" CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - - configure-macos-libssh: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --with-openssl --with-libssh --enable-debug PKG_CONFIG_PATH="$(brew --prefix openssl)/lib/pkgconfig" CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - - configure-macos-c-ares: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --without-ssl --enable-ares --enable-debug CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - - configure-macos-http-only: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-maintainer-mode --disable-dict --disable-file --disable-ftp --disable-gopher --disable-imap --disable-ldap --disable-pop3 --disable-rtmp --disable-rtsp --disable-scp --disable-sftp --disable-smb --disable-smtp --disable-telnet --disable-tftp --disable-unix-sockets --disable-shared --without-brotli --without-gssapi --without-libidn2 --without-libpsl --without-librtmp --without-libssh2 --without-nghttp2 --without-ntlm-auth --without-ssl --without-zlib --enable-debug CFLAGS='-Wno-vla -mmacosx-version-min=10.15' - - configure-macos-securetransport-http2: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --with-secure-transport CFLAGS='-Wno-vla -mmacosx-version-min=10.8' - - configure-macos-openssl-http2: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --with-openssl --enable-debug PKG_CONFIG_PATH="$(brew --prefix openssl)/lib/pkgconfig" CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - - configure-macos-libressl-http2: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --with-openssl --enable-debug PKG_CONFIG_PATH="$(brew --prefix libressl)/lib/pkgconfig" CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - - configure-macos-torture: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --disable-shared --disable-threaded-resolver --with-openssl --enable-debug PKG_CONFIG_PATH="$(brew --prefix openssl)/lib/pkgconfig" CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - - configure-macos-torture-ftp: - steps: - - run: - command: | - autoreconf -fi - ./configure --enable-warnings --enable-websockets --disable-shared --disable-threaded-resolver --with-openssl --enable-debug PKG_CONFIG_PATH="$(brew --prefix openssl)/lib/pkgconfig" CFLAGS='-Wno-vla -mmacosx-version-min=10.9' - install-cares: steps: - run: @@ -143,6 +38,7 @@ commands: steps: - run: command: | + export DEBIAN_FRONTEND=noninteractive sudo apt-get update && sudo apt-get install -y libssh-dev install-deps: @@ -150,127 +46,86 @@ commands: - run: command: | sudo apt-get update && sudo apt-get install -y libpsl-dev libbrotli-dev libzstd-dev zlib1g-dev python3-pip - sudo python3 -m pip install impacket + python3 -m venv ~/venv + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r tests/requirements.txt - install-deps-brew: + configure: steps: - run: command: | - # Drop libressl as long as we're not trying to build it - echo libtool autoconf automake pkg-config nghttp2 libssh2 openssl libssh c-ares | xargs -Ix -n1 echo brew '"x"' > /tmp/Brewfile - while [ $? -eq 0 ]; do for i in 1 2 3; do brew update && brew bundle install --no-lock --file /tmp/Brewfile && break 2 || { echo Error: wait to try again; sleep 10; } done; false Too many retries; done - sudo python3 -m pip install impacket + autoreconf -fi + ./configure --disable-dependency-tracking --enable-option-checking=fatal --enable-unity --enable-werror --enable-warnings \ + --with-openssl \ + || { tail -1000 config.log; false; } + + configure-no-proxy: + steps: + - run: + command: | + autoreconf -fi + ./configure --disable-dependency-tracking --enable-option-checking=fatal --enable-unity --enable-werror \ + --with-openssl --disable-proxy \ + || { tail -1000 config.log; false; } configure-libssh: steps: - run: command: | autoreconf -fi - ./configure --enable-warnings --enable-werror --with-openssl --with-libssh - - install-wolfssl: - steps: - - run: - command: | - WOLFSSL_VER=5.6.0 - curl -LOsSf --retry 6 --retry-connrefused --max-time 999 https://github.com/wolfSSL/wolfssl/archive/v$WOLFSSL_VER-stable.tar.gz - tar -xzf v$WOLFSSL_VER-stable.tar.gz - cd wolfssl-$WOLFSSL_VER-stable - ./autogen.sh - ./configure --enable-tls13 --enable-all --enable-harden --prefix=$HOME/wssl - make install - - install-wolfssh: - steps: - - run: - command: | - WOLFSSH_VER=1.4.12 - curl -LOsSf --retry 6 --retry-connrefused --max-time 999 https://github.com/wolfSSL/wolfssh/archive/v$WOLFSSH_VER-stable.tar.gz - tar -xzf v$WOLFSSH_VER-stable.tar.gz - cd wolfssh-$WOLFSSH_VER-stable - ./autogen.sh - ./configure --with-wolfssl=$HOME/wssl --prefix=$HOME/wssh --enable-scp --enable-sftp --disable-examples - make install + ./configure --disable-dependency-tracking --enable-option-checking=fatal --enable-unity --enable-werror --enable-warnings \ + --with-openssl --with-libssh \ + || { tail -1000 config.log; false; } configure-cares: steps: - run: command: | autoreconf -fi - ./configure --enable-warnings --enable-werror --with-openssl --enable-ares - - configure-wolfssh: - steps: - - run: - command: | - autoreconf -fi - LDFLAGS="-Wl,-rpath,$HOME/wssh/lib" ./configure --enable-warnings --enable-werror --with-wolfssl=$HOME/wssl --with-wolfssh=$HOME/wssh + ./configure --disable-dependency-tracking --enable-option-checking=fatal --enable-unity --enable-werror --enable-warnings \ + --with-openssl --enable-ares \ + || { tail -1000 config.log; false; } configure-cares-debug: steps: - run: command: | autoreconf -fi - ./configure --enable-debug --enable-werror --with-openssl --enable-ares + ./configure --disable-dependency-tracking --enable-option-checking=fatal --enable-unity --enable-werror --enable-debug \ + --with-openssl --enable-ares \ + || { tail -1000 config.log; false; } build: steps: - run: make -j3 V=1 + - run: src/curl --disable --version - run: make -j3 V=1 examples - build-macos: - steps: - - run: make -j7 V=1 - - run: make -j7 V=1 examples - test: steps: - - run: make -j3 V=1 test-ci - - test-macos: - steps: - - run: make -j7 V=1 test-ci - - test-torture: - steps: - - run: make -j5 V=1 test-ci TFLAGS="-n -t --shallow=25 !FTP" - - test-torture-ftp: - steps: - - run: make -j5 V=1 test-ci TFLAGS="-n -t --shallow=20 FTP" + - run: + command: | + source ~/venv/bin/activate + # Revert a CircleCI-specific local setting that makes test 1459 + # return 67 (CURLE_LOGIN_DENIED) instead of the + # expected 60 (CURLE_PEER_FAILED_VERIFICATION). + echo 'StrictHostKeyChecking yes' >> ~/.ssh/config + make -j3 V=1 test-ci TFLAGS='-j14' executors: ubuntu: machine: - image: ubuntu-2004:202010-01 + image: ubuntu-2204:2025.09.1 jobs: basic: executor: ubuntu steps: - checkout + - install-deps - configure - build - test - no-verbose: - executor: ubuntu - steps: - - checkout - - install-deps - - configure-openssl-no-verbose - - build - - wolfssh: - executor: ubuntu - steps: - - checkout - - install-deps - - install-wolfssl - - install-wolfssh - - configure-wolfssh - - build - no-proxy: executor: ubuntu steps: @@ -284,6 +139,7 @@ jobs: executor: ubuntu steps: - checkout + - install-deps - install-cares - configure-cares - build @@ -293,6 +149,7 @@ jobs: executor: ubuntu steps: - checkout + - install-deps - install-libssh - configure-libssh - build @@ -300,162 +157,27 @@ jobs: arm: machine: - image: ubuntu-2004:202101-01 + image: ubuntu-2204:2025.09.1 resource_class: arm.medium steps: - checkout + - install-deps - configure - build - test arm-cares: machine: - image: ubuntu-2004:202101-01 + image: ubuntu-2204:2025.09.1 resource_class: arm.medium steps: - checkout + - install-deps - install-cares - configure-cares-debug - build - test - # TODO: All builds with "macos.x86.medium.gen2" must be changed to - # "macos.m1.medium.gen1" in January 2024 because the former will be removed - # (the names should also be changed from macos-x86-* to macos-arm-*). We - # want the M1 (ARM) machines anyway, for platform diversity. - # See https://circleci.com/docs/configuration-reference/#macos-execution-environment - macos-x86-normal: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-normal - - build-macos - - test-macos - - macos-x86-debug: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-debug - - build-macos - - test-macos - - macos-x86-libssh2: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-libssh2 - - build-macos - - test-macos - - macos-x86-libssh-c-ares: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-libssh-c-ares - - build-macos - - test-macos - - macos-x86-libssh: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-libssh - - build-macos - - test-macos - - macos-x86-c-ares: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-c-ares - - build-macos - - test-macos - - macos-x86-http-only: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-http-only - - build-macos - - test-macos - - macos-x86-http-securetransport-http2: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-securetransport-http2 - - build-macos - - test-macos - - macos-x86-http-openssl-http2: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-openssl-http2 - - build-macos - - test-macos - - macos-x86-http-libressl-http2: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-libressl-http2 - - build-macos - - test-macos - - macos-x86-http-torture: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-torture - - build-macos - - test-torture - - macos-x86-http-torture-ftp: - macos: - xcode: 15.0.0 - resource_class: macos.x86.medium.gen2 - steps: - - checkout - - install-deps-brew - - configure-macos-torture-ftp - - build-macos - - test-torture-ftp - workflows: x86-openssl: jobs: @@ -473,14 +195,6 @@ workflows: jobs: - no-proxy - openssl-no-verbose: - jobs: - - no-verbose - - wolfssl-wolfssh: - jobs: - - wolfssh - arm-openssl: jobs: - arm @@ -488,53 +202,3 @@ workflows: arm-openssl-c-ares: jobs: - arm-cares - - macos-x86-normal: - jobs: - - macos-x86-normal - - macos-x86-debug: - jobs: - - macos-x86-debug - - macos-x86-libssh2: - jobs: - - macos-x86-libssh2 - - macos-x86-libssh-c-ares: - jobs: - - macos-x86-libssh-c-ares - - macos-x86-libssh: - jobs: - - macos-x86-libssh - - macos-x86-c-ares: - jobs: - - macos-x86-c-ares - - macos-x86-http-only: - jobs: - - macos-x86-http-only - - macos-x86-http-securetransport-http2: - jobs: - - macos-x86-http-securetransport-http2 - - macos-x86-http-openssl-http2: - jobs: - - macos-x86-http-openssl-http2 - - # There are problem linking with LibreSSL on the CI boxes that prevent this - # from working. - #macos-x86-http-libressl-http2: - # jobs: - # - macos-x86-http-libressl-http2 - - macos-x86-http-torture: - jobs: - - macos-x86-http-torture - - macos-x86-http-torture-ftp: - jobs: - - macos-x86-http-torture-ftp diff --git a/third-party/curl/.cirrus.yml b/third-party/curl/.cirrus.yml deleted file mode 100644 index 26aa20e526..0000000000 --- a/third-party/curl/.cirrus.yml +++ /dev/null @@ -1,85 +0,0 @@ -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### -# https://cirrus-ci.com/github/curl/curl -# -# Cirrus CI configuration: -# https://cirrus-ci.org/guide/writing-tasks/ - -freebsd_task: - skip: "changesIncludeOnly( - '**/CMakeLists.txt', - '.azure-pipelines.yml', - '.circleci/**', - '.github/**', - 'appveyor.yml', - 'CMake/**', - 'packages/**', - 'plan9/**', - 'projects/**', - 'winbuild/**' - )" - - name: FreeBSD - - matrix: - - name: FreeBSD 13.2 - freebsd_instance: - image_family: freebsd-13-2 - - env: - CIRRUS_CLONE_DEPTH: 10 - CRYPTOGRAPHY_DONT_BUILD_RUST: 1 - MAKEFLAGS: -j 3 - - pkginstall_script: - - pkg update -f - - pkg install -y autoconf automake libtool pkgconf brotli openldap24-client heimdal libpsl libssh2 openssh-portable libidn2 librtmp libnghttp2 nghttp2 stunnel py39-openssl py39-impacket py39-cryptography - - pkg delete -y curl - configure_script: - - autoreconf -fi - # Building with the address sanitizer is causing unexplainable test issues due to timeouts - #- case `uname -r` in - # 12.2*) - # export CC=clang; - # export CFLAGS="-fsanitize=address,undefined,signed-integer-overflow -fno-sanitize-recover=undefined,integer -Wformat -Werror=format-security -Werror=array-bounds -g"; - # export CXXFLAGS="-fsanitize=address,undefined -fno-sanitize-recover=undefined,integer -Wformat -Werror=format-security -Werror=array-bounds -g"; - # export LDFLAGS="-fsanitize=address,undefined -fno-sanitize-recover=undefined,integer" ;; - # esac - - ./configure --prefix="${HOME}"/install --enable-debug --with-openssl --with-libssh2 --with-brotli --with-gssapi --with-libidn2 --enable-manual --enable-ldap --enable-ldaps --with-librtmp --with-libpsl --with-nghttp2 || { tail -300 config.log; false; } - compile_script: - - make V=1 && make V=1 examples && cd tests && make V=1 - test_script: - # blackhole? - - sysctl net.inet.tcp.blackhole - # make sure we don't run blackhole != 0 - - sudo sysctl net.inet.tcp.blackhole=0 - # Some tests won't run if run as root so run them as another user. - # Make directories world writable so the test step can write wherever it needs. - - find . -type d -exec chmod 777 {} \; - # The OpenSSH server instance for the testsuite cannot be started on FreeBSD, - # therefore the SFTP and SCP tests are disabled right away from the beginning. - # - - sudo -u nobody make V=1 TFLAGS="-n !SFTP !SCP" test-ci - install_script: - - make V=1 install diff --git a/third-party/curl/.clang-tidy.yml b/third-party/curl/.clang-tidy.yml new file mode 100644 index 0000000000..5f523fb50b --- /dev/null +++ b/third-party/curl/.clang-tidy.yml @@ -0,0 +1,59 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl +--- +# https://clang.llvm.org/extra/clang-tidy/ + +# https://clang.llvm.org/extra/clang-tidy/checks/list.html +Checks: + - clang-analyzer-* + - -clang-analyzer-optin.performance.Padding + - -clang-analyzer-security.ArrayBound # due to false positives with clang-tidy v21.1.0+ + - -clang-analyzer-security.insecureAPI.bzero # for FD_ZERO() (seen on macOS) + - -clang-analyzer-security.insecureAPI.DeprecatedOrUnsafeBufferHandling + - -clang-diagnostic-nullability-extension + - bugprone-assert-side-effect + - bugprone-assignment-in-if-condition + - bugprone-chained-comparison + - bugprone-dynamic-static-initializers + - bugprone-invalid-enum-default-initialization + - bugprone-macro-parentheses + - bugprone-macro-repeated-side-effects + - bugprone-misplaced-operator-in-strlen-in-alloc + - bugprone-misplaced-pointer-arithmetic-in-alloc + - bugprone-not-null-terminated-result + - bugprone-posix-return + - bugprone-redundant-branch-condition + - bugprone-signed-char-misuse + - bugprone-sizeof-expression + - bugprone-suspicious-enum-usage + - bugprone-suspicious-memset-usage + - bugprone-suspicious-missing-comma + - bugprone-suspicious-realloc-usage + - bugprone-suspicious-semicolon + # bugprone-unchecked-string-to-number-conversion # needs converting sscanf to strtol or curlx_str_* + - misc-const-correctness + - misc-header-include-cycle + # misc-redundant-expression # undesired hits due to system macros, e.g. due to POLLIN == POLLRDNORM | POLLRDBAND, then or-ing all three + - portability-* + - readability-duplicate-include + # readability-else-after-return + # readability-enum-initial-value + # readability-function-cognitive-complexity + - readability-inconsistent-declaration-parameter-name + # readability-misleading-indentation # too many false positives and oddball/conditional source + - readability-named-parameter + # readability-redundant-casting # false positives in types that change from platform to platform, even with IgnoreTypeAliases: true + - readability-redundant-control-flow + - readability-redundant-declaration + - readability-redundant-function-ptr-dereference + - readability-redundant-parentheses + - readability-redundant-preprocessor + - readability-suspicious-call-argument + - readability-uppercase-literal-suffix + +CheckOptions: + misc-header-include-cycle.IgnoredFilesList: 'curl/curl.h' + readability-inconsistent-declaration-parameter-name.Strict: true + +HeaderFilterRegex: '.*' # Default in v22.1.0+ diff --git a/third-party/curl/.dcignore b/third-party/curl/.dcignore deleted file mode 100644 index e33af3ecc8..0000000000 --- a/third-party/curl/.dcignore +++ /dev/null @@ -1,7 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -tests/** -docs/** -docs/examples/** diff --git a/third-party/curl/.editorconfig b/third-party/curl/.editorconfig new file mode 100644 index 0000000000..edcc4629fb --- /dev/null +++ b/third-party/curl/.editorconfig @@ -0,0 +1,18 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +root = true + +[*] +charset = utf-8 +insert_final_newline = true +indent_style = space +trim_trailing_whitespace = true + +[*.{c,h}] +indent_size = 2 +max_line_length = 79 + +[*.{pl,pm}] +indent_size = 4 diff --git a/third-party/curl/.gitattributes b/third-party/curl/.gitattributes index 481fd5cff6..fc4480fb72 100644 --- a/third-party/curl/.gitattributes +++ b/third-party/curl/.gitattributes @@ -2,8 +2,6 @@ # # SPDX-License-Identifier: curl -*.dsw -crlf -buildconf eol=lf configure.ac eol=lf *.m4 eol=lf *.in eol=lf @@ -11,8 +9,6 @@ configure.ac eol=lf *.sh eol=lf *.[ch] whitespace=tab-in-indent -# Batch files (bat,btm,cmd) must be run with CRLF line endings. +# Batch files must be run with CRLF line endings. # Refer to https://github.com/curl/curl/pull/6442 *.bat text eol=crlf -*.btm text eol=crlf -*.cmd text eol=crlf diff --git a/third-party/curl/.github/CONTRIBUTING.md b/third-party/curl/.github/CONTRIBUTING.md index 18be9ed224..6121de5b8b 100644 --- a/third-party/curl/.github/CONTRIBUTING.md +++ b/third-party/curl/.github/CONTRIBUTING.md @@ -4,26 +4,19 @@ Copyright (C) Daniel Stenberg, , et al. SPDX-License-Identifier: curl --> -How to contribute to curl -========================= +# How to contribute to curl -Join the community ------------------- +## Join the community - 1. Click 'watch' on the GitHub repo +1. Click 'watch' on the GitHub repo +2. Subscribe to the suitable [mailing lists](https://curl.se/mail/) - 2. Subscribe to the suitable [mailing lists](https://curl.se/mail/) +## Read [CONTRIBUTE](/docs/CONTRIBUTE.md) -Read [CONTRIBUTE](../docs/CONTRIBUTE.md) ---------------------------------------- +## Send your suggestions using one of these methods: -Send your suggestions using one of these methods: -------------------------------------------------- +1. in a mail to the mailing list +2. as a [pull request](https://github.com/curl/curl/pulls) +3. as an [issue](https://github.com/curl/curl/issues) - 1. in a mail to the mailing list - - 2. as a [pull request](https://github.com/curl/curl/pulls) - - 3. as an [issue](https://github.com/curl/curl/issues) - -/ The curl team! +/ The curl team diff --git a/third-party/curl/.github/ISSUE_TEMPLATE/bug_report.yml b/third-party/curl/.github/ISSUE_TEMPLATE/bug_report.yml index e74ac08175..52011a6f19 100644 --- a/third-party/curl/.github/ISSUE_TEMPLATE/bug_report.yml +++ b/third-party/curl/.github/ISSUE_TEMPLATE/bug_report.yml @@ -2,8 +2,8 @@ # # SPDX-License-Identifier: curl -name: Bug Report -description: Create a report to help us improve +name: Bug Report on code +description: Tell us about your problem with curl or libcurl body: - type: markdown @@ -13,12 +13,18 @@ body: Only file bugs here! Ask questions on the mailing lists https://curl.se/mail/ - **SECURITY RELATED?** Post it here: https://hackerone.com/curl + **SECURITY RELATED?** Submit here: https://hackerone.com/curl - There are collections of known issues to be aware of: + - type: markdown + attributes: + value: " + > [!IMPORTANT] - - https://curl.se/docs/knownbugs.html - - https://curl.se/docs/todo.html + > If you cannot understand or explain your work without using + Artificial Intelligence (AI) then do not file here. Do not paste + massive AI generated explanations. We accept the use of AI as long as + it is digestible. Please explain your issues or improvements briefly + and clearly in your own human voice." - type: textarea id: reproducer @@ -40,7 +46,7 @@ body: label: curl/libcurl version description: | Please paste the output of `curl -V` here. - placeholder: 'curl 8.2.0' + placeholder: 'curl 8.18.0' validations: required: true diff --git a/third-party/curl/.github/ISSUE_TEMPLATE/config.yml b/third-party/curl/.github/ISSUE_TEMPLATE/config.yml index 9ca2c8fd11..bce618da79 100644 --- a/third-party/curl/.github/ISSUE_TEMPLATE/config.yml +++ b/third-party/curl/.github/ISSUE_TEMPLATE/config.yml @@ -4,12 +4,15 @@ blank_issues_enabled: false contact_links: + - name: Ask a question (without email) + url: https://github.com/curl/curl/discussions + about: Use the Discussion forum here on GitHub + - name: Ask a question (using email) + url: https://curl.se/mail/ + about: Send question to the suitable mailing list + - name: Commercial support + url: https://curl.se/support.html + about: Pay for fast quality support for and help with curl/libcurl - name: Feature request url: https://curl.se/mail/ about: To propose new features or enhancements, please bring that discussion to a suitable curl mailing list. - - name: Question - url: https://curl.se/mail/ - about: Questions should go to the mailing list - - name: Commercial support - url: https://curl.se/support.html - about: Several companies are offering paid support for curl/libcurl diff --git a/third-party/curl/.github/ISSUE_TEMPLATE/docs.yml b/third-party/curl/.github/ISSUE_TEMPLATE/docs.yml new file mode 100644 index 0000000000..d0c3852183 --- /dev/null +++ b/third-party/curl/.github/ISSUE_TEMPLATE/docs.yml @@ -0,0 +1,43 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +name: Bug Report on documentation +description: Problems, errors, mistakes or typos in documentation. +labels: documentation + +body: + - type: markdown + attributes: + value: | + Thanks for taking the time to fill out this bug report! + + Only file documentation bugs here! Ask questions on the mailing lists https://curl.se/mail/ + + - type: markdown + attributes: + value: " + > [!IMPORTANT] + + > If you cannot understand or explain your work without using + Artificial Intelligence (AI) then do not file here. Do not paste + massive AI generated explanations. We accept the use of AI as long as + it is digestible. Please explain your issues or improvements briefly + and clearly in your own human voice." + + - type: textarea + id: source + attributes: + label: Specify which documentation you found a problem with + description: | + Include function name, URL, tarball version and all other relevant + details that identify the documentation source. + validations: + required: true + + - type: textarea + id: problem + attributes: + label: The problem + validations: + required: true diff --git a/third-party/curl/.github/dependabot.yml b/third-party/curl/.github/dependabot.yml new file mode 100644 index 0000000000..c68d6301ef --- /dev/null +++ b/third-party/curl/.github/dependabot.yml @@ -0,0 +1,38 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +# https://docs.github.com/code-security/dependabot/working-with-dependabot/dependabot-options-reference + +version: 2 +updates: + - package-ecosystem: 'github-actions' + directory: '/' + schedule: + interval: 'monthly' + cooldown: + default-days: 7 + groups: + gha-dependencies: + patterns: + - '*' + commit-message: + prefix: 'GHA:' + + - package-ecosystem: 'pip' + directories: + - '.github/scripts' + - 'tests' + schedule: + interval: 'monthly' + cooldown: + default-days: 7 + semver-major-days: 15 + semver-minor-days: 7 + semver-patch-days: 3 + groups: + pip-dependencies: + patterns: + - '*' + commit-message: + prefix: 'GHA:' diff --git a/third-party/curl/.github/labeler.yml b/third-party/curl/.github/labeler.yml index 83f9e7d68a..f7adaba865 100644 --- a/third-party/curl/.github/labeler.yml +++ b/third-party/curl/.github/labeler.yml @@ -7,297 +7,563 @@ # triaging, but is intended to add labels to the easy cases. If the matching # language becomes more powerful, more cases should be able to be handled. # -# The biggest low-hanging problem is this: -# It looks like there's no way of specifying that a label be added if *all* the -# files match *any* one of a number of globs. This feature request is tracked -# in https://github.com/actions/labeler/issues/423 +# Labels are added in two ways: the any-glob-to-all-files ones are added if all +# the files fit into the category, and the any-glob-to-any-file ones are added +# as long as any file matches. The first ones are for "major" categories (the +# PR is all about that one topic, like HTTP/3), while the second ones are +# "addendums" that give useful information about a PR that is really mostly +# something else (e.g. CI if the PR also touches CI jobs). +# +# N.B. any-glob-to-all-files is misnamed; it acts like one-glob-to-all-files. +# Therefore, to get any-glob-to-all-files semantics with multiple matching +# patterns, they must be joined with commas to a single string surrounded by +# braces. For example: '{lib/**,src/**}'. +# +# See https://github.com/actions/labeler/ for documentation on this file. +--- + +appleOS: + - all: + - changed-files: + - any-glob-to-all-files: "{\ + .github/workflows/macos.yml,\ + lib/config-mac.h,\ + lib/macos*,\ + lib/vtls/apple.*,\ + m4/curl-apple-sectrust.m4\ + }" authentication: -- all: ['docs/mk-ca-bundle.1'] -- all: ['docs/libcurl/opts/CURLINFO_HTTPAUTH*'] -- all: ['docs/libcurl/opts/CURLINFO_PROXYAUTH*'] -- all: ['docs/libcurl/opts/CURLOPT_KRB*'] -- all: ['docs/libcurl/opts/CURLOPT_SASL*'] -- all: ['docs/libcurl/opts/CURLOPT_SERVICE_NAME*'] -- all: ['docs/libcurl/opts/CURLOPT_USERNAME*'] -- all: ['docs/libcurl/opts/CURLOPT_USERPWD*'] -- all: ['docs/libcurl/opts/CURLOPT_XOAUTH*'] -- all: ['lib/*gssapi*'] -- all: ['lib/*krb5*'] -- all: ['lib/*ntlm*'] -- all: ['lib/curl_sasl.*'] -- all: ['lib/http_aws*'] -- all: ['lib/http_digest.*'] -- all: ['lib/http_negotiate.*'] -- all: ['lib/vauth/**'] -- all: ['tests/server/fake_ntlm.c'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + CMake/FindGSS.cmake,\ + CMake/FindLibgsasl.cmake,\ + docs/internals/CREDENTIALS.md,\ + docs/libcurl/opts/CURLINFO_HTTPAUTH*,\ + docs/libcurl/opts/CURLINFO_PROXYAUTH*,\ + docs/libcurl/opts/CURLOPT_KRB*,\ + docs/libcurl/opts/CURLOPT_SASL*,\ + docs/libcurl/opts/CURLOPT_SERVICE_NAME*,\ + docs/libcurl/opts/CURLOPT_USERNAME*,\ + docs/libcurl/opts/CURLOPT_USERPWD*,\ + docs/libcurl/opts/CURLOPT_XOAUTH*,\ + lib/*gssapi*,\ + lib/*ntlm*,\ + lib/creds.*,\ + lib/curl_ntlm*,\ + lib/curl_sasl.*,\ + lib/http_aws*,\ + lib/http_digest.*,\ + lib/http_negotiate.*,\ + lib/http_ntlm.*,\ + lib/vauth/**\ + }" build: -- all: ['**/CMakeLists.txt'] -- all: ['**/Makefile.am'] -- all: ['**/Makefile.inc'] -- all: ['**/Makefile.mk'] -- all: ['**/*.m4'] -- all: ['**/*.mk'] -- all: ['lib/libcurl*.in'] -- all: ['CMake/**'] -- all: ['configure.ac'] -- all: ['m4/**'] -- all: ['MacOSX-Framework'] -- all: ['packages/**'] -- all: ['plan9/**'] -- all: ['projects/**'] -- all: ['winbuild/**'] -- all: ['libcurl.def'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + **/CMakeLists.txt,\ + **/Makefile.am,\ + **/Makefile.inc,\ + **/*.m4,\ + *.m4,\ + docs/INSTALL-CMAKE.md,\ + lib/curl_config-cmake.h.in,\ + lib/libcurl*.in,\ + CMake/**,\ + CMakeLists.txt,\ + configure.ac,\ + m4/**,\ + Makefile.*,\ + projects/**,\ + lib/libcurl.def,\ + tests/cmake/**\ + }" CI: -- any: ['.azure-pipelines.yml'] -- any: ['.circleci/**'] -- any: ['.cirrus.yml'] -- any: ['.github/**'] -- any: ['appveyor.yml'] -- any: ['tests/azure.pm'] -- any: ['tests/appveyor.pm'] + - all: + - changed-files: + - any-glob-to-any-file: + - '.circleci/**' + - '.github/**' + - 'appveyor.*' + - 'scripts/ci*' + - 'tests/azure.pm' + - 'tests/appveyor.pm' + - 'tests/CI.md' cmake: -- all: ['**/CMakeLists.txt'] -- all: ['CMake/**'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + **/CMakeLists.txt,\ + CMake/**,\ + docs/INSTALL-CMAKE.md,\ + lib/curl_config-cmake.h.in,\ + tests/cmake/**\ + }" cmdline tool: -- any: ['docs/cmdline-opts/**'] -- any: ['src/**'] + - all: + - changed-files: + - any-glob-to-any-file: + - 'docs/cmdline-opts/**' + - 'src/**' connecting & proxies: -- all: ['docs/CONNECTION-FILTERS.md'] -- all: ['docs/libcurl/opts/CURLINFO_CONNECT*'] -- all: ['docs/libcurl/opts/CURLINFO_PROXY*'] -- all: ['docs/libcurl/opts/CURLOPT_ADDRESS*'] -- all: ['docs/libcurl/opts/CURLOPT_CONNECT*'] -- all: ['docs/libcurl/opts/CURLOPT_HAPROXY*'] -- all: ['docs/libcurl/opts/CURLOPT_OPENSOCKET*'] -- all: ['docs/libcurl/opts/CURLOPT_PRE_PROXY*'] -- all: ['docs/libcurl/opts/CURLOPT_PROXY*'] -- all: ['docs/libcurl/opts/CURLOPT_SOCKOPT*'] -- all: ['docs/libcurl/opts/CURLOPT_SOCKS*'] -- all: ['docs/libcurl/opts/CURLOPT_TCP*'] -- all: ['docs/libcurl/opts/CURLOPT_TIMEOUT*'] -- all: ['lib/cf-*proxy.*'] -- all: ['lib/cf-socket.*'] -- all: ['lib/cfilters.*'] -- all: ['lib/conncache.*'] -- all: ['lib/connect.*'] -- all: ['lib/http_proxy.*'] -- all: ['lib/if2ip.*'] -- all: ['lib/noproxy.*'] -- all: ['lib/socks.*'] -- all: ['tests/server/socksd.c'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/cmdline-opts/happy-eyeballs*,\ + docs/cmdline-opts/ipv*,\ + docs/cmdline-opts/*proxy*,\ + docs/internals/CONNECTION-FILTERS.md,\ + docs/examples/ipv6.c,\ + docs/libcurl/opts/CURLINFO_CONNECT*,\ + docs/libcurl/opts/CURLINFO_PROXY*,\ + docs/libcurl/opts/CURLOPT_ADDRESS*,\ + docs/libcurl/opts/CURLOPT_CONNECT*,\ + docs/libcurl/opts/CURLOPT_HAPROXY*,\ + docs/libcurl/opts/CURLOPT_OPENSOCKET*,\ + docs/libcurl/opts/CURLOPT_PRE_PROXY*,\ + docs/libcurl/opts/CURLOPT_PROXY*,\ + docs/libcurl/opts/CURLOPT_SOCKOPT*,\ + docs/libcurl/opts/CURLOPT_SOCKS*,\ + docs/libcurl/opts/CURLOPT_TCP*,\ + docs/libcurl/opts/CURLOPT_TIMEOUT*,\ + lib/cf-https-connect.*,\ + lib/cf-ip-happy.*,\ + lib/cf-*proxy.*,\ + lib/cf-socket.*,\ + lib/cfilters.*,\ + lib/conncache.*,\ + lib/connect.*,\ + lib/http_proxy.*,\ + lib/if2ip.*,\ + lib/proxy.*,\ + lib/socks.*,\ + src/tool_cb_soc.*,\ + tests/http/*proxy*,\ + tests/http/*socks*,\ + tests/server/socksd.c\ + }" cookies: -- all: ['docs/HTTP-COOKIES.md'] -- all: ['docs/libcurl/opts/CURLINFO_COOKIE*'] -- all: ['docs/libcurl/opts/CURLOPT_COOKIE*'] -- all: ['lib/cookie.*'] -- all: ['lib/psl.*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + CMake/FindLibpsl.cmake,\ + docs/HTTP-COOKIES.md,\ + docs/cmdline-opts/cookie*,\ + docs/cmdline-opts/junk-session-cookies.md,\ + docs/libcurl/opts/CURLINFO_COOKIE*,\ + docs/libcurl/opts/CURLOPT_COOKIE*,\ + docs/examples/cookie_interface.c,\ + lib/cookie.*,\ + lib/psl.*\ + }" cryptography: -- all: ['docs/CIPHERS.md'] -- all: ['docs/RUSTLS.md'] -- all: ['docs/libcurl/opts/CURLOPT_EGDSOCKET*'] -- all: ['lib/*sha256*'] -- all: ['lib/curl_des.*'] -- all: ['lib/curl_hmac.*'] -- all: ['lib/curl_md?.*'] -- all: ['lib/md?.*'] -- all: ['lib/rand.*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/CIPHERS.md,\ + docs/RUSTLS.md,\ + docs/libcurl/opts/CURLOPT_EGDSOCKET*,\ + lib/*sha256*,\ + lib/*sha512*,\ + lib/curl_hmac.*,\ + lib/curl_md?.*,\ + lib/curl_ntlm_core.*,\ + lib/md?.*,\ + lib/rand.*\ + }" DICT: -- all: ['lib/dict.*'] -- all: ['tests/dictserver.py'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + lib/dict.*,\ + tests/dictserver.py\ + }" documentation: -- all: ['**/*.md'] -- all: ['**/*.txt', '!**/CMakeLists.txt'] -- all: ['**/*.1'] -- all: ['**/*.3'] -- all: ['CHANGES'] -- all: ['docs/**', '!docs/examples/**'] -- all: ['GIT-INFO'] -- all: ['LICENSES/**'] -- all: ['README'] -- all: ['RELEASE-NOTES'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + .github/workflows/checkdocs.yml,\ + .github/scripts/pyspelling*,\ + .github/scripts/requirements-docs.txt,\ + .github/scripts/requirements-proselint.txt,\ + .github/scripts/typos*,\ + .github/scripts/verify-examples.pl,\ + .github/scripts/verify-synopsis.pl,\ + **/*.md,\ + **/*.txt,\ + **/*.1,\ + CHANGES.md,\ + docs/**,\ + LICENSES/**,\ + README,\ + RELEASE-NOTES,\ + scripts/badwords.*,\ + scripts/cd*,\ + scripts/mdlinkcheck,\ + scripts/nroff2cd,\ + scripts/release-notes.pl\ + }" + - all-globs-to-all-files: + # negative matches + - '!**/CMakeLists.txt' + - '!**/Makefile.am' FTP: -- all: ['docs/libcurl/opts/CURLINFO_FTP*'] -- all: ['docs/libcurl/opts/CURLOPT_FTP*'] -- all: ['docs/libcurl/opts/CURLOPT_WILDCARDMATCH*'] -- all: ['lib/curl_fnmatch.*'] -- all: ['lib/curl_range.*'] -- all: ['lib/ftp*'] -- all: ['tests/ftp*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/cmdline-opts/ftp*,\ + docs/libcurl/opts/CURLINFO_FTP*,\ + docs/libcurl/opts/CURLOPT_FTP*,\ + docs/libcurl/opts/CURLOPT_WILDCARDMATCH*,\ + docs/examples/ftp*,\ + lib/curl_fnmatch.*,\ + lib/curl_range.*,\ + lib/ftp*,\ + tests/ftp*,\ + tests/http/*ftpd*,\ + tests/http/testenv/*ftpd*,\ + tests/libtest/*_ftp_*\ + }" GOPHER: -- all: ['lib/gopher*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + lib/gopher*\ + }" HTTP: -- all: ['docs/HSTS.md'] -- all: ['docs/HTTP-COOKIES.md'] -- all: ['docs/libcurl/opts/CURLINFO_COOKIE*'] -- all: ['docs/libcurl/opts/CURLOPT_COOKIE*'] -- all: ['docs/libcurl/opts/CURLINFO_HTTP_**'] -- all: ['docs/libcurl/opts/CURLINFO_REDIRECT*'] -- all: ['docs/libcurl/opts/CURLINFO_REFER*'] -- all: ['docs/libcurl/opts/CURLOPT_FOLLOWLOCATION*'] -- all: ['docs/libcurl/opts/CURLOPT_HSTS*'] -- all: ['docs/libcurl/opts/CURLOPT_HTTP*'] -- all: ['docs/libcurl/opts/CURLOPT_POST.*'] -- all: ['docs/libcurl/opts/CURLOPT_POSTFIELD*'] -- all: ['docs/libcurl/opts/CURLOPT_POSTREDIR*'] -- all: ['docs/libcurl/opts/CURLOPT_REDIR*'] -- all: ['docs/libcurl/opts/CURLOPT_REFER*'] -- all: ['docs/libcurl/opts/CURLOPT_TRAILER*'] -- all: ['docs/libcurl/opts/CURLOPT_TRANSFER_ENCODING*'] -- all: ['lib/cf-https*'] -- all: ['lib/cf-h1*'] -- all: ['lib/cf-h2*'] -- all: ['lib/cookie.*'] -- all: ['lib/http*'] -- all: ['tests/http*'] -- all: ['tests/http-server.pl'] -- all: ['tests/http/*'] -- all: ['tests/nghttp*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/HTTPSRR.md,\ + docs/HSTS.md,\ + docs/examples/hsts*,\ + docs/examples/http-*,\ + docs/examples/httpput*,\ + docs/examples/https*,\ + docs/examples/*post*,\ + docs/HTTP-COOKIES.md,\ + docs/libcurl/opts/CURLINFO_COOKIE*,\ + docs/libcurl/opts/CURLINFO_HTTP*,\ + docs/libcurl/opts/CURLINFO_REDIRECT*,\ + docs/libcurl/opts/CURLINFO_REFER*,\ + docs/libcurl/opts/CURLOPT_COOKIE*,\ + docs/libcurl/opts/CURLOPT_FOLLOWLOCATION*,\ + docs/libcurl/opts/CURLOPT_HSTS*,\ + docs/libcurl/opts/CURLOPT_HTTP*,\ + docs/libcurl/opts/CURLOPT_POST.*,\ + docs/libcurl/opts/CURLOPT_POSTFIELD*,\ + docs/libcurl/opts/CURLOPT_POSTREDIR*,\ + docs/libcurl/opts/CURLOPT_REDIR*,\ + docs/libcurl/opts/CURLOPT_REFER*,\ + docs/libcurl/opts/CURLOPT_TRAILER*,\ + docs/libcurl/opts/CURLOPT_TRANSFER_ENCODING*,\ + lib/cf-https*,\ + lib/cf-h1*,\ + lib/cf-h2*,\ + lib/cookie.*,\ + lib/hsts.*,\ + lib/http*,\ + tests/http*,\ + tests/http-server.pl,\ + tests/http/*,\ + tests/nghttp*\ + }" HTTP/2: -- all: ['docs/HTTP2.md'] -- all: ['docs/libcurl/opts/CURLOPT_STREAM*'] -- all: ['lib/http2*'] -- all: ['tests/http2-server.pl'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + CMake/FindNGHTTP2.cmake,\ + CMake/FindQuiche.cmake,\ + docs/libcurl/opts/CURLOPT_STREAM*,\ + docs/examples/http2*,\ + lib/http2*,\ + tests/http2-server.pl\ + }" HTTP/3: -- all: ['.github/workflows/ngtcp2*'] -- all: ['.github/workflows/quiche*'] -- all: ['docs/HTTP3.md'] -- all: ['lib/vquic/**'] -- all: ['tests/http3-server.pl'] -- all: ['tests/nghttpx.conf'] - -Hyper: -- all: ['docs/HYPER.md'] -- all: ['lib/c-hyper.*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + .github/workflows/http3-linux.yml,\ + CMake/FindNGHTTP3.cmake,\ + CMake/FindNGTCP2.cmake,\ + docs/cmdline-opts/proxy-http3.md,\ + docs/HTTP3.md,\ + docs/examples/http3*,\ + lib/cf-h3-proxy.*,\ + lib/vquic/**,\ + tests/http3-server.pl,\ + tests/nghttpx.conf,\ + tests/http/*httpsrr*\ + }" IMAP: -- all: ['lib/imap*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + lib/imap*,\ + docs/examples/imap*\ + }" LDAP: -- all: ['lib/*ldap*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + lib/*ldap*\ + }" libcurl API: -- all: ['docs/libcurl/ABI.md'] -- any: ['include/curl/**'] + - all: + - changed-files: + - any-glob-to-any-file: + - 'docs/libcurl/ABI.md' + - 'docs/libcurl/curl_*.md' + - 'include/curl/**' + +logging: + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/cmdline-opts/trace*,\ + docs/libcurl/curl_global_trace*,\ + lib/curl_trc*,\ + tests/http/test_15_tracing.py\ + }" MIME: -- all: ['docs/libcurl/curl_mime_*'] -- all: ['docs/libcurl/opts/CURLOPT_MIME*'] -- all: ['lib/mime*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/libcurl/curl_form*,\ + docs/libcurl/curl_mime_*,\ + docs/libcurl/opts/CURLOPT_MIME*,\ + docs/libcurl/opts/CURLOPT_HTTPPOST*,\ + lib/formdata*,\ + lib/mime*,\ + src/tool_formparse.*\ + }" MQTT: -- all: ['docs/MQTT.md'] -- all: ['lib/mqtt*'] -- all: ['tests/server/mqttd.c'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/internals/MQTT.md,\ + lib/mqtt*,\ + tests/server/mqttd.c\ + }" name lookup: -- all: ['docs/libcurl/opts/CURLINFO_NAMELOOKUP*'] -- all: ['docs/libcurl/opts/CURLOPT_DNS*'] -- all: ['docs/libcurl/opts/CURLOPT_DOH*'] -- all: ['docs/libcurl/opts/CURLOPT_RESOLVE*'] -- all: ['lib/asyn*'] -- all: ['lib/curl_gethostname.*'] -- all: ['lib/doh*'] -- all: ['lib/host*'] -- all: ['lib/idn*'] -- all: ['lib/inet_pton.*'] -- all: ['lib/socketpair*'] -- all: ['tests/server/resolve.c'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + CMake/FindLibidn2.cmake,\ + docs/cmdline-opts/doh*,\ + docs/cmdline-opts/dns*,\ + docs/examples/resolve.c,\ + docs/internals/THRDPOOL-AND-QUEUE.md,\ + docs/libcurl/opts/CURLINFO_NAMELOOKUP*,\ + docs/libcurl/opts/CURLOPT_DNS*,\ + docs/libcurl/opts/CURLOPT_DOH*,\ + docs/libcurl/opts/CURLOPT_RESOLVE*,\ + lib/*addrinfo*,\ + lib/asyn*,\ + lib/cf-dns.*,\ + lib/curl_gethostname.*,\ + lib/dns*,\ + lib/doh*,\ + lib/host*,\ + lib/idn*,\ + lib/socketpair*,\ + lib/thrdpool.*,\ + lib/thrdqueue.*,\ + tests/http/testenv/dnsd.*,\ + tests/http/*httpsrr*,\ + tests/http/*resolve.py,\ + tests/server/dnsd.c,\ + tests/server/resolve.c\ + }" POP3: -- all: ['lib/pop3.*'] - -RTMP: -- all: ['lib/curl_rtmp.*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/examples/pop3*,\ + lib/pop3.*\ + }" RTSP: -- all: ['docs/libcurl/opts/CURLINFO_RTSP*'] -- all: ['docs/libcurl/opts/CURLOPT_RTSP*'] -- all: ['lib/rtsp.*'] -- all: ['tests/rtspserver.pl'] -- all: ['tests/server/rtspd.c'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/libcurl/opts/CURLINFO_RTSP*,\ + docs/libcurl/opts/CURLOPT_RTSP*,\ + lib/rtsp.*,\ + tests/rtspserver.pl,\ + tests/server/rtspd.c\ + }" SCP/SFTP: -- all: ['docs/libcurl/opts/CURLOPT_SSH*'] -- all: ['lib/vssh/**'] -- all: ['tests/sshhelp.pm'] -- all: ['tests/sshserver.pl'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + CMake/FindLibssh.cmake,\ + CMake/FindLibssh2.cmake,\ + docs/cmdline-opts/knownhosts.md,\ + docs/libcurl/opts/CURLOPT_SSH*,\ + docs/examples/sftp*,\ + lib/vssh/**,\ + tests/sshhelp.pm,\ + tests/sshserver.pl,\ + tests/http/*scp*,\ + tests/http/*sftp*,\ + tests/http/testenv/sshd.py\ + }" script: -- all: ['**/*.pl'] -- all: ['**/*.sh'] -- all: ['curl-config.in'] -- all: ['docs/curl-config.1'] -- all: ['docs/mk-ca-bundle.1'] -- all: ['docs/THANKS-filter'] -- all: ['scripts/**'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + **/*.pl,\ + **/*.sh,\ + curl-config.in,\ + docs/curl-config.md,\ + docs/mk-ca-bundle.md,\ + docs/wcurl.md,\ + docs/THANKS-filter,\ + scripts/**\ + }" SMB: -- all: ['lib/smb.*'] -- all: ['tests/smbserver.py'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + lib/smb.*,\ + tests/smbserver.py\ + }" SMTP: -- all: ['docs/libcurl/opts/CURLOPT_MAIL*'] -- all: ['lib/smtp.*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/cmdline-opts/mail*,\ + docs/examples/smtp-*,\ + docs/libcurl/opts/CURLOPT_MAIL*,\ + lib/smtp.*\ + }" tests: -- any: ['tests/**'] + - all: + - changed-files: + - any-glob-to-any-file: + - 'docs/tests/**' + - 'tests/**' TFTP: -- all: ['lib/tftp.*'] -- all: ['tests/tftpserver.pl'] -- all: ['tests/server/tftp*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + lib/tftp.*,\ + tests/tftpserver.pl,\ + tests/server/tftp*\ + }" TLS: -- all: ['docs/SSL*'] -- all: ['docs/libcurl/opts/CURLINFO_CA*'] -- all: ['docs/libcurl/opts/CURLINFO_CERT*'] -- all: ['docs/libcurl/opts/CURLINFO_SSL*'] -- all: ['docs/libcurl/opts/CURLINFO_TLS*'] -- all: ['docs/libcurl/opts/CURLOPT_CA*'] -- all: ['docs/libcurl/opts/CURLOPT_CERT*'] -- all: ['docs/libcurl/opts/CURLOPT_PINNEDPUBLICKEY*'] -- all: ['docs/libcurl/opts/CURLOPT_SSL*'] -- all: ['docs/libcurl/opts/CURLOPT_TLS*'] -- all: ['docs/libcurl/opts/CURLOPT_USE_SSL*'] -- all: ['lib/vtls/**'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + CMake/FindGnuTLS.cmake,\ + CMake/FindMbedTLS.cmake,\ + CMake/FindWolfSSL.cmake,\ + CMake/FindRustls.cmake,\ + docs/CIPHERS-TLS12.md,\ + docs/SSL*,\ + docs/cmdline-opts/dump-ca-embed.md,\ + docs/cmdline-opts/*cert*,\ + docs/cmdline-opts/*ssl*,\ + docs/cmdline-opts/*tls*,\ + docs/examples/ssl*,\ + docs/examples/*ssl.*,\ + docs/examples/*tls.*,\ + docs/internals/TLS-SESSIONS.md,\ + docs/libcurl/curl_global_sslset*,\ + docs/libcurl/curl_easy_ssls*,\ + docs/libcurl/opts/CURLINFO_CA*,\ + docs/libcurl/opts/CURLINFO_CERT*,\ + docs/libcurl/opts/CURLINFO_EARLYDATA*,\ + docs/libcurl/opts/CURLINFO_SSL*,\ + docs/libcurl/opts/CURLINFO_TLS*,\ + docs/libcurl/opts/CURLOPT_CA*,\ + docs/libcurl/opts/CURLOPT_CERT*,\ + docs/libcurl/opts/CURLOPT_PINNEDPUBLICKEY*,\ + docs/libcurl/opts/CURLOPT_SSL*,\ + docs/libcurl/opts/CURLOPT_TLS*,\ + docs/libcurl/opts/CURLOPT_USE_SSL*,\ + lib/vtls/**,\ + m4/curl-gnutls.m4,\ + m4/curl-mbedtls.m4,\ + m4/curl-openssl.m4,\ + m4/curl-rustls.m4,\ + m4/curl-schannel.m4,\ + m4/curl-wolfssl.m4,\ + src/tool_ssls.*\ + }" URL: -- all: ['docs/libcurl/curl_url*'] -- all: ['docs/URL-SYNTAX.md'] -- all: ['include/curl/urlapi.h'] -- all: ['lib/urlapi*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/libcurl/curl_url*,\ + docs/URL-SYNTAX.md,\ + docs/examples/parseurl*,\ + include/curl/urlapi.h,\ + lib/urlapi*\ + }" WebSocket: -- all: ['docs/WEBSOCKET.md*'] -- all: ['docs/libcurl/curl_ws_*'] -- all: ['docs/libcurl/libcurl-ws.3'] -- all: ['docs/libcurl/opts/CURLOPT_WS_*'] -- all: ['include/curl/websockets.h'] -- all: ['lib/ws.*'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + docs/internals/WEBSOCKET.md,\ + docs/examples/websocket*,\ + docs/libcurl/curl_ws_*,\ + docs/libcurl/libcurl-ws*,\ + docs/libcurl/opts/CURLOPT_WS_*,\ + include/curl/websockets.h,\ + lib/ws.*,\ + tests/http/test_20_websockets.py,\ + tests/http/testenv/ws*,\ + tests/libtest/cli_ws*\ + }" Windows: -- all: ['CMake/Platforms/WindowsCache.cmake'] -- all: ['lib/*win32*'] -- all: ['lib/curl_multibyte.*'] -- all: ['lib/rename.*'] -- all: ['lib/vtls/schannel*'] -- all: ['m4/curl-schannel.m4'] -- all: ['projects/**'] -- all: ['src/tool_doswin.c'] -- all: ['winbuild/**'] -- all: ['libcurl.def'] + - all: + - changed-files: + - any-glob-to-all-files: "{\ + .github/workflows/windows.yml,\ + appveyor.*,\ + CMake/win32-cache.cmake,\ + lib/*win32*,\ + lib/curlx/fopen.*,\ + lib/curlx/multibyte.*,\ + lib/curlx/winapi.*,\ + lib/libcurl.def,\ + lib/vtls/schannel*,\ + m4/curl-schannel.m4,\ + projects/Windows/**,\ + src/tool_doswin.c\ + }" diff --git a/third-party/curl/.github/pull_request_template.md b/third-party/curl/.github/pull_request_template.md new file mode 100644 index 0000000000..34e39a2172 --- /dev/null +++ b/third-party/curl/.github/pull_request_template.md @@ -0,0 +1,8 @@ + diff --git a/third-party/curl/.github/scripts/cleancmd.pl b/third-party/curl/.github/scripts/cleancmd.pl new file mode 100644 index 0000000000..d6ddeb7274 --- /dev/null +++ b/third-party/curl/.github/scripts/cleancmd.pl @@ -0,0 +1,130 @@ +#!/usr/bin/env perl +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl +# +# Input: cmdline docs markdown files, they get modified *in place* +# +# Strip off the leading meta-data/header part, remove all known curl symbols +# and long command line options. Also clean up whatever else the spell checker +# might have a problem with that we still deem is fine. +# + +use strict; +use warnings; + +my @asyms; + +open(S, "<./docs/libcurl/symbols-in-versions") + or die "cannot find symbols-in-versions"; +while() { + if(/^([^ ]*) /) { + push @asyms, $1; + } +} +close(S); + +# init the opts table with "special" options not easy to figure out +my @aopts = ( + '--ftp-ssl-reqd', # old alias + ); + +open(O, "<./docs/options-in-versions") + or die "cannot find options-in-versions"; +while() { + chomp; + if(/^([^ ]+)/) { + my $o = $1; + push @aopts, $o; + if($o =~ /^--no-(.*)/) { + # for the --no options, also make one without it + push @aopts, "--$1"; + } + elsif($o =~ /^--disable-(.*)/) { + # for the --disable options, also make the special ones + push @aopts, "--$1"; + push @aopts, "--no-$1"; + } + } +} +close(O); + +open(C, "<./.github/scripts/spellcheck.curl") + or die "cannot find spellcheck.curl"; +while() { + if(/^\#/) { + next; + } + chomp; + if(/^([^ ]+)/) { + push @asyms, $1; + } +} +close(C); + +# longest symbols first +my @syms = sort { length($b) <=> length($a) } @asyms; + +# longest cmdline options first +my @opts = sort { length($b) <=> length($a) } @aopts; + +sub process { + my ($f) = @_; + + my $ignore = 0; + my $sepcount = 0; + my $out; + my $line = 0; + open(F, "<$f") or die; + + while() { + $line++; + if(/^---/ && ($line == 1)) { + $ignore = 1; + next; + } + elsif(/^---/ && $ignore) { + $ignore = 0; + next; + } + next if($ignore); + + my $l = $_; + + # strip out backticked words + $l =~ s/`[^`]+`//g; + + # **bold** + $l =~ s/\*\*(\S.*?)\*\*//g; + # *italics* + $l =~ s/\*(\S.*?)\*//g; + + # strip out https URLs, we do not want them spellchecked + $l =~ s!https://[a-z0-9\#_/.-]+!!gi; + + # strip links, both name and target + $l =~ s/(\[.*?\])\(.*?\)//g; + $out .= $l; + } + close(F); + + # cut out all known curl cmdline options + map { $out =~ s/$_//g; } (@opts); + + # cut out all known curl symbols + map { $out =~ s/\b$_\b//g; } (@syms); + + if(!$ignore) { + open(O, ">$f") or die; + print O $out; + close(O); + } +} + +my @filemasks = @ARGV; +open(my $git_ls_files, '-|', 'git', 'ls-files', '--', @filemasks) or die "Failed running git ls-files: $!"; +while(my $f = <$git_ls_files>) { + chomp $f; + process($f); +} +close $git_ls_files; diff --git a/third-party/curl/.github/scripts/cleanspell.pl b/third-party/curl/.github/scripts/cleanspell.pl deleted file mode 100644 index 329a972403..0000000000 --- a/third-party/curl/.github/scripts/cleanspell.pl +++ /dev/null @@ -1,79 +0,0 @@ -#!/usr/bin/perl -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl -# -# Input: a libcurl nroff man page -# Output: the same file, minus the SYNOPSIS and the EXAMPLE sections -# - -my $f = $ARGV[0]; -my $o = $ARGV[1]; - -open(F, "<$f") or die; -open(O, ">$o") or die; - -my $ignore = 0; -while() { - if($_ =~ /^.SH (SYNOPSIS|EXAMPLE|\"SEE ALSO\"|SEE ALSO)/) { - $ignore = 1; - } - elsif($ignore && ($_ =~ /^.SH/)) { - $ignore = 0; - } - elsif(!$ignore) { - # filter out mentioned CURLE_ names - $_ =~ s/CURL(M|SH|U|H)code//g; - $_ =~ s/CURL_(READ|WRITE)FUNC_[A-Z0-9_]*//g; - $_ =~ s/CURL_CSELECT_[A-Z0-9_]*//g; - $_ =~ s/CURL_DISABLE_[A-Z0-9_]*//g; - $_ =~ s/CURL_FORMADD_[A-Z0-9_]*//g; - $_ =~ s/CURL_HET_DEFAULT//g; - $_ =~ s/CURL_IPRESOLVE_[A-Z0-9_]*//g; - $_ =~ s/CURL_PROGRESSFUNC_CONTINUE//g; - $_ =~ s/CURL_REDIR_[A-Z0-9_]*//g; - $_ =~ s/CURL_RTSPREQ_[A-Z0-9_]*//g; - $_ =~ s/CURL_TIMECOND_[A-Z0-9_]*//g; - $_ =~ s/CURL_VERSION_[A-Z0-9_]*//g; - $_ =~ s/CURLALTSVC_[A-Z0-9_]*//g; - $_ =~ s/CURLAUTH_[A-Z0-9_]*//g; - $_ =~ s/CURLE_[A-Z0-9_]*//g; - $_ =~ s/CURLFORM_[A-Z0-9_]*//g; - $_ =~ s/CURLFTP_[A-Z0-9_]*//g; - $_ =~ s/CURLFTPAUTH_[A-Z0-9_]*//g; - $_ =~ s/CURLFTPMETHOD_[A-Z0-9_]*//g; - $_ =~ s/CURLFTPSSL_[A-Z0-9_]*//g; - $_ =~ s/CURLGSSAPI_[A-Z0-9_]*//g; - $_ =~ s/CURLHEADER_[A-Z0-9_]*//g; - $_ =~ s/CURLINFO_[A-Z0-9_]*//g; - $_ =~ s/CURLM_[A-Z0-9_]*//g; - $_ =~ s/CURLMIMEOPT_[A-Z0-9_]*//g; - $_ =~ s/CURLMOPT_[A-Z0-9_]*//g; - $_ =~ s/CURLOPT_[A-Z0-9_]*//g; - $_ =~ s/CURLPIPE_[A-Z0-9_]*//g; - $_ =~ s/CURLPROTO_[A-Z0-9_]*//g; - $_ =~ s/CURLPROXY_[A-Z0-9_]*//g; - $_ =~ s/CURLPX_[A-Z0-9_]*//g; - $_ =~ s/CURLSHE_[A-Z0-9_]*//g; - $_ =~ s/CURLSHOPT_[A-Z0-9_]*//g; - $_ =~ s/CURLSSH_[A-Z0-9_]*//g; - $_ =~ s/CURLSSLBACKEND_[A-Z0-9_]*//g; - $_ =~ s/CURLU_[A-Z0-9_]*//g; - $_ =~ s/CURLUE_[A-Z0-9_]*//g; - $_ =~ s/CURLUPART_[A-Z0-9_]*//g; - $_ =~ s/CURLUSESSL_[A-Z0-9_]*//g; - $_ =~ s/curl_global_(init_mem|sslset|cleanup)//g; - $_ =~ s/curl_(strequal|strnequal|formadd|waitfd|formget|getdate|formfree)//g; - $_ =~ s/curl_easy_(nextheader|duphandle)//g; - $_ =~ s/curl_multi_fdset//g; - $_ =~ s/curl_mime_(subparts|addpart|filedata|data_cb)//g; - $_ =~ s/curl_ws_(send|recv|meta)//g; - $_ =~ s/curl_url_(dup)//g; - $_ =~ s/curl_pushheader_by(name|num)//g; - $_ =~ s/libcurl-(env|ws)//g; - $_ =~ s/(^|\W)((tftp|https|http|ftp):\/\/[a-z0-9\-._~%:\/?\#\[\]\@!\$&'()*+,;=]+)//gi; - print O $_; - } -} -close(F); -close(O); diff --git a/third-party/curl/.github/scripts/cmp-config.pl b/third-party/curl/.github/scripts/cmp-config.pl new file mode 100644 index 0000000000..9c353432bb --- /dev/null +++ b/third-party/curl/.github/scripts/cmp-config.pl @@ -0,0 +1,136 @@ +#!/usr/bin/env perl +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### + +use strict; +use warnings; + +my $autotools = $ARGV[0]; +my $cmake = $ARGV[1]; + +if(!$cmake) { + print "Usage: cmp-config \n"; + exit; +} + +# this lists complete lines that are removed from the output if matching +my %remove = ( + '#define CURL_EXTERN_SYMBOL' => 1, + '#define CURL_OS "Linux"' => 1, + '#define CURL_OS "x86_64-pc-linux-gnu"' => 1, + '#define GETHOSTNAME_TYPE_ARG2 int' => 1, + '#define GETHOSTNAME_TYPE_ARG2 size_t' => 1, + '#define HAVE_BROTLI 1' => 1, + '#define HAVE_BROTLI_DECODE_H 1' => 1, + '#define HAVE_DLFCN_H 1' => 1, + '#define HAVE_GSSAPI_GSSAPI_GENERIC_H 1' => 1, + '#define HAVE_GSSAPI_GSSAPI_H 1' => 1, + '#define HAVE_GSSAPI_GSSAPI_KRB5_H 1' => 1, + '#define HAVE_INTTYPES_H 1' => 1, + '#define HAVE_LDAP_H 1' => 1, + '#define HAVE_LDAP_SSL 1' => 1, + '#define HAVE_LIBBROTLIDEC 1' => 1, + '#define HAVE_LIBPSL_H 1' => 1, + '#define HAVE_LIBSOCKET 1' => 1, + '#define HAVE_LIBSSH' => 1, + '#define HAVE_LIBSSH2 1' => 1, + '#define HAVE_LIBSSL 1' => 1, + '#define HAVE_LIBZSTD 1' => 1, + '#define HAVE_NGHTTP2_NGHTTP2_H 1' => 1, + '#define HAVE_NGHTTP3_NGHTTP3_H 1' => 1, + '#define HAVE_NGTCP2_NGTCP2_CRYPTO_H 1' => 1, + '#define HAVE_NGTCP2_NGTCP2_H 1' => 1, + '#define HAVE_OPENSSL_CRYPTO_H 1' => 1, + '#define HAVE_OPENSSL_ERR_H 1' => 1, + '#define HAVE_OPENSSL_PEM_H 1' => 1, + '#define HAVE_OPENSSL_RSA_H 1' => 1, + '#define HAVE_OPENSSL_SSL_H 1' => 1, + '#define HAVE_QUICHE_H 1' => 1, + '#define HAVE_SSL_SET_QUIC_TLS_CBS 1' => 1, + '#define HAVE_SSL_SET_QUIC_USE_LEGACY_CODEPOINT 1' => 1, + '#define HAVE_STDINT_H 1' => 1, + '#define HAVE_STDIO_H 1' => 1, + '#define HAVE_STDLIB_H 1' => 1, + '#define HAVE_STRING_H 1' => 1, + '#define HAVE_SYS_STAT_H 1' => 1, + '#define HAVE_SYS_XATTR_H 1' => 1, + '#define HAVE_UNICODE_UIDNA_H 1' => 1, + '#define HAVE_WOLFSSL_SET_QUIC_USE_LEGACY_CODEPOINT 1' => 1, + '#define HAVE_ZSTD 1' => 1, + '#define HAVE_ZSTD_H 1' => 1, + '#define LT_OBJDIR ".libs/"' => 1, + '#define NEED_LBER_H 1' => 1, + '#define PACKAGE "curl"' => 1, + '#define PACKAGE_BUGREPORT "a suitable curl mailing list: https://curl.se/mail/"' => 1, + '#define PACKAGE_NAME "curl"' => 1, + '#define PACKAGE_STRING "curl -"' => 1, + '#define PACKAGE_TARNAME "curl"' => 1, + '#define PACKAGE_URL ""' => 1, + '#define PACKAGE_VERSION "-"' => 1, + '#define VERSION "-"' => 1, + '#define _FILE_OFFSET_BITS 64' => 1, + ); + +sub filter { + my ($line) = @_; + if(!$remove{$line}) { + return "$line\n"; + } + $remove{$line}++; + return ""; +} + +sub grepit { + my ($input, $output) = @_; + my @defines; + # first get all the #define lines + open(F, "<$input"); + while() { + if($_ =~ /^#def/) { + chomp; + push @defines, $_; + } + } + close(F); + + open(O, ">$output"); + + # output the sorted list through the filter + foreach my $d(sort @defines) { + print O filter($d); + } + close(O); +} + +grepit($autotools, "/tmp/autotools"); +grepit($cmake, "/tmp/cmake"); + +foreach my $v (keys %remove) { + if($remove{$v} == 1) { + print "Ignored, never matched line: $v\n"; + } +} + +# return the exit code from diff +exit system('diff', ('-u', '/tmp/autotools', '/tmp/cmake')) >> 8; diff --git a/third-party/curl/.github/scripts/cmp-pkg-config.sh b/third-party/curl/.github/scripts/cmp-pkg-config.sh new file mode 100644 index 0000000000..37a316218c --- /dev/null +++ b/third-party/curl/.github/scripts/cmp-pkg-config.sh @@ -0,0 +1,49 @@ +#!/usr/bin/env bash +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl + +# Sort list of libs, libpaths, cflags found in libcurl.pc and curl-config files, +# then diff the autotools and cmake generated ones. + +sort_lists() { + prevline='' + section='' + while IFS= read -r l; do + if [[ "${prevline}" =~ (--cc|--configure) ]]; then # curl-config + echo "" + else + # libcurl.pc + if [[ "${l}" =~ ^(Requires|Libs|Cflags)(\.private)?:\ (.+)$ ]]; then + if [ "${BASH_REMATCH[1]}" = 'Requires' ]; then + # Spec does not allow duplicates here: + # https://manpages.debian.org/unstable/pkg-config/pkg-config.1.en.html#Requires: + # "You may only mention the same package one time on the Requires: line" + val="$(printf '%s' "${BASH_REMATCH[3]}" | tr ',' '\n' | sort | tr '\n' ' ')" + else + val="$(printf '%s' "${BASH_REMATCH[3]}" | tr ' ' '\n' | sort -u | tr '\n' ' ')" + fi + l="${BASH_REMATCH[1]}${BASH_REMATCH[2]}: ${val}" + # curl-config + elif [[ "${section}" =~ (--libs|--static-libs) && "${l}" =~ ^( *echo\ \")(.+)(\")$ ]]; then + val="$(printf '%s' "${BASH_REMATCH[2]}" | tr ' ' '\n' | sort -u | tr '\n' ' ')" + l="${BASH_REMATCH[1]}${val}${BASH_REMATCH[3]}" + section='' + fi + echo "${l}" + fi + # curl-config + prevline="${l}" + if [[ "${l}" =~ --[a-z-]+\) ]]; then + section="${BASH_REMATCH[0]}" + fi + done < "$1" +} + +am=$(mktemp -t autotools.XXX); sort_lists "$1" > "${am}" +cm=$(mktemp -t cmake.XXX) ; sort_lists "$2" > "${cm}" +diff -u "${am}" "${cm}" +res="$?" +rm -r -f "${am}" "${cm}" + +exit "${res}" diff --git a/third-party/curl/.github/scripts/codespell-ignore.words b/third-party/curl/.github/scripts/codespell-ignore.words new file mode 100644 index 0000000000..1a5e106400 --- /dev/null +++ b/third-party/curl/.github/scripts/codespell-ignore.words @@ -0,0 +1,21 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl +anonymou +aNULL +bu +clen +CNA +hel +htpts +inout +PASE +passwor +perfec +proxys +seh +ser +strat +te +UE +WONT diff --git a/third-party/curl/.github/scripts/codespell.sh b/third-party/curl/.github/scripts/codespell.sh new file mode 100644 index 0000000000..c5ddf90a47 --- /dev/null +++ b/third-party/curl/.github/scripts/codespell.sh @@ -0,0 +1,22 @@ +#!/bin/sh +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl + +set -eu + +cd "$(dirname "${0}")"/../.. + +git ls-files -z | xargs -0 -r \ +codespell \ + --skip '.github/scripts/pyspelling.words' \ + --skip '.github/scripts/typos.toml' \ + --skip 'docs/THANKS' \ + --skip 'projects/OS400/*' \ + --skip 'projects/vms/*' \ + --skip 'RELEASE-NOTES' \ + --skip 'scripts/wcurl' \ + --skip 'tests/unit/unit1625.c' \ + --ignore-regex '.*spellchecker:disable-line' \ + --ignore-words '.github/scripts/codespell-ignore.words' \ + -- diff --git a/third-party/curl/.github/scripts/distfiles.sh b/third-party/curl/.github/scripts/distfiles.sh new file mode 100644 index 0000000000..5eb6a470a8 --- /dev/null +++ b/third-party/curl/.github/scripts/distfiles.sh @@ -0,0 +1,54 @@ +#!/usr/bin/env bash +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl + +# Compare git repo files with tarball files and report a mismatch +# after excluding exceptions. + +set -eu + +gitonly=".git* +^.* +^appveyor.* +^GIT-INFO.md +^README.md +^renovate.json +^REUSE.toml +^SECURITY.md +^LICENSES/* +^docs/examples/adddocsref.pl +^docs/tests/CI.md +^docs/THANKS-filter +^projects/Windows/* +^scripts/contributors.sh +^scripts/contrithanks.sh +^scripts/delta +^scripts/installcheck.sh +^scripts/release-notes.pl +^scripts/singleuse.pl" + +tarfiles="$(mktemp)" +gitfiles="$(mktemp)" + +tar -tf "$1" \ + | sed -E 's|^[^/]+/||g' \ + | grep -v -E '(/|^)$' \ + | sort > "${tarfiles}" + +git -C "${2:-.}" ls-files \ + | grep -v -E "($(printf '%s' "${gitonly}" | tr $'\n' '|' | sed -e 's|\.|\\.|g' -e 's|\*|.+|g'))$" \ + | sort > "${gitfiles}" + +dif="$(diff -u "${tarfiles}" "${gitfiles}" | tail -n +3 || true)" + +rm -rf "${tarfiles:?}" "${gitfiles:?}" + +echo 'Only in tarball:' +echo "${dif}" | grep '^-' || true +echo + +echo 'Missing from tarball:' +if echo "${dif}" | grep '^+'; then + exit 1 +fi diff --git a/third-party/curl/.github/scripts/pyspelling.words b/third-party/curl/.github/scripts/pyspelling.words new file mode 100644 index 0000000000..1c0fb96d9b --- /dev/null +++ b/third-party/curl/.github/scripts/pyspelling.words @@ -0,0 +1,1023 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl +# +AAAA +ABI +accessor +ACK +AES +AIA +AIX +al +Alessandro +aliasMode +allocator +alnum +ALPN +Altera +AltSvc +ALTSVC +amiga +AmigaOS +AmiSSL +anyauth +anycast +apache +Apache +API +APIs +APOP +AppVeyor +archivers +Archos +Arntsen +Aros +asynch +AsynchDNS +atime +auth +autobuild +autobuilds +Autoconf +autoconf +Automake +automake +autoreconf +Autotools +autotools +AVR +AWS +AWS-LC +axTLS +backend +backends +backoff +backtick +backticks +balancers +Baratov +basename +bashrc +BDFL +BearSSL +Benoit +BeOS +bitmask +bitset +bitwise +Björn +Bjørn +bool +boolean +BoringSSL +Boukris +Broadcom +brotli +bufq +bufref +bugfix +bugfixes +buildable +buildbot +Caddy +calloc +CAPA +capath +CCC +CDN +CentOS +CFLAGS +cflags +CGI's +CHACHA +chacha +Chaffraix +changelog +changeset +CharConv +charset +charsets +checkdocs +checksrc +checksums +chgrp +chmod +chown +ChromeOS +CI's +CIDR +CIFS +CLA +CLAs +cleartext +CLI +ClientHello +clientp +cliget +closesocket +CMake +cmake +CMake's +cmake's +CMakeLists +CNA +CNAME +CNAMEs +CodeQL +CODESET +codeset +CodeSonar +Comcast +commit's +Config +config +conncache +connectdata +CookieInfo +Coverity +CPUs +CR +CRL +CRLF +crontab +crt +crypto +cryptographic +cryptographically +CSEQ +CSeq +csh +cshrc +CTRL +CURLcode +curldown +CURLE +CURLECH +CURLH +curlimages +CURLINFO +curlrc +curltest +customizable +CVE +CVSS +CWD +CWE +cyassl +Cygwin +daniel +datagrams +datatracker +dbg +decapsulation +Debian +DEBUGBUILD +decrypt +decrypted +decrypting +deepcode +defacto +DELE +DER +dereference +dereferences +DES +deselectable +deserialization +Deserialized +destructor +detections +dev +devcpp +DevOps +devtools +DHCP +DHE +dir +discoverable +distro +distro's +distros +DJGPP +dlist +DLL +dll +DLLs +DNS +dns +dnsop +DNSSEC +DoH +DoT +doxygen +drftpd +dsa +DSN +dtrace +Dudka +Dymond +dynbuf +EAGAIN +EBCDIC +ECC +ECCN +ECDHE +ECH +ECHConfig +ECHConfigList +ecl +ECONNREFUSED +eCOS +ECT +EF +EFnet +EGD +EHLO +EINTR +else's +encapsulation +encodings +enctype +endianness +Engler +enum +enums +epoll +EPRT +EPSV +ERRNO +errno +ESNI +et +etag +ETag +ETags +exa +exe +executables +EXPN +extensibility +failsafe +Falkeborn +Fandrich +Fastly +fcpp +Fedora +Feltzing +ffi +filesize +filesystem +FindCURL +FLOSS +fnmatch +footguns +formpost +formposts +Fortnite +FOSS +FPL +fread +FreeBSD +FreeDOS +FreeRTOS +freshmeat +Frexx +FS +fseek +FTPing +fuzzer +fwrite +Garmin +gcc +GCM +gdb +Genode +Gentoo +Gergely +getaddrinfo +getenv +gethostbyname +gethostname +Getinfo +getinfo +GETing +getpwuid +ggcov +GHA +Ghedini +giga +Gisle +Glesys +glibc +globbed +globbing +gmail +GnuTLS +Golemon +GOST +GPG +GPL +GPLed +GREASE +GREASEing +Greear +groff +gsasl +GSKit +gskit +GSS +GSSAPI +GTFO +Guenter +GUIs +Gunderson +Gustafsson +gzip +Gzipped +gzipped +HackerOne +HackerOne's +HAProxy +HardenedBSD +Hards +Haxx +haxx +Heimdal +HelloRetryRequest +HELO +HH +HMAC +Hoersken +Holme +homebrew +hostname +hostnames +Housley +HRR +Hruska +HSTS +hsts +HTC +html +http +HTTPAUTH +httpd +HTTPD +httpget +HttpGet +HTTPS +https +HTTPSRR +hyper's +IANA +Icecast +ICONV +iconv +IDN +IDNA +IETF +ietf +ifdef +ifdefed +Ifdefs +ifdefs +ifhost +IIS +ILE +illumos +IMAP +imap +IMAPS +imaps +impacket +implementers +init +initializer +inlined +interop +interoperable +interoperates +IoT +ipadOS +IPCXN +IPFS +ipld +IPNS +IPv +IPv4 +IPv4/6 +IPv6 +IRIs +IRIX +Itanium +iX +Jakub +Jiri +jo +jpeg +jq +JSON +json +Julien +Kamil +Kaufmann +kB +KDE +keepalive +Keil +kerberos +Keychain +keychain +KiB +kibibyte +kickstart +Kirei +Knauf +kqueue +Krb +krb +Kubernetes +Kuhrt +Largefile +LDAP +ldap +LDAPS +ldaps +LF +LGPL +LGTM +libbacktrace +libbrotlidec +libc +libcurl +libcurl's +libcurls +libera +libev +libevent +libgsasl +libidn +libnssckbi +libnsspem +libpsl +Libre +libre +LibreSSL +librtmp +libs +libssh +libssh2 +libtest +libtests +Libtool +libtool +libuv +libWebSocket +libz +libzstd +LineageOS +linter +linux +lldb +ln +localhost +LOGDIR +logfile +lookups +loopback +LOWCOST +LOWDELAY +LPRT +LSB +lseek +Lua +lwIP +macdef +macOS +macos +Makefile +makefiles +malloc +mallocs +manpage +manpages +maprintf +Marek +Mavrogiannopoulos +Mbed +mbedTLS +md +mebibyte +Meglio +memdebug +MesaLink +mesalink +Metalink +mfprintf +Michal +Micrium +MicroBlaze +MicroOS +middlebox +MINCOST +mingw +MinGW +MINIX +misconfigured +Mishyn +mitigations +MITM +mk +mkdir +mktime +Monnerat +monospace +MorphOS +MPE +MPL +mprintf +MPTCP +MQTT +mqtt +mqtts +MSB +MSGSENT +msh +MSIE +msnprintf +msprintf +msquic +mstate +MSVC +MSYS +msys +mtime +mTLS +MUA +multicwd +multiparts +multipath +MultiSSL +mumbo +musedev +mutex +mvaprintf +mvfprintf +mvprintf +mvsnprintf +mvsprintf +MX +Nagel +Nagle +NAMELOOKUP +Natively +NATs +nc +NCR +NDK +NEC +Necko +NetBSD +netrc +netstat +NetWare +Netware +NFS +nghttp +nghttpx +ngtcp +Nikos +Nios +nitems +NixOS +NLST +nmake +nmemb +nocwd +NODELAY +NonStop +NOOP +Novell +NPN +nroff +nslookup +NSS +nss +NTLM +NTLMUSER +NTLMv +NUM +NuttX +OAuth +objcopy +OCSP +Ok +OpenBSD +OpenLDAP +OpenRISC +OpenSSF +OpenSSF's +OpenSSH +OpenSSL +OpenStep +openSUSE +openwall +Orbis +ORing +Osipov +OSS +PaaS +pac +pacman +parser's +parsers +PASE +PASV +PEM +pem +perl +permafailing +peta +PINGs +pipelining +PKCS +pkcs +PKGBUILD +PKI +pluggable +pn +PolarSSL +Polhem +pollset +POSIX +Postfix +POSTing +POSTs +PowerShell +pre +prebuilt +precompiled +prepend +prepended +prepending +prepends +preprocess +preprocessed +Preprocessing +preprocessor +Prereq +PRET +pretransfer +printf +printf's +PSL +pthreads +PTR +ptr +punycode +PWD +pwd +py +pycurl +pytest +Pytest +qname +QNX +QoS +Qubes +QUIC +quictls +quicwg +Raad +radix +RAS +RBS +ReactOS +README +realloc +Realtime +rebalances +rebase +RECV +recv +Redhat +redirections +redirs +redistributable +Redox +reentrant +Referer +referer +reinitializes +Relatedly +repo +reprioritized +resending +resends +RETR +retransmit +retrigger +RHEL +Rikard +rmdir +ROADMAP +Roadmap +Rockbox +roffit +RPC +RPG +RR +RRs +RRtype +RSA +RTMP +rtmp +rtmpdump +RTMPE +RTMPS +RTMPT +RTMPTE +RTMPTS +RTOS +RTP +RTSP +rtsp +RTT +runtests +runtime +Ruslan +rustc +Rustls +rustls +rustup +Sagula +SanDisk +SAS +SASL +Satiro +Schannel +Schindelin +SCO +SCP +scp +SDK +se +SEB +SecTrust +SEK +selectable +Serv +setopt +setsockopt +setuid +SFTP +sftp +sha +SHOUTcast +SIGALRM +SIGCHLD +SIGPIPE +singlecwd +SINIX +Sintonen +sizeof +SLE +slist +sln +Slowloris +SMB +smb +SMBS +smbs +SMBv +SMTP +smtp +smtps +SMTPS +SNI +sockd +socketopen +socketpair +sockopt +SOCKOPT +SOCKSv +Solaris +SONAME +Soref +SOVERSION +SPARC +SPDX +SPNEGO +Spotify +sprintf +src +SRP +SRWLOCK +SSI +SSL +ssl +SSLeay +SSLKEYLOGFILE +SSLS +sslv +SSLv +SSLVERSION +SSPI +stackoverflow +STARTTLS +STARTTRANSFER +stateful +statvfs +stderr +stdin +stdint +stdout +Steinar +Stenberg +STLS +STOR +strcat +strcpy +strdup +strerror +strlen +strncat +struct +structs +Structs +stunnel +subdirectories +subdirectory +submitters +substring +substrings +sudo +SunOS +SunSSH +superset +svc +svcb +SVCB +SVG +Svyatoslav +Swisscom +sws +Symbian +symlink +symlinks +syntaxes +Szakats +TABs +Tatsuhiro +TBD +TCP +tcpdump +tera +testability +testcurl +TFTP +tftp +threadsafe +Tizen +TLS +tlsv +TLSv +TODO +Tomtom +toolchain +toolchains +toolset +toplevel +TOS +TPF +TrackMemory +transcode +Tru +trurl +trustless +Tse +Tsujikawa +TTL +tty +tvOS +txt +typedef +typedefed +Ubuntu +ucLinux +UCRT +UDP +UI +UID +UIDL +uint +Ultrix +umask +Unary +unassign +UNC +uncompress +unencoded +unencrypted +unescape +Unglobbed +Unicode +UNICOS +UnixSockets +UnixWare +unlink +unpause +unpaused +unpauses +unpausing +unsanitized +Unshare +unsharing +untrusted +unwrite +UPN +upstreaming +URI +URIs +url +URL's +urlencoded +urlget +USD +userdata +Userinfo +userinfo +USERPROFILE +UTF +UX +valgrind +Vanem +vararg +VC +vcpkg +vexxhost +Viktor +virtualized +Virtuozzo +VLAN +VM +VMS +VMware +vnd +VRF +VRFY +VSE +vsftpd +vsprintf +vt +vtls +vxWorks +wakeup +Warta +watchOS +WAV +WB +wcurl +WebDAV +WebOS +webpage +webpages +WebSocket +WEBSOCKET +Wget +WHATWG +whitespace +Whitespaces +winbind +winbuild +WinIDN +WinLDAP +winsock +Wireshark +wolfSSH +wolfSSL +ws +WS +WSS +www +Xbox +XDG +xdigit +XHTML +Xilinx +xmllint +XP +Xtensa +XYZ +Youtube +YYYY +YYYYMMDD +Zakrzewski +Zeropath +Zitzmann +zlib +zsh +zstd +Zuul +zuul diff --git a/third-party/curl/.github/scripts/pyspelling.yaml b/third-party/curl/.github/scripts/pyspelling.yaml new file mode 100644 index 0000000000..bb0585ab7a --- /dev/null +++ b/third-party/curl/.github/scripts/pyspelling.yaml @@ -0,0 +1,33 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl +# +# Docs: https://facelessuser.github.io/pyspelling/configuration/ +# Docs: https://github.com/UnicornGlobal/spellcheck-github-actions +matrix: + - name: Markdown + expect_match: false + apsell: + mode: en + dictionary: + wordlists: + - wordlist.txt + output: wordlist.dic + encoding: utf-8 + pipeline: + - pyspelling.filters.markdown: + markdown_extensions: + - markdown.extensions.extra: + - pyspelling.filters.html: + comments: true + attributes: + - title + - alt + ignores: + - ':matches(code, pre)' + - 'code' + - 'pre' + - 'strong' + - 'em' + sources: + - '**/*.md|!docs/BINDINGS.md|!docs/DISTROS.md|!docs/CIPHERS-TLS12.md|!docs/wcurl.md|!tests/data/data*.md' diff --git a/third-party/curl/.github/scripts/randcurl.pl b/third-party/curl/.github/scripts/randcurl.pl new file mode 100644 index 0000000000..2c24a6b500 --- /dev/null +++ b/third-party/curl/.github/scripts/randcurl.pl @@ -0,0 +1,251 @@ +#!/usr/bin/env perl +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl +# +# Input: number of seconds to run. +# +# 1. Figure out all existing command line options +# 2. Generate random command line using supported options +# 3. Run the command line +# 4. Verify that it does not return an unexpected return code +# 5. Iterate until the time runs out +# +# Do the same with regular command lines as well as reading the options from a +# -K config file +# +# BEWARE: this may create a large amount of files using random names in the +# directory where it runs. +# + +use strict; +use warnings; + +my $curl = "../src/curl"; +my $url = "localhost:7777"; # not listening to this + +my $seconds = $ARGV[0]; +if($ARGV[1]) { + $curl = $ARGV[1]; +} + +if(!$seconds) { + $seconds = 10; +} +print "Run $curl for $seconds seconds\n"; + +my @opt; +my %arg; +my %uniq; +my %allrc; + +my $totalargs = 0; +my $totalcmds = 0; + +my $counter = 0xabcdef + time(); +sub getnum { + my ($max) = @_; + return int(rand($max)); +} + +sub storedata { + my ($short, $long, $arg) = @_; + push @opt, "-$short" if($short); + push @opt, "--$long"; + + if($arg =~ /^ 1, + '-u' => 1, + '--user' => 1, + '--proxy-user' => 1); + +my %commonrc = ( + '0' => 1, + '1' => 1, + '2' => 1, + '26' => 1, + ); + +sub runone { + my $a; + my $nargs = getnum(60) + 1; + + $totalargs += $nargs; + $totalcmds++; + for (1 .. $nargs) { + my $o = getnum($nopts); + my $option = $opt[$o]; + my $ar = ""; + $uniq{$option}++; + if($arg{$option}) { + $ar = " ".randarg(); + + if($useropt{$option}) { + # append password to avoid prompting + $ar .= ":".randarg(); + } + } + $a .= sprintf(" %s%s", $option, $ar); + } + if(getnum(100) < 15) { + # add a fake arg + $a .= " ".addarg(); + } + + my $cmd = "$curl$a $url"; + + my $rc = system("$cmd >curl-output 2>&1 > 8; + #my $rc = system("valgrind -q $cmd >/dev/null 2>&1 > 8; + + $allrc{$rc}++; + + #print "CMD: $cmd\n"; + if(!$commonrc{$rc}) { + print "CMD: $cmd\n"; + print "RC: $rc\n"; + print "== curl-output == \n"; + open(D, "; + print @out; + close(D); + exit; + } +} + +sub runconfig { + my $a; + my $nargs = getnum(80) + 1; + + open(C, ">config"); + + $totalargs += $nargs; + $totalcmds++; + for (1 .. $nargs) { + my $o = getnum($nopts); + my $option = $opt[$o]; + my $ar = ""; + $uniq{$option} = 0 if(!exists $uniq{$option}); + $uniq{$option}++; + if($arg{$option}) { + $ar = " ".randarg(); + + if($useropt{$option}) { + # append password + $ar .= ":".randarg(); + } + } + $a .= sprintf("\n%s%s", $option, $ar); + } + if(getnum(100) < 15) { + # add a fake arg + $a .= "\n".addarg(); + } + + print C "$a\n"; + close(C); + + my $cmd = "$curl -K config $url"; + + my $rc = system("$cmd >curl-output 2>&1 > 8; + + $allrc{$rc}++; + + if(!$commonrc{$rc}) { + print "CMD: $cmd\n"; + print "RC: $rc\n"; + print "== config == \n"; + open(D, "; + print @all; + close(D); + print "\n== curl-output == \n"; + open(D, "; + print @out; + close(D); + exit 2; + } +} + +# run curl command lines using -K +my $end = time() + $seconds / 2; +my $c = 0; +print "Running command lines\n"; +do { + runconfig(); + $c++; +} while(time() <= $end); +print "$c command lines\n"; + +# run curl command lines +$end = time() + $seconds / 2; +$c = 0; +print "Running config lines\n"; +do { + runone(); + $c++; +} while(time() <= $end); + +print "$c config line uses\n"; + +print "Recorded exit codes:\n"; +for my $rc (keys %allrc) { + printf " %2d: %d times\n", $rc, $allrc{$rc}; +} +printf "Number or command lines tested:\n". + " $totalcmds (%.1f/second)\n", $totalcmds/$seconds; +printf "Number or command line options tested:\n". + " $totalargs (average %.1f per command line)\n", + $totalargs/$totalcmds; +printf "Number or different options tested:\n". + " %u out of %u\n", scalar(keys %uniq), $nopts; diff --git a/third-party/curl/.github/scripts/requirements-docs.txt b/third-party/curl/.github/scripts/requirements-docs.txt new file mode 100644 index 0000000000..6850461de7 --- /dev/null +++ b/third-party/curl/.github/scripts/requirements-docs.txt @@ -0,0 +1,5 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +pyspelling==2.12.1 diff --git a/third-party/curl/.github/scripts/requirements-proselint.txt b/third-party/curl/.github/scripts/requirements-proselint.txt new file mode 100644 index 0000000000..1896109442 --- /dev/null +++ b/third-party/curl/.github/scripts/requirements-proselint.txt @@ -0,0 +1,5 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +proselint==0.16.0 diff --git a/third-party/curl/.github/scripts/requirements.txt b/third-party/curl/.github/scripts/requirements.txt new file mode 100644 index 0000000000..adf6d03ba4 --- /dev/null +++ b/third-party/curl/.github/scripts/requirements.txt @@ -0,0 +1,8 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +cmakelang==0.6.13 +codespell==2.4.2 +reuse==6.2.0 +ruff==0.15.16 diff --git a/third-party/curl/.github/scripts/shellcheck-ci.sh b/third-party/curl/.github/scripts/shellcheck-ci.sh new file mode 100644 index 0000000000..87e03b9d12 --- /dev/null +++ b/third-party/curl/.github/scripts/shellcheck-ci.sh @@ -0,0 +1,30 @@ +#!/bin/sh +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl + +# Required: yq + +set -eu + +export SHELLCHECK_OPTS='--exclude=1090,1091,2086,2153 --enable=avoid-nullary-conditions,deprecate-which' + +# GHA +git ls-files '.github/workflows/*.yml' | while read -r f; do + echo "Verifying ${f}..." + { + echo '#!/usr/bin/env bash' + echo 'set -eu' + yq eval '.. | select(has("run") and (.run | type == "!!str")) | .run + "\ntrue\n"' "${f}" + } | sed -E 's|\$\{\{ .+ \}\}|GHA_EXPRESSION|g' | shellcheck - +done + +# Circle CI +git ls-files '.circleci/*.yml' | while read -r f; do + echo "Verifying ${f}..." + { + echo '#!/usr/bin/env bash' + echo 'set -eu' + yq eval '.. | select(has("command") and (.command | type == "!!str")) | .command + "\ntrue\n"' "${f}" + } | shellcheck - +done diff --git a/third-party/curl/.github/scripts/shellcheck.sh b/third-party/curl/.github/scripts/shellcheck.sh new file mode 100644 index 0000000000..59b49131ac --- /dev/null +++ b/third-party/curl/.github/scripts/shellcheck.sh @@ -0,0 +1,13 @@ +#!/bin/sh +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl + +set -eu + +cd "$(dirname "${0}")"/../.. + +git grep -z -l -E '^#!(/usr/bin/env bash|/bin/sh|/bin/bash)' | xargs -0 -r \ +shellcheck --exclude=1091,2248 \ + --enable=avoid-nullary-conditions,deprecate-which \ + -- diff --git a/third-party/curl/.github/scripts/spellcheck.curl b/third-party/curl/.github/scripts/spellcheck.curl new file mode 100644 index 0000000000..1d8be5ed3e --- /dev/null +++ b/third-party/curl/.github/scripts/spellcheck.curl @@ -0,0 +1,153 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl +# +# common variable types + structs +# callback typedefs +# public functions names +# some man page names +curl_fileinfo +curl_forms +curl_hstsentry +curl_httppost +curl_index +curl_khkey +curl_pushheaders +curl_waitfd +CURLcode +CURLformoption +CURLHcode +CURLMcode +CURLMsg +CURLSHcode +CURLUcode +curl_calloc_callback +curl_chunk_bgn_callback +curl_chunk_end_callback +curl_conv_callback +curl_debug_callback +curl_fnmatch_callback +curl_formget_callback +curl_free_callback +curl_hstsread_callback +curl_hstswrite_callback +curl_ioctl_callback +curl_malloc_callback +curl_multi_timer_callback +curl_opensocket_callback +curl_prereq_callback +curl_progress_callback +curl_push_callback +curl_read_callback +curl_realloc_callback +curl_resolver_start_callback +curl_seek_callback +curl_socket_callback +curl_sockopt_callback +curl_ssl_ctx_callback +curl_strdup_callback +curl_trailer_callback +curl_write_callback +curl_xferinfo_callback +curl_strequal +curl_strnequal +curl_mime_init +curl_mime_free +curl_mime_addpart +curl_mime_name +curl_mime_filename +curl_mime_type +curl_mime_encoder +curl_mime_data +curl_mime_filedata +curl_mime_data_cb +curl_mime_subparts +curl_mime_headers +curl_formadd +curl_formget +curl_formfree +curl_getdate +curl_getenv +curl_version +curl_easy_escape +curl_escape +curl_easy_unescape +curl_unescape +curl_free +curl_global_init +curl_global_init_mem +curl_global_cleanup +curl_global_trace +curl_global_sslset +curl_slist_append +curl_slist_free_all +curl_getdate +curl_share_init +curl_share_setopt +curl_share_cleanup +curl_version_info +curl_easy_strerror +curl_share_strerror +curl_easy_pause +curl_easy_ssls_import +curl_easy_ssls_export +curl_easy_init +curl_easy_setopt +curl_easy_perform +curl_easy_cleanup +curl_easy_getinfo +curl_easy_duphandle +curl_easy_reset +curl_easy_recv +curl_easy_send +curl_easy_upkeep +curl_easy_header +curl_easy_nextheader +curl_mprintf +curl_mfprintf +curl_msprintf +curl_msnprintf +curl_mvprintf +curl_mvfprintf +curl_mvsprintf +curl_mvsnprintf +curl_maprintf +curl_mvaprintf +curl_multi_init +curl_multi_add_handle +curl_multi_remove_handle +curl_multi_fdset +curl_multi_waitfds +curl_multi_wait +curl_multi_poll +curl_multi_wakeup +curl_multi_perform +curl_multi_cleanup +curl_multi_info_read +curl_multi_strerror +curl_multi_socket +curl_multi_socket_action +curl_multi_socket_all +curl_multi_timeout +curl_multi_setopt +curl_multi_assign +curl_multi_get_handles +curl_multi_get_offt +curl_multi_notify_disable +curl_multi_notify_enable +curl_pushheader_bynum +curl_pushheader_byname +curl_easy_option_by_name +curl_easy_option_by_id +curl_easy_option_next +curl_url +curl_url_cleanup +curl_url_dup +curl_url_get +curl_url_set +curl_url_strerror +curl_ws_recv +curl_ws_send +curl_ws_meta +libcurl-env +libcurl-ws diff --git a/third-party/curl/.github/scripts/spellcheck.words b/third-party/curl/.github/scripts/spellcheck.words deleted file mode 100644 index 11be5ba76e..0000000000 --- a/third-party/curl/.github/scripts/spellcheck.words +++ /dev/null @@ -1,909 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl -# -ABI -accessor -ACK -AES -AIA -AIX -al -Alessandro -allocator -alnum -ALPN -Altera -ALTSVC -amiga -AmigaOS -AmiSSL -anyauth -anycast -apache -Apache -API -APIs -APOP -AppVeyor -archivers -Archos -Arntsen -Aros -ascii -asynch -AsynchDNS -atime -auth -autobuild -autobuilds -Autoconf -Automake -Autotools -autotools -AVR -AWS -AWS-LC -axTLS -backend -backends -backoff -backticks -Baratov -basename -bashrc -BDFL -BearSSL -Benoit -BeOS -bitmask -bitwise -Björn -Bjørn -bool -boolean -BoringSSL -boringssl -Boukris -Broadcom -brotli -bufq -bufref -bugfix -bugfixes -buildable -buildbot -buildconf -Caddy -calloc -CAPA -capath -CCC -CDN -CentOS -CFLAGS -CGI's -CHACHA -chacha -Chaffraix -changelog -changeset -CharConv -charset -charsets -checksrc -checksums -chgrp -chmod -chown -ChromeOS -CI's -CIDR -CIFS -CLA -CLAs -cleartext -CLI -clientp -cliget -closesocket -CMake -cmake -cmake's -CMakeLists -CodeQL -codeql -CODESET -codeset -Comcast -Config -config -conncache -connectdata -CookieInfo -Coverity -CPUs -CR -CRL -CRLF -crt -crypto -cryptographic -cryptographically -CSEQ -CSeq -csh -cshrc -CTRL -cURL -CURLcode -CURLE -CURLH -curlimages -curlrc -curltest -customizable -CVE -CVSS -CWD -CWE -cyassl -Cygwin -daniel -datatracker -Debian -decrypt -deepcode -DELE -DER -deselectable -destructor -detections -dev -devcpp -DevOps -devtools -DHCP -dir -distro -distro's -distros -DJGPP -dlist -DLL -dll -DLLs -DNS -dns -dnsop -DoH -doxygen -drftpd -dsa -Dudka -Dymond -dynbuf -EAGAIN -EBCDIC -ECC -ECDHE -ECH -ECONNREFUSED -eCOS -EFnet -EGD -EHLO -EINTR -else's -encodings -enctype -endianness -Engler -enum -epoll -EPRT -EPSV -ERRNO -errno -ESNI -et -etag -ETag -ETags -exe -executables -EXPN -extensibility -failsafe -Falkeborn -Fandrich -Fastly -fcpp -Fedora -Feltzing -ffi -filesize -filesystem -FLOSS -fnmatch -formpost -formposts -Fortnite -FOSS -FPL -fread -FreeBSD -FreeDOS -FreeRTOS -freshmeat -Frexx -FS -fseek -FTPing -fuzzer -fwrite -Garmin -gcc -GCM -gdb -Genode -Gentoo -Gergely -getaddrinfo -getenv -gethostbyname -gethostname -Getinfo -getinfo -GETing -getpwuid -ggcov -Ghedini -Gisle -Glesys -globbed -globbing -gmail -GnuTLS -gnutls -Golemon -GOST -GPG -GPL -GPLed -Greear -groff -GSKit -gskit -GSS -GSSAPI -GTFO -Guenter -Gunderson -Gustafsson -gzip -Gzipped -gzipped -HackerOne -HackerOne's -HAProxy -HardenedBSD -Hards -Haxx -haxx -Heimdal -HELO -HH -HMAC -Hoersken -Holme -homebrew -hostname -hostnames -Housley -Hruska -HSTS -hsts -HTC -html -http -HTTPAUTH -httpd -HTTPD -httpget -HttpGet -HTTPS -https -hyper's -Högskolan -IANA -Icecast -ICONV -iconv -IDN -IDNA -IETF -ietf -ifdef -ifdefed -Ifdefs -ifdefs -IIS -ILE -Illumos -IMAP -imap -IMAPS -imaps -impacket -init -initializer -inlined -interop -interoperable -interoperates -IoT -ipadOS -IPCXN -IPv -IPv4 -IPv4/6 -IPv6 -IRIs -IRIX -Itanium -iX -Jakub -Jiri -jo -jpeg -jq -JSON -json -Julien -Kamil -Kaufmann -kB -KDE -keepalive -Keil -kerberos -Keychain -keychain -KiB -kickstart -Kirei -Knauf -kqueue -Krb -krb -Kubernetes -Kuhrt -Kungliga -Largefile -LDAP -ldap -LDAPS -ldaps -LF -LGTM -libbrotlidec -libc -libcurl -libcurl's -libcurls -libera -libev -libevent -libgsasl -libidn -libnssckbi -libnsspem -libpsl -Libre -libre -LibreSSL -libressl -librtmp -libs -libssh -libSSH -libssh2 -Libtool -libuv -libWebSocket -libz -libzstd -LineageOS -linux -ln -localhost -LOGDIR -logfile -lookups -loopback -LPRT -LSB -lseek -Lua -lwIP -macdef -macOS -macos -Makefile -makefiles -malloc -mallocs -maprintf -Marek -Mavrogiannopoulos -Mbed -mbedTLS -Meglio -memdebug -MesaLink -mesalink -Metalink -mfprintf -Michal -Micrium -MicroBlaze -MicroOS -mingw -MinGW -MINIX -misconfigured -Mishyn -mitigations -MITM -mk -mkdir -mktime -Monnerat -monospace -MorphOS -MPE -MPL -mprintf -MQTT -mqtt -mqtts -MSB -MSGSENT -msh -MSIE -msnprintf -msprintf -msquic -mstate -MSVC -MSYS -msys -mtime -mTLS -MUA -multicwd -multiparts -MultiSSL -mumbo -musedev -mutex -mvaprintf -mvfprintf -mvprintf -mvsnprintf -mvsprintf -MX -Nagel -Nagle -NAMELOOKUP -Natively -NATs -nc -NCR -NDK -NEC -Necko -NetBSD -netrc -netstat -Netware -NFS -nghttp -nghttpx -ngtcp -Nikos -Nios -nitems -NixOS -NLST -nmake -nmemb -nocwd -NODELAY -NonStop -NOOP -Novell -NPN -nroff -nslookup -NSS -nss -NTLM -NTLMUSER -NTLMv -NUM -NuttX -OAuth -objcopy -OCSP -Ok -OpenBSD -OpenLDAP -OpenRISC -OpenSSF -OpenSSF's -OpenSSH -OpenSSL -OpenStep -openSUSE -openwall -Orbis -ORing -Osipov -OSS -pac -pacman -parser's -parsers -PASE -PASV -PEM -pem -perl -permafailing -PINGs -pipelining -PKCS -pkcs -PKGBUILD -PKI -pluggable -PolarSSL -Polhem -pollset -POSIX -Postfix -POSTing -POSTs -PowerShell -pre -prebuilt -precompiled -prepend -prepended -prepending -prepends -preprocess -preprocessed -Preprocessing -preprocessor -Prereq -PRET -pretransfer -printf -printf's -PSL -pthreads -PTR -ptr -punycode -PWD -pwd -py -pycurl -pytest -Pytest -QNX -QoS -Qubes -QUIC -quictls -quicwg -Raad -radix -RAS -RBS -ReactOS -README -realloc -Realtime -rebase -RECV -recv -Redhat -redirections -redirs -redistributable -Redox -reentrant -Referer -referer -reinitializes -Relatedly -repo -reprioritized -resending -resends -RETR -retransmit -retrigger -RHEL -RICS -Rikard -rmdir -ROADMAP -Roadmap -Rockbox -roffit -RPG -RSA -RTMP -rtmp -RTMPE -RTMPS -RTMPT -RTMPTE -RTMPTS -RTOS -RTP -RTSP -rtsp -RTT -runtests -runtime -Ruslan -rustc -rustls -Sagula -SanDisk -SAS -SASL -Satiro -Schannel -Schindelin -SCO -SCP -scp -SDK -se -SEB -SEK -selectable -Serv -setopt -setsockopt -setuid -SFTP -sftp -sha -SHOUTcast -SIGALRM -SIGCHLD -SIGPIPE -singlecwd -SINIX -Sintonen -sizeof -SLE -slist -sln -SMB -smb -SMBS -smbs -SMBv -SMTP -smtp -smtps -SMTPS -SNI -socketopen -socketpair -sockopt -SOCKOPT -SOCKSv -Solaris -SONAME -Soref -SPARC -SPDX -SPNEGO -Spotify -sprintf -src -SRP -SRWLOCK -SSL -ssl -SSLeay -SSLKEYLOGFILE -sslv -SSLv -SSLVERSION -SSPI -stackoverflow -STARTTLS -STARTTRANSFER -stateful -statvfs -stderr -stdin -stdout -Steinar -Stenberg -STOR -strcat -strcpy -strdup -strerror -strlen -strncat -struct -structs -Structs -stunnel -subdirectories -subdirectory -submitters -substring -substrings -SunOS -SunSSH -superset -svc -svcb -Svyatoslav -Swisscom -sws -Symbian -symlink -symlinks -syntaxes -Szakats -TABs -Tatsuhiro -TBD -TCP -tcpdump -Tekniska -testability -TFTP -tftp -Tizen -TLS -tlsv -TLSv -TODO -Tomtom -toolchain -toolchains -toolset -toplevel -TPF -TrackMemory -transcode -Tru -Tse -Tsujikawa -TTL -tvOS -txt -typedef -typedefed -Ubuntu -ucLinux -UDP -UI -UID -UIDL -Ultrix -Unary -unassign -UNC -uncompress -unencoded -unencrypted -unescape -Unglobbed -UNICOS -unix -UnixSockets -UnixWare -unlink -unpause -unpaused -unpauses -unpausing -unsanitized -Unshare -unsharing -untrusted -UPN -upstreaming -URI -URIs -url -URL's -urlencoded -urlget -USD -userdata -Userinfo -userinfo -USERPROFILE -UTF -UX -valgrind -Vanem -vararg -VC -vcpkg -vexxhost -Viktor -VM -VMS -VMware -VRF -VRFY -VSE -vsprintf -vt -vtls -vxWorks -wakeup -Warta -watchOS -WAV -WB -web page -WebDAV -WebOS -WebSocket -WEBSOCKET -WHATWG -whitespace -Whitespaces -winbind -WinBind -winbuild -winidn -WinIDN -WinLDAP -WinSock -winsock -WinSSL -winssl -Wireshark -wolfSSH -wolfSSL -WS -WSS -www -Xbox -XDG -xdigit -Xilinx -XP -Xtensa -XYZ -Youtube -YYYY -YYYYMMDD -Zakrzewski -Zitzmann -zlib -zsh -zstd -Zuul -zuul diff --git a/third-party/curl/.github/scripts/spellcheck.yaml b/third-party/curl/.github/scripts/spellcheck.yaml deleted file mode 100644 index 4e4e13d48c..0000000000 --- a/third-party/curl/.github/scripts/spellcheck.yaml +++ /dev/null @@ -1,32 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl -# -# Docs: https://github.com/UnicornGlobal/spellcheck-github-actions -matrix: -- name: Markdown - expect_match: false - apsell: - mode: en - dictionary: - wordlists: - - wordlist.txt - output: wordlist.dic - encoding: utf-8 - pipeline: - - pyspelling.filters.markdown: - markdown_extensions: - - markdown.extensions.extra: - - pyspelling.filters.html: - comments: true - attributes: - - title - - alt - ignores: - - ':matches(code, pre)' - - 'code' - - 'pre' - - 'strong' - - 'em' - sources: - - '**/*.md|!docs/BINDINGS.md' diff --git a/third-party/curl/.github/scripts/trimmarkdownheader.pl b/third-party/curl/.github/scripts/trimmarkdownheader.pl new file mode 100644 index 0000000000..89b2e7d9fd --- /dev/null +++ b/third-party/curl/.github/scripts/trimmarkdownheader.pl @@ -0,0 +1,44 @@ +#!/usr/bin/env perl +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl +# +# Given: a libcurl curldown man page +# Outputs: the same file, minus the header +# + +use strict; +use warnings; + +my $f = $ARGV[0] || ''; + +open(F, "<$f") or die; + +my @out; +my $line = 0; +my $hideheader = 0; + +while() { + if($hideheader) { + if(/^---/) { + # end if hiding + $hideheader = 0; + } + push @out, "\n"; # replace with blank + next; + } + elsif(!$line++ && /^---/) { + # starts with a header, strip off the header + $hideheader = 1; + push @out, "\n"; # replace with blank + next; + } + push @out, $_; +} +close(F); + +open(O, ">$f") or die; +for my $l (@out) { + print O $l; +} +close(O); diff --git a/third-party/curl/.github/scripts/typos.sh b/third-party/curl/.github/scripts/typos.sh new file mode 100644 index 0000000000..76735c1d9f --- /dev/null +++ b/third-party/curl/.github/scripts/typos.sh @@ -0,0 +1,14 @@ +#!/bin/sh +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl + +set -eu + +cd "$(dirname "${0}")"/../.. + +git ls-files | typos \ + --isolated \ + --force-exclude \ + --config '.github/scripts/typos.toml' \ + --file-list - diff --git a/third-party/curl/.github/scripts/typos.toml b/third-party/curl/.github/scripts/typos.toml new file mode 100644 index 0000000000..3192a2987c --- /dev/null +++ b/third-party/curl/.github/scripts/typos.toml @@ -0,0 +1,36 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +[default] +extend-ignore-identifiers-re = [ + "^(ba|fo|pn|PN|UE)$", + "^(CNA|cpy|ser)$", + "^(ECT0|ECT1|HELO|htpts|mport|PASE)$", + "^[A-Za-z0-9_-]*(EDE|GOST)[A-Z0-9_-]*$", # ciphers + "^0x[0-9a-fA-F]+FUL$", # unsigned long hex literals ending with 'F' + "^[0-9a-zA-Z+]{64,}$", # possibly base64 + "^(eyeballers|HELO_smtp|Januar|optin|passin|perfec|SMTP_HELO)$", + "^(clen|req_clen|smtp_perform_helo|smtp_state_helo_resp|Tru64|_stati64)$", + "(_ccontains|_controllen|O_WRONLY|secur32)", + "proxys", # this should be limited to tests/http/*. Short for secure proxy. +] + +extend-ignore-re = [ + ".*spellchecker:disable-line", +] + +[files] +extend-exclude = [ + ".github/scripts/codespell-ignore.words", + ".github/scripts/pyspelling.words", + "docs/THANKS", + "projects/OS400/*", + "projects/vms/*", + "projects/Windows/tmpl/curl.vcxproj", + "projects/Windows/tmpl/libcurl.vcxproj", + "RELEASE-NOTES", + "scripts/wcurl", + "tests/data/test*", + "tests/unit/unit1625.c", +] diff --git a/third-party/curl/.github/scripts/verify-examples.pl b/third-party/curl/.github/scripts/verify-examples.pl new file mode 100644 index 0000000000..a23dc412f0 --- /dev/null +++ b/third-party/curl/.github/scripts/verify-examples.pl @@ -0,0 +1,106 @@ +#!/usr/bin/env perl +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### + +use strict; +use warnings; + +my @files = @ARGV; +my $cfile = "test.c"; +my $check = "./scripts/checksrc.pl"; +my $error = 0; + +if(!@files || $files[0] eq "-h") { + print "Usage: verify-examples [markdown pages]\n"; + exit; +} + +sub testcompile { + my $rc = system('gcc -c test.c -I include -W -Wall -pedantic -Werror ' . + '-Wno-unused-parameter -Wno-unused-but-set-variable ' . + '-DCURL_ALLOW_OLD_MULTI_SOCKET -DCURL_DISABLE_DEPRECATION') >> 8; + return $rc; +} + +sub checksrc { + my $rc = system($check, ('test.c')) >> 8; + return $rc; +} + +sub extract { + my($f) = @_; + my $syn = 0; + my $l = 0; + my $iline = 0; + my $fail = 0; + open(F, "<$f") or die "failed opening input file $f : $!"; + open(O, ">$cfile") or die "failed opening output file $cfile : $!"; + print O "#include \n"; + while() { + $iline++; + if(/^# EXAMPLE/) { + $syn = 1 + } + elsif($syn == 1) { + if(/^~~~/) { + $syn++; + print O "/* !checksrc! disable BANNEDFUNC all */\n"; # for fopen() + print O "/* !checksrc! disable COPYRIGHT all */\n"; + print O "/* !checksrc! disable UNUSEDIGNORE all */\n"; + printf O "#line %d \"$f\"\n", $iline + 1; + } + } + elsif($syn == 2) { + if(/^~~~/) { + last; + } + # two backslashes become one + $_ =~ s/\\\\/\\/g; + print O $_; + $l++; + } + } + close(F); + close(O); + + return ($fail ? 0 : $l); +} + +my $count = 0; +for my $m (@files) { + #print "Verify $m\n"; + my $out = extract($m); + if($out) { + $error |= testcompile($m); + $error |= checksrc($m); + } + $count++; +} +if(!$error) { + print "Verified $count man pages ok\n"; +} +else { + print "Detected problems\n"; +} +exit $error; diff --git a/third-party/curl/.github/scripts/verify-synopsis.pl b/third-party/curl/.github/scripts/verify-synopsis.pl new file mode 100644 index 0000000000..02918dd65d --- /dev/null +++ b/third-party/curl/.github/scripts/verify-synopsis.pl @@ -0,0 +1,87 @@ +#!/usr/bin/env perl +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### + +use strict; +use warnings; + +my @files = @ARGV; +my $cfile = "test.c"; + +if(!@files || $files[0] eq "-h") { + print "Usage: verify-synopsis [man pages]\n"; + exit; +} + +sub testcompile { + my $rc = system('gcc -c test.c -I include -W -Wall -pedantic -Werror ' . + '-DCURL_ALLOW_OLD_MULTI_SOCKET -DCURL_DISABLE_TYPECHECK') >> 8; + return $rc; +} + +sub extract { + my($f) = @_; + my $syn = 0; + my $l = 0; + my $iline = 0; + open(F, "<$f"); + open(O, ">$cfile"); + while() { + $iline++; + if(/^# SYNOPSIS/) { + $syn = 1 + } + elsif($syn == 1) { + if(/^\~\~\~/) { + $syn++; + print O "#line $iline \"$f\"\n"; + } + } + elsif($syn == 2) { + if(/^\~\~\~/) { + last; + } + # turn the vararg argument into vararg + $_ =~ s/, parameter\)\;/, ...);/; + print O $_; + $l++; + } + } + close(F); + close(O); + + if($syn < 2) { + print STDERR "Found no synopsis in $f\n"; + return 1; + } + + return 0; +} + +my $error; +for my $m (@files) { + $error |= extract($m); + $error |= testcompile($m); +} +exit $error; diff --git a/third-party/curl/.github/scripts/yamlcheck.sh b/third-party/curl/.github/scripts/yamlcheck.sh new file mode 100644 index 0000000000..4bdeff45cb --- /dev/null +++ b/third-party/curl/.github/scripts/yamlcheck.sh @@ -0,0 +1,15 @@ +#!/bin/sh +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl + +set -eu + +cd "$(dirname "${0}")"/../.. + +git ls-files '*.yaml' '*.yml' -z | xargs -0 -r \ +yamllint \ + --format standard \ + --strict \ + --config-data .github/scripts/yamlcheck.yaml \ + -- diff --git a/third-party/curl/.github/scripts/yamlcheck.yaml b/third-party/curl/.github/scripts/yamlcheck.yaml new file mode 100644 index 0000000000..a6e16410c1 --- /dev/null +++ b/third-party/curl/.github/scripts/yamlcheck.yaml @@ -0,0 +1,17 @@ +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl +# +# Docs: https://yamllint.readthedocs.io/en/stable/configuration.html + +extends: default + +rules: + line-length: + max: 500 + level: warning + + braces: disable + commas: disable + comments: disable + document-start: disable diff --git a/third-party/curl/.github/stale.yml b/third-party/curl/.github/stale.yml index dc239b56ce..1c2b57c2cf 100644 --- a/third-party/curl/.github/stale.yml +++ b/third-party/curl/.github/stale.yml @@ -6,7 +6,7 @@ daysUntilStale: 180 # Number of days of inactivity before a stale issue is closed daysUntilClose: 14 -# Issues with these labels will never be considered stale +# Issues with these labels are never considered stale exemptLabels: - pinned - security @@ -15,7 +15,7 @@ staleLabel: stale # Comment to post when marking an issue as stale. Set to `false` to disable markComment: > This issue has been automatically marked as stale because it has not had - recent activity. It will be closed if no further activity occurs. Thank you + recent activity. It is closed if no further activity occurs. Thank you for your contributions. # Comment to post when closing a stale issue. Set to `false` to disable closeComment: false diff --git a/third-party/curl/.github/workflows/appveyor-status.yml b/third-party/curl/.github/workflows/appveyor-status.yml index df54422ff7..c821771fc4 100644 --- a/third-party/curl/.github/workflows/appveyor-status.yml +++ b/third-party/curl/.github/workflows/appveyor-status.yml @@ -2,9 +2,9 @@ # # SPDX-License-Identifier: curl -name: AppVeyor Status Report +name: 'AppVeyor Status Report' -on: +'on': status concurrency: @@ -15,20 +15,22 @@ permissions: {} jobs: split: - runs-on: ubuntu-latest + name: 'split' + runs-on: ubuntu-24.04-arm if: ${{ github.event.sender.login == 'appveyor[bot]' }} permissions: - statuses: write + statuses: write # To update build statuses steps: - - name: Create individual AppVeyor build statuses + - name: 'Create individual AppVeyor build statuses' if: ${{ github.event.sha && github.event.target_url }} env: APPVEYOR_COMMIT_SHA: ${{ github.event.sha }} APPVEYOR_TARGET_URL: ${{ github.event.target_url }} APPVEYOR_REPOSITORY: ${{ github.event.repository.full_name }} + DO_NOT_TRACK: '1' # for gh GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | - echo ${APPVEYOR_TARGET_URL} | sed 's/\/project\//\/api\/projects\//' | xargs -t -n1 curl -s | \ + echo "${APPVEYOR_TARGET_URL}" | sed 's/\/project\//\/api\/projects\//' | xargs -t -n1 curl -s -- | \ jq -c '.build.jobs[] | {target_url: ($target_url + "/job/" + .jobId), context: (.name | sub("^(Environment: )?"; "AppVeyor / ")), state: (.status | sub("queued"; "pending") @@ -37,5 +39,5 @@ jobs: | sub("failed"; "failure") | sub("cancelled"; "error")), description: .status}' \ - --arg target_url ${APPVEYOR_TARGET_URL} | tee /dev/stderr | parallel --pipe -j 1 -N 1 \ - gh api --silent --input - repos/${APPVEYOR_REPOSITORY}/statuses/${APPVEYOR_COMMIT_SHA} + --arg target_url "${APPVEYOR_TARGET_URL}" | tee /dev/stderr | parallel --pipe -j 1 -N 1 \ + gh api --silent --input - "repos/${APPVEYOR_REPOSITORY}/statuses/${APPVEYOR_COMMIT_SHA}" diff --git a/third-party/curl/.github/workflows/awslc.yml b/third-party/curl/.github/workflows/awslc.yml deleted file mode 100644 index d183389c40..0000000000 --- a/third-party/curl/.github/workflows/awslc.yml +++ /dev/null @@ -1,152 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: Linux AWS-LC - -on: - push: - branches: - - master - - '*/ci' - paths-ignore: - - '**/*.md' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - pull_request: - branches: - - master - paths-ignore: - - '**/*.md' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - -concurrency: - # Hardcoded workflow filename as workflow name above is just Linux again - group: awslc-${{ github.event.pull_request.number || github.sha }} - cancel-in-progress: true - -permissions: {} - -env: - MAKEFLAGS: -j 3 - awslc-version: 1.13.0 - -jobs: - autoconf: - name: awslc (autoconf) - runs-on: 'ubuntu-latest' - timeout-minutes: 30 - - steps: - - run: | - sudo apt-get update --yes - sudo apt-get install --yes libtool autoconf automake pkg-config stunnel4 - # ensure we don't pick up openssl in this build - sudo apt remove --yes libssl-dev - sudo python3 -m pip install impacket - name: 'install prereqs and impacket' - - - name: cache awslc - uses: actions/cache@v3 - id: cache-awslc - env: - cache-name: cache-awslc - with: - path: /home/runner/awslc - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.awslc-version }} - - - name: build awslc - if: steps.cache-awslc.outputs.cache-hit != 'true' - run: | - curl -LOsSf --retry 6 --retry-connrefused --max-time 999 \ - https://github.com/awslabs/aws-lc/archive/refs/tags/v${{ env.awslc-version }}.tar.gz - tar xzf v${{ env.awslc-version }}.tar.gz - mkdir aws-lc-${{ env.awslc-version }}-build - cd aws-lc-${{ env.awslc-version }}-build - cmake -DCMAKE_INSTALL_PREFIX=$HOME/awslc ../aws-lc-${{ env.awslc-version }} - cmake --build . --parallel - cmake --install . - - - uses: actions/checkout@v3 - - - run: autoreconf -fi - name: 'autoreconf' - - - run: | - mkdir build - cd build - ../configure --enable-warnings --enable-werror --with-openssl=$HOME/awslc - cd .. - name: 'configure out-of-tree' - - - run: make -C build V=1 - name: 'make' - - - run: make -C build V=1 examples - name: 'make examples' - - - run: make -C build V=1 -C tests - name: 'make tests' - - - run: make -C build V=1 test-ci - name: 'run tests' - - cmake: - name: awslc (cmake) - runs-on: 'ubuntu-latest' - timeout-minutes: 15 - - steps: - - run: | - sudo apt-get update - sudo apt-get install cmake stunnel4 - # ensure we don't pick up openssl in this build - sudo apt remove --yes libssl-dev - sudo python3 -m pip install impacket - name: 'install prereqs and impacket' - - - name: cache awslc - uses: actions/cache@v3 - id: cache-awslc - env: - cache-name: cache-awslc - with: - path: /home/runner/awslc - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.awslc-version }} - - - name: build awslc - if: steps.cache-awslc.outputs.cache-hit != 'true' - run: | - curl -LOsSf --retry 6 --retry-connrefused --max-time 999 \ - https://github.com/awslabs/aws-lc/archive/refs/tags/v${{ env.awslc-version }}.tar.gz - tar xzf v${{ env.awslc-version }}.tar.gz - mkdir aws-lc-${{ env.awslc-version }}-build - cd aws-lc-${{ env.awslc-version }}-build - cmake -DCMAKE_INSTALL_PREFIX=$HOME/awslc ../aws-lc-${{ env.awslc-version }} - cmake --build . --parallel - cmake --install . - - - uses: actions/checkout@v3 - - # CMAKE_COMPILE_WARNING_AS_ERROR is available in cmake 3.24 or later - - run: cmake -Bbuild -DOPENSSL_ROOT_DIR=$HOME/awslc -DBUILD_SHARED_LIBS=ON -DCMAKE_COMPILE_WARNING_AS_ERROR=ON . - name: 'cmake generate out-of-tree' - - - run: cmake --build build --parallel - name: 'cmake build' - - - run: cmake --install build --prefix $HOME/curl --strip - name: 'cmake install' diff --git a/third-party/curl/.github/workflows/checkdocs.yml b/third-party/curl/.github/workflows/checkdocs.yml new file mode 100644 index 0000000000..52f002fa71 --- /dev/null +++ b/third-party/curl/.github/workflows/checkdocs.yml @@ -0,0 +1,135 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +# This workflow contains tests that operate on documentation files only. Some +# checks modify the source so they cannot be combined into a single job. + +name: 'Docs' + +'on': + push: + branches: + - master + - '*/ci' + paths: + - '.github/workflows/checkdocs.yml' + - '.github/scripts/**' + - 'scripts/**' + - '**.md' + - 'docs/*' + pull_request: + branches: + - master + paths: + - '.github/workflows/checkdocs.yml' + - '.github/scripts/**' + - 'scripts/**' + - '**.md' + - 'docs/*' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + DO_NOT_TRACK: '1' + +jobs: + # config file help: https://github.com/amperser/proselint/ + proselint: + name: 'proselint' + runs-on: ubuntu-24.04-arm + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'install prereqs' + run: | + python3 -m venv ~/venv + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r .github/scripts/requirements-proselint.txt + + - name: 'trim headers off all *.md files' + run: git ls-files '*.md' -z | xargs -0 -n1 .github/scripts/trimmarkdownheader.pl + + - name: 'check prose' + run: | + cat < ~/.proselintrc.json + { + "checks": { + "annotations.misc": false, + "lexical_illusions": false, + "misc.annotations": false, + "redundancy.misc.garner": false, + "security.password": false, + "spelling.ve_of": false, + "typography.diacritical_marks": false, + "typography.symbols": false + } + } + JSON + source ~/venv/bin/activate + git ls-files README '*.md' -z | grep -Evz '(CHECKSRC|DISTROS|CURLOPT_INTERFACE|interface)\.md' | xargs -0 proselint check -- + + - name: 'check special prose' # For CHECKSRC and files with aggressive exclamation mark needs + run: | + cat < ~/.proselintrc.json + { + "checks": { + "annotations.misc": false, + "lexical_illusions": false, + "typography.diacritical_marks": false, + "typography.punctuation.exclamation": false, + "typography.symbols": false + } + } + JSON + source ~/venv/bin/activate + proselint check docs/internals/CHECKSRC.md docs/libcurl/opts/CURLOPT_INTERFACE.md docs/cmdline-opts/interface.md + + pyspelling: + name: 'pyspelling' + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'trim all *.md files in docs/' + run: .github/scripts/cleancmd.pl 'docs/*.md' + + - name: 'install' + timeout-minutes: 2 + run: | + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install aspell aspell-en + python3 -m venv ~/venv + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r .github/scripts/requirements-docs.txt + + - name: 'check spelling' + run: | + source ~/venv/bin/activate + # setup the custom wordlist + grep -v '^#' .github/scripts/pyspelling.words > wordlist.txt + aspell --version + pyspelling --version + pyspelling --verbose --jobs 5 --config .github/scripts/pyspelling.yaml + + synopsis-man-examples: + name: 'synopsis, man-examples' + runs-on: ubuntu-24.04-arm + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'verify synopsis' + run: .github/scripts/verify-synopsis.pl docs/libcurl/curl*.md + + - name: 'verify examples' + run: .github/scripts/verify-examples.pl docs/libcurl/curl*.md docs/libcurl/opts/*.md diff --git a/third-party/curl/.github/workflows/checksrc.yml b/third-party/curl/.github/workflows/checksrc.yml new file mode 100644 index 0000000000..83f5afe7a1 --- /dev/null +++ b/third-party/curl/.github/workflows/checksrc.yml @@ -0,0 +1,214 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +# This workflow contains checks at the source code level only. + +name: 'Source' + +'on': + push: + branches: + - master + - '*/ci' + paths-ignore: + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + pull_request: + branches: + - master + paths-ignore: + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + DO_NOT_TRACK: '1' + +jobs: + checksrc: + name: 'checksrc' + runs-on: ubuntu-slim + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'check' + run: scripts/checksrc-all.pl + + linters: + name: 'spellcheck, linters, REUSE' + runs-on: ubuntu-24.04-arm + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'install prereqs' + run: | + python3 -m venv ~/venv + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary \ + -r .github/scripts/requirements.txt \ + -r tests/http/requirements.txt \ + -r tests/requirements.txt + + - name: 'REUSE check' + run: | + source ~/venv/bin/activate + reuse lint + + - name: 'codespell' + run: | + source ~/venv/bin/activate + codespell --version + .github/scripts/codespell.sh + + - name: 'typos' + timeout-minutes: 2 + run: | + /home/linuxbrew/.linuxbrew/bin/brew install typos-cli + eval "$(/home/linuxbrew/.linuxbrew/bin/brew shellenv)" + typos --version + .github/scripts/typos.sh + + - name: 'cmakelint' + run: | + source ~/venv/bin/activate + scripts/cmakelint.sh + + - name: 'perlcheck' + run: | + scripts/perlcheck.sh + + - name: 'ruff' + run: | + source ~/venv/bin/activate + scripts/pythonlint.sh + + pytype: + name: 'pytype' + runs-on: ubuntu-24.04-arm # pytype is discontinued and requires python 3.8-3.12 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'install prereqs' + run: | + python3 -m venv ~/venv + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary pytype==2024.10.11 \ + -r .github/scripts/requirements.txt \ + -r tests/http/requirements.txt \ + -r tests/requirements.txt + + - name: 'check' + run: | + source ~/venv/bin/activate + find . -name '*.py' -exec pytype -j auto -k -- {} + + + complexity: + name: 'complexity and function sizes' + runs-on: ubuntu-slim + timeout-minutes: 3 + steps: + - name: 'install pmccabe' + timeout-minutes: 2 + run: | + ls -l /etc/apt/sources.list.d + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install pmccabe + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'check function complexity' + run: ./scripts/top-complexity + + - name: 'check function lengths' + run: ./scripts/top-length + + xmllint: + name: 'xmllint' + runs-on: ubuntu-slim + timeout-minutes: 3 + steps: + - name: 'install prereqs' + timeout-minutes: 2 + run: | + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install libxml2-utils + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'check' + run: git grep -z -i -l -E '^<\?xml' | xargs -0 -r xmllint --output /dev/null + + miscchecks: + name: 'misc checks' + runs-on: ubuntu-24.04-arm + timeout-minutes: 5 + steps: + - name: 'install prereqs' + timeout-minutes: 2 + run: /home/linuxbrew/.linuxbrew/bin/brew install actionlint shellcheck zizmor + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'zizmor GHA' + env: + GH_TOKEN: '${{ secrets.GITHUB_TOKEN }}' + run: | + eval "$(/home/linuxbrew/.linuxbrew/bin/brew shellenv)" + zizmor --persona pedantic .github/workflows/*.yml .github/dependabot.yml + + - name: 'zizmor GHA (auditor, warning-only)' + env: + GH_TOKEN: '${{ secrets.GITHUB_TOKEN }}' + run: | + eval "$(/home/linuxbrew/.linuxbrew/bin/brew shellenv)" + zizmor --persona auditor .github/workflows/*.yml .github/dependabot.yml || true + + - name: 'actionlint' + run: | + eval "$(/home/linuxbrew/.linuxbrew/bin/brew shellenv)" + export SHELLCHECK_OPTS='--exclude=1090,1091,2086,2153 --enable=avoid-nullary-conditions,deprecate-which' + actionlint --version + actionlint --ignore matrix --ignore ubuntu-26.04 .github/workflows/*.yml + + - name: 'shellcheck CI' + run: | + eval "$(/home/linuxbrew/.linuxbrew/bin/brew shellenv)" + shellcheck --version + .github/scripts/shellcheck-ci.sh + + - name: 'shellcheck' + run: | + eval "$(/home/linuxbrew/.linuxbrew/bin/brew shellenv)" + shellcheck --version + .github/scripts/shellcheck.sh + + - name: 'spacecheck' + run: scripts/spacecheck.pl + + - name: 'yamlcheck' + run: .github/scripts/yamlcheck.sh + + - name: 'badwords' + run: scripts/badwords-all diff --git a/third-party/curl/.github/workflows/checkurls.yml b/third-party/curl/.github/workflows/checkurls.yml new file mode 100644 index 0000000000..da5a99b861 --- /dev/null +++ b/third-party/curl/.github/workflows/checkurls.yml @@ -0,0 +1,43 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +name: 'URLs' + +'on': + push: + branches: + - master + - '*/ci' + pull_request: + branches: + - master + schedule: + - cron: '10 5 * * *' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + DO_NOT_TRACK: '1' + +jobs: + linkcheck: + if: ${{ github.repository_owner == 'curl' || github.event_name != 'schedule' }} + name: 'linkcheck' + runs-on: ubuntu-slim + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'mdlinkcheck (dry run)' + if: ${{ github.event_name != 'schedule' }} + run: ./scripts/mdlinkcheck --dry-run + + - name: 'mdlinkcheck' + if: ${{ github.event_name == 'schedule' }} + run: ./scripts/mdlinkcheck diff --git a/third-party/curl/.github/workflows/codeql-analysis.yml b/third-party/curl/.github/workflows/codeql-analysis.yml deleted file mode 100644 index e5f38cc831..0000000000 --- a/third-party/curl/.github/workflows/codeql-analysis.yml +++ /dev/null @@ -1,80 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: CodeQL - -on: - push: - branches: - - master - - '*/ci' - paths-ignore: - - '**/*.md' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'docs/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'tests/data/**' - - 'winbuild/**' - pull_request: - branches: - - master - paths-ignore: - - '**/*.md' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'docs/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'tests/data/**' - - 'winbuild/**' - schedule: - - cron: '0 0 * * 4' - -concurrency: - group: ${{ github.workflow }} - -permissions: {} - -jobs: - codeql: - runs-on: ubuntu-latest - permissions: - security-events: write - steps: - - name: Checkout repository - uses: actions/checkout@v3 - - # Initializes the CodeQL tools for scanning. - - name: Initialize CodeQL - uses: github/codeql-action/init@v2 - with: - languages: cpp - queries: security-extended - - # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). - # If this step fails, then you should remove it and run the build manually (see below) - - name: Autobuild - uses: github/codeql-action/autobuild@v2 - - # â„¹ï¸ Command-line programs to run using the OS shell. - # 📚 https://git.io/JvXDl - - # âœï¸ If the Autobuild fails above, remove it and uncomment the following three lines - # and modify them (or add more) to build your code if your project - # uses a compiled language - - #- run: | - # make bootstrap - # make release - - - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v2 diff --git a/third-party/curl/.github/workflows/codeql.yml b/third-party/curl/.github/workflows/codeql.yml new file mode 100644 index 0000000000..15b91c18c4 --- /dev/null +++ b/third-party/curl/.github/workflows/codeql.yml @@ -0,0 +1,142 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +name: 'CodeQL' + +'on': + push: + branches: + - master + - '*/ci' + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'projects/**' + - 'tests/data/**' + pull_request: + branches: + - master + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'projects/**' + - 'tests/data/**' + schedule: + - cron: '0 0 * * 4' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + DO_NOT_TRACK: '1' + +jobs: + gha_python: + if: ${{ github.repository_owner == 'curl' || github.event_name != 'schedule' }} + name: 'GHA and Python' + runs-on: ubuntu-latest + permissions: + security-events: write # To create/update security events + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'initialize' + uses: github/codeql-action/init@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + with: + languages: actions, python + queries: security-extended + + - name: 'perform analysis' + uses: github/codeql-action/analyze@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + + c: + if: ${{ github.repository_owner == 'curl' || github.event_name != 'schedule' }} + name: 'C' + runs-on: ${{ matrix.platform == 'Linux' && 'ubuntu-latest' || 'windows-2022' }} + permissions: + security-events: write # To create/update security events + strategy: + fail-fast: false + matrix: + platform: [Linux, Windows] + env: + MATRIX_PLATFORM: '${{ matrix.platform }}' + steps: + - name: 'install prereqs' + if: ${{ matrix.platform == 'Linux' }} + timeout-minutes: 2 + run: | + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install \ + libpsl-dev libbrotli-dev libidn2-dev libssh2-1-dev libssh-dev \ + libnghttp2-dev libldap-dev libkrb5-dev libgnutls28-dev libwolfssl-dev + /home/linuxbrew/.linuxbrew/bin/brew install c-ares gsasl libnghttp3 libngtcp2 mbedtls rustls-ffi + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'delete test input C files' + shell: bash + run: find tests/data -name '*.c' -delete + + - name: 'initialize' + # https://github.com/github/codeql-action/blob/main/init/action.yml + uses: github/codeql-action/init@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + with: + languages: cpp + build-mode: manual + trap-caching: false + + - name: 'build' + timeout-minutes: 10 + shell: bash + run: | + if [ "${MATRIX_PLATFORM}" = 'Windows' ]; then + cmake -B . -DBUILD_SHARED_LIBS=OFF -DCURL_DROP_UNUSED=ON -DCURL_WERROR=ON \ + -DCMAKE_VS_GLOBALS=TrackFileAccess=false \ + -DCURL_USE_SCHANNEL=ON -DCURL_USE_LIBPSL=OFF -DUSE_WIN32_IDN=ON + cmake --build . --verbose + src/Debug/curl.exe --disable --version + else + eval "$(/home/linuxbrew/.linuxbrew/bin/brew shellenv)" + + export PKG_CONFIG_PATH + + # MultiSSL + PKG_CONFIG_PATH="$(brew --prefix c-ares)/lib/pkgconfig:$(brew --prefix mbedtls)/lib/pkgconfig:$(brew --prefix rustls-ffi)/lib/pkgconfig:$(brew --prefix gsasl)/lib/pkgconfig" + cmake -B _bld1 -G Ninja -DCURL_DISABLE_TYPECHECK=ON -DCURL_WERROR=ON -DENABLE_DEBUG=ON \ + -DCURL_USE_GNUTLS=ON -DCURL_USE_MBEDTLS=ON -DCURL_USE_RUSTLS=ON -DCURL_USE_WOLFSSL=ON \ + -DCURL_USE_GSASL=ON -DCURL_USE_GSSAPI=ON -DUSE_SSLS_EXPORT=ON -DUSE_ECH=ON -DENABLE_ARES=ON \ + -DCURL_DISABLE_VERBOSE_STRINGS=ON + cmake --build _bld1 + cmake --build _bld1 --target testdeps + cmake --build _bld1 --target curl-examples-build + + # HTTP/3 + PKG_CONFIG_PATH="$(brew --prefix libnghttp3)/lib/pkgconfig:$(brew --prefix libngtcp2)/lib/pkgconfig:$(brew --prefix gsasl)/lib/pkgconfig" + cmake -B _bld2 -G Ninja -DCURL_DISABLE_TYPECHECK=ON -DCURL_WERROR=ON \ + -DCURL_USE_OPENSSL=ON -DOPENSSL_ROOT_DIR="$(brew --prefix openssl)" -DUSE_NGTCP2=ON \ + -DCURL_USE_LIBSSH2=OFF -DCURL_USE_LIBSSH=ON \ + -DCURL_USE_GSASL=ON -DCURL_USE_GSSAPI=ON -DUSE_SSLS_EXPORT=ON -DUSE_PROXY_HTTP3=ON + cmake --build _bld2 + cmake --build _bld2 --target testdeps + cmake --build _bld2 --target curl-examples-build + + _bld1/src/curl --disable --version + _bld2/src/curl --disable --version + fi + + - name: 'perform analysis' + # https://github.com/github/codeql-action/blob/main/analyze/action.yml + uses: github/codeql-action/analyze@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 diff --git a/third-party/curl/.github/workflows/configure-vs-cmake.yml b/third-party/curl/.github/workflows/configure-vs-cmake.yml new file mode 100644 index 0000000000..bcab34395f --- /dev/null +++ b/third-party/curl/.github/workflows/configure-vs-cmake.yml @@ -0,0 +1,194 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +name: 'configure-vs-cmake' +'on': + push: + branches: + - master + paths: + - '*.ac' + - '**/*.m4' + - '**/CMakeLists.txt' + - 'CMake/**' + - 'lib/curl_config-cmake.h.in' + - 'tests/cmake/**' + - '.github/scripts/cmp-config.pl' + - '.github/workflows/configure-vs-cmake.yml' + + pull_request: + branches: + - master + paths: + - '*.ac' + - '**/*.m4' + - '**/CMakeLists.txt' + - 'CMake/**' + - 'lib/curl_config-cmake.h.in' + - 'tests/cmake/**' + - '.github/scripts/cmp-config.pl' + - '.github/workflows/configure-vs-cmake.yml' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + DO_NOT_TRACK: '1' + +jobs: + check-linux: + name: 'Linux' + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'run configure --with-openssl' + run: | + autoreconf -fi + export PKG_CONFIG_DEBUG_SPEW=1 + mkdir bld-am && cd bld-am && ../configure --enable-static=no --with-openssl --without-libpsl + + - name: 'run cmake' + run: cmake -B bld-cm -DCURL_WERROR=ON -DCURL_USE_CMAKECONFIG=OFF -DCURL_USE_LIBPSL=OFF + + - name: 'configure log' + run: cat bld-am/config.log 2>/dev/null || true + + - name: 'cmake log' + run: cat bld-cm/CMakeFiles/CMakeConfigureLog.yaml 2>/dev/null || true + + - name: 'dump generated files' + run: | + for f in libcurl.pc curl-config; do + echo "::group::AM ${f}"; grep -v '^#' bld-am/"${f}" || true; echo '::endgroup::' + echo "::group::CM ${f}"; grep -v '^#' bld-cm/"${f}" || true; echo '::endgroup::' + done + + - name: 'compare generated curl_config.h files' + run: ./.github/scripts/cmp-config.pl bld-am/lib/curl_config.h bld-cm/lib/curl_config.h + + - name: 'compare generated libcurl.pc files' + run: ./.github/scripts/cmp-pkg-config.sh bld-am/libcurl.pc bld-cm/libcurl.pc + + - name: 'compare generated curl-config files' + run: ./.github/scripts/cmp-pkg-config.sh bld-am/curl-config bld-cm/curl-config + + check-macos: + name: 'macOS' + runs-on: macos-latest + steps: + - name: 'install packages' + timeout-minutes: 2 + run: | + # shellcheck disable=SC2181 + while [[ $? == 0 ]]; do + for i in 1 2 3; do + if brew install automake libtool; then + break 2 + else + echo "Error: wait to try again: $i" + sleep 10 + fi + done + false Too many retries + done + + - name: 'toolchain versions' + run: echo '::group::brew packages installed'; ls -l /opt/homebrew/opt; echo '::endgroup::' + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'run configure --with-openssl' + run: | + autoreconf -fi + export PKG_CONFIG_DEBUG_SPEW=1 + mkdir bld-am && cd bld-am && ../configure --enable-static=no --with-openssl --without-libpsl --disable-ldap --with-brotli --with-zstd --with-apple-sectrust + + - name: 'run cmake' + run: | + cmake -B bld-cm -DCURL_WERROR=ON -DCURL_USE_CMAKECONFIG=OFF -DCURL_USE_LIBPSL=OFF -DCURL_DISABLE_LDAP=ON \ + -DCMAKE_C_COMPILER_TARGET="$(uname -m | sed 's/arm64/aarch64/')-apple-darwin$(uname -r)" \ + -DCURL_USE_LIBSSH2=OFF -DUSE_APPLE_SECTRUST=ON + + - name: 'configure log' + run: cat bld-am/config.log 2>/dev/null || true + + - name: 'cmake log' + run: cat bld-cm/CMakeFiles/CMakeConfigureLog.yaml 2>/dev/null || true + + - name: 'dump generated files' + run: | + for f in libcurl.pc curl-config; do + echo "::group::AM ${f}"; grep -v '^#' bld-am/"${f}" || true; echo '::endgroup::' + echo "::group::CM ${f}"; grep -v '^#' bld-cm/"${f}" || true; echo '::endgroup::' + done + + - name: 'compare generated curl_config.h files' + run: ./.github/scripts/cmp-config.pl bld-am/lib/curl_config.h bld-cm/lib/curl_config.h + + - name: 'compare generated libcurl.pc files' + run: ./.github/scripts/cmp-pkg-config.sh bld-am/libcurl.pc bld-cm/libcurl.pc + + - name: 'compare generated curl-config files' + run: ./.github/scripts/cmp-pkg-config.sh bld-am/curl-config bld-cm/curl-config + + check-windows: + name: 'Windows' + runs-on: ubuntu-latest + env: + TRIPLET: 'x86_64-w64-mingw32' + steps: + - name: 'install packages' + timeout-minutes: 1 + run: | + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install gcc-mingw-w64-x86-64-win32 + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'run configure --with-schannel' + run: | + autoreconf -fi + export PKG_CONFIG_DEBUG_SPEW=1 + mkdir bld-am && cd bld-am && ../configure --enable-static=no --with-schannel --without-libpsl --host="${TRIPLET}" + + - name: 'run cmake' + run: | + cmake -B bld-cm -DCURL_WERROR=ON -DCURL_USE_CMAKECONFIG=OFF -DCURL_USE_SCHANNEL=ON -DCURL_USE_LIBPSL=OFF \ + -DCMAKE_SYSTEM_NAME=Windows \ + -DCMAKE_C_COMPILER_TARGET="${TRIPLET}" \ + -DCMAKE_C_COMPILER="${TRIPLET}-gcc" + + - name: 'configure log' + run: cat bld-am/config.log 2>/dev/null || true + + - name: 'cmake log' + run: cat bld-cm/CMakeFiles/CMakeConfigureLog.yaml 2>/dev/null || true + + - name: 'dump generated files' + run: | + for f in libcurl.pc curl-config; do + echo "::group::AM ${f}"; grep -v '^#' bld-am/"${f}" || true; echo '::endgroup::' + echo "::group::CM ${f}"; grep -v '^#' bld-cm/"${f}" || true; echo '::endgroup::' + done + + - name: 'compare generated curl_config.h files' + run: ./.github/scripts/cmp-config.pl bld-am/lib/curl_config.h bld-cm/lib/curl_config.h + + - name: 'compare generated libcurl.pc files' + run: ./.github/scripts/cmp-pkg-config.sh bld-am/libcurl.pc bld-cm/libcurl.pc + + - name: 'compare generated curl-config files' + run: ./.github/scripts/cmp-pkg-config.sh bld-am/curl-config bld-cm/curl-config diff --git a/third-party/curl/.github/workflows/curl-for-win.yml b/third-party/curl/.github/workflows/curl-for-win.yml new file mode 100644 index 0000000000..2f47321a19 --- /dev/null +++ b/third-party/curl/.github/workflows/curl-for-win.yml @@ -0,0 +1,199 @@ +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl +--- +name: 'curl-for-win' + +'on': + push: + branches: + - master + - '*/ci' + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + pull_request: + branches: + - master + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + CW_NOGET: 'curl trurl' + CW_MAP: '0' + CW_JOBS: '5' + CW_NOPKG: '1' + DO_NOT_TRACK: '1' + +jobs: + linux-glibc-gcc: + name: 'Linux gcc glibc (amd64, arm64)' + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + path: 'curl' + fetch-depth: 8 + - name: 'build' + run: | + git clone --depth 1 https://github.com/curl/curl-for-win + mv curl-for-win/* . + export CW_CONFIG='-main-werror-unitybatch-nocertdata-linux-a64-x64-gcc' + export CW_REVISION="${GITHUB_SHA}" + . ./_versions.sh + export CW_CCSUFFIX='-15' + export CW_GCCSUFFIX='-12' + sudo podman image trust set --type reject default + sudo podman image trust set --type accept docker.io/library + time podman pull "${OCI_IMAGE_DEBIAN_STABLE}" + podman images --digests + time podman run --volume "$(pwd):$(pwd)" --workdir "$(pwd)" \ + --env-file <(env | grep -a -E \ + '^(CW_|DO_NOT_TRACK|GITHUB_)') \ + "${OCI_IMAGE_DEBIAN_STABLE}" \ + sh -c ./_ci-linux-debian.sh + + linux-glibc-gcc-minimal: # use gcc to minimize installed packages + name: 'Linux gcc glibc minimal (amd64)' + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + path: 'curl' + fetch-depth: 8 + - name: 'build' + run: | + git clone --depth 1 https://github.com/curl/curl-for-win + mv curl-for-win/* . + export CW_CONFIG='-main-werror-unitybatch-nocertdata-prefill-zero-osnotls-osnoidn-nohttp-nocurltool-linux-x64-gcc' + export CW_REVISION="${GITHUB_SHA}" + . ./_versions.sh + sudo podman image trust set --type reject default + sudo podman image trust set --type accept docker.io/library + time podman pull "${OCI_IMAGE_DEBIAN}" + podman images --digests + time podman run --volume "$(pwd):$(pwd)" --workdir "$(pwd)" \ + --env-file <(env | grep -a -E \ + '^(CW_|DO_NOT_TRACK|GITHUB_)') \ + "${OCI_IMAGE_DEBIAN}" \ + sh -c ./_ci-linux-debian.sh + + linux-musl-llvm: + name: 'Linux llvm MUSL (amd64, riscv64)' + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + path: 'curl' + fetch-depth: 8 + - name: 'build' + run: | + git clone --depth 1 https://github.com/curl/curl-for-win + mv curl-for-win/* . + export CW_CONFIG='-main-werror-unitybatch-nocertdata-linux-musl-r64-x64' + export CW_REVISION="${GITHUB_SHA}" + . ./_versions.sh + export CW_CCSUFFIX='-19' + export CW_GCCSUFFIX='-14' + sudo podman image trust set --type reject default + sudo podman image trust set --type accept docker.io/library + time podman pull "${OCI_IMAGE_DEBIAN_STABLE}" + podman images --digests + time podman run --volume "$(pwd):$(pwd)" --workdir "$(pwd)" \ + --env-file <(env | grep -a -E \ + '^(CW_|DO_NOT_TRACK|GITHUB_)') \ + "${OCI_IMAGE_DEBIAN_STABLE}" \ + sh -c ./_ci-linux-debian.sh + + mac-clang: + name: 'macOS clang cares (x86_64)' + runs-on: macos-latest + timeout-minutes: 10 + env: + CW_JOBS: '4' + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + path: 'curl' + fetch-depth: 8 + - name: 'build' + run: | + git clone --depth 1 https://github.com/curl/curl-for-win + mv curl-for-win/* . + export CW_CONFIG='-main-werror-unitybatch-nocertdata-mac-x64-cares' + export CW_REVISION="${GITHUB_SHA}" + sh -c ./_ci-mac-homebrew.sh + + win-llvm: + name: 'Windows llvm (x64)' + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + path: 'curl' + fetch-depth: 8 + - name: 'build' + run: | + git clone --depth 1 https://github.com/curl/curl-for-win + mv curl-for-win/* . + export CW_CONFIG='-main-werror-unitybatch-nocertdata-win-x64-noWINE' + export CW_REVISION="${GITHUB_SHA}" + . ./_versions.sh + sudo podman image trust set --type reject default + sudo podman image trust set --type accept docker.io/library + time podman pull "${OCI_IMAGE_DEBIAN}" + podman images --digests + time podman run --volume "$(pwd):$(pwd)" --workdir "$(pwd)" \ + --env-file <(env | grep -a -E \ + '^(CW_|DO_NOT_TRACK|GITHUB_)') \ + "${OCI_IMAGE_DEBIAN}" \ + sh -c ./_ci-linux-debian.sh + + win-gcc-zlibold-x64: + name: 'Windows gcc zlib-classic (x64)' + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + path: 'curl' + fetch-depth: 8 + - name: 'build' + run: | + git clone --depth 1 https://github.com/curl/curl-for-win + mv curl-for-win/* . + export CW_CONFIG='-main-werror-unitybatch-nocertdata-win-x64-gcc-zlibold-noWINE' + export CW_REVISION="${GITHUB_SHA}" + . ./_versions.sh + sudo podman image trust set --type reject default + sudo podman image trust set --type accept docker.io/library + time podman pull "${OCI_IMAGE_DEBIAN}" + podman images --digests + time podman run --volume "$(pwd):$(pwd)" --workdir "$(pwd)" \ + --env-file <(env | grep -a -E \ + '^(CW_|DO_NOT_TRACK|GITHUB_)') \ + "${OCI_IMAGE_DEBIAN}" \ + sh -c ./_ci-linux-debian.sh diff --git a/third-party/curl/.github/workflows/distcheck.yml b/third-party/curl/.github/workflows/distcheck.yml new file mode 100644 index 0000000000..6aa969cd0f --- /dev/null +++ b/third-party/curl/.github/workflows/distcheck.yml @@ -0,0 +1,409 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +name: 'dist' + +'on': + push: + branches: + - master + - '*/ci' + pull_request: + branches: + - master + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + CURL_TEST_MIN: 1500 + DO_NOT_TRACK: '1' + MAKEFLAGS: -j 5 + +jobs: + maketgz-and-verify-in-tree: + name: 'AM in-tree & maketgz' + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'remove preinstalled curl libcurl4{-doc}' + run: sudo apt-get -o Dpkg::Use-Pty=0 purge curl libcurl4 libcurl4-doc + + - name: 'autoreconf' + run: autoreconf -fi + + - name: 'configure' + run: ./configure --without-ssl --without-libpsl + + - name: 'make' + run: make V=1 + + - name: 'maketgz' + run: SOURCE_DATE_EPOCH=1711526400 ./scripts/maketgz 99.98.97 + + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: 'release-tgz' + path: 'curl-99.98.97.tar.gz' + retention-days: 1 + + - name: 'configure build & install' + run: | + echo "::stop-commands::$(uuidgen)" + tar xvf curl-99.98.97.tar.gz + pushd curl-99.98.97 + ./configure --prefix="$HOME"/temp --enable-option-checking=fatal --enable-werror --without-ssl --without-libpsl + make + make test-ci + make install + popd + # basic check of the installed files + bash scripts/installcheck.sh "$HOME"/temp + rm -rf curl-99.98.97 + + verify-out-of-tree-docs: + name: 'AM out-of-tree docs' + runs-on: ubuntu-latest + timeout-minutes: 10 + needs: maketgz-and-verify-in-tree + steps: + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: 'release-tgz' + + - name: 'configure build & docs' + run: | + echo "::stop-commands::$(uuidgen)" + tar xvf curl-99.98.97.tar.gz + touch curl-99.98.97/docs/{cmdline-opts,libcurl}/Makefile.inc + mkdir build + pushd build + ../curl-99.98.97/configure --enable-option-checking=fatal --enable-werror --without-ssl --without-libpsl + make + make test-ci + popd + rm -rf build + rm -rf curl-99.98.97 + + verify-out-of-tree-autotools-debug: + name: 'AM out-of-tree (debug)' + runs-on: ubuntu-latest + timeout-minutes: 10 + needs: maketgz-and-verify-in-tree + steps: + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: 'release-tgz' + + - name: 'build & install' + run: | + echo "::stop-commands::$(uuidgen)" + tar xvf curl-99.98.97.tar.gz + pushd curl-99.98.97 + mkdir build + pushd build + ../configure --prefix="$PWD"/curl-install --enable-option-checking=fatal --enable-werror --without-ssl --enable-debug --without-libpsl + make + make test-ci + make install + curl-install/bin/curl --disable --version + curl-install/bin/curl --manual | wc -l | grep -v '^ *0$' + popd + scripts/checksrc-all.pl + + verify-out-of-tree-autotools: + name: 'AM out-of-tree !perl' + runs-on: ubuntu-latest + timeout-minutes: 10 + needs: maketgz-and-verify-in-tree + steps: + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: 'release-tgz' + + - name: 'build & install' + run: | + echo "::stop-commands::$(uuidgen)" + tar xvf curl-99.98.97.tar.gz + pushd curl-99.98.97 + mkdir build + pushd build + ../configure --prefix="$PWD"/curl-install --enable-option-checking=fatal --enable-werror --without-ssl --without-libpsl ac_cv_path_PERL= + make + make install + curl-install/bin/curl --disable --version + curl-install/bin/curl --manual | wc -l | grep -v '^ *0$' + popd + + verify-in-tree-autotools: + name: 'AM in-tree !perl' + runs-on: ubuntu-latest + timeout-minutes: 10 + needs: maketgz-and-verify-in-tree + steps: + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: 'release-tgz' + + - name: 'build & install' + run: | + echo "::stop-commands::$(uuidgen)" + tar xvf curl-99.98.97.tar.gz + pushd curl-99.98.97 + ./configure --prefix="$PWD"/curl-install --enable-option-checking=fatal --enable-werror --without-ssl --without-libpsl ac_cv_path_PERL= + make + make install + curl-install/bin/curl --disable --version + curl-install/bin/curl --manual | wc -l | grep -v '^ *0$' + + verify-out-of-tree-cmake: + name: 'CM out-of-tree !perl' + runs-on: ubuntu-latest + timeout-minutes: 5 + needs: maketgz-and-verify-in-tree + steps: + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: 'release-tgz' + + - name: 'build & install' + run: | + echo "::stop-commands::$(uuidgen)" + tar xvf curl-99.98.97.tar.gz + pushd curl-99.98.97 + cmake -B build -DCMAKE_INSTALL_PREFIX="$PWD"/curl-install -DCURL_WERROR=ON -DCURL_USE_LIBPSL=OFF -DPERL_EXECUTABLE= + cmake --build build + cmake --install build + export LD_LIBRARY_PATH="$PWD/curl-install/lib:$LD_LIBRARY_PATH" + curl-install/bin/curl --disable --version + curl-install/bin/curl --manual | wc -l | grep -v '^ *0$' + + verify-in-tree-cmake: + name: 'CM in-tree !perl' + runs-on: ubuntu-latest + timeout-minutes: 5 + needs: maketgz-and-verify-in-tree + steps: + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: 'release-tgz' + + - name: 'build & install' + run: | + echo "::stop-commands::$(uuidgen)" + tar xvf curl-99.98.97.tar.gz + pushd curl-99.98.97 + cmake . -G Ninja -DCMAKE_INSTALL_PREFIX="$PWD"/curl-install -DCURL_WERROR=ON -DCURL_USE_LIBPSL=OFF -DPERL_EXECUTABLE= + cmake --build . + cmake --install . + export LD_LIBRARY_PATH="$PWD/curl-install/lib:$LD_LIBRARY_PATH" + curl-install/bin/curl --disable --version + curl-install/bin/curl --manual | wc -l | grep -v '^ *0$' + + missing-files: + name: 'missing files' + runs-on: ubuntu-slim + timeout-minutes: 5 + needs: maketgz-and-verify-in-tree + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: 'release-tgz' + + - name: 'detect files missing from release tarball' + run: .github/scripts/distfiles.sh curl-99.98.97.tar.gz + + reproducible-releases: + name: 'reproducible releases' + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'remove preinstalled curl libcurl4{-doc}' + run: sudo apt-get -o Dpkg::Use-Pty=0 purge curl libcurl4 libcurl4-doc + + - name: 'generate release tarballs' + run: ./scripts/dmaketgz 9.10.11 + + - name: 'verify release tarballs' + run: | + mkdir _verify + mv curl-9.10.11.tar.gz _verify + cd _verify + ../scripts/verify-release curl-9.10.11.tar.gz + + cmake-integration: + name: 'CM integration ${{ matrix.image }}' + runs-on: ${{ matrix.image }} + timeout-minutes: 15 + defaults: + run: + shell: ${{ contains(matrix.image, 'windows') && 'msys2 {0}' || 'bash' }} + env: + CC: ${{ !contains(matrix.image, 'windows') && 'clang' || '' }} + MAKEFLAGS: ${{ contains(matrix.image, 'macos') && '-j 4' || '-j 5' }} + MATRIX_IMAGE: '${{ matrix.image }}' + TESTOPTS: ${{ contains(matrix.image, 'macos') && '-D_CURL_PREFILL=ON' || '' }} ${{ contains(matrix.image, 'windows') && '-DCMAKE_UNITY_BUILD_BATCH_SIZE=30' || '' }} + OLD_CMAKE_VERSION: 3.19.8 + OLD_CMAKE_SHA256_LINUX_ARM: 807f5afb2a560e00af9640e496d5673afefc2888bf0ed076412884a5ebb547a1 + OLD_CMAKE_SHA256_MACOS_UNI: 0976d23d982af05dcbfb3aa34fcb62ead43bea27f0e3bb95222f2a78161423f2 + OLD_CMAKE_SHA256_WIN_INTEL: 2a30877a3d6b50da305b289f4d1c03befdfaeb2edba02a563c681e883d810380 + strategy: + fail-fast: false + matrix: + image: [ubuntu-24.04-arm, macos-latest, windows-2022] + steps: + - uses: msys2/setup-msys2@e9898307ac31d1a803454791be09ab9973336e1c # v2.31.1 + if: ${{ contains(matrix.image, 'windows') }} + with: + msystem: mingw64 + release: false + update: false + cache: false + path-type: inherit + install: >- + mingw-w64-x86_64-zlib mingw-w64-x86_64-zstd mingw-w64-x86_64-libpsl mingw-w64-x86_64-libssh2 mingw-w64-x86_64-nghttp2 mingw-w64-x86_64-openssl + + - name: 'install prereqs' + timeout-minutes: 3 + run: | + if [[ "${MATRIX_IMAGE}" = *'windows'* ]]; then + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/Kitware/CMake/releases/download/v${OLD_CMAKE_VERSION}/cmake-${OLD_CMAKE_VERSION}-win64-x64.zip" --output pkg.bin + sha256sum pkg.bin && sha256sum pkg.bin | grep -qwF -- "${OLD_CMAKE_SHA256_WIN_INTEL}" && unzip -q pkg.bin && rm -f pkg.bin + printf '%s' ~/cmake-"${OLD_CMAKE_VERSION}"-win64-x64/bin/cmake.exe > ~/old-cmake-path.txt + elif [[ "${MATRIX_IMAGE}" = *'ubuntu'* ]]; then + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install libpsl-dev libssl-dev + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/Kitware/CMake/releases/download/v${OLD_CMAKE_VERSION}/cmake-${OLD_CMAKE_VERSION}-Linux-aarch64.tar.gz" --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF -- "${OLD_CMAKE_SHA256_LINUX_ARM}" && tar -xzf pkg.bin && rm -f pkg.bin + printf '%s' ~/cmake-"${OLD_CMAKE_VERSION}"-Linux-aarch64/bin/cmake > ~/old-cmake-path.txt + else + brew install libpsl openssl + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/Kitware/CMake/releases/download/v${OLD_CMAKE_VERSION}/cmake-${OLD_CMAKE_VERSION}-macos-universal.tar.gz" --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF -- "${OLD_CMAKE_SHA256_MACOS_UNI}" && tar -xzf pkg.bin && rm -f pkg.bin + printf '%s' ~/cmake-"${OLD_CMAKE_VERSION}"-macos-universal/CMake.app/Contents/bin/cmake > ~/old-cmake-path.txt + fi + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'via ExternalProject' + if: ${{ !contains(matrix.image, 'ubuntu') }} + run: ./tests/cmake/test.sh ExternalProject ${TESTOPTS} + - name: 'via FetchContent' + run: ./tests/cmake/test.sh FetchContent ${TESTOPTS} -DCURL_USE_OPENSSL=ON + - name: 'via add_subdirectory' + run: ./tests/cmake/test.sh add_subdirectory ${TESTOPTS} -DCURL_USE_OPENSSL=ON + - name: 'via find_package' + run: ./tests/cmake/test.sh find_package ${TESTOPTS} -DCURL_USE_OPENSSL=ON + - name: 'via find_package (C++)' + if: ${{ contains(matrix.image, 'ubuntu') }} + run: TEST_CMAKE_FLAGS=-DTEST_CPP=ON ./tests/cmake/test.sh find_package ${TESTOPTS} -DCURL_USE_OPENSSL=ON + - name: 'via find_package (PREFER_CONFIG=ON)' + if: ${{ contains(matrix.image, 'windows') }} + run: | + export TEST_CMAKE_FLAGS_PROVIDER='-DCMAKE_FIND_PACKAGE_PREFER_CONFIG=ON -DCURL_ZSTD=OFF' + TEST_CMAKE_FLAGS_PROVIDER+=' -DNGHTTP2_INCLUDE_DIR=C:/msys64/mingw64/include -DNGHTTP2_LIBRARY=C:/msys64/mingw64/lib/libnghttp2.dll.a' + export TEST_CMAKE_FLAGS_CONSUMER="${TEST_CMAKE_FLAGS_PROVIDER}" + ./tests/cmake/test.sh find_package ${TESTOPTS} -DCURL_USE_OPENSSL=ON + + - name: 'via ExternalProject (old cmake)' + if: ${{ contains(matrix.image, 'ubuntu') }} + run: | + export TEST_CMAKE_CONSUMER; TEST_CMAKE_CONSUMER="$(cat ~/old-cmake-path.txt)" + if [[ "${MATRIX_IMAGE}" = *'macos'* ]]; then + export CFLAGS='-arch arm64' + fi + if [[ "${MATRIX_IMAGE}" = *'windows'* ]]; then + export TEST_CMAKE_GENERATOR='MSYS Makefiles' + export TEST_CMAKE_FLAGS='-DCMAKE_C_COMPILER=x86_64-w64-mingw32-gcc' + fi + ./tests/cmake/test.sh ExternalProject ${TESTOPTS} + + - name: 'via add_subdirectory OpenSSL (old cmake)' + run: | + export TEST_CMAKE_CONSUMER; TEST_CMAKE_CONSUMER="$(cat ~/old-cmake-path.txt)" + if [[ "${MATRIX_IMAGE}" = *'macos'* ]]; then + export CFLAGS='-arch arm64' + export TEST_CMAKE_FLAGS='-DCURL_USE_LIBPSL=OFF' # auto-detection does not work with old-cmake + fi + if [[ "${MATRIX_IMAGE}" = *'windows'* ]]; then + export TEST_CMAKE_GENERATOR='MSYS Makefiles' + export TEST_CMAKE_FLAGS='-DCMAKE_C_COMPILER=x86_64-w64-mingw32-gcc -DOPENSSL_ROOT_DIR=C:/msys64/mingw64' + fi + ./tests/cmake/test.sh add_subdirectory ${TESTOPTS} -DCURL_USE_OPENSSL=ON + + - name: 'via find_package OpenSSL (old cmake)' + run: | + export TEST_CMAKE_CONSUMER; TEST_CMAKE_CONSUMER="$(cat ~/old-cmake-path.txt)" + if [[ "${MATRIX_IMAGE}" = *'macos'* ]]; then + export CFLAGS='-arch arm64' + export TEST_CMAKE_FLAGS='-DCURL_USE_LIBPSL=OFF' # auto-detection does not work with old-cmake + fi + if [[ "${MATRIX_IMAGE}" = *'windows'* ]]; then + export TEST_CMAKE_GENERATOR='MSYS Makefiles' + export TEST_CMAKE_FLAGS='-DCMAKE_C_COMPILER=x86_64-w64-mingw32-gcc -DOPENSSL_ROOT_DIR=C:/msys64/mingw64' + fi + ./tests/cmake/test.sh find_package ${TESTOPTS} -DCURL_USE_OPENSSL=ON + + verify-tarball-downloads: + name: 'Verify tarball downloads' + runs-on: ubuntu-slim + timeout-minutes: 2 + steps: + - name: 'download and import GPG key' + env: + CURL_GPG_ID: 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2 + run: | + for keyserver in \ + https://keyserver.ubuntu.com/ \ + https://pgpkeys.eu/ \ + ; do + echo "--- Downloading from ${keyserver}..." + if curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + "${keyserver}pks/lookup?op=get&options=mr&exact=on&search=0x${CURL_GPG_ID}" \ + | gpg --batch --keyserver-options timeout=15 --display-charset utf-8 --keyid-format 0xlong --import --status-fd 1 2>&1; then + break + fi + done + + - name: 'download and verify tarballs' + run: | + echo "--- Detecting latest curl tarball version..." + curl_version="$(curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused https://curl.se/info.json \ + | jq --raw-output .Version)" + + for suffix in .tar.bz2 .tar.gz .tar.xz .zip; do + echo "--- Downloading ${curl_version} ${suffix}..." + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --output pkg.bin "https://curl.se/download/curl-${curl_version}${suffix}" \ + --output pkg.sig "https://curl.se/download/curl-${curl_version}${suffix}.asc" + echo "--- Verifying ${curl_version} ${suffix}..." + gpg --batch --keyserver-options timeout=15 --display-charset utf-8 --keyid-format 0xlong --verify-options show-primary-uid-only \ + --verify pkg.sig pkg.bin 2>&1 + echo '---' + done diff --git a/third-party/curl/.github/workflows/fuzz.yml b/third-party/curl/.github/workflows/fuzz.yml index 695e0def97..dc15b9c9db 100644 --- a/third-party/curl/.github/workflows/fuzz.yml +++ b/third-party/curl/.github/workflows/fuzz.yml @@ -2,49 +2,45 @@ # # SPDX-License-Identifier: curl -name: Fuzzer +name: 'Fuzzer' -on: +'on': push: branches: - - master - - '*/ci' + - master + - '*/ci' paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'tests/data/**' - - 'winbuild/**' + - '**/*.md' + - '**/CMakeLists.txt' + - '.circleci/**' + - 'appveyor.*' + - 'CMake/**' + - 'Dockerfile' + - 'projects/**' + - 'tests/data/**' pull_request: branches: - - master + - master paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'tests/data/**' - - 'winbuild/**' + - '**/*.md' + - '**/CMakeLists.txt' + - '.circleci/**' + - 'appveyor.*' + - 'CMake/**' + - 'Dockerfile' + - 'projects/**' + - 'tests/data/**' concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + # Hard-coded workflow name to avoid colliding with curl-fuzzer's group + group: curl-fuzz-${{ github.event.pull_request.number || github.sha }} cancel-in-progress: true permissions: {} +env: + DO_NOT_TRACK: '1' + jobs: Fuzzing: - uses: curl/curl-fuzzer/.github/workflows/ci.yml@master + uses: curl/curl-fuzzer/.github/workflows/ci.yml@master # zizmor: ignore[unpinned-uses] diff --git a/third-party/curl/.github/workflows/hacktoberfest-accepted.yml b/third-party/curl/.github/workflows/hacktoberfest-accepted.yml deleted file mode 100644 index c78ff4e301..0000000000 --- a/third-party/curl/.github/workflows/hacktoberfest-accepted.yml +++ /dev/null @@ -1,67 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: Hacktoberfest - -on: - # this must not ever run on any other branch than master - push: - branches: - - master - -concurrency: - # this should not run in parallel, so just run one at a time - group: ${{ github.workflow }} - -permissions: {} - -jobs: - # add hacktoberfest-accepted label to PRs opened starting from September 30th - # till November 1st which are closed via commit reference from master branch. - merged: - runs-on: ubuntu-latest - permissions: - # requires issues AND pull-requests write permissions to edit labels on PRs! - issues: write - pull-requests: write - steps: - - uses: actions/checkout@v3 - with: - fetch-depth: 100 - - - name: Check whether repo participates in Hacktoberfest - run: | - gh config set prompt disabled && echo "label=$( - gh repo view --json repositoryTopics --jq '.repositoryTopics[].name' | grep '^hacktoberfest$')" >> $GITHUB_OUTPUT - id: check - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - - - name: Search relevant commit message lines starting with Closes/Merges - run: | - git log --format=email ${{ github.event.before }}..${{ github.event.after }} | \ - grep -Ei "^Close[sd]? " | sort | uniq | tee log - if: steps.check.outputs.label == 'hacktoberfest' - - - name: Search for Number-based PR references - run: | - grep -Eo "#([0-9]+)" log | cut -d# -f2 | sort | uniq | xargs -t -n1 -I{} \ - gh pr view {} --json number,createdAt \ - --jq '{number, opened: .createdAt} | [.number, .opened] | join(":")' | tee /dev/stderr | \ - grep -Eo '^([0-9]+):[0-9]{4}-(09-30T|10-|11-01T)' | cut -d: -f1 | sort | uniq | xargs -t -n1 -I {} \ - gh pr edit {} --add-label 'hacktoberfest-accepted' - if: steps.check.outputs.label == 'hacktoberfest' - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - - - name: Search for URL-based PR references - run: | - grep -Eo "github.com/(.+)/(.+)/pull/([0-9]+)" log | sort | uniq | xargs -t -n1 -I{} \ - gh pr view "https://{}" --json number,createdAt \ - --jq '{number, opened: .createdAt} | [.number, .opened] | join(":")' | tee /dev/stderr | \ - grep -Eo '^([0-9]+):[0-9]{4}-(09-30T|10-|11-01T)' | cut -d: -f1 | sort | uniq | xargs -t -n1 -I {} \ - gh pr edit {} --add-label 'hacktoberfest-accepted' - if: steps.check.outputs.label == 'hacktoberfest' - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/third-party/curl/.github/workflows/http3-linux.yml b/third-party/curl/.github/workflows/http3-linux.yml new file mode 100644 index 0000000000..2be2399744 --- /dev/null +++ b/third-party/curl/.github/workflows/http3-linux.yml @@ -0,0 +1,894 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +name: 'Linux HTTP/3' + +'on': + push: + branches: + - master + - '*/ci' + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + pull_request: + branches: + - master + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + MAKEFLAGS: -j 5 + CURL_CI: github + CURL_TEST_MIN: 1850 + DO_NOT_TRACK: '1' + # renovate: datasource=github-tags depName=awslabs/aws-lc versioning=semver registryUrl=https://github.com + AWSLC_VERSION: 5.0.0 + # renovate: datasource=github-tags depName=google/boringssl versioning=semver registryUrl=https://github.com + BORINGSSL_VERSION: 0.20260616.0 + # renovate: datasource=github-tags depName=gnutls/nettle versioning=semver registryUrl=https://github.com + NETTLE_VERSION: 3.10.2 + # renovate: datasource=github-tags depName=gnutls/gnutls versioning=semver extractVersion=^nettle_?(?.+)_release_.+$ registryUrl=https://github.com + GNUTLS_VERSION: 3.8.11 + # renovate: datasource=github-tags depName=libressl/portable versioning=semver registryUrl=https://github.com + LIBRESSL_VERSION: 4.3.2 + # renovate: datasource=github-releases depName=openssl/openssl versioning=semver extractVersion=^openssl-(?.+)$ registryUrl=https://github.com + OPENSSL_VERSION: 4.0.1 + # manually bumped + OPENSSL_PREV_VERSION: 3.6.2 + OPENSSL_PREV_SHA256: aaf51a1fe064384f811daeaeb4ec4dce7340ec8bd893027eee676af31e83a04f + # renovate: datasource=github-tags depName=cloudflare/quiche versioning=semver registryUrl=https://github.com + QUICHE_VERSION: 0.29.2 + # renovate: datasource=github-tags depName=wolfSSL/wolfssl versioning=semver extractVersion=^v?(?.+)-stable$ registryUrl=https://github.com + WOLFSSL_VERSION: 5.9.1 + # renovate: datasource=github-tags depName=ngtcp2/nghttp3 versioning=semver registryUrl=https://github.com + NGHTTP3_VERSION: 1.16.0 + # renovate: datasource=github-tags depName=ngtcp2/ngtcp2 versioning=semver registryUrl=https://github.com + NGTCP2_VERSION: 1.23.0 + # renovate: datasource=github-tags depName=nghttp2/nghttp2 versioning=semver registryUrl=https://github.com + NGHTTP2_VERSION: 1.69.0 + # no tagged releases + H2O_VERSION: 11b0cfa2771e3ccad4a852e72473e4e278ab1de7 # 2026-05-28 + H2O_SHA256: 5ae1bd7b09970d7d49c41fa68193e24da04c2a7ac5581fbe2affc79200b0721f + +jobs: + build-cache: + name: 'Build caches' + runs-on: ubuntu-26.04 + + steps: + - name: 'cache awslc' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-awslc + env: + cache-name: cache-awslc + with: + path: ~/awslc/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.AWSLC_VERSION }} + + - name: 'cache boringssl' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-boringssl + env: + cache-name: cache-boringssl + with: + path: ~/boringssl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.BORINGSSL_VERSION }} + + - name: 'cache nettle' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-nettle + env: + cache-name: cache-nettle + with: + path: ~/nettle/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NETTLE_VERSION }} + + - name: 'cache gnutls' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-gnutls + env: + cache-name: cache-gnutls + with: + path: ~/gnutls/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.GNUTLS_VERSION }}-${{ env.NETTLE_VERSION }} + + - name: 'cache libressl' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-libressl + env: + cache-name: cache-libressl + with: + path: ~/libressl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.LIBRESSL_VERSION }} + + - name: 'cache openssl' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-openssl-http3-no-deprecated + env: + cache-name: cache-openssl-http3-no-deprecated + with: + path: ~/openssl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.OPENSSL_VERSION }} + + - name: 'cache openssl-prev' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-openssl-prev-http3 + env: + cache-name: cache-openssl-prev-http3 + with: + path: ~/openssl-prev/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.OPENSSL_PREV_VERSION }} + + - name: 'cache wolfssl' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-wolfssl + env: + cache-name: cache-wolfssl + with: + path: ~/wolfssl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.WOLFSSL_VERSION }} + + - name: 'cache nghttp3' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-nghttp3 + env: + cache-name: cache-nghttp3 + with: + path: ~/nghttp3/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGHTTP3_VERSION }} + + - name: 'cache ngtcp2' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-ngtcp2 + env: + cache-name: cache-ngtcp2 + with: + path: ~/ngtcp2/build + key: "${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGTCP2_VERSION }}-${{ env.OPENSSL_VERSION }}-\ + ${{ env.LIBRESSL_VERSION }}-${{ env.AWSLC_VERSION }}-${{ env.NETTLE_VERSION }}-${{ env.GNUTLS_VERSION }}-${{ env.WOLFSSL_VERSION }}" + + - name: 'cache ngtcp2 boringssl' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-ngtcp2-boringssl + env: + cache-name: cache-ngtcp2-boringssl + with: + path: ~/ngtcp2-boringssl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGTCP2_VERSION }}-${{ env.BORINGSSL_VERSION }} + + - name: 'cache ngtcp2 openssl-prev' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-ngtcp2-openssl-prev + env: + cache-name: cache-ngtcp2-openssl-prev + with: + path: ~/ngtcp2-openssl-prev/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGTCP2_VERSION }}-${{ env.OPENSSL_PREV_VERSION }} + + - name: 'cache nghttp2' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-nghttp2 + env: + cache-name: cache-nghttp2 + with: + path: ~/nghttp2/build + key: "${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGHTTP2_VERSION }}-${{ env.OPENSSL_VERSION }}-\ + ${{ env.NGTCP2_VERSION }}-${{ env.NGHTTP3_VERSION }}" + + - name: 'cache h2o' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-h2o + env: + cache-name: cache-h2o + with: + path: ~/h2o/build + key: "${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.H2O_VERSION }}-${{ env.OPENSSL_PREV_VERSION }}" + + - id: settings + if: >- + ${{ !steps.cache-awslc.outputs.cache-hit || + !steps.cache-boringssl.outputs.cache-hit || + !steps.cache-nettle.outputs.cache-hit || + !steps.cache-gnutls.outputs.cache-hit || + !steps.cache-libressl.outputs.cache-hit || + !steps.cache-openssl-http3-no-deprecated.outputs.cache-hit || + !steps.cache-openssl-prev-http3.outputs.cache-hit || + !steps.cache-wolfssl.outputs.cache-hit || + !steps.cache-nghttp3.outputs.cache-hit || + !steps.cache-ngtcp2-boringssl.outputs.cache-hit || + !steps.cache-ngtcp2-openssl-prev.outputs.cache-hit || + !steps.cache-ngtcp2.outputs.cache-hit || + !steps.cache-nghttp2.outputs.cache-hit || + !steps.cache-h2o.outputs.cache-hit }} + + run: echo 'needs-build=true' >> "$GITHUB_OUTPUT" + + - name: 'install build prereqs' + if: ${{ steps.settings.outputs.needs-build == 'true' }} + timeout-minutes: 2 + run: | + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install \ + libtool autoconf automake pkgconf \ + libbrotli-dev libzstd-dev zlib1g-dev \ + libev-dev \ + libuv1-dev \ + libc-ares-dev \ + libp11-kit-dev autopoint bison gperf gtk-doc-tools libtasn1-bin # for GnuTLS + + - name: 'build awslc' + if: ${{ !steps.cache-awslc.outputs.cache-hit }} + run: | + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/awslabs/aws-lc/archive/refs/tags/v${AWSLC_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "aws-lc-${AWSLC_VERSION}" + cmake -B . -G Ninja -DBUILD_SHARED_LIBS=ON -DBUILD_TOOL=OFF -DBUILD_TESTING=OFF -DCMAKE_INSTALL_PREFIX=/home/runner/awslc/build + cmake --build . + cmake --install . + + - name: 'build boringssl' + if: ${{ !steps.cache-boringssl.outputs.cache-hit }} + run: | + mkdir boringssl-src + cd boringssl-src + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + "https://boringssl.googlesource.com/boringssl/+archive/${BORINGSSL_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cmake -B . -G Ninja -DBUILD_SHARED_LIBS=ON -DBUILD_TESTING=OFF -DCMAKE_INSTALL_PREFIX=/home/runner/boringssl/build + cmake --build . + cmake --install . + + - name: 'build nettle' + if: ${{ !steps.cache-nettle.outputs.cache-hit }} + run: | + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://ftpmirror.gnu.org/nettle/nettle-${NETTLE_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "nettle-${NETTLE_VERSION}" + autoreconf -fi + ./configure --disable-dependency-tracking --prefix=/home/runner/nettle/build \ + --disable-static --disable-openssl --disable-documentation + make install + + - name: 'build gnutls' + if: ${{ !steps.cache-gnutls.outputs.cache-hit }} + run: | + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + "https://www.gnupg.org/ftp/gcrypt/gnutls/v${GNUTLS_VERSION%.*}/gnutls-${GNUTLS_VERSION}.tar.xz" --output pkg.bin + sha256sum pkg.bin && tar -xJf pkg.bin && rm -f pkg.bin + cd "gnutls-${GNUTLS_VERSION}" + autoreconf -fi + # required: libp11-kit-dev libev-dev autopoint bison gperf gtk-doc-tools libtasn1-bin + ./configure --disable-dependency-tracking --prefix=/home/runner/gnutls/build \ + PKG_CONFIG_PATH=/home/runner/nettle/build/lib64/pkgconfig \ + LDFLAGS=-Wl,-rpath,/home/runner/nettle/build/lib64 \ + --with-included-libtasn1 --with-included-unistring \ + --disable-guile --disable-doc --disable-tests --disable-tools + make install + + - name: 'build libressl' + if: ${{ !steps.cache-libressl.outputs.cache-hit }} + run: | + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + "https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-${LIBRESSL_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "libressl-${LIBRESSL_VERSION}" + cmake -B . -G Ninja -DLIBRESSL_APPS=OFF -DLIBRESSL_TESTS=OFF -DCMAKE_INSTALL_PREFIX=/home/runner/libressl/build + cmake --build . + cmake --install . + + - name: 'build openssl' + if: ${{ !steps.cache-openssl-http3-no-deprecated.outputs.cache-hit }} + run: | + cd ~ + git clone --quiet --depth 1 --branch "openssl-${OPENSSL_VERSION}" https://github.com/openssl/openssl + cd openssl + ./config --prefix="$PWD"/build --libdir=lib no-makedepend no-apps no-docs no-tests no-deprecated + make + make -j1 install_sw + + - name: 'build openssl-prev' + if: ${{ !steps.cache-openssl-prev-http3.outputs.cache-hit }} + run: | + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/openssl/openssl/releases/download/openssl-${OPENSSL_PREV_VERSION}/openssl-${OPENSSL_PREV_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF -- "${OPENSSL_PREV_SHA256}" && tar -xzf pkg.bin && rm -f pkg.bin + cd "openssl-${OPENSSL_PREV_VERSION}" + ./config --prefix=/home/runner/openssl-prev/build --libdir=lib no-makedepend no-apps no-docs no-tests + make + make -j1 install_sw + + - name: 'build wolfssl' + if: ${{ !steps.cache-wolfssl.outputs.cache-hit }} + run: | + cd ~ + git clone --quiet --depth 1 --branch "v${WOLFSSL_VERSION}-stable" https://github.com/wolfSSL/wolfssl + cd wolfssl + ./autogen.sh + ./configure --disable-dependency-tracking --prefix="$PWD"/build --enable-all --enable-quic \ + --disable-benchmark --disable-crypttests --disable-examples + make + make install + + - name: 'build nghttp3' + if: ${{ !steps.cache-nghttp3.outputs.cache-hit }} + run: | + cd ~ + git clone --quiet --depth 1 --branch "v${NGHTTP3_VERSION}" https://github.com/ngtcp2/nghttp3 + cd nghttp3 + git submodule update --init --depth 1 + autoreconf -fi + ./configure --disable-dependency-tracking --prefix="$PWD"/build --enable-lib-only + make + make install + + - name: 'build ngtcp2' + if: ${{ !steps.cache-ngtcp2.outputs.cache-hit }} + # building twice to get crypto libs for ossl, libressl and awslc installed + run: | + cd ~ + git clone --quiet --depth 1 --branch "v${NGTCP2_VERSION}" https://github.com/ngtcp2/ngtcp2 + cd ngtcp2 + autoreconf -fi + ./configure --disable-dependency-tracking --prefix="$PWD"/build --enable-lib-only \ + PKG_CONFIG_PATH=/home/runner/libressl/build/lib/pkgconfig \ + --with-openssl + make install + make clean + export PKG_CONFIG_PATH=/home/runner/openssl/build/lib/pkgconfig + PKG_CONFIG_PATH+=:/home/runner/nettle/build/lib64/pkgconfig + PKG_CONFIG_PATH+=:/home/runner/gnutls/build/lib/pkgconfig + PKG_CONFIG_PATH+=:/home/runner/wolfssl/build/lib/pkgconfig + ./configure --disable-dependency-tracking --prefix="$PWD"/build --enable-lib-only \ + --with-openssl --with-gnutls --with-wolfssl --with-boringssl \ + BORINGSSL_LIBS='-L/home/runner/awslc/build/lib -lssl -lcrypto' \ + BORINGSSL_CFLAGS='-I/home/runner/awslc/build/include' + make install + + - name: 'build ngtcp2 openssl-prev' + if: ${{ !steps.cache-ngtcp2-openssl-prev.outputs.cache-hit }} + run: | + cd ~ + git clone --quiet --depth 1 --branch "v${NGTCP2_VERSION}" https://github.com/ngtcp2/ngtcp2 ngtcp2-openssl-prev + cd ngtcp2-openssl-prev + autoreconf -fi + ./configure --disable-dependency-tracking --prefix="$PWD"/build --enable-lib-only \ + PKG_CONFIG_PATH=/home/runner/openssl-prev/build/lib/pkgconfig \ + --with-openssl + make install + + - name: 'build ngtcp2 boringssl' + if: ${{ !steps.cache-ngtcp2-boringssl.outputs.cache-hit }} + run: | + cd ~ + git clone --quiet --depth 1 --branch "v${NGTCP2_VERSION}" https://github.com/ngtcp2/ngtcp2 ngtcp2-boringssl + cd ngtcp2-boringssl + autoreconf -fi + ./configure --disable-dependency-tracking --prefix="$PWD"/build --enable-lib-only \ + --with-openssl=no --with-boringssl \ + BORINGSSL_LIBS='-L/home/runner/boringssl/build/lib -lssl -lcrypto' \ + BORINGSSL_CFLAGS='-I/home/runner/boringssl/build/include' + make install + + - name: 'build nghttp2' + if: ${{ !steps.cache-nghttp2.outputs.cache-hit }} + run: | + cd ~ + git clone --quiet --depth 1 --branch "v${NGHTTP2_VERSION}" https://github.com/nghttp2/nghttp2 + cd nghttp2 + git submodule update --init --depth 1 + autoreconf -fi + # required (for nghttpx application): libc-ares-dev libev-dev zlib1g-dev + # optional (for nghttpx application): libbrotli-dev + export PKG_CONFIG_PATH=/home/runner/openssl/build/lib/pkgconfig + PKG_CONFIG_PATH+=:/home/runner/nghttp3/build/lib/pkgconfig + PKG_CONFIG_PATH+=:/home/runner/ngtcp2/build/lib/pkgconfig + ./configure --disable-dependency-tracking --prefix="$PWD"/build --enable-app --enable-http3 \ + LDFLAGS=-Wl,-rpath,/home/runner/openssl/build/lib \ + --with-libbrotlienc --with-libbrotlidec + make install + + - name: 'build h2o' + if: ${{ !steps.cache-h2o.outputs.cache-hit }} + run: | + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/h2o/h2o/archive/${H2O_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF -- "${H2O_SHA256}" && tar -xzf pkg.bin && rm -f pkg.bin + cd "h2o-${H2O_VERSION}" + cmake -B . -G Ninja -DWITHOUT_LIBS=ON -DOPENSSL_ROOT_DIR=/home/runner/openssl-prev/build -DCMAKE_INSTALL_PREFIX=/home/runner/h2o/build + cmake --build . + cmake --install . + + linux: + name: ${{ matrix.build.generate && 'CM' || 'AM' }} ${{ matrix.build.name }} + needs: build-cache + runs-on: ubuntu-26.04 + timeout-minutes: 10 + env: + CURL_TRACE_PKG_CONFIG: '1' + MATRIX_BUILD: ${{ matrix.build.generate && 'cmake' || 'autotools' }} + MATRIX_INSTALL_PACKAGES: '${{ matrix.build.install_packages }}' + strategy: + fail-fast: false + matrix: + build: + - name: 'awslc' + install_steps: skipall + LDFLAGS: -Wl,-rpath,/home/runner/awslc/build/lib + PKG_CONFIG_PATH: /home/runner/awslc/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/ngtcp2/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + # Intentionally using bare '--with-ngtcp2' + 'PKG_CONFIG_PATH' to test this way of configuration, in addition to '--with-ngtcp2=' in other jobs. + configure: >- + --with-openssl=/home/runner/awslc/build --with-ngtcp2 --enable-ssls-export + + - name: 'awslc' + PKG_CONFIG_PATH: /home/runner/awslc/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/ngtcp2/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + generate: >- + -DOPENSSL_ROOT_DIR=/home/runner/awslc/build -DUSE_NGTCP2=ON -DBUILD_SHARED_LIBS=OFF + -DCMAKE_UNITY_BUILD=ON -DCURL_DROP_UNUSED=ON + + - name: 'boringssl' + install_steps: skipall + LDFLAGS: -Wl,-rpath,/home/runner/boringssl/build/lib + PKG_CONFIG_PATH: /home/runner/boringssl/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + configure: >- + --with-openssl=/home/runner/boringssl/build --with-ngtcp2=/home/runner/ngtcp2-boringssl/build --enable-ssls-export + + - name: 'boringssl' + PKG_CONFIG_PATH: "\ + /home/runner/boringssl/build/lib/pkgconfig:\ + /home/runner/nghttp3/build/lib/pkgconfig:\ + /home/runner/ngtcp2-boringssl/build/lib/pkgconfig:\ + /home/runner/nghttp2/build/lib/pkgconfig" + generate: >- + -DOPENSSL_ROOT_DIR=/home/runner/boringssl/build -DUSE_NGTCP2=ON -DBUILD_SHARED_LIBS=OFF + -DCMAKE_UNITY_BUILD=ON + + - name: 'gnutls' + install_packages: libp11-kit-dev libssh-dev + install_steps: skipall + LDFLAGS: -Wl,-rpath,/home/runner/gnutls/build/lib -Wl,-rpath,/home/runner/nettle/build/lib64 -Wl,-rpath,/home/runner/ngtcp2/build/lib + PKG_CONFIG_PATH: /home/runner/nettle/build/lib64/pkgconfig:/home/runner/gnutls/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + configure: >- + --with-gnutls=/home/runner/gnutls/build --with-ngtcp2=/home/runner/ngtcp2/build --with-libssh --enable-ssls-export + + - name: 'gnutls' + install_packages: libp11-kit-dev libssh-dev + LDFLAGS: -Wl,-rpath,/home/runner/gnutls/build/lib + PKG_CONFIG_PATH: "\ + /home/runner/nettle/build/lib64/pkgconfig:\ + /home/runner/gnutls/build/lib/pkgconfig:\ + /home/runner/nghttp3/build/lib/pkgconfig:\ + /home/runner/ngtcp2/build/lib/pkgconfig:\ + /home/runner/nghttp2/build/lib/pkgconfig" + generate: >- + -DCURL_USE_GNUTLS=ON -DUSE_NGTCP2=ON -DCURL_USE_LIBSSH=ON + -DCMAKE_UNITY_BUILD=ON + + - name: 'libressl' + install_steps: skipall + LDFLAGS: -Wl,-rpath,/home/runner/libressl/build/lib + PKG_CONFIG_PATH: /home/runner/libressl/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + # Intentionally using '--with-ngtcp2=' to test this way of configuration, in addition to bare '--with-ngtcp2' + 'PKG_CONFIG_PATH' in other jobs. + configure: >- + --with-openssl=/home/runner/libressl/build --with-ngtcp2=/home/runner/ngtcp2/build --enable-ssls-export + --enable-unity + + - name: 'libressl' + PKG_CONFIG_PATH: /home/runner/libressl/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/ngtcp2/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + generate: >- + -DOPENSSL_ROOT_DIR=/home/runner/libressl/build -DUSE_NGTCP2=ON + + - name: 'openssl' + tflags: '--min=1700' + LDFLAGS: -Wl,-rpath,/home/runner/openssl/build/lib + PKG_CONFIG_PATH: /home/runner/openssl/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + configure: >- + --with-openssl=/home/runner/openssl/build --with-ngtcp2=/home/runner/ngtcp2/build --enable-ech --enable-ssls-export --enable-proxy-http3 + + - name: 'openssl' + install_steps: skipall + PKG_CONFIG_PATH: /home/runner/openssl/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/ngtcp2/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + generate: >- + -DOPENSSL_ROOT_DIR=/home/runner/openssl/build -DUSE_NGTCP2=ON + -DCURL_DISABLE_LDAP=ON + -DUSE_ECH=ON -DUSE_PROXY_HTTP3=ON + -DCMAKE_UNITY_BUILD=ON + + - name: 'openssl-prev' + install_steps: skipall + LDFLAGS: -Wl,-rpath,/home/runner/openssl-prev/build/lib + PKG_CONFIG_PATH: "\ + /home/runner/openssl-prev/build/lib/pkgconfig:\ + /home/runner/nghttp3/build/lib/pkgconfig:\ + /home/runner/nghttp2-openssl-prev/build/lib/pkgconfig" + configure: >- + --with-openssl=/home/runner/openssl-prev/build --with-ngtcp2=/home/runner/ngtcp2-openssl-prev/build --enable-ssls-export + + - name: 'openssl-prev' + tflags: '--min=1700' + PKG_CONFIG_PATH: "\ + /home/runner/openssl-prev/build/lib/pkgconfig:\ + /home/runner/nghttp3/build/lib/pkgconfig:\ + /home/runner/ngtcp2-openssl-prev/build/lib/pkgconfig:\ + /home/runner/nghttp2/build/lib/pkgconfig" + generate: >- + -DOPENSSL_ROOT_DIR=/home/runner/openssl-prev/build -DUSE_NGTCP2=ON + -DCURL_DISABLE_LDAP=ON + + - name: 'quiche' + install_steps: skipall + LDFLAGS: -Wl,-rpath,/home/runner/quiche/target/release + PKG_CONFIG_PATH: /home/runner/nghttp2/build/lib/pkgconfig + configure: >- + --with-openssl=/home/runner/quiche/boringssl + --with-quiche=/home/runner/quiche/target/release + --with-ca-fallback + --enable-unity + + - name: 'quiche' + PKG_CONFIG_PATH: /home/runner/nghttp2/build/lib/pkgconfig:/home/runner/quiche/target/release + generate: >- + -DOPENSSL_ROOT_DIR=/home/runner/quiche/boringssl + -DUSE_QUICHE=ON + -DCURL_CA_FALLBACK=ON + + - name: 'wolfssl' + install_packages: libssh2-1-dev + install_steps: skipall + LDFLAGS: -Wl,-rpath,/home/runner/wolfssl/build/lib + PKG_CONFIG_PATH: /home/runner/wolfssl/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + configure: >- + --with-wolfssl=/home/runner/wolfssl/build --with-ngtcp2=/home/runner/ngtcp2/build --enable-ech --with-libssh2 --enable-ssls-export + --enable-unity + + - name: 'wolfssl' + install_packages: libssh2-1-dev + tflags: '--min=1900' + PKG_CONFIG_PATH: /home/runner/wolfssl/build/lib/pkgconfig:/home/runner/nghttp3/build/lib/pkgconfig:/home/runner/ngtcp2/build/lib/pkgconfig:/home/runner/nghttp2/build/lib/pkgconfig + generate: >- + -DCURL_USE_WOLFSSL=ON -DUSE_NGTCP2=ON + -DUSE_ECH=ON + + steps: + - name: 'install prereqs' + timeout-minutes: 2 + env: + INSTALL_PACKAGES: >- + ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') && 'stunnel4 ' || '' }} + ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') && + 'apache2 apache2-dev libnghttp2-dev vsftpd dante-server libev-dev' || '' }} + + run: | + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install \ + libtool autoconf automake pkgconf \ + libpsl-dev libbrotli-dev libzstd-dev zlib1g-dev libidn2-0-dev libldap-dev libuv1-dev valgrind \ + ${INSTALL_PACKAGES} \ + ${MATRIX_INSTALL_PACKAGES} + + - name: 'cache awslc' + if: ${{ contains(matrix.build.name, 'awslc') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-awslc + env: + cache-name: cache-awslc + with: + path: ~/awslc/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.AWSLC_VERSION }} + fail-on-cache-miss: true + + - name: 'cache boringssl' + if: ${{ contains(matrix.build.name, 'boringssl') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-boringssl + env: + cache-name: cache-boringssl + with: + path: ~/boringssl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.BORINGSSL_VERSION }} + fail-on-cache-miss: true + + - name: 'cache nettle' + if: ${{ contains(matrix.build.name, 'gnutls') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-nettle + env: + cache-name: cache-nettle + with: + path: ~/nettle/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NETTLE_VERSION }} + fail-on-cache-miss: true + + - name: 'cache gnutls' + if: ${{ contains(matrix.build.name, 'gnutls') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-gnutls + env: + cache-name: cache-gnutls + with: + path: ~/gnutls/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.GNUTLS_VERSION }}-${{ env.NETTLE_VERSION }} + fail-on-cache-miss: true + + - name: 'cache libressl' + if: ${{ contains(matrix.build.name, 'libressl') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-libressl + env: + cache-name: cache-libressl + with: + path: ~/libressl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.LIBRESSL_VERSION }} + fail-on-cache-miss: true + + - name: 'cache openssl' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-openssl-http3-no-deprecated + env: + cache-name: cache-openssl-http3-no-deprecated + with: + path: ~/openssl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.OPENSSL_VERSION }} + fail-on-cache-miss: true + + - name: 'cache openssl-prev' + if: ${{ contains(matrix.build.name, 'openssl-prev') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-openssl-prev-http3 + env: + cache-name: cache-openssl-prev-http3 + with: + path: ~/openssl-prev/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.OPENSSL_PREV_VERSION }} + fail-on-cache-miss: true + + - name: 'cache wolfssl' + if: ${{ contains(matrix.build.name, 'wolfssl') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-wolfssl + env: + cache-name: cache-wolfssl + with: + path: ~/wolfssl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.WOLFSSL_VERSION }} + fail-on-cache-miss: true + + - name: 'cache nghttp3' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-nghttp3 + env: + cache-name: cache-nghttp3 + with: + path: ~/nghttp3/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGHTTP3_VERSION }} + fail-on-cache-miss: true + + - name: 'cache ngtcp2' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-ngtcp2 + env: + cache-name: cache-ngtcp2 + with: + path: ~/ngtcp2/build + key: "${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGTCP2_VERSION }}-${{ env.OPENSSL_VERSION }}-\ + ${{ env.LIBRESSL_VERSION }}-${{ env.AWSLC_VERSION }}-${{ env.NETTLE_VERSION }}-${{ env.GNUTLS_VERSION }}-${{ env.WOLFSSL_VERSION }}" + fail-on-cache-miss: true + + - name: 'cache ngtcp2 boringssl' + if: ${{ contains(matrix.build.name, 'boringssl') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-ngtcp2-boringssl + env: + cache-name: cache-ngtcp2-boringssl + with: + path: ~/ngtcp2-boringssl/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGTCP2_VERSION }}-${{ env.BORINGSSL_VERSION }} + fail-on-cache-miss: true + + - name: 'cache ngtcp2 openssl-prev' + if: ${{ contains(matrix.build.name, 'openssl-prev') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-ngtcp2-openssl-prev + env: + cache-name: cache-ngtcp2-openssl-prev + with: + path: ~/ngtcp2-openssl-prev/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGTCP2_VERSION }}-${{ env.OPENSSL_PREV_VERSION }} + fail-on-cache-miss: true + + - name: 'cache nghttp2' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-nghttp2 + env: + cache-name: cache-nghttp2 + with: + path: ~/nghttp2/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.NGHTTP2_VERSION }}-${{ env.OPENSSL_VERSION }}-${{ env.NGTCP2_VERSION }}-${{ env.NGHTTP3_VERSION }} + fail-on-cache-miss: true + + - name: 'cache h2o' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-h2o + env: + cache-name: cache-h2o + with: + path: ~/h2o/build + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.H2O_VERSION }}-${{ env.OPENSSL_PREV_VERSION }} + fail-on-cache-miss: true + + - name: 'cache quiche' + if: ${{ contains(matrix.build.name, 'quiche') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-quiche + env: + cache-name: cache-quiche + with: + path: ~/quiche + key: ${{ runner.os }}-http3-build-${{ env.cache-name }}-${{ env.QUICHE_VERSION }} + + - name: 'build quiche and boringssl' + if: ${{ contains(matrix.build.name, 'quiche') && !steps.cache-quiche.outputs.cache-hit }} + run: | + cd ~ + git clone --quiet --depth 1 --branch "${QUICHE_VERSION}" --recursive https://github.com/cloudflare/quiche + cd quiche + cargo build -v --package quiche --release --features ffi,pkg-config-meta,qlog --verbose + ln -s libquiche.so target/release/libquiche.so.0 + cd .. + mkdir -p quiche/boringssl/lib + find quiche/target/release \( -name libcrypto.a -o -name libssl.a \) -exec ln -vnf -- '{}' quiche/boringssl/lib \; + find quiche/target/release/build/boring-sys-*/out/boringssl/src -maxdepth 1 \( -name include \) -exec ln -vsf -- '../../{}' quiche/boringssl \; + + # include dir + # /home/runner/quiche/boringssl/include + # lib dir + # /home/runner/quiche/boringssl/lib + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'autoreconf' + if: ${{ matrix.build.configure }} + run: autoreconf -fi + + - name: 'configure' + env: + LDFLAGS: '${{ matrix.build.LDFLAGS }}' + MATRIX_CONFIGURE: '${{ matrix.build.configure }}' + MATRIX_GENERATE: '${{ matrix.build.generate }}' + MATRIX_PKG_CONFIG_PATH: '${{ matrix.build.PKG_CONFIG_PATH }}' + run: | + [ -n "${MATRIX_PKG_CONFIG_PATH}" ] && export PKG_CONFIG_PATH="${MATRIX_PKG_CONFIG_PATH}" + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + [[ "${MATRIX_GENERATE}" = *'boringssl'* ]] && options=" -DBORINGSSL_VERSION=${BORINGSSL_VERSION}" + cmake -B bld -G Ninja \ + -DCMAKE_C_COMPILER_TARGET="$(uname -m)-unknown-linux-gnu" -DBUILD_STATIC_LIBS=ON \ + -DCURL_WERROR=ON -DENABLE_DEBUG=ON \ + -DCURL_USE_LIBUV=ON -DCURL_ENABLE_NTLM=ON \ + -DTEST_NGHTTPX=/home/runner/nghttp2/build/bin/nghttpx \ + -DH2O=/home/runner/h2o/build/bin/h2o \ + -DHTTPD_NGHTTPX=/home/runner/nghttp2/build/bin/nghttpx \ + ${MATRIX_GENERATE} ${options} + else + [[ "${MATRIX_CONFIGURE}" = *'boringssl'* ]] && export CPPFLAGS="-DCURL_BORINGSSL_VERSION=\\\"${BORINGSSL_VERSION}\\\"" + mkdir bld && cd bld && ../configure --enable-warnings --enable-werror --enable-debug --disable-static \ + --disable-dependency-tracking --enable-option-checking=fatal \ + --with-libuv --enable-ntlm \ + --with-test-h2o=/home/runner/h2o/build/bin/h2o \ + --with-test-nghttpx=/home/runner/nghttp2/build/bin/nghttpx \ + ${MATRIX_CONFIGURE} + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMakeConfigureLog.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'test configs' + run: grep -H -v '^#' bld/tests/config bld/tests/http/config.ini || true + + - name: 'build' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose + else + make -C bld V=1 + fi + + - name: 'curl -V' + run: | + find . -type f \( -name curl -o -name '*.so.*' -o -name '*.a' \) -print0 | xargs -0 file -- + find . -type f \( -name curl -o -name '*.so.*' -o -name '*.a' \) -print0 | xargs -0 stat -c '%10s bytes: %n' -- + bld/src/curl --disable -V + + - name: 'build tests' + if: ${{ !contains(matrix.build.install_steps, 'skipall') }} + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target testdeps + else + make -C bld V=1 -C tests + fi + + - name: 'install test prereqs' + if: ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') }} + run: | + python3 -m venv ~/venv + if bld/src/curl --disable -V 2>/dev/null | grep smb; then + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r tests/requirements.txt + fi + + - name: 'run tests' + if: ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') }} + env: + TFLAGS: '${{ matrix.build.tflags }}' + run: | + TFLAGS+=' -n' + source ~/venv/bin/activate + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target test-ci + else + make -C bld V=1 test-ci + fi + + - name: 'run tests (valgrind)' + if: ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') }} + run: | + export TFLAGS='-j6 --min=4 HTTP/3' + source ~/venv/bin/activate + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target test-ci + else + make -C bld V=1 test-ci + fi + + - name: 'install pytest prereqs' + if: ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') }} + run: | + [ -d ~/venv ] || python3 -m venv ~/venv + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r tests/http/requirements.txt + + - name: 'run pytest (event based)' + if: ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') }} + env: + CURL_TEST_EVENT: 1 + PYTEST_ADDOPTS: '--color=yes' + PYTEST_XDIST_AUTO_NUM_WORKERS: 4 + run: | + source ~/venv/bin/activate + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target curl-pytest-ci + else + make -C bld V=1 pytest-ci + fi diff --git a/third-party/curl/.github/workflows/label.yml b/third-party/curl/.github/workflows/label.yml index baab1e42a3..3922b8b7df 100644 --- a/third-party/curl/.github/workflows/label.yml +++ b/third-party/curl/.github/workflows/label.yml @@ -2,27 +2,34 @@ # # SPDX-License-Identifier: curl -# This workflow will triage pull requests and apply a label based on the +# This workflow triages pull requests and applies a label based on the # paths that are modified in the pull request. # -# To use this workflow, you will need to set up a .github/labeler.yml -# file with configuration. For more information, see: -# https://github.com/actions/labeler +# To use this workflow, you need to set up a .github/labeler.yml file with +# configuration. For more information, see: https://github.com/actions/labeler -name: Labeler -on: [pull_request_target] +name: 'Labeler' + +'on': [pull_request_target] # zizmor: ignore[dangerous-triggers] + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + DO_NOT_TRACK: '1' jobs: label: - - runs-on: ubuntu-latest + name: 'Labeler' + runs-on: ubuntu-slim permissions: - contents: read - pull-requests: write + contents: read # To comply with https://github.com/actions/labeler documentation + pull-requests: write # To edit labels on PRs steps: - - uses: actions/labeler@v4 - with: - repo-token: "${{ secrets.GITHUB_TOKEN }}" - # Workaround for actions/labeler#112 - sync-labels: '' + - uses: actions/labeler@f27b608878404679385c85cfa523b85ccb86e213 # v6.1.0 + with: + repo-token: '${{ secrets.GITHUB_TOKEN }}' diff --git a/third-party/curl/.github/workflows/linkcheck.yml b/third-party/curl/.github/workflows/linkcheck.yml deleted file mode 100644 index 18d12990bc..0000000000 --- a/third-party/curl/.github/workflows/linkcheck.yml +++ /dev/null @@ -1,36 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: Markdown links - -on: - push: - branches: - - master - - '*/ci' - paths: - - '.github/workflows/linkcheck.yml' - - '**.md' - pull_request: - branches: - - master - paths: - - '.github/workflows/linkcheck.yml' - - '**.md' - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} - cancel-in-progress: true - -permissions: {} - -jobs: - # Docs: https://github.com/marketplace/actions/markdown-link-check - check: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v3 - - uses: gaurav-nelson/github-action-markdown-link-check@v1 - with: - use-quiet-mode: 'yes' diff --git a/third-party/curl/.github/workflows/linux-old.yml b/third-party/curl/.github/workflows/linux-old.yml new file mode 100644 index 0000000000..46fa9acffd --- /dev/null +++ b/third-party/curl/.github/workflows/linux-old.yml @@ -0,0 +1,185 @@ +# Copyright (C) Daniel Fandrich, , et al. +# +# SPDX-License-Identifier: curl +# +# Compile on an old version of Linux that has barely the minimal build +# requirements for CMake. This tests that curl is still usable on really +# outdated systems. +# +# Debian stretch is chosen as it closely matches some of the oldest major +# versions we support (especially cmake); see docs/INTERNALS.md and it +# is still supported (as of this writing). +# stretch has ELTS support from Freexian until 2027-06-30 +# For ELTS info see https://www.freexian.com/lts/extended/docs/how-to-use-extended-lts/ +# The Debian key expires 2025-05-20, after which package signature +# verification may need to be disabled. +# httrack is one of the smallest downloaders, needed to bootstrap ELTS, +# and doesn not conflict with the curl we are building. + +name: 'Linux Old' + +'on': + push: + branches: + - master + - '*/ci' + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + pull_request: + branches: + - master + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + MAKEFLAGS: -j 5 + CURL_CI: github + CURL_TEST_MIN: 1560 + DEBIAN_FRONTEND: noninteractive + DO_NOT_TRACK: '1' + +jobs: + cmake-autotools: + name: 'autotools & cmake' + runs-on: ubuntu-latest + container: debian:stretch-20220622-slim@sha256:c5cd3ffceeb25b683bf5111ea89bf8049a177e00fb237235d48076a19cc80097 + + steps: + - name: 'install prereqs' + # Remember, this shell is dash, not bash + run: | + sed -E -i -e s@[a-z]+\.debian\.org/@archive.debian.org/debian-archive/@ -e '/ stretch-updates /d' /etc/apt/sources.list + apt-get -o Dpkg::Use-Pty=0 update + # See comment above if this fails after 2025-05-20 + apt-get -o Dpkg::Use-Pty=0 install -y --no-install-suggests --no-install-recommends httrack + httrack --get https://deb.freexian.com/extended-lts/pool/main/f/freexian-archive-keyring/freexian-archive-keyring_2022.06.08_all.deb + sha256sum freexian-archive-keyring_2022.06.08_all.deb && dpkg -i freexian-archive-keyring_2022.06.08_all.deb + echo 'deb http://deb.freexian.com/extended-lts stretch-lts main contrib non-free' | tee /etc/apt/sources.list.d/extended-lts.list + apt-get -o Dpkg::Use-Pty=0 update + apt-get -o Dpkg::Use-Pty=0 install -y --no-install-suggests --no-install-recommends \ + make automake autoconf libtool ninja-build gcc pkg-config libpsl-dev libzstd-dev zlib1g-dev libkrb5-dev libldap2-dev stunnel4 + # GitHub's actions/checkout needs newer glibc and libstdc++. The latter also depends on + # gcc-8-base, but it does not actually seem used in our situation and is not available in + # the main repo, so force the install. + httrack --get https://deb.freexian.com/extended-lts/pool/main/g/glibc/libc6_2.28-10+deb10u5_amd64.deb + httrack --get https://deb.freexian.com/extended-lts/pool/main/g/gcc-8/libstdc++6_8.3.0-6_amd64.deb + sha256sum libc6_*_amd64.deb libstdc++6_*_amd64.deb && dpkg -i --force-depends libc6_*_amd64.deb libstdc++6_*_amd64.deb + + - name: 'install prereqs (cmake)' + env: + CMAKE_VERSION: 3.18.0 # Earliest version supported by curl + CMAKE_SHA256: 4d9a9d3351161073a67e49366d701b6fa4b0343781982dc5eef08a02a750d403 + run: | + cd ~ + fn="cmake-${CMAKE_VERSION}-linux-x86_64" + httrack --get "https://github.com/Kitware/CMake/releases/download/v${CMAKE_VERSION}/${fn}.tar.gz" + sha256sum "${fn}".tar*.gz | tee /dev/stderr | grep -qwF -- "${CMAKE_SHA256}" && tar -xf "${fn}".tar*.gz && rm -f "${fn}".tar*.gz + mv "cmake-${CMAKE_VERSION}-Linux-x86_64" cmake + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'CM build-only configure (out-of-tree)' + run: | + ~/cmake/bin/cmake -B bld-1 -G Ninja -DCMAKE_UNITY_BUILD=ON -DCURL_WERROR=ON -DBUILD_SHARED_LIBS=ON \ + -DCURL_ENABLE_SSL=OFF -DENABLE_ARES=OFF -DCURL_ZSTD=OFF -DCURL_USE_GSSAPI=OFF -DCURL_USE_LIBSSH2=OFF -DCURL_USE_LIBSSH=OFF + + - name: 'CM build-only build' + run: | + ~/cmake/bin/cmake --build bld-1 --verbose + ~/cmake/bin/cmake --install bld-1 --verbose + + - name: 'CM build-only curl -V' + run: bld-1/src/curl --disable --version + + - name: 'CM build-only configure log' + if: ${{ !cancelled() }} + run: cat bld-1/CMakeFiles/CMake*.log 2>/dev/null || true + + - name: 'CM build-only curl_config.h' + run: | + echo '::group::raw'; cat bld-1/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld-1/lib/curl_config.h | sort || true + + # when this job can get libssh 0.9.0 or greater, this should get that enabled again + # when this job can get c-ares 1.16.0 or greater, this should get that enabled again + + - name: 'CM configure (out-of-tree, zstd, gssapi)' + run: | + ~/cmake/bin/cmake -B bld-oldie -G Ninja -DCMAKE_UNITY_BUILD=ON -DCURL_WERROR=ON -DBUILD_SHARED_LIBS=ON \ + -DCURL_ENABLE_SSL=OFF -DENABLE_ARES=OFF -DCURL_USE_GSSAPI=ON -DCURL_USE_LIBSSH2=OFF -DCURL_USE_LIBSSH=OFF \ + -DCURL_LIBCURL_VERSIONED_SYMBOLS=ON + + - name: 'CM configure log' + if: ${{ !cancelled() }} + run: cat bld-oldie/CMakeFiles/CMake*.log 2>/dev/null || true + + - name: 'CM curl_config.h' + run: | + echo '::group::raw'; cat bld-oldie/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld-oldie/lib/curl_config.h | sort || true + + - name: 'CM build' + run: ~/cmake/bin/cmake --build bld-oldie + + - name: 'CM curl -V' + run: bld-oldie/src/curl --disable --version + + - name: 'CM install' + run: ~/cmake/bin/cmake --install bld-oldie + + - name: 'CM build tests' + run: ~/cmake/bin/cmake --build bld-oldie --target testdeps + + - name: 'CM run tests' + run: ~/cmake/bin/cmake --build bld-oldie --target test-ci + + - name: 'CM build examples' + run: ~/cmake/bin/cmake --build bld-oldie --target curl-examples-build + + - name: 'AM autoreconf' + run: autoreconf -fi + + - name: 'AM configure (out-of-tree, zstd, gssapi)' + run: | + mkdir bld-am + cd bld-am + ../configure --prefix="$PWD"/../curl-install-am --enable-unity --enable-warnings --enable-werror --disable-shared \ + --disable-dependency-tracking --enable-option-checking=fatal \ + --without-ssl --disable-ares --without-libssh2 --with-zstd --with-gssapi + + - name: 'AM configure log' + if: ${{ !cancelled() }} + run: cat bld-am/config.log 2>/dev/null || true + + - name: 'AM curl_config.h' + run: | + echo '::group::raw'; cat bld-am/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld-am/lib/curl_config.h | sort || true + + - name: 'AM build' + run: make -C bld-am + + - name: 'AM curl -V' + run: bld-am/src/curl --disable --version + + - name: 'AM install' + run: make -C bld-am install + + - name: 'AM build tests' + run: make -C bld-am/tests all diff --git a/third-party/curl/.github/workflows/linux.yml b/third-party/curl/.github/workflows/linux.yml index d39b959bb9..fff7f1c876 100644 --- a/third-party/curl/.github/workflows/linux.yml +++ b/third-party/curl/.github/workflows/linux.yml @@ -2,36 +2,26 @@ # # SPDX-License-Identifier: curl -name: Linux +name: 'Linux' -on: +'on': push: branches: - - master - - '*/ci' + - master + - '*/ci' paths-ignore: - - '**/*.md' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' pull_request: branches: - - master + - master paths-ignore: - - '**/*.md' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} @@ -40,372 +30,974 @@ concurrency: permissions: {} env: - MAKEFLAGS: -j 3 - bearssl-version: 0.6 - libressl-version: v3.7.3 - mbedtls-version: v3.4.0 - mod_h2-version: v2.0.21 - msh3-version: v0.6.0 - openssl3-version: openssl-3.1.1 - quictls-version: OpenSSL_1_1_1t+quic - rustls-version: v0.10.0 + MAKEFLAGS: -j 5 + CURL_CI: github + CURL_TEST_MIN: 1660 + DO_NOT_TRACK: '1' + # renovate: datasource=github-tags depName=awslabs/aws-lc versioning=semver registryUrl=https://github.com + AWSLC_VERSION: 5.0.0 + # renovate: datasource=github-tags depName=google/boringssl versioning=semver registryUrl=https://github.com + BORINGSSL_VERSION: 0.20260616.0 + # renovate: datasource=github-releases depName=pizlonator/fil-c versioning=semver-coerced registryUrl=https://github.com + FIL_C_VERSION: '0.680' + # renovate: datasource=github-tags depName=libressl/portable versioning=semver registryUrl=https://github.com + LIBRESSL_VERSION: 4.3.2 + # renovate: datasource=github-tags depName=Mbed-TLS/mbedtls versioning=semver registryUrl=https://github.com + MBEDTLS_VERSION: 4.0.0 + # manually bumped + MBEDTLS_PREV_VERSION: 3.6.5 + MBEDTLS_PREV_SHA256: 4a11f1777bb95bf4ad96721cac945a26e04bf19f57d905f241fe77ebeddf46d8 + # renovate: datasource=github-tags depName=nghttp2/nghttp2 versioning=semver registryUrl=https://github.com + NGHTTP2_VERSION: 1.69.0 + # handled in renovate.json + OPENLDAP_VERSION: 2.6.10 + # renovate: datasource=github-releases depName=openssl/openssl versioning=semver extractVersion=^openssl-(?.+)$ registryUrl=https://github.com + OPENSSL_VERSION: 4.0.1 + # renovate: datasource=github-tags depName=rustls/rustls-ffi versioning=semver registryUrl=https://github.com + RUSTLS_VERSION: 0.15.3 + # renovate: datasource=github-tags depName=wolfSSL/wolfssl versioning=semver extractVersion=^v?(?.+)-stable$ registryUrl=https://github.com + WOLFSSL_VERSION: 5.9.1 jobs: - autotools: - name: ${{ matrix.build.name }} - runs-on: 'ubuntu-latest' + linux: + name: ${{ matrix.build.generate && 'CM' || 'AM' }} ${{ matrix.build.name }} + runs-on: ${{ matrix.build.image || 'ubuntu-latest' }} container: ${{ matrix.build.container }} - timeout-minutes: 90 + timeout-minutes: 15 + env: + MATRIX_BUILD: ${{ matrix.build.generate && 'cmake' || 'autotools' }} + MATRIX_INSTALL_PACKAGES: '${{ matrix.build.install_packages }}' + MATRIX_INSTALL_STEPS: '${{ matrix.build.install_steps }}' strategy: fail-fast: false matrix: build: - - name: bearssl - install_packages: zlib1g-dev valgrind - install_steps: bearssl pytest - configure: LDFLAGS="-Wl,-rpath,$HOME/bearssl/lib" --with-bearssl=$HOME/bearssl --enable-debug + - name: 'awslc' + install_steps: awslc pytest + LDFLAGS: -Wl,-rpath,/home/runner/awslc/lib + configure: --with-openssl=/home/runner/awslc --enable-ech --enable-ntlm --enable-smb - - name: bearssl-clang - install_packages: zlib1g-dev clang - install_steps: bearssl - configure: CC=clang LDFLAGS="-Wl,-rpath,$HOME/bearssl/lib" --with-bearssl=$HOME/bearssl --enable-debug + - name: 'awslc' + install_packages: libidn2-dev + install_steps: awslc + generate: -DOPENSSL_ROOT_DIR=/home/runner/awslc -DUSE_ECH=ON -DCMAKE_UNITY_BUILD=OFF -DCURL_DROP_UNUSED=ON -DCURL_PATCHSTAMP=test-patch -DCURL_ENABLE_NTLM=ON - - name: libressl - install_packages: zlib1g-dev valgrind - install_steps: libressl pytest - configure: LDFLAGS="-Wl,-rpath,$HOME/libressl/lib" --with-openssl=$HOME/libressl --enable-debug + - name: 'boringssl' + install_steps: boringssl pytest + generate: -DOPENSSL_ROOT_DIR=/home/runner/boringssl -DUSE_ECH=ON -DCURL_ENABLE_NTLM=ON - - name: libressl-clang - install_packages: zlib1g-dev clang - install_steps: libressl - configure: CC=clang LDFLAGS="-Wl,-rpath,$HOME/libressl/lib" --with-openssl=$HOME/libressl --enable-debug + - name: 'libressl krb5' + image: ubuntu-24.04-arm + install_packages: libidn2-dev libnghttp2-dev libldap-dev libkrb5-dev + install_steps: libressl-c-arm pytest codeset-test1 + LDFLAGS: -Wl,-rpath,/home/runner/libressl/lib + configure: --with-openssl=/home/runner/libressl --with-gssapi --enable-debug - - name: mbedtls - install_packages: libnghttp2-dev valgrind - install_steps: mbedtls pytest - configure: LDFLAGS="-Wl,-rpath,$HOME/mbedtls/lib" --with-mbedtls=$HOME/mbedtls --enable-debug + - name: 'libressl krb5 valgrind 1' + image: ubuntu-24.04-arm + install_packages: libnghttp2-dev libldap-dev libkrb5-dev valgrind + install_steps: libressl-c-arm + tflags: '--min=870 1 to 950' + generate: -DOPENSSL_ROOT_DIR=/home/runner/libressl -DCURL_USE_GSSAPI=ON -DENABLE_DEBUG=ON -DCURL_LIBCURL_VERSIONED_SYMBOLS=ON -DCURL_ENABLE_NTLM=ON - - name: mbedtls-clang - install_packages: libnghttp2-dev clang - install_steps: mbedtls - configure: CC=clang LDFLAGS="-Wl,-rpath,$HOME/mbedtls/lib" --with-mbedtls=$HOME/mbedtls --enable-debug + - name: 'libressl krb5 valgrind 2' + image: ubuntu-24.04-arm + install_packages: libnghttp2-dev libldap-dev libkrb5-dev valgrind + install_steps: libressl-c-arm + tflags: '--min=900 951 to 9999' + generate: -DOPENSSL_ROOT_DIR=/home/runner/libressl -DCURL_USE_GSSAPI=ON -DENABLE_DEBUG=ON -DCURL_LIBCURL_VERSIONED_SYMBOLS=ON -DCURL_ENABLE_NTLM=ON - - name: msh3 - install_packages: zlib1g-dev valgrind - install_steps: quictls msh3 - configure: LDFLAGS="-Wl,-rpath,$HOME/msh3/lib -Wl,-rpath,$HOME/quictls/lib" --with-msh3=$HOME/msh3 --with-openssl=$HOME/quictls --enable-debug + - name: 'libressl clang' + image: ubuntu-24.04-arm + install_packages: clang + install_steps: libressl-c-arm + CC: clang + LDFLAGS: -Wl,-rpath,/home/runner/libressl/lib + configure: --with-openssl=/home/runner/libressl --enable-debug - - name: openssl3 - install_packages: zlib1g-dev valgrind - install_steps: gcc-11 openssl3 pytest - configure: LDFLAGS="-Wl,-rpath,$HOME/openssl3/lib64" --with-openssl=$HOME/openssl3 --enable-debug --enable-websockets + - name: 'libressl Fil-C' + install_steps: filc libressl-filc nghttp2-filc pytest + tflags: '!776' # adds 1-9 minutes to the test run step, and fails consistently + CC: /home/runner/filc/build/bin/filcc + PKG_CONFIG_PATH: /home/runner/nghttp2/lib/pkgconfig + generate: >- + -DBUILD_STATIC_LIBS=ON -DBUILD_SHARED_LIBS=OFF -DCMAKE_UNITY_BUILD=OFF -DCURL_DISABLE_TYPECHECK=ON + -DOPENSSL_ROOT_DIR=/home/runner/libressl -DCURL_USE_LIBPSL=OFF + -DCURL_ZLIB=OFF -DCURL_BROTLI=OFF -DCURL_ZSTD=OFF + -DCURL_DISABLE_LDAP=ON -DUSE_LIBIDN2=OFF -DCURL_USE_LIBSSH2=OFF + -DCURL_ENABLE_NTLM=ON - - name: openssl3-O3 - install_packages: zlib1g-dev valgrind - install_steps: gcc-11 openssl3 - configure: CFLAGS=-O3 LDFLAGS="-Wl,-rpath,$HOME/openssl3/lib64" --with-openssl=$HOME/openssl3 --enable-debug --enable-websockets + - name: 'mbedtls gss valgrind 1' + image: ubuntu-24.04-arm + install_packages: libnghttp2-dev libidn2-dev libldap-dev libgss-dev valgrind + install_steps: mbedtls-latest-arm + tflags: '--min=850 1 to 1000' + LDFLAGS: -Wl,-rpath,/home/runner/mbedtls/lib + PKG_CONFIG_PATH: /home/runner/mbedtls/lib/pkgconfig + generate: -DCURL_USE_MBEDTLS=ON -DENABLE_DEBUG=ON -DCURL_USE_GSSAPI=ON -DCURL_DROP_UNUSED=ON - - name: openssl3-clang - install_packages: zlib1g-dev clang - install_steps: openssl3 - configure: CC=clang LDFLAGS="-Wl,-rpath,$HOME/openssl3/lib64" --with-openssl=$HOME/openssl3 --enable-debug --enable-websockets + - name: 'mbedtls gss valgrind 2' + image: ubuntu-24.04-arm + install_packages: libnghttp2-dev libidn2-dev libldap-dev libgss-dev valgrind + install_steps: mbedtls-latest-arm + tflags: '--min=900 1001 to 9999' + LDFLAGS: -Wl,-rpath,/home/runner/mbedtls/lib + PKG_CONFIG_PATH: /home/runner/mbedtls/lib/pkgconfig + generate: -DCURL_USE_MBEDTLS=ON -DENABLE_DEBUG=ON -DCURL_USE_GSSAPI=ON - - name: address-sanitizer - install_packages: zlib1g-dev libssh2-1-dev clang libssl-dev libubsan1 libasan8 libtsan2 - install_steps: pytest - configure: > - CC=clang - CFLAGS="-fsanitize=address,undefined,signed-integer-overflow -fno-sanitize-recover=undefined,integer -Wformat -Werror=format-security -Werror=array-bounds -g" - LDFLAGS="-fsanitize=address,undefined -fno-sanitize-recover=undefined,integer" - LIBS="-ldl -lubsan" - --with-openssl --enable-debug --enable-websockets + - name: 'mbedtls clang' + install_packages: libssh-dev libnghttp2-dev libldap-dev clang + install_steps: mbedtls-latest-intel pytest + CC: clang + LDFLAGS: -Wl,-rpath,/home/runner/mbedtls/lib + configure: --with-mbedtls=/home/runner/mbedtls --with-libssh --enable-debug --with-fish-functions-dir --with-zsh-functions-dir - - name: memory-sanitizer - install_packages: clang - install_steps: - configure: > - CC=clang - CFLAGS="-fsanitize=memory -Wformat -Werror=format-security -Werror=array-bounds -g" - LDFLAGS="-fsanitize=memory" - LIBS="-ldl" - --without-ssl --without-zlib --without-brotli --without-zstd --without-libpsl --without-nghttp2 --enable-debug --enable-websocketsx + - name: 'mbedtls-prev' + install_packages: libssh2-1-dev libnghttp2-dev libuv1-dev + install_steps: mbedtls-prev pytest + PKG_CONFIG_PATH: /home/runner/mbedtls-prev/lib/pkgconfig # Requires v3.6.0 + generate: -DCURL_USE_MBEDTLS=ON -DCURL_USE_LIBUV=ON -DENABLE_DEBUG=ON - - name: event-based - install_packages: libssh-dev valgrind - configure: --enable-debug --disable-shared --disable-threaded-resolver --with-libssh --with-openssl - tflags: -n -e '!TLS-SRP' + - name: 'mbedtls-pkg MultiSSL !pc' + install_packages: libnghttp2-dev libmbedtls-dev + install_steps: mbedtls-latest-intel skipall + generate: >- + -DCURL_USE_MBEDTLS=ON -DENABLE_DEBUG=ON -DCURL_DEFAULT_SSL_BACKEND=mbedtls + -DMBEDTLS_INCLUDE_DIR=/home/runner/mbedtls/include + -DMBEDTLS_LIBRARY=/home/runner/mbedtls/lib/libmbedtls.a + -DMBEDX509_LIBRARY=/home/runner/mbedtls/lib/libmbedx509.a + -DMBEDCRYPTO_LIBRARY=/home/runner/mbedtls/lib/libmbedcrypto.a + -DCURL_USE_PKGCONFIG=OFF -DCURL_USE_OPENSSL=ON + -DBUILD_LIBCURL_DOCS=OFF -DBUILD_MISC_DOCS=OFF -DENABLE_CURL_MANUAL=OFF + -DCURL_COMPLETION_FISH=ON -DCURL_COMPLETION_ZSH=ON - - name: hyper - install_steps: rust hyper valgrind - configure: LDFLAGS="-Wl,-rpath,$HOME/hyper/target/debug" --with-openssl --with-hyper=$HOME/hyper --enable-debug --enable-websockets + - name: 'rustls valgrind 1' + install_packages: libnghttp2-dev libldap-dev valgrind + install_steps: rust rustls + tflags: '--min=820 1 to 1000' + generate: -DCURL_USE_RUSTLS=ON -DUSE_ECH=ON -DENABLE_DEBUG=ON - - name: rustls - install_steps: rust rustls pytest valgrind - configure: --with-rustls=$HOME/rustls --enable-debug + - name: 'rustls valgrind 2' + install_packages: libnghttp2-dev libldap-dev valgrind + install_steps: rust rustls + tflags: '--min=830 1001 to 9999' + generate: -DCURL_USE_RUSTLS=ON -DUSE_ECH=ON -DENABLE_DEBUG=ON - - name: Intel compiler - without SSL - install_packages: zlib1g-dev valgrind - install_steps: intel - configure: CC=icc --enable-debug --without-ssl + - name: 'rustls' + install_packages: libnghttp2-dev libldap-dev + install_steps: rust rustls skiprun pytest + configure: --with-rustls --enable-ech --enable-debug - - name: Intel compiler - OpenSSL - install_packages: zlib1g-dev libssl-dev valgrind - install_steps: intel - configure: CC=icc --enable-debug --with-openssl + - name: 'wolfssl-all' + image: ubuntu-24.04-arm + install_steps: wolfssl-all-arm + LDFLAGS: -Wl,-rpath,/home/runner/wolfssl-all/lib + configure: --with-wolfssl=/home/runner/wolfssl-all --enable-ech --enable-debug - - name: Slackware-openssl-with-gssapi-gcc - # These are essentially the same flags used to build the curl Slackware package - # https://ftpmirror.infania.net/slackware/slackware64-current/source/n/curl/curl.SlackBuild - configure: --with-openssl --with-libssh2 --with-gssapi --enable-ares --enable-static=no --without-ca-bundle --with-ca-path=/etc/ssl/certs - # Docker Hub image that `container-job` executes in - container: 'andy5995/slackware-build-essential:15.0' + - name: 'wolfssl-opensslextra valgrind 1' + image: ubuntu-24.04-arm + install_packages: valgrind + install_steps: wolfssl-opensslextra-arm + tflags: '--min=815 1 to 1000' + LDFLAGS: -Wl,-rpath,/home/runner/wolfssl-opensslextra/lib + configure: --with-wolfssl=/home/runner/wolfssl-opensslextra --enable-ech --enable-debug - - name: Alpine MUSL - configure: --enable-debug --enable-websockets --with-ssl --with-libssh2 --with-libidn2 --with-gssapi --enable-ldap --with-libpsl - container: 'alpine:3.18' + - name: 'wolfssl-opensslextra valgrind 2' + image: ubuntu-24.04-arm + install_packages: valgrind + install_steps: wolfssl-opensslextra-arm + tflags: '--min=835 1001 to 9999' + LDFLAGS: -Wl,-rpath,/home/runner/wolfssl-opensslextra/lib + configure: --with-wolfssl=/home/runner/wolfssl-opensslextra --enable-ech --enable-debug + + - name: 'openssl default' + install_steps: pytest + configure: --with-openssl --enable-debug --disable-unity + + - name: 'openssl libssh2 sync-resolver valgrind 1 +analyzer' + image: ubuntu-26.04-arm + install_packages: gcc-16 libidn2-dev libssh2-1-dev libnghttp2-dev libldap-dev valgrind + CC: gcc-16 + tflags: '--min=965 1 to 1000' + generate: -DENABLE_DEBUG=ON -DENABLE_THREADED_RESOLVER=OFF -DCURL_GCC_ANALYZER=ON -DCURL_ENABLE_NTLM=ON + + - name: 'openssl libssh2 sync-resolver valgrind 2' + image: ubuntu-26.04-arm + install_packages: gcc-16 libidn2-dev libssh2-1-dev libnghttp2-dev libldap-dev valgrind + CC: gcc-16 + tflags: '--min=920 1001 to 9999' + generate: -DENABLE_DEBUG=ON -DENABLE_THREADED_RESOLVER=OFF -DCURL_ENABLE_NTLM=ON + + - name: 'openssl intel C89' + install_packages: libssh-dev + install_steps: pytest + configure: CFLAGS=-std=gnu89 --with-openssl --with-libssh --enable-debug + + - name: 'openssl arm C89' + image: ubuntu-24.04-arm + install_packages: libssh2-1-dev + install_steps: pytest + configure: CFLAGS=-std=gnu89 --with-openssl --with-libssh2 --enable-debug --disable-verbose + + - name: 'openssl -O3 libssh valgrind 1' + install_packages: libssh-dev valgrind + CFLAGS: -O3 + tflags: '--min=950 1 to 1000' + generate: -DENABLE_DEBUG=ON -DCURL_USE_LIBSSH=ON -DCMAKE_UNITY_BUILD_BATCH_SIZE=50 -DCURL_ENABLE_NTLM=ON + + - name: 'openssl -O3 libssh valgrind 2' + install_packages: libssh-dev valgrind + CFLAGS: -O3 + tflags: '--min=900 1001 to 9999' + generate: -DENABLE_DEBUG=ON -DCURL_USE_LIBSSH=ON -DCMAKE_UNITY_BUILD_BATCH_SIZE=50 -DCURL_ENABLE_NTLM=ON + + - name: 'openssl clang krb5 openldap static' + install_steps: openldap-static + install_packages: libidn2-dev libkrb5-dev clang libssl-dev + CC: clang + configure: >- + --enable-static --disable-shared --with-openssl --with-gssapi --enable-debug --disable-docs + --disable-manual --with-ldap=/home/runner/openldap-static --with-ldap-lib=ldap --with-lber-lib=lber + + - name: 'openssl clang krb5 LTO' + image: ubuntu-24.04-arm + install_packages: libssh2-1-dev libkrb5-dev clang + install_steps: skiprun pytest + CC: clang + generate: -DCURL_USE_OPENSSL=ON -DCURL_USE_GSSAPI=ON -DENABLE_DEBUG=ON -DCURL_LTO=ON + + - name: 'openssl !ipv6 !--libcurl !--digest-auth' + image: ubuntu-24.04-arm + configure: --with-openssl --disable-ipv6 --enable-debug --disable-unity --disable-libcurl-option --disable-digest-auth --enable-ntlm --enable-smb + + - name: 'curl_global_init_mem debug valgrind' + image: ubuntu-24.04-arm + install_packages: valgrind + tflags: '--min=1700' + configure: >- + --enable-init-mem-debug + --with-openssl --disable-debug --enable-unity + --enable-ntlm --enable-smb + + - name: 'openssl https-only' + image: ubuntu-24.04-arm + tflags: '--min=1260' + configure: >- + --with-openssl --enable-debug --disable-unity + --disable-dict --disable-gopher --disable-ldap --disable-telnet + --disable-imap --disable-pop3 --disable-smtp + --disable-rtsp + --without-libssh2 --without-libssh + --disable-tftp --disable-ftp --disable-file --disable-smb + --enable-ntlm + + - name: 'openssl torture 1' + install_packages: libnghttp2-dev libssh2-1-dev libc-ares-dev + tflags: '-t --shallow=25 --min=960 1 to 1000' + torture: true + generate: -DCURL_USE_OPENSSL=ON -DENABLE_DEBUG=ON -DENABLE_ARES=ON -DCURL_ENABLE_NTLM=ON + + - name: 'openssl torture 2' + install_packages: libnghttp2-dev libssh2-1-dev libc-ares-dev + tflags: '-t --shallow=25 --min=915 1001 to 9999' + torture: true + generate: -DCURL_USE_OPENSSL=ON -DENABLE_DEBUG=ON -DENABLE_ARES=ON -DCURL_ENABLE_NTLM=ON + + - name: 'openssl i686' + install_packages: gcc-14-i686-linux-gnu libssl-dev:i386 libssh2-1-dev:i386 libidn2-dev:i386 libc-ares-dev:i386 zlib1g-dev:i386 + CC: i686-linux-gnu-gcc-14 + LDFLAGS: -L/usr/lib/i386-linux-gnu + PKG_CONFIG_PATH: /usr/lib/i386-linux-gnu/pkgconfig + configure: >- + CPPFLAGS=-I/usr/include/i386-linux-gnu + --host=i686-linux-gnu + --with-openssl --with-libssh2 --with-libidn2 --enable-ares --enable-debug + + - name: '!ssl !http !smtp !imap' + image: ubuntu-24.04-arm + tflags: '--min=500' + configure: --without-ssl --enable-debug --disable-http --disable-smtp --disable-imap --disable-unity + + - name: 'clang-tidy' + image: ubuntu-26.04 + install_packages: clang-22 clang-tidy-22 libssl-dev libidn2-dev libssh2-1-dev libnghttp2-dev libldap-dev libkrb5-dev libgnutls28-dev + install_steps: skiprun mbedtls-latest-intel rustls wolfssl-opensslextra-intel + install_steps_brew: openssl@4 gsasl + CC: clang-22 + CFLAGS: -Wunused-macros + LDFLAGS: >- + -Wl,-rpath,/home/runner/wolfssl-opensslextra/lib + -Wl,-rpath,/home/runner/mbedtls/lib + -Wl,-rpath,/home/runner/rustls/lib + -Wl,-rpath,/home/linuxbrew/.linuxbrew/opt/openssl@4/lib + -Wl,-rpath,/home/linuxbrew/.linuxbrew/opt/gsasl/lib + + PKG_CONFIG_PATH: "\ + /home/runner/wolfssl-opensslextra/lib/pkgconfig:\ + /home/runner/mbedtls/lib/pkgconfig:\ + /home/runner/rustls/lib/pkgconfig:\ + /home/linuxbrew/.linuxbrew/opt/gsasl/lib/pkgconfig" + generate: >- + -DCURL_USE_OPENSSL=ON -DOPENSSL_ROOT_DIR=/home/linuxbrew/.linuxbrew/opt/openssl@4 + -DCURL_USE_WOLFSSL=ON -DCURL_USE_GNUTLS=ON -DCURL_USE_MBEDTLS=ON -DCURL_USE_RUSTLS=ON + -DCURL_USE_GSASL=ON + -DUSE_ECH=ON -DCURL_USE_GSSAPI=ON -DUSE_SSLS_EXPORT=ON + -DCURL_CLANG_TIDY=ON -DCLANG_TIDY=/usr/bin/clang-tidy-22 + + - name: 'clang-tidy H3 c-ares !examples' + image: ubuntu-26.04 + install_packages: clang-22 clang-tidy-22 libidn2-dev libssh-dev libnghttp2-dev + install_steps: skiprun + install_steps_brew: libngtcp2 libnghttp3 c-ares + CC: clang-22 + CFLAGS: -Wunused-macros + LDFLAGS: >- + -Wl,-rpath,/home/linuxbrew/.linuxbrew/opt/openssl/lib + -Wl,-rpath,/home/linuxbrew/.linuxbrew/opt/libngtcp2/lib + -Wl,-rpath,/home/linuxbrew/.linuxbrew/opt/libnghttp3/lib + -Wl,-rpath,/home/linuxbrew/.linuxbrew/opt/c-ares/lib + + PKG_CONFIG_PATH: "\ + /home/linuxbrew/.linuxbrew/opt/libngtcp2/lib/pkgconfig:\ + /home/linuxbrew/.linuxbrew/opt/libnghttp3/lib/pkgconfig:\ + /home/linuxbrew/.linuxbrew/opt/c-ares/lib/pkgconfig" + generate: >- + -DCURL_USE_OPENSSL=ON -DOPENSSL_ROOT_DIR=/home/linuxbrew/.linuxbrew/opt/openssl -DUSE_NGTCP2=ON + -DCURL_USE_LIBSSH2=OFF -DCURL_USE_LIBSSH=ON -DUSE_HTTPSRR=ON -DENABLE_ARES=ON -DUSE_PROXY_HTTP3=ON + -DCURL_DISABLE_VERBOSE_STRINGS=ON + -DCURL_CLANG_TIDY=ON -DCLANG_TIDY=/usr/bin/clang-tidy-22 + + - name: 'address-sanitizer' + image: ubuntu-26.04 + install_packages: clang-22 libssh-dev libidn2-dev libnghttp2-dev libubsan1 libasan8 libtsan2 + install_steps: pytest randcurl + install_steps_brew: openssl@4 + CC: clang-22 + CFLAGS: >- + -fsanitize=address,bounds,leak,signed-integer-overflow,undefined + -fno-sanitize-recover=address,bounds,leak,signed-integer-overflow,undefined + -fPIC + + LDFLAGS: >- + -fsanitize=address,bounds,leak,signed-integer-overflow,undefined + -fno-sanitize-recover=address,bounds,leak,signed-integer-overflow,undefined -ldl -lubsan + + generate: -DENABLE_DEBUG=ON -DCURL_USE_OPENSSL=ON -DOPENSSL_ROOT_DIR=/home/linuxbrew/.linuxbrew/opt/openssl@4 -DUSE_ECH=ON -DCURL_USE_LIBSSH=ON + + - name: 'address-sanitizer H3 c-ares' + image: ubuntu-26.04 + install_packages: clang-22 libubsan1 libasan8 libtsan2 + install_steps: pytest + install_steps_brew: openssl libssh2 libngtcp2 libnghttp3 c-ares + CC: clang-22 + CFLAGS: >- + -fsanitize=address,bounds,leak,signed-integer-overflow,undefined + -fno-sanitize-recover=address,bounds,leak,signed-integer-overflow,undefined + + LDFLAGS: >- + -fsanitize=address,bounds,leak,signed-integer-overflow,undefined + -fno-sanitize-recover=address,bounds,leak,signed-integer-overflow,undefined -ldl -lubsan + -Wl,-rpath,/home/linuxbrew/.linuxbrew/opt/c-ares/lib + + PKG_CONFIG_PATH: "\ + /home/linuxbrew/.linuxbrew/opt/libssh2/lib/pkgconfig:\ + /home/linuxbrew/.linuxbrew/opt/libngtcp2/lib/pkgconfig:\ + /home/linuxbrew/.linuxbrew/opt/libnghttp3/lib/pkgconfig:\ + /home/linuxbrew/.linuxbrew/opt/c-ares/lib/pkgconfig" + generate: >- + -DENABLE_DEBUG=ON -DCURL_USE_OPENSSL=ON -DOPENSSL_ROOT_DIR=/home/linuxbrew/.linuxbrew/opt/openssl -DUSE_NGTCP2=ON + -DUSE_SSLS_EXPORT=ON -DENABLE_ARES=ON -DUSE_PROXY_HTTP3=ON + + - name: 'thread-sanitizer' + image: ubuntu-26.04 + install_packages: clang-22 libtsan2 + install_steps: pytest openssl-tsan + CC: clang-22 + CFLAGS: -fsanitize=thread -g + LDFLAGS: -fsanitize=thread + generate: -DOPENSSL_ROOT_DIR=/home/runner/openssl -DUSE_ECH=ON -DENABLE_DEBUG=ON + + - name: 'memory-sanitizer' + image: ubuntu-26.04 + install_packages: clang-22 + install_steps: randcurl + CC: clang-22 + CFLAGS: -fsanitize=memory -Wformat -Werror=format-security -Werror=array-bounds -g + LDFLAGS: -fsanitize=memory + LIBS: -ldl + configure: --without-ssl --without-zlib --without-brotli --without-zstd --without-libpsl --without-nghttp2 --enable-debug + tflags: '--min=1540' + + - name: 'event-based' + install_packages: libssh-dev + configure: --enable-debug --enable-static --disable-shared --disable-threaded-resolver --with-libssh --with-openssl --enable-ntlm --enable-smb + tflags: '-n --test-event --min=1420' + + - name: 'duphandle' + image: ubuntu-24.04-arm + install_packages: libssh-dev + configure: --enable-debug --enable-static --disable-shared --disable-threaded-resolver --with-libssh --with-openssl + tflags: '-n --test-duphandle' + + - name: 'IntelC openssl' + install_packages: libssl-dev + install_steps: intelc + CC: icc + configure: --enable-debug --with-openssl + + - name: 'Slackware !ssl gssapi gcc' + # Flags used to build the curl Slackware package, except OpenSSL 1.1.0: + # https://ftpmirror.infania.net/slackware/slackware64-current/source/n/curl/curl.SlackBuild + configure: --enable-debug --without-ssl --with-libssh2 --with-gssapi --enable-ares --without-ca-bundle --with-ca-path=/etc/ssl/certs + # Docker Hub image that `container-job` executes in + container: andy5995/slackware-build-essential:15.0@sha256:f4f2242999038a2c2deb4e5727187caaae92502a7daf8353068932621e1ec92f + + - name: 'Alpine MUSL https-rr' + configure: --enable-debug --with-ssl --with-libssh2 --with-libidn2 --with-gssapi --enable-ldap --with-libpsl --enable-httpsrr --enable-ares --enable-threaded-resolver + container: alpine:3.23@sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11 # 3.23.4 + + - name: 'Alpine MUSL https-rr c-ares' + configure: --enable-debug --with-ssl --with-libssh2 --with-libidn2 --with-gssapi --enable-ldap --with-libpsl --enable-httpsrr --enable-ares --disable-threaded-resolver + container: alpine:3.20@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc # 3.20.10 steps: - - if: matrix.build.container == null - run: | - sudo apt-get update - sudo apt-get install libtool autoconf automake pkg-config stunnel4 libpsl-dev libbrotli-dev libzstd-dev ${{ matrix.build.install_packages }} - sudo python3 -m pip install impacket - name: 'install prereqs and impacket' + - name: 'install prereqs' + if: ${{ matrix.build.container == null && !contains(matrix.build.name, 'i686') }} + timeout-minutes: 3 + env: + INSTALL_PACKAGES_BREW: '${{ matrix.build.install_steps_brew }}' + INSTALL_PACKAGES: >- + ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') && 'stunnel4' || '' }} + ${{ contains(matrix.build.install_steps, 'pytest') && 'apache2 apache2-dev libnghttp2-dev vsftpd dante-server' || '' }} - - if: startsWith(matrix.build.container, 'alpine') - run: | - apk add --no-cache build-base autoconf automake libtool perl openssl-dev libssh2-dev zlib-dev brotli-dev zstd-dev libidn2-dev openldap-dev heimdal-dev libpsl-dev py3-impacket py3-asn1 py3-six py3-pycryptodomex perl-time-hires openssh stunnel sudo - name: 'install dependencies' + run: | + ls -l /etc/apt/sources.list.d + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install \ + libtool autoconf automake pkgconf \ + libpsl-dev zlib1g-dev libbrotli-dev libzstd-dev \ + ${INSTALL_PACKAGES} \ + ${MATRIX_INSTALL_PACKAGES} + if [ -n "${INSTALL_PACKAGES_BREW}" ]; then + /home/linuxbrew/.linuxbrew/bin/brew install ${INSTALL_PACKAGES_BREW} + fi - - uses: actions/checkout@v3 + - name: 'install prereqs (i686)' + if: ${{ contains(matrix.build.name, 'i686') }} + timeout-minutes: 2 + run: | + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo dpkg --add-architecture i386 + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install \ + libtool autoconf automake pkgconf stunnel4 \ + libpsl-dev:i386 libbrotli-dev:i386 libzstd-dev:i386 \ + ${MATRIX_INSTALL_PACKAGES} - - if: contains(matrix.build.install_steps, 'gcc-11') - run: | - sudo add-apt-repository ppa:ubuntu-toolchain-r/ppa - sudo apt-get update - sudo apt-get install gcc-11 - sudo update-alternatives --install /usr/bin/gcc gcc /usr/bin/gcc-11 100 - sudo update-alternatives --set gcc /usr/bin/gcc-11 - gcc --version - name: 'install gcc-11' + - name: 'install prereqs (alpine)' + if: ${{ startsWith(matrix.build.container, 'alpine') }} + run: | + apk add --no-cache build-base autoconf automake libtool perl openssl-dev \ + libssh2-dev zlib-dev brotli-dev zstd-dev libidn2-dev openldap-dev \ + krb5-dev libpsl-dev c-ares-dev \ + py3-impacket py3-asn1 py3-six py3-pycryptodomex \ + perl-time-hires openssh stunnel sudo git openssl - - name: cache bearssl - if: contains(matrix.build.install_steps, 'bearssl') - uses: actions/cache@v3 - id: cache-bearssl - env: - cache-name: cache-bearssl - with: - path: /home/runner/bearssl - key: ${{ runner.os }}-build-${{ env.cache-name }}-bearssl-${{ env.bearssl-version }} + - name: 'install Fil-C' + if: ${{ contains(matrix.build.install_steps, 'filc') }} + run: | + cd /home/runner + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/pizlonator/fil-c/releases/download/v${FIL_C_VERSION}/filc-${FIL_C_VERSION}-linux-x86_64.tar.xz" --output pkg.bin + sha256sum pkg.bin && tar -xJf pkg.bin && rm -f pkg.bin && mv "filc-${FIL_C_VERSION}-linux-x86_64" filc + cd filc + ./setup.sh - - name: 'build bearssl' - if: contains(matrix.build.install_steps, 'bearssl') && steps.cache-bearssl.outputs.cache-hit != 'true' - run: | - curl -LOsSf --retry 6 --retry-connrefused --max-time 999 https://bearssl.org/bearssl-${{ env.bearssl-version }}.tar.gz - tar -xzf bearssl-${{ env.bearssl-version }}.tar.gz - cd bearssl-${{ env.bearssl-version }} - make - mkdir -p $HOME/bearssl/lib $HOME/bearssl/include - cp inc/*.h $HOME/bearssl/include - cp build/libbearssl.* $HOME/bearssl/lib + - name: 'cache libressl (c-arm)' + if: ${{ contains(matrix.build.install_steps, 'libressl-c-arm') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-libressl-c-arm + env: + cache-name: cache-libressl-c-arm + with: + path: ~/libressl + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.LIBRESSL_VERSION }} - - name: cache libressl - if: contains(matrix.build.install_steps, 'libressl') - uses: actions/cache@v3 - id: cache-libressl - env: - cache-name: cache-libressl - with: - path: /home/runner/libressl - key: ${{ runner.os }}-build-${{ env.cache-name }}-libressl-${{ env.libressl-version }} + - name: 'build libressl (c-arm)' + if: ${{ contains(matrix.build.install_steps, 'libressl-c-arm') && !steps.cache-libressl-c-arm.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + "https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-${LIBRESSL_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "libressl-${LIBRESSL_VERSION}" + cmake -B . -G Ninja -DLIBRESSL_APPS=OFF -DLIBRESSL_TESTS=OFF -DCMAKE_INSTALL_PREFIX=/home/runner/libressl -DCURL_ENABLE_NTLM=ON + cmake --build . + cmake --install . - - name: 'build libressl' - if: contains(matrix.build.install_steps, 'libressl') && steps.cache-libressl.outputs.cache-hit != 'true' - run: | - git clone --quiet --depth=1 -b ${{ env.libressl-version }} https://github.com/libressl-portable/portable.git libressl-git - cd libressl-git - ./autogen.sh - ./configure --prefix=$HOME/libressl - make install + - name: 'cache libressl (filc)' + if: ${{ contains(matrix.build.install_steps, 'libressl-filc') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-libressl-filc + env: + cache-name: cache-libressl-filc + with: + path: ~/libressl + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.LIBRESSL_VERSION }}-${{ env.FIL_C_VERSION }} - - name: cache mbedtls - if: contains(matrix.build.install_steps, 'mbedtls') - uses: actions/cache@v3 - id: cache-mbedtls - env: - cache-name: cache-mbedtls - with: - path: /home/runner/mbedtls - key: ${{ runner.os }}-build-${{ env.cache-name }}-mbedtls-${{ env.mbedtls-version }} + - name: 'build libressl (filc)' + if: ${{ contains(matrix.build.install_steps, 'libressl-filc') && !steps.cache-libressl-filc.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + "https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-${LIBRESSL_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "libressl-${LIBRESSL_VERSION}" + cmake -B . -G Ninja -DLIBRESSL_APPS=OFF -DLIBRESSL_TESTS=OFF -DCMAKE_INSTALL_PREFIX=/home/runner/libressl \ + -DCMAKE_C_COMPILER=/home/runner/filc/build/bin/filcc -DENABLE_ASM=OFF + cmake --build . + cmake --install . - - name: 'build mbedtls' - if: contains(matrix.build.install_steps, 'mbedtls') && steps.cache-mbedtls.outputs.cache-hit != 'true' - run: | - git clone --quiet --depth=1 -b ${{ env.mbedtls-version }} https://github.com/ARMmbed/mbedtls - cd mbedtls - make DESTDIR=$HOME/mbedtls install + - name: 'cache nghttp2 (filc)' + if: ${{ contains(matrix.build.install_steps, 'nghttp2-filc') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-nghttp2-filc + env: + cache-name: cache-nghttp2-filc + with: + path: ~/nghttp2 + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.NGHTTP2_VERSION }}-${{ env.FIL_C_VERSION }} - - name: cache openssl3 - if: contains(matrix.build.install_steps, 'openssl3') - uses: actions/cache@v3 - id: cache-openssl3 - env: - cache-name: cache-openssl3 - with: - path: /home/runner/openssl3 - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.openssl3-version }} + - name: 'build nghttp2 (filc)' + if: ${{ contains(matrix.build.install_steps, 'nghttp2-filc') && !steps.cache-nghttp2-filc.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/nghttp2/nghttp2/releases/download/v${NGHTTP2_VERSION}/nghttp2-${NGHTTP2_VERSION}.tar.xz" --output pkg.bin + sha256sum pkg.bin && tar -xJf pkg.bin && rm -f pkg.bin + cd "nghttp2-${NGHTTP2_VERSION}" + cmake -B . -G Ninja -DENABLE_LIB_ONLY=ON -DBUILD_TESTING=OFF -DENABLE_DOC=OFF -DCMAKE_INSTALL_PREFIX=/home/runner/nghttp2 \ + -DBUILD_STATIC_LIBS=ON -DBUILD_SHARED_LIBS=OFF \ + -DCMAKE_C_COMPILER=/home/runner/filc/build/bin/filcc + cmake --build . + cmake --install . - - name: 'install openssl3' - if: contains(matrix.build.install_steps, 'openssl3') && steps.cache-openssl3.outputs.cache-hit != 'true' - run: | - git clone --quiet --depth=1 -b ${{ env.openssl3-version }} https://github.com/openssl/openssl - cd openssl - ./config enable-tls1_3 --prefix=$HOME/openssl3 - make -j1 install_sw + - name: 'cache wolfssl (all-arm)' + if: ${{ contains(matrix.build.install_steps, 'wolfssl-all-arm') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-wolfssl-all-arm + env: + cache-name: cache-wolfssl-all-arm + with: + path: ~/wolfssl-all + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.WOLFSSL_VERSION }} - - name: cache quictls - if: contains(matrix.build.install_steps, 'quictls') - uses: actions/cache@v3 - id: cache-quictls - env: - cache-name: cache-quictls - with: - path: /home/runner/quictls - key: ${{ runner.os }}-build-${{ env.cache-name }}-quictls-${{ env.quictls-version }} + - name: 'build wolfssl (all-arm)' # does not support `OPENSSL_COEXIST` + if: ${{ contains(matrix.build.install_steps, 'wolfssl-all-arm') && !steps.cache-wolfssl-all-arm.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/wolfSSL/wolfssl/archive/v${WOLFSSL_VERSION}-stable.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "wolfssl-${WOLFSSL_VERSION}-stable" + ./autogen.sh + ./configure --disable-dependency-tracking --prefix=/home/runner/wolfssl-all \ + --enable-tls13 --enable-harden --enable-all \ + --disable-benchmark --disable-crypttests --disable-examples + make install - - name: 'build quictls' - if: contains(matrix.build.install_steps, 'quictls') && steps.cache-quictls.outputs.cache-hit != 'true' - run: | - git clone --quiet --depth=1 -b ${{ env.quictls-version }} https://github.com/quictls/openssl - cd openssl - ./config enable-tls1_3 --prefix=$HOME/quictls - make -j1 install_sw + - name: 'cache wolfssl (opensslextra-intel)' # does support `OPENSSL_COEXIST` + if: ${{ contains(matrix.build.install_steps, 'wolfssl-opensslextra-intel') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-wolfssl-opensslextra-intel + env: + cache-name: cache-wolfssl-opensslextra-intel + with: + path: ~/wolfssl-opensslextra + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.WOLFSSL_VERSION }} - - name: cache msh3 - if: contains(matrix.build.install_steps, 'msh3') - uses: actions/cache@v3 - id: cache-msh3 - env: - cache-name: cache-msh3 - with: - path: /home/runner/msh3 - key: ${{ runner.os }}-build-${{ env.cache-name }}-msh3-${{ env.msh3-version }} + - name: 'build wolfssl (opensslextra-intel)' + if: ${{ contains(matrix.build.install_steps, 'wolfssl-opensslextra-intel') && !steps.cache-wolfssl-opensslextra-intel.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/wolfSSL/wolfssl/archive/v${WOLFSSL_VERSION}-stable.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "wolfssl-${WOLFSSL_VERSION}-stable" + ./autogen.sh + ./configure --disable-dependency-tracking --prefix=/home/runner/wolfssl-opensslextra \ + --enable-tls13 --enable-harden --enable-ech --enable-ed25519 --enable-opensslextra \ + --disable-benchmark --disable-crypttests --disable-examples + make install - - name: 'build msh3' - if: contains(matrix.build.install_steps, 'msh3') && steps.cache-msh3.outputs.cache-hit != 'true' - run: | - git clone --quiet -b ${{ env.msh3-version }} --depth=1 --recursive https://github.com/nibanks/msh3 - cd msh3 && mkdir build && cd build - cmake -G 'Unix Makefiles' -DCMAKE_BUILD_TYPE=RelWithDebInfo -DCMAKE_INSTALL_PREFIX=$HOME/msh3 .. - cmake --build . - cmake --install . + - name: 'cache wolfssl (opensslextra-arm)' # does support `OPENSSL_COEXIST` + if: ${{ contains(matrix.build.install_steps, 'wolfssl-opensslextra-arm') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-wolfssl-opensslextra-arm + env: + cache-name: cache-wolfssl-opensslextra-arm + with: + path: ~/wolfssl-opensslextra + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.WOLFSSL_VERSION }} - - if: contains(matrix.build.install_steps, 'rust') - run: | - cd $HOME - curl -sSf --compressed https://sh.rustup.rs/ | sh -s -- -y - source $HOME/.cargo/env - rustup toolchain install nightly - name: 'install rust' + - name: 'build wolfssl (opensslextra-arm)' + if: ${{ contains(matrix.build.install_steps, 'wolfssl-opensslextra-arm') && !steps.cache-wolfssl-opensslextra-arm.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/wolfSSL/wolfssl/archive/v${WOLFSSL_VERSION}-stable.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "wolfssl-${WOLFSSL_VERSION}-stable" + ./autogen.sh + ./configure --disable-dependency-tracking --prefix=/home/runner/wolfssl-opensslextra \ + --enable-tls13 --enable-harden --enable-ech --enable-ed25519 --enable-opensslextra \ + --disable-benchmark --disable-crypttests --disable-examples + make install - - name: cache rustls - if: contains(matrix.build.install_steps, 'rustls') - uses: actions/cache@v3 - id: cache-rustls - env: - cache-name: cache-rustls - with: - path: /home/runner/rustls - key: ${{ runner.os }}-build-${{ env.cache-name }}-rustls-${{ env.rustls-version }} + - name: 'cache mbedtls (latest-intel)' + if: ${{ contains(matrix.build.install_steps, 'mbedtls-latest-intel') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-mbedtls-latest-intel + env: + cache-name: cache-mbedtls-latest-intel + with: + path: ~/mbedtls + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.MBEDTLS_VERSION }} - - name: 'build rustls' - if: contains(matrix.build.install_steps, 'rustls') && steps.cache-rustls.outputs.cache-hit != 'true' - run: | - git clone --quiet --depth=1 -b ${{ env.rustls-version }} --recursive https://github.com/rustls/rustls-ffi.git - cd rustls-ffi - make DESTDIR=$HOME/rustls install + - name: 'build mbedtls (latest-intel)' + if: ${{ contains(matrix.build.install_steps, 'mbedtls-latest-intel') && !steps.cache-mbedtls-latest-intel.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/Mbed-TLS/mbedtls/releases/download/mbedtls-${MBEDTLS_VERSION}/mbedtls-${MBEDTLS_VERSION}.tar.bz2" --output pkg.bin + sha256sum pkg.bin && tar -xjf pkg.bin && rm -f pkg.bin + cd "mbedtls-${MBEDTLS_VERSION}" + ./scripts/config.py set MBEDTLS_THREADING_C + ./scripts/config.py set MBEDTLS_THREADING_PTHREAD + cmake -B . -G Ninja -DCMAKE_BUILD_TYPE=RelWithDebInfo -DCMAKE_POSITION_INDEPENDENT_CODE=ON -DCMAKE_INSTALL_PREFIX=/home/runner/mbedtls \ + -DENABLE_PROGRAMS=OFF -DENABLE_TESTING=OFF + cmake --build . + cmake --install . - - if: contains(matrix.build.install_steps, 'hyper') - run: | - cd $HOME - git clone --quiet --depth=1 https://github.com/hyperium/hyper.git - cd $HOME/hyper - RUSTFLAGS="--cfg hyper_unstable_ffi" cargo +nightly rustc --features client,http1,http2,ffi -Z unstable-options --crate-type cdylib - echo "LD_LIBRARY_PATH=$HOME/hyper/target/debug:/usr/local/lib" >> $GITHUB_ENV - name: 'install hyper' + - name: 'cache mbedtls (latest-arm)' + if: ${{ contains(matrix.build.install_steps, 'mbedtls-latest-arm') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-mbedtls-latest-arm + env: + cache-name: cache-mbedtls-latest-arm + with: + path: ~/mbedtls + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.MBEDTLS_VERSION }} - - if: contains(matrix.build.install_steps, 'intel') - run: | - cd /tmp - curl -sSf --compressed https://apt.repos.intel.com/intel-gpg-keys/GPG-PUB-KEY-INTEL-SW-PRODUCTS.PUB | sudo apt-key add - - sudo add-apt-repository "deb https://apt.repos.intel.com/oneapi all main" - sudo apt install --no-install-recommends intel-oneapi-compiler-dpcpp-cpp-and-cpp-classic - source /opt/intel/oneapi/setvars.sh - printenv >> $GITHUB_ENV - name: 'install Intel compilers' + - name: 'build mbedtls (latest-arm)' + if: ${{ contains(matrix.build.install_steps, 'mbedtls-latest-arm') && !steps.cache-mbedtls-latest-arm.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/Mbed-TLS/mbedtls/releases/download/mbedtls-${MBEDTLS_VERSION}/mbedtls-${MBEDTLS_VERSION}.tar.bz2" --output pkg.bin + sha256sum pkg.bin && tar -xjf pkg.bin && rm -f pkg.bin + cd "mbedtls-${MBEDTLS_VERSION}" + ./scripts/config.py set MBEDTLS_THREADING_C + ./scripts/config.py set MBEDTLS_THREADING_PTHREAD + cmake -B . -G Ninja -DCMAKE_BUILD_TYPE=RelWithDebInfo -DCMAKE_POSITION_INDEPENDENT_CODE=ON -DCMAKE_INSTALL_PREFIX=/home/runner/mbedtls \ + -DENABLE_PROGRAMS=OFF -DENABLE_TESTING=OFF + cmake --build . + cmake --install . - - if: contains(matrix.build.install_steps, 'pytest') - run: | - sudo apt-get install apache2 apache2-dev libnghttp2-dev - sudo python3 -m pip install -r tests/http/requirements.txt - name: 'install pytest and apach2-dev' + - name: 'cache mbedtls (prev)' + if: ${{ contains(matrix.build.install_steps, 'mbedtls-prev') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-mbedtls-prev + env: + cache-name: cache-mbedtls-prev + with: + path: ~/mbedtls-prev + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.MBEDTLS_PREV_VERSION }} - - name: cache mod_h2 - if: contains(matrix.build.install_steps, 'pytest') - uses: actions/cache@v3 - id: cache-mod_h2 - env: - cache-name: cache-mod_h2 - with: - path: /home/runner/mod_h2 - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.mod_h2-version }} + - name: 'build mbedtls (prev)' + if: ${{ contains(matrix.build.install_steps, 'mbedtls-prev') && !steps.cache-mbedtls-prev.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/Mbed-TLS/mbedtls/releases/download/mbedtls-${MBEDTLS_PREV_VERSION}/mbedtls-${MBEDTLS_PREV_VERSION}.tar.bz2" --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF -- "${MBEDTLS_PREV_SHA256}" && tar -xjf pkg.bin && rm -f pkg.bin + cd "mbedtls-${MBEDTLS_PREV_VERSION}" + ./scripts/config.py set MBEDTLS_THREADING_C + ./scripts/config.py set MBEDTLS_THREADING_PTHREAD + cmake -B . -G Ninja -DCMAKE_BUILD_TYPE=RelWithDebInfo -DCMAKE_POSITION_INDEPENDENT_CODE=ON -DCMAKE_INSTALL_PREFIX=/home/runner/mbedtls-prev \ + -DENABLE_PROGRAMS=OFF -DENABLE_TESTING=OFF + cmake --build . + cmake --install . - - name: 'build mod_h2' - if: contains(matrix.build.install_steps, 'pytest') && steps.cache-mod_h2.outputs.cache-hit != 'true' - run: | - cd $HOME - git clone --quiet --depth=1 -b ${{ env.mod_h2-version }} https://github.com/icing/mod_h2 - cd mod_h2 - autoreconf -fi - ./configure - make + - name: 'cache openldap (static)' + if: ${{ contains(matrix.build.install_steps, 'openldap-static') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-openldap-static + env: + cache-name: cache-openldap-static + with: + path: ~/openldap-static + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.OPENLDAP_VERSION }} - - name: 'install mod_h2' - if: contains(matrix.build.install_steps, 'pytest') - run: | - cd $HOME/mod_h2 - sudo make install + - name: 'build openldap (static)' + if: ${{ contains(matrix.build.install_steps, 'openldap-static') && !steps.cache-openldap-static.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + "https://www.openldap.org/software/download/OpenLDAP/openldap-release/openldap-${OPENLDAP_VERSION}.tgz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "openldap-${OPENLDAP_VERSION}" + autoreconf -fi + ./configure --prefix=/home/runner/openldap-static --enable-static --disable-shared --disable-slapd + make install - - run: autoreconf -fi - name: 'autoreconf' + - name: 'cache openssl (thread sanitizer)' + if: ${{ contains(matrix.build.install_steps, 'openssl-tsan') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-openssl-tsan + env: + cache-name: cache-openssl-tsan + with: + path: ~/openssl + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.OPENSSL_VERSION }} - - run: ./configure --enable-warnings --enable-werror ${{ matrix.build.configure }} - name: 'configure' + - name: 'build openssl (thread sanitizer)' + if: ${{ contains(matrix.build.install_steps, 'openssl-tsan') && !steps.cache-openssl-tsan.outputs.cache-hit }} + run: | + git clone --quiet --depth 1 --branch "openssl-${OPENSSL_VERSION}" https://github.com/openssl/openssl + cd openssl + CC=clang CFLAGS='-fsanitize=thread' LDFLAGS='-fsanitize=thread' ./config --prefix=/home/runner/openssl --libdir=lib no-makedepend no-apps no-docs no-tests + make + make -j1 install_sw - - run: make V=1 - name: 'make' + - name: 'cache awslc' + if: ${{ contains(matrix.build.install_steps, 'awslc') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-awslc + env: + cache-name: cache-awslc + with: + path: ~/awslc + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.AWSLC_VERSION }} - - run: ./src/curl -V - name: 'check curl -V output' + - name: 'build awslc' + if: ${{ contains(matrix.build.install_steps, 'awslc') && !steps.cache-awslc.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/awslabs/aws-lc/archive/refs/tags/v${AWSLC_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "aws-lc-${AWSLC_VERSION}" + cmake -B . -G Ninja -DCMAKE_INSTALL_PREFIX=/home/runner/awslc -DBUILD_TOOL=OFF -DBUILD_TESTING=OFF + cmake --build . + cmake --install . - - run: make V=1 examples - name: 'make examples' + - name: 'cache boringssl' + if: ${{ contains(matrix.build.install_steps, 'boringssl') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-boringssl + env: + cache-name: cache-boringssl + with: + path: ~/boringssl + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.BORINGSSL_VERSION }} - - run: make V=1 -C tests - name: 'make tests' + - name: 'build boringssl' + if: ${{ contains(matrix.build.install_steps, 'boringssl') && !steps.cache-boringssl.outputs.cache-hit }} + run: | + mkdir boringssl-src + cd boringssl-src + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + "https://boringssl.googlesource.com/boringssl/+archive/${BORINGSSL_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cmake -B . -G Ninja -DCMAKE_INSTALL_PREFIX=/home/runner/boringssl -DBUILD_TESTING=OFF -DBUILD_SHARED_LIBS=ON + cmake --build . + cmake --install . - - run: make V=1 test-ci - name: 'run tests' - env: - TFLAGS: "${{ matrix.build.tflags }}" + - name: 'cache rustls' + if: ${{ contains(matrix.build.install_steps, 'rustls') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-rustls + env: + cache-name: cache-rustls + with: + path: ~/rustls + key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.RUSTLS_VERSION }} - - if: contains(matrix.build.install_steps, 'pytest') - # run for `tests` directory, so pytest does not pick up any other - # packages we might have built here - run: - pytest -v tests - name: 'run pytest' - env: - TFLAGS: "${{ matrix.build.tflags }}" - CURL_CI: github + - name: 'fetch rustls deb' + if: ${{ contains(matrix.build.install_steps, 'rustls') && !steps.cache-rustls.outputs.cache-hit }} + run: | + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --location --proto-redir =https "https://github.com/rustls/rustls-ffi/releases/download/v${RUSTLS_VERSION}/librustls_${RUSTLS_VERSION}_amd64.deb.zip" --output pkg.bin + sha256sum pkg.bin && unzip pkg.bin -d rustls && rm -f pkg.bin + + - name: 'build rustls' + # Note: we do not check cache-hit here. If the cache is hit, we need to dpkg install the deb. + if: ${{ contains(matrix.build.install_steps, 'rustls') }} + run: sudo dpkg -i ~/rustls/"librustls_${RUSTLS_VERSION}_amd64.deb" + + - name: 'install Intel compilers' + if: ${{ contains(matrix.build.install_steps, 'intelc') }} + timeout-minutes: 4 + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 6 --retry-connrefused \ + --compressed https://apt.repos.intel.com/intel-gpg-keys/GPG-PUB-KEY-INTEL-SW-PRODUCTS.PUB | \ + sudo tee /etc/apt/trusted.gpg.d/intel-sw.asc >/dev/null + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo add-apt-repository 'deb https://apt.repos.intel.com/oneapi all main' + sudo apt-get -o Dpkg::Use-Pty=0 install intel-oneapi-compiler-dpcpp-cpp-and-cpp-classic + source /opt/intel/oneapi/setvars.sh + printenv >> "$GITHUB_ENV" + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'autoreconf' + if: ${{ matrix.build.configure }} + run: autoreconf -fi + + - name: 'configure' + env: + CC: '${{ matrix.build.CC }}' + CFLAGS: '${{ matrix.build.CFLAGS }}' + LDFLAGS: '${{ matrix.build.LDFLAGS }}' + LIBS: '${{ matrix.build.LIBS }}' + MATRIX_CONFIGURE: '${{ matrix.build.configure }}' + MATRIX_GENERATE: '${{ matrix.build.generate }}' + MATRIX_PKG_CONFIG_PATH: '${{ matrix.build.PKG_CONFIG_PATH }}' + run: | + [[ "${MATRIX_INSTALL_STEPS}" = *'awslc'* ]] && sudo apt-get -o Dpkg::Use-Pty=0 purge libssl-dev + [ -n "${MATRIX_PKG_CONFIG_PATH}" ] && export PKG_CONFIG_PATH="${MATRIX_PKG_CONFIG_PATH}" + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake -B bld -G Ninja \ + -DCMAKE_INSTALL_PREFIX="$HOME"/curl-install \ + -DCMAKE_C_COMPILER_TARGET="$(uname -m)-unknown-linux-gnu" -DBUILD_STATIC_LIBS=ON \ + -DCMAKE_UNITY_BUILD=ON -DCURL_WERROR=ON \ + ${MATRIX_GENERATE} + else + mkdir bld && cd bld && \ + ../configure --prefix="$HOME"/curl-install --enable-unity --enable-warnings --enable-werror --disable-static \ + --disable-dependency-tracking --enable-option-checking=fatal \ + ${MATRIX_CONFIGURE} + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMakeConfigureLog.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'test configs' + run: grep -H -v '^#' bld/tests/config bld/tests/http/config.ini || true + + - name: 'build' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose + else + make -C bld V=1 + fi + + - name: 'single-use function check' + if: ${{ (contains(matrix.build.configure, '--disable-unity') || contains(matrix.build.generate, '-DCMAKE_UNITY_BUILD=OFF')) && !contains(matrix.build.install_steps, 'filc') }} + run: | + git config --global --add safe.directory "*" + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + libcurla=bld/lib/libcurl.a + else + libcurla=bld/lib/.libs/libcurl.a + fi + ./scripts/singleuse.pl --unit "${libcurla}" + + - name: 'curl -V' + run: | + find . -type f \( -name curl -o -name '*.so.*' -o -name '*.a' \) -print0 | xargs -0 file -- + find . -type f \( -name curl -o -name '*.so.*' -o -name '*.a' \) -print0 | xargs -0 stat -c '%10s bytes: %n' -- + bld/src/curl --disable -V + + - name: 'curl install' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --install bld --strip + else + make -C bld V=1 install + fi + + - name: 'build tests' + if: ${{ !contains(matrix.build.install_steps, 'skipall') }} + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target testdeps + else + make -C bld V=1 -C tests + fi + + - name: 'install test prereqs' + if: ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') && matrix.build.container == null }} + run: | + python3 -m venv ~/venv + if bld/src/curl --disable -V 2>/dev/null | grep smb; then + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r tests/requirements.txt + fi + + - name: 'run tests' + if: ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') }} + timeout-minutes: ${{ contains(matrix.build.install_packages, 'valgrind') && 20 || 10 }} + env: + TEST_TARGET: ${{ matrix.build.torture && 'test-torture' || 'test-ci' }} + TFLAGS: '${{ matrix.build.tflags }}' + run: | + if [ "${TEST_TARGET}" = 'test-ci' ] && [[ "${MATRIX_INSTALL_PACKAGES}" = *'valgrind'* ]]; then + TFLAGS+=' -j6' + TFLAGS+=' !776' # skip long-running flaky test + if [[ "${MATRIX_INSTALL_PACKAGES}" = *'libgss-dev'* ]]; then + TFLAGS+=' ~2077 ~2078' # memory leaks from Curl_auth_decode_spnego_message() -> gss_init_sec_context() + fi + elif [ "${TEST_TARGET}" != 'test-ci' ]; then + TFLAGS+=' --buildinfo' # only test-ci sets this by default, set it manually for test-torture + fi + [ -f ~/venv/bin/activate ] && source ~/venv/bin/activate + if [[ "${MATRIX_INSTALL_STEPS}" = *'codeset-test1'* ]]; then + locale || true + export LC_ALL=C + export LC_CTYPE=C + export LC_NUMERIC=fr_FR.UTF-8 + fi + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target "${TEST_TARGET}" + else + make -C bld V=1 "${TEST_TARGET}" + fi + + - name: 'install pytest prereqs' + if: ${{ contains(matrix.build.install_steps, 'pytest') }} + run: | + [ -d ~/venv ] || python3 -m venv ~/venv + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r tests/http/requirements.txt + + - name: 'run pytest' + if: ${{ contains(matrix.build.install_steps, 'pytest') }} + env: + PYTEST_ADDOPTS: '--color=yes' + PYTEST_XDIST_AUTO_NUM_WORKERS: 4 + run: | + [ -f ~/venv/bin/activate ] && source ~/venv/bin/activate + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target curl-pytest-ci + else + make -C bld V=1 pytest-ci + fi + + - name: 'randcurl' + if: ${{ contains(matrix.build.install_steps, 'randcurl') }} + run: | + mkdir run + cd run + ../.github/scripts/randcurl.pl 60 ../bld/src/curl + + - name: 'build examples' + if: ${{ !contains(matrix.build.install_packages, 'valgrind') && !contains(matrix.build.name, '!examples') }} + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target curl-examples-build + else + make -C bld V=1 examples + fi diff --git a/third-party/curl/.github/workflows/linux32.yml b/third-party/curl/.github/workflows/linux32.yml deleted file mode 100644 index dae828f437..0000000000 --- a/third-party/curl/.github/workflows/linux32.yml +++ /dev/null @@ -1,93 +0,0 @@ -# Copyright (C) Dan Fandrich -# -# SPDX-License-Identifier: curl - -name: Linux 32-bit - -on: - push: - branches: - - master - - '*/ci' - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - pull_request: - branches: - - master - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} - cancel-in-progress: true - -permissions: {} - -env: - MAKEFLAGS: -j 3 - -jobs: - linux-i686: - name: ${{ matrix.build.name }} - runs-on: 'ubuntu-22.04' - timeout-minutes: 90 - strategy: - fail-fast: false - matrix: - build: - - name: Linux i686 - install_packages: gcc-11-i686-linux-gnu libssl-dev:i386 zlib1g-dev:i386 libpsl-dev:i386 libbrotli-dev:i386 libzstd-dev:i386 - configure: --enable-debug --enable-websockets --with-openssl --host=i686-linux-gnu CC=i686-linux-gnu-gcc-11 PKG_CONFIG_PATH=/usr/lib/i386-linux-gnu/pkgconfig CPPFLAGS=-I/usr/include/i386-linux-gnu LDFLAGS=-L/usr/lib/i386-linux-gnu - - steps: - - run: | - sudo dpkg --add-architecture i386 - sudo apt-get update -y - sudo apt-get install -y --no-install-suggests --no-install-recommends libtool autoconf automake pkg-config stunnel4 ${{ matrix.build.install_packages }} - sudo python3 -m pip install impacket - name: 'install prereqs' - - - uses: actions/checkout@v3 - - - run: autoreconf -fi - name: 'autoreconf' - - - run: ./configure --enable-warnings --enable-werror ${{ matrix.build.configure }} - name: 'configure' - - - run: make V=1 - name: 'make' - - - run: ./src/curl -V - name: 'check curl -V output' - - - run: make V=1 examples - name: 'make examples' - - - run: make V=1 -C tests - name: 'make tests' - - - run: make V=1 test-ci - name: 'run tests' - env: - TFLAGS: "${{ matrix.build.tflags }}" diff --git a/third-party/curl/.github/workflows/macos.yml b/third-party/curl/.github/workflows/macos.yml index 5539e48cc8..685a533c50 100644 --- a/third-party/curl/.github/workflows/macos.yml +++ b/third-party/curl/.github/workflows/macos.yml @@ -2,36 +2,28 @@ # # SPDX-License-Identifier: curl -name: macOS +name: 'macOS' -on: +'on': push: branches: - - master - - '*/ci' + - master + - '*/ci' paths-ignore: - - '**/*.md' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' pull_request: branches: - - master + - master paths-ignore: - - '**/*.md' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} @@ -39,201 +31,753 @@ concurrency: permissions: {} +# Apple APIs and the macos-version-min value required to avoid deprecation +# warnings with llvm/clang, and/or the feature getting enabled at build-time +# or runtime: +# +# - 10.7 Lion (2011) - GSS (build-time, deprecated MIT Kerberos shim) +# - 10.9 Mavericks (2013) - LDAP (build-time, deprecated), memset_s(), OCSP (runtime) +# - 10.11 El Capitan (2015) - connectx() (runtime) +# - 10.12 Sierra (2016) - clock_gettime() (build-time, runtime) +# - 10.14 Mojave (2018) - SecTrustEvaluateWithError() (runtime) + env: - DEVELOPER_DIR: /Applications/Xcode_14.0.1.app/Contents/Developer - MAKEFLAGS: -j 5 + CURL_CI: github + CURL_TEST_MIN: 1750 + DO_NOT_TRACK: '1' + MAKEFLAGS: -j 4 + LDFLAGS: -w # suppress 'object file was built for newer macOS version than being linked' warnings jobs: - autotools: - name: ${{ matrix.build.name }} - runs-on: 'macos-latest' - timeout-minutes: 90 + ios: + name: "iOS, ${{ (matrix.build.generator && format('CM-{0}', matrix.build.generator)) || (matrix.build.generate && 'CM' || 'AM' )}} ${{ matrix.build.name }} arm64" + runs-on: macos-latest + timeout-minutes: 10 + env: + DEVELOPER_DIR: "/Applications/Xcode${{ matrix.build.xcode && format('_{0}', matrix.build.xcode) || '' }}.app/Contents/Developer" + CC: 'clang' + LDFLAGS: '' + MATRIX_BUILD: ${{ matrix.build.generate && 'cmake' || 'autotools' }} + MATRIX_OPTIONS: ${{ matrix.build.options }} + # renovate: datasource=github-tags depName=libressl/portable versioning=semver registryUrl=https://github.com + LIBRESSL_VERSION: 4.3.1 strategy: fail-fast: false matrix: build: - - name: normal - install: nghttp2 - configure: --without-ssl --enable-websockets - macosx-version-min: 10.9 - - name: debug - install: nghttp2 - configure: --enable-debug --without-ssl --enable-websockets - macosx-version-min: 10.9 - - name: libssh2 - install: nghttp2 libssh2 - configure: --enable-debug --with-libssh2 --without-ssl --enable-websockets - macosx-version-min: 10.9 - - name: libssh-c-ares - install: openssl nghttp2 libssh - configure: --enable-debug --with-libssh --with-openssl=/usr/local/opt/openssl --enable-ares --enable-websockets - macosx-version-min: 10.9 - - name: libssh - install: openssl nghttp2 libssh - configure: --enable-debug --with-libssh --with-openssl=/usr/local/opt/openssl --enable-websockets - macosx-version-min: 10.9 - - name: c-ares - install: nghttp2 - configure: --enable-debug --enable-ares --without-ssl --enable-websockets - macosx-version-min: 10.9 - - name: HTTP only - install: nghttp2 - configure: | - --enable-debug \ - --enable-maintainer-mode \ - --disable-alt-svc \ - --disable-dict \ - --disable-file \ - --disable-ftp \ - --disable-gopher \ - --disable-imap \ - --disable-ldap \ - --disable-pop3 \ - --disable-rtmp \ - --disable-rtsp \ - --disable-scp \ - --disable-sftp \ - --disable-shared \ - --disable-smb \ - --disable-smtp \ - --disable-telnet \ - --disable-tftp \ - --disable-unix-sockets \ - --without-brotli \ - --without-gssapi \ - --without-libidn2 \ - --without-libpsl \ - --without-librtmp \ - --without-libssh2 \ - --without-nghttp2 \ - --without-ntlm-auth \ - --without-ssl \ - --without-zlib \ - --without-zstd - macosx-version-min: 10.15 - - name: SecureTransport http2 - install: nghttp2 - configure: --enable-debug --with-secure-transport --enable-websockets - macosx-version-min: 10.8 - - name: gcc SecureTransport - configure: CC=gcc-12 --enable-debug --with-secure-transport --enable-websockets - macosx-version-min: 10.8 - - name: OpenSSL http2 - install: nghttp2 openssl - configure: --enable-debug --with-openssl=/usr/local/opt/openssl --enable-websockets - macosx-version-min: 10.9 - - name: LibreSSL http2 - install: nghttp2 libressl - configure: --enable-debug --with-openssl=/usr/local/opt/libressl --enable-websockets - macosx-version-min: 10.9 - - name: torture - install: nghttp2 openssl - configure: --enable-debug --disable-shared --disable-threaded-resolver --with-openssl=/usr/local/opt/openssl --enable-websockets - tflags: -n -t --shallow=25 !FTP - macosx-version-min: 10.9 - - name: torture-ftp - install: nghttp2 openssl - configure: --enable-debug --disable-shared --disable-threaded-resolver --with-openssl=/usr/local/opt/openssl --enable-websockets - tflags: -n -t --shallow=20 FTP - macosx-version-min: 10.9 - - name: macOS 10.15 - install: nghttp2 libssh2 openssl - configure: --enable-debug --disable-ldap --with-openssl=/usr/local/opt/openssl --enable-websockets - macosx-version-min: 10.15 + - name: 'libressl' + install_steps: libressl + configure: --with-openssl=/Users/runner/libressl --without-libpsl + + - name: 'libressl' + install_steps: libressl + # FIXME: Could not make OPENSSL_ROOT_DIR work. CMake seems to prepend sysroot to it. + generator: Xcode + xcode: '' # default Xcode. Set it once to silence actionlint. + options: --config Debug + generate: >- + -DCMAKE_XCODE_ATTRIBUTE_CODE_SIGNING_ALLOWED=OFF + -DMACOSX_BUNDLE_GUI_IDENTIFIER=se.curl + -DOPENSSL_INCLUDE_DIR=/Users/runner/libressl/include + -DOPENSSL_SSL_LIBRARY=/Users/runner/libressl/lib/libssl.a + -DOPENSSL_CRYPTO_LIBRARY=/Users/runner/libressl/lib/libcrypto.a + -DCURL_USE_LIBPSL=OFF -DCURL_ENABLE_NTLM=ON + steps: - - run: echo libtool autoconf automake pkg-config ${{ matrix.build.install }} | xargs -Ix -n1 echo brew '"x"' > /tmp/Brewfile - name: 'brew bundle' + - name: 'brew install' + if: ${{ matrix.build.configure }} + timeout-minutes: 5 + run: | + # shellcheck disable=SC2181 + while [[ $? == 0 ]]; do + for i in 1 2 3; do + if brew install automake libtool; then + break 2 + else + echo "Error: wait to try again: $i" + sleep 10 + fi + done + false Too many retries + done - # Run this command with retries because of spurious failures seen - # while running the tests, for example - # https://github.com/curl/curl/runs/4095721123?check_suite_focus=true - - run: "while [[ $? == 0 ]]; do for i in 1 2 3; do brew update && brew bundle install --no-lock --file /tmp/Brewfile && break 2 || { echo Error: wait to try again; sleep 10; } done; false Too many retries; done" - name: 'brew install' + - name: 'toolchain versions' + run: | + command -v "${CC}"; "${CC}" --version || true + xcodebuild -version || true + xcodebuild -sdk -version | grep '^Path:' || true + xcrun --sdk iphoneos --show-sdk-path 2>/dev/null || true + xcrun --sdk iphoneos --show-sdk-version || true + echo '::group::compiler defaults'; echo 'int main(void) {}' | "${CC}" -v -x c -; echo '::endgroup::' + echo '::group::macros predefined'; "${CC}" -dM -E - < /dev/null | sort || true; echo '::endgroup::' + echo '::group::brew packages installed'; ls -l "$(brew --prefix)"/opt; echo '::endgroup::' - - run: | - case "${{ matrix.build.install }}" in - *openssl*) - ;; - *) - if test -d /usr/local/include/openssl; then - brew unlink openssl - fi;; - esac - name: 'brew unlink openssl' + - name: 'cache libressl' + if: ${{ contains(matrix.build.install_steps, 'libressl') }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-libressl + env: + cache-name: cache-libressl + with: + path: ~/libressl + key: iOS-${{ env.cache-name }}-${{ env.LIBRESSL_VERSION }} - - run: python3 -m pip install impacket - name: 'pip3 install' + - name: 'build libressl' + if: ${{ contains(matrix.build.install_steps, 'libressl') && !steps.cache-libressl.outputs.cache-hit }} + run: | + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/libressl/portable/releases/download/v${LIBRESSL_VERSION}/libressl-${LIBRESSL_VERSION}.tar.gz" --output pkg.bin + sha256sum pkg.bin && tar -xzf pkg.bin && rm -f pkg.bin + cd "libressl-${LIBRESSL_VERSION}" + cmake -B . -G Ninja \ + -DCMAKE_INSTALL_PREFIX=/Users/runner/libressl \ + -DCMAKE_SYSTEM_NAME=iOS \ + -DCMAKE_SYSTEM_PROCESSOR=aarch64 \ + -DBUILD_SHARED_LIBS=OFF \ + -DLIBRESSL_APPS=OFF \ + -DLIBRESSL_TESTS=OFF + cmake --build . + cmake --install . --verbose - - uses: actions/checkout@v3 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false - - run: autoreconf -fi - name: 'autoreconf' + - name: 'autoreconf' + if: ${{ matrix.build.configure }} + run: autoreconf -fi - - run: ./configure --enable-warnings --enable-werror ${{ matrix.build.configure }} - name: 'configure' - env: - CFLAGS: "-mmacosx-version-min=${{ matrix.build.macosx-version-min }}" + - name: 'configure' + env: + MATRIX_CONFIGURE: '${{ matrix.build.configure }}' + MATRIX_GENERATE: '${{ matrix.build.generate }}' + MATRIX_GENERATOR: '${{ matrix.build.generator }}' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + # https://cmake.org/cmake/help/latest/manual/cmake-toolchains.7.html#cross-compiling-for-ios-tvos-visionos-or-watchos + [ -n "${MATRIX_GENERATOR}" ] && options="-G ${MATRIX_GENERATOR}" + cmake -B bld -G Ninja -D_CURL_PREFILL=ON \ + -DCMAKE_UNITY_BUILD=ON -DCURL_DROP_UNUSED=ON -DCURL_WERROR=ON \ + -DCMAKE_SYSTEM_NAME=iOS \ + -DUSE_APPLE_IDN=ON \ + ${MATRIX_GENERATE} ${options} + else + mkdir bld && cd bld && ../configure --enable-unity --enable-warnings --enable-werror \ + --disable-dependency-tracking --enable-option-checking=fatal \ + CFLAGS="-isysroot $(xcrun --sdk iphoneos --show-sdk-path 2>/dev/null)" \ + --host=aarch64-apple-darwin \ + --with-apple-idn \ + ${MATRIX_CONFIGURE} + fi - - run: make V=1 - name: 'make' + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMakeConfigureLog.yaml 2>/dev/null || true - - run: make V=1 examples - name: 'make examples' + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true - - run: make V=1 -C tests - name: 'make tests' + - name: 'build' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld ${MATRIX_OPTIONS} --parallel 4 --verbose + else + make -C bld V=1 + fi - - run: make V=1 test-ci - name: 'run tests' - env: - TFLAGS: "${{ matrix.build.tflags }} ~1452" + - name: 'curl info' + run: | + find . -type f \( -name curl -o -name '*.dylib' -o -name '*.a' \) -print0 | xargs -0 file -- + find . -type f \( -name curl -o -name '*.dylib' -o -name '*.a' \) -print0 | xargs -0 stat -f '%10z bytes: %N' -- - cmake: - name: cmake ${{ matrix.compiler.CC }} ${{ matrix.build.name }} - runs-on: 'macos-latest' - env: ${{ matrix.compiler }} + - name: 'build tests' + if: ${{ matrix.build.generate }} # skip for autotools to save time + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld ${MATRIX_OPTIONS} --parallel 4 --target testdeps --verbose + else + make -C bld V=1 -C tests + fi + + - name: 'build examples' + if: ${{ matrix.build.generate }} # skip for autotools to save time + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld ${MATRIX_OPTIONS} --parallel 4 --target curl-examples-build --verbose + else + make -C bld examples V=1 + fi + + macos: + name: "${{ matrix.build.generate && 'CM' || 'AM' }} ${{ matrix.build.compiler }} ${{ matrix.build.name }}" + runs-on: ${{ matrix.build.image || 'macos-15' }} + timeout-minutes: 15 + env: + DEVELOPER_DIR: "/Applications/Xcode${{ matrix.build.xcode && format('_{0}', matrix.build.xcode) || '' }}.app/Contents/Developer" + CC: '${{ matrix.build.compiler }}' + MATRIX_BUILD: ${{ matrix.build.generate && 'cmake' || 'autotools' }} + MATRIX_COMPILER: '${{ matrix.build.compiler }}' + MATRIX_INSTALL: '${{ matrix.build.install }}' + MATRIX_INSTALL_STEPS: '${{ matrix.build.install_steps }}' + MATRIX_MACOS_VERSION_MIN: '${{ matrix.build.macos-version-min }}' strategy: fail-fast: false matrix: - compiler: - - CC: clang - CXX: clang++ - CFLAGS: "-mmacosx-version-min=10.15 -Wno-deprecated-declarations" - - CC: gcc-12 - CXX: g++-12 - CFLAGS: "-mmacosx-version-min=10.15 -Wno-error=undef -Wno-error=conversion" build: - - name: OpenSSL - install: nghttp2 openssl - generate: -DOPENSSL_ROOT_DIR=/usr/local/opt/openssl -DCURL_DISABLE_LDAP=ON -DCURL_DISABLE_LDAPS=ON - - name: LibreSSL - install: nghttp2 libressl - generate: -DOPENSSL_ROOT_DIR=/usr/local/opt/libressl -DCURL_DISABLE_LDAP=ON -DCURL_DISABLE_LDAPS=ON -DCMAKE_UNITY_BUILD=ON - - name: libssh2 - install: nghttp2 openssl libssh2 - generate: -DOPENSSL_ROOT_DIR=/usr/local/opt/openssl -DCURL_USE_LIBSSH2=ON -DBUILD_SHARED_LIBS=ON -DBUILD_STATIC_LIBS=ON + - name: '!ssl !debug brotli zstd' + compiler: gcc-13 + configure: --without-ssl --with-brotli --with-zstd --with-apple-idn + tflags: '--min=1520' + xcode: '' # default Xcode. Set it once to silence actionlint. + + - name: '!ssl libssh2 AppleIDN' + compiler: clang + generate: -DENABLE_DEBUG=ON -DCURL_USE_LIBSSH2=ON -DUSE_APPLE_IDN=ON -DCURL_ENABLE_SSL=OFF -DCURL_BROTLI=OFF -DCURL_ZSTD=OFF + tflags: '--min=1630' + + - name: 'OpenSSL libssh c-ares' + compiler: clang + install: openssl@4 libssh + configure: --enable-debug --with-libssh --with-openssl=/opt/homebrew/opt/openssl@4 --enable-ech --enable-ares --with-fish-functions-dir --with-zsh-functions-dir + + - name: 'OpenSSL libssh' + compiler: llvm@18 + install: libssh + generate: -DENABLE_DEBUG=ON -DCURL_USE_LIBSSH2=OFF -DCURL_USE_LIBSSH=ON -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/openssl -DCURL_BROTLI=OFF -DCURL_ZSTD=OFF + + - name: '!ssl HTTP-only c-ares' + macos-version-min: '10.15' # Catalina (2019) + compiler: clang + tflags: '--min=960' + generate: >- + -DENABLE_DEBUG=ON -DENABLE_ARES=ON + -DCURL_ENABLE_SSL=OFF -DHTTP_ONLY=ON + -DCURL_DISABLE_ALTSVC=ON -DENABLE_UNIX_SOCKETS=OFF + -DCURL_USE_LIBSSH2=OFF -DCURL_USE_LIBSSH=OFF -DUSE_NGHTTP2=OFF + -DCURL_USE_GSSAPI=OFF -DUSE_LIBIDN2=OFF -DCURL_USE_LIBPSL=OFF + -DCURL_BROTLI=OFF -DCURL_ZLIB=OFF -DCURL_ZSTD=OFF + -DBUILD_STATIC_LIBS=ON -DBUILD_SHARED_LIBS=OFF + + - name: 'LibreSSL !ldap +examples' + compiler: clang + install: libressl + install_steps: pytest + generate: >- + -DENABLE_DEBUG=ON -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/libressl -DCURL_DISABLE_LDAP=ON -DCURL_BROTLI=OFF -DCURL_ZSTD=OFF + -DCURL_USE_LIBSSH2=OFF -DCURL_ENABLE_NTLM=ON + + - name: 'OpenSSL 10.15 C89' + macos-version-min: '10.15' + compiler: clang + install: libnghttp3 libngtcp2 + install_steps: pytest + generate: >- + -DENABLE_DEBUG=ON -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/openssl -DUSE_NGTCP2=ON -DCURL_BROTLI=OFF -DCURL_ZSTD=OFF -DCURL_USE_LIBSSH2=OFF + -DCMAKE_C_STANDARD=90 -DCURL_ENABLE_NTLM=ON -DUSE_PROXY_HTTP3=ON + + - name: 'OpenSSL SecTrust krb5' + compiler: clang + install: libnghttp3 libngtcp2 + install_steps: pytest + configure: --enable-debug --with-openssl=/opt/homebrew/opt/openssl --with-ngtcp2 --with-apple-sectrust --enable-ntlm --enable-proxy-http3 --with-gssapi + + - name: 'OpenSSL event-based' + compiler: clang + generate: -DENABLE_DEBUG=ON -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/openssl -DCURL_BROTLI=OFF -DCURL_ZSTD=OFF -DCURL_USE_LIBSSH2=OFF -DCURL_ENABLE_NTLM=ON + tflags: '--test-event --min=1400' + + - name: 'OpenSSL gsasl AppleIDN SecTrust +examples' + compiler: clang + install: openssl@4 libnghttp3 libngtcp2 gsasl + generate: >- + -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/openssl@4 -DUSE_ECH=ON -DCURL_USE_GSASL=ON -DUSE_APPLE_IDN=ON -DUSE_NGTCP2=ON -DCURL_DISABLE_VERBOSE_STRINGS=ON + -DUSE_APPLE_SECTRUST=ON -DCURL_ENABLE_NTLM=ON -DUSE_PROXY_HTTP3=ON + + - name: 'MultiSSL AppleIDN clang-tidy +examples' + image: macos-26 + compiler: clang + install: llvm gnutls nettle libressl krb5 mbedtls gsasl rustls-ffi libssh fish + install_steps: skiprun + CFLAGS: -Wunused-macros + chkprefill: _chkprefill + generate: >- + -DCURL_USE_OPENSSL=ON -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/libressl -DCURL_DEFAULT_SSL_BACKEND=openssl + -DCURL_USE_GNUTLS=ON -DCURL_USE_MBEDTLS=ON -DCURL_USE_RUSTLS=ON -DENABLE_ARES=ON -DCURL_USE_GSASL=ON + -DCURL_USE_LIBSSH2=OFF -DCURL_USE_LIBSSH=ON -DUSE_APPLE_IDN=ON -DUSE_SSLS_EXPORT=ON + -DCURL_USE_GSSAPI=ON -DGSS_ROOT_DIR=/opt/homebrew/opt/krb5 + -DCURL_BROTLI=ON -DCURL_ZSTD=ON + -DCURL_CLANG_TIDY=ON -DCLANG_TIDY=/opt/homebrew/opt/llvm/bin/clang-tidy + -DCURL_COMPLETION_FISH=ON -DCURL_COMPLETION_ZSH=ON + -DCURL_ENABLE_NTLM=ON + + - name: 'HTTP/3 clang-tidy' + image: macos-26 + compiler: clang + install: llvm libnghttp3 libngtcp2 openldap krb5 + install_steps: skipall + CFLAGS: -Wunused-macros + generate: >- + -DCURL_USE_OPENSSL=ON -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/openssl -DUSE_NGTCP2=ON + -DLDAP_INCLUDE_DIR=/opt/homebrew/opt/openldap/include + -DLDAP_LIBRARY=/opt/homebrew/opt/openldap/lib/libldap.dylib + -DLDAP_LBER_LIBRARY=/opt/homebrew/opt/openldap/lib/liblber.dylib + -DCURL_USE_GSSAPI=ON -DGSS_ROOT_DIR=/opt/homebrew/opt/krb5 + -DCURL_BROTLI=ON -DCURL_ZSTD=ON + -DCURL_CLANG_TIDY=ON -DCLANG_TIDY=/opt/homebrew/opt/llvm/bin/clang-tidy + -DCURL_ENABLE_NTLM=ON -DUSE_PROXY_HTTP3=ON + + - name: 'LibreSSL openldap krb5 c-ares +examples' + compiler: clang + install: libressl krb5 openldap + generate: >- + -DENABLE_DEBUG=ON -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/libressl -DENABLE_ARES=ON -DCURL_USE_GSSAPI=ON + -DGSS_ROOT_DIR=/opt/homebrew/opt/krb5 + -DLDAP_INCLUDE_DIR=/opt/homebrew/opt/openldap/include + -DLDAP_LIBRARY=/opt/homebrew/opt/openldap/lib/libldap.dylib + -DLDAP_LBER_LIBRARY=/opt/homebrew/opt/openldap/lib/liblber.dylib + + - name: 'wolfSSL !ldap brotli zstd' + compiler: clang + install: brotli wolfssl zstd + install_steps: pytest + generate: -DCURL_USE_WOLFSSL=ON -DCURL_DISABLE_LDAP=ON -DUSE_ECH=ON -DCURL_ENABLE_NTLM=ON + + - name: 'mbedTLS !ldap brotli zstd MultiSSL AppleIDN' + compiler: llvm@18 + install: brotli mbedtls zstd + install_steps: codeset-test1 + generate: -DCURL_USE_MBEDTLS=ON -DCURL_DISABLE_LDAP=ON -DCURL_DEFAULT_SSL_BACKEND=mbedtls -DCURL_USE_OPENSSL=ON -DUSE_APPLE_IDN=ON -DCURL_ENABLE_NTLM=ON + + - name: 'GnuTLS !ldap krb5 +examples' + compiler: clang + install: gnutls nettle krb5 + install_steps: codeset-test2 + generate: >- + -DENABLE_DEBUG=ON -DCURL_USE_GNUTLS=ON -DCURL_USE_OPENSSL=OFF + -DCURL_USE_GSSAPI=ON -DGSS_ROOT_DIR=/opt/homebrew/opt/krb5 + -DCURL_DISABLE_LDAP=ON -DUSE_SSLS_EXPORT=ON + + - name: 'aws-lc +analyzer' + compiler: gcc-15 + install: aws-lc + generate: >- + -DENABLE_DEBUG=ON -DCURL_USE_OPENSSL=ON -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/aws-lc -DUSE_ECH=ON + -DCURL_DISABLE_LDAP=ON -DUSE_SSLS_EXPORT=ON -DCURL_GCC_ANALYZER=ON + + - name: 'Rustls' + compiler: clang + install: rustls-ffi + generate: -DENABLE_DEBUG=ON -DCURL_USE_RUSTLS=ON -DUSE_ECH=ON -DCURL_DISABLE_LDAP=ON -DCURL_ENABLE_NTLM=ON + tflags: '--min=1730' + + - name: 'OpenSSL torture 1' + compiler: clang + install: openssl@4 + install_steps: torture + generate: -DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DENABLE_THREADED_RESOLVER=OFF -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/openssl@4 -DUSE_ECH=ON -DCURL_ENABLE_NTLM=ON + tflags: '-t --shallow=25 --min=480 1 to 500' + + - name: 'OpenSSL torture 2' + compiler: clang + install: openssl@4 + install_steps: torture + generate: -DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DENABLE_THREADED_RESOLVER=OFF -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/openssl@4 -DUSE_ECH=ON -DCURL_ENABLE_NTLM=ON + tflags: '-t --shallow=25 --min=730 501 to 1250' + + - name: 'OpenSSL torture 3' + compiler: clang + install: openssl@4 + install_steps: torture + generate: -DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DENABLE_THREADED_RESOLVER=OFF -DOPENSSL_ROOT_DIR=/opt/homebrew/opt/openssl@4 -DUSE_ECH=ON -DCURL_ENABLE_NTLM=ON + tflags: '-t --shallow=25 --min=628 1251 to 9999' + steps: - - run: echo libtool autoconf automake pkg-config ${{ matrix.build.install }} | xargs -Ix -n1 echo brew '"x"' > /tmp/Brewfile - name: 'brew bundle' + - name: 'brew unlink openssl' + if: ${{ contains(matrix.build.install, 'aws-lc') || contains(matrix.build.install, 'libressl') || contains(matrix.build.install, 'openssl@4') }} + run: | + if [ -d "$(brew --prefix)"/include/openssl ]; then + brew unlink openssl + fi - - run: "while [[ $? == 0 ]]; do for i in 1 2 3; do brew update && brew bundle install --no-lock --file /tmp/Brewfile && break 2 || { echo Error: wait to try again; sleep 10; } done; false Too many retries; done" - name: 'brew install' + - name: 'brew install' + timeout-minutes: 5 + # Run this command with retries because of spurious failures seen + # while running the tests, for example + # https://github.com/curl/curl/runs/4095721123?check_suite_focus=true + env: + INSTALL_PACKAGES: >- + ${{ matrix.build.generate && 'ninja' || 'automake libtool' }} + ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') && 'nghttp2 stunnel' || '' }} + ${{ contains(matrix.build.install_steps, 'pytest') && 'caddy httpd vsftpd' || '' }} - - run: | - case "${{ matrix.build.install }}" in - *openssl*) - ;; - *) - if test -d /usr/local/include/openssl; then - brew unlink openssl - fi;; - esac - name: 'brew unlink openssl' + run: | + # shellcheck disable=SC2181 + while [[ $? == 0 ]]; do + for i in 1 2 3; do + if brew install pkgconf libpsl libssh2 ${INSTALL_PACKAGES} ${MATRIX_INSTALL}; then + break 2 + else + echo "Error: wait to try again: $i" + sleep 10 + fi + done + false Too many retries + done - - uses: actions/checkout@v3 + - name: 'toolchain versions' + run: | + [[ "${MATRIX_COMPILER}" = 'llvm'* ]] && CC="$(brew --prefix "${MATRIX_COMPILER}")/bin/clang" + [[ "${MATRIX_COMPILER}" = 'gcc'* ]] && "${CC}" --print-sysroot + command -v "${CC}"; "${CC}" --version || true + xcodebuild -version || true + xcrun --sdk macosx --show-sdk-path 2>/dev/null || true + xcrun --sdk macosx --show-sdk-version || true + ls -l /Library/Developer/CommandLineTools/SDKs || true + echo '::group::macros predefined'; "${CC}" -dM -E - < /dev/null | sort || true; echo '::endgroup::' + echo '::group::brew packages installed'; ls -l "$(brew --prefix)"/opt; echo '::endgroup::' - - run: cmake -S. -Bbuild -DCURL_WERROR=ON -DPICKY_COMPILER=ON ${{ matrix.build.generate }} - name: 'cmake generate' + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false - - run: cmake --build build - name: 'cmake build' + - name: 'autoreconf' + if: ${{ matrix.build.configure }} + run: autoreconf -fi + + - name: 'configure' + env: + CFLAGS: '${{ matrix.build.CFLAGS }}' + MATRIX_CHKPREFILL: '${{ matrix.build.chkprefill }}' + MATRIX_CONFIGURE: '${{ matrix.build.configure }}' + MATRIX_GENERATE: '${{ matrix.build.generate }}' + run: | + if [[ "${MATRIX_COMPILER}" = 'gcc'* ]]; then + sysroot="$("${CC}" --print-sysroot)" # Must match the SDK gcc was built for + else + sysroot="$(xcrun --sdk macosx --show-sdk-path 2>/dev/null)" + fi + + if [[ "${MATRIX_COMPILER}" = 'llvm'* ]]; then + CC="$(brew --prefix "${MATRIX_COMPILER}")/bin/clang" + CC+=" --sysroot=${sysroot}" + CC+=" --target=$(uname -m)-apple-darwin" + fi + + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + for _chkprefill in '' ${MATRIX_CHKPREFILL}; do + options='' + [ -n "${MATRIX_MACOS_VERSION_MIN}" ] && options+=" -DCMAKE_OSX_DEPLOYMENT_TARGET=${MATRIX_MACOS_VERSION_MIN}" + [[ "${MATRIX_INSTALL_STEPS}" = *'pytest'* ]] && options+=' -DVSFTPD=NO' # Skip ~20 tests that stretch run time by 7x on macOS + [ "${_chkprefill}" = '_chkprefill' ] && options+=' -D_CURL_PREFILL=OFF' + cmake -B "bld${_chkprefill}" -G Ninja -D_CURL_PREFILL=ON \ + -DCMAKE_INSTALL_PREFIX="$HOME"/curl-install \ + -DCMAKE_UNITY_BUILD=ON -DCURL_DROP_UNUSED=ON -DCURL_WERROR=ON \ + -DCMAKE_OSX_SYSROOT="${sysroot}" \ + -DCMAKE_C_COMPILER_TARGET="$(uname -m | sed 's/arm64/aarch64e/')-apple-darwin$(uname -r)" \ + ${MATRIX_GENERATE} ${options} + done + if [ -d bld_chkprefill ] && ! diff -u bld/lib/curl_config.h bld_chkprefill/lib/curl_config.h; then + echo '::group::reference configure log'; cat bld_chkprefill/CMakeFiles/CMake*.yaml 2>/dev/null || true; echo '::endgroup::' + false + fi + else + if [[ "${MATRIX_COMPILER}" = 'llvm'* ]]; then + options+=" --target=$(uname -m)-apple-darwin" + fi + if [ "${MATRIX_COMPILER}" != 'clang' ]; then + options+=" --with-sysroot=${sysroot}" + CFLAGS+=" --sysroot=${sysroot}" + fi + [ -n "${MATRIX_MACOS_VERSION_MIN}" ] && CFLAGS+=" -mmacosx-version-min=${MATRIX_MACOS_VERSION_MIN}" + [[ "${MATRIX_INSTALL_STEPS}" = *'pytest'* ]] && options+=' --with-test-vsftpd=no' # Skip ~20 tests that stretch run time by 7x on macOS + mkdir bld && cd bld && ../configure --prefix="$PWD"/curl-install --enable-unity --enable-warnings --enable-werror --disable-static \ + --disable-dependency-tracking --enable-option-checking=fatal \ + --with-libpsl="$(brew --prefix libpsl)" \ + ${MATRIX_CONFIGURE} ${options} + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMakeConfigureLog.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'test configs' + run: grep -H -v '^#' bld/tests/config bld/tests/http/config.ini || true + + - name: 'build' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose + else + make -C bld V=1 + fi + + - name: 'curl -V' + run: | + find . -type f \( -name curl -o -name '*.dylib' -o -name '*.a' \) -print0 | xargs -0 file -- + find . -type f \( -name curl -o -name '*.dylib' -o -name '*.a' \) -print0 | xargs -0 stat -f '%10z bytes: %N' -- + bld/src/curl --disable --version + + - name: 'curl install' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --install bld --strip + else + make -C bld V=1 install + fi + + - name: 'build tests' + if: ${{ !contains(matrix.build.install_steps, 'skipall') }} + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target testdeps + else + make -C bld V=1 -C tests + fi + + - name: 'install test prereqs' + if: ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') }} + run: | + python3 -m venv ~/venv + if bld/src/curl --disable -V 2>/dev/null | grep smb; then + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r tests/requirements.txt + fi + + - name: 'run tests' + if: ${{ !contains(matrix.build.install_steps, 'skipall') && !contains(matrix.build.install_steps, 'skiprun') }} + timeout-minutes: ${{ contains(matrix.build.install_steps, 'torture') && 20 || 10 }} + env: + TEST_TARGET: ${{ contains(matrix.build.install_steps, 'torture') && 'test-torture' || 'test-ci' }} + TFLAGS: '${{ matrix.build.tflags }}' + run: | + TFLAGS="-j20 ${TFLAGS}" + if [ "${TEST_TARGET}" != 'test-ci' ]; then + TFLAGS+=' --buildinfo' # only test-ci sets this by default, set it manually for test-torture + fi + source ~/venv/bin/activate + if [[ "${MATRIX_INSTALL_STEPS}" = *'codeset-test1'* ]]; then + locale || true + unset LANG + unset LC_ALL + unset LC_COLLATE + unset LC_MESSAGES + unset LC_MONETARY + unset LC_TIME + export LC_CTYPE=C + export LC_NUMERIC=fr_FR.UTF-8 + elif [[ "${MATRIX_INSTALL_STEPS}" = *'codeset-test2'* ]]; then + locale || true + unset LC_ALL + export LC_TIME=fr_FR + fi + rm -f ~/.curlrc + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target "${TEST_TARGET}" + else + make -C bld V=1 "${TEST_TARGET}" + fi + + - name: 'install pytest prereqs' + if: ${{ contains(matrix.build.install_steps, 'pytest') }} + run: | + [ -d ~/venv ] || python3 -m venv ~/venv + ~/venv/bin/pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r tests/http/requirements.txt + + - name: 'run pytest' + if: ${{ contains(matrix.build.install_steps, 'pytest') }} + env: + PYTEST_ADDOPTS: '--color=yes' + PYTEST_XDIST_AUTO_NUM_WORKERS: 4 + run: | + source ~/venv/bin/activate + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target curl-pytest-ci + else + make -C bld V=1 pytest-ci + fi + + - name: 'build examples' + if: ${{ contains(matrix.build.name, '+examples') }} + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target curl-examples-build + else + make -C bld examples V=1 + fi + + combinations: # Test buildability with host OS, Xcode / SDK, compiler, target-OS, built tool, combinations + name: "${{ matrix.build == 'cmake' && 'CM' || 'AM' }} ${{ matrix.compiler }} ${{ matrix.image }} ${{ matrix.xcode }}" + runs-on: ${{ matrix.image }} + timeout-minutes: 10 + env: + DEVELOPER_DIR: "/Applications/Xcode${{ matrix.xcode && format('_{0}', matrix.xcode) || '' }}.app/Contents/Developer" + CC: '${{ matrix.compiler }}' + MATRIX_BUILD: '${{ matrix.build }}' + MATRIX_COMPILER: '${{ matrix.compiler }}' + MATRIX_IMAGE: '${{ matrix.image }}' + MATRIX_MACOS_VERSION_MIN: '${{ matrix.macos-version-min }}' + strategy: + fail-fast: false + matrix: + # Sources: + # https://github.com/actions/runner-images/blob/main/images/macos/macos-14-arm64-Readme.md + # https://github.com/actions/runner-images/blob/main/images/macos/macos-15-arm64-Readme.md + # https://github.com/actions/runner-images/blob/main/images/macos/macos-26-arm64-Readme.md + compiler: [gcc-13, gcc-14, gcc-15, llvm@15, llvm@18, llvm@20, clang] + # Xcode support matrix as of 2025-10, with default macOS SDK versions and OS names, years: + # * = default Xcode on the runner. + # macos-14: 15.0.1, 15.1, 15.2, 15.3,*15.4 + # macos-15: 16.0, 16.1, 16.2, 16.3,*16.4, 26.0 + # macos-26: 16.4 *26.0 + # macOSSDK: 14.0, 14.2, 14.2, 14.4, 14.5, 15.0, 15.1, 15.2, 15.4, 15.5, 26.0 + # Sonoma (2023) Sequoia (2024) Tahoe (2025) + # https://github.com/actions/runner-images/tree/main/images/macos + # https://en.wikipedia.org/wiki/MacOS_version_history + image: [macos-14, macos-15, macos-26] + xcode: [''] # default Xcodes + macos-version-min: [''] + build: [autotools, cmake] + exclude: + # Combinations not covered by runner images: + - { image: macos-14, compiler: 'llvm@18' } + - { image: macos-14, compiler: 'llvm@20' } + - { image: macos-15, compiler: 'llvm@15' } + - { image: macos-15, compiler: 'llvm@20' } + - { image: macos-26, compiler: 'llvm@15' } + - { image: macos-26, compiler: 'llvm@18' } + # Covered by the main workflow + - { image: macos-15, compiler: 'gcc-13' } + - { image: macos-15, compiler: 'llvm@18' } + - { image: macos-15, compiler: 'clang' } + # Reduce build combinations, by dropping less interesting ones + - { image: macos-26, compiler: 'gcc-13' } + - { compiler: 'gcc-14' , build: cmake } + # Reduce autotools to only one job that is also build with cmake + - { compiler: 'gcc-13' , build: autotools } + - { compiler: 'gcc-14' , build: autotools } + - { compiler: 'gcc-15' , build: autotools } + - { compiler: 'llvm@15', build: autotools } + - { compiler: 'llvm@18', build: autotools } + - { compiler: 'llvm@20', build: autotools } + - { image: macos-14, build: autotools } + - { image: macos-15, build: autotools } + steps: + - name: 'install autotools' + if: ${{ matrix.build == 'autotools' }} + run: | + # shellcheck disable=SC2181 + while [[ $? == 0 ]]; do + for i in 1 2 3; do + if brew install automake libtool; then + break 2 + else + echo "Error: wait to try again: $i" + sleep 10 + fi + done + false Too many retries + done + + - name: 'toolchain versions' + run: | + [[ "${MATRIX_COMPILER}" = 'llvm'* ]] && CC="$(brew --prefix "${MATRIX_COMPILER}")/bin/clang" + [[ "${MATRIX_COMPILER}" = 'gcc'* ]] && "${CC}" --print-sysroot + command -v "${CC}"; "${CC}" --version || true + xcodebuild -version || true + xcrun --sdk macosx --show-sdk-path 2>/dev/null || true + xcrun --sdk macosx --show-sdk-version || true + ls -l /Library/Developer/CommandLineTools/SDKs || true + echo '::group::compiler defaults'; echo 'int main(void) {}' | "${CC}" -v -x c -; echo '::endgroup::' + echo '::group::macros predefined'; "${CC}" -dM -E - < /dev/null | sort || true; echo '::endgroup::' + echo '::group::brew packages preinstalled'; ls -l "$(brew --prefix)"/opt; echo '::endgroup::' + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'autoreconf' + if: ${{ matrix.build == 'autotools' }} + run: autoreconf -fi + + - name: 'configure / ${{ matrix.build }}' + run: | + if [ "${MATRIX_COMPILER}" = 'gcc-13' ] && [ "${MATRIX_IMAGE}" = 'macos-15' ]; then + # Ref: https://github.com/Homebrew/homebrew-core/issues/194778#issuecomment-2793243409 + "$(brew --prefix gcc@13)"/libexec/gcc/aarch64-apple-darwin24/13/install-tools/mkheaders + fi + + if [[ "${MATRIX_COMPILER}" = 'gcc'* ]]; then + sysroot="$("${CC}" --print-sysroot)" # Must match the SDK gcc was built for + else + sysroot="$(xcrun --sdk macosx --show-sdk-path 2>/dev/null)" + fi + + if [[ "${MATRIX_COMPILER}" = 'llvm'* ]]; then + CC="$(brew --prefix "${MATRIX_COMPILER}")/bin/clang" + CC+=" --sysroot=${sysroot}" + CC+=" --target=$(uname -m)-apple-darwin" + fi + + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + [ -n "${MATRIX_MACOS_VERSION_MIN}" ] && options+=" -DCMAKE_OSX_DEPLOYMENT_TARGET=${MATRIX_MACOS_VERSION_MIN}" + # would pick up nghttp2, libidn2, and libssh2 + cmake -B bld -G Ninja -D_CURL_PREFILL=ON \ + -DCMAKE_UNITY_BUILD=ON -DCURL_DROP_UNUSED=ON -DCURL_WERROR=ON \ + -DCMAKE_OSX_SYSROOT="${sysroot}" \ + -DCMAKE_C_COMPILER_TARGET="$(uname -m | sed 's/arm64/aarch64e/')-apple-darwin$(uname -r)" \ + -DCMAKE_IGNORE_PREFIX_PATH="$(brew --prefix)" \ + -DBUILD_LIBCURL_DOCS=OFF -DBUILD_MISC_DOCS=OFF -DENABLE_CURL_MANUAL=OFF \ + -DCURL_USE_OPENSSL=ON \ + -DUSE_NGHTTP2=OFF -DUSE_LIBIDN2=OFF \ + -DCURL_USE_LIBPSL=OFF -DCURL_USE_LIBSSH2=OFF \ + -DUSE_APPLE_IDN=ON -DUSE_APPLE_SECTRUST=ON \ + ${options} + else + export CFLAGS + if [[ "${MATRIX_COMPILER}" = 'llvm'* ]]; then + options+=" --target=$(uname -m)-apple-darwin" + fi + if [ "${MATRIX_COMPILER}" != 'clang' ]; then + options+=" --with-sysroot=${sysroot}" + CFLAGS+=" --sysroot=${sysroot}" + fi + [ -n "${MATRIX_MACOS_VERSION_MIN}" ] && CFLAGS+=" -mmacosx-version-min=${MATRIX_MACOS_VERSION_MIN}" + # would pick up nghttp2, libidn2, but libssh2 is disabled by default + mkdir bld && cd bld && ../configure --enable-unity --enable-warnings --enable-werror --disable-static \ + --disable-dependency-tracking --enable-option-checking=fatal \ + --disable-docs --disable-manual \ + --with-openssl="$(brew --prefix openssl)" \ + --without-nghttp2 --without-libidn2 \ + --without-libpsl \ + --with-apple-idn --with-apple-sectrust \ + ${options} + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMakeConfigureLog.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'build / ${{ matrix.build }}' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose + else + make -C bld V=1 + fi + + - name: 'curl -V' + run: | + find . -type f \( -name curl -o -name '*.dylib' -o -name '*.a' \) -print0 | xargs -0 file -- + find . -type f \( -name curl -o -name '*.dylib' -o -name '*.a' \) -print0 | xargs -0 stat -f '%10z bytes: %N' -- + bld/src/curl --disable --version diff --git a/third-party/curl/.github/workflows/ngtcp2-linux.yml b/third-party/curl/.github/workflows/ngtcp2-linux.yml deleted file mode 100644 index 338418cbb1..0000000000 --- a/third-party/curl/.github/workflows/ngtcp2-linux.yml +++ /dev/null @@ -1,279 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: ngtcp2-linux - -on: - push: - branches: - - master - - '*/ci' - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - pull_request: - branches: - - master - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - -concurrency: - # Hardcoded workflow filename as workflow name above is just Linux again - group: ngtcp2-${{ github.event.pull_request.number || github.sha }} - cancel-in-progress: true - -permissions: {} - -env: - MAKEFLAGS: -j 3 - quictls-version: 3.0.10+quic - gnutls-version: 3.8.0 - wolfssl-version: master - nghttp3-version: v0.15.0 - ngtcp2-version: v0.19.1 - nghttp2-version: v1.56.0 - mod_h2-version: v2.0.21 - -jobs: - autotools: - name: ${{ matrix.build.name }} - runs-on: 'ubuntu-latest' - timeout-minutes: 60 - strategy: - fail-fast: false - matrix: - build: - - name: quictls - configure: >- - PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" LDFLAGS="-Wl,-rpath,$HOME/nghttpx/lib" - --with-ngtcp2=$HOME/nghttpx --enable-warnings --enable-werror --enable-debug - --with-test-nghttpx="$HOME/nghttpx/bin/nghttpx" - --with-openssl=$HOME/nghttpx - - name: gnutls - configure: >- - PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" LDFLAGS="-Wl,-rpath,$HOME/nghttpx/lib" - --with-ngtcp2=$HOME/nghttpx --enable-warnings --enable-werror --enable-debug - --with-test-nghttpx="$HOME/nghttpx/bin/nghttpx" - --with-gnutls=$HOME/nghttpx - - name: wolfssl - configure: >- - PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" LDFLAGS="-Wl,-rpath,$HOME/nghttpx/lib" - --with-ngtcp2=$HOME/nghttpx --enable-warnings --enable-werror --enable-debug - --with-test-nghttpx="$HOME/nghttpx/bin/nghttpx" - --with-wolfssl=$HOME/nghttpx - - steps: - - run: | - sudo apt-get update - sudo apt-get install libtool autoconf automake pkg-config stunnel4 \ - libpsl-dev libbrotli-dev libzstd-dev zlib1g-dev libev-dev libc-ares-dev \ - nettle-dev libp11-kit-dev libtspi-dev libunistring-dev guile-2.2-dev libtasn1-bin \ - libtasn1-6-dev libidn2-0-dev gawk gperf libtss2-dev dns-root-data bison gtk-doc-tools \ - texinfo texlive texlive-extra-utils autopoint libev-dev \ - apache2 apache2-dev libnghttp2-dev - name: 'install prereqs and impacket, pytest, crypto, apache2' - - - name: cache quictls - uses: actions/cache@v3 - id: cache-quictls - env: - cache-name: cache-quictls - with: - path: /home/runner/quictls - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.quictls-version }} - - - if: steps.cache-quictls.outputs.cache-hit != 'true' - run: | - cd $HOME - git clone --quiet --depth=1 -b openssl-${{ env.quictls-version }} https://github.com/quictls/openssl quictls - cd quictls - ./config --prefix=$HOME/nghttpx --libdir=$HOME/nghttpx/lib - make - name: 'build quictls' - - - run: | - cd $HOME/quictls - make -j1 install_sw - name: 'install quictls' - - - - name: cache gnutls - uses: actions/cache@v3 - id: cache-gnutls - env: - cache-name: cache-gnutls - with: - path: /home/runner/gnutls - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.gnutls-version }} - - - if: steps.cache-gnutls.outputs.cache-hit != 'true' - run: | - cd $HOME - git clone --quiet --depth=1 -b ${{ env.gnutls-version }} https://github.com/gnutls/gnutls.git - cd gnutls - ./bootstrap - ./configure --prefix=$HOME/nghttpx \ - PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" LDFLAGS="-Wl,-rpath,$HOME/nghttpx/lib -L$HOME/nghttpx/lib" \ - --with-included-libtasn1 --with-included-unistring \ - --disable-guile --disable-doc --disable-tests --disable-tools - make - name: 'build gnutls' - - - run: | - cd $HOME/gnutls - make install - name: 'install gnutls' - - - - name: cache wolfssl - uses: actions/cache@v3 - id: cache-wolfssl - env: - cache-name: cache-wolfssl - with: - path: /home/runner/wolfssl - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.wolfssl-version }} - - - if: steps.cache-wolfssl.outputs.cache-hit != 'true' || ${{ env.wolfssl-version }} == 'master' - run: | - cd $HOME - rm -rf wolfssl - git clone --quiet --depth=1 -b ${{ env.wolfssl-version }} https://github.com/wolfSSL/wolfssl.git - cd wolfssl - ./autogen.sh - ./configure --enable-all --enable-quic --prefix=$HOME/nghttpx - make - name: 'build wolfssl' - - - run: | - cd $HOME/wolfssl - make install - name: 'install wolfssl' - - - - name: cache nghttp3 - uses: actions/cache@v3 - id: cache-nghttp3 - env: - cache-name: cache-nghttp3 - with: - path: /home/runner/nghttp3 - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.nghttp3-version }} - - - if: steps.cache-nghttp3.outputs.cache-hit != 'true' - run: | - cd $HOME - git clone --quiet --depth=1 -b ${{ env.nghttp3-version }} https://github.com/ngtcp2/nghttp3 - cd nghttp3 - autoreconf -fi - ./configure --prefix=$HOME/nghttpx PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" --enable-lib-only - make - name: 'build nghttp3' - - - run: | - cd $HOME/nghttp3 - make install - name: 'install nghttp3' - - # depends on all other cached libs built so far - - run: | - git clone --quiet --depth=1 -b ${{ env.ngtcp2-version }} https://github.com/ngtcp2/ngtcp2 - cd ngtcp2 - autoreconf -fi - ./configure --prefix=$HOME/nghttpx PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" --enable-lib-only --with-openssl --with-gnutls --with-wolfssl - make install - name: 'install ngtcp2' - - # depends on all other cached libs built so far - - run: | - git clone --quiet --depth=1 -b ${{ env.nghttp2-version }} https://github.com/nghttp2/nghttp2 - cd nghttp2 - autoreconf -fi - ./configure --prefix=$HOME/nghttpx PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" --enable-http3 - make install - name: 'install nghttp2' - - - name: cache mod_h2 - uses: actions/cache@v3 - id: cache-mod_h2 - env: - cache-name: cache-mod_h2 - with: - path: /home/runner/mod_h2 - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.mod_h2-version }} - - - if: steps.cache-mod_h2.outputs.cache-hit != 'true' - run: | - cd $HOME - git clone --quiet --depth=1 -b ${{ env.mod_h2-version }} https://github.com/icing/mod_h2 - cd mod_h2 - autoreconf -fi - ./configure - make - name: 'build mod_h2' - - - run: | - cd $HOME/mod_h2 - sudo make install - name: 'install mod_h2' - - - uses: actions/checkout@v3 - - - run: | - sudo python3 -m pip install -r tests/requirements.txt -r tests/http/requirements.txt - name: 'install python test prereqs' - - - run: autoreconf -fi - name: 'autoreconf' - - - run: ./configure ${{ matrix.build.configure }} - name: 'configure' - - - run: make V=1 - name: 'make' - - - run: make V=1 examples - name: 'make examples' - - - run: make V=1 -C tests - name: 'make tests' - - - run: make V=1 test-ci - name: 'run tests' - env: - TFLAGS: "${{ matrix.build.tflags }}" - - - run: pytest -v tests - name: 'run pytest' - env: - TFLAGS: "${{ matrix.build.tflags }}" - CURL_CI: github - - - run: pytest -v tests - name: 'run pytest with slowed network' - env: - # 33% of sends are EAGAINed - CURL_DBG_SOCK_WBLOCK: 33 - # only 80% of data > 10 bytes is send - CURL_DBG_SOCK_WPARTIAL: 80 - CURL_CI: github diff --git a/third-party/curl/.github/workflows/non-native.yml b/third-party/curl/.github/workflows/non-native.yml new file mode 100644 index 0000000000..621605a45e --- /dev/null +++ b/third-party/curl/.github/workflows/non-native.yml @@ -0,0 +1,565 @@ +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl + +name: 'non-native' + +'on': + push: + branches: + - master + - '*/ci' + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + pull_request: + branches: + - master + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + CURL_CI: github + CURL_TEST_MIN: 1820 + DO_NOT_TRACK: '1' + +jobs: + cross: + name: "${{ matrix.os }} ${{ matrix.version }}, ${{ matrix.build == 'cmake' && 'CM' || 'AM' }} ${{ matrix.cc }} ${{ matrix.desc }} ${{ matrix.arch }}" + runs-on: ubuntu-latest + timeout-minutes: 15 + defaults: + run: + shell: cpa.sh {0} # zizmor: ignore[misfeature] + env: + CC: '${{ matrix.cc }}' + MAKEFLAGS: -j 3 + MATRIX_ARCH: '${{ matrix.arch }}' + MATRIX_BUILD: '${{ matrix.build }}' + MATRIX_INSTALL: '${{ matrix.install }}' + MATRIX_OPTIONS: '${{ matrix.options }}' + MATRIX_OS: '${{ matrix.os }}' + MATRIX_VERSION: '${{ matrix.version }}' + strategy: + matrix: + include: + # https://github.com/DragonFlyBSD/DPorts + # { os: 'dragonflybsd', version: '6.4.2', build: 'autotools', arch: 'x86_64', cc: 'gcc' , desc: 'openssl skiprun', + # install: 'autoconf automake libtool openldap26-client libidn2', + # options: '--with-openssl --enable-ldap --enable-ldaps --with-libidn2' } + + # { os: 'dragonflybsd', version: '6.4.2', build: 'cmake' , arch: 'x86_64', cc: 'gcc' , desc: 'openssl skipall', + # install: 'cmake ninja' } + + # https://ports.freebsd.org/ + - { os: 'freebsd' , version: '15.1', build: 'autotools', arch: 'x86_64', cc: 'clang', desc: 'openssl', + install: 'autoconf automake libtool krb5-devel openldap26-client libidn2 stunnel', + options: '--with-openssl --with-gssapi --enable-ldap --enable-ldaps --with-libidn2' } + + - { os: 'freebsd' , version: '15.1', build: 'cmake' , arch: 'x86_64', cc: 'clang', desc: 'openssl !unity skiprun !examples', + install: 'cmake-core ninja perl5 krb5-devel openldap26-client libidn2', + options: '-DCURL_USE_GSSAPI=ON -DCMAKE_UNITY_BUILD=OFF' } + + - { os: 'freebsd' , version: '14.3', build: 'autotools', arch: 'arm64' , cc: 'clang', desc: 'openssl !examples', + install: 'autoconf automake libtool krb5-devel openldap26-client libidn2 stunnel', + options: '--with-openssl --with-gssapi --enable-ldap --enable-ldaps --with-libidn2' } + + - { os: 'freebsd' , version: '14.3', build: 'cmake' , arch: 'arm64' , cc: 'clang', desc: 'openssl', + install: 'cmake-core ninja perl5 krb5-devel openldap26-client libidn2 stunnel', + options: '-DCURL_USE_GSSAPI=ON' } + + # https://app.midnightbsd.org/ + # https://man.midnightbsd.org/cgi-bin/man.cgi/mport + # { os: 'midnightbsd' , version: '4.0.4', build: 'autotools' , arch: 'x86_64', cc: 'clang', desc: 'gnutls skipall !examples', + # install: 'autoconf autoconf-archive automake libtool gnutls', + # options: '--with-gnutls' } + + - { os: 'midnightbsd' , version: '4.0.4', build: 'cmake' , arch: 'x86_64', cc: 'clang', desc: 'gnutls skiprun', + install: 'cmake-core ninja perl5 gnutls openldap26-client libidn2', + options: '-DCURL_USE_GNUTLS=ON' } + + # https://pkgsrc.se/ + - { os: 'netbsd' , version: '10.1' , build: 'autotools', arch: 'x86_64', cc: 'gcc' , desc: 'openssl skipall !examples', + install: 'autoconf automake libtool mit-krb5', + options: '--with-openssl --with-gssapi' } + + - { os: 'netbsd' , version: '10.1' , build: 'cmake' , arch: 'x86_64', cc: 'gcc' , desc: 'openssl', + install: 'cmake ninja-build mit-krb5 openldap-client libidn2', + options: '-DCURL_USE_GSSAPI=ON' } + + # https://openbsd.app/ + # https://www.openbsd.org/faq/faq15.html + # https://github.com/OpenMPT/openmpt/blob/master/.github/workflows/OpenBSD-Autotools.yml + - { os: 'openbsd' , version: '7.9' , build: 'autotools', arch: 'x86_64', cc: 'clang', desc: 'libressl skipall !examples', + install: 'autoconf-2.72p0 automake-1.18.1 libtool', # NOTE: also sync these versions with the autoreconf step! + options: '--with-openssl' } + + - { os: 'openbsd' , version: '7.9' , build: 'cmake' , arch: 'x86_64', cc: 'clang', desc: 'libressl', + install: 'cmake ninja openldap-client-- libidn2' } + + fail-fast: false + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'setup VM' + uses: cross-platform-actions/action@5ea7e8e4677bd726033a10b094ba1c5762b15dee # v1.3.0 + with: + environment_variables: 'CC CURL_CI CURL_TEST_MIN DO_NOT_TRACK MAKEFLAGS MATRIX_ARCH MATRIX_BUILD MATRIX_INSTALL MATRIX_OPTIONS MATRIX_OS MATRIX_VERSION' + operating_system: '${{ matrix.os }}' + version: '${{ matrix.version }}' + architecture: '${{ matrix.arch }}' + + - name: 'install prereqs' + run: | + if [ "${MATRIX_OS}" = 'dragonflybsd' ]; then + sudo pkg install -y pkgconf brotli libnghttp2 ${MATRIX_INSTALL} + elif [ "${MATRIX_OS}" = 'freebsd' ]; then + sudo pkg install -y pkgconf brotli libnghttp2 ${MATRIX_INSTALL} + elif [ "${MATRIX_OS}" = 'midnightbsd' ]; then + if [ "${MATRIX_BUILD}" = 'autotools' ]; then + sudo mport index | grep -v -E 'Downloading.+%' + sudo mport upgrade | grep -v -E '(Downloading.+%|^/usr/local)' + fi + sudo mport install pkgconf brotli libnghttp2 ${MATRIX_INSTALL} | grep -v -E '(Downloading.+%|^/usr/local)' || true + elif [ "${MATRIX_OS}" = 'netbsd' ]; then + sudo pkgin -y install pkg-config perl brotli libssh2 libpsl nghttp2 ${MATRIX_INSTALL} + elif [ "${MATRIX_OS}" = 'openbsd' ]; then + sudo pkg_add -I brotli libssh2 libpsl nghttp2 ${MATRIX_INSTALL} + if [ "${MATRIX_BUILD}" = 'autotools' ]; then + sudo pkg_delete -I curl # to avoid autotools build linking against system libcurl + fi + fi + + - name: 'autoreconf' + if: ${{ matrix.build == 'autotools' }} + run: | + if [ "${MATRIX_OS}" = 'openbsd' ]; then + if [ "${MATRIX_VERSION}" = '7.9' ]; then + export AUTOCONF_VERSION=2.72 + export AUTOMAKE_VERSION=1.18 + fi + fi + autoreconf -fi + + - name: 'configure' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake -B bld -G Ninja -DCMAKE_INSTALL_PREFIX="$HOME"/curl-install \ + -DCMAKE_C_COMPILER="${CC}" \ + -DCMAKE_UNITY_BUILD=ON -DCURL_WERROR=ON -DENABLE_DEBUG=ON -DCMAKE_BUILD_TYPE=Debug \ + -DCURL_ENABLE_NTLM=ON ${MATRIX_OPTIONS} + else + if [ "${MATRIX_ARCH}" != 'x86_64' ]; then + options='--disable-manual --disable-docs' # Slow with autotools, skip on emulated CPU + fi + mkdir bld && cd bld + ../configure --prefix="$HOME"/curl-install --enable-unity --enable-debug --enable-warnings --enable-werror --disable-static \ + --disable-dependency-tracking --enable-option-checking=fatal \ + --with-brotli --with-libssh2 --with-nghttp2 \ + ${options} ${MATRIX_OPTIONS} + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMakeConfigureLog.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'build' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld + else + make -C bld V=1 + fi + + - name: 'curl -V' + run: bld/src/curl --disable --version + + - name: 'curl install' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --install bld + else + make -C bld install + fi + + - name: 'build tests' + if: ${{ matrix.arch == 'x86_64' && !contains(matrix.desc, 'skipall') }} # Slow on emulated CPU + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target testdeps + else + make -C bld -C tests + fi + + - name: 'run tests' + if: ${{ matrix.arch == 'x86_64' && !contains(matrix.desc, 'skipall') && !contains(matrix.desc, 'skiprun') }} # Slow on emulated CPU + run: | + export TFLAGS='-j8' + if [ "${MATRIX_OS}" = 'openbsd' ]; then + TFLAGS="$TFLAGS !2707" # Skip 2707 'ws: Peculiar frame sizes' on suspicion of hangs + fi + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target test-ci + else + make -C bld V=1 test-ci + fi + + - name: 'build examples' + if: ${{ !contains(matrix.desc, '!examples') }} + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target curl-examples-build + else + make -C bld examples + fi + + amiga: + name: "AmigaOS, ${{ matrix.build == 'cmake' && 'CM' || 'AM' }} gcc AmiSSL m68k" + runs-on: ubuntu-latest + timeout-minutes: 5 + env: + MAKEFLAGS: -j 5 + MATRIX_BUILD: '${{ matrix.build }}' + AMISSL_VERSION: '5.27' + AMISSL_SHA256: 5003bef8c5930354d16b0ce7196d71b2811891c42fad38a9238c5ce4098ad42a + TOOLCHAIN_VERSION: 6.5.0 + TOOLCHAIN_SHA256: 381e227c9ef552f073771d6f851cfdf873b574f3cf5db7c1c0107ea5d7146edc + strategy: + matrix: + build: [autotools, cmake] + fail-fast: false + steps: + - name: 'cache compiler' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-compiler + with: + path: ~/opt/amiga + key: ${{ runner.os }}-amigaos-${{ env.TOOLCHAIN_VERSION }}-${{ env.AMISSL_VERSION }}-amd64 + + - name: 'install compiler' + if: ${{ !steps.cache-compiler.outputs.cache-hit }} + run: | + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 3 --retry-connrefused \ + https://franke.ms/download/amiga-gcc.tgz --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF -- "${TOOLCHAIN_SHA256}" && tar -xf pkg.bin && rm -f pkg.bin + cd opt/amiga + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/jens-maus/amissl/releases/download/${AMISSL_VERSION}/AmiSSL-${AMISSL_VERSION}-SDK.lha" --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF -- "${AMISSL_SHA256}" && 7z x -bd -y pkg.bin && rm -f pkg.bin + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'configure' + run: | + ln -s ~/opt/amiga /opt + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake -B bld -G Ninja \ + -DAMIGA=1 \ + -DCMAKE_SYSTEM_NAME=Generic \ + -DCMAKE_SYSTEM_PROCESSOR=m68k \ + -DCMAKE_C_COMPILER_TARGET=m68k-unknown-amigaos \ + -DCMAKE_C_COMPILER=/opt/amiga/bin/m68k-amigaos-gcc \ + -DCMAKE_C_FLAGS='-O0 -msoft-float -mcrt=clib2' \ + -DCMAKE_UNITY_BUILD=ON \ + -DCURL_WERROR=ON \ + -DCURL_USE_LIBPSL=OFF \ + -DAMISSL_INCLUDE_DIR=/opt/amiga/AmiSSL/Developer/include \ + -DAMISSL_STUBS_LIBRARY=/opt/amiga/AmiSSL/Developer/lib/AmigaOS3/libamisslstubs.a \ + -DAMISSL_AUTO_LIBRARY=/opt/amiga/AmiSSL/Developer/lib/AmigaOS3/libamisslauto.a + else + autoreconf -fi + mkdir bld && cd bld && ../configure --enable-unity --enable-warnings --enable-werror \ + --disable-dependency-tracking --enable-option-checking=fatal \ + CC=/opt/amiga/bin/m68k-amigaos-gcc \ + AR=/opt/amiga/bin/m68k-amigaos-ar \ + RANLIB=/opt/amiga/bin/m68k-amigaos-ranlib \ + --host=m68k-amigaos \ + --disable-shared \ + --without-libpsl \ + --with-amissl \ + LDFLAGS=-L/opt/amiga/AmiSSL/Developer/lib/AmigaOS3 \ + CPPFLAGS=-I/opt/amiga/AmiSSL/Developer/include \ + CFLAGS='-O0 -msoft-float -mcrt=clib2' \ + LIBS='-lnet -lm -latomic' + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMake*.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'build' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld + else + make -C bld + fi + + - name: 'curl info' + run: | + find . -type f \( -name curl -o -name '*.a' \) -print0 | xargs -0 file -- + find . -type f \( -name curl -o -name '*.a' \) -print0 | xargs -0 stat -c '%10s bytes: %n' -- + + - name: 'build tests' + if: ${{ matrix.build == 'cmake' }} # skip for autotools to save time + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target testdeps + else + make -C bld -C tests + fi + + - name: 'build examples' + if: ${{ matrix.build == 'cmake' }} # skip for autotools to save time + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target curl-examples-build + else + make -C bld examples + fi + + android: + name: "Android ${{ matrix.platform }}, ${{ matrix.build == 'cmake' && 'CM' || 'AM' }} ${{ matrix.name }} arm64" + runs-on: ubuntu-latest + timeout-minutes: 5 + env: + LDFLAGS: -s + MAKEFLAGS: -j 5 + MATRIX_BUILD: '${{ matrix.build }}' + strategy: + matrix: + include: + - { build: 'autotools', platform: '21', name: "!ssl !zstd", + options: '--without-ssl --without-libpsl --without-zstd' } + + - { build: 'cmake' , platform: '21', name: "!ssl !zstd", + options: '-DCURL_ENABLE_SSL=OFF -DCURL_USE_LIBPSL=OFF -DCURL_ZSTD=OFF' } + + - { build: 'autotools', platform: '35', name: "!ssl !zstd", + options: '--without-ssl --without-libpsl --without-zstd' } + + - { build: 'cmake' , platform: '35', name: "!ssl !zstd", + options: '-DCURL_ENABLE_SSL=OFF -DCURL_USE_LIBPSL=OFF -DCURL_ZSTD=OFF' } + + fail-fast: false + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'autoreconf' + if: ${{ matrix.build == 'autotools' }} + run: autoreconf -fi + + - name: 'configure' + env: + MATRIX_OPTIONS: '${{ matrix.options }}' + MATRIX_PLATFORM: '${{ matrix.platform }}' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then # https://developer.android.com/ndk/guides/cmake + cmake -B bld -G Ninja \ + -DANDROID_ABI=arm64-v8a \ + -DANDROID_PLATFORM="android-${MATRIX_PLATFORM}" \ + -DCMAKE_TOOLCHAIN_FILE="${ANDROID_NDK_HOME}/build/cmake/android.toolchain.cmake" -DCMAKE_WARN_DEPRECATED=OFF \ + -DCMAKE_UNITY_BUILD=ON \ + -DCURL_WERROR=ON \ + ${MATRIX_OPTIONS} + else + TOOLCHAIN="${ANDROID_NDK_HOME}/toolchains/llvm/prebuilt/linux-x86_64" + mkdir bld && cd bld && ../configure --enable-unity --enable-warnings --enable-werror --disable-shared \ + --disable-dependency-tracking --enable-option-checking=fatal \ + CC="$TOOLCHAIN/bin/aarch64-linux-android${MATRIX_PLATFORM}-clang" \ + AR="$TOOLCHAIN/bin/llvm-ar" \ + RANLIB="$TOOLCHAIN/bin/llvm-ranlib" \ + --host="aarch64-linux-android${MATRIX_PLATFORM}" \ + ${MATRIX_OPTIONS} + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMake*.yaml 2>/dev/null || true + + - name: 'dump config files' + run: | + for f in libcurl.pc curl-config; do + echo "::group::${f}"; grep -v '^#' bld/"${f}" || true; echo '::endgroup::' + done + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'build' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose + else + make -C bld V=1 + fi + + - name: 'curl info' + run: | + find . -type f \( -name curl -o -name '*.so' -o -name '*.a' \) -print0 | xargs -0 file -- + find . -type f \( -name curl -o -name '*.so' -o -name '*.a' \) -print0 | xargs -0 stat -c '%10s bytes: %n' -- + + - name: 'build tests' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target testdeps + else + make -C bld -C tests + fi + + - name: 'build examples' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target curl-examples-build + else + make -C bld examples + fi + + msdos: + name: "MS-DOS, ${{ matrix.build == 'cmake' && 'CM' || 'AM' }} djgpp !ssl i586" + runs-on: ubuntu-latest + timeout-minutes: 5 + env: + LDFLAGS: -s + MAKEFLAGS: -j 5 + MATRIX_BUILD: '${{ matrix.build }}' + # renovate: datasource=github-releases depName=andrewwutw/build-djgpp versioning=semver-coerced registryUrl=https://github.com + TOOLCHAIN_VERSION: '3.4' + TOOLCHAIN_SHA256: 8464f17017d6ab1b2bb2df4ed82357b5bf692e6e2b7fee37e315638f3d505f00 + strategy: + matrix: + build: [autotools, cmake] + fail-fast: false + steps: + - name: 'install packages' + timeout-minutes: 2 + run: | + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install libfl2 + + - name: 'cache compiler (djgpp)' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-compiler + with: + path: ~/djgpp + key: ${{ runner.os }}-djgpp-${{ env.TOOLCHAIN_VERSION }}-amd64 + + - name: 'install compiler (djgpp)' + if: ${{ !steps.cache-compiler.outputs.cache-hit }} + run: | + cd ~ + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 120 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/andrewwutw/build-djgpp/releases/download/v${TOOLCHAIN_VERSION}/djgpp-linux64-gcc1220.tar.bz2" --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF -- "${TOOLCHAIN_SHA256}" && tar -xjf pkg.bin && rm -f pkg.bin + cd djgpp + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + https://www.delorie.com/pub/djgpp/current/v2tk/wat3211b.zip --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF faa2222ab5deb2c2aac229c760bf4d45aca5379f5af97865c308a0467046b67a && unzip -q pkg.bin && rm -f pkg.bin + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + https://www.delorie.com/pub/djgpp/current/v2tk/zlb13b.zip --output pkg.bin + sha256sum pkg.bin | tee /dev/stderr | grep -qwF f3d2fa8129e7591c7e79074306d8ab91a70ec172cc01baedeae74992285dd3a3 && unzip -q pkg.bin && rm -f pkg.bin + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'configure' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake -B bld -G Ninja \ + -DCMAKE_SYSTEM_NAME=DOS \ + -DCMAKE_SYSTEM_PROCESSOR=x86 \ + -DCMAKE_C_COMPILER_TARGET=i586-pc-msdosdjgpp \ + -DCMAKE_C_COMPILER="$HOME"/djgpp/bin/i586-pc-msdosdjgpp-gcc \ + -DCMAKE_UNITY_BUILD=ON \ + -DCURL_WERROR=ON \ + -DCURL_ENABLE_SSL=OFF -DCURL_USE_LIBPSL=OFF \ + -DZLIB_INCLUDE_DIR="$HOME"/djgpp/include \ + -DZLIB_LIBRARY="$HOME"/djgpp/lib/libz.a \ + -DWATT_ROOT="$HOME"/djgpp/net/watt + else + autoreconf -fi + mkdir bld && cd bld && ../configure --enable-unity --enable-warnings --enable-werror --disable-shared \ + --disable-dependency-tracking --enable-option-checking=fatal \ + CC="$HOME"/djgpp/bin/i586-pc-msdosdjgpp-gcc \ + AR="$HOME"/djgpp/bin/i586-pc-msdosdjgpp-ar \ + RANLIB="$HOME"/djgpp/bin/i586-pc-msdosdjgpp-ranlib \ + WATT_ROOT="$HOME"/djgpp/net/watt \ + --host=i586-pc-msdosdjgpp \ + --without-ssl --without-libpsl \ + --with-zlib="$HOME"/djgpp + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMake*.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'build' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld + else + make -C bld + fi + + - name: 'curl info' + run: | + find . \( -name '*.exe' -o -name '*.a' \) -print0 | xargs -0 file -- + find . \( -name '*.exe' -o -name '*.a' \) -print0 | xargs -0 stat -c '%10s bytes: %n' -- + + - name: 'build tests' + if: ${{ matrix.build == 'cmake' }} # skip for autotools to save time + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target testdeps + else + make -C bld -C tests + fi + + - name: 'build examples' + if: ${{ matrix.build == 'cmake' }} # skip for autotools to save time + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target curl-examples-build + else + make -C bld examples + fi diff --git a/third-party/curl/.github/workflows/proselint.yml b/third-party/curl/.github/workflows/proselint.yml deleted file mode 100644 index 01a7cf5c74..0000000000 --- a/third-party/curl/.github/workflows/proselint.yml +++ /dev/null @@ -1,68 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: proselint - -on: - push: - branches: - - master - - '*/ci' - paths: - - '.github/workflows/proselint.yml' - - '**.md' - pull_request: - branches: - - master - paths: - - '.github/workflows/proselint.yml' - - '**.md' - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} - cancel-in-progress: true - -permissions: {} - -jobs: - check: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v2 - - - name: install prereqs - run: sudo apt-get install python3-proselint - - # config file help: https://github.com/amperser/proselint/ - - name: create proselint config - run: | - cat < $HOME/.proselintrc - { - "checks": { - "typography.diacritical_marks": false, - "typography.symbols": false, - "annotations.misc": false - } - } - JSON - - - name: check prose - run: a=`git ls-files '*.md' | grep -v docs/CHECKSRC.md` && proselint $a README - - # This is for CHECKSRC and files with aggressive exclamation mark needs - - name: create second proselint config - run: | - cat < $HOME/.proselintrc - { - "checks": { - "typography.diacritical_marks": false, - "typography.symbols": false, - "typography.exclamation": false, - "annotations.misc": false - } - } - JSON - - - name: check special prose - run: a=docs/CHECKSRC.md && proselint $a diff --git a/third-party/curl/.github/workflows/quiche-linux.yml b/third-party/curl/.github/workflows/quiche-linux.yml deleted file mode 100644 index 69c328b47b..0000000000 --- a/third-party/curl/.github/workflows/quiche-linux.yml +++ /dev/null @@ -1,209 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: quiche - -on: - push: - branches: - - master - - '*/ci' - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - pull_request: - branches: - - master - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - -concurrency: - # Hardcoded workflow filename as workflow name above is just Linux again - group: quiche-${{ github.event.pull_request.number || github.sha }} - cancel-in-progress: true - -permissions: {} - -env: - MAKEFLAGS: -j 3 - openssl-version: 3.0.10+quic - nghttp3-version: v0.15.0 - ngtcp2-version: v0.19.1 - nghttp2-version: v1.56.0 - quiche-version: 0.17.2 - mod_h2-version: v2.0.21 - -jobs: - autotools: - name: ${{ matrix.build.name }} - runs-on: 'ubuntu-latest' - timeout-minutes: 60 - strategy: - fail-fast: false - matrix: - build: - - name: quiche - install: >- - libpsl-dev libbrotli-dev libzstd-dev zlib1g-dev libev-dev libc-ares-dev - install_steps: pytest - configure: >- - LDFLAGS="-Wl,-rpath,/home/runner/quiche/target/release" - --with-openssl=/home/runner/quiche/quiche/deps/boringssl/src - --enable-debug - --with-quiche=/home/runner/quiche/target/release - --with-test-nghttpx="$HOME/nghttpx/bin/nghttpx" - - steps: - - run: | - sudo apt-get update - sudo apt-get install libtool autoconf automake pkg-config stunnel4 ${{ matrix.build.install }} - sudo apt-get install apache2 apache2-dev libnghttp2-dev - name: 'install prereqs and impacket, pytest, crypto' - - - name: cache nghttpx - uses: actions/cache@v3 - id: cache-nghttpx - env: - cache-name: cache-nghttpx - with: - path: /home/runner/nghttpx - key: ${{ runner.os }}-build-${{ env.cache-name }}-openssl-${{ env.openssl-version }}-nghttp3-${{ env.nghttp3-version }}-ngtcp2-${{ env.ngtcp2-version }}-nghttp2-${{ env.nghttp2-version }} - - - if: steps.cache-nghttpx.outputs.cache-hit != 'true' - run: | - git clone --quiet --depth=1 -b openssl-${{ env.openssl-version }} https://github.com/quictls/openssl - cd openssl - ./config --prefix=$HOME/nghttpx --libdir=$HOME/nghttpx/lib - make -j1 install_sw - name: 'install quictls' - - - if: steps.cache-nghttpx.outputs.cache-hit != 'true' - run: | - git clone --quiet --depth=1 -b ${{ env.nghttp3-version }} https://github.com/ngtcp2/nghttp3 - cd nghttp3 - autoreconf -fi - ./configure --prefix=$HOME/nghttpx PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" --enable-lib-only - make install - name: 'install nghttp3' - - - if: steps.cache-nghttpx.outputs.cache-hit != 'true' - run: | - git clone --quiet --depth=1 -b ${{ env.ngtcp2-version }} https://github.com/ngtcp2/ngtcp2 - cd ngtcp2 - autoreconf -fi - ./configure --prefix=$HOME/nghttpx PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" --enable-lib-only --with-openssl - make install - name: 'install ngtcp2' - - - if: steps.cache-nghttpx.outputs.cache-hit != 'true' - run: | - git clone --quiet --depth=1 -b ${{ env.nghttp2-version }} https://github.com/nghttp2/nghttp2 - cd nghttp2 - autoreconf -fi - ./configure --prefix=$HOME/nghttpx PKG_CONFIG_PATH="$HOME/nghttpx/lib/pkgconfig" --enable-http3 - make install - name: 'install nghttp2' - - - name: cache quiche - uses: actions/cache@v3 - id: cache-quiche - env: - cache-name: cache-quiche - with: - path: /home/runner/quiche - key: ${{ runner.os }}-build-${{ env.cache-name }}-quiche-${{ env.quiche-version }} - - - if: steps.cache-quiche.outputs.cache-hit != 'true' - run: | - cd $HOME - git clone --quiet --depth=1 -b ${{ env.quiche-version }} --recursive https://github.com/cloudflare/quiche.git - cd quiche - #### Work-around https://github.com/curl/curl/issues/7927 ####### - #### See https://github.com/alexcrichton/cmake-rs/issues/131 #### - sed -i -e 's/cmake = "0.1"/cmake = "=0.1.45"/' quiche/Cargo.toml - - cargo build -v --package quiche --release --features ffi,pkg-config-meta,qlog --verbose - mkdir -v quiche/deps/boringssl/src/lib - ln -vnf $(find target/release -name libcrypto.a -o -name libssl.a) quiche/deps/boringssl/src/lib/ - - # include dir - # /home/runner/quiche/quiche/deps/boringssl/src/include - # lib dir - # /home/runner/quiche/quiche/deps/boringssl/src/lib - name: 'build quiche and boringssl' - - - name: cache mod_h2 - uses: actions/cache@v3 - id: cache-mod_h2 - env: - cache-name: cache-mod_h2 - with: - path: /home/runner/mod_h2 - key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ env.mod_h2-version }} - - - if: steps.cache-mod_h2.outputs.cache-hit != 'true' - run: | - cd $HOME - git clone --quiet --depth=1 -b ${{ env.mod_h2-version }} https://github.com/icing/mod_h2 - cd mod_h2 - autoreconf -fi - ./configure - make - name: 'build mod_h2' - - - run: | - cd $HOME/mod_h2 - sudo make install - name: 'install mod_h2' - - - uses: actions/checkout@v3 - - - run: | - sudo python3 -m pip install -r tests/requirements.txt -r tests/http/requirements.txt - name: 'install python test prereqs' - - - run: autoreconf -fi - name: 'autoreconf' - - - run: ./configure ${{ matrix.build.configure }} - name: 'configure' - - - run: make V=1 - name: 'make' - - - run: make V=1 examples - name: 'make examples' - - - run: make V=1 -C tests - name: 'make tests' - - - run: make V=1 test-ci - name: 'run tests' - env: - TFLAGS: "${{ matrix.build.tflags }}" - - - run: pytest -v tests - name: 'run pytest' - env: - TFLAGS: "${{ matrix.build.tflags }}" - CURL_CI: github diff --git a/third-party/curl/.github/workflows/reuse.yml b/third-party/curl/.github/workflows/reuse.yml deleted file mode 100644 index 95ad6e9295..0000000000 --- a/third-party/curl/.github/workflows/reuse.yml +++ /dev/null @@ -1,29 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# SPDX-FileCopyrightText: 2022 Free Software Foundation Europe e.V. -# -# SPDX-License-Identifier: curl - -name: REUSE compliance - -on: - push: - branches: - - master - - '*/ci' - pull_request: - branches: - - master - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} - cancel-in-progress: true - -permissions: {} - -jobs: - check: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v3 - - name: REUSE Compliance Check - uses: fsfe/reuse-action@v1 diff --git a/third-party/curl/.github/workflows/spellcheck.yml b/third-party/curl/.github/workflows/spellcheck.yml deleted file mode 100644 index 1e43707722..0000000000 --- a/third-party/curl/.github/workflows/spellcheck.yml +++ /dev/null @@ -1,66 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: spell -on: - push: - branches: - - master - paths: - - '**.md' - - '**.3' - - '**.1' - - '**/spellcheck.yml' - - '**/spellcheck.yaml' - - '**/wordlist.txt' - pull_request: - branches: - - master - paths: - - '**.md' - - '**.3' - - '**.1' - - '**/spellcheck.yml' - - '**/spellcheck.yaml' - - '**/wordlist.txt' - -permissions: {} - -jobs: - check: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v3 - - - name: install pandoc - run: sudo apt-get install pandoc - - - name: build curl.1 - run: | - autoreconf -fi - ./configure --without-ssl - make -C docs - - - name: strip "uncheckable" sections from .3 pages - run: find docs -name "*.3" -size +40c | sed 's/\.3//' | xargs -t -n1 -I OO ./.github/scripts/cleanspell.pl OO.3 OO.33 - - - name: convert .3 man pages to markdown - run: find docs -name "*.33" -size +40c | sed 's/\.33//' | xargs -t -n1 -I OO pandoc -f man -t markdown OO.33 -o OO.md - - - name: convert .1 man pages to markdown - run: find docs -name "*.1" -size +40c | sed 's/\.1//' | xargs -t -n1 -I OO pandoc OO.1 -o OO.md - - - name: trim the curl.1 markdown file - run: | - perl -pi -e 's/^ .*//' docs/curl.md - perl -pi -e 's/\-\-[\a-z0-9-]*//ig' docs/curl.md - perl -pi -e 's!https://[a-z0-9%/.-]*!!ig' docs/curl.md - - - name: setup the custom wordlist - run: grep -v '^#' .github/scripts/spellcheck.words > wordlist.txt - - - name: Check Spelling - uses: rojopolis/spellcheck-github-actions@v0 - with: - config_path: .github/scripts/spellcheck.yaml diff --git a/third-party/curl/.github/workflows/torture.yml b/third-party/curl/.github/workflows/torture.yml deleted file mode 100644 index cb639a5e38..0000000000 --- a/third-party/curl/.github/workflows/torture.yml +++ /dev/null @@ -1,92 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: Linux torture - -on: - push: - branches: - - master - - '*/ci' - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - pull_request: - branches: - - master - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - -concurrency: - # Hardcoded workflow filename as workflow name above is just Linux again - group: torture-${{ github.event.pull_request.number || github.sha }} - cancel-in-progress: true - -permissions: {} - -env: - MAKEFLAGS: -j 3 - -jobs: - autotools: - name: ${{ matrix.build.name }} - runs-on: 'ubuntu-latest' - timeout-minutes: 90 - strategy: - fail-fast: false - matrix: - build: - - name: torture - install: libpsl-dev libbrotli-dev libzstd-dev zlib1g-dev libnghttp2-dev libssh2-1-dev libc-ares-dev - configure: --with-openssl --enable-debug --enable-ares --enable-websockets - tflags: -n -t --shallow=25 !FTP - - name: torture-ftp - install: libpsl-dev libbrotli-dev libzstd-dev zlib1g-dev libnghttp2-dev libssh2-1-dev libc-ares-dev - configure: --with-openssl --enable-debug --enable-ares - tflags: -n -t --shallow=20 FTP - - steps: - - run: | - sudo apt-get update - sudo apt-get install libtool autoconf automake pkg-config stunnel4 ${{ matrix.build.install }} - sudo python3 -m pip install impacket - name: 'install prereqs and impacket' - - - uses: actions/checkout@v3 - - - run: autoreconf -fi - name: 'autoreconf' - - - run: ./configure --enable-warnings --enable-werror ${{ matrix.build.configure }} - name: 'configure' - - - run: make V=1 - name: 'make' - - - run: make V=1 -C tests - name: 'make tests' - - - run: make V=1 test-torture - name: 'run tests' - env: - TFLAGS: "${{ matrix.build.tflags }}" diff --git a/third-party/curl/.github/workflows/windows.yml b/third-party/curl/.github/workflows/windows.yml new file mode 100644 index 0000000000..53429d1f2b --- /dev/null +++ b/third-party/curl/.github/workflows/windows.yml @@ -0,0 +1,1197 @@ +# Copyright (C) Viktor Szakats +# +# SPDX-License-Identifier: curl + +name: 'Windows' + +'on': + push: + branches: + - master + - '*/ci' + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + pull_request: + branches: + - master + paths-ignore: + - '**/*.md' + - '.circleci/**' + - 'appveyor.*' + - 'Dockerfile' + - 'projects/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} + cancel-in-progress: true + +permissions: {} + +env: + CURL_CI: github + CURL_TEST_MIN: 1800 + CURL_TEST_SSH_KEYALGO: ed25519 + DO_NOT_TRACK: '1' + OPENSSH_WINDOWS_VERSION: 10.0.0.0p2-Preview + OPENSSH_WINDOWS_SHA256_ARM64: 698c6aec31c1dd0fb996206e8741f4531a97355686b5431ef347d531b07fcd42 + OPENSSH_WINDOWS_SHA256_WIN64: 23f50f3458c4c5d0b12217c6a5ddfde0137210a30fa870e98b29827f7b43aba5 + STUNNEL_VERSION: '5.78' + STUNNEL_SHA256: 32a88dcc5654f955266109be8bf10fd7d56fa4e125cab821ee508230570e46c5 + +jobs: + build-cache: + name: 'Build caches' + runs-on: ${{ matrix.image }} + strategy: + matrix: + image: [windows-11-arm, windows-2022] # Cannot share cache between arm and intel: https://github.com/actions/cache/issues/1622 + steps: + - name: 'cache test prereqs (stunnel)' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-stunnel + with: + path: C:\my-stunnel + key: ${{ runner.os }}-stunnel-${{ env.STUNNEL_VERSION }}-amd64 + lookup-only: true + + - name: 'install test prereqs (stunnel)' + if: ${{ !steps.cache-stunnel.outputs.cache-hit }} + timeout-minutes: 2 + shell: bash + run: | + cd /c && mkdir my-stunnel && cd my-stunnel + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 240 --retry 3 --retry-connrefused \ + "https://www.stunnel.org/archive/5.x/stunnel-${STUNNEL_VERSION}-win64-installer.exe" --output pkg.bin + sha256sum pkg.bin && sha256sum pkg.bin | grep -qwF -- "${STUNNEL_SHA256}" && 7z x -y pkg.bin >/dev/null && rm -f pkg.bin && ls -l && bin/tstunnel -version + + cygwin: + name: "cygwin, ${{ matrix.build == 'cmake' && 'CM' || 'AM' }} ${{ matrix.platform }} ${{ matrix.name }}" + needs: build-cache + runs-on: windows-2022 + timeout-minutes: 10 + defaults: + run: + shell: D:\cygwin\bin\bash.exe '{0}' # zizmor: ignore[misfeature] + env: + CURL_TEST_MIN: 1850 + LDFLAGS: -s + MAKEFLAGS: -j 5 + SHELLOPTS: 'igncr' + MATRIX_BUILD: '${{ matrix.build }}' + strategy: + matrix: + include: + - { name: 'openssl R', + build: 'autotools', platform: 'x86_64', tflags: 'skiprun', + config: '--with-openssl', + install: 'libssl-devel libssh2-devel' } + - { name: 'openssl', + build: 'cmake', platform: 'x86_64', tflags: '', + config: '-DENABLE_DEBUG=ON -DCURL_USE_OPENSSL=ON -DENABLE_THREADED_RESOLVER=OFF -DCURL_ENABLE_NTLM=ON', + install: 'libssl-devel libssh2-devel' } + fail-fast: false + steps: + - uses: cygwin/cygwin-install-action@3f0a3f9f988f7e96b8c18098ae05eaec175f5b52 # v6.0.2 + with: + platform: ${{ matrix.platform }} + work-vol: 'D:' + # https://cygwin.com/mirrors.html + # Main mirror status: https://archlinux.org/mirrors/kernel.org/ + site: https://mirrors.kernel.org/sourceware/cygwin/ + # https://cygwin.com/cgi-bin2/package-grep.cgi + packages: >- + ${{ matrix.build == 'autotools' && 'autoconf automake libtool make' || 'cmake ninja' }} + gcc-core binutils perl + openssh + libpsl-devel + zlib-devel + libbrotli-devel + libzstd-devel + libnghttp2-devel + ${{ matrix.install }} + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'autoreconf' + if: ${{ matrix.build == 'autotools' }} + timeout-minutes: 2 + run: | + PATH=/usr/bin + autoreconf -fi + + - name: 'configure' + timeout-minutes: 5 + env: + MATRIX_CONFIG: '${{ matrix.config }}' + run: | + PATH=/usr/bin + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake -B bld -G Ninja -D_CURL_PREFILL=ON ${options} \ + -DCMAKE_INSTALL_PREFIX="$HOME"/curl-install \ + -DCMAKE_UNITY_BUILD=ON -DCMAKE_UNITY_BUILD_BATCH_SIZE=30 \ + -DCURL_WERROR=ON \ + ${MATRIX_CONFIG} + else + mkdir bld && cd bld && ../configure --prefix="$HOME"/curl-install --enable-unity --enable-warnings --enable-werror --disable-static \ + --disable-dependency-tracking --enable-option-checking=fatal \ + --with-libssh2 \ + ${MATRIX_CONFIG} + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: | + PATH=/usr/bin + cat bld/config.log bld/CMakeFiles/CMake*.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + PATH=/usr/bin + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'build' + timeout-minutes: 10 + run: | + PATH=/usr/bin + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose + cmake --install bld --verbose + else + make -C bld V=1 install + fi + + - name: 'curl -V' + timeout-minutes: 1 + run: | + PATH=/usr/bin + find . \( -name '*.exe' -o -name '*.dll' -o -name '*.a' \) -print0 | grep -z curl | xargs -0 file -- + find . \( -name '*.exe' -o -name '*.dll' -o -name '*.a' \) -print0 | grep -z curl | xargs -0 stat -c '%10s bytes: %n' -- + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + PATH="$PWD/bld/lib:$PATH" + fi + bld/src/curl.exe --disable --version + + - name: 'build tests' + if: ${{ matrix.tflags != 'skipall' }} + timeout-minutes: 15 + run: | + PATH=/usr/bin + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target testdeps + else + make -C bld V=1 -C tests + fi + + - name: 'cache test prereqs (stunnel)' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-stunnel + with: + path: C:\my-stunnel + key: ${{ runner.os }}-stunnel-${{ env.STUNNEL_VERSION }}-amd64 + fail-on-cache-miss: true + + - name: 'run tests' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + timeout-minutes: 15 + env: + TFLAGS: '${{ matrix.tflags }}' + run: | + PATH=/usr/bin:/cygdrive/c/my-stunnel/bin + TFLAGS="-j8 ${TFLAGS}" + if [ -x "$(cygpath "${SYSTEMROOT}/System32/curl.exe")" ]; then + TFLAGS+=" -ac $(cygpath "${SYSTEMROOT}/System32/curl.exe")" + fi + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + PATH="$PWD/bld/lib:$PATH" + cmake --build bld --verbose --target test-ci + else + make -C bld V=1 test-ci + fi + + - name: 'build examples' + if: ${{ matrix.build == 'cmake' }} + timeout-minutes: 5 + run: | + PATH=/usr/bin + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target curl-examples-build + else + make -C bld V=1 examples + fi + + - name: 'disk space used' + run: du -sh .; echo; du -sh -t 250KB ./*; echo; du -h -t 250KB bld + + msys2: # both msys and mingw-w64 + name: "${{ matrix.sys == 'msys' && 'msys2' || 'mingw' }}, ${{ matrix.build == 'cmake' && 'CM' || 'AM' }} ${{ matrix.env }} ${{ matrix.name }} ${{ matrix.test }}" + needs: build-cache + runs-on: ${{ matrix.image || 'windows-2022' }} + timeout-minutes: ${{ contains(matrix.tflags, '-t') && 14 || 10 }} + defaults: + run: + shell: msys2 {0} # zizmor: ignore[misfeature] + env: + LDFLAGS: -s + MAKEFLAGS: -j 5 + MATRIX_BUILD: '${{ matrix.build }}' + MATRIX_OPENSSH: '${{ matrix.openssh }}' + MATRIX_SYS: '${{ matrix.sys }}' + MATRIX_TEST: '${{ matrix.test }}' + strategy: + matrix: + include: + # MSYS + - { name: '!proxy', + build: 'autotools', sys: 'msys' , env: 'x86_64' , tflags: '--min=1620', + config: '--enable-debug --with-openssl --disable-threaded-resolver --disable-proxy --enable-ntlm', + install: 'openssl-devel libssh2-devel' } + - { name: 'default', + build: 'autotools', sys: 'msys' , env: 'x86_64' , tflags: 'skiprun' , + config: '--enable-debug --with-openssl --disable-threaded-resolver --enable-ntlm', + install: 'openssl-devel libssh2-devel' } + - { name: 'default', + build: 'cmake' , sys: 'msys' , env: 'x86_64' , tflags: '' , + config: '-DENABLE_DEBUG=ON -DENABLE_THREADED_RESOLVER=OFF -DCURL_ENABLE_NTLM=ON', + install: 'openssl-devel libssh2-devel' } + - { name: 'default R', + build: 'autotools', sys: 'msys' , env: 'x86_64' , tflags: '' , + config: '--with-openssl --enable-ntlm', install: 'openssl-devel libssh2-devel' } + # MinGW + - { name: 'default', + build: 'autotools', sys: 'mingw64' , env: 'x86_64' , tflags: 'skiprun' , + config: '--enable-debug --with-openssl --disable-threaded-resolver --enable-static --without-zlib', + install: 'mingw-w64-x86_64-openssl mingw-w64-x86_64-libssh2' } + - { name: 'c-ares U', + build: 'autotools', sys: 'ucrt64' , env: 'ucrt-x86_64' , tflags: '' , + config: '--enable-debug --with-openssl --enable-windows-unicode --enable-ares --enable-static --disable-shared --enable-ca-native --enable-ntlm', + install: 'mingw-w64-ucrt-x86_64-c-ares mingw-w64-ucrt-x86_64-openssl mingw-w64-ucrt-x86_64-nghttp3 mingw-w64-ucrt-x86_64-libssh2' } + - { name: 'schannel c-ares U', type: 'Debug', + build: 'cmake' , sys: 'mingw64' , env: 'x86_64' , tflags: '--min=1720', + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DCURL_USE_SCHANNEL=ON -DENABLE_UNICODE=ON -DENABLE_ARES=ON -DCURL_DROP_UNUSED=ON', + install: 'mingw-w64-x86_64-c-ares mingw-w64-x86_64-libssh2' } + # MinGW torture + - { name: 'schannel U torture 1', type: 'Debug', + build: 'cmake' , sys: 'ucrt64' , env: 'ucrt-x86_64' , tflags: '-t --shallow=13 --min=820 1 to 950', + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DCURL_USE_SCHANNEL=ON -DENABLE_UNICODE=ON -DENABLE_ARES=ON', + install: 'mingw-w64-ucrt-x86_64-c-ares mingw-w64-ucrt-x86_64-libssh2' } + - { name: 'schannel U torture 2', type: 'Debug', + build: 'cmake' , sys: 'ucrt64' , env: 'ucrt-x86_64' , tflags: '-t --shallow=13 --min=820 951 to 9999', + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DCURL_USE_SCHANNEL=ON -DENABLE_UNICODE=ON -DENABLE_ARES=ON', + install: 'mingw-w64-ucrt-x86_64-c-ares mingw-w64-ucrt-x86_64-libssh2' } + # WARNING: libssh uses hard-coded world-writable paths (C:ProgramData/, /etc/..., ~/.ssh/) + # to read its configuration from, making it vulnerable to attacks on + # Windows. Do not use this component till there is a fix for these. + # Holds true after CVE-2025-14821 mitigations in 0.12.0. + # https://github.com/curl/curl-for-win/blob/471a065705a16c61a343b15d3e4ef195e2df2f9e/libssh.sh#L6-L94 + - { name: 'gnutls libssh', type: 'Debug', openssh: 'OpenSSH-Windows', + build: 'cmake' , sys: 'clang64' , env: 'clang-x86_64' , tflags: '' , + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DCURL_USE_GNUTLS=ON -DENABLE_UNICODE=OFF -DUSE_NGTCP2=ON -DCURL_USE_LIBSSH2=OFF -DCURL_USE_LIBSSH=ON -DCURL_ENABLE_NTLM=ON', + install: 'mingw-w64-clang-x86_64-gnutls mingw-w64-clang-x86_64-nghttp3 mingw-w64-clang-x86_64-ngtcp2 mingw-w64-clang-x86_64-libssh unzip' } + - { name: 'schannel R', type: 'Release', image: 'windows-11-arm', + build: 'cmake' , sys: 'clangarm64', env: 'clang-aarch64', tflags: 'skiprun' , + config: '-DENABLE_DEBUG=OFF -DBUILD_SHARED_LIBS=ON -DCURL_USE_SCHANNEL=ON -DENABLE_UNICODE=ON -DCURL_DROP_UNUSED=ON', + install: 'mingw-w64-clang-aarch64-libssh2' } + - { name: 'openssl', type: 'Release', chkprefill: '_chkprefill', + build: 'cmake' , sys: 'clang64' , env: 'clang-x86_64' , tflags: 'skiprun' , + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DCURL_USE_OPENSSL=ON -DENABLE_UNICODE=OFF -DUSE_NGTCP2=ON -DUSE_PROXY_HTTP3=ON', + install: 'mingw-w64-clang-x86_64-openssl mingw-w64-clang-x86_64-nghttp3 mingw-w64-clang-x86_64-ngtcp2 mingw-w64-clang-x86_64-libssh2' } + - { name: 'schannel', type: 'Release', test: 'uwp', + build: 'cmake' , sys: 'ucrt64' , env: 'ucrt-x86_64' , tflags: 'skiprun' , + config: '-DENABLE_DEBUG=OFF -DBUILD_SHARED_LIBS=ON -DCURL_USE_OPENSSL=ON', + install: 'mingw-w64-ucrt-x86_64-openssl mingw-w64-ucrt-x86_64-libssh2' } + # { name: 'schannel', type: 'Release', test: 'uwp', + # build: 'autotools', sys: 'ucrt64' , env: 'ucrt-x86_64' , tflags: 'skiprun' , + # config: '--without-debug --with-schannel --disable-static', + # install: 'mingw-w64-ucrt-x86_64-libssh2' } + - { name: 'schannel dev debug', type: 'Debug', cppflags: '-DCURL_SCHANNEL_DEV_DEBUG', image: 'windows-2025', + build: 'cmake' , sys: 'mingw64' , env: 'x86_64' , tflags: 'skiprun' , + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=ON -DCURL_USE_SCHANNEL=ON -DENABLE_UNICODE=ON -DCMAKE_VERBOSE_MAKEFILE=ON', + install: 'mingw-w64-x86_64-libssh2' } + - { name: 'MultiSSL R', type: 'Release', + build: 'cmake' , sys: 'mingw32' , env: 'i686' , tflags: 'skiprun' , + config: '-DENABLE_DEBUG=OFF -DBUILD_SHARED_LIBS=ON -DCURL_USE_GNUTLS=ON -DCURL_USE_OPENSSL=ON -DCURL_USE_SCHANNEL=ON -DENABLE_ARES=ON -DENABLE_UNICODE=ON', + install: 'mingw-w64-i686-c-ares mingw-w64-i686-gnutls mingw-w64-i686-libssh2 mingw-w64-i686-openssl' } + fail-fast: false + steps: + - uses: msys2/setup-msys2@e9898307ac31d1a803454791be09ab9973336e1c # v2.31.1 + if: ${{ matrix.sys == 'msys' }} + with: + msystem: ${{ matrix.sys }} + # https://packages.msys2.org/search + install: >- + gcc + ${{ matrix.build }} ${{ matrix.build == 'autotools' && 'make' || 'ninja' }} + diffutils + zlib-devel + brotli-devel + libzstd-devel + libnghttp2-devel + libpsl-devel + ${{ matrix.install }} + + - uses: msys2/setup-msys2@e9898307ac31d1a803454791be09ab9973336e1c # v2.31.1 + if: ${{ matrix.sys != 'msys' }} + with: + msystem: ${{ matrix.sys }} + install: >- + mingw-w64-${{ matrix.env }}-cc + mingw-w64-${{ matrix.env }}-${{ matrix.build }} ${{ matrix.build == 'autotools' && 'make' || '' }} + mingw-w64-${{ matrix.env }}-diffutils + mingw-w64-${{ matrix.env }}-libpsl + ${{ matrix.install }} + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'autoreconf' + if: ${{ matrix.build == 'autotools' }} + timeout-minutes: 2 + run: autoreconf -fi + + - name: 'configure' + timeout-minutes: 5 + env: + CPPFLAGS: '${{ matrix.cppflags }}' + MATRIX_CHKPREFILL: '${{ matrix.chkprefill }}' + MATRIX_CONFIG: '${{ matrix.config }}' + MATRIX_ENV: '${{ matrix.env }}' + MATRIX_TYPE: '${{ matrix.type }}' + TFLAGS: '${{ matrix.tflags }}' + run: | + if [ "${MATRIX_TEST}" = 'uwp' ]; then + CPPFLAGS+=' -DWINSTORECOMPAT -DWINAPI_FAMILY=WINAPI_FAMILY_APP -D_WIN32_WINNT=0x0a00' + if [[ "${MATRIX_ENV}" != 'clang'* ]]; then + specs="$(realpath gcc-specs-uwp)" + gcc -dumpspecs | sed -e 's/-lmingwex/-lwindowsapp -lmingwex -lwindowsapp/' -e 's/-lmsvcrt/-lucrtapp/' > "${specs}" + CFLAGS="-specs=${specs}" + CFLAGS_CMAKE="-specs=$(cygpath -w "${specs}")" + fi + fi + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + for _chkprefill in '' ${MATRIX_CHKPREFILL}; do + if [[ "${MATRIX_ENV}" = 'clang'* ]]; then + options='-DCMAKE_C_COMPILER=clang' + else + options='-DCMAKE_C_COMPILER=gcc' + fi + [ "${MATRIX_SYS}" = 'msys' ] && options+=' -D_CURL_PREFILL=ON' + [ "${MATRIX_TEST}" = 'uwp' ] && options+=' -DCMAKE_SYSTEM_NAME=WindowsStore' + [ "${TFLAGS}" = 'skiprun' ] && options+=' -D_CURL_SKIP_BUILD_CERTS=ON' + [ "${_chkprefill}" = '_chkprefill' ] && options+=' -D_CURL_PREFILL=OFF' + cmake -B "bld${_chkprefill}" -G Ninja ${options} \ + -DCMAKE_INSTALL_PREFIX="${HOME}"/curl-install \ + -DCMAKE_C_FLAGS="${CFLAGS_CMAKE} ${CPPFLAGS}" \ + -DCMAKE_BUILD_TYPE="${MATRIX_TYPE}" \ + -DCMAKE_UNITY_BUILD=ON -DCMAKE_UNITY_BUILD_BATCH_SIZE=30 \ + -DCURL_WERROR=ON \ + ${MATRIX_CONFIG} + done + if [ -d bld_chkprefill ] && ! diff -u bld/lib/curl_config.h bld_chkprefill/lib/curl_config.h; then + echo '::group::reference configure log'; cat bld_chkprefill/CMakeFiles/CMake*.yaml 2>/dev/null || true; echo '::endgroup::' + false + fi + else + export CFLAGS + mkdir bld && cd bld && ../configure --prefix="$HOME"/curl-install --enable-unity --enable-warnings --enable-werror --disable-static \ + --disable-dependency-tracking --enable-option-checking=fatal \ + --with-libssh2 \ + ${MATRIX_CONFIG} + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMake*.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + cat bld/cmake_install.cmake || true + + - name: 'build' + timeout-minutes: 10 + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose + cmake --install bld --verbose + else + make -C bld V=1 install + fi + + - name: 'curl -V' + timeout-minutes: 1 + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + PATH="$PWD/bld/lib:$PATH" + else + PATH="$PWD/bld/lib/.libs:$PATH" + # avoid libtool's curl.exe wrapper for shared builds + mv bld/src/.libs/curl.exe bld/src/curl.exe || true + fi + find . \( -name '*.exe' -o -name '*.dll' -o -name '*.a' \) -print0 | grep -z curl | xargs -0 file -- + find . \( -name '*.exe' -o -name '*.dll' -o -name '*.a' \) -print0 | grep -z curl | xargs -0 stat -c '%10s bytes: %n' -- + if [ "${MATRIX_TEST}" != 'uwp' ]; then # curl: error initializing curl library + bld/src/curl.exe --disable --version + fi + + - name: 'build tests' + if: ${{ matrix.tflags != 'skipall' }} # Save time by skipping this for autotools + timeout-minutes: 10 + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target testdeps + else + make -C bld V=1 -C tests + fi + if [ "${MATRIX_BUILD}" != 'cmake' ]; then + # avoid libtool's .exe wrappers for shared builds + mv bld/tests/libtest/.libs/*.exe bld/tests/libtest || true + mv bld/tests/server/.libs/*.exe bld/tests/server || true + mv bld/tests/tunit/.libs/*.exe bld/tests/tunit || true + mv bld/tests/unit/.libs/*.exe bld/tests/unit || true + fi + + - name: 'cache test prereqs (stunnel)' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-stunnel + with: + path: C:\my-stunnel + key: ${{ runner.os }}-stunnel-${{ env.STUNNEL_VERSION }}-amd64 + fail-on-cache-miss: true + + - name: 'install test prereqs' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + timeout-minutes: 2 + run: | + if [ -z "${MATRIX_OPENSSH}" ]; then # MSYS2 openssh + /usr/bin/pacman --noconfirm --noprogressbar --sync --needed openssh + elif [ "${MATRIX_OPENSSH}" = 'OpenSSH-Windows-builtin' ]; then + # https://learn.microsoft.com/windows-server/administration/openssh/openssh_install_firstuse + if [[ "${MATRIX_IMAGE}" = *'windows-2025'* ]]; then + pwsh -Command 'Add-WindowsCapability -Online -Name OpenSSH.Client~~~~0.0.1.0' + pwsh -Command 'Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0' + fi + else # OpenSSH-Windows + cd /c # no D: drive on windows-11-arm runners + if [[ "${MATRIX_IMAGE}" = *'-arm'* ]]; then + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/PowerShell/Win32-OpenSSH/releases/download/${OPENSSH_WINDOWS_VERSION}/OpenSSH-ARM64.zip" --output pkg.bin + sha256sum pkg.bin && sha256sum pkg.bin | grep -qwF -- "${OPENSSH_WINDOWS_SHA256_ARM64}" && unzip pkg.bin && rm -f pkg.bin + else + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/PowerShell/Win32-OpenSSH/releases/download/${OPENSSH_WINDOWS_VERSION}/OpenSSH-Win64.zip" --output pkg.bin + sha256sum pkg.bin && sha256sum pkg.bin | grep -qwF -- "${OPENSSH_WINDOWS_SHA256_WIN64}" && unzip pkg.bin && rm -f pkg.bin + fi + fi + + - name: 'run tests' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + timeout-minutes: ${{ contains(matrix.tflags, '-t') && 15 || 10 }} + env: + MATRIX_ENV: '${{ matrix.env }}' + MATRIX_INSTALL: '${{ matrix.install }}' + TFLAGS: '${{ matrix.tflags }}' + run: | + TFLAGS="-j8 ${TFLAGS}" + if [ "${MATRIX_SYS}" != 'msys' ]; then + TFLAGS+=' !498' # 'Reject too large HTTP response headers on endless redirects' HTTP, HTTP GET (runtests detecting result code 2009 instead of 56 returned by curl) + TFLAGS+=' ~3000 ~3001 ~3023 ~3024' # 'HTTPS localhost, first/last subject alt name matches, CN does not match' HTTPS, HTTP GET, PEM certificate (returning 56) + if [[ "${MATRIX_INSTALL}" = *'libssh2-wincng'* ]]; then + TFLAGS+=' ~SCP ~SFTP' # Flaky: `-8, Unable to exchange encryption keys`. https://github.com/libssh2/libssh2/issues/804 + unset CURL_TEST_SSH_KEYALGO # libssh2 built with WinCNG does not support ssh-ed25519 hostkeys + export CURL_TEST_SSH_ENABLE_KEX=diffie-hellman-group-exchange-sha256 + fi + if [[ "${TFLAGS}" = *'-t'* ]]; then + TFLAGS+=' !2300' # Leaks memory and file handle via tool_doswin.c / win32_stdin_read_thread() + export CURL_TEST_NO_TASKKILL=1 # experiment to see if it reduces flaky failures + fi + if [[ "${MATRIX_INSTALL} " = *'-libssh '* && \ + "${MATRIX_ENV}" = *'x86_64'* ]]; then + export CURL_TEST_SSH_DISABLE_KEX=mlkem768x25519-sha256 # broken with libssh 0.12.0 Windows x64 + fi + fi + if [ -n "${MATRIX_OPENSSH}" ]; then # OpenSSH-Windows + TFLAGS+=' ~601 ~603 ~617 ~619 ~621 ~641 ~665 ~2004 ~3022' # SCP + if [[ "${MATRIX_INSTALL} " = *'libssh '* ]]; then + TFLAGS+=' ~614' # 'SFTP pre-quote chmod' SFTP, pre-quote, directory + fi + fi + if [ "${MATRIX_OPENSSH}" = 'OpenSSH-Windows' ]; then + if [[ "${MATRIX_IMAGE}" = *'-arm'* ]]; then + PATH="/c/OpenSSH-ARM64:$PATH" + else + PATH="/c/OpenSSH-Win64:$PATH" + fi + fi + if [ -x "$(cygpath "${SYSTEMROOT}/System32/curl.exe")" ]; then + TFLAGS+=" -ac $(cygpath "${SYSTEMROOT}/System32/curl.exe")" + fi + PATH="$PATH:/c/my-stunnel/bin" + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + PATH="$PWD/bld/lib:$PATH" + cmake --build bld --verbose --target test-ci + else + PATH="$PWD/bld/lib/.libs:$PATH" + make -C bld V=1 test-ci + fi + + - name: 'build examples' + if: ${{ matrix.build == 'cmake' || (matrix.tflags == 'skipall' || matrix.tflags == 'skiprun') }} # Save time by skipping this for autotools running tests + timeout-minutes: 5 + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --verbose --target curl-examples-build + else + make -C bld V=1 examples + fi + + - name: 'disk space used' + run: du -sh .; echo; du -sh -t 250KB ./*; echo; du -h -t 250KB bld + + mingw-w64-standalone-downloads: + name: 'dl-mingw, CM ${{ matrix.ver }}-${{ matrix.env }} ${{ matrix.name }}' + needs: build-cache + runs-on: windows-2022 + timeout-minutes: 10 + defaults: + run: + shell: msys2 {0} # zizmor: ignore[misfeature] + env: + CURL_TEST_MIN: 1630 + LDFLAGS: -s + MAKEFLAGS: -j 5 + MATRIX_DIR: '${{ matrix.dir }}' + strategy: + matrix: + include: + - name: 'schannel +analyzer' # mingw-w64 14.0 + sys: 'mingw64' + dir: 'w64devkit' + env: 'x86_64' + ver: '16.1.0' + url: 'https://github.com/skeeto/w64devkit/releases/download/v2.8.0/w64devkit-x64-2.8.0.7z.exe' + SHA256: 6252bf34fe2231a55ac7f03d482b36d2c7c58697990551bba508102cfb3f342e + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DCURL_USE_SCHANNEL=ON -DENABLE_UNICODE=OFF -DENABLE_UNIX_SOCKETS=OFF -DCURL_GCC_ANALYZER=ON' + type: 'Release' + - name: 'schannel' # mingw-w64 10.0 + sys: 'mingw64' + dir: 'mingw64' + env: 'x86_64' + ver: '9.5.0' + url: 'https://github.com/brechtsanders/winlibs_mingw/releases/download/9.5.0-10.0.0-msvcrt-r1/winlibs-x86_64-posix-seh-gcc-9.5.0-mingw-w64msvcrt-10.0.0-r1.7z' + SHA256: 41637132ea7dc36a7f86a1961eaa334c380b5a3423d36aecb481cabcd006e3fe + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DCURL_USE_SCHANNEL=ON -DENABLE_UNICODE=OFF -DCURL_DISABLE_VERBOSE_STRINGS=ON' + type: 'Release' + tflags: 'skiprun' + - name: 'schannel mbedtls U' # mingw-w64 6.0 + sys: 'mingw64' + dir: 'mingw64' + env: 'x86_64' + ver: '7.3.0' + url: 'https://downloads.sourceforge.net/mingw-w64/Toolchains%20targetting%20Win64/Personal%20Builds/mingw-builds/7.3.0/threads-win32/seh/x86_64-7.3.0-release-win32-seh-rt_v5-rev0.7z' + SHA256: 9dc08c9c2bdd5d8173f87791bed644f6e290624f739de474f117b590dfd8a721 + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DCURL_USE_SCHANNEL=ON -DENABLE_UNICODE=ON -DCURL_USE_MBEDTLS=ON -DCURL_TARGET_WINDOWS_VERSION=0x0600' + install: mingw-w64-x86_64-mbedtls + type: 'Release' + tflags: 'skiprun' + - name: 'schannel !unity' # mingw-w64 5.0 + sys: 'mingw32' + dir: 'mingw32' + env: 'i686' + ver: '6.4.0' + url: 'https://downloads.sourceforge.net/mingw-w64/Toolchains%20targetting%20Win32/Personal%20Builds/mingw-builds/6.4.0/threads-win32/dwarf/i686-6.4.0-release-win32-dwarf-rt_v5-rev0.7z' + SHA256: 12d2c62ad4527ec8a52275ea8485678dcbe20bec4716a3c7ba274f225d696085 + config: '-DENABLE_DEBUG=ON -DCURL_USE_SCHANNEL=ON -DCURL_USE_LIBSSH=ON -DENABLE_UNICODE=OFF -DCMAKE_UNITY_BUILD=OFF -DCURL_TARGET_WINDOWS_VERSION=0x0600' + install: mingw-w64-i686-libssh + type: 'Debug' + tflags: 'skiprun' + - name: 'schannel !examples' # mingw-w64 3.0 + sys: 'mingw64' + dir: 'mingw64' + env: 'x86_64' + ver: '4.8.1' + url: 'https://downloads.sourceforge.net/mingw-w64/Toolchains%20targetting%20Win64/Personal%20Builds/mingw-builds/4.8.1/threads-win32/seh/x86_64-4.8.1-release-win32-seh-rt_v3-rev2.7z' + SHA256: 1353d997e85bb4494ebbebb432d824848d66b32c6045900da9a38a767b3c4ab4 + config: '-DENABLE_DEBUG=ON -DBUILD_SHARED_LIBS=OFF -DCURL_USE_SCHANNEL=ON -DCURL_TARGET_WINDOWS_VERSION=0x0600' + type: 'Debug' + tflags: 'skipall' + chkprefill: '' # Set it once to silence actionlint + fail-fast: false + steps: + - uses: msys2/setup-msys2@e9898307ac31d1a803454791be09ab9973336e1c # v2.31.1 + with: + msystem: ${{ matrix.sys }} + release: false + update: false + cache: false + path-type: inherit + install: >- + mingw-w64-${{ matrix.env }}-libpsl + ${{ matrix.install }} + + - name: 'cache compiler (gcc ${{ matrix.ver }}-${{ matrix.env }})' + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-compiler + with: + path: D:\my-cache + key: ${{ runner.os }}-mingw-w64-${{ matrix.ver }}-${{ matrix.env }} + + - name: 'install compiler (gcc ${{ matrix.ver }}-${{ matrix.env }})' + if: ${{ !steps.cache-compiler.outputs.cache-hit }} + timeout-minutes: 5 + env: + MATRIX_URL: '${{ matrix.url }}' + MATRIX_SHA256: '${{ matrix.SHA256 }}' + run: | + cd /d + mkdir my-cache + cd my-cache + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 240 --retry 3 --retry-connrefused \ + --location --proto-redir =https "${MATRIX_URL}" --output pkg.bin + pwd + sha256sum pkg.bin && sha256sum pkg.bin | grep -qwF -- "${MATRIX_SHA256}" && 7z x -y pkg.bin >/dev/null && rm -f pkg.bin && ls -l + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'configure' + timeout-minutes: 5 + env: + MATRIX_CHKPREFILL: '${{ matrix.chkprefill }}' + MATRIX_CONFIG: '${{ matrix.config }}' + MATRIX_TYPE: '${{ matrix.type }}' + TFLAGS: '${{ matrix.tflags }}' + run: | + PATH="/d/my-cache/${MATRIX_DIR}/bin:$PATH" + for _chkprefill in '' ${MATRIX_CHKPREFILL}; do + options='' + [ "${TFLAGS}" = 'skiprun' ] && options+=' -D_CURL_SKIP_BUILD_CERTS=ON' + [ "${_chkprefill}" = '_chkprefill' ] && options+=' -D_CURL_PREFILL=OFF' + cmake -B "bld${_chkprefill}" -G Ninja ${options} \ + -DCMAKE_C_COMPILER=gcc \ + -DCMAKE_BUILD_TYPE="${MATRIX_TYPE}" \ + -DCMAKE_UNITY_BUILD=ON -DCMAKE_UNITY_BUILD_BATCH_SIZE=30 \ + -DCURL_DROP_UNUSED=ON \ + -DCURL_WERROR=ON \ + -DUSE_LIBIDN2=OFF \ + ${MATRIX_CONFIG} + done + if [ -d bld_chkprefill ] && ! diff -u bld/lib/curl_config.h bld_chkprefill/lib/curl_config.h; then + echo '::group::reference configure log'; cat bld_chkprefill/CMakeFiles/CMake*.yaml 2>/dev/null || true; echo '::endgroup::' + false + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/CMakeFiles/CMake*.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'build' + timeout-minutes: 5 + run: | + PATH="/d/my-cache/${MATRIX_DIR}/bin:$PATH" + cmake --build bld + + - name: 'curl -V' + timeout-minutes: 1 + run: | + /usr/bin/find . \( -name '*.exe' -o -name '*.dll' -o -name '*.a' \) -print0 | grep -z curl | xargs -0 file -- + /usr/bin/find . \( -name '*.exe' -o -name '*.dll' -o -name '*.a' \) -print0 | grep -z curl | xargs -0 stat -c '%10s bytes: %n' -- + PATH="$PWD/bld/lib:$PATH" + bld/src/curl.exe --disable --version + + - name: 'build tests' + if: ${{ matrix.tflags != 'skipall' }} + timeout-minutes: 10 + run: | + PATH="/d/my-cache/${MATRIX_DIR}/bin:$PATH" + cmake --build bld --target testdeps + + - name: 'cache test prereqs (stunnel)' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-stunnel + with: + path: C:\my-stunnel + key: ${{ runner.os }}-stunnel-${{ env.STUNNEL_VERSION }}-amd64 + fail-on-cache-miss: true + + - name: 'install test prereqs' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + timeout-minutes: 2 + run: | + if bld/src/curl.exe --disable -V 2>/dev/null | grep smb; then + python3 -m pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r tests/requirements.txt + fi + + - name: 'run tests' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + timeout-minutes: 10 + env: + TFLAGS: '${{ matrix.tflags }}' + run: | + PATH="/d/my-cache/${MATRIX_DIR}/bin:$PATH" + TFLAGS="-j8 ${TFLAGS}" + TFLAGS+=' !498' # 'Reject too large HTTP response headers on endless redirects' HTTP, HTTP GET (runtests detecting result code 2009 instead of 56 returned by curl) + TFLAGS+=' ~3000 ~3001 ~3023 ~3024' # 'HTTPS localhost, last subject alt name matches, CN does not match' HTTPS, HTTP GET, PEM certificate (returning 56) + if [ -x "$(cygpath "${SYSTEMROOT}/System32/curl.exe")" ]; then + TFLAGS+=" -ac $(cygpath "${SYSTEMROOT}/System32/curl.exe")" + fi + PATH="$PWD/bld/lib:$PATH:/c/my-stunnel/bin" + cmake --build bld --target test-ci + + - name: 'build examples' + if: ${{ !contains(matrix.name, '!examples') }} + timeout-minutes: 5 + run: | + PATH="/d/my-cache/${MATRIX_DIR}/bin:$PATH" + cmake --build bld --target curl-examples-build + + - name: 'disk space used' + run: du -sh .; echo; du -sh -t 250KB ./*; echo; du -h -t 250KB bld + + linux-cross-mingw-w64: + name: "linux-mingw, ${{ matrix.build == 'cmake' && 'CM' || 'AM' }} ${{ matrix.compiler }}" + runs-on: ubuntu-26.04 + timeout-minutes: 10 + env: + LDFLAGS: -s + MAKEFLAGS: -j 5 + TRIPLET: 'x86_64-w64-mingw32' + MATRIX_BUILD: '${{ matrix.build }}' + MATRIX_COMPILER: '${{ matrix.compiler }}' + strategy: + fail-fast: false + matrix: + include: + - { build: 'autotools', compiler: 'gcc' } + - { build: 'cmake' , compiler: 'gcc' } + - { build: 'cmake' , compiler: 'clang-tidy', install_packages: 'clang-22 clang-tidy-22', CFLAGS: '-Wunused-macros' } + steps: + - name: 'install packages' + timeout-minutes: 2 + env: + MATRIX_INSTALL_PACKAGES: '${{ matrix.install_packages }}' + run: | + ls -l /etc/apt/sources.list.d + sudo find /etc/apt/sources.list.d -type f -not -name 'ubuntu.sources' -delete -print + sudo sed -i 's/priority:1/priority:9/' /etc/apt/apt-mirrors.txt; cat /etc/apt/apt-mirrors.txt + sudo apt-get -o Dpkg::Use-Pty=0 update + sudo apt-get -o Dpkg::Use-Pty=0 install gcc-mingw-w64-x86-64-win32 ${MATRIX_INSTALL_PACKAGES} + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'autoreconf' + if: ${{ matrix.build == 'autotools' }} + run: autoreconf -fi + + - name: 'configure' + env: + CFLAGS: '${{ matrix.CFLAGS }}' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + if [ "${MATRIX_COMPILER}" = 'clang-tidy' ]; then + options+=' -DCURL_CLANG_TIDY=ON -DCLANG_TIDY=/usr/bin/clang-tidy-22' + options+=' -DENABLE_UNICODE=ON -DUSE_SSLS_EXPORT=ON' + options+=' -DCMAKE_C_COMPILER=clang-22' + options+=" -DCMAKE_RC_COMPILER=llvm-windres-$(clang-22 -dumpversion | cut -d '.' -f 1)" + else + options+=" -DCMAKE_C_COMPILER=${TRIPLET}-gcc" + fi + cmake -B bld -G Ninja \ + -DCMAKE_SYSTEM_NAME=Windows \ + -DCMAKE_C_COMPILER_TARGET="${TRIPLET}" \ + -DCMAKE_UNITY_BUILD=ON -D_CURL_TESTS_CONCAT=ON \ + -DCURL_WERROR=ON \ + -DCURL_USE_SCHANNEL=ON -DUSE_WIN32_IDN=ON \ + -DCURL_USE_LIBPSL=OFF \ + -DCURL_ENABLE_NTLM=ON \ + -D_CURL_SKIP_BUILD_CERTS=ON \ + ${options} + else + mkdir bld && cd bld && ../configure --enable-unity --enable-warnings --enable-werror --disable-static \ + --disable-dependency-tracking --enable-option-checking=fatal \ + --host="${TRIPLET}" \ + --with-schannel --with-winidn \ + --without-libpsl + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/config.log bld/CMakeFiles/CMake*.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'build' + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld + else + make -C bld + fi + + - name: 'curl info' + run: | + find . \( -name '*.exe' -o -name '*.dll' -o -name '*.a' \) -print0 | grep -z curl | xargs -0 file -- + find . \( -name '*.exe' -o -name '*.dll' -o -name '*.a' \) -print0 | grep -z curl | xargs -0 stat -c '%10s bytes: %n' -- + + - name: 'build tests' + if: ${{ matrix.build == 'cmake' }} # Save time by skipping this for autotools and clang-tidy + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target testdeps + else + make -C bld -C tests + fi + + - name: 'build examples' + if: ${{ matrix.compiler != 'clang-tidy' }} # Save time by skipping this for clang-tidy + run: | + if [ "${MATRIX_BUILD}" = 'cmake' ]; then + cmake --build bld --target curl-examples-build + else + make -C bld examples + fi + + - name: 'disk space used' + run: du -sh .; echo; du -sh -t 250KB ./*; echo; du -h -t 250KB bld + + msvc: + name: 'msvc, CM ${{ matrix.arch }}-${{ matrix.plat }} ${{ matrix.name }}' + needs: build-cache + runs-on: ${{ matrix.image || 'windows-2022' }} + timeout-minutes: ${{ matrix.arch == 'arm64' && 12 || 10 }} + defaults: + run: + shell: msys2 {0} # zizmor: ignore[misfeature] + env: + MATRIX_ARCH: '${{ matrix.arch }}' + MATRIX_IMAGE: '${{ matrix.image }}' + MATRIX_INSTALL_MSYS2: '${{ matrix.install-msys2 }}' + MATRIX_INSTALL_VCPKG: '${{ matrix.install-vcpkg }}' + MATRIX_OPENSSH: '${{ matrix.openssh }}' + MATRIX_PLAT: '${{ matrix.plat }}' + MATRIX_TYPE: '${{ matrix.type }}' + VCPKG_DISABLE_METRICS: '1' + strategy: + matrix: + include: + - name: '!ssl +examples' + install-vcpkg: 'zlib libssh2[core,zlib]' + arch: 'x64' + env: 'ucrt-x86_64' + plat: 'uwp' + type: 'Debug' + image: 'windows-2025' + tflags: 'skiprun' + config: >- + -DENABLE_DEBUG=ON + -DCURL_ENABLE_SSL=OFF + -DUSE_WIN32_IDN=ON + + - name: 'openssl +examples' + install-msys2: >- + mingw-w64-ucrt-x86_64-brotli + mingw-w64-ucrt-x86_64-zlib + mingw-w64-ucrt-x86_64-zstd + mingw-w64-ucrt-x86_64-openssl + mingw-w64-ucrt-x86_64-libssh2 + mingw-w64-ucrt-x86_64-nghttp2 + mingw-w64-ucrt-x86_64-nghttp3 + mingw-w64-ucrt-x86_64-ngtcp2 + + arch: 'x64' + env: 'ucrt-x86_64' + plat: 'windows' + type: 'Debug' + image: 'windows-2025' + chkprefill: '_chkprefill' + tflags: '--min=1850' + config: >- + -DENABLE_DEBUG=ON + -DCURL_USE_OPENSSL=ON -DUSE_NGTCP2=ON + -DOPENSSL_INCLUDE_DIR=/ucrt64/include + -DSSL_EAY_DEBUG=/ucrt64/lib/libssl.dll.a + -DSSL_EAY_RELEASE=/ucrt64/lib/libssl.dll.a + -DLIB_EAY_DEBUG=/ucrt64/lib/libcrypto.dll.a + -DLIB_EAY_RELEASE=/ucrt64/lib/libcrypto.dll.a + -DUSE_WIN32_IDN=ON -DUSE_SSLS_EXPORT=ON + -DBROTLI_INCLUDE_DIR=/ucrt64/include + -DBROTLICOMMON_LIBRARY=/ucrt64/lib/libbrotlicommon.dll.a + -DBROTLIDEC_LIBRARY=/ucrt64/lib/libbrotlidec.dll.a + -DZSTD_INCLUDE_DIR=/ucrt64/include + -DZSTD_LIBRARY=/ucrt64/lib/libzstd.dll.a + -DZLIB_INCLUDE_DIR=/ucrt64/include + -DZLIB_LIBRARY=/ucrt64/lib/libz.dll.a + -DLIBSSH2_INCLUDE_DIR=/ucrt64/include + -DLIBSSH2_LIBRARY=/ucrt64/lib/libssh2.dll.a + -DNGHTTP2_INCLUDE_DIR=/ucrt64/include + -DNGHTTP2_LIBRARY=/ucrt64/lib/libnghttp2.dll.a + -DNGHTTP3_INCLUDE_DIR=/ucrt64/include + -DNGHTTP3_LIBRARY=/ucrt64/lib/libnghttp3.dll.a + -DNGTCP2_INCLUDE_DIR=/ucrt64/include + -DNGTCP2_LIBRARY=/ucrt64/lib/libngtcp2.dll.a + -DNGTCP2_CRYPTO_OSSL_LIBRARY=/ucrt64/lib/libngtcp2_crypto_ossl.dll.a + -DCURL_CA_NATIVE=ON + -DCURL_ENABLE_NTLM=ON -DUSE_PROXY_HTTP3=ON + + - name: 'schannel U' + install-vcpkg: 'zlib libssh2[core,zlib]' + arch: 'arm64' + env: 'clang-aarch64' + plat: 'windows' + type: 'Debug' + image: 'windows-11-arm' + openssh: 'OpenSSH-Windows' + tflags: '--min=1720' + # leave SMB disabled to save 30-60 seconds by omitting prereqs, + # to counteract the slower test run step + config: >- + -DENABLE_DEBUG=ON + -DCURL_USE_SCHANNEL=ON + -DUSE_WIN32_IDN=ON -DENABLE_UNICODE=ON -DUSE_SSLS_EXPORT=ON + + fail-fast: false + steps: + - uses: msys2/setup-msys2@e9898307ac31d1a803454791be09ab9973336e1c # v2.31.1 + with: + msystem: ${{ matrix.arch == 'arm64' && 'clangarm64' || 'ucrt64' }} + release: ${{ contains(matrix.image, 'arm') }} + cache: ${{ contains(matrix.image, 'arm') }} + path-type: inherit + install: >- + mingw-w64-${{ matrix.env }}-libpsl + ${{ matrix.install-msys2 }} + + - name: 'vcpkg versions' + if: ${{ matrix.install-vcpkg }} + timeout-minutes: 1 + run: | + git -C "$VCPKG_INSTALLATION_ROOT" show --no-patch --format='%H %ai' + vcpkg version + + - name: 'vcpkg build' + if: ${{ matrix.install-vcpkg }} + timeout-minutes: 45 + run: vcpkg x-set-installed ${MATRIX_INSTALL_VCPKG} --triplet="${MATRIX_ARCH}-${MATRIX_PLAT}" + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: 'configure' + timeout-minutes: 5 + env: + MATRIX_CHKPREFILL: '${{ matrix.chkprefill }}' + MATRIX_CONFIG: '${{ matrix.config }}' + TFLAGS: '${{ matrix.tflags }}' + run: | + [ -f "${MINGW_PREFIX}/include/zconf.h" ] && sed -i -E 's|(# +define +Z_HAVE_UNISTD_H)|/*\1*/|g' "${MINGW_PREFIX}/include/zconf.h" # Patch MSYS2 zconf.h for MSVC + for _chkprefill in '' ${MATRIX_CHKPREFILL}; do + options='' + cflags='' + rcflags='' + ldflags='' + if [ "${MATRIX_PLAT}" = 'uwp' ]; then + options+=' -DCMAKE_SYSTEM_NAME=WindowsStore -DCMAKE_SYSTEM_VERSION=10.0' + cflags+=' -DWINAPI_FAMILY=WINAPI_FAMILY_PC_APP' + ldflags+=' -OPT:NOREF -OPT:NOICF -APPCONTAINER:NO' + vsglobals=';AppxPackage=false;WindowsAppContainer=false' + fi + if [ "${TFLAGS}" = 'skiprun' ]; then + [ "${MATRIX_ARCH}" = 'arm64' ] && options+=' -A ARM64' + [ "${MATRIX_ARCH}" = 'x64' ] && options+=' -A x64' + [ "${MATRIX_ARCH}" = 'x86' ] && options+=' -A Win32' + options+=" -DCMAKE_VS_GLOBALS=TrackFileAccess=false${vsglobals}" + options+=' -D_CURL_SKIP_BUILD_CERTS=ON' + unset CMAKE_GENERATOR + else + # Use Ninja when running tests to avoid MSBuild heuristics picking + # up "error messages" in the test log output and making the job fail. + # Officially this requires the vcvarsall.bat MS-DOS batch file (as of + # VS2022). Since it integrates badly with CI steps and shell scripts, + # reproduce the necessary build configuration manually, without envs. + MSVC_EDITION='2022/Enterprise/vc/tools/msvc' + [[ "${MATRIX_IMAGE}" = *'windows-2025'* ]] && MSVC_EDITION='18/Enterprise/vc/tools/msvc' + [[ "$(uname -s)" = *'ARM64'* ]] && MSVC_HOST='arm64' || MSVC_HOST='x64' # x86 + MSVC_ROOTD="$(cygpath --mixed --short-name "$PROGRAMFILES/Microsoft Visual Studio")" # to avoid spaces in directory names + MSVC_ROOTU="$(/usr/bin/find "$(cygpath --unix "$MSVC_ROOTD/$MSVC_EDITION")" -mindepth 1 -maxdepth 1 -type d -name '*.*' | sort | tail -n 1)" + MSVC_ROOTW="$(cygpath --mixed "$MSVC_ROOTU")" + MSVC_ROOTU="$(cygpath --unix "$MSVC_ROOTW")" + MSVC_BINU="$MSVC_ROOTU/bin/Host$MSVC_HOST/$MATRIX_ARCH" + MSDK_ROOTW="$(cygpath --mixed --short-name "$(printenv 'ProgramFiles(x86)')/Windows Kits")/10" + MSDK_ROOTU="$(cygpath --unix "$MSDK_ROOTW")" + MSDK_VER="$(basename "$(/usr/bin/find "$MSDK_ROOTU/lib" -mindepth 1 -maxdepth 1 -type d -name '*.*' | sort | tail -n 1)")" + MSDK_LIBW="$MSDK_ROOTW/lib/$MSDK_VER" + MSDK_INCW="$MSDK_ROOTW/include/$MSDK_VER" + MSDK_BINU="$MSDK_ROOTU/bin/$MSDK_VER/$MSVC_HOST" + cflags+=" -external:W0" + cflags+=" -external:I$MSVC_ROOTW/include" + cflags+=" -external:I$MSDK_INCW/shared" + cflags+=" -external:I$MSDK_INCW/ucrt" + cflags+=" -external:I$MSDK_INCW/um" + cflags+=" -external:I$MSDK_INCW/km" + rcflags+=" -I$MSDK_INCW/shared" + rcflags+=" -I$MSDK_INCW/um" + ldflags+=" -libpath:$MSVC_ROOTW/lib/$MATRIX_ARCH" + ldflags+=" -libpath:$MSDK_LIBW/ucrt/$MATRIX_ARCH" + ldflags+=" -libpath:$MSDK_LIBW/um/$MATRIX_ARCH" + ldflags+=" -libpath:$MSDK_LIBW/km/$MATRIX_ARCH" + options+=" -DCMAKE_RC_COMPILER=$MSDK_BINU/rc.exe" + options+=" -DCMAKE_MT=$MSDK_BINU/mt.exe" + options+=" -DCMAKE_C_COMPILER=$MSVC_BINU/cl.exe" + export CMAKE_GENERATOR='Ninja Multi-Config' # pass it via env to avoid space issues + echo "Using MSVC: ${MSVC_ROOTW}" + echo "Using Windows SDK: ${MSDK_VER}" + fi + [ "${_chkprefill}" = '_chkprefill' ] && options+=' -D_CURL_PREFILL=OFF' + if [ -n "${MATRIX_INSTALL_VCPKG}" ]; then + options+=" -DCMAKE_TOOLCHAIN_FILE=$VCPKG_INSTALLATION_ROOT/scripts/buildsystems/vcpkg.cmake" + options+=" -DVCPKG_INSTALLED_DIR=$VCPKG_INSTALLATION_ROOT/installed" + options+=" -DVCPKG_TARGET_TRIPLET=${MATRIX_ARCH}-${MATRIX_PLAT}" + options+=" -DCMAKE_C_COMPILER_TARGET=${MATRIX_ARCH}-${MATRIX_PLAT}" + fi + cmake -B "bld${_chkprefill}" ${options} \ + -DCMAKE_C_FLAGS="${cflags}" \ + -DCMAKE_RC_FLAGS="${rcflags}" \ + -DCMAKE_EXE_LINKER_FLAGS="-INCREMENTAL:NO ${ldflags}" \ + -DCMAKE_SHARED_LINKER_FLAGS="-INCREMENTAL:NO ${ldflags}" \ + -DCMAKE_UNITY_BUILD=ON \ + -DCURL_DROP_UNUSED=ON \ + -DCURL_WERROR=ON \ + -DLIBPSL_INCLUDE_DIR="${MINGW_PREFIX}/include" \ + -DLIBPSL_LIBRARY="${MINGW_PREFIX}/lib/libpsl.dll.a" \ + -DBUILD_SHARED_LIBS=OFF \ + ${MATRIX_CONFIG} + done + if [ -d bld_chkprefill ] && ! diff -u bld/lib/curl_config.h bld_chkprefill/lib/curl_config.h; then + echo '::group::reference configure log'; cat bld_chkprefill/CMakeFiles/CMake*.yaml 2>/dev/null || true; echo '::endgroup::' + false + fi + + - name: 'configure log' + if: ${{ !cancelled() }} + run: cat bld/CMakeFiles/CMake*.yaml 2>/dev/null || true + + - name: 'curl_config.h' + run: | + echo '::group::raw'; cat bld/lib/curl_config.h || true; echo '::endgroup::' + grep -F '#define' bld/lib/curl_config.h | sort || true + + - name: 'build' + timeout-minutes: 5 + run: cmake --build bld --config "${MATRIX_TYPE}" --parallel 5 + + - name: 'curl -V' + timeout-minutes: 1 + run: | + /usr/bin/find . \( -name '*.exe' -o -name '*.dll' -o -name '*.lib' -o -name '*.pdb' \) -print0 | grep -z curl | xargs -0 file -- + /usr/bin/find . \( -name '*.exe' -o -name '*.dll' -o -name '*.lib' -o -name '*.pdb' \) -print0 | grep -z curl | xargs -0 stat -c '%10s bytes: %n' -- + if [ "${MATRIX_PLAT}" != 'uwp' ]; then # Missing: ucrtbased.dll, VCRUNTIME140D.dll, VCRUNTIME140D_APP.dll + PATH="$PWD/bld/lib/${MATRIX_TYPE}:$PATH" + "bld/src/${MATRIX_TYPE}/curl.exe" --disable --version + fi + + - name: 'build tests' + if: ${{ matrix.tflags != 'skipall' }} + timeout-minutes: 10 + run: cmake --build bld --config "${MATRIX_TYPE}" --parallel 5 --target testdeps + + - name: 'cache test prereqs (stunnel)' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + id: cache-stunnel + with: + path: C:\my-stunnel + key: ${{ runner.os }}-stunnel-${{ env.STUNNEL_VERSION }}-amd64 + fail-on-cache-miss: true + + - name: 'install test prereqs' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + timeout-minutes: 2 + run: | + if [ -z "${MATRIX_OPENSSH}" ]; then # MSYS2 openssh + /usr/bin/pacman --noconfirm --noprogressbar --sync --needed openssh + elif [ "${MATRIX_OPENSSH}" = 'OpenSSH-Windows-builtin' ]; then + # https://learn.microsoft.com/windows-server/administration/openssh/openssh_install_firstuse + if [[ "${MATRIX_IMAGE}" = *'windows-2025'* ]]; then + pwsh -Command 'Add-WindowsCapability -Online -Name OpenSSH.Client~~~~0.0.1.0' + pwsh -Command 'Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0' + fi + else # OpenSSH-Windows + cd /c # no D: drive on windows-11-arm runners + if [[ "${MATRIX_IMAGE}" = *'-arm'* ]]; then + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/PowerShell/Win32-OpenSSH/releases/download/${OPENSSH_WINDOWS_VERSION}/OpenSSH-ARM64.zip" --output pkg.bin + sha256sum pkg.bin && sha256sum pkg.bin | grep -qwF -- "${OPENSSH_WINDOWS_SHA256_ARM64}" && unzip pkg.bin && rm -f pkg.bin + else + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/PowerShell/Win32-OpenSSH/releases/download/${OPENSSH_WINDOWS_VERSION}/OpenSSH-Win64.zip" --output pkg.bin + sha256sum pkg.bin && sha256sum pkg.bin | grep -qwF -- "${OPENSSH_WINDOWS_SHA256_WIN64}" && unzip pkg.bin && rm -f pkg.bin + fi + fi + if "bld/src/${MATRIX_TYPE}/curl.exe" --disable -V 2>/dev/null | grep smb; then + python3 -m pip --disable-pip-version-check --no-input --no-cache-dir install --progress-bar off --prefer-binary -r tests/requirements.txt + fi + + - name: 'run tests' + if: ${{ matrix.tflags != 'skipall' && matrix.tflags != 'skiprun' }} + timeout-minutes: 10 + env: + TFLAGS: '${{ matrix.tflags }}' + run: | + TFLAGS="-j8 ${TFLAGS}" + TFLAGS+=' !498' # 'Reject too large HTTP response headers on endless redirects' HTTP, HTTP GET (runtests detecting result code 2009 instead of 56 returned by curl) + TFLAGS+=' ~3000 ~3001 ~3023 ~3024' # 'HTTPS localhost, last subject alt name matches, CN does not match' HTTPS, HTTP GET, PEM certificate (returning 56) + if [[ "${MATRIX_INSTALL_MSYS2}" = *'libssh2-wincng'* || \ + "${MATRIX_INSTALL_VCPKG}" = *'libssh2[core,zlib]'* ]]; then + TFLAGS+=' ~SCP ~SFTP' # Flaky: `-8, Unable to exchange encryption keys`. https://github.com/libssh2/libssh2/issues/804 + unset CURL_TEST_SSH_KEYALGO # libssh2 built with WinCNG does not support ssh-ed25519 hostkeys + export CURL_TEST_SSH_ENABLE_KEX=diffie-hellman-group-exchange-sha256 + fi + if [ -n "${MATRIX_OPENSSH}" ]; then # OpenSSH-Windows + TFLAGS+=' ~601 ~603 ~617 ~619 ~621 ~641 ~665 ~2004' # SCP + if [[ "${MATRIX_INSTALL_MSYS2} " = *'libssh '* || \ + "${MATRIX_INSTALL_VCPKG} " = *'libssh '* ]]; then + TFLAGS+=' ~614' # 'SFTP pre-quote chmod' SFTP, pre-quote, directory + else + TFLAGS+=' ~3022' # 'SCP correct sha256 host key' SCP, server sha256 key check + fi + fi + if [ "${MATRIX_OPENSSH}" = 'OpenSSH-Windows' ]; then + if [[ "${MATRIX_IMAGE}" = *'-arm'* ]]; then + PATH="/c/OpenSSH-ARM64:$PATH" + else + PATH="/c/OpenSSH-Win64:$PATH" + fi + fi + PATH="$PWD/bld/lib/${MATRIX_TYPE}:$PATH:/c/my-stunnel/bin" + cmake --build bld --config "${MATRIX_TYPE}" --target test-ci + + - name: 'build examples' + timeout-minutes: 5 + if: ${{ contains(matrix.name, '+examples') }} + run: cmake --build bld --config "${MATRIX_TYPE}" --parallel 5 --target curl-examples-build + + - name: 'disk space used' + run: du -sh .; echo; du -sh -t 250KB ./*; echo; du -h -t 250KB bld diff --git a/third-party/curl/.github/workflows/wolfssl.yml b/third-party/curl/.github/workflows/wolfssl.yml deleted file mode 100644 index 53ed0cc857..0000000000 --- a/third-party/curl/.github/workflows/wolfssl.yml +++ /dev/null @@ -1,105 +0,0 @@ -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -name: Linux wolfSSL - -on: - push: - branches: - - master - - '*/ci' - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - pull_request: - branches: - - master - paths-ignore: - - '**/*.md' - - '**/CMakeLists.txt' - - '.azure-pipelines.yml' - - '.circleci/**' - - '.cirrus.yml' - - 'appveyor.yml' - - 'CMake/**' - - 'packages/**' - - 'plan9/**' - - 'projects/**' - - 'winbuild/**' - -concurrency: - # Hardcoded workflow filename as workflow name above is just Linux again - group: wolfssl-${{ github.event.pull_request.number || github.sha }} - cancel-in-progress: true - -permissions: {} - -env: - MAKEFLAGS: -j 3 - -jobs: - autotools: - name: ${{ matrix.build.name }} - runs-on: 'ubuntu-latest' - timeout-minutes: 60 - strategy: - fail-fast: false - matrix: - build: - - name: wolfssl (configured with --enable-all) - install: - configure: LDFLAGS="-Wl,-rpath,$HOME/wssl/lib" --with-wolfssl=$HOME/wssl --enable-debug - wolfssl-configure: --enable-all - - name: wolfssl (configured with --enable-opensslextra) - install: - configure: LDFLAGS="-Wl,-rpath,$HOME/wssl/lib" --with-wolfssl=$HOME/wssl --enable-debug - wolfssl-configure: --enable-opensslextra - - steps: - - run: | - sudo apt-get update - sudo apt-get install libtool autoconf automake pkg-config stunnel4 ${{ matrix.build.install }} - sudo python3 -m pip install impacket - name: 'install prereqs and impacket' - - - run: | - WOLFSSL_VER=5.6.3 - curl -LOsSf --retry 6 --retry-connrefused --max-time 999 https://github.com/wolfSSL/wolfssl/archive/v$WOLFSSL_VER-stable.tar.gz - tar -xzf v$WOLFSSL_VER-stable.tar.gz - cd wolfssl-$WOLFSSL_VER-stable - ./autogen.sh - ./configure --enable-tls13 ${{ matrix.build.wolfssl-configure }} --enable-harden --prefix=$HOME/wssl - make install - name: 'install wolfssl' - - - uses: actions/checkout@v3 - - - run: autoreconf -fi - name: 'autoreconf' - - - run: ./configure --enable-warnings --enable-werror ${{ matrix.build.configure }} - name: 'configure' - - - run: make V=1 - name: 'make' - - - run: make V=1 examples - name: 'make examples' - - - run: make V=1 -C tests - name: 'make tests' - - - run: make V=1 test-ci - name: 'run tests' - env: - TFLAGS: "${{ matrix.build.tflags }}" diff --git a/third-party/curl/.gitignore b/third-party/curl/.gitignore index 2d5c292325..0ac1002956 100644 --- a/third-party/curl/.gitignore +++ b/third-party/curl/.gitignore @@ -8,11 +8,15 @@ *.exp *.la *.lib +*.a +*.res *.lo *.o *.obj *.pdb *.pyc +*.orig +*.rej *~ .*.sw? .cproject @@ -24,10 +28,8 @@ /.vs /bld/ /build/ -/builds/ /stats/ __pycache__ -CHANGES.dist Debug INSTALL Makefile @@ -37,6 +39,9 @@ TAGS aclocal.m4 aclocal.m4.bak autom4te.cache +buildinfo.txt +ca-bundle.crt +certdata.txt compile config.cache config.guess @@ -58,6 +63,7 @@ missing mkinstalldirs tags test-driver +stamp-h* scripts/_curl scripts/curl.fish curl_fuzzer @@ -65,3 +71,4 @@ curl_fuzzer_seed_corpus.zip libstandaloneengine.a tests/string tests/config +tests/ech-log/ diff --git a/third-party/curl/.mailmap b/third-party/curl/.mailmap index 2bc5635145..20384c0101 100644 --- a/third-party/curl/.mailmap +++ b/third-party/curl/.mailmap @@ -1,6 +1,10 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + Guenter Knauf -Gisle Vanem -Gisle Vanem +Gisle Vanem +Gisle Vanem Alessandro Ghedini Alessandro Ghedini Björn Stenberg @@ -65,7 +69,8 @@ Jessa Chandler Gökhan Åžengün Svyatoslav Mishyn Douglas Steinwand -James Fuller +James Fuller +James Fuller Jim Fuller Don J Olmstead Nicolas Sterchele Sergey Raevskiy @@ -79,8 +84,8 @@ Tobias Nyholm Timur Artikov MichaÅ‚ Antoniak <47522782+MAntoniak@users.noreply.github.com> Gleb Ivanovsky -Max Dymond -Max Dymond +Max Dymond +Max Dymond Abhinav Singh Malik Idrees Hasan Khan <77000356+MalikIdreesHasanKhan@users.noreply.github.com> Yongkang Huang @@ -106,3 +111,15 @@ Thomas1664 on github <46387399+Thomas1664@users.noreply.github.com> dengjfzh on github Brad Harder Derzsi Dániel +Michael Osipov <1983-01-06@gmx.net> +Michael Osipov +Christian Weisgerber +Moritz Buhl +Aki Sakurai <75532970+AkiSakurai@users.noreply.github.com> +Sinkevich Artem +Andrew Kirillov +Stephen Farrell +Calvin Ruocco +Hamza Bensliman +Kaixuan Li +Darren Banfi diff --git a/third-party/curl/.reuse/dep5 b/third-party/curl/.reuse/dep5 deleted file mode 100644 index cdefb1698f..0000000000 --- a/third-party/curl/.reuse/dep5 +++ /dev/null @@ -1,98 +0,0 @@ -Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/ -Upstream-Name: curl -Upstream-Contact: Daniel Stenberg -Source: https://curl.se - -# Tests -Files: tests/data/test* tests/certs/* tests/stunnel.pem tests/valgrind.supp -Copyright: Daniel Stenberg, , et al. -License: curl - -# Markdown documentation in docs/ -Files: docs/*.md -Copyright: Daniel Stenberg, , et al. -License: curl - -# Docs in docs/ -Files: docs/FAQ docs/INSTALL docs/INSTALL.cmake docs/KNOWN_BUGS docs/MAIL-ETIQUETTE docs/THANKS docs/TODO docs/cmdline-opts/page-footer docs/libcurl/curl_multi_socket_all.3 docs/libcurl/curl_strnequal.3 docs/libcurl/symbols-in-versions docs/options-in-versions -Copyright: Daniel Stenberg, , et al. -License: curl - -# Windows -Files: projects/Windows/* -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: libcurl.def -Copyright: Daniel Stenberg, , et al. -License: curl - -# Single files we do not want to edit directly -Files: CHANGES -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: GIT-INFO -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: RELEASE-NOTES -Copyright: Daniel Stenberg, , et al. -License: curl - -# checksrc control files -Files: lib/.checksrc docs/examples/.checksrc tests/libtest/.checksrc -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: lib/libcurl.plist.in -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: lib/libcurl.vers.in -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: packages/OS400/README.OS400 -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: packages/vms/build_vms.com -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: packages/vms/curl_release_note_start.txt -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: packages/vms/curlmsg.sdl -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: packages/vms/macro32_exactcase.patch -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: packages/vms/readme -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: plan9/README -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: projects/wolfssl_override.props -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: README -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: .github/ISSUE_TEMPLATE/bug_report.md -Copyright: Daniel Stenberg, , et al. -License: curl - -Files: .mailmap -Copyright: Daniel Stenberg, , et al. -License: curl diff --git a/third-party/curl/CHANGES b/third-party/curl/CHANGES deleted file mode 100644 index 3e2cd9947d..0000000000 --- a/third-party/curl/CHANGES +++ /dev/null @@ -1,7 +0,0 @@ -See https://curl.se/changes.html for the edited and human readable online -version of what has changed over the years in different curl releases. - -Generate a CHANGES file like the one present in every release like this: - -$ git log --pretty=fuller --no-color --date=short --decorate=full | \ - ./scripts/log2changes.pl diff --git a/third-party/curl/CHANGES.md b/third-party/curl/CHANGES.md new file mode 100644 index 0000000000..3eabec9cb8 --- /dev/null +++ b/third-party/curl/CHANGES.md @@ -0,0 +1,12 @@ + + +In a release tarball, check the RELEASE-NOTES file for what was done in the +most recent release. In a git check-out, that file mentions changes that have +been done since the previous release. + +See the online [changelog](https://curl.se/changes.html) for the edited and +human readable version of what has changed in different curl releases. diff --git a/third-party/curl/CMake/CMakeConfigurableFile.in b/third-party/curl/CMake/CMakeConfigurableFile.in deleted file mode 100644 index a3d2bc4a28..0000000000 --- a/third-party/curl/CMake/CMakeConfigurableFile.in +++ /dev/null @@ -1,24 +0,0 @@ -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### -@CMAKE_CONFIGURABLE_FILE_CONTENT@ diff --git a/third-party/curl/CMake/CurlSymbolHiding.cmake b/third-party/curl/CMake/CurlSymbolHiding.cmake index 142e919449..51a2d94de1 100644 --- a/third-party/curl/CMake/CurlSymbolHiding.cmake +++ b/third-party/curl/CMake/CurlSymbolHiding.cmake @@ -21,58 +21,48 @@ # SPDX-License-Identifier: curl # ########################################################################### -include(CheckCSourceCompiles) - -option(CURL_HIDDEN_SYMBOLS "Set to ON to hide libcurl internal symbols (=hide all symbols that aren't officially external)." ON) +option(CURL_HIDDEN_SYMBOLS "Hide libcurl internal symbols (=hide all symbols that are not officially external)" ON) mark_as_advanced(CURL_HIDDEN_SYMBOLS) -if(CURL_HIDDEN_SYMBOLS) - set(SUPPORTS_SYMBOL_HIDING FALSE) - - if(CMAKE_C_COMPILER_ID MATCHES "Clang" AND NOT MSVC) - set(SUPPORTS_SYMBOL_HIDING TRUE) - set(_SYMBOL_EXTERN "__attribute__ ((__visibility__ (\"default\")))") - set(_CFLAG_SYMBOLS_HIDE "-fvisibility=hidden") - elseif(CMAKE_COMPILER_IS_GNUCC) - if(NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 3.4) - # note: this is considered buggy prior to 4.0 but the autotools don't care, so let's ignore that fact - set(SUPPORTS_SYMBOL_HIDING TRUE) - set(_SYMBOL_EXTERN "__attribute__ ((__visibility__ (\"default\")))") - set(_CFLAG_SYMBOLS_HIDE "-fvisibility=hidden") - endif() - elseif(CMAKE_C_COMPILER_ID MATCHES "SunPro" AND NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 8.0) - set(SUPPORTS_SYMBOL_HIDING TRUE) - set(_SYMBOL_EXTERN "__global") - set(_CFLAG_SYMBOLS_HIDE "-xldscope=hidden") - elseif(CMAKE_C_COMPILER_ID MATCHES "Intel" AND NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 9.0) - # note: this should probably just check for version 9.1.045 but I'm not 100% sure - # so let's do it the same way autotools do. - set(SUPPORTS_SYMBOL_HIDING TRUE) - set(_SYMBOL_EXTERN "__attribute__ ((__visibility__ (\"default\")))") - set(_CFLAG_SYMBOLS_HIDE "-fvisibility=hidden") - check_c_source_compiles("#include - int main (void) { printf(\"icc fvisibility bug test\"); return 0; }" _no_bug) - if(NOT _no_bug) - set(SUPPORTS_SYMBOL_HIDING FALSE) - set(_SYMBOL_EXTERN "") - set(_CFLAG_SYMBOLS_HIDE "") - endif() - elseif(MSVC) - set(SUPPORTS_SYMBOL_HIDING TRUE) - endif() - - set(HIDES_CURL_PRIVATE_SYMBOLS ${SUPPORTS_SYMBOL_HIDING}) -elseif(MSVC) - if(NOT CMAKE_VERSION VERSION_LESS 3.7) - set(CMAKE_WINDOWS_EXPORT_ALL_SYMBOLS TRUE) #present since 3.4.3 but broken - set(HIDES_CURL_PRIVATE_SYMBOLS FALSE) - else() - message(WARNING "Hiding private symbols regardless CURL_HIDDEN_SYMBOLS being disabled.") - set(HIDES_CURL_PRIVATE_SYMBOLS TRUE) - endif() -else() - set(HIDES_CURL_PRIVATE_SYMBOLS FALSE) +if(WIN32 AND ENABLE_DEBUG) + # We need to export internal debug functions, + # e.g. curl_easy_perform_ev() or curl_dbg_*(), + # so disable symbol hiding for debug builds and for memory tracking. + set(CURL_HIDDEN_SYMBOLS OFF) +elseif(DOS OR AMIGA) + set(CURL_HIDDEN_SYMBOLS OFF) endif() -set(CURL_CFLAG_SYMBOLS_HIDE ${_CFLAG_SYMBOLS_HIDE}) -set(CURL_EXTERN_SYMBOL ${_SYMBOL_EXTERN}) +set(CURL_HIDES_PRIVATE_SYMBOLS FALSE) +set(CURL_EXTERN_SYMBOL "") +set(CURL_CFLAG_SYMBOLS_HIDE "") + +if(CURL_HIDDEN_SYMBOLS) + if(CMAKE_C_COMPILER_ID MATCHES "Clang" AND NOT MSVC) + set(CURL_HIDES_PRIVATE_SYMBOLS TRUE) + set(CURL_EXTERN_SYMBOL "__attribute__((__visibility__(\"default\")))") + set(CURL_CFLAG_SYMBOLS_HIDE "-fvisibility=hidden") + elseif(CMAKE_C_COMPILER_ID STREQUAL "GNU") + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.4) + # Note: This is considered buggy prior to 4.0 but the autotools do not care, so let us ignore that fact + set(CURL_HIDES_PRIVATE_SYMBOLS TRUE) + set(CURL_EXTERN_SYMBOL "__attribute__((__visibility__(\"default\")))") + set(CURL_CFLAG_SYMBOLS_HIDE "-fvisibility=hidden") + endif() + elseif(CMAKE_C_COMPILER_ID MATCHES "SunPro" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 8.0) + set(CURL_HIDES_PRIVATE_SYMBOLS TRUE) + set(CURL_EXTERN_SYMBOL "__global") + set(CURL_CFLAG_SYMBOLS_HIDE "-xldscope=hidden") + elseif(CMAKE_C_COMPILER_ID MATCHES "Intel" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 9.0) # Requires 9.1.045 + set(CURL_HIDES_PRIVATE_SYMBOLS TRUE) + set(CURL_EXTERN_SYMBOL "__attribute__((__visibility__(\"default\")))") + set(CURL_CFLAG_SYMBOLS_HIDE "-fvisibility=hidden") + elseif(MSVC) + set(CURL_HIDES_PRIVATE_SYMBOLS TRUE) + endif() +else() + if(MSVC) + # Note: This option is prone to export non-curl extra symbols. + set(CMAKE_WINDOWS_EXPORT_ALL_SYMBOLS TRUE) + endif() +endif() diff --git a/third-party/curl/CMake/CurlTests.c b/third-party/curl/CMake/CurlTests.c index 38be522d5e..be3b6f73ee 100644 --- a/third-party/curl/CMake/CurlTests.c +++ b/third-party/curl/CMake/CurlTests.c @@ -21,145 +21,86 @@ * SPDX-License-Identifier: curl * ***************************************************************************/ -#ifdef TIME_WITH_SYS_TIME -/* Time with sys/time test */ - -#include -#include -#include - -int -main () -{ -if ((struct tm *) 0) -return 0; - ; - return 0; -} - -#endif #ifdef HAVE_FCNTL_O_NONBLOCK - /* headers for FCNTL_O_NONBLOCK test */ #include #include #include -/* */ + #if defined(sun) || defined(__sun__) || \ - defined(__SUNPRO_C) || defined(__SUNPRO_CC) -# if defined(__SVR4) || defined(__srv4__) -# define PLATFORM_SOLARIS -# else -# define PLATFORM_SUNOS4 -# endif + defined(__SUNPRO_C) || defined(__SUNPRO_CC) +# if defined(__SVR4) || defined(__srv4__) +# define PLATFORM_SOLARIS +# else +# define PLATFORM_SUNOS4 +# endif #endif #if (defined(_AIX) || defined(__xlC__)) && !defined(_AIX41) -# define PLATFORM_AIX_V3 +# define PLATFORM_AIX_V3 #endif -/* */ + #if defined(PLATFORM_SUNOS4) || defined(PLATFORM_AIX_V3) #error "O_NONBLOCK does not work on this platform" #endif -int -main () +int main(void) { - /* O_NONBLOCK source test */ - int flags = 0; - if(0 != fcntl(0, F_SETFL, flags | O_NONBLOCK)) - return 1; - return 0; + /* O_NONBLOCK source test */ + int flags = 0; + if(0 != fcntl(0, F_SETFL, flags | O_NONBLOCK)) + return 1; + return 0; } #endif /* tests for gethostbyname_r */ -#if defined(HAVE_GETHOSTBYNAME_R_3_REENTRANT) || \ - defined(HAVE_GETHOSTBYNAME_R_5_REENTRANT) || \ - defined(HAVE_GETHOSTBYNAME_R_6_REENTRANT) -# define _REENTRANT - /* no idea whether _REENTRANT is always set, just invent a new flag */ -# define TEST_GETHOSTBYFOO_REENTRANT -#endif #if defined(HAVE_GETHOSTBYNAME_R_3) || \ + defined(HAVE_GETHOSTBYNAME_R_3_REENTRANT) || \ defined(HAVE_GETHOSTBYNAME_R_5) || \ + defined(HAVE_GETHOSTBYNAME_R_5_REENTRANT) || \ defined(HAVE_GETHOSTBYNAME_R_6) || \ - defined(TEST_GETHOSTBYFOO_REENTRANT) + defined(HAVE_GETHOSTBYNAME_R_6_REENTRANT) #include #include int main(void) { - char *address = "example.com"; - int length = 0; - int type = 0; + const char *address = "example.com"; struct hostent h; int rc = 0; -#if defined(HAVE_GETHOSTBYNAME_R_3) || \ - defined(HAVE_GETHOSTBYNAME_R_3_REENTRANT) +#if defined(HAVE_GETHOSTBYNAME_R_3) || \ + defined(HAVE_GETHOSTBYNAME_R_3_REENTRANT) struct hostent_data hdata; #elif defined(HAVE_GETHOSTBYNAME_R_5) || \ defined(HAVE_GETHOSTBYNAME_R_5_REENTRANT) || \ defined(HAVE_GETHOSTBYNAME_R_6) || \ defined(HAVE_GETHOSTBYNAME_R_6_REENTRANT) char buffer[8192]; - int h_errnop; struct hostent *hp; + int h_errnop; #endif #if defined(HAVE_GETHOSTBYNAME_R_3) || \ defined(HAVE_GETHOSTBYNAME_R_3_REENTRANT) rc = gethostbyname_r(address, &h, &hdata); + (void)hdata; #elif defined(HAVE_GETHOSTBYNAME_R_5) || \ defined(HAVE_GETHOSTBYNAME_R_5_REENTRANT) rc = gethostbyname_r(address, &h, buffer, 8192, &h_errnop); - (void)hp; /* not used for test */ + (void)hp; + (void)h_errnop; #elif defined(HAVE_GETHOSTBYNAME_R_6) || \ defined(HAVE_GETHOSTBYNAME_R_6_REENTRANT) rc = gethostbyname_r(address, &h, buffer, 8192, &hp, &h_errnop); + (void)hp; + (void)h_errnop; #endif - - (void)length; - (void)type; + (void)h; (void)rc; return 0; } #endif -#ifdef HAVE_SOCKLEN_T -#ifdef _WIN32 -#include -#else -#include -#include -#endif -int -main () -{ -if ((socklen_t *) 0) - return 0; -if (sizeof (socklen_t)) - return 0; - ; - return 0; -} -#endif -#ifdef HAVE_IN_ADDR_T -#include -#include -#include - -int -main () -{ -if ((in_addr_t *) 0) - return 0; -if (sizeof (in_addr_t)) - return 0; - ; - return 0; -} -#endif - #ifdef HAVE_BOOL_T #ifdef HAVE_SYS_TYPES_H #include @@ -167,13 +108,9 @@ if (sizeof (in_addr_t)) #ifdef HAVE_STDBOOL_H #include #endif -int -main () +int main(void) { -if (sizeof (bool *) ) - return 0; - ; - return 0; + return (int)sizeof(bool *); } #endif @@ -182,130 +119,94 @@ if (sizeof (bool *) ) #include #include #include -int main() { return 0; } +int main(void) +{ + return 0; +} #endif + #ifdef HAVE_FILE_OFFSET_BITS -#ifdef _FILE_OFFSET_BITS -#undef _FILE_OFFSET_BITS -#endif -#define _FILE_OFFSET_BITS 64 #include - /* Check that off_t can represent 2**63 - 1 correctly. - We can't simply define LARGE_OFF_T to be 9223372036854775807, - since some C++ compilers masquerading as C compilers - incorrectly reject 9223372036854775807. */ -#define LARGE_OFF_T (((off_t) 1 << 62) - 1 + ((off_t) 1 << 62)) - int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721 - && LARGE_OFF_T % 2147483647 == 1) - ? 1 : -1]; -int main () { ; return 0; } +/* Check that off_t can represent 2**63 - 1 correctly. + We cannot define LARGE_OFF_T to be 9223372036854775807, + since some C++ compilers masquerading as C compilers + incorrectly reject 9223372036854775807. */ +#define LARGE_OFF_T (((off_t)1 << 62) - 1 + ((off_t)1 << 62)) +static int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721 && + LARGE_OFF_T % 2147483647 == 1) + ? 1 : -1]; +int main(void) +{ + (void)off_t_is_large; + return 0; +} #endif + #ifdef HAVE_IOCTLSOCKET -/* includes start */ -#ifdef HAVE_WINDOWS_H -# ifndef WIN32_LEAN_AND_MEAN -# define WIN32_LEAN_AND_MEAN -# endif -# include -# ifdef HAVE_WINSOCK2_H -# include -# endif +#ifdef _WIN32 +# include #endif - -int -main () +int main(void) { - -/* ioctlsocket source code */ - int socket; - unsigned long flags = ioctlsocket(socket, FIONBIO, &flags); - - ; + /* ioctlsocket source code */ + int socket = -1; + unsigned long flags = ioctlsocket(socket, FIONBIO, &flags); + (void)flags; return 0; } #endif + #ifdef HAVE_IOCTLSOCKET_CAMEL -/* includes start */ -#ifdef HAVE_WINDOWS_H -# ifndef WIN32_LEAN_AND_MEAN -# define WIN32_LEAN_AND_MEAN -# endif -# include -# ifdef HAVE_WINSOCK2_H -# include -# endif -#endif - -int -main () +#include +int main(void) { - -/* IoctlSocket source code */ - if(0 != IoctlSocket(0, 0, 0)) - return 1; - ; + /* IoctlSocket source code */ + if(0 != IoctlSocket(0, 0, 0)) + return 1; return 0; } #endif + #ifdef HAVE_IOCTLSOCKET_CAMEL_FIONBIO -/* includes start */ -#ifdef HAVE_WINDOWS_H -# ifndef WIN32_LEAN_AND_MEAN -# define WIN32_LEAN_AND_MEAN -# endif -# include -# ifdef HAVE_WINSOCK2_H -# include -# endif +#include +#ifdef HAVE_SYS_IOCTL_H +# include #endif - -int -main () +int main(void) { - -/* IoctlSocket source code */ - long flags = 0; - if(0 != IoctlSocket(0, FIONBIO, &flags)) - return 1; - ; + /* IoctlSocket source code */ + long flags = 0; + if(0 != IoctlSocket(0, FIONBIO, &flags)) + return 1; + (void)flags; return 0; } #endif + #ifdef HAVE_IOCTLSOCKET_FIONBIO -/* includes start */ -#ifdef HAVE_WINDOWS_H -# ifndef WIN32_LEAN_AND_MEAN -# define WIN32_LEAN_AND_MEAN -# endif -# include -# ifdef HAVE_WINSOCK2_H -# include -# endif +#ifdef _WIN32 +# include #endif - -int -main () +int main(void) { - - int flags = 0; - if(0 != ioctlsocket(0, FIONBIO, &flags)) - return 1; - - ; + unsigned long flags = 0; + if(0 != ioctlsocket(0, FIONBIO, &flags)) + return 1; + (void)flags; return 0; } #endif + #ifdef HAVE_IOCTL_FIONBIO /* headers for FIONBIO test */ -/* includes start */ #ifdef HAVE_SYS_TYPES_H # include #endif #ifdef HAVE_UNISTD_H # include #endif -#ifdef HAVE_SYS_SOCKET_H +#ifndef _WIN32 # include #endif #ifdef HAVE_SYS_IOCTL_H @@ -314,29 +215,25 @@ main () #ifdef HAVE_STROPTS_H # include #endif - -int -main () +int main(void) { - - int flags = 0; - if(0 != ioctl(0, FIONBIO, &flags)) - return 1; - - ; + int flags = 0; + if(0 != ioctl(0, FIONBIO, &flags)) + return 1; + (void)flags; return 0; } #endif + #ifdef HAVE_IOCTL_SIOCGIFADDR /* headers for FIONBIO test */ -/* includes start */ #ifdef HAVE_SYS_TYPES_H # include #endif #ifdef HAVE_UNISTD_H # include #endif -#ifdef HAVE_SYS_SOCKET_H +#ifndef _WIN32 # include #endif #ifdef HAVE_SYS_IOCTL_H @@ -346,156 +243,111 @@ main () # include #endif #include - -int -main () +int main(void) { - struct ifreq ifr; - if(0 != ioctl(0, SIOCGIFADDR, &ifr)) - return 1; - - ; + struct ifreq ifr; + if(0 != ioctl(0, SIOCGIFADDR, &ifr)) + return 1; + (void)ifr; return 0; } #endif + #ifdef HAVE_SETSOCKOPT_SO_NONBLOCK -/* includes start */ -#ifdef HAVE_WINDOWS_H -# ifndef WIN32_LEAN_AND_MEAN -# define WIN32_LEAN_AND_MEAN -# endif -# include -# ifdef HAVE_WINSOCK2_H -# include -# endif +#ifdef _WIN32 +# include #endif -/* includes start */ #ifdef HAVE_SYS_TYPES_H # include #endif -#ifdef HAVE_SYS_SOCKET_H +#ifndef _WIN32 # include #endif -/* includes end */ - -int -main () +int main(void) { - if(0 != setsockopt(0, SOL_SOCKET, SO_NONBLOCK, 0, 0)) - return 1; - ; + if(0 != setsockopt(0, SOL_SOCKET, SO_NONBLOCK, 0, 0)) + return 1; return 0; } #endif + #ifdef HAVE_GLIBC_STRERROR_R #include #include -void check(char c) {} +static void check(char c) +{ + (void)c; +} -int -main () { +int main(void) +{ char buffer[1024]; - /* This will not compile if strerror_r does not return a char* */ + /* This does not compile if strerror_r does not return a char* */ + /* !checksrc! disable ERRNOVAR 1 */ check(strerror_r(EACCES, buffer, sizeof(buffer))[0]); return 0; } #endif + #ifdef HAVE_POSIX_STRERROR_R #include #include -/* float, because a pointer can't be implicitly cast to float */ -void check(float f) {} +/* Float, because a pointer cannot be implicitly cast to float */ +static void check(float f) +{ + (void)f; +} -int -main () { +int main(void) +{ char buffer[1024]; - /* This will not compile if strerror_r does not return an int */ + /* This does not compile if strerror_r does not return an int */ + /* !checksrc! disable ERRNOVAR 1 */ check(strerror_r(EACCES, buffer, sizeof(buffer))); return 0; } #endif + #ifdef HAVE_FSETXATTR_6 #include /* header from libc, not from libattr */ -int -main() { +int main(void) +{ fsetxattr(0, 0, 0, 0, 0, 0); return 0; } #endif + #ifdef HAVE_FSETXATTR_5 #include /* header from libc, not from libattr */ -int -main() { - fsetxattr(0, 0, 0, 0, 0); +int main(void) +{ + fsetxattr(0, "", 0, 0, 0); return 0; } #endif + #ifdef HAVE_CLOCK_GETTIME_MONOTONIC #include -int -main() { - struct timespec ts = {0, 0}; - clock_gettime(CLOCK_MONOTONIC, &ts); +int main(void) +{ + struct timespec ts; + (void)clock_gettime(CLOCK_MONOTONIC, &ts); + (void)ts; return 0; } #endif + #ifdef HAVE_BUILTIN_AVAILABLE -int -main() { - if(__builtin_available(macOS 10.12, *)) {} +int main(void) +{ + if(__builtin_available(macOS 10.12, iOS 5.0, *)) {} return 0; } #endif -#ifdef HAVE_VARIADIC_MACROS_C99 -#define c99_vmacro3(first, ...) fun3(first, __VA_ARGS__) -#define c99_vmacro2(first, ...) fun2(first, __VA_ARGS__) -int fun3(int arg1, int arg2, int arg3); -int fun2(int arg1, int arg2); - -int fun3(int arg1, int arg2, int arg3) { - return arg1 + arg2 + arg3; -} -int fun2(int arg1, int arg2) { - return arg1 + arg2; -} - -int -main() { - int res3 = c99_vmacro3(1, 2, 3); - int res2 = c99_vmacro2(1, 2); - (void)res3; - (void)res2; - return 0; -} -#endif -#ifdef HAVE_VARIADIC_MACROS_GCC -#define gcc_vmacro3(first, args...) fun3(first, args) -#define gcc_vmacro2(first, args...) fun2(first, args) - -int fun3(int arg1, int arg2, int arg3); -int fun2(int arg1, int arg2); - -int fun3(int arg1, int arg2, int arg3) { - return arg1 + arg2 + arg3; -} -int fun2(int arg1, int arg2) { - return arg1 + arg2; -} - -int -main() { - int res3 = gcc_vmacro3(1, 2, 3); - int res2 = gcc_vmacro2(1, 2); - (void)res3; - (void)res2; - return 0; -} -#endif #ifdef HAVE_ATOMIC -/* includes start */ #ifdef HAVE_SYS_TYPES_H # include #endif @@ -505,28 +357,45 @@ main() { #ifdef HAVE_STDATOMIC_H # include #endif -/* includes end */ - -int -main() { +int main(void) +{ _Atomic int i = 1; i = 0; /* Force an atomic-write operation. */ return i; } #endif + #ifdef HAVE_WIN32_WINNT -/* includes start */ -#ifdef WIN32 -# include "../lib/setup-win32.h" +#ifdef _WIN32 +# ifndef NOGDI +# define NOGDI +# endif +# include #endif -/* includes end */ #define enquote(x) #x #define expand(x) enquote(x) #pragma message("_WIN32_WINNT=" expand(_WIN32_WINNT)) -int -main() { +int main(void) +{ + return 0; +} +#endif + +#ifdef MINGW64_VERSION +#ifdef __MINGW32__ +# include <_mingw.h> +#endif + +#define enquote(x) #x +#define expand(x) enquote(x) +#pragma message("MINGW64_VERSION=" \ + expand(__MINGW64_VERSION_MAJOR) "." \ + expand(__MINGW64_VERSION_MINOR)) + +int main(void) +{ return 0; } #endif diff --git a/third-party/curl/CMake/FindBearSSL.cmake b/third-party/curl/CMake/FindBearSSL.cmake deleted file mode 100644 index 56a064eacd..0000000000 --- a/third-party/curl/CMake/FindBearSSL.cmake +++ /dev/null @@ -1,32 +0,0 @@ -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### -find_path(BEARSSL_INCLUDE_DIRS bearssl.h) - -find_library(BEARSSL_LIBRARY bearssl) - -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(BEARSSL DEFAULT_MSG - BEARSSL_INCLUDE_DIRS BEARSSL_LIBRARY) - -mark_as_advanced(BEARSSL_INCLUDE_DIRS BEARSSL_LIBRARY) diff --git a/third-party/curl/CMake/FindBrotli.cmake b/third-party/curl/CMake/FindBrotli.cmake index 11ab7f8254..bd3363cce0 100644 --- a/third-party/curl/CMake/FindBrotli.cmake +++ b/third-party/curl/CMake/FindBrotli.cmake @@ -21,23 +21,76 @@ # SPDX-License-Identifier: curl # ########################################################################### -include(FindPackageHandleStandardArgs) +# Find the brotli library +# +# Input variables: +# +# - `BROTLI_INCLUDE_DIR`: Absolute path to brotli include directory. +# - `BROTLICOMMON_LIBRARY`: Absolute path to `brotlicommon` library. +# - `BROTLIDEC_LIBRARY`: Absolute path to `brotlidec` library. +# - `BROTLI_USE_STATIC_LIBS`: Configure for static brotli libraries. +# +# Defines: +# +# - `BROTLI_FOUND`: System has brotli. +# - `BROTLI_VERSION`: Version of brotli. +# - `CURL::brotli`: brotli library target. -find_path(BROTLI_INCLUDE_DIR "brotli/decode.h") +set(_brotli_pc_requires "libbrotlidec" "libbrotlicommon") # order is significant: brotlidec then brotlicommon -find_library(BROTLICOMMON_LIBRARY NAMES brotlicommon) -find_library(BROTLIDEC_LIBRARY NAMES brotlidec) +if(CURL_USE_PKGCONFIG AND + NOT DEFINED BROTLI_INCLUDE_DIR AND + NOT DEFINED BROTLICOMMON_LIBRARY AND + NOT DEFINED BROTLIDEC_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_brotli ${_brotli_pc_requires}) +endif() -find_package_handle_standard_args(Brotli - FOUND_VAR - BROTLI_FOUND +if(_brotli_FOUND) + set(Brotli_FOUND TRUE) + set(BROTLI_FOUND TRUE) + set(BROTLI_VERSION ${_brotli_libbrotlicommon_VERSION}) + if(BROTLI_USE_STATIC_LIBS) + set(_brotli_CFLAGS "${_brotli_STATIC_CFLAGS}") + set(_brotli_INCLUDE_DIRS "${_brotli_STATIC_INCLUDE_DIRS}") + set(_brotli_LIBRARY_DIRS "${_brotli_STATIC_LIBRARY_DIRS}") + set(_brotli_LIBRARIES "${_brotli_STATIC_LIBRARIES}") + endif() + message(STATUS "Found Brotli (via pkg-config): ${_brotli_INCLUDE_DIRS} (found version \"${BROTLI_VERSION}\")") +else() + find_path(BROTLI_INCLUDE_DIR "brotli/decode.h") + if(BROTLI_USE_STATIC_LIBS) + find_library(BROTLICOMMON_LIBRARY NAMES "brotlicommon-static" "brotlicommon") + find_library(BROTLIDEC_LIBRARY NAMES "brotlidec-static" "brotlidec") + else() + find_library(BROTLICOMMON_LIBRARY NAMES "brotlicommon") + find_library(BROTLIDEC_LIBRARY NAMES "brotlidec") + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Brotli REQUIRED_VARS + BROTLI_INCLUDE_DIR BROTLIDEC_LIBRARY BROTLICOMMON_LIBRARY - BROTLI_INCLUDE_DIR - FAIL_MESSAGE - "Could NOT find Brotli" -) + ) -set(BROTLI_INCLUDE_DIRS ${BROTLI_INCLUDE_DIR}) -set(BROTLI_LIBRARIES ${BROTLICOMMON_LIBRARY} ${BROTLIDEC_LIBRARY}) + if(BROTLI_FOUND) + set(_brotli_INCLUDE_DIRS ${BROTLI_INCLUDE_DIR}) + set(_brotli_LIBRARIES ${BROTLIDEC_LIBRARY} ${BROTLICOMMON_LIBRARY}) + endif() + + mark_as_advanced(BROTLI_INCLUDE_DIR BROTLIDEC_LIBRARY BROTLICOMMON_LIBRARY) +endif() + +if(BROTLI_FOUND) + if(NOT TARGET CURL::brotli) + add_library(CURL::brotli INTERFACE IMPORTED) + set_target_properties(CURL::brotli PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_brotli_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_brotli_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_brotli_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_brotli_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_brotli_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindCARES.cmake b/third-party/curl/CMake/FindCARES.cmake index fa75891189..26efdf87ff 100644 --- a/third-party/curl/CMake/FindCARES.cmake +++ b/third-party/curl/CMake/FindCARES.cmake @@ -21,27 +21,112 @@ # SPDX-License-Identifier: curl # ########################################################################### -# - Find c-ares -# Find the c-ares includes and library -# This module defines -# CARES_INCLUDE_DIR, where to find ares.h, etc. -# CARES_LIBRARIES, the libraries needed to use c-ares. -# CARES_FOUND, If false, do not try to use c-ares. -# also defined, but not for general use are -# CARES_LIBRARY, where to find the c-ares library. +# Find the c-ares library +# +# Input variables: +# +# - `CARES_INCLUDE_DIR`: Absolute path to c-ares include directory. +# - `CARES_LIBRARY`: Absolute path to `cares` library. +# - `CARES_USE_STATIC_LIBS`: Configure for static c-ares libraries. +# +# Defines: +# +# - `CARES_FOUND`: System has c-ares. +# - `CARES_VERSION`: Version of c-ares. +# - `CURL::cares`: c-ares library target. -find_path(CARES_INCLUDE_DIR ares.h) +set(_cares_pc_requires "libcares") -set(CARES_NAMES ${CARES_NAMES} cares) -find_library(CARES_LIBRARY - NAMES ${CARES_NAMES} +if(NOT DEFINED CARES_INCLUDE_DIR AND + NOT DEFINED CARES_LIBRARY) + if(CURL_USE_PKGCONFIG) + find_package(PkgConfig QUIET) + pkg_check_modules(_cares ${_cares_pc_requires}) + endif() + if(NOT _cares_FOUND AND CURL_USE_CMAKECONFIG) + find_package(c-ares CONFIG QUIET) + endif() +endif() + +if(_cares_FOUND) + set(Cares_FOUND TRUE) + set(CARES_FOUND TRUE) + set(CARES_VERSION ${_cares_VERSION}) + if(CARES_USE_STATIC_LIBS) + set(_cares_CFLAGS "${_cares_STATIC_CFLAGS}") + set(_cares_INCLUDE_DIRS "${_cares_STATIC_INCLUDE_DIRS}") + set(_cares_LIBRARY_DIRS "${_cares_STATIC_LIBRARY_DIRS}") + set(_cares_LIBRARIES "${_cares_STATIC_LIBRARIES}") + endif() + message(STATUS "Found Cares (via pkg-config): ${_cares_INCLUDE_DIRS} (found version \"${CARES_VERSION}\")") +elseif(c-ares_CONFIG) + set(Cares_FOUND TRUE) + set(CARES_FOUND TRUE) + set(CARES_VERSION ${c-ares_VERSION}) + if(CARES_USE_STATIC_LIBS) + set(_cares_LIBRARIES c-ares::cares_static) + else() + set(_cares_LIBRARIES c-ares::cares) + endif() + message(STATUS "Found Cares (via CMake Config): ${c-ares_CONFIG} (found version \"${CARES_VERSION}\")") +else() + find_path(CARES_INCLUDE_DIR NAMES "ares.h") + if(CARES_USE_STATIC_LIBS) + set(_cares_CFLAGS "-DCARES_STATICLIB") + find_library(CARES_LIBRARY NAMES ${CARES_NAMES} "cares_static" "cares") + else() + find_library(CARES_LIBRARY NAMES ${CARES_NAMES} "cares") + endif() + + unset(CARES_VERSION CACHE) + if(CARES_INCLUDE_DIR AND EXISTS "${CARES_INCLUDE_DIR}/ares_version.h") + set(_version_regex1 "#[\t ]*define[\t ]+ARES_VERSION_MAJOR[\t ]+([0-9]+).*") + set(_version_regex2 "#[\t ]*define[\t ]+ARES_VERSION_MINOR[\t ]+([0-9]+).*") + set(_version_regex3 "#[\t ]*define[\t ]+ARES_VERSION_PATCH[\t ]+([0-9]+).*") + file(STRINGS "${CARES_INCLUDE_DIR}/ares_version.h" _version_str1 REGEX "${_version_regex1}") + file(STRINGS "${CARES_INCLUDE_DIR}/ares_version.h" _version_str2 REGEX "${_version_regex2}") + file(STRINGS "${CARES_INCLUDE_DIR}/ares_version.h" _version_str3 REGEX "${_version_regex3}") + string(REGEX REPLACE "${_version_regex1}" "\\1" _version_str1 "${_version_str1}") + string(REGEX REPLACE "${_version_regex2}" "\\1" _version_str2 "${_version_str2}") + string(REGEX REPLACE "${_version_regex3}" "\\1" _version_str3 "${_version_str3}") + set(CARES_VERSION "${_version_str1}.${_version_str2}.${_version_str3}") + unset(_version_regex1) + unset(_version_regex2) + unset(_version_regex3) + unset(_version_str1) + unset(_version_str2) + unset(_version_str3) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Cares + REQUIRED_VARS + CARES_INCLUDE_DIR + CARES_LIBRARY + VERSION_VAR + CARES_VERSION ) -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(CARES - REQUIRED_VARS CARES_LIBRARY CARES_INCLUDE_DIR) + if(CARES_FOUND) + set(_cares_INCLUDE_DIRS ${CARES_INCLUDE_DIR}) + set(_cares_LIBRARIES ${CARES_LIBRARY}) + endif() -mark_as_advanced( - CARES_LIBRARY - CARES_INCLUDE_DIR - ) + mark_as_advanced(CARES_INCLUDE_DIR CARES_LIBRARY) +endif() + +if(CARES_FOUND) + if(WIN32) + list(APPEND _cares_LIBRARIES "iphlpapi") # for if_indextoname and others + endif() + + if(NOT TARGET CURL::cares) + add_library(CURL::cares INTERFACE IMPORTED) + set_target_properties(CURL::cares PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_cares_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_cares_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_cares_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_cares_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_cares_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindGSS.cmake b/third-party/curl/CMake/FindGSS.cmake index b244e610ec..6f352b2e4f 100644 --- a/third-party/curl/CMake/FindGSS.cmake +++ b/third-party/curl/CMake/FindGSS.cmake @@ -21,292 +21,244 @@ # SPDX-License-Identifier: curl # ########################################################################### -# - Try to find the GSS Kerberos library -# Once done this will define +# Find the GSS Kerberos library # -# GSS_ROOT_DIR - Set this variable to the root installation of GSS +# Input variables: # -# Read-Only variables: -# GSS_FOUND - system has the Heimdal library -# GSS_FLAVOUR - "MIT" or "Heimdal" if anything found. -# GSS_INCLUDE_DIR - the Heimdal include directory -# GSS_LIBRARIES - The libraries needed to use GSS -# GSS_LINK_DIRECTORIES - Directories to add to linker search path -# GSS_LINKER_FLAGS - Additional linker flags -# GSS_COMPILER_FLAGS - Additional compiler flags -# GSS_VERSION - This is set to version advertised by pkg-config or read from manifest. -# In case the library is found but no version info available it'll be set to "unknown" +# - `GSS_ROOT_DIR`: Absolute path to the root installation of GSS. (also supported as environment) +# +# Defines: +# +# - `GSS_FOUND`: System has GSS. +# - `GSS_VERSION`: Version of GSS. +# - `CURL::gss`: GSS library target. +# - `INTERFACE_CURL_GSS_FLAVOR`: Custom property. "GNU" or "MIT" if detected. -set(_MIT_MODNAME mit-krb5-gssapi) -set(_HEIMDAL_MODNAME heimdal-gssapi) +set(_gnu_modname "gss") +set(_mit_modname "mit-krb5-gssapi") include(CheckIncludeFile) include(CheckIncludeFiles) include(CheckTypeSize) -set(_GSS_ROOT_HINTS - "${GSS_ROOT_DIR}" - "$ENV{GSS_ROOT_DIR}" -) +set(_gss_root_hints "${GSS_ROOT_DIR}" "$ENV{GSS_ROOT_DIR}") -# try to find library using system pkg-config if user didn't specify root dir +set(_gss_CFLAGS "") +set(_gss_LIBRARY_DIRS "") + +# Try to find library using system pkg-config if user did not specify root dir if(NOT GSS_ROOT_DIR AND NOT "$ENV{GSS_ROOT_DIR}") - if(UNIX) + if(CURL_USE_PKGCONFIG) find_package(PkgConfig QUIET) - pkg_search_module(_GSS_PKG ${_MIT_MODNAME} ${_HEIMDAL_MODNAME}) - list(APPEND _GSS_ROOT_HINTS "${_GSS_PKG_PREFIX}") - elseif(WIN32) - list(APPEND _GSS_ROOT_HINTS "[HKEY_LOCAL_MACHINE\\SOFTWARE\\MIT\\Kerberos;InstallDir]") + pkg_search_module(_gss ${_mit_modname} ${_gnu_modname}) + list(APPEND _gss_root_hints "${_gss_PREFIX}") + set(_gss_version "${_gss_VERSION}") + endif() + if(WIN32) + list(APPEND _gss_root_hints "[HKEY_LOCAL_MACHINE\\SOFTWARE\\MIT\\Kerberos;InstallDir]") endif() endif() -if(NOT _GSS_FOUND) #not found by pkg-config. Let's take more traditional approach. - find_file(_GSS_CONFIGURE_SCRIPT - NAMES - "krb5-config" - HINTS - ${_GSS_ROOT_HINTS} - PATH_SUFFIXES - bin - NO_CMAKE_PATH - NO_CMAKE_ENVIRONMENT_PATH - ) +if(NOT _gss_FOUND) # Not found by pkg-config. Let us take more traditional approach. + find_file(_gss_configure_script NAMES "krb5-config" PATH_SUFFIXES "bin" HINTS ${_gss_root_hints} + NO_CMAKE_PATH NO_CMAKE_ENVIRONMENT_PATH) + # If not found in user-supplied directories, maybe system knows better + find_file(_gss_configure_script NAMES "krb5-config" PATH_SUFFIXES "bin") - # if not found in user-supplied directories, maybe system knows better - find_file(_GSS_CONFIGURE_SCRIPT - NAMES - "krb5-config" - PATH_SUFFIXES - bin - ) + if(_gss_configure_script) - if(_GSS_CONFIGURE_SCRIPT) - execute_process( - COMMAND ${_GSS_CONFIGURE_SCRIPT} "--cflags" "gssapi" - OUTPUT_VARIABLE _GSS_CFLAGS - RESULT_VARIABLE _GSS_CONFIGURE_FAILED - OUTPUT_STRIP_TRAILING_WHITESPACE - ) - message(STATUS "CFLAGS: ${_GSS_CFLAGS}") - if(NOT _GSS_CONFIGURE_FAILED) # 0 means success - # should also work in an odd case when multiple directories are given - string(STRIP "${_GSS_CFLAGS}" _GSS_CFLAGS) - string(REGEX REPLACE " +-I" ";" _GSS_CFLAGS "${_GSS_CFLAGS}") - string(REGEX REPLACE " +-([^I][^ \\t;]*)" ";-\\1" _GSS_CFLAGS "${_GSS_CFLAGS}") + set(_gss_INCLUDE_DIRS "") + set(_gss_LIBRARIES "") - foreach(_flag ${_GSS_CFLAGS}) - if(_flag MATCHES "^-I.*") - string(REGEX REPLACE "^-I" "" _val "${_flag}") - list(APPEND _GSS_INCLUDE_DIR "${_val}") + execute_process(COMMAND ${_gss_configure_script} "--cflags" "gssapi" + OUTPUT_VARIABLE _gss_cflags_raw + RESULT_VARIABLE _gss_configure_failed + OUTPUT_STRIP_TRAILING_WHITESPACE) + message(STATUS "FindGSS krb5-config --cflags: ${_gss_cflags_raw}") + + if(NOT _gss_configure_failed) # 0 means success + # Should also work in an odd case when multiple directories are given. + string(STRIP "${_gss_cflags_raw}" _gss_cflags_raw) + string(REGEX REPLACE " +-(I)" ";-\\1" _gss_cflags_raw "${_gss_cflags_raw}") + string(REGEX REPLACE " +-([^I][^ \\t;]*)" ";-\\1" _gss_cflags_raw "${_gss_cflags_raw}") + + foreach(_flag IN LISTS _gss_cflags_raw) + if(_flag MATCHES "^-I") + string(REGEX REPLACE "^-I" "" _flag "${_flag}") + list(APPEND _gss_INCLUDE_DIRS "${_flag}") else() - list(APPEND _GSS_COMPILER_FLAGS "${_flag}") + list(APPEND _gss_CFLAGS "${_flag}") endif() endforeach() endif() - execute_process( - COMMAND ${_GSS_CONFIGURE_SCRIPT} "--libs" "gssapi" - OUTPUT_VARIABLE _GSS_LIB_FLAGS - RESULT_VARIABLE _GSS_CONFIGURE_FAILED - OUTPUT_STRIP_TRAILING_WHITESPACE - ) - message(STATUS "LDFLAGS: ${_GSS_LIB_FLAGS}") + execute_process(COMMAND ${_gss_configure_script} "--libs" "gssapi" + OUTPUT_VARIABLE _gss_lib_flags + RESULT_VARIABLE _gss_configure_failed + OUTPUT_STRIP_TRAILING_WHITESPACE) + message(STATUS "FindGSS krb5-config --libs: ${_gss_lib_flags}") - if(NOT _GSS_CONFIGURE_FAILED) # 0 means success - # this script gives us libraries and link directories. Blah. We have to deal with it. - string(STRIP "${_GSS_LIB_FLAGS}" _GSS_LIB_FLAGS) - string(REGEX REPLACE " +-(L|l)" ";-\\1" _GSS_LIB_FLAGS "${_GSS_LIB_FLAGS}") - string(REGEX REPLACE " +-([^Ll][^ \\t;]*)" ";-\\1" _GSS_LIB_FLAGS "${_GSS_LIB_FLAGS}") + if(NOT _gss_configure_failed) # 0 means success + # This script gives us libraries and link directories. + string(STRIP "${_gss_lib_flags}" _gss_lib_flags) + string(REGEX REPLACE " +-(L|l)" ";-\\1" _gss_lib_flags "${_gss_lib_flags}") + string(REGEX REPLACE " +-([^Ll][^ \\t;]*)" ";-\\1" _gss_lib_flags "${_gss_lib_flags}") - foreach(_flag ${_GSS_LIB_FLAGS}) - if(_flag MATCHES "^-l.*") - string(REGEX REPLACE "^-l" "" _val "${_flag}") - list(APPEND _GSS_LIBRARIES "${_val}") - elseif(_flag MATCHES "^-L.*") - string(REGEX REPLACE "^-L" "" _val "${_flag}") - list(APPEND _GSS_LINK_DIRECTORIES "${_val}") - else() - list(APPEND _GSS_LINKER_FLAGS "${_flag}") + foreach(_flag IN LISTS _gss_lib_flags) + if(_flag MATCHES "^-l") + string(REGEX REPLACE "^-l" "" _flag "${_flag}") + list(APPEND _gss_LIBRARIES "${_flag}") + elseif(_flag MATCHES "^-L") + string(REGEX REPLACE "^-L" "" _flag "${_flag}") + list(APPEND _gss_LIBRARY_DIRS "${_flag}") endif() endforeach() endif() - execute_process( - COMMAND ${_GSS_CONFIGURE_SCRIPT} "--version" - OUTPUT_VARIABLE _GSS_VERSION - RESULT_VARIABLE _GSS_CONFIGURE_FAILED - OUTPUT_STRIP_TRAILING_WHITESPACE - ) + execute_process(COMMAND ${_gss_configure_script} "--version" + OUTPUT_VARIABLE _gss_version + RESULT_VARIABLE _gss_configure_failed + OUTPUT_STRIP_TRAILING_WHITESPACE) - # older versions may not have the "--version" parameter. In this case we just don't care. - if(_GSS_CONFIGURE_FAILED) - set(_GSS_VERSION 0) - endif() - - execute_process( - COMMAND ${_GSS_CONFIGURE_SCRIPT} "--vendor" - OUTPUT_VARIABLE _GSS_VENDOR - RESULT_VARIABLE _GSS_CONFIGURE_FAILED - OUTPUT_STRIP_TRAILING_WHITESPACE - ) - - # older versions may not have the "--vendor" parameter. In this case we just don't care. - if(_GSS_CONFIGURE_FAILED) - set(GSS_FLAVOUR "Heimdal") # most probably, shouldn't really matter + # Older versions may not have the "--version" parameter. In this case we do not care. + if(_gss_configure_failed) + set(_gss_version 0) else() - if(_GSS_VENDOR MATCHES ".*H|heimdal.*") - set(GSS_FLAVOUR "Heimdal") - else() - set(GSS_FLAVOUR "MIT") - endif() + # Strip prefix string to leave the version number only + string(REPLACE "Kerberos 5 release " "" _gss_version "${_gss_version}") endif() - else() # either there is no config script or we are on a platform that doesn't provide one (Windows?) + execute_process(COMMAND ${_gss_configure_script} "--vendor" + OUTPUT_VARIABLE _gss_vendor + RESULT_VARIABLE _gss_configure_failed + OUTPUT_STRIP_TRAILING_WHITESPACE) - find_path(_GSS_INCLUDE_DIR - NAMES - "gssapi/gssapi.h" - HINTS - ${_GSS_ROOT_HINTS} - PATH_SUFFIXES - include - inc - ) - - if(_GSS_INCLUDE_DIR) #jay, we've found something - set(CMAKE_REQUIRED_INCLUDES "${_GSS_INCLUDE_DIR}") - check_include_files( "gssapi/gssapi_generic.h;gssapi/gssapi_krb5.h" _GSS_HAVE_MIT_HEADERS) - - if(_GSS_HAVE_MIT_HEADERS) - set(GSS_FLAVOUR "MIT") - else() - # prevent compiling the header - just check if we can include it - list(APPEND CMAKE_REQUIRED_DEFINITIONS -D__ROKEN_H__) - check_include_file( "roken.h" _GSS_HAVE_ROKEN_H) - - check_include_file( "heimdal/roken.h" _GSS_HAVE_HEIMDAL_ROKEN_H) - if(_GSS_HAVE_ROKEN_H OR _GSS_HAVE_HEIMDAL_ROKEN_H) - set(GSS_FLAVOUR "Heimdal") - endif() - list(REMOVE_ITEM CMAKE_REQUIRED_DEFINITIONS -D__ROKEN_H__) - endif() - else() - # I'm not convinced if this is the right way but this is what autotools do at the moment - find_path(_GSS_INCLUDE_DIR - NAMES - "gssapi.h" - HINTS - ${_GSS_ROOT_HINTS} - PATH_SUFFIXES - include - inc - ) - - if(_GSS_INCLUDE_DIR) - set(GSS_FLAVOUR "Heimdal") - endif() + # Older versions may not have the "--vendor" parameter. In this case we do not care. + if(NOT _gss_configure_failed AND NOT _gss_vendor MATCHES "Heimdal|heimdal") + set(_gss_flavor "MIT") # assume a default, should not really matter endif() - # if we have headers, check if we can link libraries - if(GSS_FLAVOUR) - set(_GSS_LIBDIR_SUFFIXES "") - set(_GSS_LIBDIR_HINTS ${_GSS_ROOT_HINTS}) - get_filename_component(_GSS_CALCULATED_POTENTIAL_ROOT "${_GSS_INCLUDE_DIR}" PATH) - list(APPEND _GSS_LIBDIR_HINTS ${_GSS_CALCULATED_POTENTIAL_ROOT}) + else() # Either there is no config script or we are on a platform that does not provide one (Windows?) - if(WIN32) - if(CMAKE_SIZEOF_VOID_P EQUAL 8) - list(APPEND _GSS_LIBDIR_SUFFIXES "lib/AMD64") - if(GSS_FLAVOUR STREQUAL "MIT") - set(_GSS_LIBNAME "gssapi64") + find_path(_gss_INCLUDE_DIRS NAMES "gssapi/gssapi.h" HINTS ${_gss_root_hints} PATH_SUFFIXES "include" "inc") + + if(_gss_INCLUDE_DIRS) # We have found something + set(_gss_libdir_suffixes "") + + cmake_push_check_state() + list(APPEND CMAKE_REQUIRED_INCLUDES "${_gss_INCLUDE_DIRS}") + check_include_files("gssapi/gssapi_generic.h;gssapi/gssapi_krb5.h" _gss_have_mit_headers) + cmake_pop_check_state() + + if(_gss_have_mit_headers) + set(_gss_flavor "MIT") + if(WIN32) + if(CMAKE_SIZEOF_VOID_P EQUAL 8) + list(APPEND _gss_libdir_suffixes "lib/AMD64") + set(_gss_libname "gssapi64") else() - set(_GSS_LIBNAME "libgssapi") + list(APPEND _gss_libdir_suffixes "lib/i386") + set(_gss_libname "gssapi32") endif() else() - list(APPEND _GSS_LIBDIR_SUFFIXES "lib/i386") - if(GSS_FLAVOUR STREQUAL "MIT") - set(_GSS_LIBNAME "gssapi32") - else() - set(_GSS_LIBNAME "libgssapi") - endif() - endif() - else() - list(APPEND _GSS_LIBDIR_SUFFIXES "lib;lib64") # those suffixes are not checked for HINTS - if(GSS_FLAVOUR STREQUAL "MIT") - set(_GSS_LIBNAME "gssapi_krb5") - else() - set(_GSS_LIBNAME "gssapi") + list(APPEND _gss_libdir_suffixes "lib" "lib64") # those suffixes are not checked for HINTS + set(_gss_libname "gssapi_krb5") endif() endif() + else() + find_path(_gss_INCLUDE_DIRS NAMES "gss.h" HINTS ${_gss_root_hints} PATH_SUFFIXES "include") - find_library(_GSS_LIBRARIES - NAMES - ${_GSS_LIBNAME} - HINTS - ${_GSS_LIBDIR_HINTS} - PATH_SUFFIXES - ${_GSS_LIBDIR_SUFFIXES} - ) - + if(_gss_INCLUDE_DIRS) + set(_gss_flavor "GNU") + set(_gss_pc_requires ${_gnu_modname}) + set(_gss_libname "gss") + endif() endif() + + # If we have headers, look up libraries + if(_gss_flavor) + set(_gss_libdir_hints ${_gss_root_hints}) + if(CMAKE_VERSION VERSION_GREATER_EQUAL 3.20) + cmake_path(GET _gss_INCLUDE_DIRS PARENT_PATH _gss_calculated_potential_root) + else() + get_filename_component(_gss_calculated_potential_root "${_gss_INCLUDE_DIRS}" DIRECTORY) + endif() + list(APPEND _gss_libdir_hints ${_gss_calculated_potential_root}) + + find_library(_gss_LIBRARIES NAMES ${_gss_libname} HINTS ${_gss_libdir_hints} PATH_SUFFIXES ${_gss_libdir_suffixes}) + endif() + endif() + if(NOT _gss_flavor) + message(FATAL_ERROR "GNU or MIT GSS is required") endif() else() - if(_GSS_PKG_${_MIT_MODNAME}_VERSION) - set(GSS_FLAVOUR "MIT") - set(_GSS_VERSION _GSS_PKG_${_MIT_MODNAME}_VERSION) + if(_gss_MODULE_NAME STREQUAL _gnu_modname) + set(_gss_flavor "GNU") + set(_gss_pc_requires ${_gnu_modname}) + elseif(_gss_MODULE_NAME STREQUAL _mit_modname) + set(_gss_flavor "MIT") + set(_gss_pc_requires ${_mit_modname}) else() - set(GSS_FLAVOUR "Heimdal") - set(_GSS_VERSION _GSS_PKG_${_MIT_HEIMDAL}_VERSION) + message(FATAL_ERROR "GNU or MIT GSS is required") endif() + message(STATUS "Found GSS/${_gss_flavor} (via pkg-config): ${_gss_INCLUDE_DIRS} (found version \"${_gss_version}\")") endif() -set(GSS_INCLUDE_DIR ${_GSS_INCLUDE_DIR}) -set(GSS_LIBRARIES ${_GSS_LIBRARIES}) -set(GSS_LINK_DIRECTORIES ${_GSS_LINK_DIRECTORIES}) -set(GSS_LINKER_FLAGS ${_GSS_LINKER_FLAGS}) -set(GSS_COMPILER_FLAGS ${_GSS_COMPILER_FLAGS}) -set(GSS_VERSION ${_GSS_VERSION}) +set(GSS_VERSION ${_gss_version}) -if(GSS_FLAVOUR) - if(NOT GSS_VERSION AND GSS_FLAVOUR STREQUAL "Heimdal") - if(CMAKE_SIZEOF_VOID_P EQUAL 8) - set(HEIMDAL_MANIFEST_FILE "Heimdal.Application.amd64.manifest") +if(NOT GSS_VERSION) + if(_gss_flavor STREQUAL "MIT" AND WIN32) + if(CMAKE_VERSION VERSION_GREATER_EQUAL 3.24) + cmake_host_system_information(RESULT _mit_version QUERY WINDOWS_REGISTRY + "HKLM/SOFTWARE/MIT/Kerberos/SDK/CurrentVersion" VALUE "VersionString") else() - set(HEIMDAL_MANIFEST_FILE "Heimdal.Application.x86.manifest") + get_filename_component(_mit_version + "[HKEY_LOCAL_MACHINE\\SOFTWARE\\MIT\\Kerberos\\SDK\\CurrentVersion;VersionString]" NAME CACHE) endif() - - if(EXISTS "${GSS_INCLUDE_DIR}/${HEIMDAL_MANIFEST_FILE}") - file(STRINGS "${GSS_INCLUDE_DIR}/${HEIMDAL_MANIFEST_FILE}" heimdal_version_str - REGEX "^.*version=\"[0-9]\\.[^\"]+\".*$") - - string(REGEX MATCH "[0-9]\\.[^\"]+" - GSS_VERSION "${heimdal_version_str}") - endif() - - if(NOT GSS_VERSION) - set(GSS_VERSION "Heimdal Unknown") - endif() - elseif(NOT GSS_VERSION AND GSS_FLAVOUR STREQUAL "MIT") - get_filename_component(_MIT_VERSION "[HKEY_LOCAL_MACHINE\\SOFTWARE\\MIT\\Kerberos\\SDK\\CurrentVersion;VersionString]" NAME CACHE) - if(WIN32 AND _MIT_VERSION) - set(GSS_VERSION "${_MIT_VERSION}") - else() - set(GSS_VERSION "MIT Unknown") + set(GSS_VERSION "${_mit_version}") + elseif(_gss_flavor STREQUAL "GNU") + if(_gss_INCLUDE_DIRS AND EXISTS "${_gss_INCLUDE_DIRS}/gss.h") + set(_version_regex "#[\t ]*define[\t ]+GSS_VERSION[\t ]+\"([^\"]*)\"") + file(STRINGS "${_gss_INCLUDE_DIRS}/gss.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(GSS_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) endif() endif() endif() include(FindPackageHandleStandardArgs) - -set(_GSS_REQUIRED_VARS GSS_LIBRARIES GSS_FLAVOUR) - find_package_handle_standard_args(GSS - REQUIRED_VARS - ${_GSS_REQUIRED_VARS} - VERSION_VAR - GSS_VERSION - FAIL_MESSAGE - "Could NOT find GSS, try to set the path to GSS root folder in the system variable GSS_ROOT_DIR" + REQUIRED_VARS + _gss_flavor + _gss_LIBRARIES + VERSION_VAR + GSS_VERSION + FAIL_MESSAGE + "Could NOT find GSS, try to set the absolute path to GSS installation root directory in the environment variable GSS_ROOT_DIR" ) -mark_as_advanced(GSS_INCLUDE_DIR GSS_LIBRARIES) +mark_as_advanced( + _gss_CFLAGS + _gss_FOUND + _gss_INCLUDE_DIRS + _gss_LIBRARIES + _gss_LIBRARY_DIRS + _gss_MODULE_NAME + _gss_PREFIX + _gss_version +) + +if(GSS_FOUND) + if(NOT TARGET CURL::gss) + add_library(CURL::gss INTERFACE IMPORTED) + set_target_properties(CURL::gss PROPERTIES + INTERFACE_CURL_GSS_FLAVOR "${_gss_flavor}" + INTERFACE_LIBCURL_PC_MODULES "${_gss_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_gss_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_gss_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_gss_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_gss_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindGnuTLS.cmake b/third-party/curl/CMake/FindGnuTLS.cmake new file mode 100644 index 0000000000..7f5b227dc2 --- /dev/null +++ b/third-party/curl/CMake/FindGnuTLS.cmake @@ -0,0 +1,92 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Find the GnuTLS library +# +# Input variables: +# +# - `GNUTLS_INCLUDE_DIR`: Absolute path to GnuTLS include directory. +# - `GNUTLS_LIBRARY`: Absolute path to `gnutls` library. +# +# Defines: +# +# - `GNUTLS_FOUND`: System has GnuTLS. +# - `GNUTLS_VERSION`: Version of GnuTLS. +# - `CURL::gnutls`: GnuTLS library target. + +set(_gnutls_pc_requires "gnutls") + +if(CURL_USE_PKGCONFIG AND + NOT DEFINED GNUTLS_INCLUDE_DIR AND + NOT DEFINED GNUTLS_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_gnutls ${_gnutls_pc_requires}) +endif() + +if(_gnutls_FOUND) + set(GnuTLS_FOUND TRUE) + set(GNUTLS_FOUND TRUE) + set(GNUTLS_VERSION ${_gnutls_VERSION}) + message(STATUS "Found GnuTLS (via pkg-config): ${_gnutls_INCLUDE_DIRS} (found version \"${GNUTLS_VERSION}\")") +else() + find_path(GNUTLS_INCLUDE_DIR NAMES "gnutls/gnutls.h") + find_library(GNUTLS_LIBRARY NAMES "gnutls" "libgnutls") + + unset(GNUTLS_VERSION CACHE) + if(GNUTLS_INCLUDE_DIR AND EXISTS "${GNUTLS_INCLUDE_DIR}/gnutls/gnutls.h") + set(_version_regex "#[\t ]*define[\t ]+GNUTLS_VERSION[\t ]+\"([^\"]*)\"") + file(STRINGS "${GNUTLS_INCLUDE_DIR}/gnutls/gnutls.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(GNUTLS_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(GnuTLS + REQUIRED_VARS + GNUTLS_INCLUDE_DIR + GNUTLS_LIBRARY + VERSION_VAR + GNUTLS_VERSION + ) + + if(GNUTLS_FOUND) + set(_gnutls_INCLUDE_DIRS ${GNUTLS_INCLUDE_DIR}) + set(_gnutls_LIBRARIES ${GNUTLS_LIBRARY}) + endif() + + mark_as_advanced(GNUTLS_INCLUDE_DIR GNUTLS_LIBRARY) +endif() + +if(GNUTLS_FOUND) + if(NOT TARGET CURL::gnutls) + add_library(CURL::gnutls INTERFACE IMPORTED) + set_target_properties(CURL::gnutls PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_gnutls_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_gnutls_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_gnutls_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_gnutls_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_gnutls_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindLDAP.cmake b/third-party/curl/CMake/FindLDAP.cmake new file mode 100644 index 0000000000..8902b23f8d --- /dev/null +++ b/third-party/curl/CMake/FindLDAP.cmake @@ -0,0 +1,115 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Find the ldap library +# +# Input variables: +# +# - `LDAP_INCLUDE_DIR`: Absolute path to ldap include directory. +# - `LDAP_LIBRARY`: Absolute path to `ldap` library. +# - `LDAP_LBER_LIBRARY`: Absolute path to `lber` library. +# +# Defines: +# +# - `LDAP_FOUND`: System has ldap. +# - `LDAP_VERSION`: Version of ldap. +# - `CURL::ldap`: ldap library target. + +set(_ldap_pc_requires "ldap" "lber") + +if(CURL_USE_PKGCONFIG AND + NOT DEFINED LDAP_INCLUDE_DIR AND + NOT DEFINED LDAP_LIBRARY AND + NOT DEFINED LDAP_LBER_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_ldap ${_ldap_pc_requires}) +endif() + +if(_ldap_FOUND) + set(LDAP_FOUND TRUE) + set(LDAP_VERSION ${_ldap_ldap_VERSION}) + message(STATUS "Found LDAP (via pkg-config): ${_ldap_INCLUDE_DIRS} (found version \"${LDAP_VERSION}\")") +else() + set(_ldap_pc_requires "") # Depend on pkg-config only when found via pkg-config + + # On Apple the SDK LDAP gets picked up from + # 'MacOSX.sdk/System/Library/Frameworks/LDAP.framework/Headers', which contains + # ldap.h and lber.h both being stubs to include and . + # This causes an infinite inclusion loop in compile. Also do this for libraries + # to avoid picking up the 'ldap.framework' with a full path. + set(_save_cmake_system_framework_path ${CMAKE_SYSTEM_FRAMEWORK_PATH}) + set(CMAKE_SYSTEM_FRAMEWORK_PATH "") + find_path(LDAP_INCLUDE_DIR NAMES "ldap.h") + find_library(LDAP_LIBRARY NAMES "ldap") + find_library(LDAP_LBER_LIBRARY NAMES "lber") + set(CMAKE_SYSTEM_FRAMEWORK_PATH ${_save_cmake_system_framework_path}) + + unset(LDAP_VERSION CACHE) + if(LDAP_INCLUDE_DIR AND EXISTS "${LDAP_INCLUDE_DIR}/ldap_features.h") + set(_version_regex1 "#[\t ]*define[\t ]+LDAP_VENDOR_VERSION_MAJOR[\t ]+([0-9]+).*") + set(_version_regex2 "#[\t ]*define[\t ]+LDAP_VENDOR_VERSION_MINOR[\t ]+([0-9]+).*") + set(_version_regex3 "#[\t ]*define[\t ]+LDAP_VENDOR_VERSION_PATCH[\t ]+([0-9]+).*") + file(STRINGS "${LDAP_INCLUDE_DIR}/ldap_features.h" _version_str1 REGEX "${_version_regex1}") + file(STRINGS "${LDAP_INCLUDE_DIR}/ldap_features.h" _version_str2 REGEX "${_version_regex2}") + file(STRINGS "${LDAP_INCLUDE_DIR}/ldap_features.h" _version_str3 REGEX "${_version_regex3}") + string(REGEX REPLACE "${_version_regex1}" "\\1" _version_str1 "${_version_str1}") + string(REGEX REPLACE "${_version_regex2}" "\\1" _version_str2 "${_version_str2}") + string(REGEX REPLACE "${_version_regex3}" "\\1" _version_str3 "${_version_str3}") + set(LDAP_VERSION "${_version_str1}.${_version_str2}.${_version_str3}") + unset(_version_regex1) + unset(_version_regex2) + unset(_version_regex3) + unset(_version_str1) + unset(_version_str2) + unset(_version_str3) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(LDAP + REQUIRED_VARS + LDAP_INCLUDE_DIR + LDAP_LIBRARY + LDAP_LBER_LIBRARY + VERSION_VAR + LDAP_VERSION + ) + + if(LDAP_FOUND) + set(_ldap_INCLUDE_DIRS ${LDAP_INCLUDE_DIR}) + set(_ldap_LIBRARIES ${LDAP_LIBRARY} ${LDAP_LBER_LIBRARY}) + endif() + + mark_as_advanced(LDAP_INCLUDE_DIR LDAP_LIBRARY LDAP_LBER_LIBRARY) +endif() + +if(LDAP_FOUND) + if(NOT TARGET CURL::ldap) + add_library(CURL::ldap INTERFACE IMPORTED) + set_target_properties(CURL::ldap PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_ldap_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_ldap_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_ldap_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_ldap_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_ldap_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindLibPSL.cmake b/third-party/curl/CMake/FindLibPSL.cmake index e3bd68d1d7..2287e676d3 100644 --- a/third-party/curl/CMake/FindLibPSL.cmake +++ b/third-party/curl/CMake/FindLibPSL.cmake @@ -21,25 +21,72 @@ # SPDX-License-Identifier: curl # ########################################################################### -# - Try to find the libpsl library -# Once done this will define +# Find the libpsl library # -# LIBPSL_FOUND - system has the libpsl library -# LIBPSL_INCLUDE_DIR - the libpsl include directory -# LIBPSL_LIBRARY - the libpsl library name +# Input variables: +# +# - `LIBPSL_INCLUDE_DIR`: Absolute path to libpsl include directory. +# - `LIBPSL_LIBRARY`: Absolute path to `libpsl` library. +# +# Defines: +# +# - `LIBPSL_FOUND`: System has libpsl. +# - `LIBPSL_VERSION`: Version of libpsl. +# - `CURL::libpsl`: libpsl library target. -find_path(LIBPSL_INCLUDE_DIR libpsl.h) +set(_libpsl_pc_requires "libpsl") -find_library(LIBPSL_LIBRARY NAMES psl libpsl) - -if(LIBPSL_INCLUDE_DIR) - file(STRINGS "${LIBPSL_INCLUDE_DIR}/libpsl.h" libpsl_version_str REGEX "^#define[\t ]+PSL_VERSION[\t ]+\"(.*)\"") - string(REGEX REPLACE "^.*\"([^\"]+)\"" "\\1" LIBPSL_VERSION "${libpsl_version_str}") +if(CURL_USE_PKGCONFIG AND + NOT DEFINED LIBPSL_INCLUDE_DIR AND + NOT DEFINED LIBPSL_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_libpsl ${_libpsl_pc_requires}) endif() -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(LibPSL - REQUIRED_VARS LIBPSL_LIBRARY LIBPSL_INCLUDE_DIR - VERSION_VAR LIBPSL_VERSION) +if(_libpsl_FOUND AND _libpsl_INCLUDE_DIRS) + set(Libpsl_FOUND TRUE) + set(LIBPSL_FOUND TRUE) + set(LIBPSL_VERSION ${_libpsl_VERSION}) + message(STATUS "Found Libpsl (via pkg-config): ${_libpsl_INCLUDE_DIRS} (found version \"${LIBPSL_VERSION}\")") +else() + find_path(LIBPSL_INCLUDE_DIR NAMES "libpsl.h") + find_library(LIBPSL_LIBRARY NAMES "psl" "libpsl") -mark_as_advanced(LIBPSL_INCLUDE_DIR LIBPSL_LIBRARY) + unset(LIBPSL_VERSION CACHE) + if(LIBPSL_INCLUDE_DIR AND EXISTS "${LIBPSL_INCLUDE_DIR}/libpsl.h") + set(_version_regex "#[\t ]*define[\t ]+PSL_VERSION[\t ]+\"([^\"]*)\"") + file(STRINGS "${LIBPSL_INCLUDE_DIR}/libpsl.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(LIBPSL_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Libpsl + REQUIRED_VARS + LIBPSL_INCLUDE_DIR + LIBPSL_LIBRARY + VERSION_VAR + LIBPSL_VERSION + ) + + if(LIBPSL_FOUND) + set(_libpsl_INCLUDE_DIRS ${LIBPSL_INCLUDE_DIR}) + set(_libpsl_LIBRARIES ${LIBPSL_LIBRARY}) + endif() + + mark_as_advanced(LIBPSL_INCLUDE_DIR LIBPSL_LIBRARY) +endif() + +if(LIBPSL_FOUND) + if(NOT TARGET CURL::libpsl) + add_library(CURL::libpsl INTERFACE IMPORTED) + set_target_properties(CURL::libpsl PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_libpsl_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_libpsl_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_libpsl_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_libpsl_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_libpsl_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindLibSSH2.cmake b/third-party/curl/CMake/FindLibSSH2.cmake index a0c251ae39..22481d67ae 100644 --- a/third-party/curl/CMake/FindLibSSH2.cmake +++ b/third-party/curl/CMake/FindLibSSH2.cmake @@ -21,25 +21,97 @@ # SPDX-License-Identifier: curl # ########################################################################### -# - Try to find the libssh2 library -# Once done this will define +# Find the libssh2 library # -# LIBSSH2_FOUND - system has the libssh2 library -# LIBSSH2_INCLUDE_DIR - the libssh2 include directory -# LIBSSH2_LIBRARY - the libssh2 library name +# Input variables: +# +# - `LIBSSH2_INCLUDE_DIR`: Absolute path to libssh2 include directory. +# - `LIBSSH2_LIBRARY`: Absolute path to `libssh2` library. +# - `LIBSSH2_USE_STATIC_LIBS`: Configure for static libssh2 libraries. +# +# Defines: +# +# - `LIBSSH2_FOUND`: System has libssh2. +# - `LIBSSH2_VERSION`: Version of libssh2. +# - `CURL::libssh2`: libssh2 library target. -find_path(LIBSSH2_INCLUDE_DIR libssh2.h) +set(_libssh2_pc_requires "libssh2") -find_library(LIBSSH2_LIBRARY NAMES ssh2 libssh2) - -if(LIBSSH2_INCLUDE_DIR) - file(STRINGS "${LIBSSH2_INCLUDE_DIR}/libssh2.h" libssh2_version_str REGEX "^#define[\t ]+LIBSSH2_VERSION[\t ]+\"(.*)\"") - string(REGEX REPLACE "^.*\"([^\"]+)\"" "\\1" LIBSSH2_VERSION "${libssh2_version_str}") +if(NOT DEFINED LIBSSH2_INCLUDE_DIR AND + NOT DEFINED LIBSSH2_LIBRARY) + if(CURL_USE_PKGCONFIG) + find_package(PkgConfig QUIET) + pkg_check_modules(_libssh2 ${_libssh2_pc_requires}) + endif() + if(NOT _libssh2_FOUND AND CURL_USE_CMAKECONFIG) + find_package(libssh2 CONFIG QUIET) + endif() endif() -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(LibSSH2 - REQUIRED_VARS LIBSSH2_LIBRARY LIBSSH2_INCLUDE_DIR - VERSION_VAR LIBSSH2_VERSION) +if(_libssh2_FOUND AND _libssh2_INCLUDE_DIRS) + set(Libssh2_FOUND TRUE) + set(LIBSSH2_FOUND TRUE) + set(LIBSSH2_VERSION ${_libssh2_VERSION}) + if(LIBSSH2_USE_STATIC_LIBS) + set(_libssh2_CFLAGS "${_libssh2_STATIC_CFLAGS}") + set(_libssh2_INCLUDE_DIRS "${_libssh2_STATIC_INCLUDE_DIRS}") + set(_libssh2_LIBRARY_DIRS "${_libssh2_STATIC_LIBRARY_DIRS}") + set(_libssh2_LIBRARIES "${_libssh2_STATIC_LIBRARIES}") + endif() + message(STATUS "Found Libssh2 (via pkg-config): ${_libssh2_INCLUDE_DIRS} (found version \"${LIBSSH2_VERSION}\")") +elseif(libssh2_CONFIG) + set(Libssh2_FOUND TRUE) + set(LIBSSH2_FOUND TRUE) + set(LIBSSH2_VERSION ${libssh2_VERSION}) + if(LIBSSH2_USE_STATIC_LIBS) + set(_libssh2_LIBRARIES libssh2::libssh2_static) + else() + set(_libssh2_LIBRARIES libssh2::libssh2) + endif() + message(STATUS "Found Libssh2 (via CMake Config): ${libssh2_CONFIG} (found version \"${LIBSSH2_VERSION}\")") +else() + find_path(LIBSSH2_INCLUDE_DIR NAMES "libssh2.h") + if(LIBSSH2_USE_STATIC_LIBS) + find_library(LIBSSH2_LIBRARY NAMES "ssh2_static" "libssh2_static" "ssh2" "libssh2") + else() + find_library(LIBSSH2_LIBRARY NAMES "ssh2" "libssh2") + endif() -mark_as_advanced(LIBSSH2_INCLUDE_DIR LIBSSH2_LIBRARY) + unset(LIBSSH2_VERSION CACHE) + if(LIBSSH2_INCLUDE_DIR AND EXISTS "${LIBSSH2_INCLUDE_DIR}/libssh2.h") + set(_version_regex "#[\t ]*define[\t ]+LIBSSH2_VERSION[\t ]+\"([^\"]*)\"") + file(STRINGS "${LIBSSH2_INCLUDE_DIR}/libssh2.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(LIBSSH2_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Libssh2 + REQUIRED_VARS + LIBSSH2_INCLUDE_DIR + LIBSSH2_LIBRARY + VERSION_VAR + LIBSSH2_VERSION + ) + + if(LIBSSH2_FOUND) + set(_libssh2_INCLUDE_DIRS ${LIBSSH2_INCLUDE_DIR}) + set(_libssh2_LIBRARIES ${LIBSSH2_LIBRARY}) + endif() + + mark_as_advanced(LIBSSH2_INCLUDE_DIR LIBSSH2_LIBRARY) +endif() + +if(LIBSSH2_FOUND) + if(NOT TARGET CURL::libssh2) + add_library(CURL::libssh2 INTERFACE IMPORTED) + set_target_properties(CURL::libssh2 PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_libssh2_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_libssh2_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_libssh2_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_libssh2_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_libssh2_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindLibbacktrace.cmake b/third-party/curl/CMake/FindLibbacktrace.cmake new file mode 100644 index 0000000000..59da7fdf19 --- /dev/null +++ b/third-party/curl/CMake/FindLibbacktrace.cmake @@ -0,0 +1,61 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Find the libbacktrace library +# +# Input variables: +# +# - `LIBBACKTRACE_INCLUDE_DIR`: Absolute path to libbacktrace include directory. +# - `LIBBACKTRACE_LIBRARY`: Absolute path to `libbacktrace` library. +# +# Defines: +# +# - `LIBBACKTRACE_FOUND`: System has libbacktrace. +# - `CURL::libbacktrace`: libbacktrace library target. + +find_path(LIBBACKTRACE_INCLUDE_DIR NAMES "backtrace.h") +find_library(LIBBACKTRACE_LIBRARY NAMES "backtrace" "libbacktrace") + +include(FindPackageHandleStandardArgs) +find_package_handle_standard_args(Libbacktrace + REQUIRED_VARS + LIBBACKTRACE_INCLUDE_DIR + LIBBACKTRACE_LIBRARY +) + +if(LIBBACKTRACE_FOUND) + set(_libbacktrace_INCLUDE_DIRS ${LIBBACKTRACE_INCLUDE_DIR}) + set(_libbacktrace_LIBRARIES ${LIBBACKTRACE_LIBRARY}) + + if(NOT TARGET CURL::libbacktrace) + add_library(CURL::libbacktrace INTERFACE IMPORTED) + set_target_properties(CURL::libbacktrace PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_libbacktrace_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_libbacktrace_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_libbacktrace_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_libbacktrace_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_libbacktrace_LIBRARIES}") + endif() +endif() + +mark_as_advanced(LIBBACKTRACE_INCLUDE_DIR LIBBACKTRACE_LIBRARY) diff --git a/third-party/curl/CMake/FindLibgsasl.cmake b/third-party/curl/CMake/FindLibgsasl.cmake new file mode 100644 index 0000000000..7fbaa7128f --- /dev/null +++ b/third-party/curl/CMake/FindLibgsasl.cmake @@ -0,0 +1,91 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Find the libgsasl library +# +# Input variables: +# +# - `LIBGSASL_INCLUDE_DIR`: Absolute path to libgsasl include directory. +# - `LIBGSASL_LIBRARY`: Absolute path to `libgsasl` library. +# +# Defines: +# +# - `LIBGSASL_FOUND`: System has libgsasl. +# - `LIBGSASL_VERSION`: Version of libgsasl. +# - `CURL::libgsasl`: libgsasl library target. + +set(_libgsasl_pc_requires "libgsasl") + +if(CURL_USE_PKGCONFIG AND + NOT DEFINED LIBGSASL_INCLUDE_DIR AND + NOT DEFINED LIBGSASL_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_libgsasl ${_libgsasl_pc_requires}) +endif() + +if(_libgsasl_FOUND) + set(Libgsasl_FOUND TRUE) + set(LIBGSASL_FOUND TRUE) + message(STATUS "Found Libgsasl (via pkg-config): ${_libgsasl_INCLUDE_DIRS} (found version \"${LIBGSASL_VERSION}\")") +else() + find_path(LIBGSASL_INCLUDE_DIR NAMES "gsasl.h") + find_library(LIBGSASL_LIBRARY NAMES "gsasl" "libgsasl") + + unset(LIBGSASL_VERSION CACHE) + if(LIBGSASL_INCLUDE_DIR AND EXISTS "${LIBGSASL_INCLUDE_DIR}/gsasl-version.h") + set(_version_regex "#[\t ]*define[\t ]+GSASL_VERSION[\t ]+\"([^\"]*)\"") + file(STRINGS "${LIBGSASL_INCLUDE_DIR}/gsasl-version.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(LIBGSASL_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Libgsasl + REQUIRED_VARS + LIBGSASL_INCLUDE_DIR + LIBGSASL_LIBRARY + VERSION_VAR + LIBGSASL_VERSION + ) + + if(LIBGSASL_FOUND) + set(_libgsasl_INCLUDE_DIRS ${LIBGSASL_INCLUDE_DIR}) + set(_libgsasl_LIBRARIES ${LIBGSASL_LIBRARY}) + endif() + + mark_as_advanced(LIBGSASL_INCLUDE_DIR LIBGSASL_LIBRARY) +endif() + +if(LIBGSASL_FOUND) + if(NOT TARGET CURL::libgsasl) + add_library(CURL::libgsasl INTERFACE IMPORTED) + set_target_properties(CURL::libgsasl PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_libgsasl_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_libgsasl_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_libgsasl_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_libgsasl_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_libgsasl_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindLibidn2.cmake b/third-party/curl/CMake/FindLibidn2.cmake new file mode 100644 index 0000000000..dc7873489a --- /dev/null +++ b/third-party/curl/CMake/FindLibidn2.cmake @@ -0,0 +1,92 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Find the libidn2 library +# +# Input variables: +# +# - `LIBIDN2_INCLUDE_DIR`: Absolute path to libidn2 include directory. +# - `LIBIDN2_LIBRARY`: Absolute path to `libidn2` library. +# +# Defines: +# +# - `LIBIDN2_FOUND`: System has libidn2. +# - `LIBIDN2_VERSION`: Version of libidn2. +# - `CURL::libidn2`: libidn2 library target. + +set(_libidn2_pc_requires "libidn2") + +if(CURL_USE_PKGCONFIG AND + NOT DEFINED LIBIDN2_INCLUDE_DIR AND + NOT DEFINED LIBIDN2_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_libidn2 ${_libidn2_pc_requires}) +endif() + +if(_libidn2_FOUND) + set(Libidn2_FOUND TRUE) + set(LIBIDN2_FOUND TRUE) + set(LIBIDN2_VERSION ${_libidn2_VERSION}) + message(STATUS "Found Libidn2 (via pkg-config): ${_libidn2_INCLUDE_DIRS} (found version \"${LIBIDN2_VERSION}\")") +else() + find_path(LIBIDN2_INCLUDE_DIR NAMES "idn2.h") + find_library(LIBIDN2_LIBRARY NAMES "idn2" "libidn2") + + unset(LIBIDN2_VERSION CACHE) + if(LIBIDN2_INCLUDE_DIR AND EXISTS "${LIBIDN2_INCLUDE_DIR}/idn2.h") + set(_version_regex "#[\t ]*define[\t ]+IDN2_VERSION[\t ]+\"([^\"]*)\"") + file(STRINGS "${LIBIDN2_INCLUDE_DIR}/idn2.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(LIBIDN2_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Libidn2 + REQUIRED_VARS + LIBIDN2_INCLUDE_DIR + LIBIDN2_LIBRARY + VERSION_VAR + LIBIDN2_VERSION + ) + + if(LIBIDN2_FOUND) + set(_libidn2_INCLUDE_DIRS ${LIBIDN2_INCLUDE_DIR}) + set(_libidn2_LIBRARIES ${LIBIDN2_LIBRARY}) + endif() + + mark_as_advanced(LIBIDN2_INCLUDE_DIR LIBIDN2_LIBRARY) +endif() + +if(LIBIDN2_FOUND) + if(NOT TARGET CURL::libidn2) + add_library(CURL::libidn2 INTERFACE IMPORTED) + set_target_properties(CURL::libidn2 PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_libidn2_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_libidn2_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_libidn2_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_libidn2_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_libidn2_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindLibssh.cmake b/third-party/curl/CMake/FindLibssh.cmake new file mode 100644 index 0000000000..3837d4de62 --- /dev/null +++ b/third-party/curl/CMake/FindLibssh.cmake @@ -0,0 +1,118 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Find the libssh library +# +# Input variables: +# +# - `LIBSSH_INCLUDE_DIR`: Absolute path to libssh include directory. +# - `LIBSSH_LIBRARY`: Absolute path to `libssh` library. +# - `LIBSSH_USE_STATIC_LIBS`: Configure for static libssh libraries. +# +# Defines: +# +# - `LIBSSH_FOUND`: System has libssh. +# - `LIBSSH_VERSION`: Version of libssh. +# - `CURL::libssh`: libssh library target. + +set(_libssh_pc_requires "libssh") + +if(CURL_USE_PKGCONFIG AND + NOT DEFINED LIBSSH_INCLUDE_DIR AND + NOT DEFINED LIBSSH_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_libssh ${_libssh_pc_requires}) +endif() + +if(_libssh_FOUND) + set(Libssh_FOUND TRUE) + set(LIBSSH_FOUND TRUE) + set(LIBSSH_VERSION ${_libssh_VERSION}) + if(LIBSSH_USE_STATIC_LIBS) + set(_libssh_CFLAGS "${_libssh_STATIC_CFLAGS}") + set(_libssh_INCLUDE_DIRS "${_libssh_STATIC_INCLUDE_DIRS}") + set(_libssh_LIBRARY_DIRS "${_libssh_STATIC_LIBRARY_DIRS}") + set(_libssh_LIBRARIES "${_libssh_STATIC_LIBRARIES}") + endif() + message(STATUS "Found Libssh (via pkg-config): ${_libssh_INCLUDE_DIRS} (found version \"${LIBSSH_VERSION}\")") +else() + find_path(LIBSSH_INCLUDE_DIR NAMES "libssh/libssh.h") + if(LIBSSH_USE_STATIC_LIBS) + set(_libssh_CFLAGS "-DLIBSSH_STATIC") + find_library(LIBSSH_LIBRARY NAMES "ssh_static" "libssh_static" "ssh" "libssh") + else() + find_library(LIBSSH_LIBRARY NAMES "ssh" "libssh") + endif() + + unset(LIBSSH_VERSION CACHE) + if(LIBSSH_INCLUDE_DIR AND EXISTS "${LIBSSH_INCLUDE_DIR}/libssh/libssh_version.h") + set(_version_regex1 "#[\t ]*define[\t ]+LIBSSH_VERSION_MAJOR[\t ]+([0-9]+).*") + set(_version_regex2 "#[\t ]*define[\t ]+LIBSSH_VERSION_MINOR[\t ]+([0-9]+).*") + set(_version_regex3 "#[\t ]*define[\t ]+LIBSSH_VERSION_MICRO[\t ]+([0-9]+).*") + file(STRINGS "${LIBSSH_INCLUDE_DIR}/libssh/libssh_version.h" _version_str1 REGEX "${_version_regex1}") + file(STRINGS "${LIBSSH_INCLUDE_DIR}/libssh/libssh_version.h" _version_str2 REGEX "${_version_regex2}") + file(STRINGS "${LIBSSH_INCLUDE_DIR}/libssh/libssh_version.h" _version_str3 REGEX "${_version_regex3}") + string(REGEX REPLACE "${_version_regex1}" "\\1" _version_str1 "${_version_str1}") + string(REGEX REPLACE "${_version_regex2}" "\\1" _version_str2 "${_version_str2}") + string(REGEX REPLACE "${_version_regex3}" "\\1" _version_str3 "${_version_str3}") + set(LIBSSH_VERSION "${_version_str1}.${_version_str2}.${_version_str3}") + unset(_version_regex1) + unset(_version_regex2) + unset(_version_regex3) + unset(_version_str1) + unset(_version_str2) + unset(_version_str3) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Libssh + REQUIRED_VARS + LIBSSH_INCLUDE_DIR + LIBSSH_LIBRARY + VERSION_VAR + LIBSSH_VERSION + ) + + if(LIBSSH_FOUND) + set(_libssh_INCLUDE_DIRS ${LIBSSH_INCLUDE_DIR}) + set(_libssh_LIBRARIES ${LIBSSH_LIBRARY}) + endif() + + mark_as_advanced(LIBSSH_INCLUDE_DIR LIBSSH_LIBRARY) +endif() + +if(LIBSSH_FOUND) + if(WIN32) + list(APPEND _libssh_LIBRARIES "iphlpapi") # for if_nametoindex + endif() + + if(NOT TARGET CURL::libssh) + add_library(CURL::libssh INTERFACE IMPORTED) + set_target_properties(CURL::libssh PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_libssh_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_libssh_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_libssh_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_libssh_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_libssh_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindLibuv.cmake b/third-party/curl/CMake/FindLibuv.cmake new file mode 100644 index 0000000000..47d043cff6 --- /dev/null +++ b/third-party/curl/CMake/FindLibuv.cmake @@ -0,0 +1,102 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Find the libuv library +# +# Input variables: +# +# - `LIBUV_INCLUDE_DIR`: Absolute path to libuv include directory. +# - `LIBUV_LIBRARY`: Absolute path to `libuv` library. +# +# Defines: +# +# - `LIBUV_FOUND`: System has libuv. +# - `LIBUV_VERSION`: Version of libuv. +# - `CURL::libuv`: libuv library target. + +set(_libuv_pc_requires "libuv") + +if(CURL_USE_PKGCONFIG AND + NOT DEFINED LIBUV_INCLUDE_DIR AND + NOT DEFINED LIBUV_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_libuv ${_libuv_pc_requires}) +endif() + +if(_libuv_FOUND) + set(Libuv_FOUND TRUE) + set(LIBUV_FOUND TRUE) + set(LIBUV_VERSION ${_libuv_VERSION}) + message(STATUS "Found Libuv (via pkg-config): ${_libuv_INCLUDE_DIRS} (found version \"${LIBUV_VERSION}\")") +else() + find_path(LIBUV_INCLUDE_DIR NAMES "uv.h") + find_library(LIBUV_LIBRARY NAMES "uv" "libuv") + + unset(LIBUV_VERSION CACHE) + if(LIBUV_INCLUDE_DIR AND EXISTS "${LIBUV_INCLUDE_DIR}/uv/version.h") + set(_version_regex1 "#[\t ]*define[\t ]+UV_VERSION_MAJOR[\t ]+([0-9]+).*") + set(_version_regex2 "#[\t ]*define[\t ]+UV_VERSION_MINOR[\t ]+([0-9]+).*") + set(_version_regex3 "#[\t ]*define[\t ]+UV_VERSION_PATCH[\t ]+([0-9]+).*") + file(STRINGS "${LIBUV_INCLUDE_DIR}/uv/version.h" _version_str1 REGEX "${_version_regex1}") + file(STRINGS "${LIBUV_INCLUDE_DIR}/uv/version.h" _version_str2 REGEX "${_version_regex2}") + file(STRINGS "${LIBUV_INCLUDE_DIR}/uv/version.h" _version_str3 REGEX "${_version_regex3}") + string(REGEX REPLACE "${_version_regex1}" "\\1" _version_str1 "${_version_str1}") + string(REGEX REPLACE "${_version_regex2}" "\\1" _version_str2 "${_version_str2}") + string(REGEX REPLACE "${_version_regex3}" "\\1" _version_str3 "${_version_str3}") + set(LIBUV_VERSION "${_version_str1}.${_version_str2}.${_version_str3}") + unset(_version_regex1) + unset(_version_regex2) + unset(_version_regex3) + unset(_version_str1) + unset(_version_str2) + unset(_version_str3) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Libuv + REQUIRED_VARS + LIBUV_INCLUDE_DIR + LIBUV_LIBRARY + VERSION_VAR + LIBUV_VERSION + ) + + if(LIBUV_FOUND) + set(_libuv_INCLUDE_DIRS ${LIBUV_INCLUDE_DIR}) + set(_libuv_LIBRARIES ${LIBUV_LIBRARY}) + endif() + + mark_as_advanced(LIBUV_INCLUDE_DIR LIBUV_LIBRARY) +endif() + +if(LIBUV_FOUND) + if(NOT TARGET CURL::libuv) + add_library(CURL::libuv INTERFACE IMPORTED) + set_target_properties(CURL::libuv PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_libuv_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_libuv_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_libuv_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_libuv_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_libuv_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindMSH3.cmake b/third-party/curl/CMake/FindMSH3.cmake deleted file mode 100644 index 7d9c6b6544..0000000000 --- a/third-party/curl/CMake/FindMSH3.cmake +++ /dev/null @@ -1,70 +0,0 @@ -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### - -#[=======================================================================[.rst: -FindMSH3 ----------- - -Find the msh3 library - -Result Variables -^^^^^^^^^^^^^^^^ - -``MSH3_FOUND`` - System has msh3 -``MSH3_INCLUDE_DIRS`` - The msh3 include directories. -``MSH3_LIBRARIES`` - The libraries needed to use msh3 -#]=======================================================================] -if(UNIX) - find_package(PkgConfig QUIET) - pkg_search_module(PC_MSH3 libmsh3) -endif() - -find_path(MSH3_INCLUDE_DIR msh3.h - HINTS - ${PC_MSH3_INCLUDEDIR} - ${PC_MSH3_INCLUDE_DIRS} -) - -find_library(MSH3_LIBRARY NAMES msh3 - HINTS - ${PC_MSH3_LIBDIR} - ${PC_MSH3_LIBRARY_DIRS} -) - -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(MSH3 - REQUIRED_VARS - MSH3_LIBRARY - MSH3_INCLUDE_DIR -) - -if(MSH3_FOUND) - set(MSH3_LIBRARIES ${MSH3_LIBRARY}) - set(MSH3_INCLUDE_DIRS ${MSH3_INCLUDE_DIR}) -endif() - -mark_as_advanced(MSH3_INCLUDE_DIRS MSH3_LIBRARIES) diff --git a/third-party/curl/CMake/FindMbedTLS.cmake b/third-party/curl/CMake/FindMbedTLS.cmake index 814bd97da1..21a5f4aec7 100644 --- a/third-party/curl/CMake/FindMbedTLS.cmake +++ b/third-party/curl/CMake/FindMbedTLS.cmake @@ -21,16 +21,117 @@ # SPDX-License-Identifier: curl # ########################################################################### -find_path(MBEDTLS_INCLUDE_DIRS mbedtls/ssl.h) +# Find the mbedTLS library +# +# Input variables: +# +# - `MBEDTLS_INCLUDE_DIR`: Absolute path to mbedTLS include directory. +# - `MBEDTLS_LIBRARY`: Absolute path to `mbedtls` library. +# - `MBEDX509_LIBRARY`: Absolute path to `mbedx509` library. +# - `MBEDCRYPTO_LIBRARY`: Absolute path to `mbedcrypto` library. +# - `MBEDTLS_USE_STATIC_LIBS`: Configure for static mbedTLS libraries. +# +# Defines: +# +# - `MBEDTLS_FOUND`: System has mbedTLS. +# - `MBEDTLS_VERSION`: Version of mbedTLS. +# - `CURL::mbedtls`: mbedTLS library target. -find_library(MBEDTLS_LIBRARY mbedtls) -find_library(MBEDX509_LIBRARY mbedx509) -find_library(MBEDCRYPTO_LIBRARY mbedcrypto) +if(DEFINED MBEDTLS_INCLUDE_DIRS AND NOT DEFINED MBEDTLS_INCLUDE_DIR) + message(WARNING "MBEDTLS_INCLUDE_DIRS is deprecated, use MBEDTLS_INCLUDE_DIR instead.") + set(MBEDTLS_INCLUDE_DIR "${MBEDTLS_INCLUDE_DIRS}") + unset(MBEDTLS_INCLUDE_DIRS) +endif() -set(MBEDTLS_LIBRARIES "${MBEDTLS_LIBRARY}" "${MBEDX509_LIBRARY}" "${MBEDCRYPTO_LIBRARY}") +set(_mbedtls_pc_requires "mbedtls" "mbedx509" "mbedcrypto") -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(MbedTLS DEFAULT_MSG - MBEDTLS_INCLUDE_DIRS MBEDTLS_LIBRARY MBEDX509_LIBRARY MBEDCRYPTO_LIBRARY) +if(NOT DEFINED MBEDTLS_INCLUDE_DIR AND + NOT DEFINED MBEDTLS_LIBRARY AND + NOT DEFINED MBEDX509_LIBRARY AND + NOT DEFINED MBEDCRYPTO_LIBRARY) + if(CURL_USE_PKGCONFIG) + find_package(PkgConfig QUIET) + pkg_check_modules(_mbedtls ${_mbedtls_pc_requires}) + endif() + if(NOT _mbedtls_FOUND AND CURL_USE_CMAKECONFIG) + find_package(MbedTLS CONFIG QUIET) + endif() +endif() -mark_as_advanced(MBEDTLS_INCLUDE_DIRS MBEDTLS_LIBRARY MBEDX509_LIBRARY MBEDCRYPTO_LIBRARY) +if(_mbedtls_FOUND) + set(MbedTLS_FOUND TRUE) + set(MBEDTLS_FOUND TRUE) + set(MBEDTLS_VERSION ${_mbedtls_mbedtls_VERSION}) + if(MBEDTLS_USE_STATIC_LIBS) + set(_mbedtls_CFLAGS "${_mbedtls_STATIC_CFLAGS}") + set(_mbedtls_INCLUDE_DIRS "${_mbedtls_STATIC_INCLUDE_DIRS}") + set(_mbedtls_LIBRARY_DIRS "${_mbedtls_STATIC_LIBRARY_DIRS}") + set(_mbedtls_LIBRARIES "${_mbedtls_STATIC_LIBRARIES}") + endif() + message(STATUS "Found MbedTLS (via pkg-config): ${_mbedtls_INCLUDE_DIRS} (found version \"${MBEDTLS_VERSION}\")") +elseif(MbedTLS_CONFIG) + set(MbedTLS_FOUND TRUE) + set(MBEDTLS_FOUND TRUE) + set(MBEDTLS_VERSION ${MbedTLS_VERSION}) + if(MBEDTLS_VERSION GREATER_EQUAL 4.0.0) + set(_mbedtls_LIBRARIES MbedTLS::tfpsacrypto) + else() + set(_mbedtls_LIBRARIES MbedTLS::mbedcrypto) + endif() + list(APPEND _mbedtls_LIBRARIES MbedTLS::mbedx509 MbedTLS::mbedtls) + message(STATUS "Found MbedTLS (via CMake Config): ${MbedTLS_CONFIG} (found version \"${MBEDTLS_VERSION}\")") +else() + set(_mbedtls_pc_requires "") # Depend on pkg-config only when found via pkg-config + + find_path(MBEDTLS_INCLUDE_DIR NAMES "mbedtls/ssl.h") + if(MBEDTLS_USE_STATIC_LIBS) + find_library(MBEDTLS_LIBRARY NAMES "mbedtls_static" "libmbedtls_static" "mbedtls" "libmbedtls") + find_library(MBEDX509_LIBRARY NAMES "mbedx509_static" "libmbedx509_static" "mbedx509" "libmbedx509") + find_library(MBEDCRYPTO_LIBRARY NAMES "mbedcrypto_static" "libmbedcrypto_static" "mbedcrypto" "libmbedcrypto" + "tfpsacrypto_static" "libtfpsacrypto_static" "tfpsacrypto" "libtfpsacrypto") + else() + find_library(MBEDTLS_LIBRARY NAMES "mbedtls" "libmbedtls") + find_library(MBEDX509_LIBRARY NAMES "mbedx509" "libmbedx509") + find_library(MBEDCRYPTO_LIBRARY NAMES "mbedcrypto" "libmbedcrypto" "tfpsacrypto" "libtfpsacrypto") + endif() + + unset(MBEDTLS_VERSION CACHE) + if(MBEDTLS_INCLUDE_DIR AND EXISTS "${MBEDTLS_INCLUDE_DIR}/mbedtls/build_info.h") + set(_version_regex "#[\t ]*define[\t ]+MBEDTLS_VERSION_STRING[\t ]+\"([0-9.]+)\"") + file(STRINGS "${MBEDTLS_INCLUDE_DIR}/mbedtls/build_info.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(MBEDTLS_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(MbedTLS + REQUIRED_VARS + MBEDTLS_INCLUDE_DIR + MBEDTLS_LIBRARY + MBEDX509_LIBRARY + MBEDCRYPTO_LIBRARY + VERSION_VAR + MBEDTLS_VERSION + ) + + if(MBEDTLS_FOUND) + set(_mbedtls_INCLUDE_DIRS ${MBEDTLS_INCLUDE_DIR}) + set(_mbedtls_LIBRARIES ${MBEDTLS_LIBRARY} ${MBEDX509_LIBRARY} ${MBEDCRYPTO_LIBRARY}) + endif() + + mark_as_advanced(MBEDTLS_INCLUDE_DIR MBEDTLS_LIBRARY MBEDX509_LIBRARY MBEDCRYPTO_LIBRARY) +endif() + +if(MBEDTLS_FOUND) + if(NOT TARGET CURL::mbedtls) + add_library(CURL::mbedtls INTERFACE IMPORTED) + set_target_properties(CURL::mbedtls PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_mbedtls_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_mbedtls_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_mbedtls_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_mbedtls_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_mbedtls_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindNGHTTP2.cmake b/third-party/curl/CMake/FindNGHTTP2.cmake index 3957646c43..bca7cf8a81 100644 --- a/third-party/curl/CMake/FindNGHTTP2.cmake +++ b/third-party/curl/CMake/FindNGHTTP2.cmake @@ -21,21 +21,96 @@ # SPDX-License-Identifier: curl # ########################################################################### -include(FindPackageHandleStandardArgs) +# Find the nghttp2 library +# +# Input variables: +# +# - `NGHTTP2_INCLUDE_DIR`: Absolute path to nghttp2 include directory. +# - `NGHTTP2_LIBRARY`: Absolute path to `nghttp2` library. +# - `NGHTTP2_USE_STATIC_LIBS`: Configure for static nghttp2 libraries. +# +# Defines: +# +# - `NGHTTP2_FOUND`: System has nghttp2. +# - `NGHTTP2_VERSION`: Version of nghttp2. +# - `CURL::nghttp2`: nghttp2 library target. -find_path(NGHTTP2_INCLUDE_DIR "nghttp2/nghttp2.h") +set(_nghttp2_pc_requires "libnghttp2") -find_library(NGHTTP2_LIBRARY NAMES nghttp2) +if(NOT DEFINED NGHTTP2_INCLUDE_DIR AND + NOT DEFINED NGHTTP2_LIBRARY) + if(CURL_USE_PKGCONFIG) + find_package(PkgConfig QUIET) + pkg_check_modules(_nghttp2 ${_nghttp2_pc_requires}) + endif() + if(NOT _nghttp2_FOUND AND CURL_USE_CMAKECONFIG) + find_package(nghttp2 CONFIG QUIET) + endif() +endif() -find_package_handle_standard_args(NGHTTP2 - FOUND_VAR - NGHTTP2_FOUND +if(_nghttp2_FOUND) + set(NGHTTP2_FOUND TRUE) + set(NGHTTP2_VERSION ${_nghttp2_VERSION}) + if(NGHTTP2_USE_STATIC_LIBS) + set(_nghttp2_CFLAGS "${_nghttp2_STATIC_CFLAGS}") + set(_nghttp2_INCLUDE_DIRS "${_nghttp2_STATIC_INCLUDE_DIRS}") + set(_nghttp2_LIBRARY_DIRS "${_nghttp2_STATIC_LIBRARY_DIRS}") + set(_nghttp2_LIBRARIES "${_nghttp2_STATIC_LIBRARIES}") + endif() + message(STATUS "Found NGHTTP2 (via pkg-config): ${_nghttp2_INCLUDE_DIRS} (found version \"${NGHTTP2_VERSION}\")") +elseif(nghttp2_CONFIG) + set(NGHTTP2_FOUND TRUE) + set(NGHTTP2_VERSION ${nghttp2_VERSION}) + if(NGHTTP2_USE_STATIC_LIBS OR NOT TARGET nghttp2::nghttp2) + set(_nghttp2_LIBRARIES nghttp2::nghttp2_static) + else() + set(_nghttp2_LIBRARIES nghttp2::nghttp2) + endif() + message(STATUS "Found NGHTTP2 (via CMake Config): ${nghttp2_CONFIG} (found version \"${NGHTTP2_VERSION}\")") +else() + find_path(NGHTTP2_INCLUDE_DIR NAMES "nghttp2/nghttp2.h") + if(NGHTTP2_USE_STATIC_LIBS) + set(_nghttp2_CFLAGS "-DNGHTTP2_STATICLIB") + find_library(NGHTTP2_LIBRARY NAMES "nghttp2_static" "nghttp2") + else() + find_library(NGHTTP2_LIBRARY NAMES "nghttp2" "nghttp2_static") + endif() + + unset(NGHTTP2_VERSION CACHE) + if(NGHTTP2_INCLUDE_DIR AND EXISTS "${NGHTTP2_INCLUDE_DIR}/nghttp2/nghttp2ver.h") + set(_version_regex "#[\t ]*define[\t ]+NGHTTP2_VERSION[\t ]+\"([^\"]*)\"") + file(STRINGS "${NGHTTP2_INCLUDE_DIR}/nghttp2/nghttp2ver.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(NGHTTP2_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(NGHTTP2 REQUIRED_VARS - NGHTTP2_LIBRARY NGHTTP2_INCLUDE_DIR -) + NGHTTP2_LIBRARY + VERSION_VAR + NGHTTP2_VERSION + ) -set(NGHTTP2_INCLUDE_DIRS ${NGHTTP2_INCLUDE_DIR}) -set(NGHTTP2_LIBRARIES ${NGHTTP2_LIBRARY}) + if(NGHTTP2_FOUND) + set(_nghttp2_INCLUDE_DIRS ${NGHTTP2_INCLUDE_DIR}) + set(_nghttp2_LIBRARIES ${NGHTTP2_LIBRARY}) + endif() -mark_as_advanced(NGHTTP2_INCLUDE_DIRS NGHTTP2_LIBRARIES) + mark_as_advanced(NGHTTP2_INCLUDE_DIR NGHTTP2_LIBRARY) +endif() + +if(NGHTTP2_FOUND) + if(NOT TARGET CURL::nghttp2) + add_library(CURL::nghttp2 INTERFACE IMPORTED) + set_target_properties(CURL::nghttp2 PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_nghttp2_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_nghttp2_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_nghttp2_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_nghttp2_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_nghttp2_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindNGHTTP3.cmake b/third-party/curl/CMake/FindNGHTTP3.cmake index 9b13e6c6ff..ed671b7a49 100644 --- a/third-party/curl/CMake/FindNGHTTP3.cmake +++ b/third-party/curl/CMake/FindNGHTTP3.cmake @@ -21,58 +21,96 @@ # SPDX-License-Identifier: curl # ########################################################################### +# Find the nghttp3 library +# +# Input variables: +# +# - `NGHTTP3_INCLUDE_DIR`: Absolute path to nghttp3 include directory. +# - `NGHTTP3_LIBRARY`: Absolute path to `nghttp3` library. +# - `NGHTTP3_USE_STATIC_LIBS`: Configure for static nghttp3 libraries. +# +# Defines: +# +# - `NGHTTP3_FOUND`: System has nghttp3. +# - `NGHTTP3_VERSION`: Version of nghttp3. +# - `CURL::nghttp3`: nghttp3 library target. -#[=======================================================================[.rst: -FindNGHTTP3 ----------- +set(_nghttp3_pc_requires "libnghttp3") -Find the nghttp3 library - -Result Variables -^^^^^^^^^^^^^^^^ - -``NGHTTP3_FOUND`` - System has nghttp3 -``NGHTTP3_INCLUDE_DIRS`` - The nghttp3 include directories. -``NGHTTP3_LIBRARIES`` - The libraries needed to use nghttp3 -``NGHTTP3_VERSION`` - version of nghttp3. -#]=======================================================================] - -if(UNIX) - find_package(PkgConfig QUIET) - pkg_search_module(PC_NGHTTP3 libnghttp3) +if(NOT DEFINED NGHTTP3_INCLUDE_DIR AND + NOT DEFINED NGHTTP3_LIBRARY) + if(CURL_USE_PKGCONFIG) + find_package(PkgConfig QUIET) + pkg_check_modules(_nghttp3 ${_nghttp3_pc_requires}) + endif() + if(NOT _nghttp3_FOUND AND CURL_USE_CMAKECONFIG) + find_package(nghttp3 CONFIG QUIET) + endif() endif() -find_path(NGHTTP3_INCLUDE_DIR nghttp3/nghttp3.h - HINTS - ${PC_NGHTTP3_INCLUDEDIR} - ${PC_NGHTTP3_INCLUDE_DIRS} -) +if(_nghttp3_FOUND) + set(NGHTTP3_FOUND TRUE) + set(NGHTTP3_VERSION ${_nghttp3_VERSION}) + if(NGHTTP3_USE_STATIC_LIBS) + set(_nghttp3_CFLAGS "${_nghttp3_STATIC_CFLAGS}") + set(_nghttp3_INCLUDE_DIRS "${_nghttp3_STATIC_INCLUDE_DIRS}") + set(_nghttp3_LIBRARY_DIRS "${_nghttp3_STATIC_LIBRARY_DIRS}") + set(_nghttp3_LIBRARIES "${_nghttp3_STATIC_LIBRARIES}") + endif() + message(STATUS "Found NGHTTP3 (via pkg-config): ${_nghttp3_INCLUDE_DIRS} (found version \"${NGHTTP3_VERSION}\")") +elseif(nghttp3_CONFIG) + set(NGHTTP3_FOUND TRUE) + set(NGHTTP3_VERSION ${nghttp3_VERSION}) + if(NGHTTP3_USE_STATIC_LIBS OR NOT TARGET nghttp3::nghttp3) + set(_nghttp3_LIBRARIES nghttp3::nghttp3_static) + else() + set(_nghttp3_LIBRARIES nghttp3::nghttp3) + endif() + message(STATUS "Found NGHTTP3 (via CMake Config): ${nghttp3_CONFIG} (found version \"${NGHTTP3_VERSION}\")") +else() + find_path(NGHTTP3_INCLUDE_DIR NAMES "nghttp3/nghttp3.h") + if(NGHTTP3_USE_STATIC_LIBS) + set(_nghttp3_CFLAGS "-DNGHTTP3_STATICLIB") + find_library(NGHTTP3_LIBRARY NAMES "nghttp3_static" "nghttp3") + else() + find_library(NGHTTP3_LIBRARY NAMES "nghttp3") + endif() -find_library(NGHTTP3_LIBRARY NAMES nghttp3 - HINTS - ${PC_NGHTTP3_LIBDIR} - ${PC_NGHTTP3_LIBRARY_DIRS} -) + unset(NGHTTP3_VERSION CACHE) + if(NGHTTP3_INCLUDE_DIR AND EXISTS "${NGHTTP3_INCLUDE_DIR}/nghttp3/version.h") + set(_version_regex "#[\t ]*define[\t ]+NGHTTP3_VERSION[\t ]+\"([^\"]*)\"") + file(STRINGS "${NGHTTP3_INCLUDE_DIR}/nghttp3/version.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(NGHTTP3_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() -if(PC_NGHTTP3_VERSION) - set(NGHTTP3_VERSION ${PC_NGHTTP3_VERSION}) + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(NGHTTP3 + REQUIRED_VARS + NGHTTP3_INCLUDE_DIR + NGHTTP3_LIBRARY + VERSION_VAR + NGHTTP3_VERSION + ) + + if(NGHTTP3_FOUND) + set(_nghttp3_INCLUDE_DIRS ${NGHTTP3_INCLUDE_DIR}) + set(_nghttp3_LIBRARIES ${NGHTTP3_LIBRARY}) + endif() + + mark_as_advanced(NGHTTP3_INCLUDE_DIR NGHTTP3_LIBRARY) endif() -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(NGHTTP3 - REQUIRED_VARS - NGHTTP3_LIBRARY - NGHTTP3_INCLUDE_DIR - VERSION_VAR NGHTTP3_VERSION -) - if(NGHTTP3_FOUND) - set(NGHTTP3_LIBRARIES ${NGHTTP3_LIBRARY}) - set(NGHTTP3_INCLUDE_DIRS ${NGHTTP3_INCLUDE_DIR}) + if(NOT TARGET CURL::nghttp3) + add_library(CURL::nghttp3 INTERFACE IMPORTED) + set_target_properties(CURL::nghttp3 PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_nghttp3_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_nghttp3_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_nghttp3_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_nghttp3_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_nghttp3_LIBRARIES}") + endif() endif() - -mark_as_advanced(NGHTTP3_INCLUDE_DIRS NGHTTP3_LIBRARIES) diff --git a/third-party/curl/CMake/FindNGTCP2.cmake b/third-party/curl/CMake/FindNGTCP2.cmake index ae92e417a5..bf2f488777 100644 --- a/third-party/curl/CMake/FindNGTCP2.cmake +++ b/third-party/curl/CMake/FindNGTCP2.cmake @@ -21,95 +21,167 @@ # SPDX-License-Identifier: curl # ########################################################################### +# Find the ngtcp2 library +# +# This module accepts optional COMPONENTS to control the crypto library (these are +# mutually exclusive): +# +# - BoringSSL: Use `libngtcp2_crypto_boringssl`. (also for AWS-LC) +# - GnuTLS: Use `libngtcp2_crypto_gnutls`. +# - LibreSSL: Use `libngtcp2_crypto_libressl`. (requires ngtcp2 1.15.0+) +# - ossl: Use `libngtcp2_crypto_ossl`. +# - quictls: Use `libngtcp2_crypto_quictls`. (also for LibreSSL with ngtcp2 <1.15.0) +# - wolfSSL: Use `libngtcp2_crypto_wolfssl`. +# +# Input variables: +# +# - `NGTCP2_INCLUDE_DIR`: Absolute path to ngtcp2 include directory. +# - `NGTCP2_LIBRARY`: Absolute path to `ngtcp2` library. +# - `NGTCP2_CRYPTO_BORINGSSL_LIBRARY`: Absolute path to `ngtcp2_crypto_boringssl` library. +# - `NGTCP2_CRYPTO_GNUTLS_LIBRARY`: Absolute path to `ngtcp2_crypto_gnutls` library. +# - `NGTCP2_CRYPTO_LIBRESSL_LIBRARY`: Absolute path to `ngtcp2_crypto_libressl` library. +# - `NGTCP2_CRYPTO_OSSL_LIBRARY`: Absolute path to `ngtcp2_crypto_ossl` library. +# - `NGTCP2_CRYPTO_QUICTLS_LIBRARY`: Absolute path to `ngtcp2_crypto_quictls` library. +# - `NGTCP2_CRYPTO_WOLFSSL_LIBRARY`: Absolute path to `ngtcp2_crypto_wolfssl` library. +# - `NGTCP2_USE_STATIC_LIBS`: Configure for static ngtcp2 libraries. +# +# Defines: +# +# - `NGTCP2_FOUND`: System has ngtcp2. +# - `NGTCP2_VERSION`: Version of ngtcp2. +# - `NGTCP2_CRYPTO_BACKEND`: Name of the crypto library component. (Empty if COMPONENTS was not used.) +# - `CURL::ngtcp2`: ngtcp2 library target. -#[=======================================================================[.rst: -FindNGTCP2 ----------- - -Find the ngtcp2 library - -This module accepts optional COMPONENTS to control the crypto library (these are -mutually exclusive):: - - OpenSSL: Use libngtcp2_crypto_quictls - GnuTLS: Use libngtcp2_crypto_gnutls - -Result Variables -^^^^^^^^^^^^^^^^ - -``NGTCP2_FOUND`` - System has ngtcp2 -``NGTCP2_INCLUDE_DIRS`` - The ngtcp2 include directories. -``NGTCP2_LIBRARIES`` - The libraries needed to use ngtcp2 -``NGTCP2_VERSION`` - version of ngtcp2. -#]=======================================================================] - -if(UNIX) - find_package(PkgConfig QUIET) - pkg_search_module(PC_NGTCP2 libngtcp2) -endif() - -find_path(NGTCP2_INCLUDE_DIR ngtcp2/ngtcp2.h - HINTS - ${PC_NGTCP2_INCLUDEDIR} - ${PC_NGTCP2_INCLUDE_DIRS} -) - -find_library(NGTCP2_LIBRARY NAMES ngtcp2 - HINTS - ${PC_NGTCP2_LIBDIR} - ${PC_NGTCP2_LIBRARY_DIRS} -) - -if(PC_NGTCP2_VERSION) - set(NGTCP2_VERSION ${PC_NGTCP2_VERSION}) -endif() - +set(NGTCP2_CRYPTO_BACKEND "") if(NGTCP2_FIND_COMPONENTS) - set(NGTCP2_CRYPTO_BACKEND "") - foreach(component IN LISTS NGTCP2_FIND_COMPONENTS) - if(component MATCHES "^(BoringSSL|quictls|wolfSSL|GnuTLS)") + foreach(_component IN LISTS NGTCP2_FIND_COMPONENTS) + if(_component MATCHES "^(BoringSSL|GnuTLS|LibreSSL|ossl|quictls|wolfSSL)") if(NGTCP2_CRYPTO_BACKEND) message(FATAL_ERROR "NGTCP2: Only one crypto library can be selected") endif() - set(NGTCP2_CRYPTO_BACKEND ${component}) + set(NGTCP2_CRYPTO_BACKEND ${_component}) endif() endforeach() if(NGTCP2_CRYPTO_BACKEND) - string(TOLOWER "ngtcp2_crypto_${NGTCP2_CRYPTO_BACKEND}" _crypto_library) - if(UNIX) - pkg_search_module(PC_${_crypto_library} lib${_crypto_library}) - endif() - find_library(${_crypto_library}_LIBRARY - NAMES - ${_crypto_library} - HINTS - ${PC_${_crypto_library}_LIBDIR} - ${PC_${_crypto_library}_LIBRARY_DIRS} - ) - if(${_crypto_library}_LIBRARY) - set(NGTCP2_${NGTCP2_CRYPTO_BACKEND}_FOUND TRUE) - set(NGTCP2_CRYPTO_LIBRARY ${${_crypto_library}_LIBRARY}) + string(TOLOWER "ngtcp2_crypto_${NGTCP2_CRYPTO_BACKEND}" _crypto_library_lower) + string(TOUPPER "ngtcp2_crypto_${NGTCP2_CRYPTO_BACKEND}" _crypto_library_upper) + endif() +endif() + +set(_ngtcp2_pc_requires "libngtcp2") +if(NGTCP2_CRYPTO_BACKEND) + list(APPEND _ngtcp2_pc_requires "lib${_crypto_library_lower}") +endif() + +set(_tried_pkgconfig FALSE) +if(NOT DEFINED NGTCP2_INCLUDE_DIR AND + NOT DEFINED NGTCP2_LIBRARY) + if(CURL_USE_PKGCONFIG) + find_package(PkgConfig QUIET) + pkg_check_modules(_ngtcp2 ${_ngtcp2_pc_requires}) + set(_tried_pkgconfig TRUE) + endif() + if(NOT _ngtcp2_FOUND AND CURL_USE_CMAKECONFIG AND NGTCP2_CRYPTO_BACKEND) + find_package(ngtcp2 CONFIG QUIET) + # Skip using it if the crypto library target is not available + if(ngtcp2_CONFIG AND + NOT TARGET ngtcp2::${_crypto_library_lower}_static AND + NOT TARGET ngtcp2::${_crypto_library_lower}) + unset(ngtcp2_CONFIG) endif() endif() endif() -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(NGTCP2 - REQUIRED_VARS - NGTCP2_LIBRARY - NGTCP2_INCLUDE_DIR - VERSION_VAR NGTCP2_VERSION - HANDLE_COMPONENTS -) +if(_ngtcp2_FOUND) + set(NGTCP2_FOUND TRUE) + set(NGTCP2_VERSION ${_ngtcp2_libngtcp2_VERSION}) + if(NGTCP2_USE_STATIC_LIBS) + set(_ngtcp2_CFLAGS "${_ngtcp2_STATIC_CFLAGS}") + set(_ngtcp2_INCLUDE_DIRS "${_ngtcp2_STATIC_INCLUDE_DIRS}") + set(_ngtcp2_LIBRARY_DIRS "${_ngtcp2_STATIC_LIBRARY_DIRS}") + set(_ngtcp2_LIBRARIES "${_ngtcp2_STATIC_LIBRARIES}") + endif() + message(STATUS "Found NGTCP2 (via pkg-config): ${_ngtcp2_INCLUDE_DIRS} (found version \"${NGTCP2_VERSION}\")") +elseif(ngtcp2_CONFIG) + set(NGTCP2_FOUND TRUE) + set(NGTCP2_VERSION ${ngtcp2_VERSION}) + if(NGTCP2_USE_STATIC_LIBS OR NOT TARGET ngtcp2::ngtcp2) + set(_ngtcp2_LIBRARIES ngtcp2::ngtcp2_static ngtcp2::${_crypto_library_lower}_static) + else() + set(_ngtcp2_LIBRARIES ngtcp2::ngtcp2 ngtcp2::${_crypto_library_lower}) + endif() + message(STATUS "Found NGTCP2 (via CMake Config): ${ngtcp2_CONFIG} (found version \"${NGTCP2_VERSION}\")") +else() + find_path(NGTCP2_INCLUDE_DIR NAMES "ngtcp2/ngtcp2.h") + if(NGTCP2_USE_STATIC_LIBS) + set(_ngtcp2_CFLAGS "-DNGTCP2_STATICLIB") + find_library(NGTCP2_LIBRARY NAMES "ngtcp2_static" "ngtcp2") + else() + find_library(NGTCP2_LIBRARY NAMES "ngtcp2") + endif() -if(NGTCP2_FOUND) - set(NGTCP2_LIBRARIES ${NGTCP2_LIBRARY} ${NGTCP2_CRYPTO_LIBRARY}) - set(NGTCP2_INCLUDE_DIRS ${NGTCP2_INCLUDE_DIR}) + unset(NGTCP2_VERSION CACHE) + if(NGTCP2_INCLUDE_DIR AND EXISTS "${NGTCP2_INCLUDE_DIR}/ngtcp2/version.h") + set(_version_regex "#[\t ]*define[\t ]+NGTCP2_VERSION[\t ]+\"([^\"]*)\"") + file(STRINGS "${NGTCP2_INCLUDE_DIR}/ngtcp2/version.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(NGTCP2_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() + + if(NGTCP2_CRYPTO_BACKEND) + if(CMAKE_VERSION VERSION_GREATER_EQUAL 3.20) + cmake_path(GET NGTCP2_LIBRARY PARENT_PATH _ngtcp2_library_dir) + else() + get_filename_component(_ngtcp2_library_dir "${NGTCP2_LIBRARY}" DIRECTORY) + endif() + if(NGTCP2_USE_STATIC_LIBS) + find_library(${_crypto_library_upper}_LIBRARY NAMES ${_crypto_library_lower}_static ${_crypto_library_lower} + HINTS ${_ngtcp2_library_dir}) + else() + find_library(${_crypto_library_upper}_LIBRARY NAMES ${_crypto_library_lower} + HINTS ${_ngtcp2_library_dir}) + endif() + + if(${_crypto_library_upper}_LIBRARY) + set(NGTCP2_${NGTCP2_CRYPTO_BACKEND}_FOUND TRUE) + set(NGTCP2_CRYPTO_LIBRARY ${${_crypto_library_upper}_LIBRARY}) + endif() + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(NGTCP2 + REQUIRED_VARS + NGTCP2_INCLUDE_DIR + NGTCP2_LIBRARY + VERSION_VAR + NGTCP2_VERSION + HANDLE_COMPONENTS + ) + + if(NGTCP2_FOUND) + set(_ngtcp2_INCLUDE_DIRS ${NGTCP2_INCLUDE_DIR}) + set(_ngtcp2_LIBRARIES ${NGTCP2_LIBRARY} ${NGTCP2_CRYPTO_LIBRARY}) + endif() + + mark_as_advanced(NGTCP2_INCLUDE_DIR NGTCP2_LIBRARY NGTCP2_CRYPTO_LIBRARY) + + if(NOT NGTCP2_FOUND AND _tried_pkgconfig) # reset variables to allow another round of detection + unset(NGTCP2_INCLUDE_DIR CACHE) + unset(NGTCP2_LIBRARY CACHE) + endif() endif() -mark_as_advanced(NGTCP2_INCLUDE_DIRS NGTCP2_LIBRARIES) +if(NGTCP2_FOUND) + if(NOT TARGET CURL::ngtcp2) + add_library(CURL::ngtcp2 INTERFACE IMPORTED) + set_target_properties(CURL::ngtcp2 PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_ngtcp2_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_ngtcp2_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_ngtcp2_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_ngtcp2_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_ngtcp2_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindNettle.cmake b/third-party/curl/CMake/FindNettle.cmake new file mode 100644 index 0000000000..c963180cba --- /dev/null +++ b/third-party/curl/CMake/FindNettle.cmake @@ -0,0 +1,97 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Find the nettle library +# +# Input variables: +# +# - `NETTLE_INCLUDE_DIR`: Absolute path to nettle include directory. +# - `NETTLE_LIBRARY`: Absolute path to `nettle` library. +# +# Defines: +# +# - `NETTLE_FOUND`: System has nettle. +# - `NETTLE_VERSION`: Version of nettle. +# - `CURL::nettle`: nettle library target. + +set(_nettle_pc_requires "nettle") + +if(CURL_USE_PKGCONFIG AND + NOT DEFINED NETTLE_INCLUDE_DIR AND + NOT DEFINED NETTLE_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_nettle ${_nettle_pc_requires}) +endif() + +if(_nettle_FOUND) + set(Nettle_FOUND TRUE) + set(NETTLE_FOUND TRUE) + set(NETTLE_VERSION ${_nettle_VERSION}) + message(STATUS "Found Nettle (via pkg-config): ${_nettle_INCLUDE_DIRS} (found version \"${NETTLE_VERSION}\")") +else() + find_path(NETTLE_INCLUDE_DIR NAMES "nettle/sha2.h") + find_library(NETTLE_LIBRARY NAMES "nettle") + + unset(NETTLE_VERSION CACHE) + if(NETTLE_INCLUDE_DIR AND EXISTS "${NETTLE_INCLUDE_DIR}/nettle/version.h") + set(_version_regex1 "#[\t ]*define[ \t]+NETTLE_VERSION_MAJOR[ \t]+([0-9]+).*") + set(_version_regex2 "#[\t ]*define[ \t]+NETTLE_VERSION_MINOR[ \t]+([0-9]+).*") + file(STRINGS "${NETTLE_INCLUDE_DIR}/nettle/version.h" _version_str1 REGEX "${_version_regex1}") + file(STRINGS "${NETTLE_INCLUDE_DIR}/nettle/version.h" _version_str2 REGEX "${_version_regex2}") + string(REGEX REPLACE "${_version_regex1}" "\\1" _version_str1 "${_version_str1}") + string(REGEX REPLACE "${_version_regex2}" "\\1" _version_str2 "${_version_str2}") + set(NETTLE_VERSION "${_version_str1}.${_version_str2}") + unset(_version_regex1) + unset(_version_regex2) + unset(_version_str1) + unset(_version_str2) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Nettle + REQUIRED_VARS + NETTLE_INCLUDE_DIR + NETTLE_LIBRARY + VERSION_VAR + NETTLE_VERSION + ) + + if(NETTLE_FOUND) + set(_nettle_INCLUDE_DIRS ${NETTLE_INCLUDE_DIR}) + set(_nettle_LIBRARIES ${NETTLE_LIBRARY}) + endif() + + mark_as_advanced(NETTLE_INCLUDE_DIR NETTLE_LIBRARY) +endif() + +if(NETTLE_FOUND) + if(NOT TARGET CURL::nettle) + add_library(CURL::nettle INTERFACE IMPORTED) + set_target_properties(CURL::nettle PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_nettle_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_nettle_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_nettle_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_nettle_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_nettle_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindQUICHE.cmake b/third-party/curl/CMake/FindQUICHE.cmake index 0488463d55..137679b5b3 100644 --- a/third-party/curl/CMake/FindQUICHE.cmake +++ b/third-party/curl/CMake/FindQUICHE.cmake @@ -21,50 +21,60 @@ # SPDX-License-Identifier: curl # ########################################################################### +# Find the quiche library +# +# Input variables: +# +# - `QUICHE_INCLUDE_DIR`: Absolute path to quiche include directory. +# - `QUICHE_LIBRARY`: Absolute path to `quiche` library. +# +# Defines: +# +# - `QUICHE_FOUND`: System has quiche. +# - `QUICHE_VERSION`: Version of quiche. +# - `CURL::quiche`: quiche library target. -#[=======================================================================[.rst: -FindQUICHE ----------- +set(_quiche_pc_requires "quiche") -Find the quiche library - -Result Variables -^^^^^^^^^^^^^^^^ - -``QUICHE_FOUND`` - System has quiche -``QUICHE_INCLUDE_DIRS`` - The quiche include directories. -``QUICHE_LIBRARIES`` - The libraries needed to use quiche -#]=======================================================================] -if(UNIX) +if(CURL_USE_PKGCONFIG AND + NOT DEFINED QUICHE_INCLUDE_DIR AND + NOT DEFINED QUICHE_LIBRARY) find_package(PkgConfig QUIET) - pkg_search_module(PC_QUICHE quiche) + pkg_check_modules(_quiche ${_quiche_pc_requires}) endif() -find_path(QUICHE_INCLUDE_DIR quiche.h - HINTS - ${PC_QUICHE_INCLUDEDIR} - ${PC_QUICHE_INCLUDE_DIRS} -) +if(_quiche_FOUND) + set(Quiche_FOUND TRUE) + set(QUICHE_FOUND TRUE) + set(QUICHE_VERSION ${_quiche_VERSION}) + message(STATUS "Found Quiche (via pkg-config): ${_quiche_INCLUDE_DIRS} (found version \"${QUICHE_VERSION}\")") +else() + find_path(QUICHE_INCLUDE_DIR NAMES "quiche.h") + find_library(QUICHE_LIBRARY NAMES "quiche") -find_library(QUICHE_LIBRARY NAMES quiche - HINTS - ${PC_QUICHE_LIBDIR} - ${PC_QUICHE_LIBRARY_DIRS} -) + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Quiche + REQUIRED_VARS + QUICHE_INCLUDE_DIR + QUICHE_LIBRARY + ) -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(QUICHE - REQUIRED_VARS - QUICHE_LIBRARY - QUICHE_INCLUDE_DIR -) + if(QUICHE_FOUND) + set(_quiche_INCLUDE_DIRS ${QUICHE_INCLUDE_DIR}) + set(_quiche_LIBRARIES ${QUICHE_LIBRARY}) + endif() + + mark_as_advanced(QUICHE_INCLUDE_DIR QUICHE_LIBRARY) +endif() if(QUICHE_FOUND) - set(QUICHE_LIBRARIES ${QUICHE_LIBRARY}) - set(QUICHE_INCLUDE_DIRS ${QUICHE_INCLUDE_DIR}) + if(NOT TARGET CURL::quiche) + add_library(CURL::quiche INTERFACE IMPORTED) + set_target_properties(CURL::quiche PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_quiche_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_quiche_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_quiche_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_quiche_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_quiche_LIBRARIES}") + endif() endif() - -mark_as_advanced(QUICHE_INCLUDE_DIRS QUICHE_LIBRARIES) diff --git a/third-party/curl/CMake/FindRustls.cmake b/third-party/curl/CMake/FindRustls.cmake new file mode 100644 index 0000000000..1e07565189 --- /dev/null +++ b/third-party/curl/CMake/FindRustls.cmake @@ -0,0 +1,116 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Find the Rustls library +# +# Input variables: +# +# - `RUSTLS_INCLUDE_DIR`: Absolute path to Rustls include directory. +# - `RUSTLS_LIBRARY`: Absolute path to `rustls` library. +# +# Defines: +# +# - `RUSTLS_FOUND`: System has Rustls. +# - `RUSTLS_VERSION`: Version of Rustls. +# - `CURL::rustls`: Rustls library target. + +set(_rustls_pc_requires "rustls") + +if(CURL_USE_PKGCONFIG AND + NOT DEFINED RUSTLS_INCLUDE_DIR AND + NOT DEFINED RUSTLS_LIBRARY) + find_package(PkgConfig QUIET) + pkg_check_modules(_rustls ${_rustls_pc_requires}) +endif() + +if(_rustls_FOUND) + set(Rustls_FOUND TRUE) + set(RUSTLS_FOUND TRUE) + set(RUSTLS_VERSION ${_rustls_VERSION}) + message(STATUS "Found Rustls (via pkg-config): ${_rustls_INCLUDE_DIRS} (found version \"${RUSTLS_VERSION}\")") +else() + set(_rustls_pc_requires "") # Depend on pkg-config only when found via pkg-config + + find_path(RUSTLS_INCLUDE_DIR NAMES "rustls.h") + find_library(RUSTLS_LIBRARY NAMES "rustls") + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Rustls + REQUIRED_VARS + RUSTLS_INCLUDE_DIR + RUSTLS_LIBRARY + ) + + if(RUSTLS_FOUND) + set(_rustls_INCLUDE_DIRS ${RUSTLS_INCLUDE_DIR}) + set(_rustls_LIBRARIES ${RUSTLS_LIBRARY}) + endif() + + mark_as_advanced(RUSTLS_INCLUDE_DIR RUSTLS_LIBRARY) +endif() + +if(RUSTLS_FOUND) + if(APPLE) + find_library(SECURITY_FRAMEWORK NAMES "Security") + mark_as_advanced(SECURITY_FRAMEWORK) + if(NOT SECURITY_FRAMEWORK) + message(FATAL_ERROR "Security framework not found") + endif() + list(APPEND _rustls_LIBRARIES "-framework Security") + + find_library(FOUNDATION_FRAMEWORK NAMES "Foundation") + mark_as_advanced(FOUNDATION_FRAMEWORK) + if(NOT FOUNDATION_FRAMEWORK) + message(FATAL_ERROR "Foundation framework not found") + endif() + list(APPEND _rustls_LIBRARIES "-framework Foundation") + elseif(NOT WIN32) + find_library(PTHREAD_LIBRARY NAMES "pthread") + if(PTHREAD_LIBRARY) + list(APPEND _rustls_LIBRARIES ${PTHREAD_LIBRARY}) + endif() + mark_as_advanced(PTHREAD_LIBRARY) + + find_library(DL_LIBRARY NAMES "dl") + if(DL_LIBRARY) + list(APPEND _rustls_LIBRARIES ${DL_LIBRARY}) + endif() + mark_as_advanced(DL_LIBRARY) + + find_library(MATH_LIBRARY NAMES "m") + if(MATH_LIBRARY) + list(APPEND _rustls_LIBRARIES ${MATH_LIBRARY}) + endif() + mark_as_advanced(MATH_LIBRARY) + endif() + + if(NOT TARGET CURL::rustls) + add_library(CURL::rustls INTERFACE IMPORTED) + set_target_properties(CURL::rustls PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_rustls_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_rustls_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_rustls_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_rustls_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_rustls_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/FindWolfSSL.cmake b/third-party/curl/CMake/FindWolfSSL.cmake index d67c0eb24d..964320ad6b 100644 --- a/third-party/curl/CMake/FindWolfSSL.cmake +++ b/third-party/curl/CMake/FindWolfSSL.cmake @@ -21,16 +21,115 @@ # SPDX-License-Identifier: curl # ########################################################################### -find_path(WolfSSL_INCLUDE_DIR NAMES wolfssl/ssl.h) -find_library(WolfSSL_LIBRARY NAMES wolfssl) -mark_as_advanced(WolfSSL_INCLUDE_DIR WolfSSL_LIBRARY) +# Find the wolfSSL library +# +# Input variables: +# +# - `WOLFSSL_INCLUDE_DIR`: Absolute path to wolfSSL include directory. +# - `WOLFSSL_LIBRARY`: Absolute path to `wolfssl` library. +# +# Defines: +# +# - `WOLFSSL_FOUND`: System has wolfSSL. +# - `WOLFSSL_VERSION`: Version of wolfSSL. +# - `CURL::wolfssl`: wolfSSL library target. -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(WolfSSL - REQUIRED_VARS WolfSSL_INCLUDE_DIR WolfSSL_LIBRARY +if(DEFINED WolfSSL_INCLUDE_DIR AND NOT DEFINED WOLFSSL_INCLUDE_DIR) + message(WARNING "WolfSSL_INCLUDE_DIR is deprecated, use WOLFSSL_INCLUDE_DIR instead.") + set(WOLFSSL_INCLUDE_DIR "${WolfSSL_INCLUDE_DIR}") +endif() +if(DEFINED WolfSSL_LIBRARY AND NOT DEFINED WOLFSSL_LIBRARY) + message(WARNING "WolfSSL_LIBRARY is deprecated, use WOLFSSL_LIBRARY instead.") + set(WOLFSSL_LIBRARY "${WolfSSL_LIBRARY}") +endif() + +set(_wolfssl_pc_requires "wolfssl") + +if(NOT DEFINED WOLFSSL_INCLUDE_DIR AND + NOT DEFINED WOLFSSL_LIBRARY) + if(CURL_USE_PKGCONFIG) + find_package(PkgConfig QUIET) + pkg_check_modules(_wolfssl ${_wolfssl_pc_requires}) + endif() + if(NOT _wolfssl_FOUND AND CURL_USE_CMAKECONFIG) + find_package(wolfssl CONFIG QUIET) + endif() +endif() + +if(_wolfssl_FOUND) + set(WolfSSL_FOUND TRUE) + set(WOLFSSL_FOUND TRUE) + set(WOLFSSL_VERSION ${_wolfssl_VERSION}) + message(STATUS "Found WolfSSL (via pkg-config): ${_wolfssl_INCLUDE_DIRS} (found version \"${WOLFSSL_VERSION}\")") +elseif(wolfssl_CONFIG) + set(WolfSSL_FOUND TRUE) + set(WOLFSSL_FOUND TRUE) + set(WOLFSSL_VERSION ${wolfssl_VERSION}) + set(_wolfssl_LIBRARIES wolfssl::wolfssl) + message(STATUS "Found WolfSSL (via CMake Config): ${wolfssl_CONFIG} (found version \"${WOLFSSL_VERSION}\")") +else() + find_path(WOLFSSL_INCLUDE_DIR NAMES "wolfssl/ssl.h") + find_library(WOLFSSL_LIBRARY NAMES "wolfssl") + + unset(WOLFSSL_VERSION CACHE) + if(WOLFSSL_INCLUDE_DIR AND EXISTS "${WOLFSSL_INCLUDE_DIR}/wolfssl/version.h") + set(_version_regex "#[\t ]*define[\t ]+LIBWOLFSSL_VERSION_STRING[\t ]+\"([^\"]*)\"") + file(STRINGS "${WOLFSSL_INCLUDE_DIR}/wolfssl/version.h" _version_str REGEX "${_version_regex}") + string(REGEX REPLACE "${_version_regex}" "\\1" _version_str "${_version_str}") + set(WOLFSSL_VERSION "${_version_str}") + unset(_version_regex) + unset(_version_str) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(WolfSSL + REQUIRED_VARS + WOLFSSL_INCLUDE_DIR + WOLFSSL_LIBRARY + VERSION_VAR + WOLFSSL_VERSION ) -if(WolfSSL_FOUND) - set(WolfSSL_INCLUDE_DIRS ${WolfSSL_INCLUDE_DIR}) - set(WolfSSL_LIBRARIES ${WolfSSL_LIBRARY}) + if(WOLFSSL_FOUND) + set(_wolfssl_INCLUDE_DIRS ${WOLFSSL_INCLUDE_DIR}) + set(_wolfssl_LIBRARIES ${WOLFSSL_LIBRARY}) + endif() + + mark_as_advanced(WOLFSSL_INCLUDE_DIR WOLFSSL_LIBRARY) +endif() + +if(WOLFSSL_FOUND) + if(APPLE) + find_library(SECURITY_FRAMEWORK NAMES "Security") + mark_as_advanced(SECURITY_FRAMEWORK) + if(NOT SECURITY_FRAMEWORK) + message(FATAL_ERROR "Security framework not found") + endif() + list(APPEND _wolfssl_LIBRARIES "-framework Security") + + find_library(COREFOUNDATION_FRAMEWORK NAMES "CoreFoundation") + mark_as_advanced(COREFOUNDATION_FRAMEWORK) + if(NOT COREFOUNDATION_FRAMEWORK) + message(FATAL_ERROR "CoreFoundation framework not found") + endif() + list(APPEND _wolfssl_LIBRARIES "-framework CoreFoundation") + elseif(WIN32) + list(APPEND _wolfssl_LIBRARIES "crypt32") + else() + find_library(MATH_LIBRARY NAMES "m") + if(MATH_LIBRARY) + list(APPEND _wolfssl_LIBRARIES ${MATH_LIBRARY}) # for log and pow + endif() + mark_as_advanced(MATH_LIBRARY) + endif() + + if(NOT TARGET CURL::wolfssl) + add_library(CURL::wolfssl INTERFACE IMPORTED) + set_target_properties(CURL::wolfssl PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_wolfssl_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_wolfssl_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_wolfssl_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_wolfssl_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_wolfssl_LIBRARIES}") + endif() endif() diff --git a/third-party/curl/CMake/FindZstd.cmake b/third-party/curl/CMake/FindZstd.cmake index 973e6ad4a9..176645d97b 100644 --- a/third-party/curl/CMake/FindZstd.cmake +++ b/third-party/curl/CMake/FindZstd.cmake @@ -21,51 +21,124 @@ # SPDX-License-Identifier: curl # ########################################################################### +# Find the zstd library +# +# Input variables: +# +# - `ZSTD_INCLUDE_DIR`: Absolute path to zstd include directory. +# - `ZSTD_LIBRARY`: Absolute path to `zstd` library. +# - `ZSTD_USE_STATIC_LIBS`: Configure for static zstd libraries. +# +# Defines: +# +# - `ZSTD_FOUND`: System has zstd. +# - `ZSTD_VERSION`: Version of zstd. +# - `CURL::zstd`: zstd library target. -#[=======================================================================[.rst: -FindZstd ----------- - -Find the zstd library - -Result Variables -^^^^^^^^^^^^^^^^ - -``Zstd_FOUND`` - System has zstd -``Zstd_INCLUDE_DIRS`` - The zstd include directories. -``Zstd_LIBRARIES`` - The libraries needed to use zstd -#]=======================================================================] - -if(UNIX) - find_package(PkgConfig QUIET) - pkg_search_module(PC_Zstd libzstd) +if(DEFINED Zstd_INCLUDE_DIR AND NOT DEFINED ZSTD_INCLUDE_DIR) + message(WARNING "Zstd_INCLUDE_DIR is deprecated, use ZSTD_INCLUDE_DIR instead.") + set(ZSTD_INCLUDE_DIR "${Zstd_INCLUDE_DIR}") +endif() +if(DEFINED Zstd_LIBRARY AND NOT DEFINED ZSTD_LIBRARY) + message(WARNING "Zstd_LIBRARY is deprecated, use ZSTD_LIBRARY instead.") + set(ZSTD_LIBRARY "${Zstd_LIBRARY}") endif() -find_path(Zstd_INCLUDE_DIR zstd.h - HINTS - ${PC_Zstd_INCLUDEDIR} - ${PC_Zstd_INCLUDE_DIRS} -) +set(_zstd_pc_requires "libzstd") -find_library(Zstd_LIBRARY NAMES zstd - HINTS - ${PC_Zstd_LIBDIR} - ${PC_Zstd_LIBRARY_DIRS} -) - -include(FindPackageHandleStandardArgs) -find_package_handle_standard_args(Zstd - REQUIRED_VARS - Zstd_LIBRARY - Zstd_INCLUDE_DIR -) - -if(Zstd_FOUND) - set(Zstd_LIBRARIES ${Zstd_LIBRARY}) - set(Zstd_INCLUDE_DIRS ${Zstd_INCLUDE_DIR}) +if(NOT DEFINED ZSTD_INCLUDE_DIR AND + NOT DEFINED ZSTD_LIBRARY) + if(CURL_USE_PKGCONFIG) + find_package(PkgConfig QUIET) + pkg_check_modules(_zstd ${_zstd_pc_requires}) + endif() + if(NOT _zstd_FOUND AND CURL_USE_CMAKECONFIG) + find_package(zstd CONFIG QUIET) + # Skip using if older than v1.4.5 + if(zstd_CONFIG AND + NOT TARGET zstd::libzstd_static AND + NOT TARGET zstd::libzstd_shared) + unset(zstd_CONFIG) + endif() + endif() endif() -mark_as_advanced(Zstd_INCLUDE_DIRS Zstd_LIBRARIES) +if(_zstd_FOUND) + set(Zstd_FOUND TRUE) + set(ZSTD_FOUND TRUE) + set(ZSTD_VERSION ${_zstd_VERSION}) + if(ZSTD_USE_STATIC_LIBS) + set(_zstd_CFLAGS "${_zstd_STATIC_CFLAGS}") + set(_zstd_INCLUDE_DIRS "${_zstd_STATIC_INCLUDE_DIRS}") + set(_zstd_LIBRARY_DIRS "${_zstd_STATIC_LIBRARY_DIRS}") + set(_zstd_LIBRARIES "${_zstd_STATIC_LIBRARIES}") + endif() + message(STATUS "Found Zstd (via pkg-config): ${_zstd_INCLUDE_DIRS} (found version \"${ZSTD_VERSION}\")") +elseif(zstd_CONFIG) + set(Zstd_FOUND TRUE) + set(ZSTD_FOUND TRUE) + set(ZSTD_VERSION ${zstd_VERSION}) + if(ZSTD_USE_STATIC_LIBS) + set(_zstd_LIBRARIES zstd::libzstd_static) + elseif(TARGET zstd::libzstd) + set(_zstd_LIBRARIES zstd::libzstd) # v1.5.6+ + else() + set(_zstd_LIBRARIES zstd::libzstd_shared) + endif() + message(STATUS "Found Zstd (via CMake Config): ${zstd_CONFIG} (found version \"${ZSTD_VERSION}\")") +else() + find_path(ZSTD_INCLUDE_DIR NAMES "zstd.h") + if(ZSTD_USE_STATIC_LIBS) + find_library(ZSTD_LIBRARY NAMES "zstd_static" "zstd") + else() + find_library(ZSTD_LIBRARY NAMES "zstd") + endif() + + unset(ZSTD_VERSION CACHE) + if(ZSTD_INCLUDE_DIR AND EXISTS "${ZSTD_INCLUDE_DIR}/zstd.h") + set(_version_regex1 "#[\t ]*define[ \t]+ZSTD_VERSION_MAJOR[ \t]+([0-9]+).*") + set(_version_regex2 "#[\t ]*define[ \t]+ZSTD_VERSION_MINOR[ \t]+([0-9]+).*") + set(_version_regex3 "#[\t ]*define[ \t]+ZSTD_VERSION_RELEASE[ \t]+([0-9]+).*") + file(STRINGS "${ZSTD_INCLUDE_DIR}/zstd.h" _version_str1 REGEX "${_version_regex1}") + file(STRINGS "${ZSTD_INCLUDE_DIR}/zstd.h" _version_str2 REGEX "${_version_regex2}") + file(STRINGS "${ZSTD_INCLUDE_DIR}/zstd.h" _version_str3 REGEX "${_version_regex3}") + string(REGEX REPLACE "${_version_regex1}" "\\1" _version_str1 "${_version_str1}") + string(REGEX REPLACE "${_version_regex2}" "\\1" _version_str2 "${_version_str2}") + string(REGEX REPLACE "${_version_regex3}" "\\1" _version_str3 "${_version_str3}") + set(ZSTD_VERSION "${_version_str1}.${_version_str2}.${_version_str3}") + unset(_version_regex1) + unset(_version_regex2) + unset(_version_regex3) + unset(_version_str1) + unset(_version_str2) + unset(_version_str3) + endif() + + include(FindPackageHandleStandardArgs) + find_package_handle_standard_args(Zstd + REQUIRED_VARS + ZSTD_INCLUDE_DIR + ZSTD_LIBRARY + VERSION_VAR + ZSTD_VERSION + ) + + if(ZSTD_FOUND) + set(_zstd_INCLUDE_DIRS ${ZSTD_INCLUDE_DIR}) + set(_zstd_LIBRARIES ${ZSTD_LIBRARY}) + endif() + + mark_as_advanced(ZSTD_INCLUDE_DIR ZSTD_LIBRARY) +endif() + +if(ZSTD_FOUND) + if(NOT TARGET CURL::zstd) + add_library(CURL::zstd INTERFACE IMPORTED) + set_target_properties(CURL::zstd PROPERTIES + INTERFACE_LIBCURL_PC_MODULES "${_zstd_pc_requires}" + INTERFACE_COMPILE_OPTIONS "${_zstd_CFLAGS}" + INTERFACE_INCLUDE_DIRECTORIES "${_zstd_INCLUDE_DIRS}" + INTERFACE_LINK_DIRECTORIES "${_zstd_LIBRARY_DIRS}" + INTERFACE_LINK_LIBRARIES "${_zstd_LIBRARIES}") + endif() +endif() diff --git a/third-party/curl/CMake/Macros.cmake b/third-party/curl/CMake/Macros.cmake index e12bf303f4..953c1c6ee6 100644 --- a/third-party/curl/CMake/Macros.cmake +++ b/third-party/curl/CMake/Macros.cmake @@ -21,102 +21,260 @@ # SPDX-License-Identifier: curl # ########################################################################### -#File defines convenience macros for available feature testing - -# This macro checks if the symbol exists in the library and if it -# does, it prepends library to the list. It is intended to be called -# multiple times with a sequence of possibly dependent libraries in -# order of least-to-most-dependent. Some libraries depend on others -# to link correctly. -macro(check_library_exists_concat LIBRARY SYMBOL VARIABLE) - check_library_exists("${LIBRARY};${CURL_LIBS}" ${SYMBOL} "${CMAKE_LIBRARY_PATH}" - ${VARIABLE}) - if(${VARIABLE}) - set(CURL_LIBS ${LIBRARY} ${CURL_LIBS}) - endif() -endmacro() +# File defines convenience macros for available feature testing # Check if header file exists and add it to the list. # This macro is intended to be called multiple times with a sequence of # possibly dependent header files. Some headers depend on others to be # compiled correctly. -macro(check_include_file_concat FILE VARIABLE) - check_include_files("${CURL_INCLUDES};${FILE}" ${VARIABLE}) - if(${VARIABLE}) - set(CURL_INCLUDES ${CURL_INCLUDES} ${FILE}) - set(CURL_TEST_DEFINES "${CURL_TEST_DEFINES} -D${VARIABLE}") +macro(check_include_file_concat_curl _file _variable) + check_include_files("${CURL_INCLUDES};${_file}" ${_variable}) + if(${_variable}) + list(APPEND CURL_INCLUDES ${_file}) endif() endmacro() +set(CURL_TEST_DEFINES "") # Initialize global variable + # For other curl specific tests, use this macro. -macro(curl_internal_test CURL_TEST) - if(NOT DEFINED "${CURL_TEST}") - set(MACRO_CHECK_FUNCTION_DEFINITIONS - "-D${CURL_TEST} ${CURL_TEST_DEFINES} ${CMAKE_REQUIRED_FLAGS}") - if(CMAKE_REQUIRED_LIBRARIES) - set(CURL_TEST_ADD_LIBRARIES - "-DLINK_LIBRARIES:STRING=${CMAKE_REQUIRED_LIBRARIES}") - endif() - - message(STATUS "Performing Curl Test ${CURL_TEST}") - try_compile(${CURL_TEST} - ${CMAKE_BINARY_DIR} - ${CMAKE_CURRENT_SOURCE_DIR}/CMake/CurlTests.c - CMAKE_FLAGS -DCOMPILE_DEFINITIONS:STRING=${MACRO_CHECK_FUNCTION_DEFINITIONS} - "${CURL_TEST_ADD_LIBRARIES}" - OUTPUT_VARIABLE OUTPUT) - if(${CURL_TEST}) - set(${CURL_TEST} 1 CACHE INTERNAL "Curl test ${FUNCTION}") - message(STATUS "Performing Curl Test ${CURL_TEST} - Success") - file(APPEND ${CMAKE_BINARY_DIR}${CMAKE_FILES_DIRECTORY}/CMakeOutput.log - "Performing Curl Test ${CURL_TEST} passed with the following output:\n" - "${OUTPUT}\n") +# Return result in variable: CURL_TEST_OUTPUT +macro(curl_internal_test _curl_test) + if(NOT DEFINED "${_curl_test}") + message(STATUS "Performing Test ${_curl_test}") + try_compile(${_curl_test} + ${PROJECT_BINARY_DIR} + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/CurlTests.c" + COMPILE_DEFINITIONS "-D${_curl_test}" ${CURL_TEST_DEFINES} ${CMAKE_REQUIRED_FLAGS} ${CMAKE_REQUIRED_DEFINITIONS} + LINK_LIBRARIES "${CMAKE_REQUIRED_LIBRARIES}" + OUTPUT_VARIABLE CURL_TEST_OUTPUT) + if(${_curl_test}) + set(${_curl_test} 1 CACHE INTERNAL "curl test") + message(STATUS "Performing Test ${_curl_test} - Success") else() - message(STATUS "Performing Curl Test ${CURL_TEST} - Failed") - set(${CURL_TEST} "" CACHE INTERNAL "Curl test ${FUNCTION}") - file(APPEND ${CMAKE_BINARY_DIR}${CMAKE_FILES_DIRECTORY}/CMakeError.log - "Performing Curl Test ${CURL_TEST} failed with the following output:\n" - "${OUTPUT}\n") + set(${_curl_test} "" CACHE INTERNAL "curl test") + message(STATUS "Performing Test ${_curl_test} - Failed") endif() endif() endmacro() -macro(curl_nroff_check) - find_program(NROFF NAMES gnroff nroff) - if(NROFF) - # Need a way to write to stdin, this will do - file(WRITE "${CMAKE_CURRENT_BINARY_DIR}/nroff-input.txt" "test") - # Tests for a valid nroff option to generate a manpage - foreach(_MANOPT "-man" "-mandoc") - execute_process(COMMAND "${NROFF}" ${_MANOPT} - OUTPUT_VARIABLE NROFF_MANOPT_OUTPUT - INPUT_FILE "${CMAKE_CURRENT_BINARY_DIR}/nroff-input.txt" - ERROR_QUIET) - # Save the option if it was valid - if(NROFF_MANOPT_OUTPUT) - message("Found *nroff option: -- ${_MANOPT}") - set(NROFF_MANOPT ${_MANOPT}) - set(NROFF_USEFUL ON) - break() - endif() - endforeach() - # No need for the temporary file - file(REMOVE "${CMAKE_CURRENT_BINARY_DIR}/nroff-input.txt") - if(NOT NROFF_USEFUL) - message(WARNING "Found no *nroff option to get plaintext from man pages") +# Option for dependencies that accepts an 'AUTO' value, which enables the dependency if detected. +macro(curl_dependency_option _option_name _find_name _desc_name) + set(${_option_name} "AUTO" CACHE STRING "Build curl with ${_desc_name} support (AUTO, ON or OFF)") + set_property(CACHE ${_option_name} PROPERTY STRINGS "AUTO" "ON" "OFF") + + if(${_option_name} STREQUAL "AUTO") + if(_find_name STREQUAL "ZLIB") + find_package(${_find_name}) + else() + find_package(${_find_name} MODULE) + endif() + elseif(${_option_name}) + if(_find_name STREQUAL "ZLIB") + find_package(${_find_name} REQUIRED) + else() + find_package(${_find_name} MODULE REQUIRED) endif() else() - message(WARNING "Found no *nroff program") + string(TOUPPER "${_find_name}" _find_name_upper) + set(${_find_name}_FOUND OFF) # cmake-lint: disable=C0103 + set(${_find_name_upper}_FOUND OFF) # cmake-lint: disable=C0103 endif() endmacro() -macro(optional_dependency DEPENDENCY) - set(CURL_${DEPENDENCY} AUTO CACHE STRING "Build curl with ${DEPENDENCY} support (AUTO, ON or OFF)") - set_property(CACHE CURL_${DEPENDENCY} PROPERTY STRINGS AUTO ON OFF) - - if(CURL_${DEPENDENCY} STREQUAL AUTO) - find_package(${DEPENDENCY}) - elseif(CURL_${DEPENDENCY}) - find_package(${DEPENDENCY} REQUIRED) +# Convert the passed paths to libpath linker options and add them to CMAKE_REQUIRED_*. +macro(curl_required_libpaths _libpaths_arg) + if(CMAKE_VERSION VERSION_LESS 3.31) + set(_libpaths "${_libpaths_arg}") + foreach(_libpath IN LISTS _libpaths) + list(APPEND CMAKE_REQUIRED_LINK_OPTIONS "${CMAKE_LIBRARY_PATH_FLAG}${_libpath}") + endforeach() + else() + list(APPEND CMAKE_REQUIRED_LINK_DIRECTORIES "${_libpaths_arg}") endif() endmacro() + +# Pre-fill variables set by a check_type_size() call. +macro(curl_prefill_type_size _type _size) + set(HAVE_SIZEOF_${_type} TRUE) + set(SIZEOF_${_type} ${_size}) + set(SIZEOF_${_type}_CODE "#define SIZEOF_${_type} ${_size}") +endmacro() + +# Internal: Recurse into target libraries and collect their include directories +# and macro definitions. +macro(curl_collect_target_compile_options _target) + get_target_property(_val ${_target} INTERFACE_COMPILE_DEFINITIONS) + if(_val) + list(APPEND _definitions ${_val}) + endif() + get_target_property(_val ${_target} INTERFACE_INCLUDE_DIRECTORIES) + if(_val) + list(APPEND _incsys ${_val}) + endif() + get_target_property(_val ${_target} INTERFACE_COMPILE_OPTIONS) + if(_val) + list(APPEND _options ${_val}) + endif() + get_target_property(_val ${_target} LINK_LIBRARIES) + if(_val) + foreach(_lib IN LISTS _val) + if(TARGET "${_lib}") + curl_collect_target_compile_options(${_lib}) + endif() + endforeach() + endif() + unset(_val) +endmacro() + +# Create a clang-tidy target for test targets +function(curl_add_clang_tidy_test_target _target_clang_tidy _target) + if(CURL_CLANG_TIDY) + + set(_definitions "") + set(_includes "") + set(_incsys "") + set(_options "") + + # Make a list of known system include directories + set(_sys_incdirs "${CMAKE_C_IMPLICIT_INCLUDE_DIRECTORIES}") + foreach(_inc IN LISTS CMAKE_SYSTEM_PREFIX_PATH) + if(NOT _inc MATCHES "/$") + string(APPEND _inc "/") + endif() + string(APPEND _inc "include") + if(NOT _inc IN_LIST _sys_incdirs AND IS_DIRECTORY "${_inc}") + list(APPEND _sys_incdirs "${_inc}") + endif() + endforeach() + + # Collect options applying to the directory + get_directory_property(_val COMPILE_DEFINITIONS) + if(_val) + list(APPEND _definitions ${_val}) + endif() + get_directory_property(_val INCLUDE_DIRECTORIES) + if(_val) + list(APPEND _includes ${_val}) + endif() + get_directory_property(_val COMPILE_OPTIONS) + if(_val) + list(APPEND _options ${_val}) + endif() + + # Collect options applying to the target + get_target_property(_val ${_target} COMPILE_DEFINITIONS) + if(_val) + list(APPEND _definitions ${_val}) + endif() + get_target_property(_val ${_target} INCLUDE_DIRECTORIES) + if(_val) + list(APPEND _includes ${_val}) + endif() + get_target_property(_val ${_target} COMPILE_OPTIONS) + if(_val) + list(APPEND _options ${_val}) + endif() + + # Collect header directories and macro definitions from lib dependencies + curl_collect_target_compile_options(${_target}) + + list(REMOVE_ITEM _definitions "") + string(REPLACE ";" ";-D" _definitions ";${_definitions}") + list(REMOVE_DUPLICATES _definitions) + list(SORT _definitions) # Sort like CMake does + + list(REMOVE_ITEM _includes "") + string(REPLACE ";" ";-I" _includes ";${_includes}") + list(REMOVE_DUPLICATES _includes) + + set(_incsys_tmp ${_incsys}) + list(REMOVE_DUPLICATES _incsys_tmp) + set(_incsys "") + set(_incsystop "") + foreach(_inc IN LISTS _incsys_tmp) + if(_inc IN_LIST _sys_incdirs) + list(APPEND _incsystop "${_inc}") # Save system prefixes to re-add them later to the end of list + continue() + endif() + # Avoid empty and '$' items. The latter + # evaluates to an empty path in this context. Also skip + # '$', as already present in '_includes'. + if(_inc AND + NOT _inc MATCHES "INSTALL_INTERFACE:" AND + NOT _inc MATCHES "BUILD_INTERFACE:") + list(APPEND _incsys "-isystem" "${_inc}") + endif() + endforeach() + foreach(_inc IN LISTS _incsystop) + list(APPEND _incsys "-isystem" "${_inc}") + endforeach() + + if(CMAKE_C_COMPILER_ID MATCHES "Clang") + list(REMOVE_DUPLICATES _options) # Keep the first of duplicates to imitate CMake + else() + set(_options) + endif() + + # Assemble source list + set(_sources "") + foreach(_source IN ITEMS ${ARGN}) + if(NOT EXISTS "${CMAKE_CURRENT_SOURCE_DIR}/${_source}") # if not in source tree + set(_source "${CMAKE_CURRENT_BINARY_DIR}/${_source}") # look in the build tree, for generated files, e.g. lib1521.c + endif() + list(APPEND _sources "${_source}") + endforeach() + + set(_cc "${CMAKE_C_COMPILER}") + if(CMAKE_C_COMPILER_TARGET AND CMAKE_C_COMPILE_OPTIONS_TARGET) + list(APPEND _cc "${CMAKE_C_COMPILE_OPTIONS_TARGET}${CMAKE_C_COMPILER_TARGET}") + endif() + if(APPLE AND CMAKE_OSX_SYSROOT) + list(APPEND _cc "-isysroot" "${CMAKE_OSX_SYSROOT}") + elseif(CMAKE_SYSROOT AND CMAKE_C_COMPILE_OPTIONS_SYSROOT) + list(APPEND _cc "${CMAKE_C_COMPILE_OPTIONS_SYSROOT}${CMAKE_SYSROOT}") + endif() + + # Pass -clang-diagnostic-unused-function to disable -Wunused-function implied by -Wunused + add_custom_target(${_target_clang_tidy} USES_TERMINAL + WORKING_DIRECTORY "${CMAKE_CURRENT_SOURCE_DIR}" + COMMAND ${CMAKE_C_CLANG_TIDY} + "--checks=-clang-diagnostic-unused-function" + ${_sources} -- ${_cc} ${_definitions} ${_includes} ${_incsys} ${_options} + DEPENDS ${_sources}) + add_dependencies(tests-clang-tidy ${_target_clang_tidy}) + endif() +endfunction() + +# Internal: Recurse into interface targets and collect their libraries +# and library paths. +macro(curl_collect_target_link_options _target) + get_target_property(_val ${_target} INTERFACE_LINK_DIRECTORIES) + if(_val) + list(APPEND _libdirs ${_val}) + endif() + get_target_property(_val ${_target} IMPORTED) + if(_val) + # LOCATION is empty for interface library targets and safe to ignore. + # Explicitly skip this query to avoid CMake v3.18 and older erroring out. + get_target_property(_val ${_target} TYPE) + if(NOT "${_val}" STREQUAL "INTERFACE_LIBRARY") + get_target_property(_val ${_target} LOCATION) + if(_val) + list(APPEND _libs ${_val}) + endif() + endif() + endif() + get_target_property(_val ${_target} INTERFACE_LINK_LIBRARIES) + if(_val) + foreach(_lib IN LISTS _val) + # Extract imported target name from e.g. "$" set by libssh2 + string(REGEX REPLACE "^\\\$\$" "\\1" _lib "${_lib}") + if(TARGET "${_lib}") + curl_collect_target_link_options(${_lib}) + else() + list(APPEND _libs ${_lib}) + endif() + endforeach() + endif() + unset(_val) +endmacro() diff --git a/third-party/curl/CMake/OtherTests.cmake b/third-party/curl/CMake/OtherTests.cmake index 762e6d1a5e..6619f3ab3e 100644 --- a/third-party/curl/CMake/OtherTests.cmake +++ b/third-party/curl/CMake/OtherTests.cmake @@ -22,114 +22,128 @@ # ########################################################################### include(CheckCSourceCompiles) -# The begin of the sources (macros and includes) -set(_source_epilogue "#undef inline") +include(CheckCSourceRuns) +include(CheckTypeSize) -macro(add_header_include check header) - if(${check}) - set(_source_epilogue "${_source_epilogue}\n#include <${header}>") +# #include header if condition is true +macro(curl_add_header_include _check _header) + if(${_check}) + set(_source_epilogue "${_source_epilogue} + #include <${_header}>") endif() endmacro() -set(signature_call_conv) -if(HAVE_WINDOWS_H) - add_header_include(HAVE_WINSOCK2_H "winsock2.h") - add_header_include(HAVE_WINDOWS_H "windows.h") - set(_source_epilogue - "${_source_epilogue}\n#ifndef WIN32_LEAN_AND_MEAN\n#define WIN32_LEAN_AND_MEAN\n#endif") - set(signature_call_conv "PASCAL") +set(_cmake_try_compile_target_type_save ${CMAKE_TRY_COMPILE_TARGET_TYPE}) +set(CMAKE_TRY_COMPILE_TARGET_TYPE "STATIC_LIBRARY") + +if(NOT DEFINED HAVE_STRUCT_SOCKADDR_STORAGE) + cmake_push_check_state() + set(CMAKE_EXTRA_INCLUDE_FILES "") if(WIN32) - set(CMAKE_REQUIRED_LIBRARIES ws2_32) + set(CMAKE_EXTRA_INCLUDE_FILES "winsock2.h") + list(APPEND CMAKE_REQUIRED_LIBRARIES "ws2_32") + else() + set(CMAKE_EXTRA_INCLUDE_FILES "sys/socket.h") endif() -else() - add_header_include(HAVE_SYS_TYPES_H "sys/types.h") - add_header_include(HAVE_SYS_SOCKET_H "sys/socket.h") + check_type_size("struct sockaddr_storage" SIZEOF_STRUCT_SOCKADDR_STORAGE) + set(HAVE_STRUCT_SOCKADDR_STORAGE ${HAVE_SIZEOF_STRUCT_SOCKADDR_STORAGE}) + cmake_pop_check_state() endif() -set(CMAKE_TRY_COMPILE_TARGET_TYPE STATIC_LIBRARY) - +set(_source_epilogue "#undef inline") check_c_source_compiles("${_source_epilogue} - int main(void) { - int flag = MSG_NOSIGNAL; - (void)flag; + #ifdef _MSC_VER + #include + #endif + #ifndef _WIN32 + #include + #endif + #include + int main(void) + { + struct timeval ts; + ts.tv_sec = 0; + ts.tv_usec = 0; + (void)ts; return 0; - }" HAVE_MSG_NOSIGNAL) + }" HAVE_STRUCT_TIMEVAL) -if(NOT HAVE_WINDOWS_H) - add_header_include(HAVE_SYS_TIME_H "sys/time.h") - add_header_include(TIME_WITH_SYS_TIME "time.h") - add_header_include(HAVE_TIME_H "time.h") -endif() -check_c_source_compiles("${_source_epilogue} -int main(void) { - struct timeval ts; - ts.tv_sec = 0; - ts.tv_usec = 0; - (void)ts; - return 0; -}" HAVE_STRUCT_TIMEVAL) +set(CMAKE_TRY_COMPILE_TARGET_TYPE ${_cmake_try_compile_target_type_save}) +unset(_cmake_try_compile_target_type_save) -if(HAVE_WINDOWS_H) - set(CMAKE_EXTRA_INCLUDE_FILES winsock2.h) -else() - set(CMAKE_EXTRA_INCLUDE_FILES) - if(HAVE_SYS_SOCKET_H) - set(CMAKE_EXTRA_INCLUDE_FILES sys/socket.h) - endif() +# Detect HAVE_GETADDRINFO_THREADSAFE + +if(WIN32) + set(HAVE_GETADDRINFO_THREADSAFE ${HAVE_GETADDRINFO}) +elseif(NOT HAVE_GETADDRINFO) + set(HAVE_GETADDRINFO_THREADSAFE FALSE) +elseif(APPLE OR + AIX OR CMAKE_SYSTEM_NAME STREQUAL "AIX" OR + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "HP-UX" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "NetBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "SunOS") + set(HAVE_GETADDRINFO_THREADSAFE TRUE) +elseif(BSD OR CMAKE_SYSTEM_NAME MATCHES "BSD") + set(HAVE_GETADDRINFO_THREADSAFE FALSE) endif() -check_type_size("struct sockaddr_storage" SIZEOF_STRUCT_SOCKADDR_STORAGE) -if(HAVE_SIZEOF_STRUCT_SOCKADDR_STORAGE) - set(HAVE_STRUCT_SOCKADDR_STORAGE 1) -endif() - -unset(CMAKE_TRY_COMPILE_TARGET_TYPE) - -if(NOT CMAKE_CROSSCOMPILING) - if(NOT ${CMAKE_SYSTEM_NAME} MATCHES "Darwin" AND NOT ${CMAKE_SYSTEM_NAME} MATCHES "iOS") - # only try this on non-apple platforms - - # if not cross-compilation... - include(CheckCSourceRuns) - set(CMAKE_REQUIRED_FLAGS "") - if(HAVE_SYS_POLL_H) - set(CMAKE_REQUIRED_FLAGS "-DHAVE_SYS_POLL_H") - elseif(HAVE_POLL_H) - set(CMAKE_REQUIRED_FLAGS "-DHAVE_POLL_H") - endif() - check_c_source_runs(" - #include - #include - - #ifdef HAVE_SYS_POLL_H - # include - #elif HAVE_POLL_H - # include - #endif +if(NOT DEFINED HAVE_GETADDRINFO_THREADSAFE) + set(_source_epilogue "#undef inline + #ifndef _WIN32 + #include + #include + #endif") + curl_add_header_include(HAVE_NETDB_H "netdb.h") + check_c_source_compiles("${_source_epilogue} + int main(void) + { + #ifndef h_errno + #error force compilation error + #endif + return 0; + }" HAVE_H_ERRNO) + if(NOT HAVE_H_ERRNO) + check_c_source_compiles("${_source_epilogue} int main(void) { - if(0 != poll(0, 0, 10)) { - return 1; /* fail */ - } - else { - /* detect the 10.12 poll() breakage */ - struct timeval before, after; - int rc; - size_t us; + h_errno = 2; + return h_errno != 0 ? 1 : 0; + }" HAVE_H_ERRNO_ASSIGNABLE) - gettimeofday(&before, NULL); - rc = poll(NULL, 0, 500); - gettimeofday(&after, NULL); - - us = (after.tv_sec - before.tv_sec) * 1000000 + - (after.tv_usec - before.tv_usec); - - if(us < 400000) { - return 1; - } - } + if(NOT HAVE_H_ERRNO_ASSIGNABLE) + check_c_source_compiles("${_source_epilogue} + int main(void) + { + #if defined(_POSIX_C_SOURCE) && (_POSIX_C_SOURCE >= 200809L) + #elif defined(_XOPEN_SOURCE) && (_XOPEN_SOURCE >= 700) + #else + #error force compilation error + #endif return 0; - }" HAVE_POLL_FINE) + }" HAVE_H_ERRNO_SBS_ISSUE_7) + endif() + endif() + + if(HAVE_H_ERRNO OR HAVE_H_ERRNO_ASSIGNABLE OR HAVE_H_ERRNO_SBS_ISSUE_7) + set(HAVE_GETADDRINFO_THREADSAFE TRUE) endif() endif() + +if(NOT WIN32 AND NOT DEFINED HAVE_CLOCK_GETTIME_MONOTONIC_RAW) + set(_source_epilogue "#undef inline") + curl_add_header_include(HAVE_SYS_TYPES_H "sys/types.h") + check_c_source_compiles("${_source_epilogue} + #include + #include + int main(void) + { + struct timespec ts; + (void)clock_gettime(CLOCK_MONOTONIC_RAW, &ts); + return 0; + }" HAVE_CLOCK_GETTIME_MONOTONIC_RAW) +endif() + +unset(_source_epilogue) diff --git a/third-party/curl/CMake/PickyWarnings.cmake b/third-party/curl/CMake/PickyWarnings.cmake index 1310cb4fbe..1ce5f7bda6 100644 --- a/third-party/curl/CMake/PickyWarnings.cmake +++ b/third-party/curl/CMake/PickyWarnings.cmake @@ -23,38 +23,84 @@ ########################################################################### include(CheckCCompilerFlag) +set(_picky "") +set(_picky_nocheck "") # not to pass to feature checks + +if(CURL_WERROR) + if(CMAKE_VERSION VERSION_GREATER_EQUAL 3.24) + set(CMAKE_COMPILE_WARNING_AS_ERROR ON) + elseif(MSVC) + list(APPEND _picky_nocheck "-WX") + else() # llvm/clang and gcc-style options + list(APPEND _picky_nocheck "-Werror") + endif() + + if((CMAKE_C_COMPILER_ID STREQUAL "GNU" AND + NOT DOS AND # Watt-32 headers use the '#include_next' GCC extension + CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 5.0) OR + CMAKE_C_COMPILER_ID MATCHES "Clang") + list(APPEND _picky_nocheck "-pedantic-errors") + endif() +endif() + +if(APPLE AND + (CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.6) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 6.1)) + list(APPEND _picky "-Werror=partial-availability") # clang 3.6 appleclang 6.1 +endif() + +if(CMAKE_C_COMPILER_ID STREQUAL "GNU" OR CMAKE_C_COMPILER_ID MATCHES "Clang") + list(APPEND _picky "-Werror-implicit-function-declaration") # clang 1.0 gcc 2.95 +endif() + +if(MSVC) + list(APPEND _picky "-W4") # Use the highest warning level for Visual Studio. +elseif(BORLAND) + list(APPEND _picky "-w-") # Disable warnings on Borland to avoid changing 3rd party code. +endif() + if(PICKY_COMPILER) - if(CMAKE_COMPILER_IS_GNUCC OR CMAKE_C_COMPILER_ID MATCHES "Clang") + # Leave disabled for GCC <4.6, because they lack #pragma features to silence locally. + if((CMAKE_C_COMPILER_ID STREQUAL "GNU" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.6) OR + CMAKE_C_COMPILER_ID MATCHES "Clang") # https://clang.llvm.org/docs/DiagnosticsReference.html # https://gcc.gnu.org/onlinedocs/gcc/Warning-Options.html - # WPICKY_ENABLE = Options we want to enable as-is. - # WPICKY_DETECT = Options we want to test first and enable if available. + # _picky_enable = Options we want to enable as-is. + # _picky_detect = Options we want to test first and enable if available. # Prefer the -Wextra alias with clang. if(CMAKE_C_COMPILER_ID MATCHES "Clang") - set(WPICKY_ENABLE "-Wextra") + set(_picky_enable "-Wextra") else() - set(WPICKY_ENABLE "-W") + set(_picky_enable "-W") endif() - list(APPEND WPICKY_ENABLE - -Wall -pedantic - ) + list(APPEND _picky_enable "-Wall") + + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.2) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.2) OR + CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.8) + list(APPEND _picky_enable "-Wpedantic") # clang 3.2 gcc 4.8 appleclang 4.2 + else() + list(APPEND _picky_enable "-pedantic") + endif() # ---------------------------------- # Add new options here, if in doubt: # ---------------------------------- - set(WPICKY_DETECT + set(_picky_detect ) + # Notes: -Wno-* options should ideally be disabled at their precise cutoff versions, + # to suppress undesired warnings in case -Weverything is passed as a custom option. + # Assume these options always exist with both clang and gcc. # Require clang 3.0 / gcc 2.95 or later. - list(APPEND WPICKY_ENABLE - -Wbad-function-cast # clang 3.0 gcc 2.95 - -Wconversion # clang 3.0 gcc 2.95 - -Winline # clang 1.0 gcc 1.0 + list(APPEND _picky_enable + -Wbad-function-cast # clang 2.7 gcc 2.95 + -Wconversion # clang 2.7 gcc 2.95 -Wmissing-declarations # clang 1.0 gcc 2.7 -Wmissing-prototypes # clang 1.0 gcc 1.0 -Wnested-externs # clang 1.0 gcc 2.7 @@ -69,129 +115,348 @@ if(PICKY_COMPILER) ) # Always enable with clang, version dependent with gcc - set(WPICKY_COMMON_OLD + set(_picky_common_old + -Waddress # clang 2.7 gcc 4.3 + -Wattributes # clang 2.7 gcc 4.1 -Wcast-align # clang 1.0 gcc 4.2 + -Wcast-qual # clang 2.7 gcc 3.4.6 -Wdeclaration-after-statement # clang 1.0 gcc 3.4 - -Wempty-body # clang 3.0 gcc 4.3 + -Wdiv-by-zero # clang 2.7 gcc 4.1 + -Wempty-body # clang 2.7 gcc 4.3 -Wendif-labels # clang 1.0 gcc 3.3 -Wfloat-equal # clang 1.0 gcc 2.96 (3.0) - -Wignored-qualifiers # clang 3.0 gcc 4.3 - -Wno-format-nonliteral # clang 1.0 gcc 2.96 (3.0) - -Wno-sign-conversion # clang 3.0 gcc 4.3 + -Wformat-security # clang 2.7 gcc 4.1 + -Wignored-qualifiers # clang 2.8 gcc 4.3 + -Wmissing-field-initializers # clang 2.7 gcc 4.1 + -Wmissing-noreturn # clang 2.7 gcc 4.1 + -Wno-padded # clang 2.9 gcc 4.1 # Not used: We cannot change public structs + -Wno-sign-conversion # clang 2.9 gcc 4.3 + -Wno-switch-default # clang 2.7 gcc 4.1 # Not used: Annoying to fix or silence + -Wno-switch-enum # clang 2.7 gcc 4.1 # Not used: It basically disallows default case -Wno-system-headers # clang 1.0 gcc 3.0 + -Wold-style-definition # clang 2.7 gcc 3.4 + -Wredundant-decls # clang 2.7 gcc 4.1 -Wstrict-prototypes # clang 1.0 gcc 3.3 - -Wtype-limits # clang 3.0 gcc 4.3 + -Wtype-limits # clang 2.7 gcc 4.3 + -Wunreachable-code # clang 2.7 gcc 4.1 + # -Wunused-macros # clang 2.7 gcc 4.1 # Not practical + # -Wno-error=unused-macros # clang 2.7 gcc 4.1 + -Wunused-parameter # clang 2.7 gcc 4.1 -Wvla # clang 2.8 gcc 4.3 ) - set(WPICKY_COMMON - -Wdouble-promotion # clang 3.6 gcc 4.6 appleclang 6.3 - -Wenum-conversion # clang 3.2 gcc 10.0 appleclang 4.6 g++ 11.0 - -Wunused-const-variable # clang 3.4 gcc 6.0 appleclang 5.1 - ) - if(CMAKE_C_COMPILER_ID MATCHES "Clang") - list(APPEND WPICKY_ENABLE - ${WPICKY_COMMON_OLD} + list(APPEND _picky_enable + ${_picky_common_old} + -Wconditional-uninitialized # clang 3.0 + -Wno-used-but-marked-unused # clang 2.9 # for typecheck-gcc.h with clang 14+, dependency headers -Wshift-sign-overflow # clang 2.9 -Wshorten-64-to-32 # clang 1.0 + -Wformat=2 # clang 2.7 gcc 4.8 ) + if(NOT MSVC) + list(APPEND _picky_enable + -Wlanguage-extension-token # clang 3.0 + ) + endif() # Enable based on compiler version - if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 3.6) OR - (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 6.3)) - list(APPEND WPICKY_ENABLE - ${WPICKY_COMMON} + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.1) + list(APPEND _picky_enable + -Wno-covered-switch-default # clang 3.1 appleclang 3.1 # Annoying to fix or silence + -Wno-disabled-macro-expansion # clang 3.1 appleclang 3.1 # for std headers, and curl/curl.h (rare combos) + ) + if(MSVC) + list(APPEND _picky_enable + -Wno-format-non-iso # clang 3.1 appleclang 3.1 # 'q' length modifier is not supported by ISO C + ) + else() + list(APPEND _picky_enable + -Wformat-non-iso # clang 3.1 appleclang 3.1 + ) + endif() + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.3) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 5.0)) + list(APPEND _picky_enable + -Wenum-conversion # clang 3.2 gcc 10.0 appleclang 4.2 g++ 11.0 + -Wmissing-variable-declarations # clang 3.2 appleclang 4.2 + -Wno-documentation-unknown-command # clang 3.3 appleclang 5.0 + -Wsometimes-uninitialized # clang 3.2 appleclang 4.2 ) endif() - if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 3.9) OR - (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 8.3)) - list(APPEND WPICKY_ENABLE - -Wcomma # clang 3.9 appleclang 8.3 - -Wmissing-variable-declarations # clang 3.2 appleclang 4.6 + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.6) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 6.1)) + list(APPEND _picky_enable + -Wdouble-promotion # clang 3.6 gcc 4.6 appleclang 6.1 + -Wheader-guard # clang 3.4 appleclang 5.1 + -Wpragmas # clang 3.5 gcc 4.1 appleclang 6.0 + # -Wunreachable-code-break # clang 3.5 appleclang 6.0 # Not used: Silent in "unity" builds + -Wunused-const-variable # clang 3.4 gcc 6.0 appleclang 5.1 ) endif() - if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 7.0) OR - (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 10.3)) - list(APPEND WPICKY_ENABLE - -Wassign-enum # clang 7.0 appleclang 10.3 - -Wextra-semi-stmt # clang 7.0 appleclang 10.3 + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.9) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 8.1)) + list(APPEND _picky_enable + -Wcomma # clang 3.9 appleclang 8.1 ) + if(MSVC) + list(APPEND _picky_enable + -Wno-nonportable-system-include-path # clang 3.9 appleclang 8.1 # No truly portable solution to this + ) + endif() + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 7.0) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 11)) + list(APPEND _picky_enable + -Wassign-enum # clang 7.0 appleclang 11.0 + -Wextra-semi-stmt # clang 7.0 appleclang 11.0 + ) + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 10.0) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 12)) + list(APPEND _picky_enable + -Wimplicit-fallthrough # clang 4.0 gcc 7.0 appleclang 9.0 # We do silencing for clang 10.0 and above only + -Wxor-used-as-pow # clang 10.0 gcc 13.0 appleclang 12.0 + ) + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 13.0) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 13.1)) + list(APPEND _picky_enable + -Wcast-function-type # clang 13.0 appleclang 13.1 + -Wreserved-identifier # clang 13.0 appleclang 13.1 # Keep it before -Wno-reserved-macro-identifier + -Wno-reserved-macro-identifier # clang 13.0 appleclang 13.1 # External macros have to be set sometimes + ) + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 15.0) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 14.0.3)) + if(CMAKE_GENERATOR STREQUAL "FASTBuild") + list(APPEND _picky_enable + -Wno-gnu-line-marker # clang 15.0 appleclang 14.0.3 + ) + endif() + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 16.0) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 15.0)) + list(APPEND _picky_enable + -Wno-unsafe-buffer-usage # clang 16.0 appleclang 15.0 + ) + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 16.0) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 16.0)) + list(APPEND _picky_enable + -Wcast-function-type-strict # clang 16.0 appleclang 16.0 + ) + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 19.1) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 17.0)) + list(APPEND _picky_enable + -Wformat-signedness # clang 19.1 gcc 5.1 appleclang 17.0 # In clang-cl enums are signed ints by default + ) + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 21.1) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 26.4)) + list(APPEND _picky_enable + -Warray-compare # clang 20.1 gcc 12.0 appleclang 26.4 + -Wc++-hidden-decl # clang 21.1 appleclang 26.4 + -Wimplicit-int-enum-cast # clang 21.1 + -Wjump-misses-init # clang 21.1 gcc 4.5 appleclang 26.4 + -Wno-implicit-void-ptr-cast # clang 21.1 appleclang 26.4 + -Wtentative-definition-compat # clang 21.1 appleclang 26.4 + ) + if(WIN32) + list(APPEND _picky_enable + -Wno-c++-keyword # clang 21.1 appleclang 26.4 # `wchar_t` triggers it on Windows + ) + else() + list(APPEND _picky_enable + -Wc++-keyword # clang 21.1 appleclang 26.4 + ) + endif() endif() else() # gcc - list(APPEND WPICKY_DETECT - ${WPICKY_COMMON} - ) # Enable based on compiler version - if(NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 4.3) - list(APPEND WPICKY_ENABLE - ${WPICKY_COMMON_OLD} + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.3) + list(APPEND _picky_enable + ${_picky_common_old} + -Wclobbered # gcc 4.3 -Wmissing-parameter-type # gcc 4.3 -Wold-style-declaration # gcc 4.3 + -Wpragmas # clang 3.5 gcc 4.1 appleclang 6.0 -Wstrict-aliasing=3 # gcc 4.0 + -ftree-vrp # gcc 4.3 (required for -Warray-bounds, included in -Wall) ) endif() - if(NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 4.5 AND MINGW) - list(APPEND WPICKY_ENABLE - -Wno-pedantic-ms-format # gcc 4.5 (mingw-only) + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.5) + list(APPEND _picky_enable + -Wjump-misses-init # clang 21.1 gcc 4.5 appleclang 26.4 + ) + if(MINGW) + list(APPEND _picky_enable + -Wno-pedantic-ms-format # gcc 4.5 (MinGW-only) + ) + endif() + endif() + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.8) + list(APPEND _picky_enable + -Wdouble-promotion # clang 3.6 gcc 4.6 appleclang 6.1 + -Wformat=2 # clang 2.7 gcc 4.8 + -Wlogical-op # gcc 4.4 + -Wtrampolines # gcc 4.6 ) endif() - if(NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 4.8) - list(APPEND WPICKY_ENABLE - -Wformat=2 # clang 3.0 gcc 4.8 (clang part-default, enabling it fully causes -Wformat-nonliteral warnings) + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 5.0) + list(APPEND _picky_enable + -Warray-bounds=2 # clang 2.9 gcc 5.0 (clang default: -Warray-bounds) + -Wformat-signedness # clang 19.1 gcc 5.1 appleclang 17.0 ) endif() - if(NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 5.0) - list(APPEND WPICKY_ENABLE - -Warray-bounds=2 -ftree-vrp # clang 3.0 gcc 5.0 (clang default: -Warray-bounds) - ) - endif() - if(NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 6.0) - list(APPEND WPICKY_ENABLE + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 6.0) + list(APPEND _picky_enable -Wduplicated-cond # gcc 6.0 - -Wnull-dereference # clang 3.0 gcc 6.0 (clang default) + -Wnull-dereference # clang 2.9 gcc 6.0 (clang default) -fdelete-null-pointer-checks -Wshift-negative-value # clang 3.7 gcc 6.0 (clang default) - -Wshift-overflow=2 # clang 3.0 gcc 6.0 (clang default: -Wshift-overflow) + -Wshift-overflow=2 # clang 2.9 gcc 6.0 (clang default: -Wshift-overflow) + -Wunused-const-variable # clang 3.4 gcc 6.0 appleclang 5.1 ) endif() - if(NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 7.0) - list(APPEND WPICKY_ENABLE + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 7.0) + list(APPEND _picky_enable -Walloc-zero # gcc 7.0 -Wduplicated-branches # gcc 7.0 - -Wformat-overflow=2 # gcc 7.0 - -Wformat-truncation=1 # gcc 7.0 + -Wformat-truncation=2 # gcc 7.0 + -Wimplicit-fallthrough # clang 4.0 gcc 7.0 appleclang 9.0 -Wrestrict # gcc 7.0 ) endif() - if(NOT CMAKE_C_COMPILER_VERSION VERSION_LESS 10.0) - list(APPEND WPICKY_ENABLE + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 10.0) + list(APPEND _picky_enable -Warith-conversion # gcc 10.0 + -Wenum-conversion # clang 3.2 gcc 10.0 appleclang 4.2 g++ 11.0 + ) + endif() + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 13.0) + list(APPEND _picky_enable + -Warray-compare # clang 20.1 gcc 12.0 appleclang 26.4 + -Wenum-int-mismatch # gcc 13.0 + -Wxor-used-as-pow # clang 10.0 gcc 13.0 appleclang 12.0 + ) + endif() + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 15.0) + list(APPEND _picky_enable + -Wleading-whitespace=spaces # gcc 15.0 + -Wtrailing-whitespace=any # gcc 15.0 + -Wunterminated-string-initialization # gcc 15.0 ) endif() endif() - # + # Assemble list of flags - unset(WPICKY) - - foreach(_CCOPT ${WPICKY_ENABLE}) - set(WPICKY "${WPICKY} ${_CCOPT}") + set(_picky_skipped "") + foreach(_ccopt IN LISTS _picky_enable) + string(REGEX MATCH "-W([a-z0-9+-]+)" _ccmatch "${_ccopt}") + string(REPLACE "+" "\\+" _cmake_match_1 "${CMAKE_MATCH_1}") # escape '+' to make it a valid regex + if(_ccmatch AND "${CMAKE_C_FLAGS} " MATCHES "-Wno-${_cmake_match_1} " AND + NOT _ccopt STREQUAL "-Wall" AND + NOT _ccopt MATCHES "^-Wno-") + string(APPEND _picky_skipped " ${_ccopt}") + else() + list(APPEND _picky "${_ccopt}") + endif() endforeach() + if(_picky_skipped) + message(STATUS "Picky compiler options skipped due to CMAKE_C_FLAGS override:${_picky_skipped}") + endif() - foreach(_CCOPT ${WPICKY_DETECT}) - # surprisingly, CHECK_C_COMPILER_FLAG needs a new variable to store each new - # test result in. - string(MAKE_C_IDENTIFIER "OPT${_CCOPT}" _optvarname) + foreach(_ccopt IN LISTS _picky_detect) + # Use a unique variable name 1. for meaningful log output 2. to have a fresh, undefined variable for each detection + string(MAKE_C_IDENTIFIER "OPT${_ccopt}" _optvarname) # GCC only warns about unknown -Wno- options if there are also other diagnostic messages, # so test for the positive form instead - string(REPLACE "-Wno-" "-W" _CCOPT_ON "${_CCOPT}") - check_c_compiler_flag(${_CCOPT_ON} ${_optvarname}) + string(REPLACE "-Wno-" "-W" _ccopt_on "${_ccopt}") + check_c_compiler_flag(${_ccopt_on} ${_optvarname}) if(${_optvarname}) - set(WPICKY "${WPICKY} ${_CCOPT}") + list(APPEND _picky "${_ccopt}") endif() endforeach() - message(STATUS "Picky compiler options:${WPICKY}") - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} ${WPICKY}") + if(CMAKE_C_COMPILER_ID STREQUAL "GNU") + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.0 AND CMAKE_C_COMPILER_VERSION VERSION_LESS 4.7) + list(APPEND _picky "-Wno-missing-field-initializers") # https://gcc.gnu.org/bugzilla/show_bug.cgi?id=36750 + endif() + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.3 AND CMAKE_C_COMPILER_VERSION VERSION_LESS 4.8) + list(APPEND _picky "-Wno-type-limits") # Avoid false positives + endif() + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 5.1 AND CMAKE_C_COMPILER_VERSION VERSION_LESS 5.5) + list(APPEND _picky "-Wno-conversion") # Avoid false positives + endif() + endif() + elseif(MSVC AND MSVC_VERSION LESS_EQUAL 1951) # Enable for tested versions only + list(APPEND _picky "-Wall") + list(APPEND _picky "-wd4061") # enumerator 'A' in switch of enum 'B' is not explicitly handled by a case label + list(APPEND _picky "-wd4191") # 'type cast': unsafe conversion from 'FARPROC' to 'void (__cdecl *)(void)' + list(APPEND _picky "-wd4255") # no function prototype given: converting '()' to '(void)' (in winuser.h) + list(APPEND _picky "-wd4464") # relative include path contains '..' + list(APPEND _picky "-wd4548") # expression before comma has no effect; expected expression with side-effect (in FD_SET()) + list(APPEND _picky "-wd4574") # 'M' is defined to be '0': did you mean to use '#if M'? (in ws2tcpip.h) + list(APPEND _picky "-wd4668") # 'M' is not defined as a preprocessor macro, replacing with '0' for '#if/#elif' (in winbase.h) + list(APPEND _picky "-wd4710") # 'fprintf'/'printf'/'sscanf': function not inlined (in tests, with VS2022+ Release) + list(APPEND _picky "-wd4711") # function 'A' selected for automatic inline expansion + # volatile access of '' is subject to /volatile: setting; + # consider using __iso_volatile_load/store intrinsic functions (ARM64) + list(APPEND _picky "-wd4746") + list(APPEND _picky "-wd4820") # 'A': 'N' bytes padding added after data member 'B' + if(MSVC_VERSION GREATER_EQUAL 1900) + list(APPEND _picky "-wd5045") # Compiler inserts Spectre mitigation for memory load if /Qspectre switch specified + endif() endif() endif() + +# clang-cl +if(CMAKE_C_COMPILER_ID STREQUAL "Clang" AND MSVC) + list(APPEND _picky "-Wno-language-extension-token") # Allow __int64 + + foreach(_wlist IN ITEMS _picky_nocheck _picky) + set(_picky_tmp "") + foreach(_ccopt IN LISTS "${_wlist}") + # Prefix -Wall, otherwise clang-cl interprets it as an MSVC option and translates it to -Weverything + if(_ccopt MATCHES "^-W" AND NOT _ccopt STREQUAL "-Wall") + list(APPEND _picky_tmp ${_ccopt}) + else() + list(APPEND _picky_tmp "-clang:${_ccopt}") + endif() + endforeach() + set("${_wlist}" ${_picky_tmp}) # cmake-lint: disable=C0103 + endforeach() +endif() + +if(CMAKE_C_STANDARD STREQUAL 90) + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.0) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.2)) + list(APPEND _picky "-Wno-c99-extensions") # Avoid: warning: '_Bool' is a C99 extension + endif() + if((CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.9) OR + (CMAKE_C_COMPILER_ID STREQUAL "AppleClang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 8.1)) + list(APPEND _picky "-Wno-comma") # Silly + endif() +endif() + +if(DOS AND CMAKE_C_COMPILER_ID STREQUAL "GNU" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 10.0) + list(APPEND _picky "-Wno-arith-conversion") # Avoid warnings in DJGPP's built-in FD_SET() macro +endif() + +if(_picky_nocheck OR _picky) + set(_picky_tmp "${_picky_nocheck}" "${_picky}") + string(REPLACE ";" " " _picky_tmp "${_picky_tmp}") + string(STRIP "${_picky_tmp}" _picky_tmp) + message(STATUS "Picky compiler options: ${_picky_tmp}") + set_property(DIRECTORY APPEND PROPERTY COMPILE_OPTIONS "${_picky_nocheck}" "${_picky}") + + # Apply to all feature checks + string(REPLACE ";" " " _picky_tmp "${_picky}") + string(APPEND CMAKE_REQUIRED_FLAGS " ${_picky_tmp}") + + unset(_picky) + unset(_picky_tmp) +endif() diff --git a/third-party/curl/CMake/Platforms/WindowsCache.cmake b/third-party/curl/CMake/Platforms/WindowsCache.cmake deleted file mode 100644 index 44a1fc9699..0000000000 --- a/third-party/curl/CMake/Platforms/WindowsCache.cmake +++ /dev/null @@ -1,127 +0,0 @@ -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### -if(NOT UNIX) - if(WIN32) - - set(HAVE_WINDOWS_H 1) - set(HAVE_WS2TCPIP_H 1) - set(HAVE_WINSOCK2_H 1) - - if(MINGW) - set(HAVE_SNPRINTF 1) - set(HAVE_UNISTD_H 1) - set(HAVE_INTTYPES_H 1) - set(HAVE_STRTOLL 1) - elseif(MSVC) - if(NOT MSVC_VERSION LESS 1800) - set(HAVE_INTTYPES_H 1) - set(HAVE_STRTOLL 1) - else() - set(HAVE_INTTYPES_H 0) - set(HAVE_STRTOLL 0) - endif() - if(NOT MSVC_VERSION LESS 1900) - set(HAVE_SNPRINTF 1) - else() - set(HAVE_SNPRINTF 0) - endif() - endif() - - set(HAVE_LIBSOCKET 0) - set(HAVE_GETHOSTNAME 1) - set(HAVE_LIBZ 0) - - set(HAVE_ARPA_INET_H 0) - set(HAVE_ARPA_TFTP_H 0) - set(HAVE_FCNTL_H 1) - set(HAVE_IFADDRS_H 0) - set(HAVE_IO_H 1) - set(HAVE_NETDB_H 0) - set(HAVE_NETINET_IN_H 0) - set(HAVE_NETINET_TCP_H 0) - set(HAVE_NET_IF_H 0) - set(HAVE_IOCTL_SIOCGIFADDR 0) - set(HAVE_POLL_H 0) - set(HAVE_PWD_H 0) - set(HAVE_SETJMP_H 1) - set(HAVE_SIGNAL_H 1) - set(HAVE_STDLIB_H 1) - set(HAVE_STRINGS_H 0) - set(HAVE_STRING_H 1) - set(HAVE_SYS_FILIO_H 0) - set(HAVE_SYS_IOCTL_H 0) - set(HAVE_SYS_PARAM_H 0) - set(HAVE_SYS_POLL_H 0) - set(HAVE_SYS_RESOURCE_H 0) - set(HAVE_SYS_SELECT_H 0) - set(HAVE_SYS_SOCKET_H 0) - set(HAVE_SYS_SOCKIO_H 0) - set(HAVE_SYS_STAT_H 1) - set(HAVE_SYS_TIME_H 0) - set(HAVE_SYS_TYPES_H 1) - set(HAVE_SYS_UN_H 0) - set(HAVE_SYS_UTIME_H 1) - set(HAVE_TERMIOS_H 0) - set(HAVE_TERMIO_H 0) - set(HAVE_TIME_H 1) - set(HAVE_UTIME_H 0) - - set(HAVE_SOCKET 1) - set(HAVE_SELECT 1) - set(HAVE_STRDUP 1) - set(HAVE_STRICMP 1) - set(HAVE_STRCMPI 1) - set(HAVE_GETTIMEOFDAY 0) - set(HAVE_CLOSESOCKET 1) - set(HAVE_SIGSETJMP 0) - set(HAVE_SOCKADDR_IN6_SIN6_SCOPE_ID 1) - set(HAVE_GETPASS_R 0) - set(HAVE_GETPWUID 0) - set(HAVE_GETEUID 0) - set(HAVE_UTIME 1) - set(HAVE_GMTIME_R 0) - set(HAVE_GETHOSTBYNAME_R 0) - set(HAVE_SIGNAL 1) - set(HAVE_LINUX_TCP_H 0) - set(HAVE_GLIBC_STRERROR_R 0) - set(HAVE_MACH_ABSOLUTE_TIME 0) - - set(HAVE_GETHOSTBYNAME_R_3 0) - set(HAVE_GETHOSTBYNAME_R_3_REENTRANT 0) - set(HAVE_GETHOSTBYNAME_R_5 0) - set(HAVE_GETHOSTBYNAME_R_5_REENTRANT 0) - set(HAVE_GETHOSTBYNAME_R_6 0) - set(HAVE_GETHOSTBYNAME_R_6_REENTRANT 0) - - set(TIME_WITH_SYS_TIME 0) - set(HAVE_O_NONBLOCK 0) - set(HAVE_IN_ADDR_T 0) - set(STDC_HEADERS 1) - - set(HAVE_SIGACTION 0) - set(HAVE_MACRO_SIGSETJMP 0) - else() - message("This file should be included on Windows platform only") - endif() -endif() diff --git a/third-party/curl/CMake/Utilities.cmake b/third-party/curl/CMake/Utilities.cmake index 9ff38e3a0f..f86a6aa1e8 100644 --- a/third-party/curl/CMake/Utilities.cmake +++ b/third-party/curl/CMake/Utilities.cmake @@ -23,13 +23,64 @@ ########################################################################### # File containing various utilities -# Returns a list of arguments that evaluate to true -function(count_true output_count_var) - set(lst_len 0) - foreach(option_var IN LISTS ARGN) - if(${option_var}) - math(EXPR lst_len "${lst_len} + 1") +# Return number of arguments that evaluate to true +function(curl_count_true _output_count_var) + set(_list_len 0) + foreach(_option_var IN LISTS ARGN) + if(${_option_var}) + math(EXPR _list_len "${_list_len} + 1") endif() endforeach() - set(${output_count_var} ${lst_len} PARENT_SCOPE) + set(${_output_count_var} ${_list_len} PARENT_SCOPE) +endfunction() + +# Dump all defined variables with their values +function(curl_dumpvars) + message("::group::CMake Variable Dump") + get_cmake_property(_vars VARIABLES) + foreach(_var IN ITEMS ${_vars}) + get_property(_var_type CACHE ${_var} PROPERTY TYPE) + get_property(_var_advanced CACHE ${_var} PROPERTY ADVANCED) + if(_var_type) + set(_var_type ":${_var_type}") + endif() + if(_var_advanced) + set(_var_advanced " [adv]") + endif() + message("${_var}${_var_type}${_var_advanced} = '${${_var}}'") + endforeach() + message("::endgroup::") +endfunction() + +# Dump all target properties +function(curl_dumptargetprops _target) + if(CMAKE_VERSION VERSION_GREATER_EQUAL 3.19 AND TARGET "${_target}") + execute_process(COMMAND "${CMAKE_COMMAND}" "--help-property-list" OUTPUT_VARIABLE _cmake_property_list) + string(REPLACE "\n" ";" _cmake_property_list "${_cmake_property_list}") + list(REMOVE_DUPLICATES _cmake_property_list) + list(REMOVE_ITEM _cmake_property_list "") + list(APPEND _cmake_property_list "INTERFACE_LIBCURL_PC_MODULES") + get_target_property(_target_imported ${_target} IMPORTED) + if(NOT _target_imported) + list(REMOVE_ITEM _cmake_property_list "LOCATION" "LOCATION_" "MACOSX_PACKAGE_LOCATION" "VS_DEPLOYMENT_LOCATION") + endif() + foreach(_prop IN LISTS _cmake_property_list) + if(_prop MATCHES "") + foreach(_config IN ITEMS "DEBUG" "RELEASE" "MINSIZEREL" "RELWITHDEBINFO") + string(REPLACE "" "${_config}" _propconfig "${_prop}") + get_property(_is_set TARGET "${_target}" PROPERTY "${_propconfig}" SET) + if(_is_set) + get_target_property(_val "${_target}" "${_propconfig}") + message("${_target}.${_propconfig} = '${_val}'") + endif() + endforeach() + else() + get_property(_is_set TARGET "${_target}" PROPERTY "${_prop}" SET) + if(_is_set) + get_target_property(_val "${_target}" "${_prop}") + message("${_target}.${_prop} = '${_val}'") + endif() + endif() + endforeach() + endif() endfunction() diff --git a/third-party/curl/CMake/cmake_uninstall.cmake.in b/third-party/curl/CMake/cmake_uninstall.cmake.in deleted file mode 100644 index 47aec8d42c..0000000000 --- a/third-party/curl/CMake/cmake_uninstall.cmake.in +++ /dev/null @@ -1,49 +0,0 @@ -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### -if(NOT EXISTS "@CMAKE_CURRENT_BINARY_DIR@/install_manifest.txt") - message(FATAL_ERROR "Cannot find install manifest: @CMAKE_CURRENT_BINARY_DIR@/install_manifest.txt") -endif() - -if(NOT DEFINED CMAKE_INSTALL_PREFIX) - set(CMAKE_INSTALL_PREFIX "@CMAKE_INSTALL_PREFIX@") -endif() -message(${CMAKE_INSTALL_PREFIX}) - -file(READ "@CMAKE_CURRENT_BINARY_DIR@/install_manifest.txt" files) -string(REGEX REPLACE "\n" ";" files "${files}") -foreach(file ${files}) - message(STATUS "Uninstalling $ENV{DESTDIR}${file}") - if(IS_SYMLINK "$ENV{DESTDIR}${file}" OR EXISTS "$ENV{DESTDIR}${file}") - exec_program( - "@CMAKE_COMMAND@" ARGS "-E remove \"$ENV{DESTDIR}${file}\"" - OUTPUT_VARIABLE rm_out - RETURN_VALUE rm_retval - ) - if(NOT "${rm_retval}" STREQUAL 0) - message(FATAL_ERROR "Problem when removing $ENV{DESTDIR}${file}") - endif() - else() - message(STATUS "File $ENV{DESTDIR}${file} does not exist.") - endif() -endforeach() diff --git a/third-party/curl/CMake/cmake_uninstall.in.cmake b/third-party/curl/CMake/cmake_uninstall.in.cmake new file mode 100644 index 0000000000..bb95d85a0a --- /dev/null +++ b/third-party/curl/CMake/cmake_uninstall.in.cmake @@ -0,0 +1,50 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +if(NOT EXISTS "@CMAKE_CURRENT_BINARY_DIR@/install_manifest.txt") + message(FATAL_ERROR "Cannot find install manifest: @CMAKE_CURRENT_BINARY_DIR@/install_manifest.txt") +endif() + +if(NOT DEFINED CMAKE_INSTALL_PREFIX) + set(CMAKE_INSTALL_PREFIX "@CMAKE_INSTALL_PREFIX@") +endif() +message(${CMAKE_INSTALL_PREFIX}) + +file(READ "@CMAKE_CURRENT_BINARY_DIR@/install_manifest.txt" _files) +string(REGEX REPLACE "\n" ";" _files "${_files}") +foreach(_file ${_files}) + message(STATUS "Uninstalling $ENV{DESTDIR}${_file}") + if(IS_SYMLINK "$ENV{DESTDIR}${_file}" OR EXISTS "$ENV{DESTDIR}${_file}") + execute_process( + COMMAND "@CMAKE_COMMAND@" -E remove "$ENV{DESTDIR}${_file}" + RESULT_VARIABLE rm_retval + OUTPUT_QUIET + ERROR_QUIET + ) + if(NOT "${rm_retval}" STREQUAL 0) + message(FATAL_ERROR "Problem when removing $ENV{DESTDIR}${_file}") + endif() + else() + message(STATUS "File $ENV{DESTDIR}${_file} does not exist.") + endif() +endforeach() diff --git a/third-party/curl/CMake/curl-config.cmake.in b/third-party/curl/CMake/curl-config.cmake.in deleted file mode 100644 index 056907c4f9..0000000000 --- a/third-party/curl/CMake/curl-config.cmake.in +++ /dev/null @@ -1,38 +0,0 @@ -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### -@PACKAGE_INIT@ - -include(CMakeFindDependencyMacro) -if(@USE_OPENSSL@) - find_dependency(OpenSSL @OPENSSL_VERSION_MAJOR@) -endif() -if(@USE_ZLIB@) - find_dependency(ZLIB @ZLIB_VERSION_MAJOR@) -endif() - -include("${CMAKE_CURRENT_LIST_DIR}/@TARGETS_EXPORT_NAME@.cmake") -check_required_components("@PROJECT_NAME@") - -# Alias for either shared or static library -add_library(@PROJECT_NAME@::libcurl ALIAS @PROJECT_NAME@::@LIB_SELECTED@) diff --git a/third-party/curl/CMake/curl-config.in.cmake b/third-party/curl/CMake/curl-config.in.cmake new file mode 100644 index 0000000000..b4300ca210 --- /dev/null +++ b/third-party/curl/CMake/curl-config.in.cmake @@ -0,0 +1,196 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +@PACKAGE_INIT@ + +option(CURL_USE_CMAKECONFIG "Enable detecting @PROJECT_NAME@ dependencies via CMake Config. Default: @CURL_USE_CMAKECONFIG@" + "@CURL_USE_CMAKECONFIG@") +option(CURL_USE_PKGCONFIG "Enable pkg-config to detect @PROJECT_NAME@ dependencies. Default: @CURL_USE_PKGCONFIG@" + "@CURL_USE_PKGCONFIG@") + +if(CMAKE_VERSION VERSION_LESS @CMAKE_MINIMUM_REQUIRED_VERSION@) + message(STATUS "@PROJECT_NAME@: @PROJECT_NAME@-specific Find modules require " + "CMake @CMAKE_MINIMUM_REQUIRED_VERSION@ or upper, found: ${CMAKE_VERSION}.") +endif() + +include(CMakeFindDependencyMacro) + +if("@HAVE_THREADS_POSIX@" OR "@HAVE_THREADS_POSIX_BORINGSSL@") + find_dependency(Threads) # for Threads::Threads +endif() + +if("@USE_OPENSSL@") + if("@OPENSSL_VERSION_MAJOR@") + find_dependency(OpenSSL "@OPENSSL_VERSION_MAJOR@") + else() + find_dependency(OpenSSL) + endif() + # Define lib duplicate to fixup lib order for GCC binutils ld in static builds + if(TARGET OpenSSL::Crypto AND NOT TARGET CURL::OpenSSL_Crypto) + add_library(CURL::OpenSSL_Crypto INTERFACE IMPORTED) + set_target_properties(CURL::OpenSSL_Crypto PROPERTIES INTERFACE_LINK_LIBRARIES OpenSSL::Crypto) + endif() +endif() +if("@HAVE_LIBZ@") + find_dependency(ZLIB "@ZLIB_VERSION_MAJOR@") + # Define lib duplicate to fixup lib order for GCC binutils ld in static builds + if(TARGET ZLIB::ZLIB AND NOT TARGET CURL::ZLIB) + add_library(CURL::ZLIB INTERFACE IMPORTED) + set_target_properties(CURL::ZLIB PROPERTIES INTERFACE_LINK_LIBRARIES ZLIB::ZLIB) + endif() +endif() + +set(_curl_cmake_module_path_save ${CMAKE_MODULE_PATH}) +list(PREPEND CMAKE_MODULE_PATH ${CMAKE_CURRENT_LIST_DIR}) + +set(_curl_libs "") + +if("@HAVE_BROTLI@") + find_dependency(Brotli MODULE) + list(APPEND _curl_libs CURL::brotli) +endif() +if("@USE_ARES@") + find_dependency(Cares MODULE) + list(APPEND _curl_libs CURL::cares) +endif() +if("@HAVE_GSSAPI@") + find_dependency(GSS MODULE) + list(APPEND _curl_libs CURL::gss) +endif() +if("@USE_BACKTRACE@") + find_dependency(Libbacktrace MODULE) + list(APPEND _curl_libs CURL::libbacktrace) +endif() +if("@USE_GSASL@") + find_dependency(Libgsasl MODULE) + list(APPEND _curl_libs CURL::libgsasl) +endif() +if(NOT "@USE_WIN32_LDAP@" AND NOT "@CURL_DISABLE_LDAP@") + find_dependency(LDAP MODULE) + list(APPEND _curl_libs CURL::ldap) +endif() +if("@HAVE_LIBIDN2@") + find_dependency(Libidn2 MODULE) + list(APPEND _curl_libs CURL::libidn2) +endif() +if("@USE_LIBPSL@") + find_dependency(Libpsl MODULE) + list(APPEND _curl_libs CURL::libpsl) +endif() +if("@USE_LIBSSH@") + find_dependency(Libssh MODULE) + list(APPEND _curl_libs CURL::libssh) +endif() +if("@USE_LIBSSH2@") + find_dependency(Libssh2 MODULE) + list(APPEND _curl_libs CURL::libssh2) +endif() +if("@USE_LIBUV@") + find_dependency(Libuv MODULE) + list(APPEND _curl_libs CURL::libuv) +endif() +if("@USE_MBEDTLS@") + find_dependency(MbedTLS MODULE) + list(APPEND _curl_libs CURL::mbedtls) +endif() +if("@USE_NGHTTP2@") + find_dependency(NGHTTP2 MODULE) + list(APPEND _curl_libs CURL::nghttp2) +endif() +if("@USE_NGHTTP3@") + find_dependency(NGHTTP3 MODULE) + list(APPEND _curl_libs CURL::nghttp3) +endif() +if("@USE_NGTCP2@") + find_dependency(NGTCP2 MODULE COMPONENTS "@NGTCP2_CRYPTO_BACKEND@") + list(APPEND _curl_libs CURL::ngtcp2) +endif() +if("@USE_GNUTLS@") + find_dependency(GnuTLS MODULE) + list(APPEND _curl_libs CURL::gnutls) + find_dependency(Nettle MODULE) + list(APPEND _curl_libs CURL::nettle) +endif() +if("@USE_QUICHE@") + find_dependency(Quiche MODULE) + list(APPEND _curl_libs CURL::quiche) +endif() +if("@USE_RUSTLS@") + find_dependency(Rustls MODULE) + list(APPEND _curl_libs CURL::rustls) +endif() +if("@USE_WOLFSSL@") + find_dependency(WolfSSL MODULE) + list(APPEND _curl_libs CURL::wolfssl) +endif() +if("@HAVE_ZSTD@") + find_dependency(Zstd MODULE) + list(APPEND _curl_libs CURL::zstd) +endif() + +set(CMAKE_MODULE_PATH ${_curl_cmake_module_path_save}) + +# Define lib duplicate to fixup lib order for GCC binutils ld in static builds +if(WIN32 AND NOT TARGET CURL::win32_winsock) + add_library(CURL::win32_winsock INTERFACE IMPORTED) + set_target_properties(CURL::win32_winsock PROPERTIES INTERFACE_LINK_LIBRARIES "ws2_32") +endif() + +include("${CMAKE_CURRENT_LIST_DIR}/@TARGETS_EXPORT_NAME@.cmake") + +# Alias for either shared or static library +if(NOT TARGET @PROJECT_NAME@::@LIB_NAME@) + add_library(@PROJECT_NAME@::@LIB_NAME@ ALIAS @PROJECT_NAME@::@LIB_SELECTED@) +endif() + +# For compatibility with CMake's FindCURL.cmake +set(CURL_VERSION_STRING "@CURLVERSION@") +set(CURL_LIBRARIES @PROJECT_NAME@::@LIB_NAME@) +set(CURL_LIBRARIES_PRIVATE "@LIBCURL_PC_LIBS_PRIVATE_LIST@") +set_and_check(CURL_INCLUDE_DIRS "@PACKAGE_CMAKE_INSTALL_INCLUDEDIR@") + +set(CURL_SUPPORTED_PROTOCOLS "@CURL_SUPPORTED_PROTOCOLS_LIST@") +set(CURL_SUPPORTED_FEATURES "@CURL_SUPPORTED_FEATURES_LIST@") + +foreach(_curl_item IN LISTS CURL_SUPPORTED_PROTOCOLS CURL_SUPPORTED_FEATURES) + set(CURL_SUPPORTS_${_curl_item} TRUE) +endforeach() + +set(_curl_missing_req "") +foreach(_curl_item IN LISTS CURL_FIND_COMPONENTS) + if(CURL_SUPPORTS_${_curl_item}) + set(CURL_${_curl_item}_FOUND TRUE) + elseif(CURL_FIND_REQUIRED_${_curl_item}) + list(APPEND _curl_missing_req ${_curl_item}) + endif() +endforeach() + +if(_curl_missing_req) + string(REPLACE ";" " " _curl_missing_req "${_curl_missing_req}") + if(CURL_FIND_REQUIRED) + message(FATAL_ERROR "@PROJECT_NAME@: missing required components: ${_curl_missing_req}") + endif() + unset(_curl_missing_req) +endif() + +check_required_components("@PROJECT_NAME@") diff --git a/third-party/curl/CMake/unix-cache.cmake b/third-party/curl/CMake/unix-cache.cmake new file mode 100644 index 0000000000..78816499ca --- /dev/null +++ b/third-party/curl/CMake/unix-cache.cmake @@ -0,0 +1,332 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +# Based on CI runs for Cygwin/MSYS2, Linux, macOS/iOS, DragonFly BSD, FreeBSD, MidnightBSD, NetBSD, OpenBSD +if(NOT UNIX) + message(FATAL_ERROR "This file should be included on Unix platforms only") +endif() + +if(APPLE OR + CYGWIN) + set(HAVE_ACCEPT4 0) +elseif(CMAKE_SYSTEM_NAME STREQUAL "Linux" OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "NetBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "OpenBSD") + set(HAVE_ACCEPT4 1) +endif() +set(HAVE_ALARM 1) +if(ANDROID) + set(HAVE_ARC4RANDOM 1) +else() + set(HAVE_ARC4RANDOM 0) +endif() +set(HAVE_ARPA_INET_H 1) +set(HAVE_ATOMIC 1) +set(HAVE_BASENAME 1) +set(HAVE_BOOL_T 1) +if(NOT APPLE) + set(HAVE_CLOCK_GETTIME_MONOTONIC 1) + if(CMAKE_SYSTEM_NAME STREQUAL "Linux") + set(HAVE_CLOCK_GETTIME_MONOTONIC_RAW 1) + else() + set(HAVE_CLOCK_GETTIME_MONOTONIC_RAW 0) + endif() +endif() +set(HAVE_CLOSESOCKET 0) +set(HAVE_DECL_FSEEKO 1) +set(HAVE_DIRENT_H 1) +if(APPLE OR + CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "OpenBSD") + set(HAVE_EVENTFD 0) +elseif(CMAKE_SYSTEM_NAME STREQUAL "Linux" OR + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "NetBSD") + set(HAVE_EVENTFD 1) +endif() +if(ANDROID AND ANDROID_PLATFORM_LEVEL GREATER_EQUAL 34) + set(HAVE_MEMSET_EXPLICIT 1) +endif() +if((APPLE AND CMAKE_OSX_DEPLOYMENT_TARGET VERSION_GREATER_EQUAL 10.9) OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR # v6+ + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR # v11.2+ + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD") # v1.3+ + set(HAVE_MEMSET_S 1) +elseif(NOT APPLE) + set(HAVE_MEMSET_S 0) +endif() +set(HAVE_FCNTL 1) +set(HAVE_FCNTL_H 1) +set(HAVE_FCNTL_O_NONBLOCK 1) +set(HAVE_FILE_OFFSET_BITS 1) +set(HAVE_FNMATCH 1) +set(HAVE_FREEADDRINFO 1) +set(HAVE_FSEEKO 1) +if(APPLE) + set(HAVE_FSETXATTR 1) + set(HAVE_FSETXATTR_5 0) + set(HAVE_FSETXATTR_6 1) +elseif(CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "OpenBSD") + set(HAVE_FSETXATTR 0) + set(HAVE_FSETXATTR_5 0) + set(HAVE_FSETXATTR_6 0) +elseif(CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "Linux" OR + CMAKE_SYSTEM_NAME STREQUAL "NetBSD") + set(HAVE_FSETXATTR 1) + set(HAVE_FSETXATTR_5 1) + set(HAVE_FSETXATTR_6 0) +endif() +set(HAVE_GETADDRINFO 1) +if(CMAKE_SYSTEM_NAME STREQUAL "OpenBSD") + set(HAVE_GETADDRINFO_THREADSAFE 0) +elseif(CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "Linux" OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "NetBSD") + set(HAVE_GETADDRINFO_THREADSAFE 1) +endif() +set(HAVE_GETEUID 1) +if(APPLE OR + CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "NetBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "OpenBSD") + set(HAVE_GETHOSTBYNAME_R 0) +elseif(CMAKE_SYSTEM_NAME STREQUAL "Linux" OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD") + set(HAVE_GETHOSTBYNAME_R 1) +endif() +set(HAVE_GETHOSTBYNAME_R_3 0) +set(HAVE_GETHOSTBYNAME_R_3_REENTRANT 0) +set(HAVE_GETHOSTBYNAME_R_5 0) +set(HAVE_GETHOSTBYNAME_R_5_REENTRANT 0) +if(CMAKE_SYSTEM_NAME STREQUAL "Linux" OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD") + set(HAVE_GETHOSTBYNAME_R_6 1) + set(HAVE_GETHOSTBYNAME_R_6_REENTRANT 1) +else() + set(HAVE_GETHOSTBYNAME_R_6 0) + set(HAVE_GETHOSTBYNAME_R_6_REENTRANT 0) +endif() +set(HAVE_GETHOSTNAME 1) +if(NOT ANDROID OR ANDROID_PLATFORM_LEVEL GREATER_EQUAL 24) + set(HAVE_GETIFADDRS 1) +else() + set(HAVE_GETIFADDRS 0) +endif() +if(APPLE OR + CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "Linux" OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "OpenBSD") + set(HAVE_GETPASS_R 0) +elseif(CMAKE_SYSTEM_NAME STREQUAL "NetBSD") + set(HAVE_GETPASS_R 1) +endif() +set(HAVE_GETPEERNAME 1) +set(HAVE_GETPPID 1) +set(HAVE_GETPWUID 1) +set(HAVE_GETPWUID_R 1) +set(HAVE_GETRLIMIT 1) +set(HAVE_GETSOCKNAME 1) +set(HAVE_GETTIMEOFDAY 1) +if(CMAKE_SYSTEM_NAME STREQUAL "Linux") + # Depends on C library. +else() + set(HAVE_GLIBC_STRERROR_R 0) +endif() +set(HAVE_GMTIME_R 1) +set(HAVE_IFADDRS_H 1) +set(HAVE_IF_NAMETOINDEX 1) +set(HAVE_INET_NTOP 1) +set(HAVE_INET_PTON 1) +set(HAVE_IOCTLSOCKET 0) +set(HAVE_IOCTLSOCKET_CAMEL 0) +set(HAVE_IOCTLSOCKET_CAMEL_FIONBIO 0) +set(HAVE_IOCTLSOCKET_FIONBIO 0) +set(HAVE_IOCTL_FIONBIO 1) +set(HAVE_IOCTL_SIOCGIFADDR 1) +if(CYGWIN) + set(HAVE_IO_H 1) +else() + set(HAVE_IO_H 0) +endif() +set(HAVE_LIBGEN_H 1) +if(CMAKE_SYSTEM_NAME STREQUAL "Linux") + # Requires Linux kernel userspace headers. Expected with glibc. May be missing by default with MUSL. +else() + set(HAVE_LINUX_TCP_H 0) +endif() +set(HAVE_LOCALE_H 1) +set(HAVE_LOCALTIME_R 1) +if(APPLE) + set(HAVE_MACH_ABSOLUTE_TIME 1) +endif() +if(APPLE OR + CYGWIN) + set(HAVE_MEMRCHR 0) +else() + set(HAVE_MEMRCHR 1) +endif() +set(HAVE_NETDB_H 1) +if(ANDROID) + set(HAVE_NETINET_IN6_H 1) +else() + set(HAVE_NETINET_IN6_H 0) +endif() +set(HAVE_NETINET_IN_H 1) +set(HAVE_NETINET_TCP_H 1) +set(HAVE_NETINET_UDP_H 1) +set(HAVE_NET_IF_H 1) +set(HAVE_OPENDIR 1) +set(HAVE_PIPE 1) +if(APPLE OR + CYGWIN) + set(HAVE_PIPE2 0) +elseif(CMAKE_SYSTEM_NAME STREQUAL "Linux" OR + BSD OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "NetBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "OpenBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "SunOS") + set(HAVE_PIPE2 1) +endif() +set(HAVE_POLL 1) +set(HAVE_POLL_H 1) +if(CMAKE_SYSTEM_NAME STREQUAL "Linux") + # Depends on C library. +else() + set(HAVE_POSIX_STRERROR_R 1) +endif() +set(HAVE_PWD_H 1) +set(HAVE_REALPATH 1) +set(HAVE_RECV 1) +set(HAVE_SA_FAMILY_T 1) +set(HAVE_SCHED_YIELD 1) +set(HAVE_SELECT 1) +set(HAVE_SEND 1) +if(APPLE OR + CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD") + set(HAVE_SENDMMSG 0) +else() + set(HAVE_SENDMMSG 1) +endif() +set(HAVE_SENDMSG 1) +set(HAVE_SETLOCALE 1) +set(HAVE_SETRLIMIT 1) +set(HAVE_SETSOCKOPT_SO_NONBLOCK 0) +set(HAVE_SIGACTION 1) +set(HAVE_SIGINTERRUPT 1) +set(HAVE_SIGNAL 1) +set(HAVE_SIGSETJMP 1) +set(HAVE_SOCKADDR_IN6_SIN6_ADDR 1) +set(HAVE_SOCKADDR_IN6_SIN6_SCOPE_ID 1) +set(HAVE_SOCKET 1) +set(HAVE_SOCKETPAIR 1) +set(HAVE_STDATOMIC_H 1) +set(HAVE_STDBOOL_H 1) +set(HAVE_STDDEF_H 1) # detected by CMake internally in check_type_size() +set(HAVE_STDINT_H 1) # detected by CMake internally in check_type_size() +set(HAVE_STRCASECMP 1) +set(HAVE_STRCMPI 0) +set(HAVE_STRERROR_R 1) +set(HAVE_STRICMP 0) +set(HAVE_STRINGS_H 1) +if(_CURL_OLD_LINUX) + set(HAVE_STROPTS_H 1) +else() + set(HAVE_STROPTS_H 0) # glibc 2.30 or newer. https://sourceware.org/legacy-ml/libc-alpha/2019-08/msg00029.html +endif() +set(HAVE_STRUCT_SOCKADDR_STORAGE 1) +set(HAVE_STRUCT_TIMEVAL 1) +if(ANDROID OR CMAKE_SYSTEM_NAME STREQUAL "iOS") + set(HAVE_SUSECONDS_T 1) +endif() +if(APPLE OR + CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "DragonFlyBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "OpenBSD") + set(HAVE_SYS_EVENTFD_H 0) +elseif(CMAKE_SYSTEM_NAME STREQUAL "Linux" OR + CMAKE_SYSTEM_NAME STREQUAL "FreeBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "MidnightBSD" OR + CMAKE_SYSTEM_NAME STREQUAL "NetBSD") + set(HAVE_SYS_EVENTFD_H 1) +endif() +if(CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "Linux") + set(HAVE_SYS_FILIO_H 0) +else() + set(HAVE_SYS_FILIO_H 1) +endif() +set(HAVE_SYS_IOCTL_H 1) +set(HAVE_SYS_PARAM_H 1) +set(HAVE_SYS_POLL_H 1) +set(HAVE_SYS_RESOURCE_H 1) +set(HAVE_SYS_SELECT_H 1) +if(CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "Linux") + set(HAVE_SYS_SOCKIO_H 0) +else() + set(HAVE_SYS_SOCKIO_H 1) +endif() +set(HAVE_SYS_TYPES_H 1) +set(HAVE_SYS_UN_H 1) +if(CYGWIN) + set(HAVE_SYS_UTIME_H 1) +else() + set(HAVE_SYS_UTIME_H 0) +endif() +set(HAVE_TERMIOS_H 1) +if(CYGWIN OR + CMAKE_SYSTEM_NAME STREQUAL "Linux") + set(HAVE_TERMIO_H 1) +else() + set(HAVE_TERMIO_H 0) +endif() +set(HAVE_TIME_T_UNSIGNED 0) +set(HAVE_UNISTD_H 1) +set(HAVE_UTIME 1) +set(HAVE_UTIMES 1) +set(HAVE_UTIME_H 1) +set(HAVE_WRITABLE_ARGV 1) +set(STDC_HEADERS 1) +set(USE_UNIX_SOCKETS 1) diff --git a/third-party/curl/CMake/win32-cache.cmake b/third-party/curl/CMake/win32-cache.cmake new file mode 100644 index 0000000000..bd9bb6e3fc --- /dev/null +++ b/third-party/curl/CMake/win32-cache.cmake @@ -0,0 +1,192 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +if(NOT WIN32) + message(FATAL_ERROR "This file should be included on Windows platform only") +endif() + +if(MINGW) + set(HAVE_BASENAME 1) + set(HAVE_BOOL_T 1) # = HAVE_STDBOOL_H + set(HAVE_DIRENT_H 1) + set(HAVE_GETTIMEOFDAY 1) + set(HAVE_LIBGEN_H 1) + set(HAVE_OPENDIR 1) + set(HAVE_STDBOOL_H 1) + set(HAVE_STDDEF_H 1) # detected by CMake internally in check_type_size() + set(HAVE_STDINT_H 1) # detected by CMake internally in check_type_size() + set(HAVE_STRINGS_H 1) # wrapper to string.h + set(HAVE_SYS_PARAM_H 1) + set(HAVE_UNISTD_H 1) + set(HAVE_UTIME_H 1) # wrapper to sys/utime.h +else() + set(HAVE_DIRENT_H 0) + set(HAVE_GETTIMEOFDAY 0) + set(HAVE_LIBGEN_H 0) + set(HAVE_OPENDIR 0) + set(HAVE_STRINGS_H 0) + set(HAVE_SYS_PARAM_H 0) + set(HAVE_UTIME_H 0) + if(MSVC) + set(HAVE_UNISTD_H 0) + set(HAVE_STDDEF_H 1) # detected by CMake internally in check_type_size() + set(HAVE_STDINT_H 1) # detected by CMake internally in check_type_size() + if(MSVC_VERSION GREATER_EQUAL 1800) + set(HAVE_STDBOOL_H 1) + else() + set(HAVE_STDBOOL_H 0) + endif() + set(HAVE_BOOL_T "${HAVE_STDBOOL_H}") + set(HAVE_BASENAME 0) + endif() +endif() + +if((CMAKE_C_COMPILER_ID STREQUAL "GNU" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.9) OR + (CMAKE_C_COMPILER_ID STREQUAL "Clang" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 3.6)) + # MinGW or clang-cl + set(HAVE_STDATOMIC_H 1) + set(HAVE_ATOMIC 1) +else() + set(HAVE_STDATOMIC_H 0) + set(HAVE_ATOMIC 0) +endif() + +set(HAVE_ACCEPT4 0) +set(HAVE_ALARM 0) +set(HAVE_ARC4RANDOM 0) +set(HAVE_ARPA_INET_H 0) +set(HAVE_CLOSESOCKET 1) +set(HAVE_EVENTFD 0) +set(HAVE_FCNTL 0) +set(HAVE_FCNTL_H 1) +set(HAVE_FCNTL_O_NONBLOCK 0) +set(HAVE_FNMATCH 0) +set(HAVE_FREEADDRINFO 1) # Available in Windows XP and newer +set(HAVE_FSETXATTR 0) +set(HAVE_GETADDRINFO 1) # Available in Windows XP and newer +set(HAVE_GETEUID 0) +set(HAVE_GETHOSTBYNAME_R 0) +set(HAVE_GETHOSTBYNAME_R_3 0) +set(HAVE_GETHOSTBYNAME_R_3_REENTRANT 0) +set(HAVE_GETHOSTBYNAME_R_5 0) +set(HAVE_GETHOSTBYNAME_R_5_REENTRANT 0) +set(HAVE_GETHOSTBYNAME_R_6 0) +set(HAVE_GETHOSTBYNAME_R_6_REENTRANT 0) +set(HAVE_GETHOSTNAME 1) +set(HAVE_GETIFADDRS 0) +set(HAVE_GETPASS_R 0) +set(HAVE_GETPEERNAME 1) +set(HAVE_GETPPID 0) +set(HAVE_GETPWUID 0) +set(HAVE_GETPWUID_R 0) +set(HAVE_GETRLIMIT 0) +set(HAVE_GETSOCKNAME 1) +set(HAVE_GLIBC_STRERROR_R 0) +set(HAVE_GMTIME_R 0) +set(HAVE_IFADDRS_H 0) +set(HAVE_INET_NTOP 0) +set(HAVE_INET_PTON 0) +set(HAVE_IOCTLSOCKET 1) +set(HAVE_IOCTLSOCKET_CAMEL 0) +set(HAVE_IOCTLSOCKET_CAMEL_FIONBIO 0) +set(HAVE_IOCTLSOCKET_FIONBIO 1) +set(HAVE_IOCTL_FIONBIO 0) +set(HAVE_IOCTL_SIOCGIFADDR 0) +set(HAVE_IO_H 1) +set(HAVE_LINUX_TCP_H 0) +set(HAVE_LOCALE_H 1) +set(HAVE_LOCALTIME_R 0) +set(HAVE_MEMRCHR 0) +set(HAVE_NETDB_H 0) +set(HAVE_NETINET_IN6_H 0) +set(HAVE_NETINET_IN_H 0) +set(HAVE_NETINET_TCP_H 0) +set(HAVE_NETINET_UDP_H 0) +set(HAVE_NET_IF_H 0) +set(HAVE_PIPE 0) +set(HAVE_PIPE2 0) +set(HAVE_POLL 0) +set(HAVE_POLL_H 0) +set(HAVE_POSIX_STRERROR_R 0) +set(HAVE_PWD_H 0) +set(HAVE_RECV 1) +set(HAVE_SELECT 1) +set(HAVE_SEND 1) +set(HAVE_SENDMMSG 0) +set(HAVE_SENDMSG 0) +set(HAVE_SETLOCALE 1) +set(HAVE_SETRLIMIT 0) +set(HAVE_SETSOCKOPT_SO_NONBLOCK 0) +set(HAVE_SIGACTION 0) +set(HAVE_SIGINTERRUPT 0) +set(HAVE_SIGNAL 1) +set(HAVE_SIGSETJMP 0) +set(HAVE_SOCKADDR_IN6_SIN6_SCOPE_ID 1) +set(HAVE_SOCKET 1) +set(HAVE_SOCKETPAIR 0) +set(HAVE_STRERROR_R 0) +set(HAVE_STROPTS_H 0) +set(HAVE_STRUCT_SOCKADDR_STORAGE 1) +set(HAVE_STRUCT_TIMEVAL 1) +set(HAVE_SYS_EVENTFD_H 0) +set(HAVE_SYS_FILIO_H 0) +set(HAVE_SYS_IOCTL_H 0) +set(HAVE_SYS_POLL_H 0) +set(HAVE_SYS_RESOURCE_H 0) +set(HAVE_SYS_SELECT_H 0) +set(HAVE_SYS_SOCKIO_H 0) +set(HAVE_SYS_TYPES_H 1) +set(HAVE_SYS_UN_H 0) +set(HAVE_SYS_UTIME_H 1) +set(HAVE_TERMIOS_H 0) +set(HAVE_TERMIO_H 0) +set(HAVE_TIME_T_UNSIGNED 0) +set(HAVE_UTIME 1) +set(HAVE_UTIMES 0) +set(STDC_HEADERS 1) + +# Types and sizes + +set(HAVE_SIZEOF_SA_FAMILY_T 0) +set(HAVE_SIZEOF_SUSECONDS_T 0) + +if(MINGW OR MSVC) + curl_prefill_type_size("INT" 4) + curl_prefill_type_size("LONG" 4) + curl_prefill_type_size("__INT64" 8) + curl_prefill_type_size("CURL_OFF_T" 8) + curl_prefill_type_size("CURL_SOCKET_T" ${CMAKE_SIZEOF_VOID_P}) + curl_prefill_type_size("SIZE_T" ${CMAKE_SIZEOF_VOID_P}) + # TIME_T: 8 for _WIN64 or UCRT or MSVC, 4 otherwise + # Also 4 for non-UCRT 32-bit when _USE_32BIT_TIME_T is set. + # mingw-w64 sets _USE_32BIT_TIME_T unless __MINGW_USE_VC2005_COMPAT is explicit defined. + if(MSVC) + set(HAVE_SIZEOF_SSIZE_T 0) + set(HAVE_FILE_OFFSET_BITS 0) + curl_prefill_type_size("OFF_T" 4) + else() + curl_prefill_type_size("SSIZE_T" ${CMAKE_SIZEOF_VOID_P}) + set(HAVE_FILE_OFFSET_BITS 1) # mingw-w64 v3+ + curl_prefill_type_size("OFF_T" 8) # mingw-w64 v3+ + endif() +endif() diff --git a/third-party/curl/CMakeLists.txt b/third-party/curl/CMakeLists.txt index bc42c6a628..e459b3d076 100644 --- a/third-party/curl/CMakeLists.txt +++ b/third-party/curl/CMakeLists.txt @@ -21,125 +21,324 @@ # SPDX-License-Identifier: curl # ########################################################################### -# curl/libcurl CMake script -# by Tetetest and Sukender (Benoit Neil) -# TODO: -# The output .so file lacks the soname number which we currently have within the lib/Makefile.am file -# Add full (4 or 5 libs) SSL support -# Add INSTALL target (EXTRA_DIST variables in Makefile.am may be moved to Makefile.inc so that CMake/CPack is aware of what's to include). -# Check on all possible platforms -# Test with as many configurations possible (With or without any option) -# Create scripts that help keeping the CMake build system up to date (to reduce maintenance). According to Tetetest: -# - lists of headers that 'configure' checks for; -# - curl-specific tests (the ones that are in m4/curl-*.m4 files); -# - (most obvious thing:) curl version numbers. -# Add documentation subproject -# -# To check: -# (From Daniel Stenberg) The cmake build selected to run gcc with -fPIC on my box while the plain configure script did not. -# (From Daniel Stenberg) The gcc command line use neither -g nor any -O options. As a developer, I also treasure our configure scripts's --enable-debug option that sets a long range of "picky" compiler options. +cmake_minimum_required(VERSION 3.18 FATAL_ERROR) +message(STATUS "Using CMake version ${CMAKE_VERSION}") -# Note: By default this CMake build script detects the version of some -# dependencies using `check_symbol_exists`. Those checks do not work -# in the case that both CURL and its dependency are included as -# sub-projects in a larger build using `FetchContent`. To support -# that case, additional variables may be defined by the parent -# project, ideally in the "extra" find package redirect file: -# https://cmake.org/cmake/help/latest/module/FetchContent.html#integrating-with-find-package -# -# The following variables are available: -# HAVE_SSL_SET0_WBIO: `SSL_set0_wbio` present in OpenSSL -# HAVE_AWSLC: OpenSSL is AWS-LC -# HAVE_BORINGSSL: OpenSSL is BoringSSL -# HAVE_SSL_CTX_SET_QUIC_METHOD: `SSL_CTX_set_quic_method` present in OpenSSL/wolfSSL -# HAVE_QUICHE_CONN_SET_QLOG_FD: `quiche_conn_set_qlog_fd` present in QUICHE -# HAVE_ZSTD_CREATEDSTREAM: `ZSTD_createDStream` present in Zstd -# -# For each of the above variables, if the variable is DEFINED (either -# to ON or OFF), the symbol detection will be skipped. If the -# variable is NOT DEFINED, the symbol detection will be performed. +# Collect command-line arguments for buildinfo.txt. +# Must reside at the top of the script to work as expected. +set(_cmake_args "") +if(NOT "$ENV{CURL_BUILDINFO}$ENV{CURL_CI}$ENV{CI}" STREQUAL "") + get_cmake_property(_cache_vars CACHE_VARIABLES) + foreach(_cache_var IN ITEMS ${_cache_vars}) + get_property(_cache_var_helpstring CACHE ${_cache_var} PROPERTY HELPSTRING) + if(_cache_var_helpstring STREQUAL "No help, variable specified on the command line.") + get_property(_cache_var_type CACHE ${_cache_var} PROPERTY TYPE) + get_property(_cache_var_value CACHE ${_cache_var} PROPERTY VALUE) + if(_cache_var_type STREQUAL "UNINITIALIZED") + set(_cache_var_type "") + else() + set(_cache_var_type ":${_cache_var_type}") + endif() + string(APPEND _cmake_args " -D${_cache_var}${_cache_var_type}=\"${_cache_var_value}\"") + endif() + endforeach() +endif() -cmake_minimum_required(VERSION 3.7...3.16 FATAL_ERROR) - -set(CMAKE_MODULE_PATH "${CMAKE_CURRENT_SOURCE_DIR}/CMake;${CMAKE_MODULE_PATH}") +list(PREPEND CMAKE_MODULE_PATH "${CMAKE_CURRENT_SOURCE_DIR}/CMake") include(Utilities) include(Macros) include(CMakeDependentOption) include(CheckCCompilerFlag) -project(CURL C) +file(STRINGS "${CMAKE_CURRENT_SOURCE_DIR}/include/curl/curlver.h" _curl_version_h_contents REGEX "#define LIBCURL_VERSION( |_NUM )") +string(REGEX MATCH "#define LIBCURL_VERSION \"[^\"]*" _curl_version ${_curl_version_h_contents}) +string(REGEX REPLACE "[^\"]+\"" "" _curl_version ${_curl_version}) +string(REGEX MATCH "#define LIBCURL_VERSION_NUM 0x[0-9a-fA-F]+" _curl_version_num ${_curl_version_h_contents}) +string(REGEX REPLACE "[^0]+0x" "" _curl_version_num ${_curl_version_num}) +unset(_curl_version_h_contents) -file(STRINGS ${CURL_SOURCE_DIR}/include/curl/curlver.h CURL_VERSION_H_CONTENTS REGEX "#define LIBCURL_VERSION( |_NUM )") -string(REGEX MATCH "#define LIBCURL_VERSION \"[^\"]*" - CURL_VERSION ${CURL_VERSION_H_CONTENTS}) -string(REGEX REPLACE "[^\"]+\"" "" CURL_VERSION ${CURL_VERSION}) -string(REGEX MATCH "#define LIBCURL_VERSION_NUM 0x[0-9a-fA-F]+" - CURL_VERSION_NUM ${CURL_VERSION_H_CONTENTS}) -string(REGEX REPLACE "[^0]+0x" "" CURL_VERSION_NUM ${CURL_VERSION_NUM}) +message(STATUS "curl version=[${_curl_version}]") +string(REGEX REPLACE "([0-9]+\.[0-9]+\.[0-9]+).+" "\\1" _curl_version_sem "${_curl_version}") +project(CURL + VERSION "${_curl_version_sem}" + LANGUAGES C) -# Setup package meta-data -# SET(PACKAGE "curl") -message(STATUS "curl version=[${CURL_VERSION}]") -# SET(PACKAGE_TARNAME "curl") -# SET(PACKAGE_NAME "curl") -# SET(PACKAGE_VERSION "-") -# SET(PACKAGE_STRING "curl-") -# SET(PACKAGE_BUGREPORT "a suitable curl mailing list => https://curl.se/mail/") -set(OPERATING_SYSTEM "${CMAKE_SYSTEM_NAME}") -if(CMAKE_C_COMPILER_TARGET) - set(OS "\"${CMAKE_C_COMPILER_TARGET}\"") -else() - set(OS "\"${CMAKE_SYSTEM_NAME}\"") +# CMake does not recognize some targets accurately. Touch up configuration manually as a workaround. +if(WINDOWS_STORE AND MINGW) # MinGW UWP build + # CMake (as of v3.31.2) gets confused and applies the MSVC rc.exe command-line + # template to windres. Reset it to the windres template as in 'Modules/Platform/Windows-windres.cmake': + set(CMAKE_RC_COMPILE_OBJECT " -O coff ") +elseif(DOS AND CMAKE_C_COMPILER_ID STREQUAL "GNU") # DJGPP + set(CMAKE_STATIC_LIBRARY_PREFIX "lib") + set(CMAKE_STATIC_LIBRARY_SUFFIX ".a") + set(CMAKE_FIND_LIBRARY_PREFIXES "lib") + set(CMAKE_FIND_LIBRARY_SUFFIXES ".a") endif() -include_directories(${CURL_SOURCE_DIR}/include) +# Fill platform level variable when using CMake's built-in Android configuration +if(ANDROID AND NOT DEFINED ANDROID_PLATFORM_LEVEL AND NOT CMAKE_SYSTEM_VERSION EQUAL 1) + set(ANDROID_PLATFORM_LEVEL "${CMAKE_SYSTEM_VERSION}") +endif() -set(CMAKE_UNITY_BUILD_BATCH_SIZE 0) +set(_target_flags "") +if(APPLE) + string(APPEND _target_flags " APPLE") +endif() +if(UNIX) + string(APPEND _target_flags " UNIX") +endif() +if(BSD) + string(APPEND _target_flags " BSD") +endif() +if(ANDROID) + string(APPEND _target_flags " ANDROID-${ANDROID_PLATFORM_LEVEL}") +endif() +if(WIN32) + string(APPEND _target_flags " WIN32") +endif() +if(WINDOWS_STORE) + string(APPEND _target_flags " UWP") +endif() +if(CYGWIN) + string(APPEND _target_flags " CYGWIN") +endif() +if(DOS) + string(APPEND _target_flags " DOS") +endif() +if(AMIGA) + string(APPEND _target_flags " AMIGA") +endif() +if(CMAKE_C_COMPILER_ID STREQUAL "GNU") + string(APPEND _target_flags " GCC") +endif() +if(CMAKE_C_COMPILER_ID STREQUAL "AppleClang") + string(APPEND _target_flags " APPLE-CLANG") +elseif(CMAKE_C_COMPILER_ID STREQUAL "Clang" AND MSVC) + string(APPEND _target_flags " CLANG-CL") +elseif(CMAKE_C_COMPILER_ID MATCHES "Clang") + string(APPEND _target_flags " LLVM-CLANG") +endif() +if(MINGW) + string(APPEND _target_flags " MINGW") +endif() +if(MSVC) + string(APPEND _target_flags " MSVC-${MSVC_VERSION}") +endif() +if(VCPKG_TOOLCHAIN) + string(APPEND _target_flags " VCPKG") +endif() +if(CMAKE_CROSSCOMPILING) + string(APPEND _target_flags " CROSS") +endif() +if(CMAKE_C_STANDARD) + string(APPEND _target_flags " C${CMAKE_C_STANDARD}") +endif() +message(STATUS "CMake platform flags:${_target_flags}") + +if(CMAKE_CROSSCOMPILING) + message(STATUS "Cross-compiling: " + "${CMAKE_HOST_SYSTEM_NAME}/${CMAKE_HOST_SYSTEM_PROCESSOR} -> " + "${CMAKE_SYSTEM_NAME}/${CMAKE_SYSTEM_PROCESSOR}") +endif() + +if(CMAKE_C_COMPILER_TARGET) + set(CURL_OS "\"${CMAKE_C_COMPILER_TARGET}\"") +else() + set(CURL_OS "\"${CMAKE_SYSTEM_NAME}\"") +endif() + +if(CURL_PATCHSTAMP) + set(CURL_PATCHSTAMP "\"${CURL_PATCHSTAMP}\"") +endif() + +set(LIB_NAME "libcurl") +set(EXE_NAME "curl") + +set_property(DIRECTORY APPEND PROPERTY INCLUDE_DIRECTORIES "${PROJECT_SOURCE_DIR}/include") + +if(NOT DEFINED CMAKE_UNITY_BUILD_BATCH_SIZE) + set(CMAKE_UNITY_BUILD_BATCH_SIZE 0) +endif() + +# Having CMAKE_TRY_COMPILE_TARGET_TYPE set to STATIC_LIBRARY breaks certain +# 'check_function_exists()' detections (possibly more), by detecting +# non-existing features. This happens by default when using 'ios.toolchain.cmake'. +# Work it around by setting this value to `EXECUTABLE`. +if(CMAKE_TRY_COMPILE_TARGET_TYPE STREQUAL "STATIC_LIBRARY") + message(STATUS "CMAKE_TRY_COMPILE_TARGET_TYPE was found set to STATIC_LIBRARY. " + "Overriding with EXECUTABLE for feature detections to work.") + set(_cmake_try_compile_target_type_save ${CMAKE_TRY_COMPILE_TARGET_TYPE}) + set(CMAKE_TRY_COMPILE_TARGET_TYPE "EXECUTABLE") +endif() option(CURL_WERROR "Turn compiler warnings into errors" OFF) option(PICKY_COMPILER "Enable picky compiler options" ON) -option(BUILD_CURL_EXE "Set to ON to build curl executable." ON) -option(BUILD_SHARED_LIBS "Build shared libraries" ON) -option(BUILD_STATIC_LIBS "Build shared libraries" OFF) +option(BUILD_CURL_EXE "Build curl executable" ON) +get_property(_has_shared GLOBAL PROPERTY TARGET_SUPPORTS_SHARED_LIBS) +option(BUILD_SHARED_LIBS "Build shared libraries" ${_has_shared}) +option(BUILD_STATIC_LIBS "Build static libraries" OFF) option(BUILD_STATIC_CURL "Build curl executable with static libcurl" OFF) -option(ENABLE_ARES "Set to ON to enable c-ares support" OFF) +option(ENABLE_ARES "Enable c-ares support" OFF) +option(CURL_DISABLE_INSTALL "Disable installation targets" OFF) +option(CURL_BUILD_EVERYTHING "Build optional build targets (examples, tests) by default" OFF) + if(WIN32) - option(CURL_STATIC_CRT "Set to ON to build libcurl with static CRT on Windows (/MT)." OFF) - option(ENABLE_UNICODE "Set to ON to use the Unicode version of the Windows API functions" OFF) - set(CURL_TARGET_WINDOWS_VERSION "" CACHE STRING "Minimum target Windows version as hex string") - if(CURL_TARGET_WINDOWS_VERSION) - add_definitions(-D_WIN32_WINNT=${CURL_TARGET_WINDOWS_VERSION}) - list(APPEND CMAKE_REQUIRED_DEFINITIONS -D_WIN32_WINNT=${CURL_TARGET_WINDOWS_VERSION}) - set(CURL_TEST_DEFINES "${CURL_TEST_DEFINES} -D_WIN32_WINNT=${CURL_TARGET_WINDOWS_VERSION}") + option(ENABLE_UNICODE "Use the Unicode version of the Windows API functions" OFF) + if(WINDOWS_STORE) + set(ENABLE_UNICODE ON) endif() if(ENABLE_UNICODE) - add_definitions(-DUNICODE -D_UNICODE) + set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS "UNICODE" "_UNICODE") if(MINGW) - add_compile_options(-municode) + set_property(DIRECTORY APPEND PROPERTY COMPILE_OPTIONS "-municode") endif() endif() + + # Apply to all feature checks + list(APPEND CMAKE_REQUIRED_DEFINITIONS "-DWIN32_LEAN_AND_MEAN") + + set(CURL_TARGET_WINDOWS_VERSION "" CACHE STRING "Minimum target Windows version as hex string") + if(CURL_TARGET_WINDOWS_VERSION) + if(CURL_TARGET_WINDOWS_VERSION MATCHES "^0x[0-9a-fA-F]+$") + set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS "_WIN32_WINNT=${CURL_TARGET_WINDOWS_VERSION}") + list(APPEND CMAKE_REQUIRED_DEFINITIONS "-D_WIN32_WINNT=${CURL_TARGET_WINDOWS_VERSION}") # Apply to all feature checks + else() + message(WARNING "CURL_TARGET_WINDOWS_VERSION value '${CURL_TARGET_WINDOWS_VERSION}' is not a valid hex string.") + endif() + endif() + + # Detect actual value of _WIN32_WINNT and store as HAVE_WIN32_WINNT + curl_internal_test(HAVE_WIN32_WINNT) + if(HAVE_WIN32_WINNT) + string(REGEX MATCH "_WIN32_WINNT=0x[0-9a-fA-F]+" CURL_TEST_OUTPUT "${CURL_TEST_OUTPUT}") + string(REGEX REPLACE "_WIN32_WINNT=" "" CURL_TEST_OUTPUT "${CURL_TEST_OUTPUT}") + string(REGEX REPLACE "0x([0-9a-fA-F][0-9a-fA-F][0-9a-fA-F])$" "0x0\\1" CURL_TEST_OUTPUT "${CURL_TEST_OUTPUT}") # pad to 4 digits + string(TOLOWER "${CURL_TEST_OUTPUT}" HAVE_WIN32_WINNT) + message(STATUS "Found _WIN32_WINNT=${HAVE_WIN32_WINNT}") + endif() + unset(HAVE_WIN32_WINNT CACHE) # Avoid storing in CMake cache + + if(MINGW) + # Detect __MINGW64_VERSION_MAJOR, __MINGW64_VERSION_MINOR and store as MINGW64_VERSION + curl_internal_test(MINGW64_VERSION) + if(MINGW64_VERSION) + string(REGEX MATCH "MINGW64_VERSION=[0-9]+\.[0-9]+" CURL_TEST_OUTPUT "${CURL_TEST_OUTPUT}") + string(REGEX REPLACE "MINGW64_VERSION=" "" MINGW64_VERSION "${CURL_TEST_OUTPUT}") + if(MINGW64_VERSION) + message(STATUS "Found MINGW64_VERSION=${MINGW64_VERSION}") + if(MINGW64_VERSION VERSION_LESS 3.0) + message(FATAL_ERROR "mingw-w64 3.0 or upper is required") + endif() + endif() + endif() + unset(MINGW64_VERSION CACHE) # Avoid storing in CMake cache + endif() +elseif(DOS) + set(BUILD_SHARED_LIBS OFF) + set(BUILD_STATIC_LIBS ON) endif() -option(CURL_LTO "Turn on compiler Link Time Optimizations" OFF) +option(CURL_LTO "Enable compiler Link Time Optimizations" OFF) -cmake_dependent_option(ENABLE_THREADED_RESOLVER "Set to ON to enable threaded DNS lookup" - ON "NOT ENABLE_ARES" - OFF) +if(NOT DOS AND NOT AMIGA) + # if c-ares is used, default the threaded resolver to OFF + if(ENABLE_ARES) + set(_enable_threaded_resolver_default OFF) + else() + set(_enable_threaded_resolver_default ON) + endif() + option(ENABLE_THREADED_RESOLVER "Enable threaded DNS lookup" ${_enable_threaded_resolver_default}) +endif() -option(ENABLE_DEBUG "Set to ON to enable curl debug features" OFF) -option(ENABLE_CURLDEBUG "Set to ON to build with TrackMemory feature enabled" OFF) +if(CYGWIN OR CMAKE_SYSTEM_NAME STREQUAL "Linux" OR CMAKE_SYSTEM_NAME STREQUAL "GNU") + set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS "_GNU_SOURCE") # Required for accept4(), pipe2(), sendmmsg() + list(APPEND CMAKE_REQUIRED_DEFINITIONS "-D_GNU_SOURCE") # Apply to all feature checks +endif() + +option(ENABLE_DEBUG "Enable curl debug features (for developing curl itself)" OFF) +if(ENABLE_DEBUG) + message(WARNING "This curl build is Debug-enabled and insecure, do not use in production.") +endif() + +set(CURL_DEBUG_MACROS "") +if(ENABLE_DEBUG) + list(APPEND CURL_DEBUG_MACROS "DEBUGBUILD") +endif() + +option(CURL_CLANG_TIDY "Run the build through clang-tidy" OFF) +if(CURL_CLANG_TIDY) + find_program(CLANG_TIDY NAMES "clang-tidy" REQUIRED) + if(NOT CMAKE_C_COMPILER_ID MATCHES "Clang") + set(PICKY_COMPILER OFF) # Do a best effort and skip passing non-clang warning options to clang-tidy. + # This lets through warning options enabled via CURL_WERROR=ON, affecting lib and src. + endif() + set(CURL_DISABLE_TYPECHECK ON) # to improve performance (1.4x), avoid potential interference and bugprone-macro-parentheses. + set(CMAKE_C_CLANG_TIDY "${CLANG_TIDY}") + list(APPEND CMAKE_C_CLANG_TIDY "--config-file=${PROJECT_SOURCE_DIR}/.clang-tidy.yml") + if(CURL_WERROR) + list(APPEND CMAKE_C_CLANG_TIDY "--warnings-as-errors=*") + endif() + if(CURL_CLANG_TIDYFLAGS) + string(REPLACE " " ";" _tidy_flags_list "${CURL_CLANG_TIDYFLAGS}") + list(APPEND CMAKE_C_CLANG_TIDY ${_tidy_flags_list}) + endif() +endif() + +option(CURL_GCC_ANALYZER "Enable GCC --analyzer option" OFF) +if(CURL_GCC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU" AND CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 11.0) + set(CURL_DISABLE_TYPECHECK ON) # to improve performance (1.1x). + # https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html + set(CURL_ANALYZER_CFLAGS "-fanalyzer") + # disable checks causing false positives only + list(APPEND CURL_ANALYZER_CFLAGS "-Wno-analyzer-fd-leak" "-Wno-analyzer-fd-use-without-check" "-Wno-analyzer-file-leak") + list(APPEND CURL_ANALYZER_CFLAGS "-Wno-analyzer-infinite-loop") + list(APPEND CURL_ANALYZER_CFLAGS "-Wno-analyzer-malloc-leak") + list(APPEND CURL_ANALYZER_CFLAGS "-Wno-analyzer-out-of-bounds") +endif() + +option(CURL_CODE_COVERAGE "Enable code coverage build options" OFF) +if(CURL_CODE_COVERAGE) + if(CMAKE_C_COMPILER_ID STREQUAL "GNU") + set(CURL_COVERAGE_MACROS "NDEBUG") + set(CURL_COVERAGE_CFLAGS "-O0" "-g" "-fprofile-arcs") + if(CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL 4.1) + list(APPEND CURL_COVERAGE_CFLAGS "--coverage") + else() + list(APPEND CURL_COVERAGE_CFLAGS "-ftest-coverage") + endif() + set(CURL_COVERAGE_LIBS "gcov") + elseif(CMAKE_C_COMPILER_ID MATCHES "Clang") + set(CURL_COVERAGE_MACROS "NDEBUG") + set(CURL_COVERAGE_CFLAGS "-O0" "-g" "-fprofile-instr-generate" "-fcoverage-mapping") + set(CURL_COVERAGE_LDFLAGS "-fprofile-instr-generate" "-fcoverage-mapping") + else() + set(CURL_CODE_COVERAGE OFF) + endif() +endif() include(PickyWarnings) -if(ENABLE_DEBUG) - # DEBUGBUILD will be defined only for Debug builds - set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS $<$:DEBUGBUILD>) - set(ENABLE_CURLDEBUG ON) -endif() +set(CURL_CFLAGS "") # C flags set for libcurl and curl tool (aka public binaries) only -if(ENABLE_CURLDEBUG) - set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS CURLDEBUG) +option(CURL_DROP_UNUSED "Drop unused code and data from built binaries" OFF) +if(CURL_DROP_UNUSED) + if(APPLE) + set_property(DIRECTORY APPEND PROPERTY LINK_OPTIONS "-Wl,-dead_strip") + elseif(MSVC) # Options below are toolchain defaults in Release configurations. + # This option does not seem to have an effect with VS2010: + set_property(DIRECTORY APPEND PROPERTY LINK_OPTIONS "-OPT:REF") + # Optional, but reduces binary size further, with the cost of larger objects/static libraries: + list(APPEND CURL_CFLAGS "-Gy") + elseif(CMAKE_C_COMPILER_ID STREQUAL "GNU" OR CMAKE_C_COMPILER_ID MATCHES "Clang") + if(WIN32) + # To make -Wl,--gc-sections work on Windows: https://sourceware.org/bugzilla/show_bug.cgi?id=11539 + set_property(DIRECTORY APPEND PROPERTY COMPILE_OPTIONS "-fno-asynchronous-unwind-tables") + endif() + set_property(DIRECTORY APPEND PROPERTY LINK_OPTIONS "-Wl,--gc-sections") + # Optional, but reduces binary size further, with the cost of larger objects/static libraries: + list(APPEND CURL_CFLAGS "-ffunction-sections" "-fdata-sections") + endif() endif() # For debug libs and exes, add "-d" postfix @@ -159,114 +358,180 @@ elseif(BUILD_STATIC_CURL AND NOT BUILD_STATIC_LIBS) set(BUILD_STATIC_CURL OFF) endif() -# lib flavour selected for curl tool +# Lib flavor selected for curl tool if(BUILD_STATIC_CURL) set(LIB_SELECTED_FOR_EXE ${LIB_STATIC}) else() set(LIB_SELECTED_FOR_EXE ${LIB_SHARED}) endif() -# lib flavour selected for example and test programs. +# Lib flavor selected for example and test programs. if(BUILD_SHARED_LIBS) set(LIB_SELECTED ${LIB_SHARED}) else() set(LIB_SELECTED ${LIB_STATIC}) endif() -# initialize CURL_LIBS +if(WIN32) + option(CURL_STATIC_CRT "Build libcurl with static CRT with MSVC (/MT)" OFF) + if(CURL_STATIC_CRT AND MSVC) + if(MSVC_VERSION GREATER_EQUAL 1900 OR BUILD_STATIC_CURL OR NOT BUILD_CURL_EXE) + set(CMAKE_MSVC_RUNTIME_LIBRARY "MultiThreaded$<$:Debug>") + set_property(DIRECTORY APPEND PROPERTY COMPILE_OPTIONS "$<$:-MT>") + set_property(DIRECTORY APPEND PROPERTY COMPILE_OPTIONS "$<$:-MTd>") + else() + message(WARNING "Static CRT requires UCRT, static libcurl or no curl executable.") + endif() + endif() +endif() + +# Override to force-disable or force-enable the use of CMake Configs. +if(MSVC AND NOT VCPKG_TOOLCHAIN AND NOT CMAKE_CROSSCOMPILING) + set(_curl_use_cmakeconfig_default ON) +else() + set(_curl_use_cmakeconfig_default OFF) +endif() +option(CURL_USE_CMAKECONFIG "Enable detecting dependencies via CMake Config" ${_curl_use_cmakeconfig_default}) + +# Override to force-disable or force-enable the use of pkg-config. +if((UNIX AND NOT ANDROID AND (NOT APPLE OR CMAKE_SYSTEM_NAME STREQUAL "Darwin")) OR + VCPKG_TOOLCHAIN OR + (MINGW AND NOT CMAKE_CROSSCOMPILING)) + set(_curl_use_pkgconfig_default ON) +else() + set(_curl_use_pkgconfig_default OFF) +endif() +option(CURL_USE_PKGCONFIG "Enable pkg-config to detect dependencies" ${_curl_use_pkgconfig_default}) + +# Initialize variables collecting system and dependency libs. +set(CURL_NETWORK_AND_TIME_LIBS "") set(CURL_LIBS "") if(ENABLE_ARES) set(USE_ARES 1) - find_package(CARES REQUIRED) - list(APPEND CURL_LIBS ${CARES_LIBRARY}) + find_package(Cares MODULE REQUIRED) + list(APPEND CURL_LIBS CURL::cares) endif() include(CurlSymbolHiding) -option(CURL_ENABLE_EXPORT_TARGET "to enable cmake export target" ON) +option(CURL_ENABLE_EXPORT_TARGET "Enable CMake export target" ON) mark_as_advanced(CURL_ENABLE_EXPORT_TARGET) -option(CURL_DISABLE_ALTSVC "disables alt-svc support" OFF) +option(CURL_DISABLE_ALTSVC "Disable alt-svc support" OFF) mark_as_advanced(CURL_DISABLE_ALTSVC) -option(CURL_DISABLE_COOKIES "disables cookies support" OFF) +option(CURL_DISABLE_SRP "Disable TLS-SRP support" OFF) +mark_as_advanced(CURL_DISABLE_SRP) +option(CURL_DISABLE_COOKIES "Disable cookies support" OFF) mark_as_advanced(CURL_DISABLE_COOKIES) -option(CURL_DISABLE_BASIC_AUTH "disables Basic authentication" OFF) +option(CURL_DISABLE_BASIC_AUTH "Disable Basic authentication" OFF) mark_as_advanced(CURL_DISABLE_BASIC_AUTH) -option(CURL_DISABLE_BEARER_AUTH "disables Bearer authentication" OFF) +option(CURL_DISABLE_BEARER_AUTH "Disable Bearer authentication" OFF) mark_as_advanced(CURL_DISABLE_BEARER_AUTH) -option(CURL_DISABLE_DIGEST_AUTH "disables Digest authentication" OFF) +option(CURL_DISABLE_DIGEST_AUTH "Disable Digest authentication" OFF) mark_as_advanced(CURL_DISABLE_DIGEST_AUTH) -option(CURL_DISABLE_KERBEROS_AUTH "disables Kerberos authentication" OFF) +option(CURL_DISABLE_KERBEROS_AUTH "Disable Kerberos authentication" OFF) mark_as_advanced(CURL_DISABLE_KERBEROS_AUTH) -option(CURL_DISABLE_NEGOTIATE_AUTH "disables negotiate authentication" OFF) +option(CURL_DISABLE_NEGOTIATE_AUTH "Disable negotiate authentication" OFF) mark_as_advanced(CURL_DISABLE_NEGOTIATE_AUTH) -option(CURL_DISABLE_AWS "disables AWS-SIG4" OFF) +option(CURL_DISABLE_AWS "Disable aws-sigv4" OFF) mark_as_advanced(CURL_DISABLE_AWS) -option(CURL_DISABLE_DICT "disables DICT" OFF) +option(CURL_DISABLE_DICT "Disable DICT" OFF) mark_as_advanced(CURL_DISABLE_DICT) -option(CURL_DISABLE_DOH "disables DNS-over-HTTPS" OFF) +option(CURL_DISABLE_DOH "Disable DNS-over-HTTPS" OFF) mark_as_advanced(CURL_DISABLE_DOH) -option(CURL_DISABLE_FILE "disables FILE" OFF) +option(CURL_DISABLE_FILE "Disable FILE" OFF) mark_as_advanced(CURL_DISABLE_FILE) -cmake_dependent_option(CURL_DISABLE_FORM_API "disables form api" OFF - "NOT CURL_DISABLE_MIME" ON) -mark_as_advanced(CURL_DISABLE_FORM_API) -option(CURL_DISABLE_FTP "disables FTP" OFF) +option(CURL_DISABLE_FTP "Disable FTP" OFF) mark_as_advanced(CURL_DISABLE_FTP) -option(CURL_DISABLE_GETOPTIONS "disables curl_easy_options API for existing options to curl_easy_setopt" OFF) +option(CURL_DISABLE_GETOPTIONS "Disable curl_easy_options API for existing options to curl_easy_setopt" OFF) mark_as_advanced(CURL_DISABLE_GETOPTIONS) -option(CURL_DISABLE_GOPHER "disables Gopher" OFF) +option(CURL_DISABLE_GOPHER "Disable Gopher" OFF) mark_as_advanced(CURL_DISABLE_GOPHER) -option(CURL_DISABLE_HSTS "disables HSTS support" OFF) +option(CURL_DISABLE_HEADERS_API "Disable headers-api support" OFF) +mark_as_advanced(CURL_DISABLE_HEADERS_API) +option(CURL_DISABLE_HSTS "Disable HSTS support" OFF) mark_as_advanced(CURL_DISABLE_HSTS) -option(CURL_DISABLE_HTTP "disables HTTP" OFF) +option(CURL_DISABLE_HTTP "Disable HTTP" OFF) mark_as_advanced(CURL_DISABLE_HTTP) -option(CURL_DISABLE_HTTP_AUTH "disables all HTTP authentication methods" OFF) +option(CURL_DISABLE_HTTP_AUTH "Disable all HTTP authentication methods" OFF) mark_as_advanced(CURL_DISABLE_HTTP_AUTH) -option(CURL_DISABLE_IMAP "disables IMAP" OFF) +option(CURL_DISABLE_IMAP "Disable IMAP" OFF) mark_as_advanced(CURL_DISABLE_IMAP) -option(CURL_DISABLE_LDAP "disables LDAP" OFF) +option(CURL_DISABLE_LDAP "Disable LDAP" OFF) mark_as_advanced(CURL_DISABLE_LDAP) -option(CURL_DISABLE_LDAPS "disables LDAPS" OFF) +option(CURL_DISABLE_LDAPS "Disable LDAPS" ${CURL_DISABLE_LDAP}) mark_as_advanced(CURL_DISABLE_LDAPS) -option(CURL_DISABLE_LIBCURL_OPTION "disables --libcurl option from the curl tool" OFF) +option(CURL_DISABLE_LIBCURL_OPTION "Disable --libcurl option from the curl tool" OFF) mark_as_advanced(CURL_DISABLE_LIBCURL_OPTION) -option(CURL_DISABLE_MIME "disables MIME support" OFF) +option(CURL_DISABLE_MIME "Disable MIME support" OFF) mark_as_advanced(CURL_DISABLE_MIME) -option(CURL_DISABLE_MQTT "disables MQTT" OFF) +cmake_dependent_option(CURL_DISABLE_FORM_API "Disable form-api" + OFF "NOT CURL_DISABLE_MIME" + ON) +mark_as_advanced(CURL_DISABLE_FORM_API) +option(CURL_DISABLE_MQTT "Disable MQTT" OFF) mark_as_advanced(CURL_DISABLE_MQTT) -option(CURL_DISABLE_NETRC "disables netrc parser" OFF) +option(CURL_DISABLE_BINDLOCAL "Disable local binding support" OFF) +mark_as_advanced(CURL_DISABLE_BINDLOCAL) +option(CURL_DISABLE_NETRC "Disable netrc parser" OFF) mark_as_advanced(CURL_DISABLE_NETRC) -option(CURL_DISABLE_NTLM "disables NTLM support" OFF) -mark_as_advanced(CURL_DISABLE_NTLM) -option(CURL_DISABLE_PARSEDATE "disables date parsing" OFF) +option(CURL_ENABLE_NTLM "Enable NTLM support" OFF) +mark_as_advanced(CURL_ENABLE_NTLM) +option(CURL_DISABLE_PARSEDATE "Disable date parsing" OFF) mark_as_advanced(CURL_DISABLE_PARSEDATE) -option(CURL_DISABLE_POP3 "disables POP3" OFF) +option(CURL_DISABLE_POP3 "Disable POP3" OFF) mark_as_advanced(CURL_DISABLE_POP3) -option(CURL_DISABLE_PROGRESS_METER "disables built-in progress meter" OFF) +option(CURL_DISABLE_PROGRESS_METER "Disable built-in progress meter" OFF) mark_as_advanced(CURL_DISABLE_PROGRESS_METER) -option(CURL_DISABLE_PROXY "disables proxy support" OFF) +option(CURL_DISABLE_PROXY "Disable proxy support" OFF) mark_as_advanced(CURL_DISABLE_PROXY) -option(CURL_DISABLE_RTSP "disables RTSP" OFF) +option(CURL_DISABLE_IPFS "Disable IPFS" OFF) +mark_as_advanced(CURL_DISABLE_IPFS) +option(CURL_DISABLE_RTSP "Disable RTSP" OFF) mark_as_advanced(CURL_DISABLE_RTSP) -option(CURL_DISABLE_SHUFFLE_DNS "disables shuffle DNS feature" OFF) +option(CURL_DISABLE_SHA512_256 "Disable SHA-512/256 hash algorithm" OFF) +mark_as_advanced(CURL_DISABLE_SHA512_256) +option(CURL_DISABLE_SHUFFLE_DNS "Disable shuffle DNS feature" OFF) mark_as_advanced(CURL_DISABLE_SHUFFLE_DNS) -option(CURL_DISABLE_SMB "disables SMB" OFF) -mark_as_advanced(CURL_DISABLE_SMB) -option(CURL_DISABLE_SMTP "disables SMTP" OFF) +option(CURL_ENABLE_SMB "Enable SMB" OFF) +mark_as_advanced(CURL_ENABLE_SMB) +option(CURL_DISABLE_SMTP "Disable SMTP" OFF) mark_as_advanced(CURL_DISABLE_SMTP) -option(CURL_DISABLE_SOCKETPAIR "disables use of socketpair for curl_multi_poll" OFF) +option(CURL_DISABLE_SOCKETPAIR "Disable use of socketpair for curl_multi_poll()" OFF) mark_as_advanced(CURL_DISABLE_SOCKETPAIR) -option(CURL_DISABLE_TELNET "disables Telnet" OFF) +option(CURL_DISABLE_WEBSOCKETS "Disable WebSocket" OFF) +mark_as_advanced(CURL_DISABLE_WEBSOCKETS) +option(CURL_DISABLE_TELNET "Disable Telnet" OFF) mark_as_advanced(CURL_DISABLE_TELNET) -option(CURL_DISABLE_TFTP "disables TFTP" OFF) +option(CURL_DISABLE_TFTP "Disable TFTP" OFF) mark_as_advanced(CURL_DISABLE_TFTP) -option(CURL_DISABLE_VERBOSE_STRINGS "disables verbose strings" OFF) +option(CURL_DISABLE_TYPECHECK "Disable curl_easy_setopt()/curl_easy_getinfo() type checking" OFF) +mark_as_advanced(CURL_DISABLE_TYPECHECK) +option(CURL_DISABLE_VERBOSE_STRINGS "Disable verbose strings" OFF) mark_as_advanced(CURL_DISABLE_VERBOSE_STRINGS) +option(CURL_DEBUG_GLOBAL_MEM "Debug curl_global_init_mem" OFF) +mark_as_advanced(CURL_DEBUG_GLOBAL_MEM) + +if(CURL_DEBUG_GLOBAL_MEM) + # Set it via the command-line to make it apply to the entire directory. + set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS "CURL_DEBUG_GLOBAL_MEM") +endif() +if(CURL_DISABLE_TYPECHECK) + # Set it via the command-line to make it apply to examples also. + set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS "CURL_DISABLE_TYPECHECK") +endif() + +if(CURL_DISABLE_HTTP) + set(CURL_DISABLE_ALTSVC ON) + set(CURL_DISABLE_HSTS ON) + set(CURL_DISABLE_IPFS ON) + set(CURL_DISABLE_RTSP ON) + set(CURL_DISABLE_WEBSOCKETS ON) +endif() # Corresponds to HTTP_ONLY in lib/curl_setup.h -option(HTTP_ONLY "disables all protocols except HTTP (This overrides all CURL_DISABLE_* options)" OFF) +option(HTTP_ONLY "Disable all protocols except HTTP (This overrides all CURL_DISABLE_* options)" OFF) mark_as_advanced(HTTP_ONLY) if(HTTP_ONLY) @@ -275,77 +540,72 @@ if(HTTP_ONLY) set(CURL_DISABLE_FTP ON) set(CURL_DISABLE_GOPHER ON) set(CURL_DISABLE_IMAP ON) + set(CURL_DISABLE_IPFS ON) set(CURL_DISABLE_LDAP ON) set(CURL_DISABLE_LDAPS ON) set(CURL_DISABLE_MQTT ON) set(CURL_DISABLE_POP3 ON) set(CURL_DISABLE_RTSP ON) - set(CURL_DISABLE_SMB ON) set(CURL_DISABLE_SMTP ON) set(CURL_DISABLE_TELNET ON) set(CURL_DISABLE_TFTP ON) + set(CURL_DISABLE_WEBSOCKETS ON) endif() -option(ENABLE_IPV6 "Define if you want to enable IPv6 support" ON) -mark_as_advanced(ENABLE_IPV6) -if(ENABLE_IPV6 AND NOT WIN32) - include(CheckStructHasMember) - check_struct_has_member("struct sockaddr_in6" sin6_addr "netinet/in.h" - HAVE_SOCKADDR_IN6_SIN6_ADDR) - check_struct_has_member("struct sockaddr_in6" sin6_scope_id "netinet/in.h" - HAVE_SOCKADDR_IN6_SIN6_SCOPE_ID) - if(NOT HAVE_SOCKADDR_IN6_SIN6_ADDR) - message(WARNING "struct sockaddr_in6 not available, disabling IPv6 support") - # Force the feature off as this name is used as guard macro... - set(ENABLE_IPV6 OFF - CACHE BOOL "Define if you want to enable IPv6 support" FORCE) - endif() - - if(CMAKE_SYSTEM_NAME STREQUAL "Darwin" AND NOT ENABLE_ARES) - set(use_core_foundation ON) - - find_library(SYSTEMCONFIGURATION_FRAMEWORK "SystemConfiguration") - if(NOT SYSTEMCONFIGURATION_FRAMEWORK) - message(FATAL_ERROR "SystemConfiguration framework not found") - endif() - - list(APPEND CURL_LIBS "-framework SystemConfiguration") - endif() +if(WINDOWS_STORE) + set(CURL_DISABLE_TELNET ON) # telnet code needs fixing to compile for UWP. endif() -if(USE_MANUAL) - #nroff is currently only used when USE_MANUAL is set, so we can prevent the warning of no *NROFF if USE_MANUAL is OFF (or not defined), by not even looking for NROFF.. - curl_nroff_check() -endif() +option(CURL_LINT "Run lint checks while building" OFF) + find_package(Perl) -cmake_dependent_option(ENABLE_MANUAL "to provide the built-in manual" - ON "NROFF_USEFUL;PERL_FOUND" - OFF) - -if(ENABLE_MANUAL) - set(USE_MANUAL ON) +if(PERL_EXECUTABLE) + add_custom_target(curl-ca-bundle + COMMENT "Generating a fresh ca-bundle.crt" VERBATIM USES_TERMINAL + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/mk-ca-bundle.pl" -b -l -u "lib/ca-bundle.crt" + DEPENDS "${PROJECT_SOURCE_DIR}/scripts/mk-ca-bundle.pl" + ) + add_custom_target(curl-ca-firefox + COMMENT "Generating a fresh ca-bundle.crt" VERBATIM USES_TERMINAL + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/firefox-db2pem.sh" "lib/ca-bundle.crt" + DEPENDS "${PROJECT_SOURCE_DIR}/scripts/firefox-db2pem.sh" + ) + add_custom_target(curl-lint + COMMENT "Running lint checks" VERBATIM USES_TERMINAL + WORKING_DIRECTORY ${PROJECT_SOURCE_DIR} + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/badwords-all" + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/checksrc-all.pl" + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/spacecheck.pl" + DEPENDS + "${PROJECT_SOURCE_DIR}/scripts/badwords-all" "${PROJECT_SOURCE_DIR}/scripts/badwords" + "${PROJECT_SOURCE_DIR}/scripts/checksrc-all.pl" "${PROJECT_SOURCE_DIR}/scripts/checksrc.pl" + "${PROJECT_SOURCE_DIR}/scripts/spacecheck.pl" + ) + if(CURL_LINT) + set_target_properties(curl-lint PROPERTIES EXCLUDE_FROM_ALL FALSE) + endif() endif() -if(CURL_STATIC_CRT) - set(CMAKE_MSVC_RUNTIME_LIBRARY "MultiThreaded$<$:Debug>") - set(CMAKE_C_FLAGS_RELEASE "${CMAKE_C_FLAGS_RELEASE} /MT") - set(CMAKE_C_FLAGS_DEBUG "${CMAKE_C_FLAGS_DEBUG} /MTd") -endif() +option(BUILD_LIBCURL_DOCS "Build libcurl man pages" ON) +option(BUILD_MISC_DOCS "Build misc man pages (e.g. curl-config and mk-ca-bundle)" ON) +option(ENABLE_CURL_MANUAL "Build the man page for curl and enable its -M/--manual option" ON) -# Disable warnings on Borland to avoid changing 3rd party code. -if(BORLAND) - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -w-") +if((ENABLE_CURL_MANUAL OR BUILD_LIBCURL_DOCS) AND NOT Perl_FOUND) + message(WARNING "Perl not found. Cannot build manuals.") endif() # If we are on AIX, do the _ALL_SOURCE magic -if(${CMAKE_SYSTEM_NAME} MATCHES AIX) - set(_ALL_SOURCE 1) +if(AIX OR CMAKE_SYSTEM_NAME STREQUAL "AIX") + set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS "_ALL_SOURCE") endif() # If we are on Haiku, make sure that the network library is brought in. -if(${CMAKE_SYSTEM_NAME} MATCHES Haiku) - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -lnetwork") +if(CMAKE_SYSTEM_NAME STREQUAL "Haiku") + list(APPEND CURL_NETWORK_AND_TIME_LIBS "network") +elseif(AMIGA) + list(APPEND CURL_NETWORK_AND_TIME_LIBS "net" "m" "atomic") + list(APPEND CMAKE_REQUIRED_LIBRARIES "net" "m" "atomic") endif() # Include all the necessary files for macros @@ -358,341 +618,597 @@ include(CheckSymbolExists) include(CheckTypeSize) include(CheckCSourceCompiles) -# On windows preload settings -if(WIN32) - list(APPEND CMAKE_REQUIRED_DEFINITIONS -D_WINSOCKAPI_=) - include(${CMAKE_CURRENT_SOURCE_DIR}/CMake/Platforms/WindowsCache.cmake) +option(_CURL_PREFILL "Fast-track known feature detection results (Windows, some Apple)" "${WIN32}") +mark_as_advanced(_CURL_PREFILL) +if(_CURL_PREFILL) + if(WIN32) + include("${CMAKE_CURRENT_SOURCE_DIR}/CMake/win32-cache.cmake") + elseif(UNIX) + include("${CMAKE_CURRENT_SOURCE_DIR}/CMake/unix-cache.cmake") + message(STATUS "Pre-filling feature detection results for UNIX") + endif() +elseif(WIN32) + message(STATUS "Pre-filling feature detection results disabled.") +elseif(APPLE) + set(HAVE_EVENTFD 0) + set(HAVE_GETPASS_R 0) + set(HAVE_WRITABLE_ARGV 1) + set(HAVE_SENDMMSG 0) +endif() + +if(AMIGA) + set(HAVE_GETADDRINFO 0) # Breaks the build when detected and used. +endif() +if(DOS OR AMIGA) + set(HAVE_TIME_T_UNSIGNED 1) +endif() + +if(NOT WIN32) + find_package(Threads) + if(CMAKE_USE_PTHREADS_INIT) + set(HAVE_THREADS_POSIX 1) + list(APPEND CURL_NETWORK_AND_TIME_LIBS Threads::Threads) + endif() endif() if(ENABLE_THREADED_RESOLVER) - find_package(Threads REQUIRED) - if(WIN32) - set(USE_THREADS_WIN32 ON) - else() - set(USE_THREADS_POSIX ${CMAKE_USE_PTHREADS_INIT}) - set(HAVE_PTHREAD_H ${CMAKE_USE_PTHREADS_INIT}) + if(NOT WIN32 AND NOT HAVE_THREADS_POSIX) + message(FATAL_ERROR "Threaded resolver requires POSIX Threads.") endif() - set(CURL_LIBS ${CURL_LIBS} ${CMAKE_THREAD_LIBS_INIT}) + set(USE_RESOLV_THREADED ON) +elseif(USE_ARES) + set(USE_RESOLV_ARES ON) endif() # Check for all needed libraries -check_library_exists_concat("socket" connect HAVE_LIBSOCKET) - -check_function_exists(gethostname HAVE_GETHOSTNAME) - -if(WIN32) - list(APPEND CURL_LIBS "ws2_32") - if(USE_LIBRTMP) - list(APPEND CURL_LIBS "winmm") +if(DOS) + if(WATT_ROOT) + set(USE_WATT32 ON) + # FIXME upstream: must specify the full path to avoid CMake converting "watt" to "watt.lib" + list(APPEND CURL_NETWORK_AND_TIME_LIBS "${WATT_ROOT}/lib/libwatt.a") + include_directories(SYSTEM "${WATT_ROOT}/inc") + list(APPEND CMAKE_REQUIRED_INCLUDES "${WATT_ROOT}/inc") + else() + message(FATAL_ERROR "Set WATT_ROOT variable to the absolute path to the root installation of Watt-32.") endif() - - # Matching logic used for Curl_win32_random() - if(MINGW) - check_c_source_compiles(" - #include <_mingw.h> - #if defined(__MINGW64_VERSION_MAJOR) - #error - #endif - int main(void) { - return 0; - }" - HAVE_MINGW_ORIGINAL) +elseif(AMIGA) + if(AMISSL_INCLUDE_DIR AND AMISSL_STUBS_LIBRARY AND AMISSL_AUTO_LIBRARY) + set(USE_AMISSL ON) + list(APPEND CMAKE_REQUIRED_INCLUDES "${AMISSL_INCLUDE_DIR}") + list(APPEND CMAKE_REQUIRED_LIBRARIES "${AMISSL_STUBS_LIBRARY}" "${AMISSL_AUTO_LIBRARY}") + set(OPENSSL_INCLUDE_DIR "${AMISSL_INCLUDE_DIR}") + set(OPENSSL_SSL_LIBRARY "${AMISSL_STUBS_LIBRARY}") + set(OPENSSL_CRYPTO_LIBRARY "${AMISSL_AUTO_LIBRARY}") + set(CURL_USE_OPENSSL ON) + set(CURL_CA_FALLBACK ON CACHE BOOL "") + list(PREPEND CURL_NETWORK_AND_TIME_LIBS "${AMISSL_STUBS_LIBRARY}" "${AMISSL_AUTO_LIBRARY}") + endif() +elseif(NOT WIN32 AND NOT APPLE) + check_library_exists("socket" "connect" "" HAVE_LIBSOCKET) + if(HAVE_LIBSOCKET) + list(PREPEND CURL_NETWORK_AND_TIME_LIBS "socket") endif() endif() -# check SSL libraries +option(ENABLE_IPV6 "Enable IPv6 support" ON) +mark_as_advanced(ENABLE_IPV6) +if(ENABLE_IPV6) + include(CheckStructHasMember) + if(WIN32) + check_struct_has_member("struct sockaddr_in6" "sin6_scope_id" "winsock2.h;ws2tcpip.h" HAVE_SOCKADDR_IN6_SIN6_SCOPE_ID) + else() + check_struct_has_member("struct sockaddr_in6" "sin6_scope_id" "netinet/in.h" HAVE_SOCKADDR_IN6_SIN6_SCOPE_ID) + check_struct_has_member("struct sockaddr_in6" "sin6_addr" "netinet/in.h" HAVE_SOCKADDR_IN6_SIN6_ADDR) + if(NOT HAVE_SOCKADDR_IN6_SIN6_ADDR) + if(NOT DOS AND NOT AMIGA) + message(WARNING "struct sockaddr_in6 not available, disabling IPv6 support") + endif() + set(ENABLE_IPV6 OFF CACHE BOOL "Enable IPv6 support" FORCE) # Force the feature off as we use this name as guard macro + endif() + + if(CMAKE_SYSTEM_NAME STREQUAL "Darwin" AND NOT ENABLE_ARES) + set(_use_core_foundation_and_core_services ON) + + find_library(SYSTEMCONFIGURATION_FRAMEWORK NAMES "SystemConfiguration") + mark_as_advanced(SYSTEMCONFIGURATION_FRAMEWORK) + if(NOT SYSTEMCONFIGURATION_FRAMEWORK) + message(FATAL_ERROR "SystemConfiguration framework not found") + endif() + list(APPEND CURL_LIBS "-framework SystemConfiguration") + endif() + endif() +endif() +if(ENABLE_IPV6) + set(USE_IPV6 ON) +endif() + +# Check SSL libraries option(CURL_ENABLE_SSL "Enable SSL support" ON) -if(APPLE) - cmake_dependent_option(CURL_USE_SECTRANSP "Enable Apple OS native SSL/TLS" OFF CURL_ENABLE_SSL OFF) +if(CURL_DEFAULT_SSL_BACKEND) + set(_valid_default_ssl_backend FALSE) endif() + if(WIN32) - cmake_dependent_option(CURL_USE_SCHANNEL "Enable Windows native SSL/TLS" OFF CURL_ENABLE_SSL OFF) - cmake_dependent_option(CURL_WINDOWS_SSPI "Use windows libraries to allow NTLM authentication without OpenSSL" ON - CURL_USE_SCHANNEL OFF) + cmake_dependent_option(CURL_USE_SCHANNEL "Enable Windows native SSL/TLS (Schannel)" OFF CURL_ENABLE_SSL OFF) + option(CURL_WINDOWS_SSPI "Enable SSPI on Windows" ${CURL_USE_SCHANNEL}) +else() + set(CURL_USE_SCHANNEL OFF) + set(CURL_WINDOWS_SSPI OFF) endif() cmake_dependent_option(CURL_USE_MBEDTLS "Enable mbedTLS for SSL/TLS" OFF CURL_ENABLE_SSL OFF) -cmake_dependent_option(CURL_USE_BEARSSL "Enable BearSSL for SSL/TLS" OFF CURL_ENABLE_SSL OFF) cmake_dependent_option(CURL_USE_WOLFSSL "Enable wolfSSL for SSL/TLS" OFF CURL_ENABLE_SSL OFF) -cmake_dependent_option(CURL_USE_GNUTLS "Enable GNUTLS for SSL/TLS" OFF CURL_ENABLE_SSL OFF) +cmake_dependent_option(CURL_USE_GNUTLS "Enable GnuTLS for SSL/TLS" OFF CURL_ENABLE_SSL OFF) +cmake_dependent_option(CURL_USE_RUSTLS "Enable Rustls for SSL/TLS (experimental)" OFF CURL_ENABLE_SSL OFF) -set(openssl_default ON) -if(WIN32 OR CURL_USE_SECTRANSP OR CURL_USE_SCHANNEL OR CURL_USE_MBEDTLS OR CURL_USE_WOLFSSL) - set(openssl_default OFF) +if(WIN32 OR + CURL_USE_SCHANNEL OR + CURL_USE_MBEDTLS OR + CURL_USE_WOLFSSL OR + CURL_USE_GNUTLS OR + CURL_USE_RUSTLS) + set(_openssl_default OFF) +else() + set(_openssl_default ON) endif() -cmake_dependent_option(CURL_USE_OPENSSL "Use OpenSSL code. Experimental" ${openssl_default} CURL_ENABLE_SSL OFF) +cmake_dependent_option(CURL_USE_OPENSSL "Enable OpenSSL for SSL/TLS" ${_openssl_default} CURL_ENABLE_SSL OFF) option(CURL_DISABLE_OPENSSL_AUTO_LOAD_CONFIG "Disable automatic loading of OpenSSL configuration" OFF) -count_true(enabled_ssl_options_count +curl_count_true(_enabled_ssl_options_count CURL_USE_SCHANNEL - CURL_USE_SECTRANSP CURL_USE_OPENSSL CURL_USE_MBEDTLS - CURL_USE_BEARSSL CURL_USE_WOLFSSL + CURL_USE_GNUTLS + CURL_USE_RUSTLS ) -if(enabled_ssl_options_count GREATER "1") +if(_enabled_ssl_options_count GREATER 1) set(CURL_WITH_MULTI_SSL ON) +elseif(_enabled_ssl_options_count EQUAL 0) + set(CURL_DISABLE_HSTS ON) endif() if(CURL_USE_SCHANNEL) - set(SSL_ENABLED ON) - set(USE_SCHANNEL ON) # Windows native SSL/TLS support - set(USE_WINDOWS_SSPI ON) # CURL_USE_SCHANNEL implies CURL_WINDOWS_SSPI + if(WINDOWS_STORE) + message(FATAL_ERROR "UWP does not support Schannel.") + endif() + set(_ssl_enabled ON) + set(USE_SCHANNEL ON) # Windows native SSL/TLS support + set(USE_WINDOWS_SSPI ON) # CURL_USE_SCHANNEL requires CURL_WINDOWS_SSPI + + if(CURL_DEFAULT_SSL_BACKEND AND CURL_DEFAULT_SSL_BACKEND STREQUAL "schannel") + set(_valid_default_ssl_backend TRUE) + endif() endif() -if(CURL_WINDOWS_SSPI) +if(CURL_WINDOWS_SSPI AND NOT WINDOWS_STORE) set(USE_WINDOWS_SSPI ON) endif() -if(CURL_USE_SECTRANSP) - set(use_core_foundation ON) +if(APPLE) + option(USE_APPLE_SECTRUST "Use Apple OS-native certificate verification" OFF) + if(USE_APPLE_SECTRUST) + if(NOT CURL_USE_OPENSSL AND NOT CURL_USE_GNUTLS) + message(FATAL_ERROR "Apple SecTrust is only supported with Openssl/GnuTLS") + endif() + find_library(SECURITY_FRAMEWORK NAMES "Security") + mark_as_advanced(SECURITY_FRAMEWORK) + if(NOT SECURITY_FRAMEWORK) + message(FATAL_ERROR "Security framework not found") + endif() + list(APPEND CURL_LIBS "-framework Security") - find_library(SECURITY_FRAMEWORK "Security") - if(NOT SECURITY_FRAMEWORK) - message(FATAL_ERROR "Security framework not found") + set(_use_core_foundation_and_core_services ON) + message(STATUS "Apple OS-native certificate verification enabled") endif() - - set(SSL_ENABLED ON) - set(USE_SECTRANSP ON) - list(APPEND CURL_LIBS "-framework Security") +else() + set(USE_APPLE_SECTRUST OFF) endif() -if(use_core_foundation) - find_library(COREFOUNDATION_FRAMEWORK "CoreFoundation") +if(_use_core_foundation_and_core_services) + find_library(COREFOUNDATION_FRAMEWORK NAMES "CoreFoundation") + mark_as_advanced(COREFOUNDATION_FRAMEWORK) if(NOT COREFOUNDATION_FRAMEWORK) - message(FATAL_ERROR "CoreFoundation framework not found") + message(FATAL_ERROR "CoreFoundation framework not found") endif() - list(APPEND CURL_LIBS "-framework CoreFoundation") + + find_library(CORESERVICES_FRAMEWORK NAMES "CoreServices") + mark_as_advanced(CORESERVICES_FRAMEWORK) + if(NOT CORESERVICES_FRAMEWORK) + message(FATAL_ERROR "CoreServices framework not found") + endif() + list(APPEND CURL_LIBS "-framework CoreServices") endif() if(CURL_USE_OPENSSL) find_package(OpenSSL REQUIRED) - set(SSL_ENABLED ON) + set(_ssl_enabled ON) set(USE_OPENSSL ON) - # Depend on OpenSSL via imported targets if supported by the running - # version of CMake. This allows our dependents to get our dependencies - # transitively. - if(NOT CMAKE_VERSION VERSION_LESS 3.4) - list(APPEND CURL_LIBS OpenSSL::SSL OpenSSL::Crypto) - else() - list(APPEND CURL_LIBS ${OPENSSL_LIBRARIES}) - include_directories(${OPENSSL_INCLUDE_DIR}) - endif() + # Depend on OpenSSL via imported targets. This allows our dependents to + # get our dependencies transitively. + list(APPEND CURL_LIBS OpenSSL::SSL OpenSSL::Crypto) - if(WIN32) - list(APPEND CURL_LIBS "ws2_32") - if(NOT HAVE_MINGW_ORIGINAL) - list(APPEND CURL_LIBS "bcrypt") # for OpenSSL/LibreSSL + if(CURL_DEFAULT_SSL_BACKEND AND CURL_DEFAULT_SSL_BACKEND STREQUAL "openssl") + set(_valid_default_ssl_backend TRUE) + endif() + set(_curl_ca_bundle_supported TRUE) + + cmake_push_check_state() + list(APPEND CMAKE_REQUIRED_LIBRARIES OpenSSL::SSL OpenSSL::Crypto) + if(NOT DEFINED HAVE_AWSLC) + check_symbol_exists("OPENSSL_IS_AWSLC" "openssl/base.h" HAVE_AWSLC) + endif() + if(NOT DEFINED HAVE_BORINGSSL) + check_symbol_exists("OPENSSL_IS_BORINGSSL" "openssl/base.h" HAVE_BORINGSSL) + endif() + if(NOT DEFINED HAVE_LIBRESSL) + check_symbol_exists("LIBRESSL_VERSION_NUMBER" "openssl/opensslv.h" HAVE_LIBRESSL) + endif() + cmake_pop_check_state() + + if(HAVE_AWSLC OR HAVE_BORINGSSL) + if(NOT MSVC AND NOT ANDROID) # AWS-LC/BoringSSL MSVC builds use native Windows threads + find_package(Threads) + if(CMAKE_USE_PTHREADS_INIT) + set(HAVE_THREADS_POSIX_BORINGSSL 1) + list(APPEND CURL_NETWORK_AND_TIME_LIBS Threads::Threads) + list(APPEND CMAKE_REQUIRED_LIBRARIES Threads::Threads) + elseif(OPENSSL_USE_STATIC_LIBS) + message(WARNING "AWS-LC/BoringSSL requires POSIX Threads.") + endif() + endif() + if(OPENSSL_USE_STATIC_LIBS AND CMAKE_C_COMPILER_ID MATCHES "Clang") + list(APPEND CURL_LIBS "stdc++") + list(APPEND CMAKE_REQUIRED_LIBRARIES "stdc++") endif() endif() - set(CMAKE_REQUIRED_INCLUDES ${OPENSSL_INCLUDE_DIR}) - if(NOT DEFINED HAVE_BORINGSSL) - check_symbol_exists(OPENSSL_IS_BORINGSSL "openssl/base.h" HAVE_BORINGSSL) - endif() - if(NOT DEFINED HAVE_AWSLC) - check_symbol_exists(OPENSSL_IS_AWSLC "openssl/base.h" HAVE_AWSLC) + if(USE_AMISSL) + set(_openssl "AmiSSL") + elseif(HAVE_AWSLC) + set(_openssl "AWS-LC") + elseif(HAVE_BORINGSSL) + if(BORINGSSL_VERSION) + set(CURL_BORINGSSL_VERSION "\"${BORINGSSL_VERSION}\"") + endif() + set(_openssl "BoringSSL") + elseif(HAVE_LIBRESSL) + set(_openssl "LibreSSL") + else() + set(_openssl "OpenSSL") endif() endif() if(CURL_USE_MBEDTLS) - find_package(MbedTLS REQUIRED) - set(SSL_ENABLED ON) + find_package(MbedTLS MODULE REQUIRED) + if(MBEDTLS_VERSION VERSION_LESS 3.2.0) + message(FATAL_ERROR "mbedTLS v3.2.0 or newer is required.") + endif() + set(_ssl_enabled ON) set(USE_MBEDTLS ON) - list(APPEND CURL_LIBS ${MBEDTLS_LIBRARIES}) - include_directories(${MBEDTLS_INCLUDE_DIRS}) -endif() + list(APPEND CURL_LIBS CURL::mbedtls) -if(CURL_USE_BEARSSL) - find_package(BearSSL REQUIRED) - set(SSL_ENABLED ON) - set(USE_BEARSSL ON) - list(APPEND CURL_LIBS ${BEARSSL_LIBRARY}) - include_directories(${BEARSSL_INCLUDE_DIRS}) + if(CURL_DEFAULT_SSL_BACKEND AND CURL_DEFAULT_SSL_BACKEND STREQUAL "mbedtls") + set(_valid_default_ssl_backend TRUE) + endif() + set(_curl_ca_bundle_supported TRUE) + + if(MBEDTLS_VERSION VERSION_GREATER_EQUAL 4.0.0) + set(HAVE_MBEDTLS_DES_CRYPT_ECB 0) # pre-fill detection result + endif() + if(NOT DEFINED HAVE_MBEDTLS_DES_CRYPT_ECB) + cmake_push_check_state() + list(APPEND CMAKE_REQUIRED_LIBRARIES CURL::mbedtls) + check_function_exists("mbedtls_des_crypt_ecb" HAVE_MBEDTLS_DES_CRYPT_ECB) # in mbedTLS <4 + cmake_pop_check_state() + endif() endif() if(CURL_USE_WOLFSSL) - find_package(WolfSSL REQUIRED) - set(SSL_ENABLED ON) + find_package(WolfSSL MODULE REQUIRED) + set(_ssl_enabled ON) set(USE_WOLFSSL ON) - list(APPEND CURL_LIBS ${WolfSSL_LIBRARIES}) - include_directories(${WolfSSL_INCLUDE_DIRS}) + list(APPEND CURL_LIBS CURL::wolfssl) + + if(CURL_DEFAULT_SSL_BACKEND AND CURL_DEFAULT_SSL_BACKEND STREQUAL "wolfssl") + set(_valid_default_ssl_backend TRUE) + endif() + set(_curl_ca_bundle_supported TRUE) + + if(USE_OPENSSL AND WOLFSSL_VERSION VERSION_LESS 5.7.6) + message(FATAL_ERROR "wolfSSL 5.7.6 or newer is required to coexist with OpenSSL.") + endif() + + set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS "WOLFSSL_OPTIONS_IGNORE_SYS") endif() if(CURL_USE_GNUTLS) - set(SSL_ENABLED ON) - set(USE_GNUTLS ON) + find_package(GnuTLS MODULE REQUIRED) + list(APPEND CURL_LIBS CURL::gnutls) + find_package(Nettle MODULE REQUIRED) + list(APPEND CURL_LIBS CURL::nettle) + set(_ssl_enabled ON) + set(USE_GNUTLS ON) + + if(CURL_DEFAULT_SSL_BACKEND AND CURL_DEFAULT_SSL_BACKEND STREQUAL "gnutls") + set(_valid_default_ssl_backend TRUE) + endif() + set(_curl_ca_bundle_supported TRUE) + + if(NOT DEFINED HAVE_GNUTLS_SRP AND NOT CURL_DISABLE_SRP) + cmake_push_check_state() + list(APPEND CMAKE_REQUIRED_LIBRARIES CURL::gnutls) + # In GnuTLS 3.8.0 (2023-02-10) and upper, this check always succeeds. + # Detecting actual TLS-SRP support needs poking the API at runtime. + check_symbol_exists("gnutls_srp_verifier" "gnutls/gnutls.h" HAVE_GNUTLS_SRP) + cmake_pop_check_state() + endif() +endif() + +if(CURL_USE_RUSTLS) + find_package(Rustls MODULE REQUIRED) + set(_ssl_enabled ON) + set(USE_RUSTLS ON) + list(APPEND CURL_LIBS CURL::rustls) + + if(NOT DEFINED HAVE_RUSTLS_SUPPORTED_HPKE) + if(RUSTLS_VERSION AND RUSTLS_VERSION VERSION_GREATER_EQUAL 0.15) + set(HAVE_RUSTLS_SUPPORTED_HPKE TRUE) + elseif(NOT RUSTLS_VERSION) + cmake_push_check_state() + list(APPEND CMAKE_REQUIRED_LIBRARIES CURL::rustls) + check_symbol_exists("rustls_supported_hpke" "rustls.h" HAVE_RUSTLS_SUPPORTED_HPKE) + cmake_pop_check_state() + endif() + endif() + if(NOT HAVE_RUSTLS_SUPPORTED_HPKE) + message(FATAL_ERROR "rustls-ffi library does not provide rustls_supported_hpke function. Required version is 0.15 or newer.") + endif() + + if(CURL_DEFAULT_SSL_BACKEND AND CURL_DEFAULT_SSL_BACKEND STREQUAL "rustls") + set(_valid_default_ssl_backend TRUE) + endif() + set(_curl_ca_bundle_supported TRUE) +endif() + +if(CURL_DEFAULT_SSL_BACKEND AND NOT _valid_default_ssl_backend) + message(FATAL_ERROR "CURL_DEFAULT_SSL_BACKEND '${CURL_DEFAULT_SSL_BACKEND}' not enabled.") endif() # Keep ZLIB detection after TLS detection, -# and before calling openssl_check_symbol_exists(). +# and before calling curl_openssl_check_exists(). set(HAVE_LIBZ OFF) -set(USE_ZLIB OFF) -optional_dependency(ZLIB) +curl_dependency_option(CURL_ZLIB ZLIB "ZLIB") if(ZLIB_FOUND) set(HAVE_LIBZ ON) - set(USE_ZLIB ON) - - # Depend on ZLIB via imported targets if supported by the running - # version of CMake. This allows our dependents to get our dependencies - # transitively. - if(NOT CMAKE_VERSION VERSION_LESS 3.4) - list(APPEND CURL_LIBS ZLIB::ZLIB) - else() - list(APPEND CURL_LIBS ${ZLIB_LIBRARIES}) - include_directories(${ZLIB_INCLUDE_DIRS}) - endif() - list(APPEND CMAKE_REQUIRED_INCLUDES ${ZLIB_INCLUDE_DIRS}) + # Depend on ZLIB via imported targets. This allows our dependents to + # get our dependencies transitively. + list(APPEND CURL_LIBS ZLIB::ZLIB) endif() -option(CURL_BROTLI "Set to ON to enable building curl with brotli support." OFF) set(HAVE_BROTLI OFF) -if(CURL_BROTLI) - find_package(Brotli REQUIRED) - if(BROTLI_FOUND) - set(HAVE_BROTLI ON) - set(CURL_LIBS "${BROTLI_LIBRARIES};${CURL_LIBS}") # For 'ld' linker. Emulate `list(PREPEND ...)` to stay compatible with \n") - endforeach() - - set(_SRC_STRING - " - ${_INCLUDE_STRING} - int main(int argc, char ** argv) - { - BerValue *bvp = NULL; - BerElement *bep = ber_init(bvp); - ber_free(bep, 1); - return 0; - }" - ) - list(APPEND CMAKE_REQUIRED_DEFINITIONS -DLDAP_DEPRECATED=1) - list(APPEND CMAKE_REQUIRED_LIBRARIES ${CMAKE_LDAP_LIB}) - if(HAVE_LIBLBER) - list(APPEND CMAKE_REQUIRED_LIBRARIES ${CMAKE_LBER_LIB}) - endif() - check_c_source_compiles("${_SRC_STRING}" NOT_NEED_LBER_H) - unset(CMAKE_REQUIRED_LIBRARIES) - - if(NOT_NEED_LBER_H) - set(NEED_LBER_H OFF) - else() - set(CURL_TEST_DEFINES "${CURL_TEST_DEFINES} -DNEED_LBER_H") + if(NOT CURL_DISABLE_LDAPS) + set(HAVE_LDAP_SSL ON) endif() + else() + message(STATUS "LDAP not found. CURL_DISABLE_LDAP set ON") + set(CURL_DISABLE_LDAP ON CACHE BOOL "" FORCE) endif() + cmake_pop_check_state() endif() endif() @@ -792,407 +1262,464 @@ if(CURL_DISABLE_LDAP) endif() endif() -if(NOT CURL_DISABLE_LDAPS) - check_include_file_concat("ldap_ssl.h" HAVE_LDAP_SSL_H) -endif() - -# Check for idn2 -option(USE_LIBIDN2 "Use libidn2 for IDN support" ON) -if(USE_LIBIDN2) - check_library_exists_concat("idn2" idn2_lookup_ul HAVE_LIBIDN2) -else() - set(HAVE_LIBIDN2 OFF) -endif() - if(WIN32) option(USE_WIN32_IDN "Use WinIDN for IDN support" OFF) if(USE_WIN32_IDN) - list(APPEND CURL_LIBS "normaliz") + list(APPEND CURL_LIBS "normaliz") # for IdnToAscii(), IdnToUnicode() + endif() +else() + set(USE_WIN32_IDN OFF) +endif() + +if(APPLE) + option(USE_APPLE_IDN "Use Apple built-in IDN support" OFF) + if(USE_APPLE_IDN) + cmake_push_check_state() + list(APPEND CMAKE_REQUIRED_LIBRARIES "icucore") + check_symbol_exists("uidna_openUTS46" "unicode/uidna.h" HAVE_APPLE_IDN) + cmake_pop_check_state() + if(HAVE_APPLE_IDN) + list(APPEND CURL_LIBS "icucore" "iconv") + else() + set(USE_APPLE_IDN OFF) + endif() + endif() +else() + set(USE_APPLE_IDN OFF) +endif() + +# Check for libidn2 +option(USE_LIBIDN2 "Use libidn2 for IDN support" ON) +set(HAVE_IDN2_H OFF) +set(HAVE_LIBIDN2 OFF) +if(USE_LIBIDN2 AND NOT USE_APPLE_IDN AND NOT USE_WIN32_IDN) + find_package(Libidn2 MODULE) + if(LIBIDN2_FOUND) + list(PREPEND CURL_LIBS CURL::libidn2) + set(HAVE_IDN2_H 1) + set(HAVE_LIBIDN2 1) endif() endif() -#libpsl -option(CURL_USE_LIBPSL "Use libPSL" ON) +# libpsl +option(CURL_USE_LIBPSL "Use libpsl" ON) mark_as_advanced(CURL_USE_LIBPSL) set(USE_LIBPSL OFF) - if(CURL_USE_LIBPSL) - find_package(LibPSL) - if(LIBPSL_FOUND) - list(APPEND CURL_LIBS ${LIBPSL_LIBRARY}) - list(APPEND CMAKE_REQUIRED_INCLUDES "${LIBPSL_INCLUDE_DIR}") - include_directories("${LIBPSL_INCLUDE_DIR}") - set(USE_LIBPSL ON) - endif() + find_package(Libpsl MODULE REQUIRED) + list(APPEND CURL_LIBS CURL::libpsl) + set(USE_LIBPSL ON) endif() -#libSSH2 -option(CURL_USE_LIBSSH2 "Use libSSH2" ON) +# libssh2 +option(CURL_USE_LIBSSH2 "Use libssh2" ON) mark_as_advanced(CURL_USE_LIBSSH2) set(USE_LIBSSH2 OFF) - if(CURL_USE_LIBSSH2) - find_package(LibSSH2) + find_package(Libssh2 MODULE) if(LIBSSH2_FOUND) - list(APPEND CURL_LIBS ${LIBSSH2_LIBRARY}) - list(APPEND CMAKE_REQUIRED_INCLUDES "${LIBSSH2_INCLUDE_DIR}") - include_directories("${LIBSSH2_INCLUDE_DIR}") + list(PREPEND CURL_LIBS CURL::libssh2) # keep it before TLS-crypto, compression set(USE_LIBSSH2 ON) endif() endif() # libssh -option(CURL_USE_LIBSSH "Use libSSH" OFF) +option(CURL_USE_LIBSSH "Use libssh" OFF) mark_as_advanced(CURL_USE_LIBSSH) if(NOT USE_LIBSSH2 AND CURL_USE_LIBSSH) - find_package(libssh CONFIG) - if(libssh_FOUND) - message(STATUS "Found libssh ${libssh_VERSION}") - # Use imported target for include and library paths. - list(APPEND CURL_LIBS ssh) - set(USE_LIBSSH ON) - endif() + find_package(Libssh MODULE REQUIRED) + list(PREPEND CURL_LIBS CURL::libssh) # keep it before TLS-crypto, compression + set(USE_LIBSSH ON) endif() -option(CURL_USE_GSSAPI "Use GSSAPI implementation (right now only Heimdal is supported with CMake build)" OFF) +option(CURL_USE_GSASL "Use libgsasl" OFF) +mark_as_advanced(CURL_USE_GSASL) +if(CURL_USE_GSASL) + find_package(Libgsasl MODULE REQUIRED) + list(APPEND CURL_LIBS CURL::libgsasl) + set(USE_GSASL ON) +endif() + +option(CURL_USE_GSSAPI "Use GSSAPI implementation" OFF) mark_as_advanced(CURL_USE_GSSAPI) if(CURL_USE_GSSAPI) - find_package(GSS) + find_package(GSS MODULE) set(HAVE_GSSAPI ${GSS_FOUND}) if(GSS_FOUND) + list(APPEND CURL_LIBS CURL::gss) - message(STATUS "Found ${GSS_FLAVOUR} GSSAPI version: \"${GSS_VERSION}\"") - - list(APPEND CMAKE_REQUIRED_INCLUDES ${GSS_INCLUDE_DIR}) - check_include_file_concat("gssapi/gssapi.h" HAVE_GSSAPI_GSSAPI_H) - check_include_file_concat("gssapi/gssapi_generic.h" HAVE_GSSAPI_GSSAPI_GENERIC_H) - check_include_file_concat("gssapi/gssapi_krb5.h" HAVE_GSSAPI_GSSAPI_KRB5_H) - - if(GSS_FLAVOUR STREQUAL "Heimdal") - set(HAVE_GSSHEIMDAL ON) - else() # MIT - set(HAVE_GSSMIT ON) - set(_INCLUDE_LIST "") - if(HAVE_GSSAPI_GSSAPI_H) - list(APPEND _INCLUDE_LIST "gssapi/gssapi.h") - endif() - if(HAVE_GSSAPI_GSSAPI_GENERIC_H) - list(APPEND _INCLUDE_LIST "gssapi/gssapi_generic.h") - endif() - if(HAVE_GSSAPI_GSSAPI_KRB5_H) - list(APPEND _INCLUDE_LIST "gssapi/gssapi_krb5.h") - endif() - - string(REPLACE ";" " " _COMPILER_FLAGS_STR "${GSS_COMPILER_FLAGS}") - string(REPLACE ";" " " _LINKER_FLAGS_STR "${GSS_LINKER_FLAGS}") - - foreach(_dir ${GSS_LINK_DIRECTORIES}) - set(_LINKER_FLAGS_STR "${_LINKER_FLAGS_STR} -L\"${_dir}\"") - endforeach() - - if(NOT DEFINED HAVE_GSS_C_NT_HOSTBASED_SERVICE) - set(CMAKE_REQUIRED_FLAGS "${_COMPILER_FLAGS_STR} ${_LINKER_FLAGS_STR}") - set(CMAKE_REQUIRED_LIBRARIES ${GSS_LIBRARIES}) - check_symbol_exists("GSS_C_NT_HOSTBASED_SERVICE" ${_INCLUDE_LIST} HAVE_GSS_C_NT_HOSTBASED_SERVICE) - unset(CMAKE_REQUIRED_LIBRARIES) - endif() - if(NOT HAVE_GSS_C_NT_HOSTBASED_SERVICE) - set(HAVE_OLD_GSSMIT ON) - endif() + get_target_property(_gss_flavor CURL::gss INTERFACE_CURL_GSS_FLAVOR) + if(_gss_flavor STREQUAL "GNU") + set(HAVE_GSSGNU 1) + elseif(GSS_VERSION) # MIT + set(CURL_KRB5_VERSION "\"${GSS_VERSION}\"") endif() - - include_directories(${GSS_INCLUDE_DIR}) - link_directories(${GSS_LINK_DIRECTORIES}) - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} ${GSS_COMPILER_FLAGS}") - string(REPLACE ";" " " GSS_LINKER_FLAGS "${GSS_LINKER_FLAGS}") - set(CMAKE_SHARED_LINKER_FLAGS "${CMAKE_SHARED_LINKER_FLAGS} ${GSS_LINKER_FLAGS}") - set(CMAKE_EXE_LINKER_FLAGS "${CMAKE_EXE_LINKER_FLAGS} ${GSS_LINKER_FLAGS}") - set(CMAKE_STATIC_LINKER_FLAGS "${CMAKE_STATIC_LINKER_FLAGS} ${GSS_LINKER_FLAGS}") - list(APPEND CURL_LIBS ${GSS_LIBRARIES}) - else() - message(WARNING "GSSAPI support has been requested but no supporting libraries found. Skipping.") + message(WARNING "GSSAPI has been requested, but no supporting libraries found. Skipping.") endif() endif() -option(ENABLE_UNIX_SOCKETS "Define if you want Unix domain sockets support" ON) +# libbacktrace +option(CURL_USE_LIBBACKTRACE "Use libbacktrace. Requires debug-enabled build and DWARF debug information." OFF) +if(CURL_USE_LIBBACKTRACE) + if(NOT ENABLE_DEBUG) + message(FATAL_ERROR "libbacktrace requires debug-enabled build for TrackMemory") + endif() + if(NOT CMAKE_BUILD_TYPE MATCHES "(Debug|RelWithDebInfo)") + message(FATAL_ERROR "libbacktrace requires debug information") + endif() + find_package(Libbacktrace MODULE REQUIRED) + list(APPEND CURL_LIBS CURL::libbacktrace) + set(USE_BACKTRACE ON) +endif() + +# libuv +option(CURL_USE_LIBUV "Use libuv for event-based tests" OFF) +if(CURL_USE_LIBUV) + if(NOT ENABLE_DEBUG) + message(FATAL_ERROR "Using libuv without debug support enabled is useless") + endif() + find_package(Libuv MODULE REQUIRED) + list(APPEND CURL_LIBS CURL::libuv) + set(USE_LIBUV ON) + set(HAVE_UV_H ON) +endif() + +option(ENABLE_UNIX_SOCKETS "Enable Unix domain sockets support" ON) if(ENABLE_UNIX_SOCKETS) - include(CheckStructHasMember) - if(WIN32) - set(USE_UNIX_SOCKETS ON) + if(WIN32 OR DOS) + set(USE_UNIX_SOCKETS 1) else() - check_struct_has_member("struct sockaddr_un" sun_path "sys/un.h" USE_UNIX_SOCKETS) + include(CheckStructHasMember) + check_struct_has_member("struct sockaddr_un" "sun_path" "sys/un.h" USE_UNIX_SOCKETS) endif() else() + set(USE_UNIX_SOCKETS 0) unset(USE_UNIX_SOCKETS CACHE) endif() - # # CA handling # -set(CURL_CA_BUNDLE "auto" CACHE STRING - "Path to the CA bundle. Set 'none' to disable or 'auto' for auto-detection. Defaults to 'auto'.") -set(CURL_CA_FALLBACK OFF CACHE BOOL - "Set ON to use built-in CA store of TLS backend. Defaults to OFF") -set(CURL_CA_PATH "auto" CACHE STRING - "Location of default CA path. Set 'none' to disable or 'auto' for auto-detection. Defaults to 'auto'.") - -if("${CURL_CA_BUNDLE}" STREQUAL "") - message(FATAL_ERROR "Invalid value of CURL_CA_BUNDLE. Use 'none', 'auto' or file path.") -elseif("${CURL_CA_BUNDLE}" STREQUAL "none") - unset(CURL_CA_BUNDLE CACHE) -elseif("${CURL_CA_BUNDLE}" STREQUAL "auto") - unset(CURL_CA_BUNDLE CACHE) - if(NOT CMAKE_CROSSCOMPILING) - set(CURL_CA_BUNDLE_AUTODETECT TRUE) - endif() +option(CURL_CA_NATIVE "Use native CA store" OFF) +if(CURL_CA_NATIVE) + set(_curl_disable_ca_search_default ON) else() - set(CURL_CA_BUNDLE_SET TRUE) + set(_curl_disable_ca_search_default OFF) endif() -if("${CURL_CA_PATH}" STREQUAL "") - message(FATAL_ERROR "Invalid value of CURL_CA_PATH. Use 'none', 'auto' or directory path.") -elseif("${CURL_CA_PATH}" STREQUAL "none") - unset(CURL_CA_PATH CACHE) -elseif("${CURL_CA_PATH}" STREQUAL "auto") - unset(CURL_CA_PATH CACHE) - if(NOT CMAKE_CROSSCOMPILING) - set(CURL_CA_PATH_AUTODETECT TRUE) +if(_curl_ca_bundle_supported) + set(_ca_opt_desc "Set 'none' to disable or 'auto' for auto-detection. Defaults to 'auto'.") + + set(CURL_CA_BUNDLE "auto" CACHE + STRING "Absolute path to the CA bundle. ${_ca_opt_desc}") + set(CURL_CA_FALLBACK OFF CACHE + BOOL "Use built-in CA store of OpenSSL. Defaults to OFF") + set(CURL_CA_PATH "auto" CACHE + STRING "Absolute path to a directory containing CA certificates stored individually. ${_ca_opt_desc}") + set(CURL_CA_EMBED "" CACHE + STRING "Absolute path to the CA bundle to embed in the curl tool.") + + if(CURL_CA_FALLBACK AND NOT CURL_USE_OPENSSL) + message(FATAL_ERROR "CURL_CA_FALLBACK only works with OpenSSL.") endif() -else() - set(CURL_CA_PATH_SET TRUE) -endif() -if(CURL_CA_BUNDLE_SET AND CURL_CA_PATH_AUTODETECT) - # Skip autodetection of unset CA path because CA bundle is set explicitly -elseif(CURL_CA_PATH_SET AND CURL_CA_BUNDLE_AUTODETECT) - # Skip autodetection of unset CA bundle because CA path is set explicitly -elseif(CURL_CA_PATH_AUTODETECT OR CURL_CA_BUNDLE_AUTODETECT) - # first try autodetecting a CA bundle, then a CA path + if(CURL_CA_BUNDLE STREQUAL "") + message(FATAL_ERROR "Invalid value of CURL_CA_BUNDLE. Use 'none', 'auto' or file path.") + elseif(CURL_CA_BUNDLE STREQUAL "none") + unset(CURL_CA_BUNDLE CACHE) + elseif(CURL_CA_BUNDLE STREQUAL "auto") + unset(CURL_CA_BUNDLE CACHE) + if(NOT CMAKE_CROSSCOMPILING AND NOT WIN32 AND NOT USE_APPLE_SECTRUST AND NOT CURL_CA_NATIVE) + set(_curl_ca_bundle_autodetect TRUE) + endif() + else() + set(CURL_CA_BUNDLE_SET TRUE) + endif() + mark_as_advanced(CURL_CA_BUNDLE_SET) - if(CURL_CA_BUNDLE_AUTODETECT) - set(SEARCH_CA_BUNDLE_PATHS - /etc/ssl/certs/ca-certificates.crt - /etc/pki/tls/certs/ca-bundle.crt - /usr/share/ssl/certs/ca-bundle.crt - /usr/local/share/certs/ca-root-nss.crt - /etc/ssl/cert.pem) + if(CURL_CA_PATH STREQUAL "") + message(FATAL_ERROR "Invalid value of CURL_CA_PATH. Use 'none', 'auto' or directory path.") + elseif(CURL_CA_PATH STREQUAL "none") + unset(CURL_CA_PATH CACHE) + elseif(CURL_CA_PATH STREQUAL "auto") + unset(CURL_CA_PATH CACHE) + if(NOT CMAKE_CROSSCOMPILING AND NOT WIN32 AND NOT USE_APPLE_SECTRUST AND NOT CURL_CA_NATIVE) + set(_curl_ca_path_autodetect TRUE) + endif() + else() + set(CURL_CA_PATH_SET TRUE) + endif() + mark_as_advanced(CURL_CA_PATH_SET) - foreach(SEARCH_CA_BUNDLE_PATH ${SEARCH_CA_BUNDLE_PATHS}) - if(EXISTS "${SEARCH_CA_BUNDLE_PATH}") - message(STATUS "Found CA bundle: ${SEARCH_CA_BUNDLE_PATH}") - set(CURL_CA_BUNDLE "${SEARCH_CA_BUNDLE_PATH}" CACHE STRING - "Path to the CA bundle. Set 'none' to disable or 'auto' for auto-detection. Defaults to 'auto'.") - set(CURL_CA_BUNDLE_SET TRUE CACHE BOOL "Path to the CA bundle has been set") - break() + if(CURL_CA_BUNDLE_SET AND _curl_ca_path_autodetect) + # Skip auto-detection of unset CA path because CA bundle is set explicitly + elseif(CURL_CA_PATH_SET AND _curl_ca_bundle_autodetect) + # Skip auto-detection of unset CA bundle because CA path is set explicitly + elseif(_curl_ca_bundle_autodetect OR _curl_ca_path_autodetect) + # First try auto-detecting a CA bundle, then a CA path + + if(_curl_ca_bundle_autodetect) + foreach(_search_ca_bundle_path IN ITEMS + "/etc/ssl/certs/ca-certificates.crt" + "/etc/pki/tls/certs/ca-bundle.crt" + "/usr/share/ssl/certs/ca-bundle.crt" + "/usr/local/share/certs/ca-root-nss.crt" + "/etc/ssl/cert.pem") + if(EXISTS "${_search_ca_bundle_path}") + message(STATUS "Found CA bundle: ${_search_ca_bundle_path}") + set(CURL_CA_BUNDLE "${_search_ca_bundle_path}" CACHE + STRING "Absolute path to the CA bundle. ${_ca_opt_desc}") + set(CURL_CA_BUNDLE_SET TRUE CACHE BOOL "Absolute path to the CA bundle has been set") + break() + endif() + endforeach() + endif() + + if(_curl_ca_path_autodetect AND NOT CURL_CA_PATH_SET) + set(_search_ca_path "/etc/ssl/certs") + file(GLOB _curl_ca_files_found "${_search_ca_path}/[0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f].0") + if(_curl_ca_files_found) + unset(_curl_ca_files_found) + message(STATUS "Found CA path: ${_search_ca_path}") + set(CURL_CA_PATH "${_search_ca_path}" CACHE + STRING "Absolute path to a directory containing CA certificates stored individually. ${_ca_opt_desc}") + set(CURL_CA_PATH_SET TRUE CACHE BOOL "Absolute path to the CA bundle has been set") endif() - endforeach() + endif() endif() - if(CURL_CA_PATH_AUTODETECT AND (NOT CURL_CA_PATH_SET)) - if(EXISTS "/etc/ssl/certs") - set(CURL_CA_PATH "/etc/ssl/certs" CACHE STRING - "Location of default CA path. Set 'none' to disable or 'auto' for auto-detection. Defaults to 'auto'.") - set(CURL_CA_PATH_SET TRUE CACHE BOOL "Path to the CA bundle has been set") + set(CURL_CA_EMBED_SET FALSE) + if(BUILD_CURL_EXE AND NOT CURL_CA_EMBED STREQUAL "") + if(EXISTS "${CURL_CA_EMBED}") + set(CURL_CA_EMBED_SET TRUE) + message(STATUS "Found CA bundle to embed: ${CURL_CA_EMBED}") + else() + message(FATAL_ERROR "CA bundle to embed is missing: '${CURL_CA_EMBED}'") endif() endif() endif() -if(CURL_CA_PATH_SET AND NOT USE_OPENSSL AND NOT USE_MBEDTLS) - message(STATUS - "CA path only supported by OpenSSL, GnuTLS or mbed TLS. " - "Set CURL_CA_PATH=none or enable one of those TLS backends.") +if(WIN32) + option(CURL_DISABLE_CA_SEARCH "Disable unsafe CA bundle search in PATH on Windows" ${_curl_disable_ca_search_default}) + option(CURL_CA_SEARCH_SAFE "Enable safe CA bundle search (within the curl tool directory) on Windows" OFF) endif() +set(CURL_INCLUDES "") + # Check for header files -if(NOT UNIX) - check_include_file_concat("windows.h" HAVE_WINDOWS_H) - check_include_file_concat("ws2tcpip.h" HAVE_WS2TCPIP_H) - check_include_file_concat("winsock2.h" HAVE_WINSOCK2_H) +if(WIN32) + list(APPEND CURL_INCLUDES "winsock2.h") + list(APPEND CURL_INCLUDES "ws2tcpip.h") + + if(HAVE_WIN32_WINNT AND HAVE_WIN32_WINNT LESS 0x0600) + # Windows Vista is required for freeaddrinfo, getaddrinfo, if_nametoindex + message(FATAL_ERROR "Building for Windows Vista or newer is required.") + endif() endif() -check_include_file_concat("inttypes.h" HAVE_INTTYPES_H) -check_include_file_concat("sys/filio.h" HAVE_SYS_FILIO_H) -check_include_file_concat("sys/ioctl.h" HAVE_SYS_IOCTL_H) -check_include_file_concat("sys/param.h" HAVE_SYS_PARAM_H) -check_include_file_concat("sys/poll.h" HAVE_SYS_POLL_H) -check_include_file_concat("sys/resource.h" HAVE_SYS_RESOURCE_H) -check_include_file_concat("sys/select.h" HAVE_SYS_SELECT_H) -check_include_file_concat("sys/socket.h" HAVE_SYS_SOCKET_H) -check_include_file_concat("sys/sockio.h" HAVE_SYS_SOCKIO_H) -check_include_file_concat("sys/stat.h" HAVE_SYS_STAT_H) -check_include_file_concat("sys/time.h" HAVE_SYS_TIME_H) -check_include_file_concat("sys/types.h" HAVE_SYS_TYPES_H) -check_include_file_concat("sys/un.h" HAVE_SYS_UN_H) -check_include_file_concat("sys/utime.h" HAVE_SYS_UTIME_H) -check_include_file_concat("sys/xattr.h" HAVE_SYS_XATTR_H) -check_include_file_concat("arpa/inet.h" HAVE_ARPA_INET_H) -check_include_file_concat("arpa/tftp.h" HAVE_ARPA_TFTP_H) -check_include_file_concat("fcntl.h" HAVE_FCNTL_H) -check_include_file_concat("idn2.h" HAVE_IDN2_H) -check_include_file_concat("ifaddrs.h" HAVE_IFADDRS_H) -check_include_file_concat("io.h" HAVE_IO_H) -check_include_file_concat("libgen.h" HAVE_LIBGEN_H) -check_include_file_concat("locale.h" HAVE_LOCALE_H) -check_include_file_concat("net/if.h" HAVE_NET_IF_H) -check_include_file_concat("netdb.h" HAVE_NETDB_H) -check_include_file_concat("netinet/in.h" HAVE_NETINET_IN_H) -check_include_file_concat("netinet/tcp.h" HAVE_NETINET_TCP_H) +if(NOT WIN32) + list(APPEND CURL_INCLUDES "sys/socket.h") +endif() +if(NOT WIN32 OR MINGW) + list(APPEND CURL_INCLUDES "sys/time.h") +endif() + +# Detect headers + +# Use check_include_file_concat_curl() for headers required by subsequent +# check_include_file_concat_curl() or check_symbol_exists() detections. +# Order for these is significant. +check_include_file("sys/eventfd.h" HAVE_SYS_EVENTFD_H) +check_include_file("sys/filio.h" HAVE_SYS_FILIO_H) +check_include_file("sys/ioctl.h" HAVE_SYS_IOCTL_H) +check_include_file("sys/param.h" HAVE_SYS_PARAM_H) +check_include_file("sys/poll.h" HAVE_SYS_POLL_H) +check_include_file("sys/resource.h" HAVE_SYS_RESOURCE_H) +check_include_file_concat_curl("sys/select.h" HAVE_SYS_SELECT_H) +check_include_file("sys/sockio.h" HAVE_SYS_SOCKIO_H) +check_include_file_concat_curl("sys/types.h" HAVE_SYS_TYPES_H) +check_include_file("sys/un.h" HAVE_SYS_UN_H) +check_include_file_concat_curl("sys/utime.h" HAVE_SYS_UTIME_H) # sys/types.h (AmigaOS) + +check_include_file_concat_curl("arpa/inet.h" HAVE_ARPA_INET_H) +check_include_file("dirent.h" HAVE_DIRENT_H) +check_include_file("fcntl.h" HAVE_FCNTL_H) +check_include_file_concat_curl("ifaddrs.h" HAVE_IFADDRS_H) +check_include_file("io.h" HAVE_IO_H) +check_include_file_concat_curl("libgen.h" HAVE_LIBGEN_H) check_include_file("linux/tcp.h" HAVE_LINUX_TCP_H) +check_include_file("locale.h" HAVE_LOCALE_H) +check_include_file_concat_curl("net/if.h" HAVE_NET_IF_H) # sys/select.h (e.g. MS-DOS/Watt-32) +check_include_file_concat_curl("netdb.h" HAVE_NETDB_H) +check_include_file_concat_curl("netinet/in.h" HAVE_NETINET_IN_H) +check_include_file("netinet/in6.h" HAVE_NETINET_IN6_H) +check_include_file_concat_curl("netinet/tcp.h" HAVE_NETINET_TCP_H) # sys/types.h (e.g. Cygwin) netinet/in.h +check_include_file_concat_curl("netinet/udp.h" HAVE_NETINET_UDP_H) # sys/types.h (e.g. Cygwin) +check_include_file("poll.h" HAVE_POLL_H) +check_include_file("pwd.h" HAVE_PWD_H) +check_include_file("stdatomic.h" HAVE_STDATOMIC_H) +check_include_file("stdbool.h" HAVE_STDBOOL_H) +check_include_file("strings.h" HAVE_STRINGS_H) +check_include_file("stropts.h" HAVE_STROPTS_H) +check_include_file("termio.h" HAVE_TERMIO_H) +check_include_file("termios.h" HAVE_TERMIOS_H) +check_include_file_concat_curl("unistd.h" HAVE_UNISTD_H) +check_include_file("utime.h" HAVE_UTIME_H) -check_include_file_concat("poll.h" HAVE_POLL_H) -check_include_file_concat("pwd.h" HAVE_PWD_H) -check_include_file_concat("setjmp.h" HAVE_SETJMP_H) -check_include_file_concat("signal.h" HAVE_SIGNAL_H) -check_include_file_concat("stdatomic.h" HAVE_STDATOMIC_H) -check_include_file_concat("stdbool.h" HAVE_STDBOOL_H) -check_include_file_concat("stdint.h" HAVE_STDINT_H) -check_include_file_concat("stdlib.h" HAVE_STDLIB_H) -check_include_file_concat("string.h" HAVE_STRING_H) -check_include_file_concat("strings.h" HAVE_STRINGS_H) -check_include_file_concat("stropts.h" HAVE_STROPTS_H) -check_include_file_concat("termio.h" HAVE_TERMIO_H) -check_include_file_concat("termios.h" HAVE_TERMIOS_H) -check_include_file_concat("time.h" HAVE_TIME_H) -check_include_file_concat("unistd.h" HAVE_UNISTD_H) -check_include_file_concat("utime.h" HAVE_UTIME_H) +if(AMIGA) + check_include_file_concat_curl("proto/bsdsocket.h" HAVE_PROTO_BSDSOCKET_H) +endif() -check_include_file_concat("stddef.h" HAVE_STDDEF_H) +# Pass these detection results to curl_internal_test() for use in CurlTests.c +# Add here all feature flags referenced from CurlTests.c +foreach(_variable IN ITEMS + HAVE_STDATOMIC_H + HAVE_STDBOOL_H + HAVE_STROPTS_H + HAVE_SYS_IOCTL_H + HAVE_SYS_TYPES_H + HAVE_UNISTD_H +) + if(${_variable}) + list(APPEND CURL_TEST_DEFINES "-D${_variable}") + endif() +endforeach() -check_type_size(size_t SIZEOF_SIZE_T) -check_type_size(ssize_t SIZEOF_SSIZE_T) -check_type_size("long long" SIZEOF_LONG_LONG) -check_type_size("long" SIZEOF_LONG) -check_type_size("int" SIZEOF_INT) -check_type_size("__int64" SIZEOF___INT64) -check_type_size("time_t" SIZEOF_TIME_T) +check_type_size("size_t" SIZEOF_SIZE_T) +check_type_size("ssize_t" SIZEOF_SSIZE_T) +check_type_size("long" SIZEOF_LONG) +check_type_size("int" SIZEOF_INT) +check_type_size("__int64" SIZEOF___INT64) +check_type_size("time_t" SIZEOF_TIME_T) +check_type_size("suseconds_t" SIZEOF_SUSECONDS_T) if(NOT HAVE_SIZEOF_SSIZE_T) if(SIZEOF_LONG EQUAL SIZEOF_SIZE_T) - set(ssize_t long) + set(ssize_t "long") endif() if(NOT ssize_t AND SIZEOF___INT64 EQUAL SIZEOF_SIZE_T) - set(ssize_t __int64) + set(ssize_t "__int64") endif() endif() # off_t is sized later, after the HAVE_FILE_OFFSET_BITS test -if(HAVE_SIZEOF_LONG_LONG) - set(HAVE_LONGLONG 1) -endif() - -if(NOT CMAKE_CROSSCOMPILING) - find_file(RANDOM_FILE urandom /dev) - mark_as_advanced(RANDOM_FILE) +if(SIZEOF_SUSECONDS_T) + set(HAVE_SUSECONDS_T 1) endif() # Check for some functions that are used + +# Apply to all feature checks if(WIN32) - set(CMAKE_REQUIRED_LIBRARIES ws2_32) + list(APPEND CMAKE_REQUIRED_LIBRARIES "ws2_32") + if(NOT WINDOWS_STORE) + list(APPEND CMAKE_REQUIRED_LIBRARIES "iphlpapi") + endif() elseif(HAVE_LIBSOCKET) - set(CMAKE_REQUIRED_LIBRARIES socket) + list(APPEND CMAKE_REQUIRED_LIBRARIES "socket") +elseif(DOS) + list(APPEND CMAKE_REQUIRED_LIBRARIES "${WATT_ROOT}/lib/libwatt.a") endif() -check_symbol_exists(fchmod "${CURL_INCLUDES}" HAVE_FCHMOD) -check_symbol_exists(basename "${CURL_INCLUDES}" HAVE_BASENAME) -check_symbol_exists(socket "${CURL_INCLUDES}" HAVE_SOCKET) -check_symbol_exists(socketpair "${CURL_INCLUDES}" HAVE_SOCKETPAIR) -check_symbol_exists(recv "${CURL_INCLUDES}" HAVE_RECV) -check_symbol_exists(send "${CURL_INCLUDES}" HAVE_SEND) -check_symbol_exists(sendmsg "${CURL_INCLUDES}" HAVE_SENDMSG) -check_symbol_exists(select "${CURL_INCLUDES}" HAVE_SELECT) -check_symbol_exists(strdup "${CURL_INCLUDES}" HAVE_STRDUP) -check_symbol_exists(strtok_r "${CURL_INCLUDES}" HAVE_STRTOK_R) -check_symbol_exists(strcasecmp "${CURL_INCLUDES}" HAVE_STRCASECMP) -check_symbol_exists(stricmp "${CURL_INCLUDES}" HAVE_STRICMP) -check_symbol_exists(strcmpi "${CURL_INCLUDES}" HAVE_STRCMPI) -check_symbol_exists(alarm "${CURL_INCLUDES}" HAVE_ALARM) -check_symbol_exists(getppid "${CURL_INCLUDES}" HAVE_GETPPID) -check_symbol_exists(utimes "${CURL_INCLUDES}" HAVE_UTIMES) +check_function_exists("accept4" HAVE_ACCEPT4) +check_function_exists("fnmatch" HAVE_FNMATCH) +check_symbol_exists("basename" "${CURL_INCLUDES};string.h" HAVE_BASENAME) # libgen.h unistd.h +check_symbol_exists("opendir" "dirent.h" HAVE_OPENDIR) +check_function_exists("poll" HAVE_POLL) # poll.h +check_symbol_exists("socket" "${CURL_INCLUDES}" HAVE_SOCKET) # winsock2.h sys/socket.h +check_symbol_exists("socketpair" "${CURL_INCLUDES}" HAVE_SOCKETPAIR) # sys/socket.h +check_symbol_exists("recv" "${CURL_INCLUDES}" HAVE_RECV) # proto/bsdsocket.h sys/types.h sys/socket.h +check_symbol_exists("send" "${CURL_INCLUDES}" HAVE_SEND) # proto/bsdsocket.h sys/types.h sys/socket.h +check_function_exists("sendmsg" HAVE_SENDMSG) +check_function_exists("sendmmsg" HAVE_SENDMMSG) +check_symbol_exists("select" "${CURL_INCLUDES}" HAVE_SELECT) # proto/bsdsocket.h sys/select.h sys/socket.h +check_symbol_exists("memrchr" "string.h" HAVE_MEMRCHR) +check_symbol_exists("alarm" "unistd.h" HAVE_ALARM) +check_symbol_exists("fcntl" "fcntl.h" HAVE_FCNTL) +check_function_exists("getppid" HAVE_GETPPID) +check_function_exists("utimes" HAVE_UTIMES) -check_symbol_exists(gettimeofday "${CURL_INCLUDES}" HAVE_GETTIMEOFDAY) -check_symbol_exists(closesocket "${CURL_INCLUDES}" HAVE_CLOSESOCKET) -check_symbol_exists(sigsetjmp "${CURL_INCLUDES}" HAVE_SIGSETJMP) -check_symbol_exists(getpass_r "${CURL_INCLUDES}" HAVE_GETPASS_R) -check_symbol_exists(getpwuid "${CURL_INCLUDES}" HAVE_GETPWUID) -check_symbol_exists(getpwuid_r "${CURL_INCLUDES}" HAVE_GETPWUID_R) -check_symbol_exists(geteuid "${CURL_INCLUDES}" HAVE_GETEUID) -check_symbol_exists(utime "${CURL_INCLUDES}" HAVE_UTIME) -check_symbol_exists(gmtime_r "${CURL_INCLUDES}" HAVE_GMTIME_R) +check_function_exists("gettimeofday" HAVE_GETTIMEOFDAY) # sys/time.h +check_symbol_exists("closesocket" "${CURL_INCLUDES}" HAVE_CLOSESOCKET) # winsock2.h +check_symbol_exists("sigsetjmp" "setjmp.h" HAVE_SIGSETJMP) +check_function_exists("getpass_r" HAVE_GETPASS_R) +check_function_exists("getpwuid" HAVE_GETPWUID) +check_function_exists("getpwuid_r" HAVE_GETPWUID_R) +check_function_exists("geteuid" HAVE_GETEUID) +check_function_exists("utime" HAVE_UTIME) +check_symbol_exists("gmtime_r" "stdlib.h;time.h" HAVE_GMTIME_R) +check_symbol_exists("localtime_r" "stdlib.h;time.h" HAVE_LOCALTIME_R) -check_symbol_exists(gethostbyname_r "${CURL_INCLUDES}" HAVE_GETHOSTBYNAME_R) +check_symbol_exists("gethostbyname_r" "netdb.h" HAVE_GETHOSTBYNAME_R) +check_symbol_exists("gethostname" "${CURL_INCLUDES}" HAVE_GETHOSTNAME) # winsock2.h unistd.h proto/bsdsocket.h -check_symbol_exists(signal "${CURL_INCLUDES}" HAVE_SIGNAL) -check_symbol_exists(strtoll "${CURL_INCLUDES}" HAVE_STRTOLL) -check_symbol_exists(strerror_r "${CURL_INCLUDES}" HAVE_STRERROR_R) -check_symbol_exists(siginterrupt "${CURL_INCLUDES}" HAVE_SIGINTERRUPT) -check_symbol_exists(getaddrinfo "${CURL_INCLUDES}" HAVE_GETADDRINFO) -if(WIN32) - set(HAVE_GETADDRINFO_THREADSAFE ${HAVE_GETADDRINFO}) -endif() -check_symbol_exists(freeaddrinfo "${CURL_INCLUDES}" HAVE_FREEADDRINFO) -check_symbol_exists(pipe "${CURL_INCLUDES}" HAVE_PIPE) -check_symbol_exists(ftruncate "${CURL_INCLUDES}" HAVE_FTRUNCATE) -check_symbol_exists(getpeername "${CURL_INCLUDES}" HAVE_GETPEERNAME) -check_symbol_exists(getsockname "${CURL_INCLUDES}" HAVE_GETSOCKNAME) -check_symbol_exists(if_nametoindex "${CURL_INCLUDES}" HAVE_IF_NAMETOINDEX) -check_symbol_exists(getrlimit "${CURL_INCLUDES}" HAVE_GETRLIMIT) -check_symbol_exists(setlocale "${CURL_INCLUDES}" HAVE_SETLOCALE) -check_symbol_exists(setmode "${CURL_INCLUDES}" HAVE_SETMODE) -check_symbol_exists(setrlimit "${CURL_INCLUDES}" HAVE_SETRLIMIT) +check_symbol_exists("signal" "signal.h" HAVE_SIGNAL) +check_symbol_exists("strerror_r" "stdlib.h;string.h" HAVE_STRERROR_R) +check_symbol_exists("sigaction" "signal.h" HAVE_SIGACTION) +check_symbol_exists("siginterrupt" "signal.h" HAVE_SIGINTERRUPT) +check_symbol_exists("getaddrinfo" "${CURL_INCLUDES};stdlib.h;string.h" HAVE_GETADDRINFO) # ws2tcpip.h sys/socket.h netdb.h +check_symbol_exists("getifaddrs" "${CURL_INCLUDES};stdlib.h" HAVE_GETIFADDRS) # ifaddrs.h +check_symbol_exists("freeaddrinfo" "${CURL_INCLUDES}" HAVE_FREEADDRINFO) # ws2tcpip.h sys/socket.h netdb.h +check_function_exists("pipe" HAVE_PIPE) +check_function_exists("eventfd" HAVE_EVENTFD) +check_symbol_exists("getpeername" "${CURL_INCLUDES}" HAVE_GETPEERNAME) # winsock2.h unistd.h proto/bsdsocket.h +check_symbol_exists("getsockname" "${CURL_INCLUDES}" HAVE_GETSOCKNAME) # winsock2.h unistd.h proto/bsdsocket.h +check_function_exists("getrlimit" HAVE_GETRLIMIT) +check_function_exists("setlocale" HAVE_SETLOCALE) +check_function_exists("setrlimit" HAVE_SETRLIMIT) -if(NOT MSVC OR (MSVC_VERSION GREATER_EQUAL 1900)) - # earlier MSVC compilers had faulty snprintf implementations - check_symbol_exists(snprintf "stdio.h" HAVE_SNPRINTF) -endif() -check_function_exists(mach_absolute_time HAVE_MACH_ABSOLUTE_TIME) -check_symbol_exists(inet_ntop "${CURL_INCLUDES}" HAVE_INET_NTOP) -if(MSVC AND (MSVC_VERSION LESS_EQUAL 1600)) - set(HAVE_INET_NTOP OFF) -endif() -check_symbol_exists(inet_pton "${CURL_INCLUDES}" HAVE_INET_PTON) - -check_symbol_exists(fsetxattr "${CURL_INCLUDES}" HAVE_FSETXATTR) -if(HAVE_FSETXATTR) - foreach(CURL_TEST HAVE_FSETXATTR_5 HAVE_FSETXATTR_6) - curl_internal_test(${CURL_TEST}) - endforeach() +if(APPLE) + check_function_exists("mach_absolute_time" HAVE_MACH_ABSOLUTE_TIME) +else() + # Apple platforms do not offer pipe2(), but the iPhone Simulator-specific + # /usr/lib/system/libsystem_sim_kernel.dylib exports it. To avoid false + # detection, omit this feature check for Apple targets. + check_function_exists("pipe2" HAVE_PIPE2) endif() -set(CMAKE_EXTRA_INCLUDE_FILES "sys/socket.h") -check_type_size("sa_family_t" SIZEOF_SA_FAMILY_T) -set(HAVE_SA_FAMILY_T ${HAVE_SIZEOF_SA_FAMILY_T}) -set(CMAKE_EXTRA_INCLUDE_FILES "") +if(NOT WIN32) + check_function_exists("if_nametoindex" HAVE_IF_NAMETOINDEX) # net/if.h + check_function_exists("realpath" HAVE_REALPATH) + check_function_exists("sched_yield" HAVE_SCHED_YIELD) -set(CMAKE_EXTRA_INCLUDE_FILES "ws2def.h") -check_type_size("ADDRESS_FAMILY" SIZEOF_ADDRESS_FAMILY) -set(HAVE_ADDRESS_FAMILY ${HAVE_SIZEOF_ADDRESS_FAMILY}) -set(CMAKE_EXTRA_INCLUDE_FILES "") + check_symbol_exists("inet_ntop" "${CURL_INCLUDES};stdlib.h;string.h" HAVE_INET_NTOP) # arpa/inet.h netinet/in.h sys/socket.h + check_symbol_exists("inet_pton" "${CURL_INCLUDES};stdlib.h;string.h" HAVE_INET_PTON) # arpa/inet.h netinet/in.h sys/socket.h + check_symbol_exists("strcasecmp" "string.h" HAVE_STRCASECMP) + check_symbol_exists("stricmp" "string.h" HAVE_STRICMP) + check_symbol_exists("strcmpi" "string.h" HAVE_STRCMPI) -# sigaction and sigsetjmp are special. Use special mechanism for -# detecting those, but only if previous attempt failed. -if(HAVE_SIGNAL_H) - check_symbol_exists(sigaction "signal.h" HAVE_SIGACTION) -endif() - -if(NOT HAVE_SIGSETJMP) - if(HAVE_SETJMP_H) - check_symbol_exists(sigsetjmp "setjmp.h" HAVE_MACRO_SIGSETJMP) - if(HAVE_MACRO_SIGSETJMP) - set(HAVE_SIGSETJMP 1) - endif() + check_symbol_exists("memset_s" "string.h" HAVE_MEMSET_S) + if(NOT HAVE_MEMSET_S) + check_function_exists("memset_explicit" HAVE_MEMSET_EXPLICIT) endif() endif() -# If there is no stricmp(), do not allow LDAP to parse URLs -if(NOT HAVE_STRICMP) - set(HAVE_LDAP_URL_PARSE 1) +if(AMIGA) + check_symbol_exists("CloseSocket" "${CURL_INCLUDES}" HAVE_CLOSESOCKET_CAMEL) # sys/socket.h proto/bsdsocket.h endif() +if(NOT _ssl_enabled) + check_symbol_exists("arc4random" "${CURL_INCLUDES};stdlib.h" HAVE_ARC4RANDOM) +endif() + +check_symbol_exists("fsetxattr" "sys/xattr.h" HAVE_FSETXATTR) +if(HAVE_FSETXATTR) + curl_internal_test(HAVE_FSETXATTR_5) + curl_internal_test(HAVE_FSETXATTR_6) +endif() + +cmake_push_check_state() +if(NOT WIN32) + list(APPEND CMAKE_EXTRA_INCLUDE_FILES "sys/socket.h") + check_type_size("sa_family_t" SIZEOF_SA_FAMILY_T) + set(HAVE_SA_FAMILY_T ${HAVE_SIZEOF_SA_FAMILY_T}) +endif() +cmake_pop_check_state() + # Do curl specific tests -foreach(CURL_TEST +foreach(_curl_test IN ITEMS HAVE_FCNTL_O_NONBLOCK HAVE_IOCTLSOCKET HAVE_IOCTLSOCKET_CAMEL @@ -1201,150 +1728,125 @@ foreach(CURL_TEST HAVE_IOCTL_FIONBIO HAVE_IOCTL_SIOCGIFADDR HAVE_SETSOCKOPT_SO_NONBLOCK - TIME_WITH_SYS_TIME - HAVE_O_NONBLOCK HAVE_GETHOSTBYNAME_R_3 HAVE_GETHOSTBYNAME_R_5 HAVE_GETHOSTBYNAME_R_6 - HAVE_GETHOSTBYNAME_R_3_REENTRANT - HAVE_GETHOSTBYNAME_R_5_REENTRANT - HAVE_GETHOSTBYNAME_R_6_REENTRANT - HAVE_IN_ADDR_T HAVE_BOOL_T STDC_HEADERS - HAVE_FILE_OFFSET_BITS - HAVE_VARIADIC_MACROS_C99 - HAVE_VARIADIC_MACROS_GCC HAVE_ATOMIC - ) - curl_internal_test(${CURL_TEST}) -endforeach() - -if(HAVE_FILE_OFFSET_BITS) - set(_FILE_OFFSET_BITS 64) - set(CMAKE_REQUIRED_FLAGS "-D_FILE_OFFSET_BITS=64") -endif() -check_type_size("off_t" SIZEOF_OFF_T) - -# include this header to get the type -set(CMAKE_REQUIRED_INCLUDES "${CURL_SOURCE_DIR}/include") -set(CMAKE_EXTRA_INCLUDE_FILES "curl/system.h") -check_type_size("curl_off_t" SIZEOF_CURL_OFF_T) -set(CMAKE_EXTRA_INCLUDE_FILES "curl/curl.h") -check_type_size("curl_socket_t" SIZEOF_CURL_SOCKET_T) -set(CMAKE_EXTRA_INCLUDE_FILES "") - -if(WIN32) - # detect actual value of _WIN32_WINNT and store as HAVE_WIN32_WINNT - curl_internal_test(HAVE_WIN32_WINNT) - if(HAVE_WIN32_WINNT) - string(REGEX MATCH ".*_WIN32_WINNT=0x[0-9a-fA-F]+" OUTPUT "${OUTPUT}") - string(REGEX REPLACE ".*_WIN32_WINNT=" "" HAVE_WIN32_WINNT "${OUTPUT}") - message(STATUS "Found _WIN32_WINNT=${HAVE_WIN32_WINNT}") - endif() - # avoid storing HAVE_WIN32_WINNT in CMake cache - unset(HAVE_WIN32_WINNT CACHE) -endif() - -set(CMAKE_REQUIRED_FLAGS) - -option(ENABLE_WEBSOCKETS "Set to ON to enable EXPERIMENTAL websockets" OFF) - -if(ENABLE_WEBSOCKETS) - if(${SIZEOF_CURL_OFF_T} GREATER "4") - set(USE_WEBSOCKETS ON) - else() - message(WARNING "curl_off_t is too small to enable WebSockets") - endif() -endif() - -foreach(CURL_TEST - HAVE_GLIBC_STRERROR_R - HAVE_POSIX_STRERROR_R - ) - curl_internal_test(${CURL_TEST}) +) + curl_internal_test(${_curl_test}) endforeach() # Check for reentrant -foreach(CURL_TEST +cmake_push_check_state() +list(APPEND CMAKE_REQUIRED_DEFINITIONS "-D_REENTRANT") +foreach(_curl_test IN ITEMS HAVE_GETHOSTBYNAME_R_3 HAVE_GETHOSTBYNAME_R_5 HAVE_GETHOSTBYNAME_R_6) - if(NOT ${CURL_TEST}) - if(${CURL_TEST}_REENTRANT) - set(NEED_REENTRANT 1) - endif() + curl_internal_test(${_curl_test}_REENTRANT) + if(NOT ${_curl_test} AND ${_curl_test}_REENTRANT) + set(NEED_REENTRANT 1) endif() endforeach() +cmake_pop_check_state() if(NEED_REENTRANT) - foreach(CURL_TEST + foreach(_curl_test IN ITEMS HAVE_GETHOSTBYNAME_R_3 HAVE_GETHOSTBYNAME_R_5 HAVE_GETHOSTBYNAME_R_6) - set(${CURL_TEST} 0) - if(${CURL_TEST}_REENTRANT) - set(${CURL_TEST} 1) + set(${_curl_test} 0) + if(${_curl_test}_REENTRANT) + set(${_curl_test} 1) endif() endforeach() endif() -# Check clock_gettime(CLOCK_MONOTONIC, x) support -curl_internal_test(HAVE_CLOCK_GETTIME_MONOTONIC) +cmake_push_check_state() +list(APPEND CMAKE_REQUIRED_DEFINITIONS "-D_FILE_OFFSET_BITS=64") +curl_internal_test(HAVE_FILE_OFFSET_BITS) +cmake_pop_check_state() -# Check compiler support of __builtin_available() -curl_internal_test(HAVE_BUILTIN_AVAILABLE) - -# Some other minor tests - -if(NOT HAVE_IN_ADDR_T) - set(in_addr_t "unsigned long") +cmake_push_check_state() +if(HAVE_FILE_OFFSET_BITS) + set(_FILE_OFFSET_BITS 64) + list(APPEND CMAKE_REQUIRED_DEFINITIONS "-D_FILE_OFFSET_BITS=64") endif() +check_type_size("off_t" SIZEOF_OFF_T) -# Check for nonblocking -set(HAVE_DISABLED_NONBLOCKING 1) -if(HAVE_FIONBIO OR - HAVE_IOCTLSOCKET OR - HAVE_IOCTLSOCKET_CASE OR - HAVE_O_NONBLOCK) - set(HAVE_DISABLED_NONBLOCKING) -endif() +if(NOT WIN32) + # fseeko may not exist with _FILE_OFFSET_BITS=64 but can exist with + # _FILE_OFFSET_BITS unset or 32 (as in Android ARMv7 with NDK 26b and API level < 24) + # so we need to test fseeko after testing for _FILE_OFFSET_BITS + check_symbol_exists("fseeko" "${CURL_INCLUDES};stdio.h" HAVE_FSEEKO) -if(CMAKE_COMPILER_IS_GNUCC AND APPLE) - include(CheckCCompilerFlag) - check_c_compiler_flag(-Wno-long-double HAVE_C_FLAG_Wno_long_double) - if(HAVE_C_FLAG_Wno_long_double) - # The Mac version of GCC warns about use of long double. Disable it. - get_source_file_property(MPRINTF_COMPILE_FLAGS mprintf.c COMPILE_FLAGS) - if(MPRINTF_COMPILE_FLAGS) - set(MPRINTF_COMPILE_FLAGS "${MPRINTF_COMPILE_FLAGS} -Wno-long-double") - else() - set(MPRINTF_COMPILE_FLAGS "-Wno-long-double") - endif() - set_source_files_properties(mprintf.c PROPERTIES - COMPILE_FLAGS ${MPRINTF_COMPILE_FLAGS}) + if(HAVE_FSEEKO) + set(HAVE_DECL_FSEEKO 1) endif() endif() -# TODO test which of these headers are required -if(WIN32) - set(CURL_PULL_WS2TCPIP_H ${HAVE_WS2TCPIP_H}) -else() - set(CURL_PULL_SYS_TYPES_H ${HAVE_SYS_TYPES_H}) - set(CURL_PULL_SYS_SOCKET_H ${HAVE_SYS_SOCKET_H}) - set(CURL_PULL_SYS_POLL_H ${HAVE_SYS_POLL_H}) +# Include this header to get the type +cmake_push_check_state() +list(APPEND CMAKE_REQUIRED_INCLUDES "${PROJECT_SOURCE_DIR}/include") +list(APPEND CMAKE_EXTRA_INCLUDE_FILES "curl/system.h") +check_type_size("curl_off_t" SIZEOF_CURL_OFF_T) +list(APPEND CMAKE_EXTRA_INCLUDE_FILES "curl/curl.h") +check_type_size("curl_socket_t" SIZEOF_CURL_SOCKET_T) +cmake_pop_check_state() # pop curl system headers +cmake_pop_check_state() # pop -D_FILE_OFFSET_BITS=64 + +if(NOT WIN32 AND NOT CMAKE_CROSSCOMPILING) + # On non-Windows and not cross-compiling, check for writable argv[] + include(CheckCSourceRuns) + check_c_source_runs(" + int main(int argc, char **argv) + { + (void)argc; + argv[0][0] = ' '; + return (argv[0][0] == ' ') ? 0 : 1; + }" HAVE_WRITABLE_ARGV) +endif() + +if(NOT CMAKE_CROSSCOMPILING) + include(CheckCSourceRuns) + check_c_source_runs(" + #include + int main(void) { + time_t t = -1; + return t < 0; + }" HAVE_TIME_T_UNSIGNED) +endif() + +curl_internal_test(HAVE_GLIBC_STRERROR_R) +curl_internal_test(HAVE_POSIX_STRERROR_R) + +if(NOT WIN32) + curl_internal_test(HAVE_CLOCK_GETTIME_MONOTONIC) # Check clock_gettime(CLOCK_MONOTONIC, x) support +endif() + +if(APPLE) + curl_internal_test(HAVE_BUILTIN_AVAILABLE) # Check compiler support of __builtin_available() +endif() + +# Some other minor tests + +if(_cmake_try_compile_target_type_save) + set(CMAKE_TRY_COMPILE_TARGET_TYPE ${_cmake_try_compile_target_type_save}) + unset(_cmake_try_compile_target_type_save) endif() include(CMake/OtherTests.cmake) -add_definitions(-DHAVE_CONFIG_H) +set_property(DIRECTORY APPEND PROPERTY COMPILE_DEFINITIONS "HAVE_CONFIG_H") -# For Windows, all compilers used by CMake should support large files if(WIN32) - set(USE_WIN32_LARGE_FILES ON) - - # Use the manifest embedded in the Windows Resource - set(CMAKE_RC_FLAGS "${CMAKE_RC_FLAGS} -DCURL_EMBED_MANIFEST") + list(APPEND CURL_NETWORK_AND_TIME_LIBS "ws2_32") + if(NOT WINDOWS_STORE) + list(APPEND CURL_NETWORK_AND_TIME_LIBS "iphlpapi") # for if_nametoindex() + endif() + list(APPEND CURL_LIBS "bcrypt") # for BCryptGenRandom() # We use crypto functions that are not available for UWP apps if(NOT WINDOWS_STORE) @@ -1353,216 +1855,247 @@ if(WIN32) # Link required libraries for USE_WIN32_CRYPTO or USE_SCHANNEL if(USE_WIN32_CRYPTO OR USE_SCHANNEL) - list(APPEND CURL_LIBS "advapi32" "crypt32") + # for CryptAcquireContext(), CryptCreateHash(), CryptDestroyHash(), CryptGetHashParam(), CryptHashData(), + # CryptReleaseContext() in NTLM, md4, md5, sha256, Schannel + # for CryptDestroyKey(), CryptEncrypt(), CryptImportKey() in NTLM + list(APPEND CURL_LIBS "advapi32") + # for Cert*() in openssl.c Native CA, Schannel + # for CryptDecodeObjectEx(), CryptQueryObject(), CryptStringToBinary(), PFXImportCertStore() in Schannel + list(APPEND CURL_LIBS "crypt32") endif() - - if(NOT HAVE_MINGW_ORIGINAL) - list(APPEND CURL_LIBS "bcrypt") - else() - set(HAVE_FTRUNCATE OFF) + if(USE_WINDOWS_SSPI) + list(APPEND CURL_LIBS "secur32") # for InitSecurityInterface() endif() endif() -if(MSVC) - # Disable default manifest added by CMake - set(CMAKE_EXE_LINKER_FLAGS "${CMAKE_EXE_LINKER_FLAGS} /MANIFEST:NO") +list(APPEND CURL_LIBS ${CURL_NETWORK_AND_TIME_LIBS}) +if(CURL_CODE_COVERAGE) + list(APPEND CURL_LIBS ${CURL_COVERAGE_LIBS}) +endif() - add_definitions(-D_CRT_SECURE_NO_DEPRECATE -D_CRT_NONSTDC_NO_DEPRECATE) - if(CMAKE_C_FLAGS MATCHES "/W[0-4]") - string(REGEX REPLACE "/W[0-4]" "/W4" CMAKE_C_FLAGS "${CMAKE_C_FLAGS}") - else() - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} /W4") +# Hack to add some libraries to the end of the library list to make binutils ld +# for GCC find symbols when linking statically. Necessary for libs detected via +# CMake's built-in find modules, which CMake adds to the beginning of the lib +# list on the linker command-line for some reason. This makes them appear +# before dependencies detected via curl's custom Find modules, and breaks +# linkers sensitive to lib order. There must be a better solution to this. +# Enable the workaround for all compilers, to make it available when using GCC +# to consume libcurl, regardless of the compiler used to build libcurl itself. +if(CMAKE_C_COMPILER_ID STREQUAL "GNU") + if(USE_OPENSSL AND TARGET OpenSSL::Crypto) + add_library(CURL::OpenSSL_Crypto INTERFACE IMPORTED) + set_target_properties(CURL::OpenSSL_Crypto PROPERTIES INTERFACE_LINK_LIBRARIES OpenSSL::Crypto) + list(APPEND CURL_LIBS CURL::OpenSSL_Crypto) endif() - - # Use multithreaded compilation on VS 2008+ - if(MSVC_VERSION GREATER_EQUAL 1500) - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} /MP") + if(HAVE_LIBZ AND TARGET ZLIB::ZLIB) + add_library(CURL::ZLIB INTERFACE IMPORTED) + set_target_properties(CURL::ZLIB PROPERTIES INTERFACE_LINK_LIBRARIES ZLIB::ZLIB) + list(APPEND CURL_LIBS CURL::ZLIB) + endif() + if(WIN32) + add_library(CURL::win32_winsock INTERFACE IMPORTED) + set_target_properties(CURL::win32_winsock PROPERTIES INTERFACE_LINK_LIBRARIES "ws2_32") + list(APPEND CURL_LIBS CURL::win32_winsock) endif() endif() -if(CURL_WERROR) - if(MSVC_VERSION) - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} /WX") - else() - # this assumes clang or gcc style options - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -Werror") - endif() +if(CMAKE_C_COMPILER_ID STREQUAL "MSVC") # MSVC but exclude clang-cl + set_property(DIRECTORY APPEND PROPERTY COMPILE_OPTIONS "-MP") # Parallel compilation endif() if(CURL_LTO) - if(CMAKE_VERSION VERSION_LESS 3.9) - message(FATAL_ERROR "Requested LTO but your cmake version ${CMAKE_VERSION} is to old. You need at least 3.9") - endif() - - cmake_policy(SET CMP0069 NEW) - include(CheckIPOSupported) - check_ipo_supported(RESULT CURL_HAS_LTO OUTPUT CURL_LTO_ERROR LANGUAGES C) + check_ipo_supported(RESULT CURL_HAS_LTO OUTPUT _lto_error LANGUAGES C) if(CURL_HAS_LTO) message(STATUS "LTO supported and enabled") else() - message(FATAL_ERROR "LTO was requested - but compiler doesn't support it\n${CURL_LTO_ERROR}") + message(FATAL_ERROR "LTO has been requested, but the compiler does not support it\n${_lto_error}") endif() endif() +# Ugly (but functional) way to include "Makefile.inc" by transforming it +# (= regenerate it). +function(curl_transform_makefile_inc _input_file _output_file) + file(READ ${_input_file} _makefile_inc_text) + string(REPLACE "$(top_srcdir)" "\${PROJECT_SOURCE_DIR}" _makefile_inc_text ${_makefile_inc_text}) # cmake-lint: disable=W0106 + string(REPLACE "$(top_builddir)" "\${PROJECT_BINARY_DIR}" _makefile_inc_text ${_makefile_inc_text}) # cmake-lint: disable=W0106 -# Ugly (but functional) way to include "Makefile.inc" by transforming it (= regenerate it). -function(transform_makefile_inc INPUT_FILE OUTPUT_FILE) - file(READ ${INPUT_FILE} MAKEFILE_INC_TEXT) - string(REPLACE "$(top_srcdir)" "\${CURL_SOURCE_DIR}" MAKEFILE_INC_TEXT ${MAKEFILE_INC_TEXT}) - string(REPLACE "$(top_builddir)" "\${CURL_BINARY_DIR}" MAKEFILE_INC_TEXT ${MAKEFILE_INC_TEXT}) + string(REGEX REPLACE "\\\\\n" "!^!^!" _makefile_inc_text ${_makefile_inc_text}) + string(REGEX REPLACE "([a-zA-Z_][a-zA-Z0-9_]*)[\t ]*=[\t ]*([^\n]*)" "set(\\1 \\2)" _makefile_inc_text ${_makefile_inc_text}) + string(REPLACE "!^!^!" "\n" _makefile_inc_text ${_makefile_inc_text}) - string(REGEX REPLACE "\\\\\n" "!π!α!" MAKEFILE_INC_TEXT ${MAKEFILE_INC_TEXT}) - string(REGEX REPLACE "([a-zA-Z_][a-zA-Z0-9_]*)[\t ]*=[\t ]*([^\n]*)" "SET(\\1 \\2)" MAKEFILE_INC_TEXT ${MAKEFILE_INC_TEXT}) - string(REPLACE "!π!α!" "\n" MAKEFILE_INC_TEXT ${MAKEFILE_INC_TEXT}) + # Replace $() with ${} + string(REGEX REPLACE "\\$\\(([a-zA-Z_][a-zA-Z0-9_]*)\\)" "\${\\1}" _makefile_inc_text ${_makefile_inc_text}) + # Replace @@ with ${}, even if that may not be read by CMake scripts. + string(REGEX REPLACE "@([a-zA-Z_][a-zA-Z0-9_]*)@" "\${\\1}" _makefile_inc_text ${_makefile_inc_text}) - string(REGEX REPLACE "\\$\\(([a-zA-Z_][a-zA-Z0-9_]*)\\)" "\${\\1}" MAKEFILE_INC_TEXT ${MAKEFILE_INC_TEXT}) # Replace $() with ${} - string(REGEX REPLACE "@([a-zA-Z_][a-zA-Z0-9_]*)@" "\${\\1}" MAKEFILE_INC_TEXT ${MAKEFILE_INC_TEXT}) # Replace @@ with ${}, even if that may not be read by CMake scripts. - file(WRITE ${OUTPUT_FILE} ${MAKEFILE_INC_TEXT}) - set_property(DIRECTORY APPEND PROPERTY CMAKE_CONFIGURE_DEPENDS "${INPUT_FILE}") + file(WRITE ${_output_file} ${_makefile_inc_text}) + set_property(DIRECTORY APPEND PROPERTY CMAKE_CONFIGURE_DEPENDS "${_input_file}") endfunction() include(GNUInstallDirs) -set(CURL_INSTALL_CMAKE_DIR ${CMAKE_INSTALL_LIBDIR}/cmake/${PROJECT_NAME}) +set(_install_cmake_dir "${CMAKE_INSTALL_LIBDIR}/cmake/${PROJECT_NAME}") set(TARGETS_EXPORT_NAME "${PROJECT_NAME}Targets") -set(generated_dir "${CMAKE_CURRENT_BINARY_DIR}/generated") -set(project_config "${generated_dir}/${PROJECT_NAME}Config.cmake") -set(version_config "${generated_dir}/${PROJECT_NAME}ConfigVersion.cmake") +set(_generated_dir "${CMAKE_CURRENT_BINARY_DIR}/generated") +set(_project_config "${_generated_dir}/${PROJECT_NAME}Config.cmake") +set(_version_config "${_generated_dir}/${PROJECT_NAME}ConfigVersion.cmake") -if(USE_MANUAL) +option(BUILD_TESTING "Build tests" ON) +if(BUILD_TESTING AND Perl_FOUND) + set(CURL_BUILD_TESTING ON) +else() + set(CURL_BUILD_TESTING OFF) +endif() + +if(Perl_FOUND) + set(CURL_MANPAGE "${PROJECT_BINARY_DIR}/docs/cmdline-opts/curl.1") + set(CURL_ASCIIPAGE "${PROJECT_BINARY_DIR}/docs/cmdline-opts/curl.txt") add_subdirectory(docs) endif() +add_subdirectory(scripts) # for shell completions + add_subdirectory(lib) if(BUILD_CURL_EXE) add_subdirectory(src) endif() -cmake_dependent_option(BUILD_TESTING "Build tests" - ON "PERL_FOUND;NOT CURL_DISABLE_TESTS" - OFF) -if(BUILD_TESTING) +option(BUILD_EXAMPLES "Build libcurl examples" ON) +if(BUILD_EXAMPLES) + add_subdirectory(docs/examples) +endif() + +if(CURL_BUILD_TESTING) add_subdirectory(tests) endif() -# Helper to populate a list (_items) with a label when conditions (the remaining -# args) are satisfied -macro(_add_if label) - # needs to be a macro to allow this indirection +# Helper to populate a list (_items) with a label when conditions +# (the remaining args) are satisfied +macro(curl_add_if _label) + # Needs to be a macro to allow this indirection if(${ARGN}) - set(_items ${_items} "${label}") + list(APPEND _items "${_label}") endif() endmacro() -# NTLM support requires crypto function adaptions from various SSL libs -# TODO alternative SSL libs tests for SSP1, GNUTLS, NSS -if(NOT (CURL_DISABLE_NTLM) AND - (USE_OPENSSL OR USE_MBEDTLS OR USE_DARWINSSL OR USE_WIN32_CRYPTO OR USE_GNUTLS)) - set(use_curl_ntlm_core ON) +# NTLM support requires crypto functions from various SSL libs. +# These conditions must match those in lib/curl_setup.h. +if(CURL_ENABLE_NTLM AND + ((USE_OPENSSL AND HAVE_DES_ECB_ENCRYPT) OR + (USE_MBEDTLS AND HAVE_MBEDTLS_DES_CRYPT_ECB) OR + USE_GNUTLS OR + USE_WIN32_CRYPTO OR + (USE_WOLFSSL AND HAVE_WC_DES_ECBENCRYPT))) + set(_use_curl_ntlm_core ON) endif() -# Clear list and try to detect available features -set(_items) -_add_if("SSL" SSL_ENABLED) -_add_if("IPv6" ENABLE_IPV6) -_add_if("unixsockets" USE_UNIX_SOCKETS) -_add_if("libz" HAVE_LIBZ) -_add_if("brotli" HAVE_BROTLI) -_add_if("zstd" HAVE_ZSTD) -_add_if("AsynchDNS" USE_ARES OR USE_THREADS_POSIX OR USE_THREADS_WIN32) -_add_if("IDN" HAVE_LIBIDN2 OR USE_WIN32_IDN) -_add_if("Largefile" (SIZEOF_CURL_OFF_T GREATER 4) AND - ((SIZEOF_OFF_T GREATER 4) OR USE_WIN32_LARGE_FILES)) -# TODO SSP1 (Schannel) check is missing -_add_if("SSPI" USE_WINDOWS_SSPI) -_add_if("GSS-API" HAVE_GSSAPI) -_add_if("alt-svc" NOT CURL_DISABLE_ALTSVC) -_add_if("HSTS" NOT CURL_DISABLE_HSTS) -# TODO SSP1 missing for SPNEGO -_add_if("SPNEGO" NOT CURL_DISABLE_NEGOTIATE_AUTH AND - (HAVE_GSSAPI OR USE_WINDOWS_SSPI)) -_add_if("Kerberos" NOT CURL_DISABLE_KERBEROS_AUTH AND - (HAVE_GSSAPI OR USE_WINDOWS_SSPI)) -# NTLM support requires crypto function adaptions from various SSL libs -# TODO alternative SSL libs tests for SSP1, GNUTLS, NSS -_add_if("NTLM" NOT (CURL_DISABLE_NTLM) AND - (use_curl_ntlm_core OR USE_WINDOWS_SSPI)) -# TODO missing option (autoconf: --enable-ntlm-wb) -_add_if("NTLM_WB" NOT (CURL_DISABLE_NTLM) AND - (use_curl_ntlm_core OR USE_WINDOWS_SSPI) AND - NOT CURL_DISABLE_HTTP AND NTLM_WB_ENABLED) -# TODO missing option (--enable-tls-srp), depends on GNUTLS_SRP/OPENSSL_SRP -_add_if("TLS-SRP" USE_TLS_SRP) -# TODO option --with-nghttp2 tests for nghttp2 lib and nghttp2/nghttp2.h header -_add_if("HTTP2" USE_NGHTTP2) -_add_if("HTTP3" USE_NGTCP2 OR USE_QUICHE) -_add_if("MultiSSL" CURL_WITH_MULTI_SSL) -# TODO wolfSSL only support this from v5.0.0 onwards -_add_if("HTTPS-proxy" SSL_ENABLED AND (USE_OPENSSL OR USE_GNUTLS - OR USE_SCHANNEL OR USE_RUSTLS OR USE_BEARSSL OR - USE_MBEDTLS OR USE_SECTRANSP)) -_add_if("unicode" ENABLE_UNICODE) -_add_if("threadsafe" HAVE_ATOMIC OR (WIN32 AND - HAVE_WIN32_WINNT GREATER_EQUAL 0x600)) -_add_if("PSL" USE_LIBPSL) -string(REPLACE ";" " " SUPPORT_FEATURES "${_items}") -message(STATUS "Enabled features: ${SUPPORT_FEATURES}") - # Clear list and try to detect available protocols -set(_items) -_add_if("HTTP" NOT CURL_DISABLE_HTTP) -_add_if("HTTPS" NOT CURL_DISABLE_HTTP AND SSL_ENABLED) -_add_if("FTP" NOT CURL_DISABLE_FTP) -_add_if("FTPS" NOT CURL_DISABLE_FTP AND SSL_ENABLED) -_add_if("FILE" NOT CURL_DISABLE_FILE) -_add_if("TELNET" NOT CURL_DISABLE_TELNET) -_add_if("LDAP" NOT CURL_DISABLE_LDAP) +set(_items "") +curl_add_if("HTTP" NOT CURL_DISABLE_HTTP) +curl_add_if("HTTPS" NOT CURL_DISABLE_HTTP AND _ssl_enabled) +curl_add_if("FTP" NOT CURL_DISABLE_FTP) +curl_add_if("FTPS" NOT CURL_DISABLE_FTP AND _ssl_enabled) +curl_add_if("FILE" NOT CURL_DISABLE_FILE) +curl_add_if("TELNET" NOT CURL_DISABLE_TELNET) +curl_add_if("LDAP" NOT CURL_DISABLE_LDAP) # CURL_DISABLE_LDAP implies CURL_DISABLE_LDAPS -# TODO check HAVE_LDAP_SSL (in autoconf this is enabled with --enable-ldaps) -_add_if("LDAPS" NOT CURL_DISABLE_LDAPS AND - ((USE_OPENLDAP AND SSL_ENABLED) OR - (NOT USE_OPENLDAP AND HAVE_LDAP_SSL))) -_add_if("DICT" NOT CURL_DISABLE_DICT) -_add_if("TFTP" NOT CURL_DISABLE_TFTP) -_add_if("GOPHER" NOT CURL_DISABLE_GOPHER) -_add_if("GOPHERS" NOT CURL_DISABLE_GOPHER AND SSL_ENABLED) -_add_if("POP3" NOT CURL_DISABLE_POP3) -_add_if("POP3S" NOT CURL_DISABLE_POP3 AND SSL_ENABLED) -_add_if("IMAP" NOT CURL_DISABLE_IMAP) -_add_if("IMAPS" NOT CURL_DISABLE_IMAP AND SSL_ENABLED) -_add_if("SMB" NOT CURL_DISABLE_SMB AND - use_curl_ntlm_core AND (SIZEOF_CURL_OFF_T GREATER 4)) -_add_if("SMBS" NOT CURL_DISABLE_SMB AND SSL_ENABLED AND - use_curl_ntlm_core AND (SIZEOF_CURL_OFF_T GREATER 4)) -_add_if("SMTP" NOT CURL_DISABLE_SMTP) -_add_if("SMTPS" NOT CURL_DISABLE_SMTP AND SSL_ENABLED) -_add_if("SCP" USE_LIBSSH2 OR USE_LIBSSH) -_add_if("SFTP" USE_LIBSSH2 OR USE_LIBSSH) -_add_if("RTSP" NOT CURL_DISABLE_RTSP) -_add_if("RTMP" USE_LIBRTMP) -_add_if("MQTT" NOT CURL_DISABLE_MQTT) -_add_if("WS" USE_WEBSOCKETS) -_add_if("WSS" USE_WEBSOCKETS) +curl_add_if("LDAPS" NOT CURL_DISABLE_LDAPS AND + ((USE_OPENLDAP AND _ssl_enabled) OR + (NOT USE_OPENLDAP AND HAVE_LDAP_SSL))) +curl_add_if("DICT" NOT CURL_DISABLE_DICT) +curl_add_if("TFTP" NOT CURL_DISABLE_TFTP) +curl_add_if("GOPHER" NOT CURL_DISABLE_GOPHER) +curl_add_if("GOPHERS" NOT CURL_DISABLE_GOPHER AND _ssl_enabled) +curl_add_if("POP3" NOT CURL_DISABLE_POP3) +curl_add_if("POP3S" NOT CURL_DISABLE_POP3 AND _ssl_enabled) +curl_add_if("IMAP" NOT CURL_DISABLE_IMAP) +curl_add_if("IMAPS" NOT CURL_DISABLE_IMAP AND _ssl_enabled) +curl_add_if("SMB" CURL_ENABLE_SMB AND + _use_curl_ntlm_core AND (SIZEOF_CURL_OFF_T GREATER 4)) +curl_add_if("SMBS" CURL_ENABLE_SMB AND _ssl_enabled AND + _use_curl_ntlm_core AND (SIZEOF_CURL_OFF_T GREATER 4)) +curl_add_if("SMTP" NOT CURL_DISABLE_SMTP) +curl_add_if("SMTPS" NOT CURL_DISABLE_SMTP AND _ssl_enabled) +curl_add_if("SCP" USE_LIBSSH2 OR USE_LIBSSH) +curl_add_if("SFTP" USE_LIBSSH2 OR USE_LIBSSH) +curl_add_if("IPFS" NOT CURL_DISABLE_IPFS) +curl_add_if("IPNS" NOT CURL_DISABLE_IPFS) +curl_add_if("RTSP" NOT CURL_DISABLE_RTSP) +curl_add_if("MQTT" NOT CURL_DISABLE_MQTT) +curl_add_if("MQTTS" NOT CURL_DISABLE_MQTT AND _ssl_enabled) +curl_add_if("WS" NOT CURL_DISABLE_WEBSOCKETS) +curl_add_if("WSS" NOT CURL_DISABLE_WEBSOCKETS AND _ssl_enabled) if(_items) list(SORT _items) endif() +set(CURL_SUPPORTED_PROTOCOLS_LIST "${_items}") string(REPLACE ";" " " SUPPORT_PROTOCOLS "${_items}") -message(STATUS "Enabled protocols: ${SUPPORT_PROTOCOLS}") +string(TOLOWER "${SUPPORT_PROTOCOLS}" _support_protocols_lower) +message(STATUS "Protocols: ${_support_protocols_lower}") + +# Clear list and try to detect available features +set(_items "") +curl_add_if("SSL" _ssl_enabled) +curl_add_if("IPv6" USE_IPV6) +curl_add_if("UnixSockets" USE_UNIX_SOCKETS) +curl_add_if("libz" HAVE_LIBZ) +curl_add_if("brotli" HAVE_BROTLI) +curl_add_if("gsasl" USE_GSASL) +curl_add_if("zstd" HAVE_ZSTD) +curl_add_if("AsynchDNS" USE_RESOLV_ARES OR USE_RESOLV_THREADED) +curl_add_if("asyn-rr" USE_ARES AND USE_RESOLV_THREADED AND USE_HTTPSRR) +curl_add_if("IDN" (HAVE_LIBIDN2 AND HAVE_IDN2_H) OR + USE_WIN32_IDN OR + USE_APPLE_IDN) +curl_add_if("Largefile" (SIZEOF_CURL_OFF_T GREATER 4) AND ((SIZEOF_OFF_T GREATER 4) OR WIN32)) +curl_add_if("SSPI" USE_WINDOWS_SSPI) +curl_add_if("GSS-API" HAVE_GSSAPI) +curl_add_if("alt-svc" NOT CURL_DISABLE_ALTSVC) +curl_add_if("HSTS" NOT CURL_DISABLE_HSTS) +curl_add_if("SPNEGO" NOT CURL_DISABLE_NEGOTIATE_AUTH AND + (HAVE_GSSAPI OR USE_WINDOWS_SSPI)) +curl_add_if("Kerberos" NOT CURL_DISABLE_KERBEROS_AUTH AND + (HAVE_GSSAPI OR USE_WINDOWS_SSPI)) +curl_add_if("NTLM" CURL_ENABLE_NTLM AND + (_use_curl_ntlm_core OR USE_WINDOWS_SSPI)) +curl_add_if("TLS-SRP" USE_TLS_SRP) +curl_add_if("HTTP2" USE_NGHTTP2) +curl_add_if("HTTP3" USE_NGTCP2 OR USE_QUICHE) +curl_add_if("proxy-HTTP3" USE_PROXY_HTTP3) +curl_add_if("MultiSSL" CURL_WITH_MULTI_SSL) +curl_add_if("HTTPS-proxy" NOT CURL_DISABLE_PROXY AND _ssl_enabled AND (USE_OPENSSL OR USE_GNUTLS + OR USE_SCHANNEL OR USE_RUSTLS OR USE_MBEDTLS OR + (USE_WOLFSSL AND HAVE_WOLFSSL_BIO_NEW))) +curl_add_if("Unicode" ENABLE_UNICODE) +curl_add_if("threadsafe" HAVE_ATOMIC OR HAVE_THREADS_POSIX OR WIN32) +curl_add_if("Debug" ENABLE_DEBUG) +curl_add_if("ECH" _ssl_enabled AND HAVE_ECH) +curl_add_if("HTTPSRR" _ssl_enabled AND USE_HTTPSRR) +curl_add_if("PSL" USE_LIBPSL) +curl_add_if("CAcert" CURL_CA_EMBED_SET) +curl_add_if("SSLS-EXPORT" _ssl_enabled AND USE_SSLS_EXPORT) +curl_add_if("AppleSecTrust" USE_APPLE_SECTRUST AND _ssl_enabled AND (USE_OPENSSL OR USE_GNUTLS)) +curl_add_if("NativeCA" NOT USE_APPLE_SECTRUST AND _ssl_enabled AND CURL_CA_NATIVE) +if(_items) + list(SORT _items CASE INSENSITIVE) +endif() +set(CURL_SUPPORTED_FEATURES_LIST "${_items}") +string(REPLACE ";" " " SUPPORT_FEATURES "${_items}") +message(STATUS "Features: ${SUPPORT_FEATURES}") # Clear list and collect SSL backends -set(_items) -_add_if("Schannel" SSL_ENABLED AND USE_SCHANNEL) -_add_if("OpenSSL" SSL_ENABLED AND USE_OPENSSL) -_add_if("Secure Transport" SSL_ENABLED AND USE_SECTRANSP) -_add_if("mbedTLS" SSL_ENABLED AND USE_MBEDTLS) -_add_if("BearSSL" SSL_ENABLED AND USE_BEARSSL) -_add_if("wolfSSL" SSL_ENABLED AND USE_WOLFSSL) -_add_if("GnuTLS" SSL_ENABLED AND USE_GNUTLS) +set(_items "") +curl_add_if("Schannel" _ssl_enabled AND USE_SCHANNEL) +curl_add_if("${_openssl}" _ssl_enabled AND USE_OPENSSL) +curl_add_if("mbedTLS" _ssl_enabled AND USE_MBEDTLS) +curl_add_if("wolfSSL" _ssl_enabled AND USE_WOLFSSL) +curl_add_if("GnuTLS" _ssl_enabled AND USE_GNUTLS) +curl_add_if("Rustls" _ssl_enabled AND USE_RUSTLS) if(_items) - list(SORT _items) + list(SORT _items CASE INSENSITIVE) endif() string(REPLACE ";" " " SSL_BACKENDS "${_items}") message(STATUS "Enabled SSL backends: ${SSL_BACKENDS}") @@ -1570,137 +2103,404 @@ if(CURL_DEFAULT_SSL_BACKEND) message(STATUS "Default SSL backend: ${CURL_DEFAULT_SSL_BACKEND}") endif() -# curl-config needs the following options to be set. -set(CC "${CMAKE_C_COMPILER}") -# TODO probably put a -D... options here? -set(CONFIGURE_OPTIONS "") -set(CURLVERSION "${CURL_VERSION}") -set(exec_prefix "\${prefix}") -set(includedir "\${prefix}/include") -set(LDFLAGS "${CMAKE_SHARED_LINKER_FLAGS}") -set(LIBCURL_LIBS "") -set(libdir "${CMAKE_INSTALL_PREFIX}/lib") -foreach(_lib ${CMAKE_C_IMPLICIT_LINK_LIBRARIES} ${CURL_LIBS}) - if(TARGET "${_lib}") - set(_libname "${_lib}") - get_target_property(_imported "${_libname}" IMPORTED) - if(NOT _imported) - # Reading the LOCATION property on non-imported target will error out. - # Assume the user won't need this information in the .pc file. - continue() - endif() - get_target_property(_lib "${_libname}" LOCATION) - if(NOT _lib) - message(WARNING "Bad lib in library list: ${_libname}") - continue() - endif() - endif() - if(_lib MATCHES ".*/.*" OR _lib MATCHES "^-") - set(LIBCURL_LIBS "${LIBCURL_LIBS} ${_lib}") +if(NOT CURL_DISABLE_INSTALL) + + # curl-config needs the following options to be set. + set(CC "${CMAKE_C_COMPILER}") + set(CONFIGURE_OPTIONS "") + set(CURLVERSION "${_curl_version}") + set(VERSIONNUM "${_curl_version_num}") + set(prefix "${CMAKE_INSTALL_PREFIX}") + set(exec_prefix "\${prefix}") + if(IS_ABSOLUTE ${CMAKE_INSTALL_INCLUDEDIR}) + set(includedir "${CMAKE_INSTALL_INCLUDEDIR}") else() - set(LIBCURL_LIBS "${LIBCURL_LIBS} -l${_lib}") + set(includedir "\${prefix}/${CMAKE_INSTALL_INCLUDEDIR}") endif() -endforeach() -if(BUILD_SHARED_LIBS) - set(ENABLE_SHARED "yes") - set(LIBCURL_NO_SHARED "") - set(CPPFLAG_CURL_STATICLIB "") -else() - set(ENABLE_SHARED "no") - set(LIBCURL_NO_SHARED "${LIBCURL_LIBS}") - set(CPPFLAG_CURL_STATICLIB "-DCURL_STATICLIB") -endif() -if(BUILD_STATIC_LIBS) - set(ENABLE_STATIC "yes") -else() - set(ENABLE_STATIC "no") -endif() -# "a" (Linux) or "lib" (Windows) -string(REPLACE "." "" libext "${CMAKE_STATIC_LIBRARY_SUFFIX}") -set(prefix "${CMAKE_INSTALL_PREFIX}") -# Set this to "yes" to append all libraries on which -lcurl is dependent -set(REQUIRE_LIB_DEPS "no") -# SUPPORT_FEATURES -# SUPPORT_PROTOCOLS -set(VERSIONNUM "${CURL_VERSION_NUM}") + if(IS_ABSOLUTE ${CMAKE_INSTALL_LIBDIR}) + set(libdir "${CMAKE_INSTALL_LIBDIR}") + else() + set(libdir "\${exec_prefix}/${CMAKE_INSTALL_LIBDIR}") + endif() + # "a" (Linux) or "lib" (Windows) + string(REPLACE "." "" libext "${CMAKE_STATIC_LIBRARY_SUFFIX}") -# Finally generate a "curl-config" matching this config -# Use: -# * ENABLE_SHARED -# * ENABLE_STATIC -configure_file("${CURL_SOURCE_DIR}/curl-config.in" - "${CURL_BINARY_DIR}/curl-config" @ONLY) -install(FILES "${CURL_BINARY_DIR}/curl-config" - DESTINATION ${CMAKE_INSTALL_BINDIR} - PERMISSIONS - OWNER_READ OWNER_WRITE OWNER_EXECUTE - GROUP_READ GROUP_EXECUTE - WORLD_READ WORLD_EXECUTE) + set(_ldflags "") + set(LIBCURL_PC_LIBS_PRIVATE "") -# Finally generate a pkg-config file matching this config -configure_file("${CURL_SOURCE_DIR}/libcurl.pc.in" - "${CURL_BINARY_DIR}/libcurl.pc" @ONLY) -install(FILES "${CURL_BINARY_DIR}/libcurl.pc" - DESTINATION ${CMAKE_INSTALL_LIBDIR}/pkgconfig) + # Filter CMAKE_SHARED_LINKER_FLAGS for libs and libpaths + string(STRIP "${CMAKE_SHARED_LINKER_FLAGS}" _custom_ldflags) + string(REGEX REPLACE " +-([^ \\t;]*)" ";-\\1" _custom_ldflags "${_custom_ldflags}") -# install headers -install(DIRECTORY "${CMAKE_CURRENT_SOURCE_DIR}/include/curl" + set(_custom_libs "") + set(_custom_libdirs "") + foreach(_flag IN LISTS _custom_ldflags) + if(_flag MATCHES "^-l") + string(REGEX REPLACE "^-l" "" _flag "${_flag}") + list(APPEND _custom_libs "${_flag}") + elseif(_flag MATCHES "^-framework|^-F") + list(APPEND _custom_libs "${_flag}") + elseif(_flag MATCHES "^-L") + string(REGEX REPLACE "^-L" "" _flag "${_flag}") + list(APPEND _custom_libdirs "${_flag}") + elseif(_flag MATCHES "^--library-path=") + string(REGEX REPLACE "^--library-path=" "" _flag "${_flag}") + list(APPEND _custom_libdirs "${_flag}") + endif() + endforeach() + + # Avoid getting unnecessary -L options for known system directories. + set(_sys_libdirs "${CMAKE_C_IMPLICIT_LINK_DIRECTORIES}") + foreach(_libdir IN LISTS CMAKE_SYSTEM_PREFIX_PATH) + if(_libdir MATCHES "/$") + string(APPEND _libdir "lib") + else() + string(APPEND _libdir "/lib") + endif() + if(IS_DIRECTORY "${_libdir}") + list(APPEND _sys_libdirs "${_libdir}") + endif() + if(DEFINED CMAKE_LIBRARY_ARCHITECTURE) + string(APPEND _libdir "/${CMAKE_LIBRARY_ARCHITECTURE}") + if(IS_DIRECTORY "${_libdir}") + list(APPEND _sys_libdirs "${_libdir}") + endif() + endif() + endforeach() + + set(_implicit_libs "") + if(NOT MINGW AND NOT UNIX) + set(_implicit_libs "${CMAKE_C_IMPLICIT_LINK_LIBRARIES}") + endif() + + set(_explicit_libdirs "") + set(LIBCURL_PC_REQUIRES_PRIVATE "") + set(LIBCURL_PC_LIBS_PRIVATE_LIST "") + foreach(_lib IN LISTS CURL_LIBS _custom_libs _implicit_libs) + if(TARGET "${_lib}") + set(_explicit_libs "") + get_target_property(_imported "${_lib}" IMPORTED) + if(NOT _imported) + # Reading the LOCATION property on non-imported target errors out. + # Assume the user does not need this information in the .pc file. + continue() + endif() + set(_libdirs "") + set(_libs "") + curl_collect_target_link_options("${_lib}") # look into the target recursively + list(APPEND _explicit_libdirs ${_libdirs}) + list(APPEND _explicit_libs ${_libs}) + if(NOT _libs AND NOT _libdirs AND NOT _lib STREQUAL Threads::Threads) + message(WARNING "Bad lib in library list: ${_lib}") + endif() + if(_lib STREQUAL OpenSSL::SSL AND NOT HAVE_BORINGSSL) # BoringSSL does not provide openssl.pc + set(_modules "openssl") + elseif(_lib STREQUAL ZLIB::ZLIB AND NOT ANDROID) # Android does not provide zlib.pc + set(_modules "zlib") + else() + get_target_property(_modules "${_lib}" INTERFACE_LIBCURL_PC_MODULES) + endif() + if(_modules) + list(APPEND LIBCURL_PC_REQUIRES_PRIVATE "${_modules}") + endif() + + foreach(_lib IN LISTS _explicit_libs) + if(_lib MATCHES "/") + # This gets a bit more complex, because we want to specify the + # directory separately, and only once per directory + if(CMAKE_VERSION VERSION_GREATER_EQUAL 3.20) + cmake_path(GET _lib PARENT_PATH _libdir) + cmake_path(GET _lib STEM _libname) + else() + get_filename_component(_libdir "${_lib}" DIRECTORY) + get_filename_component(_libname "${_lib}" NAME_WE) + endif() + if(_libname MATCHES "^lib") + if(CMAKE_VERSION VERSION_GREATER_EQUAL 3.20) + cmake_path(SET _libdir NORMALIZE "${_libdir}") + endif() + if(NOT _libdir IN_LIST _sys_libdirs) + list(APPEND _ldflags "-L${_libdir}") + endif() + string(REGEX REPLACE "^lib" "" _libname "${_libname}") + list(APPEND LIBCURL_PC_LIBS_PRIVATE "-l${_libname}") + list(APPEND LIBCURL_PC_LIBS_PRIVATE_LIST "${_lib}") + else() + list(APPEND LIBCURL_PC_LIBS_PRIVATE "${_lib}") + list(APPEND LIBCURL_PC_LIBS_PRIVATE_LIST "${_lib}") + endif() + elseif(_lib MATCHES "^-") # '-option' + list(APPEND _ldflags "${_lib}") + list(APPEND LIBCURL_PC_LIBS_PRIVATE_LIST "${_lib}") + else() + list(APPEND LIBCURL_PC_LIBS_PRIVATE "-l${_lib}") + list(APPEND LIBCURL_PC_LIBS_PRIVATE_LIST "${_lib}") + endif() + endforeach() + elseif(_lib MATCHES "^-") # '-framework ' + list(APPEND _ldflags "${_lib}") + list(APPEND LIBCURL_PC_LIBS_PRIVATE_LIST "${_lib}") + else() + list(APPEND LIBCURL_PC_LIBS_PRIVATE "-l${_lib}") + list(APPEND LIBCURL_PC_LIBS_PRIVATE_LIST "${_lib}") + endif() + endforeach() + + foreach(_libdir IN LISTS _custom_libdirs _explicit_libdirs) + if(CMAKE_VERSION VERSION_GREATER_EQUAL 3.20) + cmake_path(SET _libdir NORMALIZE "${_libdir}") + endif() + if(NOT _libdir IN_LIST _sys_libdirs) + list(APPEND _ldflags "-L${_libdir}") + endif() + endforeach() + + list(REMOVE_DUPLICATES _ldflags) + + if(LIBCURL_PC_REQUIRES_PRIVATE) + list(REMOVE_DUPLICATES LIBCURL_PC_REQUIRES_PRIVATE) + string(REPLACE ";" "," LIBCURL_PC_REQUIRES_PRIVATE "${LIBCURL_PC_REQUIRES_PRIVATE}") + endif() + if(LIBCURL_PC_LIBS_PRIVATE) + # Remove duplicates listed next to each other + set(_libs "") + set(_prev "") + foreach(_lib IN LISTS LIBCURL_PC_LIBS_PRIVATE) + if(NOT _prev STREQUAL _lib) + list(APPEND _libs "${_lib}") + set(_prev "${_lib}") + endif() + endforeach() + set(LIBCURL_PC_LIBS_PRIVATE "${_libs}") + + string(REPLACE ";" " " LIBCURL_PC_LIBS_PRIVATE "${LIBCURL_PC_LIBS_PRIVATE}") + endif() + if(_ldflags) + list(REMOVE_DUPLICATES _ldflags) + string(REPLACE ";" " " _ldflags "${_ldflags}") + set(LIBCURL_PC_LDFLAGS_PRIVATE "${_ldflags}") + string(STRIP "${LIBCURL_PC_LDFLAGS_PRIVATE}" LIBCURL_PC_LDFLAGS_PRIVATE) + else() + set(LIBCURL_PC_LDFLAGS_PRIVATE "") + endif() + set(LIBCURL_PC_CFLAGS_PRIVATE "-DCURL_STATICLIB") + + # Merge pkg-config private fields into public ones when static-only + if(BUILD_SHARED_LIBS) + set(ENABLE_SHARED "yes") + set(LIBCURL_PC_REQUIRES "") + set(LIBCURL_PC_LIBS "") + set(LIBCURL_PC_CFLAGS "") + else() + set(ENABLE_SHARED "no") + set(LIBCURL_PC_REQUIRES "${LIBCURL_PC_REQUIRES_PRIVATE}") + set(LIBCURL_PC_LIBS "${LIBCURL_PC_LIBS_PRIVATE}") + set(LIBCURL_PC_CFLAGS "${LIBCURL_PC_CFLAGS_PRIVATE}") + endif() + if(BUILD_STATIC_LIBS) + set(ENABLE_STATIC "yes") + else() + set(ENABLE_STATIC "no") + endif() + + # Generate a "curl-config" matching this config. + # Consumed variables: + # CC + # CONFIGURE_OPTIONS + # CURLVERSION + # CURL_CA_BUNDLE + # ENABLE_SHARED + # ENABLE_STATIC + # exec_prefix + # includedir + # LIBCURL_PC_CFLAGS + # LIBCURL_PC_LDFLAGS_PRIVATE + # LIBCURL_PC_LIBS_PRIVATE + # libdir + # libext + # prefix + # SSL_BACKENDS + # SUPPORT_FEATURES + # SUPPORT_PROTOCOLS + # VERSIONNUM + configure_file( + "${PROJECT_SOURCE_DIR}/curl-config.in" + "${PROJECT_BINARY_DIR}/curl-config" @ONLY) + install(FILES "${PROJECT_BINARY_DIR}/curl-config" + DESTINATION ${CMAKE_INSTALL_BINDIR} + PERMISSIONS + OWNER_READ OWNER_WRITE OWNER_EXECUTE + GROUP_READ GROUP_EXECUTE + WORLD_READ WORLD_EXECUTE) + + # Generate a pkg-config file matching this config. + # Consumed variables: + # CURLVERSION + # exec_prefix + # includedir + # LIBCURL_PC_CFLAGS + # LIBCURL_PC_CFLAGS_PRIVATE + # LIBCURL_PC_LDFLAGS_PRIVATE + # LIBCURL_PC_LIBS + # LIBCURL_PC_LIBS_PRIVATE + # LIBCURL_PC_REQUIRES + # LIBCURL_PC_REQUIRES_PRIVATE + # libdir + # prefix + # SUPPORT_FEATURES + # SUPPORT_PROTOCOLS + # Documentation: + # https://people.freedesktop.org/~dbn/pkg-config-guide.html + # https://manpages.debian.org/unstable/pkgconf/pkg-config.1.en.html + # https://manpages.debian.org/unstable/pkg-config/pkg-config.1.en.html + # https://www.msys2.org/docs/pkgconfig/ + configure_file( + "${PROJECT_SOURCE_DIR}/libcurl.pc.in" + "${PROJECT_BINARY_DIR}/libcurl.pc" @ONLY) + install(FILES "${PROJECT_BINARY_DIR}/libcurl.pc" + DESTINATION "${CMAKE_INSTALL_LIBDIR}/pkgconfig") + + # Install headers + install(DIRECTORY "${PROJECT_SOURCE_DIR}/include/curl" DESTINATION ${CMAKE_INSTALL_INCLUDEDIR} FILES_MATCHING PATTERN "*.h") -include(CMakePackageConfigHelpers) -write_basic_package_version_file( - "${version_config}" - VERSION ${CURL_VERSION} - COMPATIBILITY SameMajorVersion -) -file(READ "${version_config}" generated_version_config) -file(WRITE "${version_config}" -"if(NOT PACKAGE_FIND_VERSION_RANGE AND PACKAGE_FIND_VERSION_MAJOR STREQUAL \"7\") - # Version 8 satisfies version 7... requirements - set(PACKAGE_FIND_VERSION_MAJOR 8) - set(PACKAGE_FIND_VERSION_COUNT 1) -endif() -${generated_version_config}" -) + include(CMakePackageConfigHelpers) + write_basic_package_version_file("${_version_config}" + VERSION ${_curl_version} + COMPATIBILITY SameMajorVersion) + file(READ "${_version_config}" _generated_version_config) + file(WRITE "${_version_config}" " + if(NOT PACKAGE_FIND_VERSION_RANGE AND PACKAGE_FIND_VERSION_MAJOR STREQUAL \"7\") + # Version 8 satisfies version 7... requirements + set(PACKAGE_FIND_VERSION_MAJOR 8) + set(PACKAGE_FIND_VERSION_COUNT 1) + endif() + ${_generated_version_config}") -# Use: -# * TARGETS_EXPORT_NAME -# * PROJECT_NAME -configure_package_config_file(CMake/curl-config.cmake.in - "${project_config}" - INSTALL_DESTINATION ${CURL_INSTALL_CMAKE_DIR} -) + # Consumed custom variables: + # CMAKE_MINIMUM_REQUIRED_VERSION + # CURLVERSION + # LIBCURL_PC_LIBS_PRIVATE_LIST + # LIB_NAME + # LIB_SELECTED + # LIB_STATIC + # TARGETS_EXPORT_NAME + # CURL_SUPPORTED_FEATURES_LIST + # CURL_SUPPORTED_PROTOCOLS_LIST + # CURL_USE_CMAKECONFIG + # CURL_USE_PKGCONFIG + # HAVE_BROTLI + # HAVE_GSSAPI + # HAVE_LIBIDN2 + # HAVE_LIBZ ZLIB_VERSION_MAJOR + # HAVE_THREADS_POSIX + # HAVE_THREADS_POSIX_BORINGSSL + # HAVE_ZSTD + # USE_ARES + # USE_BACKTRACE + # USE_GNUTLS + # USE_GSASL + # USE_LIBPSL + # USE_LIBSSH + # USE_LIBSSH2 + # USE_LIBUV + # USE_MBEDTLS + # USE_NGHTTP2 + # USE_NGHTTP3 + # USE_NGTCP2 NGTCP2_CRYPTO_BACKEND + # USE_OPENSSL OPENSSL_VERSION_MAJOR + # USE_QUICHE + # USE_RUSTLS + # USE_WIN32_LDAP CURL_DISABLE_LDAP + # USE_WOLFSSL + configure_package_config_file("CMake/curl-config.in.cmake" + "${_project_config}" + INSTALL_DESTINATION ${_install_cmake_dir} + PATH_VARS CMAKE_INSTALL_INCLUDEDIR) -if(CURL_ENABLE_EXPORT_TARGET) - install( - EXPORT "${TARGETS_EXPORT_NAME}" - NAMESPACE "${PROJECT_NAME}::" - DESTINATION ${CURL_INSTALL_CMAKE_DIR} - ) -endif() - -install( - FILES ${version_config} ${project_config} - DESTINATION ${CURL_INSTALL_CMAKE_DIR} -) - -# Workaround for MSVS10 to avoid the Dialog Hell -# FIXME: This could be removed with future version of CMake. -if(MSVC_VERSION EQUAL 1600) - set(CURL_SLN_FILENAME "${CMAKE_CURRENT_BINARY_DIR}/CURL.sln") - if(EXISTS "${CURL_SLN_FILENAME}") - file(APPEND "${CURL_SLN_FILENAME}" "\n# This should be regenerated!\n") + if(CURL_ENABLE_EXPORT_TARGET) + install(EXPORT "${TARGETS_EXPORT_NAME}" + NAMESPACE "${PROJECT_NAME}::" + DESTINATION ${_install_cmake_dir}) endif() + + install( + FILES + ${_version_config} + ${_project_config} + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindBrotli.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindCares.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindGSS.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindGnuTLS.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindLDAP.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindLibbacktrace.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindLibgsasl.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindLibidn2.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindLibpsl.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindLibssh.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindLibssh2.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindLibuv.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindMbedTLS.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindNGHTTP2.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindNGHTTP3.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindNGTCP2.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindNettle.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindQuiche.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindRustls.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindWolfSSL.cmake" + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/FindZstd.cmake" + DESTINATION ${_install_cmake_dir}) + + if(NOT TARGET curl_uninstall) + configure_file( + "${CMAKE_CURRENT_SOURCE_DIR}/CMake/cmake_uninstall.in.cmake" + "${CMAKE_CURRENT_BINARY_DIR}/CMake/cmake_uninstall.cmake" + @ONLY) + + add_custom_target(curl_uninstall + COMMAND ${CMAKE_COMMAND} -P "${CMAKE_CURRENT_BINARY_DIR}/CMake/cmake_uninstall.cmake") + endif() + + if(BUILD_CURL_EXE) + install(FILES "${PROJECT_SOURCE_DIR}/scripts/wcurl" + DESTINATION ${CMAKE_INSTALL_BINDIR} + PERMISSIONS + OWNER_READ OWNER_WRITE OWNER_EXECUTE + GROUP_READ GROUP_EXECUTE + WORLD_READ WORLD_EXECUTE) + endif() + + # The `-DEV` part is important + string(REGEX REPLACE "([0-9]+\.[0-9]+)\.([0-9]+.*)" "\\2" CPACK_PACKAGE_VERSION_PATCH "${_curl_version}") + set(CPACK_GENERATOR "TGZ") + include(CPack) endif() -if(NOT TARGET curl_uninstall) - configure_file( - ${CMAKE_CURRENT_SOURCE_DIR}/CMake/cmake_uninstall.cmake.in - ${CMAKE_CURRENT_BINARY_DIR}/CMake/cmake_uninstall.cmake - IMMEDIATE @ONLY) - - add_custom_target(curl_uninstall - COMMAND ${CMAKE_COMMAND} -P - ${CMAKE_CURRENT_BINARY_DIR}/CMake/cmake_uninstall.cmake) +# Save build info for test runner to pick up and log +set(_cmake_sysroot "") +if(CMAKE_OSX_SYSROOT) + set(_cmake_sysroot ${CMAKE_OSX_SYSROOT}) +elseif(CMAKE_SYSROOT) + set(_cmake_sysroot ${CMAKE_SYSROOT}) +endif() +set(_buildinfo "\ +buildinfo.configure.tool: cmake +buildinfo.configure.command: ${CMAKE_COMMAND} +buildinfo.configure.version: ${CMAKE_VERSION} +buildinfo.configure.args:${_cmake_args} +buildinfo.configure.generator: ${CMAKE_GENERATOR} +buildinfo.configure.make: ${CMAKE_MAKE_PROGRAM} +buildinfo.host.cpu: ${CMAKE_HOST_SYSTEM_PROCESSOR} +buildinfo.host.os: ${CMAKE_HOST_SYSTEM_NAME} +buildinfo.target.cpu: ${CMAKE_SYSTEM_PROCESSOR} +buildinfo.target.os: ${CMAKE_SYSTEM_NAME} +buildinfo.target.flags:${_target_flags} +buildinfo.compiler: ${CMAKE_C_COMPILER_ID} +buildinfo.compiler.version: ${CMAKE_C_COMPILER_VERSION} +buildinfo.sysroot: ${_cmake_sysroot} +") +file(WRITE "${PROJECT_BINARY_DIR}/buildinfo.txt" "# This is a generated file. Do not edit.\n${_buildinfo}") +if(NOT "$ENV{CURL_BUILDINFO}$ENV{CURL_CI}$ENV{CI}" STREQUAL "") + message(STATUS "\n${_buildinfo}") endif() diff --git a/third-party/curl/COPYING b/third-party/curl/COPYING index d1eab3eb93..2f71d999a9 100644 --- a/third-party/curl/COPYING +++ b/third-party/curl/COPYING @@ -1,6 +1,6 @@ COPYRIGHT AND PERMISSION NOTICE -Copyright (c) 1996 - 2023, Daniel Stenberg, , and many +Copyright (c) 1996 - 2026, Daniel Stenberg, , and many contributors, see the THANKS file. All rights reserved. diff --git a/third-party/curl/Dockerfile b/third-party/curl/Dockerfile new file mode 100644 index 0000000000..369583f62f --- /dev/null +++ b/third-party/curl/Dockerfile @@ -0,0 +1,41 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +# Self-contained build environment to match the release environment. +# +# Build and set the timestamp for the date corresponding to the release +# +# docker build --build-arg SOURCE_DATE_EPOCH=1711526400 --build-arg UID=$(id -u) --build-arg GID=$(id -g) -t curl/curl . +# +# Then run commands from within the build environment, for example +# +# docker run --rm -it -u $(id -u):$(id -g) -v $(pwd):/usr/src -w /usr/src curl/curl autoreconf -fi +# docker run --rm -it -u $(id -u):$(id -g) -v $(pwd):/usr/src -w /usr/src curl/curl ./configure --without-ssl --without-libpsl +# docker run --rm -it -u $(id -u):$(id -g) -v $(pwd):/usr/src -w /usr/src curl/curl make +# docker run --rm -it -u $(id -u):$(id -g) -v $(pwd):/usr/src -w /usr/src curl/curl ./scripts/maketgz 8.7.1 +# +# or get into a shell in the build environment, for example +# +# docker run --rm -it -u $(id -u):$(id -g) -v $(pwd):/usr/src -w /usr/src curl/curl bash +# $ autoreconf -fi +# $ ./configure --without-ssl --without-libpsl +# $ make +# $ ./scripts/maketgz 8.7.1 + +# To update, get the latest digest e.g. from https://hub.docker.com/_/debian/tags +FROM debian:bookworm-slim@sha256:96e378d7e6531ac9a15ad505478fcc2e69f371b10f5cdf87857c4b8188404716 + +RUN apt-get update -qq && apt-get install -qq -y --no-install-recommends \ + build-essential make autoconf automake libtool git perl zip zlib1g-dev gawk && \ + rm -rf /var/lib/apt/lists/* + +ARG UID=1000 GID=1000 + +RUN groupadd --gid $GID dev && \ + useradd --uid $UID --gid dev --shell /bin/bash --create-home dev + +USER dev:dev + +ARG SOURCE_DATE_EPOCH +ENV SOURCE_DATE_EPOCH=${SOURCE_DATE_EPOCH:-1} diff --git a/third-party/curl/GIT-INFO b/third-party/curl/GIT-INFO deleted file mode 100644 index 62efbd938c..0000000000 --- a/third-party/curl/GIT-INFO +++ /dev/null @@ -1,44 +0,0 @@ - _ _ ____ _ - ___| | | | _ \| | - / __| | | | |_) | | - | (__| |_| | _ <| |___ - \___|\___/|_| \_\_____| - -GIT-INFO - -This file is only present in git - never in release archives. It contains -information about other files and things that the git repository keeps in its -inner sanctum. - -To build in environments that support configure, after having extracted -everything from git, do this: - -autoreconf -fi -./configure --with-openssl -make - - Daniel uses a ./configure line similar to this for easier development: - - ./configure --disable-shared --enable-debug --enable-maintainer-mode - -In environments that don't support configure (i.e. Microsoft), do this: - -buildconf.bat - - -REQUIREMENTS - -For autoreconf and configure (not buildconf.bat) to work, you need the -following software installed: - - o autoconf 2.57 (or later) - o automake 1.7 (or later) - o libtool 1.4.2 (or later) - o GNU m4 (required by autoconf) - - o nroff + perl - - If you don't have nroff and perl and you for some reason don't want to - install them, you can rename the source file src/tool_hugehelp.c.cvs to - src/tool_hugehelp.c and avoid having to generate this file. This will - give you a stubbed version of the file that doesn't contain actual content. diff --git a/third-party/curl/GIT-INFO.md b/third-party/curl/GIT-INFO.md new file mode 100644 index 0000000000..ee912560fd --- /dev/null +++ b/third-party/curl/GIT-INFO.md @@ -0,0 +1,33 @@ + + _ _ ____ _ + ___| | | | _ \| | + / __| | | | |_) | | + | (__| |_| | _ <| |___ + \___|\___/|_| \_\_____| + +# GIT-INFO + +This file is only present in git - never in release archives. It contains +information about other files and things that the git repository keeps in its +inner sanctum. + +To build in environments that support configure, after having extracted +everything from git, do this: + + autoreconf -fi + ./configure --with-openssl + make + +Daniel uses a configure line similar to this for easier development: + + ./configure --disable-shared --enable-debug --enable-maintainer-mode + +## REQUIREMENTS + +See [docs/INTERNALS.md][0] for requirement details. + +[0]: docs/INTERNALS.md diff --git a/third-party/curl/LICENSES/BSD-3-Clause.txt b/third-party/curl/LICENSES/BSD-3-Clause.txt deleted file mode 100644 index 086d3992cb..0000000000 --- a/third-party/curl/LICENSES/BSD-3-Clause.txt +++ /dev/null @@ -1,11 +0,0 @@ -Copyright (c) . - -Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: - -1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. - -2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. - -3. Neither the name of the copyright holder nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. - -THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. diff --git a/third-party/curl/LICENSES/BSD-4-Clause-UC.txt b/third-party/curl/LICENSES/BSD-4-Clause-UC.txt index 69edbe3242..0fffd039d8 100644 --- a/third-party/curl/LICENSES/BSD-4-Clause-UC.txt +++ b/third-party/curl/LICENSES/BSD-4-Clause-UC.txt @@ -1,15 +1,33 @@ BSD-4-Clause (University of California-Specific) -Copyright [various years] The Regents of the University of California. All rights reserved. +Copyright [various years] The Regents of the University of California. +All rights reserved. -Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: -1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. +1. Redistributions of source code must retain the above copyright notice, this + list of conditions and the following disclaimer. -2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. +2. Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. -3. All advertising materials mentioning features or use of this software must display the following acknowledgement: This product includes software developed by the University of California, Berkeley and its contributors. +3. All advertising materials mentioning features or use of this software must + display the following acknowledgement: This product includes software + developed by the University of California, Berkeley and its contributors. -4. Neither the name of the University nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. +4. Neither the name of the University nor the names of its contributors may be + used to endorse or promote products derived from this software without + specific prior written permission. -THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND ANY +EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED +WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE FOR ANY +DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES +(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; +LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON +ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS +SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. diff --git a/third-party/curl/MacOSX-Framework b/third-party/curl/MacOSX-Framework deleted file mode 100644 index 5ac537633c..0000000000 --- a/third-party/curl/MacOSX-Framework +++ /dev/null @@ -1,160 +0,0 @@ -#!/usr/bin/env bash -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### -# This script performs all of the steps needed to build a -# universal binary libcurl.framework for Mac OS X 10.4 or greater. -# -# Hendrik Visage: -# Generalizations added since Snowleopard (10.6) do not include -# the 10.4u SDK. -# -# Also note: -# 10.5 is the *ONLY* SDK that support PPC64 :( -- 10.6 do not have ppc64 support -#If you need to have PPC64 support then change below to 1 -PPC64_NEEDED=0 -# Apple does not support building for PPC anymore in Xcode 4 and later. -# If you're using Xcode 3 or earlier and need PPC support, then change -# the setting below to 1 -PPC_NEEDED=0 - -# For me the default is to develop for the platform I am on, and if you -#desire compatibility with older versions then change USE_OLD to 1 :) -USE_OLD=0 - -VERSION=`/usr/bin/sed -ne 's/^#define LIBCURL_VERSION "\(.*\)"/\1/p' include/curl/curlver.h` -FRAMEWORK_VERSION=Versions/Release-$VERSION - -#I also wanted to "copy over" the system, and thus the reason I added the -# version to Versions/Release-7.20.1 etc. -# now a simple rsync -vaP libcurl.framework /Library/Frameworks will install it -# and setup the right paths to this version, leaving the system version -# "intact", so you can "fix" it later with the links to Versions/A/... - -DEVELOPER_PATH=`xcode-select --print-path` -# Around Xcode 4.3, SDKs were moved from the Developer folder into the -# MacOSX.platform folder -if test -d "$DEVELOPER_PATH/Platforms/MacOSX.platform/Developer/SDKs"; then - SDK_PATH="$DEVELOPER_PATH/Platforms/MacOSX.platform/Developer/SDKs" -else - SDK_PATH="$DEVELOPER_PATH/SDKs" -fi -OLD_SDK=`ls $SDK_PATH|head -1` -NEW_SDK=`ls -r $SDK_PATH|head -1` - -if test "0"$USE_OLD -gt 0 -then - SDK32=$OLD_SDK -else - SDK32=$NEW_SDK -fi - -MACVER=`echo $SDK32|sed -e s/[a-zA-Z]//g -e s/.\$//` - -SDK32_DIR=$SDK_PATH/$SDK32 -MINVER32='-mmacosx-version-min='$MACVER -if test $PPC_NEEDED -gt 0; then - ARCHES32='-arch i386 -arch ppc' -else - ARCHES32='-arch i386' -fi - -if test $PPC64_NEEDED -gt 0 -then - SDK64=10.5 - ARCHES64='-arch x86_64 -arch ppc64' - SDK64=`ls $SDK_PATH | grep "10\.5" | head -1` -else - ARCHES64='-arch x86_64' - #We "know" that 10.4 and earlier do not support 64bit - OLD_SDK64=`ls $SDK_PATH | grep -v "10\.[0-4]" | head -1` - NEW_SDK64=`ls -r $SDK_PATH | grep -v "10\.[0-4][^0-9]" | head -1` - if test $USE_OLD -gt 0 - then - SDK64=$OLD_SDK64 - else - SDK64=$NEW_SDK64 - fi -fi - -SDK64_DIR=$SDK_PATH/$SDK64 -MACVER64=`echo $SDK64|sed -e s/[a-zA-Z]//g -e s/.\$//` - -MINVER64='-mmacosx-version-min='$MACVER64 - -if test ! -z $SDK32; then - echo "----Configuring libcurl for 32 bit universal framework..." - make clean - ./configure --disable-dependency-tracking --disable-static --with-gssapi --with-secure-transport \ - CFLAGS="-Os -isysroot $SDK32_DIR $ARCHES32" \ - LDFLAGS="-Wl,-syslibroot,$SDK32_DIR $ARCHES32 -Wl,-headerpad_max_install_names" \ - CC=$CC - - echo "----Building 32 bit libcurl..." - make -j `sysctl -n hw.logicalcpu_max` - - echo "----Creating 32 bit framework..." - rm -r libcurl.framework - mkdir -p libcurl.framework/${FRAMEWORK_VERSION}/Resources - cp lib/.libs/libcurl.dylib libcurl.framework/${FRAMEWORK_VERSION}/libcurl - install_name_tool -id @rpath/libcurl.framework/${FRAMEWORK_VERSION}/libcurl libcurl.framework/${FRAMEWORK_VERSION}/libcurl - cp lib/libcurl.plist libcurl.framework/${FRAMEWORK_VERSION}/Resources/Info.plist - mkdir -p libcurl.framework/${FRAMEWORK_VERSION}/Headers/curl - cp include/curl/*.h libcurl.framework/${FRAMEWORK_VERSION}/Headers/curl - pushd libcurl.framework - ln -fs ${FRAMEWORK_VERSION}/libcurl libcurl - ln -fs ${FRAMEWORK_VERSION}/Resources Resources - ln -fs ${FRAMEWORK_VERSION}/Headers Headers - cd Versions - ln -fs $(basename "${FRAMEWORK_VERSION}") Current - - echo Testing for SDK64 - if test -d $SDK64_DIR; then - echo entering... - popd - make clean - echo "----Configuring libcurl for 64 bit universal framework..." - ./configure --disable-dependency-tracking --disable-static --with-gssapi --with-secure-transport \ - CFLAGS="-Os -isysroot $SDK64_DIR $ARCHES64" \ - LDFLAGS="-Wl,-syslibroot,$SDK64_DIR $ARCHES64 -Wl,-headerpad_max_install_names" \ - CC=$CC - - echo "----Building 64 bit libcurl..." - make -j `sysctl -n hw.logicalcpu_max` - - echo "----Appending 64 bit framework to 32 bit framework..." - cp lib/.libs/libcurl.dylib libcurl.framework/${FRAMEWORK_VERSION}/libcurl64 - install_name_tool -id @rpath/libcurl.framework/${FRAMEWORK_VERSION}/libcurl libcurl.framework/${FRAMEWORK_VERSION}/libcurl64 - cp libcurl.framework/${FRAMEWORK_VERSION}/libcurl libcurl.framework/${FRAMEWORK_VERSION}/libcurl32 - pwd - lipo libcurl.framework/${FRAMEWORK_VERSION}/libcurl32 libcurl.framework/${FRAMEWORK_VERSION}/libcurl64 -create -output libcurl.framework/${FRAMEWORK_VERSION}/libcurl - rm libcurl.framework/${FRAMEWORK_VERSION}/libcurl32 libcurl.framework/${FRAMEWORK_VERSION}/libcurl64 - fi - - pwd - lipo -info libcurl.framework/${FRAMEWORK_VERSION}/libcurl - echo "libcurl.framework is built and can now be included in other projects." - echo "Copy libcurl.framework to your bundle's Contents/Frameworks folder, ~/Library/Frameworks or /Library/Frameworks." -else - echo "Building libcurl.framework requires Mac OS X 10.4 or later with the MacOSX10.4/5/6 SDK installed." -fi diff --git a/third-party/curl/Makefile.am b/third-party/curl/Makefile.am index 6c780a849d..83fdadf035 100644 --- a/third-party/curl/Makefile.am +++ b/third-party/curl/Makefile.am @@ -26,171 +26,79 @@ AUTOMAKE_OPTIONS = foreign ACLOCAL_AMFLAGS = -I m4 -CMAKE_DIST = \ - CMake/cmake_uninstall.cmake.in \ - CMake/CMakeConfigurableFile.in \ - CMake/curl-config.cmake.in \ - CMake/CurlSymbolHiding.cmake \ - CMake/CurlTests.c \ - CMake/FindBearSSL.cmake \ - CMake/FindBrotli.cmake \ - CMake/FindCARES.cmake \ - CMake/FindGSS.cmake \ - CMake/FindLibPSL.cmake \ - CMake/FindLibSSH2.cmake \ - CMake/FindMbedTLS.cmake \ - CMake/FindMSH3.cmake \ - CMake/FindNGHTTP2.cmake \ - CMake/FindNGHTTP3.cmake \ - CMake/FindNGTCP2.cmake \ - CMake/FindQUICHE.cmake \ - CMake/FindWolfSSL.cmake \ - CMake/FindZstd.cmake \ - CMake/Macros.cmake \ - CMake/OtherTests.cmake \ - CMake/PickyWarnings.cmake \ - CMake/Platforms/WindowsCache.cmake \ - CMake/Utilities.cmake \ - CMakeLists.txt +CMAKE_DIST = \ + CMake/cmake_uninstall.in.cmake \ + CMake/curl-config.in.cmake \ + CMake/CurlSymbolHiding.cmake \ + CMake/CurlTests.c \ + CMake/FindBrotli.cmake \ + CMake/FindCares.cmake \ + CMake/FindGnuTLS.cmake \ + CMake/FindGSS.cmake \ + CMake/FindLDAP.cmake \ + CMake/FindLibbacktrace.cmake \ + CMake/FindLibgsasl.cmake \ + CMake/FindLibidn2.cmake \ + CMake/FindLibpsl.cmake \ + CMake/FindLibssh.cmake \ + CMake/FindLibssh2.cmake \ + CMake/FindLibuv.cmake \ + CMake/FindMbedTLS.cmake \ + CMake/FindNGHTTP2.cmake \ + CMake/FindNGHTTP3.cmake \ + CMake/FindNGTCP2.cmake \ + CMake/FindNettle.cmake \ + CMake/FindQuiche.cmake \ + CMake/FindRustls.cmake \ + CMake/FindWolfSSL.cmake \ + CMake/FindZstd.cmake \ + CMake/Macros.cmake \ + CMake/OtherTests.cmake \ + CMake/PickyWarnings.cmake \ + CMake/Utilities.cmake \ + CMake/unix-cache.cmake \ + CMake/win32-cache.cmake \ + CMakeLists.txt \ + tests/cmake/CMakeLists.txt \ + tests/cmake/test.c \ + tests/cmake/test.cpp \ + tests/cmake/test.sh -VC10_LIBTMPL = projects/Windows/VC10/lib/libcurl.tmpl -VC10_LIBVCXPROJ = projects/Windows/VC10/lib/libcurl.vcxproj.dist -VC10_LIBVCXPROJ_DEPS = $(VC10_LIBTMPL) Makefile.am lib/Makefile.inc -VC10_SRCTMPL = projects/Windows/VC10/src/curl.tmpl -VC10_SRCVCXPROJ = projects/Windows/VC10/src/curl.vcxproj.dist -VC10_SRCVCXPROJ_DEPS = $(VC10_SRCTMPL) Makefile.am src/Makefile.inc +EXTRA_DIST = CHANGES.md COPYING RELEASE-NOTES Dockerfile .clang-tidy.yml .editorconfig $(CMAKE_DIST) -VC11_LIBTMPL = projects/Windows/VC11/lib/libcurl.tmpl -VC11_LIBVCXPROJ = projects/Windows/VC11/lib/libcurl.vcxproj.dist -VC11_LIBVCXPROJ_DEPS = $(VC11_LIBTMPL) Makefile.am lib/Makefile.inc -VC11_SRCTMPL = projects/Windows/VC11/src/curl.tmpl -VC11_SRCVCXPROJ = projects/Windows/VC11/src/curl.vcxproj.dist -VC11_SRCVCXPROJ_DEPS = $(VC11_SRCTMPL) Makefile.am src/Makefile.inc - -VC12_LIBTMPL = projects/Windows/VC12/lib/libcurl.tmpl -VC12_LIBVCXPROJ = projects/Windows/VC12/lib/libcurl.vcxproj.dist -VC12_LIBVCXPROJ_DEPS = $(VC12_LIBTMPL) Makefile.am lib/Makefile.inc -VC12_SRCTMPL = projects/Windows/VC12/src/curl.tmpl -VC12_SRCVCXPROJ = projects/Windows/VC12/src/curl.vcxproj.dist -VC12_SRCVCXPROJ_DEPS = $(VC12_SRCTMPL) Makefile.am src/Makefile.inc - -VC14_LIBTMPL = projects/Windows/VC14/lib/libcurl.tmpl -VC14_LIBVCXPROJ = projects/Windows/VC14/lib/libcurl.vcxproj.dist -VC14_LIBVCXPROJ_DEPS = $(VC14_LIBTMPL) Makefile.am lib/Makefile.inc -VC14_SRCTMPL = projects/Windows/VC14/src/curl.tmpl -VC14_SRCVCXPROJ = projects/Windows/VC14/src/curl.vcxproj.dist -VC14_SRCVCXPROJ_DEPS = $(VC14_SRCTMPL) Makefile.am src/Makefile.inc - -VC14_10_LIBTMPL = projects/Windows/VC14.10/lib/libcurl.tmpl -VC14_10_LIBVCXPROJ = projects/Windows/VC14.10/lib/libcurl.vcxproj.dist -VC14_10_LIBVCXPROJ_DEPS = $(VC14_10_LIBTMPL) Makefile.am lib/Makefile.inc -VC14_10_SRCTMPL = projects/Windows/VC14.10/src/curl.tmpl -VC14_10_SRCVCXPROJ = projects/Windows/VC14.10/src/curl.vcxproj.dist -VC14_10_SRCVCXPROJ_DEPS = $(VC14_10_SRCTMPL) Makefile.am src/Makefile.inc - -VC14_30_LIBTMPL = projects/Windows/VC14.30/lib/libcurl.tmpl -VC14_30_LIBVCXPROJ = projects/Windows/VC14.30/lib/libcurl.vcxproj.dist -VC14_30_LIBVCXPROJ_DEPS = $(VC14_30_LIBTMPL) Makefile.am lib/Makefile.inc -VC14_30_SRCTMPL = projects/Windows/VC14.30/src/curl.tmpl -VC14_30_SRCVCXPROJ = projects/Windows/VC14.30/src/curl.vcxproj.dist -VC14_30_SRCVCXPROJ_DEPS = $(VC14_30_SRCTMPL) Makefile.am src/Makefile.inc - -VC_DIST = projects/README.md \ - projects/build-openssl.bat \ - projects/build-wolfssl.bat \ - projects/checksrc.bat \ - projects/Windows/VC10/curl-all.sln \ - projects/Windows/VC10/lib/libcurl.sln \ - projects/Windows/VC10/lib/libcurl.vcxproj.filters \ - projects/Windows/VC10/src/curl.sln \ - projects/Windows/VC10/src/curl.vcxproj.filters \ - projects/Windows/VC11/curl-all.sln \ - projects/Windows/VC11/lib/libcurl.sln \ - projects/Windows/VC11/lib/libcurl.vcxproj.filters \ - projects/Windows/VC11/src/curl.sln \ - projects/Windows/VC11/src/curl.vcxproj.filters \ - projects/Windows/VC12/curl-all.sln \ - projects/Windows/VC12/lib/libcurl.sln \ - projects/Windows/VC12/lib/libcurl.vcxproj.filters \ - projects/Windows/VC12/src/curl.sln \ - projects/Windows/VC12/src/curl.vcxproj.filters \ - projects/Windows/VC14/curl-all.sln \ - projects/Windows/VC14/lib/libcurl.sln \ - projects/Windows/VC14/lib/libcurl.vcxproj.filters \ - projects/Windows/VC14/src/curl.sln \ - projects/Windows/VC14/src/curl.vcxproj.filters \ - projects/Windows/VC14.10/curl-all.sln \ - projects/Windows/VC14.10/lib/libcurl.sln \ - projects/Windows/VC14.10/lib/libcurl.vcxproj.filters \ - projects/Windows/VC14.10/src/curl.sln \ - projects/Windows/VC14.10/src/curl.vcxproj.filters \ - projects/Windows/VC14.30/curl-all.sln \ - projects/Windows/VC14.30/lib/libcurl.sln \ - projects/Windows/VC14.30/lib/libcurl.vcxproj.filters \ - projects/Windows/VC14.30/src/curl.sln \ - projects/Windows/VC14.30/src/curl.vcxproj.filters \ - projects/generate.bat \ - projects/wolfssl_options.h \ - projects/wolfssl_override.props - -WINBUILD_DIST = winbuild/README.md winbuild/gen_resp_file.bat \ - winbuild/MakefileBuild.vc winbuild/Makefile.vc - -PLAN9_DIST = plan9/include/mkfile \ - plan9/include/mkfile \ - plan9/mkfile.proto \ - plan9/mkfile \ - plan9/README \ - plan9/lib/mkfile.inc \ - plan9/lib/mkfile \ - plan9/src/mkfile.inc \ - plan9/src/mkfile - -EXTRA_DIST = CHANGES COPYING maketgz Makefile.dist curl-config.in \ - RELEASE-NOTES buildconf libcurl.pc.in MacOSX-Framework $(CMAKE_DIST) \ - $(VC_DIST) $(WINBUILD_DIST) $(PLAN9_DIST) lib/libcurl.vers.in buildconf.bat \ - libcurl.def - -CLEANFILES = $(VC10_LIBVCXPROJ) $(VC10_SRCVCXPROJ) $(VC11_LIBVCXPROJ) \ - $(VC11_SRCVCXPROJ) $(VC12_LIBVCXPROJ) $(VC12_SRCVCXPROJ) $(VC14_LIBVCXPROJ) \ - $(VC14_SRCVCXPROJ) $(VC14_10_LIBVCXPROJ) $(VC14_10_SRCVCXPROJ) \ - $(VC14_30_LIBVCXPROJ) $(VC14_30_SRCVCXPROJ) +DISTCLEANFILES = buildinfo.txt bin_SCRIPTS = curl-config -SUBDIRS = lib src -DIST_SUBDIRS = $(SUBDIRS) tests packages scripts include docs +SUBDIRS = lib docs src scripts +DIST_SUBDIRS = $(SUBDIRS) tests projects include docs pkgconfigdir = $(libdir)/pkgconfig pkgconfig_DATA = libcurl.pc -# List of files required to generate VC IDE .dsp, .vcproj and .vcxproj files -include lib/Makefile.inc -include src/Makefile.inc - dist-hook: rm -rf $(top_builddir)/tests/log - find $(distdir) -name "*.dist" -exec rm {} \; - (distit=`find $(srcdir) -name "*.dist" | grep -v ./ares/`; \ + find $(distdir) -name "*.dist" -exec rm -- {} \; + (distit=`find $(srcdir) -name "*.dist" | grep -v Makefile`; \ for file in $$distit; do \ strip=`echo $$file | sed -e s/^$(srcdir)// -e s/\.dist//`; \ cp -p $$file $(distdir)$$strip; \ done) -html: - cd docs && $(MAKE) html - -pdf: - cd docs && $(MAKE) pdf - check: test examples check-docs if CROSSCOMPILING test-full: test +test-nonflaky: test test-torture: test +test-event: test +test-am: test +test-ci: test +pytest: test +pytest-ci: test test: - @echo "NOTICE: we can't run the tests when cross-compiling!" + @echo "NOTICE: we cannot run the tests when cross-compiling!" else @@ -215,6 +123,12 @@ test-am: test-ci: @(cd tests; $(MAKE) all ci-test) +pytest: + @(cd tests; $(MAKE) all default-pytest) + +pytest-ci: + @(cd tests; $(MAKE) all ci-pytest) + endif examples: @@ -223,58 +137,17 @@ examples: check-docs: @(cd docs/libcurl; $(MAKE) check) -# Build source and binary rpms. For rpm-3.0 and above, the ~/.rpmmacros -# must contain the following line: -# %_topdir /home/loic/local/rpm -# and that /home/loic/local/rpm contains the directory SOURCES, BUILD etc. -# -# cd /home/loic/local/rpm ; mkdir -p SOURCES BUILD RPMS/i386 SPECS SRPMS -# -# If additional configure flags are needed to build the package, add the -# following in ~/.rpmmacros -# %configure CFLAGS="%{optflags}" ./configure %{_target_platform} --prefix=%{_prefix} ${AM_CONFIGFLAGS} -# and run make rpm in the following way: -# AM_CONFIGFLAGS='--with-uri=/home/users/loic/local/RedHat-6.2' make rpm -# - -rpms: - $(MAKE) RPMDIST=curl rpm - $(MAKE) RPMDIST=curl-ssl rpm - -rpm: - RPM_TOPDIR=`rpm --showrc | $(PERL) -n -e 'print if(s/.*_topdir\s+(.*)/$$1/)'` ; \ - cp $(srcdir)/packages/Linux/RPM/$(RPMDIST).spec $$RPM_TOPDIR/SPECS ; \ - cp $(PACKAGE)-$(VERSION).tar.gz $$RPM_TOPDIR/SOURCES ; \ - rpm -ba --clean --rmsource $$RPM_TOPDIR/SPECS/$(RPMDIST).spec ; \ - mv $$RPM_TOPDIR/RPMS/i386/$(RPMDIST)-*.rpm . ; \ - mv $$RPM_TOPDIR/SRPMS/$(RPMDIST)-*.src.rpm . - -# -# Build a Solaris pkgadd format file -# run 'make pkgadd' once you've done './configure' and 'make' to make a Solaris pkgadd format -# file (which ends up back in this directory). -# The pkgadd file is in 'pkgtrans' format, so to install on Solaris, do -# pkgadd -d ./HAXXcurl-* -# - -# gak - libtool requires an absolute directory, hence the pwd below... -pkgadd: - umask 022 ; \ - $(MAKE) install DESTDIR=`/bin/pwd`/packages/Solaris/root ; \ - cat COPYING > $(srcdir)/packages/Solaris/copyright ; \ - cd $(srcdir)/packages/Solaris && $(MAKE) package - -# -# Build a cygwin binary tarball installation file -# resulting .tar.bz2 file will end up at packages/Win32/cygwin -cygwinbin: - $(MAKE) -C packages/Win32/cygwin cygwinbin - # We extend the standard install with a custom hook: +if BUILD_DOCS install-data-hook: (cd include && $(MAKE) install) (cd docs && $(MAKE) install) (cd docs/libcurl && $(MAKE) install) +else +install-data-hook: + (cd include && $(MAKE) install) + (cd docs && $(MAKE) install) +endif # We extend the standard uninstall with a custom hook: uninstall-hook: @@ -296,319 +169,17 @@ checksrc: (cd tests && $(MAKE) checksrc) (cd include/curl && $(MAKE) checksrc) (cd docs/examples && $(MAKE) checksrc) - (cd packages && $(MAKE) checksrc) + (cd projects && $(MAKE) checksrc) -.PHONY: vc-ide +badwords: + @PERL@ $(top_srcdir)/scripts/badwords-all -vc-ide: $(VC10_LIBVCXPROJ_DEPS) $(VC10_SRCVCXPROJ_DEPS) \ - $(VC11_LIBVCXPROJ_DEPS) $(VC11_SRCVCXPROJ_DEPS) $(VC12_LIBVCXPROJ_DEPS) \ - $(VC12_SRCVCXPROJ_DEPS) $(VC14_LIBVCXPROJ_DEPS) $(VC14_SRCVCXPROJ_DEPS) \ - $(VC14_10_LIBVCXPROJ_DEPS) $(VC14_10_SRCVCXPROJ_DEPS) \ - $(VC14_30_LIBVCXPROJ_DEPS) $(VC14_30_SRCVCXPROJ_DEPS) - @(win32_lib_srcs='$(LIB_CFILES)'; \ - win32_lib_hdrs='$(LIB_HFILES) config-win32.h'; \ - win32_lib_rc='$(LIB_RCFILES)'; \ - win32_lib_vauth_srcs='$(LIB_VAUTH_CFILES)'; \ - win32_lib_vauth_hdrs='$(LIB_VAUTH_HFILES)'; \ - win32_lib_vquic_srcs='$(LIB_VQUIC_CFILES)'; \ - win32_lib_vquic_hdrs='$(LIB_VQUIC_HFILES)'; \ - win32_lib_vssh_srcs='$(LIB_VSSH_CFILES)'; \ - win32_lib_vssh_hdrs='$(LIB_VSSH_HFILES)'; \ - win32_lib_vtls_srcs='$(LIB_VTLS_CFILES)'; \ - win32_lib_vtls_hdrs='$(LIB_VTLS_HFILES)'; \ - win32_src_srcs='$(CURL_CFILES)'; \ - win32_src_hdrs='$(CURL_HFILES)'; \ - win32_src_rc='$(CURL_RCFILES)'; \ - win32_src_x_srcs='$(CURLX_CFILES)'; \ - win32_src_x_hdrs='$(CURLX_HFILES) ../lib/config-win32.h'; \ - \ - sorted_lib_srcs=`for file in $$win32_lib_srcs; do echo $$file; done | sort`; \ - sorted_lib_hdrs=`for file in $$win32_lib_hdrs; do echo $$file; done | sort`; \ - sorted_lib_vauth_srcs=`for file in $$win32_lib_vauth_srcs; do echo $$file; done | sort`; \ - sorted_lib_vauth_hdrs=`for file in $$win32_lib_vauth_hdrs; do echo $$file; done | sort`; \ - sorted_lib_vquic_srcs=`for file in $$win32_lib_vquic_srcs; do echo $$file; done | sort`; \ - sorted_lib_vquic_hdrs=`for file in $$win32_lib_vquic_hdrs; do echo $$file; done | sort`; \ - sorted_lib_vssh_srcs=`for file in $$win32_lib_vssh_srcs; do echo $$file; done | sort`; \ - sorted_lib_vssh_hdrs=`for file in $$win32_lib_vssh_hdrs; do echo $$file; done | sort`; \ - sorted_lib_vtls_srcs=`for file in $$win32_lib_vtls_srcs; do echo $$file; done | sort`; \ - sorted_lib_vtls_hdrs=`for file in $$win32_lib_vtls_hdrs; do echo $$file; done | sort`; \ - sorted_src_srcs=`for file in $$win32_src_srcs; do echo $$file; done | sort`; \ - sorted_src_hdrs=`for file in $$win32_src_hdrs; do echo $$file; done | sort`; \ - sorted_src_x_srcs=`for file in $$win32_src_x_srcs; do echo $$file; done | sort`; \ - sorted_src_x_hdrs=`for file in $$win32_src_x_hdrs; do echo $$file; done | sort`; \ - \ - awk_code='\ -function gen_element(type, dir, file)\ -{\ - sub(/vauth\//, "", file);\ - sub(/vquic\//, "", file);\ - sub(/vssh\//, "", file);\ - sub(/vtls\//, "", file);\ -\ - spaces=" ";\ - if(dir == "lib\\vauth" ||\ - dir == "lib\\vquic" ||\ - dir == "lib\\vssh" ||\ - dir == "lib\\vtls")\ - tabs=" ";\ - else\ - tabs=" ";\ -\ - if(type == "dsp") {\ - printf("# Begin Source File\r\n");\ - printf("\r\n");\ - printf("SOURCE=..\\..\\..\\..\\%s\\%s\r\n", dir, file);\ - printf("# End Source File\r\n");\ - }\ - else if(type == "vcproj1") {\ - printf("%s\r\n",\ - tabs, dir, file);\ - printf("%s\r\n", tabs);\ - }\ - else if(type == "vcproj2") {\ - printf("%s\r\n", tabs);\ - printf("%s\r\n", tabs);\ - }\ - else if(type == "vcxproj") {\ - i = index(file, ".");\ - ext = substr(file, i == 0 ? 0 : i + 1);\ -\ - if(ext == "c")\ - printf("%s\r\n",\ - spaces, dir, file);\ - else if(ext == "h")\ - printf("%s\r\n",\ - spaces, dir, file);\ - else if(ext == "rc")\ - printf("%s\r\n",\ - spaces, dir, file);\ - }\ -}\ -\ -{\ -\ - if($$0 == "CURL_LIB_C_FILES") {\ - split(lib_srcs, arr);\ - for(val in arr) gen_element(proj_type, "lib", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_H_FILES") {\ - split(lib_hdrs, arr);\ - for(val in arr) gen_element(proj_type, "lib", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_RC_FILES") {\ - split(lib_rc, arr);\ - for(val in arr) gen_element(proj_type, "lib", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_VAUTH_C_FILES") {\ - split(lib_vauth_srcs, arr);\ - for(val in arr) gen_element(proj_type, "lib\\vauth", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_VAUTH_H_FILES") {\ - split(lib_vauth_hdrs, arr);\ - for(val in arr) gen_element(proj_type, "lib\\vauth", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_VQUIC_C_FILES") {\ - split(lib_vquic_srcs, arr);\ - for(val in arr) gen_element(proj_type, "lib\\vquic", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_VQUIC_H_FILES") {\ - split(lib_vquic_hdrs, arr);\ - for(val in arr) gen_element(proj_type, "lib\\vquic", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_VSSH_C_FILES") {\ - split(lib_vssh_srcs, arr);\ - for(val in arr) gen_element(proj_type, "lib\\vssh", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_VSSH_H_FILES") {\ - split(lib_vssh_hdrs, arr);\ - for(val in arr) gen_element(proj_type, "lib\\vssh", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_VTLS_C_FILES") {\ - split(lib_vtls_srcs, arr);\ - for(val in arr) gen_element(proj_type, "lib\\vtls", arr[val]);\ - }\ - else if($$0 == "CURL_LIB_VTLS_H_FILES") {\ - split(lib_vtls_hdrs, arr);\ - for(val in arr) gen_element(proj_type, "lib\\vtls", arr[val]);\ - }\ - else if($$0 == "CURL_SRC_C_FILES") {\ - split(src_srcs, arr);\ - for(val in arr) gen_element(proj_type, "src", arr[val]);\ - }\ - else if($$0 == "CURL_SRC_H_FILES") {\ - split(src_hdrs, arr);\ - for(val in arr) gen_element(proj_type, "src", arr[val]);\ - }\ - else if($$0 == "CURL_SRC_RC_FILES") {\ - split(src_rc, arr);\ - for(val in arr) gen_element(proj_type, "src", arr[val]);\ - }\ - else if($$0 == "CURL_SRC_X_C_FILES") {\ - split(src_x_srcs, arr);\ - for(val in arr) {\ - sub(/..\/lib\//, "", arr[val]);\ - gen_element(proj_type, "lib", arr[val]);\ - }\ - }\ - else if($$0 == "CURL_SRC_X_H_FILES") {\ - split(src_x_hdrs, arr);\ - for(val in arr) {\ - sub(/..\/lib\//, "", arr[val]);\ - gen_element(proj_type, "lib", arr[val]);\ - }\ - }\ - else\ - printf("%s\r\n", $$0);\ -}';\ - \ - echo "generating '$(VC10_LIBVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v lib_srcs="$$sorted_lib_srcs" \ - -v lib_hdrs="$$sorted_lib_hdrs" \ - -v lib_rc="$$win32_lib_rc" \ - -v lib_vauth_srcs="$$sorted_lib_vauth_srcs" \ - -v lib_vauth_hdrs="$$sorted_lib_vauth_hdrs" \ - -v lib_vquic_srcs="$$sorted_lib_vquic_srcs" \ - -v lib_vquic_hdrs="$$sorted_lib_vquic_hdrs" \ - -v lib_vssh_srcs="$$sorted_lib_vssh_srcs" \ - -v lib_vssh_hdrs="$$sorted_lib_vssh_hdrs" \ - -v lib_vtls_srcs="$$sorted_lib_vtls_srcs" \ - -v lib_vtls_hdrs="$$sorted_lib_vtls_hdrs" \ - "$$awk_code" $(srcdir)/$(VC10_LIBTMPL) > $(VC10_LIBVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC10_SRCVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v src_srcs="$$sorted_src_srcs" \ - -v src_hdrs="$$sorted_src_hdrs" \ - -v src_rc="$$win32_src_rc" \ - -v src_x_srcs="$$sorted_src_x_srcs" \ - -v src_x_hdrs="$$sorted_src_x_hdrs" \ - "$$awk_code" $(srcdir)/$(VC10_SRCTMPL) > $(VC10_SRCVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC11_LIBVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v lib_srcs="$$sorted_lib_srcs" \ - -v lib_hdrs="$$sorted_lib_hdrs" \ - -v lib_rc="$$win32_lib_rc" \ - -v lib_vauth_srcs="$$sorted_lib_vauth_srcs" \ - -v lib_vauth_hdrs="$$sorted_lib_vauth_hdrs" \ - -v lib_vquic_srcs="$$sorted_lib_vquic_srcs" \ - -v lib_vquic_hdrs="$$sorted_lib_vquic_hdrs" \ - -v lib_vssh_srcs="$$sorted_lib_vssh_srcs" \ - -v lib_vssh_hdrs="$$sorted_lib_vssh_hdrs" \ - -v lib_vtls_srcs="$$sorted_lib_vtls_srcs" \ - -v lib_vtls_hdrs="$$sorted_lib_vtls_hdrs" \ - "$$awk_code" $(srcdir)/$(VC11_LIBTMPL) > $(VC11_LIBVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC11_SRCVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v src_srcs="$$sorted_src_srcs" \ - -v src_hdrs="$$sorted_src_hdrs" \ - -v src_rc="$$win32_src_rc" \ - -v src_x_srcs="$$sorted_src_x_srcs" \ - -v src_x_hdrs="$$sorted_src_x_hdrs" \ - "$$awk_code" $(srcdir)/$(VC11_SRCTMPL) > $(VC11_SRCVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC12_LIBVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v lib_srcs="$$sorted_lib_srcs" \ - -v lib_hdrs="$$sorted_lib_hdrs" \ - -v lib_rc="$$win32_lib_rc" \ - -v lib_vauth_srcs="$$sorted_lib_vauth_srcs" \ - -v lib_vauth_hdrs="$$sorted_lib_vauth_hdrs" \ - -v lib_vquic_srcs="$$sorted_lib_vquic_srcs" \ - -v lib_vquic_hdrs="$$sorted_lib_vquic_hdrs" \ - -v lib_vssh_srcs="$$sorted_lib_vssh_srcs" \ - -v lib_vssh_hdrs="$$sorted_lib_vssh_hdrs" \ - -v lib_vtls_srcs="$$sorted_lib_vtls_srcs" \ - -v lib_vtls_hdrs="$$sorted_lib_vtls_hdrs" \ - "$$awk_code" $(srcdir)/$(VC12_LIBTMPL) > $(VC12_LIBVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC12_SRCVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v src_srcs="$$sorted_src_srcs" \ - -v src_hdrs="$$sorted_src_hdrs" \ - -v src_rc="$$win32_src_rc" \ - -v src_x_srcs="$$sorted_src_x_srcs" \ - -v src_x_hdrs="$$sorted_src_x_hdrs" \ - "$$awk_code" $(srcdir)/$(VC12_SRCTMPL) > $(VC12_SRCVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC14_LIBVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v lib_srcs="$$sorted_lib_srcs" \ - -v lib_hdrs="$$sorted_lib_hdrs" \ - -v lib_rc="$$win32_lib_rc" \ - -v lib_vauth_srcs="$$sorted_lib_vauth_srcs" \ - -v lib_vauth_hdrs="$$sorted_lib_vauth_hdrs" \ - -v lib_vquic_srcs="$$sorted_lib_vquic_srcs" \ - -v lib_vquic_hdrs="$$sorted_lib_vquic_hdrs" \ - -v lib_vssh_srcs="$$sorted_lib_vssh_srcs" \ - -v lib_vssh_hdrs="$$sorted_lib_vssh_hdrs" \ - -v lib_vtls_srcs="$$sorted_lib_vtls_srcs" \ - -v lib_vtls_hdrs="$$sorted_lib_vtls_hdrs" \ - "$$awk_code" $(srcdir)/$(VC14_LIBTMPL) > $(VC14_LIBVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC14_SRCVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v src_srcs="$$sorted_src_srcs" \ - -v src_hdrs="$$sorted_src_hdrs" \ - -v src_rc="$$win32_src_rc" \ - -v src_x_srcs="$$sorted_src_x_srcs" \ - -v src_x_hdrs="$$sorted_src_x_hdrs" \ - "$$awk_code" $(srcdir)/$(VC14_SRCTMPL) > $(VC14_SRCVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC14_10_LIBVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v lib_srcs="$$sorted_lib_srcs" \ - -v lib_hdrs="$$sorted_lib_hdrs" \ - -v lib_rc="$$win32_lib_rc" \ - -v lib_vauth_srcs="$$sorted_lib_vauth_srcs" \ - -v lib_vauth_hdrs="$$sorted_lib_vauth_hdrs" \ - -v lib_vquic_srcs="$$sorted_lib_vquic_srcs" \ - -v lib_vquic_hdrs="$$sorted_lib_vquic_hdrs" \ - -v lib_vssh_srcs="$$sorted_lib_vssh_srcs" \ - -v lib_vssh_hdrs="$$sorted_lib_vssh_hdrs" \ - -v lib_vtls_srcs="$$sorted_lib_vtls_srcs" \ - -v lib_vtls_hdrs="$$sorted_lib_vtls_hdrs" \ - "$$awk_code" $(srcdir)/$(VC14_10_LIBTMPL) > $(VC14_10_LIBVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC14_10_SRCVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v src_srcs="$$sorted_src_srcs" \ - -v src_hdrs="$$sorted_src_hdrs" \ - -v src_rc="$$win32_src_rc" \ - -v src_x_srcs="$$sorted_src_x_srcs" \ - -v src_x_hdrs="$$sorted_src_x_hdrs" \ - "$$awk_code" $(srcdir)/$(VC14_10_SRCTMPL) > $(VC14_10_SRCVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC14_30_LIBVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v lib_srcs="$$sorted_lib_srcs" \ - -v lib_hdrs="$$sorted_lib_hdrs" \ - -v lib_rc="$$win32_lib_rc" \ - -v lib_vauth_srcs="$$sorted_lib_vauth_srcs" \ - -v lib_vauth_hdrs="$$sorted_lib_vauth_hdrs" \ - -v lib_vquic_srcs="$$sorted_lib_vquic_srcs" \ - -v lib_vquic_hdrs="$$sorted_lib_vquic_hdrs" \ - -v lib_vssh_srcs="$$sorted_lib_vssh_srcs" \ - -v lib_vssh_hdrs="$$sorted_lib_vssh_hdrs" \ - -v lib_vtls_srcs="$$sorted_lib_vtls_srcs" \ - -v lib_vtls_hdrs="$$sorted_lib_vtls_hdrs" \ - "$$awk_code" $(srcdir)/$(VC14_30_LIBTMPL) > $(VC14_30_LIBVCXPROJ) || { exit 1; }; \ - \ - echo "generating '$(VC14_30_SRCVCXPROJ)'"; \ - awk -v proj_type=vcxproj \ - -v src_srcs="$$sorted_src_srcs" \ - -v src_hdrs="$$sorted_src_hdrs" \ - -v src_rc="$$win32_src_rc" \ - -v src_x_srcs="$$sorted_src_x_srcs" \ - -v src_x_hdrs="$$sorted_src_x_hdrs" \ - "$$awk_code" $(srcdir)/$(VC14_30_SRCTMPL) > $(VC14_30_SRCVCXPROJ) || { exit 1; };) +lint: badwords checksrc + @PERL@ $(top_srcdir)/scripts/spacecheck.pl tidy: (cd src && $(MAKE) tidy) (cd lib && $(MAKE) tidy) + +clean-local: + (cd tests && $(MAKE) clean) diff --git a/third-party/curl/Makefile.dist b/third-party/curl/Makefile.dist deleted file mode 100644 index a5818e1da5..0000000000 --- a/third-party/curl/Makefile.dist +++ /dev/null @@ -1,92 +0,0 @@ -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### - -all: - ./configure - make - -ssl: - ./configure --with-openssl - make - -mingw32: - $(MAKE) -C lib -f Makefile.mk - $(MAKE) -C src -f Makefile.mk - -mingw32-clean: - $(MAKE) -C lib -f Makefile.mk clean - $(MAKE) -C src -f Makefile.mk clean - $(MAKE) -C docs/examples -f Makefile.mk clean - -mingw32-vclean mingw32-distclean: - $(MAKE) -C lib -f Makefile.mk vclean - $(MAKE) -C src -f Makefile.mk vclean - $(MAKE) -C docs/examples -f Makefile.mk vclean - -mingw32-examples%: - $(MAKE) -C docs/examples -f Makefile.mk CFG=$@ - -mingw32%: - $(MAKE) -C lib -f Makefile.mk CFG=$@ - $(MAKE) -C src -f Makefile.mk CFG=$@ - -vc: - cd winbuild - nmake /f Makefile.vc MACHINE=x86 - -vc-x64: - cd winbuild - nmake /f Makefile.vc MACHINE=x64 - -djgpp%: - $(MAKE) -C lib -f Makefile.mk CFG=$@ CROSSPREFIX=i586-pc-msdosdjgpp- - $(MAKE) -C src -f Makefile.mk CFG=$@ CROSSPREFIX=i586-pc-msdosdjgpp- - -cygwin: - ./configure - make - -cygwin-ssl: - ./configure --with-openssl - make - -amiga%: - $(MAKE) -C lib -f Makefile.mk CFG=$@ CROSSPREFIX=m68k-amigaos- - $(MAKE) -C src -f Makefile.mk CFG=$@ CROSSPREFIX=m68k-amigaos- - -unix: all - -unix-ssl: ssl - -linux: all - -linux-ssl: ssl - -ca-bundle: scripts/mk-ca-bundle.pl - @echo "generate a fresh ca-bundle.crt" - @perl $< -b -l -u lib/ca-bundle.crt - -ca-firefox: lib/firefox-db2pem.sh - @echo "generate a fresh ca-bundle.crt" - ./lib/firefox-db2pem.sh lib/ca-bundle.crt diff --git a/third-party/curl/README b/third-party/curl/README index f5efbd70a6..4ee7e43a2c 100644 --- a/third-party/curl/README +++ b/third-party/curl/README @@ -15,7 +15,8 @@ README available to be used by your software. Read the libcurl.3 man page to learn how. - You find answers to the most frequent questions we get in the FAQ document. + You find answers to the most frequent questions we get in the FAQ.md + document. Study the COPYING file for distribution terms. @@ -32,24 +33,18 @@ WEBSITE Visit the curl website for the latest news and downloads: - https://curl.se/ + https://curl.se/ GIT To download the latest source code off the GIT server, do this: - git clone https://github.com/curl/curl.git + git clone https://github.com/curl/curl (you will get a directory named curl created, filled with the source code) SECURITY PROBLEMS - Report suspected security problems via our HackerOne page and not in public. + Report suspected security problems privately and not in public. - https://hackerone.com/curl - -NOTICE - - Curl contains pieces of source code that is Copyright (c) 1998, 1999 - Kungliga Tekniska Högskolan. This notice is included here to comply with the - distribution terms. + https://curl.se/dev/vuln-disclosure.html diff --git a/third-party/curl/README.md b/third-party/curl/README.md index 8e58662603..9f77de607b 100644 --- a/third-party/curl/README.md +++ b/third-party/curl/README.md @@ -6,26 +6,33 @@ SPDX-License-Identifier: curl # [![curl logo](https://curl.se/logo/curl-logo.svg)](https://curl.se/) -Curl is a command-line tool for transferring data specified with URL -syntax. Find out how to use curl by reading [the curl.1 man -page](https://curl.se/docs/manpage.html) or [the MANUAL -document](https://curl.se/docs/manual.html). Find out how to install Curl -by reading [the INSTALL document](https://curl.se/docs/install.html). +curl is a command-line tool for transferring data from or to a server using +URLs. It supports these protocols: DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, +HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, RTSP, SCP, +SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. + +Learn how to use curl by reading [the +man page](https://curl.se/docs/manpage.html) or [everything +curl](https://everything.curl.dev/). + +Find out how to install curl by reading [the INSTALL +document](https://curl.se/docs/install.html). libcurl is the library curl is using to do its job. It is readily available to -be used by your software. Read [the libcurl.3 man -page](https://curl.se/libcurl/c/libcurl.html) to learn how. +be used by your software. Read [the libcurl +man page](https://curl.se/libcurl/c/libcurl.html) to learn how. -You can find answers to the most frequent questions we get in [the FAQ -document](https://curl.se/docs/faq.html). +## Open Source -Study [the COPYING file](https://curl.se/docs/copyright.html) for -distribution terms. +curl is Open Source and is distributed under an MIT-like +[license](https://curl.se/docs/copyright.html). ## Contact -If you have problems, questions, ideas or suggestions, please contact us by -posting to a suitable [mailing list](https://curl.se/mail/). +Contact us on a suitable [mailing list](https://curl.se/mail/) or +use GitHub [issues](https://github.com/curl/curl/issues)/ +[pull requests](https://github.com/curl/curl/pulls)/ +[discussions](https://github.com/curl/curl/discussions). All contributors to the project are listed in [the THANKS document](https://curl.se/docs/thanks.html). @@ -37,31 +44,22 @@ applications using (lib)curl visit [the support page](https://curl.se/support.ht ## Website -Visit the [curl website](https://curl.se/) for the latest news and -downloads. +Visit the [curl website](https://curl.se/) for the latest news and downloads. -## Git +## Source code -To download the latest source from the Git server, do this: +Download the latest source from the Git server: - git clone https://github.com/curl/curl.git - -(you will get a directory named curl created, filled with the source code) + git clone https://github.com/curl/curl ## Security problems -Report suspected security problems via [our HackerOne -page](https://hackerone.com/curl) and not in public. - -## Notice - -Curl contains pieces of source code that is Copyright (c) 1998, 1999 Kungliga -Tekniska Högskolan. This notice is included here to comply with the -distribution terms. +Report suspected security problems +[privately](https://curl.se/dev/vuln-disclosure.html) and not in public. ## Backers -Thank you to all our backers! 🙠[Become a backer](https://opencollective.com/curl#section-contribute). +Thank you to all our backers :pray: [Become a backer](https://opencollective.com/curl#section-contribute). ## Sponsors diff --git a/third-party/curl/RELEASE-NOTES b/third-party/curl/RELEASE-NOTES index 0fc352c458..f6f67d988c 100644 --- a/third-party/curl/RELEASE-NOTES +++ b/third-party/curl/RELEASE-NOTES @@ -1,401 +1,624 @@ -curl and libcurl 8.3.0 +curl and libcurl 8.21.0 - Public curl releases: 251 - Command line options: 257 - curl_easy_setopt() options: 303 - Public functions in libcurl: 92 - Contributors: 2977 + Public curl releases: 275 + Command line options: 274 + curl_easy_setopt() options: 308 + Public functions in libcurl: 100 + Authors: 1489 + Contributors: 3731 This release includes the following changes: - o curl: make %output{} in -w specify a file to write to [36] - o gskit: remove [71] - o lib: --disable-bindlocal builds curl without local binding support - o nss: remove support for this TLS library [10] - o tool: add "variable" support [1] - o trace: make tracing available in non-debug builds [41] - o url: change default value for CURLOPT_MAXREDIRS to 30 [46] - o urlapi: CURLU_PUNY2IDN - convert from punycode to IDN name [54] - o wolfssl: support loading system CA certificates [8] + o curl: named globs in output file name for upload glob references [77] + o HTTP/3: add proxy CONNECT and MASQUE CONNECT-UDP support (ngtcp2 QUIC) [53] + o http2: remove stream dependency tracking [40] + o lib: drop support for CURLAUTH_DIGEST_IE [4] + o libssh: add support for SHA256 host public keys [57] + o tool_urlglob: add named globs [92] This release includes the following bugfixes: - o altsvc: accept and parse IPv6 addresses in response headers [113] - o asyn-ares: reduce timeout to 2000ms [148] - o aws-sigv4: canonicalize the query [127] - o aws-sigv4: fix having date header twice in some cases [141] - o aws-sigv4: handle no-value user header entries [159] - o bearssl: don't load CA certs when peer verification is disabled [33] - o bearssl: handshake fix, provide proper get_select_socks() implementation [99] - o build: fix portability of mancheck and checksrc targets - o build: streamline non-UWP wincrypt detections [87] - o c-hyper: adjust the hyper to curlcode conversion [52] - o c-hyper: fix memory leaks in `Curl_http` [126] - o cf-haproxy: make CURLOPT_HAPROXY_CLIENT_IP set the *source* IP [61] - o cf-socket: log successful interface bind [39] - o CI/cirrus: disable python install on FreeBSD [83] - o CI: add a 32-bit i686 Linux build [158] - o CI: add caching to many jobs [19] - o CI: move on to ngtcp2 v0.19.1 [154] - o CI: move the Alpine build from Cirrus to GHA - o CI: ngtcp2-linux: use separate caches for tls libraries [125] - o CI: remove Windows builds from Cirrus, without replacement [131] - o CI: switch macOS ARM build from Cirrus to Circle CI - o CI: use master again for wolfssl - o cirrus: install everthing with pkg, avoid pip [110] - o cmake: add GnuTLS option [103] - o cmake: add support for `CURL_DEFAULT_SSL_BACKEND` [128] - o cmake: add support for single libcurl compilation pass [21] - o cmake: allow `SHARE_LIB_OBJECT=ON` on all platforms [80] - o cmake: assume `wldap32` availability on Windows [81] - o cmake: cache more config and delete unused ones [4] - o cmake: detect `SSL_set0_wbio` in OpenSSL [22] - o cmake: drop `HAVE_LIBWINMM` and `HAVE_LIBWS2_32` feature checks [68] - o cmake: fix to use variable for the curl namespace [79] - o cmake: fixup H2 duplicate symbols for unity builds [23] - o cmake: set SIZEOF_LONG_LONG in curl_config.h [165] - o cmake: support building static and shared libcurl in one go [17] - o cmdline-docs: make sure to phrase it as "added in ...." [161] - o cmdline-docs: use present tense, not future [160] - o cmdline-opts/docs: mention the negative option part [90] - o cmdline-opts/page-header: clarify stronger that !opt == URL [123] - o cmdline-opts/page-header: reorder, clean up [51] - o configure, cmake, lib: more form api deprecation [7] - o configure: fix `HAVE_TIME_T_UNSIGNED` check [153] - o configure: trust pkg-config when it's used for zlib [149] - o configure: use the pkg-config --libs-only-l flag for libssh2 [16] - o connect: stop halving the remaining timeout when less than 600 ms left [147] - o cookie-jar.d: emphasize that this option is ONLY writing cookies [72] - o crypto: ensure crypto initialization works [69] - o curl_url_get/set.3: add missing semicolon in SYNOPSIS - o CURLINFO_CERTINFO.3: better explain curl_certinfo struct [64] - o CURLINFO_TLS_SSL_PTR.3: clarify a recommendation [75] - o CURLOPT_*TIMEOUT*: extend and clarify [101] - o CURLOPT_SSL_VERIFYPEER.3: mention it does not load CA certs when disabled [42] - o CURLOPT_URL.3: add two URL API calls in the see-also section - o CURLOPT_URL.3: explain curl_url_set() uses the same parser - o digest: Use hostname to generate spn instead of realm [164] - o disable.d: explain --disable not implemented prior to 7.50.0 [115] - o docs/cmdline-opts/gen.pl: hide "added in" before 7.50.0 [76] - o docs/cmdline-opts: match the current output [104] - o docs/cmdline-opts: spellfixes, typos and polish [9] - o docs/cmdline: add small "warning" to verbose options [59] - o docs/cmdline: remove repeated working for negotiate + ntlm [58] - o docs/HYPER.md: document a workaround for a link error [73] - o docs: add curl_global_trace to some SEE ALSO sections [133] - o docs: link to the website versions instead of markdowns [3] - o docs: mark --ssl-revoke-best-effort as Schannel specific [162] - o docs: mention critical files in same directories as curl saves [119] - o docs: removing "pausing transfers" from HYPER.md. [134] - o docs: rewrite to present tense [105] - o easy: remove #ifdefs to make code easier on the eye [34] - o egd: delete feature detection and related source code [5] - o ftp: fix temp write of ipv6 address [143] - o gen.pl: escape all dashes (ascii minus) to avoid unicode hyphens [50] - o gen.pl: replace all single quotes with aq [78] - o GHA: adding quiche workflow [35] - o headers: accept leading whitespaces on first response header [37] - o http2: avoid too early connection re-use/multiplexing [20] - o http2: cleanup trace messages [56] - o http2: disable asssertion blocking OSSFuzz testing [31] - o http2: fix in h2 proxy tunnel: progress in ingress on sending [32] - o http2: polish things around POST [132] - o http2: upgrade tests and add fix for non-existing stream [44] - o http3/ngtcp2: shorten handshake, trace cleanup [13] - o http3: quiche, handshake optimization, trace cleanup [63] - o http: close the connection after a late 417 is received [109] - o http: do not require a user name when using CURLAUTH_NEGOTIATE [86] - o http: fix sending of large requests [156] - o http: remove the p_pragma struct field [60] - o http: return error when receiving too large header set [43] - o hyper: fix a progress upload counter bug [122] - o hyper: fix ownership problems [116] - o hyper: remove `hyptransfer->endtask` [137] - o imap: add a check for failing strdup() - o imap: remove the only sscanf() call in the IMAP code [84] - o include.d: explain headers not printed with --fail before 7.75.0 [155] - o include/curl/mprintf.h: add __attribute__ for the prototypes [38] - o krb5: fix "implicit conversion loses integer precision" warnings [152] - o lib: add ability to disable auths individually [135] - o lib: build fixups when built with most things disabled [97] - o lib: fix a few *printf() flag mistakes [47] - o lib: fix null ptr derefs and uninitialized vars (h2/h3) [107] - o lib: move mimepost data from ->req.p.http to ->state [94] - o libtest: use curl_free() to free libcurl allocated data [114] - o list-only.d: mention SFTP as supported protocol [55] - o macOS: fix target detection more [11] - o misc: fix various typos [18] - o multi.h: the 'revents' field of curl_waitfd is supported [117] - o multi: more efficient pollfd count for poll [130] - o multi: remove 'processing: ' debug message [142] - o ngtcp2: fix handling of large requests [150] - o openssl: auto-detect `SSL_R_TLSV13_ALERT_CERTIFICATE_REQUIRED` [65] - o openssl: clear error queue after SSL_shutdown [120] - o openssl: make aws-lc version support OCSP [48] - o openssl: Support async cert verify callback [24] - o openssl: switch to modern init for LibreSSL 2.7.0+ [70] - o openssl: use `SSL_CTX_set_ciphersuites` with LibreSSL 3.4.1 [66] - o openssl: use `SSL_CTX_set_keylog_callback` with LibreSSL 3.5.0 [67] - o openssl: when CURLOPT_SSL_CTX_FUNCTION is registered, init x509 store before [151] - o os400: build test servers [136] - o os400: do not check translatable options at build time [95] - o os400: implement CLI tool [140] - o page-footer: QLOGDIR works with ngtcp2 and quiche [62] - o page-header: move up a URL paragraph from GLOBBING to URL - o pytest: fix check for slow_network skips to only apply when intended [157] - o quic: don't set SNI if hostname is an IP address [166] - o quiche: adjust quiche `QUIC_IDLE_TIMEOUT` to 60s - o quiche: enable quiche to handle timeout events [82] - o resolve: use PF_INET6 family lookups when CURL_IPRESOLVE_V6 is set [2] - o revert "schannel: reverse the order of certinfo insertions" [14] - o schannel: fix ordering of cert chain info [163] - o schannel: fix user-set legacy algorithms in Windows 10 & 11 [53] - o schannel: verify hostname independent of verify cert [74] - o sectransp: fix compiler warnings [129] - o sectransp: prevent CFRelease() of NULL [26] - o secureserver.pl: fix stunnel path quoting [112] - o secureserver.pl: fix stunnel version parsing [111] - o SECURITY-PROCESS.md: not a sec issue: Tricking user to run a cmdline [146] - o system.h: add CURL_OFF_T definitions on HP-UX with HP aCC [108] - o test1304: build and skip without netrc support - o test1554: check translatable string options in OS400 wrapper [96] - o test1608: make it build and get skipped without shuffle DNS support - o test687/688: two more basic --xattr tests [89] - o tests/tftpd+mqttd: make variables static to silence picky warnings [57] - o tests: add 'large-time' as a testable feature [92] - o tests: add support for nested %if conditions [91] - o tests: don't call HTTP errors OK in test cases - o tests: ensure `libcurl.def` contains all exports [45] - o tests: fix h3 server check and parallel instances [6] - o tests: TLS session sharing test [100] - o tests: update cookie expiry dates to far in the future [121] - o time-cond.d: mention what happens on a missing file [93] - o tool: avoid including leading spaces in the Location hyperlink [145] - o tool: change some fopen failures from warnings to errors [144] - o tool: make the length argument an int for printf()-.* flags [49] - o tool_cb_wrt: fix invalid unicode for windows console [25] - o tool_filetime: make -z work with file dates before 1970 [139] - o tool_operate: allow both SSL_CERT_FILE and SSL_CERT_DIR [12] - o tool_operate: make aws-sigv4 not require TLS to be used - o tool_paramhlp: improve str2num(): avoid unnecessary call to strlen() [118] - o tool_urlglob: use the correct format specifier for curl_off_t in msnprintf [88] - o transfer: also stop the sending on closed connection [124] - o transfer: don't set TIMER_STARTTRANSFER on first send [77] - o unit2600: fix build warning if built without verbose messages - o url: remove infof() output for "still name resolving" [28] - o urlapi: fix heap buffer overflow [30] - o urlapi: make sure zoneid is also duplicated in curl_url_dup [29] - o urlapi: return CURLUE_BAD_HOSTNAME if puny2idn encoding fails [102] - o urlapi: setting a blank URL ("") is not an ok URL [106] - o vquic: show stringified messages for errno [40] - o vtls: clarify "ALPN: offers" message [27] - o winbuild: improve check for static zlib [15] - o wolfSSL: avoid the OpenSSL compat API when not needed [85] - o workflows/macos.yml: disable zstd and alt-svc in the http-only build [98] - o write-out.d: clarify %{time_starttransfer} - o ws: fix spelling mistakes in examples and tests [138] + o _ENVIRONMENT.md. Windows does case insensitive env variables [214] + o _URL.md: remove the zone-id mention [227] + o AmigaOS: curl_setup.h avoid explicit_bzero with clib2 [283] + o AmigaOS: fix build fallouts, re-add to CI [279] + o asyn-thrdd: add IPv6 guards [195] + o asyn-thrdd: fix result processing without wakeup socketpair [2] + o autotools: mbedtls detection fixes [163] + o BINDINGS: Update Hollywood link [181] + o BUFQ.md: re-sync with source code [111] + o build: enable `-Wlogical-op` picky warning for GCC 4.4+ [277] + o build: omit zlib pkg-config reference for Android [130] + o cf-h2-prox: fix peer leak [132] + o cf-h2-proxy: drop interim responses [47] + o cf-https-connect: do not engage on proxy origin [236] + o cf-ip-happy.c: minor comment typo + o cf-ip-happy: update documentation [223] + o cf-socket: make Curl_addr2string static [224] + o cf-socket: set scope_id for IPv6 link-local addresses [150] + o cf-socket: store errno from do_connect in ctx->error [199] + o cfilters: fix busy loop on blocked transfers [72] + o chunked: reject invalid bytes in trailer [210] + o CIPHERS.md: fix the example that uses only TLS 1.3 [137] + o cmake/FindGSS: drop "MIT Unknown" version value, related tidy ups [292] + o cmake/FindGSS: drop CMake <3.16 compatibility logic [291] + o cmake/FindGSS: fix comment, adjust custom flavor property name [261] + o cmake/FindGSS: prioritize MIT over GNU in pkg-config detection [196] + o cmake: auto-select static nghttp2/nghttp3/ngtcp2 Config [8] + o cmake: export/forward `NGTCP2_CRYPTO_BACKEND` [99] + o cmake: fix three issues generating lib options in config files [126] + o cmake: fix zstd CMake config name [5] + o cmake: opt in `MSVC_VERSION` 1951 to picky warnings [55] + o cmake: quote `COMPONENTS` string in `curl-config.in.cmake` [80] + o cmake: simplify `LINK_ONLY` imported target extraction [294] + o config2setopts: use default protocol properly [286] + o connect: remove deref of freed pointer in trace call [128] + o content_encoding: fix limit failure message [171] + o content_encoding: fix non-last chunked rejection [209] + o content_encoding: timeout during slow decoding [170] + o cookie: check __Secure- and __Host- case sensitively when read from file [256] + o cookie: compare path case sensitively [52] + o cookie: reject control octets in file-loaded cookies [289] + o cookie: simplify strstore(), remove outdated comment [12] + o cookie: tailmatch the domains for secure override [200] + o cookie: trim trailing dots when checking PSL [39] + o creds: add sasl service name [75] + o creds: create with empty user+pass [304] + o creds: mask OAuth bearer token in trace logs [117] + o creds: remove two unused functions [158] + o curl_easy_pause.md: rephrase the stream cache when pause clause [120] + o curl_easy_setopt.md: change options when no transfer runs [122] + o curl_formdata: fix to pass long where missing, document `CURLFORM_NAMELENGTH` [243] + o curl_multi_assign.md: clarify lifetime [264] + o curl_ntlm_core: fix nettle 4+ builds in certain MultiSSL combos [87] + o curl_ntlm_core: propagate DES `CryptEncrypt()` error [84] + o curl_sha512_256: fix result code on error [166] + o CURLINFO_CONTENT_LENGTH_UPLOAD_T.md: expand [215] + o CURLMOPT_SOCKETFUNCTION.md: this sends *all* file descriptors [266] + o CURLOPT_CHUNK_BGN_FUNCTION: target is there for symlinks only [156] + o CURLOPT_DISALLOW_USERNAME_IN_URL: is for CURLOPT_URL only [61] + o CURLOPT_DOH_URL.md: does not inherit proxy options [213] + o CURLOPT_ECH.md: simplify the description language [18] + o CURLOPT_HAPROXYPROTOCOL.md: only sent for newly setup connections [32] + o CURLOPT_MAXFILESIZE: clarify this also works for on-going transfers [78] + o CURLOPT_PINNEDPUBLICKEY.md: does not apply for other origins [152] + o CURLOPT_PORT.md: use stronger language [133] + o CURLOPT_SHARE: warn about early remove [51] + o CURLOPT_SSH_HOSTKEYFUNCTION.md: for new connections only [48] + o CURLOPT_WRITEFUNCTION.md: mention redirects [226] + o CURLOPT_WRITEFUNCTION.md: remove stray reference to HSTS [208] + o delta: harden external command invocations [98] + o digest: escape control codes too [206] + o digest: flush proxy state on proxy or credential change [225] + o digest: flush state on origin or credential change [235] + o dns-httpsrr-lookup: use origin, not peer [302] + o dnscache: remove Curl_dns_entry_link [160] + o docs/libcurl: fix the version for curl_multi_socket_action + o docs: end "...can be used several times..." sentences with period [34] + o docs: fix --follow doc typo [97] + o docs: fix a couple of typos [62] + o docs: fix grammar and wording in FAQ [66] + o docs: fix odd wording in CONTRIBUTE.md [107] + o docs: note CURLOPT_PINNEDPUBLICKEY has no effect on legacy LDAP backend [65] + o docs: returned header size reflects HTTP/1-style format [203] + o doh: cap the maximum TTL to 24 hours [234] + o doh: drop redundant `curlx_dyn_free()` call in `doh_probe_done()` [232] + o doh: stricter HTTPS RNAME parsing [233] + o ECH: cleanups [20] + o event: fix wakeup consumption [93] + o ftp: avoid accessing EPSV response one byte past the NULL [9] + o ftp: remove 2 Curl_resolv_blocking() calls [30] + o ftp: remove bits.ftp_use_control_ssl [28] + o ftplistparser: clear strings.target if not symlink [148] + o gnutls: allow building with nettle 4.0 [96] + o gnutls: fix more nettle 4+ compatibility issues [94] + o gnutls: require 3.7.2 for earlydata [103] + o gsasl: fix potential double free [56] + o gtls: fix ignored return and uninitialized status in OCSP check [49] + o gtls: fix some typos [15] + o gtls: minor fixes and improvements [190] + o gtls: use the correct return code in trace output [173] + o gtls: verify OCSP response signature in gtls_verify_ocsp_status [86] + o h3-proxy: fix callback return values, and a typo in tests [139] + o hostip: remove unused MAX_HOSTCACHE_LEN and MAX_DNS_CACHE_SIZE [101] + o hsts.md: mention multiple curl invokes effect [189] + o hsts: duplicate live HSTS data in curl_easy_duphandle [183] + o http-proxy: verify CONNECT response headers [192] + o HTTP3.md: update quiche build [229] + o http: don't pass on set cookies to new origins [140] + o http: prefer chunked encoding over Content-Length: 0 [146] + o http: reject spurious CR bytes in headers [157] + o http_digest: return better error [204] + o idn: replace header guards with forward declaration [100] + o INSTALL-CMAKE.md: document CMake environment variables [246] + o INTERNALS.md: document minimum nghttp3 and ngtcp2 versions [299] + o KNOWN_BUGS.md: remove fixed GnuTLS <-> OpenSSL incompat bug [41] + o KNOWN_BUGS: remove stale Threads::Threads entry [135] + o krb5_sspi: fix error message on `DecryptMessage()` fail [269] + o ldap: base64 encode binary LDIF values with WinLDAP [273] + o ldap: fix minor leak on write callback error [24] + o ldap: fix to not leak `attribute` on OOM (WinLDAP) [79] + o ldap: switch off chasing referrals [114] + o lib678: fix to not be perma-skipped [10] + o lib: make `__STDC_VERSION__` literals `L` (where missing) + o lib: transfer origin and proxy handling [276] + o lib: two minor typos [16] + o libcurl-easy.md: minor clarifications [19] + o libssh2: do not use deprecated macros when unavailable [177] + o libssh2: drop stray double-negative from `strncmp()` result [194] + o libssh2: fix to return error code on missing parameter [198] + o libssh2: replace macro names with non-misspelled alternatives [169] + o libssh2: save non-standard port to `known_hosts` [217] + o libssh2: sync version check with INTERNALS.md [176] + o libssh2: use non-deprecated `libssh2_knownhost_addc()` [178] + o libssh: map SSH_KNOWN_HOSTS_OTHER to CURLKHMATCH_MISMATCH [125] + o m4: drop redundant conditions in TLS library detections [155] + o Makefile.am: drop test1190 listed twice [144] + o managen: apply minor fixes and improvements [115] + o mbedtls: null-terminate the private key blob [36] + o mk-unity.pl: `#include`, and not concatenate input headers [124] + o mqtt: return error on truncated Remaining Length [230] + o mqtt: validate PINGRESP and DISCONNECT have remaining_length == 0 [7] + o multi: handle pause in multi socket callback [109] + o multi: remove a stale comment [216] + o multi: silence gcc 16 `-Wnull-dereference`, bump CI job to test [54] + o multi: xfers_really_alive [288] + o netrc: remember and check filename loaded [212] + o netrc: scanner refactor [121] + o ngtcp2: fail handshake directly [138] + o openssl: do not mix OpenSSL int result with `CURLcode` variable [265] + o os400sys: fix theoretical length overflows [141] + o peer.h: fix typo in comment [202] + o pingpong: reject nul byte in server response line [268] + o progress: fix CURLINFO time reporting [145] + o psl: require libpsl 0.16.0 (2016-12-10) or greater [188] + o pytest: pass `--disable` to curl [175] + o pytest: re-enable test test_05_01 and test_05_02 for quiche 0.29.0+ [154] + o pythonlint.sh: make it fail on error, fix ruff warnings in pytest [67] + o quic: count zero length packets against max [179] + o ratelimits: use minimal burst rate [245] + o RELEASE-PROCEDURE.md: update coming relese dates + o resolve: mention in error that IP address is expected [205] + o rtsp: bump buf after rtsp_filter_rtp() [88] + o runner.pm: apply minor correctness fix [105] + o runner.pm: set `CURL_TESTNUM` for `precheck` commands [13] + o runtests: fix tests for curl builds with embedded CA bundle [187] + o rustls: error on CURLOPT_CRLFILE with native CA store [59] + o schannel: check `schannel_sha256sum()` success, and more [165] + o schannel: enforce Extended Key Usage for custom CA roots [29] + o schannel: error on TLS 1.3-only with cipher list [136] + o schannel: fix https proxy for client cert and certinfo [280] + o schannel: fix revoke_best_effort setting for proxy [70] + o schannel: use fopen instead CreateFile [191] + o schannel_verify: avoid out of blob access [11] + o schannel_verify: simplify CryptQueryObject use [159] + o scripts: catch Credits-to contributors [127] + o SECURITY-ADVISORY.md: expand [220] + o setopt: changing the proxy port is also a proxy change [23] + o setopt: clear proxy auth properly on NULL [81] + o setopt: clear the "custom" CA booleans when set to NULL [218] + o setopt: CURLOPT_MAXCONNECTS set to 0 restores default value [161] + o setopt: defref the old referer when setting a new [168] + o setopt: fix to honor `CURLOPT_PROXY_CAINFO_BLOB` over Native CA [26] + o setopt: gate a few proxy TLS options by checking backend support [35] + o setopt: more careful cleanup of the HSTS cache [45] + o setopt: return error if received `curl_blob->data` is NULL [185] + o show-headers.md: mention bold headers and --no-styled-output [17] + o sigv4: URL encode the user name in the header [193] + o smb: constify `strchr()` result variable [257] + o smb: integer overflow proof a size check [263] + o smbserver: update internal id generation for Python 3 [238] + o socket: introduce `SOCK_EAGAIN()` and use it [278] + o socket: use name `sockerr` for socket error variables [271] + o socks_sspi: invalid response length is a fatal error [272] + o socks_sspi: store socks5_gssapi_enctype [262] + o spnego_sspi: honor CURLOPT_GSSAPI_DELEGATION for Windows SSPI [89] + o spnego_sspi: preserve distinction btw policy-only and uncond delegation [74] + o src: fix comment typos [83] + o src: sync nghttp2 versions checks with current requirements [300] + o ssl native_ca_store: always reinit [211] + o SSLCERTS: document 8.19.0 default Native CA builds (Windows) [14] + o sspi: clear SSPI credentials on AcquireCredentialsHandle failure [76] + o sspi: free libcurl allocated memory with curlx_free [274] + o telnet: drop an `int` cast no longer necessary [270] + o telnet: drop redundant interim variables [275] + o telnet: fix error message typos [186] + o telnet: fix old copy-paste typo in variable name [281] + o telnet: honor CURLOPT_TIMEOUT in send_telnet_data() [104] + o test1588: use %TESTNUMBER, not hard-coded number [118] + o test1981: explicitly set the locale [85] + o tests: add `cookies` feature to some tests [182] + o tests: add an assert to avoid IPC blocking [69] + o tests: add the "--resolve" keyword to tests that lack it [184] + o tests: fix unit1636 with --disable-progress-meter [37] + o tftp: avoid the timeout calc if the timeout is crazy [151] + o tftp: stricter option name checks [90] + o tidy-up: add space around operators, where missing [147] + o tidy-up: apply clang-format fixes [153] + o tidy-up: drop stray casts for allocated pointers [174] + o tidy-up: miscellaneous [106] + o tls: fix incomplete mTLS config in conn reuse and session cache [108] + o tls: wolfssl: fixes for PQC key shares [239] + o tool: warn when --ssl and --ftp-ssl-control override each other [129] + o tool_formparse.c: fix two minor comment typos [25] + o tool_formparse: polish error message + make two functions static [1] + o tool_formparse: tool2curlparts is no longer recursive [33] + o tool_help: rectify a bad assert [143] + o tool_operhlp: avoid NULL to %s [142] + o tool_urlglob: avoid overflow at end of range [22] + o tool_urlglob: better 'Duplicate glob name' position [82] + o tool_urlglob: make globbing error reported for correct position [91] + o tool_writeout: fix %time{} output for %s [231] + o transfer: clear referer when set to NULL [112] + o unit1675: fix potential memory leak on dynbuf fail path [197] + o unix-sockets: ignore proxy settings [6] + o URL-SYNTAX: document more URL parsing details [134] + o url: compare full origin when setting credentials [42] + o url: connection credentials origin [228] + o url: connection reuse fixes for starttls [68] + o url: detect proxy changes read from environment [110] + o url: don't log bits.close state [290] + o url: fix connection reuse for starttls protocols [27] + o url: keep the question mark for empty queries [73] + o url: remove superfluous check [131] + o url: url_match_destination fix [43] + o urlapi: accept 0X prefix in IPv4 address as well [63] + o urlapi: change more lowercase percent-encoded to uppercase [71] + o urlapi: compare zone-id in Curl_url_same_origin() [95] + o urlapi: consume trailing dots after IPv4 numerical addresses [50] + o urlapi: deny hostnames with more than one trailing dot [58] + o urlapi: drop base fragment on empty redirect [64] + o urlapi: fix an issue parsing file URLs [149] + o urlapi: fix memleaks on error in `parse_hostname_login()` [221] + o urlapi: fix redirect handling if CURLU_NO_GUESS_SCHEME is set [46] + o urlapi: forbid '|' in host [172] + o urlapi: handle redirect without set scheme with default-scheme [38] + o urlapi: URL decode hostname before IP address normalization [207] + o user-agent.md: mention double quotes too [3] + o var: use a dedicated pointer for the alloc [219] + o verify-release: verify more thoroughly with git [249] + o vquic: drop stray casts for `iovec.iov_len` [162] + o vquic: fix `-Wunused-parameter` with proxies disabled [260] + o vtls: more large buffer support and error checks for SHA-256 [164] + o vtls: use Curl_safecmp for CRLfile and pinned_key comparison [116] + o vtls_scache: include signature_algorithms in the SSL peer cache key [123] + o vtls_spack: drop redundant macro fallbacks [167] + o VULN-DISCLOSURE-POLICY.md: emphasize comm as a human [180] + o VULN-DISCLOSURE-POLICY.md: emphasize the no email thank you part [113] + o VULN-DISCLOSURE-POLICY.md: test code is not secure [119] + o VULN-DISCLOSURE-POLICY: non-released code [253] + o websockets: auto-tunnel through http proxy [102] + o websockets: buffer ugprade data at connection level [237] + o windows: update MS SDK versions in comments [60] + o winldap: avoid NULL pointer deref on `ldap_get_dn()` fail [242] + o ws: make pong sending lazy [201] + o x509asn1: fix DH public key parameter extraction [44] + o x509asn1: fix operator order in do_pubkey [21] This release includes the following known bugs: - o see docs/KNOWN_BUGS (https://curl.se/docs/knownbugs.html) + See https://curl.se/docs/knownbugs.html + +For all changes ever done in curl: + + See https://curl.se/changes.html Planned upcoming removals include: - o support for space-separated NOPROXY patterns - o support for the original legacy mingw version 1 + o local crypto implementations + o NTLM + o SMB + o TLS-SRP support - See https://curl.se/dev/deprecate.html for details + See https://curl.se/dev/deprecate.html This release would not have looked like this without help, code, reports and advice from friends like these: - ad0p on github, Alexander Jaeger, Alexander Kanavin, apparentorder on github, - balikalina on Github, Benoit Pierre, Chris Talbot, Christian Hesse, - Dan Fandrich, Daniel Gustafsson, Daniel Stenberg, Dan Jacobson, - Dave Cottlehuber, Davide Masserut, Derzsi Dániel, Douglas R. Reno, - ed0d2b2ce19451f2, Emanuele Torre, Enrico Scholz, eppesuig, FC Stegerman, - Gabriel Corona, Gerome Fournier, Gisle Vanem, Goro FUJI, Graham Campbell, - Guillaume Algis, guoxinvmware on github, Harry Sintonen, Jacob Mealey, - JazJas on github, John Bampton, John Hawthorn, John Walker, Joseph Tharayil, - junsik on github, kyled-dell on github, Lukas Tribus, Maksim Arhipov, - Maksim Sciepanienka, Marcel Raad, Marin Hannache, Markus Sommer, - Martin Galvan, Mathew Benson, Matthias Gatto, Maurício Meneghini Fauth, - Michael Osipov, Mohamed Daahir, Nathan Moinvaziri, Niall McGee, - Nicholas Nethercote, Nicolas Noben, Nicolás Ojeda Bär, Oleg Jukovec, - oliverpool on github, Pablo Busse, Patrick Monnerat, - Philippe Antoine on HackerOne, pszlazak on github, Randall S. Becker, - Ray Satiro, Richard W.M. Jones, Rutger Broekhoff, Ryan Schmidt, - Samuel Chiang, Satana de Sant'Ana, Sergey, Sevan Janiyan, Stefan Eissing, - Thomas M. DuBuisson, Thorsten Klein, trrui-huawei, Viktor Szakats, vvb2060, - wangzhikun, Wilhelm von Thiele, Wyatt O'Day, yushicheng7788 on github, - zhihaoy on github - (80 contributors) + 0xN3R3K3, 11soda11, Ady Elouej, A Johnston, Alan De Smet, alhudz, + alienowo on hackerone, ambikeesshh, amitbidlan, Andreas Falkenhahn, + Andrei Rybak, Andrew Nesbitt, Aritra Basu, av223119 on github, + azraelxuemo on hackerone, Bartel Sielski, Bastian Jesuiter, + BazaarAcc32 on github, Bill Mill, Bryan Henderson, ByteRay on hackerone, + chrizilla on github, co-authors in libssh2, correctmost on github, + Dan Fandrich, Daniel Gustafsson, Daniel Stenberg, Dario Vinella, + Darren Banfi, Dave Walker, daviey on hackerone, dependabot[bot], + dyingc on github, Earnestly on github, Elise Vance, Emanuel Krollmann, + Eunsoo Kim, evergarden1123 on hackerone, Fabian Keil, Filipe Casal, + Gao Liyou, Guancheng Li, Guannan Wang, Harry Sintonen, Hem Parekh, htasta, + jeffhuang, Jeremy Nicoll, Jiashuo Liang, jjchuck on hackerone, + Johannes Schlatow, Josef Cejka, Joshua Rogers, Kai Pastor, Marcel Raad, + Mark Esler, Max Dymond, Michael Kaufmann, mik, Mike-menny on github, + Muhamad Arga Reksapati, mulan_dh on hackerone, netspacer.research, + oreadvanthink on github, parasol-aser, penpal, Peter Krefting, Philip H., + Rainer Jung, Randall S. Becker, Raymond Steen, Ray Satiro, + renjian on hackerone, renovate[bot], Ross Burton, Saud Alshareef, + Sergio Correia, sfan5 on github, Shintomon Mathew, sideshowbarker on github, + Sollace on github, Song X. Gao, sourceturner, Stefan Eissing, + Tatsuhiro Tsujikawa, Tim Martin, tiymat, Tobias Frauenschläger, + Trail of Bits, Vasiliy-Kkk, vectorqueue on hackerone, vegagent on hackerone, + Viktor Szakats, violet12331 on hackerone, Will Cosgrove, + wulin-nudt on github, Xi Ruoyao, x-xiang on github, Yedaya Katsman, + Zartaj Majeed, zhanhb on github, Zhanpeng Liu + (102 contributors) References to bug reports and discussions on issues: - [1] = https://curl.se/bug/?i=11346 - [2] = https://curl.se/bug/?i=11564 - [3] = https://github.com/curl/curl-www/issues/272 - [4] = https://curl.se/bug/?i=11551 - [5] = https://curl.se/bug/?i=11556 - [6] = https://curl.se/bug/?i=11553 - [7] = https://curl.se/bug/?i=9621 - [8] = https://curl.se/bug/?i=11452 - [9] = https://curl.se/bug/?i=11562 - [10] = https://curl.se/bug/?i=11459 - [11] = https://curl.se/bug/?i=11502 - [12] = https://curl.se/bug/?i=11325 - [13] = https://curl.se/bug/?i=11609 - [14] = https://curl.se/bug/?i=11536 - [15] = https://curl.se/bug/?i=11521 - [16] = https://curl.se/bug/?i=11538 - [17] = https://curl.se/bug/?i=11505 - [18] = https://curl.se/bug/?i=11561 - [19] = https://curl.se/bug/?i=11532 - [20] = https://curl.se/mail/lib-2023-07/0045.html - [21] = https://curl.se/bug/?i=11546 - [22] = https://curl.se/bug/?i=11555 - [23] = https://curl.se/bug/?i=11550 - [24] = https://curl.se/bug/?i=11499 - [25] = https://curl.se/bug/?i=9841 - [26] = https://curl.se/bug/?i=9194 - [27] = https://curl.se/mail/lib-2023-07/0041.html - [28] = https://curl.se/bug/?i=11394 - [29] = https://curl.se/mail/lib-2023-07/0047.html - [30] = https://curl.se/bug/?i=11560 - [31] = https://curl.se/bug/?i=11500 - [32] = https://curl.se/bug/?i=11527 - [33] = https://curl.se/bug/?i=11457 - [34] = https://curl.se/bug/?i=11525 - [35] = https://curl.se/bug/?i=11517 - [36] = https://curl.se/bug/?i=11416 - [37] = https://curl.se/bug/?i=11605 - [38] = https://curl.se/bug/?i=11589 - [39] = https://curl.se/bug/?i=11608 - [40] = https://curl.se/bug/?i=11584 - [41] = https://curl.se/bug/?i=11421 - [42] = https://curl.se/bug/?i=11606 - [43] = https://curl.se/bug/?i=11582 - [44] = https://curl.se/bug/?i=11563 - [45] = https://curl.se/bug/?i=11570 - [46] = https://curl.se/bug/?i=11581 - [47] = https://curl.se/bug/?i=11579 - [48] = https://curl.se/bug/?i=11568 - [49] = https://curl.se/bug/?i=11578 - [50] = https://curl.se/bug/?i=11635 - [51] = https://curl.se/bug/?i=11638 - [52] = https://curl.se/bug/?i=11621 - [53] = https://curl.se/bug/?i=10741 - [54] = https://curl.se/bug/?i=11655 - [55] = https://curl.se/bug/?i=11628 - [56] = https://curl.se/bug/?i=11592 - [57] = https://curl.se/bug/?i=11594 - [58] = https://curl.se/bug/?i=11597 - [59] = https://curl.se/bug/?i=11596 - [60] = https://curl.se/bug/?i=11681 - [61] = https://curl.se/bug/?i=11619 - [62] = https://curl.se/bug/?i=11631 - [63] = https://curl.se/bug/?i=11618 - [64] = https://curl.se/bug/?i=11666 - [65] = https://curl.se/bug/?i=11617 - [66] = https://curl.se/bug/?i=11616 - [67] = https://curl.se/bug/?i=11615 - [68] = https://curl.se/bug/?i=11612 - [69] = https://curl.se/bug/?i=11614 - [70] = https://curl.se/bug/?i=11611 - [71] = https://curl.se/bug/?i=11460 - [72] = https://curl.se/bug/?i=11661 - [73] = https://curl.se/bug/?i=11653 - [74] = https://curl.haxx.se/mail/lib-2018-10/0113.html - [75] = https://curl.se/bug/?i=11665 - [76] = https://curl.se/bug/?i=11651 - [77] = https://curl.se/bug/?i=11669 - [78] = https://curl.se/bug/?i=11645 - [79] = https://curl.se/bug/?i=1199308 - [80] = https://curl.se/bug/?i=11627 - [81] = https://curl.se/bug/?i=11624 - [82] = https://curl.se/bug/?i=11654 - [83] = https://curl.se/bug/?i=11705 - [84] = https://curl.se/bug/?i=11673 - [85] = https://curl.se/bug/?i=11752 - [86] = https://sourceforge.net/p/curl/bugs/440/ - [87] = https://curl.se/bug/?i=11657 - [88] = https://curl.se/bug/?i=11698 - [89] = https://curl.se/bug/?i=11697 - [90] = https://curl.se/bug/?i=11695 - [91] = https://curl.se/bug/?i=11728 - [92] = https://curl.se/bug/?i=11696 - [93] = https://curl.se/bug/?i=11727 - [94] = https://curl.se/bug/?i=11680 - [95] = https://curl.se/bug/?i=11650 - [96] = https://curl.se/bug/?i=11650 - [97] = https://curl.se/bug/?i=11687 - [98] = https://curl.se/bug/?i=11683 - [99] = https://curl.se/bug/?i=11675 - [100] = https://curl.se/bug/?i=11675 - [101] = https://curl.se/bug/?i=11686 - [102] = https://curl.se/bug/?i=11674 - [103] = https://curl.se/bug/?i=11685 - [104] = https://curl.se/bug/?i=11723 - [105] = https://curl.se/bug/?i=11713 - [106] = https://curl.se/bug/?i=11714 - [107] = https://curl.se/bug/?i=11739 - [108] = https://curl.se/bug/?i=11718 - [109] = https://curl.se/bug/?i=11678 - [110] = https://curl.se/bug/?i=11711 - [111] = https://curl.se/bug/?i=11722 - [112] = https://curl.se/bug/?i=11721 - [113] = https://curl.se/bug/?i=11737 - [114] = https://curl.se/bug/?i=11746 - [115] = https://curl.se/bug/?i=11710 - [116] = https://curl.se/bug/?i=11745 - [117] = https://curl.se/bug/?i=11749 - [118] = https://curl.se/bug/?i=11742 - [119] = https://curl.se/bug/?i=11530 - [120] = https://curl.se/bug/?i=11736 - [121] = https://curl.se/bug/?i=11576 - [122] = https://curl.se/bug/?i=11780 - [123] = https://curl.se/bug/?i=11734 - [124] = https://curl.se/bug/?i=11769 - [125] = https://curl.se/bug/?i=11766 - [126] = https://curl.se/bug/?i=11729 - [127] = https://curl.se/bug/?i=11794 - [128] = https://curl.se/bug/?i=11774 - [129] = https://curl.se/bug/?i=11773 - [130] = https://curl.se/bug/?i=11792 - [131] = https://curl.se/bug/?i=11771 - [132] = https://curl.se/bug/?i=11756 - [133] = https://curl.se/bug/?i=11791 - [134] = https://curl.se/bug/?i=11764 - [135] = https://curl.se/bug/?i=11490 - [136] = https://curl.se/bug/?i=11547 - [137] = https://curl.se/bug/?i=11779 - [138] = https://curl.se/bug/?i=11784 - [139] = https://curl.se/bug/?i=11785 - [140] = https://curl.se/bug/?i=11547 - [141] = https://curl.se/bug/?i=11738 - [142] = https://curl.se/bug/?i=11759 - [143] = https://curl.se/bug/?i=11747 - [144] = https://curl.se/bug/?i=11677 - [145] = https://curl.se/bug/?i=11735 - [146] = https://curl.se/bug/?i=11757 - [147] = https://curl.se/bug/?i=11693 - [148] = https://curl.se/bug/?i=11753 - [149] = https://curl.se/mail/lib-2023-08/0081.html - [150] = https://curl.se/bug/?i=11815 - [151] = https://curl.se/bug/?i=11800 - [152] = https://curl.se/bug/?i=11814 - [153] = https://curl.se/bug/?i=11825 - [154] = https://curl.se/bug/?i=11809 - [155] = https://curl.se/bug/?i=11822 - [156] = https://curl.se/bug/?i=11342 - [157] = https://curl.se/bug/?i=11801 - [158] = https://curl.se/bug/?i=11799 - [159] = https://curl.se/bug/?i=11664 - [160] = https://curl.se/bug/?i=11821 - [161] = https://curl.se/bug/?i=11821 - [162] = https://curl.se/bug/?i=11760 - [163] = https://curl.se/bug/?i=11632 - [164] = https://curl.se/bug/?i=11395 - [165] = https://curl.se/bug/?i=11839 - [166] = https://curl.se/bug/?i=11827 + [1] = https://curl.se/bug/?i=21510 + [2] = https://curl.se/bug/?i=21476 + [3] = https://curl.se/mail/archive-2026-04/0029.html + [4] = https://curl.se/bug/?i=21486 + [5] = https://curl.se/bug/?i=21538 + [6] = https://curl.se/bug/?i=21630 + [7] = https://hackerone.com/reports/3702718 + [8] = https://curl.se/bug/?i=21470 + [9] = https://curl.se/bug/?i=21545 + [10] = https://curl.se/bug/?i=21641 + [11] = https://curl.se/bug/?i=21543 + [12] = https://curl.se/bug/?i=21541 + [13] = https://curl.se/bug/?i=21640 + [14] = https://curl.se/bug/?i=21634 + [15] = https://curl.se/bug/?i=21498 + [16] = https://curl.se/bug/?i=21496 + [17] = https://curl.se/bug/?i=21495 + [18] = https://curl.se/bug/?i=21536 + [19] = https://curl.se/bug/?i=21491 + [20] = https://curl.se/bug/?i=21532 + [21] = https://curl.se/bug/?i=21533 + [22] = https://curl.se/bug/?i=21529 + [23] = https://curl.se/bug/?i=21485 + [24] = https://curl.se/bug/?i=21530 + [25] = https://curl.se/bug/?i=21480 + [26] = https://curl.se/bug/?i=21631 + [27] = https://curl.se/bug/?i=21522 + [28] = https://curl.se/bug/?i=21521 + [29] = https://curl.se/bug/?i=21629 + [30] = https://curl.se/bug/?i=21512 + [32] = https://curl.se/bug/?i=21517 + [33] = https://curl.se/bug/?i=21518 + [34] = https://curl.se/bug/?i=21644 + [35] = https://curl.se/bug/?i=21514 + [36] = https://curl.se/bug/?i=21515 + [37] = https://curl.se/bug/?i=21500 + [38] = https://curl.se/bug/?i=21632 + [39] = https://curl.se/bug/?i=21636 + [40] = https://curl.se/bug/?i=21723 + [41] = https://curl.se/bug/?i=21720 + [42] = https://curl.se/bug/?i=21575 + [43] = https://curl.se/bug/?i=21573 + [44] = https://curl.se/bug/?i=21595 + [45] = https://curl.se/bug/?i=21615 + [46] = https://curl.se/bug/?i=21721 + [47] = https://curl.se/bug/?i=21626 + [48] = https://curl.se/bug/?i=21606 + [49] = https://curl.se/bug/?i=21679 + [50] = https://curl.se/bug/?i=21635 + [51] = https://curl.se/bug/?i=21633 + [52] = https://curl.se/bug/?i=21616 + [53] = https://curl.se/bug/?i=21153 + [54] = https://curl.se/bug/?i=21707 + [55] = https://curl.se/bug/?i=21714 + [56] = https://curl.se/bug/?i=21609 + [57] = https://curl.se/bug/?i=21605 + [58] = https://curl.se/bug/?i=21622 + [59] = https://curl.se/bug/?i=21614 + [60] = https://curl.se/bug/?i=21621 + [61] = https://curl.se/bug/?i=21890 + [62] = https://curl.se/bug/?i=21617 + [63] = https://curl.se/bug/?i=21820 + [64] = https://curl.se/bug/?i=21745 + [65] = https://curl.se/bug/?i=21682 + [66] = https://curl.se/bug/?i=21593 + [67] = https://curl.se/bug/?i=21597 + [68] = https://curl.se/bug/?i=21665 + [69] = https://curl.se/bug/?i=21688 + [70] = https://curl.se/bug/?i=21683 + [71] = https://curl.se/bug/?i=21592 + [72] = https://curl.se/bug/?i=21671 + [73] = https://curl.se/bug/?i=21544 + [74] = https://curl.se/bug/?i=21583 + [75] = https://curl.se/bug/?i=21585 + [76] = https://curl.se/bug/?i=21642 + [77] = https://curl.se/bug/?i=21407 + [78] = https://curl.se/bug/?i=21582 + [79] = https://curl.se/bug/?i=21576 + [80] = https://curl.se/bug/?i=21699 + [81] = https://curl.se/bug/?i=21696 + [82] = https://curl.se/bug/?i=21567 + [83] = https://curl.se/bug/?i=21570 + [84] = https://curl.se/bug/?i=21569 + [85] = https://curl.se/bug/?i=21749 + [86] = https://curl.se/bug/?i=21677 + [87] = https://curl.se/bug/?i=21562 + [88] = https://curl.se/bug/?i=21563 + [89] = https://curl.se/bug/?i=21528 + [90] = https://curl.se/bug/?i=21560 + [91] = https://curl.se/bug/?i=21561 + [92] = https://curl.se/bug/?i=21409 + [93] = https://curl.se/bug/?i=21547 + [94] = https://curl.se/bug/?i=21557 + [95] = https://curl.se/bug/?i=21686 + [96] = https://curl.se/bug/?i=21169 + [97] = https://curl.se/bug/?i=21553 + [98] = https://curl.se/bug/?i=21104 + [99] = https://curl.se/bug/?i=21523 + [100] = https://curl.se/bug/?i=21551 + [101] = https://curl.se/bug/?i=21550 + [102] = https://curl.se/bug/?i=21663 + [103] = https://curl.se/bug/?i=21750 + [104] = https://curl.se/bug/?i=21685 + [105] = https://curl.se/bug/?i=21672 + [106] = https://curl.se/bug/?i=21646 + [107] = https://curl.se/bug/?i=21705 + [108] = https://curl.se/bug/?i=21667 + [109] = https://curl.se/bug/?i=21748 + [110] = https://curl.se/bug/?i=21666 + [111] = https://curl.se/bug/?i=21678 + [112] = https://curl.se/bug/?i=21741 + [113] = https://curl.se/bug/?i=21747 + [114] = https://curl.se/bug/?i=21732 + [115] = https://curl.se/bug/?i=21670 + [116] = https://curl.se/bug/?i=21668 + [117] = https://curl.se/bug/?i=21659 + [118] = https://curl.se/bug/?i=21662 + [119] = https://curl.se/bug/?i=21660 + [120] = https://curl.se/bug/?i=21658 + [121] = https://curl.se/bug/?i=21624 + [122] = https://curl.se/bug/?i=21604 + [123] = https://curl.se/bug/?i=21651 + [124] = https://curl.se/bug/?i=21656 + [125] = https://curl.se/bug/?i=21724 + [126] = https://curl.se/bug/?i=21654 + [127] = https://curl.se/bug/?i=21653 + [128] = https://curl.se/bug/?i=21649 + [129] = https://curl.se/bug/?i=21887 + [130] = https://curl.se/bug/?i=21647 + [131] = https://curl.se/bug/?i=21650 + [132] = https://curl.se/bug/?i=21602 + [133] = https://curl.se/bug/?i=21886 + [134] = https://curl.se/bug/?i=21841 + [135] = https://curl.se/bug/?i=21734 + [136] = https://curl.se/bug/?i=21702 + [137] = https://curl.se/bug/?i=21719 + [138] = https://curl.se/bug/?i=21712 + [139] = https://curl.se/bug/?i=21802 + [140] = https://curl.se/bug/?i=21794 + [141] = https://curl.se/bug/?i=21840 + [142] = https://curl.se/bug/?i=21836 + [143] = https://curl.se/bug/?i=21837 + [144] = https://curl.se/bug/?i=21839 + [145] = https://curl.se/bug/?i=21828 + [146] = https://curl.se/bug/?i=21706 + [147] = https://curl.se/bug/?i=21793 + [148] = https://curl.se/bug/?i=21884 + [149] = https://curl.se/bug/?i=21743 + [150] = https://curl.se/bug/?i=21669 + [151] = https://curl.se/bug/?i=21782 + [152] = https://curl.se/bug/?i=21885 + [153] = https://curl.se/bug/?i=21786 + [154] = https://curl.se/bug/?i=21784 + [155] = https://curl.se/bug/?i=21781 + [156] = https://curl.se/bug/?i=21883 + [157] = https://curl.se/bug/?i=21882 + [158] = https://curl.se/bug/?i=21776 + [159] = https://curl.se/bug/?i=21760 + [160] = https://curl.se/bug/?i=21774 + [161] = https://curl.se/bug/?i=21829 + [162] = https://curl.se/bug/?i=21877 + [163] = https://curl.se/bug/?i=21727 + [164] = https://curl.se/bug/?i=21771 + [165] = https://curl.se/bug/?i=21739 + [166] = https://curl.se/bug/?i=21767 + [167] = https://curl.se/bug/?i=21768 + [168] = https://curl.se/bug/?i=21826 + [169] = https://curl.se/bug/?i=21876 + [170] = https://curl.se/bug/?i=21603 + [171] = https://curl.se/bug/?i=21756 + [172] = https://curl.se/bug/?i=21762 + [173] = https://curl.se/bug/?i=21766 + [174] = https://curl.se/bug/?i=21865 + [175] = https://curl.se/bug/?i=21816 + [176] = https://curl.se/bug/?i=21868 + [177] = https://curl.se/bug/?i=21867 + [178] = https://curl.se/bug/?i=21866 + [179] = https://curl.se/bug/?i=21869 + [180] = https://curl.se/bug/?i=21870 + [181] = https://curl.se/bug/?i=21862 + [182] = https://curl.se/bug/?i=21858 + [183] = https://curl.se/bug/?i=21809 + [184] = https://curl.se/bug/?i=21930 + [185] = https://curl.se/bug/?i=22129 + [186] = https://curl.se/bug/?i=21976 + [187] = https://curl.se/bug/?i=21970 + [188] = https://curl.se/bug/?i=21933 + [189] = https://curl.se/bug/?i=21851 + [190] = https://curl.se/bug/?i=21850 + [191] = https://curl.se/bug/?i=21773 + [192] = https://curl.se/bug/?i=21927 + [193] = https://curl.se/bug/?i=21923 + [194] = https://curl.se/bug/?i=22126 + [195] = https://curl.se/bug/?i=21881 + [196] = https://curl.se/bug/?i=22052 + [197] = https://curl.se/bug/?i=21922 + [198] = https://curl.se/bug/?i=22125 + [199] = https://curl.se/bug/?i=21914 + [200] = https://curl.se/bug/?i=21910 + [201] = https://curl.se/bug/?i=21911 + [202] = https://curl.se/bug/?i=21920 + [203] = https://curl.se/bug/?i=21912 + [204] = https://curl.se/bug/?i=21969 + [205] = https://curl.se/bug/?i=21913 + [206] = https://curl.se/bug/?i=21915 + [207] = https://curl.se/bug/?i=21918 + [208] = https://curl.se/bug/?i=21968 + [209] = https://curl.se/bug/?i=21966 + [210] = https://curl.se/bug/?i=21896 + [211] = https://curl.se/bug/?i=21902 + [212] = https://curl.se/bug/?i=21903 + [213] = https://curl.se/bug/?i=21904 + [214] = https://curl.se/bug/?i=21907 + [215] = https://curl.se/bug/?i=21953 + [216] = https://curl.se/bug/?i=21961 + [217] = https://curl.se/bug/?i=21863 + [218] = https://curl.se/bug/?i=21901 + [219] = https://curl.se/bug/?i=21898 + [220] = https://curl.se/bug/?i=21964 + [221] = https://curl.se/bug/?i=21879 + [223] = https://curl.se/bug/?i=21957 + [224] = https://curl.se/bug/?i=21946 + [225] = https://curl.se/bug/?i=21951 + [226] = https://curl.se/bug/?i=21945 + [227] = https://curl.se/bug/?i=22048 + [228] = https://curl.se/bug/?i=22040 + [229] = https://curl.se/bug/?i=22105 + [230] = https://curl.se/bug/?i=21949 + [231] = https://curl.se/bug/?i=22038 + [232] = https://curl.se/bug/?i=22133 + [233] = https://curl.se/bug/?i=22124 + [234] = https://curl.se/bug/?i=22122 + [235] = https://curl.se/bug/?i=21944 + [236] = https://curl.se/bug/?i=22033 + [237] = https://curl.se/bug/?i=22107 + [238] = https://curl.se/bug/?i=21937 + [239] = https://curl.se/bug/?i=22030 + [242] = https://curl.se/bug/?i=22000 + [243] = https://curl.se/bug/?i=22017 + [245] = https://curl.se/bug/?i=22016 + [246] = https://curl.se/bug/?i=22114 + [249] = https://curl.se/bug/?i=22018 + [253] = https://curl.se/bug/?i=22025 + [256] = https://curl.se/bug/?i=22085 + [257] = https://curl.se/bug/?i=22094 + [260] = https://curl.se/bug/?i=22104 + [261] = https://curl.se/bug/?i=22013 + [262] = https://curl.se/bug/?i=22004 + [263] = https://curl.se/bug/?i=22001 + [264] = https://curl.se/bug/?i=22088 + [265] = https://curl.se/bug/?i=22087 + [266] = https://curl.se/bug/?i=22081 + [268] = https://curl.se/bug/?i=21996 + [269] = https://curl.se/bug/?i=22003 + [270] = https://curl.se/bug/?i=22002 + [271] = https://curl.se/bug/?i=21998 + [272] = https://curl.se/bug/?i=21999 + [273] = https://curl.se/bug/?i=21926 + [274] = https://curl.se/bug/?i=21990 + [275] = https://curl.se/bug/?i=21995 + [276] = https://curl.se/bug/?i=21967 + [277] = https://curl.se/bug/?i=21893 + [278] = https://curl.se/bug/?i=21992 + [279] = https://curl.se/bug/?i=21993 + [280] = https://curl.se/bug/?i=21986 + [281] = https://curl.se/bug/?i=21979 + [283] = https://curl.se/bug/?i=21989 + [286] = https://curl.se/bug/?i=21983 + [288] = https://curl.se/bug/?i=22050 + [289] = https://curl.se/bug/?i=22070 + [290] = https://curl.se/bug/?i=22073 + [291] = https://curl.se/bug/?i=22072 + [292] = https://curl.se/bug/?i=22052 + [294] = https://curl.se/bug/?i=22063 + [299] = https://curl.se/bug/?i=22062 + [300] = https://curl.se/bug/?i=22061 + [302] = https://curl.se/bug/?i=22059 + [304] = https://curl.se/bug/?i=21943 diff --git a/third-party/curl/REUSE.toml b/third-party/curl/REUSE.toml new file mode 100644 index 0000000000..9e6d2d166b --- /dev/null +++ b/third-party/curl/REUSE.toml @@ -0,0 +1,41 @@ +# SPDX-License-Identifier: curl +# SPDX-FileCopyrightText: Daniel Stenberg, , et al. + +# This file describes the licensing and copyright situation for files that +# cannot be annotated directly, for example because of being uncommentable. +# Unless this is the case, a file should be annotated directly. +# +# This follows the REUSE specification: https://reuse.software/spec-3.2/#reusetoml + +version = 1 +SPDX-PackageName = "curl" +SPDX-PackageDownloadLocation = "https://curl.se/" + +[[annotations]] +path = [ + ".github/pull_request_template.md", + "docs/INSTALL", + "docs/libcurl/symbols-in-versions", + "docs/options-in-versions", + "docs/THANKS", + "lib/libcurl.vers.in", + "lib/libcurl.def", + "projects/OS400/README.OS400", + "projects/vms/build_vms.com", + "projects/vms/curl_release_note_start.txt", + "projects/vms/curlmsg.sdl", + "projects/vms/macro32_exactcase.patch", + "projects/vms/readme", + "projects/Windows/**", + "README", + "RELEASE-NOTES", + "renovate.json", + "tests/certs/**", + "tests/data/data**", + "tests/data/test**", + "tests/valgrind.supp", +] +SPDX-FileCopyrightText = "Daniel Stenberg, , et al." +SPDX-License-Identifier = "curl" +# If there is licensing/copyright information in or next to these files, prefer that +precedence = "closest" diff --git a/third-party/curl/SECURITY.md b/third-party/curl/SECURITY.md index b76da78cea..e579ebb6e6 100644 --- a/third-party/curl/SECURITY.md +++ b/third-party/curl/SECURITY.md @@ -6,11 +6,25 @@ SPDX-License-Identifier: curl # Security Policy -See [SECURITY-PROCESS](docs/SECURITY-PROCESS.md) for full details. +Read our [Vulnerability Disclosure Policy](docs/VULN-DISCLOSURE-POLICY.md). ## Reporting a Vulnerability -If you have found or just suspect a security problem somewhere in curl or -libcurl, report it on [HackerOne](https://hackerone.com/curl). +If you have found or suspect a security problem somewhere in curl or libcurl, +[report it](https://curl.se/dev/vuln-disclosure.html)! -We treat security issues with confidentiality until controlled and disclosed responsibly. +We treat security issues with confidentiality until controlled and disclosed +responsibly. + +## OpenSSF Best Practices + +curl has achieved Gold status on the Open Source Security Foundation (OpenSSF) +[Best Practices](https://bestpractices.dev/) (formerly Core Infrastructure +Initiative Best Practices), reflecting its adherence to rigorous security and +best practice standards. This achievement highlights curl's comprehensive +documentation, secure development processes, effective change control +mechanisms, and strong maintenance routines. Meeting these criteria +demonstrates curl's commitment to security and reliability, ensuring the +project's sustainability and trustworthiness. This underscores curl's role as +a leader in open-source software practices. More information can be found on +[curl's OpenSSF Best Practices project page](https://www.bestpractices.dev/projects/63). diff --git a/third-party/curl/acinclude.m4 b/third-party/curl/acinclude.m4 index 81a1c1d0de..ed8b0499dd 100644 --- a/third-party/curl/acinclude.m4 +++ b/third-party/curl/acinclude.m4 @@ -25,19 +25,19 @@ dnl CURL_CHECK_DEF (SYMBOL, [INCLUDES], [SILENT]) dnl ------------------------------------------------- dnl Use the C preprocessor to find out if the given object-style symbol -dnl is defined and get its expansion. This macro will not use default -dnl includes even if no INCLUDES argument is given. This macro will run +dnl is defined and get its expansion. This macro does not use default +dnl includes even if no INCLUDES argument is given. This macro runs dnl silently when invoked with three arguments. If the expansion would -dnl result in a set of double-quoted strings the returned expansion will -dnl actually be a single double-quoted string concatenating all them. +dnl result in a set of double-quoted strings the returned expansion is +dnl actually a single double-quoted string concatenating all them. AC_DEFUN([CURL_CHECK_DEF], [ - AC_REQUIRE([CURL_CPP_P])dnl + AC_REQUIRE([CURL_CPP_P]) OLDCPPFLAGS=$CPPFLAGS - # CPPPFLAG comes from CURL_CPP_P + dnl CPPPFLAG comes from CURL_CPP_P CPPFLAGS="$CPPFLAGS $CPPPFLAG" - AS_VAR_PUSHDEF([ac_HaveDef], [curl_cv_have_def_$1])dnl - AS_VAR_PUSHDEF([ac_Def], [curl_cv_def_$1])dnl + AS_VAR_PUSHDEF([ac_HaveDef], [curl_cv_have_def_$1]) + AS_VAR_PUSHDEF([ac_Def], [curl_cv_def_$1]) if test -z "$SED"; then AC_MSG_ERROR([SED not set. Cannot continue without SED being set.]) fi @@ -48,10 +48,10 @@ AC_DEFUN([CURL_CHECK_DEF], [ tmp_exp="" AC_PREPROC_IFELSE([ AC_LANG_SOURCE( -ifelse($2,,,[$2])[[ -#ifdef $1 -CURL_DEF_TOKEN $1 -#endif + ifelse($2,,,[$2])[[ + #ifdef $1 + CURL_DEF_TOKEN $1 + #endif ]]) ],[ tmp_exp=`eval "$ac_cpp conftest.$ac_ext" 2>/dev/null | \ @@ -70,8 +70,8 @@ CURL_DEF_TOKEN $1 AS_VAR_SET(ac_Def, $tmp_exp) ifelse($3,,[AC_MSG_RESULT([$tmp_exp])]) fi - AS_VAR_POPDEF([ac_Def])dnl - AS_VAR_POPDEF([ac_HaveDef])dnl + AS_VAR_POPDEF([ac_Def]) + AS_VAR_POPDEF([ac_HaveDef]) CPPFLAGS=$OLDCPPFLAGS ]) @@ -79,24 +79,23 @@ CURL_DEF_TOKEN $1 dnl CURL_CHECK_DEF_CC (SYMBOL, [INCLUDES], [SILENT]) dnl ------------------------------------------------- dnl Use the C compiler to find out only if the given symbol is defined -dnl or not, this can not find out its expansion. This macro will not use +dnl or not, this can not find out its expansion. This macro does not use dnl default includes even if no INCLUDES argument is given. This macro -dnl will run silently when invoked with three arguments. +dnl runs silently when invoked with three arguments. AC_DEFUN([CURL_CHECK_DEF_CC], [ - AS_VAR_PUSHDEF([ac_HaveDef], [curl_cv_have_def_$1])dnl + AS_VAR_PUSHDEF([ac_HaveDef], [curl_cv_have_def_$1]) ifelse($3,,[AC_MSG_CHECKING([for compiler definition of $1])]) AC_COMPILE_IFELSE([ AC_LANG_SOURCE( -ifelse($2,,,[$2])[[ -int main (void) -{ -#ifdef $1 - return 0; -#else - force compilation error -#endif -} + ifelse($2,,,[$2])[[ + int main(void) + { + #ifndef $1 + #error force compilation error + #endif + return 0; + } ]]) ],[ tst_symbol_defined="yes" @@ -110,7 +109,7 @@ int main (void) AS_VAR_SET(ac_HaveDef, no) ifelse($3,,[AC_MSG_RESULT([no])]) fi - AS_VAR_POPDEF([ac_HaveDef])dnl + AS_VAR_POPDEF([ac_HaveDef]) ]) @@ -123,16 +122,15 @@ AC_DEFUN([CURL_CHECK_LIB_XNET], [ tst_lib_xnet_required="no" AC_COMPILE_IFELSE([ AC_LANG_SOURCE([[ -int main (void) -{ -#if defined(__hpux) && defined(_XOPEN_SOURCE) && (_XOPEN_SOURCE >= 600) - return 0; -#elif defined(__hpux) && defined(_XOPEN_SOURCE_EXTENDED) - return 0; -#else - force compilation error -#endif -} + int main(void) + { + #if defined(__hpux) && defined(_XOPEN_SOURCE) && (_XOPEN_SOURCE >= 600) + #elif defined(__hpux) && defined(_XOPEN_SOURCE_EXTENDED) + #else + #error force compilation error + #endif + return 0; + } ]]) ],[ tst_lib_xnet_required="yes" @@ -154,9 +152,8 @@ AC_DEFUN([CURL_CHECK_AIX_ALL_SOURCE], [ #ifndef _ALL_SOURCE # undef _ALL_SOURCE #endif]) - AC_BEFORE([$0], [AC_SYS_LARGEFILE])dnl - AC_BEFORE([$0], [CURL_CONFIGURE_REENTRANT])dnl - AC_BEFORE([$0], [CURL_CONFIGURE_PULL_SYS_POLL])dnl + AC_BEFORE([$0], [AC_SYS_LARGEFILE]) + AC_BEFORE([$0], [CURL_CONFIGURE_REENTRANT]) AC_MSG_CHECKING([if OS is AIX (to define _ALL_SOURCE)]) AC_EGREP_CPP([yes_this_is_aix],[ #ifdef _AIX @@ -171,144 +168,29 @@ AC_DEFUN([CURL_CHECK_AIX_ALL_SOURCE], [ ]) -dnl CURL_CHECK_HEADER_WINDOWS -dnl ------------------------------------------------- -dnl Check for compilable and valid windows.h header - -AC_DEFUN([CURL_CHECK_HEADER_WINDOWS], [ - AC_CACHE_CHECK([for windows.h], [curl_cv_header_windows_h], [ - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#undef inline -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include - ]],[[ -#if defined(__CYGWIN__) || defined(__CEGCC__) - HAVE_WINDOWS_H shall not be defined. -#else - int dummy=2*WINVER; -#endif - ]]) - ],[ - curl_cv_header_windows_h="yes" - ],[ - curl_cv_header_windows_h="no" - ]) - ]) - case "$curl_cv_header_windows_h" in - yes) - AC_DEFINE_UNQUOTED(HAVE_WINDOWS_H, 1, - [Define to 1 if you have the windows.h header file.]) - ;; - esac -]) - - dnl CURL_CHECK_NATIVE_WINDOWS dnl ------------------------------------------------- dnl Check if building a native Windows target AC_DEFUN([CURL_CHECK_NATIVE_WINDOWS], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINDOWS])dnl AC_CACHE_CHECK([whether build target is a native Windows one], [curl_cv_native_windows], [ - if test "$curl_cv_header_windows_h" = "no"; then + AC_COMPILE_IFELSE([ + AC_LANG_PROGRAM([[ + ]],[[ + #ifdef _WIN32 + int dummy = 1; + (void)dummy; + #else + #error Not a native Windows build target. + #endif + ]]) + ],[ + curl_cv_native_windows="yes" + ],[ curl_cv_native_windows="no" - else - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ - ]],[[ -#if defined(__MINGW32__) || defined(__MINGW32CE__) || \ - (defined(_MSC_VER) && (defined(_WIN32) || defined(_WIN64))) - int dummy=1; -#else - Not a native Windows build target. -#endif - ]]) - ],[ - curl_cv_native_windows="yes" - ],[ - curl_cv_native_windows="no" - ]) - fi - ]) - AM_CONDITIONAL(DOING_NATIVE_WINDOWS, test "x$curl_cv_native_windows" = xyes) -]) - - -dnl CURL_CHECK_HEADER_WINSOCK2 -dnl ------------------------------------------------- -dnl Check for compilable and valid winsock2.h header - -AC_DEFUN([CURL_CHECK_HEADER_WINSOCK2], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINDOWS])dnl - AC_CACHE_CHECK([for winsock2.h], [curl_cv_header_winsock2_h], [ - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#undef inline -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#include - ]],[[ -#if defined(__CYGWIN__) || defined(__CEGCC__) || defined(__MINGW32CE__) - HAVE_WINSOCK2_H shall not be defined. -#else - int dummy=2*IPPROTO_ESP; -#endif - ]]) - ],[ - curl_cv_header_winsock2_h="yes" - ],[ - curl_cv_header_winsock2_h="no" ]) ]) - case "$curl_cv_header_winsock2_h" in - yes) - AC_DEFINE_UNQUOTED(HAVE_WINSOCK2_H, 1, - [Define to 1 if you have the winsock2.h header file.]) - ;; - esac -]) - - -dnl CURL_CHECK_HEADER_WS2TCPIP -dnl ------------------------------------------------- -dnl Check for compilable and valid ws2tcpip.h header - -AC_DEFUN([CURL_CHECK_HEADER_WS2TCPIP], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINSOCK2])dnl - AC_CACHE_CHECK([for ws2tcpip.h], [curl_cv_header_ws2tcpip_h], [ - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#undef inline -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#include -#include - ]],[[ -#if defined(__CYGWIN__) || defined(__CEGCC__) || defined(__MINGW32CE__) - HAVE_WS2TCPIP_H shall not be defined. -#else - int dummy=2*IP_PKTINFO; -#endif - ]]) - ],[ - curl_cv_header_ws2tcpip_h="yes" - ],[ - curl_cv_header_ws2tcpip_h="no" - ]) - ]) - case "$curl_cv_header_ws2tcpip_h" in - yes) - AC_DEFINE_UNQUOTED(HAVE_WS2TCPIP_H, 1, - [Define to 1 if you have the ws2tcpip.h header file.]) - ;; - esac + AM_CONDITIONAL(DOING_NATIVE_WINDOWS, test "$curl_cv_native_windows" = "yes") ]) @@ -318,25 +200,25 @@ dnl Check for compilable and valid lber.h header, dnl and check if it is needed even with ldap.h AC_DEFUN([CURL_CHECK_HEADER_LBER], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINDOWS])dnl + AC_REQUIRE([CURL_CHECK_NATIVE_WINDOWS]) AC_CACHE_CHECK([for lber.h], [curl_cv_header_lber_h], [ AC_COMPILE_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#else -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#endif -#ifndef NULL -#define NULL (void *)0 -#endif -#include + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #endif + #ifndef NULL + #define NULL (void *)0 + #endif + #include ]],[[ BerValue *bvp = NULL; BerElement *bep = ber_init(bvp); @@ -351,27 +233,27 @@ AC_DEFUN([CURL_CHECK_HEADER_LBER], [ if test "$curl_cv_header_lber_h" = "yes"; then AC_DEFINE_UNQUOTED(HAVE_LBER_H, 1, [Define to 1 if you have the lber.h header file.]) - # + AC_COMPILE_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#else -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#endif -#ifndef NULL -#define NULL (void *)0 -#endif -#ifndef LDAP_DEPRECATED -#define LDAP_DEPRECATED 1 -#endif -#include + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #endif + #ifndef NULL + #define NULL (void *)0 + #endif + #ifndef LDAP_DEPRECATED + #define LDAP_DEPRECATED 1 + #endif + #include ]],[[ BerValue *bvp = NULL; BerElement *bep = ber_init(bvp); @@ -382,7 +264,7 @@ AC_DEFUN([CURL_CHECK_HEADER_LBER], [ ],[ curl_cv_need_header_lber_h="yes" ]) - # + case "$curl_cv_need_header_lber_h" in yes) AC_DEFINE_UNQUOTED(NEED_LBER_H, 1, @@ -398,31 +280,32 @@ dnl ------------------------------------------------- dnl Check for compilable and valid ldap.h header AC_DEFUN([CURL_CHECK_HEADER_LDAP], [ - AC_REQUIRE([CURL_CHECK_HEADER_LBER])dnl + AC_REQUIRE([CURL_CHECK_HEADER_LBER]) AC_CACHE_CHECK([for ldap.h], [curl_cv_header_ldap_h], [ AC_COMPILE_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#else -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#endif -#ifndef LDAP_DEPRECATED -#define LDAP_DEPRECATED 1 -#endif -#ifdef NEED_LBER_H -#include -#endif -#include + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #endif + #ifndef LDAP_DEPRECATED + #define LDAP_DEPRECATED 1 + #endif + #ifdef NEED_LBER_H + #include + #endif + #include ]],[[ - LDAP *ldp = ldap_init("dummy", LDAP_PORT); + LDAP *ldp = ldap_init("0.0.0.0", LDAP_PORT); int res = ldap_unbind(ldp); + (void)res; ]]) ],[ curl_cv_header_ldap_h="yes" @@ -444,33 +327,34 @@ dnl ------------------------------------------------- dnl Check for compilable and valid ldap_ssl.h header AC_DEFUN([CURL_CHECK_HEADER_LDAP_SSL], [ - AC_REQUIRE([CURL_CHECK_HEADER_LDAP])dnl + AC_REQUIRE([CURL_CHECK_HEADER_LDAP]) AC_CACHE_CHECK([for ldap_ssl.h], [curl_cv_header_ldap_ssl_h], [ AC_COMPILE_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#else -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#endif -#ifndef LDAP_DEPRECATED -#define LDAP_DEPRECATED 1 -#endif -#ifdef NEED_LBER_H -#include -#endif -#ifdef HAVE_LDAP_H -#include -#endif -#include + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #endif + #ifndef LDAP_DEPRECATED + #define LDAP_DEPRECATED 1 + #endif + #ifdef NEED_LBER_H + #include + #endif + #ifdef HAVE_LDAP_H + #include + #endif + #include ]],[[ - LDAP *ldp = ldapssl_init("dummy", LDAPS_PORT, 1); + LDAP *ldp = ldapssl_init("0.0.0.0", LDAPS_PORT, 1); + (void)ldp; ]]) ],[ curl_cv_header_ldap_ssl_h="yes" @@ -496,12 +380,12 @@ dnl whitespace separated list of libraries to check dnl before the WINLDAP default ones. AC_DEFUN([CURL_CHECK_LIBS_WINLDAP], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINBER])dnl - # + AC_REQUIRE([CURL_CHECK_HEADER_WINBER]) + AC_MSG_CHECKING([for WINLDAP libraries]) - # + u_libs="" - # + ifelse($1,,,[ for x_lib in $1; do case "$x_lib" in @@ -519,10 +403,10 @@ AC_DEFUN([CURL_CHECK_LIBS_WINLDAP], [ fi done ]) - # + curl_cv_save_LIBS="$LIBS" curl_cv_ldap_LIBS="unknown" - # + for x_nlibs in '' "$u_libs" \ '-lwldap32' ; do if test "$curl_cv_ldap_LIBS" = "unknown"; then @@ -533,32 +417,33 @@ AC_DEFUN([CURL_CHECK_LIBS_WINLDAP], [ fi AC_LINK_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#include -#ifdef HAVE_WINBER_H -#include -#endif -#endif + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #include + #ifdef HAVE_WINBER_H + #include + #endif + #endif ]],[[ BERVAL *bvp = NULL; BerElement *bep = ber_init(bvp); - LDAP *ldp = ldap_init("dummy", LDAP_PORT); + LDAP *ldp = ldap_init("0.0.0.0", LDAP_PORT); ULONG res = ldap_unbind(ldp); ber_free(bep, 1); + (void)res; ]]) ],[ curl_cv_ldap_LIBS="$x_nlibs" ]) fi done - # + LIBS="$curl_cv_save_LIBS" - # + case X-"$curl_cv_ldap_LIBS" in X-unknown) AC_MSG_RESULT([cannot find WINLDAP libraries]) @@ -575,7 +460,6 @@ AC_DEFUN([CURL_CHECK_LIBS_WINLDAP], [ AC_MSG_RESULT([$curl_cv_ldap_LIBS]) ;; esac - # ]) @@ -588,12 +472,12 @@ dnl whitespace separated list of libraries to check dnl before the default ones. AC_DEFUN([CURL_CHECK_LIBS_LDAP], [ - AC_REQUIRE([CURL_CHECK_HEADER_LDAP])dnl - # + AC_REQUIRE([CURL_CHECK_HEADER_LDAP]) + AC_MSG_CHECKING([for LDAP libraries]) - # + u_libs="" - # + ifelse($1,,,[ for x_lib in $1; do case "$x_lib" in @@ -611,17 +495,17 @@ AC_DEFUN([CURL_CHECK_LIBS_LDAP], [ fi done ]) - # + curl_cv_save_LIBS="$LIBS" curl_cv_ldap_LIBS="unknown" - # + for x_nlibs in '' "$u_libs" \ '-lldap' \ '-lldap -llber' \ '-llber -lldap' \ '-lldapssl -lldapx -lldapsdk' \ '-lldapsdk -lldapx -lldapssl' \ - '-lldap -llber -lssl -lcrypto' ; do + '-lldap -llber -lssl -lcrypto'; do if test "$curl_cv_ldap_LIBS" = "unknown"; then if test -z "$x_nlibs"; then @@ -631,44 +515,45 @@ AC_DEFUN([CURL_CHECK_LIBS_LDAP], [ fi AC_LINK_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#else -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#endif -#ifndef NULL -#define NULL (void *)0 -#endif -#ifndef LDAP_DEPRECATED -#define LDAP_DEPRECATED 1 -#endif -#ifdef NEED_LBER_H -#include -#endif -#ifdef HAVE_LDAP_H -#include -#endif + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #endif + #ifndef NULL + #define NULL (void *)0 + #endif + #ifndef LDAP_DEPRECATED + #define LDAP_DEPRECATED 1 + #endif + #ifdef NEED_LBER_H + #include + #endif + #ifdef HAVE_LDAP_H + #include + #endif ]],[[ BerValue *bvp = NULL; BerElement *bep = ber_init(bvp); - LDAP *ldp = ldap_init("dummy", LDAP_PORT); + LDAP *ldp = ldap_init("0.0.0.0", LDAP_PORT); int res = ldap_unbind(ldp); ber_free(bep, 1); + (void)res; ]]) ],[ curl_cv_ldap_LIBS="$x_nlibs" ]) fi done - # + LIBS="$curl_cv_save_LIBS" - # + case X-"$curl_cv_ldap_LIBS" in X-unknown) AC_MSG_RESULT([cannot find LDAP libraries]) @@ -682,10 +567,13 @@ AC_DEFUN([CURL_CHECK_LIBS_LDAP], [ else LIBS="$curl_cv_ldap_LIBS $curl_cv_save_LIBS" fi + dnl FIXME: Enable when ldap was detected via pkg-config + if false; then + LIBCURL_PC_REQUIRES_PRIVATE="ldap $LIBCURL_PC_REQUIRES_PRIVATE" + fi AC_MSG_RESULT([$curl_cv_ldap_LIBS]) ;; esac - # ]) @@ -697,32 +585,27 @@ dnl hosts have it, but AIX 4.3 is one known exception. AC_DEFUN([TYPE_SOCKADDR_STORAGE], [ AC_CHECK_TYPE([struct sockaddr_storage], - AC_DEFINE(HAVE_STRUCT_SOCKADDR_STORAGE, 1, - [if struct sockaddr_storage is defined]), , + AC_DEFINE(HAVE_STRUCT_SOCKADDR_STORAGE, 1, + [if struct sockaddr_storage is defined]), , [ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#ifdef HAVE_WINSOCK2_H -#include -#endif -#else -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_SOCKET_H -#include -#endif -#ifdef HAVE_NETINET_IN_H -#include -#endif -#ifdef HAVE_ARPA_INET_H -#include -#endif -#endif + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #include + #ifdef HAVE_NETINET_IN_H + #include + #endif + #ifdef HAVE_ARPA_INET_H + #include + #endif + #endif ]) ]) @@ -731,31 +614,26 @@ dnl ------------------------------------------------- dnl Test if the socket recv() function is available, AC_DEFUN([CURL_CHECK_FUNC_RECV], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINSOCK2])dnl - AC_REQUIRE([CURL_INCLUDES_BSDSOCKET])dnl - AC_CHECK_HEADERS(sys/types.h sys/socket.h) - # + AC_REQUIRE([CURL_CHECK_NATIVE_WINDOWS]) + AC_REQUIRE([CURL_INCLUDES_BSDSOCKET]) + AC_CHECK_HEADERS(sys/types.h) + AC_MSG_CHECKING([for recv]) AC_LINK_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#ifdef HAVE_WINSOCK2_H -#include -#endif -#else -$curl_includes_bsdsocket -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_SOCKET_H -#include -#endif -#endif + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + $curl_includes_bsdsocket + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #include + #endif ]],[[ recv(0, 0, 0, 0); ]]) @@ -766,11 +644,11 @@ $curl_includes_bsdsocket AC_MSG_RESULT([no]) curl_cv_recv="no" ]) - # + if test "$curl_cv_recv" = "yes"; then - AC_DEFINE_UNQUOTED(HAVE_RECV, 1, - [Define to 1 if you have the recv function.]) - curl_cv_func_recv="yes" + AC_DEFINE_UNQUOTED(HAVE_RECV, 1, + [Define to 1 if you have the recv function.]) + curl_cv_func_recv="yes" else AC_MSG_ERROR([Unable to link function recv]) fi @@ -782,33 +660,29 @@ dnl ------------------------------------------------- dnl Test if the socket send() function is available, AC_DEFUN([CURL_CHECK_FUNC_SEND], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINSOCK2])dnl - AC_REQUIRE([CURL_INCLUDES_BSDSOCKET])dnl - AC_CHECK_HEADERS(sys/types.h sys/socket.h) - # + AC_REQUIRE([CURL_CHECK_NATIVE_WINDOWS]) + AC_REQUIRE([CURL_INCLUDES_BSDSOCKET]) + AC_CHECK_HEADERS(sys/types.h) + AC_MSG_CHECKING([for send]) AC_LINK_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#ifdef HAVE_WINSOCK2_H -#include -#endif -#else -$curl_includes_bsdsocket -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_SOCKET_H -#include -#endif -#endif + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + $curl_includes_bsdsocket + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #include + #endif ]],[[ - send(0, 0, 0, 0); + char s[] = ""; + send(0, (void *)s, 0, 0); ]]) ],[ AC_MSG_RESULT([yes]) @@ -817,7 +691,7 @@ $curl_includes_bsdsocket AC_MSG_RESULT([no]) curl_cv_send="no" ]) - # + if test "$curl_cv_send" = "yes"; then AC_DEFINE_UNQUOTED(HAVE_SEND, 1, [Define to 1 if you have the send function.]) @@ -827,84 +701,36 @@ $curl_includes_bsdsocket fi ]) -dnl CURL_CHECK_MSG_NOSIGNAL -dnl ------------------------------------------------- -dnl Check for MSG_NOSIGNAL - -AC_DEFUN([CURL_CHECK_MSG_NOSIGNAL], [ - AC_CHECK_HEADERS(sys/types.h sys/socket.h) - AC_CACHE_CHECK([for MSG_NOSIGNAL], [curl_cv_msg_nosignal], [ - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#ifdef HAVE_WINSOCK2_H -#include -#endif -#else -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_SOCKET_H -#include -#endif -#endif - ]],[[ - int flag=MSG_NOSIGNAL; - ]]) - ],[ - curl_cv_msg_nosignal="yes" - ],[ - curl_cv_msg_nosignal="no" - ]) - ]) - case "$curl_cv_msg_nosignal" in - yes) - AC_DEFINE_UNQUOTED(HAVE_MSG_NOSIGNAL, 1, - [Define to 1 if you have the MSG_NOSIGNAL flag.]) - ;; - esac -]) - dnl CURL_CHECK_STRUCT_TIMEVAL dnl ------------------------------------------------- dnl Check for timeval struct AC_DEFUN([CURL_CHECK_STRUCT_TIMEVAL], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINSOCK2])dnl - AC_CHECK_HEADERS(sys/types.h sys/time.h sys/socket.h) + AC_REQUIRE([CURL_CHECK_NATIVE_WINDOWS]) + AC_CHECK_HEADERS(sys/types.h) AC_CACHE_CHECK([for struct timeval], [curl_cv_struct_timeval], [ AC_COMPILE_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#ifdef HAVE_WINSOCK2_H -#include -#endif -#endif -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_TIME_H -#include -#endif -#include -#ifdef HAVE_SYS_SOCKET_H -#include -#endif + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + #include + #include + #endif + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #include ]],[[ struct timeval ts; - ts.tv_sec = 0; + ts.tv_sec = 0; ts.tv_usec = 0; + (void)ts; ]]) ],[ curl_cv_struct_timeval="yes" @@ -921,122 +747,38 @@ AC_DEFUN([CURL_CHECK_STRUCT_TIMEVAL], [ ]) -dnl TYPE_IN_ADDR_T -dnl ------------------------------------------------- -dnl Check for in_addr_t: it is used to receive the return code of inet_addr() -dnl and a few other things. - -AC_DEFUN([TYPE_IN_ADDR_T], [ - AC_CHECK_TYPE([in_addr_t], ,[ - dnl in_addr_t not available - AC_CACHE_CHECK([for in_addr_t equivalent], - [curl_cv_in_addr_t_equiv], [ - curl_cv_in_addr_t_equiv="unknown" - for t in "unsigned long" int size_t unsigned long; do - if test "$curl_cv_in_addr_t_equiv" = "unknown"; then - AC_LINK_IFELSE([ - AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#ifdef HAVE_WINSOCK2_H -#include -#endif -#else -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_SOCKET_H -#include -#endif -#ifdef HAVE_NETINET_IN_H -#include -#endif -#ifdef HAVE_ARPA_INET_H -#include -#endif -#endif - ]],[[ - $t data = inet_addr ("1.2.3.4"); - ]]) - ],[ - curl_cv_in_addr_t_equiv="$t" - ]) - fi - done - ]) - case "$curl_cv_in_addr_t_equiv" in - unknown) - AC_MSG_ERROR([Cannot find a type to use in place of in_addr_t]) - ;; - *) - AC_DEFINE_UNQUOTED(in_addr_t, $curl_cv_in_addr_t_equiv, - [Type to use in place of in_addr_t when system does not provide it.]) - ;; - esac - ],[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#ifdef HAVE_WINSOCK2_H -#include -#endif -#else -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_SOCKET_H -#include -#endif -#ifdef HAVE_NETINET_IN_H -#include -#endif -#ifdef HAVE_ARPA_INET_H -#include -#endif -#endif - ]) -]) - - dnl CURL_CHECK_FUNC_CLOCK_GETTIME_MONOTONIC dnl ------------------------------------------------- dnl Check if monotonic clock_gettime is available. AC_DEFUN([CURL_CHECK_FUNC_CLOCK_GETTIME_MONOTONIC], [ - AC_CHECK_HEADERS(sys/types.h sys/time.h) + AC_CHECK_HEADERS(sys/types.h) AC_MSG_CHECKING([for monotonic clock_gettime]) - # - if test "x$dontwant_rt" = "xno" ; then - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_TIME_H -#include -#endif -#include - ]],[[ - struct timespec ts; - (void)clock_gettime(CLOCK_MONOTONIC, &ts); - ]]) - ],[ - AC_MSG_RESULT([yes]) - curl_func_clock_gettime="yes" - ],[ - AC_MSG_RESULT([no]) - curl_func_clock_gettime="no" - ]) - fi + + AC_COMPILE_IFELSE([ + AC_LANG_PROGRAM([[ + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #ifndef _WIN32 + #include + #endif + #include + ]],[[ + struct timespec ts; + (void)clock_gettime(CLOCK_MONOTONIC, &ts); + (void)ts; + ]]) + ],[ + AC_MSG_RESULT([yes]) + curl_func_clock_gettime="yes" + ],[ + AC_MSG_RESULT([no]) + curl_func_clock_gettime="no" + ]) + dnl Definition of HAVE_CLOCK_GETTIME_MONOTONIC is intentionally postponed - dnl until library linking and run-time checks for clock_gettime succeed. + dnl until library linking and runtime checks for clock_gettime succeed. ]) dnl CURL_CHECK_FUNC_CLOCK_GETTIME_MONOTONIC_RAW @@ -1044,31 +786,30 @@ dnl ------------------------------------------------- dnl Check if monotonic clock_gettime is available. AC_DEFUN([CURL_CHECK_FUNC_CLOCK_GETTIME_MONOTONIC_RAW], [ - AC_CHECK_HEADERS(sys/types.h sys/time.h) + AC_CHECK_HEADERS(sys/types.h) AC_MSG_CHECKING([for raw monotonic clock_gettime]) - # - if test "x$dontwant_rt" = "xno" ; then - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_TIME_H -#include -#endif -#include - ]],[[ - struct timespec ts; - (void)clock_gettime(CLOCK_MONOTONIC_RAW, &ts); - ]]) - ],[ - AC_MSG_RESULT([yes]) - AC_DEFINE_UNQUOTED(HAVE_CLOCK_GETTIME_MONOTONIC_RAW, 1, - [Define to 1 if you have the clock_gettime function and raw monotonic timer.]) - ],[ - AC_MSG_RESULT([no]) - ]) - fi + + AC_COMPILE_IFELSE([ + AC_LANG_PROGRAM([[ + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #ifndef _WIN32 + #include + #endif + #include + ]],[[ + struct timespec ts; + (void)clock_gettime(CLOCK_MONOTONIC_RAW, &ts); + (void)ts; + ]]) + ],[ + AC_MSG_RESULT([yes]) + AC_DEFINE_UNQUOTED(HAVE_CLOCK_GETTIME_MONOTONIC_RAW, 1, + [Define to 1 if you have the clock_gettime function and raw monotonic timer.]) + ],[ + AC_MSG_RESULT([no]) + ]) ]) @@ -1078,15 +819,15 @@ dnl If monotonic clock_gettime is available then, dnl check and prepended to LIBS any needed libraries. AC_DEFUN([CURL_CHECK_LIBS_CLOCK_GETTIME_MONOTONIC], [ - AC_REQUIRE([CURL_CHECK_FUNC_CLOCK_GETTIME_MONOTONIC])dnl - # + AC_REQUIRE([CURL_CHECK_FUNC_CLOCK_GETTIME_MONOTONIC]) + if test "$curl_func_clock_gettime" = "yes"; then - # + AC_MSG_CHECKING([for clock_gettime in libraries]) - # + curl_cv_save_LIBS="$LIBS" curl_cv_gclk_LIBS="unknown" - # + for x_xlibs in '' '-lrt' '-lposix4' ; do if test "$curl_cv_gclk_LIBS" = "unknown"; then if test -z "$x_xlibs"; then @@ -1096,29 +837,30 @@ AC_DEFUN([CURL_CHECK_LIBS_CLOCK_GETTIME_MONOTONIC], [ fi AC_LINK_IFELSE([ AC_LANG_PROGRAM([[ -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_TIME_H -#include -#endif -#include + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #ifndef _WIN32 + #include + #endif + #include ]],[[ struct timespec ts; (void)clock_gettime(CLOCK_MONOTONIC, &ts); + (void)ts; ]]) ],[ curl_cv_gclk_LIBS="$x_xlibs" ]) fi done - # + LIBS="$curl_cv_save_LIBS" - # + case X-"$curl_cv_gclk_LIBS" in X-unknown) AC_MSG_RESULT([cannot find clock_gettime]) - AC_MSG_WARN([HAVE_CLOCK_GETTIME_MONOTONIC will not be defined]) + AC_MSG_WARN([HAVE_CLOCK_GETTIME_MONOTONIC is not defined]) curl_func_clock_gettime="no" ;; X-) @@ -1126,58 +868,59 @@ AC_DEFUN([CURL_CHECK_LIBS_CLOCK_GETTIME_MONOTONIC], [ curl_func_clock_gettime="yes" ;; *) - if test -z "$curl_cv_save_LIBS"; then - LIBS="$curl_cv_gclk_LIBS" + if test "$dontwant_rt" = "yes"; then + AC_MSG_WARN([needs -lrt but asked not to use it, HAVE_CLOCK_GETTIME_MONOTONIC is not defined]) + curl_func_clock_gettime="no" else - LIBS="$curl_cv_gclk_LIBS $curl_cv_save_LIBS" + if test -z "$curl_cv_save_LIBS"; then + LIBS="$curl_cv_gclk_LIBS" + else + LIBS="$curl_cv_gclk_LIBS $curl_cv_save_LIBS" + fi + AC_MSG_RESULT([$curl_cv_gclk_LIBS]) + curl_func_clock_gettime="yes" fi - AC_MSG_RESULT([$curl_cv_gclk_LIBS]) - curl_func_clock_gettime="yes" ;; esac - # + dnl only do runtime verification when not cross-compiling - if test "x$cross_compiling" != "xyes" && + if test "$cross_compiling" != "yes" && test "$curl_func_clock_gettime" = "yes"; then AC_MSG_CHECKING([if monotonic clock_gettime works]) CURL_RUN_IFELSE([ AC_LANG_PROGRAM([[ -#ifdef HAVE_STDLIB_H -#include -#endif -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_TIME_H -#include -#endif -#include + #include + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #ifndef _WIN32 + #include + #endif + #include ]],[[ struct timespec ts; - if (0 == clock_gettime(CLOCK_MONOTONIC, &ts)) - exit(0); - else - exit(1); + if(0 == clock_gettime(CLOCK_MONOTONIC, &ts)) + return 0; + (void)ts; + return 1; ]]) ],[ AC_MSG_RESULT([yes]) ],[ AC_MSG_RESULT([no]) - AC_MSG_WARN([HAVE_CLOCK_GETTIME_MONOTONIC will not be defined]) + AC_MSG_WARN([HAVE_CLOCK_GETTIME_MONOTONIC is not defined]) curl_func_clock_gettime="no" LIBS="$curl_cv_save_LIBS" ]) fi - # + case "$curl_func_clock_gettime" in yes) AC_DEFINE_UNQUOTED(HAVE_CLOCK_GETTIME_MONOTONIC, 1, [Define to 1 if you have the clock_gettime function and monotonic timer.]) ;; esac - # fi - # ]) @@ -1187,8 +930,8 @@ dnl Verify if network connect function is already available dnl using current libraries or if another one is required. AC_DEFUN([CURL_CHECK_LIBS_CONNECT], [ - AC_REQUIRE([CURL_INCLUDES_WINSOCK2])dnl - AC_REQUIRE([CURL_INCLUDES_BSDSOCKET])dnl + AC_REQUIRE([CURL_INCLUDES_WINSOCK2]) + AC_REQUIRE([CURL_INCLUDES_BSDSOCKET]) AC_MSG_CHECKING([for connect in libraries]) tst_connect_save_LIBS="$LIBS" tst_connect_need_LIBS="unknown" @@ -1199,7 +942,7 @@ AC_DEFUN([CURL_CHECK_LIBS_CONNECT], [ AC_LANG_PROGRAM([[ $curl_includes_winsock2 $curl_includes_bsdsocket - #if !defined(HAVE_WINDOWS_H) && !defined(HAVE_PROTO_BSDSOCKET_H) + #if !defined(_WIN32) && !defined(HAVE_PROTO_BSDSOCKET_H) int connect(int, void*, int); #endif ]],[[ @@ -1212,7 +955,7 @@ AC_DEFUN([CURL_CHECK_LIBS_CONNECT], [ fi done LIBS="$tst_connect_save_LIBS" - # + case X-"$tst_connect_need_LIBS" in X-unknown) AC_MSG_RESULT([cannot find connect]) @@ -1229,100 +972,40 @@ AC_DEFUN([CURL_CHECK_LIBS_CONNECT], [ ]) -dnl CURL_DEFINE_UNQUOTED (VARIABLE, [VALUE]) -dnl ------------------------------------------------- -dnl Like AC_DEFINE_UNQUOTED this macro will define a C preprocessor -dnl symbol that can be further used in custom template configuration -dnl files. This macro, unlike AC_DEFINE_UNQUOTED, does not use a third -dnl argument for the description. Symbol definitions done with this -dnl macro are intended to be exclusively used in handcrafted *.h.in -dnl template files. Contrary to what AC_DEFINE_UNQUOTED does, this one -dnl prevents autoheader generation and insertion of symbol template -dnl stub and definition into the first configuration header file. Do -dnl not use this macro as a replacement for AC_DEFINE_UNQUOTED, each -dnl one serves different functional needs. - -AC_DEFUN([CURL_DEFINE_UNQUOTED], [ -cat >>confdefs.h <<_EOF -[@%:@define] $1 ifelse($#, 2, [$2], 1) -_EOF -]) - -dnl CURL_CONFIGURE_PULL_SYS_POLL -dnl ------------------------------------------------- -dnl The need for the sys/poll.h inclusion arises mainly to properly -dnl interface AIX systems which define macros 'events' and 'revents'. - -AC_DEFUN([CURL_CONFIGURE_PULL_SYS_POLL], [ - AC_REQUIRE([CURL_INCLUDES_POLL])dnl - # - tst_poll_events_macro_defined="unknown" - # - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ - $curl_includes_poll - ]],[[ -#if defined(events) || defined(revents) - return 0; -#else - force compilation error -#endif - ]]) - ],[ - tst_poll_events_macro_defined="yes" - ],[ - tst_poll_events_macro_defined="no" - ]) - # - if test "$tst_poll_events_macro_defined" = "yes"; then - if test "x$ac_cv_header_sys_poll_h" = "xyes"; then - CURL_DEFINE_UNQUOTED([CURL_PULL_SYS_POLL_H]) - fi - fi - # -]) - - dnl CURL_CHECK_FUNC_SELECT dnl ------------------------------------------------- dnl Test if the socket select() function is available. AC_DEFUN([CURL_CHECK_FUNC_SELECT], [ - AC_REQUIRE([CURL_CHECK_STRUCT_TIMEVAL])dnl - AC_REQUIRE([CURL_INCLUDES_BSDSOCKET])dnl - AC_CHECK_HEADERS(sys/select.h sys/socket.h) - # + AC_REQUIRE([CURL_CHECK_STRUCT_TIMEVAL]) + AC_REQUIRE([CURL_INCLUDES_BSDSOCKET]) + AC_CHECK_HEADERS(sys/select.h) + AC_MSG_CHECKING([for select]) AC_LINK_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#ifdef HAVE_WINSOCK2_H -#include -#endif -#endif -#ifdef HAVE_SYS_TYPES_H -#include -#endif -#ifdef HAVE_SYS_TIME_H -#include -#endif -#include -#ifndef HAVE_WINDOWS_H -#ifdef HAVE_SYS_SELECT_H -#include -#elif defined(HAVE_UNISTD_H) -#include -#endif -#ifdef HAVE_SYS_SOCKET_H -#include -#endif -$curl_includes_bsdsocket -#endif + #undef inline + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #else + #include + #include + #endif + #ifdef HAVE_SYS_TYPES_H + #include + #endif + #include + #ifndef _WIN32 + #ifdef HAVE_SYS_SELECT_H + #include + #elif defined(HAVE_UNISTD_H) + #include + #endif + $curl_includes_bsdsocket + #endif ]],[[ select(0, 0, 0, 0, 0); ]]) @@ -1333,7 +1016,7 @@ $curl_includes_bsdsocket AC_MSG_RESULT([no]) curl_cv_select="no" ]) - # + if test "$curl_cv_select" = "yes"; then AC_DEFINE_UNQUOTED(HAVE_SELECT, 1, [Define to 1 if you have the select function.]) @@ -1345,7 +1028,7 @@ $curl_includes_bsdsocket dnl CURL_VERIFY_RUNTIMELIBS dnl ------------------------------------------------- dnl Verify that the shared libs found so far can be used when running -dnl programs, since otherwise the situation will create odd configure errors +dnl programs, since otherwise the situation creates odd configure errors dnl that are misleading people. dnl dnl Make sure this test is run BEFORE the first test in the script that @@ -1355,20 +1038,20 @@ dnl macro. It must also run AFTER all lib-checking macros are complete. AC_DEFUN([CURL_VERIFY_RUNTIMELIBS], [ dnl this test is of course not sensible if we are cross-compiling! - if test "x$cross_compiling" != xyes; then + if test "$cross_compiling" != "yes"; then - dnl just run a program to verify that the libs checked for previous to this - dnl point also is available run-time! - AC_MSG_CHECKING([run-time libs availability]) + dnl run a program to verify that the libs checked for previous to this + dnl point also is available runtime! + AC_MSG_CHECKING([runtime libs availability]) CURL_RUN_IFELSE([ -int main() -{ - return 0; -} -], + int main(void) + { + return 0; + } + ], AC_MSG_RESULT([fine]), AC_MSG_RESULT([failed]) - AC_MSG_ERROR([one or more libs available at link-time are not available run-time. Libs used at link-time: $LIBS]) + AC_MSG_ERROR([one or more libs available at link-time are not available runtime. Libs used at link-time: $LIBS]) ) dnl if this test fails, configure has already stopped @@ -1376,81 +1059,17 @@ int main() ]) -dnl CURL_CHECK_VARIADIC_MACROS -dnl ------------------------------------------------- -dnl Check compiler support of variadic macros - -AC_DEFUN([CURL_CHECK_VARIADIC_MACROS], [ - AC_CACHE_CHECK([for compiler support of C99 variadic macro style], - [curl_cv_variadic_macros_c99], [ - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#define c99_vmacro3(first, ...) fun3(first, __VA_ARGS__) -#define c99_vmacro2(first, ...) fun2(first, __VA_ARGS__) - int fun3(int arg1, int arg2, int arg3); - int fun2(int arg1, int arg2); - int fun3(int arg1, int arg2, int arg3) - { return arg1 + arg2 + arg3; } - int fun2(int arg1, int arg2) - { return arg1 + arg2; } - ]],[[ - int res3 = c99_vmacro3(1, 2, 3); - int res2 = c99_vmacro2(1, 2); - ]]) - ],[ - curl_cv_variadic_macros_c99="yes" - ],[ - curl_cv_variadic_macros_c99="no" - ]) - ]) - case "$curl_cv_variadic_macros_c99" in - yes) - AC_DEFINE_UNQUOTED(HAVE_VARIADIC_MACROS_C99, 1, - [Define to 1 if compiler supports C99 variadic macro style.]) - ;; - esac - AC_CACHE_CHECK([for compiler support of old gcc variadic macro style], - [curl_cv_variadic_macros_gcc], [ - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#define gcc_vmacro3(first, args...) fun3(first, args) -#define gcc_vmacro2(first, args...) fun2(first, args) - int fun3(int arg1, int arg2, int arg3); - int fun2(int arg1, int arg2); - int fun3(int arg1, int arg2, int arg3) - { return arg1 + arg2 + arg3; } - int fun2(int arg1, int arg2) - { return arg1 + arg2; } - ]],[[ - int res3 = gcc_vmacro3(1, 2, 3); - int res2 = gcc_vmacro2(1, 2); - ]]) - ],[ - curl_cv_variadic_macros_gcc="yes" - ],[ - curl_cv_variadic_macros_gcc="no" - ]) - ]) - case "$curl_cv_variadic_macros_gcc" in - yes) - AC_DEFINE_UNQUOTED(HAVE_VARIADIC_MACROS_GCC, 1, - [Define to 1 if compiler supports old gcc variadic macro style.]) - ;; - esac -]) - - dnl CURL_CHECK_CA_BUNDLE dnl ------------------------------------------------- dnl Check if a default ca-bundle should be used dnl -dnl regarding the paths this will scan: +dnl regarding the paths this scans: dnl /etc/ssl/certs/ca-certificates.crt Debian systems dnl /etc/pki/tls/certs/ca-bundle.crt Redhat and Mandriva dnl /usr/share/ssl/certs/ca-bundle.crt old(er) Redhat -dnl /usr/local/share/certs/ca-root-nss.crt FreeBSD, MidnightBSD -dnl /etc/ssl/cert.pem OpenBSD, FreeBSD, MidnightBSD (symlink) -dnl /etc/ssl/certs/ (ca path) SUSE +dnl /usr/local/share/certs/ca-root-nss.crt MidnightBSD +dnl /etc/ssl/cert.pem OpenBSD, MidnightBSD (symlink) +dnl /etc/ssl/certs (CA path) SUSE, FreeBSD AC_DEFUN([CURL_CHECK_CA_BUNDLE], [ @@ -1458,8 +1077,8 @@ AC_DEFUN([CURL_CHECK_CA_BUNDLE], [ AC_ARG_WITH(ca-bundle, AS_HELP_STRING([--with-ca-bundle=FILE], -[Path to a file containing CA certificates (example: /etc/ca-bundle.crt)]) -AS_HELP_STRING([--without-ca-bundle], [Don't use a default CA bundle]), + [Absolute path to a file containing CA certificates (example: /etc/ca-bundle.crt)]) +AS_HELP_STRING([--without-ca-bundle], [Do not use a default CA bundle]), [ want_ca="$withval" if test "x$want_ca" = "xyes"; then @@ -1469,11 +1088,11 @@ AS_HELP_STRING([--without-ca-bundle], [Don't use a default CA bundle]), [ want_ca="unset" ]) AC_ARG_WITH(ca-path, AS_HELP_STRING([--with-ca-path=DIRECTORY], -[Path to a directory containing CA certificates stored individually, with \ + [Absolute path to a directory containing CA certificates stored individually, with \ their filenames in a hash format. This option can be used with the OpenSSL, \ -GnuTLS and mbedTLS backends. Refer to OpenSSL c_rehash for details. \ +GnuTLS, mbedTLS and wolfSSL backends. Refer to OpenSSL c_rehash for details. \ (example: /etc/certificates)]) -AS_HELP_STRING([--without-ca-path], [Don't use a default CA path]), +AS_HELP_STRING([--without-ca-path], [Do not use a default CA path]), [ want_capath="$withval" if test "x$want_capath" = "xyes"; then @@ -1486,35 +1105,45 @@ AS_HELP_STRING([--without-ca-path], [Don't use a default CA path]), capath_warning=" (warning: certs not found)" check_capath="" - if test "x$want_ca" != "xno" -a "x$want_ca" != "xunset" -a \ - "x$want_capath" != "xno" -a "x$want_capath" != "xunset"; then + if test "$APPLE_SECTRUST_ENABLED" = "1"; then + ca_native="Apple SecTrust" + elif test "$ca_native_opt" = "1"; then + ca_native="yes" + else + ca_native="no" + fi + + if test "x$want_ca" != "xno" && test "x$want_ca" != "xunset" && + test "x$want_capath" != "xno" && test "x$want_capath" != "xunset"; then dnl both given ca="$want_ca" capath="$want_capath" - elif test "x$want_ca" != "xno" -a "x$want_ca" != "xunset"; then + elif test "x$want_ca" != "xno" && test "x$want_ca" != "xunset"; then dnl --with-ca-bundle given ca="$want_ca" capath="no" - elif test "x$want_capath" != "xno" -a "x$want_capath" != "xunset"; then + elif test "x$want_capath" != "xno" && test "x$want_capath" != "xunset"; then dnl --with-ca-path given - if test "x$OPENSSL_ENABLED" != "x1" -a "x$GNUTLS_ENABLED" != "x1" -a "x$MBEDTLS_ENABLED" != "x1"; then - AC_MSG_ERROR([--with-ca-path only works with OpenSSL, GnuTLS or mbedTLS]) - fi capath="$want_capath" ca="no" - else - dnl first try autodetecting a CA bundle , then a CA path - dnl both autodetections can be skipped by --without-ca-* + elif test "$ca_native" != "no"; then + dnl native CA configured, do not look further ca="no" capath="no" - if test "x$cross_compiling" != "xyes"; then + else + dnl First try auto-detecting a CA bundle, then a CA path. + dnl Both auto-detections can be skipped by --without-ca-* + ca="no" + capath="no" + if test "$cross_compiling" != "yes" && + test "$curl_cv_native_windows" != "yes"; then dnl NOT cross-compiling and... dnl neither of the --with-ca-* options are provided if test "x$want_ca" = "xunset"; then - dnl the path we previously would have installed the curl ca bundle + dnl the path we previously would have installed the curl CA bundle dnl to, and thus we now check for an already existing cert in that dnl place in case we find no other - if test "x$prefix" != xNONE; then + if test "x$prefix" != "xNONE"; then cac="${prefix}/share/curl/curl-ca-bundle.crt" else cac="$ac_default_prefix/share/curl/curl-ca-bundle.crt" @@ -1532,9 +1161,9 @@ AS_HELP_STRING([--without-ca-path], [Don't use a default CA path]), fi done fi - if test "x$want_capath" = "xunset" -a "x$ca" = "xno" -a \ - "x$OPENSSL_ENABLED" = "x1"; then - check_capath="/etc/ssl/certs/" + AC_MSG_NOTICE([want $want_capath CA $ca]) + if test "x$want_capath" = "xunset"; then + check_capath="/etc/ssl/certs" fi else dnl no option given and cross-compiling @@ -1550,7 +1179,7 @@ AS_HELP_STRING([--without-ca-path], [Don't use a default CA path]), check_capath="$capath" fi - if test ! -z "$check_capath"; then + if test -n "$check_capath"; then for a in "$check_capath"; do if test -d "$a" && ls "$a"/[[0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f]].0 >/dev/null 2>/dev/null; then if test "x$capath" = "xno"; then @@ -1567,115 +1196,92 @@ AS_HELP_STRING([--without-ca-path], [Don't use a default CA path]), fi if test "x$ca" != "xno"; then - CURL_CA_BUNDLE='"'$ca'"' - AC_DEFINE_UNQUOTED(CURL_CA_BUNDLE, "$ca", [Location of default ca bundle]) + CURL_CA_BUNDLE="$ca" + AC_DEFINE_UNQUOTED(CURL_CA_BUNDLE, "$ca", [Location of default CA bundle]) AC_SUBST(CURL_CA_BUNDLE) AC_MSG_RESULT([$ca]) fi if test "x$capath" != "xno"; then CURL_CA_PATH="\"$capath\"" - AC_DEFINE_UNQUOTED(CURL_CA_PATH, "$capath", [Location of default ca path]) + AC_DEFINE_UNQUOTED(CURL_CA_PATH, "$capath", [Location of default CA path]) AC_MSG_RESULT([$capath (capath)]) fi if test "x$ca" = "xno" && test "x$capath" = "xno"; then AC_MSG_RESULT([no]) fi - AC_MSG_CHECKING([whether to use builtin CA store of SSL library]) + AC_MSG_CHECKING([whether to use OpenSSL's built-in CA store]) AC_ARG_WITH(ca-fallback, -AS_HELP_STRING([--with-ca-fallback], [Use the built in CA store of the SSL library]) -AS_HELP_STRING([--without-ca-fallback], [Don't use the built in CA store of the SSL library]), +AS_HELP_STRING([--with-ca-fallback], [Use OpenSSL's built-in CA store]) +AS_HELP_STRING([--without-ca-fallback], [Do not use OpenSSL's built-in CA store]), [ - if test "x$with_ca_fallback" != "xyes" -a "x$with_ca_fallback" != "xno"; then + if test "x$with_ca_fallback" != "xyes" && test "x$with_ca_fallback" != "xno"; then AC_MSG_ERROR([--with-ca-fallback only allows yes or no as parameter]) fi ], [ with_ca_fallback="no"]) AC_MSG_RESULT([$with_ca_fallback]) if test "x$with_ca_fallback" = "xyes"; then - if test "x$OPENSSL_ENABLED" != "x1" -a "x$GNUTLS_ENABLED" != "x1"; then - AC_MSG_ERROR([--with-ca-fallback only works with OpenSSL or GnuTLS]) + if test "$OPENSSL_ENABLED" != "1"; then + AC_MSG_ERROR([--with-ca-fallback only works with OpenSSL]) fi - AC_DEFINE_UNQUOTED(CURL_CA_FALLBACK, 1, [define "1" to use built in CA store of SSL library ]) + AC_DEFINE_UNQUOTED(CURL_CA_FALLBACK, 1, [define "1" to use OpenSSL's built-in CA store]) fi ]) -dnl CURL_CHECK_WIN32_LARGEFILE -dnl ------------------------------------------------- -dnl Check if curl's WIN32 large file will be used -AC_DEFUN([CURL_CHECK_WIN32_LARGEFILE], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINDOWS])dnl - AC_MSG_CHECKING([whether build target supports WIN32 file API]) - curl_win32_file_api="no" - if test "$curl_cv_header_windows_h" = "yes"; then - if test x"$enable_largefile" != "xno"; then - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ - ]],[[ -#if !defined(_WIN32_WCE) && \ - (defined(__MINGW32__) || \ - (defined(_MSC_VER) && (defined(_WIN32) || defined(_WIN64)))) - int dummy=1; -#else - WIN32 large file API not supported. -#endif - ]]) - ],[ - curl_win32_file_api="win32_large_files" - ]) +dnl CURL_CHECK_CA_EMBED +dnl ------------------------------------------------- +dnl Check if a ca-bundle should be embedded + +AC_DEFUN([CURL_CHECK_CA_EMBED], [ + + AC_MSG_CHECKING([CA cert bundle path to embed in the curl tool]) + + AC_ARG_WITH(ca-embed, +AS_HELP_STRING([--with-ca-embed=FILE], + [Absolute path to a file containing CA certificates to embed in the curl tool (example: /etc/ca-bundle.crt)]) +AS_HELP_STRING([--without-ca-embed], [Do not embed a default CA bundle in the curl tool]), + [ + want_ca_embed="$withval" + if test "x$want_ca_embed" = "xyes"; then + AC_MSG_ERROR([--with-ca-embed=FILE requires a path to the CA bundle]) fi - if test "$curl_win32_file_api" = "no"; then - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ - ]],[[ -#if defined(_WIN32_WCE) || defined(__MINGW32__) || defined(_MSC_VER) - int dummy=1; -#else - WIN32 small file API not supported. -#endif - ]]) - ],[ - curl_win32_file_api="win32_small_files" - ]) - fi - fi - case "$curl_win32_file_api" in - win32_large_files) - AC_MSG_RESULT([yes (large file enabled)]) - AC_DEFINE_UNQUOTED(USE_WIN32_LARGE_FILES, 1, - [Define to 1 if you are building a Windows target with large file support.]) - AC_SUBST(USE_WIN32_LARGE_FILES, [1]) - ;; - win32_small_files) - AC_MSG_RESULT([yes (large file disabled)]) - AC_DEFINE_UNQUOTED(USE_WIN32_SMALL_FILES, 1, - [Define to 1 if you are building a Windows target without large file support.]) - AC_SUBST(USE_WIN32_SMALL_FILES, [1]) - ;; - *) + ], + [ want_ca_embed="unset" ]) + + CURL_CA_EMBED='' + if test "x$want_ca_embed" != "xno" && test "x$want_ca_embed" != "xunset" && test -f "$want_ca_embed"; then + if test -n "$PERL"; then + CURL_CA_EMBED="$want_ca_embed" + AC_SUBST(CURL_CA_EMBED) + AC_MSG_RESULT([$want_ca_embed]) + else AC_MSG_RESULT([no]) - ;; - esac + AC_MSG_WARN([perl was not found. Cannot do CA embed.]) + fi + else + AC_MSG_RESULT([no]) + fi ]) dnl CURL_CHECK_WIN32_CRYPTO dnl ------------------------------------------------- -dnl Check if curl's WIN32 crypto lib can be used +dnl Check if curl's Win32 crypto lib can be used AC_DEFUN([CURL_CHECK_WIN32_CRYPTO], [ - AC_REQUIRE([CURL_CHECK_HEADER_WINDOWS])dnl - AC_MSG_CHECKING([whether build target supports WIN32 crypto API]) + AC_REQUIRE([CURL_CHECK_NATIVE_WINDOWS]) + AC_MSG_CHECKING([whether build target supports Win32 crypto API]) curl_win32_crypto_api="no" - if test "$curl_cv_header_windows_h" = "yes"; then + if test "$curl_cv_native_windows" = "yes" && test "$curl_cv_winuwp" != "yes"; then AC_COMPILE_IFELSE([ AC_LANG_PROGRAM([[ -#undef inline -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#include + #undef inline + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #include ]],[[ HCRYPTPROV hCryptProv; if(CryptAcquireContext(&hCryptProv, NULL, NULL, PROV_RSA_FULL, @@ -1692,7 +1298,7 @@ AC_DEFUN([CURL_CHECK_WIN32_CRYPTO], [ AC_MSG_RESULT([yes]) AC_DEFINE_UNQUOTED(USE_WIN32_CRYPTO, 1, [Define to 1 if you are building a Windows target with crypto API support.]) - AC_SUBST(USE_WIN32_CRYPTO, [1]) + USE_WIN32_CRYPTO=1 ;; *) AC_MSG_RESULT([no]) @@ -1700,22 +1306,65 @@ AC_DEFUN([CURL_CHECK_WIN32_CRYPTO], [ esac ]) -dnl CURL_EXPORT_PCDIR ($pcdir) +dnl CURL_EXPORT_PCDIR ($pcdir, [$additive]) dnl ------------------------ -dnl if $pcdir is not empty, set PKG_CONFIG_LIBDIR to $pcdir and export +dnl if $pcdir is not empty, set PKG_CONFIG_LIBDIR to $pcdir and export. +dnl if $additive is set, extend PKG_CONFIG_PATH instead, by prepending $pcdir +dnl to it, to ensure that system locations are still checked. This is +dnl necessary for modules that depend on modules residing there +dnl (e.g. gnutls.pc). dnl -dnl we need this macro since pkg-config distinguishes among empty and unset -dnl variable while checking PKG_CONFIG_LIBDIR +dnl we need this macro to limit/expand search locations to/with a custom +dnl configured one. dnl AC_DEFUN([CURL_EXPORT_PCDIR], [ - if test -n "$1"; then + if test -n "$1"; then + if test -n "$2"; then + dnl honor system locations + PKG_CONFIG_PATH="$1${PKG_CONFIG_PATH:+:$PKG_CONFIG_PATH}" + export PKG_CONFIG_PATH + else + dnl ignore and override system locations PKG_CONFIG_LIBDIR="$1" export PKG_CONFIG_LIBDIR fi + fi ]) -dnl CURL_CHECK_PKGCONFIG ($module, [$pcdir]) +dnl CURL_TRACE_PCDIR ($module, [$pcdir], [$additive]) +dnl ------------------------ +dnl show pkg-config module lookup details, along with a detailed errors +dnl message in case of failure. Supports both pkg-config and pkgconf. +dnl + +AC_DEFUN([CURL_TRACE_PCDIR], [ + dnl Example pkgconf line: + dnl libpkgconf/pkg.c:746 [pkgconf_pkg_t *pkgconf_pkg_try_specific_path(pkgconf_client_t *, [...]*)]: + dnl trying path: /usr/local/lib/pkgconfig for libngtcp2_crypto_gnutls + dnl Rest of strings are for catching classic pkg-config lines. + trc=`CURL_EXPORT_PCDIR([$2], [$3]) + if test -n "$PKG_CONFIG_LIBDIR"; then + echo "PKG_CONFIG_LIBDIR: '$PKG_CONFIG_LIBDIR'" + fi + if test -n "$PKG_CONFIG_PATH"; then + echo "PKG_CONFIG_PATH: '$PKG_CONFIG_PATH'" + fi + $PKGCONFIG --exists --debug $1 2>&1 | \ + $EGREP '(trying path:|Adding directory|Looking for|Scanning directory|Cannot open directory)' | \ + $SED 's/^.*trying path:/trying path:/'` + msg=`CURL_EXPORT_PCDIR([$2], [$3]) + $PKGCONFIG --exists --print-errors $1 2>&1` + if test -n "$msg"; then + trc=`echo "$trc"; echo '==== error:'; echo "$msg"` + fi + AC_MSG_NOTICE([pkg-config --exists $1 trace: +---- begin +${trc} +---- end]) +]) + +dnl CURL_CHECK_PKGCONFIG ($module, [$pcdir], [$additive]) dnl ------------------------ dnl search for the pkg-config tool. Set the PKGCONFIG variable to hold the dnl path to it, or 'no' if not found/present. @@ -1727,76 +1376,127 @@ dnl Optionally PKG_CONFIG_LIBDIR may be given as $pcdir. dnl AC_DEFUN([CURL_CHECK_PKGCONFIG], [ - if test -n "$PKG_CONFIG"; then - PKGCONFIG="$PKG_CONFIG" + if test -n "$PKG_CONFIG"; then + PKGCONFIG="$PKG_CONFIG" + else + AC_PATH_TOOL([PKGCONFIG], [pkg-config], [no], + [$PATH:/usr/bin:/usr/local/bin]) + fi + + if test "$PKGCONFIG" != "no"; then + AC_MSG_CHECKING([for $1 options with pkg-config]) + dnl ask pkg-config about $1 + itexists=`CURL_EXPORT_PCDIR([$2], [$3]) + $PKGCONFIG --exists $1 >/dev/null 2>&1 && echo 1` + + if test -z "$itexists"; then + dnl pkg-config does not have info about the given module! set the + dnl variable to 'no' + AC_MSG_RESULT([no]) + if test -n "$CURL_TRACE_PKG_CONFIG$CURL_CI"; then + CURL_TRACE_PCDIR([$1], [$2], [$3]) + fi + PKGCONFIG="no" else - AC_PATH_TOOL([PKGCONFIG], [pkg-config], [no], - [$PATH:/usr/bin:/usr/local/bin]) - fi - - if test "x$PKGCONFIG" != "xno"; then - AC_MSG_CHECKING([for $1 options with pkg-config]) - dnl ask pkg-config about $1 - itexists=`CURL_EXPORT_PCDIR([$2]) dnl - $PKGCONFIG --exists $1 >/dev/null 2>&1 && echo 1` - - if test -z "$itexists"; then - dnl pkg-config does not have info about the given module! set the - dnl variable to 'no' - PKGCONFIG="no" - AC_MSG_RESULT([no]) - else - AC_MSG_RESULT([found]) + AC_MSG_RESULT([found]) + if test -n "$CURL_TRACE_PKG_CONFIG"; then + CURL_TRACE_PCDIR([$1], [$2], [$3]) fi fi + fi ]) -dnl CURL_GENERATE_CONFIGUREHELP_PM +dnl CURL_PREPARE_CONFIGUREHELP_PM dnl ------------------------------------------------- -dnl Generate test harness configurehelp.pm module, defining and +dnl Prepare test harness configurehelp.pm module, defining and dnl initializing some perl variables with values which are known dnl when the configure script runs. For portability reasons, test dnl harness needs information on how to run the C preprocessor. -AC_DEFUN([CURL_GENERATE_CONFIGUREHELP_PM], [ - AC_REQUIRE([AC_PROG_CPP])dnl +AC_DEFUN([CURL_PREPARE_CONFIGUREHELP_PM], [ + AC_REQUIRE([AC_PROG_CPP]) tmp_cpp=`eval echo "$ac_cpp" 2>/dev/null` if test -z "$tmp_cpp"; then tmp_cpp='cpp' fi - cat >./tests/configurehelp.pm <<_EOF -[@%:@] This is a generated file. Do not edit. - -package configurehelp; - -use strict; -use warnings; -use Exporter; - -use vars qw( - @ISA - @EXPORT_OK - \$Cpreprocessor - ); - -@ISA = qw(Exporter); - -@EXPORT_OK = qw( - \$Cpreprocessor - ); - -\$Cpreprocessor = '$tmp_cpp'; - -1; -_EOF + AC_SUBST(CURL_CPP, $tmp_cpp) ]) + +dnl CURL_PREPARE_BUILDINFO +dnl ------------------------------------------------- +dnl Save build info for test runner to pick up and log + +AC_DEFUN([CURL_PREPARE_BUILDINFO], [ + curl_pflags="" + if test "$curl_cv_apple" = "yes"; then + curl_pflags="${curl_pflags} APPLE" + fi + case $host in + *-*-*bsd*|*-*-aix*|*-*-hpux*|*-*-interix*|*-*-irix*|*-*-linux*|*-*-solaris*|*-*-sunos*|*-apple-*|*-*-cygwin*|*-*-msys*) + curl_pflags="${curl_pflags} UNIX";; + esac + case $host in + *-*-*bsd*) + curl_pflags="${curl_pflags} BSD";; + esac + if test "$curl_cv_android" = "yes"; then + curl_pflags="${curl_pflags} ANDROID" + ANDROID_PLATFORM_LEVEL=`echo "$host_os" | $SED -ne 's/.*android\(@<:@0-9@:>@*\).*/\1/p'` + if test -n "${ANDROID_PLATFORM_LEVEL}"; then + curl_pflags="${curl_pflags}-${ANDROID_PLATFORM_LEVEL}" + fi + fi + if test "$curl_cv_native_windows" = "yes"; then + curl_pflags="${curl_pflags} WIN32" + fi + if test "$curl_cv_winuwp" = "yes"; then + curl_pflags="${curl_pflags} UWP" + fi + case $host_os in + cygwin*|msys*) curl_pflags="${curl_pflags} CYGWIN";; + esac + case $host_os in + msdos*) curl_pflags="${curl_pflags} DOS";; + amiga*) curl_pflags="${curl_pflags} AMIGA";; + esac + if test "$compiler_id" = "GNU_C"; then + curl_pflags="${curl_pflags} GCC" + fi + if test "$compiler_id" = "APPLECLANG"; then + curl_pflags="${curl_pflags} APPLE-CLANG" + elif test "$compiler_id" = "CLANG"; then + curl_pflags="${curl_pflags} LLVM-CLANG" + fi + case $host_os in + mingw*) curl_pflags="${curl_pflags} MINGW";; + esac + if test "$cross_compiling" = "yes"; then + curl_pflags="${curl_pflags} CROSS" + fi + squeeze curl_pflags + curl_buildinfo=" +buildinfo.configure.tool: configure +buildinfo.configure.args: $ac_configure_args +buildinfo.host: $build +buildinfo.host.cpu: $build_cpu +buildinfo.host.os: $build_os +buildinfo.target: $host +buildinfo.target.cpu: $host_cpu +buildinfo.target.os: $host_os +buildinfo.target.flags: $curl_pflags +buildinfo.compiler: $compiler_id +buildinfo.compiler.version: $compiler_ver +buildinfo.sysroot: $lt_sysroot" +]) + + dnl CURL_CPP_P dnl dnl Check if $cpp -P should be used for extract define values due to gcc 5 dnl splitting up strings and defines between line outputs. gcc by default -dnl (without -P) will show TEST EINVAL TEST as +dnl (without -P) shows TEST EINVAL TEST as dnl dnl # 13 "conftest.c" dnl TEST @@ -1814,7 +1514,7 @@ TEST EINVAL TEST AC_MSG_RESULT([$cpp]) dnl we need cpp -P so check if it works then - if test "x$cpp" = "xyes"; then + if test "$cpp" = "yes"; then AC_MSG_CHECKING([if cpp -P works]) OLDCPPFLAGS=$CPPFLAGS CPPFLAGS="$CPPFLAGS -P" @@ -1824,18 +1524,18 @@ TEST EINVAL TEST ], [cpp_p=yes], [cpp_p=no]) AC_MSG_RESULT([$cpp_p]) - if test "x$cpp_p" = "xno"; then + if test "$cpp_p" = "no"; then AC_MSG_WARN([failed to figure out cpp -P alternative]) - # without -P + dnl without -P CPPPFLAG="" else - # with -P + dnl with -P CPPPFLAG="-P" fi dnl restore CPPFLAGS CPPFLAGS=$OLDCPPFLAGS else - # without -P + dnl without -P CPPPFLAG="" fi ]) @@ -1844,38 +1544,24 @@ TEST EINVAL TEST dnl CURL_DARWIN_CFLAGS dnl dnl Set -Werror=partial-availability to detect possible breaking code -dnl with very low deployment targets. +dnl with low deployment targets. dnl AC_DEFUN([CURL_DARWIN_CFLAGS], [ - - tst_cflags="no" - case $host_os in - darwin*) - tst_cflags="yes" - ;; - esac - - AC_MSG_CHECKING([for good-to-use Darwin CFLAGS]) - AC_MSG_RESULT([$tst_cflags]); - - if test "$tst_cflags" = "yes"; then - old_CFLAGS=$CFLAGS - CFLAGS="$CFLAGS -Werror=partial-availability" - AC_MSG_CHECKING([whether $CC accepts -Werror=partial-availability]) - AC_COMPILE_IFELSE([AC_LANG_PROGRAM()], - [AC_MSG_RESULT([yes])], - [AC_MSG_RESULT([no]) - CFLAGS=$old_CFLAGS]) - fi - + old_CFLAGS=$CFLAGS + CFLAGS="$CFLAGS -Werror=partial-availability" + AC_MSG_CHECKING([whether $CC accepts -Werror=partial-availability]) + AC_COMPILE_IFELSE([AC_LANG_PROGRAM()], + [AC_MSG_RESULT([yes])], + [AC_MSG_RESULT([no]) + CFLAGS=$old_CFLAGS]) ]) dnl CURL_SUPPORTS_BUILTIN_AVAILABLE dnl dnl Check to see if the compiler supports __builtin_available. This built-in -dnl compiler function first appeared in Apple LLVM 9.0.0. It's so new that, at +dnl compiler function first appeared in Apple LLVM 9.0.0. It is so new that, at dnl the time this macro was written, the function was not yet documented. Its dnl purpose is to return true if the code is running under a certain OS version dnl or later. @@ -1884,14 +1570,13 @@ AC_DEFUN([CURL_SUPPORTS_BUILTIN_AVAILABLE], [ AC_MSG_CHECKING([to see if the compiler supports __builtin_available()]) AC_COMPILE_IFELSE([ AC_LANG_PROGRAM([[ -#include ]],[[ - if (__builtin_available(macOS 10.8, iOS 5.0, *)) {} + if(__builtin_available(macOS 10.12, iOS 5.0, *)) {} ]]) ],[ AC_MSG_RESULT([yes]) AC_DEFINE_UNQUOTED(HAVE_BUILTIN_AVAILABLE, 1, - [Define to 1 if you have the __builtin_available function.]) + [Define to 1 if you have the __builtin_available function.]) ],[ AC_MSG_RESULT([no]) ]) diff --git a/third-party/curl/appveyor.sh b/third-party/curl/appveyor.sh new file mode 100644 index 0000000000..8852caec9b --- /dev/null +++ b/third-party/curl/appveyor.sh @@ -0,0 +1,132 @@ +#!/usr/bin/env bash +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### + +# shellcheck disable=SC3040,SC2039 +set -eux; [ -n "${BASH:-}${ZSH_NAME:-}" ] && set -o pipefail + +# build + +if [ -n "${CMAKE_GENERATOR:-}" ]; then + + PRJ_CFG='Debug' + [[ "${APPVEYOR_JOB_NAME}" = *'Release'* ]] && PRJ_CFG='Release' + + # Configure OpenSSL + case "${CMAKE_GENERATE:-}" in + *Win32*) openssl_suffix='-Win32';; + *) openssl_suffix='-Win64';; + esac + + if [ "${APPVEYOR_BUILD_WORKER_IMAGE}" = 'Visual Studio 2026' ]; then + openssl_root_win="C:/OpenSSL-v36${openssl_suffix}" + elif [ "${APPVEYOR_BUILD_WORKER_IMAGE}" = 'Visual Studio 2022' ]; then + openssl_root_win="C:/OpenSSL-v35${openssl_suffix}" + elif [ "${APPVEYOR_BUILD_WORKER_IMAGE}" = 'Visual Studio 2019' ]; then + openssl_root_win="C:/OpenSSL-v30${openssl_suffix}" + fi + [ -n "${openssl_root_win:-}" ] && openssl_root="$(cygpath "${openssl_root_win}")" + + # Install custom cmake version + if [ -n "${CMAKE_VERSION:-}" ]; then + cmake_ver="$(printf '%02d%02d' \ + "$(echo "${CMAKE_VERSION}" | cut -f1 -d.)" \ + "$(echo "${CMAKE_VERSION}" | cut -f2 -d.)")" + if [ "${cmake_ver}" -ge '0320' ]; then + fn="cmake-${CMAKE_VERSION}-windows-x86_64" + else + fn="cmake-${CMAKE_VERSION}-win64-x64" + fi + curl --disable --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-connrefused \ + --location --proto-redir =https "https://github.com/Kitware/CMake/releases/download/v${CMAKE_VERSION}/${fn}.zip" --output pkg.bin + sha256sum pkg.bin && sha256sum pkg.bin | grep -qwF -- "${CMAKE_SHA256}" && 7z x -y pkg.bin >/dev/null && rm -f pkg.bin + PATH="$PWD/${fn}/bin:$PATH" + fi + + # Set env CHKPREFILL to the value '_chkprefill' to compare feature detection + # results with and without the pre-fill feature. They have to match. + for _chkprefill in '' ${CHKPREFILL:-}; do + options='' + [ "${_chkprefill}" = '_chkprefill' ] && options+=' -D_CURL_PREFILL=OFF' + [[ "${CMAKE_GENERATE:-}" = *'-A ARM64'* ]] && SKIP_RUN='ARM64 architecture' + [[ "${CMAKE_GENERATE:-}" = *'-DCURL_USE_OPENSSL=ON'* ]] && options+=" -DOPENSSL_ROOT_DIR=${openssl_root_win}" + # shellcheck disable=SC2086 + time cmake -B "_bld${_chkprefill}" \ + -DENABLE_DEBUG=ON \ + -DCMAKE_UNITY_BUILD=ON -DCURL_WERROR=ON \ + -DCMAKE_VS_GLOBALS=TrackFileAccess=false \ + -DCURL_STATIC_CRT=ON \ + -DCURL_DROP_UNUSED=ON \ + -DCURL_USE_SCHANNEL=ON -DCURL_USE_LIBPSL=OFF \ + ${CMAKE_GENERATE:-} \ + ${options} \ + || { cat _bld/CMakeFiles/CMake* 2>/dev/null; false; } + done + if [ -d _bld_chkprefill ] && ! diff -u _bld/lib/curl_config.h _bld_chkprefill/lib/curl_config.h; then + cat _bld_chkprefill/CMakeFiles/CMake* 2>/dev/null || true + false + fi + echo 'curl_config.h'; grep -F '#define' _bld/lib/curl_config.h | sort || true + time cmake --build _bld --config "${PRJ_CFG}" --parallel 2 + [[ "${CMAKE_GENERATE:-}" != *'-DBUILD_SHARED_LIBS=OFF'* ]] && PATH="$PWD/_bld/lib/${PRJ_CFG}:$PATH" + [[ "${CMAKE_GENERATE:-}" = *'-DCURL_USE_OPENSSL=ON'* ]] && { PATH="${openssl_root}:$PATH"; cp "${openssl_root}"/*.dll "_bld/src/${PRJ_CFG}"; } + curl="_bld/src/${PRJ_CFG}/curl.exe" +else + ( + cd projects/Windows + ./generate.bat "${VC_VERSION}" + msbuild.exe -maxcpucount "-property:Configuration=${PRJ_CFG}" "-property:Platform=${PLAT}" "${VC_VERSION}/curl-all.sln" + ) + [ "${PLAT}" = 'x64' ] && platdir='Win64' || platdir='Win32' + [[ "${PRJ_CFG}" = *'Debug'* ]] && binsuffix='d' || binsuffix='' + curl="build/${platdir}/${VC_VERSION}/${PRJ_CFG}/curl${binsuffix}.exe" +fi + +find . \( -name '*.exe' -o -name '*.dll' -o -name '*.lib' -o -name '*.pdb' \) -print0 | grep -z curl | xargs -0 file -- +find . \( -name '*.exe' -o -name '*.dll' -o -name '*.lib' -o -name '*.pdb' \) -print0 | grep -z curl | xargs -0 stat -c '%10s bytes: %n' -- + +if [ -z "${SKIP_RUN:-}" ]; then + "${curl}" --disable --version +else + echo "Skip running curl.exe. Reason: ${SKIP_RUN}" +fi + +# build tests + +if [ -n "${CMAKE_GENERATOR:-}" ] && [[ "${APPVEYOR_JOB_NAME}" = *'Build-tests'* ]]; then + time cmake --build _bld --config "${PRJ_CFG}" --parallel 2 --target testdeps +fi + +# build examples + +if [ -n "${CMAKE_GENERATOR:-}" ] && [[ "${APPVEYOR_JOB_NAME}" = *'examples'* ]]; then + time cmake --build _bld --config "${PRJ_CFG}" --parallel 2 --target curl-examples-build +fi + +# disk space used + +du -sh .; echo; du -sh -t 250KB ./* +if [ -n "${CMAKE_GENERATOR:-}" ]; then + echo; du -h -t 250KB _bld +fi diff --git a/third-party/curl/appveyor.yml b/third-party/curl/appveyor.yml index fda46e68e9..9335da3892 100644 --- a/third-party/curl/appveyor.yml +++ b/third-party/curl/appveyor.yml @@ -21,371 +21,138 @@ # SPDX-License-Identifier: curl # ########################################################################### + # https://ci.appveyor.com/project/curlorg/curl/history -# Appveyor configuration -# https://www.appveyor.com/docs/appveyor-yml/ +# AppVeyor configuration: +# https://www.appveyor.com/docs/appveyor-yml/ +# AppVeyor worker images: +# https://www.appveyor.com/docs/windows-images-software/ version: 7.50.0.{build} environment: - UNITY: "OFF" - matrix: - # generated CMake-based Visual Studio Release builds - - job_name: "CMake, VS2008, Release x86, Schannel" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2015" - BUILD_SYSTEM: CMake - PRJ_GEN: "Visual Studio 9 2008" - PRJ_CFG: Release - OPENSSL: OFF - SCHANNEL: ON - ENABLE_UNICODE: OFF - HTTP_ONLY: OFF - TESTING: OFF - SHARED: ON - DISABLED_TESTS: "" - - job_name: "CMake, VS2022, Release x64, OpenSSL, WebSockets, Unity" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2022" - BUILD_SYSTEM: CMake - PRJ_GEN: "Visual Studio 17 2022" - TARGET: "-A x64" - PRJ_CFG: Release - OPENSSL: ON - SCHANNEL: OFF - ENABLE_UNICODE: OFF - HTTP_ONLY: OFF - TESTING: OFF - SHARED: ON - DISABLED_TESTS: "" - WEBSOCKETS: ON - UNITY: "ON" - - job_name: "CMake, VS2022, Release arm64, Schannel, Static" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2022" - BUILD_SYSTEM: CMake - PRJ_GEN: "Visual Studio 17 2022" - TARGET: "-A ARM64" - PRJ_CFG: Release - OPENSSL: OFF - SCHANNEL: ON - ENABLE_UNICODE: OFF - HTTP_ONLY: OFF - TESTING: OFF - SHARED: OFF - DISABLED_TESTS: "" - # generated CMake-based Visual Studio Debug builds - - job_name: "CMake, VS2010, Debug x64, no SSL, Static" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2015" - BUILD_SYSTEM: CMake - PRJ_GEN: "Visual Studio 10 2010 Win64" - PRJ_CFG: Debug - OPENSSL: OFF - SCHANNEL: OFF - ENABLE_UNICODE: OFF - HTTP_ONLY: OFF - TESTING: ON - SHARED: OFF - DISABLED_TESTS: "!1139 !1501 ~1056" - ADD_PATH: "C:\\msys64\\usr\\bin" - - job_name: "CMake, VS2022, Debug x64, Schannel, Static, Unicode" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2022" - BUILD_SYSTEM: CMake - PRJ_GEN: "Visual Studio 17 2022" - TARGET: "-A x64" - PRJ_CFG: Debug - OPENSSL: OFF - SCHANNEL: ON - ENABLE_UNICODE: ON - HTTP_ONLY: OFF - TESTING: ON - SHARED: OFF - DISABLED_TESTS: "~571 !1139 !1501 ~1056" - ADD_PATH: "C:\\msys64\\usr\\bin" - - job_name: "CMake, VS2022, Debug x64, no SSL, Static" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2022" - BUILD_SYSTEM: CMake - PRJ_GEN: "Visual Studio 17 2022" - TARGET: "-A x64" - PRJ_CFG: Debug - OPENSSL: OFF - SCHANNEL: OFF - ENABLE_UNICODE: OFF - HTTP_ONLY: OFF - TESTING: ON - SHARED: OFF - DISABLED_TESTS: "~571 !1139 !1501 ~1056" - ADD_PATH: "C:\\msys64\\usr\\bin" - - job_name: "CMake, VS2022, Debug x64, no SSL, Static, HTTP only" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2022" - BUILD_SYSTEM: CMake - PRJ_GEN: "Visual Studio 17 2022" - TARGET: "-A x64" - PRJ_CFG: Debug - OPENSSL: OFF - SCHANNEL: OFF - ENABLE_UNICODE: OFF - HTTP_ONLY: ON - TESTING: ON - SHARED: OFF - DISABLED_TESTS: "!1139 !1501 ~1056" - ADD_PATH: "C:\\msys64\\usr\\bin" - # generated CMake-based MSYS Makefiles builds (mingw cross-compiling) - - job_name: "CMake, mingw-w64, gcc 8, Debug x64, Schannel, Static, Unicode" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2015" - BUILD_SYSTEM: CMake - PRJ_GEN: "MSYS Makefiles" - PRJ_CFG: Debug - OPENSSL: OFF - SCHANNEL: ON - ENABLE_UNICODE: ON - HTTP_ONLY: OFF - TESTING: ON - SHARED: OFF - DISABLED_TESTS: "!1139 !1501 ~1056" - ADD_PATH: "C:\\mingw-w64\\x86_64-8.1.0-posix-seh-rt_v6-rev0\\mingw64\\bin;C:\\msys64\\usr\\bin" - MSYS2_ARG_CONV_EXCL: "/*" - BUILD_OPT: -k - - job_name: "CMake, mingw-w64, gcc 7, Debug x64, Schannel, Static, Unicode" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: CMake - PRJ_GEN: "MSYS Makefiles" - PRJ_CFG: Debug - OPENSSL: OFF - SCHANNEL: ON - ENABLE_UNICODE: ON - HTTP_ONLY: OFF - TESTING: ON - SHARED: OFF - DISABLED_TESTS: "!1139 !1501 ~1056" - ADD_PATH: "C:\\mingw-w64\\x86_64-7.2.0-posix-seh-rt_v5-rev1\\mingw64\\bin;C:\\msys64\\usr\\bin" - MSYS2_ARG_CONV_EXCL: "/*" - BUILD_OPT: -k - - job_name: "CMake, mingw-w64, Debug x64, Schannel, Static, Unity" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: CMake - PRJ_GEN: "MSYS Makefiles" - PRJ_CFG: Debug - OPENSSL: OFF - SCHANNEL: ON - ENABLE_UNICODE: OFF - HTTP_ONLY: OFF - TESTING: OFF - SHARED: OFF - ADD_PATH: "C:\\mingw-w64\\x86_64-8.1.0-posix-seh-rt_v6-rev0\\mingw64\\bin;C:\\msys64\\usr\\bin" - MSYS2_ARG_CONV_EXCL: "/*" - BUILD_OPT: -k - UNITY: "ON" - - job_name: "CMake, mingw-w64, Debug x86, Schannel, Static" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2015" - BUILD_SYSTEM: CMake - PRJ_GEN: "MSYS Makefiles" - PRJ_CFG: Debug - OPENSSL: OFF - SCHANNEL: ON - ENABLE_UNICODE: OFF - HTTP_ONLY: OFF - TESTING: ON - SHARED: OFF - DISABLED_TESTS: "!1139 !1501 ~1056" - ADD_PATH: "C:\\mingw-w64\\i686-6.3.0-posix-dwarf-rt_v5-rev1\\mingw32\\bin;C:\\msys64\\usr\\bin" - MSYS2_ARG_CONV_EXCL: "/*" - BUILD_OPT: -k - - job_name: "CMake, mingw, Debug x86, no SSL, Static" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2022" - BUILD_SYSTEM: CMake - PRJ_GEN: "MSYS Makefiles" - PRJ_CFG: Debug - OPENSSL: OFF - SCHANNEL: OFF - ENABLE_UNICODE: OFF - HTTP_ONLY: OFF - TESTING: ON - SHARED: OFF - DISABLED_TESTS: "!1139 !1501 ~1056" - ADD_PATH: "C:\\MinGW\\bin;C:\\msys64\\usr\\bin" - MSYS2_ARG_CONV_EXCL: "/*" - BUILD_OPT: -k - # winbuild-based builds - - job_name: "winbuild, VS2015, Debug" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2015" - BUILD_SYSTEM: winbuild_vs2015 - DEBUG: yes - PATHPART: debug - TESTING: OFF - ENABLE_UNICODE: no - - job_name: "winbuild, VS2015, Release" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2015" - BUILD_SYSTEM: winbuild_vs2015 - DEBUG: no - PATHPART: release - TESTING: OFF - ENABLE_UNICODE: no - - job_name: "winbuild, VS2017, Debug" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: winbuild_vs2017 - DEBUG: yes - PATHPART: debug - TESTING: OFF - ENABLE_UNICODE: no - - job_name: "winbuild, VS2017, Release" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: winbuild_vs2017 - DEBUG: no - PATHPART: release - TESTING: OFF - ENABLE_UNICODE: no - - job_name: "winbuild, VS2015, Debug, Unicode" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2015" - BUILD_SYSTEM: winbuild_vs2015 - DEBUG: yes - PATHPART: debug - TESTING: OFF - ENABLE_UNICODE: yes - - job_name: "winbuild, VS2015, Release, Unicode" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2015" - BUILD_SYSTEM: winbuild_vs2015 - DEBUG: no - PATHPART: release - TESTING: OFF - ENABLE_UNICODE: yes - - job_name: "winbuild, VS2017, Debug, Unicode" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: winbuild_vs2017 - DEBUG: yes - PATHPART: debug - TESTING: OFF - ENABLE_UNICODE: yes - - job_name: "winbuild, VS2017, Release, Unicode" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: winbuild_vs2017 - DEBUG: no - PATHPART: release - TESTING: OFF - ENABLE_UNICODE: yes - # generated VisualStudioSolution-based builds - - job_name: "VisualStudioSolution, VS2017, Debug" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: VisualStudioSolution - PRJ_CFG: "DLL Debug - DLL Windows SSPI - DLL WinIDN" - TESTING: OFF - VC_VERSION: VC14.10 - # autotools-based builds (NOT mingw cross-compiling, but msys2 native) - - job_name: "autotools, msys2, Debug, no Proxy, no SSL" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: autotools - TESTING: ON - DISABLED_TESTS: "!19 ~1056 !1233" - ADD_PATH: "C:\\msys64\\usr\\bin" - CONFIG_ARGS: "--enable-debug --enable-werror --disable-threaded-resolver --disable-proxy --without-ssl --enable-websockets" - - job_name: "autotools, msys2, Debug, no SSL" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: autotools - TESTING: ON - DISABLED_TESTS: "!19 !504 !704 !705 ~1056 !1233" - ADD_PATH: "C:\\msys64\\usr\\bin" - CONFIG_ARGS: "--enable-debug --enable-werror --disable-threaded-resolver --without-ssl --enable-websockets" - - job_name: "autotools, msys2, Release, no SSL" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2017" - BUILD_SYSTEM: autotools - TESTING: ON - DISABLED_TESTS: "!19 !504 !704 !705 ~1056 !1233" - ADD_PATH: "C:\\msys64\\usr\\bin" - CONFIG_ARGS: "--enable-warnings --enable-werror --without-ssl --enable-websockets" - # autotools-based Cygwin build - - job_name: "autotools, cygwin, Debug, no SSL" - APPVEYOR_BUILD_WORKER_IMAGE: "Visual Studio 2022" - BUILD_SYSTEM: autotools - TESTING: ON - DISABLED_TESTS: "~1056" - ADD_PATH: "C:\\cygwin64\\bin" - CONFIG_ARGS: "--enable-debug --enable-werror --disable-threaded-resolver --without-ssl --enable-websockets" - POSIX_PATH_PREFIX: "/cygdrive" + DO_NOT_TRACK: '1' + + matrix: + # CMake Visual Studio builds + + - job_name: 'CM VS2022, Release, x64, OpenSSL 3.5, Shared, Build-tests' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2022' + CMAKE_GENERATOR: 'Visual Studio 17 2022' + CMAKE_GENERATE: '-A x64 -DCURL_USE_SCHANNEL=OFF -DCURL_USE_OPENSSL=ON' + + - job_name: 'CM VS2026, Release, arm64, Schannel, Static, !DEBUGBUILD, Build-tests' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2026' + CMAKE_VERSION: 4.2.1 + CMAKE_SHA256: dfc2b2afac257555e3b9ce375b12b2883964283a366c17fec96cf4d17e4f1677 + CMAKE_GENERATOR: 'Visual Studio 18 2026' + CMAKE_GENERATE: '-A ARM64 -DENABLE_DEBUG=OFF -DBUILD_SHARED_LIBS=OFF' + + - job_name: 'CM VS2010, Debug, x64, Schannel, Shared, Build-tests & examples' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2015' + CMAKE_VERSION: 3.18.4 + CMAKE_SHA256: a932bc0c8ee79f1003204466c525b38a840424d4ae29f9e5fb88959116f2407d + CMAKE_GENERATOR: 'Visual Studio 10 2010' + CMAKE_GENERATE: '-A x64' + + - job_name: 'CM VS2012, Release, x86, Schannel, Shared, Build-tests' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2015' + CMAKE_VERSION: 3.21.7 + CMAKE_SHA256: 4c4840e2dc2bf82e8a16081ff506bba54f3a228b91ce36317129fed4035ef2e3 + CMAKE_GENERATOR: 'Visual Studio 11 2012' + CMAKE_GENERATE: '-A Win32' + + - job_name: 'CM VS2013, Debug, x64, Schannel, Shared' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2015' + CMAKE_VERSION: 3.18.4 + CMAKE_SHA256: a932bc0c8ee79f1003204466c525b38a840424d4ae29f9e5fb88959116f2407d + CMAKE_GENERATOR: 'Visual Studio 12 2013' + CMAKE_GENERATE: '-A x64' + + - job_name: 'CM VS2015, Debug, x64, Schannel, Static' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2015' + CMAKE_VERSION: 3.19.8 + CMAKE_SHA256: 2a30877a3d6b50da305b289f4d1c03befdfaeb2edba02a563c681e883d810380 + CMAKE_GENERATOR: 'Visual Studio 14 2015' + CMAKE_GENERATE: '-A x64 -DBUILD_SHARED_LIBS=OFF' + + - job_name: 'CM VS2017, Debug, x64, Schannel, Shared' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2017' + CMAKE_VERSION: 3.20.6 + CMAKE_SHA256: f240a38c964712aac474644b3ba21bdc2b4e8d5e31179f67bd2e6f45fa349419 + CMAKE_GENERATOR: 'Visual Studio 15 2017' + CMAKE_GENERATE: '-A x64' + + - job_name: 'CM VS2019, Debug, x64, OpenSSL 3.0 + Schannel, Shared, !verbose, Build-tests' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2019' + CMAKE_GENERATOR: 'Visual Studio 16 2019' + CMAKE_GENERATE: '-A x64 -DCURL_USE_OPENSSL=ON -DCURL_DISABLE_VERBOSE_STRINGS=ON' + + - job_name: 'CM VS2026, Debug, x64, OpenSSL 3.5 + Schannel, Static, Unicode, Build-tests & examples, clang-cl' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2026' + CMAKE_VERSION: 4.2.1 + CMAKE_SHA256: dfc2b2afac257555e3b9ce375b12b2883964283a366c17fec96cf4d17e4f1677 + CMAKE_GENERATOR: 'Visual Studio 18 2026' + CMAKE_GENERATE: '-A x64 -T ClangCl -DBUILD_SHARED_LIBS=OFF -DCURL_USE_OPENSSL=ON -DENABLE_UNICODE=ON' + + - job_name: 'CM VS2022, Release, x64, Schannel, Shared, Unicode, !DEBUGBUILD, Build-tests' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2022' + CMAKE_GENERATOR: 'Visual Studio 17 2022' + ENABLE_UNICODE: 'ON' + CMAKE_GENERATE: '-A x64 -DENABLE_UNICODE=ON -DENABLE_DEBUG=OFF' + + - job_name: 'CM VS2026, Debug, x64, !ssl, Static, Build-tests' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2026' + CMAKE_VERSION: 4.2.1 + CMAKE_SHA256: dfc2b2afac257555e3b9ce375b12b2883964283a366c17fec96cf4d17e4f1677 + CMAKE_GENERATOR: 'Visual Studio 18 2026' + CMAKE_GENERATE: '-A x64 -DBUILD_SHARED_LIBS=OFF -DCURL_USE_SCHANNEL=OFF' + + - job_name: 'CM VS2022, Debug, x64, !ssl, Static, HTTP-only, Build-tests' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2022' + CMAKE_GENERATOR: 'Visual Studio 17 2022' + CMAKE_GENERATE: '-A x64 -DBUILD_SHARED_LIBS=OFF -DCURL_USE_SCHANNEL=OFF -DHTTP_ONLY=ON' + + # VisualStudioSolution builds + + - job_name: 'VisualStudioSolution VS2010, Release, x86, Schannel' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2015' + PRJ_CFG: 'DLL Release - DLL Windows SSPI - DLL WinIDN' + PLAT: 'Win32' + VC_VERSION: VC10 + + - job_name: 'VisualStudioSolution VS2013, Debug, x64, Schannel' + APPVEYOR_BUILD_WORKER_IMAGE: 'Visual Studio 2015' + PRJ_CFG: 'DLL Debug - DLL Windows SSPI - DLL WinIDN' + PLAT: 'x64' + VC_VERSION: VC12 install: - - if not "%ADD_PATH%"=="" ( - set "PATH=%ADD_PATH%;%PATH%" ) + - ps: $env:PATH = "C:/msys64/usr/bin;$env:PATH" build_script: - - if %BUILD_SYSTEM%==CMake ( - cmake . - -G"%PRJ_GEN%" - %TARGET% - -DCURL_USE_OPENSSL=%OPENSSL% - -DCURL_USE_SCHANNEL=%SCHANNEL% - -DHTTP_ONLY=%HTTP_ONLY% - -DBUILD_SHARED_LIBS=%SHARED% - -DBUILD_TESTING=%TESTING% - -DENABLE_WEBSOCKETS=%WEBSOCKETS% - -DCMAKE_UNITY_BUILD=%UNITY% - -DCURL_WERROR=ON - -DENABLE_DEBUG=ON - -DENABLE_UNICODE=%ENABLE_UNICODE% - -DCMAKE_RUNTIME_OUTPUT_DIRECTORY_RELEASE="" - -DCMAKE_RUNTIME_OUTPUT_DIRECTORY_DEBUG="" - -DCMAKE_INSTALL_PREFIX="C:/CURL" - -DCMAKE_BUILD_TYPE=%PRJ_CFG% && - cmake --build . --config %PRJ_CFG% --parallel 2 --clean-first -- %BUILD_OPT% - ) else ( - if %BUILD_SYSTEM%==VisualStudioSolution ( - cd projects && - .\\generate.bat %VC_VERSION% && - msbuild.exe /p:Configuration="%PRJ_CFG%" "Windows\\%VC_VERSION%\\curl-all.sln" - ) else ( - if %BUILD_SYSTEM%==winbuild_vs2015 ( - call buildconf.bat && - cd winbuild && - call "C:\Program Files\Microsoft SDKs\Windows\v7.1\Bin\SetEnv.cmd" /x64 && - call "C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\vcvarsall.bat" x86_amd64 && - nmake /f Makefile.vc mode=dll VC=14 "SSL_PATH=C:\OpenSSL-v111-Win64" WITH_SSL=dll MACHINE=x64 DEBUG=%DEBUG% ENABLE_UNICODE=%ENABLE_UNICODE% && - ..\builds\libcurl-vc14-x64-%PATHPART%-dll-ssl-dll-ipv6-sspi\bin\curl.exe -V - ) else ( - if %BUILD_SYSTEM%==winbuild_vs2017 ( - call buildconf.bat && - cd winbuild && - call "C:\Program Files (x86)\Microsoft Visual Studio\2017\Community\VC\Auxiliary\Build\vcvars64.bat" && - nmake /f Makefile.vc mode=dll VC=14.10 "SSL_PATH=C:\OpenSSL-v111-Win64" WITH_SSL=dll MACHINE=x64 DEBUG=%DEBUG% ENABLE_UNICODE=%ENABLE_UNICODE% && - ..\builds\libcurl-vc14.10-x64-%PATHPART%-dll-ssl-dll-ipv6-sspi\bin\curl.exe -V - ) else ( - if %BUILD_SYSTEM%==autotools ( - bash.exe -e -l -c "cd %POSIX_PATH_PREFIX%/c/projects/curl && autoreconf -fi && ./configure %CONFIG_ARGS% && make V=1 && make V=1 examples && cd tests && make V=1" - ))))) - - if %TESTING%==ON ( - if %BUILD_SYSTEM%==CMake ( - cmake --build . --config %PRJ_CFG% --parallel 2 --target testdeps - )) + - cmd: sh -c ./appveyor.sh -test_script: - - if exist C:/msys64/usr/bin/curl.exe ( - set ACURL=-ac %POSIX_PATH_PREFIX%/c/msys64/usr/bin/curl.exe ) - - if exist C:/Windows/System32/curl.exe ( - set ACURL=-ac %POSIX_PATH_PREFIX%/c/Windows/System32/curl.exe ) - - if %TESTING%==ON ( - if %BUILD_SYSTEM%==CMake ( - set TFLAGS=%ACURL% %DISABLED_TESTS% && - cmake --build . --config %PRJ_CFG% --target test-ci - ) else ( - if %BUILD_SYSTEM%==autotools ( - bash.exe -e -l -c "cd %POSIX_PATH_PREFIX%/c/projects/curl && make V=1 TFLAGS='%ACURL% %DISABLED_TESTS%' test-ci" - ) else ( - bash.exe -e -l -c "cd %POSIX_PATH_PREFIX%/c/projects/curl/tests && ./runtests.pl -a -p !flaky -r -rm %ACURL% %DISABLED_TESTS%" - )) - ) +clone_depth: 10 # select branches to avoid testing feature branches twice (as branch and as pull request) branches: - only: - - master - - /\/ci$/ + only: + - master + - /\/ci$/ skip_commits: files: - - '.azure-pipelines.yml' - - '.circleci/**/*' - - '.cirrus.yml' + - '.circleci/*' - '.github/**/*' - - 'packages/**/*' - - 'plan9/**/*' + - 'Dockerfile' + - 'projects/OS400/*' + - 'projects/vms/*' -artifacts: - - path: '**/curl.exe' - name: curl - - path: '**/*curl*.dll' - name: libcurl dll +#artifacts: +# - path: '**/curl.exe' +# name: curl +# - path: '**/*.dll' +# name: libcurl dll +# - path: '**/*.lib' +# name: libcurl lib diff --git a/third-party/curl/buildconf b/third-party/curl/buildconf deleted file mode 100644 index ee6a2800be..0000000000 --- a/third-party/curl/buildconf +++ /dev/null @@ -1,8 +0,0 @@ -#!/bin/sh -# -# Copyright (C) Daniel Stenberg, , et al. -# -# SPDX-License-Identifier: curl - -echo "*** Do not use buildconf. Instead, just use: autoreconf -fi" >&2 -exec ${AUTORECONF:-autoreconf} -fi "${@}" diff --git a/third-party/curl/buildconf.bat b/third-party/curl/buildconf.bat deleted file mode 100644 index 6153661185..0000000000 --- a/third-party/curl/buildconf.bat +++ /dev/null @@ -1,319 +0,0 @@ -@echo off -rem *************************************************************************** -rem * _ _ ____ _ -rem * Project ___| | | | _ \| | -rem * / __| | | | |_) | | -rem * | (__| |_| | _ <| |___ -rem * \___|\___/|_| \_\_____| -rem * -rem * Copyright (C) Daniel Stenberg, , et al. -rem * -rem * This software is licensed as described in the file COPYING, which -rem * you should have received as part of this distribution. The terms -rem * are also available at https://curl.se/docs/copyright.html. -rem * -rem * You may opt to use, copy, modify, merge, publish, distribute and/or sell -rem * copies of the Software, and permit persons to whom the Software is -rem * furnished to do so, under the terms of the COPYING file. -rem * -rem * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -rem * KIND, either express or implied. -rem * -rem * SPDX-License-Identifier: curl -rem * -rem *************************************************************************** - -rem NOTES -rem -rem This batch file must be used to set up a git tree to build on systems where -rem there is no autotools support (i.e. DOS and Windows). -rem - -:begin - rem Set our variables - if "%OS%" == "Windows_NT" setlocal - set MODE=GENERATE - - rem Switch to this batch file's directory - cd /d "%~0\.." 1>NUL 2>&1 - - rem Check we are running from a curl git repository - if not exist GIT-INFO goto norepo - - rem Detect programs. HAVE_ - rem When not found the variable is set undefined. The undefined pattern - rem allows for statements like "if not defined HAVE_PERL (command)" - groff --version NUL 2>&1 - if errorlevel 1 (set HAVE_GROFF=) else (set HAVE_GROFF=Y) - nroff --version NUL 2>&1 - if errorlevel 1 (set HAVE_NROFF=) else (set HAVE_NROFF=Y) - perl --version NUL 2>&1 - if errorlevel 1 (set HAVE_PERL=) else (set HAVE_PERL=Y) - gzip --version NUL 2>&1 - if errorlevel 1 (set HAVE_GZIP=) else (set HAVE_GZIP=Y) - -:parseArgs - if "%~1" == "" goto start - - if /i "%~1" == "-clean" ( - set MODE=CLEAN - ) else if /i "%~1" == "-?" ( - goto syntax - ) else if /i "%~1" == "-h" ( - goto syntax - ) else if /i "%~1" == "-help" ( - goto syntax - ) else ( - goto unknown - ) - - shift & goto parseArgs - -:start - if "%MODE%" == "GENERATE" ( - echo. - echo Generating prerequisite files - - call :generate - if errorlevel 3 goto nogenhugehelp - if errorlevel 2 goto nogenmakefile - if errorlevel 1 goto warning - - ) else ( - echo. - echo Removing prerequisite files - - call :clean - if errorlevel 2 goto nocleanhugehelp - if errorlevel 1 goto nocleanmakefile - ) - - goto success - -rem Main generate function. -rem -rem Returns: -rem -rem 0 - success -rem 1 - success with simplified tool_hugehelp.c -rem 2 - failed to generate Makefile -rem 3 - failed to generate tool_hugehelp.c -rem -:generate - if "%OS%" == "Windows_NT" setlocal - set BASIC_HUGEHELP=0 - - rem Create Makefile - echo * %CD%\Makefile - if exist Makefile.dist ( - copy /Y Makefile.dist Makefile 1>NUL 2>&1 - if errorlevel 1 ( - if "%OS%" == "Windows_NT" endlocal - exit /B 2 - ) - ) - - rem Create tool_hugehelp.c - echo * %CD%\src\tool_hugehelp.c - call :genHugeHelp - if errorlevel 2 ( - if "%OS%" == "Windows_NT" endlocal - exit /B 3 - ) - if errorlevel 1 ( - set BASIC_HUGEHELP=1 - ) - cmd /c exit 0 - - rem Setup c-ares git tree - if exist ares\buildconf.bat ( - echo. - echo Configuring c-ares build environment - cd ares - call buildconf.bat - cd .. - ) - - if "%BASIC_HUGEHELP%" == "1" ( - if "%OS%" == "Windows_NT" endlocal - exit /B 1 - ) - - if "%OS%" == "Windows_NT" endlocal - exit /B 0 - -rem Main clean function. -rem -rem Returns: -rem -rem 0 - success -rem 1 - failed to clean Makefile -rem 2 - failed to clean tool_hugehelp.c -rem -:clean - rem Remove Makefile - echo * %CD%\Makefile - if exist Makefile ( - del Makefile 2>NUL - if exist Makefile ( - exit /B 1 - ) - ) - - rem Remove tool_hugehelp.c - echo * %CD%\src\tool_hugehelp.c - if exist src\tool_hugehelp.c ( - del src\tool_hugehelp.c 2>NUL - if exist src\tool_hugehelp.c ( - exit /B 2 - ) - ) - - exit /B - -rem Function to generate src\tool_hugehelp.c -rem -rem Returns: -rem -rem 0 - full tool_hugehelp.c generated -rem 1 - simplified tool_hugehelp.c -rem 2 - failure -rem -:genHugeHelp - if "%OS%" == "Windows_NT" setlocal - set LC_ALL=C - set ROFFCMD= - set BASIC=1 - - if defined HAVE_PERL ( - if defined HAVE_GROFF ( - set ROFFCMD=groff -mtty-char -Tascii -P-c -man - ) else if defined HAVE_NROFF ( - set ROFFCMD=nroff -c -Tascii -man - ) - ) - - if defined ROFFCMD ( - echo #include "tool_setup.h"> src\tool_hugehelp.c - echo #include "tool_hugehelp.h">> src\tool_hugehelp.c - - if defined HAVE_GZIP ( - echo #ifndef HAVE_LIBZ>> src\tool_hugehelp.c - ) - - %ROFFCMD% docs\curl.1 2>NUL | perl src\mkhelp.pl docs\MANUAL >> src\tool_hugehelp.c - if defined HAVE_GZIP ( - echo #else>> src\tool_hugehelp.c - %ROFFCMD% docs\curl.1 2>NUL | perl src\mkhelp.pl -c docs\MANUAL >> src\tool_hugehelp.c - echo #endif /^* HAVE_LIBZ ^*/>> src\tool_hugehelp.c - ) - - set BASIC=0 - ) else ( - if exist src\tool_hugehelp.c.cvs ( - copy /Y src\tool_hugehelp.c.cvs src\tool_hugehelp.c 1>NUL 2>&1 - ) else ( - echo #include "tool_setup.h"> src\tool_hugehelp.c - echo #include "tool_hugehelp.h">> src\tool_hugehelp.c - echo.>> src\tool_hugehelp.c - echo void hugehelp(void^)>> src\tool_hugehelp.c - echo {>> src\tool_hugehelp.c - echo #ifdef USE_MANUAL>> src\tool_hugehelp.c - echo fputs("Built-in manual not included\n", stdout^);>> src\tool_hugehelp.c - echo #endif>> src\tool_hugehelp.c - echo }>> src\tool_hugehelp.c - ) - ) - - findstr "/C:void hugehelp(void)" src\tool_hugehelp.c 1>NUL 2>&1 - if errorlevel 1 ( - if "%OS%" == "Windows_NT" endlocal - exit /B 2 - ) - - if "%BASIC%" == "1" ( - if "%OS%" == "Windows_NT" endlocal - exit /B 1 - ) - - if "%OS%" == "Windows_NT" endlocal - exit /B 0 - -rem Function to clean-up local variables under DOS, Windows 3.x and -rem Windows 9x as setlocal isn't available until Windows NT -rem -:dosCleanup - set MODE= - set HAVE_GROFF= - set HAVE_NROFF= - set HAVE_PERL= - set HAVE_GZIP= - set BASIC_HUGEHELP= - set LC_ALL - set ROFFCMD= - set BASIC= - - exit /B - -:syntax - rem Display the help - echo. - echo Usage: buildconf [-clean] - echo. - echo -clean - Removes the files - goto error - -:unknown - echo. - echo Error: Unknown argument '%1' - goto error - -:norepo - echo. - echo Error: This batch file should only be used with a curl git repository - goto error - -:nogenmakefile - echo. - echo Error: Unable to generate Makefile - goto error - -:nogenhugehelp - echo. - echo Error: Unable to generate src\tool_hugehelp.c - goto error - -:nocleanmakefile - echo. - echo Error: Unable to clean Makefile - goto error - -:nocleanhugehelp - echo. - echo Error: Unable to clean src\tool_hugehelp.c - goto error - -:warning - echo. - echo Warning: The curl manual could not be integrated in the source. This means when - echo you build curl the manual will not be available (curl --man^). Integration of - echo the manual is not required and a summary of the options will still be available - echo (curl --help^). To integrate the manual your PATH is required to have - echo groff/nroff, perl and optionally gzip for compression. - goto success - -:error - if "%OS%" == "Windows_NT" ( - endlocal - ) else ( - call :dosCleanup - ) - exit /B 1 - -:success - if "%OS%" == "Windows_NT" ( - endlocal - ) else ( - call :dosCleanup - ) - exit /B 0 diff --git a/third-party/curl/configure.ac b/third-party/curl/configure.ac index 15fbda12ad..a21847ea66 100644 --- a/third-party/curl/configure.ac +++ b/third-party/curl/configure.ac @@ -25,11 +25,10 @@ dnl Process this file with autoconf to produce a configure script. AC_PREREQ(2.59) -dnl We don't know the version number "statically" so we use a dash here +dnl We do not know the version number "statically" so we use a dash here AC_INIT([curl], [-], [a suitable curl mailing list: https://curl.se/mail/]) XC_OVR_ZZ50 -XC_OVR_ZZ60 CURL_OVERRIDE_AUTOCONF dnl configure script copyright @@ -39,25 +38,52 @@ terms of the curl license; see COPYING for more details]) AC_CONFIG_SRCDIR([lib/urldata.h]) AC_CONFIG_HEADERS(lib/curl_config.h) +AH_TOP([/* !checksrc! disable COPYRIGHT all */]) AC_CONFIG_MACRO_DIR([m4]) AM_MAINTAINER_MODE m4_ifdef([AM_SILENT_RULES], [AM_SILENT_RULES([yes])]) CURL_CHECK_OPTION_DEBUG +AM_CONDITIONAL(DEBUGBUILD, test "$want_debug" = "yes") CURL_CHECK_OPTION_OPTIMIZE CURL_CHECK_OPTION_WARNINGS CURL_CHECK_OPTION_WERROR -CURL_CHECK_OPTION_CURLDEBUG CURL_CHECK_OPTION_SYMBOL_HIDING CURL_CHECK_OPTION_ARES CURL_CHECK_OPTION_RT +CURL_CHECK_OPTION_HTTPSRR CURL_CHECK_OPTION_ECH +CURL_CHECK_OPTION_SSLS_EXPORT +AC_MSG_CHECKING([whether to enable HTTP/3 proxy support]) +OPT_PROXY_HTTP3="default" +AC_ARG_ENABLE(proxy-http3, +AS_HELP_STRING([--enable-proxy-http3],[Enable HTTP/3 proxy support (experimental)]) +AS_HELP_STRING([--disable-proxy-http3],[Disable HTTP/3 proxy support (experimental)]), + OPT_PROXY_HTTP3=$enableval) +case "$OPT_PROXY_HTTP3" in + no) + want_proxy_http3="no" + curl_proxy_http3_msg="no (--enable-proxy-http3)" + AC_MSG_RESULT([no]) + ;; + default) + want_proxy_http3="no" + curl_proxy_http3_msg="no (--enable-proxy-http3)" + AC_MSG_RESULT([no]) + ;; + *) + want_proxy_http3="yes" + curl_proxy_http3_msg="enabled (--disable-proxy-http3)" + AC_MSG_RESULT([yes]) + ;; +esac +USE_PROXY_HTTP3=0 XC_CHECK_PATH_SEPARATOR -# -# save the configure arguments -# +dnl +dnl save the configure arguments +dnl CONFIGURE_OPTIONS="\"$ac_configure_args\"" AC_SUBST(CONFIGURE_OPTIONS) @@ -118,14 +144,16 @@ AC_SUBST([AR]) AC_SUBST(libext) +if test -z "$CLANG_TIDY"; then + CLANG_TIDY=clang-tidy +fi +AC_SUBST(CLANG_TIDY) + dnl figure out the libcurl version CURLVERSION=`$SED -ne 's/^#define LIBCURL_VERSION "\(.*\)".*/\1/p' ${srcdir}/include/curl/curlver.h` XC_CHECK_PROG_CC CURL_ATOMIC -dnl for --enable-code-coverage -CURL_COVERAGE - XC_AUTOMAKE AC_MSG_CHECKING([curl version]) AC_MSG_RESULT($CURLVERSION) @@ -137,45 +165,38 @@ dnl we extract the numerical version for curl-config only VERSIONNUM=`$SED -ne 's/^#define LIBCURL_VERSION_NUM 0x\([0-9A-Fa-f]*\).*/\1/p' ${srcdir}/include/curl/curlver.h` AC_SUBST(VERSIONNUM) -dnl Solaris pkgadd support definitions -PKGADD_PKG="HAXXcurl" -PKGADD_NAME="curl - a client that groks URLs" -PKGADD_VENDOR="curl.se" -AC_SUBST(PKGADD_PKG) -AC_SUBST(PKGADD_NAME) -AC_SUBST(PKGADD_VENDOR) - dnl dnl initialize all the info variables - curl_ssl_msg="no (--with-{openssl,gnutls,mbedtls,wolfssl,schannel,secure-transport,amissl,bearssl,rustls} )" - curl_ssh_msg="no (--with-{libssh,libssh2})" - curl_zlib_msg="no (--with-zlib)" - curl_brotli_msg="no (--with-brotli)" - curl_zstd_msg="no (--with-zstd)" - curl_gss_msg="no (--with-gssapi)" - curl_gsasl_msg="no (--with-gsasl)" -curl_tls_srp_msg="no (--enable-tls-srp)" - curl_res_msg="default (--enable-ares / --enable-threaded-resolver)" - curl_ipv6_msg="no (--enable-ipv6)" -curl_unix_sockets_msg="no (--enable-unix-sockets)" - curl_idn_msg="no (--with-{libidn2,winidn})" - curl_manual_msg="no (--enable-manual)" -curl_libcurl_msg="enabled (--disable-libcurl-option)" -curl_verbose_msg="enabled (--disable-verbose)" - curl_sspi_msg="no (--enable-sspi)" - curl_ldap_msg="no (--enable-ldap / --with-ldap-lib / --with-lber-lib)" - curl_ldaps_msg="no (--enable-ldaps)" - curl_rtsp_msg="no (--enable-rtsp)" - curl_rtmp_msg="no (--with-librtmp)" - curl_psl_msg="no (--with-libpsl)" - curl_altsvc_msg="enabled (--disable-alt-svc)" -curl_headers_msg="enabled (--disable-headers-api)" - curl_hsts_msg="enabled (--disable-hsts)" - curl_ws_msg="no (--enable-websockets)" - ssl_backends= - curl_h1_msg="enabled (internal)" - curl_h2_msg="no (--with-nghttp2, --with-hyper)" - curl_h3_msg="no (--with-ngtcp2 --with-nghttp3, --with-quiche, --with-msh3)" + curl_ssl_msg="no (--with-{openssl,gnutls,mbedtls,wolfssl,schannel,amissl,rustls} )" + curl_ssh_msg="no (--with-{libssh,libssh2})" + curl_zlib_msg="no (--with-zlib)" + curl_brotli_msg="no (--with-brotli)" + curl_zstd_msg="no (--with-zstd)" + curl_gss_msg="no (--with-gssapi)" + curl_gsasl_msg="no (--with-gsasl)" + curl_tls_srp_msg="no (--enable-tls-srp)" + curl_res_msg="blocking (--enable-ares / --enable-threaded-resolver)" + curl_ipv6_msg="no (--enable-ipv6)" +curl_unix_sockets_msg="no (--enable-unix-sockets)" + curl_idn_msg="no (--with-{libidn2,winidn})" + curl_docs_msg="enabled (--disable-docs)" + curl_manual_msg="no (--enable-manual)" + curl_libcurl_msg="enabled (--disable-libcurl-option)" + curl_typecheck_msg="enabled (--disable-typecheck)" + curl_verbose_msg="enabled (--disable-verbose)" + curl_sspi_msg="no (--enable-sspi)" + curl_ldap_msg="no (--enable-ldap / --with-ldap-lib / --with-lber-lib)" + curl_ldaps_msg="no (--enable-ldaps)" + curl_ipfs_msg="no (--enable-ipfs)" + curl_rtsp_msg="no (--enable-rtsp)" + curl_psl_msg="no (--with-libpsl)" + curl_altsvc_msg="enabled (--disable-alt-svc)" + curl_headers_msg="enabled (--disable-headers-api)" + curl_hsts_msg="enabled (--disable-hsts)" + ssl_backends= + curl_h1_msg="enabled (internal)" + curl_h2_msg="no (--with-nghttp2)" + curl_h3_msg="no (--with-ngtcp2 --with-nghttp3, --with-quiche)" enable_altsvc="yes" hsts="yes" @@ -206,24 +227,17 @@ exec $CC "$@" EOF dnl ********************************************************************** -dnl See which TLS backend(s) that are requested. Just do all the +dnl See which TLS backend(s) that are requested. Do all the dnl TLS AC_ARG_WITH() invokes here and do the checks later dnl ********************************************************************** OPT_SCHANNEL=no -AC_ARG_WITH(schannel,dnl +AC_ARG_WITH(schannel, AS_HELP_STRING([--with-schannel],[enable Windows native SSL/TLS]), OPT_SCHANNEL=$withval - TLSCHOICE="schannel") - -OPT_SECURETRANSPORT=no -AC_ARG_WITH(secure-transport,dnl -AS_HELP_STRING([--with-secure-transport],[enable Apple OS native SSL/TLS]),[ - OPT_SECURETRANSPORT=$withval - TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }Secure-Transport" -]) + TLSCHOICE="Schannel") OPT_AMISSL=no -AC_ARG_WITH(amissl,dnl +AC_ARG_WITH(amissl, AS_HELP_STRING([--with-amissl],[enable Amiga native SSL/TLS (AmiSSL)]),[ OPT_AMISSL=$withval TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }AmiSSL" @@ -232,134 +246,170 @@ AS_HELP_STRING([--with-amissl],[enable Amiga native SSL/TLS (AmiSSL)]),[ OPT_OPENSSL=no dnl Default to no CA bundle ca="no" -AC_ARG_WITH(ssl,dnl +AC_ARG_WITH(ssl, AS_HELP_STRING([--with-ssl=PATH],[old version of --with-openssl]) AS_HELP_STRING([--without-ssl], [build without any TLS library]),[ OPT_SSL=$withval OPT_OPENSSL=$withval - if test X"$withval" != Xno; then + if test "x$withval" != "xno"; then TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }OpenSSL" else SSL_DISABLED="D" fi ]) -AC_ARG_WITH(openssl,dnl -AS_HELP_STRING([--with-openssl=PATH],[Where to look for OpenSSL, PATH points to the SSL installation (default: /usr/local/ssl); when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]),[ +AC_ARG_WITH(openssl, +AS_HELP_STRING([--with-openssl=PATH],[Where to look for OpenSSL, PATH points + to the SSL installation (default: /usr/local/ssl); when possible, set + the PKG_CONFIG_PATH environment variable instead of using this option]), +[ OPT_OPENSSL=$withval - if test X"$withval" != Xno; then + if test "x$withval" != "xno"; then TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }OpenSSL" fi ]) OPT_GNUTLS=no -AC_ARG_WITH(gnutls,dnl +AC_ARG_WITH(gnutls, AS_HELP_STRING([--with-gnutls=PATH],[where to look for GnuTLS, PATH points to the installation root]),[ OPT_GNUTLS=$withval - if test X"$withval" != Xno; then + if test "x$withval" != "xno"; then TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }GnuTLS" fi ]) OPT_MBEDTLS=no -AC_ARG_WITH(mbedtls,dnl +AC_ARG_WITH(mbedtls, AS_HELP_STRING([--with-mbedtls=PATH],[where to look for mbedTLS, PATH points to the installation root]),[ OPT_MBEDTLS=$withval - if test X"$withval" != Xno; then + if test "x$withval" != "xno"; then TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }mbedTLS" fi ]) OPT_WOLFSSL=no -AC_ARG_WITH(wolfssl,dnl -AS_HELP_STRING([--with-wolfssl=PATH],[where to look for WolfSSL, PATH points to the installation root (default: system lib default)]),[ +AC_ARG_WITH(wolfssl, +AS_HELP_STRING([--with-wolfssl=PATH],[where to look for wolfSSL, PATH points to the installation root (default: system lib default)]),[ OPT_WOLFSSL=$withval - if test X"$withval" != Xno; then + if test "x$withval" != "xno"; then TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }wolfSSL" fi ]) -OPT_BEARSSL=no -AC_ARG_WITH(bearssl,dnl -AS_HELP_STRING([--with-bearssl=PATH],[where to look for BearSSL, PATH points to the installation root]),[ - OPT_BEARSSL=$withval - if test X"$withval" != Xno; then - TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }BearSSL" +OPT_RUSTLS=no +AC_ARG_WITH(rustls, +AS_HELP_STRING([--with-rustls=PATH],[where to look for Rustls, PATH points to the installation root]),[ + OPT_RUSTLS=$withval + if test "x$withval" != "xno"; then + TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }Rustls" + experimental="$experimental Rustls" fi ]) -OPT_RUSTLS=no -AC_ARG_WITH(rustls,dnl -AS_HELP_STRING([--with-rustls=PATH],[where to look for rustls, PATH points to the installation root]),[ - OPT_RUSTLS=$withval - if test X"$withval" != Xno; then - TLSCHOICE="${TLSCHOICE:+$TLSCHOICE, }rustls" - experimental="$experimental rustls" - fi +OPT_APPLE_SECTRUST=no +AC_ARG_WITH(apple-sectrust, +AS_HELP_STRING([--with-apple-sectrust],[enable Apple OS native certificate verification]),[ + OPT_APPLE_SECTRUST=$withval ]) +AC_PATH_PROG(PERL, perl,, $PATH:/usr/local/bin/perl:/usr/bin/:/usr/local/bin) +AC_SUBST(PERL) +AM_CONDITIONAL(PERL, test -n "$PERL") + TEST_NGHTTPX=nghttpx -AC_ARG_WITH(test-nghttpx,dnl +AC_ARG_WITH(test-nghttpx, AS_HELP_STRING([--with-test-nghttpx=PATH],[where to find nghttpx for testing]), TEST_NGHTTPX=$withval - if test X"$OPT_TEST_NGHTTPX" = "Xno" ; then - TEST_NGHTTPX="" + if test "x$TEST_NGHTTPX" = "xno"; then + TEST_NGHTTPX="" fi ) AC_SUBST(TEST_NGHTTPX) -CADDY=caddy -AC_ARG_WITH(test-caddy,dnl +if test -x /usr/bin/caddy; then + CADDY=/usr/bin/caddy +elif test -x /usr/local/bin/caddy; then + CADDY=/usr/local/bin/caddy +elif test -x "`brew --prefix 2>/dev/null`/bin/caddy"; then + CADDY=`brew --prefix`/bin/caddy +fi +AC_ARG_WITH(test-caddy, AS_HELP_STRING([--with-test-caddy=PATH],[where to find caddy for testing]), CADDY=$withval - if test X"$OPT_CADDY" = "Xno" ; then - CADDY="" + if test "x$CADDY" = "xno"; then + CADDY="" fi ) AC_SUBST(CADDY) -dnl we'd like a httpd+apachectl as test server +if test -x /usr/local/bin/h2o; then + H2O=/usr/local/bin/h2o +elif test -x /usr/bin/h2o; then + H2O=/usr/bin/h2o +elif test -x "`brew --prefix 2>/dev/null`/bin/h2o"; then + H2O=`brew --prefix`/bin/h2o +fi +AC_ARG_WITH(test-h2o,dnl +AS_HELP_STRING([--with-test-h2o=PATH],[where to find h2o for testing]), + H2O=$withval + if test "x$H2O" = "xno"; then + H2O="" + fi +) +AC_SUBST(H2O) + +if test -x /usr/sbin/vsftpd; then + VSFTPD=/usr/sbin/vsftpd +elif test -x /usr/local/sbin/vsftpd; then + VSFTPD=/usr/local/sbin/vsftpd +elif test -x "`brew --prefix 2>/dev/null`/sbin/vsftpd"; then + VSFTPD=`brew --prefix`/sbin/vsftpd +fi +AC_ARG_WITH(test-vsftpd, +AS_HELP_STRING([--with-test-vsftpd=PATH],[where to find vsftpd for testing]), + VSFTPD=$withval + if test "x$VSFTPD" = "xno"; then + VSFTPD="" + fi +) +AC_SUBST(VSFTPD) + +dnl we would like an httpd as test server dnl HTTPD_ENABLED="maybe" AC_ARG_WITH(test-httpd, [AS_HELP_STRING([--with-test-httpd=PATH], - [where to find httpd/apache2 for testing])], + [where to find httpd/apache2 for testing])], [request_httpd=$withval], [request_httpd=check]) -if test x"$request_httpd" = "xcheck" -o x"$request_httpd" = "xyes"; then - if test -x "/usr/sbin/apache2" -a -x "/usr/sbin/apache2ctl"; then - # common location on distros (debian/ubuntu) +if test "x$request_httpd" = "xcheck" || test "x$request_httpd" = "xyes"; then + if test -x "/usr/sbin/apache2"; then + dnl common location on distros (debian/ubuntu) HTTPD="/usr/sbin/apache2" - APACHECTL="/usr/sbin/apache2ctl" AC_PATH_PROG([APXS], [apxs]) - if test "x$APXS" = "x"; then + if test -z "$APXS"; then AC_MSG_NOTICE([apache2-dev not installed, httpd tests disabled]) HTTPD_ENABLED="no" fi else AC_PATH_PROG([HTTPD], [httpd]) - if test "x$HTTPD" = "x"; then + if test -z "$HTTPD"; then AC_PATH_PROG([HTTPD], [apache2]) fi - AC_PATH_PROG([APACHECTL], [apachectl]) AC_PATH_PROG([APXS], [apxs]) - if test "x$HTTPD" = "x" -o "x$APACHECTL" = "x"; then + if test -z "$HTTPD"; then AC_MSG_NOTICE([httpd/apache2 not in PATH, http tests disabled]) HTTPD_ENABLED="no" fi - if test "x$APXS" = "x"; then + if test -z "$APXS"; then AC_MSG_NOTICE([apxs not in PATH, http tests disabled]) HTTPD_ENABLED="no" fi fi -elif test x"$request_httpd" != "xno"; then +elif test "x$request_httpd" != "xno"; then HTTPD="${request_httpd}/bin/httpd" - APACHECTL="${request_httpd}/bin/apachectl" APXS="${request_httpd}/bin/apxs" if test ! -x "${HTTPD}"; then AC_MSG_NOTICE([httpd not found as ${HTTPD}, http tests disabled]) HTTPD_ENABLED="no" - elif test ! -x "${APACHECTL}"; then - AC_MSG_NOTICE([apachectl not found as ${APACHECTL}, http tests disabled]) - HTTPD_ENABLED="no" elif test ! -x "${APXS}"; then AC_MSG_NOTICE([apxs not found as ${APXS}, http tests disabled]) HTTPD_ENABLED="no" @@ -367,17 +417,90 @@ elif test x"$request_httpd" != "xno"; then AC_MSG_NOTICE([using HTTPD=$HTTPD for tests]) fi fi -if test x"$HTTPD_ENABLED" = "xno"; then +if test "$HTTPD_ENABLED" = "no"; then HTTPD="" - APACHECTL="" APXS="" fi AC_SUBST(HTTPD) -AC_SUBST(APACHECTL) AC_SUBST(APXS) +dnl we would like a dante as test socks server +dnl +DANTED_ENABLED="maybe" +AC_ARG_WITH(test-danted, [AS_HELP_STRING([--with-test-danted=PATH], + [where to find danted socks daemon for testing])], + [request_danted=$withval], [request_danted=check]) +if test "x$request_danted" = "xcheck" || test "x$request_danted" = "xyes"; then + if test -x "/usr/sbin/danted"; then + dnl common location on distros (debian/ubuntu) + DANTED="/usr/sbin/danted" + else + AC_PATH_PROG([DANTED], [danted]) + if test -z "$DANTED"; then + AC_PATH_PROG([DANTED], [danted]) + fi + fi +elif test "x$request_danted" != "xno"; then + DANTED="${request_danted}" + if test ! -x "${DANTED}"; then + AC_MSG_NOTICE([danted not found as ${DANTED}, danted tests disabled]) + DANTED_ENABLED="no" + else + AC_MSG_NOTICE([using DANTED=$DANTED for tests]) + fi +fi +if test "$DANTED_ENABLED" = "no"; then + DANTED="" +fi +AC_SUBST(DANTED) + +dnl we would like a sshd as test server +dnl +SSHD_ENABLED="maybe" +AC_ARG_WITH(test-sshd, [AS_HELP_STRING([--with-test-sshd=PATH], + [where to find sshd for testing])], + [request_sshd=$withval], [request_sshd=check]) +if test "x$request_sshd" = "xcheck" || test "x$request_sshd" = "xyes"; then + if test -x "/usr/sbin/sshd"; then + dnl common location on distros (debian/ubuntu) + SSHD="/usr/sbin/sshd" + else + AC_PATH_PROG([SSHD], [sshd]) + if test -z "$SSHD"; then + AC_PATH_PROG([SSHD], [sshd]) + fi + fi +elif test "x$request_sshd" != "xno"; then + SSHD="${request_sshd}" + if test ! -x "${SSHD}"; then + AC_MSG_NOTICE([sshd not found as ${SSHD}, sshd tests disabled]) + SSHD_ENABLED="no" + else + AC_MSG_NOTICE([using SSHD=$SSHD for tests]) + fi +fi +if test "$SSHD_ENABLED" = "no"; then + SSHD="" + SFTPD="" +else + if test -x "/usr/libexec/sftp-server"; then + dnl common location on macOS) + SFTPD="/usr/libexec/sftp-server" + elif test -x "/usr/lib/openssh/sftp-server"; then + dnl common location on debian + SFTPD="/usr/lib/openssh/sftp-server" + else + AC_PATH_PROG([SFTPD], [sftp-server]) + if test -z "$SFTPD"; then + AC_PATH_PROG([SFTPD], [sftp-server]) + fi + fi +fi +AC_SUBST(SSHD) +AC_SUBST(SFTPD) + dnl the nghttpx we might use in httpd testing -if test "x$TEST_NGHTTPX" != "x" -a "x$TEST_NGHTTPX" != "xnghttpx"; then +if test -n "$TEST_NGHTTPX" && test "x$TEST_NGHTTPX" != "xnghttpx"; then HTTPD_NGHTTPX="$TEST_NGHTTPX" else AC_PATH_PROG([HTTPD_NGHTTPX], [nghttpx], [], @@ -386,7 +509,7 @@ fi AC_SUBST(HTTPD_NGHTTPX) dnl the Caddy server we might use in testing -if test "x$TEST_CADDY" != "x"; then +if test -n "$TEST_CADDY"; then CADDY="$TEST_CADDY" else AC_PATH_PROG([CADDY], [caddy]) @@ -402,13 +525,11 @@ if test -z "$TLSCHOICE"; then Select from these: --with-amissl - --with-bearssl --with-gnutls --with-mbedtls - --with-openssl (also works for BoringSSL and libressl) + --with-openssl (also works for AWS-LC, BoringSSL and LibreSSL) --with-rustls --with-schannel - --with-secure-transport --with-wolfssl ]) fi @@ -423,9 +544,9 @@ dnl AC_CANONICAL_HOST dnl Get system canonical name -AC_DEFINE_UNQUOTED(OS, "${host}", [cpu-machine-OS]) +AC_DEFINE_UNQUOTED(CURL_OS, "${host}", [cpu-machine-OS]) -# Silence warning: ar: 'u' modifier ignored since 'D' is the default +dnl Silence warning: ar: 'u' modifier ignored since 'D' is the default AC_SUBST(AR_FLAGS, [cr]) dnl This defines _ALL_SOURCE for AIX @@ -442,74 +563,91 @@ XC_LIBTOOL LT_LANG([Windows Resource]) -# -# Automake conditionals based on libtool related checks -# +AM_CONDITIONAL(NOT_CURL_CI, test -z "$CURL_CI") + +dnl +dnl Automake conditionals based on libtool related checks +dnl AM_CONDITIONAL([CURL_LT_SHLIB_USE_VERSION_INFO], - [test "x$xc_lt_shlib_use_version_info" = 'xyes']) + [test "$xc_lt_shlib_use_version_info" = "yes"]) AM_CONDITIONAL([CURL_LT_SHLIB_USE_NO_UNDEFINED], - [test "x$xc_lt_shlib_use_no_undefined" = 'xyes']) + [test "$xc_lt_shlib_use_no_undefined" = "yes"]) AM_CONDITIONAL([CURL_LT_SHLIB_USE_MIMPURE_TEXT], - [test "x$xc_lt_shlib_use_mimpure_text" = 'xyes']) + [test "$xc_lt_shlib_use_mimpure_text" = "yes"]) -# -# Due to libtool and automake machinery limitations of not allowing -# specifying separate CPPFLAGS or CFLAGS when compiling objects for -# inclusion of these in shared or static libraries, we are forced to -# build using separate configure runs for shared and static libraries -# on systems where different CPPFLAGS or CFLAGS are mandatory in order -# to compile objects for each kind of library. Notice that relying on -# the '-DPIC' CFLAG that libtool provides is not valid given that the -# user might for example choose to build static libraries with PIC. -# +dnl +dnl Due to libtool and automake machinery limitations of not allowing +dnl specifying separate CPPFLAGS or CFLAGS when compiling objects for +dnl inclusion of these in shared or static libraries, we are forced to +dnl build using separate configure runs for shared and static libraries +dnl on systems where different CPPFLAGS or CFLAGS are mandatory in order +dnl to compile objects for each kind of library. Notice that relying on +dnl the '-DPIC' CFLAG that libtool provides is not valid given that the +dnl user might for example choose to build static libraries with PIC. +dnl -# -# Make our Makefile.am files use the staticlib CPPFLAG only when strictly -# targeting a static library and not building its shared counterpart. -# +dnl +dnl Make our Makefile.am files use the staticlib CPPFLAG only when strictly +dnl targeting a static library and not building its shared counterpart. +dnl AM_CONDITIONAL([USE_CPPFLAG_CURL_STATICLIB], - [test "x$xc_lt_build_static_only" = 'xyes']) + [test "$xc_lt_build_static_only" = "yes"]) -# -# Make staticlib CPPFLAG variable and its definition visible in output -# files unconditionally, providing an empty definition unless strictly -# targeting a static library and not building its shared counterpart. -# +dnl +dnl Make staticlib CPPFLAG variable and its definition visible in output +dnl files unconditionally, providing an empty definition unless strictly +dnl targeting a static library and not building its shared counterpart. +dnl -CPPFLAG_CURL_STATICLIB= -if test "x$xc_lt_build_static_only" = 'xyes'; then - CPPFLAG_CURL_STATICLIB='-DCURL_STATICLIB' +LIBCURL_PC_CFLAGS_PRIVATE='-DCURL_STATICLIB' +AC_SUBST(LIBCURL_PC_CFLAGS_PRIVATE) + +LIBCURL_PC_CFLAGS= +if test "$xc_lt_build_static_only" = "yes"; then + LIBCURL_PC_CFLAGS="${LIBCURL_PC_CFLAGS_PRIVATE}" fi -AC_SUBST([CPPFLAG_CURL_STATICLIB]) - - -# Determine whether all dependent libraries must be specified when linking -if test "X$enable_shared" = "Xyes" -a "X$link_all_deplibs" = "Xno" -then - REQUIRE_LIB_DEPS=no -else - REQUIRE_LIB_DEPS=yes -fi -AC_SUBST(REQUIRE_LIB_DEPS) -AM_CONDITIONAL(USE_EXPLICIT_LIB_DEPS, test x$REQUIRE_LIB_DEPS = xyes) - -dnl check if there's a way to force code inline -AC_C_INLINE +AC_SUBST([LIBCURL_PC_CFLAGS]) dnl ********************************************************************** dnl platform/compiler/architecture specific checks/flags dnl ********************************************************************** CURL_CHECK_COMPILER +dnl for --enable-code-coverage +CURL_COVERAGE +CURL_CHECK_NATIVE_WINDOWS + +curl_cv_winuwp='no' +if test "$curl_cv_native_windows" = "yes"; then + case "$CPPFLAGS" in + *-DWINSTORECOMPAT*) curl_cv_winuwp='yes';; + esac + + AC_MSG_CHECKING([if building for Windows Vista or newer]) + AC_COMPILE_IFELSE([ + AC_LANG_PROGRAM([[ + #include + ]],[[ + #if (_WIN32_WINNT < 0x600) + #error + #endif + ]]) + ],[ + AC_MSG_RESULT([yes]) + ],[ + AC_MSG_RESULT([no]) + AC_MSG_ERROR([Building for Windows Vista or newer is required.]) + ]) +fi + CURL_SET_COMPILER_BASIC_OPTS CURL_SET_COMPILER_DEBUG_OPTS CURL_SET_COMPILER_OPTIMIZE_OPTS CURL_SET_COMPILER_WARNING_OPTS if test "$compiler_id" = "INTEL_UNIX_C"; then - # if test "$compiler_num" -ge "1000"; then dnl icc 10.X or later CFLAGS="$CFLAGS -shared-intel" @@ -517,11 +655,19 @@ if test "$compiler_id" = "INTEL_UNIX_C"; then dnl icc 9.X specific CFLAGS="$CFLAGS -i-dynamic" fi - # fi +case $host in + *msdosdjgpp) + if test "$compiler_num" -ge "1000"; then + dnl Avoid warnings in DJGPP's built-in FD_SET() macro + CFLAGS="$CFLAGS -Wno-arith-conversion" + fi + ;; +esac + CURL_CFLAG_EXTRAS="" -if test X"$want_werror" = Xyes; then +if test "$want_werror" = "yes"; then CURL_CFLAG_EXTRAS="-Werror" if test "$compiler_id" = "GNU_C"; then dnl enable -pedantic-errors for GCC 5 and later, @@ -529,30 +675,30 @@ if test X"$want_werror" = Xyes; then if test "$compiler_num" -ge "500"; then CURL_CFLAG_EXTRAS="$CURL_CFLAG_EXTRAS -pedantic-errors" fi + elif test "$compiler_id" = "CLANG" || test "$compiler_id" = "APPLECLANG"; then + CURL_CFLAG_EXTRAS="$CURL_CFLAG_EXTRAS -pedantic-errors" fi fi AC_SUBST(CURL_CFLAG_EXTRAS) +AM_CONDITIONAL(CURL_WERROR, test "$want_werror" = "yes") CURL_CHECK_COMPILER_HALT_ON_ERROR CURL_CHECK_COMPILER_ARRAY_SIZE_NEGATIVE CURL_CHECK_COMPILER_PROTOTYPE_MISMATCH CURL_CHECK_COMPILER_SYMBOL_HIDING -CURL_CHECK_CURLDEBUG -AM_CONDITIONAL(CURLDEBUG, test x$want_curldebug = xyes) - supports_unittests=yes -# cross-compilation of unit tests static library/programs fails when -# libcurl shared library is built. This might be due to a libtool or -# automake issue. In this case we disable unit tests. -if test "x$cross_compiling" != "xno" && - test "x$enable_shared" != "xno"; then +dnl cross-compilation of unit tests static library/programs fails when +dnl libcurl shared library is built. This might be due to a libtool or +dnl automake issue. In this case we disable unit tests. +if test "$cross_compiling" != "no" && + test "$enable_shared" != "no"; then supports_unittests=no fi -# IRIX 6.5.24 gcc 3.3 autobuilds fail unittests library compilation due to -# a problem related with OpenSSL headers and library versions not matching. -# Disable unit tests while time to further investigate this is found. +dnl IRIX 6.5.24 gcc 3.3 autobuilds fail unittests library compilation due to +dnl a problem related with OpenSSL headers and library versions not matching. +dnl Disable unit tests while time to further investigate this is found. case $host in mips-sgi-irix6.5) if test "$compiler_id" = "GNU_C"; then @@ -561,114 +707,44 @@ case $host in ;; esac -# All AIX autobuilds fails unit tests linking against unittests library -# due to unittests library being built with no symbols or members. Libtool ? -# Disable unit tests while time to further investigate this is found. +dnl All AIX autobuilds fails unit tests linking against unittests library +dnl due to unittests library being built with no symbols or members. Libtool ? +dnl Disable unit tests while time to further investigate this is found. case $host_os in aix*) supports_unittests=no ;; esac -dnl Build unit tests when option --enable-debug is given. -if test "x$want_debug" = "xyes" && - test "x$supports_unittests" = "xyes"; then - want_unittests=yes -else - want_unittests=no -fi -AM_CONDITIONAL(BUILD_UNITTESTS, test x$want_unittests = xyes) +AM_CONDITIONAL(BUILD_UNITTESTS, test "$supports_unittests" = "yes") -# For original MinGW (ie not MinGW-w64) define the Windows minimum supported OS -# version to Windows XP (0x501) if it hasn't already been defined by the user. -# Without this override original MinGW defaults the version to Windows NT 4.0. -# Note original MinGW sets _WIN32_WINNT if not defined to whatever WINVER is. -case $host in - *-*-mingw32*) - AC_MSG_CHECKING([if MinGW minimum supported OS should be set to XP]) - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#include <_mingw.h> - ]],[[ -#if defined(__MINGW64_VERSION_MAJOR) || \ - defined(WINVER) || \ - defined(_WIN32_WINNT) -#error -#endif - ]]) - ],[ - CPPFLAGS="$CPPFLAGS -DWINVER=0x501" - AC_MSG_RESULT([yes]) - ],[ - AC_MSG_RESULT([no]) - ]) +dnl In order to detect support of sendmmsg() and accept4(), we need to escape +dnl the POSIX jail by defining _GNU_SOURCE or does not expose it. +case $host_os in + *linux*|cygwin*|msys*|gnu*) + CPPFLAGS="$CPPFLAGS -D_GNU_SOURCE" ;; esac -# Detect original MinGW (not MinGW-w64) -curl_mingw_original=no -case $host in - *-*-mingw32*) - AC_MSG_CHECKING([using original MinGW (not MinGW-w64)]) - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#include <_mingw.h> - ]],[[ -#if defined(__MINGW64_VERSION_MAJOR) -#error -#endif - ]]) - ],[ - curl_mingw_original=yes - curl_mingw_die=yes - AC_MSG_RESULT([yes]) - ],[ - AC_MSG_RESULT([no]) - ]) - ;; -esac - - -AC_ARG_WITH(mingw1-deprecated,dnl -AS_HELP_STRING([--with-mingw1-deprecated],[confirm you realize support for mingw v1 is dying]), - if test X"$withval" != Xno; then - curl_mingw_die= - fi -) - -if test -n "$curl_mingw_die"; then - AC_MSG_ERROR([support for mingw v1 is going away, enable temporarily with --with-mingw1-deprecated]) -fi +AM_CONDITIONAL(CLANG, test "$compiler_id" = "APPLECLANG" || test "$compiler_id" = "CLANG") dnl ********************************************************************** dnl Compilation based checks should not be done before this point. dnl ********************************************************************** -dnl ********************************************************************** -dnl Make sure that our checks for headers windows.h winsock2.h -dnl and ws2tcpip.h take precedence over any other further checks which -dnl could be done later using AC_CHECK_HEADER or AC_CHECK_HEADERS for -dnl this specific header files. And do them before its results are used. -dnl ********************************************************************** - -CURL_CHECK_HEADER_WINDOWS -CURL_CHECK_NATIVE_WINDOWS -case X-"$curl_cv_native_windows" in - X-yes) - CURL_CHECK_HEADER_WINSOCK2 - CURL_CHECK_HEADER_WS2TCPIP - ;; - *) - curl_cv_header_winsock2_h="no" - curl_cv_header_ws2tcpip_h="no" - ;; -esac -CURL_CHECK_WIN32_LARGEFILE CURL_CHECK_WIN32_CRYPTO -CURL_DARWIN_CFLAGS -CURL_DARWIN_SYSTEMCONFIGURATION -CURL_SUPPORTS_BUILTIN_AVAILABLE +curl_cv_android='no' +curl_cv_apple='no' +case $host in + *-*-android*) curl_cv_android='yes';; + *-apple-*) curl_cv_apple='yes';; +esac + +if test "$curl_cv_apple" = "yes"; then + CURL_DARWIN_CFLAGS + CURL_SUPPORTS_BUILTIN_AVAILABLE +fi AM_CONDITIONAL([HAVE_WINDRES], [test "$curl_cv_native_windows" = "yes" && test -n "${RC}"]) @@ -678,6 +754,32 @@ if test "$curl_cv_native_windows" = "yes"; then [AC_MSG_ERROR([windres not found in PATH. Windows builds require windres. Cannot continue.])]) fi +dnl ---------------------------------------- +dnl whether use "unity" mode for lib and src +dnl ---------------------------------------- + +want_unity='no' +AC_MSG_CHECKING([whether to build libcurl and curl in "unity" mode]) +AC_ARG_ENABLE(unity, +AS_HELP_STRING([--enable-unity],[Enable unity mode]) +AS_HELP_STRING([--disable-unity],[Disable unity (default)]), +[ case "$enableval" in + yes) + want_unity='yes' + AC_MSG_RESULT([yes]) + ;; + *) + AC_MSG_RESULT([no]) + ;; + esac ], + AC_MSG_RESULT([no]) +) +if test -z "$PERL" && test "$want_unity" = "yes"; then + AC_MSG_WARN([perl was not found. Cannot enable unity.]) + want_unity='no' +fi +AM_CONDITIONAL([USE_UNITY], [test "$want_unity" = "yes"]) + dnl ************************************************************ dnl switch off particular protocols dnl @@ -687,26 +789,29 @@ AS_HELP_STRING([--enable-http],[Enable HTTP support]) AS_HELP_STRING([--disable-http],[Disable HTTP support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_HTTP, 1, [to disable HTTP]) - disable_http="yes" - AC_MSG_WARN([disable HTTP disables FTP over proxy and RTSP]) - AC_SUBST(CURL_DISABLE_HTTP, [1]) - AC_DEFINE(CURL_DISABLE_RTSP, 1, [to disable RTSP]) - AC_SUBST(CURL_DISABLE_RTSP, [1]) - dnl toggle off alt-svc too when HTTP is disabled - AC_DEFINE(CURL_DISABLE_ALTSVC, 1, [disable alt-svc]) - AC_DEFINE(CURL_DISABLE_HSTS, 1, [disable HSTS]) - curl_h1_msg="no (--enable-http, --with-hyper)" - curl_altsvc_msg="no"; - curl_hsts_msg="no (--enable-hsts)"; - enable_altsvc="no" - hsts="no" - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_HTTP, 1, [to disable HTTP]) + disable_http="yes" + AC_MSG_WARN([disable HTTP disables FTP over proxy, IPFS and RTSP]) + CURL_DISABLE_HTTP=1 + AC_DEFINE(CURL_DISABLE_IPFS, 1, [to disable IPFS]) + CURL_DISABLE_IPFS=1 + AC_DEFINE(CURL_DISABLE_RTSP, 1, [to disable RTSP]) + CURL_DISABLE_RTSP=1 + dnl toggle off alt-svc too when HTTP is disabled + AC_DEFINE(CURL_DISABLE_ALTSVC, 1, [disable alt-svc]) + AC_DEFINE(CURL_DISABLE_HSTS, 1, [disable HSTS]) + curl_h1_msg="no (--enable-http)" + curl_altsvc_msg="no"; + curl_hsts_msg="no (--enable-hsts)"; + enable_altsvc="no" + hsts="no" + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) AC_MSG_CHECKING([whether to support ftp]) AC_ARG_ENABLE(ftp, @@ -714,14 +819,15 @@ AS_HELP_STRING([--enable-ftp],[Enable FTP support]) AS_HELP_STRING([--disable-ftp],[Disable FTP support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_FTP, 1, [to disable FTP]) - AC_SUBST(CURL_DISABLE_FTP, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_FTP, 1, [to disable FTP]) + CURL_DISABLE_FTP=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) AC_MSG_CHECKING([whether to support file]) AC_ARG_ENABLE(file, @@ -729,14 +835,41 @@ AS_HELP_STRING([--enable-file],[Enable FILE support]) AS_HELP_STRING([--disable-file],[Disable FILE support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_FILE, 1, [to disable FILE]) - AC_SUBST(CURL_DISABLE_FILE, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_FILE, 1, [to disable FILE]) + CURL_DISABLE_FILE=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) +) +AC_MSG_CHECKING([whether to support IPFS]) +AC_ARG_ENABLE(ipfs, +AS_HELP_STRING([--enable-ipfs],[Enable IPFS support]) +AS_HELP_STRING([--disable-ipfs],[Disable IPFS support]), +[ case "$enableval" in + no) + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_IPFS, 1, [to disable IPFS]) + CURL_DISABLE_IPFS=1 + ;; + *) + if test "$CURL_DISABLE_HTTP" = "1"; then + AC_MSG_ERROR(HTTP support needs to be enabled in order to enable IPFS support!) + else + AC_MSG_RESULT(yes) + curl_ipfs_msg="enabled" + fi + ;; + esac ], + if test "$CURL_DISABLE_HTTP" != "1"; then + AC_MSG_RESULT(yes) + curl_ipfs_msg="enabled" + else + AC_MSG_RESULT(no) + fi ) AC_MSG_CHECKING([whether to support ldap]) AC_ARG_ENABLE(ldap, @@ -744,19 +877,19 @@ AS_HELP_STRING([--enable-ldap],[Enable LDAP support]) AS_HELP_STRING([--disable-ldap],[Disable LDAP support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_LDAP, 1, [to disable LDAP]) - AC_SUBST(CURL_DISABLE_LDAP, [1]) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_LDAP, 1, [to disable LDAP]) + CURL_DISABLE_LDAP=1 + ;; yes) - ldap_askedfor="yes" - AC_MSG_RESULT(yes) - ;; + ldap_askedfor="yes" + AC_MSG_RESULT(yes) + ;; *) - AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(yes) + ;; esac ],[ - AC_MSG_RESULT(yes) ] + AC_MSG_RESULT(yes) ] ) AC_MSG_CHECKING([whether to support ldaps]) AC_ARG_ENABLE(ldaps, @@ -764,157 +897,59 @@ AS_HELP_STRING([--enable-ldaps],[Enable LDAPS support]) AS_HELP_STRING([--disable-ldaps],[Disable LDAPS support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) - AC_SUBST(CURL_DISABLE_LDAPS, [1]) - ;; - *) if test "x$CURL_DISABLE_LDAP" = "x1" ; then - AC_MSG_RESULT(LDAP needs to be enabled to support LDAPS) - AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) - AC_SUBST(CURL_DISABLE_LDAPS, [1]) - else - AC_MSG_RESULT(yes) - AC_DEFINE(HAVE_LDAP_SSL, 1, [Use LDAPS implementation]) - AC_SUBST(HAVE_LDAP_SSL, [1]) - fi - ;; - esac ],[ - if test "x$CURL_DISABLE_LDAP" = "x1" ; then - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) - AC_SUBST(CURL_DISABLE_LDAPS, [1]) - else - AC_MSG_RESULT(yes) - AC_DEFINE(HAVE_LDAP_SSL, 1, [Use LDAPS implementation]) - AC_SUBST(HAVE_LDAP_SSL, [1]) - fi ] -) - -dnl ********************************************************************** -dnl Check for Hyper -dnl ********************************************************************** - -OPT_HYPER="no" - -AC_ARG_WITH(hyper, -AS_HELP_STRING([--with-hyper=PATH],[Enable hyper usage]) -AS_HELP_STRING([--without-hyper],[Disable hyper usage]), - [OPT_HYPER=$withval]) -case "$OPT_HYPER" in - no) - dnl --without-hyper option used - want_hyper="no" - ;; - yes) - dnl --with-hyper option used without path - want_hyper="default" - want_hyper_path="" + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) + CURL_DISABLE_LDAPS=1 ;; *) - dnl --with-hyper option used with path - want_hyper="yes" - want_hyper_path="$withval" + if test "$CURL_DISABLE_LDAP" = "1"; then + AC_MSG_RESULT(LDAP needs to be enabled to support LDAPS) + AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) + CURL_DISABLE_LDAPS=1 + else + AC_MSG_RESULT(yes) + AC_DEFINE(HAVE_LDAP_SSL, 1, [Use LDAPS implementation]) + HAVE_LDAP_SSL=1 + fi ;; -esac + esac ],[ + if test "$CURL_DISABLE_LDAP" = "1"; then + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) + CURL_DISABLE_LDAPS=1 + else + AC_MSG_RESULT(yes) + AC_DEFINE(HAVE_LDAP_SSL, 1, [Use LDAPS implementation]) + HAVE_LDAP_SSL=1 + fi ] +) -if test X"$want_hyper" != Xno; then - if test "x$disable_http" = "xyes"; then - AC_MSG_ERROR([--with-hyper is not compatible with --disable-http]) - fi - - dnl backup the pre-hyper variables - CLEANLDFLAGS="$LDFLAGS" - CLEANCPPFLAGS="$CPPFLAGS" - CLEANLIBS="$LIBS" - - CURL_CHECK_PKGCONFIG(hyper, $want_hyper_path) - - if test "$PKGCONFIG" != "no" ; then - LIB_HYPER=`CURL_EXPORT_PCDIR([$want_hyper_path]) - $PKGCONFIG --libs-only-l hyper` - CPP_HYPER=`CURL_EXPORT_PCDIR([$want_hyper_path]) dnl - $PKGCONFIG --cflags-only-I hyper` - LD_HYPER=`CURL_EXPORT_PCDIR([$want_hyper_path]) - $PKGCONFIG --libs-only-L hyper` - else - dnl no hyper pkg-config found - LIB_HYPER="-lhyper -ldl -lpthread -lm" - if test X"$want_hyper" != Xdefault; then - CPP_HYPER=-I"$want_hyper_path/capi/include" - LD_HYPER="-L$want_hyper_path/target/release -L$want_hyper_path/target/debug" - fi - fi - if test -n "$LIB_HYPER"; then - AC_MSG_NOTICE([-l is $LIB_HYPER]) - AC_MSG_NOTICE([-I is $CPP_HYPER]) - AC_MSG_NOTICE([-L is $LD_HYPER]) - - LDFLAGS="$LDFLAGS $LD_HYPER" - CPPFLAGS="$CPPFLAGS $CPP_HYPER" - LIBS="$LIB_HYPER $LIBS" - - if test "x$cross_compiling" != "xyes"; then - dnl remove -L, separate with colon if more than one - DIR_HYPER=`echo $LD_HYPER | $SED -e 's/^-L//' -e 's/ -L/:/g'` - fi - - AC_CHECK_LIB(hyper, hyper_io_new, - [ - AC_CHECK_HEADERS(hyper.h, - experimental="$experimental Hyper" - AC_MSG_NOTICE([Hyper support is experimental]) - curl_h1_msg="enabled (Hyper)" - curl_h2_msg=$curl_h1_msg - HYPER_ENABLED=1 - AC_DEFINE(USE_HYPER, 1, [if hyper is in use]) - AC_SUBST(USE_HYPER, [1]) - CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_HYPER" - export CURL_LIBRARY_PATH - AC_MSG_NOTICE([Added $DIR_HYPER to CURL_LIBRARY_PATH]), - ) - ], - for d in `echo $DIR_HYPER | $SED -e 's/:/ /'`; do - if test -f "$d/libhyper.a"; then - AC_MSG_ERROR([hyper was found in $d but was probably built with wrong flags. See docs/HYPER.md.]) - fi - done - AC_MSG_ERROR([--with-hyper but hyper was not found. See docs/HYPER.md.]) - ) - fi -fi - -if test X"$want_hyper" != Xno; then - AC_MSG_NOTICE([Disable RTSP support with hyper]) - AC_DEFINE(CURL_DISABLE_RTSP, 1, [to disable RTSP]) - AC_SUBST(CURL_DISABLE_RTSP, [1]) -else - AC_MSG_CHECKING([whether to support rtsp]) - AC_ARG_ENABLE(rtsp, +AC_MSG_CHECKING([whether to support rtsp]) +AC_ARG_ENABLE(rtsp, AS_HELP_STRING([--enable-rtsp],[Enable RTSP support]) AS_HELP_STRING([--disable-rtsp],[Disable RTSP support]), - [ case "$enableval" in +[ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_RTSP, 1, [to disable RTSP]) - AC_SUBST(CURL_DISABLE_RTSP, [1]) - ;; - *) - if test x$CURL_DISABLE_HTTP = x1 ; then - AC_MSG_ERROR(HTTP support needs to be enabled in order to enable RTSP support!) - else - AC_MSG_RESULT(yes) - curl_rtsp_msg="enabled" - fi - ;; - esac ], - if test "x$CURL_DISABLE_HTTP" != "x1"; then - AC_MSG_RESULT(yes) - curl_rtsp_msg="enabled" - else - AC_MSG_RESULT(no) - fi - ) -fi + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_RTSP, 1, [to disable RTSP]) + CURL_DISABLE_RTSP=1 + ;; + *) + if test "$CURL_DISABLE_HTTP" = "1"; then + AC_MSG_ERROR(HTTP support needs to be enabled in order to enable RTSP support!) + else + AC_MSG_RESULT(yes) + curl_rtsp_msg="enabled" + fi + ;; + esac ], + if test "$CURL_DISABLE_HTTP" != "1"; then + AC_MSG_RESULT(yes) + curl_rtsp_msg="enabled" + else + AC_MSG_RESULT(no) + fi +) AC_MSG_CHECKING([whether to support proxies]) AC_ARG_ENABLE(proxy, @@ -922,15 +957,16 @@ AS_HELP_STRING([--enable-proxy],[Enable proxy support]) AS_HELP_STRING([--disable-proxy],[Disable proxy support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_PROXY, 1, [to disable proxies]) - AC_SUBST(CURL_DISABLE_PROXY, [1]) - https_proxy="no" - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_PROXY, 1, [to disable proxies]) + CURL_DISABLE_PROXY=1 + https_proxy="no" + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) AC_MSG_CHECKING([whether to support dict]) @@ -939,44 +975,54 @@ AS_HELP_STRING([--enable-dict],[Enable DICT support]) AS_HELP_STRING([--disable-dict],[Disable DICT support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_DICT, 1, [to disable DICT]) - AC_SUBST(CURL_DISABLE_DICT, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_DICT, 1, [to disable DICT]) + CURL_DISABLE_DICT=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) + AC_MSG_CHECKING([whether to support telnet]) AC_ARG_ENABLE(telnet, AS_HELP_STRING([--enable-telnet],[Enable TELNET support]) AS_HELP_STRING([--disable-telnet],[Disable TELNET support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_TELNET, 1, [to disable TELNET]) - AC_SUBST(CURL_DISABLE_TELNET, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_TELNET, 1, [to disable TELNET]) + CURL_DISABLE_TELNET=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) + +if test "$curl_cv_winuwp" = "yes"; then + AC_DEFINE(CURL_DISABLE_TELNET, 1, [to disable TELNET]) + CURL_DISABLE_TELNET=1 +fi + AC_MSG_CHECKING([whether to support tftp]) AC_ARG_ENABLE(tftp, AS_HELP_STRING([--enable-tftp],[Enable TFTP support]) AS_HELP_STRING([--disable-tftp],[Disable TFTP support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_TFTP, 1, [to disable TFTP]) - AC_SUBST(CURL_DISABLE_TFTP, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_TFTP, 1, [to disable TFTP]) + CURL_DISABLE_TFTP=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) AC_MSG_CHECKING([whether to support pop3]) @@ -985,48 +1031,49 @@ AS_HELP_STRING([--enable-pop3],[Enable POP3 support]) AS_HELP_STRING([--disable-pop3],[Disable POP3 support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_POP3, 1, [to disable POP3]) - AC_SUBST(CURL_DISABLE_POP3, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_POP3, 1, [to disable POP3]) + CURL_DISABLE_POP3=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) - AC_MSG_CHECKING([whether to support imap]) AC_ARG_ENABLE(imap, AS_HELP_STRING([--enable-imap],[Enable IMAP support]) AS_HELP_STRING([--disable-imap],[Disable IMAP support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_IMAP, 1, [to disable IMAP]) - AC_SUBST(CURL_DISABLE_IMAP, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_IMAP, 1, [to disable IMAP]) + CURL_DISABLE_IMAP=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) - AC_MSG_CHECKING([whether to support smb]) AC_ARG_ENABLE(smb, -AS_HELP_STRING([--enable-smb],[Enable SMB/CIFS support]) -AS_HELP_STRING([--disable-smb],[Disable SMB/CIFS support]), +AS_HELP_STRING([--enable-smb],[Enable SMB support]) +AS_HELP_STRING([--disable-smb],[Disable SMB support]), [ case "$enableval" in - no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_SMB, 1, [to disable SMB/CIFS]) - AC_SUBST(CURL_DISABLE_SMB, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + yes) + AC_MSG_RESULT(yes) + AC_DEFINE(CURL_ENABLE_SMB, 1, [to enable SMB]) + CURL_ENABLE_SMB=1 + ;; + *) + AC_MSG_RESULT(no) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(no) ) AC_MSG_CHECKING([whether to support smtp]) @@ -1035,14 +1082,15 @@ AS_HELP_STRING([--enable-smtp],[Enable SMTP support]) AS_HELP_STRING([--disable-smtp],[Disable SMTP support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_SMTP, 1, [to disable SMTP]) - AC_SUBST(CURL_DISABLE_SMTP, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_SMTP, 1, [to disable SMTP]) + CURL_DISABLE_SMTP=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) AC_MSG_CHECKING([whether to support gopher]) @@ -1051,14 +1099,15 @@ AS_HELP_STRING([--enable-gopher],[Enable Gopher support]) AS_HELP_STRING([--disable-gopher],[Disable Gopher support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_GOPHER, 1, [to disable Gopher]) - AC_SUBST(CURL_DISABLE_GOPHER, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_GOPHER, 1, [to disable Gopher]) + CURL_DISABLE_GOPHER=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) AC_MSG_CHECKING([whether to support mqtt]) @@ -1067,14 +1116,32 @@ AS_HELP_STRING([--enable-mqtt],[Enable MQTT support]) AS_HELP_STRING([--disable-mqtt],[Disable MQTT support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_MQTT, 1, [to disable MQTT]) - AC_SUBST(CURL_DISABLE_MQTT, [1]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_MQTT, 1, [to disable MQTT]) + CURL_DISABLE_MQTT=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(no) + AC_MSG_RESULT(no) +) + +AC_MSG_CHECKING([enable curl_global_init_mem debug build]) +AC_ARG_ENABLE(init-mem-debug, +AS_HELP_STRING([--enable-init-mem-debug],[curl_global_init_mem debug]) +AS_HELP_STRING([--disable-init-mem-debug],[]), +[ case "$enableval" in + yes) + AC_MSG_RESULT(yes) + AC_DEFINE(CURL_DEBUG_GLOBAL_MEM, 1, [curl_debug_global_mem debug build]) + SUPPORT_FEATURES="$SUPPORT_FEATURES global-mem-debug" + ;; + *) + AC_MSG_RESULT(no) + ;; + esac ], + AC_MSG_RESULT(no) ) dnl ********************************************************************** @@ -1087,18 +1154,48 @@ AS_HELP_STRING([--enable-manual],[Enable built-in manual]) AS_HELP_STRING([--disable-manual],[Disable built-in manual]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - ;; - *) AC_MSG_RESULT(yes) - USE_MANUAL="1" - ;; + AC_MSG_RESULT(no) + ;; + *) + AC_MSG_RESULT(yes) + USE_MANUAL="1" + ;; esac ], - AC_MSG_RESULT(yes) - USE_MANUAL="1" + AC_MSG_RESULT(yes) + USE_MANUAL="1" ) dnl The actual use of the USE_MANUAL variable is done much later in this dnl script to allow other actions to disable it as well. +dnl ********************************************************************** +dnl Check whether to build documentation +dnl ********************************************************************** + +AC_MSG_CHECKING([whether to build documentation]) +AC_ARG_ENABLE(docs, +AS_HELP_STRING([--enable-docs],[Enable documentation]) +AS_HELP_STRING([--disable-docs],[Disable documentation]), +[ case "$enableval" in + no) + AC_MSG_RESULT(no) + BUILD_DOCS=0 + dnl disable manual too because it needs built documentation + USE_MANUAL=0 + curl_docs_msg="no" + ;; + *) + AC_MSG_RESULT(yes) + BUILD_DOCS=1 + ;; + esac ], + AC_MSG_RESULT(yes) + BUILD_DOCS=1 +) +if test -z "$PERL" && test "$BUILD_DOCS" != "0"; then + AC_MSG_WARN([perl was not found. Cannot build documentation.]) + BUILD_DOCS=0 +fi + dnl ************************************************************ dnl disable C code generation support dnl @@ -1108,14 +1205,15 @@ AS_HELP_STRING([--enable-libcurl-option],[Enable --libcurl C code generation sup AS_HELP_STRING([--disable-libcurl-option],[Disable --libcurl C code generation support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_LIBCURL_OPTION, 1, [to disable --libcurl C code generation option]) - curl_libcurl_msg="no" - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_LIBCURL_OPTION, 1, [to disable --libcurl C code generation option]) + curl_libcurl_msg="no" + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ********************************************************************** @@ -1127,51 +1225,81 @@ AC_ARG_ENABLE(libgcc, AS_HELP_STRING([--enable-libgcc],[use libgcc when linking]), [ case "$enableval" in yes) - LIBS="-lgcc $LIBS" - AC_MSG_RESULT(yes) - ;; - *) AC_MSG_RESULT(no) - ;; + LIBS="-lgcc $LIBS" + AC_MSG_RESULT(yes) + ;; + *) + AC_MSG_RESULT(no) + ;; esac ], - AC_MSG_RESULT(no) + AC_MSG_RESULT(no) +) + +AC_MSG_CHECKING([whether to use libbacktrace]) +AC_ARG_WITH(backtrace, +AS_HELP_STRING([--enable-backtrace],[use libbacktrace when linking]), +[ case "$enableval" in + yes) + LIBS="-lbacktrace $LIBS" + AC_DEFINE(USE_BACKTRACE, 1, [if libbacktrace is in use]) + AC_MSG_RESULT(yes) + ;; + *) + AC_MSG_RESULT(no) + ;; + esac ], + AC_MSG_RESULT(no) ) CURL_CHECK_LIB_XNET dnl gethostbyname without lib or in the nsl lib? AC_CHECK_FUNC(gethostbyname, - [HAVE_GETHOSTBYNAME="1" - ], - [ AC_CHECK_LIB(nsl, gethostbyname, - [HAVE_GETHOSTBYNAME="1" - LIBS="-lnsl $LIBS" - ]) - ]) + [ + HAVE_GETHOSTBYNAME="1" + ], + [ + AC_CHECK_LIB(nsl, gethostbyname, + [ + HAVE_GETHOSTBYNAME="1" + LIBS="-lnsl $LIBS" + ] + ) + ] +) -if test "$HAVE_GETHOSTBYNAME" != "1" -then +if test "$HAVE_GETHOSTBYNAME" != "1"; then dnl gethostbyname in the socket lib? AC_CHECK_LIB(socket, gethostbyname, - [HAVE_GETHOSTBYNAME="1" - LIBS="-lsocket $LIBS" - ]) + [ + HAVE_GETHOSTBYNAME="1" + LIBS="-lsocket $LIBS" + ] + ) fi -if test "$HAVE_GETHOSTBYNAME" != "1" -then +if test "$HAVE_GETHOSTBYNAME" != "1"; then dnl gethostbyname in the watt lib? + clean_CPPFLAGS=$CPPFLAGS + clean_LDFLAGS=$LDFLAGS + CPPFLAGS="-I${WATT_ROOT}/inc" + LDFLAGS="-L${WATT_ROOT}/lib" AC_CHECK_LIB(watt, gethostbyname, - [HAVE_GETHOSTBYNAME="1" - CPPFLAGS="-I/dev/env/WATT_ROOT/inc" - LDFLAGS="-L/dev/env/WATT_ROOT/lib" - LIBS="-lwatt $LIBS" - ]) + [ + HAVE_GETHOSTBYNAME="1" + LIBS="-lwatt $LIBS" + AC_DEFINE(USE_WATT32, 1, [if Watt-32 is in use]) + ], + [ + CPPFLAGS=$clean_CPPFLAGS + LDFLAGS=$clean_LDFLAGS + ] + ) fi dnl At least one system has been identified to require BOTH nsl and socket dnl libs at the same time to link properly. -if test "$HAVE_GETHOSTBYNAME" != "1" -then +if test "$HAVE_GETHOSTBYNAME" != "1"; then AC_MSG_CHECKING([for gethostbyname with both nsl and socket libs]) my_ac_save_LIBS=$LIBS LIBS="-lnsl -lsocket $LIBS" @@ -1189,53 +1317,49 @@ then ]) fi -if test "$HAVE_GETHOSTBYNAME" != "1" -then - dnl This is for winsock systems - if test "$curl_cv_header_windows_h" = "yes"; then - if test "$curl_cv_header_winsock2_h" = "yes"; then - winsock_LIB="-lws2_32" - fi - if test ! -z "$winsock_LIB"; then - my_ac_save_LIBS=$LIBS - LIBS="$winsock_LIB $LIBS" - AC_MSG_CHECKING([for gethostbyname in $winsock_LIB]) - AC_LINK_IFELSE([ - AC_LANG_PROGRAM([[ -#ifdef HAVE_WINDOWS_H -#ifndef WIN32_LEAN_AND_MEAN -#define WIN32_LEAN_AND_MEAN -#endif -#include -#ifdef HAVE_WINSOCK2_H -#include -#endif -#endif - ]],[[ - gethostbyname("www.dummysite.com"); - ]]) - ],[ - AC_MSG_RESULT([yes]) - HAVE_GETHOSTBYNAME="1" - ],[ - AC_MSG_RESULT([no]) - winsock_LIB="" - LIBS=$my_ac_save_LIBS - ]) +dnl In UWP mode gethostbyname gets detected via the core libs, but some +dnl code (in6addr_any) still need ws2_32, so let us detect and add it. +if test "$HAVE_GETHOSTBYNAME" != "1" || test "$curl_cv_winuwp" = "yes"; then + if test "$curl_cv_native_windows" = "yes"; then + dnl This is for Winsock systems + winsock_LIB="-lws2_32" + if test "$curl_cv_winuwp" != "yes"; then + winsock_LIB="$winsock_LIB -liphlpapi" fi + my_ac_save_LIBS=$LIBS + LIBS="$winsock_LIB $LIBS" + AC_MSG_CHECKING([for gethostbyname in $winsock_LIB]) + AC_LINK_IFELSE([ + AC_LANG_PROGRAM([[ + #ifdef _WIN32 + #ifndef WIN32_LEAN_AND_MEAN + #define WIN32_LEAN_AND_MEAN + #endif + #include + #endif + ]],[[ + gethostbyname("localhost"); + ]]) + ],[ + AC_MSG_RESULT([yes]) + HAVE_GETHOSTBYNAME="1" + ],[ + AC_MSG_RESULT([no]) + winsock_LIB="" + LIBS=$my_ac_save_LIBS + ]) fi fi -if test "$HAVE_GETHOSTBYNAME" != "1" -then +if test "$HAVE_GETHOSTBYNAME" != "1"; then dnl This is for Minix 3.1 AC_MSG_CHECKING([for gethostbyname for Minix 3]) AC_LINK_IFELSE([ AC_LANG_PROGRAM([[ -/* Older Minix versions may need here instead */ -#include + /* Older Minix versions may need here instead */ + #include ]],[[ - gethostbyname("www.dummysite.com"); + gethostbyname("localhost"); ]]) ],[ AC_MSG_RESULT([yes]) @@ -1245,16 +1369,15 @@ then ]) fi -if test "$HAVE_GETHOSTBYNAME" != "1" -then +if test "$HAVE_GETHOSTBYNAME" != "1"; then dnl This is for eCos with a stubbed DNS implementation AC_MSG_CHECKING([for gethostbyname for eCos]) AC_LINK_IFELSE([ AC_LANG_PROGRAM([[ -#include -#include + #include + #include ]],[[ - gethostbyname("www.dummysite.com"); + gethostbyname("localhost"); ]]) ],[ AC_MSG_RESULT([yes]) @@ -1264,50 +1387,44 @@ then ]) fi -if test "$HAVE_GETHOSTBYNAME" != "1" -o "${with_amissl+set}" = set -then +if test "$HAVE_GETHOSTBYNAME" != "1" || test "${with_amissl+set}" = "set"; then dnl This is for AmigaOS with bsdsocket.library - needs testing before -lnet AC_MSG_CHECKING([for gethostbyname for AmigaOS bsdsocket.library]) AC_LINK_IFELSE([ AC_LANG_PROGRAM([[ - #define __USE_INLINE__ - #include - #ifdef __amigaos4__ - struct SocketIFace *ISocket = NULL; - #else - struct Library *SocketBase = NULL; - #endif + #define __USE_INLINE__ + #include + #ifdef __amigaos4__ + struct SocketIFace *ISocket = NULL; + #else + struct Library *SocketBase = NULL; + #endif ]],[[ - gethostbyname("www.dummysite.com"); + unsigned char host[] = "localhost"; + gethostbyname(host); ]]) ],[ AC_MSG_RESULT([yes]) HAVE_GETHOSTBYNAME="1" HAVE_PROTO_BSDSOCKET_H="1" AC_DEFINE(HAVE_PROTO_BSDSOCKET_H, 1, [if Amiga bsdsocket.library is in use]) - AC_SUBST(HAVE_PROTO_BSDSOCKET_H, [1]) ],[ AC_MSG_RESULT([no]) ]) fi -if test "$HAVE_GETHOSTBYNAME" != "1" -then +if test "$HAVE_GETHOSTBYNAME" != "1"; then dnl gethostbyname in the network lib - for Haiku OS AC_CHECK_LIB(network, gethostbyname, - [HAVE_GETHOSTBYNAME="1" - LIBS="-lnetwork $LIBS" - ]) -fi - -if test "$HAVE_GETHOSTBYNAME" != "1"; then - AC_MSG_ERROR([couldn't find libraries for gethostbyname()]) + [ + HAVE_GETHOSTBYNAME="1" + LIBS="-lnetwork $LIBS" + ] + ) fi CURL_CHECK_LIBS_CONNECT -CURL_NETWORK_LIBS=$LIBS - dnl ********************************************************************** dnl In case that function clock_gettime with monotonic timer is available, dnl check for additional required libraries. @@ -1338,19 +1455,19 @@ ZLIB_LIBS="" AC_ARG_WITH(zlib, AS_HELP_STRING([--with-zlib=PATH],[search for zlib in PATH]) AS_HELP_STRING([--without-zlib],[disable use of zlib]), - [OPT_ZLIB="$withval"]) + [OPT_ZLIB="$withval"]) -if test "$OPT_ZLIB" = "no" ; then - AC_MSG_WARN([zlib disabled]) +if test "x$OPT_ZLIB" = "xno"; then + AC_MSG_WARN([zlib disabled]) else - if test "$OPT_ZLIB" = "yes" ; then + if test "x$OPT_ZLIB" = "xyes"; then OPT_ZLIB="" fi - if test -z "$OPT_ZLIB" ; then + if test -z "$OPT_ZLIB"; then CURL_CHECK_PKGCONFIG(zlib) - if test "$PKGCONFIG" != "no" ; then + if test "$PKGCONFIG" != "no"; then ZLIB_LIBS="`$PKGCONFIG --libs-only-l zlib`" if test -n "$ZLIB_LIBS"; then LDFLAGS="$LDFLAGS `$PKGCONFIG --libs-only-L zlib`" @@ -1369,37 +1486,45 @@ else dnl people have it in the default path AC_CHECK_LIB(z, inflateEnd, - dnl libz found, set the variable - [HAVE_LIBZ="1" - ZLIB_LIBS="-lz" - LIBS="$ZLIB_LIBS $LIBS"], - dnl if no lib found, try /usr/local - [OPT_ZLIB="/usr/local"]) + dnl libz found, set the variable + [ + HAVE_LIBZ="1" + ZLIB_LIBS="-lz" + LIBS="$ZLIB_LIBS $LIBS" + ], + dnl if no lib found, try /usr/local + [ + OPT_ZLIB="/usr/local" + ] + ) fi fi dnl Add a nonempty path to the compiler flags if test -n "$OPT_ZLIB"; then - CPPFLAGS="$CPPFLAGS -I$OPT_ZLIB/include" - LDFLAGS="$LDFLAGS -L$OPT_ZLIB/lib$libsuff" + CPPFLAGS="$CPPFLAGS -I$OPT_ZLIB/include" + LDFLAGS="$LDFLAGS -L$OPT_ZLIB/lib$libsuff" fi AC_CHECK_HEADER(zlib.h, [ - dnl zlib.h was found - HAVE_ZLIB_H="1" - dnl if the lib wasn't found already, try again with the new paths - if test "$HAVE_LIBZ" != "1"; then - AC_CHECK_LIB(z, gzread, - [ - dnl the lib was found! - HAVE_LIBZ="1" - ZLIB_LIBS="-lz" - LIBS="$ZLIB_LIBS $LIBS" - ], - [ CPPFLAGS=$clean_CPPFLAGS - LDFLAGS=$clean_LDFLAGS]) - fi + dnl zlib.h was found + HAVE_ZLIB_H="1" + dnl if the lib was not found already, try again with the new paths + if test "$HAVE_LIBZ" != "1"; then + AC_CHECK_LIB(z, gzread, + [ + dnl the lib was found! + HAVE_LIBZ="1" + ZLIB_LIBS="-lz" + LIBS="$ZLIB_LIBS $LIBS" + ], + [ + CPPFLAGS=$clean_CPPFLAGS + LDFLAGS=$clean_LDFLAGS + ] + ) + fi ], [ dnl zlib.h was not found, restore the flags @@ -1407,23 +1532,20 @@ else LDFLAGS=$clean_LDFLAGS] ) - if test "$HAVE_LIBZ" = "1" && test "$HAVE_ZLIB_H" != "1" - then + if test "$HAVE_LIBZ" = "1" && test "$HAVE_ZLIB_H" != "1"; then AC_MSG_WARN([configure found only the libz lib, not the header file!]) HAVE_LIBZ="" CPPFLAGS=$clean_CPPFLAGS LDFLAGS=$clean_LDFLAGS LIBS=$clean_LIBS ZLIB_LIBS="" - elif test "$HAVE_LIBZ" != "1" && test "$HAVE_ZLIB_H" = "1" - then + elif test "$HAVE_LIBZ" != "1" && test "$HAVE_ZLIB_H" = "1"; then AC_MSG_WARN([configure found only the libz header file, not the lib!]) CPPFLAGS=$clean_CPPFLAGS LDFLAGS=$clean_LDFLAGS LIBS=$clean_LIBS ZLIB_LIBS="" - elif test "$HAVE_LIBZ" = "1" && test "$HAVE_ZLIB_H" = "1" - then + elif test "$HAVE_LIBZ" = "1" && test "$HAVE_ZLIB_H" = "1"; then dnl both header and lib were found! AC_SUBST(HAVE_LIBZ) AC_DEFINE(HAVE_LIBZ, 1, [if zlib is available]) @@ -1432,12 +1554,16 @@ else dnl replace 'HAVE_LIBZ' in the automake makefile.ams AMFIXLIB="1" AC_MSG_NOTICE([found both libz and libz.h header]) + dnl Android does not provide zlib.pc + if test "$curl_cv_android" = "no"; then + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE zlib" + fi curl_zlib_msg="enabled" fi fi dnl set variable for use in automakefile(s) -AM_CONDITIONAL(HAVE_LIBZ, test x"$AMFIXLIB" = x1) +AM_CONDITIONAL(HAVE_LIBZ, test "$AMFIXLIB" = "1") AC_SUBST(ZLIB_LIBS) dnl ********************************************************************** @@ -1448,49 +1574,60 @@ dnl Brotli project home page: https://github.com/google/brotli dnl Default to compiler & linker defaults for BROTLI files & libraries. OPT_BROTLI=off -AC_ARG_WITH(brotli,dnl -AS_HELP_STRING([--with-brotli=PATH],[Where to look for brotli, PATH points to the BROTLI installation; when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) +AC_ARG_WITH(brotli, +AS_HELP_STRING([--with-brotli=PATH],[Where to look for brotli, PATH points to the BROTLI installation; + when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) AS_HELP_STRING([--without-brotli], [disable BROTLI]), OPT_BROTLI=$withval) -if test X"$OPT_BROTLI" != Xno; then +if test "x$OPT_BROTLI" != "xno"; then dnl backup the pre-brotli variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" case "$OPT_BROTLI" in - yes) - dnl --with-brotli (without path) used - CURL_CHECK_PKGCONFIG(libbrotlidec) + yes) + dnl --with-brotli (without path) used + CURL_CHECK_PKGCONFIG(libbrotlidec) + + if test "$PKGCONFIG" != "no"; then + LIB_BROTLI=`$PKGCONFIG --libs-only-l libbrotlidec` + LD_BROTLI=`$PKGCONFIG --libs-only-L libbrotlidec` + CPP_BROTLI=`$PKGCONFIG --cflags-only-I libbrotlidec` + version=`$PKGCONFIG --modversion libbrotlidec` + fi + + CURL_CHECK_PKGCONFIG(libbrotlicommon) + + if test "$PKGCONFIG" != "no"; then + LIB_BROTLI="$LIB_BROTLI `$PKGCONFIG --libs-only-l libbrotlicommon`" + LD_BROTLI="$LD_BROTLI `$PKGCONFIG --libs-only-L libbrotlicommon`" + CPP_BROTLI="$CPP_BROTLI `$PKGCONFIG --cflags-only-I libbrotlicommon`" + fi - if test "$PKGCONFIG" != "no" ; then - LIB_BROTLI=`$PKGCONFIG --libs-only-l libbrotlidec` - LD_BROTLI=`$PKGCONFIG --libs-only-L libbrotlidec` - CPP_BROTLI=`$PKGCONFIG --cflags-only-I libbrotlidec` - version=`$PKGCONFIG --modversion libbrotlidec` DIR_BROTLI=`echo $LD_BROTLI | $SED -e 's/^-L//'` - fi - - ;; - off) - dnl no --with-brotli option given, just check default places - ;; - *) - dnl use the given --with-brotli spot - PREFIX_BROTLI=$OPT_BROTLI - ;; + ;; + off) + dnl no --with-brotli option given, check default places + ;; + *) + dnl use the given --with-brotli spot + PREFIX_BROTLI=$OPT_BROTLI + ;; esac dnl if given with a prefix, we set -L and -I based on that if test -n "$PREFIX_BROTLI"; then - LIB_BROTLI="-lbrotlidec" + LIB_BROTLI="-lbrotlidec -lbrotlicommon" LD_BROTLI=-L${PREFIX_BROTLI}/lib$libsuff CPP_BROTLI=-I${PREFIX_BROTLI}/include DIR_BROTLI=${PREFIX_BROTLI}/lib$libsuff fi LDFLAGS="$LDFLAGS $LD_BROTLI" + LDFLAGSPC="$LDFLAGSPC $LD_BROTLI" CPPFLAGS="$CPPFLAGS $CPP_BROTLI" LIBS="$LIB_BROTLI $LIBS" @@ -1500,29 +1637,30 @@ if test X"$OPT_BROTLI" != Xno; then curl_brotli_msg="enabled (libbrotlidec)" HAVE_BROTLI=1 AC_DEFINE(HAVE_BROTLI, 1, [if BROTLI is in use]) - AC_SUBST(HAVE_BROTLI, [1]) ) - if test X"$OPT_BROTLI" != Xoff && + if test "x$OPT_BROTLI" != "xoff" && test "$HAVE_BROTLI" != "1"; then AC_MSG_ERROR([BROTLI libs and/or directories were not found where specified!]) fi if test "$HAVE_BROTLI" = "1"; then if test -n "$DIR_BROTLI"; then - dnl when the brotli shared libs were found in a path that the run-time - dnl linker doesn't search through, we need to add it to CURL_LIBRARY_PATH - dnl to prevent further configure tests to fail due to this + dnl when the brotli shared libs were found in a path that the runtime + dnl linker does not search through, we need to add it to CURL_LIBRARY_PATH + dnl to prevent further configure tests to fail due to this - if test "x$cross_compiling" != "xyes"; then - CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_BROTLI" - export CURL_LIBRARY_PATH - AC_MSG_NOTICE([Added $DIR_BROTLI to CURL_LIBRARY_PATH]) - fi + if test "$cross_compiling" != "yes"; then + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_BROTLI" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_BROTLI to CURL_LIBRARY_PATH]) + fi fi + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libbrotlidec libbrotlicommon" else dnl no brotli, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS fi @@ -1534,38 +1672,40 @@ dnl ********************************************************************** dnl Default to compiler & linker defaults for libzstd OPT_ZSTD=off -AC_ARG_WITH(zstd,dnl -AS_HELP_STRING([--with-zstd=PATH],[Where to look for libzstd, PATH points to the libzstd installation; when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) +AC_ARG_WITH(zstd, +AS_HELP_STRING([--with-zstd=PATH],[Where to look for libzstd, PATH points to the libzstd installation; + when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) AS_HELP_STRING([--without-zstd], [disable libzstd]), OPT_ZSTD=$withval) -if test X"$OPT_ZSTD" != Xno; then +if test "x$OPT_ZSTD" != "xno"; then dnl backup the pre-zstd variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" case "$OPT_ZSTD" in - yes) - dnl --with-zstd (without path) used - CURL_CHECK_PKGCONFIG(libzstd) + yes) + dnl --with-zstd (without path) used + CURL_CHECK_PKGCONFIG(libzstd) - if test "$PKGCONFIG" != "no" ; then - LIB_ZSTD=`$PKGCONFIG --libs-only-l libzstd` - LD_ZSTD=`$PKGCONFIG --libs-only-L libzstd` - CPP_ZSTD=`$PKGCONFIG --cflags-only-I libzstd` - version=`$PKGCONFIG --modversion libzstd` - DIR_ZSTD=`echo $LD_ZSTD | $SED -e 's/-L//'` - fi + if test "$PKGCONFIG" != "no"; then + LIB_ZSTD=`$PKGCONFIG --libs-only-l libzstd` + LD_ZSTD=`$PKGCONFIG --libs-only-L libzstd` + CPP_ZSTD=`$PKGCONFIG --cflags-only-I libzstd` + version=`$PKGCONFIG --modversion libzstd` + DIR_ZSTD=`echo $LD_ZSTD | $SED -e 's/-L//'` + fi - ;; - off) - dnl no --with-zstd option given, just check default places - ;; - *) - dnl use the given --with-zstd spot - PREFIX_ZSTD=$OPT_ZSTD - ;; + ;; + off) + dnl no --with-zstd option given, check default places + ;; + *) + dnl use the given --with-zstd spot + PREFIX_ZSTD=$OPT_ZSTD + ;; esac dnl if given with a prefix, we set -L and -I based on that @@ -1577,6 +1717,7 @@ if test X"$OPT_ZSTD" != Xno; then fi LDFLAGS="$LDFLAGS $LD_ZSTD" + LDFLAGSPC="$LDFLAGSPC $LD_ZSTD" CPPFLAGS="$CPPFLAGS $CPP_ZSTD" LIBS="$LIB_ZSTD $LIBS" @@ -1586,129 +1727,36 @@ if test X"$OPT_ZSTD" != Xno; then curl_zstd_msg="enabled (libzstd)" HAVE_ZSTD=1 AC_DEFINE(HAVE_ZSTD, 1, [if libzstd is in use]) - AC_SUBST(HAVE_ZSTD, [1]) ) - if test X"$OPT_ZSTD" != Xoff && + if test "x$OPT_ZSTD" != "xoff" && test "$HAVE_ZSTD" != "1"; then AC_MSG_ERROR([libzstd was not found where specified!]) fi if test "$HAVE_ZSTD" = "1"; then if test -n "$DIR_ZSTD"; then - dnl when the zstd shared lib were found in a path that the run-time - dnl linker doesn't search through, we need to add it to - dnl CURL_LIBRARY_PATH to prevent further configure tests to fail due to - dnl this + dnl when the zstd shared lib were found in a path that the runtime + dnl linker does not search through, we need to add it to + dnl CURL_LIBRARY_PATH to prevent further configure tests to fail due to + dnl this - if test "x$cross_compiling" != "xyes"; then - CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_ZSTD" - export CURL_LIBRARY_PATH - AC_MSG_NOTICE([Added $DIR_ZSTD to CURL_LIBRARY_PATH]) - fi + if test "$cross_compiling" != "yes"; then + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_ZSTD" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_ZSTD to CURL_LIBRARY_PATH]) + fi fi + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libzstd" else dnl no zstd, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS fi fi -dnl ********************************************************************** -dnl Check for LDAP -dnl ********************************************************************** - -LDAPLIBNAME="" -AC_ARG_WITH(ldap-lib, -AS_HELP_STRING([--with-ldap-lib=libname],[Specify name of ldap lib file]), - [LDAPLIBNAME="$withval"]) - -LBERLIBNAME="" -AC_ARG_WITH(lber-lib, -AS_HELP_STRING([--with-lber-lib=libname],[Specify name of lber lib file]), - [LBERLIBNAME="$withval"]) - -if test x$CURL_DISABLE_LDAP != x1 ; then - - CURL_CHECK_HEADER_LBER - CURL_CHECK_HEADER_LDAP - CURL_CHECK_HEADER_LDAP_SSL - - if test -z "$LDAPLIBNAME" ; then - if test "$curl_cv_native_windows" = "yes"; then - dnl Windows uses a single and unique LDAP library name - LDAPLIBNAME="wldap32" - LBERLIBNAME="no" - fi - fi - - if test "$LDAPLIBNAME" ; then - AC_CHECK_LIB("$LDAPLIBNAME", ldap_init,, [ - if test -n "$ldap_askedfor"; then - AC_MSG_ERROR([couldn't detect the LDAP libraries]) - fi - AC_MSG_WARN(["$LDAPLIBNAME" is not an LDAP library: LDAP disabled]) - AC_DEFINE(CURL_DISABLE_LDAP, 1, [to disable LDAP]) - AC_SUBST(CURL_DISABLE_LDAP, [1]) - AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) - AC_SUBST(CURL_DISABLE_LDAPS, [1])]) - else - dnl Try to find the right ldap libraries for this system - CURL_CHECK_LIBS_LDAP - case X-"$curl_cv_ldap_LIBS" in - X-unknown) - if test -n "$ldap_askedfor"; then - AC_MSG_ERROR([couldn't detect the LDAP libraries]) - fi - AC_MSG_WARN([Cannot find libraries for LDAP support: LDAP disabled]) - AC_DEFINE(CURL_DISABLE_LDAP, 1, [to disable LDAP]) - AC_SUBST(CURL_DISABLE_LDAP, [1]) - AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) - AC_SUBST(CURL_DISABLE_LDAPS, [1]) - ;; - esac - fi -fi - -if test x$CURL_DISABLE_LDAP != x1 ; then - - if test "$LBERLIBNAME" ; then - dnl If name is "no" then don't define this library at all - dnl (it's only needed if libldap.so's dependencies are broken). - if test "$LBERLIBNAME" != "no" ; then - AC_CHECK_LIB("$LBERLIBNAME", ber_free,, [ - AC_MSG_WARN(["$LBERLIBNAME" is not an LBER library: LDAP disabled]) - AC_DEFINE(CURL_DISABLE_LDAP, 1, [to disable LDAP]) - AC_SUBST(CURL_DISABLE_LDAP, [1]) - AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) - AC_SUBST(CURL_DISABLE_LDAPS, [1])]) - fi - fi -fi - -if test x$CURL_DISABLE_LDAP != x1 ; then - AC_CHECK_FUNCS([ldap_url_parse \ - ldap_init_fd]) - - if test "$LDAPLIBNAME" = "wldap32"; then - curl_ldap_msg="enabled (winldap)" - AC_DEFINE(USE_WIN32_LDAP, 1, [Use Windows LDAP implementation]) - else - if test "x$ac_cv_func_ldap_init_fd" = "xyes"; then - curl_ldap_msg="enabled (OpenLDAP)" - AC_DEFINE(USE_OPENLDAP, 1, [Use OpenLDAP-specific code]) - AC_SUBST(USE_OPENLDAP, [1]) - else - curl_ldap_msg="enabled (ancient OpenLDAP)" - fi - fi -fi - -if test x$CURL_DISABLE_LDAPS != x1 ; then - curl_ldaps_msg="enabled" -fi - dnl ********************************************************************** dnl Checks for IPv6 dnl ********************************************************************** @@ -1719,74 +1767,73 @@ AS_HELP_STRING([--enable-ipv6],[Enable IPv6 (with IPv4) support]) AS_HELP_STRING([--disable-ipv6],[Disable IPv6 support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - ipv6=no - ;; - *) AC_MSG_RESULT(yes) - ipv6=yes - ;; + AC_MSG_RESULT(no) + ipv6=no + ;; + *) + AC_MSG_RESULT(yes) + ipv6=yes + ;; esac ], - AC_RUN_IFELSE([AC_LANG_SOURCE([[ -/* are AF_INET6 and sockaddr_in6 available? */ -#include -#ifdef HAVE_WINSOCK2_H -#include -#include -#else -#include -#include -#if defined (__TANDEM) -# include -#endif -#endif -#include /* for exit() */ -main() -{ - struct sockaddr_in6 s; - (void)s; - if (socket(AF_INET6, SOCK_STREAM, 0) < 0) - exit(1); - else - exit(0); -} -]]) -], - AC_MSG_RESULT(yes) - ipv6=yes, - AC_MSG_RESULT(no) - ipv6=no, - AC_MSG_RESULT(yes) - ipv6=yes -)) + AC_COMPILE_IFELSE([ + AC_LANG_SOURCE([[ + /* are AF_INET6 and sockaddr_in6 available? */ + #include + #ifdef _WIN32 + #include + #include + #else + #include + #include + #ifdef __TANDEM + #include + #endif + #endif + int main(void) + { + int s = (int)sizeof(struct sockaddr_in6); + (void)s; + return socket(AF_INET6, SOCK_STREAM, 0) > 0; + } + ]]) + ], + AC_MSG_RESULT(yes) + ipv6=yes, + AC_MSG_RESULT(no) + ipv6=no + ) +) -if test "$ipv6" = yes; then +if test "$ipv6" = "yes"; then curl_ipv6_msg="enabled" - AC_DEFINE(ENABLE_IPV6, 1, [Define if you want to enable IPv6 support]) + AC_DEFINE(USE_IPV6, 1, [Define if you want to enable IPv6 support]) IPV6_ENABLED=1 - AC_SUBST(IPV6_ENABLED) AC_MSG_CHECKING([if struct sockaddr_in6 has sin6_scope_id member]) - AC_COMPILE_IFELSE([ AC_LANG_PROGRAM([[ -#include -#ifdef HAVE_WINSOCK2_H -#include -#include -#else -#include -#if defined (__TANDEM) -# include -#endif -#endif -]], [[ - struct sockaddr_in6 s; - s.sin6_scope_id = 0; -]])], [ - AC_MSG_RESULT([yes]) - AC_DEFINE(HAVE_SOCKADDR_IN6_SIN6_SCOPE_ID, 1, [Define to 1 if struct sockaddr_in6 has the sin6_scope_id member]) - ], [ + AC_COMPILE_IFELSE([ + AC_LANG_PROGRAM([[ + #include + #ifdef _WIN32 + #include + #include + #else + #include + #ifdef __TANDEM + #include + #endif + #endif + ]], [[ + struct sockaddr_in6 s; + s.sin6_scope_id = 0; + (void)s; + ]]) + ],[ + AC_MSG_RESULT([yes]) + AC_DEFINE(HAVE_SOCKADDR_IN6_SIN6_SCOPE_ID, 1, [Define to 1 if struct sockaddr_in6 has the sin6_scope_id member]) + ],[ AC_MSG_RESULT([no]) - ]) + ]) fi dnl ********************************************************************** @@ -1799,14 +1846,14 @@ int main(int argc, char **argv) { #ifdef _WIN32 /* on Windows, writing to the argv does not hide the argument in - process lists so it can just be skipped */ + process lists so it can be skipped */ (void)argc; (void)argv; return 1; #else (void)argc; argv[0][0] = ' '; - return (argv[0][0] == ' ')?0:1; + return (argv[0][0] == ' ') ? 0 : 1; #endif } ]],[ @@ -1816,18 +1863,21 @@ int main(int argc, char **argv) ],[ curl_cv_writable_argv=cross ]) +if test "$curl_cv_writable_argv" = "cross" && test "$curl_cv_apple" = "yes"; then + curl_cv_writable_argv=yes +fi case $curl_cv_writable_argv in -yes) - AC_DEFINE(HAVE_WRITABLE_ARGV, 1, [Define this symbol if your OS supports changing the contents of argv]) - AC_MSG_RESULT(yes) - ;; -no) - AC_MSG_RESULT(no) - ;; -*) - AC_MSG_RESULT(no) - AC_MSG_WARN([the previous check could not be made default was used]) - ;; + yes) + AC_DEFINE(HAVE_WRITABLE_ARGV, 1, [Define this symbol if your OS supports changing the contents of argv]) + AC_MSG_RESULT(yes) + ;; + no) + AC_MSG_RESULT(no) + ;; + *) + AC_MSG_RESULT(no) + AC_MSG_WARN([the previous check could not be made default was used]) + ;; esac dnl ********************************************************************** @@ -1838,54 +1888,54 @@ dnl check for GSS-API stuff in the /usr as default GSSAPI_ROOT="/usr" AC_ARG_WITH(gssapi-includes, - AS_HELP_STRING([--with-gssapi-includes=DIR], - [Specify location of GSS-API headers]), - [ GSSAPI_INCS="-I$withval" - want_gss="yes" ] + AS_HELP_STRING([--with-gssapi-includes=DIR], [Specify location of GSS-API headers]), [ + GSSAPI_INCS="-I$withval" + want_gss="yes" + ] ) AC_ARG_WITH(gssapi-libs, - AS_HELP_STRING([--with-gssapi-libs=DIR], - [Specify location of GSS-API libs]), - [ GSSAPI_LIB_DIR="-L$withval" - want_gss="yes" ] + AS_HELP_STRING([--with-gssapi-libs=DIR], [Specify location of GSS-API libs]), [ + GSSAPI_LIB_DIR="-L$withval" + want_gss="yes" + ] ) AC_ARG_WITH(gssapi, - AS_HELP_STRING([--with-gssapi=DIR], - [Where to look for GSS-API]), [ - GSSAPI_ROOT="$withval" - if test x"$GSSAPI_ROOT" != xno; then - want_gss="yes" - if test x"$GSSAPI_ROOT" = xyes; then - dnl if yes, then use default root - GSSAPI_ROOT="/usr" + AS_HELP_STRING([--with-gssapi=DIR], [Where to look for GSS-API]), [ + GSSAPI_ROOT="$withval" + if test "$GSSAPI_ROOT" != "no"; then + want_gss="yes" + if test "$GSSAPI_ROOT" = "yes"; then + dnl if yes, then use default root + GSSAPI_ROOT="/usr" + fi fi - fi -]) + ] +) : ${KRB5CONFIG:="$GSSAPI_ROOT/bin/krb5-config"} save_CPPFLAGS="$CPPFLAGS" AC_MSG_CHECKING([if GSS-API support is requested]) -if test x"$want_gss" = xyes; then +if test "$want_gss" = "yes"; then AC_MSG_RESULT(yes) - if test $GSSAPI_ROOT != "/usr"; then + if test "$GSSAPI_ROOT" != "/usr"; then CURL_CHECK_PKGCONFIG(mit-krb5-gssapi, $GSSAPI_ROOT/lib/pkgconfig) else CURL_CHECK_PKGCONFIG(mit-krb5-gssapi) fi if test -z "$GSSAPI_INCS"; then - if test -n "$host_alias" -a -f "$GSSAPI_ROOT/bin/$host_alias-krb5-config"; then - GSSAPI_INCS=`$GSSAPI_ROOT/bin/$host_alias-krb5-config --cflags gssapi` - elif test "$PKGCONFIG" != "no" ; then - GSSAPI_INCS=`$PKGCONFIG --cflags mit-krb5-gssapi` - elif test -f "$KRB5CONFIG"; then - GSSAPI_INCS=`$KRB5CONFIG --cflags gssapi` - elif test "$GSSAPI_ROOT" != "yes"; then - GSSAPI_INCS="-I$GSSAPI_ROOT/include" - fi + if test -n "$host_alias" && test -f "$GSSAPI_ROOT/bin/$host_alias-krb5-config"; then + GSSAPI_INCS=`$GSSAPI_ROOT/bin/$host_alias-krb5-config --cflags gssapi` + elif test "$PKGCONFIG" != "no"; then + GSSAPI_INCS=`$PKGCONFIG --cflags mit-krb5-gssapi` + elif test -f "$KRB5CONFIG"; then + GSSAPI_INCS=`$KRB5CONFIG --cflags gssapi` + elif test "$GSSAPI_ROOT" != "yes"; then + GSSAPI_INCS="-I$GSSAPI_ROOT/include" + fi fi CPPFLAGS="$CPPFLAGS $GSSAPI_INCS" @@ -1897,129 +1947,111 @@ if test x"$want_gss" = xyes; then gnu_gss=yes ], [ - dnl not found, check Heimdal or MIT - AC_CHECK_HEADERS([gssapi/gssapi.h], [], [not_mit=1]) + dnl not found, check for MIT AC_CHECK_HEADERS( - [gssapi/gssapi_generic.h gssapi/gssapi_krb5.h], + [gssapi/gssapi.h gssapi/gssapi_generic.h gssapi/gssapi_krb5.h], [], - [not_mit=1], - [ -AC_INCLUDES_DEFAULT -#ifdef HAVE_GSSAPI_GSSAPI_H -#include -#endif - ]) - if test "x$not_mit" = "x1"; then - dnl MIT not found, check for Heimdal - AC_CHECK_HEADER(gssapi.h, - [ - dnl found - AC_DEFINE(HAVE_GSSHEIMDAL, 1, [if you have Heimdal]) - ], - [ - dnl no header found, disabling GSS - want_gss=no - AC_MSG_WARN(disabling GSS-API support since no header files were found) - ] - ) - else - dnl MIT found - AC_DEFINE(HAVE_GSSMIT, 1, [if you have MIT Kerberos]) - dnl check if we have a really old MIT Kerberos version (<= 1.2) - AC_MSG_CHECKING([if GSS-API headers declare GSS_C_NT_HOSTBASED_SERVICE]) - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ -#include -#include -#include - ]],[[ - gss_import_name( - (OM_uint32 *)0, - (gss_buffer_t)0, - GSS_C_NT_HOSTBASED_SERVICE, - (gss_name_t *)0); - ]]) - ],[ - AC_MSG_RESULT([yes]) - ],[ - AC_MSG_RESULT([no]) - AC_DEFINE(HAVE_OLD_GSSMIT, 1, - [if you have an old MIT Kerberos version, lacking GSS_C_NT_HOSTBASED_SERVICE]) - ]) + [not_mit=1]) + if test "$not_mit" = "1"; then + dnl MIT not found + AC_MSG_ERROR([MIT or GNU GSS library required, but not found]) fi ] ) else AC_MSG_RESULT(no) fi -if test x"$want_gss" = xyes; then +if test "$want_gss" = "yes"; then AC_DEFINE(HAVE_GSSAPI, 1, [if you have GSS-API libraries]) HAVE_GSSAPI=1 - curl_gss_msg="enabled (MIT Kerberos/Heimdal)" + curl_gss_msg="enabled (MIT Kerberos)" + link_pkgconfig='' if test -n "$gnu_gss"; then curl_gss_msg="enabled (GNU GSS)" LDFLAGS="$LDFLAGS $GSSAPI_LIB_DIR" + LDFLAGSPC="$LDFLAGSPC $GSSAPI_LIB_DIR" LIBS="-lgss $LIBS" + link_pkgconfig=1 elif test -z "$GSSAPI_LIB_DIR"; then - case $host in - *-*-darwin*) - LIBS="-lgssapi_krb5 -lresolv $LIBS" - ;; - *) - if test $GSSAPI_ROOT != "/usr"; then - CURL_CHECK_PKGCONFIG(mit-krb5-gssapi, $GSSAPI_ROOT/lib/pkgconfig) - else - CURL_CHECK_PKGCONFIG(mit-krb5-gssapi) - fi - if test -n "$host_alias" -a -f "$GSSAPI_ROOT/bin/$host_alias-krb5-config"; then - dnl krb5-config doesn't have --libs-only-L or similar, put everything - dnl into LIBS - gss_libs=`$GSSAPI_ROOT/bin/$host_alias-krb5-config --libs gssapi` - LIBS="$gss_libs $LIBS" - elif test "$PKGCONFIG" != "no" ; then - gss_libs=`$PKGCONFIG --libs mit-krb5-gssapi` - LIBS="$gss_libs $LIBS" - elif test -f "$KRB5CONFIG"; then - dnl krb5-config doesn't have --libs-only-L or similar, put everything - dnl into LIBS - gss_libs=`$KRB5CONFIG --libs gssapi` - LIBS="$gss_libs $LIBS" - else - case $host in - *-hp-hpux*) - gss_libname="gss" - ;; - *) - gss_libname="gssapi" - ;; - esac + if test "$curl_cv_apple" = "yes"; then + LIBS="-lgssapi_krb5 -lresolv $LIBS" + else + if test "$GSSAPI_ROOT" != "/usr"; then + CURL_CHECK_PKGCONFIG(mit-krb5-gssapi, $GSSAPI_ROOT/lib/pkgconfig) + else + CURL_CHECK_PKGCONFIG(mit-krb5-gssapi) + fi + if test -n "$host_alias" && test -f "$GSSAPI_ROOT/bin/$host_alias-krb5-config"; then + dnl krb5-config does not have --libs-only-L or similar, put everything + dnl into LIBS + gss_libs=`$GSSAPI_ROOT/bin/$host_alias-krb5-config --libs gssapi` + LIBS="$gss_libs $LIBS" + elif test "$PKGCONFIG" != "no"; then + gss_libs=`$PKGCONFIG --libs mit-krb5-gssapi` + LIBS="$gss_libs $LIBS" + link_pkgconfig=1 + elif test -f "$KRB5CONFIG"; then + dnl krb5-config does not have --libs-only-L or similar, put everything + dnl into LIBS + gss_libs=`$KRB5CONFIG --libs gssapi` + LIBS="$gss_libs $LIBS" + link_pkgconfig=1 + else + case $host in + *-hp-hpux*) + gss_libname="gss" + ;; + *) + gss_libname="gssapi" + ;; + esac - if test "$GSSAPI_ROOT" != "yes"; then - LDFLAGS="$LDFLAGS -L$GSSAPI_ROOT/lib$libsuff" - LIBS="-l$gss_libname $LIBS" - else - LIBS="-l$gss_libname $LIBS" - fi + if test "$GSSAPI_ROOT" != "yes"; then + LDFLAGS="$LDFLAGS -L$GSSAPI_ROOT/lib$libsuff" + LDFLAGSPC="$LDFLAGSPC -L$GSSAPI_ROOT/lib$libsuff" + LIBS="-l$gss_libname $LIBS" + else + LIBS="-l$gss_libname $LIBS" fi - ;; - esac + fi + fi + gss_version="" + if test -n "$host_alias" && test -f "$GSSAPI_ROOT/bin/$host_alias-krb5-config"; then + gss_version=`$GSSAPI_ROOT/bin/$host_alias-krb5-config --version | $SED 's/Kerberos 5 release //'` + elif test "$PKGCONFIG" != "no"; then + gss_version=`$PKGCONFIG --modversion mit-krb5-gssapi` + elif test -f "$KRB5CONFIG"; then + gss_version=`$KRB5CONFIG --version | $SED 's/Kerberos 5 release //'` + fi + if test -n "$gss_version"; then + AC_MSG_NOTICE([GSS-API MIT Kerberos version detected: $gss_version]) + AC_DEFINE_UNQUOTED([CURL_KRB5_VERSION], ["$gss_version"], [MIT Kerberos version]) + fi else - LDFLAGS="$LDFLAGS $GSSAPI_LIB_DIR" - case $host in - *-hp-hpux*) + LDFLAGS="$LDFLAGS $GSSAPI_LIB_DIR" + LDFLAGSPC="$LDFLAGSPC $GSSAPI_LIB_DIR" + case $host in + *-hp-hpux*) LIBS="-lgss $LIBS" ;; - *) + *) LIBS="-lgssapi $LIBS" ;; - esac + esac + fi + if test -n "$link_pkgconfig"; then + if test -n "$gnu_gss"; then + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE gss" + else + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE mit-krb5-gssapi" + fi fi else CPPFLAGS="$save_CPPFLAGS" fi -if test x"$want_gss" = xyes; then +if test "$want_gss" = "yes"; then AC_MSG_CHECKING([if we can link against GSS-API library]) AC_LINK_IFELSE([ AC_LANG_FUNC_LINK_TRY([gss_init_sec_context]) @@ -2032,11 +2064,11 @@ if test x"$want_gss" = xyes; then fi build_libstubgss=no -if test x"$want_gss" = "xyes"; then +if test "$want_gss" = "yes"; then build_libstubgss=yes fi -AM_CONDITIONAL(BUILD_STUB_GSS, test "x$build_libstubgss" = "xyes") +AM_CONDITIONAL(BUILD_STUB_GSS, test "$build_libstubgss" = "yes") dnl ------------------------------------------------------------- dnl parse --with-default-ssl-backend so it can be validated below @@ -2058,128 +2090,305 @@ case "$DEFAULT_SSL_BACKEND" in ;; *) dnl --with-default-ssl-backend option used with name - AC_SUBST(DEFAULT_SSL_BACKEND) dnl needs to be validated below VALID_DEFAULT_SSL_BACKEND=no ;; esac CURL_WITH_SCHANNEL -CURL_WITH_SECURETRANSPORT CURL_WITH_AMISSL CURL_WITH_OPENSSL CURL_WITH_GNUTLS CURL_WITH_MBEDTLS CURL_WITH_WOLFSSL -CURL_WITH_BEARSSL CURL_WITH_RUSTLS +CURL_WITH_APPLE_SECTRUST -dnl link required libraries for USE_WIN32_CRYPTO or USE_SCHANNEL -if test "x$USE_WIN32_CRYPTO" = "x1" -o "x$USE_SCHANNEL" = "x1"; then +dnl link required libraries for USE_WIN32_CRYPTO or SCHANNEL_ENABLED +if test "$USE_WIN32_CRYPTO" = "1" || test "$SCHANNEL_ENABLED" = "1"; then LIBS="-ladvapi32 -lcrypt32 $LIBS" fi -dnl link bcrypt for BCryptGenRandom() (used when building for Vista or newer) -if test "x$curl_cv_native_windows" = "xyes" && - test "x$curl_mingw_original" = "xno"; then +if test "$curl_cv_native_windows" = "yes"; then + dnl for BCryptGenRandom() LIBS="-lbcrypt $LIBS" fi -case "x$SSL_DISABLED$OPENSSL_ENABLED$GNUTLS_ENABLED$MBEDTLS_ENABLED$WOLFSSL_ENABLED$SCHANNEL_ENABLED$SECURETRANSPORT_ENABLED$BEARSSL_ENABLED$RUSTLS_ENABLED" -in -x) - AC_MSG_ERROR([TLS not detected, you will not be able to use HTTPS, FTPS, NTLM and more. -Use --with-openssl, --with-gnutls, --with-wolfssl, --with-mbedtls, --with-schannel, --with-secure-transport, --with-amissl, --with-bearssl or --with-rustls to address this.]) - ;; -x1) - # one SSL backend is enabled - AC_SUBST(SSL_ENABLED) - SSL_ENABLED="1" - AC_MSG_NOTICE([built with one SSL backend]) - ;; -xD) - # explicitly built without TLS - ;; -xD*) - AC_MSG_ERROR([--without-ssl has been set together with an explicit option to use an ssl library -(e.g. --with-openssl, --with-gnutls, --with-wolfssl, --with-mbedtls, --with-schannel, --with-secure-transport, --with-amissl, --with-bearssl, --with-rustls). +case "x$SSL_DISABLED$OPENSSL_ENABLED$GNUTLS_ENABLED$MBEDTLS_ENABLED$WOLFSSL_ENABLED$SCHANNEL_ENABLED$RUSTLS_ENABLED" in + x) + AC_MSG_ERROR([TLS not detected, you will not be able to use HTTPS, FTPS, NTLM and more. +Use --with-openssl, --with-gnutls, --with-wolfssl, --with-mbedtls, --with-schannel, --with-amissl or --with-rustls to address this.]) + ;; + x1) + dnl one SSL backend is enabled + SSL_ENABLED="1" + AC_MSG_NOTICE([built with one SSL backend]) + ;; + xD) + dnl explicitly built without TLS + ;; + xD*) + AC_MSG_ERROR([--without-ssl has been set together with an explicit option to use an SSL library +(e.g. --with-openssl, --with-gnutls, --with-wolfssl, --with-mbedtls, --with-schannel, --with-amissl, --with-rustls). Since these are conflicting parameters, verify which is the desired one and drop the other.]) - ;; -*) - # more than one SSL backend is enabled - AC_SUBST(SSL_ENABLED) - SSL_ENABLED="1" - AC_SUBST(CURL_WITH_MULTI_SSL) - CURL_WITH_MULTI_SSL="1" - AC_DEFINE(CURL_WITH_MULTI_SSL, 1, [built with multiple SSL backends]) - AC_MSG_NOTICE([built with multiple SSL backends]) - ;; + ;; + *) + dnl more than one SSL backend is enabled + SSL_ENABLED="1" + CURL_WITH_MULTI_SSL="1" + AC_DEFINE(CURL_WITH_MULTI_SSL, 1, [built with multiple SSL backends]) + AC_MSG_NOTICE([built with multiple SSL backends]) + ;; esac if test -n "$ssl_backends"; then curl_ssl_msg="enabled ($ssl_backends)" fi -if test no = "$VALID_DEFAULT_SSL_BACKEND" -then - if test -n "$SSL_ENABLED" - then +if test "$VALID_DEFAULT_SSL_BACKEND" = "no"; then + if test -n "$SSL_ENABLED"; then AC_MSG_ERROR([Default SSL backend $DEFAULT_SSL_BACKEND not enabled!]) else AC_MSG_ERROR([Default SSL backend requires SSL!]) fi -elif test yes = "$VALID_DEFAULT_SSL_BACKEND" -then +elif test "$VALID_DEFAULT_SSL_BACKEND" = "yes"; then AC_DEFINE_UNQUOTED([CURL_DEFAULT_SSL_BACKEND], ["$DEFAULT_SSL_BACKEND"], [Default SSL backend]) fi +dnl --------------------- +dnl check native CA store +dnl --------------------- + +ca_native_opt=0 +AC_MSG_CHECKING([whether to use native CA store]) +AC_ARG_ENABLE(ca-native, +AS_HELP_STRING([--enable-ca-native],[Enable native CA store]) +AS_HELP_STRING([--disable-ca-native],[Disable native CA store (default)]), +[ case "$enableval" in + yes) + AC_MSG_RESULT([yes]) + AC_DEFINE(CURL_CA_NATIVE, 1, [If native CA store is enabled]) + ca_native_opt=1 + ;; + *) + AC_MSG_RESULT([no]) + ;; + esac ], + AC_MSG_RESULT([no]) +) + dnl ********************************************************************** dnl Check for the CA bundle dnl ********************************************************************** if test -n "$check_for_ca_bundle"; then CURL_CHECK_CA_BUNDLE + CURL_CHECK_CA_EMBED +fi + +AM_CONDITIONAL(CURL_CA_EMBED_SET, test -n "$CURL_CA_EMBED") + +dnl ---------------------- +dnl check unsafe CA search +dnl ---------------------- + +if test "$curl_cv_native_windows" = "yes"; then + ca_search=1 + AC_MSG_CHECKING([whether to enable unsafe CA bundle search in PATH on Windows]) + AC_ARG_ENABLE(ca-search, +AS_HELP_STRING([--enable-ca-search],[Enable unsafe CA bundle search in PATH on Windows]) +AS_HELP_STRING([--disable-ca-search],[Disable unsafe CA bundle search in PATH on Windows]), + [ case "$enableval" in + no) + AC_MSG_RESULT([no]) + ca_search=0 + ;; + yes) + AC_MSG_RESULT([yes]) + ;; + *) + if test "$ca_native_opt" = "1"; then + AC_MSG_RESULT([no]) + ca_search=0 + else + AC_MSG_RESULT([yes]) + fi + ;; + esac ], + if test "$ca_native_opt" = "1"; then + AC_MSG_RESULT([no]) + ca_search=0 + else + AC_MSG_RESULT([yes]) + fi + ) + if test "$ca_search" = "0"; then + AC_DEFINE(CURL_DISABLE_CA_SEARCH, 1, [If unsafe CA bundle search in PATH on Windows is disabled]) + fi +fi + +dnl -------------------- +dnl check safe CA search +dnl -------------------- + +if test "$curl_cv_native_windows" = "yes"; then + AC_MSG_CHECKING([whether to enable safe CA bundle search (within the curl tool directory) on Windows]) + AC_ARG_ENABLE(ca-search-safe, +AS_HELP_STRING([--enable-ca-search-safe],[Enable safe CA bundle search]) +AS_HELP_STRING([--disable-ca-search-safe],[Disable safe CA bundle search (default)]), + [ case "$enableval" in + yes) + AC_MSG_RESULT([yes]) + AC_DEFINE(CURL_CA_SEARCH_SAFE, 1, [If safe CA bundle search is enabled]) + ;; + *) + AC_MSG_RESULT([no]) + ;; + esac ], + AC_MSG_RESULT([no]) + ) fi dnl ********************************************************************** dnl Check for libpsl dnl ********************************************************************** +dnl Default to compiler & linker defaults for LIBPSL files & libraries. +OPT_LIBPSL=off AC_ARG_WITH(libpsl, - AS_HELP_STRING([--without-libpsl], - [disable support for libpsl cookie checking]), - with_libpsl=$withval, - with_libpsl=yes) -if test $with_libpsl != "no"; then - AC_SEARCH_LIBS(psl_builtin, psl, - [curl_psl_msg="enabled"; - AC_DEFINE([USE_LIBPSL], [1], [PSL support enabled]) - ], - [curl_psl_msg="no (libpsl not found)"; - AC_MSG_WARN([libpsl was not found]) - ] +AS_HELP_STRING([--with-libpsl=PATH],[Where to look for libpsl, PATH points to the LIBPSL installation; + when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) +AS_HELP_STRING([--without-libpsl], [disable LIBPSL]), + OPT_LIBPSL=$withval) + +if test "x$OPT_LIBPSL" != "xno"; then + dnl backup the pre-libpsl variables + CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" + CLEANCPPFLAGS="$CPPFLAGS" + CLEANLIBS="$LIBS" + + case "$OPT_LIBPSL" in + yes|off) + dnl --with-libpsl (without path) used + CURL_CHECK_PKGCONFIG(libpsl) + + if test "$PKGCONFIG" != "no"; then + LIB_PSL=`$PKGCONFIG --libs-only-l libpsl` + LD_PSL=`$PKGCONFIG --libs-only-L libpsl` + CPP_PSL=`$PKGCONFIG --cflags-only-I libpsl` + else + dnl no libpsl pkg-config found + LIB_PSL="-lpsl" + fi + + ;; + *) + dnl use the given --with-libpsl spot + LIB_PSL="-lpsl" + PREFIX_PSL=$OPT_LIBPSL + ;; + esac + + dnl if given with a prefix, we set -L and -I based on that + if test -n "$PREFIX_PSL"; then + LD_PSL=-L${PREFIX_PSL}/lib$libsuff + CPP_PSL=-I${PREFIX_PSL}/include + fi + + LDFLAGS="$LDFLAGS $LD_PSL" + LDFLAGSPC="$LDFLAGSPC $LD_PSL" + CPPFLAGS="$CPPFLAGS $CPP_PSL" + LIBS="$LIB_PSL $LIBS" + + AC_CHECK_LIB(psl, psl_builtin, + [ + AC_CHECK_HEADERS(libpsl.h, + curl_psl_msg="enabled" + AC_DEFINE(USE_LIBPSL, 1, [if libpsl is in use]) + USE_LIBPSL=1 + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libpsl" + ) + ], + dnl not found, revert back to clean variables + LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC + CPPFLAGS=$CLEANCPPFLAGS + LIBS=$CLEANLIBS ) + + if test "$USE_LIBPSL" != "1"; then + AC_MSG_ERROR([libpsl libs and/or directories were not found where specified!]) + fi fi AM_CONDITIONAL([USE_LIBPSL], [test "$curl_psl_msg" = "enabled"]) - dnl ********************************************************************** dnl Check for libgsasl dnl ********************************************************************** +OPT_LIBGSASL=no AC_ARG_WITH(libgsasl, - AS_HELP_STRING([--without-libgsasl], - [disable libgsasl support for SCRAM]), - with_libgsasl=$withval, - with_libgsasl=yes) -if test $with_libgsasl != "no"; then - AC_SEARCH_LIBS(gsasl_init, gsasl, - [curl_gsasl_msg="enabled"; - AC_DEFINE([USE_GSASL], [1], [GSASL support enabled]) - ], - [curl_gsasl_msg="no (libgsasl not found)"; - AC_MSG_WARN([libgsasl was not found]) - ] +AS_HELP_STRING([--with-libgsasl=PATH],[Where to look for libgsasl, PATH points to the libgsasl installation; + when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) +AS_HELP_STRING([--without-libgsasl], [disable libgsasl support for SCRAM]), + OPT_LIBGSASL=$withval) + +if test "x$OPT_LIBGSASL" != "xno"; then + dnl backup the pre-libgsasl variables + CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" + CLEANCPPFLAGS="$CPPFLAGS" + CLEANLIBS="$LIBS" + + case "$OPT_LIBGSASL" in + yes) + dnl --with-libgsasl (without path) used + CURL_CHECK_PKGCONFIG(libgsasl) + + if test "$PKGCONFIG" != "no"; then + LIB_GSASL=`$PKGCONFIG --libs-only-l libgsasl` + LD_GSASL=`$PKGCONFIG --libs-only-L libgsasl` + CPP_GSASL=`$PKGCONFIG --cflags-only-I libgsasl` + else + dnl no libgsasl pkg-config found + LIB_GSASL="-lgsasl" + fi + ;; + *) + dnl use the given --with-libgsasl spot + PREFIX_GSASL=$OPT_LIBGSASL + ;; + esac + + dnl if given with a prefix, we set -L and -I based on that + if test -n "$PREFIX_GSASL"; then + LIB_GSASL="-lgsasl" + LD_GSASL=-L${PREFIX_GSASL}/lib$libsuff + CPP_GSASL=-I${PREFIX_GSASL}/include + fi + + LDFLAGS="$LDFLAGS $LD_GSASL" + LDFLAGSPC="$LDFLAGSPC $LD_GSASL" + CPPFLAGS="$CPPFLAGS $CPP_GSASL" + LIBS="$LIB_GSASL $LIBS" + + AC_CHECK_LIB(gsasl, gsasl_init, + [ + AC_CHECK_HEADERS(gsasl.h, + curl_gsasl_msg="enabled" + AC_DEFINE(USE_GSASL, 1, [GSASL support enabled]) + USE_LIBGSASL=1 + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libgsasl" + ) + ], + dnl not found, revert back to clean variables + LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC + CPPFLAGS=$CLEANCPPFLAGS + LIBS=$CLEANLIBS + curl_gsasl_msg="no (libgsasl not found)" + AC_MSG_WARN([libgsasl was not found]) ) fi AM_CONDITIONAL([USE_GSASL], [test "$curl_gsasl_msg" = "enabled"]) @@ -2188,56 +2397,52 @@ AC_ARG_WITH(libmetalink,, AC_MSG_ERROR([--with-libmetalink and --without-libmetalink no longer work!])) dnl ********************************************************************** -dnl Check for the presence of LIBSSH2 libraries and headers +dnl Check for the presence of libssh2 libraries and headers dnl ********************************************************************** -dnl Default to compiler & linker defaults for LIBSSH2 files & libraries. +dnl Default to compiler & linker defaults for libssh2 files & libraries. OPT_LIBSSH2=off -AC_ARG_WITH(libssh2,dnl -AS_HELP_STRING([--with-libssh2=PATH],[Where to look for libssh2, PATH points to the libssh2 installation; when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) +AC_ARG_WITH(libssh2, +AS_HELP_STRING([--with-libssh2=PATH],[Where to look for libssh2, PATH points to the libssh2 installation; + when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) AS_HELP_STRING([--with-libssh2], [enable libssh2]), OPT_LIBSSH2=$withval, OPT_LIBSSH2=no) - OPT_LIBSSH=off -AC_ARG_WITH(libssh,dnl -AS_HELP_STRING([--with-libssh=PATH],[Where to look for libssh, PATH points to the libssh installation; when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) +AC_ARG_WITH(libssh, +AS_HELP_STRING([--with-libssh=PATH],[Where to look for libssh, PATH points to the libssh installation; + when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) AS_HELP_STRING([--with-libssh], [enable libssh]), OPT_LIBSSH=$withval, OPT_LIBSSH=no) -OPT_WOLFSSH=off -AC_ARG_WITH(wolfssh,dnl -AS_HELP_STRING([--with-wolfssh=PATH],[Where to look for wolfssh, PATH points to the wolfSSH installation; when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) -AS_HELP_STRING([--with-wolfssh], [enable wolfssh]), - OPT_WOLFSSH=$withval, OPT_WOLFSSH=no) - -if test X"$OPT_LIBSSH2" != Xno; then +if test "x$OPT_LIBSSH2" != "xno"; then dnl backup the pre-libssh2 variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" case "$OPT_LIBSSH2" in - yes) - dnl --with-libssh2 (without path) used - CURL_CHECK_PKGCONFIG(libssh2) + yes) + dnl --with-libssh2 (without path) used + CURL_CHECK_PKGCONFIG(libssh2) - if test "$PKGCONFIG" != "no" ; then - LIB_SSH2=`$PKGCONFIG --libs-only-l libssh2` - LD_SSH2=`$PKGCONFIG --libs-only-L libssh2` - CPP_SSH2=`$PKGCONFIG --cflags-only-I libssh2` - version=`$PKGCONFIG --modversion libssh2` - DIR_SSH2=`echo $LD_SSH2 | $SED -e 's/^-L//'` - fi + if test "$PKGCONFIG" != "no"; then + LIB_SSH2=`$PKGCONFIG --libs-only-l libssh2` + LD_SSH2=`$PKGCONFIG --libs-only-L libssh2` + CPP_SSH2=`$PKGCONFIG --cflags-only-I libssh2` + version=`$PKGCONFIG --modversion libssh2` + DIR_SSH2=`echo $LD_SSH2 | $SED -e 's/^-L//'` + fi - ;; - off) - dnl no --with-libssh2 option given, just check default places - ;; - *) - dnl use the given --with-libssh2 spot - PREFIX_SSH2=$OPT_LIBSSH2 - ;; + ;; + off) + dnl no --with-libssh2 option given, check default places + ;; + *) + dnl use the given --with-libssh2 spot + PREFIX_SSH2=$OPT_LIBSSH2 + ;; esac dnl if given with a prefix, we set -L and -I based on that @@ -2249,69 +2454,72 @@ if test X"$OPT_LIBSSH2" != Xno; then fi LDFLAGS="$LDFLAGS $LD_SSH2" + LDFLAGSPC="$LDFLAGSPC $LD_SSH2" CPPFLAGS="$CPPFLAGS $CPP_SSH2" LIBS="$LIB_SSH2 $LIBS" - dnl check for function added in libssh2 version 1.0 - AC_CHECK_LIB(ssh2, libssh2_session_block_directions) + dnl check for function added in libssh2 v1.9.0 + AC_CHECK_LIB(ssh2, libssh2_agent_get_identity_path) AC_CHECK_HEADER(libssh2.h, - curl_ssh_msg="enabled (libSSH2)" - LIBSSH2_ENABLED=1 - AC_DEFINE(USE_LIBSSH2, 1, [if libSSH2 is in use]) - AC_SUBST(USE_LIBSSH2, [1]) + curl_ssh_msg="enabled (libssh2)" + AC_DEFINE(USE_LIBSSH2, 1, [if libssh2 is in use]) + USE_LIBSSH2=1 ) - if test X"$OPT_LIBSSH2" != Xoff && - test "$LIBSSH2_ENABLED" != "1"; then - AC_MSG_ERROR([libSSH2 libs and/or directories were not found where specified!]) + if test "x$OPT_LIBSSH2" != "xoff" && + test "$USE_LIBSSH2" != "1"; then + AC_MSG_ERROR([libssh2 libs and/or directories were not found where specified!]) fi - if test "$LIBSSH2_ENABLED" = "1"; then + if test "$USE_LIBSSH2" = "1"; then if test -n "$DIR_SSH2"; then - dnl when the libssh2 shared libs were found in a path that the run-time - dnl linker doesn't search through, we need to add it to CURL_LIBRARY_PATH - dnl to prevent further configure tests to fail due to this + dnl when the libssh2 shared libs were found in a path that the runtime + dnl linker does not search through, we need to add it to CURL_LIBRARY_PATH + dnl to prevent further configure tests to fail due to this - if test "x$cross_compiling" != "xyes"; then - CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_SSH2" - export CURL_LIBRARY_PATH - AC_MSG_NOTICE([Added $DIR_SSH2 to CURL_LIBRARY_PATH]) - fi + if test "$cross_compiling" != "yes"; then + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_SSH2" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_SSH2 to CURL_LIBRARY_PATH]) + fi fi + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libssh2" else dnl no libssh2, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS fi -elif test X"$OPT_LIBSSH" != Xno; then +elif test "x$OPT_LIBSSH" != "xno"; then dnl backup the pre-libssh variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" case "$OPT_LIBSSH" in - yes) - dnl --with-libssh (without path) used - CURL_CHECK_PKGCONFIG(libssh) + yes) + dnl --with-libssh (without path) used + CURL_CHECK_PKGCONFIG(libssh) - if test "$PKGCONFIG" != "no" ; then - LIB_SSH=`$PKGCONFIG --libs-only-l libssh` - LD_SSH=`$PKGCONFIG --libs-only-L libssh` - CPP_SSH=`$PKGCONFIG --cflags-only-I libssh` - version=`$PKGCONFIG --modversion libssh` - DIR_SSH=`echo $LD_SSH | $SED -e 's/^-L//'` - fi + if test "$PKGCONFIG" != "no"; then + LIB_SSH=`$PKGCONFIG --libs-only-l libssh` + LD_SSH=`$PKGCONFIG --libs-only-L libssh` + CPP_SSH=`$PKGCONFIG --cflags-only-I libssh` + version=`$PKGCONFIG --modversion libssh` + DIR_SSH=`echo $LD_SSH | $SED -e 's/^-L//'` + fi - ;; - off) - dnl no --with-libssh option given, just check default places - ;; - *) - dnl use the given --with-libssh spot - PREFIX_SSH=$OPT_LIBSSH - ;; + ;; + off) + dnl no --with-libssh option given, check default places + ;; + *) + dnl use the given --with-libssh spot + PREFIX_SSH=$OPT_LIBSSH + ;; esac dnl if given with a prefix, we set -L and -I based on that @@ -2323,297 +2531,389 @@ elif test X"$OPT_LIBSSH" != Xno; then fi LDFLAGS="$LDFLAGS $LD_SSH" + LDFLAGSPC="$LDFLAGSPC $LD_SSH" CPPFLAGS="$CPPFLAGS $CPP_SSH" LIBS="$LIB_SSH $LIBS" AC_CHECK_LIB(ssh, ssh_new) AC_CHECK_HEADER(libssh/libssh.h, - curl_ssh_msg="enabled (libSSH)" - LIBSSH_ENABLED=1 - AC_DEFINE(USE_LIBSSH, 1, [if libSSH is in use]) - AC_SUBST(USE_LIBSSH, [1]) + curl_ssh_msg="enabled (libssh)" + AC_DEFINE(USE_LIBSSH, 1, [if libssh is in use]) + USE_LIBSSH=1 ) - if test X"$OPT_LIBSSH" != Xoff && - test "$LIBSSH_ENABLED" != "1"; then - AC_MSG_ERROR([libSSH libs and/or directories were not found where specified!]) + if test "x$OPT_LIBSSH" != "xoff" && + test "$USE_LIBSSH" != "1"; then + AC_MSG_ERROR([libssh libs and/or directories were not found where specified!]) fi - if test "$LIBSSH_ENABLED" = "1"; then - if test -n "$DIR_SSH"; then - dnl when the libssh shared libs were found in a path that the run-time - dnl linker doesn't search through, we need to add it to CURL_LIBRARY_PATH - dnl to prevent further configure tests to fail due to this - - if test "x$cross_compiling" != "xyes"; then - CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_SSH" - export CURL_LIBRARY_PATH - AC_MSG_NOTICE([Added $DIR_SSH to CURL_LIBRARY_PATH]) - fi + if test "$USE_LIBSSH" = "1"; then + if test "$curl_cv_native_windows" = "yes"; then + dnl for if_nametoindex + LIBS="-liphlpapi $LIBS" fi + if test -n "$DIR_SSH"; then + dnl when the libssh shared libs were found in a path that the runtime + dnl linker does not search through, we need to add it to CURL_LIBRARY_PATH + dnl to prevent further configure tests to fail due to this + + if test "$cross_compiling" != "yes"; then + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_SSH" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_SSH to CURL_LIBRARY_PATH]) + fi + fi + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libssh" else dnl no libssh, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS fi -elif test X"$OPT_WOLFSSH" != Xno; then - dnl backup the pre-wolfssh variables - CLEANLDFLAGS="$LDFLAGS" - CLEANCPPFLAGS="$CPPFLAGS" - CLEANLIBS="$LIBS" - - - if test "$OPT_WOLFSSH" != yes; then - WOLFCONFIG="$OPT_WOLFSSH/bin/wolfssh-config" - LDFLAGS="$LDFLAGS `$WOLFCONFIG --libs`" - CPPFLAGS="$CPPFLAGS `$WOLFCONFIG --cflags`" - fi - - AC_CHECK_LIB(wolfssh, wolfSSH_Init) - - AC_CHECK_HEADERS(wolfssh/ssh.h, - curl_ssh_msg="enabled (wolfSSH)" - WOLFSSH_ENABLED=1 - AC_DEFINE(USE_WOLFSSH, 1, [if wolfSSH is in use]) - AC_SUBST(USE_WOLFSSH, [1]) - ) - fi dnl ********************************************************************** -dnl Check for the presence of LIBRTMP libraries and headers +dnl Check for LDAP (after the SSL libraries) dnl ********************************************************************** -dnl Default to compiler & linker defaults for LIBRTMP files & libraries. -OPT_LIBRTMP=off -AC_ARG_WITH(librtmp,dnl -AS_HELP_STRING([--with-librtmp=PATH],[Where to look for librtmp, PATH points to the LIBRTMP installation; when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) -AS_HELP_STRING([--without-librtmp], [disable LIBRTMP]), - OPT_LIBRTMP=$withval) +LDAPLIBNAME="" +AC_ARG_WITH(ldap-lib, +AS_HELP_STRING([--with-ldap-lib=libname],[Specify name of ldap lib file]), + [LDAPLIBNAME="$withval"]) -if test X"$OPT_LIBRTMP" != Xno; then - dnl backup the pre-librtmp variables - CLEANLDFLAGS="$LDFLAGS" - CLEANCPPFLAGS="$CPPFLAGS" - CLEANLIBS="$LIBS" +LBERLIBNAME="" +AC_ARG_WITH(lber-lib, +AS_HELP_STRING([--with-lber-lib=libname],[Specify name of lber lib file]), + [LBERLIBNAME="$withval"]) - case "$OPT_LIBRTMP" in +dnl Handle argument to --with-ldap. +clean_LDAP_CPPFLAGS=$CPPFLAGS +clean_LDAP_LDFLAGS=$LDFLAGS +clean_LDAP_LIBS=$LIBS +OPT_LDAP=off +AC_ARG_WITH(ldap, +AS_HELP_STRING([--with-ldap=PATH],[Where to look for LDAP, PATH points to the LDAP installation; + when possible, set the PKG_CONFIG_PATH environment variable instead of using this option]) +AS_HELP_STRING([--without-ldap], [disable LDAP]), + OPT_LDAP=$withval) + +case "$OPT_LDAP" in + no) + dnl --without-ldap option used + want_ldap="no" + ;; yes) - dnl --with-librtmp (without path) used - CURL_CHECK_PKGCONFIG(librtmp) - - if test "$PKGCONFIG" != "no" ; then - LIB_RTMP=`$PKGCONFIG --libs-only-l librtmp` - LD_RTMP=`$PKGCONFIG --libs-only-L librtmp` - CPP_RTMP=`$PKGCONFIG --cflags-only-I librtmp` - version=`$PKGCONFIG --modversion librtmp` - DIR_RTMP=`echo $LD_RTMP | $SED -e 's/^-L//'` - else - dnl To avoid link errors, we do not allow --librtmp without - dnl a pkgconfig file - AC_MSG_ERROR([--librtmp was specified but could not find librtmp pkgconfig file.]) - fi - + dnl --with-ldap option used without path + want_ldap="yes" ;; off) - dnl no --with-librtmp option given, just check default places - LIB_RTMP="-lrtmp" + dnl no --with-ldap option given, do not change anything + want_ldap="default" ;; *) - dnl use the given --with-librtmp spot - LIB_RTMP="-lrtmp" - PREFIX_RTMP=$OPT_LIBRTMP + dnl --with-ldap option used with path + want_ldap="yes" + if test -d "$OPT_LDAP/lib$libsuff"; then + LDFLAGS="$LDFLAGS -L$OPT_LDAP/lib$libsuff" + DIR_LDAP="$OPT_LDAP/lib$libsuff" + elif test -d "$OPT_LDAP/lib"; then + LDFLAGS="$LDFLAGS -L$OPT_LDAP/lib" + DIR_LDAP="$OPT_LDAP/lib" + fi + if test -d "$OPT_LDAP/include"; then + CPPFLAGS="$CPPFLAGS -I$OPT_LDAP/include" + fi + ldap_askedfor="yes" ;; - esac +esac - dnl if given with a prefix, we set -L and -I based on that - if test -n "$PREFIX_RTMP"; then - LD_RTMP=-L${PREFIX_RTMP}/lib$libsuff - CPP_RTMP=-I${PREFIX_RTMP}/include - DIR_RTMP=${PREFIX_RTMP}/lib$libsuff +if test "$CURL_DISABLE_LDAP" != "1" && test "$want_ldap" != "no"; then + + CURL_CHECK_HEADER_LBER + CURL_CHECK_HEADER_LDAP + CURL_CHECK_HEADER_LDAP_SSL + + if test -z "$LDAPLIBNAME"; then + if test "$curl_cv_native_windows" = "yes" && test "$curl_cv_winuwp" != "yes"; then + dnl Windows uses a single and unique LDAP library name + LDAPLIBNAME="wldap32" + LBERLIBNAME="no" + fi fi - LDFLAGS="$LDFLAGS $LD_RTMP" - CPPFLAGS="$CPPFLAGS $CPP_RTMP" - LIBS="$LIB_RTMP $LIBS" + if test "$LDAPLIBNAME"; then + dnl If we have both LDAP and LBER library names, check if we need both + if test "$LBERLIBNAME" && test "$LBERLIBNAME" != "no"; then + dnl Try LDAP first, then with LBER if needed + AC_CHECK_LIB("$LDAPLIBNAME", ldap_init, [ldap_lib_ok=yes], [ldap_lib_ok=no]) + if test "$ldap_lib_ok" = "no"; then + dnl LDAP alone failed, try with LBER using a different function + AC_CHECK_LIB("$LDAPLIBNAME", ldap_unbind, [ldap_lib_ok=yes], [ldap_lib_ok=no], [-l$LBERLIBNAME]) + if test "$ldap_lib_ok" = "yes"; then + dnl We need both libraries + LIBS="-l$LDAPLIBNAME -l$LBERLIBNAME $LIBS" + fi + else + dnl LDAP alone is sufficient + LIBS="-l$LDAPLIBNAME $LIBS" + fi + else + dnl Only check LDAP library + AC_CHECK_LIB("$LDAPLIBNAME", ldap_init, [ldap_lib_ok=yes; LIBS="-l$LDAPLIBNAME $LIBS"], [ldap_lib_ok=no]) + fi - AC_CHECK_LIB(rtmp, RTMP_Init, - [ - AC_CHECK_HEADERS(librtmp/rtmp.h, - curl_rtmp_msg="enabled (librtmp)" - LIBRTMP_ENABLED=1 - AC_DEFINE(USE_LIBRTMP, 1, [if librtmp is in use]) - AC_SUBST(USE_LIBRTMP, [1]) - ) - ], - dnl not found, revert back to clean variables - LDFLAGS=$CLEANLDFLAGS - CPPFLAGS=$CLEANCPPFLAGS - LIBS=$CLEANLIBS - ) + if test "$ldap_lib_ok" = "no"; then + if test -n "$ldap_askedfor"; then + AC_MSG_ERROR([could not detect the LDAP libraries]) + fi + AC_MSG_WARN(["$LDAPLIBNAME" is not an LDAP library: LDAP disabled]) + AC_DEFINE(CURL_DISABLE_LDAP, 1, [to disable LDAP]) + CURL_DISABLE_LDAP=1 + AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) + CURL_DISABLE_LDAPS=1 + dnl restore original flags + CPPFLAGS=$clean_LDAP_CPPFLAGS + LDFLAGS=$clean_LDAP_LDFLAGS + LIBS=$clean_LDAP_LIBS + fi + else + dnl Try to find the right ldap libraries for this system + CURL_CHECK_LIBS_LDAP + case X-"$curl_cv_ldap_LIBS" in + X-unknown) + if test -n "$ldap_askedfor"; then + AC_MSG_ERROR([could not detect the LDAP libraries]) + fi + AC_MSG_WARN([Cannot find libraries for LDAP support: LDAP disabled]) + AC_DEFINE(CURL_DISABLE_LDAP, 1, [to disable LDAP]) + CURL_DISABLE_LDAP=1 + AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) + CURL_DISABLE_LDAPS=1 + dnl restore original flags + CPPFLAGS=$clean_LDAP_CPPFLAGS + LDFLAGS=$clean_LDAP_LDFLAGS + LIBS=$clean_LDAP_LIBS + ;; + esac + fi +fi - if test X"$OPT_LIBRTMP" != Xoff && - test "$LIBRTMP_ENABLED" != "1"; then - AC_MSG_ERROR([librtmp libs and/or directories were not found where specified!]) +if test "$CURL_DISABLE_LDAP" != "1"; then + dnl Add to library path if needed + if test -n "$DIR_LDAP"; then + dnl when the ldap shared lib were found in a path that the runtime + dnl linker does not search through, we need to add it to + dnl CURL_LIBRARY_PATH to prevent further configure tests to fail due to + dnl this + + if test "$cross_compiling" != "yes"; then + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_LDAP" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_LDAP to CURL_LIBRARY_PATH]) + fi fi + if test "$LBERLIBNAME"; then + dnl If name is "no" then do not define this library at all + dnl (it is only needed if libldap.so's dependencies are broken). + dnl Skip this check if we already determined we need both libraries above + if test "$LBERLIBNAME" != "no" && test "$ldap_lib_ok" != "yes"; then + AC_CHECK_LIB("$LBERLIBNAME", ber_free,, [ + AC_MSG_WARN(["$LBERLIBNAME" is not an LBER library: LDAP disabled]) + AC_DEFINE(CURL_DISABLE_LDAP, 1, [to disable LDAP]) + CURL_DISABLE_LDAP=1 + AC_DEFINE(CURL_DISABLE_LDAPS, 1, [to disable LDAPS]) + CURL_DISABLE_LDAPS=1 + dnl restore original flags + CPPFLAGS=$clean_LDAP_CPPFLAGS + LDFLAGS=$clean_LDAP_LDFLAGS + LIBS=$clean_LDAP_LIBS + ] + ) + fi + fi +fi + +if test "$CURL_DISABLE_LDAP" != "1"; then + AC_CHECK_FUNCS([ldap_url_parse \ + ldap_init_fd]) + + if test "$LDAPLIBNAME" = "wldap32"; then + curl_ldap_msg="enabled (winldap)" + AC_DEFINE(USE_WIN32_LDAP, 1, [Use Windows LDAP implementation]) + else + if test "$ac_cv_func_ldap_init_fd" = "yes"; then + curl_ldap_msg="enabled (OpenLDAP)" + AC_DEFINE(USE_OPENLDAP, 1, [Use OpenLDAP-specific code]) + USE_OPENLDAP=1 + else + curl_ldap_msg="enabled (ancient OpenLDAP)" + fi + fi +fi + +if test "$CURL_DISABLE_LDAPS" != "1"; then + curl_ldaps_msg="enabled" fi dnl ********************************************************************** dnl Check for linker switch for versioned symbols dnl ********************************************************************** -versioned_symbols_flavour= +versioned_symbols_flavor= AC_MSG_CHECKING([whether versioned symbols are wanted]) AC_ARG_ENABLE(versioned-symbols, AS_HELP_STRING([--enable-versioned-symbols], [Enable versioned symbols in shared library]) AS_HELP_STRING([--disable-versioned-symbols], [Disable versioned symbols in shared library]), [ case "$enableval" in - yes) AC_MSG_RESULT(yes) + no) + AC_MSG_RESULT(no) + ;; + *) + AC_MSG_RESULT(yes) AC_MSG_CHECKING([if libraries can be versioned]) GLD=`$LD --help < /dev/null 2>/dev/null | grep version-script` if test -z "$GLD"; then - AC_MSG_RESULT(no) - AC_MSG_WARN([You need an ld version supporting the --version-script option]) + AC_MSG_RESULT(no) + AC_MSG_WARN([You need an ld version supporting the --version-script option]) else - AC_MSG_RESULT(yes) - if test "x$CURL_WITH_MULTI_SSL" = "x1"; then - versioned_symbols_flavour="MULTISSL_" - elif test "x$OPENSSL_ENABLED" = "x1"; then - versioned_symbols_flavour="OPENSSL_" - elif test "x$GNUTLS_ENABLED" = "x1"; then - versioned_symbols_flavour="GNUTLS_" - elif test "x$WOLFSSL_ENABLED" = "x1"; then - versioned_symbols_flavour="WOLFSSL_" - elif test "x$SCHANNEL_ENABLED" = "x1"; then - versioned_symbols_flavour="SCHANNEL_" - elif test "x$SECURETRANSPORT_ENABLED" = "x1"; then - versioned_symbols_flavour="SECURE_TRANSPORT_" - else - versioned_symbols_flavour="" - fi - versioned_symbols="yes" + AC_MSG_RESULT(yes) + if test "x$enableval" != "xyes"; then + versioned_symbols_flavor="$enableval" + elif test "$CURL_WITH_MULTI_SSL" = "1"; then + versioned_symbols_flavor="MULTISSL_" + elif test "$OPENSSL_ENABLED" = "1"; then + versioned_symbols_flavor="OPENSSL_" + elif test "$MBEDTLS_ENABLED" = "1"; then + versioned_symbols_flavor="MBEDTLS_" + elif test "$WOLFSSL_ENABLED" = "1"; then + versioned_symbols_flavor="WOLFSSL_" + elif test "$GNUTLS_ENABLED" = "1"; then + versioned_symbols_flavor="GNUTLS_" + elif test "$RUSTLS_ENABLED" = "1"; then + versioned_symbols_flavor="RUSTLS_" + else + versioned_symbols_flavor="" + fi + versioned_symbols="yes" fi ;; - *) AC_MSG_RESULT(no) - ;; esac ], [ -AC_MSG_RESULT(no) + AC_MSG_RESULT(no) ] ) -AC_SUBST([CURL_LT_SHLIB_VERSIONED_FLAVOUR], - ["$versioned_symbols_flavour"]) +AC_SUBST([CURL_LIBCURL_VERSIONED_SYMBOLS_PREFIX], ["$versioned_symbols_flavor"]) +AC_SUBST([CURL_LIBCURL_VERSIONED_SYMBOLS_SONAME], ["4"]) dnl Keep in sync with VERSIONCHANGE - VERSIONDEL in lib/Makefile.soname AM_CONDITIONAL([CURL_LT_SHLIB_USE_VERSIONED_SYMBOLS], - [test "x$versioned_symbols" = 'xyes']) + [test "$versioned_symbols" = "yes"]) -dnl Update .plist file with current version -AC_SUBST([CURL_PLIST_VERSION], - ["$CURLVERSION"]) +dnl ---------------------------- +dnl check Windows Unicode option +dnl ---------------------------- -dnl ------------------------------------------------- -dnl check winidn option before other IDN libraries -dnl ------------------------------------------------- - -AC_MSG_CHECKING([whether to enable Windows native IDN (Windows native builds only)]) -OPT_WINIDN="default" -AC_ARG_WITH(winidn, -AS_HELP_STRING([--with-winidn=PATH],[enable Windows native IDN]) -AS_HELP_STRING([--without-winidn], [disable Windows native IDN]), - OPT_WINIDN=$withval) -case "$OPT_WINIDN" in - no|default) - dnl --without-winidn option used or configure option not specified - want_winidn="no" - AC_MSG_RESULT([no]) - ;; - yes) - dnl --with-winidn option used without path - want_winidn="yes" - want_winidn_path="default" - AC_MSG_RESULT([yes]) - ;; - *) - dnl --with-winidn option used with path - want_winidn="yes" - want_winidn_path="$withval" - AC_MSG_RESULT([yes ($withval)]) - ;; -esac - -if test "$want_winidn" = "yes"; then - dnl winidn library support has been requested - clean_CFLAGS="$CFLAGS" - clean_CPPFLAGS="$CPPFLAGS" - clean_LDFLAGS="$LDFLAGS" - clean_LIBS="$LIBS" - WINIDN_LIBS="-lnormaliz" - WINIDN_CPPFLAGS="" - # - if test "$want_winidn_path" != "default"; then - dnl path has been specified - dnl pkg-config not available or provides no info - WINIDN_LDFLAGS="-L$want_winidn_path/lib$libsuff" - WINIDN_CPPFLAGS="-I$want_winidn_path/include" - WINIDN_DIR="$want_winidn_path/lib$libsuff" - fi - # - dnl WinIDN requires a minimum supported OS version of at least Vista (0x0600) - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ - #include - ]],[[ - #if (WINVER < 0x600) && (_WIN32_WINNT < 0x600) - #error - #endif - ]]) - ],[ - ],[ - CFLAGS=`echo $CFLAGS | $SED -e 's/-DWINVER=[[^ ]]*//g'` - CFLAGS=`echo $CFLAGS | $SED -e 's/-D_WIN32_WINNT=[[^ ]]*//g'` - CPPFLAGS=`echo $CPPFLAGS | $SED -e 's/-DWINVER=[[^ ]]*//g'` - CPPFLAGS=`echo $CPPFLAGS | $SED -e 's/-D_WIN32_WINNT=[[^ ]]*//g'` - WINIDN_CPPFLAGS="$WINIDN_CPPFLAGS -DWINVER=0x0600" - ]) - # - CPPFLAGS="$CPPFLAGS $WINIDN_CPPFLAGS" - LDFLAGS="$LDFLAGS $WINIDN_LDFLAGS" - LIBS="$WINIDN_LIBS $LIBS" - # - AC_MSG_CHECKING([if IdnToUnicode can be linked]) - AC_LINK_IFELSE([ - AC_LANG_PROGRAM([[ - #include - ]],[[ - IdnToUnicode(0, NULL, 0, NULL, 0); - ]]) - ],[ - AC_MSG_RESULT([yes]) - tst_links_winidn="yes" - ],[ - AC_MSG_RESULT([no]) - tst_links_winidn="no" - ]) - # - if test "$tst_links_winidn" = "yes"; then - AC_DEFINE(USE_WIN32_IDN, 1, [Define to 1 if you have the `normaliz' (WinIDN) library (-lnormaliz).]) - AC_SUBST([IDN_ENABLED], [1]) - curl_idn_msg="enabled (Windows-native)" +want_winuni="no" +if test "$curl_cv_native_windows" = "yes"; then + if test "$curl_cv_winuwp" = "yes"; then + want_winuni="yes" else - AC_MSG_WARN([Cannot find libraries for IDN support: IDN disabled]) - CFLAGS="$clean_CFLAGS" - CPPFLAGS="$clean_CPPFLAGS" - LDFLAGS="$clean_LDFLAGS" - LIBS="$clean_LIBS" + AC_MSG_CHECKING([whether to enable Windows Unicode (Windows native builds only)]) + AC_ARG_ENABLE(windows-unicode, +AS_HELP_STRING([--enable-windows-unicode],[Enable Windows Unicode]) +AS_HELP_STRING([--disable-windows-unicode],[Disable Windows Unicode (default)]), + [ case "$enableval" in + yes) + want_winuni="yes" + AC_MSG_RESULT([yes]) + ;; + *) + AC_MSG_RESULT([no]) + ;; + esac ], + AC_MSG_RESULT([no]) + ) + fi + + if test "$want_winuni" = "yes"; then + CPPFLAGS="${CPPFLAGS} -DUNICODE -D_UNICODE" + fi +fi + +AM_CONDITIONAL([USE_UNICODE], [test "$want_winuni" = "yes"]) + +dnl ------------------------------------------------- +dnl check WinIDN option before other IDN libraries +dnl ------------------------------------------------- + +tst_links_winidn='no' +if test "$curl_cv_native_windows" = "yes"; then + AC_MSG_CHECKING([whether to enable Windows native IDN (Windows native builds only)]) + OPT_WINIDN="default" + AC_ARG_WITH(winidn, +AS_HELP_STRING([--with-winidn],[enable Windows native IDN]) +AS_HELP_STRING([--without-winidn], [disable Windows native IDN]), + OPT_WINIDN=$withval) + case "$OPT_WINIDN" in + no|default) + dnl --without-winidn option used or configure option not specified + want_winidn="no" + AC_MSG_RESULT([no]) + ;; + *) + dnl --with-winidn option + want_winidn="yes" + AC_MSG_RESULT([yes]) + ;; + esac + + if test "$want_winidn" = "yes"; then + LIBS="-lnormaliz $LIBS" + AC_DEFINE(USE_WIN32_IDN, 1, [Define to 1 if you have the `normaliz' (WinIDN) library (-lnormaliz).]) + IDN_ENABLED=1 + curl_idn_msg="enabled (Windows-native)" fi fi dnl ********************************************************************** -dnl Check for the presence of IDN libraries and headers +dnl Check for the presence of AppleIDN +dnl ********************************************************************** + +tst_links_appleidn='no' +if test "$curl_cv_apple" = "yes"; then + AC_MSG_CHECKING([whether to build with Apple IDN]) + OPT_IDN="default" + AC_ARG_WITH(apple-idn, +AS_HELP_STRING([--with-apple-idn],[Enable AppleIDN]) +AS_HELP_STRING([--without-apple-idn],[Disable AppleIDN]), + [OPT_IDN=$withval]) + case "$OPT_IDN" in + yes) + dnl --with-apple-idn option used + AC_MSG_RESULT([yes, check]) + AC_CHECK_LIB(icucore, uidna_openUTS46, + [ + AC_CHECK_HEADERS(unicode/uidna.h, + curl_idn_msg="enabled (AppleIDN)" + AC_DEFINE(USE_APPLE_IDN, 1, [if AppleIDN]) + USE_APPLE_IDN=1 + IDN_ENABLED=1 + LIBS="-licucore -liconv $LIBS" + tst_links_appleidn='yes' + ) + ]) + ;; + *) + AC_MSG_RESULT([no]) + ;; + esac +fi + +dnl ********************************************************************** +dnl Check for the presence of libidn2 dnl ********************************************************************** AC_MSG_CHECKING([whether to build with libidn2]) @@ -2622,9 +2922,12 @@ AC_ARG_WITH(libidn2, AS_HELP_STRING([--with-libidn2=PATH],[Enable libidn2 usage]) AS_HELP_STRING([--without-libidn2],[Disable libidn2 usage]), [OPT_IDN=$withval]) -if test "x$tst_links_winidn" = "xyes"; then +if test "$tst_links_winidn" = "yes"; then want_idn="no" - AC_MSG_RESULT([no (using winidn instead)]) + AC_MSG_RESULT([no (using WinIDN instead)]) +elif test "$tst_links_appleidn" = "yes"; then + want_idn="no" + AC_MSG_RESULT([no (using AppleIDN instead)]) else case "$OPT_IDN" in no) @@ -2657,19 +2960,20 @@ if test "$want_idn" = "yes"; then dnl idn library support has been requested clean_CPPFLAGS="$CPPFLAGS" clean_LDFLAGS="$LDFLAGS" + clean_LDFLAGSPC="$LDFLAGSPC" clean_LIBS="$LIBS" PKGCONFIG="no" - # + if test "$want_idn_path" != "default"; then dnl path has been specified IDN_PCDIR="$want_idn_path/lib$libsuff/pkgconfig" CURL_CHECK_PKGCONFIG(libidn2, [$IDN_PCDIR]) if test "$PKGCONFIG" != "no"; then - IDN_LIBS=`CURL_EXPORT_PCDIR([$IDN_PCDIR]) dnl + IDN_LIBS=`CURL_EXPORT_PCDIR([$IDN_PCDIR]) $PKGCONFIG --libs-only-l libidn2 2>/dev/null` - IDN_LDFLAGS=`CURL_EXPORT_PCDIR([$IDN_PCDIR]) dnl + IDN_LDFLAGS=`CURL_EXPORT_PCDIR([$IDN_PCDIR]) $PKGCONFIG --libs-only-L libidn2 2>/dev/null` - IDN_CPPFLAGS=`CURL_EXPORT_PCDIR([$IDN_PCDIR]) dnl + IDN_CPPFLAGS=`CURL_EXPORT_PCDIR([$IDN_PCDIR]) $PKGCONFIG --cflags-only-I libidn2 2>/dev/null` IDN_DIR=`echo $IDN_LDFLAGS | $SED -e 's/^-L//'` else @@ -2692,7 +2996,7 @@ if test "$want_idn" = "yes"; then IDN_LIBS="-lidn2" fi fi - # + if test "$PKGCONFIG" != "no"; then AC_MSG_NOTICE([pkg-config: IDN_LIBS: "$IDN_LIBS"]) AC_MSG_NOTICE([pkg-config: IDN_LDFLAGS: "$IDN_LDFLAGS"]) @@ -2704,11 +3008,12 @@ if test "$want_idn" = "yes"; then AC_MSG_NOTICE([IDN_CPPFLAGS: "$IDN_CPPFLAGS"]) AC_MSG_NOTICE([IDN_DIR: "$IDN_DIR"]) fi - # + CPPFLAGS="$CPPFLAGS $IDN_CPPFLAGS" LDFLAGS="$LDFLAGS $IDN_LDFLAGS" + LDFLAGSPC="$LDFLAGSPC $IDN_LDFLAGS" LIBS="$IDN_LIBS $LIBS" - # + AC_MSG_CHECKING([if idn2_lookup_ul can be linked]) AC_LINK_IFELSE([ AC_LANG_FUNC_LINK_TRY([idn2_lookup_ul]) @@ -2719,25 +3024,28 @@ if test "$want_idn" = "yes"; then AC_MSG_RESULT([no]) tst_links_libidn="no" ]) - # - AC_CHECK_HEADERS( idn2.h ) + + AC_CHECK_HEADERS(idn2.h) if test "$tst_links_libidn" = "yes"; then AC_DEFINE(HAVE_LIBIDN2, 1, [Define to 1 if you have the `idn2' library (-lidn2).]) dnl different versions of libidn have different setups of these: - AC_SUBST([IDN_ENABLED], [1]) + IDN_ENABLED=1 curl_idn_msg="enabled (libidn2)" - if test -n "$IDN_DIR" -a "x$cross_compiling" != "xyes"; then + if test -n "$IDN_DIR" && test "$cross_compiling" != "yes"; then CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$IDN_DIR" export CURL_LIBRARY_PATH AC_MSG_NOTICE([Added $IDN_DIR to CURL_LIBRARY_PATH]) fi + LIBCURL_PC_REQUIRES_PRIVATE="libidn2 $LIBCURL_PC_REQUIRES_PRIVATE" else - AC_MSG_WARN([Cannot find libraries for IDN support: IDN disabled]) + AC_MSG_WARN([Cannot find libidn2]) CPPFLAGS="$clean_CPPFLAGS" LDFLAGS="$clean_LDFLAGS" + LDFLAGSPC="$clean_LDFLAGSPC" LIBS="$clean_LIBS" + want_idn="no" fi fi @@ -2747,8 +3055,8 @@ dnl ********************************************************************** OPT_H2="yes" -if test "x$disable_http" = "xyes" -o X"$want_hyper" != Xno; then - # without HTTP or with Hyper, nghttp2 is no use +if test "$disable_http" = "yes"; then + dnl without HTTP nghttp2 is no use OPT_H2="no" fi @@ -2771,24 +3079,25 @@ case "$OPT_H2" in dnl --with-nghttp2 option used with path want_nghttp2="yes" want_nghttp2_path="$withval" - want_nghttp2_pkg_config_path="$withval/lib/pkgconfig" + want_nghttp2_pkg_config_path="$OPT_H2/lib/pkgconfig" ;; esac -if test X"$want_nghttp2" != Xno; then +if test "$want_nghttp2" != "no"; then dnl backup the pre-nghttp2 variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" CURL_CHECK_PKGCONFIG(libnghttp2, $want_nghttp2_pkg_config_path) - if test "$PKGCONFIG" != "no" ; then + if test "$PKGCONFIG" != "no"; then LIB_H2=`CURL_EXPORT_PCDIR([$want_nghttp2_pkg_config_path]) $PKGCONFIG --libs-only-l libnghttp2` AC_MSG_NOTICE([-l is $LIB_H2]) - CPP_H2=`CURL_EXPORT_PCDIR([$want_nghttp2_pkg_config_path]) dnl + CPP_H2=`CURL_EXPORT_PCDIR([$want_nghttp2_pkg_config_path]) $PKGCONFIG --cflags-only-I libnghttp2` AC_MSG_NOTICE([-I is $CPP_H2]) @@ -2797,12 +3106,12 @@ if test X"$want_nghttp2" != Xno; then AC_MSG_NOTICE([-L is $LD_H2]) DIR_H2=`echo $LD_H2 | $SED -e 's/^-L//'` - elif test x"$want_nghttp2_path" != x; then + elif test -n "$want_nghttp2_path"; then LIB_H2="-lnghttp2" LD_H2=-L${want_nghttp2_path}/lib$libsuff CPP_H2=-I${want_nghttp2_path}/include DIR_H2=${want_nghttp2_path}/lib$libsuff - elif test X"$want_nghttp2" != Xdefault; then + elif test "$want_nghttp2" != "default"; then dnl no nghttp2 pkg-config found and no custom directory specified, dnl deal with it AC_MSG_ERROR([--with-nghttp2 was specified but could not find libnghttp2 pkg-config file.]) @@ -2811,26 +3120,28 @@ if test X"$want_nghttp2" != Xno; then fi LDFLAGS="$LDFLAGS $LD_H2" + LDFLAGSPC="$LDFLAGSPC $LD_H2" CPPFLAGS="$CPPFLAGS $CPP_H2" LIBS="$LIB_H2 $LIBS" - # use nghttp2_session_get_stream_local_window_size to require nghttp2 - # >= 1.15.0 + dnl use nghttp2_session_get_stream_local_window_size to require nghttp2 + dnl >= 1.15.0 AC_CHECK_LIB(nghttp2, nghttp2_session_get_stream_local_window_size, [ - AC_CHECK_HEADERS(nghttp2/nghttp2.h, + AC_CHECK_HEADERS(nghttp2/nghttp2.h, curl_h2_msg="enabled (nghttp2)" - NGHTTP2_ENABLED=1 AC_DEFINE(USE_NGHTTP2, 1, [if nghttp2 is in use]) - AC_SUBST(USE_NGHTTP2, [1]) - ) + USE_NGHTTP2=1 + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libnghttp2" + ) - CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_H2" - export CURL_LIBRARY_PATH - AC_MSG_NOTICE([Added $DIR_H2 to CURL_LIBRARY_PATH]) + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_H2" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_H2 to CURL_LIBRARY_PATH]) ], dnl not found, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS ) @@ -2842,8 +3153,8 @@ dnl ********************************************************************** OPT_TCP2="no" -if test "x$disable_http" = "xyes"; then - # without HTTP, ngtcp2 is no use +if test "$disable_http" = "yes"; then + dnl without HTTP, ngtcp2 is no use OPT_TCP2="no" fi @@ -2864,25 +3175,31 @@ case "$OPT_TCP2" in *) dnl --with-ngtcp2 option used with path want_tcp2="yes" - want_tcp2_path="$withval/lib/pkgconfig" + want_tcp2_path="$OPT_TCP2/lib/pkgconfig" ;; esac curl_tcp2_msg="no (--with-ngtcp2)" -if test X"$want_tcp2" != Xno; then +if test "$want_tcp2" != "no"; then + + if test "$QUIC_ENABLED" != "yes"; then + AC_MSG_ERROR([the detected TLS library does not support QUIC, making --with-ngtcp2 a no-no]) + fi + dnl backup the pre-ngtcp2 variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" CURL_CHECK_PKGCONFIG(libngtcp2, $want_tcp2_path) - if test "$PKGCONFIG" != "no" ; then + if test "$PKGCONFIG" != "no"; then LIB_TCP2=`CURL_EXPORT_PCDIR([$want_tcp2_path]) $PKGCONFIG --libs-only-l libngtcp2` AC_MSG_NOTICE([-l is $LIB_TCP2]) - CPP_TCP2=`CURL_EXPORT_PCDIR([$want_tcp2_path]) dnl + CPP_TCP2=`CURL_EXPORT_PCDIR([$want_tcp2_path]) $PKGCONFIG --cflags-only-I libngtcp2` AC_MSG_NOTICE([-I is $CPP_TCP2]) @@ -2891,88 +3208,153 @@ if test X"$want_tcp2" != Xno; then AC_MSG_NOTICE([-L is $LD_TCP2]) LDFLAGS="$LDFLAGS $LD_TCP2" + LDFLAGSPC="$LDFLAGSPC $LD_TCP2" CPPFLAGS="$CPPFLAGS $CPP_TCP2" LIBS="$LIB_TCP2 $LIBS" - if test "x$cross_compiling" != "xyes"; then + if test "$cross_compiling" != "yes"; then DIR_TCP2=`echo $LD_TCP2 | $SED -e 's/^-L//'` fi AC_CHECK_LIB(ngtcp2, ngtcp2_conn_client_new_versioned, [ - AC_CHECK_HEADERS(ngtcp2/ngtcp2.h, - NGTCP2_ENABLED=1 + AC_CHECK_HEADERS(ngtcp2/ngtcp2.h, AC_DEFINE(USE_NGTCP2, 1, [if ngtcp2 is in use]) - AC_SUBST(USE_NGTCP2, [1]) + USE_NGTCP2=1 CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_TCP2" export CURL_LIBRARY_PATH AC_MSG_NOTICE([Added $DIR_TCP2 to CURL_LIBRARY_PATH]) - ) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libngtcp2" + ) ], dnl not found, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS ) else dnl no ngtcp2 pkg-config found, deal with it - if test X"$want_tcp2" != Xdefault; then + if test "$want_tcp2" != "default"; then dnl To avoid link errors, we do not allow --with-ngtcp2 without dnl a pkgconfig file AC_MSG_ERROR([--with-ngtcp2 was specified but could not find ngtcp2 pkg-config file.]) fi fi - fi -if test "x$NGTCP2_ENABLED" = "x1" -a "x$OPENSSL_ENABLED" = "x1"; then - dnl backup the pre-ngtcp2_crypto_quictls variables +if test "$USE_NGTCP2" = "1" && test "$OPENSSL_ENABLED" = "1" && test "$HAVE_LIBRESSL" = "1"; then + + dnl backup the pre-ngtcp2_crypto_libressl variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" - CURL_CHECK_PKGCONFIG(libngtcp2_crypto_quictls, $want_tcp2_path) + CURL_CHECK_PKGCONFIG(libngtcp2_crypto_libressl, $want_tcp2_path, 1) - if test "$PKGCONFIG" != "no" ; then - LIB_NGTCP2_CRYPTO_QUICTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path]) + if test "$PKGCONFIG" != "no"; then + LIB_NGTCP2_CRYPTO_LIBRESSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) + $PKGCONFIG --libs-only-l libngtcp2_crypto_libressl` + AC_MSG_NOTICE([-l is $LIB_NGTCP2_CRYPTO_LIBRESSL]) + + CPP_NGTCP2_CRYPTO_LIBRESSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) + $PKGCONFIG --cflags-only-I libngtcp2_crypto_libressl` + AC_MSG_NOTICE([-I is $CPP_NGTCP2_CRYPTO_LIBRESSL]) + + LD_NGTCP2_CRYPTO_LIBRESSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) + $PKGCONFIG --libs-only-L libngtcp2_crypto_libressl` + AC_MSG_NOTICE([-L is $LD_NGTCP2_CRYPTO_LIBRESSL]) + + LDFLAGS="$LDFLAGS $LD_NGTCP2_CRYPTO_LIBRESSL" + LDFLAGSPC="$LDFLAGSPC $LD_NGTCP2_CRYPTO_LIBRESSL" + CPPFLAGS="$CPPFLAGS $CPP_NGTCP2_CRYPTO_LIBRESSL" + LIBS="$LIB_NGTCP2_CRYPTO_LIBRESSL $LIBS" + + if test "$cross_compiling" != "yes"; then + DIR_NGTCP2_CRYPTO_LIBRESSL=`echo $LD_NGTCP2_CRYPTO_LIBRESSL | $SED -e 's/^-L//'` + fi + AC_CHECK_LIB(ngtcp2_crypto_libressl, ngtcp2_crypto_recv_client_initial_cb, + [ + AC_CHECK_HEADERS(ngtcp2/ngtcp2_crypto.h, + USE_NGTCP2=1 + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_NGTCP2_CRYPTO_LIBRESSL" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_NGTCP2_CRYPTO_LIBRESSL to CURL_LIBRARY_PATH]) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libngtcp2_crypto_libressl" + ) + ], + dnl not found, revert back to clean variables + LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC + CPPFLAGS=$CLEANCPPFLAGS + LIBS=$CLEANLIBS + ) + + else + dnl no ngtcp2_crypto_libressl pkg-config found, deal with it + if test "$want_tcp2" != "default"; then + dnl To avoid link errors, we do not allow --with-ngtcp2 without + dnl a pkgconfig file + AC_MSG_WARN([--with-ngtcp2 was specified but could not find ngtcp2_crypto_libressl pkg-config file.]) + dnl Pretend to be quictls to fall back to using ngtcp2_crypto_quictls + fi + HAVE_LIBRESSL=0 + fi +fi + +if test "$USE_NGTCP2" = "1" && test "$OPENSSL_ENABLED" = "1" && test "$HAVE_LIBRESSL" != "1" && + test "$OPENSSL_IS_AWSLC" != "1" && test "$OPENSSL_IS_BORINGSSL" != "1" && test "$OPENSSL_QUIC_API2" != "1"; then + + dnl backup the pre-ngtcp2_crypto_quictls variables + CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" + CLEANCPPFLAGS="$CPPFLAGS" + CLEANLIBS="$LIBS" + + CURL_CHECK_PKGCONFIG(libngtcp2_crypto_quictls, $want_tcp2_path, 1) + + if test "$PKGCONFIG" != "no"; then + LIB_NGTCP2_CRYPTO_QUICTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) $PKGCONFIG --libs-only-l libngtcp2_crypto_quictls` AC_MSG_NOTICE([-l is $LIB_NGTCP2_CRYPTO_QUICTLS]) - CPP_NGTCP2_CRYPTO_QUICTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path]) dnl + CPP_NGTCP2_CRYPTO_QUICTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) $PKGCONFIG --cflags-only-I libngtcp2_crypto_quictls` AC_MSG_NOTICE([-I is $CPP_NGTCP2_CRYPTO_QUICTLS]) - LD_NGTCP2_CRYPTO_QUICTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path]) + LD_NGTCP2_CRYPTO_QUICTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) $PKGCONFIG --libs-only-L libngtcp2_crypto_quictls` AC_MSG_NOTICE([-L is $LD_NGTCP2_CRYPTO_QUICTLS]) LDFLAGS="$LDFLAGS $LD_NGTCP2_CRYPTO_QUICTLS" + LDFLAGSPC="$LDFLAGSPC $LD_NGTCP2_CRYPTO_QUICTLS" CPPFLAGS="$CPPFLAGS $CPP_NGTCP2_CRYPTO_QUICTLS" LIBS="$LIB_NGTCP2_CRYPTO_QUICTLS $LIBS" - if test "x$cross_compiling" != "xyes"; then + if test "$cross_compiling" != "yes"; then DIR_NGTCP2_CRYPTO_QUICTLS=`echo $LD_NGTCP2_CRYPTO_QUICTLS | $SED -e 's/^-L//'` fi AC_CHECK_LIB(ngtcp2_crypto_quictls, ngtcp2_crypto_recv_client_initial_cb, [ - AC_CHECK_HEADERS(ngtcp2/ngtcp2_crypto.h, - NGTCP2_ENABLED=1 - AC_DEFINE(USE_NGTCP2_CRYPTO_QUICTLS, 1, [if ngtcp2_crypto_quictls is in use]) - AC_SUBST(USE_NGTCP2_CRYPTO_QUICTLS, [1]) + AC_CHECK_HEADERS(ngtcp2/ngtcp2_crypto.h, + USE_NGTCP2=1 CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_NGTCP2_CRYPTO_QUICTLS" export CURL_LIBRARY_PATH AC_MSG_NOTICE([Added $DIR_NGTCP2_CRYPTO_QUICTLS to CURL_LIBRARY_PATH]) - ) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libngtcp2_crypto_quictls" + ) ], dnl not found, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS ) else dnl no ngtcp2_crypto_quictls pkg-config found, deal with it - if test X"$want_tcp2" != Xdefault; then + if test "$want_tcp2" != "default"; then dnl To avoid link errors, we do not allow --with-ngtcp2 without dnl a pkgconfig file AC_MSG_ERROR([--with-ngtcp2 was specified but could not find ngtcp2_crypto_quictls pkg-config file.]) @@ -2980,54 +3362,175 @@ if test "x$NGTCP2_ENABLED" = "x1" -a "x$OPENSSL_ENABLED" = "x1"; then fi fi -if test "x$NGTCP2_ENABLED" = "x1" -a "x$GNUTLS_ENABLED" = "x1"; then - dnl backup the pre-ngtcp2_crypto_gnutls variables +if test "$USE_NGTCP2" = "1" && test "$OPENSSL_ENABLED" = "1" && + test "$OPENSSL_IS_AWSLC" != "1" && test "$OPENSSL_IS_BORINGSSL" != "1" && test "$OPENSSL_QUIC_API2" = "1"; then + + dnl backup the pre-ngtcp2_crypto_ossl variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" - CURL_CHECK_PKGCONFIG(libngtcp2_crypto_gnutls, $want_tcp2_path) + CURL_CHECK_PKGCONFIG(libngtcp2_crypto_ossl, $want_tcp2_path, 1) - if test "$PKGCONFIG" != "no" ; then - LIB_NGTCP2_CRYPTO_GNUTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path]) + if test "$PKGCONFIG" != "no"; then + LIB_NGTCP2_CRYPTO_OSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) + $PKGCONFIG --libs-only-l libngtcp2_crypto_ossl` + AC_MSG_NOTICE([-l is $LIB_NGTCP2_CRYPTO_OSSL]) + + CPP_NGTCP2_CRYPTO_OSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) + $PKGCONFIG --cflags-only-I libngtcp2_crypto_ossl` + AC_MSG_NOTICE([-I is $CPP_NGTCP2_CRYPTO_OSSL]) + + LD_NGTCP2_CRYPTO_OSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) + $PKGCONFIG --libs-only-L libngtcp2_crypto_ossl` + AC_MSG_NOTICE([-L is $LD_NGTCP2_CRYPTO_OSSL]) + + LDFLAGS="$LDFLAGS $LD_NGTCP2_CRYPTO_OSSL" + LDFLAGSPC="$LDFLAGSPC $LD_NGTCP2_CRYPTO_OSSL" + CPPFLAGS="$CPPFLAGS $CPP_NGTCP2_CRYPTO_OSSL" + LIBS="$LIB_NGTCP2_CRYPTO_OSSL $LIBS" + + if test "$cross_compiling" != "yes"; then + DIR_NGTCP2_CRYPTO_OSSL=`echo $LD_NGTCP2_CRYPTO_OSSL | $SED -e 's/^-L//'` + fi + AC_CHECK_LIB(ngtcp2_crypto_ossl, ngtcp2_crypto_recv_client_initial_cb, + [ + AC_CHECK_HEADERS(ngtcp2/ngtcp2_crypto.h, + USE_NGTCP2=1 + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_NGTCP2_CRYPTO_OSSL" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_NGTCP2_CRYPTO_OSSL to CURL_LIBRARY_PATH]) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libngtcp2_crypto_ossl" + AC_DEFINE(OPENSSL_QUIC_API2, 1, [openssl with new QUIC API]) + ) + ], + dnl not found, revert back to clean variables + LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC + CPPFLAGS=$CLEANCPPFLAGS + LIBS=$CLEANLIBS + ) + + else + dnl no ngtcp2_crypto_ossl pkg-config found, deal with it + if test "$want_tcp2" != "default"; then + dnl To avoid link errors, we do not allow --with-ngtcp2 without + dnl a pkgconfig file + AC_MSG_ERROR([--with-ngtcp2 was specified but could not find ngtcp2_crypto_ossl pkg-config file.]) + fi + fi +fi + +if test "$USE_NGTCP2" = "1" && test "$OPENSSL_ENABLED" = "1" && + (test "$OPENSSL_IS_AWSLC" = "1" || test "$OPENSSL_IS_BORINGSSL" = "1"); then + + dnl backup the pre-ngtcp2_crypto_boringssl variables + CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" + CLEANCPPFLAGS="$CPPFLAGS" + CLEANLIBS="$LIBS" + + CURL_CHECK_PKGCONFIG(libngtcp2_crypto_boringssl, $want_tcp2_path, 1) + + if test "$PKGCONFIG" != "no"; then + LIB_NGTCP2_CRYPTO_BORINGSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) + $PKGCONFIG --libs-only-l libngtcp2_crypto_boringssl` + AC_MSG_NOTICE([-l is $LIB_NGTCP2_CRYPTO_BORINGSSL]) + + CPP_NGTCP2_CRYPTO_BORINGSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) + $PKGCONFIG --cflags-only-I libngtcp2_crypto_boringssl` + AC_MSG_NOTICE([-I is $CPP_NGTCP2_CRYPTO_BORINGSSL]) + + LD_NGTCP2_CRYPTO_BORINGSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) + $PKGCONFIG --libs-only-L libngtcp2_crypto_boringssl` + AC_MSG_NOTICE([-L is $LD_NGTCP2_CRYPTO_BORINGSSL]) + + LDFLAGS="$LDFLAGS $LD_NGTCP2_CRYPTO_BORINGSSL" + LDFLAGSPC="$LDFLAGSPC $LD_NGTCP2_CRYPTO_BORINGSSL" + CPPFLAGS="$CPPFLAGS $CPP_NGTCP2_CRYPTO_BORINGSSL" + LIBS="$LIB_NGTCP2_CRYPTO_BORINGSSL $LIBS" + + if test "$cross_compiling" != "yes"; then + DIR_NGTCP2_CRYPTO_BORINGSSL=`echo $LD_NGTCP2_CRYPTO_BORINGSSL | $SED -e 's/^-L//'` + fi + AC_CHECK_LIB(ngtcp2_crypto_boringssl, ngtcp2_crypto_recv_client_initial_cb, + [ + AC_CHECK_HEADERS(ngtcp2/ngtcp2_crypto.h, + USE_NGTCP2=1 + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_NGTCP2_CRYPTO_BORINGSSL" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_NGTCP2_CRYPTO_BORINGSSL to CURL_LIBRARY_PATH]) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libngtcp2_crypto_boringssl" + ) + ], + dnl not found, revert back to clean variables + LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC + CPPFLAGS=$CLEANCPPFLAGS + LIBS=$CLEANLIBS + ) + + else + dnl no ngtcp2_crypto_boringssl pkg-config found, deal with it + if test "$want_tcp2" != "default"; then + dnl To avoid link errors, we do not allow --with-ngtcp2 without + dnl a pkgconfig file + AC_MSG_ERROR([--with-ngtcp2 was specified but could not find ngtcp2_crypto_boringssl pkg-config file.]) + fi + fi +fi + +if test "$USE_NGTCP2" = "1" && test "$GNUTLS_ENABLED" = "1"; then + dnl backup the pre-ngtcp2_crypto_gnutls variables + CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" + CLEANCPPFLAGS="$CPPFLAGS" + CLEANLIBS="$LIBS" + + CURL_CHECK_PKGCONFIG(libngtcp2_crypto_gnutls, $want_tcp2_path, 1) + + if test "$PKGCONFIG" != "no"; then + LIB_NGTCP2_CRYPTO_GNUTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) $PKGCONFIG --libs-only-l libngtcp2_crypto_gnutls` AC_MSG_NOTICE([-l is $LIB_NGTCP2_CRYPTO_GNUTLS]) - CPP_NGTCP2_CRYPTO_GNUTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path]) dnl + CPP_NGTCP2_CRYPTO_GNUTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) $PKGCONFIG --cflags-only-I libngtcp2_crypto_gnutls` AC_MSG_NOTICE([-I is $CPP_NGTCP2_CRYPTO_GNUTLS]) - LD_NGTCP2_CRYPTO_GNUTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path]) + LD_NGTCP2_CRYPTO_GNUTLS=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) $PKGCONFIG --libs-only-L libngtcp2_crypto_gnutls` AC_MSG_NOTICE([-L is $LD_NGTCP2_CRYPTO_GNUTLS]) LDFLAGS="$LDFLAGS $LD_NGTCP2_CRYPTO_GNUTLS" + LDFLAGSPC="$LDFLAGSPC $LD_NGTCP2_CRYPTO_GNUTLS" CPPFLAGS="$CPPFLAGS $CPP_NGTCP2_CRYPTO_GNUTLS" LIBS="$LIB_NGTCP2_CRYPTO_GNUTLS $LIBS" - if test "x$cross_compiling" != "xyes"; then + if test "$cross_compiling" != "yes"; then DIR_NGTCP2_CRYPTO_GNUTLS=`echo $LD_NGTCP2_CRYPTO_GNUTLS | $SED -e 's/^-L//'` fi AC_CHECK_LIB(ngtcp2_crypto_gnutls, ngtcp2_crypto_recv_client_initial_cb, [ - AC_CHECK_HEADERS(ngtcp2/ngtcp2_crypto.h, - NGTCP2_ENABLED=1 - AC_DEFINE(USE_NGTCP2_CRYPTO_GNUTLS, 1, [if ngtcp2_crypto_gnutls is in use]) - AC_SUBST(USE_NGTCP2_CRYPTO_GNUTLS, [1]) + AC_CHECK_HEADERS(ngtcp2/ngtcp2_crypto.h, + USE_NGTCP2=1 CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_NGTCP2_CRYPTO_GNUTLS" export CURL_LIBRARY_PATH AC_MSG_NOTICE([Added $DIR_NGTCP2_CRYPTO_GNUTLS to CURL_LIBRARY_PATH]) - ) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libngtcp2_crypto_gnutls" + ) ], dnl not found, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS ) else dnl no ngtcp2_crypto_gnutls pkg-config found, deal with it - if test X"$want_tcp2" != Xdefault; then + if test "$want_tcp2" != "default"; then dnl To avoid link errors, we do not allow --with-ngtcp2 without dnl a pkgconfig file AC_MSG_ERROR([--with-ngtcp2 was specified but could not find ngtcp2_crypto_gnutls pkg-config file.]) @@ -3035,54 +3538,56 @@ if test "x$NGTCP2_ENABLED" = "x1" -a "x$GNUTLS_ENABLED" = "x1"; then fi fi -if test "x$NGTCP2_ENABLED" = "x1" -a "x$WOLFSSL_ENABLED" = "x1"; then +if test "$USE_NGTCP2" = "1" && test "$WOLFSSL_ENABLED" = "1"; then dnl backup the pre-ngtcp2_crypto_wolfssl variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" - CURL_CHECK_PKGCONFIG(libngtcp2_crypto_wolfssl, $want_tcp2_path) + CURL_CHECK_PKGCONFIG(libngtcp2_crypto_wolfssl, $want_tcp2_path, 1) - if test "$PKGCONFIG" != "no" ; then - LIB_NGTCP2_CRYPTO_WOLFSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path]) + if test "$PKGCONFIG" != "no"; then + LIB_NGTCP2_CRYPTO_WOLFSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) $PKGCONFIG --libs-only-l libngtcp2_crypto_wolfssl` AC_MSG_NOTICE([-l is $LIB_NGTCP2_CRYPTO_WOLFSSL]) - CPP_NGTCP2_CRYPTO_WOLFSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path]) dnl + CPP_NGTCP2_CRYPTO_WOLFSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) $PKGCONFIG --cflags-only-I libngtcp2_crypto_wolfssl` AC_MSG_NOTICE([-I is $CPP_NGTCP2_CRYPTO_WOLFSSL]) - LD_NGTCP2_CRYPTO_WOLFSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path]) + LD_NGTCP2_CRYPTO_WOLFSSL=`CURL_EXPORT_PCDIR([$want_tcp2_path], 1) $PKGCONFIG --libs-only-L libngtcp2_crypto_wolfssl` AC_MSG_NOTICE([-L is $LD_NGTCP2_CRYPTO_WOLFSSL]) LDFLAGS="$LDFLAGS $LD_NGTCP2_CRYPTO_WOLFSSL" + LDFLAGSPC="$LDFLAGSPC $LD_NGTCP2_CRYPTO_WOLFSSL" CPPFLAGS="$CPPFLAGS $CPP_NGTCP2_CRYPTO_WOLFSSL" LIBS="$LIB_NGTCP2_CRYPTO_WOLFSSL $LIBS" - if test "x$cross_compiling" != "xyes"; then + if test "$cross_compiling" != "yes"; then DIR_NGTCP2_CRYPTO_WOLFSSL=`echo $LD_NGTCP2_CRYPTO_WOLFSSL | $SED -e 's/^-L//'` fi AC_CHECK_LIB(ngtcp2_crypto_wolfssl, ngtcp2_crypto_recv_client_initial_cb, [ - AC_CHECK_HEADERS(ngtcp2/ngtcp2_crypto.h, - NGTCP2_ENABLED=1 - AC_DEFINE(USE_NGTCP2_CRYPTO_WOLFSSL, 1, [if ngtcp2_crypto_wolfssl is in use]) - AC_SUBST(USE_NGTCP2_CRYPTO_WOLFSSL, [1]) + AC_CHECK_HEADERS(ngtcp2/ngtcp2_crypto.h, + USE_NGTCP2=1 CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_NGTCP2_CRYPTO_WOLFSSL" export CURL_LIBRARY_PATH AC_MSG_NOTICE([Added $DIR_NGTCP2_CRYPTO_WOLFSSL to CURL_LIBRARY_PATH]) - ) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libngtcp2_crypto_wolfssl" + ) ], dnl not found, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS ) else dnl no ngtcp2_crypto_wolfssl pkg-config found, deal with it - if test X"$want_tcp2" != Xdefault; then + if test "$want_tcp2" != "default"; then dnl To avoid link errors, we do not allow --with-ngtcp2 without dnl a pkgconfig file AC_MSG_ERROR([--with-ngtcp2 was specified but could not find ngtcp2_crypto_wolfssl pkg-config file.]) @@ -3096,9 +3601,10 @@ dnl ********************************************************************** OPT_NGHTTP3="yes" -if test "x$NGTCP2_ENABLED" = "x"; then - # without ngtcp2, nghttp3 is of no use for us +if test "$USE_NGTCP2" != "1"; then + dnl without ngtcp2, nghttp3 is of no use for us OPT_NGHTTP3="no" + want_nghttp3="no" fi AC_ARG_WITH(nghttp3, @@ -3118,25 +3624,32 @@ case "$OPT_NGHTTP3" in *) dnl --with-nghttp3 option used with path want_nghttp3="yes" - want_nghttp3_path="$withval/lib/pkgconfig" + want_nghttp3_path="$OPT_NGHTTP3/lib/pkgconfig" ;; esac curl_http3_msg="no (--with-nghttp3)" -if test X"$want_nghttp3" != Xno; then +if test "$want_nghttp3" != "no"; then + + if test "x$USE_NGTCP2" != "x1"; then + dnl without ngtcp2, nghttp3 is of no use for us + AC_MSG_ERROR([nghttp3 enabled without a QUIC library; enable ngtcp2]) + fi + dnl backup the pre-nghttp3 variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" CURL_CHECK_PKGCONFIG(libnghttp3, $want_nghttp3_path) - if test "$PKGCONFIG" != "no" ; then + if test "$PKGCONFIG" != "no"; then LIB_NGHTTP3=`CURL_EXPORT_PCDIR([$want_nghttp3_path]) $PKGCONFIG --libs-only-l libnghttp3` AC_MSG_NOTICE([-l is $LIB_NGHTTP3]) - CPP_NGHTTP3=`CURL_EXPORT_PCDIR([$want_nghttp3_path]) dnl + CPP_NGHTTP3=`CURL_EXPORT_PCDIR([$want_nghttp3_path]) $PKGCONFIG --cflags-only-I libnghttp3` AC_MSG_NOTICE([-I is $CPP_NGHTTP3]) @@ -3145,40 +3658,47 @@ if test X"$want_nghttp3" != Xno; then AC_MSG_NOTICE([-L is $LD_NGHTTP3]) LDFLAGS="$LDFLAGS $LD_NGHTTP3" + LDFLAGSPC="$LDFLAGSPC $LD_NGHTTP3" CPPFLAGS="$CPPFLAGS $CPP_NGHTTP3" LIBS="$LIB_NGHTTP3 $LIBS" - if test "x$cross_compiling" != "xyes"; then + if test "$cross_compiling" != "yes"; then DIR_NGHTTP3=`echo $LD_NGHTTP3 | $SED -e 's/^-L//'` fi AC_CHECK_LIB(nghttp3, nghttp3_conn_client_new_versioned, [ - AC_CHECK_HEADERS(nghttp3/nghttp3.h, - curl_h3_msg="enabled (ngtcp2 + nghttp3)" - NGHTTP3_ENABLED=1 + AC_CHECK_HEADERS(nghttp3/nghttp3.h, AC_DEFINE(USE_NGHTTP3, 1, [if nghttp3 is in use]) - AC_SUBST(USE_NGHTTP3, [1]) + USE_NGHTTP3=1 CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_NGHTTP3" export CURL_LIBRARY_PATH AC_MSG_NOTICE([Added $DIR_NGHTTP3 to CURL_LIBRARY_PATH]) - experimental="$experimental HTTP3" - ) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libnghttp3" + ) ], dnl not found, revert back to clean variables LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC CPPFLAGS=$CLEANCPPFLAGS LIBS=$CLEANLIBS ) - else dnl no nghttp3 pkg-config found, deal with it - if test X"$want_nghttp3" != Xdefault; then + if test "$want_nghttp3" != "default"; then dnl To avoid link errors, we do not allow --with-nghttp3 without dnl a pkgconfig file AC_MSG_ERROR([--with-nghttp3 was specified but could not find nghttp3 pkg-config file.]) fi fi +fi +dnl ********************************************************************** +dnl Check for ngtcp2 and nghttp3 (HTTP/3 with ngtcp2 + nghttp3) +dnl ********************************************************************** + +if test "$USE_NGTCP2" = "1" && test "$USE_NGHTTP3" = "1"; then + USE_NGTCP2_H3=1 + curl_h3_msg="enabled (ngtcp2 + nghttp3)" fi dnl ********************************************************************** @@ -3187,14 +3707,14 @@ dnl ********************************************************************** OPT_QUICHE="no" -if test "x$disable_http" = "xyes" -o "x$USE_NGTCP" = "x1"; then - # without HTTP or with ngtcp2, quiche is no use +if test "$disable_http" = "yes" || test "$USE_NGTCP" = "1"; then + dnl without HTTP or with ngtcp2, quiche is no use OPT_QUICHE="no" fi AC_ARG_WITH(quiche, -AS_HELP_STRING([--with-quiche=PATH],[Enable quiche usage]) -AS_HELP_STRING([--without-quiche],[Disable quiche usage]), +AS_HELP_STRING([--with-quiche=PATH],[Enable quiche usage (experimental)]) +AS_HELP_STRING([--without-quiche],[Disable quiche usage (experimental)]), [OPT_QUICHE=$withval]) case "$OPT_QUICHE" in no) @@ -3213,25 +3733,30 @@ case "$OPT_QUICHE" in ;; esac -if test X"$want_quiche" != Xno; then +if test "$want_quiche" != "no"; then - if test "$NGHTTP3_ENABLED" = 1; then + if test "$QUIC_ENABLED" != "yes"; then + AC_MSG_ERROR([the detected TLS library does not support QUIC, making --with-quiche a no-no]) + fi + + if test "$NGHTTP3_ENABLED" = "1"; then AC_MSG_ERROR([--with-quiche and --with-ngtcp2 are mutually exclusive]) fi dnl backup the pre-quiche variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" CURL_CHECK_PKGCONFIG(quiche, $want_quiche_path) - if test "$PKGCONFIG" != "no" ; then + if test "$PKGCONFIG" != "no"; then LIB_QUICHE=`CURL_EXPORT_PCDIR([$want_quiche_path]) $PKGCONFIG --libs-only-l quiche` AC_MSG_NOTICE([-l is $LIB_QUICHE]) - CPP_QUICHE=`CURL_EXPORT_PCDIR([$want_quiche_path]) dnl + CPP_QUICHE=`CURL_EXPORT_PCDIR([$want_quiche_path]) $PKGCONFIG --cflags-only-I quiche` AC_MSG_NOTICE([-I is $CPP_QUICHE]) @@ -3240,38 +3765,39 @@ if test X"$want_quiche" != Xno; then AC_MSG_NOTICE([-L is $LD_QUICHE]) LDFLAGS="$LDFLAGS $LD_QUICHE" + LDFLAGSPC="$LDFLAGSPC $LD_QUICHE" CPPFLAGS="$CPPFLAGS $CPP_QUICHE" LIBS="$LIB_QUICHE $LIBS" - if test "x$cross_compiling" != "xyes"; then + if test "$cross_compiling" != "yes"; then DIR_QUICHE=`echo $LD_QUICHE | $SED -e 's/^-L//'` fi AC_CHECK_LIB(quiche, quiche_conn_send_ack_eliciting, [ - AC_CHECK_HEADERS(quiche.h, - experimental="$experimental HTTP3" + AC_CHECK_HEADERS(quiche.h, + experimental="$experimental Quiche" AC_MSG_NOTICE([HTTP3 support is experimental]) curl_h3_msg="enabled (quiche)" - QUICHE_ENABLED=1 AC_DEFINE(USE_QUICHE, 1, [if quiche is in use]) - AC_SUBST(USE_QUICHE, [1]) + USE_QUICHE=1 AC_CHECK_FUNCS([quiche_conn_set_qlog_fd]) CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_QUICHE" export CURL_LIBRARY_PATH - AC_MSG_NOTICE([Added $DIR_QUICHE to CURL_LIBRARY_PATH]), + AC_MSG_NOTICE([Added $DIR_QUICHE to CURL_LIBRARY_PATH]) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE quiche", [], [ -AC_INCLUDES_DEFAULT -#include + AC_INCLUDES_DEFAULT + #include ] - ) + ) ], dnl not found, revert back to clean variables - AC_MSG_ERROR([couldn't use quiche]) + AC_MSG_ERROR([could not use quiche]) ) else dnl no quiche pkg-config found, deal with it - if test X"$want_quiche" != Xdefault; then + if test "$want_quiche" != "default"; then dnl To avoid link errors, we do not allow --with-quiche without dnl a pkgconfig file AC_MSG_ERROR([--with-quiche was specified but could not find quiche pkg-config file.]) @@ -3280,75 +3806,91 @@ AC_INCLUDES_DEFAULT fi dnl ********************************************************************** -dnl Check for msh3 (QUIC) +dnl libuv is only ever used for debug purposes dnl ********************************************************************** -OPT_MSH3="no" - -if test "x$disable_http" = "xyes" -o "x$USE_NGTCP" = "x1"; then - # without HTTP or with ngtcp2, msh3 is no use - OPT_MSH3="no" -fi - -AC_ARG_WITH(msh3, -AS_HELP_STRING([--with-msh3=PATH],[Enable msh3 usage]) -AS_HELP_STRING([--without-msh3],[Disable msh3 usage]), - [OPT_MSH3=$withval]) -case "$OPT_MSH3" in +OPT_LIBUV=no +AC_ARG_WITH(libuv, +AS_HELP_STRING([--with-libuv=PATH],[Enable libuv]) +AS_HELP_STRING([--without-libuv],[Disable libuv]), + [OPT_LIBUV=$withval]) +case "$OPT_LIBUV" in no) - dnl --without-msh3 option used - want_msh3="no" + dnl --without-libuv option used + want_libuv="no" ;; yes) - dnl --with-msh3 option used without path - want_msh3="default" - want_msh3_path="" + dnl --with-libuv option used without path + want_libuv="default" + want_libuv_path="" ;; *) - dnl --with-msh3 option used with path - want_msh3="yes" - want_msh3_path="$withval" + dnl --with-libuv option used with path + want_libuv="yes" + want_libuv_path="$withval" ;; esac -if test X"$want_msh3" != Xno; then - - if test "$NGHTTP3_ENABLED" = 1; then - AC_MSG_ERROR([--with-msh3 and --with-ngtcp2 are mutually exclusive]) +if test "$want_libuv" != "no"; then + if test "$want_debug" != "yes"; then + AC_MSG_ERROR([Using libuv without debug support enabled is useless]) fi - dnl backup the pre-msh3 variables + dnl backup the pre-libuv variables CLEANLDFLAGS="$LDFLAGS" + CLEANLDFLAGSPC="$LDFLAGSPC" CLEANCPPFLAGS="$CPPFLAGS" CLEANLIBS="$LIBS" - if test -n "$want_msh3_path"; then - LD_MSH3="-L$want_msh3_path/lib" - CPP_MSH3="-I$want_msh3_path/include" - DIR_MSH3="$want_msh3_path/lib" - LDFLAGS="$LDFLAGS $LD_MSH3" - CPPFLAGS="$CPPFLAGS $CPP_MSH3" - fi - LIBS="-lmsh3 $LIBS" + CURL_CHECK_PKGCONFIG(libuv, $want_libuv_path) + + if test "$PKGCONFIG" != "no"; then + LIB_LIBUV=`CURL_EXPORT_PCDIR([$want_libuv_path]) + $PKGCONFIG --libs-only-l libuv` + AC_MSG_NOTICE([-l is $LIB_LIBUV]) + + CPP_LIBUV=`CURL_EXPORT_PCDIR([$want_libuv_path]) + $PKGCONFIG --cflags-only-I libuv` + AC_MSG_NOTICE([-I is $CPP_LIBUV]) + + LD_LIBUV=`CURL_EXPORT_PCDIR([$want_libuv_path]) + $PKGCONFIG --libs-only-L libuv` + AC_MSG_NOTICE([-L is $LD_LIBUV]) + + LDFLAGS="$LDFLAGS $LD_LIBUV" + LDFLAGSPC="$LDFLAGSPC $LD_LIBUV" + CPPFLAGS="$CPPFLAGS $CPP_LIBUV" + LIBS="$LIB_LIBUV $LIBS" + + if test "$cross_compiling" != "yes"; then + DIR_LIBUV=`echo $LD_LIBUV | $SED -e 's/^-L//'` + fi + AC_CHECK_LIB(uv, uv_default_loop, + [ + AC_CHECK_HEADERS(uv.h, + AC_DEFINE(USE_LIBUV, 1, [if libuv is in use]) + USE_LIBUV=1 + CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_LIBUV" + export CURL_LIBRARY_PATH + AC_MSG_NOTICE([Added $DIR_LIBUV to CURL_LIBRARY_PATH]) + LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE libuv" + ) + ], + dnl not found, revert back to clean variables + LDFLAGS=$CLEANLDFLAGS + LDFLAGSPC=$CLEANLDFLAGSPC + CPPFLAGS=$CLEANCPPFLAGS + LIBS=$CLEANLIBS + ) + else + dnl no libuv pkg-config found, deal with it + if test "$want_libuv" != "default"; then + dnl To avoid link errors, we do not allow --with-libuv without + dnl a pkgconfig file + AC_MSG_ERROR([--with-libuv was specified but could not find libuv pkg-config file.]) + fi + fi - AC_CHECK_LIB(msh3, MsH3ApiOpen, - [ - AC_CHECK_HEADERS(msh3.h, - curl_h3_msg="enabled (msh3)" - MSH3_ENABLED=1 - AC_DEFINE(USE_MSH3, 1, [if msh3 is in use]) - AC_SUBST(USE_MSH3, [1]) - CURL_LIBRARY_PATH="$CURL_LIBRARY_PATH:$DIR_MSH3" - export CURL_LIBRARY_PATH - AC_MSG_NOTICE([Added $DIR_MSH3 to CURL_LIBRARY_PATH]), - experimental="$experimental HTTP3" - ) - ], - dnl not found, revert back to clean variables - LDFLAGS=$CLEANLDFLAGS - CPPFLAGS=$CLEANCPPFLAGS - LIBS=$CLEANLIBS - ) fi dnl ********************************************************************** @@ -3361,10 +3903,10 @@ AS_HELP_STRING([--with-zsh-functions-dir=PATH],[Install zsh completions to PATH] AS_HELP_STRING([--without-zsh-functions-dir],[Do not install zsh completions]), [OPT_ZSH_FPATH=$withval]) case "$OPT_ZSH_FPATH" in - no) + default|no) dnl --without-zsh-functions-dir option used ;; - default|yes) + yes) dnl --with-zsh-functions-dir option used without path ZSH_FUNCTIONS_DIR="$datarootdir/zsh/site-functions" AC_SUBST(ZSH_FUNCTIONS_DIR) @@ -3375,6 +3917,11 @@ case "$OPT_ZSH_FPATH" in AC_SUBST(ZSH_FUNCTIONS_DIR) ;; esac +if test -z "$PERL" && test -n "$ZSH_FUNCTIONS_DIR"; then + AC_MSG_WARN([perl was not found. Cannot install zsh completions.]) + ZSH_FUNCTIONS_DIR='' +fi +AM_CONDITIONAL(USE_ZSH_COMPLETION, test -n "$ZSH_FUNCTIONS_DIR") dnl ********************************************************************** dnl Check for fish completion path @@ -3386,14 +3933,14 @@ AS_HELP_STRING([--with-fish-functions-dir=PATH],[Install fish completions to PAT AS_HELP_STRING([--without-fish-functions-dir],[Do not install fish completions]), [OPT_FISH_FPATH=$withval]) case "$OPT_FISH_FPATH" in - no) + default|no) dnl --without-fish-functions-dir option used ;; - default|yes) + yes) dnl --with-fish-functions-dir option used without path CURL_CHECK_PKGCONFIG(fish) - if test "$PKGCONFIG" != "no" ; then - FISH_FUNCTIONS_DIR="$($PKGCONFIG --variable completionsdir fish)" + if test "$PKGCONFIG" != "no"; then + FISH_FUNCTIONS_DIR=`$PKGCONFIG --variable completionsdir fish` else FISH_FUNCTIONS_DIR="$datarootdir/fish/vendor_completions.d" fi @@ -3405,58 +3952,54 @@ case "$OPT_FISH_FPATH" in AC_SUBST(FISH_FUNCTIONS_DIR) ;; esac +if test -z "$PERL" && test -n "$FISH_FUNCTIONS_DIR"; then + AC_MSG_WARN([perl was not found. Cannot install fish completions.]) + FISH_FUNCTIONS_DIR='' +fi +AM_CONDITIONAL(USE_FISH_COMPLETION, test -n "$FISH_FUNCTIONS_DIR") -dnl Now check for the very most basic headers. Then we can use these +dnl Now check for the most basic headers. Then we can use these dnl ones as default-headers when checking for the rest! AC_CHECK_HEADERS( - sys/types.h \ - sys/time.h \ - sys/select.h \ - sys/socket.h \ - sys/ioctl.h \ - sys/uio.h \ - unistd.h \ - stdlib.h \ - arpa/inet.h \ - net/if.h \ - netinet/in.h \ - netinet/in6.h \ - sys/un.h \ - linux/tcp.h \ - netinet/tcp.h \ - netinet/udp.h \ - netdb.h \ - sys/sockio.h \ - sys/stat.h \ - sys/param.h \ - termios.h \ - termio.h \ - fcntl.h \ - io.h \ - pwd.h \ - utime.h \ - sys/utime.h \ - sys/poll.h \ - poll.h \ - socket.h \ - sys/resource.h \ - libgen.h \ - locale.h \ - stdbool.h \ - arpa/tftp.h \ - sys/filio.h \ - sys/wait.h \ - setjmp.h, -dnl to do if not found + sys/types.h \ + sys/select.h \ + sys/ioctl.h \ + unistd.h \ + arpa/inet.h \ + net/if.h \ + netinet/in.h \ + netinet/in6.h \ + sys/un.h \ + linux/tcp.h \ + netinet/tcp.h \ + netinet/udp.h \ + netdb.h \ + sys/sockio.h \ + sys/param.h \ + termios.h \ + termio.h \ + fcntl.h \ + io.h \ + pwd.h \ + utime.h \ + sys/utime.h \ + sys/poll.h \ + poll.h \ + sys/resource.h \ + libgen.h \ + locale.h \ + stdbool.h \ + sys/filio.h \ + sys/eventfd.h, [], -dnl to do if found [], -dnl default includes +/* default includes */ [ +#include #ifdef HAVE_SYS_TYPES_H #include #endif -#ifdef HAVE_SYS_TIME_H +#if !defined(_WIN32) || defined(__MINGW32__) #include #endif #ifdef HAVE_SYS_SELECT_H @@ -3464,25 +4007,23 @@ dnl default includes #elif defined(HAVE_UNISTD_H) #include #endif -#ifdef HAVE_SYS_SOCKET_H +#ifndef _WIN32 #include #endif #ifdef HAVE_NETINET_IN_H #include #endif #ifdef HAVE_NETINET_IN6_H -#include +#include /* is this really required to detect other headers? */ #endif #ifdef HAVE_SYS_UN_H -#include +#include /* is this really required to detect other headers? */ #endif ] ) - dnl Checks for typedefs, structures, and compiler characteristics. AC_C_CONST -CURL_CHECK_VARIADIC_MACROS AC_TYPE_SIZE_T CURL_CHECK_STRUCT_TIMEVAL @@ -3504,21 +4045,15 @@ CURL_SIZEOF(curl_socket_t, [ ]) CPPFLAGS=$o -AC_CHECK_TYPE(long long, - [AC_DEFINE(HAVE_LONGLONG, 1, - [Define to 1 if the compiler supports the 'long long' data type.])] - longlong="yes" -) - -if test ${ac_cv_sizeof_curl_off_t} -lt 8; then - AC_MSG_ERROR([64 bit curl_off_t is required]) +if test "$ac_cv_sizeof_curl_off_t" -lt 8; then + AC_MSG_ERROR([64-bit curl_off_t is required]) fi -# check for ssize_t +dnl check for ssize_t AC_CHECK_TYPE(ssize_t, , - AC_DEFINE(ssize_t, int, [the signed version of size_t])) + AC_DEFINE(ssize_t, int, [the signed version of size_t])) -# check for bool type +dnl check for bool type AC_CHECK_TYPE([bool],[ AC_DEFINE(HAVE_BOOL_T, 1, [Define to 1 if bool is an available type.]) @@ -3531,27 +4066,16 @@ AC_CHECK_TYPE([bool],[ #endif ]) -# check for sa_family_t -AC_CHECK_TYPE(sa_family_t, - AC_DEFINE(CURL_SA_FAMILY_T, sa_family_t, [IP address type in sockaddr]), - [ - # The windows name? - AC_CHECK_TYPE(ADDRESS_FAMILY, - AC_DEFINE(CURL_SA_FAMILY_T, ADDRESS_FAMILY, [IP address type in sockaddr]), - AC_DEFINE(CURL_SA_FAMILY_T, unsigned short, [IP address type in sockaddr]), - [ -#ifdef HAVE_SYS_SOCKET_H -#include -#endif - ]) - ], -[ -#ifdef HAVE_SYS_SOCKET_H -#include -#endif -]) +if test "$curl_cv_native_windows" != "yes"; then + dnl check for sa_family_t + AC_CHECK_TYPE(sa_family_t, + AC_DEFINE(HAVE_SA_FAMILY_T, 1, [Define to 1 if symbol `sa_family_t' exists]),, + [ + #include + ]) +fi -# check for suseconds_t +dnl check for suseconds_t AC_CHECK_TYPE([suseconds_t],[ AC_DEFINE(HAVE_SUSECONDS_T, 1, [Define to 1 if suseconds_t is an available type.]) @@ -3559,33 +4083,35 @@ AC_CHECK_TYPE([suseconds_t],[ #ifdef HAVE_SYS_TYPES_H #include #endif -#ifdef HAVE_SYS_TIME_H +#ifndef _WIN32 #include #endif ]) -AC_MSG_CHECKING([if time_t is unsigned]) -CURL_RUN_IFELSE( - [ - #include - #include - int main(void) { - time_t t = -1; - return (t < 0); - } - ],[ - AC_MSG_RESULT([yes]) - AC_DEFINE(HAVE_TIME_T_UNSIGNED, 1, [Define this if time_t is unsigned]) -],[ - AC_MSG_RESULT([no]) -],[ - dnl cross-compiling, most systems are unsigned - AC_MSG_RESULT([no]) -]) - -CURL_CONFIGURE_PULL_SYS_POLL - -TYPE_IN_ADDR_T +case $host_os in + amigaos*|msdos*) + AC_DEFINE(HAVE_TIME_T_UNSIGNED, 1, [Define this if time_t is unsigned]) + ;; + *) + AC_MSG_CHECKING([if time_t is unsigned]) + CURL_RUN_IFELSE( + [ + #include + int main(void) { + time_t t = -1; + return t < 0; + } + ],[ + AC_MSG_RESULT([yes]) + AC_DEFINE(HAVE_TIME_T_UNSIGNED, 1, [Define this if time_t is unsigned]) + ],[ + AC_MSG_RESULT([no]) + ],[ + dnl cross-compiling, most systems are signed + AC_MSG_RESULT([no]) + ]) + ;; +esac TYPE_SOCKADDR_STORAGE @@ -3593,62 +4119,46 @@ CURL_CHECK_FUNC_SELECT CURL_CHECK_FUNC_RECV CURL_CHECK_FUNC_SEND -CURL_CHECK_MSG_NOSIGNAL CURL_CHECK_FUNC_ALARM CURL_CHECK_FUNC_BASENAME CURL_CHECK_FUNC_CLOSESOCKET CURL_CHECK_FUNC_CLOSESOCKET_CAMEL -CURL_CHECK_FUNC_CONNECT CURL_CHECK_FUNC_FCNTL CURL_CHECK_FUNC_FREEADDRINFO CURL_CHECK_FUNC_FSETXATTR -CURL_CHECK_FUNC_FTRUNCATE CURL_CHECK_FUNC_GETADDRINFO -CURL_CHECK_FUNC_GETHOSTBYNAME CURL_CHECK_FUNC_GETHOSTBYNAME_R CURL_CHECK_FUNC_GETHOSTNAME +CURL_CHECK_FUNC_GETIFADDRS CURL_CHECK_FUNC_GETPEERNAME CURL_CHECK_FUNC_GETSOCKNAME -CURL_CHECK_FUNC_IF_NAMETOINDEX -CURL_CHECK_FUNC_GETIFADDRS CURL_CHECK_FUNC_GMTIME_R -CURL_CHECK_FUNC_INET_NTOP -CURL_CHECK_FUNC_INET_PTON +CURL_CHECK_FUNC_IOCTL CURL_CHECK_FUNC_IOCTLSOCKET CURL_CHECK_FUNC_IOCTLSOCKET_CAMEL +CURL_CHECK_FUNC_LOCALTIME_R CURL_CHECK_FUNC_MEMRCHR -CURL_CHECK_FUNC_POLL CURL_CHECK_FUNC_SIGACTION CURL_CHECK_FUNC_SIGINTERRUPT CURL_CHECK_FUNC_SIGNAL CURL_CHECK_FUNC_SIGSETJMP CURL_CHECK_FUNC_SOCKET CURL_CHECK_FUNC_SOCKETPAIR -CURL_CHECK_FUNC_STRCASECMP -CURL_CHECK_FUNC_STRCMPI -CURL_CHECK_FUNC_STRDUP CURL_CHECK_FUNC_STRERROR_R -CURL_CHECK_FUNC_STRICMP -CURL_CHECK_FUNC_STRTOK_R -CURL_CHECK_FUNC_STRTOLL case $host in *msdosdjgpp) - ac_cv_func_pipe=no - skipcheck_pipe=yes - AC_MSG_NOTICE([skip check for pipe on msdosdjgpp]) + ac_cv_func_pipe=no + skipcheck_pipe=yes + AC_MSG_NOTICE([skip check for pipe on msdosdjgpp]) ;; esac -AC_CHECK_DECLS([getpwuid_r], [], [AC_DEFINE(HAVE_DECL_GETPWUID_R_MISSING, 1, "Set if getpwuid_r() declaration is missing")], - [[#include - #include ]]) - - -AC_CHECK_FUNCS([fnmatch \ - fchmod \ - fork \ +AC_CHECK_FUNCS([\ + accept4 \ + eventfd \ + fnmatch \ geteuid \ getpass_r \ getppid \ @@ -3656,156 +4166,90 @@ AC_CHECK_FUNCS([fnmatch \ getpwuid_r \ getrlimit \ gettimeofday \ - if_nametoindex \ mach_absolute_time \ pipe \ - sched_yield \ + poll \ + sendmmsg \ sendmsg \ setlocale \ - setmode \ setrlimit \ - snprintf \ utime \ utimes \ - arc4random -],[ -],[ - func="$ac_func" - eval skipcheck=\$skipcheck_$func - if test "x$skipcheck" != "xyes"; then - AC_MSG_CHECKING([deeper for $func]) - AC_LINK_IFELSE([ - AC_LANG_PROGRAM([[ - ]],[[ - $func (); - ]]) - ],[ - AC_MSG_RESULT([yes]) - eval "ac_cv_func_$func=yes" - AC_DEFINE_UNQUOTED(XC_SH_TR_CPP([HAVE_$func]), [1], - [Define to 1 if you have the $func function.]) - ],[ - AC_MSG_RESULT([but still no]) - ]) - fi ]) +if test "$curl_cv_apple" != "yes"; then + dnl Apple platforms do not offer pipe2(), but the iPhone Simulator-specific + dnl /usr/lib/system/libsystem_sim_kernel.dylib exports it. To avoid false + dnl detection, omit this feature check for Apple targets. + AC_CHECK_FUNCS([\ + pipe2 \ + ]) +fi + +if test "$curl_cv_native_windows" != "yes"; then + AC_CHECK_FUNCS([\ + if_nametoindex \ + realpath \ + sched_yield \ + ]) + CURL_CHECK_FUNC_INET_NTOP + CURL_CHECK_FUNC_INET_PTON + CURL_CHECK_FUNC_STRCASECMP + CURL_CHECK_FUNC_STRCMPI + CURL_CHECK_FUNC_STRICMP + + CURL_CHECK_FUNC_MEMSET_S + if test "$curl_cv_func_memset_s" = "no"; then + AC_CHECK_FUNCS([memset_explicit]) + fi +fi + +if test -z "$ssl_backends"; then + AC_CHECK_FUNCS([arc4random]) +fi + +if test "$curl_cv_native_windows" != "yes"; then + AC_CHECK_FUNCS([fseeko]) + + dnl On Android, the only way to know if fseeko can be used is to see if it is + dnl declared or not (for this API level), as the symbol always exists in the + dnl lib. + AC_CHECK_DECL([fseeko], + [AC_DEFINE([HAVE_DECL_FSEEKO], [1], + [Define to 1 if you have the fseeko declaration])], + [], + [[#include ]]) +fi + CURL_CHECK_NONBLOCKING_SOCKET -dnl ************************************************************ -dnl nroff tool stuff -dnl - -AC_PATH_PROG( PERL, perl, , - $PATH:/usr/local/bin/perl:/usr/bin/:/usr/local/bin ) -AC_SUBST(PERL) - -AC_PATH_PROGS( NROFF, gnroff nroff, , - $PATH:/usr/bin/:/usr/local/bin ) -AC_SUBST(NROFF) - -if test -n "$NROFF"; then - dnl only check for nroff options if an nroff command was found - - AC_MSG_CHECKING([how to use *nroff to get plain text from man pages]) - MANOPT="-man" - mancheck=`echo foo | $NROFF $MANOPT 2>/dev/null` - if test -z "$mancheck"; then - MANOPT="-mandoc" - mancheck=`echo foo | $NROFF $MANOPT 2>/dev/null` - if test -z "$mancheck"; then - MANOPT="" - AC_MSG_RESULT([failed]) - AC_MSG_WARN([found no *nroff option to get plaintext from man pages]) - else - AC_MSG_RESULT([$MANOPT]) - fi - else - AC_MSG_RESULT([$MANOPT]) - fi - AC_SUBST(MANOPT) -fi - -if test -z "$MANOPT" -then - dnl if no nroff tool was found, or no option that could convert man pages - dnl was found, then disable the built-in manual stuff - AC_MSG_WARN([disabling built-in manual]) - USE_MANUAL="no"; -fi +dnl set variable for use in automakefile(s) +AM_CONDITIONAL(BUILD_DOCS, test "$BUILD_DOCS" = "1") dnl ************************************************************************* dnl If the manual variable still is set, then we go with providing a built-in dnl manual if test "$USE_MANUAL" = "1"; then - AC_DEFINE(USE_MANUAL, 1, [If you want to build curl with the built-in manual]) curl_manual_msg="enabled" fi dnl set variable for use in automakefile(s) -AM_CONDITIONAL(USE_MANUAL, test x"$USE_MANUAL" = x1) +AM_CONDITIONAL(USE_MANUAL, test "$USE_MANUAL" = "1") CURL_CHECK_LIB_ARES +CURL_CHECK_OPTION_THREADED_RESOLVER -if test "x$curl_cv_native_windows" != "xyes" && - test "x$enable_shared" = "xyes"; then - build_libhostname=yes -else - build_libhostname=no -fi -AM_CONDITIONAL(BUILD_LIBHOSTNAME, test x$build_libhostname = xyes) - -if test "x$want_ares" != xyes; then - CURL_CHECK_OPTION_THREADED_RESOLVER -fi - -dnl ************************************************************ -dnl disable POSIX threads -dnl -AC_MSG_CHECKING([whether to use POSIX threads for threaded resolver]) -AC_ARG_ENABLE(pthreads, -AS_HELP_STRING([--enable-pthreads], - [Enable POSIX threads (default for threaded resolver)]) -AS_HELP_STRING([--disable-pthreads],[Disable POSIX threads]), -[ case "$enableval" in - no) AC_MSG_RESULT(no) - want_pthreads=no - ;; - *) AC_MSG_RESULT(yes) - want_pthreads=yes - ;; - esac ], [ - AC_MSG_RESULT(auto) - want_pthreads=auto - ] -) - -dnl turn off pthreads if rt is disabled -if test "$want_pthreads" != "no"; then - if test "$want_pthreads" = "yes" && test "$dontwant_rt" = "yes"; then - AC_MSG_ERROR([options --enable-pthreads and --disable-rt are mutually exclusive]) - fi - if test "$dontwant_rt" != "no"; then - dnl if --enable-pthreads was explicit then warn it's being ignored - if test "$want_pthreads" = "yes"; then - AC_MSG_WARN([--enable-pthreads Ignored since librt is disabled.]) - fi - want_pthreads=no - fi -fi - -dnl turn off pthreads if no threaded resolver -if test "$want_pthreads" != "no" && test "$want_thres" != "yes"; then - want_pthreads=no +if test "$ipv6" = "yes" && test "$curl_cv_apple" = "yes"; then + CURL_DARWIN_SYSTEMCONFIGURATION fi dnl detect pthreads -if test "$want_pthreads" != "no"; then +if test "$curl_cv_native_windows" != "yes"; then AC_CHECK_HEADER(pthread.h, - [ AC_DEFINE(HAVE_PTHREAD_H, 1, [if you have ]) + [ save_CFLAGS="$CFLAGS" - dnl When statically linking against boringssl, -lpthread is added to LIBS. + dnl When statically linking against BoringSSL, -lpthread is added to LIBS. dnl Make sure to that this does not pass the check below, we really want dnl -pthread in CFLAGS as recommended for GCC. This also ensures that dnl lib1541 and lib1565 tests are built with these options. Otherwise @@ -3814,73 +4258,98 @@ if test "$want_pthreads" != "no"; then LIBS= dnl Check for libc variants without a separate pthread lib like bionic - AC_CHECK_FUNC(pthread_create, [USE_THREADS_POSIX=1] ) + AC_CHECK_FUNC(pthread_create, [HAVE_THREADS_POSIX=1] ) LIBS="$save_LIBS" - dnl on HPUX, life is more complicated... case $host in - *-hp-hpux*) - dnl it doesn't actually work without -lpthread - USE_THREADS_POSIX="" - ;; - *) - ;; + *-hp-hpux*) + CFLAGS="$CFLAGS -mt" + ;; + *) + ;; esac - dnl if it wasn't found without lib, search for it in pthread lib - if test "$USE_THREADS_POSIX" != "1" - then - # assign PTHREAD for pkg-config use + dnl if it was not found without lib, search for it in pthread lib + if test "$HAVE_THREADS_POSIX" != "1"; then + dnl assign PTHREAD for pkg-config use PTHREAD=" -pthread" case $host in - *-ibm-aix*) - dnl Check if compiler is xlC - COMPILER_VERSION=`"$CC" -qversion 2>/dev/null` - if test x"$COMPILER_VERSION" = "x"; then - CFLAGS="$CFLAGS -pthread" - else - CFLAGS="$CFLAGS -qthreaded" - fi - ;; - powerpc-*amigaos*) - dnl No -pthread option, but link with -lpthread - PTHREAD=" -lpthread" - ;; - *) - CFLAGS="$CFLAGS -pthread" - ;; + *-ibm-aix*) + dnl Check if compiler is xlC + COMPILER_VERSION=`"$CC" -qversion 2>/dev/null` + if test -z "$COMPILER_VERSION"; then + CFLAGS="$CFLAGS -pthread" + else + CFLAGS="$CFLAGS -qthreaded" + fi + ;; + powerpc-*amigaos*) + dnl No -pthread option, but link with -lpthread + PTHREAD=" -lpthread" + ;; + *) + CFLAGS="$CFLAGS -pthread" + ;; esac AC_CHECK_LIB(pthread, pthread_create, - [USE_THREADS_POSIX=1], + [HAVE_THREADS_POSIX=1], [ CFLAGS="$save_CFLAGS"]) fi - - if test "x$USE_THREADS_POSIX" = "x1" - then - AC_DEFINE(USE_THREADS_POSIX, 1, [if you want POSIX threaded DNS lookup]) - curl_res_msg="POSIX threaded" - fi ]) + if test "$HAVE_THREADS_POSIX" = "1"; then + AC_DEFINE(HAVE_THREADS_POSIX, 1, [if POSIX pthreads are supported]) + fi fi dnl threaded resolver check -if test "$want_thres" = "yes" && test "x$USE_THREADS_POSIX" != "x1"; then - if test "$want_pthreads" = "yes"; then - AC_MSG_ERROR([--enable-pthreads but pthreads was not found]) - fi - dnl If native Windows fallback on Win32 threads since no POSIX threads +if test "$want_threaded_resolver" = "yes"; then if test "$curl_cv_native_windows" = "yes"; then - USE_THREADS_WIN32=1 - AC_DEFINE(USE_THREADS_WIN32, 1, [if you want Win32 threaded DNS lookup]) + USE_RESOLV_THREADED=1 + AC_DEFINE(USE_RESOLV_THREADED, 1, [if you want threaded DNS lookup]) curl_res_msg="Win32 threaded" + elif test "$HAVE_THREADS_POSIX" = "1"; then + USE_RESOLV_THREADED=1 + AC_DEFINE(USE_RESOLV_THREADED, 1, [if you want threaded DNS lookup]) + curl_res_msg="POSIX threaded" else AC_MSG_ERROR([Threaded resolver enabled but no thread library found]) fi +elif test "$USE_ARES" = "1"; then + USE_RESOLV_ARES=1 + AC_DEFINE(USE_RESOLV_ARES, 1, [if you want c-ares for DNS lookup]) + curl_res_msg="c-ares" fi +AC_CHECK_HEADER(dirent.h, + [ AC_DEFINE(HAVE_DIRENT_H, 1, [if you have ]) + AC_CHECK_FUNC(opendir, AC_DEFINE(HAVE_OPENDIR, 1, [if you have opendir]) ) + ] +) + CURL_CONVERT_INCLUDE_TO_ISYSTEM +dnl ************************************************************ +dnl disable curl_easy_setopt()/curl_easy_getinfo() type checking +dnl +AC_MSG_CHECKING([whether to enable curl_easy_setopt()/curl_easy_getinfo() type checking]) +AC_ARG_ENABLE(typecheck, +AS_HELP_STRING([--enable-typecheck],[Enable type checking (default)]) +AS_HELP_STRING([--disable-typecheck],[Disable type checking]), +[ case "$enableval" in + no) + AC_MSG_RESULT(no) + dnl Set it via the command-line to make it apply to examples also. + CPPFLAGS="$CPPFLAGS -DCURL_DISABLE_TYPECHECK" + curl_typecheck_msg="no" + ;; + *) + AC_MSG_RESULT(yes) + ;; + esac ], + AC_MSG_RESULT(yes) +) + dnl ************************************************************ dnl disable verbose text strings dnl @@ -3890,51 +4359,58 @@ AS_HELP_STRING([--enable-verbose],[Enable verbose strings]) AS_HELP_STRING([--disable-verbose],[Disable verbose strings]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_VERBOSE_STRINGS, 1, [to disable verbose strings]) - curl_verbose_msg="no" - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_VERBOSE_STRINGS, 1, [to disable verbose strings]) + curl_verbose_msg="no" + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) -dnl ************************************************************ -dnl enable SSPI support -dnl -AC_MSG_CHECKING([whether to enable SSPI support (Windows native builds only)]) -AC_ARG_ENABLE(sspi, -AS_HELP_STRING([--enable-sspi],[Enable SSPI]) +if test "$curl_cv_winuwp" != "yes"; then + dnl ************************************************************ + dnl enable SSPI support + dnl + AC_MSG_CHECKING([whether to enable SSPI support (Windows native builds only)]) + AC_ARG_ENABLE(sspi, + AS_HELP_STRING([--enable-sspi],[Enable SSPI]) AS_HELP_STRING([--disable-sspi],[Disable SSPI]), -[ case "$enableval" in - yes) - if test "$curl_cv_native_windows" = "yes"; then - AC_MSG_RESULT(yes) - AC_DEFINE(USE_WINDOWS_SSPI, 1, [to enable SSPI support]) - AC_SUBST(USE_WINDOWS_SSPI, [1]) - curl_sspi_msg="enabled" - else - AC_MSG_RESULT(no) - AC_MSG_WARN([--enable-sspi Ignored. Only supported on native Windows builds.]) - fi - ;; - *) - if test "x$SCHANNEL_ENABLED" = "x1"; then - # --with-schannel implies --enable-sspi - AC_MSG_RESULT(yes) - else - AC_MSG_RESULT(no) - fi - ;; - esac ], - if test "x$SCHANNEL_ENABLED" = "x1"; then - # --with-schannel implies --enable-sspi - AC_MSG_RESULT(yes) - else - AC_MSG_RESULT(no) - fi -) + [ case "$enableval" in + yes) + if test "$curl_cv_native_windows" = "yes"; then + AC_MSG_RESULT(yes) + AC_DEFINE(USE_WINDOWS_SSPI, 1, [to enable SSPI support]) + USE_WINDOWS_SSPI=1 + curl_sspi_msg="enabled" + else + AC_MSG_RESULT(no) + AC_MSG_WARN([--enable-sspi Ignored. Only supported on native Windows builds.]) + fi + ;; + *) + if test "$SCHANNEL_ENABLED" = "1"; then + dnl --with-schannel implies --enable-sspi + AC_MSG_RESULT(yes) + else + AC_MSG_RESULT(no) + fi + ;; + esac ], + if test "$SCHANNEL_ENABLED" = "1"; then + dnl --with-schannel implies --enable-sspi + AC_MSG_RESULT(yes) + else + AC_MSG_RESULT(no) + fi + ) + + if test "$USE_WINDOWS_SSPI" = "1"; then + LIBS="-lsecur32 $LIBS" + fi +fi dnl ************************************************************ dnl disable basic authentication @@ -3945,14 +4421,14 @@ AS_HELP_STRING([--enable-basic-auth],[Enable basic authentication (default)]) AS_HELP_STRING([--disable-basic-auth],[Disable basic authentication]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_BASIC_AUTH, 1, [to disable basic authentication]) - CURL_DISABLE_BASIC_AUTH=1 - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_BASIC_AUTH, 1, [to disable basic authentication]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -3964,14 +4440,14 @@ AS_HELP_STRING([--enable-bearer-auth],[Enable bearer authentication (default)]) AS_HELP_STRING([--disable-bearer-auth],[Disable bearer authentication]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_BEARER_AUTH, 1, [to disable bearer authentication]) - CURL_DISABLE_BEARER_AUTH=1 - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_BEARER_AUTH, 1, [to disable bearer authentication]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -3983,14 +4459,14 @@ AS_HELP_STRING([--enable-digest-auth],[Enable digest authentication (default)]) AS_HELP_STRING([--disable-digest-auth],[Disable digest authentication]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_DIGEST_AUTH, 1, [to disable digest authentication]) - CURL_DISABLE_DIGEST_AUTH=1 - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_DIGEST_AUTH, 1, [to disable digest authentication]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4002,14 +4478,15 @@ AS_HELP_STRING([--enable-kerberos-auth],[Enable kerberos authentication (default AS_HELP_STRING([--disable-kerberos-auth],[Disable kerberos authentication]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_KERBEROS_AUTH, 1, [to disable kerberos authentication]) - CURL_DISABLE_KERBEROS_AUTH=1 - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_KERBEROS_AUTH, 1, [to disable kerberos authentication]) + CURL_DISABLE_KERBEROS_AUTH=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4021,17 +4498,17 @@ AS_HELP_STRING([--enable-negotiate-auth],[Enable negotiate authentication (defau AS_HELP_STRING([--disable-negotiate-auth],[Disable negotiate authentication]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_NEGOTIATE_AUTH, 1, [to disable negotiate authentication]) - CURL_DISABLE_NEGOTIATE_AUTH=1 - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_NEGOTIATE_AUTH, 1, [to disable negotiate authentication]) + CURL_DISABLE_NEGOTIATE_AUTH=1 + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) - dnl ************************************************************ dnl disable aws dnl @@ -4041,14 +4518,14 @@ AS_HELP_STRING([--enable-aws],[Enable AWS sig support (default)]) AS_HELP_STRING([--disable-aws],[Disable AWS sig support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_AWS, 1, [to disable AWS sig support]) - CURL_DISABLE_AWS=1 - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_AWS, 1, [to disable AWS sig support]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4059,21 +4536,18 @@ AC_ARG_ENABLE(ntlm, AS_HELP_STRING([--enable-ntlm],[Enable NTLM support]) AS_HELP_STRING([--disable-ntlm],[Disable NTLM support]), [ case "$enableval" in - no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_NTLM, 1, [to disable NTLM support]) - CURL_DISABLE_NTLM=1 - ;; - *) AC_MSG_RESULT(yes) - ;; + yes) + AC_MSG_RESULT(yes) + AC_DEFINE(CURL_ENABLE_NTLM, 1, [enable NTLM support]) + CURL_ENABLE_NTLM=1 + ;; + *) + AC_MSG_RESULT(no) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(no) ) -CURL_CHECK_OPTION_NTLM_WB - -CURL_CHECK_NTLM_WB - dnl ************************************************************ dnl disable TLS-SRP authentication dnl @@ -4083,21 +4557,22 @@ AS_HELP_STRING([--enable-tls-srp],[Enable TLS-SRP authentication]) AS_HELP_STRING([--disable-tls-srp],[Disable TLS-SRP authentication]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - want_tls_srp=no - ;; - *) AC_MSG_RESULT(yes) - want_tls_srp=yes - ;; + AC_MSG_RESULT(no) + want_tls_srp=no + ;; + *) + AC_MSG_RESULT(yes) + want_tls_srp=yes + ;; esac ], - AC_MSG_RESULT(yes) - want_tls_srp=yes + AC_MSG_RESULT(yes) + want_tls_srp=yes ) -if test "$want_tls_srp" = "yes" && ( test "x$HAVE_GNUTLS_SRP" = "x1" || test "x$HAVE_OPENSSL_SRP" = "x1") ; then - AC_DEFINE(USE_TLS_SRP, 1, [Use TLS-SRP authentication]) - USE_TLS_SRP=1 - curl_tls_srp_msg="enabled" +if test "$want_tls_srp" = "yes" && (test "$HAVE_GNUTLS_SRP" = "1" || test "$HAVE_OPENSSL_SRP" = "1"); then + AC_DEFINE(USE_TLS_SRP, 1, [Use TLS-SRP authentication]) + USE_TLS_SRP=1 + curl_tls_srp_msg="enabled" fi dnl ************************************************************ @@ -4108,29 +4583,31 @@ AC_ARG_ENABLE(unix-sockets, AS_HELP_STRING([--enable-unix-sockets],[Enable Unix domain sockets]) AS_HELP_STRING([--disable-unix-sockets],[Disable Unix domain sockets]), [ case "$enableval" in - no) AC_MSG_RESULT(no) - want_unix_sockets=no - ;; - *) AC_MSG_RESULT(yes) - want_unix_sockets=yes - ;; + no) + AC_MSG_RESULT(no) + want_unix_sockets=no + ;; + *) + AC_MSG_RESULT(yes) + want_unix_sockets=yes + ;; esac ], [ - AC_MSG_RESULT(auto) - want_unix_sockets=auto - ] + AC_MSG_RESULT(auto) + want_unix_sockets=auto + ] ) -if test "x$want_unix_sockets" != "xno"; then - if test "x$curl_cv_native_windows" = "xyes"; then +if test "$want_unix_sockets" != "no"; then + if test "$curl_cv_native_windows" = "yes"; then USE_UNIX_SOCKETS=1 AC_DEFINE(USE_UNIX_SOCKETS, 1, [Use Unix domain sockets]) curl_unix_sockets_msg="enabled" else AC_CHECK_MEMBER([struct sockaddr_un.sun_path], [ AC_DEFINE(USE_UNIX_SOCKETS, 1, [Use Unix domain sockets]) - AC_SUBST(USE_UNIX_SOCKETS, [1]) + USE_UNIX_SOCKETS=1 curl_unix_sockets_msg="enabled" ], [ - if test "x$want_unix_sockets" = "xyes"; then + if test "$want_unix_sockets" = "yes"; then AC_MSG_ERROR([--enable-unix-sockets is not available on this platform!]) fi ], [ @@ -4148,13 +4625,14 @@ AS_HELP_STRING([--enable-cookies],[Enable cookies support]) AS_HELP_STRING([--disable-cookies],[Disable cookies support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_COOKIES, 1, [to disable cookies support]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_COOKIES, 1, [to disable cookies support]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4166,13 +4644,14 @@ AS_HELP_STRING([--enable-socketpair],[Enable socketpair support]) AS_HELP_STRING([--disable-socketpair],[Disable socketpair support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_SOCKETPAIR, 1, [to disable socketpair support]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_SOCKETPAIR, 1, [to disable socketpair support]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4184,13 +4663,14 @@ AS_HELP_STRING([--enable-http-auth],[Enable HTTP authentication support]) AS_HELP_STRING([--disable-http-auth],[Disable HTTP authentication support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_HTTP_AUTH, 1, [disable HTTP authentication]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_HTTP_AUTH, 1, [disable HTTP authentication]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4202,13 +4682,14 @@ AS_HELP_STRING([--enable-doh],[Enable DoH support]) AS_HELP_STRING([--disable-doh],[Disable DoH support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_DOH, 1, [disable DoH]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_DOH, 1, [disable DoH]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4220,13 +4701,14 @@ AS_HELP_STRING([--enable-mime],[Enable mime API support]) AS_HELP_STRING([--disable-mime],[Disable mime API support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_MIME, 1, [disable mime API]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_MIME, 1, [disable mime API]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4238,13 +4720,14 @@ AS_HELP_STRING([--enable-bindlocal],[Enable local binding support]) AS_HELP_STRING([--disable-bindlocal],[Disable local binding support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_BINDLOCAL, 1, [disable local binding support]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_BINDLOCAL, 1, [disable local binding support]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4255,16 +4738,18 @@ AC_ARG_ENABLE(form-api, AS_HELP_STRING([--enable-form-api],[Enable form API support]) AS_HELP_STRING([--disable-form-api],[Disable form API support]), [ case "$enableval" in - no) AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_FORM_API, 1, [disable form API]) - ;; - *) AC_MSG_RESULT(yes) - test "$enable_mime" = no && - AC_MSG_ERROR(MIME support needs to be enabled in order to enable form API support) - ;; + no) + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_FORM_API, 1, [disable form API]) + ;; + *) + AC_MSG_RESULT(yes) + test "x$enable_mime" = "xno" && + AC_MSG_ERROR(MIME support needs to be enabled in order to enable form API support) + ;; esac ], [ - if test "$enable_mime" = no; then + if test "x$enable_mime" = "xno"; then enable_form_api=no AC_MSG_RESULT(no) AC_DEFINE(CURL_DISABLE_FORM_API, 1, [disable form API]) @@ -4282,13 +4767,14 @@ AS_HELP_STRING([--enable-dateparse],[Enable date parsing]) AS_HELP_STRING([--disable-dateparse],[Disable date parsing]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_PARSEDATE, 1, [disable date parsing]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_PARSEDATE, 1, [disable date parsing]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4300,13 +4786,14 @@ AS_HELP_STRING([--enable-netrc],[Enable netrc parsing]) AS_HELP_STRING([--disable-netrc],[Disable netrc parsing]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_NETRC, 1, [disable netrc parsing]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_NETRC, 1, [disable netrc parsing]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4318,13 +4805,33 @@ AS_HELP_STRING([--enable-progress-meter],[Enable progress-meter]) AS_HELP_STRING([--disable-progress-meter],[Disable progress-meter]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_PROGRESS_METER, 1, [disable progress-meter]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_PROGRESS_METER, 1, [disable progress-meter]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) +) + +dnl ************************************************************ +dnl disable SHA-512/256 hash algorithm +dnl +AC_MSG_CHECKING([whether to support the SHA-512/256 hash algorithm]) +AC_ARG_ENABLE(sha512-256, +AS_HELP_STRING([--enable-sha512-256],[Enable SHA-512/256 hash algorithm (default)]) +AS_HELP_STRING([--disable-sha512-256],[Disable SHA-512/256 hash algorithm]), +[ case "$enableval" in + no) + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_SHA512_256, 1, [disable SHA-512/256 hash algorithm]) + ;; + *) + AC_MSG_RESULT(yes) + ;; + esac ], + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4336,13 +4843,14 @@ AS_HELP_STRING([--enable-dnsshuffle],[Enable DNS shuffling]) AS_HELP_STRING([--disable-dnsshuffle],[Disable DNS shuffling]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_SHUFFLE_DNS, 1, [disable DNS shuffling]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_SHUFFLE_DNS, 1, [disable DNS shuffling]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4354,13 +4862,14 @@ AS_HELP_STRING([--enable-get-easy-options],[Enable curl_easy_options]) AS_HELP_STRING([--disable-get-easy-options],[Disable curl_easy_options]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_GETOPTIONS, 1, [to disable curl_easy_options]) - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_GETOPTIONS, 1, [to disable curl_easy_options]) + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4372,15 +4881,16 @@ AS_HELP_STRING([--enable-alt-svc],[Enable alt-svc support]) AS_HELP_STRING([--disable-alt-svc],[Disable alt-svc support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - AC_DEFINE(CURL_DISABLE_ALTSVC, 1, [disable alt-svc]) - curl_altsvc_msg="no"; - enable_altsvc="no" - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_ALTSVC, 1, [disable alt-svc]) + curl_altsvc_msg="no"; + enable_altsvc="no" + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) dnl ************************************************************ @@ -4391,18 +4901,19 @@ AC_ARG_ENABLE(headers-api, AS_HELP_STRING([--enable-headers-api],[Enable headers-api support]) AS_HELP_STRING([--disable-headers-api],[Disable headers-api support]), [ case "$enableval" in - no) AC_MSG_RESULT(no) - curl_headers_msg="no (--enable-headers-api)" - AC_DEFINE(CURL_DISABLE_HEADERS_API, 1, [disable headers-api]) - ;; + no) + AC_MSG_RESULT(no) + curl_headers_msg="no (--enable-headers-api)" + AC_DEFINE(CURL_DISABLE_HEADERS_API, 1, [disable headers-api]) + ;; *) - AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT(yes) + AC_MSG_RESULT(yes) ) -dnl only check for HSTS if there's SSL present +dnl only check for HSTS if there is SSL present if test -n "$SSL_ENABLED"; then dnl ************************************************************ dnl switch on/off hsts @@ -4413,20 +4924,21 @@ AS_HELP_STRING([--enable-hsts],[Enable HSTS support]) AS_HELP_STRING([--disable-hsts],[Disable HSTS support]), [ case "$enableval" in no) - AC_MSG_RESULT(no) - hsts="no" - ;; - *) AC_MSG_RESULT(yes) - ;; + AC_MSG_RESULT(no) + hsts="no" + ;; + *) + AC_MSG_RESULT(yes) + ;; esac ], - AC_MSG_RESULT($hsts) + AC_MSG_RESULT($hsts) ) else AC_MSG_NOTICE([disables HSTS due to lack of SSL]) hsts="no" fi -if test "x$hsts" != "xyes"; then +if test "$hsts" != "yes"; then curl_hsts_msg="no (--enable-hsts)"; AC_DEFINE(CURL_DISABLE_HSTS, 1, [disable alt-svc]) fi @@ -4434,71 +4946,149 @@ fi dnl ************************************************************* dnl check whether ECH support, if desired, is actually available dnl -if test "x$want_ech" != "xno"; then +if test "$want_ech" != "no"; then AC_MSG_CHECKING([whether ECH support is available]) dnl assume NOT and look for sufficient condition ECH_ENABLED=0 + ECH_ENABLED_OPENSSL=0 + ECH_ENABLED_WOLFSSL=0 + ECH_ENABLED_RUSTLS=0 ECH_SUPPORT='' - dnl OpenSSL with a chosen ECH function should be enough - dnl so more exhaustive checking seems unnecessary for now - if test "x$OPENSSL_ENABLED" = "x1"; then - AC_CHECK_FUNCS(SSL_get_ech_status, - ECH_SUPPORT="ECH support available (OpenSSL with SSL_get_ech_status)" - ECH_ENABLED=1) - - dnl add 'elif' chain here for additional implementations + dnl check for OpenSSL equivalent + if test "$OPENSSL_ENABLED" = "1"; then + AC_CHECK_FUNCS(SSL_set1_ech_config_list, + ECH_SUPPORT="$ECH_SUPPORT OpenSSL" + ECH_ENABLED_OPENSSL=1) + fi + if test "$WOLFSSL_ENABLED" = "1"; then + AC_CHECK_FUNCS(wolfSSL_CTX_GenerateEchConfig, + ECH_SUPPORT="$ECH_SUPPORT wolfSSL" + ECH_ENABLED_WOLFSSL=1) + fi + if test "$RUSTLS_ENABLED" = "1"; then + ECH_SUPPORT="$ECH_SUPPORT rustls-ffi" + ECH_ENABLED_RUSTLS=1 fi dnl now deal with whatever we found - if test "x$ECH_ENABLED" = "x1"; then + if test "$ECH_ENABLED_OPENSSL" = "1" || + test "$ECH_ENABLED_WOLFSSL" = "1" || + test "$ECH_ENABLED_RUSTLS" = "1"; then AC_DEFINE(USE_ECH, 1, [if ECH support is available]) - AC_MSG_RESULT($ECH_SUPPORT) + AC_MSG_RESULT(ECH support available via:$ECH_SUPPORT) experimental="$experimental ECH" + ECH_ENABLED=1 + dnl ECH wants HTTPSRR + want_httpsrr="yes" else AC_MSG_ERROR([--enable-ech ignored: No ECH support found]) fi fi +AC_MSG_CHECKING([whether to enable HTTPS-RR support]) +dnl ************************************************************* +dnl check whether HTTPSRR support if desired +dnl +if test "$want_httpsrr" != "no"; then + AC_MSG_RESULT([yes]) + AC_DEFINE(USE_HTTPSRR, 1, [enable HTTPS RR support]) + experimental="$experimental HTTPSRR" + curl_httpsrr_msg="enabled (--disable-httpsrr)" +else + AC_MSG_RESULT([no]) + dnl no HTTPSRR wanted + if test "$want_threaded_resolver" = "yes"; then + dnl and using the threaded resolver + if test "$USE_ARES" = "1"; then + AC_MSG_ERROR([without HTTPS-RR support, asking for both threaded resolver and c-ares support is ambivalent. Please drop one of them.]) + fi + fi +fi + dnl ************************************************************* dnl check whether OpenSSL (lookalikes) have SSL_set0_wbio dnl -if test "x$OPENSSL_ENABLED" = "x1"; then +if test "$OPENSSL_ENABLED" = "1"; then AC_CHECK_FUNCS([SSL_set0_wbio]) fi dnl ************************************************************* dnl WebSockets dnl -AC_MSG_CHECKING([whether to support WebSockets]) -AC_ARG_ENABLE(websockets, -AS_HELP_STRING([--enable-websockets],[Enable WebSockets support]) +if test "$CURL_DISABLE_HTTP" != "1"; then + AC_MSG_CHECKING([whether to support WebSockets]) + AC_ARG_ENABLE(websockets, + AS_HELP_STRING([--enable-websockets],[Enable WebSockets support]) AS_HELP_STRING([--disable-websockets],[Disable WebSockets support]), -[ case "$enableval" in - no) - AC_MSG_RESULT(no) - ;; - *) - if test ${ac_cv_sizeof_curl_off_t} -gt 4; then - AC_MSG_RESULT(yes) - curl_ws_msg="enabled" - AC_DEFINE_UNQUOTED(USE_WEBSOCKETS, [1], [enable websockets support]) - SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS WS" - if test "x$SSL_ENABLED" = "x1"; then - SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS WSS" - fi - experimental="$experimental Websockets" - else - dnl websockets requires >32 bit curl_off_t - AC_MSG_RESULT(no) - AC_MSG_WARN([Websockets disabled due to lack of >32 bit curl_off_t]) - fi - ;; - esac ], - AC_MSG_RESULT(no) -) + [ case "$enableval" in + no) + AC_MSG_RESULT(no) + AC_DEFINE(CURL_DISABLE_WEBSOCKETS, [1], [disable WebSockets]) + CURL_DISABLE_WEBSOCKETS=1 + ;; + *) + if test "$ac_cv_sizeof_curl_off_t" -gt 4; then + AC_MSG_RESULT(yes) + else + dnl WebSockets requires >32-bit curl_off_t + AC_MSG_RESULT(no) + AC_MSG_WARN([WebSockets disabled due to lack of >32-bit curl_off_t]) + AC_DEFINE(CURL_DISABLE_WEBSOCKETS, [1], [disable WebSockets]) + CURL_DISABLE_WEBSOCKETS=1 + fi + ;; + esac ], + AC_MSG_RESULT(yes) + ) +else + AC_MSG_WARN([WebSockets disabled because HTTP is disabled]) + AC_DEFINE(CURL_DISABLE_WEBSOCKETS, [1], [disable WebSockets]) + CURL_DISABLE_WEBSOCKETS=1 +fi +dnl ************************************************************* +dnl check whether experimental SSL Session Im-/Export is enabled +dnl +if test "$want_ssls_export" != "no"; then + AC_MSG_CHECKING([whether SSL session export support is available]) + + dnl assume NOT and look for sufficient condition + SSLS_EXPORT_ENABLED=0 + SSLS_EXPORT_SUPPORT='' + + if test "$SSL_ENABLED" != "1"; then + AC_MSG_WARN([--enable-ssls-export ignored: No SSL support]) + else + SSLS_EXPORT_ENABLED=1 + AC_DEFINE(USE_SSLS_EXPORT, 1, [if SSL session export support is available]) + AC_MSG_RESULT("SSL session im-/export enabled") + experimental="$experimental SSLS-EXPORT" + fi +fi + +dnl ************************************************************* +dnl check whether experimental HTTP/3 proxy support is enabled +dnl +if test "$want_proxy_http3" = "yes"; then + AC_MSG_CHECKING([whether HTTP/3 proxy support is available]) + + if test "$CURL_DISABLE_PROXY" = "1"; then + AC_MSG_ERROR([--enable-proxy-http3 requires proxy support]) + elif test "$CURL_DISABLE_HTTP" = "1"; then + AC_MSG_ERROR([--enable-proxy-http3 requires HTTP support]) + elif test "$USE_NGTCP2_H3" != "1"; then + AC_MSG_ERROR([--enable-proxy-http3 requires ngtcp2 + nghttp3]) + elif test "x$OPENSSL_ENABLED" != "x1"; then + AC_MSG_ERROR([--enable-proxy-http3 currently requires OpenSSL]) + else + AC_DEFINE(USE_PROXY_HTTP3, 1, [if HTTP/3 proxy support is available]) + USE_PROXY_HTTP3=1 + AC_MSG_RESULT([yes]) + experimental="$experimental proxy-HTTP3" + fi +fi dnl ************************************************************ dnl hiding of library internal symbols @@ -4508,10 +5098,28 @@ CURL_CONFIGURE_SYMBOL_HIDING dnl dnl All the library dependencies put into $LIB apply to libcurl only. dnl -LIBCURL_LIBS="$LIBS$PTHREAD" +LIBCURL_PC_LDFLAGS_PRIVATE='' +dnl Do not quote $INITIAL_LDFLAGS +set -- $INITIAL_LDFLAGS +while test -n "$1"; do + case "$1" in + -L* | --library-path=* | -F*) + LIBCURL_PC_LDFLAGS_PRIVATE="$LIBCURL_PC_LDFLAGS_PRIVATE $1" + ;; + -framework) + if test -n "$2"; then + LIBCURL_PC_LDFLAGS_PRIVATE="$LIBCURL_PC_LDFLAGS_PRIVATE $1 $2" + shift + fi + ;; + esac + shift +done +LIBCURL_PC_LDFLAGS_PRIVATE="$LIBCURL_PC_LDFLAGS_PRIVATE $LDFLAGSPC" +LIBCURL_PC_LIBS_PRIVATE="$LIBS$PTHREAD" -AC_SUBST(LIBCURL_LIBS) -AC_SUBST(CURL_NETWORK_LIBS) +AC_SUBST(LIBCURL_PC_LDFLAGS_PRIVATE) +AC_SUBST(LIBCURL_PC_LIBS_PRIVATE) AC_SUBST(CURL_NETWORK_AND_TIME_LIBS) dnl BLANK_AT_MAKETIME may be used in our Makefile.am files to blank @@ -4521,7 +5129,7 @@ dnl all link targets in given makefile. BLANK_AT_MAKETIME= AC_SUBST(BLANK_AT_MAKETIME) -AM_CONDITIONAL(CROSSCOMPILING, test x$cross_compiling = xyes) +AM_CONDITIONAL(CROSSCOMPILING, test "$cross_compiling" = "yes") dnl yes or no ENABLE_SHARED="$enable_shared" @@ -4531,13 +5139,21 @@ dnl to let curl-config output the static libraries correctly ENABLE_STATIC="$enable_static" AC_SUBST(ENABLE_STATIC) -dnl merge the pkg-config Libs.private field into Libs when static-only -if test "x$enable_shared" = "xno"; then - LIBCURL_NO_SHARED=$LIBCURL_LIBS +squeeze LIBCURL_PC_REQUIRES_PRIVATE +LIBCURL_PC_REQUIRES_PRIVATE=`echo $LIBCURL_PC_REQUIRES_PRIVATE | tr ' ' ','` + +AC_SUBST(LIBCURL_PC_REQUIRES_PRIVATE) + +dnl Merge pkg-config private fields into public ones when static-only +if test "$enable_shared" = "no"; then + LIBCURL_PC_REQUIRES=$LIBCURL_PC_REQUIRES_PRIVATE + LIBCURL_PC_LIBS=$LIBCURL_PC_LIBS_PRIVATE else - LIBCURL_NO_SHARED= + LIBCURL_PC_REQUIRES= + LIBCURL_PC_LIBS= fi -AC_SUBST(LIBCURL_NO_SHARED) +AC_SUBST(LIBCURL_PC_REQUIRES) +AC_SUBST(LIBCURL_PC_LIBS) rm $compilersh @@ -4546,239 +5162,282 @@ dnl For keeping supported features and protocols also in pkg-config file dnl since it is more cross-compile friendly than curl-config dnl -if test "x$OPENSSL_ENABLED" = "x1"; then +if test "$OPENSSL_ENABLED" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES SSL" elif test -n "$SSL_ENABLED"; then SUPPORT_FEATURES="$SUPPORT_FEATURES SSL" fi -if test "x$IPV6_ENABLED" = "x1"; then +if test "$IPV6_ENABLED" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES IPv6" fi -if test "x$USE_UNIX_SOCKETS" = "x1"; then +if test "$USE_UNIX_SOCKETS" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES UnixSockets" fi -if test "x$HAVE_LIBZ" = "x1"; then +if test "$HAVE_LIBZ" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES libz" fi -if test "x$HAVE_BROTLI" = "x1"; then +if test "$HAVE_BROTLI" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES brotli" fi -if test "x$HAVE_ZSTD" = "x1"; then +if test "$HAVE_ZSTD" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES zstd" fi -if test "x$USE_ARES" = "x1" -o "x$USE_THREADS_POSIX" = "x1" \ - -o "x$USE_THREADS_WIN32" = "x1"; then +if test "$USE_RESOLV_ARES" = "1" || test "$USE_RESOLV_THREADED" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES AsynchDNS" fi -if test "x$IDN_ENABLED" = "x1"; then +if test "$USE_ARES" = "1" && test "$want_threaded_resolver" = "yes" && test "$want_httpsrr" != "no"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES asyn-rr" +fi +if test "$IDN_ENABLED" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES IDN" fi -if test "x$USE_WINDOWS_SSPI" = "x1"; then +if test "$USE_WINDOWS_SSPI" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES SSPI" fi -if test "x$HAVE_GSSAPI" = "x1"; then +if test "$HAVE_GSSAPI" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES GSS-API" fi -if test "x$curl_psl_msg" = "xenabled"; then +if test "$curl_psl_msg" = "enabled"; then SUPPORT_FEATURES="$SUPPORT_FEATURES PSL" fi -if test "x$curl_gsasl_msg" = "xenabled"; then - SUPPORT_FEATURES="$SUPPORT_FEATURES GSASL" +if test "$USE_PROXY_HTTP3" = "1"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES proxy-HTTP3" fi -if test "x$enable_altsvc" = "xyes"; then +if test "$curl_gsasl_msg" = "enabled"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES gsasl" +fi + +if test "$enable_altsvc" = "yes"; then SUPPORT_FEATURES="$SUPPORT_FEATURES alt-svc" fi -if test "x$hsts" = "xyes"; then +if test "$hsts" = "yes"; then SUPPORT_FEATURES="$SUPPORT_FEATURES HSTS" fi -if test "x$CURL_DISABLE_NEGOTIATE_AUTH" != "x1" -a \ - \( "x$HAVE_GSSAPI" = "x1" -o "x$USE_WINDOWS_SSPI" = "x1" \); then +if test "$CURL_DISABLE_NEGOTIATE_AUTH" != "1" && (test "$HAVE_GSSAPI" = "1" || test "$USE_WINDOWS_SSPI" = "1"); then SUPPORT_FEATURES="$SUPPORT_FEATURES SPNEGO" fi -if test "x$CURL_DISABLE_KERBEROS_AUTH" != "x1" -a \ - \( "x$HAVE_GSSAPI" = "x1" -o "x$USE_WINDOWS_SSPI" = "x1" \); then +if test "$CURL_DISABLE_KERBEROS_AUTH" != "1" && (test "$HAVE_GSSAPI" = "1" || test "$USE_WINDOWS_SSPI" = "1"); then SUPPORT_FEATURES="$SUPPORT_FEATURES Kerberos" fi use_curl_ntlm_core=no -if test "x$CURL_DISABLE_NTLM" != "x1"; then - if test "x$OPENSSL_ENABLED" = "x1" -o "x$MBEDTLS_ENABLED" = "x1" \ - -o "x$GNUTLS_ENABLED" = "x1" \ - -o "x$SECURETRANSPORT_ENABLED" = "x1" \ - -o "x$USE_WIN32_CRYPTO" = "x1" \ - -o "x$WOLFSSL_NTLM" = "x1"; then +if test "$CURL_ENABLE_NTLM" = "1"; then + if test "$HAVE_DES_ECB_ENCRYPT" = "1" || + test "$GNUTLS_ENABLED" = "1" || + test "$USE_WIN32_CRYPTO" = "1" || + test "$HAVE_WC_DES_ECBENCRYPT" = "1" || + test "$HAVE_MBEDTLS_DES_CRYPT_ECB" = "1"; then use_curl_ntlm_core=yes fi - if test "x$use_curl_ntlm_core" = "xyes" \ - -o "x$USE_WINDOWS_SSPI" = "x1"; then + if test "$use_curl_ntlm_core" = "yes" || + test "$USE_WINDOWS_SSPI" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES NTLM" - - if test "x$CURL_DISABLE_HTTP" != "x1" -a \ - "x$NTLM_WB_ENABLED" = "x1"; then - SUPPORT_FEATURES="$SUPPORT_FEATURES NTLM_WB" - fi fi fi -if test "x$USE_TLS_SRP" = "x1"; then +if test "$USE_TLS_SRP" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES TLS-SRP" fi -if test "x$USE_NGHTTP2" = "x1" -o "x$USE_HYPER" = "x1"; then +if test "$USE_NGHTTP2" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES HTTP2" fi -if test "x$USE_NGTCP2" = "x1" -o "x$USE_QUICHE" = "x1" \ - -o "x$USE_MSH3" = "x1"; then +if test "$USE_NGTCP2_H3" = "1" || + test "$USE_QUICHE" = "1" || + test "$USE_OPENSSL_H3" = "1"; then + if test "$CURL_WITH_MULTI_SSL" = "1"; then + AC_MSG_ERROR([MultiSSL cannot be enabled with HTTP/3 and vice versa]) + fi SUPPORT_FEATURES="$SUPPORT_FEATURES HTTP3" fi -if test "x$CURL_WITH_MULTI_SSL" = "x1"; then +if test "$CURL_WITH_MULTI_SSL" = "1"; then SUPPORT_FEATURES="$SUPPORT_FEATURES MultiSSL" fi +AC_MSG_CHECKING([if this build supports HTTPS-proxy]) dnl if not explicitly turned off, HTTPS-proxy comes with some TLS backends -if test "x$https_proxy" != "xno"; then - if test "x$OPENSSL_ENABLED" = "x1" \ - -o "x$GNUTLS_ENABLED" = "x1" \ - -o "x$SECURETRANSPORT_ENABLED" = "x1" \ - -o "x$RUSTLS_ENABLED" = "x1" \ - -o "x$BEARSSL_ENABLED" = "x1" \ - -o "x$SCHANNEL_ENABLED" = "x1" \ - -o "x$GNUTLS_ENABLED" = "x1" \ - -o "x$MBEDTLS_ENABLED" = "x1"; then - SUPPORT_FEATURES="$SUPPORT_FEATURES HTTPS-proxy" - elif test "x$WOLFSSL_ENABLED" = "x1" -a "x$WOLFSSL_FULL_BIO" = "x1"; then - SUPPORT_FEATURES="$SUPPORT_FEATURES HTTPS-proxy" +if test "$CURL_DISABLE_HTTP" != "1"; then + if test "$https_proxy" != "no"; then + if test "$OPENSSL_ENABLED" = "1" || + test "$GNUTLS_ENABLED" = "1" || + test "$RUSTLS_ENABLED" = "1" || + test "$SCHANNEL_ENABLED" = "1" || + test "$GNUTLS_ENABLED" = "1" || + test "$MBEDTLS_ENABLED" = "1"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES HTTPS-proxy" + AC_MSG_RESULT([yes]) + elif test "$WOLFSSL_ENABLED" = "1" && test "$HAVE_WOLFSSL_BIO_NEW" = "1"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES HTTPS-proxy" + AC_MSG_RESULT([yes]) + else + AC_MSG_RESULT([no]) + fi + else + AC_MSG_RESULT([no]) + fi +else + AC_MSG_RESULT([no]) +fi + +if test "$OPENSSL_ENABLED" = "1" || test -n "$SSL_ENABLED"; then + if test "$ECH_ENABLED" = "1"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES ECH" fi fi -if test "x$ECH_ENABLED" = "x1"; then - SUPPORT_FEATURES="$SUPPORT_FEATURES ECH" +if test -n "$SSL_ENABLED"; then + if test "$APPLE_SECTRUST_ENABLED" = "1"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES AppleSecTrust" + elif test "$ca_native_opt" = "1"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES NativeCA" + fi fi -if test ${ac_cv_sizeof_curl_off_t} -gt 4; then - if test ${ac_cv_sizeof_off_t} -gt 4 -o \ - "$curl_win32_file_api" = "win32_large_files"; then +if test "$want_httpsrr" != "no"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES HTTPSRR" +fi + +if test "$SSLS_EXPORT_ENABLED" = "1"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES SSLS-EXPORT" +fi + +if test "$ac_cv_sizeof_curl_off_t" -gt 4; then + if test "$ac_cv_sizeof_off_t" -gt 4 || + test "$curl_cv_native_windows" = "yes"; then SUPPORT_FEATURES="$SUPPORT_FEATURES Largefile" fi fi if test "$tst_atomic" = "yes"; then SUPPORT_FEATURES="$SUPPORT_FEATURES threadsafe" +elif test "$HAVE_THREADS_POSIX" = "1" && test "$ac_cv_header_pthread_h" = "yes"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES threadsafe" +elif test "$curl_cv_native_windows" = "yes"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES threadsafe" +fi + +if test "$want_winuni" = "yes"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES Unicode" +fi +if test "$want_debug" = "yes"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES Debug" +fi +if test -n "$CURL_CA_EMBED"; then + SUPPORT_FEATURES="$SUPPORT_FEATURES CAcert" + CURL_CA_EMBED_msg="$CURL_CA_EMBED" else - AC_COMPILE_IFELSE([ - AC_LANG_PROGRAM([[ - #include - ]],[[ - #if (WINVER < 0x600) && (_WIN32_WINNT < 0x600) - #error - #endif - ]]) - ],[ - SUPPORT_FEATURES="$SUPPORT_FEATURES threadsafe" - ],[ - ]) + CURL_CA_EMBED_msg='no' fi dnl replace spaces with newlines dnl sort the lines dnl replace the newlines back to spaces -SUPPORT_FEATURES=`echo $SUPPORT_FEATURES | tr ' ' '\012' | sort | tr '\012' ' '` +if sort -f /dev/null 2>&1; then + SUPPORT_FEATURES=`echo $SUPPORT_FEATURES | tr ' ' '\012' | sort -f | tr '\012' ' '` +else + SUPPORT_FEATURES=`echo $SUPPORT_FEATURES | tr ' ' '\012' | sort | tr '\012' ' '` +fi AC_SUBST(SUPPORT_FEATURES) dnl For supported protocols in pkg-config file -if test "x$CURL_DISABLE_HTTP" != "x1"; then +if test "$CURL_DISABLE_HTTP" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS HTTP" - if test "x$SSL_ENABLED" = "x1"; then + if test "$SSL_ENABLED" = "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS HTTPS" fi fi -if test "x$CURL_DISABLE_FTP" != "x1"; then +if test "$CURL_DISABLE_FTP" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS FTP" - if test "x$SSL_ENABLED" = "x1"; then + if test "$SSL_ENABLED" = "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS FTPS" fi fi -if test "x$CURL_DISABLE_FILE" != "x1"; then +if test "$CURL_DISABLE_FILE" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS FILE" fi -if test "x$CURL_DISABLE_TELNET" != "x1"; then +if test "$CURL_DISABLE_TELNET" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS TELNET" fi -if test "x$CURL_DISABLE_LDAP" != "x1"; then +if test "$CURL_DISABLE_LDAP" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS LDAP" - if test "x$CURL_DISABLE_LDAPS" != "x1"; then - if (test "x$USE_OPENLDAP" = "x1" && test "x$SSL_ENABLED" = "x1") || - (test "x$USE_OPENLDAP" != "x1" && test "x$HAVE_LDAP_SSL" = "x1"); then + if test "$CURL_DISABLE_LDAPS" != "1"; then + if (test "$USE_OPENLDAP" = "1" && test "$SSL_ENABLED" = "1") || + (test "$USE_OPENLDAP" != "1" && test "$HAVE_LDAP_SSL" = "1"); then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS LDAPS" fi fi fi -if test "x$CURL_DISABLE_DICT" != "x1"; then +if test "$CURL_DISABLE_DICT" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS DICT" fi -if test "x$CURL_DISABLE_TFTP" != "x1"; then +if test "$CURL_DISABLE_TFTP" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS TFTP" fi -if test "x$CURL_DISABLE_GOPHER" != "x1"; then +if test "$CURL_DISABLE_GOPHER" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS GOPHER" - if test "x$SSL_ENABLED" = "x1"; then + if test "$SSL_ENABLED" = "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS GOPHERS" fi fi -if test "x$CURL_DISABLE_MQTT" != "x1"; then +if test "$CURL_DISABLE_MQTT" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS MQTT" + if test "$SSL_ENABLED" = "1"; then + SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS MQTTS" + fi fi -if test "x$CURL_DISABLE_POP3" != "x1"; then +if test "$CURL_DISABLE_POP3" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS POP3" - if test "x$SSL_ENABLED" = "x1"; then + if test "$SSL_ENABLED" = "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS POP3S" fi fi -if test "x$CURL_DISABLE_IMAP" != "x1"; then +if test "$CURL_DISABLE_IMAP" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS IMAP" - if test "x$SSL_ENABLED" = "x1"; then + if test "$SSL_ENABLED" = "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS IMAPS" fi fi -if test "x$CURL_DISABLE_SMB" != "x1" \ - -a "x$use_curl_ntlm_core" = "xyes"; then +if test "$CURL_ENABLE_SMB" = "1" && test "$use_curl_ntlm_core" = "yes"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS SMB" - if test "x$SSL_ENABLED" = "x1"; then + if test "$SSL_ENABLED" = "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS SMBS" fi fi -if test "x$CURL_DISABLE_SMTP" != "x1"; then +if test "$CURL_DISABLE_SMTP" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS SMTP" - if test "x$SSL_ENABLED" = "x1"; then + if test "$SSL_ENABLED" = "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS SMTPS" fi fi -if test "x$USE_LIBSSH2" = "x1"; then +if test "$USE_LIBSSH2" = "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS SCP" SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS SFTP" fi -if test "x$USE_LIBSSH" = "x1"; then +if test "$USE_LIBSSH" = "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS SCP" SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS SFTP" fi -if test "x$USE_WOLFSSH" = "x1"; then - SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS SFTP" +if test "$CURL_DISABLE_IPFS" != "1"; then + SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS IPFS IPNS" fi -if test "x$CURL_DISABLE_RTSP" != "x1"; then +if test "$CURL_DISABLE_RTSP" != "1"; then SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS RTSP" fi -if test "x$USE_LIBRTMP" = "x1"; then - SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS RTMP" +if test "$CURL_DISABLE_WEBSOCKETS" != "1"; then + SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS WS" + if test "$SSL_ENABLED" = "1"; then + SUPPORT_PROTOCOLS="$SUPPORT_PROTOCOLS WSS" + fi fi dnl replace spaces with newlines @@ -4796,8 +5455,8 @@ squeeze DEFS squeeze LDFLAGS squeeze LIBS -squeeze LIBCURL_LIBS -squeeze CURL_NETWORK_LIBS +squeeze LIBCURL_PC_LDFLAGS_PRIVATE +squeeze LIBCURL_PC_LIBS_PRIVATE squeeze CURL_NETWORK_AND_TIME_LIBS squeeze SUPPORT_FEATURES @@ -4808,43 +5467,40 @@ XC_CHECK_BUILD_FLAGS SSL_BACKENDS=${ssl_backends} AC_SUBST(SSL_BACKENDS) -if test "x$want_curldebug_assumed" = "xyes" && - test "x$want_curldebug" = "xyes" && test "x$USE_ARES" = "x1"; then - ac_configure_args="$ac_configure_args --enable-curldebug" -fi +CURL_PREPARE_CONFIGUREHELP_PM -AC_CONFIG_FILES([Makefile \ - docs/Makefile \ - docs/examples/Makefile \ - docs/libcurl/Makefile \ - docs/libcurl/opts/Makefile \ - docs/cmdline-opts/Makefile \ - include/Makefile \ - include/curl/Makefile \ - src/Makefile \ - lib/Makefile \ - scripts/Makefile \ - lib/libcurl.vers \ - lib/libcurl.plist \ - tests/Makefile \ - tests/config \ - tests/certs/Makefile \ - tests/certs/scripts/Makefile \ - tests/data/Makefile \ - tests/server/Makefile \ - tests/libtest/Makefile \ - tests/unit/Makefile \ - tests/http/config.ini \ - tests/http/Makefile \ - tests/http/clients/Makefile \ - packages/Makefile \ - packages/vms/Makefile \ - curl-config \ - libcurl.pc +AC_CONFIG_FILES([\ + Makefile \ + docs/Makefile \ + docs/examples/Makefile \ + docs/libcurl/Makefile \ + docs/libcurl/opts/Makefile \ + docs/cmdline-opts/Makefile \ + include/Makefile \ + include/curl/Makefile \ + src/Makefile \ + lib/Makefile \ + scripts/Makefile \ + lib/libcurl.vers \ + tests/Makefile \ + tests/config \ + tests/configurehelp.pm \ + tests/certs/Makefile \ + tests/data/Makefile \ + tests/server/Makefile \ + tests/libtest/Makefile \ + tests/unit/Makefile \ + tests/tunit/Makefile \ + tests/http/config.ini \ + tests/http/Makefile \ + projects/Makefile \ + projects/vms/Makefile \ + libcurl.pc ]) +AC_CONFIG_FILES([curl-config], [chmod +x curl-config]) AC_OUTPUT -CURL_GENERATE_CONFIGUREHELP_PM +SUPPORT_PROTOCOLS_LOWER=`echo "$SUPPORT_PROTOCOLS" | tr A-Z a-z` AC_MSG_NOTICE([Configured to build curl/libcurl: @@ -4852,8 +5508,10 @@ AC_MSG_NOTICE([Configured to build curl/libcurl: Install prefix: ${prefix} Compiler: ${CC} CFLAGS: ${CFLAGS} + CFLAGS extras: ${CURL_CFLAG_EXTRAS} CPPFLAGS: ${CPPFLAGS} LDFLAGS: ${LDFLAGS} + curl-config: ${LIBCURL_PC_LDFLAGS_PRIVATE} LIBS: ${LIBS} curl version: ${CURLVERSION} @@ -4869,19 +5527,23 @@ AC_MSG_NOTICE([Configured to build curl/libcurl: IPv6: ${curl_ipv6_msg} Unix sockets: ${curl_unix_sockets_msg} IDN: ${curl_idn_msg} + Build docs: ${curl_docs_msg} Build libcurl: Shared=${enable_shared}, Static=${enable_static} Built-in manual: ${curl_manual_msg} --libcurl option: ${curl_libcurl_msg} + Type checking: ${curl_typecheck_msg} Verbose errors: ${curl_verbose_msg} Code coverage: ${curl_coverage_msg} SSPI: ${curl_sspi_msg} - ca cert bundle: ${ca}${ca_warning} - ca cert path: ${capath}${capath_warning} - ca fallback: ${with_ca_fallback} + CA native: ${ca_native} + CA cert bundle: ${ca}${ca_warning} + CA cert path: ${capath}${capath_warning} + CA cert embed: ${CURL_CA_EMBED_msg} + CA fallback: ${with_ca_fallback} LDAP: ${curl_ldap_msg} LDAPS: ${curl_ldaps_msg} + IPFS/IPNS: ${curl_ipfs_msg} RTSP: ${curl_rtsp_msg} - RTMP: ${curl_rtmp_msg} PSL: ${curl_psl_msg} Alt-svc: ${curl_altsvc_msg} Headers API: ${curl_headers_msg} @@ -4889,13 +5551,22 @@ AC_MSG_NOTICE([Configured to build curl/libcurl: HTTP1: ${curl_h1_msg} HTTP2: ${curl_h2_msg} HTTP3: ${curl_h3_msg} + proxy-HTTP3: ${curl_proxy_http3_msg} ECH: ${curl_ech_msg} - WebSockets: ${curl_ws_msg} - Protocols: ${SUPPORT_PROTOCOLS} + HTTPS RR: ${curl_httpsrr_msg} + SSLS-EXPORT: ${curl_ssls_export_msg} + Protocols: ${SUPPORT_PROTOCOLS_LOWER} Features: ${SUPPORT_FEATURES} ]) + if test -n "$experimental"; then - cat >&2 << _EOF - WARNING: $experimental enabled but marked EXPERIMENTAL. Use with caution! -_EOF + for a in $experimental; do + AC_MSG_WARN([$a is enabled but marked EXPERIMENTAL. Use with caution!]) + done +fi + +CURL_PREPARE_BUILDINFO +echo "[@%:@] This is a generated file. Do not edit.${curl_buildinfo}" > ./buildinfo.txt +if test -n "$CURL_BUILDINFO$CURL_CI$CI"; then + AC_MSG_NOTICE([${curl_buildinfo}]) fi diff --git a/third-party/curl/curl-config.in b/third-party/curl/curl-config.in index 54f92d9313..a1c8185875 100644 --- a/third-party/curl/curl-config.in +++ b/third-party/curl/curl-config.in @@ -1,4 +1,4 @@ -#! /bin/sh +#!/bin/sh #*************************************************************************** # _ _ ____ _ # Project ___| | | | _ \| | @@ -23,174 +23,167 @@ # ########################################################################### -prefix="@prefix@" -exec_prefix=@exec_prefix@ -includedir=@includedir@ -cppflag_curl_staticlib=@CPPFLAG_CURL_STATICLIB@ +# shellcheck disable=SC2006 + +prefix='@prefix@' +# Used in 'libdir' +# shellcheck disable=SC2034 +exec_prefix="@exec_prefix@" +# shellcheck disable=SC2034 +includedir="@includedir@" usage() { - cat <&2 - exit 1 - fi - ;; + --ssl-backends) + echo '@SSL_BACKENDS@' + ;; - --configure) - echo @CONFIGURE_OPTIONS@ - ;; + --static-libs) + if test '@ENABLE_STATIC@' != 'no'; then + echo "@libdir@/libcurl.@libext@ @LIBCURL_PC_LDFLAGS_PRIVATE@ @LIBCURL_PC_LIBS_PRIVATE@" + else + echo 'curl was built with static libraries disabled' >&2 + exit 1 + fi + ;; - *) - echo "unknown option: $1" - usage 1 - ;; - esac - shift + --configure) + echo @CONFIGURE_OPTIONS@ + ;; + + *) + echo "unknown option: $1" + usage 1 + ;; + esac + shift done exit 0 diff --git a/third-party/curl/docs/.gitignore b/third-party/curl/docs/.gitignore index 8d0bfb31bb..31ca7656e9 100644 --- a/third-party/curl/docs/.gitignore +++ b/third-party/curl/docs/.gitignore @@ -2,7 +2,6 @@ # # SPDX-License-Identifier: curl -*.html -*.pdf -curl.1 -*.1.dist +*.1 +*.3 +RELEASE-TOOLS.md.dist diff --git a/third-party/curl/docs/ALTSVC.md b/third-party/curl/docs/ALTSVC.md index b9117e4d46..24b961a3fb 100644 --- a/third-party/curl/docs/ALTSVC.md +++ b/third-party/curl/docs/ALTSVC.md @@ -1,3 +1,9 @@ + + # Alt-Svc curl features support for the Alt-Svc: HTTP header. @@ -24,21 +30,15 @@ space separated fields. ## Fields 1. The ALPN id for the source origin -2. The host name for the source origin +2. The hostname for the source origin 3. The port number for the source origin 4. The ALPN id for the destination host -5. The host name for the destination host -6. The host number for the destination host -7. The expiration date and time of this entry within double quotes. The date format is "YYYYMMDD HH:MM:SS" and the time zone is GMT. +5. The hostname for the destination host +6. The port number for the destination host +7. The expiration date and time of this entry within double quotes. + The date format is "YYYYMMDD HH:MM:SS" and the time zone is GMT. 8. Boolean (1 or 0) if "persist" was set for this entry 9. Integer priority value (not currently used) -If the host name is an IPv6 numerical address, it is stored with brackets such +If the hostname is an IPv6 numerical address, it is stored with brackets such as `[::1]`. - -# TODO - -- handle multiple response headers, when one of them says `clear` (should - override them all) -- using `Age:` value for caching age as per spec -- `CURLALTSVC_IMMEDIATELY` support diff --git a/third-party/curl/docs/BINDINGS.md b/third-party/curl/docs/BINDINGS.md index 7be5387eb2..6c9aba6105 100644 --- a/third-party/curl/docs/BINDINGS.md +++ b/third-party/curl/docs/BINDINGS.md @@ -1,14 +1,20 @@ + + libcurl bindings ================ - Creative people have written bindings or interfaces for various environments - and programming languages. Using one of these allows you to take advantage of - curl powers from within your favourite language or system. +Creative people have written bindings or interfaces for various environments +and programming languages. Using one of these allows you to take advantage of +curl powers from within your favorite language or system. - This is a list of all known interfaces as of this writing. +This is a list of all known interfaces as of this writing. - The bindings listed below are not part of the curl/libcurl distribution - archives, but must be downloaded and installed separately. +The bindings listed below are not part of the curl/libcurl distribution +archives, but must be downloaded and installed separately. @@ -16,9 +22,9 @@ libcurl bindings [Basic](https://scriptbasic.com/) ScriptBasic bindings written by Peter Verhas -C++: [curlpp](https://github.com/jpbarrette/curlpp/) Written by Jean-Philippe Barrette-LaPierre, -[curlcpp](https://github.com/JosephP91/curlcpp) by Giuseppe Persico and [C++ -Requests](https://github.com/libcpr/cpr) by Huu Nguyen +C++: [curlpp](https://github.com/jpbarrette/curlpp) Written by Jean-Philippe Barrette-LaPierre, +[curlcpp](https://github.com/JosephP91/curlcpp) by Giuseppe Persico and +[C++ Requests](https://github.com/libcpr/cpr) by Huu Nguyen [Ch](https://chcurl.sourceforge.net/) Written by Stephen Nestinger and Jonathan Rogado @@ -37,13 +43,13 @@ Clojure: [clj-curl](https://github.com/lsevero/clj-curl) by Lucas Severo [Euphoria](https://web.archive.org/web/20050204080544/rays-web.com/eulibcurl.htm) Written by Ray Smith -[Falcon](http://www.falconpl.org/project_docs/curl/) +[Falcon](https://web.archive.org/web/20240130001835/www.falconpl.org/project_docs/curl/) [Ferite](https://web.archive.org/web/20150102192018/ferite.org/) Written by Paul Querna [Fortran](https://github.com/interkosmos/fortran-curl) Written by Philipp Engel -[Gambas](https://gambas.sourceforge.net/) +[Gambas](https://gambaswiki.org/website/en/main.html) [glib/GTK+](https://web.archive.org/web/20100526203452/atterer.net/glibcurl) Written by Richard Atterer @@ -57,17 +63,19 @@ Go: [go-curl](https://github.com/andelf/go-curl) by ShuYu Wang [Hollywood](https://www.hollywood-mal.com/download.html) hURL by Andreas Falkenhahn -[Java](https://github.com/pjlegato/curl-java) +[Java](https://github.com/covers1624/curl4j) [Julia](https://github.com/JuliaWeb/LibCURL.jl) Written by Amit Murthy -[Kapito](https://github.com/puzza007/katipo) is an Erlang HTTP library around libcurl. +[Katipo](https://github.com/puzza007/katipo) is an Erlang HTTP library around libcurl. [Lisp](https://common-lisp.net/project/cl-curl/) Written by Liam Healy -Lua: [luacurl](https://web.archive.org/web/20201205052437/luacurl.luaforge.net/) by Alexander Marinov, [Lua-cURL](https://github.com/Lua-cURL) by Jürgen Hötzel +[LibQurl](https://github.com/Qriist/LibQurl) a feature-rich AutoHotKey v2 (AHKv2) wrapper around libcurl. -[Mono](https://web.archive.org/web/20070606064500/https://forge.novell.com/modules/xfmod/project/?libcurl-mono) Written by Jeffrey Phillips +Lua: [luacurl](https://web.archive.org/web/20201205052437/luacurl.luaforge.net/) by Alexander Marinov, [Lua-curl](https://github.com/Lua-cURL) by Jürgen Hötzel + +[Mono](https://web.archive.org/web/20070606064500/forge.novell.com/modules/xfmod/project/?libcurl-mono) Written by Jeffrey Phillips [.NET](https://sourceforge.net/projects/libcurl-net/) libcurl-net by Jeffrey Phillips @@ -90,19 +98,21 @@ Bailiff and Bálint Szilakszi, [PostgreSQL](https://github.com/pramsey/pgsql-http) - HTTP client for PostgreSQL -[PostgreSQL](https://github.com/RekGRpth/pg_curl) - cURL client for PostgreSQL +[PostgreSQL](https://github.com/RekGRpth/pg_curl) - curl client for PostgreSQL -[PureBasic](https://www.purebasic.com/documentation/http/index.html) uses libcurl in its "native" HTTP subsystem +[PureBasic](https://web.archive.org/web/20250325015028/www.purebasic.com/documentation/http/index.html) uses libcurl in its "native" HTTP subsystem -[Python](http://pycurl.io/) PycURL by Kjetil Jacobsen +[Python](https://github.com/pycurl/pycurl) PycURL by Kjetil Jacobsen + +[Python](https://pypi.org/project/pymcurl/) mcurl by Ganesh Viswanathan [Q](https://q-lang.sourceforge.net/) The libcurl module is part of the default install [R](https://cran.r-project.org/package=curl) -[Rexx](https://rexxcurl.sourceforge.net/) Written Mark Hessling +[Rexx](https://rexxcurl.sourceforge.net/) Written by Mark Hessling -[Ring](https://ring-lang.sourceforge.io/doc1.3/libcurl.html) RingLibCurl by Mahmoud Fayed +[Ring](https://ring-lang.github.io/doc1.24/libcurl.html) RingLibCurl by Mahmoud Fayed RPG, support for ILE/RPG on OS/400 is included in source distribution @@ -111,7 +121,7 @@ Ruby: [curb](https://github.com/taf2/curb) written by Ross Bamford, [Rust](https://github.com/alexcrichton/curl-rust) curl-rust - by Carl Lerche -[Scheme](http://www.metapaper.net/lisovsky/web/curl/) Bigloo binding by Kirill Lisovsky +[Scheme](https://metapaper.net/lisovsky/web/curl/) Bigloo binding by Kirill Lisovsky [Scilab](https://help.scilab.org/docs/current/fr_FR/getURL.html) binding by Sylvestre Ledru @@ -125,6 +135,8 @@ Ruby: [curb](https://github.com/taf2/curb) written by Ross Bamford, [Tcl](https://web.archive.org/web/20160826011806/mirror.yellow5.com/tclcurl/) Tclcurl by Andrés García +[Vibe](https://github.com/ttytm/vibe) HTTP requests through libcurl in V + [Visual Basic](https://sourceforge.net/projects/libcurl-vb/) libcurl-vb by Jeffrey Phillips [Visual Foxpro](https://web.archive.org/web/20130730181523/www.ctl32.com.ar/libcurl.asp) by Carlos Alloatti @@ -134,3 +146,5 @@ Ruby: [curb](https://github.com/taf2/curb) written by Ross Bamford, [XBLite](https://web.archive.org/web/20060426150418/perso.wanadoo.fr/xblite/libraries.html) Written by David Szafranski [Xojo](https://github.com/charonn0/RB-libcURL) Written by Andrew Lambert + +[Zig](https://github.com/jiacai2050/zig-curl) Written by Jiacai Liu, both easy and multi API are supported. diff --git a/third-party/curl/docs/BUFQ.md b/third-party/curl/docs/BUFQ.md deleted file mode 100644 index 5ff9e28b8c..0000000000 --- a/third-party/curl/docs/BUFQ.md +++ /dev/null @@ -1,141 +0,0 @@ -# bufq - -This is an internal module for managing I/O buffers. A `bufq` can be written -to and read from. It manages read and write positions and has a maximum size. - -## read/write - -Its basic read/write functions have a similar signature and return code handling -as many internal Curl read and write ones. - - -``` -ssize_t Curl_bufq_write(struct bufq *q, const unsigned char *buf, size_t len, CURLcode *err); - -- returns the length written into `q` or -1 on error. -- writing to a full `q` will return -1 and set *err to CURLE_AGAIN - -ssize_t Curl_bufq_read(struct bufq *q, unsigned char *buf, size_t len, CURLcode *err); - -- returns the length read from `q` or -1 on error. -- reading from an empty `q` will return -1 and set *err to CURLE_AGAIN - -``` - -To pass data into a `bufq` without an extra copy, read callbacks can be used. - -``` -typedef ssize_t Curl_bufq_reader(void *reader_ctx, unsigned char *buf, size_t len, - CURLcode *err); - -ssize_t Curl_bufq_slurp(struct bufq *q, Curl_bufq_reader *reader, void *reader_ctx, - CURLcode *err); -``` - -`Curl_bufq_slurp()` will invoke the given `reader` callback, passing it its own internal -buffer memory to write to. It may invoke the `reader` several times, as long as it has space -and while the `reader` always returns the length that was requested. There are variations of `slurp` that call the `reader` at most once or only read in a -maximum amount of bytes. - -The analog mechanism for write out buffer data is: - -``` -typedef ssize_t Curl_bufq_writer(void *writer_ctx, const unsigned char *buf, size_t len, - CURLcode *err); - -ssize_t Curl_bufq_pass(struct bufq *q, Curl_bufq_writer *writer, void *writer_ctx, - CURLcode *err); -``` - -`Curl_bufq_pass()` will invoke the `writer`, passing its internal memory and remove the -amount that `writer` reports. - -## peek and skip - -It is possible to get access to the memory of data stored in a `bufq` with: - -``` -bool Curl_bufq_peek(const struct bufq *q, const unsigned char **pbuf, size_t *plen); -``` - -On returning TRUE, `pbuf` will point to internal memory with `plen` bytes that one may read. This will only -be valid until another operation on `bufq` is performed. - -Instead of reading `bufq` data, one may simply skip it: - -``` -void Curl_bufq_skip(struct bufq *q, size_t amount); -``` - -This will remove `amount` number of bytes from the `bufq`. - - -## lifetime - -`bufq` is initialized and freed similar to the `dynbuf` module. Code using `bufq` will -hold a `struct bufq` somewhere. Before it uses it, it invokes: - -``` -void Curl_bufq_init(struct bufq *q, size_t chunk_size, size_t max_chunks); -``` - -The `bufq` is told how many "chunks" of data it shall hold at maximum and how large those -"chunks" should be. There are some variants of this, allowing for more options. How "chunks" are handled in a `bufq` is presented in the section about memory management. - -The user of the `bufq` has the responsibility to call: - -``` -void Curl_bufq_free(struct bufq *q); -``` -to free all resources held by `q`. It is possible to reset a `bufq` to empty via: - -``` -void Curl_bufq_reset(struct bufq *q); -``` - -## memory management - -Internally, a `bufq` uses allocation of fixed size, e.g. the "chunk_size", up to a maximum number, e.g. "max_chunks". These chunks are allocated on demand, therefore writing to a `bufq` may return `CURLE_OUT_OF_MEMORY`. Once the max number of chunks are used, the `bufq` will report that it is "full". - -Each chunks has a `read` and `write` index. A `bufq` keeps its chunks in a list. Reading happens always at the head chunk, writing always goes to the tail chunk. When the head chunk becomes empty, it is removed. When the tail chunk becomes full, another chunk is added to the end of the list, becoming the new tail. - -Chunks that are no longer used are returned to a `spare` list by default. If the `bufq` is created with option `BUFQ_OPT_NO_SPARES` those chunks will be freed right away. - -If a `bufq` is created with a `bufc_pool`, the no longer used chunks are returned to the pool. Also `bufq` will ask the pool for a chunk when it needs one. More in section "pools". - -## empty, full and overflow - -One can ask about the state of a `bufq` with methods such as `Curl_bufq_is_empty(q)`, -`Curl_bufq_is_full(q)`, etc. The amount of data held by a `bufq` is the sum of the data in all its chunks. This is what is reported by `Curl_bufq_len(q)`. - -Note that a `bufq` length and it being "full" are only loosely related. A simple example: - -* create a `bufq` with chunk_size=1000 and max_chunks=4. -* write 4000 bytes to it, it will report "full" -* read 1 bytes from it, it will still report "full" -* read 999 more bytes from it, and it will no longer be "full" - -The reason for this is that full really means: *bufq uses max_chunks and the last one cannot be written to*. - -So when you read 1 byte from the head chunk in the example above, the head still hold 999 unread bytes. Only when those are also read, can the head chunk be removed and a new tail be added. - -There is another variation to this. If you initialized a `bufq` with option `BUFQ_OPT_SOFT_LIMIT`, it will allow writes **beyond** the `max_chunks`. It will report **full**, but one can **still** write. This option is necessary, if partial writes need to be avoided. But it means that you will need other checks to keep the `bufq` from growing ever larger and larger. - - -## pools - -A `struct bufc_pool` may be used to create chunks for a `bufq` and keep spare ones around. It is initialized -and used via: - -``` -void Curl_bufcp_init(struct bufc_pool *pool, size_t chunk_size, size_t spare_max); - -void Curl_bufq_initp(struct bufq *q, struct bufc_pool *pool, size_t max_chunks, int opts); -``` - -The pool gets the size and the mount of spares to keep. The `bufq` gets the pool and the `max_chunks`. It no longer needs to know the chunk sizes, as those are managed by the pool. - -A pool can be shared between many `bufq`s, as long as all of them operate in the same thread. In curl that would be true for all transfers using the same multi handle. The advantages of a pool are: - -* when all `bufq`s are empty, only memory for `max_spare` chunks in the pool is used. Empty `bufq`s will hold no memory. -* the latest spare chunk is the first to be handed out again, no matter which `bufq` needs it. This keeps the footprint of "recently used" memory smaller. diff --git a/third-party/curl/docs/BUG-BOUNTY.md b/third-party/curl/docs/BUG-BOUNTY.md index 3714efda52..765cf493e6 100644 --- a/third-party/curl/docs/BUG-BOUNTY.md +++ b/third-party/curl/docs/BUG-BOUNTY.md @@ -1,78 +1,16 @@ -# The curl bug bounty + -## How does it work? +# No curl bug bounty -Start out by posting your suspected security vulnerability directly to [curl's -HackerOne program](https://hackerone.com/curl). +The curl project does not offer any rewards for reported bugs or +vulnerabilities. We do not aid security researchers to get such rewards for +curl problems from other sources. -After you have reported a security issue, it has been deemed credible, and a -patch and advisory has been made public, you may be eligible for a bounty from -this program. See the [Security Process](https://curl.se/dev/secprocess.html) -document for how we work with security issues. +A bug bounty gives people too strong incentives to find and make up "problems" +in bad faith that cause overload and abuse. -## What are the reward amounts? - -The curl project offers monetary compensation for reported and published -security vulnerabilities. The amount of money that is rewarded depends on how -serious the flaw is determined to be. - -Since 2021, the Bug Bounty is managed in association with the Internet Bug -Bounty and they will set the reward amounts. If it would turn out that they -set amounts that are way lower than we can accept, the curl project intends to -"top up" rewards. - -In 2022, typical "Medium" rated vulnerabilities have been rewarded 2,400 USD -each. - -## Who is eligible for a reward? - -Everyone and anyone who reports a security problem in a released curl version -that has not already been reported can ask for a bounty. - -Dedicated - paid for - security audits that are performed in collaboration -with curl developers are not eligible for bounties. - -Vulnerabilities in features that are off by default and documented as -experimental are not eligible for a reward. - -The vulnerability has to be fixed and publicly announced (by the curl project) -before a bug bounty will be considered. - -Once the vulnerability has been published by curl, the researcher can request -their bounty from the [Internet Bug Bounty](https://hackerone.com/ibb). - -Bounties need to be requested within twelve months from the publication of the -vulnerability. - -## Product vulnerabilities only - -This bug bounty only concerns the curl and libcurl products and thus their -respective source codes - when running on existing hardware. It does not -include curl documentation, curl websites, or other curl related -infrastructure. - -The curl security team is the sole arbiter if a reported flaw is subject to a -bounty or not. - -## How are vulnerabilities graded? - -The grading of each reported vulnerability that makes a reward claim will be -performed by the curl security team. The grading will be based on the CVSS -(Common Vulnerability Scoring System) 3.0. - -## How are reward amounts determined? - -The curl security team gives the vulnerability a score or severity level, as -mentioned above. The actual monetary reward amount is decided and paid by the -Internet Bug Bounty.. - -## Regarding taxes, etc. on the bounties - -In the event that the individual receiving a bug bounty needs to pay taxes on -the reward money, the responsibility lies with the receiver. The curl project -or its security team never actually receive any of this money, hold the money, -or pay out the money. +We still appreciate and value valid vulnerability reports. diff --git a/third-party/curl/docs/BUGS.md b/third-party/curl/docs/BUGS.md index 2a8c56fe62..5f3704771b 100644 --- a/third-party/curl/docs/BUGS.md +++ b/third-party/curl/docs/BUGS.md @@ -1,265 +1,267 @@ + + # BUGS ## There are still bugs - Curl and libcurl keep being developed. Adding features and changing code - means that bugs will sneak in, no matter how hard we try to keep them out. +curl and libcurl keep being developed. Adding features and changing code +means that bugs sneak in, no matter how hard we try to keep them out. - Of course there are lots of bugs left. And lots of misfeatures. +Of course there are lots of bugs left. Not to mention misfeatures. - To help us make curl the stable and solid product we want it to be, we need - bug reports and bug fixes. +To help us make curl the stable and solid product we want it to be, we need +bug reports and bug fixes. ## Where to report - If you cannot fix a bug yourself and submit a fix for it, try to report an as - detailed report as possible to a curl mailing list to allow one of us to have - a go at a solution. You can optionally also submit your problem in [curl's - bug tracking system](https://github.com/curl/curl/issues). +If you cannot fix a bug yourself and submit a fix for it, try to report an as +detailed report as possible to a curl mailing list to allow one of us to have +a go at a solution. You can optionally also submit your problem in +[curl's bug tracking system](https://github.com/curl/curl/issues). - Please read the rest of this document below first before doing that. +Please read the rest of this document below first before doing that. - If you feel you need to ask around first, find a suitable [mailing list]( - https://curl.se/mail/) and post your questions there. +If you feel you need to ask around first, find a suitable +[mailing list](https://curl.se/mail/) and post your questions there. ## Security bugs - If you find a bug or problem in curl or libcurl that you think has a security - impact, for example a bug that can put users in danger or make them - vulnerable if the bug becomes public knowledge, then please report that bug - using our security development process. +If you find a bug or problem in curl or libcurl that you think has a security +impact, for example a bug that can put users in danger or make them +vulnerable if the bug becomes public knowledge, then please report that bug +using our security development process. - Security related bugs or bugs that are suspected to have a security impact, - should be reported on the [curl security tracker at - HackerOne](https://hackerone.com/curl). +Security related bugs or bugs that are suspected to have a security impact, +should be reported [privately](https://curl.se/dev/vuln-disclosure.html). - This ensures that the report reaches the curl security team so that they - first can deal with the report away from the public to minimize the harm - and impact it will have on existing users out there who might be using the - vulnerable versions. +This ensures that the report reaches the curl security team so that they first +can deal with the report away from the public to minimize the harm and impact +it has on existing users out there who might be using the vulnerable versions. - The curl project's process for handling security related issues is - [documented separately](https://curl.se/dev/secprocess.html). +The curl project's process for handling security related issues is +[documented separately](https://curl.se/dev/secprocess.html). ## What to report - When reporting a bug, you should include all information that will help us - understand what is wrong, what you expected to happen and how to repeat the - bad behavior. You therefore need to tell us: +When reporting a bug, you should include all information to help us +understand what is wrong, what you expected to happen and how to repeat the +bad behavior. You therefore need to tell us: - - your operating system's name and version number +- your operating system's name and version number - - what version of curl you are using (`curl -V` is fine) +- what version of curl you are using (`curl -V` is fine) - - versions of the used libraries that libcurl is built to use +- versions of the used libraries that libcurl is built to use - - what URL you were working with (if possible), at least which protocol +- what URL you were working with (if possible), at least which protocol - and anything and everything else you think matters. Tell us what you expected - to happen, tell use what did happen, tell us how you could make it work - another way. Dig around, try out, test. Then include all the tiny bits and - pieces in your report. You will benefit from this yourself, as it will enable - us to help you quicker and more accurately. +and anything and everything else you think matters. Tell us what you expected +to happen, tell us what did happen, tell us how you could make it work +another way. Dig around, try out, test. Then include all the tiny bits and +pieces in your report. You benefit from this yourself, as it enables us to +help you quicker and more accurately. - Since curl deals with networks, it often helps us if you include a protocol - debug dump with your bug report. The output you get by using the `-v` or - `--trace` options. +Since curl deals with networks, it often helps us if you include a protocol +debug dump with your bug report. The output you get by using the `-v` or +`--trace` options. - If curl crashed, causing a core dump (in Unix), there is hardly any use to - send that huge file to anyone of us. Unless we have the same system setup as - you, we cannot do much with it. Instead, we ask you to get a stack trace and - send that (much smaller) output to us instead. +If curl crashed, causing a core dump (in Unix), there is hardly any use to +send that huge file to anyone of us. Unless we have the same system setup as +you, we cannot do much with it. Instead, we ask you to get a stack trace and +send that (much smaller) output to us instead. - The address and how to subscribe to the mailing lists are detailed in the - `MANUAL.md` file. +The address and how to subscribe to the mailing lists are detailed in the +`MANUAL.md` file. ## libcurl problems - When you have written your own application with libcurl to perform transfers, - it is even more important to be specific and detailed when reporting bugs. +When you have written your own application with libcurl to perform transfers, +it is even more important to be specific and detailed when reporting bugs. - Tell us the libcurl version and your operating system. Tell us the name and - version of all relevant sub-components like for example the SSL library - you are using and what name resolving your libcurl uses. If you use SFTP or - SCP, the libssh2 version is relevant etc. +Tell us the libcurl version and your operating system. Tell us the name and +version of all relevant sub-components like for example the SSL library +you are using and what name resolving your libcurl uses. If you use SFTP or +SCP, the libssh2 version is relevant etc. - Showing us a real source code example repeating your problem is the best way - to get our attention and it will greatly increase our chances to understand - your problem and to work on a fix (if we agree it truly is a problem). +Showing us a real source code example repeating your problem is the best way +to get our attention and it greatly increases our chances to understand your +problem and to work on a fix (if we agree it truly is a problem). - Lots of problems that appear to be libcurl problems are actually just abuses - of the libcurl API or other malfunctions in your applications. It is advised - that you run your problematic program using a memory debug tool like valgrind - or similar before you post memory-related or "crashing" problems to us. +Lots of problems that appear to be libcurl problems are instead abuses of the +libcurl API or other malfunctions in your applications. It is advised that you +run your problematic program using a memory debug tool like valgrind or +similar before you post memory-related or "crashing" problems to us. -## Who will fix the problems +## Who fixes the problems - If the problems or bugs you describe are considered to be bugs, we want to - have the problems fixed. +If the problems or bugs you describe are considered to be bugs, we want to +have the problems fixed. - There are no developers in the curl project that are paid to work on bugs. - All developers that take on reported bugs do this on a voluntary basis. We do - it out of an ambition to keep curl and libcurl excellent products and out of - pride. +There are no developers in the curl project that are paid to work on bugs. +All developers that take on reported bugs do this on a voluntary basis. We do +it out of an ambition to keep curl and libcurl excellent products and out of +pride. - Please do not assume that you can just lump over something to us and it will - then magically be fixed after some given time. Most often we need feedback - and help to understand what you have experienced and how to repeat a - problem. Then we may only be able to assist YOU to debug the problem and to - track down the proper fix. +Please do not assume that you can lump over something to us and it then +automatically gets fixed after some given time. Most often we need feedback +and help to understand what you have experienced and how to repeat a problem. +Then we may only be able to assist YOU to debug the problem and to track down +the proper fix. - We get reports from many people every month and each report can take a - considerable amount of time to really go to the bottom with. +We get reports from many people every month and each report can take a +considerable amount of time to really go to the bottom with. ## How to get a stack trace - First, you must make sure that you compile all sources with `-g` and that you - do not 'strip' the final executable. Try to avoid optimizing the code as well, - remove `-O`, `-O2` etc from the compiler options. +First, you must make sure that you compile all sources with `-g` and that you +do not 'strip' the final executable. Try to avoid optimizing the code as well, +remove `-O`, `-O2` etc from the compiler options. - Run the program until it cores. +Run the program until it cores. - Run your debugger on the core file, like ` curl - core`. `` should be replaced with the name of your debugger, in - most cases that will be `gdb`, but `dbx` and others also occur. +Run your debugger on the core file, like ` curl core`. `` +should be replaced with the name of your debugger, in most cases that is +`gdb`, but `dbx` and others also occur. - When the debugger has finished loading the core file and presents you a - prompt, enter `where` (without quotes) and press return. +When the debugger has finished loading the core file and presents you a +prompt, enter `where` (without quotes) and press return. - The list that is presented is the stack trace. If everything worked, it is - supposed to contain the chain of functions that were called when curl - crashed. Include the stack trace with your detailed bug report, it will help a - lot. +The list that is presented is the stack trace. If everything worked, it is +supposed to contain the chain of functions that were called when curl +crashed. Include the stack trace with your detailed bug report, it helps a +lot. ## Bugs in libcurl bindings - There will of course pop up bugs in libcurl bindings. You should then - primarily approach the team that works on that particular binding and see - what you can do to help them fix the problem. +There are of course bugs in libcurl bindings. You should then primarily +approach the team that works on that particular binding and see what you can +do to help them fix the problem. - If you suspect that the problem exists in the underlying libcurl, then please - convert your program over to plain C and follow the steps outlined above. +If you suspect that the problem exists in the underlying libcurl, then please +convert your program over to plain C and follow the steps outlined above. ## Bugs in old versions - The curl project typically releases new versions every other month, and we - fix several hundred bugs per year. For a huge table of releases, number of - bug fixes and more, see: https://curl.se/docs/releases.html +The curl project typically releases new versions every other month, and we +fix several hundred bugs per year. For a huge table of releases, number of +bug fixes and more, see: https://curl.se/docs/releases.html - The developers in the curl project do not have bandwidth or energy enough to - maintain several branches or to spend much time on hunting down problems in - old versions when chances are we already fixed them or at least that they have - changed nature and appearance in later versions. +The developers in the curl project do not have bandwidth or energy enough to +maintain several branches or to spend much time on hunting down problems in +old versions when chances are we already fixed them or at least that they have +changed nature and appearance in later versions. - When you experience a problem and want to report it, you really SHOULD - include the version number of the curl you are using when you experience the - issue. If that version number shows us that you are using an out-of-date curl, - you should also try out a modern curl version to see if the problem persists - or how/if it has changed in appearance. +When you experience a problem and want to report it, you really SHOULD +include the version number of the curl you are using when you experience the +issue. If that version number shows us that you are using an out-of-date curl, +you should also try out a modern curl version to see if the problem persists +or how/if it has changed in appearance. - Even if you cannot immediately upgrade your application/system to run the - latest curl version, you can most often at least run a test version or - experimental build or similar, to get this confirmed or not. +Even if you cannot immediately upgrade your application/system to run the +latest curl version, you can most often at least run a test version or +experimental build or similar, to get this confirmed or not. - At times people insist that they cannot upgrade to a modern curl version, but - instead, they "just want the bug fixed". That is fine, just do not count on us - spending many cycles on trying to identify which single commit, if that is - even possible, that at some point in the past fixed the problem you are now - experiencing. +At times people insist that they cannot upgrade to a modern curl version, they +only "want the bug fixed". That is fine, but do not count on us spending many +cycles on trying to identify which single commit, if that is even possible, +that at some point in the past fixed the problem you are now experiencing. - Security wise, it is almost always a bad idea to lag behind the current curl - versions by a lot. We keep discovering and reporting security problems - over time see you can see in [this - table](https://curl.se/docs/vulnerabilities.html) +Security wise, it is almost always a bad idea to lag behind the current curl +versions by a lot. We keep discovering and reporting security problems +over time see you can see in +[this table](https://curl.se/docs/vulnerabilities.html) # Bug fixing procedure ## What happens on first filing - When a new issue is posted in the issue tracker or on the mailing list, the - team of developers first needs to see the report. Maybe they took the day off, - maybe they are off in the woods hunting. Have patience. Allow at least a few - days before expecting someone to have responded. +When a new issue is posted in the issue tracker or on the mailing list, the +team of developers first needs to see the report. Maybe they took the day off, +maybe they are off in the woods hunting. Have patience. Allow at least a few +days before expecting someone to have responded. - In the issue tracker, you can expect that some labels will be set on the issue - to help categorize it. +In the issue tracker, you can expect that some labels are set on the issue to +help categorize it. ## First response - If your issue/bug report was not perfect at once (and few are), chances are - that someone will ask follow-up questions. Which version did you use? Which - options did you use? How often does the problem occur? How can we reproduce - this problem? Which protocols does it involve? Or perhaps much more specific - and deep diving questions. It all depends on your specific issue. +If your issue/bug report was not perfect at once (and few are), chances are +that someone asks follow-up questions. Which version did you use? Which +options did you use? How often does the problem occur? How can we reproduce +this problem? Which protocols does it involve? Or perhaps much more specific +and deep diving questions. It all depends on your specific issue. - You should then respond to these follow-up questions and provide more info - about the problem, so that we can help you figure it out. Or maybe you can - help us figure it out. An active back-and-forth communication is important - and the key for finding a cure and landing a fix. +You should then respond to these follow-up questions and provide more info +about the problem, so that we can help you figure it out. Or maybe you can +help us figure it out. An active back-and-forth communication is important +and the key for finding a cure and landing a fix. ## Not reproducible - We may require further work from you who actually see or experience the - problem if we cannot reproduce it and cannot understand it even after having - gotten all the info we need and having studied the source code over again. +We may require further work from you who actually see or experience the +problem if we cannot reproduce it and cannot understand it even after having +gotten all the info we need and having studied the source code over again. ## Unresponsive - If the problem have not been understood or reproduced, and there is nobody - responding to follow-up questions or questions asking for clarifications or - for discussing possible ways to move forward with the task, we take that as a - strong suggestion that the bug is unimportant. +If the problem have not been understood or reproduced, and there is nobody +responding to follow-up questions or questions asking for clarifications or +for discussing possible ways to move forward with the task, we take that as a +strong suggestion that the bug is unimportant. - Unimportant issues will be closed as inactive sooner or later as they cannot - be fixed. The inactivity period (waiting for responses) should not be shorter - than two weeks but may extend months. +Unimportant issues are closed as inactive sooner or later as they cannot be +fixed. The inactivity period (waiting for responses) should not be shorter +than two weeks but may extend months. ## Lack of time/interest - Bugs that are filed and are understood can unfortunately end up in the - "nobody cares enough about it to work on it" category. Such bugs are - perfectly valid problems that *should* get fixed but apparently are not. We - try to mark such bugs as `KNOWN_BUGS material` after a time of inactivity and - if no activity is noticed after yet some time those bugs are added to the - `KNOWN_BUGS` document and are closed in the issue tracker. +Bugs that are filed and are understood can unfortunately end up in the +"nobody cares enough about it to work on it" category. Such bugs are +perfectly valid problems that *should* get fixed but apparently are not. We +try to mark such bugs as `KNOWN_BUGS material` after a time of inactivity and +if no activity is noticed after yet some time those bugs are added to the +`KNOWN_BUGS` document and are closed in the issue tracker. ## `KNOWN_BUGS` - This is a list of known bugs. Bugs we know exist and that have been pointed - out but that have not yet been fixed. The reasons for why they have not been - fixed can involve anything really, but the primary reason is that nobody has - considered these problems to be important enough to spend the necessary time - and effort to have them fixed. +This is a list of known bugs. Bugs we know exist and that have been pointed +out but that have not yet been fixed. The reasons for why they have not been +fixed can involve anything really, but the primary reason is that nobody has +considered these problems to be important enough to spend the necessary time +and effort to have them fixed. - The `KNOWN_BUGS` items are always up for grabs and we love the ones who bring - one of them back to life and offer solutions to them. +The `KNOWN_BUGS` items are always up for grabs and we love the ones who bring +one of them back to life and offer solutions to them. - The `KNOWN_BUGS` document has a sibling document known as `TODO`. +The `KNOWN_BUGS` document has a sibling document known as `TODO`. ## `TODO` - Issues that are filed or reported that are not really bugs but more missing - features or ideas for future improvements and so on are marked as - 'enhancement' or 'feature-request' and will be added to the `TODO` document - and the issues are closed. We do not keep TODO items open in the issue - tracker. +Issues that are filed or reported that are not really bugs but more missing +features or ideas for future improvements and so on are marked as +*enhancement* or *feature-request* and get added to the `TODO` document and +the issues are closed. We do not keep TODO items open in the issue tracker. - The `TODO` document is full of ideas and suggestions of what we can add or - fix one day. You are always encouraged and free to grab one of those items and - take up a discussion with the curl development team on how that could be - implemented or provided in the project so that you can work on ticking it odd - that document. +The `TODO` document is full of ideas and suggestions of what we can add or +fix one day. You are always encouraged and free to grab one of those items and +take up a discussion with the curl development team on how that could be +implemented or provided in the project so that you can work on ticking it odd +that document. - If an issue is rather a bug and not a missing feature or functionality, it is - listed in `KNOWN_BUGS` instead. +If an issue is rather a bug and not a missing feature or functionality, it is +listed in `KNOWN_BUGS` instead. ## Closing off stalled bugs - The [issue and pull request trackers](https://github.com/curl/curl) only - hold "active" entries open (using a non-precise definition of what active - actually is, but they are at least not completely dead). Those that are - abandoned or in other ways dormant will be closed and sometimes added to - `TODO` and `KNOWN_BUGS` instead. +The [issue and pull request trackers](https://github.com/curl/curl) only hold +"active" entries open (using a non-precise definition of what active actually +is, but they are at least not completely dead). Those that are abandoned or +in other ways dormant are closed and sometimes added to `TODO` and +`KNOWN_BUGS` instead. - This way, we only have "active" issues open on GitHub. Irrelevant issues and - pull requests will not distract developers or casual visitors. +This way, we only have "active" issues open on GitHub. Irrelevant issues and +pull requests do not distract developers or casual visitors. diff --git a/third-party/curl/docs/CHECKSRC.md b/third-party/curl/docs/CHECKSRC.md deleted file mode 100644 index 476df262a1..0000000000 --- a/third-party/curl/docs/CHECKSRC.md +++ /dev/null @@ -1,182 +0,0 @@ -# checksrc - -This is the tool we use within the curl project to scan C source code and -check that it adheres to our [Source Code Style guide](CODE_STYLE.md). - -## Usage - - checksrc.pl [options] [file1] [file2] ... - -## Command line options - -`-W[file]` skip that file and exclude it from being checked. Helpful -when, for example, one of the files is generated. - -`-D[dir]` directory name to prepend to file names when accessing them. - -`-h` shows the help output, that also lists all recognized warnings - -## What does `checksrc` warn for? - -`checksrc` does not check and verify the code against the entire style guide. -The script is an effort to detect the most common mistakes and syntax mistakes -that contributors make before they get accustomed to our code style. Heck, -many of us regulars do the mistakes too and this script helps us keep the code -in shape. - - checksrc.pl -h - -Lists how to use the script and it lists all existing warnings it has and -problems it detects. At the time of this writing, the existing `checksrc` -warnings are: - -- `ASSIGNWITHINCONDITION`: Assignment within a conditional expression. The - code style mandates the assignment to be done outside of it. - -- `ASTERISKNOSPACE`: A pointer was declared like `char* name` instead of the - more appropriate `char *name` style. The asterisk should sit next to the - name. - -- `ASTERISKSPACE`: A pointer was declared like `char * name` instead of the - more appropriate `char *name` style. The asterisk should sit right next to - the name without a space in between. - -- `BADCOMMAND`: There is a bad `checksrc` instruction in the code. See the - **Ignore certain warnings** section below for details. - -- `BANNEDFUNC`: A banned function was used. The functions sprintf, vsprintf, - strcat, strncat, gets are **never** allowed in curl source code. - -- `BRACEELSE`: '} else' on the same line. The else is supposed to be on the - following line. - -- `BRACEPOS`: wrong position for an open brace (`{`). - -- `BRACEWHILE`: more than once space between end brace and while keyword - -- `COMMANOSPACE`: a comma without following space - -- `COPYRIGHT`: the file is missing a copyright statement - -- `CPPCOMMENTS`: `//` comment detected, that is not C89 compliant - -- `DOBRACE`: only use one space after do before open brace - -- `EMPTYLINEBRACE`: found empty line before open brace - -- `EQUALSNOSPACE`: no space after `=` sign - -- `EQUALSNULL`: comparison with `== NULL` used in if/while. We use `!var`. - -- `EXCLAMATIONSPACE`: space found after exclamations mark - -- `FOPENMODE`: `fopen()` needs a macro for the mode string, use it - -- `INDENTATION`: detected a wrong start column for code. Note that this - warning only checks some specific places and will certainly miss many bad - indentations. - -- `LONGLINE`: A line is longer than 79 columns. - -- `MULTISPACE`: Multiple spaces were found where only one should be used. - -- `NOSPACEEQUALS`: An equals sign was found without preceding space. We prefer - `a = 2` and *not* `a=2`. - -- `NOTEQUALSZERO`: check found using `!= 0`. We use plain `if(var)`. - -- `ONELINECONDITION`: do not put the conditional block on the same line as `if()` - -- `OPENCOMMENT`: File ended with a comment (`/*`) still "open". - -- `PARENBRACE`: `){` was used without sufficient space in between. - -- `RETURNNOSPACE`: `return` was used without space between the keyword and the - following value. - -- `SEMINOSPACE`: There was no space (or newline) following a semicolon. - -- `SIZEOFNOPAREN`: Found use of sizeof without parentheses. We prefer - `sizeof(int)` style. - -- `SNPRINTF` - Found use of `snprintf()`. Since we use an internal replacement - with a different return code etc, we prefer `msnprintf()`. - -- `SPACEAFTERPAREN`: there was a space after open parenthesis, `( text`. - -- `SPACEBEFORECLOSE`: there was a space before a close parenthesis, `text )`. - -- `SPACEBEFORECOMMA`: there was a space before a comma, `one , two`. - -- `SPACEBEFOREPAREN`: there was a space before an open parenthesis, `if (`, - where one was not expected - -- `SPACESEMICOLON`: there was a space before semicolon, ` ;`. - -- `TABS`: TAB characters are not allowed - -- `TRAILINGSPACE`: Trailing whitespace on the line - -- `TYPEDEFSTRUCT`: we frown upon (most) typedefed structs - -- `UNUSEDIGNORE`: a `checksrc` inlined warning ignore was asked for but not - used, that is an ignore that should be removed or changed to get used. - -### Extended warnings - -Some warnings are quite computationally expensive to perform, so they are -turned off by default. To enable these warnings, place a `.checksrc` file in -the directory where they should be activated with commands to enable the -warnings you are interested in. The format of the file is to enable one -warning per line like so: `enable ` - -Currently these are the extended warnings which can be enabled: - -- `COPYRIGHTYEAR`: the current changeset has not updated the copyright year in - the source file - -- `STRERROR`: use of banned function strerror() - -## Ignore certain warnings - -Due to the nature of the source code and the flaws of the `checksrc` tool, -there is sometimes a need to ignore specific warnings. `checksrc` allows a few -different ways to do this. - -### Inline ignore - -You can control what to ignore within a specific source file by providing -instructions to `checksrc` in the source code itself. See examples below. The -instruction can ask to ignore a specific warning a specific number of times or -you ignore all of them until you mark the end of the ignored section. - -Inline ignores are only done for that single specific source code file. - -Example - - /* !checksrc! disable LONGLINE all */ - -This will ignore the warning for overly long lines until it is re-enabled with: - - /* !checksrc! enable LONGLINE */ - -If the enabling is not performed before the end of the file, it will be enabled -automatically for the next file. - -You can also opt to ignore just N violations so that if you have a single long -line you just cannot shorten and is agreed to be fine anyway: - - /* !checksrc! disable LONGLINE 1 */ - -... and the warning for long lines will be enabled again automatically after -it has ignored that single warning. The number `1` can of course be changed to -any other integer number. It can be used to make sure only the exact intended -instances are ignored and nothing extra. - -### Directory wide ignore patterns - -This is a method we have transitioned away from. Use inline ignores as far as -possible. - -Make a `checksrc.skip` file in the directory of the source code with the -false positive, and include the full offending line into this file. diff --git a/third-party/curl/docs/CIPHERS-TLS12.md b/third-party/curl/docs/CIPHERS-TLS12.md new file mode 100644 index 0000000000..d67c62ba7e --- /dev/null +++ b/third-party/curl/docs/CIPHERS-TLS12.md @@ -0,0 +1,336 @@ + + +# TLS 1.2 cipher suites + +| Id | IANA name | OpenSSL name | RFC | +|--------|-----------------------------------------------|------------------------------------|--------------------| +| 0x0001 | TLS_RSA_WITH_NULL_MD5 | NULL-MD5 | [RFC5246] | +| 0x0002 | TLS_RSA_WITH_NULL_SHA | NULL-SHA | [RFC5246] | +| 0x0003 | TLS_RSA_EXPORT_WITH_RC4_40_MD5 | EXP-RC4-MD5 | [RFC4346][RFC6347] | +| 0x0004 | TLS_RSA_WITH_RC4_128_MD5 | RC4-MD5 | [RFC5246][RFC6347] | +| 0x0005 | TLS_RSA_WITH_RC4_128_SHA | RC4-SHA | [RFC5246][RFC6347] | +| 0x0006 | TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 | EXP-RC2-CBC-MD5 | [RFC4346] | +| 0x0007 | TLS_RSA_WITH_IDEA_CBC_SHA | IDEA-CBC-SHA | [RFC8996] | +| 0x0008 | TLS_RSA_EXPORT_WITH_DES40_CBC_SHA | EXP-DES-CBC-SHA | [RFC4346] | +| 0x0009 | TLS_RSA_WITH_DES_CBC_SHA | DES-CBC-SHA | [RFC8996] | +| 0x000A | TLS_RSA_WITH_3DES_EDE_CBC_SHA | DES-CBC3-SHA | [RFC5246] | +| 0x000B | TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA | EXP-DH-DSS-DES-CBC-SHA | [RFC4346] | +| 0x000C | TLS_DH_DSS_WITH_DES_CBC_SHA | DH-DSS-DES-CBC-SHA | [RFC8996] | +| 0x000D | TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA | DH-DSS-DES-CBC3-SHA | [RFC5246] | +| 0x000E | TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA | EXP-DH-RSA-DES-CBC-SHA | [RFC4346] | +| 0x000F | TLS_DH_RSA_WITH_DES_CBC_SHA | DH-RSA-DES-CBC-SHA | [RFC8996] | +| 0x0010 | TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA | DH-RSA-DES-CBC3-SHA | [RFC5246] | +| 0x0011 | TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA | EXP-DHE-DSS-DES-CBC-SHA | [RFC4346] | +| 0x0012 | TLS_DHE_DSS_WITH_DES_CBC_SHA | DHE-DSS-DES-CBC-SHA | [RFC8996] | +| 0x0013 | TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA | DHE-DSS-DES-CBC3-SHA | [RFC5246] | +| 0x0014 | TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA | EXP-DHE-RSA-DES-CBC-SHA | [RFC4346] | +| 0x0015 | TLS_DHE_RSA_WITH_DES_CBC_SHA | DHE-RSA-DES-CBC-SHA | [RFC8996] | +| 0x0016 | TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA | DHE-RSA-DES-CBC3-SHA | [RFC5246] | +| 0x0017 | TLS_DH_anon_EXPORT_WITH_RC4_40_MD5 | EXP-ADH-RC4-MD5 | [RFC4346][RFC6347] | +| 0x0018 | TLS_DH_anon_WITH_RC4_128_MD5 | ADH-RC4-MD5 | [RFC5246][RFC6347] | +| 0x0019 | TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA | EXP-ADH-DES-CBC-SHA | [RFC4346] | +| 0x001A | TLS_DH_anon_WITH_DES_CBC_SHA | ADH-DES-CBC-SHA | [RFC8996] | +| 0x001B | TLS_DH_anon_WITH_3DES_EDE_CBC_SHA | ADH-DES-CBC3-SHA | [RFC5246] | +| 0x001C | | FZA-NULL-SHA | | +| 0x001D | | FZA-FZA-CBC-SHA | | +| 0x001E | TLS_KRB5_WITH_DES_CBC_SHA | KRB5-DES-CBC-SHA | [RFC2712] | +| 0x001F | TLS_KRB5_WITH_3DES_EDE_CBC_SHA | KRB5-DES-CBC3-SHA | [RFC2712] | +| 0x0020 | TLS_KRB5_WITH_RC4_128_SHA | KRB5-RC4-SHA | [RFC2712][RFC6347] | +| 0x0021 | TLS_KRB5_WITH_IDEA_CBC_SHA | KRB5-IDEA-CBC-SHA | [RFC2712] | +| 0x0022 | TLS_KRB5_WITH_DES_CBC_MD5 | KRB5-DES-CBC-MD5 | [RFC2712] | +| 0x0023 | TLS_KRB5_WITH_3DES_EDE_CBC_MD5 | KRB5-DES-CBC3-MD5 | [RFC2712] | +| 0x0024 | TLS_KRB5_WITH_RC4_128_MD5 | KRB5-RC4-MD5 | [RFC2712][RFC6347] | +| 0x0025 | TLS_KRB5_WITH_IDEA_CBC_MD5 | KRB5-IDEA-CBC-MD5 | [RFC2712] | +| 0x0026 | TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA | EXP-KRB5-DES-CBC-SHA | [RFC2712] | +| 0x0027 | TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA | EXP-KRB5-RC2-CBC-SHA | [RFC2712] | +| 0x0028 | TLS_KRB5_EXPORT_WITH_RC4_40_SHA | EXP-KRB5-RC4-SHA | [RFC2712][RFC6347] | +| 0x0029 | TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5 | EXP-KRB5-DES-CBC-MD5 | [RFC2712] | +| 0x002A | TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5 | EXP-KRB5-RC2-CBC-MD5 | [RFC2712] | +| 0x002B | TLS_KRB5_EXPORT_WITH_RC4_40_MD5 | EXP-KRB5-RC4-MD5 | [RFC2712][RFC6347] | +| 0x002C | TLS_PSK_WITH_NULL_SHA | PSK-NULL-SHA | [RFC4785] | +| 0x002D | TLS_DHE_PSK_WITH_NULL_SHA | DHE-PSK-NULL-SHA | [RFC4785] | +| 0x002E | TLS_RSA_PSK_WITH_NULL_SHA | RSA-PSK-NULL-SHA | [RFC4785] | +| 0x002F | TLS_RSA_WITH_AES_128_CBC_SHA | AES128-SHA | [RFC5246] | +| 0x0030 | TLS_DH_DSS_WITH_AES_128_CBC_SHA | DH-DSS-AES128-SHA | [RFC5246] | +| 0x0031 | TLS_DH_RSA_WITH_AES_128_CBC_SHA | DH-RSA-AES128-SHA | [RFC5246] | +| 0x0032 | TLS_DHE_DSS_WITH_AES_128_CBC_SHA | DHE-DSS-AES128-SHA | [RFC5246] | +| 0x0033 | TLS_DHE_RSA_WITH_AES_128_CBC_SHA | DHE-RSA-AES128-SHA | [RFC5246] | +| 0x0034 | TLS_DH_anon_WITH_AES_128_CBC_SHA | ADH-AES128-SHA | [RFC5246] | +| 0x0035 | TLS_RSA_WITH_AES_256_CBC_SHA | AES256-SHA | [RFC5246] | +| 0x0036 | TLS_DH_DSS_WITH_AES_256_CBC_SHA | DH-DSS-AES256-SHA | [RFC5246] | +| 0x0037 | TLS_DH_RSA_WITH_AES_256_CBC_SHA | DH-RSA-AES256-SHA | [RFC5246] | +| 0x0038 | TLS_DHE_DSS_WITH_AES_256_CBC_SHA | DHE-DSS-AES256-SHA | [RFC5246] | +| 0x0039 | TLS_DHE_RSA_WITH_AES_256_CBC_SHA | DHE-RSA-AES256-SHA | [RFC5246] | +| 0x003A | TLS_DH_anon_WITH_AES_256_CBC_SHA | ADH-AES256-SHA | [RFC5246] | +| 0x003B | TLS_RSA_WITH_NULL_SHA256 | NULL-SHA256 | [RFC5246] | +| 0x003C | TLS_RSA_WITH_AES_128_CBC_SHA256 | AES128-SHA256 | [RFC5246] | +| 0x003D | TLS_RSA_WITH_AES_256_CBC_SHA256 | AES256-SHA256 | [RFC5246] | +| 0x003E | TLS_DH_DSS_WITH_AES_128_CBC_SHA256 | DH-DSS-AES128-SHA256 | [RFC5246] | +| 0x003F | TLS_DH_RSA_WITH_AES_128_CBC_SHA256 | DH-RSA-AES128-SHA256 | [RFC5246] | +| 0x0040 | TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 | DHE-DSS-AES128-SHA256 | [RFC5246] | +| 0x0041 | TLS_RSA_WITH_CAMELLIA_128_CBC_SHA | CAMELLIA128-SHA | [RFC5932] | +| 0x0042 | TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA | DH-DSS-CAMELLIA128-SHA | [RFC5932] | +| 0x0043 | TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA | DH-RSA-CAMELLIA128-SHA | [RFC5932] | +| 0x0044 | TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA | DHE-DSS-CAMELLIA128-SHA | [RFC5932] | +| 0x0045 | TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA | DHE-RSA-CAMELLIA128-SHA | [RFC5932] | +| 0x0046 | TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA | ADH-CAMELLIA128-SHA | [RFC5932] | +| 0x0060 | | EXP1024-RC4-MD5 | | +| 0x0061 | | EXP1024-RC2-CBC-MD5 | | +| 0x0062 | | EXP1024-DES-CBC-SHA | | +| 0x0063 | | EXP1024-DHE-DSS-DES-CBC-SHA | | +| 0x0064 | | EXP1024-RC4-SHA | | +| 0x0065 | | EXP1024-DHE-DSS-RC4-SHA | | +| 0x0066 | | DHE-DSS-RC4-SHA | | +| 0x0067 | TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 | DHE-RSA-AES128-SHA256 | [RFC5246] | +| 0x0068 | TLS_DH_DSS_WITH_AES_256_CBC_SHA256 | DH-DSS-AES256-SHA256 | [RFC5246] | +| 0x0069 | TLS_DH_RSA_WITH_AES_256_CBC_SHA256 | DH-RSA-AES256-SHA256 | [RFC5246] | +| 0x006A | TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 | DHE-DSS-AES256-SHA256 | [RFC5246] | +| 0x006B | TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 | DHE-RSA-AES256-SHA256 | [RFC5246] | +| 0x006C | TLS_DH_anon_WITH_AES_128_CBC_SHA256 | ADH-AES128-SHA256 | [RFC5246] | +| 0x006D | TLS_DH_anon_WITH_AES_256_CBC_SHA256 | ADH-AES256-SHA256 | [RFC5246] | +| 0x0080 | | GOST94-GOST89-GOST89 | | +| 0x0081 | | GOST2001-GOST89-GOST89 | | +| 0x0082 | | GOST94-NULL-GOST94 | | +| 0x0083 | | GOST2001-NULL-GOST94 | | +| 0x0084 | TLS_RSA_WITH_CAMELLIA_256_CBC_SHA | CAMELLIA256-SHA | [RFC5932] | +| 0x0085 | TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA | DH-DSS-CAMELLIA256-SHA | [RFC5932] | +| 0x0086 | TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA | DH-RSA-CAMELLIA256-SHA | [RFC5932] | +| 0x0087 | TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA | DHE-DSS-CAMELLIA256-SHA | [RFC5932] | +| 0x0088 | TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA | DHE-RSA-CAMELLIA256-SHA | [RFC5932] | +| 0x0089 | TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA | ADH-CAMELLIA256-SHA | [RFC5932] | +| 0x008A | TLS_PSK_WITH_RC4_128_SHA | PSK-RC4-SHA | [RFC4279][RFC6347] | +| 0x008B | TLS_PSK_WITH_3DES_EDE_CBC_SHA | PSK-3DES-EDE-CBC-SHA | [RFC4279] | +| 0x008C | TLS_PSK_WITH_AES_128_CBC_SHA | PSK-AES128-CBC-SHA | [RFC4279] | +| 0x008D | TLS_PSK_WITH_AES_256_CBC_SHA | PSK-AES256-CBC-SHA | [RFC4279] | +| 0x008E | TLS_DHE_PSK_WITH_RC4_128_SHA | DHE-PSK-RC4-SHA | [RFC4279][RFC6347] | +| 0x008F | TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA | DHE-PSK-3DES-EDE-CBC-SHA | [RFC4279] | +| 0x0090 | TLS_DHE_PSK_WITH_AES_128_CBC_SHA | DHE-PSK-AES128-CBC-SHA | [RFC4279] | +| 0x0091 | TLS_DHE_PSK_WITH_AES_256_CBC_SHA | DHE-PSK-AES256-CBC-SHA | [RFC4279] | +| 0x0092 | TLS_RSA_PSK_WITH_RC4_128_SHA | RSA-PSK-RC4-SHA | [RFC4279][RFC6347] | +| 0x0093 | TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA | RSA-PSK-3DES-EDE-CBC-SHA | [RFC4279] | +| 0x0094 | TLS_RSA_PSK_WITH_AES_128_CBC_SHA | RSA-PSK-AES128-CBC-SHA | [RFC4279] | +| 0x0095 | TLS_RSA_PSK_WITH_AES_256_CBC_SHA | RSA-PSK-AES256-CBC-SHA | [RFC4279] | +| 0x0096 | TLS_RSA_WITH_SEED_CBC_SHA | SEED-SHA | [RFC4162] | +| 0x0097 | TLS_DH_DSS_WITH_SEED_CBC_SHA | DH-DSS-SEED-SHA | [RFC4162] | +| 0x0098 | TLS_DH_RSA_WITH_SEED_CBC_SHA | DH-RSA-SEED-SHA | [RFC4162] | +| 0x0099 | TLS_DHE_DSS_WITH_SEED_CBC_SHA | DHE-DSS-SEED-SHA | [RFC4162] | +| 0x009A | TLS_DHE_RSA_WITH_SEED_CBC_SHA | DHE-RSA-SEED-SHA | [RFC4162] | +| 0x009B | TLS_DH_anon_WITH_SEED_CBC_SHA | ADH-SEED-SHA | [RFC4162] | +| 0x009C | TLS_RSA_WITH_AES_128_GCM_SHA256 | AES128-GCM-SHA256 | [RFC5288] | +| 0x009D | TLS_RSA_WITH_AES_256_GCM_SHA384 | AES256-GCM-SHA384 | [RFC5288] | +| 0x009E | TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 | DHE-RSA-AES128-GCM-SHA256 | [RFC5288] | +| 0x009F | TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 | DHE-RSA-AES256-GCM-SHA384 | [RFC5288] | +| 0x00A0 | TLS_DH_RSA_WITH_AES_128_GCM_SHA256 | DH-RSA-AES128-GCM-SHA256 | [RFC5288] | +| 0x00A1 | TLS_DH_RSA_WITH_AES_256_GCM_SHA384 | DH-RSA-AES256-GCM-SHA384 | [RFC5288] | +| 0x00A2 | TLS_DHE_DSS_WITH_AES_128_GCM_SHA256 | DHE-DSS-AES128-GCM-SHA256 | [RFC5288] | +| 0x00A3 | TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 | DHE-DSS-AES256-GCM-SHA384 | [RFC5288] | +| 0x00A4 | TLS_DH_DSS_WITH_AES_128_GCM_SHA256 | DH-DSS-AES128-GCM-SHA256 | [RFC5288] | +| 0x00A5 | TLS_DH_DSS_WITH_AES_256_GCM_SHA384 | DH-DSS-AES256-GCM-SHA384 | [RFC5288] | +| 0x00A6 | TLS_DH_anon_WITH_AES_128_GCM_SHA256 | ADH-AES128-GCM-SHA256 | [RFC5288] | +| 0x00A7 | TLS_DH_anon_WITH_AES_256_GCM_SHA384 | ADH-AES256-GCM-SHA384 | [RFC5288] | +| 0x00A8 | TLS_PSK_WITH_AES_128_GCM_SHA256 | PSK-AES128-GCM-SHA256 | [RFC5487] | +| 0x00A9 | TLS_PSK_WITH_AES_256_GCM_SHA384 | PSK-AES256-GCM-SHA384 | [RFC5487] | +| 0x00AA | TLS_DHE_PSK_WITH_AES_128_GCM_SHA256 | DHE-PSK-AES128-GCM-SHA256 | [RFC5487] | +| 0x00AB | TLS_DHE_PSK_WITH_AES_256_GCM_SHA384 | DHE-PSK-AES256-GCM-SHA384 | [RFC5487] | +| 0x00AC | TLS_RSA_PSK_WITH_AES_128_GCM_SHA256 | RSA-PSK-AES128-GCM-SHA256 | [RFC5487] | +| 0x00AD | TLS_RSA_PSK_WITH_AES_256_GCM_SHA384 | RSA-PSK-AES256-GCM-SHA384 | [RFC5487] | +| 0x00AE | TLS_PSK_WITH_AES_128_CBC_SHA256 | PSK-AES128-CBC-SHA256 | [RFC5487] | +| 0x00AF | TLS_PSK_WITH_AES_256_CBC_SHA384 | PSK-AES256-CBC-SHA384 | [RFC5487] | +| 0x00B0 | TLS_PSK_WITH_NULL_SHA256 | PSK-NULL-SHA256 | [RFC5487] | +| 0x00B1 | TLS_PSK_WITH_NULL_SHA384 | PSK-NULL-SHA384 | [RFC5487] | +| 0x00B2 | TLS_DHE_PSK_WITH_AES_128_CBC_SHA256 | DHE-PSK-AES128-CBC-SHA256 | [RFC5487] | +| 0x00B3 | TLS_DHE_PSK_WITH_AES_256_CBC_SHA384 | DHE-PSK-AES256-CBC-SHA384 | [RFC5487] | +| 0x00B4 | TLS_DHE_PSK_WITH_NULL_SHA256 | DHE-PSK-NULL-SHA256 | [RFC5487] | +| 0x00B5 | TLS_DHE_PSK_WITH_NULL_SHA384 | DHE-PSK-NULL-SHA384 | [RFC5487] | +| 0x00B6 | TLS_RSA_PSK_WITH_AES_128_CBC_SHA256 | RSA-PSK-AES128-CBC-SHA256 | [RFC5487] | +| 0x00B7 | TLS_RSA_PSK_WITH_AES_256_CBC_SHA384 | RSA-PSK-AES256-CBC-SHA384 | [RFC5487] | +| 0x00B8 | TLS_RSA_PSK_WITH_NULL_SHA256 | RSA-PSK-NULL-SHA256 | [RFC5487] | +| 0x00B9 | TLS_RSA_PSK_WITH_NULL_SHA384 | RSA-PSK-NULL-SHA384 | [RFC5487] | +| 0x00BA | TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256 | CAMELLIA128-SHA256 | [RFC5932] | +| 0x00BD | TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA256 | DHE-DSS-CAMELLIA128-SHA256 | [RFC5932] | +| 0x00BE | TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 | DHE-RSA-CAMELLIA128-SHA256 | [RFC5932] | +| 0x00BF | TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256 | ADH-CAMELLIA128-SHA256 | [RFC5932] | +| 0x00C0 | TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256 | CAMELLIA256-SHA256 | [RFC5932] | +| 0x00C3 | TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA256 | DHE-DSS-CAMELLIA256-SHA256 | [RFC5932] | +| 0x00C4 | TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 | DHE-RSA-CAMELLIA256-SHA256 | [RFC5932] | +| 0x00C5 | TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256 | ADH-CAMELLIA256-SHA256 | [RFC5932] | +| 0x00FF | TLS_EMPTY_RENEGOTIATION_INFO_SCSV | | [RFC5746] | +| 0x5600 | TLS_FALLBACK_SCSV | | [RFC7507] | +| 0xC001 | TLS_ECDH_ECDSA_WITH_NULL_SHA | ECDH-ECDSA-NULL-SHA | [RFC8422] | +| 0xC002 | TLS_ECDH_ECDSA_WITH_RC4_128_SHA | ECDH-ECDSA-RC4-SHA | [RFC8422][RFC6347] | +| 0xC003 | TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA | ECDH-ECDSA-DES-CBC3-SHA | [RFC8422] | +| 0xC004 | TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA | ECDH-ECDSA-AES128-SHA | [RFC8422] | +| 0xC005 | TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA | ECDH-ECDSA-AES256-SHA | [RFC8422] | +| 0xC006 | TLS_ECDHE_ECDSA_WITH_NULL_SHA | ECDHE-ECDSA-NULL-SHA | [RFC8422] | +| 0xC007 | TLS_ECDHE_ECDSA_WITH_RC4_128_SHA | ECDHE-ECDSA-RC4-SHA | [RFC8422][RFC6347] | +| 0xC008 | TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA | ECDHE-ECDSA-DES-CBC3-SHA | [RFC8422] | +| 0xC009 | TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA | ECDHE-ECDSA-AES128-SHA | [RFC8422] | +| 0xC00A | TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA | ECDHE-ECDSA-AES256-SHA | [RFC8422] | +| 0xC00B | TLS_ECDH_RSA_WITH_NULL_SHA | ECDH-RSA-NULL-SHA | [RFC8422] | +| 0xC00C | TLS_ECDH_RSA_WITH_RC4_128_SHA | ECDH-RSA-RC4-SHA | [RFC8422][RFC6347] | +| 0xC00D | TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA | ECDH-RSA-DES-CBC3-SHA | [RFC8422] | +| 0xC00E | TLS_ECDH_RSA_WITH_AES_128_CBC_SHA | ECDH-RSA-AES128-SHA | [RFC8422] | +| 0xC00F | TLS_ECDH_RSA_WITH_AES_256_CBC_SHA | ECDH-RSA-AES256-SHA | [RFC8422] | +| 0xC010 | TLS_ECDHE_RSA_WITH_NULL_SHA | ECDHE-RSA-NULL-SHA | [RFC8422] | +| 0xC011 | TLS_ECDHE_RSA_WITH_RC4_128_SHA | ECDHE-RSA-RC4-SHA | [RFC8422][RFC6347] | +| 0xC012 | TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA | ECDHE-RSA-DES-CBC3-SHA | [RFC8422] | +| 0xC013 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA | ECDHE-RSA-AES128-SHA | [RFC8422] | +| 0xC014 | TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA | ECDHE-RSA-AES256-SHA | [RFC8422] | +| 0xC015 | TLS_ECDH_anon_WITH_NULL_SHA | AECDH-NULL-SHA | [RFC8422] | +| 0xC016 | TLS_ECDH_anon_WITH_RC4_128_SHA | AECDH-RC4-SHA | [RFC8422][RFC6347] | +| 0xC017 | TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA | AECDH-DES-CBC3-SHA | [RFC8422] | +| 0xC018 | TLS_ECDH_anon_WITH_AES_128_CBC_SHA | AECDH-AES128-SHA | [RFC8422] | +| 0xC019 | TLS_ECDH_anon_WITH_AES_256_CBC_SHA | AECDH-AES256-SHA | [RFC8422] | +| 0xC01A | TLS_SRP_SHA_WITH_3DES_EDE_CBC_SHA | SRP-3DES-EDE-CBC-SHA | [RFC5054] | +| 0xC01B | TLS_SRP_SHA_RSA_WITH_3DES_EDE_CBC_SHA | SRP-RSA-3DES-EDE-CBC-SHA | [RFC5054] | +| 0xC01C | TLS_SRP_SHA_DSS_WITH_3DES_EDE_CBC_SHA | SRP-DSS-3DES-EDE-CBC-SHA | [RFC5054] | +| 0xC01D | TLS_SRP_SHA_WITH_AES_128_CBC_SHA | SRP-AES-128-CBC-SHA | [RFC5054] | +| 0xC01E | TLS_SRP_SHA_RSA_WITH_AES_128_CBC_SHA | SRP-RSA-AES-128-CBC-SHA | [RFC5054] | +| 0xC01F | TLS_SRP_SHA_DSS_WITH_AES_128_CBC_SHA | SRP-DSS-AES-128-CBC-SHA | [RFC5054] | +| 0xC020 | TLS_SRP_SHA_WITH_AES_256_CBC_SHA | SRP-AES-256-CBC-SHA | [RFC5054] | +| 0xC021 | TLS_SRP_SHA_RSA_WITH_AES_256_CBC_SHA | SRP-RSA-AES-256-CBC-SHA | [RFC5054] | +| 0xC022 | TLS_SRP_SHA_DSS_WITH_AES_256_CBC_SHA | SRP-DSS-AES-256-CBC-SHA | [RFC5054] | +| 0xC023 | TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 | ECDHE-ECDSA-AES128-SHA256 | [RFC5289] | +| 0xC024 | TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 | ECDHE-ECDSA-AES256-SHA384 | [RFC5289] | +| 0xC025 | TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 | ECDH-ECDSA-AES128-SHA256 | [RFC5289] | +| 0xC026 | TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 | ECDH-ECDSA-AES256-SHA384 | [RFC5289] | +| 0xC027 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 | ECDHE-RSA-AES128-SHA256 | [RFC5289] | +| 0xC028 | TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 | ECDHE-RSA-AES256-SHA384 | [RFC5289] | +| 0xC029 | TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256 | ECDH-RSA-AES128-SHA256 | [RFC5289] | +| 0xC02A | TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384 | ECDH-RSA-AES256-SHA384 | [RFC5289] | +| 0xC02B | TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 | ECDHE-ECDSA-AES128-GCM-SHA256 | [RFC5289] | +| 0xC02C | TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 | ECDHE-ECDSA-AES256-GCM-SHA384 | [RFC5289] | +| 0xC02D | TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256 | ECDH-ECDSA-AES128-GCM-SHA256 | [RFC5289] | +| 0xC02E | TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384 | ECDH-ECDSA-AES256-GCM-SHA384 | [RFC5289] | +| 0xC02F | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 | ECDHE-RSA-AES128-GCM-SHA256 | [RFC5289] | +| 0xC030 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 | ECDHE-RSA-AES256-GCM-SHA384 | [RFC5289] | +| 0xC031 | TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256 | ECDH-RSA-AES128-GCM-SHA256 | [RFC5289] | +| 0xC032 | TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384 | ECDH-RSA-AES256-GCM-SHA384 | [RFC5289] | +| 0xC033 | TLS_ECDHE_PSK_WITH_RC4_128_SHA | ECDHE-PSK-RC4-SHA | [RFC5489][RFC6347] | +| 0xC034 | TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA | ECDHE-PSK-3DES-EDE-CBC-SHA | [RFC5489] | +| 0xC035 | TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA | ECDHE-PSK-AES128-CBC-SHA | [RFC5489] | +| 0xC036 | TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA | ECDHE-PSK-AES256-CBC-SHA | [RFC5489] | +| 0xC037 | TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256 | ECDHE-PSK-AES128-CBC-SHA256 | [RFC5489] | +| 0xC038 | TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384 | ECDHE-PSK-AES256-CBC-SHA384 | [RFC5489] | +| 0xC039 | TLS_ECDHE_PSK_WITH_NULL_SHA | ECDHE-PSK-NULL-SHA | [RFC5489] | +| 0xC03A | TLS_ECDHE_PSK_WITH_NULL_SHA256 | ECDHE-PSK-NULL-SHA256 | [RFC5489] | +| 0xC03B | TLS_ECDHE_PSK_WITH_NULL_SHA384 | ECDHE-PSK-NULL-SHA384 | [RFC5489] | +| 0xC03C | TLS_RSA_WITH_ARIA_128_CBC_SHA256 | ARIA128-SHA256 | [RFC6209] | +| 0xC03D | TLS_RSA_WITH_ARIA_256_CBC_SHA384 | ARIA256-SHA384 | [RFC6209] | +| 0xC044 | TLS_DHE_RSA_WITH_ARIA_128_CBC_SHA256 | DHE-RSA-ARIA128-SHA256 | [RFC6209] | +| 0xC045 | TLS_DHE_RSA_WITH_ARIA_256_CBC_SHA384 | DHE-RSA-ARIA256-SHA384 | [RFC6209] | +| 0xC048 | TLS_ECDHE_ECDSA_WITH_ARIA_128_CBC_SHA256 | ECDHE-ECDSA-ARIA128-SHA256 | [RFC6209] | +| 0xC049 | TLS_ECDHE_ECDSA_WITH_ARIA_256_CBC_SHA384 | ECDHE-ECDSA-ARIA256-SHA384 | [RFC6209] | +| 0xC04A | TLS_ECDH_ECDSA_WITH_ARIA_128_CBC_SHA256 | ECDH-ECDSA-ARIA128-SHA256 | [RFC6209] | +| 0xC04B | TLS_ECDH_ECDSA_WITH_ARIA_256_CBC_SHA384 | ECDH-ECDSA-ARIA256-SHA384 | [RFC6209] | +| 0xC04C | TLS_ECDHE_RSA_WITH_ARIA_128_CBC_SHA256 | ECDHE-ARIA128-SHA256 | [RFC6209] | +| 0xC04D | TLS_ECDHE_RSA_WITH_ARIA_256_CBC_SHA384 | ECDHE-ARIA256-SHA384 | [RFC6209] | +| 0xC04E | TLS_ECDH_RSA_WITH_ARIA_128_CBC_SHA256 | ECDH-ARIA128-SHA256 | [RFC6209] | +| 0xC04F | TLS_ECDH_RSA_WITH_ARIA_256_CBC_SHA384 | ECDH-ARIA256-SHA384 | [RFC6209] | +| 0xC050 | TLS_RSA_WITH_ARIA_128_GCM_SHA256 | ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC051 | TLS_RSA_WITH_ARIA_256_GCM_SHA384 | ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC052 | TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256 | DHE-RSA-ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC053 | TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384 | DHE-RSA-ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC056 | TLS_DHE_DSS_WITH_ARIA_128_GCM_SHA256 | DHE-DSS-ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC057 | TLS_DHE_DSS_WITH_ARIA_256_GCM_SHA384 | DHE-DSS-ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC05C | TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256 | ECDHE-ECDSA-ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC05D | TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384 | ECDHE-ECDSA-ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC05E | TLS_ECDH_ECDSA_WITH_ARIA_128_GCM_SHA256 | ECDH-ECDSA-ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC05F | TLS_ECDH_ECDSA_WITH_ARIA_256_GCM_SHA384 | ECDH-ECDSA-ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC060 | TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 | ECDHE-ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC061 | TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 | ECDHE-ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC062 | TLS_ECDH_RSA_WITH_ARIA_128_GCM_SHA256 | ECDH-ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC063 | TLS_ECDH_RSA_WITH_ARIA_256_GCM_SHA384 | ECDH-ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC064 | TLS_PSK_WITH_ARIA_128_CBC_SHA256 | PSK-ARIA128-SHA256 | [RFC6209] | +| 0xC065 | TLS_PSK_WITH_ARIA_256_CBC_SHA384 | PSK-ARIA256-SHA384 | [RFC6209] | +| 0xC066 | TLS_DHE_PSK_WITH_ARIA_128_CBC_SHA256 | DHE-PSK-ARIA128-SHA256 | [RFC6209] | +| 0xC067 | TLS_DHE_PSK_WITH_ARIA_256_CBC_SHA384 | DHE-PSK-ARIA256-SHA384 | [RFC6209] | +| 0xC068 | TLS_RSA_PSK_WITH_ARIA_128_CBC_SHA256 | RSA-PSK-ARIA128-SHA256 | [RFC6209] | +| 0xC069 | TLS_RSA_PSK_WITH_ARIA_256_CBC_SHA384 | RSA-PSK-ARIA256-SHA384 | [RFC6209] | +| 0xC06A | TLS_PSK_WITH_ARIA_128_GCM_SHA256 | PSK-ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC06B | TLS_PSK_WITH_ARIA_256_GCM_SHA384 | PSK-ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC06C | TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256 | DHE-PSK-ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC06D | TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384 | DHE-PSK-ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC06E | TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256 | RSA-PSK-ARIA128-GCM-SHA256 | [RFC6209] | +| 0xC06F | TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384 | RSA-PSK-ARIA256-GCM-SHA384 | [RFC6209] | +| 0xC070 | TLS_ECDHE_PSK_WITH_ARIA_128_CBC_SHA256 | ECDHE-PSK-ARIA128-SHA256 | [RFC6209] | +| 0xC071 | TLS_ECDHE_PSK_WITH_ARIA_256_CBC_SHA384 | ECDHE-PSK-ARIA256-SHA384 | [RFC6209] | +| 0xC072 | TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 | ECDHE-ECDSA-CAMELLIA128-SHA256 | [RFC6367] | +| 0xC073 | TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 | ECDHE-ECDSA-CAMELLIA256-SHA384 | [RFC6367] | +| 0xC074 | TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 | ECDH-ECDSA-CAMELLIA128-SHA256 | [RFC6367] | +| 0xC075 | TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 | ECDH-ECDSA-CAMELLIA256-SHA384 | [RFC6367] | +| 0xC076 | TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 | ECDHE-RSA-CAMELLIA128-SHA256 | [RFC6367] | +| 0xC077 | TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 | ECDHE-RSA-CAMELLIA256-SHA384 | [RFC6367] | +| 0xC078 | TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 | ECDH-CAMELLIA128-SHA256 | [RFC6367] | +| 0xC079 | TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 | ECDH-CAMELLIA256-SHA384 | [RFC6367] | +| 0xC07A | TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256 | CAMELLIA128-GCM-SHA256 | [RFC6367] | +| 0xC07B | TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384 | CAMELLIA256-GCM-SHA384 | [RFC6367] | +| 0xC07C | TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256 | DHE-RSA-CAMELLIA128-GCM-SHA256 | [RFC6367] | +| 0xC07D | TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384 | DHE-RSA-CAMELLIA256-GCM-SHA384 | [RFC6367] | +| 0xC086 | TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256 | ECDHE-ECDSA-CAMELLIA128-GCM-SHA256 | [RFC6367] | +| 0xC087 | TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384 | ECDHE-ECDSA-CAMELLIA256-GCM-SHA384 | [RFC6367] | +| 0xC088 | TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256 | ECDH-ECDSA-CAMELLIA128-GCM-SHA256 | [RFC6367] | +| 0xC089 | TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384 | ECDH-ECDSA-CAMELLIA256-GCM-SHA384 | [RFC6367] | +| 0xC08A | TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256 | ECDHE-CAMELLIA128-GCM-SHA256 | [RFC6367] | +| 0xC08B | TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384 | ECDHE-CAMELLIA256-GCM-SHA384 | [RFC6367] | +| 0xC08C | TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256 | ECDH-CAMELLIA128-GCM-SHA256 | [RFC6367] | +| 0xC08D | TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384 | ECDH-CAMELLIA256-GCM-SHA384 | [RFC6367] | +| 0xC08E | TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256 | PSK-CAMELLIA128-GCM-SHA256 | [RFC6367] | +| 0xC08F | TLS_PSK_WITH_CAMELLIA_256_GCM_SHA384 | PSK-CAMELLIA256-GCM-SHA384 | [RFC6367] | +| 0xC090 | TLS_DHE_PSK_WITH_CAMELLIA_128_GCM_SHA256 | DHE-PSK-CAMELLIA128-GCM-SHA256 | [RFC6367] | +| 0xC091 | TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384 | DHE-PSK-CAMELLIA256-GCM-SHA384 | [RFC6367] | +| 0xC092 | TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256 | RSA-PSK-CAMELLIA128-GCM-SHA256 | [RFC6367] | +| 0xC093 | TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384 | RSA-PSK-CAMELLIA256-GCM-SHA384 | [RFC6367] | +| 0xC094 | TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256 | PSK-CAMELLIA128-SHA256 | [RFC6367] | +| 0xC095 | TLS_PSK_WITH_CAMELLIA_256_CBC_SHA384 | PSK-CAMELLIA256-SHA384 | [RFC6367] | +| 0xC096 | TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 | DHE-PSK-CAMELLIA128-SHA256 | [RFC6367] | +| 0xC097 | TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 | DHE-PSK-CAMELLIA256-SHA384 | [RFC6367] | +| 0xC098 | TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256 | RSA-PSK-CAMELLIA128-SHA256 | [RFC6367] | +| 0xC099 | TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384 | RSA-PSK-CAMELLIA256-SHA384 | [RFC6367] | +| 0xC09A | TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 | ECDHE-PSK-CAMELLIA128-SHA256 | [RFC6367] | +| 0xC09B | TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 | ECDHE-PSK-CAMELLIA256-SHA384 | [RFC6367] | +| 0xC09C | TLS_RSA_WITH_AES_128_CCM | AES128-CCM | [RFC6655] | +| 0xC09D | TLS_RSA_WITH_AES_256_CCM | AES256-CCM | [RFC6655] | +| 0xC09E | TLS_DHE_RSA_WITH_AES_128_CCM | DHE-RSA-AES128-CCM | [RFC6655] | +| 0xC09F | TLS_DHE_RSA_WITH_AES_256_CCM | DHE-RSA-AES256-CCM | [RFC6655] | +| 0xC0A0 | TLS_RSA_WITH_AES_128_CCM_8 | AES128-CCM8 | [RFC6655] | +| 0xC0A1 | TLS_RSA_WITH_AES_256_CCM_8 | AES256-CCM8 | [RFC6655] | +| 0xC0A2 | TLS_DHE_RSA_WITH_AES_128_CCM_8 | DHE-RSA-AES128-CCM8 | [RFC6655] | +| 0xC0A3 | TLS_DHE_RSA_WITH_AES_256_CCM_8 | DHE-RSA-AES256-CCM8 | [RFC6655] | +| 0xC0A4 | TLS_PSK_WITH_AES_128_CCM | PSK-AES128-CCM | [RFC6655] | +| 0xC0A5 | TLS_PSK_WITH_AES_256_CCM | PSK-AES256-CCM | [RFC6655] | +| 0xC0A6 | TLS_DHE_PSK_WITH_AES_128_CCM | DHE-PSK-AES128-CCM | [RFC6655] | +| 0xC0A7 | TLS_DHE_PSK_WITH_AES_256_CCM | DHE-PSK-AES256-CCM | [RFC6655] | +| 0xC0A8 | TLS_PSK_WITH_AES_128_CCM_8 | PSK-AES128-CCM8 | [RFC6655] | +| 0xC0A9 | TLS_PSK_WITH_AES_256_CCM_8 | PSK-AES256-CCM8 | [RFC6655] | +| 0xC0AA | TLS_PSK_DHE_WITH_AES_128_CCM_8 | DHE-PSK-AES128-CCM8 | [RFC6655] | +| 0xC0AB | TLS_PSK_DHE_WITH_AES_256_CCM_8 | DHE-PSK-AES256-CCM8 | [RFC6655] | +| 0xC0AC | TLS_ECDHE_ECDSA_WITH_AES_128_CCM | ECDHE-ECDSA-AES128-CCM | [RFC7251] | +| 0xC0AD | TLS_ECDHE_ECDSA_WITH_AES_256_CCM | ECDHE-ECDSA-AES256-CCM | [RFC7251] | +| 0xC0AE | TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 | ECDHE-ECDSA-AES128-CCM8 | [RFC7251] | +| 0xC0AF | TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8 | ECDHE-ECDSA-AES256-CCM8 | [RFC7251] | +| 0xC100 | TLS_GOSTR341112_256_WITH_KUZNYECHIK_CTR_OMAC | GOST2012-KUZNYECHIK-KUZNYECHIKOMAC | [RFC9189] | +| 0xC101 | TLS_GOSTR341112_256_WITH_MAGMA_CTR_OMAC | GOST2012-MAGMA-MAGMAOMAC | [RFC9189] | +| 0xC102 | TLS_GOSTR341112_256_WITH_28147_CNT_IMIT | IANA-GOST2012-GOST8912-GOST8912 | [RFC9189] | +| 0xCC13 | | ECDHE-RSA-CHACHA20-POLY1305-OLD | | +| 0xCC14 | | ECDHE-ECDSA-CHACHA20-POLY1305-OLD | | +| 0xCC15 | | DHE-RSA-CHACHA20-POLY1305-OLD | | +| 0xCCA8 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 | ECDHE-RSA-CHACHA20-POLY1305 | [RFC7905] | +| 0xCCA9 | TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 | ECDHE-ECDSA-CHACHA20-POLY1305 | [RFC7905] | +| 0xCCAA | TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 | DHE-RSA-CHACHA20-POLY1305 | [RFC7905] | +| 0xCCAB | TLS_PSK_WITH_CHACHA20_POLY1305_SHA256 | PSK-CHACHA20-POLY1305 | [RFC7905] | +| 0xCCAC | TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 | ECDHE-PSK-CHACHA20-POLY1305 | [RFC7905] | +| 0xCCAD | TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256 | DHE-PSK-CHACHA20-POLY1305 | [RFC7905] | +| 0xCCAE | TLS_RSA_PSK_WITH_CHACHA20_POLY1305_SHA256 | RSA-PSK-CHACHA20-POLY1305 | [RFC7905] | +| 0xD001 | TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256 | ECDHE-PSK-AES128-GCM-SHA256 | [RFC8442] | +| 0xE011 | | ECDHE-ECDSA-SM4-CBC-SM3 | | +| 0xE051 | | ECDHE-ECDSA-SM4-GCM-SM3 | | +| 0xE052 | | ECDHE-ECDSA-SM4-CCM-SM3 | | +| 0xFF00 | | GOST-MD5 | | +| 0xFF01 | | GOST-GOST94 | | +| 0xFF02 | | GOST-GOST89MAC | | +| 0xFF03 | | GOST-GOST89STREAM | | diff --git a/third-party/curl/docs/CIPHERS.md b/third-party/curl/docs/CIPHERS.md index 27de940363..0b70bda7d9 100644 --- a/third-party/curl/docs/CIPHERS.md +++ b/third-party/curl/docs/CIPHERS.md @@ -1,427 +1,279 @@ -# Ciphers + -TLS 1.3 ciphers are supported since curl 7.61 for OpenSSL 1.1.1+, and since -curl 7.85 for Schannel with options -[`CURLOPT_TLS13_CIPHERS`](https://curl.se/libcurl/c/CURLOPT_TLS13_CIPHERS.html) -and +## curl cipher options + +A TLS handshake involves many parameters which take part in the negotiation +between client and server in order to agree on the TLS version and set of +algorithms to use for a connection. + +What has become known as a "cipher" or better "cipher suite" in TLS +are names for specific combinations of +[key exchange](https://en.wikipedia.org/wiki/Key_exchange), +[bulk encryption](https://en.wikipedia.org/wiki/Link_encryption), +[message authentication code](https://en.wikipedia.org/wiki/Message_authentication_code) +and with TLSv1.3 the +[authenticated encryption](https://en.wikipedia.org/wiki/Authenticated_encryption). +In addition, there are other parameters that influence the TLS handshake, like +[DHE](https://en.wikipedia.org/wiki/Diffie%e2%80%93Hellman_key_exchange) "groups" +and [ECDHE](https://en.wikipedia.org/wiki/Elliptic-curve_Diffie%e2%80%93Hellman) +with its "curves". + +### History + +curl's way of letting users configure these settings closely followed OpenSSL +in its API. TLS learned new parameters, OpenSSL added new API functions and +curl added command line options. + +Several other TLS backends followed the OpenSSL approach, more or less closely, +and curl maps the command line options to these TLS backends. Some TLS +backends do not support all of it and command line options are either +ignored or lead to an error. + +Many examples below show the OpenSSL-like use of these options. GnuTLS +however chose a different approach. These are described in a separate +section further below. + +## ciphers, the OpenSSL way + +With curl's option [`--tls13-ciphers`](https://curl.se/docs/manpage.html#--tls13-ciphers) -. If you are using a different SSL backend you can try setting TLS 1.3 cipher -suites by using the respective regular cipher option. +or +[`CURLOPT_TLS13_CIPHERS`](https://curl.se/libcurl/c/CURLOPT_TLS13_CIPHERS.html) +users can control which cipher suites to consider when negotiating TLS 1.3 +connections. With option +[`--ciphers`](https://curl.se/docs/manpage.html#--ciphers) +or +[`CURLOPT_SSL_CIPHER_LIST`](https://curl.se/libcurl/c/CURLOPT_SSL_CIPHER_LIST.html) +users can control which cipher suites to consider when negotiating +TLS 1.2 (1.1, 1.0) connections. -The names of the known ciphers differ depending on which TLS backend that -libcurl was built to use. This is an attempt to list known cipher names. +By default, curl may negotiate TLS 1.3 and TLS 1.2 connections, so the cipher +suites considered when negotiating a TLS connection are a union of the TLS 1.3 +and TLS 1.2 cipher suites. If you want curl to consider only TLS 1.3 cipher +suites for the connection, you have to set the minimum TLS version to 1.3 by +using [`--tlsv1.3`](https://curl.se/docs/manpage.html#--tlsv13) +or [`CURLOPT_SSLVERSION`](https://curl.se/libcurl/c/CURLOPT_SSLVERSION.html) +with `CURL_SSLVERSION_TLSv1_3`. -## OpenSSL +Both the TLS 1.3 and TLS 1.2 cipher options expect a list of cipher suites +separated by colons (`:`). This list is parsed opportunistically, cipher suites +that are not recognized or implemented are ignored. As long as there is at +least one recognized cipher suite in the list, the list is considered valid. -(based on [OpenSSL docs](https://www.openssl.org/docs/manmaster/man1/openssl-ciphers.html)) - -When specifying multiple cipher names, separate them with colon (`:`). - -### SSL3 cipher suites - -`NULL-MD5` -`NULL-SHA` -`RC4-MD5` -`RC4-SHA` -`IDEA-CBC-SHA` -`DES-CBC3-SHA` -`DH-DSS-DES-CBC3-SHA` -`DH-RSA-DES-CBC3-SHA` -`DHE-DSS-DES-CBC3-SHA` -`DHE-RSA-DES-CBC3-SHA` -`ADH-RC4-MD5` -`ADH-DES-CBC3-SHA` - -### TLS v1.0 cipher suites - -`NULL-MD5` -`NULL-SHA` -`RC4-MD5` -`RC4-SHA` -`IDEA-CBC-SHA` -`DES-CBC3-SHA` -`DHE-DSS-DES-CBC3-SHA` -`DHE-RSA-DES-CBC3-SHA` -`ADH-RC4-MD5` -`ADH-DES-CBC3-SHA` - -### AES cipher suites from RFC 3268, extending TLS v1.0 - -`AES128-SHA` -`AES256-SHA` -`DH-DSS-AES128-SHA` -`DH-DSS-AES256-SHA` -`DH-RSA-AES128-SHA` -`DH-RSA-AES256-SHA` -`DHE-DSS-AES128-SHA` -`DHE-DSS-AES256-SHA` -`DHE-RSA-AES128-SHA` -`DHE-RSA-AES256-SHA` -`ADH-AES128-SHA` -`ADH-AES256-SHA` - -### SEED cipher suites from RFC 4162, extending TLS v1.0 - -`SEED-SHA` -`DH-DSS-SEED-SHA` -`DH-RSA-SEED-SHA` -`DHE-DSS-SEED-SHA` -`DHE-RSA-SEED-SHA` -`ADH-SEED-SHA` - -### GOST cipher suites, extending TLS v1.0 - -`GOST94-GOST89-GOST89` -`GOST2001-GOST89-GOST89` -`GOST94-NULL-GOST94` -`GOST2001-NULL-GOST94` - -### Elliptic curve cipher suites - -`ECDHE-RSA-NULL-SHA` -`ECDHE-RSA-RC4-SHA` -`ECDHE-RSA-DES-CBC3-SHA` -`ECDHE-RSA-AES128-SHA` -`ECDHE-RSA-AES256-SHA` -`ECDHE-ECDSA-NULL-SHA` -`ECDHE-ECDSA-RC4-SHA` -`ECDHE-ECDSA-DES-CBC3-SHA` -`ECDHE-ECDSA-AES128-SHA` -`ECDHE-ECDSA-AES256-SHA` -`AECDH-NULL-SHA` -`AECDH-RC4-SHA` -`AECDH-DES-CBC3-SHA` -`AECDH-AES128-SHA` -`AECDH-AES256-SHA` - -### TLS v1.2 cipher suites - -`NULL-SHA256` -`AES128-SHA256` -`AES256-SHA256` -`AES128-GCM-SHA256` -`AES256-GCM-SHA384` -`DH-RSA-AES128-SHA256` -`DH-RSA-AES256-SHA256` -`DH-RSA-AES128-GCM-SHA256` -`DH-RSA-AES256-GCM-SHA384` -`DH-DSS-AES128-SHA256` -`DH-DSS-AES256-SHA256` -`DH-DSS-AES128-GCM-SHA256` -`DH-DSS-AES256-GCM-SHA384` -`DHE-RSA-AES128-SHA256` -`DHE-RSA-AES256-SHA256` -`DHE-RSA-AES128-GCM-SHA256` -`DHE-RSA-AES256-GCM-SHA384` -`DHE-DSS-AES128-SHA256` -`DHE-DSS-AES256-SHA256` -`DHE-DSS-AES128-GCM-SHA256` -`DHE-DSS-AES256-GCM-SHA384` -`ECDHE-RSA-AES128-SHA256` -`ECDHE-RSA-AES256-SHA384` -`ECDHE-RSA-AES128-GCM-SHA256` -`ECDHE-RSA-AES256-GCM-SHA384` -`ECDHE-ECDSA-AES128-SHA256` -`ECDHE-ECDSA-AES256-SHA384` -`ECDHE-ECDSA-AES128-GCM-SHA256` -`ECDHE-ECDSA-AES256-GCM-SHA384` -`ADH-AES128-SHA256` -`ADH-AES256-SHA256` -`ADH-AES128-GCM-SHA256` -`ADH-AES256-GCM-SHA384` -`AES128-CCM` -`AES256-CCM` -`DHE-RSA-AES128-CCM` -`DHE-RSA-AES256-CCM` -`AES128-CCM8` -`AES256-CCM8` -`DHE-RSA-AES128-CCM8` -`DHE-RSA-AES256-CCM8` -`ECDHE-ECDSA-AES128-CCM` -`ECDHE-ECDSA-AES256-CCM` -`ECDHE-ECDSA-AES128-CCM8` -`ECDHE-ECDSA-AES256-CCM8` - -### Camellia HMAC-Based cipher suites from RFC 6367, extending TLS v1.2 - -`ECDHE-ECDSA-CAMELLIA128-SHA256` -`ECDHE-ECDSA-CAMELLIA256-SHA384` -`ECDHE-RSA-CAMELLIA128-SHA256` -`ECDHE-RSA-CAMELLIA256-SHA384` +For both the TLS 1.3 and TLS 1.2 cipher options, the order in which the +cipher suites are specified determine the preference of them. When negotiating +a TLS connection the server picks a cipher suite from the intersection of the +cipher suites supported by the server and the cipher suites sent by curl. If +the server is configured to honor the client's cipher preference, the first +common cipher suite in the list sent by curl is chosen. ### TLS 1.3 cipher suites -(Note these ciphers are set with `CURLOPT_TLS13_CIPHERS` and `--tls13-ciphers`) +Setting TLS 1.3 cipher suites is supported by curl with +OpenSSL (1.1.1+, curl 7.61.0+), LibreSSL (3.4.1+, curl 8.3.0+), +wolfSSL (curl 8.10.0+) and mbedTLS (3.6.0+, curl 8.10.0+). -`TLS_AES_256_GCM_SHA384` -`TLS_CHACHA20_POLY1305_SHA256` -`TLS_AES_128_GCM_SHA256` -`TLS_AES_128_CCM_8_SHA256` -`TLS_AES_128_CCM_SHA256` +The list of cipher suites that can be used for the `--tls13-ciphers` option: -## WolfSSL +``` +TLS_AES_128_GCM_SHA256 +TLS_AES_256_GCM_SHA384 +TLS_CHACHA20_POLY1305_SHA256 +TLS_AES_128_CCM_SHA256 +TLS_AES_128_CCM_8_SHA256 +``` -`RC4-SHA`, -`RC4-MD5`, -`DES-CBC3-SHA`, -`AES128-SHA`, -`AES256-SHA`, -`NULL-SHA`, -`NULL-SHA256`, -`DHE-RSA-AES128-SHA`, -`DHE-RSA-AES256-SHA`, -`DHE-PSK-AES256-GCM-SHA384`, -`DHE-PSK-AES128-GCM-SHA256`, -`PSK-AES256-GCM-SHA384`, -`PSK-AES128-GCM-SHA256`, -`DHE-PSK-AES256-CBC-SHA384`, -`DHE-PSK-AES128-CBC-SHA256`, -`PSK-AES256-CBC-SHA384`, -`PSK-AES128-CBC-SHA256`, -`PSK-AES128-CBC-SHA`, -`PSK-AES256-CBC-SHA`, -`DHE-PSK-AES128-CCM`, -`DHE-PSK-AES256-CCM`, -`PSK-AES128-CCM`, -`PSK-AES256-CCM`, -`PSK-AES128-CCM-8`, -`PSK-AES256-CCM-8`, -`DHE-PSK-NULL-SHA384`, -`DHE-PSK-NULL-SHA256`, -`PSK-NULL-SHA384`, -`PSK-NULL-SHA256`, -`PSK-NULL-SHA`, -`HC128-MD5`, -`HC128-SHA`, -`HC128-B2B256`, -`AES128-B2B256`, -`AES256-B2B256`, -`RABBIT-SHA`, -`NTRU-RC4-SHA`, -`NTRU-DES-CBC3-SHA`, -`NTRU-AES128-SHA`, -`NTRU-AES256-SHA`, -`AES128-CCM-8`, -`AES256-CCM-8`, -`ECDHE-ECDSA-AES128-CCM`, -`ECDHE-ECDSA-AES128-CCM-8`, -`ECDHE-ECDSA-AES256-CCM-8`, -`ECDHE-RSA-AES128-SHA`, -`ECDHE-RSA-AES256-SHA`, -`ECDHE-ECDSA-AES128-SHA`, -`ECDHE-ECDSA-AES256-SHA`, -`ECDHE-RSA-RC4-SHA`, -`ECDHE-RSA-DES-CBC3-SHA`, -`ECDHE-ECDSA-RC4-SHA`, -`ECDHE-ECDSA-DES-CBC3-SHA`, -`AES128-SHA256`, -`AES256-SHA256`, -`DHE-RSA-AES128-SHA256`, -`DHE-RSA-AES256-SHA256`, -`ECDH-RSA-AES128-SHA`, -`ECDH-RSA-AES256-SHA`, -`ECDH-ECDSA-AES128-SHA`, -`ECDH-ECDSA-AES256-SHA`, -`ECDH-RSA-RC4-SHA`, -`ECDH-RSA-DES-CBC3-SHA`, -`ECDH-ECDSA-RC4-SHA`, -`ECDH-ECDSA-DES-CBC3-SHA`, -`AES128-GCM-SHA256`, -`AES256-GCM-SHA384`, -`DHE-RSA-AES128-GCM-SHA256`, -`DHE-RSA-AES256-GCM-SHA384`, -`ECDHE-RSA-AES128-GCM-SHA256`, -`ECDHE-RSA-AES256-GCM-SHA384`, -`ECDHE-ECDSA-AES128-GCM-SHA256`, -`ECDHE-ECDSA-AES256-GCM-SHA384`, -`ECDH-RSA-AES128-GCM-SHA256`, -`ECDH-RSA-AES256-GCM-SHA384`, -`ECDH-ECDSA-AES128-GCM-SHA256`, -`ECDH-ECDSA-AES256-GCM-SHA384`, -`CAMELLIA128-SHA`, -`DHE-RSA-CAMELLIA128-SHA`, -`CAMELLIA256-SHA`, -`DHE-RSA-CAMELLIA256-SHA`, -`CAMELLIA128-SHA256`, -`DHE-RSA-CAMELLIA128-SHA256`, -`CAMELLIA256-SHA256`, -`DHE-RSA-CAMELLIA256-SHA256`, -`ECDHE-RSA-AES128-SHA256`, -`ECDHE-ECDSA-AES128-SHA256`, -`ECDH-RSA-AES128-SHA256`, -`ECDH-ECDSA-AES128-SHA256`, -`ECDHE-RSA-AES256-SHA384`, -`ECDHE-ECDSA-AES256-SHA384`, -`ECDH-RSA-AES256-SHA384`, -`ECDH-ECDSA-AES256-SHA384`, -`ECDHE-RSA-CHACHA20-POLY1305`, -`ECDHE-ECDSA-CHACHA20-POLY1305`, -`DHE-RSA-CHACHA20-POLY1305`, -`ECDHE-RSA-CHACHA20-POLY1305-OLD`, -`ECDHE-ECDSA-CHACHA20-POLY1305-OLD`, -`DHE-RSA-CHACHA20-POLY1305-OLD`, -`ADH-AES128-SHA`, -`QSH`, -`RENEGOTIATION-INFO`, -`IDEA-CBC-SHA`, -`ECDHE-ECDSA-NULL-SHA`, -`ECDHE-PSK-NULL-SHA256`, -`ECDHE-PSK-AES128-CBC-SHA256`, -`PSK-CHACHA20-POLY1305`, -`ECDHE-PSK-CHACHA20-POLY1305`, -`DHE-PSK-CHACHA20-POLY1305`, -`EDH-RSA-DES-CBC3-SHA`, +#### wolfSSL notes -## Schannel +In addition to above list the following cipher suites can be used: +`TLS_SM4_GCM_SM3` `TLS_SM4_CCM_SM3` `TLS_SHA256_SHA256` `TLS_SHA384_SHA384`. +Usage of these cipher suites is not recommended. (The last two cipher suites +are NULL ciphers, offering no encryption whatsoever.) -Schannel allows the enabling and disabling of encryption algorithms, but not -specific cipher suites, prior to TLS 1.3. The algorithms are -[defined](https://docs.microsoft.com/windows/desktop/SecCrypto/alg-id) by -Microsoft. +### TLS 1.2 (1.1, 1.0) cipher suites -The algorithms below are for TLS 1.2 and earlier. TLS 1.3 is covered in the -next section. +Setting TLS 1.2 cipher suites is supported by curl with AWS-LC, BoringSSL, +LibreSSL, mbedTLS (curl 8.8.0+), OpenSSL, wolfSSL (curl 7.53.0+). Schannel +does not support setting cipher suites directly, but does support setting +algorithms (curl 7.61.0+), see Schannel notes below. -There is also the case that the selected algorithm is not supported by the -protocol or does not match the ciphers offered by the server during the SSL -negotiation. In this case curl will return error -`CURLE_SSL_CONNECT_ERROR (35) SEC_E_ALGORITHM_MISMATCH` -and the request will fail. +For TLS 1.2 cipher suites there are multiple naming schemes, the two most used +are with OpenSSL names (e.g. `ECDHE-RSA-AES128-GCM-SHA256`) and IANA names +(e.g. `TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256`). IANA names of TLS 1.2 cipher +suites look similar to TLS 1.3 cipher suite names, to distinguish them note +that TLS 1.2 names contain `_WITH_`, while TLS 1.3 names do not. When setting +TLS 1.2 cipher suites with curl it is recommended that you use OpenSSL names +as these are most widely recognized by the supported SSL backends. -`CALG_MD2`, -`CALG_MD4`, -`CALG_MD5`, -`CALG_SHA`, -`CALG_SHA1`, -`CALG_MAC`, -`CALG_RSA_SIGN`, -`CALG_DSS_SIGN`, -`CALG_NO_SIGN`, -`CALG_RSA_KEYX`, -`CALG_DES`, -`CALG_3DES_112`, -`CALG_3DES`, -`CALG_DESX`, -`CALG_RC2`, -`CALG_RC4`, -`CALG_SEAL`, -`CALG_DH_SF`, -`CALG_DH_EPHEM`, -`CALG_AGREEDKEY_ANY`, -`CALG_HUGHES_MD5`, -`CALG_SKIPJACK`, -`CALG_TEK`, -`CALG_CYLINK_MEK`, -`CALG_SSL3_SHAMD5`, -`CALG_SSL3_MASTER`, -`CALG_SCHANNEL_MASTER_HASH`, -`CALG_SCHANNEL_MAC_KEY`, -`CALG_SCHANNEL_ENC_KEY`, -`CALG_PCT1_MASTER`, -`CALG_SSL2_MASTER`, -`CALG_TLS1_MASTER`, -`CALG_RC5`, -`CALG_HMAC`, -`CALG_TLS1PRF`, -`CALG_HASH_REPLACE_OWF`, -`CALG_AES_128`, -`CALG_AES_192`, -`CALG_AES_256`, -`CALG_AES`, -`CALG_SHA_256`, -`CALG_SHA_384`, -`CALG_SHA_512`, -`CALG_ECDH`, -`CALG_ECMQV`, -`CALG_ECDSA`, -`CALG_ECDH_EPHEM`, +The complete list of cipher suites that may be considered for the `--ciphers` +option is extensive, it consists of more than 300 ciphers suites. Nowadays, +most of them are discouraged, and support for a lot of them has been removed +from the various SSL backends, if ever implemented at all. -As of curl 7.77.0, you can also pass `SCH_USE_STRONG_CRYPTO` as a cipher name -to [constrain the set of available ciphers as specified in the Schannel -documentation](https://docs.microsoft.com/en-us/windows/win32/secauthn/tls-cipher-suites-in-windows-server-2022). -Note that the supported ciphers in this case follow the OS version, so if you -are running an outdated OS you might still be supporting weak ciphers. +A shortened list (based on [recommendations by +Mozilla](https://wiki.mozilla.org/Security/Server_Side_TLS)) of cipher suites, +which are (mostly) supported by all SSL backends, that can be used for the +`--ciphers` option: -### TLS 1.3 cipher suites +``` +ECDHE-ECDSA-AES128-GCM-SHA256 +ECDHE-RSA-AES128-GCM-SHA256 +ECDHE-ECDSA-AES256-GCM-SHA384 +ECDHE-RSA-AES256-GCM-SHA384 +ECDHE-ECDSA-CHACHA20-POLY1305 +ECDHE-RSA-CHACHA20-POLY1305 +DHE-RSA-AES128-GCM-SHA256 +DHE-RSA-AES256-GCM-SHA384 +DHE-RSA-CHACHA20-POLY1305 +ECDHE-ECDSA-AES128-SHA256 +ECDHE-RSA-AES128-SHA256 +ECDHE-ECDSA-AES128-SHA +ECDHE-RSA-AES128-SHA +ECDHE-ECDSA-AES256-SHA384 +ECDHE-RSA-AES256-SHA384 +ECDHE-ECDSA-AES256-SHA +ECDHE-RSA-AES256-SHA +DHE-RSA-AES128-SHA256 +DHE-RSA-AES256-SHA256 +AES128-GCM-SHA256 +AES256-GCM-SHA384 +AES128-SHA256 +AES256-SHA256 +AES128-SHA +AES256-SHA +DES-CBC3-SHA +``` -You can set TLS 1.3 ciphers for Schannel by using `CURLOPT_TLS13_CIPHERS` or -`--tls13-ciphers` with the names below. +See this [list](https://github.com/curl/curl/blob/master/docs/CIPHERS-TLS12.md) +for a complete list of TLS 1.2 cipher suites. -If TLS 1.3 cipher suites are set then libcurl will add or restrict Schannel TLS -1.3 algorithms automatically. Essentially, libcurl is emulating support for -individual TLS 1.3 cipher suites since Schannel does not support it directly. +#### OpenSSL notes -`TLS_AES_256_GCM_SHA384` -`TLS_AES_128_GCM_SHA256` -`TLS_CHACHA20_POLY1305_SHA256` -`TLS_AES_128_CCM_8_SHA256` -`TLS_AES_128_CCM_SHA256` +In addition to specifying a list of cipher suites, OpenSSL also accepts a +format with specific cipher strings (like `TLSv1.2`, `AESGCM`, `CHACHA20`) and +`!`, `-` and `+` operators. Refer to the +[OpenSSL cipher documentation](https://docs.openssl.org/master/man1/openssl-ciphers/#cipher-list-format) +for further information on that format. -Note if you set TLS 1.3 ciphers without also setting the minimum TLS version to -1.3 then it's possible Schannel may negotiate an earlier TLS version and cipher -suite if your libcurl and OS settings allow it. You can set the minimum TLS -version by using `CURLOPT_SSLVERSION` or `--tlsv1.3`. +#### Schannel notes -## BearSSL +Schannel does not support setting individual TLS 1.2 cipher suites directly. +It only allows the enabling and disabling of encryption algorithms. These are +in the form of `CALG_xxx`, see the [Schannel `ALG_ID` +documentation](https://learn.microsoft.com/windows/win32/seccrypto/alg-id) +for a list of these algorithms. Also, (since curl 7.77.0) +`SCH_USE_STRONG_CRYPTO` can be given to pass that flag to Schannel, lookup the +[documentation for the Windows version in +use](https://learn.microsoft.com/windows/win32/secauthn/cipher-suites-in-schannel) +to see how that affects the cipher suite selection. When not specifying the +`--ciphers` and `--tls13-ciphers` options curl passes this flag by default. -BearSSL ciphers can be specified by either the OpenSSL name (`ECDHE-RSA-AES128-GCM-SHA256`) or the IANA name (`TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256`). +### Examples -Since BearSSL 0.1: +```sh +curl \ + --tls13-ciphers TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256 \ + --ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:\ +ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305 \ + https://example.com/ +``` -`DES-CBC3-SHA` -`AES128-SHA` -`AES256-SHA` -`AES128-SHA256` -`AES256-SHA256` -`AES128-GCM-SHA256` -`AES256-GCM-SHA384` -`ECDH-ECDSA-DES-CBC3-SHA` -`ECDH-ECDSA-AES128-SHA` -`ECDH-ECDSA-AES256-SHA` -`ECDHE-ECDSA-DES-CBC3-SHA` -`ECDHE-ECDSA-AES128-SHA` -`ECDHE-ECDSA-AES256-SHA` -`ECDH-RSA-DES-CBC3-SHA` -`ECDH-RSA-AES128-SHA` -`ECDH-RSA-AES256-SHA` -`ECDHE-RSA-DES-CBC3-SHA` -`ECDHE-RSA-AES128-SHA` -`ECDHE-RSA-AES256-SHA` -`ECDHE-ECDSA-AES128-SHA256` -`ECDHE-ECDSA-AES256-SHA384` -`ECDH-ECDSA-AES128-SHA256` -`ECDH-ECDSA-AES256-SHA384` -`ECDHE-RSA-AES128-SHA256` -`ECDHE-RSA-AES256-SHA384` -`ECDH-RSA-AES128-SHA256` -`ECDH-RSA-AES256-SHA384` -`ECDHE-ECDSA-AES128-GCM-SHA256` -`ECDHE-ECDSA-AES256-GCM-SHA384` -`ECDH-ECDSA-AES128-GCM-SHA256` -`ECDH-ECDSA-AES256-GCM-SHA384` -`ECDHE-RSA-AES128-GCM-SHA256` -`ECDHE-RSA-AES256-GCM-SHA384` -`ECDH-RSA-AES128-GCM-SHA256` -`ECDH-RSA-AES256-GCM-SHA384` +Restrict ciphers to `aes128-gcm` and `chacha20`. Works with OpenSSL, LibreSSL, +mbedTLS and wolfSSL. -Since BearSSL 0.2: +```sh +curl \ + --tlsv1.3 \ + --tls-max 1.3 \ + --tls13-ciphers TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256 \ + https://example.com/ +``` -`ECDHE-RSA-CHACHA20-POLY1305` -`ECDHE-ECDSA-CHACHA20-POLY1305` +Restrict to only TLS 1.3 with `aes128-gcm` and `chacha20` ciphers. Works with +OpenSSL, LibreSSL, mbedTLS and wolfSSL. -Since BearSSL 0.6: +```sh +curl \ + --ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:\ +ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305 \ + https://example.com/ +``` -`AES128-CCM` -`AES256-CCM` -`AES128-CCM8` -`AES256-CCM8` -`ECDHE-ECDSA-AES128-CCM` -`ECDHE-ECDSA-AES256-CCM` -`ECDHE-ECDSA-AES128-CCM8` -`ECDHE-ECDSA-AES256-CCM8` +Restrict TLS 1.2 ciphers to `aes128-gcm` and `chacha20`, use default TLS 1.3 +ciphers (if TLS 1.3 is available). Works with OpenSSL, LibreSSL, BoringSSL, +mbedTLS and wolfSSL. + +## ciphers, the GnuTLS way + +With GnuTLS, curl allows configuration of all TLS parameters via option +[`--ciphers`](https://curl.se/docs/manpage.html#--ciphers) +or +[`CURLOPT_SSL_CIPHER_LIST`](https://curl.se/libcurl/c/CURLOPT_SSL_CIPHER_LIST.html) +only. The option +[`--tls13-ciphers`](https://curl.se/docs/manpage.html#--tls13-ciphers) +or +[`CURLOPT_TLS13_CIPHERS`](https://curl.se/libcurl/c/CURLOPT_TLS13_CIPHERS.html) +is being ignored. + +`--ciphers` is used to set the GnuTLS **priority string** in +the following way: + +* When the set string starts with '+', '-' or '!' it is *appended* to the + priority string libcurl itself generates (separated by ':'). This initial + priority depends other settings such as CURLOPT_SSLVERSION(3), + CURLOPT_TLSAUTH_USERNAME(3) (for SRP) or if HTTP/3 (QUIC) + is being negotiated. +* Otherwise, the set string fully *replaces* the libcurl generated one. While + giving full control to the application, the set priority needs to + provide for everything the transfer may need to negotiate. Example: if + the set priority only allows TLSv1.2, all HTTP/3 attempts fail. + +Users may specify via `--ciphers` anything that GnuTLS supports: ciphers, +key exchange, MAC, compression, TLS versions, signature algorithms, groups, +elliptic curves, certificate types. In addition, GnuTLS has a variety of +other keywords that tweak its operations. Applications or a system +may define new alias names for priority strings that can then be used here. + +Since the order of items in priority strings is significant, it makes no +sense for curl to puzzle other SSL options somehow together. `--ciphers` +is the single way to change priority. + +### Examples + +```sh +curl \ + --ciphers '-CIPHER_ALL:+AES-128-GCM:+CHACHA20-POLY1305' \ + https://example.com/ +``` + +Restrict ciphers to `aes128-gcm` and `chacha20` in GnuTLS. + +```sh +curl \ + --ciphers 'NORMAL:-VERS-ALL:+TLS1.3:-AES-256-GCM' \ + https://example.com/ +``` + +Restrict to only TLS 1.3 without the `aes256-gcm` cipher. + +```sh +curl \ + --ciphers 'NORMAL:-VERS-ALL:+TLS1.2:-CIPHER_ALL:+CAMELLIA-128-GCM' \ + https://example.com/ +``` + +Restrict to only TLS 1.2 with the `CAMELLIA-128-GCM` cipher. + +## Further reading + +- [GnuTLS Priority Strings](https://gnutls.org/manual/html_node/Priority-Strings.html) +- [IANA cipher suites list](https://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#tls-parameters-4) +- [mbedTLS cipher suites reference](https://mbed-tls.readthedocs.io/projects/api/en/development/api/file/ssl__ciphersuites_8h/) +- [OpenSSL cipher suite names documentation](https://docs.openssl.org/master/man1/openssl-ciphers/#cipher-suite-names) +- [Schannel cipher suites documentation](https://learn.microsoft.com/windows/win32/secauthn/cipher-suites-in-schannel) +- [Wikipedia cipher suite article](https://en.wikipedia.org/wiki/Cipher_suite) +- [wolfSSL cipher support documentation](https://www.wolfssl.com/documentation/manuals/wolfssl/chapter04.html#cipher-support) diff --git a/third-party/curl/docs/CMakeLists.txt b/third-party/curl/docs/CMakeLists.txt index dd2c6dc74e..9c02530193 100644 --- a/third-party/curl/docs/CMakeLists.txt +++ b/third-party/curl/docs/CMakeLists.txt @@ -21,6 +21,31 @@ # SPDX-License-Identifier: curl # ########################################################################### -#add_subdirectory(examples) -add_subdirectory(libcurl) -add_subdirectory(cmdline-opts) + +if(BUILD_LIBCURL_DOCS) + add_subdirectory(libcurl) +endif() +if(ENABLE_CURL_MANUAL AND BUILD_CURL_EXE) + add_subdirectory(cmdline-opts) +endif() + +if(BUILD_MISC_DOCS) + set(_man_targets "curl-config" "mk-ca-bundle") + if(BUILD_CURL_EXE) + list(APPEND _man_targets "wcurl") + endif() + + foreach(_man_misc IN LISTS _man_targets) + set(_man_target "${CMAKE_CURRENT_BINARY_DIR}/${_man_misc}.1") + add_custom_command(OUTPUT "${_man_target}" + WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR} + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/cd2nroff" "${_man_misc}.md" > "${_man_target}" + DEPENDS "${PROJECT_SOURCE_DIR}/scripts/cd2nroff" "${_man_misc}.md" + VERBATIM + ) + add_custom_target("curl-generate-${_man_misc}.1" ALL DEPENDS "${_man_target}") + if(NOT CURL_DISABLE_INSTALL AND NOT _man_misc STREQUAL "mk-ca-bundle") + install(FILES "${_man_target}" DESTINATION "${CMAKE_INSTALL_MANDIR}/man1") + endif() + endforeach() +endif() diff --git a/third-party/curl/docs/CODE_OF_CONDUCT.md b/third-party/curl/docs/CODE_OF_CONDUCT.md index 1f71c387bd..f42fd493d0 100644 --- a/third-party/curl/docs/CODE_OF_CONDUCT.md +++ b/third-party/curl/docs/CODE_OF_CONDUCT.md @@ -1,5 +1,10 @@ -Contributor Code of Conduct -=========================== + + +# Contributor Code of Conduct As contributors and maintainers of this project, we pledge to respect all people who contribute through reporting issues, posting feature requests, @@ -27,6 +32,7 @@ Instances of abusive, harassing, or otherwise unacceptable behavior may be reported by opening an issue or contacting one or more of the project maintainers. -This Code of Conduct is adapted from the [Contributor -Covenant](https://contributor-covenant.org/), version 1.1.0, available at +This Code of Conduct is adapted from the +[Contributor Covenant](https://contributor-covenant.org/), version 1.1.0, +available at [https://contributor-covenant.org/version/1/1/0/](https://contributor-covenant.org/version/1/1/0/) diff --git a/third-party/curl/docs/CODE_REVIEW.md b/third-party/curl/docs/CODE_REVIEW.md index 0776d30a08..a80d2eec3c 100644 --- a/third-party/curl/docs/CODE_REVIEW.md +++ b/third-party/curl/docs/CODE_REVIEW.md @@ -1,3 +1,9 @@ + + # How to do code reviews for curl Anyone and everyone is encouraged and welcome to review code submissions in @@ -135,13 +141,13 @@ data. Where it comes from and where it goes. `size_t` is not a fixed size. `time_t` can be signed or unsigned and have different sizes. Relying on variable sizes is a red flag. -Also remember that endianness and >= 32 bit accesses to unaligned addresses +Also remember that endianness and >= 32-bit accesses to unaligned addresses are problematic areas. ## Integer overflows -Be careful about integer overflows. Some variable types can be either 32 bit -or 64 bit. Integer overflows must be detected and acted on *before* they +Be careful about integer overflows. Some variable types can be either 32-bit +or 64-bit. Integer overflows must be detected and acted on *before* they happen. ## Dangerous use of functions @@ -150,19 +156,20 @@ Maybe use of `realloc()` should rather use the dynbuf functions? Do not allow new code that grows buffers without using dynbuf. -Use of C functions that rely on a terminating zero must only be used on data -that really do have a null-terminating zero. +Use of C functions that rely on a null-terminator must only be used on data +that really do have a null-terminator (`\0` byte). ## Dangerous "data styles" -Make extra precautions and verify that memory buffers that need a terminating -zero always have exactly that. Buffers *without* a null-terminator must not be -used as input to string functions. +Make extra precautions and verify that memory buffers that need +null-terminator always have exactly that. Buffers *without* a null-terminator +must not be used as input to string functions. # Commit messages Tightly coupled with a code review is making sure that the commit message is good. It is the responsibility of the person who merges the code to make sure that the commit message follows our standard (detailed in the -[CONTRIBUTE](CONTRIBUTE.md) document). This includes making sure the PR -identifies related issues and giving credit to reporters and helpers. +[CONTRIBUTE](https://curl.se/dev/contribute.html) document). This includes +making sure the PR identifies related issues and giving credit to reporters +and helpers. diff --git a/third-party/curl/docs/CONNECTION-FILTERS.md b/third-party/curl/docs/CONNECTION-FILTERS.md deleted file mode 100644 index c4b11dbb01..0000000000 --- a/third-party/curl/docs/CONNECTION-FILTERS.md +++ /dev/null @@ -1,127 +0,0 @@ -# curl connection filters - -Connection filters is a design in the internals of curl, not visible in its public API. They were added -in curl v7.xx.x. This document describes the concepts, its high level implementation and the motivations. - -## Filters - -A "connection filter" is a piece of code that is responsible for handling a range of operations -of curl's connections: reading, writing, waiting on external events, connecting and closing down - to name the most important ones. - -The most important feat of connection filters is that they can be stacked on top of each other (or "chained" if you prefer that metaphor). In the common scenario that you want to retrieve a `https:` url with curl, you need 2 basic things to send the request and get the response: a TCP connection, represented by a `socket` and a SSL instance en- and decrypt over that socket. You write your request to the SSL instance, which encrypts and writes that data to the socket, which then sends the bytes over the network. - -With connection filters, curl's internal setup will look something like this (cf for connection filter): - -``` -Curl_easy *data connectdata *conn cf-ssl cf-socket -+----------------+ +-----------------+ +-------+ +--------+ -|https://curl.se/|----> | properties |----> | keys |---> | socket |--> OS --> network -+----------------+ +-----------------+ +-------+ +--------+ - - Curl_write(data, buffer) - --> Curl_cfilter_write(data, data->conn, buffer) - ---> conn->filter->write(conn->filter, data, buffer) -``` - -While connection filters all do different things, they look the same from the "outside". The code in `data` and `conn` does not really know **which** filters are installed. `conn` just writes into the first filter, whatever that is. - -Same is true for filters. Each filter has a pointer to the `next` filter. When SSL has encrypted the data, it does not write to a socket, it writes to the next filter. If that is indeed a socket, or a file, or an HTTP/2 connection is of no concern to the SSL filter. - -And this allows the stacking, as in: - -``` -Direct: - http://localhost/ conn -> cf-socket - https://curl.se/ conn -> cf-ssl -> cf-socket -Via http proxy tunnel: - http://localhost/ conn -> cf-http-proxy -> cf-socket - https://curl.se/ conn -> cf-ssl -> cf-http-proxy -> cf-socket -Via https proxy tunnel: - http://localhost/ conn -> cf-http-proxy -> cf-ssl -> cf-socket - https://curl.se/ conn -> cf-ssl -> cf-http-proxy -> cf-ssl -> cf-socket -Via http proxy tunnel via SOCKS proxy: - http://localhost/ conn -> cf-http-proxy -> cf-socks -> cf-socket -``` - -### Connecting/Closing - -Before `Curl_easy` can send the request, the connection needs to be established. This means that all connection filters have done, whatever they need to do: waiting for the socket to be connected, doing the TLS handshake, performing the HTTP tunnel request, etc. This has to be done in reverse order: the last filter has to do its connect first, then the one above can start, etc. - -Each filter does in principle the following: - -``` -static CURLcode -myfilter_cf_connect(struct Curl_cfilter *cf, - struct Curl_easy *data, - bool *done) -{ - CURLcode result; - - if(cf->connected) { /* we and all below are done */ - *done = TRUE; - return CURLE_OK; - } - /* Let the filters below connect */ - result = cf->next->cft->connect(cf->next, data, blocking, done); - if(result || !*done) - return result; /* below errored/not finished yet */ - - /* MYFILTER CONNECT THINGS */ /* below connected, do out thing */ - *done = cf->connected = TRUE; /* done, remember, return */ - return CURLE_OK; -} -``` - -Closing a connection then works similar. The `conn` tells the first filter to close. Contrary to connecting, -the filter does its own things first, before telling the next filter to close. - -### Efficiency - -There are two things curl is concerned about: efficient memory use and fast transfers. - -The memory footprint of a filter is relatively small: - -``` -struct Curl_cfilter { - const struct Curl_cftype *cft; /* the type providing implementation */ - struct Curl_cfilter *next; /* next filter in chain */ - void *ctx; /* filter type specific settings */ - struct connectdata *conn; /* the connection this filter belongs to */ - int sockindex; /* TODO: like to get rid off this */ - BIT(connected); /* != 0 iff this filter is connected */ -}; -``` -The filter type `cft` is a singleton, one static struct for each type of filter. The `ctx` is where a filter will hold its specific data. That varies by filter type. An http-proxy filter will keep the ongoing state of the CONNECT here, but free it after its has been established. The SSL filter will keep the `SSL*` (if OpenSSL is used) here until the connection is closed. So, this varies. - -`conn` is a reference to the connection this filter belongs to, so nothing extra besides the pointer itself. - -Several things, that before were kept in `struct connectdata`, will now go into the `filter->ctx` *when needed*. So, the memory footprint for connections that do *not* use an http proxy, or socks, or https will be lower. - -As to transfer efficiency, writing and reading through a filter comes at near zero cost *if the filter does not transform the data*. An http proxy or socks filter, once it is connected, will just pass the calls through. Those filters implementations will look like this: - -``` -ssize_t Curl_cf_def_send(struct Curl_cfilter *cf, struct Curl_easy *data, - const void *buf, size_t len, CURLcode *err) -{ - return cf->next->cft->do_send(cf->next, data, buf, len, err); -} -``` -The `recv` implementation is equivalent. - -## Filter Types - -The (currently) existing filter types are: SOCKET, SOCKET-ACCEPT, SSL, HTTP-PROXY and SOCKS-PROXY. Vital to establishing and read/writing a connection. But filters are also a good way to implement tasks for *managing* a connection: - -* **Statistics**: a filter that counts the number of bytes sent/received. Place one in front of SOCKET and one higher up and get the number of raw and "easy" bytes transferred. They may track the speed as well, or number of partial writes, etc. -* **Timeout**: enforce timeouts, e.g. fail if a connection cannot be established in a certain amount of time. -* **Progress**: report progress on a connection. -* **Pacing**: limit read/write rates. -* **Testing**: simulate network condition or failures. - -As you see, filters are a good way to add functionality to curl's internal handling of transfers without impact on other code. - -## Easy Filters? - -Some things that curl needs to manage are not directly tied to a specific connection but the property of the `Curl_easy` handle, e.g. a particular transfer. When using HTTP/2 or HTTP/3, many transfers can use the same connection. If one wants to monitor of the transfer itself or restricting its speed alone, a connection filter is not the right place to do this. - -So we might add "easy filters" one day. Who knows? diff --git a/third-party/curl/docs/CONTRIBUTE.md b/third-party/curl/docs/CONTRIBUTE.md index 72d3190019..f9b473c09a 100644 --- a/third-party/curl/docs/CONTRIBUTE.md +++ b/third-party/curl/docs/CONTRIBUTE.md @@ -1,3 +1,9 @@ + + # Contributing to the curl project This document is intended to offer guidelines on how to best contribute to the @@ -18,7 +24,7 @@ Before posting to one of the curl mailing lists, please read up on the We also hang out on IRC in #curl on libera.chat If you are at all interested in the code side of things, consider clicking -'watch' on the [curl repo on GitHub](https://github.com/curl/curl) to be +'watch' on the [curl repository on GitHub](https://github.com/curl/curl) to be notified of pull requests and new issues posted there. ## License and copyright @@ -35,14 +41,14 @@ must use "GPL compatible" licenses (as we want to allow users to use libcurl properly in GPL licensed environments). When changing existing source code, you do not alter the copyright of the -original file(s). The copyright will still be owned by the original creator(s) -or those who have been assigned copyright by the original author(s). +original file(s). The copyright is still owned by the original creator(s) or +those who have been assigned copyright by the original author(s). By submitting a patch to the curl project, you are assumed to have the right to the code and to be allowed by your employer or whatever to hand over that -patch/code to us. We will credit you for your changes as far as possible, to -give credit but also to keep a trace back to who made what changes. Please -always provide us with your full real name when contributing, +patch/code to us. We credit you for your changes as far as possible, to give +credit but also to keep a trace back to who made what changes. Please always +provide us with your full real name when contributing. ## What To Read @@ -50,10 +56,10 @@ Source code, the man pages, the [INTERNALS document](https://curl.se/dev/internals.html), [TODO](https://curl.se/docs/todo.html), [KNOWN_BUGS](https://curl.se/docs/knownbugs.html) and the [most recent -changes](https://curl.se/dev/sourceactivity.html) in git. Just lurking on -the [curl-library mailing -list](https://curl.se/mail/list.cgi?list=curl-library) will give you a -lot of insights on what's going on right now. Asking there is a good idea too. +changes](https://curl.se/dev/sourceactivity.html) in git. Lurking on the +[curl-library mailing list](https://curl.se/mail/list.cgi?list=curl-library) +gives you a lot of insights on what's going on right now. Asking there is a +good idea too. ## Write a good patch @@ -77,11 +83,11 @@ fix one bug at a time and send them as separate patches. ### Write Separate Changes -It is annoying when you get a huge patch from someone that is said to fix 511 -odd problems, but discussions and opinions do not agree with 510 of them - or -509 of them were already fixed in a different way. Then the person merging -this change needs to extract the single interesting patch from somewhere -within the huge pile of source, and that creates a lot of extra work. +It is annoying when you get a huge patch from someone that is said to fix 11 +odd problems, but discussions and opinions do not agree with 10 of them - or 9 +of them were already fixed in a different way. Then the person merging this +change needs to extract the single interesting patch from somewhere within the +huge pile of source, and that creates a lot of extra work. Preferably, each fix that corrects a problem should be in its own patch/commit with its own description/commit message stating exactly what they correct so @@ -96,57 +102,58 @@ and regression in the future. Please try to get the latest available sources to make your patches against. It makes the lives of the developers so much easier. The best is if you get the most up-to-date sources from the git repository, but the latest release -archive is quite OK as well. +archive is OK as well. ### Documentation Writing docs is dead boring and one of the big problems with many open source -projects. But someone's gotta do it. It makes things a lot easier if you -submit a small description of your fix or your new features with every -contribution so that it can be swiftly added to the package documentation. +projects but someone's gotta do it. It makes things a lot easier if you submit +a small description of your fix or your new features with every contribution +so that it can be swiftly added to the package documentation. -The documentation is always made in man pages (nroff formatted) or plain -ASCII files. All HTML files on the website and in the release archives are -generated from the nroff/ASCII versions. +Documentation is mostly provided as man pages or plain ASCII files. The +man pages are rendered from their source files that are usually written using +markdown. Most HTML files on the website and in the release archives are +generated from corresponding markdown and ASCII files. ### Test Cases Since the introduction of the test suite, we can quickly verify that the main features are working as they are supposed to. To maintain this situation and -improve it, all new features and functions that are added need to be tested -in the test suite. Every feature that is added should get at least one valid -test case that verifies that it works as documented. If every submitter also -posts a few test cases, it will not end up as a heavy burden on a single person! +improve it, all new features and functions that are added need to be tested in +the test suite. Every feature that is added should get at least one valid test +case that verifies that it works as documented. If every submitter also posts +a few test cases, it does not end up a heavy burden on a single person. If you do not have test cases or perhaps you have done something that is hard to write tests for, do explain exactly how you have otherwise tested and verified your changes. -## Submit Your Changes +# Submit Your Changes -### How to get your changes into the main sources +## Get your changes merged Ideally you file a [pull request on GitHub](https://github.com/curl/curl/pulls), but you can also send your plain patch to [the curl-library mailing list](https://curl.se/mail/list.cgi?list=curl-library). -If you opt to post a patch on the mailing list, chances are someone will -convert it into a pull request for you, to have the CI jobs verify it proper -before it can be merged. Be prepared that some feedback on the proposed change -might then come on GitHub. +If you opt to post a patch on the mailing list, chances are someone converts +it into a pull request for you, to have the CI jobs verify it proper before it +can be merged. Be prepared that some feedback on the proposed change might +then come on GitHub. -Your change will be reviewed and discussed and you will be expected to correct -flaws pointed out and update accordingly, or the change risks stalling and -eventually just getting deleted without action. As a submitter of a change, -you are the owner of that change until it has been merged. +As your changes are reviewed and discussed, you are expected to address any +flaws pointed out and update accordingly. Otherwise your changes risk stalling +and eventually being deleted without action. As a submitter of a change, you +are the owner of that change until it has been merged. Respond on the list or on GitHub about the change and answer questions and/or -fix nits/flaws. This is important. We will take lack of replies as a sign that -you are not anxious to get your patch accepted and we tend to simply drop such +fix nits/flaws. This is important. We take lack of replies as a sign that you +are not anxious to get your patch accepted and we tend to drop such changes. -### About pull requests +## About pull requests With GitHub it is easy to send a [pull request](https://github.com/curl/curl/pulls) to the curl project to have @@ -157,13 +164,13 @@ git commit that is easy to merge and they are easy to track and not that easy to lose in the flood of many emails, like they sometimes do on the mailing lists. -Every pull request submitted will automatically be tested in several different +Every pull request submitted is automatically tested in several different ways. [See the CI document for more -information](https://github.com/curl/curl/blob/master/tests/CI.md). +information](https://github.com/curl/curl/blob/master/docs/tests/CI.md). Sometimes the tests fail due to a dependency service temporarily being offline -or otherwise unavailable, e.g. package downloads. In this case you can just -try to update your pull requests to rerun the tests later as described below. +or otherwise unavailable, e.g. package downloads. In this case you can try to +update your pull requests to rerun the tests later as described below. You can update your pull requests by pushing new commits or force-pushing changes to existing commits. Force-pushing an amended commit without any @@ -178,7 +185,23 @@ checks and qualifications this pull request must also receive more "votes" of user support. More signs that people want this to happen. It could be in the form of messages saying so, or thumbs-up reactions on GitHub. -### Making quality changes +## When the pull request is approved + +If it does not seem to get approved when you think it is ready - feel free to +ask for approval. + +Once your pull request has been approved it can be merged by a maintainer. + +For new features, or changes, we require that the *feature window* is open for +the pull request to be merged. This is typically a three week period that +starts ten days after a previous release. New features submitted as pull +requests while the window is closed have to wait until it opens to get +merged. + +If time passes without your approved pull request gets merged: feel free to +ask what more you can do to make it happen. + +## Making quality changes Make the patch against as recent source versions as possible. @@ -186,131 +209,161 @@ If you have followed the tips in this document and your patch still has not been incorporated or responded to after some weeks, consider resubmitting it to the list or better yet: change it to a pull request. -### Commit messages +## Commit messages -A short guide to how to write git commit messages in the curl project. +How to write git commit messages in the curl project. ---- start ---- [area]: [short line describing the main effect] -- empty line -- [full description, no wider than 72 columns that describes as much as possible as to why this change is made, and possibly what things - it fixes and everything else that is related, with unwieldy URLs replaced - with references like [0], [1], etc.] - -- empty line -- - [[0] URL - Reference to a URL in the description, almost like Markdown; - the last numbered reference is followed by an -- empty line -- ] - [Follow-up to {shorthash} - if this fixes or continues a previous commit; - add a Ref: that commit's PR or issue if it's not a small, obvious fix; - followed by an -- empty line -- ] - [Bug: URL to the source of the report or more related discussion; use Fixes - for GitHub issues instead when that is appropriate] - [Approved-by: John Doe - credit someone who approved the PR; if you are - committing this for someone else using --author=... you do not need this - as you are implicitly approving it by committing] - [Authored-by: John Doe - credit the original author of the code; only use - this if you cannot use "git commit --author=..."] - [Signed-off-by: John Doe - we do not use this, but do not bother removing it] - [whatever-else-by: credit all helpers, finders, doers; try to use one of - the following keywords if at all possible, for consistency: - Acked-by:, Assisted-by:, Co-authored-by:, Found-by:, Reported-by:, - Reviewed-by:, Suggested-by:, Tested-by:] - [Ref: #1234 - if this is related to a GitHub issue or PR, possibly one that - has already been closed] - [Ref: URL to more information about the commit; use Bug: instead for - a reference to a bug on another bug tracker] - [Fixes #1234 - if this closes a GitHub issue; GitHub will actually - close the issue once this commit is merged] - [Closes #1234 - if this closes a GitHub PR; GitHub will actually - close the PR once this commit is merged] - ---- stop ---- + it fixes and everything else that is related, + -- end -- -The first line is a succinct description of the change: +The first line is a succinct description of the change and should ideally work +as a single line in the RELEASE NOTES. - - use the imperative, present tense: "change" not "changed" nor "changes" - - do not capitalize the first letter - - no period (.) at the end +- use the imperative, present tense: **change** not "changed" nor "changes" +- do not capitalize the first letter +- no period (.) at the end The `[area]` in the first line can be `http2`, `cookies`, `openssl` or similar. There is no fixed list to select from but using the same "area" as other related changes could make sense. -Do not forget to use commit --author=... if you commit someone else's work, and -make sure that you have your own user and email setup correctly in git before -you commit. +## Commit message keywords + +Use the following ways to improve the message and provide pointers to related +work. + +- `Follow-up to {shorthash}` - if this fixes or continues a previous commit; + add a `Ref:` that commit's PR or issue if it is not a small, obvious fix; + followed by an empty line + +- `Bug: URL` to the source of the report or more related discussion; use + `Fixes` for GitHub issues instead when that is appropriate. + +- `Approved-by: John Doe` - credit someone who approved the PR. + +- `Authored-by: John Doe` - credit the original author of the code; only use + this if you cannot use `git commit --author=...`. + +- `Signed-off-by: John Doe` - we do not use this, but do not bother removing + it. + +- `whatever-else-by:` credit all helpers, finders, doers; try to use one of + the following keywords if at all possible, for consistency: `Acked-by:`, + `Assisted-by:`, `Co-authored-by:`, `Found-by:`, `Reported-by:`, + `Reviewed-by:`, `Suggested-by:`, `Tested-by:`. + +- `Ref: #1234` - if this is related to a GitHub issue or PR, possibly one that + has already been closed. + +- `Ref: URL` to more information about the commit; use `Bug:` instead for a + reference to a bug on another bug tracker. + +- `Fixes #1234` - if this fixes a GitHub issue; GitHub closes the issue once + this commit is merged. + +- `Closes #1234` - if this merges a GitHub PR; GitHub closes the PR once this + commit is merged. + +Do not forget to use commit with `--author` if you commit someone else's work, +and make sure that you have your own user and email setup correctly in git +before you commit. Add whichever header lines as appropriate, with one line per person if more -than one person was involved. There is no need to credit yourself unless you are -using --author=... which hides your identity. Do not include people's e-mail +than one person was involved. There is no need to credit yourself unless you +are using `--author` which hides your identity. Do not include people's email addresses in headers to avoid spam, unless they are already public from a previous commit; saying `{userid} on github` is OK. -### Write Access to git Repository +## Push Access If you are a frequent contributor, you may be given push access to the git -repository and then you will be able to push your changes straight into the git -repo instead of sending changes as pull requests or by mail as patches. +repository and then you are able to push your changes straight into the git +repository instead of sending changes as pull requests or by mail as patches. -Just ask if this is what you would want. You will be required to have posted -several high quality patches first, before you can be granted push access. +Feel free to ask for this, if this is what you want. You are required to have +posted several high quality patches first, before you can be granted push +access. -### How To Make a Patch with git +## Useful resources -You need to first checkout the repository: +- [Webinar on getting code into curl](https://youtu.be/QmZ3W1d6LQI) - git clone https://github.com/curl/curl.git +# Update copyright and license information -You then proceed and edit all the files you like and you commit them to your -local repository: - - git commit [file] - -As usual, group your commits so that you commit all changes at once that -constitute a logical change. - -Once you have done all your commits and you are happy with what you see, you -can make patches out of your changes that are suitable for mailing: - - git format-patch remotes/origin/master - -This creates files in your local directory named `NNNN-[name].patch` for each -commit. - -Now send those patches off to the curl-library list. You can of course opt to -do that with the 'git send-email' command. - -### How To Make a Patch without git - -Keep a copy of the unmodified curl sources. Make your changes in a separate -source tree. When you think you have something that you want to offer the -curl community, use GNU diff to generate patches. - -If you have modified a single file, try something like: - - diff -u unmodified-file.c my-changed-one.c > my-fixes.diff - -If you have modified several files, possibly in different directories, you -can use diff recursively: - - diff -ur curl-original-dir curl-modified-sources-dir > my-fixes.diff - -The GNU diff and GNU patch tools exist for virtually all platforms, including -all kinds of Unixes and Windows. - -### Useful resources - - [Webinar on getting code into cURL](https://www.youtube.com/watch?v=QmZ3W1d6LQI) - -## Update copyright and license information - -There is a CI job called **REUSE compliance / check** that will run on every -pull request and commit to verify that the *REUSE state* of all files are -still fine. +There is a CI job called **REUSE compliance / check** that runs on every pull +request and commit to verify that the *REUSE state* of all files are still +fine. This means that all files need to have their license and copyright information clearly stated. Ideally by having the standard curl source code header, with -the SPDX-License-Identifier included. If the header does not work, you can use a -smaller header or add the information for a specific file to the `.reuse/dep5` -file. +the `SPDX-License-Identifier` included. If the header does not work, you can +use a smaller header or add the information for a specific file to the +`REUSE.toml` file. You can manually verify the copyright and compliance status by running the -`./scripts/copyright.pl` script in the root of the git repository. +[REUSE helper tool](https://github.com/fsfe/reuse-tool): `reuse lint` + +# On AI use in curl + +Guidelines for AI use when contributing to curl. + +## For security reports and other issues + +If you asked an AI tool to find problems in curl, you **must** make sure to +reveal this fact in your report. + +You must also double-check the findings carefully before reporting them to us +to validate that the issues are indeed existing and working exactly as the AI +says. AI-based tools frequently generate inaccurate or fabricated results. + +Further: it is *rarely* a good idea to copy and paste an AI generated report +to the project. Those generated reports typically are too wordy and rarely to +the point (in addition to the common fabricated details). If you actually find +a problem with an AI and you have verified it yourself to be true: write the +report yourself and explain the problem as you have learned it. This makes +sure the AI-generated inaccuracies and invented issues are filtered out early +before they waste more people's time. + +As we take security reports seriously, we investigate each report with +priority. This work is both time and energy consuming and pulls us away from +doing other meaningful work. Fake and otherwise made up security problems +effectively prevent us from doing real project work and make us waste time and +resources. + +We ban users immediately who submit made up fake reports to the project. + +## For pull requests + +When contributing content to the curl project, you give us permission to use +it as-is and you must make sure you are allowed to distribute it to us. By +submitting a change to us, you agree that the changes can and should be +adopted by curl and get redistributed under the curl license. Authors should +be explicitly aware that the burden is on them to ensure no unlicensed code is +submitted to the project. + +This is independent if AI is used or not. + +When contributing a pull request you should of course always make sure that +the proposal is good quality and a best effort that follows our guidelines. A +basic rule of thumb is that if someone can spot that the contribution was made +with the help of AI, you have more work to do. + +We can accept code written with the help of AI into the project, but the code +must still follow coding standards, be written clearly, be documented, feature +test cases and adhere to all the normal requirements we have. + +## For translation + +Translation services help users write reports, texts and documentation in +non-native languages and we encourage and welcome such contributors and +contributions. + +As AI-based translation tools sometimes have a way to make the output sound a +little robotic and add an "AI tone" to the text, you may want to consider +mentioning that you used such a tool. Failing to do so risks that maintainers +wrongly dismiss translated texts as AI slop. diff --git a/third-party/curl/docs/CURL-DISABLE.md b/third-party/curl/docs/CURL-DISABLE.md index 7978ed2125..a6a1ea1661 100644 --- a/third-party/curl/docs/CURL-DISABLE.md +++ b/third-party/curl/docs/CURL-DISABLE.md @@ -1,3 +1,9 @@ + + # Code defines to disable features and protocols ## `CURL_DISABLE_ALTSVC` @@ -34,7 +40,11 @@ Disable support for the negotiate authentication methods. ## `CURL_DISABLE_AWS` -Disable **AWS-SIG4** support. +Disable **aws-sigv4** support. + +## `CURL_DISABLE_CA_SEARCH` + +Disable unsafe CA bundle search in PATH on Windows. ## `CURL_DISABLE_DICT` @@ -58,8 +68,8 @@ Disable the FTP (and FTPS) protocol ## `CURL_DISABLE_GETOPTIONS` -Disable the `curl_easy_options` API calls that lets users get information -about existing options to `curl_easy_setopt`. +Disable the `curl_easy_options()` API calls that lets users get information +about existing options to `curl_easy_setopt()`. ## `CURL_DISABLE_GOPHER` @@ -110,10 +120,6 @@ Disable MQTT support. Disable the netrc parser. -## `CURL_DISABLE_NTLM` - -Disable support for NTLM. - ## `CURL_DISABLE_OPENSSL_AUTO_LOAD_CONFIG` Disable the auto load config support in the OpenSSL backend. @@ -134,17 +140,26 @@ Disable the built-in progress meter Disable support for proxies +## `CURL_DISABLE_IPFS` + +Disable the IPFS/IPNS protocols. This affects the curl tool only, where +IPFS/IPNS protocol support is implemented. + ## `CURL_DISABLE_RTSP` Disable the RTSP protocol. +## `CURL_DISABLE_SHA512_256` + +Disable the SHA-512/256 hash algorithm. + ## `CURL_DISABLE_SHUFFLE_DNS` Disable the shuffle DNS feature -## `CURL_DISABLE_SMB` +## `CURL_ENABLE_SMB` -Disable the SMB(S) protocols +Enable the SMB(S) protocols ## `CURL_DISABLE_SMTP` @@ -163,6 +178,16 @@ Disable the TELNET protocol Disable the TFTP protocol +## `CURL_DISABLE_TYPECHECK` + +Disable `curl_easy_setopt()`/`curl_easy_getinfo()` type checking. + +Useful to improve build performance for the `tests/libtest` test tool. + ## `CURL_DISABLE_VERBOSE_STRINGS` Disable verbose strings and error messages. + +## `CURL_DISABLE_WEBSOCKETS` + +Disable the WebSocket protocols. diff --git a/third-party/curl/docs/CURLDOWN.md b/third-party/curl/docs/CURLDOWN.md new file mode 100644 index 0000000000..c804eae746 --- /dev/null +++ b/third-party/curl/docs/CURLDOWN.md @@ -0,0 +1,165 @@ + + +# curldown + +A markdown-like syntax for libcurl man pages. + +## Purpose + +A text format for writing libcurl documentation in the shape of man pages. + +Make it easier for users to contribute and write documentation. A format that +is easier on the eye in its source format. + +Make it harder to do syntactical mistakes. + +Use a format that allows creating man pages that end up looking exactly like +the man pages did when we wrote them in nroff format. + +Take advantage of the fact that people these days are accustomed to markdown +by using a markdown-like syntax. + +This allows us to fix issues in the nroff format easier since now we generate +them. For example: escaping minus to prevent them from being turned into +Unicode by man. + +Generate nroff output that looks (next to) *identical* to the previous files, +so that the look, existing test cases, HTML conversions, existing +infrastructure etc remain mostly intact. + +Contains meta-data in a structured way to allow better output (for example the +see also information) and general awareness of what the file is about. + +## File extension + +Since curldown looks similar to markdown, we use `.md` extensions on the +files. + +## Conversion + +Convert **from curldown to nroff** with `cd2nroff`. Generates nroff man pages. + +Convert **from nroff to curldown** with `nroff2cd`. This is only meant to be +used for the initial conversion to curldown and should ideally never be needed +again. + +Convert, check or clean up an existing curldown to nicer, better, cleaner +curldown with **cd2cd**. + +Mass-convert all curldown files to nroff in specified directories with +`cdall`: + + cdall [dir1] [dir2] [dir3] .. + +## Known issues + +The `cd2nroff` tool does not yet handle *italics* or **bold** where the start +and the end markers are used on separate lines. + +The `nroff2cd` tool generates code style quotes for all `.fi` sections since +the nroff format does not carry a distinction. + +# Format + +Each curldown starts with a header with meta-data: + + --- + c: Copyright (C) Daniel Stenberg, , et al. + SPDX-License-Identifier: curl + Title: CURLOPT_AWS_SIGV4 + Section: 3 + Source: libcurl + Protocol: + - HTTP + See-also: + - CURLOPT_HEADEROPT (3) + - CURLOPT_HTTPAUTH (3) + TLS-backend: + - [name] + Added-in: [version or "n/a"] + --- + +All curldown files *must* have all the headers present and at least one +`See-also:` entry specified. + +If the man page is for section 3 (library related). The `Protocol` list must +contain at least one protocol, which can be `*` if the option is virtually for +everything. If `*` is used, it must be the only listed protocol. Recognized +protocols are either URL schemes (in uppercase), `TLS` or `TCP`. + +If the `Protocol` list contains `TLS`, then there must also be a `TLS-backend` +list, specifying `All` or a list of what TLS backends that work with this +option. The available TLS backends are: + +- `GnuTLS` +- `mbedTLS` +- `OpenSSL` (also covers AmiSSL, AWS-LC, BoringSSL, LibreSSL and quictls) +- `rustls` +- `Schannel` +- `wolfSSL` +- `All`: all TLS backends + +Following the header in the file, is the manual page using markdown-like +syntax: + +~~~ + # NAME + a page - this is a page describing something + + # SYNOPSIS + ~~~c + #include + + CURLcode curl_easy_setopt(CURL *handle, CURLOPT_AWS_SIGV4, char *param); + ~~~ +~~~ + +Quoted source code should start with `~~~c` and end with `~~~` while regular +quotes can start with `~~~` or be indented with 4 spaces. + +Headers at top-level `#` get converted to `.SH`. + +`nroff2cd` supports the `##` next level header which gets converted to `.IP`. + +Write bold words or phrases within `**` like: + + This is a **bold** word. + +Write italics like: + + This is *italics*. + +Due to how man pages do not support backticks especially formatted, such +occurrences in the source are instead using italics in the generated output: + + This `word` appears in italics. + +When generating the nroff output, the tooling removes superfluous newlines, +meaning they can be used freely in the source file to make the text more +readable. + +To make sure curldown documents render correctly as markdown, all literal +occurrences of `<` or `>` need to be escaped by a leading backslash. + +## Generating contents + +`# %PROTOCOLS%` - inserts a **PROTOCOLS** section based on the metadata +provided in the header. + +`# %AVAILABILITY%` - inserts an **AVAILABILITY** section based on the metadata +provided in the header. + +## Symbols + +All mentioned curl symbols that have their own man pages, like +`curl_easy_perform(3)` are automatically rendered using italics in the output +without having to enclose it with asterisks. This helps ensuring that they get +converted to links properly later in the HTML version on the website, as +converted with `roffit`. This makes the curldown text easier to read even when +mentioning many curl symbols. + +This auto-linking works for patterns matching `(lib|)curl[^ ]*(3)`. diff --git a/third-party/curl/docs/DEPRECATE.md b/third-party/curl/docs/DEPRECATE.md index 5ea36eb57f..fe00189182 100644 --- a/third-party/curl/docs/DEPRECATE.md +++ b/third-party/curl/docs/DEPRECATE.md @@ -1,3 +1,9 @@ + + # Items to be removed from future curl releases If any of these deprecated features is a cause for concern for you, please @@ -6,43 +12,74 @@ email the as soon as possible and explain to us why this is a problem for you and how your use case cannot be satisfied properly using a workaround. -## mingw v1 +## TLS-SRP Authentication -We remove support for building curl with the original legacy mingw version 1 -in September 2023. +Transport Layer Security Secure Remote Password is a TLS feature that does not +work with TLS 1.3 or QUIC and is virtually unused by curl users and in +general. -During the deprecation period you can enable the support with the configure -option `--with-mingw1-deprecated`. +TLS-SRP support gets removed in August 2026. -mingw version 1 is old and deprecated software. There are much better and -still support build environments to use to build curl and other software. For -example [MinGW-w64](https://www.mingw-w64.org/). +## drop SMB support -## space-separated `NOPROXY` patterns +The SMB protocol has weak security and is rarely used these days. -When specifying patterns/domain names for curl that should *not* go through a -proxy, the curl tool features the `--noproxy` command line option and the -library supports the `NO_PROXY` environment variable and the `CURLOPT_NOPROXY` -libcurl option. +SMB support gets removed in September 2026. -They all set the same list of patterns. This list is documented to be a set of -**comma-separated** names, but can also be provided separated with just -space. The ability to just use spaces for this has never been documented but -some users may still have come to rely on this. +## drop NTLM support -Several other tools and utilities also parse the `NO_PROXY` environment -variable but do not consider a space to be a valid separator. Using spaces for -separator is probably less portable and might cause more friction than commas -do. Users should use commas for this for greater portability. +The NTLM authentication method has weak security and is rarely used these +days. It has been deprecated by Microsoft and does not work over HTTP/2 or +HTTP/3. -curl will remove the support for space-separated names in July 2024. +NTLM support gets removed in September 2026 -## past removals +## Local crypto implementations - - Pipelining - - axTLS - - PolarSSL - - NPN - - Support for systems without 64 bit data types - - NSS - - gskit +Since the dawn of time, curl bundles code for a few crypto and hash algorithms +in order to enable functionality for builds without TLS libraries. This list +includes MD4, MD5, SHA256, SHA256_512 and perhaps something more. + +Meanwhile, curl is almost always built to use a TLS/crypto library which for +sure has better maintained and better performing versions of these algorithms. + +Also, the local curl implementations are not as widely tested since curl +builds without TLS are rare. + +Since these implementations are going away, a good idea is to verify ahead of +time that builds using your preferred TLS library use the crypto functions +provided by that library and are not bundled by curl. + +The removal of local crypto functions subsequently disables some functions in +future curl versions when built without TLS support. For example Digest. + +Local crypto gets removed in October 2026. + +## Past removals + +- axTLS (removed in 7.63.0) +- Pipelining (removed in 7.65.0) +- PolarSSL (removed in 7.69.0) +- NPN (removed in 7.86.0) +- Support for systems without 64-bit data types (removed in 8.0.0) +- NSS (removed in 8.3.0) +- gskit (removed in 8.3.0) +- MinGW v1 (removed in 8.4.0) +- NTLM_WB (removed in 8.8.0) +- space-separated `NOPROXY` patterns (removed in 8.9.0) +- hyper (removed in 8.12.0) +- Support for Visual Studio 2005 and older (removed in 8.13.0) +- Secure Transport (removed in 8.15.0) +- BearSSL (removed in 8.15.0) +- msh3 (removed in 8.16.0) +- winbuild build system (removed in 8.17.0) +- Windows CE (removed in 8.18.0) +- Support for Visual Studio 2008 (removed in 8.18.0) +- OpenSSL 1.1.1 and older (removed in 8.18.0) +- Support for Windows XP (removed in 8.19.0) +- OpenSSL-QUIC (removed in 8.19.0) +- CMake 3.17 and older (removed in 8.20.0) +- RTMP (removed in 8.20.0) +- SMB (became opt-in in 8.20.0) +- NTLM (became opt-in in 8.20.0) +- c-ares < 1.16.0 (removed in 8.20.0) diff --git a/third-party/curl/docs/DISTROS.md b/third-party/curl/docs/DISTROS.md new file mode 100644 index 0000000000..3a433445da --- /dev/null +++ b/third-party/curl/docs/DISTROS.md @@ -0,0 +1,304 @@ + + +# curl distros + + + +Lots of organizations distribute curl packages to end users. This is a +collection of pointers to where to learn more about curl on and with each +distro. Those marked *Rolling Release* typically run the latest version of curl +and are therefore less likely to have back-ported patches to older versions. + +We discuss curl distro issues, patches and collaboration on the [curl-distros +mailing list](https://lists.haxx.se/listinfo/curl-distros) ([list +archives](https://curl.se/mail/list.cgi?list=curl-distros)). + +## AlmaLinux + +- curl package source and patches: https://git.almalinux.org/rpms/curl/ +- curl issues: https://bugs.almalinux.org/view_all_bug_page.php click Category and choose curl +- curl security: https://errata.almalinux.org/ search for curl + +## Alpine Linux + +- curl: https://pkgs.alpinelinux.org/package/edge/main/x86_64/curl +- curl issues: https://gitlab.alpinelinux.org/alpine/aports/-/issues +- curl security: https://security.alpinelinux.org/srcpkg/curl +- curl package source and patches: https://gitlab.alpinelinux.org/alpine/aports/-/tree/master/main/curl + +## Alt Linux + +- curl: https://packages.altlinux.org/en/search/?q=curl +- curl issues: https://packages.altlinux.org/en/sisyphus/srpms/curl/issues/ +- curl patches: https://git.altlinux.org/gears/c/curl.git?p=curl.git;a=tree;f=.gear + +## Arch Linux + +*Rolling Release* + +- curl: https://archlinux.org/packages/core/x86_64/curl/ +- curl issues: https://gitlab.archlinux.org/archlinux/packaging/packages/curl/-/issues +- curl security: https://security.archlinux.org/package/curl +- curl wiki: https://wiki.archlinux.org/title/CURL + +## Buildroot + +*Rolling Release* + +- curl package source and patches: **missing URL** +- curl issues: **missing URL** + +## Chimera + +- curl package source and patches: https://github.com/chimera-linux/cports/tree/master/main/curl + +## Clear Linux + +*Rolling Release* + +- curl: https://github.com/clearlinux-pkgs/curl +- curl issues: https://github.com/clearlinux/distribution/issues + +## Conary + +- curl: https://github.com/conan-io/conan-center-index/tree/master/recipes/libcurl +- curl issues: https://github.com/conan-io/conan-center-index/issues +- curl patches: https://github.com/conan-io/conan-center-index/tree/master/recipes/libcurl (in `all/patches/*`, if any) + +## conda-forge + +- curl: https://github.com/conda-forge/curl-feedstock +- curl issues: https://github.com/conda-forge/curl-feedstock/issues + +## CRUX + +- curl: https://crux.nu/portdb/?a=search&q=curl +- curl issues: https://git.crux.nu/ports/core/issues/?type=all&state=open&q=curl + +## curl-for-win + +(this is the official curl binaries for Windows shipped by the curl project) + +*Rolling Release* + +- curl: https://curl.se/windows/ +- curl patches: https://github.com/curl/curl-for-win/blob/main/curl.patch (if any) +- build-specific issues: https://github.com/curl/curl-for-win/issues + +Issues and patches for this are managed in the main curl project. + +## Cygwin + +- curl: https://cygwin.com/cgit/cygwin-packages/curl/tree/curl.cygport +- curl patches: https://cygwin.com/cgit/cygwin-packages/curl/tree +- curl issues: https://inbox.sourceware.org/cygwin/?q=s%3Acurl + +## Cygwin (cross mingw64) + +- mingw64-x86_64-curl: https://cygwin.com/cgit/cygwin-packages/mingw64-x86_64-curl/tree/mingw64-x86_64-curl.cygport +- mingw64-x86_64-curl patches: https://cygwin.com/cgit/cygwin-packages/mingw64-x86_64-curl/tree +- mingw64-x86_64-curl issues: https://inbox.sourceware.org/cygwin/?q=s%3Amingw64-x86_64-curl + +## Debian + +- curl: https://tracker.debian.org/pkg/curl +- curl issues: https://bugs.debian.org/cgi-bin/pkgreport.cgi?pkg=curl +- curl patches: https://udd.debian.org/patches.cgi?src=curl +- curl patches: https://salsa.debian.org/debian/curl (in debian/* branches, inside the folder debian/patches) + +## Fedora + +- curl: https://src.fedoraproject.org/rpms/curl +- curl issues: [bugzilla](https://bugzilla.redhat.com/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&classification=Fedora&product=Fedora&product=Fedora%20EPEL&component=curl) +- curl patches: [list of patches in package git](https://src.fedoraproject.org/rpms/curl/tree/rawhide) + +## FreeBSD + +- curl: https://cgit.freebsd.org/ports/tree/ftp/curl +- curl patches: https://cgit.freebsd.org/ports/tree/ftp/curl +- curl issues: https://bugs.freebsd.org/bugzilla/buglist.cgi?bug_status=__open__&order=Importance&product=Ports%20%26%20Packages&query_format=advanced&short_desc=curl&short_desc_type=allwordssubstr + +## Gentoo Linux + +*Rolling Release* + +- curl: https://packages.gentoo.org/packages/net-misc/curl +- curl issues: https://bugs.gentoo.org/buglist.cgi?quicksearch=net-misc/curl +- curl package sources and patches: https://gitweb.gentoo.org/repo/gentoo.git/tree/net-misc/curl/ + +## GNU Guix + +*Rolling Release* + +- curl: https://git.savannah.gnu.org/gitweb/?p=guix.git;a=blob;f=gnu/packages/curl.scm;hb=HEAD +- curl issues: https://issues.guix.gnu.org/search?query=curl + +## Haiku + +- curl: https://github.com/haikuports/haikuports/tree/master/net-misc/curl +- curl issues: https://github.com/haikuports/haikuports/issues +- curl patches: https://github.com/haikuports/haikuports/tree/master/net-misc/curl/patches (if any) + +## Homebrew + +*Rolling Release* + +- curl: https://formulae.brew.sh/formula/curl + +Homebrew's policy is that all patches and issues should be submitted upstream +unless it is specific to Homebrew's way of packaging software. + +## LibreELEC + +- curl: https://github.com/LibreELEC/LibreELEC.tv/blob/master/packages/web/curl/ +- curl issues: https://github.com/LibreELEC/LibreELEC.tv/issues?q=is%3Aissue%20state%3Aopen%20curl +- curl patches: https://github.com/LibreELEC/LibreELEC.tv/blob/master/packages/web/curl/patches/ + +## MacPorts + +*Rolling Release* + +- curl: https://github.com/macports/macports-ports/tree/master/net/curl +- curl issues: https://trac.macports.org/query?0_port=curl&0_port_mode=%7E&0_status=%21closed +- curl patches: https://github.com/macports/macports-ports/tree/master/net/curl/files + +## Mageia + +- curl: https://svnweb.mageia.org/packages/cauldron/curl/current/SPECS/curl.spec?view=markup +- curl issues: https://bugs.mageia.org/buglist.cgi?bug_status=NEW&bug_status=UNCONFIRMED&bug_status=NEEDINFO&bug_status=UPSTREAM&bug_status=ASSIGNED&component=RPM%20Packages&f1=cf_rpmpkg&list_id=176576&o1=casesubstring&product=Mageia&query_format=advanced&v1=curl +- curl patches: https://svnweb.mageia.org/packages/cauldron/curl/current/SOURCES/ +- curl patches in stable distro releases: https://svnweb.mageia.org/packages/updates/9/curl/current/SOURCES/ +- curl security: https://advisories.mageia.org/src_curl.html + +## MSYS2 + +*Rolling Release* + +- curl: https://github.com/msys2/MSYS2-packages/tree/master/curl +- curl issues: https://github.com/msys2/MSYS2-packages/issues +- curl patches: https://github.com/msys2/MSYS2-packages/tree/master/curl (`*.patch`) + +## MSYS2 (mingw-w64) + +*Rolling Release* + +- curl: https://github.com/msys2/MINGW-packages/tree/master/mingw-w64-curl +- curl issues: https://github.com/msys2/MINGW-packages/issues +- curl patches: https://github.com/msys2/MINGW-packages/tree/master/mingw-w64-curl (`*.patch`) + +## Muldersoft + +*Rolling Release* + +- curl: https://github.com/lordmulder/curl-build-win32 +- curl issues: https://github.com/lordmulder/curl-build-win32/issues +- curl patches: https://github.com/lordmulder/curl-build-win32/tree/master/patch + +## NixOS + +- curl: https://github.com/NixOS/nixpkgs/blob/nixos-unstable/pkgs/by-name/cu/curlMinimal/package.nix +- curl issues: https://github.com/NixOS/nixpkgs + +nixpkgs is the package repository used by the NixOS Linux distribution, but +can also be used on other distributions + +## OmniOS + +- curl: https://github.com/omniosorg/omnios-build/tree/master/build/curl +- curl issues: https://github.com/omniosorg/omnios-build/issues +- curl patches: https://github.com/omniosorg/omnios-build/tree/master/build/curl/patches + +## OpenIndiana + +- curl: https://github.com/OpenIndiana/oi-userland/tree/oi/hipster/components/web/curl +- curl issues: https://www.illumos.org/projects/openindiana/issues +- curl patches: https://github.com/OpenIndiana/oi-userland/tree/oi/hipster/components/web/curl/patches + +## OpenSUSE + +- curl source and patches: https://build.opensuse.org/package/show/openSUSE%3AFactory/curl + +## Oracle Solaris + +- curl: https://github.com/oracle/solaris-userland/tree/master/components/curl +- curl issues: https://support.oracle.com/ (requires support contract) +- curl patches: https://github.com/oracle/solaris-userland/tree/master/components/curl/patches + +## OpenBSD + +- curl: https://github.com/openbsd/ports/tree/master/net/curl +- curl issues: https://www.openbsd.org/mail.html (ports mailing list) +- curl patches: https://github.com/openbsd/ports/tree/master/net/curl/patches + +## OpenEmbedded / Yocto Project + +*Rolling Release* + +- curl: https://layers.openembedded.org/layerindex/recipe/5765/ +- curl issues: https://bugzilla.yoctoproject.org/ +- curl patches: https://git.openembedded.org/openembedded-core/tree/meta/recipes-support/curl + +## PLD Linux + +- curl package source and patches: https://github.com/pld-linux/curl +- curl issues: https://bugs.launchpad.net/pld-linux?field.searchtext=curl&search=Search&field.status%3Alist=NEW&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.status%3Alist=CONFIRMED&field.status%3Alist=TRIAGED&field.status%3Alist=INPROGRESS&field.status%3Alist=FIXCOMMITTED&field.assignee=&field.bug_reporter=&field.omit_dupes=on&field.has_patch=&field.has_no_package= + +## pkgsrc + +- curl: https://github.com/NetBSD/pkgsrc/tree/trunk/www/curl +- curl issues: https://github.com/NetBSD/pkgsrc/issues +- curl patches: https://github.com/NetBSD/pkgsrc/tree/trunk/www/curl/patches + +## Red Hat Enterprise Linux / CentOS Stream + +- curl: https://kojihub.stream.centos.org/koji/packageinfo?packageID=217 +- curl issues: https://issues.redhat.com/secure/CreateIssueDetails!init.jspa?pid=12332745&issuetype=1&components=12377466&priority=10300 +- curl patches: https://gitlab.com/redhat/centos-stream/rpms/curl + +## Rocky Linux + +- curl: https://git.rockylinux.org/staging/rpms/curl/-/blob/r9/SPECS/curl.spec +- curl issues: https://bugs.rockylinux.org/ +- curl patches: https://git.rockylinux.org/staging/rpms/curl/-/tree/r9/SOURCES + +## SerenityOS + +- curl: https://github.com/SerenityOS/serenity/tree/master/Ports/curl +- curl issues: https://github.com/SerenityOS/serenity/issues?q=label%3Aports +- curl patches: https://github.com/SerenityOS/serenity/tree/master/Ports/curl/patches + +## SmartOS + +- curl: https://github.com/TritonDataCenter/illumos-extra/tree/master/curl +- curl issues: https://github.com/TritonDataCenter/illumos-extra/issues +- curl patches: https://github.com/TritonDataCenter/illumos-extra/tree/master/curl/Patches + +## SPACK + +- curl package source and patches: https://github.com/spack/spack/tree/develop/var/spack/repos/builtin/packages/curl + +## vcpkg + +*Rolling Release* + +- curl: https://github.com/microsoft/vcpkg/tree/master/ports/curl +- curl issues: https://github.com/microsoft/vcpkg/issues +- curl patches: https://github.com/microsoft/vcpkg/tree/master/ports/curl (`*.patch`) + +## Void Linux + +*Rolling Release* + +- curl: https://github.com/void-linux/void-packages/tree/master/srcpkgs/curl +- curl issues: https://github.com/void-linux/void-packages/issues +- curl patches: https://github.com/void-linux/void-packages/tree/master/srcpkgs/curl/patches + +## Wolfi + +*Rolling Release* + +- curl: https://github.com/wolfi-dev/os/blob/main/curl.yaml diff --git a/third-party/curl/docs/DYNBUF.md b/third-party/curl/docs/DYNBUF.md deleted file mode 100644 index c3a4b76679..0000000000 --- a/third-party/curl/docs/DYNBUF.md +++ /dev/null @@ -1,128 +0,0 @@ -# dynbuf - -This is the internal module for creating and handling "dynamic buffers". This -means buffers that can be appended to, dynamically and grow to adapt. - -There will always be a terminating zero put at the end of the dynamic buffer. - -The `struct dynbuf` is used to hold data for each instance of a dynamic -buffer. The members of that struct **MUST NOT** be accessed or modified -without using the dedicated dynbuf API. - -## `Curl_dyn_init` - -```c -void Curl_dyn_init(struct dynbuf *s, size_t toobig); -``` - -This initializes a struct to use for dynbuf and it cannot fail. The `toobig` -value **must** be set to the maximum size we allow this buffer instance to -grow to. The functions below will return `CURLE_OUT_OF_MEMORY` when hitting -this limit. - -## `Curl_dyn_free` - -```c -void Curl_dyn_free(struct dynbuf *s); -``` - -Free the associated memory and clean up. After a free, the `dynbuf` struct can -be reused to start appending new data to. - -## `Curl_dyn_addn` - -```c -CURLcode Curl_dyn_addn(struct dynbuf *s, const void *mem, size_t len); -``` - -Append arbitrary data of a given length to the end of the buffer. - -If this function fails it calls `Curl_dyn_free` on `dynbuf`. - -## `Curl_dyn_add` - -```c -CURLcode Curl_dyn_add(struct dynbuf *s, const char *str); -``` - -Append a C string to the end of the buffer. - -If this function fails it calls `Curl_dyn_free` on `dynbuf`. - -## `Curl_dyn_addf` - -```c -CURLcode Curl_dyn_addf(struct dynbuf *s, const char *fmt, ...); -``` - -Append a `printf()`-style string to the end of the buffer. - -If this function fails it calls `Curl_dyn_free` on `dynbuf`. - -## `Curl_dyn_vaddf` - -```c -CURLcode Curl_dyn_vaddf(struct dynbuf *s, const char *fmt, va_list ap); -``` - -Append a `vprintf()`-style string to the end of the buffer. - -If this function fails it calls `Curl_dyn_free` on `dynbuf`. - -## `Curl_dyn_reset` - -```c -void Curl_dyn_reset(struct dynbuf *s); -``` - -Reset the buffer length, but leave the allocation. - -## `Curl_dyn_tail` - -```c -CURLcode Curl_dyn_tail(struct dynbuf *s, size_t length); -``` - -Keep `length` bytes of the buffer tail (the last `length` bytes of the -buffer). The rest of the buffer is dropped. The specified `length` must not be -larger than the buffer length. To instead keep the leading part, see -`Curl_dyn_setlen()`. - -## `Curl_dyn_ptr` - -```c -char *Curl_dyn_ptr(const struct dynbuf *s); -``` - -Returns a `char *` to the buffer if it has a length, otherwise may return -NULL. Since the buffer may be reallocated, this pointer should not be trusted -or used anymore after the next buffer manipulation call. - -## `Curl_dyn_uptr` - -```c -unsigned char *Curl_dyn_uptr(const struct dynbuf *s); -``` - -Returns an `unsigned char *` to the buffer if it has a length, otherwise may -return NULL. Since the buffer may be reallocated, this pointer should not be -trusted or used anymore after the next buffer manipulation call. - -## `Curl_dyn_len` - -```c -size_t Curl_dyn_len(const struct dynbuf *s); -``` - -Returns the length of the buffer in bytes. Does not include the terminating -zero byte. - -## `Curl_dyn_setlen` - -```c -CURLcode Curl_dyn_setlen(struct dynbuf *s, size_t len); -``` - -Sets the new shorter length of the buffer in number of bytes. Keeps the -leftmost set number of bytes, discards the rest. To instead keep the tail part -of the buffer, see `Curl_dyn_tail()`. diff --git a/third-party/curl/docs/EARLY-RELEASE.md b/third-party/curl/docs/EARLY-RELEASE.md index 6d5a5e25b4..8ec74c3e20 100644 --- a/third-party/curl/docs/EARLY-RELEASE.md +++ b/third-party/curl/docs/EARLY-RELEASE.md @@ -1,3 +1,9 @@ + + # How to determine if an early patch release is warranted In the curl project we do releases every 8 weeks. Unless we break the cycle @@ -21,14 +27,14 @@ in the git master branch. An early patch release means that we ship a new, complete and full release called `major.minor.patch` where the `patch` part is increased by one since the previous release. A curl release is a curl release. There is no small or -big and we never release just a patch. There is only "release". +big and we never ship stand-alone separate patches. There is only "release". ## Questions to ask - - Is there a security advisory rated high or critical? - - Is there a data corruption bug? - - Did the bug cause an API/ABI breakage? - - Will the problem annoy a significant share of the user population? +- Is there a security advisory rated high or critical? +- Is there a data corruption bug? +- Did the bug cause an API/ABI breakage? +- Does the problem annoy a significant share of the user population? If the answer is yes to one or more of the above, an early release might be warranted. @@ -36,25 +42,25 @@ warranted. More questions to ask ourselves when doing the assessment if the answers to the three ones above are all 'no'. - - Does the bug cause curl to prematurely terminate? - - How common is the affected buggy option/feature/protocol/platform to get - used? - - How large is the estimated impacted user base? - - Does the bug block something crucial for applications or other adoption of - curl "out there" ? - - Does the bug cause problems for curl developers or others on "the curl - team" ? - - Is the bug limited to the curl tool only? That might have a smaller impact - than a bug also present in libcurl. - - Is there a (decent) workaround? - - Is it a regression? Is the bug introduced in this release? - - Can the bug be fixed "easily" by applying a patch? - - Does the bug break the build? Most users do not build curl themselves. - - How long is it until the already scheduled next release? - - Can affected users safely rather revert to a former release until the next - scheduled release? - - Is it a performance regression with no functionality side-effects? If so it - has to be substantial. +- Does the bug cause curl to prematurely terminate? +- How common is the affected buggy option/feature/protocol/platform to get + used? +- How large is the estimated impacted user base? +- Does the bug block something crucial for applications or other adoption of + curl "out there" ? +- Does the bug cause problems for curl developers or others on "the curl + team" ? +- Is the bug limited to the curl tool only? That might have a smaller impact + than a bug also present in libcurl. +- Is there a (decent) workaround? +- Is it a regression? Is the bug introduced in this release? +- Can the bug be fixed "easily" by applying a patch? +- Does the bug break the build? Most users do not build curl themselves. +- How long is it until the already scheduled next release? +- Can affected users safely rather revert to a former release until the next + scheduled release? +- Is it a performance regression with no functionality side-effects? If so it + has to be substantial. ## If an early release is deemed necessary diff --git a/third-party/curl/docs/ECH.md b/third-party/curl/docs/ECH.md new file mode 100644 index 0000000000..8a0153209d --- /dev/null +++ b/third-party/curl/docs/ECH.md @@ -0,0 +1,492 @@ + + +# Building curl with HTTPS-RR and ECH support + +We have added support for ECH to curl. It can use HTTPS RRs published in the +DNS if curl uses DoH, or else can accept the relevant ECHConfigList values +from the command line. This works with AWS-LC, BoringSSL, OpenSSL, Rustls or +wolfSSL as the TLS provider. + +This feature is EXPERIMENTAL. DO NOT USE IN PRODUCTION. + +This should however provide enough of a proof-of-concept to prompt an informed +discussion about a good path forward for ECH support in curl. + +## OpenSSL Build + +To build OpenSSL 4.0.0+: + +```sh +cd $HOME/code +git clone --depth 1 --branch openssl-4.0.0 https://github.com/openssl/openssl +cd openssl +./config --libdir=lib --prefix=$HOME/code/openssl-local-inst +...stuff... +make -j8 +...more stuff... +make install_sw +...a little bit of stuff... +``` + +To build curl ECH-enabled, making use of the above: + +```sh +cd $HOME/code +git clone --depth 1 https://github.com/curl/curl +cd curl +autoreconf -fi +LDFLAGS="-Wl,-rpath,$HOME/code/openssl-local-inst/lib/" ./configure --with-ssl=$HOME/code/openssl-local-inst --enable-ech +...lots of output... +WARNING: ECH is enabled but marked EXPERIMENTAL... +make +...lots more output... +``` + +If you do not get that WARNING at the end of the `configure` command, then +ECH is not enabled, so go back some steps and re-do whatever needs re-doing:-) +If you want to debug curl then you should add `--enable-debug` to the +`configure` command. + +In a recent (2024-05-20) build on one machine, configure failed to find the +ECH-enabled SSL library, apparently due to the existence of +`$HOME/code/openssl-local-inst/lib/pkgconfig` as a directory containing +various settings. Deleting that directory worked around the problem but may +not be the best solution. + +## Using ECH and DoH + +curl supports using DoH for A/AAAA lookups so it was relatively easy to add +retrieval of HTTPS RRs in that situation. To use ECH and DoH together: + +```sh +cd $HOME/code/curl +LD_LIBRARY_PATH=$HOME/code/openssl ./src/curl --ech true --doh-url https://one.one.one.one/dns-query https://defo.ie/ech-check.php +... +SSL_ECH_STATUS: success good
+... +``` + +The output snippet above is within the HTML for the webpage, when things work. + +The above works for these test sites: + +```sh +https://defo.ie/ech-check.php +https://crypto.cloudflare.com/cdn-cgi/trace +https://tls-ech.dev/ +``` + +The list above has 4 different server technologies, implemented by 3 different +parties, and includes a case (the port 8414 server) where HelloRetryRequest +(HRR) is forced. + +We currently support the following new curl command line arguments/options: + +- `--ech ` - the `config` value can be one of: + - `false` says to not attempt ECH + - `true` says to attempt ECH, if possible + - `grease` if attempting ECH is not possible, then send a GREASE ECH extension + - `hard` hard-fail the connection if ECH cannot be attempted + - `ecl:` a base64 encoded ECHConfigList, rather than one accessed from the DNS + - `pn:` override the `public_name` from an ECHConfigList + +Note that in the above "attempt ECH" means the client emitting a TLS +ClientHello with a "real" ECH extension, but that does not mean that the +relevant server can succeed in decrypting, as things can fail for other +reasons. + +## Supplying an ECHConfigList on the command line + +To supply the ECHConfigList on the command line, you might need a bit of +cut-and-paste, e.g.: + +```sh +dig +short https defo.ie +1 . ipv4hint=213.108.108.101 ech=AED+DQA8PAAgACD8WhlS7VwEt5bf3lekhHvXrQBGDrZh03n/LsNtAodbUAAEAAEAAQANY292ZXIuZGVmby5pZQAA + ipv6hint=2a00:c6c0:0:116:5::10 +``` + +Then paste the base64 encoded ECHConfigList onto the curl command line: + +```sh +LD_LIBRARY_PATH=$HOME/code/openssl ./src/curl --ech ecl:AED+DQA8PAAgACD8WhlS7VwEt5bf3lekhHvXrQBGDrZh03n/LsNtAodbUAAEAAEAAQANY292ZXIuZGVmby5pZQAA \ + https://defo.ie/ech-check.php +... +SSL_ECH_STATUS: success good
+... +``` + +The output snippet above is within the HTML for the webpage. + +If you paste in the wrong ECHConfigList (it changes hourly for `defo.ie`) you +should get an error like this: + +```sh +LD_LIBRARY_PATH=$HOME/code/openssl ./src/curl -vvv --ech ecl:AED+DQA8yAAgACDRMQo+qYNsNRNj+vfuQfFIkrrUFmM4vogucxKj/4nzYgAEAAEAAQANY292ZXIuZGVmby5pZQAA \ + https://defo.ie/ech-check.php +... +* OpenSSL/3.3.0: error:0A00054B:SSL routines::ech required +... +``` + +There is a reason to want this command line option - for use before publishing +an ECHConfigList in the DNS as per the Internet-draft [A well-known URI for +publishing ECHConfigList values](https://datatracker.ietf.org/doc/html/draft-ietf-tls-wkech/). + +If you do use a wrong ECHConfigList value, then the server might return a +good value, via the `retry_configs` mechanism. You can see that value in +the verbose output, e.g.: + +```sh +LD_LIBRARY_PATH=$HOME/code/openssl ./src/curl -vvv --ech ecl:AED+DQA8yAAgACDRMQo+qYNsNRNj+vfuQfFIkrrUFmM4vogucxKj/4nzYgAEAAEAAQANY292ZXIuZGVmby5pZQAA \ + https://defo.ie/ech-check.php +... +* ECH: retry_configs AQD+DQA8DAAgACBvYqJy+Hgk33wh/ZLBzKSPgwxeop7gvojQzfASq7zeZQAEAAEAAQANY292ZXIuZGVmby5pZQAA/g0APEMAIAAgXkT5r4cYs8z19q5rdittyIX + 8gfQ3ENW4wj1fVoiJZBoABAABAAEADWNvdmVyLmRlZm8uaWUAAP4NADw2ACAAINXSE9EdXzEQIJZA7vpwCIQsWqsFohZARXChgPsnfI1kAAQAAQABAA1jb3Zlci5kZWZvLmllAAD+DQA8c + QAgACASeiD5F+UoSnVoHvA2l1EifUVMFtbVZ76xwDqmMPraHQAEAAEAAQANY292ZXIuZGVmby5pZQAA +* ECH: retry_configs for defo.ie from cover.defo.ie, 319 +... +``` + +At that point, you could copy the base64 encoded value above and try again. +For now, this only works for the OpenSSL and AWS-LC/BoringSSL builds. + +## Default settings + +curl has various ways to configure default settings, e.g. in `$HOME/.curlrc`, +so one can set the DoH URL and enable ECH that way: + +```sh +cat ~/.curlrc +doh-url=https://one.one.one.one/dns-query +silent +ech=true +``` + +Note that when you use the system's curl command (rather than our ECH-enabled +build), it is liable to warn that `ech` is an unknown option. If that is an +issue (e.g. if some script re-directs stdout and stderr somewhere) then adding +the `silent` line above seems to be a good enough fix. (Though of +course, yet another script could depend on non-silent behavior, so you may have +to figure out what you prefer yourself.) That seems to have changed with the +latest build, previously `silent=TRUE` was what I used in `~/.curlrc` but +now that seems to cause a problem, so that the following line(s) are ignored. + +If you want to always use our OpenSSL build you can set `LD_LIBRARY_PATH` +in the environment: + +```sh +export LD_LIBRARY_PATH=$HOME/code/openssl +``` + +When you do the above, there can be a mismatch between OpenSSL versions +for applications that check that. A `git push` for example fails so you +should unset `LD_LIBRARY_PATH` before doing that or use a different shell. + +```sh +git push +OpenSSL version mismatch. Built against 30000080, you have 30200000 +... +``` + +With all that setup as above the command line gets simpler: + +```sh +./src/curl https://defo.ie/ech-check.php +... +SSL_ECH_STATUS: success good
+... +``` + +The `--ech true` option is opportunistic, so tries to do ECH but does not fail if +the client for example cannot find any ECHConfig values. The `--ech hard` +option hard-fails if there is no ECHConfig found in DNS, so for now, that is not +a good option to set as a default. Once ECH has really been attempted by +the client, if decryption on the server side fails, then curl fails. + +## Code changes for ECH support when using DoH + +Code changes are `#ifdef` protected via `USE_ECH` or `USE_HTTPSRR`: + +- `USE_HTTPSRR` is used for HTTPS RR retrieval code that could be generically + used should non-ECH uses for HTTPS RRs be identified, e.g. use of ALPN values + or IP address hints. + +- `USE_ECH` protects ECH specific code. + +There are various obvious code blocks for handling the new command line +arguments which are not described here, but should be fairly clear. + +As shown in the `configure` usage above, there are `configure.ac` changes +that allow separately dis/enabling `USE_HTTPSRR` and `USE_ECH`. If `USE_ECH` +is enabled, then `USE_HTTPSRR` is forced. In both cases `CURL_DISABLE_DOH` +must not be enabled. (There may be some configuration conflicts available for the +determined :-) + +The main functional change, as you would expect, is in `lib/vtls/openssl.c` +where an ECHConfig, if available from command line or DNS cache, is fed into +the OpenSSL library via the new APIs implemented in our OpenSSL fork for that +purpose. This code also implements the opportunistic (`--ech true`) or hard-fail +(`--ech hard`) logic. + +Other than that, the main additions are in `lib/doh.c` +where we reuse `dohprobe()` to retrieve an HTTPS RR value for the target +domain. If such a value is found, that is stored using a new `doh_store_https()` +function in a new field in the `dohentry` structure. + +The qname for the DoH query is modified if the port number is not 443, as +defined in the SVCB specification. + +When the DoH process has worked, `Curl_doh_take_result()` now also returns +the relevant HTTPS RR value data in the `Curl_dns_entry` structure. +That is later accessed when the TLS session is being established, if ECH is +enabled (from `lib/vtls/openssl.c` as described above). + +## Limitations + +Things that need fixing, but that can probably be ignored for the +moment: + +- We could easily add code to make use of an `alpn=` value found in an HTTPS + RR, passing that on to OpenSSL for use as the "inner" ALPN value, but have + yet to do that. + +Current limitations (more interesting than the above): + +- Only the first HTTPS RR value retrieved is actually processed as described + above, that could be extended in future, though picking the "right" HTTPS RR + could be non-trivial if multiple RRs are published - matching IP address + hints versus A/AAAA values might be a good basis for that. Last I checked + though, browsers supporting ECH did not handle multiple HTTPS RRs well, though + that needs re-checking as it has been a while. + +- It is unclear how one should handle any IP address hints found in an HTTPS RR. + It may be that a bit of consideration of how "multi-CDN" deployments might + emerge would provide good answers there, but for now, it is not clear how best + curl might handle those values when present in the DNS. + +- The SVCB/HTTPS RR specification supports a new "CNAME at apex" indirection + ("aliasMode") - the current code takes no account of that at all. One could + envisage implementing the equivalent of following CNAMEs in such cases, but + it is not clear if that'd be a good plan. (As of now, chrome browsers do not + seem to have any support for that "aliasMode" and we have not checked Firefox + for that recently.) + +- We have not investigated what related changes or additions might be needed + for applications using libcurl, as opposed to use of curl as a command line + tool. + +- We have not yet implemented tests as part of the usual curl test harness as + doing so would seem to require re-implementing an ECH-enabled server as part + of the curl test harness. For now, we have a `./tests/ech_test.sh` script + that attempts ECH with various test servers and with many combinations of the + allowed command line options. While that is a useful test and has find + issues, it is not comprehensive and we are not (as yet) sure what would be + the right level of coverage. When running that script you should not have a + `$HOME/.curlrc` file that affects ECH or some of the negative tests could + produce spurious failures. + +## Building with cmake + +To build with cmake, assuming our ECH-enabled OpenSSL is as before: + +```sh +cd $HOME/code +git clone --depth 1 https://github.com/curl/curl +cd curl +mkdir build +cd build +cmake -DOPENSSL_ROOT_DIR=$HOME/code/openssl -DUSE_ECH=1 .. +... +make +... +[100%] Built target curl +``` + +The binary produced by the cmake build does not need any ECH-specific +`LD_LIBRARY_PATH` setting. + +## BoringSSL build + +BoringSSL is also supported by curl and also supports ECH, so to build +with that, instead of our ECH-enabled OpenSSL: + +```sh +cd $HOME/code +git clone --depth 1 https://boringssl.googlesource.com/boringssl +cd boringssl +cmake -DCMAKE_INSTALL_PREFIX:PATH=$HOME/code/boringssl/inst -DBUILD_SHARED_LIBS=1 +make +... +make install +``` + +Then: + +```sh +cd $HOME/code +git clone --depth 1 https://github.com/curl/curl +cd curl +autoreconf -fi +LDFLAGS="-Wl,-rpath,$HOME/code/boringssl/inst/lib" ./configure --with-ssl=$HOME/code/boringssl/inst --enable-ech +...lots of output... +WARNING: ECH HTTPSRR enabled but marked EXPERIMENTAL. Use with caution. +make +``` + +The AWS-LC/BoringSSL APIs are fairly similar to those in our ECH-enabled +OpenSSL fork, so code changes are also in `lib/vtls/openssl.c`, protected +via `#ifdef OPENSSL_IS_BORINGSSL` and are mostly obvious API variations. + +The AWS-LC/BoringSSL APIs however do not support the `--ech pn:` command +line variant as of now. + +## wolfSSL build + +wolfSSL also supports ECH and can be used by curl, so here's how: + +```sh +cd $HOME/code +git clone --depth 1 https://github.com/wolfSSL/wolfssl +cd wolfssl +./autogen.sh +./configure --prefix=$HOME/code/wolfssl/inst --enable-ech --enable-debug --enable-opensslextra +make +make install +``` + +The install prefix (`inst`) in the above causes wolfSSL to be installed there +and we seem to need that for the curl configure command to work out. The +`--enable-opensslextra` turns out (after much faffing about;-) to be +important or else we get build problems with curl below. + +```sh +cd $HOME/code +git clone --depth 1 https://github.com/curl/curl +cd curl +autoreconf -fi +./configure --with-wolfssl=$HOME/code/wolfssl/inst --enable-ech +make +``` + +There are some known issues with the ECH implementation in wolfSSL: + +- The main issue is that the client currently handles HelloRetryRequest + incorrectly. [HRR issue](https://github.com/wolfSSL/wolfssl/issues/6802).) + The HRR issue means that the client does not work for + [this ECH test web site](https://tls-ech.dev/) and any other similarly + configured sites. +- There is also an issue related to so-called middlebox compatibility mode. + [middlebox compatibility issue](https://github.com/wolfSSL/wolfssl/issues/6774) + +### Code changes to support wolfSSL + +There are what seem like oddball differences: + +- The DoH URL in`$HOME/.curlrc` can use `1.1.1.1` for OpenSSL but has to be + `one.one.one.one` for wolfSSL. The latter works for both, so OK, we us that. +- There seems to be some difference in CA databases too - the wolfSSL version + does not like `defo.ie`, whereas the system and OpenSSL ones do. We can + ignore that for our purposes via `--insecure`/`-k` but would need to fix + for a real setup. (Browsers do like those certificates though.) + +Then there are some functional code changes: + +- tweak to `configure.ac` to check if wolfSSL has ECH or not +- added code to `lib/vtls/wolfssl.c` mirroring what's done in the + OpenSSL equivalent above. +- wolfSSL does not support `--ech false` or the `--ech pn:` command line + argument. + +The lack of support for `--ech false` is because wolfSSL has decided to +always at least GREASE if built to support ECH. In other words, GREASE is +a compile time choice for wolfSSL, but a runtime choice for OpenSSL or +AWS-LC/BoringSSL. (Both are reasonable.) + +## Additional notes + +### Supporting ECH without DoH + +All of the above only applies if DoH is being used. There should be a use-case +for ECH when DoH is not used by curl - if a system stub resolver supports DoT +or DoH, then, considering only ECH and the network threat model, it would make +sense for curl to support ECH without curl itself using DoH. The author for +example uses a combination of stubby+unbound as the system resolver listening +on localhost:53, so would fit this use-case. That said, it is unclear if this +is a niche that is worth trying to address. (The author is happy to let curl +use DoH to talk to the same public recursive that stubby might use:-) + +Assuming for the moment this is a use-case we would like to support, then if +DoH is not being used by curl, it is not clear at this time how to provide +support for ECH. One option would seem to be to extend the `c-ares` library +to support HTTPS RRs, but in that case it is not now clear whether such +changes would be attractive to the `c-ares` maintainers, nor whether the +"tag=value" extensibility inherent in the HTTPS/SVCB specification is a good +match for the `c-ares` approach of defining structures specific to decoded +answers for each supported RRtype. We are also not sure how many downstream +curl deployments actually make use of the `c-ares` library, which would +affect the utility of such changes. Another option might be to consider using +some other generic DNS library that does support HTTPS RRs, but it is unclear +if such a library could or would be used by all or almost all curl builds and +downstream releases of curl. + +Our current conclusion is that doing the above is likely best left until we +have some experience with the "using DoH" approach, so we are going to punt on +this for now. + +### Localhost testing + +It can be useful to be able to run against a localhost OpenSSL `s_server` +for testing. We have published instructions for such +[localhost tests](https://github.com/defo-project/ech-dev-utils/blob/main/howtos/localhost-tests.md) +in another repository. Once you have that set up, you can start a server +and then run curl against that: + +```sh +cd $HOME/code/ech-dev-utils +./scripts/echsvr.sh -d +... +``` + +The `echsvr.sh` script supports many ECH-related options. Use `echsvr.sh -h` +for details. + +In another window: + +```sh +cd $HOME/code/curl/ +./src/curl -vvv --insecure --connect-to foo.example.com:8443:localhost:8443 \ + --ech ecl:AD7+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAA== +``` + +### Automated use of `retry_configs` not supported so far... + +As of now we have not added support for using `retry_config` handling in the +application - for a command line tool, one can use `dig` (or `kdig`) to +get the HTTPS RR and pass the ECHConfigList from that on the command line, if +needed, or one can access the value from command line output in verbose more +and then reuse that in another invocation. + +Both our OpenSSL fork and AWS-LC/BoringSSL have APIs for both controlling GREASE +and accessing and logging `retry_configs`, it seems wolfSSL has neither. + +### Testing ECH + +We have yet to add a robust test setup for ECH as that requires an ECH-enabled +test server. + +We have added two basic tests though, aiming to ensure that the client sends a +GREASE or real ECH extension when requested, and reacts correctly to the +failure of ECH in the latter case. (Given that `stunnel` has no ECH support.) + +As with other similar tests, those tests require the `stunnel` tool be +installed. On Ubuntu `sudo apt install stunnel4` achieves that. + +The test cases are: + +- data/test4000: GREASE ECH, expected result: connection succeeds +- data/test4001: real ECH, connection fails with error 101 (ECH required) diff --git a/third-party/curl/docs/EXPERIMENTAL.md b/third-party/curl/docs/EXPERIMENTAL.md index 6b7145df68..9e39a9b36c 100644 --- a/third-party/curl/docs/EXPERIMENTAL.md +++ b/third-party/curl/docs/EXPERIMENTAL.md @@ -1,3 +1,9 @@ + + # Experimental Some features and functionality in curl and libcurl are considered @@ -8,17 +14,94 @@ Experimental support in curl means: 1. Experimental features are provided to allow users to try them out and provide feedback on functionality and API etc before they ship and get "carved in stone". -2. You must enable the feature when invoking configure as otherwise curl will - not be built with the feature present. +2. You must enable the feature when invoking configure as otherwise curl is + not built with the feature present. 3. We strongly advise against using this feature in production. 4. **We reserve the right to change behavior** of the feature without sticking to our API/ABI rules as we do for regular features, as long as it is marked experimental. 5. Experimental features are clearly marked so in documentation. Beware. +## Graduation + +1. Each experimental feature should have a set of documented requirements of + what is needed for that feature to graduate. Graduation means being removed + from the list of experiments. +2. An experiment should NOT graduate if it needs test cases to be disabled, + unless they are for minor features that are clearly documented as not + provided by the experiment and then the disabling should be managed inside + each affected test case. + ## Experimental features right now - - The Hyper HTTP backend - - HTTP/3 support and options - - The rustls backend - - WebSocket +### HTTP/3 support (non-ngtcp2 backends) + +Graduation requirements: + +- The used libraries should be considered out-of-beta with a reasonable + expectation of a stable API going forward. + +- Using HTTP/3 with the given build should perform without risking busy-loops + +### HTTP/3 proxy and CONNECT-UDP support + +Support for HTTP/3 proxy and CONNECT-UDP tunneling is experimental and +requires an explicit build-time opt-in (`--enable-proxy-http3` for +autotools, `-DUSE_PROXY_HTTP3=ON` for CMake). + +Graduation requirements: + +- implementation stability over time with no known severe regressions + +### The Quiche backend + +Graduation requirements: + +- the library needs to consider itself non-beta. +- a reasonable expectation of a stable API going forward. + +### The Rustls backend + +Graduation requirements: + +- a reasonable expectation of a stable API going forward. + +## ECH + +Use of the HTTPS resource record and Encrypted Client Hello (ECH) when using +DoH + +Graduation requirements: + +- ECH support exists in at least one widely used TLS library apart from + BoringSSL and wolfSSL. + +- feedback from users saying that ECH works for their use cases + +- it has been given time to mature, so no earlier than April 2025 (twelve + months after being added here) + +## SSL session import/export + +Import/Export of SSL sessions tickets in libcurl and curl command line +option '--ssl-session ' for faster TLS handshakes and use +of TLSv1.3/QUIC Early Data (0-RTT). + +Graduation requirements: + +- the implementation is considered safe + +- feedback from users saying that session export works for their use cases + +## HTTPS RR + +HTTPS records support is a requirement for ECH but is provided as a +stand-alone feature that is itself considered EXPERIMENTAL. + +Graduation requirements: + +- HTTPS records work for DoH, c-ares and the threaded resolver + +- HTTPS records can control ALPN and port number, at least + +- There are options to control HTTPS use diff --git a/third-party/curl/docs/FAQ b/third-party/curl/docs/FAQ deleted file mode 100644 index 78a238832a..0000000000 --- a/third-party/curl/docs/FAQ +++ /dev/null @@ -1,1544 +0,0 @@ - _ _ ____ _ - ___| | | | _ \| | - / __| | | | |_) | | - | (__| |_| | _ <| |___ - \___|\___/|_| \_\_____| - -FAQ - - 1. Philosophy - 1.1 What is cURL? - 1.2 What is libcurl? - 1.3 What is curl not? - 1.4 When will you make curl do XXXX ? - 1.5 Who makes curl? - 1.6 What do you get for making curl? - 1.7 What about CURL from curl.com? - 1.8 I have a problem, who do I mail? - 1.9 Where do I buy commercial support for curl? - 1.10 How many are using curl? - 1.11 Why do you not update ca-bundle.crt - 1.12 I have a problem, who can I chat with? - 1.13 curl's ECCN number? - 1.14 How do I submit my patch? - 1.15 How do I port libcurl to my OS? - - 2. Install Related Problems - 2.1 configure fails when using static libraries - 2.2 Does curl work/build with other SSL libraries? - 2.4 Does curl support SOCKS (RFC 1928) ? - - 3. Usage Problems - 3.1 curl: (1) SSL is disabled, https: not supported - 3.2 How do I tell curl to resume a transfer? - 3.3 Why does my posting using -F not work? - 3.4 How do I tell curl to run custom FTP commands? - 3.5 How can I disable the Accept: */* header? - 3.6 Does curl support ASP, XML, XHTML or HTML version Y? - 3.7 Can I use curl to delete/rename a file through FTP? - 3.8 How do I tell curl to follow HTTP redirects? - 3.9 How do I use curl in my favorite programming language? - 3.10 What about SOAP, WebDAV, XML-RPC or similar protocols over HTTP? - 3.11 How do I POST with a different Content-Type? - 3.12 Why do FTP-specific features over HTTP proxy fail? - 3.13 Why do my single/double quotes fail? - 3.14 Does curl support JavaScript or PAC (automated proxy config)? - 3.15 Can I do recursive fetches with curl? - 3.16 What certificates do I need when I use SSL? - 3.17 How do I list the root directory of an FTP server? - 3.18 Can I use curl to send a POST/PUT and not wait for a response? - 3.19 How do I get HTTP from a host using a specific IP address? - 3.20 How to SFTP from my user's home directory? - 3.21 Protocol xxx not supported or disabled in libcurl - 3.22 curl -X gives me HTTP problems - - 4. Running Problems - 4.2 Why do I get problems when I use & or % in the URL? - 4.3 How can I use {, }, [ or ] to specify multiple URLs? - 4.4 Why do I get downloaded data even though the web page does not exist? - 4.5 Why do I get return code XXX from an HTTP server? - 4.5.1 "400 Bad Request" - 4.5.2 "401 Unauthorized" - 4.5.3 "403 Forbidden" - 4.5.4 "404 Not Found" - 4.5.5 "405 Method Not Allowed" - 4.5.6 "301 Moved Permanently" - 4.6 Can you tell me what error code 142 means? - 4.7 How do I keep user names and passwords secret in curl command lines? - 4.8 I found a bug - 4.9 curl cannot authenticate to a server that requires NTLM? - 4.10 My HTTP request using HEAD, PUT or DELETE does not work - 4.11 Why do my HTTP range requests return the full document? - 4.12 Why do I get "certificate verify failed" ? - 4.13 Why is curl -R on Windows one hour off? - 4.14 Redirects work in browser but not with curl - 4.15 FTPS does not work - 4.16 My HTTP POST or PUT requests are slow - 4.17 Non-functional connect timeouts on Windows - 4.18 file:// URLs containing drive letters (Windows, NetWare) - 4.19 Why does not curl return an error when the network cable is unplugged? - 4.20 curl does not return error for HTTP non-200 responses - - 5. libcurl Issues - 5.1 Is libcurl thread-safe? - 5.2 How can I receive all data into a large memory chunk? - 5.3 How do I fetch multiple files with libcurl? - 5.4 Does libcurl do Winsock initialization on win32 systems? - 5.5 Does CURLOPT_WRITEDATA and CURLOPT_READDATA work on win32 ? - 5.6 What about Keep-Alive or persistent connections? - 5.7 Link errors when building libcurl on Windows - 5.8 libcurl.so.X: open failed: No such file or directory - 5.9 How does libcurl resolve host names? - 5.10 How do I prevent libcurl from writing the response to stdout? - 5.11 How do I make libcurl not receive the whole HTTP response? - 5.12 Can I make libcurl fake or hide my real IP address? - 5.13 How do I stop an ongoing transfer? - 5.14 Using C++ non-static functions for callbacks? - 5.15 How do I get an FTP directory listing? - 5.16 I want a different time-out - 5.17 Can I write a server with libcurl? - 5.18 Does libcurl use threads? - - 6. License Issues - 6.1 I have a GPL program, can I use the libcurl library? - 6.2 I have a closed-source program, can I use the libcurl library? - 6.3 I have a BSD licensed program, can I use the libcurl library? - 6.4 I have a program that uses LGPL libraries, can I use libcurl? - 6.5 Can I modify curl/libcurl for my program and keep the changes secret? - 6.6 Can you please change the curl/libcurl license to XXXX? - 6.7 What are my obligations when using libcurl in my commercial apps? - - 7. PHP/CURL Issues - 7.1 What is PHP/CURL? - 7.2 Who wrote PHP/CURL? - 7.3 Can I perform multiple requests using the same handle? - 7.4 Does PHP/CURL have dependencies? - - 8. Development - 8.1 Why does curl use C89? - 8.2 Will curl be rewritten? - -============================================================================== - -1. Philosophy - - 1.1 What is cURL? - - cURL is the name of the project. The name is a play on 'Client for URLs', - originally with URL spelled in uppercase to make it obvious it deals with - URLs. The fact it can also be read as 'see URL' also helped, it works as - an abbreviation for "Client URL Request Library" or why not the recursive - version: "curl URL Request Library". - - The cURL project produces two products: - - libcurl - - A client-side URL transfer library, supporting DICT, FILE, FTP, FTPS, - GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, POP3, POP3S, - RTMP, RTMPS, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS - and WSS. - - libcurl supports HTTPS certificates, HTTP POST, HTTP PUT, FTP uploading, - Kerberos, SPNEGO, HTTP form based upload, proxies, cookies, user+password - authentication, file transfer resume, http proxy tunneling and more. - - libcurl is highly portable, it builds and works identically on numerous - platforms, including Solaris, NetBSD, FreeBSD, OpenBSD, Darwin, HP-UX, - IRIX, AIX, Tru64, Linux, UnixWare, HURD, Windows, Amiga, OS/2, macOS, - Ultrix, QNX, OpenVMS, RISC OS, Novell NetWare, DOS, Symbian, OSF, Android, - Minix, IBM TPF and more... - - libcurl is free, thread-safe, IPv6 compatible, feature rich, well - supported and fast. - - curl - - A command line tool for getting or sending data using URL syntax. - - Since curl uses libcurl, curl supports the same wide range of common - Internet protocols that libcurl does. - - We pronounce curl with an initial k sound. It rhymes with words like girl - and earl. This is a short WAV file to help you: - - https://media.merriam-webster.com/soundc11/c/curl0001.wav - - There are numerous sub-projects and related projects that also use the word - curl in the project names in various combinations, but you should take - notice that this FAQ is directed at the command-line tool named curl (and - libcurl the library), and may therefore not be valid for other curl-related - projects. (There is however a small section for the PHP/CURL in this FAQ.) - - 1.2 What is libcurl? - - libcurl is a reliable and portable library for doing Internet data transfers - using one or more of its supported Internet protocols. - - You can use libcurl freely in your application, be it open source, - commercial or closed-source. - - libcurl is most probably the most portable, most powerful and most often - used C-based multi-platform file transfer library on this planet - be it - open source or commercial. - - 1.3 What is curl not? - - curl is not a wget clone. That is a common misconception. Never, during - curl's development, have we intended curl to replace wget or compete on its - market. curl is targeted at single-shot file transfers. - - curl is not a website mirroring program. If you want to use curl to mirror - something: fine, go ahead and write a script that wraps around curl or use - libcurl to make it reality. - - curl is not an FTP site mirroring program. Sure, get and send FTP with curl - but if you want systematic and sequential behavior you should write a - script (or write a new program that interfaces libcurl) and do it. - - curl is not a PHP tool, even though it works perfectly well when used from - or with PHP (when using the PHP/CURL module). - - curl is not a program for a single operating system. curl exists, compiles, - builds and runs under a wide range of operating systems, including all - modern Unixes (and a bunch of older ones too), Windows, Amiga, OS/2, macOS, - QNX etc. - - 1.4 When will you make curl do XXXX ? - - We love suggestions of what to change in order to make curl and libcurl - better. We do however believe in a few rules when it comes to the future of - curl: - - curl -- the command line tool -- is to remain a non-graphical command line - tool. If you want GUIs or fancy scripting capabilities, you should look for - another tool that uses libcurl. - - We do not add things to curl that other small and available tools already do - well at the side. curl's output can be piped into another program or - redirected to another file for the next program to interpret. - - We focus on protocol related issues and improvements. If you want to do more - magic with the supported protocols than curl currently does, chances are - good we will agree. If you want to add more protocols, we may agree. - - If you want someone else to do all the work while you wait for us to - implement it for you, that is not a friendly attitude. We spend a - considerable time already on maintaining and developing curl. In order to - get more out of us, you should consider trading in some of your time and - effort in return. Simply go to the GitHub repository which resides at - https://github.com/curl/curl, fork the project, and create pull requests - with your proposed changes. - - If you write the code, chances are better that it will get into curl faster. - - 1.5 Who makes curl? - - curl and libcurl are not made by any single individual. Daniel Stenberg is - project leader and main developer, but other persons' submissions are - important and crucial. Anyone can contribute and post their changes and - improvements and have them inserted in the main sources (of course on the - condition that developers agree that the fixes are good). - - The full list of all contributors is found in the docs/THANKS file. - - curl is developed by a community, with Daniel at the wheel. - - 1.6 What do you get for making curl? - - Project cURL is entirely free and open. We do this voluntarily, mostly in - our spare time. Companies may pay individual developers to work on curl. - This is not controlled by nor supervised in any way by the curl project. - - We get help from companies. Haxx provides website, bandwidth, mailing lists - etc, GitHub hosts the primary git repository and other services like the bug - tracker at https://github.com/curl/curl. Also again, some companies have - sponsored certain parts of the development in the past and I hope some will - continue to do so in the future. - - If you want to support our project, consider a donation or a banner-program - or even better: by helping us with coding, documenting or testing etc. - - See also: https://curl.se/sponsors.html - - 1.7 What about CURL from curl.com? - - During the summer of 2001, curl.com was busy advertising their client-side - programming language for the web, named CURL. - - We are in no way associated with curl.com or their CURL programming - language. - - Our project name curl has been in effective use since 1998. We were not the - first computer related project to use the name "curl" and do not claim any - rights to the name. - - We recognize that we will be living in parallel with curl.com and wish them - every success. - - 1.8 I have a problem, who do I mail? - - Please do not mail any single individual unless you really need to. Keep - curl-related questions on a suitable mailing list. All available mailing - lists are listed in the MANUAL document and online at - https://curl.se/mail/ - - Keeping curl-related questions and discussions on mailing lists allows - others to join in and help, to share their ideas, to contribute their - suggestions and to spread their wisdom. Keeping discussions on public mailing - lists also allows for others to learn from this (both current and future - users thanks to the web based archives of the mailing lists), thus saving us - from having to repeat ourselves even more. Thanks for respecting this. - - If you have found or simply suspect a security problem in curl or libcurl, - submit all the details at https://hackerone.one/curl. On there we keep the - issue private while we investigate, confirm it, work and validate a fix and - agree on a time schedule for publication etc. That way we produce a fix in a - timely manner before the flaw is announced to the world, reducing the impact - the problem risks having on existing users. - - Security issues can also be taking to the curl security team by emailing - security at curl.se (closed list of receivers, mails are not disclosed). - - 1.9 Where do I buy commercial support for curl? - - curl is fully open source. It means you can hire any skilled engineer to fix - your curl-related problems. - - We list available alternatives on the curl website: - https://curl.se/support.html - - 1.10 How many are using curl? - - It is impossible to tell. - - We do not know how many users that knowingly have installed and use curl. - - We do not know how many users that use curl without knowing that they are in - fact using it. - - We do not know how many users that downloaded or installed curl and then - never use it. - - In 2020, we estimate that curl runs in roughly ten billion installations - world wide. - - 1.11 Why do you not update ca-bundle.crt - - In the cURL project we have decided not to attempt to keep this file updated - (or even present) since deciding what to add to a ca cert bundle is an - undertaking we have not been ready to accept, and the one we can get from - Mozilla is perfectly fine so there is no need to duplicate that work. - - Today, with many services performed over HTTPS, every operating system - should come with a default ca cert bundle that can be deemed somewhat - trustworthy and that collection (if reasonably updated) should be deemed to - be a lot better than a private curl version. - - If you want the most recent collection of ca certs that Mozilla Firefox - uses, we recommend that you extract the collection yourself from Mozilla - Firefox (by running 'make ca-bundle), or by using our online service setup - for this purpose: https://curl.se/docs/caextract.html - - 1.12 I have a problem who, can I chat with? - - There is a bunch of friendly people hanging out in the #curl channel on the - IRC network libera.chat. If you are polite and nice, chances are good that - you can get -- or provide -- help instantly. - - 1.13 curl's ECCN number? - - The US government restricts exports of software that contains or uses - cryptography. When doing so, the Export Control Classification Number (ECCN) - is used to identify the level of export control etc. - - Apache Software Foundation gives a good explanation of ECCNs at - https://www.apache.org/dev/crypto.html - - We believe curl's number might be ECCN 5D002, another possibility is - 5D992. It seems necessary to write them (the authority that administers ECCN - numbers), asking to confirm. - - Comprehensible explanations of the meaning of such numbers and how to obtain - them (resp.) are here - - https://www.bis.doc.gov/licensing/exportingbasics.htm - https://www.bis.doc.gov/licensing/do_i_needaneccn.html - - An incomprehensible description of the two numbers above is here - https://www.bis.doc.gov/index.php/documents/new-encryption/1653-ccl5-pt2-3 - - 1.14 How do I submit my patch? - - We strongly encourage you to submit changes and improvements directly as - "pull requests" on GitHub: https://github.com/curl/curl/pulls - - If you for any reason cannot or will not deal with GitHub, send your patch to - the curl-library mailing list. We are many subscribers there and there are - lots of people who can review patches, comment on them and "receive" them - properly. - - Lots of more details are found in the CONTRIBUTE.md and INTERNALS.md - documents. - - 1.15 How do I port libcurl to my OS? - - Here's a rough step-by-step: - - 1. copy a suitable lib/config-*.h file as a start to lib/config-[youros].h - - 2. edit lib/config-[youros].h to match your OS and setup - - 3. edit lib/curl_setup.h to include config-[youros].h when your OS is - detected by the preprocessor, in the style others already exist - - 4. compile lib/*.c and make them into a library - - -2. Install Related Problems - - 2.1 configure fails when using static libraries - - You may find that configure fails to properly detect the entire dependency - chain of libraries when you provide static versions of the libraries that - configure checks for. - - The reason why static libraries is much harder to deal with is that for them - we do not get any help but the script itself must know or check what more - libraries that are needed (with shared libraries, that dependency "chain" is - handled automatically). This is a error-prone process and one that also - tends to vary over time depending on the release versions of the involved - components and may also differ between operating systems. - - For that reason, configure does few attempts to actually figure this out and - you are instead encouraged to set LIBS and LDFLAGS accordingly when you - invoke configure, and point out the needed libraries and set the necessary - flags yourself. - - 2.2 Does curl work with other SSL libraries? - - curl has been written to use a generic SSL function layer internally, and - that SSL functionality can then be provided by one out of many different SSL - backends. - - curl can be built to use one of the following SSL alternatives: OpenSSL, - libressl, BoringSSL, AWS-LC, GnuTLS, wolfSSL, mbedTLS, Secure Transport - (native iOS/OS X), Schannel (native Windows), BearSSL or Rustls. They all - have their pros and cons, and we try to maintain a comparison of them here: - https://curl.se/docs/ssl-compared.html - - 2.4 Does curl support SOCKS (RFC 1928) ? - - Yes, SOCKS 4 and 5 are supported. - -3. Usage problems - - 3.1 curl: (1) SSL is disabled, https: not supported - - If you get this output when trying to get anything from an https:// server, - it means that the instance of curl/libcurl that you are using was built - without support for this protocol. - - This could have happened if the configure script that was run at build time - could not find all libs and include files curl requires for SSL to work. If - the configure script fails to find them, curl is simply built without SSL - support. - - To get the https:// support into a curl that was previously built but that - reports that https:// is not supported, you should dig through the document - and logs and check out why the configure script does not find the SSL libs - and/or include files. - - Also, check out the other paragraph in this FAQ labeled "configure does not - find OpenSSL even when it is installed". - - 3.2 How do I tell curl to resume a transfer? - - curl supports resumed transfers both ways on both FTP and HTTP. - Try the -C option. - - 3.3 Why does my posting using -F not work? - - You cannot arbitrarily use -F or -d, the choice between -F or -d depends on - the HTTP operation you need curl to do and what the web server that will - receive your post expects. - - If the form you are trying to submit uses the type 'multipart/form-data', - then and only then you must use the -F type. In all the most common cases, - you should use -d which then causes a posting with the type - 'application/x-www-form-urlencoded'. - - This is described in some detail in the MANUAL and TheArtOfHttpScripting - documents, and if you do not understand it the first time, read it again - before you post questions about this to the mailing list. Also, try reading - through the mailing list archives for old postings and questions regarding - this. - - 3.4 How do I tell curl to run custom FTP commands? - - You can tell curl to perform optional commands both before and/or after a - file transfer. Study the -Q/--quote option. - - Since curl is used for file transfers, you do not normally use curl to - perform FTP commands without transferring anything. Therefore you must - always specify a URL to transfer to/from even when doing custom FTP - commands, or use -I which implies the "no body" option sent to libcurl. - - 3.5 How can I disable the Accept: */* header? - - You can change all internally generated headers by adding a replacement with - the -H/--header option. By adding a header with empty contents you safely - disable that one. Use -H "Accept:" to disable that specific header. - - 3.6 Does curl support ASP, XML, XHTML or HTML version Y? - - To curl, all contents are alike. It does not matter how the page was - generated. It may be ASP, PHP, Perl, shell-script, SSI or plain HTML - files. There is no difference to curl and it does not even know what kind of - language that generated the page. - - See also item 3.14 regarding JavaScript. - - 3.7 Can I use curl to delete/rename a file through FTP? - - Yes. You specify custom FTP commands with -Q/--quote. - - One example would be to delete a file after you have downloaded it: - - curl -O ftp://download.com/coolfile -Q '-DELE coolfile' - - or rename a file after upload: - - curl -T infile ftp://upload.com/dir/ -Q "-RNFR infile" -Q "-RNTO newname" - - 3.8 How do I tell curl to follow HTTP redirects? - - curl does not follow so-called redirects by default. The Location: header - that informs the client about this is only interpreted if you are using the - -L/--location option. As in: - - curl -L http://redirector.com - - Not all redirects are HTTP ones, see 4.14 - - 3.9 How do I use curl in my favorite programming language? - - Many programming languages have interfaces/bindings that allow you to use - curl without having to use the command line tool. If you are fluent in such - a language, you may prefer to use one of these interfaces instead. - - Find out more about which languages that support curl directly, and how to - install and use them, in the libcurl section of the curl website: - https://curl.se/libcurl/ - - All the various bindings to libcurl are made by other projects and people, - outside of the cURL project. The cURL project itself only produces libcurl - with its plain C API. If you do not find anywhere else to ask you can ask - about bindings on the curl-library list too, but be prepared that people on - that list may not know anything about bindings. - - In December 2021, there were interfaces available for the following - languages: Ada95, Basic, C, C++, Ch, Cocoa, D, Delphi, Dylan, Eiffel, - Euphoria, Falcon, Ferite, Gambas, glib/GTK+, Go, Guile, Harbour, Haskell, - Java, Julia, Lisp, Lua, Mono, .NET, node.js, Object-Pascal, OCaml, Pascal, - Perl, PHP, PostgreSQL, Python, R, Rexx, Ring, RPG, Ruby, Rust, Scheme, - Scilab, S-Lang, Smalltalk, SP-Forth, SPL, Tcl, Visual Basic, Visual FoxPro, - Q, wxwidgets, XBLite and Xoho. By the time you read this, additional ones - may have appeared. - - 3.10 What about SOAP, WebDAV, XML-RPC or similar protocols over HTTP? - - curl adheres to the HTTP spec, which basically means you can play with *any* - protocol that is built on top of HTTP. Protocols such as SOAP, WEBDAV and - XML-RPC are all such ones. You can use -X to set custom requests and -H to - set custom headers (or replace internally generated ones). - - Using libcurl is of course just as good and you would just use the proper - library options to do the same. - - 3.11 How do I POST with a different Content-Type? - - You can always replace the internally generated headers with -H/--header. - To make a simple HTTP POST with text/xml as content-type, do something like: - - curl -d "datatopost" -H "Content-Type: text/xml" [URL] - - 3.12 Why do FTP-specific features over HTTP proxy fail? - - Because when you use an HTTP proxy, the protocol spoken on the network will - be HTTP, even if you specify an FTP URL. This effectively means that you - normally cannot use FTP-specific features such as FTP upload and FTP quote - etc. - - There is one exception to this rule, and that is if you can "tunnel through" - the given HTTP proxy. Proxy tunneling is enabled with a special option (-p) - and is generally not available as proxy admins usually disable tunneling to - ports other than 443 (which is used for HTTPS access through proxies). - - 3.13 Why do my single/double quotes fail? - - To specify a command line option that includes spaces, you might need to - put the entire option within quotes. Like in: - - curl -d " with spaces " url.com - - or perhaps - - curl -d ' with spaces ' url.com - - Exactly what kind of quotes and how to do this is entirely up to the shell - or command line interpreter that you are using. For most unix shells, you - can more or less pick either single (') or double (") quotes. For - Windows/DOS command prompts you must use double (") quotes, and if the - option string contains inner double quotes you can escape them with a - backslash. - - For Windows powershell the arguments are not always passed on as expected - because curl is not a powershell script. You may or may not be able to use - single quotes. To escape inner double quotes seems to require a - backslash-backtick escape sequence and the outer quotes as double quotes. - - Please study the documentation for your particular environment. Examples in - the curl docs will use a mix of both of these as shown above. You must - adjust them to work in your environment. - - Remember that curl works and runs on more operating systems than most single - individuals have ever tried. - - 3.14 Does curl support JavaScript or PAC (automated proxy config)? - - Many web pages do magic stuff using embedded JavaScript. curl and libcurl - have no built-in support for that, so it will be treated just like any other - contents. - - .pac files are a Netscape invention and are sometimes used by organizations - to allow them to differentiate which proxies to use. The .pac contents is - just a JavaScript program that gets invoked by the browser and that returns - the name of the proxy to connect to. Since curl does not support JavaScript, - it cannot support .pac proxy configuration either. - - Some workarounds usually suggested to overcome this JavaScript dependency: - - Depending on the JavaScript complexity, write up a script that translates it - to another language and execute that. - - Read the JavaScript code and rewrite the same logic in another language. - - Implement a JavaScript interpreter, people have successfully used the - Mozilla JavaScript engine in the past. - - Ask your admins to stop this, for a static proxy setup or similar. - - 3.15 Can I do recursive fetches with curl? - - No. curl itself has no code that performs recursive operations, such as - those performed by wget and similar tools. - - There exists wrapper scripts with that functionality (for example the - curlmirror perl script), and you can write programs based on libcurl to do - it, but the command line tool curl itself cannot. - - 3.16 What certificates do I need when I use SSL? - - There are three different kinds of "certificates" to keep track of when we - talk about using SSL-based protocols (HTTPS or FTPS) using curl or libcurl. - - CLIENT CERTIFICATE - - The server you communicate with may require that you can provide this in - order to prove that you actually are who you claim to be. If the server - does not require this, you do not need a client certificate. - - A client certificate is always used together with a private key, and the - private key has a pass phrase that protects it. - - SERVER CERTIFICATE - - The server you communicate with has a server certificate. You can and should - verify this certificate to make sure that you are truly talking to the real - server and not a server impersonating it. - - CERTIFICATE AUTHORITY CERTIFICATE ("CA cert") - - You often have several CA certs in a CA cert bundle that can be used to - verify a server certificate that was signed by one of the authorities in the - bundle. curl does not come with a CA cert bundle but most curl installs - provide one. You can also override the default. - - The server certificate verification process is made by using a Certificate - Authority certificate ("CA cert") that was used to sign the server - certificate. Server certificate verification is enabled by default in curl - and libcurl and is often the reason for problems as explained in FAQ entry - 4.12 and the SSLCERTS document - (https://curl.se/docs/sslcerts.html). Server certificates that are - "self-signed" or otherwise signed by a CA that you do not have a CA cert - for, cannot be verified. If the verification during a connect fails, you are - refused access. You then need to explicitly disable the verification to - connect to the server. - - 3.17 How do I list the root directory of an FTP server? - - There are two ways. The way defined in the RFC is to use an encoded slash - in the first path part. List the "/tmp" directory like this: - - curl ftp://ftp.sunet.se/%2ftmp/ - - or the not-quite-kosher-but-more-readable way, by simply starting the path - section of the URL with a slash: - - curl ftp://ftp.sunet.se//tmp/ - - 3.18 Can I use curl to send a POST/PUT and not wait for a response? - - No. - - You can easily write your own program using libcurl to do such stunts. - - 3.19 How do I get HTTP from a host using a specific IP address? - - For example, you may be trying out a website installation that is not yet in - the DNS. Or you have a site using multiple IP addresses for a given host - name and you want to address a specific one out of the set. - - Set a custom Host: header that identifies the server name you want to reach - but use the target IP address in the URL: - - curl --header "Host: www.example.com" http://127.0.0.1/ - - You can also opt to add faked host name entries to curl with the --resolve - option. That has the added benefit that things like redirects will also work - properly. The above operation would instead be done as: - - curl --resolve www.example.com:80:127.0.0.1 http://www.example.com/ - - 3.20 How to SFTP from my user's home directory? - - Contrary to how FTP works, SFTP and SCP URLs specify the exact directory to - work with. It means that if you do not specify that you want the user's home - directory, you get the actual root directory. - - To specify a file in your user's home directory, you need to use the correct - URL syntax which for SFTP might look similar to: - - curl -O -u user:password sftp://example.com/~/file.txt - - and for SCP it is just a different protocol prefix: - - curl -O -u user:password scp://example.com/~/file.txt - - 3.21 Protocol xxx not supported or disabled in libcurl - - When passing on a URL to curl to use, it may respond that the particular - protocol is not supported or disabled. The particular way this error message - is phrased is because curl does not make a distinction internally of whether - a particular protocol is not supported (i.e. never got any code added that - knows how to speak that protocol) or if it was explicitly disabled. curl can - be built to only support a given set of protocols, and the rest would then - be disabled or not supported. - - Note that this error will also occur if you pass a wrongly spelled protocol - part as in "htpt://example.com" or as in the less evident case if you prefix - the protocol part with a space as in " http://example.com/". - - 3.22 curl -X gives me HTTP problems - - In normal circumstances, -X should hardly ever be used. - - By default you use curl without explicitly saying which request method to - use when the URL identifies an HTTP transfer. If you just pass in a URL like - "curl http://example.com" it will use GET. If you use -d or -F curl will use - POST, -I will cause a HEAD and -T will make it a PUT. - - If for whatever reason you are not happy with these default choices that curl - does for you, you can override those request methods by specifying -X - [WHATEVER]. This way you can for example send a DELETE by doing "curl -X - DELETE [URL]". - - It is thus pointless to do "curl -XGET [URL]" as GET would be used - anyway. In the same vein it is pointless to do "curl -X POST -d data - [URL]"... But you can make a fun and somewhat rare request that sends a - request-body in a GET request with something like "curl -X GET -d data - [URL]" - - Note that -X does not actually change curl's behavior as it only modifies the - actual string sent in the request, but that may of course trigger a - different set of events. - - Accordingly, by using -XPOST on a command line that for example would follow - a 303 redirect, you will effectively prevent curl from behaving - correctly. Be aware. - - -4. Running Problems - - 4.2 Why do I get problems when I use & or % in the URL? - - In general Unix shells, the & symbol is treated specially and when used, it - runs the specified command in the background. To safely send the & as a part - of a URL, you should quote the entire URL by using single (') or double (") - quotes around it. Similar problems can also occur on some shells with other - characters, including ?*!$~(){}<>\|;`. When in doubt, quote the URL. - - An example that would invoke a remote CGI that uses &-symbols could be: - - curl 'http://www.altavista.com/cgi-bin/query?text=yes&q=curl' - - In Windows, the standard DOS shell treats the percent sign specially and you - need to use TWO percent signs for each single one you want to use in the - URL. - - If you want a literal percent sign to be part of the data you pass in a POST - using -d/--data you must encode it as '%25' (which then also needs the - percent sign doubled on Windows machines). - - 4.3 How can I use {, }, [ or ] to specify multiple URLs? - - Because those letters have a special meaning to the shell, to be used in - a URL specified to curl you must quote them. - - An example that downloads two URLs (sequentially) would be: - - curl '{curl,www}.haxx.se' - - To be able to use those characters as actual parts of the URL (without using - them for the curl URL "globbing" system), use the -g/--globoff option: - - curl -g 'www.site.com/weirdname[].html' - - 4.4 Why do I get downloaded data even though the web page does not exist? - - curl asks remote servers for the page you specify. If the page does not exist - at the server, the HTTP protocol defines how the server should respond and - that means that headers and a "page" will be returned. That is simply how - HTTP works. - - By using the --fail option you can tell curl explicitly to not get any data - if the HTTP return code does not say success. - - 4.5 Why do I get return code XXX from an HTTP server? - - RFC 2616 clearly explains the return codes. This is a short transcript. Go - read the RFC for exact details: - - 4.5.1 "400 Bad Request" - - The request could not be understood by the server due to malformed - syntax. The client SHOULD NOT repeat the request without modifications. - - 4.5.2 "401 Unauthorized" - - The request requires user authentication. - - 4.5.3 "403 Forbidden" - - The server understood the request, but is refusing to fulfill it. - Authorization will not help and the request SHOULD NOT be repeated. - - 4.5.4 "404 Not Found" - - The server has not found anything matching the Request-URI. No indication - is given as to whether the condition is temporary or permanent. - - 4.5.5 "405 Method Not Allowed" - - The method specified in the Request-Line is not allowed for the resource - identified by the Request-URI. The response MUST include an Allow header - containing a list of valid methods for the requested resource. - - 4.5.6 "301 Moved Permanently" - - If you get this return code and an HTML output similar to this: - -

Moved Permanently

The document has moved here. - - it might be because you requested a directory URL but without the trailing - slash. Try the same operation again _with_ the trailing URL, or use the - -L/--location option to follow the redirection. - - 4.6 Can you tell me what error code 142 means? - - All curl error codes are described at the end of the man page, in the - section called "EXIT CODES". - - Error codes that are larger than the highest documented error code means - that curl has exited due to a crash. This is a serious error, and we - appreciate a detailed bug report from you that describes how we could go - ahead and repeat this. - - 4.7 How do I keep user names and passwords secret in curl command lines? - - This problem has two sides: - - The first part is to avoid having clear-text passwords in the command line - so that they do not appear in 'ps' outputs and similar. That is easily - avoided by using the "-K" option to tell curl to read parameters from a file - or stdin to which you can pass the secret info. curl itself will also - attempt to "hide" the given password by blanking out the option - this - does not work on all platforms. - - To keep the passwords in your account secret from the rest of the world is - not a task that curl addresses. You could of course encrypt them somehow to - at least hide them from being read by human eyes, but that is not what - anyone would call security. - - Also note that regular HTTP (using Basic authentication) and FTP passwords - are sent as cleartext across the network. All it takes for anyone to fetch - them is to listen on the network. Eavesdropping is easy. Use more secure - authentication methods (like Digest, Negotiate or even NTLM) or consider the - SSL-based alternatives HTTPS and FTPS. - - 4.8 I found a bug - - It is not a bug if the behavior is documented. Read the docs first. - Especially check out the KNOWN_BUGS file, it may be a documented bug. - - If it is a problem with a binary you have downloaded or a package for your - particular platform, try contacting the person who built the package/archive - you have. - - If there is a bug, read the BUGS document first. Then report it as described - in there. - - 4.9 curl cannot authenticate to a server that requires NTLM? - - NTLM support requires OpenSSL, GnuTLS, mbedTLS, Secure Transport, or - Microsoft Windows libraries at build-time to provide this functionality. - - 4.10 My HTTP request using HEAD, PUT or DELETE does not work - - Many web servers allow or demand that the administrator configures the - server properly for these requests to work on the web server. - - Some servers seem to support HEAD only on certain kinds of URLs. - - To fully grasp this, try the documentation for the particular server - software you are trying to interact with. This is not anything curl can do - anything about. - - 4.11 Why do my HTTP range requests return the full document? - - Because the range may not be supported by the server, or the server may - choose to ignore it and return the full document anyway. - - 4.12 Why do I get "certificate verify failed" ? - - When you invoke curl and get an error 60 error back it means that curl - could not verify that the server's certificate was good. curl verifies the - certificate using the CA cert bundle and verifying for which names the - certificate has been granted. - - To completely disable the certificate verification, use -k. This does - however enable man-in-the-middle attacks and makes the transfer INSECURE. - We strongly advise against doing this for more than experiments. - - If you get this failure with a CA cert bundle installed and used, the - server's certificate might not be signed by one of the CA's in your CA - store. It might for example be self-signed. You then correct this problem by - obtaining a valid CA cert for the server. Or again, decrease the security by - disabling this check. - - At times, you find that the verification works in your favorite browser but - fails in curl. When this happens, the reason is usually that the server - sends an incomplete cert chain. The server is mandated to send all - "intermediate certificates" but does not. This typically works with browsers - anyway since they A) cache such certs and B) supports AIA which downloads - such missing certificates on demand. This is a server misconfiguration. A - good way to figure out if this is the case it to use the SSL Labs server - test and check the certificate chain: https://www.ssllabs.com/ssltest/ - - Details are also in the SSLCERTS.md document, found online here: - https://curl.se/docs/sslcerts.html - - 4.13 Why is curl -R on Windows one hour off? - - Since curl 7.53.0 this issue should be fixed as long as curl was built with - any modern compiler that allows for a 64-bit curl_off_t type. For older - compilers or prior curl versions it may set a time that appears one hour off. - This happens due to a flaw in how Windows stores and uses file modification - times and it is not easily worked around. For more details read this: - https://www.codeproject.com/Articles/1144/Beating-the-Daylight-Savings-Time-bug-and-getting - - 4.14 Redirects work in browser but not with curl - - curl supports HTTP redirects well (see item 3.8). Browsers generally support - at least two other ways to perform redirects that curl does not: - - Meta tags. You can write an HTML tag that will cause the browser to redirect - to another given URL after a certain time. - - JavaScript. You can write a JavaScript program embedded in an HTML page that - redirects the browser to another given URL. - - There is no way to make curl follow these redirects. You must either - manually figure out what the page is set to do, or write a script that parses - the results and fetches the new URL. - - 4.15 FTPS does not work - - curl supports FTPS (sometimes known as FTP-SSL) both implicit and explicit - mode. - - When a URL is used that starts with FTPS://, curl assumes implicit SSL on - the control connection and will therefore immediately connect and try to - speak SSL. FTPS:// connections default to port 990. - - To use explicit FTPS, you use an FTP:// URL and the --ftp-ssl option (or one - of its related flavors). This is the most common method, and the one - mandated by RFC 4217. This kind of connection will then of course use the - standard FTP port 21 by default. - - 4.16 My HTTP POST or PUT requests are slow - - libcurl makes all POST and PUT requests (except for requests with a small - request body) use the "Expect: 100-continue" header. This header allows the - server to deny the operation early so that libcurl can bail out before having - to send any data. This is useful in authentication cases and others. - - However, many servers do not implement the Expect: stuff properly and if the - server does not respond (positively) within 1 second libcurl will continue - and send off the data anyway. - - You can disable libcurl's use of the Expect: header the same way you disable - any header, using -H / CURLOPT_HTTPHEADER, or by forcing it to use HTTP 1.0. - - 4.17 Non-functional connect timeouts - - In most Windows setups having a timeout longer than 21 seconds make no - difference, as it will only send 3 TCP SYN packets and no more. The second - packet sent three seconds after the first and the third six seconds after - the second. No more than three packets are sent, no matter how long the - timeout is set. - - See option TcpMaxConnectRetransmissions on this page: - https://support.microsoft.com/en-us/kb/175523/en-us - - Also, even on non-Windows systems there may run a firewall or anti-virus - software or similar that accepts the connection but does not actually do - anything else. This will make (lib)curl to consider the connection connected - and thus the connect timeout will not trigger. - - 4.18 file:// URLs containing drive letters (Windows, NetWare) - - When using curl to try to download a local file, one might use a URL - in this format: - - file://D:/blah.txt - - you will find that even if D:\blah.txt does exist, curl returns a 'file - not found' error. - - According to RFC 1738 (https://www.ietf.org/rfc/rfc1738.txt), - file:// URLs must contain a host component, but it is ignored by - most implementations. In the above example, 'D:' is treated as the - host component, and is taken away. Thus, curl tries to open '/blah.txt'. - If your system is installed to drive C:, that will resolve to 'C:\blah.txt', - and if that does not exist you will get the not found error. - - To fix this problem, use file:// URLs with *three* leading slashes: - - file:///D:/blah.txt - - Alternatively, if it makes more sense, specify 'localhost' as the host - component: - - file://localhost/D:/blah.txt - - In either case, curl should now be looking for the correct file. - - 4.19 Why does not curl return an error when the network cable is unplugged? - - Unplugging a cable is not an error situation. The TCP/IP protocol stack - was designed to be fault tolerant, so even though there may be a physical - break somewhere the connection should not be affected, just possibly - delayed. Eventually, the physical break will be fixed or the data will be - re-routed around the physical problem through another path. - - In such cases, the TCP/IP stack is responsible for detecting when the - network connection is irrevocably lost. Since with some protocols it is - perfectly legal for the client to wait indefinitely for data, the stack may - never report a problem, and even when it does, it can take up to 20 minutes - for it to detect an issue. The curl option --keepalive-time enables - keep-alive support in the TCP/IP stack which makes it periodically probe the - connection to make sure it is still available to send data. That should - reliably detect any TCP/IP network failure. - - TCP keep alive will not detect the network going down before the TCP/IP - connection is established (e.g. during a DNS lookup) or using protocols that - do not use TCP. To handle those situations, curl offers a number of timeouts - on its own. --speed-limit/--speed-time will abort if the data transfer rate - falls too low, and --connect-timeout and --max-time can be used to put an - overall timeout on the connection phase or the entire transfer. - - A libcurl-using application running in a known physical environment (e.g. - an embedded device with only a single network connection) may want to act - immediately if its lone network connection goes down. That can be achieved - by having the application monitor the network connection on its own using an - OS-specific mechanism, then signaling libcurl to abort (see also item 5.13). - - 4.20 curl does not return error for HTTP non-200 responses - - Correct. Unless you use -f (--fail). - - When doing HTTP transfers, curl will perform exactly what you are asking it - to do and if successful it will not return an error. You can use curl to - test your web server's "file not found" page (that gets 404 back), you can - use it to check your authentication protected web pages (that gets a 401 - back) and so on. - - The specific HTTP response code does not constitute a problem or error for - curl. It simply sends and delivers HTTP as you asked and if that worked, - everything is fine and dandy. The response code is generally providing more - higher level error information that curl does not care about. The error was - not in the HTTP transfer. - - If you want your command line to treat error codes in the 400 and up range - as errors and thus return a non-zero value and possibly show an error - message, curl has a dedicated option for that: -f (CURLOPT_FAILONERROR in - libcurl speak). - - You can also use the -w option and the variable %{response_code} to extract - the exact response code that was returned in the response. - -5. libcurl Issues - - 5.1 Is libcurl thread-safe? - - Yes. - - We have written the libcurl code specifically adjusted for multi-threaded - programs. libcurl will use thread-safe functions instead of non-safe ones if - your system has such. Note that you must never share the same handle in - multiple threads. - - There may be some exceptions to thread safety depending on how libcurl was - built. Please review the guidelines for thread safety to learn more: - https://curl.se/libcurl/c/threadsafe.html - - 5.2 How can I receive all data into a large memory chunk? - - [ See also the examples/getinmemory.c source ] - - You are in full control of the callback function that gets called every time - there is data received from the remote server. You can make that callback do - whatever you want. You do not have to write the received data to a file. - - One solution to this problem could be to have a pointer to a struct that you - pass to the callback function. You set the pointer using the - CURLOPT_WRITEDATA option. Then that pointer will be passed to the callback - instead of a FILE * to a file: - - /* imaginary struct */ - struct MemoryStruct { - char *memory; - size_t size; - }; - - /* imaginary callback function */ - size_t - WriteMemoryCallback(void *ptr, size_t size, size_t nmemb, void *data) - { - size_t realsize = size * nmemb; - struct MemoryStruct *mem = (struct MemoryStruct *)data; - - mem->memory = (char *)realloc(mem->memory, mem->size + realsize + 1); - if (mem->memory) { - memcpy(&(mem->memory[mem->size]), ptr, realsize); - mem->size += realsize; - mem->memory[mem->size] = 0; - } - return realsize; - } - - 5.3 How do I fetch multiple files with libcurl? - - libcurl has excellent support for transferring multiple files. You should - just repeatedly set new URLs with curl_easy_setopt() and then transfer it - with curl_easy_perform(). The handle you get from curl_easy_init() is not - only reusable, but you are even encouraged to reuse it if you can, as that - will enable libcurl to use persistent connections. - - 5.4 Does libcurl do Winsock initialization on win32 systems? - - Yes, if told to in the curl_global_init() call. - - 5.5 Does CURLOPT_WRITEDATA and CURLOPT_READDATA work on win32 ? - - Yes, but you cannot open a FILE * and pass the pointer to a DLL and have - that DLL use the FILE * (as the DLL and the client application cannot access - each others' variable memory areas). If you set CURLOPT_WRITEDATA you must - also use CURLOPT_WRITEFUNCTION as well to set a function that writes the - file, even if that simply writes the data to the specified FILE *. - Similarly, if you use CURLOPT_READDATA you must also specify - CURLOPT_READFUNCTION. - - 5.6 What about Keep-Alive or persistent connections? - - curl and libcurl have excellent support for persistent connections when - transferring several files from the same server. curl will attempt to reuse - connections for all URLs specified on the same command line/config file, and - libcurl will reuse connections for all transfers that are made using the - same libcurl handle. - - When you use the easy interface the connection cache is kept within the easy - handle. If you instead use the multi interface, the connection cache will be - kept within the multi handle and will be shared among all the easy handles - that are used within the same multi handle. - - 5.7 Link errors when building libcurl on Windows - - You need to make sure that your project, and all the libraries (both static - and dynamic) that it links against, are compiled/linked against the same run - time library. - - This is determined by the /MD, /ML, /MT (and their corresponding /M?d) - options to the command line compiler. /MD (linking against MSVCRT dll) seems - to be the most commonly used option. - - When building an application that uses the static libcurl library, you must - add -DCURL_STATICLIB to your CFLAGS. Otherwise the linker will look for - dynamic import symbols. If you are using Visual Studio, you need to instead - add CURL_STATICLIB in the "Preprocessor Definitions" section. - - If you get a linker error like "unknown symbol __imp__curl_easy_init ..." you - have linked against the wrong (static) library. If you want to use the - libcurl.dll and import lib, you do not need any extra CFLAGS, but use one of - the import libraries below. These are the libraries produced by the various - lib/Makefile.* files: - - Target: static lib. import lib for libcurl*.dll. - ----------------------------------------------------------- - MinGW: libcurl.a libcurldll.a - MSVC (release): libcurl.lib libcurl_imp.lib - MSVC (debug): libcurld.lib libcurld_imp.lib - Borland: libcurl.lib libcurl_imp.lib - - 5.8 libcurl.so.X: open failed: No such file or directory - - This is an error message you might get when you try to run a program linked - with a shared version of libcurl and your runtime linker (ld.so) could not - find the shared library named libcurl.so.X. (Where X is the number of the - current libcurl ABI, typically 3 or 4). - - You need to make sure that ld.so finds libcurl.so.X. You can do that - multiple ways, and it differs somewhat between different operating systems. - They are usually: - - * Add an option to the linker command line that specify the hard-coded path - the runtime linker should check for the lib (usually -R) - - * Set an environment variable (LD_LIBRARY_PATH for example) where ld.so - should check for libs - - * Adjust the system's config to check for libs in the directory where you have - put the library (like Linux's /etc/ld.so.conf) - - 'man ld.so' and 'man ld' will tell you more details - - 5.9 How does libcurl resolve host names? - - libcurl supports a large number of name resolve functions. One of them is - picked at build-time and will be used unconditionally. Thus, if you want to - change name resolver function you must rebuild libcurl and tell it to use a - different function. - - - The non-IPv6 resolver that can use one of four different host name resolve - calls (depending on what your system supports): - - A - gethostbyname() - B - gethostbyname_r() with 3 arguments - C - gethostbyname_r() with 5 arguments - D - gethostbyname_r() with 6 arguments - - - The IPv6-resolver that uses getaddrinfo() - - - The c-ares based name resolver that uses the c-ares library for resolves. - Using this offers asynchronous name resolves. - - - The threaded resolver (default option on Windows). It uses: - - A - gethostbyname() on plain IPv4 hosts - B - getaddrinfo() on IPv6 enabled hosts - - Also note that libcurl never resolves or reverse-lookups addresses given as - pure numbers, such as 127.0.0.1 or ::1. - - 5.10 How do I prevent libcurl from writing the response to stdout? - - libcurl provides a default built-in write function that writes received data - to stdout. Set the CURLOPT_WRITEFUNCTION to receive the data, or possibly - set CURLOPT_WRITEDATA to a different FILE * handle. - - 5.11 How do I make libcurl not receive the whole HTTP response? - - You make the write callback (or progress callback) return an error and - libcurl will then abort the transfer. - - 5.12 Can I make libcurl fake or hide my real IP address? - - No. libcurl operates on a higher level. Besides, faking IP address would - imply sending IP packets with a made-up source address, and then you normally - get a problem with receiving the packet sent back as they would then not be - routed to you. - - If you use a proxy to access remote sites, the sites will not see your local - IP address but instead the address of the proxy. - - Also note that on many networks NATs or other IP-munging techniques are used - that makes you see and use a different IP address locally than what the - remote server will see you coming from. You may also consider using - https://www.torproject.org/ . - - 5.13 How do I stop an ongoing transfer? - - With the easy interface you make sure to return the correct error code from - one of the callbacks, but none of them are instant. There is no function you - can call from another thread or similar that will stop it immediately. - Instead, you need to make sure that one of the callbacks you use returns an - appropriate value that will stop the transfer. Suitable callbacks that you - can do this with include the progress callback, the read callback and the - write callback. - - If you are using the multi interface, you can also stop a transfer by - removing the particular easy handle from the multi stack at any moment you - think the transfer is done or when you wish to abort the transfer. - - 5.14 Using C++ non-static functions for callbacks? - - libcurl is a C library, it does not know anything about C++ member functions. - - You can overcome this "limitation" with relative ease using a static - member function that is passed a pointer to the class: - - // f is the pointer to your object. - static size_t YourClass::func(void *buffer, size_t sz, size_t n, void *f) - { - // Call non-static member function. - static_cast(f)->nonStaticFunction(); - } - - // This is how you pass pointer to the static function: - curl_easy_setopt(hcurl, CURLOPT_WRITEFUNCTION, YourClass::func); - curl_easy_setopt(hcurl, CURLOPT_WRITEDATA, this); - - 5.15 How do I get an FTP directory listing? - - If you end the FTP URL you request with a slash, libcurl will provide you - with a directory listing of that given directory. You can also set - CURLOPT_CUSTOMREQUEST to alter what exact listing command libcurl would use - to list the files. - - The follow-up question tends to be how is a program supposed to parse the - directory listing. How does it know what's a file and what's a directory and - what's a symlink etc. If the FTP server supports the MLSD command then it - will return data in a machine-readable format that can be parsed for type. - The types are specified by RFC 3659 section 7.5.1. If MLSD is not supported - then you have to work with what you are given. The LIST output format is - entirely at the server's own liking and the NLST output does not reveal any - types and in many cases does not even include all the directory entries. - Also, both LIST and NLST tend to hide unix-style hidden files (those that - start with a dot) by default so you need to do "LIST -a" or similar to see - them. - - Example - List only directories. - ftp.funet.fi supports MLSD and ftp.kernel.org does not: - - curl -s ftp.funet.fi/pub/ -X MLSD | \ - perl -lne 'print if s/(?:^|;)type=dir;[^ ]+ (.+)$/$1/' - - curl -s ftp.kernel.org/pub/linux/kernel/ | \ - perl -lne 'print if s/^d[-rwx]{9}(?: +[^ ]+){7} (.+)$/$1/' - - If you need to parse LIST output in libcurl one such existing - list parser is available at https://cr.yp.to/ftpparse.html Versions of - libcurl since 7.21.0 also provide the ability to specify a wildcard to - download multiple files from one FTP directory. - - 5.16 I want a different time-out - - Sometimes users realize that CURLOPT_TIMEOUT and CURLOPT_CONNECTIMEOUT are - not sufficiently advanced or flexible to cover all the various use cases and - scenarios applications end up with. - - libcurl offers many more ways to time-out operations. A common alternative - is to use the CURLOPT_LOW_SPEED_LIMIT and CURLOPT_LOW_SPEED_TIME options to - specify the lowest possible speed to accept before to consider the transfer - timed out. - - The most flexible way is by writing your own time-out logic and using - CURLOPT_XFERINFOFUNCTION (perhaps in combination with other callbacks) and - use that to figure out exactly when the right condition is met when the - transfer should get stopped. - - 5.17 Can I write a server with libcurl? - - No. libcurl offers no functions or building blocks to build any kind of - Internet protocol server. libcurl is only a client-side library. For server - libraries, you need to continue your search elsewhere but there exist many - good open source ones out there for most protocols you could want a server - for. There are also really good stand-alone servers that have been tested - and proven for many years. There is no need for you to reinvent them. - - 5.18 Does libcurl use threads? - - Put simply: no, libcurl will execute in the same thread you call it in. All - callbacks will be called in the same thread as the one you call libcurl in. - - If you want to avoid your thread to be blocked by the libcurl call, you make - sure you use the non-blocking multi API which will do transfers - asynchronously - still in the same single thread. - - libcurl will potentially internally use threads for name resolving, if it - was built to work like that, but in those cases it will create the child - threads by itself and they will only be used and then killed internally by - libcurl and never exposed to the outside. - -6. License Issues - - curl and libcurl are released under a MIT/X derivative license. The license - is liberal and should not impose a problem for your project. This section is - just a brief summary for the cases we get the most questions. (Parts of this - section was much enhanced by Bjorn Reese.) - - We are not lawyers and this is not legal advice. You should probably consult - one if you want true and accurate legal insights without our prejudice. Note - especially that this section concerns the libcurl license only; compiling in - features of libcurl that depend on other libraries (e.g. OpenSSL) may affect - the licensing obligations of your application. - - 6.1 I have a GPL program, can I use the libcurl library? - - Yes - - Since libcurl may be distributed under the MIT/X derivative license, it can - be used together with GPL in any software. - - 6.2 I have a closed-source program, can I use the libcurl library? - - Yes - - libcurl does not put any restrictions on the program that uses the library. - - 6.3 I have a BSD licensed program, can I use the libcurl library? - - Yes - - libcurl does not put any restrictions on the program that uses the library. - - 6.4 I have a program that uses LGPL libraries, can I use libcurl? - - Yes - - The LGPL license does not clash with other licenses. - - 6.5 Can I modify curl/libcurl for my program and keep the changes secret? - - Yes - - The MIT/X derivative license practically allows you to do almost anything - with the sources, on the condition that the copyright texts in the sources - are left intact. - - 6.6 Can you please change the curl/libcurl license to XXXX? - - No. - - We have carefully picked this license after years of development and - discussions and a large amount of people have contributed with source code - knowing that this is the license we use. This license puts the restrictions - we want on curl/libcurl and it does not spread to other programs or - libraries that use it. It should be possible for everyone to use libcurl or - curl in their projects, no matter what license they already have in use. - - 6.7 What are my obligations when using libcurl in my commercial apps? - - Next to none. All you need to adhere to is the MIT-style license (stated in - the COPYING file) which basically says you have to include the copyright - notice in "all copies" and that you may not use the copyright holder's name - when promoting your software. - - You do not have to release any of your source code. - - You do not have to reveal or make public any changes to the libcurl source - code. - - You do not have to broadcast to the world that you are using libcurl within - your app. - - All we ask is that you disclose "the copyright notice and this permission - notice" somewhere. Most probably like in the documentation or in the section - where other third party dependencies already are mentioned and acknowledged. - - As can be seen here: https://curl.se/docs/companies.html and elsewhere, - more and more companies are discovering the power of libcurl and take - advantage of it even in commercial environments. - - -7. PHP/CURL Issues - - 7.1 What is PHP/CURL? - - The module for PHP that makes it possible for PHP programs to access curl- - functions from within PHP. - - In the cURL project we call this module PHP/CURL to differentiate it from - curl the command line tool and libcurl the library. The PHP team however - does not refer to it like this (for unknown reasons). They call it plain - CURL (often using all caps) or sometimes ext/curl, but both cause much - confusion to users which in turn gives us a higher question load. - - 7.2 Who wrote PHP/CURL? - - PHP/CURL was initially written by Sterling Hughes. - - 7.3 Can I perform multiple requests using the same handle? - - Yes - at least in PHP version 4.3.8 and later (this has been known to not - work in earlier versions, but the exact version when it started to work is - unknown to me). - - After a transfer, you just set new options in the handle and make another - transfer. This will make libcurl reuse the same connection if it can. - - 7.4 Does PHP/CURL have dependencies? - - PHP/CURL is a module that comes with the regular PHP package. It depends on - and uses libcurl, so you need to have libcurl installed properly before - PHP/CURL can be used. - -8. Development - - 8.1 Why does curl use C89? - - As with everything in curl, there is a history and we keep using what we have - used before until someone brings up the subject and argues for and works on - changing it. - - We started out using C89 in the 1990s because that was the only way to write - a truly portable C program and have it run as widely as possible. C89 was for - a long time even necessary to make things work on otherwise considered modern - platforms such as Windows. Today, we do not really know how many users that - still require the use of a C89 compiler. - - We will continue to use C89 for as long as nobody brings up a strong enough - reason for us to change our minds. The core developers of the project do not - feel restricted by this and we are not convinced that going C99 will offer us - enough of a benefit to warrant the risk of cutting off a share of users. - - 8.2 Will curl be rewritten? - - In one go: no. Little by little over time? Maybe. - - Over the years, new languages and clever operating environments come and go. - Every now and then the urge apparently arises to request that we rewrite curl - in another language. - - Some the most important properties in curl are maintaining the API and ABI - for libcurl and keeping the behavior for the command line tool. As long as we - can do that, everything else is up for discussion. To maintain the ABI, we - probably have to maintain a certain amount of code in C, and to remain rock - stable, we will never risk anything by rewriting a lot of things in one go. - That said, we can certainly offer more and more optional backends written in - other languages, as long as those backends can be plugged in at build-time. - Backends can be written in any language, but should probably provide APIs - usable from C to ease integration and transition. diff --git a/third-party/curl/docs/FAQ.md b/third-party/curl/docs/FAQ.md new file mode 100644 index 0000000000..6cdf97d327 --- /dev/null +++ b/third-party/curl/docs/FAQ.md @@ -0,0 +1,1427 @@ + + +# Frequently Asked Questions + +# Philosophy + +## What is curl? + +curl is the name of the project. The name is a play on *Client for URLs*, +originally with URL spelled in uppercase to make it obvious it deals with +URLs. The fact it can also be read as *see URL* also helped, it works as an +abbreviation for *Client URL Request Library* or why not the recursive +version: *curl URL Request Library*. + +The curl project produces two products: + +### libcurl + +A client-side URL transfer library, supporting DICT, FILE, FTP, FTPS, GOPHER, +GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, +RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. + +libcurl supports HTTPS certificates, HTTP POST, HTTP PUT, FTP uploading, +Kerberos, SPNEGO, HTTP form based upload, proxies, cookies, user+password +authentication, file transfer resume, http proxy tunneling and more. + +libcurl is highly portable, it builds and works identically on numerous +platforms. The [internals document](https://curl.se/docs/install.html#Ports) +lists more than 110 operating systems and 28 CPU architectures on which curl +has been reported to run. + +libcurl is free, thread-safe, IPv6 compatible, feature-rich, well supported +and fast. + +### curl + +A command line tool for getting or sending data using URL syntax. + +Since curl uses libcurl, curl supports the same wide range of common Internet +protocols that libcurl does. + +We pronounce curl with an initial k sound. It rhymes with words like girl and +earl. [This is a short WAV +file](https://media.merriam-webster.com/soundc11/c/curl0001.wav) to help you. + +There are numerous sub-projects and related projects that also use the word +curl in the project names in various combinations, but you should take notice +that this FAQ is directed at the command-line tool named curl (and libcurl the +library), and may therefore not be valid for other curl-related projects. +(There is however a small section for the PHP/CURL in this FAQ.) + +## What is libcurl? + +libcurl is a reliable and portable library for doing Internet data transfers +using one or more of its supported Internet protocols. + +You can use libcurl freely in your application, be it open source, commercial +or closed-source. + +libcurl is most probably the most portable, most powerful and most often used +C-based multi-platform file transfer library on this planet - be it open +source or commercial. + +## What is curl not? + +curl is not a Wget clone. That is a common misconception. Never, during curl's +development, have we intended curl to replace Wget or compete on its market. +curl is targeted at single-shot file transfers. + +curl is not a website mirroring program. If you want to use curl to mirror +something: fine, go ahead and write a script that wraps around curl or use +libcurl to make it reality. + +curl is not an FTP site mirroring program. Sure, get and send FTP with curl +but if you want systematic and sequential behavior you should write a script +(or write a new program that interfaces libcurl) and do it. + +curl is not a PHP tool, even though it works perfectly well when used from or +with PHP (when using the PHP/CURL module). + +curl is not a program for a single operating system. curl exists, compiles, +builds and runs under a wide range of operating systems, including all modern +Unixes (and a bunch of older ones too), Windows, Amiga, OS/2, macOS, QNX etc. + +## When would you make curl do ... ? + +We love suggestions of what to change in order to make curl and libcurl +better. We do however believe in a few rules when it comes to the future of +curl: + +curl the command line tool is to remain a non-graphical command line tool. If +you want GUIs or fancy scripting capabilities, you should look for another +tool that uses libcurl. + +We do not add things to curl that other small and available tools already do +well at the side. curl's output can be piped into another program or +redirected to another file for the next program to interpret. + +We focus on protocol related issues and improvements. If you want to do more +with the supported protocols than curl currently does, chances are good we +would agree. If you want to add more protocols, we may agree. + +If you want someone else to do all the work while you wait for us to implement +it for you, that is not a friendly attitude. We spend a considerable time +already on maintaining and developing curl. In order to get more out of us, +you should consider trading in some of your time and effort in return. Go to +the [GitHub repository](https://github.com/curl/curl), fork the project, +and create pull requests with your proposed changes. + +If you write the code, chances are better that it gets into curl faster. + +## Who makes curl? + +curl and libcurl are not made by any single individual. Daniel Stenberg is +project leader and main developer, but other persons' submissions are +important and crucial. Anyone can contribute and post their changes and +improvements and have them inserted in the main sources (of course on the +condition that developers agree that the fixes are good). + +The full list of all contributors is found in the +[docs/THANKS](https://curl.se/docs/thanks.html) file. + +curl is developed by a community, with Daniel at the wheel. + +## What do you get for making curl? + +Project curl is entirely free and open. We do this voluntarily, mostly in our +spare time. Companies may pay individual developers to work on curl. This is +not controlled by nor supervised in any way by the curl project. + +We get help from companies. Haxx provides website, bandwidth, mailing lists +etc, GitHub hosts [the primary git repository](https://github.com/curl/curl) +and other services like the bug tracker. Also again, some companies have +sponsored certain parts of the development in the past and I hope some +continue to do so in the future. + +If you want to [support our project](https://curl.se/sponsors.html), consider +a donation or a banner-program or even better: by helping us with coding, +documenting or testing etc. + +## What about CURL from curl.com? + +During the summer of 2001, curl.com was busy advertising their client-side +programming language for the web, named CURL. + +We are in no way associated with curl.com or their CURL programming language. + +Our project name curl has been in effective use since 1998. We were not the +first computer related project to use the name *curl* and do not claim any +rights to the name. + +We recognize that we are living in parallel with curl.com and wish them +every success. + +## I have a problem, who do I mail? + +Please do not mail any single individual unless you really need to. Keep +curl-related questions on a suitable mailing list. All available mailing lists +are listed [online](https://curl.se/mail/). + +Keeping curl-related questions and discussions on mailing lists allows others +to join in and help, to share their ideas, to contribute their suggestions and +to spread their wisdom. Keeping discussions on public mailing lists also +allows for others to learn from this (both current and future users thanks to +the web based archives of the mailing lists), thus saving us from having to +repeat ourselves even more. Thanks for respecting this. + +If you have found or suspect a security problem in curl or libcurl, +[submit all the details to us](https://curl.se/dev/vuln-disclosure.html). We +keep the issue private while we investigate, confirm it, work and validate a +fix and agree on a time schedule for publication etc. That way we produce a +fix in a timely manner before the flaw is announced to the world, reducing the +impact the problem risks having on existing users. + +Security issues can also be taken to the curl security team by emailing +security at curl.se (closed list of receivers, mails are not disclosed). + +## Where do I buy commercial support for curl? + +curl is fully open source. It means you can hire any skilled engineer to fix +your curl-related problems. + +We list [available alternatives](https://curl.se/support.html). + +## How many are using curl? + +It is impossible to tell. + +We do not know how many users that knowingly have installed and use curl. + +We do not know how many users that use curl without knowing that they are in +fact using it. + +We do not know how many users that downloaded or installed curl and then never +use it. + +In 2025, we estimate that curl runs in roughly thirty billion installations +world wide. + +## Why do you not update ca-bundle.crt + +In the curl project we have decided not to attempt to keep this file updated +(or even present) since deciding what to add to a CA cert bundle is an +undertaking we have not been ready to accept, and the one we can get from +Mozilla is perfectly fine so there is no need to duplicate that work. + +Today, with many services performed over HTTPS, every operating system should +come with a default CA cert bundle that can be deemed somewhat trustworthy and +that collection (if reasonably updated) should be deemed to be a lot better +than a private curl version. + +If you want the most recent collection of CA certs that Mozilla Firefox uses, +we recommend using our online [CA certificate +service](https://curl.se/docs/caextract.html) setup for this purpose. + +## I have a problem, who can I chat with? + +There is a bunch of friendly people hanging out in the #curl channel on the +IRC network libera.chat. If you are polite and nice, chances are good that you +can get -- or provide -- help instantly. + +## curl's ECCN number? + +The US government restricts exports of software that contains or uses +cryptography. When doing so, the Export Control Classification Number (ECCN) +is used to identify the level of export control etc. + +Apache Software Foundation has [a good explanation of +ECCN](https://www.apache.org/dev/crypto.html). + +We believe curl's number might be ECCN 5D002, another possibility is 5D992. It +seems necessary to write them (the authority that administers ECCN numbers), +asking to confirm. + +Comprehensible explanations of the meaning of such numbers and how to obtain +them (resp.) are [here](https://www.bis.gov/licensing/classify-your-item) +and [here](https://www.bis.gov/licensing/classify-your-item/publicly-available-classification-information). + +An incomprehensible description of the two numbers above is available on +[bis.doc.gov](https://www.bis.doc.gov/index.php/documents/new-encryption/1653-ccl5-pt2-3) + +## How do I submit my patch? + +We strongly encourage you to submit changes and improvements directly as [pull +requests on GitHub](https://github.com/curl/curl/pulls). + +If you cannot or choose not to engage with GitHub, send your patch +to the curl-library mailing list. We are many subscribers there and there are +lots of people who can review patches, comment on them and receive them +properly. + +Many more details are found in the +[contribute](https://curl.se/dev/contribute.html) and +[internals](https://curl.se/dev/internals.html) +documents. + +## How do I port libcurl to my OS? + +Here's a rough step-by-step: + +1. copy a suitable `lib/config-*.h` file as a start to `lib/config-[youros].h` +2. edit `lib/config-[youros].h` to match your OS and setup +3. edit `lib/curl_setup.h` to include `config-[youros].h` when your OS is + detected by the preprocessor, in the style others already exist +4. compile `lib/*.c` and make them into a library + +# Install + +## configure fails when using static libraries + +You may find that configure fails to properly detect the entire dependency +chain of libraries when you provide static versions of the libraries that +configure checks for. + +The reason why static libraries are much harder to deal with is that for them +we do not get any help but the script itself must know or check what more +libraries that are needed (with shared libraries, that dependency chain is +handled automatically). This is an error-prone process and one that also tends +to vary over time depending on the release versions of the involved components +and may also differ between operating systems. + +For that reason, configure does few attempts to actually figure this out and +you are instead encouraged to set `LIBS` and `LDFLAGS` accordingly when you invoke +configure, and point out the needed libraries and set the necessary flags +yourself. + +## Does curl work with other SSL libraries? + +curl has been written to use a generic SSL function layer internally, and +that SSL functionality can then be provided by one out of many different SSL +backends. + +curl can be built to use one of the following SSL alternatives: AWS-LC, +BoringSSL, GnuTLS, LibreSSL, OpenSSL, mbedTLS, Rustls, Schannel (native +Windows), or wolfSSL. They all have their pros and cons, and we maintain +[a TLS library comparison](https://curl.se/docs/ssl-compared.html). + +## How do I upgrade curl.exe in Windows? + +The curl tool that is shipped as an integrated component of Windows 10 and +Windows 11 is managed by Microsoft. If you were to delete the file or replace +it with a newer version downloaded from [the curl +website](https://curl.se/windows/), then Windows Update ceases to work on +your system. + +There is no way to independently force an upgrade of the curl.exe that is part +of Windows other than through the regular Windows update process. There is +also nothing the curl project itself can do about this, since this is managed +and controlled entirely by Microsoft as owners of the operating system. + +You can always download and install [the latest version of curl for +Windows](https://curl.se/windows/) into a separate location. + +## Does curl support SOCKS (RFC 1928) ? + +Yes, SOCKS 4 and 5 are supported. + +# Usage + +## curl: (1) SSL is disabled, https: not supported + +If you get this output when trying to get anything from an HTTPS server, it +means that the instance of curl/libcurl that you are using was built without +support for this protocol. + +This could have happened if the configure script that was run at build time +could not find all libs and include files curl requires for SSL to work. If +the configure script fails to find them, curl is built without SSL +support. + +To get HTTPS support into a curl that was previously built but that reports +that HTTPS is not supported, you should dig through the document and logs and +check out why the configure script does not find the SSL libs and/or include +files. + +## How do I tell curl to resume a transfer? + +curl supports resumed transfers both ways on both FTP and HTTP. Try the `-C` +option. + +## Why does my posting using -F not work? + +You cannot arbitrarily use `-F` or `-d`, the choice between `-F` or `-d` +depends on the HTTP operation you need curl to do and what the web server that +receives your post expects. + +If the form you are trying to submit uses the type 'multipart/form-data', +then and only then you must use the -F type. In all the most common cases, +you should use `-d` which then causes a posting with the type +`application/x-www-form-urlencoded`. + +This is described in some detail in the +[Manual](https://curl.se/docs/tutorial.html) and [The Art Of HTTP +Scripting](https://curl.se/docs/httpscripting.html) documents, and if you do +not understand it the first time, read it again before you post questions +about this to the mailing list. Also, try reading through the mailing list +archives for old postings and questions regarding this. + +## How do I tell curl to run custom FTP commands? + +You can tell curl to perform optional commands both before and/or after a file +transfer. Study the `-Q`/`--quote` option. + +Since curl is used for file transfers, you do not normally use curl to perform +FTP commands without transferring anything. Therefore you must always specify +a URL to transfer to/from even when doing custom FTP commands, or use `-I` +which implies the *no body* option sent to libcurl. + +## How can I disable the Accept: header? + +You can change this and all internally generated headers by adding a +replacement with the `-H`/`--header` option. By adding a header with empty +contents you safely disable that one. Use `-H Accept:` to disable that +specific header. + +## Does curl support ASP, XML, XHTML or HTML version Y? + +To curl, all contents are alike. It does not matter how the page was +generated. It may be ASP, PHP, Perl, shell-script, SSI or plain HTML +files. There is no difference to curl and it does not even know what kind of +language that generated the page. + +See also the separate question about JavaScript. + +## Can I use curl to delete/rename a file through FTP? + +Yes. You specify custom FTP commands with `-Q`/`--quote`. + +One example would be to delete a file after you have downloaded it: + + curl -O ftp://example.com/coolfile -Q '-DELE coolfile' + +or rename a file after upload: + + curl -T infile ftp://example.com/dir/ -Q "-RNFR infile" -Q "-RNTO newname" + +## How do I tell curl to follow HTTP redirects? + +curl does not follow so-called redirects by default. The `Location:` header that +informs the client about this is only interpreted if you are using the +`-L`/`--location` option. As in: + + curl -L https://example.com + +Not all redirects are HTTP ones. See [Redirects work in browser but not with +curl](#redirects-work-in-browser-but-not-with-curl) + +## How do I use curl in my favorite programming language? + +Many programming languages have interfaces and bindings that allow you to use +curl without having to use the command line tool. If you are fluent in such a +language, you may prefer to use one of these interfaces instead. + +Find out more about which languages that support curl directly, and how to +install and use them, in the [libcurl section of the curl +website](https://curl.se/libcurl/). + +All the various bindings to libcurl are made by other projects and people, +outside of the curl project. The curl project itself only produces libcurl +with its plain C API. If you do not find anywhere else to ask you can ask +about bindings on the curl-library list too, but be prepared that people on +that list may not know anything about bindings. + +In December 2025 there were around **60** different [interfaces +available](https://curl.se/libcurl/bindings.html) for almost any language you +can imagine. + +## What about SOAP, WebDAV, XML-RPC or similar protocols over HTTP? + +curl adheres to the HTTP spec, which means you can play with *any* protocol +that is built on top of HTTP. Protocols such as SOAP, WebDAV and XML-RPC are +all such ones. You can use `-X` to set custom requests and -H to set custom +headers (or replace internally generated ones). + +Using libcurl of course also works and you would use the proper library +options to do the same. + +## How do I POST with a different Content-Type? + +You can always replace the internally generated headers with `-H`/`--header`. +To make a simple HTTP POST with `text/xml` as content-type, do something like: + + curl -d "datatopost" -H "Content-Type: text/xml" [URL] + +## Why do FTP-specific features over HTTP proxy fail? + +Because when you use an HTTP proxy, the protocol spoken on the network is +HTTP, even if you specify an FTP URL. This effectively means that you normally +cannot use FTP-specific features such as FTP upload and FTP quote etc. + +There is one exception to this rule, and that is if you can *tunnel through* +the given HTTP proxy. Proxy tunneling is enabled with a special option (`-p`) +and is generally not available as proxy admins usually disable tunneling to +ports other than 443 (which is used for HTTPS access through proxies). + +## Why do my single/double quotes fail? + +To specify a command line option that includes spaces, you might need to put +the entire option within quotes. Like in: + + curl -d " with spaces " example.com + +or perhaps + + curl -d ' with spaces ' example.com + +Exactly what kind of quotes and how to do this is entirely up to the shell or +command line interpreter that you are using. For most Unix shells, you can +more or less pick either single (`'`) or double (`"`) quotes. For Windows/DOS +command prompts you must use double (") quotes, and if the option string +contains inner double quotes you can escape them with a backslash. + +For Windows PowerShell the arguments are not always passed on as expected +because curl is not a PowerShell script. You may or may not be able to use +single quotes. To escape inner double quotes seems to require a +backslash-backtick escape sequence and the outer quotes as double quotes. + +Please study the documentation for your particular environment. Examples in +the curl docs use a mix of both of these as shown above. You must adjust them +to work in your environment. + +Remember that curl works and runs on more operating systems than most single +individuals have ever tried. + +## Does curl support JavaScript or PAC (automated proxy config)? + +Many webpages do stuff using embedded JavaScript. curl and libcurl have +no built-in support for that, so it is treated like any other contents. + +`.pac` files are a Netscape invention and are sometimes used by organizations +to allow them to differentiate which proxies to use. The `.pac` contents is a +JavaScript program that gets invoked by the browser and that returns the name +of the proxy to connect to. Since curl does not support JavaScript, it cannot +support .pac proxy configuration either. + +Some workarounds usually suggested to overcome this JavaScript dependency: + +Depending on the JavaScript complexity, write up a script that translates it +to another language and execute that. + +Read the JavaScript code and rewrite the same logic in another language. + +Implement a JavaScript interpreter, people have successfully used the +Mozilla JavaScript engine in the past. + +Ask your admins to stop this, for a static proxy setup or similar. + +## Can I do recursive fetches with curl? + +No. curl itself has no code that performs recursive operations, such as those +performed by Wget and similar tools. + +There exists curl using scripts with that functionality, and you can write +programs based on libcurl to do it, but the command line tool curl itself +cannot. + +## What certificates do I need when I use SSL? + +There are three different kinds of certificates to keep track of when we talk +about using SSL-based protocols (HTTPS or FTPS) using curl or libcurl. + +### Client certificate + +The server you communicate with may require that you can provide this in +order to prove that you actually are who you claim to be. If the server +does not require this, you do not need a client certificate. + +A client certificate is always used together with a private key, and the +private key has a passphrase that protects it. + +### Server certificate + +The server you communicate with has a server certificate. You can and should +verify this certificate to make sure that you are truly talking to the real +server and not a server impersonating it. + +Servers often also provide an intermediate certificate. It acts as a bridge +between a website's SSL certificate and a Certificate Authority's (CA) root +certificate, creating a "chain of trust". + +### Certificate Authority Certificate ("CA cert") + +You often have several CA certs in a CA cert bundle that can be used to verify +a server certificate that was signed by one of the authorities in the bundle. +curl does not come with a CA cert bundle but most curl installs provide one. +You can also override the default. + +Server certificate verification is enabled by default in curl and libcurl. +Server certificates that are *self-signed* or otherwise signed by a CA that +you do not have a CA cert for, cannot be verified. If the verification during +a connect fails, you are refused access. You then might have to explicitly +disable the verification to connect to the server. + +## How do I list the root directory of an FTP server? + +There are two ways. The way defined in the RFC is to use an encoded slash in +the first path part. List the `/tmp` directory like this: + + curl ftp://ftp.example.com/%2ftmp/ + +The second way is non-standard but more readable; start the path section of the +URL with a slash: + + curl ftp://ftp.example.com//tmp/ + +## Can I use curl to send a POST/PUT and not wait for a response? + +No. + +You can easily write your own program using libcurl to do such stunts. + +## How do I get HTTP from a host using a specific IP address? + +For example, you may be trying out a website installation that is not yet in +the DNS. Or you have a site using multiple IP addresses for a given host +name and you want to address a specific one out of the set. + +Set a custom `Host:` header that identifies the server name you want to reach +but use the target IP address in the URL: + + curl --header "Host: www.example.com" https://somewhere.example/ + +You can also opt to add faked hostname entries to curl with the --resolve +option. That has the added benefit to make things like redirects also work +properly. The above operation would instead be done as: + + curl --resolve www.example.com:80:127.0.0.1 https://www.example.com/ + +## How to SFTP from my user's home directory? + +Contrary to how FTP works, SFTP and SCP URLs specify the exact directory to +work with. It means that if you do not specify that you want the user's home +directory, you get the actual root directory. + +To specify a file in your user's home directory, you need to use the correct +URL syntax which for SFTP might look similar to: + + curl -O -u user:password sftp://example.com/~/file.txt + +and for SCP it is a different protocol prefix: + + curl -O -u user:password scp://example.com/~/file.txt + +## Protocol xxx not supported or disabled in libcurl + +When passing on a URL to curl to use, it may respond that the particular +protocol is not supported or disabled. The particular way this error message +is phrased is because curl does not make a distinction internally of whether a +particular protocol is not supported (i.e. never got any code added that knows +how to speak that protocol) or if it was explicitly disabled. curl can be +built to only support a given set of protocols, and the rest would then be +disabled or not supported. + +Note that this error also occurs if you pass a wrongly spelled protocol part +as in `htpts://example.com` or as in the less evident case if you prefix +the protocol part with a space as in `" https://example.com/"`. + +## curl `-X` gives me HTTP problems + +In normal circumstances, `-X` should hardly ever be used. + +By default you use curl without explicitly saying which request method to use +when the URL identifies an HTTP transfer. If you pass in a URL like `curl +https://example.com` it uses GET. If you use `-d` or `-F`, curl uses POST, +`-I` causes a HEAD and `-T` makes it a PUT. + +If for whatever reason you are not happy with these default choices that curl +does for you, you can override those request methods by specifying `-X +[WHATEVER]`. This way you can for example send a DELETE by doing +`curl -X DELETE [URL]`. + +It is thus pointless to do `curl -XGET [URL]` as GET would be used anyway. In +the same vein it is pointless to do `curl -X POST -d data [URL]`. You can make +a fun and somewhat rare request that sends a request-body in a GET request +with something like `curl -X GET -d data [URL]`. + +Note that `-X` does not actually change curl's behavior as it only modifies +the actual string sent in the request, but that may of course trigger a +different set of events. + +Accordingly, by using `-XPOST` on a command line that for example would follow +a 303 redirect, you effectively prevent curl from behaving correctly. Be aware. + +# Running + +## Why do I get problems when I use & or % in the URL? + +In general Unix shells, the & symbol is treated specially and when used, it +runs the specified command in the background. To safely send the & as a part +of a URL, you should quote the entire URL by using single (`'`) or double +(`"`) quotes around it. Similar problems can also occur on some shells with +other characters, including ?*!$~(){}<>\|;`. When in doubt, quote the URL. + +An example that would invoke a remote CGI that uses &-symbols could be: + + curl 'https://www.example.com/cgi-bin/query?text=yes&q=curl' + +In Windows, the standard DOS shell treats the percent sign specially and you +need to use TWO percent signs for each single one you want to use in the URL. + +If you want a literal percent sign to be part of the data you pass in a POST +using `-d`/`--data` you must encode it as `%25` (which then also needs the +percent sign doubled on Windows machines). + +## How can I use {, }, [ or ] to specify multiple URLs? + +Because those letters have a special meaning to the shell, to be used in a URL +specified to curl you must quote them. + +An example that downloads two URLs (sequentially) would be: + + curl '{curl,www}.haxx.se' + +To be able to use those characters as actual parts of the URL (without using +them for the curl URL *globbing* system), use the `-g`/`--globoff` option: + + curl -g 'www.example.com/weirdname[].html' + +## Why do I get downloaded data even though the webpage does not exist? + +curl asks remote servers for the page you specify. If the page does not exist +at the server, the HTTP protocol defines how the server should respond and +that means that headers and a page get returned. That is how HTTP works. + +By using the `--fail` option you can tell curl explicitly to not get any data +if the HTTP return code does not say success. + +## Why do I get return code XXX from an HTTP server? + +RFC 2616 clearly explains the return codes. This is a short transcript. Go +read the RFC for exact details: + +### 400 Bad Request + +The request could not be understood by the server due to malformed +syntax. The client SHOULD NOT repeat the request without modifications. + +### 401 Unauthorized + +The request requires user authentication. + +### 403 Forbidden + +The server understood the request, but is refusing to fulfill it. +Authorization cannot help and the request SHOULD NOT be repeated. + +### 404 Not Found + +The server has not found anything matching the Request-URI. No indication is +given as to whether the condition is temporary or permanent. + +### 405 Method Not Allowed + +The method specified in the Request-Line is not allowed for the resource +identified by the Request-URI. The response MUST include an `Allow:` header +containing a list of valid methods for the requested resource. + +### 301 Moved Permanently + +If you get this return code and an HTML output similar to this: + +

Moved Permanently

The document has moved here. + +it might be because you requested a directory URL but without the trailing +slash. Try the same operation again _with_ the trailing URL, or use the +`-L`/`--location` option to follow the redirection. + +## Can you tell me what error code 142 means? + +All curl error codes are described at the end of the man page, in the section +called **EXIT CODES**. + +Error codes that are larger than the highest documented error code means that +curl has exited due to a crash. This is a serious error, and we appreciate a +detailed bug report from you that describes how we could go ahead and repeat +this. + +## How do I keep usernames and passwords secret in curl command lines? + +This problem has two sides: + +The first part is to avoid having clear-text passwords in the command line so +that they do not appear in *ps* outputs and similar. That is easily avoided by +using the `-K` option to tell curl to read parameters from a file or stdin to +which you can pass the secret info. curl itself also attempts to hide the given +password by blanking out the option - this does not work on all platforms. + +To keep the passwords in your account secret from the rest of the world is +not a task that curl addresses. You could of course encrypt them somehow to +at least hide them from being read by human eyes, but that is not what +anyone would call security. + +Also note that regular HTTP (using Basic authentication) and FTP passwords are +sent as cleartext across the network. All it takes for anyone to fetch them is +to listen on the network. Eavesdropping is easy. Use more secure +authentication methods (like Digest, Negotiate or even NTLM) or consider the +SSL-based alternatives HTTPS and FTPS. + +## I found a bug + +It is not a bug if the behavior is documented. Read the docs first. Especially +check out the KNOWN_BUGS file, it may be a documented bug. + +If it is a problem with a binary you have downloaded or a package for your +particular platform, try contacting the person who built the package/archive +you have. + +If there is a bug, read the BUGS document first. Then report it as described +in there. + +## curl cannot authenticate to a server that requires NTLM? + +NTLM support requires OpenSSL, GnuTLS, mbedTLS or Microsoft Windows libraries +at build-time to provide this functionality. + +## My HTTP request using HEAD, PUT or DELETE does not work + +Many web servers allow or demand that the administrator configures the server +properly for these requests to work on the web server. + +Some servers seem to support HEAD only on certain kinds of URLs. + +To fully grasp this, try the documentation for the particular server software +you are trying to interact with. This is not anything curl can do anything +about. + +## Why do my HTTP range requests return the full document? + +Because the range may not be supported by the server, or the server may choose +to ignore it and return the full document anyway. + +## Why do I get "certificate verify failed" ? + +When you invoke curl and get an error 60 error back it means that curl could +not verify that the server's certificate was good. curl verifies the +certificate using the CA cert bundle and verifying for which names the +certificate has been granted. + +To completely disable the certificate verification, use `-k`. This does +however enable man-in-the-middle attacks and makes the transfer **insecure**. +We strongly advise against doing this for more than experiments. + +If you get this failure with a CA cert bundle installed and used, the server's +certificate might not be signed by one of the certificate authorities in your +CA store. It might for example be self-signed. You then correct this problem +by obtaining a valid CA cert for the server. Or again, decrease the security +by disabling this check. + +At times, you find that the verification works in your favorite browser but +fails in curl. When this happens, the reason is usually that the server sends +an incomplete cert chain. The server is mandated to send all *intermediate +certificates* but does not. This typically works with browsers anyway since +they A) cache such certs and B) supports AIA which downloads such missing +certificates on demand. This is a bad server configuration. A good way to +figure out if this is the case it to use [the SSL Labs +server](https://www.ssllabs.com/ssltest/) test and check the certificate +chain. + +Details are also in [the SSL certificates +document](https://curl.se/docs/sslcerts.html). + +## Why is curl -R on Windows one hour off? + +Since curl 7.53.0 this issue should be fixed as long as curl was built with +any modern compiler that allows for a 64-bit curl_off_t type. For older +compilers or prior curl versions it may set a time that appears one hour off. +This happens due to a flaw in how Windows stores and uses file modification +times and it is not easily worked around. For more details +[read this](https://web.archive.org/web/20050715084352/codeproject.com/datetime/dstbugs.asp). + +## Redirects work in browser but not with curl + +curl supports HTTP redirects well (see a previous question above). Browsers +generally support at least two other ways to perform redirects that curl does +not: + +Meta tags. You can write an HTML tag that causes the browser to redirect +to another given URL after a certain time. + +JavaScript. You can write a JavaScript program embedded in an HTML page that +redirects the browser to another given URL. + +There is no way to make curl follow these redirects. You must either manually +figure out what the page is set to do, or write a script that parses the +results and fetches the new URL. + +## FTPS does not work + +curl supports FTPS (sometimes known as FTP-SSL) both implicit and explicit +mode. + +When a URL is used that starts with `ftps://`, curl assumes implicit SSL on +the control connection and therefore immediately connects and tries to speak +SSL. `ftps://` connections default to port 990. + +To use explicit FTPS, you use an `ftp://` URL and the `--ssl-reqd` option (or +one of its related flavors). This is the most common method, and the one +mandated by RFC 4217. This kind of connection then of course uses the standard +FTP port 21 by default. + +## My HTTP POST or PUT requests are slow + +libcurl makes all POST and PUT requests (except for requests with a small +request body) use the `Expect: 100-continue` header. This header allows the +server to deny the operation early so that libcurl can bail out before having +to send any data. This is useful in authentication cases and others. + +Many servers do not implement the `Expect:` stuff properly and if the server +does not respond (positively) within 1 second libcurl continues and sends +off the data anyway. + +You can disable libcurl's use of the `Expect:` header the same way you disable +any header, using `-H` / `CURLOPT_HTTPHEADER`, or by forcing it to use HTTP +1.0. + +## Non-functional connect timeouts + +In most Windows setups having a timeout longer than 21 seconds makes no +difference, as it only sends 3 TCP SYN packets and no more. The second +packet sent three seconds after the first and the third six seconds after +the second. No more than three packets are sent, no matter how long the +timeout is set. + +See Windows option `TcpMaxConnectRetransmissions` for more. + +Also, even on non-Windows systems there may run a firewall or anti-virus +software or similar that accepts the connection but does not actually do +anything else. This makes (lib)curl to consider the connection connected +and thus the connect timeout does not trigger. + +## `file://` URLs containing drive letters (Windows, NetWare) + +When using curl to try to download a local file, one might use a URL in this +format: + + file://D:/blah.txt + +you find that even if `D:\blah.txt` does exist, curl returns a 'file not +found' error. + +According to [RFC 1738](https://datatracker.ietf.org/doc/html/rfc1738), +`file://` URLs must contain a host component, but it is ignored by most +implementations. In the above example, `D:` is treated as the host component, +and is taken away. Thus, curl tries to open `/blah.txt`. If your system is +installed to drive C:, that resolves to `C:\blah.txt`, and if that does +not exist you get the not found error. + +To fix this problem, use `file://` URLs with *three* leading slashes: + + file:///D:/blah.txt + +Alternatively, if it makes more sense, specify `localhost` as the host +component: + + file://localhost/D:/blah.txt + +In either case, curl should now be looking for the correct file. + +## Why does not curl return an error when the network cable is unplugged? + +Unplugging a cable is not an error situation. The TCP/IP protocol stack was +designed to be fault tolerant, so even though there may be a physical break +somewhere the connection should not be affected, but possibly delayed. +Eventually, the physical break gets fixed or the data re-routed around +the physical problem through another path. + +In such cases, the TCP/IP stack is responsible for detecting when the network +connection is irrevocably lost. Since with some protocols it is perfectly +legal for the client to wait indefinitely for data, the stack may never report +a problem, and even when it does, it can take up to 20 minutes for it to +detect an issue. The curl option `--keepalive-time` enables keep-alive support +in the TCP/IP stack which makes it periodically probe the connection to make +sure it is still available to send data. That should reliably detect any +TCP/IP network failure. + +TCP keep alive does not detect the network going down before the TCP/IP +connection is established (e.g. during a DNS lookup) or using protocols that +do not use TCP. To handle those situations, curl offers a number of timeouts +on its own. `--speed-limit`/`--speed-time` aborts if the data transfer rate +falls too low, and `--connect-timeout` and `--max-time` can be used to put +an overall timeout on the connection phase or the entire transfer. + +A libcurl-using application running in a known physical environment (e.g. an +embedded device with only a single network connection) may want to act +immediately if its lone network connection goes down. That can be achieved by +having the application monitor the network connection on its own using an +OS-specific mechanism, then signaling libcurl to abort. + +## curl does not return error for HTTP non-200 responses + +Correct. Unless you use `-f` (`--fail`) or `--fail-with-body`. + +When doing HTTP transfers, curl performs exactly what you are asking it to +do and if successful it does not return an error. You can use curl to test +your web server's "file not found" page (that gets 404 back), you can use it +to check your authentication protected webpages (that gets a 401 back) and so +on. + +The specific HTTP response code does not constitute a problem or error for +curl. It sends and delivers HTTP as you asked and if that worked, +everything is fine and dandy. The response code is generally providing more +higher level error information that curl does not care about. The error was +not in the HTTP transfer. + +If you want your command line to treat error codes in the 400 and up range as +errors and thus return a non-zero value and possibly show an error message, +curl has a dedicated option for that: `-f` (`CURLOPT_FAILONERROR` in libcurl +speak). + +You can also use the `-w` option and the variable `%{response_code}` to +extract the exact response code that was returned in the response. + +# libcurl + +## Is libcurl thread-safe? + +Yes. + +We have written the libcurl code specifically adjusted for multi-threaded +programs. libcurl uses thread-safe functions instead of non-safe ones if your +system has such. Note that you must never share the same handle in multiple +threads. + +There may be some exceptions to thread-safety depending on how libcurl was +built. Please review [the guidelines for thread +safety](https://curl.se/libcurl/c/threadsafe.html) to learn more. + +## How can I receive all data into a large memory chunk? + +(See the [get in memory](https://curl.se/libcurl/c/getinmemory.html) example.) + +You are in full control of the callback function that gets called every time +there is data received from the remote server. You can make that callback do +whatever you want. You do not have to write the received data to a file. + +One solution to this problem could be to have a pointer to a struct that you +pass to the callback function. You set the pointer using the CURLOPT_WRITEDATA +option. Then that pointer is passed to the callback instead of a FILE * +to a file: + +~~~c +/* store data this struct */ +struct MemoryStruct { + char *memory; + size_t size; +}; + +/* imaginary callback function */ +size_t +WriteMemoryCallback(void *ptr, size_t size, size_t nmemb, void *data) +{ + size_t realsize = size * nmemb; + struct MemoryStruct *mem = (struct MemoryStruct *)data; + + mem->memory = realloc(mem->memory, mem->size + realsize + 1); + if(mem->memory) { + memcpy(&(mem->memory[mem->size]), ptr, realsize); + mem->size += realsize; + mem->memory[mem->size] = 0; + } + return realsize; +} +~~~ + +## How do I fetch multiple files with libcurl? + +libcurl has excellent support for transferring multiple files. You should +repeatedly set new URLs with `curl_easy_setopt()` and then transfer it with +`curl_easy_perform()`. The handle you get from curl_easy_init() is not only +reusable, but you are even encouraged to reuse it if you can, as that +enables libcurl to use persistent connections. + +## Does libcurl do Winsock initialization on Win32 systems? + +Yes, if told to in the `curl_global_init()` call. + +## Does CURLOPT_WRITEDATA and CURLOPT_READDATA work on Win32 ? + +Yes, but you cannot open a FILE * and pass the pointer to a DLL and have that +DLL use the FILE * (as the DLL and the client application cannot access each +others' variable memory areas). If you set `CURLOPT_WRITEDATA` you must also use +`CURLOPT_WRITEFUNCTION` as well to set a function that writes the file, even if +all it does is write the data to the specified FILE *. Similarly, if you use +`CURLOPT_READDATA` you must also specify `CURLOPT_READFUNCTION`. + +## What about Keep-Alive or persistent connections? + +curl and libcurl have excellent support for persistent connections when +transferring several files from the same server. curl attempts to reuse +connections for all URLs specified on the same command line/config file, and +libcurl reuses connections for all transfers that are made using the same +libcurl handle. + +When you use the easy interface the connection cache is kept within the easy +handle. If you instead use the multi interface, the connection cache is kept +within the multi handle and shared among all the easy handles that are used +within the same multi handle. + +## Link errors when building libcurl on Windows + +You need to make sure that your project, and all the libraries (both static +and dynamic) that it links against, are compiled/linked against the same run +time library. + +This is determined by the `/MD`, `/ML`, `/MT` (and their corresponding `/M?d`) +options to the command line compiler. `/MD` (linking against `MSVCRT.dll`) +seems to be the most commonly used option. + +When building an application that uses the static libcurl library, you must +add `-DCURL_STATICLIB` to your `CFLAGS`. Otherwise the linker looks for +dynamic import symbols. If you are using Visual Studio, you need to instead +add `CURL_STATICLIB` in the "Preprocessor Definitions" section. + +If you get a linker error like `unknown symbol __imp__curl_easy_init ...` you +have linked against the wrong (static) library. If you want to use the +libcurl.dll and import lib, you do not need any extra `CFLAGS`, but use one of +the import libraries below. These are the libraries produced by the various +lib/Makefile.* files: + +| Target | static lib | import lib for DLL | +|----------------|----------------|--------------------| +| MinGW | `libcurl.a` | `libcurldll.a` | +| MSVC (release) | `libcurl.lib` | `libcurl_imp.lib` | +| MSVC (debug) | `libcurld.lib` | `libcurld_imp.lib` | + +## libcurl.so.X: open failed: No such file or directory + +This is an error message you might get when you try to run a program linked +with a shared version of libcurl and your runtime linker (`ld.so`) could not +find the shared library named `libcurl.so.X`. (Where X is the number of the +current libcurl ABI, typically 3 or 4). + +You need to make sure that `ld.so` finds `libcurl.so.X`. You can do that +multiple ways, and it differs somewhat between different operating systems. +They are usually: + +* Add an option to the linker command line that specify the hard-coded path + the runtime linker should check for the lib (usually `-R`) +* Set an environment variable (`LD_LIBRARY_PATH` for example) where `ld.so` + should check for libs +* Adjust the system's config to check for libs in the directory where you have + put the library (like Linux's `/etc/ld.so.conf`) + +`man ld.so` and `man ld` tells you more details + +## How does libcurl resolve hostnames? + +libcurl supports a large number of name resolve functions. One of them is +picked at build-time and used unconditionally. Thus, if you want to change +name resolver function you must rebuild libcurl and tell it to use +a different function. + +### The non-IPv6 resolver + +The non-IPv6 resolver that can use one of four different hostname resolve +calls depending on what your system supports: + +1. gethostbyname() +2. gethostbyname_r() with 3 arguments +3. gethostbyname_r() with 5 arguments +4. gethostbyname_r() with 6 arguments + +### The IPv6 resolver + +Uses getaddrinfo() + +### The cares resolver + +The c-ares based name resolver that uses the c-ares library for resolves. +Using this offers asynchronous name resolves. + +## The threaded resolver + +It uses the IPv6 or the non-IPv6 resolver solution in a temporary thread. + +## How do I prevent libcurl from writing the response to stdout? + +libcurl provides a default built-in write function that writes received data +to stdout. Set the `CURLOPT_WRITEFUNCTION` to receive the data, or possibly +set `CURLOPT_WRITEDATA` to a different FILE * handle. + +## How do I make libcurl not receive the whole HTTP response? + +You make the write callback (or progress callback) return an error and libcurl +then aborts the transfer. + +## Can I make libcurl fake or hide my real IP address? + +No. libcurl operates on a higher level. Besides, faking IP address would +imply sending IP packets with a made-up source address, and then you normally +get a problem with receiving the packet sent back as they would then not be +routed to you. + +If you use a proxy to access remote sites, the sites do not see your local +IP address but instead the address of the proxy. + +Also note that on many networks NATs or other IP-munging techniques are used +that makes you see and use a different IP address locally than what the remote +server is seeing you coming from. You may also consider using +[Tor](https://www.torproject.org/). + +## How do I stop an ongoing transfer? + +With the easy interface you make sure to return the correct error code from +one of the callbacks, but none of them are instant. There is no function you +can call from another thread or similar that stops it immediately. +Instead, you need to make sure that one of the callbacks you use returns an +appropriate value that stops the transfer. Suitable callbacks that you can +do this with include the progress callback, the read callback and the write +callback. + +If you are using the multi interface, you can also stop a transfer by removing +the particular easy handle from the multi stack at any moment you think the +transfer is done or when you wish to abort the transfer. + +## Using C++ non-static functions for callbacks? + +libcurl is a C library, it does not know anything about C++ member functions. + +You can overcome this limitation with relative ease using a static member +function that is passed a pointer to the class: + +~~~c++ +// f is the pointer to your object. +static size_t YourClass::func(char *buffer, size_t sz, size_t n, void *f) +{ + // Call non-static member function. + static_cast(f)->nonStaticFunction(); +} + +// This is how you pass pointer to the static function: +curl_easy_setopt(hcurl, CURLOPT_WRITEFUNCTION, YourClass::func); +curl_easy_setopt(hcurl, CURLOPT_WRITEDATA, this); +~~~ + +## How do I get an FTP directory listing? + +If you end the FTP URL you request with a slash, libcurl provides you with +a directory listing of that given directory. You can also set +`CURLOPT_CUSTOMREQUEST` to alter what exact listing command libcurl would use +to list the files. + +The follow-up question tends to be how is a program supposed to parse the +directory listing. How does it know what's a file and what's a directory and +what's a symlink etc. If the FTP server supports the `MLSD` command then it +returns data in a machine-readable format that can be parsed for type. The +types are specified by RFC 3659 section 7.5.1. If `MLSD` is not supported then +you have to work with what you are given. The `LIST` output format is entirely +at the server's own liking and the `NLST` output does not reveal any types and +in many cases does not even include all the directory entries. Also, both +`LIST` and `NLST` tend to hide Unix-style hidden files (those that start with +a dot) by default so you need to do `LIST -a` or similar to see them. + +Example - List only directories. `ftp.funet.fi` supports `MLSD` and +`ftp.kernel.org` does not: + + curl -s ftp.funet.fi/pub/ -X MLSD | \ + perl -lne 'print if s/(?:^|;)type=dir;[^ ]+ (.+)$/$1/' + + curl -s ftp.kernel.org/pub/linux/kernel/ | \ + perl -lne 'print if s/^d[-rwx]{9}(?: +[^ ]+){7} (.+)$/$1/' + +If you need to parse LIST output, libcurl provides the ability to specify a +wildcard to download multiple files from an FTP directory. + +## I want a different time-out + +Sometimes users realize that `CURLOPT_TIMEOUT` and `CURLOPT_CONNECTIMEOUT` are +not sufficiently advanced or flexible to cover all the various use cases and +scenarios applications end up with. + +libcurl offers many more ways to time-out operations. A common alternative is +to use the `CURLOPT_LOW_SPEED_LIMIT` and `CURLOPT_LOW_SPEED_TIME` options to +specify the lowest possible speed to accept before to consider the transfer +timed out. + +The most flexible way is by writing your own time-out logic and using +`CURLOPT_XFERINFOFUNCTION` (perhaps in combination with other callbacks) and +use that to figure out exactly when the right condition is met when the +transfer should get stopped. + +## Can I write a server with libcurl? + +No. libcurl offers no functions or building blocks to build any kind of +Internet protocol server. libcurl is only a client-side library. For server +libraries, you need to continue your search elsewhere but there exist many +good open source ones out there for most protocols you could want a server +for. There are also really good stand-alone servers that have been tested and +proven for many years. There is no need for you to reinvent them. + +## Does libcurl use threads? + +No, libcurl executes in the same thread you call it in. All callbacks are +called in the same thread as the one you call libcurl in. + +If you want to avoid your thread to be blocked by the libcurl call, you make +sure you use the non-blocking multi API which does transfers +asynchronously - still in the same single thread. + +libcurl does potentially internally use threads for name resolving, if it was +built to work like that, but in those cases it creates the child threads by +itself and they are only used and then killed internally by libcurl and never +exposed to the outside. + +# License + +curl and libcurl are released under an MIT/X derivative license. The license +is liberal and should not impose a problem for your project. This section is a +brief summary for the cases we get the most questions. + +We are not lawyers and this is not legal advice. You should probably consult +one if you want true and accurate legal insights without our prejudice. Note +especially that this section concerns the libcurl license only; compiling in +features of libcurl that depend on other libraries (e.g. OpenSSL) may affect +the licensing obligations of your application. + +## I have a GPL program, can I use the libcurl library? + +Yes + +Since libcurl may be distributed under the MIT/X derivative license, it can be +used together with GPL in any software. + +## I have a closed-source program, can I use the libcurl library? + +Yes + +libcurl does not put any restrictions on the program that uses the library. + +## I have a BSD licensed program, can I use the libcurl library? + +Yes + +libcurl does not put any restrictions on the program that uses the library. + +## I have a program that uses LGPL libraries, can I use libcurl? + +Yes + +The LGPL license does not clash with other licenses. + +## Can I modify curl/libcurl for my program and keep the changes secret? + +Yes + +The MIT/X derivative license practically allows you to do almost anything with +the sources, on the condition that the copyright texts in the sources are left +intact. + +## Can you please change the curl/libcurl license? + +No. + +We have carefully picked this license after years of development and +discussions and a large amount of people have contributed with source code +knowing that this is the license we use. This license puts the restrictions we +want on curl/libcurl and it does not spread to other programs or libraries +that use it. It should be possible for everyone to use libcurl or curl in +their projects, no matter what license they already have in use. + +## What are my obligations when using libcurl in my commercial apps? + +Next to none. All you need to adhere to is the MIT-style license (stated in +the COPYING file) which says you have to include the copyright notice in *all +copies* and that you may not use the copyright holder's name when promoting +your software. + +You do not have to release any of your source code. + +You do not have to reveal or make public any changes to the libcurl source +code. + +You do not have to broadcast to the world that you are using libcurl within +your app. + +All we ask is that you disclose *the copyright notice and this permission +notice* somewhere. Most probably like in the documentation or in the section +where other third party dependencies already are mentioned and acknowledged. + +As can be seen [here](https://curl.se/docs/companies.html) and elsewhere, more +and more companies are discovering the power of libcurl and take advantage of +it even in commercial environments. + +## What license does curl use exactly? + +curl is released under an [MIT derivative +license](https://curl.se/docs/copyright.html). It is similar but not identical +to the MIT license. + +The difference is considered big enough to make SPDX list it under its own +identifier: [curl](https://spdx.org/licenses/curl.html). + +The changes done to the license that make it uniquely curl were tiny and +well-intended, but the reasons for them have been forgotten and we strongly +discourage others from doing the same thing. + +# PHP/CURL + +## What is PHP/CURL? + +The module for PHP that makes it possible for PHP programs to access curl +functions from within PHP. + +In the curl project we call this module PHP/CURL to differentiate it from curl +the command line tool and libcurl the library. The PHP team however does not +refer to it like this (for unknown reasons). They call it plain CURL (often +using all caps) or sometimes ext/curl, but both cause much confusion to users +which in turn gives us a higher question load. + +## Who wrote PHP/CURL? + +PHP/CURL was initially written by Sterling Hughes. + +## Can I perform multiple requests using the same handle? + +Yes. + +After a transfer, you set new options in the handle and make another transfer. +This makes libcurl reuse the same connection if it can. + +## Does PHP/CURL have dependencies? + +PHP/CURL is a module that comes with the regular PHP package. It depends on +and uses libcurl, so you need to have libcurl installed properly before +PHP/CURL can be used. + +# Development + +## Why does curl use C89? + +As with everything in curl, there is a history and we keep using what we have +used before until someone brings up the subject and argues for and works on +changing it. + +We started out using C89 in the 1990s because that was the only way to write a +truly portable C program and have it run as widely as possible. C89 was for a +long time even necessary to make things work on otherwise considered modern +platforms such as Windows. Today, we do not really know how many users that +still require the use of a C89 compiler. + +We continue to use C89 for as long as nobody brings up a strong enough reason +for us to change our minds. The core developers of the project do not feel +restricted by this and we are not convinced that going C99 offers us enough +of a benefit to warrant the risk of cutting off a share of users. + +## Would curl be rewritten? + +In one go: no. Little by little over time? Sure. + +Over the years, new languages and clever operating environments come and go. +Every now and then the urge apparently arises to request that we rewrite curl +in another language. + +Some the most important properties in curl are maintaining the API and ABI for +libcurl and keeping the behavior for the command line tool. As long as we can +do that, everything else is up for discussion. To maintain the ABI, we +probably have to maintain a certain amount of code in C, and to remain rock +stable, we never risk anything by rewriting a lot of things in one go. +That said, we can certainly offer more and more optional backends written in +other languages, as long as those backends can be plugged in at build-time. +Backends can be written in any language, but should probably provide APIs +usable from C to ease integration and transition. diff --git a/third-party/curl/docs/FEATURES.md b/third-party/curl/docs/FEATURES.md index 9f763d3a70..a7f1845056 100644 --- a/third-party/curl/docs/FEATURES.md +++ b/third-party/curl/docs/FEATURES.md @@ -1,219 +1,249 @@ + + # Features -- what curl can do ## curl tool - - config file support - - multiple URLs in a single command line - - range "globbing" support: [0-13], {one,two,three} - - multiple file upload on a single command line - - custom maximum transfer rate - - redirect stderr - - parallel transfers +- config file support +- multiple URLs in a single command line +- range "globbing" support: [0-13], {one,two,three} +- multiple file upload on a single command line +- redirect stderr +- parallel transfers ## libcurl - - full URL syntax with no length limit - - custom maximum download time - - custom least download speed acceptable - - custom output result after completion - - guesses protocol from host name unless specified - - uses .netrc - - progress bar with time statistics while downloading - - "standard" proxy environment variables support - - compiles on win32 (reported builds on 70+ operating systems) - - selectable network interface for outgoing traffic - - IPv6 support on Unix and Windows - - happy eyeballs dual-stack connects - - persistent connections - - SOCKS 4 + 5 support, with or without local name resolving - - supports user name and password in proxy environment variables - - operations through HTTP proxy "tunnel" (using CONNECT) - - replaceable memory functions (malloc, free, realloc, etc) - - asynchronous name resolving (6) - - both a push and a pull style interface - - international domain names (10) +- URL RFC 3986 syntax +- custom maximum download time +- custom lowest download speed acceptable +- custom output result after completion +- guesses protocol from hostname unless specified +- supports .netrc +- progress bar with time statistics while downloading +- standard proxy environment variables support +- have run on 101 operating systems and 28 CPU architectures +- selectable network interface for outgoing traffic +- IPv6 support on Unix and Windows +- happy eyeballs dual-stack IPv4 + IPv6 connects +- persistent connections +- SOCKS 4 + 5 support, with or without local name resolving +- *pre-proxy* support, for *proxy chaining* +- supports username and password in proxy environment variables +- operations through HTTP proxy "tunnel" (using CONNECT) +- replaceable memory functions (malloc, free, realloc, etc) +- asynchronous name resolving +- both a push and a pull style interface +- international domain names (IDN) +- transfer rate limiting +- stable API and ABI +- TCP keep alive +- TCP Fast Open +- DNS cache (that can be shared between transfers) +- non-blocking single-threaded parallel transfers +- Unix domain sockets to server or proxy +- DNS-over-HTTPS +- uses non-blocking name resolves +- selectable name resolver backend + +## URL API + +- parses RFC 3986 URLs +- generates URLs from individual components +- manages "redirects" + +## Header API + +- easy access to HTTP response headers, from all contexts +- named headers +- iterate over headers + +## TLS + +- selectable TLS backend(s) +- TLS False Start +- TLS version control +- TLS session resumption +- key pinning +- mutual authentication +- Use dedicated CA cert bundle +- Use OS-provided CA store +- separate TLS options for HTTPS proxy ## HTTP - - HTTP/0.9 responses are optionally accepted - - HTTP/1.0 - - HTTP/1.1 - - HTTP/2, including multiplexing and server push (5) - - GET - - PUT - - HEAD - - POST - - multipart formpost (RFC 1867-style) - - authentication: Basic, Digest, NTLM (9) and Negotiate (SPNEGO) (3) - to server and proxy - - resume (both GET and PUT) - - follow redirects - - maximum amount of redirects to follow - - custom HTTP request - - cookie get/send fully parsed - - reads/writes the Netscape cookie file format - - custom headers (replace/remove internally generated headers) - - custom user-agent string - - custom referrer string - - range - - proxy authentication - - time conditions - - via HTTP proxy, HTTPS proxy or SOCKS proxy - - retrieve file modification date - - Content-Encoding support for deflate and gzip - - "Transfer-Encoding: chunked" support in uploads - - automatic data compression (11) +- HTTP/0.9 responses are optionally accepted +- HTTP/1.0 +- HTTP/1.1 +- HTTP/2, including multiplexing and server push +- GET +- PUT +- HEAD +- POST +- multipart formpost (RFC 1867-style) +- authentication: Basic, Digest, NTLM (9) and Negotiate (SPNEGO) + to server and proxy +- resume transfers +- follow redirects +- maximum amount of redirects to follow +- custom HTTP request +- cookie get/send fully parsed +- reads/writes the Netscape cookie file format +- custom headers (replace/remove internally generated headers) +- custom user-agent string +- custom referrer string +- range +- proxy authentication +- time conditions +- via HTTP proxy, HTTPS proxy or SOCKS proxy +- HTTP/2 or HTTP/1.1 to HTTPS proxy +- retrieve file modification date +- Content-Encoding support for deflate, gzip, brotli and zstd +- "Transfer-Encoding: chunked" support in uploads +- HSTS +- alt-svc +- ETags +- HTTP/1.1 trailers, both sending and getting -## HTTPS (1) +## HTTPS - - (all the HTTP features) - - HTTP/3 experimental support - - using client certificates - - verify server certificate - - via HTTP proxy, HTTPS proxy or SOCKS proxy - - select desired encryption - - select usage of a specific SSL version +- HTTP/3 +- using client certificates +- verify server certificate +- via HTTP proxy, HTTPS proxy or SOCKS proxy +- select desired encryption +- select usage of a specific TLS version +- ECH ## FTP - - download - - authentication - - Kerberos 5 (12) - - active/passive using PORT, EPRT, PASV or EPSV - - single file size information (compare to HTTP HEAD) - - 'type=' URL support - - dir listing - - dir listing names-only - - upload - - upload append - - upload via http-proxy as HTTP PUT - - download resume - - upload resume - - custom ftp commands (before and/or after the transfer) - - simple "range" support - - via HTTP proxy, HTTPS proxy or SOCKS proxy - - all operations can be tunneled through proxy - - customizable to retrieve file modification date - - no dir depth limit +- download +- authentication +- Kerberos 5 +- active/passive using PORT, EPRT, PASV or EPSV +- single file size information (compare to HTTP HEAD) +- 'type=' URL support +- directory listing +- directory listing names-only +- upload +- upload append +- upload via http-proxy as HTTP PUT +- download resume +- upload resume +- custom ftp commands (before and/or after the transfer) +- simple "range" support +- via HTTP proxy, HTTPS proxy or SOCKS proxy +- all operations can be tunneled through proxy +- customizable to retrieve file modification date +- no directory depth limit -## FTPS (1) +## FTPS - - implicit `ftps://` support that use SSL on both connections - - explicit "AUTH TLS" and "AUTH SSL" usage to "upgrade" plain `ftp://` - connection to use SSL for both or one of the connections +- implicit `ftps://` support that use SSL on both connections +- explicit "AUTH TLS" and "AUTH SSL" usage to "upgrade" plain `ftp://` + connection to use SSL for both or one of the connections -## SCP (8) +## SSH (both SCP and SFTP) - - both password and public key auth +- selectable SSH backend +- known hosts support +- public key fingerprinting +- both password and public key auth -## SFTP (7) +## SFTP - - both password and public key auth - - with custom commands sent before/after the transfer +- both password and public key auth +- with custom commands sent before/after the transfer +- directory listing ## TFTP - - download - - upload +- download +- upload ## TELNET - - connection negotiation - - custom telnet options - - stdin/stdout I/O +- connection negotiation +- custom telnet options +- stdin/stdout I/O -## LDAP (2) +## LDAP - - full LDAP URL support +- full LDAP URL support ## DICT - - extended DICT URL support +- extended DICT URL support ## FILE - - URL support - - upload - - resume +- URL support +- upload +- resume ## SMB - - SMBv1 over TCP and SSL - - download - - upload - - authentication with NTLMv1 +- SMBv1 over TCP and SSL +- download +- upload +- authentication with NTLMv1 ## SMTP - - authentication: Plain, Login, CRAM-MD5, Digest-MD5, NTLM (9), Kerberos 5 - (4) and External. - - send emails - - mail from support - - mail size support - - mail auth support for trusted server-to-server relaying - - multiple recipients - - via http-proxy +- authentication: Plain, Login, CRAM-MD5, Digest-MD5, NTLM, Kerberos 5 and + External +- send emails +- mail from support +- mail size support +- mail auth support for trusted server-to-server relaying +- multiple recipients +- via http-proxy -## SMTPS (1) +## SMTPS - - implicit `smtps://` support - - explicit "STARTTLS" usage to "upgrade" plain `smtp://` connections to use SSL - - via http-proxy +- implicit `smtps://` support +- explicit "STARTTLS" usage to "upgrade" plain `smtp://` connections to use SSL +- via http-proxy ## POP3 - - authentication: Clear Text, APOP and SASL - - SASL based authentication: Plain, Login, CRAM-MD5, Digest-MD5, NTLM (9), - Kerberos 5 (4) and External. - - list emails - - retrieve emails - - enhanced command support for: CAPA, DELE, TOP, STAT, UIDL and NOOP via - custom requests - - via http-proxy +- authentication: Clear Text, APOP and SASL +- SASL based authentication: Plain, Login, CRAM-MD5, Digest-MD5, NTLM, + Kerberos 5 and External +- list emails +- retrieve emails +- enhanced command support for: CAPA, DELE, TOP, STAT, UIDL and NOOP via + custom requests +- via http-proxy -## POP3S (1) +## POP3S - - implicit `pop3s://` support - - explicit `STLS` usage to "upgrade" plain `pop3://` connections to use SSL - - via http-proxy +- implicit `pop3s://` support +- explicit `STLS` usage to "upgrade" plain `pop3://` connections to use SSL +- via http-proxy ## IMAP - - authentication: Clear Text and SASL - - SASL based authentication: Plain, Login, CRAM-MD5, Digest-MD5, NTLM (9), - Kerberos 5 (4) and External. - - list the folders of a mailbox - - select a mailbox with support for verifying the `UIDVALIDITY` - - fetch emails with support for specifying the UID and SECTION - - upload emails via the append command - - enhanced command support for: EXAMINE, CREATE, DELETE, RENAME, STATUS, - STORE, COPY and UID via custom requests - - via http-proxy +- authentication: Clear Text and SASL +- SASL based authentication: Plain, Login, CRAM-MD5, Digest-MD5, NTLM, + Kerberos 5 and External +- list the folders of a mailbox +- select a mailbox with support for verifying the `UIDVALIDITY` +- fetch emails with support for specifying the UID and SECTION +- upload emails via the append command +- enhanced command support for: EXAMINE, CREATE, DELETE, RENAME, STATUS, + STORE, COPY and UID via custom requests +- via http-proxy -## IMAPS (1) +## IMAPS - - implicit `imaps://` support - - explicit "STARTTLS" usage to "upgrade" plain `imap://` connections to use SSL - - via http-proxy +- implicit `imaps://` support +- explicit "STARTTLS" usage to "upgrade" plain `imap://` connections to use SSL +- via http-proxy ## MQTT - - Subscribe to and publish topics using URL scheme `mqtt://broker/topic` - -## Footnotes - - 1. requires a TLS library - 2. requires OpenLDAP or WinLDAP - 3. requires a GSS-API implementation (such as Heimdal or MIT Kerberos) or - SSPI (native Windows) - 4. requires a GSS-API implementation, however, only Windows SSPI is - currently supported - 5. requires nghttp2 - 6. requires c-ares - 7. requires libssh2, libssh or wolfSSH - 8. requires libssh2 or libssh - 9. requires OpenSSL, GnuTLS, mbedTLS, Secure Transport or SSPI - (native Windows) - 10. requires libidn2 or Windows - 11. requires libz, brotli and/or zstd - 12. requires a GSS-API implementation (such as Heimdal or MIT Kerberos) +- Subscribe to and publish topics using URL scheme `mqtt://broker/topic` diff --git a/third-party/curl/docs/GOVERNANCE.md b/third-party/curl/docs/GOVERNANCE.md index dd09de4563..bae06009b9 100644 --- a/third-party/curl/docs/GOVERNANCE.md +++ b/third-party/curl/docs/GOVERNANCE.md @@ -1,3 +1,9 @@ + + # Decision making in the curl project A rough guide to how we make decisions and who does what. @@ -10,13 +16,12 @@ BDFL (Benevolent Dictator For Life) style project. This setup has been used due to convenience and the fact that it has worked fine this far. It is not because someone thinks of it as a superior project -leadership model. It will also only continue working as long as Daniel manages -to listen in to what the project and the general user population wants and -expects from us. +leadership model. It also only works as long as Daniel manages to listen in to +what the project and the general user population wants and expects from us. ## Legal entity -There is no legal entity. The curl project is just a bunch of people scattered +There is no legal entity. The curl project is a bunch of people scattered around the globe with the common goal to produce source code that creates great products. We are not part of any umbrella organization and we are not located in any specific country. We are totally independent. @@ -29,21 +34,20 @@ that wrote those parts of the code. The curl project is not a democracy, but everyone is entitled to state their opinion and may argue for their sake within the community. -All and any changes that have been done or will be done are eligible to bring -up for discussion, to object to or to praise. Ideally, we find consensus for -the appropriate way forward in any given situation or challenge. +All and any changes that have been done or are done are eligible to bring up +for discussion, to object to or to praise. Ideally, we find consensus for the +appropriate way forward in any given situation or challenge. If there is no obvious consensus, a maintainer who's knowledgeable in the -specific area will take an "executive" decision that they think is the right -for the project. +specific area takes an "executive" decision that they think is the right for +the project. ## Donations Donating plain money to curl is best done to curl's [Open Collective fund](https://opencollective.com/curl). Open Collective is a US based -non-profit organization that holds on to funds for us. This fund is then used -for paying the curl security bug bounties, to reimburse project related -expenses etc. +non-profit organization that holds on to funds for us. This fund is used to +reimburse and pay for project related expenses etc. Donations to the project can also come in the form of server hosting, providing services and paying for people to work on curl related code etc. Usually, such @@ -57,7 +61,7 @@ they can be mentioned on the Sponsors page on the curl website. The curl project does not do or offer commercial support. It only hosts mailing lists, runs bug trackers etc to facilitate communication and work. -However, Daniel works for wolfSSL and we offer commercial curl support there. +Daniel works for wolfSSL, which offers commercial curl support. # Key roles @@ -81,17 +85,17 @@ curl source code repository. Committers are recorded as `Author` in git. A maintainer in the curl project is an individual who has been given permissions to push commits to one of the git repositories. -Maintainers are free to push commits to the repositories at their own will. +Maintainers are free to push commits to the repositories at they see fit. Maintainers are however expected to listen to feedback from users and any change that is non-trivial in size or nature *should* be brought to the project as a Pull-Request (PR) to allow others to comment/object before merge. ## Former maintainers -A maintainer who stops being active in the project will at some point get -their push permissions removed. We do this for security reasons but also to -make sure that we always have the list of maintainers as "the team that push -stuff to curl". +A maintainer who stops being active in the project gets their push permissions +removed at some point. We do this for security reasons but also to make sure +that we always have the list of maintainers as "the team that push stuff to +curl". Getting push permissions removed is not a punishment. Everyone who ever worked on maintaining curl is considered a hero, for all time hereafter. @@ -100,13 +104,29 @@ on maintaining curl is considered a hero, for all time hereafter. We have a security team. That is the team of people who are subscribed to the curl-security mailing list; the receivers of security reports from users and -developers. This list of people will vary over time but should be skilled +developers. This list of people varies over time but they are all skilled developers familiar with the curl project. The security team works best when it consists of a small set of active persons. We invite new members when the team seems to need it, and we also expect to retire security team members as they "drift off" from the project or -just find themselves unable to perform their duties there. +find themselves unable to perform their duties there. + +## Core team + +There is a curl core team. It currently has the same set of members as the +security team. It can also be reached on the security email address. + +The core team nominates and invites new members to the team when it sees fit. +There is no open member voting or formal ways to be a candidate. Active +participants in the curl project who want to join the core team can ask to +join. + +The core team is a board of advisors. It deals with project management +subjects that need confidentiality or for other reasons cannot be dealt with +and discussed in the open (for example reports of code of conduct violations). +Project matters should always as far as possible be discussed on open mailing +lists. ## Server admins @@ -172,11 +192,25 @@ different individuals and over time. If you think you can help making the project better by shouldering some maintaining responsibilities, then please get in touch. -You will be expected to be familiar with the curl project and its ways of -working. You need to have gotten a few quality patches merged as a proof of -this. +You are expected to be familiar with the curl project and its ways of working. +You need to have gotten a few quality patches merged as a proof of this. ### Stop being a maintainer If you (appear to) not be active in the project anymore, you may be removed as -a maintainer. Thank you for your service! +a maintainer. Thank you for your service. + +# Post-Daniel BDFL + +At the point in a future when Daniel steps away from the project and stops +being the project lead, there is reason to reconsider how to keep driving the +project forward. Countries, companies and organizations have a single +president or CEO for a reason; having a single leader that responsibly can +take quick daily decisions is efficient. Without Daniel as BDFL, either +someone else needs to step up and become president, or the project needs to +adopt a council-driven process. Maybe both? Maybe vote a new project leader +for one year or a few years at a time? + +Deciding the replacement person and governance is a subject for the curl core +team to vote on. When that happens, this section of this document should also +get updated. diff --git a/third-party/curl/docs/HELP-US.md b/third-party/curl/docs/HELP-US.md index 90c9724b21..e676dcf08f 100644 --- a/third-party/curl/docs/HELP-US.md +++ b/third-party/curl/docs/HELP-US.md @@ -1,3 +1,9 @@ + + # How to get started helping out in the curl project We are always in need of more help. If you are new to the project and are @@ -27,12 +33,12 @@ If you are looking for a smaller or simpler task in the project to help out with as an entry-point into the project, perhaps because you are a newcomer or even maybe not a terribly experienced developer, here's our advice: - - Read through this document to get a grasp on a general approach to use - - Consider adding a test case for something not currently tested (correctly) - - Consider updating or adding documentation - - One way to get started gently in the project, is to participate in an - existing issue/PR and help out by reproducing the issue, review the code in - the PR etc. +- Read through this document to get a grasp on a general approach to use +- Consider adding a test case for something not currently tested (correctly) +- Consider updating or adding documentation +- One way to get started gently in the project, is to participate in an + existing issue/PR and help out by reproducing the issue, review the code in + the PR etc. ## Help wanted @@ -40,8 +46,8 @@ In the issue tracker we occasionally mark bugs with [help wanted](https://github.com/curl/curl/labels/help%20wanted), as a sign that the bug is acknowledged to exist and that there is nobody known to work on this issue for the moment. Those are bugs that are fine to "grab" and provide a -pull request for. The complexity level of these will of course vary, so pick -one that piques your interest. +pull request for. The complexity level of these of course varies, so pick one +that piques your interest. ## Work on known bugs @@ -77,13 +83,12 @@ brainstorming on specific ways to do the implementation etc. You can also come up with a completely new thing you think we should do. Or not do. Or fix. Or add to the project. You then either bring it to the mailing -list first to see if people will shoot down the idea at once, or you bring a -first draft of the idea as a pull request and take the discussion there around -the specific implementation. Either way is fine. +list first to see if people shoot down the idea at once, or you bring a first +draft of the idea as a pull request and take the discussion there around the +specific implementation. Either way is fine. ## CONTRIBUTE -We offer [guidelines](https://curl.se/dev/contribute.html) that are -suitable to be familiar with before you decide to contribute to curl. If -you are used to open source development, you will probably not find many -surprises there. +We offer [guidelines](https://curl.se/dev/contribute.html) that are suitable +to be familiar with before you decide to contribute to curl. If you are used +to open source development, you probably do not find many surprises there. diff --git a/third-party/curl/docs/HISTORY.md b/third-party/curl/docs/HISTORY.md index f39c45ea12..3723052f9e 100644 --- a/third-party/curl/docs/HISTORY.md +++ b/third-party/curl/docs/HISTORY.md @@ -1,25 +1,28 @@ -How curl Became Like This -========================= + + +# How curl Became Like This Towards the end of 1996, Daniel Stenberg was spending time writing an IRC bot for an Amiga related channel on EFnet. He then came up with the idea to make -currency-exchange calculations available to Internet Relay Chat (IRC) -users. All the necessary data were published on the Web; he just needed to -automate their retrieval. +currency-exchange calculations available to Internet Relay Chat (IRC) users. +All the necessary data were published on the Web; he only needed to automate +their retrieval. -1996 ----- +## 1996 On November 11, 1996 the Brazilian developer Rafael Sagula wrote and released HttpGet version 0.1. Daniel extended this existing command-line open-source tool. After a few minor -adjustments, it did just what he needed. The first release with Daniel's -additions was 0.2, released on December 17, 1996. Daniel quickly became the -new maintainer of the project. +adjustments, it did what he needed. The first release with Daniel's additions +was 0.2, released on December 17, 1996. Daniel quickly became the new +maintainer of the project. -1997 ----- +## 1997 HttpGet 0.3 was released in January 1997 and now it accepted HTTP URLs on the command line. @@ -37,8 +40,7 @@ November 24 1997: Version 3.1 added FTP upload support. Version 3.5 added support for HTTP POST. -1998 ----- +## 1998 February 4: urlget 3.10 @@ -65,14 +67,14 @@ code, we switched over to the MPL license to restrict the effects of "copyleft". November: configure script and reported successful compiles on several -major operating systems. The never-quite-understood -F option was added and -curl could now simulate quite a lot of a browser. TELNET support was added. +major operating systems. The often-misunderstood -F option was added, and +curl could now simulate significant browser functionality. TELNET support was +added. -Curl 5 was released in December 1998 and introduced the first ever curl man +curl 5 was released in December 1998 and introduced the first ever curl man page. People started making Linux RPM packages out of it. -1999 ----- +## 1999 January: DICT support added. @@ -80,16 +82,15 @@ OpenSSL took over and SSLeay was abandoned. May: first Debian package. -August: LDAP:// and FILE:// support added. The curl website gets 1300 visits -weekly. Moved site to curl.haxx.nu. +August: `ldap://` and `file://` support added. The curl website gets 1300 +visits weekly. Moved site to curl.haxx.nu. September: Released curl 6.0. 15000 lines of code. December 28: added the project on Sourceforge and started using its services for managing the project. -2000 ----- +## 2000 Spring: major internal overhaul to provide a suitable library interface. The first non-beta release was named 7.1 and arrived in August. This offered @@ -111,8 +112,7 @@ September: kerberos4 support was added. November: started the work on a test suite for curl. It was later re-written from scratch again. The libcurl major SONAME number was set to 1. -2001 ----- +## 2001 January: Daniel released curl 7.5.2 under a new license again: MIT (or MPL). The MIT license is extremely liberal and can be combined with GPL @@ -124,7 +124,7 @@ deemed "GPL incompatible".) March 22: curl supports HTTP 1.1 starting with the release of 7.7. This also introduced libcurl's ability to do persistent connections. 24000 lines of code. The libcurl major SONAME number was bumped to 2 due to this overhaul. -The first experimental ftps:// support was added. +The first experimental `ftps://` support was added. August: The curl website gets 8000 visits weekly. Curl Corporation contacted Daniel to discuss "the name issue". After Daniel's reply, they have never @@ -138,8 +138,7 @@ September 25: curl (7.7.2) is bundled in Mac OS X (10.1) for the first time. It already becoming more and more of a standard utility of Linux distributions and a regular in the BSD ports collections. -2002 ----- +## 2002 June: the curl website gets 13000 visits weekly. curl and libcurl is 35000 lines of code. Reported successful compiles on more than 40 combinations @@ -155,8 +154,7 @@ only. Starting with 7.10, curl verifies SSL server certificates by default. -2003 ----- +## 2003 January: Started working on the distributed curl tests. The autobuilds. @@ -171,8 +169,7 @@ to the website. Five official web mirrors. December: full-fledged SSL for FTP is supported. -2004 ----- +## 2004 January: curl 7.11.0 introduced large file support. @@ -181,7 +178,7 @@ June: curl 7.12.0 introduced IDN support. 10 official web mirrors. This release bumped the major SONAME to 3 due to the removal of the `curl_formparse()` function -August: Curl and libcurl 7.12.1 +August: curl and libcurl 7.12.1 Public curl release number: 82 Releases counted from the beginning: 109 @@ -191,8 +188,7 @@ August: Curl and libcurl 7.12.1 Amount of public website mirrors: 12 Number of known libcurl bindings: 26 -2005 ----- +## 2005 April: GnuTLS can now optionally be used for the secure layer when curl is built. @@ -205,8 +201,7 @@ More than 100,000 unique visitors of the curl website. 25 mirrors. December: security vulnerability: libcurl URL Buffer Overflow -2006 ----- +## 2006 January: We dropped support for Gopher. We found bugs in the implementation that turned out to have been introduced years ago, so with the conclusion that @@ -217,17 +212,18 @@ March: security vulnerability: libcurl TFTP Packet Buffer Overflow September: The major SONAME number for libcurl was bumped to 4 due to the removal of ftp third party transfer support. +October: we started to offer the Mozilla CA cert bundle as a PEM file on the +curl website. + November: Added SCP and SFTP support -2007 ----- +## 2007 February: Added support for the Mozilla NSS library to do the SSL/TLS stuff July: security vulnerability: libcurl GnuTLS insufficient cert verification -2008 ----- +## 2008 November: @@ -237,10 +233,9 @@ November: Known libcurl bindings: 37 Contributors: 683 - 145,000 unique visitors. >100 GB downloaded. +145,000 unique visitors. >100 GB downloaded. -2009 ----- +## 2009 March: security vulnerability: libcurl Arbitrary File Access @@ -250,8 +245,7 @@ August: security vulnerability: libcurl embedded zero in cert name December: Added support for IMAP, POP3 and SMTP -2010 ----- +## 2010 January: Added support for RTSP @@ -273,154 +267,153 @@ August: Known libcurl bindings: 39 Contributors: 808 - Gopher support added (re-added actually, see January 2006) +Gopher support added (re-added actually, see January 2006) -2011 ----- +## 2011 February: added support for the axTLS backend -April: added the cyassl backend (later renamed to WolfSSL) +April: added the cyassl backend (later renamed to wolfSSL) -2012 ----- +## 2012 - July: Added support for Schannel (native Windows TLS backend) and Darwin SSL - (Native Mac OS X and iOS TLS backend). +July: Added support for Schannel (native Windows TLS backend) and Darwin SSL +(Native Mac OS X and iOS TLS backend). - Supports Metalink +Supports Metalink - October: SSH-agent support. +October: SSH-agent support. -2013 ----- +## 2013 - February: Cleaned up internals to always uses the "multi" non-blocking - approach internally and only expose the blocking API with a wrapper. +February: Cleaned up internals to always uses the "multi" non-blocking +approach internally and only expose the blocking API with a wrapper. - September: First small steps on supporting HTTP/2 with nghttp2. +September: First small steps on supporting HTTP/2 with nghttp2. - October: Removed krb4 support. +October: Removed krb4 support. - December: Happy eyeballs. +December: Happy eyeballs. -2014 ----- +## 2014 - March: first real release supporting HTTP/2 +March: first real release supporting HTTP/2 - September: Website had 245,000 unique visitors and served 236GB data +September: Website had 245,000 unique visitors and served 236GB data - SMB and SMBS support +SMB and SMBS support -2015 ----- +## 2015 - June: support for multiplexing with HTTP/2 +June: support for multiplexing with HTTP/2 - August: support for HTTP/2 server push +August: support for HTTP/2 server push - December: Public Suffix List +September: started "everything curl". A separate stand-alone book documenting +curl and related info in perhaps a more tutorial style rather than a +reference, -2016 ----- +December: Public Suffix List - January: the curl tool defaults to HTTP/2 for HTTPS URLs +## 2016 - December: curl 7.52.0 introduced support for HTTPS-proxy! +January: the curl tool defaults to HTTP/2 for HTTPS URLs - First TLS 1.3 support +June 26: Rafael Sagula, author of the original httpget tool in 1996 died. -2017 ----- +December: curl 7.52.0 introduced support for HTTPS-proxy - July: OSS-Fuzz started fuzzing libcurl +First TLS 1.3 support - September: Added Multi-SSL support +## 2017 - The website serves 3100 GB/month +May: Fastly starts hosting the curl website - Public curl releases: 169 - Command line options: 211 - curl_easy_setopt() options: 249 - Public functions in libcurl: 74 - Contributors: 1609 +July: OSS-Fuzz started fuzzing libcurl - October: SSLKEYLOGFILE support, new MIME API +September: Added MultiSSL support - October: Daniel received the Polhem Prize for his work on curl +The website serves 3100 GB/month - November: brotli + Public curl releases: 169 + Command line options: 211 + curl_easy_setopt() options: 249 + Public functions in libcurl: 74 + Contributors: 1609 -2018 ----- +October: SSLKEYLOGFILE support, new MIME API - January: new SSH backend powered by libssh +October: Daniel received the Polhem Prize for his work on curl - March: starting with the 1803 release of Windows 10, curl is shipped bundled - with Microsoft's operating system. +November: brotli - July: curl shows headers using bold type face +## 2018 - October: added DNS-over-HTTPS (DoH) and the URL API +January: new SSH backend powered by libssh - MesaLink is a new supported TLS backend +March: starting with the 1803 release of Windows 10, curl is shipped bundled +with Microsoft's operating system. - libcurl now does HTTP/2 (and multiplexing) by default on HTTPS URLs +July: curl shows headers using bold type face - curl and libcurl are installed in an estimated 5 *billion* instances - world-wide. +October: added DNS-over-HTTPS (DoH) and the URL API - October 31: Curl and libcurl 7.62.0 +MesaLink is a new supported TLS backend - Public curl releases: 177 - Command line options: 219 - curl_easy_setopt() options: 261 - Public functions in libcurl: 80 - Contributors: 1808 +libcurl now does HTTP/2 (and multiplexing) by default on HTTPS URLs - December: removed axTLS support +curl and libcurl are installed in an estimated 5 *billion* instances +world-wide. -2019 ----- +October 31: curl and libcurl 7.62.0 - March: added experimental alt-svc support + Public curl releases: 177 + Command line options: 219 + curl_easy_setopt() options: 261 + Public functions in libcurl: 80 + Contributors: 1808 - August: the first HTTP/3 requests with curl. +December: removed axTLS support - September: 7.66.0 is released and the tool offers parallel downloads +## 2019 -2020 ----- +January: Daniel started working full-time on curl, employed by wolfSSL - curl and libcurl are installed in an estimated 10 *billion* instances - world-wide. +March: added experimental alt-svc support - January: added BearSSL support +August: the first HTTP/3 requests with curl. - March: removed support for PolarSSL, added wolfSSH support +September: 7.66.0 is released and the tool offers parallel downloads - April: experimental MQTT support +## 2020 - August: zstd support +curl and libcurl are installed in an estimated 10 *billion* instances +world-wide. - November: the website moves to curl.se. The website serves 10TB data monthly. +January: added BearSSL support - December: alt-svc support +March: removed support for PolarSSL, added wolfSSH support. Created the first +dashboard on the website. -2021 ----- +April: experimental MQTT support - February 3: curl 7.75.0 ships with support for Hyper as an HTTP backend +August: zstd support - March 31: curl 7.76.0 ships with support for rustls +November: the website moves to curl.se. The website serves 10TB data monthly. - July: HSTS is supported +December: alt-svc support -2022 ----- +## 2021 - March: added --json, removed mesalink support +February 3: curl 7.75.0 ships with support for Hyper as an HTTP backend + +March 31: curl 7.76.0 ships with support for Rustls + +July: HSTS is supported + +## 2022 + +March: added --json, removed mesalink support Public curl releases: 206 Command line options: 245 @@ -428,10 +421,79 @@ April: added the cyassl backend (later renamed to WolfSSL) Public functions in libcurl: 86 Contributors: 2601 - The curl.se website serves 16,500 GB/month over 462M requests, the - official docker image has been pulled 4,098,015,431 times. +The curl.se website serves 16,500 GB/month over 462M requests, the +official docker image has been pulled 4,098,015,431 times. -2023 ----- +April: added support for msh3 as another HTTP/3 backend + +October: initial WebSocket support + +## 2023 + +March: remove support for curl_off_t < 8 bytes + +March 31: we started working on a new command line tool for URL parsing and +manipulations: trurl. + +May: added support for HTTP/2 over HTTPS proxy. Refuse to resolve .onion. The +curl GitHub repository reaches 30,000 stars. August: Dropped support for the NSS library + +September: added "variable" support in the command line tool. Dropped support +for the gskit TLS library. + +October: added support for IPFS via HTTP gateway + +December: HTTP/3 support with ngtcp2 is no longer experimental + +## 2024 + +January: switched to "curldown" for all documentation + +April 24: the curl container has been pulled more than six billion times + +May: experimental support for ECH, dropped NTLM_WB + +August 9: we adopted the wcurl tool into the curl organization + +September 11: --help [option] + +November 6: TLS 1.3 early data, WebSocket is official + +December 21: dropped hyper + +## 2025 + +February 5: first 0RTT for QUIC, SSL session import/export + +February: experimental HTTPS RR support + +February 22: The website served 62.95 TB/month; 12.43 billion requests. The +docker image has been pulled 6373501745 times. + +June: we removed support for BearSSL, Secure Transport and msh3 + +October: Daniel gets awarded a gold medal by the Swedish Royal Academy of +Engineering Sciences for his work on curl. + +We counted curl having been installed on 110 operating systems and 28 CPU +architectures. + +November: + + Public curl releases: 271 + Command line options: 273 + curl_easy_setopt() options: 308 + Public functions in libcurl: 100 + Contributors: 3534 + +We drop support for krb-ftp, Heimdal, wolfSSH and the winbuild build system. + +Add support for Apple SecTrust, native CA certs on Apple systems. + +December 15: the website served 78 TB over the last month. + +## 2026 + +April: removed support for RTMP diff --git a/third-party/curl/docs/HSTS.md b/third-party/curl/docs/HSTS.md index e541024936..c6d872077b 100644 --- a/third-party/curl/docs/HSTS.md +++ b/third-party/curl/docs/HSTS.md @@ -1,3 +1,9 @@ + + # HSTS support HTTP Strict-Transport-Security. Added as experimental in curl @@ -10,19 +16,22 @@ HTTP Strict-Transport-Security. Added as experimental in curl ## Behavior libcurl features an in-memory cache for HSTS hosts, so that subsequent -HTTP-only requests to a host name present in the cache will get internally +HTTP-only requests to a hostname present in the cache gets internally "redirected" to the HTTPS version. +Since curl 8.20.0, libcurl keeps no more than the most recently added 10,000 +unique HSTS hostnames. + ## `curl_easy_setopt()` options: - - `CURLOPT_HSTS_CTRL` - enable HSTS for this easy handle - - `CURLOPT_HSTS` - specify file name where to store the HSTS cache on close +- `CURLOPT_HSTS_CTRL` - enable HSTS for this easy handle +- `CURLOPT_HSTS` - specify filename where to store the HSTS cache on close (and possibly read from at startup) ## curl command line options - - `--hsts [filename]` - enable HSTS, use the file as HSTS cache. If filename - is `""` (no length) then no file will be used, only in-memory cache. +- `--hsts [filename]` - enable HSTS, use the file as HSTS cache. If filename + is `""` (no length) then no file is used, only in-memory cache. ## HSTS cache file format @@ -30,13 +39,13 @@ Lines starting with `#` are ignored. For each hsts entry: - [host name] "YYYYMMDD HH:MM:SS" + [hostname] "YYYYMMDD HH:MM:SS" -The `[host name]` is dot-prefixed if it includes subdomains. +The `[hostname]` is dot-prefixed if it includes subdomains. The time stamp is when the entry expires. ## Possible future additions - - `CURLOPT_HSTS_PRELOAD` - provide a set of HSTS host names to load first - - ability to save to something else than a file +- `CURLOPT_HSTS_PRELOAD` - provide a set of HSTS hostnames to load first +- ability to save to something else than a file diff --git a/third-party/curl/docs/HTTP-COOKIES.md b/third-party/curl/docs/HTTP-COOKIES.md index d6fd87d205..2a32aae605 100644 --- a/third-party/curl/docs/HTTP-COOKIES.md +++ b/third-party/curl/docs/HTTP-COOKIES.md @@ -1,147 +1,171 @@ + + # HTTP Cookies ## Cookie overview - Cookies are `name=contents` pairs that an HTTP server tells the client to - hold and then the client sends back those to the server on subsequent - requests to the same domains and paths for which the cookies were set. +Cookies are `name=contents` pairs that an HTTP server tells the client to +hold and then the client sends back those to the server on subsequent +requests to the same domains and paths for which the cookies were set. - Cookies are either "session cookies" which typically are forgotten when the - session is over which is often translated to equal when browser quits, or - the cookies are not session cookies they have expiration dates after which - the client will throw them away. +Cookies are either "session cookies" which typically are forgotten when the +session is over which is often translated to equal when browser quits, or +the cookies are not session cookies they have expiration dates after which +the client throws them away. - Cookies are set to the client with the Set-Cookie: header and are sent to - servers with the Cookie: header. +Cookies are set to the client with the Set-Cookie: header and are sent to +servers with the Cookie: header. - For a long time, the only spec explaining how to use cookies was the - original [Netscape spec from 1994](https://curl.se/rfc/cookie_spec.html). +For a long time, the only spec explaining how to use cookies was the +original [Netscape spec from 1994](https://curl.se/rfc/cookie_spec.html). - In 2011, [RFC 6265](https://www.ietf.org/rfc/rfc6265.txt) was finally - published and details how cookies work within HTTP. In 2016, an update which - added support for prefixes was - [proposed](https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-cookie-prefixes-00), - and in 2017, another update was - [drafted](https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-cookie-alone-01) - to deprecate modification of 'secure' cookies from non-secure origins. Both - of these drafts have been incorporated into a proposal to - [replace](https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-rfc6265bis-11) - RFC 6265. Cookie prefixes and secure cookie modification protection has been - implemented by curl. +In 2011, [RFC 6265](https://datatracker.ietf.org/doc/html/rfc6265) was finally +published and details how cookies work within HTTP. In 2016, an update which +added support for prefixes was +[proposed](https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-cookie-prefixes-00), +and in 2017, another update was +[drafted](https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-cookie-alone-01) +to deprecate modification of 'secure' cookies from non-secure origins. Both +of these drafts have been incorporated into a proposal to +[replace](https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-rfc6265bis-11) +RFC 6265. Cookie prefixes and secure cookie modification protection has been +implemented by curl. - curl considers `http://localhost` to be a *secure context*, meaning that it - will allow and use cookies marked with the `secure` keyword even when done - over plain HTTP for this host. curl does this to match how popular browsers - work with secure cookies. +curl considers `http://localhost` to be a *secure context*, meaning that it +allows and uses cookies marked with the `secure` keyword even when done over +plain HTTP for this host. curl does this to match how popular browsers work +with secure cookies. + +## Super cookies + +A single cookie can be set for a domain that matches multiple hosts. Like if +set for `example.com` it gets sent to both `aa.example.com` as well as +`bb.example.com`. + +A challenge with this concept is that there are certain domains for which +cookies should not be allowed at all, because they are *Public +Suffixes*. Similarly, a client never accepts cookies set directly for the +top-level domain like for example `.com`. Cookies set for *too broad* +domains are generally referred to as *super cookies*. + +If curl is built with PSL (**Public Suffix List**) support, it detects and +discards cookies that are specified for such suffix domains that should not +be allowed to have cookies. + +if curl is *not* built with PSL support, it has no ability to stop super +cookies. ## Cookies saved to disk - Netscape once created a file format for storing cookies on disk so that they - would survive browser restarts. curl adopted that file format to allow - sharing the cookies with browsers, only to see browsers move away from that - format. Modern browsers no longer use it, while curl still does. +Netscape once created a file format for storing cookies on disk so that they +would survive browser restarts. curl adopted that file format to allow +sharing the cookies with browsers, only to see browsers move away from that +format. Modern browsers no longer use it, while curl still does. - The Netscape cookie file format stores one cookie per physical line in the - file with a bunch of associated meta data, each field separated with - TAB. That file is called the cookie jar in curl terminology. +The Netscape cookie file format stores one cookie per physical line in the +file with a bunch of associated meta data, each field separated with +TAB. That file is called the cookie jar in curl terminology. - When libcurl saves a cookie jar, it creates a file header of its own in - which there is a URL mention that will link to the web version of this - document. +When libcurl saves a cookie jar, it creates a file header of its own in +which there is a URL mention that links to the web version of this document. ## Cookie file format - The cookie file format is text based and stores one cookie per line. Lines - that start with `#` are treated as comments. An exception is lines that - start with `#HttpOnly_`, which is a prefix for cookies that have the - `HttpOnly` attribute set. +The cookie file format is text based and stores one cookie per line. Lines +that start with `#` are treated as comments. An exception is lines that +start with `#HttpOnly_`, which is a prefix for cookies that have the +`HttpOnly` attribute set. - Each line that specifies a single cookie consists of seven text fields - separated with TAB characters. A valid line must end with a newline - character. +Each line that specifies a single cookie consists of seven text fields +separated with TAB characters. A valid line must end with a newline +character. ### Fields in the file - Field number, what type and example data and the meaning of it: +Field number, what type and example data and the meaning of it: - 0. string `example.com` - the domain name - 1. boolean `FALSE` - include subdomains - 2. string `/foobar/` - path - 3. boolean `TRUE` - send/receive over HTTPS only - 4. number `1462299217` - expires at - seconds since Jan 1st 1970, or 0 - 5. string `person` - name of the cookie - 6. string `daniel` - value of the cookie +0. string `example.com` - the domain name +1. boolean `FALSE` - include subdomains +2. string `/foobar/` - path +3. boolean `TRUE` - send/receive over HTTPS only +4. number `1462299217` - expires at - seconds since Jan 1st 1970, or 0 +5. string `person` - name of the cookie +6. string `daniel` - value of the cookie ## Cookies with curl the command line tool - curl has a full cookie "engine" built in. If you just activate it, you can - have curl receive and send cookies exactly as mandated in the specs. +curl has a full cookie "engine" built in. If you activate it, you can have +curl receive and send cookies exactly as mandated in the specs. - Command line options: +Command line options: - `-b, --cookie` +[`-b, --cookie`](https://curl.se/docs/manpage.html#-b) - tell curl a file to read cookies from and start the cookie engine, or if it - is not a file it will pass on the given string. `-b name=var` works and so - does `-b cookiefile`. +tell curl a file to read cookies from and start the cookie engine, or if it +is not a file it passes on the given string. `-b name=var` works and so does +`-b cookiefile`. - `-j, --junk-session-cookies` +[`-j, --junk-session-cookies`](https://curl.se/docs/manpage.html#-j) - when used in combination with -b, it will skip all "session cookies" on load - so as to appear to start a new cookie session. +when used in combination with -b, it skips all "session cookies" on load so +as to appear to start a new cookie session. - `-c, --cookie-jar` +[`-c, --cookie-jar`](https://curl.se/docs/manpage.html#-c) - tell curl to start the cookie engine and write cookies to the given file - after the request(s) +tell curl to start the cookie engine and write cookies to the given file +after the request(s) ## Cookies with libcurl - libcurl offers several ways to enable and interface the cookie engine. These - options are the ones provided by the native API. libcurl bindings may offer - access to them using other means. +libcurl offers several ways to enable and interface the cookie engine. These +options are the ones provided by the native API. libcurl bindings may offer +access to them using other means. - `CURLOPT_COOKIE` +[`CURLOPT_COOKIE`](https://curl.se/libcurl/c/CURLOPT_COOKIE.html) - Is used when you want to specify the exact contents of a cookie header to - send to the server. +Is used when you want to specify the exact contents of a cookie header to +send to the server. - `CURLOPT_COOKIEFILE` +[`CURLOPT_COOKIEFILE`](https://curl.se/libcurl/c/CURLOPT_COOKIEFILE.html) - Tell libcurl to activate the cookie engine, and to read the initial set of - cookies from the given file. Read-only. +Tell libcurl to activate the cookie engine, and to read the initial set of +cookies from the given file. Read-only. - `CURLOPT_COOKIEJAR` +[`CURLOPT_COOKIEJAR`](https://curl.se/libcurl/c/CURLOPT_COOKIEJAR.html) - Tell libcurl to activate the cookie engine, and when the easy handle is - closed save all known cookies to the given cookie jar file. Write-only. +Tell libcurl to activate the cookie engine, and when the easy handle is +closed save all known cookies to the given cookie jar file. Write-only. - `CURLOPT_COOKIELIST` +[`CURLOPT_COOKIELIST`](https://curl.se/libcurl/c/CURLOPT_COOKIELIST.html) - Provide detailed information about a single cookie to add to the internal - storage of cookies. Pass in the cookie as an HTTP header with all the - details set, or pass in a line from a Netscape cookie file. This option can - also be used to flush the cookies etc. +Provide detailed information about a single cookie to add to the internal +storage of cookies. Pass in the cookie as an HTTP header with all the +details set, or pass in a line from a Netscape cookie file. This option can +also be used to flush the cookies etc. - `CURLOPT_COOKIESESSION` +[`CURLOPT_COOKIESESSION`](https://curl.se/libcurl/c/CURLOPT_COOKIESESSION.html) - Tell libcurl to ignore all cookies it is about to load that are session - cookies. +Tell libcurl to ignore all cookies it is about to load that are session +cookies. - `CURLINFO_COOKIELIST` +[`CURLINFO_COOKIELIST`](https://curl.se/libcurl/c/CURLINFO_COOKIELIST.html) - Extract cookie information from the internal cookie storage as a linked - list. +Extract cookie information from the internal cookie storage as a linked +list. ## Cookies with JavaScript - These days a lot of the web is built up by JavaScript. The web browser loads - complete programs that render the page you see. These JavaScript programs - can also set and access cookies. +These days a lot of the web is built up by JavaScript. The web browser loads +complete programs that render the page you see. These JavaScript programs +can also set and access cookies. - Since curl and libcurl are plain HTTP clients without any knowledge of or - capability to handle JavaScript, such cookies will not be detected or used. +Since curl and libcurl are plain HTTP clients without any knowledge of or +capability to handle JavaScript, such cookies are not detected or used. - Often, if you want to mimic what a browser does on such websites, you can - record web browser HTTP traffic when using such a site and then repeat the - cookie operations using curl or libcurl. +Often, if you want to mimic what a browser does on such websites, you can +record web browser HTTP traffic when using such a site and then repeat the +cookie operations using curl or libcurl. diff --git a/third-party/curl/docs/HTTP2.md b/third-party/curl/docs/HTTP2.md deleted file mode 100644 index 5b4028349c..0000000000 --- a/third-party/curl/docs/HTTP2.md +++ /dev/null @@ -1,102 +0,0 @@ -HTTP/2 with curl -================ - -[HTTP/2 Spec](https://www.rfc-editor.org/rfc/rfc7540.txt) -[http2 explained](https://daniel.haxx.se/http2/) - -Build prerequisites -------------------- - - nghttp2 - - OpenSSL, libressl, BoringSSL, GnuTLS, mbedTLS, wolfSSL or Schannel - with a new enough version. - -[nghttp2](https://nghttp2.org/) -------------------------------- - -libcurl uses this 3rd party library for the low level protocol handling -parts. The reason for this is that HTTP/2 is much more complex at that layer -than HTTP/1.1 (which we implement on our own) and that nghttp2 is an already -existing and well functional library. - -We require at least version 1.12.0. - -Over an http:// URL -------------------- - -If `CURLOPT_HTTP_VERSION` is set to `CURL_HTTP_VERSION_2_0`, libcurl will -include an upgrade header in the initial request to the host to allow -upgrading to HTTP/2. - -Possibly we can later introduce an option that will cause libcurl to fail if -not possible to upgrade. Possibly we introduce an option that makes libcurl -use HTTP/2 at once over http:// - -Over an https:// URL --------------------- - -If `CURLOPT_HTTP_VERSION` is set to `CURL_HTTP_VERSION_2_0`, libcurl will use -ALPN to negotiate which protocol to continue with. Possibly introduce an -option that will cause libcurl to fail if not possible to use HTTP/2. - -`CURL_HTTP_VERSION_2TLS` was added in 7.47.0 as a way to ask libcurl to prefer -HTTP/2 for HTTPS but stick to 1.1 by default for plain old HTTP connections. - -ALPN is the TLS extension that HTTP/2 is expected to use. - -`CURLOPT_SSL_ENABLE_ALPN` is offered to allow applications to explicitly -disable ALPN. - -Multiplexing ------------- - -Starting in 7.43.0, libcurl fully supports HTTP/2 multiplexing, which is the -term for doing multiple independent transfers over the same physical TCP -connection. - -To take advantage of multiplexing, you need to use the multi interface and set -`CURLMOPT_PIPELINING` to `CURLPIPE_MULTIPLEX`. With that bit set, libcurl will -attempt to reuse existing HTTP/2 connections and just add a new stream over -that when doing subsequent parallel requests. - -While libcurl sets up a connection to an HTTP server there is a period during -which it does not know if it can pipeline or do multiplexing and if you add -new transfers in that period, libcurl will default to start new connections -for those transfers. With the new option `CURLOPT_PIPEWAIT` (added in 7.43.0), -you can ask that a transfer should rather wait and see in case there is a -connection for the same host in progress that might end up being possible to -multiplex on. It favors keeping the number of connections low to the cost of -slightly longer time to first byte transferred. - -Applications ------------- - -We hide HTTP/2's binary nature and convert received HTTP/2 traffic to headers -in HTTP 1.1 style. This allows applications to work unmodified. - -curl tool ---------- - -curl offers the `--http2` command line option to enable use of HTTP/2. - -curl offers the `--http2-prior-knowledge` command line option to enable use of -HTTP/2 without HTTP/1.1 Upgrade. - -Since 7.47.0, the curl tool enables HTTP/2 by default for HTTPS connections. - -curl tool limitations ---------------------- - -The command line tool does not support HTTP/2 server push. It supports -multiplexing when the parallel transfer option is used. - -HTTP Alternative Services -------------------------- - -Alt-Svc is an extension with a corresponding frame (ALTSVC) in HTTP/2 that -tells the client about an alternative "route" to the same content for the same -origin server that you get the response from. A browser or long-living client -can use that hint to create a new connection asynchronously. For libcurl, we -may introduce a way to bring such clues to the application and/or let a -subsequent request use the alternate route automatically. - -[Detailed in RFC 7838](https://datatracker.ietf.org/doc/html/rfc7838) diff --git a/third-party/curl/docs/HTTP3.md b/third-party/curl/docs/HTTP3.md index 48e27d3191..74254233b2 100644 --- a/third-party/curl/docs/HTTP3.md +++ b/third-party/curl/docs/HTTP3.md @@ -1,3 +1,9 @@ + + # HTTP3 (and QUIC) ## Resources @@ -9,268 +15,253 @@ book describing the protocols involved. ## QUIC libraries -QUIC libraries we are experimenting with: +QUIC libraries we are using: [ngtcp2](https://github.com/ngtcp2/ngtcp2) -[quiche](https://github.com/cloudflare/quiche) - -[msh3](https://github.com/nibanks/msh3) (with [msquic](https://github.com/microsoft/msquic)) +[quiche](https://github.com/cloudflare/quiche) - **EXPERIMENTAL** ## Experimental -HTTP/3 and QUIC support in curl is considered **EXPERIMENTAL** until further -notice. It needs to be enabled at build-time. +HTTP/3 support using *quiche* in curl is considered **EXPERIMENTAL** until +further notice. Only the *ngtcp2* backend is not experimental. -Further development and tweaking of the HTTP/3 support in curl will happen in -the master branch using pull-requests, just like ordinary changes. +Further development and tweaking of the HTTP/3 support in curl happens in the +master branch using pull-requests like ordinary changes. To fix before we remove the experimental label: - - the used QUIC library needs to consider itself non-beta - - it's fine to "leave" individual backends as experimental if necessary +- the used QUIC library needs to consider itself non-beta +- it is fine to "leave" individual backends as experimental if necessary # ngtcp2 version -Building curl with ngtcp2 involves 3 components: `ngtcp2` itself, `nghttp3` and a QUIC supporting TLS library. The supported TLS libraries are covered below. +Building curl with ngtcp2 involves 3 components: `ngtcp2` itself, `nghttp3` +and a QUIC supporting TLS library. The supported TLS libraries are covered +below. -For now, `ngtcp2` and `nghttp3` are still *experimental* which means their evolution bring breaking changes. Therefore, the proper version of both libraries need to be used when building curl. These are +While any version of `ngtcp2` and `nghttp3` from v1.0.0 on are expected to +work, using the latest versions often brings functional and performance +improvements. - * `ngtcp2`: v0.19.1 - * `nghttp3`: v0.15.0 +The build examples use `$NGHTTP3_VERSION` and `$NGTCP2_VERSION` as +placeholders for the version you build. -## Build with OpenSSL +## Build with OpenSSL or fork -Build (patched) OpenSSL +OpenSSL v3.5.0+ requires *ngtcp2* v1.12.0+. Earlier versions do not work. - % git clone --depth 1 -b openssl-3.0.10+quic https://github.com/quictls/openssl +Build OpenSSL (v3.5.0+) or fork AWS-LC, BoringSSL, LibreSSL or quictls: + + # Instructions for OpenSSL v3.5.0+ + % git clone --depth 1 --branch openssl-$OPENSSL_VERSION https://github.com/openssl/openssl % cd openssl - % ./config enable-tls1_3 --prefix= + % ./config --prefix=/path/to/openssl --libdir=lib % make % make install -Build nghttp3 +Build nghttp3: % cd .. - % git clone -b v0.15.0 https://github.com/ngtcp2/nghttp3 + % git clone --depth 1 --branch $NGHTTP3_VERSION https://github.com/ngtcp2/nghttp3 % cd nghttp3 + % git submodule update --init % autoreconf -fi - % ./configure --prefix= --enable-lib-only + % ./configure --prefix=/path/to/nghttp3 --enable-lib-only % make % make install -Build ngtcp2 +Build ngtcp2: % cd .. - % git clone -b v0.19.1 https://github.com/ngtcp2/ngtcp2 + % git clone --depth 1 --branch $NGTCP2_VERSION https://github.com/ngtcp2/ngtcp2 % cd ngtcp2 % autoreconf -fi - % ./configure PKG_CONFIG_PATH=/lib/pkgconfig:/lib/pkgconfig LDFLAGS="-Wl,-rpath,/lib" --prefix= --enable-lib-only + # Change --with-openssl to --with-boringssl for AWS-LC and BoringSSL + % ./configure PKG_CONFIG_PATH=/path/to/openssl/lib/pkgconfig:/path/to/nghttp3/lib/pkgconfig LDFLAGS="-Wl,-rpath,/path/to/openssl/lib" \ + --prefix=/path/to/ngtcp2 --enable-lib-only --with-openssl % make % make install -Build curl +Build curl (with autotools): % cd .. - % git clone https://github.com/curl/curl + % git clone --depth 1 https://github.com/curl/curl % cd curl % autoreconf -fi - % LDFLAGS="-Wl,-rpath,/lib" ./configure --with-openssl= --with-nghttp3= --with-ngtcp2= + % ./configure PKG_CONFIG_PATH=/path/to/openssl/lib/pkgconfig LDFLAGS="-Wl,-rpath,/path/to/openssl/lib" \ + --with-openssl=/path/to/openssl --with-ngtcp2=/path/to/ngtcp2 --with-nghttp3=/path/to/nghttp3 % make % make install -For OpenSSL 3.0.0 or later builds on Linux for x86_64 architecture, substitute all occurrences of "/lib" with "/lib64" +Build curl (with CMake): + + % cd .. + % git clone --depth 1 https://github.com/curl/curl + % cd curl + % PKG_CONFIG_PATH=/path/to/openssl/lib/pkgconfig:/path/to/ngtcp2/lib/pkgconfig:/path/to/nghttp3/lib/pkgconfig cmake -B bld \ + -DOPENSSL_ROOT_DIR=/path/to/openssl -DUSE_NGTCP2=ON + % cmake --build bld ## Build with GnuTLS -Build GnuTLS +Build GnuTLS: - % git clone --depth 1 https://gitlab.com/gnutls/gnutls.git + % git clone --depth 1 https://gitlab.com/gnutls/gnutls % cd gnutls % ./bootstrap - % ./configure --prefix= + % ./configure --prefix=/path/to/gnutls % make % make install -Build nghttp3 +Build nghttp3: % cd .. - % git clone -b v0.15.0 https://github.com/ngtcp2/nghttp3 + % git clone --depth 1 --branch $NGHTTP3_VERSION https://github.com/ngtcp2/nghttp3 % cd nghttp3 + % git submodule update --init % autoreconf -fi - % ./configure --prefix= --enable-lib-only + % ./configure --prefix=/path/to/nghttp3 --enable-lib-only % make % make install -Build ngtcp2 +Build ngtcp2: % cd .. - % git clone -b v0.19.1 https://github.com/ngtcp2/ngtcp2 + % git clone --depth 1 --branch $NGTCP2_VERSION https://github.com/ngtcp2/ngtcp2 % cd ngtcp2 % autoreconf -fi - % ./configure PKG_CONFIG_PATH=/lib/pkgconfig:/lib/pkgconfig LDFLAGS="-Wl,-rpath,/lib" --prefix= --enable-lib-only --with-gnutls + % ./configure PKG_CONFIG_PATH=/path/to/gnutls/lib/pkgconfig:/path/to/nghttp3/lib/pkgconfig LDFLAGS="-Wl,-rpath,/path/to/gnutls/lib" \ + --prefix=/path/to/ngtcp2 --enable-lib-only --with-gnutls % make % make install -Build curl +Build curl (with autotools): % cd .. - % git clone https://github.com/curl/curl + % git clone --depth 1 https://github.com/curl/curl % cd curl % autoreconf -fi - % ./configure --with-gnutls= --with-nghttp3= --with-ngtcp2= + % ./configure PKG_CONFIG_PATH=/path/to/gnutls/lib/pkgconfig --with-gnutls=/path/to/gnutls --with-ngtcp2=/path/to/ngtcp2 --with-nghttp3=/path/to/nghttp3 % make % make install +Build curl (with CMake): + + % cd .. + % git clone --depth 1 https://github.com/curl/curl + % cd curl + % PKG_CONFIG_PATH=/path/to/gnutls/lib/pkgconfig:/path/to/ngtcp2/lib/pkgconfig:/path/to/nghttp3/lib/pkgconfig cmake -B bld -DCURL_USE_GNUTLS=ON -DUSE_NGTCP2=ON + % cmake --build bld + ## Build with wolfSSL -Build wolfSSL +Build wolfSSL: - % git clone https://github.com/wolfSSL/wolfssl.git + % git clone --depth 1 https://github.com/wolfSSL/wolfssl % cd wolfssl % autoreconf -fi - % ./configure --prefix= --enable-quic --enable-session-ticket --enable-earlydata --enable-psk --enable-harden --enable-altcertchains + % ./configure --prefix=/path/to/wolfssl --enable-quic --enable-session-ticket --enable-earlydata --enable-psk --enable-harden --enable-altcertchains % make % make install -Build nghttp3 +Build nghttp3: % cd .. - % git clone -b v0.15.0 https://github.com/ngtcp2/nghttp3 + % git clone --depth 1 --branch $NGHTTP3_VERSION https://github.com/ngtcp2/nghttp3 % cd nghttp3 + % git submodule update --init % autoreconf -fi - % ./configure --prefix= --enable-lib-only + % ./configure --prefix=/path/to/nghttp3 --enable-lib-only % make % make install -Build ngtcp2 +Build ngtcp2: % cd .. - % git clone -b v0.19.1 https://github.com/ngtcp2/ngtcp2 + % git clone --depth 1 --branch $NGTCP2_VERSION https://github.com/ngtcp2/ngtcp2 % cd ngtcp2 % autoreconf -fi - % ./configure PKG_CONFIG_PATH=/lib/pkgconfig:/lib/pkgconfig LDFLAGS="-Wl,-rpath,/lib" --prefix= --enable-lib-only --with-wolfssl + % ./configure PKG_CONFIG_PATH=/path/to/wolfssl/lib/pkgconfig:/path/to/nghttp3/lib/pkgconfig LDFLAGS="-Wl,-rpath,/path/to/wolfssl/lib" \ + --prefix=/path/to/ngtcp2 --enable-lib-only --with-wolfssl % make % make install -Build curl +Build curl (with autotools): % cd .. - % git clone https://github.com/curl/curl + % git clone --depth 1 https://github.com/curl/curl % cd curl % autoreconf -fi - % ./configure --with-wolfssl= --with-nghttp3= --with-ngtcp2= + % ./configure PKG_CONFIG_PATH=/path/to/wolfssl/lib/pkgconfig --with-wolfssl=/path/to/wolfssl --with-ngtcp2=/path/to/ngtcp2 --with-nghttp3=/path/to/nghttp3 % make % make install +Build curl (with CMake): + + % cd .. + % git clone --depth 1 https://github.com/curl/curl + % cd curl + % PKG_CONFIG_PATH=/path/to/wolfssl/lib/pkgconfig:/path/to/ngtcp2/lib/pkgconfig:/path/to/nghttp3/lib/pkgconfig cmake -B bld -DCURL_USE_WOLFSSL=ON -DUSE_NGTCP2=ON + % cmake --build bld + # quiche version -Since the quiche build manages its dependencies, curl can be built against the latest version. You are *probably* able to build against their main branch, but in case of problems, we recommend their latest release tag. +quiche support is **EXPERIMENTAL** -## build +Since the quiche build manages its dependencies, curl can be built against the +latest version. You are *probably* able to build against their main branch, +but in case of problems, we recommend their latest release tag. -Build quiche and BoringSSL: +## Build - % git clone --recursive https://github.com/cloudflare/quiche +Build quiche and BoringSSL (described here for quiche v0.29.1, the locations +where BoringSSL is to be found vary with version): + + % git clone --depth 1 --branch 0.29.1 --recursive https://github.com/cloudflare/quiche % cd quiche % cargo build --package quiche --release --features ffi,pkg-config-meta,qlog - % mkdir quiche/deps/boringssl/src/lib - % ln -vnf $(find target/release -name libcrypto.a -o -name libssl.a) quiche/deps/boringssl/src/lib/ + % ln -s libquiche.so target/release/libquiche.so.0 + % mkdir -p boringssl/lib + % find target/release \( -name libcrypto.a -o -name libssl.a \) -exec ln -vnf -- '{}' boringssl/lib \; + % find target/release/build/boring-sys-*/out/boringssl/src -maxdepth 1 \( -name include \) -exec ln -vsf -- '../{}' boringssl \; Build curl: % cd .. - % git clone https://github.com/curl/curl + % git clone --depth 1 https://github.com/curl/curl % cd curl % autoreconf -fi - % ./configure LDFLAGS="-Wl,-rpath,$PWD/../quiche/target/release" --with-openssl=$PWD/../quiche/quiche/deps/boringssl/src --with-quiche=$PWD/../quiche/target/release + % ./configure --with-openssl=$PWD/../quiche/boringssl \ + --with-quiche=$PWD/../quiche/target/release % make % make install - If `make install` results in `Permission denied` error, you will need to prepend it with `sudo`. - -# msh3 (msquic) version - -**Note**: The msquic HTTP/3 backend is immature and is not properly functional -one as of September 2023. Feel free to help us test it and improve it, but -there is no point in filing bugs about it just yet. - -## Build Linux (with quictls fork of OpenSSL) - -Build msh3: - - % git clone -b v0.6.0 --depth 1 --recursive https://github.com/nibanks/msh3 - % cd msh3 && mkdir build && cd build - % cmake -G 'Unix Makefiles' -DCMAKE_BUILD_TYPE=RelWithDebInfo .. - % cmake --build . - % cmake --install . - -Build curl: - - % git clone https://github.com/curl/curl - % cd curl - % autoreconf -fi - % ./configure LDFLAGS="-Wl,-rpath,/usr/local/lib" --with-msh3=/usr/local --with-openssl - % make - % make install - -Run from `/usr/local/bin/curl`. - -## Build Windows - -Build msh3: - - % git clone -b v0.6.0 --depth 1 --recursive https://github.com/nibanks/msh3 - % cd msh3 && mkdir build && cd build - % cmake -G 'Visual Studio 17 2022' -DCMAKE_BUILD_TYPE=RelWithDebInfo .. - % cmake --build . --config Release - % cmake --install . --config Release - -**Note** - On Windows, Schannel will be used for TLS support by default. If -you with to use (the quictls fork of) OpenSSL, specify the -`-DQUIC_TLS=openssl` option to the generate command above. Also note that -OpenSSL brings with it an additional set of build dependencies not specified -here. - -Build curl (in [Visual Studio Command -prompt](../winbuild/README.md#open-a-command-prompt)): - - % git clone https://github.com/curl/curl - % cd curl/winbuild - % nmake /f Makefile.vc mode=dll WITH_MSH3=dll MSH3_PATH="C:/Program Files/msh3" MACHINE=x64 - -**Note** - If you encounter a build error with `tool_hugehelp.c` being -missing, rename `tool_hugehelp.c.cvs` in the same directory to -`tool_hugehelp.c` and then run `nmake` again. - -Run in the `C:/Program Files/msh3/lib` directory, copy `curl.exe` to that -directory, or copy `msquic.dll` and `msh3.dll` from that directory to the -`curl.exe` directory. For example: - - % C:\Program Files\msh3\lib> F:\curl\builds\libcurl-vc-x64-release-dll-ipv6-sspi-schannel-msh3\bin\curl.exe --http3 https://www.google.com +If `make install` results in `Permission denied` error, you need to prepend +it with `sudo`. # `--http3` Use only HTTP/3: - curl --http3-only https://nghttp2.org:4433/ + % curl --http3-only https://example.org:4433/ Use HTTP/3 with fallback to HTTP/2 or HTTP/1.1 (see "HTTPS eyeballing" below): - curl --http3 https://nghttp2.org:4433/ + % curl --http3 https://example.org:4433/ Upgrade via Alt-Svc: - curl --alt-svc altsvc.cache https://quic.aiortc.org/ + % curl --alt-svc altsvc.cache https://curl.se/ See this [list of public HTTP/3 servers](https://bagder.github.io/HTTP3-test/) ### HTTPS eyeballing -With option `--http3` curl will attempt earlier HTTP versions as well should -the connect attempt via HTTP/3 not succeed "fast enough". This strategy is -similar to IPv4/6 happy eyeballing where the alternate address family is used -in parallel after a short delay. +With option `--http3` curl attempts earlier HTTP versions as well should the +connect attempt via HTTP/3 fail "fast enough". This strategy is similar +to IPv4/6 happy eyeballing where the alternate address family is used in +parallel after a short delay. The IPv4/6 eyeballing has a default of 200ms and you may override that via `--happy-eyeballs-timeout-ms value`. Since HTTP/3 is still relatively new, we @@ -283,25 +274,26 @@ or HTTP/1.1. At half of that value - currently - is the **soft** timeout. The soft timeout fires, when there has been **no data at all** seen from the server on the HTTP/3 connection. -So, without you specifying anything, the hard timeout is 200ms and the soft is 100ms: +Without you specifying anything, the hard timeout is 200ms and the soft is +100ms: - * Ideally, the whole QUIC handshake happens and curl has an HTTP/3 connection - in less than 100ms. - * When QUIC is not supported (or UDP does not work for this network path), no - reply is seen and the HTTP/2 TLS+TCP connection starts 100ms later. - * In the worst case, UDP replies start before 100ms, but drag on. This will - start the TLS+TCP connection after 200ms. - * When the QUIC handshake fails, the TLS+TCP connection is attempted right - away. For example, when the QUIC server presents the wrong certificate. +* Ideally, the whole QUIC handshake happens and curl has an HTTP/3 connection + in less than 100ms. +* When QUIC is not supported (or UDP does not work for this network path), no + reply is seen and the HTTP/2 TLS+TCP connection starts 100ms later. +* In the worst case, UDP replies start before 100ms, but drag on. This starts + the TLS+TCP connection after 200ms. +* When the QUIC handshake fails, the TLS+TCP connection is attempted right + away. For example, when the QUIC server presents the wrong certificate. The whole transfer only fails, when **both** QUIC and TLS+TCP fail to handshake or time out. Note that all this happens in addition to IP version happy eyeballing. If the -name resolution for the server gives more than one IP address, curl will try -all those until one succeeds - just as with all other protocols. And if those -IP addresses contain both IPv6 and IPv4, those attempts will happen, delayed, -in parallel (the actual eyeballing). +name resolution for the server gives more than one IP address, curl tries all +those until one succeeds - as with all other protocols. If those IP addresses +contain both IPv6 and IPv4, those attempts happen, delayed, in parallel (the +actual eyeballing). ## Known Bugs @@ -316,10 +308,9 @@ development and experimenting. An existing local HTTP/1.1 server that hosts files. Preferably also a few huge ones. You can easily create huge local files like `truncate -s=8G 8GB` - they -are huge but do not occupy that much space on disk since they are just big -holes. +are huge but do not occupy that much space on disk since they are big holes. -In a Debian setup you can install **apache2**. It runs on port 80 and has a +In a Debian setup you can install apache2. It runs on port 80 and has a document root in `/var/www/html`. Download the 8GB file from apache with `curl localhost/8GB -o dev/null` @@ -332,29 +323,31 @@ You can select either or both of these server solutions. ### nghttpx -Get, build and install **quictls**, **nghttp3** and **ngtcp2** as described +Get, build and install quictls, nghttp3 and ngtcp2 as described above. -Get, build and install **nghttp2**: +Get, build and install nghttp2: - git clone https://github.com/nghttp2/nghttp2.git - cd nghttp2 - autoreconf -fi - PKG_CONFIG_PATH=$PKG_CONFIG_PATH:/home/daniel/build-quictls/lib/pkgconfig:/home/daniel/build-nghttp3/lib/pkgconfig:/home/daniel/build-ngtcp2/lib/pkgconfig LDFLAGS=-L/home/daniel/build-quictls/lib CFLAGS=-I/home/daniel/build-quictls/include ./configure --enable-maintainer-mode --prefix=/home/daniel/build-nghttp2 --disable-shared --enable-app --enable-http3 --without-jemalloc --without-libxml2 --without-systemd - make && make install + % git clone --depth 1 https://github.com/nghttp2/nghttp2 + % cd nghttp2 + % autoreconf -fi + % PKG_CONFIG_PATH=$PKG_CONFIG_PATH:/path/to/quictls/lib/pkgconfig:/path/to/nghttp3/lib/pkgconfig:/path/to/ngtcp2/lib/pkgconfig \ + LDFLAGS=-L/path/to/quictls/lib CFLAGS=-I/path/to/quictls/include ./configure --enable-maintainer-mode \ + --prefix=/path/to/nghttp2 --disable-shared --enable-app --enable-http3 --without-jemalloc --without-libxml2 --without-systemd + % make && make install Run the local h3 server on port 9443, make it proxy all traffic through to -HTTP/1 on localhost port 80. For local toying, we can just use the test cert -that exists in curl's test dir. +HTTP/1 on localhost port 80. For local toying, we can use the test cert that +exists in curl's test dir. - CERT=$CURLSRC/tests/stunnel.pem - $HOME/bin/nghttpx $CERT $CERT --backend=localhost,80 \ - --frontend="localhost,9443;quic" + % CERT=/path/to/stunnel.pem + % $HOME/bin/nghttpx $CERT $CERT --backend=localhost,80 \ + --frontend="localhost,9443;quic" ### Caddy -[Install Caddy](https://caddyserver.com/docs/install). For easiest use, the binary -should be either in your PATH or your current directory. +[Install Caddy](https://caddyserver.com/docs/install). For easiest use, the +binary should be either in your PATH or your current directory. Create a `Caddyfile` with the following content: ~~~ @@ -365,9 +358,11 @@ localhost:7443 { Then run Caddy: - ./caddy start + % ./caddy start -Making requests to `https://localhost:7443` should tell you which protocol is being used. +Making requests to `https://localhost:7443` should tell you which protocol is +being used. -You can change the hard-coded response to something more useful by replacing `respond` -with `reverse_proxy` or `file_server`, for example: `reverse_proxy localhost:80` +You can change the hard-coded response to something more useful by replacing +`respond` with `reverse_proxy` or `file_server`, for example: `reverse_proxy +localhost:80` diff --git a/third-party/curl/docs/HTTPSRR.md b/third-party/curl/docs/HTTPSRR.md new file mode 100644 index 0000000000..fbdebc7fde --- /dev/null +++ b/third-party/curl/docs/HTTPSRR.md @@ -0,0 +1,100 @@ + + +# HTTPS RR + +[RFC 9460](https://datatracker.ietf.org/doc/html/rfc9460) documents the HTTPS +DNS Resource Record. + +curl features **experimental** support for HTTPS RR. + +- The ALPN list from the record is parsed and used +- The ECH field is stored - and used if ECH is enabled in the build +- The port number is not used (Firefox supports it, Chrome does not) +- The target name is not used +- The IP addresses (`Ipv6hints`, `Ipv4hints`) from the HTTPS RR are not used +- It only supports a single HTTPS RR per hostname +- Hostnames without A/AAAA records but *with* HTTPS RR fails +- consider service profiles where the RR provides different addresses for TCP + vs QUIC etc + +`HTTPSRR` is listed as a feature in the `curl -V` output if curl contains +HTTPS RR support. If c-ares is not included in the build, the HTTPS RR support +is limited to DoH. + +`asyn-rr` is listed as a feature in the `curl -V` output if c-ares is used for +additional resolves in addition to a "normal" resolve done with the threaded +resolver. + +The data extracted from the HTTPS RR is stored in the in-memory DNS cache to +be reused on subsequent uses of the same hostnames. + +## limitations + +We have decided to work on the HTTPS RR support by following what seems to be +(widely) used, and wait with implementing the details of the record +that do not seem to be deployed. HTTPS RR is a DNS field with many odd corners +and complexities and we might as well avoid them if no one seems to want them. + +## build + + ./configure --enable-httpsrr + +or + + cmake -DUSE_HTTPSRR=ON + +## ALPN + +The list of ALPN IDs is parsed but may not be completely respected because of +what the HTTP version preference is set to, which is a problem we are working +on. Also, getting an `HTTP/1.1` ALPN in the HTTPS RR field for an `http://` +transfer should imply switching to HTTPS, HSTS style. Which curl currently +does not. + +## DoH + +When HTTPS RR is enabled in the curl build, The DoH code asks for an HTTPS +record in addition to the A and AAAA records, and if an HTTPS RR answer is +returned, curl parses it and stores the retrieved information. + +## Non-DoH + +If DoH is not used for name resolving in an HTTPS RR enabled build, we must +provide the ability using the regular resolver backends. We use the c-ares DNS +library for the HTTPS RR lookup. Version 1.28.0 or later. + +### c-ares + +If curl is built to use the c-ares library for name resolves, an HTTPS RR +enabled build makes a request for the HTTPS RR in addition to the regular +lookup. + +### Threaded resolver + +When built to use the threaded resolver, which is the default, an HTTPS RR +build still needs a c-ares installation provided so that a separate request +for the HTTPS record can be done in parallel to the regular getaddrinfo() +call. + +This is done by specifying both c-ares and threaded resolver to configure: + + ./configure --enable-ares=... --enable-threaded-resolver + +or to cmake: + + cmake -DENABLE_ARES=ON -DENABLE_THREADED_RESOLVER=ON + +Because the HTTPS record is handled separately from the A/AAAA record +retrieval, by a separate library, there is a small risk for discrepancies. + +When building curl using the threaded resolver with HTTPS RR support (using +c-ares), the `curl -V` output looks exactly like a c-ares resolver build. + +## HTTPS RR Options + +Because curl is a low level transfer tool for which users sometimes want +detailed control, we need to offer options to control HTTPS RR use. diff --git a/third-party/curl/docs/HYPER.md b/third-party/curl/docs/HYPER.md deleted file mode 100644 index 1c3b0dded4..0000000000 --- a/third-party/curl/docs/HYPER.md +++ /dev/null @@ -1,69 +0,0 @@ -# Hyper - -Hyper is a separate HTTP library written in Rust. curl can be told to use this -library as a backend to deal with HTTP. - -## Experimental! - -Hyper support in curl is considered **EXPERIMENTAL** until further notice. It -needs to be explicitly enabled at build-time. - -Further development and tweaking of the Hyper backend support in curl will -happen in the master branch using pull-requests, just like ordinary -changes. - -## Hyper version - -The C API for Hyper is brand new and is still under development. - -## build curl with hyper - -Using Rust 1.64.0 or later, build hyper and enable its C API like this: - - % git clone https://github.com/hyperium/hyper - % cd hyper - % RUSTFLAGS="--cfg hyper_unstable_ffi" cargo rustc --features client,http1,http2,ffi --crate-type cdylib - -Also, `--release` can be added for a release (optimized) build. - -Build curl to use hyper's C API: - - % git clone https://github.com/curl/curl - % cd curl - % autoreconf -fi - % ./configure LDFLAGS="-Wl,-rpath,/target/debug -Wl,-rpath,/target/release" --with-openssl --with-hyper= - % make - -# using Hyper internally - -Hyper is a low level HTTP transport library. curl itself provides all HTTP -headers and Hyper provides all received headers back to curl. - -Therefore, most of the "header logic" in curl as in responding to and acting -on specific input and output headers are done the same way in curl code. - -The API in Hyper delivers received HTTP headers as (cleaned up) name=value -pairs, making it impossible for curl to know the exact byte representation -over the wire with Hyper. - -## Limitations - -The hyper backend does not support - -- `CURLOPT_IGNORE_CONTENT_LENGTH` -- `--raw` and disabling `CURLOPT_HTTP_TRANSFER_DECODING` -- RTSP -- hyper is much stricter about what HTTP header contents it allows -- leading whitespace in first HTTP/1 response header -- HTTP/0.9 -- HTTP/2 upgrade using HTTP:// URLs. Aka 'h2c' - -## Remaining issues - -This backend is still not feature complete with the native backend. Areas that -still need attention and verification include: - -- multiplexed HTTP/2 -- h2 Upgrade: -- receiving HTTP/1 trailers -- sending HTTP/1 trailers diff --git a/third-party/curl/docs/INFRASTRUCTURE.md b/third-party/curl/docs/INFRASTRUCTURE.md new file mode 100644 index 0000000000..a4f8b58433 --- /dev/null +++ b/third-party/curl/docs/INFRASTRUCTURE.md @@ -0,0 +1,201 @@ + + +# Infrastructure in the curl project + +Overview of infrastructure we maintain, host and run in the project for the +project. + +## git repository + +Since 2010, the main curl git repository has been hosted by GitHub, available +at https://github.com/curl/curl. + +We also use the issue tracker, pull requests and discussions on GitHub. + +curl has an "enterprise account" on GitHub and is an "organization" on the +site. + +We accept sponsorship via GitHub Sponsors. + +## CI services + +For every pull request and git push to the master repository, a number of +build and testing jobs are run on a set of different CI services. The exact +services vary over time. GitHub Actions and AppVeyor are the primary ones +these days. + +## Test Clutch + +A [Test Clutch](https://github.com/dfandrich/testclutch) instance generates +regular reports on curl CI test results at https://testclutch.curl.se/ as well +as writing comments on curl pull requests whose tests have failed. The jobs +are hosted on a Virtuozzo Application Platform PaaS instance and is managed by +Dan Fandrich. The configuration code is available and managed at +https://github.com/dfandrich/testclutch-curl-web + +## Autobuilds + +The curl autobuild system is a set of scripts that build and test curl and +send all output logs back to the autobuild server. The results are +continuously collected and visualized on the curl website at +. + +The autobuild system and server is maintained by Daniel Stenberg. + +## OSS-Fuzz + +Google runs the [OSS-Fuzz](https://google.github.io/oss-fuzz/) project which +also runs fuzzing on curl code, non-stop, in their infrastructure and they +send us emails in the rare instances they actually find something. + +OSS-Fuzz notifies those that are members in the "curl team". Any curl +maintainer who wants to is welcome to participate. It requires a Google +account. + +## Coverity + +We regularly run our code through the [Coverity static code +analyzer](https://scan.coverity.com/) thanks to them offering this service to +us free of charge. + +## CodeSonar + +[CodeSonar](https://www.adacore.com/codesonar) analyzes the curl +source code daily and emails Daniel Stenberg whenever it finds suspected +problems in the source code. I hope and expect that we can invite other +maintainers to access these reports soon. + +## Domain names + +The project runs services and website using a few different curl related +domain names, including `curl.se` and `curl.dev`. Daniel Stenberg owns these +domain names. + +Until a few years ago, the curl website was present at `curl.haxx.se`. The +`haxx.se` domain is owned by Haxx AB, administered by Daniel Stenberg. The +curl.haxx.se name is meant to keep working and be redirecting to curl.se for +the foreseeable future. + +## Websites + +The main curl website at `curl.se` is maintained by curl maintainers and the +content is available and managed at https://github.com/curl/curl-www. The site +updates from git and runs make every 20 minutes. Any change pushed to git can +thus take up to 20 minutes until it takes effect on the origin server. + +The content on `curl.dev` is available and managed at +https://github.com/curl/curl.dev/ + +The content on `everything-curl.dev` is available and managed at +https://github.com/curl/everything-curl/ + +The machine hosting the website contents for these three sites is owned by +Haxx AB and is primarily managed by Daniel Stenberg (co-owner of the Haxx +company). The machine is physically located in Sweden. + +curl release tarballs are hosted on https://curl.se/download.html. They are +uploaded there at release-time by the release manager. + +curl-for-win downloads are hosted on https://curl.se/windows/ and are uploaded +to the server by Viktor Szakats. + +curl-for-QNX downloads are hosted on and are uploaded +to the server by Daniel Stenberg. + +Daily release tarball-like snapshots are generated automatically and are +provided for download at . + +CA certificate bundles are extracted from the Firefox source code, hosted by +Mozilla and converted to PEM file format and is offered for download. The +conversion checks for updates daily. The bundle is provided for download at +. + +There is an automated "download check bot" that runs twice daily to scan for +available curl downloads to populate the curl download page appropriately with +the correct updated information. The bot uses URLs and patterns for all +download packages and is maintained in a database, maintained by Daniel +Stenberg and Dan Fandrich. + +The TLS certificate for the origin curl web server is automatically updated +from Let's Encrypt. + +## CDN + +Fastly runs the Content Delivery Network (CDN) that fronts all the curl +websites. The CDN caches content that it gets from the origin server. +Recently, roughly 99.99% of web requests are satisfied by the CDN without +having to reach the origin. + +The CDN caches different content at different lengths depending on the +content-type. The caching thus adds to the time for a change to have an effect +on the site from the moment it gets pushed to the git repository. + +Using this setup, we provide four IPv4 addresses and eight IPv6 addresses for +anycast access to the site. Should be snappy from virtually everywhere across +the globe. + +The CDN servers support HTTP/1, HTTP/2 and HTTP/3. They set HSTS for a year. +The `http://` version of the site redirects to `https://`. + +Fastly manages the TLS certificates from Let's Encrypt for the servers they +run on the behalf of curl. + +## Containers + +The curl project offer container builds of curl. The source repository for +them is located at . + +Container images are hosted at and + + +## DNS + +The primary domain name, `curl.se` is managed by Kirei and is offered over +fault-tolerant anycast servers. High availability and fast access for +everyone. + +The actual physical DNS files and origin bind instance is managed by Daniel +Stenberg. + +## Mailing lists + +The curl related mailing lists are hosted by Haxx AB on `lists.haxx.se` and +are maintained by Daniel Stenberg. This includes the mailman2 and Postfix +instances used for this. + +## Email + +We use a few rare additional curl related email aliases in the curl domains. +They go through the mail server `mail.haxx.se` maintained by Daniel Stenberg + +## Open Collective + +We use [Open Collective](https://opencollective.com/curl) as our "fiscal +host". All money sent to and received by the curl project is managed by Open +Collective. + +## Merchandise + +We have stickers, coffee mugs and coasters. They are managed by Daniel who +sits on the inventory. The best way to get your hands on curl merchandise is +to attend events where Daniel is physically. + +## Chat + +Some curl developers, maintainers, users and enthusiasts use IRC for real-time +chat about curl and related topics. This done in the `#curl` channel on the +`libra.chat` IRC network. **Daniel Stenberg** (`bagder`) is registered owner +of the channel. We do not run any IRC servers or services ourselves. + +`curelbot` is a service in the channel that shows details about GitHub issues +and pull requests when publicly mentioned using #[number]. The bot is run by +user `TheAssassin`. + +There is a Matrix bridge to the IRC channel called `matrix.curl.se`. The +bridge is setup and run by **Sergio Durigan Junior** and **Daniel Stenberg**. + +[curl online chat documentation](https://curl.se/docs/irc.html) diff --git a/third-party/curl/docs/INSTALL-CMAKE.md b/third-party/curl/docs/INSTALL-CMAKE.md new file mode 100644 index 0000000000..64975ab630 --- /dev/null +++ b/third-party/curl/docs/INSTALL-CMAKE.md @@ -0,0 +1,612 @@ + + +# Building with CMake + +This document describes how to configure, build and install curl and libcurl +from source code using the CMake build tool. To build with CMake, you of +course first have to install CMake. The minimum required version of CMake is +specified in the file `CMakeLists.txt` found in the top of the curl source +tree. Once the correct version of CMake is installed you can follow the +instructions below for the platform you are building on. + +CMake builds can be configured either from the command line, or from one of +CMake's GUIs. + +# Configuring + +A CMake configuration of curl is similar to the autotools build of curl. +It consists of the following steps after you have unpacked the source. + +We recommend building with CMake on Windows. For instructions on migrating +from the `projects/Windows` Visual Studio solution files, see +[this section](#migrating-from-visual-studio-ide-project-files). + +## Using `cmake` + +You can configure for in source tree builds or for a build tree +that is apart from the source tree. + +- Build in the source tree. + + $ cmake -B . + +- Build in a separate directory (parallel to the curl source tree in this + example). The build directory is created for you. This is recommended over + building in the source tree to separate source and build artifacts. + + $ cmake -B ../curl-build + +For the full list of CMake build configuration variables see +[the corresponding section](#cmake-build-options). + +### Build system generator selection + +You can override CMake's default by using `-G `. For example +on Windows with multiple build systems if you have MinGW-w64 then you could use +`-G "MinGW Makefiles"`. +[List of generator names](https://cmake.org/cmake/help/latest/manual/cmake-generators.7.html). + +## Using `ccmake` + +CMake comes with a curses based interface called `ccmake`. To run `ccmake` +on a curl use the instructions for the command line cmake, but substitute +`ccmake` for `cmake`. + +This brings up a curses interface with instructions on the bottom of the +screen. You can press the "c" key to configure the project, and the "g" key to +generate the project. After the project is generated, you can run make. + +## Using `cmake-gui` + +CMake also comes with a Qt based GUI called `cmake-gui`. To configure with +`cmake-gui`, you run `cmake-gui` and follow these steps: + +1. Fill in the "Where is the source code" combo box with the path to + the curl source tree. +2. Fill in the "Where to build the binaries" combo box with the path to + the directory for your build tree, ideally this should not be the same + as the source tree, but a parallel directory called curl-build or + something similar. +3. Once the source and binary directories are specified, press the + "Configure" button. +4. Select the native build tool that you want to use. +5. At this point you can change any of the options presented in the GUI. + Once you have selected all the options you want, click the "Generate" + button. + +# Building + +Build (you have to specify the build directory). + + $ cmake --build ../curl-build + +## Static builds + +The CMake build setup is primarily done to work with shared/dynamic third +party dependencies. When linking with shared libraries, the dependency "chain" +is handled automatically by the library loader - on all modern systems. + +If you instead link with a static library, you need to provide all the +dependency libraries already at the link command line. + +Figuring out all the dependency libraries for a given library is hard, as it +might involve figuring out the dependencies of the dependencies and they vary +between platforms and can change between versions. + +When using static dependencies, the build scripts mostly assume that you, the +user, provide all the necessary additional dependency libraries as additional +arguments in the build. + +Building statically is not for the faint of heart. + +# Testing + +(The test suite does not yet work with the cmake build) + +# Installing + +Install to default location (you have to specify the build directory). + + $ cmake --install ../curl-build + +Do not use `--prefix` to change the installation prefix as the output produced +by the `curl-config` script is determined at CMake configure time. If you want +to set a custom install prefix for curl, set +[`CMAKE_INSTALL_PREFIX`](https://cmake.org/cmake/help/latest/variable/CMAKE_INSTALL_PREFIX.html) +when configuring the CMake build. + +# CMake usage + +This section describes how to locate and use curl/libcurl from CMake-based +projects. + +## Using `find_package` + +To locate libcurl from CMake, one can use the standard +[`find_package`](https://cmake.org/cmake/help/latest/command/find_package.html) +command in the typical fashion: + +```cmake +find_package(CURL 8.12.0 REQUIRED) # FATAL_ERROR if CURL is not found +``` + +This invokes the CMake-provided +[FindCURL](https://cmake.org/cmake/help/latest/module/FindCURL.html) find module, +which first performs a search using the `find_package` +[config mode](https://cmake.org/cmake/help/latest/command/find_package.html#config-mode-search-procedure). +This is supported by the `CURLConfig.cmake` CMake config script which is +available if the given CURL was built and installed using CMake. + +### Detecting CURL features/protocols + +Since version 8.12.0, `CURLConfig.cmake` publishes the supported CURL features +and protocols (see [release notes](https://curl.se/ch/8.12.0.html)). These can +be specified using the `find_package` keywords `COMPONENTS` and +`OPTIONAL_COMPONENTS`, with protocols in all caps, e.g. `HTTPS`, `LDAP`, while +features should be in their original sentence case, e.g. `AsynchDNS`, +`UnixSockets`. If any of the `COMPONENTS` are missing, then CURL is considered +as *not* found. + +Here is an example of using `COMPONENTS` and `OPTIONAL_COMPONENTS` in +`find_package` with CURL: + +```cmake +# CURL_FOUND is FALSE if no HTTPS but brotli and zstd can be missing +find_package(CURL 8.12.0 COMPONENTS HTTPS OPTIONAL_COMPONENTS brotli zstd) +``` + +One can also check the defined `CURL_SUPPORTS_` variables +if a particular feature/protocol is supported. For example: + +```cmake +# check HTTPS +if(CURL_SUPPORTS_HTTPS) + message(STATUS "CURL supports HTTPS") +else() + message(STATUS "CURL does NOT support HTTPS") +endif() +``` + +### Linking against libcurl + +To link a CMake target against libcurl one can use +[`target_link_libraries`](https://cmake.org/cmake/help/latest/command/target_link_libraries.html) +as usual: + +```cmake +target_link_libraries(my_target PRIVATE CURL::libcurl) +``` + +# CMake build options + +- `BUILD_CURL_EXE`: Build curl executable. Default: `ON` +- `BUILD_EXAMPLES`: Build libcurl examples. Default: `ON` +- `BUILD_LIBCURL_DOCS`: Build libcurl man pages. Default: `ON` +- `BUILD_MISC_DOCS`: Build misc man pages (e.g. `curl-config` and `mk-ca-bundle`). Default: `ON` +- `BUILD_SHARED_LIBS`: Build shared libraries. Default: `ON` (if target platform supports shared libs, otherwise `OFF`) +- `BUILD_STATIC_CURL`: Build curl executable with static libcurl. Default: `OFF` (turns to `ON`, when building static libcurl only) +- `BUILD_STATIC_LIBS`: Build static libraries. Default: `OFF` (turns to `ON` if `BUILD_SHARED_LIBS` is `OFF`) +- `BUILD_TESTING`: Build tests. Default: `ON` +- `CURL_BUILD_EVERYTHING`: Build optional build targets (examples, tests) by default. Default: `OFF` + Set `QUICK` to build examples quickly with the `curl-examples-build` target (for build tests). + Set `NOEXAMPLES` to not build examples. +- `CURL_CLANG_TIDY`: Run the build through `clang-tidy`. Default: `OFF` + If enabled, it implies `CURL_DISABLE_TYPECHECK=ON` and force-disables unity mode + for libcurl and the curl tool. +- `CURL_CLANG_TIDYFLAGS`: Custom options to pass to `clang-tidy`. Default: (empty) +- `CURL_CODE_COVERAGE`: Enable code coverage build options. Default: `OFF` +- `CURL_COMPLETION_FISH`: Install fish completions. Default: `OFF` +- `CURL_COMPLETION_FISH_DIR`: Custom fish completion install directory. +- `CURL_COMPLETION_ZSH`: Install zsh completions. Default: `OFF` +- `CURL_COMPLETION_ZSH_DIR`: Custom zsh completion install directory. +- `CURL_DEFAULT_SSL_BACKEND`: Override default TLS backend in MultiSSL builds. + Accepted values in order of default priority: + `wolfssl`, `gnutls`, `mbedtls`, `openssl`, `schannel`, `rustls` +- `CURL_DROP_UNUSED`: Drop unused code and data from built binaries. Default: `OFF` +- `CURL_ENABLE_EXPORT_TARGET`: Enable CMake export target. Default: `ON` +- `CURL_GCC_ANALYZER`: Enable GCC `--analyzer` option. Default: `OFF` +- `CURL_HIDDEN_SYMBOLS`: Hide libcurl internal symbols (=hide all symbols that are not officially external). Default: `ON` +- `CURL_LIBCURL_SOVERSION`: Enable libcurl SOVERSION. Default: `ON` for supported platforms +- `CURL_LIBCURL_VERSIONED_SYMBOLS`: Enable libcurl versioned symbols. Default: `OFF` +- `CURL_LIBCURL_VERSIONED_SYMBOLS_PREFIX`: Override default versioned symbol prefix. Default: `_` or `MULTISSL_` +- `CURL_LINT`: Run lint checks while building. Default: `OFF` +- `CURL_LTO`: Enable compiler Link Time Optimizations. Default: `OFF` +- `CURL_PATCHSTAMP`: Set security patch string for `curl -V`/`curl --version` output. +- `CURL_STATIC_CRT`: Build libcurl with static CRT with MSVC (`/MT`) (requires UCRT, static libcurl or no curl executable). Default: `OFF` +- `CURL_TARGET_WINDOWS_VERSION`: Minimum target Windows version as hex string, e.g. `0x0a00` for Windows 10. +- `CURL_WERROR`: Turn compiler warnings into errors. Default: `OFF` +- `ENABLE_CURL_MANUAL`: Build the man page for curl and enable its `-M`/`--manual` option. Default: `ON` +- `ENABLE_DEBUG`: Enable curl debug features (for developing curl itself). Default: `OFF` +- `IMPORT_LIB_SUFFIX`: Import library suffix. Default: `_imp` for MSVC-like toolchains, otherwise empty. +- `LIBCURL_OUTPUT_NAME`: Basename of the curl library. Default: `libcurl` +- `PICKY_COMPILER`: Enable picky compiler options. Default: `ON` +- `SHARE_LIB_OBJECT`: Build shared and static libcurl in a single pass (requires CMake 3.12 or newer). Default: `ON` for Windows +- `STATIC_LIB_SUFFIX`: Static library suffix. Default: (empty) + +## Root CA options + +- `CURL_CA_BUNDLE`: Absolute path to the CA bundle. Set `none` to disable or `auto` for auto-detection. Default: `auto` +- `CURL_CA_EMBED`: Absolute path to the CA bundle to embed in the curl tool. Default: (disabled) +- `CURL_CA_FALLBACK`: Use built-in CA store of OpenSSL. Default: `OFF` +- `CURL_CA_NATIVE`: Use native CA store. Default: `OFF` + Supported by GnuTLS, OpenSSL (including forks) on Windows, wolfSSL. +- `CURL_CA_PATH`: Absolute path to a directory containing CA certificates stored individually. + Set `none` to disable or `auto` for auto-detection. Default: `auto` +- `CURL_CA_SEARCH_SAFE`: Enable safe CA bundle search (within the curl tool directory) on Windows. Default: `OFF` +- `USE_APPLE_SECTRUST`: Use Apple OS-native certificate verification. Default: `OFF` + +## Enabling features + +- `CURL_ENABLE_NTLM`: Enable NTLM support. Default: `OFF` +- `CURL_ENABLE_SMB`: Enable SMB. Default: `OFF` +- `CURL_ENABLE_SSL`: Enable SSL support. Default: `ON` +- `CURL_WINDOWS_SSPI`: Enable SSPI on Windows. Default: =`CURL_USE_SCHANNEL` +- `ENABLE_IPV6`: Enable IPv6 support. Default: `ON` if target supports IPv6. +- `ENABLE_THREADED_RESOLVER`: Enable threaded DNS lookup. Default: `ON` if c-ares is not enabled and target supports threading. +- `ENABLE_UNICODE`: Use the Unicode version of the Windows API functions. Default: `OFF` +- `ENABLE_UNIX_SOCKETS`: Enable Unix domain sockets support. Default: `ON` +- `USE_APPLE_IDN`: Use Apple built-in IDN support. Default: `OFF` +- `USE_ECH`: Enable ECH support (experimental). Default: `OFF` +- `USE_HTTPSRR`: Enable HTTPS RR support (experimental). Default: `OFF` +- `USE_PROXY_HTTP3`: Enable HTTP/3 proxy support (experimental). Default: `OFF` +- `USE_SSLS_EXPORT`: Enable SSL session import/export (experimental). Default: `OFF` +- `USE_WIN32_IDN`: Use WinIDN for IDN support. Default: `OFF` +- `USE_WIN32_LDAP`: Use Windows LDAP implementation. Default: `ON` + +## Disabling features + +- `CURL_DISABLE_ALTSVC`: Disable alt-svc support. Default: `OFF` +- `CURL_DISABLE_AWS`: Disable **aws-sigv4**. Default: `OFF` +- `CURL_DISABLE_BASIC_AUTH`: Disable Basic authentication. Default: `OFF` +- `CURL_DISABLE_BEARER_AUTH`: Disable Bearer authentication. Default: `OFF` +- `CURL_DISABLE_BINDLOCAL`: Disable local binding support. Default: `OFF` +- `CURL_DISABLE_CA_SEARCH`: Disable unsafe CA bundle search in PATH on Windows. Default: `OFF` (turns to `ON`, when `CURL_CA_NATIVE=ON`) +- `CURL_DISABLE_COOKIES`: Disable cookies support. Default: `OFF` +- `CURL_DISABLE_DICT`: Disable DICT. Default: `OFF` +- `CURL_DISABLE_DIGEST_AUTH`: Disable Digest authentication. Default: `OFF` +- `CURL_DISABLE_DOH`: Disable DNS-over-HTTPS. Default: `OFF` +- `CURL_DISABLE_FILE`: Disable FILE. Default: `OFF` +- `CURL_DISABLE_FORM_API`: Disable **form-api**. Default: =`CURL_DISABLE_MIME` +- `CURL_DISABLE_FTP`: Disable FTP. Default: `OFF` +- `CURL_DISABLE_GETOPTIONS`: Disable `curl_easy_options` API for existing options to `curl_easy_setopt`. Default: `OFF` +- `CURL_DISABLE_GOPHER`: Disable Gopher. Default: `OFF` +- `CURL_DISABLE_HEADERS_API`: Disable **headers-api** support. Default: `OFF` +- `CURL_DISABLE_HSTS`: Disable HSTS support. Default: `OFF` +- `CURL_DISABLE_HTTP`: Disable HTTP. Default: `OFF` +- `CURL_DISABLE_HTTP_AUTH`: Disable all HTTP authentication methods. Default: `OFF` +- `CURL_DISABLE_IMAP`: Disable IMAP. Default: `OFF` +- `CURL_DISABLE_INSTALL`: Disable installation targets. Default: `OFF` +- `CURL_DISABLE_IPFS`: Disable IPFS. Default: `OFF` +- `CURL_DISABLE_KERBEROS_AUTH`: Disable Kerberos authentication. Default: `OFF` +- `CURL_DISABLE_LDAP`: Disable LDAP. Default: `OFF` +- `CURL_DISABLE_LDAPS`: Disable LDAPS. Default: =`CURL_DISABLE_LDAP` +- `CURL_DISABLE_LIBCURL_OPTION`: Disable `--libcurl` option from the curl tool. Default: `OFF` +- `CURL_DISABLE_MIME`: Disable MIME support. Default: `OFF` +- `CURL_DISABLE_MQTT`: Disable MQTT. Default: `OFF` +- `CURL_DISABLE_NEGOTIATE_AUTH`: Disable negotiate authentication. Default: `OFF` +- `CURL_DISABLE_NETRC`: Disable netrc parser. Default: `OFF` +- `CURL_DISABLE_OPENSSL_AUTO_LOAD_CONFIG`: Disable automatic loading of OpenSSL configuration. Default: `OFF` +- `CURL_DISABLE_PARSEDATE`: Disable date parsing. Default: `OFF` +- `CURL_DISABLE_POP3`: Disable POP3. Default: `OFF` +- `CURL_DISABLE_PROGRESS_METER`: Disable built-in progress meter. Default: `OFF` +- `CURL_DISABLE_PROXY`: Disable proxy support. Default: `OFF` +- `CURL_DISABLE_RTSP`: Disable RTSP. Default: `OFF` +- `CURL_DISABLE_SHA512_256`: Disable SHA-512/256 hash algorithm. Default: `OFF` +- `CURL_DISABLE_SHUFFLE_DNS`: Disable shuffle DNS feature. Default: `OFF` +- `CURL_DISABLE_SMTP`: Disable SMTP. Default: `OFF` +- `CURL_DISABLE_SOCKETPAIR`: Disable use of socketpair for curl_multi_poll(). Default: `OFF` +- `CURL_DISABLE_SRP`: Disable TLS-SRP support. Default: `OFF` +- `CURL_DISABLE_TELNET`: Disable Telnet. Default: `OFF` +- `CURL_DISABLE_TFTP`: Disable TFTP. Default: `OFF` +- `CURL_DISABLE_TYPECHECK`: Disable curl_easy_setopt()/curl_easy_getinfo() type checking. Default: `OFF` +- `CURL_DISABLE_VERBOSE_STRINGS`: Disable verbose strings. Default: `OFF` +- `CURL_DISABLE_WEBSOCKETS`: Disable WebSocket. Default: `OFF` +- `HTTP_ONLY`: Disable all protocols except HTTP (This overrides all `CURL_DISABLE_*` options). Default: `OFF` + +## Environment + +- `CI`: Assume running under CI if set. +- `CURL_BUILDINFO`: Print `buildinfo.txt` if set. +- `CURL_CI`: Assume running under CI if set. + +## Environment (via CMake) + +- `CC`: Set C compiler. Alternative to `CMAKE_C_COMPILER` option. +- `CFLAGS`: Pass custom C compiler flags. Alternative to `CMAKE_C_FLAGS` option. +- `CMAKE_GENERATOR`: Alternative to `-G` command-line option. +- `DESTDIR`: Set install destination directory. +- `LDFLAGS`: Pass custom linker flags. + +Details via CMake +[envvars](https://cmake.org/cmake/help/latest/manual/cmake-env-variables.7.html). + +## CMake options + +- `CMAKE_BUILD_TYPE`: (see CMake) +- `CMAKE_DEBUG_POSTFIX`: Default: `-d` +- `CMAKE_IMPORT_LIBRARY_SUFFIX` (see CMake) +- `CMAKE_INSTALL_BINDIR` (see CMake) +- `CMAKE_INSTALL_INCLUDEDIR` (see CMake) +- `CMAKE_INSTALL_LIBDIR` (see CMake) +- `CMAKE_INSTALL_PREFIX` (see CMake) +- `CMAKE_STATIC_LIBRARY_SUFFIX` (see CMake) +- `CMAKE_UNITY_BUILD_BATCH_SIZE`: Set the number of sources in a "unity" unit. Default: `0` (all) +- `CMAKE_UNITY_BUILD`: Enable "unity" (aka "jumbo") builds. Default: `OFF` + +Details via CMake +[variables](https://cmake.org/cmake/help/latest/manual/cmake-variables.7.html) and +[install directories](https://cmake.org/cmake/help/latest/module/GNUInstallDirs.html). + +## Dependencies + +- `CURL_BROTLI`: Use brotli (`ON`, `OFF` or `AUTO`). Default: `AUTO` +- `CURL_USE_CMAKECONFIG`: Enable detecting dependencies via CMake Config. + Default: `ON` for MSVC (except under vcpkg), if not cross-compiling. (experimental) +- `CURL_USE_GNUTLS`: Enable GnuTLS for SSL/TLS. Default: `OFF` +- `CURL_USE_GSASL`: Use libgsasl. Default: `OFF` +- `CURL_USE_GSSAPI`: Use GSSAPI implementation. Default: `OFF` +- `CURL_USE_LIBBACKTRACE`: Use [libbacktrace](https://github.com/ianlancetaylor/libbacktrace). + Requires debug-enabled build and DWARF debug information. Default: `OFF` +- `CURL_USE_LIBPSL`: Use libpsl. Default: `ON` +- `CURL_USE_LIBSSH2`: Use libssh2. Default: `ON` +- `CURL_USE_LIBSSH`: Use libssh. Default: `OFF` +- `CURL_USE_LIBUV`: Use libuv for event-based tests. Default: `OFF` +- `CURL_USE_MBEDTLS`: Enable mbedTLS for SSL/TLS. Default: `OFF` +- `CURL_USE_OPENSSL`: Enable OpenSSL for SSL/TLS. Default: `ON` if no other TLS backend was enabled. +- `CURL_USE_PKGCONFIG`: Enable `pkg-config` to detect dependencies. + Default: `ON` for Unix (except Android, Apple devices), vcpkg, MinGW if not cross-compiling. +- `CURL_USE_RUSTLS`: Enable Rustls for SSL/TLS (experimental). Default: `OFF` +- `CURL_USE_SCHANNEL`: Enable Windows native SSL/TLS (Schannel). Default: `OFF` +- `CURL_USE_WOLFSSL`: Enable wolfSSL for SSL/TLS. Default: `OFF` +- `CURL_ZLIB`: Use zlib (`ON`, `OFF` or `AUTO`). Default: `AUTO` +- `CURL_ZSTD`: Use zstd (`ON`, `OFF` or `AUTO`). Default: `AUTO` +- `ENABLE_ARES`: Enable c-ares support. Default: `OFF` +- `USE_LIBIDN2`: Use libidn2 for IDN support. Default: `ON` +- `USE_NGHTTP2`: Use nghttp2 library. Default: `ON` +- `USE_NGTCP2`: Use ngtcp2 and nghttp3 libraries for HTTP/3 support. Default: `OFF` +- `USE_QUICHE`: Use quiche library for HTTP/3 support (experimental). Default: `OFF` + +## Dependency options (via CMake) + +- `OPENSSL_ROOT_DIR`: Absolute path to the root installation of OpenSSL (and forks). +- `OPENSSL_INCLUDE_DIR`: Absolute path to OpenSSL include directory. +- `OPENSSL_SSL_LIBRARY`: Absolute path to `ssl` library. + With MSVC, CMake uses variables `SSL_EAY_DEBUG`/`SSL_EAY_RELEASE` instead. +- `OPENSSL_CRYPTO_LIBRARY`: Absolute path to `crypto` library. + With MSVC, CMake uses variables `LIB_EAY_DEBUG`/`LIB_EAY_RELEASE` instead. +- `OPENSSL_USE_STATIC_LIBS`: Look for static OpenSSL libraries. +- `ZLIB_INCLUDE_DIR`: Absolute path to zlib include directory. +- `ZLIB_LIBRARY`: Absolute path to `zlib` library. +- `ZLIB_USE_STATIC_LIBS`: Look for static `zlib` library (requires CMake v3.24). +- `_DIR`: Absolute path to `` CMake Config directory where `*.cmake` files reside. + Used when `CURL_USE_CMAKECONFIG` is enabled. + `` may be: + `c-ares`, `Libssh2`, `MbedTLS`, `NGHTTP2`, `NGHTTP3`, + `NGTCP2` for 1.19.0+ (with non-fork OpenSSL only), + `wolfssl` for 5.2.1+, `Zstd` for 1.4.5+. + +## Dependency options (tools) + +- `CLANG_TIDY`: Absolute path to `clang-tidy` tool used with `CURL_CLANG_TIDY=ON`. Default: search for `clang-tidy` +- `PERL_EXECUTABLE`: Absolute path to Perl binary used throughout the build and tests. Default: auto-detect + +## Dependency options (libraries) + +- `AMISSL_INCLUDE_DIR`: Absolute path to AmiSSL include directory. +- `AMISSL_STUBS_LIBRARY`: Absolute path to `amisslstubs` library. +- `AMISSL_AUTO_LIBRARY`: Absolute path to `amisslauto` library. +- `BORINGSSL_VERSION`: Set BoringSSL version for `curl -V`/`curl --version` output. +- `BROTLI_INCLUDE_DIR`: Absolute path to brotli include directory. +- `BROTLICOMMON_LIBRARY`: Absolute path to `brotlicommon` library. +- `BROTLIDEC_LIBRARY`: Absolute path to `brotlidec` library. +- `BROTLI_USE_STATIC_LIBS`: Configure for static brotli libraries. (experimental) +- `CARES_INCLUDE_DIR`: Absolute path to c-ares include directory. +- `CARES_LIBRARY`: Absolute path to `cares` library. +- `CARES_USE_STATIC_LIBS`: Configure for static c-ares libraries. (experimental) +- `DL_LIBRARY`: Absolute path to `dl` library. (for Rustls) +- `GNUTLS_INCLUDE_DIR`: Absolute path to GnuTLS include directory. +- `GNUTLS_LIBRARY`: Absolute path to `gnutls` library. +- `GSS_ROOT_DIR`: Absolute path to the root installation of GSS. (also supported as environment) +- `LDAP_INCLUDE_DIR`: Absolute path to LDAP include directory. +- `LDAP_LIBRARY`: Absolute path to `ldap` library. +- `LDAP_LBER_LIBRARY`: Absolute path to `lber` library. +- `LIBBACKTRACE_INCLUDE_DIR`: Absolute path to libbacktrace include directory (https://github.com/ianlancetaylor/libbacktrace). +- `LIBBACKTRACE_LIBRARY`: Absolute path to `libbacktrace` library. +- `LIBGSASL_INCLUDE_DIR`: Absolute path to libgsasl include directory. +- `LIBGSASL_LIBRARY`: Absolute path to `libgsasl` library. +- `LIBIDN2_INCLUDE_DIR`: Absolute path to libidn2 include directory. +- `LIBIDN2_LIBRARY`: Absolute path to `libidn2` library. +- `LIBPSL_INCLUDE_DIR`: Absolute path to libpsl include directory. +- `LIBPSL_LIBRARY`: Absolute path to `libpsl` library. +- `LIBSSH_INCLUDE_DIR`: Absolute path to libssh include directory. +- `LIBSSH_LIBRARY`: Absolute path to `libssh` library. +- `LIBSSH_USE_STATIC_LIBS`: Configure for static libssh libraries. (experimental) +- `LIBSSH2_INCLUDE_DIR`: Absolute path to libssh2 include directory. +- `LIBSSH2_LIBRARY`: Absolute path to `libssh2` library. +- `LIBSSH2_USE_STATIC_LIBS`: Configure for static libssh2 libraries. (experimental) +- `LIBUV_INCLUDE_DIR`: Absolute path to libuv include directory. +- `LIBUV_LIBRARY`: Absolute path to `libuv` library. +- `MATH_LIBRARY`: Absolute path to `m` library. (for Rustls, wolfSSL) +- `MBEDTLS_INCLUDE_DIR`: Absolute path to mbedTLS include directory. +- `MBEDTLS_LIBRARY`: Absolute path to `mbedtls` library. +- `MBEDX509_LIBRARY`: Absolute path to `mbedx509` library. +- `MBEDCRYPTO_LIBRARY`: Absolute path to `mbedcrypto` library. +- `MBEDTLS_USE_STATIC_LIBS`: Configure for static mbedTLS libraries. (experimental) +- `NGHTTP2_INCLUDE_DIR`: Absolute path to nghttp2 include directory. +- `NGHTTP2_LIBRARY`: Absolute path to `nghttp2` library. +- `NGHTTP2_USE_STATIC_LIBS`: Configure for static nghttp2 libraries. (experimental) +- `NGHTTP3_INCLUDE_DIR`: Absolute path to nghttp3 include directory. +- `NGHTTP3_LIBRARY`: Absolute path to `nghttp3` library. +- `NGHTTP3_USE_STATIC_LIBS`: Configure for static nghttp3 libraries. (experimental) +- `NGTCP2_INCLUDE_DIR`: Absolute path to ngtcp2 include directory. +- `NGTCP2_LIBRARY`: Absolute path to `ngtcp2` library. +- `NGTCP2_CRYPTO_BORINGSSL_LIBRARY`: Absolute path to `ngtcp2_crypto_boringssl` library. (also for AWS-LC) +- `NGTCP2_CRYPTO_GNUTLS_LIBRARY`: Absolute path to `ngtcp2_crypto_gnutls` library. +- `NGTCP2_CRYPTO_LIBRESSL_LIBRARY`: Absolute path to `ngtcp2_crypto_libressl` library. (requires ngtcp2 1.15.0+) +- `NGTCP2_CRYPTO_OSSL_LIBRARY`: Absolute path to `ngtcp2_crypto_ossl` library. +- `NGTCP2_CRYPTO_QUICTLS_LIBRARY`: Absolute path to `ngtcp2_crypto_quictls` library. (also for LibreSSL with ngtcp2 <1.15.0) +- `NGTCP2_CRYPTO_WOLFSSL_LIBRARY`: Absolute path to `ngtcp2_crypto_wolfssl` library. +- `NGTCP2_USE_STATIC_LIBS`: Configure for static ngtcp2 libraries. (experimental) +- `NETTLE_INCLUDE_DIR`: Absolute path to nettle include directory. +- `NETTLE_LIBRARY`: Absolute path to `nettle` library. +- `PTHREAD_LIBRARY`: Absolute path to `pthread` library. (for Rustls) +- `QUICHE_INCLUDE_DIR`: Absolute path to quiche include directory. +- `QUICHE_LIBRARY`: Absolute path to `quiche` library. +- `RUSTLS_INCLUDE_DIR`: Absolute path to Rustls include directory. +- `RUSTLS_LIBRARY`: Absolute path to `rustls` library. +- `WATT_ROOT`: Absolute path to the root installation of Watt-32. +- `WOLFSSL_INCLUDE_DIR`: Absolute path to wolfSSL include directory. +- `WOLFSSL_LIBRARY`: Absolute path to `wolfssl` library. +- `ZSTD_INCLUDE_DIR`: Absolute path to zstd include directory. +- `ZSTD_LIBRARY`: Absolute path to `zstd` library. +- `ZSTD_USE_STATIC_LIBS`: Configure for static zstd libraries. (experimental) + +Examples: + +- `-DLIBPSL_INCLUDE_DIR=/path/to/libpl/include`, + which directory contains `libpsl.h`. + No ending slash or backslash is necessary. + +- `-DNGHTTP3_INCLUDE_DIR=/path/to/libnghttp3/include`, + which directory contains an `nghttp3` subdirectory with `.h` files in it. + +- `-DLIBPSL_LIBRARY=/path/to/libpsl/lib/libpsl.a` + Always a single library, with its complete filename, as-is on the file system. + +- `-DOPENSSL_ROOT_DIR=/path/to/openssl`, + which directory (typically) contains `include` and `lib` subdirectories. + No ending slash or backslash is necessary. + +## Dependency options (Apple frameworks) + +- `COREFOUNDATION_FRAMEWORK`: Absolute path to `CoreFoundation` framework. (for IPv6 non-c-ares, SecTrust, wolfSSL) +- `CORESERVICES_FRAMEWORK`: Absolute path to `CoreServices` framework. (for IPv6 non-c-ares, SecTrust) +- `FOUNDATION_FRAMEWORK`: Absolute path to `Foundation` framework. (for Rustls) +- `SECURITY_FRAMEWORK`: Absolute path to `Security` framework. (for Rustls, SecTrust, wolfSSL) +- `SYSTEMCONFIGURATION_FRAMEWORK`: Absolute path to `SystemConfiguration` framework. (for IPv6 non-c-ares) + +## Test tools + +- `APXS`: Absolute path. Default: search for `apxs` +- `CADDY`: Absolute path. Default: search for `caddy` +- `H2O`: Absolute path. Default: search for `h2o` +- `HTTPD_NGHTTPX`: Absolute path. Default: search for `nghttpx` +- `HTTPD`: Absolute path. Default: search for `apache2` +- `DANTED`: Absolute path. Default: search for `danted` +- `TEST_NGHTTPX`: Absolute path. Default: search for `nghttpx` +- `VSFTPD`: Absolute path. Default: search for `vsftpd` +- `SSHD`: Absolute path. Default: search for `sshd` +- `SFTPD`: Absolute path. Default: search for `sftp-server` + +## Feature detection variables + +By default the curl CMake build script detects the version of some dependencies +using `check_symbol_exists()`. Those checks do not work in the case that both +CURL and its dependency are included as sub-projects in a larger build using +`FetchContent`. To support that case, additional variables may be defined by +the parent project, ideally in the "extra" find package redirect file: + + +Available variables: + +- `HAVE_DES_ECB_ENCRYPT`: `DES_ecb_encrypt` present in OpenSSL (or fork). +- `HAVE_GNUTLS_SRP`: `gnutls_srp_verifier` present in GnuTLS. +- `HAVE_LDAP_INIT_FD`: `ldap_init_fd` present in LDAP library. +- `HAVE_LDAP_URL_PARSE`: `ldap_url_parse` present in LDAP library. +- `HAVE_MBEDTLS_DES_CRYPT_ECB`: `mbedtls_des_crypt_ecb` present in mbedTLS <4. +- `HAVE_OPENSSL_SRP`: `SSL_CTX_set_srp_username` present in OpenSSL (or fork). +- `HAVE_QUICHE_CONN_SET_QLOG_FD`: `quiche_conn_set_qlog_fd` present in quiche. +- `HAVE_RUSTLS_SUPPORTED_HPKE`: `rustls_supported_hpke` present in Rustls (unused if Rustls is detected via `pkg-config`). +- `HAVE_SSL_SET0_WBIO`: `SSL_set0_wbio` present in OpenSSL (or fork). +- `HAVE_SSL_SET1_ECH_CONFIG_LIST`: `SSL_set1_ech_config_list` present in OpenSSL (or fork). +- `HAVE_SSL_SET_QUIC_TLS_CBS`: `SSL_set_quic_tls_cbs` in OpenSSL. +- `HAVE_SSL_SET_QUIC_USE_LEGACY_CODEPOINT`: `SSL_set_quic_use_legacy_codepoint` in OpenSSL fork. +- `HAVE_WOLFSSL_BIO_NEW`: `wolfSSL_BIO_new` present in wolfSSL. +- `HAVE_WOLFSSL_BIO_SET_SHUTDOWN`: `wolfSSL_BIO_set_shutdown` present in wolfSSL. +- `HAVE_WOLFSSL_CTX_GENERATEECHCONFIG`: `wolfSSL_CTX_GenerateEchConfig` present in wolfSSL. +- `HAVE_WOLFSSL_GET_PEER_CERTIFICATE`: `wolfSSL_get_peer_certificate` present in wolfSSL. +- `HAVE_WOLFSSL_SET_QUIC_USE_LEGACY_CODEPOINT`: + `wolfSSL_set_quic_use_legacy_codepoint` present in wolfSSL. +- `HAVE_WOLFSSL_USEALPN`: `wolfSSL_UseALPN` present in wolfSSL. +- `HAVE_WC_DES_ECBENCRYPT`: `wc_Des_EcbEncrypt` present in wolfSSL. + +For each of the above variables, if the variable is *defined* (either to `ON` +or `OFF`), the symbol detection is skipped. If the variable is *not defined*, +the feature detection is performed. + +Note: These variables are internal and subject to change. + +## Useful build targets + +- `testdeps`: Build test dependencies (test binaries, test certificates). + Test certificates: `build-certs` (clean with `clean-certs`) +- `tests`: Run tests (`runtests.pl`). Customize via the `TFLAGS` environment variable, e.g. `TFLAGS=1621`. + Other flavors: `test-am`, `test-ci`, `test-event`, `test-full`, `test-nonflaky`, `test-quiet`, `test-torture` +- `tt`: Build test binaries (servers, tools). + Individual targets: `curlinfo`, `libtests`, `servers`, `tunits`, `units` +- `curl-pytest`: Run tests (pytest). + Other flavor: `curl-test-ci` +- `curl-examples`: Build examples + Individual targets: `curl-example-`, + where is the .c filename without extension. +- `curl-examples-build`: Build examples quickly but without the ability to run them. (for build tests) +- `curl-man`: Build man pages. (built by default unless disabled) +- `curl`: Build curl tool. +- `curl_uninstall`: Uninstall curl. +- `curl-completion-fish`: Build shell completions for fish. (built by default if enabled) +- `curl-completion-zsh`: Build shell completions for zsh. (built by default if enabled) +- `curl-ca-bundle`: Build the CA bundle via `scripts/mk-ca-bundle.pl`. +- `curl-ca-firefox`: Build the CA bundle via `scripts/firefox-db2pem.sh`. +- `curl-lint`: Run lint checks. +- `curl-listcats`: Generate help category constants for `src/tool_help.h` from documentation. +- `curl-listhelp`: Generate `src/tool_listhelp.c` from documentation. +- `curl-optiontable`: Generate `lib/easyoptions.c` from documentation. + +# Migrating from Visual Studio IDE Project Files + +We recommend using CMake to build curl with MSVC. + +The project build files reside in project/Windows/VC\* for VS2010, VS2012 and +VS2013. + +These CMake Visual Studio generators require CMake v3.24 or older. You can +download them from . + +You can also use `-G "NMake Makefiles"`, which is supported by all CMake +versions. + +Configuration element | Equivalent CMake options +:-------------------------------- | :-------------------------------- +`VC10` | `-G "Visual Studio 10 2010"` +`VC11` | `-G "Visual Studio 11 2012"` +`VC12` | `-G "Visual Studio 12 2013"` +`x64` | `-A x64` +`Win32` | `-A Win32` +`DLL` | `BUILD_SHARED_LIBS=ON`, `BUILD_STATIC_LIBS=OFF`, (default) +`LIB` | `BUILD_SHARED_LIBS=OFF`, `BUILD_STATIC_LIBS=ON` +`Debug` | `CMAKE_BUILD_TYPE=Debug` (`-G "NMake Makefiles"` only) +`Release` | `CMAKE_BUILD_TYPE=Release` (`-G "NMake Makefiles"` only) +`DLL Windows SSPI` | `CURL_USE_SCHANNEL=ON` (with SSPI enabled by default) +`DLL OpenSSL` | `CURL_USE_OPENSSL=ON`, optional: `OPENSSL_ROOT_DIR`, `OPENSSL_USE_STATIC_LIBS=ON` +`DLL libssh2` | `CURL_USE_LIBSSH2=ON`, optional: `LIBSSH2_INCLUDE_DIR`, `LIBSSH2_LIBRARY` +`DLL WinIDN` | `USE_WIN32_IDN=ON` + +For example these commands: + + > cd projects/Windows + > ./generate.bat VC12 + > msbuild "-property:Configuration=DLL Debug - DLL Windows SSPI - DLL WinIDN" VC12/curl-all.sln + +translate to: + + > cmake . -G "Visual Studio 12 2013" -A x64 -DCURL_USE_SCHANNEL=ON -DUSE_WIN32_IDN=ON -DCURL_USE_LIBPSL=OFF + > cmake --build . --config Debug --parallel + +We do *not* specify `-DCMAKE_BUILD_TYPE=Debug` here as we might do for the +`"NMake Makefiles"` generator because the Visual Studio generators are +[multi-config generators](https://cmake.org/cmake/help/latest/prop_gbl/GENERATOR_IS_MULTI_CONFIG.html) +and therefore ignore the value of `CMAKE_BUILD_TYPE`. diff --git a/third-party/curl/docs/INSTALL.cmake b/third-party/curl/docs/INSTALL.cmake deleted file mode 100644 index 4e7f706a96..0000000000 --- a/third-party/curl/docs/INSTALL.cmake +++ /dev/null @@ -1,89 +0,0 @@ - _ _ ____ _ - ___| | | | _ \| | - / __| | | | |_) | | - | (__| |_| | _ <| |___ - \___|\___/|_| \_\_____| - - How To Compile with CMake - -Building with CMake -========================== - This document describes how to compile, build and install curl and libcurl - from source code using the CMake build tool. To build with CMake, you will - of course have to first install CMake. The minimum required version of - CMake is specified in the file CMakeLists.txt found in the top of the curl - source tree. Once the correct version of CMake is installed you can follow - the instructions below for the platform you are building on. - - CMake builds can be configured either from the command line, or from one - of CMake's GUI's. - -Current flaws in the curl CMake build -===================================== - - Missing features in the cmake build: - - - Builds libcurl without large file support - - Does not support all SSL libraries (only OpenSSL, Schannel, - Secure Transport, and mbedTLS, WolfSSL) - - Does not allow different resolver backends (no c-ares build support) - - No RTMP support built - - Does not allow build curl and libcurl debug enabled - - Does not allow a custom CA bundle path - - Does not allow you to disable specific protocols from the build - - Does not find or use krb4 or GSS - - Rebuilds test files too eagerly, but still cannot run the tests - - Does not detect the correct strerror_r flavor when cross-compiling (issue #1123) - - -Command Line CMake -================== - A CMake build of curl is similar to the autotools build of curl. It - consists of the following steps after you have unpacked the source. - - 1. Create an out of source build tree parallel to the curl source - tree and change into that directory - - $ mkdir curl-build - $ cd curl-build - - 2. Run CMake from the build tree, giving it the path to the top of - the curl source tree. CMake will pick a compiler for you. If you - want to specify the compile, you can set the CC environment - variable prior to running CMake. - - $ cmake ../curl - $ make - - 3. Install to default location: - - $ make install - - (The test suite does not work with the cmake build) - -ccmake -========= - CMake comes with a curses based interface called ccmake. To run ccmake on - a curl use the instructions for the command line cmake, but substitute - ccmake ../curl for cmake ../curl. This will bring up a curses interface - with instructions on the bottom of the screen. You can press the "c" key - to configure the project, and the "g" key to generate the project. After - the project is generated, you can run make. - -cmake-gui -========= - CMake also comes with a Qt based GUI called cmake-gui. To configure with - cmake-gui, you run cmake-gui and follow these steps: - 1. Fill in the "Where is the source code" combo box with the path to - the curl source tree. - 2. Fill in the "Where to build the binaries" combo box with the path - to the directory for your build tree, ideally this should not be the - same as the source tree, but a parallel directory called curl-build or - something similar. - 3. Once the source and binary directories are specified, press the - "Configure" button. - 4. Select the native build tool that you want to use. - 5. At this point you can change any of the options presented in the - GUI. Once you have selected all the options you want, click the - "Generate" button. - 6. Run the native build tool that you used CMake to generate. diff --git a/third-party/curl/docs/INSTALL.md b/third-party/curl/docs/INSTALL.md index 28ad553048..467aa64c05 100644 --- a/third-party/curl/docs/INSTALL.md +++ b/third-party/curl/docs/INSTALL.md @@ -1,17 +1,24 @@ -# how to install curl and libcurl + + +# How to install curl and libcurl ## Installing Binary Packages Lots of people download binary distributions of curl and libcurl. This document does not describe how to install curl or libcurl using such a binary package. This document describes how to compile, build and install curl and -libcurl from source code. +libcurl from [source code](https://curl.se/download.html). ## Building using vcpkg -You can download and install curl and libcurl using the [vcpkg](https://github.com/Microsoft/vcpkg/) dependency manager: +You can download and install curl and libcurl using +the [vcpkg](https://github.com/Microsoft/vcpkg) dependency manager: - git clone https://github.com/Microsoft/vcpkg.git + git clone --depth 1 https://github.com/Microsoft/vcpkg cd vcpkg ./bootstrap-vcpkg.sh ./vcpkg integrate install @@ -24,8 +31,8 @@ or pull request](https://github.com/Microsoft/vcpkg) on the vcpkg repository. ## Building from git If you get your code off a git repository instead of a release tarball, see -the `GIT-INFO` file in the root directory for specific instructions on how to -proceed. +the [GIT-INFO.md](https://github.com/curl/curl/blob/master/GIT-INFO.md) file in +the root directory for specific instructions on how to proceed. # Unix @@ -39,6 +46,9 @@ unpacked the source archive): (Adjust the configure line accordingly to use the TLS library you want.) +By default curl builds with libpsl (Public Suffix List) support. If libpsl is +not available on your system, install it or disable it with `--without-libpsl`. + You probably need to be root when doing the last command. Get a full listing of all available configure options by invoking it like: @@ -58,10 +68,9 @@ your own home directory: make make install -The configure script always tries to find a working SSL library unless -explicitly told not to. If you have OpenSSL installed in the default search -path for your compiler/linker, you do not need to do anything special. If you -have OpenSSL installed in `/usr/local/ssl`, you can run configure like: +The configure script requires you to select a TLS backend explicitly unless +you disable TLS with `--without-ssl`. If you have OpenSSL installed in the +default search path for your compiler/linker, you can run configure like: ./configure --with-openssl @@ -84,7 +93,7 @@ header files somewhere else, you have to set the `LDFLAGS` and `CPPFLAGS` environment variables prior to running configure. Something like this should work: - CPPFLAGS="-I/path/to/ssl/include" LDFLAGS="-L/path/to/ssl/lib" ./configure + CPPFLAGS="-I/path/to/ssl/include" LDFLAGS="-L/path/to/ssl/lib" ./configure --with-openssl If you have shared SSL libs installed in a directory where your runtime linker does not find them (which usually causes configure failures), you can @@ -110,10 +119,10 @@ Figuring out all the dependency libraries for a given library is hard, as it might involve figuring out the dependencies of the dependencies and they vary between platforms and change between versions. -When using static dependencies, the build scripts will mostly assume that you, -the user, will provide all the necessary additional dependency libraries as -additional arguments in the build. With configure, by setting `LIBS` or -`LDFLAGS` on the command line. +When using static dependencies, the build scripts mostly assume that you, the +user, provide all the necessary additional dependency libraries as additional +arguments in the build. With configure, by setting `LIBS` or `LDFLAGS` on the +command line. Building statically is not for the faint of heart. @@ -123,32 +132,63 @@ If you are a curl developer and use gcc, you might want to enable more debug options with the `--enable-debug` option. curl can be built to use a whole range of libraries to provide various useful -services, and configure will try to auto-detect a decent default. But if you -want to alter it, you can select how to deal with each individual library. +services, and configure tries to auto-detect a decent default. If you want to +alter it, you can select how to deal with each individual library. + +To debug the build itself, you can set the environment variable +`CURL_TRACE_PKG_CONFIG` to a non-empty value to enable detailed trace +information and verbose errors from `pkg-config` module detection invocations. ## Select TLS backend These options are provided to select the TLS backend to use. - - AmiSSL: `--with-amissl` - - BearSSL: `--with-bearssl` - - GnuTLS: `--with-gnutls`. - - mbedTLS: `--with-mbedtls` - - OpenSSL: `--with-openssl` (also for BoringSSL, AWS-LC, libressl, and quictls) - - rustls: `--with-rustls` - - Schannel: `--with-schannel` - - Secure Transport: `--with-secure-transport` - - wolfSSL: `--with-wolfssl` +- AmiSSL: `--with-amissl` +- GnuTLS: `--with-gnutls`. +- mbedTLS: `--with-mbedtls` +- OpenSSL: `--with-openssl` (also for AWS-LC, BoringSSL, LibreSSL, and quictls) +- Rustls: `--with-rustls` +- Schannel: `--with-schannel` +- wolfSSL: `--with-wolfssl` You can build curl with *multiple* TLS backends at your choice, but some TLS backends cannot be combined: if you build with an OpenSSL fork (or wolfSSL), -you cannot add another OpenSSL fork (or wolfSSL) simply because they have +you cannot add another OpenSSL fork (or wolfSSL) because they have conflicting identical symbol names. When you build with multiple TLS backends, you can select the active one at -run-time when curl starts up. +runtime when curl starts up. -## configure finding libs in wrong directory +### Selecting TLS Trust Anchors Defaults + +Verifying a server certificate established a chain of trust that needs to +start somewhere. Those "root" certificates make the set of Trust Anchors. + +While the build system tries to find good defaults on the platform you +use, you may specify these explicitly. The following options are provided: + +- `--with-ca-bundle=FILE`: the file that libcurl loads default root + certificates from. +- `--with-ca-path=DIRECTORY`: a directory in which root certificates files + are found. +- `--with-ca-embed=FILE`: a file read *at build time* and added to `libcurl`. +- `--with-ca-fallback`: an OpenSSL specific option for delegating default + trust anchor selection to what OpenSSL thinks is best, *if* there are + no other certificates configured by the application. +- `--with-apple-sectrust`: use the system "SecTrust" service on Apple + operating systems for verification. (Added in 8.17.0) + +## MultiSSL and HTTP/3 + +HTTP/3 needs QUIC and QUIC needs TLS. Building libcurl with HTTP/3 and QUIC +support is not compatible with the MultiSSL feature: they are mutually +exclusive. If you need MultiSSL in your build, you cannot have HTTP/3 support +and vice versa. + +libcurl can only use a single TLS library with QUIC and that *same* TLS +library needs to be used for the other TLS using protocols. + +## Configure finding libs in wrong directory When the configure script checks for third-party libraries, it adds those directories to the `LDFLAGS` variable and then tries linking to see if it @@ -162,106 +202,175 @@ library check. # Windows +Building for Windows Vista/Server 2008 is required as a minimum. + +You can build curl with: + +- Microsoft Visual Studio 2010 v10.0 or later (`_MSC_VER >= 1600`) +- MinGW-w64 3.0 or later (`__MINGW64_VERSION_MAJOR >= 3`) + ## Building Windows DLLs and C runtime (CRT) linkage issues - As a general rule, building a DLL with static CRT linkage is highly - discouraged, and intermixing CRTs in the same app is something to avoid at - any cost. +As a general rule, building a DLL with static CRT linkage is highly +discouraged, and intermixing CRTs in the same app is something to avoid at +any cost. - Reading and comprehending Microsoft Knowledge Base articles KB94248 and - KB140584 is a must for any Windows developer. Especially important is full - understanding if you are not going to follow the advice given above. +Reading and comprehending Microsoft Knowledge Base articles KB94248 and +KB140584 is a must for any Windows developer. Especially important is full +understanding if you are not going to follow the advice given above. - - [How To Use the C Run-Time](https://support.microsoft.com/help/94248/how-to-use-the-c-run-time) - - [Run-Time Library Compiler Options](https://docs.microsoft.com/cpp/build/reference/md-mt-ld-use-run-time-library) - - [Potential Errors Passing CRT Objects Across DLL Boundaries](https://docs.microsoft.com/cpp/c-runtime-library/potential-errors-passing-crt-objects-across-dll-boundaries) +- [How To Use the C Runtime](https://learn.microsoft.com/troubleshoot/developer/visualstudio/cpp/libraries/use-c-run-time) +- [Runtime Library Compiler Options](https://learn.microsoft.com/cpp/build/reference/md-mt-ld-use-run-time-library) +- [Potential Errors Passing CRT Objects + Across DLL Boundaries](https://learn.microsoft.com/cpp/c-runtime-library/potential-errors-passing-crt-objects-across-dll-boundaries) If your app is misbehaving in some strange way, or it is suffering from memory corruption, before asking for further help, please try first to rebuild every single library your app uses as well as your app using the debug multi-threaded dynamic C runtime. - If you get linkage errors read section 5.7 of the FAQ document. - -## MinGW32 - -Make sure that MinGW32's bin directory is in the search path, for example: - -```cmd -set PATH=c:\mingw32\bin;%PATH% -``` - -then run `mingw32-make mingw32` in the root dir. There are other -make targets available to build libcurl with more features, use: - - - `mingw32-make mingw32-zlib` to build with Zlib support; - - `mingw32-make mingw32-ssl-zlib` to build with SSL and Zlib enabled; - - `mingw32-make mingw32-ssh2-ssl-zlib` to build with SSH2, SSL, Zlib; - - `mingw32-make mingw32-ssh2-ssl-sspi-zlib` to build with SSH2, SSL, Zlib - and SSPI support. - -If you have any problems linking libraries or finding header files, be sure -to verify that the provided `Makefile.mk` files use the proper paths, and -adjust as necessary. It is also possible to override these paths with -environment variables, for example: - -```cmd -set ZLIB_PATH=c:\zlib-1.2.12 -set OPENSSL_PATH=c:\openssl-3.0.5 -set LIBSSH2_PATH=c:\libssh2-1.10.0 -``` - -It is also possible to build with other LDAP installations than MS LDAP; -currently it is possible to build with native Win32 OpenLDAP, or with the -*Novell CLDAP* SDK. If you want to use these you need to set these vars: - -```cmd -set CPPFLAGS=-Ic:/openldap/include -DCURL_HAS_OPENLDAP_LDAPSDK -set LDFLAGS=-Lc:/openldap/lib -set LIBS=-lldap -llber -``` - -or for using the Novell SDK: - -```cmd -set CPPFLAGS=-Ic:/openldapsdk/inc -DCURL_HAS_NOVELL_LDAPSDK -set LDFLAGS=-Lc:/openldapsdk/lib/mscvc -set LIBS=-lldapsdk -lldapssl -lldapx -``` - -If you want to enable LDAPS support then append `-ldaps` to the make target. +If you get linkage errors read section 5.7 of the FAQ document. ## Cygwin -Almost identical to the Unix installation. Run the configure script in the -curl source tree root with `sh configure`. Make sure you have the `sh` -executable in `/bin/` or you will see the configure fail toward the end. +Almost identical to the Unix installation. Download the `curl` source code, +then essentially run the configure script in the curl source tree root with +`sh configure`, then run `make`. -Run `make` +To expand on building with Cygwin first ensure it is in your path, and +there are no conflicting tools (*i.e. Chocolatey with sed package*). If so +move Cygwin ahead of any items in your path that would conflict with +Cygwin commands, making sure you have the `sh` executable in `/bin/` or +you see the configure fail toward the end. + +Download the setup installer from [Cygwin](https://cygwin.com/) to begin. +Additional Cygwin packages are needed for the install. For more on +installing packages visit +[Cygwin Setup](https://cygwin.com/faq/faq.html#faq.setup.cli). + +Either run `setup-x86_64.exe`, then search and select packages individually, +or try: + + setup-x86_64.exe --no-admin -q -I -P binutils,gcc-core,libpsl-devel,libtool,perl,make + +Expand the below details to show the list of required packages for a +successful Cygwin install: + +
+ Package List + +``` +binutils +gcc-core +libpsl-devel +libtool +perl +make +``` + +
+ +Once all the packages have been installed, begin the process of installing +curl from the source code: + +
+ configure_options + +``` +--with-gnutls +--with-mbedtls +--with-openssl (also works for OpenSSL forks) +--with-rustls +--with-wolfssl +--without-ssl +``` + +
+ +1. `sh configure ` +2. `make` + +> [!Note] +> If an error occurs during the installation, then try: + +- Use `cmake` to configure and/or build +- Use `ninja` to build (***much** faster*) +- Reinstalling the required Cygwin packages from the list above without + passing `-I` to `setup-x86_64` +- Temporarily move Cygwin to the top of your path +- Install all of the Cygwin build packages using + `setup-x86_64 --build-depends curl` ## MS-DOS -Requires DJGPP in the search path and pointing to the Watt-32 stack via -`WATT_PATH=c:/djgpp/net/watt`. +You can use either autotools or cmake: -Run `make -f Makefile.dist djgpp` in the root curl dir. +```sh +./configure \ + CC=/path/to/djgpp/bin/i586-pc-msdosdjgpp-gcc \ + AR=/path/to/djgpp/bin/i586-pc-msdosdjgpp-ar \ + RANLIB=/path/to/djgpp/bin/i586-pc-msdosdjgpp-ranlib \ + WATT_ROOT=/path/to/djgpp/net/watt \ + --host=i586-pc-msdosdjgpp \ + --with-openssl=/path/to/djgpp \ + --with-zlib=/path/to/djgpp \ + --without-libpsl \ + --disable-shared +``` -For build configuration options, please see the MinGW32 section. +```sh +cmake . \ + -DCMAKE_SYSTEM_NAME=DOS \ + -DCMAKE_C_COMPILER_TARGET=i586-pc-msdosdjgpp \ + -DCMAKE_C_COMPILER=/path/to/djgpp/bin/i586-pc-msdosdjgpp-gcc \ + -DWATT_ROOT=/path/to/djgpp/net/watt \ + -DOPENSSL_INCLUDE_DIR=/path/to/djgpp/include \ + -DOPENSSL_SSL_LIBRARY=/path/to/djgpp/lib/libssl.a \ + -DOPENSSL_CRYPTO_LIBRARY=/path/to/djgpp/lib/libcrypto.a \ + -DZLIB_INCLUDE_DIR=/path/to/djgpp/include \ + -DZLIB_LIBRARY=/path/to/djgpp/lib/libz.a \ + -DCURL_USE_LIBPSL=OFF +``` Notes: - - DJGPP 2.04 beta has a `sscanf()` bug so the URL parsing is not done - properly. Use DJGPP 2.03 until they fix it. +- Requires DJGPP 2.04 or upper. - - Compile Watt-32 (and OpenSSL) with the same version of DJGPP. Otherwise - things go wrong because things like FS-extensions and `errno` values have - been changed between releases. +- Compile Watt-32 (and OpenSSL) with the same version of DJGPP. Otherwise + things go wrong because things like FS-extensions and `errno` values have + been changed between releases. ## AmigaOS -Run `make -f Makefile.dist amiga` in the root curl dir. +You can use either autotools or cmake: -For build configuration options, please see the MinGW32 section. +```sh +./configure \ + CC=/opt/amiga/bin/m68k-amigaos-gcc \ + AR=/opt/amiga/bin/m68k-amigaos-ar \ + RANLIB=/opt/amiga/bin/m68k-amigaos-ranlib \ + --host=m68k-amigaos \ + --with-amissl \ + CFLAGS='-O0 -msoft-float -mcrt=clib2' \ + CPPFLAGS=-I/path/to/AmiSSL/Developer/include \ + LDFLAGS=-L/path/to/AmiSSL/Developer/lib/AmigaOS3 \ + LIBS='-lnet -lm -latomic' \ + --without-libpsl \ + --disable-shared +``` + +```sh +cmake . \ + -DAMIGA=1 \ + -DCMAKE_SYSTEM_NAME=Generic \ + -DCMAKE_C_COMPILER_TARGET=m68k-unknown-amigaos \ + -DCMAKE_C_COMPILER=/opt/amiga/bin/m68k-amigaos-gcc \ + -DCMAKE_C_FLAGS='-O0 -msoft-float -mcrt=clib2' \ + -DAMISSL_INCLUDE_DIR=/path/to/AmiSSL/Developer/include \ + -DAMISSL_STUBS_LIBRARY=/path/to/AmiSSL/Developer/lib/AmigaOS3/libamisslstubs.a \ + -DAMISSL_AUTO_LIBRARY=/path/to/AmiSSL/Developer/lib/AmigaOS3/libamisslauto.a \ + -DCURL_USE_LIBPSL=OFF +``` ## Disabling Specific Protocols in Windows builds @@ -270,29 +379,28 @@ environment, therefore, you cannot use the various disable-protocol options of the configure utility on this platform. You can use specific defines to disable specific protocols and features. See -[CURL-DISABLE](CURL-DISABLE.md) for the full list. +[CURL-DISABLE](https://github.com/curl/curl/blob/master/docs/CURL-DISABLE.md) +for the full list. If you want to set any of these defines you have the following options: - - Modify `lib/config-win32.h` - - Modify `lib/curl_setup.h` - - Modify `winbuild/Makefile.vc` - - Modify the "Preprocessor Definitions" in the libcurl project +- Modify `lib/config-win32.h` +- Modify `lib/curl_setup.h` +- Modify the "Preprocessor Definitions" in the libcurl project Note: The pre-processor settings can be found using the Visual Studio IDE under "Project -> Properties -> Configuration Properties -> C/C++ -> Preprocessor". -## Using BSD-style lwIP instead of Winsock TCP/IP stack in Win32 builds +## Using BSD-style lwIP instead of Winsock TCP/IP stack in Windows builds In order to compile libcurl and curl using BSD-style lwIP TCP/IP stack it is necessary to make the definition of the preprocessor symbol `USE_LWIPSOCK` visible to libcurl and curl compilation processes. To set this definition you have the following alternatives: - - Modify `lib/config-win32.h` and `src/config-win32.h` - - Modify `winbuild/Makefile.vc` - - Modify the "Preprocessor Definitions" in the libcurl project +- Modify `lib/config-win32.h` +- Modify the "Preprocessor Definitions" in the libcurl project Note: The pre-processor settings can be found using the Visual Studio IDE under "Project -> Properties -> Configuration Properties -> C/C++ -> @@ -313,96 +421,52 @@ might yet need some additional adjustment. ## Important static libcurl usage note When building an application that uses the static libcurl library on Windows, -you must add `-DCURL_STATICLIB` to your `CFLAGS`. Otherwise the linker will -look for dynamic import symbols. +you must add `-DCURL_STATICLIB` to your `CFLAGS`. Otherwise the linker looks +for dynamic import symbols. ## Legacy Windows and SSL -Schannel (from Windows SSPI), is the native SSL library in Windows. However, -Schannel in Windows <= XP is unable to connect to servers that -no longer support the legacy handshakes and algorithms used by those -versions. If you will be using curl in one of those earlier versions of -Windows you should choose another SSL backend such as OpenSSL. - -# Apple Platforms (macOS, iOS, tvOS, watchOS, and their simulator counterparts) - -On modern Apple operating systems, curl can be built to use Apple's SSL/TLS -implementation, Secure Transport, instead of OpenSSL. To build with Secure -Transport for SSL/TLS, use the configure option `--with-secure-transport`. - -When Secure Transport is in use, the curl options `--cacert` and `--capath` -and their libcurl equivalents, will be ignored, because Secure Transport uses -the certificates stored in the Keychain to evaluate whether or not to trust -the server. This, of course, includes the root certificates that ship with the -OS. The `--cert` and `--engine` options, and their libcurl equivalents, are -currently unimplemented in curl with Secure Transport. - -In general, a curl build for an Apple `ARCH/SDK/DEPLOYMENT_TARGET` combination -can be taken by providing appropriate values for `ARCH`, `SDK`, `DEPLOYMENT_TARGET` -below and running the commands: - -```bash -# Set these three according to your needs -export ARCH=x86_64 -export SDK=macosx -export DEPLOYMENT_TARGET=10.8 - -export CFLAGS="-arch $ARCH -isysroot $(xcrun -sdk $SDK --show-sdk-path) -m$SDK-version-min=$DEPLOYMENT_TARGET" -./configure --host=$ARCH-apple-darwin --prefix $(pwd)/artifacts --with-secure-transport -make -j8 -make install -``` - -Above will build curl for macOS platform with `x86_64` architecture and `10.8` as deployment target. - -Here is an example for iOS device: - -```bash -export ARCH=arm64 -export SDK=iphoneos -export DEPLOYMENT_TARGET=11.0 - -export CFLAGS="-arch $ARCH -isysroot $(xcrun -sdk $SDK --show-sdk-path) -m$SDK-version-min=$DEPLOYMENT_TARGET" -./configure --host=$ARCH-apple-darwin --prefix $(pwd)/artifacts --with-secure-transport -make -j8 -make install -``` - -Another example for watchOS simulator for macs with Apple Silicon: - -```bash -export ARCH=arm64 -export SDK=watchsimulator -export DEPLOYMENT_TARGET=5.0 - -export CFLAGS="-arch $ARCH -isysroot $(xcrun -sdk $SDK --show-sdk-path) -m$SDK-version-min=$DEPLOYMENT_TARGET" -./configure --host=$ARCH-apple-darwin --prefix $(pwd)/artifacts --with-secure-transport -make -j8 -make install -``` - -In all above, the built libraries and executables can be found in the -`artifacts` folder. +Schannel (from Windows SSPI), is the native SSL library in Windows. Schannel +in Windows <= XP is unable to connect to servers that no longer support the +legacy handshakes and algorithms used by those versions. If you are using curl +in one of those earlier versions of Windows you should choose another SSL +backend such as OpenSSL. # Android -When building curl for Android it's recommended to use a Linux/macOS environment -since using curl's `configure` script is the easiest way to build curl -for Android. Before you can build curl for Android, you need to install the -Android NDK first. This can be done using the SDK Manager that is part of -Android Studio. Once you have installed the Android NDK, you need to figure out -where it has been installed and then set up some environment variables before -launching `configure`. On macOS, those variables could look like this to compile -for `aarch64` and API level 29: +When building curl for Android you can either use CMake or `configure`. -```bash +Before you can build curl for Android, you need to install the Android NDK +first. This can be done using the SDK Manager that is part of Android Studio. +Once you have installed the Android NDK, you need to figure out where it has +been installed and then set up some environment variables before launching +the build. + +Examples to compile for `aarch64` and API level 29: + +with CMake, where `ANDROID_NDK_HOME` points into your NDK: + +```sh +cmake . \ + -DANDROID_ABI=arm64-v8a \ + -DANDROID_PLATFORM=android-29 \ + -DCMAKE_TOOLCHAIN_FILE="$ANDROID_NDK_HOME/build/cmake/android.toolchain.cmake" \ + -DCURL_ENABLE_SSL=OFF \ + -DCURL_USE_LIBPSL=OFF +``` + +with `configure`, on macOS: + +```sh export ANDROID_NDK_HOME=~/Library/Android/sdk/ndk/25.1.8937393 # Point into your NDK. -export HOST_TAG=darwin-x86_64 # Same tag for Apple Silicon. Other OS values here: https://developer.android.com/ndk/guides/other_build_systems#overview +# Same tag for Apple Silicon. Other OS values here: +# https://developer.android.com/ndk/guides/other_build_systems#overview +export HOST_TAG=darwin-x86_64 export TOOLCHAIN=$ANDROID_NDK_HOME/toolchains/llvm/prebuilt/$HOST_TAG export AR=$TOOLCHAIN/bin/llvm-ar export AS=$TOOLCHAIN/bin/llvm-as -export CC=$TOOLCHAIN/bin/aarch64-linux-android21-clang -export CXX=$TOOLCHAIN/bin/aarch64-linux-android21-clang++ +export CC=$TOOLCHAIN/bin/aarch64-linux-android29-clang +export CXX=$TOOLCHAIN/bin/aarch64-linux-android29-clang++ export LD=$TOOLCHAIN/bin/ld export RANLIB=$TOOLCHAIN/bin/llvm-ranlib export STRIP=$TOOLCHAIN/bin/llvm-strip @@ -413,16 +477,18 @@ to adjust those variables accordingly. After that you can build curl like this: ./configure --host aarch64-linux-android --with-pic --disable-shared -Note that this will not give you SSL/TLS support. If you need SSL/TLS, you have -to build curl against a SSL/TLS layer, e.g. OpenSSL, because it's impossible for -curl to access Android's native SSL/TLS layer. To build curl for Android using -OpenSSL, follow the OpenSSL build instructions and then install `libssl.a` and -`libcrypto.a` to `$TOOLCHAIN/sysroot/usr/lib` and copy `include/openssl` to -`$TOOLCHAIN/sysroot/usr/include`. Now you can build curl for Android using -OpenSSL like this: +Note that this does not give you SSL/TLS support. If you need SSL/TLS, you +have to build curl with an SSL/TLS library, e.g. OpenSSL, because it is +impossible for curl to access Android's native SSL/TLS layer. To build curl +for Android using OpenSSL, follow the OpenSSL build instructions and then +install `libssl.a` and `libcrypto.a` to `$TOOLCHAIN/sysroot/usr/lib` and copy +`include/openssl` to `$TOOLCHAIN/sysroot/usr/include`. Now you can build curl +for Android using OpenSSL like this: -```bash -LIBS="-lssl -lcrypto -lc++" # For OpenSSL/BoringSSL. In general, you will need to the SSL/TLS layer's transitive dependencies if you are linking statically. +```sh +# For BoringSSL/OpenSSL. In general, you need to the SSL/TLS layer's transitive +# dependencies if you are linking statically. +LIBS='-lssl -lcrypto -lc++' ./configure --host aarch64-linux-android --with-pic --disable-shared --with-openssl="$TOOLCHAIN/sysroot/usr" ``` @@ -432,22 +498,22 @@ For IBM i (formerly OS/400), you can use curl in two different ways: - Natively, running in the **ILE**. The obvious use is being able to call curl from ILE C or RPG applications. - - You will need to build this from source. See `packages/OS400/README` for - the ILE specific build instructions. -- In the **PASE** environment, which runs AIX programs. curl will be built as - it would be on AIX. - - IBM provides builds of curl in their Yum repository for PASE software. - - To build from source, follow the Unix instructions. +- You need to build this from source. See `projects/OS400/README` for the ILE + specific build instructions. +- In the **PASE** environment, which runs AIX programs. curl is built as it + would be on AIX. +- IBM provides builds of curl in their Yum repository for PASE software. +- To build from source, follow the Unix instructions. There are some additional limitations and quirks with curl on this platform; they affect both environments. ## Multi-threading notes -By default, jobs in IBM i will not start with threading enabled. (Exceptions +By default, jobs in IBM i does not start with threading enabled. (Exceptions include interactive PASE sessions started by `QP2TERM` or SSH.) If you use curl in an environment without threading when options like asynchronous DNS -were enabled, you will get messages like: +were enabled, you get messages like: ``` getaddrinfo() thread failed to start @@ -471,9 +537,7 @@ configure with any options you need. Be sure and specify the `--host` and of cross-compiling for the IBM 405GP PowerPC processor using the toolchain on Linux. -```bash -#! /bin/sh - +```sh export PATH=$PATH:/opt/hardhat/devkit/ppc/405/bin export CPPFLAGS="-I/opt/hardhat/devkit/ppc/405/target/usr/include" export AR=ppc_405-ar @@ -483,18 +547,16 @@ export RANLIB=ppc_405-ranlib export CC=ppc_405-gcc export NM=ppc_405-nm -./configure --target=powerpc-hardhat-linux - --host=powerpc-hardhat-linux - --build=i586-pc-linux-gnu - --prefix=/opt/hardhat/devkit/ppc/405/target/usr/local - --exec-prefix=/usr/local +./configure \ + --target=powerpc-hardhat-linux + --host=powerpc-hardhat-linux + --build=i586-pc-linux-gnu + --prefix=/opt/hardhat/devkit/ppc/405/target/usr/local + --exec-prefix=/usr/local ``` -You may also need to provide a parameter like `--with-random=/dev/urandom` to -configure as it cannot detect the presence of a random number generating -device for a target system. The `--prefix` parameter specifies where curl -will be installed. If `configure` completes successfully, do `make` and `make -install` as usual. +The `--prefix` parameter specifies where curl gets installed. If `configure` +completes successfully, do `make` and `make install` as usual. In some cases, you may be able to simplify the above commands to as little as: @@ -506,10 +568,16 @@ There are a number of configure options that can be used to reduce the size of libcurl for embedded applications where binary size is an important factor. First, be sure to set the `CFLAGS` variable when configuring with any relevant compiler optimization flags to reduce the size of the binary. For gcc, this -would mean at minimum the -Os option, and potentially the `-march=X`, -`-mdynamic-no-pic` and `-flto` options as well, e.g. +would mean at minimum the `-Os` option, and others like the following that +may be relevant in some environments: `-march=X`, `-mthumb`, `-m32`, +`-mdynamic-no-pic`, `-flto`, `-fdata-sections`, `-ffunction-sections`, +`-fno-unwind-tables`, `-fno-asynchronous-unwind-tables`, +`-fno-record-gcc-switches`, `-fsection-anchors`, `-fno-plt`, +`-Wl,--gc-sections`, `-Wl,-dead_strip` (Apple), `-Wl,-Bsymbolic`, `-Wl,-s` - ./configure CFLAGS='-Os' LDFLAGS='-Wl,-Bsymbolic'... +For example, this is how to combine a few of these options: + + ./configure CC=gcc CFLAGS='-Os -ffunction-sections' LDFLAGS='-Wl,--gc-sections'... Note that newer compilers often produce smaller code than older versions due to improved optimization. @@ -517,101 +585,100 @@ due to improved optimization. Be sure to specify as many `--disable-` and `--without-` flags on the configure command-line as you can to disable all the libcurl features that you know your application is not going to need. Besides specifying the -`--disable-PROTOCOL` flags for all the types of URLs your application will not +`--disable-PROTOCOL` flags for all the types of URLs your application do not use, here are some other flags that can reduce the size of the library by -disabling support for some feature: +disabling support for some features (run `./configure --help` to see them all): - - `--disable-alt-svc` (HTTP Alt-Svc) - - `--disable-ares` (the C-ARES DNS library) - - `--disable-cookies` (HTTP cookies) - - `--disable-crypto-auth` (cryptographic authentication) - - `--disable-dateparse` (date parsing for time conditionals) - - `--disable-dnsshuffle` (internal server load spreading) - - `--disable-doh` (DNS-over-HTTP) - - `--disable-get-easy-options` (lookup easy options at runtime) - - `--disable-hsts` (HTTP Strict Transport Security) - - `--disable-http-auth` (all HTTP authentication) - - `--disable-ipv6` (IPv6) - - `--disable-libcurl-option` (--libcurl C code generation support) - - `--disable-manual` (built-in documentation) - - `--disable-netrc` (.netrc file) - - `--disable-ntlm-wb` (NTLM WinBind) - - `--disable-progress-meter` (graphical progress meter in library) - - `--disable-proxy` (HTTP and SOCKS proxies) - - `--disable-pthreads` (multi-threading) - - `--disable-socketpair` (socketpair for asynchronous name resolving) - - `--disable-threaded-resolver` (threaded name resolver) - - `--disable-tls-srp` (Secure Remote Password authentication for TLS) - - `--disable-unix-sockets` (UNIX sockets) - - `--disable-verbose` (eliminates debugging strings and error code strings) - - `--disable-versioned-symbols` (versioned symbols) - - `--enable-symbol-hiding` (eliminates unneeded symbols in the shared library) - - `--without-brotli` (Brotli on-the-fly decompression) - - `--without-libpsl` (Public Suffix List in cookies) - - `--without-nghttp2` (HTTP/2 using nghttp2) - - `--without-ngtcp2` (HTTP/2 using ngtcp2) - - `--without-zstd` (Zstd on-the-fly decompression) - - `--without-libidn2` (internationalized domain names) - - `--without-librtmp` (RTMP) - - `--without-ssl` (SSL/TLS) - - `--without-zlib` (on-the-fly decompression) - -The GNU compiler and linker have a number of options that can reduce the -size of the libcurl dynamic libraries on some platforms even further. -Specify them by providing appropriate `CFLAGS` and `LDFLAGS` variables on -the configure command-line, e.g. - - CFLAGS="-Os -ffunction-sections -fdata-sections - -fno-unwind-tables -fno-asynchronous-unwind-tables -flto" - LDFLAGS="-Wl,-s -Wl,-Bsymbolic -Wl,--gc-sections" +- `--disable-aws` (cryptographic authentication) +- `--disable-basic-auth` (cryptographic authentication) +- `--disable-bearer-auth` (cryptographic authentication) +- `--disable-digest-auth` (cryptographic authentication) +- `--disable-http-auth` (all HTTP authentication) +- `--disable-kerberos-auth` (cryptographic authentication) +- `--disable-negotiate-auth` (cryptographic authentication) +- `--disable-ntlm` (NTLM authentication) +- `--disable-alt-svc` (HTTP Alt-Svc) +- `--disable-ares` (the C-ARES DNS library) +- `--disable-cookies` (HTTP cookies) +- `--disable-dateparse` (date parsing for time conditionals) +- `--disable-dnsshuffle` (internal server load spreading) +- `--disable-doh` (DNS-over-HTTP) +- `--disable-form-api` (POST form API) +- `--disable-get-easy-options` (lookup easy options at runtime) +- `--disable-headers-api` (API to access headers) +- `--disable-hsts` (HTTP Strict Transport Security) +- `--disable-ipv6` (IPv6) +- `--disable-libcurl-option` (--libcurl C code generation support) +- `--disable-manual` (--manual built-in documentation) +- `--disable-mime` (MIME API) +- `--disable-netrc` (.netrc file) +- `--disable-progress-meter` (graphical progress meter in library) +- `--disable-proxy` (HTTP and SOCKS proxies) +- `--disable-socketpair` (socketpair for asynchronous name resolving) +- `--disable-threaded-resolver` (threaded name resolver) +- `--disable-tls-srp` (Secure Remote Password authentication for TLS) +- `--disable-unix-sockets` (Unix sockets) +- `--disable-verbose` (eliminates debugging strings and error code strings) +- `--disable-versioned-symbols` (versioned symbols) +- `--enable-symbol-hiding` (eliminates unneeded symbols in the shared library) +- `--without-brotli` (Brotli on-the-fly decompression) +- `--without-libpsl` (Public Suffix List in cookies) +- `--without-nghttp2` (HTTP/2 using nghttp2) +- `--without-ngtcp2` (HTTP/2 using ngtcp2) +- `--without-zstd` (Zstd on-the-fly decompression) +- `--without-libidn2` (internationalized domain names) +- `--without-ssl` (SSL/TLS) +- `--without-zlib` (gzip/deflate on-the-fly decompression) Be sure also to strip debugging symbols from your binaries after compiling -using 'strip' (or the appropriate variant if cross-compiling). If space is -really tight, you may be able to remove some unneeded sections of the shared -library using the -R option to objcopy (e.g. the .comment section). +using 'strip' or an option like `-s`. If space is really tight, you may be able +to gain a few bytes by removing some unneeded sections of the shared library +using the -R option to objcopy (e.g. the .comment section). Using these techniques it is possible to create a basic HTTP-only libcurl -shared library for i386 Linux platforms that is only 133 KiB in size -(as of libcurl version 7.80.0, using gcc 11.2.0). +shared library for i386 Linux platforms that is only 137 KiB in size +(as of libcurl version 8.13.0, using gcc 14.2.0). -You may find that statically linking libcurl to your application will result -in a lower total size than dynamically linking. +You may find that statically linking libcurl to your application results in a +lower total size than dynamically linking. -Note that the curl test harness can detect the use of some, but not all, of -the `--disable` statements suggested above. Use will cause tests relying on -those features to fail. The test harness can be manually forced to skip the +The curl test harness can detect the use of some, but not all, of the +`--disable` statements suggested above. Use of these can cause tests relying +on those features to fail. The test harness can be manually forced to skip the relevant tests by specifying certain key words on the `runtests.pl` command line. Following is a list of appropriate key words for those configure options that are not automatically detected: - - `--disable-cookies` !cookies - - `--disable-dateparse` !RETRY-AFTER !`CURLOPT_TIMECONDITION` !`CURLINFO_FILETIME` !`If-Modified-Since` !`curl_getdate` !`-z` - - `--disable-libcurl-option` !`--libcurl` - - `--disable-verbose` !verbose\ logs +- `--disable-cookies` !cookies +- `--disable-dateparse` !RETRY-AFTER !`CURLOPT_TIMECONDITION` !`CURLINFO_FILETIME` !`If-Modified-Since` !`curl_getdate` !`-z` +- `--disable-libcurl-option` !`--libcurl` +- `--disable-verbose` !verbose\ logs -# PORTS +# Ports This is a probably incomplete list of known CPU architectures and operating systems that curl has been compiled for. If you know a system curl compiles -and runs on, that is not listed, please let us know! +and runs on, that is not listed, please let us know. -## 92 Operating Systems +## 108 Operating Systems - AIX, AmigaOS, Android, Aros, BeOS, Blackberry 10, Blackberry Tablet OS, - Cell OS, Chrome OS, Cisco IOS, Cygwin, DG/UX, Dragonfly BSD, DR DOS, eCOS, - FreeBSD, FreeDOS, FreeRTOS, Fuchsia, Garmin OS, Genode, Haiku, HardenedBSD, - HP-UX, Hurd, Illumos, Integrity, iOS, ipadOS, IRIX, Linux, Lua RTOS, - Mac OS 9, macOS, Mbed, Micrium, MINIX, MorphOS, MPE/iX, MS-DOS, NCR MP-RAS, - NetBSD, Netware, Nintendo Switch, NonStop OS, NuttX, Omni OS, OpenBSD, - OpenStep, Orbis OS, OS/2, OS/400, OS21, Plan 9, PlayStation Portable, QNX, - Qubes OS, ReactOS, Redox, RICS OS, RTEMS, Sailfish OS, SCO Unix, Serenity, - SINIX-Z, Solaris, SunOS, Syllable OS, Symbian, Tizen, TPF, Tru64, tvOS, - ucLinux, Ultrix, UNICOS, UnixWare, VMS, vxWorks, watchOS, WebOS, - Wii system software, Windows, Windows CE, Xbox System, Xenix, Zephyr, - z/OS, z/TPF, z/VM, z/VSE + AIX, AmigaOS, Android, ArcaOS, Aros, Atari FreeMiNT, Azure Sphere, BeOS, + Blackberry 10, Blackberry Tablet OS, Cell OS, Cesium, CheriBSD, Chrome OS, + Cisco IOS, DG/UX, DR DOS, Dragonfly BSD, eCOS, FreeBSD, FreeDOS, FreeRTOS, + Fuchsia, Garmin OS, Genode, Haiku, HardenedBSD, HP-UX, Hurd, IBM I, + illumos, Integrity, iOS, ipadOS, IRIX, KasperskyOS, Linux, Lua RTOS, + Mac OS 9, macOS, Maemo, Mbed, Meego, Micrium, MINIX, Minoca, Moblin, + MorphOS, MPE/iX, MS-DOS, NCR MP-RAS, NetBSD, Netware, NextStep, + Nintendo 3DS, Nintendo Switch, NonStop OS, NuttX, OpenBSD, OpenStep, + Orbis OS, OS/2, OS21, PikeOS, Plan 9, PlayStation Portable, QNX, Qubes OS, + ReactOS, Redox, RISC OS, ROS, RTEMS, Sailfish OS, SCO Unix, Serenity, + SINIX-Z, SkyOS, SmartOS, Solaris, Sortix, SunOS, Syllable OS, Symbian, + Tizen, TPF, Tru64, tvOS, ucLinux, Ultrix, UNICOS, UnixWare, visionOS, VMS, + vxWorks, watchOS, Wear OS, WebOS, Wii System Software, Wii U, Windows, + Xbox System, Xenix, z/OS, z/TPF, z/VM, z/VSE, Zephyr -## 26 CPU Architectures +## 28 CPU Architectures - Alpha, ARC, ARM, AVR32, CompactRISC, Elbrus, ETRAX, HP-PA, Itanium, + Alpha, ARC, ARM, AVR32, C-SKY, CompactRISC, Elbrus, ETRAX, HP-PA, Itanium, LoongArch, m68k, m88k, MicroBlaze, MIPS, Nios, OpenRISC, POWER, PowerPC, - RISC-V, s390, SH4, SPARC, Tilera, VAX, x86, Xtensa + RISC-V, s390, SH4, SPARC, Tilera, VAX, x86, Xtensa, z/arch diff --git a/third-party/curl/docs/INTERNALS.md b/third-party/curl/docs/INTERNALS.md index d7513a8ff3..ff59f733e0 100644 --- a/third-party/curl/docs/INTERNALS.md +++ b/third-party/curl/docs/INTERNALS.md @@ -1,3 +1,9 @@ + + # curl internals The canonical libcurl internals documentation is now in the [everything @@ -6,51 +12,61 @@ versions of libs and build tools. ## Portability - We write curl and libcurl to compile with C89 compilers on 32-bit and up - machines. Most of libcurl assumes more or less POSIX compliance but that is - not a requirement. +We write curl and libcurl to compile with C89 compilers on 32-bit and up +machines. Most of libcurl assumes more or less POSIX compliance but that is +not a requirement. The compiler must support a 64-bit integer type as well as +supply a stdint.h header file that defines C99-style fixed-width integer types +like uint32_t. - We write libcurl to build and work with lots of third party tools, and we - want it to remain functional and buildable with these and later versions - (older versions may still work but is not what we work hard to maintain): +We write libcurl to build and work with lots of third party tools, and we +want it to remain functional and buildable with these and later versions +(older versions may still work but is not what we work hard to maintain): ## Dependencies - We aim to support these or later versions. +We aim to support these or later versions: - - OpenSSL 0.9.7 - - GnuTLS 3.1.10 - - zlib 1.1.4 - - libssh2 1.0 - - c-ares 1.16.0 - - libidn2 2.0.0 - - wolfSSL 2.0.0 - - OpenLDAP 2.0 - - MIT Kerberos 1.2.4 - - Heimdal ? - - nghttp2 1.15.0 - - WinSock 2.2 (on Windows 95+ and Windows CE .NET 4.1+) +- brotli 1.0.0 (2017-09-21) +- c-ares 1.16.0 (2020-03-13) +- GnuTLS 3.6.5 (2018-12-01) +- libidn2 2.0.0 (2017-03-29) +- libgsasl 1.6.0 (2010-12-14) +- libpsl 0.16.0 (2016-12-10) +- LibreSSL 2.9.1 (2019-04-21) +- libssh 0.9.0 (2019-06-28) +- libssh2 1.9.0 (2019-06-20) +- mbedTLS 3.2.0 (2022-07-11) +- MIT Kerberos 1.3 (2003-07-31) +- nghttp2 1.15.0 (2016-09-25) +- nghttp3 1.0.0 (2023-10-15) +- ngtcp2 1.0.0 (2023-10-15), with OpenSSL 3.5.0+: 1.12.0 (2025-04-16) +- OpenLDAP 2.0 (2000-08-01) +- OpenSSL 3.0.0 (2021-09-07) +- Windows Vista 6.0 (2006-11-08 - 2012-04-10) +- wolfSSL 5.0.0 (2021-11-01) +- zlib 1.2.5.2 (2011-12-11) +- zstd 1.0 (2016-08-31) ## Build tools - When writing code (mostly for generating stuff included in release tarballs) - we use a few "build tools" and we make sure that we remain functional with - these versions: +When writing code (mostly for generating stuff included in release tarballs) +we use a few "build tools" and we make sure that we remain functional with +these or later versions: - - GNU Libtool 1.4.2 - - GNU Autoconf 2.59 - - GNU Automake 1.7 - - GNU M4 1.4 - - perl 5.6 - - roffit 0.5 - - nroff any version that supports `-man [in] [out]` - - cmake 3.7 +- clang-tidy 17.0.0 (2023-09-19), recommended: 19.1.0 (2024-09-17) +- cmake 3.18 (2020-07-15) +- GNU autoconf 2.59 (2003-11-06) +- GNU automake 1.7 (2002-09-25) +- GNU libtool 1.4.2 (2001-09-11) +- GNU m4 1.4 (2007-09-21) +- mingw-w64 3.0 (2013-09-20) +- perl 5.8 (2002-07-19), on Windows: 5.22 (2015-06-01) +- Visual Studio 2010 10.0 (2010-04-12 - 2020-07-14) -Library Symbols -=============== +## Library Symbols - All symbols used internally in libcurl must use a `Curl_` prefix if they are - used in more than a single file. Single-file symbols must be made static. - Public ("exported") symbols must use a `curl_` prefix. Public API functions - are marked with `CURL_EXTERN` in the public header files so that all others - can be hidden on platforms where this is possible. +All symbols used internally in libcurl must use a `Curl_` prefix if they are +used in more than a single file. Single-file symbols must be made static. +Public ("exported") symbols must use a `curl_` prefix. Public API functions +are marked with `CURL_EXTERN` in the public header files so that all others +can be hidden on platforms where this is possible. diff --git a/third-party/curl/docs/IPFS.md b/third-party/curl/docs/IPFS.md new file mode 100644 index 0000000000..2cf64543b9 --- /dev/null +++ b/third-party/curl/docs/IPFS.md @@ -0,0 +1,150 @@ + + +# IPFS + +For an overview about IPFS, visit the [IPFS project site](https://ipfs.tech/). + +In IPFS there are two protocols. IPFS and IPNS (their workings are explained +in detail [here](https://docs.ipfs.tech/concepts/)). The ideal way to access +data on the IPFS network is through those protocols. For example to access +the Big Buck Bunny video the ideal way to access it is like: +`ipfs://bafybeigagd5nmnn2iys2f3doro7ydrevyr2mzarwidgadawmamiteydbzi` + +## IPFS Gateways + +IPFS Gateway acts as a bridge between traditional HTTP clients and IPFS. +IPFS Gateway specifications of HTTP semantics can be found +[here](https://specs.ipfs.tech/http-gateways/). + +### Deserialized responses + +By default, a gateway acts as a bridge between traditional HTTP clients and +IPFS and performs necessary hash verification and deserialization. Through such +gateway, users can download files, directories, and other content-addressed +data stored with IPFS or IPNS as if they were stored in a traditional web +server. + +### Verifiable responses + +By explicitly requesting +[application/vnd.ipld.raw](https://www.iana.org/assignments/media-types/application/vnd.ipld.raw) or +[application/vnd.ipld.car](https://www.iana.org/assignments/media-types/application/vnd.ipld.car) +responses, by means defined in +[Trustless Gateway Specification](https://specs.ipfs.tech/http-gateways/trustless-gateway/), +the user is able to fetch raw content-addressed data and +[perform hash verification themselves](https://docs.ipfs.tech/reference/http/gateway/#trustless-verifiable-retrieval). + +This enables users to use untrusted, public gateways without worrying they +might return invalid/malicious bytes. + +## IPFS and IPNS protocol handling + +There are various ways to access data from the IPFS network. One such way is +through the concept of public +"[gateways](https://docs.ipfs.tech/concepts/ipfs-gateway/#overview)". The +short version is that entities can offer gateway services. An example here +that is hosted by Protocol Labs (who also makes IPFS) is `dweb.link` and +`ipfs.io`. Both sites expose gateway functionality. Getting a file through +`ipfs.io` looks like this: +`https://ipfs.io/ipfs/bafybeigagd5nmnn2iys2f3doro7ydrevyr2mzarwidgadawmamiteydbzi` + +If you were to be [running your own IPFS +node](https://docs.ipfs.tech/how-to/command-line-quick-start/) then you, by +default, also have a [local gateway](https://specs.ipfs.tech/http-gateways/) +running. In its default configuration the earlier example would then also work +in this link: + +`http://127.0.0.1:8080/ipfs/bafybeigagd5nmnn2iys2f3doro7ydrevyr2mzarwidgadawmamiteydbzi` + +## curl handling of the IPFS protocols + +The IPFS integration in curl hides this gateway logic for you. Instead of +providing a full URL to a file on IPFS like this: + +```sh +curl http://127.0.0.1:8080/ipfs/bafybeigagd5nmnn2iys2f3doro7ydrevyr2mzarwidgadawmamiteydbzi +``` + +You can provide it with the IPFS protocol instead: +```sh +curl ipfs://bafybeigagd5nmnn2iys2f3doro7ydrevyr2mzarwidgadawmamiteydbzi +``` + +With the IPFS protocol way of asking a file, curl still needs to know the +gateway. curl essentially rewrites the IPFS based URL to a gateway URL. + +### IPFS_GATEWAY environment variable + +If the `IPFS_GATEWAY` environment variable is found, its value is used as +gateway. + +### Automatic gateway detection + +When you provide no additional details to curl then it: + +1. First looks for the `IPFS_GATEWAY` environment variable and use that if it + is set. +2. Looks for the file: `~/.ipfs/gateway`. If it can find that file then it + means that you have a local gateway running and that file contains the URL + to your local gateway. + +If curl fails, you are presented with an error message and a link to this page +to the option most applicable to solving the issue. + +### `--ipfs-gateway` argument + +You can also provide a `--ipfs-gateway` argument to curl. This overrules any +other gateway setting. curl does not fallback to the other options if the +provided gateway did not work. + +## Gateway redirects + +A gateway could redirect to another place. For example, `dweb.link` redirects +[path based](https://docs.ipfs.tech/how-to/address-ipfs-on-web/#path-gateway) +requests to [subdomain +based](https://docs.ipfs.tech/how-to/address-ipfs-on-web/#subdomain-gateway) +ones. A request using: + + curl ipfs://bafybeigagd5nmnn2iys2f3doro7ydrevyr2mzarwidgadawmamiteydbzi --ipfs-gateway https://dweb.link + +Which would be translated to: + + https://dweb.link/ipfs/bafybeigagd5nmnn2iys2f3doro7ydrevyr2mzarwidgadawmamiteydbzi + +redirects to: + + https://bafybeigagd5nmnn2iys2f3doro7ydrevyr2mzarwidgadawmamiteydbzi.ipfs.dweb.link + +If you trust this behavior from your gateway of choice then passing the `-L` +option follows the redirect. + +## Error messages and hints + +Depending on the arguments, curl could present the user with an error. + +### Gateway file and environment variable + +curl tried to look for the file: `~/.ipfs/gateway` but could not find it. It +also tried to look for the `IPFS_GATEWAY` environment variable but could not +find that either. This happens when no extra arguments are passed to curl and +letting it try to figure it out [automatically](#automatic-gateway-detection). + +Any IPFS implementation that has gateway support should expose its URL in +`~/.ipfs/gateway`. If you are already running a gateway, make sure it exposes +the file where curl expects to find it. + +Alternatively you could set the `IPFS_GATEWAY` environment variable or pass +the `--ipfs-gateway` flag to the curl command. + +### Malformed gateway URL + +The command executed evaluates in an invalid URL. This could be anywhere in +the URL, but a likely point is a wrong gateway URL. + +Inspect the URL set via the `IPFS_GATEWAY` environment variable or passed with +the `--ipfs-gateway` flag. Alternatively opt to go for the +[automatic](#automatic-gateway-detection) gateway detection. diff --git a/third-party/curl/docs/KNOWN_BUGS b/third-party/curl/docs/KNOWN_BUGS deleted file mode 100644 index 395426b4dd..0000000000 --- a/third-party/curl/docs/KNOWN_BUGS +++ /dev/null @@ -1,625 +0,0 @@ - _ _ ____ _ - ___| | | | _ \| | - / __| | | | |_) | | - | (__| |_| | _ <| |___ - \___|\___/|_| \_\_____| - - Known Bugs - -These are problems and bugs known to exist at the time of this release. Feel -free to join in and help us correct one or more of these. Also be sure to -check the changelog of the current development status, as one or more of these -problems may have been fixed or changed somewhat since this was written. - - 1. HTTP - 1.1 hyper memory-leaks - 1.2 hyper is slow - 1.5 Expect-100 meets 417 - - 2. TLS - 2.3 Unable to use PKCS12 certificate with Secure Transport - 2.4 Secure Transport will not import PKCS#12 client certificates without a password - 2.5 Client cert handling with Issuer DN differs between backends - 2.7 Client cert (MTLS) issues with Schannel - 2.11 Schannel TLS 1.2 handshake bug in old Windows versions - 2.12 FTPS with Schannel times out file list operation - 2.13 CURLOPT_CERTINFO results in CURLE_OUT_OF_MEMORY with Schannel - - 3. Email protocols - 3.1 IMAP SEARCH ALL truncated response - 3.2 No disconnect command - 3.3 POP3 expects "CRLF.CRLF" eob for some single-line responses - 3.4 AUTH PLAIN for SMTP is not working on all servers - 3.5 APOP authentication fails on POP3 - - 4. Command line - - 5. Build and portability issues - 5.1 OS400 port requires deprecated IBM library - 5.2 curl-config --libs contains private details - 5.3 building for old macOS fails with gcc - 5.5 cannot handle Unicode arguments in non-Unicode builds on Windows - 5.6 cygwin: make install installs curl-config.1 twice - 5.9 Utilize Requires.private directives in libcurl.pc - 5.11 configure --with-gssapi with Heimdal is ignored on macOS - 5.12 flaky CI builds - 5.13 long paths are not fully supported on Windows - 5.14 Windows Unicode builds use homedir in current locale - - 6. Authentication - 6.1 NTLM authentication and unicode - 6.2 MIT Kerberos for Windows build - 6.3 NTLM in system context uses wrong name - 6.5 NTLM does not support password with § character - 6.6 libcurl can fail to try alternatives with --proxy-any - 6.7 Do not clear digest for single realm - 6.9 SHA-256 digest not supported in Windows SSPI builds - 6.10 curl never completes Negotiate over HTTP - 6.11 Negotiate on Windows fails - 6.12 cannot use Secure Transport with Crypto Token Kit - 6.13 Negotiate against Hadoop HDFS - - 7. FTP - 7.3 FTP with NOBODY and FAILONERROR - 7.4 FTP with ACCT - 7.11 FTPS upload data loss with TLS 1.3 - 7.12 FTPS directory listing hangs on Windows with Schannel - - 9. SFTP and SCP - 9.1 SFTP does not do CURLOPT_POSTQUOTE correct - 9.2 wolfssh: publickey auth does not work - 9.3 Remote recursive folder creation with SFTP - 9.4 libssh blocking and infinite loop problem - 9.5 cygwin: "WARNING: UNPROTECTED PRIVATE KEY FILE!" - - 10. SOCKS - 10.3 FTPS over SOCKS - - 11. Internals - 11.2 error buffer not set if connection to multiple addresses fails - 11.4 HTTP test server 'connection-monitor' problems - 11.5 Connection information when using TCP Fast Open - - 12. LDAP - 12.1 OpenLDAP hangs after returning results - 12.2 LDAP on Windows does authentication wrong? - 12.3 LDAP on Windows does not work - 12.4 LDAPS requests to ActiveDirectory server hang - - 13. TCP/IP - 13.2 Trying local ports fails on Windows - - 15. CMake - 15.1 cmake outputs: no version information available - 15.2 support build with GnuTLS - 15.3 unusable tool_hugehelp.c with MinGW - 15.4 build docs/curl.1 - 15.6 uses -lpthread instead of Threads::Threads - 15.7 generated .pc file contains strange entries - 15.8 libcurl.pc uses absolute library paths - 15.11 ExternalProject_Add does not set CURL_CA_PATH - 15.13 CMake build with MIT Kerberos does not work - - 16. aws-sigv4 - 16.1 aws-sigv4 does not sign requests with * correctly - 16.2 aws-sigv4 does not sign requests with valueless queries correctly - 16.3 aws-sigv4 is missing the amz-content-sha256 header - 16.4 aws-sigv4 does not sort query string parameters before signing - 16.5 aws-sigv4 does not sign requests with empty URL query correctly - 16.6 aws-sigv4 does not behave well with AWS VPC Lattice - - 17. HTTP/2 - 17.2 HTTP/2 frames while in the connection pool kill reuse - 17.3 ENHANCE_YOUR_CALM causes infinite retries - - 18. HTTP/3 - 18.1 connection migration does not work - -============================================================================== - -1. HTTP - -1.2 hyper is slow - - When curl is built to use hyper for HTTP, it is unnecessary slow. - - https://github.com/curl/curl/issues/11203 - -1.5 Expect-100 meets 417 - - If an upload using Expect: 100-continue receives an HTTP 417 response, it - ought to be automatically resent without the Expect:. A workaround is for - the client application to redo the transfer after disabling Expect:. - https://curl.se/mail/archive-2008-02/0043.html - -2. TLS - -2.3 Unable to use PKCS12 certificate with Secure Transport - - See https://github.com/curl/curl/issues/5403 - -2.4 Secure Transport will not import PKCS#12 client certificates without a password - - libcurl calls SecPKCS12Import with the PKCS#12 client certificate, but that - function rejects certificates that do not have a password. - https://github.com/curl/curl/issues/1308 - -2.5 Client cert handling with Issuer DN differs between backends - - When the specified client certificate does not match any of the - server-specified DNs, the OpenSSL and GnuTLS backends behave differently. - The github discussion may contain a solution. - - See https://github.com/curl/curl/issues/1411 - -2.7 Client cert (MTLS) issues with Schannel - - See https://github.com/curl/curl/issues/3145 - -2.11 Schannel TLS 1.2 handshake bug in old Windows versions - - In old versions of Windows such as 7 and 8.1 the Schannel TLS 1.2 handshake - implementation likely has a bug that can rarely cause the key exchange to - fail, resulting in error SEC_E_BUFFER_TOO_SMALL or SEC_E_MESSAGE_ALTERED. - - https://github.com/curl/curl/issues/5488 - -2.12 FTPS with Schannel times out file list operation - - "Instead of the command completing, it just sits there until the timeout - expires." - the same command line seems to work with other TLS backends and - other operating systems. See https://github.com/curl/curl/issues/5284. - -2.13 CURLOPT_CERTINFO results in CURLE_OUT_OF_MEMORY with Schannel - - https://github.com/curl/curl/issues/8741 - -3. Email protocols - -3.1 IMAP SEARCH ALL truncated response - - IMAP "SEARCH ALL" truncates output on large boxes. "A quick search of the - code reveals that pingpong.c contains some truncation code, at line 408, when - it deems the server response to be too large truncating it to 40 characters" - https://curl.se/bug/view.cgi?id=1366 - -3.2 No disconnect command - - The disconnect commands (LOGOUT and QUIT) may not be sent by IMAP, POP3 and - SMTP if a failure occurs during the authentication phase of a connection. - -3.3 POP3 expects "CRLF.CRLF" eob for some single-line responses - - You have to tell libcurl not to expect a body, when dealing with one line - response commands. Please see the POP3 examples and test cases which show - this for the NOOP and DELE commands. https://curl.se/bug/?i=740 - -3.4 AUTH PLAIN for SMTP is not working on all servers - - Specifying "--login-options AUTH=PLAIN" on the command line does not seem to - work correctly. - - See https://github.com/curl/curl/issues/4080 - -3.5 APOP authentication fails on POP3 - - See https://github.com/curl/curl/issues/10073 - -4. Command line - -5. Build and portability issues - -5.1 OS400 port requires deprecated IBM library - - curl for OS400 requires QADRT to build, which provides ASCII wrappers for - libc/POSIX functions in the ILE, but IBM no longer supports or even offers - this library to download. - - See https://github.com/curl/curl/issues/5176 - -5.2 curl-config --libs contains private details - - "curl-config --libs" will include details set in LDFLAGS when configure is - run that might be needed only for building libcurl. Further, curl-config - --cflags suffers from the same effects with CFLAGS/CPPFLAGS. - -5.3 building for old macOS fails with gcc - - Building curl for certain old macOS versions fails when gcc is used. We - command using clang in those cases. - - See https://github.com/curl/curl/issues/11441 - -5.5 cannot handle Unicode arguments in non-Unicode builds on Windows - - If a URL or filename cannot be encoded using the user's current codepage then - it can only be encoded properly in the Unicode character set. Windows uses - UTF-16 encoding for Unicode and stores it in wide characters, however curl - and libcurl are not equipped for that at the moment except when built with - _UNICODE and UNICODE defined. And, except for Cygwin, Windows cannot use UTF-8 - as a locale. - - https://curl.se/bug/?i=345 - https://curl.se/bug/?i=731 - https://curl.se/bug/?i=3747 - -5.6 cygwin: make install installs curl-config.1 twice - - https://github.com/curl/curl/issues/8839 - -5.9 Utilize Requires.private directives in libcurl.pc - - https://github.com/curl/curl/issues/864 - -5.11 configure --with-gssapi with Heimdal is ignored on macOS - - ... unless you also pass --with-gssapi-libs - - https://github.com/curl/curl/issues/3841 - -5.12 flaky CI builds - - We run many CI builds for each commit and PR on github, and especially a - number of the Windows builds are flaky. This means that we rarely get all CI - builds go green and complete without errors. This is unfortunate as it makes - us sometimes miss actual build problems and it is surprising to newcomers to - the project who (rightfully) do not expect this. - - See https://github.com/curl/curl/issues/6972 - -5.13 long paths are not fully supported on Windows - - curl on Windows cannot access long paths (paths longer than 260 characters). - However, as a workaround, the Windows path prefix \\?\ which disables all path - interpretation may work to allow curl to access the path. For example: - \\?\c:\longpath. - - See https://github.com/curl/curl/issues/8361 - -5.14 Windows Unicode builds use homedir in current locale - - The Windows Unicode builds of curl use the current locale, but expect Unicode - UTF-8 encoded paths for internal use such as open, access and stat. The user's - home directory is retrieved via curl_getenv in the current locale and not as - UTF-8 encoded Unicode. - - See https://github.com/curl/curl/pull/7252 and - https://github.com/curl/curl/pull/7281 - -6. Authentication - -6.1 NTLM authentication and unicode - - NTLM authentication involving unicode user name or password only works - properly if built with UNICODE defined together with the Schannel - backend. The original problem was mentioned in: - https://curl.se/mail/lib-2009-10/0024.html - https://curl.se/bug/view.cgi?id=896 - - The Schannel version verified to work as mentioned in - https://curl.se/mail/lib-2012-07/0073.html - -6.2 MIT Kerberos for Windows build - - libcurl fails to build with MIT Kerberos for Windows (KfW) due to KfW's - library header files exporting symbols/macros that should be kept private to - the KfW library. See ticket #5601 at https://krbdev.mit.edu/rt/ - -6.3 NTLM in system context uses wrong name - - NTLM authentication using SSPI (on Windows) when (lib)curl is running in - "system context" will make it use wrong(?) user name - at least when compared - to what winhttp does. See https://curl.se/bug/view.cgi?id=535 - -6.5 NTLM does not support password with § character - - https://github.com/curl/curl/issues/2120 - -6.6 libcurl can fail to try alternatives with --proxy-any - - When connecting via a proxy using --proxy-any, a failure to establish an - authentication will cause libcurl to abort trying other options if the - failed method has a higher preference than the alternatives. As an example, - --proxy-any against a proxy which advertise Negotiate and NTLM, but which - fails to set up Kerberos authentication will not proceed to try authentication - using NTLM. - - https://github.com/curl/curl/issues/876 - -6.7 Do not clear digest for single realm - - https://github.com/curl/curl/issues/3267 - -6.9 SHA-256 digest not supported in Windows SSPI builds - - Windows builds of curl that have SSPI enabled use the native Windows API calls - to create authentication strings. The call to InitializeSecurityContext fails - with SEC_E_QOP_NOT_SUPPORTED which causes curl to fail with CURLE_AUTH_ERROR. - - Microsoft does not document supported digest algorithms and that SEC_E error - code is not a documented error for InitializeSecurityContext (digest). - - https://github.com/curl/curl/issues/6302 - -6.10 curl never completes Negotiate over HTTP - - Apparently it is not working correctly...? - - See https://github.com/curl/curl/issues/5235 - -6.11 Negotiate on Windows fails - - When using --negotiate (or NTLM) with curl on Windows, SSL/TLS handshake - fails despite having a valid kerberos ticket cached. Works without any issue - in Unix/Linux. - - https://github.com/curl/curl/issues/5881 - -6.12 cannot use Secure Transport with Crypto Token Kit - - https://github.com/curl/curl/issues/7048 - -6.13 Negotiate authentication against Hadoop HDFS - - https://github.com/curl/curl/issues/8264 - -7. FTP - -7.3 FTP with NOBODY and FAILONERROR - - It seems sensible to be able to use CURLOPT_NOBODY and CURLOPT_FAILONERROR - with FTP to detect if a file exists or not, but it is not working: - https://curl.se/mail/lib-2008-07/0295.html - -7.4 FTP with ACCT - - When doing an operation over FTP that requires the ACCT command (but not when - logging in), the operation will fail since libcurl does not detect this and - thus fails to issue the correct command: - https://curl.se/bug/view.cgi?id=635 - -7.11 FTPS upload data loss with TLS 1.3 - - During FTPS upload curl does not attempt to read TLS handshake messages sent - after the initial handshake. OpenSSL servers running TLS 1.3 may send such a - message. When curl closes the upload connection if unread data has been - received (such as a TLS handshake message) then the TCP protocol sends an - RST to the server, which may cause the server to discard or truncate the - upload if it has not read all sent data yet, and then return an error to curl - on the control channel connection. - - Since 7.78.0 this is mostly fixed. curl will do a single read before closing - TLS connections (which causes the TLS library to read handshake messages), - however there is still possibility of an RST if more messages need to be read - or a message arrives after the read but before close (network race condition). - - https://github.com/curl/curl/issues/6149 - -7.12 FTPS directory listing hangs on Windows with Schannel - - https://github.com/curl/curl/issues/9161 - -9. SFTP and SCP - -9.1 SFTP does not do CURLOPT_POSTQUOTE correct - - When libcurl sends CURLOPT_POSTQUOTE commands when connected to a SFTP server - using the multi interface, the commands are not being sent correctly and - instead the connection is "cancelled" (the operation is considered done) - prematurely. There is a half-baked (busy-looping) patch provided in the bug - report but it cannot be accepted as-is. See - https://curl.se/bug/view.cgi?id=748 - -9.2 wolfssh: publickey auth does not work - - When building curl to use the wolfSSH backend for SFTP, the publickey - authentication does not work. This is simply functionality not written for curl - yet, the necessary API for make this work is provided by wolfSSH. - - See https://github.com/curl/curl/issues/4820 - -9.3 Remote recursive folder creation with SFTP - - On this servers, the curl fails to create directories on the remote server - even when the CURLOPT_FTP_CREATE_MISSING_DIRS option is set. - - See https://github.com/curl/curl/issues/5204 - -9.4 libssh blocking and infinite loop problem - - In the SSH_SFTP_INIT state for libssh, the ssh session working mode is set to - blocking mode. If the network is suddenly disconnected during sftp - transmission, curl will be stuck, even if curl is configured with a timeout. - - https://github.com/curl/curl/issues/8632 - -9.5 cygwin: "WARNING: UNPROTECTED PRIVATE KEY FILE!" - - Running SCP and SFTP tests on cygwin makes this warning message appear. - - https://github.com/curl/curl/issues/11244 - -10. SOCKS - -10.3 FTPS over SOCKS - - libcurl does not support FTPS over a SOCKS proxy. - - -11. Internals - -11.2 error buffer not set if connection to multiple addresses fails - - If you ask libcurl to resolve a hostname like example.com to IPv6 addresses - only. But you only have IPv4 connectivity. libcurl will correctly fail with - CURLE_COULDNT_CONNECT. But the error buffer set by CURLOPT_ERRORBUFFER - remains empty. Issue: https://github.com/curl/curl/issues/544 - -11.4 HTTP test server 'connection-monitor' problems - - The 'connection-monitor' feature of the sws HTTP test server does not work - properly if some tests are run in unexpected order. Like 1509 and then 1525. - - See https://github.com/curl/curl/issues/868 - -11.5 Connection information when using TCP Fast Open - - CURLINFO_LOCAL_PORT (and possibly a few other) fails when TCP Fast Open is - enabled. - - See https://github.com/curl/curl/issues/1332 and - https://github.com/curl/curl/issues/4296 - -12. LDAP - -12.1 OpenLDAP hangs after returning results - - By configuration defaults, OpenLDAP automatically chase referrals on - secondary socket descriptors. The OpenLDAP backend is asynchronous and thus - should monitor all socket descriptors involved. Currently, these secondary - descriptors are not monitored, causing OpenLDAP library to never receive - data from them. - - As a temporary workaround, disable referrals chasing by configuration. - - The fix is not easy: proper automatic referrals chasing requires a - synchronous bind callback and monitoring an arbitrary number of socket - descriptors for a single easy handle (currently limited to 5). - - Generic LDAP is synchronous: OK. - - See https://github.com/curl/curl/issues/622 and - https://curl.se/mail/lib-2016-01/0101.html - -12.2 LDAP on Windows does authentication wrong? - - https://github.com/curl/curl/issues/3116 - -12.3 LDAP on Windows does not work - - A simple curl command line getting "ldap://ldap.forumsys.com" returns an - error that says "no memory" ! - - https://github.com/curl/curl/issues/4261 - -12.4 LDAPS requests to ActiveDirectory server hang - - https://github.com/curl/curl/issues/9580 - -13. TCP/IP - -13.2 Trying local ports fails on Windows - - This makes '--local-port [range]' to not work since curl cannot properly - detect if a port is already in use, so it will try the first port, use that and - then subsequently fail anyway if that was actually in use. - - https://github.com/curl/curl/issues/8112 - -15. CMake - -15.1 cmake outputs: no version information available - - Something in the SONAME generation seems to be wrong in the cmake build. - - https://github.com/curl/curl/issues/11158 - -15.2 support build with GnuTLS - -15.3 unusable tool_hugehelp.c with MinGW - - see https://github.com/curl/curl/issues/3125 - -15.4 build docs/curl.1 - - The cmake build does not create the docs/curl.1 file and therefore must rely on - it being there already. This makes the --manual option not work and test - cases like 1139 cannot function. - -15.6 uses -lpthread instead of Threads::Threads - - See https://github.com/curl/curl/issues/6166 - -15.7 generated .pc file contains strange entries - - The Libs.private field of the generated .pc file contains -lgcc -lgcc_s -lc - -lgcc -lgcc_s - - See https://github.com/curl/curl/issues/6167 - -15.8 libcurl.pc uses absolute library paths - - The libcurl.pc file generated by cmake contains things like Libs.private: - /usr/lib64/libssl.so /usr/lib64/libcrypto.so /usr/lib64/libz.so. The - autotools equivalent would say Libs.private: -lssl -lcrypto -lz - - See https://github.com/curl/curl/issues/6169 - -15.11 ExternalProject_Add does not set CURL_CA_PATH - - CURL_CA_BUNDLE and CURL_CA_PATH are not set properly when cmake's - ExternalProject_Add is used to build curl as a dependency. - - See https://github.com/curl/curl/issues/6313 - -15.13 CMake build with MIT Kerberos does not work - - Minimum CMake version was bumped in curl 7.71.0 (#5358) Since CMake 3.2 - try_compile started respecting the CMAKE_EXE_FLAGS. The code dealing with - MIT Kerberos detection sets few variables to potentially weird mix of space, - and ;-separated flags. It had to blow up at some point. All the CMake checks - that involve compilation are doomed from that point, the configured tree - cannot be built. - - https://github.com/curl/curl/issues/6904 - -16. aws-sigv4 - -16.1 aws-sigv4 does not sign requests with * correctly - - https://github.com/curl/curl/issues/7559 - -16.2 aws-sigv4 does not sign requests with valueless queries correctly - - https://github.com/curl/curl/issues/8107 - -16.3 aws-sigv4 is missing the amz-content-sha256 header - - https://github.com/curl/curl/issues/8810 - -16.4 aws-sigv4 does not sort query string parameters before signing - - https://github.com/curl/curl/issues/9717 - -16.5 aws-sigv4 does not sign requests with empty URL query correctly - - https://github.com/curl/curl/issues/10129 - -16.6 aws-sigv4 does not behave well with AWS VPC Lattice - - https://github.com/curl/curl/issues/11007 - -17. HTTP/2 - -17.2 HTTP/2 frames while in the connection pool kill reuse - - If the server sends HTTP/2 frames (like for example an HTTP/2 PING frame) to - curl while the connection is held in curl's connection pool, the socket will - be found readable when considered for reuse and that makes curl think it is - dead and then it will be closed and a new connection gets created instead. - - This is *best* fixed by adding monitoring to connections while they are kept - in the pool so that pings can be responded to appropriately. - -17.3 ENHANCE_YOUR_CALM causes infinite retries - - Infinite retries with 2 parallel requests on one connection receiving GOAWAY - with ENHANCE_YOUR_CALM error code. - - See https://github.com/curl/curl/issues/5119 - -18. HTTP/3 - -18.1 connection migration does not work - - https://github.com/curl/curl/issues/7695 diff --git a/third-party/curl/docs/KNOWN_BUGS.md b/third-party/curl/docs/KNOWN_BUGS.md new file mode 100644 index 0000000000..359c2fab99 --- /dev/null +++ b/third-party/curl/docs/KNOWN_BUGS.md @@ -0,0 +1,548 @@ + + +# Known bugs intro + +These are problems and bugs known to exist at the time of this release. Feel +free to join in and help us correct one or more of these. Also be sure to +check the changelog of the current development status, as one or more of these +problems may have been fixed or changed somewhat since this was written. + +# TLS + +## IMAPS connection fails with Rustls error + +[curl issue 10457](https://github.com/curl/curl/issues/10457) + +## Access violation sending client cert with Schannel + +When using Schannel to do client certs, curl sets `PKCS12_NO_PERSIST_KEY` to +avoid leaking the private key into the filesystem. Unfortunately that flag +instead seems to trigger a crash. + +See [curl issue 17626](https://github.com/curl/curl/issues/17626) + +## Client cert (MTLS) issues with Schannel + +See [curl issue 3145](https://github.com/curl/curl/issues/3145) + +## Schannel TLS 1.2 handshake bug in old Windows versions + +In old versions of Windows such as 7 and 8.1 the Schannel TLS 1.2 handshake +implementation likely has a bug that can rarely cause the key exchange to +fail, resulting in error SEC_E_BUFFER_TOO_SMALL or SEC_E_MESSAGE_ALTERED. + +[curl issue 5488](https://github.com/curl/curl/issues/5488) + +## mbedTLS and CURLE_AGAIN handling + +[curl issue 15801](https://github.com/curl/curl/issues/15801) + +## Native CA roots incomplete on Windows with OpenSSL (or fork) + +Certain Windows installations may be missing CA roots. + +[curl issue 20897](https://github.com/curl/curl/issues/20897) +[curl issue 12303](https://github.com/curl/curl/issues/12303) + +## ECH not working through Proxy Tunnels + +[curl issue 22043](https://github.com/curl/curl/issues/22043) + +# Email protocols + +## IMAP `SEARCH ALL` truncated response + +IMAP `SEARCH ALL` truncates output on large boxes. "A quick search of the code +reveals that `pingpong.c` contains some truncation code, at line 408, when it +deems the server response to be too large truncating it to 40 characters" + +https://curl.se/bug/view.cgi?id=1366 + +## No disconnect command + +The disconnect commands (`LOGOUT` and `QUIT`) may not be sent by IMAP, POP3 +and SMTP if a failure occurs during the authentication phase of a connection. + +## `AUTH PLAIN` for SMTP is not working on all servers + +Specifying `--login-options AUTH=PLAIN` on the command line does not seem to +work correctly. + +See [curl issue 4080](https://github.com/curl/curl/issues/4080) + +## `APOP` authentication fails on POP3 + +See [curl issue 10073](https://github.com/curl/curl/issues/10073) + +## POP3 issue when reading small chunks + + CURL_DBG_SOCK_RMAX=4 ./runtests.pl -v 982 + +See [curl issue 12063](https://github.com/curl/curl/issues/12063) + +# Command line + +## `-T /dev/stdin` may upload with an incorrect content length + +`-T` stats the path to figure out its size in bytes to use it as +`Content-Length` if it is a regular file. + +The problem with that is that on BSD and some other UNIX systems (not Linux), +open(path) may not give you a file descriptor with a 0 offset from the start +of the file. + +See [curl issue 12177](https://github.com/curl/curl/issues/12177) + +## `-T -` always uploads chunked + +When the `<` shell operator is used. curl should realize that stdin is a +regular file in this case, and that it can do a non-chunked upload, like it +would do if you used `-T` file. + +See [curl issue 12171](https://github.com/curl/curl/issues/12171) + +## Windows stdin relay accepts unauthenticated local connections + +curl features a Windows-only stdin relay in `src/tool_doswin.c` that creates a +loopback TCP listener and spawns a thread to accept the first incoming +connection, then forwards stdin to it. There is no authentication or peer +validation on the accepted socket. A local attacker can race to connect to the +ephemeral loopback port (discoverable via local port enumeration/scan) before +curl connects, causing the thread to send stdin/upload data to the attacker or +to disrupt the transfer. + +The function should verify the client-side with a random number similar to the +socketpair emulation function in libcurl. It cannot verify the source address +and port since there is this widespread habit on Windows to run tools that +MITM even local TCP connections for security. + +# Build and portability issues + +## OS400 port requires deprecated IBM library + +curl for OS400 requires `QADRT` to build, which provides ASCII wrappers for +libc/POSIX functions in the ILE, but IBM no longer supports or even offers +this library to download. + +See [curl issue 5176](https://github.com/curl/curl/issues/5176) + +## `curl-config --libs` contains private details + +`curl-config --libs` include details set in `LDFLAGS` when configure is run +that might be needed only for building libcurl. Further, `curl-config +--cflags` suffers from the same effects with `CFLAGS`/`CPPFLAGS`. + +## `LDFLAGS` passed too late making libs linked incorrectly + +Compiling latest curl on HP-UX and linking against a custom OpenSSL (which is +on the default loader/linker path), fails because the generated Makefile has +`LDFLAGS` passed on after `LIBS`. + +See [curl issue 14893](https://github.com/curl/curl/issues/14893) + +## Cygwin: make install installs curl-config.1 twice + +[curl issue 8839](https://github.com/curl/curl/issues/8839) + +## flaky CI builds + +We run many CI builds for each commit and PR on GitHub, and especially a +number of the Windows builds are flaky. This means that we rarely get all CI +builds go green and complete without errors. This is unfortunate as it makes +us sometimes miss actual build problems and it is surprising to newcomers to +the project who (rightfully) do not expect this. + +See [curl issue 6972](https://github.com/curl/curl/issues/6972) + +## long paths are not fully supported on Windows + +curl on Windows cannot access long paths (paths longer than 260 characters). +As a workaround, the Windows path prefix `\\?\` which disables all path +interpretation may work to allow curl to access the path. For example: +`\\?\c:\longpath`. + +See [curl issue 8361](https://github.com/curl/curl/issues/8361) + +## Unicode on Windows + +Passing in a Unicode filename with -o: + +[curl issue 11461](https://github.com/curl/curl/issues/11461) + +Passing in Unicode character with -d: + +[curl issue 12231](https://github.com/curl/curl/issues/12231) + +Windows Unicode builds use the home directory in current locale. + +The Windows Unicode builds of curl use the current locale, but expect Unicode +UTF-8 encoded paths for internal use such as open, access and stat. The user's +home directory is retrieved via curl_getenv in the current locale and not as +UTF-8 encoded Unicode. + +See [curl pull request 7252](https://github.com/curl/curl/pull/7252) and [curl pull request 7281](https://github.com/curl/curl/pull/7281) + +Cannot handle Unicode arguments in non-Unicode builds on Windows + +If a URL or filename cannot be encoded using the user's current code page then +it can only be encoded properly in the Unicode character set. Windows uses +UTF-16 encoding for Unicode and stores it in wide characters, however curl and +libcurl are not equipped for that at the moment except when built with +_UNICODE and UNICODE defined. Except for Cygwin, Windows cannot use UTF-8 as a +locale. + +https://curl.se/bug/?i=345 +https://curl.se/bug/?i=731 +https://curl.se/bug/?i=3747 + +NTLM authentication and Unicode + +NTLM authentication involving Unicode username or password only works properly +if built with UNICODE defined together with the Schannel backend. The original +problem was mentioned in: https://curl.se/mail/lib-2009-10/0024.html and +https://curl.se/bug/view.cgi?id=896 + +The Schannel version verified to work as mentioned in +https://curl.se/mail/lib-2012-07/0073.html + +# Authentication + +## `--aws-sigv4` does not handle multipart/form-data correctly + +[curl issue 13351](https://github.com/curl/curl/issues/13351) + +## Digest `auth-int` for PUT/POST + +We do not support auth-int for Digest using PUT or POST + +## Digest does not care for `domain` + +libcurl ignores the `domain` directive in Digest authentication challenges +(`WWW-Authenticate:`). RFC 7616 defines it as a quoted, space-separated list +of URIs that define the protection space. + +## MIT Kerberos for Windows build + +libcurl fails to build with MIT Kerberos for Windows (`KfW`) due to its +library header files exporting symbols/macros that should be kept private to +the library. + +## NTLM in system context uses wrong name + +NTLM authentication using SSPI (on Windows) when (lib)curl is running in +"system context" makes it use wrong(?) username - at least when compared to +what `winhttp` does. See https://curl.se/bug/view.cgi?id=535 + +## NTLM does not support password with Unicode 'SECTION SIGN' character + +Code point: U+00A7 + +https://en.wikipedia.org/wiki/Section_sign +[curl issue 2120](https://github.com/curl/curl/issues/2120) + +## libcurl can fail to try alternatives with `--proxy-any` + +When connecting via a proxy using `--proxy-any`, a failure to establish an +authentication causes libcurl to abort trying other options if the failed +method has a higher preference than the alternatives. As an example, +`--proxy-any` against a proxy which advertise Negotiate and NTLM, but which +fails to set up Kerberos authentication does not proceed to try authentication +using NTLM. + +[curl issue 876](https://github.com/curl/curl/issues/876) + +## Do not clear digest for single realm + +[curl issue 3267](https://github.com/curl/curl/issues/3267) + +## SHA-256 digest not supported in Windows SSPI builds + +Windows builds of curl that have SSPI enabled use the native Windows API calls +to create authentication strings. The call to `InitializeSecurityContext` fails +with `SEC_E_QOP_NOT_SUPPORTED` which causes curl to fail with +`CURLE_AUTH_ERROR`. + +Microsoft does not document supported digest algorithms and that `SEC_E` error +code is not a documented error for `InitializeSecurityContext` (digest). + +[curl issue 6302](https://github.com/curl/curl/issues/6302) + +## curl never completes Negotiate over HTTP + +Apparently it is not working correctly...? + +See [curl issue 5235](https://github.com/curl/curl/issues/5235) + +## Negotiate on Windows fails + +When using `--negotiate` (or NTLM) with curl on Windows, SSL/TLS handshake +fails despite having a valid kerberos ticket cached. Works without any issue +in Unix/Linux. + +[curl issue 5881](https://github.com/curl/curl/issues/5881) + +## Negotiate authentication against Hadoop + +[curl issue 8264](https://github.com/curl/curl/issues/8264) + +# FTP + +## FTP with ACCT + +When doing an operation over FTP that requires the `ACCT` command (but not when +logging in), the operation fails since libcurl does not detect this and thus +fails to issue the correct command: https://curl.se/bug/view.cgi?id=635 + +## FTPS server compatibility on Windows with Schannel + +FTPS is not widely used with the Schannel TLS backend and so there may be more +bugs compared to other TLS backends such as OpenSSL. In the past users have +reported hanging and failed connections. It is likely some changes to curl +since then fixed the issues. None of the reported issues can be reproduced any +longer. + +If you encounter an issue connecting to your server via FTPS with the latest +curl and Schannel then please search for open issues or file a new issue. + +# SFTP and SCP + +## SFTP does not do `CURLOPT_POSTQUOTE` correct + +When libcurl sends `CURLOPT_POSTQUOTE` commands when connected to an SFTP +server using the multi interface, the commands are not being sent correctly +and instead the connection is canceled (the operation is considered done) +prematurely. There is a half-baked (busy-looping) patch provided in the bug +report but it cannot be accepted as-is. See +https://curl.se/bug/view.cgi?id=748 + +## Remote recursive folder creation with SFTP + +On this servers, the curl fails to create directories on the remote server +even when the `CURLOPT_FTP_CREATE_MISSING_DIRS` option is set. + +See [curl issue 5204](https://github.com/curl/curl/issues/5204) + +## libssh blocking and infinite loop problem + +In the `SSH_SFTP_INIT` state for libssh, the ssh session working mode is set +to blocking mode. If the network is suddenly disconnected during sftp +transmission, curl is stuck, even if curl is configured with a timeout. + +[curl issue 8632](https://github.com/curl/curl/issues/8632) + +## Cygwin: "WARNING: UNPROTECTED PRIVATE KEY FILE!" + +Running SCP and SFTP tests on Cygwin makes this warning message appear. + +[curl issue 11244](https://github.com/curl/curl/issues/11244) + +# Connection + +## `--interface` with link-scoped IPv6 address + +When you give the `--interface` option telling curl to use a specific +interface for its outgoing traffic in combination with an IPv6 address in the +URL that uses a link-local scope, curl might pick the wrong address from the +named interface and the subsequent transfer fails. + +Example command line: + + curl --interface eth0 'http://[fe80:928d:xxff:fexx:xxxx]/' + +The fact that the given IP address is link-scoped should probably be used as +input to somehow make curl make a better choice for this. + +[curl issue 14782](https://github.com/curl/curl/issues/14782) + +## Does not acknowledge getaddrinfo sorting policy + +Even if a user edits `/etc/gai.conf` to prefer IPv4, curl still prefers and +tries IPv6 addresses first. + +[curl issue 16718](https://github.com/curl/curl/issues/16718) + +## SOCKS-SSPI discards the security context + +After a successful SSPI/GSS-API exchange, the function queries and logs the +authenticated username and reports the supported data-protection level, but +then immediately deletes the negotiated SSPI security context and frees the +credentials before returning. The negotiated context is not stored on the +connection and is therefore never used to protect later SOCKS5 traffic. + +## cannot use absolute Unix domain filename for SOCKS on Windows + +curl supports using a Unix domain socket path for speaking SOCKS to a proxy, +by providing a filename in the URL used for `-x` (`CURLOPT_PROXY`), but that +path cannot be a proper absolute Windows path with a drive letter etc. + +A solution for this probably requires that we add and provide a +`--unix-socket` (`CURLOPT_UNIX_SOCKET_PATH`) option alternative for proxy +communication. + +See [curl issue 19825](https://github.com/curl/curl/issues/19825) + +# Internals + +## GSSAPI library name + version is missing in `curl_version_info()` + +The struct needs to be expanded and code added to store this info. + +See [curl issue 13492](https://github.com/curl/curl/issues/13492) + +## error buffer not set if connection to multiple addresses fails + +If you ask libcurl to resolve a hostname like example.com to IPv6 addresses +when you only have IPv4 connectivity. libcurl fails with +`CURLE_COULDNT_CONNECT`, but the error buffer set by `CURLOPT_ERRORBUFFER` +remains empty. Issue: [curl issue 544](https://github.com/curl/curl/issues/544) + +## HTTP test server 'connection-monitor' problems + +The `connection-monitor` feature of the HTTP test server does not work +properly if some tests are run in unexpected order. Like 1509 and then 1525. + +See [curl issue 868](https://github.com/curl/curl/issues/868) + +## Connection information when using TCP Fast Open + +`CURLINFO_LOCAL_PORT` (and possibly a few other) fails when TCP Fast Open is +enabled. + +See [curl issue 1332](https://github.com/curl/curl/issues/1332) and +[curl issue 4296](https://github.com/curl/curl/issues/4296) + +## test cases sometimes timeout + +Occasionally, one of the tests timeouts. Inexplicably. + +See [curl issue 13350](https://github.com/curl/curl/issues/13350) + +## `CURLOPT_CONNECT_TO` does not work for HTTPS proxy + +It is unclear if the same option should even cover the proxy connection or if +it requires a separate option. + +See [curl issue 14481](https://github.com/curl/curl/issues/14481) + +## WinIDN test failures + +Test 165 disabled when built with WinIDN. + +## setting a disabled option should return `CURLE_NOT_BUILT_IN` + +When curl has been built with specific features or protocols disabled, setting +such options with `curl_easy_setopt()` should rather return +`CURLE_NOT_BUILT_IN` instead of `CURLE_UNKNOWN_OPTION` to signal the +difference to the application + +See [curl issue 15472](https://github.com/curl/curl/issues/15472) + +# LDAP + +## OpenLDAP hangs after returning results + +By configuration defaults, OpenLDAP automatically chase referrals on secondary +socket descriptors. The OpenLDAP backend is asynchronous and thus should +monitor all socket descriptors involved. Currently, these secondary +descriptors are not monitored, causing OpenLDAP library to never receive data +from them. + +As a temporary workaround, disable referrals chasing by configuration. + +The fix is not easy: proper automatic referrals chasing requires a synchronous +bind callback and monitoring an arbitrary number of socket descriptors for a +single easy handle (currently limited to 5). + +Generic LDAP is synchronous: OK. + +See [curl issue 622](https://github.com/curl/curl/issues/622) and +https://curl.se/mail/lib-2016-01/0101.html + +## LDAP on Windows does authentication wrong? + +[curl issue 3116](https://github.com/curl/curl/issues/3116) + +## LDAP on Windows does not work + +A simple curl command line getting `ldap://ldap.forumsys.com` returns an error +that says `no memory` ! + +[curl issue 4261](https://github.com/curl/curl/issues/4261) + +## LDAPS requests to Active Directory server hang + +[curl issue 9580](https://github.com/curl/curl/issues/9580) + +# TCP/IP + +## telnet code does not handle partial writes properly + +It probably does not happen too easily because of how slow and infrequent +sends are normally performed. + +## Trying local ports fails on Windows + +This makes `--local-port [range]` to not work since curl cannot properly +detect if a port is already in use, so it tries the first port, uses that and +then subsequently fails anyway if that was actually in use. + +[curl issue 8112](https://github.com/curl/curl/issues/8112) + +# HTTP/2 + +## HTTP/2 prior knowledge over proxy + +[curl issue 12641](https://github.com/curl/curl/issues/12641) + +## HTTP/2 frames while in the connection pool kill reuse + +If the server sends HTTP/2 frames (like for example an HTTP/2 PING frame) to +curl while the connection is held in curl's connection pool, the socket is +found readable when considered for reuse and that makes curl think it is dead +and then it is closed and a new connection gets created instead. + +This is *best* fixed by adding monitoring to connections while they are kept +in the pool so that pings can be responded to appropriately. + +## `ENHANCE_YOUR_CALM` causes infinite retries + +Infinite retries with 2 parallel requests on one connection receiving `GOAWAY` +with `ENHANCE_YOUR_CALM` error code. + +See [curl issue 5119](https://github.com/curl/curl/issues/5119) + +## HTTP/2 + TLS spends a lot of time in recv + +It has been observed that by making the speed limit less accurate we could +improve this performance. (by reverting +[db5c9f4f9e0779](https://github.com/curl/curl/commit/db5c9f4f9e0779b49624752b135281a0717b277b)) +Can we find a golden middle ground? + +See https://curl.se/mail/lib-2024-05/0026.html and +[curl issue 13416](https://github.com/curl/curl/issues/13416) + +# HTTP/3 + +## connection migration does not work + +[curl issue 7695](https://github.com/curl/curl/issues/7695) + +## quiche: QUIC connection is draining + +The transfer ends with error "QUIC connection is draining". + +[curl issue 12037](https://github.com/curl/curl/issues/12037) + +# RTSP + +## Some methods do not support response bodies + +The RTSP implementation is written to assume that a number of RTSP methods +always get responses without bodies, even though there seems to be no +indication in the RFC that this is always the case. + +[curl issue 12414](https://github.com/curl/curl/issues/12414) diff --git a/third-party/curl/docs/KNOWN_RISKS.md b/third-party/curl/docs/KNOWN_RISKS.md new file mode 100644 index 0000000000..82125f0c66 --- /dev/null +++ b/third-party/curl/docs/KNOWN_RISKS.md @@ -0,0 +1,149 @@ + + +# Known Risks + +This is an incomplete list of known risks when running and using curl and +libcurl. + +# Risks + +## Insecure transfers + +When using curl to perform transfers with protocols that are insecure or the +server identity is unverified, everything that is sent and received can be +intercepted by eavesdroppers and the servers can easily be spoofed by +impostors. + +## Untrusted input + +You should **never** run curl command lines or use curl config files provided +to you from untrusted sources. + +curl can do a lot of things, and you should only ask it do things you want and +deem correct. + +Even accepting only the URL part without careful vetting might make curl do +things you do not like. Like accessing internal hosts, like connecting to +rogue servers that redirect to even weirder places, like using ports or +protocols that play tricks on you. + +## Command line misuse + +The command line tool and its options should be used and be expected to work +as documented. Relying on undocumented functions or side-effects is unreliable +as they may cause problems or get changed behavior between releases. + +For several command line options, you can confuse either curl or the involved +server endpoint by using characters or byte sequences for the option that are +not expected. For example, adding line feeds and/or carriage returns to inputs +can produce unexpected, invalid, or insecure results. + +## API misuse + +Applications using the libcurl API in a way that is not documented to work or +even documented to not work, is unsafe and might cause security problems. We +only guarantee secure and proper functionality when the APIs are used as +documented. + +## Local attackers already present + +When there is a local attacker present locally, curl cannot prevent such an +adversary to use curl's full potential. Possibly in malicious ways. + +## Remote attackers already present + +When there is a remote attacker already present in the server, curl cannot +protect its operations against mischief. For example, if an attacker manages +to insert a symlink in your remote upload directory the upload may cause +havoc. Maybe the attacker makes certain responses come back with unexpected +content. + +## Debug & Experiments + +We encourage users to test curl experiments and use debug code, but only in +controlled environments and setups - never in production. + +Using debug builds and experimental curl features in production is a security +risk. Do not do that. + +The same applies to scripts and software which are not installed by default +through the make install rule: they are not intended or made for production +use. + +## URL inconsistencies + +URL parser inconsistencies between browsers and curl are expected and are not +considered security vulnerabilities. The WHATWG URL Specification and RFC +3986+ (the plus meaning that it is an extended version) [are not completely +interoperable](https://github.com/bagder/docs/blob/master/URL-interop.md). + +You must never expect two independent URL parsers to treat every URL +identically. + +## Visible command line arguments + +The curl command blanks the contents of a number of command line arguments to +prevent them from appearing in process listings. It does not blank all +arguments, even though some that are not blanked might contain sensitive data. + +- not all systems allow the arguments to be blanked in the first place +- since curl blanks the argument itself they are readable for a short moment + no matter what +- virtually every argument can contain sensitive data, depending on use +- blanking all arguments would make it impractical for users to differentiate + curl command lines in process listings + +## HTTP headers in redirects + +It is powerful to provide a set of custom headers to curl. Beware that when +asking curl to follow HTTP redirects, it also sends those headers to the new +URL which might be a different server. That might do another redirect etc. + +curl makes some limited attempts to not leak credentials this way when set +using the standard curl options, but when you pass on custom headers curl +cannot know what headers or details in those headers are sensitive. + +## Verbose logs + +When asked to provide verbose output and trace logging, curl may output and +show details that are private and sensitive. Like for example raw credentials +or the password weakly disguised using base64 encoding. + +## Terminal output and escape sequences + +Content that is transferred from a server and gets displayed in a terminal by +curl may contain escape sequences or use other tricks to fool the user. Escape +sequences, moving cursor, changing color etc, is also frequently used for +good. To reduce the risk of getting fooled, save files and browse them after +download using a display method that minimizes risks. + +## Legacy dependencies + +Every curl build is made to use a range of third party libraries. Each third +party library also needs to be safe and secure for the entire operation to be +risk-free. + +Relying on legacy dependencies is a risk. + +## Weak algorithms + +curl supports several cryptographic algorithms that are considered weak, like +DES and MD5. These algorithms are still in use because some protocols and +transfer options require use of them. For example NTLM or legacy HTTP Digest +authentication. + +curl users should consider switching to servers and options that use modern +and secure algorithms. + +## Compression bombs + +When asking curl or libcurl to automatically decompress data on arrival, there +is a risk that the size of the output from the decompression process ends up +many times larger than the input data size. + +Since curl 8.20.0, users can mitigate this risk by setting the max filesize +option that also covers the decompressed size. diff --git a/third-party/curl/docs/MAIL-ETIQUETTE b/third-party/curl/docs/MAIL-ETIQUETTE deleted file mode 100644 index 2dcf9cb896..0000000000 --- a/third-party/curl/docs/MAIL-ETIQUETTE +++ /dev/null @@ -1,285 +0,0 @@ - _ _ ____ _ - ___| | | | _ \| | - / __| | | | |_) | | - | (__| |_| | _ <| |___ - \___|\___/|_| \_\_____| - -MAIL ETIQUETTE - - 1. About the lists - 1.1 Mailing Lists - 1.2 Netiquette - 1.3 Do Not Mail a Single Individual - 1.4 Subscription Required - 1.5 Moderation of new posters - 1.6 Handling trolls and spam - 1.7 How to unsubscribe - 1.8 I posted, now what? - 1.9 Your emails are public - - 2. Sending mail - 2.1 Reply or New Mail - 2.2 Reply to the List - 2.3 Use a Sensible Subject - 2.4 Do Not Top-Post - 2.5 HTML is not for mails - 2.6 Quoting - 2.7 Digest - 2.8 Please Tell Us How You Solved The Problem - -============================================================================== - -1. About the lists - - 1.1 Mailing Lists - - The mailing lists we have are all listed and described at - https://curl.se/mail/ - - Each mailing list is targeted to a specific set of users and subjects, - please use the one or the ones that suit you the most. - - Each mailing list has hundreds up to thousands of readers, meaning that each - mail sent will be received and read by a large number of people. People - from various cultures, regions, religions and continents. - - 1.2 Netiquette - - Netiquette is a common term for how to behave on the Internet. Of course, in - each particular group and subculture there will be differences in what is - acceptable and what is considered good manners. - - This document outlines what we in the curl project consider to be good - etiquette, and primarily this focus on how to behave on and how to use our - mailing lists. - - 1.3 Do Not Mail a Single Individual - - Many people send one question to one person. One person gets many mails, and - there is only one person who can give you a reply. The question may be - something that other people would also like to ask. These other people have - no way to read the reply, but to ask the one person the question. The one - person consequently gets overloaded with mail. - - If you really want to contact an individual and perhaps pay for his or her - services, by all means go ahead, but if it's just another curl question, - take it to a suitable list instead. - - 1.4 Subscription Required - - All curl mailing lists require that you are subscribed to allow a mail to go - through to all the subscribers. - - If you post without being subscribed (or from a different mail address than - the one you are subscribed with), your mail will simply be silently - discarded. You have to subscribe first, then post. - - The reason for this unfortunate and strict subscription policy is of course - to stop spam from pestering the lists. - - 1.5 Moderation of new posters - - Several of the curl mailing lists automatically make all posts from new - subscribers be moderated. This means that after you have subscribed and - sent your first mail to a list, that mail will not be let through to the - list until a mailing list administrator has verified that it is OK and - permits it to get posted. - - Once a first post has been made that proves the sender is actually talking - about curl-related subjects, the moderation "flag" will be switched off and - future posts will go through without being moderated. - - The reason for this moderation policy is that we do suffer from spammers who - actually subscribe and send spam to our lists. - - 1.6 Handling trolls and spam - - Despite our good intentions and hard work to keep spam off the lists and to - maintain a friendly and positive atmosphere, there will be times when spam - and or trolls get through. - - Troll - "someone who posts inflammatory, extraneous, or off-topic messages - in an online community" - - Spam - "use of electronic messaging systems to send unsolicited bulk - messages" - - No matter what, we NEVER EVER respond to trolls or spammers on the list. If - you believe the list admin should do something in particular, contact them - off-list. The subject will be taken care of as much as possible to prevent - repeated offenses, but responding on the list to such messages never leads to - anything good and only puts the light even more on the offender: which was - the entire purpose of it getting sent to the list in the first place. - - Do not feed the trolls. - - 1.7 How to unsubscribe - - You can unsubscribe the same way you subscribed in the first place. You go - to the page for the particular mailing list you are subscribed to and you enter - your email address and password and press the unsubscribe button. - - Also, the instructions to unsubscribe are included in the headers of every - mail that is sent out to all curl related mailing lists and there is a footer - in each mail that links to the "admin" page on which you can unsubscribe and - change other options. - - You NEVER EVER email the mailing list requesting someone else to take you off - the list. - - 1.8 I posted, now what? - - If you are not subscribed with the same email address that you used to send - the email, your post will just be silently discarded. - - If you posted for the first time to the mailing list, you first need to wait - for an administrator to allow your email to go through (moderated). This - normally happens quickly but in case we are asleep, you may have to wait a - few hours. - - Once your email goes through it is sent out to several hundred or even - thousands of recipients. Your email may cover an area that not that many - people know about or are interested in. Or possibly the person who knows - about it is on vacation or under a heavy work load right now. You may have - to wait for a response and you should not expect to get a response at all. - Ideally, you get an answer within a couple of days. - - You do yourself and all of us a service when you include as many details as - possible already in your first email. Mention your operating system and - environment. Tell us which curl version you are using and tell us what you - did, what happened and what you expected would happen. Preferably, show us - what you did with details enough to allow others to help point out the - problem or repeat the steps in their locations. - - Failing to include details will only delay responses and make people respond - and ask for more details and you will have to send a follow-up email that - includes them. - - Expect the responses to primarily help YOU debug the issue, or ask YOU - questions that can lead you or others towards a solution or explanation to - whatever you experience. - - If you are a repeat offender to the guidelines outlined in this document, - chances are that people will ignore you at will and your chances to get - responses in the future will greatly diminish. - - 1.9 Your emails are public - - Your email, its contents and all its headers and the details in those - headers will be received by every subscriber of the mailing list that you - send your email to. - - Your email as sent to a curl mailing list will end up in mail archives, on - the curl website and elsewhere, for others to see and read. Today and in - the future. In addition to the archives, the mail is sent out to thousands - of individuals. There is no way to undo a sent email. - - When sending emails to a curl mailing list, do not include sensitive - information such as user names and passwords; use fake ones, temporary ones - or just remove them completely from the mail. Note that this includes base64 - encoded HTTP Basic auth headers. - - This public nature of the curl mailing lists makes automatically inserted mail - footers about mails being "private" or "only meant for the recipient" or - similar even more silly than usual. Because they are absolutely not private - when sent to a public mailing list. - - -2. Sending mail - - 2.1 Reply or New Mail - - Please do not reply to an existing message as a short-cut to post a message - to the lists. - - Many mail programs and web archivers use information within mails to keep - them together as "threads", as collections of posts that discuss a certain - subject. If you do not intend to reply on the same or similar subject, do not - just hit reply on an existing mail and change the subject, create a new mail. - - 2.2 Reply to the List - - When replying to a message from the list, make sure that you do "group - reply" or "reply to all", and not just reply to the author of the single - mail you reply to. - - We are actively discouraging replying back to the single person by setting - the Reply-To: field in outgoing mails back to the mailing list address, - making it harder for people to mail the author directly, if only by mistake. - - 2.3 Use a Sensible Subject - - Please use a subject of the mail that makes sense and that is related to the - contents of your mail. It makes it a lot easier to find your mail afterwards - and it makes it easier to track mail threads and topics. - - 2.4 Do Not Top-Post - - If you reply to a message, do not use top-posting. Top-posting is when you - write the new text at the top of a mail and you insert the previous quoted - mail conversation below. It forces users to read the mail in a backwards - order to properly understand it. - - This is why top posting is so bad (in top posting order): - - A: Because it messes up the order in which people normally read text. - Q: Why is top-posting such a bad thing? - A: Top-posting. - Q: What is the most annoying thing in email? - - Apart from the screwed up read order (especially when mixed together in a - thread when someone responds using the mandated bottom-posting style), it - also makes it impossible to quote only parts of the original mail. - - When you reply to a mail. You let the mail client insert the previous mail - quoted. Then you put the cursor on the first line of the mail and you move - down through the mail, deleting all parts of the quotes that do not add - context for your comments. When you want to add a comment you do so, inline, - right after the quotes that relate to your comment. Then you continue - downwards again. - - When most of the quotes have been removed and you have added your own words, - you are done. - - 2.5 HTML is not for mails - - Please switch off those HTML encoded messages. You can mail all those funny - mails to your friends. We speak plain text mails. - - 2.6 Quoting - - Quote as little as possible. Just enough to provide the context you cannot - leave out. A lengthy description can be found here: - - https://www.netmeister.org/news/learn2quote.html - - 2.7 Digest - - We allow subscribers to subscribe to the "digest" version of the mailing - lists. A digest is a collection of mails lumped together in one single mail. - - Should you decide to reply to a mail sent out as a digest, there are two - things you MUST consider if you really really cannot subscribe normally - instead: - - Cut off all mails and chatter that is not related to the mail you want to - reply to. - - Change the subject name to something sensible and related to the subject, - preferably even the actual subject of the single mail you wanted to reply to - - 2.8 Please Tell Us How You Solved The Problem - - Many people mail questions to the list, people spend some of their time and - make an effort in providing good answers to these questions. - - If you are the one who asks, please consider responding once more in case - one of the hints was what solved your problems. The guys who write answers - feel good to know that they provided a good answer and that you fixed the - problem. Far too often, the person who asked the question is never heard from - again, and we never get to know if they are gone because the problem was - solved or perhaps because the problem was unsolvable. - - Getting the solution posted also helps other users that experience the same - problem(s). They get to see (possibly in the web archives) that the - suggested fixes actually have helped at least one person. diff --git a/third-party/curl/docs/MAIL-ETIQUETTE.md b/third-party/curl/docs/MAIL-ETIQUETTE.md new file mode 100644 index 0000000000..9c2527d04d --- /dev/null +++ b/third-party/curl/docs/MAIL-ETIQUETTE.md @@ -0,0 +1,257 @@ + + +# Mail etiquette + +## About the lists + +### Mailing Lists + +The mailing lists we have are all listed and described on the [curl +website](https://curl.se/mail/). + +Each mailing list is targeted to a specific set of users and subjects, please +use the one or the ones that suit you the most. + +Each mailing list has hundreds up to thousands of readers, meaning that each +mail sent is received and read by a large number of people. People from +various cultures, regions, religions and continents. + +### Netiquette + +Netiquette is a common term for how to behave on the Internet. Of course, in +each particular group and subculture there are differences in what is +acceptable and what is considered good manners. + +This document outlines what we in the curl project consider to be good +etiquette, and primarily this focus on how to behave on and how to use our +mailing lists. + +### Do Not Mail a Single Individual + +Many people send one question to one person. One person gets many mails, and +there is only one person who can give you a reply. The question may be +something that other people would also like to ask. These other people have no +way to read the reply, but to ask the one person the question. The one person +consequently gets overloaded with mail. + +If you really want to contact an individual and perhaps pay for his or her +services, by all means go ahead, but if it is another curl question, take it +to a suitable list instead. + +### Subscription Required + +All curl mailing lists require that you are subscribed to allow a mail to go +through to all the subscribers. + +If you post without being subscribed (or from a different mail address than +the one you are subscribed with), your mail is silently discarded. You +have to subscribe first, then post. + +The reason for this unfortunate and strict subscription policy is of course to +stop spam from pestering the lists. + +### Moderation of new posters + +Several of the curl mailing lists automatically make all posts from new +subscribers be moderated. After you have subscribed and sent your first mail +to a list, that mail is not let through to the list until a mailing list +administrator has verified that it is OK and permits it to get posted. + +Once a first post has been made that proves the sender is actually talking +about curl-related subjects, the moderation "flag" is switched off and future +posts go through without being moderated. + +The reason for this moderation policy is that we do suffer from spammers who +actually subscribe and send spam to our lists. + +### Handling trolls and spam + +Despite our good intentions and hard work to keep spam off the lists and to +maintain a friendly and positive atmosphere, there are times when spam and or +trolls get through. + +Troll - "someone who posts inflammatory, extraneous, or off-topic messages in +an online community" + +Spam - "use of electronic messaging systems to send unsolicited bulk messages" + +No matter what, we NEVER EVER respond to trolls or spammers on the list. If +you believe the list admin should do something in particular, contact them +off-list. The subject is taken care of as much as possible to prevent repeated +offenses, but responding on the list to such messages never leads to anything +good and only puts the light even more on the offender: which was the entire +purpose of it getting sent to the list in the first place. + +Do not feed the trolls. + +### How to unsubscribe + +You can unsubscribe the same way you subscribed in the first place. You go to +the page for the particular mailing list you are subscribed to and you enter +your email address and password and press the unsubscribe button. + +Also, the instructions to unsubscribe are included in the headers of every +mail that is sent out to all curl related mailing lists and there is a footer +in each mail that links to the "admin" page on which you can unsubscribe and +change other options. + +You NEVER EVER email the mailing list requesting someone else to take you off +the list. + +### I posted, now what? + +If you are not subscribed with the same email address that you used to send +the email, your post is silently discarded. + +If you posted for the first time to the mailing list, you first need to wait +for an administrator to allow your email to go through (moderated). This +normally happens quickly but in case we are asleep, you may have to wait a few +hours. + +Once your email goes through it is sent out to several hundred or even +thousands of recipients. Your email may cover an area that not that many +people know about or are interested in. Or possibly the person who knows about +it is on vacation or under a heavy work load right now. You may have to wait +for a response and you should not expect to get a response at all. Ideally, +you get an answer within a couple of days. + +You do yourself and all of us a service when you include as many details as +possible already in your first email. Mention your operating system and +environment. Tell us which curl version you are using and tell us what you +did, what happened and what you expected would happen. Preferably, show us +what you did with details enough to allow others to help point out the problem +or repeat the steps in their locations. + +Failing to include details only delays responses and make people respond and +ask for more details and you have to send follow-up emails that include them. + +Expect the responses to primarily help YOU debug the issue, or ask YOU +questions that can lead you or others towards a solution or explanation to +whatever you experience. + +If you are a repeat offender to the guidelines outlined in this document, +chances are that people ignore you and your chances to get responses in the +future greatly diminish. + +### Your emails are public + +Your email, its contents and all its headers and the details in those headers +are received by every subscriber of the mailing list that you send your email +to. + +Your email as sent to a curl mailing list ends up in mail archives, on the +curl website and elsewhere, for others to see and read. Today and in the +future. In addition to the archives, the mail is sent out to thousands of +individuals. There is no way to undo a sent email. + +When sending emails to a curl mailing list, do not include sensitive +information such as usernames and passwords; use fake ones, temporary ones or +remove them completely from the mail. Note that this includes base64 encoded +HTTP Basic auth headers. + +This public nature of the curl mailing lists makes automatically inserted mail +footers about mails being "private" or "only meant for the recipient" or +similar even more silly than usual. Because they are absolutely not private +when sent to a public mailing list. + +## Sending mail + +### Reply or New Mail + +Please do not reply to an existing message as a short-cut to post a message to +the lists. + +Many mail programs and web archivers use information within mails to keep them +together as "threads", as collections of posts that discuss a certain subject. +If you do not intend to reply on the same or similar subject, do not hit reply +on an existing mail and change the subject, create a new mail. + +### Reply to the List + +When replying to a message from the list, make sure that you do "group reply" +or "reply to all", and not reply to the author of the single mail you reply +to. + +We are actively discouraging replying to the single person by setting the +correct field in outgoing mails back asking for replies to get sent to the +mailing list address, making it harder for people to reply to the author only +by mistake. + +### Use a Sensible Subject + +Please use a subject of the mail that makes sense and that is related to the +contents of your mail. It makes it a lot easier to find your mail afterwards +and it makes it easier to track mail threads and topics. + +### Do Not Top-Post + +If you reply to a message, do not use top-posting. Top-posting is when you +write the new text at the top of a mail and you insert the previous quoted +mail conversation below. It forces users to read the mail in a backwards order +to properly understand it. + +This is why top posting is so bad (in top posting order): + + A: Because it messes up the order in which people normally read text. + Q: Why is top-posting such a bad thing? + A: Top-posting. + Q: What is the most annoying thing in email? + +Apart from the screwed up read order (especially when mixed together in a +thread when someone responds using the mandated bottom-posting style), it also +makes it impossible to quote only parts of the original mail. + +When you reply to a mail. You let the mail client insert the previous mail +quoted. Then you put the cursor on the first line of the mail and you move +down through the mail, deleting all parts of the quotes that do not add +context for your comments. When you want to add a comment you do so, inline, +right after the quotes that relate to your comment. Then you continue +downwards again. + +When most of the quotes have been removed and you have added your own words, +you are done. + +### HTML is not for mails + +Please switch off those HTML encoded messages. You can mail all those funny +mails to your friends. We speak plain text mails. + +### Quoting + +Quote as little as possible. Enough to provide the context you cannot leave +out. + +### Digest + +We allow subscribers to subscribe to the "digest" version of the mailing +lists. A digest is a collection of mails lumped together in one single mail. + +Should you decide to reply to a mail sent out as a digest, there are two +things you MUST consider if you really, really cannot subscribe normally +instead: + +Cut off all mails and chatter that is not related to the mail you want to +reply to. + +Change the subject name to something sensible and related to the subject, +preferably even the actual subject of the single mail you wanted to reply to + +### Please Tell Us How You Solved The Problem + +Many people mail questions to the list, people spend some of their time and +make an effort in providing good answers to these questions. + +If you are the one who asks, please consider responding once more in case one +of the hints was what solved your problems. The guys who write answers feel +good to know that they provided a good answer and that you fixed the problem. +Far too often, the person who asked the question is never heard from again, +and we never get to know if they are gone because the problem was solved or +perhaps because the problem was unsolvable. + +Getting the solution posted also helps other users that experience the same +problem(s). They get to see (possibly in the web archives) that the suggested +fixes actually have helped at least one person. diff --git a/third-party/curl/docs/MANUAL.md b/third-party/curl/docs/MANUAL.md index 9c1b291f05..fb62f64ba2 100644 --- a/third-party/curl/docs/MANUAL.md +++ b/third-party/curl/docs/MANUAL.md @@ -1,3 +1,9 @@ + + # curl tutorial ## Simple Usage @@ -8,35 +14,35 @@ Get the main page from a web-server: Get a README file from an FTP server: - curl ftp://ftp.funet.fi/README + curl ftp://ftp.example.com/README -Get a web page from a server using port 8000: +Get a webpage from a server using port 8000: - curl http://www.weirdserver.com:8000/ + curl http://www.example.com:8000/ Get a directory listing of an FTP site: - curl ftp://ftp.funet.fi + curl ftp://ftp.example.com/ Get the all terms matching curl from a dictionary: - curl dict://dict.org/m:curl + curl dict://dict.example.com/m:curl Get the definition of curl from a dictionary: - curl dict://dict.org/d:curl + curl dict://dict.example.com/d:curl Fetch two documents at once: - curl ftp://ftp.funet.fi/ http://www.weirdserver.com:8000/ + curl ftp://ftp.example.com/ https://www.example.com:8000/ Get a file off an FTPS server: - curl ftps://files.are.secure.com/secrets.txt + curl ftps://files.are.example.com/secrets.txt or use the more appropriate FTPS way to get the same file: - curl --ftp-ssl ftp://files.are.secure.com/secrets.txt + curl --ssl-reqd ftp://files.are.example.com/secrets.txt Get a file from an SSH server using SFTP: @@ -63,15 +69,14 @@ Get a file from an SMB server: ## Download to a File -Get a web page and store in a local file with a specific name: +Get a webpage and store in a local file with a specific name: - curl -o thatpage.html http://www.example.com/ + curl -o thatpage.html https://www.example.com/ -Get a web page and store in a local file, make the local file get the name of -the remote document (if no file name part is specified in the URL, this will -fail): +Get a webpage and store in a local file, make the local file get the name of +the remote document (if no filename part is specified in the URL, this fails): - curl -O http://www.example.com/index.html + curl -O https://www.example.com/index.html Fetch two files and store them with their remote names: @@ -83,19 +88,19 @@ Fetch two files and store them with their remote names: To ftp files using name and password, include them in the URL like: - curl ftp://name:passwd@machine.domain:port/full/path/to/file + curl ftp://name:passwd@ftp.server.example:port/full/path/to/file or specify them with the `-u` flag like - curl -u name:passwd ftp://machine.domain:port/full/path/to/file + curl -u name:passwd ftp://ftp.server.example:port/full/path/to/file ### FTPS -It is just like for FTP, but you may also want to specify and use SSL-specific -options for certificates etc. +It is like FTP, but you may also want to specify and use SSL-specific options +for certificates etc. -Note that using `FTPS://` as prefix is the *implicit* way as described in the -standards while the recommended *explicit* way is done by using `FTP://` and +Note that using `ftps://` as prefix is the *implicit* way as described in the +standards while the recommended *explicit* way is done by using `ftp://` and the `--ssl-reqd` option. ### SFTP / SCP @@ -104,20 +109,20 @@ This is similar to FTP, but you can use the `--key` option to specify a private key to use instead of a password. Note that the private key may itself be protected by a password that is unrelated to the login password of the remote system; this password is specified using the `--pass` option. -Typically, curl will automatically extract the public key from the private key +Typically, curl automatically extracts the public key from the private key file, but in cases where curl does not have the proper library support, a matching public key file must be specified using the `--pubkey` option. ### HTTP -Curl also supports user and password in HTTP URLs, thus you can pick a file +curl also supports user and password in HTTP(S) URLs. You can download a file like: - curl http://name:passwd@machine.domain/full/path/to/file + curl https://name:passwd@http.server.example/full/path/to/file or specify user and password separately like in - curl -u name:passwd http://machine.domain/full/path/to/file + curl -u name:passwd https://http.server.example/full/path/to/file HTTP offers many different methods of authentication and curl supports several: Basic, Digest, NTLM and Negotiate (SPNEGO). Without telling which @@ -126,7 +131,7 @@ secure ones out of the ones that the server accepts for the given URL, by using `--anyauth`. **Note**! According to the URL specification, HTTP URLs can not contain a user -and password, so that style will not work when using curl via a proxy, even +and password, so that style does not work when using curl via a proxy, even though curl allows it at other times. When using a proxy, you _must_ use the `-u` style for user and password. @@ -144,28 +149,28 @@ servers. Get an ftp file using an HTTP proxy named my-proxy that uses port 888: - curl -x my-proxy:888 ftp://ftp.leachsite.com/README + curl -x my-proxy:888 ftp://ftp.example.com/README -Get a file from an HTTP server that requires user and password, using the +Get a file from an HTTPS server that requires user and password, using the same proxy as above: - curl -u user:passwd -x my-proxy:888 http://www.get.this/ + curl -u user:passwd -x my-proxy:888 https://www.example.com/ Some proxies require special authentication. Specify by using -U as above: - curl -U user:passwd -x my-proxy:888 http://www.get.this/ + curl -U user:passwd -x my-proxy:888 https://www.example.com/ A comma-separated list of hosts and domains which do not use the proxy can be specified as: - curl --noproxy localhost,get.this -x my-proxy:888 http://www.get.this/ + curl --noproxy example.com -x my-proxy:888 https://www.example.com/ If the proxy is specified with `--proxy1.0` instead of `--proxy` or `-x`, then -curl will use HTTP/1.0 instead of HTTP/1.1 for any `CONNECT` attempts. +curl uses HTTP/1.0 instead of HTTP/1.1 for any `CONNECT` attempts. curl also supports SOCKS4 and SOCKS5 proxies with `--socks4` and `--socks5`. -See also the environment variables Curl supports that offer further proxy +See also the environment variables curl supports that offer further proxy control. Most FTP proxy servers are set up to appear as a normal FTP server from the @@ -174,43 +179,43 @@ curl supports the `-u`, `-Q` and `--ftp-account` options that can be used to set up transfers through many FTP proxies. For example, a file can be uploaded to a remote FTP server using a Blue Coat FTP proxy with the options: - curl -u "username@ftp.server Proxy-Username:Remote-Pass" + curl -u "username@ftp.server.example Proxy-Username:Remote-Pass" --ftp-account Proxy-Password --upload-file local-file - ftp://my-ftp.proxy.server:21/remote/upload/path/ + ftp://my-ftp.proxy.example:21/remote/upload/path/ See the manual for your FTP proxy to determine the form it expects to set up transfers, and curl's `-v` option to see exactly what curl is sending. ## Piping -Get a key file and add it with `apt-key` (when on a system that uses `apt` for -package management): +Get a key file and install it as a trusted one (when on a system that uses +`apt` for package management): - curl -L https://apt.llvm.org/llvm-snapshot.gpg.key | sudo apt-key add - + curl -L https://apt.example.org/llvm-snapshot.gpg.key | sudo tee + /etc/apt/trusted.gpg.d/llvm-snapshot.asc >/dev/null -The '|' pipes the output to STDIN. `-` tells `apt-key` that the key file -should be read from STDIN. +The '|' pipes the output to stdin. `tee` reads from stdin. ## Ranges HTTP 1.1 introduced byte-ranges. Using this, a client can request to get only -one or more sub-parts of a specified document. Curl supports this with the +one or more sub-parts of a specified document. curl supports this with the `-r` flag. Get the first 100 bytes of a document: - curl -r 0-99 http://www.get.this/ + curl -r 0-99 https://www.example.com/ Get the last 500 bytes of a document: - curl -r -500 http://www.get.this/ + curl -r -500 https://www.example.com/ -Curl also supports simple ranges for FTP files as well. Then you can only +curl also supports simple ranges for FTP files as well. Then you can only specify start and stop position. Get the first 100 bytes of a document using FTP: - curl -r 0-99 ftp://www.get.this/README + curl -r 0-99 ftp://www.example.com/README ## Uploading @@ -218,26 +223,26 @@ Get the first 100 bytes of a document using FTP: Upload all data on stdin to a specified server: - curl -T - ftp://ftp.upload.com/myfile + curl -T - ftp://ftp.example.com/myfile Upload data from a specified file, login with user and password: - curl -T uploadfile -u user:passwd ftp://ftp.upload.com/myfile + curl -T uploadfile -u user:passwd ftp://ftp.example.com/myfile -Upload a local file to the remote site, and use the local file name at the +Upload a local file to the remote site, and use the local filename at the remote site too: - curl -T uploadfile -u user:passwd ftp://ftp.upload.com/ + curl -T uploadfile -u user:passwd ftp://ftp.example.com/ Upload a local file to get appended to the remote file: - curl -T localfile -a ftp://ftp.upload.com/remotefile + curl -T localfile -a ftp://ftp.example.com/remotefile -Curl also supports ftp upload through a proxy, but only if the proxy is +curl also supports ftp upload through a proxy, but only if the proxy is configured to allow that kind of tunneling. If it does, you can run curl in a fashion similar to: - curl --proxytunnel -x proxy:port -T localfile ftp.upload.com + curl --proxytunnel -x proxy:port -T localfile ftp.example.com ### SMB / SMBS @@ -246,9 +251,9 @@ fashion similar to: ### HTTP -Upload all data on stdin to a specified HTTP site: +Upload all data on stdin to a specified HTTPS site: - curl -T - http://www.upload.com/myfile + curl -T - https://www.example.com/myfile Note that the HTTP server must have been configured to accept PUT before this can be done successfully. @@ -257,20 +262,19 @@ For other ways to do HTTP data upload, see the POST section below. ## Verbose / Debug -If curl fails where it is not supposed to, if the servers do not let you in, if -you cannot understand the responses: use the `-v` flag to get verbose -fetching. Curl will output lots of info and what it sends and receives in -order to let the user see all client-server interaction (but it will not show you -the actual data). +If curl fails where it is not supposed to, if the servers do not let you in, +if you cannot understand the responses: use the `-v` flag to get verbose +fetching. curl outputs lots of info and what it sends and receives in order to +let the user see all client-server interaction (but it does not show you the +actual data). - curl -v ftp://ftp.upload.com/ + curl -v ftp://ftp.example.com/ To get even more details and information on what curl does, try using the -`--trace` or `--trace-ascii` options with a given file name to log to, like +`--trace` or `--trace-ascii` options with a given filename to log to, like this: - curl --trace trace.txt www.haxx.se - + curl --trace my-trace.txt www.haxx.se ## Detailed Information @@ -281,9 +285,9 @@ info on a single file for HTTP and FTP. The HTTP information is a lot more extensive. For HTTP, you can get the header information (the same as `-I` would show) -shown before the data by using `-i`/`--include`. Curl understands the +shown before the data by using `-i`/`--include`. curl understands the `-D`/`--dump-header` option when getting files from both FTP and HTTP, and it -will then store the headers in the specified file. +then stores the headers in the specified file. Store the HTTP headers in a separate file (headers.txt in the example): @@ -300,11 +304,12 @@ The post data must be urlencoded. Post a simple `name` and `phone` guestbook. - curl -d "name=Rafael%20Sagula&phone=3320780" http://www.where.com/guest.cgi + curl -d "name=Rafael%20Sagula&phone=3320780" https://www.example.com/guest.cgi Or automatically [URL encode the data](https://everything.curl.dev/http/post/url-encode). - curl --data-urlencode "name=Rafael Sagula&phone=3320780" http://www.where.com/guest.cgi + curl --data-urlencode "name=Rafael Sagula&phone=3320780" + https://www.example.com/guest.cgi How to post a form with curl, lesson #1: @@ -323,23 +328,23 @@ of the letter's ASCII code. Example: -(page located at `http://www.formpost.com/getthis/`) +(say if `https://example.com` had the following html) ```html
- - - - + + + +
``` We want to enter user `foobar` with password `12345`. -To post to this, you enter a curl command line like: +To post to this, you would enter a curl command line like: curl -d "user=foobar&pass=12345&id=blablabla&ding=submit" - http://www.formpost.com/getthis/post.cgi + https://example.com/post.cgi While `-d` uses the application/x-www-form-urlencoded mime-type, generally understood by CGI's and similar, curl also supports the more capable @@ -348,20 +353,20 @@ multipart/form-data type. This latter type supports things like file upload. `-F` accepts parameters like `-F "name=contents"`. If you want the contents to be read from a file, use `@filename` as contents. When specifying a file, you can also specify the file content type by appending `;type=` to the -file name. You can also post the contents of several files in one field. For +filename. You can also post the contents of several files in one field. For example, the field name `coolfiles` is used to send three files, with different content types using the following syntax: curl -F "coolfiles=@fil1.gif;type=image/gif,fil2.txt,fil3.html" - http://www.post.com/postit.cgi + https://www.example.com/postit.cgi -If the content-type is not specified, curl will try to guess from the file +If the content-type is not specified, curl tries to guess from the file extension (it only knows a few), or use the previously specified type (from an -earlier file if several files are specified in a list) or else it will use the +earlier file if several files are specified in a list) or else it uses the default type `application/octet-stream`. Emulate a fill-in form with `-F`. Let's say you fill in three fields in a -form. One field is a file name which to post, one field is your name and one +form. One field is a filename which to post, one field is your name and one field is a file description. We want to post the file we have written named `cooltext.txt`. To let curl do the posting of this data instead of your favorite browser, you have to read the HTML source of the form page and find @@ -370,7 +375,7 @@ the names of the input fields. In our example, the input field names are curl -F "file=@cooltext.txt" -F "yourname=Daniel" -F "filedescription=Cool text file with cool text inside" - http://www.post.com/postit.cgi + https://www.example.com/postit.cgi To send two files in one post you can do it in two ways: @@ -396,18 +401,18 @@ used on the command line. It is especially useful to fool or trick stupid servers or CGI scripts that rely on that information being available or contain certain data. - curl -e www.coolsite.com http://www.showme.com/ + curl -e www.example.org https://www.example.com/ ## User Agent An HTTP request has the option to include information about the browser that -generated the request. Curl allows it to be specified on the command line. It +generated the request. curl allows it to be specified on the command line. It is especially useful to fool or trick stupid servers or CGI scripts that only accept certain browsers. Example: - curl -A 'Mozilla/3.0 (Win95; I)' http://www.nationsbank.com/ + curl -A 'Mozilla/3.0 (Win95; I)' https://www.bank.example.com/ Other common strings: @@ -448,9 +453,9 @@ path beginning with `/foo`. Example, get a page that wants my name passed in a cookie: - curl -b "name=Daniel" www.sillypage.com + curl -b "name=Daniel" www.example.com -Curl also has the ability to use previously received cookies in following +curl also has the ability to use previously received cookies in following sessions. If you get cookies from a server and store them in a file in a manner similar to: @@ -476,11 +481,11 @@ non-existing file to trigger the cookie awareness like: curl -L -b empty.txt www.example.com The file to read cookies from must be formatted using plain HTTP headers OR as -Netscape's cookie file. Curl will determine what kind it is based on the file -contents. In the above command, curl will parse the header and store the -cookies received from www.example.com. curl will send to the server the stored -cookies which match the request as it follows the location. The file -`empty.txt` may be a nonexistent file. +Netscape's cookie file. curl determines what kind it is based on the file +contents. In the above command, curl parses the header and store the cookies +received from www.example.com. curl sends the stored cookies which match the +request to the server as it follows the location. The file `empty.txt` may be +a nonexistent file. To read and write cookies from a Netscape cookie file, you can set both `-b` and `-c` to use the same file: @@ -498,26 +503,26 @@ happening. The different fields in the output have the following meaning: From left-to-right: - - `%` - percentage completed of the whole transfer - - `Total` - total size of the whole expected transfer - - `%` - percentage completed of the download - - `Received` - currently downloaded amount of bytes - - `%` - percentage completed of the upload - - `Xferd` - currently uploaded amount of bytes - - `Average Speed Dload` - the average transfer speed of the download - - `Average Speed Upload` - the average transfer speed of the upload - - `Time Total` - expected time to complete the operation - - `Time Current` - time passed since the invoke - - `Time Left` - expected time left to completion - - `Curr.Speed` - the average transfer speed the last 5 seconds (the first +- `%` - percentage completed of the whole transfer +- `Total` - total size of the whole expected transfer +- `%` - percentage completed of the download +- `Received` - currently downloaded amount of bytes +- `%` - percentage completed of the upload +- `Xferd` - currently uploaded amount of bytes +- `Average Speed Dload` - the average transfer speed of the download +- `Average Speed Upload` - the average transfer speed of the upload +- `Time Total` - expected time to complete the operation +- `Time Current` - time passed since the invoke +- `Time Left` - expected time left to completion +- `Curr.Speed` - the average transfer speed the last 5 seconds (the first 5 seconds of a transfer is based on less time of course.) -The `-#` option will display a totally different progress bar that does not -need much explanation! +The `-#` option displays a totally different progress bar that does not need +much explanation! ## Speed Limit -Curl allows the user to set the transfer speed conditions that must be met to +curl allows the user to set the transfer speed conditions that must be met to let the transfer keep going. By using the switch `-y` and `-Y` you can make curl abort transfers if the transfer speed is below the specified lowest limit for a specified time. @@ -525,12 +530,12 @@ for a specified time. To have curl abort the download if the speed is slower than 3000 bytes per second for 1 minute, run: - curl -Y 3000 -y 60 www.far-away-site.com + curl -Y 3000 -y 60 www.far-away.example.com This can be used in combination with the overall time limit, so that the above operation must be completed in whole within 30 minutes: - curl -m 1800 -Y 3000 -y 60 www.far-away-site.com + curl -m 1800 -Y 3000 -y 60 www.far-away.example.com Forcing curl not to transfer data faster than a given rate is also possible, which might be useful if you are using a limited bandwidth connection and you @@ -539,25 +544,25 @@ do not want your transfer to use all of it (sometimes referred to as Make curl transfer data no faster than 10 kilobytes per second: - curl --limit-rate 10K www.far-away-site.com + curl --limit-rate 10K www.far-away.example.com or - curl --limit-rate 10240 www.far-away-site.com + curl --limit-rate 10240 www.far-away.example.com Or prevent curl from uploading data faster than 1 megabyte per second: - curl -T upload --limit-rate 1M ftp://uploadshereplease.com + curl -T upload --limit-rate 1M ftp://uploads.example.com When using the `--limit-rate` option, the transfer rate is regulated on a -per-second basis, which will cause the total transfer speed to become lower -than the given number. Sometimes of course substantially lower, if your -transfer stalls during periods. +per-second basis, which causes the total transfer speed to become lower than +the given number. Sometimes of course substantially lower, if your transfer +stalls during periods. ## Config File -Curl automatically tries to read the `.curlrc` file (or `_curlrc` file on -Microsoft Windows systems) from the user's home dir on startup. +curl automatically tries to read the `.curlrc` file (or `_curlrc` file on +Microsoft Windows systems) from the user's home directory on startup. The config file could be made up with normal command line switches, but you can also specify the long options without the dashes to make it more @@ -576,7 +581,7 @@ Example, set default time out and proxy in a config file: # We want a 30 minute timeout: -m 1800 # ... and we use a proxy for all accesses: - proxy = proxy.our.domain.com:8080 + proxy = proxy.our.domain.example.com:8080 Whitespaces ARE significant at the end of lines, but all whitespace leading up to the first characters of each line are ignored. @@ -584,31 +589,31 @@ up to the first characters of each line are ignored. Prevent curl from reading the default file by using -q as the first command line parameter, like: - curl -q www.thatsite.com + curl -q www.example.org Force curl to get and display a local help page in case it is invoked without URL by making a config file similar to: - # default url to get - url = "http://help.with.curl.com/curlhelp.html" + # default URL to get + url = "https://help.with.curl.example.com/curlhelp.html" You can specify another config file to be read by using the `-K`/`--config` -flag. If you set config file name to `-` it will read the config from stdin, -which can be handy if you want to hide options from being visible in process -tables etc: +flag. If you set config filename to `-` it reads the config from stdin, which +can be handy if you want to hide options from being visible in process tables +etc: - echo "user = user:passwd" | curl -K - http://that.secret.site.com + echo "user = user:passwd" | curl -K - https://that.secret.example.com ## Extra Headers When using curl in your own programs, you may end up needing to pass on your -own custom headers when getting a web page. You can do this by using the `-H` +own custom headers when getting a webpage. You can do this by using the `-H` flag. Example, send the header `X-you-and-me: yes` to the server when getting a page: - curl -H "X-you-and-me: yes" www.love.com + curl -H "X-you-and-me: yes" love.example.com This can also be useful in case you want curl to send a different text in a header than it normally does. The `-H` header you specify then replaces the @@ -616,7 +621,7 @@ header curl would normally send. If you replace an internal header with an empty one, you prevent that header from being sent. To prevent the `Host:` header from being used: - curl -H "Host:" www.server.com + curl -H "Host:" server.example.com ## FTP and Path Names @@ -624,14 +629,14 @@ Do note that when getting files with a `ftp://` URL, the given path is relative to the directory you enter. To get the file `README` from your home directory at your ftp site, do: - curl ftp://user:passwd@my.site.com/README + curl ftp://user:passwd@my.example.com/README If you want the README file from the root directory of that same site, you -need to specify the absolute file name: +need to specify the absolute filename: - curl ftp://user:passwd@my.site.com//README + curl ftp://user:passwd@my.example.com//README -(I.e with an extra slash in front of the file name.) +(I.e with an extra slash in front of the filename.) ## SFTP and SCP and Path Names @@ -652,10 +657,10 @@ to open another port and await another connection performed by the client. This is good if the client is behind a firewall that does not allow incoming connections. - curl ftp.download.com + curl ftp.example.com If the server, for example, is behind a firewall that does not allow -connections on ports other than 21 (or if it just does not support the `PASV` +connections on ports other than 21 (or if it does not support the `PASV` command), the other way to do it is to use the `PORT` command and instruct the server to connect to the client on the given IP number and port (as parameters to the PORT command). @@ -664,26 +669,26 @@ The `-P` flag to curl supports a few different options. Your machine may have several IP-addresses and/or network interfaces and curl allows you to select which of them to use. Default address can also be used: - curl -P - ftp.download.com + curl -P - ftp.example.com Download with `PORT` but use the IP address of our `le0` interface (this does not work on Windows): - curl -P le0 ftp.download.com + curl -P le0 ftp.example.com Download with `PORT` but use 192.168.0.10 as our IP address to use: - curl -P 192.168.0.10 ftp.download.com + curl -P 192.168.0.10 ftp.example.com ## Network Interface -Get a web page from a server using a specified port for the interface: +Get a webpage from a server using a specified port for the interface: - curl --interface eth0:1 http://www.example.com/ + curl --interface eth0:1 https://www.example.com/ or - curl --interface 192.168.1.10 http://www.example.com/ + curl --interface 192.168.1.10 https://www.example.com/ ## HTTPS @@ -693,7 +698,7 @@ using the HTTPS protocol. Example: - curl https://www.secure-site.com + curl https://secure.example.com curl is also capable of using client certificates to get/post files from sites that require valid certificates. The only drawback is that the certificate @@ -706,18 +711,18 @@ formatted certificates to PEM formatted ones. Example on how to automatically retrieve a document using a certificate with a personal password: - curl -E /path/to/cert.pem:password https://secure.site.com/ + curl -E /path/to/cert.pem:password https://secure.example.com/ -If you neglect to specify the password on the command line, you will be -prompted for the correct password before any data can be received. +If you neglect to specify the password on the command line, you are prompted +for the correct password before any data can be received. Many older HTTPS servers have problems with specific SSL or TLS versions, which newer versions of OpenSSL etc use, therefore it is sometimes useful to specify what TLS version curl should use.: - curl --tlv1.0 https://secure.site.com/ + curl --tlv1.0 https://secure.example.com/ -Otherwise, curl will attempt to use a sensible TLS default version. +Otherwise, curl attempts to use a sensible TLS default version. ## Resuming File Transfers @@ -726,15 +731,15 @@ resume on HTTP(S) downloads as well as FTP uploads and downloads. Continue downloading a document: - curl -C - -o file ftp://ftp.server.com/path/file + curl -C - -o file ftp://ftp.example.com/path/file Continue uploading a document: - curl -C - -T file ftp://ftp.server.com/path/file + curl -C - -T file ftp://ftp.example.com/path/file Continue downloading a document from a web server - curl -C - -o file http://www.server.com/ + curl -C - -o file https://www.example.com/ ## Time Conditions @@ -745,17 +750,17 @@ them with the `-z`/`--time-cond` flag. For example, you can easily make a download that only gets performed if the remote file is newer than a local copy. It would be made like: - curl -z local.html http://remote.server.com/remote.html + curl -z local.html https://remote.example.com/remote.html Or you can download a file only if the local file is newer than the remote one. Do this by prepending the date string with a `-`, as in: - curl -z -local.html http://remote.server.com/remote.html + curl -z -local.html https://remote.example.com/remote.html You can specify a plain text date as condition. Tell curl to only download the file if it was updated since January 12, 2012: - curl -z "Jan 12 2012" http://remote.server.com/remote.html + curl -z "Jan 12 2012" https://remote.example.com/remote.html curl accepts a wide range of date formats. You always make the date check the other way around by prepending it with a dash (`-`). @@ -784,11 +789,11 @@ Authentication support is still missing ## LDAP If you have installed the OpenLDAP library, curl can take advantage of it and -offer `ldap://` support. On Windows, curl will use WinLDAP from Platform SDK -by default. +offer `ldap://` support. On Windows, curl uses WinLDAP from Platform SDK by +default. -Default protocol version used by curl is LDAP version 3. Version 2 will be -used as a fallback mechanism in case version 3 fails to connect. +Default protocol version used by curl is LDAP version 3. Version 2 is used as +a fallback mechanism in case version 3 fails to connect. LDAP is a complex thing and writing an LDAP query is not an easy task. Familiarize yourself with the exact syntax description elsewhere. One @@ -798,25 +803,25 @@ Format](https://curl.se/rfc/rfc2255.txt) To show you an example, this is how to get all people from an LDAP server that has a certain subdomain in their email address: - curl -B "ldap://ldap.frontec.se/o=frontec??sub?mail=*sth.frontec.se" + curl -B "ldap://ldap.example.com/o=frontec??sub?mail=*sth.example.com" You also can use authentication when accessing LDAP catalog: - curl -u user:passwd "ldap://ldap.frontec.se/o=frontec??sub?mail=*" - curl "ldap://user:passwd@ldap.frontec.se/o=frontec??sub?mail=*" + curl -u user:passwd "ldap://ldap.example.com/o=frontec??sub?mail=*" + curl "ldap://user:passwd@ldap.example.com/o=frontec??sub?mail=*" -By default, if user and password are provided, OpenLDAP/WinLDAP will use basic +By default, if user and password are provided, OpenLDAP/WinLDAP uses basic authentication. On Windows you can control this behavior by providing one of `--basic`, `--ntlm` or `--digest` option in curl command line - curl --ntlm "ldap://user:passwd@ldap.frontec.se/o=frontec??sub?mail=*" + curl --ntlm "ldap://user:passwd@ldap.example.com/o=frontec??sub?mail=*" -On Windows, if no user/password specified, auto-negotiation mechanism will be -used with current logon credentials (SSPI/SPNEGO). +On Windows, if no user/password specified, auto-negotiation mechanism is used +with current logon credentials (SSPI/SPNEGO). ## Environment Variables -Curl reads and understands the following environment variables: +curl reads and understands the following proxy related environment variables: http_proxy, HTTPS_PROXY, FTP_PROXY @@ -825,17 +830,17 @@ with ALL_PROXY -A comma-separated list of host names that should not go through any proxy is +A comma-separated list of hostnames that should not go through any proxy is set in (only an asterisk, `*` matches all hosts) NO_PROXY -If the host name matches one of these strings, or the host is within the -domain of one of these strings, transactions with that node will not be done -over proxy. When a domain is used, it needs to start with a period. A user can +If the hostname matches one of these strings, or the host is within the domain +of one of these strings, transactions with that node is not done over the +proxy. When a domain is used, it needs to start with a period. A user can specify that both www.example.com and foo.example.com should not use a proxy by setting `NO_PROXY` to `.example.com`. By including the full name you can -exclude specific host names, so to make `www.example.com` not use a proxy but +exclude specific hostnames, so to make `www.example.com` not use a proxy but still have `foo.example.com` do it, set `NO_PROXY` to `www.example.com`. The usage of the `-x`/`--proxy` flag overrides the environment variables. @@ -846,12 +851,12 @@ Unix introduced the `.netrc` concept a long time ago. It is a way for a user to specify name and password for commonly visited FTP sites in a file so that you do not have to type them in each time you visit those sites. You realize this is a big security risk if someone else gets hold of your passwords, -therefore most Unix programs will not read this file unless it is only readable +therefore most Unix programs do not read this file unless it is only readable by yourself (curl does not care though). -Curl supports `.netrc` files if told to (using the `-n`/`--netrc` and -`--netrc-optional` options). This is not restricted to just FTP, so curl can -use it for all protocols where authentication is used. +curl supports `.netrc` files if told to (using the `-n`/`--netrc` and +`--netrc-optional` options). This is not restricted to FTP, so curl can use it +for all protocols where authentication is used. A simple `.netrc` file could look something like: @@ -866,31 +871,31 @@ information from the previous transfer you want to extract. To display the amount of bytes downloaded together with some text and an ending newline: - curl -w 'We downloaded %{size_download} bytes\n' www.download.com + curl -w 'We downloaded %{size_download} bytes\n' www.example.com ## Kerberos FTP Transfer -Curl supports kerberos4 and kerberos5/GSSAPI for FTP transfers. You need the +curl supports kerberos4 and kerberos5/GSSAPI for FTP transfers. You need the kerberos package installed and used at curl build time for it to be available. First, get the krb-ticket the normal way, like with the `kinit`/`kauth` tool. Then use curl in way similar to: - curl --krb private ftp://krb4site.com -u username:fakepwd + curl --krb private ftp://krb4site.example.com -u username:fakepwd -There is no use for a password on the `-u` switch, but a blank one will make -curl ask for one and you already entered the real password to `kinit`/`kauth`. +There is no use for a password on the `-u` switch, but a blank one makes curl +ask for one and you already entered the real password to `kinit`/`kauth`. ## TELNET -The curl telnet support is basic and easy to use. Curl passes all data passed +The curl telnet support is basic and easy to use. curl passes all data passed to it on stdin to the remote server. Connect to a remote telnet server using a command line similar to: - curl telnet://remote.server.com + curl telnet://remote.example.com -And enter the data to pass to the server on stdin. The result will be sent to -stdout or to the file you specify with `-o`. +Enter the data to pass to the server on stdin. The result is sent to stdout or +to the file you specify with `-o`. You might want the `-N`/`--no-buffer` option to switch off the buffered output for slow connections or similar. @@ -898,12 +903,12 @@ for slow connections or similar. Pass options to the telnet protocol negotiation, by using the `-t` option. To tell the server we use a vt100 terminal, try something like: - curl -tTTYPE=vt100 telnet://remote.server.com + curl -tTTYPE=vt100 telnet://remote.example.com Other interesting options for it `-t` include: - - `XDISPLOC=` Sets the X display location. - - `NEW_ENV=` Sets an environment variable. +- `XDISPLOC=` Sets the X display location. +- `NEW_ENV=` Sets an environment variable. NOTE: The telnet protocol does not specify any way to login with a specified user and password so curl cannot do that automatically. To do that, you need to @@ -912,47 +917,46 @@ accordingly. ## Persistent Connections -Specifying multiple files on a single command line will make curl transfer all -of them, one after the other in the specified order. +Specifying multiple files on a single command line makes curl transfer all of +them, one after the other in the specified order. -libcurl will attempt to use persistent connections for the transfers so that -the second transfer to the same host can use the same connection that was -already initiated and was left open in the previous transfer. This greatly -decreases connection time for all but the first transfer and it makes a far -better use of the network. +libcurl attempts to use persistent connections for the transfers so that the +second transfer to the same host can use the same connection that was already +initiated and was left open in the previous transfer. This greatly decreases +connection time for all but the first transfer and it makes a far better use +of the network. Note that curl cannot use persistent connections for transfers that are used in subsequent curl invokes. Try to stuff as many URLs as possible on the same -command line if they are using the same host, as that will make the transfers +command line if they are using the same host, as that makes the transfers faster. If you use an HTTP proxy for file transfers, practically all transfers -will be persistent. +are persistent. ## Multiple Transfers With A Single Command Line As is mentioned above, you can download multiple files with one command line -by simply adding more URLs. If you want those to get saved to a local file -instead of just printed to stdout, you need to add one save option for each -URL you specify. Note that this also goes for the `-O` option (but not +by adding more URLs. If you want those to get saved to a local file +instead of printed to stdout, you need to add one save option for each URL you +specify. Note that this also goes for the `-O` option (but not `--remote-name-all`). For example: get two files and use `-O` for the first and a custom file name for the second: - curl -O http://url.com/file.txt ftp://ftp.com/moo.exe -o moo.jpg + curl -O https://example.com/file.txt ftp://example.com/moo.exe -o moo.jpg You can also upload multiple files in a similar fashion: - curl -T local1 ftp://ftp.com/moo.exe -T local2 ftp://ftp.com/moo2.txt + curl -T local1 ftp://example.com/moo.exe -T local2 ftp://example.com/moo2.txt ## IPv6 -curl will connect to a server with IPv6 when a host lookup returns an IPv6 -address and fall back to IPv4 if the connection fails. The `--ipv4` and -`--ipv6` options can specify which address to use when both are -available. IPv6 addresses can also be specified directly in URLs using the -syntax: +curl connects to a server with IPv6 when a host lookup returns an IPv6 address +and fall back to IPv4 if the connection fails. The `--ipv4` and `--ipv6` +options can specify which address to use when both are available. IPv6 +addresses can also be specified directly in URLs using the syntax: - http://[2001:1890:1112:1::20]/overview.html + https://[2001:1890:1112:1::20]/overview.html When this style is used, the `-g` option must be given to stop curl from interpreting the square brackets as special globbing characters. Link local diff --git a/third-party/curl/docs/MQTT.md b/third-party/curl/docs/MQTT.md deleted file mode 100644 index 0f034f72e4..0000000000 --- a/third-party/curl/docs/MQTT.md +++ /dev/null @@ -1,27 +0,0 @@ -# MQTT in curl - -## Usage - -A plain "GET" subscribes to the topic and prints all published messages. -Doing a "POST" publishes the post data to the topic and exits. - -Example subscribe: - - curl mqtt://host/home/bedroom/temp - -Example publish: - - curl -d 75 mqtt://host/home/bedroom/dimmer - -## What does curl deliver as a response to a subscribe - -It outputs two bytes topic length (MSB | LSB), the topic followed by the -payload. - -## Caveats - -Remaining limitations: - - Only QoS level 0 is implemented for publish - - No way to set retain flag for publish - - No TLS (mqtts) support - - Naive EAGAIN handling will not handle split messages diff --git a/third-party/curl/docs/Makefile.am b/third-party/curl/docs/Makefile.am index 4220f121b6..fdc4511b5c 100644 --- a/third-party/curl/docs/Makefile.am +++ b/third-party/curl/docs/Makefile.am @@ -24,111 +24,133 @@ AUTOMAKE_OPTIONS = foreign no-dependencies -# EXTRA_DIST breaks with $(abs_builddir) so build it using this variable -# but distribute it (using the relative file name) in the next variable -man_MANS = $(abs_builddir)/curl.1 -noinst_man_MANS = curl.1 mk-ca-bundle.1 -dist_man_MANS = curl-config.1 -GENHTMLPAGES = curl.html curl-config.html mk-ca-bundle.html -PDFPAGES = curl.pdf curl-config.pdf mk-ca-bundle.pdf -MANDISTPAGES = curl.1.dist curl-config.1.dist +if BUILD_DOCS +# if we disable man page building, ignore these +MK_CA_DOCS = mk-ca-bundle.1 +CURLCONF_DOCS = curl-config.1 +man_MANS = curl-config.1 wcurl.1 +endif -HTMLPAGES = $(GENHTMLPAGES) +CURLPAGES = curl-config.md mk-ca-bundle.md wcurl.md runtests.md testcurl.md -# Build targets in this file (.) before cmdline-opts to ensure that -# the curl.1 rule below runs first -SUBDIRS = . cmdline-opts -DIST_SUBDIRS = $(SUBDIRS) examples libcurl +SUBDIRS = . cmdline-opts libcurl +DIST_SUBDIRS = $(SUBDIRS) examples -CLEANFILES = $(GENHTMLPAGES) $(PDFPAGES) $(MANDISTPAGES) curl.1 +if BUILD_DOCS +CLEANFILES = $(MK_CA_DOCS) $(man_MANS) +endif -EXTRA_DIST = \ - $(noinst_man_MANS) \ - ALTSVC.md \ - BINDINGS.md \ - BUFREF.md \ - BUG-BOUNTY.md \ - BUGS.md \ - CHECKSRC.md \ - CIPHERS.md \ - CMakeLists.txt \ - CODE_OF_CONDUCT.md \ - CODE_REVIEW.md \ - CODE_STYLE.md \ - CONNECTION-FILTERS.md \ - CONTRIBUTE.md \ - CURL-DISABLE.md \ - DEPRECATE.md \ - DYNBUF.md \ - EARLY-RELEASE.md \ - EXPERIMENTAL.md \ - FAQ \ - FEATURES.md \ - GOVERNANCE.md \ - HELP-US.md \ - HISTORY.md \ - HSTS.md \ - HTTP-COOKIES.md \ - HTTP2.md \ - HTTP3.md \ - HYPER.md \ - INSTALL \ - INSTALL.cmake \ - INSTALL.md \ - INTERNALS.md \ - KNOWN_BUGS \ - MAIL-ETIQUETTE \ - MQTT.md \ - NEW-PROTOCOL.md \ - options-in-versions \ - PARALLEL-TRANSFERS.md \ - README.md \ - RELEASE-PROCEDURE.md \ - RUSTLS.md \ - ROADMAP.md \ - SECURITY-ADVISORY.md \ - SECURITY-PROCESS.md \ - SSL-PROBLEMS.md \ - SSLCERTS.md \ - THANKS \ - TODO \ - TheArtOfHttpScripting.md \ - URL-SYNTAX.md \ - VERSIONS.md \ - WEBSOCKET.md +TESTDOCS = \ + tests/FILEFORMAT.md \ + tests/HTTP.md \ + tests/TEST-SUITE.md -MAN2HTML= roffit $< >$@ +INTERNALDOCS = \ + internals/BUFQ.md \ + internals/BUFREF.md \ + internals/CHECKSRC.md \ + internals/CLIENT-READERS.md \ + internals/CLIENT-WRITERS.md \ + internals/CODE_STYLE.md \ + internals/CONNECTION-FILTERS.md \ + internals/CREDENTIALS.md \ + internals/CURLX.md \ + internals/DYNBUF.md \ + internals/HASH.md \ + internals/LLIST.md \ + internals/MID.md \ + internals/MQTT.md \ + internals/MULTI-EV.md \ + internals/NEW-PROTOCOL.md \ + internals/PEERS.md \ + internals/PORTING.md \ + internals/RATELIMITS.md \ + internals/README.md \ + internals/SCORECARD.md \ + internals/SPLAY.md \ + internals/STRPARSE.md \ + internals/THRDPOOL-AND-QUEUE.md \ + internals/TIME-KEEPING.md \ + internals/TLS-SESSIONS.md \ + internals/UINT_SETS.md \ + internals/WEBSOCKET.md -SUFFIXES = .1 .html .pdf +EXTRA_DIST = \ + $(CURLPAGES) \ + $(INTERNALDOCS) \ + $(TESTDOCS) \ + ALTSVC.md \ + BINDINGS.md \ + BUG-BOUNTY.md \ + BUGS.md \ + CIPHERS.md \ + CIPHERS-TLS12.md \ + CMakeLists.txt \ + CODE_OF_CONDUCT.md \ + CODE_REVIEW.md \ + CONTRIBUTE.md \ + CURL-DISABLE.md \ + CURLDOWN.md \ + DEPRECATE.md \ + DISTROS.md \ + EARLY-RELEASE.md \ + ECH.md \ + EXPERIMENTAL.md \ + FAQ.md \ + FEATURES.md \ + GOVERNANCE.md \ + HELP-US.md \ + HISTORY.md \ + HSTS.md \ + HTTP-COOKIES.md \ + HTTP3.md \ + HTTPSRR.md \ + INFRASTRUCTURE.md \ + INSTALL \ + INSTALL-CMAKE.md \ + INSTALL.md \ + INTERNALS.md \ + IPFS.md \ + KNOWN_BUGS.md \ + KNOWN_RISKS.md \ + MAIL-ETIQUETTE.md \ + MANUAL.md \ + options-in-versions \ + README.md \ + RELEASE-PROCEDURE.md \ + RUSTLS.md \ + ROADMAP.md \ + SECURITY-ADVISORY.md \ + SPONSORS.md \ + SSL-PROBLEMS.md \ + SSLCERTS.md \ + THANKS \ + TODO.md \ + TheArtOfHttpScripting.md \ + URL-SYNTAX.md \ + VERIFY.md \ + VERSIONS.md \ + VULN-DISCLOSURE-POLICY.md -# $(abs_builddir) is to disable VPATH when searching for this file, which -# would otherwise find the copy in $(srcdir) which breaks the $(HUGE) -# rule in src/Makefile.am in out-of-tree builds that references the file in the -# build directory. -# -# First, seed the used copy of curl.1 with the prebuilt copy (in an out-of-tree -# build), then run make recursively to rebuild it only if its dependencies -# have changed. -$(abs_builddir)/curl.1: - if test "$(top_builddir)x" != "$(top_srcdir)x" -a -e "$(srcdir)/curl.1"; then \ - $(INSTALL_DATA) "$(srcdir)/curl.1" $@; fi - cd cmdline-opts && $(MAKE) +CD2NROFF = $(top_srcdir)/scripts/cd2nroff $< >$@ -html: $(HTMLPAGES) - cd libcurl && $(MAKE) html +CD2 = $(CD2_$(V)) +CD2_0 = @echo " RENDER " $@; +CD2_1 = +CD2_ = $(CD2_0) -pdf: $(PDFPAGES) - cd libcurl && $(MAKE) pdf +SUFFIXES = .1 .md -.1.html: - $(MAN2HTML) +all: $(MK_CA_DOCS) $(CURLCONF_DOCS) -.1.pdf: - @(foo=`echo $@ | sed -e 's/\.[0-9]$$//g'`; \ - groff -Tps -man $< >$$foo.ps; \ - ps2pdf $$foo.ps $@; \ - rm $$foo.ps; \ - echo "converted $< to $@") +.md.1: + $(CD2)$(CD2NROFF) + +curl-config.1: curl-config.md + +mk-ca-bundle.1: mk-ca-bundle.md + +wcurl.1: wcurl.md distclean: rm -f $(CLEANFILES) diff --git a/third-party/curl/docs/PARALLEL-TRANSFERS.md b/third-party/curl/docs/PARALLEL-TRANSFERS.md deleted file mode 100644 index 337fab5faa..0000000000 --- a/third-party/curl/docs/PARALLEL-TRANSFERS.md +++ /dev/null @@ -1,50 +0,0 @@ -# Parallel transfers - -curl 7.66.0 introduced support for doing multiple transfers simultaneously; in -parallel. - -## -Z, --parallel - -When this command line option is used, curl will perform the transfers given -to it at the same time. It will do up to `--parallel-max` concurrent -transfers, with a default value of 50. - -## Progress meter - -The progress meter that is displayed when doing parallel transfers is -completely different than the regular one used for each single transfer. - - It shows: - - o percent download (if known, which means *all* transfers need to have a - known size) - o percent upload (if known, with the same caveat as for download) - o total amount of downloaded data - o total amount of uploaded data - o number of transfers to perform - o number of concurrent transfers being transferred right now - o number of transfers queued up waiting to start - o total time all transfers are expected to take (if sizes are known) - o current time the transfers have spent so far - o estimated time left (if sizes are known) - o current transfer speed (the faster of upload/download speeds measured over - the last few seconds) - -Example: - - DL% UL% Dled Uled Xfers Live Qd Total Current Left Speed - 72 -- 37.9G 0 101 30 23 0:00:55 0:00:34 0:00:22 2752M - -## Behavior differences - -Connections are shared fine between different easy handles, but the -"authentication contexts" are not. So for example doing HTTP Digest auth with -one handle for a particular transfer and then continue on with another handle -that reuses the same connection, the second handle cannot send the necessary -Authorization header at once since the context is only kept in the original -easy handle. - -To fix this, the authorization state could be made possible to share with the -share API as well, as a context per origin + path (realm?) basically. - -Visible in test 153, 1412 and more. diff --git a/third-party/curl/docs/README.md b/third-party/curl/docs/README.md index b72d8bc454..22d96ea9bd 100644 --- a/third-party/curl/docs/README.md +++ b/third-party/curl/docs/README.md @@ -1,10 +1,16 @@ + + ![curl logo](https://curl.se/logo/curl-logo.svg) # Documentation -you will find a mix of various documentation in this directory and -subdirectories, using several different formats. Some of them are not ideal -for reading directly in your browser. +You find a mix of various documentation in this directory and subdirectories, +using several different formats. Some of them are not ideal for reading +directly in your browser. If you would rather see the rendered version of the documentation, check out the curl website's [documentation section](https://curl.se/docs/) for diff --git a/third-party/curl/docs/RELEASE-PROCEDURE.md b/third-party/curl/docs/RELEASE-PROCEDURE.md index 4ff8fcc516..e62a90cbd7 100644 --- a/third-party/curl/docs/RELEASE-PROCEDURE.md +++ b/third-party/curl/docs/RELEASE-PROCEDURE.md @@ -1,25 +1,26 @@ -curl release procedure - how to do a release -============================================ + -- run `./scripts/copyright.pl` and correct possible omissions +# curl release procedure - how to do a release + +## in the source code repo - edit `RELEASE-NOTES` to be accurate - update `docs/THANKS` +- update the "past releases" section in `docs/VERSIONS.md` + - make sure all relevant changes are committed on the master branch - tag the git repo in this style: `git tag -a curl-7_34_0`. -a annotates the tag and we use underscores instead of dots in the version number. Make sure the tag is GPG signed (using -s). -- run `./maketgz 7.34.0` to build the release tarballs. It is important that - you run this on a machine with the correct set of autotools etc installed - as this is what then will be shipped and used by most users on \*nix like - systems. +- run `./scripts/dmaketgz 7.34.0` to build the release tarballs. - push the git commits and the new tag @@ -27,13 +28,10 @@ in the source code repo - upload the 8 resulting files to the primary download directory -in the curl-www repo --------------------- +## in the curl-www repo - edit `Makefile` (version number and date), -- edit `_newslog.html` (announce the new release) and - - edit `_changes.html` (insert changes+bugfixes from RELEASE-NOTES) - commit all local changes @@ -44,27 +42,26 @@ in the curl-www repo (the website then updates its contents automatically) -on GitHub ---------- +## on GitHub - edit the newly made release tag so that it is listed as the latest release -inform ------- +## inform - send an email to curl-users, curl-announce and curl-library. Insert the RELEASE-NOTES into the mail. -celebrate ---------- +- if there are any advisories associated with the release, send each markdown + file to the above lists as well as to `oss-security@lists.openwall.com` + (unless the problem is unique to the non-open operating systems) + +## celebrate - suitable beverage intake is encouraged for the festivities -curl release scheduling -======================= +# curl release scheduling -Release Cycle -------------- +## Release Cycle We normally do releases every 8 weeks on Wednesdays. If important problems arise, we can insert releases outside the schedule or we can move the release @@ -89,8 +86,31 @@ of common public holidays or when the lead release manager is unavailable, the release date can be moved forwards or backwards a full week. This is then advertised well in advance. -Critical problems ------------------ +# Release Candidates + +We ship release candidate tarballs on three occasions in preparation for the +pending release: + +- Release candidate one (**rc1**) ships the same Saturday the feature freeze + starts. Twenty-five days before the release. Tagged like `rc-7_34_0-1`. + +- Release candidate two (**rc2**) ships nine days later, sixteen days before + the release. On a Monday. Tagged like `rc-7_34_0-2`. + +- Release candidate three (**rc3**) ships nine days later, seven days before + the release. On a Wednesday. Tagged like `rc-7_34_0-3`. + +Release candidate tarballs are ephemeral and each such tarball is only kept +around for a few weeks. They are provided on their dedicated webpage at: +https://curl.se/rc/ + +The git tags for release candidate are temporary and remain set only for a +limited period of time. + +**Do not use release candidates in production**. They are work in progress. +Use them for testing and verification only. Use actual releases in production. + +# Critical problems We can break the release cycle and do a patch release at any point if a critical enough problem is reported. There is no exact definition of how to @@ -101,17 +121,13 @@ qualify. If you think an issue qualifies, bring it to the curl-library mailing list and push for it. -Coming dates ------------- +# Coming dates -Based on the description above, here are some planned release dates (at the -time of this writing): +Based on the description above, here are some planned future release dates: -- July 19, 2023 -- September 13, 2023 -- November 8, 2023 -- January 3, 2024 -- February 28, 2024 -- April 24, 2024 -- June 19, 2024 -- August 14, 2024 +- June 24, 2026 +- September 2, 2026 +- October 28, 2026 +- December 23, 2026 +- February 17, 2027 +- April 14, 2027 diff --git a/third-party/curl/docs/ROADMAP.md b/third-party/curl/docs/ROADMAP.md index 4642938348..abf306b335 100644 --- a/third-party/curl/docs/ROADMAP.md +++ b/third-party/curl/docs/ROADMAP.md @@ -1,24 +1,17 @@ + + # curl the next few years - perhaps Roadmap of things Daniel Stenberg wants to work on next. It is intended to serve as a guideline for others for information, feedback and possible participation. -## "Complete" the HTTP/3 support +## WebSocket -curl has experimental support for HTTP/3 since a good while back. There are -some functionality missing and once the final specs are published we want to -eventually remove the "experimental" label from this functionality. +Agree that it is a good enough API and remove the EXPERIMENTAL label. -## HTTPS DNS records - -As a DNS version of alt-svc and also a pre-requisite for ECH (see below). - -See: https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-svcb-https-02 - -## ECH (Encrypted Client Hello - formerly known as ESNI) - - See Daniel's post on [Support of Encrypted - SNI](https://curl.se/mail/lib-2019-03/0000.html) on the mailing list. - - Initial work exists in [PR 4011](https://github.com/curl/curl/pull/4011) +## diff --git a/third-party/curl/docs/RUSTLS.md b/third-party/curl/docs/RUSTLS.md index 7a0d806b62..ed032f7fb6 100644 --- a/third-party/curl/docs/RUSTLS.md +++ b/third-party/curl/docs/RUSTLS.md @@ -1,26 +1,85 @@ + + # Rustls -[Rustls is a TLS backend written in Rust](https://docs.rs/rustls/). Curl can +[Rustls is a TLS backend written in Rust](https://docs.rs/rustls/). curl can be built to use it as an alternative to OpenSSL or other TLS backends. We use -the [rustls-ffi C bindings](https://github.com/rustls/rustls-ffi/). This -version of curl depends on version v0.10.0 of rustls-ffi. +the [rustls-ffi C bindings](https://github.com/rustls/rustls-ffi). This +version of curl is compatible with `rustls-ffi` v0.15.x. -# Building with rustls +## Getting rustls-ffi -First, [install Rust](https://rustup.rs/). +To build `curl` with `rustls` support you need to have `rustls-ffi` available first. +There are three options for this: -Next, check out, build, and install the appropriate version of rustls-ffi: +1. Install it from your package manager, if available. +2. Download pre-built binaries. +3. Build it from source. - % cargo install cbindgen - % git clone https://github.com/rustls/rustls-ffi -b v0.10.0 - % cd rustls-ffi +### Installing rustls-ffi from a package manager + +See the [rustls-ffi README] for packaging status. Availability and details for installation +differ between distributions. + +Once installed, build `curl` using `--with-rustls`. + + % git clone --depth 1 https://github.com/curl/curl + % cd curl + % autoreconf -fi + % ./configure --with-rustls % make - % make DESTDIR=${HOME}/rustls-ffi-built/ install -Now configure and build curl with rustls: +[rustls-ffi README]: https://github.com/rustls/rustls-ffi?tab=readme-ov-file - % git clone https://github.com/curl/curl +### Downloading pre-built rustls-ffi binaries + +Pre-built binaries are available on the [releases page] on GitHub for releases since 0.15.0. +Download the appropriate archive for your platform and extract it to a directory of your choice +(e.g. `${HOME}/rustls-ffi-built`). + +Once downloaded, build `curl` using `--with-rustls` and the path to the extracted binaries. + + % git clone --depth 1 https://github.com/curl/curl % cd curl % autoreconf -fi % ./configure --with-rustls=${HOME}/rustls-ffi-built % make + +[releases page]: https://github.com/rustls/rustls-ffi/releases + +### Building rustls-ffi from source + +Building `rustls-ffi` from source requires both a rust compiler, and the [cargo-c] cargo plugin. + +To install a Rust compiler, use [rustup] or your package manager to install +the **1.73** or newer toolchain. + +To install `cargo-c`, use your [package manager][cargo-c pkg], download +[a pre-built archive][cargo-c prebuilt], or build it from source with `cargo install cargo-c`. + +Next, check out, build, and install the appropriate version of `rustls-ffi` using `cargo`: + + % git clone --depth 1 --branch v0.15.3 https://github.com/rustls/rustls-ffi + % cd rustls-ffi + % cargo capi install --release --prefix=${HOME}/rustls-ffi-built + +Now configure and build `curl` using `--with-rustls`: + + % git clone --depth 1 https://github.com/curl/curl + % cd curl + % autoreconf -fi + % ./configure --with-rustls=${HOME}/rustls-ffi-built + % make + +See the [rustls-ffi README][cryptography provider] for more information on cryptography providers and +their build/platform requirements. + +[cargo-c]: https://github.com/lu-zero/cargo-c +[rustup]: https://rustup.rs/ +[cargo-c pkg]: https://github.com/lu-zero/cargo-c?tab=readme-ov-file#availability +[cargo-c prebuilt]: https://github.com/lu-zero/cargo-c/releases +[cryptography provider]: https://github.com/cpu/rustls-ffi?tab=readme-ov-file#cryptography-provider diff --git a/third-party/curl/docs/SECURITY-ADVISORY.md b/third-party/curl/docs/SECURITY-ADVISORY.md index 0ddc38b90d..34c342509d 100644 --- a/third-party/curl/docs/SECURITY-ADVISORY.md +++ b/third-party/curl/docs/SECURITY-ADVISORY.md @@ -1,10 +1,19 @@ + + # Anatomy of a curl security advisory -As described in the [Security Process](https://curl.se/dev/secprocess.html) -document, when a security vulnerability has been reported to the project and -confirmed, we author an advisory document for the issue. It should ideally -be written in cooperation with the reporter to make sure all the angles and -details of the problem are gathered and described correctly and succinctly. +As described in the [vulnerability disclosure +policy](https://curl.se/dev/vuln-disclosure.html), when a vulnerability has +been reported to the project and and it has been confirmed by the team, we +author an advisory document for the issue. + +

This advisory document should ideally be written in cooperation with the +reporter to make sure all the angles and details of the problem are gathered +and described correctly and succinctly. ## New document @@ -25,17 +34,26 @@ in the same directory. It holds a large array with all published curl vulnerabilities. All fields should be filled in accordingly, separated by a pipe character (`|`). -The eleven fields for each CVE in `vuln.pm` are, in order: +The fields for every CVE in `vuln.pm` are, in order: - HTML page name, first vulnerable version, last vulnerable version, name of - the issue, CVE Id, announce date (`YYYYMMDD`), report to the project date - (`YYYYMMDD`), CWE, awarded reward amount (USD), area (single word), C-issue - (`-` if not a C issue at all, `OVERFLOW` , `OVERREAD`, `DOUBLE_FREE`, - `USE_AFTER_FREE`, `NULL_MISTAKE`, `UNINIT`) +1. HTML page name +2. first vulnerable version +3. last vulnerable version +4. name of the issue +5. CVE Id +6. announce date (`YYYYMMDD`) +7. report to the project date (`YYYYMMDD`) +8. CWE +9. awarded reward amount (USD) +10. area (single word) +11. C-issue (`-` if not a C issue at all, `OVERFLOW` , `OVERREAD`, `DOUBLE_FREE`, `USE_AFTER_FREE`, `NULL_MISTAKE`, `UNINIT`, `BAD_FREE`) +12. affected components: `both`, `lib` or `tool` +13. severity: `low`, `medium`, `high` or `critical` +14. URL to the initial report (often on HackerOne) ### `Makefile` -The new CVE web page file name needs to be added in the `Makefile`'s `CVELIST` +The new CVE webpage filename needs to be added in the `Makefile`'s `CVELIST` macro. When the markdown is in place and the `Makefile` and `vuln.pm` are updated, @@ -44,12 +62,12 @@ generated automatically using those files. ## Document format -The easy way is to start with a recent previously published advisory and just -blank out old texts and save it using a new name. Save the subtitles and -general layout. +The easy way is to start with a recent previously published advisory and blank +out old texts and save it using a new name. Save the subtitles and general +layout. -Some details and metadata will be extracted from this document so it is -important to stick to the existing format. +Some details and metadata are extracted from this document so it is important +to stick to the existing format. The first list must be the title of the issue. diff --git a/third-party/curl/docs/SECURITY-PROCESS.md b/third-party/curl/docs/SECURITY-PROCESS.md deleted file mode 100644 index a4cda248cf..0000000000 --- a/third-party/curl/docs/SECURITY-PROCESS.md +++ /dev/null @@ -1,285 +0,0 @@ -# curl security process - -This document describes how security vulnerabilities should be handled in the -curl project. - -## Publishing Information - -All known and public curl or libcurl related vulnerabilities are listed on -[the curl website security page](https://curl.se/docs/security.html). - -Security vulnerabilities **should not** be entered in the project's public bug -tracker. - -## Vulnerability Handling - -The typical process for handling a new security vulnerability is as follows. - -No information should be made public about a vulnerability until it is -formally announced at the end of this process. That means, for example, that a -bug tracker entry must NOT be created to track the issue since that will make -the issue public and it should not be discussed on any of the project's public -mailing lists. Messages associated with any commits should not make any -reference to the security nature of the commit if done prior to the public -announcement. - -- The person discovering the issue, the reporter, reports the vulnerability on - [HackerOne](https://hackerone.com/curl). Issues filed there reach a handful - of selected and trusted people. - -- Messages that do not relate to the reporting or managing of an undisclosed - security vulnerability in curl or libcurl are ignored and no further action - is required. - -- A person in the security team responds to the original report to acknowledge - that a human has seen the report. - -- The security team investigates the report and either rejects it or accepts - it. See below for examples of problems that are not considered - vulnerabilities. - -- If the report is rejected, the team writes to the reporter to explain why. - -- If the report is accepted, the team writes to the reporter to let them - know it is accepted and that they are working on a fix. - -- The security team discusses the problem, works out a fix, considers the - impact of the problem and suggests a release schedule. This discussion - should involve the reporter as much as possible. - -- The release of the information should be "as soon as possible" and is most - often synchronized with an upcoming release that contains the fix. If the - reporter, or anyone else involved, thinks the next planned release is too - far away, then a separate earlier release should be considered. - -- Write a security advisory draft about the problem that explains what the - problem is, its impact, which versions it affects, solutions or workarounds, - when the release is out and make sure to credit all contributors properly. - Figure out the CWE (Common Weakness Enumeration) number for the flaw. See - [SECURITY-ADVISORY](https://curl.se/dev/advisory.html) for help on creating - the advisory. - -- Request a CVE number from - [HackerOne](https://docs.hackerone.com/programs/cve-requests.html) - -- Update the "security advisory" with the CVE number. - -- The security team commits the fix in a private branch. The commit message - should ideally contain the CVE number. If the severity level of the issue is - set to Low or Medium, the fix is allowed to get merged into the master - repository via a normal PR - but without mentioning it being a security - vulnerability. - -- The monetary reward part of the bug-bounty is managed by the Internet Bug - Bounty team and the reporter is asked to request the reward from them after - the issue has been completely handled and published by curl. - -- No more than 10 days before release, inform - [distros@openwall](https://oss-security.openwall.org/wiki/mailing-lists/distros) - to prepare them about the upcoming public security vulnerability - announcement - attach the advisory draft for information with CVE and - current patch. 'distros' does not accept an embargo longer than 14 days and - they do not care for Windows-specific flaws. - -- No more than 48 hours before the release, the private branch is merged into - the master branch and pushed. Once pushed, the information is accessible to - the public and the actual release should follow suit immediately afterwards. - The time between the push and the release is used for final tests and - reviews. - -- The project team creates a release that includes the fix. - -- The project team announces the release and the vulnerability to the world in - the same manner we always announce releases. It gets sent to the - curl-announce, curl-library and curl-users mailing lists. - -- The security web page on the website should get the new vulnerability - mentioned. - -## security (at curl dot se) - -This is a private mailing list for discussions on and about curl security -issues. - -Who is on this list? There are a couple of criteria you must meet, and then we -might ask you to join the list or you can ask to join it. It really is not a -formal process. We basically only require that you have a long-term presence -in the curl project and you have shown an understanding for the project and -its way of working. You must have been around for a good while and you should -have no plans of vanishing in the near future. - -We do not make the list of participants public mostly because it tends to vary -somewhat over time and a list somewhere will only risk getting outdated. - -## Publishing Security Advisories - -1. Write up the security advisory, using markdown syntax. Use the same - subtitles as last time to maintain consistency. - -2. Name the advisory file after the allocated CVE id. - -3. Add a line on the top of the array in `curl-www/docs/vuln.pm`. - -4. Put the new advisory markdown file in the `curl-www/docs/` directory. Add it - to the git repository. - -5. Run `make` in your local web checkout and verify that things look fine. - -6. On security advisory release day, push the changes on the curl-www - repository's remote master branch. - -## HackerOne - -Request the issue to be disclosed. If there are sensitive details present in -the report and discussion, those should be redacted from the disclosure. The -default policy is to disclose as much as possible as soon as the vulnerability -has been published. - -## Bug Bounty - -See [BUG-BOUNTY](https://curl.se/docs/bugbounty.html) for details on the -bug bounty program. - -# Severity levels - -The curl project's security team rates security problems using four severity -levels depending how serious we consider the problem to be. We use **Low**, -**Medium**, **High** and **Critical**. We refrain from using numerical scoring -of vulnerabilities. - -When deciding severity level on a particular issue, we take all the factors -into account: attack vector, attack complexity, required privileges, necessary -build configuration, protocols involved, platform specifics and also what -effects a possible exploit or trigger of the issue can lead do, including -confidentiality, integrity or availability problems. - -## Low - -This is a security problem that is truly hard or unlikely to exploit or -trigger. Due to timing, platform requirements or the fact that options or -protocols involved are rare etc. [Past -example](https://curl.se/docs/CVE-2022-43552.html) - -## Medium - -This is a security problem that is less hard than **Low** to exploit or -trigger. Less strict timing, wider platforms availability or involving more -widely used options or protocols. A problem that usually needs something else -to also happen to become serious. [Past -example](https://curl.se/docs/CVE-2022-32206.html) - -## High - -This issue in itself a serious problem with real world impact. Flaws that can -easily compromise the confidentiality, integrity or availability of resources. -Exploiting or triggering this problem is not hard. [Past -example](https://curl.se/docs/CVE-2019-3822.html) - -## Critical - -Easily exploitable by a remote unauthenticated attacker and lead to system -compromise (arbitrary code execution) without requiring user interaction, with -a common configuration on a popular platform. This issue has few restrictions -and requirements and can be exploited easily using most curl configurations. -[Past example](https://curl.se/docs/CVE-2000-0973.html) - -# Not security issues - -This is an incomplete list of issues that are not considered vulnerabilities. - -## Small memory leaks - -We do not consider a small memory leak a security problem; even if the amount -of allocated memory grows by a small amount every now and then. Long-living -applications and services already need to have counter-measures and deal with -growing memory usage, be it leaks or just increased use. A small memory or -resource leak is then expected to *not* cause a security problem. - -Of course there can be a discussion if a leak is small or not. A large leak -can be considered a security problem due to the DOS risk. If leaked memory -contains sensitive data it might also qualify as a security problem. - -## Never-ending transfers - -We do not consider flaws that cause a transfer to never end to be a security -problem. There are already several benign and likely reasons for transfers to -stall and never end, so applications that cannot deal with never-ending -transfers already need to have counter-measures established. - -If the problem avoids the regular counter-measures when it causes a never- -ending transfer, it might be a security problem. - -## Not practically possible - -If the flaw or vulnerability cannot practically get executed on existing -hardware it is not a security problem. - -## API misuse - -If a reported issue only triggers by an application using the API in a way -that is not documented to work or even documented to not work, it is probably -not going to be considered a security problem. We only guarantee secure and -proper functionality when the APIs are used as expected and documented. - -There can be a discussion about what the documentation actually means and how -to interpret the text, which might end up with us still agreeing that it is a -security problem. - -## Local attackers already present - -When an issue can only be attacked or misused by an attacker present on the -local system or network, the bar is raised. If a local user wrongfully has -elevated rights on your system enough to attack curl, they can probably -already do much worse harm and the problem is not really in curl. - -## Experiments - -Vulnerabilities in features which are off by default (in the build) and -documented as experimental, are not eligible for a reward and we do not -consider them security problems. - -## URL inconsistencies - -URL parser inconsistencies between browsers and curl are expected and are not -considered security vulnerabilities. The WHATWG URL Specification and RFC -3986+ (the plus meaning that it is an extended version) [are not completely -interoperable](https://github.com/bagder/docs/blob/master/URL-interop.md). - -Obvious parser bugs can still be vulnerabilities of course. - -## Visible command line arguments - -The curl command blanks the contents of a number of command line arguments to -prevent them from appearing in process listings. It does not blank all -arguments even if some of them that are not blanked might contain sensitive -data. We consider this functionality a best-effort and omissions are not -security vulnerabilities. - - - not all systems allow the arguments to be blanked in the first place - - since curl blanks the argument itself they will be readable for a short - moment no matter what - - virtually every argument can contain sensitive data, depending on use - - blanking all arguments would make it impractical for users to differentiate - curl command lines in process listings - -## Busy-loops - -Busy-loops that consume 100% CPU time but eventually end (perhaps due to a set -timeout value or otherwise) are not considered security problems. Applications -are supposed to already handle situations when the transfer loop legitimately -consumes 100% CPU time, so while a prolonged such busy-loop is a nasty bug, we -do not consider it a security problem. - -## Saving files - -curl cannot protect against attacks where an attacker has write access to the -same directory where curl is directed to save files. - -## Tricking a user to run a command line - -A creative, misleading or funny looking command line is not a security -problem. The curl command line tool takes options and URLs on the command line -and if an attacker can trick the user to run a specifically crafted curl -command line, all bets are off. Such an attacker can just as well have the -user run a much worse command that can do something fatal (like -`sudo rm -rf /`). diff --git a/third-party/curl/docs/SPONSORS.md b/third-party/curl/docs/SPONSORS.md new file mode 100644 index 0000000000..dc9d26fe6b --- /dev/null +++ b/third-party/curl/docs/SPONSORS.md @@ -0,0 +1,55 @@ + + +# curl sponsors + +A sponsor is someone who donates money or resources to the curl project for no +specific service in return. + +curl accepts donations via [GitHub sponsors](https://github.com/sponsors/curl) +and [Open Collective](https://opencollective.com/curl). + +An even better way to contribute to the project might be to pay an engineer or +two to spend work hours on curl related tasks. + +We promise to use donated funds for things and activities that we believe are +beneficial for the project and its development. That includes but is not +limited to developer conferences, infrastructure, development, services and +hardware. + +Recurring donations above a certain amount of money puts the sponsor at a +named sponsor level: **Silver**, **Gold**, **Platinum** or **Top**. + +Sponsors on a named level can provide their logo image and preferred URL and +get recognition on the curl website's [sponsor +page](https://curl.se/sponsors.html), assuming they meet the project's +standards and requirements. + +- **Silver Sponsor** at least 100 USD/month +- **Gold Sponsor** at least 500 USD/month +- **Platinum Sponsor** at least 1000 USD/month +- **Top Sponsor** outstanding extra valuable help + +## Sponsor requirements + +A named level sponsor is entitled a logo and link on the curl website assuming +the company, brand and link are not deemed unsuitable. The curl team reserves +the right to make that decision at its own discretion. + +Sponsors may be denied a website presence for example if involved with drugs, +gambling, pornography, social media manipulation etc. + +## Past Sponsors + +Sponsors that stop paying are considered *Past Sponsors* and are not displayed +on the sponsor page anymore. We thank you for your contributions. + +## Donations + +Please note that sponsorship and donations are exactly that: donations to the +curl project. They are used to help and further the project as the project +leadership deems best. No goods or services are expected or promised in +return. Requests for refunds for such purposes are rejected. diff --git a/third-party/curl/docs/SSL-PROBLEMS.md b/third-party/curl/docs/SSL-PROBLEMS.md index afe42506c6..4809f84a97 100644 --- a/third-party/curl/docs/SSL-PROBLEMS.md +++ b/third-party/curl/docs/SSL-PROBLEMS.md @@ -1,97 +1,97 @@ - _ _ ____ _ - ___| | | | _ \| | - / __| | | | |_) | | - | (__| |_| | _ <| |___ - \___|\___/|_| \_\_____| + # SSL problems - First, let's establish that we often refer to TLS and SSL interchangeably as - SSL here. The current protocol is called TLS, it was called SSL a long time - ago. +First, let's establish that we often refer to TLS and SSL interchangeably as +SSL here. The current protocol is called TLS, it was called SSL a long time +ago. - There are several known reasons why a connection that involves SSL might - fail. This is a document that attempts to detail the most common ones and - how to mitigate them. +There are several known reasons why a connection that involves SSL might +fail. This is a document that attempts to detail the most common ones and +how to mitigate them. ## CA certs - CA certs are used to digitally verify the server's certificate. You need a - "ca bundle" for this. See lots of more details on this in the `SSLCERTS` - document. +CA certs are used to digitally verify the server's certificate. You need a +"ca bundle" for this. See lots of more details on this in the `SSLCERTS` +document. ## CA bundle missing intermediate certificates - When using said CA bundle to verify a server cert, you will experience - problems if your CA store does not contain the certificates for the - intermediates if the server does not provide them. +When using said CA bundle to verify a server cert, you may experience +problems if your CA store does not contain the certificates for the +intermediates if the server does not provide them. - The TLS protocol mandates that the intermediate certificates are sent in the - handshake, but as browsers have ways to survive or work around such - omissions, missing intermediates in TLS handshakes still happen that - browser-users will not notice. +The TLS protocol mandates that the intermediate certificates are sent in the +handshake, but as browsers have ways to survive or work around such +omissions, missing intermediates in TLS handshakes still happen that browser +users do not notice. - Browsers work around this problem in two ways: they cache intermediate - certificates from previous transfers and some implement the TLS "AIA" - extension that lets the client explicitly download such certificates on - demand. +Browsers work around this problem in two ways: they cache intermediate +certificates from previous transfers and some implement the TLS "AIA" +extension that lets the client explicitly download such certificates on +demand. ## Protocol version - Some broken servers fail to support the protocol negotiation properly that - SSL servers are supposed to handle. This may cause the connection to fail - completely. Sometimes you may need to explicitly select a SSL version to use - when connecting to make the connection succeed. +Some broken servers fail to support the protocol negotiation properly that +SSL servers are supposed to handle. This may cause the connection to fail +completely. Sometimes you may need to explicitly select an SSL version to +use when connecting to make the connection succeed. - An additional complication can be that modern SSL libraries sometimes are - built with support for older SSL and TLS versions disabled! +An additional complication can be that modern SSL libraries sometimes are +built with support for older SSL and TLS versions disabled. - All versions of SSL and the TLS versions before 1.2 are considered insecure - and should be avoided. Use TLS 1.2 or later. +All versions of SSL and the TLS versions before 1.2 are considered insecure +and should be avoided. Use TLS 1.2 or later. ## Ciphers - Clients give servers a list of ciphers to select from. If the list does not - include any ciphers the server wants/can use, the connection handshake - fails. +Clients give servers a list of ciphers to select from. If the list does not +include any ciphers the server wants/can use, the connection handshake +fails. - curl has recently disabled the user of a whole bunch of seriously insecure - ciphers from its default set (slightly depending on SSL backend in use). +curl has recently disabled the user of a whole bunch of seriously insecure +ciphers from its default set (slightly depending on SSL backend in use). - You may have to explicitly provide an alternative list of ciphers for curl - to use to allow the server to use a weak cipher for you. +You may have to explicitly provide an alternative list of ciphers for curl +to use to allow the server to use a weak cipher for you. - Note that these weak ciphers are identified as flawed. For example, this - includes symmetric ciphers with less than 128 bit keys and RC4. +Note that these weak ciphers are identified as flawed. For example, this +includes symmetric ciphers with less than 128-bit keys and RC4. - Schannel in Windows XP is not able to connect to servers that no longer - support the legacy handshakes and algorithms used by those versions, so we - advise against building curl to use Schannel on really old Windows versions. +Schannel in Windows XP is not able to connect to servers that no longer +support the legacy handshakes and algorithms used by those versions, so we +advise against building curl to use Schannel on really old Windows versions. - Reference: [Prohibiting RC4 Cipher - Suites](https://datatracker.ietf.org/doc/html/draft-popov-tls-prohibiting-rc4-01) +Reference: [Prohibiting RC4 Cipher +Suites](https://datatracker.ietf.org/doc/html/draft-popov-tls-prohibiting-rc4-01) ## Allow BEAST - BEAST is the name of a TLS 1.0 attack that surfaced 2011. When adding means - to mitigate this attack, it turned out that some broken servers out there in - the wild did not work properly with the BEAST mitigation in place. +BEAST is the name of a TLS 1.0 attack that surfaced 2011. When adding means +to mitigate this attack, it turned out that some broken servers out there in +the wild did not work properly with the BEAST mitigation in place. - To make such broken servers work, the --ssl-allow-beast option was - introduced. Exactly as it sounds, it re-introduces the BEAST vulnerability - but on the other hand it allows curl to connect to that kind of strange - servers. +To make such broken servers work, the --ssl-allow-beast option was +introduced. Exactly as it sounds, it re-introduces the BEAST vulnerability +but on the other hand it allows curl to connect to that kind of strange +servers. ## Disabling certificate revocation checks - Some SSL backends may do certificate revocation checks (CRL, OCSP, etc) - depending on the OS or build configuration. The --ssl-no-revoke option was - introduced in 7.44.0 to disable revocation checking but currently is only - supported for Schannel (the native Windows SSL library), with an exception - in the case of Windows' Untrusted Publishers block list which it seems cannot - be bypassed. This option may have broader support to accommodate other SSL - backends in the future. +Some SSL backends may do certificate revocation checks (CRL, OCSP, etc) +depending on the OS or build configuration. The --ssl-no-revoke option was +introduced in 7.44.0 to disable revocation checking but currently is only +supported for Schannel (the native Windows SSL library), with an exception +in the case of Windows' Untrusted Publishers block list which it seems cannot +be bypassed. This option may have broader support to accommodate other SSL +backends in the future. - References: +References: - https://curl.se/docs/ssl-compared.html +https://curl.se/docs/ssl-compared.html diff --git a/third-party/curl/docs/SSLCERTS.md b/third-party/curl/docs/SSLCERTS.md index 4094e2fec6..d5110e18f0 100644 --- a/third-party/curl/docs/SSLCERTS.md +++ b/third-party/curl/docs/SSLCERTS.md @@ -1,155 +1,159 @@ -SSL Certificate Verification -============================ + -SSL is the old name. It is called TLS these days. +# TLS Certificate Verification -Native SSL ----------- +## Native vs file based -If libcurl was built with Schannel or Secure Transport support (the native SSL -libraries included in Windows and Mac OS X), then this does not apply to -you. Scroll down for details on how the OS-native engines handle SSL -certificates. If you are not sure, then run "curl -V" and read the results. If -the version string says `Schannel` in it, then it was built with Schannel -support. +If curl was built with Schannel support, then curl uses the Windows native CA +store for verification. On Apple operating systems, it is possible to use Apple's +"SecTrust" services for certain TLS backends, details below. +All other TLS libraries use a file based CA store by +default. -It is about trust ------------------ +## Verification -This system is about trust. In your local CA certificate store you have certs -from *trusted* Certificate Authorities that you then can use to verify that -the server certificates you see are valid. They are signed by one of the -certificate authorities you trust. +Every trusted server certificate is digitally signed by a Certificate +Authority, a CA. -Which certificate authorities do you trust? You can decide to trust the same -set of companies your operating system trusts, or the set one of the known -browsers trust. That is basically trust via someone else you trust. You should -just be aware that modern operating systems and browsers are setup to trust -*hundreds* of companies and in recent years several certificate authorities -have been found untrustworthy. +In your local CA store you have a collection of certificates from *trusted* +certificate authorities that TLS clients like curl use to verify servers. -Certificate Verification ------------------------- - -libcurl performs peer SSL certificate verification by default. This is done -by using a CA certificate store that the SSL library can use to make sure the -peer's server certificate is valid. +curl does certificate verification by default. This is done by verifying the +signature and making sure the certificate was crafted for the server name +provided in the URL. If you communicate with HTTPS, FTPS or other TLS-using servers using -certificates in the CA store, you can be sure that the remote server really is -the one it claims to be. +certificates signed by a CA whose certificate is present in the store, you can +be sure that the remote server really is the one it claims to be. -If the remote server uses a self-signed certificate, if you do not install a CA -cert store, if the server uses a certificate signed by a CA that is not +If the remote server uses a self-signed certificate, if you do not install a +CA cert store, if the server uses a certificate signed by a CA that is not included in the store you use or if the remote host is an impostor -impersonating your favorite site, and you want to transfer files from this -server, do one of the following: +impersonating your favorite site, the certificate check fails and reports an +error. - 1. Tell libcurl to *not* verify the peer. With libcurl you disable this with - `curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, FALSE);` +If you think it wrongly failed the verification, consider one of the following +sections. - With the curl command line tool, you disable this with `-k`/`--insecure`. +### Skip verification - 2. Get a CA certificate that can verify the remote server and use the proper - option to point out this CA cert for verification when connecting. For - libcurl hackers: `curl_easy_setopt(curl, CURLOPT_CAINFO, cacert);` +Tell curl to *not* verify the peer with `-k`/`--insecure`. - With the curl command line tool: `--cacert [file]` +We **strongly** recommend this is avoided and that even if you end up doing +this for experimentation or development, **never** skip verification in +production. - 3. Add the CA cert for your server to the existing default CA certificate - store. The default CA certificate store can be changed at compile time with - the following configure options: +### Use a custom CA store - `--with-ca-bundle=FILE`: use the specified file as the CA certificate - store. CA certificates need to be concatenated in PEM format into this - file. +Get a CA certificate that can verify the remote server and use the proper +option to point out this CA cert for verification when connecting - for this +specific transfer only. - `--with-ca-path=PATH`: use the specified path as CA certificate store. CA - certificates need to be stored as individual PEM files in this directory. - You may need to run c_rehash after adding files there. +With the curl command line tool: `--cacert [file]` - If neither of the two options is specified, configure will try to - auto-detect a setting. It's also possible to explicitly not set any - default store but rely on the built in default the crypto library may - provide instead. You can achieve that by passing both - `--without-ca-bundle` and `--without-ca-path` to the configure script. +If you use the curl command line tool without a native CA store, then you can +specify your own CA cert file by setting the environment variable +`CURL_CA_BUNDLE` to the path of your choice. `SSL_CERT_FILE` and `SSL_CERT_DIR` +are also supported. - If you use Internet Explorer, this is one way to get extract the CA cert - for a particular server: +If you are using the curl command line tool on Windows, curl searches for a CA +cert file named `curl-ca-bundle.crt` in these directories and in this order: + 1. application's directory + 2. current working directory + 3. Windows System directory (e.g. C:\Windows\System32) + 4. Windows Directory (e.g. C:\Windows) + 5. all directories along %PATH% - - View the certificate by double-clicking the padlock - - Find out where the CA certificate is kept (Certificate> - Authority Information Access>URL) - - Get a copy of the crt file using curl - - Convert it from crt to PEM using the OpenSSL tool: - `openssl x509 -inform DES -in yourdownloaded.crt -out outcert.pem -text` - - Add the `outcert.pem` to the CA certificate store or use it stand-alone - as described below. +curl 8.11.0 added a build-time option to disable this search behavior, and +another option to restrict search to the application's directory. - If you use the `openssl` tool, this is one way to get extract the CA cert - for a particular server: +curl 8.19.0 added a build-time option to enable Native CA by default on +Windows. This build-time option by default also disables searching for +a `curl-ca-bundle.crt` on disk. - - `openssl s_client -showcerts -servername server -connect server:443 > cacert.pem` - - type "quit", followed by the "ENTER" key - - The certificate will have "BEGIN CERTIFICATE" and "END CERTIFICATE" - markers. - - If you want to see the data in the certificate, you can do: `openssl - x509 -inform PEM -in certfile -text -out certdata` where `certfile` is - the cert you extracted from logfile. Look in `certdata`. - - If you want to trust the certificate, you can add it to your CA - certificate store or use it stand-alone as described. Just remember that - the security is no better than the way you obtained the certificate. +### Use the native store - 4. If you are using the curl command line tool, you can specify your own CA - cert file by setting the environment variable `CURL_CA_BUNDLE` to the path - of your choice. +In several environments, in particular on Microsoft and Apple operating +systems, you can ask curl to use the system's native CA store when verifying +the certificate. Depending on how curl was built, this may already be the +default. - If you are using the curl command line tool on Windows, curl will search - for a CA cert file named "curl-ca-bundle.crt" in these directories and in - this order: - 1. application's directory - 2. current working directory - 3. Windows System directory (e.g. C:\windows\system32) - 4. Windows Directory (e.g. C:\windows) - 5. all directories along %PATH% +With the curl command line tool: `--ca-native`. - 5. Get a better/different/newer CA cert bundle! One option is to extract the - one a recent Firefox browser uses by running 'make ca-bundle' in the curl - build tree root, or possibly download a version that was generated this - way for you: [CA Extract](https://curl.se/docs/caextract.html) +### Modify the CA store -Neglecting to use one of the above methods when dealing with a server using a -certificate that is not signed by one of the certificates in the installed CA -certificate store, will cause SSL to report an error ("certificate verify -failed") during the handshake and SSL will then refuse further communication -with that server. +Add the CA cert for your server to the existing default CA certificate store. -Certificate Verification with Schannel and Secure Transport ------------------------------------------------------------ +Usually you can figure out the path to the local CA store by looking at the +verbose output that `curl -v` shows when you connect to an HTTPS site. -If libcurl was built with Schannel (Microsoft's native TLS engine) or Secure -Transport (Apple's native TLS engine) support, then libcurl will still perform -peer certificate verification, but instead of using a CA cert bundle, it will -use the certificates that are built into the OS. These are the same -certificates that appear in the Internet Options control panel (under Windows) -or Keychain Access application (under OS X). Any custom security rules for -certificates will be honored. +### Change curl's default CA store -Schannel will run CRL checks on certificates unless peer verification is -disabled. Secure Transport on iOS will run OCSP checks on certificates unless -peer verification is disabled. Secure Transport on OS X will run either OCSP -or CRL checks on certificates if those features are enabled, and this behavior -can be adjusted in the preferences of Keychain Access. +The default CA certificate store curl uses is set at build time. When you +build curl you can point out your preferred path. -HTTPS proxy ------------ +### Extract CA cert from a server -Since version 7.52.0, curl can do HTTPS to the proxy separately from the -connection to the server. This TLS connection is handled separately from the -server connection so instead of `--insecure` and `--cacert` to control the + curl -w %{certs} https://example.com > cacert.pem + +The certificate has `BEGIN CERTIFICATE` and `END CERTIFICATE` markers. + +### Get the Mozilla CA store + +Download a version of the Firefox CA store converted to PEM format on the [CA +Extract](https://curl.se/docs/caextract.html) page. It always features the +latest Firefox bundle. + +## Native CA store + +### Windows + Schannel + +If curl was built with Schannel, then curl uses the certificates that are +built into the OS. These are the same certificates that appear in the +Internet Options control panel (under Windows). +Any custom security rules for certificates are honored. + +Schannel runs CRL checks on certificates unless peer verification is disabled. + +### Apple + OpenSSL/GnuTLS + +When curl is built with Apple SecTrust enabled and uses an OpenSSL compatible +TLS backend or GnuTLS, the default verification is handled by that Apple +service. As in: + + curl https://example.com + +You may still provide your own certificates on the command line, such as: + + curl --cacert mycerts.pem https://example.com + +In this situation, Apple SecTrust is **not** used and verification is done +**only** with the trust anchors found in `mycerts.pem`. If you want **both** +Apple SecTrust and your own file to be considered, use: + + curl --ca-native --cacert mycerts.pem https://example.com + +#### Other Combinations + +How well the use of native CA stores work in all other combinations depends +on the TLS backend and the OS. Many TLS backends offer functionality to access +the native CA on a range of operating systems. Some provide this only on specific +configurations. + +Specific support in curl exists for Windows and OpenSSL compatible TLS backends. +It tries to load the certificates from the Windows "CA" and "ROOT" stores for +transfers requesting the native CA. Due to Window's delayed population of those +stores, this might not always find all certificates. + +## HTTPS proxy + +curl can do HTTPS to the proxy separately from the connection to the server. +This TLS connection is handled and verified separately from the server +connection so instead of `--insecure` and `--cacert` to control the certificate verification, you use `--proxy-insecure` and `--proxy-cacert`. With these options, you make sure that the TLS connection and the trust of the proxy can be kept totally separate from the TLS connection to the server. diff --git a/third-party/curl/docs/THANKS b/third-party/curl/docs/THANKS index a8a4d6a1b5..a70bf7527d 100644 --- a/third-party/curl/docs/THANKS +++ b/third-party/curl/docs/THANKS @@ -6,22 +6,29 @@ 0xee on github 0xflotus on github +0xN3R3K3 +11soda11 12932 on github 1337vt on github 1ocalhost on github 3dyd on github 3eka on github +4lan.m +5533asdg on github 8U61ife on github +9cel a1346054 on github Aaro Koskinen Aaron Oneal Aaron Orenstein Aaron Scarisbrick aasivov on github +Abdullah Alyan Abhinav Singh +Abhinav Singhal Abram Pousada accountantM on github -AceCrow on Github +AceCrow on github ad0p on github Adam Averay Adam Barclay @@ -34,63 +41,63 @@ Adam Marcionek Adam Piggott Adam Rosenfield Adam Sampson +adamse on github Adam Tkac +ad-chaos on github +Aditya Garg +Ãdler Jonas Gross Adnan Khan adnn on github Adrian Burcea +Adriano Meirelles Adrian Peniak Adrian Schuur -Adriano Meirelles +Ady Elouej +afengsoft on github afrind on github Aftab Alam +Ahmad Gani ahodesuka on github +aisle-research-bot ajak in #curl Ajit Dhumale +A Johnston +Akhilesh Nema Akhil Kedia Aki Koskinen +Aki Sakurai Akos Pasztory Akshay Vernekar Alain Danteny Alain Miniussi +Alan Coopersmith +Alan De Smet Alan Jenkins Alan Pinstein Albert Chin-A-Young Albert Choy +Alberto Leiva Popper Albin Vass +albrechtd on github Alejandro Alvarez Ayllon Alejandro Colomar Alejandro R. Sedeño Aleksandar Milivojevic Aleksander Mazur Aleksandr Krotov +Aleksandr Sergeev +Aleksei Bavshin Aleksey Tulinov +alervd on github Ales Mlakar Ales Novak Alessandro Ghedini Alessandro Vesely Alex aka WindEagle -Alex Baines -Alex Bligh -Alex Chan -Alex Crichton -Alex Fishman -Alex Gaynor -Alex Grebenschikov -Alex Gruz -Alex Kiernan -Alex Konev -Alex Malinovich -Alex Mayorga -Alex McLellan -Alex Neblett -Alex Nichols -Alex Potapenko -Alex Rousskov -Alex Samorukov -Alex Suykov -Alex Vinnik -Alex Xu +Alexander Bartel +Alexander Batischev Alexander Beedie +Alexander Blach Alexander Chuykov Alexander Dyagilev Alexander Elgert @@ -102,6 +109,7 @@ Alexander Krasnostavsky Alexander Lazic Alexander Pepper Alexander Peslyak +Alexander Shtuchkin Alexander Sinditskiy Alexander Traud Alexander V. Tikhonov @@ -109,28 +117,63 @@ Alexander Zhuravlev Alexandre Bury Alexandre Ferrieux Alexandre Pion +Alex Baines +Alex Bligh +Alex Bozarth +Alex Chan +Alex Crichton Alexey Borzov Alexey Eremikhin +Alexey Larikov Alexey Melnichuk Alexey Pesternikov Alexey Savchuk Alexey Simak Alexey Zakhlestin +Alex Fishman +Alex Gaynor +Alex Grebenschikov +Alex Gruz +Alex Hamilton Alexis Carvalho Alexis La Goutte +Alexis Savin Alexis Vachette +Alex Kiernan +Alex Klyubin +Alex Konev +Alex Malinovich +Alex Mayorga +Alex McLellan +Alex Neblett +Alex Nichols +Alex Potapenko +Alex Rousskov +Alex Samorukov +Alex Snast +Alex Suykov +Alex Vinnik +Alex Xu Alfonso Martone Alfred Gebert +alhudz +Alice Lee Poetics +alienowo on hackerone Ali Khodkar -Ali Utku Selen ALittleDruid on github +Ali Utku Selen Allen Pulsifer Alois Klink Alona Rossen Amaury Denoyelle +ambikeesshh +Ameda Amahru amishmm on github +amitbidlan Amit Katyal +Ammar Faizi Amol Pattekar +am-perip on hackerone Amr Shahin Anatol Belski Anatoli Tubman @@ -138,18 +181,17 @@ Anders Bakken Anders Berg Anders Gustafsson Anders Havn -Anders Roxell Anderson Sasaki Anderson Toshiyuki Sasaki +Anders Roxell Andi Jahja -Andre Guibert de Bruet -Andre Heinecke Andrea Pappacoda Andreas Damm Andreas Falkenhahn Andreas Farber Andreas Fischer Andreas Huebner +Andreas Kiefer Andreas Kostyrka Andreas Malzahn Andreas Ntaflos @@ -160,11 +202,16 @@ Andreas Schneider Andreas Schuldei Andreas Sommer Andreas Streichardt +Andreas Westin Andreas Wurf +Andre Guibert de Bruet +Andre Heinecke Andrei Benea Andrei Bica Andrei Cipu +Andrei Florea Andrei Karas +Andrei Korshikov Andrei Kurushin Andrei Neculau Andrei Rybak @@ -172,6 +219,9 @@ Andrei Sedoi Andrei Valeriu BICA Andrei Virtosu Andrej E Baranov +Andrés García +Andrew +Andrew Ayer Andrew Barnert Andrew Barnes Andrew Benham @@ -181,10 +231,15 @@ Andrew de los Reyes Andrew Francis Andrew Fuller Andrew Ishchuk +Andrew Kaster +Andrew Kirillov Andrew Krieger Andrew Kurushin +Andrew Kvalheim Andrew Lambert Andrew Moise +Andrew Nesbitt +Andrew Olsen Andrew Potter Andrew Robbins Andrew Wansink @@ -193,16 +248,22 @@ Andrey Gursky Andrey Labunets Andrii Moiseiev Andrius Merkys -Andrés García +Andriy Druk Andy Alt Andy Cedilnik Andy Fiddaman +Andy Pan +Andy Reitz Andy Serpa Andy Stamp Andy Tsouladze +And-yW on github Angus Mackay anio on github +annalee +Anna Liberty anon00000000 on github +anonymous237 on hackerone anshnd on github Anssi Kolehmainen Antarpreet Singh @@ -214,28 +275,39 @@ Anthony Hu Anthony Ramine Anthony Shaw Antoine Aubert +Antoine Bollengier Antoine Calando Antoine du Hamel Antoine Pietri Antoine Pitrou Anton Bychkov Anton Gerasimov +Antonio Larrosa +Antoni Villalonga Anton Kalmykov Anton Malov -Anton Yabchinskiy -Antoni Villalonga -Antonio Larrosa Antony74 on github +Anton Yabchinskiy Antti Hätälä +antypanty on hackerone +Anubhav Rai apparentorder on github April King +Aquila Macedo arainchik on github Archangel_SDY on github +Arian van Putten +Aritra Basu +Arjan van de Ven Arkadiusz Miskiewicz +Arkadi Vainbrand +arlt on github Armel Asselin Arnaud Compan Arnaud Ebalard Arnaud Rebillout +Arnav Purushotam +Arnav-Purushotam-CUBoulder Arne Soete Aron Bergman Aron Rotteveel @@ -246,16 +318,22 @@ Arve Knudsen Arvid Norberg arvids-kokins-bidstack on github asavah on github +Asger Hautop Drewsen Ashish Shukla Ashwin Metpalli -Ask Bjørn Hansen Askar Safin +Ask Bjørn Hansen AtariDreams on github Ates Goral atjg on github +Augment code Augustus Saunders +Aurélien Pierre Austin Green +Austin Moore +av223119 on github Avery Fay +awesomekosm on github awesomenode on github Axel Chong Axel Morawietz @@ -263,40 +341,44 @@ Axel Tillequin Ayesh Karunaratne Ayoub Boudhar Ayushman Singh Chauhan +azraelxuemo on hackerone b9a1 on github Bachue Zhou Baitinq on github Balaji Parasuram -Balaji S Rao Balaji Salunke +Balaji S Rao Balakrishnan Balasubramanian Balazs Kovacsics -balikalina on Github +balikalina on github Balint Szilakszi +BANADDA +baranyaib90 on github Barry Abrahamson Barry Pollard +Bartel Sielski +Bartosz Ruszczak Bart Whiteley Baruch Siach Bas Mevissen -Bas van Schaik +Bastian Jesuiter Bastian Krause Bastien Bouclet Basuke Suzuki +Bas van Schaik baumanj on github +BazaarAcc32 on github bdry on github beckenc on github +behindtheblackwall on hackerone +Ben +Benau on github +Ben Bodenmiller Ben Boeckel +Benbuck Nason Ben Darnell Ben Fritz Ben Greear -Ben Kohler -Ben Madsen -Ben Noordhuis -Ben Van Hof -Ben Voris -Ben Winslow -Benau on github -Benbuck Nason Benjamin Gerard Benjamin Gilbert Benjamin Johnson @@ -305,9 +387,16 @@ Benjamin Loison Benjamin Riefenstahl Benjamin Ritcey Benjamin Sergeant -Benoit Neil +Ben Kohler +Ben Madsen +Ben Noordhuis +Benoit Neil (Sukender) Benoit Pierre Benoit Sigoure +Ben Van Hof +Ben Voris +Ben Winslow +Ben Zanin Bernard Leak Bernard Spil Bernat Mut @@ -316,21 +405,26 @@ Bernhard Iselborn Bernhard M. Wiedemann Bernhard Reutner-Fischer Bernhard Walle +Berthin Torres Callañaupa Bert Huijben Bertrand Demiddelaer Bertrand Simonnet beslick5 on github Bevan Weiss +Bhanu Prakash Bill Doyle Bill Egert Bill Hoffman +billionai on github Bill Middlecamp +Bill Mill Bill Nagel Bill Pyne -billionai on github +Billy O'Neal Billyzou0741326 on github Bin Lan Bin Meng +bird on github Biswapriyo Nath Bjarni Ingi Gislason Bjoern Franke @@ -338,112 +432,150 @@ Bjoern Sikora Bjorn Augustsson Bjorn Reese Björn Stenberg +black-desk on github +BlackFuffey on github Blaise Potard Blake Burkhart +blankie bnfp on github +bo0tzz on github Bo Anderson +bobmitchell1956 on github +BobodevMm on github Bob Relyea Bob Richmond Bob Schader -bobmitchell1956 on github Bodo Bergmann Bogdan Nicula +BohwaZ +boilingoden +boingball Boris Kuschel Boris Okunskiy Boris Rasin Boris Verkhovskiy Brad Burdick Brad Fitzpatrick +Bradford Bruce Brad Forschinger Brad Harder Brad Hards +Brad House Brad King Brad Spencer -Bradford Bruce bramus on github Brandon Casey Brandon Dong Brandon Wang BratSinot on github +Brendan Dolan-Gavitt Brendan Jurd +Brendon Smith +Brennan Kinney Brent Beardsley +Brett Buddin Brian Akins Brian Bergeron Brian Carpenter Brian Chaplin Brian Childs Brian Chrisman +Brian Chrzanowski +Brian Clemens Brian Dessent Brian E. Gallew Brian Green +Brian Harris Brian Inglis Brian J. Murrell Brian Lund +brian m. carlson Brian Nixon Brian Prodoehl Brian R Duffy Brian Ulm Brock Noland -Bru Rom Bruce Mitchener Bruce Stephens +bruce.yoon BrumBrum on hackerone Bruno Baguette Bruno de Carvalho Bruno Grasselli Bruno Henrique Batista Cruz da Silva Bruno Thomsen +Bru Rom Bryan Henderson Bryan Kemp bsammon on github bsergean on github +bsr13 on hackerone +bttrfl on github +bubbleguuum on github Bubu on github buzo-ffm on github bxac on github Bylon2 on github Byrial Jensen +ByteRay on hackerone +Cajus Pollmeier Caleb Raitto +calm329 +calvin2021y on github Calvin Buckley +Calvin Ruocco Cameron Blomquist Cameron Cawley Cameron Kaiser Cameron MacMinn Cameron Will Camille Moncelier -Cao ZhenXiang Caolan McNamara +Caolán McNamara +Cao ZhenXiang Captain Basil Carie Pointer -Carl Zogheib Carlo Alberto +Carlo Cabrera Carlo Cannas Carlo Marcelo Arenas Belón +Carlos Carrillo +Carlos Henrique Lima Melara +Carlos ORyan Carlo Teubner Carlo Wood -Carlos ORyan +Carl Zogheib Carsten Lange Casey Bodley Casey O'Donnell Catalin Patulea +Catena cyber causal-agent on github cbartl on github cclauss on github +Cédric Connes +Cédric Deltheil Cering on github Cesar Eduardo Barros +Ch40zz on github Chad Monroe Chandrakant Bagul +Chara White Charles Cazabon Charles Kerr Charles Romestant +Charlie C +chemodax Chen Prog +chensong1211 on github Cherish98 on github Chester Liu Chih-Chung Chang Chih-Hsuan Yen Chilledheart on github Chloe Kudryavtsev -Chris "Bob Bob" Chris Araman +Chris "Bob Bob" Chris Carlmar Chris Combes Chris Conlon @@ -455,123 +587,149 @@ Chris Maltby Chris Mumford Chris Paulson-Ellis Chris Roberts +Chris Sauer Chris Smowton +Chris Stubbs +Chris Swan Chris Talbot -Chris Young Christian Fillion Christian Grothoff +Christian Hägele Christian Heimes Christian Hesse -Christian Hägele +Christian Heusel Christian Krause Christian Kurz Christian Robottom Reis Christian Schmitz +Christian Schmitza Christian Stewart Christian Vogt Christian Weisgerber -Christoph Krey -Christoph M. Becker -Christoph Reiter Christophe Demory Christophe Dervieux Christophe Legry +Christopher Boyd Christopher Conroy +Christopher Dannemiller Christopher Degawa Christopher Head Christopher Palow -Christopher R. Palmer Christopher Reid +Christopher R. Palmer Christopher Sauer Christopher Stone +Christopher Wellons +Christoph Jabs +Christoph Krey +Christoph M. Becker +Christoph Reiter +Chris Webb +Chris Young +chrizilla on github +chrysos349 on github Chungtsun Li Ciprian Badescu civodul on github Claes Jakobsson Clarence Gardner Claudio Neves +claudiusaiz on github clbr on github Clemens Gruber +Clément Notin Cliff Crosland Clifford Wolf Clint Clayton Cloudogu Siebels -Clément Notin +CMD cmfrolick on github +co-authors in libssh2 codesniffer13 on github Cody Jones Cody Mack COFFEETALES on github coinhubs on github Colby Ranger +Cole Helbling +Cole Leavitt Colin Blair Colin Cross Colin Hogben Colin Leroy +Colin Leroy-Mira Colin O'Dell Colin Watson -Colm Buckley Colman Mbuya +Colm Buckley +Colton Willey Constantine Sapuntzakis +consulion on github +cooldadpresident on github coralw on github +Corinna Brandt correctmost on github Cory Benfield Cory Nelson Costya Shulyupin -Craig A West Craig Andrews +Craig A West Craig Davison Craig de Stigter Craig Markwardt +crawfordxx crazydef on github Cris Bailiff Cristian Greco Cristian Morales Vega Cristian Rodríguez +CueXXIII on github +curl.stunt430 Curt Bogmine +Cutiapreta on hackerone Cynthia Coan Cyril B Cyrill Osterwalder -Cédric Connes -Cédric Deltheil -D. Flinkmann +d1r3ct0r d4d on hackerone d912e3 on github -Da-Yoon Chung daboul on github Dag Ekengren +Dag-Erling Smørgrav +Dagfinn Ilmari MannsÃ¥ker +Dag Haavi Finstad Dagobert Michelsen +dahmono on github Daiki Ueno Dair Grant +Dalei Dambaev Alexander Damian Dixon Damien Adant Damien Vielpeau Damien Walsh +Dan Arnfield Dan Becker Dan Cristian Dan Donahue Dan Fandrich -Dan Frandrich -Dan Johnson -Dan Kenigsberg -Dan Locks -Dan McNulty -Dan Nelson -Dan Petitt -Dan Torop -Dan Zitter Daniel at touchtunes +Dániel Bakai Daniel Bankhead Daniel Black +Daniel Böhmer Daniel Carpenter Daniel Cater +Daniel Díaz Daniel Egger +Daniel Engberg Daniel Faust +Daniel Fosco Daniel Gustafsson Daniel Hallberg Daniel Hwang Daniel JeliÅ„ski +Daniel J. H. Daniel Johnson Daniel Kahn Gillmor Daniel Katz @@ -580,33 +738,56 @@ Daniel KureÄka Daniel Lee Hwang Daniel Lublin Daniel Marjamäki +Daniel McCarney Daniel Melani Daniel Mentz +Daniel Pouzzner Daniel Romero +Daniel Santos Daniel Schauenberg +Daniel Schulte Daniel Seither Daniel Shahaf Daniel Silverstone Daniel Steinberg Daniel Stenberg +Daniel Szmulewicz +Daniel Terhorst-North Daniel Theron Daniel Valenzuela +Daniel Wade Daniel Woelfel +Daniil Gentili +Dan Johnson +Dan Kenigsberg +Dan Locks +Dan McDonald +Dan McNulty +Dan Nelson +Dan Petitt +Dan Rosser +Dan Torop +Dan Zitter Daphne Luong +Darío Hereñú Dario Nieuwenhuis +Dario Vinella Dario Weißer +Darren Banfi Darryl House Darshan Mody -Darío Hereñú dasimx on github +DasKutti on github Dave Cottlehuber Dave Dribin Dave Halbakken Dave Hamilton Dave May +Dave Nicolson Dave Reisner Dave Thompson Dave Vasilevsky +Dave Walker Davey Shafik David Bau David Benjamin @@ -618,19 +799,23 @@ David Carlier David Cohen David Cook David Demelier -David E. Narváez David Earl +Davide Cassioli +davidedec on github +Davide Masserut +David E. Narváez David Eriksson David Garske David Goerger David Houlder David Hu David Hull -David J Meyer David James +David J Meyer David Kalnischkies David Kierznowski David Kimdon +David Korczynski David L. David Lang David LeBlanc @@ -643,22 +828,31 @@ David Phillips David Rosenstrauch David Ryskalczyk David Sanderson +David Sardari David Schweikert David Shaw David Strauss +David Suter David Tarendash David Thiel David Walser David Woodhouse David Wright David Yan -Davide Cassioli -Davide Masserut -davidedec on github +David Zhuang +daviey on hackerone +Da-Yoon Chung +dbalsom dbrowndan on github +dEajL3kA dEajL3kA on github Deal(一线çµ) +defnull dekerser on github +deliciouslytyped on github +delogicsreal on github +Demi Marie Obenour +denandz on github dengjfzh on github Dengminwen Denis BaruÄić @@ -667,13 +861,22 @@ Denis Feklushkin Denis Goleshchikhin Denis Laxalde Denis Ollier +Deniz Parlak +Deniz Sökmen Dennis Clarke Dennis Felsing +dependabot[bot] Derek Higgins +Derek Huang Derzsi Dániel Desmond O. Chang destman on github Detlef Schmier +Devdatta Talele +devgs on github +Dexter Gerig +dfdity on github +D. Flinkmann Dheeraj Sangamkar Didier Brisebourg Diego Bes @@ -689,14 +892,17 @@ Dimitrios Apostolou Dimitrios Siganos Dimitris Sarris Dinar +Diogo Correia Diogo Teles Sant'Anna Dion Williams +Dio Putra Dirk Eddelbuettel Dirk Feytons +Dirk Hünniger +Dirkjan Bussink Dirk Manske Dirk Rosenkranz Dirk Wetter -Dirkjan Bussink Diven Qi divinity76 on github Divy Le Ray @@ -717,21 +923,27 @@ Dmitry Mikhirev Dmitry Popov Dmitry Rechkin Dmitry S. Baikov +Dmitry Tretyakov Dmitry Wagin dnivras on github +dogma +DoI Dolbneff A.V -Domen Kožar Domenico Andreoli +Domen Kožar Dominick Meglio Dominik Hölzl Dominik Klemba +Dominik PiÄ…tkowski Dominik Thalhammer +Dominik Tomecki Dominique Leuenberger -Don J Olmstead Dongliang Mu +Donguk Kim +Don J Olmstead +Dorian Craps Doron Behar Doug Kaufman -Doug Porter Douglas Creager Douglas E. Wegscheid Douglas Kilpatrick @@ -739,6 +951,7 @@ Douglas Mencken Douglas R. Horner Douglas R. Reno Douglas Steinwand +Doug Porter Dov Murik dpull on github Drake Arconis @@ -747,14 +960,17 @@ Duane Cathey Duncan Mac-Vicar Prett Duncan Wilcox Dustin Boswell -Dustin Howett +Dustin L. Howett Dusty Mabe Duy Phan Thanh Dwarakanath Yadavalli +dwickr +Dwij Mehta +dyingc on github +Dylam De La Torre Dylan Anthony Dylan Ellicott Dylan Salisbury -Dániel Bakai eaglegai on github Early Ehlinger Earnestly on github @@ -762,94 +978,123 @@ Eason-Yu on github Ebe Janchivdorj ebejan on github Ebenezer Ikonne -Ed Morley ed0d2b2ce19451f2 Eddie Lumpkin Edgaras JanuÅ¡auskas Edin Kadribasic +edmcln on github Edmond Yu +Ed Morley Edoardo Lolletti Eduard Bloch +Eduard Strehlau Edward Kimmel Edward Rudd Edward Sheldrake Edward Thomson +Edwin Török Eelco Dolstra Eetu Ojanen +eeverettrbx on github Egon Eckert Egor Pugin Ehren Bendler Eldar Zaitov elelel on github elephoenix on github -Eli Schwartz Elia Tufarolo +Eli Schwartz +Elise Vance +Elliot Killick Elliot Saba +Elliott Balsley Ellis Pritchard Elmira A Semenova Elms Eloy Degen elsamuko on github +elvinasp on github emanruse on github Emanuele Bovisio Emanuele Torre +Emanuel Komínek +Emanuel Krollmann Emil Engler -Emil Lerner -Emil Romanus -Emil Österlund Emiliano Ida Emilio Cobos Ãlvarez Emilio López +Emilio Pozuelo Monfort +Emil Lerner +Emil Österlund +Emil Romanus Emmanuel Tychon +Emre Çalışkan +Enno Boland Enrico Scholz Enrik Berkhan +enWILLYado on github +epicmkirzinger on github eppesuig Eramoto Masaya +Ercan Ermis Eric Cooper Eric Curtin Eric Gallager Eric Hu +Eric Knibbe +Erick Nuwendam Eric Landes Eric Lavigne Eric Lubin Eric Melville Eric Mertens +Eric Murphy Eric Musser +Eric Norris +Érico Nogueira +Érico Nogueira Rolim Eric Rautman Eric Rescorla Eric Ridge Eric Rosenquist -Eric S. Raymond Eric Sauvageau +Eric S. Raymond Eric Thelin Eric Vergnaud Eric Vigeant Eric Wong Eric Wu Eric Young -Erick Nuwendam Erik Jacobsen Erik Janssen Erik Johansson Erik Minekus Erik Olsson +Erik Schnetter Erik Stenlund Ernest Beinrohr Ernst Sjöstrand Erwan Legrand Erwin Authried Esdras de Morais da Silva +Eshan Kelkar Estanislau Augé-Pujadas +Ethan Alker +Ethan Everett Ethan Glasser Camp +Ethan Wilkes Etienne Simard Eugene Kotlyarov -Evan Jordan +Eunsoo Kim Evangelos Foutras +Evan Jordan Even Rouault +evergarden1123 on hackerone Evert Pot Evgeny Grin (Karlson2k) Evgeny Turnaev eXeC64 on github +extrimexxx on github Eygene Ryabinkin Eylem Ugurel Fabian Fischer @@ -857,20 +1102,27 @@ Fabian Frank Fabian Hiernaux Fabian Keil Fabian Ruff +Fabian Vogt Fabian Yamaguchi Fabrice Fontaine +Fabrício Canedo Fabrizio Ammollo Fahim Chandurwala Faizur Rahman +Faraz Fallahi +farazrbx on github Farzin on github Fata Nugraha Fawad Mirza +Fay Stegerman FC Stegerman +Fd929c2CE5fA on github fds242 on github Federico Bianchi Federico Pellegrin Fedor Karpelevitch Fedor Korotkov +feelingseas on github FeignClaims on github Feist Josselin Felipe Gasper @@ -880,12 +1132,21 @@ Felix von Leitner Felix Yan Feng Tu Fernando Muñoz +ffath-vo on github +Filipe Casal Filip Lundgren Filip Salomonsson finkjsc on github +Fiona Klute Firefox OS +Fizn-Ahmd on github +fjaell on github Flameborn on github +Flavio Amieiro Flavio Medeiros +Florian Eckert +Florian Friedrich +Florian Imdahl Florian Kohnhäuser Florian Pritz Florian Schoppmann @@ -897,8 +1158,12 @@ Francisco Moraes Francisco Munoz Francisco Olarte Francisco Sedano +François Charlier +François Michel Francois Petitjean +François Rigault Francois Rivard +Frank Buss Frank Denis Frank Gevaerts Frank Hempel @@ -908,28 +1173,33 @@ Frank Meier Frank Ticheler Frank Van Uffelen FrantiÅ¡ek KuÄera -François Charlier -François Michel -François Rigault Frazer Smith -Fred Machado -Fred New -Fred Noz -Fred Stluka Frederic Lepied Frederik B Frederik Wedel-Heinen +Fred Machado +Fred New +Fred Noz Fredrik Thulin +Fred Stluka FuccDucc on github Fujii Hironori fullincome on github fundawang on github +fuzzard +Gabe Gabriel Corona Gabriel Kuri +Gabriel Marin Gabriel Simmer Gabriel Sjoberg +Gaelan Steele +Gaël Portay +galen11 on github Gambit Communications Ganesh Kamath +Ganesh Viswanathan +Gao Liyou gaoxingwang on github Garrett Holmstrom Garrett Squire @@ -940,17 +1210,17 @@ Gautam Mani Gavin Wong Gavrie Philipson Gaz Iqbal -Gaël Portay gclinch on github Gealber Morales Geeknik Labs Geoff Beier Georeth Zhou +George Liu Georg Horn Georg Huettenegger Georg Lippitsch +Georg Schulz-Allgaier Georg Wicherski -George Liu Gerd v. Egidy Gergely Nagy Gerhard Herre @@ -960,11 +1230,11 @@ Gerrit Renker Ghennadi Procopciuc Giancarlo Formicuccia Giaslas Georgios -Gil Weber Gilad Gilbert Ramirez Jr. Gilles Blanc Gilles Vollant +Gil Weber Giorgos Oikonomou Gisle Vanem git-bruh on github @@ -972,116 +1242,153 @@ GitYuanQu on github Giuseppe Attardi Giuseppe D'Ambrosio Giuseppe Persico +gkarracer on github Gleb Ivanovsky Glen A Johnson Jr. Glen Nakamura -Glen Scott Glenn de boer Glenn Sheridan Glenn Strauss +Glen Scott godmar on github Godwin Stewart +Gökhan Åžengün +Gonçalo Carvalho +Google Big Sleep Google Inc. Gordon Marler +Gordon Parke Gorilla Maguila Goro FUJI +Götz Babin-Ebell Gou Lingfeng Graham Campbell +Graham Christensen Grant Erickson Grant Pannell +graywolf on github Greg Hewgill +Greg Hudson +Greg Kroah-Hartman Greg Morse Greg Onufer -Greg Pratt -Greg Rowe -Greg Zavertnik Gregor Jasny Gregory Jefferis Gregory Muchka Gregory Nicholls Gregory Panakkal Gregory Szorc +Greg Pratt +Greg Rowe +Greg Zavertnik Griffin Downs Grigory Entin Grisha Levit +Gruber Glass +Guancheng Li +Guannan Wang +gudyuu on hackerone Guenole Bescon Guido Berhoerster +Guilherme Puida Guillaume Algis Guillaume Arluison guitared on github Gunamoi Software +Gunni on github Gunter Knauf guoxinvmware on github Gustaf Hui Gustavo Grieco +Gusted Guy Poizat GwanYeong Kim -Gwen Shapira Gwenole Beauchesne -Gökhan Åžengün -Götz Babin-Ebell +Gwen Shapira h1zzz on github H3RSKO on github Hagai Auro Haibo Huang +Hakan Sunay Halil Hamish Mackenzie +hammlee96 on github hamstergene on github -Han Han -Han Qiao +Hamza Bensliman Hang Kin Lau Hang Su +Han Han Hannah Schierling Hannes Magnusson Hanno Böck Hanno Kranzhoff -Hans Steegers +Han Qiao +Hans-Christian Egtvedt Hans-Christian Noren Egtvedt Hans-Jurgen May +Hans Steegers Hao Wu Hardeep Singh Haris Okanovic +Harmen Stoppels Harold Stuart +Harry Mallon Harry Sarson Harry Sintonen Harshal Pradhan Hauke Duden +Haydar Alaidrus Hayden Roche -He Qin Heikki Korpela Heinrich Ko Heinrich Schaefer Helge Klein +Helmut Grohne Helmut K. C. Tessarek Helwing Lutz +Hem Parekh Hendrik Visage Henning Schild Henri Gomez Henrik Gaßmann Henrik Holst +henrikjehgmti on github Henrik Storner +Henrique Pereira Henry Ludemann Henry Roeland +He Qin +herbenderbler on github +herdiyanitdev on hackerone +Hermes Zhang Herve Amblard HexTheDragon +hgdagon on github Hide Ishikawa Hidemoto Nakada highmtworks on github +hiimmat on github Himanshu Gupta Hind Montassif Hiroki Kurosawa Hirotaka Tagawa Ho-chi Chen Hoi-Ho Chan +Hongfei Li Hongli Lai Hongyi Zhao Howard Blaise Howard Chu hsiao yi +HsiehYuho on github +htasta htasta on github +huanghuihui0904 Hubert Kario Hugh Macdonald Hugo van Kemenade humbleacolyte +Hunt Darlener +Huseyin Tintas Huzaifa Sidhpurwala huzunhao on github hydra3333 on github @@ -1096,7 +1403,12 @@ Ian Lynagh Ian Spence Ian Turner Ian Wilkes +iAroc on github +IcedCoffeee on github +iconoclasthero +icy17 on github Ignacio Vazquez-Abrams +Ignat Loskutov Igor Franchuk Igor Khristophorov Igor Makarov @@ -1115,13 +1427,15 @@ Ilmari Lauhakangas Ilya Kosarev imilli on github Immanuel Gregoire -ImpatientHippo on GitHub +ImpatientHippo on github Inca R infinnovation-dev on github Ingmar Runge Ingo Ralf Blum Ingo Wilken Inho Oh +Int64x86 on github +IoannisGS on github IonuÈ›-Francisc Oancea Irfan Adilovic Ironbars13 on github @@ -1129,19 +1443,26 @@ Irving Wolfe Isaac Boukris Isaiah Norton Ishan SinghLevett +İsmail Dönmez +Itay Bookstein Ithubg on github +Ivan Ivan Avdeev -Ivan Tsybulin +ivanfywang +Ivan Kuchin IvanoG on github +Ivan Tsybulin Ivo Bellin Salarin iz8mbw on github -J. Bromley -Jack Boos Yu -Jack Zhang +Izan on hackerone +Jacek Migacz Jackarain on github JackBoosY on github +Jack Boos Yu Jacky Lam +Jack Zhang Jacob Barthelmeh +Jacob Champion Jacob Hoffman-Andrews Jacob Mealey Jacob Meuser @@ -1150,11 +1471,15 @@ Jacob Tolar Jactry Zeng Jad Chamcham Jaime Fullaondo +Jake Yuesong Li jakirkham on github Jakob Hirsch Jakub Bochenski +Jakub Jelen +Jakub Stasiak Jakub Wilk Jakub Zakrzewski +James Abbatiello James Atwill James Brown James Bursa @@ -1176,22 +1501,25 @@ Jamie Lokier Jamie Newton Jamie Wilkinson Jan Alexander Steffens +JanB on github Jan Chren +janedenone on github Jan Ehrhardt Jan Engelhardt Jan Koen Annot +janko-js on github Jan Kunder Jan Macku Jan Mazur +Janne Blomqvist +Janne Johansson +János Fekete +Jan-Piet Mens Jan Schaumann Jan Schmidt Jan Van Boghout Jan Venekamp Jan Verbeek -Jan-Piet Mens -JanB on github -Janne Blomqvist -Janne Johansson Jared Jennings Jared Lundell Jari Aalto @@ -1199,11 +1527,13 @@ Jari Sundell jasal82 on github Jason Baietto Jason Glasgow +Jason Hood Jason Juang Jason Lee Jason Liu Jason McDonald Jason S. Priebe +Jason Stangroome Javier Barroso Javier Blazquez Javier G. Sogo @@ -1212,15 +1542,19 @@ Javier Sixto Jay Austin Jay Dommaschk Jayesh A Shah +Jay Guerette +Jay Wu Jaz Fresh JazJas on github jbgoog on github -Jean Fabrice -Jean Gressmann -Jean Jacques Drouin +J. Bromley +Jean-Christophe Amiel Jean-Claude Chauve +Jean Fabrice Jean-Francois Bertrand Jean-Francois Durand +Jean Gressmann +Jean Jacques Drouin Jean-Louis Lemaire Jean-Marc Ranger Jean-Noël Rouvignac @@ -1228,6 +1562,7 @@ Jean-Philippe Barrette-LaPierre Jean-Philippe Menil Jeff Connelly Jeff Hodges +jeffhuang Jeff Johnson Jeff King Jeff Lawson @@ -1235,27 +1570,33 @@ Jeff Luszcz Jeff Mears Jeff Phillips Jeff Pohlmeyer -Jeff Weber Jeffrey Tolar Jeffrey Walton jeffrson on github +Jeff Weber +Jelle Raaijmakers Jelle van der Waa Jenny Heino Jens Finkhaeuser Jens Rantil Jens Schleusener Jeremie Rapin +Jeremy Drake Jeremy Falcon Jeremy Friesner Jeremy Huddleston Jeremy Lainé Jeremy Lin Jeremy Maitin-Shepard +Jeremy Nicoll Jeremy Pearson +Jérémy Rabasco +Jérémy Rocher Jeremy Tan Jeremy Thibault Jeroen Koekkoek Jeroen Ooms +Jérôme Leclercq Jerome Mao Jerome Muffat-Meridol Jerome Robert @@ -1268,46 +1609,70 @@ Jesper Jensen Jesse Chisholm Jesse Noller Jesse Tan +Jess Lowe +Jesus Malo Poyatos jethrogb on github +jhauga jhoyla on github +Jiacai Liu +Jiang Wenjian +Jiashuo Liang +Jiawen Geng +Jicea Jie He +Jiehong on github Jilayne Lovejoy Jim Beveridge Jim Drash Jim Freeman -Jim Fuller Jim Hollinger Jim King Jim Meyering Jimmy Gaussen +Jimmy Sjölund +Jiří Bok Jiri Dvorak Jiri Hruska Jiri Jaburek -Jishan Shaikh Jiří Malák +Jiri Stary +Jishan Shaikh +Jiwoo Park +Jixinqi +Jiyong Yang +jjchuck on hackerone +jkamp-aws on github +jmaggard10 on github jmdavitt on github jnbr on github Jocelyn Jaubert Jochem Broekhoff +Jochen Sprickerhof +Joe Birr-Pixton +Joe Cise Joe Halpin -Joe Malicki -Joe Mason +JoelAtWisetech on github Joel Chen Joel Depooter Joel Jakobsson Joel Teichroeb +Joe Malicki +Joe Mason joey-l-us on github Jofell Gallardo Johan Anderson +Johan Eliasson Johan Lantz -Johan Nilsson -Johan van Selst Johann150 on github Johannes Bauer Johannes Ernst Johannes G. Kristinsson Johannes Lesr Johannes Schindelin +Johannes Schlatow +Johan Nilsson +Johann Sebastian Schicho +Johan van Selst John A. Bristor John Bampton John Bradshaw @@ -1320,10 +1685,10 @@ John Dennis John Dunn John E. Malmberg John Gardiner Myers -John H. Ayad John Hascall John Haugabook John Hawthorn +John H. Ayad John Janssen John Joseph Bachir John Kelly @@ -1332,10 +1697,13 @@ John Lask John Levon John Lightsey John Marino +John-Mark Bell John Marshall John McGowan +Johnny Luong John P. McCaskey John Porter +John Rodriguez John Schroeder John Sherrill John Simpson @@ -1346,13 +1714,31 @@ John Walker John Wanghui John Weismiller John Wilkinson -John-Mark Bell -Johnny Luong Jojojov on github +Jonas Bülow +Jonas Forsman +Jonas Haag +Jonas Minnberg +Jonas Schnelli +Jonas 'Sortie' Termansen +Jonas Vautherin +Jonatan Lander +Jonatan Vela +Jonathan Cardoso Machado +Jonathan Hseu +Jonathan Matthews +Jonathan Moerman +Jonathan Nieder +Jonathan Perkin +Jonathan Rosa +Jonathan Watt +Jonathan Wernberg Jon DeVree +Jongki Suwandi Jon Grubbs Jon Johnson Jr Jon Nelson +jonny112 on github Jon Rumsey Jon Sargeant Jon Seymour @@ -1361,45 +1747,37 @@ Jon Torrey Jon Travis Jon Turner Jon Wilkes -Jonas Bülow -Jonas Forsman -Jonas Haag -Jonas Minnberg -Jonas Schnelli -Jonas Vautherin -Jonatan Lander -Jonatan Vela -Jonathan Cardoso Machado -Jonathan Hseu -Jonathan Moerman -Jonathan Nieder -Jonathan Watt -Jonathan Wernberg -Jongki Suwandi -jonny112 on github Joombalaya on github Joonas Kuorilehto Jordan Brown +Jörg Mueller-Tolk +Jörn Hartroth Jose Alf -Jose Kahan +Josef Cejka Josef Wolf +José Joaquín Atria +Jose Kahan +Joseph Birr-Pixton Joseph Chen Joseph Tharayil Josh Bialkowski Josh Brobst +joshhe on github +Joshix-1 on github Josh Kapell Josh McCullough Josh Soref -joshhe on github Joshua Kwan +Joshua Rogers Joshua Root Joshua Swink +Joshua Vandaële Josie Huddleston Josip Medved Josue Andrade Gomes -José Joaquín Atria Jozef Kralik Juan Barreto +Juan Belón Juan Cruz Viotti Juan F. Codagnone Juan Ignacio Hervás @@ -1408,6 +1786,7 @@ Judson Bishop Juergen Hoetzel Juergen Wilke Jukka Pihl +Julian K. Julian Montes Julian Noble Julian Ospald @@ -1417,12 +1796,14 @@ Julian Z Julien Chaffraix Julien Nabet Julien Royer -Jun Tseng -Jun-ichiro itojun Hagino -Jun-ya Kato +Juliusz Sosinowicz jungle-boogie on github Junho Choi +Jun-ichiro itojun Hagino junsik on github +Jun Tseng +Jun-ya Kato +Jürgen Gmach Jurij Smakov jurisuk on github Juro Bystricky @@ -1433,42 +1814,46 @@ Justin Ehlert Justin Fletcher Justin Karneges Justin Maggard +Justin Steventon jveazey on github jvreelanda on github jvvprasad78 on github jzinn on github -János Fekete -Jérémy Rabasco -Jérémy Rocher -Jörg Mueller-Tolk -Jörn Hartroth -Jürgen Gmach -K. R. Walker ka7 on github +Kadambini Nema Kael1117 on github Kai Engert +Kailun Qin Kai Noda Kai Pastor Kai Sommerfeld Kai-Uwe Rommel +Kaixuan Li Kalle Vahlman +kalvdans on github Kamil Dudka Kane York -Kang Lin Kang-Jin Lee +Kang Lin Kantanat Wannapaka +kapsiR on github +Kareem Kari Pahula Karl Chen Karl Moerder Karol Pietrzak -Karthikdasari0423 +Kartatz on github +Karthik Das +Karthik Dasari Karthikdasari0423 on github Kartik Mahajan Kaspar Brand Katie Wang Katsuhiko YOSHIDA +kayrus on github Kazuho Oku kchow-FTNT on github +Keerthi Timmaraju Kees Cook Kees Dekker Keitagit-kun on github @@ -1478,17 +1863,18 @@ Keith Mok Kelly Kaoudis Ken Brown Ken Hirsch -Ken Rastatter Kenneth Davidson Kenneth Myhra Kenny To +Keno Fischer +Ken Rastatter Kent Boortz Kerem Kat Keshav Krity -Kev Jackson Kevin Adler Kevin Baughman Kevin Burke +Kevin Daudt Kevin Fisk Kevin Ji Kevin Lussier @@ -1497,15 +1883,22 @@ Kevin Reed Kevin Roth Kevin Ryan Kevin Smith +Kevin Sun Kevin Ushey +Kev Jackson Kim Minjoong +Kimmo Kinnunen Kim Rinnewitz Kim Vandry -Kimmo Kinnunen +kirbyn17 on hackerone Kirill Efimov Kirill Marchuk +Kirill Obukhov +kit-ty-kate on github Kjell Ericson Kjetil Jacobsen +kkalganov on github +kkmuffme on github Klaus Crusius Klaus Stein Klevtsov Vadim @@ -1515,32 +1908,41 @@ Koichi Shiraishi kokke on github Konstantin Isakov Konstantin Kushnir +Konstantin Kuzov +Konstantin Vlasov KotlinIsland on github kotoriã®ã­ã“ +koujaz on github kouzhudong on github Kovalkov Dmitrii +kpcyrd on github kreshano on github -Kris Kennaway Krishnendu Majumdar +Kris Kennaway Krister Johansen Kristian Gunstone Kristian Köhntopp Kristian Mide Kristiyan Tsaklev Kristoffer Gleditsch +kriztalz +K. R. Walker +Kuan-Wei Chiu +kuchara on github Kunal Chandarana Kunal Ekawde +kupavcevdenis on github Kurt Fankhauser Kushal Das Kvarec Lezki kwind on github Kwon-Young Choi Kyle Abramowitz +kyled-dell on github Kyle Edwards Kyle J. McKay Kyle L. Huff Kyle Sallee -kyled-dell on github Kyohei Kadota Kyselgov E.N l00p3r on Hackerone @@ -1554,37 +1956,48 @@ Larry Lin Larry Stefani Larry Stone Lars Buitinck +Lars Francke Lars Gustafsson Lars J. Aas Lars Johannesen +Lars Karlitski +Lars Kellogg-Stedman Lars Nilsson Lars Torben Wilson +Lau Laurent Bonnans Laurent Dufresne +LaurenÈ›iu Nicola Laurent Rabret -Lauri Kasanen Laurie Clark-Michalek +Lauri Kasanen Lawrence Gripper Lawrence Matthews Lawrence Wagerfield Leah Neukirchen +Lealem Amedie Leandro Coutinho +Lee Li +LeeRiva Legoff Vincent Lehel Bernadt Leif W Leigh Purdie Leith Bade +Lenaic Lefever Len Krause Len Marinaccio -Lenaic Lefever Lenny Rachitsky -Leo Neat -Leon Breedt -Leon Winter Leonardo Rosati Leonardo Taccari +Leon Breedt +Leo Neat +Leon Timmermans +Leon Winter Leszek Kubik -Li Xinwei +letshack9707 on hackerone +lf- on github +lg_oled77c5pua on hackerone Liam Healy Liam Warfield LigH-de on github @@ -1595,6 +2008,7 @@ Linas Vepstas Lindley French Ling Thio Linos Giannopoulos +Lin Sun Linus Lewandowski Linus Nielsen Feltzing Linus Nordberg @@ -1602,23 +2016,35 @@ Lior Kaplan Lisa Xu Litter White Liviu Chircu +Li Xinwei Liza Alenchery lizhuang0630 on github +lkordos on github lllaffer on github Lloyd Fournier Lluís Batlle i Rossell locpyl-tidnyd on github Loganaden Velvindron +Logan Buth Loic Dachary +Loïc Yhuel +lolbinarycat on github +lomberd2 on github +LoRd_MuldeR Loren Kirkby Lorenzo Miniero +Louis Solofrizzo +lRoccoon on github Luan Cestari +Luật Nguyá»…n Luca Altea Luca Boccassi +Luca Kellermann Luca Niccoli Lucas Adamski Lucas Clemente Vella Lucas Holt +Lucas Nussbaum Lucas Pardue Lucas Servén Marín Lucas Severo @@ -1628,66 +2054,81 @@ Ludovico Cavedon Ludwig Nussel Lukas Ruzicka Lukas Tribus +Lukáš Zaoral Lukasz Czekierda +Åukasz Domeradzki lukaszgn on github Luke Amery Luke Call Luke Dashjr Luke Granger-Brown +Luke Hamburg +Luke Wilde luminixinc on github Luo Jinghua Luong Dinh Dung Luz Paz -Luật Nguyá»…n lwthiker on github Lyman Epp Lyndon Hill -M.R.T on github +M42kL33 on hackerone +m777m0 on hackerone +Maarten Billemont Maciej Domanski Maciej Karpiuk Maciej Puzio Maciej W. Rozycki +MacKenzie madblobfish on github +madoe on github MaeIsBad on github +magisterquis on hackerone Mahmoud Samir Fayed -Maks Naumov Maksim Arhipov Maksim Kuzevanov -Maksim Sciepanienka +Maksim Åšciepanienka Maksim Stsepanenka +Maks Naumov +Maksymilian Arciemowicz Malik Idrees Hasan Khan Mamoru Tasaka Mamta Upadhyay Mandy Wu Manfred Schwarb +Manuel Einfalt Manuel Massing +Manuel Strehl Manuj Bhatia Marc Aldorasi +Marc-Antoine Perennou Marc Boucher Marc Deslauriers Marc Doughty -Marc Hesse -Marc Hörsken -Marc Kleine-Budde -Marc Renault -Marc Schlatter -Marc-Antoine Perennou -marc-groundctl on github Marcel Hernandez -Marcel Raad -Marcel Roelofs +Marcel Lang Marcelo Echeverria Marcelo Juchem +Marcel Raad +Marcel Roelofs +marc-groundctl on github +Marc Hesse +Marc Hörsken Marcin Adamski Marcin Gryszkalis Marcin Konicki +Marcin Rataj +Marc Kleine-Budde Marco Deckel Marco G. Salvagno Marco Kamner Marco Maggi Marcos Diazr +marcos-ng on github +Marc Renault +Marc Schlatter Marcus Hoffmann Marcus Klein +Marcus Müller Marcus Sundberg Marcus T Marcus Webster @@ -1695,25 +2136,29 @@ Margu Marian Klymov Marin Hannache Mario Schroeder +Marius Albrecht +Marius Kleidl Mark Brand Mark Butler Mark Davies Mark Dodgson +Mark Esler Mark Gaiser Mark Hamilton +Mark Huang Mark Incley Mark Itzcovitz Mark Karpeles Mark Lentczner Mark Nottingham +Mark Phillips Mark Roszko Mark Salisbury Mark Seuffert +Mark Sinkovics Mark Snelling Mark Swaanenburg Mark Tully -Mark W. Eichin -Mark Wotton Markus Duft Markus Elfring Markus Koetter @@ -1721,11 +2166,15 @@ Markus Moeller Markus Oberhumer Markus Olsson Markus Sommer +Markus Unterwaditzer Markus Westerlind +Mark W. Eichin +Mark Wotton Maros Priputen Marquis de Muesli marski on github Martijn Koster +Martin Ã…gren Martin Ankerl Martin BaÅ¡ti Martin C. Martin @@ -1733,17 +2182,22 @@ Martin D'Aloia Martin Dorey Martin Drasar Martin Dreher +Martin Dürrmeier +martinevsky Martin Frodl Martin Galvan Martin Gartner Martin Hager Martin Halle +Martin Harrigan Martin Hedenfalk Martin Howarth Martin Jansen Martin Kammerhofer Martin Kepplinger Martin Lemke +Martin Peck +Martin Schmatz Martin Skinner Martin Staael Martin Storsjö @@ -1751,38 +2205,35 @@ Martin Strunz Martin V Martin Vejnár Martin Waleczek -Martin Ã…gren +Martxel Marty Kuhrt Maruko +Marwan Yassini Masaya Suzuki masbug on github Massimiliano Fantuzzi Massimiliano Ziccardi Massimo Callegari -Master Inspire MasterInQuestion on github +Master Inspire Mateusz Loskot +Mathesh V Mathew Benson Mathias Axelsson +Mathias Fuchs Mathias Gumz Mathieu Carbonneaux +Mathieu Garaud Mathieu Legare Matias N. Goldberg Mats Lidell Mats Lindestam Matt Arsenault -Matt Ford -Matt Holt -Matt Jolly -Matt Kraai -Matt McClure -Matt Veenstra -Matt Witherspoon -Matt Wixson Matteo Baccan Matteo Bignotti Matteo Bignottignotti Matteo Rocco +Matt Ford Matthew Blain Matthew Clarke Matthew Hall @@ -1792,13 +2243,31 @@ Matthew Whitehead Matthias Bolte Matthias Gatto Matthias Naegler +Matthieu Baerts +Matt Holt Mattias Fornander +Matt Jolly +Matt Kraai +Matt McClure +Matt Veenstra +Matt Witherspoon +Matt Wixson Matus Uzak +mauke Maurice Barnum +Maurício Meneghini Fauth +Mauricio Scheffer Mauro Iorio Mauro Rappa -Maurício Meneghini Fauth Max Dymond +Max Eliaser +Max Faxälv +Maxim Dzhura +Maxime Larocque +Maxime Legros +Maxim Ivanov +Maxim Perenesenko +Maxim Prohorov Max Katsev Max Kellermann Max Khon @@ -1806,22 +2275,20 @@ Max Mehl Max Peal Max Savenkov Max Zettlmeißl -Maxim Ivanov -Maxim Perenesenko -Maxim Prohorov -Maxime Larocque -Maxime Legros mbeifuss on github mccormickt12 on github Median Median Stride +Megamouse on github mehatzri on github Mehmet Bozkurt +Mehtab Zafar Mekonikum Melissa Mears Melroy van den Berg +Mel Zuser Mert YazıcıoÄŸlu Mettgut Jamalla -Micah Snyder) +Micah Snyder Michael Afanasiev Michael Anti Michael Baentsch @@ -1838,6 +2305,7 @@ Michael Forney Michael Gmelin Michael Goffioul Michael Heimpold +Michael Hendricks Michael Hordijk Michael Jahn Michael Jerris @@ -1845,9 +2313,10 @@ Michael Kalinin Michael Kaufmann Michael Kilburn Michael Kolechkin -Michael Kujawa Michael König +Michael Kujawa Michael Lee +Michael Litwak Michael Maltese Michael Mealling Michael Mueller @@ -1856,6 +2325,7 @@ Michael O'Farrell Michael Olbrich Michael Osipov Michael Schmid +Michael Schuster Michael Smith Michael Stapelberg Michael Steuer @@ -1863,24 +2333,25 @@ Michael Stillwell Michael Trebilcock Michael Vittiglio Michael Wallner -Michal Bonino -Michal Marek -Michal Rus -Michal Trybus -Michal ÄŒaplygin MichaÅ‚ Antoniak +Michal Bonino +Michal ÄŒaplygin MichaÅ‚ Fita MichaÅ‚ Górny MichaÅ‚ Janiszewski MichaÅ‚ Kowalczyk +Michal Marek MichaÅ‚ Petryka MichaÅ‚ Piechowski -Michel Promonet +Michal Rus +Michal Trybus Michele Bini +Michel Promonet Miguel Angel Miguel Diaz migueljcrum on github Mihai Ionescu +mik Mikael Johansson Mikael Sennerholm Mikalai Ananenka @@ -1895,6 +2366,7 @@ Mike Giancola Mike Hasselberg Mike Henshaw Mike Hommey +Mike-menny on github Mike Mio Mike Norton Mike Power @@ -1903,12 +2375,14 @@ Mike Revi Mike Tzou Mikhail Kuznetsov Miklos Nemeth +Milon Renatus MiloÅ¡ Ljumović Mingliang Zhu Mingtao Yang Miroslav Franc Miroslav Spousta Mischa Salle +Mitchell Blank Jr Mitz Wark mkzero on github modbw on github @@ -1917,20 +2391,31 @@ Mohamed Lrhazi Mohamed Osama Mohammad AlSaleh Mohammad Hasbini +Mohammadreza Hendiani Mohammed Naser +Mohammed Sadiq Mohun Biswas momala454 on github Momoka Yamamoto MonkeybreadSoftware on github +Montg0mery on github moohoorama on github +Morgan Willcock +Moritz +Moritz Buhl +Moritz Knüsel Morten Minde Neergaard Mostyn Bramley-Moore Moti Avrahami MrdUkk on github MrSorcus on github +M.R.T on github +mschroeder-fzj on github +Muhamad Arga Reksapati Muhammad Herdiansyah Muhammad Hussein Ammari Muhammed Yavuz Nuzumlalı +mulan_dh on hackerone Murugan Balraj musvaage on github Muz Dima @@ -1938,18 +2423,24 @@ Myk Taylor n0name321 on github Nach M. S. Nagai H -Nao Yonashiro +nait-furry naost3rn on github +Nao Yonashiro +Natanael Copa Nate Prewitt -Nathan Coulter -Nathan Moinvaziri -Nathan O'Sullivan Nathanael Nerode +Nathan Coulter Nathaniel J. Smith Nathaniel R. Lewis Nathaniel Waisbrot +Nathan-M-code on github +Nathan Moinvaziri +Nathan O'Sullivan +Natris on github +na-trium-144 on github Naveen Chandran Naveen Noel +ncaklovic on github Neal McBurnett Neal Poole nedres on github @@ -1958,16 +2449,24 @@ Nehal J Wani neheb on github Neil Bowers Neil Dunbar +Neil Horman +Neil Johari Neil Kolban Neil Spring +NeimadTL +nekopsykose on github +Nemos2024 on github +netspacer.research neutric on github +nevakrien on github nevv on HackerOne/curl +newfunction +newfunction on hackerone +Ngoc Hieu Niall McGee Niall O'Reilly -niallor on github nian6324 on github nianxuejie on github -Nic Roets Nicholas Maniscalco Nicholas Nethercote Nick Banks @@ -1975,58 +2474,74 @@ Nick Coghlan Nick Draffen Nick Gimbrone Nick Humfrey -Nick Miyake -Nick Zitzmann -nick-telia on github +Nick Korepanov Nicklas Avén -Nico Baggus +Nick Miyake +nick-telia on github +Nick Zitzmann nico-abram on github +Nico Baggus Nicolas Berloquin Nicolas Croiset +Nicolas F. Nicolas François +Nicolas George Nicolas Grekas Nicolas Guillier Nicolas Morey-Chaisemartin Nicolas Noben -Nicolas Sterchele Nicolás Ojeda Bär +Nicolás San Martín +Nicolas Sterchele +Nico Rieck +Nic Roets Niels Martignène Niels van Tongeren +Nigel Brittain Nikita Schmidt +Nikita Taranov Nikitinskit Dmitriy Niklas Angebrand Niklas Hambüchen Nikolai Kondrashov Nikos Mavrogiannopoulos Nikos Tsipinakis +Nils Goroll nimaje on github niner on github Ning Dong -Nir Soffer +NINIKA +Niracler Li Niranjan Hasabnis +Nir Azkiel +Nir Soffer Nis Jorgensen +nitrogene on github nk Noam Moshe nobedee on github NobodyXu on github Nobuhiro Ban Nodak Sodak +nono303 on github nopjmp on github Norbert Frese Norbert Kett -Norbert Novotny norbertmm on github +Norbert Novotny nosajsnikta on github -NTMan on Github +NTMan on github +Nuno Goncalves Nuru on github Octavio Schroeder odek86 on github Ofer +ohyeaah on github Okhin Vasilij -Ola Mork Olaf Flebbe Olaf Hering Olaf Stüben +Ola Mork Oleg Jukovec Oleg Pudeyev Oleguer Llopart @@ -2037,18 +2552,23 @@ Oliver Chang Oliver Gondža Oliver Graute Oliver Kuckertz +oliverpool on github Oliver Roberts Oliver Schindler Oliver Urbann -oliverpool on github Olivier Berger +Olivier Bonaventure Olivier Brunel Omar Ramadan omau on github +Omdahake on github +OndÅ™ej Hlavatý OndÅ™ej KoláÄek opensignature on github opensslonzos-github on github +Ophir Lojkine Orange Tsai +oreadvanthink on github Oren Souroujon Oren Tirosh Orgad Shaneh @@ -2057,27 +2577,32 @@ orycho on github osabc on github Osaila on github Osama Albahrani +Osama Hamad Oscar Koeroo Oscar Norlander Oskar Liljeblad Oskar Sigvardsson +Otis Cui Lei Oumph on github +Outvi V ovidiu-benea on github -P R Schaffner +Oxan van Leeuwen +Ozan Cansel Pablo Busse Palo Markovic pandada8 on github Paolo Mossino Paolo Piacentini +parasol-aser Paras Sethia parazyd on github Pascal Gaudette Pascal Terjan Pasha Kuznetsov Pasi Karkkainen -Pat Ray patelvivekv1993 on github patnyb on github +Pat Ray Patrice Guerin Patricia Muscalu Patrick Bihan-Faou @@ -2088,12 +2613,15 @@ Patrick Rapin Patrick Schlangen Patrick Scott Patrick Smith +Patrick Steinhardt +Patrick Stoeckle Patrick Watson Patrik Thunstrom Pau Garcia i Quiles Paul B. Omta Paul Donohue Paul Dreik +Paul Gilmartin Paul Groke Paul Harrington Paul Harris @@ -2106,18 +2634,20 @@ Paul Marquis Paul Moore Paul Nolan Paul Oliver +Paulo Roberto Tomasi Paul Querna Paul Saab Paul Seligman Paul Vixie Paul Wise -Paulo Roberto Tomasi Pavel Cenek Pavel Gushchin Pavel Kalyugin +Pavel Kropachev Pavel Löbl Pavel Mayorov Pavel Orehov +Pavel P Pavel Pavlov Pavel Raiskup Pavel Rochnyak @@ -2127,17 +2657,24 @@ Pawel A. Gajda Pawel Kierski PaweÅ‚ Kowalski PaweÅ‚ Wegner +PaweÅ‚ Witas +PBudmark on github Pedro Henrique Pedro Larroy Pedro Monreal Pedro Neves +pelioro on hackerone pendrek at hackerone Peng Li Peng-Yu Chen +pennae on github +penpal Per Jensen Per Lundberg Per Malmberg Per Nilsson +Petar Popovic +Pete Cordell Pete Lomax Peter Bray Peter Forret @@ -2146,11 +2683,16 @@ Peter Gal Peter Goodman Peter Heuchert Peter Hjalmarsson -Peter Korsgaard +PÄ“teris Caune +Peteris Krumins +Peter Kokot Peter Körner +Peter Korsgaard +Peter Krefting Peter Lamare Peter Lamberg Peter Laser +Peter Marko Peter O'Gorman Peter Pentchev Peter Piekarski @@ -2165,44 +2707,52 @@ Peter Verhas Peter Wang Peter Wu Peter Wullinger -Peteris Krumins Petr Bahula Petr Novak Petr Pisar -Petr Voytsik Petr Å tetiar +Petr Voytsik Phil Blundell Phil Crump Phil E. Taylor -Phil Karn -Phil Lisiecki -Phil Pellouchoud Philip Chan Philip Craig Philip Gladstone +Philip H. Philip Heiduck Philip Langdale -Philip Prindeville -Philip Sanetra -Philipp Engel -Philipp Klaus Krause -Philipp Waehnert +Philippe Antoine Philippe Antoine on HackerOne Philippe Hameau Philippe Marguinaud +Philipp Engel Philippe Raoult Philippe Vaucher +Philipp Klaus Krause +Philip Prindeville +Philipp Waehnert +Philip Sanetra +Phil Karn +Phil Lisiecki +Phil Pellouchoud Pierre Pierre Brico Pierre Chapuis +Pierre-Etienne Meunier Pierre Joye Pierre Yager Pierre Ynard Pierre-Yves Bigourdan Pierrick Charron +Pino Toscano Piotr Dobrogost Piotr Komborski +Piotr Nakraszewicz +PleaseJustDont +plv1313 on github Po-Chuan Hsieh +Pocs Norbert +pojomi Pontakorn Prasertsuk Pontus Lundkvist Pooyan McSporran @@ -2214,58 +2764,76 @@ Prithvi MK privetryan on github Priyanka Shah ProceduralMan on github +programmerlexi on github +promptfuzz_ on hackerone Pronyushkin Petr +prpr19xx on github +P R Schaffner PrzemysÅ‚aw Tomaszewski pszemus on github pszlazak on github puckipedia on github Puneet Pawaia +qhill +qhill on github qiandu2006 on github +Qriist on github +Quac Tran Quagmire Quanah Gibson-Mount Quentin Balland Quinn Slack -r-a-sattarov on github -R. Dennis Steed Radek Brich Radek Zajic Radoslav Georgiev Radu Hociung Radu Simionescu -Rafa Muyo Rafael Antonio -Rafael Sagula -Rafayel Mkrtchyan Rafaël Carré +Rafael Sagula RafaÅ‚ Mikrut +Rafa Muyo +Rafayel Mkrtchyan +Rahul Krishna M Rainer Canavan Rainer Jung Rainer Koenig Rainer Müller +RainRat Raito Bezarius Rajesh Naganathan Rajkumar Mandal +Ralf A. Timmermann +ralfjunker on github Ralf S. Engelschall Ralph Beckmann Ralph Langendam Ralph Mitchell +Ralph Sennhauser +Ramiro Garcia Ram Krushna Mishra +rampageX on github ramsay-jones on github -Ran Mozes RanBarLavie on github Randall S. Becker Randolf J Randy Armstrong Randy McMurchy +Ran Mozes Raphael Gozzo +r-a-sattarov on github Rasmus Melchior Jacobsen +Rasmus Thomsen Raul Onitza-Klugman Ravi Pratap Ray Dassen +Raymond Steen Ray Pekowski Ray Satiro Razvan Cojocaru +Razvan Pricope rcombs on github +R. Dennis Steed Red Hat Product Security Reed Loden Reinhard Max @@ -2274,6 +2842,7 @@ RekGRpth on github Remco van Hooff Remi Gacogne Remo E +Rémy Léone Renato Botelho Renaud Allard Renaud Chaillat @@ -2282,20 +2851,19 @@ Renaud Guillard Renaud Lehoux Rene Bernhardt Rene Rebe +renjian on hackerone +renovate[bot] +renovate[bot] +RepoRascal on hackerone Reuven Wachtfogel +RevaliQaQ on github Reza Arbab Rianov Viacheslav +riastradh on github Ricardo Cadime Ricardo Gomes -Ricardo M. Correia Ricardo Martins -Rich Burridge -Rich FitzJohn -Rich Gray -Rich Mirch -Rich Rauenzahn -Rich Salz -Rich Turner +Ricardo M. Correia Richard Adams Richard Alcock Richard Archer @@ -2308,68 +2876,88 @@ Richard Gorton Richard Gray Richard Hosking Richard Hsu +Richard Levitte Richard Marion Richard Michael Richard Moore Richard Prescott Richard Silverman +Richard Tollerton Richard van den Berg -Richard W.M. Jones Richard Whitehouse +Richard W.M. Jones +Rich Burridge +Rich FitzJohn +Rich Gray +Rich Mirch +Rich Rauenzahn +Rich Salz +Rich Turner Richy Kim Rici Lake +Rickard Hallerbäck Rick Deist +Ricki Hirner Rick Jones Rick Lane Rick Richardson Rick Welykochy -Rickard Hallerbäck -Ricki Hirner Ricky Leverence Ricky-Tigg on github -Rider Linden RiderALT on github +Rider Linden Rikard Falkeborn +rilysh +Rinku Das +rinsuki on github rl1987 on github +rmg-x on github +rm-rmonaghan on github Rob Boeckermann +RobBotic1 on github +Robby Simpson Rob Cotrone Rob Crittenden Rob Davies Rob de Wit -Rob Jones -Rob Sanders -Rob Stanzel -Rob Ward -RobBotic1 on github -Robby Simpson Robert A. Monat Robert B. Harris Robert Brose Robert Charles Muir -Robert D. Young Robert Dunaj +Robert D. Young Robert Foreman Robert Iakobashvili Robert Kolcun Robert Linden +Robert Maynard +Robert Moreton +Roberto Hidalgo Robert Olson Robert Prag Robert Ronto Robert Schumann +Robert Simpson +Robert Southee Robert Weaver Robert Wruck +Robert W. Van Kirk Robin A. Meade Robin Cornelius Robin Douine Robin Johnson Robin Kay Robin Marx +Rob Jones +Rob Sanders Robson Braga Araujo -Rod Widdowson +Rob Stanzel +Rob Ward Rodger Combs Rodney Simmons Rodric Glaser Rodrigo Silva +Rod Widdowson Roger Leigh Roger Orr Roger Young @@ -2385,12 +2973,14 @@ Romain Geissler romamik om github Roman Koifman Roman Mamedov +Roman Zharkov Romulo A. Ceccon +Ronald Crane +Ronan Pigott Ron Eldor +Ronnie Mose Ron Parker Ron Zapp -Ronan Pigott -Ronnie Mose Rosen Penev Rosimildo da Silva Ross Burton @@ -2398,6 +2988,8 @@ roughtex on github Roy Bellingan Roy Li Roy Shan +RubisetCie on github +Rudi Heitbaum Rui LIU Rui Pinheiro Rune Kleveland @@ -2406,36 +2998,42 @@ Ruslan Gazizov Rutger Broekhoff Rutger Hofman Ruurd Beerstra -RuurdBeerstra on github rwmjones on github Ryan Beck-Buysse Ryan Braud +ryancaicse on github +Ryan Carsten Schmidt Ryan Chan +Ryan Hooper Ryan Mast Ryan Nelson Ryan Schmidt Ryan Scott Ryan Sleevi Ryan Winograd -ryancaicse on github Ryuichi KAWAMATA rzrymiak on github -Rémy Léone -S. Moonesamy +s0urc3_ on hackerone +saimen Sai Ram Kunala +Sakthi SK Salah-Eddin Shaban Saleem Abdulrasool SaltyMilk Salvador Dávila Salvatore Sorrentino +Samanta Navarro Sam Deane Sam Hurst +Sam James +Sam Jessup +sammydono on github +Sampo Kellomaki Sam Roth Sam Schanken -Samanta Navarro -Sampo Kellomaki Samuel Chiang Samuel Díaz García +Samuel Dionne-Riel Samuel Henrique Samuel Listopad Samuel Marks @@ -2446,24 +3044,37 @@ SandakovMM on github Sander Gates Sandor Feldi Sandro Jaeckel +Sanjay Pujare Santhana Todatry Santino Keupp Saqib Ali Sara Golemon +Sarah Gooding Saran Neti +Sascha Frinken Sascha Swiercy Sascha Zengler Satadru Pramanik Satana de Sant'Ana +Saud Alshareef Saul good +saurabhsingh-dev on github Saurav Babu sayrer on github +sbernatsky on github SBKarr on github +SC404 +Scarlett McAllister +Schrijvers Luc Scott Bailey Scott Barrett +Scott Boudreaux Scott Cantor Scott Davis Scott McCreary +Scott Mutter +Scott Talbert +sd0 on hackerone Sean Boudreau Sean Burford Sean MacLennan @@ -2471,11 +3082,17 @@ Sean McArthur Sean Miller Sean Molenaar Sebastiaan van Erk +Sebastian Andersson +Sebastian Carlos Sebastian Haglund Sebastian Mundry +Sebastian Neubauer Sebastian Pohlschmidt Sebastian Rasmussen Sebastian Sterk +Sebastian Walz +Sébastien Helleu +Sébastien Willemijns selmelc on hackerone SendSonS on github Senthil Raja Velu @@ -2484,7 +3101,9 @@ Sergei Nikulov Sergey Sergey Alirzaev Sergey Bronnikov +Sergey Fedorov Sergey Fionov +Sergey Katsubo Sergey Markelov Sergey Ogryzkov Sergey Ryabinin @@ -2494,17 +3113,19 @@ Sergii Pylypenko Sergio Ballestrero Sergio Barresi Sergio Borghese +Sergio Correia Sergio Durigan Junior -Sergio Mijatovic Sergio-IME on github +Sergio Mijatovic sergio-nsk on github Serj Kalichev +Sertonix SerusDev on github Seshubabu Pasam Seth Mos Sevan Janiyan +sfan5 on github Sgharat on github -Sh Diao Shachaf Ben-Kiki ShadowZzj on github Shailesh Kapse @@ -2517,9 +3138,11 @@ Shaun Jackman Shaun Mirani Shawn Landden Shawn Poulson +Sh Diao Sheshadri.V Shikha Sharma Shine Fan +Shintomon Mathew Shiraz Kanga shithappens2016 on github Shlomi Fish @@ -2527,28 +3150,42 @@ Shmulik Regev Shohei Maeda Siddhartha Prakash Jain siddharthchhabrap on github +sideshowbarker on github Sidney San Martín Siegfried Gyuricsko silveja1 on github Simon Berger Simon Chalifoux +Simon Dalvai Simon Dick Simon H. Simon Josefsson +Simon K Simon Legner Simon Liu Simon Warta simplerobot on github +Sinkevich Artem Siva Sivaraman +Slaven Rezić SLDiggie on github Smackd0wn on github +S. Moonesamy smuellerDD on github sn on hackerone sofaboss on github +Sohom Datta +Sollace on github Somnath Kundu Song Ma +Song X. Gao Sonia Subramanian +Sören Tempel +sourceturner +southernedge on github Spacen Jasset +spectreglobalsec on hackerone +Spenser Black Spezifant on github Spiridonoff A.V Spoon Man @@ -2556,12 +3193,16 @@ Spork Schivago ssdbest on github sspiri on github sstruchtrup on github +st751228051 on github Stadler Stephan Stan Hu -Stan van de Burgt +Stanislav Fort Stanislav Ivochkin +Stanislav Lange +Stanislav Osipov Stanislav Zidek Stanley Wucw +Stan van de Burgt Stathis Kapnidis Stav Nir steelman on github @@ -2574,49 +3215,55 @@ Stefan Huber Stefan Kanthak Stefan Karpinski Stefan Krause +Å tefan Kremeň Stefan Neis +Stefano Simonelli Stefan Strogin Stefan Talpalaru Stefan Teleman Stefan Tomanek Stefan Ulrich Stefan Yohansson -Stefano Simonelli +Steffen Kieß Steinar H. Gunderson steini2000 on github Stepan Broz Stepan Efremov Stephan Bergmann +Stephane Pellegrino Stephan Guilloux Stephan Lagerholm Stephan Mühlstrasser +stephannn on github Stephan Szabo -Stephane Pellegrino Stephen Boost Stephen Brokenshire Stephen Collyer +Stephen Farrell Stephen Kick Stephen M. Coakley Stephen More Stephen Toub Sterling Hughes Steve Green -Steve H Truong Steve Havelka Steve Herrell Steve Holme +Steve H Truong Steve Lhomme Steve Little Steve Marx -Steve Oliphant -Steve Roskowski -Steve Walch +Steven Allen Steven Bazyl Steven G. Johnson Steven Gu Steven M. Schweda +stevenpackardblp on github Steven Parkes Steven Penny +Steve Oliphant +Steve Roskowski +Steve Walch Stewart Gebbie Stian Soiland-Reyes Stoned Elipot @@ -2625,9 +3272,12 @@ Stuart Henderson Sukanya Hanumanthu SumatraPeter on github Sune Ahlgren +Sunny Sunny Bean Sunny Purushe +sunriseL SuperIlu on github +SuperStormer on github Sven Anders Sven Blumenstein Sven Neuhaus @@ -2637,46 +3287,62 @@ swalkaus at yahoo.com sylgal on github Sylvestre Ledru Symeon Paraschoudis -Sébastien Helleu -Sébastien Willemijns -T. Bharath -T. Yamada T200proX7 on github Tadej Vengust Tae Hyoung Ahn Taiyu Len +Tal Regev +Tamás Bálint Misius +Tamir Duberstein Taneli Vähäkangas Tanguy Fautre Taras Kushnir tarek112 on github +Tatsuhiko Miyagawa Tatsuhiro Tsujikawa tawmoto on github +T. Bharath tbugfinder on github Ted Lyngmo Teemu Yli-Elsila +Teh Kok How Temprimus +Tenant HellTower +Terence Eden +Terrance Wong Terri Oda Terry Wu +Tetetest thanhchungbtc on github -The Infinnovation team TheAssassin on github +TheBitBrine +The Infinnovation team TheKnarf on github +Theo +Theo Buehler +Theodore A. Roth Theodore Dubois therealhirudo on github Thiago Suchorski +Thibault de Villèle +thisisgk on github tholin on github +Thomas +Thomas1664 on github Thomas Bouzerar Thomas Braun Thomas Danielsson +Thomas Ferguson Thomas Gamper Thomas Glanzmann Thomas Guillem Thomas J. Moore Thomas Klausner -Thomas L. Shinnick Thomas Lopatic +Thomas L. Shinnick Thomas M. DuBuisson Thomas Petazzoni +Thomas Pyle Thomas Ruecker Thomas Schwinge Thomas Taylor @@ -2684,41 +3350,54 @@ Thomas Tonino Thomas van Hesteren Thomas Vegas Thomas Weißschuh -Thomas1664 on github Thorsten Klein Thorsten Schöning +Tianyi Song Tiit Pikma Till Maas +Till Wegmüller Tim Ansell Tim Baker Tim Bartley +Tim Becker Tim Chen Tim Costello +Tim Friedrich Brüggemann Tim Harder Tim Heckman +Tim Hill +Tim Martin Tim Mcdonough +Timmy Schierling Tim Newsome +Timo Lange +Tim Omta +Timo Sirainen +Timotej Lazar +Timothe Litt +Timothy Gu +Timothy Polich +Timo Tijhof Tim Rühsen Tim Sedlmeyer Tim Sneddon Tim Stack Tim Starling Tim Tassonis -Tim Verhoeven -Timmy Schierling -Timo Lange -Timo Sirainen -Timotej Lazar -Timothe Litt -Timothy Gu -Timothy Polich Timur Artikov +Tim Verhoeven +Tim Yuer Tinus van den Berg +tinyboxvk +tiymat TJ Saunders Tk Xiong +tkzv on github tlahn on github tmkk on github Tobias Blomberg +Tobias Bora +Tobias Frauenschläger Tobias Gabriel Tobias Hieta Tobias Hintze @@ -2730,12 +3409,27 @@ Tobias Nyholm Tobias Rundström Tobias Schaefer Tobias Stoeckmann +Tobias Wendorff +Tobias Zimmermann Toby Peterson Todd A Ouska +Todd Gamblin Todd Kaufmann Todd Kulesza Todd Short Todd Vierling +Tomas Berger +Tomas Hoger +Tomas Jakobsson +Tomáš Malý +Tomas Mlcoch +Tomas Mraz +Tomas Pospisek +Tomas Szepe +Tomas Tomecek +Tomas Volf +Tomasz Kojm +Tomasz Lacki Tom Benoist Tom Donovan Tom Eccles @@ -2744,87 +3438,99 @@ Tom Grace Tom Greenslade Tom Lee Tom Mattison -Tom Moers -Tom Mueller -Tom Regner -Tom Seddon -Tom Sparrow -Tom van der Woerdt -Tom Wright -Tom Zerucha -Tomas Berger -Tomas Hoger -Tomas Jakobsson -Tomas Mlcoch -Tomas Mraz -Tomas Pospisek -Tomas Szepe -Tomas Tomecek -Tomasz Kojm -Tomasz Lacki Tommie Gannert tommink[at]post.pl +Tom Moers +Tom Mueller +tommy Tommy Chiang Tommy Odom Tommy Petty Tommy Tam -Ton Voon +Tom Regner +Tom Seddon +Tom Sparrow +Tom St Denis +Tom van der Woerdt +Tom Wright +tomy2105 on github +Tom Zerucha Toni Moreno +Ton Voon Tony Kelman -tonystz on Github +tonystz on github +Toon Claes Toon Verwaest Tor Arntsen Torben Dannhauer +Torben Dury +Török Edwin Torsten Foertsch Toshio Kuratomi Toshiyuki Maezawa tpaukrt on github Traian Nicolescu Trail of Bits +tranzystorekk on github Travis Burtrum +Travis Lane Travis Obenhaus +Tristan Perrault Trivikram Kamat Troels Walsted Hansen Troy Engel trrui-huawei +Trumeet on github +trxvorr +Trzik on github Tseng Jun Tuomas Siipola Tuomo Rinne Tupone Alfredo +Turiiya +T. Yamada Tyler Hall -Török Edwin u20221022 on github Ulf Härnhammar Ulf Samuelsson Ulrich Doehner Ulrich Telle Ulrich Zadow -UnicornZhang on Github +UnicornZhang on github updatede on github UrsusArctos on github User Sg ustcqidi on github Vadim Grinshpun +Vaibhav Kumar Valentin David +Valentín Gutiérrez Valentin Richter Valentyn Korniienko -Valentín Gutiérrez +Valerie Snyder Valerii Zapodovnikov vanillajonathan on github Varnavas Papaioannou Vasiliy Faronov +Vasiliy-Kkk Vasiliy Ulyanov Vasily Lobaskin Vasy Okhin +vectorqueue on hackerone +vegagent on hackerone Venkat Akella Venkataramana Mokkapati +Venkat Krishna R Vicente Garcia +Victor Kislov Victor Magierski Victor Snezhko -Victor Vieux VictorVG on github +Victor Vieux Vijay Panghal Vikram Saxena +Viktor Dukhovni +Viktor Petersson Viktor Szakats Vilhelm Prytz Ville Skyttä @@ -2836,39 +3542,48 @@ Vincent Le Normand Vincent Penquerc'h Vincent Sanders Vincent Torri +violet12331 on hackerone violetlige on github vitaha85 on github Vitaly Varyvdin +Vítor Galvão vl409 on github Vlad Grachov -Vlad Ureche Vladimir Grishchenko Vladimir Kotal Vladimir Lazarenko +Vladimír Marek Vladimir Panteleev Vladimir Varlamov +Vladislavs Sokurenko +Vlad Ureche Vlastimil OvÄáÄík vlkl-sap on github vlubart on github Vojtech Janota -Vojtech Minarik VojtÄ›ch Král +Vojtech Minarik Volker Schmid +Vollstrecker on github Vsevolod Novikov vshmuk on hackerone -vvb2060 +vulnerabilityspotter on hackerone +Vulpes Vulpes +vuonganh1993 on github vvb2060 on github Vyron Tsingaras -Vítor Galvão -W. Mark Kubacki +w0x42 on hackerone Waldek Kozba +Waldemar Kornewald Walter J. Mack +WangDaLei on github wangzhikun Ward Willats Warren Menzer Wayne Haigh Wei Chong Tan Wenchao Li +Weng Xuetian Wenxiang Qian Werner Koch Werner Stolz @@ -2876,107 +3591,147 @@ Wes Hinsley wesinator on github Wesley Laxton Wesley Miaw +Wesley Moore Wez Furlong Wham Bang Wilfredo Sanchez Wilhelm von Thiele +Will Cosgrove Will Dietz -Will Roberts Willem Hoek Willem Sparreboom -William A. Rowe Jr William Ahern +William A. Rowe Jr William Desportes William Tang +Will Roberts +Winni Neessen +W. Mark Kubacki wmsch on github wncboy on github Wojciech Zwiefka +wolfsage on hackerone Wolf Vollprecht Wouter Van Rooy +wulin-nudt on github Wu Yongzheng Wu Zheng +wxiaoguang on github Wyatt O'Day Wyatt OʼDay +Wyuer on github +x1sc0 on github x2018 on github Xavier Bouchoux +XCas13 +xfangfang XhmikosR on github XhstormR on github -Xiang Xiao +xiadnoring on github Xiangbin Li xianghongai on github +Xiang Xiao +xiaofeng Xiaoke Wang Xiaoyin Liu +Xì Gà +Xi Ruoyao +xkilua on hackerone XmiliaH on github +xmoezzz on github xnynx on github xtonik on github xwxbug on github -Xì Gà +x-xiang on github +XYenon Yaakov Selkowitz +Yadhu Krishna M Yair Lenga +Yalguun Tumenkhuu Yang Tse Yaobin Wen +yaoy6 on github Yarram Sunil Yasuharu Yamada Yasuhiro Matsumoto Yechiel Kalmenson +Yedaya Katsman Yehezkel Horowitz Yehoshua Hershberg ygthien on github +Yifei Kong +Yihang Zhou Yi Huang Yiming Jing Yingwei Liu +Yiwei Hou yiyuaner on github Ymir1711 on github Yonggang Luo Yongkang Huang +Yoshimasa Ohno +Yoshiro Yoneya Younes El-karama youngchopin on github Yousuke Kimoto -Yu Xin +Yuhao Jiang Yukihiro Kawada Yun SangHo -Yuri Slobodyanyuk Yurii Rashkovskii +Yuri Slobodyanyuk Yuriy Chernyshov Yuriy Sosov yushicheng7788 on github Yusuke Nakamura +Yu Xin +Yuyi Wang Yves Arrouye Yves Lejeune YX Hao -z2-2z on github -z2_ on hackerone +z2_ Zachary Seguin +Zartaj Majeed Zdenek Pavlas Zekun Ni zelinchen on github +zengwei +zengwei2000 Zenju on github Zero King Zespre Schmidt -Zhang Xiuhua zhanghu on xiaomi -Zhao Yisha +Zhang Wen +Zhang Xiuhua +zhanhb on github +Zhanpeng Liu +Zhaoming Luo Zhaoyang Wu +Zhao Yisha +zhengqwe on github Zhibiao Wu +Zhicheng Chen zhihaoy on github Zhouyihai Ding ZimCodes on github +zjyhjqs zloi-user on github +zmcx16 on github Zmey Petroff +zopsicle on github Zvi Har'El zzq1015 on github -Ãdler Jonas Gross -Érico Nogueira -Érico Nogueira Rolim -İsmail Dönmez -Åukasz Domeradzki -Å tefan Kremeň Ð‘Ð¾Ñ€Ð¸Ñ Ð’ÐµÑ€Ñ…Ð¾Ð²Ñкий +Йоте Коваленко Ðнатолий Викторович +наб Ðикита Дорохин ウã•ã‚“ ä¸ç¡®å®š 加藤éƒä¹‹ +åŒ…å¸ƒä¸ +å—å®«é›ªçŠ å·¦æ½‡å³° +æŽå›› 梦终无痕 ç©ä¸¹å°¼ Dan Jacobson +ç½—æœè¾‰ diff --git a/third-party/curl/docs/THANKS-filter b/third-party/curl/docs/THANKS-filter index 99eacfced5..f9e7e1c8d2 100644 --- a/third-party/curl/docs/THANKS-filter +++ b/third-party/curl/docs/THANKS-filter @@ -25,7 +25,7 @@ # This is a list of names we have recorded that already are thanked # appropriately in THANKS. This list contains variations of their names and # their "canonical" name. This file is used for scripting purposes to avoid -# duplicate entries and will not be included in release tarballs. +# duplicate entries and is not included in release tarballs. # When removing dupes that are not identical names from THANKS, add a line # here! # @@ -133,6 +133,33 @@ s/ *via curl-library *// s/Evgeny Grin$/Evgeny Grin (Karlson2k)/ s/Karlson2k on github/Evgeny Grin (Karlson2k)/ s/Dan Frandrich/Dan Fandrich/ +s/Dan Fandrich\./Dan Fandrich/ s/GitHub$// s/pszlazak$/pszlazak on github/ s/Randall$/Randall S. Becker/ +s/talregev on github/Tal Regev/ +s/daniel-j-h/Daniel J. H./ +s/hongfei.li/Hongfei Li/ +s/z2_ on hackerone/z2_/ +s/z2-2z on github/z2_/ +s/janedenone on hackerone/janedenone on github/ +s/Benjamin Riefenstahl Mecom/Benjamin Riefenstahl/ +s/Micah Snyder)/Micah Snyder/ +s/\#14922// +s/vvb2060\z/vvb2060 on github/ +s/kartatz\z/Kartatz on github/i +s/Karthikdasari0423\z/Karthikdasari0423 on github/ +s/niallor on github/Niall O'Reilly/ +s/RuurdBeerstra on github/Ruurd Beerstra/ +s/Smackd0wn\z/Smackd0wn on github/ +s/Testclutch// +s/edmcln\z/edmcln on github/ +s/andrewkirillov-ibm/Andrew Kirillov/ +s/\(.*\) via #[0-9]*// +s/jethrogb$/jethrogb on github/ +s/on github/on github/i +s/Maksim Sciepanienka/Maksim Åšciepanienka/ +s/Qriist.*/Qriist on github/ +s/Viktor Szakatas/Viktor Szakats/ +s/Val S\./Valerie Snyder/ +s/Andrew Nesbit$/Andrew Nesbitt/ diff --git a/third-party/curl/docs/TODO b/third-party/curl/docs/TODO deleted file mode 100644 index a8e090c168..0000000000 --- a/third-party/curl/docs/TODO +++ /dev/null @@ -1,1385 +0,0 @@ - _ _ ____ _ - ___| | | | _ \| | - / __| | | | |_) | | - | (__| |_| | _ <| |___ - \___|\___/|_| \_\_____| - - Things that could be nice to do in the future - - Things to do in project curl. Please tell us what you think, contribute and - send us patches that improve things. - - Be aware that these are things that we could do, or have once been considered - things we could do. If you want to work on any of these areas, please - consider bringing it up for discussions first on the mailing list so that we - all agree it is still a good idea for the project. - - All bugs documented in the KNOWN_BUGS document are subject for fixing. - - 1. libcurl - 1.1 TFO support on Windows - 1.2 Consult %APPDATA% also for .netrc - 1.3 struct lifreq - 1.4 alt-svc sharing - 1.5 get rid of PATH_MAX - 1.6 native IDN support on macOS - 1.8 CURLOPT_RESOLVE for any port number - 1.9 Cache negative name resolves - 1.10 auto-detect proxy - 1.11 minimize dependencies with dynamically loaded modules - 1.12 updated DNS server while running - 1.13 c-ares and CURLOPT_OPENSOCKETFUNCTION - 1.15 Monitor connections in the connection pool - 1.16 Try to URL encode given URL - 1.17 Add support for IRIs - 1.18 try next proxy if one does not work - 1.19 provide timing info for each redirect - 1.20 SRV and URI DNS records - 1.21 netrc caching and sharing - 1.22 CURLINFO_PAUSE_STATE - 1.23 Offer API to flush the connection pool - 1.25 Expose tried IP addresses that failed - 1.28 FD_CLOEXEC - 1.29 WebSocket read callback - 1.30 config file parsing - 1.31 erase secrets from heap/stack after use - 1.32 add asynch getaddrinfo support - 1.33 make DoH inherit more transfer properties - - 2. libcurl - multi interface - 2.1 More non-blocking - 2.2 Better support for same name resolves - 2.3 Non-blocking curl_multi_remove_handle() - 2.4 Split connect and authentication process - 2.5 Edge-triggered sockets should work - 2.6 multi upkeep - 2.7 Virtual external sockets - 2.8 dynamically decide to use socketpair - - 3. Documentation - 3.1 Improve documentation about fork safety - 3.2 Provide cmake config-file - - 4. FTP - 4.1 HOST - 4.2 Alter passive/active on failure and retry - 4.3 Earlier bad letter detection - 4.4 Support CURLOPT_PREQUOTE for dir listings too - 4.5 ASCII support - 4.6 GSSAPI via Windows SSPI - 4.7 STAT for LIST without data connection - 4.8 Passive transfer could try other IP addresses - - 5. HTTP - 5.1 Provide the error body from a CONNECT response - 5.2 Obey Retry-After in redirects - 5.3 Rearrange request header order - 5.4 Allow SAN names in HTTP/2 server push - 5.5 auth= in URLs - 5.6 alt-svc should fallback if alt-svc does not work - 5.7 Require HTTP version X or higher - - 6. TELNET - 6.1 ditch stdin - 6.2 ditch telnet-specific select - 6.3 feature negotiation debug data - 6.4 exit immediately upon connection if stdin is /dev/null - - 7. SMTP - 7.1 Passing NOTIFY option to CURLOPT_MAIL_RCPT - 7.2 Enhanced capability support - 7.3 Add CURLOPT_MAIL_CLIENT option - - 8. POP3 - 8.2 Enhanced capability support - - 9. IMAP - 9.1 Enhanced capability support - - 10. LDAP - 10.1 SASL based authentication mechanisms - 10.2 CURLOPT_SSL_CTX_FUNCTION for LDAPS - 10.3 Paged searches on LDAP server - 10.4 Certificate-Based Authentication - - 11. SMB - 11.1 File listing support - 11.2 Honor file timestamps - 11.3 Use NTLMv2 - 11.4 Create remote directories - - 12. FILE - 12.1 Directory listing for FILE: - - 13. TLS - 13.1 TLS-PSK with OpenSSL - 13.2 Provide mutex locking API - 13.3 Defeat TLS fingerprinting - 13.4 Cache/share OpenSSL contexts - 13.5 Export session ids - 13.6 Provide callback for cert verification - 13.7 Less memory massaging with Schannel - 13.8 Support DANE - 13.9 TLS record padding - 13.10 Support Authority Information Access certificate extension (AIA) - 13.12 Reduce CA certificate bundle reparsing - 13.13 Make sure we forbid TLS 1.3 post-handshake authentication - 13.14 Support the clienthello extension - - 14. GnuTLS - 14.2 check connection - - 15. Schannel - 15.1 Extend support for client certificate authentication - 15.2 Extend support for the --ciphers option - 15.4 Add option to allow abrupt server closure - - 16. SASL - 16.1 Other authentication mechanisms - 16.2 Add QOP support to GSSAPI authentication - - 17. SSH protocols - 17.1 Multiplexing - 17.2 Handle growing SFTP files - 17.3 Read keys from ~/.ssh/id_ecdsa, id_ed25519 - 17.4 Support CURLOPT_PREQUOTE - 17.5 SSH over HTTPS proxy with more backends - 17.6 SFTP with SCP:// - - 18. Command line tool - 18.1 sync - 18.2 glob posts - 18.4 --proxycommand - 18.5 UTF-8 filenames in Content-Disposition - 18.6 Option to make -Z merge lined based outputs on stdout - 18.8 Consider convenience options for JSON and XML? - 18.9 Choose the name of file in braces for complex URLs - 18.10 improve how curl works in a windows console window - 18.11 Windows: set attribute 'archive' for completed downloads - 18.12 keep running, read instructions from pipe/socket - 18.13 Ratelimit or wait between serial requests - 18.14 --dry-run - 18.15 --retry should resume - 18.16 send only part of --data - 18.17 consider file name from the redirected URL with -O ? - 18.18 retry on network is unreachable - 18.19 expand ~/ in config files - 18.20 host name sections in config files - 18.21 retry on the redirected-to URL - 18.23 Set the modification date on an uploaded file - 18.24 Use multiple parallel transfers for a single download - 18.25 Prevent terminal injection when writing to terminal - 18.26 Custom progress meter update interval - 18.27 -J and -O with %-encoded file names - 18.28 -J with -C - - 18.29 --retry and transfer timeouts - - 19. Build - 19.1 roffit - 19.2 Enable PIE and RELRO by default - 19.3 Do not use GNU libtool on OpenBSD - 19.4 Package curl for Windows in a signed installer - 19.5 make configure use --cache-file more and better - 19.6 build curl with Windows Unicode support - - 20. Test suite - 20.1 SSL tunnel - 20.2 nicer lacking perl message - 20.3 more protocols supported - 20.4 more platforms supported - 20.5 Add support for concurrent connections - 20.6 Use the RFC 6265 test suite - 20.7 Support LD_PRELOAD on macOS - 20.8 Run web-platform-tests URL tests - - 21. MQTT - 21.1 Support rate-limiting - -============================================================================== - -1. libcurl - -1.1 TFO support on Windows - - libcurl supports the CURLOPT_TCP_FASTOPEN option since 7.49.0 for Linux and - Mac OS. Windows supports TCP Fast Open starting with Windows 10, version 1607 - and we should add support for it. - - TCP Fast Open is supported on several platforms but not on Windows. Work on - this was once started but never finished. - - See https://github.com/curl/curl/pull/3378 - -1.2 Consult %APPDATA% also for .netrc - - %APPDATA%\.netrc is not considered when running on Windows. should not it? - - See https://github.com/curl/curl/issues/4016 - -1.3 struct lifreq - - Use 'struct lifreq' and SIOCGLIFADDR instead of 'struct ifreq' and - SIOCGIFADDR on newer Solaris versions as they claim the latter is obsolete. - To support IPv6 interface addresses for network interfaces properly. - -1.4 Better and more sharing - - The share interface could benefit from allowing the alt-svc cache to be - possible to share between easy handles. - - See https://github.com/curl/curl/issues/4476 - - The share interface offers CURL_LOCK_DATA_CONNECT to have multiple easy - handle share a connection cache, but due to how connections are used they are - still not thread-safe when used shared. - - See https://github.com/curl/curl/issues/4915 and lib1541.c - - The share interface offers CURL_LOCK_DATA_HSTS to have multiple easy handle - share a HSTS cache, but this is not thread-safe. - -1.5 get rid of PATH_MAX - - Having code use and rely on PATH_MAX is not nice: - https://insanecoding.blogspot.com/2007/11/pathmax-simply-isnt.html - - Currently the libssh2 SSH based code uses it, but to remove PATH_MAX from - there we need libssh2 to properly tell us when we pass in a too small buffer - and its current API (as of libssh2 1.2.7) does not. - -1.6 native IDN support on macOS - - On recent macOS versions, the getaddrinfo() function itself has built-in IDN - support. By setting the AI_CANONNAME flag, the function will return the - encoded name in the ai_canonname struct field in the returned information. - This could be used by curl on macOS when built without a separate IDN library - and an IDN host name is used in a URL. - - See initial work in https://github.com/curl/curl/pull/5371 - -1.8 CURLOPT_RESOLVE for any port number - - This option allows applications to set a replacement IP address for a given - host + port pair. Consider making support for providing a replacement address - for the host name on all port numbers. - - See https://github.com/curl/curl/issues/1264 - -1.9 Cache negative name resolves - - A name resolve that has failed is likely to fail when made again within a - short period of time. Currently we only cache positive responses. - -1.10 auto-detect proxy - - libcurl could be made to detect the system proxy setup automatically and use - that. On Windows, macOS and Linux desktops for example. - - The pull-request to use libproxy for this was deferred due to doubts on the - reliability of the dependency and how to use it: - https://github.com/curl/curl/pull/977 - - libdetectproxy is a (C++) library for detecting the proxy on Windows - https://github.com/paulharris/libdetectproxy - -1.11 minimize dependencies with dynamically loaded modules - - We can create a system with loadable modules/plug-ins, where these modules - would be the ones that link to 3rd party libs. That would allow us to avoid - having to load ALL dependencies since only the necessary ones for this - app/invoke/used protocols would be necessary to load. See - https://github.com/curl/curl/issues/349 - -1.12 updated DNS server while running - - If /etc/resolv.conf gets updated while a program using libcurl is running, it - is may cause name resolves to fail unless res_init() is called. We should - consider calling res_init() + retry once unconditionally on all name resolve - failures to mitigate against this. Firefox works like that. Note that Windows - does not have res_init() or an alternative. - - https://github.com/curl/curl/issues/2251 - -1.13 c-ares and CURLOPT_OPENSOCKETFUNCTION - - curl will create most sockets via the CURLOPT_OPENSOCKETFUNCTION callback and - close them with the CURLOPT_CLOSESOCKETFUNCTION callback. However, c-ares - does not use those functions and instead opens and closes the sockets - itself. This means that when curl passes the c-ares socket to the - CURLMOPT_SOCKETFUNCTION it is not owned by the application like other sockets. - - See https://github.com/curl/curl/issues/2734 - -1.15 Monitor connections in the connection pool - - libcurl's connection cache or pool holds a number of open connections for the - purpose of possible subsequent connection reuse. It may contain a few up to a - significant amount of connections. Currently, libcurl leaves all connections - as they are and first when a connection is iterated over for matching or - reuse purpose it is verified that it is still alive. - - Those connections may get closed by the server side for idleness or they may - get an HTTP/2 ping from the peer to verify that they are still alive. By - adding monitoring of the connections while in the pool, libcurl can detect - dead connections (and close them) better and earlier, and it can handle - HTTP/2 pings to keep such ones alive even when not actively doing transfers - on them. - -1.16 Try to URL encode given URL - - Given a URL that for example contains spaces, libcurl could have an option - that would try somewhat harder than it does now and convert spaces to %20 and - perhaps URL encoded byte values over 128 etc (basically do what the redirect - following code already does). - - https://github.com/curl/curl/issues/514 - -1.17 Add support for IRIs - - IRIs (RFC 3987) allow localized, non-ascii, names in the URL. To properly - support this, curl/libcurl would need to translate/encode the given input - from the input string encoding into percent encoded output "over the wire". - - To make that work smoothly for curl users even on Windows, curl would - probably need to be able to convert from several input encodings. - -1.18 try next proxy if one does not work - - Allow an application to specify a list of proxies to try, and failing to - connect to the first go on and try the next instead until the list is - exhausted. Browsers support this feature at least when they specify proxies - using PACs. - - https://github.com/curl/curl/issues/896 - -1.19 provide timing info for each redirect - - curl and libcurl provide timing information via a set of different - time-stamps (CURLINFO_*_TIME). When curl is following redirects, those - returned time value are the accumulated sums. An improvement could be to - offer separate timings for each redirect. - - https://github.com/curl/curl/issues/6743 - -1.20 SRV and URI DNS records - - Offer support for resolving SRV and URI DNS records for libcurl to know which - server to connect to for various protocols (including HTTP). - -1.21 netrc caching and sharing - - The netrc file is read and parsed each time a connection is setup, which - means that if a transfer needs multiple connections for authentication or - redirects, the file might be reread (and parsed) multiple times. This makes - it impossible to provide the file as a pipe. - -1.22 CURLINFO_PAUSE_STATE - - Return information about the transfer's current pause state, in both - directions. https://github.com/curl/curl/issues/2588 - -1.23 Offer API to flush the connection pool - - Sometimes applications want to flush all the existing connections kept alive. - An API could allow a forced flush or just a forced loop that would properly - close all connections that have been closed by the server already. - -1.25 Expose tried IP addresses that failed - - When libcurl fails to connect to a host, it could offer the application the - addresses that were used in the attempt. Source + dest IP, source + dest port - and protocol (UDP or TCP) for each failure. Possibly as a callback. Perhaps - also provide "reason". - - https://github.com/curl/curl/issues/2126 - -1.28 FD_CLOEXEC - - It sets the close-on-exec flag for the file descriptor, which causes the file - descriptor to be automatically (and atomically) closed when any of the - exec-family functions succeed. Should probably be set by default? - - https://github.com/curl/curl/issues/2252 - -1.29 WebSocket read callback - - Call the read callback once the connection is established to allow sending - the first message in the connection. - - https://github.com/curl/curl/issues/11402 - -1.30 config file parsing - - Consider providing an API, possibly in a separate companion library, for - parsing a config file like curl's -K/--config option to allow applications to - get the same ability to read curl options from files. - - See https://github.com/curl/curl/issues/3698 - -1.31 erase secrets from heap/stack after use - - Introducing a concept and system to erase secrets from memory after use, it - could help mitigate and lessen the impact of (future) security problems etc. - However: most secrets are passed to libcurl as clear text from the - application and then clearing them within the library adds nothing... - - https://github.com/curl/curl/issues/7268 - -1.32 add asynch getaddrinfo support - - Use getaddrinfo_a() to provide an asynch name resolver backend to libcurl - that does not use threads and does not depend on c-ares. The getaddrinfo_a - function is (probably?) glibc specific but that is a widely used libc among - our users. - - https://github.com/curl/curl/pull/6746 - -1.33 make DoH inherit more transfer properties - - Some options are not inherited because they are not relevant for the DoH SSL - connections, or inheriting the option may result in unexpected behavior. For - example the user's debug function callback is not inherited because it would - be unexpected for internal handles (ie DoH handles) to be passed to that - callback. - - If an option is not inherited then it is not possible to set it separately - for DoH without a DoH-specific option. For example: - CURLOPT_DOH_SSL_VERIFYHOST, CURLOPT_DOH_SSL_VERIFYPEER and - CURLOPT_DOH_SSL_VERIFYSTATUS. - - See https://github.com/curl/curl/issues/6605 - -2. libcurl - multi interface - -2.1 More non-blocking - - Make sure we do not ever loop because of non-blocking sockets returning - EWOULDBLOCK or similar. Blocking cases include: - - - Name resolves on non-windows unless c-ares or the threaded resolver is used. - - - The threaded resolver may block on cleanup: - https://github.com/curl/curl/issues/4852 - - - file:// transfers - - - TELNET transfers - - - GSSAPI authentication for FTP transfers - - - The "DONE" operation (post transfer protocol-specific actions) for the - protocols SFTP, SMTP, FTP. Fixing multi_done() for this is a worthy task. - - - curl_multi_remove_handle for any of the above. See section 2.3. - -2.2 Better support for same name resolves - - If a name resolve has been initiated for name NN and a second easy handle - wants to resolve that name as well, make it wait for the first resolve to end - up in the cache instead of doing a second separate resolve. This is - especially needed when adding many simultaneous handles using the same host - name when the DNS resolver can get flooded. - -2.3 Non-blocking curl_multi_remove_handle() - - The multi interface has a few API calls that assume a blocking behavior, like - add_handle() and remove_handle() which limits what we can do internally. The - multi API need to be moved even more into a single function that "drives" - everything in a non-blocking manner and signals when something is done. A - remove or add would then only ask for the action to get started and then - multi_perform() etc still be called until the add/remove is completed. - -2.4 Split connect and authentication process - - The multi interface treats the authentication process as part of the connect - phase. As such any failures during authentication will not trigger the relevant - QUIT or LOGOFF for protocols such as IMAP, POP3 and SMTP. - -2.5 Edge-triggered sockets should work - - The multi_socket API should work with edge-triggered socket events. One of - the internal actions that need to be improved for this to work perfectly is - the 'maxloops' handling in transfer.c:readwrite_data(). - -2.6 multi upkeep - - In libcurl 7.62.0 we introduced curl_easy_upkeep. It unfortunately only works - on easy handles. We should introduces a version of that for the multi handle, - and also consider doing "upkeep" automatically on connections in the - connection pool when the multi handle is in used. - - See https://github.com/curl/curl/issues/3199 - -2.7 Virtual external sockets - - libcurl performs operations on the given file descriptor that presumes it is - a socket and an application cannot replace them at the moment. Allowing an - application to fully replace those would allow a larger degree of freedom and - flexibility. - - See https://github.com/curl/curl/issues/5835 - -2.8 dynamically decide to use socketpair - - For users who do not use curl_multi_wait() or do not care for - curl_multi_wakeup(), we could introduce a way to make libcurl NOT - create a socketpair in the multi handle. - - See https://github.com/curl/curl/issues/4829 - -3. Documentation - -3.1 Improve documentation about fork safety - - See https://github.com/curl/curl/issues/6968 - -3.2 Provide cmake config-file - - A config-file package is a set of files provided by us to allow applications - to write cmake scripts to find and use libcurl easier. See - https://github.com/curl/curl/issues/885 - -4. FTP - -4.1 HOST - - HOST is a command for a client to tell which host name to use, to offer FTP - servers named-based virtual hosting: - - https://datatracker.ietf.org/doc/html/rfc7151 - -4.2 Alter passive/active on failure and retry - - When trying to connect passively to a server which only supports active - connections, libcurl returns CURLE_FTP_WEIRD_PASV_REPLY and closes the - connection. There could be a way to fallback to an active connection (and - vice versa). https://curl.se/bug/feature.cgi?id=1754793 - -4.3 Earlier bad letter detection - - Make the detection of (bad) %0d and %0a codes in FTP URL parts earlier in the - process to avoid doing a resolve and connect in vain. - -4.4 Support CURLOPT_PREQUOTE for dir listings too - - The lack of support is mostly an oversight and requires the FTP state machine - to get updated to get fixed. - - https://github.com/curl/curl/issues/8602 - -4.5 ASCII support - - FTP ASCII transfers do not follow RFC 959. They do not convert the data - accordingly. - -4.6 GSSAPI via Windows SSPI - - In addition to currently supporting the SASL GSSAPI mechanism (Kerberos V5) - via third-party GSS-API libraries, such as Heimdal or MIT Kerberos, also add - support for GSSAPI authentication via Windows SSPI. - -4.7 STAT for LIST without data connection - - Some FTP servers allow STAT for listing directories instead of using LIST, - and the response is then sent over the control connection instead of as the - otherwise usedw data connection: https://www.nsftools.com/tips/RawFTP.htm#STAT - - This is not detailed in any FTP specification. - -4.8 Passive transfer could try other IP addresses - - When doing FTP operations through a proxy at localhost, the reported spotted - that curl only tried to connect once to the proxy, while it had multiple - addresses and a failed connect on one address should make it try the next. - - After switching to passive mode (EPSV), curl could try all IP addresses for - "localhost". Currently it tries ::1, but it should also try 127.0.0.1. - - See https://github.com/curl/curl/issues/1508 - -5. HTTP - -5.1 Provide the error body from a CONNECT response - - When curl receives a body response from a CONNECT request to a proxy, it will - always just read and ignore it. It would make some users happy if curl - instead optionally would be able to make that responsible available. Via a new - callback? Through some other means? - - See https://github.com/curl/curl/issues/9513 - -5.2 Obey Retry-After in redirects - - The Retry-After is said to dicate "the minimum time that the user agent is - asked to wait before issuing the redirected request" and libcurl does not - obey this. - - See https://github.com/curl/curl/issues/11447 - -5.3 Rearrange request header order - - Server implementors often make an effort to detect browser and to reject - clients it can detect to not match. One of the last details we cannot yet - control in libcurl's HTTP requests, which also can be exploited to detect - that libcurl is in fact used even when it tries to impersonate a browser, is - the order of the request headers. I propose that we introduce a new option in - which you give headers a value, and then when the HTTP request is built it - sorts the headers based on that number. We could then have internally created - headers use a default value so only headers that need to be moved have to be - specified. - -5.4 Allow SAN names in HTTP/2 server push - - curl only allows HTTP/2 push promise if the provided :authority header value - exactly matches the host name given in the URL. It could be extended to allow - any name that would match the Subject Alternative Names in the server's TLS - certificate. - - See https://github.com/curl/curl/pull/3581 - -5.5 auth= in URLs - - Add the ability to specify the preferred authentication mechanism to use by - using ;auth= in the login part of the URL. - - For example: - - http://test:pass;auth=NTLM@example.com would be equivalent to specifying - --user test:pass;auth=NTLM or --user test:pass --ntlm from the command line. - - Additionally this should be implemented for proxy base URLs as well. - -5.6 alt-svc should fallback if alt-svc does not work - - The alt-svc: header provides a set of alternative services for curl to use - instead of the original. If the first attempted one fails, it should try the - next etc and if all alternatives fail go back to the original. - - See https://github.com/curl/curl/issues/4908 - -5.7 Require HTTP version X or higher - - curl and libcurl provide options for trying higher HTTP versions (for example - HTTP/2) but then still allows the server to pick version 1.1. We could - consider adding a way to require a minimum version. - - See https://github.com/curl/curl/issues/7980 - -6. TELNET - -6.1 ditch stdin - - Reading input (to send to the remote server) on stdin is a crappy solution - for library purposes. We need to invent a good way for the application to be - able to provide the data to send. - -6.2 ditch telnet-specific select - - Move the telnet support's network select() loop go away and merge the code - into the main transfer loop. Until this is done, the multi interface will not - work for telnet. - -6.3 feature negotiation debug data - - Add telnet feature negotiation data to the debug callback as header data. - -6.4 exit immediately upon connection if stdin is /dev/null - - If it did, curl could be used to probe if there is an server there listening - on a specific port. That is, the following command would exit immediately - after the connection is established with exit code 0: - - curl -s --connect-timeout 2 telnet://example.com:80 NOTIFY=SUCCESS,FAILURE" ); - - https://github.com/curl/curl/issues/8232 - -7.2 Enhanced capability support - - Add the ability, for an application that uses libcurl, to obtain the list of - capabilities returned from the EHLO command. - -7.3 Add CURLOPT_MAIL_CLIENT option - - Rather than use the URL to specify the mail client string to present in the - HELO and EHLO commands, libcurl should support a new CURLOPT specifically for - specifying this data as the URL is non-standard and to be honest a bit of a - hack ;-) - - Please see the following thread for more information: - https://curl.se/mail/lib-2012-05/0178.html - - -8. POP3 - -8.2 Enhanced capability support - - Add the ability, for an application that uses libcurl, to obtain the list of - capabilities returned from the CAPA command. - -9. IMAP - -9.1 Enhanced capability support - - Add the ability, for an application that uses libcurl, to obtain the list of - capabilities returned from the CAPABILITY command. - -10. LDAP - -10.1 SASL based authentication mechanisms - - Currently the LDAP module only supports ldap_simple_bind_s() in order to bind - to an LDAP server. However, this function sends username and password details - using the simple authentication mechanism (as clear text). However, it should - be possible to use ldap_bind_s() instead specifying the security context - information ourselves. - -10.2 CURLOPT_SSL_CTX_FUNCTION for LDAPS - - CURLOPT_SSL_CTX_FUNCTION works perfectly for HTTPS and email protocols, but - it has no effect for LDAPS connections. - - https://github.com/curl/curl/issues/4108 - -10.3 Paged searches on LDAP server - - https://github.com/curl/curl/issues/4452 - -10.4 Certificate-Based Authentication - - LDAPS not possible with MAC and Windows with Certificate-Based Authentication - - https://github.com/curl/curl/issues/9641 - -11. SMB - -11.1 File listing support - - Add support for listing the contents of a SMB share. The output should - probably be the same as/similar to FTP. - -11.2 Honor file timestamps - - The timestamp of the transferred file should reflect that of the original - file. - -11.3 Use NTLMv2 - - Currently the SMB authentication uses NTLMv1. - -11.4 Create remote directories - - Support for creating remote directories when uploading a file to a directory - that does not exist on the server, just like --ftp-create-dirs. - - -12. FILE - -12.1 Directory listing for FILE: - - Add support for listing the contents of a directory accessed with FILE. The - output should probably be the same as/similar to FTP. - - -13. TLS - -13.1 TLS-PSK with OpenSSL - - Transport Layer Security pre-shared key ciphersuites (TLS-PSK) is a set of - cryptographic protocols that provide secure communication based on pre-shared - keys (PSKs). These pre-shared keys are symmetric keys shared in advance among - the communicating parties. - - https://github.com/curl/curl/issues/5081 - -13.2 Provide mutex locking API - - Provide a libcurl API for setting mutex callbacks in the underlying SSL - library, so that the same application code can use mutex-locking - independently of OpenSSL or GnutTLS being used. - -13.3 Defeat TLS fingerprinting - - By changing the order of TLS extensions provided in the TLS handshake, it is - sometimes possible to circumvent TLS fingerprinting by servers. The TLS - extension order is of course not the only way to fingerprint a client. - - See https://github.com/curl/curl/issues/8119 - -13.4 Cache/share OpenSSL contexts - - "Look at SSL cafile - quick traces look to me like these are done on every - request as well, when they should only be necessary once per SSL context (or - once per handle)". The major improvement we can rather easily do is to make - sure we do not create and kill a new SSL "context" for every request, but - instead make one for every connection and reuse that SSL context in the same - style connections are reused. It will make us use slightly more memory but it - will libcurl do less creations and deletions of SSL contexts. - - Technically, the "caching" is probably best implemented by getting added to - the share interface so that easy handles who want to and can reuse the - context specify that by sharing with the right properties set. - - https://github.com/curl/curl/issues/1110 - -13.5 Export session ids - - Add an interface to libcurl that enables "session IDs" to get - exported/imported. Cris Bailiff said: "OpenSSL has functions which can - serialise the current SSL state to a buffer of your choice, and recover/reset - the state from such a buffer at a later date - this is used by mod_ssl for - apache to implement and SSL session ID cache". - -13.6 Provide callback for cert verification - - OpenSSL supports a callback for customised verification of the peer - certificate, but this does not seem to be exposed in the libcurl APIs. Could - it be? There is so much that could be done if it were. - -13.7 Less memory massaging with Schannel - - The Schannel backend does a lot of custom memory management we would rather - avoid: the repeated alloc + free in sends and the custom memory + realloc - system for encrypted and decrypted data. That should be avoided and reduced - for 1) efficiency and 2) safety. - -13.8 Support DANE - - DNS-Based Authentication of Named Entities (DANE) is a way to provide SSL - keys and certs over DNS using DNSSEC as an alternative to the CA model. - https://www.rfc-editor.org/rfc/rfc6698.txt - - An initial patch was posted by Suresh Krishnaswamy on March 7th 2013 - (https://curl.se/mail/lib-2013-03/0075.html) but it was a too simple - approach. See Daniel's comments: - https://curl.se/mail/lib-2013-03/0103.html . libunbound may be the - correct library to base this development on. - - Björn Stenberg wrote a separate initial take on DANE that was never - completed. - -13.9 TLS record padding - - TLS (1.3) offers optional record padding and OpenSSL provides an API for it. - I could make sense for libcurl to offer this ability to applications to make - traffic patterns harder to figure out by network traffic observers. - - See https://github.com/curl/curl/issues/5398 - -13.10 Support Authority Information Access certificate extension (AIA) - - AIA can provide various things like CRLs but more importantly information - about intermediate CA certificates that can allow validation path to be - fulfilled when the HTTPS server does not itself provide them. - - Since AIA is about downloading certs on demand to complete a TLS handshake, - it is probably a bit tricky to get done right. - - See https://github.com/curl/curl/issues/2793 - -13.12 Reduce CA certificate bundle reparsing - - When using the OpenSSL backend, curl will load and reparse the CA bundle at - the creation of the "SSL context" when it sets up a connection to do a TLS - handshake. A more effective way would be to somehow cache the CA bundle to - avoid it having to be repeatedly reloaded and reparsed. - - See https://github.com/curl/curl/issues/9379 - -13.13 Make sure we forbid TLS 1.3 post-handshake authentication - - RFC 8740 explains how using HTTP/2 must forbid the use of TLS 1.3 - post-handshake authentication. We should make sure to live up to that. - - See https://github.com/curl/curl/issues/5396 - -13.14 Support the clienthello extension - - Certain stupid networks and middle boxes have a problem with SSL handshake - packets that are within a certain size range because how that sets some bits - that previously (in older TLS version) were not set. The clienthello - extension adds padding to avoid that size range. - - https://datatracker.ietf.org/doc/html/rfc7685 - https://github.com/curl/curl/issues/2299 - -14. GnuTLS - -14.2 check connection - - Add a way to check if the connection seems to be alive, to correspond to the - SSL_peak() way we use with OpenSSL. - -15. Schannel - -15.1 Extend support for client certificate authentication - - The existing support for the -E/--cert and --key options could be - extended by supplying a custom certificate and key in PEM format, see: - - Getting a Certificate for Schannel - https://msdn.microsoft.com/en-us/library/windows/desktop/aa375447.aspx - -15.2 Extend support for the --ciphers option - - The existing support for the --ciphers option could be extended - by mapping the OpenSSL/GnuTLS cipher suites to the Schannel APIs, see - - Specifying Schannel Ciphers and Cipher Strengths - https://msdn.microsoft.com/en-us/library/windows/desktop/aa380161.aspx - -15.4 Add option to allow abrupt server closure - - libcurl w/schannel will error without a known termination point from the - server (such as length of transfer, or SSL "close notify" alert) to prevent - against a truncation attack. Really old servers may neglect to send any - termination point. An option could be added to ignore such abrupt closures. - - https://github.com/curl/curl/issues/4427 - -16. SASL - -16.1 Other authentication mechanisms - - Add support for other authentication mechanisms such as OLP, - GSS-SPNEGO and others. - -16.2 Add QOP support to GSSAPI authentication - - Currently the GSSAPI authentication only supports the default QOP of auth - (Authentication), whilst Kerberos V5 supports both auth-int (Authentication - with integrity protection) and auth-conf (Authentication with integrity and - privacy protection). - - -17. SSH protocols - -17.1 Multiplexing - - SSH is a perfectly fine multiplexed protocols which would allow libcurl to do - multiple parallel transfers from the same host using the same connection, - much in the same spirit as HTTP/2 does. libcurl however does not take - advantage of that ability but will instead always create a new connection for - new transfers even if an existing connection already exists to the host. - - To fix this, libcurl would have to detect an existing connection and "attach" - the new transfer to the existing one. - -17.2 Handle growing SFTP files - - The SFTP code in libcurl checks the file size *before* a transfer starts and - then proceeds to transfer exactly that amount of data. If the remote file - grows while the transfer is in progress libcurl will not notice and will not - adapt. The OpenSSH SFTP command line tool does and libcurl could also just - attempt to download more to see if there is more to get... - - https://github.com/curl/curl/issues/4344 - -17.3 Read keys from ~/.ssh/id_ecdsa, id_ed25519 - - The libssh2 backend in curl is limited to only reading keys from id_rsa and - id_dsa, which makes it fail connecting to servers that use more modern key - types. - - https://github.com/curl/curl/issues/8586 - -17.4 Support CURLOPT_PREQUOTE - - The two other QUOTE options are supported for SFTP, but this was left out for - unknown reasons. - -17.5 SSH over HTTPS proxy with more backends - - The SSH based protocols SFTP and SCP did not work over HTTPS proxy at - all until PR https://github.com/curl/curl/pull/6021 brought the - functionality with the libssh2 backend. Presumably, this support - can/could be added for the other backends as well. - -17.6 SFTP with SCP:// - - OpenSSH 9 switched their 'scp' tool to speak SFTP under the hood. Going - forward it might be worth having curl or libcurl attempt SFTP if SCP fails to - follow suite. - -18. Command line tool - -18.1 sync - - "curl --sync http://example.com/feed[1-100].rss" or - "curl --sync http://example.net/{index,calendar,history}.html" - - Downloads a range or set of URLs using the remote name, but only if the - remote file is newer than the local file. A Last-Modified HTTP date header - should also be used to set the mod date on the downloaded file. - -18.2 glob posts - - Globbing support for -d and -F, as in 'curl -d "name=foo[0-9]" URL'. - This is easily scripted though. - -18.4 --proxycommand - - Allow the user to make curl run a command and use its stdio to make requests - and not do any network connection by itself. Example: - - curl --proxycommand 'ssh pi@raspberrypi.local -W 10.1.1.75 80' \ - http://some/otherwise/unavailable/service.php - - See https://github.com/curl/curl/issues/4941 - -18.5 UTF-8 filenames in Content-Disposition - - RFC 6266 documents how UTF-8 names can be passed to a client in the - Content-Disposition header, and curl does not support this. - - https://github.com/curl/curl/issues/1888 - -18.6 Option to make -Z merge lined based outputs on stdout - - When a user requests multiple lined based files using -Z and sends them to - stdout, curl will not "merge" and send complete lines fine but may send - partial lines from several sources. - - https://github.com/curl/curl/issues/5175 - -18.8 Consider convenience options for JSON and XML? - - Could we add `--xml` or `--json` to add headers needed to call rest API: - - `--xml` adds -H 'Content-Type: application/xml' -H "Accept: application/xml" and - `--json` adds -H 'Content-Type: application/json' -H "Accept: application/json" - - Setting Content-Type when doing a GET or any other method without a body - would be a bit strange I think - so maybe only add CT for requests with body? - Maybe plain `--xml` and ` --json` are a bit too brief and generic. Maybe - `--http-json` etc? - - See https://github.com/curl/curl/issues/5203 - -18.9 Choose the name of file in braces for complex URLs - - When using braces to download a list of URLs and you use complicated names - in the list of alternatives, it could be handy to allow curl to use other - names when saving. - - Consider a way to offer that. Possibly like - {partURL1:name1,partURL2:name2,partURL3:name3} where the name following the - colon is the output name. - - See https://github.com/curl/curl/issues/221 - -18.10 improve how curl works in a windows console window - - If you pull the scrollbar when transferring with curl in a Windows console - window, the transfer is interrupted and can get disconnected. This can - probably be improved. See https://github.com/curl/curl/issues/322 - -18.11 Windows: set attribute 'archive' for completed downloads - - The archive bit (FILE_ATTRIBUTE_ARCHIVE, 0x20) separates files that shall be - backed up from those that are either not ready or have not changed. - - Downloads in progress are neither ready to be backed up, nor should they be - opened by a different process. Only after a download has been completed it's - sensible to include it in any integer snapshot or backup of the system. - - See https://github.com/curl/curl/issues/3354 - -18.12 keep running, read instructions from pipe/socket - - Provide an option that makes curl not exit after the last URL (or even work - without a given URL), and then make it read instructions passed on a pipe or - over a socket to make further instructions so that a second subsequent curl - invoke can talk to the still running instance and ask for transfers to get - done, and thus maintain its connection pool, DNS cache and more. - -18.13 Ratelimit or wait between serial requests - - Consider a command line option that can make curl do multiple serial requests - slow, potentially with a (random) wait between transfers. There is also a - proposed set of standard HTTP headers to let servers let the client adapt to - its rate limits: - https://www.ietf.org/id/draft-polli-ratelimit-headers-02.html - - See https://github.com/curl/curl/issues/5406 - -18.14 --dry-run - - A command line option that makes curl show exactly what it would do and send - if it would run for real. - - See https://github.com/curl/curl/issues/5426 - -18.15 --retry should resume - - When --retry is used and curl actually retries transfer, it should use the - already transferred data and do a resumed transfer for the rest (when - possible) so that it does not have to transfer the same data again that was - already transferred before the retry. - - See https://github.com/curl/curl/issues/1084 - -18.16 send only part of --data - - When the user only wants to send a small piece of the data provided with - --data or --data-binary, like when that data is a huge file, consider a way - to specify that curl should only send a piece of that. One suggested syntax - would be: "--data-binary @largefile.zip!1073741823-2147483647". - - See https://github.com/curl/curl/issues/1200 - -18.17 consider file name from the redirected URL with -O ? - - When a user gives a URL and uses -O, and curl follows a redirect to a new - URL, the file name is not extracted and used from the newly redirected-to URL - even if the new URL may have a much more sensible file name. - - This is clearly documented and helps for security since there is no surprise - to users which file name that might get overwritten. But maybe a new option - could allow for this or maybe -J should imply such a treatment as well as -J - already allows for the server to decide what file name to use so it already - provides the "may overwrite any file" risk. - - This is extra tricky if the original URL has no file name part at all since - then the current code path will error out with an error message, and we cannot - *know* already at that point if curl will be redirected to a URL that has a - file name... - - See https://github.com/curl/curl/issues/1241 - -18.18 retry on network is unreachable - - The --retry option retries transfers on "transient failures". We later added - --retry-connrefused to also retry for "connection refused" errors. - - Suggestions have been brought to also allow retry on "network is unreachable" - errors and while totally reasonable, maybe we should consider a way to make - this more configurable than to add a new option for every new error people - want to retry for? - - https://github.com/curl/curl/issues/1603 - -18.19 expand ~/ in config files - - For example .curlrc could benefit from being able to do this. - - See https://github.com/curl/curl/issues/2317 - -18.20 host name sections in config files - - config files would be more powerful if they could set different - configurations depending on used URLs, host name or possibly origin. Then a - default .curlrc could a specific user-agent only when doing requests against - a certain site. - -18.21 retry on the redirected-to URL - - When curl is told to --retry a failed transfer and follows redirects, it - might get an HTTP 429 response from the redirected-to URL and not the - original one, which then could make curl decide to rather retry the transfer - on that URL only instead of the original operation to the original URL. - - Perhaps extra emphasized if the original transfer is a large POST that - redirects to a separate GET, and that GET is what gets the 529 - - See https://github.com/curl/curl/issues/5462 - -18.23 Set the modification date on an uploaded file - - For SFTP and possibly FTP, curl could offer an option to set the - modification time for the uploaded file. - - See https://github.com/curl/curl/issues/5768 - -18.24 Use multiple parallel transfers for a single download - - To enhance transfer speed, downloading a single URL can be split up into - multiple separate range downloads that get combined into a single final - result. - - An ideal implementation would not use a specified number of parallel - transfers, but curl could: - - First start getting the full file as transfer A - - If after N seconds have passed and the transfer is expected to continue for - M seconds or more, add a new transfer (B) that asks for the second half of - A's content (and stop A at the middle). - - If splitting up the work improves the transfer rate, it could then be done - again. Then again, etc up to a limit. - - This way, if transfer B fails (because Range: is not supported) it will let - transfer A remain the single one. N and M could be set to some sensible - defaults. - - See https://github.com/curl/curl/issues/5774 - -18.25 Prevent terminal injection when writing to terminal - - curl could offer an option to make escape sequence either non-functional or - avoid cursor moves or similar to reduce the risk of a user getting tricked by - clever tricks. - - See https://github.com/curl/curl/issues/6150 - -18.26 Custom progress meter update interval - - Users who are for example doing large downloads in CI or remote setups might - want the occasional progress meter update to see that the transfer is - progressing and has not stuck, but they may not appreciate the - many-times-a-second frequency curl can end up doing it with now. - -18.27 -J and -O with %-encoded file names - - -J/--remote-header-name does not decode %-encoded file names. RFC 6266 details - how it should be done. The can of worm is basically that we have no charset - handling in curl and ascii >=128 is a challenge for us. Not to mention that - decoding also means that we need to check for nastiness that is attempted, - like "../" sequences and the like. Probably everything to the left of any - embedded slashes should be cut off. - https://curl.se/bug/view.cgi?id=1294 - - -O also does not decode %-encoded names, and while it has even less - information about the charset involved the process is similar to the -J case. - - Note that we will not add decoding to -O without the user asking for it with - some other means as well, since -O has always been documented to use the name - exactly as specified in the URL. - -18.28 -J with -C - - - When using -J (with -O), automatically resumed downloading together with "-C - -" fails. Without -J the same command line works. This happens because the - resume logic is worked out before the target file name (and thus its - pre-transfer size) has been figured out. This can be improved. - - https://curl.se/bug/view.cgi?id=1169 - -18.29 --retry and transfer timeouts - - If using --retry and the transfer timeouts (possibly due to using -m or - -y/-Y) the next attempt does not resume the transfer properly from what was - downloaded in the previous attempt but will truncate and restart at the - original position where it was at before the previous failed attempt. See - https://curl.se/mail/lib-2008-01/0080.html and Mandriva bug report - https://qa.mandriva.com/show_bug.cgi?id=22565 - - - -19. Build - -19.1 roffit - - Consider extending 'roffit' to produce decent ASCII output, and use that - instead of (g)nroff when building src/tool_hugehelp.c - -19.2 Enable PIE and RELRO by default - - Especially when having programs that execute curl via the command line, PIE - renders the exploitation of memory corruption vulnerabilities a lot more - difficult. This can be attributed to the additional information leaks being - required to conduct a successful attack. RELRO, on the other hand, masks - different binary sections like the GOT as read-only and thus kills a handful - of techniques that come in handy when attackers are able to arbitrarily - overwrite memory. A few tests showed that enabling these features had close - to no impact, neither on the performance nor on the general functionality of - curl. - -19.3 Do not use GNU libtool on OpenBSD - When compiling curl on OpenBSD with "--enable-debug" it will give linking - errors when you use GNU libtool. This can be fixed by using the libtool - provided by OpenBSD itself. However for this the user always needs to invoke - make with "LIBTOOL=/usr/bin/libtool". It would be nice if the script could - have some magic to detect if this system is an OpenBSD host and then use the - OpenBSD libtool instead. - - See https://github.com/curl/curl/issues/5862 - -19.4 Package curl for Windows in a signed installer - - See https://github.com/curl/curl/issues/5424 - -19.5 make configure use --cache-file more and better - - The configure script can be improved to cache more values so that repeated - invokes run much faster. - - See https://github.com/curl/curl/issues/7753 - -19.6 build curl with Windows Unicode support - - The user wants an easier way to tell autotools to build curl with Windows - Unicode support, like ./configure --enable-windows-unicode - - See https://github.com/curl/curl/issues/7229 - -20. Test suite - -20.1 SSL tunnel - - Make our own version of stunnel for simple port forwarding to enable HTTPS - and FTP-SSL tests without the stunnel dependency, and it could allow us to - provide test tools built with either OpenSSL or GnuTLS - -20.2 nicer lacking perl message - - If perl was not found by the configure script, do not attempt to run the tests - but explain something nice why it does not. - -20.3 more protocols supported - - Extend the test suite to include more protocols. The telnet could just do FTP - or http operations (for which we have test servers). - -20.4 more platforms supported - - Make the test suite work on more platforms. OpenBSD and Mac OS. Remove - fork()s and it should become even more portable. - -20.5 Add support for concurrent connections - - Tests 836, 882 and 938 were designed to verify that separate connections are - not used when using different login credentials in protocols that should not - reuse a connection under such circumstances. - - Unfortunately, ftpserver.pl does not appear to support multiple concurrent - connections. The read while() loop seems to loop until it receives a - disconnect from the client, where it then enters the waiting for connections - loop. When the client opens a second connection to the server, the first - connection has not been dropped (unless it has been forced - which we - should not do in these tests) and thus the wait for connections loop is never - entered to receive the second connection. - -20.6 Use the RFC 6265 test suite - - A test suite made for HTTP cookies (RFC 6265) by Adam Barth is available at - https://github.com/abarth/http-state/tree/master/tests - - It'd be really awesome if someone would write a script/setup that would run - curl with that test suite and detect deviances. Ideally, that would even be - incorporated into our regular test suite. - -20.7 Support LD_PRELOAD on macOS - - LD_RELOAD does not work on macOS, but there are tests which require it to run - properly. Look into making the preload support in runtests.pl portable such - that it uses DYLD_INSERT_LIBRARIES on macOS. - -20.8 Run web-platform-tests URL tests - - Run web-platform-tests URL tests and compare results with browsers on wpt.fyi - - It would help us find issues to fix and help us document where our parser - differs from the WHATWG URL spec parsers. - - See https://github.com/curl/curl/issues/4477 - -21. MQTT - -21.1 Support rate-limiting - - The rate-limiting logic is done in the PERFORMING state in multi.c but MQTT - is not (yet) implemented to use that. diff --git a/third-party/curl/docs/TODO.md b/third-party/curl/docs/TODO.md new file mode 100644 index 0000000000..15d6c02ba0 --- /dev/null +++ b/third-party/curl/docs/TODO.md @@ -0,0 +1,1032 @@ + + +# TODO intro + +Things to do in project curl. Please tell us what you think, contribute and +send us patches that improve things. + +Be aware that these are things that we could do, or have once been considered +things we could do. If you want to work on any of these areas, please consider +bringing it up for discussions first on the mailing list so that we all agree +it is still a good idea for the project. + +All bugs documented in the [known_bugs +document](https://curl.se/docs/knownbugs.html) are subject for fixing. + +# libcurl + +## Consult `%APPDATA%` also for `.netrc` + +`%APPDATA%\.netrc` is not considered when running on Windows. Should it not? + +See [curl issue 4016](https://github.com/curl/curl/issues/4016) + +## `struct lifreq` + +Use `struct lifreq` and `SIOCGLIFADDR` instead of `struct ifreq` and +`SIOCGIFADDR` on newer Solaris versions as they claim the latter is obsolete. +To support IPv6 interface addresses for network interfaces properly. + +## alt-svc sharing + +The share interface could benefit from allowing the alt-svc cache to be +possible to share between easy handles. + +See [curl issue 4476](https://github.com/curl/curl/issues/4476) + +The share interface offers CURL_LOCK_DATA_CONNECT to have multiple easy +handle share a connection cache, but due to how connections are used they are +still not thread-safe when used shared. + +See [curl issue 4915](https://github.com/curl/curl/issues/4915) and lib1541.c + +The share interface offers CURL_LOCK_DATA_HSTS to have multiple easy handle +share an HSTS cache, but this is not thread-safe. + +## thread-safe sharing + +Using the share interface users can share some data between easy handles but +several of the sharing options are documented as not safe and supported to +share between multiple concurrent threads. Fixing this would enable more users +to share data in more powerful ways. + +## updated DNS server while running + +If `/etc/resolv.conf` gets updated while a program using libcurl is running, it +is may cause name resolves to fail unless `res_init()` is called. We should +consider calling `res_init()` + retry once unconditionally on all name resolve +failures to mitigate against this. Firefox works like that. Note that Windows +does not have `res_init()` or an alternative. + +[curl issue 2251](https://github.com/curl/curl/issues/2251) + +## c-ares and CURLOPT_OPENSOCKETFUNCTION + +curl creates most sockets via the CURLOPT_OPENSOCKETFUNCTION callback and +close them with the CURLOPT_CLOSESOCKETFUNCTION callback. c-ares does not use +those functions and instead opens and closes the sockets itself. This means +that when curl passes the c-ares socket to the CURLMOPT_SOCKETFUNCTION it is +not owned by the application like other sockets. + +See [curl issue 2734](https://github.com/curl/curl/issues/2734) + +## Monitor connections in the connection pool + +libcurl's connection cache or pool holds a number of open connections for the +purpose of possible subsequent connection reuse. It may contain a few up to a +significant amount of connections. Currently, libcurl leaves all connections +as they are and first when a connection is iterated over for matching or reuse +purpose it is verified that it is still alive. + +Those connections may get closed by the server side for idleness or they may +get an HTTP/2 ping from the peer to verify that they are still alive. By +adding monitoring of the connections while in the pool, libcurl can detect +dead connections (and close them) better and earlier, and it can handle HTTP/2 +pings to keep such ones alive even when not actively doing transfers on them. + +## Try to URL encode given URL + +Given a URL that for example contains spaces, libcurl could have an option +that would try somewhat harder than it does now and convert spaces to %20 and +perhaps URL encoded byte values over 128 etc (do what the redirect following +code already does). + +[curl issue 514](https://github.com/curl/curl/issues/514) + +## Add support for IRIs + +IRIs (RFC 3987) allow localized, non-ASCII, names in the URL. To properly +support this, curl/libcurl would need to translate/encode the given input +from the input string encoding into percent encoded output "over the wire". + +To make that work smoothly for curl users even on Windows, curl would probably +need to be able to convert from several input encodings. + +## try next proxy if one does not work + +Allow an application to specify a list of proxies to try, and failing to +connect to the first go on and try the next instead until the list is +exhausted. Browsers support this feature at least when they specify proxies +using `PAC`. + +[curl issue 896](https://github.com/curl/curl/issues/896) + +## provide timing info for each redirect + +curl and libcurl provide timing information via a set of different time-stamps +(CURLINFO_*_TIME). When curl is following redirects, those returned time value +are the accumulated sums. An improvement could be to offer separate timings +for each redirect. + +[curl issue 6743](https://github.com/curl/curl/issues/6743) + +## CURLINFO_PAUSE_STATE + +Return information about the transfer's current pause state, in both +directions. See [curl issue 2588](https://github.com/curl/curl/issues/2588) + +## Expose tried IP addresses that failed + +When libcurl fails to connect to a host, it could offer the application the +addresses that were used in the attempt. Source + destination IP, source + +destination port and protocol (UDP or TCP) for each failure. Possibly as a +callback. Perhaps also provide reason. + +[curl issue 2126](https://github.com/curl/curl/issues/2126) + +## erase secrets from heap/stack after use + +Introducing a concept and system to erase secrets from memory after use, it +could help mitigate and lessen the impact of (future) security problems etc. +However: most secrets are passed to libcurl as clear text from the application +and then clearing them within the library adds nothing... + +[curl issue 7268](https://github.com/curl/curl/issues/7268) + +## make DoH inherit more transfer properties + +Some options are not inherited because they are not relevant for the DoH SSL +connections, or inheriting the option may result in unexpected behavior. For +example the user's debug function callback is not inherited because it would +be unexpected for internal handles (i.e DoH handles) to be passed to that +callback. + +If an option is not inherited then it is not possible to set it separately +for DoH without a DoH-specific option. For example: +`CURLOPT_DOH_SSL_VERIFYHOST`, `CURLOPT_DOH_SSL_VERIFYPEER` and +`CURLOPT_DOH_SSL_VERIFYSTATUS`. + +See [curl issue 6605](https://github.com/curl/curl/issues/6605) + +# libcurl - multi interface + +## More non-blocking + +Make sure we do not ever loop because of non-blocking sockets returning +`EWOULDBLOCK` or similar. Blocking cases include: + +- Name resolves on non-Windows unless c-ares or the threaded resolver is used. +- The threaded resolver may block on cleanup: + [curl issue 4852](https://github.com/curl/curl/issues/4852) +- `file://` transfers +- TELNET transfers +- GSSAPI authentication for FTP transfers +- The "DONE" operation (post transfer protocol-specific actions) for the +protocols SFTP, SMTP, FTP. Fixing `multi_done()` for this is a worthy task. +- `curl_multi_remove_handle()` for any of the above. +- Calling `curl_ws_send()` from a callback + +## Better support for same name resolves + +If a name resolve has been initiated for a given name and a second easy handle +wants to resolve that same name as well, make it wait for the first resolve to +end up in the cache instead of doing a second separate resolve. This is +especially needed when adding many simultaneous handles using the same +hostname when the DNS resolver can get flooded. + +## Non-blocking `curl_multi_remove_handle()` + +The multi interface has a few API calls that assume a blocking behavior, like +`add_handle()` and `remove_handle()` which limits what we can do internally. +The multi API need to be moved even more into a single function that "drives" +everything in a non-blocking manner and signals when something is done. A +remove or add would then only ask for the action to get started and then +`multi_perform()` etc still be called until the add/remove is completed. + +## Split connect and authentication process + +The multi interface treats the authentication process as part of the connect +phase. As such any failures during authentication does not trigger the +relevant QUIT or LOGOFF for protocols such as IMAP, POP3 and SMTP. + +## Edge-triggered sockets should work + +The multi_socket API should work with edge-triggered socket events. One of the +internal actions that need to be improved for this to work perfectly is the +`maxloops` handling in `transfer.c:readwrite_data()`. + +## multi upkeep + +In libcurl 7.62.0 we introduced `curl_easy_upkeep`. It unfortunately only +works on easy handles. We should introduces a version of that for the multi +handle, and also consider doing `upkeep` automatically on connections in the +connection pool when the multi handle is in used. + +See [curl issue 3199](https://github.com/curl/curl/issues/3199) + +## Virtual external sockets + +libcurl performs operations on the given file descriptor that presumes it is a +socket and an application cannot replace them at the moment. Allowing an +application to fully replace those would allow a larger degree of freedom and +flexibility. + +See [curl issue 5835](https://github.com/curl/curl/issues/5835) + +## dynamically decide to use socketpair + +For users who do not use `curl_multi_wait()` or do not care for +`curl_multi_wakeup()`, we could introduce a way to make libcurl NOT create a +socketpair in the multi handle. + +See [curl issue 4829](https://github.com/curl/curl/issues/4829) + +# Documentation + +## Improve documentation about fork safety + +See [curl issue 6968](https://github.com/curl/curl/issues/6968) + +# FTP + +## A fixed directory listing format + +Since listing the contents of a remove directory with FTP is returning the +list in a format and style the server likes without any established or even +defacto standard existing, it would be a feature to users if curl could parse +the directory listing and output a general curl format that is fixed and the +same, independent of the server's choice. This would allow users to better and +more reliably extract information about remote content via FTP directory +listings. + +## GSSAPI via Windows SSPI + +In addition to currently supporting the SASL GSSAPI mechanism (Kerberos V5) +via third-party GSS-API libraries, such as MIT Kerberos, also add support for +GSSAPI authentication via Windows SSPI. + +## STAT for LIST without data connection + +Some FTP servers allow STAT for listing directories instead of using LIST, and +the response is then sent over the control connection instead of as the +otherwise used data connection. + +This is not detailed in any FTP specification. + +## Passive transfer could try other IP addresses + +When doing FTP operations through a proxy at localhost, the reported spotted +that curl only tried to connect once to the proxy, while it had multiple +addresses and a failed connect on one address should make it try the next. + +After switching to passive mode (EPSV), curl could try all IP addresses for +`localhost`. Currently it tries `::1`, but it should also try `127.0.0.1`. + +See [curl issue 1508](https://github.com/curl/curl/issues/1508) + +# HTTP + +## Provide the error body from a CONNECT response + +When curl receives a body response from a CONNECT request to a proxy, it +always reads and ignores it. It would make some users happy if curl instead +optionally would be able to make that responsible available. Via a new +callback? Through some other means? + +See [curl issue 9513](https://github.com/curl/curl/issues/9513) + +## Obey `Retry-After` in redirects + +The `Retry-After` response header is said to dictate "the minimum time that +the user agent is asked to wait before issuing the redirected request" and +libcurl does not obey this. + +See [curl issue 11447](https://github.com/curl/curl/issues/11447) + +## Rearrange request header order + +Server implementers often make an effort to detect browser and to reject +clients it can detect to not match. One of the last details we cannot yet +control in libcurl's HTTP requests, which also can be exploited to detect that +libcurl is in fact used even when it tries to impersonate a browser, is the +order of the request headers. I propose that we introduce a new option in +which you give headers a value, and then when the HTTP request is built it +sorts the headers based on that number. We could then have internally created +headers use a default value so only headers that need to be moved have to be +specified. + +## Allow SAN names in HTTP/2 server push + +curl only allows HTTP/2 push promise if the provided :authority header value +exactly matches the hostname given in the URL. It could be extended to allow +any name that would match the Subject Alternative Names in the server's TLS +certificate. + +See [curl pull request 3581](https://github.com/curl/curl/pull/3581) + +## `auth=` in URLs + +Add the ability to specify the preferred authentication mechanism to use by +using `;auth=` in the login part of the URL. + +For example: + +`http://test:pass;auth=NTLM@example.com` would be equivalent to specifying +`--user test:pass;auth=NTLM` or `--user test:pass --ntlm` from the command +line. + +Additionally this should be implemented for proxy base URLs as well. + +## Require HTTP version X or higher + +curl and libcurl provide options for trying higher HTTP versions (for example +HTTP/2) but then still allows the server to pick version 1.1. We could +consider adding a way to require a minimum version. + +See [curl issue 7980](https://github.com/curl/curl/issues/7980) + +# TELNET + +## ditch stdin + +Reading input (to send to the remote server) on stdin is a crappy solution for +library purposes. We need to invent a good way for the application to be able +to provide the data to send. + +## ditch telnet-specific select + +Move the telnet support's network `select()` loop go away and merge the code +into the main transfer loop. Until this is done, the multi interface does not +work for telnet. + +## feature negotiation debug data + +Add telnet feature negotiation data to the debug callback as header data. + +## exit immediately upon connection if stdin is /dev/null + +If it did, curl could be used to probe if there is an server there listening +on a specific port. That is, the following command would exit immediately +after the connection is established with exit code 0: + + curl -s --connect-timeout 2 telnet://example.com:80 NOTIFY=SUCCESS,FAILURE");`. + +[curl issue 8232](https://github.com/curl/curl/issues/8232) + +## Enhanced capability support + +Add the ability, for an application that uses libcurl, to obtain the list of +capabilities returned from the EHLO command. + +## Add `CURLOPT_MAIL_CLIENT` option + +Rather than use the URL to specify the mail client string to present in the +`HELO` and `EHLO` commands, libcurl should support a new `CURLOPT` +specifically for specifying this data as the URL is non-standard and to be +honest a bit of a hack. + +Please see the following thread for more information: +https://curl.se/mail/lib-2012-05/0178.html + +# POP3 + +## Enhanced capability support + +Add the ability, for an application that uses libcurl, to obtain the list of +capabilities returned from the CAPA command. + +# IMAP + +## Enhanced capability support + +Add the ability, for an application that uses libcurl, to obtain the list of +capabilities returned from the CAPABILITY command. + +# LDAP + +## SASL based authentication mechanisms + +Currently the LDAP module only supports `ldap_simple_bind_s()` in order to +bind to an LDAP server. This function sends username and password details +using the simple authentication mechanism (as clear text). It should be +possible to use `ldap_bind_s()` instead specifying the security context +information ourselves. + +## `CURLOPT_SSL_CTX_FUNCTION` for LDAPS + +`CURLOPT_SSL_CTX_FUNCTION` works perfectly for HTTPS and email protocols, but +it has no effect for LDAPS connections. + +[curl issue 4108](https://github.com/curl/curl/issues/4108) + +## Paged searches on LDAP server + +[curl issue 4452](https://github.com/curl/curl/issues/4452) + +## Certificate-Based Authentication + +LDAPS not possible with macOS and Windows with Certificate-Based Authentication + +[curl issue 9641](https://github.com/curl/curl/issues/9641) + +# SMB + +## Support modern versions + +curl only supports version 1, which barely anyone is using anymore. + +## File listing support + +Add support for listing the contents of an SMB share. The output should +probably be the same as/similar to FTP. + +## Honor file timestamps + +The timestamp of the transferred file should reflect that of the original +file. + +## Use NTLMv2 + +Currently the SMB authentication uses NTLMv1. + +## Create remote directories + +Support for creating remote directories when uploading a file to a directory +that does not exist on the server, like `--ftp-create-dirs`. + +# FILE + +## Directory listing on non-POSIX + +Listing the contents of a directory accessed with FILE only works on platforms +with `opendir()`. Support could be added for more systems, like Windows. + +# TLS + +## `TLS-PSK` with OpenSSL + +Transport Layer Security pre-shared key cipher suites (`TLS-PSK`) is a set of +cryptographic protocols that provide secure communication based on pre-shared +keys (`PSK`). These pre-shared keys are symmetric keys shared in advance among +the communicating parties. + +[curl issue 5081](https://github.com/curl/curl/issues/5081) + +## TLS channel binding + +TLS 1.2 and 1.3 provide the ability to extract some secret data from the TLS +connection and use it in the client request (usually in some sort of +authentication) to ensure that the data sent is bound to the specific TLS +connection and cannot be successfully intercepted by a proxy. This +functionality can be used in a standard authentication mechanism such as +GSS-API or SCRAM, or in custom approaches like custom HTTP Authentication +headers. + +For TLS 1.2, the binding type is usually `tls-unique`, and for TLS 1.3 it is +`tls-exporter`. + +- https://datatracker.ietf.org/doc/html/rfc5929 +- https://datatracker.ietf.org/doc/html/rfc9266 +- [curl issue 9226](https://github.com/curl/curl/issues/9226) + +## Defeat TLS fingerprinting + +By changing the order of TLS extensions provided in the TLS handshake, it is +sometimes possible to circumvent TLS fingerprinting by servers. The TLS +extension order is of course not the only way to fingerprint a client. + +## Consider OCSP stapling by default + +Treat a negative response a reason for aborting the connection. Since OCSP +stapling is presumed to get used much less in the future when Let's Encrypt +drops the OCSP support, the benefit of this might however be limited. + +[curl issue 15483](https://github.com/curl/curl/issues/15483) + +## Provide callback for cert verification + +OpenSSL supports a callback for customized verification of the peer +certificate, but this does not seem to be exposed in the libcurl APIs. Could +it be? There is so much that could be done if it were. + +## Less memory massaging with Schannel + +The Schannel backend does a lot of custom memory management we would rather +avoid: the repeated allocation + free in sends and the custom memory + realloc +system for encrypted and decrypted data. That should be avoided and reduced +for 1) efficiency and 2) safety. + +## Support DANE + +[DNS-Based Authentication of Named Entities +(DANE)](https://datatracker.ietf.org/doc/html/rfc6698) is a way to provide +SSL keys and certs over DNS using DNSSEC as an alternative to the CA model. + +A patch was posted on March 7 2013 +(https://curl.se/mail/lib-2013-03/0075.html) but it was a too simple approach. +See Daniel's comments: https://curl.se/mail/lib-2013-03/0103.html + +Björn Stenberg once wrote a separate initial take on DANE that was never +completed. + +## TLS record padding + +TLS (1.3) offers optional record padding and OpenSSL provides an API for it. I +could make sense for libcurl to offer this ability to applications to make +traffic patterns harder to figure out by network traffic observers. + +See [curl issue 5398](https://github.com/curl/curl/issues/5398) + +## Support Authority Information Access certificate extension (AIA) + +AIA can provide various things like certificate revocation lists but more +importantly information about intermediate CA certificates that can allow +validation path to be fulfilled when the HTTPS server does not itself provide +them. + +Since AIA is about downloading certs on demand to complete a TLS handshake, it +is probably a bit tricky to get done right and a serious privacy leak. + +See [curl issue 2793](https://github.com/curl/curl/issues/2793) + +## Some TLS options are not offered for HTTPS proxies + +Some TLS related options to the command line tool and libcurl are only +provided for the server and not for HTTPS proxies. `--proxy-tls-max`, +`--proxy-tlsv1.3`, `--proxy-curves` and a few more. For more Documentation on +this see: https://curl.se/libcurl/c/tls-options.html + +[curl issue 12286](https://github.com/curl/curl/issues/12286) + +## Make sure we forbid TLS 1.3 post-handshake authentication + +RFC 8740 explains how using HTTP/2 must forbid the use of TLS 1.3 +post-handshake authentication. We should make sure to live up to that. + +See [curl issue 5396](https://github.com/curl/curl/issues/5396) + +## Support the `clienthello` extension + +Certain stupid networks and middle boxes have a problem with SSL handshake +packets that are within a certain size range because how that sets some bits +that previously (in older TLS version) were not set. The `clienthello` +extension adds padding to avoid that size range. + +- https://datatracker.ietf.org/doc/html/rfc7685 +- [curl issue 2299](https://github.com/curl/curl/issues/2299) + +## Share the CA cache + +For TLS backends that supports CA caching, it makes sense to allow the share +object to be used to store the CA cache as well via the share API. Would allow +multiple easy handles to reuse the CA cache and save themselves from a lot of +extra processing overhead. + +## Add missing features to TLS backends + +The feature matrix at https://curl.se/libcurl/c/tls-options.html shows which +features are supported by which TLS backends, and thus also where there are +feature gaps. + +# Proxy + +## Retry SOCKS handshake on address type not supported + +When curl resolves a hostname, it might get a mix of IPv6 and IPv4 returned. +curl might then use an IPv6 address with a SOCKS5 proxy, which - if it does +not support IPv6 - returns "Address type not supported" and curl exits with +that error. + +Perhaps it is preferred if curl would in this situation instead first retry +the SOCKS handshake again for this case and then use one of the IPv4 addresses +for the target host. + +See [curl issue 17222](https://github.com/curl/curl/issues/17222) + +# Schannel + +## Extend support for client certificate authentication + +The existing support for the `-E`/`--cert` and `--key` options could be +extended by supplying a custom certificate and key in PEM format, see: +[Getting a Certificate for +Schannel](https://learn.microsoft.com/windows/win32/secauthn/getting-a-certificate-for-schannel) + +## Extend support for the `--ciphers` option + +The existing support for the `--ciphers` option could be extended by mapping +the OpenSSL/GnuTLS cipher suites to the Schannel APIs, see [Specifying +Schannel Ciphers and Cipher +Strengths](https://learn.microsoft.com/windows/win32/secauthn/specifying-schannel-ciphers-and-cipher-strengths). + +## Add option to allow abrupt server closure + +libcurl with Schannel errors without a known termination point from the server +(such as length of transfer, or SSL "close notify" alert) to prevent against a +truncation attack. Really old servers may neglect to send any termination +point. An option could be added to ignore such abrupt closures. + +[curl issue 4427](https://github.com/curl/curl/issues/4427) + +# SASL + +## Other authentication mechanisms + +Add support for other authentication mechanisms such as `OLP`, `GSS-SPNEGO` +and others. + +## Add `QOP` support to GSSAPI authentication + +Currently the GSSAPI authentication only supports the default `QOP` of auth +(Authentication), whilst Kerberos V5 supports both `auth-int` (Authentication +with integrity protection) and `auth-conf` (Authentication with integrity and +privacy protection). + +# SSH protocols + +## Multiplexing + +SSH is a perfectly fine multiplexed protocols which would allow libcurl to do +multiple parallel transfers from the same host using the same connection, much +in the same spirit as HTTP/2 does. libcurl however does not take advantage of +that ability but does instead always create a new connection for new transfers +even if an existing connection already exists to the host. + +To fix this, libcurl would have to detect an existing connection and "attach" +the new transfer to the existing one. + +## Handle growing SFTP files + +The SFTP code in libcurl checks the file size *before* a transfer starts and +then proceeds to transfer exactly that amount of data. If the remote file +grows while the transfer is in progress libcurl does not notice and does not +adapt. The OpenSSH SFTP command line tool does and libcurl could also attempt +to download more to see if there is more to get... + +[curl issue 4344](https://github.com/curl/curl/issues/4344) + +## Read keys from `~/.ssh/id_ecdsa`, `id_ed25519` + +The libssh2 backend in curl is limited to only reading keys from `id_rsa` and +`id_dsa`, which makes it fail connecting to servers that use more modern key +types. + +[curl issue 8586](https://github.com/curl/curl/issues/8586) + +## Support `CURLOPT_PREQUOTE` + +The two other `QUOTE` options are supported for SFTP, but this was left out +for unknown reasons. + +## SSH over HTTPS proxy for libssh + +The SSH based protocols SFTP and SCP did not work over HTTPS proxy at all +until [curl pull request 6021](https://github.com/curl/curl/pull/6021) brought +the functionality with the libssh2 backend. Presumably, this support can/could +be added for the libssh backend as well. + +## SFTP with `scp://` + +OpenSSH 9 switched their `scp` tool to speak SFTP under the hood. Going +forward it might be worth having curl or libcurl attempt SFTP if SCP fails to +follow suite. + +# Command line tool + +## multi-threading + +When asked to do transfers in parallel, the curl tool could be extended to use +a number of independent worker threads. This would allow faster transfers in +situations where curl becomes CPU bound. + +Ideally, curl would (with permission) fire up new threads on demand when it +deems that it might be helpful. Perhaps, if it has more transfers to add and +the existing transfers make the CPU busy enough and there are more cores +available. + +## sync + +`curl --sync http://example.com/feed[1-100].rss` or +`curl --sync http://example.net/{index,calendar,history}.html` + +Downloads a range or set of URLs using the remote name, but only if the remote +file is newer than the local file. A `Last-Modified` HTTP date header should +also be used to set the mod date on the downloaded file. + +## glob posts + +Globbing support for `-d` and `-F`, as in `curl -d "name=foo[0-9]" URL`. This +is easily scripted though. + +## `--proxycommand` + +Allow the user to make curl run a command and use its stdio to make requests +and not do any network connection by itself. Example: + + curl --proxycommand 'ssh pi@raspberrypi.local -W 10.1.1.75 80' \ + http://some/otherwise/unavailable/service.php + +See [curl issue 4941](https://github.com/curl/curl/issues/4941) + +## UTF-8 filenames in Content-Disposition + +RFC 6266 documents how UTF-8 names can be passed to a client in the +`Content-Disposition` header, and curl does not support this. + +[curl issue 1888](https://github.com/curl/curl/issues/1888) + +## Option to make `-Z` merge lined based outputs on stdout + +When a user requests multiple lined based files using `-Z` and sends them to +stdout, curl does not *merge* and send complete lines fine but may send +partial lines from several sources. + +[curl issue 5175](https://github.com/curl/curl/issues/5175) + +## specify which response codes that make `-f`/`--fail` return error + +Allows a user to better specify exactly which error code(s) that are fine and +which are errors for their specific uses cases + +## Choose the name of file in braces for complex URLs + +When using braces to download a list of URLs and you use complicated names +in the list of alternatives, it could be handy to allow curl to use other +names when saving. + +Consider a way to offer that. Possibly like +`{partURL1:name1,partURL2:name2,partURL3:name3}` where the name following the +colon is the output name. + +See [curl issue 221](https://github.com/curl/curl/issues/221) + +## improve how curl works in a Windows console window + +If you pull the scroll bar when transferring with curl in a Windows console +window, the transfer is interrupted and can get disconnected. This can +probably be improved. See [curl issue 322](https://github.com/curl/curl/issues/322) + +## Windows: set attribute 'archive' for completed downloads + +The archive bit (`FILE_ATTRIBUTE_ARCHIVE, 0x20`) separates files that shall be +backed up from those that are either not ready or have not changed. + +Downloads in progress are neither ready to be backed up, nor should they be +opened by a different process. Only after a download has been completed it is +sensible to include it in any integer snapshot or backup of the system. + +See [curl issue 3354](https://github.com/curl/curl/issues/3354) + +## keep running, read instructions from pipe/socket + +Provide an option that makes curl not exit after the last URL (or even work +without a given URL), and then make it read instructions passed on a pipe or +over a socket to make further instructions so that a second subsequent curl +invoke can talk to the still running instance and ask for transfers to get +done, and thus maintain its connection pool, DNS cache and more. + +## Acknowledge `Ratelimit` headers + +Consider a command line option that can make curl do multiple serial requests +while acknowledging server specified [rate +limits](https://datatracker.ietf.org/doc/html/draft-ietf-httpapi-ratelimit-headers/). + +See [curl issue 5406](https://github.com/curl/curl/issues/5406) + +## `--dry-run` + +A command line option that makes curl show exactly what it would do and send +if it would run for real. + +See [curl issue 5426](https://github.com/curl/curl/issues/5426) + +## `--retry` should resume + +When `--retry` is used and curl actually retries transfer, it should use the +already transferred data and do a resumed transfer for the rest (when +possible) so that it does not have to transfer the same data again that was +already transferred before the retry. + +See [curl issue 1084](https://github.com/curl/curl/issues/1084) + +## retry on network is unreachable + +The `--retry` option retries transfers on *transient failures*. We later added +`--retry-connrefused` to also retry for *connection refused* errors. + +Suggestions have been brought to also allow retry on *network is unreachable* +errors and while totally reasonable, maybe we should consider a way to make +this more configurable than to add a new option for every new error people +want to retry for? + +[curl issue 1603](https://github.com/curl/curl/issues/1603) + +## hostname sections in config files + +config files would be more powerful if they could set different configurations +depending on used URLs, hostname or possibly origin. Then a default `.curlrc` +could a specific user-agent only when doing requests against a certain site. + +## retry on the redirected-to URL + +When curl is told to `--retry` a failed transfer and follows redirects, it +might get an HTTP 429 response from the redirected-to URL and not the original +one, which then could make curl decide to rather retry the transfer on that +URL only instead of the original operation to the original URL. + +Perhaps extra emphasized if the original transfer is a large POST that +redirects to a separate GET, and that GET is what gets the 529 + +See [curl issue 5462](https://github.com/curl/curl/issues/5462) + +## Set the modification date on an uploaded file + +For SFTP and possibly FTP, curl could offer an option to set the modification +time for the uploaded file. + +See [curl issue 5768](https://github.com/curl/curl/issues/5768) + +## Use multiple parallel transfers for a single download + +To enhance transfer speed, downloading a single URL can be split up into +multiple separate range downloads that get combined into a single final +result. + +An ideal implementation would not use a specified number of parallel +transfers, but curl could: +- First start getting the full file as transfer A +- If after N seconds have passed and the transfer is expected to continue for + M seconds or more, add a new transfer (B) that asks for the second half of + A's content (and stop A at the middle). +- If splitting up the work improves the transfer rate, it could then be done + again. Then again, etc up to a limit. + +This way, if transfer B fails (because Range: is not supported) it lets +transfer A remain the single one. N and M could be set to some sensible +defaults. + +See [curl issue 5774](https://github.com/curl/curl/issues/5774) + +## Prevent terminal injection when writing to terminal + +curl could offer an option to make escape sequence either non-functional or +avoid cursor moves or similar to reduce the risk of a user getting tricked by +clever tricks. + +See [curl issue 6150](https://github.com/curl/curl/issues/6150) + +## `-J` and `-O` with %-encoded filenames + +`-J`/`--remote-header-name` does not decode %-encoded filenames. RFC 6266 +details how it should be done. The can of worm is that we have no charset +handling in curl and ASCII >=128 is a challenge for us. Not to mention that +decoding also means that we need to check for nastiness that is attempted, +like `../` sequences and the like. Probably everything to the left of any +embedded slashes should be cut off. See https://curl.se/bug/view.cgi?id=1294 + +`-O` also does not decode %-encoded names, and while it has even less +information about the charset involved the process is similar to the `-J` +case. + +Note that we do not decode `-O` without the user asking for it with some other +means, since `-O` has always been documented to use the name exactly as +specified in the URL. + +## `-J` with `-C -` + +When using `-J` (with `-O`), automatically resumed downloading together with +`-C -` fails. Without `-J` the same command line works. This happens because +the resume logic is worked out before the target filename (and thus its +pre-transfer size) has been figured out. This can be improved. + +https://curl.se/bug/view.cgi?id=1169 + +## `--retry` and transfer timeouts + +If using `--retry` and the transfer timeouts (possibly due to using -m or +`-y`/`-Y`) the next attempt does not resume the transfer properly from what +was downloaded in the previous attempt but truncates and restarts at the +original position where it was at before the previous failed attempt. See +https://curl.se/mail/lib-2008-01/0080.html + +# Build + +## Enable `PIE` and `RELRO` by default + +Especially when having programs that execute curl via the command line, `PIE` +renders the exploitation of memory corruption vulnerabilities a lot more +difficult. This can be attributed to the additional information leaks being +required to conduct a successful attack. `RELRO`, on the other hand, masks +different binary sections like the `GOT` as read-only and thus kills a handful +of techniques that come in handy when attackers are able to arbitrarily +overwrite memory. A few tests showed that enabling these features had close to +no impact, neither on the performance nor on the general functionality of +curl. + +## Do not use GNU libtool on OpenBSD + +When compiling curl on OpenBSD with `--enable-debug` it gives linking errors +when you use GNU libtool. This can be fixed by using the libtool provided by +OpenBSD itself. However for this the user always needs to invoke make with +`LIBTOOL=/usr/bin/libtool`. It would be nice if the script could have some +logic to detect if this system is an OpenBSD host and then use the OpenBSD +libtool instead. + +See [curl issue 5862](https://github.com/curl/curl/issues/5862) + +## Package curl for Windows in a signed installer + +See [curl issue 5424](https://github.com/curl/curl/issues/5424) + +## make configure use `--cache-file` more and better + +The configure script can be improved to cache more values so that repeated +invokes run much faster. + +See [curl issue 7753](https://github.com/curl/curl/issues/7753) + +# Test suite + +## SSL tunnel + +Make our own version of stunnel for simple port forwarding to enable HTTPS and +FTP-SSL tests without the stunnel dependency, and it could allow us to provide +test tools built with either OpenSSL or GnuTLS + +## more protocols supported + +Extend the test suite to include more protocols. The telnet could do FTP or +http operations (for which we have test servers). + +## more platforms supported + +Make the test suite work on more platforms. OpenBSD and macOS. Remove fork()s +and it should become even more portable. + +## write an SMB test server to replace impacket + +This would allow us to run SMB tests on more platforms and do better and more +covering tests. + +See [curl issue 15697](https://github.com/curl/curl/issues/15697) + +## Use the RFC 6265 test suite + +A test suite made for HTTP cookies (RFC 6265) by Adam Barth [is +available](https://github.com/abarth/http-state/tree/master/tests). + +It would be good if someone would write a script/setup that would run curl +with that test suite and detect deviance. Ideally, that would even be +incorporated into our regular test suite. + +## Run web-platform-tests URL tests + +Run web-platform-tests URL tests and compare results with browsers on +`wpt.fyi`. + +It would help us find issues to fix and help us document where our parser +differs from the WHATWG URL spec parsers. + +See [curl issue 4477](https://github.com/curl/curl/issues/4477) + +# MQTT + +## Support rate-limiting + +The rate-limiting logic is done in the PERFORMING state in multi.c but MQTT is +not (yet) implemented to use that. + +## Support MQTTS + +## Handle network blocks + +Running test suite with `CURL_DBG_SOCK_WBLOCK=90 ./runtests.pl -a mqtt` makes +several MQTT test cases fail where they should not. + +## large payloads + +libcurl unnecessarily allocates heap memory to hold the entire payload to get +sent, when the data is already perfectly accessible where it is when +`CURLOPT_POSTFIELDS` is used. This is highly inefficient for larger payloads. +Additionally, libcurl does not support using the read callback for sending +MQTT which is yet another way to avoid having to hold large payload in memory. + +# TFTP + +## TFTP does not convert LF to CRLF for `mode=netascii` + +RFC 3617 defines that an TFTP transfer can be done using `netascii` mode. curl +does not support extracting that mode from the URL nor does it treat such +transfers specifically. It should probably do LF to CRLF translations for +them. + +See [curl issue 12655](https://github.com/curl/curl/issues/12655) + +# Gopher + +## Handle network blocks + +Running test suite with `CURL_DBG_SOCK_WBLOCK=90 ./runtests.pl -a 1200 to +1300` makes several Gopher test cases fail where they should not. diff --git a/third-party/curl/docs/TheArtOfHttpScripting.md b/third-party/curl/docs/TheArtOfHttpScripting.md index 2973a36cd2..541cb4c2ff 100644 --- a/third-party/curl/docs/TheArtOfHttpScripting.md +++ b/third-party/curl/docs/TheArtOfHttpScripting.md @@ -1,238 +1,240 @@ -# The Art Of Scripting HTTP Requests Using Curl + + +# The Art Of Scripting HTTP Requests Using curl ## Background - This document assumes that you are familiar with HTML and general networking. +This document assumes that you are familiar with HTML and general networking. - The increasing amount of applications moving to the web has made "HTTP - Scripting" more frequently requested and wanted. To be able to automatically - extract information from the web, to fake users, to post or upload data to - web servers are all important tasks today. +The increasing amount of applications moving to the web has made "HTTP +Scripting" more frequently requested and wanted. To be able to automatically +extract information from the web, to fake users, to post or upload data to +web servers are all important tasks today. - Curl is a command line tool for doing all sorts of URL manipulations and - transfers, but this particular document will focus on how to use it when - doing HTTP requests for fun and profit. This documents assumes that you know - how to invoke `curl --help` or `curl --manual` to get basic information about - it. +curl is a command line tool for doing all sorts of URL manipulations and +transfers, but this particular document focuses on how to use it when doing +HTTP requests for fun and profit. This documents assumes that you know how to +invoke `curl --help` or `curl --manual` to get basic information about it. - Curl is not written to do everything for you. It makes the requests, it gets - the data, it sends data and it retrieves the information. You probably need - to glue everything together using some kind of script language or repeated - manual invokes. +curl is not written to do everything for you. It makes the requests, it gets +the data, it sends data and it retrieves the information. You probably need +to glue everything together using some kind of script language or repeated +manual invokes. ## The HTTP Protocol - HTTP is the protocol used to fetch data from web servers. It is a simple - protocol that is built upon TCP/IP. The protocol also allows information to - get sent to the server from the client using a few different methods, as will - be shown here. +HTTP is the protocol used to fetch data from web servers. It is a simple +protocol that is built upon TCP/IP. The protocol also allows information to +get sent to the server from the client using a few different methods, as is +shown here. - HTTP is plain ASCII text lines being sent by the client to a server to - request a particular action, and then the server replies a few text lines - before the actual requested content is sent to the client. +HTTP is plain ASCII text lines being sent by the client to a server to +request a particular action, and then the server replies a few text lines +before the actual requested content is sent to the client. - The client, curl, sends an HTTP request. The request contains a method (like - GET, POST, HEAD etc), a number of request headers and sometimes a request - body. The HTTP server responds with a status line (indicating if things went - well), response headers and most often also a response body. The "body" part - is the plain data you requested, like the actual HTML or the image etc. +The client, curl, sends an HTTP request. The request contains a method (like +GET, POST, HEAD etc), a number of request headers and sometimes a request +body. The HTTP server responds with a status line (indicating if things went +well), response headers and most often also a response body. The "body" part +is the plain data you requested, like the actual HTML or the image etc. ## See the Protocol - Using curl's option [`--verbose`](https://curl.se/docs/manpage.html#-v) - (`-v` as a short option) will display what kind of commands curl sends to the - server, as well as a few other informational texts. +Using curl's option [`--verbose`](https://curl.se/docs/manpage.html#-v) (`-v` +as a short option) displays what kind of commands curl sends to the server, +as well as a few other informational texts. - `--verbose` is the single most useful option when it comes to debug or even - understand the curl<->server interaction. +`--verbose` is the single most useful option when it comes to debug or even +understand the curl<->server interaction. - Sometimes even `--verbose` is not enough. Then - [`--trace`](https://curl.se/docs/manpage.html#-trace) and - [`--trace-ascii`](https://curl.se/docs/manpage.html#--trace-ascii) - offer even more details as they show **everything** curl sends and - receives. Use it like this: +Sometimes even `--verbose` is not enough. Then +[`--trace`](https://curl.se/docs/manpage.html#-trace) and +[`--trace-ascii`](https://curl.se/docs/manpage.html#--trace-ascii) +offer even more details as they show **everything** curl sends and +receives. Use it like this: - curl --trace-ascii debugdump.txt http://www.example.com/ + curl --trace-ascii debugdump.txt https://www.example.com/ ## See the Timing - Many times you may wonder what exactly is taking all the time, or you just - want to know the amount of milliseconds between two points in a transfer. For - those, and other similar situations, the - [`--trace-time`](https://curl.se/docs/manpage.html#--trace-time) option - is what you need. It will prepend the time to each trace output line: +Many times you may wonder what exactly is taking all the time, or you want to +know the amount of milliseconds between two points in a transfer. For those, +and other similar situations, the +[`--trace-time`](https://curl.se/docs/manpage.html#--trace-time) option is +what you need. It prepends the time to each trace output line: - curl --trace-ascii d.txt --trace-time http://example.com/ + curl --trace-ascii d.txt --trace-time https://example.com/ ## See which Transfer - When doing parallel transfers, it is relevant to see which transfer is - doing what. When response headers are received (and logged) you need to - know which transfer these are for. - [`--trace-ids`](https://curl.se/docs/manpage.html#--trace-ids) option - is what you need. It will prepend the transfer and connection identifier - to each trace output line: +When doing parallel transfers, it is relevant to see which transfer is doing +what. When response headers are received (and logged) you need to know which +transfer these are for. +[`--trace-ids`](https://curl.se/docs/manpage.html#--trace-ids) option is what +you need. It prepends the transfer and connection identifier to each trace +output line: - curl --trace-ascii d.txt --trace-ids http://example.com/ + curl --trace-ascii d.txt --trace-ids https://example.com/ ## See the Response - By default curl sends the response to stdout. You need to redirect it - somewhere to avoid that, most often that is done with `-o` or `-O`. +By default curl sends the response to stdout. You need to redirect it +somewhere to avoid that, most often that is done with `-o` or `-O`. # URL ## Spec - The Uniform Resource Locator format is how you specify the address of a - particular resource on the Internet. You know these, you have seen URLs like - https://curl.se or https://example.com a million times. RFC 3986 is the - canonical spec. And yeah, the formal name is not URL, it is URI. +The Uniform Resource Locator format is how you specify the address of a +particular resource on the Internet. You know these, you have seen URLs like +https://curl.se/ or https://example.com/ a million times. RFC 3986 is the +canonical spec. The formal name is not URL, it is **URI**. ## Host - The host name is usually resolved using DNS or your /etc/hosts file to an IP - address and that is what curl will communicate with. Alternatively you specify - the IP address directly in the URL instead of a name. +The hostname is usually resolved using DNS or your /etc/hosts file to an IP +address and that is what curl communicates with. Alternatively you specify +the IP address directly in the URL instead of a name. - For development and other trying out situations, you can point to a different - IP address for a host name than what would otherwise be used, by using curl's - [`--resolve`](https://curl.se/docs/manpage.html#--resolve) option: +For development and other trying out situations, you can point to a different +IP address for a hostname than what would otherwise be used, by using curl's +[`--resolve`](https://curl.se/docs/manpage.html#--resolve) option: - curl --resolve www.example.org:80:127.0.0.1 http://www.example.org/ + curl --resolve www.example.org:80:127.0.0.1 https://www.example.org/ ## Port number - Each protocol curl supports operates on a default port number, be it over TCP - or in some cases UDP. Normally you do not have to take that into - consideration, but at times you run test servers on other ports or - similar. Then you can specify the port number in the URL with a colon and a - number immediately following the host name. Like when doing HTTP to port - 1234: +Each protocol curl supports operates on a default port number, be it over TCP +or in some cases UDP. Normally you do not have to take that into +consideration, but at times you run test servers on other ports or +similar. Then you can specify the port number in the URL with a colon and a +number immediately following the hostname. Like when doing HTTP to port +1234: - curl http://www.example.org:1234/ + curl https://www.example.org:1234/ - The port number you specify in the URL is the number that the server uses to - offer its services. Sometimes you may use a proxy, and then you may - need to specify that proxy's port number separately from what curl needs to - connect to the server. Like when using an HTTP proxy on port 4321: +The port number you specify in the URL is the number that the server uses to +offer its services. Sometimes you may use a proxy, and then you may +need to specify that proxy's port number separately from what curl needs to +connect to the server. Like when using an HTTP proxy on port 4321: - curl --proxy http://proxy.example.org:4321 http://remote.example.org/ + curl --proxy http://proxy.example.org:4321 https://remote.example.org/ -## User name and password +## Username and password - Some services are setup to require HTTP authentication and then you need to - provide name and password which is then transferred to the remote site in - various ways depending on the exact authentication protocol used. +Some services are setup to require HTTP authentication and then you need to +provide name and password which is then transferred to the remote site in +various ways depending on the exact authentication protocol used. - You can opt to either insert the user and password in the URL or you can - provide them separately: +You can opt to either insert the user and password in the URL or you can +provide them separately: - curl http://user:password@example.org/ + curl https://user:password@example.org/ - or +or - curl -u user:password http://example.org/ + curl -u user:password https://example.org/ - You need to pay attention that this kind of HTTP authentication is not what - is usually done and requested by user-oriented websites these days. They tend - to use forms and cookies instead. +You need to pay attention that this kind of HTTP authentication is not what +is usually done and requested by user-oriented websites these days. They tend +to use forms and cookies instead. ## Path part - The path part is just sent off to the server to request that it sends back - the associated response. The path is what is to the right side of the slash - that follows the host name and possibly port number. +The path part is sent off to the server to request that it sends back the +associated response. The path is what is to the right side of the slash that +follows the hostname and possibly port number. # Fetch a page ## GET - The simplest and most common request/operation made using HTTP is to GET a - URL. The URL could itself refer to a web page, an image or a file. The client - issues a GET request to the server and receives the document it asked for. - If you issue the command line +The simplest and most common request/operation made using HTTP is to GET a +URL. The URL could itself refer to a webpage, an image or a file. The client +issues a GET request to the server and receives the document it asked for. +If you issue the command line - curl https://curl.se + curl https://curl.se/ - you get a web page returned in your terminal window. The entire HTML document - that that URL holds. +you get a webpage returned in your terminal window. The entire HTML document +this URL identifies. - All HTTP replies contain a set of response headers that are normally hidden, - use curl's [`--include`](https://curl.se/docs/manpage.html#-i) (`-i`) - option to display them as well as the rest of the document. +All HTTP replies contain a set of response headers that are normally hidden, +use curl's [`--include`](https://curl.se/docs/manpage.html#-i) (`-i`) +option to display them as well as the rest of the document. ## HEAD - You can ask the remote server for ONLY the headers by using the - [`--head`](https://curl.se/docs/manpage.html#-I) (`-I`) option which - will make curl issue a HEAD request. In some special cases servers deny the - HEAD method while others still work, which is a particular kind of annoyance. +You can ask the remote server for ONLY the headers by using the +[`--head`](https://curl.se/docs/manpage.html#-I) (`-I`) option which makes +curl issue a HEAD request. In some special cases servers deny the HEAD method +while others still work, which is a particular kind of annoyance. - The HEAD method is defined and made so that the server returns the headers - exactly the way it would do for a GET, but without a body. It means that you - may see a `Content-Length:` in the response headers, but there must not be an - actual body in the HEAD response. +The HEAD method is defined and made so that the server returns the headers +exactly the way it would do for a GET, but without a body. It means that you +may see a `Content-Length:` in the response headers, but there must not be an +actual body in the HEAD response. ## Multiple URLs in a single command line - A single curl command line may involve one or many URLs. The most common case - is probably to just use one, but you can specify any amount of URLs. Yes - any. No limits. You will then get requests repeated over and over for all the - given URLs. +A single curl command line may involve one or many URLs. The most common case +is probably to use one, but you can specify any amount of URLs. Yes any. No +limits. You then get requests repeated over and over for all the given URLs. - Example, send two GET requests: +Example, send two GET requests: - curl http://url1.example.com http://url2.example.com + curl https://url1.example.com https://url2.example.com - If you use [`--data`](https://curl.se/docs/manpage.html#-d) to POST to - the URL, using multiple URLs means that you send that same POST to all the - given URLs. +If you use [`--data`](https://curl.se/docs/manpage.html#-d) to POST to +the URL, using multiple URLs means that you send that same POST to all the +given URLs. - Example, send two POSTs: - - curl --data name=curl http://url1.example.com http://url2.example.com +Example, send two POSTs: + curl --data name=curl https://url1.example.com https://url2.example.com ## Multiple HTTP methods in a single command line - Sometimes you need to operate on several URLs in a single command line and do - different HTTP methods on each. For this, you will enjoy the - [`--next`](https://curl.se/docs/manpage.html#-:) option. It is basically - a separator that separates a bunch of options from the next. All the URLs - before `--next` will get the same method and will get all the POST data - merged into one. +Sometimes you need to operate on several URLs in a single command line and do +different HTTP methods on each. For this, you might enjoy the +[`--next`](https://curl.se/docs/manpage.html#-:) option. It is a separator +that separates a bunch of options from the next. All the URLs before `--next` +get the same method and get all the POST data merged into one. - When curl reaches the `--next` on the command line, it will sort of reset the - method and the POST data and allow a new set. +When curl reaches the `--next` on the command line, it resets the method and +the POST data and allow a new set. - Perhaps this is best shown with a few examples. To send first a HEAD and then - a GET: +Perhaps this is best shown with a few examples. To send first a HEAD and then +a GET: - curl -I http://example.com --next http://example.com + curl -I https://example.com --next https://example.com - To first send a POST and then a GET: +To first send a POST and then a GET: - curl -d score=10 http://example.com/post.cgi --next http://example.com/results.html + curl -d score=10 https://example.com/post.cgi --next https://example.com/results.html # HTML forms ## Forms explained - Forms are the general way a website can present an HTML page with fields for - the user to enter data in, and then press some kind of 'OK' or 'Submit' - button to get that data sent to the server. The server then typically uses - the posted data to decide how to act. Like using the entered words to search - in a database, or to add the info in a bug tracking system, display the - entered address on a map or using the info as a login-prompt verifying that - the user is allowed to see what it is about to see. +Forms are the general way a website can present an HTML page with fields for +the user to enter data in, and then press some kind of 'OK' or 'Submit' +button to get that data sent to the server. The server then typically uses +the posted data to decide how to act. Like using the entered words to search +in a database, or to add the info in a bug tracking system, display the +entered address on a map or using the info as a login-prompt verifying that +the user is allowed to see what it is about to see. - Of course there has to be some kind of program on the server end to receive - the data you send. You cannot just invent something out of the air. +Of course there has to be some kind of program on the server end to receive +the data you send. You cannot invent something out of the air. ## GET - A GET-form uses the method GET, as specified in HTML like: +A GET-form uses the method GET, as specified in HTML like: ```html

@@ -241,36 +243,35 @@
``` - In your favorite browser, this form will appear with a text box to fill in - and a press-button labeled "OK". If you fill in '1905' and press the OK - button, your browser will then create a new URL to get for you. The URL will - get `junk.cgi?birthyear=1905&press=OK` appended to the path part of the - previous URL. +In your favorite browser, this form appears with a text box to fill in and a +press-button labeled "OK". If you fill in '1905' and press the OK button, +your browser then creates a new URL to get for you. The URL gets +`junk.cgi?birthyear=1905&press=OK` appended to the path part of the previous +URL. - If the original form was seen on the page `www.example.com/when/birth.html`, - the second page you will get will become - `www.example.com/when/junk.cgi?birthyear=1905&press=OK`. +If the original form was seen on the page `www.example.com/when/birth.html`, +the second page you get becomes +`www.example.com/when/junk.cgi?birthyear=1905&press=OK`. - Most search engines work this way. +Most search engines work this way. - To make curl do the GET form post for you, just enter the expected created - URL: +To make curl do the GET form post for you, enter the expected created URL: - curl "http://www.example.com/when/junk.cgi?birthyear=1905&press=OK" + curl "https://www.example.com/when/junk.cgi?birthyear=1905&press=OK" ## POST - The GET method makes all input field names get displayed in the URL field of - your browser. That is generally a good thing when you want to be able to - bookmark that page with your given data, but it is an obvious disadvantage if - you entered secret information in one of the fields or if there are a large - amount of fields creating a long and unreadable URL. +The GET method makes all input field names get displayed in the URL field of +your browser. That is generally a good thing when you want to be able to +bookmark that page with your given data, but it is an obvious disadvantage if +you entered secret information in one of the fields or if there are a large +amount of fields creating a long and unreadable URL. - The HTTP protocol then offers the POST method. This way the client sends the - data separated from the URL and thus you will not see any of it in the URL - address field. +The HTTP protocol then offers the POST method. This way the client sends the +data separated from the URL and thus you do not see any of it in the URL +address field. - The form would look similar to the previous one: +The form would look similar to the previous one: ```html
@@ -279,59 +280,56 @@
``` - And to use curl to post this form with the same data filled in as before, we - could do it like: +To use curl to post this form with the same data filled in as before, we +could do it like: - curl --data "birthyear=1905&press=%20OK%20" http://www.example.com/when/junk.cgi + curl --data "birthyear=1905&press=%20OK%20" https://www.example.com/when/junk.cgi - This kind of POST will use the Content-Type - `application/x-www-form-urlencoded` and is the most widely used POST kind. +This kind of POST uses the Content-Type `application/x-www-form-urlencoded` +and is the most widely used POST kind. - The data you send to the server MUST already be properly encoded, curl will - not do that for you. For example, if you want the data to contain a space, - you need to replace that space with `%20`, etc. Failing to comply with this will - most likely cause your data to be received wrongly and messed up. +The data you send to the server MUST already be properly encoded, curl does +not do that for you. For example, if you want the data to contain a space, +you need to replace that space with `%20`, etc. Failing to comply with this +most likely causes your data to be received wrongly and messed up. - Recent curl versions can in fact url-encode POST data for you, like this: +Recent curl versions can in fact URL encode POST data for you, like this: - curl --data-urlencode "name=I am Daniel" http://www.example.com + curl --data-urlencode "name=I am Daniel" https://www.example.com - If you repeat `--data` several times on the command line, curl will - concatenate all the given data pieces - and put a `&` symbol between each - data segment. +If you repeat `--data` several times on the command line, curl concatenates +all the given data pieces - and put a `&` symbol between each data segment. ## File Upload POST - Back in late 1995 they defined an additional way to post data over HTTP. It - is documented in the RFC 1867, why this method sometimes is referred to as - RFC 1867-posting. +Back in late 1995 they defined an additional way to post data over HTTP. It +is documented in the RFC 1867, why this method sometimes is referred to as +RFC 1867-posting. - This method is mainly designed to better support file uploads. A form that - allows a user to upload a file could be written like this in HTML: +This method is mainly designed to better support file uploads. A form that +allows a user to upload a file could be written like this in HTML: -```html -
- - -
-``` +
+ + +
- This clearly shows that the Content-Type about to be sent is - `multipart/form-data`. +This clearly shows that the Content-Type about to be sent is +`multipart/form-data`. - To post to a form like this with curl, you enter a command line like: +To post to a form like this with curl, you enter a command line like: curl --form upload=@localfilename --form press=OK [URL] ## Hidden Fields - A common way for HTML based applications to pass state information between - pages is to add hidden fields to the forms. Hidden fields are already filled - in, they are not displayed to the user and they get passed along just as all - the other fields. +A common way for HTML based applications to pass state information between +pages is to add hidden fields to the forms. Hidden fields are already filled +in, they are not displayed to the user and they get passed along as all the +other fields. - A similar example form with one visible field, one hidden field and one - submit button could look like: +A similar example form with one visible field, one hidden field and one +submit button could look like: ```html
@@ -341,124 +339,126 @@
``` - To POST this with curl, you will not have to think about if the fields are - hidden or not. To curl they are all the same: +To POST this with curl, you do not have to think about if the fields are +hidden or not. To curl they are all the same: curl --data "birthyear=1905&press=OK&person=daniel" [URL] ## Figure Out What A POST Looks Like - When you are about to fill in a form and send it to a server by using curl - instead of a browser, you are of course interested in sending a POST exactly - the way your browser does. +When you are about to fill in a form and send it to a server by using curl +instead of a browser, you are of course interested in sending a POST exactly +the way your browser does. - An easy way to get to see this, is to save the HTML page with the form on - your local disk, modify the 'method' to a GET, and press the submit button - (you could also change the action URL if you want to). +An easy way to get to see this, is to save the HTML page with the form on +your local disk, modify the 'method' to a GET, and press the submit button +(you could also change the action URL if you want to). - You will then clearly see the data get appended to the URL, separated with a - `?`-letter as GET forms are supposed to. +You then clearly see the data get appended to the URL, separated with a +`?`-letter as GET forms are supposed to. # HTTP upload ## PUT - Perhaps the best way to upload data to an HTTP server is to use PUT. Then - again, this of course requires that someone put a program or script on the - server end that knows how to receive an HTTP PUT stream. +Perhaps the best way to upload data to an HTTP server is to use PUT. Then +again, this of course requires that someone put a program or script on the +server end that knows how to receive an HTTP PUT stream. - Put a file to an HTTP server with curl: +Put a file to an HTTP server with curl: - curl --upload-file uploadfile http://www.example.com/receive.cgi + curl --upload-file uploadfile https://www.example.com/receive.cgi # HTTP Authentication ## Basic Authentication - HTTP Authentication is the ability to tell the server your username and - password so that it can verify that you are allowed to do the request you are - doing. The Basic authentication used in HTTP (which is the type curl uses by - default) is **plain text** based, which means it sends username and password - only slightly obfuscated, but still fully readable by anyone that sniffs on - the network between you and the remote server. +HTTP Authentication is the ability to tell the server your username and +password so that it can verify that you are allowed to do the request you are +doing. The Basic authentication used in HTTP (which is the type curl uses by +default) is **plain text** based, which means it sends username and password +only slightly obfuscated, but still fully readable by anyone that sniffs on +the network between you and the remote server. - To tell curl to use a user and password for authentication: +To tell curl to use a user and password for authentication: - curl --user name:password http://www.example.com + curl --user myname:password https://www.example.com ## Other Authentication - The site might require a different authentication method (check the headers - returned by the server), and then - [`--ntlm`](https://curl.se/docs/manpage.html#--ntlm), - [`--digest`](https://curl.se/docs/manpage.html#--digest), - [`--negotiate`](https://curl.se/docs/manpage.html#--negotiate) or even - [`--anyauth`](https://curl.se/docs/manpage.html#--anyauth) might be - options that suit you. +The site might require a different authentication method (check the headers +returned by the server), and then +[`--ntlm`](https://curl.se/docs/manpage.html#--ntlm), +[`--digest`](https://curl.se/docs/manpage.html#--digest), +[`--negotiate`](https://curl.se/docs/manpage.html#--negotiate) or even +[`--anyauth`](https://curl.se/docs/manpage.html#--anyauth) might be +options that suit you. ## Proxy Authentication - Sometimes your HTTP access is only available through the use of an HTTP - proxy. This seems to be especially common at various companies. An HTTP proxy - may require its own user and password to allow the client to get through to - the Internet. To specify those with curl, run something like: +Sometimes your HTTP access is only available through the use of an HTTP +proxy. This seems to be especially common at various companies. An HTTP proxy +may require its own user and password to allow the client to get through to +the Internet. To specify those with curl, run something like: curl --proxy-user proxyuser:proxypassword curl.se - If your proxy requires the authentication to be done using the NTLM method, - use [`--proxy-ntlm`](https://curl.se/docs/manpage.html#--proxy-ntlm), if - it requires Digest use - [`--proxy-digest`](https://curl.se/docs/manpage.html#--proxy-digest). +If your proxy requires the authentication to be done using the NTLM method, +use [`--proxy-ntlm`](https://curl.se/docs/manpage.html#--proxy-ntlm), if +it requires Digest use +[`--proxy-digest`](https://curl.se/docs/manpage.html#--proxy-digest). - If you use any one of these user+password options but leave out the password - part, curl will prompt for the password interactively. +If you use any one of these user+password options but leave out the password +part, curl prompts for the password interactively. ## Hiding credentials - Do note that when a program is run, its parameters might be possible to see - when listing the running processes of the system. Thus, other users may be - able to watch your passwords if you pass them as plain command line - options. There are ways to circumvent this. +Do note that when a program is run, its parameters might be possible to see +when listing the running processes of the system. Thus, other users may be +able to watch your passwords if you pass them as plain command line +options. There are ways to circumvent this. - It is worth noting that while this is how HTTP Authentication works, many - websites will not use this concept when they provide logins etc. See the Web - Login chapter further below for more details on that. +It is worth noting that while this is how HTTP Authentication works, many +websites do not use this concept when they provide logins etc. See the Web +Login chapter further below for more details on that. # More HTTP Headers ## Referer - An HTTP request may include a 'referer' field (yes it is misspelled), which - can be used to tell from which URL the client got to this particular - resource. Some programs/scripts check the referer field of requests to verify - that this was not arriving from an external site or an unknown page. While - this is a stupid way to check something so easily forged, many scripts still - do it. Using curl, you can put anything you want in the referer-field and - thus more easily be able to fool the server into serving your request. +An HTTP request may include a 'referer' field (yes it is misspelled), which +can be used to tell from which URL the client got to this particular +resource. Some programs/scripts check the referer field of requests to verify +that this was not arriving from an external site or an unknown page. While +this is a stupid way to check something so easily forged, many scripts still +do it. Using curl, you can put anything you want in the referer-field and +thus more easily be able to fool the server into serving your request. - Use curl to set the referer field with: +Use curl to set the referer field with: - curl --referer http://www.example.come http://www.example.com + curl --referer https://www.example.come https://www.example.com ## User Agent - Similar to the referer field, all HTTP requests may set the User-Agent - field. It names what user agent (client) that is being used. Many - applications use this information to decide how to display pages. Silly web - programmers try to make different pages for users of different browsers to - make them look the best possible for their particular browsers. They usually - also do different kinds of JavaScript etc. +Similar to the referer field, all HTTP requests may set the User-Agent +field. It names what user agent (client) that is being used. Many +applications use this information to decide how to display pages. Silly web +programmers try to make different pages for users of different browsers to +make them look the best possible for their particular browsers. They usually +also do different kinds of JavaScript etc. - At times, you will see that getting a page with curl will not return the same - page that you see when getting the page with your browser. Then you know it - is time to set the User Agent field to fool the server into thinking you are - one of those browsers. +At times, you may learn that getting a page with curl does not return the +same page that you see when getting the page with your browser. Then you know +it is time to set the User Agent field to fool the server into thinking you +are one of those browsers. - To make curl look like Internet Explorer 5 on a Windows 2000 box: +By default, curl uses curl/VERSION, such as User-Agent: curl/8.11.0. + +To make curl look like Internet Explorer 5 on a Windows 2000 box: curl --user-agent "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" [URL] - Or why not look like you are using Netscape 4.73 on an old Linux box: +Or why not look like you are using Netscape 4.73 on an old Linux box: curl --user-agent "Mozilla/4.73 [en] (X11; U; Linux 2.2.15 i686)" [URL] @@ -466,139 +466,136 @@ ## Location header - When a resource is requested from a server, the reply from the server may - include a hint about where the browser should go next to find this page, or a - new page keeping newly generated output. The header that tells the browser to - redirect is `Location:`. +When a resource is requested from a server, the reply from the server may +include a hint about where the browser should go next to find this page, or a +new page keeping newly generated output. The header that tells the browser to +redirect is `Location:`. - Curl does not follow `Location:` headers by default, but will simply display - such pages in the same manner it displays all HTTP replies. It does however - feature an option that will make it attempt to follow the `Location:` - pointers. +curl does not follow `Location:` headers by default, but displays such +pages in the same manner it displays all HTTP replies. It does however +feature an option that makes it attempt to follow the `Location:` pointers. - To tell curl to follow a Location: +To tell curl to follow a Location: - curl --location http://www.example.com + curl --location https://www.example.com - If you use curl to POST to a site that immediately redirects you to another - page, you can safely use - [`--location`](https://curl.se/docs/manpage.html#-L) (`-L`) and - `--data`/`--form` together. Curl will only use POST in the first request, and - then revert to GET in the following operations. +If you use curl to POST to a site that immediately redirects you to another +page, you can safely use [`--location`](https://curl.se/docs/manpage.html#-L) +(`-L`) and `--data`/`--form` together. curl only uses POST in the first +request, and then revert to GET in the following operations. ## Other redirects - Browsers typically support at least two other ways of redirects that curl - does not: first the html may contain a meta refresh tag that asks the browser - to load a specific URL after a set number of seconds, or it may use - JavaScript to do it. +Browsers typically support at least two other ways of redirects that curl +does not: first the html may contain a meta refresh tag that asks the browser +to load a specific URL after a set number of seconds, or it may use +JavaScript to do it. # Cookies ## Cookie Basics - The way the web browsers do "client side state control" is by using - cookies. Cookies are just names with associated contents. The cookies are - sent to the client by the server. The server tells the client for what path - and host name it wants the cookie sent back, and it also sends an expiration - date and a few more properties. +The way the web browsers do "client side state control" is by using cookies. +Cookies are names with associated contents. The cookies are sent to the client +by the server. The server tells the client for what path and hostname it wants +the cookie sent back, and it also sends an expiration date and a few more +properties. - When a client communicates with a server with a name and path as previously - specified in a received cookie, the client sends back the cookies and their - contents to the server, unless of course they are expired. +When a client communicates with a server with a name and path as previously +specified in a received cookie, the client sends back the cookies and their +contents to the server, unless of course they are expired. - Many applications and servers use this method to connect a series of requests - into a single logical session. To be able to use curl in such occasions, we - must be able to record and send back cookies the way the web application - expects them. The same way browsers deal with them. +Many applications and servers use this method to connect a series of requests +into a single logical session. To be able to use curl in such occasions, we +must be able to record and send back cookies the way the web application +expects them. The same way browsers deal with them. ## Cookie options - The simplest way to send a few cookies to the server when getting a page with - curl is to add them on the command line like: +The simplest way to send a few cookies to the server when getting a page with +curl is to add them on the command line like: - curl --cookie "name=Daniel" http://www.example.com + curl --cookie "name=Daniel" https://www.example.com - Cookies are sent as common HTTP headers. This is practical as it allows curl - to record cookies simply by recording headers. Record cookies with curl by - using the [`--dump-header`](https://curl.se/docs/manpage.html#-D) (`-D`) - option like: +Cookies are sent as common HTTP headers. This is practical as it allows curl +to record cookies by recording headers. Record cookies with curl by +using the [`--dump-header`](https://curl.se/docs/manpage.html#-D) (`-D`) +option like: - curl --dump-header headers_and_cookies http://www.example.com + curl --dump-header headers_and_cookies https://www.example.com - (Take note that the - [`--cookie-jar`](https://curl.se/docs/manpage.html#-c) option described - below is a better way to store cookies.) +(Take note that the +[`--cookie-jar`](https://curl.se/docs/manpage.html#-c) option described +below is a better way to store cookies.) - Curl has a full blown cookie parsing engine built-in that comes in use if you - want to reconnect to a server and use cookies that were stored from a - previous connection (or hand-crafted manually to fool the server into - believing you had a previous connection). To use previously stored cookies, - you run curl like: +curl has a full blown cookie parsing engine built-in that comes in use if you +want to reconnect to a server and use cookies that were stored from a +previous connection (or hand-crafted manually to fool the server into +believing you had a previous connection). To use previously stored cookies, +you run curl like: - curl --cookie stored_cookies_in_file http://www.example.com + curl --cookie stored_cookies_in_file https://www.example.com - Curl's "cookie engine" gets enabled when you use the - [`--cookie`](https://curl.se/docs/manpage.html#-b) option. If you only - want curl to understand received cookies, use `--cookie` with a file that - does not exist. Example, if you want to let curl understand cookies from a - page and follow a location (and thus possibly send back cookies it received), - you can invoke it like: +curl's "cookie engine" gets enabled when you use the +[`--cookie`](https://curl.se/docs/manpage.html#-b) option. If you only +want curl to understand received cookies, use `--cookie` with a file that +does not exist. Example, if you want to let curl understand cookies from a +page and follow a location (and thus possibly send back cookies it received), +you can invoke it like: - curl --cookie nada --location http://www.example.com + curl --cookie nada --location https://www.example.com - Curl has the ability to read and write cookie files that use the same file - format that Netscape and Mozilla once used. It is a convenient way to share - cookies between scripts or invokes. The `--cookie` (`-b`) switch - automatically detects if a given file is such a cookie file and parses it, - and by using the `--cookie-jar` (`-c`) option you will make curl write a new - cookie file at the end of an operation: +curl has the ability to read and write cookie files that use the same file +format that Netscape and Mozilla once used. It is a convenient way to share +cookies between scripts or invokes. The `--cookie` (`-b`) switch +automatically detects if a given file is such a cookie file and parses it, +and by using the `--cookie-jar` (`-c`) option you make curl write a new +cookie file at the end of an operation: curl --cookie cookies.txt --cookie-jar newcookies.txt \ - http://www.example.com + https://www.example.com # HTTPS ## HTTPS is HTTP secure - There are a few ways to do secure HTTP transfers. By far the most common - protocol for doing this is what is generally known as HTTPS, HTTP over - SSL. SSL encrypts all the data that is sent and received over the network and - thus makes it harder for attackers to spy on sensitive information. +There are a few ways to do secure HTTP transfers. By far the most common +protocol for doing this is what is generally known as HTTPS, HTTP over +SSL. SSL encrypts all the data that is sent and received over the network and +thus makes it harder for attackers to spy on sensitive information. - SSL (or TLS as the current version of the standard is called) offers a set of - advanced features to do secure transfers over HTTP. +SSL (or TLS as the current version of the standard is called) offers a set of +advanced features to do secure transfers over HTTP. - Curl supports encrypted fetches when built to use a TLS library and it can be - built to use one out of a fairly large set of libraries - `curl -V` will show - which one your curl was built to use (if any!). To get a page from an HTTPS - server, simply run curl like: +curl supports encrypted fetches when built to use a TLS library and it can be +built to use one out of a fairly large set of libraries - `curl -V` shows +which one your curl was built to use (if any). To get a page from an HTTPS +server, run curl like: curl https://secure.example.com ## Certificates - In the HTTPS world, you use certificates to validate that you are the one - you claim to be, as an addition to normal passwords. Curl supports client- - side certificates. All certificates are locked with a pass phrase, which you - need to enter before the certificate can be used by curl. The pass phrase - can be specified on the command line or if not, entered interactively when - curl queries for it. Use a certificate with curl on an HTTPS server like: +In the HTTPS world, you use certificates to validate that you are the one you +claim to be, as an addition to normal passwords. curl supports client- side +certificates. All certificates are locked with a passphrase, which you need +to enter before the certificate can be used by curl. The passphrase can be +specified on the command line or if not, entered interactively when curl +queries for it. Use a certificate with curl on an HTTPS server like: curl --cert mycert.pem https://secure.example.com - curl also tries to verify that the server is who it claims to be, by - verifying the server's certificate against a locally stored CA cert - bundle. Failing the verification will cause curl to deny the connection. You - must then use [`--insecure`](https://curl.se/docs/manpage.html#-k) - (`-k`) in case you want to tell curl to ignore that the server cannot be - verified. +curl also tries to verify that the server is who it claims to be, by +verifying the server's certificate against a locally stored CA cert bundle. +Failing the verification causes curl to deny the connection. You must then +use [`--insecure`](https://curl.se/docs/manpage.html#-k) (`-k`) in case you +want to tell curl to ignore that the server cannot be verified. - More about server certificate verification and ca cert bundles can be read in - the [`SSLCERTS` document](https://curl.se/docs/sslcerts.html). +More about server certificate verification and CA cert bundles can be read in +the [`SSLCERTS` document](https://curl.se/docs/sslcerts.html). - At times you may end up with your own CA cert store and then you can tell - curl to use that to verify the server's certificate: +At times you may end up with your own CA cert store and then you can tell +curl to use that to verify the server's certificate: curl --cacert ca-bundle.pem https://example.com/ @@ -606,107 +603,106 @@ ## Modify method and headers - Doing fancy stuff, you may need to add or change elements of a single curl - request. +Doing fancy stuff, you may need to add or change elements of a single curl +request. - For example, you can change the POST method to `PROPFIND` and send the data - as `Content-Type: text/xml` (instead of the default `Content-Type`) like - this: +For example, you can change the POST method to `PROPFIND` and send the data +as `Content-Type: text/xml` (instead of the default `Content-Type`) like +this: curl --data "" --header "Content-Type: text/xml" \ --request PROPFIND example.com - You can delete a default header by providing one without content. Like you - can ruin the request by chopping off the `Host:` header: +You can delete a default header by providing one without content. Like you +can ruin the request by chopping off the `Host:` header: - curl --header "Host:" http://www.example.com + curl --header "Host:" https://www.example.com - You can add headers the same way. Your server may want a `Destination:` - header, and you can add it: +You can add headers the same way. Your server may want a `Destination:` +header, and you can add it: - curl --header "Destination: http://nowhere" http://example.com + curl --header "Destination: nowhere" https://example.com ## More on changed methods - It should be noted that curl selects which methods to use on its own - depending on what action to ask for. `-d` will do POST, `-I` will do HEAD and - so on. If you use the - [`--request`](https://curl.se/docs/manpage.html#-X) / `-X` option you - can change the method keyword curl selects, but you will not modify curl's - behavior. This means that if you for example use -d "data" to do a POST, you - can modify the method to a `PROPFIND` with `-X` and curl will still think it - sends a POST . You can change the normal GET to a POST method by simply - adding `-X POST` in a command line like: +It should be noted that curl selects which methods to use on its own +depending on what action to ask for. `-d` makes a POST, `-I` makes a HEAD and +so on. If you use the [`--request`](https://curl.se/docs/manpage.html#-X) / +`-X` option you can change the method keyword curl selects, but you do not +modify curl's behavior. This means that if you for example use -d "data" to +do a POST, you can modify the method to a `PROPFIND` with `-X` and curl still +thinks it sends a POST. You can change the normal GET to a POST method by +adding `-X POST` in a command line like: - curl -X POST http://example.org/ + curl -X POST https://example.org/ - ... but curl will still think and act as if it sent a GET so it will not send - any request body etc. +curl however still acts as if it sent a GET so it does not send any request +body etc. # Web Login ## Some login tricks - While not strictly just HTTP related, it still causes a lot of people - problems so here's the executive run-down of how the vast majority of all - login forms work and how to login to them using curl. +While not strictly HTTP related, it still causes a lot of people problems so +here's the executive run-down of how the vast majority of all login forms work +and how to login to them using curl. - It can also be noted that to do this properly in an automated fashion, you - will most certainly need to script things and do multiple curl invokes etc. +It can also be noted that to do this properly in an automated fashion, you +most certainly need to script things and do multiple curl invokes etc. - First, servers mostly use cookies to track the logged-in status of the - client, so you will need to capture the cookies you receive in the - responses. Then, many sites also set a special cookie on the login page (to - make sure you got there through their login page) so you should make a habit - of first getting the login-form page to capture the cookies set there. +First, servers mostly use cookies to track the logged-in status of the +client, so you need to capture the cookies you receive in the responses. +Then, many sites also set a special cookie on the login page (to make sure +you got there through their login page) so you should make a habit of first +getting the login-form page to capture the cookies set there. - Some web-based login systems feature various amounts of JavaScript, and - sometimes they use such code to set or modify cookie contents. Possibly they - do that to prevent programmed logins, like this manual describes how to... - Anyway, if reading the code is not enough to let you repeat the behavior - manually, capturing the HTTP requests done by your browsers and analyzing the - sent cookies is usually a working method to work out how to shortcut the - JavaScript need. +Some web-based login systems feature various amounts of JavaScript, and +sometimes they use such code to set or modify cookie contents. Possibly they +do that to prevent programmed logins, like this manual describes how to... +Anyway, if reading the code is not enough to let you repeat the behavior +manually, capturing the HTTP requests done by your browsers and analyzing the +sent cookies is usually a working method to work out how to shortcut the +JavaScript need. - In the actual `
` tag for the login, lots of sites fill-in - random/session or otherwise secretly generated hidden tags and you may need - to first capture the HTML code for the login form and extract all the hidden - fields to be able to do a proper login POST. Remember that the contents need - to be URL encoded when sent in a normal POST. +In the actual `` tag for the login, lots of sites fill-in +random/session or otherwise secretly generated hidden tags and you may need +to first capture the HTML code for the login form and extract all the hidden +fields to be able to do a proper login POST. Remember that the contents need +to be URL encoded when sent in a normal POST. # Debug ## Some debug tricks - Many times when you run curl on a site, you will notice that the site does not - seem to respond the same way to your curl requests as it does to your - browser's. +Many times when you run curl on a site, you notice that the site does not +seem to respond the same way to your curl requests as it does to your +browser's. - Then you need to start making your curl requests more similar to your - browser's requests: +Then you need to start making your curl requests more similar to your +browser's requests: - - Use the `--trace-ascii` option to store fully detailed logs of the requests - for easier analyzing and better understanding +- Use the `--trace-ascii` option to store fully detailed logs of the requests + for easier analyzing and better understanding - - Make sure you check for and use cookies when needed (both reading with - `--cookie` and writing with `--cookie-jar`) +- Make sure you check for and use cookies when needed (both reading with + `--cookie` and writing with `--cookie-jar`) - - Set user-agent (with [`-A`](https://curl.se/docs/manpage.html#-A)) to - one like a recent popular browser does +- Set user-agent (with [`-A`](https://curl.se/docs/manpage.html#-A)) to + one like a recent popular browser does - - Set referer (with [`-E`](https://curl.se/docs/manpage.html#-E)) like - it is set by the browser +- Set referer (with [`-E`](https://curl.se/docs/manpage.html#-E)) like + it is set by the browser - - If you use POST, make sure you send all the fields and in the same order as - the browser does it. +- If you use POST, make sure you send all the fields and in the same order as + the browser does it. ## Check what the browsers do - A good helper to make sure you do this right, is the web browsers' developers - tools that let you view all headers you send and receive (even when using - HTTPS). +A good helper to make sure you do this right, is the web browsers' developers +tools that let you view all headers you send and receive (even when using +HTTPS). - A more raw approach is to capture the HTTP traffic on the network with tools - such as Wireshark or tcpdump and check what headers that were sent and - received by the browser. (HTTPS forces you to use `SSLKEYLOGFILE` to do - that.) +A more raw approach is to capture the HTTP traffic on the network with tools +such as Wireshark or tcpdump and check what headers that were sent and +received by the browser. (HTTPS forces you to use `SSLKEYLOGFILE` to do +that.) diff --git a/third-party/curl/docs/URL-SYNTAX.md b/third-party/curl/docs/URL-SYNTAX.md index ddd99454fb..219e84ee93 100644 --- a/third-party/curl/docs/URL-SYNTAX.md +++ b/third-party/curl/docs/URL-SYNTAX.md @@ -1,3 +1,9 @@ + + # URL syntax and their use in curl ## Specifications @@ -5,9 +11,9 @@ The official "URL syntax" is primarily defined in these two different specifications: - - [RFC 3986](https://datatracker.ietf.org/doc/html/rfc3986) (although URL is called - "URI" in there) - - [The WHATWG URL Specification](https://url.spec.whatwg.org/) +- [RFC 3986](https://datatracker.ietf.org/doc/html/rfc3986) (although URL is + called "URI" in there) +- [The WHATWG URL Specification](https://url.spec.whatwg.org/) RFC 3986 is the earlier one, and curl has always tried to adhere to that one (since it shipped in January 2005). @@ -26,12 +32,12 @@ unlikely that multiple parsers treat URLs the same way. Due to the inherent differences between URL parser implementations, it is considered a security risk to mix different implementations and assume the -same behavior! +same behavior. -For example, if you use one parser to check if a URL uses a good host name or +For example, if you use one parser to check if a URL uses a good hostname or the correct auth field, and then pass on that same URL to a *second* parser, -there will always be a risk it treats the same URL differently. There is no -right and wrong in URL land, only differences of opinions. +there is always a risk it treats the same URL differently. There is no right +and wrong in URL land, only differences of opinions. libcurl offers a separate API to its URL parser for this reason, among others. @@ -55,13 +61,13 @@ security concerns: ## "RFC 3986 plus" curl recognizes a URL syntax that we call "RFC 3986 plus". It is grounded on -the well established RFC 3986 to make sure previously written command lines and -curl using scripts will remain working. +the well established RFC 3986 to make sure previously written command lines +and curl using scripts remain working. curl's URL parser allows a few deviations from the spec in order to inter-operate better with URLs that appear in the wild. -### spaces +### Spaces A URL provided to curl cannot contain spaces. They need to be provided URL encoded to be accepted in a URL by curl. @@ -71,12 +77,12 @@ client where a resource has been redirected to, sometimes contain spaces. This is a violation of RFC 3986 but is fine in the WHATWG spec. curl handles these by re-encoding them to `%20`. -### non-ASCII +### Non-ASCII Byte values in a provided URL that are outside of the printable ASCII range are percent-encoded by curl. -### multiple slashes +### Multiple slashes An absolute URL always starts with a "scheme" followed by a colon. For all the schemes curl supports, the colon must be followed by two slashes according to @@ -92,18 +98,17 @@ curl supports "URLs" that do not start with a scheme. This is not supported by any of the specifications. This is a shortcut to entering URLs that was supported by browsers early on and has been mimicked by curl. -Based on what the host name starts with, curl will "guess" what protocol to -use: +Based on what the hostname starts with, curl "guesses" what protocol to use: - - `ftp.` means FTP - - `dict.` means DICT - - `ldap.` means LDAP - - `imap.` means IMAP - - `smtp.` means SMTP - - `pop3.` means POP3 - - all other means HTTP +- `ftp.` means FTP +- `dict.` means DICT +- `ldap.` means LDAP +- `imap.` means IMAP +- `smtp.` means SMTP +- `pop3.` means POP3 +- all other means HTTP -### globbing letters +### Globbing letters The curl command line tool supports "globbing" of URLs. It means that you can create ranges and lists using `[N-M]` and `{one,two,three}` sequences. The @@ -125,7 +130,7 @@ character or string. For example, this could look like: - http://user:password@www.example.com:80/index.html?foo=bar#top + https://user:password@www.example.com:80/index.html?foo=bar#top ## Scheme @@ -136,9 +141,8 @@ curl supports the following schemes on URLs specified to transfer. They are matched case insensitively: `dict`, `file`, `ftp`, `ftps`, `gopher`, `gophers`, `http`, `https`, `imap`, -`imaps`, `ldap`, `ldaps`, `mqtt`, `pop3`, `pop3s`, `rtmp`, `rtmpe`, `rtmps`, -`rtmpt`, `rtmpte`, `rtmpts`, `rtsp`, `smb`, `smbs`, `smtp`, `smtps`, `telnet`, -`tftp` +`imaps`, `ldap`, `ldaps`, `mqtt`, `pop3`, `pop3s`, `rtsp`, `smb`, `smbs`, +`smtp`, `smtps`, `telnet`, `tftp` When the URL is specified to identify a proxy, curl recognizes the following schemes: @@ -147,10 +151,9 @@ schemes: ## Userinfo -The userinfo field can be used to set user name and password for -authentication purposes in this transfer. The use of this field is discouraged -since it often means passing around the password in plain text and is thus a -security risk. +The userinfo field can be used to set username and password for authentication +purposes in this transfer. The use of this field is discouraged since it often +means passing around the password in plain text and is thus a security risk. URLs for IMAP, POP3 and SMTP also support *login options* as part of the userinfo field. They are provided as a semicolon after the password and then @@ -164,13 +167,47 @@ local network name of the machine on your network or the IP address of the server or machine represented by either an IPv4 or IPv6 address (within brackets). For example: - http://www.example.com/ + https://www.example.com/ - http://hostname/ + https://hostname.example/ - http://192.168.0.1/ + https://192.168.0.1/ - http://[2001:1890:1112:1::20]/ + https://[2001:1890:1112:1::20]/ + +libcurl rejects hostnames with more than one trailing dot. + +### Numerical IPv4 addresses + +libcurl parses and normalizes everything that appears to be a numerical IPv4 +address. Including octal and hexadecimal formats and using one, two, three or +four number groups. + +This normalizing is done so that curl can properly get documents from HTTP +servers (with the correctly formatted address in the `Host:` header), so that +IP based filtering for things like the `NO_PROXY` environment variable has a +higher chance of working correctly, to increase the chances that two URLs can +be compared and to allow users to extract and visualize the address in a readable +way and to make sure libcurl works identically across different name resolver +libraries and function calls. + +For a hostname that is only an IPv4 address with a trailing dot, the trailing +dot is removed in the normalizing process. + +### Numerical IPv6 addresses + +libcurl allows a zone id to be provided with a numerical IPv6 address, +separated with a percent character (`%`). The percent character may also be +percent-encoded as `%25`. Like this: + + http://[fe80::1%25eth0]/ + + http://[fe80::1%eth0]/ + +### `IPvFuture` + +RFC 3986 documents a numerical IP address format called `IPvFuture`. libcurl +does not recognize this format. Using it causes parse errors. ### "localhost" @@ -184,15 +221,15 @@ machine. ### IDNA If curl was built with International Domain Name (IDN) support, it can also -handle host names using non-ASCII characters. +handle hostnames using non-ASCII characters. When built with libidn2, curl uses the IDNA 2008 standard. This is equivalent to the WHATWG URL spec, but differs from certain browsers that use IDNA 2003 Transitional Processing. The two standards have a huge overlap but differ -slightly, perhaps most famously in how they deal with the German "double s" -(`ß`). +slightly, perhaps most famously in how they deal with the +[German "double s"](https://en.wikipedia.org/wiki/%c3%9f). -When winidn is used, curl uses IDNA 2003 Transitional Processing, like the rest +When WinIDN is used, curl uses IDNA 2003 Transitional Processing, like the rest of Windows. ## Port number @@ -201,13 +238,20 @@ If there is a colon after the hostname, that should be followed by the port number to use. 1 - 65535. curl also supports a blank port number field - but only if the URL starts with a scheme. -If the port number is not specified in the URL, curl will used a default port -based on the provide scheme: +If the port number is not specified in the URL, curl uses a default port +number based on the provide scheme: -DICT 2628, FTP 21, FTPS 990, GOPHER 70, GOPHERS 70, HTTP 80, HTTPS 443, -IMAP 132, IMAPS 993, LDAP 369, LDAPS 636, MQTT 1883, POP3 110, POP3S 995, -RTMP 1935, RTMPS 443, RTMPT 80, RTSP 554, SCP 22, SFTP 22, SMB 445, SMBS 445, -SMTP 25, SMTPS 465, TELNET 23, TFTP 69 +DICT 2628, FTP 21, FTPS 990, GOPHER 70, GOPHERS 70, HTTP 80, HTTPS 443, IMAP +143, IMAPS 993, LDAP 389, LDAPS 636, MQTT 1883, POP3 110, POP3S 995, RTSP 554, +SCP 22, SFTP 22, SMB 445, SMBS 445, SMTP 25, SMTPS 465, TELNET 23, TFTP 69 + +## Path + +By default, libcurl removes sequences of `/./` and `/../` from the path as per +RFC 3986. + +libcurl might also normalize percent-encoded sequences to use uppercase +hexadecimal letters. # Scheme specific behaviors @@ -216,29 +260,29 @@ SMTP 25, SMTPS 465, TELNET 23, TFTP 69 The path part of an FTP request specifies the file to retrieve and from which directory. If the file part is omitted then libcurl downloads the directory listing for the directory specified. If the directory is omitted then the -directory listing for the root / home directory will be returned. +directory listing for the root / home directory is returned. FTP servers typically put the user in its "home directory" after login, which then differs between users. To explicitly specify the root directory of an FTP server, start the path with double slash `//` or `/%2f` (2F is the hexadecimal -value of the ascii code for the slash). +value of the ASCII code for the slash). ## FILE -When a `FILE://` URL is accessed on Windows systems, it can be crafted in a +When a `file://` URL is accessed on Windows systems, it can be crafted in a way so that Windows attempts to connect to a (remote) machine when curl wants to read or write such a path. curl only allows the hostname part of a FILE URL to be one out of these three alternatives: `localhost`, `127.0.0.1` or blank ("", zero characters). -Anything else will make curl fail to parse the URL. +Anything else makes curl fail to parse the URL. ### Windows-specific FILE details curl accepts that the FILE URL's path starts with a "drive letter". That is a single letter `a` to `z` followed by a colon or a pipe character (`|`). -The Windows operating system itself will convert some file accesses to perform +The Windows operating system itself converts some file accesses to perform network accesses over SMB/CIFS, through several different file path patterns. This way, a `file://` URL passed to curl *might* be converted into a network access inadvertently and unknowingly to curl. This is a Windows feature curl @@ -312,16 +356,16 @@ was specified in the URL. That was a bug fixed in 7.62.0, which added ## LDAP -The path part of a LDAP request can be used to specify the: Distinguished -Name, Attributes, Scope, Filter and Extension for a LDAP search. Each field is -separated by a question mark and when that field is not required an empty +The path part of an LDAP request can be used to specify the: Distinguished +Name, Attributes, Scope, Filter and Extension for an LDAP search. Each field +is separated by a question mark and when that field is not required an empty string with the question mark separator should be included. Search for the `DN` as `My Organization`: ldap://ldap.example.com/o=My%20Organization -the same search but will only return `postalAddress` attributes: +the same search but only return `postalAddress` attributes: ldap://ldap.example.com/o=My%20Organization?postalAddress @@ -330,8 +374,8 @@ Search for an empty `DN` and request information about the ldap://ldap.example.com/?rootDomainNamingContext -For more information about the individual components of a LDAP URL please -see [RFC 4516](https://datatracker.ietf.org/doc/html/rfc4516). +For more information about the individual components of an LDAP URL please see +[RFC 4516](https://datatracker.ietf.org/doc/html/rfc4516). ## POP3 @@ -352,12 +396,12 @@ To specify a path relative to the user's home directory on the server, prepend The path part of an SFTP URL specifies the file to retrieve or upload. If the path ends with a slash (`/`) then a directory listing is returned instead of a file. If the path is omitted entirely then the directory listing for the root -/ home directory will be returned. +/ home directory is returned. ## SMB -The path part of a SMB request specifies the file to retrieve and from what +The path part of an SMB request specifies the file to retrieve and from what share and directory or the share to upload to and as such, may not be omitted. -If the user name is embedded in the URL then it must contain the domain name +If the username is embedded in the URL then it must contain the domain name and as such, the backslash must be URL encoded as %2f. When uploading to SMB, the size of the file needs to be known ahead of time, @@ -367,25 +411,12 @@ curl supports SMB version 1 (only) ## SMTP -The path part of a SMTP request specifies the host name to present during -communication with the mail server. If the path is omitted, then libcurl will -attempt to resolve the local computer's host name. However, this may not -return the fully qualified domain name that is required by some mail servers -and specifying this path allows you to set an alternative name, such as your +The path part of an SMTP request specifies the hostname to present during +communication with the mail server. If the path is omitted, then libcurl +attempts to resolve the local computer's hostname. This may not return the +fully qualified domain name that is required by some mail servers and +specifying this path allows you to set an alternative name, such as your machine's fully qualified domain name, which you might have obtained from an external function such as gethostname or getaddrinfo. The default smtp port is 25. Some servers use port 587 as an alternative. - -## RTMP - -There is no official URL spec for RTMP so libcurl uses the URL syntax supported -by the underlying librtmp library. It has a syntax where it wants a -traditional URL, followed by a space and a series of space-separated -`name=value` pairs. - -While space is not typically a "legal" letter, libcurl accepts them. When a -user wants to pass in a `#` (hash) character it will be treated as a fragment -and get cut off by libcurl if provided literally. You will instead have to -escape it by providing it as backslash and its ASCII value in hexadecimal: -`\23`. diff --git a/third-party/curl/docs/VERIFY.md b/third-party/curl/docs/VERIFY.md new file mode 100644 index 0000000000..c18b65a661 --- /dev/null +++ b/third-party/curl/docs/VERIFY.md @@ -0,0 +1,168 @@ + + +# Verify + +Do not trust, verify! + +## Signed releases + +Every curl release is shipped as a set of tarballs. They all have the exact +same content but use different archivers, visible by the different file +extensions used. + +Each tarball is signed by the curl release manager Daniel. The digital +signatures for each tarball are always provided. The digital signatures can be +used to verify that the tarballs were produced by Daniel. + +If the curl website were breached and fake curl releases were +provided, they could be detected using these signatures. + +Daniel's public GPG key: [27ED EAF2 2F3A BCEB 50DB 9A12 5CC9 08FD B71E 12C2](https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x27edeaf22f3abceb50db9a125cc908fdb71e12c2) + +## Reproducible releases + +The curl project ships *reproducible releases*. This means that everyone is +able - and encouraged - to independently verify the contents of every curl +release. Verify that it contains exactly the bits that are supposed to be in +the release and nothing extra. + +The curl releases are generated using a Docker image to make it easy to get an +identical setup. To verify an existing curl release, we provide a convenient +script that generates a new curl release from source code and then compares +this newly generated release tarball with the tarball file you downloaded from +curl.se. + +For full verification, invoke the script inside an up-to-date curl source code +git repository. Without a git repository present, it does a lighter check by +rebuilding the release using the files in the tarball. + +Note: full verification mode checks out the release tag in your repository. +Run it in a clean working tree (no local changes) or a dedicated clone. + +Invoke it like this: + + git clone https://github.com/curl/curl + cd curl + mv [download-dir]/curl-8.19.0.tar.xz . + ./scripts/verify-release curl-8.19.0.tar.xz + +A successful check ends up with a final output similar to: + + curl-8.19.0.tar.xz: OK + +By verifying the release tarballs, you verify that Daniel does not infect the +release on purpose or involuntarily because of anything malicious running in +his setup. + +### Verify the verify + +Of course you should not blindly trust the verification script. It is short +and simple and should be quick to verify. Or you write your own script that +you trust, to do the same job. + +## Source code + +How do you then verify that what is in git is fine to build a product from? + +In the curl project we verify the source code in multiple ways, and one way to +gain trust is to verify and review our testing procedures. + +- we have a consistent code style (invalid style causes errors) + +- we ban and avoid a number of "sensitive" and "hard-to-use" C functions (use + of such functions causes errors) + +- we have a ceiling for complexity in functions to keep them easy to follow, + read and understand (failing to do so causes errors) + +- we review all pull requests before merging, both with humans and with bots. + We link back commits to their origin pull requests in commit messages. + +- we ban use of "binary blobs" in git to not provide means for malicious + actors to bundle encrypted payloads (trying to include a blob causes errors) + +- every single file in the git repository has a clear copyright and license + statement. Complete knowledge and tracking of provenience. + +- we actively avoid base64 encoded chunks as they too could function as ways + to obfuscate malicious contents + +- we forbid and prevent git force push on the master branch. History cannot be + rewritten. + +- we ban most uses of UTF-8 in code and documentation to avoid easily mixed + up Unicode characters that look like other characters. (adding Unicode + characters causes errors) + +- we document everything to make it clear how things are supposed to work. No + surprises. Lots of documentation is tested and verified in addition to + spellchecks and consistent wording. + +- we have thousands of tests and we add test cases for (ideally) every + functionality. Finding "white spots" and adding coverage is a top priority. + curl runs on countless operating systems, CPU architectures and you can + build curl in billions of different configuration setups: not every + combination is practically possible to test + +- we build curl and run tests in over two hundred CI jobs that are run for + every commit and every PR. We do not merge commits that have unexplained + test failures. + +- we run all tests as "torture tests", where each test case is rerun to have + every invoked fallible function call fail once each, to make sure curl + never leaks memory or crashes due to this. + +- we build curl in CI with the most picky compiler options enabled and we + never allow compiler warnings to linger. We always use `-Werror` that + converts warnings to errors and fail the builds. + +- we run all tests using valgrind and several combinations of sanitizers to + find and reduce the risk for memory problems, undefined behavior and + similar + +- we keep running static code analyzers on the code, both traditional ones + (clang-tidy, CodeSonar, Coverity) but also new generation AI powered ones + like Zeropath and Codex Security. + +- we run fuzzing on curl: non-stop as part of Google's OSS-Fuzz project, but + also briefly as part of the CI setup for every commit and PR + +- we make sure that the CI jobs we have for curl never "write back" to curl. + They access the source repository read-only and even if they would be + breached, they cannot infect or taint source code. + +- we run `zizmor` and other code analyzer tools on the CI job config scripts + to reduce the risk of us running or using insecure CI jobs. + +- we do reproducible releases to allow anyone to verify that the contents is + untainted + +- we digitally sign releases, git tags and git commits + +- there is a git backup on [codeberg](https://codeberg.org/curl/) for enhanced + resilience to infrastructure disturbance + +- we are committed to always fix reported vulnerabilities in the following + release. Security problems never linger around once they have been + reported. + +- we document everything and every detail about all curl vulnerabilities ever + reported + +- our code has been audited several times by external security experts, and + the few issues that have been detected in those were immediately addressed + +- Strong two-factor authentication on GitHub is mandatory for all committers + +- our commitment to never breaking ABI or API allows all users to easily + upgrade to new releases. This enables users to run recent security-fixed + versions instead of legacy insecure versions. + +- we have a vulnerability disclosure program that allows researchers to submit + suspected vulnerabilities in a private and secure fashion, so that we can + work on fixing curl and announcing the flaw in a responsible manner to + minimize risks for users. diff --git a/third-party/curl/docs/VERSIONS.md b/third-party/curl/docs/VERSIONS.md index 0ec9cd518a..5db6a51a76 100644 --- a/third-party/curl/docs/VERSIONS.md +++ b/third-party/curl/docs/VERSIONS.md @@ -1,57 +1,346 @@ -Version Numbers and Releases -============================ + - The version numbering is always built up using the same system: +# Version Numbers and Releases - X.Y.Z +The command line tool curl and the library libcurl are individually +versioned, but they usually follow each other closely. - - X is main version number - - Y is release number - - Z is patch number +The version numbering is always built up using the same system: + + X.Y.Z + +- X is main version number +- Y is release number +- Z is patch number ## Bumping numbers - One of these numbers will get bumped in each new release. The numbers to the - right of a bumped number will be reset to zero. +One of these numbers get bumped in each new release. The numbers to the right +of a bumped number are reset to zero. - The main version number will get bumped when *really* big, world colliding - changes are made. The release number is bumped when changes are performed or - things/features are added. The patch number is bumped when the changes are - mere bugfixes. +The main version number is bumped when *really* big, world colliding changes +are made. The release number is bumped when changes are performed or +things/features are added. The patch number is bumped when the changes are +mere bugfixes. - It means that after release 1.2.3, we can release 2.0.0 if something really - big has been made, 1.3.0 if not that big changes were made or 1.2.4 if only - bugs were fixed. +It means that after release 1.2.3, we can release 2.0.0 if something really +big has been made, 1.3.0 if not that big changes were made or 1.2.4 if only +bugs were fixed. - Bumping, as in increasing the number with 1, is unconditionally only - affecting one of the numbers (except the ones to the right of it, that may be - set to zero). 1 becomes 2, 3 becomes 4, 9 becomes 10, 88 becomes 89 and 99 - becomes 100. So, after 1.2.9 comes 1.2.10. After 3.99.3, 3.100.0 might come. +Bumping, as in increasing the number with 1, is unconditionally only affecting +one of the numbers (except the ones to the right of it, that may be set to +zero). 1 becomes 2, 3 becomes 4, 9 becomes 10, 88 becomes 89 and 99 +becomes 100. After 1.2.9 comes 1.2.10. After 3.99.3, 3.100.0 might come. - All original curl source release archives are named according to the libcurl - version (not according to the curl client version that, as said before, might - differ). +All original curl source release archives are named according to the libcurl +version (not according to the curl client version that, as said before, might +differ). - As a service to any application that might want to support new libcurl - features while still being able to build with older versions, all releases - have the libcurl version stored in the `curl/curlver.h` file using a static - numbering scheme that can be used for comparison. The version number is - defined as: +As a service to any application that might want to support new libcurl +features while still being able to build with older versions, all releases +have the libcurl version stored in the `curl/curlver.h` file using a static +numbering scheme that can be used for comparison. The version number is +defined as: ```c #define LIBCURL_VERSION_NUM 0xXXYYZZ ``` - Where `XX`, `YY` and `ZZ` are the main version, release and patch numbers in - hexadecimal. All three number fields are always represented using two digits - (eight bits each). 1.2 would appear as "0x010200" while version 9.11.7 - appears as `0x090b07`. +Where `XX`, `YY` and `ZZ` are the main version, release and patch numbers in +hexadecimal. All three number fields are always represented using two digits +(eight bits each). 1.2 would appear as "0x010200" while version 9.11.7 +appears as `0x090b07`. - This 6-digit hexadecimal number is always a greater number in a more recent - release. It makes comparisons with greater than and less than work. +This 6-digit hexadecimal number is always a greater number in a more recent +release. It makes comparisons with greater than and less than work. - This number is also available as three separate defines: - `LIBCURL_VERSION_MAJOR`, `LIBCURL_VERSION_MINOR` and `LIBCURL_VERSION_PATCH`. +This number is also available as three separate defines: +`LIBCURL_VERSION_MAJOR`, `LIBCURL_VERSION_MINOR` and `LIBCURL_VERSION_PATCH`. + +## Past releases + +This is a list of all public releases with their version numbers and release +dates. The tool was called `httpget` before 2.0, `urlget` before 4.0 then +`curl` since 4.0. `libcurl` and `curl` are always released in sync, using the +same version numbers. + +- 8.22.0: pending +- 8.21.0: June 24 2026 +- 8.20.0: April 29 2026 +- 8.19.0: March 11 2026 +- 8.18.0: January 7 2026 +- 8.17.0: November 5 2025 +- 8.16.0: September 10 2025 +- 8.15.0: July 16 2025 +- 8.14.1: June 4 2025 +- 8.14.0: May 28 2025 +- 8.13.0: April 2 2025 +- 8.12.1: February 13 2025 +- 8.12.0: February 5 2025 +- 8.11.1: December 11 2024 +- 8.11.0: November 6 2024 +- 8.10.1: September 18 2024 +- 8.10.0: September 11 2024 +- 8.9.1: July 31 2024 +- 8.9.0: July 24 2024 +- 8.8.0: May 22 2024 +- 8.7.1: March 27 2024 +- 8.7.0: March 27 2024 +- 8.6.0: January 31 2024 +- 8.5.0: December 6 2023 +- 8.4.0: October 11 2023 +- 8.3.0: September 13 2023 +- 8.2.1: July 26 2023 +- 8.2.0: July 19 2023 +- 8.1.2: May 30 2023 +- 8.1.1: May 23 2023 +- 8.1.0: May 17 2023 +- 8.0.1: March 20 2023 +- 8.0.0: March 20 2023 +- 7.88.1: February 20 2023 +- 7.88.0: February 15 2023 +- 7.87.0: December 21 2022 +- 7.86.0: October 26 2022 +- 7.85.0: August 31 2022 +- 7.84.0: June 27 2022 +- 7.83.1: May 11 2022 +- 7.83.0: April 27 2022 +- 7.82.0: March 5 2022 +- 7.81.0: January 5 2022 +- 7.80.0: November 10 2021 +- 7.79.1: September 22 2021 +- 7.79.0: September 15 2021 +- 7.78.0: July 21 2021 +- 7.77.0: May 26 2021 +- 7.76.1: April 14 2021 +- 7.76.0: March 31 2021 +- 7.75.0: February 3 2021 +- 7.74.0: December 9 2020 +- 7.73.0: October 14 2020 +- 7.72.0: August 19 2020 +- 7.71.1: July 1 2020 +- 7.71.0: June 24 2020 +- 7.70.0: April 29 2020 +- 7.69.1: March 11 2020 +- 7.69.0: March 4 2020 +- 7.68.0: January 8 2020 +- 7.67.0: November 6 2019 +- 7.66.0: September 11 2019 +- 7.65.3: July 19 2019 +- 7.65.2: July 17 2019 +- 7.65.1: June 5 2019 +- 7.65.0: May 22 2019 +- 7.64.1: March 27 2019 +- 7.64.0: February 6 2019 +- 7.63.0: December 12 2018 +- 7.62.0: October 31 2018 +- 7.61.1: September 5 2018 +- 7.61.0: July 11 2018 +- 7.60.0: May 16 2018 +- 7.59.0: March 14 2018 +- 7.58.0: January 24 2018 +- 7.57.0: November 29 2017 +- 7.56.1: October 23 2017 +- 7.56.0: October 4 2017 +- 7.55.1: August 14 2017 +- 7.55.0: August 9 2017 +- 7.54.1: June 14 2017 +- 7.54.0: April 19 2017 +- 7.53.1: February 24 2017 +- 7.53.0: February 22 2017 +- 7.52.1: December 23 2016 +- 7.52.0: December 21 2016 +- 7.51.0: November 2 2016 +- 7.50.3: September 14 2016 +- 7.50.2: September 7 2016 +- 7.50.1: August 3 2016 +- 7.50.0: July 21 2016 +- 7.49.1: May 30 2016 +- 7.49.0: May 18 2016 +- 7.48.0: March 23 2016 +- 7.47.1: February 8 2016 +- 7.47.0: January 27 2016 +- 7.46.0: December 2 2015 +- 7.45.0: October 7 2015 +- 7.44.0: August 12 2015 +- 7.43.0: June 17 2015 +- 7.42.1: April 29 2015 +- 7.42.0: April 22 2015 +- 7.41.0: February 25 2015 +- 7.40.0: January 8 2015 +- 7.39.0: November 5 2014 +- 7.38.0: September 10 2014 +- 7.37.1: July 16 2014 +- 7.37.0: May 21 2014 +- 7.36.0: March 26 2014 +- 7.35.0: January 29 2014 +- 7.34.0: December 17 2013 +- 7.33.0: October 14 2013 +- 7.32.0: August 12 2013 +- 7.31.0: June 22 2013 +- 7.30.0: April 12 2013 +- 7.29.0: February 6 2013 +- 7.28.1: November 20 2012 +- 7.28.0: October 10 2012 +- 7.27.0: July 27 2012 +- 7.26.0: May 24 2012 +- 7.25.0: March 22 2012 +- 7.24.0: January 24 2012 +- 7.23.1: November 17 2011 +- 7.23.0: November 15 2011 +- 7.22.0: September 13 2011 +- 7.21.7: June 23 2011 +- 7.21.6: April 22 2011 +- 7.21.5: April 17 2011 +- 7.21.4: February 17 2011 +- 7.21.3: December 15 2010 +- 7.21.2: October 13 2010 +- 7.21.1: August 11 2010 +- 7.21.0: June 16 2010 +- 7.20.1: April 14 2010 +- 7.20.0: February 9 2010 +- 7.19.7: November 4 2009 +- 7.19.6: August 12 2009 +- 7.19.5: May 18 2009 +- 7.19.4: March 3 2009 +- 7.19.3: January 19 2009 +- 7.19.2: November 13 2008 +- 7.19.1: November 5 2008 +- 7.19.0: September 1 2008 +- 7.18.2: June 4 2008 +- 7.18.1: March 30 2008 +- 7.18.0: January 28 2008 +- 7.17.1: October 29 2007 +- 7.17.0: September 13 2007 +- 7.16.4: July 10 2007 +- 7.16.3: June 25 2007 +- 7.16.2: April 11 2007 +- 7.16.1: January 29 2007 +- 7.16.0: October 30 2006 +- 7.15.5: August 7 2006 +- 7.15.4: June 12 2006 +- 7.15.3: March 20 2006 +- 7.15.2: February 27 2006 +- 7.15.1: December 7 2005 +- 7.15.0: October 13 2005 +- 7.14.1: September 1 2005 +- 7.14.0: May 16 2005 +- 7.13.2: April 4 2005 +- 7.13.1: March 4 2005 +- 7.13.0: February 1 2005 +- 7.12.3: December 20 2004 +- 7.12.2: October 18 2004 +- 7.12.1: August 10 2004 +- 7.12.0: June 2 2004 +- 7.11.2: April 26 2004 +- 7.11.1: March 19 2004 +- 7.11.0: January 22 2004 +- 7.10.8: November 1 2003 +- 7.10.7: August 15 2003 +- 7.10.6: July 28 2003 +- 7.10.5: May 19 2003 +- 7.10.4: April 2 2003 +- 7.10.3: January 14 2003 +- 7.10.2: November 18 2002 +- 7.10.1: October 11 2002 +- 7.10: October 1 2002 +- 7.9.8: June 13 2002 +- 7.9.7: May 10 2002 +- 7.9.6: April 14 2002 +- 7.9.5: March 7 2002 +- 7.9.4: March 4 2002 +- 7.9.3: January 23 2002 +- 7.9.2: December 5 2001 +- 7.9.1: November 4 2001 +- 7.9: September 23 2001 +- 7.8.1: August 20 2001 +- 7.8: June 7 2001 +- 7.7.3: May 4 2001 +- 7.7.2: April 22 2001 +- 7.7.1: April 3 2001 +- 7.7: March 22 2001 +- 7.6.1: February 9 2001 +- 7.6: January 26 2001 +- 7.5.2: January 4 2001 +- 7.5.1: December 11 2000 +- 7.5: December 1 2000 +- 7.4.2: November 15 2000 +- 7.4.1: October 16 2000 +- 7.4: October 16 2000 +- 7.3: September 28 2000 +- 7.2.1: August 31 2000 +- 7.2: August 30 2000 +- 7.1.1: August 21 2000 +- 7.1: August 7 2000 +- 6.5.2: March 21 2000 +- 6.5.1: March 20 2000 +- 6.5: March 13 2000 +- 6.4: January 17 2000 +- 6.3.1: November 23 1999 +- 6.3: November 10 1999 +- 6.2: October 21 1999 +- 6.1: October 17 1999 +- 6.0: September 13 1999 +- 5.11: August 25 1999 +- 5.10: August 13 1999 +- 5.9.1: July 30 1999 +- 5.9: May 22 1999 +- 5.8: May 5 1999 +- 5.7.1: April 23 1999 +- 5.7: April 20 1999 +- 5.5.1: January 27 1999 +- 5.5: January 15 1999 +- 5.4: January 7 1999 +- 5.3: December 21 1998 +- 5.2.1: December 14 1998 +- 5.2: December 14 1998 +- 5.0: December 1 1998 +- 4.10: October 26 1998 +- 4.9: October 7 1998 +- 4.8.4: September 20 1998 +- 4.8.3: September 7 1998 +- 4.8.2: August 14 1998 +- 4.8.1: August 7 1998 +- 4.8: July 30 1998 +- 4.7: July 20 1998 +- 4.6: July 3 1998 +- 4.5.1: June 12 1998 +- 4.5: May 30 1998 +- 4.4: May 13 1998 +- 4.3: April 30 1998 +- 4.2: April 15 1998 +- 4.1: April 3 1998 +- 4.0: March 20 1998 +- 3.12: March 14 1998 +- 3.11: February 9 1998 +- 3.10: February 4 1998 +- 3.9: February 4 1998 +- 3.7: January 15 1998 +- 3.6: January 1 1998 +- 3.5: December 15 1997 +- 3.2: December 1 1997 +- 3.1: November 24 1997 +- 3.0: November 1 1997 +- 2.9: October 15 1997 +- 2.8: October 1 1997 +- 2.7: September 20 1997 +- 2.6: September 10 1997 +- 2.5: September 1 1997 +- 2.4: August 27 1997 +- 2.3: August 21 1997 +- 2.2: August 14 1997 +- 2.1: August 10 1997 +- 2.0: August 1 1997 +- 1.5: July 21 1997 +- 1.4: July 15 1997 +- 1.3: June 1 1997 +- 1.2: May 1 1997 +- 1.1: April 20 1997 +- 1.0: April 8 1997 +- 0.3: February 1 1997 +- 0.2: December 17 1996 +- 0.1: November 11 1996 diff --git a/third-party/curl/docs/VULN-DISCLOSURE-POLICY.md b/third-party/curl/docs/VULN-DISCLOSURE-POLICY.md new file mode 100644 index 0000000000..a115ee1716 --- /dev/null +++ b/third-party/curl/docs/VULN-DISCLOSURE-POLICY.md @@ -0,0 +1,484 @@ + + +# curl vulnerability disclosure policy + +This document describes how security vulnerabilities are handled in the curl +project. + +There is no bug bounty and the curl project never offers rewards for reported +vulnerabilities. + +## Publishing Information + +All known and public curl or libcurl related vulnerabilities are listed on +[the curl website security page](https://curl.se/docs/security.html). + +Security vulnerabilities **should not** be entered in the project's public bug +tracker. + +## Vulnerability Handling + +The typical process for handling a new security vulnerability is as follows. + +No information should be made public about a vulnerability until it is +formally announced at the end of this process. That means, for example, that a +bug tracker entry must NOT be created to track the issue since that makes the +issue public and it should not be discussed on any of the project's public +mailing lists. Messages associated with any commits should not make any +reference to the security nature of the commit if done prior to the public +announcement. + +- The person discovering the issue, the reporter, reports the vulnerability on + [HackerOne](https://hackerone.com/curl). Issues filed there reach a handful + of selected and trusted people. + +- When communicating in the curl project, please explain your issues or + improvements briefly and clearly in your own human voice. Do not lazily + paste massive, AI-generated explanations; as a contributor doing this + infrequently, it is your responsibility to invest a few extra minutes into + making your message digestible. The maintainers review submissions + constantly, and clear writing reduces their daily burden and friction. + +- The curl project cannot handle vulnerability reports sent to us over email. + We lose track of the reports. We cannot easily disclose them. Please do not + send us reports over email. + +- Messages that do not relate to the reporting or managing of an undisclosed + security vulnerability in curl or libcurl are ignored and no further action + is required. + +- A person in the security team responds to the original report to acknowledge + that a human has seen the report. + +- The security team investigates the report and either rejects it or accepts + it. See below for examples of problems that are not considered + vulnerabilities. + +- If the report is rejected, the team writes to the reporter to explain why. + +- If the report is accepted, the team writes to the reporter to let them + know it is accepted and that they are working on a fix. + +- The security team discusses the problem, works out a fix, considers the + impact of the problem and suggests a release schedule. This discussion + should involve the reporter as much as possible. + +- The release of the information should be "as soon as possible" and is most + often synchronized with an upcoming release that contains the fix. If the + reporter, or anyone else involved, thinks the next planned release is too + far away, then a separate earlier release should be considered. + +- Write a security advisory draft about the problem that explains what the + problem is, its impact, which versions it affects, solutions or workarounds, + when the release is out and make sure to credit all contributors properly. + Figure out the CWE (Common Weakness Enumeration) number for the flaw. See + [SECURITY-ADVISORY](https://curl.se/dev/advisory.html) for help on creating + the advisory. + +- Request a CVE Id for the issue. curl is a CNA (CVE Numbering Authority) and + can request its own numbers. + +- Update the "security advisory" with the CVE number. + +- The security team commits the fix in a private branch. The commit message + should ideally contain the CVE number. If the severity level of the issue is + set to Low or Medium, the fix is allowed to get merged into the master + repository via a normal PR - but without mentioning it being a security + vulnerability. + +- No more than seven days before release, inform + [distros@openwall](https://oss-security.openwall.org/wiki/mailing-lists/distros) + to prepare them about the upcoming public security vulnerability + announcement - attach the advisory draft for information with CVE and + current patch. 'distros' does not accept an embargo longer than 7 days and + they do not care for Windows-specific flaws. + +- No more than 48 hours before the release, the private branch is merged into + the master branch and pushed. Once pushed, the information is accessible to + the public and the actual release should follow suit immediately afterwards. + The time between the push and the release is used for final tests and + reviews. + +- The project team creates a release that includes the fix. + +- The project team announces the release and the vulnerability to the world in + the same manner we always announce releases. It gets sent to the + curl-announce, curl-library and curl-users mailing lists. + +- The security webpage on the website should get the new vulnerability + mentioned. + +## security (at curl dot se) + +This is a private mailing list for discussions on and about curl security +issues. + +Who is on this list? There are a couple of criteria you must meet, and then we +might ask you to join the list or you can ask to join it. It really is not a +formal process. We only require that you have a long-term presence in the curl +project and you have shown an understanding for the project and its way of +working. You must have been around for a good while and you should have no +plans of vanishing in the near future. + +We do not make the list of participants public mostly because it tends to vary +somewhat over time and a list somewhere only risks getting outdated. + +## Publishing Security Advisories + +1. Write up the security advisory, using markdown syntax. Use the same + subtitles as last time to maintain consistency. + +2. Name the advisory file after the allocated CVE id. + +3. Add a line on the top of the array in `curl-www/docs/vuln.pm`. + +4. Put the new advisory markdown file in the `curl-www/docs/` directory. Add it + to the git repository. + +5. Run `make` in your local web checkout and verify that things look fine. + +6. On security advisory release day, push the changes on the curl-www + repository's remote master branch. + +## Disclose the report + +Request the issue to be disclosed. If there are sensitive details present in +the report and discussion, those should be redacted from the disclosure. The +default policy is to disclose as much as possible as soon as the vulnerability +has been published. + +*All* reports submitted to the project, valid or not, should be disclosed and +made public. + +# Severity levels + +The curl project's security team rates security problems using four severity +levels depending on how serious we consider the problem to be. We use **Low**, +**Medium**, **High** and **Critical**. We refrain from using numerical scoring +of vulnerabilities. + +We do not support CVSS as a method to grade security vulnerabilities, so we do +not set them for CVE records published by the curl project. We believe CVSS is +a broken system that often does not properly evaluate to suitable severity +levels that reflect all dimensions and factors involved. Other organizations +however set and provide CVSS scores for curl vulnerabilities. You need to +decide for yourself if you believe they know enough about the subjects +involved to make reasonable assessments. Deciding between four different +severity levels is hard enough for us. + +When deciding severity level on a particular issue, we take all the factors +into account: attack vector, attack complexity, required privileges, necessary +build configuration, protocols involved, platform specifics and also what +effects a possible exploit or trigger of the issue can lead to, including +confidentiality, integrity or availability problems. + +## Low + +This is a security problem that is truly hard or unlikely to exploit or +trigger. Due to timing, platform requirements or the fact that options or +protocols involved are rare etc. [Past +example](https://curl.se/docs/CVE-2022-43552.html) + +## Medium + +This is a security problem that is less hard than **Low** to exploit or +trigger. Less strict timing, wider platform availability or involving more +widely used options or protocols. A problem that usually needs something else +to also happen to become serious. [Past +example](https://curl.se/docs/CVE-2022-32206.html) + +## High + +This issue is in itself a serious problem with real world impact. Flaws that +can easily compromise the confidentiality, integrity or availability of +resources. Exploiting or triggering this problem is not hard. [Past +example](https://curl.se/docs/CVE-2019-3822.html) + +## Critical + +Easily exploitable by a remote unauthenticated attacker and lead to system +compromise (arbitrary code execution) without requiring user interaction, with +a common configuration on a popular platform. This issue has few restrictions +and requirements and can be exploited easily using most curl configurations. +[Past example](https://curl.se/docs/CVE-2000-0973.html) + +# Not security issues + +This is an incomplete list of issues that are not considered vulnerabilities. + +## Small memory leaks + +We do not consider a small memory leak a security problem; even if the amount +of allocated memory grows by a small amount every now and then. Long-living +applications and services already need to have countermeasures and deal with +growing memory usage, be it leaks or increased use. A small memory or resource +leak is then expected to *not* cause a security problem. + +Of course there can be a discussion if a leak is small or not. A large leak +can be considered a security problem due to the DOS risk. If leaked memory +contains sensitive data it might also qualify as a security problem. + +## Never-ending transfers + +We do not consider flaws that cause a transfer to never end to be a security +problem. There are already several benign and likely reasons for transfers to +stall and never end, so applications that cannot deal with never-ending +transfers already need to have counter-measures established. + +Well-known attacks, like +[Slowloris](https://en.wikipedia.org/wiki/Slowloris_(cyber_attack)), that send +partial requests are usually not considered a flaw. If the problem bypasses +the regular counter-measures and it causes a never-ending transfer, it might +be a security problem. + +## Not practically possible + +If the flaw or vulnerability cannot practically get executed on existing +hardware it is not a security problem. + +## API misuse + +If a reported issue only triggers by an application using the API in a way +that is not documented to work or even documented to not work, it is probably +not going to be considered a security problem. We only guarantee secure and +proper functionality when the APIs are used as expected and documented. + +There can be a discussion about what the documentation actually means and how +to interpret the text, which might end up with us still agreeing that it is a +security problem. + +## Local attackers already present + +When an issue can only be attacked or misused by an attacker present on the +local system or network, the bar is raised. If a local user wrongfully has +elevated rights on your system enough to attack curl, they can probably +already do much worse harm and the problem is not really in curl. + +## Debug & Experiments + +Vulnerabilities in features which are off by default (in the build) and +documented as experimental, or exist only in debug mode, are not considered +security problems. + +The same applies to scripts and software which are not installed by default +through the make install rule. + +## Test code + +curl has an extensive test suite with lots of code written specifically to +exercise and verify curl, libcurl and specific internal functions. The test +code and its associated test servers are *not* intended for production use. +They are not secure, you should not assume otherwise and must not report about +security problems in those. + +## URL inconsistencies + +URL parser inconsistencies between browsers and curl are expected and are not +considered security vulnerabilities. The WHATWG URL Specification and RFC +3986+ (the plus meaning that it is an extended version) [are not completely +interoperable](https://github.com/bagder/docs/blob/master/URL-interop.md). + +Obvious parser bugs can still be vulnerabilities of course. + +## Visible command line arguments + +The curl command blanks the contents of a number of command line arguments to +prevent them from appearing in process listings. It does not blank all +arguments, even though some that are not blanked might contain sensitive +data. We consider this functionality a best-effort and omissions are not +security vulnerabilities. + +- not all systems allow the arguments to be blanked in the first place +- since curl blanks the argument itself they are readable for a short moment + no matter what +- virtually every argument can contain sensitive data, depending on use +- blanking all arguments would make it impractical for users to differentiate + curl command lines in process listings + +## Busy-loops + +Busy-loops that consume 100% CPU time but eventually end (perhaps due to a set +timeout value or otherwise) are not considered security problems. Applications +are supposed to already handle situations when the transfer loop legitimately +consumes 100% CPU time, so while a prolonged such busy-loop is a nasty bug, we +do not consider it a security problem. + +## Saving files + +curl cannot protect against attacks where an attacker has write access to the +same directory where curl is directed to save files. + +## Tricking a user to run a command line + +A creative, misleading or funny looking command line is not a security +problem. The curl command line tool takes options and URLs on the command line +and if an attacker can trick the user to run a specifically crafted curl +command line, all bets are off. Such an attacker can already have the user run +a much worse command that can do something fatal (like `sudo rm -rf /`). + +## Terminal output and escape sequences + +Content that is transferred from a server and gets displayed in a terminal by +curl may contain escape sequences or use other tricks to fool the user. This +is curl working as designed and is not a curl security problem. Escape +sequences, moving cursor, changing color etc, is also frequently used for +good. To reduce the risk of getting fooled, save files and browse them after +download using a display method that minimizes risks. + +## NULL dereferences and crashes + +If a malicious server can trigger a NULL dereference in curl or otherwise +cause curl to crash (and nothing worse), chances are big that we do not +consider that a security problem. + +Malicious servers can already cause considerable harm and denial of service +like scenarios without having to trigger such code paths. For example by +stalling, being terribly slow or by delivering enormous amounts of data. +Additionally, applications are expected to handle "normal" crashes without +that being the end of the world. + +There need to be more and special circumstances to treat such problems as +security issues. + +## Legacy dependencies + +Problems that can be triggered only by the use of a *legacy dependency* are +not considered security problems. + +A *legacy dependency* is here defined as: + +- the legacy version was released over ten years ago AND + +- the legacy version is no longer in use by any existing still supported + operating system or distribution AND + +- there are modern versions of equivalent or better functionality offered and + in common use + +## weak algorithms required for functionality + +curl supports several algorithms that are considered weak, like DES and MD5. +These algorithms are still not curl security vulnerabilities or security +problems as they are only used when the users explicitly ask for their use by +using the protocols or options that require the use of those algorithms. + +When servers upgrade to use secure alternatives, curl users should use those +options/protocols. + +## CRLF in data + +curl makes barely any claims of *cleaning* input or rejecting invalid data. A +user that uses a curl feature can send in *creative* sequences that include +carriage-return (CR) or line-feed (LF) characters. + +Therefore, we reject the idea of *CRLF injection* as a security problem. It is +a *feature* that users can send creative byte sequences. If users do not want +to send such octets, they are in control and should avoid sending such bytes +to curl. + +For example, a user might pass in a username that looks like +`Mr[CR][LF]Smith`. It may cause some minor havoc in the protocol handling, +depending on what protocol is used. + +## Non-released code + +Only curl releases are ever considered *secure*. Between releases, we are +under development and then we may have code present in the git repository that +is insecure, but without those flaws being considered as vulnerabilities. +Another reason we strongly suggest you only use curl release versions in +production. + +Unreleased code may also contain fixes to problems that were present in the +most recent release. + +# curl major incident response + +Vulnerability disclosure manages the full life cycle of a vulnerability +affecting curl - where the **curl-security** team privately engages with +reporters coordinating on embargo and eventual release of security fixes. + +For most vulnerabilities (even critical vulnerabilities) this is the +normal _'mode'_ of incident response. + +A **major incident** is defined as something that has much larger scope and +impact on users and developers of curl. + +A major incident usually encompasses one or more of the following: +* broad and deep impact on developers, distros and users +* high visibility +* remote code execution +* exploit readily available +* critical curl infrastructure compromised +* time sensitive +* premature disclosure (e.g. embargo broken) + +A major incident is declared only when it is deemed that the normal +vulnerability disclosure process is not sufficient. + +The curl **major incident** process is as follows: + +## Major incident begins + +Only a member of the **curl-security** team can declare a **major incident** +via any or all of the following communication channels: + +* **irc**: channel #curl on the network [Libera.Chat](https://libera.chat/) +* **mailing-lists**: + * curl-announce + * curl-users + * curl-distros +* **website**: [curl.se](https://curl.se/) + +This declaration may also be transmitted via other channels, though the +above are considered official channels. + +The veracity of such a communication can be verified by consulting two +or more **curl-security** team members. + +This announcement nominates, from **curl-security** team, the following +roles: + +* **incident lead** - Coordinates technical efforts +* **communication lead** - Single point of public contact + +It is likely that our +[BDFL](https://en.wikipedia.org/wiki/Benevolent_dictator_for_life) occupies +one of these roles, though this plan does not depend on it. + +A declaration may also contain more detailed information but as we honor +embargoes and vulnerability disclosure throughout this process, it may also +contain a brief notification that a **major incident** is occurring. + +## Major incident ongoing + +During the incident - all press, media, legal or commercial entities should +contact communication lead (security@curl.se). + +Existing **curl-security** team internal communication channels are used +for all internal communication. + +Existing vulnerability disclosure process are followed for any embargoes +and fixes. + +Where possible, public communications are provided: +* regular communication from communication lead (for example daily update) +* asynchronous communication from incident lead + +* Delivered to the aforementioned curl communication channels. + +A log is kept of all external and internal communication. + +Once fixes have been released we may provide a more detailed postmortem and +overall timeline of events. + +## Major incident ends + +Both the incident and communication leads declare when a **major incident** +has finished. + +Any notices are removed and a return to normal vulnerability disclosure +process. diff --git a/third-party/curl/docs/cmdline-opts/.gitignore b/third-party/curl/docs/cmdline-opts/.gitignore new file mode 100644 index 0000000000..8d42e2c53d --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/.gitignore @@ -0,0 +1,5 @@ +# Copyright (C) Daniel Stenberg, , et al. +# +# SPDX-License-Identifier: curl + +curl.txt diff --git a/third-party/curl/docs/cmdline-opts/CMakeLists.txt b/third-party/curl/docs/cmdline-opts/CMakeLists.txt index 3dd8be49b1..83949969ae 100644 --- a/third-party/curl/docs/cmdline-opts/CMakeLists.txt +++ b/third-party/curl/docs/cmdline-opts/CMakeLists.txt @@ -21,15 +21,38 @@ # SPDX-License-Identifier: curl # ########################################################################### -set(MANPAGE "${CURL_BINARY_DIR}/docs/curl.1") - -# Load DPAGES and OTHERPAGES from shared file -transform_makefile_inc("Makefile.inc" "${CMAKE_CURRENT_BINARY_DIR}/Makefile.inc.cmake") +# Get SUPPORT, DPAGES variables +curl_transform_makefile_inc("Makefile.inc" "${CMAKE_CURRENT_BINARY_DIR}/Makefile.inc.cmake") include("${CMAKE_CURRENT_BINARY_DIR}/Makefile.inc.cmake") -add_custom_command(OUTPUT "${MANPAGE}" - COMMAND "${PERL_EXECUTABLE}" "${CMAKE_CURRENT_SOURCE_DIR}/gen.pl" mainpage "${CMAKE_CURRENT_SOURCE_DIR}" > "${MANPAGE}" - DEPENDS ${DPAGES} ${OTHERPAGES} +add_custom_command(OUTPUT "${CURL_MANPAGE}" "${CURL_ASCIIPAGE}" + WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR} + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/managen" mainpage ${DPAGES} > "${CURL_MANPAGE}" + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/managen" ascii ${DPAGES} > "${CURL_ASCIIPAGE}" + DEPENDS "${PROJECT_SOURCE_DIR}/scripts/managen" ${DPAGES} ${SUPPORT} + "${CMAKE_CURRENT_SOURCE_DIR}/Makefile.inc" + "${CMAKE_CURRENT_SOURCE_DIR}/mainpage.idx" VERBATIM ) -add_custom_target(generate-curl.1 DEPENDS "${MANPAGE}") + +add_custom_target(generate-curl.1 ALL DEPENDS "${CURL_MANPAGE}") + +if(NOT CURL_DISABLE_INSTALL) + install(FILES "${CURL_MANPAGE}" DESTINATION "${CMAKE_INSTALL_MANDIR}/man1") +endif() + +if(PERL_EXECUTABLE) + add_custom_target(curl-listhelp + WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR} + COMMENT "Generating src/tool_listhelp.c" VERBATIM USES_TERMINAL + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/managen" -d "${CMAKE_CURRENT_SOURCE_DIR}" listhelp ${DPAGES} + > "${PROJECT_SOURCE_DIR}/src/tool_listhelp.c" + DEPENDS "${PROJECT_SOURCE_DIR}/scripts/managen" ${DPAGES} + ) + add_custom_target(curl-listcats + WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR} + COMMENT "Generating help category constants for src/tool_help.h" VERBATIM USES_TERMINAL + COMMAND "${PERL_EXECUTABLE}" "${PROJECT_SOURCE_DIR}/scripts/managen" listcats ${DPAGES} + DEPENDS "${PROJECT_SOURCE_DIR}/scripts/managen" ${DPAGES} + ) +endif() diff --git a/third-party/curl/docs/cmdline-opts/MANPAGE.md b/third-party/curl/docs/cmdline-opts/MANPAGE.md index 6de32dab94..1e4facd954 100644 --- a/third-party/curl/docs/cmdline-opts/MANPAGE.md +++ b/third-party/curl/docs/cmdline-opts/MANPAGE.md @@ -6,37 +6,53 @@ # curl man page generator -This is the curl man page generator. It generates a single nroff man page +`managen` is the curl man page generator. It generates a single nroff man page output from the set of sources files in this directory. -There is one source file for each supported command line option. The output -gets `page-header` prepended and `page-footer` appended. The format is -described below. +The `mainpage.idx` file lists all files that are rendered in that order to +produce the output. The special `%options` keyword inserts all command line +options documented. + +The `%options` documentation is created with one source file for each +supported command line option. + +The documentation file format is described below. It is meant to look similar +to markdown which is why it uses `.md` file extensions. ## Option files Each command line option is described in a file named `.d`, where -option name is written without any prefixing dashes. Like the file name for -the -v, --verbose option is named `verbose.d`. +option name is written without any prefixing dashes. Like the filename for the +`-v, --verbose` option is named `verbose.d`. -Each file has a set of meta-data and a body of text. +Each file has a set of meta-data in the top of the file, followed by a body of +text. + +The documentation files that do not document options have no meta-data part. + +A line that starts with ``. ### Meta-data + --- (start of meta-data) Added: (version number in which this was added) Arg: (the argument the option takes) c: (copyright line) - Example: (example command line, without "curl" and can use `$URL`) + Example: + - (an example command line, without "curl" and can use `$URL`) + - (another example) Experimental: yes (if so) Help: (short text for the --help output for this option) Long: (long form name, without dashes) Magic: (description of "magic" options) - Multi: single/append/boolean/mutex/custom (if used more than once) + Multi: single/append/boolean/mutex/custom/per-URL (if used more than once) Mutexed: (space separated list of options this overrides, no dashes) Protocols: (space separated list for which protocols this option works) Requires: (space separated list of features this requires, no dashes) Scope: global (if the option is global) - See-also: (space separated list of related options, no dashes) + See-also: + - (a related option, no dashes) + - (another related option, no dashes) Short: (single letter, without dash) SPDX-License-Identifier: curl Tags: (space separated list) @@ -54,20 +70,97 @@ Text written within `*asterisks*` is shown using italics. Text within two Text that is prefixed with a space is treated like an "example" and gets output in monospace. -## Header and footer +Within the body, describe a list of items like this: -`page-header` is the file that is output before the generated options output -for the master man page. + ## item 1 + description -`page-footer` is appended after all the individual options. + ## item 2 + second description + +The list is automatically terminated at end of file, or you can do it +explicitly with an empty "header": + + ## + +Angle brackets (`<>`) need to be escaped when used in text like `\<` and +`\>`. This, to ensure that the text renders nicely as markdown. + +### Headers + +The `#` header can be used by non-option files and it produces a +`.SH` output. + +If the `#` header is used for a command line option file, that header is +ignored in the generated output. It can still serve a purpose in the +source file as it helps the user identify what option the file is for. + +### Variables + +There are three different "variables" that can be used when creating the +output. They need to be written within backticks in the source file (to escape +getting spellchecked by CI jobs): `%DATE`, `%VERSION` and `%GLOBALS`. + +During rendering, the generator expands them as follows: + +- `%VERSION` -- replaced with the curl version string read from + `include/curl/curlver.h` (e.g. `8.12.0`). Can be overridden by setting + the `CURL_MAKETGZ_VERSION` environment variable. +- `%DATE` -- replaced with the current date in `YYYY-MM-DD` format, or + the date derived from `SOURCE_DATE_EPOCH` if that environment variable + is set (for reproducible builds). +- `%GLOBALS` -- replaced with a comma-separated list of all command line + options that have `Scope: global` in their meta-data. ## Generate -`./gen.pl mainpage` +`managen mainpage [list of markdown option file names]` This command outputs a single huge nroff file, meant to become `curl.1`. The full curl man page. -`./gen.pl listhelp` +`managen ascii [list of markdown option file names]` + +This command outputs a single text file, meant to become `curl.txt`. The full +curl man page in text format, used to build `tool_hugehelp.c`. + +`managen listhelp` Generates a full `curl --help` output for all known command line options. + +## Generating the man page + +The `curl.1` man page is generated from the source files in this directory +using the `managen` Perl script located in `scripts/managen`. The build +system runs this automatically, but it can also be invoked manually. + +### Prerequisites + +The generator requires Perl. The version string is read from +`include/curl/curlver.h` (or from the `CURL_MAKETGZ_VERSION` environment +variable if set). The date defaults to the current date unless +`SOURCE_DATE_EPOCH` is set. + +### Manual invocation + +From the `docs/cmdline-opts` directory, run: + + cd docs/cmdline-opts + perl ../../scripts/managen -I ../../include mainpage ./*.md > curl.1 + +This produces the complete `curl.1` nroff man page. To produce a plain-text +version instead, replace `mainpage` with `ascii`: + + perl ../../scripts/managen -I ../../include ascii ./*.md > curl.txt + +The `-d` flag specifies the directory containing `mainpage.idx` and the +`.md` option files. The `-I` flag specifies the include directory root +used to locate `curl/curlver.h` for the version string. + +### How it works + +The generator reads `mainpage.idx`, which lists the documentation source +files in their intended order. Each line names one `.md` file to render. +When the generator encounters the `%options` keyword in `mainpage.idx`, +it inserts the documentation for every command line option (one `.md` file +per option), sorted alphabetically by long option name. diff --git a/third-party/curl/docs/cmdline-opts/Makefile.am b/third-party/curl/docs/cmdline-opts/Makefile.am index 5a8996bc22..019dd57b8a 100644 --- a/third-party/curl/docs/cmdline-opts/Makefile.am +++ b/third-party/curl/docs/cmdline-opts/Makefile.am @@ -24,18 +24,41 @@ AUTOMAKE_OPTIONS = foreign no-dependencies -MANPAGE = $(top_builddir)/docs/curl.1 +MANPAGE = curl.1 +ASCIIPAGE = curl.txt +# Get SUPPORT, DPAGES variables include Makefile.inc -EXTRA_DIST = $(DPAGES) MANPAGE.md gen.pl $(OTHERPAGES) CMakeLists.txt +EXTRA_DIST = $(DPAGES) MANPAGE.md $(SUPPORT) CMakeLists.txt mainpage.idx GEN = $(GN_$(V)) GN_0 = @echo " GENERATE" $@; GN_1 = GN_ = $(GN_0) -all: $(MANPAGE) +MANAGEN=$(top_srcdir)/scripts/managen +MAXLINE=$(top_srcdir)/scripts/maxline -$(MANPAGE): $(DPAGES) $(OTHERPAGES) Makefile.inc gen.pl - $(GEN)(rm -f $(MANPAGE) && cd $(srcdir) && @PERL@ ./gen.pl mainpage $(DPAGES) > $(builddir)/manpage.tmp && mv $(builddir)/manpage.tmp $(MANPAGE)) +# Maximum number of columns accepted in the ASCII version of the man page +INCDIR=$(top_srcdir)/include + +if BUILD_DOCS +CLEANFILES = $(MANPAGE) $(ASCIIPAGE) +man_MANS = $(MANPAGE) + +all: $(MANPAGE) $(ASCIIPAGE) + +endif + +$(MANPAGE): $(DPAGES) $(SUPPORT) mainpage.idx Makefile.inc $(MANAGEN) + $(GEN)(rm -f $(MANPAGE) && @PERL@ $(MANAGEN) -d $(srcdir) -I $(INCDIR) mainpage $(DPAGES) > manpage.tmp.$$$$ && mv manpage.tmp.$$$$ $(MANPAGE)) + +$(ASCIIPAGE): $(DPAGES) $(SUPPORT) mainpage.idx Makefile.inc $(MANAGEN) + $(GEN)(rm -f $(ASCIIPAGE) && @PERL@ $(MANAGEN) -d $(srcdir) -I $(INCDIR) ascii $(DPAGES) > asciipage.tmp.$$$$ && mv asciipage.tmp.$$$$ $(ASCIIPAGE)) + +listhelp: + $(MANAGEN) -d $(srcdir) listhelp $(DPAGES) > $(top_builddir)/src/tool_listhelp.c + +listcats: + @$(MANAGEN) listcats $(DPAGES) diff --git a/third-party/curl/docs/cmdline-opts/Makefile.inc b/third-party/curl/docs/cmdline-opts/Makefile.inc index fa4cbe59f0..f8fd01ccd6 100644 --- a/third-party/curl/docs/cmdline-opts/Makefile.inc +++ b/third-party/curl/docs/cmdline-opts/Makefile.inc @@ -21,265 +21,301 @@ # SPDX-License-Identifier: curl # ########################################################################### -# Shared between Makefile.am and CMakeLists.txt +# Shared between CMakeLists.txt and Makefile.am + +SUPPORT = \ + _AUTHORS.md \ + _BUGS.md \ + _DESCRIPTION.md \ + _ENVIRONMENT.md \ + _EXITCODES.md \ + _FILES.md \ + _GLOBBING.md \ + _NAME.md \ + _OPTIONS.md \ + _OUTPUT.md \ + _PROGRESS.md \ + _PROTOCOLS.md \ + _PROXYPREFIX.md \ + _SEEALSO.md \ + _SYNOPSIS.md \ + _URL.md \ + _VARIABLES.md \ + _VERSION.md \ + _WWW.md DPAGES = \ - abstract-unix-socket.d \ - alt-svc.d \ - anyauth.d \ - append.d \ - aws-sigv4.d \ - basic.d \ - ca-native.d \ - cacert.d \ - capath.d \ - cert-status.d \ - cert-type.d \ - cert.d \ - ciphers.d \ - compressed-ssh.d \ - compressed.d \ - config.d \ - connect-timeout.d \ - connect-to.d \ - continue-at.d \ - cookie-jar.d \ - cookie.d \ - create-dirs.d \ - create-file-mode.d \ - crlf.d \ - crlfile.d \ - curves.d \ - data-ascii.d \ - data-binary.d \ - data-raw.d \ - data-urlencode.d \ - data.d \ - delegation.d \ - digest.d \ - disable-eprt.d \ - disable-epsv.d \ - disable.d \ - disallow-username-in-url.d \ - dns-interface.d \ - dns-ipv4-addr.d \ - dns-ipv6-addr.d \ - dns-servers.d \ - doh-cert-status.d \ - doh-insecure.d \ - doh-url.d \ - dump-header.d \ - egd-file.d \ - engine.d \ - etag-compare.d \ - etag-save.d \ - expect100-timeout.d \ - fail-early.d \ - fail-with-body.d \ - fail.d \ - false-start.d \ - form-escape.d \ - form-string.d \ - form.d \ - ftp-account.d \ - ftp-alternative-to-user.d \ - ftp-create-dirs.d \ - ftp-method.d \ - ftp-pasv.d \ - ftp-port.d \ - ftp-pret.d \ - ftp-skip-pasv-ip.d \ - ftp-ssl-ccc-mode.d \ - ftp-ssl-ccc.d \ - ftp-ssl-control.d \ - get.d \ - globoff.d \ - happy-eyeballs-timeout-ms.d \ - haproxy-protocol.d \ - haproxy-clientip.d \ - head.d \ - header.d \ - help.d \ - hostpubmd5.d \ - hostpubsha256.d \ - hsts.d \ - http0.9.d \ - http1.0.d \ - http1.1.d \ - http2-prior-knowledge.d \ - http2.d \ - http3.d \ - http3-only.d \ - ignore-content-length.d \ - include.d \ - insecure.d \ - interface.d \ - ipv4.d \ - ipv6.d \ - json.d \ - junk-session-cookies.d \ - keepalive-time.d \ - key-type.d \ - key.d \ - krb.d \ - libcurl.d \ - limit-rate.d \ - list-only.d \ - local-port.d \ - location-trusted.d \ - location.d \ - login-options.d \ - mail-auth.d \ - mail-from.d \ - mail-rcpt-allowfails.d \ - mail-rcpt.d \ - manual.d \ - max-filesize.d \ - max-redirs.d \ - max-time.d \ - metalink.d \ - negotiate.d \ - netrc-file.d \ - netrc-optional.d \ - netrc.d \ - next.d \ - no-alpn.d \ - no-buffer.d \ - no-clobber.d \ - no-keepalive.d \ - no-npn.d \ - no-progress-meter.d \ - no-sessionid.d \ - noproxy.d \ - ntlm-wb.d \ - ntlm.d \ - oauth2-bearer.d \ - output-dir.d \ - output.d \ - parallel-immediate.d \ - parallel-max.d \ - parallel.d \ - pass.d \ - path-as-is.d \ - pinnedpubkey.d \ - post301.d \ - post302.d \ - post303.d \ - preproxy.d \ - progress-bar.d \ - proto-default.d \ - proto-redir.d \ - proto.d \ - proxy-anyauth.d \ - proxy-basic.d \ - proxy-ca-native.d \ - proxy-cacert.d \ - proxy-capath.d \ - proxy-cert-type.d \ - proxy-cert.d \ - proxy-ciphers.d \ - proxy-crlfile.d \ - proxy-digest.d \ - proxy-header.d \ - proxy-http2.d \ - proxy-insecure.d \ - proxy-key-type.d \ - proxy-key.d \ - proxy-negotiate.d \ - proxy-ntlm.d \ - proxy-pass.d \ - proxy-pinnedpubkey.d \ - proxy-service-name.d \ - proxy-ssl-allow-beast.d \ - proxy-ssl-auto-client-cert.d \ - proxy-tls13-ciphers.d \ - proxy-tlsauthtype.d \ - proxy-tlspassword.d \ - proxy-tlsuser.d \ - proxy-tlsv1.d \ - proxy-user.d \ - proxy.d \ - proxy1.0.d \ - proxytunnel.d \ - pubkey.d \ - quote.d \ - random-file.d \ - range.d \ - rate.d \ - raw.d \ - referer.d \ - remote-header-name.d \ - remote-name-all.d \ - remote-name.d \ - remote-time.d \ - remove-on-error.d \ - request-target.d \ - request.d \ - resolve.d \ - retry-all-errors.d \ - retry-connrefused.d \ - retry-delay.d \ - retry-max-time.d \ - retry.d \ - sasl-authzid.d \ - sasl-ir.d \ - service-name.d \ - show-error.d \ - silent.d \ - socks4.d \ - socks4a.d \ - socks5-basic.d \ - socks5-gssapi-nec.d \ - socks5-gssapi-service.d \ - socks5-gssapi.d \ - socks5-hostname.d \ - socks5.d \ - speed-limit.d \ - speed-time.d \ - ssl-allow-beast.d \ - ssl-auto-client-cert.d \ - ssl-no-revoke.d \ - ssl-reqd.d \ - ssl-revoke-best-effort.d \ - ssl.d \ - sslv2.d \ - sslv3.d \ - stderr.d \ - styled-output.d \ - suppress-connect-headers.d \ - tcp-fastopen.d \ - tcp-nodelay.d \ - telnet-option.d \ - tftp-blksize.d \ - tftp-no-options.d \ - time-cond.d \ - tls-max.d \ - tls13-ciphers.d \ - tlsauthtype.d \ - tlspassword.d \ - tlsuser.d \ - tlsv1.0.d \ - tlsv1.1.d \ - tlsv1.2.d \ - tlsv1.3.d \ - tlsv1.d \ - tr-encoding.d \ - trace-ascii.d \ - trace-config.d \ - trace-ids.d \ - trace-time.d \ - trace.d \ - unix-socket.d \ - upload-file.d \ - url.d \ - url-query.d \ - use-ascii.d \ - user-agent.d \ - user.d \ - variable.d \ - verbose.d \ - version.d \ - write-out.d \ - xattr.d - -OTHERPAGES = page-footer page-header + abstract-unix-socket.md \ + alt-svc.md \ + anyauth.md \ + append.md \ + aws-sigv4.md \ + basic.md \ + ca-native.md \ + cacert.md \ + capath.md \ + cert-status.md \ + cert-type.md \ + cert.md \ + ciphers.md \ + compressed-ssh.md \ + compressed.md \ + config.md \ + connect-timeout.md \ + connect-to.md \ + continue-at.md \ + cookie-jar.md \ + cookie.md \ + create-dirs.md \ + create-file-mode.md \ + crlf.md \ + crlfile.md \ + curves.md \ + data-ascii.md \ + data-binary.md \ + data-raw.md \ + data-urlencode.md \ + data.md \ + delegation.md \ + digest.md \ + disable-eprt.md \ + disable-epsv.md \ + disable.md \ + disallow-username-in-url.md \ + dns-interface.md \ + dns-ipv4-addr.md \ + dns-ipv6-addr.md \ + dns-servers.md \ + doh-cert-status.md \ + doh-insecure.md \ + doh-url.md \ + dump-ca-embed.md \ + dump-header.md \ + ech.md \ + egd-file.md \ + engine.md \ + etag-compare.md \ + etag-save.md \ + expect100-timeout.md \ + fail-early.md \ + fail-with-body.md \ + fail.md \ + false-start.md \ + follow.md \ + form-escape.md \ + form-string.md \ + form.md \ + ftp-account.md \ + ftp-alternative-to-user.md \ + ftp-create-dirs.md \ + ftp-method.md \ + ftp-pasv.md \ + ftp-port.md \ + ftp-pret.md \ + ftp-skip-pasv-ip.md \ + ftp-ssl-ccc-mode.md \ + ftp-ssl-ccc.md \ + ftp-ssl-control.md \ + get.md \ + globoff.md \ + happy-eyeballs-timeout-ms.md \ + haproxy-protocol.md \ + haproxy-clientip.md \ + head.md \ + header.md \ + help.md \ + hostpubmd5.md \ + hostpubsha256.md \ + hsts.md \ + http0.9.md \ + http1.0.md \ + http1.1.md \ + http2-prior-knowledge.md \ + http2.md \ + http3.md \ + http3-only.md \ + ignore-content-length.md \ + insecure.md \ + interface.md \ + ip-tos.md \ + ipfs-gateway.md \ + ipv4.md \ + ipv6.md \ + json.md \ + junk-session-cookies.md \ + keepalive-cnt.md \ + keepalive-time.md \ + key-type.md \ + key.md \ + knownhosts.md \ + krb.md \ + libcurl.md \ + limit-rate.md \ + list-only.md \ + local-port.md \ + location-trusted.md \ + location.md \ + login-options.md \ + mail-auth.md \ + mail-from.md \ + mail-rcpt-allowfails.md \ + mail-rcpt.md \ + manual.md \ + max-filesize.md \ + max-redirs.md \ + max-time.md \ + metalink.md \ + mptcp.md \ + negotiate.md \ + netrc-file.md \ + netrc-optional.md \ + netrc.md \ + next.md \ + no-alpn.md \ + no-buffer.md \ + no-clobber.md \ + no-keepalive.md \ + no-npn.md \ + no-progress-meter.md \ + no-sessionid.md \ + noproxy.md \ + ntlm-wb.md \ + ntlm.md \ + oauth2-bearer.md \ + output-dir.md \ + out-null.md \ + output.md \ + parallel-immediate.md \ + parallel-max-host.md \ + parallel-max.md \ + parallel.md \ + pass.md \ + path-as-is.md \ + pinnedpubkey.md \ + post301.md \ + post302.md \ + post303.md \ + preproxy.md \ + progress-bar.md \ + proto-default.md \ + proto-redir.md \ + proto.md \ + proxy-anyauth.md \ + proxy-basic.md \ + proxy-ca-native.md \ + proxy-cacert.md \ + proxy-capath.md \ + proxy-cert-type.md \ + proxy-cert.md \ + proxy-ciphers.md \ + proxy-crlfile.md \ + proxy-digest.md \ + proxy-header.md \ + proxy-http2.md \ + proxy-http3.md \ + proxy-insecure.md \ + proxy-key-type.md \ + proxy-key.md \ + proxy-negotiate.md \ + proxy-ntlm.md \ + proxy-pass.md \ + proxy-pinnedpubkey.md \ + proxy-service-name.md \ + proxy-ssl-allow-beast.md \ + proxy-ssl-auto-client-cert.md \ + proxy-tls13-ciphers.md \ + proxy-tlsauthtype.md \ + proxy-tlspassword.md \ + proxy-tlsuser.md \ + proxy-tlsv1.md \ + proxy-user.md \ + proxy.md \ + proxy1.0.md \ + proxytunnel.md \ + pubkey.md \ + quote.md \ + random-file.md \ + range.md \ + rate.md \ + raw.md \ + referer.md \ + remote-header-name.md \ + remote-name-all.md \ + remote-name.md \ + remote-time.md \ + remove-on-error.md \ + request-target.md \ + request.md \ + resolve.md \ + retry-all-errors.md \ + retry-connrefused.md \ + retry-delay.md \ + retry-max-time.md \ + retry.md \ + sasl-authzid.md \ + sasl-ir.md \ + service-name.md \ + show-error.md \ + show-headers.md \ + silent.md \ + sigalgs.md \ + skip-existing.md \ + socks4.md \ + socks4a.md \ + socks5-basic.md \ + socks5-gssapi-nec.md \ + socks5-gssapi-service.md \ + socks5-gssapi.md \ + socks5-hostname.md \ + socks5.md \ + speed-limit.md \ + speed-time.md \ + ssl-allow-beast.md \ + ssl-auto-client-cert.md \ + ssl-no-revoke.md \ + ssl-reqd.md \ + ssl-revoke-best-effort.md \ + ssl-sessions.md \ + ssl.md \ + sslv2.md \ + sslv3.md \ + stderr.md \ + styled-output.md \ + suppress-connect-headers.md \ + tcp-fastopen.md \ + tcp-nodelay.md \ + telnet-option.md \ + tftp-blksize.md \ + tftp-no-options.md \ + time-cond.md \ + tls-earlydata.md \ + tls-max.md \ + tls13-ciphers.md \ + tlsauthtype.md \ + tlspassword.md \ + tlsuser.md \ + tlsv1.0.md \ + tlsv1.1.md \ + tlsv1.2.md \ + tlsv1.3.md \ + tlsv1.md \ + tr-encoding.md \ + trace-ascii.md \ + trace-config.md \ + trace-ids.md \ + trace-time.md \ + trace.md \ + unix-socket.md \ + upload-file.md \ + upload-flags.md \ + url.md \ + url-query.md \ + use-ascii.md \ + user-agent.md \ + user.md \ + variable.md \ + verbose.md \ + version.md \ + vlan-priority.md \ + write-out.md \ + xattr.md diff --git a/third-party/curl/docs/cmdline-opts/_AUTHORS.md b/third-party/curl/docs/cmdline-opts/_AUTHORS.md new file mode 100644 index 0000000000..0c9bfb9538 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_AUTHORS.md @@ -0,0 +1,5 @@ + + +# AUTHORS +Daniel Stenberg is the main author, but the whole list of contributors is +found in the separate THANKS file. diff --git a/third-party/curl/docs/cmdline-opts/_BUGS.md b/third-party/curl/docs/cmdline-opts/_BUGS.md new file mode 100644 index 0000000000..45630d4352 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_BUGS.md @@ -0,0 +1,5 @@ + + +# BUGS +If you experience any problems with curl, submit an issue in the project's bug +tracker on GitHub: https://github.com/curl/curl/issues diff --git a/third-party/curl/docs/cmdline-opts/_DESCRIPTION.md b/third-party/curl/docs/cmdline-opts/_DESCRIPTION.md new file mode 100644 index 0000000000..bb21f0ba32 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_DESCRIPTION.md @@ -0,0 +1,11 @@ + + +# DESCRIPTION + +**curl** is a tool for transferring data from or to a server using URLs. It +supports these protocols: DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, +IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, RTSP, SCP, SFTP, SMB, +SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. + +curl is powered by libcurl for all transfer-related features. See +*libcurl(3)* for details. diff --git a/third-party/curl/docs/cmdline-opts/_ENVIRONMENT.md b/third-party/curl/docs/cmdline-opts/_ENVIRONMENT.md new file mode 100644 index 0000000000..a3c13ae0c0 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_ENVIRONMENT.md @@ -0,0 +1,120 @@ + + +# ENVIRONMENT +The environment variables can be specified in lower case or upper case. The +lower case version has precedence. `http_proxy` is an exception as it is only +available in lower case. (Note that some systems, like Windows, do not +differentiate between environment variables using different case.) + +Using an environment variable to set the proxy has the same effect as using +the --proxy option. + +## `http_proxy [protocol://][:port]` +Sets the proxy server to use for HTTP. + +## `HTTPS_PROXY [protocol://][:port]` +Sets the proxy server to use for HTTPS. + +## `[url-protocol]_PROXY [protocol://][:port]` +Sets the proxy server to use for [url-protocol], where the protocol is a +protocol that curl supports and as specified in a URL. FTP, FTPS, POP3, IMAP, +SMTP, LDAP, etc. + +## `ALL_PROXY [protocol://][:port]` +Sets the proxy server to use if no protocol-specific proxy is set. + +## `NO_PROXY ` +list of hostnames that should not go through any proxy. If set to an asterisk +'*' only, it matches all hosts. Each name in this list is matched as either a +domain name which contains the hostname, or the hostname itself. + +This environment variable disables use of the proxy even when specified with +the --proxy option. That is + + NO_PROXY=direct.example.com curl -x http://proxy.example.com + https://direct.example.com + +accesses the target URL directly, and + + NO_PROXY=direct.example.com curl -x http://proxy.example.com + https://somewhere.example.com + +accesses the target URL through the proxy. + +The list of hostnames can also include numerical IP addresses, and IPv6 +versions should then be given without enclosing brackets. + +IP addresses can be specified using CIDR notation: an appended slash and +number specifies the number of "network bits" out of the address to use in the +comparison (added in 7.86.0). For example "192.168.0.0/16" would match all +addresses starting with "192.168". + +## `APPDATA ` +On Windows, this variable is used when trying to find the home directory. If +the primary home variables are all unset. + +## `COLUMNS ` +If set, the specified number of characters is used as the terminal width when +the alternative progress-bar is shown. If not set, curl tries to figure it out +using other ways. + +## `CURL_CA_BUNDLE ` +If set, it is used as the --cacert value. This environment variable is ignored +if Schannel is used as the TLS backend. + +## `CURL_HOME ` +If set, is the first variable curl checks when trying to find its home +directory. If not set, it continues to check *XDG_CONFIG_HOME* + +## `CURL_SSL_BACKEND ` +If curl was built with support for "MultiSSL", meaning that it has built-in +support for more than one TLS backend, this environment variable can be set to +the case insensitive name of the particular backend to use when curl is +invoked. Setting a name that is not a built-in alternative makes curl stay +with the default. + +SSL backend names (case-insensitive): **gnutls**, **mbedtls**, **openssl**, +**rustls**, **schannel**, **wolfssl** + +## `HOME ` +If set, this is used to find the home directory when that is needed. Like when +looking for the default .curlrc. *CURL_HOME* and *XDG_CONFIG_HOME* +have preference. + +## `NETRC ` +If set, this is used to find the `.netrc` file. It overrides all other netrc +file location mechanisms and should be set to the full file path. +(Added in curl 8.16.0) + +## `QLOGDIR ` +If curl was built with HTTP/3 support, setting this environment variable to a +local directory makes curl produce **qlogs** in that directory, using file +names named after the destination connection id (in hex). Do note that these +files can become rather large. Works with the ngtcp2 and quiche QUIC backends. + +## `SHELL` +Used on VMS when trying to detect if using a **DCL** or a **Unix** shell. + +## `SSL_CERT_DIR ` +If set, it is used as the --capath value. This environment variable is ignored +if Schannel is used as the TLS backend. + +## `SSL_CERT_FILE ` +If set, it is used as the --cacert value. This environment variable is ignored +if Schannel is used as the TLS backend. + +## `SSLKEYLOGFILE ` +If you set this environment variable to a filename, curl stores TLS secrets +from its connections in that file when invoked to enable you to analyze the +TLS traffic in real time using network analyzing tools such as Wireshark. This +works with the following TLS backends: OpenSSL, LibreSSL (TLS 1.2 max), +BoringSSL, GnuTLS, wolfSSL and Rustls. + +## `USERPROFILE ` +On Windows, this variable is used when trying to find the home directory. If +the other, primary, variables are all unset. If set, curl uses the path +**"$USERPROFILE\Application Data"**. + +## `XDG_CONFIG_HOME ` +If *CURL_HOME* is not set, this variable is checked when looking for a +default .curlrc file. diff --git a/third-party/curl/docs/cmdline-opts/_EXITCODES.md b/third-party/curl/docs/cmdline-opts/_EXITCODES.md new file mode 100644 index 0000000000..333e198d7c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_EXITCODES.md @@ -0,0 +1,203 @@ + + +# EXIT CODES +There are a bunch of different error codes and their corresponding error +messages that may appear under error conditions. At the time of this writing, +the exit codes are: +## 0 +Success. The operation completed successfully according to the instructions. +## 1 +Unsupported protocol. This build of curl has no support for this protocol. +## 2 +Failed to initialize. +## 3 +URL malformed. The syntax was not correct. +## 4 +A feature or option that was needed to perform the desired request was not +enabled or was explicitly disabled at build-time. To make curl able to do +this, you probably need another build of libcurl. +## 5 +Could not resolve proxy. The given proxy host could not be resolved. +## 6 +Could not resolve host. The given remote host could not be resolved. +## 7 +Failed to connect to host. +## 8 +Weird server reply. The server sent data curl could not parse. +## 9 +FTP access denied. The server denied login or denied access to the particular +resource or directory you wanted to reach. Most often you tried to change to a +directory that does not exist on the server. +## 10 +FTP accept failed. While waiting for the server to connect back when an active +FTP session is used, an error code was sent over the control connection or +similar. +## 11 +FTP weird PASS reply. curl could not parse the reply sent to the PASS request. +## 12 +During an active FTP session while waiting for the server to connect back to +curl, the timeout expired. +## 13 +FTP weird PASV reply, curl could not parse the reply sent to the PASV request. +## 14 +FTP weird 227 format. curl could not parse the 227-line the server sent. +## 15 +FTP cannot use host. Could not resolve the host IP we got in the 227-line. +## 16 +HTTP/2 error. A problem was detected in the HTTP2 framing layer. This is +somewhat generic and can be one out of several problems, see the error message +for details. +## 17 +FTP could not set binary. Could not change transfer method to binary. +## 18 +Partial file. Only a part of the file was transferred. +## 19 +FTP could not download/access the given file, the RETR (or similar) command +failed. +## 21 +FTP quote error. A quote command returned error from the server. +## 22 +HTTP page not retrieved. The requested URL was not found or returned another +error with the HTTP error code being 400 or above. This return code only +appears if --fail is used. +## 23 +Write error. curl could not write data to a local file system or similar. +## 25 +Failed starting the upload. For FTP, the server typically denied the STOR +command. +## 26 +Read error. Various reading problems. +## 27 +Out of memory. A memory allocation request failed. +## 28 +Operation timeout. The specified time-out period was reached according to the +conditions. +## 30 +FTP PORT failed. The PORT command failed. Not all FTP servers support the PORT +command, try doing a transfer using PASV instead. +## 31 +FTP could not use REST. The REST command failed. This command is used for +resumed FTP transfers. +## 33 +HTTP range error. The range "command" did not work. +## 34 +HTTP post error. Internal post-request generation error. +## 35 +SSL connect error. The SSL handshaking failed. +## 36 +Bad download resume. Could not continue an earlier aborted download. +## 37 +FILE could not read file. Failed to open the file. Permissions? +## 38 +LDAP cannot bind. LDAP bind operation failed. +## 39 +LDAP search failed. +## 41 +Function not found. A required LDAP function was not found. +## 42 +Aborted by callback. An application told curl to abort the operation. +## 43 +Internal error. A function was called with a bad parameter. +## 45 +Interface error. A specified outgoing interface could not be used. +## 47 +Too many redirects. When following redirects, curl hit the maximum amount. +## 48 +Unknown option specified to libcurl. This indicates that you passed a weird +option to curl that was passed on to libcurl and rejected. Read up in the +manual. +## 49 +Malformed telnet option. +## 52 +The server did not reply anything, which here is considered an error. +## 53 +SSL crypto engine not found. +## 54 +Cannot set SSL crypto engine as default. +## 55 +Failed sending network data. +## 56 +Failure in receiving network data. +## 58 +Problem with the local certificate. +## 59 +Could not use specified SSL cipher. +## 60 +Peer certificate cannot be authenticated with known CA certificates. +## 61 +Unrecognized transfer encoding. +## 63 +Maximum file size exceeded. +## 64 +Requested FTP SSL level failed. +## 65 +Sending the data requires a rewind that failed. +## 66 +Failed to initialize SSL Engine. +## 67 +The username, password, or similar was not accepted and curl failed to log in. +## 68 +File not found on TFTP server. +## 69 +Permission problem on TFTP server. +## 70 +Out of disk space on TFTP server. +## 71 +Illegal TFTP operation. +## 72 +Unknown TFTP transfer ID. +## 73 +File already exists (TFTP). +## 74 +No such user (TFTP). +## 77 +Problem reading the SSL CA cert (path? access rights?). +## 78 +The resource referenced in the URL does not exist. +## 79 +An unspecified error occurred during the SSH session. +## 80 +Failed to shut down the SSL connection. +## 82 +Could not load CRL file, missing or wrong format (added in 7.19.0). +## 83 +Issuer check failed (added in 7.19.0). +## 84 +The FTP PRET command failed. +## 85 +Mismatch of RTSP CSeq numbers. +## 86 +Mismatch of RTSP Session Identifiers. +## 87 +Unable to parse FTP file list. +## 88 +FTP chunk callback reported error. +## 89 +No connection available, the session is queued. +## 90 +SSL public key does not match pinned public key. +## 91 +Invalid SSL certificate status. +## 92 +Stream error in HTTP/2 framing layer. +## 93 +An API function was called from inside a callback. +## 94 +An authentication function returned an error. +## 95 +A problem was detected in the HTTP/3 layer. This is somewhat generic and can +be one out of several problems, see the error message for details. +## 96 +QUIC connection error. This error may be caused by an SSL library error. QUIC +is the protocol used for HTTP/3 transfers. +## 97 +Proxy handshake error. +## 98 +A client-side certificate is required to complete the TLS handshake. +## 99 +Poll or select returned fatal error. +## 100 +A value or data field grew larger than allowed. +## XX +More error codes might appear here in future releases. The existing ones are +meant to never change. diff --git a/third-party/curl/docs/cmdline-opts/_FILES.md b/third-party/curl/docs/cmdline-opts/_FILES.md new file mode 100644 index 0000000000..8c5d3faa7b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_FILES.md @@ -0,0 +1,6 @@ + + +# FILES +*~/.curlrc* + +Default config file, see --config for details. diff --git a/third-party/curl/docs/cmdline-opts/_GLOBBING.md b/third-party/curl/docs/cmdline-opts/_GLOBBING.md new file mode 100644 index 0000000000..b801adb4d1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_GLOBBING.md @@ -0,0 +1,55 @@ + + +# GLOBBING +You can specify multiple URLs or parts of URLs by writing lists within braces +or ranges within brackets. We call this "globbing". + +Provide a list with three different names like this: + + https://fun.example/{one,two,three}.jpg + + sftp://{one,two,three}.example/README + +Do sequences of alphanumeric series by using [] as in: + + ftp://ftp.example.com/file[1-100].txt + +With leading zeroes: + + ftp://ftp.example.com/file[001-100].txt + +With letters through the alphabet: + + ftp://ftp.example.com/file[a-z].txt + +Nested sequences are not supported, but you can use several ones next to each +other: + + https://example.com/archive[1996-1999]/vol[1-4]/part{a,b,c}.html + +You can specify a step counter for the ranges to get every Nth number or +letter: + + https://example.com/file[1-100:10].txt + + https://example.com/file[a-z:2].txt + +When using [] or {} sequences when invoked from a command line prompt, you +probably have to put the full URL within double quotes to avoid the shell from +interfering with it. This also goes for other characters treated special, like +for example '&', '?' and '*'. + +The separate globbing components can be referenced in the --output option to +allow pieces to be reused in the target filename. + +Starting in curl 8.21.0, the separate globbing parts can be named and +referenced by their names. The case sensitive alphanumeric name is set +enclosed within angle brackets after the opening character. Examples: + + https://fun.example/{one,two,three}.jpg + + ftp://ftp.example.com/file[1-100].txt + +Setting the same glob name twice is an error. + +Switch off globbing with --globoff. diff --git a/third-party/curl/docs/cmdline-opts/_NAME.md b/third-party/curl/docs/cmdline-opts/_NAME.md new file mode 100644 index 0000000000..b0d8916144 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_NAME.md @@ -0,0 +1,4 @@ + + +# NAME +curl - transfer a URL diff --git a/third-party/curl/docs/cmdline-opts/_OPTIONS.md b/third-party/curl/docs/cmdline-opts/_OPTIONS.md new file mode 100644 index 0000000000..9155d857ec --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_OPTIONS.md @@ -0,0 +1,39 @@ + + +# OPTIONS + +Options start with one or two dashes. Many of the options require an +additional value next to them. If provided text does not start with a dash, it +is presumed to be and treated as a URL. + +The short "single-dash" form of the options, -d for example, may be used with +or without a space between it and its value, although a space is a recommended +separator. The long double-dash form, --data for example, requires a space +between it and its value. + +Short version options that do not need any additional values can be used +immediately next to each other, like for example you can specify all the +options *-O*, *-L* and *-v* at once as *-OLv*. + +In general, all boolean options are enabled with --**option** and yet again +disabled with --**no-**option. That is, you use the same option name but +prefix it with `no-`. In this list we mostly show the --**option** version of +them. + +When --next is used, it resets the parser state and you start again with a +clean option state, except for the options that are global. Global options +retain their values and meaning even after --next. + +If the long option name ends with an equals sign (`=`), the argument is the +text following on its right side. (Added in 8.16.0) + +The first argument that is exactly two dashes (`--`), marks the end of +options; any argument after the end of options is interpreted as a URL +argument even if it starts with a dash. + +curl does little to no verification of the contents of command line arguments. +Passing in "creative octets" like newlines might trigger unexpected results. + +The following options are global: `%GLOBALS`. + +# ALL OPTIONS diff --git a/third-party/curl/docs/cmdline-opts/_OUTPUT.md b/third-party/curl/docs/cmdline-opts/_OUTPUT.md new file mode 100644 index 0000000000..32a5457afc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_OUTPUT.md @@ -0,0 +1,11 @@ + + +# OUTPUT +If not told otherwise, curl writes the received data to stdout. It can be +instructed to instead save that data into a local file, using the --output or +--remote-name options. If curl is given multiple URLs to transfer on the +command line, it similarly needs multiple options for where to save them. + +curl does not parse or otherwise "understand" the content it gets or writes as +output. It does no encoding or decoding, unless explicitly asked to with +dedicated command line options. diff --git a/third-party/curl/docs/cmdline-opts/_PROGRESS.md b/third-party/curl/docs/cmdline-opts/_PROGRESS.md new file mode 100644 index 0000000000..a506d041dc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_PROGRESS.md @@ -0,0 +1,26 @@ + + +# PROGRESS METER + +curl normally displays a progress meter during operations, indicating the +amount of transferred data, transfer speeds and estimated time left, etc. The +progress meter displays the transfer rate in bytes per second. The used +suffixes (`k` for kilo, `M` for mega, `G` for giga, `T` for tera, `P` for peta +and `E` for exa) are 1024 based. For example 1k is 1024 bytes. 1M is 1048576 +bytes. Strictly speaking this makes the units kibibyte and mebibyte etc. + +curl displays this data to the terminal by default, so if you invoke curl to +do an operation and it is about to write data to the terminal, it *disables* +the progress meter as otherwise it would mess up the output mixing progress +meter and response data. + +If you want a progress meter for HTTP POST or PUT requests, you need to +redirect the response output to a file, using shell redirect (\>), --output or +similar. + +This does not apply to FTP upload as that operation does not spit out any +response data to the terminal. + +If you prefer a progress bar instead of the regular meter, --progress-bar is +your friend. You can also disable the progress meter completely with the +--silent option. diff --git a/third-party/curl/docs/cmdline-opts/_PROTOCOLS.md b/third-party/curl/docs/cmdline-opts/_PROTOCOLS.md new file mode 100644 index 0000000000..6b1918a9b2 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_PROTOCOLS.md @@ -0,0 +1,50 @@ + + +# PROTOCOLS +curl supports numerous protocols, or put in URL terms: schemes. Your +particular build may not support them all. +## DICT +Lets you lookup words using online dictionaries. +## FILE +Read or write local files. curl does not support accessing `file://` URL +remotely, but when running on Microsoft Windows using the native UNC approach +works. Only absolute paths. +## FTP(S) +curl supports the File Transfer Protocol with a lot of tweaks and levers. With +or without using TLS. +## GOPHER(S) +Retrieve files. +## HTTP(S) +curl supports HTTP with numerous options and variations. It can speak HTTP +version 0.9, 1.0, 1.1, 2 and 3 depending on build options and the correct +command line options. +## IMAP(S) +Using the mail reading protocol, curl can download emails for you. With or +without using TLS. +## LDAP(S) +curl can do directory lookups for you, with or without TLS. +## MQTT +curl supports MQTT version 3. Downloading over MQTT equals subscribing to a +topic while uploading/posting equals publishing on a topic. MQTT over TLS is not +supported (yet). +## POP3(S) +Downloading from a pop3 server means getting an email. With or without using +TLS. +## RTSP +curl supports RTSP 1.0 downloads. +## SCP +curl supports SSH version 2 scp transfers. +## SFTP +curl supports SFTP (draft 5) done over SSH version 2. +## SMB(S) +curl supports SMB version 1 for upload and download. +## SMTP(S) +Uploading contents to an SMTP server means sending an email. With or without +TLS. +## TELNET +Fetching a telnet URL starts an interactive session where it sends what it +reads on stdin and outputs what the server sends it. +## TFTP +curl can do TFTP downloads and uploads. +## WS(S) +WebSocket done over HTTP/1. WSS implies that it works over HTTPS. diff --git a/third-party/curl/docs/cmdline-opts/_PROXYPREFIX.md b/third-party/curl/docs/cmdline-opts/_PROXYPREFIX.md new file mode 100644 index 0000000000..0c106306d8 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_PROXYPREFIX.md @@ -0,0 +1,22 @@ + + +# PROXY PROTOCOL PREFIXES +The proxy string may be specified with a `protocol://` prefix to specify +alternative proxy protocols. (Added in 7.21.7) + +If no protocol is specified in the proxy string or if the string does not +match a supported one, the proxy is treated as an HTTP proxy. + +The supported proxy protocol prefixes are as follows: +## `http://` +Makes it use it as an HTTP proxy. The default if no scheme prefix is used. +## `https://` +Makes it treated as an **HTTPS** proxy. +## `socks4://` +Makes it the equivalent of --socks4 +## `socks4a://` +Makes it the equivalent of --socks4a +## `socks5://` +Makes it the equivalent of --socks5 +## `socks5h://` +Makes it the equivalent of --socks5-hostname diff --git a/third-party/curl/docs/cmdline-opts/_SEEALSO.md b/third-party/curl/docs/cmdline-opts/_SEEALSO.md new file mode 100644 index 0000000000..aa1b25984b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_SEEALSO.md @@ -0,0 +1,5 @@ + + +# SEE ALSO + +**ftp(1)**, **wget(1)** diff --git a/third-party/curl/docs/cmdline-opts/_SYNOPSIS.md b/third-party/curl/docs/cmdline-opts/_SYNOPSIS.md new file mode 100644 index 0000000000..3815877448 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_SYNOPSIS.md @@ -0,0 +1,5 @@ + + +# SYNOPSIS + +**curl [options / URLs]** diff --git a/third-party/curl/docs/cmdline-opts/_URL.md b/third-party/curl/docs/cmdline-opts/_URL.md new file mode 100644 index 0000000000..700e711359 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_URL.md @@ -0,0 +1,24 @@ + + +# URL +The URL syntax is protocol-dependent. You can find a detailed description in +RFC 3986. + +If you provide a URL without a leading `protocol://` scheme, curl guesses +what protocol you want. It then defaults to HTTP but assumes others based on +often-used hostname prefixes. For example, for hostnames starting with `ftp.` +curl assumes you want FTP. + +You can specify any amount of URLs on the command line. They are fetched in a +sequential manner in the specified order unless you use --parallel. You can +specify command line options and URLs mixed and in any order on the command +line. + +curl attempts to reuse connections when doing multiple transfers, so that +getting many files from the same server do not use multiple connects and setup +handshakes. This improves speed. Connection reuse can only be done for URLs +specified for a single command line invocation and cannot be performed between +separate curl runs. + +Everything provided on the command line that is not a command line option or +its argument, curl assumes is a URL and treats it as such. diff --git a/third-party/curl/docs/cmdline-opts/_VARIABLES.md b/third-party/curl/docs/cmdline-opts/_VARIABLES.md new file mode 100644 index 0000000000..834fc5ef28 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_VARIABLES.md @@ -0,0 +1,43 @@ + + +# VARIABLES +curl supports command line variables (added in 8.3.0). Set variables with +--variable name=content or --variable name@file (where `file` can be stdin if +set to a single dash (-)). + +Variable contents can be expanded in option parameters using `{{name}}` if the +option name is prefixed with `--expand-`. This gets the contents of the +variable `name` inserted, or a blank if the name does not exist as a +variable. Insert `{{` verbatim in the string by prefixing it with a backslash, +like `\{{`. + +You can access and expand environment variables by importing them with +`--variable %name`. This imports the variable called `name` but exits with an +error if that environment variable is not already set. To provide a default +value in case it is not already set, use `--variable %name=content` or +`--variable %name@content`. + +Example: get the USER environment variable and expand into the URL, fail if +USER is not set: + + --variable '%USER' + --expand-url = "https://example.com/api/{{USER}}/method" + +When expanding variables, curl supports a set of functions that can make the +variable contents more convenient to use. It can trim leading and trailing +white space with `trim`, output the contents as a JSON quoted string with +`json`, URL encode the string with `url`, base64 encode it with `b64` and +base64 decode it with `64dec`. To apply functions to a variable expansion, add +them colon separated to the right side of the variable. Variable content +holding null bytes that are not encoded when expanded causes an error. + +Example: get the contents of a file called $HOME/.secret into a variable +called "fix". Make sure that the content is trimmed and percent-encoded when +sent as POST data: + + --variable %HOME + --expand-variable fix@{{HOME}}/.secret + --expand-data "{{fix:trim:url}}" + https://example.com/ + +Command line variables and expansions were added in 8.3.0. diff --git a/third-party/curl/docs/cmdline-opts/_VERSION.md b/third-party/curl/docs/cmdline-opts/_VERSION.md new file mode 100644 index 0000000000..e0228fe9cd --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_VERSION.md @@ -0,0 +1,15 @@ + + +# VERSION + +This man page describes curl `%VERSION`. If you use a later version, chances +are this man page does not fully document it. If you use an earlier version, +this document tries to include version information about which specific +version that introduced changes. + +You can always learn which the latest curl version is by running + + curl https://curl.se/info + +The online version of this man page is always showing the latest incarnation: +https://curl.se/docs/manpage.html diff --git a/third-party/curl/docs/cmdline-opts/_WWW.md b/third-party/curl/docs/cmdline-opts/_WWW.md new file mode 100644 index 0000000000..8656e9ee8c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/_WWW.md @@ -0,0 +1,4 @@ + + +# WWW +https://curl.se/ diff --git a/third-party/curl/docs/cmdline-opts/abstract-unix-socket.d b/third-party/curl/docs/cmdline-opts/abstract-unix-socket.d deleted file mode 100644 index 5c2fd4a476..0000000000 --- a/third-party/curl/docs/cmdline-opts/abstract-unix-socket.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: abstract-unix-socket -Arg: -Help: Connect via abstract Unix domain socket -Added: 7.53.0 -Protocols: HTTP -Category: connection -See-also: unix-socket -Example: --abstract-unix-socket socketpath $URL -Multi: single ---- -Connect through an abstract Unix domain socket, instead of using the network. -Note: netstat shows the path of an abstract socket prefixed with '@', however -the argument should not have this leading character. diff --git a/third-party/curl/docs/cmdline-opts/abstract-unix-socket.md b/third-party/curl/docs/cmdline-opts/abstract-unix-socket.md new file mode 100644 index 0000000000..b1b6100e16 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/abstract-unix-socket.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: abstract-unix-socket +Arg: +Help: Connect via abstract Unix domain socket +Added: 7.53.0 +Protocols: HTTP +Category: connection +Multi: single +See-also: + - unix-socket +Example: + - --abstract-unix-socket socketpath $URL +--- + +# `--abstract-unix-socket` + +Connect to the server through an abstract Unix domain socket, instead of using +the network. Note: netstat shows the path of an abstract socket prefixed with +`@`, however the \ argument should not have this leading character. diff --git a/third-party/curl/docs/cmdline-opts/alt-svc.d b/third-party/curl/docs/cmdline-opts/alt-svc.d deleted file mode 100644 index 276ac1b669..0000000000 --- a/third-party/curl/docs/cmdline-opts/alt-svc.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: alt-svc -Arg: -Protocols: HTTPS -Help: Enable alt-svc with this cache file -Added: 7.64.1 -Category: http -See-also: resolve connect-to -Example: --alt-svc svc.txt $URL -Multi: append ---- -This option enables the alt-svc parser in curl. If the file name points to an -existing alt-svc cache file, that gets used. After a completed transfer, the -cache is saved to the file name again if it has been modified. - -Specify a "" file name (zero length) to avoid loading/saving and make curl -just handle the cache in memory. - -If this option is used several times, curl loads contents from all the -files but the last one is used for saving. diff --git a/third-party/curl/docs/cmdline-opts/alt-svc.md b/third-party/curl/docs/cmdline-opts/alt-svc.md new file mode 100644 index 0000000000..fe2e8736fa --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/alt-svc.md @@ -0,0 +1,31 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: alt-svc +Arg: +Protocols: HTTPS +Help: Enable alt-svc with this cache file +Added: 7.64.1 +Category: http +Multi: append +See-also: + - resolve + - connect-to +Example: + - --alt-svc svc.txt $URL +--- + +# `--alt-svc` + +Enable the alt-svc parser. If the filename points to an existing alt-svc cache +file, that gets used. After a completed transfer, the cache is saved to the +filename again if it has been modified. + +Specify a "" filename (zero length) to avoid loading/saving and make curl +handle the cache in memory. + +You may want to restrict your umask to prevent other users on the same system +to access the created file. + +If this option is used several times, curl loads contents from all the +files but the last one is used for saving. diff --git a/third-party/curl/docs/cmdline-opts/anyauth.d b/third-party/curl/docs/cmdline-opts/anyauth.d deleted file mode 100644 index 2498bdcd84..0000000000 --- a/third-party/curl/docs/cmdline-opts/anyauth.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: anyauth -Help: Pick any authentication method -Protocols: HTTP -See-also: proxy-anyauth basic digest -Category: http proxy auth -Example: --anyauth --user me:pwd $URL -Added: 7.10.6 -Multi: mutex ---- -Tells curl to figure out authentication method by itself, and use the most -secure one the remote site claims to support. This is done by first doing a -request and checking the response-headers, thus possibly inducing an extra -network round-trip. This is used instead of setting a specific authentication -method, which you can do with --basic, --digest, --ntlm, and --negotiate. - -Using --anyauth is not recommended if you do uploads from stdin, since it may -require data to be sent twice and then the client must be able to rewind. If -the need should arise when uploading from stdin, the upload operation fails. - -Used together with --user. diff --git a/third-party/curl/docs/cmdline-opts/anyauth.md b/third-party/curl/docs/cmdline-opts/anyauth.md new file mode 100644 index 0000000000..2afde38224 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/anyauth.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: anyauth +Help: Pick any authentication method +Protocols: HTTP +Category: http proxy auth +Added: 7.10.6 +Multi: custom +See-also: + - proxy-anyauth + - basic + - digest +Example: + - --anyauth --user me:pwd $URL +--- + +# `--anyauth` + +Figure out authentication method automatically, and use the most secure one +the remote site claims to support. This is done by first doing a request and +checking the response-headers, thus possibly inducing an extra network +round-trip. This option is used instead of setting a specific authentication +method, which you can do with --basic, --digest, --ntlm, and --negotiate. + +Using --anyauth is not recommended if you do uploads from stdin, since it may +require data to be sent twice and then the client must be able to rewind. If +the need should arise when uploading from stdin, the upload operation fails. + +Used together with --user. diff --git a/third-party/curl/docs/cmdline-opts/append.d b/third-party/curl/docs/cmdline-opts/append.d deleted file mode 100644 index 7561c951c5..0000000000 --- a/third-party/curl/docs/cmdline-opts/append.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: a -Long: append -Help: Append to target file when uploading -Protocols: FTP SFTP -Category: ftp sftp -See-also: range continue-at -Example: --upload-file local --append ftp://example.com/ -Added: 4.8 -Multi: boolean ---- -When used in an upload, this option makes curl append to the target file -instead of overwriting it. If the remote file does not exist, it is -created. Note that this flag is ignored by some SFTP servers (including -OpenSSH). diff --git a/third-party/curl/docs/cmdline-opts/append.md b/third-party/curl/docs/cmdline-opts/append.md new file mode 100644 index 0000000000..3d0030d6a7 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/append.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: a +Long: append +Help: Append to target file when uploading +Protocols: FTP SFTP +Category: ftp sftp +Added: 4.8 +Multi: boolean +See-also: + - range + - continue-at +Example: + - --upload-file local --append ftp://example.com/ +--- + +# `--append` + +When used in an upload, this option makes curl append to the target file +instead of overwriting it. If the remote file does not exist, it is +created. Note that this flag is ignored by some SFTP servers (including +OpenSSH). diff --git a/third-party/curl/docs/cmdline-opts/aws-sigv4.d b/third-party/curl/docs/cmdline-opts/aws-sigv4.d deleted file mode 100644 index b771eee6a9..0000000000 --- a/third-party/curl/docs/cmdline-opts/aws-sigv4.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: aws-sigv4 -Arg: -Help: Use AWS V4 signature authentication -Category: auth http -Added: 7.75.0 -See-also: basic user -Example: --aws-sigv4 "aws:amz:us-east-2:es" --user "key:secret" $URL -Multi: single ---- -Use AWS V4 signature authentication in the transfer. - -The provider argument is a string that is used by the algorithm when creating -outgoing authentication headers. - -The region argument is a string that points to a geographic area of -a resources collection (region-code) when the region name is omitted from -the endpoint. - -The service argument is a string that points to a function provided by a cloud -(service-code) when the service name is omitted from the endpoint. diff --git a/third-party/curl/docs/cmdline-opts/aws-sigv4.md b/third-party/curl/docs/cmdline-opts/aws-sigv4.md new file mode 100644 index 0000000000..517cc1c5b0 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/aws-sigv4.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: aws-sigv4 +Protocols: HTTP +Arg: +Help: AWS V4 signature auth +Category: auth http +Added: 7.75.0 +Multi: single +See-also: + - basic + - user +Example: + - --aws-sigv4 "aws:amz:us-east-2:es" --user "key:secret" $URL +--- + +# `--aws-sigv4` + +Use AWS V4 signature authentication in the transfer. + +The provider argument is a string that is used by the algorithm when creating +outgoing authentication headers. + +The region argument is a string that points to a geographic area of +a resources collection (region-code) when the region name is omitted from +the endpoint. + +The service argument is a string that points to a function provided by a cloud +(service-code) when the service name is omitted from the endpoint. diff --git a/third-party/curl/docs/cmdline-opts/basic.d b/third-party/curl/docs/cmdline-opts/basic.d deleted file mode 100644 index cb0642620e..0000000000 --- a/third-party/curl/docs/cmdline-opts/basic.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: basic -Help: Use HTTP Basic Authentication -See-also: proxy-basic -Protocols: HTTP -Category: auth -Example: -u name:password --basic $URL -Added: 7.10.6 -Multi: mutex ---- -Tells curl to use HTTP Basic authentication with the remote host. This is the -default and this option is usually pointless, unless you use it to override a -previously set option that sets a different authentication method (such as ---ntlm, --digest, or --negotiate). - -Used together with --user. diff --git a/third-party/curl/docs/cmdline-opts/basic.md b/third-party/curl/docs/cmdline-opts/basic.md new file mode 100644 index 0000000000..1c372fbc71 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/basic.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: basic +Help: HTTP Basic Authentication +Protocols: HTTP +Category: auth +Added: 7.10.6 +Multi: boolean +See-also: + - proxy-basic +Example: + - -u name:password --basic $URL +--- + +# `--basic` + +Use HTTP Basic authentication with the remote host. This method is the default +and this option is usually pointless, unless you use it to override a +previously set option that sets a different authentication method (such as +--ntlm, --digest, or --negotiate). + +Used together with --user. diff --git a/third-party/curl/docs/cmdline-opts/ca-native.d b/third-party/curl/docs/cmdline-opts/ca-native.d deleted file mode 100644 index 51e36918aa..0000000000 --- a/third-party/curl/docs/cmdline-opts/ca-native.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ca-native -Help: Use CA certificates from the native OS -Protocols: TLS -Category: tls -See-also: cacert capath insecure -Example: --ca-native $URL -Added: 8.2.0 -Multi: boolean ---- -Tells curl to use the CA store from the native operating system to verify the -peer. By default, curl otherwise uses a CA store provided in a single file or -directory, but when using this option it interfaces the operating system's -own vault. - -This option only works for curl on Windows when built to use OpenSSL. When -curl on Windows is built to use Schannel, this feature is implied and curl -then only uses the native CA store. - -curl built with wolfSSL also supports this option (added in 8.3.0). diff --git a/third-party/curl/docs/cmdline-opts/ca-native.md b/third-party/curl/docs/cmdline-opts/ca-native.md new file mode 100644 index 0000000000..67fdf8c3ac --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ca-native.md @@ -0,0 +1,44 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ca-native +Help: Load CA certs from the OS +Protocols: TLS +Category: tls +Added: 8.2.0 +Multi: boolean +See-also: + - cacert + - capath + - dump-ca-embed + - insecure + - proxy-ca-native +Example: + - --ca-native $URL +--- + +# `--ca-native` + +Use the operating system's native CA store for certificate verification. + +This option is independent of other CA certificate locations set at run time or +build time. Those locations are searched in addition to the native CA store. + +This option works with OpenSSL and its forks (BoringSSL, LibreSSL, etc) on +Windows (Added in 7.71.0) and on Apple OS when libcurl is built with +Apple SecTrust enabled. (Added in 8.17.0) + +This option works with wolfSSL on Windows, Linux (Debian, Ubuntu, Gentoo, +Fedora, RHEL), macOS, Android and iOS. (Added in 8.3.0) + +This option works with GnuTLS (Added in 8.5.0) and also uses Apple +SecTrust when libcurl is built with it. (Added in 8.17.0) + +This option works with Rustls on Windows, macOS, Android and iOS. On Linux it +is equivalent to using the Mozilla CA certificate bundle. When used with Rustls +_only_ the native CA store is consulted, not other locations set at run time or +build time. (Added in 8.13.0) + +This option currently has no effect for Schannel. This is the native TLS +library from Microsoft, that by default uses the native CA store for +verification unless overridden by a CA certificate location setting. diff --git a/third-party/curl/docs/cmdline-opts/cacert.d b/third-party/curl/docs/cmdline-opts/cacert.d deleted file mode 100644 index 5e4e74901e..0000000000 --- a/third-party/curl/docs/cmdline-opts/cacert.d +++ /dev/null @@ -1,35 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: cacert -Arg: -Help: CA certificate to verify peer against -Protocols: TLS -Category: tls -See-also: capath insecure -Example: --cacert CA-file.txt $URL -Added: 7.5 -Multi: single ---- -Tells curl to use the specified certificate file to verify the peer. The file -may contain multiple CA certificates. The certificate(s) must be in PEM -format. Normally curl is built to use a default file for this, so this option -is typically used to alter that default file. - -curl recognizes the environment variable named 'CURL_CA_BUNDLE' if it is -set, and uses the given path as a path to a CA cert bundle. This option -overrides that variable. - -The windows version of curl automatically looks for a CA certs file named -'curl-ca-bundle.crt', either in the same directory as curl.exe, or in the -Current Working Directory, or in any folder along your PATH. - -(iOS and macOS only) If curl is built against Secure Transport, then this -option is supported for backward compatibility with other SSL engines, but it -should not be set. If the option is not set, then curl uses the certificates -in the system and user Keychain to verify the peer, which is the preferred -method of verifying the peer's certificate chain. - -(Schannel only) This option is supported for Schannel in Windows 7 or later -(added in 7.60.0). This option is supported for backward compatibility with -other SSL engines; instead it is recommended to use Windows' store of root -certificates (the default for Schannel). diff --git a/third-party/curl/docs/cmdline-opts/cacert.md b/third-party/curl/docs/cmdline-opts/cacert.md new file mode 100644 index 0000000000..ae9be3824b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/cacert.md @@ -0,0 +1,40 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: cacert +Arg: +Help: CA certificate to verify peer against +Protocols: TLS +Category: tls +Added: 7.5 +Multi: single +See-also: + - capath + - dump-ca-embed + - insecure +Example: + - --cacert CA-file.txt $URL +--- + +# `--cacert` + +Use the specified certificate file to verify the peer. The file may contain +multiple CA certificates. The certificate(s) must be in PEM format. Normally +curl is built to use a default file for this, so this option is typically used +to alter that default file. + +curl recognizes the environment variable named 'CURL_CA_BUNDLE' if it is set +and the TLS backend is not Schannel, and uses the given path as a path to a CA +cert bundle. This option overrides that variable. + +(Windows) curl automatically looks for a CA certs file named +'curl-ca-bundle.crt', either in the same directory as curl.exe, or in the +Current Working Directory, or in any folder along your PATH. + +curl 8.11.0 added a build-time option to disable this search behavior, and +another option to restrict search to the application's directory. + +(Schannel) This option is supported for Schannel in Windows 7 or later (added +in 7.60.0). This option is supported for backward compatibility with other SSL +engines; instead it is recommended to use Windows' store of root certificates +(the default for Schannel). diff --git a/third-party/curl/docs/cmdline-opts/capath.d b/third-party/curl/docs/cmdline-opts/capath.d deleted file mode 100644 index 75e9f2e400..0000000000 --- a/third-party/curl/docs/cmdline-opts/capath.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: capath -Arg: -Help: CA directory to verify peer against -Protocols: TLS -Category: tls -See-also: cacert insecure -Example: --capath /local/directory $URL -Added: 7.9.8 -Multi: single ---- -Tells curl to use the specified certificate directory to verify the -peer. Multiple paths can be provided by separating them with ":" (e.g. -"path1:path2:path3"). The certificates must be in PEM format, and if curl is -built against OpenSSL, the directory must have been processed using the -c_rehash utility supplied with OpenSSL. Using --capath can allow -OpenSSL-powered curl to make SSL-connections much more efficiently than using ---cacert if the --cacert file contains many CA certificates. - -If this option is set, the default capath value is ignored. diff --git a/third-party/curl/docs/cmdline-opts/capath.md b/third-party/curl/docs/cmdline-opts/capath.md new file mode 100644 index 0000000000..68bc86fbbc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/capath.md @@ -0,0 +1,31 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: capath +Arg: +Help: CA directory to verify peer against +Protocols: TLS +Category: tls +Added: 7.9.8 +Multi: single +See-also: + - cacert + - dump-ca-embed + - insecure +Example: + - --capath /local/directory $URL +--- + +# `--capath` + +Use the specified certificate directory to verify the peer. If curl is built against +OpenSSL, multiple paths can be provided by separating them with the appropriate platform-specific +separator (e.g. `path1:path2:path3` on Unix-style platforms for `path1;path2;path3` on Windows). + +The certificates must be in PEM format, and if curl is built against OpenSSL, the +directory must have been processed using the c_rehash utility supplied with +OpenSSL. Using --capath can allow OpenSSL-powered curl to make SSL-connections +much more efficiently than using --cacert if the --cacert file contains many +CA certificates. + +If this option is set, the default capath value is ignored. diff --git a/third-party/curl/docs/cmdline-opts/cert-status.d b/third-party/curl/docs/cmdline-opts/cert-status.d deleted file mode 100644 index e2d1d7aa24..0000000000 --- a/third-party/curl/docs/cmdline-opts/cert-status.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: cert-status -Protocols: TLS -Added: 7.41.0 -Help: Verify the status of the server cert via OCSP-staple -Category: tls -See-also: pinnedpubkey -Example: --cert-status $URL -Multi: boolean ---- -Tells curl to verify the status of the server certificate by using the -Certificate Status Request (aka. OCSP stapling) TLS extension. - -If this option is enabled and the server sends an invalid (e.g. expired) -response, if the response suggests that the server certificate has been -revoked, or no response at all is received, the verification fails. - -This is currently only implemented in the OpenSSL and GnuTLS backends. diff --git a/third-party/curl/docs/cmdline-opts/cert-status.md b/third-party/curl/docs/cmdline-opts/cert-status.md new file mode 100644 index 0000000000..8b6e57b9ed --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/cert-status.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: cert-status +Protocols: TLS +Added: 7.41.0 +Help: Verify server cert status OCSP-staple +Category: tls +Multi: boolean +See-also: + - pinnedpubkey +Example: + - --cert-status $URL +--- + +# `--cert-status` + +Verify the status of the server certificate by using the Certificate Status +Request (aka. OCSP stapling) TLS extension. + +If this option is enabled and the server sends an invalid (e.g. expired) +response, if the response suggests that the server certificate has been +revoked, or no response at all is received, the verification fails. + +This support is currently only implemented in the OpenSSL and GnuTLS backends. diff --git a/third-party/curl/docs/cmdline-opts/cert-type.d b/third-party/curl/docs/cmdline-opts/cert-type.d deleted file mode 100644 index cf9f17b7d5..0000000000 --- a/third-party/curl/docs/cmdline-opts/cert-type.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: cert-type -Protocols: TLS -Arg: -Help: Certificate type (DER/PEM/ENG/P12) -See-also: cert key key-type -Category: tls -Example: --cert-type PEM --cert file $URL -Added: 7.9.3 -Multi: single ---- -Tells curl what type the provided client certificate is using. PEM, DER, ENG -and P12 are recognized types. - -The default type depends on the TLS backend and is usually PEM, however for -Secure Transport and Schannel it is P12. If --cert is a pkcs11: URI then ENG is -the default type. diff --git a/third-party/curl/docs/cmdline-opts/cert-type.md b/third-party/curl/docs/cmdline-opts/cert-type.md new file mode 100644 index 0000000000..a96587ff63 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/cert-type.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: cert-type +Protocols: TLS +Arg: +Help: Certificate type (DER/PEM/ENG/PROV/P12) +Category: tls +Added: 7.9.3 +Multi: single +See-also: + - cert + - key + - key-type +Example: + - --cert-type PEM --cert file $URL +--- + +# `--cert-type` + +Set type of the provided client certificate. PEM, DER, ENG, PROV and P12 are +recognized types. + +The default type depends on the TLS backend and is usually PEM. For Schannel +it is P12. If --cert is a pkcs11: URI then ENG or PROV is the default type +(depending on OpenSSL version). diff --git a/third-party/curl/docs/cmdline-opts/cert.d b/third-party/curl/docs/cmdline-opts/cert.d deleted file mode 100644 index 56d0df7fdf..0000000000 --- a/third-party/curl/docs/cmdline-opts/cert.d +++ /dev/null @@ -1,49 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: E -Long: cert -Arg: -Help: Client certificate file and password -Protocols: TLS -See-also: cert-type key key-type -Category: tls -Example: --cert certfile --key keyfile $URL -Added: 5.0 -Multi: single ---- -Tells curl to use the specified client certificate file when getting a file -with HTTPS, FTPS or another SSL-based protocol. The certificate must be in -PKCS#12 format if using Secure Transport, or PEM format if using any other -engine. If the optional password is not specified, it is queried for on -the terminal. Note that this option assumes a certificate file that is the -private key and the client certificate concatenated. See --cert and --key to -specify them independently. - -In the portion of the argument, you must escape the character ":" -as "\\:" so that it is not recognized as the password delimiter. Similarly, you -must escape the character "\\" as "\\\\" so that it is not recognized as an -escape character. - -If curl is built against OpenSSL library, and the engine pkcs11 is available, -then a PKCS#11 URI (RFC 7512) can be used to specify a certificate located in -a PKCS#11 device. A string beginning with "pkcs11:" is interpreted as a -PKCS#11 URI. If a PKCS#11 URI is provided, then the --engine option is set as -"pkcs11" if none was provided and the --cert-type option is set as "ENG" if -none was provided. - -(iOS and macOS only) If curl is built against Secure Transport, then the -certificate string can either be the name of a certificate/private key in the -system or user keychain, or the path to a PKCS#12-encoded certificate and -private key. If you want to use a file from the current directory, please -precede it with "./" prefix, in order to avoid confusion with a nickname. - -(Schannel only) Client certificates must be specified by a path -expression to a certificate store. (Loading *PFX* is not supported; you can -import it to a store first). You can use -"\\\\" to refer to a certificate -in the system certificates store, for example, -*"CurrentUser\\MY\\934a7ac6f8a5d579285a74fa61e19f23ddfe8d7a"*. Thumbprint is -usually a SHA-1 hex string which you can see in certificate details. Following -store locations are supported: *CurrentUser*, *LocalMachine*, *CurrentService*, -*Services*, *CurrentUserGroupPolicy*, *LocalMachineGroupPolicy* and -*LocalMachineEnterprise*. diff --git a/third-party/curl/docs/cmdline-opts/cert.md b/third-party/curl/docs/cmdline-opts/cert.md new file mode 100644 index 0000000000..2bc3d8fa29 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/cert.md @@ -0,0 +1,53 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: E +Long: cert +Arg: +Help: Client certificate file and password +Protocols: TLS +Category: tls +Added: 5.0 +Multi: single +See-also: + - cert-type + - key + - key-type +Example: + - --cert certfile --key keyfile $URL +--- + +# `--cert` + +Use the specified client certificate file when getting a file with HTTPS, FTPS +or another SSL-based protocol. The certificate must be PEM format. If the +optional password is not specified, it is queried for on the terminal. Note +that this option assumes a certificate file that is the private key and the +client certificate concatenated. See --cert and --key to specify them +independently. + +In the \ portion of the argument, you must escape the character +`:` as `\:` so that it is not recognized as the password delimiter. Similarly, +you must escape the double quote character as \" so that it is not recognized +as an escape character. + +If curl is built against OpenSSL, and the engine pkcs11 or pkcs11 +provider is available, then a PKCS#11 URI (RFC 7512) can be used to specify a +certificate located in a PKCS#11 device. A string beginning with `pkcs11:` is +interpreted as a PKCS#11 URI. If a PKCS#11 URI is provided, then the --engine +option is set as `pkcs11` if none was provided and the --cert-type option is +set as `ENG` or `PROV` if none was provided (depending on OpenSSL version). + +If curl is built against GnuTLS, a PKCS#11 URI can be used to specify +a certificate located in a PKCS#11 device. A string beginning with `pkcs11:` +is interpreted as a PKCS#11 URI. + +(Schannel) Client certificates must be specified by a path expression to a +certificate store. (Loading *PFX* is not supported; you can import it to a +store first). You can use "\\\\\" +to refer to a certificate in the system certificates store, for example, +*"CurrentUser\MY\934a7ac6f8a5d579285a74fa61e19f23ddfe8d7a"*. Thumbprint is +usually a SHA-1 hex string which you can see in certificate details. Following +store locations are supported: *CurrentUser*, *LocalMachine*, +*CurrentService*, *Services*, *CurrentUserGroupPolicy*, +*LocalMachineGroupPolicy* and *LocalMachineEnterprise*. diff --git a/third-party/curl/docs/cmdline-opts/ciphers.d b/third-party/curl/docs/cmdline-opts/ciphers.d deleted file mode 100644 index a30902bdb8..0000000000 --- a/third-party/curl/docs/cmdline-opts/ciphers.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ciphers -Arg: -Help: SSL ciphers to use -Protocols: TLS -Category: tls -See-also: tlsv1.3 tls13-ciphers proxy-ciphers -Example: --ciphers ECDHE-ECDSA-AES256-CCM8 $URL -Added: 7.9 -Multi: single ---- -Specifies which ciphers to use in the connection. The list of ciphers must -specify valid ciphers. Read up on SSL cipher list details on this URL: - -https://curl.se/docs/ssl-ciphers.html diff --git a/third-party/curl/docs/cmdline-opts/ciphers.md b/third-party/curl/docs/cmdline-opts/ciphers.md new file mode 100644 index 0000000000..14f0425dbf --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ciphers.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ciphers +Arg: +Help: TLS 1.2 (1.1, 1.0) ciphers to use +Protocols: TLS +Category: tls +Added: 7.9 +Multi: single +See-also: + - tls13-ciphers + - proxy-ciphers + - curves +Example: + - --ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256 $URL +--- + +# `--ciphers` + +Specify which cipher suites to use in the connection if it negotiates TLS 1.2 +(1.1, 1.0). The list of ciphers suites must specify valid ciphers. Read up on +cipher suite details on this URL: + +https://curl.se/docs/ssl-ciphers.html diff --git a/third-party/curl/docs/cmdline-opts/compressed-ssh.d b/third-party/curl/docs/cmdline-opts/compressed-ssh.d deleted file mode 100644 index 897395677b..0000000000 --- a/third-party/curl/docs/cmdline-opts/compressed-ssh.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: compressed-ssh -Help: Enable SSH compression -Protocols: SCP SFTP -Added: 7.56.0 -Category: scp ssh -See-also: compressed -Example: --compressed-ssh sftp://example.com/ -Multi: boolean ---- -Enables built-in SSH compression. -This is a request, not an order; the server may or may not do it. diff --git a/third-party/curl/docs/cmdline-opts/compressed-ssh.md b/third-party/curl/docs/cmdline-opts/compressed-ssh.md new file mode 100644 index 0000000000..07d3981b48 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/compressed-ssh.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: compressed-ssh +Help: Enable SSH compression +Protocols: SCP SFTP +Added: 7.56.0 +Category: scp ssh +Multi: boolean +See-also: + - compressed +Example: + - --compressed-ssh sftp://example.com/ +--- + +# `--compressed-ssh` + +Enable SSH compression. This is a request, not an order; the server may or may +not do it. This allows the data to be sent compressed over the wire, and +automatically decompressed in the receiving end, to save bandwidth. diff --git a/third-party/curl/docs/cmdline-opts/compressed.d b/third-party/curl/docs/cmdline-opts/compressed.d deleted file mode 100644 index bb1d3baa74..0000000000 --- a/third-party/curl/docs/cmdline-opts/compressed.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: compressed -Help: Request compressed response -Protocols: HTTP -Category: http -Example: --compressed $URL -See-also: compressed-ssh -Added: 7.10 -Multi: boolean ---- -Request a compressed response using one of the algorithms curl supports, and -automatically decompress the content. - -Response headers are not modified when saved, so if they are "interpreted" -separately again at a later point they might appear to be saying that the -content is (still) compressed; while in fact it has already been decompressed. - -If this option is used and the server sends an unsupported encoding, curl -reports an error. This is a request, not an order; the server may or may not -deliver data compressed. diff --git a/third-party/curl/docs/cmdline-opts/compressed.md b/third-party/curl/docs/cmdline-opts/compressed.md new file mode 100644 index 0000000000..712f93df19 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/compressed.md @@ -0,0 +1,32 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: compressed +Help: Request compressed response +Protocols: HTTP +Category: http +Added: 7.10 +Multi: boolean +See-also: + - compressed-ssh +Example: + - --compressed $URL +--- + +# `--compressed` + +Request a compressed response using one of the algorithms curl supports, and +automatically decompress the content. + +Response headers are not modified when saved, so if they are "interpreted" +separately again at a later point they might appear to be saying that the +content is (still) compressed; while in fact it has already been decompressed. + +If this option is used and the server sends an unsupported encoding, curl +reports an error. This is a request, not an order; the server may or may not +deliver data compressed. + +**WARNING**: when decompressing data, even tiny transfers might be expanded +and generate a huge amount of bytes. You might want to limit using this option +to only known and trusted sites using secure protocols, perhaps in combination +with --max-filesize. diff --git a/third-party/curl/docs/cmdline-opts/config.d b/third-party/curl/docs/cmdline-opts/config.d deleted file mode 100644 index c22a827f61..0000000000 --- a/third-party/curl/docs/cmdline-opts/config.d +++ /dev/null @@ -1,77 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: config -Arg: -Help: Read config from a file -Short: K -Category: curl -Example: --config file.txt $URL -Added: 4.10 -See-also: disable -Multi: append ---- -Specify a text file to read curl arguments from. The command line arguments -found in the text file are used as if they were provided on the command -line. - -Options and their parameters must be specified on the same line in the file, -separated by whitespace, colon, or the equals sign. Long option names can -optionally be given in the config file without the initial double dashes and -if so, the colon or equals characters can be used as separators. If the option -is specified with one or two dashes, there can be no colon or equals character -between the option and its parameter. - -If the parameter contains whitespace or starts with a colon (:) or equals sign -(=), it must be specified enclosed within double quotes (\&"). Within double -quotes the following escape sequences are available: \\\\, \\", \\t, \\n, \\r -and \\v. A backslash preceding any other letter is ignored. - -If the first non-blank column of a config line is a '#' character, that line -is treated as a comment. - -Only write one option per physical line in the config file. A single line is -required to be no more than 10 megabytes (since 8.2.0). - -Specify the filename to --config as '-' to make curl read the file from stdin. - -Note that to be able to specify a URL in the config file, you need to specify -it using the --url option, and not by simply writing the URL on its own -line. So, it could look similar to this: - -url = "https://curl.se/docs/" - - # --- Example file --- - # this is a comment - url = "example.com" - output = "curlhere.html" - user-agent = "superagent/1.0" - - # and fetch another URL too - url = "example.com/docs/manpage.html" - -O - referer = "http://nowhereatall.example.com/" - # --- End of example file --- - -When curl is invoked, it (unless --disable is used) checks for a default -config file and uses it if found, even when --config is used. The default -config file is checked for in the following places in this order: - -1) **"$CURL_HOME/.curlrc"** - -2) **"$XDG_CONFIG_HOME/curlrc"** (Added in 7.73.0) - -3) **"$HOME/.curlrc"** - -4) Windows: **"%USERPROFILE%\\.curlrc"** - -5) Windows: **"%APPDATA%\\.curlrc"** - -6) Windows: **"%USERPROFILE%\\Application Data\\.curlrc"** - -7) Non-Windows: use getpwuid to find the home directory - -8) On Windows, if it finds no *.curlrc* file in the sequence described above, it -checks for one in the same dir the curl executable is placed. - -On Windows two filenames are checked per location: *.curlrc* and *_curlrc*, -preferring the former. Older versions on Windows checked for *_curlrc* only. diff --git a/third-party/curl/docs/cmdline-opts/config.md b/third-party/curl/docs/cmdline-opts/config.md new file mode 100644 index 0000000000..637918df75 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/config.md @@ -0,0 +1,84 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: config +Arg: +Help: Read config from a file +Short: K +Category: curl +Added: 4.10 +Multi: append +See-also: + - disable +Example: + - --config file.txt $URL +--- + +# `--config` + +Specify a text file to read curl arguments from. The command line arguments +found in the text file are used as if they were provided on the command +line. + +Options and their parameters must be specified on the same line in the file, +separated by whitespace, colon, or the equals sign. Long option names can +optionally be given in the config file without the initial double dashes and +if so, the colon or equals characters can be used as separators. If the option +is specified with one or two dashes, there can be no colon or equals character +between the option and its parameter. + +If the parameter contains whitespace or starts with a colon (:) or equals sign +(=), it must be specified enclosed within double quotes ("like this"). Within +double quotes the following escape sequences are available: \\, \", \t, \n, \r +and \v. A backslash preceding any other letter is ignored. + +If the first non-blank column of a config line is a '#' character, that line +is treated as a comment. + +Only write one option per physical line in the config file. A single line is +required to be no more than 10 megabytes (since 8.2.0). + +Specify the filename to --config as minus "-" to make curl read the file from +stdin. + +Note that to be able to specify a URL in the config file, you need to specify +it using the --url option, and not by writing the URL on its own line. +It could look similar to this: + + url = "https://curl.se/docs/" + + # --- Example file --- + # this is a comment + url = "example.com" + output = "curlhere.html" + user-agent = "superagent/1.0" + + # and fetch another URL too + url = "example.com/docs/manpage.html" + -O + referer = "http://nowhereatall.example.com/" + # --- End of example file --- + +When curl is invoked, it (unless --disable is used) checks for a default +config file and uses it if found, even when --config is used. The default +config file is checked for in the following places in this order: + +1) **"$CURL_HOME/.curlrc"** + +2) **"$XDG_CONFIG_HOME/curlrc"** (Added in 7.73.0) + +3) **"$HOME/.curlrc"** + +4) Windows: **"%USERPROFILE%\.curlrc"** + +5) Windows: **"%APPDATA%\.curlrc"** + +6) Windows: **"%USERPROFILE%\Application Data\.curlrc"** + +7) Non-Windows: use getpwuid to find the home directory + +8) On Windows, if it finds no *.curlrc* file in the sequence described above, it +checks for one in the same directory the curl executable is placed. + +On Windows two filenames are checked per location: *.curlrc* and *_curlrc*, +preferring the former. Older versions on Windows checked for *_curlrc* only. diff --git a/third-party/curl/docs/cmdline-opts/connect-timeout.d b/third-party/curl/docs/cmdline-opts/connect-timeout.d deleted file mode 100644 index b3d19b3c33..0000000000 --- a/third-party/curl/docs/cmdline-opts/connect-timeout.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: connect-timeout -Arg: -Help: Maximum time allowed for connection -See-also: max-time -Category: connection -Example: --connect-timeout 20 $URL -Example: --connect-timeout 3.14 $URL -Added: 7.7 -Multi: single ---- -Maximum time in seconds that you allow curl's connection to take. This only -limits the connection phase, so if curl connects within the given period it -continues - if not it exits. - -This option accepts decimal values (added in 7.32.0). The decimal value needs -to be provided using a dot (.) as decimal separator - not the local version -even if it might be using another separator. - -The connection phase is considered complete when the DNS lookup and requested -TCP, TLS or QUIC handshakes are done. diff --git a/third-party/curl/docs/cmdline-opts/connect-timeout.md b/third-party/curl/docs/cmdline-opts/connect-timeout.md new file mode 100644 index 0000000000..dc5f927040 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/connect-timeout.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: connect-timeout +Arg: +Help: Maximum time allowed to connect +Category: connection timeout +Added: 7.7 +Multi: single +See-also: + - max-time +Example: + - --connect-timeout 20 $URL + - --connect-timeout 3.14 $URL +--- + +# `--connect-timeout` + +Maximum time in seconds that you allow curl's connection to take. This only +limits the connection phase, so if curl connects within the given period it +continues - if not it exits. + +This option accepts decimal values (added in 7.32.0). The decimal value needs +to be provided using a dot (.) as decimal separator - not the local version +even if it might be using another separator. + +The connection phase is considered complete when the DNS lookup and requested +TCP, TLS or QUIC handshakes are done. diff --git a/third-party/curl/docs/cmdline-opts/connect-to.d b/third-party/curl/docs/cmdline-opts/connect-to.d deleted file mode 100644 index 95fab91121..0000000000 --- a/third-party/curl/docs/cmdline-opts/connect-to.d +++ /dev/null @@ -1,24 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: connect-to -Arg: -Help: Connect to host -Added: 7.49.0 -See-also: resolve header -Category: connection -Example: --connect-to example.com:443:example.net:8443 $URL -Multi: append ---- - -For a request to the given HOST1:PORT1 pair, connect to HOST2:PORT2 instead. -This option is suitable to direct requests at a specific server, e.g. at a -specific cluster node in a cluster of servers. This option is only used to -establish the network connection. It does NOT affect the hostname/port that is -used for TLS/SSL (e.g. SNI, certificate verification) or for the application -protocols. "HOST1" and "PORT1" may be the empty string, meaning "any -host/port". "HOST2" and "PORT2" may also be the empty string, meaning "use the -request's original host/port". - -A "host" specified to this option is compared as a string, so it needs to -match the name used in request URL. It can be either numerical such as -"127.0.0.1" or the full host name such as "example.org". diff --git a/third-party/curl/docs/cmdline-opts/connect-to.md b/third-party/curl/docs/cmdline-opts/connect-to.md new file mode 100644 index 0000000000..c7378318e2 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/connect-to.md @@ -0,0 +1,40 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: connect-to +Arg: +Help: Connect to host2 instead of host1 +Added: 7.49.0 +Category: connection dns +Multi: append +See-also: + - resolve + - header +Example: + - --connect-to example.com:443:example.net:8443 $URL +--- + +# `--connect-to` + +For a request intended for the `HOST1:PORT1` pair, connect to `HOST2:PORT2` +instead. This option is only used to establish the network connection. It does +NOT affect the hostname/port number that is used for TLS/SSL (e.g. SNI, +certificate verification) or for the application protocols. + +`HOST1` and `PORT1` may be empty strings, meaning any host or any port number. +`HOST2` and `PORT2` may also be empty strings, meaning use the request's +original hostname and port number. + +A hostname specified to this option is compared as a string, so it needs to +match the name used in the request URL. It can be either numerical such as +`127.0.0.1` or the full hostname such as `example.org`. + +Example: redirect connects from the example.com hostname to 127.0.0.1 +independently of port number: + + curl --connect-to example.com::127.0.0.1: https://example.com/ + +Example: redirect connects from all hostnames to 127.0.0.1 independently of +port number: + + curl --connect-to ::127.0.0.1: http://example.com/ diff --git a/third-party/curl/docs/cmdline-opts/continue-at.d b/third-party/curl/docs/cmdline-opts/continue-at.d deleted file mode 100644 index a4fc1a9695..0000000000 --- a/third-party/curl/docs/cmdline-opts/continue-at.d +++ /dev/null @@ -1,20 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: C -Long: continue-at -Arg: -Help: Resumed transfer offset -See-also: range -Category: connection -Example: -C - $URL -Example: -C 400 $URL -Added: 4.8 -Multi: single ---- -Continue/Resume a previous file transfer at the given offset. The given offset -is the exact number of bytes that are skipped, counting from the beginning -of the source file before it is transferred to the destination. If used with -uploads, the FTP server command SIZE is not used by curl. - -Use "-C -" to tell curl to automatically find out where/how to resume the -transfer. It then uses the given output/input files to figure that out. diff --git a/third-party/curl/docs/cmdline-opts/continue-at.md b/third-party/curl/docs/cmdline-opts/continue-at.md new file mode 100644 index 0000000000..67a1376093 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/continue-at.md @@ -0,0 +1,37 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: C +Long: continue-at +Arg: +Help: Resumed transfer offset +Category: connection +Added: 4.8 +Multi: single +See-also: + - range +Example: + - -C - $URL + - -C 400 $URL +--- + +# `--continue-at` + +Resume a previous transfer from the given byte offset. The given offset is the +exact number of bytes that are skipped, counting from the beginning of the +source file before it is transferred to the destination. If used with uploads, +the FTP server command SIZE is not used by curl. + +Use "-C -" to instruct curl to automatically find out where/how to resume the +transfer. It then uses the given output/input files to figure that out. + +When using this option for HTTP uploads using POST or PUT, functionality is +not guaranteed. The HTTP protocol has no standard interoperable resume upload +and curl uses a set of headers for this purpose that once proved working for +some servers and have been left for those who find that useful. + +This command line option is mutually exclusive with --range: you can only use +one of them for a single transfer. + +The --no-clobber and --remove-on-error options cannot be used together with +--continue-at. diff --git a/third-party/curl/docs/cmdline-opts/cookie-jar.d b/third-party/curl/docs/cmdline-opts/cookie-jar.d deleted file mode 100644 index 28738cac94..0000000000 --- a/third-party/curl/docs/cmdline-opts/cookie-jar.d +++ /dev/null @@ -1,31 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: c -Long: cookie-jar -Arg: -Protocols: HTTP -Help: Write cookies to after operation -Category: http -Example: -c store-here.txt $URL -Example: -c store-here.txt -b read-these $URL -Added: 7.9 -See-also: cookie -Multi: single ---- -Specify to which file you want curl to write all cookies after a completed -operation. Curl writes all cookies from its in-memory cookie storage to the -given file at the end of operations. If no cookies are known, no data is -written. The file is created using the Netscape cookie file format. If you set -the file name to a single dash, "-", the cookies are written to stdout. - -The file specified with --cookie-jar is only used for output. No cookies are -read from the file. To read cookies, use the --cookie option. Both options -can specify the same file. - -This command line option activates the cookie engine that makes curl record -and use cookies. The --cookie option also activates it. - -If the cookie jar cannot be created or written to, the whole curl operation -does not fail or even report an error clearly. Using --verbose gets a warning -displayed, but that is the only visible feedback you get about this possibly -lethal situation. diff --git a/third-party/curl/docs/cmdline-opts/cookie-jar.md b/third-party/curl/docs/cmdline-opts/cookie-jar.md new file mode 100644 index 0000000000..de09fd5274 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/cookie-jar.md @@ -0,0 +1,42 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: c +Long: cookie-jar +Arg: +Protocols: HTTP +Help: Save cookies to after operation +Category: http +Added: 7.9 +Multi: single +See-also: + - cookie + - junk-session-cookies +Example: + - -c store-here.txt $URL + - -c store-here.txt -b read-these $URL +--- + +# `--cookie-jar` + +Specify to which file you want curl to write all cookies after a completed +operation. curl writes all cookies from its in-memory cookie storage to the +given file at the end of operations. Even if no cookies are known, a file is +created so that it removes any formerly existing cookies from the file. The +file uses the Netscape cookie file format. If you set the filename to a single +minus, "-", the cookies are written to stdout. + +The file specified with --cookie-jar is only used for output. No cookies are +read from the file. To read cookies, use the --cookie option. Both options +can specify the same file. + +This command line option activates the cookie engine that makes curl record +and use cookies. The --cookie option also activates it. + +If the cookie jar cannot be created or written to, the whole curl operation +does not fail or even report an error clearly. Using --verbose gets a warning +displayed, but that is the only visible feedback you get about this possibly +lethal situation. + +You may want to restrict your umask to prevent other users on the same system +to access the created file. diff --git a/third-party/curl/docs/cmdline-opts/cookie.d b/third-party/curl/docs/cmdline-opts/cookie.d deleted file mode 100644 index 0f858d6613..0000000000 --- a/third-party/curl/docs/cmdline-opts/cookie.d +++ /dev/null @@ -1,42 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: b -Long: cookie -Arg: -Protocols: HTTP -Help: Send cookies from string/file -Category: http -Example: -b cookiefile $URL -Example: -b cookiefile -c cookiefile $URL -See-also: cookie-jar junk-session-cookies -Added: 4.9 -Multi: append ---- -Pass the data to the HTTP server in the Cookie header. It is supposedly the -data previously received from the server in a "Set-Cookie:" line. The data -should be in the format "NAME1=VALUE1; NAME2=VALUE2". This makes curl use the -cookie header with this content explicitly in all outgoing request(s). If -multiple requests are done due to authentication, followed redirects or -similar, they all get this cookie passed on. - -If no '=' symbol is used in the argument, it is instead treated as a filename -to read previously stored cookie from. This option also activates the cookie -engine which makes curl record incoming cookies, which may be handy if you are -using this in combination with the --location option or do multiple URL -transfers on the same invoke. If the file name is exactly a minus ("-"), curl -instead reads the contents from stdin. - -The file format of the file to read cookies from should be plain HTTP headers -(Set-Cookie style) or the Netscape/Mozilla cookie file format. - -The file specified with --cookie is only used as input. No cookies are written -to the file. To store cookies, use the --cookie-jar option. - -If you use the Set-Cookie file format and do not specify a domain then the -cookie is not sent since the domain never matches. To address this, set a -domain in Set-Cookie line (doing that includes subdomains) or preferably: use -the Netscape format. - -Users often want to both read cookies from a file and write updated cookies -back to a file, so using both --cookie and --cookie-jar in the same command -line is common. diff --git a/third-party/curl/docs/cmdline-opts/cookie.md b/third-party/curl/docs/cmdline-opts/cookie.md new file mode 100644 index 0000000000..30288fbcba --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/cookie.md @@ -0,0 +1,63 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: b +Long: cookie +Arg: +Protocols: HTTP +Help: Send cookies from string/load from file +Category: http +Added: 4.9 +Multi: append +See-also: + - cookie-jar + - junk-session-cookies +Example: + - -b "" $URL + - -b cookiefile $URL + - -b cookiefile -c cookiefile $URL + - -b name=Jane $URL +--- + +# `--cookie` + +This option has two slightly separate cookie sending functions. + +Either: pass the exact data to send to the HTTP server in the Cookie header. +It is supposedly data previously received from the server in a `Set-Cookie:` +line. The data should be in the format `NAME1=VALUE1; NAME2=VALUE2`. When +given a set of specific cookies, curl populates its cookie header with this +content explicitly in all outgoing request(s). If multiple requests are done +due to authentication, followed redirects or similar, they all get this cookie +header passed on. + +Or: If no `=` symbol is used in the argument, it is instead treated as a +filename to read previously stored cookie from. This option also activates the +cookie engine which makes curl record incoming cookies, which may be handy if +you are using this in combination with the --location option or do multiple +URL transfers on the same invoke. + +If the filename is a single minus ("-"), curl reads the contents from stdin. +If the filename is an empty string ("") and is the only cookie input, curl +activates the cookie engine without any cookies. + +The file format of the file to read cookies from should be plain HTTP headers +(Set-Cookie style) or the Netscape/Mozilla cookie file format. + +The file specified with --cookie is only used as input. No cookies are written +to that file. To store cookies, use the --cookie-jar option. + +If you use the Set-Cookie file format and do not specify a domain then the +cookie is not sent since the domain never matches. To address this, set a +domain in Set-Cookie line (doing that includes subdomains) or preferably: use +the Netscape format. + +Users often want to both read cookies from a file and write updated cookies +back to a file, so using both --cookie and --cookie-jar in the same command +line is common. curl ignores filenames specified with --cookie which do not +exist or point to a directory. + +If curl is built with PSL (**Public Suffix List**) support, it detects and +discards cookies that are specified for such suffix domains that should not be +allowed to have cookies. If curl is *not* built with PSL support, it has no +ability to stop super cookies. diff --git a/third-party/curl/docs/cmdline-opts/create-dirs.d b/third-party/curl/docs/cmdline-opts/create-dirs.d deleted file mode 100644 index f137e7d10d..0000000000 --- a/third-party/curl/docs/cmdline-opts/create-dirs.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: create-dirs -Help: Create necessary local directory hierarchy -Category: curl -Example: --create-dirs --output local/dir/file $URL -Added: 7.10.3 -See-also: ftp-create-dirs output-dir -Multi: boolean ---- -When used in conjunction with the --output option, curl creates the necessary -local directory hierarchy as needed. This option creates the directories -mentioned with the --output option, nothing else. If the --output file name -uses no directory, or if the directories it mentions already exist, no -directories are created. - -Created directories are made with mode 0750 on unix style file systems. - -To create remote directories when using FTP or SFTP, try --ftp-create-dirs. diff --git a/third-party/curl/docs/cmdline-opts/create-dirs.md b/third-party/curl/docs/cmdline-opts/create-dirs.md new file mode 100644 index 0000000000..89d24f76b5 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/create-dirs.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: create-dirs +Help: Create necessary local directory hierarchy +Category: output +Added: 7.10.3 +Multi: boolean +See-also: + - ftp-create-dirs + - output-dir +Example: + - --create-dirs --output local/dir/file $URL +--- + +# `--create-dirs` + +When used in conjunction with the --output option, curl creates the necessary +local directory hierarchy as needed. This option creates the directories +mentioned with the --output option combined with the path possibly set with +--output-dir. If the combined output filename uses no directory, or if the +directories it mentions already exist, no directories are created. + +Created directories are made with mode 0750 on Unix-style file systems. + +To create remote directories when using FTP or SFTP, try --ftp-create-dirs. diff --git a/third-party/curl/docs/cmdline-opts/create-file-mode.d b/third-party/curl/docs/cmdline-opts/create-file-mode.d deleted file mode 100644 index c0ebc08d44..0000000000 --- a/third-party/curl/docs/cmdline-opts/create-file-mode.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: create-file-mode -Arg: -Help: File mode for created files -Protocols: SFTP SCP FILE -Category: sftp scp file upload -See-also: ftp-create-dirs -Added: 7.75.0 -Example: --create-file-mode 0777 -T localfile sftp://example.com/new -Multi: single ---- -When curl is used to create files remotely using one of the supported -protocols, this option allows the user to set which 'mode' to set on the file -at creation time, instead of the default 0644. - -This option takes an octal number as argument. diff --git a/third-party/curl/docs/cmdline-opts/create-file-mode.md b/third-party/curl/docs/cmdline-opts/create-file-mode.md new file mode 100644 index 0000000000..c6467d15a4 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/create-file-mode.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: create-file-mode +Arg: +Help: File mode for created files +Protocols: SFTP SCP FILE +Category: sftp scp file upload +Added: 7.75.0 +Multi: single +See-also: + - ftp-create-dirs +Example: + - --create-file-mode 0777 -T localfile sftp://example.com/new +--- + +# `--create-file-mode` + +When curl is used to create files remotely using one of the supported +protocols, this option allows the user to set which 'mode' to set on the file +at creation time, instead of the default 0644. + +This option takes an octal number as argument. diff --git a/third-party/curl/docs/cmdline-opts/crlf.d b/third-party/curl/docs/cmdline-opts/crlf.d deleted file mode 100644 index ea7fb1526a..0000000000 --- a/third-party/curl/docs/cmdline-opts/crlf.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: crlf -Help: Convert LF to CRLF in upload -Protocols: FTP SMTP -Category: ftp smtp -Example: --crlf -T file ftp://example.com/ -Added: 5.7 -See-also: use-ascii -Multi: boolean ---- -Convert line feeds to carriage return plus line feeds in upload. Useful for -**MVS (OS/390)**. - -(SMTP added in 7.40.0) diff --git a/third-party/curl/docs/cmdline-opts/crlf.md b/third-party/curl/docs/cmdline-opts/crlf.md new file mode 100644 index 0000000000..c36884113d --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/crlf.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: crlf +Help: Convert LF to CRLF in upload +Protocols: FTP SMTP +Category: ftp smtp +Added: 5.7 +Multi: boolean +See-also: + - use-ascii +Example: + - --crlf -T file ftp://example.com/ +--- + +# `--crlf` + +Convert line feeds to carriage return plus line feeds in upload. Useful for +**MVS (OS/390)**. diff --git a/third-party/curl/docs/cmdline-opts/crlfile.d b/third-party/curl/docs/cmdline-opts/crlfile.d deleted file mode 100644 index da0d239bad..0000000000 --- a/third-party/curl/docs/cmdline-opts/crlfile.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: crlfile -Arg: -Protocols: TLS -Help: Use this CRL list -Added: 7.19.7 -Category: tls -Example: --crlfile rejects.txt $URL -See-also: cacert capath -Multi: single ---- -Provide a file using PEM format with a Certificate Revocation List that may -specify peer certificates that are to be considered revoked. diff --git a/third-party/curl/docs/cmdline-opts/crlfile.md b/third-party/curl/docs/cmdline-opts/crlfile.md new file mode 100644 index 0000000000..a762af09f1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/crlfile.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: crlfile +Arg: +Protocols: TLS +Help: Certificate Revocation list +Added: 7.19.7 +Category: tls +Multi: single +See-also: + - cacert + - capath +Example: + - --crlfile rejects.txt $URL +--- + +# `--crlfile` + +Provide a file using PEM format with a Certificate Revocation List that may +specify peer certificates that are to be considered revoked. diff --git a/third-party/curl/docs/cmdline-opts/curves.d b/third-party/curl/docs/cmdline-opts/curves.d deleted file mode 100644 index 58d472d20d..0000000000 --- a/third-party/curl/docs/cmdline-opts/curves.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: curves -Arg: -Help: (EC) TLS key exchange algorithm(s) to request -Protocols: TLS -Added: 7.73.0 -Category: tls -Example: --curves X25519 $URL -See-also: ciphers -Multi: single ---- -Tells curl to request specific curves to use during SSL session establishment -according to RFC 8422, 5.1. Multiple algorithms can be provided by separating -them with ":" (e.g. "X25519:P-521"). The parameter is available identically -in the "openssl s_client/s_server" utilities. - ---curves allows a OpenSSL powered curl to make SSL-connections with exactly -the (EC) curve requested by the client, avoiding nontransparent client/server -negotiations. - -If this option is set, the default curves list built into OpenSSL are ignored. diff --git a/third-party/curl/docs/cmdline-opts/curves.md b/third-party/curl/docs/cmdline-opts/curves.md new file mode 100644 index 0000000000..9473aeaa7a --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/curves.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: curves +Arg: +Help: (EC) TLS key exchange algorithms to request +Protocols: TLS +Added: 7.73.0 +Category: tls +Multi: single +See-also: + - ciphers +Example: + - --curves X25519 $URL +--- + +# `--curves` + +Set specific curves to use during SSL session establishment according to RFC +8422, 5.1. Multiple algorithms can be provided by separating them with `:` +(e.g. `X25519:P-521`). The parameter is available identically in the OpenSSL +`s_client` and `s_server` utilities. + +--curves allows a OpenSSL powered curl to make SSL-connections with exactly +the (EC) curve requested by the client, avoiding nontransparent client/server +negotiations. + +If this option is set, the default curves list built into OpenSSL are ignored. diff --git a/third-party/curl/docs/cmdline-opts/data-ascii.d b/third-party/curl/docs/cmdline-opts/data-ascii.d deleted file mode 100644 index 5c7840bbc4..0000000000 --- a/third-party/curl/docs/cmdline-opts/data-ascii.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: data-ascii -Arg: -Help: HTTP POST ASCII data -Protocols: HTTP -Category: http post upload -Example: --data-ascii @file $URL -Added: 7.2 -See-also: data-binary data-raw data-urlencode -Multi: append ---- -This is just an alias for --data. diff --git a/third-party/curl/docs/cmdline-opts/data-ascii.md b/third-party/curl/docs/cmdline-opts/data-ascii.md new file mode 100644 index 0000000000..c1d9d75bbd --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/data-ascii.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: data-ascii +Arg: +Help: HTTP POST ASCII data +Protocols: HTTP +Category: http post upload +Added: 7.2 +Multi: append +See-also: + - data-binary + - data-raw + - data-urlencode +Example: + - --data-ascii @file $URL +--- + +# `--data-ascii` + +This option is an alias for --data. diff --git a/third-party/curl/docs/cmdline-opts/data-binary.d b/third-party/curl/docs/cmdline-opts/data-binary.d deleted file mode 100644 index 2cedda97b0..0000000000 --- a/third-party/curl/docs/cmdline-opts/data-binary.d +++ /dev/null @@ -1,25 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: data-binary -Arg: -Help: HTTP POST binary data -Protocols: HTTP -Category: http post upload -Example: --data-binary @filename $URL -Added: 7.2 -See-also: data-ascii -Multi: append ---- -This posts data exactly as specified with no extra processing whatsoever. - -If you start the data with the letter @, the rest should be a filename. Data -is posted in a similar manner as --data does, except that newlines and -carriage returns are preserved and conversions are never done. - -Like --data the default content-type sent to the server is -application/x-www-form-urlencoded. If you want the data to be treated as -arbitrary binary data by the server then set the content-type to octet-stream: --H "Content-Type: application/octet-stream". - -If this option is used several times, the ones following the first append -data as described in --data. diff --git a/third-party/curl/docs/cmdline-opts/data-binary.md b/third-party/curl/docs/cmdline-opts/data-binary.md new file mode 100644 index 0000000000..4c5e4da8d1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/data-binary.md @@ -0,0 +1,32 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: data-binary +Arg: +Help: HTTP POST binary data +Protocols: HTTP +Category: http post upload +Added: 7.2 +Multi: append +See-also: + - data-ascii +Example: + - --data-binary @filename $URL +--- + +# `--data-binary` + +Post data exactly as specified with no extra processing whatsoever. + +If you start the data with the letter @, the rest should be a filename. +`@-` makes curl read the data from stdin. Data is posted in a similar +manner as --data does, except that newlines and carriage returns are +preserved and conversions are never done. + +Like --data the default content-type sent to the server is +application/x-www-form-urlencoded. If you want the data to be treated as +arbitrary binary data by the server then set the content-type to octet-stream: +-H "Content-Type: application/octet-stream". + +If this option is used several times, the ones following the first append +data as described in --data. diff --git a/third-party/curl/docs/cmdline-opts/data-raw.d b/third-party/curl/docs/cmdline-opts/data-raw.d deleted file mode 100644 index e6a5a5b2b9..0000000000 --- a/third-party/curl/docs/cmdline-opts/data-raw.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: data-raw -Arg: -Protocols: HTTP -Help: HTTP POST data, '@' allowed -Added: 7.43.0 -See-also: data -Category: http post upload -Example: --data-raw "hello" $URL -Example: --data-raw "@at@at@" $URL -Multi: append ---- -This posts data similarly to --data but without the special -interpretation of the @ character. diff --git a/third-party/curl/docs/cmdline-opts/data-raw.md b/third-party/curl/docs/cmdline-opts/data-raw.md new file mode 100644 index 0000000000..1033678bde --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/data-raw.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: data-raw +Arg: +Protocols: HTTP +Help: HTTP POST data, '@' allowed +Added: 7.43.0 +Category: http post upload +Multi: append +See-also: + - data +Example: + - --data-raw "hello" $URL + - --data-raw "@at@at@" $URL +--- + +# `--data-raw` + +Post data similarly to --data but without the special interpretation of the @ +character. diff --git a/third-party/curl/docs/cmdline-opts/data-urlencode.d b/third-party/curl/docs/cmdline-opts/data-urlencode.d deleted file mode 100644 index 3c436b26b1..0000000000 --- a/third-party/curl/docs/cmdline-opts/data-urlencode.d +++ /dev/null @@ -1,42 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: data-urlencode -Arg: -Help: HTTP POST data URL encoded -Protocols: HTTP -See-also: data data-raw -Added: 7.18.0 -Category: http post upload -Example: --data-urlencode name=val $URL -Example: --data-urlencode =encodethis $URL -Example: --data-urlencode name@file $URL -Example: --data-urlencode @fileonly $URL -Multi: append ---- -This posts data, similar to the other --data options with the exception -that this performs URL-encoding. - -To be CGI-compliant, the part should begin with a *name* followed -by a separator and a content specification. The part can be passed to -curl using one of the following syntaxes: -.RS -.IP "content" -This makes curl URL-encode the content and pass that on. Just be careful -so that the content does not contain any = or @ symbols, as that makes -the syntax match one of the other cases below! -.IP "=content" -This makes curl URL-encode the content and pass that on. The preceding = -symbol is not included in the data. -.IP "name=content" -This makes curl URL-encode the content part and pass that on. Note that -the name part is expected to be URL-encoded already. -.IP "@filename" -This makes curl load data from the given file (including any newlines), -URL-encode that data and pass it on in the POST. -.IP "name@filename" -This makes curl load data from the given file (including any newlines), -URL-encode that data and pass it on in the POST. The name part gets an equal -sign appended, resulting in *name=urlencoded-file-content*. Note that the -name is expected to be URL-encoded already. -.RE -.IP diff --git a/third-party/curl/docs/cmdline-opts/data-urlencode.md b/third-party/curl/docs/cmdline-opts/data-urlencode.md new file mode 100644 index 0000000000..36fdf3df2f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/data-urlencode.md @@ -0,0 +1,51 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: data-urlencode +Arg: +Help: HTTP POST data URL encoded +Protocols: HTTP +Added: 7.18.0 +Category: http post upload +Multi: append +See-also: + - data + - data-raw +Example: + - --data-urlencode name=val $URL + - --data-urlencode =encodethis $URL + - --data-urlencode name@file $URL + - --data-urlencode @fileonly $URL +--- + +# `--data-urlencode` + +Post data, similar to the other --data options with the exception that this +performs URL-encoding. + +To be CGI-compliant, the \ part should begin with a *name* followed by +a separator and a content specification. The \ part can be passed to +curl using one of the following syntaxes: + +## content +URL-encode the content and pass that on. Be careful so that the content does +not contain any `=` or `@` symbols, as that makes the syntax match one of the +other cases below. + +## =content +URL-encode the content and pass that on. The preceding `=` symbol is not +included in the data. + +## name=content +URL-encode the content part and pass that on. Note that the name part is +expected to be URL-encoded already. + +## @filename +load data from the given file (including any newlines), URL-encode that data +and pass it on in the POST. Using `@-` makes curl read the data from stdin. + +## name@filename +load data from the given file (including any newlines), URL-encode that data +and pass it on in the POST. The name part gets an equal sign appended, +resulting in *name=urlencoded-file-content*. Note that the name is expected to +be URL-encoded already. diff --git a/third-party/curl/docs/cmdline-opts/data.d b/third-party/curl/docs/cmdline-opts/data.d deleted file mode 100644 index f1d67b9506..0000000000 --- a/third-party/curl/docs/cmdline-opts/data.d +++ /dev/null @@ -1,41 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: data -Short: d -Arg: -Help: HTTP POST data -Protocols: HTTP MQTT -See-also: data-binary data-urlencode data-raw -Mutexed: form head upload-file -Category: important http post upload -Example: -d "name=curl" $URL -Example: -d "name=curl" -d "tool=cmdline" $URL -Example: -d @filename $URL -Added: 4.0 -Multi: append ---- -Sends the specified data in a POST request to the HTTP server, in the same way -that a browser does when a user has filled in an HTML form and presses the -submit button. This makes curl pass the data to the server using the -content-type application/x-www-form-urlencoded. Compare to --form. - ---data-raw is almost the same but does not have a special interpretation of -the @ character. To post data purely binary, you should instead use the ---data-binary option. To URL-encode the value of a form field you may use ---data-urlencode. - -If any of these options is used more than once on the same command line, the -data pieces specified are merged with a separating &-symbol. Thus, using -'-d name=daniel -d skill=lousy' would generate a post chunk that looks like -'name=daniel&skill=lousy'. - -If you start the data with the letter @, the rest should be a file name to -read the data from, or - if you want curl to read the data from stdin. Posting -data from a file named 'foobar' would thus be done with --data @foobar. When ---data is told to read from a file like that, carriage returns and newlines -are stripped out. If you do not want the @ character to have a special -interpretation use --data-raw instead. - -The data for this option is passed on to the server exactly as provided on the -command line. curl does not convert, change or improve it. It is up to the -user to provide the data in the correct form. diff --git a/third-party/curl/docs/cmdline-opts/data.md b/third-party/curl/docs/cmdline-opts/data.md new file mode 100644 index 0000000000..d95b023953 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/data.md @@ -0,0 +1,49 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: data +Short: d +Arg: +Help: HTTP POST data +Protocols: HTTP MQTT +Mutexed: form head upload-file +Category: important http post upload +Added: 4.0 +Multi: append +See-also: + - data-binary + - data-urlencode + - data-raw +Example: + - -d "name=curl" $URL + - -d "name=curl" -d "tool=cmdline" $URL + - -d @filename $URL +--- + +# `--data` + +Send the specified data in a POST request to the HTTP server, in the same way +that a browser does when a user has filled in an HTML form and presses the +submit button. This option makes curl pass the data to the server using the +content-type application/x-www-form-urlencoded. Compared to --form. + +--data-raw is almost the same but does not have a special interpretation of +the @ character. To post data purely binary, you should instead use the +--data-binary option. To URL-encode the value of a form field you may use +--data-urlencode. + +If any of these options is used more than once on the same command line, the +data pieces specified are merged with a separating &-symbol. Thus, using +'-d name=daniel -d skill=lousy' would generate a post chunk that looks like +'name=daniel&skill=lousy'. + +If you start the data with the letter @, the rest should be a filename to read +the data from, or - if you want curl to read the data from stdin. Posting data +from a file named 'foobar' would thus be done with --data @foobar. When --data +is told to read from a file like that, carriage returns, newlines and null +bytes are stripped out. If you do not want the @ character to have a special +interpretation use --data-raw instead. + +The data for this option is passed on to the server exactly as provided on the +command line. curl does not convert, change or improve it. It is up to the +user to provide the data in the correct form. diff --git a/third-party/curl/docs/cmdline-opts/delegation.d b/third-party/curl/docs/cmdline-opts/delegation.d deleted file mode 100644 index 7941849347..0000000000 --- a/third-party/curl/docs/cmdline-opts/delegation.d +++ /dev/null @@ -1,24 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: delegation -Arg: -Help: GSS-API delegation permission -Protocols: GSS/kerberos -Category: auth -Example: --delegation "none" $URL -Added: 7.22.0 -See-also: insecure ssl -Multi: single ---- -Set LEVEL to tell the server what it is allowed to delegate when it -comes to user credentials. -.RS -.IP "none" -Do not allow any delegation. -.IP "policy" -Delegates if and only if the OK-AS-DELEGATE flag is set in the Kerberos -service ticket, which is a matter of realm policy. -.IP "always" -Unconditionally allow the server to delegate. -.RE -.IP diff --git a/third-party/curl/docs/cmdline-opts/delegation.md b/third-party/curl/docs/cmdline-opts/delegation.md new file mode 100644 index 0000000000..c874a2b59d --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/delegation.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: delegation +Arg: +Help: GSS-API delegation permission +Protocols: GSS/kerberos +Category: auth +Added: 7.22.0 +Multi: single +See-also: + - insecure + - ssl +Example: + - --delegation "none" $URL +--- + +# `--delegation` + +Set LEVEL what curl is allowed to delegate when it comes to user credentials. + +## none +Do not allow any delegation. + +## policy +Delegates if and only if the OK-AS-DELEGATE flag is set in the Kerberos +service ticket, which is a matter of realm policy. + +## always +Unconditionally allow the server to delegate. diff --git a/third-party/curl/docs/cmdline-opts/digest.d b/third-party/curl/docs/cmdline-opts/digest.d deleted file mode 100644 index f2ee551c5e..0000000000 --- a/third-party/curl/docs/cmdline-opts/digest.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: digest -Help: Use HTTP Digest Authentication -Protocols: HTTP -Mutexed: basic ntlm negotiate -See-also: user proxy-digest anyauth -Category: proxy auth http -Example: -u name:password --digest $URL -Added: 7.10.6 -Multi: boolean ---- -Enables HTTP Digest authentication. This is an authentication scheme that -prevents the password from being sent over the wire in clear text. Use this in -combination with the normal --user option to set user name and password. diff --git a/third-party/curl/docs/cmdline-opts/digest.md b/third-party/curl/docs/cmdline-opts/digest.md new file mode 100644 index 0000000000..c67d7894c8 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/digest.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: digest +Help: HTTP Digest Authentication +Protocols: HTTP +Category: proxy auth http +Added: 7.10.6 +Multi: boolean +See-also: + - user + - proxy-digest + - anyauth +Example: + - -u name:password --digest $URL +--- + +# `--digest` + +Enable HTTP Digest authentication. This authentication scheme avoids sending +the password over the wire in clear text. Use this in combination with the +normal --user option to set username and password. diff --git a/third-party/curl/docs/cmdline-opts/disable-eprt.d b/third-party/curl/docs/cmdline-opts/disable-eprt.d deleted file mode 100644 index b6d382bafa..0000000000 --- a/third-party/curl/docs/cmdline-opts/disable-eprt.d +++ /dev/null @@ -1,25 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: disable-eprt -Help: Inhibit using EPRT or LPRT -Protocols: FTP -Category: ftp -Example: --disable-eprt ftp://example.com/ -Added: 7.10.5 -See-also: disable-epsv ftp-port -Multi: boolean ---- -Tell curl to disable the use of the EPRT and LPRT commands when doing active -FTP transfers. Curl normally first attempts to use EPRT before using PORT, but -with this option, it uses PORT right away. EPRT is an extension to the -original FTP protocol, and does not work on all servers, but enables more -functionality in a better way than the traditional PORT command. - ---eprt can be used to explicitly enable EPRT again and --no-eprt is an alias -for --disable-eprt. - -If the server is accessed using IPv6, this option has no effect as EPRT is -necessary then. - -Disabling EPRT only changes the active behavior. If you want to switch to -passive mode you need to not use --ftp-port or force it with --ftp-pasv. diff --git a/third-party/curl/docs/cmdline-opts/disable-eprt.md b/third-party/curl/docs/cmdline-opts/disable-eprt.md new file mode 100644 index 0000000000..768b689c13 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/disable-eprt.md @@ -0,0 +1,32 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: disable-eprt +Help: Inhibit using EPRT or LPRT +Protocols: FTP +Category: ftp +Added: 7.10.5 +Multi: boolean +See-also: + - disable-epsv + - ftp-port +Example: + - --disable-eprt ftp://example.com/ +--- + +# `--disable-eprt` + +Disable the use of the EPRT and LPRT commands when doing active FTP transfers. +curl normally first attempts to use EPRT before using PORT, but with this +option, it uses PORT right away. EPRT is an extension to the original FTP +protocol, and does not work on all servers, but enables more functionality in +a better way than the traditional PORT command. + +--eprt can be used to explicitly enable EPRT again and --no-eprt is an alias +for --disable-eprt. + +If the server is accessed using IPv6, this option has no effect as EPRT is +necessary then. + +Disabling EPRT only changes the active behavior. If you want to switch to +passive mode you need to not use --ftp-port or force it with --ftp-pasv. diff --git a/third-party/curl/docs/cmdline-opts/disable-epsv.d b/third-party/curl/docs/cmdline-opts/disable-epsv.d deleted file mode 100644 index f02df763da..0000000000 --- a/third-party/curl/docs/cmdline-opts/disable-epsv.d +++ /dev/null @@ -1,23 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: disable-epsv -Help: Inhibit using EPSV -Protocols: FTP -Category: ftp -Example: --disable-epsv ftp://example.com/ -Added: 7.9.2 -See-also: disable-eprt ftp-port -Multi: boolean ---- -Tell curl to disable the use of the EPSV command when doing passive FTP -transfers. Curl normally first attempts to use EPSV before PASV, but with this -option, it does not try EPSV. - ---epsv can be used to explicitly enable EPSV again and --no-epsv is an alias -for --disable-epsv. - -If the server is an IPv6 host, this option has no effect as EPSV is necessary -then. - -Disabling EPSV only changes the passive behavior. If you want to switch to -active mode you need to use --ftp-port. diff --git a/third-party/curl/docs/cmdline-opts/disable-epsv.md b/third-party/curl/docs/cmdline-opts/disable-epsv.md new file mode 100644 index 0000000000..d13e076907 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/disable-epsv.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: disable-epsv +Help: Inhibit using EPSV +Protocols: FTP +Category: ftp +Added: 7.9.2 +Multi: boolean +See-also: + - disable-eprt + - ftp-port +Example: + - --disable-epsv ftp://example.com/ +--- + +# `--disable-epsv` + +Disable the use of the EPSV command when doing passive FTP transfers. curl +normally first attempts to use EPSV before PASV, but with this option, it does +not try EPSV. + +--epsv can be used to explicitly enable EPSV again and --no-epsv is an alias +for --disable-epsv. + +If the server is an IPv6 host, this option has no effect as EPSV is necessary +then. + +Disabling EPSV only changes the passive behavior. If you want to switch to +active mode you need to use --ftp-port. diff --git a/third-party/curl/docs/cmdline-opts/disable.d b/third-party/curl/docs/cmdline-opts/disable.d deleted file mode 100644 index 979c039915..0000000000 --- a/third-party/curl/docs/cmdline-opts/disable.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: disable -Short: q -Help: Disable .curlrc -Category: curl -Example: -q $URL -Added: 5.0 -See-also: config -Multi: boolean ---- -If used as the **first** parameter on the command line, the *curlrc* config -file is not read or used. See the --config for details on the default config -file search path. - -Prior to 7.50.0 curl supported the short option name *q* but not the long -option name *disable*. diff --git a/third-party/curl/docs/cmdline-opts/disable.md b/third-party/curl/docs/cmdline-opts/disable.md new file mode 100644 index 0000000000..1370b91d7b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/disable.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: disable +Short: q +Help: Disable .curlrc +Category: curl +Added: 5.0 +Multi: boolean +See-also: + - config +Example: + - -q $URL +--- + +# `--disable` + +If used as the **first** parameter on the command line, the *curlrc* config +file is not read or used. See the --config for details on the default config +file search path. diff --git a/third-party/curl/docs/cmdline-opts/disallow-username-in-url.d b/third-party/curl/docs/cmdline-opts/disallow-username-in-url.d deleted file mode 100644 index d0537db97a..0000000000 --- a/third-party/curl/docs/cmdline-opts/disallow-username-in-url.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: disallow-username-in-url -Help: Disallow username in URL -Protocols: HTTP -Added: 7.61.0 -See-also: proto -Category: curl http -Example: --disallow-username-in-url $URL -Multi: boolean ---- -This tells curl to exit if passed a URL containing a username. This is probably -most useful when the URL is being provided at runtime or similar. diff --git a/third-party/curl/docs/cmdline-opts/disallow-username-in-url.md b/third-party/curl/docs/cmdline-opts/disallow-username-in-url.md new file mode 100644 index 0000000000..0507f531cc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/disallow-username-in-url.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: disallow-username-in-url +Help: Disallow username in URL +Added: 7.61.0 +Category: curl +Multi: boolean +See-also: + - proto +Example: + - --disallow-username-in-url $URL +--- + +# `--disallow-username-in-url` + +Exit with error if passed a URL containing a username. Probably most useful +when the URL is being provided at runtime or similar. + +Accepting and using credentials in a URL is normally considered a security +hazard as they are easily leaked that way. diff --git a/third-party/curl/docs/cmdline-opts/dns-interface.d b/third-party/curl/docs/cmdline-opts/dns-interface.d deleted file mode 100644 index fd924b897a..0000000000 --- a/third-party/curl/docs/cmdline-opts/dns-interface.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: dns-interface -Arg: -Help: Interface to use for DNS requests -Protocols: DNS -See-also: dns-ipv4-addr dns-ipv6-addr -Added: 7.33.0 -Requires: c-ares -Category: dns -Example: --dns-interface eth0 $URL -Multi: single ---- -Tell curl to send outgoing DNS requests through . This option is a -counterpart to --interface (which does not affect DNS). The supplied string -must be an interface name (not an address). diff --git a/third-party/curl/docs/cmdline-opts/dns-interface.md b/third-party/curl/docs/cmdline-opts/dns-interface.md new file mode 100644 index 0000000000..aee7400bc5 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/dns-interface.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: dns-interface +Arg: +Help: Interface to use for DNS requests +Protocols: DNS +Added: 7.33.0 +Requires: c-ares +Category: dns +Multi: single +See-also: + - dns-ipv4-addr + - dns-ipv6-addr +Example: + - --dns-interface eth0 $URL +--- + +# `--dns-interface` + +Send outgoing DNS requests through the given interface. This option is a +counterpart to --interface (which does not affect DNS). The supplied string +must be an interface name (not an address). diff --git a/third-party/curl/docs/cmdline-opts/dns-ipv4-addr.d b/third-party/curl/docs/cmdline-opts/dns-ipv4-addr.d deleted file mode 100644 index 5930557397..0000000000 --- a/third-party/curl/docs/cmdline-opts/dns-ipv4-addr.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: dns-ipv4-addr -Arg:
-Help: IPv4 address to use for DNS requests -Protocols: DNS -See-also: dns-interface dns-ipv6-addr -Added: 7.33.0 -Requires: c-ares -Category: dns -Example: --dns-ipv4-addr 10.1.2.3 $URL -Multi: single ---- -Tell curl to bind to a specific IP address when making IPv4 DNS requests, so -that the DNS requests originate from this address. The argument should be a -single IPv4 address. diff --git a/third-party/curl/docs/cmdline-opts/dns-ipv4-addr.md b/third-party/curl/docs/cmdline-opts/dns-ipv4-addr.md new file mode 100644 index 0000000000..4a43cb1d90 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/dns-ipv4-addr.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: dns-ipv4-addr +Arg:
+Help: IPv4 address to use for DNS requests +Protocols: DNS +Added: 7.33.0 +Requires: c-ares +Category: dns +Multi: single +See-also: + - dns-interface + - dns-ipv6-addr +Example: + - --dns-ipv4-addr 10.1.2.3 $URL +--- + +# `--dns-ipv4-addr` + +Bind to a specific IP address when making IPv4 DNS requests, so that the DNS +requests originate from this address. The argument should be a single IPv4 +address. diff --git a/third-party/curl/docs/cmdline-opts/dns-ipv6-addr.d b/third-party/curl/docs/cmdline-opts/dns-ipv6-addr.d deleted file mode 100644 index a76120cdc1..0000000000 --- a/third-party/curl/docs/cmdline-opts/dns-ipv6-addr.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: dns-ipv6-addr -Arg:
-Help: IPv6 address to use for DNS requests -Protocols: DNS -See-also: dns-interface dns-ipv4-addr -Added: 7.33.0 -Requires: c-ares -Category: dns -Example: --dns-ipv6-addr 2a04:4e42::561 $URL -Multi: single ---- -Tell curl to bind to a specific IP address when making IPv6 DNS requests, so -that the DNS requests originate from this address. The argument should be a -single IPv6 address. diff --git a/third-party/curl/docs/cmdline-opts/dns-ipv6-addr.md b/third-party/curl/docs/cmdline-opts/dns-ipv6-addr.md new file mode 100644 index 0000000000..7112311767 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/dns-ipv6-addr.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: dns-ipv6-addr +Arg:
+Help: IPv6 address to use for DNS requests +Protocols: DNS +Added: 7.33.0 +Requires: c-ares +Category: dns +Multi: single +See-also: + - dns-interface + - dns-ipv4-addr +Example: + - --dns-ipv6-addr 2a04:4e42::561 $URL +--- + +# `--dns-ipv6-addr` + +Bind to a specific IP address when making IPv6 DNS requests, so that the DNS +requests originate from this address. The argument should be a single IPv6 +address. diff --git a/third-party/curl/docs/cmdline-opts/dns-servers.d b/third-party/curl/docs/cmdline-opts/dns-servers.d deleted file mode 100644 index bec23a3c35..0000000000 --- a/third-party/curl/docs/cmdline-opts/dns-servers.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: dns-servers -Arg: -Help: DNS server addrs to use -Requires: c-ares -Added: 7.33.0 -Category: dns -Example: --dns-servers 192.168.0.1,192.168.0.2 $URL -See-also: dns-interface dns-ipv4-addr -Multi: single ---- -Set the list of DNS servers to be used instead of the system default. -The list of IP addresses should be separated with commas. Port numbers -may also optionally be given as *:* after each IP -address. diff --git a/third-party/curl/docs/cmdline-opts/dns-servers.md b/third-party/curl/docs/cmdline-opts/dns-servers.md new file mode 100644 index 0000000000..bf6ba3fe93 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/dns-servers.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: dns-servers +Arg: +Help: DNS server addrs to use +Protocols: DNS +Requires: c-ares +Added: 7.33.0 +Category: dns +Multi: single +See-also: + - dns-interface + - dns-ipv4-addr +Example: + - --dns-servers 192.168.0.1,192.168.0.2 $URL + - --dns-servers 10.0.0.1:53 $URL +--- + +# `--dns-servers` + +Set the list of DNS servers to be used instead of the system default. The list +of IP addresses should be separated with commas. Port numbers may also +optionally be given, appended to the IP address separated with a colon. diff --git a/third-party/curl/docs/cmdline-opts/doh-cert-status.d b/third-party/curl/docs/cmdline-opts/doh-cert-status.d deleted file mode 100644 index 37ae0f8274..0000000000 --- a/third-party/curl/docs/cmdline-opts/doh-cert-status.d +++ /dev/null @@ -1,11 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: doh-cert-status -Help: Verify the status of the DoH server cert via OCSP-staple -Added: 7.76.0 -Category: dns tls -Example: --doh-cert-status --doh-url https://doh.example $URL -See-also: doh-insecure -Multi: boolean ---- -Same as --cert-status but used for DoH (DNS-over-HTTPS). diff --git a/third-party/curl/docs/cmdline-opts/doh-cert-status.md b/third-party/curl/docs/cmdline-opts/doh-cert-status.md new file mode 100644 index 0000000000..445eb3dcd0 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/doh-cert-status.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: doh-cert-status +Help: Verify DoH server cert status OCSP-staple +Added: 7.76.0 +Category: dns tls +Protocols: DNS +Multi: boolean +See-also: + - doh-insecure +Example: + - --doh-cert-status --doh-url https://doh.example $URL +--- + +# `--doh-cert-status` + +Same as --cert-status but used for DoH (DNS-over-HTTPS). + +Verify the status of the DoH servers' certificate by using the Certificate +Status Request (aka. OCSP stapling) TLS extension. + +If this option is enabled and the DoH server sends an invalid (e.g. expired) +response, if the response suggests that the server certificate has been +revoked, or no response at all is received, the verification fails. + +This support is currently only implemented in the OpenSSL and GnuTLS backends. diff --git a/third-party/curl/docs/cmdline-opts/doh-insecure.d b/third-party/curl/docs/cmdline-opts/doh-insecure.d deleted file mode 100644 index dcc65fb6c9..0000000000 --- a/third-party/curl/docs/cmdline-opts/doh-insecure.d +++ /dev/null @@ -1,11 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: doh-insecure -Help: Allow insecure DoH server connections -Added: 7.76.0 -Category: dns tls -Example: --doh-insecure --doh-url https://doh.example $URL -See-also: doh-url -Multi: boolean ---- -Same as --insecure but used for DoH (DNS-over-HTTPS). diff --git a/third-party/curl/docs/cmdline-opts/doh-insecure.md b/third-party/curl/docs/cmdline-opts/doh-insecure.md new file mode 100644 index 0000000000..ee1602a242 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/doh-insecure.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: doh-insecure +Help: Allow insecure DoH server connections +Added: 7.76.0 +Category: dns tls +Protocols: DNS +Multi: boolean +See-also: + - doh-url + - insecure + - proxy-insecure +Example: + - --doh-insecure --doh-url https://doh.example $URL +--- + +# `--doh-insecure` + +By default, every connection curl makes to a DoH server is verified to be +secure before the transfer takes place. This option tells curl to skip the +verification step and proceed without checking. + +**WARNING**: using this option makes the DoH transfer and name resolution +insecure. + +This option is equivalent to --insecure and --proxy-insecure but used for DoH +(DNS-over-HTTPS) only. diff --git a/third-party/curl/docs/cmdline-opts/doh-url.d b/third-party/curl/docs/cmdline-opts/doh-url.d deleted file mode 100644 index 6d0dd1605e..0000000000 --- a/third-party/curl/docs/cmdline-opts/doh-url.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: doh-url -Arg: -Help: Resolve host names over DoH -Added: 7.62.0 -Category: dns -Example: --doh-url https://doh.example $URL -See-also: doh-insecure -Multi: single ---- -Specifies which DNS-over-HTTPS (DoH) server to use to resolve hostnames, -instead of using the default name resolver mechanism. The URL must be HTTPS. - -Some SSL options that you set for your transfer also applies to DoH since the -name lookups take place over SSL. However, the certificate verification -settings are not inherited but are controlled separately via --doh-insecure -and --doh-cert-status. - -This option is unset if an empty string "" is used as the URL. -(Added in 7.85.0) diff --git a/third-party/curl/docs/cmdline-opts/doh-url.md b/third-party/curl/docs/cmdline-opts/doh-url.md new file mode 100644 index 0000000000..3d146a789c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/doh-url.md @@ -0,0 +1,31 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: doh-url +Arg: +Help: Resolve hostnames over DoH +Added: 7.62.0 +Category: dns +Protocols: DNS +Multi: single +See-also: + - doh-insecure +Example: + - --doh-url https://doh.example $URL + - --doh-url https://doh.example --resolve doh.example:443:192.0.2.1 $URL +--- + +# `--doh-url` + +Specify which DNS-over-HTTPS (DoH) server to use to resolve hostnames, instead +of using the default name resolver mechanism. The URL must be HTTPS. + +Some SSL options that you set for your transfer also apply to DoH since the +name lookups take place over SSL. The certificate verification settings are +not inherited but are controlled separately via --doh-insecure and +--doh-cert-status. + +By default, DoH is bypassed when initially looking up DNS records of the DoH server. You can specify the IP address(es) of the DoH server with --resolve to avoid this. + +This option is unset if an empty string "" is used as the URL. +(Added in 7.85.0) diff --git a/third-party/curl/docs/cmdline-opts/dump-ca-embed.md b/third-party/curl/docs/cmdline-opts/dump-ca-embed.md new file mode 100644 index 0000000000..2ad123014b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/dump-ca-embed.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: dump-ca-embed +Help: Write the embedded CA bundle to standard output +Protocols: TLS +Category: http proxy tls +Added: 8.10.0 +Multi: boolean +See-also: + - ca-native + - cacert + - capath + - proxy-ca-native + - proxy-cacert + - proxy-capath +Example: + - --dump-ca-embed +--- + +# `--dump-ca-embed` + +Write the CA bundle embedded in curl to standard output, then quit. + +If curl was not built with a default CA bundle embedded, the output is empty. diff --git a/third-party/curl/docs/cmdline-opts/dump-header.d b/third-party/curl/docs/cmdline-opts/dump-header.d deleted file mode 100644 index 42a79e7ddf..0000000000 --- a/third-party/curl/docs/cmdline-opts/dump-header.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: dump-header -Short: D -Arg: -Help: Write the received headers to -Protocols: HTTP FTP -See-also: output -Category: http ftp -Example: --dump-header store.txt $URL -Added: 5.7 -Multi: single ---- -Write the received protocol headers to the specified file. If no headers are -received, the use of this option creates an empty file. - -When used in FTP, the FTP server response lines are considered being "headers" -and thus are saved there. - -Having multiple transfers in one set of operations (i.e. the URLs in one ---next clause), appends them to the same file, separated by a blank line. diff --git a/third-party/curl/docs/cmdline-opts/dump-header.md b/third-party/curl/docs/cmdline-opts/dump-header.md new file mode 100644 index 0000000000..bdb0e874e3 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/dump-header.md @@ -0,0 +1,35 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: dump-header +Short: D +Arg: +Help: Write the received headers to +Protocols: HTTP FTP +Category: http ftp +Added: 5.7 +Multi: single +See-also: + - output +Example: + - --dump-header store.txt $URL + - --dump-header - $URL -o save +--- + +# `--dump-header` + +Write the received protocol headers to the specified file. If no headers are +received, the use of this option creates an empty file. Specify `-` as +filename (a single minus) to have it written to stdout. + +Starting in curl 8.10.0, specify `%` (a single percent sign) as filename +writes the output to stderr. + +When used in FTP, the FTP server response lines are considered being "headers" +and thus are saved there. + +Starting in curl 8.11.0, using the --create-dirs option can also create +missing directory components for the path provided in --dump-header. + +Having multiple transfers in one set of operations (i.e. the URLs in one +--next clause), appends them to the same file, separated by a blank line. diff --git a/third-party/curl/docs/cmdline-opts/ech.md b/third-party/curl/docs/cmdline-opts/ech.md new file mode 100644 index 0000000000..3d8f3873af --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ech.md @@ -0,0 +1,52 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ech +Arg: +Help: Configure ECH +Added: 8.8.0 +Category: tls +Protocols: HTTPS +Multi: single +See-also: + - doh-url +Example: + - --ech true $URL +--- + +# `--ech` + +Specify how to do ECH (Encrypted Client Hello). + +The values allowed for \ can be: + +## `false` + +Do not attempt ECH. The is the default. + +## `grease` + +Send a GREASE ECH extension + +## `true` + +Attempt ECH if possible, but do not fail if ECH is not attempted. +(The connection fails if ECH is attempted but fails.) + +## `hard` + +Attempt ECH and fail if that is not possible. ECH only works with TLS 1.3 and +also requires using DoH or providing an ECHConfigList on the command line. + +## `ecl:` + +A base64 encoded ECHConfigList that is used for ECH. + +## `pn:` + +A name to use to over-ride the `public_name` field of an ECHConfigList (only +available with OpenSSL TLS support) + +## + +Most ECH related errors cause error *CURLE_ECH_REQUIRED* (101). diff --git a/third-party/curl/docs/cmdline-opts/egd-file.d b/third-party/curl/docs/cmdline-opts/egd-file.d deleted file mode 100644 index 4543ecf15e..0000000000 --- a/third-party/curl/docs/cmdline-opts/egd-file.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: egd-file -Arg: -Help: EGD socket path for random data -Protocols: TLS -See-also: random-file -Category: tls -Example: --egd-file /random/here $URL -Added: 7.7 -Multi: single ---- -Deprecated option (added in 7.84.0). Prior to that it only had an effect on -curl if built to use old versions of OpenSSL. - -Specify the path name to the Entropy Gathering Daemon socket. The socket is -used to seed the random engine for SSL connections. diff --git a/third-party/curl/docs/cmdline-opts/egd-file.md b/third-party/curl/docs/cmdline-opts/egd-file.md new file mode 100644 index 0000000000..ef16b99648 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/egd-file.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: egd-file +Arg: +Help: EGD socket path for random data +Protocols: TLS +Category: deprecated +Added: 7.7 +Multi: single +See-also: + - random-file +Example: + - --egd-file /random/here $URL +--- + +# `--egd-file` + +Deprecated option (added in 7.84.0). Prior to that it only had an effect on +curl if built to use old versions of OpenSSL. + +Specify the path name to the Entropy Gathering Daemon socket. The socket is +used to seed the random engine for SSL connections. diff --git a/third-party/curl/docs/cmdline-opts/engine.d b/third-party/curl/docs/cmdline-opts/engine.d deleted file mode 100644 index 1ebc779c0d..0000000000 --- a/third-party/curl/docs/cmdline-opts/engine.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: engine -Arg: -Help: Crypto engine to use -Protocols: TLS -Category: tls -Example: --engine flavor $URL -Added: 7.9.3 -See-also: ciphers curves -Multi: single ---- -Select the OpenSSL crypto engine to use for cipher operations. Use --engine -list to print a list of build-time supported engines. Note that not all (and -possibly none) of the engines may be available at runtime. diff --git a/third-party/curl/docs/cmdline-opts/engine.md b/third-party/curl/docs/cmdline-opts/engine.md new file mode 100644 index 0000000000..cde6949b86 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/engine.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: engine +Arg: +Help: Crypto engine to use +Protocols: TLS +Category: tls +Added: 7.9.3 +Multi: single +See-also: + - ciphers + - curves +Example: + - --engine flavor $URL +--- + +# `--engine` + +Select the OpenSSL crypto engine to use for cipher operations. Use `--engine +list` to print a list of build-time supported engines. Note that not all (and +possibly none) of the engines may be available at runtime. + +The OpenSSL concept "engines" has been superseded by "providers" in OpenSSL 3, +and this option should work fine to specify such as well. diff --git a/third-party/curl/docs/cmdline-opts/etag-compare.d b/third-party/curl/docs/cmdline-opts/etag-compare.d deleted file mode 100644 index d3c48d17a6..0000000000 --- a/third-party/curl/docs/cmdline-opts/etag-compare.d +++ /dev/null @@ -1,23 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: etag-compare -Arg: -Help: Pass an ETag from a file as a custom header -Protocols: HTTP -Added: 7.68.0 -Category: http -Example: --etag-compare etag.txt $URL -See-also: etag-save time-cond -Multi: single ---- -This option makes a conditional HTTP request for the specific ETag read -from the given file by sending a custom If-None-Match header using the -stored ETag. - -For correct results, make sure that the specified file contains only a -single line with the desired ETag. An empty file is parsed as an empty -ETag. - -Use the option --etag-save to first save the ETag from a response, and -then use this option to compare against the saved ETag in a subsequent -request. diff --git a/third-party/curl/docs/cmdline-opts/etag-compare.md b/third-party/curl/docs/cmdline-opts/etag-compare.md new file mode 100644 index 0000000000..64ab80cd12 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/etag-compare.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: etag-compare +Arg: +Help: Load ETag from file +Protocols: HTTP +Added: 7.68.0 +Category: http +Multi: single +See-also: + - etag-save + - time-cond +Example: + - --etag-compare etag.txt $URL +--- + +# `--etag-compare` + +Make a conditional HTTP request for the specific ETag read from the given file +by sending a custom If-None-Match header using the stored ETag. + +For correct results, make sure that the specified file contains only a single +line with the desired ETag. A non-existing or empty file is treated as an +empty ETag. + +Use the option --etag-save to first save the ETag from a response, and then +use this option to compare against the saved ETag in a subsequent request. + +Use this option with a single URL only. diff --git a/third-party/curl/docs/cmdline-opts/etag-save.d b/third-party/curl/docs/cmdline-opts/etag-save.d deleted file mode 100644 index 6295a9e311..0000000000 --- a/third-party/curl/docs/cmdline-opts/etag-save.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: etag-save -Arg: -Help: Parse ETag from a request and save it to a file -Protocols: HTTP -Added: 7.68.0 -Category: http -Example: --etag-save storetag.txt $URL -See-also: etag-compare -Multi: single ---- -This option saves an HTTP ETag to the specified file. An ETag is a -caching related header, usually returned in a response. - -If no ETag is sent by the server, an empty file is created. diff --git a/third-party/curl/docs/cmdline-opts/etag-save.md b/third-party/curl/docs/cmdline-opts/etag-save.md new file mode 100644 index 0000000000..137a4d5a55 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/etag-save.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: etag-save +Arg: +Help: Parse incoming ETag and save to a file +Protocols: HTTP +Added: 7.68.0 +Category: http +Multi: single +See-also: + - etag-compare +Example: + - --etag-save storetag.txt $URL +--- + +# `--etag-save` + +Save an HTTP ETag to the specified file. An ETag is a caching related header, +usually returned in a response. Use this option with a single URL only. + +If no ETag is sent by the server, an empty file is created. + +In many situations you want to use an existing etag in the request to avoid +downloading the same resource again but also save the new etag if it has +indeed changed, by using both etag options --etag-save and --etag-compare with +the same filename, in the same command line. + +Starting in curl 8.12.0, using the --create-dirs option can also create +missing directory components for the path provided in --etag-save. diff --git a/third-party/curl/docs/cmdline-opts/expect100-timeout.d b/third-party/curl/docs/cmdline-opts/expect100-timeout.d deleted file mode 100644 index f9a119bd97..0000000000 --- a/third-party/curl/docs/cmdline-opts/expect100-timeout.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: expect100-timeout -Arg: -Help: How long to wait for 100-continue -Protocols: HTTP -Added: 7.47.0 -See-also: connect-timeout -Category: http -Example: --expect100-timeout 2.5 -T file $URL -Multi: single ---- -Maximum time in seconds that you allow curl to wait for a 100-continue -response when curl emits an Expects: 100-continue header in its request. By -default curl waits one second. This option accepts decimal values! When -curl stops waiting, it continues as if the response has been received. - -The decimal value needs to provided using a dot (.) as decimal separator - not -the local version even if it might be using another separator. diff --git a/third-party/curl/docs/cmdline-opts/expect100-timeout.md b/third-party/curl/docs/cmdline-opts/expect100-timeout.md new file mode 100644 index 0000000000..80cf4eba61 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/expect100-timeout.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: expect100-timeout +Arg: +Help: How long to wait for 100-continue +Protocols: HTTP +Added: 7.47.0 +Category: http timeout +Multi: single +See-also: + - connect-timeout +Example: + - --expect100-timeout 2.5 -T file $URL +--- + +# `--expect100-timeout` + +Maximum time in seconds that you allow curl to wait for a 100-continue +response when curl emits an Expects: 100-continue header in its request. By +default curl waits one second. This option accepts decimal values. When curl +stops waiting, it continues as if a response was received. + +The decimal value needs to be provided using a dot (`.`) as decimal separator - +not the local version even if it might be using another separator. diff --git a/third-party/curl/docs/cmdline-opts/fail-early.d b/third-party/curl/docs/cmdline-opts/fail-early.d deleted file mode 100644 index 36b3309996..0000000000 --- a/third-party/curl/docs/cmdline-opts/fail-early.d +++ /dev/null @@ -1,25 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: fail-early -Help: Fail on first transfer error, do not continue -Added: 7.52.0 -Category: curl -Example: --fail-early $URL https://two.example -See-also: fail fail-with-body -Multi: boolean -Scope: global ---- -Fail and exit on the first detected transfer error. - -When curl is used to do multiple transfers on the command line, it attempts to -operate on each given URL, one by one. By default, it ignores errors if there -are more URLs given and the last URL's success determines the error code curl -returns. So early failures are "hidden" by subsequent successful transfers. - -Using this option, curl instead returns an error on the first transfer that -fails, independent of the amount of URLs that are given on the command -line. This way, no transfer failures go undetected by scripts and similar. - -This option does not imply --fail, which causes transfers to fail due to the -server's HTTP status code. You can combine the two options, however note --fail -is not global and is therefore contained by --next. diff --git a/third-party/curl/docs/cmdline-opts/fail-early.md b/third-party/curl/docs/cmdline-opts/fail-early.md new file mode 100644 index 0000000000..67edbf919e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/fail-early.md @@ -0,0 +1,32 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: fail-early +Help: Fail on first transfer error +Added: 7.52.0 +Category: curl global +Multi: boolean +Scope: global +See-also: + - fail + - fail-with-body +Example: + - --fail-early $URL https://two.example +--- + +# `--fail-early` + +Fail and exit on the first detected transfer error. + +When curl is used to do multiple transfers on the command line, it attempts to +operate on each given URL, one by one. By default, it ignores errors if there +are more URLs given and the last URL's success determines the error code curl +returns. Early failures are "hidden" by subsequent successful transfers. + +Using this option, curl instead returns an error on the first transfer that +fails, independent of the amount of URLs that are given on the command +line. This way, no transfer failures go undetected by scripts and similar. + +This option does not imply --fail, which causes transfers to fail due to the +server's HTTP status code. You can combine the two options, however note --fail +is not global and is therefore contained by --next. diff --git a/third-party/curl/docs/cmdline-opts/fail-with-body.d b/third-party/curl/docs/cmdline-opts/fail-with-body.d deleted file mode 100644 index dddb86e229..0000000000 --- a/third-party/curl/docs/cmdline-opts/fail-with-body.d +++ /dev/null @@ -1,20 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: fail-with-body -Protocols: HTTP -Help: Fail on HTTP errors but save the body -Category: http output -Added: 7.76.0 -See-also: fail fail-early -Mutexed: fail -Example: --fail-with-body $URL -Multi: boolean ---- -Return an error on server errors where the HTTP response code is 400 or -greater). In normal cases when an HTTP server fails to deliver a document, it -returns an HTML document stating so (which often also describes why and -more). This flag allows curl to output and save that content but also to -return error 22. - -This is an alternative option to --fail which makes curl fail for the same -circumstances but without saving the content. diff --git a/third-party/curl/docs/cmdline-opts/fail-with-body.md b/third-party/curl/docs/cmdline-opts/fail-with-body.md new file mode 100644 index 0000000000..670959ba9b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/fail-with-body.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: fail-with-body +Protocols: HTTP +Help: Fail on HTTP errors but save the body +Category: http output +Added: 7.76.0 +Mutexed: fail +Multi: boolean +See-also: + - fail + - fail-early +Example: + - --fail-with-body $URL +--- + +# `--fail-with-body` + +Return an error on server errors where the HTTP response code is 400 or +greater). In normal cases when an HTTP server fails to deliver a document, it +returns an HTML document stating so (which often also describes why and more). +This option allows curl to output and save that content but also to return +error 22. + +This is an alternative option to --fail which makes curl fail for the same +circumstances but without saving the content. diff --git a/third-party/curl/docs/cmdline-opts/fail.d b/third-party/curl/docs/cmdline-opts/fail.d deleted file mode 100644 index 8196a908de..0000000000 --- a/third-party/curl/docs/cmdline-opts/fail.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: fail -Short: f -Protocols: HTTP -Help: Fail fast with no output on HTTP errors -See-also: fail-with-body fail-early -Category: important http -Example: --fail $URL -Mutexed: fail-with-body -Added: 4.0 -Multi: boolean ---- -Fail fast with no output at all on server errors. This is useful to enable -scripts and users to better deal with failed attempts. In normal cases when an -HTTP server fails to deliver a document, it returns an HTML document stating -so (which often also describes why and more). This flag prevents curl from -outputting that and return error 22. - -This method is not fail-safe and there are occasions where non-successful -response codes slip through, especially when authentication is involved -(response codes 401 and 407). diff --git a/third-party/curl/docs/cmdline-opts/fail.md b/third-party/curl/docs/cmdline-opts/fail.md new file mode 100644 index 0000000000..0c8db1367b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/fail.md @@ -0,0 +1,35 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: fail +Short: f +Protocols: HTTP +Help: Fail fast with no output on HTTP errors +Category: important http +Mutexed: fail-with-body +Added: 4.0 +Multi: boolean +See-also: + - fail-with-body + - fail-early +Example: + - --fail $URL +--- + +# `--fail` + +Fail with error code 22 and with no response body output at all for HTTP +transfers returning HTTP response codes at 400 or greater. + +In normal cases when an HTTP server fails to deliver a document, it returns a +body of text stating so (which often also describes why and more) and a 4xx +HTTP response code. This command line option prevents curl from outputting +that data and instead returns error 22 early. By default, curl does not +consider HTTP response codes to indicate failure. + +To get both the error code and also save the content, use --fail-with-body +instead. + +This method is not fail-safe and there are occasions where non-successful +response codes slip through, especially when authentication is involved +(response codes 401 and 407). diff --git a/third-party/curl/docs/cmdline-opts/false-start.d b/third-party/curl/docs/cmdline-opts/false-start.d deleted file mode 100644 index 73240492b9..0000000000 --- a/third-party/curl/docs/cmdline-opts/false-start.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: false-start -Help: Enable TLS False Start -Protocols: TLS -Added: 7.42.0 -Category: tls -Example: --false-start $URL -See-also: tcp-fastopen -Multi: boolean ---- -Tells curl to use false start during the TLS handshake. False start is a mode -where a TLS client starts sending application data before verifying the -server's Finished message, thus saving a round trip when performing a full -handshake. - -This is currently only implemented in the Secure Transport (on iOS 7.0 or -later, or OS X 10.9 or later) backend. diff --git a/third-party/curl/docs/cmdline-opts/false-start.md b/third-party/curl/docs/cmdline-opts/false-start.md new file mode 100644 index 0000000000..7c8c976698 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/false-start.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: false-start +Help: Enable TLS False Start +Protocols: TLS +Added: 7.42.0 +Category: deprecated +Multi: boolean +See-also: + - tcp-fastopen +Example: + - --false-start $URL +--- + +# `--false-start` + +No TLS backend currently supports this feature. + +Use false start during the TLS handshake. False start is a mode where a TLS +client starts sending application data before verifying the server's Finished +message, thus saving a round trip when performing a full handshake. diff --git a/third-party/curl/docs/cmdline-opts/follow.md b/third-party/curl/docs/cmdline-opts/follow.md new file mode 100644 index 0000000000..b34e30c693 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/follow.md @@ -0,0 +1,33 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: follow +Help: Follow redirects per spec +Category: http +Protocols: HTTP +Added: 8.16.0 +Multi: boolean +See-also: + - request + - location + - proto-redir + - max-redirs +Example: + - -X POST --follow $URL +--- + +# `--follow` + +Instructs curl to follow HTTP redirects and to do the custom request method +set with --request when following redirects as the HTTP specification says. + +The method string set with --request is used in subsequent requests for the +status codes 307 or 308, but may be reset to GET for 301, 302 and 303. + +This is subtly different than --location, as that option always sets the custom +method in all subsequent requests independent of response code. + +Restrict which protocols a redirect is accepted to follow with --proto-redir. + +When --netrc is used in combination with this option, credentials for the +followed-to hosts may also be selected from that file. diff --git a/third-party/curl/docs/cmdline-opts/form-escape.d b/third-party/curl/docs/cmdline-opts/form-escape.d deleted file mode 100644 index 304bfe8149..0000000000 --- a/third-party/curl/docs/cmdline-opts/form-escape.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: form-escape -Help: Escape multipart form field/file names using backslash -Protocols: HTTP -See-also: form -Added: 7.81.0 -Category: http upload -Example: --form-escape -F 'field\\name=curl' -F 'file=@load"this' $URL -Multi: single ---- -Tells curl to pass on names of multipart form fields and files using -backslash-escaping instead of percent-encoding. diff --git a/third-party/curl/docs/cmdline-opts/form-escape.md b/third-party/curl/docs/cmdline-opts/form-escape.md new file mode 100644 index 0000000000..7cf1cb7403 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/form-escape.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: form-escape +Help: Escape form fields using backslash +Protocols: HTTP IMAP SMTP +Added: 7.81.0 +Category: http upload post +Multi: single +See-also: + - form +Example: + - --form-escape -F 'field\name=curl' -F 'file=@load"this' $URL +--- + +# `--form-escape` + +Pass on names of multipart form fields and files using backslash-escaping +instead of percent-encoding. diff --git a/third-party/curl/docs/cmdline-opts/form-string.d b/third-party/curl/docs/cmdline-opts/form-string.d deleted file mode 100644 index 6d7a500a44..0000000000 --- a/third-party/curl/docs/cmdline-opts/form-string.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: form-string -Help: Specify multipart MIME data -Protocols: HTTP SMTP IMAP -Arg: -See-also: form -Category: http upload -Example: --form-string "data" $URL -Added: 7.13.2 -Multi: append ---- -Similar to --form except that the value string for the named parameter is used -literally. Leading '@' and '<' characters, and the ';type=' string in -the value have no special meaning. Use this in preference to --form if -there is any possibility that the string value may accidentally trigger the -'@' or '<' features of --form. diff --git a/third-party/curl/docs/cmdline-opts/form-string.md b/third-party/curl/docs/cmdline-opts/form-string.md new file mode 100644 index 0000000000..e58ad625d9 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/form-string.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: form-string +Help: Specify multipart MIME data +Protocols: HTTP SMTP IMAP +Arg: +Category: http upload post smtp imap +Added: 7.13.2 +Multi: append +See-also: + - form +Example: + - --form-string "name=data" $URL +--- + +# `--form-string` + +Similar to --form except that the value string for the named parameter is used +literally. Leading @ and \< characters, and the `;type=` string in the value +have no special meaning. Use this in preference to --form if there is any +possibility that the string value may accidentally trigger the @ or \< +features of --form. diff --git a/third-party/curl/docs/cmdline-opts/form.d b/third-party/curl/docs/cmdline-opts/form.d deleted file mode 100644 index e53e93ae0d..0000000000 --- a/third-party/curl/docs/cmdline-opts/form.d +++ /dev/null @@ -1,134 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: form -Short: F -Arg: -Help: Specify multipart MIME data -Protocols: HTTP SMTP IMAP -Mutexed: data head upload-file -Category: http upload -Example: --form "name=curl" --form "file=@loadthis" $URL -Added: 5.0 -See-also: data form-string form-escape -Multi: append ---- -For HTTP protocol family, this lets curl emulate a filled-in form in which a -user has pressed the submit button. This causes curl to POST data using the -Content-Type multipart/form-data according to RFC 2388. - -For SMTP and IMAP protocols, this is the means to compose a multipart mail -message to transmit. - -This enables uploading of binary files etc. To force the 'content' part to be -a file, prefix the file name with an @ sign. To just get the content part from -a file, prefix the file name with the symbol <. The difference between @ and < -is then that @ makes a file get attached in the post as a file upload, while -the < makes a text field and just get the contents for that text field from a -file. - -Tell curl to read content from stdin instead of a file by using - as -filename. This goes for both @ and < constructs. When stdin is used, the -contents is buffered in memory first by curl to determine its size and allow a -possible resend. Defining a part's data from a named non-regular file (such as -a named pipe or similar) is not subject to buffering and is instead read at -transmission time; since the full size is unknown before the transfer starts, -such data is sent as chunks by HTTP and rejected by IMAP. - -Example: send an image to an HTTP server, where 'profile' is the name of the -form-field to which the file **portrait.jpg** is the input: - - curl -F profile=@portrait.jpg https://example.com/upload.cgi - -Example: send your name and shoe size in two text fields to the server: - - curl -F name=John -F shoesize=11 https://example.com/ - -Example: send your essay in a text field to the server. Send it as a plain -text field, but get the contents for it from a local file: - - curl -F "story=HTML message;type=text/html' \\ - -F '=)' -F '=@textfile.txt' ... smtp://example.com - -Data can be encoded for transfer using encoder=. Available encodings are -*binary* and *8bit* that do nothing else than adding the corresponding -Content-Transfer-Encoding header, *7bit* that only rejects 8-bit characters -with a transfer error, *quoted-printable* and *base64* that encodes data -according to the corresponding schemes, limiting lines length to 76 -characters. - -Example: send multipart mail with a quoted-printable text message and a -base64 attached file: - - curl -F '=text message;encoder=quoted-printable' \\ - -F '=@localfile;encoder=base64' ... smtp://example.com - -See further examples and details in the MANUAL. diff --git a/third-party/curl/docs/cmdline-opts/form.md b/third-party/curl/docs/cmdline-opts/form.md new file mode 100644 index 0000000000..87b019604f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/form.md @@ -0,0 +1,143 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: form +Short: F +Arg: +Help: Specify multipart MIME data +Protocols: HTTP SMTP IMAP +Mutexed: data head upload-file +Category: http upload post imap smtp +Added: 5.0 +Multi: append +See-also: + - data + - form-string + - form-escape +Example: + - --form "name=curl" --form "file=@loadthis" $URL +--- + +# `--form` + +For the HTTP protocol family, emulate a filled-in form in which a user has +pressed the submit button. This makes curl POST data using the Content-Type +multipart/form-data according to RFC 2388. + +For SMTP and IMAP protocols, this composes a multipart mail message to +transmit. + +This enables uploading of binary files etc. To force the 'content' part to be +a file, prefix the filename with an @ sign. To get the content part from a +file, prefix the filename with the symbol \<. The difference between @ and \< +is then that @ makes a file get attached in the post as a file upload, while +the \< makes a text field and gets the contents for that text field from a +file. + +Read content from stdin instead of a file by using a single "-" as filename. +This goes for both @ and \< constructs. When stdin is used, the contents is +buffered in memory first by curl to determine its size and allow a possible +resend. Defining a part's data from a named non-regular file (such as a named +pipe or similar) is not subject to buffering and is instead read at +transmission time; since the full size is unknown before the transfer starts, +such data is sent as chunks by HTTP and rejected by IMAP. + +Example: send an image to an HTTP server, where 'profile' is the name of the +form-field to which the file **portrait.jpg** is the input: + + curl -F profile=@portrait.jpg https://example.com/upload.cgi + +Example: send your name and shoe size in two text fields to the server: + + curl -F name=John -F shoesize=11 https://example.com/ + +Example: send your essay in a text field to the server. Send it as a plain +text field, but get the contents for it from a local file: + + curl -F "story=HTML message;type=text/html' \ + -F '=)' -F '=@textfile.txt' ... smtp://example.com + +Data can be encoded for transfer using encoder=. Available encodings are +*binary* and *8bit* that do nothing else than adding the corresponding +Content-Transfer-Encoding header, *7bit* that only rejects 8-bit characters +with a transfer error, *quoted-printable* and *base64* that encodes data +according to the corresponding schemes, limiting lines length to 76 +characters. + +Example: send multipart mail with a quoted-printable text message and a +base64 attached file: + + curl -F '=text message;encoder=quoted-printable' \ + -F '=@localfile;encoder=base64' ... smtp://example.com diff --git a/third-party/curl/docs/cmdline-opts/ftp-account.d b/third-party/curl/docs/cmdline-opts/ftp-account.d deleted file mode 100644 index eb669c5628..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-account.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-account -Arg: -Help: Account data string -Protocols: FTP -Added: 7.13.0 -Category: ftp auth -Example: --ftp-account "mr.robot" ftp://example.com/ -See-also: user -Multi: single ---- -When an FTP server asks for "account data" after user name and password has -been provided, this data is sent off using the ACCT command. diff --git a/third-party/curl/docs/cmdline-opts/ftp-account.md b/third-party/curl/docs/cmdline-opts/ftp-account.md new file mode 100644 index 0000000000..e275349dee --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-account.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-account +Arg: +Help: Account data string +Protocols: FTP +Added: 7.13.0 +Category: ftp auth +Multi: single +See-also: + - user +Example: + - --ftp-account "mr.robot" ftp://example.com/ +--- + +# `--ftp-account` + +When an FTP server asks for "account data" after username and password has +been provided, this data is sent off using the ACCT command. diff --git a/third-party/curl/docs/cmdline-opts/ftp-alternative-to-user.d b/third-party/curl/docs/cmdline-opts/ftp-alternative-to-user.d deleted file mode 100644 index f030bcf598..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-alternative-to-user.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-alternative-to-user -Arg: -Help: String to replace USER [name] -Protocols: FTP -Added: 7.15.5 -Category: ftp -Example: --ftp-alternative-to-user "U53r" ftp://example.com -See-also: ftp-account user -Multi: single ---- -If authenticating with the USER and PASS commands fails, send this command. -When connecting to Tumbleweed's Secure Transport server over FTPS using a -client certificate, using "SITE AUTH" tells the server to retrieve the -username from the certificate. diff --git a/third-party/curl/docs/cmdline-opts/ftp-alternative-to-user.md b/third-party/curl/docs/cmdline-opts/ftp-alternative-to-user.md new file mode 100644 index 0000000000..9bd3686001 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-alternative-to-user.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-alternative-to-user +Arg: +Help: String to replace USER [name] +Protocols: FTP +Added: 7.15.5 +Category: ftp +Multi: single +See-also: + - ftp-account + - user +Example: + - --ftp-alternative-to-user "U53r" ftp://example.com +--- + +# `--ftp-alternative-to-user` + +If authenticating with the USER and PASS commands fails, send this command. +When connecting to Tumbleweed's Secure Transport server over FTPS using a +client certificate, using "SITE AUTH" tells the server to retrieve the +username from the certificate. diff --git a/third-party/curl/docs/cmdline-opts/ftp-create-dirs.d b/third-party/curl/docs/cmdline-opts/ftp-create-dirs.d deleted file mode 100644 index 7c64f0e21c..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-create-dirs.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-create-dirs -Protocols: FTP SFTP -Help: Create the remote dirs if not present -See-also: create-dirs -Category: ftp sftp curl -Example: --ftp-create-dirs -T file ftp://example.com/remote/path/file -Added: 7.10.7 -Multi: boolean ---- -When an FTP or SFTP URL/operation uses a path that does not currently exist on -the server, the standard behavior of curl is to fail. Using this option, curl -instead attempts to create missing directories. diff --git a/third-party/curl/docs/cmdline-opts/ftp-create-dirs.md b/third-party/curl/docs/cmdline-opts/ftp-create-dirs.md new file mode 100644 index 0000000000..3e851ccae9 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-create-dirs.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-create-dirs +Protocols: FTP SFTP +Help: Create the remote dirs if not present +Category: ftp sftp +Added: 7.10.7 +Multi: boolean +See-also: + - create-dirs +Example: + - --ftp-create-dirs -T file ftp://example.com/remote/path/file +--- + +# `--ftp-create-dirs` + +When an FTP or SFTP URL/operation uses a path that does not currently exist on +the server, the standard behavior of curl is to fail. Using this option, curl +instead attempts to create missing directories. diff --git a/third-party/curl/docs/cmdline-opts/ftp-method.d b/third-party/curl/docs/cmdline-opts/ftp-method.d deleted file mode 100644 index 8061d2b682..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-method.d +++ /dev/null @@ -1,30 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-method -Arg: -Help: Control CWD usage -Protocols: FTP -Added: 7.15.1 -Category: ftp -Example: --ftp-method multicwd ftp://example.com/dir1/dir2/file -Example: --ftp-method nocwd ftp://example.com/dir1/dir2/file -Example: --ftp-method singlecwd ftp://example.com/dir1/dir2/file -See-also: list-only -Multi: single ---- -Control what method curl should use to reach a file on an FTP(S) -server. The method argument should be one of the following alternatives: -.RS -.IP multicwd -curl does a single CWD operation for each path part in the given URL. For deep -hierarchies this means many commands. This is how RFC 1738 says it should -be done. This is the default but the slowest behavior. -.IP nocwd -curl does no CWD at all. curl does SIZE, RETR, STOR etc and give a full -path to the server for all these commands. This is the fastest behavior. -.IP singlecwd -curl does one CWD with the full target directory and then operates on the file -"normally" (like in the multicwd case). This is somewhat more standards -compliant than 'nocwd' but without the full penalty of 'multicwd'. -.RE -.IP diff --git a/third-party/curl/docs/cmdline-opts/ftp-method.md b/third-party/curl/docs/cmdline-opts/ftp-method.md new file mode 100644 index 0000000000..d2bff21d59 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-method.md @@ -0,0 +1,36 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-method +Arg: +Help: Control CWD usage +Protocols: FTP +Added: 7.15.1 +Category: ftp +Multi: single +See-also: + - list-only +Example: + - --ftp-method multicwd ftp://example.com/dir1/dir2/file + - --ftp-method nocwd ftp://example.com/dir1/dir2/file + - --ftp-method singlecwd ftp://example.com/dir1/dir2/file +--- + +# `--ftp-method` + +Control what method curl should use to reach a file on an FTP(S) +server. The method argument should be one of the following alternatives: + +## multicwd +Do a single CWD operation for each path part in the given URL. For deep +hierarchies this means many commands. This is how RFC 1738 says it should be +done. This is the default but the slowest behavior. + +## nocwd +Do no CWD at all. curl does SIZE, RETR, STOR etc and gives the full path to +the server for each of these commands. This is the fastest behavior. + +## singlecwd +Do one CWD with the full target directory and then operate on the file +"normally" (like in the multicwd case). This is somewhat more standards +compliant than `nocwd` but without the full penalty of `multicwd`. diff --git a/third-party/curl/docs/cmdline-opts/ftp-pasv.d b/third-party/curl/docs/cmdline-opts/ftp-pasv.d deleted file mode 100644 index c43bf2beea..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-pasv.d +++ /dev/null @@ -1,20 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-pasv -Help: Use PASV/EPSV instead of PORT -Protocols: FTP -Added: 7.11.0 -See-also: disable-epsv -Category: ftp -Example: --ftp-pasv ftp://example.com/ -Multi: boolean ---- -Use passive mode for the data connection. Passive is the internal default -behavior, but using this option can be used to override a previous --ftp-port -option. - -Reversing an enforced passive really is not doable but you must then instead -enforce the correct --ftp-port again. - -Passive mode means that curl tries the EPSV command first and then PASV, -unless --disable-epsv is used. diff --git a/third-party/curl/docs/cmdline-opts/ftp-pasv.md b/third-party/curl/docs/cmdline-opts/ftp-pasv.md new file mode 100644 index 0000000000..02deee30de --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-pasv.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-pasv +Help: Send PASV/EPSV instead of PORT +Protocols: FTP +Added: 7.11.0 +Category: ftp +Multi: mutex +Mutexed: ftp-port +See-also: + - disable-epsv +Example: + - --ftp-pasv ftp://example.com/ +--- + +# `--ftp-pasv` + +Use passive mode for the data connection. Passive is the internal default +behavior, but using this option can be used to override a previous --ftp-port +option. + +Reversing an enforced passive really is not doable but you must then instead +enforce the correct --ftp-port again. + +Passive mode means that curl tries the EPSV command first and then PASV, +unless --disable-epsv is used. diff --git a/third-party/curl/docs/cmdline-opts/ftp-port.d b/third-party/curl/docs/cmdline-opts/ftp-port.d deleted file mode 100644 index e1f4a1dba7..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-port.d +++ /dev/null @@ -1,41 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-port -Arg:
-Help: Use PORT instead of PASV -Short: P -Protocols: FTP -See-also: ftp-pasv disable-eprt -Category: ftp -Example: -P - ftp:/example.com -Example: -P eth0 ftp:/example.com -Example: -P 192.168.0.2 ftp:/example.com -Added: 4.0 -Multi: single ---- -Reverses the default initiator/listener roles when connecting with FTP. This -option makes curl use active mode. curl then tells the server to connect back -to the client's specified address and port, while passive mode asks the server -to setup an IP address and port for it to connect to.
should be one -of: -.RS -.IP interface -e.g. "eth0" to specify which interface's IP address you want to use (Unix only) -.IP "IP address" -e.g. "192.168.10.1" to specify the exact IP address -.IP "host name" -e.g. "my.host.domain" to specify the machine -.IP "-" -make curl pick the same IP address that is already used for the control -connection -.RE -.IP - -Disable the use of PORT with --ftp-pasv. Disable the attempt to use the EPRT -command instead of PORT by using --disable-eprt. EPRT is really PORT++. - -You can also append ":[start]-[end]\&" to the right of the address, to tell -curl what TCP port range to use. That means you specify a port range, from a -lower to a higher number. A single number works as well, but do note that it -increases the risk of failure since the port may not be available. -(Added in 7.19.5) diff --git a/third-party/curl/docs/cmdline-opts/ftp-port.md b/third-party/curl/docs/cmdline-opts/ftp-port.md new file mode 100644 index 0000000000..28cc34ba2f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-port.md @@ -0,0 +1,51 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-port +Arg:
+Help: Send PORT instead of PASV +Short: P +Protocols: FTP +Category: ftp +Added: 4.0 +Multi: single +See-also: + - ftp-pasv + - disable-eprt +Example: + - -P - ftp:/example.com + - -P eth0 ftp:/example.com + - -P 192.168.0.2 ftp:/example.com +--- + +# `--ftp-port` + +Reverse the default initiator/listener roles when connecting with FTP. This +option makes curl use active mode. curl then commands the server to connect +back to the client's specified address and port, while passive mode asks the +server to setup an IP address and port for it to connect to. \ +should be one of: + +## interface +e.g. **eth0** to specify which interface's IP address you want to use (Unix only) + +## IP address +e.g. **192.168.10.1** to specify the exact IP address + +## hostname +e.g. **my.host.domain** to specify the machine + +## - +make curl pick the same IP address that is already used for the control +connection. This is the recommended choice. + +## + +Disable the use of PORT with --ftp-pasv. Disable the attempt to use the EPRT +command instead of PORT by using --disable-eprt. EPRT is really PORT++. + +You can also append ":[start]-[end]" to the right of the address, to tell +curl what TCP port range to use. That means you specify a port range, from a +lower to a higher number. A single number works as well, but do note that it +increases the risk of failure since the port may not be available. +(Added in 7.19.5) diff --git a/third-party/curl/docs/cmdline-opts/ftp-pret.d b/third-party/curl/docs/cmdline-opts/ftp-pret.d deleted file mode 100644 index 4bea99e6d8..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-pret.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-pret -Help: Send PRET before PASV -Protocols: FTP -Added: 7.20.0 -Category: ftp -Example: --ftp-pret ftp://example.com/ -See-also: ftp-port ftp-pasv -Multi: boolean ---- -Tell curl to send a PRET command before PASV (and EPSV). Certain FTP servers, -mainly drftpd, require this non-standard command for directory listings as -well as up and downloads in PASV mode. diff --git a/third-party/curl/docs/cmdline-opts/ftp-pret.md b/third-party/curl/docs/cmdline-opts/ftp-pret.md new file mode 100644 index 0000000000..48c48e3e77 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-pret.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-pret +Help: Send PRET before PASV +Protocols: FTP +Added: 7.20.0 +Category: ftp +Multi: boolean +See-also: + - ftp-port + - ftp-pasv +Example: + - --ftp-pret ftp://example.com/ +--- + +# `--ftp-pret` + +Send a PRET command before PASV (and EPSV). Certain FTP servers, mainly +drftpd, require this non-standard command for directory listings as well as up +and downloads in PASV mode. diff --git a/third-party/curl/docs/cmdline-opts/ftp-skip-pasv-ip.d b/third-party/curl/docs/cmdline-opts/ftp-skip-pasv-ip.d deleted file mode 100644 index 3af9c6de4f..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-skip-pasv-ip.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-skip-pasv-ip -Help: Skip the IP address for PASV -Protocols: FTP -Added: 7.14.2 -See-also: ftp-pasv -Category: ftp -Example: --ftp-skip-pasv-ip ftp://example.com/ -Multi: boolean ---- -Tell curl to not use the IP address the server suggests in its response to -curl's PASV command when curl connects the data connection. Instead curl -reuses the same IP address it already uses for the control connection. - -This option is enabled by default (added in 7.74.0). - -This option has no effect if PORT, EPRT or EPSV is used instead of PASV. diff --git a/third-party/curl/docs/cmdline-opts/ftp-skip-pasv-ip.md b/third-party/curl/docs/cmdline-opts/ftp-skip-pasv-ip.md new file mode 100644 index 0000000000..37905e63b1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-skip-pasv-ip.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-skip-pasv-ip +Help: Skip the IP address for PASV +Protocols: FTP +Added: 7.15.0 +Category: ftp +Multi: boolean +See-also: + - ftp-pasv +Example: + - --ftp-skip-pasv-ip ftp://example.com/ +--- + +# `--ftp-skip-pasv-ip` + +Do not use the IP address the server suggests in its response to curl's PASV +command when curl connects the data connection. Instead curl reuses the same +IP address it already uses for the control connection. + +This option is enabled by default (added in 7.74.0). + +This option has no effect if PORT, EPRT or EPSV is used instead of PASV. diff --git a/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc-mode.d b/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc-mode.d deleted file mode 100644 index ae9af9429d..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc-mode.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-ssl-ccc-mode -Arg: -Help: Set CCC mode -Protocols: FTP -Added: 7.16.2 -See-also: ftp-ssl-ccc -Category: ftp tls -Example: --ftp-ssl-ccc-mode active --ftp-ssl-ccc ftps://example.com/ -Multi: boolean ---- -Sets the CCC mode. The passive mode does not initiate the shutdown, but -instead waits for the server to do it, and does not reply to the shutdown from -the server. The active mode initiates the shutdown and waits for a reply from -the server. diff --git a/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc-mode.md b/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc-mode.md new file mode 100644 index 0000000000..3e9eb725c6 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc-mode.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-ssl-ccc-mode +Arg: +Help: Set CCC mode +Protocols: FTP +Added: 7.16.2 +Category: ftp tls +Multi: boolean +See-also: + - ftp-ssl-ccc +Example: + - --ftp-ssl-ccc-mode active --ftp-ssl-ccc ftps://example.com/ +--- + +# `--ftp-ssl-ccc-mode` + +Set the CCC mode. The passive mode does not initiate the shutdown, but instead +waits for the server to do it, and does not reply to the shutdown from the +server. The active mode initiates the shutdown and waits for a reply from the +server. diff --git a/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc.d b/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc.d deleted file mode 100644 index 33ae83b1c9..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-ssl-ccc -Help: Send CCC after authenticating -Protocols: FTP -See-also: ssl ftp-ssl-ccc-mode -Added: 7.16.1 -Category: ftp tls -Example: --ftp-ssl-ccc ftps://example.com/ -Multi: boolean ---- -Use CCC (Clear Command Channel) Shuts down the SSL/TLS layer after -authenticating. The rest of the control channel communication is be -unencrypted. This allows NAT routers to follow the FTP transaction. The -default mode is passive. diff --git a/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc.md b/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc.md new file mode 100644 index 0000000000..40666646e9 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-ssl-ccc.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-ssl-ccc +Help: Send CCC after authenticating +Protocols: FTP +Added: 7.16.1 +Category: ftp tls +Multi: boolean +See-also: + - ssl + - ftp-ssl-ccc-mode +Example: + - --ftp-ssl-ccc ftps://example.com/ +--- + +# `--ftp-ssl-ccc` + +Use CCC (Clear Command Channel) Shuts down the SSL/TLS layer after +authenticating. The rest of the control channel communication is +unencrypted. This allows NAT routers to follow the FTP transaction. The +default mode is passive. diff --git a/third-party/curl/docs/cmdline-opts/ftp-ssl-control.d b/third-party/curl/docs/cmdline-opts/ftp-ssl-control.d deleted file mode 100644 index b895779271..0000000000 --- a/third-party/curl/docs/cmdline-opts/ftp-ssl-control.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ftp-ssl-control -Help: Require SSL/TLS for FTP login, clear for transfer -Protocols: FTP -Added: 7.16.0 -Category: ftp tls -Example: --ftp-ssl-control ftp://example.com -See-also: ssl -Multi: boolean ---- -Require SSL/TLS for the FTP login, clear for transfer. Allows secure -authentication, but non-encrypted data transfers for efficiency. Fails the -transfer if the server does not support SSL/TLS. diff --git a/third-party/curl/docs/cmdline-opts/ftp-ssl-control.md b/third-party/curl/docs/cmdline-opts/ftp-ssl-control.md new file mode 100644 index 0000000000..fa85de24f1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ftp-ssl-control.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ftp-ssl-control +Help: Require TLS for login, clear for transfer +Protocols: FTP +Added: 7.16.0 +Category: ftp tls +Multi: boolean +See-also: + - ssl +Example: + - --ftp-ssl-control ftp://example.com +--- + +# `--ftp-ssl-control` + +Require SSL/TLS for the FTP login, clear for transfer. Allows secure +authentication, but non-encrypted data transfers for efficiency. Fails the +transfer if the server does not support SSL/TLS. + +If set, this option overrides --ssl. diff --git a/third-party/curl/docs/cmdline-opts/gen.pl b/third-party/curl/docs/cmdline-opts/gen.pl deleted file mode 100644 index 8b9b98bb2d..0000000000 --- a/third-party/curl/docs/cmdline-opts/gen.pl +++ /dev/null @@ -1,744 +0,0 @@ -#!/usr/bin/env perl -#*************************************************************************** -# _ _ ____ _ -# Project ___| | | | _ \| | -# / __| | | | |_) | | -# | (__| |_| | _ <| |___ -# \___|\___/|_| \_\_____| -# -# Copyright (C) Daniel Stenberg, , et al. -# -# This software is licensed as described in the file COPYING, which -# you should have received as part of this distribution. The terms -# are also available at https://curl.se/docs/copyright.html. -# -# You may opt to use, copy, modify, merge, publish, distribute and/or sell -# copies of the Software, and permit persons to whom the Software is -# furnished to do so, under the terms of the COPYING file. -# -# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -# KIND, either express or implied. -# -# SPDX-License-Identifier: curl -# -########################################################################### - -=begin comment - -This script generates the manpage. - -Example: gen.pl [files] > curl.1 - -Dev notes: - -We open *input* files in :crlf translation (a no-op on many platforms) in -case we have CRLF line endings in Windows but a perl that defaults to LF. -Unfortunately it seems some perls like msysgit cannot handle a global input-only -:crlf so it has to be specified on each file open for text input. - -=end comment -=cut - -my %optshort; -my %optlong; -my %helplong; -my %arglong; -my %redirlong; -my %protolong; -my %catlong; - -use POSIX qw(strftime); -my $date = strftime "%B %d %Y", localtime; -my $year = strftime "%Y", localtime; -my $version = "unknown"; -my $globals; - -open(INC, "<../../include/curl/curlver.h"); -while() { - if($_ =~ /^#define LIBCURL_VERSION \"([0-9.]*)/) { - $version = $1; - last; - } -} -close(INC); - -# get the long name version, return the man page string -sub manpageify { - my ($k)=@_; - my $l; - my $klong = $k; - # quote "bare" minuses in the long name - $klong =~ s/-/\\-/g; - if($optlong{$k} ne "") { - # both short + long - $l = "\\fI-".$optlong{$k}.", \\-\\-$klong\\fP"; - } - else { - # only long - $l = "\\fI\\-\\-$klong\\fP"; - } - return $l; -} - -sub printdesc { - my @desc = @_; - my $exam = 0; - for my $d (@desc) { - if($d =~ /\(Added in ([0-9.]+)\)/i) { - my $ver = $1; - if(too_old($ver)) { - $d =~ s/ *\(Added in $ver\)//gi; - } - } - if($d !~ /^.\\"/) { - # **bold** - $d =~ s/\*\*([^ ]*)\*\*/\\fB$1\\fP/g; - # *italics* - $d =~ s/\*([^ ]*)\*/\\fI$1\\fP/g; - } - if(!$exam && ($d =~ /^ /)) { - # start of example - $exam = 1; - print ".nf\n"; # no-fill - } - elsif($exam && ($d !~ /^ /)) { - # end of example - $exam = 0; - print ".fi\n"; # fill-in - } - # skip lines starting with space (examples) - if($d =~ /^[^ ]/ && $d =~ /--/) { - # scan for options in longest-names first order - for my $k (sort {length($b) <=> length($a)} keys %optlong) { - # --tlsv1 is complicated since --tlsv1.2 etc are also - # acceptable options! - if(($k eq "tlsv1") && ($d =~ /--tlsv1\.[0-9]\\f/)) { - next; - } - my $l = manpageify($k); - $d =~ s/\-\-$k([^a-z0-9-])/$l$1/g; - } - } - # quote minuses in the output - $d =~ s/([^\\])-/$1\\-/g; - # replace single quotes - $d =~ s/\'/\\(aq/g; - # handle double quotes first on the line - $d =~ s/^(\s*)\"/$1\\(dq/; - print $d; - } - if($exam) { - print ".fi\n"; # fill-in - } -} - -sub seealso { - my($standalone, $data)=@_; - if($standalone) { - return sprintf - ".SH \"SEE ALSO\"\n$data\n"; - } - else { - return "See also $data. "; - } -} - -sub overrides { - my ($standalone, $data)=@_; - if($standalone) { - return ".SH \"OVERRIDES\"\n$data\n"; - } - else { - return $data; - } -} - -sub protocols { - my ($standalone, $data)=@_; - if($standalone) { - return ".SH \"PROTOCOLS\"\n$data\n"; - } - else { - return "($data) "; - } -} - -sub too_old { - my ($version)=@_; - my $a = 999999; - if($version =~ /^(\d+)\.(\d+)\.(\d+)/) { - $a = $1 * 1000 + $2 * 10 + $3; - } - elsif($version =~ /^(\d+)\.(\d+)/) { - $a = $1 * 1000 + $2 * 10; - } - if($a < 7500) { - # we consider everything before 7.50.0 to be too old to mention - # specific changes for - return 1; - } - return 0; -} - -sub added { - my ($standalone, $data)=@_; - if(too_old($data)) { - # do not mention ancient additions - return ""; - } - if($standalone) { - return ".SH \"ADDED\"\nAdded in curl version $data\n"; - } - else { - return "Added in $data. "; - } -} - -sub single { - my ($f, $standalone)=@_; - open(F, "<:crlf", "$f") || - return 1; - my $short; - my $long; - my $tags; - my $added; - my $protocols; - my $arg; - my $mutexed; - my $requires; - my $category; - my $seealso; - my $copyright; - my $spdx; - my @examples; # there can be more than one - my $magic; # cmdline special option - my $line; - my $multi; - my $scope; - my $experimental; - while() { - $line++; - if(/^Short: *(.)/i) { - $short=$1; - } - elsif(/^Long: *(.*)/i) { - $long=$1; - } - elsif(/^Added: *(.*)/i) { - $added=$1; - } - elsif(/^Tags: *(.*)/i) { - $tags=$1; - } - elsif(/^Arg: *(.*)/i) { - $arg=$1; - } - elsif(/^Magic: *(.*)/i) { - $magic=$1; - } - elsif(/^Mutexed: *(.*)/i) { - $mutexed=$1; - } - elsif(/^Protocols: *(.*)/i) { - $protocols=$1; - } - elsif(/^See-also: *(.*)/i) { - if($seealso) { - print STDERR "ERROR: duplicated See-also in $f\n"; - return 1; - } - $seealso=$1; - } - elsif(/^Requires: *(.*)/i) { - $requires=$1; - } - elsif(/^Category: *(.*)/i) { - $category=$1; - } - elsif(/^Example: *(.*)/i) { - push @examples, $1; - } - elsif(/^Multi: *(.*)/i) { - $multi=$1; - } - elsif(/^Scope: *(.*)/i) { - $scope=$1; - } - elsif(/^Experimental: yes/i) { - $experimental=1; - } - elsif(/^C: (.*)/i) { - $copyright=$1; - } - elsif(/^SPDX-License-Identifier: (.*)/i) { - $spdx=$1; - } - elsif(/^Help: *(.*)/i) { - ; - } - elsif(/^---/) { - if(!$long) { - print STDERR "ERROR: no 'Long:' in $f\n"; - return 1; - } - if(!$category) { - print STDERR "ERROR: no 'Category:' in $f\n"; - return 2; - } - if(!$examples[0]) { - print STDERR "$f:$line:1:ERROR: no 'Example:' present\n"; - return 2; - } - if(!$added) { - print STDERR "$f:$line:1:ERROR: no 'Added:' version present\n"; - return 2; - } - if(!$seealso) { - print STDERR "$f:$line:1:ERROR: no 'See-also:' field present\n"; - return 2; - } - if(!$copyright) { - print STDERR "$f:$line:1:ERROR: no 'C:' field present\n"; - return 2; - } - if(!$spdx) { - print STDERR "$f:$line:1:ERROR: no 'SPDX-License-Identifier:' field present\n"; - return 2; - } - last; - } - else { - chomp; - print STDERR "WARN: unrecognized line in $f, ignoring:\n:'$_';" - } - } - my @desc; - while() { - push @desc, $_; - } - close(F); - my $opt; - - if(defined($short) && $long) { - $opt = "-$short, --$long"; - } - elsif($short && !$long) { - $opt = "-$short"; - } - elsif($long && !$short) { - $opt = "--$long"; - } - - if($arg) { - $opt .= " $arg"; - } - - # quote "bare" minuses in opt - $opt =~ s/-/\\-/g; - if($standalone) { - print ".TH curl 1 \"30 Nov 2016\" \"curl 7.52.0\" \"curl manual\"\n"; - print ".SH OPTION\n"; - print "curl $opt\n"; - } - else { - print ".IP \"$opt\"\n"; - } - if($protocols) { - print protocols($standalone, $protocols); - } - - if($standalone) { - print ".SH DESCRIPTION\n"; - } - - if($experimental) { - print "**WARNING**: this option is experimental. Do not use in production.\n\n"; - } - - printdesc(@desc); - undef @desc; - - if($scope) { - if($scope eq "global") { - print "\nThis option is global and does not need to be specified for each use of --next.\n"; - } - else { - print STDERR "$f:$line:1:ERROR: unrecognized scope: '$scope'\n"; - return 2; - } - } - - my @extra; - if($multi eq "single") { - push @extra, "\nIf --$long is provided several times, the last set ". - "value is used.\n"; - } - elsif($multi eq "append") { - push @extra, "\n--$long can be used several times in a command line\n"; - } - elsif($multi eq "boolean") { - my $rev = "no-$long"; - # for options that start with "no-" the reverse is then without - # the no- prefix - if($long =~ /^no-/) { - $rev = $long; - $rev =~ s/^no-//; - } - push @extra, - "\nProviding --$long multiple times has no extra effect.\n". - "Disable it again with \\-\\-$rev.\n"; - } - elsif($multi eq "mutex") { - push @extra, - "\nProviding --$long multiple times has no extra effect.\n"; - } - elsif($multi eq "custom") { - ; # left for the text to describe - } - else { - print STDERR "$f:$line:1:ERROR: unrecognized Multi: '$multi'\n"; - return 2; - } - - printdesc(@extra); - - my @foot; - if($seealso) { - my @m=split(/ /, $seealso); - my $mstr; - my $and = 0; - my $num = scalar(@m); - if($num > 2) { - # use commas up to this point - $and = $num - 1; - } - my $i = 0; - for my $k (@m) { - if(!$helplong{$k}) { - print STDERR "$f:$line:1:WARN: see-also a non-existing option: $k\n"; - } - my $l = manpageify($k); - my $sep = " and"; - if($and && ($i < $and)) { - $sep = ","; - } - $mstr .= sprintf "%s$l", $mstr?"$sep ":""; - $i++; - } - push @foot, seealso($standalone, $mstr); - } - - if($requires) { - my $l = manpageify($long); - push @foot, "$l requires that the underlying libcurl". - " was built to support $requires. "; - } - if($mutexed) { - my @m=split(/ /, $mutexed); - my $mstr; - for my $k (@m) { - if(!$helplong{$k}) { - print STDERR "WARN: $f mutexes a non-existing option: $k\n"; - } - my $l = manpageify($k); - $mstr .= sprintf "%s$l", $mstr?" and ":""; - } - push @foot, overrides($standalone, - "This option is mutually exclusive to $mstr. "); - } - if($examples[0]) { - my $s =""; - $s="s" if($examples[1]); - print "\nExample$s:\n.nf\n"; - foreach my $e (@examples) { - $e =~ s!\$URL!https://example.com!g; - $e =~ s/-/\\-/g; - $e =~ s/\'/\\(aq/g; - print " curl $e\n"; - } - print ".fi\n"; - } - if($added) { - push @foot, added($standalone, $added); - } - if($foot[0]) { - print "\n"; - my $f = join("", @foot); - $f =~ s/ +\z//; # remove trailing space - print "$f\n"; - } - return 0; -} - -sub getshortlong { - my ($f)=@_; - open(F, "<:crlf", "$f"); - my $short; - my $long; - my $help; - my $arg; - my $protocols; - my $category; - while() { - if(/^Short: (.)/i) { - $short=$1; - } - elsif(/^Long: (.*)/i) { - $long=$1; - } - elsif(/^Help: (.*)/i) { - $help=$1; - } - elsif(/^Arg: (.*)/i) { - $arg=$1; - } - elsif(/^Protocols: (.*)/i) { - $protocols=$1; - } - elsif(/^Category: (.*)/i) { - $category=$1; - } - elsif(/^---/) { - last; - } - } - close(F); - if($short) { - $optshort{$short}=$long; - } - if($long) { - $optlong{$long}=$short; - $helplong{$long}=$help; - $arglong{$long}=$arg; - $protolong{$long}=$protocols; - $catlong{$long}=$category; - } -} - -sub indexoptions { - my (@files) = @_; - foreach my $f (@files) { - getshortlong($f); - } -} - -sub header { - my ($f)=@_; - open(F, "<:crlf", "$f"); - my @d; - while() { - s/%DATE/$date/g; - s/%VERSION/$version/g; - s/%GLOBALS/$globals/g; - push @d, $_; - } - close(F); - printdesc(@d); -} - -sub listhelp { - print <, et al. - * - * This software is licensed as described in the file COPYING, which - * you should have received as part of this distribution. The terms - * are also available at https://curl.se/docs/copyright.html. - * - * You may opt to use, copy, modify, merge, publish, distribute and/or sell - * copies of the Software, and permit persons to whom the Software is - * furnished to do so, under the terms of the COPYING file. - * - * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY - * KIND, either express or implied. - * - * SPDX-License-Identifier: curl - * - ***************************************************************************/ -#include "tool_setup.h" -#include "tool_help.h" - -/* - * DO NOT edit tool_listhelp.c manually. - * This source file is generated with the following command: - - cd \$srcroot/docs/cmdline-opts - ./gen.pl listhelp *.d > \$srcroot/src/tool_listhelp.c - */ - -const struct helptxt helptext[] = { -HEAD - ; - foreach my $f (sort keys %helplong) { - my $long = $f; - my $short = $optlong{$long}; - my @categories = split ' ', $catlong{$long}; - my $bitmask = ' '; - my $opt; - - if(defined($short) && $long) { - $opt = "-$short, --$long"; - } - elsif($long && !$short) { - $opt = " --$long"; - } - for my $i (0 .. $#categories) { - $bitmask .= 'CURLHELP_' . uc $categories[$i]; - # If not last element, append | - if($i < $#categories) { - $bitmask .= ' | '; - } - } - $bitmask =~ s/(?=.{76}).{1,76}\|/$&\n /g; - my $arg = $arglong{$long}; - if($arg) { - $opt .= " $arg"; - } - my $desc = $helplong{$f}; - $desc =~ s/\"/\\\"/g; # escape double quotes - - my $line = sprintf " {\"%s\",\n \"%s\",\n %s},\n", $opt, $desc, $bitmask; - - if(length($opt) > 78) { - print STDERR "WARN: the --$long name is too long\n"; - } - elsif(length($desc) > 78) { - print STDERR "WARN: the --$long description is too long\n"; - } - print $line; - } - print <) { - if(/^Long: *(.*)/i) { - $long=$1; - } - elsif(/^Scope: global/i) { - push @globalopts, $long; - last; - } - elsif(/^---/) { - last; - } - } - close(F); - } - return $ret if($ret); - for my $e (0 .. $#globalopts) { - $globals .= sprintf "%s--%s", $e?($globalopts[$e+1] ? ", " : " and "):"", - $globalopts[$e],; - } -} - -sub mainpage { - my (@files) = @_; - my $ret; - # show the page header - header("page-header"); - - # output docs for all options - foreach my $f (sort @files) { - $ret += single($f, 0); - } - - if(!$ret) { - header("page-footer"); - } - exit $ret if($ret); -} - -sub showonly { - my ($f) = @_; - if(single($f, 1)) { - print STDERR "$f: failed\n"; - } -} - -sub showprotocols { - my %prots; - foreach my $f (keys %optlong) { - my @p = split(/ /, $protolong{$f}); - for my $p (@p) { - $prots{$p}++; - } - } - for(sort keys %prots) { - printf "$_ (%d options)\n", $prots{$_}; - } -} - -sub getargs { - my ($f, @s) = @_; - if($f eq "mainpage") { - listglobals(@s); - mainpage(@s); - return; - } - elsif($f eq "listhelp") { - listhelp(); - return; - } - elsif($f eq "single") { - showonly($s[0]); - return; - } - elsif($f eq "protos") { - showprotocols(); - return; - } - elsif($f eq "listcats") { - listcats(); - return; - } - - print "Usage: gen.pl [files]\n"; -} - -#------------------------------------------------------------------------ - -my $cmd = shift @ARGV; -my @files = @ARGV; # the rest are the files - -# learn all existing options -indexoptions(@files); - -getargs($cmd, @files); diff --git a/third-party/curl/docs/cmdline-opts/get.d b/third-party/curl/docs/cmdline-opts/get.d deleted file mode 100644 index 2e03a255bc..0000000000 --- a/third-party/curl/docs/cmdline-opts/get.d +++ /dev/null @@ -1,20 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: get -Short: G -Help: Put the post data in the URL and use GET -Category: http upload -Example: --get $URL -Example: --get -d "tool=curl" -d "age=old" $URL -Example: --get -I -d "tool=curl" $URL -Added: 7.8.1 -See-also: data request -Multi: boolean ---- -When used, this option makes all data specified with --data, --data-binary -or --data-urlencode to be used in an HTTP GET request instead of the POST -request that otherwise would be used. The data is appended to the URL -with a '?' separator. - -If used in combination with --head, the POST data is instead appended to the -URL with a HEAD request. diff --git a/third-party/curl/docs/cmdline-opts/get.md b/third-party/curl/docs/cmdline-opts/get.md new file mode 100644 index 0000000000..ac0560ab69 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/get.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: get +Short: G +Help: Put the post data in the URL and use GET +Protocols: HTTP +Category: http +Added: 7.8.1 +Multi: boolean +See-also: + - data + - request +Example: + - --get $URL + - --get -d "tool=curl" -d "age=old" $URL + - --get -I -d "tool=curl" $URL +--- + +# `--get` + +When used, this option makes all data specified with --data, --data-binary or +--data-urlencode to be used in an HTTP GET request instead of the POST request +that otherwise would be used. curl appends the provided data to the URL as a +query string. + +If used in combination with --head, the POST data is instead appended to the +URL with a HEAD request. diff --git a/third-party/curl/docs/cmdline-opts/globoff.d b/third-party/curl/docs/cmdline-opts/globoff.d deleted file mode 100644 index 53bed6ec84..0000000000 --- a/third-party/curl/docs/cmdline-opts/globoff.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: globoff -Short: g -Help: Disable URL sequences and ranges using {} and [] -Category: curl -Example: -g "https://example.com/{[]}}}}" -Added: 7.6 -See-also: config disable -Multi: boolean ---- -This option switches off the "URL globbing parser". When you set this option, -you can specify URLs that contain the letters {}[] without having curl itself -interpret them. Note that these letters are not normal legal URL contents but -they should be encoded according to the URI standard. diff --git a/third-party/curl/docs/cmdline-opts/globoff.md b/third-party/curl/docs/cmdline-opts/globoff.md new file mode 100644 index 0000000000..5ef4b2ae88 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/globoff.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: globoff +Short: g +Help: Disable URL globbing with {} and [] +Category: curl +Added: 7.6 +Multi: boolean +See-also: + - config + - disable +Example: + - -g "https://example.com/{[]}}}}" +--- + +# `--globoff` + +Switch off the URL globbing function. When you set this option, you can +specify URLs that contain the letters {}[] without having curl itself +interpret them. Note that these letters are not normal legal URL contents but +they should be encoded according to the URI standard. + +curl detects numerical IPv6 addresses when used in URLs and excludes them from +the treatment, so they can still be used without having to disable globbing. diff --git a/third-party/curl/docs/cmdline-opts/happy-eyeballs-timeout-ms.d b/third-party/curl/docs/cmdline-opts/happy-eyeballs-timeout-ms.d deleted file mode 100644 index 29114e209a..0000000000 --- a/third-party/curl/docs/cmdline-opts/happy-eyeballs-timeout-ms.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: happy-eyeballs-timeout-ms -Arg: -Help: Time for IPv6 before trying IPv4 -Added: 7.59.0 -Category: connection -Example: --happy-eyeballs-timeout-ms 500 $URL -See-also: max-time connect-timeout -Multi: single ---- -Happy Eyeballs is an algorithm that attempts to connect to both IPv4 and IPv6 -addresses for dual-stack hosts, giving IPv6 a head-start of the specified -number of milliseconds. If the IPv6 address cannot be connected to within that -time, then a connection attempt is made to the IPv4 address in parallel. The -first connection to be established is the one that is used. - -The range of suggested useful values is limited. Happy Eyeballs RFC 6555 says -"It is RECOMMENDED that connection attempts be paced 150-250 ms apart to -balance human factors against network load." libcurl currently defaults to -200 ms. Firefox and Chrome currently default to 300 ms. diff --git a/third-party/curl/docs/cmdline-opts/happy-eyeballs-timeout-ms.md b/third-party/curl/docs/cmdline-opts/happy-eyeballs-timeout-ms.md new file mode 100644 index 0000000000..f1abb37725 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/happy-eyeballs-timeout-ms.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: happy-eyeballs-timeout-ms +Arg: +Help: Time for IPv6 before IPv4 +Added: 7.59.0 +Category: connection timeout +Multi: single +See-also: + - max-time + - connect-timeout +Example: + - --happy-eyeballs-timeout-ms 500 $URL +--- + +# `--happy-eyeballs-timeout-ms` + +Set the timeout for Happy Eyeballs. + +Happy Eyeballs is an algorithm that attempts to connect to both IPv4 and IPv6 +addresses for dual-stack hosts, giving IPv6 a head-start of the specified +number of milliseconds. If the IPv6 address cannot be connected to within that +time, then a connection attempt is made to the IPv4 address in parallel. The +first connection to be established is the one that is used. + +The range of suggested useful values is limited. Happy Eyeballs RFC 6555 says +"It is RECOMMENDED that connection attempts be paced 150-250 ms apart to +balance human factors against network load." libcurl currently defaults to +200 ms. Firefox and Chrome currently default to 300 ms. diff --git a/third-party/curl/docs/cmdline-opts/haproxy-clientip.d b/third-party/curl/docs/cmdline-opts/haproxy-clientip.d deleted file mode 100644 index 25cb7e6236..0000000000 --- a/third-party/curl/docs/cmdline-opts/haproxy-clientip.d +++ /dev/null @@ -1,29 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: haproxy-clientip -Help: Sets client IP in HAProxy PROXY protocol v1 header -Protocols: HTTP -Added: 8.2.0 -Category: http proxy -Example: --haproxy-clientip $IP -See-also: proxy -Multi: single ---- -Sets a client IP in HAProxy PROXY protocol v1 header at the beginning of the -connection. - -For valid requests, IPv4 addresses must be indicated as a series of exactly -4 integers in the range [0..255] inclusive written in decimal representation -separated by exactly one dot between each other. Heading zeroes are not -permitted in front of numbers in order to avoid any possible confusion -with octal numbers. IPv6 addresses must be indicated as series of 4 hexadecimal -digits (upper or lower case) delimited by colons between each other, with the -acceptance of one double colon sequence to replace the largest acceptable range -of consecutive zeroes. The total number of decoded bits must exactly be 128. - -Otherwise, any string can be accepted for the client IP and get sent. - -It replaces --haproxy-protocol if used, it is not necessary to specify both flags. - -This option is primarily useful when sending test requests to -verify a service is working as intended. diff --git a/third-party/curl/docs/cmdline-opts/haproxy-clientip.md b/third-party/curl/docs/cmdline-opts/haproxy-clientip.md new file mode 100644 index 0000000000..4bbf26ecce --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/haproxy-clientip.md @@ -0,0 +1,33 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: haproxy-clientip +Arg: +Help: Set address in HAProxy PROXY +Protocols: HTTP +Added: 8.2.0 +Category: http proxy +Multi: single +See-also: + - proxy +Example: + - --haproxy-clientip $IP +--- + +# `--haproxy-clientip` + +Set a client IP in HAProxy PROXY protocol v1 header at the beginning of the +connection. + +For valid requests, IPv4 addresses must be indicated as a series of exactly +4 integers in the range [0..255] inclusive written in decimal representation +separated by exactly one dot between each other. Heading zeroes are not +permitted in front of numbers in order to avoid any possible confusion +with octal numbers. IPv6 addresses must be indicated as series of 4 hexadecimal +digits (upper or lower case) delimited by colons between each other, with the +acceptance of one double colon sequence to replace the largest acceptable range +of consecutive zeroes. The total number of decoded bits must be exactly 128. + +Otherwise, any string can be accepted for the client IP and get sent. + +It replaces --haproxy-protocol if used, it is not necessary to specify both flags. diff --git a/third-party/curl/docs/cmdline-opts/haproxy-protocol.d b/third-party/curl/docs/cmdline-opts/haproxy-protocol.d deleted file mode 100644 index 34119062e4..0000000000 --- a/third-party/curl/docs/cmdline-opts/haproxy-protocol.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: haproxy-protocol -Help: Send HAProxy PROXY protocol v1 header -Protocols: HTTP -Added: 7.60.0 -Category: http proxy -Example: --haproxy-protocol $URL -See-also: proxy -Multi: boolean ---- -Send a HAProxy PROXY protocol v1 header at the beginning of the -connection. This is used by some load balancers and reverse proxies to -indicate the client's true IP address and port. - -This option is primarily useful when sending test requests to a service that -expects this header. diff --git a/third-party/curl/docs/cmdline-opts/haproxy-protocol.md b/third-party/curl/docs/cmdline-opts/haproxy-protocol.md new file mode 100644 index 0000000000..26456c80bf --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/haproxy-protocol.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: haproxy-protocol +Help: Send HAProxy PROXY protocol v1 header +Protocols: HTTP +Added: 7.60.0 +Category: http proxy +Multi: boolean +See-also: + - proxy +Example: + - --haproxy-protocol $URL +--- + +# `--haproxy-protocol` + +Send a HAProxy PROXY protocol v1 header at the beginning of the connection. +This is used by some load balancers and reverse proxies to indicate the +client's true IP address and port. + +This option is primarily useful when sending test requests to a service that +expects this header. diff --git a/third-party/curl/docs/cmdline-opts/head.d b/third-party/curl/docs/cmdline-opts/head.d deleted file mode 100644 index bb748b72ef..0000000000 --- a/third-party/curl/docs/cmdline-opts/head.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: head -Short: I -Help: Show document info only -Protocols: HTTP FTP FILE -Category: http ftp file -Example: -I $URL -Added: 4.0 -See-also: get verbose trace-ascii -Multi: boolean ---- -Fetch the headers only! HTTP-servers feature the command HEAD which this uses -to get nothing but the header of a document. When used on an FTP or FILE file, -curl displays the file size and last modification time only. diff --git a/third-party/curl/docs/cmdline-opts/head.md b/third-party/curl/docs/cmdline-opts/head.md new file mode 100644 index 0000000000..7e005c7254 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/head.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: head +Short: I +Help: Show document info only +Protocols: HTTP FTP FILE +Category: important http ftp file +Added: 4.0 +Multi: boolean +See-also: + - get + - verbose + - trace-ascii +Example: + - -I $URL +--- + +# `--head` + +Fetch the headers only. HTTP-servers feature the command HEAD which this uses +to get nothing but the header of a document. When used on an FTP or FILE URL, +curl displays the file size and last modification time only. diff --git a/third-party/curl/docs/cmdline-opts/header.d b/third-party/curl/docs/cmdline-opts/header.d deleted file mode 100644 index f5b7685524..0000000000 --- a/third-party/curl/docs/cmdline-opts/header.d +++ /dev/null @@ -1,56 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: header -Short: H -Arg:
-Help: Pass custom header(s) to server -Protocols: HTTP IMAP SMTP -Category: http imap smtp -See-also: user-agent referer -Example: -H "X-First-Name: Joe" $URL -Example: -H "User-Agent: yes-please/2000" $URL -Example: -H "Host:" $URL -Example: -H @headers.txt $URL -Added: 5.0 -Multi: append ---- -Extra header to include in information sent. When used within an HTTP request, -it is added to the regular request headers. - -For an IMAP or SMTP MIME uploaded mail built with --form options, it is -prepended to the resulting MIME document, effectively including it at the mail -global level. It does not affect raw uploaded mails (Added in 7.56.0). - -You may specify any number of extra headers. Note that if you should add a -custom header that has the same name as one of the internal ones curl would -use, your externally set header is used instead of the internal one. This -allows you to make even trickier stuff than curl would normally do. You should -not replace internally set headers without knowing perfectly well what you are -doing. Remove an internal header by giving a replacement without content on -the right side of the colon, as in: -H "Host:". If you send the custom header -with no-value then its header must be terminated with a semicolon, such as \-H -"X-Custom-Header;" to send "X-Custom-Header:". - -curl makes sure that each header you add/replace is sent with the proper -end-of-line marker, you should thus **not** add that as a part of the header -content: do not add newlines or carriage returns, they only mess things up for -you. - -This option can take an argument in @filename style, which then adds a header -for each line in the input file. Using @- makes curl read the header file from -stdin. Added in 7.55.0. - -Please note that most anti-spam utilities check the presence and value of -several MIME mail headers: these are "From:", "To:", "Date:" and "Subject:" -among others and should be added with this option. - -You need --proxy-header to send custom headers intended for an HTTP -proxy. Added in 7.37.0. - -Passing on a "Transfer-Encoding: chunked" header when doing an HTTP request -with a request body, makes curl send the data using chunked encoding. - -**WARNING**: headers set with this option are set in all HTTP requests - even -after redirects are followed, like when told with --location. This can lead to -the header being sent to other hosts than the original host, so sensitive -headers should be used with caution combined with following redirects. diff --git a/third-party/curl/docs/cmdline-opts/header.md b/third-party/curl/docs/cmdline-opts/header.md new file mode 100644 index 0000000000..9e1f2029e0 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/header.md @@ -0,0 +1,69 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: header +Short: H +Arg:
+Help: Pass custom header(s) to server +Protocols: HTTP IMAP SMTP +Category: important http imap smtp +Added: 5.0 +Multi: append +See-also: + - user-agent + - referer + - proxy-header +Example: + - -H "X-First-Name: Joe" $URL + - -H "User-Agent: yes-please/2000" $URL + - -H "Host:" $URL + - -H @headers.txt $URL +--- + +# `--header` + +Extra header to include in information sent. When used within an HTTP request, +it is added to the regular request headers. + +For an IMAP or SMTP MIME uploaded mail built with --form options, it is +prepended to the resulting MIME document, effectively including it at the mail +global level. It does not affect raw uploaded mails (Added in 7.56.0). + +You may specify any number of extra headers. Note that if you should add a +custom header that has the same name as one of the internal ones curl would +use, your externally set header is used instead of the internal one. This +allows you to make even trickier stuff than curl would normally do. You should +not replace internally set headers without knowing perfectly well what you are +doing. Remove an internal header by giving a replacement without content on +the right side of the colon, as in: -H `Host:`. If you send the custom header +with no-value then its header must be terminated with a semicolon, such as -H +`X-Custom-Header;` to send `X-Custom-Header:`. + +curl makes sure that each header you add/replace is sent with the proper +end-of-line marker, you should thus **not** add that as a part of the header +content: do not add newlines or carriage returns, they only mess things up for +you. curl passes on the verbatim string you give it without any filter or +other safe guards. That includes white space and control characters. + +This option can take an argument in @filename style, which then adds a header +for each line in the input file. Using @- makes curl read the header file from +stdin. (Added in 7.55.0) + +Please note that most anti-spam utilities check the presence and value of +several MIME mail headers: these are `From:`, `To:`, `Date:` and `Subject:` +among others and should be added with this option. + +You need --proxy-header to send custom headers intended for an HTTP proxy. +(Added in 7.37.0) + +Passing on a `Transfer-Encoding: chunked` header when doing an HTTP request +with a request body, makes curl send the data using chunked encoding. + +**WARNING**: headers set with this option are set in all HTTP requests - even +after redirects are followed, like when told with --location. This can lead to +the header being sent to other hosts than the original host, so sensitive +headers should be used with caution combined with following redirects. + +`Authorization:` and `Cookie:` headers are explicitly *not* passed on in HTTP +requests when following redirects to other origins, unless --location-trusted +is used. diff --git a/third-party/curl/docs/cmdline-opts/help.d b/third-party/curl/docs/cmdline-opts/help.d deleted file mode 100644 index f8675e4842..0000000000 --- a/third-party/curl/docs/cmdline-opts/help.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: help -Arg: -Short: h -Help: Get help for commands -Category: important curl -Example: --help all -Added: 4.0 -See-also: verbose -Multi: custom ---- -Usage help. This lists all curl command line options within the given -**category**. - -If no argument is provided, curl displays only the most important command line -arguments. - -For category **all**, curl displays help for all options. - -If **category** is specified, curl displays all available help categories. diff --git a/third-party/curl/docs/cmdline-opts/help.md b/third-party/curl/docs/cmdline-opts/help.md new file mode 100644 index 0000000000..122c55cd43 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/help.md @@ -0,0 +1,39 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: help +Arg: +Short: h +Help: Get help for commands +Category: important curl +Added: 4.0 +Multi: custom +See-also: + - verbose +Example: + - --help all + - --help --insecure + - --help -f +--- + +# `--help` + +Usage help. Provide help for the subject given as an optional argument. + +If no argument is provided, curl displays the most important command line +arguments. + +The argument can either be a **category** or a **command line option**. When a +category is provided, curl shows all command line options within the given +category. Specify category `all` to list all available options. + +If `category` is specified, curl displays all available help categories. + +If the provided subject is instead an existing command line option, specified +either in its short form with a single dash and a single letter, or in the +long form with two dashes and a longer name, curl displays a help text for +that option in the terminal. + +The help output is extensive for some options. + +If the provided command line option is not known, curl says so. diff --git a/third-party/curl/docs/cmdline-opts/hostpubmd5.d b/third-party/curl/docs/cmdline-opts/hostpubmd5.d deleted file mode 100644 index e9db23db08..0000000000 --- a/third-party/curl/docs/cmdline-opts/hostpubmd5.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: hostpubmd5 -Arg: -Help: Acceptable MD5 hash of the host public key -Protocols: SFTP SCP -Added: 7.17.1 -Category: sftp scp -Example: --hostpubmd5 e5c1c49020640a5ab0f2034854c321a8 sftp://example.com/ -See-also: hostpubsha256 -Multi: single ---- -Pass a string containing 32 hexadecimal digits. The string should -be the 128 bit MD5 checksum of the remote host's public key, curl refuses -the connection with the host unless the md5sums match. diff --git a/third-party/curl/docs/cmdline-opts/hostpubmd5.md b/third-party/curl/docs/cmdline-opts/hostpubmd5.md new file mode 100644 index 0000000000..5d480a5bcd --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/hostpubmd5.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: hostpubmd5 +Arg: +Help: Acceptable MD5 hash of host public key +Protocols: SFTP SCP +Added: 7.17.1 +Category: sftp scp ssh +Multi: single +See-also: + - hostpubsha256 +Example: + - --hostpubmd5 e5c1c49020640a5ab0f2034854c321a8 sftp://example.com/ +--- + +# `--hostpubmd5` + +Pass a string containing 32 hexadecimal digits. The string should be the 128 +bit **MD5** checksum of the remote host's public key, curl refuses the +connection with the host unless the checksums match. diff --git a/third-party/curl/docs/cmdline-opts/hostpubsha256.d b/third-party/curl/docs/cmdline-opts/hostpubsha256.d deleted file mode 100644 index b33f338bdd..0000000000 --- a/third-party/curl/docs/cmdline-opts/hostpubsha256.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: hostpubsha256 -Arg: -Help: Acceptable SHA256 hash of the host public key -Protocols: SFTP SCP -Added: 7.80.0 -Category: sftp scp -Example: --hostpubsha256 NDVkMTQxMGQ1ODdmMjQ3MjczYjAyOTY5MmRkMjVmNDQ= sftp://example.com/ -See-also: hostpubmd5 -Multi: single ---- -Pass a string containing a Base64-encoded SHA256 hash of the remote host's -public key. Curl refuses the connection with the host unless the hashes match. - -This feature requires libcurl to be built with libssh2 and does not work with -other SSH backends. diff --git a/third-party/curl/docs/cmdline-opts/hostpubsha256.md b/third-party/curl/docs/cmdline-opts/hostpubsha256.md new file mode 100644 index 0000000000..a92dbe5d7c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/hostpubsha256.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: hostpubsha256 +Arg: +Help: Acceptable SHA256 hash of host public key +Protocols: SFTP SCP +Added: 7.80.0 +Category: sftp scp ssh +Multi: single +See-also: + - hostpubmd5 +Example: + - --hostpubsha256 NDVkMTQxMGQ1ODdmMjQ3MjczYjAyOTY5MmRkMjVmNDQ= sftp://example.com/ +--- + +# `--hostpubsha256` + +Pass a string containing a Base64-encoded SHA256 hash of the remote host's +public key. curl refuses the connection with the host unless the hashes match. diff --git a/third-party/curl/docs/cmdline-opts/hsts.d b/third-party/curl/docs/cmdline-opts/hsts.d deleted file mode 100644 index e30d3b419d..0000000000 --- a/third-party/curl/docs/cmdline-opts/hsts.d +++ /dev/null @@ -1,26 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: hsts -Arg: -Protocols: HTTPS -Help: Enable HSTS with this cache file -Added: 7.74.0 -Category: http -Example: --hsts cache.txt $URL -See-also: proto -Multi: append ---- -This option enables HSTS for the transfer. If the file name points to an -existing HSTS cache file, that is used. After a completed transfer, the -cache is saved to the file name again if it has been modified. - -If curl is told to use HTTP:// for a transfer involving a host name that -exists in the HSTS cache, it upgrades the transfer to use HTTPS. Each HSTS -cache entry has an individual life time after which the upgrade is no longer -performed. - -Specify a "" file name (zero length) to avoid loading/saving and make curl -just handle HSTS in memory. - -If this option is used several times, curl loads contents from all the -files but the last one is used for saving. diff --git a/third-party/curl/docs/cmdline-opts/hsts.md b/third-party/curl/docs/cmdline-opts/hsts.md new file mode 100644 index 0000000000..7653c65cd5 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/hsts.md @@ -0,0 +1,40 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: hsts +Arg: +Protocols: HTTPS +Help: Enable HSTS with this cache file +Added: 7.74.0 +Category: http +Multi: append +See-also: + - proto +Example: + - --hsts cache.txt $URL +--- + +# `--hsts` + +Enable HSTS for the transfer. If the filename points to an existing HSTS cache +file, that is used. After a completed transfer, the cache is saved to the +filename again if it has been modified. If you run multiple curl invokes at +the same time using the same HSTS cache file, they might interfere with each +other in possibly undesired ways. + +If curl is told to use `http://` for a transfer involving a hostname that +exists in the HSTS cache, it upgrades the transfer to use HTTPS. Each HSTS +cache entry has an individual lifetime after which the upgrade is no longer +performed. + +Specify a "" filename (zero length) to avoid loading/saving and make curl +handle HSTS in memory. + +You may want to restrict your umask to prevent other users on the same system +to access the created file. + +If this option is used several times, curl loads contents from all the +files but the last one is used for saving. + +Since curl 8.20.0, curl keeps no more than the most recently added 10,000 +unique HSTS hostnames. diff --git a/third-party/curl/docs/cmdline-opts/http0.9.d b/third-party/curl/docs/cmdline-opts/http0.9.d deleted file mode 100644 index 3dd14a05ce..0000000000 --- a/third-party/curl/docs/cmdline-opts/http0.9.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: http0.9 -Tags: Versions -Protocols: HTTP -Help: Allow HTTP 0.9 responses -Category: http -Example: --http0.9 $URL -Added: 7.64.0 -See-also: http1.1 http2 http3 -Multi: boolean ---- -Tells curl to be fine with HTTP version 0.9 response. - -HTTP/0.9 is a response without headers and therefore you can also connect with -this to non-HTTP servers and still get a response since curl simply -transparently downgrades - if allowed. - -HTTP/0.9 is disabled by default (added in 7.66.0) diff --git a/third-party/curl/docs/cmdline-opts/http0.9.md b/third-party/curl/docs/cmdline-opts/http0.9.md new file mode 100644 index 0000000000..65be14491c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/http0.9.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: http0.9 +Tags: Versions +Protocols: HTTP +Help: Allow HTTP/0.9 responses +Category: http +Added: 7.64.0 +Multi: boolean +See-also: + - http1.1 + - http2 + - http3 +Example: + - --http0.9 $URL +--- + +# `--http0.9` + +Accept an HTTP version 0.9 response. + +HTTP/0.9 is a response without headers and therefore you can also connect with +this to non-HTTP servers and still get a response since curl +transparently downgrades - if allowed. + +HTTP/0.9 is disabled by default (added in 7.66.0) diff --git a/third-party/curl/docs/cmdline-opts/http1.0.d b/third-party/curl/docs/cmdline-opts/http1.0.d deleted file mode 100644 index c5f4de872e..0000000000 --- a/third-party/curl/docs/cmdline-opts/http1.0.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: 0 -Long: http1.0 -Tags: Versions -Protocols: HTTP -Added: 7.9.1 -Mutexed: http1.1 http2 http2-prior-knowledge http3 -Help: Use HTTP 1.0 -Category: http -Example: --http1.0 $URL -See-also: http0.9 http1.1 -Multi: mutex ---- -Tells curl to use HTTP version 1.0 instead of using its internally preferred -HTTP version. diff --git a/third-party/curl/docs/cmdline-opts/http1.0.md b/third-party/curl/docs/cmdline-opts/http1.0.md new file mode 100644 index 0000000000..0252f05230 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/http1.0.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: 0 +Long: http1.0 +Tags: Versions +Protocols: HTTP +Added: 7.9.1 +Mutexed: http1.1 http2 http2-prior-knowledge http3 +Help: Use HTTP/1.0 +Category: http +Multi: mutex +See-also: + - http0.9 + - http1.1 +Example: + - --http1.0 $URL +--- + +# `--http1.0` + +Use HTTP version 1.0 instead of using its internally preferred HTTP version. diff --git a/third-party/curl/docs/cmdline-opts/http1.1.d b/third-party/curl/docs/cmdline-opts/http1.1.d deleted file mode 100644 index 3057aed36d..0000000000 --- a/third-party/curl/docs/cmdline-opts/http1.1.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: http1.1 -Tags: Versions -Protocols: HTTP -Added: 7.33.0 -Mutexed: http1.0 http2 http2-prior-knowledge http3 -Help: Use HTTP 1.1 -Category: http -Example: --http1.1 $URL -See-also: http1.0 http0.9 -Multi: mutex ---- -Tells curl to use HTTP version 1.1. diff --git a/third-party/curl/docs/cmdline-opts/http1.1.md b/third-party/curl/docs/cmdline-opts/http1.1.md new file mode 100644 index 0000000000..3d241e5c59 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/http1.1.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: http1.1 +Tags: Versions +Protocols: HTTP +Added: 7.33.0 +Mutexed: http1.0 http2 http2-prior-knowledge http3 +Help: Use HTTP/1.1 +Category: http +Multi: mutex +See-also: + - http1.0 + - http0.9 +Example: + - --http1.1 $URL +--- + +# `--http1.1` + +Use HTTP version 1.1. This is the default with `http://` URLs. diff --git a/third-party/curl/docs/cmdline-opts/http2-prior-knowledge.d b/third-party/curl/docs/cmdline-opts/http2-prior-knowledge.d deleted file mode 100644 index 7d7cabfd86..0000000000 --- a/third-party/curl/docs/cmdline-opts/http2-prior-knowledge.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: http2-prior-knowledge -Tags: Versions -Protocols: HTTP -Added: 7.49.0 -Mutexed: http1.1 http1.0 http2 http3 -Requires: HTTP/2 -Help: Use HTTP 2 without HTTP/1.1 Upgrade -Category: http -Example: --http2-prior-knowledge $URL -See-also: http2 http3 -Multi: boolean ---- -Tells curl to issue its non-TLS HTTP requests using HTTP/2 without HTTP/1.1 -Upgrade. It requires prior knowledge that the server supports HTTP/2 straight -away. HTTPS requests still do HTTP/2 the standard way with negotiated protocol -version in the TLS handshake. diff --git a/third-party/curl/docs/cmdline-opts/http2-prior-knowledge.md b/third-party/curl/docs/cmdline-opts/http2-prior-knowledge.md new file mode 100644 index 0000000000..6351e06a79 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/http2-prior-knowledge.md @@ -0,0 +1,29 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: http2-prior-knowledge +Tags: Versions +Protocols: HTTP +Added: 7.49.0 +Mutexed: http1.1 http1.0 http2 http3 +Requires: HTTP/2 +Help: Use HTTP/2 without HTTP/1.1 Upgrade +Category: http +Multi: boolean +See-also: + - http2 + - http3 +Example: + - --http2-prior-knowledge $URL +--- + +# `--http2-prior-knowledge` + +Issue a non-TLS HTTP request using HTTP/2 directly without HTTP/1.1 Upgrade. +It requires prior knowledge that the server supports HTTP/2 straight away. +HTTPS requests still do HTTP/2 the standard way with negotiated protocol +versions in the TLS handshake. + +Since 8.10.0 if this option is set for an HTTPS request then the application +layer protocol version (ALPN) offered to the server is only HTTP/2. Prior to +that both HTTP/1.1 and HTTP/2 were offered. diff --git a/third-party/curl/docs/cmdline-opts/http2.d b/third-party/curl/docs/cmdline-opts/http2.d deleted file mode 100644 index af5f3c4f5a..0000000000 --- a/third-party/curl/docs/cmdline-opts/http2.d +++ /dev/null @@ -1,25 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: http2 -Tags: Versions -Protocols: HTTP -Added: 7.33.0 -Mutexed: http1.1 http1.0 http2-prior-knowledge http3 -Requires: HTTP/2 -Help: Use HTTP/2 -See-also: http1.1 http3 no-alpn -Category: http -Example: --http2 $URL -Multi: mutex ---- -Tells curl to use HTTP version 2. - -For HTTPS, this means curl negotiates HTTP/2 in the TLS handshake. curl does -this by default. - -For HTTP, this means curl attempts to upgrade the request to HTTP/2 using the -Upgrade: request header. - -When curl uses HTTP/2 over HTTPS, it does not itself insist on TLS 1.2 or -higher even though that is required by the specification. A user can add this -version requirement with --tlsv1.2. diff --git a/third-party/curl/docs/cmdline-opts/http2.md b/third-party/curl/docs/cmdline-opts/http2.md new file mode 100644 index 0000000000..f5180be2b5 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/http2.md @@ -0,0 +1,34 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: http2 +Tags: Versions +Protocols: HTTP +Added: 7.33.0 +Mutexed: http1.1 http1.0 http2-prior-knowledge http3 +Requires: HTTP/2 +Help: Use HTTP/2 +Category: http +Multi: mutex +See-also: + - http1.1 + - http3 + - no-alpn + - proxy-http2 +Example: + - --http2 $URL +--- + +# `--http2` + +Use HTTP/2. + +For HTTPS, this means curl negotiates HTTP/2 in the TLS handshake. curl does +this by default. + +For HTTP, this means curl attempts to upgrade the request to HTTP/2 using the +Upgrade: request header. + +When curl uses HTTP/2 over HTTPS, it does not itself insist on TLS 1.2 or +higher even though that is required by the specification. A user can add this +version requirement with --tlsv1.2. diff --git a/third-party/curl/docs/cmdline-opts/http3-only.d b/third-party/curl/docs/cmdline-opts/http3-only.d deleted file mode 100644 index c3f0f31aa1..0000000000 --- a/third-party/curl/docs/cmdline-opts/http3-only.d +++ /dev/null @@ -1,25 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: http3-only -Tags: Versions -Protocols: HTTP -Added: 7.88.0 -Mutexed: http1.1 http1.0 http2 http2-prior-knowledge http3 -Requires: HTTP/3 -Help: Use HTTP v3 only -See-also: http1.1 http2 http3 -Category: http -Example: --http3-only $URL -Multi: mutex -Experimental: yes ---- -Instructs curl to use HTTP/3 to the host in the URL, with no fallback to -earlier HTTP versions. HTTP/3 can only be used for HTTPS and not for HTTP -URLs. For HTTP, this option triggers an error. - -This option allows a user to avoid using the Alt-Svc method of upgrading to -HTTP/3 when you know that the target speaks HTTP/3 on the given host and port. - -This option makes curl fail if a QUIC connection cannot be established, it -does not attempt any other HTTP versions on its own. Use --http3 for similar -functionality *with* a fallback. diff --git a/third-party/curl/docs/cmdline-opts/http3-only.md b/third-party/curl/docs/cmdline-opts/http3-only.md new file mode 100644 index 0000000000..400ac19ac2 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/http3-only.md @@ -0,0 +1,32 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: http3-only +Tags: Versions +Protocols: HTTP +Added: 7.88.0 +Mutexed: http1.1 http1.0 http2 http2-prior-knowledge http3 +Requires: HTTP/3 +Help: Use HTTP/3 only +Category: http +Multi: mutex +See-also: + - http1.1 + - http2 + - http3 +Example: + - --http3-only $URL +--- + +# `--http3-only` + +Instruct curl to use HTTP/3 to the host in the URL, with no fallback to +earlier HTTP versions. HTTP/3 can only be used for HTTPS and not for HTTP +URLs. For HTTP, this option triggers an error. + +This option allows a user to avoid using the Alt-Svc method of upgrading to +HTTP/3 when you know that the target speaks HTTP/3 on the given host and port. + +This option makes curl fail if a QUIC connection cannot be established, it +does not attempt any other HTTP versions on its own. Use --http3 for similar +functionality *with* a fallback. diff --git a/third-party/curl/docs/cmdline-opts/http3.d b/third-party/curl/docs/cmdline-opts/http3.d deleted file mode 100644 index a8258c4d31..0000000000 --- a/third-party/curl/docs/cmdline-opts/http3.d +++ /dev/null @@ -1,27 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: http3 -Tags: Versions -Protocols: HTTP -Added: 7.66.0 -Mutexed: http1.1 http1.0 http2 http2-prior-knowledge http3-only -Requires: HTTP/3 -Help: Use HTTP v3 -See-also: http1.1 http2 -Category: http -Example: --http3 $URL -Multi: mutex -Experimental: yes ---- -Tells curl to try HTTP/3 to the host in the URL, but fallback to earlier -HTTP versions if the HTTP/3 connection establishment fails. HTTP/3 is only -available for HTTPS and not for HTTP URLs. - -This option allows a user to avoid using the Alt-Svc method of upgrading to -HTTP/3 when you know that the target speaks HTTP/3 on the given host and port. - -When asked to use HTTP/3, curl issues a separate attempt to use older HTTP -versions with a slight delay, so if the HTTP/3 transfer fails or is slow, curl -still tries to proceed with an older HTTP version. - -Use --http3-only for similar functionality *without* a fallback. diff --git a/third-party/curl/docs/cmdline-opts/http3.md b/third-party/curl/docs/cmdline-opts/http3.md new file mode 100644 index 0000000000..e4dfeef075 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/http3.md @@ -0,0 +1,37 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: http3 +Tags: Versions +Protocols: HTTP +Added: 7.66.0 +Mutexed: http1.1 http1.0 http2 http2-prior-knowledge http3-only +Requires: HTTP/3 +Help: Use HTTP/3 +Category: http +Multi: mutex +See-also: + - http1.1 + - http2 +Example: + - --http3 $URL +--- + +# `--http3` + +Attempt HTTP/3 to the host in the URL, but fallback to earlier HTTP versions +if the HTTP/3 connection establishment fails or is slow. HTTP/3 is only +available for HTTPS and not for HTTP URLs. + +This option allows a user to avoid using the Alt-Svc method of upgrading to +HTTP/3 when you know or suspect that the target speaks HTTP/3 on the given +host and port. + +When asked to use HTTP/3, curl issues a separate attempt to use older HTTP +versions with a slight delay, so if the HTTP/3 transfer fails or is slow, curl +still tries to proceed with an older HTTP version. The fallback performs the +regular negotiation between HTTP/1 and HTTP/2. + +Use --http3-only for similar functionality *without* a fallback. + +curl cannot do HTTP/3 over any proxy. diff --git a/third-party/curl/docs/cmdline-opts/ignore-content-length.d b/third-party/curl/docs/cmdline-opts/ignore-content-length.d deleted file mode 100644 index 505c04c18b..0000000000 --- a/third-party/curl/docs/cmdline-opts/ignore-content-length.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ignore-content-length -Help: Ignore the size of the remote resource -Protocols: FTP HTTP -Category: http ftp -Example: --ignore-content-length $URL -Added: 7.14.1 -See-also: ftp-skip-pasv-ip -Multi: boolean ---- -For HTTP, Ignore the Content-Length header. This is particularly useful for -servers running Apache 1.x, which reports incorrect Content-Length for -files larger than 2 gigabytes. - -For FTP, this makes curl skip the SIZE command to figure out the size before -downloading a file (added in 7.46.0). - -This option does not work for HTTP if libcurl was built to use hyper. diff --git a/third-party/curl/docs/cmdline-opts/ignore-content-length.md b/third-party/curl/docs/cmdline-opts/ignore-content-length.md new file mode 100644 index 0000000000..01ff43b06e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ignore-content-length.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ignore-content-length +Help: Ignore the size of the remote resource +Protocols: FTP HTTP +Category: http ftp +Added: 7.14.1 +Multi: boolean +See-also: + - ftp-skip-pasv-ip +Example: + - --ignore-content-length $URL +--- + +# `--ignore-content-length` + +For HTTP, ignore the Content-Length header. This is particularly useful for +servers running Apache 1.x, which reports incorrect Content-Length for files +larger than 2 gigabytes. + +For FTP, this makes curl skip the SIZE command to figure out the size before +downloading a file (added in 7.46.0). diff --git a/third-party/curl/docs/cmdline-opts/include.d b/third-party/curl/docs/cmdline-opts/include.d deleted file mode 100644 index ce7b9d87b4..0000000000 --- a/third-party/curl/docs/cmdline-opts/include.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: include -Short: i -Help: Include protocol response headers in the output -See-also: verbose -Category: important verbose -Example: -i $URL -Added: 4.8 -Multi: boolean ---- -Include the HTTP response headers in the output. The HTTP response headers can -include things like server name, cookies, date of the document, HTTP version -and more... - -To view the request headers, consider the --verbose option. - -Prior to 7.75.0 curl did not print the headers if --fail was used in -combination with this option and there was error reported by server. diff --git a/third-party/curl/docs/cmdline-opts/insecure.d b/third-party/curl/docs/cmdline-opts/insecure.d deleted file mode 100644 index e48d500029..0000000000 --- a/third-party/curl/docs/cmdline-opts/insecure.d +++ /dev/null @@ -1,33 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: insecure -Short: k -Help: Allow insecure server connections -Protocols: TLS SFTP SCP -See-also: proxy-insecure cacert capath -Category: tls sftp scp -Example: --insecure $URL -Added: 7.10 -Multi: boolean ---- -By default, every secure connection curl makes is verified to be secure before -the transfer takes place. This option makes curl skip the verification step -and proceed without checking. - -When this option is not used for protocols using TLS, curl verifies the -server's TLS certificate before it continues: that the certificate contains -the right name which matches the host name used in the URL and that the -certificate has been signed by a CA certificate present in the cert store. -See this online resource for further details: - https://curl.se/docs/sslcerts.html - -For SFTP and SCP, this option makes curl skip the *known_hosts* verification. -*known_hosts* is a file normally stored in the user's home directory in the -".ssh" subdirectory, which contains host names and their public keys. - -**WARNING**: using this option makes the transfer insecure. - -When curl uses secure protocols it trusts responses and allows for example -HSTS and Alt-Svc information to be stored and used subsequently. Using ---insecure can make curl trust and use such information from malicious -servers. diff --git a/third-party/curl/docs/cmdline-opts/insecure.md b/third-party/curl/docs/cmdline-opts/insecure.md new file mode 100644 index 0000000000..6b7009f251 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/insecure.md @@ -0,0 +1,41 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: insecure +Short: k +Help: Allow insecure server connections +Protocols: TLS SFTP SCP +Category: tls sftp scp ssh +Added: 7.10 +Multi: boolean +See-also: + - proxy-insecure + - cacert + - capath +Example: + - --insecure $URL +--- + +# `--insecure` + +By default, every secure connection curl makes is verified to be secure before +the transfer takes place. This option makes curl skip the verification step +and proceed without checking. + +When this option is not used for protocols using TLS, curl verifies the +server's TLS certificate before it continues: that the certificate contains +the right name which matches the hostname used in the URL and that the +certificate has been signed by a CA certificate present in the cert store. See +this online resource for further details: +**https://curl.se/docs/sslcerts.html** + +For SFTP and SCP, this option makes curl skip the *known_hosts* verification. +*known_hosts* is a file normally stored in the user's home directory in the +".ssh" subdirectory, which contains hostnames and their public keys. + +**WARNING**: using this option makes the transfer insecure. + +When curl uses secure protocols it trusts responses and allows for example +HSTS and Alt-Svc information to be stored and used subsequently. Using +--insecure can make curl trust and use such information from malicious +servers. diff --git a/third-party/curl/docs/cmdline-opts/interface.d b/third-party/curl/docs/cmdline-opts/interface.d deleted file mode 100644 index 026ceaef5a..0000000000 --- a/third-party/curl/docs/cmdline-opts/interface.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: interface -Arg: -Help: Use network INTERFACE (or address) -See-also: dns-interface -Category: connection -Example: --interface eth0 $URL -Added: 7.3 -Multi: single ---- -Perform an operation using a specified interface. You can enter interface -name, IP address or host name. An example could look like: - - curl --interface eth0:1 https://www.example.com/ - -On Linux it can be used to specify a **VRF**, but the binary needs to either -have **CAP_NET_RAW** or to be run as root. More information about Linux -**VRF**: https://www.kernel.org/doc/Documentation/networking/vrf.txt diff --git a/third-party/curl/docs/cmdline-opts/interface.md b/third-party/curl/docs/cmdline-opts/interface.md new file mode 100644 index 0000000000..1609cc35d3 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/interface.md @@ -0,0 +1,51 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: interface +Arg: +Help: Use network interface +Category: connection +Added: 7.3 +Multi: single +See-also: + - dns-interface +Example: + - --interface eth0 $URL + - --interface "host!10.0.0.1" $URL + - --interface "if!enp3s0" $URL +--- + +# `--interface` + +Perform the operation using a specified interface. You can enter interface +name, IP address or hostname. If you prefer to be specific, you can use the +following special syntax: + +## `if!` + +Interface name. If the provided name does not match an existing interface, +curl returns with error 45. + +## `host!` + +IP address or hostname. + +## `ifhost!!` + +Interface name and IP address or hostname. This syntax requires libcurl 8.9.0 +or later. + +If the provided name does not match an existing interface, curl returns with +error 45. + +## + +curl does not support using network interface names for this option on +Windows. + +That name resolve operation if a hostname is provided does **not** use +DNS-over-HTTPS even if --doh-url is set. + +On Linux this option can be used to specify a **VRF** (Virtual Routing and +Forwarding) device, but the binary then needs to either have the +**CAP_NET_RAW** capability set or to be run as root. diff --git a/third-party/curl/docs/cmdline-opts/ip-tos.md b/third-party/curl/docs/cmdline-opts/ip-tos.md new file mode 100644 index 0000000000..f5ef589e23 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ip-tos.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ip-tos +Arg: +Help: Set IP Type of Service or Traffic Class +Added: 8.9.0 +Category: connection +Multi: single +See-also: + - tcp-nodelay + - vlan-priority +Example: + - --ip-tos CS5 $URL +--- + +# `--ip-tos` + +Set Type of Service (TOS) for IPv4 or Traffic Class for IPv6. + +The values allowed for \ can be a numeric value between 1 and 255 +or one of the following: + +CS0, CS1, CS2, CS3, CS4, CS5, CS6, CS7, AF11, AF12, AF13, AF21, AF22, AF23, +AF31, AF32, AF33, AF41, AF42, AF43, EF, VOICE-ADMIT, ECT1, ECT0, CE, LE, +LOWCOST, LOWDELAY, THROUGHPUT, RELIABILITY, MINCOST diff --git a/third-party/curl/docs/cmdline-opts/ipfs-gateway.md b/third-party/curl/docs/cmdline-opts/ipfs-gateway.md new file mode 100644 index 0000000000..16e197fcfe --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ipfs-gateway.md @@ -0,0 +1,40 @@ +--- +c: Copyright (C) Mark Gaiser, +SPDX-License-Identifier: curl +Long: ipfs-gateway +Arg: +Help: Gateway for IPFS +Protocols: IPFS +Added: 8.4.0 +Category: curl +Multi: single +See-also: + - help + - manual +Example: + - --ipfs-gateway $URL ipfs:// +--- + +# `--ipfs-gateway` + +Specify which gateway to use for IPFS and IPNS URLs. Not specifying this +instead makes curl check if the IPFS_GATEWAY environment variable is set, or +if a `~/.ipfs/gateway` file holding the gateway URL exists. + +If you run a local IPFS node, this gateway is by default available under +`http://localhost:8080`. A full example URL would look like: + + curl --ipfs-gateway http://localhost:8080 \ + ipfs://bafybeigagd5nmnn2iys2f3 + +There are many public IPFS gateways. See for example: +https://ipfs.github.io/public-gateway-checker/ + +If you opt to go for a remote gateway you need to be aware that you completely +trust the gateway. This might be fine in local gateways that you host +yourself. With remote gateways there could potentially be malicious actors +returning you data that does not match the request you made, inspect or even +interfere with the request. You may not notice this when using curl. A +mitigation could be to go for a "trustless" gateway. This means you locally +verify the data. Consult the docs page on trusted vs trustless: +https://docs.ipfs.tech/reference/http/gateway/#trusted-vs-trustless diff --git a/third-party/curl/docs/cmdline-opts/ipv4.d b/third-party/curl/docs/cmdline-opts/ipv4.d deleted file mode 100644 index 60690bedcf..0000000000 --- a/third-party/curl/docs/cmdline-opts/ipv4.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: 4 -Long: ipv4 -Tags: Versions -Protocols: -Added: 7.10.8 -Mutexed: ipv6 -Requires: -See-also: http1.1 http2 -Help: Resolve names to IPv4 addresses -Category: connection dns -Example: --ipv4 $URL -Multi: mutex ---- -This option tells curl to use IPv4 addresses only when resolving host names, -and not for example try IPv6. diff --git a/third-party/curl/docs/cmdline-opts/ipv4.md b/third-party/curl/docs/cmdline-opts/ipv4.md new file mode 100644 index 0000000000..d7d571d5bd --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ipv4.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: 4 +Long: ipv4 +Tags: Versions +Protocols: +Added: 7.10.8 +Mutexed: ipv6 +Requires: +Help: Resolve names to IPv4 addresses +Category: connection dns +Multi: mutex +See-also: + - http1.1 + - http2 +Example: + - --ipv4 $URL +--- + +# `--ipv4` + +Request only IPv4 addresses when resolving hostnames, and not for example any +IPv6. diff --git a/third-party/curl/docs/cmdline-opts/ipv6.d b/third-party/curl/docs/cmdline-opts/ipv6.d deleted file mode 100644 index 24ce201a2e..0000000000 --- a/third-party/curl/docs/cmdline-opts/ipv6.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: 6 -Long: ipv6 -Tags: Versions -Protocols: -Added: 7.10.8 -Mutexed: ipv4 -Requires: -See-also: http1.1 http2 -Help: Resolve names to IPv6 addresses -Category: connection dns -Example: --ipv6 $URL -Multi: mutex ---- -This option tells curl to use IPv6 addresses only when resolving host names, -and not for example try IPv4. diff --git a/third-party/curl/docs/cmdline-opts/ipv6.md b/third-party/curl/docs/cmdline-opts/ipv6.md new file mode 100644 index 0000000000..c2f1398774 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ipv6.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: 6 +Long: ipv6 +Tags: Versions +Protocols: +Added: 7.10.8 +Mutexed: ipv4 +Requires: +Help: Resolve names to IPv6 addresses +Category: connection dns +Multi: mutex +See-also: + - http1.1 + - http2 +Example: + - --ipv6 $URL +--- + +# `--ipv6` + +Request only IPv6 addresses when resolving hostnames, and not for example any +IPv4. + +Your resolver may still respond to an IPv6-only resolve request by returning +IPv6 addresses that contain "mapped" IPv4 addresses for compatibility purposes. +macOS is known to do this. diff --git a/third-party/curl/docs/cmdline-opts/json.d b/third-party/curl/docs/cmdline-opts/json.d deleted file mode 100644 index aa3b49de2f..0000000000 --- a/third-party/curl/docs/cmdline-opts/json.d +++ /dev/null @@ -1,35 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: json -Arg: -Help: HTTP POST JSON -Protocols: HTTP -See-also: data-binary data-raw -Mutexed: form head upload-file -Category: http post upload -Example: --json '{ "drink": "coffe" }' $URL -Example: --json '{ "drink":' --json ' "coffe" }' $URL -Example: --json @prepared $URL -Example: --json @- $URL < json.txt -Added: 7.82.0 -Multi: append ---- -Sends the specified JSON data in a POST request to the HTTP server. --json -works as a shortcut for passing on these three options: - - --data [arg] - --header "Content-Type: application/json" - --header "Accept: application/json" - -There is **no verification** that the passed in data is actual JSON or that -the syntax is correct. - -If you start the data with the letter @, the rest should be a file name to -read the data from, or a single dash (-) if you want curl to read the data -from stdin. Posting data from a file named 'foobar' would thus be done with ---json @foobar and to instead read the data from stdin, use --json @-. - -If this option is used more than once on the same command line, the additional -data pieces are concatenated to the previous before sending. - -The headers this option sets can be overridden with --header as usual. diff --git a/third-party/curl/docs/cmdline-opts/json.md b/third-party/curl/docs/cmdline-opts/json.md new file mode 100644 index 0000000000..3f1a9a1b74 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/json.md @@ -0,0 +1,42 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: json +Arg: +Help: HTTP POST JSON +Protocols: HTTP +Mutexed: form head upload-file +Category: http post upload +Added: 7.82.0 +Multi: append +See-also: + - data-binary + - data-raw +Example: + - --json '{ "drink": "coffee" }' $URL + - --json '{ "drink":' --json ' "coffee" }' $URL + - --json @prepared $URL + - --json @- $URL < json.txt +--- + +# `--json` + +Send the specified JSON data in a POST request to the HTTP server. --json +works as a shortcut for passing on these three options: + + --data-binary [arg] + --header "Content-Type: application/json" + --header "Accept: application/json" + +There is **no verification** that the passed in data is actual JSON or that +the syntax is correct. + +If you start the data with the letter @, the rest should be a filename to read +the data from, or a single dash (-) if you want curl to read the data from +stdin. Posting data from a file named 'foobar' would thus be done with --json +@foobar and to instead read the data from stdin, use --json @-. + +If this option is used more than once on the same command line, the additional +data pieces are concatenated to the previous before sending. + +The headers this option sets can be overridden with --header as usual. diff --git a/third-party/curl/docs/cmdline-opts/junk-session-cookies.d b/third-party/curl/docs/cmdline-opts/junk-session-cookies.d deleted file mode 100644 index daea7840ad..0000000000 --- a/third-party/curl/docs/cmdline-opts/junk-session-cookies.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: junk-session-cookies -Short: j -Help: Ignore session cookies read from file -Protocols: HTTP -See-also: cookie cookie-jar -Category: http -Example: --junk-session-cookies -b cookies.txt $URL -Added: 7.9.7 -Multi: boolean ---- -When curl is told to read cookies from a given file, this option makes it -discard all "session cookies". This has the same effect as if a new session is -started. Typical browsers discard session cookies when they are closed down. diff --git a/third-party/curl/docs/cmdline-opts/junk-session-cookies.md b/third-party/curl/docs/cmdline-opts/junk-session-cookies.md new file mode 100644 index 0000000000..668dfce2d6 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/junk-session-cookies.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: junk-session-cookies +Short: j +Help: Ignore session cookies read from file +Protocols: HTTP +Category: http +Added: 7.9.7 +Multi: boolean +See-also: + - cookie + - cookie-jar +Example: + - --junk-session-cookies -b cookies.txt $URL +--- + +# `--junk-session-cookies` + +When curl is told to read cookies from a given file, this option makes it +discard all session cookies. This has the same effect as if a new session is +started. Typical browsers discard session cookies when they are closed down. + +Session cookies are cookies without a set expiry time. They are meant to only +last for "a session". diff --git a/third-party/curl/docs/cmdline-opts/keepalive-cnt.md b/third-party/curl/docs/cmdline-opts/keepalive-cnt.md new file mode 100644 index 0000000000..e56c976eca --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/keepalive-cnt.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: keepalive-cnt +Arg: +Help: Maximum number of keepalive probes +Added: 8.9.0 +Category: connection +Multi: single +See-also: + - keepalive-time + - no-keepalive +Example: + - --keepalive-cnt 3 $URL +--- + +# `--keepalive-cnt` + +Set the maximum number of keepalive probes TCP should send but get no response +before dropping the connection. This option is usually used in conjunction +with --keepalive-time. + +This option is supported on Linux, *BSD/macOS, Windows \>=10.0.16299, Solaris +11.4, and recent AIX, HP-UX and more. This option has no effect if +--no-keepalive is used. + +If unspecified, the option defaults to 9. diff --git a/third-party/curl/docs/cmdline-opts/keepalive-time.d b/third-party/curl/docs/cmdline-opts/keepalive-time.d deleted file mode 100644 index 5e284774df..0000000000 --- a/third-party/curl/docs/cmdline-opts/keepalive-time.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: keepalive-time -Arg: -Help: Interval time for keepalive probes -Added: 7.18.0 -Category: connection -Example: --keepalive-time 20 $URL -See-also: no-keepalive max-time -Multi: single ---- -This option sets the time a connection needs to remain idle before sending -keepalive probes and the time between individual keepalive probes. It is -currently effective on operating systems offering the TCP_KEEPIDLE and -TCP_KEEPINTVL socket options (meaning Linux, recent AIX, HP-UX and more). -Keepalives are used by the TCP stack to detect broken networks on idle -connections. The number of missed keepalive probes before declaring the -connection down is OS dependent and is commonly 9 or 10. This option has no -effect if --no-keepalive is used. - -If unspecified, the option defaults to 60 seconds. diff --git a/third-party/curl/docs/cmdline-opts/keepalive-time.md b/third-party/curl/docs/cmdline-opts/keepalive-time.md new file mode 100644 index 0000000000..4b10ff6f45 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/keepalive-time.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: keepalive-time +Arg: +Help: Interval time for keepalive probes +Added: 7.18.0 +Category: connection timeout +Multi: single +See-also: + - no-keepalive + - keepalive-cnt + - max-time +Example: + - --keepalive-time 20 $URL +--- + +# `--keepalive-time` + +Set the time a connection needs to remain idle before sending keepalive probes +and the time between individual keepalive probes. It is currently effective on +operating systems offering the `TCP_KEEPIDLE` and `TCP_KEEPINTVL` socket +options (meaning Linux, *BSD/macOS, Windows, Solaris, and recent AIX, HP-UX and more). +Keepalive is used by the TCP stack to detect broken networks on idle connections. +The number of missed keepalive probes before declaring the connection down is OS +dependent and is commonly 8 (*BSD/macOS/AIX), 9 (Linux/AIX) or 5/10 (Windows), and +this number can be changed by specifying the curl option `keepalive-cnt`. +Note that this option has no effect if --no-keepalive is used. + +If unspecified, the option defaults to 60 seconds. diff --git a/third-party/curl/docs/cmdline-opts/key-type.d b/third-party/curl/docs/cmdline-opts/key-type.d deleted file mode 100644 index 22339b4c90..0000000000 --- a/third-party/curl/docs/cmdline-opts/key-type.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: key-type -Arg: -Help: Private key file type (DER/PEM/ENG) -Protocols: TLS -Category: tls -Example: --key-type DER --key here $URL -Added: 7.9.3 -See-also: key -Multi: single ---- -Private key file type. Specify which type your --key provided private key -is. DER, PEM, and ENG are supported. If not specified, PEM is assumed. diff --git a/third-party/curl/docs/cmdline-opts/key-type.md b/third-party/curl/docs/cmdline-opts/key-type.md new file mode 100644 index 0000000000..4128bfeafc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/key-type.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: key-type +Arg: +Help: Private key file type (DER/PEM/ENG) +Protocols: TLS +Category: tls +Added: 7.9.3 +Multi: single +See-also: + - key +Example: + - --key-type DER --key here $URL +--- + +# `--key-type` + +Private key file type. Specify which type your --key provided private key +is. DER, PEM, and ENG are supported. If not specified, PEM is assumed. diff --git a/third-party/curl/docs/cmdline-opts/key.d b/third-party/curl/docs/cmdline-opts/key.d deleted file mode 100644 index 4236218c9d..0000000000 --- a/third-party/curl/docs/cmdline-opts/key.d +++ /dev/null @@ -1,27 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: key -Arg: -Protocols: TLS SSH -Help: Private key file name -Category: tls ssh -Example: --cert certificate --key here $URL -Added: 7.9.3 -See-also: key-type cert -Multi: single ---- -Private key file name. Allows you to provide your private key in this separate -file. For SSH, if not specified, curl tries the following candidates in order: -'~/.ssh/id_rsa', '~/.ssh/id_dsa', './id_rsa', './id_dsa'. - -If curl is built against OpenSSL library, and the engine pkcs11 is available, -then a PKCS#11 URI (RFC 7512) can be used to specify a private key located in -a PKCS#11 device. A string beginning with "pkcs11:" is interpreted as a -PKCS#11 URI. If a PKCS#11 URI is provided, then the --engine option is set as -"pkcs11" if none was provided and the --key-type option is set as "ENG" if -none was provided. - -If curl is built against Secure Transport or Schannel then this option is -ignored for TLS protocols (HTTPS, etc). Those backends expect the private key -to be already present in the keychain or PKCS#12 file containing the -certificate. diff --git a/third-party/curl/docs/cmdline-opts/key.md b/third-party/curl/docs/cmdline-opts/key.md new file mode 100644 index 0000000000..cc4bc73fa5 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/key.md @@ -0,0 +1,33 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: key +Arg: +Protocols: TLS SCP SFTP +Help: Private key filename +Category: tls ssh +Added: 7.9.3 +Multi: single +See-also: + - key-type + - cert +Example: + - --cert certificate --key here $URL +--- + +# `--key` + +Private key filename. Allows you to provide your private key in this separate +file. For SSH, if not specified, curl tries the following candidates in order: +`~/.ssh/id_rsa`, `~/.ssh/id_dsa`, `./id_rsa`, `./id_dsa`. + +If curl is built against OpenSSL library, and the engine pkcs11 or pkcs11 +provider is available, then a PKCS#11 URI (RFC 7512) can be used to specify a +private key located in a PKCS#11 device. A string beginning with `pkcs11:` is +interpreted as a PKCS#11 URI. If a PKCS#11 URI is provided, then the --engine +option is set as `pkcs11` if none was provided and the --key-type option is +set as `ENG` or `PROV` if none was provided (depending on OpenSSL version). + +If curl is built against Schannel then this option is ignored for TLS +protocols (HTTPS, etc). That backend expects the private key to be already +present in the keychain or PKCS#12 file containing the certificate. diff --git a/third-party/curl/docs/cmdline-opts/knownhosts.md b/third-party/curl/docs/cmdline-opts/knownhosts.md new file mode 100644 index 0000000000..4b6386dd24 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/knownhosts.md @@ -0,0 +1,31 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: knownhosts +Arg: +Protocols: SCP SFTP +Help: Specify knownhosts path +Category: ssh +Added: 8.17.0 +Multi: single +See-also: + - hostpubsha256 + - hostpubmd5 + - insecure + - key +Example: + - --knownhosts filename --key here $URL +--- + +# `--knownhosts` + +When doing SCP and SFTP transfers, curl automatically checks a database +containing identification for all hosts it has ever been used with to verify +that the host it connects to is the same as previously. Host keys are stored +in such a known hosts file. curl uses the ~/.ssh/known_hosts in the user's +home directory by default. + +This option lets a user specify a specific file to check the host against. + +The known hosts check can be disabled with --insecure, but that makes the +transfer insecure and is strongly discouraged. diff --git a/third-party/curl/docs/cmdline-opts/krb.d b/third-party/curl/docs/cmdline-opts/krb.d deleted file mode 100644 index 42aa67ada4..0000000000 --- a/third-party/curl/docs/cmdline-opts/krb.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: krb -Arg: -Help: Enable Kerberos with security -Protocols: FTP -Requires: Kerberos -Category: ftp -Example: --krb clear ftp://example.com/ -Added: 7.3 -See-also: delegation ssl -Multi: single ---- -Enable Kerberos authentication and use. The level must be entered and should -be one of 'clear', 'safe', 'confidential', or 'private'. Should you use a -level that is not one of these, 'private' is used. diff --git a/third-party/curl/docs/cmdline-opts/krb.md b/third-party/curl/docs/cmdline-opts/krb.md new file mode 100644 index 0000000000..6d47a76d6e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/krb.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: krb +Arg: +Help: Enable Kerberos with security +Protocols: FTP +Requires: Kerberos +Category: deprecated +Added: 7.3 +Multi: single +See-also: + - delegation + - ssl +Example: + - --krb clear ftp://example.com/ +--- + +# `--krb` + +Deprecated option (added in 8.17.0). It has no function anymore. + +Enable Kerberos authentication and use. The level must be entered and should +be one of `clear`, `safe`, `confidential`, or `private`. Should you use a +level that is not one of these, `private` is used. diff --git a/third-party/curl/docs/cmdline-opts/libcurl.d b/third-party/curl/docs/cmdline-opts/libcurl.d deleted file mode 100644 index 52e252f3b9..0000000000 --- a/third-party/curl/docs/cmdline-opts/libcurl.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: libcurl -Arg: -Help: Dump libcurl equivalent code of this command line -Added: 7.16.1 -Category: curl -Example: --libcurl client.c $URL -See-also: verbose -Multi: single -Scope: global ---- -Append this option to any ordinary curl command line, and you get -libcurl-using C source code written to the file that does the equivalent of -what your command-line operation does! diff --git a/third-party/curl/docs/cmdline-opts/libcurl.md b/third-party/curl/docs/cmdline-opts/libcurl.md new file mode 100644 index 0000000000..e37e5aa0fa --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/libcurl.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: libcurl +Arg: +Help: Generate libcurl code for this command line +Added: 7.16.1 +Category: curl global +Multi: single +Scope: global +See-also: + - verbose +Example: + - --libcurl client.c $URL +--- + +# `--libcurl` + +Append this option to any ordinary curl command line, and you get +libcurl-using C source code written to the file that does the equivalent of +what your command-line operation does. diff --git a/third-party/curl/docs/cmdline-opts/limit-rate.d b/third-party/curl/docs/cmdline-opts/limit-rate.d deleted file mode 100644 index 43ebf2c233..0000000000 --- a/third-party/curl/docs/cmdline-opts/limit-rate.d +++ /dev/null @@ -1,29 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: limit-rate -Arg: -Help: Limit transfer speed to RATE -Category: connection -Example: --limit-rate 100K $URL -Example: --limit-rate 1000 $URL -Example: --limit-rate 10M $URL -Added: 7.10 -See-also: rate speed-limit speed-time -Multi: single ---- -Specify the maximum transfer rate you want curl to use - for both downloads -and uploads. This feature is useful if you have a limited pipe and you would like -your transfer not to use your entire bandwidth. To make it slower than it -otherwise would be. - -The given speed is measured in bytes/second, unless a suffix is appended. -Appending 'k' or 'K' counts the number as kilobytes, 'm' or 'M' makes it -megabytes, while 'g' or 'G' makes it gigabytes. The suffixes (k, M, G, T, P) -are 1024 based. For example 1k is 1024. Examples: 200K, 3m and 1G. - -The rate limiting logic works on averaging the transfer speed to no more than -the set threshold over a period of multiple seconds. - -If you also use the --speed-limit option, that option takes precedence and -might cripple the rate-limiting slightly, to help keeping the speed-limit -logic working. diff --git a/third-party/curl/docs/cmdline-opts/limit-rate.md b/third-party/curl/docs/cmdline-opts/limit-rate.md new file mode 100644 index 0000000000..88f62709b0 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/limit-rate.md @@ -0,0 +1,42 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: limit-rate +Arg: +Help: Limit transfer speed to RATE +Category: connection +Added: 7.10 +Multi: single +See-also: + - rate + - speed-limit + - speed-time +Example: + - --limit-rate 123.45K $URL + - --limit-rate 1000 $URL + - --limit-rate 10M $URL + - --limit-rate 200K --max-time 60 $URL +--- + +# `--limit-rate` + +Specify the maximum transfer rate you want curl to use - for both downloads +and uploads. This feature is useful if you have a limited pipe and you would +like your transfer not to use your entire bandwidth. To make it slower than it +otherwise would be. + +The given speed is measured in bytes/second, unless a suffix is appended. +Appending 'k' or 'K' counts the number as kilobytes, 'm' or 'M' makes it +megabytes etc. The supported suffixes (k, M, G, T, P) are 1024-based. For +example 1k is 1024. Examples: 200K, 3m and 1G. + +The rate limiting logic works on averaging the transfer speed to no more than +the set threshold over a period of multiple seconds. + +If you also use the --speed-limit option, that option takes precedence and +might cripple the rate-limiting slightly, to help keep the speed-limit +logic working. + +Starting in curl 8.19.0, the rate can be specified using a fraction as in +`2.5M` for two and a half megabytes per second. It only works with a period +(`.`) delimiter, independent of what your locale might prefer. diff --git a/third-party/curl/docs/cmdline-opts/list-only.d b/third-party/curl/docs/cmdline-opts/list-only.d deleted file mode 100644 index dcfbf2ccc9..0000000000 --- a/third-party/curl/docs/cmdline-opts/list-only.d +++ /dev/null @@ -1,36 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: list-only -Short: l -Protocols: FTP POP3 SFTP -Help: List only mode -Added: 4.0 -Category: ftp pop3 sftp -Example: --list-only ftp://example.com/dir/ -See-also: quote request -Multi: boolean ---- -(FTP) -When listing an FTP directory, this switch forces a name-only view. This is -especially useful if the user wants to machine-parse the contents of an FTP -directory since the normal directory view does not use a standard look or -format. When used like this, the option causes an NLST command to be sent to -the server instead of LIST. - -Note: Some FTP servers list only files in their response to NLST; they do not -include sub-directories and symbolic links. - -(SFTP) -When listing an SFTP directory, this switch forces a name-only view, one per line. -This is especially useful if the user wants to machine-parse the contents of an -SFTP directory since the normal directory view provides more information than just -file names. - -(POP3) -When retrieving a specific email from POP3, this switch forces a LIST command -to be performed instead of RETR. This is particularly useful if the user wants -to see if a specific message-id exists on the server and what size it is. - -Note: When combined with --request, this option can be used to send a UIDL -command instead, so the user may use the email's unique identifier rather than -its message-id to make the request. diff --git a/third-party/curl/docs/cmdline-opts/list-only.md b/third-party/curl/docs/cmdline-opts/list-only.md new file mode 100644 index 0000000000..36d6321039 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/list-only.md @@ -0,0 +1,43 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: list-only +Short: l +Protocols: FTP POP3 SFTP FILE +Help: List only mode +Added: 4.0 +Category: ftp pop3 sftp file +Multi: boolean +See-also: + - quote + - request +Example: + - --list-only ftp://example.com/dir/ +--- + +# `--list-only` + +When listing an FTP directory, force a name-only view. Maybe particularly +useful if the user wants to machine-parse the contents of an FTP directory +since the normal directory view does not use a standard look or format. When +used like this, the option causes an NLST command to be sent to the server +instead of LIST. + +Note: Some FTP servers list only files in their response to NLST; they do not +include subdirectories and symbolic links. + +When listing an SFTP directory, this switch forces a name-only view, one per +line. This is especially useful if the user wants to machine-parse the +contents of an SFTP directory since the normal directory view provides more +information than filenames. + +When retrieving a specific email from POP3, this switch forces a LIST command +to be performed instead of RETR. This is particularly useful if the user wants +to see if a specific message-id exists on the server and what size it is. + +For FILE, this option has no effect yet as directories are always listed in +this mode. + +Note: When combined with --request, this option can be used to send a UIDL +command instead, so the user may use the email's unique identifier rather than +its message-id to make the request. diff --git a/third-party/curl/docs/cmdline-opts/local-port.d b/third-party/curl/docs/cmdline-opts/local-port.d deleted file mode 100644 index d6949b7ee3..0000000000 --- a/third-party/curl/docs/cmdline-opts/local-port.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: local-port -Arg: -Help: Force use of RANGE for local port numbers -Added: 7.15.2 -Category: connection -Example: --local-port 1000-3000 $URL -See-also: globoff -Multi: single ---- -Set a preferred single number or range (FROM-TO) of local port numbers to use -for the connection(s). Note that port numbers by nature are a scarce resource -so setting this range to something too narrow might cause unnecessary -connection setup failures. diff --git a/third-party/curl/docs/cmdline-opts/local-port.md b/third-party/curl/docs/cmdline-opts/local-port.md new file mode 100644 index 0000000000..b8c0d3fda1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/local-port.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: local-port +Arg: +Help: Use a local port number within RANGE +Added: 7.15.2 +Category: connection +Multi: single +See-also: + - globoff +Example: + - --local-port 1000-3000 $URL +--- + +# `--local-port` + +Set a preferred single number or range (FROM-TO) of local port numbers to use +for the connection(s). Note that port numbers by nature are a scarce resource +so setting this range to something too narrow might cause unnecessary +connection setup failures. diff --git a/third-party/curl/docs/cmdline-opts/location-trusted.d b/third-party/curl/docs/cmdline-opts/location-trusted.d deleted file mode 100644 index 9f83d0ef0e..0000000000 --- a/third-party/curl/docs/cmdline-opts/location-trusted.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: location-trusted -Help: Like --location, and send auth to other hosts -Protocols: HTTP -See-also: user -Category: http auth -Example: --location-trusted -u user:password $URL -Added: 7.10.4 -Multi: boolean ---- -Like --location, but allows sending the name + password to all hosts that the -site may redirect to. This may or may not introduce a security breach if the -site redirects you to a site to which you send your authentication info -(which is plaintext in the case of HTTP Basic authentication). diff --git a/third-party/curl/docs/cmdline-opts/location-trusted.md b/third-party/curl/docs/cmdline-opts/location-trusted.md new file mode 100644 index 0000000000..7d9810802c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/location-trusted.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: location-trusted +Help: As --location, but send secrets to other hosts +Protocols: HTTP +Category: http auth +Added: 7.10.4 +Multi: boolean +See-also: + - user + - follow +Example: + - --location-trusted -u user:password $URL + - --location-trusted -H "Cookie: session=abc" $URL +--- + +# `--location-trusted` + +Instruct curl to follow HTTP redirects like --location, but permit curl to +send credentials and other secrets along to other hosts than the initial one. + +This may or may not introduce a security breach if the site redirects you to a +site to which you send this sensitive data to. Another host means that one or +more of hostname, protocol scheme or port number changed. + +This option also allows curl to pass long cookies set explicitly with --header. diff --git a/third-party/curl/docs/cmdline-opts/location.d b/third-party/curl/docs/cmdline-opts/location.d deleted file mode 100644 index 9a99a05133..0000000000 --- a/third-party/curl/docs/cmdline-opts/location.d +++ /dev/null @@ -1,33 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: location -Short: L -Help: Follow redirects -Protocols: HTTP -Category: http -Example: -L $URL -Added: 4.9 -See-also: resolve alt-svc -Multi: boolean ---- -If the server reports that the requested page has moved to a different -location (indicated with a Location: header and a 3XX response code), this -option makes curl redo the request on the new place. If used together with ---include or --head, headers from all requested pages are shown. - -When authentication is used, curl only sends its credentials to the initial -host. If a redirect takes curl to a different host, it does not get the -user+password pass on. See also --location-trusted on how to change this. - -Limit the amount of redirects to follow by using the --max-redirs option. - -When curl follows a redirect and if the request is a POST, it sends the -following request with a GET if the HTTP response was 301, 302, or 303. If the -response code was any other 3xx code, curl resends the following request using -the same unmodified method. - -You can tell curl to not change POST requests to GET after a 30x response by -using the dedicated options for that: --post301, --post302 and --post303. - -The method set with --request overrides the method curl would otherwise select -to use. diff --git a/third-party/curl/docs/cmdline-opts/location.md b/third-party/curl/docs/cmdline-opts/location.md new file mode 100644 index 0000000000..4ea115a634 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/location.md @@ -0,0 +1,48 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: location +Short: L +Help: Follow redirects +Protocols: HTTP +Category: http +Added: 4.9 +Multi: boolean +See-also: + - resolve + - alt-svc + - follow + - proto-redir + - max-redirs +Example: + - -L $URL +--- + +# `--location` + +If the server reports that the requested page has moved to a different +location (indicated with a Location: header and a 3XX response code), this +option makes curl redo the request to the new place. If used together with +--show-headers or --head, headers from all requested pages are shown. + +When authentication is provided on the command line (for example --user or +--oauth2-bearer), or when sending a cookie with `-H Cookie:`, curl only sends +its credentials to the initial host. If a redirect takes curl to a different +host, it does not get the credentials passed on. See --location-trusted on how +to change this. When --netrc is used in combination with this option, +credentials for the followed-to hosts may also be selected from that file. + +Limit the amount of redirects to follow by using the --max-redirs option. + +When curl follows a redirect and if the request is a POST, it sends the +following request with a GET if the HTTP response was 301, 302, or 303. If the +response code was any other 3xx code, curl resends the following request using +the same unmodified method. + +You can tell curl to not change POST requests to GET after a 30x response by +using the dedicated options for that: --post301, --post302 and --post303. + +The method set with --request overrides the method curl would otherwise select +to use. + +Restrict which protocols a redirect is accepted to follow with --proto-redir. diff --git a/third-party/curl/docs/cmdline-opts/login-options.d b/third-party/curl/docs/cmdline-opts/login-options.d deleted file mode 100644 index c67be90f87..0000000000 --- a/third-party/curl/docs/cmdline-opts/login-options.d +++ /dev/null @@ -1,25 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: login-options -Arg: -Protocols: IMAP LDAP POP3 SMTP -Help: Server login options -Added: 7.34.0 -Category: imap pop3 smtp auth -Example: --login-options 'AUTH=*' imap://example.com -See-also: user -Multi: single ---- -Specify the login options to use during server authentication. - -You can use login options to specify protocol specific options that may be -used during authentication. At present only IMAP, POP3 and SMTP support login -options. For more information about login options please see RFC 2384, -RFC 5092 and the IETF draft -https://datatracker.ietf.org/doc/html/draft-earhart-url-smtp-00. - -Since 8.2.0, IMAP supports the login option "AUTH=+LOGIN". With this option, -curl uses the plain (not SASL) LOGIN IMAP command even if the server -advertises SASL authentication. Care should be taken in using this option, as -it sends your password over the network in plain text. This does not work if -the IMAP server disables the plain LOGIN (e.g. to prevent password snooping). diff --git a/third-party/curl/docs/cmdline-opts/login-options.md b/third-party/curl/docs/cmdline-opts/login-options.md new file mode 100644 index 0000000000..fc8292a2b9 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/login-options.md @@ -0,0 +1,32 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: login-options +Arg: +Protocols: IMAP LDAP POP3 SMTP +Help: Server login options +Added: 7.34.0 +Category: imap pop3 smtp auth ldap +Multi: single +See-also: + - user +Example: + - --login-options 'AUTH=*' imap://example.com +--- + +# `--login-options` + +Specify the login options to use during server authentication. + +You can use login options to specify protocol specific options that may be +used during authentication. At present only IMAP, POP3 and SMTP support login +options. For more information about login options please see RFC 2384, +RFC 5092 and the IETF draft +https://datatracker.ietf.org/doc/html/draft-earhart-url-smtp-00 + +Since 8.2.0, IMAP supports the login option `AUTH=+LOGIN`. With this option, +curl uses the plain (not SASL) `LOGIN IMAP` command even if the server +advertises SASL authentication. Care should be taken in using this option, as +it sends your password over the network in plain text. This does not work if +the IMAP server disables the plain `LOGIN` (e.g. to prevent password +snooping). diff --git a/third-party/curl/docs/cmdline-opts/mail-auth.d b/third-party/curl/docs/cmdline-opts/mail-auth.d deleted file mode 100644 index 45ceebd99f..0000000000 --- a/third-party/curl/docs/cmdline-opts/mail-auth.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: mail-auth -Arg:
-Protocols: SMTP -Help: Originator address of the original email -Added: 7.25.0 -See-also: mail-rcpt mail-from -Category: smtp -Example: --mail-auth user@example.come -T mail smtp://example.com/ -Multi: single ---- -Specify a single address. This is used to specify the authentication address -(identity) of a submitted message that is being relayed to another server. diff --git a/third-party/curl/docs/cmdline-opts/mail-auth.md b/third-party/curl/docs/cmdline-opts/mail-auth.md new file mode 100644 index 0000000000..deabb38b97 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/mail-auth.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: mail-auth +Arg:
+Protocols: SMTP +Help: Originator address of the original email +Added: 7.25.0 +Category: smtp +Multi: single +See-also: + - mail-rcpt + - mail-from +Example: + - --mail-auth user@example.com -T mail smtp://example.com/ +--- + +# `--mail-auth` + +Specify a single address. This is used to specify the authentication address +(identity) of a submitted message that is being relayed to another server. diff --git a/third-party/curl/docs/cmdline-opts/mail-from.d b/third-party/curl/docs/cmdline-opts/mail-from.d deleted file mode 100644 index 0729e841a9..0000000000 --- a/third-party/curl/docs/cmdline-opts/mail-from.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: mail-from -Arg:
-Help: Mail from this address -Protocols: SMTP -Added: 7.20.0 -See-also: mail-rcpt mail-auth -Category: smtp -Example: --mail-from user@example.com -T mail smtp://example.com/ -Multi: single ---- -Specify a single address that the given mail should get sent from. diff --git a/third-party/curl/docs/cmdline-opts/mail-from.md b/third-party/curl/docs/cmdline-opts/mail-from.md new file mode 100644 index 0000000000..96b062501b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/mail-from.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: mail-from +Arg:
+Help: Mail from this address +Protocols: SMTP +Added: 7.20.0 +Category: smtp +Multi: single +See-also: + - mail-rcpt + - mail-auth +Example: + - --mail-from user@example.com -T mail smtp://example.com/ +--- + +# `--mail-from` + +Specify a single address that the given mail should get sent from. diff --git a/third-party/curl/docs/cmdline-opts/mail-rcpt-allowfails.d b/third-party/curl/docs/cmdline-opts/mail-rcpt-allowfails.d deleted file mode 100644 index d2a5f39d3b..0000000000 --- a/third-party/curl/docs/cmdline-opts/mail-rcpt-allowfails.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: mail-rcpt-allowfails -Help: Allow RCPT TO command to fail for some recipients -Protocols: SMTP -Added: 7.69.0 -Category: smtp -Example: --mail-rcpt-allowfails --mail-rcpt dest@example.com smtp://example.com -See-also: mail-rcpt -Multi: boolean ---- -When sending data to multiple recipients, by default curl aborts SMTP -conversation if at least one of the recipients causes RCPT TO command to -return an error. - -The default behavior can be changed by passing --mail-rcpt-allowfails -command-line option which makes curl ignore errors and proceed with the -remaining valid recipients. - -If all recipients trigger RCPT TO failures and this flag is specified, curl -still aborts the SMTP conversation and returns the error received from to the -last RCPT TO command. diff --git a/third-party/curl/docs/cmdline-opts/mail-rcpt-allowfails.md b/third-party/curl/docs/cmdline-opts/mail-rcpt-allowfails.md new file mode 100644 index 0000000000..a82948bbc4 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/mail-rcpt-allowfails.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: mail-rcpt-allowfails +Help: Allow RCPT TO command to fail +Protocols: SMTP +Added: 7.69.0 +Category: smtp +Multi: boolean +See-also: + - mail-rcpt +Example: + - --mail-rcpt-allowfails --mail-rcpt dest@example.com smtp://example.com +--- + +# `--mail-rcpt-allowfails` + +When sending data to multiple recipients, by default curl aborts SMTP +conversation if at least one of the recipients causes RCPT TO command to +return an error. + +The default behavior can be changed by passing --mail-rcpt-allowfails +command-line option which makes curl ignore errors and proceed with the +remaining valid recipients. + +If all recipients trigger RCPT TO failures and this flag is specified, curl +still aborts the SMTP conversation and returns the error received from to the +last RCPT TO command. diff --git a/third-party/curl/docs/cmdline-opts/mail-rcpt.d b/third-party/curl/docs/cmdline-opts/mail-rcpt.d deleted file mode 100644 index a4b16c4f7b..0000000000 --- a/third-party/curl/docs/cmdline-opts/mail-rcpt.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: mail-rcpt -Arg:
-Help: Mail to this address -Protocols: SMTP -Added: 7.20.0 -Category: smtp -Example: --mail-rcpt user@example.net smtp://example.com -See-also: mail-rcpt-allowfails -Multi: append ---- -Specify a single email address, user name or mailing list name. Repeat this -option several times to send to multiple recipients. - -When performing an address verification (**VRFY** command), the recipient should be -specified as the user name or user name and domain (as per Section 3.5 of -RFC 5321). (Added in 7.34.0) - -When performing a mailing list expand (EXPN command), the recipient should be -specified using the mailing list name, such as "Friends" or "London-Office". -(Added in 7.34.0) diff --git a/third-party/curl/docs/cmdline-opts/mail-rcpt.md b/third-party/curl/docs/cmdline-opts/mail-rcpt.md new file mode 100644 index 0000000000..bd787c2fa0 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/mail-rcpt.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: mail-rcpt +Arg:
+Help: Mail to this address +Protocols: SMTP +Added: 7.20.0 +Category: smtp +Multi: append +See-also: + - mail-rcpt-allowfails +Example: + - --mail-rcpt user@example.net smtp://example.com +--- + +# `--mail-rcpt` + +Specify a single email address, username or mailing list name. Repeat this +option several times to send to multiple recipients. + +When performing an address verification (**VRFY** command), the recipient +should be specified as the username or username and domain (as per Section 3.5 +of RFC 5321). (Added in 7.34.0) + +When performing a mailing list expand (EXPN command), the recipient should be +specified using the mailing list name, such as "Friends" or "London-Office". +(Added in 7.34.0) diff --git a/third-party/curl/docs/cmdline-opts/mainpage.idx b/third-party/curl/docs/cmdline-opts/mainpage.idx new file mode 100644 index 0000000000..8496ee46dc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/mainpage.idx @@ -0,0 +1,43 @@ +#*************************************************************************** +# _ _ ____ _ +# Project ___| | | | _ \| | +# / __| | | | |_) | | +# | (__| |_| | _ <| |___ +# \___|\___/|_| \_\_____| +# +# Copyright (C) Daniel Stenberg, , et al. +# +# This software is licensed as described in the file COPYING, which +# you should have received as part of this distribution. The terms +# are also available at https://curl.se/docs/copyright.html. +# +# You may opt to use, copy, modify, merge, publish, distribute and/or sell +# copies of the Software, and permit persons to whom the Software is +# furnished to do so, under the terms of the COPYING file. +# +# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY +# KIND, either express or implied. +# +# SPDX-License-Identifier: curl +# +########################################################################### +_NAME.md +_SYNOPSIS.md +_DESCRIPTION.md +_URL.md +_GLOBBING.md +_VARIABLES.md +_OUTPUT.md +_PROTOCOLS.md +_PROGRESS.md +_VERSION.md +_OPTIONS.md +%options +_FILES.md +_ENVIRONMENT.md +_PROXYPREFIX.md +_EXITCODES.md +_BUGS.md +_AUTHORS.md +_WWW.md +_SEEALSO.md diff --git a/third-party/curl/docs/cmdline-opts/manual.d b/third-party/curl/docs/cmdline-opts/manual.d deleted file mode 100644 index 9ee4d075ad..0000000000 --- a/third-party/curl/docs/cmdline-opts/manual.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: manual -Short: M -Help: Display the full manual -Category: curl -Example: --manual -Added: 5.2 -See-also: verbose libcurl trace -Multi: custom ---- -Manual. Display the huge help text. diff --git a/third-party/curl/docs/cmdline-opts/manual.md b/third-party/curl/docs/cmdline-opts/manual.md new file mode 100644 index 0000000000..bf44f3b8ad --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/manual.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: manual +Short: M +Help: Display the full manual +Category: curl +Added: 5.2 +Multi: custom +See-also: + - verbose + - libcurl + - trace +Example: + - --manual +--- + +# `--manual` + +Manual. Display the huge help text. diff --git a/third-party/curl/docs/cmdline-opts/max-filesize.d b/third-party/curl/docs/cmdline-opts/max-filesize.d deleted file mode 100644 index ada730d926..0000000000 --- a/third-party/curl/docs/cmdline-opts/max-filesize.d +++ /dev/null @@ -1,23 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: max-filesize -Arg: -Help: Maximum file size to download -Protocols: FTP HTTP MQTT -See-also: limit-rate -Category: connection -Example: --max-filesize 100K $URL -Added: 7.10.8 -Multi: single ---- -Specify the maximum size (in bytes) of a file to download. If the file -requested is larger than this value, the transfer does not start and curl -returns with exit code 63. - -A size modifier may be used. For example, Appending 'k' or 'K' counts the -number as kilobytes, 'm' or 'M' makes it megabytes, while 'g' or 'G' makes it -gigabytes. Examples: 200K, 3m and 1G. (Added in 7.58.0) - -**NOTE**: The file size is not always known prior to download, and for such -files this option has no effect even if the file transfer ends up being larger -than this given limit. diff --git a/third-party/curl/docs/cmdline-opts/max-filesize.md b/third-party/curl/docs/cmdline-opts/max-filesize.md new file mode 100644 index 0000000000..02b2293c56 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/max-filesize.md @@ -0,0 +1,42 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: max-filesize +Arg: +Help: Maximum file size to download +Protocols: FTP HTTP MQTT +Category: connection +Added: 7.10.8 +Multi: single +See-also: + - limit-rate +Example: + - --max-filesize 100K $URL + - --max-filesize 2.6M $URL +--- + +# `--max-filesize` + +When set to a non-zero value, it specifies the maximum size (in bytes) of a +file to download. If the file requested is larger than this value, the +transfer does not start and curl returns with exit code 63. + +Setting the maximum value to zero disables the limit. + +A unit suffix letter can be used. Appending 'k' or 'K' counts the number as +kilobytes, 'm' or 'M' makes it megabytes etc. The supported suffixes (k, M, G, +T, P) are 1024-based. Examples: 200K, 3m and 1G. (Added in 7.58.0) + +**NOTE**: before curl 8.4.0, when the file size is not known prior to +download, for such files this option has no effect even if the file transfer +ends up being larger than this given limit. + +Starting with curl 8.4.0, this option aborts the transfer if it reaches the +threshold during transfer. + +Starting in curl 8.19.0, the maximum size can be specified using a fraction as +in `2.5M` for two and a half megabytes. It only works with a period (`.`) +delimiter, independent of what your locale might prefer. + +Since 8.20.0, this option also stops ongoing transfers that would reach this +threshold due to automatic decompression using --compressed. diff --git a/third-party/curl/docs/cmdline-opts/max-redirs.d b/third-party/curl/docs/cmdline-opts/max-redirs.d deleted file mode 100644 index 31ce98ea5e..0000000000 --- a/third-party/curl/docs/cmdline-opts/max-redirs.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: max-redirs -Arg: -Help: Maximum number of redirects allowed -Protocols: HTTP -Category: http -Example: --max-redirs 3 --location $URL -Added: 7.5 -See-also: location -Multi: single ---- -Set maximum number of redirections to follow. When --location is used, to -prevent curl from following too many redirects, by default, the limit is -set to 50 redirects. Set this option to -1 to make it unlimited. diff --git a/third-party/curl/docs/cmdline-opts/max-redirs.md b/third-party/curl/docs/cmdline-opts/max-redirs.md new file mode 100644 index 0000000000..02bdfaa7fb --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/max-redirs.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: max-redirs +Arg: +Help: Maximum number of redirects allowed +Protocols: HTTP +Category: http +Added: 7.5 +Multi: single +See-also: + - location + - follow +Example: + - --max-redirs 3 --location $URL +--- + +# `--max-redirs` + +Set the maximum number of redirections to follow. When --location or --follow +are used, this option prevents curl from following too many redirects. By +default the limit is set to 50 redirects. Set this option to -1 to make it +unlimited. diff --git a/third-party/curl/docs/cmdline-opts/max-time.d b/third-party/curl/docs/cmdline-opts/max-time.d deleted file mode 100644 index 0d5747b26f..0000000000 --- a/third-party/curl/docs/cmdline-opts/max-time.d +++ /dev/null @@ -1,23 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: max-time -Short: m -Arg: -Help: Maximum time allowed for transfer -See-also: connect-timeout retry-max-time -Category: connection -Example: --max-time 10 $URL -Example: --max-time 2.92 $URL -Added: 4.0 -Multi: single ---- -Maximum time in seconds that you allow each transfer to take. This is useful -for preventing your batch jobs from hanging for hours due to slow networks or -links going down. This option accepts decimal values (added in 7.32.0). - -If you enable retrying the transfer (--retry) then the maximum time counter is -reset each time the transfer is retried. You can use --retry-max-time to limit -the retry time. - -The decimal value needs to provided using a dot (.) as decimal separator - not -the local version even if it might be using another separator. diff --git a/third-party/curl/docs/cmdline-opts/max-time.md b/third-party/curl/docs/cmdline-opts/max-time.md new file mode 100644 index 0000000000..2475dd1986 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/max-time.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: max-time +Short: m +Arg: +Help: Maximum time allowed for transfer +Category: connection timeout +Added: 4.0 +Multi: single +See-also: + - connect-timeout + - retry-max-time +Example: + - --max-time 10 $URL + - --max-time 2.92 $URL +--- + +# `--max-time` + +Set the maximum time in seconds that you allow each transfer to take. Prevents +your batch jobs from hanging for hours due to slow networks or links going +down. This option accepts decimal values (added in 7.32.0). + +If you enable retrying the transfer (--retry) then the maximum time counter is +reset each time the transfer is retried. You can use --retry-max-time to limit +the retry time. + +The decimal value needs to be provided using a dot (.) as decimal separator - +not the local version even if it might be using another separator. diff --git a/third-party/curl/docs/cmdline-opts/metalink.d b/third-party/curl/docs/cmdline-opts/metalink.d deleted file mode 100644 index 88f012176e..0000000000 --- a/third-party/curl/docs/cmdline-opts/metalink.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: metalink -Help: Process given URLs as metalink XML file -Added: 7.27.0 -Category: misc -Example: --metalink file $URL -See-also: parallel -Multi: single ---- -This option was previously used to specify a Metalink resource. Metalink -support is disabled in curl for security reasons (added in 7.78.0). diff --git a/third-party/curl/docs/cmdline-opts/metalink.md b/third-party/curl/docs/cmdline-opts/metalink.md new file mode 100644 index 0000000000..d3d3e25746 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/metalink.md @@ -0,0 +1,18 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: metalink +Help: Process given URLs as metalink XML file +Added: 7.27.0 +Category: deprecated +Multi: single +See-also: + - parallel +Example: + - --metalink file $URL +--- + +# `--metalink` + +This option was previously used to specify a Metalink resource. Metalink +support is disabled in curl for security reasons (added in 7.78.0). diff --git a/third-party/curl/docs/cmdline-opts/mptcp.md b/third-party/curl/docs/cmdline-opts/mptcp.md new file mode 100644 index 0000000000..4a1bb65c06 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/mptcp.md @@ -0,0 +1,31 @@ +--- +c: Copyright (C) Dorian Craps, +SPDX-License-Identifier: curl +Long: mptcp +Added: 8.9.0 +Help: Enable Multipath TCP +Category: connection +Multi: boolean +See-also: + - tcp-fastopen +Example: + - --mptcp $URL +--- + +# `--mptcp` + +Enable the use of Multipath TCP (MPTCP) for connections. MPTCP is an extension +to the standard TCP that allows multiple TCP streams over different network +paths between the same source and destination. This can enhance bandwidth and +improve reliability by using multiple paths simultaneously. + +MPTCP is beneficial in networks where multiple paths exist between clients and +servers, such as mobile networks where a device may switch between WiFi and +cellular data or in wired networks with multiple Internet Service Providers. + +This option is currently only supported on Linux starting from kernel 5.6. Only +TCP connections are modified, hence this option does not affect HTTP/3 (QUIC) +or UDP connections. + +The server curl connects to must also support MPTCP. If not, the connection +seamlessly falls back to TCP. diff --git a/third-party/curl/docs/cmdline-opts/negotiate.d b/third-party/curl/docs/cmdline-opts/negotiate.d deleted file mode 100644 index f1dd34dbaf..0000000000 --- a/third-party/curl/docs/cmdline-opts/negotiate.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: negotiate -Help: Use HTTP Negotiate (SPNEGO) authentication -Protocols: HTTP -See-also: basic ntlm anyauth proxy-negotiate -Category: auth http -Example: --negotiate -u : $URL -Added: 7.10.6 -Multi: mutex ---- -Enables Negotiate (SPNEGO) authentication. - -This option requires a library built with GSS-API or SSPI support. Use ---version to see if your curl supports GSS-API/SSPI or SPNEGO. - -When using this option, you must also provide a fake --user option to activate -the authentication code properly. Sending a '-u :' is enough as the user name -and password from the --user option are not actually used. diff --git a/third-party/curl/docs/cmdline-opts/negotiate.md b/third-party/curl/docs/cmdline-opts/negotiate.md new file mode 100644 index 0000000000..b7982d7c48 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/negotiate.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: negotiate +Help: Use HTTP Negotiate (SPNEGO) authentication +Protocols: HTTP +Category: auth http +Added: 7.10.6 +Multi: boolean +See-also: + - basic + - ntlm + - anyauth + - proxy-negotiate +Example: + - --negotiate -u : $URL +--- + +# `--negotiate` + +Enable Negotiate (SPNEGO) authentication. + +This option requires a library built with GSS-API or SSPI support. Use +--version to see if your curl supports GSS-API/SSPI or SPNEGO. + +When using this option, you must also provide a fake --user option to activate +the authentication code properly. Sending a '-u :' is enough as the username +and password from the --user option are not actually used. diff --git a/third-party/curl/docs/cmdline-opts/netrc-file.d b/third-party/curl/docs/cmdline-opts/netrc-file.d deleted file mode 100644 index 7b1a214da2..0000000000 --- a/third-party/curl/docs/cmdline-opts/netrc-file.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: netrc-file -Help: Specify FILE for netrc -Arg: -Added: 7.21.5 -Mutexed: netrc -Category: curl -Example: --netrc-file netrc $URL -See-also: netrc user config -Multi: single ---- -This option is similar to --netrc, except that you provide the path (absolute -or relative) to the netrc file that curl should use. You can only specify one -netrc file per invocation. - -It abides by --netrc-optional if specified. diff --git a/third-party/curl/docs/cmdline-opts/netrc-file.md b/third-party/curl/docs/cmdline-opts/netrc-file.md new file mode 100644 index 0000000000..3df72ce145 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/netrc-file.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: netrc-file +Help: Specify FILE for netrc +Arg: +Added: 7.21.5 +Mutexed: netrc +Category: auth +Multi: single +See-also: + - netrc + - user + - config +Example: + - --netrc-file netrc $URL +--- + +# `--netrc-file` + +Set the netrc file to use. Similar to --netrc, except that you also provide +the path (absolute or relative). + +It abides by --netrc-optional if specified. diff --git a/third-party/curl/docs/cmdline-opts/netrc-optional.d b/third-party/curl/docs/cmdline-opts/netrc-optional.d deleted file mode 100644 index a7759640f9..0000000000 --- a/third-party/curl/docs/cmdline-opts/netrc-optional.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: netrc-optional -Help: Use either .netrc or URL -Mutexed: netrc -See-also: netrc-file -Category: curl -Example: --netrc-optional $URL -Added: 7.9.8 -Multi: boolean ---- -Similar to --netrc, but this option makes the .netrc usage **optional** -and not mandatory as the --netrc option does. diff --git a/third-party/curl/docs/cmdline-opts/netrc-optional.md b/third-party/curl/docs/cmdline-opts/netrc-optional.md new file mode 100644 index 0000000000..9b9c068c88 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/netrc-optional.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: netrc-optional +Help: Use either .netrc or URL +Mutexed: netrc +Category: auth +Added: 7.9.8 +Multi: boolean +See-also: + - netrc-file +Example: + - --netrc-optional $URL +--- + +# `--netrc-optional` + +Similar to --netrc, but this option makes the .netrc usage **optional** +and not mandatory as the --netrc option does. diff --git a/third-party/curl/docs/cmdline-opts/netrc.d b/third-party/curl/docs/cmdline-opts/netrc.d deleted file mode 100644 index 46e8778fa0..0000000000 --- a/third-party/curl/docs/cmdline-opts/netrc.d +++ /dev/null @@ -1,27 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: netrc -Short: n -Help: Must read .netrc for user name and password -Category: curl -Example: --netrc $URL -Added: 4.6 -See-also: netrc-file config user -Mutexed: netrc-file netrc-optional -Multi: boolean ---- -Makes curl scan the *.netrc* (*_netrc* on Windows) file in the user's home -directory for login name and password. This is typically used for FTP on -Unix. If used with HTTP, curl enables user authentication. See *netrc(5)* and -*ftp(1)* for details on the file format. Curl does not complain if that file -does not have the right permissions (it should be neither world- nor -group-readable). The environment variable "HOME" is used to find the home -directory. - -A quick and simple example of how to setup a *.netrc* to allow curl to FTP to -the machine host.domain.com with user name 'myself' and password 'secret' -could look similar to: - - machine host.domain.com - login myself - password secret diff --git a/third-party/curl/docs/cmdline-opts/netrc.md b/third-party/curl/docs/cmdline-opts/netrc.md new file mode 100644 index 0000000000..03a7ed6e5d --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/netrc.md @@ -0,0 +1,52 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: netrc +Short: n +Help: Must read .netrc for username and password +Category: auth +Added: 4.6 +Mutexed: netrc-file netrc-optional +Multi: boolean +See-also: + - netrc-file + - config + - user +Example: + - --netrc $URL +--- + +# `--netrc` + +Make curl scan the *.netrc* file in the user's home directory for login name +and password. This is typically used for FTP on Unix. If used with HTTP, curl +enables user authentication. See *netrc(5)* and *ftp(1)* for details on the +file format. curl does not complain if that file does not have the right +permissions (it should be neither world- nor group-readable). The environment +variable `HOME` is used to find the home directory. If the `NETRC` environment +variable is set, that filename is used as the netrc file. (Added in 8.16.0) + +If --netrc-file is used, that overrides all other ways to figure out the file. + +The netrc file provides credentials for a hostname independent of which +protocol and port number that are used. + +On Windows two filenames in the home directory are checked: *.netrc* and +*_netrc*, preferring the former. Older versions on Windows checked for +*_netrc* only. + +A quick and simple example of how to setup a *.netrc* to allow curl to access +the machine host.example.com with username `myself` and password `secret` +could look similar to: + + machine host.example.com + login myself + password secret + +curl also supports the `default` keyword. This is the same as machine name +except that default matches any name. There can be only one `default` token, +and it must be after all machine tokens. + +When providing a username in the URL and a *.netrc* file, curl looks for the +password for that specific user for the given host if such an entry appears in +the file before a "generic" `machine` entry without `login` specified. diff --git a/third-party/curl/docs/cmdline-opts/next.d b/third-party/curl/docs/cmdline-opts/next.d deleted file mode 100644 index 93c9c45b38..0000000000 --- a/third-party/curl/docs/cmdline-opts/next.d +++ /dev/null @@ -1,27 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: : -Long: next -Tags: -Protocols: -Added: 7.36.0 -Magic: divider -Help: Make next URL use its separate set of options -Category: curl -Example: $URL --next -d postthis www2.example.com -Example: -I $URL --next https://example.net/ -See-also: parallel config -Multi: append ---- -Tells curl to use a separate operation for the following URL and associated -options. This allows you to send several URL requests, each with their own -specific options, for example, such as different user names or custom requests -for each. - ---next resets all local options and only global ones have their values survive -over to the operation following the --next instruction. Global options include ---verbose, --trace, --trace-ascii and --fail-early. - -For example, you can do both a GET and a POST in a single command line: - - curl www1.example.com --next -d postthis www2.example.com diff --git a/third-party/curl/docs/cmdline-opts/next.md b/third-party/curl/docs/cmdline-opts/next.md new file mode 100644 index 0000000000..cb67e907f4 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/next.md @@ -0,0 +1,33 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: : +Long: next +Tags: +Protocols: +Added: 7.36.0 +Magic: divider +Help: Make next URL use separate options +Category: curl +Multi: append +See-also: + - parallel + - config +Example: + - $URL --next -d postthis www2.example.com + - -I $URL --next https://example.net/ +--- + +# `--next` + +Use a separate operation for the following URL and associated options. This +allows you to send several URL requests, each with their own specific options, +for example, such as different usernames or custom requests for each. + +--next resets all local options and only global ones have their values survive +over to the operation following the --next instruction. Global options include +--verbose, --trace, --trace-ascii and --fail-early. + +For example, you can do both a GET and a POST in a single command line: + + curl www1.example.com --next -d postthis www2.example.com diff --git a/third-party/curl/docs/cmdline-opts/no-alpn.d b/third-party/curl/docs/cmdline-opts/no-alpn.d deleted file mode 100644 index 102f2990e5..0000000000 --- a/third-party/curl/docs/cmdline-opts/no-alpn.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: no-alpn -Tags: HTTP/2 -Protocols: HTTPS -Added: 7.36.0 -See-also: no-npn http2 -Requires: TLS -Help: Disable the ALPN TLS extension -Category: tls http -Example: --no-alpn $URL -Multi: boolean ---- -Disable the ALPN TLS extension. ALPN is enabled by default if libcurl was built -with an SSL library that supports ALPN. ALPN is used by a libcurl that supports -HTTP/2 to negotiate HTTP/2 support with the server during https sessions. - -Note that this is the negated option name documented. You can use --alpn to -enable ALPN. diff --git a/third-party/curl/docs/cmdline-opts/no-alpn.md b/third-party/curl/docs/cmdline-opts/no-alpn.md new file mode 100644 index 0000000000..4752948787 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/no-alpn.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: no-alpn +Tags: HTTP/2 +Protocols: HTTPS +Added: 7.36.0 +Requires: TLS +Help: Disable the ALPN TLS extension +Category: tls http +Multi: boolean +See-also: + - no-npn + - http2 +Example: + - --no-alpn $URL +--- + +# `--no-alpn` + +Disable the ALPN TLS extension. ALPN is enabled by default if libcurl was built +with an SSL library that supports ALPN. ALPN is used by a libcurl that supports +HTTP/2 to negotiate HTTP/2 support with the server during https sessions. + +Note that this is the negated option name documented. You can use --alpn to +enable ALPN. diff --git a/third-party/curl/docs/cmdline-opts/no-buffer.d b/third-party/curl/docs/cmdline-opts/no-buffer.d deleted file mode 100644 index 33f6fbc5bf..0000000000 --- a/third-party/curl/docs/cmdline-opts/no-buffer.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: no-buffer -Short: N -Help: Disable buffering of the output stream -Category: curl -Example: --no-buffer $URL -Added: 6.5 -See-also: progress-bar -Multi: boolean ---- -Disables the buffering of the output stream. In normal work situations, curl -uses a standard buffered output stream that has the effect that it outputs the -data in chunks, not necessarily exactly when the data arrives. Using this -option disables that buffering. - -Note that this is the negated option name documented. You can use --buffer to -enable buffering again. diff --git a/third-party/curl/docs/cmdline-opts/no-buffer.md b/third-party/curl/docs/cmdline-opts/no-buffer.md new file mode 100644 index 0000000000..442beb0b3c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/no-buffer.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: no-buffer +Short: N +Help: Disable buffering of the output stream +Category: output +Added: 6.5 +Multi: boolean +See-also: + - progress-bar +Example: + - --no-buffer $URL +--- + +# `--no-buffer` + +Disable the buffering of the output stream. In normal work situations, curl +uses a standard buffered output stream that has the effect that it outputs the +data in chunks, not necessarily exactly when the data arrives. Using this +option disables that buffering. + +Note that this is the negated option name documented. You can use --buffer to +enable buffering again. diff --git a/third-party/curl/docs/cmdline-opts/no-clobber.d b/third-party/curl/docs/cmdline-opts/no-clobber.d deleted file mode 100644 index 9325558da6..0000000000 --- a/third-party/curl/docs/cmdline-opts/no-clobber.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: no-clobber -Help: Do not overwrite files that already exist -Category: curl output -Added: 7.83.0 -See-also: output remote-name -Example: --no-clobber --output local/dir/file $URL -Multi: boolean ---- -When used in conjunction with the --output, --remote-header-name, ---remote-name, or --remote-name-all options, curl avoids overwriting files -that already exist. Instead, a dot and a number gets appended to the name of -the file that would be created, up to filename.100 after which it does not -create any file. - -Note that this is the negated option name documented. You can thus use ---clobber to enforce the clobbering, even if --remote-header-name is -specified. diff --git a/third-party/curl/docs/cmdline-opts/no-clobber.md b/third-party/curl/docs/cmdline-opts/no-clobber.md new file mode 100644 index 0000000000..02a74b25e4 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/no-clobber.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: no-clobber +Help: Do not overwrite files that already exist +Category: output +Added: 7.83.0 +Multi: boolean +See-also: + - output + - remote-name +Example: + - --no-clobber --output local/dir/file $URL +--- + +# `--no-clobber` + +When used in conjunction with the --output, --remote-header-name, +--remote-name, or --remote-name-all options, curl avoids overwriting files +that already exist. Instead, a dot and a number gets appended to the name of +the file that would be created, up to filename.100 after which it does not +create any file. + +Note that this is the negated option name documented. You can thus use +--clobber to enforce the clobbering, even if --remote-header-name is +specified. + +The --continue-at option cannot be used together with --no-clobber. diff --git a/third-party/curl/docs/cmdline-opts/no-keepalive.d b/third-party/curl/docs/cmdline-opts/no-keepalive.d deleted file mode 100644 index 0aeaef8d53..0000000000 --- a/third-party/curl/docs/cmdline-opts/no-keepalive.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: no-keepalive -Help: Disable TCP keepalive on the connection -Category: connection -Example: --no-keepalive $URL -Added: 7.18.0 -See-also: keepalive-time -Multi: boolean ---- -Disables the use of keepalive messages on the TCP connection. curl otherwise -enables them by default. - -Note that this is the negated option name documented. You can thus use ---keepalive to enforce keepalive. diff --git a/third-party/curl/docs/cmdline-opts/no-keepalive.md b/third-party/curl/docs/cmdline-opts/no-keepalive.md new file mode 100644 index 0000000000..99dd0329db --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/no-keepalive.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: no-keepalive +Help: Disable TCP keepalive on the connection +Category: connection +Added: 7.18.0 +Multi: boolean +See-also: + - keepalive-time + - keepalive-cnt +Example: + - --no-keepalive $URL +--- + +# `--no-keepalive` + +Disable the use of keepalive messages on the TCP connection. curl otherwise +enables them by default. + +Note that this is the negated option name documented. You can thus use +--keepalive to enforce keepalive. diff --git a/third-party/curl/docs/cmdline-opts/no-npn.d b/third-party/curl/docs/cmdline-opts/no-npn.d deleted file mode 100644 index cd0e5e2af5..0000000000 --- a/third-party/curl/docs/cmdline-opts/no-npn.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: no-npn -Tags: Versions HTTP/2 -Protocols: HTTPS -Added: 7.36.0 -Mutexed: -See-also: no-alpn http2 -Requires: TLS -Help: Disable the NPN TLS extension -Category: tls http -Example: --no-npn $URL -Multi: boolean ---- -curl never uses NPN, this option has no effect (added in 7.86.0). - -Disable the NPN TLS extension. NPN is enabled by default if libcurl was built -with an SSL library that supports NPN. NPN is used by a libcurl that supports -HTTP/2 to negotiate HTTP/2 support with the server during https sessions. diff --git a/third-party/curl/docs/cmdline-opts/no-npn.md b/third-party/curl/docs/cmdline-opts/no-npn.md new file mode 100644 index 0000000000..dbb69e91bb --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/no-npn.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: no-npn +Tags: Versions HTTP/2 +Protocols: HTTPS +Added: 7.36.0 +Mutexed: +Requires: TLS +Help: Disable the NPN TLS extension +Category: deprecated +Multi: boolean +See-also: + - no-alpn + - http2 +Example: + - --no-npn $URL +--- + +# `--no-npn` + +curl never uses NPN, this option has no effect (added in 7.86.0). + +Disable the NPN TLS extension. NPN is enabled by default if libcurl was built +with an SSL library that supports NPN. NPN is used by a libcurl that supports +HTTP/2 to negotiate HTTP/2 support with the server during https sessions. diff --git a/third-party/curl/docs/cmdline-opts/no-progress-meter.d b/third-party/curl/docs/cmdline-opts/no-progress-meter.d deleted file mode 100644 index 820557d9d5..0000000000 --- a/third-party/curl/docs/cmdline-opts/no-progress-meter.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: no-progress-meter -Help: Do not show the progress meter -See-also: verbose silent -Added: 7.67.0 -Category: verbose -Example: --no-progress-meter -o store $URL -Multi: boolean ---- -Option to switch off the progress meter output without muting or otherwise -affecting warning and informational messages like --silent does. - -Note that this is the negated option name documented. You can thus use ---progress-meter to enable the progress meter again. diff --git a/third-party/curl/docs/cmdline-opts/no-progress-meter.md b/third-party/curl/docs/cmdline-opts/no-progress-meter.md new file mode 100644 index 0000000000..72ec993762 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/no-progress-meter.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: no-progress-meter +Help: Do not show the progress meter +Added: 7.67.0 +Category: verbose +Multi: boolean +See-also: + - verbose + - silent +Example: + - --no-progress-meter -o store $URL +--- + +# `--no-progress-meter` + +Option to switch off the progress meter output without muting or otherwise +affecting warning and informational messages like --silent does. + +Note that this is the negated option name documented. You can thus use +--progress-meter to enable the progress meter again. diff --git a/third-party/curl/docs/cmdline-opts/no-sessionid.d b/third-party/curl/docs/cmdline-opts/no-sessionid.d deleted file mode 100644 index 9699f46bc9..0000000000 --- a/third-party/curl/docs/cmdline-opts/no-sessionid.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: no-sessionid -Help: Disable SSL session-ID reusing -Protocols: TLS -Added: 7.16.0 -Category: tls -Example: --no-sessionid $URL -See-also: insecure -Multi: boolean ---- -Disable curl's use of SSL session-ID caching. By default all transfers are -done using the cache. Note that while nothing should ever get hurt by -attempting to reuse SSL session-IDs, there seem to be broken SSL -implementations in the wild that may require you to disable this in order for -you to succeed. - -Note that this is the negated option name documented. You can thus use ---sessionid to enforce session-ID caching. diff --git a/third-party/curl/docs/cmdline-opts/no-sessionid.md b/third-party/curl/docs/cmdline-opts/no-sessionid.md new file mode 100644 index 0000000000..08ba990bee --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/no-sessionid.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: no-sessionid +Help: Disable SSL session-ID reusing +Protocols: TLS +Added: 7.16.0 +Category: tls +Multi: boolean +See-also: + - insecure +Example: + - --no-sessionid $URL +--- + +# `--no-sessionid` + +Disable curl's use of SSL session-ID caching. By default all transfers are +done using the cache. Note that while nothing should ever get hurt by +attempting to reuse SSL session-IDs, there seem to be broken SSL +implementations in the wild that may require you to disable this in order for +you to succeed. + +Note that this is the negated option name documented. You can thus use +--sessionid to enforce session-ID caching. diff --git a/third-party/curl/docs/cmdline-opts/noproxy.d b/third-party/curl/docs/cmdline-opts/noproxy.d deleted file mode 100644 index 001c109b69..0000000000 --- a/third-party/curl/docs/cmdline-opts/noproxy.d +++ /dev/null @@ -1,27 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: noproxy -Arg: -Help: List of hosts which do not use proxy -Added: 7.19.4 -Category: proxy -Example: --noproxy "www.example" $URL -See-also: proxy -Multi: single ---- -Comma-separated list of hosts for which not to use a proxy, if one is -specified. The only wildcard is a single * character, which matches all hosts, -and effectively disables the proxy. Each name in this list is matched as -either a domain which contains the hostname, or the hostname itself. For -example, local.com would match local.com, local.com:80, and www.local.com, but -not www.notlocal.com. - -This option overrides the environment variables that disable the proxy -('no_proxy' and 'NO_PROXY') (added in 7.53.0). If there is an environment -variable disabling a proxy, you can set the no proxy list to "" to override -it. - -IP addresses specified to this option can be provided using CIDR notation -(added in 7.86.0): an appended slash and number specifies the number of -"network bits" out of the address to use in the comparison. For example -"192.168.0.0/16" would match all addresses starting with "192.168". diff --git a/third-party/curl/docs/cmdline-opts/noproxy.md b/third-party/curl/docs/cmdline-opts/noproxy.md new file mode 100644 index 0000000000..10b74ecbf4 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/noproxy.md @@ -0,0 +1,36 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: noproxy +Arg: +Help: List of hosts which do not use proxy +Added: 7.19.4 +Category: proxy +Multi: single +See-also: + - proxy +Example: + - --noproxy "www.example" $URL +--- + +# `--noproxy` + +Comma-separated list of hosts for which not to use a proxy, if one is +specified. The only wildcard is a single `*` character, which matches all +hosts, and effectively disables the proxy. Each name in this list is matched +as either a domain which contains the hostname, or the hostname itself. For +example, `local.com` would match `local.com`, `local.com:80`, and +`www.local.com`, but not `www.notlocal.com`. + +To use international hostnames in this list, add the punycode version of the +hostname. + +This option overrides the environment variables that disable the proxy +(`no_proxy` and `NO_PROXY`) (added in 7.53.0). If there is an environment +variable disabling a proxy, you can set the no proxy list to "" to override +it. + +IP addresses specified to this option can be provided using CIDR notation +(added in 7.86.0): an appended slash and number specifies the number of +network bits out of the address to use in the comparison. For example +`192.168.0.0/16` would match all addresses starting with `192.168`. diff --git a/third-party/curl/docs/cmdline-opts/ntlm-wb.d b/third-party/curl/docs/cmdline-opts/ntlm-wb.d deleted file mode 100644 index 4a32252936..0000000000 --- a/third-party/curl/docs/cmdline-opts/ntlm-wb.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ntlm-wb -Help: Use HTTP NTLM authentication with winbind -Protocols: HTTP -See-also: ntlm proxy-ntlm -Category: auth http -Example: --ntlm-wb -u user:password $URL -Added: 7.22.0 -Multi: mutex ---- -Enables NTLM much in the style --ntlm does, but hand over the authentication -to the separate binary ntlmauth application that is executed when needed. diff --git a/third-party/curl/docs/cmdline-opts/ntlm-wb.md b/third-party/curl/docs/cmdline-opts/ntlm-wb.md new file mode 100644 index 0000000000..3a1d35cb16 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ntlm-wb.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ntlm-wb +Help: HTTP NTLM authentication with winbind +Protocols: HTTP +Category: deprecated +Added: 7.22.0 +Multi: mutex +See-also: + - ntlm + - proxy-ntlm +Example: + - --ntlm-wb -u user:password $URL +--- + +# `--ntlm-wb` + +Deprecated option (added in 8.8.0). + +Enabled NTLM much in the style --ntlm does, but handed over the authentication +to a separate executable that was executed when needed. diff --git a/third-party/curl/docs/cmdline-opts/ntlm.d b/third-party/curl/docs/cmdline-opts/ntlm.d deleted file mode 100644 index cc98c51e34..0000000000 --- a/third-party/curl/docs/cmdline-opts/ntlm.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ntlm -Help: Use HTTP NTLM authentication -Mutexed: basic negotiate digest anyauth -See-also: proxy-ntlm -Protocols: HTTP -Requires: TLS -Category: auth http -Example: --ntlm -u user:password $URL -Added: 7.10.6 -Multi: mutex ---- -Enables NTLM authentication. The NTLM authentication method was designed by -Microsoft and is used by IIS web servers. It is a proprietary protocol, -reverse-engineered by clever people and implemented in curl based on their -efforts. This kind of behavior should not be endorsed, you should encourage -everyone who uses NTLM to switch to a public and documented authentication -method instead, such as Digest. - -If you want to enable NTLM for your proxy authentication, then use ---proxy-ntlm. diff --git a/third-party/curl/docs/cmdline-opts/ntlm.md b/third-party/curl/docs/cmdline-opts/ntlm.md new file mode 100644 index 0000000000..6850e115ae --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ntlm.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ntlm +Help: HTTP NTLM authentication +Protocols: HTTP +Requires: TLS +Category: auth http +Added: 7.10.6 +Multi: boolean +See-also: + - proxy-ntlm +Example: + - --ntlm -u user:password $URL +--- + +# `--ntlm` + +Use NTLM authentication. The NTLM authentication method was designed by +Microsoft and is used by IIS web servers. It is a proprietary protocol, +reverse-engineered by clever people and implemented in curl based on their +efforts. This kind of behavior should not be endorsed, you should encourage +everyone who uses NTLM to switch to a public and documented authentication +method instead, such as Digest. + +If you want to enable NTLM for your proxy authentication, then use +--proxy-ntlm. diff --git a/third-party/curl/docs/cmdline-opts/oauth2-bearer.d b/third-party/curl/docs/cmdline-opts/oauth2-bearer.d deleted file mode 100644 index 6f35147840..0000000000 --- a/third-party/curl/docs/cmdline-opts/oauth2-bearer.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: oauth2-bearer -Help: OAuth 2 Bearer Token -Arg: -Protocols: IMAP LDAP POP3 SMTP HTTP -Category: auth -Example: --oauth2-bearer "mF_9.B5f-4.1JqM" $URL -Added: 7.33.0 -See-also: basic ntlm digest -Multi: single ---- -Specify the Bearer Token for OAUTH 2.0 server authentication. The Bearer Token -is used in conjunction with the user name which can be specified as part of -the --url or --user options. - -The Bearer Token and user name are formatted according to RFC 6750. diff --git a/third-party/curl/docs/cmdline-opts/oauth2-bearer.md b/third-party/curl/docs/cmdline-opts/oauth2-bearer.md new file mode 100644 index 0000000000..b66477fc70 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/oauth2-bearer.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: oauth2-bearer +Help: OAuth 2 Bearer Token +Arg: +Protocols: IMAP LDAP POP3 SMTP HTTP +Category: auth imap pop3 smtp ldap +Added: 7.33.0 +Multi: single +See-also: + - basic + - ntlm + - digest +Example: + - --oauth2-bearer "mF_9.B5f-4.1JqM" $URL +--- + +# `--oauth2-bearer` + +Specify the Bearer Token for OAUTH 2.0 server authentication. The Bearer Token +is used in conjunction with the username which can be specified as part of the +--url or --user options. + +The Bearer Token and username are formatted according to RFC 6750. diff --git a/third-party/curl/docs/cmdline-opts/out-null.md b/third-party/curl/docs/cmdline-opts/out-null.md new file mode 100644 index 0000000000..cca193e3af --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/out-null.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: out-null +Help: Discard response data into the void +Category: output +Added: 8.16.0 +Multi: per-URL +See-also: + - output + - remote-name + - remote-name-all + - remote-header-name +Example: + - "https://example.com" --out-null +--- + +# `--out-null` + +Discard all response output of a transfer silently. This is the more +efficient and portable version of + + curl https://host.example -o /dev/null + +The transfer is done in full, all data is received and checked, but +the bytes are not written anywhere. diff --git a/third-party/curl/docs/cmdline-opts/output-dir.d b/third-party/curl/docs/cmdline-opts/output-dir.d deleted file mode 100644 index 803b2948bb..0000000000 --- a/third-party/curl/docs/cmdline-opts/output-dir.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: output-dir -Arg: -Help: Directory to save files in -Added: 7.73.0 -See-also: remote-name remote-header-name -Category: curl -Example: --output-dir "tmp" -O $URL -Multi: single ---- -This option specifies the directory in which files should be stored, when ---remote-name or --output are used. - -The given output directory is used for all URLs and output options on the -command line, up until the first --next. - -If the specified target directory does not exist, the operation fails unless ---create-dirs is also used. diff --git a/third-party/curl/docs/cmdline-opts/output-dir.md b/third-party/curl/docs/cmdline-opts/output-dir.md new file mode 100644 index 0000000000..468ecc8a11 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/output-dir.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: output-dir +Arg: +Help: Directory to save files in +Added: 7.73.0 +Category: output +Multi: single +See-also: + - remote-name + - remote-header-name +Example: + - --output-dir "tmp" -O $URL +--- + +# `--output-dir` + +Specify the directory in which files should be stored, when --remote-name or +--output are used. + +The given output directory is used for all URLs and output options on the +command line, up until the first --next. + +If the specified target directory does not exist, the operation fails unless +--create-dirs is also used. diff --git a/third-party/curl/docs/cmdline-opts/output.d b/third-party/curl/docs/cmdline-opts/output.d deleted file mode 100644 index 067151091d..0000000000 --- a/third-party/curl/docs/cmdline-opts/output.d +++ /dev/null @@ -1,49 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: output -Arg: -Short: o -Help: Write to file instead of stdout -See-also: remote-name remote-name-all remote-header-name -Category: important curl -Example: -o file $URL -Example: "http://{one,two}.example.com" -o "file_#1.txt" -Example: "http://{site,host}.host[1-5].com" -o "#1_#2" -Example: -o file $URL -o file2 https://example.net -Added: 4.0 -Multi: append ---- -Write output to instead of stdout. If you are using {} or [] to fetch -multiple documents, you should quote the URL and you can use '#' followed by a -number in the specifier. That variable is replaced with the current -string for the URL being fetched. Like in: - - curl "http://{one,two}.example.com" -o "file_#1.txt" - -or use several variables like: - - curl "http://{site,host}.host[1-5].com" -o "#1_#2" - -You may use this option as many times as the number of URLs you have. For -example, if you specify two URLs on the same command line, you can use it like -this: - - curl -o aa example.com -o bb example.net - -and the order of the -o options and the URLs does not matter, just that the -first -o is for the first URL and so on, so the above command line can also be -written as - - curl example.com example.net -o aa -o bb - -See also the --create-dirs option to create the local directories -dynamically. Specifying the output as '-' (a single dash) passes the output to -stdout. - -To suppress response bodies, you can redirect output to /dev/null: - - curl example.com -o /dev/null - -Or for Windows: - - curl example.com -o nul diff --git a/third-party/curl/docs/cmdline-opts/output.md b/third-party/curl/docs/cmdline-opts/output.md new file mode 100644 index 0000000000..b2d196d038 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/output.md @@ -0,0 +1,90 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: output +Arg: +Short: o +Help: Write to file instead of stdout +Category: important output +Added: 4.0 +Multi: per-URL +See-also: + - out-null + - remote-name + - remote-name-all + - remote-header-name + - compressed +Example: + - -o file $URL + - "http://{one,two}.example.com" -o "file_#1.txt" + - "http://{site,host}.host[1-5].example" -o "#1_#2" + - -o file $URL -o file2 https://example.net +--- + +# `--output` + +Write output to the given file instead of stdout. If you are using globbing in +the URL to fetch multiple documents, you should quote the URL and you can use +`#` followed by a number in the filename. That variable gets replaced with the +current glob text. Like in: + + curl "http://{one,two}.example.com" -o "file_#1.txt" + +or use several variables like: + + curl "http://{site,host}.host[1-5].example" -o "#1_#2" + +You may use this option as many times as the number of URLs you have. For +example, if you specify two URLs on the same command line, you can use it like +this: + + curl -o aa example.com -o bb example.net + +and the order of the -o options and the URLs does not matter, only that the +first -o is for the first URL and so on, so the above command line can also be +written as + + curl example.com example.net -o aa -o bb + +See also the --create-dirs option to create the local directories +dynamically. Specifying the output as '-' (a single dash) passes the output to +stdout. + +To suppress response bodies, you can redirect output to /dev/null: + + curl example.com -o /dev/null + +Or for Windows: + + curl example.com -o nul + +Or, even more efficient and portable, use + + curl example.com --out-null + +Specify the filename as single minus to force the output to stdout, to +override curl's internal binary output in terminal prevention: + + curl https://example.com/jpeg -o - + +Note that the binary output may be caused by the response being compressed, in +which case you may want to use the --compressed option. + +Since curl 8.21.0, the separate globbing parts can be named and referenced by +their names. The case sensitive alphanumeric name is set enclosed within angle +brackets after the opening character. Examples: + + curl "https://fun.example/{one,two}.jpg" -o "save-#" + + curl "ftp://ftp.example/file[1-100].txt" \ + -o "save-#.txt" + +Referencing a named glob that is not set, causes an error. + +Since curl 8.21.0, you can use parts of the upload filename when it uses +globbing by setting a glob name and referencing it the same way you reference +named URL globs. For example, if you upload three files to a single fixed HTTP +URL and want to save the corresponding responses in separate files: + + curl -T 'file{1,2,3}' \ + https://upload.example/ -o 'response-#' diff --git a/third-party/curl/docs/cmdline-opts/page-footer b/third-party/curl/docs/cmdline-opts/page-footer deleted file mode 100644 index beae49ac12..0000000000 --- a/third-party/curl/docs/cmdline-opts/page-footer +++ /dev/null @@ -1,322 +0,0 @@ -.SH FILES -.I ~/.curlrc -.RS -Default config file, see --config for details. -.SH ENVIRONMENT -The environment variables can be specified in lower case or upper case. The -lower case version has precedence. http_proxy is an exception as it is only -available in lower case. - -Using an environment variable to set the proxy has the same effect as using -the --proxy option. - -.IP "http_proxy [protocol://][:port]" -Sets the proxy server to use for HTTP. -.IP "HTTPS_PROXY [protocol://][:port]" -Sets the proxy server to use for HTTPS. -.IP "[url-protocol]_PROXY [protocol://][:port]" -Sets the proxy server to use for [url-protocol], where the protocol is a -protocol that curl supports and as specified in a URL. FTP, FTPS, POP3, IMAP, -SMTP, LDAP, etc. -.IP "ALL_PROXY [protocol://][:port]" -Sets the proxy server to use if no protocol-specific proxy is set. -.IP "NO_PROXY " -list of host names that should not go through any proxy. If set to an asterisk -'*' only, it matches all hosts. Each name in this list is matched as either -a domain name which contains the hostname, or the hostname itself. - -This environment variable disables use of the proxy even when specified with -the --proxy option. That is -.B NO_PROXY=direct.example.com curl -x http://proxy.example.com -.B http://direct.example.com -accesses the target URL directly, and -.B NO_PROXY=direct.example.com curl -x http://proxy.example.com -.B http://somewhere.example.com -accesses the target URL through the proxy. - -The list of host names can also be include numerical IP addresses, and IPv6 -versions should then be given without enclosing brackets. - -IP addresses can be specified using CIDR notation: an appended slash and -number specifies the number of "network bits" out of the address to use in the -comparison (added in 7.86.0). For example "192.168.0.0/16" would match all -addresses starting with "192.168". -.IP "APPDATA " -On Windows, this variable is used when trying to find the home directory. If -the primary home variable are all unset. -.IP "COLUMNS " -If set, the specified number of characters is used as the terminal width when -the alternative progress-bar is shown. If not set, curl tries to figure it out -using other ways. -.IP "CURL_CA_BUNDLE " -If set, it is used as the --cacert value. -.IP "CURL_HOME " -If set, is the first variable curl checks when trying to find its home -directory. If not set, it continues to check *XDG_CONFIG_HOME* -.IP "CURL_SSL_BACKEND " -If curl was built with support for "MultiSSL", meaning that it has built-in -support for more than one TLS backend, this environment variable can be set to -the case insensitive name of the particular backend to use when curl is -invoked. Setting a name that is not a built-in alternative makes curl stay -with the default. - -SSL backend names (case-insensitive): **bearssl**, **gnutls**, **mbedtls**, -**openssl**, **rustls**, **schannel**, **secure-transport**, **wolfssl** -.IP "HOME " -If set, this is used to find the home directory when that is needed. Like when -looking for the default .curlrc. *CURL_HOME* and *XDG_CONFIG_HOME* -have preference. -.IP "QLOGDIR " -If curl was built with HTTP/3 support, setting this environment variable to a -local directory makes curl produce **qlogs** in that directory, using file -names named after the destination connection id (in hex). Do note that these -files can become rather large. Works with the ngtcp2 and quiche QUIC backends. -.IP SHELL -Used on VMS when trying to detect if using a **DCL** or a **unix** shell. -.IP "SSL_CERT_DIR " -If set, it is used as the --capath value. -.IP "SSL_CERT_FILE " -If set, it is used as the --cacert value. -.IP "SSLKEYLOGFILE " -If you set this environment variable to a file name, curl stores TLS secrets -from its connections in that file when invoked to enable you to analyze the -TLS traffic in real time using network analyzing tools such as Wireshark. This -works with the following TLS backends: OpenSSL, libressl, BoringSSL, GnuTLS -and wolfSSL. -.IP "USERPROFILE " -On Windows, this variable is used when trying to find the home directory. If -the other, primary, variable are all unset. If set, curl uses the path -**"$USERPROFILE\\Application Data"**. -.IP "XDG_CONFIG_HOME " -If *CURL_HOME* is not set, this variable is checked when looking for a -default .curlrc file. -.SH "PROXY PROTOCOL PREFIXES" -The proxy string may be specified with a protocol:// prefix to specify -alternative proxy protocols. (Added in 7.21.7) - -If no protocol is specified in the proxy string or if the string does not -match a supported one, the proxy is treated as an HTTP proxy. - -The supported proxy protocol prefixes are as follows: -.IP "http://" -Makes it use it as an HTTP proxy. The default if no scheme prefix is used. -.IP "https://" -Makes it treated as an **HTTPS** proxy. -.IP "socks4://" -Makes it the equivalent of --socks4 -.IP "socks4a://" -Makes it the equivalent of --socks4a -.IP "socks5://" -Makes it the equivalent of --socks5 -.IP "socks5h://" -Makes it the equivalent of --socks5-hostname -.SH EXIT CODES -There are a bunch of different error codes and their corresponding error -messages that may appear under error conditions. At the time of this writing, -the exit codes are: -.IP 0 -Success. The operation completed successfully according to the instructions. -.IP 1 -Unsupported protocol. This build of curl has no support for this protocol. -.IP 2 -Failed to initialize. -.IP 3 -URL malformed. The syntax was not correct. -.IP 4 -A feature or option that was needed to perform the desired request was not -enabled or was explicitly disabled at build-time. To make curl able to do -this, you probably need another build of libcurl. -.IP 5 -Could not resolve proxy. The given proxy host could not be resolved. -.IP 6 -Could not resolve host. The given remote host could not be resolved. -.IP 7 -Failed to connect to host. -.IP 8 -Weird server reply. The server sent data curl could not parse. -.IP 9 -FTP access denied. The server denied login or denied access to the particular -resource or directory you wanted to reach. Most often you tried to change to a -directory that does not exist on the server. -.IP 10 -FTP accept failed. While waiting for the server to connect back when an active -FTP session is used, an error code was sent over the control connection or -similar. -.IP 11 -FTP weird PASS reply. Curl could not parse the reply sent to the PASS request. -.IP 12 -During an active FTP session while waiting for the server to connect back to -curl, the timeout expired. -.IP 13 -FTP weird PASV reply, Curl could not parse the reply sent to the PASV request. -.IP 14 -FTP weird 227 format. Curl could not parse the 227-line the server sent. -.IP 15 -FTP cannot use host. Could not resolve the host IP we got in the 227-line. -.IP 16 -HTTP/2 error. A problem was detected in the HTTP2 framing layer. This is -somewhat generic and can be one out of several problems, see the error message -for details. -.IP 17 -FTP could not set binary. Could not change transfer method to binary. -.IP 18 -Partial file. Only a part of the file was transferred. -.IP 19 -FTP could not download/access the given file, the RETR (or similar) command -failed. -.IP 21 -FTP quote error. A quote command returned error from the server. -.IP 22 -HTTP page not retrieved. The requested URL was not found or returned another -error with the HTTP error code being 400 or above. This return code only -appears if --fail is used. -.IP 23 -Write error. Curl could not write data to a local filesystem or similar. -.IP 25 -FTP could not STOR file. The server denied the STOR operation, used for FTP -uploading. -.IP 26 -Read error. Various reading problems. -.IP 27 -Out of memory. A memory allocation request failed. -.IP 28 -Operation timeout. The specified time-out period was reached according to the -conditions. -.IP 30 -FTP PORT failed. The PORT command failed. Not all FTP servers support the PORT -command, try doing a transfer using PASV instead! -.IP 31 -FTP could not use REST. The REST command failed. This command is used for -resumed FTP transfers. -.IP 33 -HTTP range error. The range "command" did not work. -.IP 34 -HTTP post error. Internal post-request generation error. -.IP 35 -SSL connect error. The SSL handshaking failed. -.IP 36 -Bad download resume. Could not continue an earlier aborted download. -.IP 37 -FILE could not read file. Failed to open the file. Permissions? -.IP 38 -LDAP cannot bind. LDAP bind operation failed. -.IP 39 -LDAP search failed. -.IP 41 -Function not found. A required LDAP function was not found. -.IP 42 -Aborted by callback. An application told curl to abort the operation. -.IP 43 -Internal error. A function was called with a bad parameter. -.IP 45 -Interface error. A specified outgoing interface could not be used. -.IP 47 -Too many redirects. When following redirects, curl hit the maximum amount. -.IP 48 -Unknown option specified to libcurl. This indicates that you passed a weird -option to curl that was passed on to libcurl and rejected. Read up in the -manual! -.IP 49 -Malformed telnet option. -.IP 52 -The server did not reply anything, which here is considered an error. -.IP 53 -SSL crypto engine not found. -.IP 54 -Cannot set SSL crypto engine as default. -.IP 55 -Failed sending network data. -.IP 56 -Failure in receiving network data. -.IP 58 -Problem with the local certificate. -.IP 59 -Could not use specified SSL cipher. -.IP 60 -Peer certificate cannot be authenticated with known CA certificates. -.IP 61 -Unrecognized transfer encoding. -.IP 63 -Maximum file size exceeded. -.IP 64 -Requested FTP SSL level failed. -.IP 65 -Sending the data requires a rewind that failed. -.IP 66 -Failed to initialize SSL Engine. -.IP 67 -The user name, password, or similar was not accepted and curl failed to log in. -.IP 68 -File not found on TFTP server. -.IP 69 -Permission problem on TFTP server. -.IP 70 -Out of disk space on TFTP server. -.IP 71 -Illegal TFTP operation. -.IP 72 -Unknown TFTP transfer ID. -.IP 73 -File already exists (TFTP). -.IP 74 -No such user (TFTP). -.IP 77 -Problem reading the SSL CA cert (path? access rights?). -.IP 78 -The resource referenced in the URL does not exist. -.IP 79 -An unspecified error occurred during the SSH session. -.IP 80 -Failed to shut down the SSL connection. -.IP 82 -Could not load CRL file, missing or wrong format (added in 7.19.0). -.IP 83 -Issuer check failed (added in 7.19.0). -.IP 84 -The FTP PRET command failed. -.IP 85 -Mismatch of RTSP CSeq numbers. -.IP 86 -Mismatch of RTSP Session Identifiers. -.IP 87 -Unable to parse FTP file list. -.IP 88 -FTP chunk callback reported error. -.IP 89 -No connection available, the session is queued. -.IP 90 -SSL public key does not matched pinned public key. -.IP 91 -Invalid SSL certificate status. -.IP 92 -Stream error in HTTP/2 framing layer. -.IP 93 -An API function was called from inside a callback. -.IP 94 -An authentication function returned an error. -.IP 95 -A problem was detected in the HTTP/3 layer. This is somewhat generic and can -be one out of several problems, see the error message for details. -.IP 96 -QUIC connection error. This error may be caused by an SSL library error. QUIC -is the protocol used for HTTP/3 transfers. -.IP 97 -Proxy handshake error. -.IP 98 -A client-side certificate is required to complete the TLS handshake. -.IP 99 -Poll or select returned fatal error. -.IP XX -More error codes might appear here in future releases. The existing ones are -meant to never change. -.SH BUGS -If you experience any problems with curl, submit an issue in the project's bug -tracker on GitHub: https://github.com/curl/curl/issues -.SH AUTHORS / CONTRIBUTORS -Daniel Stenberg is the main author, but the whole list of contributors is -found in the separate THANKS file. -.SH WWW -https://curl.se -.SH "SEE ALSO" -.BR ftp (1), -.BR wget (1) diff --git a/third-party/curl/docs/cmdline-opts/page-header b/third-party/curl/docs/cmdline-opts/page-header deleted file mode 100644 index 7d14f4c452..0000000000 --- a/third-party/curl/docs/cmdline-opts/page-header +++ /dev/null @@ -1,258 +0,0 @@ -.\" ************************************************************************** -.\" * _ _ ____ _ -.\" * Project ___| | | | _ \| | -.\" * / __| | | | |_) | | -.\" * | (__| |_| | _ <| |___ -.\" * \___|\___/|_| \_\_____| -.\" * -.\" * Copyright (C) Daniel Stenberg, , et al. -.\" * -.\" * This software is licensed as described in the file COPYING, which -.\" * you should have received as part of this distribution. The terms -.\" * are also available at https://curl.se/docs/copyright.html. -.\" * -.\" * You may opt to use, copy, modify, merge, publish, distribute and/or sell -.\" * copies of the Software, and permit persons to whom the Software is -.\" * furnished to do so, under the terms of the COPYING file. -.\" * -.\" * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY -.\" * KIND, either express or implied. -.\" * -.\" * SPDX-License-Identifier: curl -.\" * -.\" ************************************************************************** -.\" -.\" DO NOT EDIT. Generated by the curl project gen.pl man page generator. -.\" -.TH curl 1 "%DATE" "curl %VERSION" "curl Manual" -.SH NAME -curl \- transfer a URL -.SH SYNOPSIS -.B curl [options / URLs] -.SH DESCRIPTION -**curl** is a tool for transferring data from or to a server using URLs. It -supports these protocols: DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, -IMAP, IMAPS, LDAP, LDAPS, MQTT, POP3, POP3S, RTMP, RTMPS, RTSP, SCP, SFTP, -SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. - -curl is powered by libcurl for all transfer-related features. See -*libcurl(3)* for details. -.SH URL -The URL syntax is protocol-dependent. You find a detailed description in -RFC 3986. - -If you provide a URL without a leading **protocol://** scheme, curl guesses -what protocol you want. It then defaults to HTTP but assumes others based on -often-used host name prefixes. For example, for host names starting with -"ftp." curl assumes you want FTP. - -You can specify any amount of URLs on the command line. They are fetched in a -sequential manner in the specified order unless you use --parallel. You can -specify command line options and URLs mixed and in any order on the command -line. - -curl attempts to reuse connections when doing multiple transfers, so that -getting many files from the same server do not use multiple connects and setup -handshakes. This improves speed. Connection reuse can only be done for URLs -specified for a single command line invocation and cannot be performed between -separate curl runs. - -Provide an IPv6 zone id in the URL with an escaped percentage sign. Like in - - "http://[fe80::3%25eth0]/" - -Everything provided on the command line that is not a command line option or -its argument, curl assumes is a URL and treats it as such. -.SH GLOBBING -You can specify multiple URLs or parts of URLs by writing lists within braces -or ranges within brackets. We call this "globbing". - -Provide a list with three different names like this: - - "http://site.{one,two,three}.com" - -or you can get sequences of alphanumeric series by using [] as in: - - "ftp://ftp.example.com/file[1-100].txt" - - "ftp://ftp.example.com/file[001-100].txt" (with leading zeros) - - "ftp://ftp.example.com/file[a-z].txt" - -Nested sequences are not supported, but you can use several ones next to each -other: - - "http://example.com/archive[1996-1999]/vol[1-4]/part{a,b,c}.html" - -You can specify a step counter for the ranges to get every Nth number or -letter: - - "http://example.com/file[1-100:10].txt" - - "http://example.com/file[a-z:2].txt" - -When using [] or {} sequences when invoked from a command line prompt, you -probably have to put the full URL within double quotes to avoid the shell from -interfering with it. This also goes for other characters treated special, like -for example '&', '?' and '*'. - -Switch off globbing with --globoff. -.SH VARIABLES -curl supports command line variables (added in 8.3.0). Set variables with ---variable name=content or --variable name@file (where "file" can be stdin if -set to a single dash (-)). - -Variable contents can expanded in option parameters using "{{name}}" (without -the quotes) if the option name is prefixed with "--expand-". This gets the -contents of the variable "name" inserted, or a blank if the name does not -exist as a variable. Insert "{{" verbatim in the string by prefixing it with a -backslash, like "\\{{". - -You an access and expand environment variables by first importing them. You -can select to either require the environment variable to be set or you can -provide a default value in case it is not already set. Plain --variable %name -imports the variable called 'name' but exits with an error if that environment -variable is not already set. To provide a default value if it is not set, use ---variable %name=content or --variable %name@content. - -Example. Get the USER environment variable into the URL, fail if USER is not -set: - - --variable '%USER' - --expand-url = "https://example.com/api/{{USER}}/method" - -When expanding variables, curl supports a set of functions that can make the -variable contents more convenient to use. It can trim leading and trailing -white space with *trim*, it can output the contents as a JSON quoted string -with *json*, URL encode the string with *url* or base64 encode it with -*b64*. You apply function to a variable expansion, add them colon separated to -the right side of the variable. Variable content holding null bytes that are -not encoded when expanded cause error. - -Example: get the contents of a file called $HOME/.secret into a variable -called "fix". Make sure that the content is trimmed and percent-encoded sent -as POST data: - - --variable %HOME - --expand-variable fix@{{HOME}}/.secret - --expand-data "{{fix:trim:url}}" - https://example.com/ - -Command line variables and expansions were added in in 8.3.0. -.SH OUTPUT -If not told otherwise, curl writes the received data to stdout. It can be -instructed to instead save that data into a local file, using the --output or ---remote-name options. If curl is given multiple URLs to transfer on the -command line, it similarly needs multiple options for where to save them. - -curl does not parse or otherwise "understand" the content it gets or writes as -output. It does no encoding or decoding, unless explicitly asked to with -dedicated command line options. -.SH PROTOCOLS -curl supports numerous protocols, or put in URL terms: schemes. Your -particular build may not support them all. -.IP DICT -Lets you lookup words using online dictionaries. -.IP FILE -Read or write local files. curl does not support accessing file:// URL -remotely, but when running on Microsoft Windows using the native UNC approach -works. -.IP FTP(S) -curl supports the File Transfer Protocol with a lot of tweaks and levers. With -or without using TLS. -.IP GOPHER(S) -Retrieve files. -.IP HTTP(S) -curl supports HTTP with numerous options and variations. It can speak HTTP -version 0.9, 1.0, 1.1, 2 and 3 depending on build options and the correct -command line options. -.IP IMAP(S) -Using the mail reading protocol, curl can "download" emails for you. With or -without using TLS. -.IP LDAP(S) -curl can do directory lookups for you, with or without TLS. -.IP MQTT -curl supports MQTT version 3. Downloading over MQTT equals "subscribe" to a -topic while uploading/posting equals "publish" on a topic. MQTT over TLS is -not supported (yet). -.IP POP3(S) -Downloading from a pop3 server means getting a mail. With or without using -TLS. -.IP RTMP(S) -The **Realtime Messaging Protocol** is primarily used to serve streaming media -and curl can download it. -.IP RTSP -curl supports RTSP 1.0 downloads. -.IP SCP -curl supports SSH version 2 scp transfers. -.IP SFTP -curl supports SFTP (draft 5) done over SSH version 2. -.IP SMB(S) -curl supports SMB version 1 for upload and download. -.IP SMTP(S) -Uploading contents to an SMTP server means sending an email. With or without -TLS. -.IP TELNET -Telling curl to fetch a telnet URL starts an interactive session where it -sends what it reads on stdin and outputs what the server sends it. -.IP TFTP -curl can do TFTP downloads and uploads. -.SH "PROGRESS METER" -curl normally displays a progress meter during operations, indicating the -amount of transferred data, transfer speeds and estimated time left, etc. The -progress meter displays the transfer rate in bytes per second. The suffixes -(k, M, G, T, P) are 1024 based. For example 1k is 1024 bytes. 1M is 1048576 -bytes. - -curl displays this data to the terminal by default, so if you invoke curl to -do an operation and it is about to write data to the terminal, it -*disables* the progress meter as otherwise it would mess up the output -mixing progress meter and response data. - -If you want a progress meter for HTTP POST or PUT requests, you need to -redirect the response output to a file, using shell redirect (>), --output or -similar. - -This does not apply to FTP upload as that operation does not spit out any -response data to the terminal. - -If you prefer a progress "bar" instead of the regular meter, --progress-bar is -your friend. You can also disable the progress meter completely with the ---silent option. -.SH VERSION -This man page describes curl %VERSION. If you use a later version, chances are -this man page does not fully document it. If you use an earlier version, this -document tries to include version information about which specific version -that introduced changes. - -You can always learn which the latest curl version is by running - - curl https://curl.se/info - -The online version of this man page is always showing the latest incarnation: -https://curl.se/docs/manpage.html -.SH OPTIONS -Options start with one or two dashes. Many of the options require an -additional value next to them. If provided text does not start with a dash, it -is presumed to be and treated as a URL. - -The short "single-dash" form of the options, -d for example, may be used with -or without a space between it and its value, although a space is a recommended -separator. The long "double-dash" form, --data for example, requires a space -between it and its value. - -Short version options that do not need any additional values can be used -immediately next to each other, like for example you can specify all the -options *-O*, *-L* and *-v* at once as *-OLv*. - -In general, all boolean options are enabled with --**option** and yet again -disabled with --**no-**option. That is, you use the same option name but -prefix it with "no-". However, in this list we mostly only list and show the -*--option* version of them. - -When --next is used, it resets the parser state and you start again with a -clean option state, except for the options that are "global". Global options -retain their values and meaning even after --next. - -The following options are global: -%GLOBALS. diff --git a/third-party/curl/docs/cmdline-opts/parallel-immediate.d b/third-party/curl/docs/cmdline-opts/parallel-immediate.d deleted file mode 100644 index b534dd5122..0000000000 --- a/third-party/curl/docs/cmdline-opts/parallel-immediate.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: parallel-immediate -Help: Do not wait for multiplexing (with --parallel) -Added: 7.68.0 -See-also: parallel parallel-max -Category: connection curl -Example: --parallel-immediate -Z $URL -o file1 $URL -o file2 -Multi: boolean -Scope: global ---- -When doing parallel transfers, this option instructs curl that it should -rather prefer opening up more connections in parallel at once rather than -waiting to see if new transfers can be added as multiplexed streams on another -connection. diff --git a/third-party/curl/docs/cmdline-opts/parallel-immediate.md b/third-party/curl/docs/cmdline-opts/parallel-immediate.md new file mode 100644 index 0000000000..4d7a3ad516 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/parallel-immediate.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: parallel-immediate +Help: Do not wait for multiplexing +Added: 7.68.0 +Category: connection curl global +Multi: boolean +Scope: global +See-also: + - parallel + - parallel-max +Example: + - --parallel-immediate -Z $URL -o file1 $URL -o file2 +--- + +# `--parallel-immediate` + +When doing parallel transfers, this option instructs curl to prefer opening up +more connections in parallel at once rather than waiting to see if new +transfers can be added as multiplexed streams on another connection. + +By default, without this option set, curl prefers to wait a little and +multiplex new transfers over existing connections. It keeps the number of +connections low at the expense of risking a slightly slower transfer startup. diff --git a/third-party/curl/docs/cmdline-opts/parallel-max-host.md b/third-party/curl/docs/cmdline-opts/parallel-max-host.md new file mode 100644 index 0000000000..a21c9acddd --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/parallel-max-host.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: parallel-max-host +Arg: +Help: Maximum connections to a single host +Added: 8.16.0 +Category: connection curl global +Multi: single +Scope: global +See-also: + - parallel + - parallel-max +Example: + - --parallel-max-host 5 -Z $URL ftp://example.com/ +--- + +# `--parallel-max-host` + +When asked to do parallel transfers, using --parallel, this option controls +the maximum amount of concurrent connections curl is allowed to do to the same +protocol + hostname + port number target. + +The limit is enforced by libcurl and queued "internally", which means that +transfers that are waiting for an available connection still look like started +transfers in the progress meter. + +The default is 0 (unlimited). 65535 is the largest supported value. diff --git a/third-party/curl/docs/cmdline-opts/parallel-max.d b/third-party/curl/docs/cmdline-opts/parallel-max.d deleted file mode 100644 index cc6d32d182..0000000000 --- a/third-party/curl/docs/cmdline-opts/parallel-max.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: parallel-max -Arg: -Help: Maximum concurrency for parallel transfers -Added: 7.66.0 -See-also: parallel -Category: connection curl -Example: --parallel-max 100 -Z $URL ftp://example.com/ -Multi: single ---- -When asked to do parallel transfers, using --parallel, this option controls -the maximum amount of transfers to do simultaneously. - -This option is global and does not need to be specified for each use of ---next. - -The default is 50. diff --git a/third-party/curl/docs/cmdline-opts/parallel-max.md b/third-party/curl/docs/cmdline-opts/parallel-max.md new file mode 100644 index 0000000000..a487f4cc9e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/parallel-max.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: parallel-max +Arg: +Help: Maximum concurrency for parallel transfers +Added: 7.66.0 +Category: connection curl global +Multi: single +Scope: global +See-also: + - parallel + - parallel-max-host +Example: + - --parallel-max 100 -Z $URL ftp://example.com/ +--- + +# `--parallel-max` + +When asked to do parallel transfers, using --parallel, this option controls +the maximum amount of transfers to do simultaneously. + +The default is 50. 65535 is the largest supported value. diff --git a/third-party/curl/docs/cmdline-opts/parallel.d b/third-party/curl/docs/cmdline-opts/parallel.d deleted file mode 100644 index 4f698f8b3a..0000000000 --- a/third-party/curl/docs/cmdline-opts/parallel.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: Z -Long: parallel -Help: Perform transfers in parallel -Added: 7.66.0 -Category: connection curl -Example: --parallel $URL -o file1 $URL -o file2 -See-also: next verbose -Multi: boolean -Scope: global ---- -Makes curl perform its transfers in parallel as compared to the regular serial -manner. diff --git a/third-party/curl/docs/cmdline-opts/parallel.md b/third-party/curl/docs/cmdline-opts/parallel.md new file mode 100644 index 0000000000..907ab8cb85 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/parallel.md @@ -0,0 +1,32 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: Z +Long: parallel +Help: Perform transfers in parallel +Added: 7.66.0 +Category: connection curl global +Multi: boolean +Scope: global +See-also: + - next + - verbose + - parallel-max + - parallel-immediate +Example: + - --parallel $URL -o file1 $URL -o file2 +--- + +# `--parallel` + +Make curl perform all transfers in parallel as compared to the regular serial +manner. Parallel transfer means that curl runs up to N concurrent transfers +simultaneously and if there are more than N transfers to handle, it starts new +ones when earlier transfers finish. + +With parallel transfers, the progress meter output is different from when +doing serial transfers, as it then displays the transfer status for multiple +transfers in a single line. + +The maximum amount of concurrent transfers is set with --parallel-max and it +defaults to 50. diff --git a/third-party/curl/docs/cmdline-opts/pass.d b/third-party/curl/docs/cmdline-opts/pass.d deleted file mode 100644 index 2c0a2bef62..0000000000 --- a/third-party/curl/docs/cmdline-opts/pass.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: pass -Arg: -Help: Pass phrase for the private key -Protocols: SSH TLS -Category: ssh tls auth -Example: --pass secret --key file $URL -Added: 7.9.3 -See-also: key user -Multi: single ---- -Passphrase for the private key. diff --git a/third-party/curl/docs/cmdline-opts/pass.md b/third-party/curl/docs/cmdline-opts/pass.md new file mode 100644 index 0000000000..79c2f8738a --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/pass.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: pass +Arg: +Help: Passphrase for the private key +Protocols: TLS SCP SFTP +Category: ssh tls auth +Added: 7.9.3 +Multi: single +See-also: + - key + - user +Example: + - --pass secret --key file $URL +--- + +# `--pass` + +Passphrase for the private key used for SSH or TLS. diff --git a/third-party/curl/docs/cmdline-opts/path-as-is.d b/third-party/curl/docs/cmdline-opts/path-as-is.d deleted file mode 100644 index 9897d882f6..0000000000 --- a/third-party/curl/docs/cmdline-opts/path-as-is.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: path-as-is -Help: Do not squash .. sequences in URL path -Added: 7.42.0 -Category: curl -Example: --path-as-is https://example.com/../../etc/passwd -See-also: request-target -Multi: boolean ---- -Tell curl to not handle sequences of /../ or /./ in the given URL -path. Normally curl squashes or merges them according to standards but with -this option set you tell it not to do that. diff --git a/third-party/curl/docs/cmdline-opts/path-as-is.md b/third-party/curl/docs/cmdline-opts/path-as-is.md new file mode 100644 index 0000000000..f3a60cff24 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/path-as-is.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: path-as-is +Help: Do not squash .. sequences in URL path +Added: 7.42.0 +Category: curl +Multi: boolean +See-also: + - request-target +Example: + - --path-as-is https://example.com/../../etc/passwd +--- + +# `--path-as-is` + +Do not handle sequences of /../ or /./ in the given URL path. Normally curl +squashes or merges them according to standards but with this option set you +tell it not to do that. diff --git a/third-party/curl/docs/cmdline-opts/pinnedpubkey.d b/third-party/curl/docs/cmdline-opts/pinnedpubkey.d deleted file mode 100644 index 48b96dfc5a..0000000000 --- a/third-party/curl/docs/cmdline-opts/pinnedpubkey.d +++ /dev/null @@ -1,32 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: pinnedpubkey -Arg: -Help: FILE/HASHES Public key to verify peer against -Protocols: TLS -Category: tls -Example: --pinnedpubkey keyfile $URL -Example: --pinnedpubkey 'sha256//ce118b51897f4452dc' $URL -Added: 7.39.0 -See-also: hostpubsha256 -Multi: single ---- -Tells curl to use the specified public key file (or hashes) to verify the -peer. This can be a path to a file which contains a single public key in PEM -or DER format, or any number of base64 encoded sha256 hashes preceded by -'sha256//' and separated by ';'. - -When negotiating a TLS or SSL connection, the server sends a certificate -indicating its identity. A public key is extracted from this certificate and -if it does not exactly match the public key provided to this option, curl -aborts the connection before sending or receiving any data. - -PEM/DER support: - -OpenSSL and GnuTLS (added in 7.39.0), wolfSSL (added in 7.43.0), mbedTLS (added in 7.47.0) - -sha256 support: - -OpenSSL, GnuTLS and wolfSSL (added in 7.44.0), mbedTLS (added in 7.47.0) - -Other SSL backends not supported. diff --git a/third-party/curl/docs/cmdline-opts/pinnedpubkey.md b/third-party/curl/docs/cmdline-opts/pinnedpubkey.md new file mode 100644 index 0000000000..ff7c42b39d --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/pinnedpubkey.md @@ -0,0 +1,43 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: pinnedpubkey +Arg: +Help: Public key to verify peer against +Protocols: TLS +Category: tls +Added: 7.39.0 +Multi: single +See-also: + - hostpubsha256 +Example: + - --pinnedpubkey keyfile $URL + - --pinnedpubkey 'sha256//ce118b51897f4452dc' $URL +--- + +# `--pinnedpubkey` + +Use the specified public key file (or hashes) to verify the peer. This can be +a path to a file which contains a single public key in PEM or DER format, or +any number of base64 encoded sha256 hashes preceded by 'sha256//' and +separated by ';'. + +When negotiating a TLS or SSL connection, the server sends a certificate +indicating its identity. A public key is extracted from this certificate and +if it does not exactly match the public key provided to this option, curl +aborts the connection before sending or receiving any data. + +This option is independent of option --insecure. If you use both options +together then the peer is still verified by public key. + +PEM/DER support: + +OpenSSL and GnuTLS (added in 7.39.0), wolfSSL (added in 7.43.0), +mbedTLS (added in 7.47.0), Schannel (added in 7.58.1) + +sha256 support: + +OpenSSL, GnuTLS and wolfSSL (added in 7.44.0), mbedTLS (added in 7.47.0), +Schannel (added in 7.58.1) + +Other SSL backends not supported. diff --git a/third-party/curl/docs/cmdline-opts/post301.d b/third-party/curl/docs/cmdline-opts/post301.d deleted file mode 100644 index d067fc8cc0..0000000000 --- a/third-party/curl/docs/cmdline-opts/post301.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: post301 -Help: Do not switch to GET after following a 301 -Protocols: HTTP -See-also: post302 post303 location -Added: 7.17.1 -Category: http post -Example: --post301 --location -d "data" $URL -Multi: boolean ---- -Tells curl to respect RFC 7231/6.4.2 and not convert POST requests into GET -requests when following a 301 redirection. The non-RFC behavior is ubiquitous -in web browsers, so curl does the conversion by default to maintain -consistency. However, a server may require a POST to remain a POST after such -a redirection. This option is meaningful only when using --location. diff --git a/third-party/curl/docs/cmdline-opts/post301.md b/third-party/curl/docs/cmdline-opts/post301.md new file mode 100644 index 0000000000..3bcded869f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/post301.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: post301 +Help: Do not switch to GET after a 301 redirect +Protocols: HTTP +Added: 7.17.1 +Category: http post +Multi: boolean +See-also: + - post302 + - post303 + - location +Example: + - --post301 --location -d "data" $URL +--- + +# `--post301` + +Respect RFC 7231/6.4.2 and do not convert POST requests into GET requests when +following a 301 redirect. The non-RFC behavior is ubiquitous in web browsers, +so curl does the conversion by default to maintain consistency. A server may +require a POST to remain a POST after such a redirection. This option is +meaningful only when using --location. diff --git a/third-party/curl/docs/cmdline-opts/post302.d b/third-party/curl/docs/cmdline-opts/post302.d deleted file mode 100644 index b7190ce0fb..0000000000 --- a/third-party/curl/docs/cmdline-opts/post302.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: post302 -Help: Do not switch to GET after following a 302 -Protocols: HTTP -See-also: post301 post303 location -Added: 7.19.1 -Category: http post -Example: --post302 --location -d "data" $URL -Multi: boolean ---- -Tells curl to respect RFC 7231/6.4.3 and not convert POST requests into GET -requests when following a 302 redirection. The non-RFC behavior is ubiquitous -in web browsers, so curl does the conversion by default to maintain -consistency. However, a server may require a POST to remain a POST after such -a redirection. This option is meaningful only when using --location. diff --git a/third-party/curl/docs/cmdline-opts/post302.md b/third-party/curl/docs/cmdline-opts/post302.md new file mode 100644 index 0000000000..bcb35fc5df --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/post302.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: post302 +Help: Do not switch to GET after a 302 redirect +Protocols: HTTP +Added: 7.19.1 +Category: http post +Multi: boolean +See-also: + - post301 + - post303 + - location +Example: + - --post302 --location -d "data" $URL +--- + +# `--post302` + +Respect RFC 7231/6.4.3 and do not convert POST requests into GET requests when +following a 302 redirect. The non-RFC behavior is ubiquitous in web browsers, +so curl does the conversion by default to maintain consistency. A server may +require a POST to remain a POST after such a redirection. This option is +meaningful only when using --location. diff --git a/third-party/curl/docs/cmdline-opts/post303.d b/third-party/curl/docs/cmdline-opts/post303.d deleted file mode 100644 index 52d440c453..0000000000 --- a/third-party/curl/docs/cmdline-opts/post303.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: post303 -Help: Do not switch to GET after following a 303 -Protocols: HTTP -See-also: post302 post301 location -Added: 7.26.0 -Category: http post -Example: --post303 --location -d "data" $URL -Multi: boolean ---- -Tells curl to violate RFC 7231/6.4.4 and not convert POST requests into GET -requests when following 303 redirections. A server may require a POST to -remain a POST after a 303 redirection. This option is meaningful only when -using --location. diff --git a/third-party/curl/docs/cmdline-opts/post303.md b/third-party/curl/docs/cmdline-opts/post303.md new file mode 100644 index 0000000000..63dc0d7956 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/post303.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: post303 +Help: Do not switch to GET after a 303 redirect +Protocols: HTTP +Added: 7.26.0 +Category: http post +Multi: boolean +See-also: + - post302 + - post301 + - location +Example: + - --post303 --location -d "data" $URL +--- + +# `--post303` + +Violate RFC 7231/6.4.4 and do not convert POST requests into GET requests when +following 303 redirect. A server may require a POST to remain a POST after a +303 redirection. This option is meaningful only when using --location. diff --git a/third-party/curl/docs/cmdline-opts/preproxy.d b/third-party/curl/docs/cmdline-opts/preproxy.d deleted file mode 100644 index b55c1d47a2..0000000000 --- a/third-party/curl/docs/cmdline-opts/preproxy.d +++ /dev/null @@ -1,26 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: preproxy -Arg: [protocol://]host[:port] -Help: Use this proxy first -Added: 7.52.0 -Category: proxy -Example: --preproxy socks5://proxy.example -x http://http.example $URL -See-also: proxy socks5 -Multi: single ---- -Use the specified SOCKS proxy before connecting to an HTTP or HTTPS --proxy. In -such a case curl first connects to the SOCKS proxy and then connects (through -SOCKS) to the HTTP or HTTPS proxy. Hence pre proxy. - -The pre proxy string should be specified with a protocol:// prefix to specify -alternative proxy protocols. Use socks4://, socks4a://, socks5:// or -socks5h:// to request the specific SOCKS version to be used. No protocol -specified makes curl default to SOCKS4. - -If the port number is not specified in the proxy string, it is assumed to be -1080. - -User and password that might be provided in the proxy string are URL decoded -by curl. This allows you to pass in special characters such as @ by using %40 -or pass in a colon with %3a. diff --git a/third-party/curl/docs/cmdline-opts/preproxy.md b/third-party/curl/docs/cmdline-opts/preproxy.md new file mode 100644 index 0000000000..a108d9f094 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/preproxy.md @@ -0,0 +1,33 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: preproxy +Arg: <[protocol://]host[:port]> +Help: Use this proxy first +Added: 7.52.0 +Category: proxy +Multi: single +See-also: + - proxy + - socks5 +Example: + - --preproxy socks5://proxy.example -x http://http.example $URL +--- + +# `--preproxy` + +Use the specified SOCKS proxy before connecting to an HTTP or HTTPS --proxy. In +such a case curl first connects to the SOCKS proxy and then connects (through +SOCKS) to the HTTP or HTTPS proxy. Hence pre proxy. + +The pre proxy string should be specified with a `protocol://` prefix to specify +alternative proxy protocols. Use `socks4://`, `socks4a://`, `socks5://` or +`socks5h://` to request the specific SOCKS version to be used. No protocol +specified makes curl default to SOCKS4. + +If the port number is not specified in the proxy string, it is assumed to be +1080. + +User and password that might be provided in the proxy string are URL decoded +by curl. This allows you to pass in special characters such as @ by using %40 +or pass in a colon with %3a. diff --git a/third-party/curl/docs/cmdline-opts/progress-bar.d b/third-party/curl/docs/cmdline-opts/progress-bar.d deleted file mode 100644 index fee170979d..0000000000 --- a/third-party/curl/docs/cmdline-opts/progress-bar.d +++ /dev/null @@ -1,20 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: # -Long: progress-bar -Help: Display transfer progress as a bar -Category: verbose -Example: -# -O $URL -Added: 5.10 -See-also: styled-output -Multi: boolean -Scope: global ---- -Make curl display transfer progress as a simple progress bar instead of the -standard, more informational, meter. - -This progress bar draws a single line of '#' characters across the screen and -shows a percentage if the transfer size is known. For transfers without a -known size, there is a space ship (-=o=-) that moves back and forth but only -while data is being transferred, with a set of flying hash sign symbols on -top. diff --git a/third-party/curl/docs/cmdline-opts/progress-bar.md b/third-party/curl/docs/cmdline-opts/progress-bar.md new file mode 100644 index 0000000000..6f08d7f7c7 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/progress-bar.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: # +Long: progress-bar +Help: Display transfer progress as a bar +Category: verbose global +Added: 5.10 +Multi: boolean +Scope: global +See-also: + - styled-output +Example: + - -# -O $URL +--- + +# `--progress-bar` + +Make curl display transfer progress as a simple progress bar instead of the +standard, more informational, meter. + +This progress bar draws a single line of '#' characters across the screen and +shows a percentage if the transfer size is known. For transfers without a +known size, there is a space ship (-=o=-) that moves back and forth but only +while data is being transferred, with a set of flying hash sign symbols on +top. diff --git a/third-party/curl/docs/cmdline-opts/proto-default.d b/third-party/curl/docs/cmdline-opts/proto-default.d deleted file mode 100644 index d5b4bcd10d..0000000000 --- a/third-party/curl/docs/cmdline-opts/proto-default.d +++ /dev/null @@ -1,20 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proto-default -Help: Use PROTOCOL for any URL missing a scheme -Arg: -Added: 7.45.0 -Category: connection curl -Example: --proto-default https ftp.example.com -See-also: proto proto-redir -Multi: single ---- -Tells curl to use *protocol* for any URL missing a scheme name. - -An unknown or unsupported protocol causes error -*CURLE_UNSUPPORTED_PROTOCOL* (1). - -This option does not change the default proxy protocol (http). - -Without this option set, curl guesses protocol based on the host name, see ---url for details. diff --git a/third-party/curl/docs/cmdline-opts/proto-default.md b/third-party/curl/docs/cmdline-opts/proto-default.md new file mode 100644 index 0000000000..903fac73a5 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proto-default.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proto-default +Help: Use PROTOCOL for any URL missing a scheme +Arg: +Added: 7.45.0 +Category: connection curl +Multi: single +See-also: + - proto + - proto-redir +Example: + - --proto-default https ftp.example.com +--- + +# `--proto-default` + +Use *protocol* for any provided URL missing a scheme. The case-insensitive +name should be given without any `://` suffix. + +An unknown or unsupported protocol causes error *CURLE_UNSUPPORTED_PROTOCOL*. + +This option does not change the default proxy protocol (http). + +Without this option set, curl guesses protocol based on the hostname, see +--url for details. + +The default protocol cannot be set to `ipfs` or `ipns`. Those schemes need to +be used explicitly in the URL. diff --git a/third-party/curl/docs/cmdline-opts/proto-redir.d b/third-party/curl/docs/cmdline-opts/proto-redir.d deleted file mode 100644 index dec8716144..0000000000 --- a/third-party/curl/docs/cmdline-opts/proto-redir.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proto-redir -Arg: -Help: Enable/disable PROTOCOLS on redirect -Added: 7.20.2 -Category: connection curl -Example: --proto-redir =http,https $URL -See-also: proto -Multi: single ---- -Tells curl to limit what protocols it may use on redirect. Protocols denied by ---proto are not overridden by this option. See --proto for how protocols are -represented. - -Example, allow only HTTP and HTTPS on redirect: - - curl --proto-redir -all,http,https http://example.com - -By default curl only allows HTTP, HTTPS, FTP and FTPS on redirects (added in -7.65.2). Specifying *all* or *+all* enables all protocols on redirects, which -is not good for security. diff --git a/third-party/curl/docs/cmdline-opts/proto-redir.md b/third-party/curl/docs/cmdline-opts/proto-redir.md new file mode 100644 index 0000000000..1f75bfdfd6 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proto-redir.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proto-redir +Arg: +Help: Enable/disable PROTOCOLS on redirect +Added: 7.21.0 +Category: connection curl +Multi: single +See-also: + - proto + - follow +Example: + - --proto-redir =http,https --follow $URL +--- + +# `--proto-redir` + +Limit what protocols to allow on redirects. Protocols denied by --proto are +not overridden by this option. See --proto for how protocols are represented. + +Example, allow only HTTP and HTTPS on redirect: + + curl --proto-redir -all,http,https --follow http://example.com + +By default curl only allows HTTP, HTTPS, FTP and FTPS on redirects +(added in 7.65.2). Specifying *all* or *+all* enables all protocols on +redirects, which is not good for security. diff --git a/third-party/curl/docs/cmdline-opts/proto.d b/third-party/curl/docs/cmdline-opts/proto.d deleted file mode 100644 index ac024bf428..0000000000 --- a/third-party/curl/docs/cmdline-opts/proto.d +++ /dev/null @@ -1,48 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proto -Arg: -Help: Enable/disable PROTOCOLS -See-also: proto-redir proto-default -Added: 7.20.2 -Category: connection curl -Example: --proto =http,https,sftp $URL -Multi: single ---- -Tells curl to limit what protocols it may use for transfers. Protocols are -evaluated left to right, are comma separated, and are each a protocol name or -'all', optionally prefixed by zero or more modifiers. Available modifiers are: -.RS -.TP 3 -.B + -Permit this protocol in addition to protocols already permitted (this is -the default if no modifier is used). -.TP -.B - -Deny this protocol, removing it from the list of protocols already permitted. -.TP -.B = -Permit only this protocol (ignoring the list already permitted), though -subject to later modification by subsequent entries in the comma separated -list. -.RE -.IP -For example: -.RS -.TP 15 -.B --proto -ftps -uses the default protocols, but disables ftps -.TP -.B --proto -all,https,+http -only enables http and https -.TP -.B --proto =http,https -also only enables http and https -.RE -.IP -Unknown and disabled protocols produce a warning. This allows scripts to -safely rely on being able to disable potentially dangerous protocols, without -relying upon support for that protocol being built into curl to avoid an error. - -This option can be used multiple times, in which case the effect is the same -as concatenating the protocols into one instance of the option. diff --git a/third-party/curl/docs/cmdline-opts/proto.md b/third-party/curl/docs/cmdline-opts/proto.md new file mode 100644 index 0000000000..cf288d4565 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proto.md @@ -0,0 +1,48 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proto +Arg: +Help: Enable/disable PROTOCOLS +Added: 7.21.0 +Category: connection curl +Multi: single +See-also: + - proto-redir + - proto-default +Example: + - --proto =http,https,sftp $URL +--- + +# `--proto` + +Limit what protocols to allow for transfers. Protocols are evaluated left to +right, are comma separated, and are each a protocol name or 'all', optionally +prefixed by zero or more modifiers. Available modifiers are: + +## + +Permit this protocol in addition to protocols already permitted (this is +the default if no modifier is used). + +## - +Deny this protocol, removing it from the list of protocols already permitted. + +## = +Permit only this protocol (ignoring the list already permitted), though +subject to later modification by subsequent entries in the comma separated +list. + +## + +For example: --proto -ftps uses the default protocols, but disables ftps + +--proto -all,https,+http only enables http and https + +--proto =http,https also only enables http and https + +Unknown and disabled protocols produce a warning. This allows scripts to +safely rely on being able to disable potentially dangerous protocols, without +relying upon support for that protocol being built into curl to avoid an error. + +This option can be used multiple times, in which case the effect is the same +as concatenating the protocols into one instance of the option. diff --git a/third-party/curl/docs/cmdline-opts/proxy-anyauth.d b/third-party/curl/docs/cmdline-opts/proxy-anyauth.d deleted file mode 100644 index fa460876ef..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-anyauth.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-anyauth -Help: Pick any proxy authentication method -Added: 7.13.2 -See-also: proxy proxy-basic proxy-digest -Category: proxy auth -Example: --proxy-anyauth --proxy-user user:passwd -x proxy $URL -Multi: mutex ---- -Tells curl to pick a suitable authentication method when communicating with -the given HTTP proxy. This might cause an extra request/response round-trip. diff --git a/third-party/curl/docs/cmdline-opts/proxy-anyauth.md b/third-party/curl/docs/cmdline-opts/proxy-anyauth.md new file mode 100644 index 0000000000..bb59b21e8f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-anyauth.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-anyauth +Help: Pick any proxy authentication method +Added: 7.13.2 +Category: proxy auth +Multi: custom +See-also: + - proxy + - proxy-basic + - proxy-digest +Example: + - --proxy-anyauth --proxy-user user:passwd -x proxy $URL +--- + +# `--proxy-anyauth` + +Automatically pick a suitable authentication method when communicating with +the given HTTP proxy. This might cause an extra request/response round-trip. diff --git a/third-party/curl/docs/cmdline-opts/proxy-basic.d b/third-party/curl/docs/cmdline-opts/proxy-basic.d deleted file mode 100644 index ff56631f77..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-basic.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-basic -Help: Use Basic authentication on the proxy -See-also: proxy proxy-anyauth proxy-digest -Category: proxy auth -Example: --proxy-basic --proxy-user user:passwd -x proxy $URL -Added: 7.12.0 -Multi: mutex ---- -Tells curl to use HTTP Basic authentication when communicating with the given -proxy. Use --basic for enabling HTTP Basic with a remote host. Basic is the -default authentication method curl uses with proxies. diff --git a/third-party/curl/docs/cmdline-opts/proxy-basic.md b/third-party/curl/docs/cmdline-opts/proxy-basic.md new file mode 100644 index 0000000000..732ea1f45c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-basic.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-basic +Help: Use Basic authentication on the proxy +Category: proxy auth +Added: 7.12.0 +Multi: boolean +See-also: + - proxy + - proxy-anyauth + - proxy-digest +Example: + - --proxy-basic --proxy-user user:passwd -x proxy $URL +--- + +# `--proxy-basic` + +Use HTTP Basic authentication when communicating with the given proxy. Use +--basic for enabling HTTP Basic with a remote host. Basic is the default +authentication method curl uses with proxies. diff --git a/third-party/curl/docs/cmdline-opts/proxy-ca-native.d b/third-party/curl/docs/cmdline-opts/proxy-ca-native.d deleted file mode 100644 index aab4fcabc2..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-ca-native.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-ca-native -Help: Use CA certificates from the native OS for proxy -Protocols: TLS -Category: tls -See-also: cacert capath insecure -Example: --ca-native $URL -Added: 8.2.0 -Multi: boolean ---- -Tells curl to use the CA store from the native operating system to verify the -HTTPS proxy. By default, curl uses a CA store provided in a single file or -directory, but when using this option it interfaces the operating system's own -vault. - -This option only works for curl on Windows when built to use OpenSSL. When -curl on Windows is built to use Schannel, this feature is implied and curl -then only uses the native CA store. - -curl built with wolfSSL also supports this option (added in 8.3.0). diff --git a/third-party/curl/docs/cmdline-opts/proxy-ca-native.md b/third-party/curl/docs/cmdline-opts/proxy-ca-native.md new file mode 100644 index 0000000000..0252e993fc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-ca-native.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-ca-native +Help: Load CA certs from the OS to verify proxy +Protocols: TLS +Category: tls +Added: 8.2.0 +Multi: boolean +See-also: + - ca-native + - cacert + - capath + - dump-ca-embed + - insecure +Example: + - --proxy-ca-native $URL +--- + +# `--proxy-ca-native` + +Use the operating system's native CA store for certificate verification of the +HTTPS proxy. + +This option is independent of other HTTPS proxy CA certificate locations set at +run time or build time. Those locations are searched in addition to the native +CA store. + +Equivalent to --ca-native but used in HTTPS proxy context. Refer to --ca-native +for TLS backend limitations. diff --git a/third-party/curl/docs/cmdline-opts/proxy-cacert.d b/third-party/curl/docs/cmdline-opts/proxy-cacert.d deleted file mode 100644 index 45dc3f301b..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-cacert.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-cacert -Help: CA certificate to verify peer against for proxy -Arg: -Added: 7.52.0 -See-also: proxy-capath cacert capath proxy -Category: proxy tls -Example: --proxy-cacert CA-file.txt -x https://proxy $URL -Multi: single ---- -Same as --cacert but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-cacert.md b/third-party/curl/docs/cmdline-opts/proxy-cacert.md new file mode 100644 index 0000000000..0b2405d1c9 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-cacert.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-cacert +Help: CA certificates to verify proxy against +Arg: +Added: 7.52.0 +Category: proxy tls +Multi: single +See-also: + - proxy-capath + - cacert + - capath + - dump-ca-embed + - proxy +Example: + - --proxy-cacert CA-file.txt -x https://proxy.example $URL +--- + +# `--proxy-cacert` + +Use the specified certificate file to verify the HTTPS proxy. The file may +contain multiple CA certificates. The certificate(s) must be in PEM format. + +This allows you to use a different trust for the proxy compared to the remote +server connected to via the proxy. + +Equivalent to --cacert but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-capath.d b/third-party/curl/docs/cmdline-opts/proxy-capath.d deleted file mode 100644 index 309f9408a8..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-capath.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-capath -Help: CA directory to verify peer against for proxy -Arg: -Added: 7.52.0 -See-also: proxy-cacert proxy capath -Category: proxy tls -Example: --proxy-capath /local/directory -x https://proxy $URL -Multi: single ---- -Same as --capath but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-capath.md b/third-party/curl/docs/cmdline-opts/proxy-capath.md new file mode 100644 index 0000000000..344756a43e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-capath.md @@ -0,0 +1,31 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-capath +Help: CA directory to verify proxy against +Arg: +Added: 7.52.0 +Category: proxy tls +Multi: single +See-also: + - proxy-cacert + - proxy + - capath + - dump-ca-embed +Example: + - --proxy-capath /local/directory -x https://proxy.example $URL +--- + +# `--proxy-capath` + +Same as --capath but used in HTTPS proxy context. + +Use the specified certificate directory to verify the proxy. Multiple paths +can be provided by separating them with colon (`:`) (e.g. `path1:path2:path3`). The +certificates must be in PEM format, and if curl is built against OpenSSL, the +directory must have been processed using the c_rehash utility supplied with +OpenSSL. Using --proxy-capath can allow OpenSSL-powered curl to make +SSL-connections much more efficiently than using --proxy-cacert if the +--proxy-cacert file contains many CA certificates. + +If this option is set, the default capath value is ignored. diff --git a/third-party/curl/docs/cmdline-opts/proxy-cert-type.d b/third-party/curl/docs/cmdline-opts/proxy-cert-type.d deleted file mode 100644 index 4ab38f5a80..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-cert-type.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-cert-type -Arg: -Added: 7.52.0 -Help: Client certificate type for HTTPS proxy -Category: proxy tls -Example: --proxy-cert-type PEM --proxy-cert file -x https://proxy $URL -See-also: proxy-cert -Multi: single ---- -Same as --cert-type but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-cert-type.md b/third-party/curl/docs/cmdline-opts/proxy-cert-type.md new file mode 100644 index 0000000000..3dcd2017c4 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-cert-type.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-cert-type +Arg: +Added: 7.52.0 +Help: Client certificate type for HTTPS proxy +Category: proxy tls +Multi: single +See-also: + - proxy-cert + - proxy-key +Example: + - --proxy-cert-type PEM --proxy-cert file -x https://proxy.example $URL +--- + +# `--proxy-cert-type` + +Set type of the provided client certificate when using HTTPS proxy. PEM, DER, +ENG, PROV and P12 are recognized types. + +The default type depends on the TLS backend and is usually PEM. For Schannel +it is P12. If --proxy-cert is a pkcs11: URI then ENG or PROV is the default +type (depending on OpenSSL version). + +Equivalent to --cert-type but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-cert.d b/third-party/curl/docs/cmdline-opts/proxy-cert.d deleted file mode 100644 index 2a869deb02..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-cert.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-cert -Arg: -Help: Set client certificate for proxy -Added: 7.52.0 -Category: proxy tls -Example: --proxy-cert file -x https://proxy $URL -See-also: proxy-cert-type -Multi: single ---- -Same as --cert but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-cert.md b/third-party/curl/docs/cmdline-opts/proxy-cert.md new file mode 100644 index 0000000000..929791e3a1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-cert.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-cert +Arg: +Help: Set client certificate for proxy +Added: 7.52.0 +Category: proxy tls +Multi: single +See-also: + - proxy + - proxy-key + - proxy-cert-type +Example: + - --proxy-cert file -x https://proxy.example $URL +--- + +# `--proxy-cert` + +Use the specified client certificate file when communicating with an HTTPS +proxy. The certificate must be PEM format. If the optional password is not +specified, it is queried for on the terminal. Use --proxy-key to provide the +private key. + +This option is the equivalent to --cert but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-ciphers.d b/third-party/curl/docs/cmdline-opts/proxy-ciphers.d deleted file mode 100644 index 5879f397e1..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-ciphers.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-ciphers -Arg: -Help: SSL ciphers to use for proxy -Added: 7.52.0 -Category: proxy tls -Example: --proxy-ciphers ECDHE-ECDSA-AES256-CCM8 -x https://proxy $URL -See-also: ciphers curves proxy -Multi: single ---- -Same as --ciphers but used in HTTPS proxy context. - -Specifies which ciphers to use in the connection to the HTTPS proxy. The list -of ciphers must specify valid ciphers. Read up on SSL cipher list details on -this URL: - -https://curl.se/docs/ssl-ciphers.html diff --git a/third-party/curl/docs/cmdline-opts/proxy-ciphers.md b/third-party/curl/docs/cmdline-opts/proxy-ciphers.md new file mode 100644 index 0000000000..4cb85e1e67 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-ciphers.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-ciphers +Arg: +Help: TLS 1.2 (1.1, 1.0) ciphers to use for proxy +Protocols: TLS +Added: 7.52.0 +Category: proxy tls +Multi: single +See-also: + - proxy-tls13-ciphers + - ciphers + - proxy +Example: + - --proxy-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256 -x https://proxy.example $URL +--- + +# `--proxy-ciphers` + +Same as --ciphers but used in HTTPS proxy context. + +Specify which cipher suites to use in the connection to your HTTPS proxy when +it negotiates TLS 1.2 (1.1, 1.0). The list of ciphers suites must specify +valid ciphers. Read up on cipher suite details on this URL: + +https://curl.se/docs/ssl-ciphers.html diff --git a/third-party/curl/docs/cmdline-opts/proxy-crlfile.d b/third-party/curl/docs/cmdline-opts/proxy-crlfile.d deleted file mode 100644 index 1a8fdf25da..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-crlfile.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-crlfile -Arg: -Help: Set a CRL list for proxy -Added: 7.52.0 -Category: proxy tls -Example: --proxy-crlfile rejects.txt -x https://proxy $URL -See-also: crlfile proxy -Multi: single ---- -Same as --crlfile but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-crlfile.md b/third-party/curl/docs/cmdline-opts/proxy-crlfile.md new file mode 100644 index 0000000000..9f7d3304fa --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-crlfile.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-crlfile +Arg: +Help: Set a CRL list for proxy +Added: 7.52.0 +Category: proxy tls +Multi: single +See-also: + - crlfile + - proxy +Example: + - --proxy-crlfile rejects.txt -x https://proxy.example $URL +--- + +# `--proxy-crlfile` + +Provide filename for a PEM formatted file with a Certificate Revocation List +that specifies peer certificates that are considered revoked when +communicating with an HTTPS proxy. + +Equivalent to --crlfile but only used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-digest.d b/third-party/curl/docs/cmdline-opts/proxy-digest.d deleted file mode 100644 index c5cb19c48b..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-digest.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-digest -Help: Use Digest authentication on the proxy -See-also: proxy proxy-anyauth proxy-basic -Category: proxy tls -Example: --proxy-digest --proxy-user user:passwd -x proxy $URL -Added: 7.12.0 -Multi: mutex ---- -Tells curl to use HTTP Digest authentication when communicating with the given -proxy. Use --digest for enabling HTTP Digest with a remote host. diff --git a/third-party/curl/docs/cmdline-opts/proxy-digest.md b/third-party/curl/docs/cmdline-opts/proxy-digest.md new file mode 100644 index 0000000000..08984dcb5f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-digest.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-digest +Help: Digest auth with the proxy +Category: proxy tls +Added: 7.12.0 +Multi: boolean +See-also: + - proxy + - proxy-anyauth + - proxy-basic +Example: + - --proxy-digest --proxy-user user:passwd -x proxy $URL +--- + +# `--proxy-digest` + +Use HTTP Digest authentication when communicating with the given proxy. Use +--digest for enabling HTTP Digest with a remote host. diff --git a/third-party/curl/docs/cmdline-opts/proxy-header.d b/third-party/curl/docs/cmdline-opts/proxy-header.d deleted file mode 100644 index 06ae3bcbaa..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-header.d +++ /dev/null @@ -1,32 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-header -Arg:
-Help: Pass custom header(s) to proxy -Protocols: HTTP -Added: 7.37.0 -Category: proxy -Example: --proxy-header "X-First-Name: Joe" -x http://proxy $URL -Example: --proxy-header "User-Agent: surprise" -x http://proxy $URL -Example: --proxy-header "Host:" -x http://proxy $URL -See-also: proxy -Multi: append ---- -Extra header to include in the request when sending HTTP to a proxy. You may -specify any number of extra headers. This is the equivalent option to --header -but is for proxy communication only like in CONNECT requests when you want a -separate header sent to the proxy to what is sent to the actual remote host. - -curl makes sure that each header you add/replace is sent with the proper -end-of-line marker, you should thus **not** add that as a part of the header -content: do not add newlines or carriage returns, they only mess things up for -you. - -Headers specified with this option are not included in requests that curl -knows are not be sent to a proxy. - -This option can take an argument in @filename style, which then adds a header -for each line in the input file (added in 7.55.0). Using @- makes curl read -the headers from stdin. - -This option can be used multiple times to add/replace/remove multiple headers. diff --git a/third-party/curl/docs/cmdline-opts/proxy-header.md b/third-party/curl/docs/cmdline-opts/proxy-header.md new file mode 100644 index 0000000000..459eb462f6 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-header.md @@ -0,0 +1,39 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-header +Arg:
+Help: Pass custom header(s) to proxy +Protocols: HTTP +Added: 7.37.0 +Category: proxy +Multi: append +See-also: + - proxy + - header +Example: + - --proxy-header "X-First-Name: Joe" -x http://proxy $URL + - --proxy-header "User-Agent: surprise" -x http://proxy $URL + - --proxy-header "Host:" -x http://proxy $URL +--- + +# `--proxy-header` + +Extra header to include in the request when sending HTTP to a proxy. You may +specify any number of extra headers. This is the equivalent option to --header +but is for proxy communication only like in CONNECT requests when you want a +separate header sent to the proxy to what is sent to the actual remote host. + +curl makes sure that each header you add/replace is sent with the proper +end-of-line marker, you should thus **not** add that as a part of the header +content: do not add newlines or carriage returns, they only mess things up for +you. + +Headers specified with this option are not included in requests that curl +knows are not to be sent to a proxy. + +This option can take an argument in @filename style, which then adds a header +for each line in the input file (added in 7.55.0). Using @- makes curl read +the headers from stdin. + +This option can be used multiple times to add/replace/remove multiple headers. diff --git a/third-party/curl/docs/cmdline-opts/proxy-http2.d b/third-party/curl/docs/cmdline-opts/proxy-http2.d deleted file mode 100644 index 58f55e74dd..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-http2.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-http2 -Tags: Versions HTTP/2 -Protocols: HTTP -Added: 8.1.0 -Mutexed: -Requires: HTTP/2 -See-also: proxy -Help: Use HTTP/2 with HTTPS proxy -Category: http proxy -Example: --proxy-http2 -x proxy $URL -Multi: boolean ---- -Tells curl to try negotiate HTTP version 2 with an HTTPS proxy. The proxy might -still only offer HTTP/1 and then curl sticks to using that version. - -This has no effect for any other kinds of proxies. diff --git a/third-party/curl/docs/cmdline-opts/proxy-http2.md b/third-party/curl/docs/cmdline-opts/proxy-http2.md new file mode 100644 index 0000000000..a38da9e87e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-http2.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-http2 +Tags: Versions HTTP/2 +Protocols: HTTP +Added: 8.1.0 +Mutexed: proxy-http3 +Requires: HTTP/2 +Help: Use HTTP/2 with HTTPS proxy +Category: http proxy +Multi: boolean +See-also: + - proxy +Example: + - --proxy-http2 -x proxy $URL +--- + +# `--proxy-http2` + +Negotiate HTTP/2 with an HTTPS proxy. The proxy might still only offer HTTP/1 +and then curl sticks to using that version. + +This has no effect for any other kinds of proxies. + +This option is mutually exclusive with `--proxy-http3`. diff --git a/third-party/curl/docs/cmdline-opts/proxy-http3.md b/third-party/curl/docs/cmdline-opts/proxy-http3.md new file mode 100644 index 0000000000..6533b980b6 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-http3.md @@ -0,0 +1,31 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-http3 +Tags: Versions HTTP/3 +Protocols: HTTP +Added: 8.21.0 +Mutexed: proxy-http2 +Requires: HTTP/3 +Help: Use HTTP/3 with HTTPS proxy +Category: http proxy +Multi: boolean +See-also: + - proxy + - proxy-http2 +Example: + - --proxy-http3 -x proxy $URL +--- + +# `--proxy-http3` + +Negotiate HTTP/3 with an HTTPS proxy. +Fails to perform the transfer if the given proxy does not support HTTP/3. + +This has no effect for any other kinds of proxies. + +This option is mutually exclusive with `--proxy-http2`. + +This feature is experimental and requires a build with HTTP/3 proxy support +enabled. For autotools builds, use `--enable-proxy-http3`. For CMake builds, +use `-DUSE_PROXY_HTTP3=ON`. diff --git a/third-party/curl/docs/cmdline-opts/proxy-insecure.d b/third-party/curl/docs/cmdline-opts/proxy-insecure.d deleted file mode 100644 index beb8c25317..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-insecure.d +++ /dev/null @@ -1,11 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-insecure -Help: Do HTTPS proxy connections without verifying the proxy -Added: 7.52.0 -Category: proxy tls -Example: --proxy-insecure -x https://proxy $URL -See-also: proxy insecure -Multi: boolean ---- -Same as --insecure but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-insecure.md b/third-party/curl/docs/cmdline-opts/proxy-insecure.md new file mode 100644 index 0000000000..0c2d8b99bc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-insecure.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-insecure +Help: Skip HTTPS proxy cert verification +Added: 7.52.0 +Category: proxy tls +Multi: boolean +See-also: + - proxy + - insecure +Example: + - --proxy-insecure -x https://proxy.example $URL +--- + +# `--proxy-insecure` + +Same as --insecure but used in HTTPS proxy context. + +Every secure connection curl makes is verified to be secure before the +transfer takes place. This option makes curl skip the verification step with a +proxy and proceed without checking. + +When this option is not used for a proxy using HTTPS, curl verifies the +proxy's TLS certificate before it continues: that the certificate contains the +right name which matches the hostname and that the certificate has been signed +by a CA certificate present in the cert store. See this online resource for +further details: **https://curl.se/docs/sslcerts.html** + +**WARNING**: using this option makes the transfer to the proxy insecure. diff --git a/third-party/curl/docs/cmdline-opts/proxy-key-type.d b/third-party/curl/docs/cmdline-opts/proxy-key-type.d deleted file mode 100644 index 3fd11f3a32..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-key-type.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-key-type -Arg: -Help: Private key file type for proxy -Added: 7.52.0 -Category: proxy tls -Example: --proxy-key-type DER --proxy-key here -x https://proxy $URL -See-also: proxy-key proxy -Multi: single ---- -Same as --key-type but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-key-type.md b/third-party/curl/docs/cmdline-opts/proxy-key-type.md new file mode 100644 index 0000000000..e455140016 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-key-type.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-key-type +Arg: +Help: Private key file type for proxy +Added: 7.52.0 +Category: proxy tls +Multi: single +See-also: + - proxy-key + - proxy +Example: + - --proxy-key-type DER --proxy-key here -x https://proxy.example $URL +--- + +# `--proxy-key-type` + +Specify the private key file type your --proxy-key provided private key uses. +DER, PEM, and ENG are supported. If not specified, PEM is assumed. + +Equivalent to --key-type but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-key.d b/third-party/curl/docs/cmdline-opts/proxy-key.d deleted file mode 100644 index 4bf2748a4e..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-key.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-key -Help: Private key for HTTPS proxy -Arg: -Category: proxy tls -Example: --proxy-key here -x https://proxy $URL -Added: 7.52.0 -See-also: proxy-key-type proxy -Multi: single ---- -Same as --key but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-key.md b/third-party/curl/docs/cmdline-opts/proxy-key.md new file mode 100644 index 0000000000..8ee78c46ea --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-key.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-key +Help: Private key for HTTPS proxy +Arg: +Category: proxy tls +Added: 7.52.0 +Multi: single +See-also: + - proxy-key-type + - proxy +Example: + - --proxy-key here -x https://proxy.example $URL +--- + +# `--proxy-key` + +Specify the filename for your private key when using client certificates with +your HTTPS proxy. This option is the equivalent to --key but used in HTTPS +proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-negotiate.d b/third-party/curl/docs/cmdline-opts/proxy-negotiate.d deleted file mode 100644 index 89b5c1bde3..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-negotiate.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-negotiate -Help: Use HTTP Negotiate (SPNEGO) authentication on the proxy -Added: 7.17.1 -See-also: proxy-anyauth proxy-basic -Category: proxy auth -Example: --proxy-negotiate --proxy-user user:passwd -x proxy $URL -Multi: mutex ---- -Tells curl to use HTTP Negotiate (SPNEGO) authentication when communicating -with the given proxy. Use --negotiate for enabling HTTP Negotiate (SPNEGO) -with a remote host. diff --git a/third-party/curl/docs/cmdline-opts/proxy-negotiate.md b/third-party/curl/docs/cmdline-opts/proxy-negotiate.md new file mode 100644 index 0000000000..0285155c6a --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-negotiate.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-negotiate +Help: HTTP Negotiate (SPNEGO) auth with the proxy +Added: 7.17.1 +Category: proxy auth +Multi: mutex +See-also: + - proxy-anyauth + - proxy-basic + - proxy-service-name +Example: + - --proxy-negotiate --proxy-user user:passwd -x proxy $URL +--- + +# `--proxy-negotiate` + +Use HTTP Negotiate (SPNEGO) authentication when communicating with the given +proxy. Use --negotiate for enabling HTTP Negotiate (SPNEGO) with a remote +host. diff --git a/third-party/curl/docs/cmdline-opts/proxy-ntlm.d b/third-party/curl/docs/cmdline-opts/proxy-ntlm.d deleted file mode 100644 index f8481e5d6d..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-ntlm.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-ntlm -Help: Use NTLM authentication on the proxy -See-also: proxy-negotiate proxy-anyauth -Category: proxy auth -Example: --proxy-ntlm --proxy-user user:passwd -x http://proxy $URL -Added: 7.10.7 -Multi: mutex ---- -Tells curl to use HTTP NTLM authentication when communicating with the given -proxy. Use --ntlm for enabling NTLM with a remote host. diff --git a/third-party/curl/docs/cmdline-opts/proxy-ntlm.md b/third-party/curl/docs/cmdline-opts/proxy-ntlm.md new file mode 100644 index 0000000000..a0b6a252d4 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-ntlm.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-ntlm +Help: NTLM authentication with the proxy +Category: proxy auth +Added: 7.10.7 +Multi: boolean +See-also: + - proxy-negotiate + - proxy-anyauth + - proxy-user +Example: + - --proxy-ntlm --proxy-user user:passwd -x http://proxy $URL +--- + +# `--proxy-ntlm` + +Use HTTP NTLM authentication when communicating with the given proxy. Use +--ntlm for enabling NTLM with a remote host. diff --git a/third-party/curl/docs/cmdline-opts/proxy-pass.d b/third-party/curl/docs/cmdline-opts/proxy-pass.d deleted file mode 100644 index 3071399519..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-pass.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-pass -Arg: -Help: Pass phrase for the private key for HTTPS proxy -Added: 7.52.0 -Category: proxy tls auth -Example: --proxy-pass secret --proxy-key here -x https://proxy $URL -See-also: proxy proxy-key -Multi: single ---- -Same as --pass but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-pass.md b/third-party/curl/docs/cmdline-opts/proxy-pass.md new file mode 100644 index 0000000000..1005d95d2f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-pass.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-pass +Arg: +Help: Passphrase for private key for HTTPS proxy +Added: 7.52.0 +Category: proxy tls auth +Multi: single +See-also: + - proxy + - proxy-key +Example: + - --proxy-pass secret --proxy-key here -x https://proxy.example $URL +--- + +# `--proxy-pass` + +Passphrase for the private key for HTTPS proxy client certificate. + +Equivalent to --pass but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-pinnedpubkey.d b/third-party/curl/docs/cmdline-opts/proxy-pinnedpubkey.d deleted file mode 100644 index 7bf99d8c5b..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-pinnedpubkey.d +++ /dev/null @@ -1,22 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-pinnedpubkey -Arg: -Help: FILE/HASHES public key to verify proxy with -Protocols: TLS -Category: proxy tls -Example: --proxy-pinnedpubkey keyfile $URL -Example: --proxy-pinnedpubkey 'sha256//ce118b51897f4452dc' $URL -Added: 7.59.0 -See-also: pinnedpubkey proxy -Multi: single ---- -Tells curl to use the specified public key file (or hashes) to verify the -proxy. This can be a path to a file which contains a single public key in PEM -or DER format, or any number of base64 encoded sha256 hashes preceded by -'sha256//' and separated by ';'. - -When negotiating a TLS or SSL connection, the server sends a certificate -indicating its identity. A public key is extracted from this certificate and -if it does not exactly match the public key provided to this option, curl -aborts the connection before sending or receiving any data. diff --git a/third-party/curl/docs/cmdline-opts/proxy-pinnedpubkey.md b/third-party/curl/docs/cmdline-opts/proxy-pinnedpubkey.md new file mode 100644 index 0000000000..df0b0bb907 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-pinnedpubkey.md @@ -0,0 +1,31 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-pinnedpubkey +Arg: +Help: FILE/HASHES public key to verify proxy with +Protocols: TLS +Category: proxy tls +Added: 7.59.0 +Multi: single +See-also: + - pinnedpubkey + - proxy +Example: + - --proxy-pinnedpubkey keyfile $URL + - --proxy-pinnedpubkey 'sha256//ce118b51897f4452dc' $URL +--- + +# `--proxy-pinnedpubkey` + +Use the specified public key file (or hashes) to verify the proxy. This can be +a path to a file which contains a single public key in PEM or DER format, or +any number of base64 encoded sha256 hashes preceded by 'sha256//' and +separated by ';'. + +When negotiating a TLS or SSL connection, the server sends a certificate +indicating its identity. A public key is extracted from this certificate and +if it does not exactly match the public key provided to this option, curl +aborts the connection before sending or receiving any data. + +Before curl 8.10.0 this option did not work due to a bug. diff --git a/third-party/curl/docs/cmdline-opts/proxy-service-name.d b/third-party/curl/docs/cmdline-opts/proxy-service-name.d deleted file mode 100644 index 200973fb52..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-service-name.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-service-name -Arg: -Help: SPNEGO proxy service name -Added: 7.43.0 -Category: proxy tls -Example: --proxy-service-name "shrubbery" -x proxy $URL -See-also: service-name proxy -Multi: single ---- -This option allows you to change the service name for proxy negotiation. diff --git a/third-party/curl/docs/cmdline-opts/proxy-service-name.md b/third-party/curl/docs/cmdline-opts/proxy-service-name.md new file mode 100644 index 0000000000..b3d665d8b4 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-service-name.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-service-name +Arg: +Help: SPNEGO proxy service name +Added: 7.43.0 +Category: proxy tls +Multi: single +See-also: + - service-name + - proxy + - proxy-negotiate +Example: + - --proxy-service-name "shrubbery" -x proxy $URL +--- + +# `--proxy-service-name` + +Set the service name for SPNEGO when doing proxy authentication. diff --git a/third-party/curl/docs/cmdline-opts/proxy-ssl-allow-beast.d b/third-party/curl/docs/cmdline-opts/proxy-ssl-allow-beast.d deleted file mode 100644 index 55ff62b46e..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-ssl-allow-beast.d +++ /dev/null @@ -1,11 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-ssl-allow-beast -Help: Allow security flaw for interop for HTTPS proxy -Added: 7.52.0 -Category: proxy tls -Example: --proxy-ssl-allow-beast -x https://proxy $URL -See-also: ssl-allow-beast proxy -Multi: boolean ---- -Same as --ssl-allow-beast but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-ssl-allow-beast.md b/third-party/curl/docs/cmdline-opts/proxy-ssl-allow-beast.md new file mode 100644 index 0000000000..909a7f026e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-ssl-allow-beast.md @@ -0,0 +1,29 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-ssl-allow-beast +Help: Allow this security flaw for HTTPS proxy +Added: 7.52.0 +Category: proxy tls +Multi: boolean +See-also: + - ssl-allow-beast + - proxy +Example: + - --proxy-ssl-allow-beast -x https://proxy.example $URL +--- + +# `--proxy-ssl-allow-beast` + +Do not work around a security flaw in the TLS1.0 protocol known as BEAST when +communicating to an HTTPS proxy. If this option is not used, the TLS layer may +use workarounds known to cause interoperability problems with some older +server implementations. + +This option only changes how curl does TLS 1.0 with an HTTPS proxy and has no +effect on later TLS versions. + +**WARNING**: this option loosens the TLS security, and by using this flag you +ask for exactly that. + +Equivalent to --ssl-allow-beast but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-ssl-auto-client-cert.d b/third-party/curl/docs/cmdline-opts/proxy-ssl-auto-client-cert.d deleted file mode 100644 index ea0f0c04dd..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-ssl-auto-client-cert.d +++ /dev/null @@ -1,11 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-ssl-auto-client-cert -Help: Use auto client certificate for proxy (Schannel) -Added: 7.77.0 -Category: proxy tls -Example: --proxy-ssl-auto-client-cert -x https://proxy $URL -See-also: ssl-auto-client-cert proxy -Multi: boolean ---- -Same as --ssl-auto-client-cert but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-ssl-auto-client-cert.md b/third-party/curl/docs/cmdline-opts/proxy-ssl-auto-client-cert.md new file mode 100644 index 0000000000..e041b81523 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-ssl-auto-client-cert.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-ssl-auto-client-cert +Help: Auto client certificate for proxy +Added: 7.77.0 +Category: proxy tls +Multi: boolean +See-also: + - ssl-auto-client-cert + - proxy +Example: + - --proxy-ssl-auto-client-cert -x https://proxy.example $URL +--- + +# `--proxy-ssl-auto-client-cert` + +Same as --ssl-auto-client-cert but used in HTTPS proxy context. + +This is only supported by Schannel. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tls13-ciphers.d b/third-party/curl/docs/cmdline-opts/proxy-tls13-ciphers.d deleted file mode 100644 index f18c3d5c0c..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-tls13-ciphers.d +++ /dev/null @@ -1,21 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-tls13-ciphers -Arg: -help: TLS 1.3 proxy cipher suites -Protocols: TLS -Category: proxy tls -Example: --proxy-tls13-ciphers TLS_AES_128_GCM_SHA256 -x proxy $URL -Added: 7.61.0 -See-also: tls13-ciphers curves proxy-ciphers -Multi: single ---- -Specifies which cipher suites to use in the connection to your HTTPS proxy -when it negotiates TLS 1.3. The list of ciphers suites must specify valid -ciphers. Read up on TLS 1.3 cipher suite details on this URL: - -https://curl.se/docs/ssl-ciphers.html - -This option is currently used only when curl is built to use OpenSSL 1.1.1 or -later. If you are using a different SSL backend you can try setting TLS 1.3 -cipher suites by using the --proxy-ciphers option. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tls13-ciphers.md b/third-party/curl/docs/cmdline-opts/proxy-tls13-ciphers.md new file mode 100644 index 0000000000..6fcf6d79dc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-tls13-ciphers.md @@ -0,0 +1,33 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-tls13-ciphers +Arg: +Help: TLS 1.3 proxy cipher suites +Protocols: TLS +Category: proxy tls +Added: 7.61.0 +Multi: single +See-also: + - proxy-ciphers + - tls13-ciphers + - proxy +Example: + - --proxy-tls13-ciphers TLS_AES_128_GCM_SHA256 -x proxy $URL +--- + +# `--proxy-tls13-ciphers` + +Same as --tls13-ciphers but used in HTTPS proxy context. + +Specify which cipher suites to use in the connection to your HTTPS proxy when +it negotiates TLS 1.3. The list of ciphers suites must specify valid ciphers. +Read up on TLS 1.3 cipher suite details on this URL: + +https://curl.se/docs/ssl-ciphers.html + +This option is used when curl is built to use OpenSSL 1.1.1 or later, +Schannel, wolfSSL, or mbedTLS 3.6.0 or later. + +Before curl 8.10.0 with mbedTLS or wolfSSL, TLS 1.3 cipher suites were set +by using the --proxy-ciphers option. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tlsauthtype.d b/third-party/curl/docs/cmdline-opts/proxy-tlsauthtype.d deleted file mode 100644 index f83153e7ba..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-tlsauthtype.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-tlsauthtype -Arg: -Help: TLS authentication type for HTTPS proxy -Added: 7.52.0 -Category: proxy tls auth -Example: --proxy-tlsauthtype SRP -x https://proxy $URL -See-also: proxy proxy-tlsuser -Multi: single ---- -Same as --tlsauthtype but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tlsauthtype.md b/third-party/curl/docs/cmdline-opts/proxy-tlsauthtype.md new file mode 100644 index 0000000000..84becc149e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-tlsauthtype.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-tlsauthtype +Arg: +Help: TLS authentication type for HTTPS proxy +Added: 7.52.0 +Category: proxy tls auth +Multi: single +See-also: + - proxy + - proxy-tlsuser + - proxy-tlspassword +Example: + - --proxy-tlsauthtype SRP -x https://proxy.example $URL +--- + +# `--proxy-tlsauthtype` + +Set TLS authentication type with HTTPS proxy. The only supported option is +`SRP`, for TLS-SRP (RFC 5054). This option works only if the underlying +libcurl is built with TLS-SRP support. + +Equivalent to --tlsauthtype but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tlspassword.d b/third-party/curl/docs/cmdline-opts/proxy-tlspassword.d deleted file mode 100644 index 7ec01401be..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-tlspassword.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-tlspassword -Arg: -Help: TLS password for HTTPS proxy -Added: 7.52.0 -Category: proxy tls auth -Example: --proxy-tlspassword passwd -x https://proxy $URL -See-also: proxy proxy-tlsuser -Multi: single ---- -Same as --tlspassword but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tlspassword.md b/third-party/curl/docs/cmdline-opts/proxy-tlspassword.md new file mode 100644 index 0000000000..63c2521566 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-tlspassword.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-tlspassword +Arg: +Help: TLS password for HTTPS proxy +Added: 7.52.0 +Category: proxy tls auth +Multi: single +See-also: + - proxy + - proxy-tlsuser +Example: + - --proxy-tlspassword passwd -x https://proxy.example $URL +--- + +# `--proxy-tlspassword` + +Set password to use with the TLS authentication method specified with +--proxy-tlsauthtype when using HTTPS proxy. Requires that --proxy-tlsuser is +set. + +This option does not work with TLS 1.3. + +Equivalent to --tlspassword but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tlsuser.d b/third-party/curl/docs/cmdline-opts/proxy-tlsuser.d deleted file mode 100644 index 17be7f7bae..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-tlsuser.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-tlsuser -Arg: -Help: TLS username for HTTPS proxy -Added: 7.52.0 -Category: proxy tls auth -Example: --proxy-tlsuser smith -x https://proxy $URL -See-also: proxy proxy-tlspassword -Multi: single ---- -Same as --tlsuser but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tlsuser.md b/third-party/curl/docs/cmdline-opts/proxy-tlsuser.md new file mode 100644 index 0000000000..610a2169b8 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-tlsuser.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-tlsuser +Arg: +Help: TLS username for HTTPS proxy +Added: 7.52.0 +Category: proxy tls auth +Multi: single +See-also: + - proxy + - proxy-tlspassword +Example: + - --proxy-tlsuser smith -x https://proxy.example $URL +--- + +# `--proxy-tlsuser` + +Set username for use for HTTPS proxy with the TLS authentication method +specified with --proxy-tlsauthtype. Requires that --proxy-tlspassword also is +set. + +This option does not work with TLS 1.3. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tlsv1.d b/third-party/curl/docs/cmdline-opts/proxy-tlsv1.d deleted file mode 100644 index c4345023ef..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-tlsv1.d +++ /dev/null @@ -1,11 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-tlsv1 -Help: Use TLSv1 for HTTPS proxy -Added: 7.52.0 -Category: proxy tls auth -Example: --proxy-tlsv1 -x https://proxy $URL -See-also: proxy -Multi: mutex ---- -Same as --tlsv1 but used in HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-tlsv1.md b/third-party/curl/docs/cmdline-opts/proxy-tlsv1.md new file mode 100644 index 0000000000..20643fd82b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-tlsv1.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-tlsv1 +Help: TLSv1 for HTTPS proxy +Added: 7.52.0 +Category: proxy tls auth +Multi: mutex +See-also: + - proxy +Example: + - --proxy-tlsv1 -x https://proxy.example $URL +--- + +# `--proxy-tlsv1` + +Use at least TLS version 1.x when negotiating with an HTTPS proxy. That means +TLS version 1.0 or higher + +Equivalent to --tlsv1 but for an HTTPS proxy context. diff --git a/third-party/curl/docs/cmdline-opts/proxy-user.d b/third-party/curl/docs/cmdline-opts/proxy-user.d deleted file mode 100644 index df30de2d92..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy-user.d +++ /dev/null @@ -1,23 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy-user -Short: U -Arg: -Help: Proxy user and password -Category: proxy auth -Example: --proxy-user name:pwd -x proxy $URL -Added: 4.0 -See-also: proxy-pass -Multi: single ---- -Specify the user name and password to use for proxy authentication. - -If you use a Windows SSPI-enabled curl binary and do either Negotiate or NTLM -authentication then you can tell curl to select the user name and password -from your environment by specifying a single colon with this option: "-U :". - -On systems where it works, curl hides the given option argument from process -listings. This is not enough to protect credentials from possibly getting seen -by other users on the same system as they still are visible for a moment -before cleared. Such sensitive data should be retrieved from a file instead or -similar and never used in clear text in a command line. diff --git a/third-party/curl/docs/cmdline-opts/proxy-user.md b/third-party/curl/docs/cmdline-opts/proxy-user.md new file mode 100644 index 0000000000..e2508eda05 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy-user.md @@ -0,0 +1,29 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy-user +Short: U +Arg: +Help: Proxy user and password +Category: proxy auth +Added: 4.0 +Multi: single +See-also: + - proxy-pass +Example: + - --proxy-user smith:secret -x proxy $URL +--- + +# `--proxy-user` + +Specify the username and password to use for proxy authentication. + +If you use a Windows SSPI-enabled curl binary and do either Negotiate or NTLM +authentication then you can tell curl to select the username and password from +your environment by specifying a single colon with this option: "-U :". + +On systems where it works, curl hides the given option argument from process +listings. This is not enough to protect credentials from possibly getting seen +by other users on the same system as they still are visible for a moment +before being cleared. Such sensitive data should be retrieved from a file instead or +similar and never used in clear text in a command line. diff --git a/third-party/curl/docs/cmdline-opts/proxy.d b/third-party/curl/docs/cmdline-opts/proxy.d deleted file mode 100644 index b7d550a110..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy.d +++ /dev/null @@ -1,51 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy -Short: x -Arg: [protocol://]host[:port] -Help: Use this proxy -Category: proxy -Example: --proxy http://proxy.example $URL -Added: 4.0 -See-also: socks5 proxy-basic -Multi: single ---- -Use the specified proxy. - -The proxy string can be specified with a protocol:// prefix. No protocol -specified or http:// it is treated as an HTTP proxy. Use socks4://, -socks4a://, socks5:// or socks5h:// to request a specific SOCKS version to be -used. (Added in 7.21.7) - -Unix domain sockets are supported for socks proxy. Set localhost for the host -part. e.g. socks5h://localhost/path/to/socket.sock - -HTTPS proxy support works set with the https:// protocol prefix for OpenSSL -and GnuTLS (added in 7.52.0). It also works for BearSSL, mbedTLS, rustls, -Schannel, Secure Transport and wolfSSL (added in 7.87.0). - -Unrecognized and unsupported proxy protocols cause an error (added in 7.52.0). -Ancient curl versions ignored unknown schemes and used http:// instead. - -If the port number is not specified in the proxy string, it is assumed to be -1080. - -This option overrides existing environment variables that set the proxy to -use. If there is an environment variable setting a proxy, you can set proxy to -"" to override it. - -All operations that are performed over an HTTP proxy are transparently -converted to HTTP. It means that certain protocol specific operations might -not be available. This is not the case if you can tunnel through the proxy, as -one with the --proxytunnel option. - -User and password that might be provided in the proxy string are URL decoded -by curl. This allows you to pass in special characters such as @ by using %40 -or pass in a colon with %3a. - -The proxy host can be specified the same way as the proxy environment -variables, including the protocol prefix (http://) and the embedded user + -password. - -When a proxy is used, the active FTP mode as set with --ftp-port, cannot be -used. diff --git a/third-party/curl/docs/cmdline-opts/proxy.md b/third-party/curl/docs/cmdline-opts/proxy.md new file mode 100644 index 0000000000..881f62d6a1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy.md @@ -0,0 +1,61 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy +Short: x +Arg: <[protocol://]host[:port]> +Help: Use this proxy +Category: proxy +Added: 4.0 +Multi: single +See-also: + - socks5 + - proxy-basic +Example: + - --proxy http://proxy.example $URL +--- + +# `--proxy` + +Use the specified proxy. + +The proxy string can be specified with a `protocol://` prefix. No protocol +specified or http:// it is treated as an HTTP proxy. Use `socks4://`, +`socks4a://`, `socks5://` or `socks5h://` to request a specific SOCKS version +to be used. (Added in 7.21.7) + +Unix domain sockets are supported for socks proxy. Set localhost for the host +part. e.g. socks5h://localhost/path/to/socket.sock + +HTTPS proxy support works with the `https://` protocol prefix for OpenSSL and +GnuTLS (added in 7.52.0). It also works for mbedTLS, Rustls, Schannel and +wolfSSL (added in 7.87.0). + +Unrecognized and unsupported proxy protocol schemes cause an error. + +If the port number is not specified in the proxy string, it is assumed to be +1080. + +This option overrides existing environment variables that set the proxy to +use. If there is an environment variable setting a proxy, you can set proxy to +"" to override it. + +All operations that are performed over an HTTP proxy are transparently +converted to HTTP. It means that certain protocol specific operations might +not be available. This is not the case if you can tunnel through the proxy, as +one with the --proxytunnel option. + +User and password that might be provided in the proxy string are URL decoded +by curl. This allows you to pass in special characters such as @ by using %40 +or pass in a colon with %3a. + +The proxy host can be specified the same way as the proxy environment +variables, including the protocol prefix (`http://`) and the embedded user + +password. + +When a proxy is used, the active FTP mode as set with --ftp-port, cannot be +used. + +Doing FTP over an HTTP proxy without --proxytunnel makes curl do HTTP with an +FTP URL over the proxy. For such transfers, common FTP specific options do not +work, including --ssl-reqd and --ftp-ssl-control. diff --git a/third-party/curl/docs/cmdline-opts/proxy1.0.d b/third-party/curl/docs/cmdline-opts/proxy1.0.d deleted file mode 100644 index 0657a9519d..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxy1.0.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxy1.0 -Arg: -Help: Use HTTP/1.0 proxy on given port -Category: proxy -Example: --proxy1.0 -x http://proxy $URL -Added: 7.19.4 -See-also: proxy socks5 preproxy -Multi: mutex ---- -Use the specified HTTP 1.0 proxy. If the port number is not specified, it is -assumed at port 1080. - -The only difference between this and the HTTP proxy option --proxy, is that -attempts to use CONNECT through the proxy specifies an HTTP 1.0 protocol -instead of the default HTTP 1.1. diff --git a/third-party/curl/docs/cmdline-opts/proxy1.0.md b/third-party/curl/docs/cmdline-opts/proxy1.0.md new file mode 100644 index 0000000000..4d3203a032 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxy1.0.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxy1.0 +Arg: +Help: Use HTTP/1.0 proxy on given port +Category: proxy +Added: 7.19.4 +Multi: mutex +See-also: + - proxy + - socks5 + - preproxy +Example: + - --proxy1.0 http://proxy $URL +--- + +# `--proxy1.0` + +Use the specified HTTP 1.0 proxy. If the port number is not specified, it is +assumed at port 1080. + +The only difference between this and the HTTP proxy option --proxy, is that +attempts to use CONNECT through the proxy specifies an HTTP 1.0 protocol +instead of the default HTTP 1.1. diff --git a/third-party/curl/docs/cmdline-opts/proxytunnel.d b/third-party/curl/docs/cmdline-opts/proxytunnel.d deleted file mode 100644 index 51457870b2..0000000000 --- a/third-party/curl/docs/cmdline-opts/proxytunnel.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: proxytunnel -Short: p -Help: Operate through an HTTP proxy tunnel (using CONNECT) -See-also: proxy -Category: proxy -Example: --proxytunnel -x http://proxy $URL -Added: 7.3 -Multi: boolean ---- -When an HTTP proxy is used --proxy, this option makes curl tunnel the traffic -through the proxy. The tunnel approach is made with the HTTP proxy CONNECT -request and requires that the proxy allows direct connect to the remote port -number curl wants to tunnel through to. - -To suppress proxy CONNECT response headers when curl is set to output headers -use --suppress-connect-headers. diff --git a/third-party/curl/docs/cmdline-opts/proxytunnel.md b/third-party/curl/docs/cmdline-opts/proxytunnel.md new file mode 100644 index 0000000000..fcec87480d --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/proxytunnel.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: proxytunnel +Short: p +Help: HTTP proxy tunnel (using CONNECT) +Category: proxy +Added: 7.3 +Multi: boolean +See-also: + - proxy +Example: + - --proxytunnel -x http://proxy $URL +--- + +# `--proxytunnel` + +When an HTTP proxy is used --proxy, this option makes curl tunnel the traffic +through the proxy. The tunnel approach is made with the HTTP proxy CONNECT +request and requires that the proxy allows direct connection to the remote port +number curl wants to tunnel through to. + +To suppress proxy CONNECT response headers when curl is set to output headers +use --suppress-connect-headers. diff --git a/third-party/curl/docs/cmdline-opts/pubkey.d b/third-party/curl/docs/cmdline-opts/pubkey.d deleted file mode 100644 index b2f4b727b6..0000000000 --- a/third-party/curl/docs/cmdline-opts/pubkey.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: pubkey -Arg: -Protocols: SFTP SCP -Help: SSH Public key file name -Category: sftp scp auth -Example: --pubkey file.pub sftp://example.com/ -Added: 7.16.2 -See-also: pass -Multi: single ---- -Public key file name. Allows you to provide your public key in this separate -file. - -curl attempts to automatically extract the public key from the private key -file, so passing this option is generally not required. Note that this public -key extraction requires libcurl to be linked against a copy of libssh2 1.2.8 -or higher that is itself linked against OpenSSL. (Added in 7.39.0.) diff --git a/third-party/curl/docs/cmdline-opts/pubkey.md b/third-party/curl/docs/cmdline-opts/pubkey.md new file mode 100644 index 0000000000..373d113c3f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/pubkey.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: pubkey +Arg: +Protocols: SFTP SCP +Help: SSH Public key filename +Category: sftp scp ssh auth +Added: 7.16.2 +Multi: single +See-also: + - pass +Example: + - --pubkey file.pub sftp://example.com/ +--- + +# `--pubkey` + +Public key filename. Allows you to provide your public key in this separate +file. + +curl attempts to automatically extract the public key from the private key +file, so passing this option is generally not required. Note that this public +key extraction requires libcurl to be linked against a copy of libssh2 1.2.8 +or higher that is itself linked against OpenSSL. (Added in 7.39.0.) diff --git a/third-party/curl/docs/cmdline-opts/quote.d b/third-party/curl/docs/cmdline-opts/quote.d deleted file mode 100644 index 5008d49321..0000000000 --- a/third-party/curl/docs/cmdline-opts/quote.d +++ /dev/null @@ -1,87 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: quote -Arg: -Short: Q -Help: Send command(s) to server before transfer -Protocols: FTP SFTP -Category: ftp sftp -Example: --quote "DELE file" ftp://example.com/foo -Added: 5.3 -See-also: request -Multi: append ---- -Send an arbitrary command to the remote FTP or SFTP server. Quote commands are -sent BEFORE the transfer takes place (just after the initial **PWD** command -in an FTP transfer, to be exact). To make commands take place after a -successful transfer, prefix them with a dash '-'. - -(FTP only) To make commands be sent after curl has changed the working -directory, just before the file transfer command(s), prefix the command with a -'+'. This is not performed when a directory listing is performed. - -You may specify any number of commands. - -By default curl stops at first failure. To make curl continue even if the -command fails, prefix the command with an asterisk (*). Otherwise, if the -server returns failure for one of the commands, the entire operation is -aborted. - -You must send syntactically correct FTP commands as RFC 959 defines to FTP -servers, or one of the commands listed below to SFTP servers. - -SFTP is a binary protocol. Unlike for FTP, curl interprets SFTP quote commands -itself before sending them to the server. File names may be quoted -shell-style to embed spaces or special characters. Following is the list of -all supported SFTP quote commands: -.RS -.TP -**"atime date file"** -The atime command sets the last access time of the file named by the file -operand. The can be all sorts of date strings, see the -*curl_getdate(3)* man page for date expression details. (Added in 7.73.0) -.TP -**"chgrp group file"** -The chgrp command sets the group ID of the file named by the file operand to -the group ID specified by the group operand. The group operand is a decimal -integer group ID. -.TP -**"chmod mode file"** -The chmod command modifies the file mode bits of the specified file. The -mode operand is an octal integer mode number. -.TP -**"chown user file"** -The chown command sets the owner of the file named by the file operand to the -user ID specified by the user operand. The user operand is a decimal -integer user ID. -.TP -**"ln source_file target_file"** -The ln and symlink commands create a symbolic link at the target_file location -pointing to the source_file location. -.TP -**"mkdir directory_name"** -The mkdir command creates the directory named by the directory_name operand. -.TP -**"mtime date file"** -The mtime command sets the last modification time of the file named by the -file operand. The can be all sorts of date strings, see the -*curl_getdate(3)* man page for date expression details. (Added in 7.73.0) -.TP -**"pwd"** -The pwd command returns the absolute path name of the current working directory. -.TP -**"rename source target"** -The rename command renames the file or directory named by the source -operand to the destination path named by the target operand. -.TP -**"rm file"** -The rm command removes the file specified by the file operand. -.TP -**"rmdir directory"** -The rmdir command removes the directory entry specified by the directory -operand, provided it is empty. -.TP -**"symlink source_file target_file"** -See ln. -.RE -.IP diff --git a/third-party/curl/docs/cmdline-opts/quote.md b/third-party/curl/docs/cmdline-opts/quote.md new file mode 100644 index 0000000000..1ac2076b74 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/quote.md @@ -0,0 +1,93 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: quote +Arg: +Short: Q +Help: Send command(s) to server before transfer +Protocols: FTP SFTP +Category: ftp sftp +Added: 5.3 +Multi: append +See-also: + - request +Example: + - --quote "DELE file" ftp://example.com/foo +--- + +# `--quote` + +Send an arbitrary command to the remote FTP or SFTP server. Quote commands are +sent BEFORE the transfer takes place (immediately after the initial **PWD** +command in an FTP transfer, to be exact). To make commands take place after a +successful transfer, prefix them with a dash '-'. + +(FTP only) To make commands be sent after curl has changed the working +directory, immediately before the file transfer command(s), prefix the command +with a '+'. + +You may specify any number of commands. + +By default curl stops at first failure. To make curl continue even if the +command fails, prefix the command with an asterisk (*). Otherwise, if the +server returns failure for one of the commands, the entire operation is +aborted. + +You must send syntactically correct FTP commands as RFC 959 defines to FTP +servers, or one of the commands listed below to SFTP servers. + +SFTP is a binary protocol. Unlike for FTP, curl interprets SFTP quote commands +itself before sending them to the server. Filenames must be provided within +double quotes to embed spaces, backslashes, quotes or double quotes. Within +double quotes the following escape sequences are available for that purpose: +\\, \", and \'. + +Following is the list of all supported SFTP quote commands: + +## atime date file +The atime command sets the last access time of the file named by the file +operand. The date expression can be all sorts of date strings, see the +*curl_getdate(3)* man page for date expression details. (Added in 7.73.0) + +## chgrp group file +The chgrp command sets the group ID of the file named by the file operand to +the group ID specified by the group operand. The group operand is a decimal +integer group ID. + +## chmod mode file +The chmod command modifies the file mode bits of the specified file. The +mode operand is an octal integer mode number. + +## chown user file +The chown command sets the owner of the file named by the file operand to the +user ID specified by the user operand. The user operand is a decimal +integer user ID. + +## ln source_file target_file +The ln and symlink commands create a symbolic link at the target_file location +pointing to the source_file location. + +## mkdir directory_name +The mkdir command creates the directory named by the directory_name operand. + +## mtime date file +The mtime command sets the last modification time of the file named by the +file operand. The date expression can be all sorts of date strings, see the +*curl_getdate(3)* man page for date expression details. (Added in 7.73.0) + +## pwd +The pwd command returns the absolute path name of the current working directory. + +## rename source target +The rename command renames the file or directory named by the source +operand to the destination path named by the target operand. + +## rm file +The rm command removes the file specified by the file operand. + +## rmdir directory +The rmdir command removes the directory entry specified by the directory +operand, provided it is empty. + +## symlink source_file target_file +See ln. diff --git a/third-party/curl/docs/cmdline-opts/random-file.d b/third-party/curl/docs/cmdline-opts/random-file.d deleted file mode 100644 index aa076de7fc..0000000000 --- a/third-party/curl/docs/cmdline-opts/random-file.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: random-file -Arg: -Help: File for reading random data from -Category: misc -Example: --random-file rubbish $URL -Added: 7.7 -See-also: egd-file -Multi: single ---- -Deprecated option. This option is ignored (added in 7.84.0). Prior to that it -only had an effect on curl if built to use old versions of OpenSSL. - -Specify the path name to file containing random data. The data may be used to -seed the random engine for SSL connections. diff --git a/third-party/curl/docs/cmdline-opts/random-file.md b/third-party/curl/docs/cmdline-opts/random-file.md new file mode 100644 index 0000000000..e2c8624abf --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/random-file.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: random-file +Arg: +Help: File for reading random data from +Category: deprecated +Added: 7.7 +Multi: single +See-also: + - egd-file +Example: + - --random-file rubbish $URL +--- + +# `--random-file` + +Deprecated option. This option is ignored (added in 7.84.0). Prior to that it +only had an effect on curl if built to use old versions of OpenSSL. + +Specify the path name to file containing random data. The data may be used to +seed the random engine for SSL connections. diff --git a/third-party/curl/docs/cmdline-opts/range.d b/third-party/curl/docs/cmdline-opts/range.d deleted file mode 100644 index eba7220e1e..0000000000 --- a/third-party/curl/docs/cmdline-opts/range.d +++ /dev/null @@ -1,50 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: range -Short: r -Help: Retrieve only the bytes within RANGE -Arg: -Protocols: HTTP FTP SFTP FILE -Category: http ftp sftp file -Example: --range 22-44 $URL -Added: 4.0 -See-also: continue-at append -Multi: single ---- -Retrieve a byte range (i.e. a partial document) from an HTTP/1.1, FTP or SFTP -server or a local FILE. Ranges can be specified in a number of ways. -.RS -.TP 10 -.B 0-499 -specifies the first 500 bytes -.TP -.B 500-999 -specifies the second 500 bytes -.TP -.B -500 -specifies the last 500 bytes -.TP -.B 9500- -specifies the bytes from offset 9500 and forward -.TP -.B 0-0,-1 -specifies the first and last byte only(*)(HTTP) -.TP -.B 100-199,500-599 -specifies two separate 100-byte ranges(*) (HTTP) -.RE -.IP -(*) = NOTE that this causes the server to reply with a multipart response, -which is returned as-is by curl! Parsing or otherwise transforming this -response is the responsibility of the caller. - -Only digit characters (0-9) are valid in the 'start' and 'stop' fields of the -'start-stop' range syntax. If a non-digit character is given in the range, the -server's response is unspecified, depending on the server's configuration. - -Many HTTP/1.1 servers do not have this feature enabled, so that when you -attempt to get a range, curl instead gets the whole document. - -FTP and SFTP range downloads only support the simple 'start-stop' syntax -(optionally with one of the numbers omitted). FTP use depends on the extended -FTP command SIZE. diff --git a/third-party/curl/docs/cmdline-opts/range.md b/third-party/curl/docs/cmdline-opts/range.md new file mode 100644 index 0000000000..ab1b126575 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/range.md @@ -0,0 +1,66 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: range +Short: r +Help: Retrieve only the bytes within RANGE +Arg: +Protocols: HTTP FTP SFTP FILE +Category: http ftp sftp file +Added: 4.0 +Multi: single +See-also: + - continue-at + - append +Example: + - --range 22-44 $URL +--- + +# `--range` + +Retrieve a byte range (i.e. a partial document) from an HTTP/1.1, FTP or SFTP +server or a local FILE. Ranges can be specified in a number of ways. + +## 0-499 +specifies the first 500 bytes + +## 500-999 +specifies the second 500 bytes + +## -500 +specifies the last 500 bytes + +## 9500- +specifies the bytes from offset 9500 and forward + +## 0-0,-1 +specifies the first and last byte only(*)(HTTP) + +## 100-199,500-599 +specifies two separate 100-byte ranges(*) (HTTP) + +## + +(*) = NOTE that if specifying multiple ranges and the server supports it then +it replies with a multiple part response that curl returns as-is. It +contains meta information in addition to the requested bytes. Parsing or +otherwise transforming this response is the responsibility of the caller. + +Only digit characters (0-9) are valid in the 'start' and 'stop' fields of the +'start-stop' range syntax. If a non-digit character is given in the range, the +server's response is unspecified, depending on the server's configuration. + +Many HTTP/1.1 servers do not have this feature enabled, so that when you +attempt to get a range, curl instead gets the whole document. + +FTP and SFTP range downloads only support the simple 'start-stop' syntax +(optionally with one of the numbers omitted). FTP use depends on the extended +FTP command SIZE. + +When using this option for HTTP uploads using POST or PUT, functionality is +not guaranteed. The HTTP protocol has no standard interoperable resume upload +and curl uses a set of headers for this purpose that once proved working for +some servers and have been left for those who find that useful. + +This command line option is mutually exclusive with --continue-at: you can only +use one of them for a single transfer. diff --git a/third-party/curl/docs/cmdline-opts/rate.d b/third-party/curl/docs/cmdline-opts/rate.d deleted file mode 100644 index d3cbd2849d..0000000000 --- a/third-party/curl/docs/cmdline-opts/rate.d +++ /dev/null @@ -1,35 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: rate -Arg: -Help: Request rate for serial transfers -Category: connection -Example: --rate 2/s $URL ... -Example: --rate 3/h $URL ... -Example: --rate 14/m $URL ... -Added: 7.84.0 -See-also: limit-rate retry-delay -Multi: single -Scope: global ---- -Specify the maximum transfer frequency you allow curl to use - in number of -transfer starts per time unit (sometimes called request rate). Without this -option, curl starts the next transfer as fast as possible. - -If given several URLs and a transfer completes faster than the allowed rate, -curl waits until the next transfer is started to maintain the requested -rate. This option has no effect when --parallel is used. - -The request rate is provided as "N/U" where N is an integer number and U is a -time unit. Supported units are 's' (second), 'm' (minute), 'h' (hour) and 'd' -/(day, as in a 24 hour unit). The default time unit, if no "/U" is provided, -is number of transfers per hour. - -If curl is told to allow 10 requests per minute, it does not start the next -request until 6 seconds have elapsed since the previous transfer was started. - -This function uses millisecond resolution. If the allowed frequency is set -more than 1000 per second, it instead runs unrestricted. - -When retrying transfers, enabled with --retry, the separate retry delay logic -is used and not this setting. diff --git a/third-party/curl/docs/cmdline-opts/rate.md b/third-party/curl/docs/cmdline-opts/rate.md new file mode 100644 index 0000000000..d389da5747 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/rate.md @@ -0,0 +1,46 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: rate +Arg: +Help: Request rate for serial transfers +Category: connection global +Added: 7.84.0 +Multi: single +Scope: global +See-also: + - limit-rate + - retry-delay +Example: + - --rate 2/s $URL ... + - --rate 3/h $URL ... + - --rate 14/m $URL ... +--- + +# `--rate` + +Specify the maximum transfer frequency you allow curl to use - in number of +transfer starts per time unit (sometimes called request rate). Without this +option, curl starts the next transfer as fast as possible. + +If given several URLs and a transfer completes faster than the allowed rate, +curl waits until the next transfer is started to maintain the requested +rate. This option has no effect when --parallel is used. + +The request rate is provided as "N/U" where N is an integer number and U is a +time unit. Supported units are 's' (second), 'm' (minute), 'h' (hour) and 'd' +/(day, as in a 24 hour unit). The default time unit, if no "/U" is provided, +is number of transfers per hour. + +If curl is told to allow 10 requests per minute, it does not start the next +request until 6 seconds have elapsed since the previous transfer was started. + +This function uses millisecond resolution. If the allowed frequency is set +more than 1000 per second, it instead runs unrestricted. + +When retrying transfers, enabled with --retry, the separate retry delay logic +is used and not this setting. + +Starting in version 8.10.0, you can specify the number of time units in the rate +expression. Make curl do no more than 5 transfers per 15 seconds with "5/15s" +or limit it to 3 transfers per 4 hours with "3/4h". No spaces allowed. diff --git a/third-party/curl/docs/cmdline-opts/raw.d b/third-party/curl/docs/cmdline-opts/raw.d deleted file mode 100644 index 0523d62fab..0000000000 --- a/third-party/curl/docs/cmdline-opts/raw.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: raw -Help: Do HTTP "raw"; no transfer decoding -Added: 7.16.2 -Protocols: HTTP -Category: http -Example: --raw $URL -See-also: tr-encoding -Multi: boolean ---- -When used, it disables all internal HTTP decoding of content or transfer -encodings and instead makes them passed on unaltered, raw. diff --git a/third-party/curl/docs/cmdline-opts/raw.md b/third-party/curl/docs/cmdline-opts/raw.md new file mode 100644 index 0000000000..ca63dc318c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/raw.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: raw +Help: Do HTTP raw; no transfer decoding +Added: 7.16.2 +Protocols: HTTP +Category: http +Multi: boolean +See-also: + - tr-encoding +Example: + - --raw $URL +--- + +# `--raw` + +When used, it disables all internal HTTP decoding of content or transfer +encodings and instead makes them passed on unaltered, raw. diff --git a/third-party/curl/docs/cmdline-opts/referer.d b/third-party/curl/docs/cmdline-opts/referer.d deleted file mode 100644 index 0609e8c997..0000000000 --- a/third-party/curl/docs/cmdline-opts/referer.d +++ /dev/null @@ -1,20 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: referer -Short: e -Arg: -Protocols: HTTP -Help: Referrer URL -See-also: user-agent header -Category: http -Example: --referer "https://fake.example" $URL -Example: --referer "https://fake.example;auto" -L $URL -Example: --referer ";auto" -L $URL -Added: 4.0 -Multi: single ---- -Sends the "Referrer Page" information to the HTTP server. This can also be set -with the --header flag of course. When used with --location you can append -";auto" to the --referer URL to make curl automatically set the previous URL -when it follows a Location: header. The ";auto" string can be used alone, -even if you do not set an initial --referer. diff --git a/third-party/curl/docs/cmdline-opts/referer.md b/third-party/curl/docs/cmdline-opts/referer.md new file mode 100644 index 0000000000..1fec248501 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/referer.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: referer +Short: e +Arg: +Protocols: HTTP +Help: Referrer URL +Category: http +Added: 4.0 +Multi: single +See-also: + - user-agent + - header +Example: + - --referer "https://fake.example" $URL + - --referer "https://fake.example;auto" -L $URL + - --referer ";auto" -L $URL +--- + +# `--referer` + +Set the referrer URL in the HTTP request. This can also be set with the +--header flag of course. When used with --location you can append `;auto`" to +the --referer URL to make curl automatically set the previous URL when it +follows a Location: header. The `;auto` string can be used alone, even if you +do not set an initial --referer. diff --git a/third-party/curl/docs/cmdline-opts/remote-header-name.d b/third-party/curl/docs/cmdline-opts/remote-header-name.d deleted file mode 100644 index 917fe7abf2..0000000000 --- a/third-party/curl/docs/cmdline-opts/remote-header-name.d +++ /dev/null @@ -1,34 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: remote-header-name -Short: J -Protocols: HTTP -Help: Use the header-provided filename -Category: output -Example: -OJ https://example.com/file -Added: 7.20.0 -See-also: remote-name -Multi: boolean ---- -This option tells the --remote-name option to use the server-specified -Content-Disposition filename instead of extracting a filename from the URL. If -the server-provided file name contains a path, that is stripped off before the -file name is used. - -The file is saved in the current directory, or in the directory specified with ---output-dir. - -If the server specifies a file name and a file with that name already exists -in the destination directory, it is not overwritten and an error occurs - -unless you allow it by using the --clobber option. If the server does not -specify a file name then this option has no effect. - -There is no attempt to decode %-sequences (yet) in the provided file name, so -this option may provide you with rather unexpected file names. - -This feature uses the name from the "filename" field, it does not yet support -the "filename*" field (filenames with explicit character sets). - -**WARNING**: Exercise judicious use of this option, especially on Windows. A -rogue server could send you the name of a DLL or other file that could be -loaded automatically by Windows or some third party software. diff --git a/third-party/curl/docs/cmdline-opts/remote-header-name.md b/third-party/curl/docs/cmdline-opts/remote-header-name.md new file mode 100644 index 0000000000..52ae98b01c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/remote-header-name.md @@ -0,0 +1,42 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: remote-header-name +Short: J +Protocols: HTTP +Help: Use the header-provided filename +Category: output +Added: 7.20.0 +Multi: boolean +See-also: + - remote-name +Example: + - -OJ https://example.com/file +--- + +# `--remote-header-name` + +Tell the --remote-name option to use the server-specified Content-Disposition +filename instead of extracting a filename from the URL. If the server-provided +filename contains a path, that is stripped off before the filename is used. + +The file is saved in the current directory, or in the directory specified with +--output-dir. + +If the server specifies a filename and a file with that name already exists in +the destination directory, it is not overwritten and an error occurs - unless +you allow it by using the --clobber option. If the server does not specify a +filename then this option has no effect. + +There is no attempt to decode %-sequences (yet) in the provided filename, so +this option may provide you with rather unexpected filenames. + +This feature uses the name from the `filename` field, it does not yet support +the `filename*` field (filenames with explicit character sets). + +Starting in 8.19.0, curl falls back and uses the filename extracted from the +last redirect header if no `Content-Disposition:` header provides a filename. + +**WARNING**: Exercise judicious use of this option, especially on Windows. A +rogue server could send you the name of a DLL or other file that could be +loaded automatically by Windows or some third party software. diff --git a/third-party/curl/docs/cmdline-opts/remote-name-all.d b/third-party/curl/docs/cmdline-opts/remote-name-all.d deleted file mode 100644 index 249c4e265f..0000000000 --- a/third-party/curl/docs/cmdline-opts/remote-name-all.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: remote-name-all -Help: Use the remote file name for all URLs -Added: 7.19.0 -Category: output -Example: --remote-name-all ftp://example.com/file1 ftp://example.com/file2 -See-also: remote-name -Multi: boolean ---- -This option changes the default action for all given URLs to be dealt with as -if --remote-name were used for each one. So if you want to disable that for a -specific URL after --remote-name-all has been used, you must use "-o -" or ---no-remote-name. diff --git a/third-party/curl/docs/cmdline-opts/remote-name-all.md b/third-party/curl/docs/cmdline-opts/remote-name-all.md new file mode 100644 index 0000000000..92d348e27c --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/remote-name-all.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: remote-name-all +Help: Use the remote filename for all URLs +Added: 7.19.0 +Category: output +Multi: boolean +See-also: + - remote-name +Example: + - --remote-name-all ftp://example.com/file1 ftp://example.com/file2 +--- + +# `--remote-name-all` + +Change the default action for all given URLs to be dealt with as if +--remote-name were used for each one. If you want to disable that for a +specific URL after --remote-name-all has been used, you must use "-o -" or +--no-remote-name. diff --git a/third-party/curl/docs/cmdline-opts/remote-name.d b/third-party/curl/docs/cmdline-opts/remote-name.d deleted file mode 100644 index 215cf72deb..0000000000 --- a/third-party/curl/docs/cmdline-opts/remote-name.d +++ /dev/null @@ -1,28 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: remote-name -Short: O -Help: Write output to a file named as the remote file -Category: important output -Example: -O https://example.com/filename -Added: 4.0 -See-also: remote-name-all output-dir remote-header-name -Multi: append ---- -Write output to a local file named like the remote file we get. (Only the file -part of the remote file is used, the path is cut off.) - -The file is saved in the current working directory. If you want the file saved -in a different directory, make sure you change the current working directory -before invoking curl with this option or use --output-dir. - -The remote file name to use for saving is extracted from the given URL, -nothing else, and if it already exists it is overwritten. If you want the -server to be able to choose the file name refer to --remote-header-name which -can be used in addition to this option. If the server chooses a file name and -that name already exists it is not overwritten. - -There is no URL decoding done on the file name. If it has %20 or other URL -encoded parts of the name, they end up as-is as file name. - -You may use this option as many times as the number of URLs you have. diff --git a/third-party/curl/docs/cmdline-opts/remote-name.md b/third-party/curl/docs/cmdline-opts/remote-name.md new file mode 100644 index 0000000000..e39dd51aea --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/remote-name.md @@ -0,0 +1,42 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: remote-name +Short: O +Help: Write output to file named as remote file +Category: important output +Added: 4.0 +Multi: per-URL +See-also: + - remote-name-all + - output-dir + - remote-header-name +Example: + - -O https://example.com/filename + - -O https://example.com/filename -O https://example.com/file2 +--- + +# `--remote-name` + +Write output to a local file named like the remote file we get. (Only the file +part of the remote file is used, the path is cut off.) + +The file is saved in the current working directory. If you want the file saved +in a different directory, make sure you change the current working directory +before invoking curl with this option or use --output-dir. + +The remote filename to use for saving is extracted from the given URL, nothing +else, and if it already exists it is overwritten. If you want the server to be +able to choose the filename refer to --remote-header-name which can be used in +addition to this option. If the server chooses a filename and that name +already exists it is not overwritten. + +There is no URL decoding done on the filename. If it has %20 or other URL +encoded parts of the name, they end up as-is as filename. + +You may use this option as many times as the number of URLs you have. + +Before curl 8.10.0, curl returned an error if the URL ended with a slash, +which means that there is no filename part in the URL. Starting in 8.10.0, +curl sets the filename to the last directory part of the URL or if that also +is missing to `curl_response` (without extension) for this situation. diff --git a/third-party/curl/docs/cmdline-opts/remote-time.d b/third-party/curl/docs/cmdline-opts/remote-time.d deleted file mode 100644 index 6dfb26c491..0000000000 --- a/third-party/curl/docs/cmdline-opts/remote-time.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: remote-time -Short: R -Help: Set the remote file's time on the local output -Category: output -Example: --remote-time -o foo $URL -Added: 7.9 -See-also: remote-name time-cond -Multi: boolean ---- -Makes curl attempt to figure out the timestamp of the remote file that is -getting downloaded, and if that is available make the local file get that same -timestamp. diff --git a/third-party/curl/docs/cmdline-opts/remote-time.md b/third-party/curl/docs/cmdline-opts/remote-time.md new file mode 100644 index 0000000000..3f8c702b45 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/remote-time.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: remote-time +Short: R +Help: Set remote file's time on local output +Category: output +Added: 7.9 +Multi: boolean +See-also: + - remote-name + - time-cond +Example: + - --remote-time -o foo $URL +--- + +# `--remote-time` + +Make curl attempt to figure out the timestamp of the remote file that is +getting downloaded, and if that is available make the local file get that same +timestamp. diff --git a/third-party/curl/docs/cmdline-opts/remove-on-error.d b/third-party/curl/docs/cmdline-opts/remove-on-error.d deleted file mode 100644 index 50b7b1b65c..0000000000 --- a/third-party/curl/docs/cmdline-opts/remove-on-error.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: remove-on-error -Help: Remove output file on errors -See-also: fail -Category: curl -Example: --remove-on-error -o output $URL -Added: 7.83.0 -Multi: boolean ---- -When curl returns an error when told to save output in a local file, this -option removes that saved file before exiting. This prevents curl from -leaving a partial file in the case of an error during transfer. - -If the output is not a file, this option has no effect. diff --git a/third-party/curl/docs/cmdline-opts/remove-on-error.md b/third-party/curl/docs/cmdline-opts/remove-on-error.md new file mode 100644 index 0000000000..ec7b88882b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/remove-on-error.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: remove-on-error +Help: Remove output file on errors +Category: output +Added: 7.83.0 +Multi: boolean +See-also: + - fail +Example: + - --remove-on-error -o output $URL +--- + +# `--remove-on-error` + +Remove the output file if an error occurs. If curl returns an error when told to +save output in a local file. This prevents curl from leaving a partial file in +the case of an error during transfer. + +If the output is not a regular file, this option has no effect. + +The --continue-at option cannot be used together with --remove-on-error. diff --git a/third-party/curl/docs/cmdline-opts/request-target.d b/third-party/curl/docs/cmdline-opts/request-target.d deleted file mode 100644 index 61ead5f2b0..0000000000 --- a/third-party/curl/docs/cmdline-opts/request-target.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: request-target -Arg: -Help: Specify the target for this request -Protocols: HTTP -Added: 7.55.0 -Category: http -Example: --request-target "*" -X OPTIONS $URL -See-also: request -Multi: single ---- -Tells curl to use an alternative "target" (path) instead of using the path as -provided in the URL. Particularly useful when wanting to issue HTTP requests -without leading slash or other data that does not follow the regular URL -pattern, like "OPTIONS *". diff --git a/third-party/curl/docs/cmdline-opts/request-target.md b/third-party/curl/docs/cmdline-opts/request-target.md new file mode 100644 index 0000000000..c76b6b34de --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/request-target.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: request-target +Arg: +Help: Specify the target for this request +Protocols: HTTP +Added: 7.55.0 +Category: http +Multi: single +See-also: + - request +Example: + - --request-target "*" -X OPTIONS $URL +--- + +# `--request-target` + +Use an alternative target (path) instead of using the path as provided in the +URL. Particularly useful when wanting to issue HTTP requests without leading +slash or other data that does not follow the regular URL pattern, like +"OPTIONS *". + +curl passes on the verbatim string you give it in the request without any +filter or other safe guards. That includes white space and control characters. diff --git a/third-party/curl/docs/cmdline-opts/request.d b/third-party/curl/docs/cmdline-opts/request.d deleted file mode 100644 index 0020babf91..0000000000 --- a/third-party/curl/docs/cmdline-opts/request.d +++ /dev/null @@ -1,51 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: request -Short: X -Arg: -Help: Specify request method to use -Category: connection -Example: -X "DELETE" $URL -Example: -X NLST ftp://example.com/ -Added: 6.0 -See-also: request-target -Multi: single ---- -Change the method to use when starting the transfer. -.RS -.TP 15 -**HTTP** -Specifies a custom request method to use when communicating with the HTTP -server. The specified request method is used instead of the method otherwise -used (which defaults to *GET*). Read the HTTP 1.1 specification for details -and explanations. Common additional HTTP requests include *PUT* and *DELETE*, -but related technologies like WebDAV offers *PROPFIND*, *COPY*, *MOVE* and -more. - -Normally you do not need this option. All sorts of *GET*, *HEAD*, *POST* and -*PUT* requests are rather invoked by using dedicated command line options. - -This option only changes the actual word used in the HTTP request, it does not -alter the way curl behaves. So for example if you want to make a proper HEAD -request, using -X HEAD does not suffice. You need to use the --head option. - -The method string you set with --request is used for all requests, which -if you for example use --location may cause unintended side-effects when curl -does not change request method according to the HTTP 30x response codes - and -similar. -.TP -**FTP** -Specifies a custom FTP command to use instead of *LIST* when doing file lists -with FTP. -.TP -**POP3** -Specifies a custom POP3 command to use instead of *LIST* or *RETR*. -(Added in 7.26.0) -.TP -**IMAP** -Specifies a custom IMAP command to use instead of *LIST*. (Added in 7.30.0) -.TP -**SMTP** -Specifies a custom SMTP command to use instead of *HELP* or **VRFY**. (Added in 7.34.0) -.RE -.IP diff --git a/third-party/curl/docs/cmdline-opts/request.md b/third-party/curl/docs/cmdline-opts/request.md new file mode 100644 index 0000000000..2c9d7776e5 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/request.md @@ -0,0 +1,58 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: request +Short: X +Arg: +Help: Specify request method to use +Category: connection pop3 ftp imap smtp +Added: 6.0 +Multi: single +See-also: + - request-target + - follow +Example: + - --request "DELETE" $URL + - -X NLST ftp://example.com/ +--- + +# `--request` + +Change the method to use when starting the transfer. + +curl passes on the verbatim string you give it in the request without any +filter or other safe guards. That includes white space and control characters. + +## HTTP +Specifies a custom request method to use when communicating with the HTTP +server. The specified request method is used instead of the method otherwise +used (which defaults to *GET*). Read the HTTP 1.1 specification for details +and explanations. Common additional HTTP requests include *PUT* and *DELETE*, +while related technologies like WebDAV offers *PROPFIND*, *COPY*, *MOVE* and +more. + +Normally you do not need this option. All sorts of *GET*, *HEAD*, *POST* and +*PUT* requests are rather invoked by using dedicated command line options. + +This option only changes the actual word used in the HTTP request, it does not +alter the way curl behaves. For example if you want to make a proper HEAD +request, using -X HEAD does not suffice. You need to use the --head option. + +If --location is used, the method string you set with --request is used for +all requests, which may cause unintended side-effects when curl does not +change request method according to the HTTP 30x response codes - and similar. +Consider using --follow instead in combination with --request. + +## FTP +Specifies a custom FTP command to use instead of *LIST* when doing file lists +with FTP. + +## POP3 +Specifies a custom POP3 command to use instead of *LIST* or *RETR*. +(Added in 7.26.0) + +## IMAP +Specifies a custom IMAP command to use instead of *LIST*. (Added in 7.30.0) + +## SMTP +Specifies a custom SMTP command to use instead of *HELP* or **VRFY**. (Added in 7.34.0) diff --git a/third-party/curl/docs/cmdline-opts/resolve.d b/third-party/curl/docs/cmdline-opts/resolve.d deleted file mode 100644 index 31dd099a2f..0000000000 --- a/third-party/curl/docs/cmdline-opts/resolve.d +++ /dev/null @@ -1,41 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: resolve -Arg: <[+]host:port:addr[,addr]...> -Help: Resolve the host+port to this address -Added: 7.21.3 -Category: connection dns -Example: --resolve example.com:443:127.0.0.1 $URL -See-also: connect-to alt-svc -Multi: append ---- -Provide a custom address for a specific host and port pair. Using this, you -can make the curl requests(s) use a specified address and prevent the -otherwise normally resolved address to be used. Consider it a sort of -/etc/hosts alternative provided on the command line. The port number should be -the number used for the specific protocol the host is used for. It means -you need several entries if you want to provide address for the same host but -different ports. - -By specifying '*' as host you can tell curl to resolve any host and specific -port pair to the specified address. Wildcard is resolved last so any --resolve -with a specific host and port is used first. - -The provided address set by this option is used even if --ipv4 or --ipv6 is -set to make curl use another IP version. - -By prefixing the host with a '+' you can make the entry time out after curl's -default timeout (1 minute). Note that this only makes sense for long running -parallel transfers with a lot of files. In such cases, if this option is used -curl tries to resolve the host as it normally would once the timeout has -expired. - -Support for providing the IP address within [brackets] was added in 7.57.0. - -Support for providing multiple IP addresses per entry was added in 7.59.0. - -Support for resolving with wildcard was added in 7.64.0. - -Support for the '+' prefix was was added in 7.75.0. - -This option can be used many times to add many host names to resolve. diff --git a/third-party/curl/docs/cmdline-opts/resolve.md b/third-party/curl/docs/cmdline-opts/resolve.md new file mode 100644 index 0000000000..18733df0c2 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/resolve.md @@ -0,0 +1,50 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: resolve +Arg: <[+]host:port:addr[,addr]...> +Help: Resolve host+port to address +Added: 7.21.3 +Category: connection dns +Multi: append +See-also: + - connect-to + - alt-svc +Example: + - --resolve example.com:443:127.0.0.1 $URL + - --resolve example.com:443:[2001:db8::252f:efd6] $URL +--- + +# `--resolve` + +Provide a custom address for a specific host and port pair. Using this, you +can make the curl requests(s) use a specified address and prevent the +otherwise normally resolved address to be used. Consider it a sort of +/etc/hosts alternative provided on the command line. The port number should be +the number used for the specific protocol the host is used for. It means you +need several entries if you want to provide addresses for the same host but +different ports. + +By specifying `*` as host you can tell curl to resolve any host and specific +port pair to the specified address. Wildcard is resolved last so any --resolve +with a specific host and port is used first. + +The provided address set by this option is used even if --ipv4 or --ipv6 is +set to make curl use another IP version. + +By prefixing the host with a '+' you can make the entry time out after curl's +default timeout (1 minute). Note that this only makes sense for long running +parallel transfers with a lot of files. In such cases, if this option is used +curl tries to resolve the host as it normally would once the timeout has +expired. + +Provide IPv6 addresses within [brackets]. + +To redirect connects from a specific hostname or any hostname, independently +of port number, consider the --connect-to option. + +Support for resolving with wildcard was added in 7.64.0. + +Support for the '+' prefix was added in 7.75.0. + +Support for specifying the host component as an IPv6 address was added in 8.13.0. diff --git a/third-party/curl/docs/cmdline-opts/retry-all-errors.d b/third-party/curl/docs/cmdline-opts/retry-all-errors.d deleted file mode 100644 index 1190d6a3ae..0000000000 --- a/third-party/curl/docs/cmdline-opts/retry-all-errors.d +++ /dev/null @@ -1,34 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: retry-all-errors -Help: Retry all errors (use with --retry) -Added: 7.71.0 -Category: curl -Example: --retry 5 --retry-all-errors $URL -See-also: retry -Multi: boolean ---- -Retry on any error. This option is used together with --retry. - -This option is the "sledgehammer" of retrying. Do not use this option by -default (for example in your **curlrc**), there may be unintended consequences -such as sending or receiving duplicate data. Do not use with redirected input -or output. You'd be much better off handling your unique problems in shell -script. Please read the example below. - -**WARNING**: For server compatibility curl attempts to retry failed flaky -transfers as close as possible to how they were started, but this is not -possible with redirected input or output. For example, before retrying it -removes output data from a failed partial transfer that was written to an -output file. However this is not true of data redirected to a | pipe or > -file, which are not reset. We strongly suggest you do not parse or record -output via redirect in combination with this option, since you may receive -duplicate data. - -By default curl does not return error for transfers with an HTTP response code -that indicates an HTTP error, if the transfer was successful. For example, if -a server replies 404 Not Found and the reply is fully received then that is -not an error. When --retry is used then curl retries on some HTTP response -codes that indicate transient HTTP errors, but that does not include most 4xx -response codes such as 404. If you want to retry on all response codes that -indicate HTTP errors (4xx and 5xx) then combine with --fail. diff --git a/third-party/curl/docs/cmdline-opts/retry-all-errors.md b/third-party/curl/docs/cmdline-opts/retry-all-errors.md new file mode 100644 index 0000000000..cb337f3f16 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/retry-all-errors.md @@ -0,0 +1,40 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: retry-all-errors +Help: Retry all errors (with --retry) +Added: 7.71.0 +Category: curl +Multi: boolean +See-also: + - retry +Example: + - --retry 5 --retry-all-errors $URL +--- + +# `--retry-all-errors` + +Retry on any error. This option is used together with --retry. + +This option is the "sledgehammer" of retrying. Do not use this option by +default (for example in your **curlrc**), there may be unintended consequences +such as sending or receiving duplicate data. Do not use with redirected input +or output. You might be better off handling your unique problems in a shell +script. Please read the example below. + +**WARNING**: For server compatibility curl attempts to retry failed flaky +transfers as close as possible to how they were started, but this is not +possible with redirected input or output. For example, before retrying it +removes output data from a failed partial transfer that was written to an +output file. However this is not true of data redirected to a | pipe or \> +file, which are not reset. We strongly suggest you do not parse or record +output via redirect in combination with this option, since you may receive +duplicate data. + +By default curl does not return an error for transfers with an HTTP response code +that indicates an HTTP error, if the transfer was successful. For example, if +a server replies 404 Not Found and the reply is fully received then that is +not an error. When --retry is used then curl retries on some HTTP response +codes that indicate transient HTTP errors, but that does not include most 4xx +response codes such as 404. If you want to retry on all response codes that +indicate HTTP errors (4xx and 5xx) then combine with --fail. diff --git a/third-party/curl/docs/cmdline-opts/retry-connrefused.d b/third-party/curl/docs/cmdline-opts/retry-connrefused.d deleted file mode 100644 index a7b9643ce2..0000000000 --- a/third-party/curl/docs/cmdline-opts/retry-connrefused.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: retry-connrefused -Help: Retry on connection refused (use with --retry) -Added: 7.52.0 -Category: curl -Example: --retry-connrefused --retry 7 $URL -See-also: retry retry-all-errors -Multi: boolean ---- -In addition to the other conditions, consider ECONNREFUSED as a transient -error too for --retry. This option is used together with --retry. diff --git a/third-party/curl/docs/cmdline-opts/retry-connrefused.md b/third-party/curl/docs/cmdline-opts/retry-connrefused.md new file mode 100644 index 0000000000..c7f96a8fee --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/retry-connrefused.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: retry-connrefused +Help: Retry on connection refused (with --retry) +Added: 7.52.0 +Category: curl +Multi: boolean +See-also: + - retry + - retry-all-errors +Example: + - --retry-connrefused --retry 7 $URL +--- + +# `--retry-connrefused` + +In addition to the other conditions, also consider ECONNREFUSED as a transient +error for --retry. This option is used together with --retry. Normally, a +refused connection is not considered a transient error and therefore would not +otherwise trigger a retry. diff --git a/third-party/curl/docs/cmdline-opts/retry-delay.d b/third-party/curl/docs/cmdline-opts/retry-delay.d deleted file mode 100644 index 686a0d8ba4..0000000000 --- a/third-party/curl/docs/cmdline-opts/retry-delay.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: retry-delay -Arg: -Help: Wait time between retries -Added: 7.12.3 -Category: curl -Example: --retry-delay 5 --retry 7 $URL -See-also: retry -Multi: single ---- -Make curl sleep this amount of time before each retry when a transfer has -failed with a transient error (it changes the default backoff time algorithm -between retries). This option is only interesting if --retry is also -used. Setting this delay to zero makes curl use the default backoff time. diff --git a/third-party/curl/docs/cmdline-opts/retry-delay.md b/third-party/curl/docs/cmdline-opts/retry-delay.md new file mode 100644 index 0000000000..dbc78e00d8 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/retry-delay.md @@ -0,0 +1,28 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: retry-delay +Arg: +Help: Wait time between retries +Added: 7.12.3 +Category: curl timeout +Multi: single +See-also: + - retry + - retry-max-time +Example: + - --retry-delay 5 --retry 7 $URL +--- + +# `--retry-delay` + +Make curl sleep this amount of time before each retry when a transfer has +failed with a transient error (it changes the default backoff time algorithm +between retries). This option is only interesting if --retry is also +used. Setting this delay to zero makes curl use the default backoff time. + +By default, curl uses an exponentially increasing timeout between retries. + +Starting in curl 8.16.0, this option accepts a time as decimal number for parts +of seconds. The decimal value needs to be provided using a dot (.) as decimal +separator - not the local version even if it might be using another separator. diff --git a/third-party/curl/docs/cmdline-opts/retry-max-time.d b/third-party/curl/docs/cmdline-opts/retry-max-time.d deleted file mode 100644 index de2aff9a80..0000000000 --- a/third-party/curl/docs/cmdline-opts/retry-max-time.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: retry-max-time -Arg: -Help: Retry only within this period -Added: 7.12.3 -Category: curl -Example: --retry-max-time 30 --retry 10 $URL -See-also: retry -Multi: single ---- -The retry timer is reset before the first transfer attempt. Retries are done -as usual (see --retry) as long as the timer has not reached this given -limit. Notice that if the timer has not reached the limit, the request is -made and while performing, it may take longer than this given time period. To -limit a single request's maximum time, use --max-time. Set this option to zero -to not timeout retries. diff --git a/third-party/curl/docs/cmdline-opts/retry-max-time.md b/third-party/curl/docs/cmdline-opts/retry-max-time.md new file mode 100644 index 0000000000..45c141fb7f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/retry-max-time.md @@ -0,0 +1,38 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: retry-max-time +Arg: +Help: Retry only within this period +Added: 7.12.3 +Category: curl timeout +Multi: single +See-also: + - retry + - retry-delay +Example: + - --retry-max-time 30 --retry 10 $URL +--- + +# `--retry-max-time` + +The retry timer is reset before the first transfer attempt. Retries are done +as usual (see --retry) as long as the timer has not reached this given limit. +Notice that if the timer has not reached the limit, the request is made and +while performing, it may take longer than this given time period. To limit a +single request's maximum time, use --max-time. Set this option to zero to not +timeout retries. + +The retry timer starts immediately before the first transfer attempt and +includes time spent sleeping between retries (such as delays defined by +--retry-delay). Before each new retry is started, curl checks whether the +elapsed time has reached the specified limit. If it has, no further retries are +performed. + +A transfer that has already started is allowed to run to completion even if +this makes the total wall clock time exceed the limit. Use --max-time to also +cap the duration of each individual transfer attempt. + +Starting in curl 8.16.0, this option accepts a time as decimal number for parts +of seconds. The decimal value needs to be provided using a dot (.) as decimal +separator - not the local version even if it might be using another separator. diff --git a/third-party/curl/docs/cmdline-opts/retry.d b/third-party/curl/docs/cmdline-opts/retry.d deleted file mode 100644 index d49a0cdfb4..0000000000 --- a/third-party/curl/docs/cmdline-opts/retry.d +++ /dev/null @@ -1,25 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: retry -Arg: -Added: 7.12.3 -Help: Retry request if transient problems occur -Category: curl -Example: --retry 7 $URL -See-also: retry-max-time -Multi: single ---- -If a transient error is returned when curl tries to perform a transfer, it -retries this number of times before giving up. Setting the number to 0 -makes curl do no retries (which is the default). Transient error means either: -a timeout, an FTP 4xx response code or an HTTP 408, 429, 500, 502, 503 or 504 -response code. - -When curl is about to retry a transfer, it first waits one second and then for -all forthcoming retries it doubles the waiting time until it reaches 10 -minutes which then remains delay between the rest of the retries. By using ---retry-delay you disable this exponential backoff algorithm. See also ---retry-max-time to limit the total time allowed for retries. - -curl complies with the Retry-After: response header if one was present to know -when to issue the next retry (added in 7.66.0). diff --git a/third-party/curl/docs/cmdline-opts/retry.md b/third-party/curl/docs/cmdline-opts/retry.md new file mode 100644 index 0000000000..4d9e83cd5f --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/retry.md @@ -0,0 +1,34 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: retry +Arg: +Added: 7.12.3 +Help: Retry request if transient problems occur +Category: curl +Multi: single +See-also: + - retry-max-time + - retry-connrefused + - retry-delay +Example: + - --retry 7 $URL +--- + +# `--retry` + +If a transient error is returned when curl tries to perform a transfer, it +retries this number of times before giving up. Setting the number to 0 makes +curl do no retries (which is the default). Transient error means either: a +timeout, an FTP 4xx response code or an HTTP 408, 429, 500, 502, 503, 504, 522 +or 524 response code. + +When curl is about to retry a transfer, it first waits one second and then for +all forthcoming retries it doubles the waiting time until it reaches 10 +minutes, which then remains the set fixed delay time between the rest of the +retries. By using --retry-delay you disable this exponential backoff +algorithm. See also --retry-max-time to limit the total time allowed for +retries. + +curl complies with the Retry-After: response header if one was present to know +when to issue the next retry (added in 7.66.0). diff --git a/third-party/curl/docs/cmdline-opts/sasl-authzid.d b/third-party/curl/docs/cmdline-opts/sasl-authzid.d deleted file mode 100644 index 872818df77..0000000000 --- a/third-party/curl/docs/cmdline-opts/sasl-authzid.d +++ /dev/null @@ -1,19 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: sasl-authzid -Arg: -Help: Identity for SASL PLAIN authentication -Added: 7.66.0 -Category: auth -Example: --sasl-authzid zid imap://example.com/ -See-also: login-options -Multi: single ---- -Use this authorization identity (**authzid**), during SASL PLAIN -authentication, in addition to the authentication identity (**authcid**) as -specified by --user. - -If the option is not specified, the server derives the **authzid** from the -**authcid**, but if specified, and depending on the server implementation, it -may be used to access another user's inbox, that the user has been granted -access to, or a shared mailbox for example. diff --git a/third-party/curl/docs/cmdline-opts/sasl-authzid.md b/third-party/curl/docs/cmdline-opts/sasl-authzid.md new file mode 100644 index 0000000000..4e92a20541 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/sasl-authzid.md @@ -0,0 +1,26 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: sasl-authzid +Arg: +Help: Identity for SASL PLAIN authentication +Protocols: LDAP IMAP POP3 SMTP +Added: 7.66.0 +Category: auth +Multi: single +See-also: + - login-options +Example: + - --sasl-authzid zid imap://example.com/ +--- + +# `--sasl-authzid` + +Use this authorization identity (**authzid**), during SASL PLAIN +authentication, in addition to the authentication identity (**authcid**) as +specified by --user. + +If the option is not specified, the server derives the **authzid** from the +**authcid**, but if specified, and depending on the server implementation, it +may be used to access another user's inbox, that the user has been granted +access to, or a shared mailbox for example. diff --git a/third-party/curl/docs/cmdline-opts/sasl-ir.d b/third-party/curl/docs/cmdline-opts/sasl-ir.d deleted file mode 100644 index 56f1ae8ad7..0000000000 --- a/third-party/curl/docs/cmdline-opts/sasl-ir.d +++ /dev/null @@ -1,11 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: sasl-ir -Help: Enable initial response in SASL authentication -Added: 7.31.0 -Category: auth -Example: --sasl-ir imap://example.com/ -See-also: sasl-authzid -Multi: boolean ---- -Enable initial response in SASL authentication. diff --git a/third-party/curl/docs/cmdline-opts/sasl-ir.md b/third-party/curl/docs/cmdline-opts/sasl-ir.md new file mode 100644 index 0000000000..206bf29317 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/sasl-ir.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: sasl-ir +Help: Initial response in SASL authentication +Protocols: LDAP IMAP POP3 SMTP +Added: 7.31.0 +Category: auth +Multi: boolean +See-also: + - sasl-authzid +Example: + - --sasl-ir imap://example.com/ +--- + +# `--sasl-ir` + +Enable initial response in SASL authentication. Such an "initial response" is +a message sent by the client to the server after the client selects an +authentication mechanism. diff --git a/third-party/curl/docs/cmdline-opts/service-name.d b/third-party/curl/docs/cmdline-opts/service-name.d deleted file mode 100644 index 54d7ebf7bc..0000000000 --- a/third-party/curl/docs/cmdline-opts/service-name.d +++ /dev/null @@ -1,12 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: service-name -Help: SPNEGO service name -Arg: -Added: 7.43.0 -Category: misc -Example: --service-name sockd/server $URL -See-also: negotiate proxy-service-name -Multi: single ---- -This option allows you to change the service name for SPNEGO. diff --git a/third-party/curl/docs/cmdline-opts/service-name.md b/third-party/curl/docs/cmdline-opts/service-name.md new file mode 100644 index 0000000000..f98409aa25 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/service-name.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: service-name +Help: SPNEGO service name +Arg: +Added: 7.43.0 +Category: auth +Multi: single +See-also: + - negotiate + - proxy-service-name +Example: + - --service-name sockd/server $URL +--- + +# `--service-name` + +Set the service name for SPNEGO. diff --git a/third-party/curl/docs/cmdline-opts/show-error.d b/third-party/curl/docs/cmdline-opts/show-error.d deleted file mode 100644 index f150287458..0000000000 --- a/third-party/curl/docs/cmdline-opts/show-error.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: show-error -Short: S -Help: Show error even when -s is used -See-also: no-progress-meter -Category: curl -Example: --show-error --silent $URL -Added: 5.9 -Multi: boolean -Scope: global ---- -When used with --silent, it makes curl show an error message if it fails. diff --git a/third-party/curl/docs/cmdline-opts/show-error.md b/third-party/curl/docs/cmdline-opts/show-error.md new file mode 100644 index 0000000000..aaf865bc0e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/show-error.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: show-error +Short: S +Help: Show error even when -s is used +Category: curl global +Added: 5.9 +Multi: boolean +Scope: global +See-also: + - no-progress-meter +Example: + - --show-error --silent $URL +--- + +# `--show-error` + +When used with --silent, it makes curl show an error message if it fails. diff --git a/third-party/curl/docs/cmdline-opts/show-headers.md b/third-party/curl/docs/cmdline-opts/show-headers.md new file mode 100644 index 0000000000..40c5ae790b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/show-headers.md @@ -0,0 +1,39 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: show-headers +Short: i +Help: Show response headers in output +Protocols: HTTP FTP +Category: important verbose output +Added: 4.8 +Multi: boolean +See-also: + - verbose + - dump-header +Example: + - -i $URL +--- + +# `--show-headers` + +Show response headers in the output. HTTP response headers can include things +like server name, cookies, date of the document, HTTP version and more. With +non-HTTP protocols, the "headers" are other server communication. + +This option makes the response headers get saved in the same stream/output as +the data. --dump-header exists to save headers in a separate stream. + +When HTTP headers are output to a tty, curl may use escape codes to make the +header field names appear in bold and URLs in `Location:` headers be +especially marked as such. Disable the use of terminal escape codes with +--no-styled-output. (This means using the --styled-output option with a +`--no-` prefix to disable it.) + +To view the request headers, consider the --verbose option. + +Prior to 7.75.0 curl did not print the headers if --fail was used in +combination with this option and there was an error reported by the server. + +This option was called --include before 8.10.0. The previous name remains +functional. diff --git a/third-party/curl/docs/cmdline-opts/sigalgs.md b/third-party/curl/docs/cmdline-opts/sigalgs.md new file mode 100644 index 0000000000..537b34f3ad --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/sigalgs.md @@ -0,0 +1,33 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: sigalgs +Arg: +Help: TLS signature algorithms to use +Protocols: TLS +Added: 8.14.0 +Category: tls +Multi: single +See-also: + - ciphers +Example: + - --sigalgs ecdsa_secp256r1_sha256 $URL +--- + +# `--sigalgs` + +Set specific signature algorithms to use during SSL session establishment according to RFC +5246, 7.4.1.4.1. + +An algorithm can use either a signature algorithm and a hash algorithm pair separated by a +`+` (e.g. `ECDSA+SHA224`), or its TLS 1.3 signature scheme name (e.g. `ed25519`). + +Multiple algorithms can be provided by separating them with `:` +(e.g. `DSA+SHA256:rsa_pss_pss_sha256`). The parameter is available as `-sigalgs` in the +OpenSSL `s_client` and `s_server` utilities. + +`--sigalgs` allows a OpenSSL powered curl to make SSL-connections with exactly +the signature algorithms requested by the client, avoiding nontransparent client/server +negotiations. + +If this option is set, the default signature algorithm list built into OpenSSL are ignored. diff --git a/third-party/curl/docs/cmdline-opts/silent.d b/third-party/curl/docs/cmdline-opts/silent.d deleted file mode 100644 index 74bb299cc2..0000000000 --- a/third-party/curl/docs/cmdline-opts/silent.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: silent -Short: s -Help: Silent mode -See-also: verbose stderr no-progress-meter -Category: important verbose -Example: -s $URL -Added: 4.0 -Multi: boolean ---- -Silent or quiet mode. Do not show progress meter or error messages. Makes Curl -mute. It still outputs the data you ask for, potentially even to the -terminal/stdout unless you redirect it. - -Use --show-error in addition to this option to disable progress meter but -still show error messages. diff --git a/third-party/curl/docs/cmdline-opts/silent.md b/third-party/curl/docs/cmdline-opts/silent.md new file mode 100644 index 0000000000..2498ca56f4 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/silent.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: silent +Short: s +Help: Silent mode +Category: important verbose +Added: 4.0 +Multi: boolean +See-also: + - verbose + - stderr + - no-progress-meter +Example: + - -s $URL +--- + +# `--silent` + +Silent or quiet mode. Do not show progress meter, warning messages or error +messages. Makes curl mute. It still outputs the data you ask for, potentially +even to the terminal/stdout unless you redirect it. + +Use --show-error in addition to this option to disable progress meter but +still show error messages. diff --git a/third-party/curl/docs/cmdline-opts/skip-existing.md b/third-party/curl/docs/cmdline-opts/skip-existing.md new file mode 100644 index 0000000000..dbef2fae92 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/skip-existing.md @@ -0,0 +1,22 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: skip-existing +Help: Skip download if local file already exists +Category: curl output +Added: 8.10.0 +Multi: boolean +See-also: + - output + - remote-name + - no-clobber +Example: + - --skip-existing --output local/dir/file $URL +--- + +# `--skip-existing` + +If there is a local file present when a download is requested, the operation +is skipped. Note that curl cannot know if the local file was previously +downloaded fine, or if it is incomplete etc, it knows if there is a filename +present in the file system or not and it skips the transfer if it is. diff --git a/third-party/curl/docs/cmdline-opts/socks4.d b/third-party/curl/docs/cmdline-opts/socks4.d deleted file mode 100644 index d8cf719aad..0000000000 --- a/third-party/curl/docs/cmdline-opts/socks4.d +++ /dev/null @@ -1,28 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: socks4 -Arg: -Help: SOCKS4 proxy on given host + port -Added: 7.15.2 -Category: proxy -Example: --socks4 hostname:4096 $URL -See-also: socks4a socks5 socks5-hostname -Multi: single ---- -Use the specified SOCKS4 proxy. If the port number is not specified, it is -assumed at port 1080. Using this socket type make curl resolve the host name -and passing the address on to the proxy. - -To specify proxy on a unix domain socket, use localhost for host, e.g. -socks4://localhost/path/to/socket.sock - -This option overrides any previous use of --proxy, as they are mutually -exclusive. - -This option is superfluous since you can specify a socks4 proxy with --proxy -using a socks4:// protocol prefix. (Added in 7.21.7) - ---preproxy can be used to specify a SOCKS proxy at the same time proxy is used -with an HTTP/HTTPS proxy (added in 7.52.0). In such a case, curl first -connects to the SOCKS proxy and then connects (through SOCKS) to the HTTP or -HTTPS proxy. diff --git a/third-party/curl/docs/cmdline-opts/socks4.md b/third-party/curl/docs/cmdline-opts/socks4.md new file mode 100644 index 0000000000..9d1c5671c9 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/socks4.md @@ -0,0 +1,38 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: socks4 +Arg: +Help: SOCKS4 proxy on given host + port +Added: 7.15.2 +Category: proxy +Multi: single +Mutexed: proxy socks4a socks5 socks5-hostname +See-also: + - socks4a + - socks5 + - socks5-hostname +Example: + - --socks4 hostname:4096 $URL +--- + +# `--socks4` + +Use the specified SOCKS4 proxy. If the port number is not specified, it is +assumed at port 1080. Using this socket type makes curl resolve the hostname +and pass the address on to the proxy. + +To specify the proxy on a Unix domain socket, use localhost for host and +append the absolute path to the domain socket. For example: +`socks4://localhost/path/to/socket.sock` (the scheme may be omitted). + +This option overrides any previous use of --proxy, as they are mutually +exclusive. + +This option is superfluous since you can specify a socks4 proxy with --proxy +using a `socks4://` protocol prefix. (Added in 7.21.7) + +--preproxy can be used to specify a SOCKS proxy at the same time proxy is used +with an HTTP/HTTPS proxy (added in 7.52.0). In such a case, curl first +connects to the SOCKS proxy and then connects (through SOCKS) to the HTTP or +HTTPS proxy. diff --git a/third-party/curl/docs/cmdline-opts/socks4a.d b/third-party/curl/docs/cmdline-opts/socks4a.d deleted file mode 100644 index cbb62724cd..0000000000 --- a/third-party/curl/docs/cmdline-opts/socks4a.d +++ /dev/null @@ -1,27 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: socks4a -Arg: -Help: SOCKS4a proxy on given host + port -Added: 7.18.0 -Category: proxy -Example: --socks4a hostname:4096 $URL -See-also: socks4 socks5 socks5-hostname -Multi: single ---- -Use the specified SOCKS4a proxy. If the port number is not specified, it is -assumed at port 1080. This asks the proxy to resolve the host name. - -To specify proxy on a unix domain socket, use localhost for host, e.g. -socks4a://localhost/path/to/socket.sock - -This option overrides any previous use of --proxy, as they are mutually -exclusive. - -This option is superfluous since you can specify a socks4a proxy with --proxy -using a socks4a:// protocol prefix. (Added in 7.21.7) - ---preproxy can be used to specify a SOCKS proxy at the same time --proxy is -used with an HTTP/HTTPS proxy (added in 7.52.0). In such a case, curl first -connects to the SOCKS proxy and then connects (through SOCKS) to the HTTP or -HTTPS proxy. diff --git a/third-party/curl/docs/cmdline-opts/socks4a.md b/third-party/curl/docs/cmdline-opts/socks4a.md new file mode 100644 index 0000000000..695e44cb2b --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/socks4a.md @@ -0,0 +1,37 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: socks4a +Arg: +Help: SOCKS4a proxy on given host + port +Added: 7.18.0 +Category: proxy +Multi: single +Mutexed: proxy socks4 socks5 socks5-hostname +See-also: + - socks4 + - socks5 + - socks5-hostname +Example: + - --socks4a hostname:4096 $URL +--- + +# `--socks4a` + +Use the specified SOCKS4a proxy. If the port number is not specified, it is +assumed at port 1080. This asks the proxy to resolve the hostname. + +To specify the proxy on a Unix domain socket, use localhost for host and +append the absolute path to the domain socket. For example: +`socks4a://localhost/path/to/socket.sock` (the scheme may be omitted). + +This option overrides any previous use of --proxy, as they are mutually +exclusive. + +This option is superfluous since you can specify a socks4a proxy with --proxy +using a `socks4a://` protocol prefix. (Added in 7.21.7) + +--preproxy can be used to specify a SOCKS proxy at the same time --proxy is +used with an HTTP/HTTPS proxy (added in 7.52.0). In such a case, curl first +connects to the SOCKS proxy and then connects (through SOCKS) to the HTTP or +HTTPS proxy. diff --git a/third-party/curl/docs/cmdline-opts/socks5-basic.d b/third-party/curl/docs/cmdline-opts/socks5-basic.d deleted file mode 100644 index a16831be18..0000000000 --- a/third-party/curl/docs/cmdline-opts/socks5-basic.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: socks5-basic -Help: Enable username/password auth for SOCKS5 proxies -Added: 7.55.0 -Category: proxy auth -Example: --socks5-basic --socks5 hostname:4096 $URL -See-also: socks5 -Multi: mutex ---- -Tells curl to use username/password authentication when connecting to a SOCKS5 -proxy. The username/password authentication is enabled by default. Use ---socks5-gssapi to force GSS-API authentication to SOCKS5 proxies. diff --git a/third-party/curl/docs/cmdline-opts/socks5-basic.md b/third-party/curl/docs/cmdline-opts/socks5-basic.md new file mode 100644 index 0000000000..dc2a5532f1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/socks5-basic.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: socks5-basic +Help: Username/password auth for SOCKS5 proxies +Added: 7.55.0 +Category: proxy auth +Multi: mutex +See-also: + - socks5 +Example: + - --socks5-basic --socks5 hostname:4096 $URL +--- + +# `--socks5-basic` + +Use username/password authentication when connecting to a SOCKS5 proxy. The +username/password authentication is enabled by default. Use --socks5-gssapi to +force GSS-API authentication to SOCKS5 proxies. diff --git a/third-party/curl/docs/cmdline-opts/socks5-gssapi-nec.d b/third-party/curl/docs/cmdline-opts/socks5-gssapi-nec.d deleted file mode 100644 index 957655a091..0000000000 --- a/third-party/curl/docs/cmdline-opts/socks5-gssapi-nec.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: socks5-gssapi-nec -Help: Compatibility with NEC SOCKS5 server -Added: 7.19.4 -Category: proxy auth -Example: --socks5-gssapi-nec --socks5 hostname:4096 $URL -See-also: socks5 -Multi: boolean ---- -As part of the GSS-API negotiation a protection mode is negotiated. RFC 1961 -says in section 4.3/4.4 it should be protected, but the NEC reference -implementation does not. The option --socks5-gssapi-nec allows the -unprotected exchange of the protection mode negotiation. diff --git a/third-party/curl/docs/cmdline-opts/socks5-gssapi-nec.md b/third-party/curl/docs/cmdline-opts/socks5-gssapi-nec.md new file mode 100644 index 0000000000..9cd91b9615 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/socks5-gssapi-nec.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: socks5-gssapi-nec +Help: Compatibility with NEC SOCKS5 server +Added: 7.19.4 +Category: proxy auth +Protocols: GSS/kerberos +Multi: boolean +See-also: + - socks5 +Example: + - --socks5-gssapi-nec --socks5 hostname:4096 $URL +--- + +# `--socks5-gssapi-nec` + +As part of the GSS-API negotiation a protection mode is negotiated. RFC 1961 +says in section 4.3/4.4 it should be protected, but the NEC reference +implementation does not. The option --socks5-gssapi-nec allows the +unprotected exchange of the protection mode negotiation. diff --git a/third-party/curl/docs/cmdline-opts/socks5-gssapi-service.d b/third-party/curl/docs/cmdline-opts/socks5-gssapi-service.d deleted file mode 100644 index 66c2f33a59..0000000000 --- a/third-party/curl/docs/cmdline-opts/socks5-gssapi-service.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: socks5-gssapi-service -Arg: -Help: SOCKS5 proxy service name for GSS-API -Added: 7.19.4 -Category: proxy auth -Example: --socks5-gssapi-service sockd --socks5 hostname:4096 $URL -See-also: socks5 -Multi: single ---- -The default service name for a socks server is **rcmd/server-fqdn**. This option -allows you to change it. diff --git a/third-party/curl/docs/cmdline-opts/socks5-gssapi-service.md b/third-party/curl/docs/cmdline-opts/socks5-gssapi-service.md new file mode 100644 index 0000000000..d847e65e24 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/socks5-gssapi-service.md @@ -0,0 +1,18 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: socks5-gssapi-service +Arg: +Help: SOCKS5 proxy service name for GSS-API +Added: 7.19.4 +Category: proxy auth +Multi: single +See-also: + - socks5 +Example: + - --socks5-gssapi-service sockd --socks5 hostname:4096 $URL +--- + +# `--socks5-gssapi-service` + +Set the service name for a socks server. Default is **rcmd/server-fqdn**. diff --git a/third-party/curl/docs/cmdline-opts/socks5-gssapi.d b/third-party/curl/docs/cmdline-opts/socks5-gssapi.d deleted file mode 100644 index cec684f422..0000000000 --- a/third-party/curl/docs/cmdline-opts/socks5-gssapi.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: socks5-gssapi -Help: Enable GSS-API auth for SOCKS5 proxies -Added: 7.55.0 -Category: proxy auth -Example: --socks5-gssapi --socks5 hostname:4096 $URL -See-also: socks5 -Multi: boolean ---- -Tells curl to use GSS-API authentication when connecting to a SOCKS5 proxy. -The GSS-API authentication is enabled by default (if curl is compiled with -GSS-API support). Use --socks5-basic to force username/password authentication -to SOCKS5 proxies. diff --git a/third-party/curl/docs/cmdline-opts/socks5-gssapi.md b/third-party/curl/docs/cmdline-opts/socks5-gssapi.md new file mode 100644 index 0000000000..b8520b22cc --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/socks5-gssapi.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: socks5-gssapi +Help: Enable GSS-API auth for SOCKS5 proxies +Added: 7.55.0 +Category: proxy auth +Protocols: GSS/kerberos +Multi: boolean +See-also: + - socks5 +Example: + - --socks5-gssapi --socks5 hostname:4096 $URL +--- + +# `--socks5-gssapi` + +Use GSS-API authentication when connecting to a SOCKS5 proxy. The GSS-API +authentication is enabled by default (if curl is compiled with GSS-API +support). Use --socks5-basic to force username/password authentication to +SOCKS5 proxies. diff --git a/third-party/curl/docs/cmdline-opts/socks5-hostname.d b/third-party/curl/docs/cmdline-opts/socks5-hostname.d deleted file mode 100644 index ee49ca6426..0000000000 --- a/third-party/curl/docs/cmdline-opts/socks5-hostname.d +++ /dev/null @@ -1,27 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: socks5-hostname -Arg: -Help: SOCKS5 proxy, pass host name to proxy -Added: 7.18.0 -Category: proxy -Example: --socks5-hostname proxy.example:7000 $URL -See-also: socks5 socks4a -Multi: single ---- -Use the specified SOCKS5 proxy (and let the proxy resolve the host name). If -the port number is not specified, it is assumed at port 1080. - -To specify proxy on a unix domain socket, use localhost for host, e.g. -socks5h://localhost/path/to/socket.sock - -This option overrides any previous use of --proxy, as they are mutually -exclusive. - -This option is superfluous since you can specify a socks5 hostname proxy with ---proxy using a socks5h:// protocol prefix. (Added in 7.21.7) - ---preproxy can be used to specify a SOCKS proxy at the same time --proxy is -used with an HTTP/HTTPS proxy (added in 7.52.0). In such a case, curl first -connects to the SOCKS proxy and then connects (through SOCKS) to the HTTP or -HTTPS proxy. diff --git a/third-party/curl/docs/cmdline-opts/socks5-hostname.md b/third-party/curl/docs/cmdline-opts/socks5-hostname.md new file mode 100644 index 0000000000..f8ee9fe137 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/socks5-hostname.md @@ -0,0 +1,36 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: socks5-hostname +Arg: +Help: SOCKS5 proxy, pass hostname to proxy +Added: 7.18.0 +Category: proxy +Multi: single +Mutexed: proxy socks4 socks4a socks5 +See-also: + - socks5 + - socks4a +Example: + - --socks5-hostname proxy.example:7000 $URL +--- + +# `--socks5-hostname` + +Use the specified SOCKS5 proxy (and let the proxy resolve the hostname). If +the port number is not specified, it is assumed at port 1080. + +To specify the proxy on a Unix domain socket, use localhost for host and +append the absolute path to the domain socket. For example: +`socks5h://localhost/path/to/socket.sock` (the scheme may be omitted). + +This option overrides any previous use of --proxy, as they are mutually +exclusive. + +This option is superfluous since you can specify a socks5 hostname proxy with +--proxy using a `socks5h://` protocol prefix. (Added in 7.21.7) + +--preproxy can be used to specify a SOCKS proxy at the same time --proxy is +used with an HTTP/HTTPS proxy (added in 7.52.0). In such a case, curl first +connects to the SOCKS proxy and then connects (through SOCKS) to the HTTP or +HTTPS proxy. diff --git a/third-party/curl/docs/cmdline-opts/socks5.d b/third-party/curl/docs/cmdline-opts/socks5.d deleted file mode 100644 index 0e52166ea2..0000000000 --- a/third-party/curl/docs/cmdline-opts/socks5.d +++ /dev/null @@ -1,29 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: socks5 -Arg: -Help: SOCKS5 proxy on given host + port -Added: 7.18.0 -Category: proxy -Example: --socks5 proxy.example:7000 $URL -See-also: socks5-hostname socks4a -Multi: single ---- -Use the specified SOCKS5 proxy - but resolve the host name locally. If the -port number is not specified, it is assumed at port 1080. - -To specify proxy on a unix domain socket, use localhost for host, e.g. -socks5://localhost/path/to/socket.sock - -This option overrides any previous use of --proxy, as they are mutually -exclusive. - -This option is superfluous since you can specify a socks5 proxy with --proxy -using a socks5:// protocol prefix. (Added in 7.21.7) - ---preproxy can be used to specify a SOCKS proxy at the same time --proxy is -used with an HTTP/HTTPS proxy (added in 7.52.0). In such a case, curl first -connects to the SOCKS proxy and then connects (through SOCKS) to the HTTP or -HTTPS proxy. - -This option (as well as --socks4) does not work with IPV6, FTPS or LDAP. diff --git a/third-party/curl/docs/cmdline-opts/socks5.md b/third-party/curl/docs/cmdline-opts/socks5.md new file mode 100644 index 0000000000..b70e88f6fa --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/socks5.md @@ -0,0 +1,39 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: socks5 +Arg: +Help: SOCKS5 proxy on given host + port +Added: 7.18.0 +Category: proxy +Multi: single +See-also: + - socks5-hostname + - socks4a +Mutexed: proxy socks4 socks4a socks5-hostname +Example: + - --socks5 proxy.example:7000 $URL + - --socks5 localhost/path/unix-domain $URL +--- + +# `--socks5` + +Use the specified SOCKS5 proxy - but resolve the hostname locally. If the +port number is not specified, it is assumed at port 1080. + +To specify the proxy on a Unix domain socket, use localhost for host and +append the absolute path to the domain socket. For example: +`socks5://localhost/path/to/socket.sock` (the scheme may be omitted). + +This option overrides any previous use of --proxy, as they are mutually +exclusive. + +This option is superfluous since you can specify a socks5 proxy with --proxy +using a `socks5://` protocol prefix. (Added in 7.21.7) + +--preproxy can be used to specify a SOCKS proxy at the same time --proxy is +used with an HTTP/HTTPS proxy (added in 7.52.0). In such a case, curl first +connects to the SOCKS proxy and then connects (through SOCKS) to the HTTP or +HTTPS proxy. + +This option does not work with FTPS or LDAP. diff --git a/third-party/curl/docs/cmdline-opts/speed-limit.d b/third-party/curl/docs/cmdline-opts/speed-limit.d deleted file mode 100644 index dc9778db9b..0000000000 --- a/third-party/curl/docs/cmdline-opts/speed-limit.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: speed-limit -Short: Y -Arg: -Help: Stop transfers slower than this -Category: connection -Example: --speed-limit 300 --speed-time 10 $URL -Added: 4.7 -See-also: speed-time limit-rate max-time -Multi: single ---- -If a transfer is slower than this given speed (in bytes per second) for -speed-time seconds it gets aborted. speed-time is set with --speed-time and is -30 if not set. diff --git a/third-party/curl/docs/cmdline-opts/speed-limit.md b/third-party/curl/docs/cmdline-opts/speed-limit.md new file mode 100644 index 0000000000..b95d6e7d49 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/speed-limit.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: speed-limit +Short: Y +Arg: +Help: Stop transfers slower than this +Category: connection +Added: 4.7 +Multi: single +See-also: + - speed-time + - limit-rate + - max-time +Example: + - --speed-limit 300 --speed-time 10 $URL +--- + +# `--speed-limit` + +If a transfer is slower than this set speed (in bytes per second) for a given +number of seconds, it gets aborted. The time period is set with --speed-time +and is 30 seconds by default. diff --git a/third-party/curl/docs/cmdline-opts/speed-time.d b/third-party/curl/docs/cmdline-opts/speed-time.d deleted file mode 100644 index 4a8860660a..0000000000 --- a/third-party/curl/docs/cmdline-opts/speed-time.d +++ /dev/null @@ -1,18 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: speed-time -Short: y -Arg: -Help: Trigger 'speed-limit' abort after this time -Category: connection -Example: --speed-limit 300 --speed-time 10 $URL -Added: 4.7 -See-also: speed-limit limit-rate -Multi: single ---- -If a transfer runs slower than speed-limit bytes per second during a -speed-time period, the transfer is aborted. If speed-time is used, the default -speed-limit is 1 unless set with --speed-limit. - -This option controls transfers (in both directions) but does not affect slow -connects etc. If this is a concern for you, try the --connect-timeout option. diff --git a/third-party/curl/docs/cmdline-opts/speed-time.md b/third-party/curl/docs/cmdline-opts/speed-time.md new file mode 100644 index 0000000000..f27702bec3 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/speed-time.md @@ -0,0 +1,25 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: speed-time +Short: y +Arg: +Help: Trigger 'speed-limit' abort after this time +Category: connection timeout +Added: 4.7 +Multi: single +See-also: + - speed-limit + - limit-rate +Example: + - --speed-limit 300 --speed-time 10 $URL +--- + +# `--speed-time` + +If a transfer runs slower than speed-limit bytes per second during a +speed-time period, the transfer is aborted. If speed-time is used, the default +speed-limit is 1 unless set with --speed-limit. + +This option controls transfers (in both directions) but does not affect slow +connects etc. If this is a concern for you, try the --connect-timeout option. diff --git a/third-party/curl/docs/cmdline-opts/ssl-allow-beast.d b/third-party/curl/docs/cmdline-opts/ssl-allow-beast.d deleted file mode 100644 index 2547675d64..0000000000 --- a/third-party/curl/docs/cmdline-opts/ssl-allow-beast.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ssl-allow-beast -Help: Allow security flaw to improve interop -Added: 7.25.0 -Category: tls -Example: --ssl-allow-beast $URL -See-also: proxy-ssl-allow-beast insecure -Multi: boolean ---- -This option tells curl to not work around a security flaw in the SSL3 and -TLS1.0 protocols known as BEAST. If this option is not used, the SSL layer -may use workarounds known to cause interoperability problems with some older -SSL implementations. - -**WARNING**: this option loosens the SSL security, and by using this flag you -ask for exactly that. diff --git a/third-party/curl/docs/cmdline-opts/ssl-allow-beast.md b/third-party/curl/docs/cmdline-opts/ssl-allow-beast.md new file mode 100644 index 0000000000..f9933b77af --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ssl-allow-beast.md @@ -0,0 +1,27 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ssl-allow-beast +Help: Allow security flaw to improve interop +Protocols: TLS +Added: 7.25.0 +Category: tls +Multi: boolean +See-also: + - proxy-ssl-allow-beast + - insecure +Example: + - --ssl-allow-beast $URL +--- + +# `--ssl-allow-beast` + +Do not work around a security flaw in the TLS1.0 protocol known as BEAST. If +this option is not used, the TLS layer may use workarounds known to cause +interoperability problems with some older server implementations. + +This option only changes how curl does TLS 1.0 and has no effect on later TLS +versions. + +**WARNING**: this option loosens the TLS security, and by using this flag you +ask for exactly that. diff --git a/third-party/curl/docs/cmdline-opts/ssl-auto-client-cert.d b/third-party/curl/docs/cmdline-opts/ssl-auto-client-cert.d deleted file mode 100644 index 5328adea71..0000000000 --- a/third-party/curl/docs/cmdline-opts/ssl-auto-client-cert.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ssl-auto-client-cert -Help: Use auto client certificate (Schannel) -Added: 7.77.0 -See-also: proxy-ssl-auto-client-cert -Category: tls -Example: --ssl-auto-client-cert $URL -Multi: boolean ---- -(Schannel) Tell libcurl to automatically locate and use a client certificate -for authentication, when requested by the server. Since the server can request -any certificate that supports client authentication in the OS certificate -store it could be a privacy violation and unexpected. diff --git a/third-party/curl/docs/cmdline-opts/ssl-auto-client-cert.md b/third-party/curl/docs/cmdline-opts/ssl-auto-client-cert.md new file mode 100644 index 0000000000..4f0be5bd7e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ssl-auto-client-cert.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ssl-auto-client-cert +Help: Use auto client certificate (Schannel) +Added: 7.77.0 +Category: tls +Protocols: TLS +Multi: boolean +See-also: + - proxy-ssl-auto-client-cert +Example: + - --ssl-auto-client-cert $URL +--- + +# `--ssl-auto-client-cert` + +(Schannel) Automatically locate and use a client certificate for +authentication, when requested by the server. Since the server can request any +certificate that supports client authentication in the OS certificate store it +could be a privacy violation and unexpected. diff --git a/third-party/curl/docs/cmdline-opts/ssl-no-revoke.d b/third-party/curl/docs/cmdline-opts/ssl-no-revoke.d deleted file mode 100644 index 37e91d9c20..0000000000 --- a/third-party/curl/docs/cmdline-opts/ssl-no-revoke.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ssl-no-revoke -Help: Disable cert revocation checks (Schannel) -Added: 7.44.0 -Category: tls -Example: --ssl-no-revoke $URL -See-also: crlfile -Multi: boolean ---- -(Schannel) This option tells curl to disable certificate revocation checks. -WARNING: this option loosens the SSL security, and by using this flag you ask -for exactly that. diff --git a/third-party/curl/docs/cmdline-opts/ssl-no-revoke.md b/third-party/curl/docs/cmdline-opts/ssl-no-revoke.md new file mode 100644 index 0000000000..16981f14d1 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ssl-no-revoke.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ssl-no-revoke +Help: Disable cert revocation checks (Schannel) +Added: 7.44.0 +Protocols: TLS +Category: tls +Multi: boolean +See-also: + - crlfile +Example: + - --ssl-no-revoke $URL +--- + +# `--ssl-no-revoke` + +(Schannel) Disable certificate revocation checks. WARNING: this option loosens +the SSL security, and by using this flag you ask for exactly that. diff --git a/third-party/curl/docs/cmdline-opts/ssl-reqd.d b/third-party/curl/docs/cmdline-opts/ssl-reqd.d deleted file mode 100644 index 8a5b8577e0..0000000000 --- a/third-party/curl/docs/cmdline-opts/ssl-reqd.d +++ /dev/null @@ -1,23 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ssl-reqd -Help: Require SSL/TLS -Protocols: FTP IMAP POP3 SMTP LDAP -Added: 7.20.0 -Category: tls -Example: --ssl-reqd ftp://example.com -See-also: ssl insecure -Multi: boolean ---- -Require SSL/TLS for the connection. Terminates the connection if the transfer -cannot be upgraded to use SSL/TLS. - -This option is handled in LDAP (added in 7.81.0). It is fully supported by the -OpenLDAP backend and rejected by the generic ldap backend if explicit TLS is -required. - -This option is unnecessary if you use a URL scheme that in itself implies -immediate and implicit use of TLS, like for FTPS, IMAPS, POP3S, SMTPS and -LDAPS. Such a transfer always fails if the TLS handshake does not work. - -This option was formerly known as --ftp-ssl-reqd. diff --git a/third-party/curl/docs/cmdline-opts/ssl-reqd.md b/third-party/curl/docs/cmdline-opts/ssl-reqd.md new file mode 100644 index 0000000000..f21c145f59 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ssl-reqd.md @@ -0,0 +1,31 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ssl-reqd +Help: Require SSL/TLS +Protocols: FTP IMAP POP3 SMTP LDAP +Added: 7.20.0 +Category: tls imap pop3 smtp ldap +Multi: boolean +See-also: + - ssl + - insecure +Example: + - --ssl-reqd ftp://example.com +--- + +# `--ssl-reqd` + +Require SSL/TLS for the connection - often referred to as STARTTLS or STLS +because of the involved commands. Terminates the connection if the transfer +cannot be upgraded to use SSL/TLS. + +This option is handled in LDAP (added in 7.81.0). It is fully supported by the +OpenLDAP backend and rejected by the generic ldap backend if explicit TLS is +required. + +This option is unnecessary if you use a URL scheme that in itself implies +immediate and implicit use of TLS, like for FTPS, IMAPS, POP3S, SMTPS and +LDAPS. Such a transfer always fails if the TLS handshake does not work. + +This option was formerly known as --ftp-ssl-reqd. diff --git a/third-party/curl/docs/cmdline-opts/ssl-revoke-best-effort.d b/third-party/curl/docs/cmdline-opts/ssl-revoke-best-effort.d deleted file mode 100644 index cb26d0b9a0..0000000000 --- a/third-party/curl/docs/cmdline-opts/ssl-revoke-best-effort.d +++ /dev/null @@ -1,13 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ssl-revoke-best-effort -Help: Ignore missing/offline cert CRL dist points (Schannel) -Added: 7.70.0 -Category: tls -Example: --ssl-revoke-best-effort $URL -See-also: crlfile insecure -Multi: boolean ---- -(Schannel) This option tells curl to ignore certificate revocation checks when -they failed due to missing/offline distribution points for the revocation check -lists. diff --git a/third-party/curl/docs/cmdline-opts/ssl-revoke-best-effort.md b/third-party/curl/docs/cmdline-opts/ssl-revoke-best-effort.md new file mode 100644 index 0000000000..0257e05f47 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ssl-revoke-best-effort.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ssl-revoke-best-effort +Help: Ignore missing cert CRL dist points +Added: 7.70.0 +Protocols: TLS +Category: tls +Multi: boolean +See-also: + - crlfile + - insecure +Example: + - --ssl-revoke-best-effort $URL +--- + +# `--ssl-revoke-best-effort` + +(Schannel) Ignore certificate revocation checks when they failed due to +missing/offline distribution points for the revocation check lists. diff --git a/third-party/curl/docs/cmdline-opts/ssl-sessions.md b/third-party/curl/docs/cmdline-opts/ssl-sessions.md new file mode 100644 index 0000000000..33ef984a3e --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ssl-sessions.md @@ -0,0 +1,39 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ssl-sessions +Arg: +Protocols: TLS +Help: Load/save SSL session tickets from/to this file +Added: 8.12.0 +Category: tls +Multi: single +Experimental: yes +See-also: + - tls-earlydata +Example: + - --ssl-sessions sessions.txt $URL +--- + +# `--ssl-sessions` + +Use the given file to load SSL session tickets into curl's cache before +starting any transfers. At the end of a successful curl run, the cached +SSL sessions tickets are saved to the file, replacing any previous content. + +The file does not have to exist, but curl reports an error if it is +unable to create it. Unused loaded tickets are saved again, unless they +get replaced or purged from the cache for space reasons. + +Using a session file allows `--tls-earlydata` to send the first request +in "0-RTT" mode, should an SSL session with the feature be found. Note that +a server may not support early data. Also note that early data does +not provide forward secrecy, e.g. is not as secure. + +The SSL session tickets are stored as base64 encoded text, each ticket on +its own line. The hostnames are cryptographically salted and hashed. While +this prevents someone from easily seeing the hosts you contacted, they could +still check if a specific hostname matches one of the values. + +This feature requires that the underlying libcurl was built with the +experimental SSL session import/export feature (SSLS-EXPORT) enabled. diff --git a/third-party/curl/docs/cmdline-opts/ssl.d b/third-party/curl/docs/cmdline-opts/ssl.d deleted file mode 100644 index b8fd22a9ca..0000000000 --- a/third-party/curl/docs/cmdline-opts/ssl.d +++ /dev/null @@ -1,26 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: ssl -Help: Try SSL/TLS -Protocols: FTP IMAP POP3 SMTP LDAP -Added: 7.20.0 -Category: tls -Example: --ssl pop3://example.com/ -See-also: ssl-reqd insecure ciphers -Multi: boolean ---- -Warning: this is considered an insecure option. Consider using --ssl-reqd -instead to be sure curl upgrades to a secure connection. - -Try to use SSL/TLS for the connection. Reverts to a non-secure connection if -the server does not support SSL/TLS. See also --ftp-ssl-control and --ssl-reqd -for different levels of encryption required. - -This option is handled in LDAP (added in 7.81.0). It is fully supported by the -OpenLDAP backend and ignored by the generic ldap backend. - -Please note that a server may close the connection if the negotiation does -not succeed. - -This option was formerly known as --ftp-ssl (added in 7.11.0). That option -name can still be used but might be removed in a future version. diff --git a/third-party/curl/docs/cmdline-opts/ssl.md b/third-party/curl/docs/cmdline-opts/ssl.md new file mode 100644 index 0000000000..b234585809 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/ssl.md @@ -0,0 +1,36 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: ssl +Help: Try enabling TLS +Protocols: FTP IMAP POP3 SMTP LDAP +Added: 7.20.0 +Category: tls imap pop3 smtp ldap +Multi: boolean +See-also: + - ssl-reqd + - insecure + - ciphers +Example: + - --ssl pop3://example.com/ +--- + +# `--ssl` + +Warning: this is considered an insecure option. Consider using --ssl-reqd +instead to be sure curl upgrades to a secure connection. + +Try to use SSL/TLS for the connection - often referred to as STARTTLS or STLS +because of the involved commands. Reverts to a non-secure connection if the +server does not support SSL/TLS. See also --ftp-ssl-control and --ssl-reqd for +different levels of encryption required. + +This option is handled in LDAP (added in 7.81.0). It is fully supported by the +OpenLDAP backend and ignored by the generic ldap backend. + +Please note that a server may close the connection if the negotiation fails. + +If set, this option overrides --ftp-ssl-control. + +This option was formerly known as --ftp-ssl (added in 7.11.0). That option +name can still be used but might be removed in a future version. diff --git a/third-party/curl/docs/cmdline-opts/sslv2.d b/third-party/curl/docs/cmdline-opts/sslv2.d deleted file mode 100644 index 3ecf109a09..0000000000 --- a/third-party/curl/docs/cmdline-opts/sslv2.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: 2 -Long: sslv2 -Tags: Versions -Protocols: SSL -Added: 5.9 -Mutexed: sslv3 tlsv1 tlsv1.1 tlsv1.2 -Requires: TLS -See-also: http1.1 http2 -Help: Use SSLv2 -Category: tls -Example: --sslv2 $URL -Multi: mutex ---- -This option previously asked curl to use SSLv2, but is now ignored -(added in 7.77.0). SSLv2 is widely considered insecure (see RFC 6176). diff --git a/third-party/curl/docs/cmdline-opts/sslv2.md b/third-party/curl/docs/cmdline-opts/sslv2.md new file mode 100644 index 0000000000..ea92a2cb46 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/sslv2.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: 2 +Long: sslv2 +Tags: Versions +Protocols: SSL +Added: 5.9 +Mutexed: sslv3 tlsv1 tlsv1.1 tlsv1.2 +Requires: TLS +Help: SSLv2 +Category: deprecated +Multi: mutex +See-also: + - http1.1 + - http2 +Example: + - --sslv2 $URL +--- + +# `--sslv2` + +This option previously asked curl to use SSLv2, but is now ignored +(added in 7.77.0). SSLv2 is widely considered insecure (see RFC 6176). diff --git a/third-party/curl/docs/cmdline-opts/sslv3.d b/third-party/curl/docs/cmdline-opts/sslv3.d deleted file mode 100644 index 409afc610f..0000000000 --- a/third-party/curl/docs/cmdline-opts/sslv3.d +++ /dev/null @@ -1,17 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Short: 3 -Long: sslv3 -Tags: Versions -Protocols: SSL -Added: 5.9 -Mutexed: sslv2 tlsv1 tlsv1.1 tlsv1.2 -Requires: TLS -See-also: http1.1 http2 -Help: Use SSLv3 -Category: tls -Example: --sslv3 $URL -Multi: mutex ---- -This option previously asked curl to use SSLv3, but is now ignored -(added in 7.77.0). SSLv3 is widely considered insecure (see RFC 7568). diff --git a/third-party/curl/docs/cmdline-opts/sslv3.md b/third-party/curl/docs/cmdline-opts/sslv3.md new file mode 100644 index 0000000000..f022124e10 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/sslv3.md @@ -0,0 +1,24 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Short: 3 +Long: sslv3 +Tags: Versions +Protocols: SSL +Added: 5.9 +Mutexed: sslv2 tlsv1 tlsv1.1 tlsv1.2 +Requires: TLS +Help: SSLv3 +Category: deprecated +Multi: mutex +See-also: + - http1.1 + - http2 +Example: + - --sslv3 $URL +--- + +# `--sslv3` + +This option previously asked curl to use SSLv3, but is now ignored +(added in 7.77.0). SSLv3 is widely considered insecure (see RFC 7568). diff --git a/third-party/curl/docs/cmdline-opts/stderr.d b/third-party/curl/docs/cmdline-opts/stderr.d deleted file mode 100644 index a80bf43d1c..0000000000 --- a/third-party/curl/docs/cmdline-opts/stderr.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: stderr -Arg: -Help: Where to redirect stderr -See-also: verbose silent -Category: verbose -Example: --stderr output.txt $URL -Added: 6.2 -Multi: single -Scope: global ---- -Redirect all writes to stderr to the specified file instead. If the file name -is a plain '-', it is instead written to stdout. diff --git a/third-party/curl/docs/cmdline-opts/stderr.md b/third-party/curl/docs/cmdline-opts/stderr.md new file mode 100644 index 0000000000..7030e557b0 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/stderr.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: stderr +Arg: +Help: Where to redirect stderr +Category: verbose global +Added: 6.2 +Multi: single +Scope: global +See-also: + - verbose + - silent +Example: + - --stderr output.txt $URL +--- + +# `--stderr` + +Redirect all writes to stderr to the specified file instead. If the filename +is a plain '-', it is instead written to stdout. diff --git a/third-party/curl/docs/cmdline-opts/styled-output.d b/third-party/curl/docs/cmdline-opts/styled-output.d deleted file mode 100644 index 70e9da4e84..0000000000 --- a/third-party/curl/docs/cmdline-opts/styled-output.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: styled-output -Help: Enable styled output for HTTP headers -Added: 7.61.0 -Category: verbose -Example: --styled-output -I $URL -See-also: head verbose -Multi: boolean -Scope: global ---- -Enables the automatic use of bold font styles when writing HTTP headers to the -terminal. Use --no-styled-output to switch them off. - -Styled output requires a terminal that supports bold fonts. This feature is -not present on curl for Windows due to lack of this capability. diff --git a/third-party/curl/docs/cmdline-opts/styled-output.md b/third-party/curl/docs/cmdline-opts/styled-output.md new file mode 100644 index 0000000000..8193896c5d --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/styled-output.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: styled-output +Help: Enable styled output for HTTP headers +Added: 7.61.0 +Category: verbose global +Multi: boolean +Scope: global +See-also: + - head + - verbose +Example: + - --styled-output -I $URL +--- + +# `--styled-output` + +Enable automatic use of bold font styles when writing HTTP headers to the +terminal. Use --no-styled-output to switch them off. + +Styled output requires a terminal that supports bold fonts. This feature is +not present on curl for Windows due to lack of this capability. diff --git a/third-party/curl/docs/cmdline-opts/suppress-connect-headers.d b/third-party/curl/docs/cmdline-opts/suppress-connect-headers.d deleted file mode 100644 index ed38f36de8..0000000000 --- a/third-party/curl/docs/cmdline-opts/suppress-connect-headers.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: suppress-connect-headers -Help: Suppress proxy CONNECT response headers -See-also: dump-header include proxytunnel -Category: proxy -Example: --suppress-connect-headers --include -x proxy $URL -Added: 7.54.0 -Multi: boolean ---- -When --proxytunnel is used and a CONNECT request is made do not output proxy -CONNECT response headers. This option is meant to be used with --dump-header or ---include which are used to show protocol headers in the output. It has no -effect on debug options such as --verbose or --trace, or any statistics. diff --git a/third-party/curl/docs/cmdline-opts/suppress-connect-headers.md b/third-party/curl/docs/cmdline-opts/suppress-connect-headers.md new file mode 100644 index 0000000000..91d99775ca --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/suppress-connect-headers.md @@ -0,0 +1,23 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: suppress-connect-headers +Help: Suppress proxy CONNECT response headers +Category: proxy +Added: 7.54.0 +Multi: boolean +See-also: + - dump-header + - show-headers + - proxytunnel +Example: + - --suppress-connect-headers --show-headers -x proxy $URL +--- + +# `--suppress-connect-headers` + +When --proxytunnel is used and a CONNECT request is made, do not output proxy +CONNECT response headers. This option is meant to be used with --dump-header +or --show-headers which are used to show protocol headers in the output. It +has no effect on debug options such as --verbose or --trace, or any +statistics. diff --git a/third-party/curl/docs/cmdline-opts/tcp-fastopen.d b/third-party/curl/docs/cmdline-opts/tcp-fastopen.d deleted file mode 100644 index bcf1edbff5..0000000000 --- a/third-party/curl/docs/cmdline-opts/tcp-fastopen.d +++ /dev/null @@ -1,14 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: tcp-fastopen -Added: 7.49.0 -Help: Use TCP Fast Open -Category: connection -Example: --tcp-fastopen $URL -See-also: false-start -Multi: boolean ---- - -Enable use of TCP Fast Open (RFC 7413). TCP Fast Open is a TCP extension that -allows data to get sent earlier over the connection (before the final -handshake ACK) if the client and server have been connected previously. diff --git a/third-party/curl/docs/cmdline-opts/tcp-fastopen.md b/third-party/curl/docs/cmdline-opts/tcp-fastopen.md new file mode 100644 index 0000000000..7a954d006a --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/tcp-fastopen.md @@ -0,0 +1,19 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: tcp-fastopen +Added: 7.49.0 +Help: Use TCP Fast Open +Category: connection +Multi: boolean +See-also: + - false-start +Example: + - --tcp-fastopen $URL +--- + +# `--tcp-fastopen` + +Enable use of TCP Fast Open (RFC 7413). TCP Fast Open is a TCP extension that +allows data to be sent earlier over the connection (before the final +handshake ACK) if the client and server have been connected previously. diff --git a/third-party/curl/docs/cmdline-opts/tcp-nodelay.d b/third-party/curl/docs/cmdline-opts/tcp-nodelay.d deleted file mode 100644 index 2bf51cb5f4..0000000000 --- a/third-party/curl/docs/cmdline-opts/tcp-nodelay.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: tcp-nodelay -Help: Use the TCP_NODELAY option -Added: 7.11.2 -Category: connection -Example: --tcp-nodelay $URL -See-also: no-buffer -Multi: boolean ---- -Turn on the TCP_NODELAY option. See the *curl_easy_setopt(3)* man page for -details about this option. - -curl sets this option by default and you need to explicitly switch it off if -you do not want it on (added in 7.50.2). diff --git a/third-party/curl/docs/cmdline-opts/tcp-nodelay.md b/third-party/curl/docs/cmdline-opts/tcp-nodelay.md new file mode 100644 index 0000000000..605667181a --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/tcp-nodelay.md @@ -0,0 +1,30 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: tcp-nodelay +Help: Set TCP_NODELAY +Added: 7.11.2 +Category: connection +Multi: boolean +See-also: + - no-buffer +Example: + - --tcp-nodelay $URL +--- + +# `--tcp-nodelay` + +Turn on the TCP_NODELAY option. + +This option disables the Nagle algorithm on TCP connections. The purpose of +this algorithm is to minimize the number of small packets on the network +(where "small packets" means TCP segments less than the Maximum Segment Size +for the network). + +Maximizing the amount of data sent per TCP segment is good because it +amortizes the overhead of the send. In some cases small segments may need to +be sent without delay. This is less efficient than sending larger amounts of +data at a time, and can contribute to congestion on the network if overdone. + +curl sets this option by default and you need to explicitly switch it off if +you do not want it on (added in 7.50.2). diff --git a/third-party/curl/docs/cmdline-opts/telnet-option.d b/third-party/curl/docs/cmdline-opts/telnet-option.d deleted file mode 100644 index 651ce4203e..0000000000 --- a/third-party/curl/docs/cmdline-opts/telnet-option.d +++ /dev/null @@ -1,23 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: telnet-option -Short: t -Arg: -Help: Set telnet option -Category: telnet -Example: -t TTYPE=vt100 telnet://example.com/ -Added: 7.7 -See-also: config -Multi: append ---- -Pass options to the telnet protocol. Supported options are: - -.RS -.TP 15 -**TTYPE**= Sets the terminal type. -.TP -**XDISPLOC**= Sets the X display location. -.TP -**NEW_ENV**= Sets an environment variable. -.RE -.IP diff --git a/third-party/curl/docs/cmdline-opts/telnet-option.md b/third-party/curl/docs/cmdline-opts/telnet-option.md new file mode 100644 index 0000000000..ca82a4ceb8 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/telnet-option.md @@ -0,0 +1,29 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: telnet-option +Short: t +Arg: +Help: Set telnet option +Category: telnet +Protocols: TELNET +Added: 7.7 +Multi: append +See-also: + - config +Example: + - -t TTYPE=vt100 telnet://example.com/ +--- + +# `--telnet-option` + +Pass options to the telnet protocol. Supported options are: + +## `TTYPE=` +Sets the terminal type. + +## `XDISPLOC=` +Sets the X display location. + +## `NEW_ENV=` +Sets an environment variable. diff --git a/third-party/curl/docs/cmdline-opts/tftp-blksize.d b/third-party/curl/docs/cmdline-opts/tftp-blksize.d deleted file mode 100644 index 76c7ee4b13..0000000000 --- a/third-party/curl/docs/cmdline-opts/tftp-blksize.d +++ /dev/null @@ -1,15 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: tftp-blksize -Arg: -Help: Set TFTP BLKSIZE option -Protocols: TFTP -Added: 7.20.0 -Category: tftp -Example: --tftp-blksize 1024 tftp://example.com/file -See-also: tftp-no-options -Multi: single ---- -Set the TFTP **BLKSIZE** option (must be >512). This is the block size that -curl tries to use when transferring data to or from a TFTP server. By -default 512 bytes are used. diff --git a/third-party/curl/docs/cmdline-opts/tftp-blksize.md b/third-party/curl/docs/cmdline-opts/tftp-blksize.md new file mode 100644 index 0000000000..21d8476af0 --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/tftp-blksize.md @@ -0,0 +1,21 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: tftp-blksize +Arg: +Help: Set TFTP BLKSIZE option +Protocols: TFTP +Added: 7.20.0 +Category: tftp +Multi: single +See-also: + - tftp-no-options +Example: + - --tftp-blksize 1024 tftp://example.com/file +--- + +# `--tftp-blksize` + +Set the TFTP **BLKSIZE** option (must be 512 or larger). This is the block +size that curl tries to use when transferring data to or from a TFTP +server. By default 512 bytes are used. diff --git a/third-party/curl/docs/cmdline-opts/tftp-no-options.d b/third-party/curl/docs/cmdline-opts/tftp-no-options.d deleted file mode 100644 index 43b1c00c47..0000000000 --- a/third-party/curl/docs/cmdline-opts/tftp-no-options.d +++ /dev/null @@ -1,16 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: tftp-no-options -Help: Do not send any TFTP options -Protocols: TFTP -Added: 7.48.0 -Category: tftp -Example: --tftp-no-options tftp://192.168.0.1/ -See-also: tftp-blksize -Multi: boolean ---- -Tells curl not to send TFTP options requests. - -This option improves interop with some legacy servers that do not acknowledge -or properly implement TFTP options. When this option is used --tftp-blksize is -ignored. diff --git a/third-party/curl/docs/cmdline-opts/tftp-no-options.md b/third-party/curl/docs/cmdline-opts/tftp-no-options.md new file mode 100644 index 0000000000..27bbe55bba --- /dev/null +++ b/third-party/curl/docs/cmdline-opts/tftp-no-options.md @@ -0,0 +1,20 @@ +--- +c: Copyright (C) Daniel Stenberg, , et al. +SPDX-License-Identifier: curl +Long: tftp-no-options +Help: Do not send any TFTP options +Protocols: TFTP +Added: 7.48.0 +Category: tftp +Multi: boolean +See-also: + - tftp-blksize +Example: + - --tftp-no-options tftp://192.168.0.1/ +--- + +# `--tftp-no-options` + +Do not send TFTP options requests. This improves interop with some legacy +servers that do not acknowledge or properly implement TFTP options. When this +option is used --tftp-blksize is ignored. diff --git a/third-party/curl/docs/cmdline-opts/time-cond.d b/third-party/curl/docs/cmdline-opts/time-cond.d deleted file mode 100644 index c21ed2853b..0000000000 --- a/third-party/curl/docs/cmdline-opts/time-cond.d +++ /dev/null @@ -1,27 +0,0 @@ -c: Copyright (C) Daniel Stenberg, , et al. -SPDX-License-Identifier: curl -Long: time-cond -Short: z -Arg: