Go to the documentation of this file.
24 #include <gnutls/gnutls.h>
25 #include <gnutls/dtls.h>
26 #include <gnutls/x509.h>
36 #ifndef GNUTLS_VERSION_NUMBER
37 #define GNUTLS_VERSION_NUMBER LIBGNUTLS_VERSION_NUMBER
40 #if HAVE_THREADS && GNUTLS_VERSION_NUMBER <= 0x020b00
42 GCRY_THREAD_OPTION_PTHREAD_IMPL;
48 gnutls_certificate_credentials_t
cred;
60 #if HAVE_THREADS && GNUTLS_VERSION_NUMBER < 0x020b00
61 if (gcry_control(GCRYCTL_ANY_INITIALIZATION_P) == 0)
62 gcry_control(GCRYCTL_SET_THREAD_CBS, &gcry_threads_pthread);
71 gnutls_global_deinit();
81 case GNUTLS_E_INTERRUPTED:
82 #ifdef GNUTLS_E_PREMATURE_TERMINATION
83 case GNUTLS_E_PREMATURE_TERMINATION:
86 case GNUTLS_E_WARNING_ALERT_RECEIVED:
106 if (
c->need_shutdown)
107 gnutls_bye(
c->session, GNUTLS_SHUT_WR);
109 gnutls_deinit(
c->session);
111 gnutls_certificate_free_credentials(
c->cred);
112 if (!
s->external_sock)
119 void *buf,
size_t len)
126 if (
s->is_dtls &&
s->listen && !
c->dest_addr_len) {
151 const void *buf,
size_t len)
182 FD_SET(sockfd, &rfds);
184 tv.tv_sec = ms / 1000;
185 tv.tv_usec = (ms % 1000) * 1000;
208 ret = gnutls_handshake(
c->session);
209 if (gnutls_error_is_fatal(
ret)) {
223 uint16_t gnutls_flags = 0;
232 gnutls_flags |= GNUTLS_DATAGRAM;
235 gnutls_flags |= GNUTLS_SERVER;
237 gnutls_flags |= GNUTLS_CLIENT;
238 gnutls_init(&
c->session, gnutls_flags);
239 if (!
s->listen && !
s->numerichost)
240 gnutls_server_name_set(
c->session, GNUTLS_NAME_DNS,
s->host, strlen(
s->host));
241 gnutls_certificate_allocate_credentials(&
c->cred);
243 ret = gnutls_certificate_set_x509_trust_file(
c->cred,
s->ca_file, GNUTLS_X509_FMT_PEM);
247 #if GNUTLS_VERSION_NUMBER >= 0x030020
249 gnutls_certificate_set_x509_system_trust(
c->cred);
251 gnutls_certificate_set_verify_flags(
c->cred,
s->verify ?
252 GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT : 0);
253 if (
s->cert_file &&
s->key_file) {
254 ret = gnutls_certificate_set_x509_key_file(
c->cred,
255 s->cert_file,
s->key_file,
256 GNUTLS_X509_FMT_PEM);
259 "Unable to set cert/key files %s and %s: %s\n",
260 s->cert_file,
s->key_file, gnutls_strerror(
ret));
264 }
else if (
s->cert_file ||
s->key_file)
266 gnutls_credentials_set(
c->session, GNUTLS_CRD_CERTIFICATE,
c->cred);
269 gnutls_transport_set_ptr(
c->session,
c);
273 gnutls_dtls_set_mtu(
c->session,
s->mtu);
275 gnutls_set_default_priority(
c->session);
279 c->need_shutdown = 1;
281 unsigned int status, cert_list_size;
282 gnutls_x509_crt_t cert;
283 const gnutls_datum_t *cert_list;
284 if ((
ret = gnutls_certificate_verify_peers2(
c->session, &
status)) < 0) {
286 gnutls_strerror(
ret));
290 if (
status & GNUTLS_CERT_INVALID) {
295 if (gnutls_certificate_type_get(
c->session) != GNUTLS_CRT_X509) {
300 gnutls_x509_crt_init(&cert);
301 cert_list = gnutls_certificate_get_peers(
c->session, &cert_list_size);
302 gnutls_x509_crt_import(cert, cert_list, GNUTLS_X509_FMT_DER);
303 ret = gnutls_x509_crt_check_hostname(cert,
s->host);
304 gnutls_x509_crt_deinit(cert);
307 "The certificate's owner does not match hostname %s\n",
s->host);
336 ret = gnutls_record_recv(
c->session, buf,
size);
353 ret = gnutls_record_send(
c->session, buf,
size);
void ff_gnutls_init(void)
#define AV_LOG_WARNING
Something somehow does not look correct.
Filter the word “frame” indicates either a video frame or a group of audio as stored in an AVFrame structure Format for each input and each output the list of supported formats For video that means pixel format For audio that means channel sample they are references to shared objects When the negotiation mechanism computes the intersection of the formats supported at each end of a all references to both lists are replaced with a reference to the intersection And when a single format is eventually chosen for a link amongst the remaining all references to the list are updated That means that if a filter requires that its input and output have the same format amongst a supported all it has to do is use a reference to the same list of formats query_formats can leave some formats unset and return AVERROR(EAGAIN) to cause the negotiation mechanism toagain later. That can be used by filters with complex requirements to use the format negotiated on one link to set the formats supported on another. Frame references ownership and permissions
#define URL_PROTOCOL_FLAG_NETWORK
static ssize_t gnutls_url_pull(gnutls_transport_ptr_t transport, void *buf, size_t len)
#define AVERROR_EOF
End of file.
static int ffurl_write(URLContext *h, const uint8_t *buf, int size)
Write size bytes from buf to the resource accessed by h.
static int print_tls_error(URLContext *h, int ret)
static const AVClass tls_class
static int tls_write(URLContext *h, const uint8_t *buf, int size)
static int ff_mutex_unlock(AVMutex *mutex)
gnutls_certificate_credentials_t cred
#define TLS_COMMON_OPTIONS(pstruct, options_field)
int ffurl_get_short_seek(void *urlcontext)
Return the current short seek threshold value for this URL.
static AVMutex gnutls_mutex
int ff_check_interrupt(AVIOInterruptCB *cb)
Check if the user has requested to interrupt a blocking function associated with cb.
#define AV_LOG_TRACE
Extremely verbose debugging, useful for libav* development.
static int tls_open(URLContext *h, const char *uri, int flags, AVDictionary **options)
#define AV_LOG_ERROR
Something went wrong and cannot losslessly be recovered.
static const AVClass dtls_class
static int tls_close(URLContext *h)
int ff_udp_set_remote_addr(URLContext *h, const struct sockaddr *dest_addr, socklen_t dest_addr_len, int do_connect)
This function is identical to ff_udp_set_remote_url, except that it takes a sockaddr directly.
#define LIBAVUTIL_VERSION_INT
Describe the class of an AVClass context structure.
const char * av_default_item_name(void *ptr)
Return the context name.
void ff_udp_get_last_recv_addr(URLContext *h, struct sockaddr_storage *addr, socklen_t *addr_len)
Undefined Behavior In the C some operations are like signed integer dereferencing freed accessing outside allocated Undefined Behavior must not occur in a C it is not safe even if the output of undefined operations is unused The unsafety may seem nit picking but Optimizing compilers have in fact optimized code on the assumption that no undefined Behavior occurs Optimizing code based on wrong assumptions can and has in some cases lead to effects beyond the output of computations The signed integer overflow problem in speed critical code Code which is highly optimized and works with signed integers sometimes has the problem that often the output of the computation does not c
#define av_err2str(errnum)
Convenience macro, the return value should be used only directly in function arguments but never stan...
#define AV_MUTEX_INITIALIZER
static int tls_get_file_handle(URLContext *h)
static ssize_t gnutls_url_push(gnutls_transport_ptr_t transport, const void *buf, size_t len)
static int ff_mutex_lock(AVMutex *mutex)
struct sockaddr_storage dest_addr
static int tls_handshake(URLContext *h)
static int tls_get_short_seek(URLContext *h)
static int dtls_open(URLContext *h, const char *uri, int flags, AVDictionary **options)
const URLProtocol ff_tls_protocol
int ffurl_closep(URLContext **hh)
Close the resource accessed by the URLContext h, and free the memory used by it.
int ff_tls_open_underlying(TLSShared *c, URLContext *parent, const char *uri, AVDictionary **options)
const char * class_name
The name of the class; usually it is the same name as the context structure type to which the AVClass...
const URLProtocol ff_dtls_protocol
static const AVOption options[]
static int gnutls_pull_timeout(gnutls_transport_ptr_t ptr, unsigned int ms)
static int tls_read(URLContext *h, uint8_t *buf, int size)
#define AVIO_FLAG_NONBLOCK
Use non-blocking mode.
#define AVERROR_EXIT
Immediate exit was requested; the called function should not be restarted.
void ff_gnutls_deinit(void)
int ffurl_get_file_handle(URLContext *h)
Return the file descriptor associated with this URL.
static int ffurl_read(URLContext *h, uint8_t *buf, int size)
Read up to size bytes from the resource accessed by h, and store the read bytes in buf.