nginx 模块支持IPv6

This commit is contained in:
fa1seut0pia 2026-02-09 03:29:43 +08:00
parent e183607da5
commit 7d6ea00303
2 changed files with 334 additions and 100 deletions

View File

@ -4,7 +4,9 @@
#include "ngx_http_ip2region_module.h" #include "ngx_http_ip2region_module.h"
static ngx_int_t ngx_http_ua_parser_test_full_name(char *name); static ngx_int_t ngx_http_ip2region_is_absolute_path(char *name);
static char *ngx_http_ip2region_init_searcher(ngx_conf_t *cf, char *db_name,
char *cache_policy, xdb_version_t *expected_version, const char *directive_name);
static ngx_int_t ngx_http_ip2region_add_variables(ngx_conf_t *cf); static ngx_int_t ngx_http_ip2region_add_variables(ngx_conf_t *cf);
@ -28,6 +30,9 @@ static ngx_http_module_t ngx_http_ip2region_ctx = {
}; };
static char *ngx_http_ip2region_init(ngx_conf_t *cf, ngx_command_t *cmd, void *conf);
static char *ngx_http_ip2region_init_v6(ngx_conf_t *cf, ngx_command_t *cmd, void *conf);
static ngx_command_t ngx_http_ip2region_commands[] = { static ngx_command_t ngx_http_ip2region_commands[] = {
{ ngx_string("ip2region_db"), { ngx_string("ip2region_db"),
NGX_HTTP_MAIN_CONF | NGX_CONF_TAKE12, NGX_HTTP_MAIN_CONF | NGX_CONF_TAKE12,
@ -36,6 +41,13 @@ static ngx_command_t ngx_http_ip2region_commands[] = {
0, 0,
NULL }, NULL },
{ ngx_string("ip2region_db6"),
NGX_HTTP_MAIN_CONF | NGX_CONF_TAKE12,
ngx_http_ip2region_init_v6,
NGX_HTTP_MAIN_CONF_OFFSET,
0,
NULL },
ngx_null_command ngx_null_command
}; };
@ -66,25 +78,168 @@ static ngx_http_variable_t ngx_http_ip2region_vars[] = {
}; };
// 用于初始化带版本校验的搜索器的辅助函数
static char *
ngx_http_ip2region_init_searcher(ngx_conf_t *cf, char *db_name,
char *cache_policy, xdb_version_t *expected_version, const char *directive_name)
{
ip2region_searcher_t *ip2region_searcher;
int err;
char *db_path;
size_t len;
if(ngx_http_ip2region_is_absolute_path(db_name) == NGX_OK) {
db_path = db_name;
} else { // relative path to conf directory
len = ngx_cycle->conf_prefix.len + strlen(db_name) + 1;
db_path = malloc(len);
if (db_path == NULL) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to allocate memory for db_path");
return NGX_CONF_ERROR;
}
memset(db_path, '\0', len);
memcpy(db_path, ngx_cycle->conf_prefix.data, ngx_cycle->conf_prefix.len);
strcat(db_path, db_name);
}
ip2region_searcher = ngx_palloc(cf->pool, sizeof(ip2region_searcher_t));
if(ip2region_searcher == NULL) {
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
ip2region_searcher->v_index = NULL;
ip2region_searcher->c_buffer = NULL;
// 检查XDB文件的版本信息以确定IP类型
xdb_header_t *header = xdb_load_header_from_file(db_path);
if (header == NULL) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to load xdb header from: %s", db_path);
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
xdb_version_t *xdb_version = xdb_version_from_header(header);
if (xdb_version == NULL) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to determine xdb version from header: %s", db_path);
xdb_free_header((void *)header);
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
// 验证XDB文件版本是否匹配
if (xdb_version->id != expected_version->id) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"%s expects %s xdb file, but got %s: %s",
directive_name, expected_version->name, xdb_version->name, db_path);
xdb_free_header((void *)header);
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
if (strcmp(cache_policy, "file") == 0) {
err = xdb_new_with_file_only(xdb_version, &ip2region_searcher->searcher, db_path);
xdb_free_header((void *)header);
if (err != 0) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to create searcher: %s", db_path);
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
} else if (strcmp(cache_policy, "vectorIndex") == 0) {
ip2region_searcher->v_index = xdb_load_vector_index_from_file(db_path);
if (ip2region_searcher->v_index == NULL) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to load vector index from: %s", db_path);
xdb_free_header((void *)header);
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
err = xdb_new_with_vector_index(xdb_version, &ip2region_searcher->searcher, db_path, ip2region_searcher->v_index);
xdb_free_header((void *)header);
if (err != 0) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to create vector index cached searcher: %s", db_path);
xdb_free_vector_index((void *)ip2region_searcher->v_index);
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
} else if (strcmp(cache_policy, "content") == 0) {
ip2region_searcher->c_buffer = xdb_load_content_from_file(db_path);
if (ip2region_searcher->c_buffer == NULL) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to load xdb content: %s", db_path);
xdb_free_header((void *)header);
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
err = xdb_new_with_buffer(xdb_version, &ip2region_searcher->searcher, ip2region_searcher->c_buffer);
xdb_free_header((void *)header);
if (err != 0) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to create content cached searcher: %s", db_path);
xdb_free_content((void *)ip2region_searcher->c_buffer);
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
} else {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"invalid cache policy, options: file/vectorIndex/content");
xdb_free_header((void *)header);
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_ERROR;
}
if(ngx_http_ip2region_is_absolute_path(db_name) != NGX_OK) {
free(db_path);
}
return (char *)ip2region_searcher;
}
static char * static char *
ngx_http_ip2region_init(ngx_conf_t *cf, ngx_command_t *cmd, ngx_http_ip2region_init(ngx_conf_t *cf, ngx_command_t *cmd,
void *conf) void *conf)
{ {
ngx_http_ip2region_conf_t *ip2region_cf; ngx_http_ip2region_conf_t *ip2region_cf;
ip2region_searcher_t *ip2region_searcher;
char *db_name, *cache_policy; char *db_name, *cache_policy;
ngx_str_t *value; ngx_str_t *value;
int err; char *result;
char *db_path;
size_t len;
ip2region_cf = conf; ip2region_cf = conf;
if (ip2region_cf->ip2region_searcher) { if (ip2region_cf->v4_searcher) {
return "is duplicate"; return "ip2region_db is duplicate";
} }
value = cf->args->elts; value = cf->args->elts;
db_name = (char *)value[1].data; db_name = (char *)value[1].data;
// default cache_policy: content // default cache_policy: content
@ -94,71 +249,49 @@ ngx_http_ip2region_init(ngx_conf_t *cf, ngx_command_t *cmd,
cache_policy = (char *)value[2].data; cache_policy = (char *)value[2].data;
} }
if(ngx_http_ua_parser_test_full_name(db_name) == NGX_OK) { result = ngx_http_ip2region_init_searcher(cf, db_name, cache_policy,
db_path = db_name; xdb_version_v4(), "ip2region_db");
} else { // relative path to conf directory if (result == NGX_CONF_ERROR) {
len = ngx_cycle->conf_prefix.len + strlen(db_name) + 1;
db_path = malloc(len);
memset(db_path, '\0', len);
memcpy(db_path, ngx_cycle->conf_prefix.data, ngx_cycle->conf_prefix.len);
strcat(db_path, db_name);
}
ip2region_searcher = ngx_palloc(cf->pool, sizeof(ip2region_searcher_t));
if(ip2region_searcher == NULL) {
return NGX_CONF_ERROR; return NGX_CONF_ERROR;
} }
ip2region_searcher->v_index = NULL; ip2region_cf->v4_searcher = (ip2region_searcher_t *)result;
ip2region_searcher->c_buffer = NULL;
if (strcmp(cache_policy, "file") == 0) { return NGX_CONF_OK;
err = xdb_new_with_file_only(&ip2region_searcher->searcher, db_path); }
if (err != 0) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to create searcher: %s", db_path);
return NGX_CONF_ERROR;
}
} else if (strcmp(cache_policy, "vectorIndex") == 0) {
ip2region_searcher->v_index = xdb_load_vector_index_from_file(db_path);
if (ip2region_searcher->v_index == NULL) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to load vector index from: %s", db_path);
return NGX_CONF_ERROR;
}
err = xdb_new_with_vector_index(&ip2region_searcher->searcher, db_path, ip2region_searcher->v_index); static char *
if (err != 0) { ngx_http_ip2region_init_v6(ngx_conf_t *cf, ngx_command_t *cmd,
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, void *conf)
"failed to create vector index cached searcher: %s", db_path); {
return NGX_CONF_ERROR; ngx_http_ip2region_conf_t *ip2region_cf;
} char *db_name, *cache_policy;
} else if (strcmp(cache_policy, "content") == 0) { ngx_str_t *value;
ip2region_searcher->c_buffer = xdb_load_content_from_file(db_path); char *result;
if (ip2region_searcher->c_buffer == NULL) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0,
"failed to load xdb content: %s", db_path);
return NGX_CONF_ERROR;
}
err = xdb_new_with_buffer(&ip2region_searcher->searcher, ip2region_searcher->c_buffer); ip2region_cf = conf;
if (err != 0) {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, if (ip2region_cf->v6_searcher) {
"failed to create content cached searcher: %s", db_path); return "ip2region_db6 is duplicate";
return NGX_CONF_ERROR; }
}
value = cf->args->elts;
db_name = (char *)value[1].data;
// default cache_policy: content
if(cf->args->nelts == 2) {
cache_policy = "content";
} else { } else {
ngx_conf_log_error(NGX_LOG_EMERG, cf, 0, cache_policy = (char *)value[2].data;
"invalid cache policy `%V`, options: file/vectorIndex/content", &value[2]); }
result = ngx_http_ip2region_init_searcher(cf, db_name, cache_policy,
xdb_version_v6(), "ip2region_db6");
if (result == NGX_CONF_ERROR) {
return NGX_CONF_ERROR; return NGX_CONF_ERROR;
} }
ip2region_cf->ip2region_searcher = ip2region_searcher; ip2region_cf->v6_searcher = (ip2region_searcher_t *)result;
if(ngx_http_ua_parser_test_full_name(db_name) != NGX_OK) {
free(db_path);
}
return NGX_CONF_OK; return NGX_CONF_OK;
} }
@ -212,9 +345,11 @@ ngx_http_ip2region_variable(ngx_http_request_t *r,
{ {
ngx_http_ip2region_conf_t *ip2region_conf; ngx_http_ip2region_conf_t *ip2region_conf;
struct sockaddr_in *sin; struct sockaddr_in *sin;
char region[512] = {'\0'}; char region_buffer[512] = {'\0'};
int err; xdb_region_buffer_t region;
int err = 1;
unsigned int ip; unsigned int ip;
xdb_searcher_t *searcher_ptr = NULL;
#if (NGX_HAVE_INET6) #if (NGX_HAVE_INET6)
u_char *p; u_char *p;
@ -224,47 +359,119 @@ ngx_http_ip2region_variable(ngx_http_request_t *r,
ip2region_conf = ngx_http_get_module_main_conf(r, ngx_http_ip2region_module); ip2region_conf = ngx_http_get_module_main_conf(r, ngx_http_ip2region_module);
if (ip2region_conf->ip2region_searcher != NULL) { if (ip2region_conf->v4_searcher == NULL && ip2region_conf->v6_searcher == NULL) {
v->not_found = 1;
return NGX_OK;
}
switch (r->connection->sockaddr->sa_family) { // 初始化 region buffer
case AF_INET: err = xdb_region_buffer_init(&region, region_buffer, sizeof(region_buffer));
sin = (struct sockaddr_in *) r->connection->sockaddr; if (err != 0) {
ip = htonl(sin->sin_addr.s_addr); v->not_found = 1;
err = xdb_search(&ip2region_conf->ip2region_searcher->searcher, ip, region, sizeof(region)); return NGX_OK;
if (err == 0) { }
v->data = (unsigned char *)region;
v->len = strlen(region); switch (r->connection->sockaddr->sa_family) {
return NGX_OK; case AF_INET:
} sin = (struct sockaddr_in *) r->connection->sockaddr;
// 检查是否有IPv4 searcher
if (ip2region_conf->v4_searcher == NULL) {
ngx_log_error(NGX_LOG_WARN, r->connection->log, 0,
"no IPv4 searcher available for IPv4 address");
break; break;
}
searcher_ptr = &ip2region_conf->v4_searcher->searcher;
// 正确转换IP地址字节序按ip2region期望的格式
ip = ntohl(sin->sin_addr.s_addr); // 将网络字节序转换为主机字节序
// 按照xdb_parse_v4_ip中的格式重新组织字节
{
bytes_ip_t ip_bytes[4];
ip_bytes[0] = (ip >> 24) & 0xFF;
ip_bytes[1] = (ip >> 16) & 0xFF;
ip_bytes[2] = (ip >> 8) & 0xFF;
ip_bytes[3] = ip & 0xFF;
err = xdb_search(searcher_ptr, ip_bytes, 4, &region);
}
if (err == 0) {
v->data = (unsigned char *)region.value;
v->len = strlen(region.value);
xdb_region_buffer_free(&region);
return NGX_OK;
} else {
ngx_log_error(NGX_LOG_WARN, r->connection->log, 0,
"ip2region search failed for IPv4 address");
}
break;
#if (NGX_HAVE_INET6) #if (NGX_HAVE_INET6)
case AF_INET6: case AF_INET6:
sin6 = (struct sockaddr_in6 *) r->connection->sockaddr; sin6 = (struct sockaddr_in6 *) r->connection->sockaddr;
p = sin6->sin6_addr.s6_addr; p = sin6->sin6_addr.s6_addr;
if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) { if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
// 处理IPv4映射的IPv6地址
if (ip2region_conf->v4_searcher != NULL) {
searcher_ptr = &ip2region_conf->v4_searcher->searcher;
addr = p[12] << 24; addr = p[12] << 24;
addr += p[13] << 16; addr += p[13] << 16;
addr += p[14] << 8; addr += p[14] << 8;
addr += p[15]; addr += p[15];
// 按照xdb_parse_v4_ip中的格式重新组织字节
ip = htonl(addr); {
err = xdb_search(&ip2region_conf->ip2region_searcher->searcher, ip, region, sizeof(region)); bytes_ip_t ip_bytes[4];
ip_bytes[0] = (addr >> 24) & 0xFF;
ip_bytes[1] = (addr >> 16) & 0xFF;
ip_bytes[2] = (addr >> 8) & 0xFF;
ip_bytes[3] = addr & 0xFF;
err = xdb_search(searcher_ptr, ip_bytes, 4, &region);
}
if (err == 0) { if (err == 0) {
v->data = (unsigned char *)region; v->data = (unsigned char *)region.value;
v->len = strlen(region); v->len = strlen(region.value);
xdb_region_buffer_free(&region);
return NGX_OK; return NGX_OK;
} else {
ngx_log_error(NGX_LOG_WARN, r->connection->log, 0,
"ip2region search failed for IPv4-mapped IPv6 address");
} }
} }
break; } else {
// 处理纯IPv6地址
if (ip2region_conf->v6_searcher != NULL) {
searcher_ptr = &ip2region_conf->v6_searcher->searcher;
bytes_ip_t ip6_bytes[16];
if (p != NULL) {
memcpy(ip6_bytes, p, 16);
err = xdb_search(searcher_ptr, ip6_bytes, 16, &region);
if (err == 0) {
v->data = (unsigned char *)region.value;
v->len = strlen(region.value);
xdb_region_buffer_free(&region);
return NGX_OK;
} else {
ngx_log_error(NGX_LOG_WARN, r->connection->log, 0,
"ip2region search failed for IPv6 address");
}
}
} else {
ngx_log_error(NGX_LOG_WARN, r->connection->log, 0,
"no IPv6 searcher available for IPv6 address");
}
}
break;
#endif #endif
}
} }
// 如果搜索失败,释放 region buffer
xdb_region_buffer_free(&region);
ngx_log_error(NGX_LOG_INFO, r->connection->log, 0,
"ip2region: no region found for IP address");
v->not_found = 1; v->not_found = 1;
return NGX_OK; return NGX_OK;
} }
@ -275,28 +482,48 @@ ngx_http_ip2region_cleanup(void *data)
{ {
ngx_http_ip2region_conf_t *ip2region_conf = data; ngx_http_ip2region_conf_t *ip2region_conf = data;
if(ip2region_conf->ip2region_searcher != NULL) { // 清理 IPv4 searcher
xdb_close(&ip2region_conf->ip2region_searcher->searcher); if(ip2region_conf->v4_searcher != NULL) {
xdb_close(&ip2region_conf->v4_searcher->searcher);
// check and free the vector index // check and free the vector index
if (ip2region_conf->ip2region_searcher->v_index != NULL) { if (ip2region_conf->v4_searcher->v_index != NULL) {
xdb_close_vector_index(ip2region_conf->ip2region_searcher->v_index); xdb_free_vector_index((void *)ip2region_conf->v4_searcher->v_index);
ip2region_conf->ip2region_searcher->v_index = NULL; ip2region_conf->v4_searcher->v_index = NULL;
} }
// check and free the content buffer // check and free the content buffer
if (ip2region_conf->ip2region_searcher->c_buffer != NULL) { if (ip2region_conf->v4_searcher->c_buffer != NULL) {
xdb_close_content(ip2region_conf->ip2region_searcher->c_buffer); xdb_free_content((void *)ip2region_conf->v4_searcher->c_buffer);
ip2region_conf->ip2region_searcher->c_buffer = NULL; ip2region_conf->v4_searcher->c_buffer = NULL;
} }
ip2region_conf->ip2region_searcher = NULL; ip2region_conf->v4_searcher = NULL;
}
// 清理 IPv6 searcher
if(ip2region_conf->v6_searcher != NULL) {
xdb_close(&ip2region_conf->v6_searcher->searcher);
// check and free the vector index
if (ip2region_conf->v6_searcher->v_index != NULL) {
xdb_free_vector_index((void *)ip2region_conf->v6_searcher->v_index);
ip2region_conf->v6_searcher->v_index = NULL;
}
// check and free the content buffer
if (ip2region_conf->v6_searcher->c_buffer != NULL) {
xdb_free_content((void *)ip2region_conf->v6_searcher->c_buffer);
ip2region_conf->v6_searcher->c_buffer = NULL;
}
ip2region_conf->v6_searcher = NULL;
} }
} }
static ngx_int_t static ngx_int_t
ngx_http_ua_parser_test_full_name(char *name) ngx_http_ip2region_is_absolute_path(char *name)
{ {
#if (NGX_WIN32) #if (NGX_WIN32)
u_char c0, c1; u_char c0, c1;

View File

@ -8,7 +8,13 @@
#include <ngx_config.h> #include <ngx_config.h>
#include <ngx_core.h> #include <ngx_core.h>
#include <ngx_http.h> #include <ngx_http.h>
#include <xdb_searcher.h> #include <xdb_api.h>
#if (NGX_HAVE_INET6)
#include <sys/socket.h>
#include <netinet/in.h>
#include <arpa/inet.h>
#endif
typedef struct { typedef struct {
xdb_searcher_t searcher; xdb_searcher_t searcher;
@ -16,8 +22,9 @@ typedef struct {
xdb_content_t *c_buffer; xdb_content_t *c_buffer;
} ip2region_searcher_t; } ip2region_searcher_t;
typedef struct { typedef struct {
ip2region_searcher_t *ip2region_searcher; ip2region_searcher_t *v4_searcher; // IPv4 searcher for ip2region_db
ip2region_searcher_t *v6_searcher; // IPv6 searcher for ip2region_db6
} ngx_http_ip2region_conf_t; } ngx_http_ip2region_conf_t;
#endif #endif