* | Inspire Internet Relay Chat Daemon |
* +------------------------------------+
*
- * InspIRCd is copyright (C) 2002-2006 ChatSpike-Dev.
- * E-mail:
- * <brain@chatspike.net>
- * <Craig@chatspike.net>
- *
- * Written by Craig Edwards, Craig McLure, and others.
+ * InspIRCd: (C) 2002-2007 InspIRCd Development Team
+ * See: http://www.inspircd.org/wiki/index.php/Credits
+ *
* This program is free but copyrighted software; see
- * the file COPYING for details.
+ * the file COPYING for details.
*
* ---------------------------------------------------
*/
/*
dns.cpp - Nonblocking DNS functions.
-Very loosely based on the firedns library,
-Copyright (C) 2002 Ian Gulliver.
-
-There have been so many modifications to this file
-to make it fit into InspIRCd and make it object
-orientated that you should not take this code as
-being what firedns really looks like. It used to
-look very different to this! :-P
+Very very loosely based on the firedns library,
+Copyright (C) 2002 Ian Gulliver. This file is no
+longer anything like firedns, there are many major
+differences between this code and the original.
+Please do not assume that firedns works like this,
+looks like this, walks like this or tastes like this.
*/
-using namespace std;
-
-#include <string>
-#include <stdlib.h>
-#include <time.h>
#include <sys/types.h>
#include <sys/socket.h>
-#include <sys/time.h>
-#include <string.h>
-#include <unistd.h>
-#include <stdio.h>
#include <errno.h>
-#include <fcntl.h>
-#include <poll.h>
-#include <sys/types.h>
-#include <sys/socket.h>
#include <netinet/in.h>
#include <arpa/inet.h>
-#include <map>
-#include <algorithm>
#include "dns.h"
#include "inspircd.h"
-#include "helperfuncs.h"
-#include "inspircd_config.h"
#include "socketengine.h"
#include "configreader.h"
+#include "socket.h"
-extern InspIRCd* ServerInstance;
-extern ServerConfig* Config;
-extern time_t TIME;
-extern userrec* fd_ref_table[MAX_DESCRIPTORS];
+using irc::sockets::insp_sockaddr;
+using irc::sockets::insp_inaddr;
+using irc::sockets::insp_ntoa;
+using irc::sockets::insp_aton;
-enum QueryType { DNS_QRY_A = 1, DNS_QRY_PTR = 12 };
-enum QueryFlags1 { FLAGS1_MASK_RD = 0x01, FLAGS1_MASK_TC = 0x02, FLAGS1_MASK_AA = 0x04, FLAGS1_MASK_OPCODE = 0x78, FLAGS1_MASK_QR = 0x80 };
-enum QueryFlags2 { FLAGS2_MASK_RCODE = 0x0F, FLAGS2_MASK_Z = 0x70, FLAGS2_MASK_RA = 0x80 };
-
-class s_connection;
-
-typedef std::map<int,s_connection*> connlist;
-typedef connlist::iterator connlist_iter;
+/** Masks to mask off the responses we get from the DNSRequest methods
+ */
+enum QueryInfo
+{
+ ERROR_MASK = 0x10000 /* Result is an error */
+};
-DNS* Res = NULL;
+/** Flags which can be ORed into a request or reply for different meanings
+ */
+enum QueryFlags
+{
+ FLAGS_MASK_RD = 0x01, /* Recursive */
+ FLAGS_MASK_TC = 0x02,
+ FLAGS_MASK_AA = 0x04, /* Authoritative */
+ FLAGS_MASK_OPCODE = 0x78,
+ FLAGS_MASK_QR = 0x80,
+ FLAGS_MASK_RCODE = 0x0F, /* Request */
+ FLAGS_MASK_Z = 0x70,
+ FLAGS_MASK_RA = 0x80
+};
-connlist connections;
-int master_socket = -1;
-Resolver* dns_classes[65536];
-insp_inaddr myserver;
-class s_rr_middle
+/** Represents a dns resource record (rr)
+ */
+class ResourceRecord
{
public:
- QueryType type;
- unsigned int _class;
- unsigned long ttl;
- unsigned int rdlength;
+ QueryType type; /* Record type */
+ unsigned int rr_class; /* Record class */
+ unsigned long ttl; /* Time to live */
+ unsigned int rdlength; /* Record length */
};
-class s_header
+/** Represents a dns request/reply header, and its payload as opaque data.
+ */
+class DNSHeader
{
public:
- unsigned char id[2];
- unsigned int flags1;
- unsigned int flags2;
+ unsigned char id[2]; /* Request id */
+ unsigned int flags1; /* Flags */
+ unsigned int flags2; /* Flags */
unsigned int qdcount;
- unsigned int ancount;
- unsigned int nscount;
+ unsigned int ancount; /* Answer count */
+ unsigned int nscount; /* Nameserver count */
unsigned int arcount;
- unsigned char payload[512];
+ unsigned char payload[512]; /* Packet payload */
};
-class s_connection
+class DNSRequest
{
public:
- unsigned char id[2];
- unsigned char res[512];
- unsigned int _class;
- QueryType type;
+ unsigned char id[2]; /* Request id */
+ unsigned char* res; /* Result processing buffer */
+ unsigned int rr_class; /* Request class */
+ QueryType type; /* Request type */
+ insp_inaddr myserver; /* DNS server address*/
+ DNS* dnsobj; /* DNS caller (where we get our FD from) */
+
+ DNSRequest(InspIRCd* Instance, DNS* dns, insp_inaddr server, int id);
+ ~DNSRequest();
+ DNSInfo ResultIsReady(DNSHeader &h, int length);
+ int SendRequests(const DNSHeader *header, const int length, QueryType qt);
+};
- s_connection()
+class RequestTimeout : public InspTimer
+{
+ InspIRCd* ServerInstance;
+ DNSRequest* watch;
+ int watchid;
+ public:
+ RequestTimeout(unsigned long n, InspIRCd* SI, DNSRequest* watching, int id) : InspTimer(n, time(NULL)), ServerInstance(SI), watch(watching), watchid(id)
{
- *res = 0;
+ ServerInstance->Log(DEBUG, "New DNS timeout set on %08x", watching);
}
- unsigned char* result_ready(s_header &h, int length);
- int send_requests(const s_header *h, const int l, QueryType qt);
+ void Tick(time_t TIME)
+ {
+ if (ServerInstance->Res->requests[watchid] == watch)
+ {
+ /* Still exists, whack it */
+ if (ServerInstance->Res->Classes[watchid])
+ {
+ ServerInstance->Res->Classes[watchid]->OnError(RESOLVER_TIMEOUT, "Request timed out");
+ delete ServerInstance->Res->Classes[watchid];
+ ServerInstance->Res->Classes[watchid] = NULL;
+ }
+ ServerInstance->Res->requests[watchid] = NULL;
+ delete watch;
+ ServerInstance->Log(DEBUG, "DNS timeout on %08x squished pointer", watch);
+ return;
+ }
+ ServerInstance->Log(DEBUG, "DNS timeout on %08x: result already received!", watch);
+ }
};
-
-
-void *dns_align(void *inp)
+/* Allocate the processing buffer */
+DNSRequest::DNSRequest(InspIRCd* Instance, DNS* dns, insp_inaddr server, int id) : dnsobj(dns)
{
- char *p = (char*)inp;
- int offby = ((char *)p - (char *)0) % (sizeof(void *) > sizeof(long) ? sizeof(void *) : sizeof(long));
- if (offby != 0)
- return p + ((sizeof(void *) > sizeof(long) ? sizeof(void *) : sizeof(long)) - offby);
- else
- return p;
+ res = new unsigned char[512];
+ *res = 0;
+ memcpy(&myserver, &server, sizeof(insp_inaddr));
+ RequestTimeout* RT = new RequestTimeout(Instance->Config->dns_timeout ? Instance->Config->dns_timeout : 5, Instance, this, id);
+ Instance->Timers->AddTimer(RT); /* The timer manager frees this */
}
-/*
- * Optimized by brain, these were using integer division and modulus.
- * We can use logic shifts and logic AND to replace these even divisions
- * and multiplications, it should be a bit faster (probably not noticably,
- * but of course, more impressive). Also made these inline.
- */
+/* Deallocate the processing buffer */
+DNSRequest::~DNSRequest()
+{
+ delete[] res;
+}
-inline void dns_fill_rr(s_rr_middle* rr, const unsigned char *input)
+/** Fill a ResourceRecord class based on raw data input */
+inline void DNS::FillResourceRecord(ResourceRecord* rr, const unsigned char *input)
{
rr->type = (QueryType)((input[0] << 8) + input[1]);
- rr->_class = (input[2] << 8) + input[3];
+ rr->rr_class = (input[2] << 8) + input[3];
rr->ttl = (input[4] << 24) + (input[5] << 16) + (input[6] << 8) + input[7];
rr->rdlength = (input[8] << 8) + input[9];
}
-inline void dns_fill_header(s_header *header, const unsigned char *input, const int l)
+/** Fill a DNSHeader class based on raw data input of a given length */
+inline void DNS::FillHeader(DNSHeader *header, const unsigned char *input, const int length)
{
header->id[0] = input[0];
header->id[1] = input[1];
header->ancount = (input[6] << 8) + input[7];
header->nscount = (input[8] << 8) + input[9];
header->arcount = (input[10] << 8) + input[11];
- memcpy(header->payload,&input[12],l);
+ memcpy(header->payload,&input[12],length);
}
-inline void dns_empty_header(unsigned char *output, const s_header *header, const int l)
+/** Empty a DNSHeader class out into raw data, ready for transmission */
+inline void DNS::EmptyHeader(unsigned char *output, const DNSHeader *header, const int length)
{
output[0] = header->id[0];
output[1] = header->id[1];
output[9] = header->nscount & 0xFF;
output[10] = header->arcount >> 8;
output[11] = header->arcount & 0xFF;
- memcpy(&output[12],header->payload,l);
+ memcpy(&output[12],header->payload,length);
}
-
-int s_connection::send_requests(const s_header *h, const int l, QueryType qt)
+/** Send requests we have previously built down the UDP socket */
+int DNSRequest::SendRequests(const DNSHeader *header, const int length, QueryType qt)
{
insp_sockaddr addr;
- unsigned char payload[sizeof(s_header)];
+ unsigned char payload[sizeof(DNSHeader)];
- this->_class = 1;
+ this->rr_class = 1;
this->type = qt;
- dns_empty_header(payload,h,l);
+ DNS::EmptyHeader(payload,header,length);
memset(&addr,0,sizeof(addr));
#ifdef IPV6
memcpy(&addr.sin6_addr,&myserver,sizeof(addr.sin6_addr));
addr.sin6_family = AF_FAMILY;
- addr.sin6_port = htons(53);
+ addr.sin6_port = htons(DNS::QUERY_PORT);
#else
memcpy(&addr.sin_addr.s_addr,&myserver,sizeof(addr.sin_addr));
addr.sin_family = AF_FAMILY;
- addr.sin_port = htons(53);
+ addr.sin_port = htons(DNS::QUERY_PORT);
#endif
- if (sendto(master_socket, payload, l + 12, 0, (sockaddr *) &addr, sizeof(addr)) == -1)
- {
- log(DEBUG,"Error in sendto!");
+ if (sendto(dnsobj->GetFd(), payload, length + 12, 0, (sockaddr *) &addr, sizeof(addr)) == -1)
return -1;
- }
return 0;
}
-s_connection* dns_add_query(s_header *h, int &id)
+/** Add a query with a predefined header, and allocate an ID for it. */
+DNSRequest* DNS::AddQuery(DNSHeader *header, int &id)
{
-
- id = rand() % 65536;
- s_connection * s = new s_connection();
-
- h->id[0] = s->id[0] = id >> 8;
- h->id[1] = s->id[1] = id & 0xFF;
- h->flags1 = 0 | FLAGS1_MASK_RD;
- h->flags2 = 0;
- h->qdcount = 1;
- h->ancount = 0;
- h->nscount = 0;
- h->arcount = 0;
-
- if (connections.find(id) == connections.end())
- connections[id] = s;
- return s;
+ /* Is the DNS connection down? */
+ if (this->GetFd() == -1)
+ return NULL;
+
+ /* Create an id */
+ id = this->PRNG() & DNS::MAX_REQUEST_ID;
+
+ /* If this id is already 'in flight', pick another. */
+ while (requests[id])
+ id = this->PRNG() & DNS::MAX_REQUEST_ID;
+
+ DNSRequest* req = new DNSRequest(ServerInstance, this, this->myserver, id);
+
+ header->id[0] = req->id[0] = id >> 8;
+ header->id[1] = req->id[1] = id & 0xFF;
+ header->flags1 = FLAGS_MASK_RD;
+ header->flags2 = 0;
+ header->qdcount = 1;
+ header->ancount = 0;
+ header->nscount = 0;
+ header->arcount = 0;
+
+ /* At this point we already know the id doesnt exist,
+ * so there needs to be no second check for the ::end()
+ */
+ requests[id] = req;
+
+ /* According to the C++ spec, new never returns NULL. */
+ return req;
}
-void create_socket()
+/** Initialise the DNS UDP socket so that we can send requests */
+DNS::DNS(InspIRCd* Instance) : ServerInstance(Instance)
{
- log(DEBUG,"---- BEGIN DNS INITIALIZATION, SERVER=%s ---",Config->DNSServer);
+ ServerInstance->Log(DEBUG,"DNS::DNS: Instance = %08x",Instance);
+
insp_inaddr addr;
- srand((unsigned int) TIME);
+
+ /* Clear the Resolver class table */
+ memset(Classes,0,sizeof(Classes));
+
+ /* Clear the requests class table */
+ memset(requests,0,sizeof(requests));
+
+ /* Set the id of the next request to 0
+ */
+ currid = 0;
+
+ /* By default we're not munging ip's
+ */
+ ip6munge = false;
+
+ /* Clear the namesever address */
memset(&myserver,0,sizeof(insp_inaddr));
- if (insp_aton(Config->DNSServer,&addr) > 0)
+
+ /* Convert the nameserver address into an insp_inaddr */
+ if (insp_aton(ServerInstance->Config->DNSServer,&addr) > 0)
+ {
memcpy(&myserver,&addr,sizeof(insp_inaddr));
+ if ((strstr(ServerInstance->Config->DNSServer,"::ffff:") == (char*)&ServerInstance->Config->DNSServer) || (strstr(ServerInstance->Config->DNSServer,"::FFFF:") == (char*)&ServerInstance->Config->DNSServer))
+ {
+ /* These dont come back looking like they did when they went in.
+ * We're forced to turn some checks off.
+ * If anyone knows how to fix this, let me know. --Brain
+ */
+ ServerInstance->Log(DEFAULT,"WARNING: Using IPv4 addresses over IPv6 forces some DNS checks to be disabled.");
+ ServerInstance->Log(DEFAULT," This should not cause a problem, however it is recommended you migrate");
+ ServerInstance->Log(DEFAULT," to a true IPv6 environment.");
+ this->ip6munge = true;
+ }
+ ServerInstance->Log(DEBUG,"Added nameserver '%s'",ServerInstance->Config->DNSServer);
+ }
+ else
+ {
+ ServerInstance->Log(DEBUG,"GACK! insp_aton says the nameserver '%s' is invalid!",ServerInstance->Config->DNSServer);
+ }
- master_socket = socket(PF_PROTOCOL, SOCK_DGRAM, 0);
- if (master_socket != -1)
+ /* Initialize mastersocket */
+ this->SetFd(socket(PF_PROTOCOL, SOCK_DGRAM, 0));
+ if (this->GetFd() != -1)
{
- log(DEBUG,"Set query socket nonblock");
- if (fcntl(master_socket, F_SETFL, O_NONBLOCK) != 0)
+ /* Did it succeed? */
+ if (fcntl(this->GetFd(), F_SETFL, O_NONBLOCK) != 0)
{
- shutdown(master_socket,2);
- close(master_socket);
- master_socket = -1;
+ /* Couldn't make the socket nonblocking */
+ shutdown(this->GetFd(),2);
+ close(this->GetFd());
+ this->SetFd(-1);
}
}
- if (master_socket != -1)
+ else
+ {
+ ServerInstance->Log(DEBUG,"I cant socket() this socket! (%s)",strerror(errno));
+ }
+ /* Have we got a socket and is it nonblocking? */
+ if (this->GetFd() != -1)
{
#ifdef IPV6
insp_sockaddr addr;
memset(&addr,0,sizeof(addr));
addr.sin6_family = AF_FAMILY;
addr.sin6_port = 0;
- memset(&addr.sin6_addr,255,sizeof(in6_addr));
+ addr.sin6_addr = in6addr_any;
#else
insp_sockaddr addr;
memset(&addr,0,sizeof(addr));
addr.sin_port = 0;
addr.sin_addr.s_addr = INADDR_ANY;
#endif
- log(DEBUG,"Binding query port");
- if (bind(master_socket,(sockaddr *)&addr,sizeof(addr)) != 0)
+ /* Bind the port */
+ if (bind(this->GetFd(),(sockaddr *)&addr,sizeof(addr)) != 0)
{
- log(DEBUG,"Cant bind with source port = 0");
- shutdown(master_socket,2);
- close(master_socket);
- master_socket = -1;
+ /* Failed to bind */
+ ServerInstance->Log(DEBUG,"Cant bind DNS fd");
+ shutdown(this->GetFd(),2);
+ close(this->GetFd());
+ this->SetFd(-1);
}
- if (master_socket >= 0)
+ if (this->GetFd() >= 0)
{
- log(DEBUG,"Attach query port to socket engine");
+ ServerInstance->Log(DEBUG,"Add master socket %d",this->GetFd());
+ /* Hook the descriptor into the socket engine */
if (ServerInstance && ServerInstance->SE)
- ServerInstance->SE->AddFd(master_socket,true,X_ESTAB_DNS);
+ {
+ if (!ServerInstance->SE->AddFd(this))
+ {
+ ServerInstance->Log(DEFAULT,"Internal error starting DNS - hostnames will NOT resolve.");
+ shutdown(this->GetFd(),2);
+ close(this->GetFd());
+ this->SetFd(-1);
+ }
+ }
}
}
}
-int dns_build_query_payload(const char * const name, const unsigned short rr, const unsigned short _class, unsigned char * const payload)
+/** Build a payload to be placed after the header, based upon input data, a resource type, a class and a pointer to a buffer */
+int DNS::MakePayload(const char * const name, const QueryType rr, const unsigned short rr_class, unsigned char * const payload)
{
- short payloadpos;
- const char * tempchr, * tempchr2;
- unsigned short l;
-
- payloadpos = 0;
- tempchr2 = name;
+ short payloadpos = 0;
+ const char* tempchr, *tempchr2 = name;
+ unsigned short length;
/* split name up into labels, create query */
while ((tempchr = strchr(tempchr2,'.')) != NULL)
{
- l = tempchr - tempchr2;
- if (payloadpos + l + 1 > 507)
+ length = tempchr - tempchr2;
+ if (payloadpos + length + 1 > 507)
return -1;
- payload[payloadpos++] = l;
- memcpy(&payload[payloadpos],tempchr2,l);
- payloadpos += l;
+ payload[payloadpos++] = length;
+ memcpy(&payload[payloadpos],tempchr2,length);
+ payloadpos += length;
tempchr2 = &tempchr[1];
}
- l = strlen(tempchr2);
- if (l)
+ length = strlen(tempchr2);
+ if (length)
{
- if (payloadpos + l + 2 > 507)
+ if (payloadpos + length + 2 > 507)
return -1;
- payload[payloadpos++] = l;
- memcpy(&payload[payloadpos],tempchr2,l);
- payloadpos += l;
- payload[payloadpos++] = '\0';
+ payload[payloadpos++] = length;
+ memcpy(&payload[payloadpos],tempchr2,length);
+ payloadpos += length;
+ payload[payloadpos++] = 0;
}
if (payloadpos > 508)
return -1;
- l = htons(rr);
- memcpy(&payload[payloadpos],&l,2);
- l = htons(_class);
- memcpy(&payload[payloadpos + 2],&l,2);
+ length = htons(rr);
+ memcpy(&payload[payloadpos],&length,2);
+ length = htons(rr_class);
+ memcpy(&payload[payloadpos + 2],&length,2);
return payloadpos + 4;
}
-int DNS::dns_getip4(const char *name)
+/** Start lookup of an hostname to an IP address */
+int DNS::GetIP(const char *name)
{
- /* build, add and send A query; retrieve result with dns_getresult() */
- s_header h;
- s_connection *s;
- int l;
+ DNSHeader h;
int id;
+ int length;
- l = dns_build_query_payload(name,DNS_QRY_A,1,(unsigned char *)&h.payload);
- if (l == -1)
- return -1;
- s = dns_add_query(&h, id);
- if (s == NULL)
+ if ((length = this->MakePayload(name, DNS_QUERY_A, 1, (unsigned char*)&h.payload)) == -1)
return -1;
- if (s->send_requests(&h,l,DNS_QRY_A) == -1)
+ DNSRequest* req = this->AddQuery(&h, id);
+
+ if ((!req) || (req->SendRequests(&h, length, DNS_QUERY_A) == -1))
return -1;
return id;
}
-int DNS::dns_getname4(const insp_inaddr *ip)
-{ /* build, add and send PTR query; retrieve result with dns_getresult() */
-#ifdef IPV6
- return -1;
-#else
- log(DEBUG,"DNS::dns_getname4");
- char query[512];
- s_header h;
- s_connection * s;
- unsigned char *c;
- int l;
+/** Start lookup of an hostname to an IPv6 address */
+int DNS::GetIP6(const char *name)
+{
+ DNSHeader h;
int id;
+ int length;
- c = (unsigned char *)&ip->s_addr;
+ if ((length = this->MakePayload(name, DNS_QUERY_AAAA, 1, (unsigned char*)&h.payload)) == -1)
+ return -1;
- sprintf(query,"%d.%d.%d.%d.in-addr.arpa",c[3],c[2],c[1],c[0]);
+ DNSRequest* req = this->AddQuery(&h, id);
- l = dns_build_query_payload(query,DNS_QRY_PTR,1,(unsigned char *)&h.payload);
- if (l == -1)
+ if ((!req) || (req->SendRequests(&h, length, DNS_QUERY_AAAA) == -1))
return -1;
- s = dns_add_query(&h, id);
- if (s == NULL)
+
+ return id;
+}
+
+/** Start lookup of a cname to another name */
+int DNS::GetCName(const char *alias)
+{
+ DNSHeader h;
+ int id;
+ int length;
+
+ if ((length = this->MakePayload(alias, DNS_QUERY_CNAME, 1, (unsigned char*)&h.payload)) == -1)
return -1;
- if (s->send_requests(&h,l,DNS_QRY_PTR) == -1)
+
+ DNSRequest* req = this->AddQuery(&h, id);
+
+ if ((!req) || (req->SendRequests(&h, length, DNS_QUERY_CNAME) == -1))
return -1;
return id;
-#endif
}
-/* Return the next id which is ready, and the result attached to it
- */
-DNSResult DNS::dns_getresult()
+/** Start lookup of an IP address to a hostname */
+int DNS::GetName(const insp_inaddr *ip)
{
- /* retrieve result of DNS query (buffered) */
- s_header h;
- s_connection *c;
+ char query[128];
+ DNSHeader h;
+ int id;
int length;
- unsigned char buffer[sizeof(s_header)];
- length = recv(master_socket,buffer,sizeof(s_header),0);
+#ifdef IPV6
+ unsigned char* c = (unsigned char*)&ip->s6_addr;
+ if (c[0] == 0 && c[1] == 0 && c[2] == 0 && c[3] == 0 &&
+ c[4] == 0 && c[5] == 0 && c[6] == 0 && c[7] == 0 &&
+ c[8] == 0 && c[9] == 0 && c[10] == 0xFF && c[11] == 0xFF)
+ sprintf(query,"%d.%d.%d.%d.in-addr.arpa",c[15],c[14],c[13],c[12]);
+ else
+ DNS::MakeIP6Int(query, (in6_addr*)ip);
+#else
+ unsigned char* c = (unsigned char*)&ip->s_addr;
+ sprintf(query,"%d.%d.%d.%d.in-addr.arpa",c[3],c[2],c[1],c[0]);
+#endif
- if (length < 12)
- return std::make_pair(-1,"");
+ if ((length = this->MakePayload(query, DNS_QUERY_PTR, 1, (unsigned char*)&h.payload)) == -1)
+ return -1;
- dns_fill_header(&h,buffer,length - 12);
-
- // Get the id of this request
- unsigned long this_id = h.id[1] + (h.id[0] << 8);
-
- // Do we have a pending request for it?
-
- connlist_iter n_iter = connections.find(this_id);
- if (n_iter == connections.end())
- {
- log(DEBUG,"DNS: got a response for a query we didnt send with fd=%d queryid=%d",master_socket,this_id);
- return std::make_pair(-1,"");
- }
- else
- {
- /* Remove the query from the list */
- c = (s_connection*)n_iter->second;
- /* We don't delete c here, because its done later when needed */
- connections.erase(n_iter);
- }
- unsigned char* a = c->result_ready(h, length);
- std::string resultstr;
+ DNSRequest* req = this->AddQuery(&h, id);
+
+ if ((!req) || (req->SendRequests(&h, length, DNS_QUERY_PTR) == -1))
+ return -1;
+
+ return id;
+}
- if (a == NULL)
+/** Start lookup of an IP address to a hostname */
+int DNS::GetNameForce(const char *ip, ForceProtocol fp)
+{
+ char query[128];
+ DNSHeader h;
+ int id;
+ int length;
+#ifdef SUPPORT_IP6LINKS
+ if (fp == PROTOCOL_IPV6)
{
- resultstr = "";
+ in6_addr i;
+ if (inet_pton(AF_INET6, ip, &i) > 0)
+ {
+ DNS::MakeIP6Int(query, &i);
+ }
+ else
+ /* Invalid IP address */
+ return -1;
}
else
+#endif
{
- if (c->type == DNS_QRY_A)
+ in_addr i;
+ if (inet_aton(ip, &i))
{
- char formatted[1024];
- snprintf(formatted,1024,"%u.%u.%u.%u",a[0],a[1],a[2],a[3]);
- resultstr = std::string(formatted);
+ unsigned char* c = (unsigned char*)&i.s_addr;
+ sprintf(query,"%d.%d.%d.%d.in-addr.arpa",c[3],c[2],c[1],c[0]);
}
else
- {
- resultstr = std::string((const char*)a);
- }
+ /* Invalid IP address */
+ return -1;
}
- delete c;
- return std::make_pair(this_id,resultstr);
+ ServerInstance->Log(DEBUG,"DNS::GetNameForce: %s %d",query, fp);
+
+ if ((length = this->MakePayload(query, DNS_QUERY_PTR, 1, (unsigned char*)&h.payload)) == -1)
+ return -1;
+
+ DNSRequest* req = this->AddQuery(&h, id);
+
+ if ((!req) || (req->SendRequests(&h, length, DNS_QUERY_PTR) == -1))
+ return -1;
+
+ return id;
}
-/** A result is ready, process it
+/** Build an ipv6 reverse domain from an in6_addr
*/
-unsigned char* s_connection::result_ready(s_header &h, int length)
+void DNS::MakeIP6Int(char* query, const in6_addr *ip)
{
- int i, q, curanswer, o;
- s_rr_middle rr;
- unsigned short p;
-
- if ((h.flags1 & FLAGS1_MASK_QR) == 0)
+#ifdef SUPPORT_IP6LINKS
+ const char* hex = "0123456789abcdef";
+ for (int index = 31; index >= 0; index--) /* for() loop steps twice per byte */
{
- log(DEBUG,"DNS: didnt get a query result");
- return NULL;
+ if (index % 2)
+ /* low nibble */
+ *query++ = hex[ip->s6_addr[index / 2] & 0x0F];
+ else
+ /* high nibble */
+ *query++ = hex[(ip->s6_addr[index / 2] & 0xF0) >> 4];
+ *query++ = '.'; /* Seperator */
}
- if ((h.flags1 & FLAGS1_MASK_OPCODE) != 0)
+ strcpy(query,"ip6.arpa"); /* Suffix the string */
+#else
+ *query = 0;
+#endif
+}
+
+/** Return the next id which is ready, and the result attached to it */
+DNSResult DNS::GetResult()
+{
+ /* Fetch dns query response and decide where it belongs */
+ DNSHeader header;
+ DNSRequest *req;
+ unsigned char buffer[sizeof(DNSHeader)];
+ sockaddr from;
+ socklen_t x = sizeof(from);
+ const char* ipaddr_from = "";
+ unsigned short int port_from = 0;
+
+ int length = recvfrom(this->GetFd(),buffer,sizeof(DNSHeader),0,&from,&x);
+
+ if (length < 0)
+ ServerInstance->Log(DEBUG,"Error in recvfrom()! (%s)",strerror(errno));
+
+ /* Did we get the whole header? */
+ if (length < 12)
{
- log(DEBUG,"DNS: got an OPCODE and didnt want one");
- return NULL;
+ /* Nope - something screwed up. */
+ ServerInstance->Log(DEBUG,"Whole header not read!");
+ return std::make_pair(-1,"");
}
- if ((h.flags2 & FLAGS2_MASK_RCODE) != 0)
+
+ /* Check wether the reply came from a different DNS
+ * server to the one we sent it to, or the source-port
+ * is not 53.
+ * A user could in theory still spoof dns packets anyway
+ * but this is less trivial than just sending garbage
+ * to the client, which is possible without this check.
+ *
+ * -- Thanks jilles for pointing this one out.
+ */
+#ifdef IPV6
+ ipaddr_from = insp_ntoa(((sockaddr_in6*)&from)->sin6_addr);
+ port_from = ntohs(((sockaddr_in6*)&from)->sin6_port);
+#else
+ ipaddr_from = insp_ntoa(((sockaddr_in*)&from)->sin_addr);
+ port_from = ntohs(((sockaddr_in*)&from)->sin_port);
+#endif
+
+ /* We cant perform this security check if you're using 4in6.
+ * Tough luck to you, choose one or't other!
+ */
+ if (!ip6munge)
{
- log(DEBUG,"DNS lookup failed due to SERVFAIL");
- return NULL;
+ if ((port_from != DNS::QUERY_PORT) || (strcasecmp(ipaddr_from, ServerInstance->Config->DNSServer)))
+ {
+ ServerInstance->Log(DEBUG,"port %d is not 53, or %s is not %s",port_from, ipaddr_from, ServerInstance->Config->DNSServer);
+ return std::make_pair(-1,"");
+ }
}
- if (h.ancount < 1)
+
+ /* Put the read header info into a header class */
+ DNS::FillHeader(&header,buffer,length - 12);
+
+ /* Get the id of this request.
+ * Its a 16 bit value stored in two char's,
+ * so we use logic shifts to create the value.
+ */
+ unsigned long this_id = header.id[1] + (header.id[0] << 8);
+
+ /* Do we have a pending request matching this id? */
+ if (!requests[this_id])
{
- log(DEBUG,"DNS: no answers!");
- return NULL;
+ /* Somehow we got a DNS response for a request we never made... */
+ ServerInstance->Log(DEBUG,"DNS: got a response for a query we didnt send with fd=%d queryid=%d",this->GetFd(),this_id);
+ return std::make_pair(-1,"");
+ }
+ else
+ {
+ /* Remove the query from the list of pending queries */
+ req = requests[this_id];
+ requests[this_id] = NULL;
+ }
+
+ /* Inform the DNSRequest class that it has a result to be read.
+ * When its finished it will return a DNSInfo which is a pair of
+ * unsigned char* resource record data, and an error message.
+ */
+ DNSInfo data = req->ResultIsReady(header, length);
+ std::string resultstr;
+
+ /* Check if we got a result, if we didnt, its an error */
+ if (data.first == NULL)
+ {
+ /* An error.
+ * Mask the ID with the value of ERROR_MASK, so that
+ * the dns_deal_with_classes() function knows that its
+ * an error response and needs to be treated uniquely.
+ * Put the error message in the second field.
+ */
+ delete req;
+ return std::make_pair(this_id | ERROR_MASK, data.second);
+ }
+ else
+ {
+ char formatted[128];
+
+ /* Forward lookups come back as binary data. We must format them into ascii */
+ switch (req->type)
+ {
+ case DNS_QUERY_A:
+ snprintf(formatted,16,"%u.%u.%u.%u",data.first[0],data.first[1],data.first[2],data.first[3]);
+ resultstr = formatted;
+ break;
+
+ case DNS_QUERY_AAAA:
+ {
+ snprintf(formatted,40,"%x:%x:%x:%x:%x:%x:%x:%x",
+ (ntohs(data.first[0]) + ntohs(data.first[1] << 8)),
+ (ntohs(data.first[2]) + ntohs(data.first[3] << 8)),
+ (ntohs(data.first[4]) + ntohs(data.first[5] << 8)),
+ (ntohs(data.first[6]) + ntohs(data.first[7] << 8)),
+ (ntohs(data.first[8]) + ntohs(data.first[9] << 8)),
+ (ntohs(data.first[10]) + ntohs(data.first[11] << 8)),
+ (ntohs(data.first[12]) + ntohs(data.first[13] << 8)),
+ (ntohs(data.first[14]) + ntohs(data.first[15] << 8)));
+ char* c = strstr(formatted,":0:");
+ if (c != NULL)
+ {
+ memmove(c+1,c+2,strlen(c+2) + 1);
+ c += 2;
+ while (memcmp(c,"0:",2) == 0)
+ memmove(c,c+2,strlen(c+2) + 1);
+ if (memcmp(c,"0",2) == 0)
+ *c = 0;
+ if (memcmp(formatted,"0::",3) == 0)
+ memmove(formatted,formatted + 1, strlen(formatted + 1) + 1);
+ }
+ resultstr = formatted;
+
+ /* Special case. Sending ::1 around between servers
+ * and to clients is dangerous, because the : on the
+ * start makes the client or server interpret the IP
+ * as the last parameter on the line with a value ":1".
+ */
+ if (*formatted == ':')
+ resultstr = "0" + resultstr;
+ }
+ break;
+
+ case DNS_QUERY_CNAME:
+ /* Identical handling to PTR */
+
+ case DNS_QUERY_PTR:
+ /* Reverse lookups just come back as char* */
+ resultstr = std::string((const char*)data.first);
+ break;
+
+ default:
+ ServerInstance->Log(DEBUG,"WARNING: Somehow we made a request for a DNS_QUERY_PTR4 or DNS_QUERY_PTR6, but these arent real rr types!");
+ break;
+
+ }
+
+ /* Build the reply with the id and hostname/ip in it */
+ delete req;
+ return std::make_pair(this_id,resultstr);
}
- i = 0;
- q = 0;
+}
+
+/** A result is ready, process it */
+DNSInfo DNSRequest::ResultIsReady(DNSHeader &header, int length)
+{
+ int i = 0;
+ int q = 0;
+ int curanswer, o;
+ ResourceRecord rr;
+ unsigned short ptr;
+
+ /* This is just to keep _FORTIFY_SOURCE happy */
+ rr.type = DNS_QUERY_NONE;
+ rr.rdlength = 0;
+
+ if (!(header.flags1 & FLAGS_MASK_QR))
+ return std::make_pair((unsigned char*)NULL,"Not a query result");
+
+ if (header.flags1 & FLAGS_MASK_OPCODE)
+ return std::make_pair((unsigned char*)NULL,"Unexpected value in DNS reply packet");
+
+ if (header.flags2 & FLAGS_MASK_RCODE)
+ return std::make_pair((unsigned char*)NULL,"Domain name not found");
+
+ if (header.ancount < 1)
+ return std::make_pair((unsigned char*)NULL,"No resource records returned");
+
+ /* Subtract the length of the header from the length of the packet */
length -= 12;
- while ((unsigned)q < h.qdcount && i < length)
+
+ while ((unsigned int)q < header.qdcount && i < length)
{
- if (h.payload[i] > 63)
+ if (header.payload[i] > 63)
{
i += 6;
q++;
}
else
{
- if (h.payload[i] == 0)
+ if (header.payload[i] == 0)
{
q++;
i += 5;
}
- else i += h.payload[i] + 1;
+ else i += header.payload[i] + 1;
}
}
curanswer = 0;
- while ((unsigned)curanswer < h.ancount)
+ while ((unsigned)curanswer < header.ancount)
{
q = 0;
while (q == 0 && i < length)
{
- if (h.payload[i] > 63)
+ if (header.payload[i] > 63)
{
i += 2;
q = 1;
}
else
{
- if (h.payload[i] == 0)
+ if (header.payload[i] == 0)
{
i++;
q = 1;
}
- else i += h.payload[i] + 1; /* skip length and label */
+ else i += header.payload[i] + 1; /* skip length and label */
}
}
if (length - i < 10)
- {
- return NULL;
- }
- dns_fill_rr(&rr,&h.payload[i]);
+ return std::make_pair((unsigned char*)NULL,"Incorrectly sized DNS reply");
+
+ DNS::FillResourceRecord(&rr,&header.payload[i]);
i += 10;
if (rr.type != this->type)
{
i += rr.rdlength;
continue;
}
- if (rr._class != this->_class)
+ if (rr.rr_class != this->rr_class)
{
curanswer++;
i += rr.rdlength;
}
break;
}
- if ((unsigned int)curanswer == h.ancount)
- return NULL;
+ if ((unsigned int)curanswer == header.ancount)
+ return std::make_pair((unsigned char*)NULL,"No valid answers");
+
if (i + rr.rdlength > (unsigned int)length)
- return NULL;
+ return std::make_pair((unsigned char*)NULL,"Resource record larger than stated");
+
if (rr.rdlength > 1023)
- return NULL;
+ return std::make_pair((unsigned char*)NULL,"Resource record too large");
switch (rr.type)
{
- case DNS_QRY_PTR:
- log(DEBUG,"DNS: got a result of type DNS_QRY_PTR");
+ case DNS_QUERY_CNAME:
+ /* CNAME and PTR have the same processing code */
+ case DNS_QUERY_PTR:
o = 0;
q = 0;
while (q == 0 && i < length && o + 256 < 1023)
{
- if (h.payload[i] > 63)
+ if (header.payload[i] > 63)
{
- log(DEBUG,"DNS: h.payload[i] > 63");
- memcpy(&p,&h.payload[i],2);
- i = ntohs(p) - 0xC000 - 12;
+ memcpy(&ptr,&header.payload[i],2);
+ i = ntohs(ptr) - 0xC000 - 12;
}
else
{
- if (h.payload[i] == 0)
+ if (header.payload[i] == 0)
{
q = 1;
}
else
{
- res[o] = '\0';
+ res[o] = 0;
if (o != 0)
res[o++] = '.';
- memcpy(&res[o],&h.payload[i + 1],h.payload[i]);
- o += h.payload[i];
- i += h.payload[i] + 1;
+ memcpy(&res[o],&header.payload[i + 1],header.payload[i]);
+ o += header.payload[i];
+ i += header.payload[i] + 1;
}
}
}
- res[o] = '\0';
+ res[o] = 0;
+ break;
+ case DNS_QUERY_AAAA:
+ memcpy(res,&header.payload[i],rr.rdlength);
+ res[rr.rdlength] = 0;
+ break;
+ case DNS_QUERY_A:
+ memcpy(res,&header.payload[i],rr.rdlength);
+ res[rr.rdlength] = 0;
break;
- case DNS_QRY_A:
- log(DEBUG,"DNS: got a result of type DNS_QRY_A");
- memcpy(res,&h.payload[i],rr.rdlength);
- res[rr.rdlength] = '\0';
- break;
default:
- memcpy(res,&h.payload[i],rr.rdlength);
- res[rr.rdlength] = '\0';
- break;
+ memcpy(res,&header.payload[i],rr.rdlength);
+ res[rr.rdlength] = 0;
+ break;
}
- return res;
-}
-
-DNS::DNS()
-{
- log(DEBUG,"Create blank DNS");
+ return std::make_pair(res,"No error");;
}
+/** Close the master socket */
DNS::~DNS()
{
+ shutdown(this->GetFd(), 2);
+ close(this->GetFd());
}
-Resolver::Resolver(const std::string &source, bool forward) : input(source), fwd(forward)
+/** High level abstraction of dns used by application at large */
+Resolver::Resolver(InspIRCd* Instance, const std::string &source, QueryType qt, Module* creator) : ServerInstance(Instance), Creator(creator), input(source), querytype(qt)
{
- if (forward)
- {
- log(DEBUG,"Resolver: Forward lookup on %s",source.c_str());
- this->myid = Res->dns_getip4(source.c_str());
- }
- else
+ ServerInstance->Log(DEBUG,"Instance: %08x %08x",Instance, ServerInstance);
+
+ insp_inaddr binip;
+
+ switch (querytype)
{
- log(DEBUG,"Resolver: Reverse lookup on %s",source.c_str());
- insp_inaddr binip;
- if (insp_aton(source.c_str(), &binip) > 0)
- {
- /* Valid ip address */
- this->myid = Res->dns_getname4(&binip);
- }
+ case DNS_QUERY_A:
+ this->myid = ServerInstance->Res->GetIP(source.c_str());
+ break;
+
+ case DNS_QUERY_PTR:
+ if (insp_aton(source.c_str(), &binip) > 0)
+ {
+ /* Valid ip address */
+ this->myid = ServerInstance->Res->GetName(&binip);
+ }
+ else
+ {
+ this->OnError(RESOLVER_BADIP, "Bad IP address for reverse lookup");
+ throw ModuleException("Resolver: Bad IP address");
+ return;
+ }
+ break;
+
+ case DNS_QUERY_PTR4:
+ querytype = DNS_QUERY_PTR;
+ this->myid = ServerInstance->Res->GetNameForce(source.c_str(), PROTOCOL_IPV4);
+ break;
+
+ case DNS_QUERY_PTR6:
+ querytype = DNS_QUERY_PTR;
+ this->myid = ServerInstance->Res->GetNameForce(source.c_str(), PROTOCOL_IPV6);
+ break;
+
+ case DNS_QUERY_AAAA:
+ this->myid = ServerInstance->Res->GetIP6(source.c_str());
+ break;
+
+ case DNS_QUERY_CNAME:
+ this->myid = ServerInstance->Res->GetCName(source.c_str());
+ break;
+
+ default:
+ this->myid = -1;
+ break;
}
if (this->myid == -1)
{
- log(DEBUG,"Resolver::Resolver: Could not get an id!");
- this->OnError(RESOLVER_NSDOWN);
+ ServerInstance->Log(DEBUG,"Resolver::Resolver: Could not get an id!");
+ this->OnError(RESOLVER_NSDOWN, "Nameserver is down");
throw ModuleException("Resolver: Couldnt get an id to make a request");
/* We shouldnt get here really */
return;
}
- log(DEBUG,"Resolver::Resolver: this->myid=%d",this->myid);
-}
-
-void Resolver::OnLookupComplete(const std::string &result)
-{
+ ServerInstance->Log(DEBUG,"Resolver::Resolver: this->myid=%d",this->myid);
}
-void Resolver::OnError(ResolverError e)
+/** Called when an error occurs */
+void Resolver::OnError(ResolverError e, const std::string &errormessage)
{
+ /* Nothing in here */
}
+/** Destroy a resolver */
Resolver::~Resolver()
{
- log(DEBUG,"Resolver::~Resolver");
+ /* Nothing here (yet) either */
}
+/** Get the request id associated with this class */
int Resolver::GetId()
{
return this->myid;
}
-bool Resolver::ProcessResult(const std::string &result)
+Module* Resolver::GetCreator()
{
- log(DEBUG,"Resolver::ProcessResult");
-
- if (!result.length())
- {
- log(DEBUG,"Resolver::OnError(RESOLVER_NXDOMAIN)");
- this->OnError(RESOLVER_NXDOMAIN);
- return false;
- }
- else
- {
-
- log(DEBUG,"Resolver::OnLookupComplete(%s)",result.c_str());
- this->OnLookupComplete(result);
- return true;
- }
+ return this->Creator;
}
-void dns_deal_with_classes(int fd)
+/** Process a socket read event */
+void DNS::HandleEvent(EventType et, int errornum)
{
- log(DEBUG,"dns_deal_with_classes(%d)",fd);
- if (fd == master_socket)
+ /* Fetch the id and result of the next available packet */
+ DNSResult res = this->GetResult();
+ /* Is there a usable request id? */
+ if (res.first != -1)
{
- DNSResult res = Res->dns_getresult();
- if (res.first != -1)
+ /* Its an error reply */
+ if (res.first & ERROR_MASK)
{
- log(DEBUG,"Result available, id=%d",res.first);
- if (dns_classes[res.first])
+ /* Mask off the error bit */
+ res.first -= ERROR_MASK;
+ /* Marshall the error to the correct class */
+ ServerInstance->Log(DEBUG,"Error available, id=%d",res.first);
+ if (Classes[res.first])
{
- dns_classes[res.first]->ProcessResult(res.second);
- delete dns_classes[res.first];
- dns_classes[res.first] = NULL;
+ if (ServerInstance && ServerInstance->stats)
+ ServerInstance->stats->statsDnsBad++;
+ Classes[res.first]->OnError(RESOLVER_NXDOMAIN, res.second);
+ delete Classes[res.first];
+ Classes[res.first] = NULL;
}
}
+ else
+ {
+ /* It is a non-error result */
+ ServerInstance->Log(DEBUG,"Result available, id=%d",res.first);
+ /* Marshall the result to the correct class */
+ if (Classes[res.first])
+ {
+ if (ServerInstance && ServerInstance->stats)
+ ServerInstance->stats->statsDnsGood++;
+ Classes[res.first]->OnLookupComplete(res.second);
+ delete Classes[res.first];
+ Classes[res.first] = NULL;
+ }
+ }
+
+ if (ServerInstance && ServerInstance->stats)
+ ServerInstance->stats->statsDns++;
}
}
-bool dns_add_class(Resolver* r)
+/** Add a derived Resolver to the working set */
+bool DNS::AddResolverClass(Resolver* r)
{
- log(DEBUG,"dns_add_class");
+ /* Check the pointers validity and the id's validity */
if ((r) && (r->GetId() > -1))
{
- if (!dns_classes[r->GetId()])
+ /* Check the slot isnt already occupied -
+ * This should NEVER happen unless we have
+ * a severely broken DNS server somewhere
+ */
+ if (!Classes[r->GetId()])
{
- log(DEBUG,"dns_add_class: added class");
- dns_classes[r->GetId()] = r;
+ /* Set up the pointer to the class */
+ Classes[r->GetId()] = r;
return true;
}
else
- {
- log(DEBUG,"Space occupied!");
+ /* Duplicate id */
return false;
- }
}
else
{
- log(DEBUG,"Bad class");
- delete r;
- return true;
+ /* Pointer or id not valid.
+ * Free the item and return
+ */
+ if (r)
+ delete r;
+
+ return false;
+ }
+}
+
+void DNS::CleanResolvers(Module* module)
+{
+ for (int i = 0; i < MAX_REQUEST_ID; i++)
+ {
+ if (Classes[i])
+ {
+ if (Classes[i]->GetCreator() == module)
+ {
+ Classes[i]->OnError(RESLOVER_FORCEUNLOAD, "Parent module is unloading");
+ delete Classes[i];
+ Classes[i] = NULL;
+ }
+ }
}
}
-void init_dns()
+/** Generate pseudo-random number */
+unsigned long DNS::PRNG()
{
- Res = new DNS();
- memset(dns_classes,0,sizeof(dns_classes));
- create_socket();
+ unsigned long val = 0;
+ timeval n;
+ serverstats* s = ServerInstance->stats;
+ gettimeofday(&n,NULL);
+ val = (n.tv_usec ^ getpid() ^ geteuid() ^ (this->currid++)) ^ s->statsAccept + n.tv_sec;
+ val = val + s->statsCollisions ^ s->statsDnsGood - s->statsDnsBad;
+ val += (s->statsConnects ^ (unsigned long)s->statsSent ^ (unsigned long)s->statsRecv) - s->BoundPortCount;
+ return val;
}