dns_conf.c 65 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744
  1. /*************************************************************************
  2. *
  3. * Copyright (C) 2018-2020 Ruilin Peng (Nick) <[email protected]>.
  4. *
  5. * smartdns is free software: you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation, either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * smartdns is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. */
  18. #include "dns_conf.h"
  19. #include "list.h"
  20. #include "rbtree.h"
  21. #include "tlog.h"
  22. #include "util.h"
  23. #include <errno.h>
  24. #include <getopt.h>
  25. #include <libgen.h>
  26. #include <stdio.h>
  27. #include <stdlib.h>
  28. #include <string.h>
  29. #include <syslog.h>
  30. #include <unistd.h>
  31. #define DEFAULT_DNS_CACHE_SIZE 512
  32. #define DNS_MAX_REPLY_IP_NUM 8
  33. #define DNS_RESOLV_FILE "/etc/resolv.conf"
  34. /* ipset */
  35. struct dns_ipset_table {
  36. DECLARE_HASHTABLE(ipset, 8);
  37. };
  38. static struct dns_ipset_table dns_ipset_table;
  39. struct dns_nftset_table {
  40. DECLARE_HASHTABLE(nftset, 8);
  41. };
  42. static struct dns_nftset_table dns_nftset_table;
  43. struct dns_qtype_soa_table dns_qtype_soa_table;
  44. struct dns_domain_set_rule_table dns_domain_set_rule_table;
  45. struct dns_domain_set_name_table dns_domain_set_name_table;
  46. /* dns groups */
  47. struct dns_group_table dns_group_table;
  48. struct dns_ptr_table dns_ptr_table;
  49. static char dns_conf_dnsmasq_lease_file[DNS_MAX_PATH];
  50. static time_t dns_conf_dnsmasq_lease_file_time;
  51. struct dns_hosts_table dns_hosts_table;
  52. int dns_hosts_record_num;
  53. /* server ip/port */
  54. struct dns_bind_ip dns_conf_bind_ip[DNS_MAX_BIND_IP];
  55. int dns_conf_bind_ip_num = 0;
  56. int dns_conf_tcp_idle_time = 120;
  57. int dns_conf_max_reply_ip_num = DNS_MAX_REPLY_IP_NUM;
  58. static struct config_enum_list dns_conf_response_mode_enum[] = {
  59. {"first-ping", DNS_RESPONSE_MODE_FIRST_PING_IP},
  60. {"fastest-ip", DNS_RESPONSE_MODE_FASTEST_IP},
  61. {"fastest-response", DNS_RESPONSE_MODE_FASTEST_RESPONSE},
  62. {0, 0}};
  63. enum response_mode_type dns_conf_response_mode;
  64. /* cache */
  65. int dns_conf_cachesize = DEFAULT_DNS_CACHE_SIZE;
  66. int dns_conf_prefetch = 0;
  67. int dns_conf_serve_expired = 1;
  68. int dns_conf_serve_expired_ttl = 24 * 3600; /* 1 day */
  69. int dns_conf_serve_expired_prefetch_time;
  70. int dns_conf_serve_expired_reply_ttl = 3;
  71. /* upstream servers */
  72. struct dns_servers dns_conf_servers[DNS_MAX_SERVERS];
  73. char dns_conf_server_name[DNS_MAX_SERVER_NAME_LEN];
  74. int dns_conf_server_num;
  75. int dns_conf_resolv_hostname = 1;
  76. struct dns_domain_check_orders dns_conf_check_orders = {
  77. .orders =
  78. {
  79. {.type = DOMAIN_CHECK_ICMP, .tcp_port = 0},
  80. {.type = DOMAIN_CHECK_TCP, .tcp_port = 80},
  81. {.type = DOMAIN_CHECK_TCP, .tcp_port = 443},
  82. },
  83. };
  84. static int dns_has_cap_ping = 0;
  85. /* logging */
  86. int dns_conf_log_level = TLOG_ERROR;
  87. char dns_conf_log_file[DNS_MAX_PATH];
  88. size_t dns_conf_log_size = 1024 * 1024;
  89. int dns_conf_log_num = 8;
  90. /* CA file */
  91. char dns_conf_ca_file[DNS_MAX_PATH];
  92. char dns_conf_ca_path[DNS_MAX_PATH];
  93. char dns_conf_cache_file[DNS_MAX_PATH];
  94. int dns_conf_cache_persist = 2;
  95. /* auditing */
  96. int dns_conf_audit_enable = 0;
  97. int dns_conf_audit_log_SOA;
  98. char dns_conf_audit_file[DNS_MAX_PATH];
  99. size_t dns_conf_audit_size = 1024 * 1024;
  100. int dns_conf_audit_num = 2;
  101. /* address rules */
  102. art_tree dns_conf_domain_rule;
  103. struct dns_conf_address_rule dns_conf_address_rule;
  104. /* dual-stack selection */
  105. int dns_conf_dualstack_ip_selection = 1;
  106. int dns_conf_dualstack_ip_allow_force_AAAA;
  107. int dns_conf_dualstack_ip_selection_threshold = 15;
  108. /* TTL */
  109. int dns_conf_rr_ttl;
  110. int dns_conf_rr_ttl_reply_max;
  111. int dns_conf_rr_ttl_min = 600;
  112. int dns_conf_rr_ttl_max;
  113. int dns_conf_local_ttl;
  114. int dns_conf_force_AAAA_SOA;
  115. int dns_conf_force_no_cname;
  116. int dns_conf_ipset_timeout_enable;
  117. int dns_conf_nftset_timeout_enable;
  118. int dns_conf_nftset_debug_enable;
  119. char dns_conf_user[DNS_CONF_USRNAME_LEN];
  120. int dns_save_fail_packet;
  121. char dns_save_fail_packet_dir[DNS_MAX_PATH];
  122. char dns_resolv_file[DNS_MAX_PATH];
  123. /* ECS */
  124. struct dns_edns_client_subnet dns_conf_ipv4_ecs;
  125. struct dns_edns_client_subnet dns_conf_ipv6_ecs;
  126. char dns_conf_sni_proxy_ip[DNS_MAX_IPLEN];
  127. static void *_new_dns_rule(enum domain_rule domain_rule)
  128. {
  129. struct dns_rule *rule;
  130. int size = 0;
  131. if (domain_rule >= DOMAIN_RULE_MAX) {
  132. return NULL;
  133. }
  134. switch (domain_rule) {
  135. case DOMAIN_RULE_FLAGS:
  136. size = sizeof(struct dns_rule_flags);
  137. break;
  138. case DOMAIN_RULE_ADDRESS_IPV4:
  139. size = sizeof(struct dns_rule_address_IPV4);
  140. break;
  141. case DOMAIN_RULE_ADDRESS_IPV6:
  142. size = sizeof(struct dns_rule_address_IPV6);
  143. break;
  144. case DOMAIN_RULE_IPSET:
  145. case DOMAIN_RULE_IPSET_IPV4:
  146. case DOMAIN_RULE_IPSET_IPV6:
  147. size = sizeof(struct dns_ipset_rule);
  148. break;
  149. case DOMAIN_RULE_NFTSET_IP:
  150. case DOMAIN_RULE_NFTSET_IP6:
  151. size = sizeof(struct dns_nftset_rule);
  152. break;
  153. case DOMAIN_RULE_NAMESERVER:
  154. size = sizeof(struct dns_nameserver_rule);
  155. break;
  156. case DOMAIN_RULE_CHECKSPEED:
  157. size = sizeof(struct dns_domain_check_orders);
  158. break;
  159. default:
  160. return NULL;
  161. }
  162. rule = malloc(size);
  163. if (!rule) {
  164. return NULL;
  165. }
  166. memset(rule, 0, size);
  167. rule->rule = domain_rule;
  168. atomic_set(&rule->refcnt, 1);
  169. return rule;
  170. }
  171. static void _dns_rule_get(struct dns_rule *rule)
  172. {
  173. atomic_inc(&rule->refcnt);
  174. }
  175. static void _dns_rule_put(struct dns_rule *rule)
  176. {
  177. if (atomic_dec_and_test(&rule->refcnt)) {
  178. free(rule);
  179. }
  180. }
  181. static int _get_domain(char *value, char *domain, int max_dmain_size, char **ptr_after_domain)
  182. {
  183. char *begin = NULL;
  184. char *end = NULL;
  185. int len = 0;
  186. if (value == NULL || domain == NULL) {
  187. goto errout;
  188. }
  189. /* first field */
  190. begin = strstr(value, "/");
  191. if (begin == NULL) {
  192. goto errout;
  193. }
  194. /* second field */
  195. begin++;
  196. end = strstr(begin, "/");
  197. if (end == NULL) {
  198. goto errout;
  199. }
  200. /* remove prefix . */
  201. while (*begin == '.') {
  202. begin++;
  203. }
  204. /* Get domain */
  205. len = end - begin;
  206. if (len >= max_dmain_size) {
  207. tlog(TLOG_ERROR, "domain name %s too long", value);
  208. goto errout;
  209. }
  210. memcpy(domain, begin, len);
  211. domain[len] = '\0';
  212. if (ptr_after_domain) {
  213. *ptr_after_domain = end + 1;
  214. }
  215. return 0;
  216. errout:
  217. return -1;
  218. }
  219. /* create and get dns server group */
  220. static struct dns_server_groups *_dns_conf_get_group(const char *group_name)
  221. {
  222. uint32_t key = 0;
  223. struct dns_server_groups *group = NULL;
  224. key = hash_string(group_name);
  225. hash_for_each_possible(dns_group_table.group, group, node, key)
  226. {
  227. if (strncmp(group->group_name, group_name, DNS_MAX_IPLEN) == 0) {
  228. return group;
  229. }
  230. }
  231. group = malloc(sizeof(*group));
  232. if (group == NULL) {
  233. goto errout;
  234. }
  235. memset(group, 0, sizeof(*group));
  236. safe_strncpy(group->group_name, group_name, DNS_GROUP_NAME_LEN);
  237. hash_add(dns_group_table.group, &group->node, key);
  238. return group;
  239. errout:
  240. if (group) {
  241. free(group);
  242. }
  243. return NULL;
  244. }
  245. static int _dns_conf_get_group_set(const char *group_name, struct dns_servers *server)
  246. {
  247. struct dns_server_groups *group = NULL;
  248. int i = 0;
  249. group = _dns_conf_get_group(group_name);
  250. if (group == NULL) {
  251. return -1;
  252. }
  253. for (i = 0; i < group->server_num; i++) {
  254. if (group->servers[i] == server) {
  255. return 0;
  256. }
  257. }
  258. if (group->server_num >= DNS_MAX_SERVERS) {
  259. return -1;
  260. }
  261. group->servers[group->server_num] = server;
  262. group->server_num++;
  263. return 0;
  264. }
  265. static const char *_dns_conf_get_group_name(const char *group_name)
  266. {
  267. struct dns_server_groups *group = NULL;
  268. group = _dns_conf_get_group(group_name);
  269. if (group == NULL) {
  270. return NULL;
  271. }
  272. return group->group_name;
  273. }
  274. static void _config_group_table_destroy(void)
  275. {
  276. struct dns_server_groups *group = NULL;
  277. struct hlist_node *tmp = NULL;
  278. unsigned long i = 0;
  279. hash_for_each_safe(dns_group_table.group, i, tmp, group, node)
  280. {
  281. hlist_del_init(&group->node);
  282. free(group);
  283. }
  284. }
  285. static int _config_server(int argc, char *argv[], dns_server_type_t type, int default_port)
  286. {
  287. int index = dns_conf_server_num;
  288. struct dns_servers *server = NULL;
  289. int port = -1;
  290. char *ip = NULL;
  291. int opt = 0;
  292. unsigned int result_flag = 0;
  293. unsigned int server_flag = 0;
  294. unsigned char *spki = NULL;
  295. int ttl = 0;
  296. /* clang-format off */
  297. static struct option long_options[] = {
  298. {"blacklist-ip", no_argument, NULL, 'b'}, /* filtering with blacklist-ip */
  299. {"whitelist-ip", no_argument, NULL, 'w'}, /* filtering with whitelist-ip */
  300. #ifdef FEATURE_CHECK_EDNS
  301. /* experimental feature */
  302. {"check-edns", no_argument, NULL, 'e'}, /* check edns */
  303. #endif
  304. {"spki-pin", required_argument, NULL, 'p'}, /* check SPKI pin */
  305. {"host-name", required_argument, NULL, 'h'}, /* host name */
  306. {"http-host", required_argument, NULL, 'H'}, /* http host */
  307. {"no-check-certificate", no_argument, NULL, 'N'}, /* do not check certificate */
  308. {"tls-host-verify", required_argument, NULL, 'V' }, /* verify tls hostname */
  309. {"group", required_argument, NULL, 'g'}, /* add to group */
  310. {"exclude-default-group", no_argument, NULL, 'E'}, /* ecluse this from default group */
  311. {"set-mark", required_argument, NULL, 254}, /* set mark */
  312. {NULL, no_argument, NULL, 0}
  313. };
  314. /* clang-format on */
  315. if (argc <= 1) {
  316. tlog(TLOG_ERROR, "invalid parameter.");
  317. return -1;
  318. }
  319. ip = argv[1];
  320. if (index >= DNS_MAX_SERVERS) {
  321. tlog(TLOG_WARN, "exceeds max server number, %s", ip);
  322. return 0;
  323. }
  324. server = &dns_conf_servers[index];
  325. server->spki[0] = '\0';
  326. server->path[0] = '\0';
  327. server->hostname[0] = '\0';
  328. server->httphost[0] = '\0';
  329. server->tls_host_verify[0] = '\0';
  330. server->set_mark = -1;
  331. if (type == DNS_SERVER_HTTPS) {
  332. if (parse_uri(ip, NULL, server->server, &port, server->path) != 0) {
  333. return -1;
  334. }
  335. safe_strncpy(server->hostname, server->server, sizeof(server->hostname));
  336. safe_strncpy(server->httphost, server->server, sizeof(server->httphost));
  337. if (server->path[0] == 0) {
  338. safe_strncpy(server->path, "/", sizeof(server->path));
  339. }
  340. } else {
  341. /* parse ip, port from ip */
  342. if (parse_ip(ip, server->server, &port) != 0) {
  343. return -1;
  344. }
  345. }
  346. /* if port is not defined, set port to default 53 */
  347. if (port == PORT_NOT_DEFINED) {
  348. port = default_port;
  349. }
  350. /* process extra options */
  351. optind = 1;
  352. while (1) {
  353. opt = getopt_long_only(argc, argv, "", long_options, NULL);
  354. if (opt == -1) {
  355. break;
  356. }
  357. switch (opt) {
  358. case 'b': {
  359. result_flag |= DNSSERVER_FLAG_BLACKLIST_IP;
  360. break;
  361. }
  362. case 'w': {
  363. result_flag |= DNSSERVER_FLAG_WHITELIST_IP;
  364. break;
  365. }
  366. case 'e': {
  367. result_flag |= DNSSERVER_FLAG_CHECK_EDNS;
  368. break;
  369. }
  370. case 'h': {
  371. safe_strncpy(server->hostname, optarg, DNS_MAX_CNAME_LEN);
  372. if (strncmp(server->hostname, "-", 2) == 0) {
  373. server->hostname[0] = '\0';
  374. }
  375. break;
  376. }
  377. case 'H': {
  378. safe_strncpy(server->httphost, optarg, DNS_MAX_CNAME_LEN);
  379. break;
  380. }
  381. case 'E': {
  382. server_flag |= SERVER_FLAG_EXCLUDE_DEFAULT;
  383. break;
  384. }
  385. case 'g': {
  386. if (_dns_conf_get_group_set(optarg, server) != 0) {
  387. tlog(TLOG_ERROR, "add group failed.");
  388. goto errout;
  389. }
  390. break;
  391. }
  392. case 'p': {
  393. safe_strncpy(server->spki, optarg, DNS_MAX_SPKI_LEN);
  394. break;
  395. }
  396. case 'V': {
  397. safe_strncpy(server->tls_host_verify, optarg, DNS_MAX_CNAME_LEN);
  398. break;
  399. }
  400. case 'N': {
  401. server->skip_check_cert = 1;
  402. break;
  403. }
  404. case 254: {
  405. server->set_mark = atoll(optarg);
  406. break;
  407. }
  408. default:
  409. break;
  410. }
  411. }
  412. /* add new server */
  413. server->type = type;
  414. server->port = port;
  415. server->result_flag = result_flag;
  416. server->server_flag = server_flag;
  417. server->ttl = ttl;
  418. dns_conf_server_num++;
  419. tlog(TLOG_DEBUG, "add server %s, flag: %X, ttl: %d", ip, result_flag, ttl);
  420. return 0;
  421. errout:
  422. if (spki) {
  423. free(spki);
  424. }
  425. return -1;
  426. }
  427. static int _config_domain_iter_free(void *data, const unsigned char *key, uint32_t key_len, void *value)
  428. {
  429. struct dns_domain_rule *domain_rule = value;
  430. int i = 0;
  431. if (domain_rule == NULL) {
  432. return 0;
  433. }
  434. for (i = 0; i < DOMAIN_RULE_MAX; i++) {
  435. if (domain_rule->rules[i] == NULL) {
  436. continue;
  437. }
  438. _dns_rule_put(domain_rule->rules[i]);
  439. domain_rule->rules[i] = NULL;
  440. }
  441. free(domain_rule);
  442. return 0;
  443. }
  444. static void _config_domain_destroy(void)
  445. {
  446. art_iter(&dns_conf_domain_rule, _config_domain_iter_free, NULL);
  447. art_tree_destroy(&dns_conf_domain_rule);
  448. }
  449. static void _config_address_destroy(radix_node_t *node, void *cbctx)
  450. {
  451. if (node == NULL) {
  452. return;
  453. }
  454. if (node->data == NULL) {
  455. return;
  456. }
  457. free(node->data);
  458. node->data = NULL;
  459. }
  460. static int _config_domain_set_rule_add_ext(const char *set_name, enum domain_rule type, void *rule, unsigned int flags,
  461. int is_clear_flag)
  462. {
  463. struct dns_domain_set_rule *set_rule = NULL;
  464. struct dns_domain_set_rule_list *set_rule_list = NULL;
  465. uint32_t key = 0;
  466. if (set_name == NULL) {
  467. return -1;
  468. }
  469. set_rule = malloc(sizeof(struct dns_domain_set_rule));
  470. if (set_rule == NULL) {
  471. goto errout;
  472. }
  473. memset(set_rule, 0, sizeof(struct dns_domain_set_rule));
  474. set_rule->type = type;
  475. set_rule->rule = rule;
  476. set_rule->flags = flags;
  477. set_rule->is_clear_flag = is_clear_flag;
  478. if (rule) {
  479. _dns_rule_get(rule);
  480. }
  481. key = hash_string(set_name);
  482. hash_for_each_possible(dns_domain_set_rule_table.rule_list, set_rule_list, node, key)
  483. {
  484. if (strncmp(set_rule_list->domain_set, set_name, DNS_MAX_CNAME_LEN) == 0) {
  485. break;
  486. }
  487. }
  488. if (set_rule_list == NULL) {
  489. set_rule_list = malloc(sizeof(struct dns_domain_set_rule_list));
  490. if (set_rule_list == NULL) {
  491. goto errout;
  492. }
  493. memset(set_rule_list, 0, sizeof(struct dns_domain_set_rule_list));
  494. INIT_LIST_HEAD(&set_rule_list->domain_ruls_list);
  495. safe_strncpy(set_rule_list->domain_set, set_name, DNS_MAX_CNAME_LEN);
  496. hash_add(dns_domain_set_rule_table.rule_list, &set_rule_list->node, key);
  497. }
  498. list_add_tail(&set_rule->list, &set_rule_list->domain_ruls_list);
  499. return 0;
  500. errout:
  501. if (set_rule) {
  502. free(set_rule);
  503. }
  504. return -1;
  505. }
  506. static int _config_domian_set_rule_flags(const char *set_name, unsigned int flags, int is_clear_flag)
  507. {
  508. return _config_domain_set_rule_add_ext(set_name, DOMAIN_RULE_FLAGS, NULL, flags, is_clear_flag);
  509. }
  510. static int _config_domain_set_rule_add(char *set_name, enum domain_rule type, void *rule)
  511. {
  512. return _config_domain_set_rule_add_ext(set_name, type, rule, 0, 0);
  513. }
  514. static int _config_domain_rule_add(char *domain, enum domain_rule type, void *rule)
  515. {
  516. struct dns_domain_rule *domain_rule = NULL;
  517. struct dns_domain_rule *old_domain_rule = NULL;
  518. struct dns_domain_rule *add_domain_rule = NULL;
  519. char domain_key[DNS_MAX_CONF_CNAME_LEN];
  520. int len = 0;
  521. /* Reverse string, for suffix match */
  522. len = strlen(domain);
  523. if (len >= (int)sizeof(domain_key)) {
  524. tlog(TLOG_ERROR, "domain name %s too long", domain);
  525. goto errout;
  526. }
  527. if (strncmp(domain, "domain-set:", sizeof("domain-set:") - 1) == 0) {
  528. return _config_domain_set_rule_add(domain + sizeof("domain-set:") - 1, type, rule);
  529. }
  530. reverse_string(domain_key, domain, len, 1);
  531. domain_key[len] = '.';
  532. len++;
  533. domain_key[len] = 0;
  534. if (type >= DOMAIN_RULE_MAX) {
  535. goto errout;
  536. }
  537. /* Get existing or create domain rule */
  538. domain_rule = art_search(&dns_conf_domain_rule, (unsigned char *)domain_key, len);
  539. if (domain_rule == NULL) {
  540. add_domain_rule = malloc(sizeof(*add_domain_rule));
  541. if (add_domain_rule == NULL) {
  542. goto errout;
  543. }
  544. memset(add_domain_rule, 0, sizeof(*add_domain_rule));
  545. domain_rule = add_domain_rule;
  546. }
  547. /* add new rule to domain */
  548. if (domain_rule->rules[type]) {
  549. _dns_rule_put(domain_rule->rules[type]);
  550. domain_rule->rules[type] = NULL;
  551. }
  552. domain_rule->rules[type] = rule;
  553. _dns_rule_get(rule);
  554. /* update domain rule */
  555. if (add_domain_rule) {
  556. old_domain_rule = art_insert(&dns_conf_domain_rule, (unsigned char *)domain_key, len, add_domain_rule);
  557. if (old_domain_rule) {
  558. free(old_domain_rule);
  559. }
  560. }
  561. return 0;
  562. errout:
  563. if (add_domain_rule) {
  564. free(add_domain_rule);
  565. }
  566. tlog(TLOG_ERROR, "add doamin %s rule failed", domain);
  567. return -1;
  568. }
  569. static int _config_domain_rule_flag_set(const char *domain, unsigned int flag, unsigned int is_clear)
  570. {
  571. struct dns_domain_rule *domain_rule = NULL;
  572. struct dns_domain_rule *old_domain_rule = NULL;
  573. struct dns_domain_rule *add_domain_rule = NULL;
  574. struct dns_rule_flags *rule_flags = NULL;
  575. char domain_key[DNS_MAX_CONF_CNAME_LEN];
  576. int len = 0;
  577. if (strncmp(domain, "domain-set:", sizeof("domain-set:") - 1) == 0) {
  578. return _config_domian_set_rule_flags(domain + sizeof("domain-set:") - 1, flag, is_clear);
  579. }
  580. len = strlen(domain);
  581. if (len >= (int)sizeof(domain_key)) {
  582. tlog(TLOG_ERROR, "domain %s too long", domain);
  583. return -1;
  584. }
  585. reverse_string(domain_key, domain, len, 1);
  586. domain_key[len] = '.';
  587. len++;
  588. domain_key[len] = 0;
  589. /* Get existing or create domain rule */
  590. domain_rule = art_search(&dns_conf_domain_rule, (unsigned char *)domain_key, len);
  591. if (domain_rule == NULL) {
  592. add_domain_rule = malloc(sizeof(*add_domain_rule));
  593. if (add_domain_rule == NULL) {
  594. goto errout;
  595. }
  596. memset(add_domain_rule, 0, sizeof(*add_domain_rule));
  597. domain_rule = add_domain_rule;
  598. }
  599. /* add new rule to domain */
  600. if (domain_rule->rules[DOMAIN_RULE_FLAGS] == NULL) {
  601. rule_flags = _new_dns_rule(DOMAIN_RULE_FLAGS);
  602. rule_flags->flags = 0;
  603. domain_rule->rules[DOMAIN_RULE_FLAGS] = (struct dns_rule *)rule_flags;
  604. }
  605. rule_flags = (struct dns_rule_flags *)domain_rule->rules[DOMAIN_RULE_FLAGS];
  606. if (is_clear == false) {
  607. rule_flags->flags |= flag;
  608. } else {
  609. rule_flags->flags &= ~flag;
  610. }
  611. rule_flags->is_flag_set |= flag;
  612. /* update domain rule */
  613. if (add_domain_rule) {
  614. old_domain_rule = art_insert(&dns_conf_domain_rule, (unsigned char *)domain_key, len, add_domain_rule);
  615. if (old_domain_rule) {
  616. free(old_domain_rule);
  617. }
  618. }
  619. return 0;
  620. errout:
  621. if (add_domain_rule) {
  622. free(add_domain_rule);
  623. }
  624. tlog(TLOG_ERROR, "add doamin %s rule failed", domain);
  625. return 0;
  626. }
  627. static void _config_ipset_table_destroy(void)
  628. {
  629. struct dns_ipset_name *ipset_name = NULL;
  630. struct hlist_node *tmp = NULL;
  631. unsigned long i = 0;
  632. hash_for_each_safe(dns_ipset_table.ipset, i, tmp, ipset_name, node)
  633. {
  634. hlist_del_init(&ipset_name->node);
  635. free(ipset_name);
  636. }
  637. }
  638. static const char *_dns_conf_get_ipset(const char *ipsetname)
  639. {
  640. uint32_t key = 0;
  641. struct dns_ipset_name *ipset_name = NULL;
  642. key = hash_string(ipsetname);
  643. hash_for_each_possible(dns_ipset_table.ipset, ipset_name, node, key)
  644. {
  645. if (strncmp(ipset_name->ipsetname, ipsetname, DNS_MAX_IPSET_NAMELEN) == 0) {
  646. return ipset_name->ipsetname;
  647. }
  648. }
  649. ipset_name = malloc(sizeof(*ipset_name));
  650. if (ipset_name == NULL) {
  651. goto errout;
  652. }
  653. key = hash_string(ipsetname);
  654. safe_strncpy(ipset_name->ipsetname, ipsetname, DNS_MAX_IPSET_NAMELEN);
  655. hash_add(dns_ipset_table.ipset, &ipset_name->node, key);
  656. return ipset_name->ipsetname;
  657. errout:
  658. if (ipset_name) {
  659. free(ipset_name);
  660. }
  661. return NULL;
  662. }
  663. static int _conf_domain_rule_ipset(char *domain, const char *ipsetname)
  664. {
  665. struct dns_ipset_rule *ipset_rule = NULL;
  666. const char *ipset = NULL;
  667. char *copied_name = NULL;
  668. enum domain_rule type = 0;
  669. int ignore_flag = 0;
  670. copied_name = strdup(ipsetname);
  671. if (copied_name == NULL) {
  672. goto errout;
  673. }
  674. for (char *tok = strtok(copied_name, ","); tok; tok = strtok(NULL, ",")) {
  675. if (tok[0] == '#') {
  676. if (strncmp(tok, "#6:", 3U) == 0) {
  677. type = DOMAIN_RULE_IPSET_IPV6;
  678. ignore_flag = DOMAIN_FLAG_IPSET_IPV6_IGN;
  679. } else if (strncmp(tok, "#4:", 3U) == 0) {
  680. type = DOMAIN_RULE_IPSET_IPV4;
  681. ignore_flag = DOMAIN_FLAG_IPSET_IPV4_IGN;
  682. } else {
  683. goto errout;
  684. }
  685. tok += 3;
  686. } else {
  687. type = DOMAIN_RULE_IPSET;
  688. ignore_flag = DOMAIN_FLAG_IPSET_IGN;
  689. }
  690. if (strncmp(tok, "-", 1) == 0) {
  691. _config_domain_rule_flag_set(domain, ignore_flag, 0);
  692. continue;
  693. }
  694. /* new ipset domain */
  695. ipset = _dns_conf_get_ipset(tok);
  696. if (ipset == NULL) {
  697. goto errout;
  698. }
  699. ipset_rule = _new_dns_rule(type);
  700. if (ipset_rule == NULL) {
  701. goto errout;
  702. }
  703. ipset_rule->ipsetname = ipset;
  704. if (_config_domain_rule_add(domain, type, ipset_rule) != 0) {
  705. goto errout;
  706. }
  707. _dns_rule_put(&ipset_rule->head);
  708. }
  709. goto clear;
  710. errout:
  711. tlog(TLOG_ERROR, "add ipset %s failed", ipsetname);
  712. if (ipset_rule) {
  713. _dns_rule_put(&ipset_rule->head);
  714. }
  715. clear:
  716. if (copied_name) {
  717. free(copied_name);
  718. }
  719. return 0;
  720. }
  721. static int _config_ipset(void *data, int argc, char *argv[])
  722. {
  723. char domain[DNS_MAX_CONF_CNAME_LEN];
  724. char *value = argv[1];
  725. if (argc <= 1) {
  726. goto errout;
  727. }
  728. if (_get_domain(value, domain, DNS_MAX_CONF_CNAME_LEN, &value) != 0) {
  729. goto errout;
  730. }
  731. return _conf_domain_rule_ipset(domain, value);
  732. errout:
  733. tlog(TLOG_ERROR, "add ipset %s failed", value);
  734. return 0;
  735. }
  736. static void _config_nftset_table_destroy(void)
  737. {
  738. struct dns_nftset_name *nftset = NULL;
  739. struct hlist_node *tmp = NULL;
  740. unsigned long i = 0;
  741. hash_for_each_safe(dns_nftset_table.nftset, i, tmp, nftset, node)
  742. {
  743. hlist_del_init(&nftset->node);
  744. free(nftset);
  745. }
  746. }
  747. static const struct dns_nftset_name *_dns_conf_get_nftable(const char *familyname, const char *tablename,
  748. const char *setname)
  749. {
  750. uint32_t key = 0;
  751. struct dns_nftset_name *nftset_name = NULL;
  752. if (familyname == NULL || tablename == NULL || setname == NULL) {
  753. return NULL;
  754. }
  755. const char *hasher[4] = {familyname, tablename, setname, NULL};
  756. key = hash_string_array(hasher);
  757. hash_for_each_possible(dns_nftset_table.nftset, nftset_name, node, key)
  758. {
  759. if (strncmp(nftset_name->nftfamilyname, familyname, DNS_MAX_NFTSET_FAMILYLEN) == 0 &&
  760. strncmp(nftset_name->nfttablename, tablename, DNS_MAX_NFTSET_NAMELEN) == 0 &&
  761. strncmp(nftset_name->nftsetname, setname, DNS_MAX_NFTSET_NAMELEN) == 0) {
  762. return nftset_name;
  763. }
  764. }
  765. nftset_name = malloc(sizeof(*nftset_name));
  766. if (nftset_name == NULL) {
  767. goto errout;
  768. }
  769. safe_strncpy(nftset_name->nftfamilyname, familyname, DNS_MAX_NFTSET_FAMILYLEN);
  770. safe_strncpy(nftset_name->nfttablename, tablename, DNS_MAX_NFTSET_NAMELEN);
  771. safe_strncpy(nftset_name->nftsetname, setname, DNS_MAX_NFTSET_NAMELEN);
  772. hash_add(dns_nftset_table.nftset, &nftset_name->node, key);
  773. return nftset_name;
  774. errout:
  775. if (nftset_name) {
  776. free(nftset_name);
  777. }
  778. return NULL;
  779. }
  780. static int _conf_domain_rule_nftset(char *domain, const char *nftsetname)
  781. {
  782. struct dns_nftset_rule *nftset_rule = NULL;
  783. const struct dns_nftset_name *nftset = NULL;
  784. char *copied_name = NULL;
  785. enum domain_rule type = 0;
  786. int ignore_flag = 0;
  787. char *setname = NULL;
  788. char *tablename = NULL;
  789. char *family = NULL;
  790. copied_name = strdup(nftsetname);
  791. if (copied_name == NULL) {
  792. goto errout;
  793. }
  794. for (char *tok = strtok(copied_name, ","); tok; tok = strtok(NULL, ",")) {
  795. char *saveptr = NULL;
  796. char *tok_set = NULL;
  797. nftset_rule = NULL;
  798. if (strncmp(tok, "#4:", 3U) == 0) {
  799. type = DOMAIN_RULE_NFTSET_IP;
  800. ignore_flag = DOMAIN_FLAG_NFTSET_IP_IGN;
  801. } else if (strncmp(tok, "#6:", 3U) == 0) {
  802. type = DOMAIN_RULE_NFTSET_IP6;
  803. ignore_flag = DOMAIN_FLAG_NFTSET_IP6_IGN;
  804. } else if (strncmp(tok, "-", 2U) == 0) {
  805. _config_domain_rule_flag_set(domain, DOMAIN_FLAG_NFTSET_INET_IGN, 0);
  806. continue;
  807. } else {
  808. goto errout;
  809. }
  810. tok_set = tok + 3;
  811. if (strncmp(tok_set, "-", 2U) == 0) {
  812. _config_domain_rule_flag_set(domain, ignore_flag, 0);
  813. continue;
  814. }
  815. family = strtok_r(tok_set, "#", &saveptr);
  816. if (family == NULL) {
  817. goto errout;
  818. }
  819. tablename = strtok_r(NULL, "#", &saveptr);
  820. if (tablename == NULL) {
  821. goto errout;
  822. }
  823. setname = strtok_r(NULL, "#", &saveptr);
  824. if (setname == NULL) {
  825. goto errout;
  826. }
  827. /* new ipset domain */
  828. nftset = _dns_conf_get_nftable(family, tablename, setname);
  829. if (nftset == NULL) {
  830. goto errout;
  831. }
  832. nftset_rule = _new_dns_rule(type);
  833. if (nftset_rule == NULL) {
  834. goto errout;
  835. }
  836. nftset_rule->nfttablename = nftset->nfttablename;
  837. nftset_rule->nftsetname = nftset->nftsetname;
  838. nftset_rule->familyname = nftset->nftfamilyname;
  839. if (_config_domain_rule_add(domain, type, nftset_rule) != 0) {
  840. goto errout;
  841. }
  842. _dns_rule_put(&nftset_rule->head);
  843. }
  844. goto clear;
  845. errout:
  846. tlog(TLOG_ERROR, "add nftset %s %s failed", domain, nftsetname);
  847. if (nftset_rule) {
  848. _dns_rule_put(&nftset_rule->head);
  849. }
  850. clear:
  851. if (copied_name) {
  852. free(copied_name);
  853. }
  854. return 0;
  855. }
  856. static int _config_nftset(void *data, int argc, char *argv[])
  857. {
  858. char domain[DNS_MAX_CONF_CNAME_LEN];
  859. char *value = argv[1];
  860. if (argc <= 1) {
  861. goto errout;
  862. }
  863. if (_get_domain(value, domain, DNS_MAX_CONF_CNAME_LEN, &value) != 0) {
  864. goto errout;
  865. }
  866. return _conf_domain_rule_nftset(domain, value);
  867. errout:
  868. tlog(TLOG_ERROR, "add nftset %s failed", value);
  869. return 0;
  870. }
  871. static int _conf_domain_rule_address(char *domain, const char *domain_address)
  872. {
  873. struct dns_rule_address_IPV4 *address_ipv4 = NULL;
  874. struct dns_rule_address_IPV6 *address_ipv6 = NULL;
  875. struct dns_rule *address = NULL;
  876. char ip[MAX_IP_LEN];
  877. int port = 0;
  878. struct sockaddr_storage addr;
  879. socklen_t addr_len = sizeof(addr);
  880. enum domain_rule type = 0;
  881. unsigned int flag = 0;
  882. if (*(domain_address) == '#') {
  883. if (strncmp(domain_address, "#4", sizeof("#4")) == 0) {
  884. flag = DOMAIN_FLAG_ADDR_IPV4_SOA;
  885. } else if (strncmp(domain_address, "#6", sizeof("#6")) == 0) {
  886. flag = DOMAIN_FLAG_ADDR_IPV6_SOA;
  887. } else if (strncmp(domain_address, "#", sizeof("#")) == 0) {
  888. flag = DOMAIN_FLAG_ADDR_SOA;
  889. } else {
  890. goto errout;
  891. }
  892. /* add SOA rule */
  893. if (_config_domain_rule_flag_set(domain, flag, 0) != 0) {
  894. goto errout;
  895. }
  896. return 0;
  897. } else if (*(domain_address) == '-') {
  898. if (strncmp(domain_address, "-4", sizeof("-4")) == 0) {
  899. flag = DOMAIN_FLAG_ADDR_IPV4_IGN;
  900. } else if (strncmp(domain_address, "-6", sizeof("-6")) == 0) {
  901. flag = DOMAIN_FLAG_ADDR_IPV6_IGN;
  902. } else if (strncmp(domain_address, "-", sizeof("-")) == 0) {
  903. flag = DOMAIN_FLAG_ADDR_IGN;
  904. } else {
  905. goto errout;
  906. }
  907. /* ignore rule */
  908. if (_config_domain_rule_flag_set(domain, flag, 0) != 0) {
  909. goto errout;
  910. }
  911. return 0;
  912. } else {
  913. /* set address to domain */
  914. if (parse_ip(domain_address, ip, &port) != 0) {
  915. goto errout;
  916. }
  917. if (getaddr_by_host(ip, (struct sockaddr *)&addr, &addr_len) != 0) {
  918. goto errout;
  919. }
  920. switch (addr.ss_family) {
  921. case AF_INET: {
  922. struct sockaddr_in *addr_in = NULL;
  923. address_ipv4 = _new_dns_rule(DOMAIN_RULE_ADDRESS_IPV4);
  924. if (address_ipv4 == NULL) {
  925. goto errout;
  926. }
  927. addr_in = (struct sockaddr_in *)&addr;
  928. memcpy(address_ipv4->ipv4_addr, &addr_in->sin_addr.s_addr, 4);
  929. type = DOMAIN_RULE_ADDRESS_IPV4;
  930. address = (struct dns_rule *)address_ipv4;
  931. } break;
  932. case AF_INET6: {
  933. struct sockaddr_in6 *addr_in6 = NULL;
  934. addr_in6 = (struct sockaddr_in6 *)&addr;
  935. if (IN6_IS_ADDR_V4MAPPED(&addr_in6->sin6_addr)) {
  936. address_ipv4 = _new_dns_rule(DOMAIN_RULE_ADDRESS_IPV4);
  937. if (address_ipv4 == NULL) {
  938. goto errout;
  939. }
  940. memcpy(address_ipv4->ipv4_addr, addr_in6->sin6_addr.s6_addr + 12, 4);
  941. type = DOMAIN_RULE_ADDRESS_IPV4;
  942. address = (struct dns_rule *)address_ipv4;
  943. } else {
  944. address_ipv6 = _new_dns_rule(DOMAIN_RULE_ADDRESS_IPV6);
  945. if (address_ipv6 == NULL) {
  946. goto errout;
  947. }
  948. memcpy(address_ipv6->ipv6_addr, addr_in6->sin6_addr.s6_addr, 16);
  949. type = DOMAIN_RULE_ADDRESS_IPV6;
  950. address = (struct dns_rule *)address_ipv6;
  951. }
  952. } break;
  953. default:
  954. goto errout;
  955. }
  956. }
  957. /* add domain to ART-tree */
  958. if (_config_domain_rule_add(domain, type, address) != 0) {
  959. goto errout;
  960. }
  961. _dns_rule_put(address);
  962. return 0;
  963. errout:
  964. if (address) {
  965. _dns_rule_put(address);
  966. }
  967. tlog(TLOG_ERROR, "add address %s, %s failed", domain, domain_address);
  968. return 0;
  969. }
  970. static int _config_address(void *data, int argc, char *argv[])
  971. {
  972. char *value = argv[1];
  973. char domain[DNS_MAX_CONF_CNAME_LEN];
  974. if (argc <= 1) {
  975. goto errout;
  976. }
  977. if (_get_domain(value, domain, DNS_MAX_CONF_CNAME_LEN, &value) != 0) {
  978. goto errout;
  979. }
  980. return _conf_domain_rule_address(domain, value);
  981. errout:
  982. tlog(TLOG_ERROR, "add address %s failed", value);
  983. return 0;
  984. }
  985. static void _config_speed_check_mode_clear(struct dns_domain_check_orders *check_orders)
  986. {
  987. memset(check_orders->orders, 0, sizeof(check_orders->orders));
  988. }
  989. static int _config_speed_check_mode_parser(struct dns_domain_check_orders *check_orders, const char *mode)
  990. {
  991. char tmpbuff[DNS_MAX_OPT_LEN];
  992. char *field = NULL;
  993. char *ptr = NULL;
  994. int order = 0;
  995. int port = 80;
  996. int i = 0;
  997. safe_strncpy(tmpbuff, mode, DNS_MAX_OPT_LEN);
  998. _config_speed_check_mode_clear(check_orders);
  999. ptr = tmpbuff;
  1000. do {
  1001. field = ptr;
  1002. ptr = strstr(ptr, ",");
  1003. if (field == NULL || order >= DOMAIN_CHECK_NUM) {
  1004. return 0;
  1005. }
  1006. if (ptr) {
  1007. *ptr = 0;
  1008. }
  1009. if (strncmp(field, "ping", sizeof("ping")) == 0) {
  1010. if (dns_has_cap_ping == 0) {
  1011. if (ptr) {
  1012. ptr++;
  1013. }
  1014. continue;
  1015. }
  1016. check_orders->orders[order].type = DOMAIN_CHECK_ICMP;
  1017. check_orders->orders[order].tcp_port = 0;
  1018. } else if (strstr(field, "tcp") == field) {
  1019. char *port_str = strstr(field, ":");
  1020. if (port_str) {
  1021. port = atoi(port_str + 1);
  1022. if (port <= 0 || port >= 65535) {
  1023. port = 80;
  1024. }
  1025. }
  1026. check_orders->orders[order].type = DOMAIN_CHECK_TCP;
  1027. check_orders->orders[order].tcp_port = port;
  1028. } else if (strncmp(field, "none", sizeof("none")) == 0) {
  1029. for (i = order; i < DOMAIN_CHECK_NUM; i++) {
  1030. check_orders->orders[i].type = DOMAIN_CHECK_NONE;
  1031. check_orders->orders[i].tcp_port = 0;
  1032. }
  1033. return 0;
  1034. }
  1035. order++;
  1036. if (ptr) {
  1037. ptr++;
  1038. }
  1039. } while (ptr);
  1040. return 0;
  1041. }
  1042. static int _config_speed_check_mode(void *data, int argc, char *argv[])
  1043. {
  1044. char mode[DNS_MAX_OPT_LEN];
  1045. if (argc <= 1) {
  1046. return -1;
  1047. }
  1048. safe_strncpy(mode, argv[1], sizeof(mode));
  1049. return _config_speed_check_mode_parser(&dns_conf_check_orders, mode);
  1050. }
  1051. static int _config_bind_ip(int argc, char *argv[], DNS_BIND_TYPE type)
  1052. {
  1053. int index = dns_conf_bind_ip_num;
  1054. struct dns_bind_ip *bind_ip = NULL;
  1055. char *ip = NULL;
  1056. int opt = 0;
  1057. char group_name[DNS_GROUP_NAME_LEN];
  1058. const char *group = NULL;
  1059. unsigned int server_flag = 0;
  1060. int i = 0;
  1061. /* clang-format off */
  1062. static struct option long_options[] = {
  1063. {"group", required_argument, NULL, 'g'}, /* add to group */
  1064. {"no-rule-addr", no_argument, NULL, 'A'},
  1065. {"no-rule-nameserver", no_argument, NULL, 'N'},
  1066. {"no-rule-ipset", no_argument, NULL, 'I'},
  1067. {"no-rule-sni-proxy", no_argument, NULL, 'P'},
  1068. {"no-rule-soa", no_argument, NULL, 'O'},
  1069. {"no-speed-check", no_argument, NULL, 'S'},
  1070. {"no-cache", no_argument, NULL, 'C'},
  1071. {"no-dualstack-selection", no_argument, NULL, 'D'},
  1072. {"force-aaaa-soa", no_argument, NULL, 'F'},
  1073. {NULL, no_argument, NULL, 0}
  1074. };
  1075. /* clang-format on */
  1076. if (argc <= 1) {
  1077. tlog(TLOG_ERROR, "invalid parameter.");
  1078. goto errout;
  1079. }
  1080. ip = argv[1];
  1081. if (index >= DNS_MAX_SERVERS) {
  1082. tlog(TLOG_WARN, "exceeds max server number, %s", ip);
  1083. return 0;
  1084. }
  1085. for (i = 0; i < dns_conf_bind_ip_num; i++) {
  1086. bind_ip = &dns_conf_bind_ip[i];
  1087. if (bind_ip->type != type) {
  1088. continue;
  1089. }
  1090. if (strncmp(bind_ip->ip, ip, DNS_MAX_IPLEN) != 0) {
  1091. continue;
  1092. }
  1093. tlog(TLOG_WARN, "Bind server %s, type %d, already configured, skip.", ip, type);
  1094. return 0;
  1095. }
  1096. bind_ip = &dns_conf_bind_ip[index];
  1097. bind_ip->type = type;
  1098. bind_ip->flags = 0;
  1099. safe_strncpy(bind_ip->ip, ip, DNS_MAX_IPLEN);
  1100. /* process extra options */
  1101. optind = 1;
  1102. while (1) {
  1103. opt = getopt_long_only(argc, argv, "", long_options, NULL);
  1104. if (opt == -1) {
  1105. break;
  1106. }
  1107. switch (opt) {
  1108. case 'g': {
  1109. safe_strncpy(group_name, optarg, DNS_GROUP_NAME_LEN);
  1110. group = _dns_conf_get_group_name(group_name);
  1111. break;
  1112. }
  1113. case 'A': {
  1114. server_flag |= BIND_FLAG_NO_RULE_ADDR;
  1115. break;
  1116. }
  1117. case 'N': {
  1118. server_flag |= BIND_FLAG_NO_RULE_NAMESERVER;
  1119. break;
  1120. }
  1121. case 'I': {
  1122. server_flag |= BIND_FLAG_NO_RULE_IPSET;
  1123. break;
  1124. }
  1125. case 'P': {
  1126. server_flag |= BIND_FLAG_NO_RULE_SNIPROXY;
  1127. break;
  1128. }
  1129. case 'S': {
  1130. server_flag |= BIND_FLAG_NO_SPEED_CHECK;
  1131. break;
  1132. }
  1133. case 'C': {
  1134. server_flag |= BIND_FLAG_NO_CACHE;
  1135. break;
  1136. }
  1137. case 'O': {
  1138. server_flag |= BIND_FLAG_NO_RULE_SOA;
  1139. break;
  1140. }
  1141. case 'D': {
  1142. server_flag |= BIND_FLAG_NO_DUALSTACK_SELECTION;
  1143. break;
  1144. }
  1145. case 'F': {
  1146. server_flag |= BIND_FLAG_FORCE_AAAA_SOA;
  1147. break;
  1148. }
  1149. default:
  1150. break;
  1151. }
  1152. }
  1153. /* add new server */
  1154. bind_ip->flags = server_flag;
  1155. bind_ip->group = group;
  1156. dns_conf_bind_ip_num++;
  1157. tlog(TLOG_DEBUG, "bind ip %s, type: %d, flag: %X", ip, type, server_flag);
  1158. return 0;
  1159. errout:
  1160. return -1;
  1161. }
  1162. static int _config_bind_ip_udp(void *data, int argc, char *argv[])
  1163. {
  1164. return _config_bind_ip(argc, argv, DNS_BIND_TYPE_UDP);
  1165. }
  1166. static int _config_bind_ip_tcp(void *data, int argc, char *argv[])
  1167. {
  1168. return _config_bind_ip(argc, argv, DNS_BIND_TYPE_TCP);
  1169. }
  1170. static int _config_server_udp(void *data, int argc, char *argv[])
  1171. {
  1172. return _config_server(argc, argv, DNS_SERVER_UDP, DEFAULT_DNS_PORT);
  1173. }
  1174. static int _config_server_tcp(void *data, int argc, char *argv[])
  1175. {
  1176. return _config_server(argc, argv, DNS_SERVER_TCP, DEFAULT_DNS_PORT);
  1177. }
  1178. static int _config_server_tls(void *data, int argc, char *argv[])
  1179. {
  1180. return _config_server(argc, argv, DNS_SERVER_TLS, DEFAULT_DNS_TLS_PORT);
  1181. }
  1182. static int _config_server_https(void *data, int argc, char *argv[])
  1183. {
  1184. int ret = 0;
  1185. ret = _config_server(argc, argv, DNS_SERVER_HTTPS, DEFAULT_DNS_HTTPS_PORT);
  1186. return ret;
  1187. }
  1188. static int _conf_domain_rule_nameserver(char *domain, const char *group_name)
  1189. {
  1190. struct dns_nameserver_rule *nameserver_rule = NULL;
  1191. const char *group = NULL;
  1192. if (strncmp(group_name, "-", sizeof("-")) != 0) {
  1193. group = _dns_conf_get_group_name(group_name);
  1194. if (group == NULL) {
  1195. goto errout;
  1196. }
  1197. nameserver_rule = _new_dns_rule(DOMAIN_RULE_NAMESERVER);
  1198. if (nameserver_rule == NULL) {
  1199. goto errout;
  1200. }
  1201. nameserver_rule->group_name = group;
  1202. } else {
  1203. /* ignore this domain */
  1204. if (_config_domain_rule_flag_set(domain, DOMAIN_FLAG_NAMESERVER_IGNORE, 0) != 0) {
  1205. goto errout;
  1206. }
  1207. return 0;
  1208. }
  1209. if (_config_domain_rule_add(domain, DOMAIN_RULE_NAMESERVER, nameserver_rule) != 0) {
  1210. goto errout;
  1211. }
  1212. _dns_rule_put(&nameserver_rule->head);
  1213. return 0;
  1214. errout:
  1215. if (nameserver_rule) {
  1216. _dns_rule_put(&nameserver_rule->head);
  1217. }
  1218. tlog(TLOG_ERROR, "add nameserver %s, %s failed", domain, group_name);
  1219. return 0;
  1220. }
  1221. static int _conf_domain_rule_dualstack_selection(char *domain, const char *yesno)
  1222. {
  1223. if (strncmp(yesno, "yes", sizeof("yes")) == 0 || strncmp(yesno, "Yes", sizeof("Yes")) == 0) {
  1224. if (_config_domain_rule_flag_set(domain, DOMAIN_FLAG_DUALSTACK_SELECT, 0) != 0) {
  1225. goto errout;
  1226. }
  1227. } else {
  1228. /* ignore this domain */
  1229. if (_config_domain_rule_flag_set(domain, DOMAIN_FLAG_DUALSTACK_SELECT, 1) != 0) {
  1230. goto errout;
  1231. }
  1232. }
  1233. return 0;
  1234. errout:
  1235. tlog(TLOG_ERROR, "set dualstack for %s failed. ", domain);
  1236. return 1;
  1237. }
  1238. static int _config_nameserver(void *data, int argc, char *argv[])
  1239. {
  1240. char domain[DNS_MAX_CONF_CNAME_LEN];
  1241. char *value = argv[1];
  1242. if (argc <= 1) {
  1243. goto errout;
  1244. }
  1245. if (_get_domain(value, domain, DNS_MAX_CONF_CNAME_LEN, &value) != 0) {
  1246. goto errout;
  1247. }
  1248. return _conf_domain_rule_nameserver(domain, value);
  1249. errout:
  1250. tlog(TLOG_ERROR, "add nameserver %s failed", value);
  1251. return 0;
  1252. }
  1253. static radix_node_t *_create_addr_node(char *addr)
  1254. {
  1255. radix_node_t *node = NULL;
  1256. void *p = NULL;
  1257. prefix_t prefix;
  1258. const char *errmsg = NULL;
  1259. radix_tree_t *tree = NULL;
  1260. p = prefix_pton(addr, -1, &prefix, &errmsg);
  1261. if (p == NULL) {
  1262. return NULL;
  1263. }
  1264. switch (prefix.family) {
  1265. case AF_INET:
  1266. tree = dns_conf_address_rule.ipv4;
  1267. break;
  1268. case AF_INET6:
  1269. tree = dns_conf_address_rule.ipv6;
  1270. break;
  1271. }
  1272. node = radix_lookup(tree, &prefix);
  1273. return node;
  1274. }
  1275. static int _config_iplist_rule(char *subnet, enum address_rule rule)
  1276. {
  1277. radix_node_t *node = NULL;
  1278. struct dns_ip_address_rule *ip_rule = NULL;
  1279. node = _create_addr_node(subnet);
  1280. if (node == NULL) {
  1281. return -1;
  1282. }
  1283. if (node->data == NULL) {
  1284. ip_rule = malloc(sizeof(*ip_rule));
  1285. if (ip_rule == NULL) {
  1286. return -1;
  1287. }
  1288. node->data = ip_rule;
  1289. memset(ip_rule, 0, sizeof(*ip_rule));
  1290. }
  1291. ip_rule = node->data;
  1292. switch (rule) {
  1293. case ADDRESS_RULE_BLACKLIST:
  1294. ip_rule->blacklist = 1;
  1295. break;
  1296. case ADDRESS_RULE_WHITELIST:
  1297. ip_rule->whitelist = 1;
  1298. break;
  1299. case ADDRESS_RULE_BOGUS:
  1300. ip_rule->bogus = 1;
  1301. break;
  1302. case ADDRESS_RULE_IP_IGNORE:
  1303. ip_rule->ip_ignore = 1;
  1304. break;
  1305. default:
  1306. return -1;
  1307. }
  1308. return 0;
  1309. }
  1310. static int _config_qtype_soa(void *data, int argc, char *argv[])
  1311. {
  1312. struct dns_qtype_soa_list *soa_list = NULL;
  1313. int i = 0;
  1314. if (argc <= 1) {
  1315. return -1;
  1316. }
  1317. for (i = 1; i < argc; i++) {
  1318. soa_list = malloc(sizeof(*soa_list));
  1319. if (soa_list == NULL) {
  1320. tlog(TLOG_ERROR, "cannot malloc memory");
  1321. return -1;
  1322. }
  1323. memset(soa_list, 0, sizeof(*soa_list));
  1324. soa_list->qtypeid = atol(argv[i]);
  1325. if (soa_list->qtypeid == DNS_T_AAAA) {
  1326. dns_conf_force_AAAA_SOA = 1;
  1327. }
  1328. uint32_t key = hash_32_generic(soa_list->qtypeid, 32);
  1329. hash_add(dns_qtype_soa_table.qtype, &soa_list->node, key);
  1330. }
  1331. return 0;
  1332. }
  1333. static void _config_qtype_soa_table_destroy(void)
  1334. {
  1335. struct dns_qtype_soa_list *soa_list = NULL;
  1336. struct hlist_node *tmp = NULL;
  1337. unsigned long i = 0;
  1338. hash_for_each_safe(dns_qtype_soa_table.qtype, i, tmp, soa_list, node)
  1339. {
  1340. hlist_del_init(&soa_list->node);
  1341. free(soa_list);
  1342. }
  1343. }
  1344. static void _config_domain_set_name_table_destroy(void)
  1345. {
  1346. struct dns_domain_set_name_list *set_name_list = NULL;
  1347. struct hlist_node *tmp = NULL;
  1348. struct dns_domain_set_name *set_name = NULL;
  1349. struct dns_domain_set_name *tmp1 = NULL;
  1350. unsigned long i = 0;
  1351. hash_for_each_safe(dns_domain_set_name_table.names, i, tmp, set_name_list, node)
  1352. {
  1353. hlist_del_init(&set_name_list->node);
  1354. list_for_each_entry_safe(set_name, tmp1, &set_name_list->set_name_list, list)
  1355. {
  1356. list_del(&set_name->list);
  1357. free(set_name);
  1358. }
  1359. free(set_name_list);
  1360. }
  1361. }
  1362. static void _config_domain_set_rule_table_destroy(void)
  1363. {
  1364. struct dns_domain_set_rule_list *set_rule_list = NULL;
  1365. struct hlist_node *tmp = NULL;
  1366. struct dns_domain_set_rule *set_rule = NULL;
  1367. struct dns_domain_set_rule *tmp1 = NULL;
  1368. unsigned long i = 0;
  1369. hash_for_each_safe(dns_domain_set_rule_table.rule_list, i, tmp, set_rule_list, node)
  1370. {
  1371. hlist_del_init(&set_rule_list->node);
  1372. list_for_each_entry_safe(set_rule, tmp1, &set_rule_list->domain_ruls_list, list)
  1373. {
  1374. list_del(&set_rule->list);
  1375. if (set_rule->rule) {
  1376. _dns_rule_put(set_rule->rule);
  1377. }
  1378. free(set_rule);
  1379. }
  1380. free(set_rule_list);
  1381. }
  1382. }
  1383. static int _config_blacklist_ip(void *data, int argc, char *argv[])
  1384. {
  1385. if (argc <= 1) {
  1386. return -1;
  1387. }
  1388. return _config_iplist_rule(argv[1], ADDRESS_RULE_BLACKLIST);
  1389. }
  1390. static int _conf_bogus_nxdomain(void *data, int argc, char *argv[])
  1391. {
  1392. if (argc <= 1) {
  1393. return -1;
  1394. }
  1395. return _config_iplist_rule(argv[1], ADDRESS_RULE_BOGUS);
  1396. }
  1397. static int _conf_ip_ignore(void *data, int argc, char *argv[])
  1398. {
  1399. if (argc <= 1) {
  1400. return -1;
  1401. }
  1402. return _config_iplist_rule(argv[1], ADDRESS_RULE_IP_IGNORE);
  1403. }
  1404. static int _conf_whitelist_ip(void *data, int argc, char *argv[])
  1405. {
  1406. if (argc <= 1) {
  1407. return -1;
  1408. }
  1409. return _config_iplist_rule(argv[1], ADDRESS_RULE_WHITELIST);
  1410. }
  1411. static int _conf_edns_client_subnet(void *data, int argc, char *argv[])
  1412. {
  1413. char *slash = NULL;
  1414. char *value = NULL;
  1415. int subnet = 0;
  1416. struct dns_edns_client_subnet *ecs = NULL;
  1417. struct sockaddr_storage addr;
  1418. socklen_t addr_len = sizeof(addr);
  1419. if (argc <= 1) {
  1420. return -1;
  1421. }
  1422. value = argv[1];
  1423. slash = strstr(value, "/");
  1424. if (slash) {
  1425. *slash = 0;
  1426. slash++;
  1427. subnet = atoi(slash);
  1428. if (subnet < 0 || subnet > 128) {
  1429. return -1;
  1430. }
  1431. }
  1432. if (getaddr_by_host(value, (struct sockaddr *)&addr, &addr_len) != 0) {
  1433. goto errout;
  1434. }
  1435. switch (addr.ss_family) {
  1436. case AF_INET:
  1437. ecs = &dns_conf_ipv4_ecs;
  1438. break;
  1439. case AF_INET6:
  1440. ecs = &dns_conf_ipv6_ecs;
  1441. break;
  1442. default:
  1443. goto errout;
  1444. }
  1445. safe_strncpy(ecs->ip, value, DNS_MAX_IPLEN);
  1446. ecs->subnet = subnet;
  1447. ecs->enable = 1;
  1448. return 0;
  1449. errout:
  1450. return -1;
  1451. }
  1452. static int _conf_domain_rule_speed_check(char *domain, const char *mode)
  1453. {
  1454. struct dns_domain_check_orders *check_orders = NULL;
  1455. check_orders = _new_dns_rule(DOMAIN_RULE_CHECKSPEED);
  1456. if (check_orders == NULL) {
  1457. goto errout;
  1458. }
  1459. if (_config_speed_check_mode_parser(check_orders, mode) != 0) {
  1460. goto errout;
  1461. }
  1462. if (_config_domain_rule_add(domain, DOMAIN_RULE_CHECKSPEED, check_orders) != 0) {
  1463. goto errout;
  1464. }
  1465. _dns_rule_put(&check_orders->head);
  1466. return 0;
  1467. errout:
  1468. if (check_orders) {
  1469. _dns_rule_put(&check_orders->head);
  1470. }
  1471. return 0;
  1472. }
  1473. static int _conf_domain_set(void *data, int argc, char *argv[])
  1474. {
  1475. int opt = 0;
  1476. uint32_t key = 0;
  1477. struct dns_domain_set_name *domain_set = NULL;
  1478. struct dns_domain_set_name_list *domain_set_name_list = NULL;
  1479. char set_name[DNS_MAX_CNAME_LEN] = {0};
  1480. /* clang-format off */
  1481. static struct option long_options[] = {
  1482. {"name", required_argument, NULL, 'n'},
  1483. {"type", required_argument, NULL, 't'},
  1484. {"file", required_argument, NULL, 'f'},
  1485. {NULL, 0, NULL, 0}
  1486. };
  1487. if (argc <= 1) {
  1488. tlog(TLOG_ERROR, "invalid parameter.");
  1489. goto errout;
  1490. }
  1491. domain_set = malloc(sizeof(*domain_set));
  1492. if (domain_set == NULL) {
  1493. tlog(TLOG_ERROR, "cannot malloc memory.");
  1494. goto errout;
  1495. }
  1496. memset(domain_set, 0, sizeof(*domain_set));
  1497. INIT_LIST_HEAD(&domain_set->list);
  1498. optind = 1;
  1499. while (1) {
  1500. opt = getopt_long_only(argc, argv, "n:t:f:", long_options, NULL);
  1501. if (opt == -1) {
  1502. break;
  1503. }
  1504. switch (opt) {
  1505. case 'n':
  1506. safe_strncpy(set_name, optarg, DNS_MAX_CNAME_LEN);
  1507. break;
  1508. case 't': {
  1509. const char *type = optarg;
  1510. if (strncmp(type, "list", 5) == 0) {
  1511. domain_set->type = DNS_DOMAIN_SET_LIST;
  1512. } else if (strncmp(type, "geosite", 7) == 0) {
  1513. domain_set->type = DNS_DOMAIN_SET_GEOSITE;
  1514. } else {
  1515. tlog(TLOG_ERROR, "invalid domain set type.");
  1516. goto errout;
  1517. }
  1518. break;
  1519. }
  1520. case 'f':
  1521. conf_get_conf_fullpath(optarg, domain_set->file, DNS_MAX_PATH);
  1522. break;
  1523. default:
  1524. break;
  1525. }
  1526. }
  1527. /* clang-format on */
  1528. if (set_name[0] == 0 || domain_set->file[0] == 0) {
  1529. tlog(TLOG_ERROR, "invalid parameter.");
  1530. goto errout;
  1531. }
  1532. key = hash_string(set_name);
  1533. hash_for_each_possible(dns_domain_set_name_table.names, domain_set_name_list, node, key)
  1534. {
  1535. if (strcmp(domain_set_name_list->name, set_name) == 0) {
  1536. break;
  1537. }
  1538. }
  1539. if (domain_set_name_list == NULL) {
  1540. domain_set_name_list = malloc(sizeof(*domain_set_name_list));
  1541. if (domain_set_name_list == NULL) {
  1542. tlog(TLOG_ERROR, "cannot malloc memory.");
  1543. goto errout;
  1544. }
  1545. memset(domain_set_name_list, 0, sizeof(*domain_set_name_list));
  1546. INIT_LIST_HEAD(&domain_set_name_list->set_name_list);
  1547. safe_strncpy(domain_set_name_list->name, set_name, DNS_MAX_CNAME_LEN);
  1548. hash_add(dns_domain_set_name_table.names, &domain_set_name_list->node, key);
  1549. }
  1550. list_add_tail(&domain_set->list, &domain_set_name_list->set_name_list);
  1551. return 0;
  1552. errout:
  1553. if (domain_set) {
  1554. free(domain_set);
  1555. }
  1556. return -1;
  1557. }
  1558. static int _conf_domain_rule_no_serve_expired(const char *domain)
  1559. {
  1560. return _config_domain_rule_flag_set(domain, DOMAIN_FLAG_NO_SERVE_EXPIRED, 0);
  1561. }
  1562. static int _conf_domain_rules(void *data, int argc, char *argv[])
  1563. {
  1564. int opt = 0;
  1565. char domain[DNS_MAX_CONF_CNAME_LEN];
  1566. char *value = argv[1];
  1567. /* clang-format off */
  1568. static struct option long_options[] = {
  1569. {"speed-check-mode", required_argument, NULL, 'c'},
  1570. {"address", required_argument, NULL, 'a'},
  1571. {"ipset", required_argument, NULL, 'p'},
  1572. {"nftset", required_argument, NULL, 't'},
  1573. {"nameserver", required_argument, NULL, 'n'},
  1574. {"dualstack-ip-selection", required_argument, NULL, 'd'},
  1575. {"no-serve-expired", no_argument, NULL, 254},
  1576. {NULL, no_argument, NULL, 0}
  1577. };
  1578. /* clang-format on */
  1579. if (argc <= 1) {
  1580. tlog(TLOG_ERROR, "invalid parameter.");
  1581. goto errout;
  1582. }
  1583. if (_get_domain(value, domain, DNS_MAX_CONF_CNAME_LEN, &value) != 0) {
  1584. goto errout;
  1585. }
  1586. /* process extra options */
  1587. optind = 1;
  1588. while (1) {
  1589. opt = getopt_long_only(argc, argv, "c:a:p:t:n:d:", long_options, NULL);
  1590. if (opt == -1) {
  1591. break;
  1592. }
  1593. switch (opt) {
  1594. case 'c': {
  1595. const char *check_mode = optarg;
  1596. if (check_mode == NULL) {
  1597. goto errout;
  1598. }
  1599. if (_conf_domain_rule_speed_check(domain, check_mode) != 0) {
  1600. tlog(TLOG_ERROR, "add check-speed-rule rule failed.");
  1601. goto errout;
  1602. }
  1603. break;
  1604. }
  1605. case 'a': {
  1606. const char *address = optarg;
  1607. if (address == NULL) {
  1608. goto errout;
  1609. }
  1610. if (_conf_domain_rule_address(domain, address) != 0) {
  1611. tlog(TLOG_ERROR, "add address rule failed.");
  1612. goto errout;
  1613. }
  1614. break;
  1615. }
  1616. case 'p': {
  1617. const char *ipsetname = optarg;
  1618. if (ipsetname == NULL) {
  1619. goto errout;
  1620. }
  1621. if (_conf_domain_rule_ipset(domain, ipsetname) != 0) {
  1622. tlog(TLOG_ERROR, "add ipset rule failed.");
  1623. goto errout;
  1624. }
  1625. break;
  1626. }
  1627. case 'n': {
  1628. const char *nameserver_group = optarg;
  1629. if (nameserver_group == NULL) {
  1630. goto errout;
  1631. }
  1632. if (_conf_domain_rule_nameserver(domain, nameserver_group) != 0) {
  1633. tlog(TLOG_ERROR, "add nameserver rule failed.");
  1634. goto errout;
  1635. }
  1636. break;
  1637. }
  1638. case 'd': {
  1639. const char *yesno = optarg;
  1640. if (_conf_domain_rule_dualstack_selection(domain, yesno) != 0) {
  1641. tlog(TLOG_ERROR, "set dualstack selection rule failed.");
  1642. goto errout;
  1643. }
  1644. break;
  1645. }
  1646. case 't': {
  1647. const char *nftsetname = optarg;
  1648. if (nftsetname == NULL) {
  1649. goto errout;
  1650. }
  1651. if (_conf_domain_rule_nftset(domain, nftsetname) != 0) {
  1652. tlog(TLOG_ERROR, "add nftset rule failed.");
  1653. goto errout;
  1654. }
  1655. break;
  1656. }
  1657. case 254: {
  1658. if (_conf_domain_rule_no_serve_expired(domain) != 0) {
  1659. tlog(TLOG_ERROR, "set no-serve-expired rule failed.");
  1660. goto errout;
  1661. }
  1662. break;
  1663. }
  1664. default:
  1665. break;
  1666. }
  1667. }
  1668. return 0;
  1669. errout:
  1670. return -1;
  1671. }
  1672. static struct dns_ptr *_dns_conf_get_ptr(const char *ptr_domain)
  1673. {
  1674. uint32_t key = 0;
  1675. struct dns_ptr *ptr = NULL;
  1676. key = hash_string(ptr_domain);
  1677. hash_for_each_possible(dns_ptr_table.ptr, ptr, node, key)
  1678. {
  1679. if (strncmp(ptr->ptr_domain, ptr_domain, DNS_MAX_PTR_LEN) != 0) {
  1680. continue;
  1681. }
  1682. return ptr;
  1683. }
  1684. ptr = malloc(sizeof(*ptr));
  1685. if (ptr == NULL) {
  1686. goto errout;
  1687. }
  1688. safe_strncpy(ptr->ptr_domain, ptr_domain, DNS_MAX_PTR_LEN);
  1689. hash_add(dns_ptr_table.ptr, &ptr->node, key);
  1690. return ptr;
  1691. errout:
  1692. if (ptr) {
  1693. free(ptr);
  1694. }
  1695. return NULL;
  1696. }
  1697. static int _conf_ptr_add(const char *hostname, const char *ip)
  1698. {
  1699. struct dns_ptr *ptr = NULL;
  1700. struct sockaddr_storage addr;
  1701. unsigned char *paddr = NULL;
  1702. socklen_t addr_len = sizeof(addr);
  1703. char ptr_domain[DNS_MAX_PTR_LEN];
  1704. if (getaddr_by_host(ip, (struct sockaddr *)&addr, &addr_len) != 0) {
  1705. goto errout;
  1706. }
  1707. switch (addr.ss_family) {
  1708. case AF_INET: {
  1709. struct sockaddr_in *addr_in = NULL;
  1710. addr_in = (struct sockaddr_in *)&addr;
  1711. paddr = (unsigned char *)&(addr_in->sin_addr.s_addr);
  1712. snprintf(ptr_domain, sizeof(ptr_domain), "%d.%d.%d.%d.in-addr.arpa", paddr[3], paddr[2], paddr[1], paddr[0]);
  1713. } break;
  1714. case AF_INET6: {
  1715. struct sockaddr_in6 *addr_in6 = NULL;
  1716. addr_in6 = (struct sockaddr_in6 *)&addr;
  1717. if (IN6_IS_ADDR_V4MAPPED(&addr_in6->sin6_addr)) {
  1718. paddr = addr_in6->sin6_addr.s6_addr + 12;
  1719. snprintf(ptr_domain, sizeof(ptr_domain), "%d.%d.%d.%d.in-addr.arpa", paddr[3], paddr[2], paddr[1],
  1720. paddr[0]);
  1721. } else {
  1722. paddr = addr_in6->sin6_addr.s6_addr;
  1723. snprintf(ptr_domain, sizeof(ptr_domain),
  1724. "%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x."
  1725. "%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x."
  1726. "%x.ip6.arpa",
  1727. paddr[15] & 0xF, (paddr[15] >> 4) & 0xF, paddr[14] & 0xF, (paddr[14] >> 4) & 0xF, paddr[13] & 0xF,
  1728. (paddr[13] >> 4) & 0xF, paddr[12] & 0xF, (paddr[12] >> 4) & 0xF, paddr[11] & 0xF,
  1729. (paddr[11] >> 4) & 0xF, paddr[10] & 0xF, (paddr[10] >> 4) & 0xF, paddr[9] & 0xF,
  1730. (paddr[9] >> 4) & 0xF, paddr[8] & 0xF, (paddr[8] >> 4) & 0xF, paddr[7] & 0xF,
  1731. (paddr[7] >> 4) & 0xF, paddr[6] & 0xF, (paddr[6] >> 4) & 0xF, paddr[5] & 0xF,
  1732. (paddr[5] >> 4) & 0xF, paddr[4] & 0xF, (paddr[4] >> 4) & 0xF, paddr[3] & 0xF,
  1733. (paddr[3] >> 4) & 0xF, paddr[2] & 0xF, (paddr[2] >> 4) & 0xF, paddr[1] & 0xF,
  1734. (paddr[1] >> 4) & 0xF, paddr[0] & 0xF, (paddr[0] >> 4) & 0xF);
  1735. }
  1736. } break;
  1737. default:
  1738. goto errout;
  1739. break;
  1740. }
  1741. ptr = _dns_conf_get_ptr(ptr_domain);
  1742. if (ptr == NULL) {
  1743. goto errout;
  1744. }
  1745. safe_strncpy(ptr->hostname, hostname, DNS_MAX_CNAME_LEN);
  1746. return 0;
  1747. errout:
  1748. return -1;
  1749. }
  1750. static void _config_ptr_table_destroy(void)
  1751. {
  1752. struct dns_ptr *ptr = NULL;
  1753. struct hlist_node *tmp = NULL;
  1754. unsigned long i = 0;
  1755. hash_for_each_safe(dns_ptr_table.ptr, i, tmp, ptr, node)
  1756. {
  1757. hlist_del_init(&ptr->node);
  1758. free(ptr);
  1759. }
  1760. }
  1761. static struct dns_hosts *_dns_conf_get_hosts(const char *hostname, int dns_type)
  1762. {
  1763. uint32_t key = 0;
  1764. struct dns_hosts *host = NULL;
  1765. char hostname_lower[DNS_MAX_CNAME_LEN];
  1766. key = hash_string(to_lower_case(hostname_lower, hostname, DNS_MAX_CNAME_LEN));
  1767. key = jhash(&dns_type, sizeof(dns_type), key);
  1768. hash_for_each_possible(dns_hosts_table.hosts, host, node, key)
  1769. {
  1770. if (host->dns_type != dns_type) {
  1771. continue;
  1772. }
  1773. if (strncmp(host->domain, hostname_lower, DNS_MAX_CNAME_LEN) != 0) {
  1774. continue;
  1775. }
  1776. return host;
  1777. }
  1778. host = malloc(sizeof(*host));
  1779. if (host == NULL) {
  1780. goto errout;
  1781. }
  1782. safe_strncpy(host->domain, hostname_lower, DNS_MAX_CNAME_LEN);
  1783. host->dns_type = dns_type;
  1784. host->is_soa = 1;
  1785. hash_add(dns_hosts_table.hosts, &host->node, key);
  1786. return host;
  1787. errout:
  1788. if (host) {
  1789. free(host);
  1790. }
  1791. return NULL;
  1792. }
  1793. static int _conf_host_add(const char *hostname, const char *ip, dns_hosts_type host_type)
  1794. {
  1795. struct dns_hosts *host = NULL;
  1796. struct dns_hosts *host_other __attribute__((unused));
  1797. struct sockaddr_storage addr;
  1798. socklen_t addr_len = sizeof(addr);
  1799. int dns_type = 0;
  1800. int dns_type_other = 0;
  1801. if (getaddr_by_host(ip, (struct sockaddr *)&addr, &addr_len) != 0) {
  1802. goto errout;
  1803. }
  1804. switch (addr.ss_family) {
  1805. case AF_INET:
  1806. dns_type = DNS_T_A;
  1807. dns_type_other = DNS_T_AAAA;
  1808. break;
  1809. case AF_INET6: {
  1810. struct sockaddr_in6 *addr_in6 = NULL;
  1811. addr_in6 = (struct sockaddr_in6 *)&addr;
  1812. if (IN6_IS_ADDR_V4MAPPED(&addr_in6->sin6_addr)) {
  1813. dns_type = DNS_T_A;
  1814. dns_type_other = DNS_T_AAAA;
  1815. } else {
  1816. dns_type = DNS_T_AAAA;
  1817. dns_type_other = DNS_T_A;
  1818. }
  1819. } break;
  1820. default:
  1821. goto errout;
  1822. break;
  1823. }
  1824. host = _dns_conf_get_hosts(hostname, dns_type);
  1825. if (host == NULL) {
  1826. goto errout;
  1827. }
  1828. /* add this to return SOA when addr is not exist */
  1829. host_other = _dns_conf_get_hosts(hostname, dns_type_other);
  1830. host->host_type = host_type;
  1831. switch (addr.ss_family) {
  1832. case AF_INET: {
  1833. struct sockaddr_in *addr_in = NULL;
  1834. addr_in = (struct sockaddr_in *)&addr;
  1835. memcpy(host->ipv4_addr, &addr_in->sin_addr.s_addr, 4);
  1836. host->is_soa = 0;
  1837. } break;
  1838. case AF_INET6: {
  1839. struct sockaddr_in6 *addr_in6 = NULL;
  1840. addr_in6 = (struct sockaddr_in6 *)&addr;
  1841. if (IN6_IS_ADDR_V4MAPPED(&addr_in6->sin6_addr)) {
  1842. memcpy(host->ipv4_addr, addr_in6->sin6_addr.s6_addr + 12, 4);
  1843. } else {
  1844. memcpy(host->ipv6_addr, addr_in6->sin6_addr.s6_addr, 16);
  1845. }
  1846. host->is_soa = 0;
  1847. } break;
  1848. default:
  1849. goto errout;
  1850. }
  1851. dns_hosts_record_num++;
  1852. return 0;
  1853. errout:
  1854. return -1;
  1855. }
  1856. static int _conf_dhcp_lease_dnsmasq_add(const char *file)
  1857. {
  1858. FILE *fp = NULL;
  1859. char line[MAX_LINE_LEN];
  1860. char ip[DNS_MAX_IPLEN];
  1861. char hostname[DNS_MAX_CNAME_LEN];
  1862. int ret = 0;
  1863. int line_no = 0;
  1864. int filed_num = 0;
  1865. fp = fopen(file, "r");
  1866. if (fp == NULL) {
  1867. tlog(TLOG_WARN, "open file %s error, %s", file, strerror(errno));
  1868. return 0;
  1869. }
  1870. line_no = 0;
  1871. while (fgets(line, MAX_LINE_LEN, fp)) {
  1872. line_no++;
  1873. filed_num = sscanf(line, "%*s %*s %64s %256s %*s", ip, hostname);
  1874. if (filed_num <= 0) {
  1875. continue;
  1876. }
  1877. if (strncmp(hostname, "*", DNS_MAX_CNAME_LEN - 1) == 0) {
  1878. continue;
  1879. }
  1880. ret = _conf_host_add(hostname, ip, DNS_HOST_TYPE_DNSMASQ);
  1881. if (ret != 0) {
  1882. tlog(TLOG_WARN, "add host %s/%s at %d failed", hostname, ip, line_no);
  1883. }
  1884. ret = _conf_ptr_add(hostname, ip);
  1885. if (ret != 0) {
  1886. tlog(TLOG_WARN, "add ptr %s/%s at %d failed.", hostname, ip, line_no);
  1887. }
  1888. }
  1889. fclose(fp);
  1890. return 0;
  1891. }
  1892. static int _conf_dhcp_lease_dnsmasq_file(void *data, int argc, char *argv[])
  1893. {
  1894. struct stat statbuf;
  1895. if (argc < 1) {
  1896. return -1;
  1897. }
  1898. conf_get_conf_fullpath(argv[1], dns_conf_dnsmasq_lease_file, sizeof(dns_conf_dnsmasq_lease_file));
  1899. if (_conf_dhcp_lease_dnsmasq_add(dns_conf_dnsmasq_lease_file) != 0) {
  1900. return -1;
  1901. }
  1902. if (stat(dns_conf_dnsmasq_lease_file, &statbuf) != 0) {
  1903. return 0;
  1904. }
  1905. dns_conf_dnsmasq_lease_file_time = statbuf.st_mtime;
  1906. return 0;
  1907. }
  1908. static int _conf_hosts_file(void *data, int argc, char *argv[])
  1909. {
  1910. return 0;
  1911. }
  1912. static void _config_host_table_destroy(void)
  1913. {
  1914. struct dns_hosts *host = NULL;
  1915. struct hlist_node *tmp = NULL;
  1916. unsigned long i = 0;
  1917. hash_for_each_safe(dns_hosts_table.hosts, i, tmp, host, node)
  1918. {
  1919. hlist_del_init(&host->node);
  1920. free(host);
  1921. }
  1922. dns_hosts_record_num = 0;
  1923. }
  1924. int dns_server_check_update_hosts(void)
  1925. {
  1926. struct stat statbuf;
  1927. time_t now = 0;
  1928. if (dns_conf_dnsmasq_lease_file[0] == '\0') {
  1929. return -1;
  1930. }
  1931. if (stat(dns_conf_dnsmasq_lease_file, &statbuf) != 0) {
  1932. return -1;
  1933. }
  1934. if (dns_conf_dnsmasq_lease_file_time == statbuf.st_mtime) {
  1935. return -1;
  1936. }
  1937. time(&now);
  1938. if (now - statbuf.st_mtime < 30) {
  1939. return -1;
  1940. }
  1941. _config_ptr_table_destroy();
  1942. _config_host_table_destroy();
  1943. if (_conf_dhcp_lease_dnsmasq_add(dns_conf_dnsmasq_lease_file) != 0) {
  1944. return -1;
  1945. }
  1946. dns_conf_dnsmasq_lease_file_time = statbuf.st_mtime;
  1947. return 0;
  1948. }
  1949. static int _config_log_level(void *data, int argc, char *argv[])
  1950. {
  1951. /* read log level and set */
  1952. char *value = argv[1];
  1953. if (strncmp("debug", value, MAX_LINE_LEN) == 0) {
  1954. dns_conf_log_level = TLOG_DEBUG;
  1955. } else if (strncmp("info", value, MAX_LINE_LEN) == 0) {
  1956. dns_conf_log_level = TLOG_INFO;
  1957. } else if (strncmp("notice", value, MAX_LINE_LEN) == 0) {
  1958. dns_conf_log_level = TLOG_NOTICE;
  1959. } else if (strncmp("warn", value, MAX_LINE_LEN) == 0) {
  1960. dns_conf_log_level = TLOG_WARN;
  1961. } else if (strncmp("error", value, MAX_LINE_LEN) == 0) {
  1962. dns_conf_log_level = TLOG_ERROR;
  1963. } else if (strncmp("fatal", value, MAX_LINE_LEN) == 0) {
  1964. dns_conf_log_level = TLOG_FATAL;
  1965. } else {
  1966. return -1;
  1967. }
  1968. return 0;
  1969. }
  1970. static void _config_setup_smartdns_domain(void)
  1971. {
  1972. char hostname[DNS_MAX_CNAME_LEN];
  1973. char domainname[DNS_MAX_CNAME_LEN];
  1974. hostname[0] = '\0';
  1975. domainname[0] = '\0';
  1976. /* get local domain name */
  1977. if (getdomainname(domainname, DNS_MAX_CNAME_LEN - 1) == 0) {
  1978. /* check domain is valid */
  1979. if (strncmp(domainname, "(none)", DNS_MAX_CNAME_LEN - 1) == 0) {
  1980. domainname[0] = '\0';
  1981. }
  1982. }
  1983. if (gethostname(hostname, DNS_MAX_CNAME_LEN - 1) == 0) {
  1984. /* check hostname is valid */
  1985. if (strncmp(hostname, "(none)", DNS_MAX_CNAME_LEN - 1) == 0) {
  1986. hostname[0] = '\0';
  1987. }
  1988. }
  1989. if (dns_conf_resolv_hostname == 1) {
  1990. /* add hostname to rule table */
  1991. if (hostname[0] != '\0') {
  1992. _config_domain_rule_flag_set(hostname, DOMAIN_FLAG_SMARTDNS_DOMAIN, 0);
  1993. }
  1994. /* add domainname to rule table */
  1995. if (domainname[0] != '\0') {
  1996. char full_domain[DNS_MAX_CNAME_LEN];
  1997. snprintf(full_domain, DNS_MAX_CNAME_LEN, "%.64s.%.128s", hostname, domainname);
  1998. _config_domain_rule_flag_set(full_domain, DOMAIN_FLAG_SMARTDNS_DOMAIN, 0);
  1999. }
  2000. }
  2001. /* add server name to rule table */
  2002. if (dns_conf_server_name[0] != '\0' && strncmp(dns_conf_server_name, "smartdns", DNS_MAX_CNAME_LEN - 1) != 0) {
  2003. _config_domain_rule_flag_set(dns_conf_server_name, DOMAIN_FLAG_SMARTDNS_DOMAIN, 0);
  2004. }
  2005. _config_domain_rule_flag_set("smartdns", DOMAIN_FLAG_SMARTDNS_DOMAIN, 0);
  2006. }
  2007. static struct config_item _config_item[] = {
  2008. CONF_STRING("server-name", (char *)dns_conf_server_name, DNS_MAX_SERVER_NAME_LEN),
  2009. CONF_YESNO("resolv-hostname", &dns_conf_resolv_hostname),
  2010. CONF_CUSTOM("bind", _config_bind_ip_udp, NULL),
  2011. CONF_CUSTOM("bind-tcp", _config_bind_ip_tcp, NULL),
  2012. CONF_CUSTOM("server", _config_server_udp, NULL),
  2013. CONF_CUSTOM("server-tcp", _config_server_tcp, NULL),
  2014. CONF_CUSTOM("server-tls", _config_server_tls, NULL),
  2015. CONF_CUSTOM("server-https", _config_server_https, NULL),
  2016. CONF_CUSTOM("nameserver", _config_nameserver, NULL),
  2017. CONF_CUSTOM("address", _config_address, NULL),
  2018. CONF_YESNO("ipset-timeout", &dns_conf_ipset_timeout_enable),
  2019. CONF_CUSTOM("ipset", _config_ipset, NULL),
  2020. CONF_YESNO("nftset-timeout", &dns_conf_nftset_timeout_enable),
  2021. CONF_YESNO("nftset-debug", &dns_conf_nftset_debug_enable),
  2022. CONF_CUSTOM("nftset", _config_nftset, NULL),
  2023. CONF_CUSTOM("speed-check-mode", _config_speed_check_mode, NULL),
  2024. CONF_INT("tcp-idle-time", &dns_conf_tcp_idle_time, 0, 3600),
  2025. CONF_INT("cache-size", &dns_conf_cachesize, 0, CONF_INT_MAX),
  2026. CONF_STRING("cache-file", (char *)&dns_conf_cache_file, DNS_MAX_PATH),
  2027. CONF_YESNO("cache-persist", &dns_conf_cache_persist),
  2028. CONF_YESNO("prefetch-domain", &dns_conf_prefetch),
  2029. CONF_YESNO("serve-expired", &dns_conf_serve_expired),
  2030. CONF_INT("serve-expired-ttl", &dns_conf_serve_expired_ttl, 0, CONF_INT_MAX),
  2031. CONF_INT("serve-expired-reply-ttl", &dns_conf_serve_expired_reply_ttl, 0, CONF_INT_MAX),
  2032. CONF_INT("serve-expired-prefetch-time", &dns_conf_serve_expired_prefetch_time, 0, CONF_INT_MAX),
  2033. CONF_YESNO("dualstack-ip-selection", &dns_conf_dualstack_ip_selection),
  2034. CONF_YESNO("dualstack-ip-allow-force-AAAA", &dns_conf_dualstack_ip_allow_force_AAAA),
  2035. CONF_INT("dualstack-ip-selection-threshold", &dns_conf_dualstack_ip_selection_threshold, 0, 1000),
  2036. CONF_CUSTOM("log-level", _config_log_level, NULL),
  2037. CONF_STRING("log-file", (char *)dns_conf_log_file, DNS_MAX_PATH),
  2038. CONF_SIZE("log-size", &dns_conf_log_size, 0, 1024 * 1024 * 1024),
  2039. CONF_INT("log-num", &dns_conf_log_num, 0, 1024),
  2040. CONF_YESNO("audit-enable", &dns_conf_audit_enable),
  2041. CONF_YESNO("audit-SOA", &dns_conf_audit_log_SOA),
  2042. CONF_STRING("audit-file", (char *)&dns_conf_audit_file, DNS_MAX_PATH),
  2043. CONF_SIZE("audit-size", &dns_conf_audit_size, 0, 1024 * 1024 * 1024),
  2044. CONF_INT("audit-num", &dns_conf_audit_num, 0, 1024),
  2045. CONF_INT("rr-ttl", &dns_conf_rr_ttl, 0, CONF_INT_MAX),
  2046. CONF_INT("rr-ttl-min", &dns_conf_rr_ttl_min, 0, CONF_INT_MAX),
  2047. CONF_INT("rr-ttl-max", &dns_conf_rr_ttl_max, 0, CONF_INT_MAX),
  2048. CONF_INT("rr-ttl-reply-max", &dns_conf_rr_ttl_reply_max, 0, CONF_INT_MAX),
  2049. CONF_INT("local-ttl", &dns_conf_local_ttl, 0, CONF_INT_MAX),
  2050. CONF_INT("max-reply-ip-num", &dns_conf_max_reply_ip_num, 1, CONF_INT_MAX),
  2051. CONF_ENUM("response-mode", &dns_conf_response_mode, &dns_conf_response_mode_enum),
  2052. CONF_YESNO("force-AAAA-SOA", &dns_conf_force_AAAA_SOA),
  2053. CONF_YESNO("force-no-CNAME", &dns_conf_force_no_cname),
  2054. CONF_CUSTOM("force-qtype-SOA", _config_qtype_soa, NULL),
  2055. CONF_CUSTOM("blacklist-ip", _config_blacklist_ip, NULL),
  2056. CONF_CUSTOM("whitelist-ip", _conf_whitelist_ip, NULL),
  2057. CONF_CUSTOM("bogus-nxdomain", _conf_bogus_nxdomain, NULL),
  2058. CONF_CUSTOM("ignore-ip", _conf_ip_ignore, NULL),
  2059. CONF_CUSTOM("edns-client-subnet", _conf_edns_client_subnet, NULL),
  2060. CONF_CUSTOM("domain-rules", _conf_domain_rules, NULL),
  2061. CONF_CUSTOM("domain-set", _conf_domain_set, NULL),
  2062. CONF_CUSTOM("dnsmasq-lease-file", _conf_dhcp_lease_dnsmasq_file, NULL),
  2063. CONF_CUSTOM("hosts-file", _conf_hosts_file, NULL),
  2064. CONF_STRING("ca-file", (char *)&dns_conf_ca_file, DNS_MAX_PATH),
  2065. CONF_STRING("ca-path", (char *)&dns_conf_ca_path, DNS_MAX_PATH),
  2066. CONF_STRING("user", (char *)&dns_conf_user, sizeof(dns_conf_user)),
  2067. CONF_YESNO("debug-save-fail-packet", &dns_save_fail_packet),
  2068. CONF_STRING("resolv-file", (char *)&dns_resolv_file, sizeof(dns_resolv_file)),
  2069. CONF_STRING("debug-save-fail-packet-dir", (char *)&dns_save_fail_packet_dir, sizeof(dns_save_fail_packet_dir)),
  2070. CONF_CUSTOM("conf-file", config_addtional_file, NULL),
  2071. CONF_END(),
  2072. };
  2073. static int _conf_printf(const char *file, int lineno, int ret)
  2074. {
  2075. switch (ret) {
  2076. case CONF_RET_ERR:
  2077. case CONF_RET_WARN:
  2078. case CONF_RET_BADCONF:
  2079. tlog(TLOG_WARN, "process config file '%s' failed at line %d.", file, lineno);
  2080. syslog(LOG_NOTICE, "process config file '%s' failed at line %d.", file, lineno);
  2081. return -1;
  2082. break;
  2083. default:
  2084. break;
  2085. }
  2086. return 0;
  2087. }
  2088. int config_addtional_file(void *data, int argc, char *argv[])
  2089. {
  2090. char *conf_file = NULL;
  2091. char file_path[DNS_MAX_PATH];
  2092. char file_path_dir[DNS_MAX_PATH];
  2093. if (argc < 1) {
  2094. return -1;
  2095. }
  2096. conf_file = argv[1];
  2097. if (conf_file[0] != '/') {
  2098. safe_strncpy(file_path_dir, conf_get_conf_file(), DNS_MAX_PATH);
  2099. dirname(file_path_dir);
  2100. if (strncmp(file_path_dir, conf_get_conf_file(), sizeof(file_path_dir)) == 0) {
  2101. if (snprintf(file_path, DNS_MAX_PATH, "%s", conf_file) < 0) {
  2102. return -1;
  2103. }
  2104. } else {
  2105. if (snprintf(file_path, DNS_MAX_PATH, "%s/%s", file_path_dir, conf_file) < 0) {
  2106. return -1;
  2107. }
  2108. }
  2109. } else {
  2110. safe_strncpy(file_path, conf_file, DNS_MAX_PATH);
  2111. }
  2112. if (access(file_path, R_OK) != 0) {
  2113. tlog(TLOG_WARN, "conf file %s is not readable.", file_path);
  2114. syslog(LOG_NOTICE, "conf file %s is not readable.", file_path);
  2115. return 0;
  2116. }
  2117. return load_conf(file_path, _config_item, _conf_printf);
  2118. }
  2119. static int _update_domain_set_from_list(const char *file, struct dns_domain_set_rule_list *set_rule_list)
  2120. {
  2121. FILE *fp = NULL;
  2122. char line[MAX_LINE_LEN];
  2123. char domain[DNS_MAX_CNAME_LEN];
  2124. int ret = 0;
  2125. int line_no = 0;
  2126. int filed_num = 0;
  2127. struct dns_domain_set_rule *set_rule = NULL;
  2128. fp = fopen(file, "r");
  2129. if (fp == NULL) {
  2130. tlog(TLOG_WARN, "open file %s error, %s", file, strerror(errno));
  2131. return 0;
  2132. }
  2133. line_no = 0;
  2134. while (fgets(line, MAX_LINE_LEN, fp)) {
  2135. line_no++;
  2136. filed_num = sscanf(line, "%256s", domain);
  2137. if (filed_num <= 0) {
  2138. continue;
  2139. }
  2140. if (domain[0] == '#' || domain[0] == '\n') {
  2141. continue;
  2142. }
  2143. list_for_each_entry(set_rule, &set_rule_list->domain_ruls_list, list)
  2144. {
  2145. if (set_rule->type == DOMAIN_RULE_FLAGS) {
  2146. ret = _config_domain_rule_flag_set(domain, set_rule->flags, set_rule->is_clear_flag);
  2147. } else {
  2148. ret = _config_domain_rule_add(domain, set_rule->type, set_rule->rule);
  2149. }
  2150. if (ret != 0) {
  2151. tlog(TLOG_WARN, "process file %s failed at line %d.", file, line_no);
  2152. continue;
  2153. }
  2154. }
  2155. }
  2156. fclose(fp);
  2157. return ret;
  2158. }
  2159. static int _update_domain_set(void)
  2160. {
  2161. struct dns_domain_set_rule_list *set_rule_list = NULL;
  2162. struct dns_domain_set_name_list *set_name_list = NULL;
  2163. struct dns_domain_set_name *set_name_item = NULL;
  2164. unsigned long i = 0;
  2165. uint32_t key = 0;
  2166. hash_for_each(dns_domain_set_rule_table.rule_list, i, set_rule_list, node)
  2167. {
  2168. key = hash_string(set_rule_list->domain_set);
  2169. hash_for_each_possible(dns_domain_set_name_table.names, set_name_list, node, key)
  2170. {
  2171. if (strcmp(set_name_list->name, set_rule_list->domain_set) == 0) {
  2172. break;
  2173. }
  2174. }
  2175. if (set_name_list == NULL) {
  2176. tlog(TLOG_WARN, "domain set %s not found.", set_rule_list->domain_set);
  2177. continue;
  2178. }
  2179. list_for_each_entry(set_name_item, &set_name_list->set_name_list, list)
  2180. {
  2181. switch (set_name_item->type) {
  2182. case DNS_DOMAIN_SET_LIST:
  2183. _update_domain_set_from_list(set_name_item->file, set_rule_list);
  2184. break;
  2185. case DNS_DOMAIN_SET_GEOSITE:
  2186. break;
  2187. default:
  2188. tlog(TLOG_WARN, "domain set %s type %d not support.", set_name_list->name, set_name_item->type);
  2189. break;
  2190. }
  2191. }
  2192. }
  2193. return 0;
  2194. }
  2195. static int _dns_server_load_conf_init(void)
  2196. {
  2197. dns_conf_address_rule.ipv4 = New_Radix();
  2198. dns_conf_address_rule.ipv6 = New_Radix();
  2199. if (dns_conf_address_rule.ipv4 == NULL || dns_conf_address_rule.ipv6 == NULL) {
  2200. tlog(TLOG_WARN, "init radix tree failed.");
  2201. return -1;
  2202. }
  2203. art_tree_init(&dns_conf_domain_rule);
  2204. hash_init(dns_ipset_table.ipset);
  2205. hash_init(dns_nftset_table.nftset);
  2206. hash_init(dns_qtype_soa_table.qtype);
  2207. hash_init(dns_group_table.group);
  2208. hash_init(dns_hosts_table.hosts);
  2209. hash_init(dns_ptr_table.ptr);
  2210. hash_init(dns_domain_set_rule_table.rule_list);
  2211. hash_init(dns_domain_set_name_table.names);
  2212. return 0;
  2213. }
  2214. void dns_server_load_exit(void)
  2215. {
  2216. _config_domain_destroy();
  2217. Destroy_Radix(dns_conf_address_rule.ipv4, _config_address_destroy, NULL);
  2218. Destroy_Radix(dns_conf_address_rule.ipv6, _config_address_destroy, NULL);
  2219. _config_ipset_table_destroy();
  2220. _config_nftset_table_destroy();
  2221. _config_group_table_destroy();
  2222. _config_ptr_table_destroy();
  2223. _config_host_table_destroy();
  2224. _config_qtype_soa_table_destroy();
  2225. }
  2226. static int _dns_conf_speed_check_mode_verify(void)
  2227. {
  2228. int i = 0;
  2229. int j = 0;
  2230. int print_log = 0;
  2231. if (dns_has_cap_ping == 1) {
  2232. return 0;
  2233. }
  2234. for (i = 0; i < DOMAIN_CHECK_NUM; i++) {
  2235. if (dns_conf_check_orders.orders[i].type == DOMAIN_CHECK_ICMP) {
  2236. for (j = i + 1; j < DOMAIN_CHECK_NUM; j++) {
  2237. dns_conf_check_orders.orders[j - 1].type = dns_conf_check_orders.orders[j].type;
  2238. dns_conf_check_orders.orders[j - 1].tcp_port = dns_conf_check_orders.orders[j].tcp_port;
  2239. }
  2240. dns_conf_check_orders.orders[j - 1].type = DOMAIN_CHECK_NONE;
  2241. dns_conf_check_orders.orders[j - 1].tcp_port = 0;
  2242. print_log = 1;
  2243. }
  2244. }
  2245. if (print_log) {
  2246. tlog(TLOG_WARN, "speed check by ping is disabled because smartdns does not have network raw privileges");
  2247. }
  2248. return 0;
  2249. }
  2250. static int _dns_ping_cap_check(void)
  2251. {
  2252. int has_ping = 0;
  2253. int has_raw_cap = 0;
  2254. has_raw_cap = has_network_raw_cap();
  2255. has_ping = has_unprivileged_ping();
  2256. if (has_ping == 0) {
  2257. if (errno == EACCES && has_raw_cap == 0) {
  2258. tlog(TLOG_WARN, "unpriviledged ping is disabled, please enable by setting net.ipv4.ping_group_range");
  2259. }
  2260. }
  2261. if (has_ping == 1 || has_raw_cap == 1) {
  2262. dns_has_cap_ping = 1;
  2263. }
  2264. return 0;
  2265. }
  2266. static int _dns_conf_load_pre(void)
  2267. {
  2268. if (_dns_server_load_conf_init() != 0) {
  2269. goto errout;
  2270. }
  2271. _dns_ping_cap_check();
  2272. safe_strncpy(dns_save_fail_packet_dir, SMARTDNS_DEBUG_DIR, sizeof(dns_save_fail_packet_dir));
  2273. return 0;
  2274. errout:
  2275. return -1;
  2276. }
  2277. static int _dns_conf_load_post(void)
  2278. {
  2279. _config_setup_smartdns_domain();
  2280. _dns_conf_speed_check_mode_verify();
  2281. if (dns_conf_cachesize == 0 && dns_conf_response_mode == DNS_RESPONSE_MODE_FASTEST_RESPONSE) {
  2282. dns_conf_response_mode = DNS_RESPONSE_MODE_FASTEST_IP;
  2283. tlog(TLOG_WARN, "force set response to %s as cache size is 0",
  2284. dns_conf_response_mode_enum[dns_conf_response_mode].name);
  2285. }
  2286. if ((dns_conf_rr_ttl_min > dns_conf_rr_ttl_max) && dns_conf_rr_ttl_max > 0) {
  2287. dns_conf_rr_ttl_min = dns_conf_rr_ttl_max;
  2288. }
  2289. if ((dns_conf_rr_ttl_max < dns_conf_rr_ttl_min) && dns_conf_rr_ttl_max > 0) {
  2290. dns_conf_rr_ttl_max = dns_conf_rr_ttl_min;
  2291. }
  2292. if (dns_conf_local_ttl == 0) {
  2293. dns_conf_local_ttl = dns_conf_rr_ttl_min;
  2294. }
  2295. if (dns_resolv_file[0] == '\0') {
  2296. safe_strncpy(dns_resolv_file, DNS_RESOLV_FILE, sizeof(dns_resolv_file));
  2297. }
  2298. _update_domain_set();
  2299. _config_domain_set_name_table_destroy();
  2300. _config_domain_set_rule_table_destroy();
  2301. return 0;
  2302. }
  2303. int dns_server_load_conf(const char *file)
  2304. {
  2305. int ret = 0;
  2306. _dns_conf_load_pre();
  2307. openlog("smartdns", LOG_CONS | LOG_NDELAY, LOG_LOCAL1);
  2308. ret = load_conf(file, _config_item, _conf_printf);
  2309. closelog();
  2310. _dns_conf_load_post();
  2311. return ret;
  2312. }