LookupServer.cpp 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365
  1. /*
  2. * Copyright (c) 2018-2021, Andreas Kling <kling@serenityos.org>
  3. *
  4. * SPDX-License-Identifier: BSD-2-Clause
  5. */
  6. #include "LookupServer.h"
  7. #include "ClientConnection.h"
  8. #include "DNSPacket.h"
  9. #include <AK/Debug.h>
  10. #include <AK/HashMap.h>
  11. #include <AK/Random.h>
  12. #include <AK/String.h>
  13. #include <AK/StringBuilder.h>
  14. #include <LibCore/ConfigFile.h>
  15. #include <LibCore/File.h>
  16. #include <LibCore/LocalServer.h>
  17. #include <LibCore/UDPSocket.h>
  18. #include <stdio.h>
  19. #include <time.h>
  20. #include <unistd.h>
  21. namespace LookupServer {
  22. static LookupServer* s_the;
  23. // NOTE: This is the TTL we return for the hostname or answers from /etc/hosts.
  24. static constexpr u32 s_static_ttl = 86400;
  25. LookupServer& LookupServer::the()
  26. {
  27. VERIFY(s_the);
  28. return *s_the;
  29. }
  30. LookupServer::LookupServer()
  31. {
  32. VERIFY(s_the == nullptr);
  33. s_the = this;
  34. auto config = Core::ConfigFile::get_for_system("LookupServer");
  35. dbgln("Using network config file at {}", config->filename());
  36. m_nameservers = config->read_entry("DNS", "Nameservers", "1.1.1.1,1.0.0.1").split(',');
  37. load_etc_hosts();
  38. auto maybe_file_watcher = Core::FileWatcher::create();
  39. // NOTE: If this happens during startup, something is very wrong.
  40. if (maybe_file_watcher.is_error()) {
  41. dbgln("Core::FileWatcher::create(): {}", maybe_file_watcher.error());
  42. VERIFY_NOT_REACHED();
  43. }
  44. m_file_watcher = maybe_file_watcher.release_value();
  45. m_file_watcher->on_change = [this](auto&) {
  46. dbgln("Reloading '/etc/hosts' because it was changed.");
  47. load_etc_hosts();
  48. };
  49. auto result = m_file_watcher->add_watch("/etc/hosts", Core::FileWatcherEvent::Type::ContentModified | Core::FileWatcherEvent::Type::Deleted);
  50. // NOTE: If this happens during startup, something is very wrong.
  51. if (result.is_error()) {
  52. dbgln("Core::FileWatcher::add_watch(): {}", result.error());
  53. VERIFY_NOT_REACHED();
  54. } else if (!result.value()) {
  55. dbgln("Core::FileWatcher::add_watch(): {}", result.value());
  56. VERIFY_NOT_REACHED();
  57. }
  58. if (config->read_bool_entry("DNS", "EnableServer")) {
  59. m_dns_server = DNSServer::construct(this);
  60. // TODO: drop root privileges here.
  61. }
  62. m_mdns = MulticastDNS::construct(this);
  63. m_local_server = Core::LocalServer::construct(this);
  64. m_local_server->on_ready_to_accept = [this]() {
  65. auto socket = m_local_server->accept();
  66. if (!socket) {
  67. dbgln("Failed to accept a client connection");
  68. return;
  69. }
  70. static int s_next_client_id = 0;
  71. int client_id = ++s_next_client_id;
  72. IPC::new_client_connection<ClientConnection>(socket.release_nonnull(), client_id);
  73. };
  74. bool ok = m_local_server->take_over_from_system_server();
  75. VERIFY(ok);
  76. }
  77. void LookupServer::load_etc_hosts()
  78. {
  79. m_etc_hosts.clear();
  80. auto add_answer = [this](const DNSName& name, DNSRecordType record_type, String data) {
  81. auto it = m_etc_hosts.find(name);
  82. if (it == m_etc_hosts.end()) {
  83. m_etc_hosts.set(name, {});
  84. it = m_etc_hosts.find(name);
  85. }
  86. it->value.empend(name, record_type, DNSRecordClass::IN, s_static_ttl, data, false);
  87. };
  88. auto file = Core::File::construct("/etc/hosts");
  89. if (!file->open(Core::OpenMode::ReadOnly)) {
  90. dbgln("Failed to open '/etc/hosts'");
  91. return;
  92. }
  93. u32 line_number = 0;
  94. while (!file->eof()) {
  95. auto original_line = file->read_line(1024);
  96. ++line_number;
  97. if (original_line.is_empty())
  98. break;
  99. auto trimmed_line = original_line.view().trim_whitespace();
  100. auto fields = trimmed_line.split_view('\t', false);
  101. if (fields.size() < 2) {
  102. dbgln("Failed to parse line {} from '/etc/hosts': '{}'", line_number, original_line);
  103. continue;
  104. }
  105. if (fields.size() > 2)
  106. dbgln("Line {} from '/etc/hosts' ('{}') has more than two parts, only the first two are used.", line_number, original_line);
  107. auto maybe_address = IPv4Address::from_string(fields[0]);
  108. if (!maybe_address.has_value()) {
  109. dbgln("Failed to parse line {} from '/etc/hosts': '{}'", line_number, original_line);
  110. continue;
  111. }
  112. auto raw_addr = maybe_address->to_in_addr_t();
  113. DNSName name { fields[1] };
  114. add_answer(name, DNSRecordType::A, String { (const char*)&raw_addr, sizeof(raw_addr) });
  115. StringBuilder builder;
  116. builder.append(maybe_address->to_string_reversed());
  117. builder.append(".in-addr.arpa");
  118. add_answer(builder.to_string(), DNSRecordType::PTR, name.as_string());
  119. }
  120. }
  121. static String get_hostname()
  122. {
  123. char buffer[HOST_NAME_MAX];
  124. VERIFY(gethostname(buffer, sizeof(buffer)) == 0);
  125. return buffer;
  126. }
  127. Vector<DNSAnswer> LookupServer::lookup(const DNSName& name, DNSRecordType record_type)
  128. {
  129. dbgln_if(LOOKUPSERVER_DEBUG, "Got request for '{}'", name.as_string());
  130. Vector<DNSAnswer> answers;
  131. auto add_answer = [&](const DNSAnswer& answer) {
  132. DNSAnswer answer_with_original_case {
  133. name,
  134. answer.type(),
  135. answer.class_code(),
  136. answer.ttl(),
  137. answer.record_data(),
  138. answer.mdns_cache_flush(),
  139. };
  140. answers.append(answer_with_original_case);
  141. };
  142. // First, try /etc/hosts.
  143. if (auto local_answers = m_etc_hosts.get(name); local_answers.has_value()) {
  144. for (auto& answer : local_answers.value()) {
  145. if (answer.type() == record_type)
  146. add_answer(answer);
  147. }
  148. if (!answers.is_empty())
  149. return answers;
  150. }
  151. // Second, try the hostname.
  152. // NOTE: We don't cache the hostname since it could change during runtime.
  153. if (record_type == DNSRecordType::A && get_hostname() == name) {
  154. IPv4Address address = { 127, 0, 0, 1 };
  155. auto raw_address = address.to_in_addr_t();
  156. DNSAnswer answer { name, DNSRecordType::A, DNSRecordClass::IN, s_static_ttl, String { (const char*)&raw_address, sizeof(raw_address) }, false };
  157. answers.append(move(answer));
  158. return answers;
  159. }
  160. // Third, try our cache.
  161. if (auto cached_answers = m_lookup_cache.get(name); cached_answers.has_value()) {
  162. for (auto& answer : cached_answers.value()) {
  163. // TODO: Actually remove expired answers from the cache.
  164. if (answer.type() == record_type && !answer.has_expired()) {
  165. dbgln_if(LOOKUPSERVER_DEBUG, "Cache hit: {} -> {}", name.as_string(), answer.record_data());
  166. add_answer(answer);
  167. }
  168. }
  169. if (!answers.is_empty())
  170. return answers;
  171. }
  172. // Fourth, look up .local names using mDNS instead of DNS nameservers.
  173. if (name.as_string().ends_with(".local")) {
  174. answers = m_mdns->lookup(name, record_type);
  175. for (auto& answer : answers)
  176. put_in_cache(answer);
  177. return answers;
  178. }
  179. // Fifth, ask the upstream nameservers.
  180. for (auto& nameserver : m_nameservers) {
  181. dbgln_if(LOOKUPSERVER_DEBUG, "Doing lookup using nameserver '{}'", nameserver);
  182. bool did_get_response = false;
  183. int retries = 3;
  184. Vector<DNSAnswer> upstream_answers;
  185. do {
  186. upstream_answers = lookup(name, nameserver, did_get_response, record_type);
  187. if (did_get_response)
  188. break;
  189. } while (--retries);
  190. if (!upstream_answers.is_empty()) {
  191. for (auto& answer : upstream_answers)
  192. add_answer(answer);
  193. break;
  194. } else {
  195. if (!did_get_response)
  196. dbgln("Never got a response from '{}', trying next nameserver", nameserver);
  197. else
  198. dbgln("Received response from '{}' but no result(s), trying next nameserver", nameserver);
  199. }
  200. }
  201. // Sixth, fail.
  202. if (answers.is_empty()) {
  203. dbgln("Tried all nameservers but never got a response :(");
  204. return {};
  205. }
  206. return answers;
  207. }
  208. Vector<DNSAnswer> LookupServer::lookup(const DNSName& name, const String& nameserver, bool& did_get_response, DNSRecordType record_type, ShouldRandomizeCase should_randomize_case)
  209. {
  210. DNSPacket request;
  211. request.set_is_query();
  212. request.set_id(get_random_uniform(UINT16_MAX));
  213. DNSName name_in_question = name;
  214. if (should_randomize_case == ShouldRandomizeCase::Yes)
  215. name_in_question.randomize_case();
  216. request.add_question({ name_in_question, record_type, DNSRecordClass::IN, false });
  217. auto buffer = request.to_byte_buffer();
  218. auto udp_socket = Core::UDPSocket::construct();
  219. udp_socket->set_blocking(true);
  220. struct timeval timeout {
  221. 1, 0
  222. };
  223. int rc = setsockopt(udp_socket->fd(), SOL_SOCKET, SO_RCVTIMEO, &timeout, sizeof(timeout));
  224. if (rc < 0) {
  225. perror("setsockopt(SOL_SOCKET, SO_RCVTIMEO)");
  226. return {};
  227. }
  228. if (!udp_socket->connect(nameserver, 53))
  229. return {};
  230. if (!udp_socket->write(buffer))
  231. return {};
  232. u8 response_buffer[4096];
  233. int nrecv = udp_socket->read(response_buffer, sizeof(response_buffer));
  234. if (nrecv == 0)
  235. return {};
  236. did_get_response = true;
  237. auto o_response = DNSPacket::from_raw_packet(response_buffer, nrecv);
  238. if (!o_response.has_value())
  239. return {};
  240. auto& response = o_response.value();
  241. if (response.id() != request.id()) {
  242. dbgln("LookupServer: ID mismatch ({} vs {}) :(", response.id(), request.id());
  243. return {};
  244. }
  245. if (response.code() == DNSPacket::Code::REFUSED) {
  246. if (should_randomize_case == ShouldRandomizeCase::Yes) {
  247. // Retry with 0x20 case randomization turned off.
  248. return lookup(name, nameserver, did_get_response, record_type, ShouldRandomizeCase::No);
  249. }
  250. return {};
  251. }
  252. if (response.question_count() != request.question_count()) {
  253. dbgln("LookupServer: Question count ({} vs {}) :(", response.question_count(), request.question_count());
  254. return {};
  255. }
  256. // Verify the questions in our request and in their response match exactly, including case.
  257. for (size_t i = 0; i < request.question_count(); ++i) {
  258. auto& request_question = request.questions()[i];
  259. auto& response_question = response.questions()[i];
  260. bool exact_match = request_question.class_code() == response_question.class_code()
  261. && request_question.record_type() == response_question.record_type()
  262. && request_question.name().as_string() == response_question.name().as_string();
  263. if (!exact_match) {
  264. dbgln("Request and response questions do not match");
  265. dbgln(" Request: name=_{}_, type={}, class={}", request_question.name().as_string(), response_question.record_type(), response_question.class_code());
  266. dbgln(" Response: name=_{}_, type={}, class={}", response_question.name().as_string(), response_question.record_type(), response_question.class_code());
  267. return {};
  268. }
  269. }
  270. if (response.answer_count() < 1) {
  271. dbgln("LookupServer: No answers :(");
  272. return {};
  273. }
  274. Vector<DNSAnswer, 8> answers;
  275. for (auto& answer : response.answers()) {
  276. put_in_cache(answer);
  277. if (answer.type() != record_type)
  278. continue;
  279. answers.append(answer);
  280. }
  281. return answers;
  282. }
  283. void LookupServer::put_in_cache(const DNSAnswer& answer)
  284. {
  285. if (answer.has_expired())
  286. return;
  287. // Prevent the cache from growing too big.
  288. // TODO: Evict least used entries.
  289. if (m_lookup_cache.size() >= 256)
  290. m_lookup_cache.remove(m_lookup_cache.begin());
  291. auto it = m_lookup_cache.find(answer.name());
  292. if (it == m_lookup_cache.end())
  293. m_lookup_cache.set(answer.name(), { answer });
  294. else {
  295. if (answer.mdns_cache_flush()) {
  296. auto now = time(nullptr);
  297. it->value.remove_all_matching([&](DNSAnswer const& other_answer) {
  298. if (other_answer.type() != answer.type() || other_answer.class_code() != answer.class_code())
  299. return false;
  300. if (other_answer.received_time() >= now - 1)
  301. return false;
  302. dbgln_if(LOOKUPSERVER_DEBUG, "Removing cache entry: {}", other_answer.name());
  303. return true;
  304. });
  305. }
  306. it->value.append(answer);
  307. }
  308. }
  309. }