]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/resolve/resolved-dns-packet.h
tree-wide: drop 'This file is part of systemd' blurb
[thirdparty/systemd.git] / src / resolve / resolved-dns-packet.h
CommitLineData
53e1b683 1/* SPDX-License-Identifier: LGPL-2.1+ */
74b2466e
LP
2#pragma once
3
4/***
74b2466e 5 Copyright 2014 Lennart Poettering
74b2466e
LP
6 ***/
7
a0166609 8#include <netinet/ip.h>
71d35b6b 9#include <netinet/udp.h>
74b2466e 10
74b2466e 11#include "hashmap.h"
7e8e0422 12#include "in-addr-util.h"
71d35b6b
TA
13#include "macro.h"
14#include "sparse-endian.h"
7e8e0422
LP
15
16typedef struct DnsPacketHeader DnsPacketHeader;
17typedef struct DnsPacket DnsPacket;
18
51323288 19#include "resolved-def.h"
71d35b6b
TA
20#include "resolved-dns-answer.h"
21#include "resolved-dns-question.h"
22#include "resolved-dns-rr.h"
74b2466e 23
1716f6dc
LP
24typedef enum DnsProtocol {
25 DNS_PROTOCOL_DNS,
26 DNS_PROTOCOL_MDNS,
27 DNS_PROTOCOL_LLMNR,
28 _DNS_PROTOCOL_MAX,
29 _DNS_PROTOCOL_INVALID = -1
30} DnsProtocol;
31
74b2466e
LP
32struct DnsPacketHeader {
33 uint16_t id;
34 be16_t flags;
35 be16_t qdcount;
36 be16_t ancount;
37 be16_t nscount;
38 be16_t arcount;
39};
40
41#define DNS_PACKET_HEADER_SIZE sizeof(DnsPacketHeader)
a0166609 42#define UDP_PACKET_HEADER_SIZE (sizeof(struct iphdr) + sizeof(struct udphdr))
c73ce96b
LP
43
44/* The various DNS protocols deviate in how large a packet can grow,
86d06089
ZJS
45 * but the TCP transport has a 16bit size field, hence that appears to
46 * be the absolute maximum. */
64a21fda 47#define DNS_PACKET_SIZE_MAX 0xFFFFu
e1c95994 48
86d06089
ZJS
49/* The default size to use for allocation when we don't know how large
50 * the packet will turn out to be. */
51#define DNS_PACKET_SIZE_START 512u
52
e1c95994 53/* RFC 1035 say 512 is the maximum, for classic unicast DNS */
64a21fda 54#define DNS_PACKET_UNICAST_SIZE_MAX 512u
e1c95994 55
d74fb368 56/* With EDNS0 we can use larger packets, default to 4096, which is what is commonly used */
64a21fda 57#define DNS_PACKET_UNICAST_SIZE_LARGE_MAX 4096u
d74fb368 58
74b2466e
LP
59struct DnsPacket {
60 int n_ref;
1716f6dc 61 DnsProtocol protocol;
51027656 62 size_t size, allocated, rindex, max_size;
faa133f3 63 void *_data; /* don't access directly, use DNS_PACKET_DATA()! */
74b2466e 64 Hashmap *names; /* For name compression */
519ef046 65 size_t opt_start, opt_size;
faa133f3
LP
66
67 /* Parsed data */
68 DnsQuestion *question;
69 DnsAnswer *answer;
d75acfb0 70 DnsResourceRecord *opt;
1716f6dc 71
dc61b7e4 72 /* Packet reception metadata */
1716f6dc 73 int ifindex;
623a4c97 74 int family, ipproto;
1716f6dc 75 union in_addr_union sender, destination;
623a4c97 76 uint16_t sender_port, destination_port;
0dd25fb9 77 uint32_t ttl;
a4076574 78
9c491563
DM
79 /* For support of truncated packets */
80 DnsPacket *more;
81
a8812dd7
LP
82 bool on_stack:1;
83 bool extracted:1;
84 bool refuse_compression:1;
85 bool canonical_form:1;
74b2466e
LP
86};
87
88static inline uint8_t* DNS_PACKET_DATA(DnsPacket *p) {
89 if (_unlikely_(!p))
90 return NULL;
91
faa133f3
LP
92 if (p->_data)
93 return p->_data;
74b2466e
LP
94
95 return ((uint8_t*) p) + ALIGN(sizeof(DnsPacket));
96}
97
98#define DNS_PACKET_HEADER(p) ((DnsPacketHeader*) DNS_PACKET_DATA(p))
3cb10d3a
LP
99#define DNS_PACKET_ID(p) DNS_PACKET_HEADER(p)->id
100#define DNS_PACKET_QR(p) ((be16toh(DNS_PACKET_HEADER(p)->flags) >> 15) & 1)
101#define DNS_PACKET_OPCODE(p) ((be16toh(DNS_PACKET_HEADER(p)->flags) >> 11) & 15)
8b757a38 102#define DNS_PACKET_AA(p) ((be16toh(DNS_PACKET_HEADER(p)->flags) >> 10) & 1)
ad867662 103#define DNS_PACKET_TC(p) ((be16toh(DNS_PACKET_HEADER(p)->flags) >> 9) & 1)
8b757a38
DM
104#define DNS_PACKET_RD(p) ((be16toh(DNS_PACKET_HEADER(p)->flags) >> 8) & 1)
105#define DNS_PACKET_RA(p) ((be16toh(DNS_PACKET_HEADER(p)->flags) >> 7) & 1)
106#define DNS_PACKET_AD(p) ((be16toh(DNS_PACKET_HEADER(p)->flags) >> 5) & 1)
107#define DNS_PACKET_CD(p) ((be16toh(DNS_PACKET_HEADER(p)->flags) >> 4) & 1)
f3abbe25 108
b30bf55d
LP
109#define DNS_PACKET_FLAG_TC (UINT16_C(1) << 9)
110
f3abbe25
LP
111static inline uint16_t DNS_PACKET_RCODE(DnsPacket *p) {
112 uint16_t rcode;
113
114 if (p->opt)
115 rcode = (uint16_t) (p->opt->ttl >> 24);
116 else
117 rcode = 0;
118
b30bf55d
LP
119 return rcode | (be16toh(DNS_PACKET_HEADER(p)->flags) & 0xF);
120}
121
122static inline uint16_t DNS_PACKET_PAYLOAD_SIZE_MAX(DnsPacket *p) {
123
124 /* Returns the advertised maximum datagram size for replies, or the DNS default if there's nothing defined. */
125
126 if (p->opt)
127 return MAX(DNS_PACKET_UNICAST_SIZE_MAX, p->opt->key->class);
128
129 return DNS_PACKET_UNICAST_SIZE_MAX;
130}
131
132static inline bool DNS_PACKET_DO(DnsPacket *p) {
133 if (!p->opt)
134 return false;
135
136 return !!(p->opt->ttl & (1U << 15));
137}
138
139static inline bool DNS_PACKET_VERSION_SUPPORTED(DnsPacket *p) {
140 /* Returns true if this packet is in a version we support. Which means either non-EDNS or EDNS(0), but not EDNS
141 * of any newer versions */
142
143 if (!p->opt)
144 return true;
145
146 return DNS_RESOURCE_RECORD_OPT_VERSION_SUPPORTED(p->opt);
f3abbe25 147}
8b757a38
DM
148
149/* LLMNR defines some bits differently */
150#define DNS_PACKET_LLMNR_C(p) DNS_PACKET_AA(p)
151#define DNS_PACKET_LLMNR_T(p) DNS_PACKET_RD(p)
152
3cb10d3a
LP
153#define DNS_PACKET_QDCOUNT(p) be16toh(DNS_PACKET_HEADER(p)->qdcount)
154#define DNS_PACKET_ANCOUNT(p) be16toh(DNS_PACKET_HEADER(p)->ancount)
155#define DNS_PACKET_NSCOUNT(p) be16toh(DNS_PACKET_HEADER(p)->nscount)
156#define DNS_PACKET_ARCOUNT(p) be16toh(DNS_PACKET_HEADER(p)->arcount)
157
158#define DNS_PACKET_MAKE_FLAGS(qr, opcode, aa, tc, rd, ra, ad, cd, rcode) \
f0258e47
LP
159 (((uint16_t) !!(qr) << 15) | \
160 ((uint16_t) ((opcode) & 15) << 11) | \
161 ((uint16_t) !!(aa) << 10) | /* on LLMNR: c */ \
162 ((uint16_t) !!(tc) << 9) | \
163 ((uint16_t) !!(rd) << 8) | /* on LLMNR: t */ \
164 ((uint16_t) !!(ra) << 7) | \
165 ((uint16_t) !!(ad) << 5) | \
166 ((uint16_t) !!(cd) << 4) | \
167 ((uint16_t) ((rcode) & 15)))
3cb10d3a 168
322345fd
LP
169static inline unsigned DNS_PACKET_RRCOUNT(DnsPacket *p) {
170 return
171 (unsigned) DNS_PACKET_ANCOUNT(p) +
172 (unsigned) DNS_PACKET_NSCOUNT(p) +
173 (unsigned) DNS_PACKET_ARCOUNT(p);
174}
74b2466e 175
51027656 176int dns_packet_new(DnsPacket **p, DnsProtocol protocol, size_t min_alloc_dsize, size_t max_size);
46a58596 177int dns_packet_new_query(DnsPacket **p, DnsProtocol protocol, size_t min_alloc_dsize, bool dnssec_checking_disabled);
74b2466e 178
dbfbb6e7
DM
179void dns_packet_set_flags(DnsPacket *p, bool dnssec_checking_disabled, bool truncated);
180
74b2466e
LP
181DnsPacket *dns_packet_ref(DnsPacket *p);
182DnsPacket *dns_packet_unref(DnsPacket *p);
183
184DEFINE_TRIVIAL_CLEANUP_FUNC(DnsPacket*, dns_packet_unref);
185
186int dns_packet_validate(DnsPacket *p);
187int dns_packet_validate_reply(DnsPacket *p);
623a4c97 188int dns_packet_validate_query(DnsPacket *p);
74b2466e 189
8af5b883
LP
190int dns_packet_is_reply_for(DnsPacket *p, const DnsResourceKey *key);
191
623a4c97 192int dns_packet_append_blob(DnsPacket *p, const void *d, size_t sz, size_t *start);
74b2466e
LP
193int dns_packet_append_uint8(DnsPacket *p, uint8_t v, size_t *start);
194int dns_packet_append_uint16(DnsPacket *p, uint16_t v, size_t *start);
623a4c97 195int dns_packet_append_uint32(DnsPacket *p, uint32_t v, size_t *start);
74b2466e 196int dns_packet_append_string(DnsPacket *p, const char *s, size_t *start);
2001c805 197int dns_packet_append_raw_string(DnsPacket *p, const void *s, size_t size, size_t *start);
a3db237b
LP
198int dns_packet_append_label(DnsPacket *p, const char *s, size_t l, bool canonical_candidate, size_t *start);
199int dns_packet_append_name(DnsPacket *p, const char *name, bool allow_compression, bool canonical_candidate, size_t *start);
58ab31d5
DR
200int dns_packet_append_key(DnsPacket *p, const DnsResourceKey *key, const DnsAnswerFlags flags, size_t *start);
201int dns_packet_append_rr(DnsPacket *p, const DnsResourceRecord *rr, const DnsAnswerFlags flags, size_t *start, size_t *rdata_start);
f2ed4c69 202int dns_packet_append_opt(DnsPacket *p, uint16_t max_udp_size, bool edns0_do, int rcode, size_t *start);
f471bc11
LP
203int dns_packet_append_question(DnsPacket *p, DnsQuestion *q);
204int dns_packet_append_answer(DnsPacket *p, DnsAnswer *a);
74b2466e 205
9c5e12a4 206void dns_packet_truncate(DnsPacket *p, size_t sz);
519ef046 207int dns_packet_truncate_opt(DnsPacket *p);
9c5e12a4 208
74b2466e 209int dns_packet_read(DnsPacket *p, size_t sz, const void **ret, size_t *start);
623a4c97 210int dns_packet_read_blob(DnsPacket *p, void *d, size_t sz, size_t *start);
74b2466e
LP
211int dns_packet_read_uint8(DnsPacket *p, uint8_t *ret, size_t *start);
212int dns_packet_read_uint16(DnsPacket *p, uint16_t *ret, size_t *start);
213int dns_packet_read_uint32(DnsPacket *p, uint32_t *ret, size_t *start);
214int dns_packet_read_string(DnsPacket *p, char **ret, size_t *start);
2001c805
LP
215int dns_packet_read_raw_string(DnsPacket *p, const void **ret, size_t *size, size_t *start);
216int dns_packet_read_name(DnsPacket *p, char **ret, bool allow_compression, size_t *start);
d2579eec
LP
217int dns_packet_read_key(DnsPacket *p, DnsResourceKey **ret, bool *ret_cache_flush, size_t *start);
218int dns_packet_read_rr(DnsPacket *p, DnsResourceRecord **ret, bool *ret_cache_flush, size_t *start);
74b2466e 219
8ba9fd9c
LP
220void dns_packet_rewind(DnsPacket *p, size_t idx);
221
74b2466e 222int dns_packet_skip_question(DnsPacket *p);
faa133f3 223int dns_packet_extract(DnsPacket *p);
74b2466e 224
d830ebbd
LP
225static inline bool DNS_PACKET_SHALL_CACHE(DnsPacket *p) {
226 /* Never cache data originating from localhost, under the
227 * assumption, that it's coming from a locally DNS forwarder
228 * or server, that is caching on its own. */
229
230 return in_addr_is_localhost(p->family, &p->sender) == 0;
231}
232
f3abbe25 233/* https://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml#dns-parameters-6 */
74b2466e
LP
234enum {
235 DNS_RCODE_SUCCESS = 0,
236 DNS_RCODE_FORMERR = 1,
237 DNS_RCODE_SERVFAIL = 2,
238 DNS_RCODE_NXDOMAIN = 3,
239 DNS_RCODE_NOTIMP = 4,
240 DNS_RCODE_REFUSED = 5,
241 DNS_RCODE_YXDOMAIN = 6,
242 DNS_RCODE_YXRRSET = 7,
243 DNS_RCODE_NXRRSET = 8,
244 DNS_RCODE_NOTAUTH = 9,
245 DNS_RCODE_NOTZONE = 10,
246 DNS_RCODE_BADVERS = 16,
247 DNS_RCODE_BADSIG = 16, /* duplicate value! */
248 DNS_RCODE_BADKEY = 17,
249 DNS_RCODE_BADTIME = 18,
250 DNS_RCODE_BADMODE = 19,
251 DNS_RCODE_BADNAME = 20,
252 DNS_RCODE_BADALG = 21,
253 DNS_RCODE_BADTRUNC = 22,
6f21e066 254 DNS_RCODE_BADCOOKIE = 23,
f2ed4c69
LP
255 _DNS_RCODE_MAX_DEFINED,
256 _DNS_RCODE_MAX = 4095 /* 4 bit rcode in the header plus 8 bit rcode in OPT, makes 12 bit */
74b2466e
LP
257};
258
259const char* dns_rcode_to_string(int i) _const_;
260int dns_rcode_from_string(const char *s) _pure_;
1716f6dc
LP
261
262const char* dns_protocol_to_string(DnsProtocol p) _const_;
263DnsProtocol dns_protocol_from_string(const char *s) _pure_;
264
265#define LLMNR_MULTICAST_IPV4_ADDRESS ((struct in_addr) { .s_addr = htobe32(224U << 24 | 252U) })
266#define LLMNR_MULTICAST_IPV6_ADDRESS ((struct in6_addr) { .s6_addr = { 0xFF, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01, 0x00, 0x03 } })
8db0d2f5 267
0db4c90a 268#define MDNS_MULTICAST_IPV4_ADDRESS ((struct in_addr) { .s_addr = htobe32(224U << 24 | 251U) })
b6c5d46b 269#define MDNS_MULTICAST_IPV6_ADDRESS ((struct in6_addr) { .s6_addr = { 0xFF, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xfb } })
0db4c90a 270
98767d75
IT
271extern const struct hash_ops dns_packet_hash_ops;
272
931851e8
LP
273static inline uint64_t SD_RESOLVED_FLAGS_MAKE(DnsProtocol protocol, int family, bool authenticated) {
274 uint64_t f;
51323288 275
931851e8
LP
276 /* Converts a protocol + family into a flags field as used in queries and responses */
277
278 f = authenticated ? SD_RESOLVED_AUTHENTICATED : 0;
51323288 279
106784eb
DM
280 switch (protocol) {
281 case DNS_PROTOCOL_DNS:
931851e8 282 return f|SD_RESOLVED_DNS;
51323288 283
106784eb 284 case DNS_PROTOCOL_LLMNR:
931851e8 285 return f|(family == AF_INET6 ? SD_RESOLVED_LLMNR_IPV6 : SD_RESOLVED_LLMNR_IPV4);
51323288 286
4e5bf5e1 287 case DNS_PROTOCOL_MDNS:
12e1893a 288 return f|(family == AF_INET6 ? SD_RESOLVED_MDNS_IPV6 : SD_RESOLVED_MDNS_IPV4);
4e5bf5e1 289
106784eb 290 default:
12e1893a 291 return f;
106784eb 292 }
51323288 293}
51027656
LP
294
295static inline size_t dns_packet_size_max(DnsPacket *p) {
296 assert(p);
297
298 /* Why not insist on a fully initialized max_size during DnsPacket construction? Well, this way it's easy to
299 * allocate a transient, throw-away DnsPacket on the stack by simple zero initialization, without having to
300 * deal with explicit field initialization. */
301
302 return p->max_size != 0 ? p->max_size : DNS_PACKET_SIZE_MAX;
303}