]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/resolve/resolved-dns-server.h
Merge pull request #18007 from fw-strlen/ipv6_masq_and_dnat
[thirdparty/systemd.git] / src / resolve / resolved-dns-server.h
1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
2 #pragma once
3
4 #include "in-addr-util.h"
5 #include "list.h"
6 #include "resolve-util.h"
7 #include "time-util.h"
8
9 typedef struct DnsScope DnsScope;
10 typedef struct DnsServer DnsServer;
11 typedef struct DnsStream DnsStream;
12 typedef struct DnsPacket DnsPacket;
13 typedef struct Link Link;
14 typedef struct Manager Manager;
15
16 #include "resolved-dnstls.h"
17
18 typedef enum DnsServerType {
19 DNS_SERVER_SYSTEM,
20 DNS_SERVER_FALLBACK,
21 DNS_SERVER_LINK,
22 _DNS_SERVER_TYPE_MAX,
23 _DNS_SERVER_TYPE_INVALID = -EINVAL,
24 } DnsServerType;
25
26 const char* dns_server_type_to_string(DnsServerType i) _const_;
27 DnsServerType dns_server_type_from_string(const char *s) _pure_;
28
29 typedef enum DnsServerFeatureLevel {
30 DNS_SERVER_FEATURE_LEVEL_TCP,
31 DNS_SERVER_FEATURE_LEVEL_UDP,
32 DNS_SERVER_FEATURE_LEVEL_EDNS0,
33 DNS_SERVER_FEATURE_LEVEL_TLS_PLAIN,
34 DNS_SERVER_FEATURE_LEVEL_DO,
35 DNS_SERVER_FEATURE_LEVEL_LARGE,
36 DNS_SERVER_FEATURE_LEVEL_TLS_DO,
37 _DNS_SERVER_FEATURE_LEVEL_MAX,
38 _DNS_SERVER_FEATURE_LEVEL_INVALID = -EINVAL,
39 } DnsServerFeatureLevel;
40
41 #define DNS_SERVER_FEATURE_LEVEL_WORST 0
42 #define DNS_SERVER_FEATURE_LEVEL_BEST (_DNS_SERVER_FEATURE_LEVEL_MAX - 1)
43 #define DNS_SERVER_FEATURE_LEVEL_IS_EDNS0(x) ((x) >= DNS_SERVER_FEATURE_LEVEL_EDNS0)
44 #define DNS_SERVER_FEATURE_LEVEL_IS_TLS(x) IN_SET(x, DNS_SERVER_FEATURE_LEVEL_TLS_PLAIN, DNS_SERVER_FEATURE_LEVEL_TLS_DO)
45 #define DNS_SERVER_FEATURE_LEVEL_IS_DNSSEC(x) ((x) >= DNS_SERVER_FEATURE_LEVEL_DO)
46 #define DNS_SERVER_FEATURE_LEVEL_IS_UDP(x) IN_SET(x, DNS_SERVER_FEATURE_LEVEL_UDP, DNS_SERVER_FEATURE_LEVEL_EDNS0, DNS_SERVER_FEATURE_LEVEL_DO, DNS_SERVER_FEATURE_LEVEL_LARGE)
47
48 const char* dns_server_feature_level_to_string(int i) _const_;
49 int dns_server_feature_level_from_string(const char *s) _pure_;
50
51 struct DnsServer {
52 Manager *manager;
53
54 unsigned n_ref;
55
56 DnsServerType type;
57 Link *link;
58
59 int family;
60 union in_addr_union address;
61 int ifindex; /* for IPv6 link-local DNS servers */
62 uint16_t port;
63 char *server_name;
64
65 char *server_string;
66 char *server_string_full;
67
68 /* The long-lived stream towards this server. */
69 DnsStream *stream;
70
71 #if ENABLE_DNS_OVER_TLS
72 DnsTlsServerData dnstls_data;
73 #endif
74
75 DnsServerFeatureLevel verified_feature_level;
76 DnsServerFeatureLevel possible_feature_level;
77
78 size_t received_udp_packet_max;
79
80 unsigned n_failed_udp;
81 unsigned n_failed_tcp;
82 unsigned n_failed_tls;
83
84 bool packet_truncated:1; /* Set when TC bit was set on reply */
85 bool packet_bad_opt:1; /* Set when OPT was missing or otherwise bad on reply */
86 bool packet_rrsig_missing:1; /* Set when RRSIG was missing */
87 bool packet_invalid:1; /* Set when we failed to parse a reply */
88
89 usec_t verified_usec;
90 usec_t features_grace_period_usec;
91
92 /* Whether we already warned about downgrading to non-DNSSEC mode for this server */
93 bool warned_downgrade:1;
94
95 /* Used when GC'ing old DNS servers when configuration changes. */
96 bool marked:1;
97
98 /* If linked is set, then this server appears in the servers linked list */
99 bool linked:1;
100 LIST_FIELDS(DnsServer, servers);
101 };
102
103 int dns_server_new(
104 Manager *m,
105 DnsServer **ret,
106 DnsServerType type,
107 Link *link,
108 int family,
109 const union in_addr_union *address,
110 uint16_t port,
111 int ifindex,
112 const char *server_string);
113
114 DnsServer* dns_server_ref(DnsServer *s);
115 DnsServer* dns_server_unref(DnsServer *s);
116
117 void dns_server_unlink(DnsServer *s);
118 void dns_server_move_back_and_unmark(DnsServer *s);
119
120 void dns_server_packet_received(DnsServer *s, int protocol, DnsServerFeatureLevel level, size_t size);
121 void dns_server_packet_lost(DnsServer *s, int protocol, DnsServerFeatureLevel level);
122 void dns_server_packet_truncated(DnsServer *s, DnsServerFeatureLevel level);
123 void dns_server_packet_rrsig_missing(DnsServer *s, DnsServerFeatureLevel level);
124 void dns_server_packet_bad_opt(DnsServer *s, DnsServerFeatureLevel level);
125 void dns_server_packet_rcode_downgrade(DnsServer *s, DnsServerFeatureLevel level);
126 void dns_server_packet_invalid(DnsServer *s, DnsServerFeatureLevel level);
127
128 DnsServerFeatureLevel dns_server_possible_feature_level(DnsServer *s);
129
130 int dns_server_adjust_opt(DnsServer *server, DnsPacket *packet, DnsServerFeatureLevel level);
131
132 const char *dns_server_string(DnsServer *server);
133 const char *dns_server_string_full(DnsServer *server);
134 int dns_server_ifindex(const DnsServer *s);
135 uint16_t dns_server_port(const DnsServer *s);
136
137 bool dns_server_dnssec_supported(DnsServer *server);
138
139 void dns_server_warn_downgrade(DnsServer *server);
140
141 DnsServer *dns_server_find(DnsServer *first, int family, const union in_addr_union *in_addr, uint16_t port, int ifindex, const char *name);
142
143 void dns_server_unlink_all(DnsServer *first);
144 void dns_server_unlink_marked(DnsServer *first);
145 void dns_server_mark_all(DnsServer *first);
146
147 DnsServer *manager_get_first_dns_server(Manager *m, DnsServerType t);
148
149 DnsServer *manager_set_dns_server(Manager *m, DnsServer *s);
150 DnsServer *manager_get_dns_server(Manager *m);
151 void manager_next_dns_server(Manager *m, DnsServer *if_current);
152
153 DnssecMode dns_server_get_dnssec_mode(DnsServer *s);
154 DnsOverTlsMode dns_server_get_dns_over_tls_mode(DnsServer *s);
155
156 DEFINE_TRIVIAL_CLEANUP_FUNC(DnsServer*, dns_server_unref);
157
158 extern const struct hash_ops dns_server_hash_ops;
159
160 void dns_server_flush_cache(DnsServer *s);
161
162 void dns_server_reset_features(DnsServer *s);
163 void dns_server_reset_features_all(DnsServer *s);
164
165 void dns_server_dump(DnsServer *s, FILE *f);
166
167 void dns_server_unref_stream(DnsServer *s);
168
169 DnsScope *dns_server_scope(DnsServer *s);