2 * This file is part of PowerDNS or dnsdist.
3 * Copyright -- PowerDNS.COM B.V. and its contributors
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of version 2 of the GNU General Public License as
7 * published by the Free Software Foundation.
9 * In addition, for the avoidance of any doubt, permission is granted to
10 * link this program with OpenSSL and to (re)distribute the binaries
11 * produced as the result of such linking.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
22 #ifndef RECURSOR_CACHE_HH
23 #define RECURSOR_CACHE_HH
31 #include "dnsrecords.hh"
32 #include <boost/utility.hpp>
34 #include <boost/multi_index_container.hpp>
35 #include <boost/multi_index/ordered_index.hpp>
36 #include <boost/multi_index/hashed_index.hpp>
37 #include <boost/tuple/tuple_comparison.hpp>
38 #include <boost/multi_index/key_extractors.hpp>
39 #include <boost/multi_index/sequenced_index.hpp>
40 #include <boost/version.hpp>
42 #include "validate.hh"
46 #include "namespaces.hh"
47 using namespace ::boost::multi_index;
49 class MemRecursorCache : public boost::noncopyable // : public RecursorCache
52 MemRecursorCache() : d_cachecachevalid(false)
54 cacheHits = cacheMisses = 0;
58 int32_t get(time_t, const DNSName &qname, const QType& qt, bool requireAuth, vector<DNSRecord>* res, const ComboAddress& who, vector<std::shared_ptr<RRSIGRecordContent>>* signatures=nullptr, std::vector<std::shared_ptr<DNSRecord>>* authorityRecs=nullptr, bool* variable=nullptr, vState* state=nullptr, bool* wasAuth=nullptr);
60 void replace(time_t, const DNSName &qname, const QType& qt, const vector<DNSRecord>& content, const vector<shared_ptr<RRSIGRecordContent>>& signatures, const std::vector<std::shared_ptr<DNSRecord>>& authorityRecs, bool auth, boost::optional<Netmask> ednsmask=boost::none, vState state=Indeterminate);
63 void doPrune(unsigned int keep);
64 uint64_t doDump(int fd);
66 int doWipeCache(const DNSName& name, bool sub, uint16_t qtype=0xffff);
67 bool doAgeCache(time_t now, const DNSName& name, uint16_t qtype, uint32_t newTTL);
68 bool updateValidationStatus(time_t now, const DNSName &qname, const QType& qt, const ComboAddress& who, bool requireAuth, vState newState);
70 uint64_t cacheHits, cacheMisses;
76 CacheEntry(const boost::tuple<DNSName, uint16_t, Netmask>& key, const vector<shared_ptr<DNSRecordContent>>& records, bool auth) :
77 d_records(records), d_qname(key.get<0>()), d_netmask(key.get<2>()), d_state(Indeterminate), d_ttd(0), d_qtype(key.get<1>()), d_auth(auth)
80 typedef vector<std::shared_ptr<DNSRecordContent>> records_t;
87 std::vector<std::shared_ptr<RRSIGRecordContent>> d_signatures;
88 std::vector<std::shared_ptr<DNSRecord>> d_authorityRecs;
91 mutable vState d_state;
97 /* The ECS Index (d_ecsIndex) keeps track of whether there is any ECS-specific
98 entry for a given (qname,qtype) entry in the cache (d_cache), and if so
99 provides a NetmaskTree of those ECS entries.
100 This allows figuring out quickly if we should look for an entry
101 specific to the requestor IP, and if so which entry is the most
103 Keeping the entries in the regular cache is currently necessary
104 because of the way we manage expired entries (moving them to the
105 front of the expunge queue to be deleted at a regular interval).
110 ECSIndexEntry(const DNSName& qname, uint16_t qtype): d_qname(qname), d_qtype(qtype)
114 Netmask lookupBestMatch(const ComboAddress& addr) const
116 Netmask result = Netmask();
118 const auto best = d_nmt.lookup(addr);
119 if (best != nullptr) {
120 result = best->first;
126 void addMask(const Netmask& nm) const
128 d_nmt.insert(nm).second = true;
131 void removeNetmask(const Netmask& nm) const
138 return d_nmt.empty();
141 mutable NetmaskTree<bool> d_nmt;
146 typedef multi_index_container<
152 member<CacheEntry,DNSName,&CacheEntry::d_qname>,
153 member<CacheEntry,uint16_t,&CacheEntry::d_qtype>,
154 member<CacheEntry,Netmask,&CacheEntry::d_netmask>
156 composite_key_compare<CanonDNSNameCompare, std::less<uint16_t>, std::less<Netmask> >
161 typedef multi_index_container<
167 member<ECSIndexEntry,DNSName,&ECSIndexEntry::d_qname>,
168 member<ECSIndexEntry,uint16_t,&ECSIndexEntry::d_qtype>
175 ecsIndex_t d_ecsIndex;
176 pair<cache_t::iterator, cache_t::iterator> d_cachecache;
177 DNSName d_cachedqname;
178 bool d_cachecachevalid;
180 bool attemptToRefreshNSTTL(const QType& qt, const vector<DNSRecord>& content, const CacheEntry& stored);
181 bool entryMatches(cache_t::const_iterator& entry, uint16_t qt, bool requireAuth, const ComboAddress& who);
182 std::pair<cache_t::const_iterator, cache_t::const_iterator> getEntries(const DNSName &qname, const QType& qt);
183 cache_t::const_iterator getEntryUsingECSIndex(time_t now, const DNSName &qname, uint16_t qtype, bool requireAuth, const ComboAddress& who);
184 int32_t handleHit(cache_t::iterator entry, const DNSName& qname, const ComboAddress& who, vector<DNSRecord>* res, vector<std::shared_ptr<RRSIGRecordContent>>* signatures, std::vector<std::shared_ptr<DNSRecord>>* authorityRecs, bool* variable, vState* state, bool* wasAuth);
187 void preRemoval(const CacheEntry& entry)
189 if (entry.d_netmask.empty()) {
193 auto key = tie(entry.d_qname, entry.d_qtype);
194 auto ecsIndexEntry = d_ecsIndex.find(key);
195 if (ecsIndexEntry != d_ecsIndex.end()) {
196 ecsIndexEntry->removeNetmask(entry.d_netmask);
197 if (ecsIndexEntry->isEmpty()) {
198 d_ecsIndex.erase(ecsIndexEntry);