1 /* SPDX-License-Identifier: LGPL-2.1+ */
5 This file is part of systemd.
7 Copyright 2014 Lennart Poettering
9 systemd is free software; you can redistribute it and/or modify it
10 under the terms of the GNU Lesser General Public License as published by
11 the Free Software Foundation; either version 2.1 of the License, or
12 (at your option) any later version.
14 systemd is distributed in the hope that it will be useful, but
15 WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
17 Lesser General Public License for more details.
19 You should have received a copy of the GNU Lesser General Public License
20 along with systemd; If not, see <http://www.gnu.org/licenses/>.
23 #include <netinet/in.h>
28 #include "in-addr-util.h"
30 #include "string-util.h"
32 typedef struct DnsResourceKey DnsResourceKey
;
33 typedef struct DnsResourceRecord DnsResourceRecord
;
34 typedef struct DnsTxtItem DnsTxtItem
;
37 #define DNSKEY_FLAG_SEP (UINT16_C(1) << 0)
38 #define DNSKEY_FLAG_REVOKE (UINT16_C(1) << 7)
39 #define DNSKEY_FLAG_ZONE_KEY (UINT16_C(1) << 8)
42 #define MDNS_RR_CACHE_FLUSH (UINT16_C(1) << 15)
44 /* DNSSEC algorithm identifiers, see
45 * http://tools.ietf.org/html/rfc4034#appendix-A.1 and
46 * https://www.iana.org/assignments/dns-sec-alg-numbers/dns-sec-alg-numbers.xhtml */
48 DNSSEC_ALGORITHM_RSAMD5
= 1,
52 DNSSEC_ALGORITHM_RSASHA1
,
53 DNSSEC_ALGORITHM_DSA_NSEC3_SHA1
,
54 DNSSEC_ALGORITHM_RSASHA1_NSEC3_SHA1
,
55 DNSSEC_ALGORITHM_RSASHA256
= 8, /* RFC 5702 */
56 DNSSEC_ALGORITHM_RSASHA512
= 10, /* RFC 5702 */
57 DNSSEC_ALGORITHM_ECC_GOST
= 12, /* RFC 5933 */
58 DNSSEC_ALGORITHM_ECDSAP256SHA256
= 13, /* RFC 6605 */
59 DNSSEC_ALGORITHM_ECDSAP384SHA384
= 14, /* RFC 6605 */
60 DNSSEC_ALGORITHM_ED25519
= 15, /* RFC 8080 */
61 DNSSEC_ALGORITHM_ED448
= 16, /* RFC 8080 */
62 DNSSEC_ALGORITHM_INDIRECT
= 252,
63 DNSSEC_ALGORITHM_PRIVATEDNS
,
64 DNSSEC_ALGORITHM_PRIVATEOID
,
65 _DNSSEC_ALGORITHM_MAX_DEFINED
68 /* DNSSEC digest identifiers, see
69 * https://www.iana.org/assignments/ds-rr-types/ds-rr-types.xhtml */
71 DNSSEC_DIGEST_SHA1
= 1,
72 DNSSEC_DIGEST_SHA256
= 2, /* RFC 4509 */
73 DNSSEC_DIGEST_GOST_R_34_11_94
= 3, /* RFC 5933 */
74 DNSSEC_DIGEST_SHA384
= 4, /* RFC 6605 */
75 _DNSSEC_DIGEST_MAX_DEFINED
78 /* DNSSEC NSEC3 hash algorithms, see
79 * https://www.iana.org/assignments/dnssec-nsec3-parameters/dnssec-nsec3-parameters.xhtml */
81 NSEC3_ALGORITHM_SHA1
= 1,
82 _NSEC3_ALGORITHM_MAX_DEFINED
85 struct DnsResourceKey
{
86 unsigned n_ref
; /* (unsigned -1) for const keys, see below */
88 char *_name
; /* don't access directly, use dns_resource_key_name()! */
91 /* Creates a temporary resource key. This is only useful to quickly
92 * look up something, without allocating a full DnsResourceKey object
93 * for it. Note that it is not OK to take references to this kind of
94 * resource key object. */
95 #define DNS_RESOURCE_KEY_CONST(c, t, n) \
97 .n_ref = (unsigned) -1, \
100 ._name = (char*) n, \
106 LIST_FIELDS(DnsTxtItem
, items
);
110 struct DnsResourceRecord
{
117 usec_t expiry
; /* RRSIG signature expiry */
119 /* How many labels to strip to determine "signer" of the RRSIG (aka, the zone). -1 if not signed. */
120 unsigned n_skip_labels_signer
;
121 /* How many labels to strip to determine "synthesizing source" of this RR, i.e. the wildcard's immediate parent. -1 if not signed. */
122 unsigned n_skip_labels_source
;
126 bool wire_format_canonical
:1;
128 size_t wire_format_size
;
129 size_t wire_format_rdata_offset
;
146 } ptr
, ns
, cname
, dname
;
158 struct in_addr in_addr
;
162 struct in6_addr in6_addr
;
180 /* https://tools.ietf.org/html/rfc1876 */
191 /* https://tools.ietf.org/html/rfc4255#section-3.1 */
196 size_t fingerprint_size
;
199 /* http://tools.ietf.org/html/rfc4034#section-2.1 */
208 /* http://tools.ietf.org/html/rfc4034#section-3.1 */
210 uint16_t type_covered
;
213 uint32_t original_ttl
;
219 size_t signature_size
;
222 /* https://tools.ietf.org/html/rfc4034#section-4.1 */
224 char *next_domain_name
;
228 /* https://tools.ietf.org/html/rfc4034#section-5.1 */
243 void *next_hashed_name
;
244 size_t next_hashed_name_size
;
248 /* https://tools.ietf.org/html/draft-ietf-dane-protocol-23 */
252 uint8_t matching_type
;
257 /* https://tools.ietf.org/html/rfc6844 */
267 static inline const void* DNS_RESOURCE_RECORD_RDATA(DnsResourceRecord
*rr
) {
271 if (!rr
->wire_format
)
274 assert(rr
->wire_format_rdata_offset
<= rr
->wire_format_size
);
275 return (uint8_t*) rr
->wire_format
+ rr
->wire_format_rdata_offset
;
278 static inline size_t DNS_RESOURCE_RECORD_RDATA_SIZE(DnsResourceRecord
*rr
) {
281 if (!rr
->wire_format
)
284 assert(rr
->wire_format_rdata_offset
<= rr
->wire_format_size
);
285 return rr
->wire_format_size
- rr
->wire_format_rdata_offset
;
288 static inline uint8_t DNS_RESOURCE_RECORD_OPT_VERSION_SUPPORTED(DnsResourceRecord
*rr
) {
290 assert(rr
->key
->type
== DNS_TYPE_OPT
);
292 return ((rr
->ttl
>> 16) & 0xFF) == 0;
295 DnsResourceKey
* dns_resource_key_new(uint16_t class, uint16_t type
, const char *name
);
296 DnsResourceKey
* dns_resource_key_new_redirect(const DnsResourceKey
*key
, const DnsResourceRecord
*cname
);
297 int dns_resource_key_new_append_suffix(DnsResourceKey
**ret
, DnsResourceKey
*key
, char *name
);
298 DnsResourceKey
* dns_resource_key_new_consume(uint16_t class, uint16_t type
, char *name
);
299 DnsResourceKey
* dns_resource_key_ref(DnsResourceKey
*key
);
300 DnsResourceKey
* dns_resource_key_unref(DnsResourceKey
*key
);
301 const char* dns_resource_key_name(const DnsResourceKey
*key
);
302 bool dns_resource_key_is_address(const DnsResourceKey
*key
);
303 bool dns_resource_key_is_dnssd_ptr(const DnsResourceKey
*key
);
304 int dns_resource_key_equal(const DnsResourceKey
*a
, const DnsResourceKey
*b
);
305 int dns_resource_key_match_rr(const DnsResourceKey
*key
, DnsResourceRecord
*rr
, const char *search_domain
);
306 int dns_resource_key_match_cname_or_dname(const DnsResourceKey
*key
, const DnsResourceKey
*cname
, const char *search_domain
);
307 int dns_resource_key_match_soa(const DnsResourceKey
*key
, const DnsResourceKey
*soa
);
309 /* _DNS_{CLASS,TYPE}_STRING_MAX include one byte for NUL, which we use for space instead below.
310 * DNS_HOSTNAME_MAX does not include the NUL byte, so we need to add 1. */
311 #define DNS_RESOURCE_KEY_STRING_MAX (_DNS_CLASS_STRING_MAX + _DNS_TYPE_STRING_MAX + DNS_HOSTNAME_MAX + 1)
313 char* dns_resource_key_to_string(const DnsResourceKey
*key
, char *buf
, size_t buf_size
);
314 ssize_t
dns_resource_record_payload(DnsResourceRecord
*rr
, void **out
);
316 DEFINE_TRIVIAL_CLEANUP_FUNC(DnsResourceKey
*, dns_resource_key_unref
);
318 static inline bool dns_key_is_shared(const DnsResourceKey
*key
) {
319 return IN_SET(key
->type
, DNS_TYPE_PTR
);
322 bool dns_resource_key_reduce(DnsResourceKey
**a
, DnsResourceKey
**b
);
324 DnsResourceRecord
* dns_resource_record_new(DnsResourceKey
*key
);
325 DnsResourceRecord
* dns_resource_record_new_full(uint16_t class, uint16_t type
, const char *name
);
326 DnsResourceRecord
* dns_resource_record_ref(DnsResourceRecord
*rr
);
327 DnsResourceRecord
* dns_resource_record_unref(DnsResourceRecord
*rr
);
328 int dns_resource_record_new_reverse(DnsResourceRecord
**ret
, int family
, const union in_addr_union
*address
, const char *name
);
329 int dns_resource_record_new_address(DnsResourceRecord
**ret
, int family
, const union in_addr_union
*address
, const char *name
);
330 int dns_resource_record_equal(const DnsResourceRecord
*a
, const DnsResourceRecord
*b
);
331 const char* dns_resource_record_to_string(DnsResourceRecord
*rr
);
332 DnsResourceRecord
*dns_resource_record_copy(DnsResourceRecord
*rr
);
333 DEFINE_TRIVIAL_CLEANUP_FUNC(DnsResourceRecord
*, dns_resource_record_unref
);
335 int dns_resource_record_to_wire_format(DnsResourceRecord
*rr
, bool canonical
);
337 int dns_resource_record_signer(DnsResourceRecord
*rr
, const char **ret
);
338 int dns_resource_record_source(DnsResourceRecord
*rr
, const char **ret
);
339 int dns_resource_record_is_signer(DnsResourceRecord
*rr
, const char *zone
);
340 int dns_resource_record_is_synthetic(DnsResourceRecord
*rr
);
342 int dns_resource_record_clamp_ttl(DnsResourceRecord
**rr
, uint32_t max_ttl
);
344 DnsTxtItem
*dns_txt_item_free_all(DnsTxtItem
*i
);
345 bool dns_txt_item_equal(DnsTxtItem
*a
, DnsTxtItem
*b
);
346 DnsTxtItem
*dns_txt_item_copy(DnsTxtItem
*i
);
347 int dns_txt_item_new_empty(DnsTxtItem
**ret
);
349 void dns_resource_record_hash_func(const void *i
, struct siphash
*state
);
351 extern const struct hash_ops dns_resource_key_hash_ops
;
352 extern const struct hash_ops dns_resource_record_hash_ops
;
354 int dnssec_algorithm_to_string_alloc(int i
, char **ret
);
355 int dnssec_algorithm_from_string(const char *s
) _pure_
;
357 int dnssec_digest_to_string_alloc(int i
, char **ret
);
358 int dnssec_digest_from_string(const char *s
) _pure_
;