fc9ddcf941
Merge in DNS/adguard-home from 1383-client-id to master Updates #1383. Squashed commit of the following: commit ebe2678bfa9bf651a2cb1e64499b38edcf19a7ad Author: Ildar Kamalov <ik@adguard.com> Date: Wed Jan 27 17:51:59 2021 +0300 - client: check if IP is valid commit 0c330585a170ea149ee75e43dfa65211e057299c Author: Ildar Kamalov <ik@adguard.com> Date: Wed Jan 27 17:07:50 2021 +0300 - client: find clients by client_id commit 71c9593ee35d996846f061e114b7867c3aa3c978 Merge: 9104f1613e9edd9e
Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Wed Jan 27 16:09:45 2021 +0300 Merge branch 'master' into 1383-client-id commit 9104f1615d2d462606c52017df25a422df872cea Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Wed Jan 27 13:28:50 2021 +0300 dnsforward: imp tests commit ed47f26e611ade625a2cc2c2f71a291b796bbf8f Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Wed Jan 27 12:39:52 2021 +0300 dnsforward: fix address commit 98b222ba69a5d265f620c180c960d01c84a1fb3b Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Tue Jan 26 19:50:31 2021 +0300 home: imp code commit 4f3966548a2d8437d0b68207dd108dd1a6cb7d20 Merge: 199fdc05c215b820
Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Tue Jan 26 19:45:13 2021 +0300 Merge branch 'master' into 1383-client-id commit 199fdc056f8a8be5500584f3aaee32865188aedc Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Tue Jan 26 19:20:37 2021 +0300 all: imp tests, logging, etc commit 35ff14f4d534251aecb2ea60baba225f3eed8a3e Author: Ildar Kamalov <ik@adguard.com> Date: Tue Jan 26 18:55:19 2021 +0300 + client: remove block button from clients with client_id commit 32991a0b4c56583a02fb5e00bba95d96000bce20 Author: Ildar Kamalov <ik@adguard.com> Date: Tue Jan 26 18:54:25 2021 +0300 + client: add requests count for client_id commit 2d68df4d2eac4a296d7469923e601dad4575c1a1 Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Tue Jan 26 15:49:50 2021 +0300 stats: handle client ids commit 4e14ab3590328f93a8cd6e9cbe1665baf74f220b Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Tue Jan 26 13:45:25 2021 +0300 openapi: fix example commit ca9cf3f744fe197cace2c28ddc5bc68f71dad1f3 Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Tue Jan 26 13:37:10 2021 +0300 openapi: improve clients find api docs commit f79876e550c424558b704bc316a4cd04f25db011 Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Tue Jan 26 13:18:52 2021 +0300 home: accept ids in clients find commit 5b72595122aa0bd64debadfd753ed8a0e0840629 Merge: 607e241fabf8f65f
Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Mon Jan 25 18:34:56 2021 +0300 Merge branch 'master' into 1383-client-id commit 607e241f1c339dd6397218f70b8301e3de6a1ee0 Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Mon Jan 25 18:30:39 2021 +0300 dnsforward: fix quic commit f046352fef93e46234c2bbe8ae316d21034260e5 Author: Ainar Garipov <A.Garipov@AdGuard.COM> Date: Mon Jan 25 16:53:09 2021 +0300 all: remove wildcard requirement commit 3b679489bae82c54177372be453fe184d8f0bab6 Author: Andrey Meshkov <am@adguard.com> Date: Mon Jan 25 16:02:28 2021 +0300 workDir now supports symlinks commit 0647ab4f113de2223f6949df001f42ecab05c995 Author: Ildar Kamalov <ik@adguard.com> Date: Mon Jan 25 14:59:46 2021 +0300 - client: remove wildcard from domain validation commit b1aec04a4ecadc9d65648ed6d284188fecce01c3 Author: Ildar Kamalov <ik@adguard.com> Date: Mon Jan 25 14:55:39 2021 +0300 + client: add form to download mobileconfig ... and 12 more commits
143 lines
3.3 KiB
Go
143 lines
3.3 KiB
Go
package dnsforward
|
|
|
|
import (
|
|
"net"
|
|
"strings"
|
|
"sync"
|
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/util"
|
|
"github.com/AdguardTeam/golibs/log"
|
|
"github.com/miekg/dns"
|
|
)
|
|
|
|
type ipsetCtx struct {
|
|
ipsetList map[string][]string // domain -> []ipset_name
|
|
ipsetCache map[[4]byte]bool // cache for IP[] to prevent duplicate calls to ipset program
|
|
ipsetMutex *sync.Mutex
|
|
ipset6Cache map[[16]byte]bool // cache for IP[] to prevent duplicate calls to ipset program
|
|
ipset6Mutex *sync.Mutex
|
|
}
|
|
|
|
// Convert configuration settings to an internal map
|
|
// DOMAIN[,DOMAIN].../IPSET1_NAME[,IPSET2_NAME]...
|
|
func (c *ipsetCtx) init(ipsetConfig []string) {
|
|
c.ipsetList = make(map[string][]string)
|
|
c.ipsetCache = make(map[[4]byte]bool)
|
|
c.ipsetMutex = &sync.Mutex{}
|
|
c.ipset6Cache = make(map[[16]byte]bool)
|
|
c.ipset6Mutex = &sync.Mutex{}
|
|
|
|
for _, it := range ipsetConfig {
|
|
it = strings.TrimSpace(it)
|
|
hostsAndNames := strings.Split(it, "/")
|
|
if len(hostsAndNames) != 2 {
|
|
log.Debug("IPSET: invalid value %q", it)
|
|
continue
|
|
}
|
|
|
|
ipsetNames := strings.Split(hostsAndNames[1], ",")
|
|
if len(ipsetNames) == 0 {
|
|
log.Debug("IPSET: invalid value %q", it)
|
|
continue
|
|
}
|
|
bad := false
|
|
for i := range ipsetNames {
|
|
ipsetNames[i] = strings.TrimSpace(ipsetNames[i])
|
|
if len(ipsetNames[i]) == 0 {
|
|
bad = true
|
|
break
|
|
}
|
|
}
|
|
if bad {
|
|
log.Debug("IPSET: invalid value %q", it)
|
|
continue
|
|
}
|
|
|
|
hosts := strings.Split(hostsAndNames[0], ",")
|
|
for _, host := range hosts {
|
|
host = strings.TrimSpace(host)
|
|
host = strings.ToLower(host)
|
|
if len(host) == 0 {
|
|
log.Debug("IPSET: invalid value %q", it)
|
|
continue
|
|
}
|
|
c.ipsetList[host] = ipsetNames
|
|
}
|
|
}
|
|
log.Debug("IPSET: added %d hosts", len(c.ipsetList))
|
|
}
|
|
|
|
func (c *ipsetCtx) getIP(rr dns.RR) net.IP {
|
|
switch a := rr.(type) {
|
|
case *dns.A:
|
|
var ip4 [4]byte
|
|
copy(ip4[:], a.A.To4())
|
|
c.ipsetMutex.Lock()
|
|
defer c.ipsetMutex.Unlock()
|
|
_, found := c.ipsetCache[ip4]
|
|
if found {
|
|
return nil // this IP was added before
|
|
}
|
|
c.ipsetCache[ip4] = false
|
|
return a.A
|
|
|
|
case *dns.AAAA:
|
|
var ip6 [16]byte
|
|
copy(ip6[:], a.AAAA)
|
|
c.ipset6Mutex.Lock()
|
|
defer c.ipset6Mutex.Unlock()
|
|
_, found := c.ipset6Cache[ip6]
|
|
if found {
|
|
return nil // this IP was added before
|
|
}
|
|
c.ipset6Cache[ip6] = false
|
|
return a.AAAA
|
|
|
|
default:
|
|
return nil
|
|
}
|
|
}
|
|
|
|
// Add IP addresses of the specified in configuration domain names to an ipset list
|
|
func (c *ipsetCtx) process(ctx *dnsContext) (rc resultCode) {
|
|
req := ctx.proxyCtx.Req
|
|
if !(req.Question[0].Qtype == dns.TypeA ||
|
|
req.Question[0].Qtype == dns.TypeAAAA) ||
|
|
!ctx.responseFromUpstream {
|
|
return resultCodeSuccess
|
|
}
|
|
|
|
host := req.Question[0].Name
|
|
host = strings.TrimSuffix(host, ".")
|
|
host = strings.ToLower(host)
|
|
ipsetNames, found := c.ipsetList[host]
|
|
if !found {
|
|
return resultCodeSuccess
|
|
}
|
|
|
|
log.Debug("IPSET: found ipsets %v for host %s", ipsetNames, host)
|
|
|
|
for _, it := range ctx.proxyCtx.Res.Answer {
|
|
ip := c.getIP(it)
|
|
if ip == nil {
|
|
continue
|
|
}
|
|
|
|
ipStr := ip.String()
|
|
for _, name := range ipsetNames {
|
|
code, out, err := util.RunCommand("ipset", "add", name, ipStr)
|
|
if err != nil {
|
|
log.Info("IPSET: %s(%s) -> %s: %s", host, ipStr, name, err)
|
|
continue
|
|
}
|
|
if code != 0 {
|
|
log.Info("IPSET: ipset add: code:%d output:%q", code, out)
|
|
continue
|
|
}
|
|
log.Debug("IPSET: added %s(%s) -> %s", host, ipStr, name)
|
|
}
|
|
}
|
|
|
|
return resultCodeSuccess
|
|
}
|