4 Commits

Author SHA1 Message Date
liuxueli
604fd5d179 TSG-6992: 变更DNS应答记录策略表名称,由FW_PROFILE_DNS_RECORDS变更为TSG_PROFILE_DNS_RECORDS 2021-07-09 11:36:42 +08:00
liuxueli
57c2feb69d 支持从profile中选择应答记录内容,TSG-6653 2021-06-11 09:39:29 +08:00
liuxueli
2a25c20cea 控制日志输出,在FATAL模式下不调用printaddr 2021-04-19 20:21:26 +08:00
刘学利
ab097e3bff 命中策略后返回GIVEME,处理链接上后续的DNS请求
用户自定义没有符合的欺骗IP时,串联环境丢弃真实应答包
2021-04-17 13:38:01 +00:00
4 changed files with 335 additions and 251 deletions

View File

@@ -35,10 +35,13 @@ static __attribute__((__used__)) const char * GIT_VERSION_UNKNOWN = NULL;
} }
#endif #endif
#ifndef PRINTADDR
#define PRINTADDR(a, b) ((b)<RLOG_LV_FATAL ? printaddr(&(a->addr), a->threadnum) : "")
#endif
char FW_DNS_PLUG_VERSION_20210607=0;
struct fw_dns_plug g_fw_dns_plug_info;
char *g_fw_dns_conffile=(char *)"tsgconf/main.conf"; char *g_fw_dns_conffile=(char *)"tsgconf/main.conf";
char FW_DNS_PLUG_VERSION_20191220=0;
struct _fw_dns_plug g_fw_dns_plug_info;
static int get_answer_ttl(cJSON *object) static int get_answer_ttl(cJSON *object)
{ {
@@ -46,6 +49,11 @@ static int get_answer_ttl(cJSON *object)
int max=0; int max=0;
cJSON *item=NULL; cJSON *item=NULL;
if(object==NULL)
{
return 0;
}
item=cJSON_GetObjectItem(object, "min"); item=cJSON_GetObjectItem(object, "min");
min=item->valueint; min=item->valueint;
@@ -79,62 +87,97 @@ static cJSON * get_answer_records(cJSON *object, int qtype)
return NULL; return NULL;
} }
static char fw_dns_action(struct streaminfo *a_stream, dns_info_t *dns_info, Maat_rule_t *p_result, const void *a_packet) static int build_answer_records(struct streaminfo *a_stream, dns_info_t *dns_info, cJSON *object, cheat_pkt_opt_t *cheat_opt, int cheat_opt_num)
{ {
int ttl=0;
int record_id=0; int record_id=0;
int i=0,used_num=0; int i=0,used_num=0;
int answer_size=0,ret=0; int answer_size=0;
int payload_len=0,ttl=0; cJSON *one_record=NULL;
cJSON *a_item=NULL;
cJSON *answer_array=NULL;
int answer_type=DNS_TYPE_UNKNOWN;
answer_array=get_answer_records(object, dns_info->query_question.qtype);
if(answer_array!=NULL)
{
memset(cheat_opt, 0, sizeof(cheat_pkt_opt_t)*cheat_opt_num);
answer_size=cJSON_GetArraySize(answer_array);
for(i=0; i<answer_size; i++)
{
one_record=cJSON_GetArrayItem(answer_array, i);
a_item=cJSON_GetObjectItem(one_record, "atype");
if(a_item==NULL)
{
continue;
}
answer_type=fw_dns_type2index(a_item->valuestring);
a_item=cJSON_GetObjectItem(one_record, "ttl");
ttl=get_answer_ttl(a_item);
a_item=cJSON_GetObjectItem(one_record, "value");
if(a_item!=NULL)
{
cheat_opt[used_num].res_type=answer_type;
cheat_opt[used_num].cfg_type=answer_type;
cheat_opt[used_num].ttl=ttl;
switch(answer_type)
{
case DNS_TYPE_A:
cheat_opt[used_num].res_len=sizeof(unsigned int);
inet_pton(AF_INET, a_item->valuestring, (void *)cheat_opt[used_num].res_info);
break;
case DNS_TYPE_AAAA:
cheat_opt[used_num].res_len=IPV6_ADDR_LEN;
inet_pton(AF_INET6, a_item->valuestring, (void *)cheat_opt[used_num].res_info);
break;
case DNS_TYPE_NS:
case DNS_TYPE_TXT:
case DNS_TYPE_PTR:
case DNS_TYPE_CNAME:
cheat_opt[used_num].res_len=(strlen(a_item->valuestring) > sizeof(cheat_opt[used_num].res_info)-1) ? sizeof(cheat_opt[used_num].res_info)-1 : strlen(a_item->valuestring);
memcpy(cheat_opt[used_num].res_info, a_item->valuestring, cheat_opt[used_num].res_len);
break;
default:
continue;
}
used_num++;
}
else
{
a_item=cJSON_GetObjectItem(one_record, "record_id");
record_id=a_item->valueint;
a_item=cJSON_GetObjectItem(one_record, "selected_num");
used_num+=dns_get_cheat_opt(record_id, a_item->valueint, ttl, answer_type, cheat_opt+used_num, cheat_opt_num-used_num);
}
}
}
return used_num;
}
static char fw_dns_action(struct streaminfo *a_stream, dns_info_t *dns_info, Maat_rule_t *p_result, const void *a_packet)
{
int ret=0;
int payload_len=0;
int answer_records_num=0;
dns_hdr_t *dns_hdr = NULL; dns_hdr_t *dns_hdr = NULL;
cJSON *item=NULL; cJSON *item=NULL;
cJSON *a_item=NULL;
cJSON *object=NULL; cJSON *object=NULL;
cJSON *answer_array=NULL;
char *tmp_buff=NULL; char *tmp_buff=NULL;
unsigned char senddir=0; unsigned char senddir=0;
char state=PROT_STATE_GIVEME; char state=PROT_STATE_GIVEME;
int answer_type=DNS_TYPE_UNKNOWN;
int method_type=TSG_METHOD_TYPE_UNKNOWN; int method_type=TSG_METHOD_TYPE_UNKNOWN;
cheat_pkt_opt_t cheat_opt[MAX_ANSWER_RECORDS_NUM]; cheat_pkt_opt_t cheat_opt[MAX_ANSWER_RECORDS_NUM];
unsigned char cheat_pkt_payload[MAX_CHEAT_PKT_PAYLOAD_LEN]; unsigned char cheat_pkt_payload[MAX_CHEAT_PKT_PAYLOAD_LEN];
if(p_result->serv_def_len<128) tmp_buff=(char *)calloc(1, p_result->serv_def_len+1);
{ Maat_read_rule(g_tsg_maat_feather, p_result, MAAT_RULE_SERV_DEFINE, tmp_buff, p_result->serv_def_len);
object=cJSON_Parse(p_result->service_defined);
MESA_handle_runtime_log(g_fw_dns_plug_info.logger,
RLOG_LV_DEBUG,
"DO_ACTION",
"Hit policy_id: %d service: %d action: %d user_reagion: %s domain: %s qtype: %d addr: %s",
p_result->config_id,
p_result->service_id,
p_result->action,
p_result->service_defined,
(char *)dns_info->query_question.qname,
dns_info->query_question.qtype,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "")
);
}
else
{
tmp_buff=(char *)calloc(1, p_result->serv_def_len+1);
Maat_read_rule(g_tsg_maat_feather, p_result, MAAT_RULE_SERV_DEFINE, tmp_buff, p_result->serv_def_len);
object=cJSON_Parse(tmp_buff);
MESA_handle_runtime_log(g_fw_dns_plug_info.logger,
RLOG_LV_DEBUG,
"DO_ACTION",
"Hit policy_id: %d service: %d action: %d user_reagion: %s domain: %s qtype: %d addr: %s",
p_result->config_id,
p_result->service_id,
p_result->action,
tmp_buff,
(char *)dns_info->query_question.qname,
dns_info->query_question.qtype,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "")
);
}
object=cJSON_Parse(tmp_buff);
if(object==NULL) if(object==NULL)
{ {
MESA_handle_runtime_log(g_fw_dns_plug_info.logger, MESA_handle_runtime_log(g_fw_dns_plug_info.logger,
@@ -147,28 +190,23 @@ static char fw_dns_action(struct streaminfo *a_stream, dns_info_t *dns_info, Maa
(tmp_buff==NULL) ? p_result->service_defined : tmp_buff, (tmp_buff==NULL) ? p_result->service_defined : tmp_buff,
(char *)dns_info->query_question.qname, (char *)dns_info->query_question.qname,
dns_info->query_question.qtype, dns_info->query_question.qtype,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "") PRINTADDR(a_stream, g_fw_dns_plug_info.level)
); );
method_type=TSG_METHOD_TYPE_DROP;
if(tmp_buff!=NULL)
{
free(tmp_buff);
tmp_buff=NULL;
}
return PROT_STATE_GIVEME;
} }
else
item=cJSON_GetObjectItem(object, "method");
if(item!=NULL)
{ {
method_type=tsg_get_method_id(item->valuestring); item=cJSON_GetObjectItem(object, "method");
if(item!=NULL)
{
method_type=tsg_get_method_id(item->valuestring);
}
} }
switch(method_type) switch(method_type)
{ {
case TSG_METHOD_TYPE_DROP: case TSG_METHOD_TYPE_DROP:
state=PROT_STATE_DROPME|PROT_STATE_DROPPKT; state=PROT_STATE_GIVEME|PROT_STATE_DROPPKT;
break; break;
case TSG_METHOD_TYPE_REDIRECTION: case TSG_METHOD_TYPE_REDIRECTION:
if(g_fw_dns_plug_info.mode==0 && dns_info->hdr_info.qr==1) //mirror if(g_fw_dns_plug_info.mode==0 && dns_info->hdr_info.qr==1) //mirror
@@ -181,118 +219,88 @@ static char fw_dns_action(struct streaminfo *a_stream, dns_info_t *dns_info, Maa
break; break;
} }
answer_array=get_answer_records(object, dns_info->query_question.qtype); answer_records_num=build_answer_records(a_stream, dns_info, object, cheat_opt, MAX_ANSWER_RECORDS_NUM);
if(answer_array!=NULL) if(answer_records_num<=0)
{
memset(cheat_opt, 0, sizeof(cheat_opt));
answer_size=cJSON_GetArraySize(answer_array);
for(i=0; i<answer_size; i++)
{
item=cJSON_GetArrayItem(answer_array, i);
a_item=cJSON_GetObjectItem(item, "atype");
answer_type=fw_dns_type2index(a_item->valuestring);
a_item=cJSON_GetObjectItem(item, "ttl");
ttl=get_answer_ttl(a_item);
a_item=cJSON_GetObjectItem(item, "value");
if(a_item!=NULL)
{
cheat_opt[used_num].res_type=answer_type;
cheat_opt[used_num].cfg_type=answer_type;
cheat_opt[used_num].ttl=ttl;
switch(answer_type)
{
case DNS_TYPE_A:
cheat_opt[used_num].res_len=sizeof(unsigned int);
inet_pton(AF_INET, a_item->valuestring, (void *)cheat_opt[used_num].res_info);
break;
case DNS_TYPE_AAAA:
cheat_opt[used_num].res_len=IPV6_ADDR_LEN;
inet_pton(AF_INET6, a_item->valuestring, (void *)cheat_opt[used_num].res_info);
break;
default:
cheat_opt[used_num].res_len=(strlen(a_item->valuestring) > sizeof(cheat_opt[used_num].res_info)-1) ? sizeof(cheat_opt[used_num].res_info)-1 : strlen(a_item->valuestring);
memcpy(cheat_opt[used_num].res_info, a_item->valuestring, cheat_opt[used_num].res_len);
break;
}
used_num++;
}
else
{
a_item=cJSON_GetObjectItem(object, "record_id");
record_id=a_item->valueint;
a_item=cJSON_GetObjectItem(object, "selected_num");
used_num+=get_cheat_opt(record_id, a_item->valueint, ttl, answer_type, cheat_opt+used_num, MAX_ANSWER_RECORDS_NUM-used_num);
}
}
memset(cheat_pkt_payload, 0, MAX_CHEAT_PKT_PAYLOAD_LEN);
dns_hdr = (dns_hdr_t *)cheat_pkt_payload;
dns_hdr->id = dns_info->hdr_info.id;
dns_hdr->qdcount = 1;
dns_hdr->ancount = used_num;
payload_len=build_cheat_pkt(cheat_pkt_payload, MAX_CHEAT_PKT_PAYLOAD_LEN, &dns_info->query_question, cheat_opt, used_num);
if(payload_len==-1)
{
return -1;
}
if(dns_info->hdr_info.qr==0)
{
senddir = MESA_dir_reverse(a_stream->routedir);
}
else
{
senddir = a_stream->routedir;
}
ret=MESA_inject_pkt(a_stream, (const char *)cheat_pkt_payload, payload_len, (const char *)a_packet, senddir);
if(ret<0)
{
MESA_handle_runtime_log(g_fw_dns_plug_info.logger,
RLOG_LV_FATAL,
"SEND_CHEAT_PKT",
"Return of MESA_inject_pkt_feedback function is %d, qname: %s qtype: %d cfg_id: %d service: %d addr: %s",
ret,
dns_info->query_question.qname,
dns_info->query_question.qtype,
p_result->config_id,
p_result->service_id,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "")
);
}
state=PROT_STATE_DROPME|PROT_STATE_DROPPKT;
}
else
{ {
MESA_handle_runtime_log(g_fw_dns_plug_info.logger, MESA_handle_runtime_log(g_fw_dns_plug_info.logger,
RLOG_LV_FATAL, RLOG_LV_FATAL,
"DO_ACTION", "DO_ACTION",
"Hit policy_id: %d service: %d action: %d user_reagion: %s domain: %s qtype: %d addr: %s", "Hit policy_id: %d service: %d action: %d user_region: %s domain: %s qtype: %d addr: %s",
p_result->config_id, p_result->config_id,
p_result->service_id, p_result->service_id,
p_result->action, p_result->action,
(tmp_buff==NULL) ? p_result->service_defined : tmp_buff, (tmp_buff==NULL) ? p_result->service_defined : tmp_buff,
(char *)dns_info->query_question.qname, (char *)dns_info->query_question.qname,
dns_info->query_question.qtype, dns_info->query_question.qtype,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "") PRINTADDR(a_stream, g_fw_dns_plug_info.level)
); );
state=PROT_STATE_GIVEME; state=PROT_STATE_GIVEME|PROT_STATE_DROPPKT;
break;
} }
memset(cheat_pkt_payload, 0, MAX_CHEAT_PKT_PAYLOAD_LEN);
dns_hdr = (dns_hdr_t *)cheat_pkt_payload;
dns_hdr->id = dns_info->hdr_info.id;
dns_hdr->qdcount = 1;
dns_hdr->ancount = answer_records_num;
payload_len=build_cheat_pkt(cheat_pkt_payload, MAX_CHEAT_PKT_PAYLOAD_LEN, &dns_info->query_question, cheat_opt, answer_records_num);
if(payload_len==-1)
{
MESA_handle_runtime_log(g_fw_dns_plug_info.logger,
RLOG_LV_FATAL,
"DO_ACTION",
"Hit policy_id: %d service: %d action: %d build_cheat_pkt ret: %d addr: %s",
p_result->config_id,
p_result->service_id,
p_result->action,
payload_len,
PRINTADDR(a_stream, g_fw_dns_plug_info.level)
);
break;
}
if(dns_info->hdr_info.qr==0)
{
senddir = MESA_dir_reverse(a_stream->routedir);
}
else
{
senddir = a_stream->routedir;
}
ret=MESA_inject_pkt(a_stream, (const char *)cheat_pkt_payload, payload_len, (const char *)a_packet, senddir);
if(ret<0)
{
MESA_handle_runtime_log(g_fw_dns_plug_info.logger,
RLOG_LV_FATAL,
"SEND_CHEAT_PKT",
"Return of MESA_inject_pkt_feedback function is %d, qname: %s qtype: %d cfg_id: %d service: %d addr: %s",
ret,
dns_info->query_question.qname,
dns_info->query_question.qtype,
p_result->config_id,
p_result->service_id,
PRINTADDR(a_stream, g_fw_dns_plug_info.level)
);
}
state=PROT_STATE_GIVEME|PROT_STATE_DROPPKT;
break; break;
default: default:
break; break;
} }
cJSON_Delete(object); if(object!=NULL)
object=NULL; {
cJSON_Delete(object);
object=NULL;
}
if(tmp_buff!=NULL)
{
free(tmp_buff);
tmp_buff=NULL;
}
return state; return state;
} }
@@ -343,10 +351,11 @@ static int fw_dns_send_log(struct streaminfo *a_stream, dns_info_t *dns_info, st
} }
cname=cJSON_PrintUnformatted(cname_array); cname=cJSON_PrintUnformatted(cname_array);
if(strlen(cname)>0) if(cname!=NULL && strlen(cname)>0)
{ {
TLD_append(handle, (char *)"dns_cname", (void *)cname, TLD_TYPE_STRING); TLD_append(handle, (char *)"dns_cname", (void *)cname, TLD_TYPE_STRING);
free(cname); cJSON_free(cname);
cname=NULL;
} }
cJSON_Delete(cname_array); cJSON_Delete(cname_array);
cname_array=NULL; cname_array=NULL;
@@ -359,7 +368,7 @@ static int fw_dns_send_log(struct streaminfo *a_stream, dns_info_t *dns_info, st
cJSON_Delete(object); cJSON_Delete(object);
object=NULL; object=NULL;
free(rr_buf); cJSON_free(rr_buf);
rr_buf=NULL; rr_buf=NULL;
TLD_append(handle, (char *)"dns_sub", (void *)(long)dns_sec, TLD_TYPE_LONG); TLD_append(handle, (char *)"dns_sub", (void *)(long)dns_sec, TLD_TYPE_LONG);
@@ -385,7 +394,7 @@ extern "C" char FW_DNS_PLUG_ENTRY(stSessionInfo* session_info, void **pme, int
struct Maat_rule_t result[MAX_RESULT_NUM], *p_result=NULL; struct Maat_rule_t result[MAX_RESULT_NUM], *p_result=NULL;
dns_info_t *dns_info=(dns_info_t *)session_info->app_info; dns_info_t *dns_info=(dns_info_t *)session_info->app_info;
if(dns_info==NULL) if(dns_info==NULL || a_stream==NULL)
{ {
return state; return state;
} }
@@ -397,7 +406,7 @@ extern "C" char FW_DNS_PLUG_ENTRY(stSessionInfo* session_info, void **pme, int
"DNS_PLUG", "DNS_PLUG",
"Qname is %s, addr: %s", "Qname is %s, addr: %s",
(dns_info==NULL) ? "NULL" : ((strlen((char *)dns_info->query_question.qname)==0) ? "NULL" : (char *)dns_info->query_question.qname), (dns_info==NULL) ? "NULL" : ((strlen((char *)dns_info->query_question.qname)==0) ? "NULL" : (char *)dns_info->query_question.qname),
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "") PRINTADDR(a_stream, g_fw_dns_plug_info.level)
); );
return state; return state;
} }
@@ -414,7 +423,7 @@ extern "C" char FW_DNS_PLUG_ENTRY(stSessionInfo* session_info, void **pme, int
result[hit_num].action, result[hit_num].action,
(char *)dns_info->query_question.qname, (char *)dns_info->query_question.qname,
dns_info->query_question.qtype, dns_info->query_question.qtype,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "") PRINTADDR(a_stream, g_fw_dns_plug_info.level)
); );
hit_num+=ret; hit_num+=ret;
} }
@@ -427,7 +436,7 @@ extern "C" char FW_DNS_PLUG_ENTRY(stSessionInfo* session_info, void **pme, int
(char *)dns_info->query_question.qname, (char *)dns_info->query_question.qname,
dns_info->query_question.qtype, dns_info->query_question.qtype,
ret, ret,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "") PRINTADDR(a_stream, g_fw_dns_plug_info.level)
); );
} }
@@ -455,7 +464,7 @@ extern "C" char FW_DNS_PLUG_ENTRY(stSessionInfo* session_info, void **pme, int
result[hit_num].config_id, result[hit_num].config_id,
result[hit_num].service_id, result[hit_num].service_id,
result[hit_num].action, result[hit_num].action,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "") PRINTADDR(a_stream, g_fw_dns_plug_info.level)
); );
hit_num+=ret; hit_num+=ret;
} }
@@ -468,7 +477,7 @@ extern "C" char FW_DNS_PLUG_ENTRY(stSessionInfo* session_info, void **pme, int
(char *)dns_info->query_question.qname, (char *)dns_info->query_question.qname,
dns_info->query_question.qtype, dns_info->query_question.qtype,
ret, ret,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "") PRINTADDR(a_stream, g_fw_dns_plug_info.level)
); );
} }
@@ -488,7 +497,7 @@ extern "C" char FW_DNS_PLUG_ENTRY(stSessionInfo* session_info, void **pme, int
result[hit_num].config_id, result[hit_num].config_id,
result[hit_num].service_id, result[hit_num].service_id,
result[hit_num].action, result[hit_num].action,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "") PRINTADDR(a_stream, g_fw_dns_plug_info.level)
); );
hit_num+=ret; hit_num+=ret;
} }
@@ -501,7 +510,7 @@ extern "C" char FW_DNS_PLUG_ENTRY(stSessionInfo* session_info, void **pme, int
(char *)dns_info->query_question.qname, (char *)dns_info->query_question.qname,
category_id[i], category_id[i],
ret, ret,
(g_fw_dns_plug_info.level<RLOG_LV_FATAL ? printaddr(&a_stream->addr, a_stream->threadnum) : "") PRINTADDR(a_stream, g_fw_dns_plug_info.level)
); );
} }
@@ -514,10 +523,7 @@ extern "C" char FW_DNS_PLUG_ENTRY(stSessionInfo* session_info, void **pme, int
if(p_result!=NULL) if(p_result!=NULL)
{ {
state=fw_dns_action(a_stream, dns_info, p_result, a_packet); state=fw_dns_action(a_stream, dns_info, p_result, a_packet);
if(PROT_STATE_GIVEME!=state) fw_dns_send_log(a_stream, dns_info, p_result, 1, thread_seq);
{
fw_dns_send_log(a_stream, dns_info, p_result, 1, thread_seq);
}
} }
else else
{ {
@@ -569,7 +575,7 @@ extern "C" int FW_DNS_PLUG_INIT(void)
ret=sapp_get_platform_opt(SPO_DEPLOYMENT_MODE_STR, g_fw_dns_plug_info.s_mode, &len); ret=sapp_get_platform_opt(SPO_DEPLOYMENT_MODE_STR, g_fw_dns_plug_info.s_mode, &len);
if(ret>=0) if(ret>=0)
{ {
if((memcmp(g_fw_dns_plug_info.s_mode, "mirror", strlen(g_fw_dns_plug_info.s_mode)))==0) if((memcmp(g_fw_dns_plug_info.s_mode, "mirror", strlen(g_fw_dns_plug_info.s_mode)))==0 || (memcmp(g_fw_dns_plug_info.s_mode, "dumpfile", strlen(g_fw_dns_plug_info.s_mode)))==0)
{ {
g_fw_dns_plug_info.mode=0; g_fw_dns_plug_info.mode=0;
} }

View File

@@ -5,7 +5,7 @@
#define MAX_ANSWER_RECORDS_NUM 32 #define MAX_ANSWER_RECORDS_NUM 32
struct _fw_dns_plug struct fw_dns_plug
{ {
int mode; int mode;
int level; int level;

View File

@@ -1,4 +1,5 @@
#include <stdio.h> #include <stdio.h>
#include <time.h>
#include <arpa/inet.h> #include <arpa/inet.h>
#include <MESA/stream.h> #include <MESA/stream.h>
@@ -12,10 +13,10 @@
#include "tsg_rule.h" #include "tsg_rule.h"
#include "fw_dns_rule.h" #include "fw_dns_rule.h"
fw_dns_rule_t g_fw_dns_rule_info; struct fw_dns_rule g_fw_dns_rule_info;
char FW_DNS_RULE_VERSION_20191201=0; char FW_DNS_RULE_VERSION_20191201=0;
struct _dns_str2idx str2index[]={{DNS_TYPE_CNAME, 5, (char *)"CNAME"}, struct dns_str2idx str2index[]={{DNS_TYPE_CNAME, 5, (char *)"CNAME"},
{DNS_TYPE_MX, 2, (char *)"MX"}, {DNS_TYPE_MX, 2, (char *)"MX"},
{DNS_TYPE_A, 1, (char *)"A"}, {DNS_TYPE_A, 1, (char *)"A"},
{DNS_TYPE_NS, 2, (char *)"NS"}, {DNS_TYPE_NS, 2, (char *)"NS"},
@@ -28,7 +29,7 @@ int fw_dns_type2index(char *type)
{ {
int i=0; int i=0;
for(i=0; i<(int)(sizeof(str2index)/sizeof(struct _dns_str2idx)); i++) for(i=0; i<(int)(sizeof(str2index)/sizeof(struct dns_str2idx)); i++)
{ {
if(str2index[i].len==(int)strlen(type) && (strncasecmp(str2index[i].type, type, str2index[i].len))==0) if(str2index[i].len==(int)strlen(type) && (strncasecmp(str2index[i].type, type, str2index[i].len))==0)
{ {
@@ -39,65 +40,31 @@ int fw_dns_type2index(char *type)
return -1; return -1;
} }
int get_cheat_opt(int record_id, int select_num, int ttl, int atype, cheat_pkt_opt_t* cheat_opt, int cheat_opt_num)
{
int i=0,idx=0;
int used_num=0,real_num=0;
cb_rule_t *cb_rule=NULL;
real_num=(select_num>cheat_opt_num) ? cheat_opt_num : select_num;
cb_rule=(cb_rule_t *)Maat_plugin_get_EX_data(g_tsg_maat_feather, g_fw_dns_rule_info.table_records_id, (char *)&record_id);
if(cb_rule!=NULL && real_num>0)
{
idx = (cb_rule->record_num>=real_num) ? (random()%(cb_rule->record_num-real_num+1)) : 0;
for(i=0; i<real_num && i+idx<cb_rule->record_num; i++)
{
cheat_opt[used_num].ttl=ttl;
cheat_opt[used_num].res_type=atype;
cheat_opt[used_num].cfg_type=atype;
switch(atype)
{
case DNS_TYPE_A:
cheat_opt[used_num].res_len=sizeof(unsigned int);
break;
case DNS_TYPE_AAAA:
cheat_opt[used_num].res_len=IPV6_ADDR_LEN;
break;
default:
cheat_opt[used_num].res_len=MIN(strlen((char *)(cb_rule->record_values[i+idx])), sizeof(cheat_opt[used_num].res_info)-1);
break;
}
memcpy(cheat_opt[used_num].res_info, (char *)(cb_rule->record_values[i+idx]), cheat_opt[used_num].res_len);
used_num++;
}
}
return used_num;
}
void fw_dns_EX_data_create(int table_id, const char* key, const char* table_line, MAAT_PLUGIN_EX_DATA* ad, long argl, void *argp) void fw_dns_EX_data_create(int table_id, const char* key, const char* table_line, MAAT_PLUGIN_EX_DATA* ad, long argl, void *argp)
{ {
int i=0; int i=0;
cJSON *pSub=NULL; cJSON *one_record=NULL,*pSub=NULL;
cb_rule_t *cb_rule=(cb_rule_t *)calloc(1, sizeof(cb_rule_t));
struct dns_records *records=(struct dns_records *)calloc(1, sizeof(struct dns_records));
char *tmp_records=(char *)calloc(1, strlen(table_line)+1); char *tmp_records=(char *)calloc(1, strlen(table_line)+1);
sscanf(table_line, "%d %s %s %s %d", &records->record_id, records->record_name, records->record_type, tmp_records, &records->is_valid);
sscanf(table_line, "%d %s %s %s %d", &cb_rule->record_id, cb_rule->record_name, cb_rule->record_type, tmp_records, &cb_rule->is_valid); int index=fw_dns_type2index(records->record_type);
int index=fw_dns_type2index(cb_rule->record_type);
cJSON *tmp_array=cJSON_Parse(tmp_records); cJSON *tmp_array=cJSON_Parse(tmp_records);
if(tmp_array != NULL) if(tmp_array!=NULL)
{ {
cb_rule->record_num=cJSON_GetArraySize(tmp_array); records->record_num=cJSON_GetArraySize(tmp_array);
*cb_rule->record_values=(void *)malloc(cb_rule->record_num*sizeof(void *)); records->record_values=(void **)malloc(records->record_num*sizeof(void *));
for(i=0; i<cb_rule->record_num; i++) for(i=0; i<records->record_num; i++)
{ {
pSub = cJSON_GetArrayItem(tmp_array, i); one_record=cJSON_GetArrayItem(tmp_array, i);
if(one_record==NULL)
{
continue;
}
pSub=cJSON_GetObjectItem(one_record, "value");
if(NULL==pSub ) if(NULL==pSub )
{ {
continue; continue;
@@ -106,12 +73,12 @@ void fw_dns_EX_data_create(int table_id, const char* key, const char* table_line
switch(index) switch(index)
{ {
case DNS_TYPE_A: case DNS_TYPE_A:
cb_rule->record_values[i]=calloc(1, sizeof(unsigned int)); records->record_values[i]=calloc(1, sizeof(unsigned int));
inet_pton(AF_INET, pSub->valuestring, cb_rule->record_values[i]); inet_pton(AF_INET, pSub->valuestring, records->record_values[i]);
break; break;
case DNS_TYPE_AAAA: case DNS_TYPE_AAAA:
cb_rule->record_values[i]=calloc(1, IPV6_ADDR_LEN); records->record_values[i]=calloc(1, IPV6_ADDR_LEN);
inet_pton(AF_INET6, pSub->valuestring, cb_rule->record_values[i]); inet_pton(AF_INET6, pSub->valuestring, records->record_values[i]);
break; break;
case DNS_TYPE_MX: case DNS_TYPE_MX:
break; break;
@@ -119,45 +86,141 @@ void fw_dns_EX_data_create(int table_id, const char* key, const char* table_line
case DNS_TYPE_TXT: case DNS_TYPE_TXT:
case DNS_TYPE_PTR: case DNS_TYPE_PTR:
case DNS_TYPE_CNAME: case DNS_TYPE_CNAME:
cb_rule->record_values[i]=calloc(1, strlen(pSub->valuestring)+1); records->record_values[i]=calloc(1, strlen(pSub->valuestring)+1);
memcpy(cb_rule->record_values[i], pSub->valuestring, strlen(pSub->valuestring)); memcpy(records->record_values[i], pSub->valuestring, strlen(pSub->valuestring));
break; break;
default: default:
continue; continue;
} }
} }
records->table_id=table_id;
atomic_inc(&records->ref_cnt);
(*ad)=(MAAT_PLUGIN_EX_DATA)(records);
cJSON_Delete(tmp_array);
tmp_array=NULL;
}
else
{
free(records);
records=NULL;
} }
free(tmp_records); free(tmp_records);
tmp_records=NULL;
return ;
} }
void fw_dns_EX_data_free(int table_id, MAAT_PLUGIN_EX_DATA* ad, long argl, void *argp) void fw_dns_EX_data_free(int table_id, MAAT_PLUGIN_EX_DATA* ad, long argl, void *argp)
{ {
int i=0; int i=0;
cb_rule_t *cb_rule=(cb_rule_t *)*ad; struct dns_records *records=(struct dns_records *)*ad;
if(cb_rule!=NULL) if(records!=NULL)
{ {
for(i=0; i<cb_rule->record_num; i++) atomic_dec(&records->ref_cnt);
if(records->ref_cnt<=0)
{ {
free(cb_rule->record_values[i]); for(i=0; i<records->record_num; i++)
cb_rule->record_values[i]=NULL; {
} free(records->record_values[i]);
free(*cb_rule->record_values); records->record_values[i]=NULL;
*cb_rule->record_values=NULL; }
free(cb_rule); free(*records->record_values);
cb_rule=NULL; *records->record_values=NULL;
free(records);
records=NULL;
}
} }
return ;
} }
void fw_dns_EX_data_dup(int table_id, MAAT_PLUGIN_EX_DATA *to, MAAT_PLUGIN_EX_DATA *from, long argl, void *argp) void fw_dns_EX_data_dup(int table_id, MAAT_PLUGIN_EX_DATA *to, MAAT_PLUGIN_EX_DATA *from, long argl, void *argp)
{ {
struct dns_records *records=(struct dns_records *)(*from);
if(records!=NULL)
{
atomic_inc(&records->ref_cnt);
(*to)=(*from);
}
return ;
}
static int set_one_cheat_opt(cheat_pkt_opt_t *cheat_opt, int ttl, int atype, char *record_values)
{
cheat_opt->ttl=ttl;
cheat_opt->res_type=atype;
cheat_opt->cfg_type=atype;
switch(atype)
{
case DNS_TYPE_A:
cheat_opt->res_len=sizeof(unsigned int);
break;
case DNS_TYPE_AAAA:
cheat_opt->res_len=IPV6_ADDR_LEN;
break;
case DNS_TYPE_NS:
case DNS_TYPE_TXT:
case DNS_TYPE_PTR:
case DNS_TYPE_CNAME:
cheat_opt->res_len=MIN(strlen(record_values), sizeof(cheat_opt->res_info)-1);
break;
default:
return 0;
}
memcpy(cheat_opt->res_info, record_values, cheat_opt->res_len);
return 1;
} }
int fw_dns_EX_data_key2index(const char* key) int dns_get_cheat_opt(int record_id, int select_num, int ttl, int atype, cheat_pkt_opt_t* cheat_opt, int cheat_opt_num)
{ {
return 0; int i=0,idx=0;
char record_id_str[32]={0};
int used_num=0,real_num=0;
struct dns_records *records=NULL;
real_num=MIN(select_num, cheat_opt_num);
if(real_num<=0)
{
return 0;
}
snprintf(record_id_str, sizeof(record_id_str), "%d", record_id);
records=(struct dns_records *)Maat_plugin_get_EX_data(g_tsg_maat_feather, g_fw_dns_rule_info.table_records_id, record_id_str);
if(records!=NULL)
{
if(records->record_num<=real_num)
{
for(i=0; i<records->record_num; i++)
{
used_num+=set_one_cheat_opt(&(cheat_opt[used_num]), ttl, atype, (char *)(records->record_values[i]));
}
}
else
{
srand(time(0));
idx=rand()%(records->record_num-real_num+1);
for(i=0; i<real_num; i++)
{
used_num+=set_one_cheat_opt(&(cheat_opt[used_num]), ttl, atype, (char *)(records->record_values[idx+i]));
}
}
fw_dns_EX_data_free(records->table_id, (MAAT_PLUGIN_EX_DATA *)&records, 0, NULL);
}
return used_num;
} }
@@ -167,7 +230,7 @@ int fw_dns_rule_init(const char *conffile, void *logger)
long arg=0; long arg=0;
memset(&g_fw_dns_rule_info, 0, sizeof(g_fw_dns_rule_info)); memset(&g_fw_dns_rule_info, 0, sizeof(g_fw_dns_rule_info));
MESA_load_profile_string_def(conffile, "DNS_PLUG", "TABLE_RECORDS", g_fw_dns_rule_info.table_records_name, MAX_TABLE_NAME_LEN, (char *)"FW_PROFILE_DNS_RECORDS"); MESA_load_profile_string_def(conffile, "DNS_PLUG", "TABLE_RECORDS", g_fw_dns_rule_info.table_records_name, MAX_TABLE_NAME_LEN, (char *)"TSG_PROFILE_DNS_RECORDS");
g_fw_dns_rule_info.table_records_id=Maat_table_register(g_tsg_maat_feather, g_fw_dns_rule_info.table_records_name); g_fw_dns_rule_info.table_records_id=Maat_table_register(g_tsg_maat_feather, g_fw_dns_rule_info.table_records_name);
if(g_fw_dns_rule_info.table_records_id<0) if(g_fw_dns_rule_info.table_records_id<0)
@@ -181,7 +244,7 @@ int fw_dns_rule_init(const char *conffile, void *logger)
fw_dns_EX_data_create, fw_dns_EX_data_create,
fw_dns_EX_data_free, fw_dns_EX_data_free,
fw_dns_EX_data_dup, fw_dns_EX_data_dup,
fw_dns_EX_data_key2index, NULL,
arg, arg,
NULL); NULL);

View File

@@ -1,36 +1,51 @@
#ifndef __FW_DNS_RULE_H__ #ifndef __FW_DNS_RULE_H__
#define __FW_DNS_RULE_H__ #define __FW_DNS_RULE_H__
#if(__GNUC__ * 100 + __GNUC_MINOR__ * 10 + __GNUC_PATCHLEVEL__ >= 411)
#define atomic_inc(x) __sync_add_and_fetch((x),1)
#define atomic_dec(x) __sync_sub_and_fetch((x),1)
#define atomic_add(x,y) __sync_add_and_fetch((x),(y))
#define atomic_sub(x,y) __sync_sub_and_fetch((x),(y))
typedef int atomic_t;
#define ATOMIC_INIT(i) { (i) }
#define atomic_read(x) __sync_add_and_fetch((x),0)
#define atomic_set(x,y) __sync_lock_test_and_set((x),y)
#else
#include <alsa/iatomic.h>
#endif
#define MIN(a, b) ((a>b) ? b: a) #define MIN(a, b) ((a>b) ? b: a)
#define MAX_TABLE_NAME_LEN 32 #define MAX_TABLE_NAME_LEN 32
struct _dns_str2idx struct dns_str2idx
{ {
int index; int index;
int len; int len;
char *type; char *type;
}; };
typedef struct _cb_rule struct dns_records
{ {
int ref_cnt;
int record_id; int record_id;
int record_num; int record_num;
int is_valid; int is_valid;
int table_id;
char record_type[128]; char record_type[128];
char record_name[MAX_TABLE_NAME_LEN]; char record_name[MAX_TABLE_NAME_LEN];
void **record_values; void **record_values;
}cb_rule_t; };
typedef struct _fw_dns_rule struct fw_dns_rule
{ {
int table_records_id; int table_records_id;
char table_records_name[MAX_TABLE_NAME_LEN]; char table_records_name[MAX_TABLE_NAME_LEN];
}fw_dns_rule_t; };
int fw_dns_type2index(char *type); int fw_dns_type2index(char *type);
int fw_dns_rule_init(const char *conffile, void *logger); int fw_dns_rule_init(const char *conffile, void *logger);
int get_cheat_opt(int record_id, int select_num, int ttl, int atype, cheat_pkt_opt_t* cheat_opt, int cheat_opt_num); int dns_get_cheat_opt(int record_id, int select_num, int ttl, int atype, cheat_pkt_opt_t* cheat_opt, int cheat_opt_num);
#endif #endif